diff --git a/advisories/github-reviewed/2022/05/GHSA-3832-9276-x7gf/GHSA-3832-9276-x7gf.json b/advisories/github-reviewed/2022/05/GHSA-3832-9276-x7gf/GHSA-3832-9276-x7gf.json index 35c9a08e939..67c21cf0766 100644 --- a/advisories/github-reviewed/2022/05/GHSA-3832-9276-x7gf/GHSA-3832-9276-x7gf.json +++ b/advisories/github-reviewed/2022/05/GHSA-3832-9276-x7gf/GHSA-3832-9276-x7gf.json @@ -8,9 +8,7 @@ ], "summary": "Improper Certificate Validation in Apache Commons HttpClient", "details": "Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.\n\nNote that the Commons HttpClient project is [end of life](https://hc.apache.org/httpclient-legacy/). It has been replaced by the Apache HttpComponents project in its [HttpClient](https://hc.apache.org/httpcomponents-client-5.4.x/) and [HttpCore](https://hc.apache.org/httpcomponents-core-5.3.x/) modules. CVE-2012-5783 has been patched in [v4.0](https://repo1.maven.org/maven2/org/apache/httpcomponents/httpclient/4.0/) of the Apache HttpComponents HttpClient module.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-x24q-xwrf-66jm/GHSA-x24q-xwrf-66jm.json b/advisories/github-reviewed/2022/05/GHSA-x24q-xwrf-66jm/GHSA-x24q-xwrf-66jm.json index c908c7bda9e..e8ac416eb48 100644 --- a/advisories/github-reviewed/2022/05/GHSA-x24q-xwrf-66jm/GHSA-x24q-xwrf-66jm.json +++ b/advisories/github-reviewed/2022/05/GHSA-x24q-xwrf-66jm/GHSA-x24q-xwrf-66jm.json @@ -8,9 +8,7 @@ ], "summary": "Improper Neutralization of Input During Web Page Generation in Google Web Toolkit", "details": "Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files in the GWTTestCase in Google Web Toolkit (GWT) before 2.5.1 RC1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/10/GHSA-v9vj-9pxv-mr2w/GHSA-v9vj-9pxv-mr2w.json b/advisories/github-reviewed/2023/10/GHSA-v9vj-9pxv-mr2w/GHSA-v9vj-9pxv-mr2w.json index acad02bdf2e..30b9d745aae 100644 --- a/advisories/github-reviewed/2023/10/GHSA-v9vj-9pxv-mr2w/GHSA-v9vj-9pxv-mr2w.json +++ b/advisories/github-reviewed/2023/10/GHSA-v9vj-9pxv-mr2w/GHSA-v9vj-9pxv-mr2w.json @@ -8,9 +8,7 @@ ], "summary": "mycli has Inadequate Encryption Strength", "details": "Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via `/mycli/config.py`.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/02/GHSA-54rr-7fvw-6x8f/GHSA-54rr-7fvw-6x8f.json b/advisories/github-reviewed/2024/02/GHSA-54rr-7fvw-6x8f/GHSA-54rr-7fvw-6x8f.json index 66ddf0a1fb2..eaf5b53b2c9 100644 --- a/advisories/github-reviewed/2024/02/GHSA-54rr-7fvw-6x8f/GHSA-54rr-7fvw-6x8f.json +++ b/advisories/github-reviewed/2024/02/GHSA-54rr-7fvw-6x8f/GHSA-54rr-7fvw-6x8f.json @@ -8,9 +8,7 @@ ], "summary": "Rack Header Parsing leads to Possible Denial of Service Vulnerability", "details": "# Possible Denial of Service Vulnerability in Rack Header Parsing\n\nThere is a possible denial of service vulnerability in the header parsing\nroutines in Rack. This vulnerability has been assigned the CVE identifier\nCVE-2024-26146.\n\nVersions Affected: All.\nNot affected: None\nFixed Versions: 2.0.9.4, 2.1.4.4, 2.2.8.1, 3.0.9.1\n\nImpact\n------\nCarefully crafted headers can cause header parsing in Rack to take longer than\nexpected resulting in a possible denial of service issue. Accept and Forwarded\nheaders are impacted.\n\nRuby 3.2 has mitigations for this problem, so Rack applications using Ruby 3.2\nor newer are unaffected.\n\nReleases\n--------\nThe fixed releases are available at the normal locations.\n\nWorkarounds\n-----------\nThere are no feasible workarounds for this issue.\n\nPatches\n-------\nTo aid users who aren't able to upgrade immediately we have provided patches for\nthe two supported release series. They are in git-am format and consist of a\nsingle changeset.\n\n* 2-0-header-redos.patch - Patch for 2.0 series\n* 2-1-header-redos.patch - Patch for 2.1 series\n* 2-2-header-redos.patch - Patch for 2.2 series\n* 3-0-header-redos.patch - Patch for 3.0 series\n\nCredits\n-------\n\nThanks to [svalkanov](https://hackerone.com/svalkanov) for reporting this and\nproviding patches!", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/02/GHSA-qp56-82vp-xqgv/GHSA-qp56-82vp-xqgv.json b/advisories/github-reviewed/2024/02/GHSA-qp56-82vp-xqgv/GHSA-qp56-82vp-xqgv.json index a5f8b454d74..ab16ab95212 100644 --- a/advisories/github-reviewed/2024/02/GHSA-qp56-82vp-xqgv/GHSA-qp56-82vp-xqgv.json +++ b/advisories/github-reviewed/2024/02/GHSA-qp56-82vp-xqgv/GHSA-qp56-82vp-xqgv.json @@ -8,9 +8,7 @@ ], "summary": "Mezzanine allows attackers to bypass access control mechanisms", "details": "An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -63,9 +61,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-28T22:58:36Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-xj5v-6v4g-jfw6/GHSA-xj5v-6v4g-jfw6.json b/advisories/github-reviewed/2024/02/GHSA-xj5v-6v4g-jfw6/GHSA-xj5v-6v4g-jfw6.json index 586d581c102..dbc8a211717 100644 --- a/advisories/github-reviewed/2024/02/GHSA-xj5v-6v4g-jfw6/GHSA-xj5v-6v4g-jfw6.json +++ b/advisories/github-reviewed/2024/02/GHSA-xj5v-6v4g-jfw6/GHSA-xj5v-6v4g-jfw6.json @@ -8,9 +8,7 @@ ], "summary": "Rack has possible DoS Vulnerability with Range Header", "details": "# Possible DoS Vulnerability with Range Header in Rack\n\nThere is a possible DoS vulnerability relating to the Range request header in\nRack. This vulnerability has been assigned the CVE identifier CVE-2024-26141.\n\nVersions Affected: >= 1.3.0.\nNot affected: < 1.3.0\nFixed Versions: 3.0.9.1, 2.2.8.1\n\nImpact\n------\nCarefully crafted Range headers can cause a server to respond with an\nunexpectedly large response. Responding with such large responses could lead\nto a denial of service issue.\n\nVulnerable applications will use the `Rack::File` middleware or the\n`Rack::Utils.byte_ranges` methods (this includes Rails applications).\n\nReleases\n--------\nThe fixed releases are available at the normal locations.\n\nWorkarounds\n-----------\nThere are no feasible workarounds for this issue.\n\nPatches\n-------\nTo aid users who aren't able to upgrade immediately we have provided patches for\nthe two supported release series. They are in git-am format and consist of a\nsingle changeset.\n\n* 3-0-range.patch - Patch for 3.0 series\n* 2-2-range.patch - Patch for 2.2 series\n\nCredits\n-------\n\nThank you [ooooooo_q](https://hackerone.com/ooooooo_q) for the report and\npatch", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/05/GHSA-7336-ghhp-f2qj/GHSA-7336-ghhp-f2qj.json b/advisories/github-reviewed/2024/05/GHSA-7336-ghhp-f2qj/GHSA-7336-ghhp-f2qj.json index 889d813268c..c7f324e1b2b 100644 --- a/advisories/github-reviewed/2024/05/GHSA-7336-ghhp-f2qj/GHSA-7336-ghhp-f2qj.json +++ b/advisories/github-reviewed/2024/05/GHSA-7336-ghhp-f2qj/GHSA-7336-ghhp-f2qj.json @@ -3,9 +3,7 @@ "id": "GHSA-7336-ghhp-f2qj", "modified": "2024-05-21T20:54:03Z", "published": "2024-05-21T20:52:57Z", - "aliases": [ - - ], + "aliases": [], "summary": "Shopware Remote Code Execution Vulnerability", "details": "Under certain circumstances, it’s possible to execute an unauthorized foreign code in Shopware in versions prior to 5.2.16. One possible threat is if a template that doesn’t derive from the Shopware standard has been completely copied. Themes or plugins that execute or overwrite the following template code are vulnerable.\n\n- Affected file: emotion.tpl\n\nPath template file \"Emotion template\": templates / _default / frontend / forms / elements.tpl\nPath template file \"Responsive template\": themes/Frontend/Bare/frontend/forms/elements.tpl\n\nThe complete line beginning with: `{eval var=$sSupport.sFields[$sKey]...` should be exchanged with the following:\n\n```\n{$sSupport.sFields[$sKey]|replace:'{literal}':''|replace:'{/literal}':''|replace:'%*%':\"{s name='RequiredField' namespace='frontend/register/index'}{/s}\"}\n```", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-9phw-7h96-q3rv/GHSA-9phw-7h96-q3rv.json b/advisories/github-reviewed/2024/05/GHSA-9phw-7h96-q3rv/GHSA-9phw-7h96-q3rv.json index f30eb5e6425..71ce8032d7b 100644 --- a/advisories/github-reviewed/2024/05/GHSA-9phw-7h96-q3rv/GHSA-9phw-7h96-q3rv.json +++ b/advisories/github-reviewed/2024/05/GHSA-9phw-7h96-q3rv/GHSA-9phw-7h96-q3rv.json @@ -3,9 +3,7 @@ "id": "GHSA-9phw-7h96-q3rv", "modified": "2024-05-21T18:22:04Z", "published": "2024-05-21T18:22:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "scheb/two-factor-bundle bypass two-factor authentication with remember-me option", "details": "In versions prior to 3.26.0 and prior to 4.11.0 of the \"scheb/two-factor-bundle\" project, a security vulnerability allowed attackers to bypass two-factor authentication (2FA) using the remember_me cookie. When the remember_me checkbox was used during login, a \"REMEMBERME\" cookie was created. Upon redirection to the 2FA page, attackers could manipulate the SESSIONID key, granting access to the homepage \"/\" and gaining authentication without completing 2FA.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-h6mp-mc7g-mg49/GHSA-h6mp-mc7g-mg49.json b/advisories/github-reviewed/2024/05/GHSA-h6mp-mc7g-mg49/GHSA-h6mp-mc7g-mg49.json index bf69a10f9fb..4b37d860419 100644 --- a/advisories/github-reviewed/2024/05/GHSA-h6mp-mc7g-mg49/GHSA-h6mp-mc7g-mg49.json +++ b/advisories/github-reviewed/2024/05/GHSA-h6mp-mc7g-mg49/GHSA-h6mp-mc7g-mg49.json @@ -3,9 +3,7 @@ "id": "GHSA-h6mp-mc7g-mg49", "modified": "2024-05-21T18:16:24Z", "published": "2024-05-21T18:16:24Z", - "aliases": [ - - ], + "aliases": [], "summary": "scheb/two-factor-bundle bypass two-factor authentication with unverified JWT trusted device token", "details": "Before version 3.7 the bundle is vulnerable to a [security issue in JWT](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/), which can be exploited by an attacker to generate trusted device cookies on their own, effectively by-passing two-factor authentication.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-jqr7-5h7r-ch8p/GHSA-jqr7-5h7r-ch8p.json b/advisories/github-reviewed/2024/05/GHSA-jqr7-5h7r-ch8p/GHSA-jqr7-5h7r-ch8p.json index a56c5dddc65..1d824dfe7bf 100644 --- a/advisories/github-reviewed/2024/05/GHSA-jqr7-5h7r-ch8p/GHSA-jqr7-5h7r-ch8p.json +++ b/advisories/github-reviewed/2024/05/GHSA-jqr7-5h7r-ch8p/GHSA-jqr7-5h7r-ch8p.json @@ -3,9 +3,7 @@ "id": "GHSA-jqr7-5h7r-ch8p", "modified": "2024-05-21T20:42:46Z", "published": "2024-05-21T20:42:46Z", - "aliases": [ - - ], + "aliases": [], "summary": "Shopware Non-Persistent XSS in the Frontend", "details": "A non-persistent Cross-Site Scripting (XSS) vulnerability has been identified in the Shopware eCommerce platform within the frontend. This vulnerability may allow an attacker to inject and execute malicious scripts in the context of a victim's web browser.", "severity": [ diff --git a/advisories/github-reviewed/2024/05/GHSA-q3g4-2vw9-xv27/GHSA-q3g4-2vw9-xv27.json b/advisories/github-reviewed/2024/05/GHSA-q3g4-2vw9-xv27/GHSA-q3g4-2vw9-xv27.json index 7487cc4233b..6e9bc615f0a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-q3g4-2vw9-xv27/GHSA-q3g4-2vw9-xv27.json +++ b/advisories/github-reviewed/2024/05/GHSA-q3g4-2vw9-xv27/GHSA-q3g4-2vw9-xv27.json @@ -3,9 +3,7 @@ "id": "GHSA-q3g4-2vw9-xv27", "modified": "2024-05-21T18:50:07Z", "published": "2024-05-21T18:50:07Z", - "aliases": [ - - ], + "aliases": [], "summary": "Shopware Remote Code Execution Vulnerability", "details": "Under certain circumstances, it’s possible to execute an unauthorized foreign code in Shopware. This is a critical security vulnerability that could affect the entire system. All Shopware versions including Shopware 5.2.14 are affected.\n", "severity": [ diff --git a/advisories/github-reviewed/2024/09/GHSA-2326-pfpj-vx3h/GHSA-2326-pfpj-vx3h.json b/advisories/github-reviewed/2024/09/GHSA-2326-pfpj-vx3h/GHSA-2326-pfpj-vx3h.json index d42498ee1fa..fbdd30499ea 100644 --- a/advisories/github-reviewed/2024/09/GHSA-2326-pfpj-vx3h/GHSA-2326-pfpj-vx3h.json +++ b/advisories/github-reviewed/2024/09/GHSA-2326-pfpj-vx3h/GHSA-2326-pfpj-vx3h.json @@ -3,14 +3,10 @@ "id": "GHSA-2326-pfpj-vx3h", "modified": "2024-09-16T17:19:01Z", "published": "2024-09-16T17:19:01Z", - "aliases": [ - - ], + "aliases": [], "summary": "lexical-core has multiple soundness issues", "details": "`RUSTSEC-2024-0377` contains multiple soundness issues:\n\n 1. [Bytes::read() allows creating instances of types with invalid bit patterns](https://github.com/Alexhuszagh/rust-lexical/issues/102)\n 1. [BytesIter::read() advances iterators out of bounds](https://github.com/Alexhuszagh/rust-lexical/issues/101)\n 1. [The `BytesIter` trait has safety invariants but is public and not marked `unsafe`](https://github.com/Alexhuszagh/rust-lexical/issues/104)\n 1. [`write_float()` calls `MaybeUninit::assume_init()` on uninitialized data, which is is not allowed by the Rust abstract machine](https://github.com/Alexhuszagh/rust-lexical/issues/95)\n 1. [`radix()` calls `MaybeUninit::assume_init()` on uninitialized data, which is is not allowed by the Rust abstract machine](https://github.com/Alexhuszagh/rust-lexical/issues/126)\n\nVersion 1.0 fixes these issues, removes the vast majority of `unsafe` code, and also fixes some correctness issues.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -71,9 +67,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-09-16T17:19:01Z", diff --git a/advisories/unreviewed/2021/12/GHSA-3jcx-v57w-c6rq/GHSA-3jcx-v57w-c6rq.json b/advisories/unreviewed/2021/12/GHSA-3jcx-v57w-c6rq/GHSA-3jcx-v57w-c6rq.json index cd5a3fcee2d..d5383482703 100644 --- a/advisories/unreviewed/2021/12/GHSA-3jcx-v57w-c6rq/GHSA-3jcx-v57w-c6rq.json +++ b/advisories/unreviewed/2021/12/GHSA-3jcx-v57w-c6rq/GHSA-3jcx-v57w-c6rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-6ffh-2qg3-m72q/GHSA-6ffh-2qg3-m72q.json b/advisories/unreviewed/2021/12/GHSA-6ffh-2qg3-m72q/GHSA-6ffh-2qg3-m72q.json index a210c9f5e68..475d1300d25 100644 --- a/advisories/unreviewed/2021/12/GHSA-6ffh-2qg3-m72q/GHSA-6ffh-2qg3-m72q.json +++ b/advisories/unreviewed/2021/12/GHSA-6ffh-2qg3-m72q/GHSA-6ffh-2qg3-m72q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jcr9-6f4v-3f68/GHSA-jcr9-6f4v-3f68.json b/advisories/unreviewed/2021/12/GHSA-jcr9-6f4v-3f68/GHSA-jcr9-6f4v-3f68.json index 2474d5a71d5..3f52cde27d0 100644 --- a/advisories/unreviewed/2021/12/GHSA-jcr9-6f4v-3f68/GHSA-jcr9-6f4v-3f68.json +++ b/advisories/unreviewed/2021/12/GHSA-jcr9-6f4v-3f68/GHSA-jcr9-6f4v-3f68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-jgjr-5rhg-5c7w/GHSA-jgjr-5rhg-5c7w.json b/advisories/unreviewed/2021/12/GHSA-jgjr-5rhg-5c7w/GHSA-jgjr-5rhg-5c7w.json index 7353ce207ee..f282803e1bf 100644 --- a/advisories/unreviewed/2021/12/GHSA-jgjr-5rhg-5c7w/GHSA-jgjr-5rhg-5c7w.json +++ b/advisories/unreviewed/2021/12/GHSA-jgjr-5rhg-5c7w/GHSA-jgjr-5rhg-5c7w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-m95m-2xc3-p525/GHSA-m95m-2xc3-p525.json b/advisories/unreviewed/2021/12/GHSA-m95m-2xc3-p525/GHSA-m95m-2xc3-p525.json index d1b914f524c..8361f1b40a0 100644 --- a/advisories/unreviewed/2021/12/GHSA-m95m-2xc3-p525/GHSA-m95m-2xc3-p525.json +++ b/advisories/unreviewed/2021/12/GHSA-m95m-2xc3-p525/GHSA-m95m-2xc3-p525.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mfmh-5798-r2wm/GHSA-mfmh-5798-r2wm.json b/advisories/unreviewed/2021/12/GHSA-mfmh-5798-r2wm/GHSA-mfmh-5798-r2wm.json index ee326a2b2eb..d94df96c89b 100644 --- a/advisories/unreviewed/2021/12/GHSA-mfmh-5798-r2wm/GHSA-mfmh-5798-r2wm.json +++ b/advisories/unreviewed/2021/12/GHSA-mfmh-5798-r2wm/GHSA-mfmh-5798-r2wm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mgfp-f8w4-cfpf/GHSA-mgfp-f8w4-cfpf.json b/advisories/unreviewed/2021/12/GHSA-mgfp-f8w4-cfpf/GHSA-mgfp-f8w4-cfpf.json index 853373854f0..d6e77f6fb8f 100644 --- a/advisories/unreviewed/2021/12/GHSA-mgfp-f8w4-cfpf/GHSA-mgfp-f8w4-cfpf.json +++ b/advisories/unreviewed/2021/12/GHSA-mgfp-f8w4-cfpf/GHSA-mgfp-f8w4-cfpf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-pm57-h436-7cgq/GHSA-pm57-h436-7cgq.json b/advisories/unreviewed/2021/12/GHSA-pm57-h436-7cgq/GHSA-pm57-h436-7cgq.json index 7bb28885437..918074af586 100644 --- a/advisories/unreviewed/2021/12/GHSA-pm57-h436-7cgq/GHSA-pm57-h436-7cgq.json +++ b/advisories/unreviewed/2021/12/GHSA-pm57-h436-7cgq/GHSA-pm57-h436-7cgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-f44x-m52x-fpcf/GHSA-f44x-m52x-fpcf.json b/advisories/unreviewed/2022/01/GHSA-f44x-m52x-fpcf/GHSA-f44x-m52x-fpcf.json index a000d672029..2fbcfb351bb 100644 --- a/advisories/unreviewed/2022/01/GHSA-f44x-m52x-fpcf/GHSA-f44x-m52x-fpcf.json +++ b/advisories/unreviewed/2022/01/GHSA-f44x-m52x-fpcf/GHSA-f44x-m52x-fpcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-fv8f-h6jw-598x/GHSA-fv8f-h6jw-598x.json b/advisories/unreviewed/2022/01/GHSA-fv8f-h6jw-598x/GHSA-fv8f-h6jw-598x.json index 449277861b7..7905d6accbd 100644 --- a/advisories/unreviewed/2022/01/GHSA-fv8f-h6jw-598x/GHSA-fv8f-h6jw-598x.json +++ b/advisories/unreviewed/2022/01/GHSA-fv8f-h6jw-598x/GHSA-fv8f-h6jw-598x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-gc9x-xj3h-72v9/GHSA-gc9x-xj3h-72v9.json b/advisories/unreviewed/2022/01/GHSA-gc9x-xj3h-72v9/GHSA-gc9x-xj3h-72v9.json index a03ac971c87..765418d82ce 100644 --- a/advisories/unreviewed/2022/01/GHSA-gc9x-xj3h-72v9/GHSA-gc9x-xj3h-72v9.json +++ b/advisories/unreviewed/2022/01/GHSA-gc9x-xj3h-72v9/GHSA-gc9x-xj3h-72v9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-grh3-9qm5-9w2v/GHSA-grh3-9qm5-9w2v.json b/advisories/unreviewed/2022/01/GHSA-grh3-9qm5-9w2v/GHSA-grh3-9qm5-9w2v.json index 5d3ebbbe3d2..5abc8e41277 100644 --- a/advisories/unreviewed/2022/01/GHSA-grh3-9qm5-9w2v/GHSA-grh3-9qm5-9w2v.json +++ b/advisories/unreviewed/2022/01/GHSA-grh3-9qm5-9w2v/GHSA-grh3-9qm5-9w2v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-rw79-f757-2ffc/GHSA-rw79-f757-2ffc.json b/advisories/unreviewed/2022/01/GHSA-rw79-f757-2ffc/GHSA-rw79-f757-2ffc.json index 38cedf97ced..18127a71e58 100644 --- a/advisories/unreviewed/2022/01/GHSA-rw79-f757-2ffc/GHSA-rw79-f757-2ffc.json +++ b/advisories/unreviewed/2022/01/GHSA-rw79-f757-2ffc/GHSA-rw79-f757-2ffc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-4g55-4fxv-2g82/GHSA-4g55-4fxv-2g82.json b/advisories/unreviewed/2022/02/GHSA-4g55-4fxv-2g82/GHSA-4g55-4fxv-2g82.json index cd4b77da21f..df5dcaf2f4f 100644 --- a/advisories/unreviewed/2022/02/GHSA-4g55-4fxv-2g82/GHSA-4g55-4fxv-2g82.json +++ b/advisories/unreviewed/2022/02/GHSA-4g55-4fxv-2g82/GHSA-4g55-4fxv-2g82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-q4hp-w7cp-76mv/GHSA-q4hp-w7cp-76mv.json b/advisories/unreviewed/2022/02/GHSA-q4hp-w7cp-76mv/GHSA-q4hp-w7cp-76mv.json index 95c1b34e4c9..ba1141180ca 100644 --- a/advisories/unreviewed/2022/02/GHSA-q4hp-w7cp-76mv/GHSA-q4hp-w7cp-76mv.json +++ b/advisories/unreviewed/2022/02/GHSA-q4hp-w7cp-76mv/GHSA-q4hp-w7cp-76mv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-86pj-p9q6-88h5/GHSA-86pj-p9q6-88h5.json b/advisories/unreviewed/2022/03/GHSA-86pj-p9q6-88h5/GHSA-86pj-p9q6-88h5.json index 45c779cfce0..8cd100b7bcb 100644 --- a/advisories/unreviewed/2022/03/GHSA-86pj-p9q6-88h5/GHSA-86pj-p9q6-88h5.json +++ b/advisories/unreviewed/2022/03/GHSA-86pj-p9q6-88h5/GHSA-86pj-p9q6-88h5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-j285-2pfr-phwh/GHSA-j285-2pfr-phwh.json b/advisories/unreviewed/2022/03/GHSA-j285-2pfr-phwh/GHSA-j285-2pfr-phwh.json index f8b3a82c5d7..89b45d49456 100644 --- a/advisories/unreviewed/2022/03/GHSA-j285-2pfr-phwh/GHSA-j285-2pfr-phwh.json +++ b/advisories/unreviewed/2022/03/GHSA-j285-2pfr-phwh/GHSA-j285-2pfr-phwh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-p6fp-whjx-7g5m/GHSA-p6fp-whjx-7g5m.json b/advisories/unreviewed/2022/03/GHSA-p6fp-whjx-7g5m/GHSA-p6fp-whjx-7g5m.json index a83789bdd93..7f34db27f82 100644 --- a/advisories/unreviewed/2022/03/GHSA-p6fp-whjx-7g5m/GHSA-p6fp-whjx-7g5m.json +++ b/advisories/unreviewed/2022/03/GHSA-p6fp-whjx-7g5m/GHSA-p6fp-whjx-7g5m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2gc6-xpq3-f7gm/GHSA-2gc6-xpq3-f7gm.json b/advisories/unreviewed/2022/04/GHSA-2gc6-xpq3-f7gm/GHSA-2gc6-xpq3-f7gm.json index 8c14eeba62e..a763cb8256c 100644 --- a/advisories/unreviewed/2022/04/GHSA-2gc6-xpq3-f7gm/GHSA-2gc6-xpq3-f7gm.json +++ b/advisories/unreviewed/2022/04/GHSA-2gc6-xpq3-f7gm/GHSA-2gc6-xpq3-f7gm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6vm3-p7q5-88mf/GHSA-6vm3-p7q5-88mf.json b/advisories/unreviewed/2022/04/GHSA-6vm3-p7q5-88mf/GHSA-6vm3-p7q5-88mf.json index 6254b43a777..1db5e8b4b57 100644 --- a/advisories/unreviewed/2022/04/GHSA-6vm3-p7q5-88mf/GHSA-6vm3-p7q5-88mf.json +++ b/advisories/unreviewed/2022/04/GHSA-6vm3-p7q5-88mf/GHSA-6vm3-p7q5-88mf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hp9h-gmr9-r5h4/GHSA-hp9h-gmr9-r5h4.json b/advisories/unreviewed/2022/04/GHSA-hp9h-gmr9-r5h4/GHSA-hp9h-gmr9-r5h4.json index e0a626a476a..a46b627bc6b 100644 --- a/advisories/unreviewed/2022/04/GHSA-hp9h-gmr9-r5h4/GHSA-hp9h-gmr9-r5h4.json +++ b/advisories/unreviewed/2022/04/GHSA-hp9h-gmr9-r5h4/GHSA-hp9h-gmr9-r5h4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rh37-88v6-qm47/GHSA-rh37-88v6-qm47.json b/advisories/unreviewed/2022/04/GHSA-rh37-88v6-qm47/GHSA-rh37-88v6-qm47.json index 9f8263e90b0..2e64747daa1 100644 --- a/advisories/unreviewed/2022/04/GHSA-rh37-88v6-qm47/GHSA-rh37-88v6-qm47.json +++ b/advisories/unreviewed/2022/04/GHSA-rh37-88v6-qm47/GHSA-rh37-88v6-qm47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-vp88-r9qc-vwrw/GHSA-vp88-r9qc-vwrw.json b/advisories/unreviewed/2022/04/GHSA-vp88-r9qc-vwrw/GHSA-vp88-r9qc-vwrw.json index 3888a2be845..6538122654a 100644 --- a/advisories/unreviewed/2022/04/GHSA-vp88-r9qc-vwrw/GHSA-vp88-r9qc-vwrw.json +++ b/advisories/unreviewed/2022/04/GHSA-vp88-r9qc-vwrw/GHSA-vp88-r9qc-vwrw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-223w-875h-mjqc/GHSA-223w-875h-mjqc.json b/advisories/unreviewed/2022/05/GHSA-223w-875h-mjqc/GHSA-223w-875h-mjqc.json index 317477de79b..bba3f961e8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-223w-875h-mjqc/GHSA-223w-875h-mjqc.json +++ b/advisories/unreviewed/2022/05/GHSA-223w-875h-mjqc/GHSA-223w-875h-mjqc.json @@ -7,12 +7,8 @@ "CVE-2010-4795" ], "details": "SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ev_id parameter in a details action to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22hh-v2f4-4vpg/GHSA-22hh-v2f4-4vpg.json b/advisories/unreviewed/2022/05/GHSA-22hh-v2f4-4vpg/GHSA-22hh-v2f4-4vpg.json index 815f619e890..063ab697968 100644 --- a/advisories/unreviewed/2022/05/GHSA-22hh-v2f4-4vpg/GHSA-22hh-v2f4-4vpg.json +++ b/advisories/unreviewed/2022/05/GHSA-22hh-v2f4-4vpg/GHSA-22hh-v2f4-4vpg.json @@ -7,12 +7,8 @@ "CVE-2011-1865" ], "details": "Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to execute arbitrary code via a request containing crafted parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2394-24xh-gqgr/GHSA-2394-24xh-gqgr.json b/advisories/unreviewed/2022/05/GHSA-2394-24xh-gqgr/GHSA-2394-24xh-gqgr.json index 087580e9a0a..9d600b4fe8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2394-24xh-gqgr/GHSA-2394-24xh-gqgr.json +++ b/advisories/unreviewed/2022/05/GHSA-2394-24xh-gqgr/GHSA-2394-24xh-gqgr.json @@ -7,12 +7,8 @@ "CVE-2010-4433" ], "details": "Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality via unknown vectors related to Ethernet and the Driver sub-component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23qv-956x-w2hr/GHSA-23qv-956x-w2hr.json b/advisories/unreviewed/2022/05/GHSA-23qv-956x-w2hr/GHSA-23qv-956x-w2hr.json index deb9302da42..04e883b998b 100644 --- a/advisories/unreviewed/2022/05/GHSA-23qv-956x-w2hr/GHSA-23qv-956x-w2hr.json +++ b/advisories/unreviewed/2022/05/GHSA-23qv-956x-w2hr/GHSA-23qv-956x-w2hr.json @@ -7,12 +7,8 @@ "CVE-2011-1688" ], "details": "Directory traversal vulnerability in Best Practical Solutions RT 3.2.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote attackers to read arbitrary files via a crafted HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-245h-cphj-6cq7/GHSA-245h-cphj-6cq7.json b/advisories/unreviewed/2022/05/GHSA-245h-cphj-6cq7/GHSA-245h-cphj-6cq7.json index e042d9521bb..3729720fb5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-245h-cphj-6cq7/GHSA-245h-cphj-6cq7.json +++ b/advisories/unreviewed/2022/05/GHSA-245h-cphj-6cq7/GHSA-245h-cphj-6cq7.json @@ -7,12 +7,8 @@ "CVE-2010-4757" ], "details": "Cross-site scripting (XSS) vulnerability in submitnews.php in e107 before 0.7.23 allows remote attackers to inject arbitrary web script or HTML via the submitnews_title parameter, a different vector than CVE-2008-6208. NOTE: some of these details are obtained from third party information. NOTE: this might be the same as CVE-2009-4083.1 or CVE-2011-0457.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-246p-f5jm-57hh/GHSA-246p-f5jm-57hh.json b/advisories/unreviewed/2022/05/GHSA-246p-f5jm-57hh/GHSA-246p-f5jm-57hh.json index 523f0e317ce..32159ef28e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-246p-f5jm-57hh/GHSA-246p-f5jm-57hh.json +++ b/advisories/unreviewed/2022/05/GHSA-246p-f5jm-57hh/GHSA-246p-f5jm-57hh.json @@ -7,12 +7,8 @@ "CVE-2011-1208" ], "details": "IBM solidDB 4.5.x before 4.5.182, 6.0.x before 6.0.1069, 6.1.x and 6.3.x before 6.3 FP8 (aka 6.3.49), and 6.5.x before 6.5 FP4 (aka 6.5.0.4) does not properly handle the (1) rpc_test_svc_readwrite and (2) rpc_test_svc_done commands, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24f2-v9rg-22q2/GHSA-24f2-v9rg-22q2.json b/advisories/unreviewed/2022/05/GHSA-24f2-v9rg-22q2/GHSA-24f2-v9rg-22q2.json index 67581fbcb94..f4db089f69a 100644 --- a/advisories/unreviewed/2022/05/GHSA-24f2-v9rg-22q2/GHSA-24f2-v9rg-22q2.json +++ b/advisories/unreviewed/2022/05/GHSA-24f2-v9rg-22q2/GHSA-24f2-v9rg-22q2.json @@ -7,12 +7,8 @@ "CVE-2011-1689" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24p2-hmff-5vm2/GHSA-24p2-hmff-5vm2.json b/advisories/unreviewed/2022/05/GHSA-24p2-hmff-5vm2/GHSA-24p2-hmff-5vm2.json index 490fe75f43a..1bd2da403e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-24p2-hmff-5vm2/GHSA-24p2-hmff-5vm2.json +++ b/advisories/unreviewed/2022/05/GHSA-24p2-hmff-5vm2/GHSA-24p2-hmff-5vm2.json @@ -7,12 +7,8 @@ "CVE-2011-0902" ], "details": "Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 allow local users to execute arbitrary code via a modified (1) PATH or (2) LD_LIBRARY_PATH environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24px-fh32-jvj7/GHSA-24px-fh32-jvj7.json b/advisories/unreviewed/2022/05/GHSA-24px-fh32-jvj7/GHSA-24px-fh32-jvj7.json index 561370eae04..997320b3390 100644 --- a/advisories/unreviewed/2022/05/GHSA-24px-fh32-jvj7/GHSA-24px-fh32-jvj7.json +++ b/advisories/unreviewed/2022/05/GHSA-24px-fh32-jvj7/GHSA-24px-fh32-jvj7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26qm-2594-mccv/GHSA-26qm-2594-mccv.json b/advisories/unreviewed/2022/05/GHSA-26qm-2594-mccv/GHSA-26qm-2594-mccv.json index 3560d034089..83c2fe52229 100644 --- a/advisories/unreviewed/2022/05/GHSA-26qm-2594-mccv/GHSA-26qm-2594-mccv.json +++ b/advisories/unreviewed/2022/05/GHSA-26qm-2594-mccv/GHSA-26qm-2594-mccv.json @@ -7,12 +7,8 @@ "CVE-2011-1029" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-274r-p6v6-fhh4/GHSA-274r-p6v6-fhh4.json b/advisories/unreviewed/2022/05/GHSA-274r-p6v6-fhh4/GHSA-274r-p6v6-fhh4.json index 8f8772dd691..46f7884a267 100644 --- a/advisories/unreviewed/2022/05/GHSA-274r-p6v6-fhh4/GHSA-274r-p6v6-fhh4.json +++ b/advisories/unreviewed/2022/05/GHSA-274r-p6v6-fhh4/GHSA-274r-p6v6-fhh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-279h-w9gh-fpvc/GHSA-279h-w9gh-fpvc.json b/advisories/unreviewed/2022/05/GHSA-279h-w9gh-fpvc/GHSA-279h-w9gh-fpvc.json index 79108789cde..2a1c4f54673 100644 --- a/advisories/unreviewed/2022/05/GHSA-279h-w9gh-fpvc/GHSA-279h-w9gh-fpvc.json +++ b/advisories/unreviewed/2022/05/GHSA-279h-w9gh-fpvc/GHSA-279h-w9gh-fpvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28wv-3g38-px4r/GHSA-28wv-3g38-px4r.json b/advisories/unreviewed/2022/05/GHSA-28wv-3g38-px4r/GHSA-28wv-3g38-px4r.json index dce431c72d7..6c71872d769 100644 --- a/advisories/unreviewed/2022/05/GHSA-28wv-3g38-px4r/GHSA-28wv-3g38-px4r.json +++ b/advisories/unreviewed/2022/05/GHSA-28wv-3g38-px4r/GHSA-28wv-3g38-px4r.json @@ -7,12 +7,8 @@ "CVE-2011-1392" ], "details": "The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29f9-3r2g-rwg5/GHSA-29f9-3r2g-rwg5.json b/advisories/unreviewed/2022/05/GHSA-29f9-3r2g-rwg5/GHSA-29f9-3r2g-rwg5.json index ee2d2ac79fa..dd92af785df 100644 --- a/advisories/unreviewed/2022/05/GHSA-29f9-3r2g-rwg5/GHSA-29f9-3r2g-rwg5.json +++ b/advisories/unreviewed/2022/05/GHSA-29f9-3r2g-rwg5/GHSA-29f9-3r2g-rwg5.json @@ -7,12 +7,8 @@ "CVE-2011-1607" ], "details": "Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote authenticated users to upload files to arbitrary directories via a modified pathname in an upload request, aka Bug ID CSCti81603.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c4f-33fr-h9q2/GHSA-2c4f-33fr-h9q2.json b/advisories/unreviewed/2022/05/GHSA-2c4f-33fr-h9q2/GHSA-2c4f-33fr-h9q2.json index 34ba1b0953f..66d35efee17 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c4f-33fr-h9q2/GHSA-2c4f-33fr-h9q2.json +++ b/advisories/unreviewed/2022/05/GHSA-2c4f-33fr-h9q2/GHSA-2c4f-33fr-h9q2.json @@ -7,12 +7,8 @@ "CVE-2011-0391" ], "details": "Cisco TelePresence Recording Server devices with software 1.6.x allow remote attackers to cause a denial of service (thread consumption and device outage) via a malformed request, related to an \"ad hoc recording\" issue, aka Bug ID CSCtf97205.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2c7m-3xrp-8qgf/GHSA-2c7m-3xrp-8qgf.json b/advisories/unreviewed/2022/05/GHSA-2c7m-3xrp-8qgf/GHSA-2c7m-3xrp-8qgf.json index 91f4fcdcf37..4d5c54fec20 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c7m-3xrp-8qgf/GHSA-2c7m-3xrp-8qgf.json +++ b/advisories/unreviewed/2022/05/GHSA-2c7m-3xrp-8qgf/GHSA-2c7m-3xrp-8qgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2ch2-m5qc-grp2/GHSA-2ch2-m5qc-grp2.json b/advisories/unreviewed/2022/05/GHSA-2ch2-m5qc-grp2/GHSA-2ch2-m5qc-grp2.json index b55a4aba318..a2fe6dfcd86 100644 --- a/advisories/unreviewed/2022/05/GHSA-2ch2-m5qc-grp2/GHSA-2ch2-m5qc-grp2.json +++ b/advisories/unreviewed/2022/05/GHSA-2ch2-m5qc-grp2/GHSA-2ch2-m5qc-grp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fcg-5wrc-pm23/GHSA-2fcg-5wrc-pm23.json b/advisories/unreviewed/2022/05/GHSA-2fcg-5wrc-pm23/GHSA-2fcg-5wrc-pm23.json index 33d0463d865..2d16946a0af 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fcg-5wrc-pm23/GHSA-2fcg-5wrc-pm23.json +++ b/advisories/unreviewed/2022/05/GHSA-2fcg-5wrc-pm23/GHSA-2fcg-5wrc-pm23.json @@ -7,12 +7,8 @@ "CVE-2011-0275" ], "details": "Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2fr9-r8v5-x2h3/GHSA-2fr9-r8v5-x2h3.json b/advisories/unreviewed/2022/05/GHSA-2fr9-r8v5-x2h3/GHSA-2fr9-r8v5-x2h3.json index 86fe3a994fa..9f19adb4f2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fr9-r8v5-x2h3/GHSA-2fr9-r8v5-x2h3.json +++ b/advisories/unreviewed/2022/05/GHSA-2fr9-r8v5-x2h3/GHSA-2fr9-r8v5-x2h3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2gwh-vr5q-hm52/GHSA-2gwh-vr5q-hm52.json b/advisories/unreviewed/2022/05/GHSA-2gwh-vr5q-hm52/GHSA-2gwh-vr5q-hm52.json index 9eb9536505e..8976150225e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gwh-vr5q-hm52/GHSA-2gwh-vr5q-hm52.json +++ b/advisories/unreviewed/2022/05/GHSA-2gwh-vr5q-hm52/GHSA-2gwh-vr5q-hm52.json @@ -7,12 +7,8 @@ "CVE-2011-0348" ], "details": "Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2h7r-8m29-9xgp/GHSA-2h7r-8m29-9xgp.json b/advisories/unreviewed/2022/05/GHSA-2h7r-8m29-9xgp/GHSA-2h7r-8m29-9xgp.json index a36748336bd..9d7dd68e973 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h7r-8m29-9xgp/GHSA-2h7r-8m29-9xgp.json +++ b/advisories/unreviewed/2022/05/GHSA-2h7r-8m29-9xgp/GHSA-2h7r-8m29-9xgp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2m5p-7g2f-f542/GHSA-2m5p-7g2f-f542.json b/advisories/unreviewed/2022/05/GHSA-2m5p-7g2f-f542/GHSA-2m5p-7g2f-f542.json index 594663c8cec..c9ba0cdde42 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m5p-7g2f-f542/GHSA-2m5p-7g2f-f542.json +++ b/advisories/unreviewed/2022/05/GHSA-2m5p-7g2f-f542/GHSA-2m5p-7g2f-f542.json @@ -7,12 +7,8 @@ "CVE-2011-0680" ], "details": "data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via a standard text messaging service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2p6p-7p5q-rwp9/GHSA-2p6p-7p5q-rwp9.json b/advisories/unreviewed/2022/05/GHSA-2p6p-7p5q-rwp9/GHSA-2p6p-7p5q-rwp9.json index 2a464e72c1a..516619e4116 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p6p-7p5q-rwp9/GHSA-2p6p-7p5q-rwp9.json +++ b/advisories/unreviewed/2022/05/GHSA-2p6p-7p5q-rwp9/GHSA-2p6p-7p5q-rwp9.json @@ -7,12 +7,8 @@ "CVE-2011-0637" ], "details": "The FC SCSI protocol driver in IBM AIX 6.1 does not verify that a timer is unused before deallocating this timer, which might allow attackers to cause a denial of service (system crash) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2pqx-426g-hrmc/GHSA-2pqx-426g-hrmc.json b/advisories/unreviewed/2022/05/GHSA-2pqx-426g-hrmc/GHSA-2pqx-426g-hrmc.json index 205af67778c..e47f11d4c14 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pqx-426g-hrmc/GHSA-2pqx-426g-hrmc.json +++ b/advisories/unreviewed/2022/05/GHSA-2pqx-426g-hrmc/GHSA-2pqx-426g-hrmc.json @@ -7,12 +7,8 @@ "CVE-2011-1384" ], "details": "The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r7g-chxq-57q7/GHSA-2r7g-chxq-57q7.json b/advisories/unreviewed/2022/05/GHSA-2r7g-chxq-57q7/GHSA-2r7g-chxq-57q7.json index f2ea09ccaeb..925dd5e2702 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r7g-chxq-57q7/GHSA-2r7g-chxq-57q7.json +++ b/advisories/unreviewed/2022/05/GHSA-2r7g-chxq-57q7/GHSA-2r7g-chxq-57q7.json @@ -7,12 +7,8 @@ "CVE-2010-3042" ], "details": "Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, a different vulnerability than CVE-2010-3041, CVE-2010-3043, and CVE-2010-3044.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r8x-hfx4-m6x7/GHSA-2r8x-hfx4-m6x7.json b/advisories/unreviewed/2022/05/GHSA-2r8x-hfx4-m6x7/GHSA-2r8x-hfx4-m6x7.json index a4c3c9e5ff1..4f74a3f303a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r8x-hfx4-m6x7/GHSA-2r8x-hfx4-m6x7.json +++ b/advisories/unreviewed/2022/05/GHSA-2r8x-hfx4-m6x7/GHSA-2r8x-hfx4-m6x7.json @@ -7,12 +7,8 @@ "CVE-2011-1389" ], "details": "Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-4135.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rcq-q564-ppc9/GHSA-2rcq-q564-ppc9.json b/advisories/unreviewed/2022/05/GHSA-2rcq-q564-ppc9/GHSA-2rcq-q564-ppc9.json index b828f6b2ef7..2482172e028 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rcq-q564-ppc9/GHSA-2rcq-q564-ppc9.json +++ b/advisories/unreviewed/2022/05/GHSA-2rcq-q564-ppc9/GHSA-2rcq-q564-ppc9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rv6-295f-xw2p/GHSA-2rv6-295f-xw2p.json b/advisories/unreviewed/2022/05/GHSA-2rv6-295f-xw2p/GHSA-2rv6-295f-xw2p.json index 95a9f0b4adf..89411f9113a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rv6-295f-xw2p/GHSA-2rv6-295f-xw2p.json +++ b/advisories/unreviewed/2022/05/GHSA-2rv6-295f-xw2p/GHSA-2rv6-295f-xw2p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v69-c83c-r4mh/GHSA-2v69-c83c-r4mh.json b/advisories/unreviewed/2022/05/GHSA-2v69-c83c-r4mh/GHSA-2v69-c83c-r4mh.json index 81b2de18259..e6e0da87bb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v69-c83c-r4mh/GHSA-2v69-c83c-r4mh.json +++ b/advisories/unreviewed/2022/05/GHSA-2v69-c83c-r4mh/GHSA-2v69-c83c-r4mh.json @@ -7,12 +7,8 @@ "CVE-2011-0427" ], "details": "Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vc9-3j28-9rcg/GHSA-2vc9-3j28-9rcg.json b/advisories/unreviewed/2022/05/GHSA-2vc9-3j28-9rcg/GHSA-2vc9-3j28-9rcg.json index 74f20d5c18d..6f7f6e60d1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vc9-3j28-9rcg/GHSA-2vc9-3j28-9rcg.json +++ b/advisories/unreviewed/2022/05/GHSA-2vc9-3j28-9rcg/GHSA-2vc9-3j28-9rcg.json @@ -7,12 +7,8 @@ "CVE-2011-1913" ], "details": "SQL injection vulnerability in the login form in the web interface in Mercator SENTINEL 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vfp-2qpf-jwrq/GHSA-2vfp-2qpf-jwrq.json b/advisories/unreviewed/2022/05/GHSA-2vfp-2qpf-jwrq/GHSA-2vfp-2qpf-jwrq.json index 8c30ef2c3cc..52fd24b7b6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vfp-2qpf-jwrq/GHSA-2vfp-2qpf-jwrq.json +++ b/advisories/unreviewed/2022/05/GHSA-2vfp-2qpf-jwrq/GHSA-2vfp-2qpf-jwrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w6p-6qgj-jpgr/GHSA-2w6p-6qgj-jpgr.json b/advisories/unreviewed/2022/05/GHSA-2w6p-6qgj-jpgr/GHSA-2w6p-6qgj-jpgr.json index 111a5f0ba9f..6ffa2c6ed6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w6p-6qgj-jpgr/GHSA-2w6p-6qgj-jpgr.json +++ b/advisories/unreviewed/2022/05/GHSA-2w6p-6qgj-jpgr/GHSA-2w6p-6qgj-jpgr.json @@ -7,12 +7,8 @@ "CVE-2011-0267" ], "details": "Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attackers to execute arbitrary code via a long (1) schdParams or (2) nameParams parameter, a different vulnerability than CVE-2011-0266.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wgh-cg2p-67mv/GHSA-2wgh-cg2p-67mv.json b/advisories/unreviewed/2022/05/GHSA-2wgh-cg2p-67mv/GHSA-2wgh-cg2p-67mv.json index 587fdb414cc..26e03c107b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wgh-cg2p-67mv/GHSA-2wgh-cg2p-67mv.json +++ b/advisories/unreviewed/2022/05/GHSA-2wgh-cg2p-67mv/GHSA-2wgh-cg2p-67mv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3232-c8xr-84gw/GHSA-3232-c8xr-84gw.json b/advisories/unreviewed/2022/05/GHSA-3232-c8xr-84gw/GHSA-3232-c8xr-84gw.json index 82289fa8861..e5a1672feac 100644 --- a/advisories/unreviewed/2022/05/GHSA-3232-c8xr-84gw/GHSA-3232-c8xr-84gw.json +++ b/advisories/unreviewed/2022/05/GHSA-3232-c8xr-84gw/GHSA-3232-c8xr-84gw.json @@ -7,12 +7,8 @@ "CVE-2010-3028" ], "details": "The Aardvertiser component before 2.2.1 for Joomla! uses insecure permissions (777) in unspecified folders, which allows local users to modify, create, or delete certain files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-335j-8h73-qjmc/GHSA-335j-8h73-qjmc.json b/advisories/unreviewed/2022/05/GHSA-335j-8h73-qjmc/GHSA-335j-8h73-qjmc.json index a43151f007c..9bf583c389c 100644 --- a/advisories/unreviewed/2022/05/GHSA-335j-8h73-qjmc/GHSA-335j-8h73-qjmc.json +++ b/advisories/unreviewed/2022/05/GHSA-335j-8h73-qjmc/GHSA-335j-8h73-qjmc.json @@ -7,12 +7,8 @@ "CVE-2011-1103" ], "details": "The WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before hotfix 4 on Windows and hotfix 2 on Linux, allows remote attackers to obtain sensitive information via a request to an invalid report, which reveals the installation path in an error message, as demonstrated with requests to (1) report/infection-table.html or (2) report/productsummary-table.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3389-w97w-jqjj/GHSA-3389-w97w-jqjj.json b/advisories/unreviewed/2022/05/GHSA-3389-w97w-jqjj/GHSA-3389-w97w-jqjj.json index 8d1a8829763..7c5f5e8dce3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3389-w97w-jqjj/GHSA-3389-w97w-jqjj.json +++ b/advisories/unreviewed/2022/05/GHSA-3389-w97w-jqjj/GHSA-3389-w97w-jqjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-339v-wcxr-4xwf/GHSA-339v-wcxr-4xwf.json b/advisories/unreviewed/2022/05/GHSA-339v-wcxr-4xwf/GHSA-339v-wcxr-4xwf.json index ab7a3cd8be9..5f980d0ff08 100644 --- a/advisories/unreviewed/2022/05/GHSA-339v-wcxr-4xwf/GHSA-339v-wcxr-4xwf.json +++ b/advisories/unreviewed/2022/05/GHSA-339v-wcxr-4xwf/GHSA-339v-wcxr-4xwf.json @@ -7,12 +7,8 @@ "CVE-2011-1386" ], "details": "IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35cw-298h-r635/GHSA-35cw-298h-r635.json b/advisories/unreviewed/2022/05/GHSA-35cw-298h-r635/GHSA-35cw-298h-r635.json index 8072cad6339..069d0383cb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-35cw-298h-r635/GHSA-35cw-298h-r635.json +++ b/advisories/unreviewed/2022/05/GHSA-35cw-298h-r635/GHSA-35cw-298h-r635.json @@ -7,12 +7,8 @@ "CVE-2011-1753" ], "details": "expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35h4-3q56-pc46/GHSA-35h4-3q56-pc46.json b/advisories/unreviewed/2022/05/GHSA-35h4-3q56-pc46/GHSA-35h4-3q56-pc46.json index 003afd8a8d5..6ab81d66279 100644 --- a/advisories/unreviewed/2022/05/GHSA-35h4-3q56-pc46/GHSA-35h4-3q56-pc46.json +++ b/advisories/unreviewed/2022/05/GHSA-35h4-3q56-pc46/GHSA-35h4-3q56-pc46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35hp-gw4q-r3gw/GHSA-35hp-gw4q-r3gw.json b/advisories/unreviewed/2022/05/GHSA-35hp-gw4q-r3gw/GHSA-35hp-gw4q-r3gw.json index 264b5198829..e66ba5f5724 100644 --- a/advisories/unreviewed/2022/05/GHSA-35hp-gw4q-r3gw/GHSA-35hp-gw4q-r3gw.json +++ b/advisories/unreviewed/2022/05/GHSA-35hp-gw4q-r3gw/GHSA-35hp-gw4q-r3gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35v8-x66v-gw3q/GHSA-35v8-x66v-gw3q.json b/advisories/unreviewed/2022/05/GHSA-35v8-x66v-gw3q/GHSA-35v8-x66v-gw3q.json index 74ce3afa116..ae46e3762be 100644 --- a/advisories/unreviewed/2022/05/GHSA-35v8-x66v-gw3q/GHSA-35v8-x66v-gw3q.json +++ b/advisories/unreviewed/2022/05/GHSA-35v8-x66v-gw3q/GHSA-35v8-x66v-gw3q.json @@ -7,12 +7,8 @@ "CVE-2011-0989" ], "details": "The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which allows remote attackers to modify internal read-only data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file, as demonstrated by modifying a C# struct.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-36hv-fqvj-3wq3/GHSA-36hv-fqvj-3wq3.json b/advisories/unreviewed/2022/05/GHSA-36hv-fqvj-3wq3/GHSA-36hv-fqvj-3wq3.json index ba2b8d28b94..354b7aa7fb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-36hv-fqvj-3wq3/GHSA-36hv-fqvj-3wq3.json +++ b/advisories/unreviewed/2022/05/GHSA-36hv-fqvj-3wq3/GHSA-36hv-fqvj-3wq3.json @@ -7,12 +7,8 @@ "CVE-2011-0987" ], "details": "The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37j2-4mf7-p7r4/GHSA-37j2-4mf7-p7r4.json b/advisories/unreviewed/2022/05/GHSA-37j2-4mf7-p7r4/GHSA-37j2-4mf7-p7r4.json index a2b776ebbcc..04295f14909 100644 --- a/advisories/unreviewed/2022/05/GHSA-37j2-4mf7-p7r4/GHSA-37j2-4mf7-p7r4.json +++ b/advisories/unreviewed/2022/05/GHSA-37j2-4mf7-p7r4/GHSA-37j2-4mf7-p7r4.json @@ -7,12 +7,8 @@ "CVE-2011-1326" ], "details": "Unspecified vulnerability on the La Fonera+ router with firmware before 1.7.0.1 allows remote attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-37pv-7pr3-8rcc/GHSA-37pv-7pr3-8rcc.json b/advisories/unreviewed/2022/05/GHSA-37pv-7pr3-8rcc/GHSA-37pv-7pr3-8rcc.json index 07a7b51d62b..18e3268ae69 100644 --- a/advisories/unreviewed/2022/05/GHSA-37pv-7pr3-8rcc/GHSA-37pv-7pr3-8rcc.json +++ b/advisories/unreviewed/2022/05/GHSA-37pv-7pr3-8rcc/GHSA-37pv-7pr3-8rcc.json @@ -7,12 +7,8 @@ "CVE-2010-4801" ], "details": "Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filepath parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37r4-8c9f-fpvp/GHSA-37r4-8c9f-fpvp.json b/advisories/unreviewed/2022/05/GHSA-37r4-8c9f-fpvp/GHSA-37r4-8c9f-fpvp.json index 147b7c36fb7..5d96b2c4133 100644 --- a/advisories/unreviewed/2022/05/GHSA-37r4-8c9f-fpvp/GHSA-37r4-8c9f-fpvp.json +++ b/advisories/unreviewed/2022/05/GHSA-37r4-8c9f-fpvp/GHSA-37r4-8c9f-fpvp.json @@ -7,12 +7,8 @@ "CVE-2011-0584" ], "details": "Session fixation vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to hijack web sessions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-386v-w8vv-pcqx/GHSA-386v-w8vv-pcqx.json b/advisories/unreviewed/2022/05/GHSA-386v-w8vv-pcqx/GHSA-386v-w8vv-pcqx.json index f2173b11529..d2f2876c6a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-386v-w8vv-pcqx/GHSA-386v-w8vv-pcqx.json +++ b/advisories/unreviewed/2022/05/GHSA-386v-w8vv-pcqx/GHSA-386v-w8vv-pcqx.json @@ -7,12 +7,8 @@ "CVE-2010-4709" ], "details": "Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a MODBUS response packet with a crafted length field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38gq-f4qx-7pmw/GHSA-38gq-f4qx-7pmw.json b/advisories/unreviewed/2022/05/GHSA-38gq-f4qx-7pmw/GHSA-38gq-f4qx-7pmw.json index a8bcb61af44..70c000b69f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-38gq-f4qx-7pmw/GHSA-38gq-f4qx-7pmw.json +++ b/advisories/unreviewed/2022/05/GHSA-38gq-f4qx-7pmw/GHSA-38gq-f4qx-7pmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-395x-3x8q-mv38/GHSA-395x-3x8q-mv38.json b/advisories/unreviewed/2022/05/GHSA-395x-3x8q-mv38/GHSA-395x-3x8q-mv38.json index 80e8db5c3b1..c429f4984a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-395x-3x8q-mv38/GHSA-395x-3x8q-mv38.json +++ b/advisories/unreviewed/2022/05/GHSA-395x-3x8q-mv38/GHSA-395x-3x8q-mv38.json @@ -7,12 +7,8 @@ "CVE-2011-0539" ], "details": "The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39j6-mhhv-2qpx/GHSA-39j6-mhhv-2qpx.json b/advisories/unreviewed/2022/05/GHSA-39j6-mhhv-2qpx/GHSA-39j6-mhhv-2qpx.json index 145218ac932..4bf52f8a978 100644 --- a/advisories/unreviewed/2022/05/GHSA-39j6-mhhv-2qpx/GHSA-39j6-mhhv-2qpx.json +++ b/advisories/unreviewed/2022/05/GHSA-39j6-mhhv-2qpx/GHSA-39j6-mhhv-2qpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-39r3-j54m-rvh3/GHSA-39r3-j54m-rvh3.json b/advisories/unreviewed/2022/05/GHSA-39r3-j54m-rvh3/GHSA-39r3-j54m-rvh3.json index 7b9318b5f3f..a35fc95bccc 100644 --- a/advisories/unreviewed/2022/05/GHSA-39r3-j54m-rvh3/GHSA-39r3-j54m-rvh3.json +++ b/advisories/unreviewed/2022/05/GHSA-39r3-j54m-rvh3/GHSA-39r3-j54m-rvh3.json @@ -7,12 +7,8 @@ "CVE-2010-4646" ], "details": "Cross-site scripting (XSS) vulnerability in Hastymail2 before 1.01 allows remote attackers to inject arbitrary web script or HTML via a crafted background attribute within a cell in a TABLE element, related to improper use of the htmLawed filter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3ff6-3j6w-48qf/GHSA-3ff6-3j6w-48qf.json b/advisories/unreviewed/2022/05/GHSA-3ff6-3j6w-48qf/GHSA-3ff6-3j6w-48qf.json index 1950187ff58..4f6a94c8a4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ff6-3j6w-48qf/GHSA-3ff6-3j6w-48qf.json +++ b/advisories/unreviewed/2022/05/GHSA-3ff6-3j6w-48qf/GHSA-3ff6-3j6w-48qf.json @@ -7,12 +7,8 @@ "CVE-2010-4415" ], "details": "Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to libc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fjv-whfc-w3gr/GHSA-3fjv-whfc-w3gr.json b/advisories/unreviewed/2022/05/GHSA-3fjv-whfc-w3gr/GHSA-3fjv-whfc-w3gr.json index c31b8c244cb..271d967c105 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fjv-whfc-w3gr/GHSA-3fjv-whfc-w3gr.json +++ b/advisories/unreviewed/2022/05/GHSA-3fjv-whfc-w3gr/GHSA-3fjv-whfc-w3gr.json @@ -7,12 +7,8 @@ "CVE-2011-1682" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fm3-mfvv-cwx4/GHSA-3fm3-mfvv-cwx4.json b/advisories/unreviewed/2022/05/GHSA-3fm3-mfvv-cwx4/GHSA-3fm3-mfvv-cwx4.json index 64a2a82d10b..797a0f0850a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fm3-mfvv-cwx4/GHSA-3fm3-mfvv-cwx4.json +++ b/advisories/unreviewed/2022/05/GHSA-3fm3-mfvv-cwx4/GHSA-3fm3-mfvv-cwx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3h7f-5q54-4v2g/GHSA-3h7f-5q54-4v2g.json b/advisories/unreviewed/2022/05/GHSA-3h7f-5q54-4v2g/GHSA-3h7f-5q54-4v2g.json index 9183d9b4e4a..93c4f70296b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h7f-5q54-4v2g/GHSA-3h7f-5q54-4v2g.json +++ b/advisories/unreviewed/2022/05/GHSA-3h7f-5q54-4v2g/GHSA-3h7f-5q54-4v2g.json @@ -7,12 +7,8 @@ "CVE-2011-0496" ], "details": "Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a \"design vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3h7j-mv2q-qm4h/GHSA-3h7j-mv2q-qm4h.json b/advisories/unreviewed/2022/05/GHSA-3h7j-mv2q-qm4h/GHSA-3h7j-mv2q-qm4h.json index 5e0cb4bb2f8..188c06de41d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h7j-mv2q-qm4h/GHSA-3h7j-mv2q-qm4h.json +++ b/advisories/unreviewed/2022/05/GHSA-3h7j-mv2q-qm4h/GHSA-3h7j-mv2q-qm4h.json @@ -7,12 +7,8 @@ "CVE-2011-0350" ], "details": "Unspecified vulnerability in Cisco IOS 12.4(24)MD before 12.4(24)MD2 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to cause a denial of service (device hang or reload) via crafted TCP packets, aka Bug ID CSCth41891, a different vulnerability than CVE-2011-0349.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3hj2-5cwp-2349/GHSA-3hj2-5cwp-2349.json b/advisories/unreviewed/2022/05/GHSA-3hj2-5cwp-2349/GHSA-3hj2-5cwp-2349.json index ec19375e161..6e6ba3bce17 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hj2-5cwp-2349/GHSA-3hj2-5cwp-2349.json +++ b/advisories/unreviewed/2022/05/GHSA-3hj2-5cwp-2349/GHSA-3hj2-5cwp-2349.json @@ -7,12 +7,8 @@ "CVE-2011-1823" ], "details": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jfh-c76q-4r5j/GHSA-3jfh-c76q-4r5j.json b/advisories/unreviewed/2022/05/GHSA-3jfh-c76q-4r5j/GHSA-3jfh-c76q-4r5j.json index 9de7b98cd01..748dcbbb7ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jfh-c76q-4r5j/GHSA-3jfh-c76q-4r5j.json +++ b/advisories/unreviewed/2022/05/GHSA-3jfh-c76q-4r5j/GHSA-3jfh-c76q-4r5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jvh-qjxv-65c8/GHSA-3jvh-qjxv-65c8.json b/advisories/unreviewed/2022/05/GHSA-3jvh-qjxv-65c8/GHSA-3jvh-qjxv-65c8.json index fa02e65cda1..b735ea1a3f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jvh-qjxv-65c8/GHSA-3jvh-qjxv-65c8.json +++ b/advisories/unreviewed/2022/05/GHSA-3jvh-qjxv-65c8/GHSA-3jvh-qjxv-65c8.json @@ -7,12 +7,8 @@ "CVE-2010-3208" ], "details": "Cross-site scripting (XSS) vulnerability in ajax.php in Wiccle Web Builder (WWB) 1.00 and 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the post_text parameter in a site custom_search action to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jwh-g84j-75mq/GHSA-3jwh-g84j-75mq.json b/advisories/unreviewed/2022/05/GHSA-3jwh-g84j-75mq/GHSA-3jwh-g84j-75mq.json index 12739069b82..910a7aea7f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jwh-g84j-75mq/GHSA-3jwh-g84j-75mq.json +++ b/advisories/unreviewed/2022/05/GHSA-3jwh-g84j-75mq/GHSA-3jwh-g84j-75mq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mjj-j5cv-mf5p/GHSA-3mjj-j5cv-mf5p.json b/advisories/unreviewed/2022/05/GHSA-3mjj-j5cv-mf5p/GHSA-3mjj-j5cv-mf5p.json index e51fe0182f1..8bcddd294ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mjj-j5cv-mf5p/GHSA-3mjj-j5cv-mf5p.json +++ b/advisories/unreviewed/2022/05/GHSA-3mjj-j5cv-mf5p/GHSA-3mjj-j5cv-mf5p.json @@ -7,12 +7,8 @@ "CVE-2011-0643" ], "details": "Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3ppj-x7p7-vph2/GHSA-3ppj-x7p7-vph2.json b/advisories/unreviewed/2022/05/GHSA-3ppj-x7p7-vph2/GHSA-3ppj-x7p7-vph2.json index e0bb29c2e16..272af4dd9be 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ppj-x7p7-vph2/GHSA-3ppj-x7p7-vph2.json +++ b/advisories/unreviewed/2022/05/GHSA-3ppj-x7p7-vph2/GHSA-3ppj-x7p7-vph2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pvf-vxc3-wr36/GHSA-3pvf-vxc3-wr36.json b/advisories/unreviewed/2022/05/GHSA-3pvf-vxc3-wr36/GHSA-3pvf-vxc3-wr36.json index df09491fd1d..2841b259a81 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pvf-vxc3-wr36/GHSA-3pvf-vxc3-wr36.json +++ b/advisories/unreviewed/2022/05/GHSA-3pvf-vxc3-wr36/GHSA-3pvf-vxc3-wr36.json @@ -7,12 +7,8 @@ "CVE-2011-0642" ], "details": "Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qfx-62r9-w7q6/GHSA-3qfx-62r9-w7q6.json b/advisories/unreviewed/2022/05/GHSA-3qfx-62r9-w7q6/GHSA-3qfx-62r9-w7q6.json index c4bff299426..9351ec3b6eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qfx-62r9-w7q6/GHSA-3qfx-62r9-w7q6.json +++ b/advisories/unreviewed/2022/05/GHSA-3qfx-62r9-w7q6/GHSA-3qfx-62r9-w7q6.json @@ -7,12 +7,8 @@ "CVE-2011-0725" ], "details": "Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local users to read arbitrary files via a full pathname in the sources_list argument, related to the D-Bus interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qwg-qhg3-83g6/GHSA-3qwg-qhg3-83g6.json b/advisories/unreviewed/2022/05/GHSA-3qwg-qhg3-83g6/GHSA-3qwg-qhg3-83g6.json index 853bffac9d9..782d72a823b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qwg-qhg3-83g6/GHSA-3qwg-qhg3-83g6.json +++ b/advisories/unreviewed/2022/05/GHSA-3qwg-qhg3-83g6/GHSA-3qwg-qhg3-83g6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qxq-5jcx-g5cg/GHSA-3qxq-5jcx-g5cg.json b/advisories/unreviewed/2022/05/GHSA-3qxq-5jcx-g5cg/GHSA-3qxq-5jcx-g5cg.json index 78ff7a5920f..4ac5263b49b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qxq-5jcx-g5cg/GHSA-3qxq-5jcx-g5cg.json +++ b/advisories/unreviewed/2022/05/GHSA-3qxq-5jcx-g5cg/GHSA-3qxq-5jcx-g5cg.json @@ -7,12 +7,8 @@ "CVE-2011-0645" ], "details": "SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time parameter in a get action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3r4f-8jgm-m5g9/GHSA-3r4f-8jgm-m5g9.json b/advisories/unreviewed/2022/05/GHSA-3r4f-8jgm-m5g9/GHSA-3r4f-8jgm-m5g9.json index 5dddeb0ba39..313bd484905 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r4f-8jgm-m5g9/GHSA-3r4f-8jgm-m5g9.json +++ b/advisories/unreviewed/2022/05/GHSA-3r4f-8jgm-m5g9/GHSA-3r4f-8jgm-m5g9.json @@ -7,12 +7,8 @@ "CVE-2011-1788" ], "details": "vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vm3-7j4f-rg76/GHSA-3vm3-7j4f-rg76.json b/advisories/unreviewed/2022/05/GHSA-3vm3-7j4f-rg76/GHSA-3vm3-7j4f-rg76.json index 4efeac15efa..e67c0feddb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vm3-7j4f-rg76/GHSA-3vm3-7j4f-rg76.json +++ b/advisories/unreviewed/2022/05/GHSA-3vm3-7j4f-rg76/GHSA-3vm3-7j4f-rg76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vr3-73ff-f37h/GHSA-3vr3-73ff-f37h.json b/advisories/unreviewed/2022/05/GHSA-3vr3-73ff-f37h/GHSA-3vr3-73ff-f37h.json index 50ddc2406d1..486ac5fc921 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vr3-73ff-f37h/GHSA-3vr3-73ff-f37h.json +++ b/advisories/unreviewed/2022/05/GHSA-3vr3-73ff-f37h/GHSA-3vr3-73ff-f37h.json @@ -7,12 +7,8 @@ "CVE-2011-0265" ], "details": "Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long data_select1 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vrj-vr67-c34w/GHSA-3vrj-vr67-c34w.json b/advisories/unreviewed/2022/05/GHSA-3vrj-vr67-c34w/GHSA-3vrj-vr67-c34w.json index bbe024f8238..caad5d76073 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vrj-vr67-c34w/GHSA-3vrj-vr67-c34w.json +++ b/advisories/unreviewed/2022/05/GHSA-3vrj-vr67-c34w/GHSA-3vrj-vr67-c34w.json @@ -7,12 +7,8 @@ "CVE-2010-3372" ], "details": "Untrusted search path vulnerability in NorduGrid Advanced Resource Connector (ARC) before 0.8.3 allows local users to gain privileges via vectors related to the LD_LIBRARY_PATH environment variable. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4224-58xc-w446/GHSA-4224-58xc-w446.json b/advisories/unreviewed/2022/05/GHSA-4224-58xc-w446/GHSA-4224-58xc-w446.json index 7581364302a..08b9d010f34 100644 --- a/advisories/unreviewed/2022/05/GHSA-4224-58xc-w446/GHSA-4224-58xc-w446.json +++ b/advisories/unreviewed/2022/05/GHSA-4224-58xc-w446/GHSA-4224-58xc-w446.json @@ -7,12 +7,8 @@ "CVE-2011-1551" ], "details": "SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root filesystem operations by the Cobbler daemon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-437h-qp99-8cwj/GHSA-437h-qp99-8cwj.json b/advisories/unreviewed/2022/05/GHSA-437h-qp99-8cwj/GHSA-437h-qp99-8cwj.json index a00a98024f3..71cc4648f37 100644 --- a/advisories/unreviewed/2022/05/GHSA-437h-qp99-8cwj/GHSA-437h-qp99-8cwj.json +++ b/advisories/unreviewed/2022/05/GHSA-437h-qp99-8cwj/GHSA-437h-qp99-8cwj.json @@ -7,12 +7,8 @@ "CVE-2010-3281" ], "details": "Stack-based buffer overflow in the HTTP proxy service in Alcatel-Lucent OmniVista 4760 server before R5.1.06.03.c_Patch3 allows remote attackers to execute arbitrary code or cause a denial of service (service crash) via a long request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43h4-q69g-56g6/GHSA-43h4-q69g-56g6.json b/advisories/unreviewed/2022/05/GHSA-43h4-q69g-56g6/GHSA-43h4-q69g-56g6.json index 2fceb88ad9e..2c6e8e9e794 100644 --- a/advisories/unreviewed/2022/05/GHSA-43h4-q69g-56g6/GHSA-43h4-q69g-56g6.json +++ b/advisories/unreviewed/2022/05/GHSA-43h4-q69g-56g6/GHSA-43h4-q69g-56g6.json @@ -7,12 +7,8 @@ "CVE-2011-0580" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43mp-m7qp-jhq5/GHSA-43mp-m7qp-jhq5.json b/advisories/unreviewed/2022/05/GHSA-43mp-m7qp-jhq5/GHSA-43mp-m7qp-jhq5.json index ac4d6ea0515..388815d930b 100644 --- a/advisories/unreviewed/2022/05/GHSA-43mp-m7qp-jhq5/GHSA-43mp-m7qp-jhq5.json +++ b/advisories/unreviewed/2022/05/GHSA-43mp-m7qp-jhq5/GHSA-43mp-m7qp-jhq5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43vr-qg9p-fhgg/GHSA-43vr-qg9p-fhgg.json b/advisories/unreviewed/2022/05/GHSA-43vr-qg9p-fhgg/GHSA-43vr-qg9p-fhgg.json index df874878651..3fa6ab84d04 100644 --- a/advisories/unreviewed/2022/05/GHSA-43vr-qg9p-fhgg/GHSA-43vr-qg9p-fhgg.json +++ b/advisories/unreviewed/2022/05/GHSA-43vr-qg9p-fhgg/GHSA-43vr-qg9p-fhgg.json @@ -7,12 +7,8 @@ "CVE-2010-4637" ], "details": "Cross-site scripting (XSS) vulnerability in feedlist/handler_image.php in the FeedList plugin 2.61.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46cw-m9jr-4whp/GHSA-46cw-m9jr-4whp.json b/advisories/unreviewed/2022/05/GHSA-46cw-m9jr-4whp/GHSA-46cw-m9jr-4whp.json index abcf06cb203..ccfbab2caf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-46cw-m9jr-4whp/GHSA-46cw-m9jr-4whp.json +++ b/advisories/unreviewed/2022/05/GHSA-46cw-m9jr-4whp/GHSA-46cw-m9jr-4whp.json @@ -7,12 +7,8 @@ "CVE-2010-4689" ], "details": "Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) do not properly preserve ACL behavior after a migration, which allows remote attackers to bypass intended access restrictions via an unspecified type of network traffic that had previously been denied, aka Bug ID CSCte46460.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-475c-78rh-rffp/GHSA-475c-78rh-rffp.json b/advisories/unreviewed/2022/05/GHSA-475c-78rh-rffp/GHSA-475c-78rh-rffp.json index 217a8481ee5..e54f8422a60 100644 --- a/advisories/unreviewed/2022/05/GHSA-475c-78rh-rffp/GHSA-475c-78rh-rffp.json +++ b/advisories/unreviewed/2022/05/GHSA-475c-78rh-rffp/GHSA-475c-78rh-rffp.json @@ -7,12 +7,8 @@ "CVE-2011-0323" ], "details": "Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-475j-c8fh-8fh5/GHSA-475j-c8fh-8fh5.json b/advisories/unreviewed/2022/05/GHSA-475j-c8fh-8fh5/GHSA-475j-c8fh-8fh5.json index 73b65260d04..be5484bd3e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-475j-c8fh-8fh5/GHSA-475j-c8fh-8fh5.json +++ b/advisories/unreviewed/2022/05/GHSA-475j-c8fh-8fh5/GHSA-475j-c8fh-8fh5.json @@ -7,12 +7,8 @@ "CVE-2011-1674" ], "details": "The NetGear ProSafe WNAP210 with firmware 2.0.12 allows remote attackers to bypass authentication and obtain access to the configuration page by visiting recreate.php and then visiting index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-479f-xfrj-xvx9/GHSA-479f-xfrj-xvx9.json b/advisories/unreviewed/2022/05/GHSA-479f-xfrj-xvx9/GHSA-479f-xfrj-xvx9.json index a8f14aed02b..ae1cfbb2c81 100644 --- a/advisories/unreviewed/2022/05/GHSA-479f-xfrj-xvx9/GHSA-479f-xfrj-xvx9.json +++ b/advisories/unreviewed/2022/05/GHSA-479f-xfrj-xvx9/GHSA-479f-xfrj-xvx9.json @@ -7,12 +7,8 @@ "CVE-2011-1054" ], "details": "Unspecified vulnerability in the PEF input file loader in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47pg-c4cm-269h/GHSA-47pg-c4cm-269h.json b/advisories/unreviewed/2022/05/GHSA-47pg-c4cm-269h/GHSA-47pg-c4cm-269h.json index a9c8813c152..ffc334e7a63 100644 --- a/advisories/unreviewed/2022/05/GHSA-47pg-c4cm-269h/GHSA-47pg-c4cm-269h.json +++ b/advisories/unreviewed/2022/05/GHSA-47pg-c4cm-269h/GHSA-47pg-c4cm-269h.json @@ -7,12 +7,8 @@ "CVE-2011-1355" ], "details": "Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-47w3-v9wp-56q9/GHSA-47w3-v9wp-56q9.json b/advisories/unreviewed/2022/05/GHSA-47w3-v9wp-56q9/GHSA-47w3-v9wp-56q9.json index 6d303b20537..2fe9723f248 100644 --- a/advisories/unreviewed/2022/05/GHSA-47w3-v9wp-56q9/GHSA-47w3-v9wp-56q9.json +++ b/advisories/unreviewed/2022/05/GHSA-47w3-v9wp-56q9/GHSA-47w3-v9wp-56q9.json @@ -7,12 +7,8 @@ "CVE-2011-1205" ], "details": "Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a Trojan horse HTML document in the My Computer zone.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-47wv-f5hh-xpcm/GHSA-47wv-f5hh-xpcm.json b/advisories/unreviewed/2022/05/GHSA-47wv-f5hh-xpcm/GHSA-47wv-f5hh-xpcm.json index 30cc1c2c653..ddd2de2892a 100644 --- a/advisories/unreviewed/2022/05/GHSA-47wv-f5hh-xpcm/GHSA-47wv-f5hh-xpcm.json +++ b/advisories/unreviewed/2022/05/GHSA-47wv-f5hh-xpcm/GHSA-47wv-f5hh-xpcm.json @@ -7,12 +7,8 @@ "CVE-2011-0341" ], "details": "Stack-based buffer overflow in the pdfmoz_onmouse function in apps/mozilla/moz_main.c in the MuPDF plug-in 2008.09.02 for Firefox allows remote attackers to execute arbitrary code via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48g9-h8v9-c2qm/GHSA-48g9-h8v9-c2qm.json b/advisories/unreviewed/2022/05/GHSA-48g9-h8v9-c2qm/GHSA-48g9-h8v9-c2qm.json index 26910a34e19..7e439fbf296 100644 --- a/advisories/unreviewed/2022/05/GHSA-48g9-h8v9-c2qm/GHSA-48g9-h8v9-c2qm.json +++ b/advisories/unreviewed/2022/05/GHSA-48g9-h8v9-c2qm/GHSA-48g9-h8v9-c2qm.json @@ -7,12 +7,8 @@ "CVE-2011-1338" ], "details": "Untrusted search path vulnerability in XnView before 1.98.1 allows local users to gain privileges via a Trojan horse .exe file in a folder selected by the \"Open containing folder\" menu item.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-492v-8jgq-fj65/GHSA-492v-8jgq-fj65.json b/advisories/unreviewed/2022/05/GHSA-492v-8jgq-fj65/GHSA-492v-8jgq-fj65.json index 953bbc27080..6c26d7e4cf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-492v-8jgq-fj65/GHSA-492v-8jgq-fj65.json +++ b/advisories/unreviewed/2022/05/GHSA-492v-8jgq-fj65/GHSA-492v-8jgq-fj65.json @@ -7,12 +7,8 @@ "CVE-2011-0740" ], "details": "Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49mj-77q5-qw5g/GHSA-49mj-77q5-qw5g.json b/advisories/unreviewed/2022/05/GHSA-49mj-77q5-qw5g/GHSA-49mj-77q5-qw5g.json index 7d83c6c1825..8097cbfe468 100644 --- a/advisories/unreviewed/2022/05/GHSA-49mj-77q5-qw5g/GHSA-49mj-77q5-qw5g.json +++ b/advisories/unreviewed/2022/05/GHSA-49mj-77q5-qw5g/GHSA-49mj-77q5-qw5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49p2-x345-c788/GHSA-49p2-x345-c788.json b/advisories/unreviewed/2022/05/GHSA-49p2-x345-c788/GHSA-49p2-x345-c788.json index a896eeb1625..f55e5e6fde0 100644 --- a/advisories/unreviewed/2022/05/GHSA-49p2-x345-c788/GHSA-49p2-x345-c788.json +++ b/advisories/unreviewed/2022/05/GHSA-49p2-x345-c788/GHSA-49p2-x345-c788.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c65-9qmh-v9h5/GHSA-4c65-9qmh-v9h5.json b/advisories/unreviewed/2022/05/GHSA-4c65-9qmh-v9h5/GHSA-4c65-9qmh-v9h5.json index dde651cff46..eec311f47c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c65-9qmh-v9h5/GHSA-4c65-9qmh-v9h5.json +++ b/advisories/unreviewed/2022/05/GHSA-4c65-9qmh-v9h5/GHSA-4c65-9qmh-v9h5.json @@ -7,12 +7,8 @@ "CVE-2011-1925" ], "details": "nbd-server.c in Network Block Device (nbd-server) 2.9.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by causing a negotiation failure, as demonstrated by specifying a name for a non-existent export.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f6f-x539-9v2g/GHSA-4f6f-x539-9v2g.json b/advisories/unreviewed/2022/05/GHSA-4f6f-x539-9v2g/GHSA-4f6f-x539-9v2g.json index 5a45d2b08e4..2c1af1cce79 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f6f-x539-9v2g/GHSA-4f6f-x539-9v2g.json +++ b/advisories/unreviewed/2022/05/GHSA-4f6f-x539-9v2g/GHSA-4f6f-x539-9v2g.json @@ -7,12 +7,8 @@ "CVE-2011-0311" ], "details": "The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4g88-pvpj-755p/GHSA-4g88-pvpj-755p.json b/advisories/unreviewed/2022/05/GHSA-4g88-pvpj-755p/GHSA-4g88-pvpj-755p.json index 6e89406a7b6..21a13070592 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g88-pvpj-755p/GHSA-4g88-pvpj-755p.json +++ b/advisories/unreviewed/2022/05/GHSA-4g88-pvpj-755p/GHSA-4g88-pvpj-755p.json @@ -7,12 +7,8 @@ "CVE-2011-1839" ], "details": "IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j55-6fc3-6h48/GHSA-4j55-6fc3-6h48.json b/advisories/unreviewed/2022/05/GHSA-4j55-6fc3-6h48/GHSA-4j55-6fc3-6h48.json index 8f0eef0be0e..b2b5548af53 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j55-6fc3-6h48/GHSA-4j55-6fc3-6h48.json +++ b/advisories/unreviewed/2022/05/GHSA-4j55-6fc3-6h48/GHSA-4j55-6fc3-6h48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4p7m-9f38-j933/GHSA-4p7m-9f38-j933.json b/advisories/unreviewed/2022/05/GHSA-4p7m-9f38-j933/GHSA-4p7m-9f38-j933.json index d775bd74f11..be121db146a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p7m-9f38-j933/GHSA-4p7m-9f38-j933.json +++ b/advisories/unreviewed/2022/05/GHSA-4p7m-9f38-j933/GHSA-4p7m-9f38-j933.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pww-4mvf-9jr8/GHSA-4pww-4mvf-9jr8.json b/advisories/unreviewed/2022/05/GHSA-4pww-4mvf-9jr8/GHSA-4pww-4mvf-9jr8.json index 123ce882d5f..f9dfa7aabfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pww-4mvf-9jr8/GHSA-4pww-4mvf-9jr8.json +++ b/advisories/unreviewed/2022/05/GHSA-4pww-4mvf-9jr8/GHSA-4pww-4mvf-9jr8.json @@ -7,12 +7,8 @@ "CVE-2010-3206" ], "details": "Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to modules/guestbook/blocks/control.block.php, (2) main_module parameter to index.php, and (3) getFile parameter to includes/general.functions.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4q79-qphh-pxpm/GHSA-4q79-qphh-pxpm.json b/advisories/unreviewed/2022/05/GHSA-4q79-qphh-pxpm/GHSA-4q79-qphh-pxpm.json index 71ffa5657b1..93b364e93c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q79-qphh-pxpm/GHSA-4q79-qphh-pxpm.json +++ b/advisories/unreviewed/2022/05/GHSA-4q79-qphh-pxpm/GHSA-4q79-qphh-pxpm.json @@ -7,12 +7,8 @@ "CVE-2011-1051" ], "details": "Integer overflow in the COFF/EPOC/EXPLOAD input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vrq-3967-6xg8/GHSA-4vrq-3967-6xg8.json b/advisories/unreviewed/2022/05/GHSA-4vrq-3967-6xg8/GHSA-4vrq-3967-6xg8.json index 8f9ff05e088..6558b245c37 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vrq-3967-6xg8/GHSA-4vrq-3967-6xg8.json +++ b/advisories/unreviewed/2022/05/GHSA-4vrq-3967-6xg8/GHSA-4vrq-3967-6xg8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w4w-866c-5vgg/GHSA-4w4w-866c-5vgg.json b/advisories/unreviewed/2022/05/GHSA-4w4w-866c-5vgg/GHSA-4w4w-866c-5vgg.json index 0db97495f90..9f9d8b20afa 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w4w-866c-5vgg/GHSA-4w4w-866c-5vgg.json +++ b/advisories/unreviewed/2022/05/GHSA-4w4w-866c-5vgg/GHSA-4w4w-866c-5vgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wp6-r9gv-37c2/GHSA-4wp6-r9gv-37c2.json b/advisories/unreviewed/2022/05/GHSA-4wp6-r9gv-37c2/GHSA-4wp6-r9gv-37c2.json index d6fee7cbc8a..d75eff7d80f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wp6-r9gv-37c2/GHSA-4wp6-r9gv-37c2.json +++ b/advisories/unreviewed/2022/05/GHSA-4wp6-r9gv-37c2/GHSA-4wp6-r9gv-37c2.json @@ -7,12 +7,8 @@ "CVE-2011-0951" ], "details": "The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5228-qfm2-w928/GHSA-5228-qfm2-w928.json b/advisories/unreviewed/2022/05/GHSA-5228-qfm2-w928/GHSA-5228-qfm2-w928.json index 32c780f169a..f9605b1f8f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5228-qfm2-w928/GHSA-5228-qfm2-w928.json +++ b/advisories/unreviewed/2022/05/GHSA-5228-qfm2-w928/GHSA-5228-qfm2-w928.json @@ -7,12 +7,8 @@ "CVE-2011-1637" ], "details": "Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52mm-w3hf-39rg/GHSA-52mm-w3hf-39rg.json b/advisories/unreviewed/2022/05/GHSA-52mm-w3hf-39rg/GHSA-52mm-w3hf-39rg.json index 80164c7c27f..1294b3b94ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-52mm-w3hf-39rg/GHSA-52mm-w3hf-39rg.json +++ b/advisories/unreviewed/2022/05/GHSA-52mm-w3hf-39rg/GHSA-52mm-w3hf-39rg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52r3-f6x8-h7v5/GHSA-52r3-f6x8-h7v5.json b/advisories/unreviewed/2022/05/GHSA-52r3-f6x8-h7v5/GHSA-52r3-f6x8-h7v5.json index fedff1b3b94..b325131445d 100644 --- a/advisories/unreviewed/2022/05/GHSA-52r3-f6x8-h7v5/GHSA-52r3-f6x8-h7v5.json +++ b/advisories/unreviewed/2022/05/GHSA-52r3-f6x8-h7v5/GHSA-52r3-f6x8-h7v5.json @@ -7,12 +7,8 @@ "CVE-2011-1661" ], "details": "The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53cv-x4gp-67j7/GHSA-53cv-x4gp-67j7.json b/advisories/unreviewed/2022/05/GHSA-53cv-x4gp-67j7/GHSA-53cv-x4gp-67j7.json index 0bab48ce9f5..1efe2222524 100644 --- a/advisories/unreviewed/2022/05/GHSA-53cv-x4gp-67j7/GHSA-53cv-x4gp-67j7.json +++ b/advisories/unreviewed/2022/05/GHSA-53cv-x4gp-67j7/GHSA-53cv-x4gp-67j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53gq-qw8x-rqhq/GHSA-53gq-qw8x-rqhq.json b/advisories/unreviewed/2022/05/GHSA-53gq-qw8x-rqhq/GHSA-53gq-qw8x-rqhq.json index 9ce5f4211c7..730ecb9cb2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-53gq-qw8x-rqhq/GHSA-53gq-qw8x-rqhq.json +++ b/advisories/unreviewed/2022/05/GHSA-53gq-qw8x-rqhq/GHSA-53gq-qw8x-rqhq.json @@ -7,12 +7,8 @@ "CVE-2010-3279" ], "details": "The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables maintenance access, which allows remote attackers to monitor or reconfigure Contact Center operations via vectors involving TSA_maintenance.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53hg-rp39-h2xc/GHSA-53hg-rp39-h2xc.json b/advisories/unreviewed/2022/05/GHSA-53hg-rp39-h2xc/GHSA-53hg-rp39-h2xc.json index 59453459df6..7457bc61c74 100644 --- a/advisories/unreviewed/2022/05/GHSA-53hg-rp39-h2xc/GHSA-53hg-rp39-h2xc.json +++ b/advisories/unreviewed/2022/05/GHSA-53hg-rp39-h2xc/GHSA-53hg-rp39-h2xc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53p4-qm3j-q67h/GHSA-53p4-qm3j-q67h.json b/advisories/unreviewed/2022/05/GHSA-53p4-qm3j-q67h/GHSA-53p4-qm3j-q67h.json index 84f8772df28..5ce9fe7bee7 100644 --- a/advisories/unreviewed/2022/05/GHSA-53p4-qm3j-q67h/GHSA-53p4-qm3j-q67h.json +++ b/advisories/unreviewed/2022/05/GHSA-53p4-qm3j-q67h/GHSA-53p4-qm3j-q67h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54gc-922g-p6xr/GHSA-54gc-922g-p6xr.json b/advisories/unreviewed/2022/05/GHSA-54gc-922g-p6xr/GHSA-54gc-922g-p6xr.json index 465b77ae239..702a71812f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-54gc-922g-p6xr/GHSA-54gc-922g-p6xr.json +++ b/advisories/unreviewed/2022/05/GHSA-54gc-922g-p6xr/GHSA-54gc-922g-p6xr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-555p-vhfv-8grv/GHSA-555p-vhfv-8grv.json b/advisories/unreviewed/2022/05/GHSA-555p-vhfv-8grv/GHSA-555p-vhfv-8grv.json index b530a126e60..f5bcb97516b 100644 --- a/advisories/unreviewed/2022/05/GHSA-555p-vhfv-8grv/GHSA-555p-vhfv-8grv.json +++ b/advisories/unreviewed/2022/05/GHSA-555p-vhfv-8grv/GHSA-555p-vhfv-8grv.json @@ -7,12 +7,8 @@ "CVE-2010-4364" ], "details": "DaDaBIK 4.3 beta3, when running in a case-sensitive environment, does not include the htmLawed library, which allows remote attackers to bypass the protection mechanism for CVE-2010-4355 and conduct cross-site scripting (XSS) attacks via the (1) html content and (2) rich_editor fields. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55m2-m4jf-3wm8/GHSA-55m2-m4jf-3wm8.json b/advisories/unreviewed/2022/05/GHSA-55m2-m4jf-3wm8/GHSA-55m2-m4jf-3wm8.json index 7adcfda7bd6..1d6f8bf8e83 100644 --- a/advisories/unreviewed/2022/05/GHSA-55m2-m4jf-3wm8/GHSA-55m2-m4jf-3wm8.json +++ b/advisories/unreviewed/2022/05/GHSA-55m2-m4jf-3wm8/GHSA-55m2-m4jf-3wm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5683-7cr4-v2pp/GHSA-5683-7cr4-v2pp.json b/advisories/unreviewed/2022/05/GHSA-5683-7cr4-v2pp/GHSA-5683-7cr4-v2pp.json index 2c067255c2b..7b0a68dd860 100644 --- a/advisories/unreviewed/2022/05/GHSA-5683-7cr4-v2pp/GHSA-5683-7cr4-v2pp.json +++ b/advisories/unreviewed/2022/05/GHSA-5683-7cr4-v2pp/GHSA-5683-7cr4-v2pp.json @@ -7,12 +7,8 @@ "CVE-2011-0550" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allow remote attackers to inject arbitrary web script or HTML via (1) the token parameter to portal/Help.jsp or (2) the URI in a console/apps/sepm request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56mw-6mm9-crqj/GHSA-56mw-6mm9-crqj.json b/advisories/unreviewed/2022/05/GHSA-56mw-6mm9-crqj/GHSA-56mw-6mm9-crqj.json index 5929822a588..0cae29b5bd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-56mw-6mm9-crqj/GHSA-56mw-6mm9-crqj.json +++ b/advisories/unreviewed/2022/05/GHSA-56mw-6mm9-crqj/GHSA-56mw-6mm9-crqj.json @@ -7,12 +7,8 @@ "CVE-2011-0206" ], "details": "Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving uppercase strings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57ph-55m2-798w/GHSA-57ph-55m2-798w.json b/advisories/unreviewed/2022/05/GHSA-57ph-55m2-798w/GHSA-57ph-55m2-798w.json index e9fad48c1a1..8c2e1b41869 100644 --- a/advisories/unreviewed/2022/05/GHSA-57ph-55m2-798w/GHSA-57ph-55m2-798w.json +++ b/advisories/unreviewed/2022/05/GHSA-57ph-55m2-798w/GHSA-57ph-55m2-798w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-592g-2wx9-5j84/GHSA-592g-2wx9-5j84.json b/advisories/unreviewed/2022/05/GHSA-592g-2wx9-5j84/GHSA-592g-2wx9-5j84.json index 2b075c12bf9..f788a586f2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-592g-2wx9-5j84/GHSA-592g-2wx9-5j84.json +++ b/advisories/unreviewed/2022/05/GHSA-592g-2wx9-5j84/GHSA-592g-2wx9-5j84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c56-7q2q-qv2j/GHSA-5c56-7q2q-qv2j.json b/advisories/unreviewed/2022/05/GHSA-5c56-7q2q-qv2j/GHSA-5c56-7q2q-qv2j.json index c8f032702ef..b03e595dec5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c56-7q2q-qv2j/GHSA-5c56-7q2q-qv2j.json +++ b/advisories/unreviewed/2022/05/GHSA-5c56-7q2q-qv2j/GHSA-5c56-7q2q-qv2j.json @@ -7,12 +7,8 @@ "CVE-2011-0381" ], "details": "Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI interface, related to a \"command injection vulnerability,\" aka Bug ID CSCtf97085.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c7f-3fp9-p3v4/GHSA-5c7f-3fp9-p3v4.json b/advisories/unreviewed/2022/05/GHSA-5c7f-3fp9-p3v4/GHSA-5c7f-3fp9-p3v4.json index 40151e64ab3..897cb03c9d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c7f-3fp9-p3v4/GHSA-5c7f-3fp9-p3v4.json +++ b/advisories/unreviewed/2022/05/GHSA-5c7f-3fp9-p3v4/GHSA-5c7f-3fp9-p3v4.json @@ -7,12 +7,8 @@ "CVE-2011-0904" ], "details": "The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via a large (1) X position or (2) Y position value in a framebuffer update request that triggers an out-of-bounds memory access, related to the rfbTranslateNone and rfbSendRectEncodingRaw functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5cgr-rxfv-wjgv/GHSA-5cgr-rxfv-wjgv.json b/advisories/unreviewed/2022/05/GHSA-5cgr-rxfv-wjgv/GHSA-5cgr-rxfv-wjgv.json index da7290851dc..d5633461e79 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cgr-rxfv-wjgv/GHSA-5cgr-rxfv-wjgv.json +++ b/advisories/unreviewed/2022/05/GHSA-5cgr-rxfv-wjgv/GHSA-5cgr-rxfv-wjgv.json @@ -7,12 +7,8 @@ "CVE-2011-0959" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to iptm/ddv.do, the (3) cmd or (4) group parameter to iptm/eventmon, the (5) clusterName or (6) deviceName parameter to iptm/faultmon/ui/dojo/Main/eventmon_wrapper.jsp, or the (7) ccmName or (8) clusterName parameter to iptm/logicalTopo.do, aka Bug ID CSCtn61716.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5chx-q2h4-95hq/GHSA-5chx-q2h4-95hq.json b/advisories/unreviewed/2022/05/GHSA-5chx-q2h4-95hq/GHSA-5chx-q2h4-95hq.json index e5c901eddad..9eb1d280768 100644 --- a/advisories/unreviewed/2022/05/GHSA-5chx-q2h4-95hq/GHSA-5chx-q2h4-95hq.json +++ b/advisories/unreviewed/2022/05/GHSA-5chx-q2h4-95hq/GHSA-5chx-q2h4-95hq.json @@ -7,12 +7,8 @@ "CVE-2011-0344" ], "details": "Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Communication Server (CS) in Alcatel-Lucent OmniPCX Enterprise before R9.0 H1.301.50 allow remote attackers to execute arbitrary code via crafted HTTP headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f9r-6cq4-fph8/GHSA-5f9r-6cq4-fph8.json b/advisories/unreviewed/2022/05/GHSA-5f9r-6cq4-fph8/GHSA-5f9r-6cq4-fph8.json index 16a1fbecd1f..517991df670 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f9r-6cq4-fph8/GHSA-5f9r-6cq4-fph8.json +++ b/advisories/unreviewed/2022/05/GHSA-5f9r-6cq4-fph8/GHSA-5f9r-6cq4-fph8.json @@ -7,12 +7,8 @@ "CVE-2011-1580" ], "details": "The transwiki import functionality in MediaWiki before 1.16.3 does not properly check privileges, which allows remote authenticated users to perform imports from any wgImportSources wiki via a crafted POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fhw-rc3x-vmxm/GHSA-5fhw-rc3x-vmxm.json b/advisories/unreviewed/2022/05/GHSA-5fhw-rc3x-vmxm/GHSA-5fhw-rc3x-vmxm.json index 6dd5ace1b4e..1a0e33ca743 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fhw-rc3x-vmxm/GHSA-5fhw-rc3x-vmxm.json +++ b/advisories/unreviewed/2022/05/GHSA-5fhw-rc3x-vmxm/GHSA-5fhw-rc3x-vmxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5ggv-2jrf-6fx5/GHSA-5ggv-2jrf-6fx5.json b/advisories/unreviewed/2022/05/GHSA-5ggv-2jrf-6fx5/GHSA-5ggv-2jrf-6fx5.json index ed66d47a670..fd193217644 100644 --- a/advisories/unreviewed/2022/05/GHSA-5ggv-2jrf-6fx5/GHSA-5ggv-2jrf-6fx5.json +++ b/advisories/unreviewed/2022/05/GHSA-5ggv-2jrf-6fx5/GHSA-5ggv-2jrf-6fx5.json @@ -7,12 +7,8 @@ "CVE-2011-0163" ], "details": "WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified \"cached resources,\" which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poisoning attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h64-f677-76hx/GHSA-5h64-f677-76hx.json b/advisories/unreviewed/2022/05/GHSA-5h64-f677-76hx/GHSA-5h64-f677-76hx.json index 1cfbf3cd736..da453a38673 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h64-f677-76hx/GHSA-5h64-f677-76hx.json +++ b/advisories/unreviewed/2022/05/GHSA-5h64-f677-76hx/GHSA-5h64-f677-76hx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hv9-93p8-hw48/GHSA-5hv9-93p8-hw48.json b/advisories/unreviewed/2022/05/GHSA-5hv9-93p8-hw48/GHSA-5hv9-93p8-hw48.json index 779aba62008..86728a8879d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hv9-93p8-hw48/GHSA-5hv9-93p8-hw48.json +++ b/advisories/unreviewed/2022/05/GHSA-5hv9-93p8-hw48/GHSA-5hv9-93p8-hw48.json @@ -7,12 +7,8 @@ "CVE-2011-1862" ], "details": "Cross-site scripting (XSS) vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j6c-7vj8-67j5/GHSA-5j6c-7vj8-67j5.json b/advisories/unreviewed/2022/05/GHSA-5j6c-7vj8-67j5/GHSA-5j6c-7vj8-67j5.json index 32cc271fb7b..cde9fe54b53 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j6c-7vj8-67j5/GHSA-5j6c-7vj8-67j5.json +++ b/advisories/unreviewed/2022/05/GHSA-5j6c-7vj8-67j5/GHSA-5j6c-7vj8-67j5.json @@ -7,12 +7,8 @@ "CVE-2011-1372" ], "details": "The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j8x-37gw-wf45/GHSA-5j8x-37gw-wf45.json b/advisories/unreviewed/2022/05/GHSA-5j8x-37gw-wf45/GHSA-5j8x-37gw-wf45.json index 27e290d6fc8..dc1ba44fb2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j8x-37gw-wf45/GHSA-5j8x-37gw-wf45.json +++ b/advisories/unreviewed/2022/05/GHSA-5j8x-37gw-wf45/GHSA-5j8x-37gw-wf45.json @@ -7,12 +7,8 @@ "CVE-2011-0274" ], "details": "Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m78-jr6f-rgf5/GHSA-5m78-jr6f-rgf5.json b/advisories/unreviewed/2022/05/GHSA-5m78-jr6f-rgf5/GHSA-5m78-jr6f-rgf5.json index 59f61fc412a..e4dbe436bd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m78-jr6f-rgf5/GHSA-5m78-jr6f-rgf5.json +++ b/advisories/unreviewed/2022/05/GHSA-5m78-jr6f-rgf5/GHSA-5m78-jr6f-rgf5.json @@ -7,12 +7,8 @@ "CVE-2011-0644" ], "details": "SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the modelid parameter to flash_upload.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p32-34xx-jmq8/GHSA-5p32-34xx-jmq8.json b/advisories/unreviewed/2022/05/GHSA-5p32-34xx-jmq8/GHSA-5p32-34xx-jmq8.json index 96ea8537353..3798cfe5ff2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p32-34xx-jmq8/GHSA-5p32-34xx-jmq8.json +++ b/advisories/unreviewed/2022/05/GHSA-5p32-34xx-jmq8/GHSA-5p32-34xx-jmq8.json @@ -7,12 +7,8 @@ "CVE-2011-1343" ], "details": "SQL injection vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus before 7.3.0.4 allows remote attackers to execute arbitrary SQL commands via \"dynamic SQL parameters.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p42-9ww9-5p77/GHSA-5p42-9ww9-5p77.json b/advisories/unreviewed/2022/05/GHSA-5p42-9ww9-5p77/GHSA-5p42-9ww9-5p77.json index bb053c4a494..60b2681b42c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p42-9ww9-5p77/GHSA-5p42-9ww9-5p77.json +++ b/advisories/unreviewed/2022/05/GHSA-5p42-9ww9-5p77/GHSA-5p42-9ww9-5p77.json @@ -7,12 +7,8 @@ "CVE-2011-1409" ], "details": "Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication and upload arbitrary files via a request that lacks an authentication ID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pfw-q7gf-m255/GHSA-5pfw-q7gf-m255.json b/advisories/unreviewed/2022/05/GHSA-5pfw-q7gf-m255/GHSA-5pfw-q7gf-m255.json index 05d223ec1d7..4a637a6ac71 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pfw-q7gf-m255/GHSA-5pfw-q7gf-m255.json +++ b/advisories/unreviewed/2022/05/GHSA-5pfw-q7gf-m255/GHSA-5pfw-q7gf-m255.json @@ -7,12 +7,8 @@ "CVE-2011-1362" ], "details": "Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1308.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pm8-4cgq-c8fp/GHSA-5pm8-4cgq-c8fp.json b/advisories/unreviewed/2022/05/GHSA-5pm8-4cgq-c8fp/GHSA-5pm8-4cgq-c8fp.json index a84612c3288..604ba489a8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pm8-4cgq-c8fp/GHSA-5pm8-4cgq-c8fp.json +++ b/advisories/unreviewed/2022/05/GHSA-5pm8-4cgq-c8fp/GHSA-5pm8-4cgq-c8fp.json @@ -7,12 +7,8 @@ "CVE-2011-0966" ], "details": "Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, aka Bug ID CSCto35577.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pmf-6h5c-44g9/GHSA-5pmf-6h5c-44g9.json b/advisories/unreviewed/2022/05/GHSA-5pmf-6h5c-44g9/GHSA-5pmf-6h5c-44g9.json index ecaba464c88..dc77043c773 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pmf-6h5c-44g9/GHSA-5pmf-6h5c-44g9.json +++ b/advisories/unreviewed/2022/05/GHSA-5pmf-6h5c-44g9/GHSA-5pmf-6h5c-44g9.json @@ -7,12 +7,8 @@ "CVE-2011-0900" ], "details": "Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a .RDP file with a long hostname argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qcq-h4g6-rvvf/GHSA-5qcq-h4g6-rvvf.json b/advisories/unreviewed/2022/05/GHSA-5qcq-h4g6-rvvf/GHSA-5qcq-h4g6-rvvf.json index 07924b2d465..58aae56939f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qcq-h4g6-rvvf/GHSA-5qcq-h4g6-rvvf.json +++ b/advisories/unreviewed/2022/05/GHSA-5qcq-h4g6-rvvf/GHSA-5qcq-h4g6-rvvf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qhf-p2cv-vwq5/GHSA-5qhf-p2cv-vwq5.json b/advisories/unreviewed/2022/05/GHSA-5qhf-p2cv-vwq5/GHSA-5qhf-p2cv-vwq5.json index 32b695cf7a4..bcc3069e0a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qhf-p2cv-vwq5/GHSA-5qhf-p2cv-vwq5.json +++ b/advisories/unreviewed/2022/05/GHSA-5qhf-p2cv-vwq5/GHSA-5qhf-p2cv-vwq5.json @@ -7,12 +7,8 @@ "CVE-2011-0423" ], "details": "The PolyVision RoomWizard with firmware 3.2.3 has a default password of roomwizard for the administrator account, which makes it easier for remote attackers to obtain console access via an HTTP session, a different vulnerability than CVE-2010-0214.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5r4w-2fg5-326q/GHSA-5r4w-2fg5-326q.json b/advisories/unreviewed/2022/05/GHSA-5r4w-2fg5-326q/GHSA-5r4w-2fg5-326q.json index c06668c9460..9a0edbe05d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r4w-2fg5-326q/GHSA-5r4w-2fg5-326q.json +++ b/advisories/unreviewed/2022/05/GHSA-5r4w-2fg5-326q/GHSA-5r4w-2fg5-326q.json @@ -7,12 +7,8 @@ "CVE-2010-3289" ], "details": "Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v2g-vp3m-c3jg/GHSA-5v2g-vp3m-c3jg.json b/advisories/unreviewed/2022/05/GHSA-5v2g-vp3m-c3jg/GHSA-5v2g-vp3m-c3jg.json index a4f0817418d..34a0deb382f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v2g-vp3m-c3jg/GHSA-5v2g-vp3m-c3jg.json +++ b/advisories/unreviewed/2022/05/GHSA-5v2g-vp3m-c3jg/GHSA-5v2g-vp3m-c3jg.json @@ -7,12 +7,8 @@ "CVE-2011-0992" ], "details": "Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wcj-6r5g-pm7f/GHSA-5wcj-6r5g-pm7f.json b/advisories/unreviewed/2022/05/GHSA-5wcj-6r5g-pm7f/GHSA-5wcj-6r5g-pm7f.json index 0cea95a7403..d64c67bdaab 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wcj-6r5g-pm7f/GHSA-5wcj-6r5g-pm7f.json +++ b/advisories/unreviewed/2022/05/GHSA-5wcj-6r5g-pm7f/GHSA-5wcj-6r5g-pm7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6252-f9r2-74xr/GHSA-6252-f9r2-74xr.json b/advisories/unreviewed/2022/05/GHSA-6252-f9r2-74xr/GHSA-6252-f9r2-74xr.json index 39b442d3e49..083d6cc315d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6252-f9r2-74xr/GHSA-6252-f9r2-74xr.json +++ b/advisories/unreviewed/2022/05/GHSA-6252-f9r2-74xr/GHSA-6252-f9r2-74xr.json @@ -7,12 +7,8 @@ "CVE-2011-1360" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified documentation files in (1) manual/ibm/ and (2) htdocs/*/manual/ibm/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6347-hpf5-rgp8/GHSA-6347-hpf5-rgp8.json b/advisories/unreviewed/2022/05/GHSA-6347-hpf5-rgp8/GHSA-6347-hpf5-rgp8.json index 89b733fe5c1..e8e93fb3745 100644 --- a/advisories/unreviewed/2022/05/GHSA-6347-hpf5-rgp8/GHSA-6347-hpf5-rgp8.json +++ b/advisories/unreviewed/2022/05/GHSA-6347-hpf5-rgp8/GHSA-6347-hpf5-rgp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63f9-cj55-4rmw/GHSA-63f9-cj55-4rmw.json b/advisories/unreviewed/2022/05/GHSA-63f9-cj55-4rmw/GHSA-63f9-cj55-4rmw.json index 1311c425d2e..b4fd3f05a0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-63f9-cj55-4rmw/GHSA-63f9-cj55-4rmw.json +++ b/advisories/unreviewed/2022/05/GHSA-63f9-cj55-4rmw/GHSA-63f9-cj55-4rmw.json @@ -7,12 +7,8 @@ "CVE-2011-1366" ], "details": "Unspecified vulnerability in the Import feature in IBM Rational AppScan Enterprise and AppScan Reporting Console 5.2 through 7.9.x and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary commands on an agent server via a crafted ZIP archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63qh-xc4p-2395/GHSA-63qh-xc4p-2395.json b/advisories/unreviewed/2022/05/GHSA-63qh-xc4p-2395/GHSA-63qh-xc4p-2395.json index 35f465c658d..0e173b2d8dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-63qh-xc4p-2395/GHSA-63qh-xc4p-2395.json +++ b/advisories/unreviewed/2022/05/GHSA-63qh-xc4p-2395/GHSA-63qh-xc4p-2395.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63qq-pm7h-vc34/GHSA-63qq-pm7h-vc34.json b/advisories/unreviewed/2022/05/GHSA-63qq-pm7h-vc34/GHSA-63qq-pm7h-vc34.json index 6a32cf1b985..ed37128c1b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-63qq-pm7h-vc34/GHSA-63qq-pm7h-vc34.json +++ b/advisories/unreviewed/2022/05/GHSA-63qq-pm7h-vc34/GHSA-63qq-pm7h-vc34.json @@ -7,12 +7,8 @@ "CVE-2011-1425" ], "details": "xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63xg-gpgq-r284/GHSA-63xg-gpgq-r284.json b/advisories/unreviewed/2022/05/GHSA-63xg-gpgq-r284/GHSA-63xg-gpgq-r284.json index c118bd5adc6..e8e98bb5ae2 100644 --- a/advisories/unreviewed/2022/05/GHSA-63xg-gpgq-r284/GHSA-63xg-gpgq-r284.json +++ b/advisories/unreviewed/2022/05/GHSA-63xg-gpgq-r284/GHSA-63xg-gpgq-r284.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64gc-rw82-mfm5/GHSA-64gc-rw82-mfm5.json b/advisories/unreviewed/2022/05/GHSA-64gc-rw82-mfm5/GHSA-64gc-rw82-mfm5.json index 5e6893cf441..b3b1494d86d 100644 --- a/advisories/unreviewed/2022/05/GHSA-64gc-rw82-mfm5/GHSA-64gc-rw82-mfm5.json +++ b/advisories/unreviewed/2022/05/GHSA-64gc-rw82-mfm5/GHSA-64gc-rw82-mfm5.json @@ -7,12 +7,8 @@ "CVE-2011-0583" ], "details": "Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via the cfform tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64gw-g9jq-7wp6/GHSA-64gw-g9jq-7wp6.json b/advisories/unreviewed/2022/05/GHSA-64gw-g9jq-7wp6/GHSA-64gw-g9jq-7wp6.json index 128fbf4f8b1..6dba2523c11 100644 --- a/advisories/unreviewed/2022/05/GHSA-64gw-g9jq-7wp6/GHSA-64gw-g9jq-7wp6.json +++ b/advisories/unreviewed/2022/05/GHSA-64gw-g9jq-7wp6/GHSA-64gw-g9jq-7wp6.json @@ -7,12 +7,8 @@ "CVE-2011-0404" ], "details": "Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows remote attackers to execute arbitrary code via a long control hostname to TCP port 5405, probably a different vulnerability than CVE-2007-5252.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6522-m749-xgvf/GHSA-6522-m749-xgvf.json b/advisories/unreviewed/2022/05/GHSA-6522-m749-xgvf/GHSA-6522-m749-xgvf.json index 5ad81ee07ff..b9f518d4b2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6522-m749-xgvf/GHSA-6522-m749-xgvf.json +++ b/advisories/unreviewed/2022/05/GHSA-6522-m749-xgvf/GHSA-6522-m749-xgvf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-675w-v7h4-pr55/GHSA-675w-v7h4-pr55.json b/advisories/unreviewed/2022/05/GHSA-675w-v7h4-pr55/GHSA-675w-v7h4-pr55.json index 645fc592f68..87a759da729 100644 --- a/advisories/unreviewed/2022/05/GHSA-675w-v7h4-pr55/GHSA-675w-v7h4-pr55.json +++ b/advisories/unreviewed/2022/05/GHSA-675w-v7h4-pr55/GHSA-675w-v7h4-pr55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6887-f7jr-vhc9/GHSA-6887-f7jr-vhc9.json b/advisories/unreviewed/2022/05/GHSA-6887-f7jr-vhc9/GHSA-6887-f7jr-vhc9.json index 5064b22b639..df757193e0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6887-f7jr-vhc9/GHSA-6887-f7jr-vhc9.json +++ b/advisories/unreviewed/2022/05/GHSA-6887-f7jr-vhc9/GHSA-6887-f7jr-vhc9.json @@ -7,12 +7,8 @@ "CVE-2011-0759" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration page in the Recaptcha (aka WP-reCAPTCHA) plugin 2.9.8.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that disable the CAPTCHA requirement or insert cross-site scripting (XSS) sequences via the (1) recaptcha_opt_pubkey, (2) recaptcha_opt_privkey, (3) re_tabindex, (4) error_blank, (5) error_incorrect, (6) mailhide_pub, (7) mailhide_priv, (8) mh_replace_link, or (9) mh_replace_title parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68c7-7p5r-7c3q/GHSA-68c7-7p5r-7c3q.json b/advisories/unreviewed/2022/05/GHSA-68c7-7p5r-7c3q/GHSA-68c7-7p5r-7c3q.json index 8ff228049aa..1538380152d 100644 --- a/advisories/unreviewed/2022/05/GHSA-68c7-7p5r-7c3q/GHSA-68c7-7p5r-7c3q.json +++ b/advisories/unreviewed/2022/05/GHSA-68c7-7p5r-7c3q/GHSA-68c7-7p5r-7c3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-697q-5f36-g4h9/GHSA-697q-5f36-g4h9.json b/advisories/unreviewed/2022/05/GHSA-697q-5f36-g4h9/GHSA-697q-5f36-g4h9.json index 0a568fa6ab2..901cd20b0cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-697q-5f36-g4h9/GHSA-697q-5f36-g4h9.json +++ b/advisories/unreviewed/2022/05/GHSA-697q-5f36-g4h9/GHSA-697q-5f36-g4h9.json @@ -7,12 +7,8 @@ "CVE-2011-1081" ], "details": "modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6f37-5xj5-jmhh/GHSA-6f37-5xj5-jmhh.json b/advisories/unreviewed/2022/05/GHSA-6f37-5xj5-jmhh/GHSA-6f37-5xj5-jmhh.json index e7e15f89879..2e7e77845ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f37-5xj5-jmhh/GHSA-6f37-5xj5-jmhh.json +++ b/advisories/unreviewed/2022/05/GHSA-6f37-5xj5-jmhh/GHSA-6f37-5xj5-jmhh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fh4-f2fp-rjwp/GHSA-6fh4-f2fp-rjwp.json b/advisories/unreviewed/2022/05/GHSA-6fh4-f2fp-rjwp/GHSA-6fh4-f2fp-rjwp.json index 902b20c4f35..b0fa6a07816 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fh4-f2fp-rjwp/GHSA-6fh4-f2fp-rjwp.json +++ b/advisories/unreviewed/2022/05/GHSA-6fh4-f2fp-rjwp/GHSA-6fh4-f2fp-rjwp.json @@ -7,12 +7,8 @@ "CVE-2010-4434" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.50.0 through 8.50.14 and 8.51.0 through 8.51.04 allows remote authenticated users to affect confidentiality via unknown vectors related to Portal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fj9-8rr3-5f7v/GHSA-6fj9-8rr3-5f7v.json b/advisories/unreviewed/2022/05/GHSA-6fj9-8rr3-5f7v/GHSA-6fj9-8rr3-5f7v.json index e33d9ab61be..877cf14e84c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fj9-8rr3-5f7v/GHSA-6fj9-8rr3-5f7v.json +++ b/advisories/unreviewed/2022/05/GHSA-6fj9-8rr3-5f7v/GHSA-6fj9-8rr3-5f7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gmv-88w5-24w6/GHSA-6gmv-88w5-24w6.json b/advisories/unreviewed/2022/05/GHSA-6gmv-88w5-24w6/GHSA-6gmv-88w5-24w6.json index 9855440b30d..7b536fc91cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gmv-88w5-24w6/GHSA-6gmv-88w5-24w6.json +++ b/advisories/unreviewed/2022/05/GHSA-6gmv-88w5-24w6/GHSA-6gmv-88w5-24w6.json @@ -7,12 +7,8 @@ "CVE-2011-1414" ], "details": "Cross-site scripting (XSS) vulnerability in the tibbr web server, as used in TIBCO tibbr 1.0.0 through 1.5.0 and tibbr Service 1.0.0 through 1.5.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gxj-qxj4-wm7j/GHSA-6gxj-qxj4-wm7j.json b/advisories/unreviewed/2022/05/GHSA-6gxj-qxj4-wm7j/GHSA-6gxj-qxj4-wm7j.json index edd38022e47..d712f3c4ef7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gxj-qxj4-wm7j/GHSA-6gxj-qxj4-wm7j.json +++ b/advisories/unreviewed/2022/05/GHSA-6gxj-qxj4-wm7j/GHSA-6gxj-qxj4-wm7j.json @@ -7,12 +7,8 @@ "CVE-2011-0991" ], "details": "Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to finalizing and then resurrecting a DynamicMethod instance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j5j-pw44-wfwj/GHSA-6j5j-pw44-wfwj.json b/advisories/unreviewed/2022/05/GHSA-6j5j-pw44-wfwj/GHSA-6j5j-pw44-wfwj.json index b6bfad4b807..9b64fd302e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j5j-pw44-wfwj/GHSA-6j5j-pw44-wfwj.json +++ b/advisories/unreviewed/2022/05/GHSA-6j5j-pw44-wfwj/GHSA-6j5j-pw44-wfwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6m9j-qm9r-jrxm/GHSA-6m9j-qm9r-jrxm.json b/advisories/unreviewed/2022/05/GHSA-6m9j-qm9r-jrxm/GHSA-6m9j-qm9r-jrxm.json index af4610f75b1..f6df29e04f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m9j-qm9r-jrxm/GHSA-6m9j-qm9r-jrxm.json +++ b/advisories/unreviewed/2022/05/GHSA-6m9j-qm9r-jrxm/GHSA-6m9j-qm9r-jrxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mpg-fqxp-qcp9/GHSA-6mpg-fqxp-qcp9.json b/advisories/unreviewed/2022/05/GHSA-6mpg-fqxp-qcp9/GHSA-6mpg-fqxp-qcp9.json index ef24b4e928d..8a7d26d5524 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mpg-fqxp-qcp9/GHSA-6mpg-fqxp-qcp9.json +++ b/advisories/unreviewed/2022/05/GHSA-6mpg-fqxp-qcp9/GHSA-6mpg-fqxp-qcp9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6p2p-vj22-cmm3/GHSA-6p2p-vj22-cmm3.json b/advisories/unreviewed/2022/05/GHSA-6p2p-vj22-cmm3/GHSA-6p2p-vj22-cmm3.json index c4654587be1..0a6d923219b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p2p-vj22-cmm3/GHSA-6p2p-vj22-cmm3.json +++ b/advisories/unreviewed/2022/05/GHSA-6p2p-vj22-cmm3/GHSA-6p2p-vj22-cmm3.json @@ -7,12 +7,8 @@ "CVE-2011-0161" ], "details": "WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rhw-x726-9gwr/GHSA-6rhw-x726-9gwr.json b/advisories/unreviewed/2022/05/GHSA-6rhw-x726-9gwr/GHSA-6rhw-x726-9gwr.json index 6e083cbdec5..78ce1c0d08e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rhw-x726-9gwr/GHSA-6rhw-x726-9gwr.json +++ b/advisories/unreviewed/2022/05/GHSA-6rhw-x726-9gwr/GHSA-6rhw-x726-9gwr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v7q-gh5p-vgqc/GHSA-6v7q-gh5p-vgqc.json b/advisories/unreviewed/2022/05/GHSA-6v7q-gh5p-vgqc/GHSA-6v7q-gh5p-vgqc.json index 02e1d3b844e..59db4325fe4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v7q-gh5p-vgqc/GHSA-6v7q-gh5p-vgqc.json +++ b/advisories/unreviewed/2022/05/GHSA-6v7q-gh5p-vgqc/GHSA-6v7q-gh5p-vgqc.json @@ -7,12 +7,8 @@ "CVE-2011-1920" ], "details": "The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend##### temporary file, related to (1) bsd.lib.mk and (2) bsd.prog.mk.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6w75-jr8q-wwpv/GHSA-6w75-jr8q-wwpv.json b/advisories/unreviewed/2022/05/GHSA-6w75-jr8q-wwpv/GHSA-6w75-jr8q-wwpv.json index 9f40015a4fb..115b31073af 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w75-jr8q-wwpv/GHSA-6w75-jr8q-wwpv.json +++ b/advisories/unreviewed/2022/05/GHSA-6w75-jr8q-wwpv/GHSA-6w75-jr8q-wwpv.json @@ -7,12 +7,8 @@ "CVE-2011-1308" ], "details": "Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wqp-749m-jfw7/GHSA-6wqp-749m-jfw7.json b/advisories/unreviewed/2022/05/GHSA-6wqp-749m-jfw7/GHSA-6wqp-749m-jfw7.json index 60df192deba..6ecfb1b4051 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wqp-749m-jfw7/GHSA-6wqp-749m-jfw7.json +++ b/advisories/unreviewed/2022/05/GHSA-6wqp-749m-jfw7/GHSA-6wqp-749m-jfw7.json @@ -7,12 +7,8 @@ "CVE-2011-0721" ], "details": "Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xx2-h456-85xh/GHSA-6xx2-h456-85xh.json b/advisories/unreviewed/2022/05/GHSA-6xx2-h456-85xh/GHSA-6xx2-h456-85xh.json index 06adfc57312..5e9c455a831 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xx2-h456-85xh/GHSA-6xx2-h456-85xh.json +++ b/advisories/unreviewed/2022/05/GHSA-6xx2-h456-85xh/GHSA-6xx2-h456-85xh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xx4-5cv4-g34r/GHSA-6xx4-5cv4-g34r.json b/advisories/unreviewed/2022/05/GHSA-6xx4-5cv4-g34r/GHSA-6xx4-5cv4-g34r.json index 9bb51a37fc8..7c83447bad1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xx4-5cv4-g34r/GHSA-6xx4-5cv4-g34r.json +++ b/advisories/unreviewed/2022/05/GHSA-6xx4-5cv4-g34r/GHSA-6xx4-5cv4-g34r.json @@ -7,12 +7,8 @@ "CVE-2011-1667" ], "details": "SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands via the q parameter in a list action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-727h-w92q-ch5h/GHSA-727h-w92q-ch5h.json b/advisories/unreviewed/2022/05/GHSA-727h-w92q-ch5h/GHSA-727h-w92q-ch5h.json index b098c324db9..b7e2a2c964d 100644 --- a/advisories/unreviewed/2022/05/GHSA-727h-w92q-ch5h/GHSA-727h-w92q-ch5h.json +++ b/advisories/unreviewed/2022/05/GHSA-727h-w92q-ch5h/GHSA-727h-w92q-ch5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74xx-pqw5-w2m2/GHSA-74xx-pqw5-w2m2.json b/advisories/unreviewed/2022/05/GHSA-74xx-pqw5-w2m2/GHSA-74xx-pqw5-w2m2.json index 2884aba9b8b..199cc1ad0ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-74xx-pqw5-w2m2/GHSA-74xx-pqw5-w2m2.json +++ b/advisories/unreviewed/2022/05/GHSA-74xx-pqw5-w2m2/GHSA-74xx-pqw5-w2m2.json @@ -7,12 +7,8 @@ "CVE-2011-0896" ], "details": "Unspecified vulnerability in HP NFS/ONCplus B.11.31.10 and earlier on HP-UX B.11.31 allows remote authenticated users to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75hx-fx5h-j6hw/GHSA-75hx-fx5h-j6hw.json b/advisories/unreviewed/2022/05/GHSA-75hx-fx5h-j6hw/GHSA-75hx-fx5h-j6hw.json index fb86a8d8b37..9ff8954ad84 100644 --- a/advisories/unreviewed/2022/05/GHSA-75hx-fx5h-j6hw/GHSA-75hx-fx5h-j6hw.json +++ b/advisories/unreviewed/2022/05/GHSA-75hx-fx5h-j6hw/GHSA-75hx-fx5h-j6hw.json @@ -7,12 +7,8 @@ "CVE-2010-4428" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.0 Update 2010-F allows remote authenticated users to affect confidentiality via unknown vectors related to Absence Management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75m8-pqjg-gwwv/GHSA-75m8-pqjg-gwwv.json b/advisories/unreviewed/2022/05/GHSA-75m8-pqjg-gwwv/GHSA-75m8-pqjg-gwwv.json index 296df7bcbb9..6a8eaf4d007 100644 --- a/advisories/unreviewed/2022/05/GHSA-75m8-pqjg-gwwv/GHSA-75m8-pqjg-gwwv.json +++ b/advisories/unreviewed/2022/05/GHSA-75m8-pqjg-gwwv/GHSA-75m8-pqjg-gwwv.json @@ -7,12 +7,8 @@ "CVE-2010-4719" ], "details": "Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75w9-f53w-7vh5/GHSA-75w9-f53w-7vh5.json b/advisories/unreviewed/2022/05/GHSA-75w9-f53w-7vh5/GHSA-75w9-f53w-7vh5.json index 6b469cc3d20..96e1a7d7e32 100644 --- a/advisories/unreviewed/2022/05/GHSA-75w9-f53w-7vh5/GHSA-75w9-f53w-7vh5.json +++ b/advisories/unreviewed/2022/05/GHSA-75w9-f53w-7vh5/GHSA-75w9-f53w-7vh5.json @@ -7,12 +7,8 @@ "CVE-2011-1390" ], "details": "SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76jp-9697-7322/GHSA-76jp-9697-7322.json b/advisories/unreviewed/2022/05/GHSA-76jp-9697-7322/GHSA-76jp-9697-7322.json index 16cb5ba6d7d..e25b8fb4b90 100644 --- a/advisories/unreviewed/2022/05/GHSA-76jp-9697-7322/GHSA-76jp-9697-7322.json +++ b/advisories/unreviewed/2022/05/GHSA-76jp-9697-7322/GHSA-76jp-9697-7322.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76ph-hphh-2jgj/GHSA-76ph-hphh-2jgj.json b/advisories/unreviewed/2022/05/GHSA-76ph-hphh-2jgj/GHSA-76ph-hphh-2jgj.json index 5e0acadc4ff..cace92d51cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-76ph-hphh-2jgj/GHSA-76ph-hphh-2jgj.json +++ b/advisories/unreviewed/2022/05/GHSA-76ph-hphh-2jgj/GHSA-76ph-hphh-2jgj.json @@ -7,12 +7,8 @@ "CVE-2011-0349" ], "details": "Unspecified vulnerability in Cisco IOS 12.4(24)MD before 12.4(24)MD2 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to cause a denial of service (device hang or reload) via crafted TCP packets, aka Bug ID CSCth17178, a different vulnerability than CVE-2011-0350.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77q5-xr9p-645w/GHSA-77q5-xr9p-645w.json b/advisories/unreviewed/2022/05/GHSA-77q5-xr9p-645w/GHSA-77q5-xr9p-645w.json index 733e22bfdbe..b48411ee35d 100644 --- a/advisories/unreviewed/2022/05/GHSA-77q5-xr9p-645w/GHSA-77q5-xr9p-645w.json +++ b/advisories/unreviewed/2022/05/GHSA-77q5-xr9p-645w/GHSA-77q5-xr9p-645w.json @@ -7,12 +7,8 @@ "CVE-2011-0889" ], "details": "Unspecified vulnerability in HP Client Automation Enterprise (aka HPCA or Radia Notify) 5.11, 7.2, 7.5, 7.8, and 7.9 allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7842-gcxf-cmg8/GHSA-7842-gcxf-cmg8.json b/advisories/unreviewed/2022/05/GHSA-7842-gcxf-cmg8/GHSA-7842-gcxf-cmg8.json index 70e2e8f19d4..0036df44f6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7842-gcxf-cmg8/GHSA-7842-gcxf-cmg8.json +++ b/advisories/unreviewed/2022/05/GHSA-7842-gcxf-cmg8/GHSA-7842-gcxf-cmg8.json @@ -7,12 +7,8 @@ "CVE-2011-1364" ], "details": "Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console) in the Google App Engine Python SDK before 1.5.4 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary Python code via the code parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78c4-hp78-4mrr/GHSA-78c4-hp78-4mrr.json b/advisories/unreviewed/2022/05/GHSA-78c4-hp78-4mrr/GHSA-78c4-hp78-4mrr.json index 1a2bf967a9b..e95b306e63d 100644 --- a/advisories/unreviewed/2022/05/GHSA-78c4-hp78-4mrr/GHSA-78c4-hp78-4mrr.json +++ b/advisories/unreviewed/2022/05/GHSA-78c4-hp78-4mrr/GHSA-78c4-hp78-4mrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78gc-jmvw-x2mx/GHSA-78gc-jmvw-x2mx.json b/advisories/unreviewed/2022/05/GHSA-78gc-jmvw-x2mx/GHSA-78gc-jmvw-x2mx.json index 73a65363240..2c273603811 100644 --- a/advisories/unreviewed/2022/05/GHSA-78gc-jmvw-x2mx/GHSA-78gc-jmvw-x2mx.json +++ b/advisories/unreviewed/2022/05/GHSA-78gc-jmvw-x2mx/GHSA-78gc-jmvw-x2mx.json @@ -7,12 +7,8 @@ "CVE-2011-0441" ], "details": "The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c3f-vrwq-r85g/GHSA-7c3f-vrwq-r85g.json b/advisories/unreviewed/2022/05/GHSA-7c3f-vrwq-r85g/GHSA-7c3f-vrwq-r85g.json index 851ae076955..d5454b3cf52 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c3f-vrwq-r85g/GHSA-7c3f-vrwq-r85g.json +++ b/advisories/unreviewed/2022/05/GHSA-7c3f-vrwq-r85g/GHSA-7c3f-vrwq-r85g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7cmx-w79g-cwf8/GHSA-7cmx-w79g-cwf8.json b/advisories/unreviewed/2022/05/GHSA-7cmx-w79g-cwf8/GHSA-7cmx-w79g-cwf8.json index e67b0b961a0..35920c5b695 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cmx-w79g-cwf8/GHSA-7cmx-w79g-cwf8.json +++ b/advisories/unreviewed/2022/05/GHSA-7cmx-w79g-cwf8/GHSA-7cmx-w79g-cwf8.json @@ -7,12 +7,8 @@ "CVE-2010-4745" ], "details": "Cross-site scripting (XSS) vulnerability in nav.html in PHPXref before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g36-rq2m-mrf6/GHSA-7g36-rq2m-mrf6.json b/advisories/unreviewed/2022/05/GHSA-7g36-rq2m-mrf6/GHSA-7g36-rq2m-mrf6.json index 807109e51fd..0cf06389bbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g36-rq2m-mrf6/GHSA-7g36-rq2m-mrf6.json +++ b/advisories/unreviewed/2022/05/GHSA-7g36-rq2m-mrf6/GHSA-7g36-rq2m-mrf6.json @@ -7,12 +7,8 @@ "CVE-2011-1687" ], "details": "Best Practical Solutions RT 3.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote authenticated users to obtain sensitive information by using the search interface, as demonstrated by retrieving encrypted passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7ggh-v837-ff2g/GHSA-7ggh-v837-ff2g.json b/advisories/unreviewed/2022/05/GHSA-7ggh-v837-ff2g/GHSA-7ggh-v837-ff2g.json index 3b062ce37f5..3c68c402562 100644 --- a/advisories/unreviewed/2022/05/GHSA-7ggh-v837-ff2g/GHSA-7ggh-v837-ff2g.json +++ b/advisories/unreviewed/2022/05/GHSA-7ggh-v837-ff2g/GHSA-7ggh-v837-ff2g.json @@ -7,12 +7,8 @@ "CVE-2010-3158" ], "details": "Untrusted search path vulnerability in Lhaplus before 1.58 allows local users to gain privileges via a Trojan horse executable file in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7gjp-mccf-jrm5/GHSA-7gjp-mccf-jrm5.json b/advisories/unreviewed/2022/05/GHSA-7gjp-mccf-jrm5/GHSA-7gjp-mccf-jrm5.json index 0386aacc44a..71a36c95144 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gjp-mccf-jrm5/GHSA-7gjp-mccf-jrm5.json +++ b/advisories/unreviewed/2022/05/GHSA-7gjp-mccf-jrm5/GHSA-7gjp-mccf-jrm5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hr3-g9fq-x7fw/GHSA-7hr3-g9fq-x7fw.json b/advisories/unreviewed/2022/05/GHSA-7hr3-g9fq-x7fw/GHSA-7hr3-g9fq-x7fw.json index a0405c59f98..194e60acd7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hr3-g9fq-x7fw/GHSA-7hr3-g9fq-x7fw.json +++ b/advisories/unreviewed/2022/05/GHSA-7hr3-g9fq-x7fw/GHSA-7hr3-g9fq-x7fw.json @@ -7,12 +7,8 @@ "CVE-2011-0436" ], "details": "The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mail message, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7hx7-q7rx-7h3h/GHSA-7hx7-q7rx-7h3h.json b/advisories/unreviewed/2022/05/GHSA-7hx7-q7rx-7h3h/GHSA-7hx7-q7rx-7h3h.json index a93a2ec127b..fa675cd791a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hx7-q7rx-7h3h/GHSA-7hx7-q7rx-7h3h.json +++ b/advisories/unreviewed/2022/05/GHSA-7hx7-q7rx-7h3h/GHSA-7hx7-q7rx-7h3h.json @@ -7,12 +7,8 @@ "CVE-2011-0899" ], "details": "The AES encryption module 7.x-1.4 for Drupal leaves certain debugging code enabled in release, which records the plaintext password of the last logged-in user and allows remote attackers to gain privileges as that user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7px8-9g52-58qr/GHSA-7px8-9g52-58qr.json b/advisories/unreviewed/2022/05/GHSA-7px8-9g52-58qr/GHSA-7px8-9g52-58qr.json index 651b5560bcc..05de7552794 100644 --- a/advisories/unreviewed/2022/05/GHSA-7px8-9g52-58qr/GHSA-7px8-9g52-58qr.json +++ b/advisories/unreviewed/2022/05/GHSA-7px8-9g52-58qr/GHSA-7px8-9g52-58qr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qmv-52x2-wcqx/GHSA-7qmv-52x2-wcqx.json b/advisories/unreviewed/2022/05/GHSA-7qmv-52x2-wcqx/GHSA-7qmv-52x2-wcqx.json index 1c3874f4511..33bc4e8f666 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qmv-52x2-wcqx/GHSA-7qmv-52x2-wcqx.json +++ b/advisories/unreviewed/2022/05/GHSA-7qmv-52x2-wcqx/GHSA-7qmv-52x2-wcqx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7r94-35cw-4j7r/GHSA-7r94-35cw-4j7r.json b/advisories/unreviewed/2022/05/GHSA-7r94-35cw-4j7r/GHSA-7r94-35cw-4j7r.json index b7e9019b74d..083d96347a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r94-35cw-4j7r/GHSA-7r94-35cw-4j7r.json +++ b/advisories/unreviewed/2022/05/GHSA-7r94-35cw-4j7r/GHSA-7r94-35cw-4j7r.json @@ -7,12 +7,8 @@ "CVE-2011-0773" ], "details": "Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rj2-8vxc-4g4c/GHSA-7rj2-8vxc-4g4c.json b/advisories/unreviewed/2022/05/GHSA-7rj2-8vxc-4g4c/GHSA-7rj2-8vxc-4g4c.json index 819d473d766..32f9d407ef2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rj2-8vxc-4g4c/GHSA-7rj2-8vxc-4g4c.json +++ b/advisories/unreviewed/2022/05/GHSA-7rj2-8vxc-4g4c/GHSA-7rj2-8vxc-4g4c.json @@ -7,12 +7,8 @@ "CVE-2011-0266" ], "details": "Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long nameParams parameter, a different vulnerability than CVE-2011-0267.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rxx-w8q3-rg72/GHSA-7rxx-w8q3-rg72.json b/advisories/unreviewed/2022/05/GHSA-7rxx-w8q3-rg72/GHSA-7rxx-w8q3-rg72.json index 9ed49ce9a33..c59d03e5534 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rxx-w8q3-rg72/GHSA-7rxx-w8q3-rg72.json +++ b/advisories/unreviewed/2022/05/GHSA-7rxx-w8q3-rg72/GHSA-7rxx-w8q3-rg72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7v6j-5qh6-4pwp/GHSA-7v6j-5qh6-4pwp.json b/advisories/unreviewed/2022/05/GHSA-7v6j-5qh6-4pwp/GHSA-7v6j-5qh6-4pwp.json index 68dcbb030c3..f7ca7572ff1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v6j-5qh6-4pwp/GHSA-7v6j-5qh6-4pwp.json +++ b/advisories/unreviewed/2022/05/GHSA-7v6j-5qh6-4pwp/GHSA-7v6j-5qh6-4pwp.json @@ -7,12 +7,8 @@ "CVE-2011-0724" ], "details": "The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installation to have the same fixed key, which allows remote attackers to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vq7-qcwq-j3vc/GHSA-7vq7-qcwq-j3vc.json b/advisories/unreviewed/2022/05/GHSA-7vq7-qcwq-j3vc/GHSA-7vq7-qcwq-j3vc.json index cd07fa20570..8b44612fb29 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vq7-qcwq-j3vc/GHSA-7vq7-qcwq-j3vc.json +++ b/advisories/unreviewed/2022/05/GHSA-7vq7-qcwq-j3vc/GHSA-7vq7-qcwq-j3vc.json @@ -7,12 +7,8 @@ "CVE-2011-0520" ], "details": "The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long DNS hostname with a large number of labels, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wrc-jf8c-7fmx/GHSA-7wrc-jf8c-7fmx.json b/advisories/unreviewed/2022/05/GHSA-7wrc-jf8c-7fmx/GHSA-7wrc-jf8c-7fmx.json index 1677a92100f..4e8c4919fbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wrc-jf8c-7fmx/GHSA-7wrc-jf8c-7fmx.json +++ b/advisories/unreviewed/2022/05/GHSA-7wrc-jf8c-7fmx/GHSA-7wrc-jf8c-7fmx.json @@ -7,12 +7,8 @@ "CVE-2011-0383" ], "details": "The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug IDs CSCtf42005 and CSCtf42008.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7x69-vj7p-23wv/GHSA-7x69-vj7p-23wv.json b/advisories/unreviewed/2022/05/GHSA-7x69-vj7p-23wv/GHSA-7x69-vj7p-23wv.json index 7dc5ea6c12e..6939a2b7b5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x69-vj7p-23wv/GHSA-7x69-vj7p-23wv.json +++ b/advisories/unreviewed/2022/05/GHSA-7x69-vj7p-23wv/GHSA-7x69-vj7p-23wv.json @@ -7,12 +7,8 @@ "CVE-2011-0629" ], "details": "Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xr4-52vv-2ffw/GHSA-7xr4-52vv-2ffw.json b/advisories/unreviewed/2022/05/GHSA-7xr4-52vv-2ffw/GHSA-7xr4-52vv-2ffw.json index 71dee5a8c67..c61eb3d2bb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xr4-52vv-2ffw/GHSA-7xr4-52vv-2ffw.json +++ b/advisories/unreviewed/2022/05/GHSA-7xr4-52vv-2ffw/GHSA-7xr4-52vv-2ffw.json @@ -7,12 +7,8 @@ "CVE-2010-3350" ], "details": "bareFTP 0.3.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82hw-277w-7pw5/GHSA-82hw-277w-7pw5.json b/advisories/unreviewed/2022/05/GHSA-82hw-277w-7pw5/GHSA-82hw-277w-7pw5.json index 11638524add..2090b40fb55 100644 --- a/advisories/unreviewed/2022/05/GHSA-82hw-277w-7pw5/GHSA-82hw-277w-7pw5.json +++ b/advisories/unreviewed/2022/05/GHSA-82hw-277w-7pw5/GHSA-82hw-277w-7pw5.json @@ -7,12 +7,8 @@ "CVE-2010-4431" ], "details": "Unspecified vulnerability in Oracle Sun Java System Portal Server 7.1 and 7.2 allows local users to affect confidentiality via unknown vectors related to Proxy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-832p-pfmm-vjj7/GHSA-832p-pfmm-vjj7.json b/advisories/unreviewed/2022/05/GHSA-832p-pfmm-vjj7/GHSA-832p-pfmm-vjj7.json index e1292cb58d5..8e69485228d 100644 --- a/advisories/unreviewed/2022/05/GHSA-832p-pfmm-vjj7/GHSA-832p-pfmm-vjj7.json +++ b/advisories/unreviewed/2022/05/GHSA-832p-pfmm-vjj7/GHSA-832p-pfmm-vjj7.json @@ -7,12 +7,8 @@ "CVE-2011-1306" ], "details": "Unspecified vulnerability in the Scratchpad application in Google Chrome OS before R10 0.10.156.46 Beta has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8369-6qrq-42rr/GHSA-8369-6qrq-42rr.json b/advisories/unreviewed/2022/05/GHSA-8369-6qrq-42rr/GHSA-8369-6qrq-42rr.json index 28b0e51dc74..a5ac7e36d23 100644 --- a/advisories/unreviewed/2022/05/GHSA-8369-6qrq-42rr/GHSA-8369-6qrq-42rr.json +++ b/advisories/unreviewed/2022/05/GHSA-8369-6qrq-42rr/GHSA-8369-6qrq-42rr.json @@ -7,12 +7,8 @@ "CVE-2011-0262" ], "details": "Buffer overflow in the stringToSeconds function in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via large values of variables to jovgraph.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83mw-xpgw-63qr/GHSA-83mw-xpgw-63qr.json b/advisories/unreviewed/2022/05/GHSA-83mw-xpgw-63qr/GHSA-83mw-xpgw-63qr.json index 41ac8460e9a..eddf273a413 100644 --- a/advisories/unreviewed/2022/05/GHSA-83mw-xpgw-63qr/GHSA-83mw-xpgw-63qr.json +++ b/advisories/unreviewed/2022/05/GHSA-83mw-xpgw-63qr/GHSA-83mw-xpgw-63qr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84qx-w96q-23c8/GHSA-84qx-w96q-23c8.json b/advisories/unreviewed/2022/05/GHSA-84qx-w96q-23c8/GHSA-84qx-w96q-23c8.json index 6faefc6aad2..4f0cdfa8a62 100644 --- a/advisories/unreviewed/2022/05/GHSA-84qx-w96q-23c8/GHSA-84qx-w96q-23c8.json +++ b/advisories/unreviewed/2022/05/GHSA-84qx-w96q-23c8/GHSA-84qx-w96q-23c8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84rp-f8pv-g8m7/GHSA-84rp-f8pv-g8m7.json b/advisories/unreviewed/2022/05/GHSA-84rp-f8pv-g8m7/GHSA-84rp-f8pv-g8m7.json index a791ef629dd..2826041d565 100644 --- a/advisories/unreviewed/2022/05/GHSA-84rp-f8pv-g8m7/GHSA-84rp-f8pv-g8m7.json +++ b/advisories/unreviewed/2022/05/GHSA-84rp-f8pv-g8m7/GHSA-84rp-f8pv-g8m7.json @@ -7,12 +7,8 @@ "CVE-2010-4416" ], "details": "Unspecified vulnerability in the Oracle GoldenGate Veridata component in Oracle Fusion Middleware 3.0.0.4 allows remote attackers to affect availability via unknown vectors related to Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party researcher that this is a buffer overflow via a crafted XML soap request and a value that does not contain the expected 0x20 terminator character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-854h-gmvf-x57p/GHSA-854h-gmvf-x57p.json b/advisories/unreviewed/2022/05/GHSA-854h-gmvf-x57p/GHSA-854h-gmvf-x57p.json index f2b21499d42..6cedaa4e83a 100644 --- a/advisories/unreviewed/2022/05/GHSA-854h-gmvf-x57p/GHSA-854h-gmvf-x57p.json +++ b/advisories/unreviewed/2022/05/GHSA-854h-gmvf-x57p/GHSA-854h-gmvf-x57p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8585-gvw6-24g3/GHSA-8585-gvw6-24g3.json b/advisories/unreviewed/2022/05/GHSA-8585-gvw6-24g3/GHSA-8585-gvw6-24g3.json index d29710ee7f2..504aae8e607 100644 --- a/advisories/unreviewed/2022/05/GHSA-8585-gvw6-24g3/GHSA-8585-gvw6-24g3.json +++ b/advisories/unreviewed/2022/05/GHSA-8585-gvw6-24g3/GHSA-8585-gvw6-24g3.json @@ -7,12 +7,8 @@ "CVE-2011-0387" ], "details": "The administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote authenticated users to cause a denial of service or have unspecified other impact via vectors involving access to a servlet, aka Bug ID CSCtf97164.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85x6-4jmm-mx7r/GHSA-85x6-4jmm-mx7r.json b/advisories/unreviewed/2022/05/GHSA-85x6-4jmm-mx7r/GHSA-85x6-4jmm-mx7r.json index 5d4b414dbf4..75f0cb05caa 100644 --- a/advisories/unreviewed/2022/05/GHSA-85x6-4jmm-mx7r/GHSA-85x6-4jmm-mx7r.json +++ b/advisories/unreviewed/2022/05/GHSA-85x6-4jmm-mx7r/GHSA-85x6-4jmm-mx7r.json @@ -7,12 +7,8 @@ "CVE-2011-1727" ], "details": "Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an \"HTML injection\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-866w-gx4x-q287/GHSA-866w-gx4x-q287.json b/advisories/unreviewed/2022/05/GHSA-866w-gx4x-q287/GHSA-866w-gx4x-q287.json index d1034f642ba..c7269af8647 100644 --- a/advisories/unreviewed/2022/05/GHSA-866w-gx4x-q287/GHSA-866w-gx4x-q287.json +++ b/advisories/unreviewed/2022/05/GHSA-866w-gx4x-q287/GHSA-866w-gx4x-q287.json @@ -7,12 +7,8 @@ "CVE-2011-0455" ], "details": "Cross-site scripting (XSS) vulnerability in Things BBS before 2.0.3 and BBS Thread before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-876x-3ww3-wx43/GHSA-876x-3ww3-wx43.json b/advisories/unreviewed/2022/05/GHSA-876x-3ww3-wx43/GHSA-876x-3ww3-wx43.json index 83d76eb24c7..8a2bd696493 100644 --- a/advisories/unreviewed/2022/05/GHSA-876x-3ww3-wx43/GHSA-876x-3ww3-wx43.json +++ b/advisories/unreviewed/2022/05/GHSA-876x-3ww3-wx43/GHSA-876x-3ww3-wx43.json @@ -7,12 +7,8 @@ "CVE-2011-1669" ], "details": "Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cpj-p4g2-v3pc/GHSA-8cpj-p4g2-v3pc.json b/advisories/unreviewed/2022/05/GHSA-8cpj-p4g2-v3pc/GHSA-8cpj-p4g2-v3pc.json index b96cffc293f..ad107111171 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cpj-p4g2-v3pc/GHSA-8cpj-p4g2-v3pc.json +++ b/advisories/unreviewed/2022/05/GHSA-8cpj-p4g2-v3pc/GHSA-8cpj-p4g2-v3pc.json @@ -7,12 +7,8 @@ "CVE-2011-0380" ], "details": "Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8f23-mxmj-hcw5/GHSA-8f23-mxmj-hcw5.json b/advisories/unreviewed/2022/05/GHSA-8f23-mxmj-hcw5/GHSA-8f23-mxmj-hcw5.json index 199fda5ada8..d1c378ff666 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f23-mxmj-hcw5/GHSA-8f23-mxmj-hcw5.json +++ b/advisories/unreviewed/2022/05/GHSA-8f23-mxmj-hcw5/GHSA-8f23-mxmj-hcw5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8f67-f75m-fxfm/GHSA-8f67-f75m-fxfm.json b/advisories/unreviewed/2022/05/GHSA-8f67-f75m-fxfm/GHSA-8f67-f75m-fxfm.json index fbe96d58c8e..56e7f0a4cbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f67-f75m-fxfm/GHSA-8f67-f75m-fxfm.json +++ b/advisories/unreviewed/2022/05/GHSA-8f67-f75m-fxfm/GHSA-8f67-f75m-fxfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fr7-2mr9-63wj/GHSA-8fr7-2mr9-63wj.json b/advisories/unreviewed/2022/05/GHSA-8fr7-2mr9-63wj/GHSA-8fr7-2mr9-63wj.json index 882c57d341f..15a76da7dfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fr7-2mr9-63wj/GHSA-8fr7-2mr9-63wj.json +++ b/advisories/unreviewed/2022/05/GHSA-8fr7-2mr9-63wj/GHSA-8fr7-2mr9-63wj.json @@ -7,12 +7,8 @@ "CVE-2011-0392" ], "details": "Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug ID CSCtg35833.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gcf-rhcm-7v68/GHSA-8gcf-rhcm-7v68.json b/advisories/unreviewed/2022/05/GHSA-8gcf-rhcm-7v68/GHSA-8gcf-rhcm-7v68.json index 9867e77039b..da333ee2d56 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gcf-rhcm-7v68/GHSA-8gcf-rhcm-7v68.json +++ b/advisories/unreviewed/2022/05/GHSA-8gcf-rhcm-7v68/GHSA-8gcf-rhcm-7v68.json @@ -7,12 +7,8 @@ "CVE-2010-3041" ], "details": "Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to atas32.dll, a different vulnerability than CVE-2010-3042, CVE-2010-3043, and CVE-2010-3044.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gh9-3698-mj6g/GHSA-8gh9-3698-mj6g.json b/advisories/unreviewed/2022/05/GHSA-8gh9-3698-mj6g/GHSA-8gh9-3698-mj6g.json index bc68c9d75bb..14211617e31 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gh9-3698-mj6g/GHSA-8gh9-3698-mj6g.json +++ b/advisories/unreviewed/2022/05/GHSA-8gh9-3698-mj6g/GHSA-8gh9-3698-mj6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h4h-9352-9m7v/GHSA-8h4h-9352-9m7v.json b/advisories/unreviewed/2022/05/GHSA-8h4h-9352-9m7v/GHSA-8h4h-9352-9m7v.json index 93094170d3d..492d1d0ab3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h4h-9352-9m7v/GHSA-8h4h-9352-9m7v.json +++ b/advisories/unreviewed/2022/05/GHSA-8h4h-9352-9m7v/GHSA-8h4h-9352-9m7v.json @@ -7,12 +7,8 @@ "CVE-2011-1356" ], "details": "IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hm3-4p5h-mv6g/GHSA-8hm3-4p5h-mv6g.json b/advisories/unreviewed/2022/05/GHSA-8hm3-4p5h-mv6g/GHSA-8hm3-4p5h-mv6g.json index fcefb42f319..f6b45f51f07 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hm3-4p5h-mv6g/GHSA-8hm3-4p5h-mv6g.json +++ b/advisories/unreviewed/2022/05/GHSA-8hm3-4p5h-mv6g/GHSA-8hm3-4p5h-mv6g.json @@ -7,12 +7,8 @@ "CVE-2011-1929" ], "details": "lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hxf-9chv-c2pv/GHSA-8hxf-9chv-c2pv.json b/advisories/unreviewed/2022/05/GHSA-8hxf-9chv-c2pv/GHSA-8hxf-9chv-c2pv.json index ef08842cfa1..d420d943da5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hxf-9chv-c2pv/GHSA-8hxf-9chv-c2pv.json +++ b/advisories/unreviewed/2022/05/GHSA-8hxf-9chv-c2pv/GHSA-8hxf-9chv-c2pv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jgw-rgrm-6q38/GHSA-8jgw-rgrm-6q38.json b/advisories/unreviewed/2022/05/GHSA-8jgw-rgrm-6q38/GHSA-8jgw-rgrm-6q38.json index 39c4f586d44..1c44334a058 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jgw-rgrm-6q38/GHSA-8jgw-rgrm-6q38.json +++ b/advisories/unreviewed/2022/05/GHSA-8jgw-rgrm-6q38/GHSA-8jgw-rgrm-6q38.json @@ -7,12 +7,8 @@ "CVE-2011-0269" ], "details": "Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long schd_select1 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p7m-w89h-34v5/GHSA-8p7m-w89h-34v5.json b/advisories/unreviewed/2022/05/GHSA-8p7m-w89h-34v5/GHSA-8p7m-w89h-34v5.json index 4e5eaed4cf4..fee15e52318 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p7m-w89h-34v5/GHSA-8p7m-w89h-34v5.json +++ b/advisories/unreviewed/2022/05/GHSA-8p7m-w89h-34v5/GHSA-8p7m-w89h-34v5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p8p-8qmp-rfr2/GHSA-8p8p-8qmp-rfr2.json b/advisories/unreviewed/2022/05/GHSA-8p8p-8qmp-rfr2/GHSA-8p8p-8qmp-rfr2.json index f1f15ca5c3c..e1b324fe386 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p8p-8qmp-rfr2/GHSA-8p8p-8qmp-rfr2.json +++ b/advisories/unreviewed/2022/05/GHSA-8p8p-8qmp-rfr2/GHSA-8p8p-8qmp-rfr2.json @@ -7,12 +7,8 @@ "CVE-2011-0530" ], "details": "Buffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to execute arbitrary code via a long request. NOTE: this issue exists because of a CVE-2005-3534 regression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8phm-24vg-g4ph/GHSA-8phm-24vg-g4ph.json b/advisories/unreviewed/2022/05/GHSA-8phm-24vg-g4ph/GHSA-8phm-24vg-g4ph.json index 1e505525927..6cfbb18c136 100644 --- a/advisories/unreviewed/2022/05/GHSA-8phm-24vg-g4ph/GHSA-8phm-24vg-g4ph.json +++ b/advisories/unreviewed/2022/05/GHSA-8phm-24vg-g4ph/GHSA-8phm-24vg-g4ph.json @@ -7,12 +7,8 @@ "CVE-2011-0901" ], "details": "Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allow user-assisted remote attackers to execute arbitrary code via a .RDP file with a long (1) username, (2) password, or (3) domain argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pvp-w328-qfwv/GHSA-8pvp-w328-qfwv.json b/advisories/unreviewed/2022/05/GHSA-8pvp-w328-qfwv/GHSA-8pvp-w328-qfwv.json index 801423cc01d..91593ce0260 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pvp-w328-qfwv/GHSA-8pvp-w328-qfwv.json +++ b/advisories/unreviewed/2022/05/GHSA-8pvp-w328-qfwv/GHSA-8pvp-w328-qfwv.json @@ -7,12 +7,8 @@ "CVE-2010-3290" ], "details": "Unspecified vulnerability in HP Systems Insight Manager (SIM) before 6.2 allows remote authenticated users to gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8pwh-g3mh-g2qj/GHSA-8pwh-g3mh-g2qj.json b/advisories/unreviewed/2022/05/GHSA-8pwh-g3mh-g2qj/GHSA-8pwh-g3mh-g2qj.json index 98f50f95015..71d8e166e45 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pwh-g3mh-g2qj/GHSA-8pwh-g3mh-g2qj.json +++ b/advisories/unreviewed/2022/05/GHSA-8pwh-g3mh-g2qj/GHSA-8pwh-g3mh-g2qj.json @@ -7,12 +7,8 @@ "CVE-2011-1433" ], "details": "The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the _UserLogin and _UserPW fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q2g-xrhx-2vj9/GHSA-8q2g-xrhx-2vj9.json b/advisories/unreviewed/2022/05/GHSA-8q2g-xrhx-2vj9/GHSA-8q2g-xrhx-2vj9.json index b0aab60da1a..4fa19cc5efa 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q2g-xrhx-2vj9/GHSA-8q2g-xrhx-2vj9.json +++ b/advisories/unreviewed/2022/05/GHSA-8q2g-xrhx-2vj9/GHSA-8q2g-xrhx-2vj9.json @@ -7,12 +7,8 @@ "CVE-2010-4429" ], "details": "Unspecified vulnerability in the Agile Core component in Oracle Supply Chain Products Suite 9.3.0.2 and 9.3.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Client, a different vulnerability than CVE-2010-3505.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q7c-5gh4-x64v/GHSA-8q7c-5gh4-x64v.json b/advisories/unreviewed/2022/05/GHSA-8q7c-5gh4-x64v/GHSA-8q7c-5gh4-x64v.json index 1759edac67f..7bd9e858a9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q7c-5gh4-x64v/GHSA-8q7c-5gh4-x64v.json +++ b/advisories/unreviewed/2022/05/GHSA-8q7c-5gh4-x64v/GHSA-8q7c-5gh4-x64v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q9q-68wf-88g9/GHSA-8q9q-68wf-88g9.json b/advisories/unreviewed/2022/05/GHSA-8q9q-68wf-88g9/GHSA-8q9q-68wf-88g9.json index 4dc274b50dd..b874ec74b33 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q9q-68wf-88g9/GHSA-8q9q-68wf-88g9.json +++ b/advisories/unreviewed/2022/05/GHSA-8q9q-68wf-88g9/GHSA-8q9q-68wf-88g9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qrq-h7pw-6rfg/GHSA-8qrq-h7pw-6rfg.json b/advisories/unreviewed/2022/05/GHSA-8qrq-h7pw-6rfg/GHSA-8qrq-h7pw-6rfg.json index 929b6977d97..a383eca1eb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qrq-h7pw-6rfg/GHSA-8qrq-h7pw-6rfg.json +++ b/advisories/unreviewed/2022/05/GHSA-8qrq-h7pw-6rfg/GHSA-8qrq-h7pw-6rfg.json @@ -7,12 +7,8 @@ "CVE-2011-1535" ], "details": "Unspecified vulnerability in HP Insight Control for Linux (aka IC-Linux) before 6.3 allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r4h-25v6-93q9/GHSA-8r4h-25v6-93q9.json b/advisories/unreviewed/2022/05/GHSA-8r4h-25v6-93q9/GHSA-8r4h-25v6-93q9.json index d94c7d8cc7a..4f3981e2e96 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r4h-25v6-93q9/GHSA-8r4h-25v6-93q9.json +++ b/advisories/unreviewed/2022/05/GHSA-8r4h-25v6-93q9/GHSA-8r4h-25v6-93q9.json @@ -7,12 +7,8 @@ "CVE-2010-3280" ], "details": "The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8r98-2jrh-g328/GHSA-8r98-2jrh-g328.json b/advisories/unreviewed/2022/05/GHSA-8r98-2jrh-g328/GHSA-8r98-2jrh-g328.json index 5f82d81f44e..764be7e380b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r98-2jrh-g328/GHSA-8r98-2jrh-g328.json +++ b/advisories/unreviewed/2022/05/GHSA-8r98-2jrh-g328/GHSA-8r98-2jrh-g328.json @@ -7,12 +7,8 @@ "CVE-2011-1722" ], "details": "Multiple SQL injection vulnerabilities in WEC Discussion Forum (wec_discussion) extension 2.1.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in April 2011.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rf9-5q8r-r2w8/GHSA-8rf9-5q8r-r2w8.json b/advisories/unreviewed/2022/05/GHSA-8rf9-5q8r-r2w8/GHSA-8rf9-5q8r-r2w8.json index fd7bbb32271..57531847bff 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rf9-5q8r-r2w8/GHSA-8rf9-5q8r-r2w8.json +++ b/advisories/unreviewed/2022/05/GHSA-8rf9-5q8r-r2w8/GHSA-8rf9-5q8r-r2w8.json @@ -7,12 +7,8 @@ "CVE-2011-0443" ], "details": "SQL injection vulnerability in inc/tinybb-settings.php in tinyBB 1.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rpv-957g-66xr/GHSA-8rpv-957g-66xr.json b/advisories/unreviewed/2022/05/GHSA-8rpv-957g-66xr/GHSA-8rpv-957g-66xr.json index fecd727a1e0..0584a32cbb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rpv-957g-66xr/GHSA-8rpv-957g-66xr.json +++ b/advisories/unreviewed/2022/05/GHSA-8rpv-957g-66xr/GHSA-8rpv-957g-66xr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vff-xvp2-m6wp/GHSA-8vff-xvp2-m6wp.json b/advisories/unreviewed/2022/05/GHSA-8vff-xvp2-m6wp/GHSA-8vff-xvp2-m6wp.json index 5d85e9bce16..7a2dc7addbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vff-xvp2-m6wp/GHSA-8vff-xvp2-m6wp.json +++ b/advisories/unreviewed/2022/05/GHSA-8vff-xvp2-m6wp/GHSA-8vff-xvp2-m6wp.json @@ -7,12 +7,8 @@ "CVE-2010-4751" ], "details": "SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the id parameter in an edituser action, a different vector than CVE-2008-6593, CVE-2010-3484, and CVE-2010-3485.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wg3-98jg-4824/GHSA-8wg3-98jg-4824.json b/advisories/unreviewed/2022/05/GHSA-8wg3-98jg-4824/GHSA-8wg3-98jg-4824.json index ed83409d37a..a6317a1b16f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wg3-98jg-4824/GHSA-8wg3-98jg-4824.json +++ b/advisories/unreviewed/2022/05/GHSA-8wg3-98jg-4824/GHSA-8wg3-98jg-4824.json @@ -7,12 +7,8 @@ "CVE-2011-1531" ], "details": "The webscan component in the Embedded Web Server (EWS) on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to read documents on the scan surface via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9284-wmfv-pjq2/GHSA-9284-wmfv-pjq2.json b/advisories/unreviewed/2022/05/GHSA-9284-wmfv-pjq2/GHSA-9284-wmfv-pjq2.json index ba34085e429..9e97ec013de 100644 --- a/advisories/unreviewed/2022/05/GHSA-9284-wmfv-pjq2/GHSA-9284-wmfv-pjq2.json +++ b/advisories/unreviewed/2022/05/GHSA-9284-wmfv-pjq2/GHSA-9284-wmfv-pjq2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93q5-9xfx-j4cw/GHSA-93q5-9xfx-j4cw.json b/advisories/unreviewed/2022/05/GHSA-93q5-9xfx-j4cw/GHSA-93q5-9xfx-j4cw.json index f60d58d876b..ba6139847ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-93q5-9xfx-j4cw/GHSA-93q5-9xfx-j4cw.json +++ b/advisories/unreviewed/2022/05/GHSA-93q5-9xfx-j4cw/GHSA-93q5-9xfx-j4cw.json @@ -7,12 +7,8 @@ "CVE-2011-1430" ], "details": "The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a \"plaintext command injection\" attack, a similar issue to CVE-2011-0411.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94c3-vwq8-frg9/GHSA-94c3-vwq8-frg9.json b/advisories/unreviewed/2022/05/GHSA-94c3-vwq8-frg9/GHSA-94c3-vwq8-frg9.json index 363f97050d6..df5412f7abe 100644 --- a/advisories/unreviewed/2022/05/GHSA-94c3-vwq8-frg9/GHSA-94c3-vwq8-frg9.json +++ b/advisories/unreviewed/2022/05/GHSA-94c3-vwq8-frg9/GHSA-94c3-vwq8-frg9.json @@ -7,12 +7,8 @@ "CVE-2011-1681" ], "details": "vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4.2-261024 and earlier attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to trigger corruption of this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95cx-gjq8-8gp7/GHSA-95cx-gjq8-8gp7.json b/advisories/unreviewed/2022/05/GHSA-95cx-gjq8-8gp7/GHSA-95cx-gjq8-8gp7.json index 8158d289cc8..cbf04341bf4 100644 --- a/advisories/unreviewed/2022/05/GHSA-95cx-gjq8-8gp7/GHSA-95cx-gjq8-8gp7.json +++ b/advisories/unreviewed/2022/05/GHSA-95cx-gjq8-8gp7/GHSA-95cx-gjq8-8gp7.json @@ -7,12 +7,8 @@ "CVE-2011-0272" ], "details": "Unspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, related to the HttpTunnel feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-95f5-grg9-mpvq/GHSA-95f5-grg9-mpvq.json b/advisories/unreviewed/2022/05/GHSA-95f5-grg9-mpvq/GHSA-95f5-grg9-mpvq.json index b77f1f3e7ca..360f1eeeac4 100644 --- a/advisories/unreviewed/2022/05/GHSA-95f5-grg9-mpvq/GHSA-95f5-grg9-mpvq.json +++ b/advisories/unreviewed/2022/05/GHSA-95f5-grg9-mpvq/GHSA-95f5-grg9-mpvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95pv-49p4-79mc/GHSA-95pv-49p4-79mc.json b/advisories/unreviewed/2022/05/GHSA-95pv-49p4-79mc/GHSA-95pv-49p4-79mc.json index de3abb36e0d..aaf3aa3b9f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-95pv-49p4-79mc/GHSA-95pv-49p4-79mc.json +++ b/advisories/unreviewed/2022/05/GHSA-95pv-49p4-79mc/GHSA-95pv-49p4-79mc.json @@ -7,12 +7,8 @@ "CVE-2011-0511" ], "details": "SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95xh-v26r-rgjw/GHSA-95xh-v26r-rgjw.json b/advisories/unreviewed/2022/05/GHSA-95xh-v26r-rgjw/GHSA-95xh-v26r-rgjw.json index 947a15d8541..4ce94b334a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-95xh-v26r-rgjw/GHSA-95xh-v26r-rgjw.json +++ b/advisories/unreviewed/2022/05/GHSA-95xh-v26r-rgjw/GHSA-95xh-v26r-rgjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-968h-hqr4-4xp2/GHSA-968h-hqr4-4xp2.json b/advisories/unreviewed/2022/05/GHSA-968h-hqr4-4xp2/GHSA-968h-hqr4-4xp2.json index b5cec98ee5e..c2442636104 100644 --- a/advisories/unreviewed/2022/05/GHSA-968h-hqr4-4xp2/GHSA-968h-hqr4-4xp2.json +++ b/advisories/unreviewed/2022/05/GHSA-968h-hqr4-4xp2/GHSA-968h-hqr4-4xp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-976p-w5qr-hpr2/GHSA-976p-w5qr-hpr2.json b/advisories/unreviewed/2022/05/GHSA-976p-w5qr-hpr2/GHSA-976p-w5qr-hpr2.json index 07838549a18..f2f903bc4eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-976p-w5qr-hpr2/GHSA-976p-w5qr-hpr2.json +++ b/advisories/unreviewed/2022/05/GHSA-976p-w5qr-hpr2/GHSA-976p-w5qr-hpr2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9793-cggf-824w/GHSA-9793-cggf-824w.json b/advisories/unreviewed/2022/05/GHSA-9793-cggf-824w/GHSA-9793-cggf-824w.json index a03fbcbf05b..41fbfb19a0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9793-cggf-824w/GHSA-9793-cggf-824w.json +++ b/advisories/unreviewed/2022/05/GHSA-9793-cggf-824w/GHSA-9793-cggf-824w.json @@ -7,12 +7,8 @@ "CVE-2011-1094" ], "details": "kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a certificate issued by a legitimate Certification Authority for an IP address, a different vulnerability than CVE-2009-2702.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98vg-3x92-29rv/GHSA-98vg-3x92-29rv.json b/advisories/unreviewed/2022/05/GHSA-98vg-3x92-29rv/GHSA-98vg-3x92-29rv.json index 48da3f2f854..227b8f7f34c 100644 --- a/advisories/unreviewed/2022/05/GHSA-98vg-3x92-29rv/GHSA-98vg-3x92-29rv.json +++ b/advisories/unreviewed/2022/05/GHSA-98vg-3x92-29rv/GHSA-98vg-3x92-29rv.json @@ -7,12 +7,8 @@ "CVE-2011-0678" ], "details": "Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the getImagefile component of EasyEdit.cfm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9969-72v6-m66h/GHSA-9969-72v6-m66h.json b/advisories/unreviewed/2022/05/GHSA-9969-72v6-m66h/GHSA-9969-72v6-m66h.json index 8938b407fa0..9733774cd57 100644 --- a/advisories/unreviewed/2022/05/GHSA-9969-72v6-m66h/GHSA-9969-72v6-m66h.json +++ b/advisories/unreviewed/2022/05/GHSA-9969-72v6-m66h/GHSA-9969-72v6-m66h.json @@ -7,12 +7,8 @@ "CVE-2011-0679" ], "details": "IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a \"modified message.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99cf-pj5r-c423/GHSA-99cf-pj5r-c423.json b/advisories/unreviewed/2022/05/GHSA-99cf-pj5r-c423/GHSA-99cf-pj5r-c423.json index 3b0b6235dd8..f970a480b5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-99cf-pj5r-c423/GHSA-99cf-pj5r-c423.json +++ b/advisories/unreviewed/2022/05/GHSA-99cf-pj5r-c423/GHSA-99cf-pj5r-c423.json @@ -7,12 +7,8 @@ "CVE-2011-0996" ], "details": "dhcpcd before 5.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9fmr-8qmc-p6jq/GHSA-9fmr-8qmc-p6jq.json b/advisories/unreviewed/2022/05/GHSA-9fmr-8qmc-p6jq/GHSA-9fmr-8qmc-p6jq.json index 7c0c01c302f..07812dc9761 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fmr-8qmc-p6jq/GHSA-9fmr-8qmc-p6jq.json +++ b/advisories/unreviewed/2022/05/GHSA-9fmr-8qmc-p6jq/GHSA-9fmr-8qmc-p6jq.json @@ -7,12 +7,8 @@ "CVE-2010-4641" ], "details": "SQL injection vulnerability in XWiki Enterprise before 2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gc6-qxcw-9qv6/GHSA-9gc6-qxcw-9qv6.json b/advisories/unreviewed/2022/05/GHSA-9gc6-qxcw-9qv6/GHSA-9gc6-qxcw-9qv6.json index 0d9b2593468..a6a8f9e674d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gc6-qxcw-9qv6/GHSA-9gc6-qxcw-9qv6.json +++ b/advisories/unreviewed/2022/05/GHSA-9gc6-qxcw-9qv6/GHSA-9gc6-qxcw-9qv6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gvm-96mj-8h5r/GHSA-9gvm-96mj-8h5r.json b/advisories/unreviewed/2022/05/GHSA-9gvm-96mj-8h5r/GHSA-9gvm-96mj-8h5r.json index e5cfa438bc5..b257bbed6e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gvm-96mj-8h5r/GHSA-9gvm-96mj-8h5r.json +++ b/advisories/unreviewed/2022/05/GHSA-9gvm-96mj-8h5r/GHSA-9gvm-96mj-8h5r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gvx-ch3q-5hrq/GHSA-9gvx-ch3q-5hrq.json b/advisories/unreviewed/2022/05/GHSA-9gvx-ch3q-5hrq/GHSA-9gvx-ch3q-5hrq.json index f0fe64853fa..07396f2c83c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gvx-ch3q-5hrq/GHSA-9gvx-ch3q-5hrq.json +++ b/advisories/unreviewed/2022/05/GHSA-9gvx-ch3q-5hrq/GHSA-9gvx-ch3q-5hrq.json @@ -7,12 +7,8 @@ "CVE-2011-1101" ], "details": "Multiple unspecified vulnerabilities in a third-party component of the Citrix Licensing Administration Console 11.6, formerly License Management Console, allow remote attackers to (1) access unauthorized \"license administration functionality\" or (2) cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hfc-v5g3-qvq4/GHSA-9hfc-v5g3-qvq4.json b/advisories/unreviewed/2022/05/GHSA-9hfc-v5g3-qvq4/GHSA-9hfc-v5g3-qvq4.json index 072b8176437..331274af7e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hfc-v5g3-qvq4/GHSA-9hfc-v5g3-qvq4.json +++ b/advisories/unreviewed/2022/05/GHSA-9hfc-v5g3-qvq4/GHSA-9hfc-v5g3-qvq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hpr-5xf7-5cmq/GHSA-9hpr-5xf7-5cmq.json b/advisories/unreviewed/2022/05/GHSA-9hpr-5xf7-5cmq/GHSA-9hpr-5xf7-5cmq.json index d996c97b11b..99357a09804 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hpr-5xf7-5cmq/GHSA-9hpr-5xf7-5cmq.json +++ b/advisories/unreviewed/2022/05/GHSA-9hpr-5xf7-5cmq/GHSA-9hpr-5xf7-5cmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hr3-v7cg-39j6/GHSA-9hr3-v7cg-39j6.json b/advisories/unreviewed/2022/05/GHSA-9hr3-v7cg-39j6/GHSA-9hr3-v7cg-39j6.json index e2634314579..754ef00b996 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hr3-v7cg-39j6/GHSA-9hr3-v7cg-39j6.json +++ b/advisories/unreviewed/2022/05/GHSA-9hr3-v7cg-39j6/GHSA-9hr3-v7cg-39j6.json @@ -7,12 +7,8 @@ "CVE-2011-1690" ], "details": "Best Practical Solutions RT 3.6.0 through 3.6.10 and 3.8.0 through 3.8.8 allows remote attackers to trick users into sending credentials to an arbitrary server via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jj6-2jv6-4cg4/GHSA-9jj6-2jv6-4cg4.json b/advisories/unreviewed/2022/05/GHSA-9jj6-2jv6-4cg4/GHSA-9jj6-2jv6-4cg4.json index 0546abfda2e..87fb6b95b76 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jj6-2jv6-4cg4/GHSA-9jj6-2jv6-4cg4.json +++ b/advisories/unreviewed/2022/05/GHSA-9jj6-2jv6-4cg4/GHSA-9jj6-2jv6-4cg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jxx-4x48-3ff9/GHSA-9jxx-4x48-3ff9.json b/advisories/unreviewed/2022/05/GHSA-9jxx-4x48-3ff9/GHSA-9jxx-4x48-3ff9.json index ef94efef98f..83316089191 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jxx-4x48-3ff9/GHSA-9jxx-4x48-3ff9.json +++ b/advisories/unreviewed/2022/05/GHSA-9jxx-4x48-3ff9/GHSA-9jxx-4x48-3ff9.json @@ -7,12 +7,8 @@ "CVE-2010-4796" ], "details": "Multiple SQL injection vulnerabilities in PHPYun 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) provinceid parameter to search.php and the (2) e parameter to resumeview.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m47-g6q4-562g/GHSA-9m47-g6q4-562g.json b/advisories/unreviewed/2022/05/GHSA-9m47-g6q4-562g/GHSA-9m47-g6q4-562g.json index ef191b3e1a3..cff6cc0bd9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m47-g6q4-562g/GHSA-9m47-g6q4-562g.json +++ b/advisories/unreviewed/2022/05/GHSA-9m47-g6q4-562g/GHSA-9m47-g6q4-562g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mrw-5cmq-64wh/GHSA-9mrw-5cmq-64wh.json b/advisories/unreviewed/2022/05/GHSA-9mrw-5cmq-64wh/GHSA-9mrw-5cmq-64wh.json index e07f861cd53..f8fa7406dde 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mrw-5cmq-64wh/GHSA-9mrw-5cmq-64wh.json +++ b/advisories/unreviewed/2022/05/GHSA-9mrw-5cmq-64wh/GHSA-9mrw-5cmq-64wh.json @@ -7,12 +7,8 @@ "CVE-2011-0499" ], "details": "Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element with a long \"name\" attribute. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pr2-3qq3-m7mc/GHSA-9pr2-3qq3-m7mc.json b/advisories/unreviewed/2022/05/GHSA-9pr2-3qq3-m7mc/GHSA-9pr2-3qq3-m7mc.json index 4db35c15dac..0422791e81d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pr2-3qq3-m7mc/GHSA-9pr2-3qq3-m7mc.json +++ b/advisories/unreviewed/2022/05/GHSA-9pr2-3qq3-m7mc/GHSA-9pr2-3qq3-m7mc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qcj-jr73-4fqp/GHSA-9qcj-jr73-4fqp.json b/advisories/unreviewed/2022/05/GHSA-9qcj-jr73-4fqp/GHSA-9qcj-jr73-4fqp.json index e9bf1593083..846f02e7ca6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qcj-jr73-4fqp/GHSA-9qcj-jr73-4fqp.json +++ b/advisories/unreviewed/2022/05/GHSA-9qcj-jr73-4fqp/GHSA-9qcj-jr73-4fqp.json @@ -7,12 +7,8 @@ "CVE-2010-4639" ], "details": "SQL injection vulnerability in index.php in MySource Matrix allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qpg-7p56-5mjx/GHSA-9qpg-7p56-5mjx.json b/advisories/unreviewed/2022/05/GHSA-9qpg-7p56-5mjx/GHSA-9qpg-7p56-5mjx.json index 147da25a276..80d8ef4e80c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qpg-7p56-5mjx/GHSA-9qpg-7p56-5mjx.json +++ b/advisories/unreviewed/2022/05/GHSA-9qpg-7p56-5mjx/GHSA-9qpg-7p56-5mjx.json @@ -7,12 +7,8 @@ "CVE-2011-1375" ], "details": "IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rcm-4wjg-wvhc/GHSA-9rcm-4wjg-wvhc.json b/advisories/unreviewed/2022/05/GHSA-9rcm-4wjg-wvhc/GHSA-9rcm-4wjg-wvhc.json index 2732ff5ad54..df959007c17 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rcm-4wjg-wvhc/GHSA-9rcm-4wjg-wvhc.json +++ b/advisories/unreviewed/2022/05/GHSA-9rcm-4wjg-wvhc/GHSA-9rcm-4wjg-wvhc.json @@ -7,12 +7,8 @@ "CVE-2011-1405" ], "details": "Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors associated with HTML e-mail messages, related to artefact/comment/lib.php and interaction/forum/lib.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rpv-x9vj-8cxq/GHSA-9rpv-x9vj-8cxq.json b/advisories/unreviewed/2022/05/GHSA-9rpv-x9vj-8cxq/GHSA-9rpv-x9vj-8cxq.json index 8677bf63b9a..246af446401 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rpv-x9vj-8cxq/GHSA-9rpv-x9vj-8cxq.json +++ b/advisories/unreviewed/2022/05/GHSA-9rpv-x9vj-8cxq/GHSA-9rpv-x9vj-8cxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v9m-grrv-xcjm/GHSA-9v9m-grrv-xcjm.json b/advisories/unreviewed/2022/05/GHSA-9v9m-grrv-xcjm/GHSA-9v9m-grrv-xcjm.json index 418e7da98b1..677bcc2361a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v9m-grrv-xcjm/GHSA-9v9m-grrv-xcjm.json +++ b/advisories/unreviewed/2022/05/GHSA-9v9m-grrv-xcjm/GHSA-9v9m-grrv-xcjm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vc2-646h-wpq7/GHSA-9vc2-646h-wpq7.json b/advisories/unreviewed/2022/05/GHSA-9vc2-646h-wpq7/GHSA-9vc2-646h-wpq7.json index 8a169f65398..6ea01ac7dc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vc2-646h-wpq7/GHSA-9vc2-646h-wpq7.json +++ b/advisories/unreviewed/2022/05/GHSA-9vc2-646h-wpq7/GHSA-9vc2-646h-wpq7.json @@ -7,12 +7,8 @@ "CVE-2011-0410" ], "details": "CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-dependent attackers to obtain sensitive information by (1) sniffing the network for transmissions of Java objects or (2) reading the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9vrq-23pr-3gff/GHSA-9vrq-23pr-3gff.json b/advisories/unreviewed/2022/05/GHSA-9vrq-23pr-3gff/GHSA-9vrq-23pr-3gff.json index 3f86112fe78..2db821a8e07 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vrq-23pr-3gff/GHSA-9vrq-23pr-3gff.json +++ b/advisories/unreviewed/2022/05/GHSA-9vrq-23pr-3gff/GHSA-9vrq-23pr-3gff.json @@ -7,12 +7,8 @@ "CVE-2011-0158" ], "details": "MobileSafari in Apple iOS before 4.3 does not properly implement application launching through URL handlers, which allows remote attackers to cause a denial of service (persistent application crash) via crafted JavaScript code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2hr-2vmh-xcx9/GHSA-c2hr-2vmh-xcx9.json b/advisories/unreviewed/2022/05/GHSA-c2hr-2vmh-xcx9/GHSA-c2hr-2vmh-xcx9.json index d75f12db9a6..a83911a0728 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2hr-2vmh-xcx9/GHSA-c2hr-2vmh-xcx9.json +++ b/advisories/unreviewed/2022/05/GHSA-c2hr-2vmh-xcx9/GHSA-c2hr-2vmh-xcx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2pm-4p8q-67xh/GHSA-c2pm-4p8q-67xh.json b/advisories/unreviewed/2022/05/GHSA-c2pm-4p8q-67xh/GHSA-c2pm-4p8q-67xh.json index 8b7de5585da..88f29b8640a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2pm-4p8q-67xh/GHSA-c2pm-4p8q-67xh.json +++ b/advisories/unreviewed/2022/05/GHSA-c2pm-4p8q-67xh/GHSA-c2pm-4p8q-67xh.json @@ -7,12 +7,8 @@ "CVE-2011-0990" ], "details": "Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file in which a thread makes a change after a type check but before a copy action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3jv-xx3c-w254/GHSA-c3jv-xx3c-w254.json b/advisories/unreviewed/2022/05/GHSA-c3jv-xx3c-w254/GHSA-c3jv-xx3c-w254.json index a26eefedd8d..e65aeb5ea62 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3jv-xx3c-w254/GHSA-c3jv-xx3c-w254.json +++ b/advisories/unreviewed/2022/05/GHSA-c3jv-xx3c-w254/GHSA-c3jv-xx3c-w254.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3wq-jrvp-9pp9/GHSA-c3wq-jrvp-9pp9.json b/advisories/unreviewed/2022/05/GHSA-c3wq-jrvp-9pp9/GHSA-c3wq-jrvp-9pp9.json index d58b048e1c1..04b8afc9e3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3wq-jrvp-9pp9/GHSA-c3wq-jrvp-9pp9.json +++ b/advisories/unreviewed/2022/05/GHSA-c3wq-jrvp-9pp9/GHSA-c3wq-jrvp-9pp9.json @@ -7,12 +7,8 @@ "CVE-2011-1102" ], "details": "Cross-site scripting (XSS) vulnerability in the WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before hotfix 4 on Windows and hotfix 2 on Linux, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4mq-4wp5-9pxq/GHSA-c4mq-4wp5-9pxq.json b/advisories/unreviewed/2022/05/GHSA-c4mq-4wp5-9pxq/GHSA-c4mq-4wp5-9pxq.json index 386db58b565..24f4856c286 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4mq-4wp5-9pxq/GHSA-c4mq-4wp5-9pxq.json +++ b/advisories/unreviewed/2022/05/GHSA-c4mq-4wp5-9pxq/GHSA-c4mq-4wp5-9pxq.json @@ -7,12 +7,8 @@ "CVE-2011-1431" ], "details": "The STARTTLS implementation in qmail-smtpd.c in qmail-smtpd in the netqmail-1.06-tls patch for netqmail 1.06 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a \"plaintext command injection\" attack, a similar issue to CVE-2011-0411.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4wx-89j8-9hmm/GHSA-c4wx-89j8-9hmm.json b/advisories/unreviewed/2022/05/GHSA-c4wx-89j8-9hmm/GHSA-c4wx-89j8-9hmm.json index 2efa37c12dd..a68ad13a2bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4wx-89j8-9hmm/GHSA-c4wx-89j8-9hmm.json +++ b/advisories/unreviewed/2022/05/GHSA-c4wx-89j8-9hmm/GHSA-c4wx-89j8-9hmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5rj-2jm6-m2wj/GHSA-c5rj-2jm6-m2wj.json b/advisories/unreviewed/2022/05/GHSA-c5rj-2jm6-m2wj/GHSA-c5rj-2jm6-m2wj.json index 710dc5070a5..2bc3b7f3135 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5rj-2jm6-m2wj/GHSA-c5rj-2jm6-m2wj.json +++ b/advisories/unreviewed/2022/05/GHSA-c5rj-2jm6-m2wj/GHSA-c5rj-2jm6-m2wj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c67j-99px-gg68/GHSA-c67j-99px-gg68.json b/advisories/unreviewed/2022/05/GHSA-c67j-99px-gg68/GHSA-c67j-99px-gg68.json index c06ebda61a5..0a5307846f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c67j-99px-gg68/GHSA-c67j-99px-gg68.json +++ b/advisories/unreviewed/2022/05/GHSA-c67j-99px-gg68/GHSA-c67j-99px-gg68.json @@ -7,12 +7,8 @@ "CVE-2011-0270" ], "details": "Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via format string specifiers in input data that involves an invalid template name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6fr-x99h-2jv7/GHSA-c6fr-x99h-2jv7.json b/advisories/unreviewed/2022/05/GHSA-c6fr-x99h-2jv7/GHSA-c6fr-x99h-2jv7.json index 55ad59f83af..1927d46278e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6fr-x99h-2jv7/GHSA-c6fr-x99h-2jv7.json +++ b/advisories/unreviewed/2022/05/GHSA-c6fr-x99h-2jv7/GHSA-c6fr-x99h-2jv7.json @@ -7,12 +7,8 @@ "CVE-2011-0507" ], "details": "FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.1737, allows remote attackers to cause a denial of service (crash) via a large number of PORT commands with long arguments, which triggers a NULL pointer dereference. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c7mf-3c4g-q9f2/GHSA-c7mf-3c4g-q9f2.json b/advisories/unreviewed/2022/05/GHSA-c7mf-3c4g-q9f2/GHSA-c7mf-3c4g-q9f2.json index 341657becc3..3d7f7f75ba5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7mf-3c4g-q9f2/GHSA-c7mf-3c4g-q9f2.json +++ b/advisories/unreviewed/2022/05/GHSA-c7mf-3c4g-q9f2/GHSA-c7mf-3c4g-q9f2.json @@ -7,12 +7,8 @@ "CVE-2011-0385" ], "details": "The administrative web interface on Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote attackers to create or overwrite arbitrary files, and possibly execute arbitrary code, via a crafted request, aka Bug IDs CSCth85786 and CSCth61065.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c833-h92x-3p97/GHSA-c833-h92x-3p97.json b/advisories/unreviewed/2022/05/GHSA-c833-h92x-3p97/GHSA-c833-h92x-3p97.json index 9b81b7cb741..5b4e5e4fad2 100644 --- a/advisories/unreviewed/2022/05/GHSA-c833-h92x-3p97/GHSA-c833-h92x-3p97.json +++ b/advisories/unreviewed/2022/05/GHSA-c833-h92x-3p97/GHSA-c833-h92x-3p97.json @@ -7,12 +7,8 @@ "CVE-2011-1209" ], "details": "IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to obtain plaintext data from a (1) JAX-RPC or (2) JAX-WS Web Services request via unspecified vectors related to a \"decryption attack.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c97w-jh64-6jmv/GHSA-c97w-jh64-6jmv.json b/advisories/unreviewed/2022/05/GHSA-c97w-jh64-6jmv/GHSA-c97w-jh64-6jmv.json index 69e8467f0d0..c65750f0a8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c97w-jh64-6jmv/GHSA-c97w-jh64-6jmv.json +++ b/advisories/unreviewed/2022/05/GHSA-c97w-jh64-6jmv/GHSA-c97w-jh64-6jmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9g7-3qqw-h79j/GHSA-c9g7-3qqw-h79j.json b/advisories/unreviewed/2022/05/GHSA-c9g7-3qqw-h79j/GHSA-c9g7-3qqw-h79j.json index 9ec9632008e..23a5ba82b0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9g7-3qqw-h79j/GHSA-c9g7-3qqw-h79j.json +++ b/advisories/unreviewed/2022/05/GHSA-c9g7-3qqw-h79j/GHSA-c9g7-3qqw-h79j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfj4-pwcj-qhgc/GHSA-cfj4-pwcj-qhgc.json b/advisories/unreviewed/2022/05/GHSA-cfj4-pwcj-qhgc/GHSA-cfj4-pwcj-qhgc.json index 4e71adc225c..5daf560988f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfj4-pwcj-qhgc/GHSA-cfj4-pwcj-qhgc.json +++ b/advisories/unreviewed/2022/05/GHSA-cfj4-pwcj-qhgc/GHSA-cfj4-pwcj-qhgc.json @@ -7,12 +7,8 @@ "CVE-2011-1175" ], "details": "tcptls.c in the TCP/TLS server in Asterisk Open Source 1.6.1.x before 1.6.1.23, 1.6.2.x before 1.6.2.17.1, and 1.8.x before 1.8.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by establishing many short TCP sessions to services that use a certain TLS API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfqr-x5f5-23cm/GHSA-cfqr-x5f5-23cm.json b/advisories/unreviewed/2022/05/GHSA-cfqr-x5f5-23cm/GHSA-cfqr-x5f5-23cm.json index f1f7c530a86..084e143b622 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfqr-x5f5-23cm/GHSA-cfqr-x5f5-23cm.json +++ b/advisories/unreviewed/2022/05/GHSA-cfqr-x5f5-23cm/GHSA-cfqr-x5f5-23cm.json @@ -7,12 +7,8 @@ "CVE-2011-0510" ], "details": "SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the oid parameter in an add_other action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg94-q2f7-g4vr/GHSA-cg94-q2f7-g4vr.json b/advisories/unreviewed/2022/05/GHSA-cg94-q2f7-g4vr/GHSA-cg94-q2f7-g4vr.json index 901e7f790f8..088057a1bd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg94-q2f7-g4vr/GHSA-cg94-q2f7-g4vr.json +++ b/advisories/unreviewed/2022/05/GHSA-cg94-q2f7-g4vr/GHSA-cg94-q2f7-g4vr.json @@ -7,12 +7,8 @@ "CVE-2010-4424" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.49.0 through 8.49.29, 8.50.0 through 8.50.14, and 8.51.0 through 8.51.04 allows remote attackers to affect availability via unknown vectors related to the Security sub-component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgmc-f9pw-cxc9/GHSA-cgmc-f9pw-cxc9.json b/advisories/unreviewed/2022/05/GHSA-cgmc-f9pw-cxc9/GHSA-cgmc-f9pw-cxc9.json index c7ba91c9a96..85b4a4b7859 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgmc-f9pw-cxc9/GHSA-cgmc-f9pw-cxc9.json +++ b/advisories/unreviewed/2022/05/GHSA-cgmc-f9pw-cxc9/GHSA-cgmc-f9pw-cxc9.json @@ -7,12 +7,8 @@ "CVE-2011-0454" ], "details": "Buffer overflow in the PPP Access Concentrator (PPPAC) on the SEIL/x86 with firmware 1.00 through 1.61, SEIL/B1 with firmware 1.00 through 3.11, SEIL/X1 with firmware 1.00 through 3.11, SEIL/X2 with firmware 1.00 through 3.11, SEIL/Turbo with firmware 1.80 through 2.10, and SEIL/neu 2FE Plus with firmware 1.80 through 2.10 might allow remote attackers to execute arbitrary code via a PPPoE packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmj3-gcg6-cpp8/GHSA-cmj3-gcg6-cpp8.json b/advisories/unreviewed/2022/05/GHSA-cmj3-gcg6-cpp8/GHSA-cmj3-gcg6-cpp8.json index 3b7f12227d6..a1fc9c2d64e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmj3-gcg6-cpp8/GHSA-cmj3-gcg6-cpp8.json +++ b/advisories/unreviewed/2022/05/GHSA-cmj3-gcg6-cpp8/GHSA-cmj3-gcg6-cpp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpcv-642m-28fw/GHSA-cpcv-642m-28fw.json b/advisories/unreviewed/2022/05/GHSA-cpcv-642m-28fw/GHSA-cpcv-642m-28fw.json index 660c35b7198..ac16871c7b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpcv-642m-28fw/GHSA-cpcv-642m-28fw.json +++ b/advisories/unreviewed/2022/05/GHSA-cpcv-642m-28fw/GHSA-cpcv-642m-28fw.json @@ -7,12 +7,8 @@ "CVE-2011-0741" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image editor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpfw-6597-3vc6/GHSA-cpfw-6597-3vc6.json b/advisories/unreviewed/2022/05/GHSA-cpfw-6597-3vc6/GHSA-cpfw-6597-3vc6.json index e2f3befcdf6..227e363f558 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpfw-6597-3vc6/GHSA-cpfw-6597-3vc6.json +++ b/advisories/unreviewed/2022/05/GHSA-cpfw-6597-3vc6/GHSA-cpfw-6597-3vc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq2g-q9mw-v9xp/GHSA-cq2g-q9mw-v9xp.json b/advisories/unreviewed/2022/05/GHSA-cq2g-q9mw-v9xp/GHSA-cq2g-q9mw-v9xp.json index 3e351c6f7a4..2fbe34ec06c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq2g-q9mw-v9xp/GHSA-cq2g-q9mw-v9xp.json +++ b/advisories/unreviewed/2022/05/GHSA-cq2g-q9mw-v9xp/GHSA-cq2g-q9mw-v9xp.json @@ -7,12 +7,8 @@ "CVE-2010-4776" ], "details": "SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqfp-9rxf-m432/GHSA-cqfp-9rxf-m432.json b/advisories/unreviewed/2022/05/GHSA-cqfp-9rxf-m432/GHSA-cqfp-9rxf-m432.json index 195def3ef0e..cc58561d6b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqfp-9rxf-m432/GHSA-cqfp-9rxf-m432.json +++ b/advisories/unreviewed/2022/05/GHSA-cqfp-9rxf-m432/GHSA-cqfp-9rxf-m432.json @@ -7,12 +7,8 @@ "CVE-2010-3404" ], "details": "Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL commands via the (1) Criteria field in an unspecified form related to catlgsearch.aspx or (2) user name to an unspecified form related to adminlogin.aspx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cr9f-q846-6jw6/GHSA-cr9f-q846-6jw6.json b/advisories/unreviewed/2022/05/GHSA-cr9f-q846-6jw6/GHSA-cr9f-q846-6jw6.json index 7e6654faa9f..d9259532345 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr9f-q846-6jw6/GHSA-cr9f-q846-6jw6.json +++ b/advisories/unreviewed/2022/05/GHSA-cr9f-q846-6jw6/GHSA-cr9f-q846-6jw6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crj4-gj97-jggx/GHSA-crj4-gj97-jggx.json b/advisories/unreviewed/2022/05/GHSA-crj4-gj97-jggx/GHSA-crj4-gj97-jggx.json index e34cb9ab2d8..7b79c0be7c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-crj4-gj97-jggx/GHSA-crj4-gj97-jggx.json +++ b/advisories/unreviewed/2022/05/GHSA-crj4-gj97-jggx/GHSA-crj4-gj97-jggx.json @@ -7,12 +7,8 @@ "CVE-2010-4695" ], "details": "A certain Fedora patch for gif2png.c in gif2png 2.5.1 and 2.5.2, as distributed in gif2png-2.5.1-1200.fc12 on Fedora 12 and gif2png_2.5.2-1 on Debian GNU/Linux, truncates a GIF pathname specified on the command line, which might allow remote attackers to create PNG files in unintended directories via a crafted command-line argument, as demonstrated by a CGI program that launches gif2png, a different vulnerability than CVE-2009-5018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvv9-f32p-cp3v/GHSA-cvv9-f32p-cp3v.json b/advisories/unreviewed/2022/05/GHSA-cvv9-f32p-cp3v/GHSA-cvv9-f32p-cp3v.json index bcb4958dbf6..3a12f10be7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvv9-f32p-cp3v/GHSA-cvv9-f32p-cp3v.json +++ b/advisories/unreviewed/2022/05/GHSA-cvv9-f32p-cp3v/GHSA-cvv9-f32p-cp3v.json @@ -7,12 +7,8 @@ "CVE-2011-1388" ], "details": "The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the TestCompatibilityRecordMode method, which allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx8m-mfqm-j9vm/GHSA-cx8m-mfqm-j9vm.json b/advisories/unreviewed/2022/05/GHSA-cx8m-mfqm-j9vm/GHSA-cx8m-mfqm-j9vm.json index d6e70327257..3f9128720d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx8m-mfqm-j9vm/GHSA-cx8m-mfqm-j9vm.json +++ b/advisories/unreviewed/2022/05/GHSA-cx8m-mfqm-j9vm/GHSA-cx8m-mfqm-j9vm.json @@ -7,12 +7,8 @@ "CVE-2011-1359" ], "details": "Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxc2-3pj3-4vvp/GHSA-cxc2-3pj3-4vvp.json b/advisories/unreviewed/2022/05/GHSA-cxc2-3pj3-4vvp/GHSA-cxc2-3pj3-4vvp.json index 83b27687356..b744514a558 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxc2-3pj3-4vvp/GHSA-cxc2-3pj3-4vvp.json +++ b/advisories/unreviewed/2022/05/GHSA-cxc2-3pj3-4vvp/GHSA-cxc2-3pj3-4vvp.json @@ -7,12 +7,8 @@ "CVE-2011-0993" ], "details": "SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f22v-g3v4-mp5r/GHSA-f22v-g3v4-mp5r.json b/advisories/unreviewed/2022/05/GHSA-f22v-g3v4-mp5r/GHSA-f22v-g3v4-mp5r.json index d9a675a0c4c..2bf96d6ae9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f22v-g3v4-mp5r/GHSA-f22v-g3v4-mp5r.json +++ b/advisories/unreviewed/2022/05/GHSA-f22v-g3v4-mp5r/GHSA-f22v-g3v4-mp5r.json @@ -7,12 +7,8 @@ "CVE-2010-4426" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.49.0 through 8.49.29, 8.50.0 through 8.50.14, and 8.51.0 through 8.51.04 allows remote attackers to affect integrity, related to PIA Core Technology.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2vg-j7cg-mp3f/GHSA-f2vg-j7cg-mp3f.json b/advisories/unreviewed/2022/05/GHSA-f2vg-j7cg-mp3f/GHSA-f2vg-j7cg-mp3f.json index d6b66129390..5fb88ebd607 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2vg-j7cg-mp3f/GHSA-f2vg-j7cg-mp3f.json +++ b/advisories/unreviewed/2022/05/GHSA-f2vg-j7cg-mp3f/GHSA-f2vg-j7cg-mp3f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f49g-9gwg-jc3x/GHSA-f49g-9gwg-jc3x.json b/advisories/unreviewed/2022/05/GHSA-f49g-9gwg-jc3x/GHSA-f49g-9gwg-jc3x.json index 4fd93b8e560..ff1214ab35d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f49g-9gwg-jc3x/GHSA-f49g-9gwg-jc3x.json +++ b/advisories/unreviewed/2022/05/GHSA-f49g-9gwg-jc3x/GHSA-f49g-9gwg-jc3x.json @@ -7,12 +7,8 @@ "CVE-2011-0688" ], "details": "Intel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote attackers to execute arbitrary commands via crafted messages over TCP, as discovered by Junaid Bohio, a different vulnerability than CVE-2010-0110 and CVE-2010-0111. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4hr-f9q4-xw2j/GHSA-f4hr-f9q4-xw2j.json b/advisories/unreviewed/2022/05/GHSA-f4hr-f9q4-xw2j/GHSA-f4hr-f9q4-xw2j.json index b76b33291b5..1d964f139e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4hr-f9q4-xw2j/GHSA-f4hr-f9q4-xw2j.json +++ b/advisories/unreviewed/2022/05/GHSA-f4hr-f9q4-xw2j/GHSA-f4hr-f9q4-xw2j.json @@ -7,12 +7,8 @@ "CVE-2010-4752" ], "details": "SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter, a different vector than CVE-2008-6593, CVE-2010-3484, and CVE-2010-3485. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5mm-gwr7-gxf7/GHSA-f5mm-gwr7-gxf7.json b/advisories/unreviewed/2022/05/GHSA-f5mm-gwr7-gxf7/GHSA-f5mm-gwr7-gxf7.json index 530889b4011..395863ea3ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5mm-gwr7-gxf7/GHSA-f5mm-gwr7-gxf7.json +++ b/advisories/unreviewed/2022/05/GHSA-f5mm-gwr7-gxf7/GHSA-f5mm-gwr7-gxf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5rx-c6g6-f629/GHSA-f5rx-c6g6-f629.json b/advisories/unreviewed/2022/05/GHSA-f5rx-c6g6-f629/GHSA-f5rx-c6g6-f629.json index 6156f527e8c..e3e09dc7d73 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5rx-c6g6-f629/GHSA-f5rx-c6g6-f629.json +++ b/advisories/unreviewed/2022/05/GHSA-f5rx-c6g6-f629/GHSA-f5rx-c6g6-f629.json @@ -7,12 +7,8 @@ "CVE-2010-4794" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in a jscalendar action to index.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6g3-fh8w-f8x8/GHSA-f6g3-fh8w-f8x8.json b/advisories/unreviewed/2022/05/GHSA-f6g3-fh8w-f8x8/GHSA-f6g3-fh8w-f8x8.json index 8ef14fd9a28..a2c2420eeba 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6g3-fh8w-f8x8/GHSA-f6g3-fh8w-f8x8.json +++ b/advisories/unreviewed/2022/05/GHSA-f6g3-fh8w-f8x8/GHSA-f6g3-fh8w-f8x8.json @@ -7,12 +7,8 @@ "CVE-2011-1105" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Mutare EVM allow remote attackers to inject arbitrary web script or HTML via (1) a delivery address and possibly (2) a PIN.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6rm-576m-gxcr/GHSA-f6rm-576m-gxcr.json b/advisories/unreviewed/2022/05/GHSA-f6rm-576m-gxcr/GHSA-f6rm-576m-gxcr.json index d881b20e8eb..a64cd040aa7 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6rm-576m-gxcr/GHSA-f6rm-576m-gxcr.json +++ b/advisories/unreviewed/2022/05/GHSA-f6rm-576m-gxcr/GHSA-f6rm-576m-gxcr.json @@ -7,12 +7,8 @@ "CVE-2010-4797" ], "details": "Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f79w-3mc4-xqgc/GHSA-f79w-3mc4-xqgc.json b/advisories/unreviewed/2022/05/GHSA-f79w-3mc4-xqgc/GHSA-f79w-3mc4-xqgc.json index 0346505c699..a5fc3a2108e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f79w-3mc4-xqgc/GHSA-f79w-3mc4-xqgc.json +++ b/advisories/unreviewed/2022/05/GHSA-f79w-3mc4-xqgc/GHSA-f79w-3mc4-xqgc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7c9-wvq2-wpm7/GHSA-f7c9-wvq2-wpm7.json b/advisories/unreviewed/2022/05/GHSA-f7c9-wvq2-wpm7/GHSA-f7c9-wvq2-wpm7.json index 7ea17a4933c..19143a12f55 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7c9-wvq2-wpm7/GHSA-f7c9-wvq2-wpm7.json +++ b/advisories/unreviewed/2022/05/GHSA-f7c9-wvq2-wpm7/GHSA-f7c9-wvq2-wpm7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7j8-6p45-qvgf/GHSA-f7j8-6p45-qvgf.json b/advisories/unreviewed/2022/05/GHSA-f7j8-6p45-qvgf/GHSA-f7j8-6p45-qvgf.json index 17bc25fe4b8..c4a800ebef6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7j8-6p45-qvgf/GHSA-f7j8-6p45-qvgf.json +++ b/advisories/unreviewed/2022/05/GHSA-f7j8-6p45-qvgf/GHSA-f7j8-6p45-qvgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f88x-mrj5-3243/GHSA-f88x-mrj5-3243.json b/advisories/unreviewed/2022/05/GHSA-f88x-mrj5-3243/GHSA-f88x-mrj5-3243.json index d417dea92b0..80280e55839 100644 --- a/advisories/unreviewed/2022/05/GHSA-f88x-mrj5-3243/GHSA-f88x-mrj5-3243.json +++ b/advisories/unreviewed/2022/05/GHSA-f88x-mrj5-3243/GHSA-f88x-mrj5-3243.json @@ -7,12 +7,8 @@ "CVE-2011-1680" ], "details": "ncpmount in ncpfs 2.2.6 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8mw-q536-545m/GHSA-f8mw-q536-545m.json b/advisories/unreviewed/2022/05/GHSA-f8mw-q536-545m/GHSA-f8mw-q536-545m.json index 9414820da40..6aa43b657cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8mw-q536-545m/GHSA-f8mw-q536-545m.json +++ b/advisories/unreviewed/2022/05/GHSA-f8mw-q536-545m/GHSA-f8mw-q536-545m.json @@ -7,12 +7,8 @@ "CVE-2010-4275" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) name or (2) descr parameter in an (a) update_usergroup or a (b) store_nas action to admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fchw-39vq-2wvv/GHSA-fchw-39vq-2wvv.json b/advisories/unreviewed/2022/05/GHSA-fchw-39vq-2wvv/GHSA-fchw-39vq-2wvv.json index 549f5d6610f..4916ce7839a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fchw-39vq-2wvv/GHSA-fchw-39vq-2wvv.json +++ b/advisories/unreviewed/2022/05/GHSA-fchw-39vq-2wvv/GHSA-fchw-39vq-2wvv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcmr-8hmm-9f43/GHSA-fcmr-8hmm-9f43.json b/advisories/unreviewed/2022/05/GHSA-fcmr-8hmm-9f43/GHSA-fcmr-8hmm-9f43.json index 0bf985e342a..47f676664e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcmr-8hmm-9f43/GHSA-fcmr-8hmm-9f43.json +++ b/advisories/unreviewed/2022/05/GHSA-fcmr-8hmm-9f43/GHSA-fcmr-8hmm-9f43.json @@ -7,12 +7,8 @@ "CVE-2011-0988" ], "details": "pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcw4-67mp-q8qc/GHSA-fcw4-67mp-q8qc.json b/advisories/unreviewed/2022/05/GHSA-fcw4-67mp-q8qc/GHSA-fcw4-67mp-q8qc.json index 8b2d7a6e68b..851fe606271 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcw4-67mp-q8qc/GHSA-fcw4-67mp-q8qc.json +++ b/advisories/unreviewed/2022/05/GHSA-fcw4-67mp-q8qc/GHSA-fcw4-67mp-q8qc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff82-9ghf-36pg/GHSA-ff82-9ghf-36pg.json b/advisories/unreviewed/2022/05/GHSA-ff82-9ghf-36pg/GHSA-ff82-9ghf-36pg.json index 05a094ba960..9b8e42197bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff82-9ghf-36pg/GHSA-ff82-9ghf-36pg.json +++ b/advisories/unreviewed/2022/05/GHSA-ff82-9ghf-36pg/GHSA-ff82-9ghf-36pg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg45-xgpm-wfcg/GHSA-fg45-xgpm-wfcg.json b/advisories/unreviewed/2022/05/GHSA-fg45-xgpm-wfcg/GHSA-fg45-xgpm-wfcg.json index fa11ddc3867..584c404ab89 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg45-xgpm-wfcg/GHSA-fg45-xgpm-wfcg.json +++ b/advisories/unreviewed/2022/05/GHSA-fg45-xgpm-wfcg/GHSA-fg45-xgpm-wfcg.json @@ -7,12 +7,8 @@ "CVE-2010-4702" ], "details": "SQL injection vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg8f-6q25-239r/GHSA-fg8f-6q25-239r.json b/advisories/unreviewed/2022/05/GHSA-fg8f-6q25-239r/GHSA-fg8f-6q25-239r.json index c0ed4ed84ca..623d1bff76b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg8f-6q25-239r/GHSA-fg8f-6q25-239r.json +++ b/advisories/unreviewed/2022/05/GHSA-fg8f-6q25-239r/GHSA-fg8f-6q25-239r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh5f-7jxv-wjmw/GHSA-fh5f-7jxv-wjmw.json b/advisories/unreviewed/2022/05/GHSA-fh5f-7jxv-wjmw/GHSA-fh5f-7jxv-wjmw.json index 3e072defb94..31eb9d33a94 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh5f-7jxv-wjmw/GHSA-fh5f-7jxv-wjmw.json +++ b/advisories/unreviewed/2022/05/GHSA-fh5f-7jxv-wjmw/GHSA-fh5f-7jxv-wjmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fhhx-vmqp-c557/GHSA-fhhx-vmqp-c557.json b/advisories/unreviewed/2022/05/GHSA-fhhx-vmqp-c557/GHSA-fhhx-vmqp-c557.json index 06bee2a87a4..aeb266873ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhhx-vmqp-c557/GHSA-fhhx-vmqp-c557.json +++ b/advisories/unreviewed/2022/05/GHSA-fhhx-vmqp-c557/GHSA-fhhx-vmqp-c557.json @@ -7,12 +7,8 @@ "CVE-2011-0452" ], "details": "Untrusted search path vulnerability in the script function in Lunascape before 6.4.3 allows local users to gain privileges via a Trojan horse executable file in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhvf-2vjr-3jh6/GHSA-fhvf-2vjr-3jh6.json b/advisories/unreviewed/2022/05/GHSA-fhvf-2vjr-3jh6/GHSA-fhvf-2vjr-3jh6.json index 4f3e0f36212..4e927f21fd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhvf-2vjr-3jh6/GHSA-fhvf-2vjr-3jh6.json +++ b/advisories/unreviewed/2022/05/GHSA-fhvf-2vjr-3jh6/GHSA-fhvf-2vjr-3jh6.json @@ -7,12 +7,8 @@ "CVE-2011-1604" ], "details": "Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (memory consumption and process failure) via a malformed SIP message, aka Bug ID CSCti42904.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fj7j-xmwg-9w4h/GHSA-fj7j-xmwg-9w4h.json b/advisories/unreviewed/2022/05/GHSA-fj7j-xmwg-9w4h/GHSA-fj7j-xmwg-9w4h.json index 05c4f3f5ab5..f539eca808f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj7j-xmwg-9w4h/GHSA-fj7j-xmwg-9w4h.json +++ b/advisories/unreviewed/2022/05/GHSA-fj7j-xmwg-9w4h/GHSA-fj7j-xmwg-9w4h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjwm-vprq-674q/GHSA-fjwm-vprq-674q.json b/advisories/unreviewed/2022/05/GHSA-fjwm-vprq-674q/GHSA-fjwm-vprq-674q.json index d3834226f39..0be9138058c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjwm-vprq-674q/GHSA-fjwm-vprq-674q.json +++ b/advisories/unreviewed/2022/05/GHSA-fjwm-vprq-674q/GHSA-fjwm-vprq-674q.json @@ -7,12 +7,8 @@ "CVE-2011-1404" ], "details": "Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmhf-v67j-2c7q/GHSA-fmhf-v67j-2c7q.json b/advisories/unreviewed/2022/05/GHSA-fmhf-v67j-2c7q/GHSA-fmhf-v67j-2c7q.json index 2e28b93552d..30f198097d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmhf-v67j-2c7q/GHSA-fmhf-v67j-2c7q.json +++ b/advisories/unreviewed/2022/05/GHSA-fmhf-v67j-2c7q/GHSA-fmhf-v67j-2c7q.json @@ -7,12 +7,8 @@ "CVE-2011-0898" ], "details": "Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.00 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmhw-c29c-fhf7/GHSA-fmhw-c29c-fhf7.json b/advisories/unreviewed/2022/05/GHSA-fmhw-c29c-fhf7/GHSA-fmhw-c29c-fhf7.json index b11487d2843..d999a7eb68e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmhw-c29c-fhf7/GHSA-fmhw-c29c-fhf7.json +++ b/advisories/unreviewed/2022/05/GHSA-fmhw-c29c-fhf7/GHSA-fmhw-c29c-fhf7.json @@ -7,12 +7,8 @@ "CVE-2011-1378" ], "details": "IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpr3-x698-3rrr/GHSA-fpr3-x698-3rrr.json b/advisories/unreviewed/2022/05/GHSA-fpr3-x698-3rrr/GHSA-fpr3-x698-3rrr.json index 41588e6147d..8c50a1500bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpr3-x698-3rrr/GHSA-fpr3-x698-3rrr.json +++ b/advisories/unreviewed/2022/05/GHSA-fpr3-x698-3rrr/GHSA-fpr3-x698-3rrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpwp-r2g2-q9mp/GHSA-fpwp-r2g2-q9mp.json b/advisories/unreviewed/2022/05/GHSA-fpwp-r2g2-q9mp/GHSA-fpwp-r2g2-q9mp.json index 823f16f6e4f..26157d65916 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpwp-r2g2-q9mp/GHSA-fpwp-r2g2-q9mp.json +++ b/advisories/unreviewed/2022/05/GHSA-fpwp-r2g2-q9mp/GHSA-fpwp-r2g2-q9mp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fq75-hmm6-xg54/GHSA-fq75-hmm6-xg54.json b/advisories/unreviewed/2022/05/GHSA-fq75-hmm6-xg54/GHSA-fq75-hmm6-xg54.json index 87b80d0b632..849578b03ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq75-hmm6-xg54/GHSA-fq75-hmm6-xg54.json +++ b/advisories/unreviewed/2022/05/GHSA-fq75-hmm6-xg54/GHSA-fq75-hmm6-xg54.json @@ -7,12 +7,8 @@ "CVE-2011-0403" ], "details": "Untrusted search path vulnerability in ImgBurn.exe in ImgBurn 2.4.0.0, 2.5.4.0, and other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a CUE file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fqw3-rxcx-3r2j/GHSA-fqw3-rxcx-3r2j.json b/advisories/unreviewed/2022/05/GHSA-fqw3-rxcx-3r2j/GHSA-fqw3-rxcx-3r2j.json index 1f49ed2f6a9..58ceff94086 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqw3-rxcx-3r2j/GHSA-fqw3-rxcx-3r2j.json +++ b/advisories/unreviewed/2022/05/GHSA-fqw3-rxcx-3r2j/GHSA-fqw3-rxcx-3r2j.json @@ -7,12 +7,8 @@ "CVE-2010-4799" ], "details": "Multiple SQL injection vulnerabilities in Chipmunk Pwngame 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to authenticate.php and the (3) ID parameter to pwn.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frw6-628x-33cp/GHSA-frw6-628x-33cp.json b/advisories/unreviewed/2022/05/GHSA-frw6-628x-33cp/GHSA-frw6-628x-33cp.json index 3c8953c14a4..9a8d3e75afa 100644 --- a/advisories/unreviewed/2022/05/GHSA-frw6-628x-33cp/GHSA-frw6-628x-33cp.json +++ b/advisories/unreviewed/2022/05/GHSA-frw6-628x-33cp/GHSA-frw6-628x-33cp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvvp-x46q-mfrf/GHSA-fvvp-x46q-mfrf.json b/advisories/unreviewed/2022/05/GHSA-fvvp-x46q-mfrf/GHSA-fvvp-x46q-mfrf.json index 5b2d8186f3b..d4e1d0654c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvvp-x46q-mfrf/GHSA-fvvp-x46q-mfrf.json +++ b/advisories/unreviewed/2022/05/GHSA-fvvp-x46q-mfrf/GHSA-fvvp-x46q-mfrf.json @@ -7,12 +7,8 @@ "CVE-2011-0767" ], "details": "Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall 6.2, 7.x, and 8.x allows remote attackers to inject arbitrary web script or HTML via an HTTP request to a firewalled server, aka Bug ID 31759.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx56-vgv5-wgf4/GHSA-fx56-vgv5-wgf4.json b/advisories/unreviewed/2022/05/GHSA-fx56-vgv5-wgf4/GHSA-fx56-vgv5-wgf4.json index f3ea7269951..c9b549fd9c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx56-vgv5-wgf4/GHSA-fx56-vgv5-wgf4.json +++ b/advisories/unreviewed/2022/05/GHSA-fx56-vgv5-wgf4/GHSA-fx56-vgv5-wgf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx9f-m844-h4j5/GHSA-fx9f-m844-h4j5.json b/advisories/unreviewed/2022/05/GHSA-fx9f-m844-h4j5/GHSA-fx9f-m844-h4j5.json index e6188573ea4..1e1d501ec1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx9f-m844-h4j5/GHSA-fx9f-m844-h4j5.json +++ b/advisories/unreviewed/2022/05/GHSA-fx9f-m844-h4j5/GHSA-fx9f-m844-h4j5.json @@ -7,12 +7,8 @@ "CVE-2011-0905" ], "details": "The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxxm-wp8x-x657/GHSA-fxxm-wp8x-x657.json b/advisories/unreviewed/2022/05/GHSA-fxxm-wp8x-x657/GHSA-fxxm-wp8x-x657.json index b2eca76aea5..c567e6f2ef7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxxm-wp8x-x657/GHSA-fxxm-wp8x-x657.json +++ b/advisories/unreviewed/2022/05/GHSA-fxxm-wp8x-x657/GHSA-fxxm-wp8x-x657.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2rg-wccx-q8f2/GHSA-g2rg-wccx-q8f2.json b/advisories/unreviewed/2022/05/GHSA-g2rg-wccx-q8f2/GHSA-g2rg-wccx-q8f2.json index c2cf55a7b20..1c4a03c09ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2rg-wccx-q8f2/GHSA-g2rg-wccx-q8f2.json +++ b/advisories/unreviewed/2022/05/GHSA-g2rg-wccx-q8f2/GHSA-g2rg-wccx-q8f2.json @@ -7,12 +7,8 @@ "CVE-2011-1715" ], "details": "Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to read arbitrary files via ..%2f (encoded dot dot) sequences in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g46c-hpfh-622w/GHSA-g46c-hpfh-622w.json b/advisories/unreviewed/2022/05/GHSA-g46c-hpfh-622w/GHSA-g46c-hpfh-622w.json index c948f44ec4b..ec6d9a689b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g46c-hpfh-622w/GHSA-g46c-hpfh-622w.json +++ b/advisories/unreviewed/2022/05/GHSA-g46c-hpfh-622w/GHSA-g46c-hpfh-622w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g4j3-947f-4vxm/GHSA-g4j3-947f-4vxm.json b/advisories/unreviewed/2022/05/GHSA-g4j3-947f-4vxm/GHSA-g4j3-947f-4vxm.json index 3409d797c88..5cdb964cbce 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4j3-947f-4vxm/GHSA-g4j3-947f-4vxm.json +++ b/advisories/unreviewed/2022/05/GHSA-g4j3-947f-4vxm/GHSA-g4j3-947f-4vxm.json @@ -7,12 +7,8 @@ "CVE-2011-1533" ], "details": "Cross-site scripting (XSS) vulnerability on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g649-qh35-mgfj/GHSA-g649-qh35-mgfj.json b/advisories/unreviewed/2022/05/GHSA-g649-qh35-mgfj/GHSA-g649-qh35-mgfj.json index da55ead8ae9..8a04486463b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g649-qh35-mgfj/GHSA-g649-qh35-mgfj.json +++ b/advisories/unreviewed/2022/05/GHSA-g649-qh35-mgfj/GHSA-g649-qh35-mgfj.json @@ -7,12 +7,8 @@ "CVE-2011-0279" ], "details": "HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to require authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6f4-4v6c-7rj9/GHSA-g6f4-4v6c-7rj9.json b/advisories/unreviewed/2022/05/GHSA-g6f4-4v6c-7rj9/GHSA-g6f4-4v6c-7rj9.json index fd588703d1d..83019834e85 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6f4-4v6c-7rj9/GHSA-g6f4-4v6c-7rj9.json +++ b/advisories/unreviewed/2022/05/GHSA-g6f4-4v6c-7rj9/GHSA-g6f4-4v6c-7rj9.json @@ -7,12 +7,8 @@ "CVE-2010-4427" ], "details": "Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.4.0, 10.1.3.4.1, and 11.1.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g9gc-6wqh-28r5/GHSA-g9gc-6wqh-28r5.json b/advisories/unreviewed/2022/05/GHSA-g9gc-6wqh-28r5/GHSA-g9gc-6wqh-28r5.json index e61b9ef926d..7375bce1a7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9gc-6wqh-28r5/GHSA-g9gc-6wqh-28r5.json +++ b/advisories/unreviewed/2022/05/GHSA-g9gc-6wqh-28r5/GHSA-g9gc-6wqh-28r5.json @@ -7,12 +7,8 @@ "CVE-2011-1864" ], "details": "Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gc7p-h58r-x4mr/GHSA-gc7p-h58r-x4mr.json b/advisories/unreviewed/2022/05/GHSA-gc7p-h58r-x4mr/GHSA-gc7p-h58r-x4mr.json index 8fe294e430d..e67e8cbd05d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc7p-h58r-x4mr/GHSA-gc7p-h58r-x4mr.json +++ b/advisories/unreviewed/2022/05/GHSA-gc7p-h58r-x4mr/GHSA-gc7p-h58r-x4mr.json @@ -7,12 +7,8 @@ "CVE-2010-4673" ], "details": "Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(4) and earlier allow remote attackers to cause a denial of service via a flood of packets, aka Bug ID CSCtg06316.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcr6-mhvm-c5mf/GHSA-gcr6-mhvm-c5mf.json b/advisories/unreviewed/2022/05/GHSA-gcr6-mhvm-c5mf/GHSA-gcr6-mhvm-c5mf.json index 90bd88770fc..f86333cdcf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcr6-mhvm-c5mf/GHSA-gcr6-mhvm-c5mf.json +++ b/advisories/unreviewed/2022/05/GHSA-gcr6-mhvm-c5mf/GHSA-gcr6-mhvm-c5mf.json @@ -7,12 +7,8 @@ "CVE-2011-1922" ], "details": "daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gf7c-j3g3-g2r4/GHSA-gf7c-j3g3-g2r4.json b/advisories/unreviewed/2022/05/GHSA-gf7c-j3g3-g2r4/GHSA-gf7c-j3g3-g2r4.json index 837b67fd1bf..0d3eb7f83bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf7c-j3g3-g2r4/GHSA-gf7c-j3g3-g2r4.json +++ b/advisories/unreviewed/2022/05/GHSA-gf7c-j3g3-g2r4/GHSA-gf7c-j3g3-g2r4.json @@ -7,12 +7,8 @@ "CVE-2011-1499" ], "details": "acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gf89-385c-hq37/GHSA-gf89-385c-hq37.json b/advisories/unreviewed/2022/05/GHSA-gf89-385c-hq37/GHSA-gf89-385c-hq37.json index acade12da7c..52bf6051608 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf89-385c-hq37/GHSA-gf89-385c-hq37.json +++ b/advisories/unreviewed/2022/05/GHSA-gf89-385c-hq37/GHSA-gf89-385c-hq37.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gfff-p3q7-9jjv/GHSA-gfff-p3q7-9jjv.json b/advisories/unreviewed/2022/05/GHSA-gfff-p3q7-9jjv/GHSA-gfff-p3q7-9jjv.json index a0a48a5d792..59accbde37b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfff-p3q7-9jjv/GHSA-gfff-p3q7-9jjv.json +++ b/advisories/unreviewed/2022/05/GHSA-gfff-p3q7-9jjv/GHSA-gfff-p3q7-9jjv.json @@ -7,12 +7,8 @@ "CVE-2011-1045" ], "details": "Unspecified vulnerability in the Rendition Engine (aka P8RE) 4.0.1 through 4.5.1 in IBM FileNet P8 Content Manager (CM) allows remote attackers to gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ggc4-2r54-5p25/GHSA-ggc4-2r54-5p25.json b/advisories/unreviewed/2022/05/GHSA-ggc4-2r54-5p25/GHSA-ggc4-2r54-5p25.json index 0ed3ea045a3..b394f1d900b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggc4-2r54-5p25/GHSA-ggc4-2r54-5p25.json +++ b/advisories/unreviewed/2022/05/GHSA-ggc4-2r54-5p25/GHSA-ggc4-2r54-5p25.json @@ -7,12 +7,8 @@ "CVE-2011-1403" ], "details": "Cross-site request forgery (CSRF) vulnerability in the pieforms implementation in Mahara before 1.3.6 allows remote attackers to hijack the authentication of arbitrary users for requests to any form, related to inappropriate regeneration of session keys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggx7-cwf4-pmg3/GHSA-ggx7-cwf4-pmg3.json b/advisories/unreviewed/2022/05/GHSA-ggx7-cwf4-pmg3/GHSA-ggx7-cwf4-pmg3.json index 777fbf0866d..fa34bd63bef 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggx7-cwf4-pmg3/GHSA-ggx7-cwf4-pmg3.json +++ b/advisories/unreviewed/2022/05/GHSA-ggx7-cwf4-pmg3/GHSA-ggx7-cwf4-pmg3.json @@ -7,12 +7,8 @@ "CVE-2010-4419" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise CRM component in Oracle PeopleSoft and JDEdwards Suite 9.0 Bundle #31 and 9.1 Bundle #6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Order Capture.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ghhh-97cc-m8qx/GHSA-ghhh-97cc-m8qx.json b/advisories/unreviewed/2022/05/GHSA-ghhh-97cc-m8qx/GHSA-ghhh-97cc-m8qx.json index 727fdb1afc1..e7757903fed 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghhh-97cc-m8qx/GHSA-ghhh-97cc-m8qx.json +++ b/advisories/unreviewed/2022/05/GHSA-ghhh-97cc-m8qx/GHSA-ghhh-97cc-m8qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghqg-r775-f425/GHSA-ghqg-r775-f425.json b/advisories/unreviewed/2022/05/GHSA-ghqg-r775-f425/GHSA-ghqg-r775-f425.json index c6fb47102ce..9e00133a532 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghqg-r775-f425/GHSA-ghqg-r775-f425.json +++ b/advisories/unreviewed/2022/05/GHSA-ghqg-r775-f425/GHSA-ghqg-r775-f425.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghr7-5368-f73m/GHSA-ghr7-5368-f73m.json b/advisories/unreviewed/2022/05/GHSA-ghr7-5368-f73m/GHSA-ghr7-5368-f73m.json index 8a3ea4c2871..07c6eab512c 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghr7-5368-f73m/GHSA-ghr7-5368-f73m.json +++ b/advisories/unreviewed/2022/05/GHSA-ghr7-5368-f73m/GHSA-ghr7-5368-f73m.json @@ -7,12 +7,8 @@ "CVE-2010-3263" ], "details": "Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm33-63vv-wrmp/GHSA-gm33-63vv-wrmp.json b/advisories/unreviewed/2022/05/GHSA-gm33-63vv-wrmp/GHSA-gm33-63vv-wrmp.json index 61428cce1be..5f20178e81a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm33-63vv-wrmp/GHSA-gm33-63vv-wrmp.json +++ b/advisories/unreviewed/2022/05/GHSA-gm33-63vv-wrmp/GHSA-gm33-63vv-wrmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmwh-w874-fr82/GHSA-gmwh-w874-fr82.json b/advisories/unreviewed/2022/05/GHSA-gmwh-w874-fr82/GHSA-gmwh-w874-fr82.json index 4792136702d..9f1aba53533 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmwh-w874-fr82/GHSA-gmwh-w874-fr82.json +++ b/advisories/unreviewed/2022/05/GHSA-gmwh-w874-fr82/GHSA-gmwh-w874-fr82.json @@ -7,12 +7,8 @@ "CVE-2011-0271" ], "details": "The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a \"command injection vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gp85-9v5p-3cfv/GHSA-gp85-9v5p-3cfv.json b/advisories/unreviewed/2022/05/GHSA-gp85-9v5p-3cfv/GHSA-gp85-9v5p-3cfv.json index 236424a12c7..147c652bee1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp85-9v5p-3cfv/GHSA-gp85-9v5p-3cfv.json +++ b/advisories/unreviewed/2022/05/GHSA-gp85-9v5p-3cfv/GHSA-gp85-9v5p-3cfv.json @@ -7,12 +7,8 @@ "CVE-2011-0960" ], "details": "Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv73-3v96-pq6f/GHSA-gv73-3v96-pq6f.json b/advisories/unreviewed/2022/05/GHSA-gv73-3v96-pq6f/GHSA-gv73-3v96-pq6f.json index ec8230675eb..4c5ead80795 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv73-3v96-pq6f/GHSA-gv73-3v96-pq6f.json +++ b/advisories/unreviewed/2022/05/GHSA-gv73-3v96-pq6f/GHSA-gv73-3v96-pq6f.json @@ -7,12 +7,8 @@ "CVE-2011-1863" ], "details": "HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allow remote authenticated users to conduct unspecified script injection attacks via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv9p-397w-xfq9/GHSA-gv9p-397w-xfq9.json b/advisories/unreviewed/2022/05/GHSA-gv9p-397w-xfq9/GHSA-gv9p-397w-xfq9.json index a6b8878d37a..304df507560 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv9p-397w-xfq9/GHSA-gv9p-397w-xfq9.json +++ b/advisories/unreviewed/2022/05/GHSA-gv9p-397w-xfq9/GHSA-gv9p-397w-xfq9.json @@ -7,12 +7,8 @@ "CVE-2011-0491" ], "details": "The tor_realloc function in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not validate a certain size value during memory allocation, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors, related to \"underflow errors.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvv4-f8jm-4w34/GHSA-gvv4-f8jm-4w34.json b/advisories/unreviewed/2022/05/GHSA-gvv4-f8jm-4w34/GHSA-gvv4-f8jm-4w34.json index e5a15c2af3d..86f3c3e9dc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvv4-f8jm-4w34/GHSA-gvv4-f8jm-4w34.json +++ b/advisories/unreviewed/2022/05/GHSA-gvv4-f8jm-4w34/GHSA-gvv4-f8jm-4w34.json @@ -7,12 +7,8 @@ "CVE-2011-1391" ], "details": "The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the InsertMarker method, which allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvxq-7mqc-6hc7/GHSA-gvxq-7mqc-6hc7.json b/advisories/unreviewed/2022/05/GHSA-gvxq-7mqc-6hc7/GHSA-gvxq-7mqc-6hc7.json index 3d8a2fb4cb1..10fe50caa81 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvxq-7mqc-6hc7/GHSA-gvxq-7mqc-6hc7.json +++ b/advisories/unreviewed/2022/05/GHSA-gvxq-7mqc-6hc7/GHSA-gvxq-7mqc-6hc7.json @@ -7,12 +7,8 @@ "CVE-2011-1402" ], "details": "Mahara before 1.3.6 allows remote authenticated users to bypass intended access restrictions, and suspend a user account, edit a view, visit a view, edit a plan artefact, read a plans block, read a plan artefact, edit a blog, read a blog block, read a blog artefact, or access a block, via a request associated with (1) admin/users/search.json.php, (2) view/newviewtoken.json.php, (3) lib/mahara.php, (4) artefact/plans/tasks.json.php, (5) artefact/plans/viewtasks.json.php, (6) artefact/blog/view/index.json.php, (7) artefact/blog/posts.json.php, or (8) blocktype/myfriends/myfriends.json.php, related to incorrect privilege enforcement, a missing user id check, and incorrect enforcement of the Overriding Start/Stop Dates setting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gx6f-w2q9-mwc8/GHSA-gx6f-w2q9-mwc8.json b/advisories/unreviewed/2022/05/GHSA-gx6f-w2q9-mwc8/GHSA-gx6f-w2q9-mwc8.json index 1bb00bb3c31..b304047d4b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx6f-w2q9-mwc8/GHSA-gx6f-w2q9-mwc8.json +++ b/advisories/unreviewed/2022/05/GHSA-gx6f-w2q9-mwc8/GHSA-gx6f-w2q9-mwc8.json @@ -7,12 +7,8 @@ "CVE-2011-0512" ], "details": "SQL injection vulnerability in team.php in the Teams Structure module 3.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the team_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxjq-3q6x-qgmh/GHSA-gxjq-3q6x-qgmh.json b/advisories/unreviewed/2022/05/GHSA-gxjq-3q6x-qgmh/GHSA-gxjq-3q6x-qgmh.json index ceca62d9512..5affb88b1ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxjq-3q6x-qgmh/GHSA-gxjq-3q6x-qgmh.json +++ b/advisories/unreviewed/2022/05/GHSA-gxjq-3q6x-qgmh/GHSA-gxjq-3q6x-qgmh.json @@ -7,12 +7,8 @@ "CVE-2010-4417" ], "details": "Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h285-vv62-q7vr/GHSA-h285-vv62-q7vr.json b/advisories/unreviewed/2022/05/GHSA-h285-vv62-q7vr/GHSA-h285-vv62-q7vr.json index 4a13dc11de2..af888a7a678 100644 --- a/advisories/unreviewed/2022/05/GHSA-h285-vv62-q7vr/GHSA-h285-vv62-q7vr.json +++ b/advisories/unreviewed/2022/05/GHSA-h285-vv62-q7vr/GHSA-h285-vv62-q7vr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h34q-7cxx-g6r9/GHSA-h34q-7cxx-g6r9.json b/advisories/unreviewed/2022/05/GHSA-h34q-7cxx-g6r9/GHSA-h34q-7cxx-g6r9.json index 0f85c511b2e..d2c5656091e 100644 --- a/advisories/unreviewed/2022/05/GHSA-h34q-7cxx-g6r9/GHSA-h34q-7cxx-g6r9.json +++ b/advisories/unreviewed/2022/05/GHSA-h34q-7cxx-g6r9/GHSA-h34q-7cxx-g6r9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3jj-q38m-9734/GHSA-h3jj-q38m-9734.json b/advisories/unreviewed/2022/05/GHSA-h3jj-q38m-9734/GHSA-h3jj-q38m-9734.json index 26bc0877b31..0acea1a04b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3jj-q38m-9734/GHSA-h3jj-q38m-9734.json +++ b/advisories/unreviewed/2022/05/GHSA-h3jj-q38m-9734/GHSA-h3jj-q38m-9734.json @@ -7,12 +7,8 @@ "CVE-2010-4635" ], "details": "SQL injection vulnerability in detail.asp in Site2Nite Vacation Rental (VRBO) Listings allows remote attackers to execute arbitrary SQL commands via the ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h548-mpc5-c65p/GHSA-h548-mpc5-c65p.json b/advisories/unreviewed/2022/05/GHSA-h548-mpc5-c65p/GHSA-h548-mpc5-c65p.json index 1a0e0ab44cf..d1d83265cdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-h548-mpc5-c65p/GHSA-h548-mpc5-c65p.json +++ b/advisories/unreviewed/2022/05/GHSA-h548-mpc5-c65p/GHSA-h548-mpc5-c65p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5r6-mrjh-qc56/GHSA-h5r6-mrjh-qc56.json b/advisories/unreviewed/2022/05/GHSA-h5r6-mrjh-qc56/GHSA-h5r6-mrjh-qc56.json index 7b27598b25a..eb637e11874 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5r6-mrjh-qc56/GHSA-h5r6-mrjh-qc56.json +++ b/advisories/unreviewed/2022/05/GHSA-h5r6-mrjh-qc56/GHSA-h5r6-mrjh-qc56.json @@ -7,12 +7,8 @@ "CVE-2010-4642" ], "details": "Cross-site scripting (XSS) vulnerability in XWiki Enterprise before 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h64v-56v4-2q6j/GHSA-h64v-56v4-2q6j.json b/advisories/unreviewed/2022/05/GHSA-h64v-56v4-2q6j/GHSA-h64v-56v4-2q6j.json index 943c618e637..040cdf16e2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h64v-56v4-2q6j/GHSA-h64v-56v4-2q6j.json +++ b/advisories/unreviewed/2022/05/GHSA-h64v-56v4-2q6j/GHSA-h64v-56v4-2q6j.json @@ -7,12 +7,8 @@ "CVE-2011-1429" ], "details": "Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6f7-wjm5-gjgh/GHSA-h6f7-wjm5-gjgh.json b/advisories/unreviewed/2022/05/GHSA-h6f7-wjm5-gjgh/GHSA-h6f7-wjm5-gjgh.json index de63ce735dd..fa34a666a3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6f7-wjm5-gjgh/GHSA-h6f7-wjm5-gjgh.json +++ b/advisories/unreviewed/2022/05/GHSA-h6f7-wjm5-gjgh/GHSA-h6f7-wjm5-gjgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6ph-4xc6-hpjh/GHSA-h6ph-4xc6-hpjh.json b/advisories/unreviewed/2022/05/GHSA-h6ph-4xc6-hpjh/GHSA-h6ph-4xc6-hpjh.json index 5557bd76b20..03e8f178b74 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6ph-4xc6-hpjh/GHSA-h6ph-4xc6-hpjh.json +++ b/advisories/unreviewed/2022/05/GHSA-h6ph-4xc6-hpjh/GHSA-h6ph-4xc6-hpjh.json @@ -7,12 +7,8 @@ "CVE-2011-0314" ], "details": "Heap-based buffer overflow in IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 allows remote authenticated users to execute arbitrary code or cause a denial of service (queue manager crash) by inserting an invalid message into the queue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6r9-68fv-7pc8/GHSA-h6r9-68fv-7pc8.json b/advisories/unreviewed/2022/05/GHSA-h6r9-68fv-7pc8/GHSA-h6r9-68fv-7pc8.json index b3d6db61f0e..60bee1e0a1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6r9-68fv-7pc8/GHSA-h6r9-68fv-7pc8.json +++ b/advisories/unreviewed/2022/05/GHSA-h6r9-68fv-7pc8/GHSA-h6r9-68fv-7pc8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h749-7h9c-cq2g/GHSA-h749-7h9c-cq2g.json b/advisories/unreviewed/2022/05/GHSA-h749-7h9c-cq2g/GHSA-h749-7h9c-cq2g.json index 2c4ff35ba93..53345b48e30 100644 --- a/advisories/unreviewed/2022/05/GHSA-h749-7h9c-cq2g/GHSA-h749-7h9c-cq2g.json +++ b/advisories/unreviewed/2022/05/GHSA-h749-7h9c-cq2g/GHSA-h749-7h9c-cq2g.json @@ -7,12 +7,8 @@ "CVE-2011-0169" ], "details": "WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h78r-gxwp-4fvm/GHSA-h78r-gxwp-4fvm.json b/advisories/unreviewed/2022/05/GHSA-h78r-gxwp-4fvm/GHSA-h78r-gxwp-4fvm.json index 522c6bbb93c..68ef54eebae 100644 --- a/advisories/unreviewed/2022/05/GHSA-h78r-gxwp-4fvm/GHSA-h78r-gxwp-4fvm.json +++ b/advisories/unreviewed/2022/05/GHSA-h78r-gxwp-4fvm/GHSA-h78r-gxwp-4fvm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7jg-m25q-jf3g/GHSA-h7jg-m25q-jf3g.json b/advisories/unreviewed/2022/05/GHSA-h7jg-m25q-jf3g/GHSA-h7jg-m25q-jf3g.json index 75d7e7b1684..dce56b56313 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7jg-m25q-jf3g/GHSA-h7jg-m25q-jf3g.json +++ b/advisories/unreviewed/2022/05/GHSA-h7jg-m25q-jf3g/GHSA-h7jg-m25q-jf3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7rx-vh4g-24pp/GHSA-h7rx-vh4g-24pp.json b/advisories/unreviewed/2022/05/GHSA-h7rx-vh4g-24pp/GHSA-h7rx-vh4g-24pp.json index 6aab275f848..c5319525a71 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7rx-vh4g-24pp/GHSA-h7rx-vh4g-24pp.json +++ b/advisories/unreviewed/2022/05/GHSA-h7rx-vh4g-24pp/GHSA-h7rx-vh4g-24pp.json @@ -7,12 +7,8 @@ "CVE-2011-0390" ], "details": "The XML-RPC implementation on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, 1.6.x, and 1.7.0 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka Bug ID CSCtj44534.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h8jc-fxc6-j8gp/GHSA-h8jc-fxc6-j8gp.json b/advisories/unreviewed/2022/05/GHSA-h8jc-fxc6-j8gp/GHSA-h8jc-fxc6-j8gp.json index c18098b0ab7..e455364bb83 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8jc-fxc6-j8gp/GHSA-h8jc-fxc6-j8gp.json +++ b/advisories/unreviewed/2022/05/GHSA-h8jc-fxc6-j8gp/GHSA-h8jc-fxc6-j8gp.json @@ -7,12 +7,8 @@ "CVE-2011-0384" ], "details": "The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug ID CSCtf01253.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8wq-82x5-99wg/GHSA-h8wq-82x5-99wg.json b/advisories/unreviewed/2022/05/GHSA-h8wq-82x5-99wg/GHSA-h8wq-82x5-99wg.json index e11111408e1..edcf1d83f61 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8wq-82x5-99wg/GHSA-h8wq-82x5-99wg.json +++ b/advisories/unreviewed/2022/05/GHSA-h8wq-82x5-99wg/GHSA-h8wq-82x5-99wg.json @@ -7,12 +7,8 @@ "CVE-2010-4773" ], "details": "Unspecified vulnerability in Hitachi EUR Form Client before 05-10 -/D 2010.11.15 and 05-10-CA (* 2) 2010.11.15; Hitachi EUR Form Service before 05-10 -/D 2010.11.15; and uCosminexus EUR Form Service before 07-60 -/D 2010.11.15 on Windows, before 05-10 -/D 2010.11.15 and 07-50 -/D 2010.11.15 on Linux, and before 07-50 -/C 2010.11.15 on AIX; allows remote attackers to execute arbitrary code via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h945-62jx-whh7/GHSA-h945-62jx-whh7.json b/advisories/unreviewed/2022/05/GHSA-h945-62jx-whh7/GHSA-h945-62jx-whh7.json index 2e5b55ea1ec..c9c22b7e111 100644 --- a/advisories/unreviewed/2022/05/GHSA-h945-62jx-whh7/GHSA-h945-62jx-whh7.json +++ b/advisories/unreviewed/2022/05/GHSA-h945-62jx-whh7/GHSA-h945-62jx-whh7.json @@ -7,12 +7,8 @@ "CVE-2011-0273" ], "details": "Buffer overflow in crs.exe in HP OpenView Storage Data Protector Cell Manager 6.11 allows remote attackers to execute arbitrary code via unspecified message types.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc92-928v-m6vq/GHSA-hc92-928v-m6vq.json b/advisories/unreviewed/2022/05/GHSA-hc92-928v-m6vq/GHSA-hc92-928v-m6vq.json index 80040c4e9fd..f25da7a92b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc92-928v-m6vq/GHSA-hc92-928v-m6vq.json +++ b/advisories/unreviewed/2022/05/GHSA-hc92-928v-m6vq/GHSA-hc92-928v-m6vq.json @@ -7,12 +7,8 @@ "CVE-2011-1820" ], "details": "IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the ibm-auditAttributesOnGroupEvalOp setting for auditing of extended operations, which might allow attackers to obtain sensitive information by reading the audit log.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcjh-vxw9-5294/GHSA-hcjh-vxw9-5294.json b/advisories/unreviewed/2022/05/GHSA-hcjh-vxw9-5294/GHSA-hcjh-vxw9-5294.json index cdb1f89a095..890b3d340d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcjh-vxw9-5294/GHSA-hcjh-vxw9-5294.json +++ b/advisories/unreviewed/2022/05/GHSA-hcjh-vxw9-5294/GHSA-hcjh-vxw9-5294.json @@ -7,12 +7,8 @@ "CVE-2011-0497" ], "details": "Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to read arbitrary files via \"../\\\" (dot dot forward-slash backslash) sequences in a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hf97-32ff-w4h6/GHSA-hf97-32ff-w4h6.json b/advisories/unreviewed/2022/05/GHSA-hf97-32ff-w4h6/GHSA-hf97-32ff-w4h6.json index ab4c47a1128..5d47ba1fbe2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf97-32ff-w4h6/GHSA-hf97-32ff-w4h6.json +++ b/advisories/unreviewed/2022/05/GHSA-hf97-32ff-w4h6/GHSA-hf97-32ff-w4h6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfwj-43j6-7v2f/GHSA-hfwj-43j6-7v2f.json b/advisories/unreviewed/2022/05/GHSA-hfwj-43j6-7v2f/GHSA-hfwj-43j6-7v2f.json index 0847d0c3f74..a9e6e651a4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfwj-43j6-7v2f/GHSA-hfwj-43j6-7v2f.json +++ b/advisories/unreviewed/2022/05/GHSA-hfwj-43j6-7v2f/GHSA-hfwj-43j6-7v2f.json @@ -7,12 +7,8 @@ "CVE-2011-1377" ], "details": "The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhwf-x424-rgm4/GHSA-hhwf-x424-rgm4.json b/advisories/unreviewed/2022/05/GHSA-hhwf-x424-rgm4/GHSA-hhwf-x424-rgm4.json index 64b76455f46..95c74b6b3f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhwf-x424-rgm4/GHSA-hhwf-x424-rgm4.json +++ b/advisories/unreviewed/2022/05/GHSA-hhwf-x424-rgm4/GHSA-hhwf-x424-rgm4.json @@ -7,12 +7,8 @@ "CVE-2011-0771" ], "details": "The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not validate the file for a profile image, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks and possibly execute arbitrary PHP code by causing a crafted avatar to be downloaded from an external login provider site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj6x-qwph-j4jm/GHSA-hj6x-qwph-j4jm.json b/advisories/unreviewed/2022/05/GHSA-hj6x-qwph-j4jm/GHSA-hj6x-qwph-j4jm.json index dfb04c9b796..1057018374e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj6x-qwph-j4jm/GHSA-hj6x-qwph-j4jm.json +++ b/advisories/unreviewed/2022/05/GHSA-hj6x-qwph-j4jm/GHSA-hj6x-qwph-j4jm.json @@ -7,12 +7,8 @@ "CVE-2011-1393" ], "details": "Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x before 8.5.2 FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Notes RPC packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjqq-3jq5-hrqf/GHSA-hjqq-3jq5-hrqf.json b/advisories/unreviewed/2022/05/GHSA-hjqq-3jq5-hrqf/GHSA-hjqq-3jq5-hrqf.json index 03e68972592..6e73f69864a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjqq-3jq5-hrqf/GHSA-hjqq-3jq5-hrqf.json +++ b/advisories/unreviewed/2022/05/GHSA-hjqq-3jq5-hrqf/GHSA-hjqq-3jq5-hrqf.json @@ -7,12 +7,8 @@ "CVE-2011-1623" ], "details": "Cisco Media Processing Software before 1.2 on Media Experience Engine (MXE) 5600 devices has a default root password, which makes it easier for context-dependent attackers to obtain access via (1) the local console, (2) an SSH session, or (3) a TELNET session, aka Bug ID CSCto77737.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp9f-m83m-8748/GHSA-hp9f-m83m-8748.json b/advisories/unreviewed/2022/05/GHSA-hp9f-m83m-8748/GHSA-hp9f-m83m-8748.json index acee3cb15e5..ca38ff579ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp9f-m83m-8748/GHSA-hp9f-m83m-8748.json +++ b/advisories/unreviewed/2022/05/GHSA-hp9f-m83m-8748/GHSA-hp9f-m83m-8748.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hq6p-w27f-28m9/GHSA-hq6p-w27f-28m9.json b/advisories/unreviewed/2022/05/GHSA-hq6p-w27f-28m9/GHSA-hq6p-w27f-28m9.json index f89e1b87096..6eb61b485ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq6p-w27f-28m9/GHSA-hq6p-w27f-28m9.json +++ b/advisories/unreviewed/2022/05/GHSA-hq6p-w27f-28m9/GHSA-hq6p-w27f-28m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hq75-7jp8-q8x3/GHSA-hq75-7jp8-q8x3.json b/advisories/unreviewed/2022/05/GHSA-hq75-7jp8-q8x3/GHSA-hq75-7jp8-q8x3.json index a89e6dac578..76e79e7cc4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq75-7jp8-q8x3/GHSA-hq75-7jp8-q8x3.json +++ b/advisories/unreviewed/2022/05/GHSA-hq75-7jp8-q8x3/GHSA-hq75-7jp8-q8x3.json @@ -7,12 +7,8 @@ "CVE-2011-0962" ], "details": "Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hq8x-2vmq-vp3c/GHSA-hq8x-2vmq-vp3c.json b/advisories/unreviewed/2022/05/GHSA-hq8x-2vmq-vp3c/GHSA-hq8x-2vmq-vp3c.json index 5b661e241f2..f3eab079f59 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq8x-2vmq-vp3c/GHSA-hq8x-2vmq-vp3c.json +++ b/advisories/unreviewed/2022/05/GHSA-hq8x-2vmq-vp3c/GHSA-hq8x-2vmq-vp3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hr4m-fxpj-q7hc/GHSA-hr4m-fxpj-q7hc.json b/advisories/unreviewed/2022/05/GHSA-hr4m-fxpj-q7hc/GHSA-hr4m-fxpj-q7hc.json index 1a5a923d071..18c22051f97 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr4m-fxpj-q7hc/GHSA-hr4m-fxpj-q7hc.json +++ b/advisories/unreviewed/2022/05/GHSA-hr4m-fxpj-q7hc/GHSA-hr4m-fxpj-q7hc.json @@ -7,12 +7,8 @@ "CVE-2011-1406" ], "details": "Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrm9-j88x-2cc8/GHSA-hrm9-j88x-2cc8.json b/advisories/unreviewed/2022/05/GHSA-hrm9-j88x-2cc8/GHSA-hrm9-j88x-2cc8.json index 8403153c4a0..8b90f22c89b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrm9-j88x-2cc8/GHSA-hrm9-j88x-2cc8.json +++ b/advisories/unreviewed/2022/05/GHSA-hrm9-j88x-2cc8/GHSA-hrm9-j88x-2cc8.json @@ -7,12 +7,8 @@ "CVE-2011-1665" ], "details": "PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain backup SQL files via a direct request for predictable filenames in cache/backup/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hv39-2fmf-jg4m/GHSA-hv39-2fmf-jg4m.json b/advisories/unreviewed/2022/05/GHSA-hv39-2fmf-jg4m/GHSA-hv39-2fmf-jg4m.json index fdd364ee018..ea657d497cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv39-2fmf-jg4m/GHSA-hv39-2fmf-jg4m.json +++ b/advisories/unreviewed/2022/05/GHSA-hv39-2fmf-jg4m/GHSA-hv39-2fmf-jg4m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvhm-xx39-3276/GHSA-hvhm-xx39-3276.json b/advisories/unreviewed/2022/05/GHSA-hvhm-xx39-3276/GHSA-hvhm-xx39-3276.json index d847e68a9ff..e8501f3f34b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvhm-xx39-3276/GHSA-hvhm-xx39-3276.json +++ b/advisories/unreviewed/2022/05/GHSA-hvhm-xx39-3276/GHSA-hvhm-xx39-3276.json @@ -7,12 +7,8 @@ "CVE-2011-1606" ], "details": "Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtg62855.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwq4-pqf6-gq3c/GHSA-hwq4-pqf6-gq3c.json b/advisories/unreviewed/2022/05/GHSA-hwq4-pqf6-gq3c/GHSA-hwq4-pqf6-gq3c.json index 2acd5dd500a..6d0e3c52fcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwq4-pqf6-gq3c/GHSA-hwq4-pqf6-gq3c.json +++ b/advisories/unreviewed/2022/05/GHSA-hwq4-pqf6-gq3c/GHSA-hwq4-pqf6-gq3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwqv-g52g-rgvm/GHSA-hwqv-g52g-rgvm.json b/advisories/unreviewed/2022/05/GHSA-hwqv-g52g-rgvm/GHSA-hwqv-g52g-rgvm.json index 85004c7b80b..a9001d85cf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwqv-g52g-rgvm/GHSA-hwqv-g52g-rgvm.json +++ b/advisories/unreviewed/2022/05/GHSA-hwqv-g52g-rgvm/GHSA-hwqv-g52g-rgvm.json @@ -7,12 +7,8 @@ "CVE-2011-0649" ], "details": "Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver BusinessWorks Service 1.0.0, when running on Unix systems, allow local users to gain root privileges via unknown vectors related to SUID and (1) Rendezvous Routing Daemon (rvrd), (2) Rendezvous Secure Daemon (rvsd), (3) Rendezvous Secure Routing Daemon (rvsrd), and (4) EMS Server (tibemsd).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hx66-9rq3-9f99/GHSA-hx66-9rq3-9f99.json b/advisories/unreviewed/2022/05/GHSA-hx66-9rq3-9f99/GHSA-hx66-9rq3-9f99.json index 62b0d16313e..ef53558a2d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx66-9rq3-9f99/GHSA-hx66-9rq3-9f99.json +++ b/advisories/unreviewed/2022/05/GHSA-hx66-9rq3-9f99/GHSA-hx66-9rq3-9f99.json @@ -7,12 +7,8 @@ "CVE-2011-1673" ], "details": "BackupConfig.php on the NetGear ProSafe WNAP210 allows remote attackers to obtain the administrator password by reading the configuration file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2v7-mg5j-hjc3/GHSA-j2v7-mg5j-hjc3.json b/advisories/unreviewed/2022/05/GHSA-j2v7-mg5j-hjc3/GHSA-j2v7-mg5j-hjc3.json index 4c55459a2ba..b27954db8e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2v7-mg5j-hjc3/GHSA-j2v7-mg5j-hjc3.json +++ b/advisories/unreviewed/2022/05/GHSA-j2v7-mg5j-hjc3/GHSA-j2v7-mg5j-hjc3.json @@ -7,12 +7,8 @@ "CVE-2011-1858" ], "details": "Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows local users to bypass intended access restrictions via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j3h9-vcx4-qgvw/GHSA-j3h9-vcx4-qgvw.json b/advisories/unreviewed/2022/05/GHSA-j3h9-vcx4-qgvw/GHSA-j3h9-vcx4-qgvw.json index 9f0394a19cc..298314976bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3h9-vcx4-qgvw/GHSA-j3h9-vcx4-qgvw.json +++ b/advisories/unreviewed/2022/05/GHSA-j3h9-vcx4-qgvw/GHSA-j3h9-vcx4-qgvw.json @@ -7,12 +7,8 @@ "CVE-2011-1064" ], "details": "SQL injection vulnerability in member/list.php in qibosoft Qi Bo CMS 7 allows remote attackers to execute arbitrary SQL commands via the aidDB[] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j497-52cv-pcp6/GHSA-j497-52cv-pcp6.json b/advisories/unreviewed/2022/05/GHSA-j497-52cv-pcp6/GHSA-j497-52cv-pcp6.json index 043b0355dd7..250ddfd1532 100644 --- a/advisories/unreviewed/2022/05/GHSA-j497-52cv-pcp6/GHSA-j497-52cv-pcp6.json +++ b/advisories/unreviewed/2022/05/GHSA-j497-52cv-pcp6/GHSA-j497-52cv-pcp6.json @@ -7,12 +7,8 @@ "CVE-2011-0310" ], "details": "Buffer overflow in IBM WebSphere MQ 7.0 before 7.0.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted header field in a message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4j2-652r-qc85/GHSA-j4j2-652r-qc85.json b/advisories/unreviewed/2022/05/GHSA-j4j2-652r-qc85/GHSA-j4j2-652r-qc85.json index 169542a1c6a..5dca04dd8e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4j2-652r-qc85/GHSA-j4j2-652r-qc85.json +++ b/advisories/unreviewed/2022/05/GHSA-j4j2-652r-qc85/GHSA-j4j2-652r-qc85.json @@ -7,12 +7,8 @@ "CVE-2011-1518" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.4.x before 2.4.10 and 3.x before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j4rv-442r-v8h9/GHSA-j4rv-442r-v8h9.json b/advisories/unreviewed/2022/05/GHSA-j4rv-442r-v8h9/GHSA-j4rv-442r-v8h9.json index 56e922a927e..432dd6fb9c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4rv-442r-v8h9/GHSA-j4rv-442r-v8h9.json +++ b/advisories/unreviewed/2022/05/GHSA-j4rv-442r-v8h9/GHSA-j4rv-442r-v8h9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j4vr-x7g7-jv3j/GHSA-j4vr-x7g7-jv3j.json b/advisories/unreviewed/2022/05/GHSA-j4vr-x7g7-jv3j/GHSA-j4vr-x7g7-jv3j.json index 67de257b4af..3c00e85c271 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4vr-x7g7-jv3j/GHSA-j4vr-x7g7-jv3j.json +++ b/advisories/unreviewed/2022/05/GHSA-j4vr-x7g7-jv3j/GHSA-j4vr-x7g7-jv3j.json @@ -7,12 +7,8 @@ "CVE-2011-0406" ], "details": "Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a long request to TCP port 777.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5wq-5rfm-xx8g/GHSA-j5wq-5rfm-xx8g.json b/advisories/unreviewed/2022/05/GHSA-j5wq-5rfm-xx8g/GHSA-j5wq-5rfm-xx8g.json index 5c5ca59b503..a65824e79dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5wq-5rfm-xx8g/GHSA-j5wq-5rfm-xx8g.json +++ b/advisories/unreviewed/2022/05/GHSA-j5wq-5rfm-xx8g/GHSA-j5wq-5rfm-xx8g.json @@ -7,12 +7,8 @@ "CVE-2011-1174" ], "details": "manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x before 1.8.3.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a series of manager sessions involving invalid data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j62c-r2vh-7rq3/GHSA-j62c-r2vh-7rq3.json b/advisories/unreviewed/2022/05/GHSA-j62c-r2vh-7rq3/GHSA-j62c-r2vh-7rq3.json index 381001d7bae..4add7b7f3a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j62c-r2vh-7rq3/GHSA-j62c-r2vh-7rq3.json +++ b/advisories/unreviewed/2022/05/GHSA-j62c-r2vh-7rq3/GHSA-j62c-r2vh-7rq3.json @@ -7,12 +7,8 @@ "CVE-2011-1050" ], "details": "Unspecified vulnerability in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to \"converson of string encodings\" and \"inconsistencies in the handling of UTF8 sequences by the user interface.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j66m-x5fg-q9vc/GHSA-j66m-x5fg-q9vc.json b/advisories/unreviewed/2022/05/GHSA-j66m-x5fg-q9vc/GHSA-j66m-x5fg-q9vc.json index cc8532e0dd5..b776236a7b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-j66m-x5fg-q9vc/GHSA-j66m-x5fg-q9vc.json +++ b/advisories/unreviewed/2022/05/GHSA-j66m-x5fg-q9vc/GHSA-j66m-x5fg-q9vc.json @@ -7,12 +7,8 @@ "CVE-2011-1224" ], "details": "IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j66p-7xqc-vr5m/GHSA-j66p-7xqc-vr5m.json b/advisories/unreviewed/2022/05/GHSA-j66p-7xqc-vr5m/GHSA-j66p-7xqc-vr5m.json index 87c85584d25..4d29061c436 100644 --- a/advisories/unreviewed/2022/05/GHSA-j66p-7xqc-vr5m/GHSA-j66p-7xqc-vr5m.json +++ b/advisories/unreviewed/2022/05/GHSA-j66p-7xqc-vr5m/GHSA-j66p-7xqc-vr5m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6xx-f4pg-fp88/GHSA-j6xx-f4pg-fp88.json b/advisories/unreviewed/2022/05/GHSA-j6xx-f4pg-fp88/GHSA-j6xx-f4pg-fp88.json index 6ddd347f2c9..dee12b6fccc 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6xx-f4pg-fp88/GHSA-j6xx-f4pg-fp88.json +++ b/advisories/unreviewed/2022/05/GHSA-j6xx-f4pg-fp88/GHSA-j6xx-f4pg-fp88.json @@ -7,12 +7,8 @@ "CVE-2011-1685" ], "details": "Best Practical Solutions RT 3.8.0 through 3.8.9 and 4.0.0rc through 4.0.0rc7, when the CustomFieldValuesSources (aka external custom field) option is enabled, allows remote authenticated users to execute arbitrary code via unspecified vectors, as demonstrated by a cross-site request forgery (CSRF) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j75f-9wv2-95m3/GHSA-j75f-9wv2-95m3.json b/advisories/unreviewed/2022/05/GHSA-j75f-9wv2-95m3/GHSA-j75f-9wv2-95m3.json index 7ca872ec11d..6d54f02f34f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j75f-9wv2-95m3/GHSA-j75f-9wv2-95m3.json +++ b/advisories/unreviewed/2022/05/GHSA-j75f-9wv2-95m3/GHSA-j75f-9wv2-95m3.json @@ -7,12 +7,8 @@ "CVE-2010-3044" ], "details": "Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to atas32.dll, a different vulnerability than CVE-2010-3041, CVE-2010-3042, and CVE-2010-3043.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j774-385g-cxm2/GHSA-j774-385g-cxm2.json b/advisories/unreviewed/2022/05/GHSA-j774-385g-cxm2/GHSA-j774-385g-cxm2.json index adbdfc15b02..c12c431f76e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j774-385g-cxm2/GHSA-j774-385g-cxm2.json +++ b/advisories/unreviewed/2022/05/GHSA-j774-385g-cxm2/GHSA-j774-385g-cxm2.json @@ -7,12 +7,8 @@ "CVE-2011-1371" ], "details": "Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an Unknown Error document, a different vulnerability than CVE-2011-4171.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7gh-88xh-vghc/GHSA-j7gh-88xh-vghc.json b/advisories/unreviewed/2022/05/GHSA-j7gh-88xh-vghc/GHSA-j7gh-88xh-vghc.json index 9a968cfeda1..e6416063b87 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7gh-88xh-vghc/GHSA-j7gh-88xh-vghc.json +++ b/advisories/unreviewed/2022/05/GHSA-j7gh-88xh-vghc/GHSA-j7gh-88xh-vghc.json @@ -7,12 +7,8 @@ "CVE-2011-0518" ], "details": "Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via the system parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j825-vhpg-2qh4/GHSA-j825-vhpg-2qh4.json b/advisories/unreviewed/2022/05/GHSA-j825-vhpg-2qh4/GHSA-j825-vhpg-2qh4.json index 6dbf6e39284..356f0dc0332 100644 --- a/advisories/unreviewed/2022/05/GHSA-j825-vhpg-2qh4/GHSA-j825-vhpg-2qh4.json +++ b/advisories/unreviewed/2022/05/GHSA-j825-vhpg-2qh4/GHSA-j825-vhpg-2qh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9gr-m9mp-f3p2/GHSA-j9gr-m9mp-f3p2.json b/advisories/unreviewed/2022/05/GHSA-j9gr-m9mp-f3p2/GHSA-j9gr-m9mp-f3p2.json index 0e13a4cc24b..bdf65cb3ffc 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9gr-m9mp-f3p2/GHSA-j9gr-m9mp-f3p2.json +++ b/advisories/unreviewed/2022/05/GHSA-j9gr-m9mp-f3p2/GHSA-j9gr-m9mp-f3p2.json @@ -7,12 +7,8 @@ "CVE-2010-3043" ], "details": "Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, a different vulnerability than CVE-2010-3041, CVE-2010-3042, and CVE-2010-3044.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9hm-95rh-8hr5/GHSA-j9hm-95rh-8hr5.json b/advisories/unreviewed/2022/05/GHSA-j9hm-95rh-8hr5/GHSA-j9hm-95rh-8hr5.json index 5aec7f4c5af..e463ed9693b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9hm-95rh-8hr5/GHSA-j9hm-95rh-8hr5.json +++ b/advisories/unreviewed/2022/05/GHSA-j9hm-95rh-8hr5/GHSA-j9hm-95rh-8hr5.json @@ -7,12 +7,8 @@ "CVE-2011-1487" ], "details": "The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jc88-chvq-jj2r/GHSA-jc88-chvq-jj2r.json b/advisories/unreviewed/2022/05/GHSA-jc88-chvq-jj2r/GHSA-jc88-chvq-jj2r.json index 91711c895b1..0a3e38459f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc88-chvq-jj2r/GHSA-jc88-chvq-jj2r.json +++ b/advisories/unreviewed/2022/05/GHSA-jc88-chvq-jj2r/GHSA-jc88-chvq-jj2r.json @@ -7,12 +7,8 @@ "CVE-2011-0440" ], "details": "Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcpv-mpm6-gv57/GHSA-jcpv-mpm6-gv57.json b/advisories/unreviewed/2022/05/GHSA-jcpv-mpm6-gv57/GHSA-jcpv-mpm6-gv57.json index 9236504e77f..efc32e4fce8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcpv-mpm6-gv57/GHSA-jcpv-mpm6-gv57.json +++ b/advisories/unreviewed/2022/05/GHSA-jcpv-mpm6-gv57/GHSA-jcpv-mpm6-gv57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcw8-xvpg-r9ph/GHSA-jcw8-xvpg-r9ph.json b/advisories/unreviewed/2022/05/GHSA-jcw8-xvpg-r9ph/GHSA-jcw8-xvpg-r9ph.json index 6d811b9ce84..df1cb3ddc8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcw8-xvpg-r9ph/GHSA-jcw8-xvpg-r9ph.json +++ b/advisories/unreviewed/2022/05/GHSA-jcw8-xvpg-r9ph/GHSA-jcw8-xvpg-r9ph.json @@ -7,12 +7,8 @@ "CVE-2011-0652" ], "details": "lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 and 2.07 allows local users to cause a denial of service (crash) via a crafted 0x80000064 IOCTL request that triggers an assertion failure. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfh8-pcf9-hvrw/GHSA-jfh8-pcf9-hvrw.json b/advisories/unreviewed/2022/05/GHSA-jfh8-pcf9-hvrw/GHSA-jfh8-pcf9-hvrw.json index c5e50f05034..b252abd13b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfh8-pcf9-hvrw/GHSA-jfh8-pcf9-hvrw.json +++ b/advisories/unreviewed/2022/05/GHSA-jfh8-pcf9-hvrw/GHSA-jfh8-pcf9-hvrw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgm5-f5vx-vqj5/GHSA-jgm5-f5vx-vqj5.json b/advisories/unreviewed/2022/05/GHSA-jgm5-f5vx-vqj5/GHSA-jgm5-f5vx-vqj5.json index 2feffe5ea6f..c52807d0caf 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgm5-f5vx-vqj5/GHSA-jgm5-f5vx-vqj5.json +++ b/advisories/unreviewed/2022/05/GHSA-jgm5-f5vx-vqj5/GHSA-jgm5-f5vx-vqj5.json @@ -7,12 +7,8 @@ "CVE-2011-0961" ], "details": "Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the device parameter, aka Bug ID CSCto12704.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jh92-c236-hm8p/GHSA-jh92-c236-hm8p.json b/advisories/unreviewed/2022/05/GHSA-jh92-c236-hm8p/GHSA-jh92-c236-hm8p.json index cd3d37cb564..b323f825c71 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh92-c236-hm8p/GHSA-jh92-c236-hm8p.json +++ b/advisories/unreviewed/2022/05/GHSA-jh92-c236-hm8p/GHSA-jh92-c236-hm8p.json @@ -7,12 +7,8 @@ "CVE-2011-0718" ], "details": "Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jjp2-5wrp-96x7/GHSA-jjp2-5wrp-96x7.json b/advisories/unreviewed/2022/05/GHSA-jjp2-5wrp-96x7/GHSA-jjp2-5wrp-96x7.json index 2c67b0ddbda..0f374970cef 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjp2-5wrp-96x7/GHSA-jjp2-5wrp-96x7.json +++ b/advisories/unreviewed/2022/05/GHSA-jjp2-5wrp-96x7/GHSA-jjp2-5wrp-96x7.json @@ -7,12 +7,8 @@ "CVE-2011-1860" ], "details": "Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to capture HTTP session credentials via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmmf-pffx-66x4/GHSA-jmmf-pffx-66x4.json b/advisories/unreviewed/2022/05/GHSA-jmmf-pffx-66x4/GHSA-jmmf-pffx-66x4.json index 518a97c9de2..9b15802434a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmmf-pffx-66x4/GHSA-jmmf-pffx-66x4.json +++ b/advisories/unreviewed/2022/05/GHSA-jmmf-pffx-66x4/GHSA-jmmf-pffx-66x4.json @@ -7,12 +7,8 @@ "CVE-2011-1662" ], "details": "Cross-site scripting (XSS) vulnerability in Translation Management module 6.x before 6.x-1.21 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmp9-8jfr-9j94/GHSA-jmp9-8jfr-9j94.json b/advisories/unreviewed/2022/05/GHSA-jmp9-8jfr-9j94/GHSA-jmp9-8jfr-9j94.json index fee5f4b5af6..b688edbeced 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmp9-8jfr-9j94/GHSA-jmp9-8jfr-9j94.json +++ b/advisories/unreviewed/2022/05/GHSA-jmp9-8jfr-9j94/GHSA-jmp9-8jfr-9j94.json @@ -7,12 +7,8 @@ "CVE-2011-1472" ], "details": "The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpx6-hf99-37f7/GHSA-jpx6-hf99-37f7.json b/advisories/unreviewed/2022/05/GHSA-jpx6-hf99-37f7/GHSA-jpx6-hf99-37f7.json index 055b51527e5..f6cefff6ea8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpx6-hf99-37f7/GHSA-jpx6-hf99-37f7.json +++ b/advisories/unreviewed/2022/05/GHSA-jpx6-hf99-37f7/GHSA-jpx6-hf99-37f7.json @@ -7,12 +7,8 @@ "CVE-2011-1062" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sContext, (2) sort, (3) dir, and (4) show parameters in a save action to index.php; the (5) dir and (6) show parameters to print_list.php; and the (7) HTTP referer header to rss.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq66-67j4-wrrv/GHSA-jq66-67j4-wrrv.json b/advisories/unreviewed/2022/05/GHSA-jq66-67j4-wrrv/GHSA-jq66-67j4-wrrv.json index 8e8082df2ae..795968f69a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq66-67j4-wrrv/GHSA-jq66-67j4-wrrv.json +++ b/advisories/unreviewed/2022/05/GHSA-jq66-67j4-wrrv/GHSA-jq66-67j4-wrrv.json @@ -7,12 +7,8 @@ "CVE-2010-4791" ], "details": "SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqgm-p37c-mhv7/GHSA-jqgm-p37c-mhv7.json b/advisories/unreviewed/2022/05/GHSA-jqgm-p37c-mhv7/GHSA-jqgm-p37c-mhv7.json index 0ad4779e5af..736c0f246c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqgm-p37c-mhv7/GHSA-jqgm-p37c-mhv7.json +++ b/advisories/unreviewed/2022/05/GHSA-jqgm-p37c-mhv7/GHSA-jqgm-p37c-mhv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqh8-gj8c-rrrg/GHSA-jqh8-gj8c-rrrg.json b/advisories/unreviewed/2022/05/GHSA-jqh8-gj8c-rrrg/GHSA-jqh8-gj8c-rrrg.json index 52498ff81c5..3abb6c429e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqh8-gj8c-rrrg/GHSA-jqh8-gj8c-rrrg.json +++ b/advisories/unreviewed/2022/05/GHSA-jqh8-gj8c-rrrg/GHSA-jqh8-gj8c-rrrg.json @@ -7,12 +7,8 @@ "CVE-2011-1052" ], "details": "Integer overflow in the PSX/GEOS input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqmc-9xvm-35mh/GHSA-jqmc-9xvm-35mh.json b/advisories/unreviewed/2022/05/GHSA-jqmc-9xvm-35mh/GHSA-jqmc-9xvm-35mh.json index 2a21fed0b0e..8262c44f22f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqmc-9xvm-35mh/GHSA-jqmc-9xvm-35mh.json +++ b/advisories/unreviewed/2022/05/GHSA-jqmc-9xvm-35mh/GHSA-jqmc-9xvm-35mh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqx3-rv7j-m4gm/GHSA-jqx3-rv7j-m4gm.json b/advisories/unreviewed/2022/05/GHSA-jqx3-rv7j-m4gm/GHSA-jqx3-rv7j-m4gm.json index d58b8c7a226..35b9f2c713f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqx3-rv7j-m4gm/GHSA-jqx3-rv7j-m4gm.json +++ b/advisories/unreviewed/2022/05/GHSA-jqx3-rv7j-m4gm/GHSA-jqx3-rv7j-m4gm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrf2-626v-253x/GHSA-jrf2-626v-253x.json b/advisories/unreviewed/2022/05/GHSA-jrf2-626v-253x/GHSA-jrf2-626v-253x.json index cd87c8a767f..97898a004fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrf2-626v-253x/GHSA-jrf2-626v-253x.json +++ b/advisories/unreviewed/2022/05/GHSA-jrf2-626v-253x/GHSA-jrf2-626v-253x.json @@ -7,12 +7,8 @@ "CVE-2011-1861" ], "details": "Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to modify data or obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrf9-r4h8-9228/GHSA-jrf9-r4h8-9228.json b/advisories/unreviewed/2022/05/GHSA-jrf9-r4h8-9228/GHSA-jrf9-r4h8-9228.json index 5a59ba978f4..9ec46279919 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrf9-r4h8-9228/GHSA-jrf9-r4h8-9228.json +++ b/advisories/unreviewed/2022/05/GHSA-jrf9-r4h8-9228/GHSA-jrf9-r4h8-9228.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrm8-f68q-rfrc/GHSA-jrm8-f68q-rfrc.json b/advisories/unreviewed/2022/05/GHSA-jrm8-f68q-rfrc/GHSA-jrm8-f68q-rfrc.json index 972f8852820..2106ac76f94 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrm8-f68q-rfrc/GHSA-jrm8-f68q-rfrc.json +++ b/advisories/unreviewed/2022/05/GHSA-jrm8-f68q-rfrc/GHSA-jrm8-f68q-rfrc.json @@ -7,12 +7,8 @@ "CVE-2011-0290" ], "details": "The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv6m-3w7g-pv7c/GHSA-jv6m-3w7g-pv7c.json b/advisories/unreviewed/2022/05/GHSA-jv6m-3w7g-pv7c/GHSA-jv6m-3w7g-pv7c.json index 3ad5e9f2919..bb086aaf226 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv6m-3w7g-pv7c/GHSA-jv6m-3w7g-pv7c.json +++ b/advisories/unreviewed/2022/05/GHSA-jv6m-3w7g-pv7c/GHSA-jv6m-3w7g-pv7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvjf-pvc6-744q/GHSA-jvjf-pvc6-744q.json b/advisories/unreviewed/2022/05/GHSA-jvjf-pvc6-744q/GHSA-jvjf-pvc6-744q.json index c133af438bb..8961c8771ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvjf-pvc6-744q/GHSA-jvjf-pvc6-744q.json +++ b/advisories/unreviewed/2022/05/GHSA-jvjf-pvc6-744q/GHSA-jvjf-pvc6-744q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jw24-x846-m6wv/GHSA-jw24-x846-m6wv.json b/advisories/unreviewed/2022/05/GHSA-jw24-x846-m6wv/GHSA-jw24-x846-m6wv.json index 5c2327924b3..a68d0344bc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw24-x846-m6wv/GHSA-jw24-x846-m6wv.json +++ b/advisories/unreviewed/2022/05/GHSA-jw24-x846-m6wv/GHSA-jw24-x846-m6wv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jw33-q8g2-4wfm/GHSA-jw33-q8g2-4wfm.json b/advisories/unreviewed/2022/05/GHSA-jw33-q8g2-4wfm/GHSA-jw33-q8g2-4wfm.json index 260a2ca2e36..ec41a37b818 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw33-q8g2-4wfm/GHSA-jw33-q8g2-4wfm.json +++ b/advisories/unreviewed/2022/05/GHSA-jw33-q8g2-4wfm/GHSA-jw33-q8g2-4wfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jw74-vhrj-52qg/GHSA-jw74-vhrj-52qg.json b/advisories/unreviewed/2022/05/GHSA-jw74-vhrj-52qg/GHSA-jw74-vhrj-52qg.json index dea16b370ec..a387bef663a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw74-vhrj-52qg/GHSA-jw74-vhrj-52qg.json +++ b/advisories/unreviewed/2022/05/GHSA-jw74-vhrj-52qg/GHSA-jw74-vhrj-52qg.json @@ -7,12 +7,8 @@ "CVE-2010-4747" ], "details": "Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxqv-w47x-q5c9/GHSA-jxqv-w47x-q5c9.json b/advisories/unreviewed/2022/05/GHSA-jxqv-w47x-q5c9/GHSA-jxqv-w47x-q5c9.json index d6ac72beda5..54af51f95b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxqv-w47x-q5c9/GHSA-jxqv-w47x-q5c9.json +++ b/advisories/unreviewed/2022/05/GHSA-jxqv-w47x-q5c9/GHSA-jxqv-w47x-q5c9.json @@ -7,12 +7,8 @@ "CVE-2010-2933" ], "details": "SQL injection vulnerability in AV Scripts AV Arcade 3 allows remote attackers to execute arbitrary SQL commands via the ava_code cookie to the \"main page,\" related to index.php and the login task.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m22q-wr54-7hg4/GHSA-m22q-wr54-7hg4.json b/advisories/unreviewed/2022/05/GHSA-m22q-wr54-7hg4/GHSA-m22q-wr54-7hg4.json index 305edec3c21..f6dbd5a311f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m22q-wr54-7hg4/GHSA-m22q-wr54-7hg4.json +++ b/advisories/unreviewed/2022/05/GHSA-m22q-wr54-7hg4/GHSA-m22q-wr54-7hg4.json @@ -7,12 +7,8 @@ "CVE-2011-0377" ], "details": "Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malformed SOAP request in conjunction with a spoofed TelePresence Manager that supplies an invalid IP address, aka Bug ID CSCth03605.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2hm-m569-8xqm/GHSA-m2hm-m569-8xqm.json b/advisories/unreviewed/2022/05/GHSA-m2hm-m569-8xqm/GHSA-m2hm-m569-8xqm.json index b6914eebb46..81a4e69200e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2hm-m569-8xqm/GHSA-m2hm-m569-8xqm.json +++ b/advisories/unreviewed/2022/05/GHSA-m2hm-m569-8xqm/GHSA-m2hm-m569-8xqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2mj-228v-ghx2/GHSA-m2mj-228v-ghx2.json b/advisories/unreviewed/2022/05/GHSA-m2mj-228v-ghx2/GHSA-m2mj-228v-ghx2.json index 9cc89e298eb..8103be6b476 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2mj-228v-ghx2/GHSA-m2mj-228v-ghx2.json +++ b/advisories/unreviewed/2022/05/GHSA-m2mj-228v-ghx2/GHSA-m2mj-228v-ghx2.json @@ -7,12 +7,8 @@ "CVE-2011-0316" ], "details": "The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict access to console servlets, which allows remote attackers to obtain potentially sensitive status information via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3qg-wjgv-hpqm/GHSA-m3qg-wjgv-hpqm.json b/advisories/unreviewed/2022/05/GHSA-m3qg-wjgv-hpqm/GHSA-m3qg-wjgv-hpqm.json index ea25fe12d32..dd372d960fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3qg-wjgv-hpqm/GHSA-m3qg-wjgv-hpqm.json +++ b/advisories/unreviewed/2022/05/GHSA-m3qg-wjgv-hpqm/GHSA-m3qg-wjgv-hpqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m47h-p2v4-v383/GHSA-m47h-p2v4-v383.json b/advisories/unreviewed/2022/05/GHSA-m47h-p2v4-v383/GHSA-m47h-p2v4-v383.json index 36310591987..ec4c3f8958a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m47h-p2v4-v383/GHSA-m47h-p2v4-v383.json +++ b/advisories/unreviewed/2022/05/GHSA-m47h-p2v4-v383/GHSA-m47h-p2v4-v383.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m667-8qgh-87fr/GHSA-m667-8qgh-87fr.json b/advisories/unreviewed/2022/05/GHSA-m667-8qgh-87fr/GHSA-m667-8qgh-87fr.json index 6cfc3d3a7aa..4b156d582cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-m667-8qgh-87fr/GHSA-m667-8qgh-87fr.json +++ b/advisories/unreviewed/2022/05/GHSA-m667-8qgh-87fr/GHSA-m667-8qgh-87fr.json @@ -7,12 +7,8 @@ "CVE-2011-0527" ], "details": "VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during JMX authentication, which makes it easier for context-dependent attackers to obtain access by leveraging an ability to read stored passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7cc-4256-rx42/GHSA-m7cc-4256-rx42.json b/advisories/unreviewed/2022/05/GHSA-m7cc-4256-rx42/GHSA-m7cc-4256-rx42.json index 9561dee7b34..456ab29b554 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7cc-4256-rx42/GHSA-m7cc-4256-rx42.json +++ b/advisories/unreviewed/2022/05/GHSA-m7cc-4256-rx42/GHSA-m7cc-4256-rx42.json @@ -7,12 +7,8 @@ "CVE-2011-0581" ], "details": "Multiple CRLF injection vulnerabilities in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7vh-w5pc-9jxv/GHSA-m7vh-w5pc-9jxv.json b/advisories/unreviewed/2022/05/GHSA-m7vh-w5pc-9jxv/GHSA-m7vh-w5pc-9jxv.json index 25a29563edf..69b8867fbda 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7vh-w5pc-9jxv/GHSA-m7vh-w5pc-9jxv.json +++ b/advisories/unreviewed/2022/05/GHSA-m7vh-w5pc-9jxv/GHSA-m7vh-w5pc-9jxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8wf-mm8p-m4mr/GHSA-m8wf-mm8p-m4mr.json b/advisories/unreviewed/2022/05/GHSA-m8wf-mm8p-m4mr/GHSA-m8wf-mm8p-m4mr.json index e5d57b2eda4..cfe88c5b772 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8wf-mm8p-m4mr/GHSA-m8wf-mm8p-m4mr.json +++ b/advisories/unreviewed/2022/05/GHSA-m8wf-mm8p-m4mr/GHSA-m8wf-mm8p-m4mr.json @@ -7,12 +7,8 @@ "CVE-2011-1857" ], "details": "Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote authenticated users to bypass intended access restrictions via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9h2-f9w3-462f/GHSA-m9h2-f9w3-462f.json b/advisories/unreviewed/2022/05/GHSA-m9h2-f9w3-462f/GHSA-m9h2-f9w3-462f.json index b29047ed73d..bec1cf9ad89 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9h2-f9w3-462f/GHSA-m9h2-f9w3-462f.json +++ b/advisories/unreviewed/2022/05/GHSA-m9h2-f9w3-462f/GHSA-m9h2-f9w3-462f.json @@ -7,12 +7,8 @@ "CVE-2011-1560" ], "details": "solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which allows remote attackers to bypass authentication via a short length value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9qh-28m3-qw83/GHSA-m9qh-28m3-qw83.json b/advisories/unreviewed/2022/05/GHSA-m9qh-28m3-qw83/GHSA-m9qh-28m3-qw83.json index 08c4957164f..dba117af607 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9qh-28m3-qw83/GHSA-m9qh-28m3-qw83.json +++ b/advisories/unreviewed/2022/05/GHSA-m9qh-28m3-qw83/GHSA-m9qh-28m3-qw83.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9xq-xgvf-jw86/GHSA-m9xq-xgvf-jw86.json b/advisories/unreviewed/2022/05/GHSA-m9xq-xgvf-jw86/GHSA-m9xq-xgvf-jw86.json index 22d4b8e8eb8..a1b74d0fb14 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9xq-xgvf-jw86/GHSA-m9xq-xgvf-jw86.json +++ b/advisories/unreviewed/2022/05/GHSA-m9xq-xgvf-jw86/GHSA-m9xq-xgvf-jw86.json @@ -7,12 +7,8 @@ "CVE-2011-0517" ], "details": "Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted 0x02 opcode to TCP port 46823.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfx4-mv99-gv77/GHSA-mfx4-mv99-gv77.json b/advisories/unreviewed/2022/05/GHSA-mfx4-mv99-gv77/GHSA-mfx4-mv99-gv77.json index 921ede48f02..56911c38295 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfx4-mv99-gv77/GHSA-mfx4-mv99-gv77.json +++ b/advisories/unreviewed/2022/05/GHSA-mfx4-mv99-gv77/GHSA-mfx4-mv99-gv77.json @@ -7,12 +7,8 @@ "CVE-2011-1035" ], "details": "The password reset in PivotX before 2.2.4 allows remote attackers to modify the passwords of arbitrary users via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mg67-hq97-f99j/GHSA-mg67-hq97-f99j.json b/advisories/unreviewed/2022/05/GHSA-mg67-hq97-f99j/GHSA-mg67-hq97-f99j.json index d6dc6f188ce..8ffcea1a23c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg67-hq97-f99j/GHSA-mg67-hq97-f99j.json +++ b/advisories/unreviewed/2022/05/GHSA-mg67-hq97-f99j/GHSA-mg67-hq97-f99j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgrr-7c88-34fm/GHSA-mgrr-7c88-34fm.json b/advisories/unreviewed/2022/05/GHSA-mgrr-7c88-34fm/GHSA-mgrr-7c88-34fm.json index 2a48fb4ee70..81fdf7d1ed7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgrr-7c88-34fm/GHSA-mgrr-7c88-34fm.json +++ b/advisories/unreviewed/2022/05/GHSA-mgrr-7c88-34fm/GHSA-mgrr-7c88-34fm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhgj-vvw3-qmgq/GHSA-mhgj-vvw3-qmgq.json b/advisories/unreviewed/2022/05/GHSA-mhgj-vvw3-qmgq/GHSA-mhgj-vvw3-qmgq.json index 8524fc64574..5c0683c4b4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhgj-vvw3-qmgq/GHSA-mhgj-vvw3-qmgq.json +++ b/advisories/unreviewed/2022/05/GHSA-mhgj-vvw3-qmgq/GHSA-mhgj-vvw3-qmgq.json @@ -7,12 +7,8 @@ "CVE-2011-1042" ], "details": "Use-after-free vulnerability in flimflamd in flimflam in Google Chrome OS before 0.9.130.14 Beta allows user-assisted remote attackers to cause a denial of service (daemon crash) by providing the name of a hidden WiFi network that does not respond to connection attempts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhwr-wcrg-9jjg/GHSA-mhwr-wcrg-9jjg.json b/advisories/unreviewed/2022/05/GHSA-mhwr-wcrg-9jjg/GHSA-mhwr-wcrg-9jjg.json index 8dace43b9c3..ee58839ffa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhwr-wcrg-9jjg/GHSA-mhwr-wcrg-9jjg.json +++ b/advisories/unreviewed/2022/05/GHSA-mhwr-wcrg-9jjg/GHSA-mhwr-wcrg-9jjg.json @@ -7,12 +7,8 @@ "CVE-2011-0315" ], "details": "Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mm2m-8vf5-7472/GHSA-mm2m-8vf5-7472.json b/advisories/unreviewed/2022/05/GHSA-mm2m-8vf5-7472/GHSA-mm2m-8vf5-7472.json index 6de3ec6fc33..700e37b1d6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm2m-8vf5-7472/GHSA-mm2m-8vf5-7472.json +++ b/advisories/unreviewed/2022/05/GHSA-mm2m-8vf5-7472/GHSA-mm2m-8vf5-7472.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp6m-j6gx-x6p6/GHSA-mp6m-j6gx-x6p6.json b/advisories/unreviewed/2022/05/GHSA-mp6m-j6gx-x6p6/GHSA-mp6m-j6gx-x6p6.json index 35e29af3122..90c7ffe1168 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp6m-j6gx-x6p6/GHSA-mp6m-j6gx-x6p6.json +++ b/advisories/unreviewed/2022/05/GHSA-mp6m-j6gx-x6p6/GHSA-mp6m-j6gx-x6p6.json @@ -7,12 +7,8 @@ "CVE-2010-3211" ], "details": "Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via category categorylist operations with (1) the catid parameter or (2) the catid parameter in a lists action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvjv-gchx-qg75/GHSA-mvjv-gchx-qg75.json b/advisories/unreviewed/2022/05/GHSA-mvjv-gchx-qg75/GHSA-mvjv-gchx-qg75.json index c35b9848151..45ac4cf8b4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvjv-gchx-qg75/GHSA-mvjv-gchx-qg75.json +++ b/advisories/unreviewed/2022/05/GHSA-mvjv-gchx-qg75/GHSA-mvjv-gchx-qg75.json @@ -7,12 +7,8 @@ "CVE-2010-3213" ], "details": "Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwvc-fhmm-47cq/GHSA-mwvc-fhmm-47cq.json b/advisories/unreviewed/2022/05/GHSA-mwvc-fhmm-47cq/GHSA-mwvc-fhmm-47cq.json index b0c83bc9da8..74edd3f47bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwvc-fhmm-47cq/GHSA-mwvc-fhmm-47cq.json +++ b/advisories/unreviewed/2022/05/GHSA-mwvc-fhmm-47cq/GHSA-mwvc-fhmm-47cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx2c-rq9j-c2gx/GHSA-mx2c-rq9j-c2gx.json b/advisories/unreviewed/2022/05/GHSA-mx2c-rq9j-c2gx/GHSA-mx2c-rq9j-c2gx.json index aade8f42a51..f48e177debf 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx2c-rq9j-c2gx/GHSA-mx2c-rq9j-c2gx.json +++ b/advisories/unreviewed/2022/05/GHSA-mx2c-rq9j-c2gx/GHSA-mx2c-rq9j-c2gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2q6-4rhc-9fhc/GHSA-p2q6-4rhc-9fhc.json b/advisories/unreviewed/2022/05/GHSA-p2q6-4rhc-9fhc/GHSA-p2q6-4rhc-9fhc.json index 8316f146979..e953efa8566 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2q6-4rhc-9fhc/GHSA-p2q6-4rhc-9fhc.json +++ b/advisories/unreviewed/2022/05/GHSA-p2q6-4rhc-9fhc/GHSA-p2q6-4rhc-9fhc.json @@ -7,12 +7,8 @@ "CVE-2011-1153" ], "details": "Multiple format string vulnerabilities in phar_object.c in the phar extension in PHP 5.3.5 and earlier allow context-dependent attackers to obtain sensitive information from process memory, cause a denial of service (memory corruption), or possibly execute arbitrary code via format string specifiers in an argument to a class method, leading to an incorrect zend_throw_exception_ex call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p39j-f99x-4xhj/GHSA-p39j-f99x-4xhj.json b/advisories/unreviewed/2022/05/GHSA-p39j-f99x-4xhj/GHSA-p39j-f99x-4xhj.json index c879a1b69cd..0ca63bcb4a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p39j-f99x-4xhj/GHSA-p39j-f99x-4xhj.json +++ b/advisories/unreviewed/2022/05/GHSA-p39j-f99x-4xhj/GHSA-p39j-f99x-4xhj.json @@ -7,12 +7,8 @@ "CVE-2011-0582" ], "details": "Unspecified vulnerability in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allows attackers to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p473-99rc-hf3w/GHSA-p473-99rc-hf3w.json b/advisories/unreviewed/2022/05/GHSA-p473-99rc-hf3w/GHSA-p473-99rc-hf3w.json index 5d9562a3cbb..c5aec3ae2f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p473-99rc-hf3w/GHSA-p473-99rc-hf3w.json +++ b/advisories/unreviewed/2022/05/GHSA-p473-99rc-hf3w/GHSA-p473-99rc-hf3w.json @@ -7,12 +7,8 @@ "CVE-2010-3209" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to execute arbitrary PHP code via a URL in the includeFile parameter to (1) Config/Container.php and (2) HTML/QuickForm.php in fog/lib/pear/, the (3) driverpath parameter to fog/lib/pear/DB/NestedSet.php, and the (4) path parameter to fog/lib/pear/DB/NestedSet/Output.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p58j-654q-6xvh/GHSA-p58j-654q-6xvh.json b/advisories/unreviewed/2022/05/GHSA-p58j-654q-6xvh/GHSA-p58j-654q-6xvh.json index 0228805fd0e..84f99d54af3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p58j-654q-6xvh/GHSA-p58j-654q-6xvh.json +++ b/advisories/unreviewed/2022/05/GHSA-p58j-654q-6xvh/GHSA-p58j-654q-6xvh.json @@ -7,12 +7,8 @@ "CVE-2011-1828" ], "details": "usb-creator-helper in usb-creator before 0.2.28.3 does not enforce intended PolicyKit restrictions, which allows local users to perform arbitrary unmount operations via the UnmountFile method in a dbus-send command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p58w-8546-2xhw/GHSA-p58w-8546-2xhw.json b/advisories/unreviewed/2022/05/GHSA-p58w-8546-2xhw/GHSA-p58w-8546-2xhw.json index 884c1debc59..852f4b09ed8 100644 --- a/advisories/unreviewed/2022/05/GHSA-p58w-8546-2xhw/GHSA-p58w-8546-2xhw.json +++ b/advisories/unreviewed/2022/05/GHSA-p58w-8546-2xhw/GHSA-p58w-8546-2xhw.json @@ -7,12 +7,8 @@ "CVE-2010-4798" ], "details": "Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uri parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5jh-65m7-7pfg/GHSA-p5jh-65m7-7pfg.json b/advisories/unreviewed/2022/05/GHSA-p5jh-65m7-7pfg/GHSA-p5jh-65m7-7pfg.json index 4dbf6a41325..c24bd2b9eed 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5jh-65m7-7pfg/GHSA-p5jh-65m7-7pfg.json +++ b/advisories/unreviewed/2022/05/GHSA-p5jh-65m7-7pfg/GHSA-p5jh-65m7-7pfg.json @@ -7,12 +7,8 @@ "CVE-2011-1432" ], "details": "The STARTTLS implementation in SCO SCOoffice Server does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a \"plaintext command injection\" attack, a similar issue to CVE-2011-0411.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p72p-3m8j-v5mg/GHSA-p72p-3m8j-v5mg.json b/advisories/unreviewed/2022/05/GHSA-p72p-3m8j-v5mg/GHSA-p72p-3m8j-v5mg.json index 88fd06e24f8..973f348863e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p72p-3m8j-v5mg/GHSA-p72p-3m8j-v5mg.json +++ b/advisories/unreviewed/2022/05/GHSA-p72p-3m8j-v5mg/GHSA-p72p-3m8j-v5mg.json @@ -7,12 +7,8 @@ "CVE-2011-1500" ], "details": "PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user's home directory, which allows local users to obtain Pandora credentials by reading this file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p7w4-2fhg-mqv6/GHSA-p7w4-2fhg-mqv6.json b/advisories/unreviewed/2022/05/GHSA-p7w4-2fhg-mqv6/GHSA-p7w4-2fhg-mqv6.json index 991c29d58fb..09ab071550d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7w4-2fhg-mqv6/GHSA-p7w4-2fhg-mqv6.json +++ b/advisories/unreviewed/2022/05/GHSA-p7w4-2fhg-mqv6/GHSA-p7w4-2fhg-mqv6.json @@ -7,12 +7,8 @@ "CVE-2011-1754" ], "details": "jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p93p-h47j-hj8j/GHSA-p93p-h47j-hj8j.json b/advisories/unreviewed/2022/05/GHSA-p93p-h47j-hj8j/GHSA-p93p-h47j-hj8j.json index 73998143d44..f8db8b1e57d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p93p-h47j-hj8j/GHSA-p93p-h47j-hj8j.json +++ b/advisories/unreviewed/2022/05/GHSA-p93p-h47j-hj8j/GHSA-p93p-h47j-hj8j.json @@ -7,12 +7,8 @@ "CVE-2011-1859" ], "details": "Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p95c-7vrm-5qhj/GHSA-p95c-7vrm-5qhj.json b/advisories/unreviewed/2022/05/GHSA-p95c-7vrm-5qhj/GHSA-p95c-7vrm-5qhj.json index 8f407d428da..48d221c95be 100644 --- a/advisories/unreviewed/2022/05/GHSA-p95c-7vrm-5qhj/GHSA-p95c-7vrm-5qhj.json +++ b/advisories/unreviewed/2022/05/GHSA-p95c-7vrm-5qhj/GHSA-p95c-7vrm-5qhj.json @@ -7,12 +7,8 @@ "CVE-2011-1605" ], "details": "Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su2, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCth39586.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pc23-m78g-gxhh/GHSA-pc23-m78g-gxhh.json b/advisories/unreviewed/2022/05/GHSA-pc23-m78g-gxhh/GHSA-pc23-m78g-gxhh.json index f7634cdd4d5..081c689fc5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc23-m78g-gxhh/GHSA-pc23-m78g-gxhh.json +++ b/advisories/unreviewed/2022/05/GHSA-pc23-m78g-gxhh/GHSA-pc23-m78g-gxhh.json @@ -7,12 +7,8 @@ "CVE-2011-0738" ], "details": "MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a) myproxy-logon or (b) myproxy-get-delegation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf64-xgj7-56fc/GHSA-pf64-xgj7-56fc.json b/advisories/unreviewed/2022/05/GHSA-pf64-xgj7-56fc/GHSA-pf64-xgj7-56fc.json index 4f24af65db1..413380f79cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf64-xgj7-56fc/GHSA-pf64-xgj7-56fc.json +++ b/advisories/unreviewed/2022/05/GHSA-pf64-xgj7-56fc/GHSA-pf64-xgj7-56fc.json @@ -7,12 +7,8 @@ "CVE-2011-1672" ], "details": "The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2) sysprep.inf file, as demonstrated by reading a password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfrv-7vc2-g369/GHSA-pfrv-7vc2-g369.json b/advisories/unreviewed/2022/05/GHSA-pfrv-7vc2-g369/GHSA-pfrv-7vc2-g369.json index ed368cd1f23..a3d47356a89 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfrv-7vc2-g369/GHSA-pfrv-7vc2-g369.json +++ b/advisories/unreviewed/2022/05/GHSA-pfrv-7vc2-g369/GHSA-pfrv-7vc2-g369.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgrj-3jmg-f2wq/GHSA-pgrj-3jmg-f2wq.json b/advisories/unreviewed/2022/05/GHSA-pgrj-3jmg-f2wq/GHSA-pgrj-3jmg-f2wq.json index 86d7d2893d5..255e66371ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgrj-3jmg-f2wq/GHSA-pgrj-3jmg-f2wq.json +++ b/advisories/unreviewed/2022/05/GHSA-pgrj-3jmg-f2wq/GHSA-pgrj-3jmg-f2wq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ph56-qx6x-j8xv/GHSA-ph56-qx6x-j8xv.json b/advisories/unreviewed/2022/05/GHSA-ph56-qx6x-j8xv/GHSA-ph56-qx6x-j8xv.json index 4d6e5142dbe..02c9c1fec76 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph56-qx6x-j8xv/GHSA-ph56-qx6x-j8xv.json +++ b/advisories/unreviewed/2022/05/GHSA-ph56-qx6x-j8xv/GHSA-ph56-qx6x-j8xv.json @@ -7,12 +7,8 @@ "CVE-2011-1496" ], "details": "tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ph6h-8gxh-chp4/GHSA-ph6h-8gxh-chp4.json b/advisories/unreviewed/2022/05/GHSA-ph6h-8gxh-chp4/GHSA-ph6h-8gxh-chp4.json index 0a8e8e0164a..53da0391c60 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph6h-8gxh-chp4/GHSA-ph6h-8gxh-chp4.json +++ b/advisories/unreviewed/2022/05/GHSA-ph6h-8gxh-chp4/GHSA-ph6h-8gxh-chp4.json @@ -7,12 +7,8 @@ "CVE-2011-1065" ], "details": "Multiple stack-based buffer overflows in the PIPIWebPlayer ActiveX control (PIWebPlayer.ocx) in PIPI Player 2.8.0.0 allow remote attackers to execute arbitrary code via long arguments to the (1) PlayURL or (2) PlayURLWithLocalPlayer methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phwc-6r39-22r4/GHSA-phwc-6r39-22r4.json b/advisories/unreviewed/2022/05/GHSA-phwc-6r39-22r4/GHSA-phwc-6r39-22r4.json index dee7f1377dd..10482d4487b 100644 --- a/advisories/unreviewed/2022/05/GHSA-phwc-6r39-22r4/GHSA-phwc-6r39-22r4.json +++ b/advisories/unreviewed/2022/05/GHSA-phwc-6r39-22r4/GHSA-phwc-6r39-22r4.json @@ -7,12 +7,8 @@ "CVE-2011-1337" ], "details": "Opera before 11.50 allows remote attackers to cause a denial of service (disk consumption) via invalid URLs that trigger creation of error pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-phx8-gf7f-9rqw/GHSA-phx8-gf7f-9rqw.json b/advisories/unreviewed/2022/05/GHSA-phx8-gf7f-9rqw/GHSA-phx8-gf7f-9rqw.json index bc9773aa8e2..1a1ec25b4ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-phx8-gf7f-9rqw/GHSA-phx8-gf7f-9rqw.json +++ b/advisories/unreviewed/2022/05/GHSA-phx8-gf7f-9rqw/GHSA-phx8-gf7f-9rqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjc2-fghh-wx28/GHSA-pjc2-fghh-wx28.json b/advisories/unreviewed/2022/05/GHSA-pjc2-fghh-wx28/GHSA-pjc2-fghh-wx28.json index 25b59bf0bda..e3b8d62a05b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjc2-fghh-wx28/GHSA-pjc2-fghh-wx28.json +++ b/advisories/unreviewed/2022/05/GHSA-pjc2-fghh-wx28/GHSA-pjc2-fghh-wx28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjch-5rqh-cgmm/GHSA-pjch-5rqh-cgmm.json b/advisories/unreviewed/2022/05/GHSA-pjch-5rqh-cgmm/GHSA-pjch-5rqh-cgmm.json index 21771f8be82..fda2025fa99 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjch-5rqh-cgmm/GHSA-pjch-5rqh-cgmm.json +++ b/advisories/unreviewed/2022/05/GHSA-pjch-5rqh-cgmm/GHSA-pjch-5rqh-cgmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm29-7x5p-c328/GHSA-pm29-7x5p-c328.json b/advisories/unreviewed/2022/05/GHSA-pm29-7x5p-c328/GHSA-pm29-7x5p-c328.json index 111d8f99508..e224c91eb0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm29-7x5p-c328/GHSA-pm29-7x5p-c328.json +++ b/advisories/unreviewed/2022/05/GHSA-pm29-7x5p-c328/GHSA-pm29-7x5p-c328.json @@ -7,12 +7,8 @@ "CVE-2011-1725" ], "details": "Unspecified vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to obtain sensitive information via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pmr5-7wxg-jgcx/GHSA-pmr5-7wxg-jgcx.json b/advisories/unreviewed/2022/05/GHSA-pmr5-7wxg-jgcx/GHSA-pmr5-7wxg-jgcx.json index 5c6f539b688..6f81c438032 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmr5-7wxg-jgcx/GHSA-pmr5-7wxg-jgcx.json +++ b/advisories/unreviewed/2022/05/GHSA-pmr5-7wxg-jgcx/GHSA-pmr5-7wxg-jgcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppp2-xhm6-jw52/GHSA-ppp2-xhm6-jw52.json b/advisories/unreviewed/2022/05/GHSA-ppp2-xhm6-jw52/GHSA-ppp2-xhm6-jw52.json index 085821df8fb..10691a3b6ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppp2-xhm6-jw52/GHSA-ppp2-xhm6-jw52.json +++ b/advisories/unreviewed/2022/05/GHSA-ppp2-xhm6-jw52/GHSA-ppp2-xhm6-jw52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppwq-8qp3-j45p/GHSA-ppwq-8qp3-j45p.json b/advisories/unreviewed/2022/05/GHSA-ppwq-8qp3-j45p/GHSA-ppwq-8qp3-j45p.json index e7580db5893..b1d9b92f4cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppwq-8qp3-j45p/GHSA-ppwq-8qp3-j45p.json +++ b/advisories/unreviewed/2022/05/GHSA-ppwq-8qp3-j45p/GHSA-ppwq-8qp3-j45p.json @@ -7,12 +7,8 @@ "CVE-2011-0489" ], "details": "The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data, obtain sensitive information, or cause a denial of service by sending requests over TCP to (1) the Lock Server or (2) the Advanced Multithreaded Server, as demonstrated by commands that are ordinarily sent by the (a) ookillls and (b) oostopams applications. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pq46-h8gg-4pjh/GHSA-pq46-h8gg-4pjh.json b/advisories/unreviewed/2022/05/GHSA-pq46-h8gg-4pjh/GHSA-pq46-h8gg-4pjh.json index 2502f49604a..693fcc03c7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq46-h8gg-4pjh/GHSA-pq46-h8gg-4pjh.json +++ b/advisories/unreviewed/2022/05/GHSA-pq46-h8gg-4pjh/GHSA-pq46-h8gg-4pjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqcm-92mq-2rgw/GHSA-pqcm-92mq-2rgw.json b/advisories/unreviewed/2022/05/GHSA-pqcm-92mq-2rgw/GHSA-pqcm-92mq-2rgw.json index a5f2eeb333a..fdca8a979ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqcm-92mq-2rgw/GHSA-pqcm-92mq-2rgw.json +++ b/advisories/unreviewed/2022/05/GHSA-pqcm-92mq-2rgw/GHSA-pqcm-92mq-2rgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw8c-3x98-r358/GHSA-pw8c-3x98-r358.json b/advisories/unreviewed/2022/05/GHSA-pw8c-3x98-r358/GHSA-pw8c-3x98-r358.json index 30e3bb1aa36..b3ba4de5460 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw8c-3x98-r358/GHSA-pw8c-3x98-r358.json +++ b/advisories/unreviewed/2022/05/GHSA-pw8c-3x98-r358/GHSA-pw8c-3x98-r358.json @@ -7,12 +7,8 @@ "CVE-2011-0532" ], "details": "The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x) place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pwfc-xvgf-hcc3/GHSA-pwfc-xvgf-hcc3.json b/advisories/unreviewed/2022/05/GHSA-pwfc-xvgf-hcc3/GHSA-pwfc-xvgf-hcc3.json index 9b8acb44efe..552352cd692 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwfc-xvgf-hcc3/GHSA-pwfc-xvgf-hcc3.json +++ b/advisories/unreviewed/2022/05/GHSA-pwfc-xvgf-hcc3/GHSA-pwfc-xvgf-hcc3.json @@ -7,12 +7,8 @@ "CVE-2010-4775" ], "details": "The Relevant Content module 5.x before 5.x-1.4 and 6.x before 6.x-1.5 for Drupal does not properly implement node access logic, which allows remote attackers to discover restricted node titles and relationships.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q489-g4m3-rrv2/GHSA-q489-g4m3-rrv2.json b/advisories/unreviewed/2022/05/GHSA-q489-g4m3-rrv2/GHSA-q489-g4m3-rrv2.json index faee1fa1fdc..1f42fb6bce1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q489-g4m3-rrv2/GHSA-q489-g4m3-rrv2.json +++ b/advisories/unreviewed/2022/05/GHSA-q489-g4m3-rrv2/GHSA-q489-g4m3-rrv2.json @@ -7,12 +7,8 @@ "CVE-2011-0646" ], "details": "SQL injection vulnerability in viewfaqs.php in PHP LOW BIDS allows remote attackers to execute arbitrary SQL commands via the cat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q48f-fp8r-4r2c/GHSA-q48f-fp8r-4r2c.json b/advisories/unreviewed/2022/05/GHSA-q48f-fp8r-4r2c/GHSA-q48f-fp8r-4r2c.json index 3670f8a6ab5..da4dcb0fbc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q48f-fp8r-4r2c/GHSA-q48f-fp8r-4r2c.json +++ b/advisories/unreviewed/2022/05/GHSA-q48f-fp8r-4r2c/GHSA-q48f-fp8r-4r2c.json @@ -7,12 +7,8 @@ "CVE-2011-0890" ], "details": "HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive information or have unspecified other impact by leveraging the public read community.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q528-gc65-6mp4/GHSA-q528-gc65-6mp4.json b/advisories/unreviewed/2022/05/GHSA-q528-gc65-6mp4/GHSA-q528-gc65-6mp4.json index 133fc283e6a..e9dedbad52a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q528-gc65-6mp4/GHSA-q528-gc65-6mp4.json +++ b/advisories/unreviewed/2022/05/GHSA-q528-gc65-6mp4/GHSA-q528-gc65-6mp4.json @@ -7,12 +7,8 @@ "CVE-2011-0291" ], "details": "The BlackBerry PlayBook service on the Research In Motion (RIM) BlackBerry PlayBook tablet with software before 1.0.8.6067 allows local users to gain privileges via a crafted configuration file in a backup archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5cv-2mrg-wvw2/GHSA-q5cv-2mrg-wvw2.json b/advisories/unreviewed/2022/05/GHSA-q5cv-2mrg-wvw2/GHSA-q5cv-2mrg-wvw2.json index 5ab77fa108d..2c3de766579 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5cv-2mrg-wvw2/GHSA-q5cv-2mrg-wvw2.json +++ b/advisories/unreviewed/2022/05/GHSA-q5cv-2mrg-wvw2/GHSA-q5cv-2mrg-wvw2.json @@ -7,12 +7,8 @@ "CVE-2010-4694" ], "details": "Buffer overflow in gif2png.c in gif2png 2.5.3 and earlier might allow context-dependent attackers to cause a denial of service (application crash) or have unspecified other impact via a GIF file that contains many images, leading to long extensions such as .p100 for PNG output files, as demonstrated by a CGI program that launches gif2png, a different vulnerability than CVE-2009-5018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q635-879v-fwvp/GHSA-q635-879v-fwvp.json b/advisories/unreviewed/2022/05/GHSA-q635-879v-fwvp/GHSA-q635-879v-fwvp.json index 1e8c45891d4..f652477f2f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-q635-879v-fwvp/GHSA-q635-879v-fwvp.json +++ b/advisories/unreviewed/2022/05/GHSA-q635-879v-fwvp/GHSA-q635-879v-fwvp.json @@ -7,12 +7,8 @@ "CVE-2011-0760" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration screen in wp-relatedposts.php in the WP Related Posts plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the (1) wp_relatedposts_title, (2) wp_relatedposts_num, or (3) wp_relatedposts_type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q69f-3429-57w3/GHSA-q69f-3429-57w3.json b/advisories/unreviewed/2022/05/GHSA-q69f-3429-57w3/GHSA-q69f-3429-57w3.json index f98aa0f998c..1f035c733ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-q69f-3429-57w3/GHSA-q69f-3429-57w3.json +++ b/advisories/unreviewed/2022/05/GHSA-q69f-3429-57w3/GHSA-q69f-3429-57w3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q87h-pwgw-6qgc/GHSA-q87h-pwgw-6qgc.json b/advisories/unreviewed/2022/05/GHSA-q87h-pwgw-6qgc/GHSA-q87h-pwgw-6qgc.json index 1fec74a958a..5268aa5dcef 100644 --- a/advisories/unreviewed/2022/05/GHSA-q87h-pwgw-6qgc/GHSA-q87h-pwgw-6qgc.json +++ b/advisories/unreviewed/2022/05/GHSA-q87h-pwgw-6qgc/GHSA-q87h-pwgw-6qgc.json @@ -7,12 +7,8 @@ "CVE-2011-0264" ], "details": "Stack-based buffer overflow in ovutil.dll in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long COOKIE variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q937-2q57-mgxf/GHSA-q937-2q57-mgxf.json b/advisories/unreviewed/2022/05/GHSA-q937-2q57-mgxf/GHSA-q937-2q57-mgxf.json index c7b374b25cc..130a0738aef 100644 --- a/advisories/unreviewed/2022/05/GHSA-q937-2q57-mgxf/GHSA-q937-2q57-mgxf.json +++ b/advisories/unreviewed/2022/05/GHSA-q937-2q57-mgxf/GHSA-q937-2q57-mgxf.json @@ -7,12 +7,8 @@ "CVE-2011-1367" ], "details": "Unspecified vulnerability in the File Load feature in IBM Rational AppScan Standard and Express 7.8.x, 7.9.x, and 8.0.x before 8.0.0.3 allows remote attackers to execute arbitrary commands via a crafted .scan file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9h6-jm9r-6x4w/GHSA-q9h6-jm9r-6x4w.json b/advisories/unreviewed/2022/05/GHSA-q9h6-jm9r-6x4w/GHSA-q9h6-jm9r-6x4w.json index d52775211aa..381d98e0736 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9h6-jm9r-6x4w/GHSA-q9h6-jm9r-6x4w.json +++ b/advisories/unreviewed/2022/05/GHSA-q9h6-jm9r-6x4w/GHSA-q9h6-jm9r-6x4w.json @@ -7,12 +7,8 @@ "CVE-2011-0435" ], "details": "Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth information via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgv6-745c-pw4v/GHSA-qgv6-745c-pw4v.json b/advisories/unreviewed/2022/05/GHSA-qgv6-745c-pw4v/GHSA-qgv6-745c-pw4v.json index 5288a7c6c65..d1440d9e2c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgv6-745c-pw4v/GHSA-qgv6-745c-pw4v.json +++ b/advisories/unreviewed/2022/05/GHSA-qgv6-745c-pw4v/GHSA-qgv6-745c-pw4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgxf-389p-456g/GHSA-qgxf-389p-456g.json b/advisories/unreviewed/2022/05/GHSA-qgxf-389p-456g/GHSA-qgxf-389p-456g.json index 0a714445d53..ac29233af00 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgxf-389p-456g/GHSA-qgxf-389p-456g.json +++ b/advisories/unreviewed/2022/05/GHSA-qgxf-389p-456g/GHSA-qgxf-389p-456g.json @@ -7,12 +7,8 @@ "CVE-2010-4413" ], "details": "Unspecified vulnerability in the Scheduler Agent component in Oracle Database Server 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qj33-3pm8-2r4w/GHSA-qj33-3pm8-2r4w.json b/advisories/unreviewed/2022/05/GHSA-qj33-3pm8-2r4w/GHSA-qj33-3pm8-2r4w.json index fbb7165852e..ea4697a5b00 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj33-3pm8-2r4w/GHSA-qj33-3pm8-2r4w.json +++ b/advisories/unreviewed/2022/05/GHSA-qj33-3pm8-2r4w/GHSA-qj33-3pm8-2r4w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qj78-2g8g-r26x/GHSA-qj78-2g8g-r26x.json b/advisories/unreviewed/2022/05/GHSA-qj78-2g8g-r26x/GHSA-qj78-2g8g-r26x.json index fb26178744a..a12754bcf6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj78-2g8g-r26x/GHSA-qj78-2g8g-r26x.json +++ b/advisories/unreviewed/2022/05/GHSA-qj78-2g8g-r26x/GHSA-qj78-2g8g-r26x.json @@ -7,12 +7,8 @@ "CVE-2011-1106" ], "details": "Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjcq-qr88-rmx8/GHSA-qjcq-qr88-rmx8.json b/advisories/unreviewed/2022/05/GHSA-qjcq-qr88-rmx8/GHSA-qjcq-qr88-rmx8.json index fb7b723d31d..c51b24b7714 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjcq-qr88-rmx8/GHSA-qjcq-qr88-rmx8.json +++ b/advisories/unreviewed/2022/05/GHSA-qjcq-qr88-rmx8/GHSA-qjcq-qr88-rmx8.json @@ -7,12 +7,8 @@ "CVE-2011-1532" ], "details": "Unspecified vulnerability in the SNMP component on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to obtain sensitive information or modify data via vectors related to the Embedded Web Server (EWS).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qm7q-x8gp-f7m8/GHSA-qm7q-x8gp-f7m8.json b/advisories/unreviewed/2022/05/GHSA-qm7q-x8gp-f7m8/GHSA-qm7q-x8gp-f7m8.json index c017d9b58d5..2af88e6c475 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm7q-x8gp-f7m8/GHSA-qm7q-x8gp-f7m8.json +++ b/advisories/unreviewed/2022/05/GHSA-qm7q-x8gp-f7m8/GHSA-qm7q-x8gp-f7m8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmxw-7v53-gvv4/GHSA-qmxw-7v53-gvv4.json b/advisories/unreviewed/2022/05/GHSA-qmxw-7v53-gvv4/GHSA-qmxw-7v53-gvv4.json index d13fa0d42cc..e3102072a4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmxw-7v53-gvv4/GHSA-qmxw-7v53-gvv4.json +++ b/advisories/unreviewed/2022/05/GHSA-qmxw-7v53-gvv4/GHSA-qmxw-7v53-gvv4.json @@ -7,12 +7,8 @@ "CVE-2010-4800" ], "details": "SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpgx-58jc-jwvw/GHSA-qpgx-58jc-jwvw.json b/advisories/unreviewed/2022/05/GHSA-qpgx-58jc-jwvw/GHSA-qpgx-58jc-jwvw.json index 420fefd0f57..a08d0d8ee0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpgx-58jc-jwvw/GHSA-qpgx-58jc-jwvw.json +++ b/advisories/unreviewed/2022/05/GHSA-qpgx-58jc-jwvw/GHSA-qpgx-58jc-jwvw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qq27-pp42-p3c7/GHSA-qq27-pp42-p3c7.json b/advisories/unreviewed/2022/05/GHSA-qq27-pp42-p3c7/GHSA-qq27-pp42-p3c7.json index c663c34c87d..85ac8fa34d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq27-pp42-p3c7/GHSA-qq27-pp42-p3c7.json +++ b/advisories/unreviewed/2022/05/GHSA-qq27-pp42-p3c7/GHSA-qq27-pp42-p3c7.json @@ -7,12 +7,8 @@ "CVE-2011-1740" ], "details": "EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about product activities by leveraging privileged access to a different domain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqfr-pqgv-jcc6/GHSA-qqfr-pqgv-jcc6.json b/advisories/unreviewed/2022/05/GHSA-qqfr-pqgv-jcc6/GHSA-qqfr-pqgv-jcc6.json index 4331027f399..bc12c4b33c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqfr-pqgv-jcc6/GHSA-qqfr-pqgv-jcc6.json +++ b/advisories/unreviewed/2022/05/GHSA-qqfr-pqgv-jcc6/GHSA-qqfr-pqgv-jcc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqp3-5fc5-8mf5/GHSA-qqp3-5fc5-8mf5.json b/advisories/unreviewed/2022/05/GHSA-qqp3-5fc5-8mf5/GHSA-qqp3-5fc5-8mf5.json index 05a98ad4d6a..0662569d4ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqp3-5fc5-8mf5/GHSA-qqp3-5fc5-8mf5.json +++ b/advisories/unreviewed/2022/05/GHSA-qqp3-5fc5-8mf5/GHSA-qqp3-5fc5-8mf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qr77-cqc5-fjjj/GHSA-qr77-cqc5-fjjj.json b/advisories/unreviewed/2022/05/GHSA-qr77-cqc5-fjjj/GHSA-qr77-cqc5-fjjj.json index 25d9d69ffb7..ed842b8b5ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr77-cqc5-fjjj/GHSA-qr77-cqc5-fjjj.json +++ b/advisories/unreviewed/2022/05/GHSA-qr77-cqc5-fjjj/GHSA-qr77-cqc5-fjjj.json @@ -7,12 +7,8 @@ "CVE-2011-0492" ], "details": "Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exit) via blobs that trigger a certain file size, as demonstrated by the cached-descriptors.new file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrcv-3fq9-34gg/GHSA-qrcv-3fq9-34gg.json b/advisories/unreviewed/2022/05/GHSA-qrcv-3fq9-34gg/GHSA-qrcv-3fq9-34gg.json index b6167773c07..4ba1a73f104 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrcv-3fq9-34gg/GHSA-qrcv-3fq9-34gg.json +++ b/advisories/unreviewed/2022/05/GHSA-qrcv-3fq9-34gg/GHSA-qrcv-3fq9-34gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrjv-qwxf-47cg/GHSA-qrjv-qwxf-47cg.json b/advisories/unreviewed/2022/05/GHSA-qrjv-qwxf-47cg/GHSA-qrjv-qwxf-47cg.json index c00890a3fec..976e335629f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrjv-qwxf-47cg/GHSA-qrjv-qwxf-47cg.json +++ b/advisories/unreviewed/2022/05/GHSA-qrjv-qwxf-47cg/GHSA-qrjv-qwxf-47cg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrw7-xwg4-r3j7/GHSA-qrw7-xwg4-r3j7.json b/advisories/unreviewed/2022/05/GHSA-qrw7-xwg4-r3j7/GHSA-qrw7-xwg4-r3j7.json index 1e688837cde..bfcb7a0976c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrw7-xwg4-r3j7/GHSA-qrw7-xwg4-r3j7.json +++ b/advisories/unreviewed/2022/05/GHSA-qrw7-xwg4-r3j7/GHSA-qrw7-xwg4-r3j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qv24-jf7w-mgpv/GHSA-qv24-jf7w-mgpv.json b/advisories/unreviewed/2022/05/GHSA-qv24-jf7w-mgpv/GHSA-qv24-jf7w-mgpv.json index e7421400511..9adb61115eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv24-jf7w-mgpv/GHSA-qv24-jf7w-mgpv.json +++ b/advisories/unreviewed/2022/05/GHSA-qv24-jf7w-mgpv/GHSA-qv24-jf7w-mgpv.json @@ -7,12 +7,8 @@ "CVE-2010-4792" ], "details": "Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrary web script or HTML via the frame parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv3f-mvrx-9wqv/GHSA-qv3f-mvrx-9wqv.json b/advisories/unreviewed/2022/05/GHSA-qv3f-mvrx-9wqv/GHSA-qv3f-mvrx-9wqv.json index 717520b5ac8..359ae6174ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv3f-mvrx-9wqv/GHSA-qv3f-mvrx-9wqv.json +++ b/advisories/unreviewed/2022/05/GHSA-qv3f-mvrx-9wqv/GHSA-qv3f-mvrx-9wqv.json @@ -7,12 +7,8 @@ "CVE-2010-4710" ], "details": "Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxxp-xm6c-x64j/GHSA-qxxp-xm6c-x64j.json b/advisories/unreviewed/2022/05/GHSA-qxxp-xm6c-x64j/GHSA-qxxp-xm6c-x64j.json index 2f47fbb9001..590d686f6c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxxp-xm6c-x64j/GHSA-qxxp-xm6c-x64j.json +++ b/advisories/unreviewed/2022/05/GHSA-qxxp-xm6c-x64j/GHSA-qxxp-xm6c-x64j.json @@ -7,12 +7,8 @@ "CVE-2011-0263" ], "details": "Multiple stack-based buffer overflows in ovas.exe in the OVAS service in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attackers to execute arbitrary code via a long (1) Source Node or (2) Destination Node variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r23x-gvpc-gggx/GHSA-r23x-gvpc-gggx.json b/advisories/unreviewed/2022/05/GHSA-r23x-gvpc-gggx/GHSA-r23x-gvpc-gggx.json index ec63f1712f5..b585454a371 100644 --- a/advisories/unreviewed/2022/05/GHSA-r23x-gvpc-gggx/GHSA-r23x-gvpc-gggx.json +++ b/advisories/unreviewed/2022/05/GHSA-r23x-gvpc-gggx/GHSA-r23x-gvpc-gggx.json @@ -7,12 +7,8 @@ "CVE-2011-1491" ], "details": "The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a \"login CSRF\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3r8-7x27-gphf/GHSA-r3r8-7x27-gphf.json b/advisories/unreviewed/2022/05/GHSA-r3r8-7x27-gphf/GHSA-r3r8-7x27-gphf.json index fdd42cd0abe..c6a45675844 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3r8-7x27-gphf/GHSA-r3r8-7x27-gphf.json +++ b/advisories/unreviewed/2022/05/GHSA-r3r8-7x27-gphf/GHSA-r3r8-7x27-gphf.json @@ -7,12 +7,8 @@ "CVE-2011-0494" ], "details": "Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 5.1 before 5.1.0.39-TIV-AWS-IF0040, 6.0 before 6.0.0.25-TIV-AWS-IF0026, 6.1.0 before 6.1.0.5-TIV-AWS-IF0006, and 6.1.1 before 6.1.1-TIV-AWS-FP0001 has unspecified impact and attack vectors. NOTE: this might overlap CVE-2010-4622.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r42g-6jh5-6q2v/GHSA-r42g-6jh5-6q2v.json b/advisories/unreviewed/2022/05/GHSA-r42g-6jh5-6q2v/GHSA-r42g-6jh5-6q2v.json index 2a324db71a8..edd575eaf5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r42g-6jh5-6q2v/GHSA-r42g-6jh5-6q2v.json +++ b/advisories/unreviewed/2022/05/GHSA-r42g-6jh5-6q2v/GHSA-r42g-6jh5-6q2v.json @@ -7,12 +7,8 @@ "CVE-2011-1179" ], "details": "The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r433-22xc-g83r/GHSA-r433-22xc-g83r.json b/advisories/unreviewed/2022/05/GHSA-r433-22xc-g83r/GHSA-r433-22xc-g83r.json index fea5dde82bd..40fa7d88e71 100644 --- a/advisories/unreviewed/2022/05/GHSA-r433-22xc-g83r/GHSA-r433-22xc-g83r.json +++ b/advisories/unreviewed/2022/05/GHSA-r433-22xc-g83r/GHSA-r433-22xc-g83r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4gp-h7pq-qx3w/GHSA-r4gp-h7pq-qx3w.json b/advisories/unreviewed/2022/05/GHSA-r4gp-h7pq-qx3w/GHSA-r4gp-h7pq-qx3w.json index 1540c065b14..fbf115b5aa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4gp-h7pq-qx3w/GHSA-r4gp-h7pq-qx3w.json +++ b/advisories/unreviewed/2022/05/GHSA-r4gp-h7pq-qx3w/GHSA-r4gp-h7pq-qx3w.json @@ -7,12 +7,8 @@ "CVE-2011-0493" ], "details": "Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors related to malformed router caches and improper handling of integer values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r4q8-v93h-wrvh/GHSA-r4q8-v93h-wrvh.json b/advisories/unreviewed/2022/05/GHSA-r4q8-v93h-wrvh/GHSA-r4q8-v93h-wrvh.json index 869db6bc5b8..744c285939c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4q8-v93h-wrvh/GHSA-r4q8-v93h-wrvh.json +++ b/advisories/unreviewed/2022/05/GHSA-r4q8-v93h-wrvh/GHSA-r4q8-v93h-wrvh.json @@ -7,12 +7,8 @@ "CVE-2011-0516" ], "details": "SQL injection vulnerability in mainx_a.php in E-PROMPT C BetMore Site Suite 4.0 through 4.2.0 allows remote attackers to execute arbitrary SQL commands via the bid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r629-p653-cjj8/GHSA-r629-p653-cjj8.json b/advisories/unreviewed/2022/05/GHSA-r629-p653-cjj8/GHSA-r629-p653-cjj8.json index e6cf74546ed..7714e37fe14 100644 --- a/advisories/unreviewed/2022/05/GHSA-r629-p653-cjj8/GHSA-r629-p653-cjj8.json +++ b/advisories/unreviewed/2022/05/GHSA-r629-p653-cjj8/GHSA-r629-p653-cjj8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r646-w9ph-62w9/GHSA-r646-w9ph-62w9.json b/advisories/unreviewed/2022/05/GHSA-r646-w9ph-62w9/GHSA-r646-w9ph-62w9.json index e3daf2de8fb..7b246f6830f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r646-w9ph-62w9/GHSA-r646-w9ph-62w9.json +++ b/advisories/unreviewed/2022/05/GHSA-r646-w9ph-62w9/GHSA-r646-w9ph-62w9.json @@ -7,12 +7,8 @@ "CVE-2011-1492" ], "details": "steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8gh-gwc3-5f54/GHSA-r8gh-gwc3-5f54.json b/advisories/unreviewed/2022/05/GHSA-r8gh-gwc3-5f54/GHSA-r8gh-gwc3-5f54.json index dbaaaef229c..b76878bbaf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8gh-gwc3-5f54/GHSA-r8gh-gwc3-5f54.json +++ b/advisories/unreviewed/2022/05/GHSA-r8gh-gwc3-5f54/GHSA-r8gh-gwc3-5f54.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rc8p-4gwj-2v23/GHSA-rc8p-4gwj-2v23.json b/advisories/unreviewed/2022/05/GHSA-rc8p-4gwj-2v23/GHSA-rc8p-4gwj-2v23.json index bea9a606eab..ca7b9c7c4ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc8p-4gwj-2v23/GHSA-rc8p-4gwj-2v23.json +++ b/advisories/unreviewed/2022/05/GHSA-rc8p-4gwj-2v23/GHSA-rc8p-4gwj-2v23.json @@ -7,12 +7,8 @@ "CVE-2011-0157" ], "details": "WebKit, as used in Apple iOS before 4.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-09-1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfmg-cq5f-fchc/GHSA-rfmg-cq5f-fchc.json b/advisories/unreviewed/2022/05/GHSA-rfmg-cq5f-fchc/GHSA-rfmg-cq5f-fchc.json index 263c90fc293..cb1c8e07fea 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfmg-cq5f-fchc/GHSA-rfmg-cq5f-fchc.json +++ b/advisories/unreviewed/2022/05/GHSA-rfmg-cq5f-fchc/GHSA-rfmg-cq5f-fchc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg82-c3xg-wvrf/GHSA-rg82-c3xg-wvrf.json b/advisories/unreviewed/2022/05/GHSA-rg82-c3xg-wvrf/GHSA-rg82-c3xg-wvrf.json index b76b4b77f48..44a4c5eb98a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg82-c3xg-wvrf/GHSA-rg82-c3xg-wvrf.json +++ b/advisories/unreviewed/2022/05/GHSA-rg82-c3xg-wvrf/GHSA-rg82-c3xg-wvrf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg93-gvp9-mv6g/GHSA-rg93-gvp9-mv6g.json b/advisories/unreviewed/2022/05/GHSA-rg93-gvp9-mv6g/GHSA-rg93-gvp9-mv6g.json index ce14c9c5854..58c980d8f1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg93-gvp9-mv6g/GHSA-rg93-gvp9-mv6g.json +++ b/advisories/unreviewed/2022/05/GHSA-rg93-gvp9-mv6g/GHSA-rg93-gvp9-mv6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgj5-vhq5-p9jc/GHSA-rgj5-vhq5-p9jc.json b/advisories/unreviewed/2022/05/GHSA-rgj5-vhq5-p9jc/GHSA-rgj5-vhq5-p9jc.json index 86fe027088e..bd123b25a13 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgj5-vhq5-p9jc/GHSA-rgj5-vhq5-p9jc.json +++ b/advisories/unreviewed/2022/05/GHSA-rgj5-vhq5-p9jc/GHSA-rgj5-vhq5-p9jc.json @@ -7,12 +7,8 @@ "CVE-2011-0641" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/admin.php in the StatPressCN plugin 1.9.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) what1, (2) what2, (3) what3, (4) what4, and (5) what5 parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rh35-v95q-2mfc/GHSA-rh35-v95q-2mfc.json b/advisories/unreviewed/2022/05/GHSA-rh35-v95q-2mfc/GHSA-rh35-v95q-2mfc.json index cebef2e140b..23420a5918a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh35-v95q-2mfc/GHSA-rh35-v95q-2mfc.json +++ b/advisories/unreviewed/2022/05/GHSA-rh35-v95q-2mfc/GHSA-rh35-v95q-2mfc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rm9r-mxqr-25v7/GHSA-rm9r-mxqr-25v7.json b/advisories/unreviewed/2022/05/GHSA-rm9r-mxqr-25v7/GHSA-rm9r-mxqr-25v7.json index 4cc329711b3..f3f12391a5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm9r-mxqr-25v7/GHSA-rm9r-mxqr-25v7.json +++ b/advisories/unreviewed/2022/05/GHSA-rm9r-mxqr-25v7/GHSA-rm9r-mxqr-25v7.json @@ -7,12 +7,8 @@ "CVE-2011-0386" ], "details": "The XML-RPC implementation on Cisco TelePresence Recording Server devices with software 1.6.x and 1.7.x before 1.7.1 allows remote attackers to overwrite files and consequently execute arbitrary code via a malformed request, aka Bug ID CSCti50739.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmpx-3972-chvw/GHSA-rmpx-3972-chvw.json b/advisories/unreviewed/2022/05/GHSA-rmpx-3972-chvw/GHSA-rmpx-3972-chvw.json index 5359200eb12..2087833b606 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmpx-3972-chvw/GHSA-rmpx-3972-chvw.json +++ b/advisories/unreviewed/2022/05/GHSA-rmpx-3972-chvw/GHSA-rmpx-3972-chvw.json @@ -7,12 +7,8 @@ "CVE-2010-4436" ], "details": "Unspecified vulnerability in Oracle Sun Management Center (SunMC) 4.0 allows remote attackers to affect confidentiality via unknown vectors related to Web Console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rp7w-w68q-3c8g/GHSA-rp7w-w68q-3c8g.json b/advisories/unreviewed/2022/05/GHSA-rp7w-w68q-3c8g/GHSA-rp7w-w68q-3c8g.json index 52798bb90e3..2f592d76c11 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp7w-w68q-3c8g/GHSA-rp7w-w68q-3c8g.json +++ b/advisories/unreviewed/2022/05/GHSA-rp7w-w68q-3c8g/GHSA-rp7w-w68q-3c8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpc9-4cjr-9wxx/GHSA-rpc9-4cjr-9wxx.json b/advisories/unreviewed/2022/05/GHSA-rpc9-4cjr-9wxx/GHSA-rpc9-4cjr-9wxx.json index b5d30137fa0..42c5194f995 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpc9-4cjr-9wxx/GHSA-rpc9-4cjr-9wxx.json +++ b/advisories/unreviewed/2022/05/GHSA-rpc9-4cjr-9wxx/GHSA-rpc9-4cjr-9wxx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rv69-mh9p-xcg6/GHSA-rv69-mh9p-xcg6.json b/advisories/unreviewed/2022/05/GHSA-rv69-mh9p-xcg6/GHSA-rv69-mh9p-xcg6.json index 9ddc139c021..6c0e6878362 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv69-mh9p-xcg6/GHSA-rv69-mh9p-xcg6.json +++ b/advisories/unreviewed/2022/05/GHSA-rv69-mh9p-xcg6/GHSA-rv69-mh9p-xcg6.json @@ -7,12 +7,8 @@ "CVE-2011-1679" ], "details": "ncpfs 2.2.6 and earlier attempts to use (1) ncpmount to append to the /etc/mtab file and (2) ncpumount to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwjq-pqc6-6rcp/GHSA-rwjq-pqc6-6rcp.json b/advisories/unreviewed/2022/05/GHSA-rwjq-pqc6-6rcp/GHSA-rwjq-pqc6-6rcp.json index 0b2ebe22ef4..d1cd6fcf835 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwjq-pqc6-6rcp/GHSA-rwjq-pqc6-6rcp.json +++ b/advisories/unreviewed/2022/05/GHSA-rwjq-pqc6-6rcp/GHSA-rwjq-pqc6-6rcp.json @@ -7,12 +7,8 @@ "CVE-2011-1579" ], "details": "The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaWiki before 1.16.3 does not properly validate Cascading Style Sheets (CSS) token sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information by using the \\2f\\2a and \\2a\\2f hex strings to surround CSS comments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v26p-6c8q-68r2/GHSA-v26p-6c8q-68r2.json b/advisories/unreviewed/2022/05/GHSA-v26p-6c8q-68r2/GHSA-v26p-6c8q-68r2.json index 226ba10d5c5..b16ac33e89d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v26p-6c8q-68r2/GHSA-v26p-6c8q-68r2.json +++ b/advisories/unreviewed/2022/05/GHSA-v26p-6c8q-68r2/GHSA-v26p-6c8q-68r2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2qr-r9vx-5x54/GHSA-v2qr-r9vx-5x54.json b/advisories/unreviewed/2022/05/GHSA-v2qr-r9vx-5x54/GHSA-v2qr-r9vx-5x54.json index 4f7c2b0f1ee..06de9a65747 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2qr-r9vx-5x54/GHSA-v2qr-r9vx-5x54.json +++ b/advisories/unreviewed/2022/05/GHSA-v2qr-r9vx-5x54/GHSA-v2qr-r9vx-5x54.json @@ -7,12 +7,8 @@ "CVE-2011-0268" ], "details": "Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long text1 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3cw-vvcv-pgw2/GHSA-v3cw-vvcv-pgw2.json b/advisories/unreviewed/2022/05/GHSA-v3cw-vvcv-pgw2/GHSA-v3cw-vvcv-pgw2.json index 375d2c98424..dec036ce571 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3cw-vvcv-pgw2/GHSA-v3cw-vvcv-pgw2.json +++ b/advisories/unreviewed/2022/05/GHSA-v3cw-vvcv-pgw2/GHSA-v3cw-vvcv-pgw2.json @@ -7,12 +7,8 @@ "CVE-2011-0261" ], "details": "Unspecified vulnerability in jovgraph.exe in jovgraph in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a malformed displayWidth option in the arg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v3hq-hr77-g53p/GHSA-v3hq-hr77-g53p.json b/advisories/unreviewed/2022/05/GHSA-v3hq-hr77-g53p/GHSA-v3hq-hr77-g53p.json index 5f08028b71a..95d445b1ce9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3hq-hr77-g53p/GHSA-v3hq-hr77-g53p.json +++ b/advisories/unreviewed/2022/05/GHSA-v3hq-hr77-g53p/GHSA-v3hq-hr77-g53p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v55f-f77h-vx5c/GHSA-v55f-f77h-vx5c.json b/advisories/unreviewed/2022/05/GHSA-v55f-f77h-vx5c/GHSA-v55f-f77h-vx5c.json index f8f5402e812..369d03cefb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v55f-f77h-vx5c/GHSA-v55f-f77h-vx5c.json +++ b/advisories/unreviewed/2022/05/GHSA-v55f-f77h-vx5c/GHSA-v55f-f77h-vx5c.json @@ -7,12 +7,8 @@ "CVE-2011-0405" ], "details": "Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the pgvaction parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5g8-xvf6-qv6q/GHSA-v5g8-xvf6-qv6q.json b/advisories/unreviewed/2022/05/GHSA-v5g8-xvf6-qv6q/GHSA-v5g8-xvf6-qv6q.json index 61418d9a682..9e2aa3161c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5g8-xvf6-qv6q/GHSA-v5g8-xvf6-qv6q.json +++ b/advisories/unreviewed/2022/05/GHSA-v5g8-xvf6-qv6q/GHSA-v5g8-xvf6-qv6q.json @@ -7,12 +7,8 @@ "CVE-2011-1328" ], "details": "SQL injection vulnerability in RADVISION iVIEW Suite before 7.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v725-vrpf-8mgm/GHSA-v725-vrpf-8mgm.json b/advisories/unreviewed/2022/05/GHSA-v725-vrpf-8mgm/GHSA-v725-vrpf-8mgm.json index b9a77ecfc04..429b747b2ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-v725-vrpf-8mgm/GHSA-v725-vrpf-8mgm.json +++ b/advisories/unreviewed/2022/05/GHSA-v725-vrpf-8mgm/GHSA-v725-vrpf-8mgm.json @@ -7,12 +7,8 @@ "CVE-2011-1046" ], "details": "IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM), does not require the PRIVILEGED_WRITE access role for all intended Object Store modifications, which allows remote attackers to change a privileged property of an object via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v72x-8x3q-g9mx/GHSA-v72x-8x3q-g9mx.json b/advisories/unreviewed/2022/05/GHSA-v72x-8x3q-g9mx/GHSA-v72x-8x3q-g9mx.json index 70b1f27c2cf..e0f75433361 100644 --- a/advisories/unreviewed/2022/05/GHSA-v72x-8x3q-g9mx/GHSA-v72x-8x3q-g9mx.json +++ b/advisories/unreviewed/2022/05/GHSA-v72x-8x3q-g9mx/GHSA-v72x-8x3q-g9mx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v77p-x4g7-6364/GHSA-v77p-x4g7-6364.json b/advisories/unreviewed/2022/05/GHSA-v77p-x4g7-6364/GHSA-v77p-x4g7-6364.json index d66fe64cdf4..07b5980d178 100644 --- a/advisories/unreviewed/2022/05/GHSA-v77p-x4g7-6364/GHSA-v77p-x4g7-6364.json +++ b/advisories/unreviewed/2022/05/GHSA-v77p-x4g7-6364/GHSA-v77p-x4g7-6364.json @@ -7,12 +7,8 @@ "CVE-2011-0770" ], "details": "Cross-site scripting (XSS) vulnerability in Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 allows remote attackers to inject arbitrary web script or HTML via the Windows XP variable in a file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7c3-qvjr-7hpp/GHSA-v7c3-qvjr-7hpp.json b/advisories/unreviewed/2022/05/GHSA-v7c3-qvjr-7hpp/GHSA-v7c3-qvjr-7hpp.json index 648360e913a..89400bd93d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7c3-qvjr-7hpp/GHSA-v7c3-qvjr-7hpp.json +++ b/advisories/unreviewed/2022/05/GHSA-v7c3-qvjr-7hpp/GHSA-v7c3-qvjr-7hpp.json @@ -7,12 +7,8 @@ "CVE-2010-4669" ], "details": "The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7ff-c7xw-37pw/GHSA-v7ff-c7xw-37pw.json b/advisories/unreviewed/2022/05/GHSA-v7ff-c7xw-37pw/GHSA-v7ff-c7xw-37pw.json index a2c90062d6a..f1fcaaef8f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7ff-c7xw-37pw/GHSA-v7ff-c7xw-37pw.json +++ b/advisories/unreviewed/2022/05/GHSA-v7ff-c7xw-37pw/GHSA-v7ff-c7xw-37pw.json @@ -7,12 +7,8 @@ "CVE-2011-1726" ], "details": "Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7g7-rpcw-4f58/GHSA-v7g7-rpcw-4f58.json b/advisories/unreviewed/2022/05/GHSA-v7g7-rpcw-4f58/GHSA-v7g7-rpcw-4f58.json index e4dfa1a6110..44c0c0f5b7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7g7-rpcw-4f58/GHSA-v7g7-rpcw-4f58.json +++ b/advisories/unreviewed/2022/05/GHSA-v7g7-rpcw-4f58/GHSA-v7g7-rpcw-4f58.json @@ -7,12 +7,8 @@ "CVE-2011-1678" ], "details": "smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v825-m7vv-ghg2/GHSA-v825-m7vv-ghg2.json b/advisories/unreviewed/2022/05/GHSA-v825-m7vv-ghg2/GHSA-v825-m7vv-ghg2.json index 24c6490240b..52526c144f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v825-m7vv-ghg2/GHSA-v825-m7vv-ghg2.json +++ b/advisories/unreviewed/2022/05/GHSA-v825-m7vv-ghg2/GHSA-v825-m7vv-ghg2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v82p-53p5-5mr8/GHSA-v82p-53p5-5mr8.json b/advisories/unreviewed/2022/05/GHSA-v82p-53p5-5mr8/GHSA-v82p-53p5-5mr8.json index e3a201bfbab..c5235318c5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v82p-53p5-5mr8/GHSA-v82p-53p5-5mr8.json +++ b/advisories/unreviewed/2022/05/GHSA-v82p-53p5-5mr8/GHSA-v82p-53p5-5mr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8v6-8p4v-p892/GHSA-v8v6-8p4v-p892.json b/advisories/unreviewed/2022/05/GHSA-v8v6-8p4v-p892/GHSA-v8v6-8p4v-p892.json index ac08f2341e2..c62fcf01bc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8v6-8p4v-p892/GHSA-v8v6-8p4v-p892.json +++ b/advisories/unreviewed/2022/05/GHSA-v8v6-8p4v-p892/GHSA-v8v6-8p4v-p892.json @@ -7,12 +7,8 @@ "CVE-2010-4793" ], "details": "SQL injection vulnerability in detail.asp in Site2Nite Auto e-Manager allows remote attackers to execute arbitrary SQL commands via the ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vc9w-r2x3-9p7g/GHSA-vc9w-r2x3-9p7g.json b/advisories/unreviewed/2022/05/GHSA-vc9w-r2x3-9p7g/GHSA-vc9w-r2x3-9p7g.json index f3ef162f0a8..85ec87d4c34 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc9w-r2x3-9p7g/GHSA-vc9w-r2x3-9p7g.json +++ b/advisories/unreviewed/2022/05/GHSA-vc9w-r2x3-9p7g/GHSA-vc9w-r2x3-9p7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfhq-jx46-fgf3/GHSA-vfhq-jx46-fgf3.json b/advisories/unreviewed/2022/05/GHSA-vfhq-jx46-fgf3/GHSA-vfhq-jx46-fgf3.json index 7853d375399..37d8177bd56 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfhq-jx46-fgf3/GHSA-vfhq-jx46-fgf3.json +++ b/advisories/unreviewed/2022/05/GHSA-vfhq-jx46-fgf3/GHSA-vfhq-jx46-fgf3.json @@ -7,12 +7,8 @@ "CVE-2011-0903" ], "details": "Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibly have other unspecified impact via a .. (dot dot) in the (1) awcm_theme or (2) awcm_lang cookie to (a) index.php or (b) header.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfpf-55wm-vcv7/GHSA-vfpf-55wm-vcv7.json b/advisories/unreviewed/2022/05/GHSA-vfpf-55wm-vcv7/GHSA-vfpf-55wm-vcv7.json index 8a3e86c407d..c655eba485a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfpf-55wm-vcv7/GHSA-vfpf-55wm-vcv7.json +++ b/advisories/unreviewed/2022/05/GHSA-vfpf-55wm-vcv7/GHSA-vfpf-55wm-vcv7.json @@ -7,12 +7,8 @@ "CVE-2010-3186" ], "details": "IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg2h-xpwx-rj8w/GHSA-vg2h-xpwx-rj8w.json b/advisories/unreviewed/2022/05/GHSA-vg2h-xpwx-rj8w/GHSA-vg2h-xpwx-rj8w.json index 4a94e491cd0..b79ac5d6029 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg2h-xpwx-rj8w/GHSA-vg2h-xpwx-rj8w.json +++ b/advisories/unreviewed/2022/05/GHSA-vg2h-xpwx-rj8w/GHSA-vg2h-xpwx-rj8w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg3h-2vxq-p9cc/GHSA-vg3h-2vxq-p9cc.json b/advisories/unreviewed/2022/05/GHSA-vg3h-2vxq-p9cc/GHSA-vg3h-2vxq-p9cc.json index 5a476a0dbf1..fe4495c09e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg3h-2vxq-p9cc/GHSA-vg3h-2vxq-p9cc.json +++ b/advisories/unreviewed/2022/05/GHSA-vg3h-2vxq-p9cc/GHSA-vg3h-2vxq-p9cc.json @@ -7,12 +7,8 @@ "CVE-2011-1370" ], "details": "The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which allows remote attackers to read the configuration settings by examining a response message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vgg4-r596-q6v8/GHSA-vgg4-r596-q6v8.json b/advisories/unreviewed/2022/05/GHSA-vgg4-r596-q6v8/GHSA-vgg4-r596-q6v8.json index f3f5d1070ad..134d5db512b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgg4-r596-q6v8/GHSA-vgg4-r596-q6v8.json +++ b/advisories/unreviewed/2022/05/GHSA-vgg4-r596-q6v8/GHSA-vgg4-r596-q6v8.json @@ -7,12 +7,8 @@ "CVE-2011-1842" ], "details": "dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2) SetSystemDefaultLanguageEnv functions, which allows local users to gain privileges via shell metacharacters in a string argument, a different vulnerability than CVE-2011-0729.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh49-4q7j-v7vc/GHSA-vh49-4q7j-v7vc.json b/advisories/unreviewed/2022/05/GHSA-vh49-4q7j-v7vc/GHSA-vh49-4q7j-v7vc.json index e4e670ffbe6..87a85d13922 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh49-4q7j-v7vc/GHSA-vh49-4q7j-v7vc.json +++ b/advisories/unreviewed/2022/05/GHSA-vh49-4q7j-v7vc/GHSA-vh49-4q7j-v7vc.json @@ -7,12 +7,8 @@ "CVE-2011-1664" ], "details": "Cross-site request forgery (CSRF) vulnerability in the Translation Management module 6.x before 6.x-1.21 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh6c-5xwq-r5vw/GHSA-vh6c-5xwq-r5vw.json b/advisories/unreviewed/2022/05/GHSA-vh6c-5xwq-r5vw/GHSA-vh6c-5xwq-r5vw.json index d9b8a1df77b..af1fb92033f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh6c-5xwq-r5vw/GHSA-vh6c-5xwq-r5vw.json +++ b/advisories/unreviewed/2022/05/GHSA-vh6c-5xwq-r5vw/GHSA-vh6c-5xwq-r5vw.json @@ -7,12 +7,8 @@ "CVE-2011-0166" ], "details": "The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content. NOTE: this might overlap CVE-2011-0778.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vhxf-9672-mr6m/GHSA-vhxf-9672-mr6m.json b/advisories/unreviewed/2022/05/GHSA-vhxf-9672-mr6m/GHSA-vhxf-9672-mr6m.json index 7f6678859c5..643f5d6c585 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhxf-9672-mr6m/GHSA-vhxf-9672-mr6m.json +++ b/advisories/unreviewed/2022/05/GHSA-vhxf-9672-mr6m/GHSA-vhxf-9672-mr6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vj97-j3v8-5gc9/GHSA-vj97-j3v8-5gc9.json b/advisories/unreviewed/2022/05/GHSA-vj97-j3v8-5gc9/GHSA-vj97-j3v8-5gc9.json index f16c4c69a87..8b027529234 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj97-j3v8-5gc9/GHSA-vj97-j3v8-5gc9.json +++ b/advisories/unreviewed/2022/05/GHSA-vj97-j3v8-5gc9/GHSA-vj97-j3v8-5gc9.json @@ -7,12 +7,8 @@ "CVE-2011-1686" ], "details": "Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, as demonstrated by reading data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vjf4-chxp-cg8g/GHSA-vjf4-chxp-cg8g.json b/advisories/unreviewed/2022/05/GHSA-vjf4-chxp-cg8g/GHSA-vjf4-chxp-cg8g.json index 2373ae8db66..3d1429bbf5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjf4-chxp-cg8g/GHSA-vjf4-chxp-cg8g.json +++ b/advisories/unreviewed/2022/05/GHSA-vjf4-chxp-cg8g/GHSA-vjf4-chxp-cg8g.json @@ -7,12 +7,8 @@ "CVE-2011-1000" ], "details": "jingle-factory.c in Telepathy Gabble 0.11 before 0.11.7, 0.10 before 0.10.5, and 0.8 before 0.8.15 allows remote attackers to sniff audio and video calls via a crafted google:jingleinfo stanza that specifies an alternate server for streamed media.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vjg7-fw98-736x/GHSA-vjg7-fw98-736x.json b/advisories/unreviewed/2022/05/GHSA-vjg7-fw98-736x/GHSA-vjg7-fw98-736x.json index 0f7413642c7..873b309a8a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjg7-fw98-736x/GHSA-vjg7-fw98-736x.json +++ b/advisories/unreviewed/2022/05/GHSA-vjg7-fw98-736x/GHSA-vjg7-fw98-736x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm86-rqfj-qp62/GHSA-vm86-rqfj-qp62.json b/advisories/unreviewed/2022/05/GHSA-vm86-rqfj-qp62/GHSA-vm86-rqfj-qp62.json index 81b935c2e90..46781dbfdfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm86-rqfj-qp62/GHSA-vm86-rqfj-qp62.json +++ b/advisories/unreviewed/2022/05/GHSA-vm86-rqfj-qp62/GHSA-vm86-rqfj-qp62.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmv9-679j-8xv5/GHSA-vmv9-679j-8xv5.json b/advisories/unreviewed/2022/05/GHSA-vmv9-679j-8xv5/GHSA-vmv9-679j-8xv5.json index 290c5e20051..d28291ae2e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmv9-679j-8xv5/GHSA-vmv9-679j-8xv5.json +++ b/advisories/unreviewed/2022/05/GHSA-vmv9-679j-8xv5/GHSA-vmv9-679j-8xv5.json @@ -7,12 +7,8 @@ "CVE-2011-0321" ], "details": "librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.3.x before 7.5.3.5, and 7.6.x before 7.6.1.2 does not properly mitigate the possibility of a spoofed localhost source IP address, which allows remote attackers to (1) register or (2) unregister RPC services, and consequently cause a denial of service or obtain sensitive information from interprocess communication, via crafted UDP packets containing service commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmw6-ff98-m24q/GHSA-vmw6-ff98-m24q.json b/advisories/unreviewed/2022/05/GHSA-vmw6-ff98-m24q/GHSA-vmw6-ff98-m24q.json index 0d7b8416d60..0cf82b8deb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmw6-ff98-m24q/GHSA-vmw6-ff98-m24q.json +++ b/advisories/unreviewed/2022/05/GHSA-vmw6-ff98-m24q/GHSA-vmw6-ff98-m24q.json @@ -7,12 +7,8 @@ "CVE-2011-1506" ], "details": "The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a \"plaintext command injection\" attack, a similar issue to CVE-2011-0411. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpr5-jfp7-mh29/GHSA-vpr5-jfp7-mh29.json b/advisories/unreviewed/2022/05/GHSA-vpr5-jfp7-mh29/GHSA-vpr5-jfp7-mh29.json index 9c8cec4b518..e9ca893bb0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpr5-jfp7-mh29/GHSA-vpr5-jfp7-mh29.json +++ b/advisories/unreviewed/2022/05/GHSA-vpr5-jfp7-mh29/GHSA-vpr5-jfp7-mh29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq32-57rm-4rq8/GHSA-vq32-57rm-4rq8.json b/advisories/unreviewed/2022/05/GHSA-vq32-57rm-4rq8/GHSA-vq32-57rm-4rq8.json index 30cd9b97269..bff568b5884 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq32-57rm-4rq8/GHSA-vq32-57rm-4rq8.json +++ b/advisories/unreviewed/2022/05/GHSA-vq32-57rm-4rq8/GHSA-vq32-57rm-4rq8.json @@ -7,12 +7,8 @@ "CVE-2011-1066" ], "details": "Cross-site scripting (XSS) vulnerability in the Messaging module 6.x-2.x before 6.x-2.4 and 6.x-4.x before 6.x-4.0-beta8 for Drupal allows remote attackers with administer messaging permissions to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqhx-m344-7rcj/GHSA-vqhx-m344-7rcj.json b/advisories/unreviewed/2022/05/GHSA-vqhx-m344-7rcj/GHSA-vqhx-m344-7rcj.json index 2cae6ead99a..8091799f832 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqhx-m344-7rcj/GHSA-vqhx-m344-7rcj.json +++ b/advisories/unreviewed/2022/05/GHSA-vqhx-m344-7rcj/GHSA-vqhx-m344-7rcj.json @@ -7,12 +7,8 @@ "CVE-2011-1331" ], "details": "JustSystems Ichitaro 2005 through 2011, Ichitaro Government 6, Ichitaro Government 2006 through 2010, Ichitaro Portable, Ichitaro Pro, and Ichitaro Viewer allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document, as exploited in the wild in early 2011.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqj4-7669-fw9c/GHSA-vqj4-7669-fw9c.json b/advisories/unreviewed/2022/05/GHSA-vqj4-7669-fw9c/GHSA-vqj4-7669-fw9c.json index f4c33194331..2adb52ee613 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqj4-7669-fw9c/GHSA-vqj4-7669-fw9c.json +++ b/advisories/unreviewed/2022/05/GHSA-vqj4-7669-fw9c/GHSA-vqj4-7669-fw9c.json @@ -7,12 +7,8 @@ "CVE-2011-0727" ], "details": "GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqmh-h9f4-cvv4/GHSA-vqmh-h9f4-cvv4.json b/advisories/unreviewed/2022/05/GHSA-vqmh-h9f4-cvv4/GHSA-vqmh-h9f4-cvv4.json index 5047e8c0145..c3f760332f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqmh-h9f4-cvv4/GHSA-vqmh-h9f4-cvv4.json +++ b/advisories/unreviewed/2022/05/GHSA-vqmh-h9f4-cvv4/GHSA-vqmh-h9f4-cvv4.json @@ -7,12 +7,8 @@ "CVE-2011-1946" ], "details": "gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid function, which allows local users to gain privileges by leveraging access to two unprivileged user accounts, and running many processes under one of these accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrwf-2wgx-949w/GHSA-vrwf-2wgx-949w.json b/advisories/unreviewed/2022/05/GHSA-vrwf-2wgx-949w/GHSA-vrwf-2wgx-949w.json index ea59dfc1d2f..be48e10e29c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrwf-2wgx-949w/GHSA-vrwf-2wgx-949w.json +++ b/advisories/unreviewed/2022/05/GHSA-vrwf-2wgx-949w/GHSA-vrwf-2wgx-949w.json @@ -7,12 +7,8 @@ "CVE-2011-1589" ], "details": "Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows remote attackers to read arbitrary files via a %2f..%2f (encoded slash dot dot slash) in a URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw3j-pcrq-5hxc/GHSA-vw3j-pcrq-5hxc.json b/advisories/unreviewed/2022/05/GHSA-vw3j-pcrq-5hxc/GHSA-vw3j-pcrq-5hxc.json index c6a4067f212..45e0733751c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw3j-pcrq-5hxc/GHSA-vw3j-pcrq-5hxc.json +++ b/advisories/unreviewed/2022/05/GHSA-vw3j-pcrq-5hxc/GHSA-vw3j-pcrq-5hxc.json @@ -7,12 +7,8 @@ "CVE-2011-0402" ], "details": "dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw4q-9gcf-xhx2/GHSA-vw4q-9gcf-xhx2.json b/advisories/unreviewed/2022/05/GHSA-vw4q-9gcf-xhx2/GHSA-vw4q-9gcf-xhx2.json index d491635cd40..79ffbd6edb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw4q-9gcf-xhx2/GHSA-vw4q-9gcf-xhx2.json +++ b/advisories/unreviewed/2022/05/GHSA-vw4q-9gcf-xhx2/GHSA-vw4q-9gcf-xhx2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwv9-rw76-p5x4/GHSA-vwv9-rw76-p5x4.json b/advisories/unreviewed/2022/05/GHSA-vwv9-rw76-p5x4/GHSA-vwv9-rw76-p5x4.json index 85623a6cf6a..a0ec443236f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwv9-rw76-p5x4/GHSA-vwv9-rw76-p5x4.json +++ b/advisories/unreviewed/2022/05/GHSA-vwv9-rw76-p5x4/GHSA-vwv9-rw76-p5x4.json @@ -7,12 +7,8 @@ "CVE-2011-1329" ], "details": "WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vx6p-mwpm-f3vg/GHSA-vx6p-mwpm-f3vg.json b/advisories/unreviewed/2022/05/GHSA-vx6p-mwpm-f3vg/GHSA-vx6p-mwpm-f3vg.json index 47be61abcff..79b1755c718 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx6p-mwpm-f3vg/GHSA-vx6p-mwpm-f3vg.json +++ b/advisories/unreviewed/2022/05/GHSA-vx6p-mwpm-f3vg/GHSA-vx6p-mwpm-f3vg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2xr-v554-cf87/GHSA-w2xr-v554-cf87.json b/advisories/unreviewed/2022/05/GHSA-w2xr-v554-cf87/GHSA-w2xr-v554-cf87.json index 4c880efb4ce..55c8bd7ce82 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2xr-v554-cf87/GHSA-w2xr-v554-cf87.json +++ b/advisories/unreviewed/2022/05/GHSA-w2xr-v554-cf87/GHSA-w2xr-v554-cf87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2xx-4cpj-crmx/GHSA-w2xx-4cpj-crmx.json b/advisories/unreviewed/2022/05/GHSA-w2xx-4cpj-crmx/GHSA-w2xx-4cpj-crmx.json index a4d13d734b1..fa5b1f2b17c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2xx-4cpj-crmx/GHSA-w2xx-4cpj-crmx.json +++ b/advisories/unreviewed/2022/05/GHSA-w2xx-4cpj-crmx/GHSA-w2xx-4cpj-crmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3xw-rq95-8jcw/GHSA-w3xw-rq95-8jcw.json b/advisories/unreviewed/2022/05/GHSA-w3xw-rq95-8jcw/GHSA-w3xw-rq95-8jcw.json index 37368251729..e2dc09b4e63 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3xw-rq95-8jcw/GHSA-w3xw-rq95-8jcw.json +++ b/advisories/unreviewed/2022/05/GHSA-w3xw-rq95-8jcw/GHSA-w3xw-rq95-8jcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5cp-gh54-jfjq/GHSA-w5cp-gh54-jfjq.json b/advisories/unreviewed/2022/05/GHSA-w5cp-gh54-jfjq/GHSA-w5cp-gh54-jfjq.json index a421693a8fe..b64bde9952f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5cp-gh54-jfjq/GHSA-w5cp-gh54-jfjq.json +++ b/advisories/unreviewed/2022/05/GHSA-w5cp-gh54-jfjq/GHSA-w5cp-gh54-jfjq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5mc-rjm5-5w3q/GHSA-w5mc-rjm5-5w3q.json b/advisories/unreviewed/2022/05/GHSA-w5mc-rjm5-5w3q/GHSA-w5mc-rjm5-5w3q.json index b55acd929e8..67cafaa6a67 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5mc-rjm5-5w3q/GHSA-w5mc-rjm5-5w3q.json +++ b/advisories/unreviewed/2022/05/GHSA-w5mc-rjm5-5w3q/GHSA-w5mc-rjm5-5w3q.json @@ -7,12 +7,8 @@ "CVE-2011-0352" ], "details": "Buffer overflow in the web-based management interface on the Cisco Linksys WRT54GC router with firmware before 1.06.1 allows remote attackers to cause a denial of service (device crash) via a long string in a POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w66g-pq85-j4vq/GHSA-w66g-pq85-j4vq.json b/advisories/unreviewed/2022/05/GHSA-w66g-pq85-j4vq/GHSA-w66g-pq85-j4vq.json index ceb80da7102..d9d4dbbc73a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w66g-pq85-j4vq/GHSA-w66g-pq85-j4vq.json +++ b/advisories/unreviewed/2022/05/GHSA-w66g-pq85-j4vq/GHSA-w66g-pq85-j4vq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w885-jw3g-7qf8/GHSA-w885-jw3g-7qf8.json b/advisories/unreviewed/2022/05/GHSA-w885-jw3g-7qf8/GHSA-w885-jw3g-7qf8.json index ed5061718e3..282ba28d059 100644 --- a/advisories/unreviewed/2022/05/GHSA-w885-jw3g-7qf8/GHSA-w885-jw3g-7qf8.json +++ b/advisories/unreviewed/2022/05/GHSA-w885-jw3g-7qf8/GHSA-w885-jw3g-7qf8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w975-73p7-chcj/GHSA-w975-73p7-chcj.json b/advisories/unreviewed/2022/05/GHSA-w975-73p7-chcj/GHSA-w975-73p7-chcj.json index aa8175ce4c9..f7e839612a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w975-73p7-chcj/GHSA-w975-73p7-chcj.json +++ b/advisories/unreviewed/2022/05/GHSA-w975-73p7-chcj/GHSA-w975-73p7-chcj.json @@ -7,12 +7,8 @@ "CVE-2011-1841" ], "details": "Cross-site scripting (XSS) vulnerability in the link_to helper in Mojolicious before 1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w99c-9xfc-p23p/GHSA-w99c-9xfc-p23p.json b/advisories/unreviewed/2022/05/GHSA-w99c-9xfc-p23p/GHSA-w99c-9xfc-p23p.json index 4ed0cea54e9..a9a8461676e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w99c-9xfc-p23p/GHSA-w99c-9xfc-p23p.json +++ b/advisories/unreviewed/2022/05/GHSA-w99c-9xfc-p23p/GHSA-w99c-9xfc-p23p.json @@ -7,12 +7,8 @@ "CVE-2011-0434" ], "details": "Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) before 0.32.9 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) admin/bw_per_month.php or (2) client/bw_per_month.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9cr-6gj4-6mgj/GHSA-w9cr-6gj4-6mgj.json b/advisories/unreviewed/2022/05/GHSA-w9cr-6gj4-6mgj/GHSA-w9cr-6gj4-6mgj.json index 836c47cdbed..5783942e02e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9cr-6gj4-6mgj/GHSA-w9cr-6gj4-6mgj.json +++ b/advisories/unreviewed/2022/05/GHSA-w9cr-6gj4-6mgj/GHSA-w9cr-6gj4-6mgj.json @@ -7,12 +7,8 @@ "CVE-2011-0549" ], "details": "SQL injection vulnerability in forget.php in the management GUI in Symantec Web Gateway 4.5.x allows remote attackers to execute arbitrary SQL commands via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcc8-4f85-h634/GHSA-wcc8-4f85-h634.json b/advisories/unreviewed/2022/05/GHSA-wcc8-4f85-h634/GHSA-wcc8-4f85-h634.json index 00fee3645bc..20642c072eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcc8-4f85-h634/GHSA-wcc8-4f85-h634.json +++ b/advisories/unreviewed/2022/05/GHSA-wcc8-4f85-h634/GHSA-wcc8-4f85-h634.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcmm-28rg-mg3r/GHSA-wcmm-28rg-mg3r.json b/advisories/unreviewed/2022/05/GHSA-wcmm-28rg-mg3r/GHSA-wcmm-28rg-mg3r.json index 651551fafe9..08131230c7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcmm-28rg-mg3r/GHSA-wcmm-28rg-mg3r.json +++ b/advisories/unreviewed/2022/05/GHSA-wcmm-28rg-mg3r/GHSA-wcmm-28rg-mg3r.json @@ -7,12 +7,8 @@ "CVE-2011-0986" ], "details": "phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the installation path via a direct request for a nonexistent file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfcg-m45x-v8xf/GHSA-wfcg-m45x-v8xf.json b/advisories/unreviewed/2022/05/GHSA-wfcg-m45x-v8xf/GHSA-wfcg-m45x-v8xf.json index ffb093fec0c..034528abbd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfcg-m45x-v8xf/GHSA-wfcg-m45x-v8xf.json +++ b/advisories/unreviewed/2022/05/GHSA-wfcg-m45x-v8xf/GHSA-wfcg-m45x-v8xf.json @@ -7,12 +7,8 @@ "CVE-2011-0651" ], "details": "Buffer overflow in the key exchange functionality in Icon Labs Iconfidant SSL Server before 1.3.0 allows remote attackers to execute arbitrary code via a client master key packet in which the sum of unspecified length fields is greater than a certain value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgm7-p834-p3r7/GHSA-wgm7-p834-p3r7.json b/advisories/unreviewed/2022/05/GHSA-wgm7-p834-p3r7/GHSA-wgm7-p834-p3r7.json index 0ab8ced08fe..0f11f0b68f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgm7-p834-p3r7/GHSA-wgm7-p834-p3r7.json +++ b/advisories/unreviewed/2022/05/GHSA-wgm7-p834-p3r7/GHSA-wgm7-p834-p3r7.json @@ -7,12 +7,8 @@ "CVE-2011-0897" ], "details": "Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.00 allows local users to read arbitrary files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wgq9-v99g-7fpg/GHSA-wgq9-v99g-7fpg.json b/advisories/unreviewed/2022/05/GHSA-wgq9-v99g-7fpg/GHSA-wgq9-v99g-7fpg.json index c6647932971..f78de41286e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgq9-v99g-7fpg/GHSA-wgq9-v99g-7fpg.json +++ b/advisories/unreviewed/2022/05/GHSA-wgq9-v99g-7fpg/GHSA-wgq9-v99g-7fpg.json @@ -7,12 +7,8 @@ "CVE-2010-4633" ], "details": "SQL injection vulnerability in cart.php in digiSHOP 2.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vulnerability than CVE-2005-4614.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgwx-cwf3-jffh/GHSA-wgwx-cwf3-jffh.json b/advisories/unreviewed/2022/05/GHSA-wgwx-cwf3-jffh/GHSA-wgwx-cwf3-jffh.json index 11e17025c79..e13e9e0a213 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgwx-cwf3-jffh/GHSA-wgwx-cwf3-jffh.json +++ b/advisories/unreviewed/2022/05/GHSA-wgwx-cwf3-jffh/GHSA-wgwx-cwf3-jffh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wj48-vr63-9mc8/GHSA-wj48-vr63-9mc8.json b/advisories/unreviewed/2022/05/GHSA-wj48-vr63-9mc8/GHSA-wj48-vr63-9mc8.json index 7df29acf8b7..702ec0930cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj48-vr63-9mc8/GHSA-wj48-vr63-9mc8.json +++ b/advisories/unreviewed/2022/05/GHSA-wj48-vr63-9mc8/GHSA-wj48-vr63-9mc8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wphx-j4h9-hfr8/GHSA-wphx-j4h9-hfr8.json b/advisories/unreviewed/2022/05/GHSA-wphx-j4h9-hfr8/GHSA-wphx-j4h9-hfr8.json index f3b95b79dc3..79f7991d932 100644 --- a/advisories/unreviewed/2022/05/GHSA-wphx-j4h9-hfr8/GHSA-wphx-j4h9-hfr8.json +++ b/advisories/unreviewed/2022/05/GHSA-wphx-j4h9-hfr8/GHSA-wphx-j4h9-hfr8.json @@ -7,12 +7,8 @@ "CVE-2011-0465" ], "details": "xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpmr-prm6-682h/GHSA-wpmr-prm6-682h.json b/advisories/unreviewed/2022/05/GHSA-wpmr-prm6-682h/GHSA-wpmr-prm6-682h.json index de6ac48882e..26bf1c35cb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpmr-prm6-682h/GHSA-wpmr-prm6-682h.json +++ b/advisories/unreviewed/2022/05/GHSA-wpmr-prm6-682h/GHSA-wpmr-prm6-682h.json @@ -7,12 +7,8 @@ "CVE-2011-0280" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2) the Id parameter to Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to Contents/applicationlogs.asp. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wq98-2gx5-4gfp/GHSA-wq98-2gx5-4gfp.json b/advisories/unreviewed/2022/05/GHSA-wq98-2gx5-4gfp/GHSA-wq98-2gx5-4gfp.json index 1ea4654a9e8..05886ff02d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq98-2gx5-4gfp/GHSA-wq98-2gx5-4gfp.json +++ b/advisories/unreviewed/2022/05/GHSA-wq98-2gx5-4gfp/GHSA-wq98-2gx5-4gfp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wq9w-phf6-r3p2/GHSA-wq9w-phf6-r3p2.json b/advisories/unreviewed/2022/05/GHSA-wq9w-phf6-r3p2/GHSA-wq9w-phf6-r3p2.json index 12d7d9072a4..607c1eb47a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq9w-phf6-r3p2/GHSA-wq9w-phf6-r3p2.json +++ b/advisories/unreviewed/2022/05/GHSA-wq9w-phf6-r3p2/GHSA-wq9w-phf6-r3p2.json @@ -7,12 +7,8 @@ "CVE-2011-1505" ], "details": "Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.27 services for Lotus Domino has unknown impact and attack vectors, aka SPR ESEO8DQME2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqhm-hj4w-xppw/GHSA-wqhm-hj4w-xppw.json b/advisories/unreviewed/2022/05/GHSA-wqhm-hj4w-xppw/GHSA-wqhm-hj4w-xppw.json index f8fcdcc7e37..caf825d1fba 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqhm-hj4w-xppw/GHSA-wqhm-hj4w-xppw.json +++ b/advisories/unreviewed/2022/05/GHSA-wqhm-hj4w-xppw/GHSA-wqhm-hj4w-xppw.json @@ -7,12 +7,8 @@ "CVE-2011-1053" ], "details": "Unspecified vulnerability in the Mach-O input file loader in Hex-Rays IDA Pro 5.7 and 6.0 allows user-assisted remote attackers to cause a denial of service (out-of-memory exception and inability to analyze code) via a crafted Mach-O file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqvf-x4mq-9ghv/GHSA-wqvf-x4mq-9ghv.json b/advisories/unreviewed/2022/05/GHSA-wqvf-x4mq-9ghv/GHSA-wqvf-x4mq-9ghv.json index 13c20341d98..973a5fac853 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqvf-x4mq-9ghv/GHSA-wqvf-x4mq-9ghv.json +++ b/advisories/unreviewed/2022/05/GHSA-wqvf-x4mq-9ghv/GHSA-wqvf-x4mq-9ghv.json @@ -7,12 +7,8 @@ "CVE-2011-1368" ], "details": "The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to read unspecified files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr98-3q9r-m539/GHSA-wr98-3q9r-m539.json b/advisories/unreviewed/2022/05/GHSA-wr98-3q9r-m539/GHSA-wr98-3q9r-m539.json index 396dcd92275..723dc375456 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr98-3q9r-m539/GHSA-wr98-3q9r-m539.json +++ b/advisories/unreviewed/2022/05/GHSA-wr98-3q9r-m539/GHSA-wr98-3q9r-m539.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrm4-mcrj-r7f7/GHSA-wrm4-mcrj-r7f7.json b/advisories/unreviewed/2022/05/GHSA-wrm4-mcrj-r7f7/GHSA-wrm4-mcrj-r7f7.json index f8e8e2b44bc..5eca47338bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrm4-mcrj-r7f7/GHSA-wrm4-mcrj-r7f7.json +++ b/advisories/unreviewed/2022/05/GHSA-wrm4-mcrj-r7f7/GHSA-wrm4-mcrj-r7f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv6m-q5g2-j9v4/GHSA-wv6m-q5g2-j9v4.json b/advisories/unreviewed/2022/05/GHSA-wv6m-q5g2-j9v4/GHSA-wv6m-q5g2-j9v4.json index c502eacc52a..b0f69f06be5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv6m-q5g2-j9v4/GHSA-wv6m-q5g2-j9v4.json +++ b/advisories/unreviewed/2022/05/GHSA-wv6m-q5g2-j9v4/GHSA-wv6m-q5g2-j9v4.json @@ -7,12 +7,8 @@ "CVE-2011-0505" ], "details": "Directory traversal vulnerability in system/system.php in Zwii 2.1.1, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the set[template][value] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv93-cm32-r2q2/GHSA-wv93-cm32-r2q2.json b/advisories/unreviewed/2022/05/GHSA-wv93-cm32-r2q2/GHSA-wv93-cm32-r2q2.json index 91eb9680bb7..b260186179f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv93-cm32-r2q2/GHSA-wv93-cm32-r2q2.json +++ b/advisories/unreviewed/2022/05/GHSA-wv93-cm32-r2q2/GHSA-wv93-cm32-r2q2.json @@ -7,12 +7,8 @@ "CVE-2011-0775" ], "details": "pivotx/modules/module_image.php in PivotX 2.2.2 allows remote attackers to obtain sensitive information via a non-existent file in the image parameter, which reveals the installation path in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvf3-49g5-gf8c/GHSA-wvf3-49g5-gf8c.json b/advisories/unreviewed/2022/05/GHSA-wvf3-49g5-gf8c/GHSA-wvf3-49g5-gf8c.json index a7ebbf1fa9c..b7edde8e6d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvf3-49g5-gf8c/GHSA-wvf3-49g5-gf8c.json +++ b/advisories/unreviewed/2022/05/GHSA-wvf3-49g5-gf8c/GHSA-wvf3-49g5-gf8c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvw3-4jv4-x75p/GHSA-wvw3-4jv4-x75p.json b/advisories/unreviewed/2022/05/GHSA-wvw3-4jv4-x75p/GHSA-wvw3-4jv4-x75p.json index e9f109bcf03..33d4f20938e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvw3-4jv4-x75p/GHSA-wvw3-4jv4-x75p.json +++ b/advisories/unreviewed/2022/05/GHSA-wvw3-4jv4-x75p/GHSA-wvw3-4jv4-x75p.json @@ -7,12 +7,8 @@ "CVE-2011-1100" ], "details": "Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) findfid, (2) id, (3) selectfcat, (4) selectfmon, or (5) selectftag parameter in an images action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwg9-gfq6-f7h3/GHSA-wwg9-gfq6-f7h3.json b/advisories/unreviewed/2022/05/GHSA-wwg9-gfq6-f7h3/GHSA-wwg9-gfq6-f7h3.json index fe85e3c3d5b..67767d532d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwg9-gfq6-f7h3/GHSA-wwg9-gfq6-f7h3.json +++ b/advisories/unreviewed/2022/05/GHSA-wwg9-gfq6-f7h3/GHSA-wwg9-gfq6-f7h3.json @@ -7,12 +7,8 @@ "CVE-2011-1376" ], "details": "iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/client_ffdc/, which allows local users to read or modify files via standard filesystem operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwj5-m94m-cj5c/GHSA-wwj5-m94m-cj5c.json b/advisories/unreviewed/2022/05/GHSA-wwj5-m94m-cj5c/GHSA-wwj5-m94m-cj5c.json index bbfe173ac34..01e0bcc42de 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwj5-m94m-cj5c/GHSA-wwj5-m94m-cj5c.json +++ b/advisories/unreviewed/2022/05/GHSA-wwj5-m94m-cj5c/GHSA-wwj5-m94m-cj5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxhc-rwm9-xjjx/GHSA-wxhc-rwm9-xjjx.json b/advisories/unreviewed/2022/05/GHSA-wxhc-rwm9-xjjx/GHSA-wxhc-rwm9-xjjx.json index b27f23f0cef..4963a145a21 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxhc-rwm9-xjjx/GHSA-wxhc-rwm9-xjjx.json +++ b/advisories/unreviewed/2022/05/GHSA-wxhc-rwm9-xjjx/GHSA-wxhc-rwm9-xjjx.json @@ -7,12 +7,8 @@ "CVE-2011-1938" ], "details": "Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x263-gfrx-5m9x/GHSA-x263-gfrx-5m9x.json b/advisories/unreviewed/2022/05/GHSA-x263-gfrx-5m9x/GHSA-x263-gfrx-5m9x.json index 81f1027f6d3..02e16203bae 100644 --- a/advisories/unreviewed/2022/05/GHSA-x263-gfrx-5m9x/GHSA-x263-gfrx-5m9x.json +++ b/advisories/unreviewed/2022/05/GHSA-x263-gfrx-5m9x/GHSA-x263-gfrx-5m9x.json @@ -7,12 +7,8 @@ "CVE-2011-1206" ], "details": "Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows remote attackers to execute arbitrary code via a crafted LDAP request. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2j3-3jfh-q9x7/GHSA-x2j3-3jfh-q9x7.json b/advisories/unreviewed/2022/05/GHSA-x2j3-3jfh-q9x7/GHSA-x2j3-3jfh-q9x7.json index 2495de5db54..c967901aa5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2j3-3jfh-q9x7/GHSA-x2j3-3jfh-q9x7.json +++ b/advisories/unreviewed/2022/05/GHSA-x2j3-3jfh-q9x7/GHSA-x2j3-3jfh-q9x7.json @@ -7,12 +7,8 @@ "CVE-2011-1609" ], "details": "SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtg85647.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3qx-m9p3-wj5r/GHSA-x3qx-m9p3-wj5r.json b/advisories/unreviewed/2022/05/GHSA-x3qx-m9p3-wj5r/GHSA-x3qx-m9p3-wj5r.json index 53f4bbbad6f..cec0ab639c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3qx-m9p3-wj5r/GHSA-x3qx-m9p3-wj5r.json +++ b/advisories/unreviewed/2022/05/GHSA-x3qx-m9p3-wj5r/GHSA-x3qx-m9p3-wj5r.json @@ -7,12 +7,8 @@ "CVE-2011-1357" ], "details": "Cross-site scripting (XSS) vulnerability in agentDetect.jsp in the web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 before 6.3.0.5, 7.0 before 7.0.0.5, and 7.5 before 7.5.0.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4qg-rgm7-vgvv/GHSA-x4qg-rgm7-vgvv.json b/advisories/unreviewed/2022/05/GHSA-x4qg-rgm7-vgvv/GHSA-x4qg-rgm7-vgvv.json index 90138950eb5..023cff46533 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4qg-rgm7-vgvv/GHSA-x4qg-rgm7-vgvv.json +++ b/advisories/unreviewed/2022/05/GHSA-x4qg-rgm7-vgvv/GHSA-x4qg-rgm7-vgvv.json @@ -7,12 +7,8 @@ "CVE-2011-0412" ], "details": "Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x546-m6gw-qc7f/GHSA-x546-m6gw-qc7f.json b/advisories/unreviewed/2022/05/GHSA-x546-m6gw-qc7f/GHSA-x546-m6gw-qc7f.json index b657a1a095d..08f3efd2b7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x546-m6gw-qc7f/GHSA-x546-m6gw-qc7f.json +++ b/advisories/unreviewed/2022/05/GHSA-x546-m6gw-qc7f/GHSA-x546-m6gw-qc7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x624-7h2h-m4ph/GHSA-x624-7h2h-m4ph.json b/advisories/unreviewed/2022/05/GHSA-x624-7h2h-m4ph/GHSA-x624-7h2h-m4ph.json index fa61087ca23..97ac60a8741 100644 --- a/advisories/unreviewed/2022/05/GHSA-x624-7h2h-m4ph/GHSA-x624-7h2h-m4ph.json +++ b/advisories/unreviewed/2022/05/GHSA-x624-7h2h-m4ph/GHSA-x624-7h2h-m4ph.json @@ -7,12 +7,8 @@ "CVE-2011-0464" ], "details": "Unspecified vulnerability in Novell Vibe OnPrem 3.0 before Hot Patch 1 allows remote attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x64p-468c-m65v/GHSA-x64p-468c-m65v.json b/advisories/unreviewed/2022/05/GHSA-x64p-468c-m65v/GHSA-x64p-468c-m65v.json index 6f52d936373..ae877ad728f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x64p-468c-m65v/GHSA-x64p-468c-m65v.json +++ b/advisories/unreviewed/2022/05/GHSA-x64p-468c-m65v/GHSA-x64p-468c-m65v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6h9-w59x-x6v8/GHSA-x6h9-w59x-x6v8.json b/advisories/unreviewed/2022/05/GHSA-x6h9-w59x-x6v8/GHSA-x6h9-w59x-x6v8.json index c16c2c8837b..a815941052d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6h9-w59x-x6v8/GHSA-x6h9-w59x-x6v8.json +++ b/advisories/unreviewed/2022/05/GHSA-x6h9-w59x-x6v8/GHSA-x6h9-w59x-x6v8.json @@ -7,12 +7,8 @@ "CVE-2010-4430" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.1 Update 2010-F allows remote authenticated users to affect confidentiality via unknown vectors related to Absence Management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6jw-95g6-c4pf/GHSA-x6jw-95g6-c4pf.json b/advisories/unreviewed/2022/05/GHSA-x6jw-95g6-c4pf/GHSA-x6jw-95g6-c4pf.json index b86724db1a7..67713911cf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6jw-95g6-c4pf/GHSA-x6jw-95g6-c4pf.json +++ b/advisories/unreviewed/2022/05/GHSA-x6jw-95g6-c4pf/GHSA-x6jw-95g6-c4pf.json @@ -7,12 +7,8 @@ "CVE-2011-1908" ], "details": "Integer overflow in the Type 1 font decoder in the FreeType engine in Foxit Reader before 4.0.0.0619 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font in a PDF document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6q8-w8xf-7859/GHSA-x6q8-w8xf-7859.json b/advisories/unreviewed/2022/05/GHSA-x6q8-w8xf-7859/GHSA-x6q8-w8xf-7859.json index a2546b21f2e..33010bfd6a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6q8-w8xf-7859/GHSA-x6q8-w8xf-7859.json +++ b/advisories/unreviewed/2022/05/GHSA-x6q8-w8xf-7859/GHSA-x6q8-w8xf-7859.json @@ -7,12 +7,8 @@ "CVE-2011-0488" ], "details": "Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long request to TCP port 80.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x772-gj3f-cm3q/GHSA-x772-gj3f-cm3q.json b/advisories/unreviewed/2022/05/GHSA-x772-gj3f-cm3q/GHSA-x772-gj3f-cm3q.json index f199dc6e388..5f7b5115dbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-x772-gj3f-cm3q/GHSA-x772-gj3f-cm3q.json +++ b/advisories/unreviewed/2022/05/GHSA-x772-gj3f-cm3q/GHSA-x772-gj3f-cm3q.json @@ -7,12 +7,8 @@ "CVE-2010-4640" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in XWiki Watch 1.0 allow remote attackers to inject arbitrary web script or HTML via the rev parameter to (1) bin/viewrev/Main/WebHome and (2) bin/view/Blog, and the (3) register_first_name and (4) register_last_name parameters to bin/register/XWiki/Register. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x786-9669-6rv6/GHSA-x786-9669-6rv6.json b/advisories/unreviewed/2022/05/GHSA-x786-9669-6rv6/GHSA-x786-9669-6rv6.json index c4732421214..6044ea07c8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x786-9669-6rv6/GHSA-x786-9669-6rv6.json +++ b/advisories/unreviewed/2022/05/GHSA-x786-9669-6rv6/GHSA-x786-9669-6rv6.json @@ -7,12 +7,8 @@ "CVE-2011-0439" ], "details": "Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the Pieforms select box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x789-p2c6-5hxj/GHSA-x789-p2c6-5hxj.json b/advisories/unreviewed/2022/05/GHSA-x789-p2c6-5hxj/GHSA-x789-p2c6-5hxj.json index 02b7b0ccbc7..4ae3ec13364 100644 --- a/advisories/unreviewed/2022/05/GHSA-x789-p2c6-5hxj/GHSA-x789-p2c6-5hxj.json +++ b/advisories/unreviewed/2022/05/GHSA-x789-p2c6-5hxj/GHSA-x789-p2c6-5hxj.json @@ -7,12 +7,8 @@ "CVE-2010-4420" ], "details": "Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows local users to affect confidentiality and integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x7g8-6gcg-3rxc/GHSA-x7g8-6gcg-3rxc.json b/advisories/unreviewed/2022/05/GHSA-x7g8-6gcg-3rxc/GHSA-x7g8-6gcg-3rxc.json index 9d0982aa6b8..0580bdaf810 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7g8-6gcg-3rxc/GHSA-x7g8-6gcg-3rxc.json +++ b/advisories/unreviewed/2022/05/GHSA-x7g8-6gcg-3rxc/GHSA-x7g8-6gcg-3rxc.json @@ -7,12 +7,8 @@ "CVE-2011-1613" ], "details": "Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0 before 7.0.98.216, and 7.0.1xx before 7.0.112.0 allows remote attackers to cause a denial of service (device reload) via a sequence of ICMP packets, aka Bug ID CSCth74426.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x838-qr7r-99r6/GHSA-x838-qr7r-99r6.json b/advisories/unreviewed/2022/05/GHSA-x838-qr7r-99r6/GHSA-x838-qr7r-99r6.json index 26e489f427e..04964c99d26 100644 --- a/advisories/unreviewed/2022/05/GHSA-x838-qr7r-99r6/GHSA-x838-qr7r-99r6.json +++ b/advisories/unreviewed/2022/05/GHSA-x838-qr7r-99r6/GHSA-x838-qr7r-99r6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x84h-fcr4-jgx6/GHSA-x84h-fcr4-jgx6.json b/advisories/unreviewed/2022/05/GHSA-x84h-fcr4-jgx6/GHSA-x84h-fcr4-jgx6.json index 2001bbd8522..a4af18fe21c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x84h-fcr4-jgx6/GHSA-x84h-fcr4-jgx6.json +++ b/advisories/unreviewed/2022/05/GHSA-x84h-fcr4-jgx6/GHSA-x84h-fcr4-jgx6.json @@ -7,12 +7,8 @@ "CVE-2011-1556" ], "details": "SQL injection vulnerability in plugins/pdfClasses/pdfgen.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.4 allows remote attackers to execute arbitrary SQL commands via the pdfa parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x932-88vq-xg5c/GHSA-x932-88vq-xg5c.json b/advisories/unreviewed/2022/05/GHSA-x932-88vq-xg5c/GHSA-x932-88vq-xg5c.json index 37886ff9c42..ab44c3b1262 100644 --- a/advisories/unreviewed/2022/05/GHSA-x932-88vq-xg5c/GHSA-x932-88vq-xg5c.json +++ b/advisories/unreviewed/2022/05/GHSA-x932-88vq-xg5c/GHSA-x932-88vq-xg5c.json @@ -7,12 +7,8 @@ "CVE-2011-0438" ], "details": "nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x994-jpg5-7jqr/GHSA-x994-jpg5-7jqr.json b/advisories/unreviewed/2022/05/GHSA-x994-jpg5-7jqr/GHSA-x994-jpg5-7jqr.json index a8fc2fa0dec..536d3b17302 100644 --- a/advisories/unreviewed/2022/05/GHSA-x994-jpg5-7jqr/GHSA-x994-jpg5-7jqr.json +++ b/advisories/unreviewed/2022/05/GHSA-x994-jpg5-7jqr/GHSA-x994-jpg5-7jqr.json @@ -7,12 +7,8 @@ "CVE-2010-4432" ], "details": "Unspecified vulnerability in the Oracle Transportation Manager component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Infrastructure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x9c6-rvmm-xwvg/GHSA-x9c6-rvmm-xwvg.json b/advisories/unreviewed/2022/05/GHSA-x9c6-rvmm-xwvg/GHSA-x9c6-rvmm-xwvg.json index 06b78689c4b..5e293e15808 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9c6-rvmm-xwvg/GHSA-x9c6-rvmm-xwvg.json +++ b/advisories/unreviewed/2022/05/GHSA-x9c6-rvmm-xwvg/GHSA-x9c6-rvmm-xwvg.json @@ -7,12 +7,8 @@ "CVE-2011-1711" ], "details": "Unspecified vulnerability in the Mobility Pack 1.1.2 and earlier in Novell Data Synchronizer 1.0.x, and 1.1.x through 1.1.1 build 428, allows remote authenticated users to access the accounts of other users via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x9m6-45gv-4vc4/GHSA-x9m6-45gv-4vc4.json b/advisories/unreviewed/2022/05/GHSA-x9m6-45gv-4vc4/GHSA-x9m6-45gv-4vc4.json index 4ac1792f245..88877f7f961 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9m6-45gv-4vc4/GHSA-x9m6-45gv-4vc4.json +++ b/advisories/unreviewed/2022/05/GHSA-x9m6-45gv-4vc4/GHSA-x9m6-45gv-4vc4.json @@ -7,12 +7,8 @@ "CVE-2011-0506" ], "details": "Directory traversal vulnerability in modules/profile/user.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to execute arbitrary code via a .. (dot dot) in the aXconf[default_language] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9m9-3w3m-hrf4/GHSA-x9m9-3w3m-hrf4.json b/advisories/unreviewed/2022/05/GHSA-x9m9-3w3m-hrf4/GHSA-x9m9-3w3m-hrf4.json index bd3239760aa..927eac982d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9m9-3w3m-hrf4/GHSA-x9m9-3w3m-hrf4.json +++ b/advisories/unreviewed/2022/05/GHSA-x9m9-3w3m-hrf4/GHSA-x9m9-3w3m-hrf4.json @@ -7,12 +7,8 @@ "CVE-2010-2940" ], "details": "The auth_send function in providers/ldap/ldap_auth.c in System Security Services Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind are enabled, allows remote attackers to bypass the authentication requirements of pam_authenticate via an empty password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc37-cv9h-f6mv/GHSA-xc37-cv9h-f6mv.json b/advisories/unreviewed/2022/05/GHSA-xc37-cv9h-f6mv/GHSA-xc37-cv9h-f6mv.json index 14e8fca7218..ac9a4c0d1ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc37-cv9h-f6mv/GHSA-xc37-cv9h-f6mv.json +++ b/advisories/unreviewed/2022/05/GHSA-xc37-cv9h-f6mv/GHSA-xc37-cv9h-f6mv.json @@ -7,12 +7,8 @@ "CVE-2011-1067" ], "details": "slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the c_timelimit field of the connection table element, which allows remote attackers to cause a denial of service (daemon outage) via Simple Paged Results connections, as demonstrated by using multiple processes to replay TCP sessions, a different vulnerability than CVE-2011-0019.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc55-qhgh-qjg9/GHSA-xc55-qhgh-qjg9.json b/advisories/unreviewed/2022/05/GHSA-xc55-qhgh-qjg9/GHSA-xc55-qhgh-qjg9.json index 26749b06280..e80ddb28f05 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc55-qhgh-qjg9/GHSA-xc55-qhgh-qjg9.json +++ b/advisories/unreviewed/2022/05/GHSA-xc55-qhgh-qjg9/GHSA-xc55-qhgh-qjg9.json @@ -7,12 +7,8 @@ "CVE-2011-0324" ], "details": "Multiple heap-based buffer overflows in Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allow remote attackers to execute arbitrary code via a long (1) KeyString property, (2) NewPath parameter to the SetLocalIniFilePath method, or (3) NewPortPath parameter to the SetTabletPortPath method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xffq-rx82-3974/GHSA-xffq-rx82-3974.json b/advisories/unreviewed/2022/05/GHSA-xffq-rx82-3974/GHSA-xffq-rx82-3974.json index 5cace727e7a..398167fef70 100644 --- a/advisories/unreviewed/2022/05/GHSA-xffq-rx82-3974/GHSA-xffq-rx82-3974.json +++ b/advisories/unreviewed/2022/05/GHSA-xffq-rx82-3974/GHSA-xffq-rx82-3974.json @@ -7,12 +7,8 @@ "CVE-2011-1911" ], "details": "JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfp9-8qrm-4pcx/GHSA-xfp9-8qrm-4pcx.json b/advisories/unreviewed/2022/05/GHSA-xfp9-8qrm-4pcx/GHSA-xfp9-8qrm-4pcx.json index 340ef097d32..035169870c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfp9-8qrm-4pcx/GHSA-xfp9-8qrm-4pcx.json +++ b/advisories/unreviewed/2022/05/GHSA-xfp9-8qrm-4pcx/GHSA-xfp9-8qrm-4pcx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgxp-wxpw-r9x6/GHSA-xgxp-wxpw-r9x6.json b/advisories/unreviewed/2022/05/GHSA-xgxp-wxpw-r9x6/GHSA-xgxp-wxpw-r9x6.json index 30afa6d1051..a1425f633cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgxp-wxpw-r9x6/GHSA-xgxp-wxpw-r9x6.json +++ b/advisories/unreviewed/2022/05/GHSA-xgxp-wxpw-r9x6/GHSA-xgxp-wxpw-r9x6.json @@ -7,12 +7,8 @@ "CVE-2011-1676" ], "details": "mount in util-linux 2.19 and earlier does not remove the /etc/mtab.tmp file after a failed attempt to add a mount entry, which allows local users to trigger corruption of the /etc/mtab file via multiple invocations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjrv-p75r-gqqr/GHSA-xjrv-p75r-gqqr.json b/advisories/unreviewed/2022/05/GHSA-xjrv-p75r-gqqr/GHSA-xjrv-p75r-gqqr.json index f806d662b9d..7783c440a85 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjrv-p75r-gqqr/GHSA-xjrv-p75r-gqqr.json +++ b/advisories/unreviewed/2022/05/GHSA-xjrv-p75r-gqqr/GHSA-xjrv-p75r-gqqr.json @@ -7,12 +7,8 @@ "CVE-2011-1784" ], "details": "The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.pid, and (3) vrrp.pid files in /var/run/, which allows local users to kill arbitrary processes by writing a PID to one of these files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjx2-8v8q-jccq/GHSA-xjx2-8v8q-jccq.json b/advisories/unreviewed/2022/05/GHSA-xjx2-8v8q-jccq/GHSA-xjx2-8v8q-jccq.json index 35c802b9e9f..fb423c460c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjx2-8v8q-jccq/GHSA-xjx2-8v8q-jccq.json +++ b/advisories/unreviewed/2022/05/GHSA-xjx2-8v8q-jccq/GHSA-xjx2-8v8q-jccq.json @@ -7,12 +7,8 @@ "CVE-2010-3024" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm3v-cqxc-rwgh/GHSA-xm3v-cqxc-rwgh.json b/advisories/unreviewed/2022/05/GHSA-xm3v-cqxc-rwgh/GHSA-xm3v-cqxc-rwgh.json index 68aba7b2365..f51d22c4290 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm3v-cqxc-rwgh/GHSA-xm3v-cqxc-rwgh.json +++ b/advisories/unreviewed/2022/05/GHSA-xm3v-cqxc-rwgh/GHSA-xm3v-cqxc-rwgh.json @@ -7,12 +7,8 @@ "CVE-2011-0437" ], "details": "shared/inc/sql/ssh.php in the SSH accounts management implementation in Domain Technologie Control (DTC) before 0.32.9 allows remote authenticated users to delete arbitrary accounts via the edssh_account parameter in a deletesshaccount Delete action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xm66-mcrg-rgjf/GHSA-xm66-mcrg-rgjf.json b/advisories/unreviewed/2022/05/GHSA-xm66-mcrg-rgjf/GHSA-xm66-mcrg-rgjf.json index 9eb09e7f799..f055c33b57a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm66-mcrg-rgjf/GHSA-xm66-mcrg-rgjf.json +++ b/advisories/unreviewed/2022/05/GHSA-xm66-mcrg-rgjf/GHSA-xm66-mcrg-rgjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xmpq-jvm5-c452/GHSA-xmpq-jvm5-c452.json b/advisories/unreviewed/2022/05/GHSA-xmpq-jvm5-c452/GHSA-xmpq-jvm5-c452.json index 0032469360d..f2dbe5ba211 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmpq-jvm5-c452/GHSA-xmpq-jvm5-c452.json +++ b/advisories/unreviewed/2022/05/GHSA-xmpq-jvm5-c452/GHSA-xmpq-jvm5-c452.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqp7-4r9c-vqq2/GHSA-xqp7-4r9c-vqq2.json b/advisories/unreviewed/2022/05/GHSA-xqp7-4r9c-vqq2/GHSA-xqp7-4r9c-vqq2.json index eea16e33d19..371d45eab17 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqp7-4r9c-vqq2/GHSA-xqp7-4r9c-vqq2.json +++ b/advisories/unreviewed/2022/05/GHSA-xqp7-4r9c-vqq2/GHSA-xqp7-4r9c-vqq2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr4g-93qp-pf58/GHSA-xr4g-93qp-pf58.json b/advisories/unreviewed/2022/05/GHSA-xr4g-93qp-pf58/GHSA-xr4g-93qp-pf58.json index e148a8aeae1..32b48b8f3a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr4g-93qp-pf58/GHSA-xr4g-93qp-pf58.json +++ b/advisories/unreviewed/2022/05/GHSA-xr4g-93qp-pf58/GHSA-xr4g-93qp-pf58.json @@ -7,12 +7,8 @@ "CVE-2011-0458" ], "details": "Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xr9g-g7xh-rw7g/GHSA-xr9g-g7xh-rw7g.json b/advisories/unreviewed/2022/05/GHSA-xr9g-g7xh-rw7g/GHSA-xr9g-g7xh-rw7g.json index 5d79e783c0d..063c5522d27 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr9g-g7xh-rw7g/GHSA-xr9g-g7xh-rw7g.json +++ b/advisories/unreviewed/2022/05/GHSA-xr9g-g7xh-rw7g/GHSA-xr9g-g7xh-rw7g.json @@ -7,12 +7,8 @@ "CVE-2011-1739" ], "details": "The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances via an NFS mount request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xrvp-4p2v-gq5h/GHSA-xrvp-4p2v-gq5h.json b/advisories/unreviewed/2022/05/GHSA-xrvp-4p2v-gq5h/GHSA-xrvp-4p2v-gq5h.json index f6fbaea3099..288846378a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrvp-4p2v-gq5h/GHSA-xrvp-4p2v-gq5h.json +++ b/advisories/unreviewed/2022/05/GHSA-xrvp-4p2v-gq5h/GHSA-xrvp-4p2v-gq5h.json @@ -7,12 +7,8 @@ "CVE-2011-0389" ], "details": "Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allow remote attackers to cause a denial of service (process crash) via a crafted Real-Time Transport Control Protocol (RTCP) UDP packet, aka Bug ID CSCth60993.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xv2x-75x9-84vr/GHSA-xv2x-75x9-84vr.json b/advisories/unreviewed/2022/05/GHSA-xv2x-75x9-84vr/GHSA-xv2x-75x9-84vr.json index a5df32ffacb..0a0d593bfd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv2x-75x9-84vr/GHSA-xv2x-75x9-84vr.json +++ b/advisories/unreviewed/2022/05/GHSA-xv2x-75x9-84vr/GHSA-xv2x-75x9-84vr.json @@ -7,12 +7,8 @@ "CVE-2011-1513" ], "details": "Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvx3-whgp-7rq7/GHSA-xvx3-whgp-7rq7.json b/advisories/unreviewed/2022/05/GHSA-xvx3-whgp-7rq7/GHSA-xvx3-whgp-7rq7.json index 5d0a1408afc..d5f1095f89f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvx3-whgp-7rq7/GHSA-xvx3-whgp-7rq7.json +++ b/advisories/unreviewed/2022/05/GHSA-xvx3-whgp-7rq7/GHSA-xvx3-whgp-7rq7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xw8q-7hw6-59rg/GHSA-xw8q-7hw6-59rg.json b/advisories/unreviewed/2022/05/GHSA-xw8q-7hw6-59rg/GHSA-xw8q-7hw6-59rg.json index 16d1d4d262a..dce5791757d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw8q-7hw6-59rg/GHSA-xw8q-7hw6-59rg.json +++ b/advisories/unreviewed/2022/05/GHSA-xw8q-7hw6-59rg/GHSA-xw8q-7hw6-59rg.json @@ -7,12 +7,8 @@ "CVE-2011-1663" ], "details": "SQL injection vulnerability in the Translation Management module 6.x before 6.x-1.21 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwc2-2xh3-v7qg/GHSA-xwc2-2xh3-v7qg.json b/advisories/unreviewed/2022/05/GHSA-xwc2-2xh3-v7qg/GHSA-xwc2-2xh3-v7qg.json index 06b50f75188..ee3056a3ea5 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwc2-2xh3-v7qg/GHSA-xwc2-2xh3-v7qg.json +++ b/advisories/unreviewed/2022/05/GHSA-xwc2-2xh3-v7qg/GHSA-xwc2-2xh3-v7qg.json @@ -7,12 +7,8 @@ "CVE-2011-0490" ], "details": "Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha makes calls to Libevent within Libevent log handlers, which might allow remote attackers to cause a denial of service (daemon crash) via vectors that trigger certain log messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-88h4-6224-7659/GHSA-88h4-6224-7659.json b/advisories/unreviewed/2023/07/GHSA-88h4-6224-7659/GHSA-88h4-6224-7659.json index 465179d7a36..012c7e8d84f 100644 --- a/advisories/unreviewed/2023/07/GHSA-88h4-6224-7659/GHSA-88h4-6224-7659.json +++ b/advisories/unreviewed/2023/07/GHSA-88h4-6224-7659/GHSA-88h4-6224-7659.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-2r4q-h9qr-qqjp/GHSA-2r4q-h9qr-qqjp.json b/advisories/unreviewed/2023/08/GHSA-2r4q-h9qr-qqjp/GHSA-2r4q-h9qr-qqjp.json index 4fc0cd6c4d9..062c34ee457 100644 --- a/advisories/unreviewed/2023/08/GHSA-2r4q-h9qr-qqjp/GHSA-2r4q-h9qr-qqjp.json +++ b/advisories/unreviewed/2023/08/GHSA-2r4q-h9qr-qqjp/GHSA-2r4q-h9qr-qqjp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-3f5p-gg24-f77h/GHSA-3f5p-gg24-f77h.json b/advisories/unreviewed/2023/08/GHSA-3f5p-gg24-f77h/GHSA-3f5p-gg24-f77h.json index 0598434183d..4498660704a 100644 --- a/advisories/unreviewed/2023/08/GHSA-3f5p-gg24-f77h/GHSA-3f5p-gg24-f77h.json +++ b/advisories/unreviewed/2023/08/GHSA-3f5p-gg24-f77h/GHSA-3f5p-gg24-f77h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-3p92-26vx-7f7j/GHSA-3p92-26vx-7f7j.json b/advisories/unreviewed/2023/08/GHSA-3p92-26vx-7f7j/GHSA-3p92-26vx-7f7j.json index 34e71d9aa26..71f2ecabccd 100644 --- a/advisories/unreviewed/2023/08/GHSA-3p92-26vx-7f7j/GHSA-3p92-26vx-7f7j.json +++ b/advisories/unreviewed/2023/08/GHSA-3p92-26vx-7f7j/GHSA-3p92-26vx-7f7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-3rxg-298f-hp3q/GHSA-3rxg-298f-hp3q.json b/advisories/unreviewed/2023/08/GHSA-3rxg-298f-hp3q/GHSA-3rxg-298f-hp3q.json index 500a4f92d02..63acfebc49d 100644 --- a/advisories/unreviewed/2023/08/GHSA-3rxg-298f-hp3q/GHSA-3rxg-298f-hp3q.json +++ b/advisories/unreviewed/2023/08/GHSA-3rxg-298f-hp3q/GHSA-3rxg-298f-hp3q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-5g5r-9pxv-4v7g/GHSA-5g5r-9pxv-4v7g.json b/advisories/unreviewed/2023/08/GHSA-5g5r-9pxv-4v7g/GHSA-5g5r-9pxv-4v7g.json index 5f890cbd8f6..d1d4185e624 100644 --- a/advisories/unreviewed/2023/08/GHSA-5g5r-9pxv-4v7g/GHSA-5g5r-9pxv-4v7g.json +++ b/advisories/unreviewed/2023/08/GHSA-5g5r-9pxv-4v7g/GHSA-5g5r-9pxv-4v7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-695q-j34x-vcjq/GHSA-695q-j34x-vcjq.json b/advisories/unreviewed/2023/08/GHSA-695q-j34x-vcjq/GHSA-695q-j34x-vcjq.json index 2ff0133a612..74c59b3d98e 100644 --- a/advisories/unreviewed/2023/08/GHSA-695q-j34x-vcjq/GHSA-695q-j34x-vcjq.json +++ b/advisories/unreviewed/2023/08/GHSA-695q-j34x-vcjq/GHSA-695q-j34x-vcjq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-7988-2cjh-wqjr/GHSA-7988-2cjh-wqjr.json b/advisories/unreviewed/2023/08/GHSA-7988-2cjh-wqjr/GHSA-7988-2cjh-wqjr.json index 5be346fe76e..a08dc72b389 100644 --- a/advisories/unreviewed/2023/08/GHSA-7988-2cjh-wqjr/GHSA-7988-2cjh-wqjr.json +++ b/advisories/unreviewed/2023/08/GHSA-7988-2cjh-wqjr/GHSA-7988-2cjh-wqjr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-7q3f-vpx9-359h/GHSA-7q3f-vpx9-359h.json b/advisories/unreviewed/2023/08/GHSA-7q3f-vpx9-359h/GHSA-7q3f-vpx9-359h.json index bd7a91e81d1..f9070817d1b 100644 --- a/advisories/unreviewed/2023/08/GHSA-7q3f-vpx9-359h/GHSA-7q3f-vpx9-359h.json +++ b/advisories/unreviewed/2023/08/GHSA-7q3f-vpx9-359h/GHSA-7q3f-vpx9-359h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-8qg9-9fqc-xjj6/GHSA-8qg9-9fqc-xjj6.json b/advisories/unreviewed/2023/08/GHSA-8qg9-9fqc-xjj6/GHSA-8qg9-9fqc-xjj6.json index a76c926a8ac..1aec409a323 100644 --- a/advisories/unreviewed/2023/08/GHSA-8qg9-9fqc-xjj6/GHSA-8qg9-9fqc-xjj6.json +++ b/advisories/unreviewed/2023/08/GHSA-8qg9-9fqc-xjj6/GHSA-8qg9-9fqc-xjj6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-8vvw-5p96-3whf/GHSA-8vvw-5p96-3whf.json b/advisories/unreviewed/2023/08/GHSA-8vvw-5p96-3whf/GHSA-8vvw-5p96-3whf.json index 19180cb1418..7426b60e77b 100644 --- a/advisories/unreviewed/2023/08/GHSA-8vvw-5p96-3whf/GHSA-8vvw-5p96-3whf.json +++ b/advisories/unreviewed/2023/08/GHSA-8vvw-5p96-3whf/GHSA-8vvw-5p96-3whf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-c3g6-xrx4-3q8c/GHSA-c3g6-xrx4-3q8c.json b/advisories/unreviewed/2023/08/GHSA-c3g6-xrx4-3q8c/GHSA-c3g6-xrx4-3q8c.json index cc9dca529c3..fa2315c49d9 100644 --- a/advisories/unreviewed/2023/08/GHSA-c3g6-xrx4-3q8c/GHSA-c3g6-xrx4-3q8c.json +++ b/advisories/unreviewed/2023/08/GHSA-c3g6-xrx4-3q8c/GHSA-c3g6-xrx4-3q8c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-fx57-9rp5-hqmv/GHSA-fx57-9rp5-hqmv.json b/advisories/unreviewed/2023/08/GHSA-fx57-9rp5-hqmv/GHSA-fx57-9rp5-hqmv.json index 5a7cd48ecca..1a3ecfa82fd 100644 --- a/advisories/unreviewed/2023/08/GHSA-fx57-9rp5-hqmv/GHSA-fx57-9rp5-hqmv.json +++ b/advisories/unreviewed/2023/08/GHSA-fx57-9rp5-hqmv/GHSA-fx57-9rp5-hqmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-g4qr-w38q-pxrw/GHSA-g4qr-w38q-pxrw.json b/advisories/unreviewed/2023/08/GHSA-g4qr-w38q-pxrw/GHSA-g4qr-w38q-pxrw.json index fea10cdf56b..26b02f1573f 100644 --- a/advisories/unreviewed/2023/08/GHSA-g4qr-w38q-pxrw/GHSA-g4qr-w38q-pxrw.json +++ b/advisories/unreviewed/2023/08/GHSA-g4qr-w38q-pxrw/GHSA-g4qr-w38q-pxrw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-gjj9-765f-28v4/GHSA-gjj9-765f-28v4.json b/advisories/unreviewed/2023/08/GHSA-gjj9-765f-28v4/GHSA-gjj9-765f-28v4.json index b594571fe5d..3d094278376 100644 --- a/advisories/unreviewed/2023/08/GHSA-gjj9-765f-28v4/GHSA-gjj9-765f-28v4.json +++ b/advisories/unreviewed/2023/08/GHSA-gjj9-765f-28v4/GHSA-gjj9-765f-28v4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-m867-f2x7-hf3g/GHSA-m867-f2x7-hf3g.json b/advisories/unreviewed/2023/08/GHSA-m867-f2x7-hf3g/GHSA-m867-f2x7-hf3g.json index c44b6e39332..953ef4e1b08 100644 --- a/advisories/unreviewed/2023/08/GHSA-m867-f2x7-hf3g/GHSA-m867-f2x7-hf3g.json +++ b/advisories/unreviewed/2023/08/GHSA-m867-f2x7-hf3g/GHSA-m867-f2x7-hf3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-mwj3-42r4-52rx/GHSA-mwj3-42r4-52rx.json b/advisories/unreviewed/2023/08/GHSA-mwj3-42r4-52rx/GHSA-mwj3-42r4-52rx.json index ada8ddafab1..3c123f735b9 100644 --- a/advisories/unreviewed/2023/08/GHSA-mwj3-42r4-52rx/GHSA-mwj3-42r4-52rx.json +++ b/advisories/unreviewed/2023/08/GHSA-mwj3-42r4-52rx/GHSA-mwj3-42r4-52rx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-p3rg-vmcm-jwv4/GHSA-p3rg-vmcm-jwv4.json b/advisories/unreviewed/2023/08/GHSA-p3rg-vmcm-jwv4/GHSA-p3rg-vmcm-jwv4.json index 9c73ad0ab4f..f45559bf21c 100644 --- a/advisories/unreviewed/2023/08/GHSA-p3rg-vmcm-jwv4/GHSA-p3rg-vmcm-jwv4.json +++ b/advisories/unreviewed/2023/08/GHSA-p3rg-vmcm-jwv4/GHSA-p3rg-vmcm-jwv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-p8r8-49jx-w65g/GHSA-p8r8-49jx-w65g.json b/advisories/unreviewed/2023/08/GHSA-p8r8-49jx-w65g/GHSA-p8r8-49jx-w65g.json index cc96f557a32..1e078431d14 100644 --- a/advisories/unreviewed/2023/08/GHSA-p8r8-49jx-w65g/GHSA-p8r8-49jx-w65g.json +++ b/advisories/unreviewed/2023/08/GHSA-p8r8-49jx-w65g/GHSA-p8r8-49jx-w65g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-q4f5-fxmm-4mqw/GHSA-q4f5-fxmm-4mqw.json b/advisories/unreviewed/2023/08/GHSA-q4f5-fxmm-4mqw/GHSA-q4f5-fxmm-4mqw.json index 25794012652..6876af3aa00 100644 --- a/advisories/unreviewed/2023/08/GHSA-q4f5-fxmm-4mqw/GHSA-q4f5-fxmm-4mqw.json +++ b/advisories/unreviewed/2023/08/GHSA-q4f5-fxmm-4mqw/GHSA-q4f5-fxmm-4mqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-qq6h-h8q7-3pg5/GHSA-qq6h-h8q7-3pg5.json b/advisories/unreviewed/2023/08/GHSA-qq6h-h8q7-3pg5/GHSA-qq6h-h8q7-3pg5.json index 277031f2e40..3aa4ca37048 100644 --- a/advisories/unreviewed/2023/08/GHSA-qq6h-h8q7-3pg5/GHSA-qq6h-h8q7-3pg5.json +++ b/advisories/unreviewed/2023/08/GHSA-qq6h-h8q7-3pg5/GHSA-qq6h-h8q7-3pg5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-r8qv-5mc6-cp4c/GHSA-r8qv-5mc6-cp4c.json b/advisories/unreviewed/2023/08/GHSA-r8qv-5mc6-cp4c/GHSA-r8qv-5mc6-cp4c.json index b5f962f63ca..39c00bca426 100644 --- a/advisories/unreviewed/2023/08/GHSA-r8qv-5mc6-cp4c/GHSA-r8qv-5mc6-cp4c.json +++ b/advisories/unreviewed/2023/08/GHSA-r8qv-5mc6-cp4c/GHSA-r8qv-5mc6-cp4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-v2v6-82m7-wwrr/GHSA-v2v6-82m7-wwrr.json b/advisories/unreviewed/2023/08/GHSA-v2v6-82m7-wwrr/GHSA-v2v6-82m7-wwrr.json index 40e5642e89e..14bb823aee9 100644 --- a/advisories/unreviewed/2023/08/GHSA-v2v6-82m7-wwrr/GHSA-v2v6-82m7-wwrr.json +++ b/advisories/unreviewed/2023/08/GHSA-v2v6-82m7-wwrr/GHSA-v2v6-82m7-wwrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-vvmm-p3f9-wx7p/GHSA-vvmm-p3f9-wx7p.json b/advisories/unreviewed/2023/08/GHSA-vvmm-p3f9-wx7p/GHSA-vvmm-p3f9-wx7p.json index 97444a03e48..12178084303 100644 --- a/advisories/unreviewed/2023/08/GHSA-vvmm-p3f9-wx7p/GHSA-vvmm-p3f9-wx7p.json +++ b/advisories/unreviewed/2023/08/GHSA-vvmm-p3f9-wx7p/GHSA-vvmm-p3f9-wx7p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-wpmv-5vqj-jc9f/GHSA-wpmv-5vqj-jc9f.json b/advisories/unreviewed/2023/08/GHSA-wpmv-5vqj-jc9f/GHSA-wpmv-5vqj-jc9f.json index 3811c1b3d16..772fe1394dc 100644 --- a/advisories/unreviewed/2023/08/GHSA-wpmv-5vqj-jc9f/GHSA-wpmv-5vqj-jc9f.json +++ b/advisories/unreviewed/2023/08/GHSA-wpmv-5vqj-jc9f/GHSA-wpmv-5vqj-jc9f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-wrhq-63m5-3pfr/GHSA-wrhq-63m5-3pfr.json b/advisories/unreviewed/2023/08/GHSA-wrhq-63m5-3pfr/GHSA-wrhq-63m5-3pfr.json index e9aa8327227..d2ad0c3900b 100644 --- a/advisories/unreviewed/2023/08/GHSA-wrhq-63m5-3pfr/GHSA-wrhq-63m5-3pfr.json +++ b/advisories/unreviewed/2023/08/GHSA-wrhq-63m5-3pfr/GHSA-wrhq-63m5-3pfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-xm6r-7vj6-hr5j/GHSA-xm6r-7vj6-hr5j.json b/advisories/unreviewed/2023/08/GHSA-xm6r-7vj6-hr5j/GHSA-xm6r-7vj6-hr5j.json index bec9b7b4d98..3592010a4f9 100644 --- a/advisories/unreviewed/2023/08/GHSA-xm6r-7vj6-hr5j/GHSA-xm6r-7vj6-hr5j.json +++ b/advisories/unreviewed/2023/08/GHSA-xm6r-7vj6-hr5j/GHSA-xm6r-7vj6-hr5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-23xx-r9hm-q9g9/GHSA-23xx-r9hm-q9g9.json b/advisories/unreviewed/2023/09/GHSA-23xx-r9hm-q9g9/GHSA-23xx-r9hm-q9g9.json index 1a14ac644e4..a97a2f1f8cc 100644 --- a/advisories/unreviewed/2023/09/GHSA-23xx-r9hm-q9g9/GHSA-23xx-r9hm-q9g9.json +++ b/advisories/unreviewed/2023/09/GHSA-23xx-r9hm-q9g9/GHSA-23xx-r9hm-q9g9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-2h72-wjmg-q2hg/GHSA-2h72-wjmg-q2hg.json b/advisories/unreviewed/2023/09/GHSA-2h72-wjmg-q2hg/GHSA-2h72-wjmg-q2hg.json index c0b56f57782..ca18a26b6f7 100644 --- a/advisories/unreviewed/2023/09/GHSA-2h72-wjmg-q2hg/GHSA-2h72-wjmg-q2hg.json +++ b/advisories/unreviewed/2023/09/GHSA-2h72-wjmg-q2hg/GHSA-2h72-wjmg-q2hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-2hg9-5m5v-wmhr/GHSA-2hg9-5m5v-wmhr.json b/advisories/unreviewed/2023/09/GHSA-2hg9-5m5v-wmhr/GHSA-2hg9-5m5v-wmhr.json index 7f098072a01..d01d6b4044d 100644 --- a/advisories/unreviewed/2023/09/GHSA-2hg9-5m5v-wmhr/GHSA-2hg9-5m5v-wmhr.json +++ b/advisories/unreviewed/2023/09/GHSA-2hg9-5m5v-wmhr/GHSA-2hg9-5m5v-wmhr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-348j-ghgq-g3hj/GHSA-348j-ghgq-g3hj.json b/advisories/unreviewed/2023/09/GHSA-348j-ghgq-g3hj/GHSA-348j-ghgq-g3hj.json index aea4789bc8c..43b52bfdeb2 100644 --- a/advisories/unreviewed/2023/09/GHSA-348j-ghgq-g3hj/GHSA-348j-ghgq-g3hj.json +++ b/advisories/unreviewed/2023/09/GHSA-348j-ghgq-g3hj/GHSA-348j-ghgq-g3hj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-3m3j-wxmw-vm2c/GHSA-3m3j-wxmw-vm2c.json b/advisories/unreviewed/2023/09/GHSA-3m3j-wxmw-vm2c/GHSA-3m3j-wxmw-vm2c.json index 98f8d269409..39357b47fda 100644 --- a/advisories/unreviewed/2023/09/GHSA-3m3j-wxmw-vm2c/GHSA-3m3j-wxmw-vm2c.json +++ b/advisories/unreviewed/2023/09/GHSA-3m3j-wxmw-vm2c/GHSA-3m3j-wxmw-vm2c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json b/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json index 24e6e42f4b4..8fb0bceebd8 100644 --- a/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json +++ b/advisories/unreviewed/2023/09/GHSA-3r84-hhrv-2935/GHSA-3r84-hhrv-2935.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-3w3w-2hqv-65f8/GHSA-3w3w-2hqv-65f8.json b/advisories/unreviewed/2023/09/GHSA-3w3w-2hqv-65f8/GHSA-3w3w-2hqv-65f8.json index 7176c03cb9c..51d3514ddce 100644 --- a/advisories/unreviewed/2023/09/GHSA-3w3w-2hqv-65f8/GHSA-3w3w-2hqv-65f8.json +++ b/advisories/unreviewed/2023/09/GHSA-3w3w-2hqv-65f8/GHSA-3w3w-2hqv-65f8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-3wvr-c56w-pv39/GHSA-3wvr-c56w-pv39.json b/advisories/unreviewed/2023/09/GHSA-3wvr-c56w-pv39/GHSA-3wvr-c56w-pv39.json index a1a719b69ec..db5a45ed217 100644 --- a/advisories/unreviewed/2023/09/GHSA-3wvr-c56w-pv39/GHSA-3wvr-c56w-pv39.json +++ b/advisories/unreviewed/2023/09/GHSA-3wvr-c56w-pv39/GHSA-3wvr-c56w-pv39.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-48cj-hmgx-8f7h/GHSA-48cj-hmgx-8f7h.json b/advisories/unreviewed/2023/09/GHSA-48cj-hmgx-8f7h/GHSA-48cj-hmgx-8f7h.json index d3e04959790..e1041c45b99 100644 --- a/advisories/unreviewed/2023/09/GHSA-48cj-hmgx-8f7h/GHSA-48cj-hmgx-8f7h.json +++ b/advisories/unreviewed/2023/09/GHSA-48cj-hmgx-8f7h/GHSA-48cj-hmgx-8f7h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-48gj-fq9q-g4j7/GHSA-48gj-fq9q-g4j7.json b/advisories/unreviewed/2023/09/GHSA-48gj-fq9q-g4j7/GHSA-48gj-fq9q-g4j7.json index f1f80dd4227..0560c12c186 100644 --- a/advisories/unreviewed/2023/09/GHSA-48gj-fq9q-g4j7/GHSA-48gj-fq9q-g4j7.json +++ b/advisories/unreviewed/2023/09/GHSA-48gj-fq9q-g4j7/GHSA-48gj-fq9q-g4j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-52x5-j3x8-48hp/GHSA-52x5-j3x8-48hp.json b/advisories/unreviewed/2023/09/GHSA-52x5-j3x8-48hp/GHSA-52x5-j3x8-48hp.json index 57dd901608b..9313b530584 100644 --- a/advisories/unreviewed/2023/09/GHSA-52x5-j3x8-48hp/GHSA-52x5-j3x8-48hp.json +++ b/advisories/unreviewed/2023/09/GHSA-52x5-j3x8-48hp/GHSA-52x5-j3x8-48hp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-55hg-f2gx-jqr7/GHSA-55hg-f2gx-jqr7.json b/advisories/unreviewed/2023/09/GHSA-55hg-f2gx-jqr7/GHSA-55hg-f2gx-jqr7.json index fabb5f11108..9c9c989927d 100644 --- a/advisories/unreviewed/2023/09/GHSA-55hg-f2gx-jqr7/GHSA-55hg-f2gx-jqr7.json +++ b/advisories/unreviewed/2023/09/GHSA-55hg-f2gx-jqr7/GHSA-55hg-f2gx-jqr7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-587m-w2mv-x5j7/GHSA-587m-w2mv-x5j7.json b/advisories/unreviewed/2023/09/GHSA-587m-w2mv-x5j7/GHSA-587m-w2mv-x5j7.json index ad07bf5946e..130775e0145 100644 --- a/advisories/unreviewed/2023/09/GHSA-587m-w2mv-x5j7/GHSA-587m-w2mv-x5j7.json +++ b/advisories/unreviewed/2023/09/GHSA-587m-w2mv-x5j7/GHSA-587m-w2mv-x5j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-5f2g-4wwf-xc25/GHSA-5f2g-4wwf-xc25.json b/advisories/unreviewed/2023/09/GHSA-5f2g-4wwf-xc25/GHSA-5f2g-4wwf-xc25.json index 68ef9c02f06..76f31272213 100644 --- a/advisories/unreviewed/2023/09/GHSA-5f2g-4wwf-xc25/GHSA-5f2g-4wwf-xc25.json +++ b/advisories/unreviewed/2023/09/GHSA-5f2g-4wwf-xc25/GHSA-5f2g-4wwf-xc25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-5h3v-c93c-9gh7/GHSA-5h3v-c93c-9gh7.json b/advisories/unreviewed/2023/09/GHSA-5h3v-c93c-9gh7/GHSA-5h3v-c93c-9gh7.json index 8667c39abda..d9be0ea36a5 100644 --- a/advisories/unreviewed/2023/09/GHSA-5h3v-c93c-9gh7/GHSA-5h3v-c93c-9gh7.json +++ b/advisories/unreviewed/2023/09/GHSA-5h3v-c93c-9gh7/GHSA-5h3v-c93c-9gh7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-5ph3-mr96-8v94/GHSA-5ph3-mr96-8v94.json b/advisories/unreviewed/2023/09/GHSA-5ph3-mr96-8v94/GHSA-5ph3-mr96-8v94.json index 499a552db0f..fea17dc25c3 100644 --- a/advisories/unreviewed/2023/09/GHSA-5ph3-mr96-8v94/GHSA-5ph3-mr96-8v94.json +++ b/advisories/unreviewed/2023/09/GHSA-5ph3-mr96-8v94/GHSA-5ph3-mr96-8v94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-5w42-6c5v-phmf/GHSA-5w42-6c5v-phmf.json b/advisories/unreviewed/2023/09/GHSA-5w42-6c5v-phmf/GHSA-5w42-6c5v-phmf.json index 7bd82fe1581..eb7a47972a2 100644 --- a/advisories/unreviewed/2023/09/GHSA-5w42-6c5v-phmf/GHSA-5w42-6c5v-phmf.json +++ b/advisories/unreviewed/2023/09/GHSA-5w42-6c5v-phmf/GHSA-5w42-6c5v-phmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-7xxv-8q2p-34g3/GHSA-7xxv-8q2p-34g3.json b/advisories/unreviewed/2023/09/GHSA-7xxv-8q2p-34g3/GHSA-7xxv-8q2p-34g3.json index 22fd73db9e3..fc567f6a004 100644 --- a/advisories/unreviewed/2023/09/GHSA-7xxv-8q2p-34g3/GHSA-7xxv-8q2p-34g3.json +++ b/advisories/unreviewed/2023/09/GHSA-7xxv-8q2p-34g3/GHSA-7xxv-8q2p-34g3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-8758-wxjc-xqrh/GHSA-8758-wxjc-xqrh.json b/advisories/unreviewed/2023/09/GHSA-8758-wxjc-xqrh/GHSA-8758-wxjc-xqrh.json index d5c38c78949..dbbc3a056a1 100644 --- a/advisories/unreviewed/2023/09/GHSA-8758-wxjc-xqrh/GHSA-8758-wxjc-xqrh.json +++ b/advisories/unreviewed/2023/09/GHSA-8758-wxjc-xqrh/GHSA-8758-wxjc-xqrh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-8x9q-p82f-q5gx/GHSA-8x9q-p82f-q5gx.json b/advisories/unreviewed/2023/09/GHSA-8x9q-p82f-q5gx/GHSA-8x9q-p82f-q5gx.json index 20d3c730182..666d21aaeda 100644 --- a/advisories/unreviewed/2023/09/GHSA-8x9q-p82f-q5gx/GHSA-8x9q-p82f-q5gx.json +++ b/advisories/unreviewed/2023/09/GHSA-8x9q-p82f-q5gx/GHSA-8x9q-p82f-q5gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-92qm-237g-crfp/GHSA-92qm-237g-crfp.json b/advisories/unreviewed/2023/09/GHSA-92qm-237g-crfp/GHSA-92qm-237g-crfp.json index 6ee9d89402a..f3f5aa37888 100644 --- a/advisories/unreviewed/2023/09/GHSA-92qm-237g-crfp/GHSA-92qm-237g-crfp.json +++ b/advisories/unreviewed/2023/09/GHSA-92qm-237g-crfp/GHSA-92qm-237g-crfp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-95xr-xpj5-h4g4/GHSA-95xr-xpj5-h4g4.json b/advisories/unreviewed/2023/09/GHSA-95xr-xpj5-h4g4/GHSA-95xr-xpj5-h4g4.json index 1598b78e243..5794af8518b 100644 --- a/advisories/unreviewed/2023/09/GHSA-95xr-xpj5-h4g4/GHSA-95xr-xpj5-h4g4.json +++ b/advisories/unreviewed/2023/09/GHSA-95xr-xpj5-h4g4/GHSA-95xr-xpj5-h4g4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-974r-7wqw-f9j9/GHSA-974r-7wqw-f9j9.json b/advisories/unreviewed/2023/09/GHSA-974r-7wqw-f9j9/GHSA-974r-7wqw-f9j9.json index 7ce5aa714b2..b7b135f7cff 100644 --- a/advisories/unreviewed/2023/09/GHSA-974r-7wqw-f9j9/GHSA-974r-7wqw-f9j9.json +++ b/advisories/unreviewed/2023/09/GHSA-974r-7wqw-f9j9/GHSA-974r-7wqw-f9j9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-9hhj-7pgp-fvc5/GHSA-9hhj-7pgp-fvc5.json b/advisories/unreviewed/2023/09/GHSA-9hhj-7pgp-fvc5/GHSA-9hhj-7pgp-fvc5.json index 46b8a94018e..e18cbfffd9f 100644 --- a/advisories/unreviewed/2023/09/GHSA-9hhj-7pgp-fvc5/GHSA-9hhj-7pgp-fvc5.json +++ b/advisories/unreviewed/2023/09/GHSA-9hhj-7pgp-fvc5/GHSA-9hhj-7pgp-fvc5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-9rfw-qc4x-5385/GHSA-9rfw-qc4x-5385.json b/advisories/unreviewed/2023/09/GHSA-9rfw-qc4x-5385/GHSA-9rfw-qc4x-5385.json index 20791efc3d4..5819d53bcd0 100644 --- a/advisories/unreviewed/2023/09/GHSA-9rfw-qc4x-5385/GHSA-9rfw-qc4x-5385.json +++ b/advisories/unreviewed/2023/09/GHSA-9rfw-qc4x-5385/GHSA-9rfw-qc4x-5385.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-9v7r-x7cv-v437/GHSA-9v7r-x7cv-v437.json b/advisories/unreviewed/2023/09/GHSA-9v7r-x7cv-v437/GHSA-9v7r-x7cv-v437.json index e4046574493..a8e9d3814ad 100644 --- a/advisories/unreviewed/2023/09/GHSA-9v7r-x7cv-v437/GHSA-9v7r-x7cv-v437.json +++ b/advisories/unreviewed/2023/09/GHSA-9v7r-x7cv-v437/GHSA-9v7r-x7cv-v437.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-9xcg-3948-4766/GHSA-9xcg-3948-4766.json b/advisories/unreviewed/2023/09/GHSA-9xcg-3948-4766/GHSA-9xcg-3948-4766.json index 95945c1f011..04c302b1857 100644 --- a/advisories/unreviewed/2023/09/GHSA-9xcg-3948-4766/GHSA-9xcg-3948-4766.json +++ b/advisories/unreviewed/2023/09/GHSA-9xcg-3948-4766/GHSA-9xcg-3948-4766.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-c2rp-g99g-j6gv/GHSA-c2rp-g99g-j6gv.json b/advisories/unreviewed/2023/09/GHSA-c2rp-g99g-j6gv/GHSA-c2rp-g99g-j6gv.json index e73a1994c56..c00b08c9fa2 100644 --- a/advisories/unreviewed/2023/09/GHSA-c2rp-g99g-j6gv/GHSA-c2rp-g99g-j6gv.json +++ b/advisories/unreviewed/2023/09/GHSA-c2rp-g99g-j6gv/GHSA-c2rp-g99g-j6gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-c567-fgv9-j7jc/GHSA-c567-fgv9-j7jc.json b/advisories/unreviewed/2023/09/GHSA-c567-fgv9-j7jc/GHSA-c567-fgv9-j7jc.json index 9c6dc01191b..543ae39b35b 100644 --- a/advisories/unreviewed/2023/09/GHSA-c567-fgv9-j7jc/GHSA-c567-fgv9-j7jc.json +++ b/advisories/unreviewed/2023/09/GHSA-c567-fgv9-j7jc/GHSA-c567-fgv9-j7jc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-c8qw-jpg3-vv7v/GHSA-c8qw-jpg3-vv7v.json b/advisories/unreviewed/2023/09/GHSA-c8qw-jpg3-vv7v/GHSA-c8qw-jpg3-vv7v.json index b0cb17130a6..b41803ff4e3 100644 --- a/advisories/unreviewed/2023/09/GHSA-c8qw-jpg3-vv7v/GHSA-c8qw-jpg3-vv7v.json +++ b/advisories/unreviewed/2023/09/GHSA-c8qw-jpg3-vv7v/GHSA-c8qw-jpg3-vv7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-cm4f-g738-hp2g/GHSA-cm4f-g738-hp2g.json b/advisories/unreviewed/2023/09/GHSA-cm4f-g738-hp2g/GHSA-cm4f-g738-hp2g.json index fa375b4b0a0..5ebc302972d 100644 --- a/advisories/unreviewed/2023/09/GHSA-cm4f-g738-hp2g/GHSA-cm4f-g738-hp2g.json +++ b/advisories/unreviewed/2023/09/GHSA-cm4f-g738-hp2g/GHSA-cm4f-g738-hp2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-fv49-5g7c-gh7p/GHSA-fv49-5g7c-gh7p.json b/advisories/unreviewed/2023/09/GHSA-fv49-5g7c-gh7p/GHSA-fv49-5g7c-gh7p.json index ceabeadd8a1..aa6f9812478 100644 --- a/advisories/unreviewed/2023/09/GHSA-fv49-5g7c-gh7p/GHSA-fv49-5g7c-gh7p.json +++ b/advisories/unreviewed/2023/09/GHSA-fv49-5g7c-gh7p/GHSA-fv49-5g7c-gh7p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-gw2j-8qx6-wpp9/GHSA-gw2j-8qx6-wpp9.json b/advisories/unreviewed/2023/09/GHSA-gw2j-8qx6-wpp9/GHSA-gw2j-8qx6-wpp9.json index 983b9a111aa..0bea4ce631b 100644 --- a/advisories/unreviewed/2023/09/GHSA-gw2j-8qx6-wpp9/GHSA-gw2j-8qx6-wpp9.json +++ b/advisories/unreviewed/2023/09/GHSA-gw2j-8qx6-wpp9/GHSA-gw2j-8qx6-wpp9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-hgrq-77qx-v7gx/GHSA-hgrq-77qx-v7gx.json b/advisories/unreviewed/2023/09/GHSA-hgrq-77qx-v7gx/GHSA-hgrq-77qx-v7gx.json index f1ef5a92028..b08a64a8609 100644 --- a/advisories/unreviewed/2023/09/GHSA-hgrq-77qx-v7gx/GHSA-hgrq-77qx-v7gx.json +++ b/advisories/unreviewed/2023/09/GHSA-hgrq-77qx-v7gx/GHSA-hgrq-77qx-v7gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-hrxx-273v-pgj4/GHSA-hrxx-273v-pgj4.json b/advisories/unreviewed/2023/09/GHSA-hrxx-273v-pgj4/GHSA-hrxx-273v-pgj4.json index c753813cccf..c4525be1421 100644 --- a/advisories/unreviewed/2023/09/GHSA-hrxx-273v-pgj4/GHSA-hrxx-273v-pgj4.json +++ b/advisories/unreviewed/2023/09/GHSA-hrxx-273v-pgj4/GHSA-hrxx-273v-pgj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-j59c-pv3w-ph9q/GHSA-j59c-pv3w-ph9q.json b/advisories/unreviewed/2023/09/GHSA-j59c-pv3w-ph9q/GHSA-j59c-pv3w-ph9q.json index cbac1934b88..14bd4057061 100644 --- a/advisories/unreviewed/2023/09/GHSA-j59c-pv3w-ph9q/GHSA-j59c-pv3w-ph9q.json +++ b/advisories/unreviewed/2023/09/GHSA-j59c-pv3w-ph9q/GHSA-j59c-pv3w-ph9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-j755-gxrc-w73v/GHSA-j755-gxrc-w73v.json b/advisories/unreviewed/2023/09/GHSA-j755-gxrc-w73v/GHSA-j755-gxrc-w73v.json index 04076f77dc5..eb8cfb3c251 100644 --- a/advisories/unreviewed/2023/09/GHSA-j755-gxrc-w73v/GHSA-j755-gxrc-w73v.json +++ b/advisories/unreviewed/2023/09/GHSA-j755-gxrc-w73v/GHSA-j755-gxrc-w73v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-jfv5-v5gm-jvgm/GHSA-jfv5-v5gm-jvgm.json b/advisories/unreviewed/2023/09/GHSA-jfv5-v5gm-jvgm/GHSA-jfv5-v5gm-jvgm.json index 88406cb2ba3..eda882f4cf7 100644 --- a/advisories/unreviewed/2023/09/GHSA-jfv5-v5gm-jvgm/GHSA-jfv5-v5gm-jvgm.json +++ b/advisories/unreviewed/2023/09/GHSA-jfv5-v5gm-jvgm/GHSA-jfv5-v5gm-jvgm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-jhch-w5jq-fhfq/GHSA-jhch-w5jq-fhfq.json b/advisories/unreviewed/2023/09/GHSA-jhch-w5jq-fhfq/GHSA-jhch-w5jq-fhfq.json index 30f3726310c..d7a5d6dd969 100644 --- a/advisories/unreviewed/2023/09/GHSA-jhch-w5jq-fhfq/GHSA-jhch-w5jq-fhfq.json +++ b/advisories/unreviewed/2023/09/GHSA-jhch-w5jq-fhfq/GHSA-jhch-w5jq-fhfq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-p95j-356c-hgx2/GHSA-p95j-356c-hgx2.json b/advisories/unreviewed/2023/09/GHSA-p95j-356c-hgx2/GHSA-p95j-356c-hgx2.json index c06529ba990..509cc978efa 100644 --- a/advisories/unreviewed/2023/09/GHSA-p95j-356c-hgx2/GHSA-p95j-356c-hgx2.json +++ b/advisories/unreviewed/2023/09/GHSA-p95j-356c-hgx2/GHSA-p95j-356c-hgx2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-pjfc-p84w-fwgj/GHSA-pjfc-p84w-fwgj.json b/advisories/unreviewed/2023/09/GHSA-pjfc-p84w-fwgj/GHSA-pjfc-p84w-fwgj.json index 0246b968b2f..a379c4472b7 100644 --- a/advisories/unreviewed/2023/09/GHSA-pjfc-p84w-fwgj/GHSA-pjfc-p84w-fwgj.json +++ b/advisories/unreviewed/2023/09/GHSA-pjfc-p84w-fwgj/GHSA-pjfc-p84w-fwgj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-pqgj-wx7f-6f72/GHSA-pqgj-wx7f-6f72.json b/advisories/unreviewed/2023/09/GHSA-pqgj-wx7f-6f72/GHSA-pqgj-wx7f-6f72.json index 3c122c1285c..319c0114be4 100644 --- a/advisories/unreviewed/2023/09/GHSA-pqgj-wx7f-6f72/GHSA-pqgj-wx7f-6f72.json +++ b/advisories/unreviewed/2023/09/GHSA-pqgj-wx7f-6f72/GHSA-pqgj-wx7f-6f72.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-qj57-gm77-m65m/GHSA-qj57-gm77-m65m.json b/advisories/unreviewed/2023/09/GHSA-qj57-gm77-m65m/GHSA-qj57-gm77-m65m.json index 4247b7199e4..cdfa4dd1d3a 100644 --- a/advisories/unreviewed/2023/09/GHSA-qj57-gm77-m65m/GHSA-qj57-gm77-m65m.json +++ b/advisories/unreviewed/2023/09/GHSA-qj57-gm77-m65m/GHSA-qj57-gm77-m65m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-qr3g-7vmg-24hh/GHSA-qr3g-7vmg-24hh.json b/advisories/unreviewed/2023/09/GHSA-qr3g-7vmg-24hh/GHSA-qr3g-7vmg-24hh.json index 339420e04b6..9b9b06c6def 100644 --- a/advisories/unreviewed/2023/09/GHSA-qr3g-7vmg-24hh/GHSA-qr3g-7vmg-24hh.json +++ b/advisories/unreviewed/2023/09/GHSA-qr3g-7vmg-24hh/GHSA-qr3g-7vmg-24hh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-r97g-mv85-crqf/GHSA-r97g-mv85-crqf.json b/advisories/unreviewed/2023/09/GHSA-r97g-mv85-crqf/GHSA-r97g-mv85-crqf.json index 375a45a7e0b..d144a38f260 100644 --- a/advisories/unreviewed/2023/09/GHSA-r97g-mv85-crqf/GHSA-r97g-mv85-crqf.json +++ b/advisories/unreviewed/2023/09/GHSA-r97g-mv85-crqf/GHSA-r97g-mv85-crqf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-rq33-vcqg-6whp/GHSA-rq33-vcqg-6whp.json b/advisories/unreviewed/2023/09/GHSA-rq33-vcqg-6whp/GHSA-rq33-vcqg-6whp.json index c471aff265d..766c31847e0 100644 --- a/advisories/unreviewed/2023/09/GHSA-rq33-vcqg-6whp/GHSA-rq33-vcqg-6whp.json +++ b/advisories/unreviewed/2023/09/GHSA-rq33-vcqg-6whp/GHSA-rq33-vcqg-6whp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-v82h-vx7v-xprp/GHSA-v82h-vx7v-xprp.json b/advisories/unreviewed/2023/09/GHSA-v82h-vx7v-xprp/GHSA-v82h-vx7v-xprp.json index 742b83d9576..082f4ee3806 100644 --- a/advisories/unreviewed/2023/09/GHSA-v82h-vx7v-xprp/GHSA-v82h-vx7v-xprp.json +++ b/advisories/unreviewed/2023/09/GHSA-v82h-vx7v-xprp/GHSA-v82h-vx7v-xprp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-vgx5-mfp7-c7qj/GHSA-vgx5-mfp7-c7qj.json b/advisories/unreviewed/2023/09/GHSA-vgx5-mfp7-c7qj/GHSA-vgx5-mfp7-c7qj.json index f127808dccb..99cb7017867 100644 --- a/advisories/unreviewed/2023/09/GHSA-vgx5-mfp7-c7qj/GHSA-vgx5-mfp7-c7qj.json +++ b/advisories/unreviewed/2023/09/GHSA-vgx5-mfp7-c7qj/GHSA-vgx5-mfp7-c7qj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-vww5-xjhj-fxmg/GHSA-vww5-xjhj-fxmg.json b/advisories/unreviewed/2023/09/GHSA-vww5-xjhj-fxmg/GHSA-vww5-xjhj-fxmg.json index 30d81b087cb..37dd28c63d0 100644 --- a/advisories/unreviewed/2023/09/GHSA-vww5-xjhj-fxmg/GHSA-vww5-xjhj-fxmg.json +++ b/advisories/unreviewed/2023/09/GHSA-vww5-xjhj-fxmg/GHSA-vww5-xjhj-fxmg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-w64v-g398-2hjx/GHSA-w64v-g398-2hjx.json b/advisories/unreviewed/2023/09/GHSA-w64v-g398-2hjx/GHSA-w64v-g398-2hjx.json index b7492b99a8e..bd544bc21ab 100644 --- a/advisories/unreviewed/2023/09/GHSA-w64v-g398-2hjx/GHSA-w64v-g398-2hjx.json +++ b/advisories/unreviewed/2023/09/GHSA-w64v-g398-2hjx/GHSA-w64v-g398-2hjx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-w9xx-prgq-m734/GHSA-w9xx-prgq-m734.json b/advisories/unreviewed/2023/09/GHSA-w9xx-prgq-m734/GHSA-w9xx-prgq-m734.json index 96df69ba445..473ece0032a 100644 --- a/advisories/unreviewed/2023/09/GHSA-w9xx-prgq-m734/GHSA-w9xx-prgq-m734.json +++ b/advisories/unreviewed/2023/09/GHSA-w9xx-prgq-m734/GHSA-w9xx-prgq-m734.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-wmwj-g626-fj2w/GHSA-wmwj-g626-fj2w.json b/advisories/unreviewed/2023/09/GHSA-wmwj-g626-fj2w/GHSA-wmwj-g626-fj2w.json index 1e6c62d03e3..454182fdd2d 100644 --- a/advisories/unreviewed/2023/09/GHSA-wmwj-g626-fj2w/GHSA-wmwj-g626-fj2w.json +++ b/advisories/unreviewed/2023/09/GHSA-wmwj-g626-fj2w/GHSA-wmwj-g626-fj2w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-x2jc-989c-47q4/GHSA-x2jc-989c-47q4.json b/advisories/unreviewed/2023/09/GHSA-x2jc-989c-47q4/GHSA-x2jc-989c-47q4.json index aba316681e7..011e3b95fbf 100644 --- a/advisories/unreviewed/2023/09/GHSA-x2jc-989c-47q4/GHSA-x2jc-989c-47q4.json +++ b/advisories/unreviewed/2023/09/GHSA-x2jc-989c-47q4/GHSA-x2jc-989c-47q4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-xpgj-rhc7-55qx/GHSA-xpgj-rhc7-55qx.json b/advisories/unreviewed/2023/09/GHSA-xpgj-rhc7-55qx/GHSA-xpgj-rhc7-55qx.json index 158f62ccda5..a75e5c28f1f 100644 --- a/advisories/unreviewed/2023/09/GHSA-xpgj-rhc7-55qx/GHSA-xpgj-rhc7-55qx.json +++ b/advisories/unreviewed/2023/09/GHSA-xpgj-rhc7-55qx/GHSA-xpgj-rhc7-55qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-2v35-g5rr-c2v3/GHSA-2v35-g5rr-c2v3.json b/advisories/unreviewed/2023/10/GHSA-2v35-g5rr-c2v3/GHSA-2v35-g5rr-c2v3.json index 5ae31864a4b..c5f28113ad1 100644 --- a/advisories/unreviewed/2023/10/GHSA-2v35-g5rr-c2v3/GHSA-2v35-g5rr-c2v3.json +++ b/advisories/unreviewed/2023/10/GHSA-2v35-g5rr-c2v3/GHSA-2v35-g5rr-c2v3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-2x4w-j73f-g9qq/GHSA-2x4w-j73f-g9qq.json b/advisories/unreviewed/2023/10/GHSA-2x4w-j73f-g9qq/GHSA-2x4w-j73f-g9qq.json index 50540957954..20da8aa7f27 100644 --- a/advisories/unreviewed/2023/10/GHSA-2x4w-j73f-g9qq/GHSA-2x4w-j73f-g9qq.json +++ b/advisories/unreviewed/2023/10/GHSA-2x4w-j73f-g9qq/GHSA-2x4w-j73f-g9qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json b/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json index f9163d4934c..3b29c86f6cc 100644 --- a/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json +++ b/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-55pc-c7f5-9cxc/GHSA-55pc-c7f5-9cxc.json b/advisories/unreviewed/2023/10/GHSA-55pc-c7f5-9cxc/GHSA-55pc-c7f5-9cxc.json index b0835e85846..26ebb536f65 100644 --- a/advisories/unreviewed/2023/10/GHSA-55pc-c7f5-9cxc/GHSA-55pc-c7f5-9cxc.json +++ b/advisories/unreviewed/2023/10/GHSA-55pc-c7f5-9cxc/GHSA-55pc-c7f5-9cxc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-6733-chfh-xr5v/GHSA-6733-chfh-xr5v.json b/advisories/unreviewed/2023/10/GHSA-6733-chfh-xr5v/GHSA-6733-chfh-xr5v.json index 2464f4c9a03..ed284306fce 100644 --- a/advisories/unreviewed/2023/10/GHSA-6733-chfh-xr5v/GHSA-6733-chfh-xr5v.json +++ b/advisories/unreviewed/2023/10/GHSA-6733-chfh-xr5v/GHSA-6733-chfh-xr5v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-72hp-jh2c-vv79/GHSA-72hp-jh2c-vv79.json b/advisories/unreviewed/2023/10/GHSA-72hp-jh2c-vv79/GHSA-72hp-jh2c-vv79.json index 5dec255230a..002b95523a8 100644 --- a/advisories/unreviewed/2023/10/GHSA-72hp-jh2c-vv79/GHSA-72hp-jh2c-vv79.json +++ b/advisories/unreviewed/2023/10/GHSA-72hp-jh2c-vv79/GHSA-72hp-jh2c-vv79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-826h-3r9h-j2hm/GHSA-826h-3r9h-j2hm.json b/advisories/unreviewed/2023/10/GHSA-826h-3r9h-j2hm/GHSA-826h-3r9h-j2hm.json index c34f0626837..2019ccd8e3f 100644 --- a/advisories/unreviewed/2023/10/GHSA-826h-3r9h-j2hm/GHSA-826h-3r9h-j2hm.json +++ b/advisories/unreviewed/2023/10/GHSA-826h-3r9h-j2hm/GHSA-826h-3r9h-j2hm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-8fpf-jxpx-6gf6/GHSA-8fpf-jxpx-6gf6.json b/advisories/unreviewed/2023/10/GHSA-8fpf-jxpx-6gf6/GHSA-8fpf-jxpx-6gf6.json index ae6c392614f..8092b468f1b 100644 --- a/advisories/unreviewed/2023/10/GHSA-8fpf-jxpx-6gf6/GHSA-8fpf-jxpx-6gf6.json +++ b/advisories/unreviewed/2023/10/GHSA-8fpf-jxpx-6gf6/GHSA-8fpf-jxpx-6gf6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-9983-52gj-4grg/GHSA-9983-52gj-4grg.json b/advisories/unreviewed/2023/10/GHSA-9983-52gj-4grg/GHSA-9983-52gj-4grg.json index bf32e8578c1..57a569d001b 100644 --- a/advisories/unreviewed/2023/10/GHSA-9983-52gj-4grg/GHSA-9983-52gj-4grg.json +++ b/advisories/unreviewed/2023/10/GHSA-9983-52gj-4grg/GHSA-9983-52gj-4grg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-9jh8-9mcr-89jq/GHSA-9jh8-9mcr-89jq.json b/advisories/unreviewed/2023/10/GHSA-9jh8-9mcr-89jq/GHSA-9jh8-9mcr-89jq.json index 5c001cfac55..d5d2fe4202f 100644 --- a/advisories/unreviewed/2023/10/GHSA-9jh8-9mcr-89jq/GHSA-9jh8-9mcr-89jq.json +++ b/advisories/unreviewed/2023/10/GHSA-9jh8-9mcr-89jq/GHSA-9jh8-9mcr-89jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-g8j7-2rhp-x3w4/GHSA-g8j7-2rhp-x3w4.json b/advisories/unreviewed/2023/10/GHSA-g8j7-2rhp-x3w4/GHSA-g8j7-2rhp-x3w4.json index 18e4107ebc2..325e0d0e607 100644 --- a/advisories/unreviewed/2023/10/GHSA-g8j7-2rhp-x3w4/GHSA-g8j7-2rhp-x3w4.json +++ b/advisories/unreviewed/2023/10/GHSA-g8j7-2rhp-x3w4/GHSA-g8j7-2rhp-x3w4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-j3jp-4g73-9xxh/GHSA-j3jp-4g73-9xxh.json b/advisories/unreviewed/2023/10/GHSA-j3jp-4g73-9xxh/GHSA-j3jp-4g73-9xxh.json index 846f4d9b489..fa61766a043 100644 --- a/advisories/unreviewed/2023/10/GHSA-j3jp-4g73-9xxh/GHSA-j3jp-4g73-9xxh.json +++ b/advisories/unreviewed/2023/10/GHSA-j3jp-4g73-9xxh/GHSA-j3jp-4g73-9xxh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-j56p-gcm8-59g5/GHSA-j56p-gcm8-59g5.json b/advisories/unreviewed/2023/10/GHSA-j56p-gcm8-59g5/GHSA-j56p-gcm8-59g5.json index 35f9c2c950b..2c1d0ce09e1 100644 --- a/advisories/unreviewed/2023/10/GHSA-j56p-gcm8-59g5/GHSA-j56p-gcm8-59g5.json +++ b/advisories/unreviewed/2023/10/GHSA-j56p-gcm8-59g5/GHSA-j56p-gcm8-59g5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-jf7p-xvx5-8827/GHSA-jf7p-xvx5-8827.json b/advisories/unreviewed/2023/10/GHSA-jf7p-xvx5-8827/GHSA-jf7p-xvx5-8827.json index 6d74a6c6316..58dc823afbc 100644 --- a/advisories/unreviewed/2023/10/GHSA-jf7p-xvx5-8827/GHSA-jf7p-xvx5-8827.json +++ b/advisories/unreviewed/2023/10/GHSA-jf7p-xvx5-8827/GHSA-jf7p-xvx5-8827.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-jv5p-m99x-6734/GHSA-jv5p-m99x-6734.json b/advisories/unreviewed/2023/10/GHSA-jv5p-m99x-6734/GHSA-jv5p-m99x-6734.json index a7c96fcec52..8c370dffeff 100644 --- a/advisories/unreviewed/2023/10/GHSA-jv5p-m99x-6734/GHSA-jv5p-m99x-6734.json +++ b/advisories/unreviewed/2023/10/GHSA-jv5p-m99x-6734/GHSA-jv5p-m99x-6734.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-m4gf-gh3f-383f/GHSA-m4gf-gh3f-383f.json b/advisories/unreviewed/2023/10/GHSA-m4gf-gh3f-383f/GHSA-m4gf-gh3f-383f.json index b7c1d0f5ef2..b02684615b3 100644 --- a/advisories/unreviewed/2023/10/GHSA-m4gf-gh3f-383f/GHSA-m4gf-gh3f-383f.json +++ b/advisories/unreviewed/2023/10/GHSA-m4gf-gh3f-383f/GHSA-m4gf-gh3f-383f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-m923-pj5j-h9qp/GHSA-m923-pj5j-h9qp.json b/advisories/unreviewed/2023/10/GHSA-m923-pj5j-h9qp/GHSA-m923-pj5j-h9qp.json index 022ebe07f77..8cec1d6e0e5 100644 --- a/advisories/unreviewed/2023/10/GHSA-m923-pj5j-h9qp/GHSA-m923-pj5j-h9qp.json +++ b/advisories/unreviewed/2023/10/GHSA-m923-pj5j-h9qp/GHSA-m923-pj5j-h9qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-pmp4-3p6p-g7xv/GHSA-pmp4-3p6p-g7xv.json b/advisories/unreviewed/2023/10/GHSA-pmp4-3p6p-g7xv/GHSA-pmp4-3p6p-g7xv.json index 1c7896a4094..2c4890acc8b 100644 --- a/advisories/unreviewed/2023/10/GHSA-pmp4-3p6p-g7xv/GHSA-pmp4-3p6p-g7xv.json +++ b/advisories/unreviewed/2023/10/GHSA-pmp4-3p6p-g7xv/GHSA-pmp4-3p6p-g7xv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-pwj3-ccfm-6r93/GHSA-pwj3-ccfm-6r93.json b/advisories/unreviewed/2023/10/GHSA-pwj3-ccfm-6r93/GHSA-pwj3-ccfm-6r93.json index 51fc8b7ad83..83f340e7212 100644 --- a/advisories/unreviewed/2023/10/GHSA-pwj3-ccfm-6r93/GHSA-pwj3-ccfm-6r93.json +++ b/advisories/unreviewed/2023/10/GHSA-pwj3-ccfm-6r93/GHSA-pwj3-ccfm-6r93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-wgjv-rjgv-p6mx/GHSA-wgjv-rjgv-p6mx.json b/advisories/unreviewed/2023/10/GHSA-wgjv-rjgv-p6mx/GHSA-wgjv-rjgv-p6mx.json index dae4e1801e4..fcfb1e99435 100644 --- a/advisories/unreviewed/2023/10/GHSA-wgjv-rjgv-p6mx/GHSA-wgjv-rjgv-p6mx.json +++ b/advisories/unreviewed/2023/10/GHSA-wgjv-rjgv-p6mx/GHSA-wgjv-rjgv-p6mx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-xqw5-p932-5jgr/GHSA-xqw5-p932-5jgr.json b/advisories/unreviewed/2023/10/GHSA-xqw5-p932-5jgr/GHSA-xqw5-p932-5jgr.json index 3168f0cc5e6..819db04a155 100644 --- a/advisories/unreviewed/2023/10/GHSA-xqw5-p932-5jgr/GHSA-xqw5-p932-5jgr.json +++ b/advisories/unreviewed/2023/10/GHSA-xqw5-p932-5jgr/GHSA-xqw5-p932-5jgr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-4696-w7m2-9g4h/GHSA-4696-w7m2-9g4h.json b/advisories/unreviewed/2023/11/GHSA-4696-w7m2-9g4h/GHSA-4696-w7m2-9g4h.json index c179df575f2..eef10a63d4d 100644 --- a/advisories/unreviewed/2023/11/GHSA-4696-w7m2-9g4h/GHSA-4696-w7m2-9g4h.json +++ b/advisories/unreviewed/2023/11/GHSA-4696-w7m2-9g4h/GHSA-4696-w7m2-9g4h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-769q-xhv3-qgqv/GHSA-769q-xhv3-qgqv.json b/advisories/unreviewed/2023/11/GHSA-769q-xhv3-qgqv/GHSA-769q-xhv3-qgqv.json index d6c7f4bfb25..9c7365a8fdd 100644 --- a/advisories/unreviewed/2023/11/GHSA-769q-xhv3-qgqv/GHSA-769q-xhv3-qgqv.json +++ b/advisories/unreviewed/2023/11/GHSA-769q-xhv3-qgqv/GHSA-769q-xhv3-qgqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-9h2f-7xpr-xgq4/GHSA-9h2f-7xpr-xgq4.json b/advisories/unreviewed/2023/11/GHSA-9h2f-7xpr-xgq4/GHSA-9h2f-7xpr-xgq4.json index 88dd4f2280f..06f0ebf7700 100644 --- a/advisories/unreviewed/2023/11/GHSA-9h2f-7xpr-xgq4/GHSA-9h2f-7xpr-xgq4.json +++ b/advisories/unreviewed/2023/11/GHSA-9h2f-7xpr-xgq4/GHSA-9h2f-7xpr-xgq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-vx62-r535-jwqf/GHSA-vx62-r535-jwqf.json b/advisories/unreviewed/2023/11/GHSA-vx62-r535-jwqf/GHSA-vx62-r535-jwqf.json index 23c7d039d13..dd0219b7029 100644 --- a/advisories/unreviewed/2023/11/GHSA-vx62-r535-jwqf/GHSA-vx62-r535-jwqf.json +++ b/advisories/unreviewed/2023/11/GHSA-vx62-r535-jwqf/GHSA-vx62-r535-jwqf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-3569-vj4f-62c6/GHSA-3569-vj4f-62c6.json b/advisories/unreviewed/2023/12/GHSA-3569-vj4f-62c6/GHSA-3569-vj4f-62c6.json index 600a1ba557b..e2afc3685c0 100644 --- a/advisories/unreviewed/2023/12/GHSA-3569-vj4f-62c6/GHSA-3569-vj4f-62c6.json +++ b/advisories/unreviewed/2023/12/GHSA-3569-vj4f-62c6/GHSA-3569-vj4f-62c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-38xw-jx8m-w5wp/GHSA-38xw-jx8m-w5wp.json b/advisories/unreviewed/2023/12/GHSA-38xw-jx8m-w5wp/GHSA-38xw-jx8m-w5wp.json index 182316fac08..96438d9e763 100644 --- a/advisories/unreviewed/2023/12/GHSA-38xw-jx8m-w5wp/GHSA-38xw-jx8m-w5wp.json +++ b/advisories/unreviewed/2023/12/GHSA-38xw-jx8m-w5wp/GHSA-38xw-jx8m-w5wp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-468h-cjv9-mg3h/GHSA-468h-cjv9-mg3h.json b/advisories/unreviewed/2023/12/GHSA-468h-cjv9-mg3h/GHSA-468h-cjv9-mg3h.json index 2a0084c86fa..30a62535d80 100644 --- a/advisories/unreviewed/2023/12/GHSA-468h-cjv9-mg3h/GHSA-468h-cjv9-mg3h.json +++ b/advisories/unreviewed/2023/12/GHSA-468h-cjv9-mg3h/GHSA-468h-cjv9-mg3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-49q5-wf3p-7xv2/GHSA-49q5-wf3p-7xv2.json b/advisories/unreviewed/2023/12/GHSA-49q5-wf3p-7xv2/GHSA-49q5-wf3p-7xv2.json index 85c59c23af2..f3f23cd05ff 100644 --- a/advisories/unreviewed/2023/12/GHSA-49q5-wf3p-7xv2/GHSA-49q5-wf3p-7xv2.json +++ b/advisories/unreviewed/2023/12/GHSA-49q5-wf3p-7xv2/GHSA-49q5-wf3p-7xv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-53qp-xq7m-xppp/GHSA-53qp-xq7m-xppp.json b/advisories/unreviewed/2023/12/GHSA-53qp-xq7m-xppp/GHSA-53qp-xq7m-xppp.json index 3b56bb21dce..ce643595b33 100644 --- a/advisories/unreviewed/2023/12/GHSA-53qp-xq7m-xppp/GHSA-53qp-xq7m-xppp.json +++ b/advisories/unreviewed/2023/12/GHSA-53qp-xq7m-xppp/GHSA-53qp-xq7m-xppp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-7qjm-443c-38h9/GHSA-7qjm-443c-38h9.json b/advisories/unreviewed/2023/12/GHSA-7qjm-443c-38h9/GHSA-7qjm-443c-38h9.json index 426f0394a26..b5c6006b20f 100644 --- a/advisories/unreviewed/2023/12/GHSA-7qjm-443c-38h9/GHSA-7qjm-443c-38h9.json +++ b/advisories/unreviewed/2023/12/GHSA-7qjm-443c-38h9/GHSA-7qjm-443c-38h9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-9m44-6f5v-p3rf/GHSA-9m44-6f5v-p3rf.json b/advisories/unreviewed/2023/12/GHSA-9m44-6f5v-p3rf/GHSA-9m44-6f5v-p3rf.json index 02ba04e8a81..c62bca24664 100644 --- a/advisories/unreviewed/2023/12/GHSA-9m44-6f5v-p3rf/GHSA-9m44-6f5v-p3rf.json +++ b/advisories/unreviewed/2023/12/GHSA-9m44-6f5v-p3rf/GHSA-9m44-6f5v-p3rf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-f92h-rw3f-8j92/GHSA-f92h-rw3f-8j92.json b/advisories/unreviewed/2023/12/GHSA-f92h-rw3f-8j92/GHSA-f92h-rw3f-8j92.json index 8af2774a4fb..a991c0cd2f4 100644 --- a/advisories/unreviewed/2023/12/GHSA-f92h-rw3f-8j92/GHSA-f92h-rw3f-8j92.json +++ b/advisories/unreviewed/2023/12/GHSA-f92h-rw3f-8j92/GHSA-f92h-rw3f-8j92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-g8c7-p5fx-vxh6/GHSA-g8c7-p5fx-vxh6.json b/advisories/unreviewed/2023/12/GHSA-g8c7-p5fx-vxh6/GHSA-g8c7-p5fx-vxh6.json index a34820946b9..638996952de 100644 --- a/advisories/unreviewed/2023/12/GHSA-g8c7-p5fx-vxh6/GHSA-g8c7-p5fx-vxh6.json +++ b/advisories/unreviewed/2023/12/GHSA-g8c7-p5fx-vxh6/GHSA-g8c7-p5fx-vxh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-hpp6-2prw-cvwr/GHSA-hpp6-2prw-cvwr.json b/advisories/unreviewed/2023/12/GHSA-hpp6-2prw-cvwr/GHSA-hpp6-2prw-cvwr.json index 1675e9448ff..fc28f177588 100644 --- a/advisories/unreviewed/2023/12/GHSA-hpp6-2prw-cvwr/GHSA-hpp6-2prw-cvwr.json +++ b/advisories/unreviewed/2023/12/GHSA-hpp6-2prw-cvwr/GHSA-hpp6-2prw-cvwr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-rfg4-wjmf-xghf/GHSA-rfg4-wjmf-xghf.json b/advisories/unreviewed/2023/12/GHSA-rfg4-wjmf-xghf/GHSA-rfg4-wjmf-xghf.json index 123b48f7cd7..ff37f5ef418 100644 --- a/advisories/unreviewed/2023/12/GHSA-rfg4-wjmf-xghf/GHSA-rfg4-wjmf-xghf.json +++ b/advisories/unreviewed/2023/12/GHSA-rfg4-wjmf-xghf/GHSA-rfg4-wjmf-xghf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-rv87-xrcf-5c22/GHSA-rv87-xrcf-5c22.json b/advisories/unreviewed/2023/12/GHSA-rv87-xrcf-5c22/GHSA-rv87-xrcf-5c22.json index 20bcefaafd6..4a5193aa55a 100644 --- a/advisories/unreviewed/2023/12/GHSA-rv87-xrcf-5c22/GHSA-rv87-xrcf-5c22.json +++ b/advisories/unreviewed/2023/12/GHSA-rv87-xrcf-5c22/GHSA-rv87-xrcf-5c22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-g6q5-f5p2-c8vp/GHSA-g6q5-f5p2-c8vp.json b/advisories/unreviewed/2024/01/GHSA-g6q5-f5p2-c8vp/GHSA-g6q5-f5p2-c8vp.json index 950af69414f..858a02806d3 100644 --- a/advisories/unreviewed/2024/01/GHSA-g6q5-f5p2-c8vp/GHSA-g6q5-f5p2-c8vp.json +++ b/advisories/unreviewed/2024/01/GHSA-g6q5-f5p2-c8vp/GHSA-g6q5-f5p2-c8vp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-24qg-89rj-g629/GHSA-24qg-89rj-g629.json b/advisories/unreviewed/2024/02/GHSA-24qg-89rj-g629/GHSA-24qg-89rj-g629.json index 607e4f33874..6d082c7ac6b 100644 --- a/advisories/unreviewed/2024/02/GHSA-24qg-89rj-g629/GHSA-24qg-89rj-g629.json +++ b/advisories/unreviewed/2024/02/GHSA-24qg-89rj-g629/GHSA-24qg-89rj-g629.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-27g5-cf66-m7v6/GHSA-27g5-cf66-m7v6.json b/advisories/unreviewed/2024/02/GHSA-27g5-cf66-m7v6/GHSA-27g5-cf66-m7v6.json index 51692400c49..e391c447d2a 100644 --- a/advisories/unreviewed/2024/02/GHSA-27g5-cf66-m7v6/GHSA-27g5-cf66-m7v6.json +++ b/advisories/unreviewed/2024/02/GHSA-27g5-cf66-m7v6/GHSA-27g5-cf66-m7v6.json @@ -7,12 +7,8 @@ "CVE-2021-47052" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sa2ul - Fix memory leak of rxd\n\nThere are two error return paths that are not freeing rxd and causing\nmemory leaks. Fix these.\n\nAddresses-Coverity: (\"Resource leak\")", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-28cg-r647-j4cw/GHSA-28cg-r647-j4cw.json b/advisories/unreviewed/2024/02/GHSA-28cg-r647-j4cw/GHSA-28cg-r647-j4cw.json index 9a2d092ab58..16b3d76fcbd 100644 --- a/advisories/unreviewed/2024/02/GHSA-28cg-r647-j4cw/GHSA-28cg-r647-j4cw.json +++ b/advisories/unreviewed/2024/02/GHSA-28cg-r647-j4cw/GHSA-28cg-r647-j4cw.json @@ -7,12 +7,8 @@ "CVE-2021-46998" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nethernet:enic: Fix a use after free bug in enic_hard_start_xmit\n\nIn enic_hard_start_xmit, it calls enic_queue_wq_skb(). Inside\nenic_queue_wq_skb, if some error happens, the skb will be freed\nby dev_kfree_skb(skb). But the freed skb is still used in\nskb_tx_timestamp(skb).\n\nMy patch makes enic_queue_wq_skb() return error and goto spin_unlock()\nincase of error. The solution is provided by Govind.\nSee https://lkml.org/lkml/2021/4/30/961.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-2v9v-6h75-597v/GHSA-2v9v-6h75-597v.json b/advisories/unreviewed/2024/02/GHSA-2v9v-6h75-597v/GHSA-2v9v-6h75-597v.json index 301fb2352af..cacd07ecd27 100644 --- a/advisories/unreviewed/2024/02/GHSA-2v9v-6h75-597v/GHSA-2v9v-6h75-597v.json +++ b/advisories/unreviewed/2024/02/GHSA-2v9v-6h75-597v/GHSA-2v9v-6h75-597v.json @@ -7,12 +7,8 @@ "CVE-2021-47046" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix off by one in hdmi_14_process_transaction()\n\nThe hdcp_i2c_offsets[] array did not have an entry for\nHDCP_MESSAGE_ID_WRITE_CONTENT_STREAM_TYPE so it led to an off by one\nread overflow. I added an entry and copied the 0x0 value for the offset\nfrom similar code in drivers/gpu/drm/amd/display/modules/hdcp/hdcp_ddc.c.\n\nI also declared several of these arrays as having HDCP_MESSAGE_ID_MAX\nentries. This doesn't change the code, but it's just a belt and\nsuspenders approach to try future proof the code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-3ch6-f277-559q/GHSA-3ch6-f277-559q.json b/advisories/unreviewed/2024/02/GHSA-3ch6-f277-559q/GHSA-3ch6-f277-559q.json index c6a6c64f8e0..e43ad4245e6 100644 --- a/advisories/unreviewed/2024/02/GHSA-3ch6-f277-559q/GHSA-3ch6-f277-559q.json +++ b/advisories/unreviewed/2024/02/GHSA-3ch6-f277-559q/GHSA-3ch6-f277-559q.json @@ -7,12 +7,8 @@ "CVE-2021-47013" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send\n\nIn emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..).\nIf some error happens in emac_tx_fill_tpd(), the skb will be freed via\ndev_kfree_skb(skb) in error branch of emac_tx_fill_tpd().\nBut the freed skb is still used via skb->len by netdev_sent_queue(,skb->len).\n\nAs i observed that emac_tx_fill_tpd() haven't modified the value of skb->len,\nthus my patch assigns skb->len to 'len' before the possible free and\nuse 'len' instead of skb->len later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-3jvq-9rg9-g8rp/GHSA-3jvq-9rg9-g8rp.json b/advisories/unreviewed/2024/02/GHSA-3jvq-9rg9-g8rp/GHSA-3jvq-9rg9-g8rp.json index 3d85bd4edf9..97858a24071 100644 --- a/advisories/unreviewed/2024/02/GHSA-3jvq-9rg9-g8rp/GHSA-3jvq-9rg9-g8rp.json +++ b/advisories/unreviewed/2024/02/GHSA-3jvq-9rg9-g8rp/GHSA-3jvq-9rg9-g8rp.json @@ -7,12 +7,8 @@ "CVE-2021-47038" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: avoid deadlock between hci_dev->lock and socket lock\n\nCommit eab2404ba798 (\"Bluetooth: Add BT_PHY socket option\") added a\ndependency between socket lock and hci_dev->lock that could lead to\ndeadlock.\n\nIt turns out that hci_conn_get_phy() is not in any way relying on hdev\nbeing immutable during the runtime of this function, neither does it even\nlook at any of the members of hdev, and as such there is no need to hold\nthat lock.\n\nThis fixes the lockdep splat below:\n\n ======================================================\n WARNING: possible circular locking dependency detected\n 5.12.0-rc1-00026-g73d464503354 #10 Not tainted\n ------------------------------------------------------\n bluetoothd/1118 is trying to acquire lock:\n ffff8f078383c078 (&hdev->lock){+.+.}-{3:3}, at: hci_conn_get_phy+0x1c/0x150 [bluetooth]\n\n but task is already holding lock:\n ffff8f07e831d920 (sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP){+.+.}-{0:0}, at: l2cap_sock_getsockopt+0x8b/0x610\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -> #3 (sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP){+.+.}-{0:0}:\n lock_sock_nested+0x72/0xa0\n l2cap_sock_ready_cb+0x18/0x70 [bluetooth]\n l2cap_config_rsp+0x27a/0x520 [bluetooth]\n l2cap_sig_channel+0x658/0x1330 [bluetooth]\n l2cap_recv_frame+0x1ba/0x310 [bluetooth]\n hci_rx_work+0x1cc/0x640 [bluetooth]\n process_one_work+0x244/0x5f0\n worker_thread+0x3c/0x380\n kthread+0x13e/0x160\n ret_from_fork+0x22/0x30\n\n -> #2 (&chan->lock#2/1){+.+.}-{3:3}:\n __mutex_lock+0xa3/0xa10\n l2cap_chan_connect+0x33a/0x940 [bluetooth]\n l2cap_sock_connect+0x141/0x2a0 [bluetooth]\n __sys_connect+0x9b/0xc0\n __x64_sys_connect+0x16/0x20\n do_syscall_64+0x33/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n -> #1 (&conn->chan_lock){+.+.}-{3:3}:\n __mutex_lock+0xa3/0xa10\n l2cap_chan_connect+0x322/0x940 [bluetooth]\n l2cap_sock_connect+0x141/0x2a0 [bluetooth]\n __sys_connect+0x9b/0xc0\n __x64_sys_connect+0x16/0x20\n do_syscall_64+0x33/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n -> #0 (&hdev->lock){+.+.}-{3:3}:\n __lock_acquire+0x147a/0x1a50\n lock_acquire+0x277/0x3d0\n __mutex_lock+0xa3/0xa10\n hci_conn_get_phy+0x1c/0x150 [bluetooth]\n l2cap_sock_getsockopt+0x5a9/0x610 [bluetooth]\n __sys_getsockopt+0xcc/0x200\n __x64_sys_getsockopt+0x20/0x30\n do_syscall_64+0x33/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n other info that might help us debug this:\n\n Chain exists of:\n &hdev->lock --> &chan->lock#2/1 --> sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP);\n lock(&chan->lock#2/1);\n lock(sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP);\n lock(&hdev->lock);\n\n *** DEADLOCK ***\n\n 1 lock held by bluetoothd/1118:\n #0: ffff8f07e831d920 (sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP){+.+.}-{0:0}, at: l2cap_sock_getsockopt+0x8b/0x610 [bluetooth]\n\n stack backtrace:\n CPU: 3 PID: 1118 Comm: bluetoothd Not tainted 5.12.0-rc1-00026-g73d464503354 #10\n Hardware name: LENOVO 20K5S22R00/20K5S22R00, BIOS R0IET38W (1.16 ) 05/31/2017\n Call Trace:\n dump_stack+0x7f/0xa1\n check_noncircular+0x105/0x120\n ? __lock_acquire+0x147a/0x1a50\n __lock_acquire+0x147a/0x1a50\n lock_acquire+0x277/0x3d0\n ? hci_conn_get_phy+0x1c/0x150 [bluetooth]\n ? __lock_acquire+0x2e1/0x1a50\n ? lock_is_held_type+0xb4/0x120\n ? hci_conn_get_phy+0x1c/0x150 [bluetooth]\n __mutex_lock+0xa3/0xa10\n ? hci_conn_get_phy+0x1c/0x150 [bluetooth]\n ? lock_acquire+0x277/0x3d0\n ? mark_held_locks+0x49/0x70\n ? mark_held_locks+0x49/0x70\n ? hci_conn_get_phy+0x1c/0x150 [bluetooth]\n hci_conn_get_phy+0x\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-42gh-8g4f-4x6c/GHSA-42gh-8g4f-4x6c.json b/advisories/unreviewed/2024/02/GHSA-42gh-8g4f-4x6c/GHSA-42gh-8g4f-4x6c.json index d842887e193..c365a752f1e 100644 --- a/advisories/unreviewed/2024/02/GHSA-42gh-8g4f-4x6c/GHSA-42gh-8g4f-4x6c.json +++ b/advisories/unreviewed/2024/02/GHSA-42gh-8g4f-4x6c/GHSA-42gh-8g4f-4x6c.json @@ -7,12 +7,8 @@ "CVE-2021-47053" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ss - Fix memory leak of pad\n\nIt appears there are several failure return paths that don't seem\nto be free'ing pad. Fix these.\n\nAddresses-Coverity: (\"Resource leak\")", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-4qp7-5rvw-5428/GHSA-4qp7-5rvw-5428.json b/advisories/unreviewed/2024/02/GHSA-4qp7-5rvw-5428/GHSA-4qp7-5rvw-5428.json index 52f7fb07512..e5bfb0ef629 100644 --- a/advisories/unreviewed/2024/02/GHSA-4qp7-5rvw-5428/GHSA-4qp7-5rvw-5428.json +++ b/advisories/unreviewed/2024/02/GHSA-4qp7-5rvw-5428/GHSA-4qp7-5rvw-5428.json @@ -7,12 +7,8 @@ "CVE-2021-46984" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkyber: fix out of bounds access when preempted\n\n__blk_mq_sched_bio_merge() gets the ctx and hctx for the current CPU and\npasses the hctx to ->bio_merge(). kyber_bio_merge() then gets the ctx\nfor the current CPU again and uses that to get the corresponding Kyber\ncontext in the passed hctx. However, the thread may be preempted between\nthe two calls to blk_mq_get_ctx(), and the ctx returned the second time\nmay no longer correspond to the passed hctx. This \"works\" accidentally\nmost of the time, but it can cause us to read garbage if the second ctx\ncame from an hctx with more ctx's than the first one (i.e., if\nctx->index_hw[hctx->type] > hctx->nr_ctx).\n\nThis manifested as this UBSAN array index out of bounds error reported\nby Jakub:\n\nUBSAN: array-index-out-of-bounds in ../kernel/locking/qspinlock.c:130:9\nindex 13106 is out of range for type 'long unsigned int [128]'\nCall Trace:\n dump_stack+0xa4/0xe5\n ubsan_epilogue+0x5/0x40\n __ubsan_handle_out_of_bounds.cold.13+0x2a/0x34\n queued_spin_lock_slowpath+0x476/0x480\n do_raw_spin_lock+0x1c2/0x1d0\n kyber_bio_merge+0x112/0x180\n blk_mq_submit_bio+0x1f5/0x1100\n submit_bio_noacct+0x7b0/0x870\n submit_bio+0xc2/0x3a0\n btrfs_map_bio+0x4f0/0x9d0\n btrfs_submit_data_bio+0x24e/0x310\n submit_one_bio+0x7f/0xb0\n submit_extent_page+0xc4/0x440\n __extent_writepage_io+0x2b8/0x5e0\n __extent_writepage+0x28d/0x6e0\n extent_write_cache_pages+0x4d7/0x7a0\n extent_writepages+0xa2/0x110\n do_writepages+0x8f/0x180\n __writeback_single_inode+0x99/0x7f0\n writeback_sb_inodes+0x34e/0x790\n __writeback_inodes_wb+0x9e/0x120\n wb_writeback+0x4d2/0x660\n wb_workfn+0x64d/0xa10\n process_one_work+0x53a/0xa80\n worker_thread+0x69/0x5b0\n kthread+0x20b/0x240\n ret_from_fork+0x1f/0x30\n\nOnly Kyber uses the hctx, so fix it by passing the request_queue to\n->bio_merge() instead. BFQ and mq-deadline just use that, and Kyber can\nmap the queues itself to avoid the mismatch.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-4rvh-837w-4r69/GHSA-4rvh-837w-4r69.json b/advisories/unreviewed/2024/02/GHSA-4rvh-837w-4r69/GHSA-4rvh-837w-4r69.json index a78ffbd5d00..f5a12f428d9 100644 --- a/advisories/unreviewed/2024/02/GHSA-4rvh-837w-4r69/GHSA-4rvh-837w-4r69.json +++ b/advisories/unreviewed/2024/02/GHSA-4rvh-837w-4r69/GHSA-4rvh-837w-4r69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-57c7-52jj-89fr/GHSA-57c7-52jj-89fr.json b/advisories/unreviewed/2024/02/GHSA-57c7-52jj-89fr/GHSA-57c7-52jj-89fr.json index ebcc1220b06..a0892a2a9fa 100644 --- a/advisories/unreviewed/2024/02/GHSA-57c7-52jj-89fr/GHSA-57c7-52jj-89fr.json +++ b/advisories/unreviewed/2024/02/GHSA-57c7-52jj-89fr/GHSA-57c7-52jj-89fr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5f6g-q8f6-3c5x/GHSA-5f6g-q8f6-3c5x.json b/advisories/unreviewed/2024/02/GHSA-5f6g-q8f6-3c5x/GHSA-5f6g-q8f6-3c5x.json index f45ca58dc7e..9a3a90caa76 100644 --- a/advisories/unreviewed/2024/02/GHSA-5f6g-q8f6-3c5x/GHSA-5f6g-q8f6-3c5x.json +++ b/advisories/unreviewed/2024/02/GHSA-5f6g-q8f6-3c5x/GHSA-5f6g-q8f6-3c5x.json @@ -7,12 +7,8 @@ "CVE-2021-47032" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7915: fix tx skb dma unmap\n\nThe first pointer in the txp needs to be unmapped as well, otherwise it will\nleak DMA mapping entries", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-5m36-66x4-phpf/GHSA-5m36-66x4-phpf.json b/advisories/unreviewed/2024/02/GHSA-5m36-66x4-phpf/GHSA-5m36-66x4-phpf.json index be175a87ce1..442b88f40ae 100644 --- a/advisories/unreviewed/2024/02/GHSA-5m36-66x4-phpf/GHSA-5m36-66x4-phpf.json +++ b/advisories/unreviewed/2024/02/GHSA-5m36-66x4-phpf/GHSA-5m36-66x4-phpf.json @@ -7,12 +7,8 @@ "CVE-2021-47051" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: fsl-lpspi: Fix PM reference leak in lpspi_prepare_xfer_hardware()\n\npm_runtime_get_sync will increment pm usage counter even it failed.\nForgetting to putting operation will result in reference leak here.\nFix it by replacing it with pm_runtime_resume_and_get to keep usage\ncounter balanced.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-5wjq-3hcv-7r2j/GHSA-5wjq-3hcv-7r2j.json b/advisories/unreviewed/2024/02/GHSA-5wjq-3hcv-7r2j/GHSA-5wjq-3hcv-7r2j.json index 0e12830e241..7a13a839aa3 100644 --- a/advisories/unreviewed/2024/02/GHSA-5wjq-3hcv-7r2j/GHSA-5wjq-3hcv-7r2j.json +++ b/advisories/unreviewed/2024/02/GHSA-5wjq-3hcv-7r2j/GHSA-5wjq-3hcv-7r2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-66ww-hh28-59jg/GHSA-66ww-hh28-59jg.json b/advisories/unreviewed/2024/02/GHSA-66ww-hh28-59jg/GHSA-66ww-hh28-59jg.json index 501373882ec..e8c01b1985c 100644 --- a/advisories/unreviewed/2024/02/GHSA-66ww-hh28-59jg/GHSA-66ww-hh28-59jg.json +++ b/advisories/unreviewed/2024/02/GHSA-66ww-hh28-59jg/GHSA-66ww-hh28-59jg.json @@ -7,12 +7,8 @@ "CVE-2021-47017" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nath10k: Fix a use after free in ath10k_htc_send_bundle\n\nIn ath10k_htc_send_bundle, the bundle_skb could be freed by\ndev_kfree_skb_any(bundle_skb). But the bundle_skb is used later\nby bundle_skb->len.\n\nAs skb_len = bundle_skb->len, my patch replaces bundle_skb->len to\nskb_len after the bundle_skb was freed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-68vm-vpf9-fgr6/GHSA-68vm-vpf9-fgr6.json b/advisories/unreviewed/2024/02/GHSA-68vm-vpf9-fgr6/GHSA-68vm-vpf9-fgr6.json index dc6b3c3f8e6..a67b23eb34d 100644 --- a/advisories/unreviewed/2024/02/GHSA-68vm-vpf9-fgr6/GHSA-68vm-vpf9-fgr6.json +++ b/advisories/unreviewed/2024/02/GHSA-68vm-vpf9-fgr6/GHSA-68vm-vpf9-fgr6.json @@ -7,12 +7,8 @@ "CVE-2021-47028" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7915: fix txrate reporting\n\nProperly check rate_info to fix unexpected reporting.\n\n[ 1215.161863] Call trace:\n[ 1215.164307] cfg80211_calculate_bitrate+0x124/0x200 [cfg80211]\n[ 1215.170139] ieee80211s_update_metric+0x80/0xc0 [mac80211]\n[ 1215.175624] ieee80211_tx_status_ext+0x508/0x838 [mac80211]\n[ 1215.181190] mt7915_mcu_get_rx_rate+0x28c/0x8d0 [mt7915e]\n[ 1215.186580] mt7915_mac_tx_free+0x324/0x7c0 [mt7915e]\n[ 1215.191623] mt7915_queue_rx_skb+0xa8/0xd0 [mt7915e]\n[ 1215.196582] mt76_dma_cleanup+0x7b0/0x11d0 [mt76]\n[ 1215.201276] __napi_poll+0x38/0xf8\n[ 1215.204668] napi_workfn+0x40/0x80\n[ 1215.208062] process_one_work+0x1fc/0x390\n[ 1215.212062] worker_thread+0x48/0x4d0\n[ 1215.215715] kthread+0x120/0x128\n[ 1215.218935] ret_from_fork+0x10/0x1c", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-69jc-r7p8-4cpg/GHSA-69jc-r7p8-4cpg.json b/advisories/unreviewed/2024/02/GHSA-69jc-r7p8-4cpg/GHSA-69jc-r7p8-4cpg.json index 0fc92b1d99d..0400729727e 100644 --- a/advisories/unreviewed/2024/02/GHSA-69jc-r7p8-4cpg/GHSA-69jc-r7p8-4cpg.json +++ b/advisories/unreviewed/2024/02/GHSA-69jc-r7p8-4cpg/GHSA-69jc-r7p8-4cpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-6m5f-gf5f-wvx9/GHSA-6m5f-gf5f-wvx9.json b/advisories/unreviewed/2024/02/GHSA-6m5f-gf5f-wvx9/GHSA-6m5f-gf5f-wvx9.json index baf2aa8dc32..d8b33897a05 100644 --- a/advisories/unreviewed/2024/02/GHSA-6m5f-gf5f-wvx9/GHSA-6m5f-gf5f-wvx9.json +++ b/advisories/unreviewed/2024/02/GHSA-6m5f-gf5f-wvx9/GHSA-6m5f-gf5f-wvx9.json @@ -7,12 +7,8 @@ "CVE-2021-47022" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7615: fix memleak when mt7615_unregister_device()\n\nmt7615_tx_token_put() should get call before mt76_free_pending_txwi().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-6xgc-32qf-8pxm/GHSA-6xgc-32qf-8pxm.json b/advisories/unreviewed/2024/02/GHSA-6xgc-32qf-8pxm/GHSA-6xgc-32qf-8pxm.json index 4a4f681657b..ce1523a9885 100644 --- a/advisories/unreviewed/2024/02/GHSA-6xgc-32qf-8pxm/GHSA-6xgc-32qf-8pxm.json +++ b/advisories/unreviewed/2024/02/GHSA-6xgc-32qf-8pxm/GHSA-6xgc-32qf-8pxm.json @@ -7,12 +7,8 @@ "CVE-2021-47050" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmemory: renesas-rpc-if: fix possible NULL pointer dereference of resource\n\nThe platform_get_resource_byname() can return NULL which would be\nimmediately dereferenced by resource_size(). Instead dereference it\nafter validating the resource.\n\nAddresses-Coverity: Dereference null return value", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-73mf-287p-8r8c/GHSA-73mf-287p-8r8c.json b/advisories/unreviewed/2024/02/GHSA-73mf-287p-8r8c/GHSA-73mf-287p-8r8c.json index 7ff23ce7513..d8e5d44102d 100644 --- a/advisories/unreviewed/2024/02/GHSA-73mf-287p-8r8c/GHSA-73mf-287p-8r8c.json +++ b/advisories/unreviewed/2024/02/GHSA-73mf-287p-8r8c/GHSA-73mf-287p-8r8c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-77r5-rg8x-qv78/GHSA-77r5-rg8x-qv78.json b/advisories/unreviewed/2024/02/GHSA-77r5-rg8x-qv78/GHSA-77r5-rg8x-qv78.json index 9c4c09bc4b1..6e1ec88d72b 100644 --- a/advisories/unreviewed/2024/02/GHSA-77r5-rg8x-qv78/GHSA-77r5-rg8x-qv78.json +++ b/advisories/unreviewed/2024/02/GHSA-77r5-rg8x-qv78/GHSA-77r5-rg8x-qv78.json @@ -7,12 +7,8 @@ "CVE-2021-47029" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: connac: fix kernel warning adding monitor interface\n\nFix the following kernel warning adding a monitor interface in\nmt76_connac_mcu_uni_add_dev routine.\n\n[ 507.984882] ------------[ cut here ]------------\n[ 507.989515] WARNING: CPU: 1 PID: 3017 at mt76_connac_mcu_uni_add_dev+0x178/0x190 [mt76_connac_lib]\n[ 508.059379] CPU: 1 PID: 3017 Comm: ifconfig Not tainted 5.4.98 #0\n[ 508.065461] Hardware name: MT7622_MT7531 RFB (DT)\n[ 508.070156] pstate: 80000005 (Nzcv daif -PAN -UAO)\n[ 508.074939] pc : mt76_connac_mcu_uni_add_dev+0x178/0x190 [mt76_connac_lib]\n[ 508.081806] lr : mt7921_eeprom_init+0x1288/0x1cb8 [mt7921e]\n[ 508.087367] sp : ffffffc013a33930\n[ 508.090671] x29: ffffffc013a33930 x28: ffffff801e628ac0\n[ 508.095973] x27: ffffff801c7f1200 x26: ffffff801c7eb008\n[ 508.101275] x25: ffffff801c7eaef0 x24: ffffff801d025610\n[ 508.106577] x23: ffffff801d022990 x22: ffffff801d024de8\n[ 508.111879] x21: ffffff801d0226a0 x20: ffffff801c7eaee8\n[ 508.117181] x19: ffffff801d0226a0 x18: 000000005d00b000\n[ 508.122482] x17: 00000000ffffffff x16: 0000000000000000\n[ 508.127785] x15: 0000000000000080 x14: ffffff801d704000\n[ 508.133087] x13: 0000000000000040 x12: 0000000000000002\n[ 508.138389] x11: 000000000000000c x10: 0000000000000000\n[ 508.143691] x9 : 0000000000000020 x8 : 0000000000000001\n[ 508.148992] x7 : 0000000000000000 x6 : 0000000000000000\n[ 508.154294] x5 : ffffff801c7eaee8 x4 : 0000000000000006\n[ 508.159596] x3 : 0000000000000001 x2 : 0000000000000000\n[ 508.164898] x1 : ffffff801c7eac08 x0 : ffffff801d0226a0\n[ 508.170200] Call trace:\n[ 508.172640] mt76_connac_mcu_uni_add_dev+0x178/0x190 [mt76_connac_lib]\n[ 508.179159] mt7921_eeprom_init+0x1288/0x1cb8 [mt7921e]\n[ 508.184394] drv_add_interface+0x34/0x88 [mac80211]\n[ 508.189271] ieee80211_add_virtual_monitor+0xe0/0xb48 [mac80211]\n[ 508.195277] ieee80211_do_open+0x86c/0x918 [mac80211]\n[ 508.200328] ieee80211_do_open+0x900/0x918 [mac80211]\n[ 508.205372] __dev_open+0xcc/0x150\n[ 508.208763] __dev_change_flags+0x134/0x198\n[ 508.212937] dev_change_flags+0x20/0x60\n[ 508.216764] devinet_ioctl+0x3e8/0x748\n[ 508.220503] inet_ioctl+0x1e4/0x350\n[ 508.223983] sock_do_ioctl+0x48/0x2a0\n[ 508.227635] sock_ioctl+0x310/0x4f8\n[ 508.231116] do_vfs_ioctl+0xa4/0xac0\n[ 508.234681] ksys_ioctl+0x44/0x90\n[ 508.237985] __arm64_sys_ioctl+0x1c/0x48\n[ 508.241901] el0_svc_common.constprop.1+0x7c/0x100\n[ 508.246681] el0_svc_handler+0x18/0x20\n[ 508.250421] el0_svc+0x8/0x1c8\n[ 508.253465] ---[ end trace c7b90fee13d72c39 ]---\n[ 508.261278] ------------[ cut here ]------------", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-7h2p-gcjg-4fw8/GHSA-7h2p-gcjg-4fw8.json b/advisories/unreviewed/2024/02/GHSA-7h2p-gcjg-4fw8/GHSA-7h2p-gcjg-4fw8.json index 3a20b6f664c..cf7fe51ab96 100644 --- a/advisories/unreviewed/2024/02/GHSA-7h2p-gcjg-4fw8/GHSA-7h2p-gcjg-4fw8.json +++ b/advisories/unreviewed/2024/02/GHSA-7h2p-gcjg-4fw8/GHSA-7h2p-gcjg-4fw8.json @@ -7,12 +7,8 @@ "CVE-2021-47045" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix null pointer dereference in lpfc_prep_els_iocb()\n\nIt is possible to call lpfc_issue_els_plogi() passing a did for which no\nmatching ndlp is found. A call is then made to lpfc_prep_els_iocb() with a\nnull pointer to a lpfc_nodelist structure resulting in a null pointer\ndereference.\n\nFix by returning an error status if no valid ndlp is found. Fix up comments\nregarding ndlp reference counting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-843c-j8jj-h425/GHSA-843c-j8jj-h425.json b/advisories/unreviewed/2024/02/GHSA-843c-j8jj-h425/GHSA-843c-j8jj-h425.json index 043e0fb65b6..36ab3587f98 100644 --- a/advisories/unreviewed/2024/02/GHSA-843c-j8jj-h425/GHSA-843c-j8jj-h425.json +++ b/advisories/unreviewed/2024/02/GHSA-843c-j8jj-h425/GHSA-843c-j8jj-h425.json @@ -7,12 +7,8 @@ "CVE-2024-25422" ], "details": "SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-85xw-cv8g-9227/GHSA-85xw-cv8g-9227.json b/advisories/unreviewed/2024/02/GHSA-85xw-cv8g-9227/GHSA-85xw-cv8g-9227.json index fac9939c13c..7337cb79b84 100644 --- a/advisories/unreviewed/2024/02/GHSA-85xw-cv8g-9227/GHSA-85xw-cv8g-9227.json +++ b/advisories/unreviewed/2024/02/GHSA-85xw-cv8g-9227/GHSA-85xw-cv8g-9227.json @@ -7,12 +7,8 @@ "CVE-2021-46987" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock when cloning inline extents and using qgroups\n\nThere are a few exceptional cases where cloning an inline extent needs to\ncopy the inline extent data into a page of the destination inode.\n\nWhen this happens, we end up starting a transaction while having a dirty\npage for the destination inode and while having the range locked in the\ndestination's inode iotree too. Because when reserving metadata space\nfor a transaction we may need to flush existing delalloc in case there is\nnot enough free space, we have a mechanism in place to prevent a deadlock,\nwhich was introduced in commit 3d45f221ce627d (\"btrfs: fix deadlock when\ncloning inline extent and low on free metadata space\").\n\nHowever when using qgroups, a transaction also reserves metadata qgroup\nspace, which can also result in flushing delalloc in case there is not\nenough available space at the moment. When this happens we deadlock, since\nflushing delalloc requires locking the file range in the inode's iotree\nand the range was already locked at the very beginning of the clone\noperation, before attempting to start the transaction.\n\nWhen this issue happens, stack traces like the following are reported:\n\n [72747.556262] task:kworker/u81:9 state:D stack: 0 pid: 225 ppid: 2 flags:0x00004000\n [72747.556268] Workqueue: writeback wb_workfn (flush-btrfs-1142)\n [72747.556271] Call Trace:\n [72747.556273] __schedule+0x296/0x760\n [72747.556277] schedule+0x3c/0xa0\n [72747.556279] io_schedule+0x12/0x40\n [72747.556284] __lock_page+0x13c/0x280\n [72747.556287] ? generic_file_readonly_mmap+0x70/0x70\n [72747.556325] extent_write_cache_pages+0x22a/0x440 [btrfs]\n [72747.556331] ? __set_page_dirty_nobuffers+0xe7/0x160\n [72747.556358] ? set_extent_buffer_dirty+0x5e/0x80 [btrfs]\n [72747.556362] ? update_group_capacity+0x25/0x210\n [72747.556366] ? cpumask_next_and+0x1a/0x20\n [72747.556391] extent_writepages+0x44/0xa0 [btrfs]\n [72747.556394] do_writepages+0x41/0xd0\n [72747.556398] __writeback_single_inode+0x39/0x2a0\n [72747.556403] writeback_sb_inodes+0x1ea/0x440\n [72747.556407] __writeback_inodes_wb+0x5f/0xc0\n [72747.556410] wb_writeback+0x235/0x2b0\n [72747.556414] ? get_nr_inodes+0x35/0x50\n [72747.556417] wb_workfn+0x354/0x490\n [72747.556420] ? newidle_balance+0x2c5/0x3e0\n [72747.556424] process_one_work+0x1aa/0x340\n [72747.556426] worker_thread+0x30/0x390\n [72747.556429] ? create_worker+0x1a0/0x1a0\n [72747.556432] kthread+0x116/0x130\n [72747.556435] ? kthread_park+0x80/0x80\n [72747.556438] ret_from_fork+0x1f/0x30\n\n [72747.566958] Workqueue: btrfs-flush_delalloc btrfs_work_helper [btrfs]\n [72747.566961] Call Trace:\n [72747.566964] __schedule+0x296/0x760\n [72747.566968] ? finish_wait+0x80/0x80\n [72747.566970] schedule+0x3c/0xa0\n [72747.566995] wait_extent_bit.constprop.68+0x13b/0x1c0 [btrfs]\n [72747.566999] ? finish_wait+0x80/0x80\n [72747.567024] lock_extent_bits+0x37/0x90 [btrfs]\n [72747.567047] btrfs_invalidatepage+0x299/0x2c0 [btrfs]\n [72747.567051] ? find_get_pages_range_tag+0x2cd/0x380\n [72747.567076] __extent_writepage+0x203/0x320 [btrfs]\n [72747.567102] extent_write_cache_pages+0x2bb/0x440 [btrfs]\n [72747.567106] ? update_load_avg+0x7e/0x5f0\n [72747.567109] ? enqueue_entity+0xf4/0x6f0\n [72747.567134] extent_writepages+0x44/0xa0 [btrfs]\n [72747.567137] ? enqueue_task_fair+0x93/0x6f0\n [72747.567140] do_writepages+0x41/0xd0\n [72747.567144] __filemap_fdatawrite_range+0xc7/0x100\n [72747.567167] btrfs_run_delalloc_work+0x17/0x40 [btrfs]\n [72747.567195] btrfs_work_helper+0xc2/0x300 [btrfs]\n [72747.567200] process_one_work+0x1aa/0x340\n [72747.567202] worker_thread+0x30/0x390\n [72747.567205] ? create_worker+0x1a0/0x1a0\n [72747.567208] kthread+0x116/0x130\n [72747.567211] ? kthread_park+0x80/0x80\n [72747.567214] ret_from_fork+0x1f/0x30\n\n [72747.569686] task:fsstress state:D stack: \n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-88w2-c8v7-h7p6/GHSA-88w2-c8v7-h7p6.json b/advisories/unreviewed/2024/02/GHSA-88w2-c8v7-h7p6/GHSA-88w2-c8v7-h7p6.json index cbcb1878cf4..2d1aa9e40bf 100644 --- a/advisories/unreviewed/2024/02/GHSA-88w2-c8v7-h7p6/GHSA-88w2-c8v7-h7p6.json +++ b/advisories/unreviewed/2024/02/GHSA-88w2-c8v7-h7p6/GHSA-88w2-c8v7-h7p6.json @@ -7,12 +7,8 @@ "CVE-2021-47021" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7915: fix memleak when mt7915_unregister_device()\n\nmt7915_tx_token_put() should get call before mt76_free_pending_txwi().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-8xhh-j9m8-989c/GHSA-8xhh-j9m8-989c.json b/advisories/unreviewed/2024/02/GHSA-8xhh-j9m8-989c/GHSA-8xhh-j9m8-989c.json index f3d1bc0ed35..067dbf886b1 100644 --- a/advisories/unreviewed/2024/02/GHSA-8xhh-j9m8-989c/GHSA-8xhh-j9m8-989c.json +++ b/advisories/unreviewed/2024/02/GHSA-8xhh-j9m8-989c/GHSA-8xhh-j9m8-989c.json @@ -7,12 +7,8 @@ "CVE-2021-47037" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: q6afe-clocks: fix reprobing of the driver\n\nQ6afe-clocks driver can get reprobed. For example if the APR services\nare restarted after the firmware crash. However currently Q6afe-clocks\ndriver will oops because hw.init will get cleared during first _probe\ncall. Rewrite the driver to fill the clock data at runtime rather than\nusing big static array of clocks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-93vc-xxjx-g2p3/GHSA-93vc-xxjx-g2p3.json b/advisories/unreviewed/2024/02/GHSA-93vc-xxjx-g2p3/GHSA-93vc-xxjx-g2p3.json index 6ff26598cde..db165a4b1bf 100644 --- a/advisories/unreviewed/2024/02/GHSA-93vc-xxjx-g2p3/GHSA-93vc-xxjx-g2p3.json +++ b/advisories/unreviewed/2024/02/GHSA-93vc-xxjx-g2p3/GHSA-93vc-xxjx-g2p3.json @@ -7,12 +7,8 @@ "CVE-2023-34198" ], "details": "In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any\" type, which may have unexpected results for access control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-94mv-98xv-9mqq/GHSA-94mv-98xv-9mqq.json b/advisories/unreviewed/2024/02/GHSA-94mv-98xv-9mqq/GHSA-94mv-98xv-9mqq.json index 8655c1caa34..de52138661d 100644 --- a/advisories/unreviewed/2024/02/GHSA-94mv-98xv-9mqq/GHSA-94mv-98xv-9mqq.json +++ b/advisories/unreviewed/2024/02/GHSA-94mv-98xv-9mqq/GHSA-94mv-98xv-9mqq.json @@ -7,12 +7,8 @@ "CVE-2021-47014" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: fix wild memory access when clearing fragments\n\nwhile testing re-assembly/re-fragmentation using act_ct, it's possible to\nobserve a crash like the following one:\n\n KASAN: maybe wild-memory-access in range [0x0001000000000448-0x000100000000044f]\n CPU: 50 PID: 0 Comm: swapper/50 Tainted: G S 5.12.0-rc7+ #424\n Hardware name: Dell Inc. PowerEdge R730/072T6D, BIOS 2.4.3 01/17/2017\n RIP: 0010:inet_frag_rbtree_purge+0x50/0xc0\n Code: 00 fc ff df 48 89 c3 31 ed 48 89 df e8 a9 7a 38 ff 4c 89 fe 48 89 df 49 89 c6 e8 5b 3a 38 ff 48 8d 7b 40 48 89 f8 48 c1 e8 03 <42> 80 3c 20 00 75 59 48 8d bb d0 00 00 00 4c 8b 6b 40 48 89 f8 48\n RSP: 0018:ffff888c31449db8 EFLAGS: 00010203\n RAX: 0000200000000089 RBX: 000100000000040e RCX: ffffffff989eb960\n RDX: 0000000000000140 RSI: ffffffff97cfb977 RDI: 000100000000044e\n RBP: 0000000000000900 R08: 0000000000000000 R09: ffffed1186289350\n R10: 0000000000000003 R11: ffffed1186289350 R12: dffffc0000000000\n R13: 000100000000040e R14: 0000000000000000 R15: ffff888155e02160\n FS: 0000000000000000(0000) GS:ffff888c31440000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00005600cb70a5b8 CR3: 0000000a2c014005 CR4: 00000000003706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n inet_frag_destroy+0xa9/0x150\n call_timer_fn+0x2d/0x180\n run_timer_softirq+0x4fe/0xe70\n __do_softirq+0x197/0x5a0\n irq_exit_rcu+0x1de/0x200\n sysvec_apic_timer_interrupt+0x6b/0x80\n \n\nwhen act_ct temporarily stores an IP fragment, restoring the skb qdisc cb\nresults in putting random data in FRAG_CB(), and this causes those \"wild\"\nmemory accesses later, when the rbtree is purged. Never overwrite the skb\ncb in case tcf_ct_handle_fragments() returns -EINPROGRESS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-98fc-82jh-j626/GHSA-98fc-82jh-j626.json b/advisories/unreviewed/2024/02/GHSA-98fc-82jh-j626/GHSA-98fc-82jh-j626.json index 4a976f7296c..1cdf7ac1844 100644 --- a/advisories/unreviewed/2024/02/GHSA-98fc-82jh-j626/GHSA-98fc-82jh-j626.json +++ b/advisories/unreviewed/2024/02/GHSA-98fc-82jh-j626/GHSA-98fc-82jh-j626.json @@ -7,12 +7,8 @@ "CVE-2021-47004" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid touching checkpointed data in get_victim()\n\nIn CP disabling mode, there are two issues when using LFS or SSR | AT_SSR\nmode to select victim:\n\n1. LFS is set to find source section during GC, the victim should have\nno checkpointed data, since after GC, section could not be set free for\nreuse.\n\nPreviously, we only check valid chpt blocks in current segment rather\nthan section, fix it.\n\n2. SSR | AT_SSR are set to find target segment for writes which can be\nfully filled by checkpointed and newly written blocks, we should never\nselect such segment, otherwise it can cause panic or data corruption\nduring allocation, potential case is described as below:\n\n a) target segment has 'n' (n < 512) ckpt valid blocks\n b) GC migrates 'n' valid blocks to other segment (segment is still\n in dirty list)\n c) GC migrates '512 - n' blocks to target segment (segment has 'n'\n cp_vblocks and '512 - n' vblocks)\n d) If GC selects target segment via {AT,}SSR allocator, however there\n is no free space in targe segment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-9hfp-g5cj-92p6/GHSA-9hfp-g5cj-92p6.json b/advisories/unreviewed/2024/02/GHSA-9hfp-g5cj-92p6/GHSA-9hfp-g5cj-92p6.json index 04486852620..c00adb77116 100644 --- a/advisories/unreviewed/2024/02/GHSA-9hfp-g5cj-92p6/GHSA-9hfp-g5cj-92p6.json +++ b/advisories/unreviewed/2024/02/GHSA-9hfp-g5cj-92p6/GHSA-9hfp-g5cj-92p6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-9hx5-6xv8-6w7c/GHSA-9hx5-6xv8-6w7c.json b/advisories/unreviewed/2024/02/GHSA-9hx5-6xv8-6w7c/GHSA-9hx5-6xv8-6w7c.json index daced0c75a9..07e10bfe1f7 100644 --- a/advisories/unreviewed/2024/02/GHSA-9hx5-6xv8-6w7c/GHSA-9hx5-6xv8-6w7c.json +++ b/advisories/unreviewed/2024/02/GHSA-9hx5-6xv8-6w7c/GHSA-9hx5-6xv8-6w7c.json @@ -7,12 +7,8 @@ "CVE-2020-36787" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: aspeed: fix clock handling logic\n\nVideo engine uses eclk and vclk for its clock sources and its reset\ncontrol is coupled with eclk so the current clock enabling sequence works\nlike below.\n\n Enable eclk\n De-assert Video Engine reset\n 10ms delay\n Enable vclk\n\nIt introduces improper reset on the Video Engine hardware and eventually\nthe hardware generates unexpected DMA memory transfers that can corrupt\nmemory region in random and sporadic patterns. This issue is observed\nvery rarely on some specific AST2500 SoCs but it causes a critical\nkernel panic with making a various shape of signature so it's extremely\nhard to debug. Moreover, the issue is observed even when the video\nengine is not actively used because udevd turns on the video engine\nhardware for a short time to make a query in every boot.\n\nTo fix this issue, this commit changes the clock handling logic to make\nthe reset de-assertion triggered after enabling both eclk and vclk. Also,\nit adds clk_unprepare call for a case when probe fails.\n\nclk: ast2600: fix reset settings for eclk and vclk\nVideo engine reset setting should be coupled with eclk to match it\nwith the setting for previous Aspeed SoCs which is defined in\nclk-aspeed.c since all Aspeed SoCs are sharing a single video engine\ndriver. Also, reset bit 6 is defined as 'Video Engine' reset in\ndatasheet so it should be de-asserted when eclk is enabled. This\ncommit fixes the setting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-9p5f-hx26-h2xq/GHSA-9p5f-hx26-h2xq.json b/advisories/unreviewed/2024/02/GHSA-9p5f-hx26-h2xq/GHSA-9p5f-hx26-h2xq.json index 76b3e86d669..93b07dcb8e2 100644 --- a/advisories/unreviewed/2024/02/GHSA-9p5f-hx26-h2xq/GHSA-9p5f-hx26-h2xq.json +++ b/advisories/unreviewed/2024/02/GHSA-9p5f-hx26-h2xq/GHSA-9p5f-hx26-h2xq.json @@ -7,12 +7,8 @@ "CVE-2021-46997" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: entry: always set GIC_PRIO_PSR_I_SET during entry\n\nZenghui reports that booting a kernel with \"irqchip.gicv3_pseudo_nmi=1\"\non the command line hits a warning during kernel entry, due to the way\nwe manipulate the PMR.\n\nEarly in the entry sequence, we call lockdep_hardirqs_off() to inform\nlockdep that interrupts have been masked (as the HW sets DAIF wqhen\nentering an exception). Architecturally PMR_EL1 is not affected by\nexception entry, and we don't set GIC_PRIO_PSR_I_SET in the PMR early in\nthe exception entry sequence, so early in exception entry the PMR can\nindicate that interrupts are unmasked even though they are masked by\nDAIF.\n\nIf DEBUG_LOCKDEP is selected, lockdep_hardirqs_off() will check that\ninterrupts are masked, before we set GIC_PRIO_PSR_I_SET in any of the\nexception entry paths, and hence lockdep_hardirqs_off() will WARN() that\nsomething is amiss.\n\nWe can avoid this by consistently setting GIC_PRIO_PSR_I_SET during\nexception entry so that kernel code sees a consistent environment. We\nmust also update local_daif_inherit() to undo this, as currently only\ntouches DAIF. For other paths, local_daif_restore() will update both\nDAIF and the PMR. With this done, we can remove the existing special\ncases which set this later in the entry code.\n\nWe always use (GIC_PRIO_IRQON | GIC_PRIO_PSR_I_SET) for consistency with\nlocal_daif_save(), as this will warn if it ever encounters\n(GIC_PRIO_IRQOFF | GIC_PRIO_PSR_I_SET), and never sets this itself. This\nmatches the gic_prio_kentry_setup that we have to retain for\nret_to_user.\n\nThe original splat from Zenghui's report was:\n\n| DEBUG_LOCKS_WARN_ON(!irqs_disabled())\n| WARNING: CPU: 3 PID: 125 at kernel/locking/lockdep.c:4258 lockdep_hardirqs_off+0xd4/0xe8\n| Modules linked in:\n| CPU: 3 PID: 125 Comm: modprobe Tainted: G W 5.12.0-rc8+ #463\n| Hardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015\n| pstate: 604003c5 (nZCv DAIF +PAN -UAO -TCO BTYPE=--)\n| pc : lockdep_hardirqs_off+0xd4/0xe8\n| lr : lockdep_hardirqs_off+0xd4/0xe8\n| sp : ffff80002a39bad0\n| pmr_save: 000000e0\n| x29: ffff80002a39bad0 x28: ffff0000de214bc0\n| x27: ffff0000de1c0400 x26: 000000000049b328\n| x25: 0000000000406f30 x24: ffff0000de1c00a0\n| x23: 0000000020400005 x22: ffff8000105f747c\n| x21: 0000000096000044 x20: 0000000000498ef9\n| x19: ffff80002a39bc88 x18: ffffffffffffffff\n| x17: 0000000000000000 x16: ffff800011c61eb0\n| x15: ffff800011700a88 x14: 0720072007200720\n| x13: 0720072007200720 x12: 0720072007200720\n| x11: 0720072007200720 x10: 0720072007200720\n| x9 : ffff80002a39bad0 x8 : ffff80002a39bad0\n| x7 : ffff8000119f0800 x6 : c0000000ffff7fff\n| x5 : ffff8000119f07a8 x4 : 0000000000000001\n| x3 : 9bcdab23f2432800 x2 : ffff800011730538\n| x1 : 9bcdab23f2432800 x0 : 0000000000000000\n| Call trace:\n| lockdep_hardirqs_off+0xd4/0xe8\n| enter_from_kernel_mode.isra.5+0x7c/0xa8\n| el1_abort+0x24/0x100\n| el1_sync_handler+0x80/0xd0\n| el1_sync+0x6c/0x100\n| __arch_clear_user+0xc/0x90\n| load_elf_binary+0x9fc/0x1450\n| bprm_execve+0x404/0x880\n| kernel_execve+0x180/0x188\n| call_usermodehelper_exec_async+0xdc/0x158\n| ret_from_fork+0x10/0x18", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-c5jp-vv5q-7wc3/GHSA-c5jp-vv5q-7wc3.json b/advisories/unreviewed/2024/02/GHSA-c5jp-vv5q-7wc3/GHSA-c5jp-vv5q-7wc3.json index ea63c6fd195..02718904cd8 100644 --- a/advisories/unreviewed/2024/02/GHSA-c5jp-vv5q-7wc3/GHSA-c5jp-vv5q-7wc3.json +++ b/advisories/unreviewed/2024/02/GHSA-c5jp-vv5q-7wc3/GHSA-c5jp-vv5q-7wc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-cghh-45gx-84f7/GHSA-cghh-45gx-84f7.json b/advisories/unreviewed/2024/02/GHSA-cghh-45gx-84f7/GHSA-cghh-45gx-84f7.json index 12b6205726f..e4c69bb0ce6 100644 --- a/advisories/unreviewed/2024/02/GHSA-cghh-45gx-84f7/GHSA-cghh-45gx-84f7.json +++ b/advisories/unreviewed/2024/02/GHSA-cghh-45gx-84f7/GHSA-cghh-45gx-84f7.json @@ -7,12 +7,8 @@ "CVE-2021-46979" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: core: fix ioctl handlers removal\n\nCurrently ioctl handlers are removed twice. For the first time during\niio_device_unregister() then later on inside\niio_device_unregister_eventset() and iio_buffers_free_sysfs_and_mask().\nDouble free leads to kernel panic.\n\nFix this by not touching ioctl handlers list directly but rather\nletting code responsible for registration call the matching cleanup\nroutine itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-cpr5-fxjg-jcr6/GHSA-cpr5-fxjg-jcr6.json b/advisories/unreviewed/2024/02/GHSA-cpr5-fxjg-jcr6/GHSA-cpr5-fxjg-jcr6.json index ddbf8e5d507..a2f46d03b2e 100644 --- a/advisories/unreviewed/2024/02/GHSA-cpr5-fxjg-jcr6/GHSA-cpr5-fxjg-jcr6.json +++ b/advisories/unreviewed/2024/02/GHSA-cpr5-fxjg-jcr6/GHSA-cpr5-fxjg-jcr6.json @@ -7,12 +7,8 @@ "CVE-2021-47041" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: fix incorrect locking in state_change sk callback\n\nWe are not changing anything in the TCP connection state so\nwe should not take a write_lock but rather a read lock.\n\nThis caused a deadlock when running nvmet-tcp and nvme-tcp\non the same system, where state_change callbacks on the\nhost and on the controller side have causal relationship\nand made lockdep report on this with blktests:\n\n================================\nWARNING: inconsistent lock state\n5.12.0-rc3 #1 Tainted: G I\n--------------------------------\ninconsistent {IN-SOFTIRQ-W} -> {SOFTIRQ-ON-R} usage.\nnvme/1324 [HC0[0]:SC0[0]:HE1:SE1] takes:\nffff888363151000 (clock-AF_INET){++-?}-{2:2}, at: nvme_tcp_state_change+0x21/0x150 [nvme_tcp]\n{IN-SOFTIRQ-W} state was registered at:\n __lock_acquire+0x79b/0x18d0\n lock_acquire+0x1ca/0x480\n _raw_write_lock_bh+0x39/0x80\n nvmet_tcp_state_change+0x21/0x170 [nvmet_tcp]\n tcp_fin+0x2a8/0x780\n tcp_data_queue+0xf94/0x1f20\n tcp_rcv_established+0x6ba/0x1f00\n tcp_v4_do_rcv+0x502/0x760\n tcp_v4_rcv+0x257e/0x3430\n ip_protocol_deliver_rcu+0x69/0x6a0\n ip_local_deliver_finish+0x1e2/0x2f0\n ip_local_deliver+0x1a2/0x420\n ip_rcv+0x4fb/0x6b0\n __netif_receive_skb_one_core+0x162/0x1b0\n process_backlog+0x1ff/0x770\n __napi_poll.constprop.0+0xa9/0x5c0\n net_rx_action+0x7b3/0xb30\n __do_softirq+0x1f0/0x940\n do_softirq+0xa1/0xd0\n __local_bh_enable_ip+0xd8/0x100\n ip_finish_output2+0x6b7/0x18a0\n __ip_queue_xmit+0x706/0x1aa0\n __tcp_transmit_skb+0x2068/0x2e20\n tcp_write_xmit+0xc9e/0x2bb0\n __tcp_push_pending_frames+0x92/0x310\n inet_shutdown+0x158/0x300\n __nvme_tcp_stop_queue+0x36/0x270 [nvme_tcp]\n nvme_tcp_stop_queue+0x87/0xb0 [nvme_tcp]\n nvme_tcp_teardown_admin_queue+0x69/0xe0 [nvme_tcp]\n nvme_do_delete_ctrl+0x100/0x10c [nvme_core]\n nvme_sysfs_delete.cold+0x8/0xd [nvme_core]\n kernfs_fop_write_iter+0x2c7/0x460\n new_sync_write+0x36c/0x610\n vfs_write+0x5c0/0x870\n ksys_write+0xf9/0x1d0\n do_syscall_64+0x33/0x40\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nirq event stamp: 10687\nhardirqs last enabled at (10687): [] _raw_spin_unlock_irqrestore+0x2d/0x40\nhardirqs last disabled at (10686): [] _raw_spin_lock_irqsave+0x68/0x90\nsoftirqs last enabled at (10684): [] __do_softirq+0x608/0x940\nsoftirqs last disabled at (10649): [] do_softirq+0xa1/0xd0\n\nother info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(clock-AF_INET);\n \n lock(clock-AF_INET);\n\n *** DEADLOCK ***\n\n5 locks held by nvme/1324:\n #0: ffff8884a01fe470 (sb_writers#4){.+.+}-{0:0}, at: ksys_write+0xf9/0x1d0\n #1: ffff8886e435c090 (&of->mutex){+.+.}-{3:3}, at: kernfs_fop_write_iter+0x216/0x460\n #2: ffff888104d90c38 (kn->active#255){++++}-{0:0}, at: kernfs_remove_self+0x22d/0x330\n #3: ffff8884634538d0 (&queue->queue_lock){+.+.}-{3:3}, at: nvme_tcp_stop_queue+0x52/0xb0 [nvme_tcp]\n #4: ffff888363150d30 (sk_lock-AF_INET){+.+.}-{0:0}, at: inet_shutdown+0x59/0x300\n\nstack backtrace:\nCPU: 26 PID: 1324 Comm: nvme Tainted: G I 5.12.0-rc3 #1\nHardware name: Dell Inc. PowerEdge R640/06NR82, BIOS 2.10.0 11/12/2020\nCall Trace:\n dump_stack+0x93/0xc2\n mark_lock_irq.cold+0x2c/0xb3\n ? verify_lock_unused+0x390/0x390\n ? stack_trace_consume_entry+0x160/0x160\n ? lock_downgrade+0x100/0x100\n ? save_trace+0x88/0x5e0\n ? _raw_spin_unlock_irqrestore+0x2d/0x40\n mark_lock+0x530/0x1470\n ? mark_lock_irq+0x1d10/0x1d10\n ? enqueue_timer+0x660/0x660\n mark_usage+0x215/0x2a0\n __lock_acquire+0x79b/0x18d0\n ? tcp_schedule_loss_probe.part.0+0x38c/0x520\n lock_acquire+0x1ca/0x480\n ? nvme_tcp_state_change+0x21/0x150 [nvme_tcp]\n ? rcu_read_unlock+0x40/0x40\n ? tcp_mtu_probe+0x1ae0/0x1ae0\n ? kmalloc_reserve+0xa0/0xa0\n ? sysfs_file_ops+0x170/0x170\n _raw_read_lock+0x3d/0xa0\n ? nvme_tcp_state_change+0x21/0x150 [nvme_tcp]\n nvme_tcp_state_change+0x21/0x150 [nvme_tcp]\n ? sysfs_file_ops\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-f8w9-xppp-jf8p/GHSA-f8w9-xppp-jf8p.json b/advisories/unreviewed/2024/02/GHSA-f8w9-xppp-jf8p/GHSA-f8w9-xppp-jf8p.json index 67d291f935d..60af92f65b8 100644 --- a/advisories/unreviewed/2024/02/GHSA-f8w9-xppp-jf8p/GHSA-f8w9-xppp-jf8p.json +++ b/advisories/unreviewed/2024/02/GHSA-f8w9-xppp-jf8p/GHSA-f8w9-xppp-jf8p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-f962-cfv2-wvqj/GHSA-f962-cfv2-wvqj.json b/advisories/unreviewed/2024/02/GHSA-f962-cfv2-wvqj/GHSA-f962-cfv2-wvqj.json index 2f280f1c026..1a1bf143240 100644 --- a/advisories/unreviewed/2024/02/GHSA-f962-cfv2-wvqj/GHSA-f962-cfv2-wvqj.json +++ b/advisories/unreviewed/2024/02/GHSA-f962-cfv2-wvqj/GHSA-f962-cfv2-wvqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-ffm2-8jrv-hhxj/GHSA-ffm2-8jrv-hhxj.json b/advisories/unreviewed/2024/02/GHSA-ffm2-8jrv-hhxj/GHSA-ffm2-8jrv-hhxj.json index a09bbef08d2..da7dab2009c 100644 --- a/advisories/unreviewed/2024/02/GHSA-ffm2-8jrv-hhxj/GHSA-ffm2-8jrv-hhxj.json +++ b/advisories/unreviewed/2024/02/GHSA-ffm2-8jrv-hhxj/GHSA-ffm2-8jrv-hhxj.json @@ -7,12 +7,8 @@ "CVE-2021-47039" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nataflop: potential out of bounds in do_format()\n\nThe function uses \"type\" as an array index:\n\n\tq = unit[drive].disk[type]->queue;\n\nUnfortunately the bounds check on \"type\" isn't done until later in the\nfunction. Fix this by moving the bounds check to the start.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-fwfw-qq2h-g6g5/GHSA-fwfw-qq2h-g6g5.json b/advisories/unreviewed/2024/02/GHSA-fwfw-qq2h-g6g5/GHSA-fwfw-qq2h-g6g5.json index 06dabd0ffad..d52cfddf2a3 100644 --- a/advisories/unreviewed/2024/02/GHSA-fwfw-qq2h-g6g5/GHSA-fwfw-qq2h-g6g5.json +++ b/advisories/unreviewed/2024/02/GHSA-fwfw-qq2h-g6g5/GHSA-fwfw-qq2h-g6g5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-fxr5-32j9-7wfr/GHSA-fxr5-32j9-7wfr.json b/advisories/unreviewed/2024/02/GHSA-fxr5-32j9-7wfr/GHSA-fxr5-32j9-7wfr.json index 2f9f794b68f..93e80046aa5 100644 --- a/advisories/unreviewed/2024/02/GHSA-fxr5-32j9-7wfr/GHSA-fxr5-32j9-7wfr.json +++ b/advisories/unreviewed/2024/02/GHSA-fxr5-32j9-7wfr/GHSA-fxr5-32j9-7wfr.json @@ -7,12 +7,8 @@ "CVE-2021-46983" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-rdma: Fix NULL deref when SEND is completed with error\n\nWhen running some traffic and taking down the link on peer, a\nretry counter exceeded error is received. This leads to\nnvmet_rdma_error_comp which tried accessing the cq_context to\nobtain the queue. The cq_context is no longer valid after the\nfix to use shared CQ mechanism and should be obtained similar\nto how it is obtained in other functions from the wc->qp.\n\n[ 905.786331] nvmet_rdma: SEND for CQE 0x00000000e3337f90 failed with status transport retry counter exceeded (12).\n[ 905.832048] BUG: unable to handle kernel NULL pointer dereference at 0000000000000048\n[ 905.839919] PGD 0 P4D 0\n[ 905.842464] Oops: 0000 1 SMP NOPTI\n[ 905.846144] CPU: 13 PID: 1557 Comm: kworker/13:1H Kdump: loaded Tainted: G OE --------- - - 4.18.0-304.el8.x86_64 #1\n[ 905.872135] RIP: 0010:nvmet_rdma_error_comp+0x5/0x1b [nvmet_rdma]\n[ 905.878259] Code: 19 4f c0 e8 89 b3 a5 f6 e9 5b e0 ff ff 0f b7 75 14 4c 89 ea 48 c7 c7 08 1a 4f c0 e8 71 b3 a5 f6 e9 4b e0 ff ff 0f 1f 44 00 00 <48> 8b 47 48 48 85 c0 74 08 48 89 c7 e9 98 bf 49 00 e9 c3 e3 ff ff\n[ 905.897135] RSP: 0018:ffffab601c45fe28 EFLAGS: 00010246\n[ 905.902387] RAX: 0000000000000065 RBX: ffff9e729ea2f800 RCX: 0000000000000000\n[ 905.909558] RDX: 0000000000000000 RSI: ffff9e72df9567c8 RDI: 0000000000000000\n[ 905.916731] RBP: ffff9e729ea2b400 R08: 000000000000074d R09: 0000000000000074\n[ 905.923903] R10: 0000000000000000 R11: ffffab601c45fcc0 R12: 0000000000000010\n[ 905.931074] R13: 0000000000000000 R14: 0000000000000010 R15: ffff9e729ea2f400\n[ 905.938247] FS: 0000000000000000(0000) GS:ffff9e72df940000(0000) knlGS:0000000000000000\n[ 905.938249] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 905.950067] nvmet_rdma: SEND for CQE 0x00000000c7356cca failed with status transport retry counter exceeded (12).\n[ 905.961855] CR2: 0000000000000048 CR3: 000000678d010004 CR4: 00000000007706e0\n[ 905.961855] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 905.961856] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 905.961857] PKRU: 55555554\n[ 906.010315] Call Trace:\n[ 906.012778] __ib_process_cq+0x89/0x170 [ib_core]\n[ 906.017509] ib_cq_poll_work+0x26/0x80 [ib_core]\n[ 906.022152] process_one_work+0x1a7/0x360\n[ 906.026182] ? create_worker+0x1a0/0x1a0\n[ 906.030123] worker_thread+0x30/0x390\n[ 906.033802] ? create_worker+0x1a0/0x1a0\n[ 906.037744] kthread+0x116/0x130\n[ 906.040988] ? kthread_flush_work_fn+0x10/0x10\n[ 906.045456] ret_from_fork+0x1f/0x40", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-g32h-2c9h-xpxj/GHSA-g32h-2c9h-xpxj.json b/advisories/unreviewed/2024/02/GHSA-g32h-2c9h-xpxj/GHSA-g32h-2c9h-xpxj.json index 42a43810d55..1a85fd1bbb5 100644 --- a/advisories/unreviewed/2024/02/GHSA-g32h-2c9h-xpxj/GHSA-g32h-2c9h-xpxj.json +++ b/advisories/unreviewed/2024/02/GHSA-g32h-2c9h-xpxj/GHSA-g32h-2c9h-xpxj.json @@ -7,12 +7,8 @@ "CVE-2021-46980" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Retrieve all the PDOs instead of just the first 4\n\ncommit 4dbc6a4ef06d (\"usb: typec: ucsi: save power data objects\nin PD mode\") introduced retrieval of the PDOs when connected to a\nPD-capable source. But only the first 4 PDOs are received since\nthat is the maximum number that can be fetched at a time given the\nMESSAGE_IN length limitation (16 bytes). However, as per the PD spec\na connected source may advertise up to a maximum of 7 PDOs.\n\nIf such a source is connected it's possible the PPM could have\nnegotiated a power contract with one of the PDOs at index greater\nthan 4, and would be reflected in the request data object's (RDO)\nobject position field. This would result in an out-of-bounds access\nwhen the rdo_index() is used to index into the src_pdos array in\nucsi_psy_get_voltage_now().\n\nWith the help of the UBSAN -fsanitize=array-bounds checker enabled\nthis exact issue is revealed when connecting to a PD source adapter\nthat advertise 5 PDOs and the PPM enters a contract having selected\nthe 5th one.\n\n[ 151.545106][ T70] Unexpected kernel BRK exception at EL1\n[ 151.545112][ T70] Internal error: BRK handler: f2005512 [#1] PREEMPT SMP\n...\n[ 151.545499][ T70] pc : ucsi_psy_get_prop+0x208/0x20c\n[ 151.545507][ T70] lr : power_supply_show_property+0xc0/0x328\n...\n[ 151.545542][ T70] Call trace:\n[ 151.545544][ T70] ucsi_psy_get_prop+0x208/0x20c\n[ 151.545546][ T70] power_supply_uevent+0x1a4/0x2f0\n[ 151.545550][ T70] dev_uevent+0x200/0x384\n[ 151.545555][ T70] kobject_uevent_env+0x1d4/0x7e8\n[ 151.545557][ T70] power_supply_changed_work+0x174/0x31c\n[ 151.545562][ T70] process_one_work+0x244/0x6f0\n[ 151.545564][ T70] worker_thread+0x3e0/0xa64\n\nWe can resolve this by instead retrieving and storing up to the\nmaximum of 7 PDOs in the con->src_pdos array. This would involve\ntwo calls to the GET_PDOS command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-gc58-f6gq-w9xv/GHSA-gc58-f6gq-w9xv.json b/advisories/unreviewed/2024/02/GHSA-gc58-f6gq-w9xv/GHSA-gc58-f6gq-w9xv.json index 0bf9cc51792..03fb5b060e0 100644 --- a/advisories/unreviewed/2024/02/GHSA-gc58-f6gq-w9xv/GHSA-gc58-f6gq-w9xv.json +++ b/advisories/unreviewed/2024/02/GHSA-gc58-f6gq-w9xv/GHSA-gc58-f6gq-w9xv.json @@ -7,12 +7,8 @@ "CVE-2021-47019" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7921: fix possible invalid register access\n\nDisable the interrupt and synchronze for the pending irq handlers to ensure\nthe irq tasklet is not being scheduled after the suspend to avoid the\npossible invalid register access acts when the host pcie controller is\nsuspended.\n\n[17932.910534] mt7921e 0000:01:00.0: pci_pm_suspend+0x0/0x22c returned 0 after 21375 usecs\n[17932.910590] pcieport 0000:00:00.0: calling pci_pm_suspend+0x0/0x22c @ 18565, parent: pci0000:00\n[17932.910602] pcieport 0000:00:00.0: pci_pm_suspend+0x0/0x22c returned 0 after 8 usecs\n[17932.910671] mtk-pcie 11230000.pcie: calling platform_pm_suspend+0x0/0x60 @ 22783, parent: soc\n[17932.910674] mtk-pcie 11230000.pcie: platform_pm_suspend+0x0/0x60 returned 0 after 0 usecs\n\n...\n\n17933.615352] x1 : 00000000000d4200 x0 : ffffff8269ca2300\n[17933.620666] Call trace:\n[17933.623127] mt76_mmio_rr+0x28/0xf0 [mt76]\n[17933.627234] mt7921_rr+0x38/0x44 [mt7921e]\n[17933.631339] mt7921_irq_tasklet+0x54/0x1d8 [mt7921e]\n[17933.636309] tasklet_action_common+0x12c/0x16c\n[17933.640754] tasklet_action+0x24/0x2c\n[17933.644418] __do_softirq+0x16c/0x344\n[17933.648082] irq_exit+0xa8/0xac\n[17933.651224] scheduler_ipi+0xd4/0x148\n[17933.654890] handle_IPI+0x164/0x2d4\n[17933.658379] gic_handle_irq+0x140/0x178\n[17933.662216] el1_irq+0xb8/0x180\n[17933.665361] cpuidle_enter_state+0xf8/0x204\n[17933.669544] cpuidle_enter+0x38/0x4c\n[17933.673122] do_idle+0x1a4/0x2a8\n[17933.676352] cpu_startup_entry+0x24/0x28\n[17933.680276] rest_init+0xd4/0xe0\n[17933.683508] arch_call_rest_init+0x10/0x18\n[17933.687606] start_kernel+0x340/0x3b4\n[17933.691279] Code: aa0003f5 d503201f f953eaa8 8b344108 (b9400113)\n[17933.697373] ---[ end trace a24b8e26ffbda3c5 ]---\n[17933.767846] Kernel panic - not syncing: Fatal exception in interrupt", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-gfg7-ch8h-x539/GHSA-gfg7-ch8h-x539.json b/advisories/unreviewed/2024/02/GHSA-gfg7-ch8h-x539/GHSA-gfg7-ch8h-x539.json index 47f14115a2e..2fd4d8abf42 100644 --- a/advisories/unreviewed/2024/02/GHSA-gfg7-ch8h-x539/GHSA-gfg7-ch8h-x539.json +++ b/advisories/unreviewed/2024/02/GHSA-gfg7-ch8h-x539/GHSA-gfg7-ch8h-x539.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json b/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json index 2754c61320a..7ed1ac6a322 100644 --- a/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json +++ b/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json @@ -7,12 +7,8 @@ "CVE-2021-47001" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Fix cwnd update ordering\n\nAfter a reconnect, the reply handler is opening the cwnd (and thus\nenabling more RPC Calls to be sent) /before/ rpcrdma_post_recvs()\ncan post enough Receive WRs to receive their replies. This causes an\nRNR and the new connection is lost immediately.\n\nThe race is most clearly exposed when KASAN and disconnect injection\nare enabled. This slows down rpcrdma_rep_create() enough to allow\nthe send side to post a bunch of RPC Calls before the Receive\ncompletion handler can invoke ib_post_recv().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-h6m9-gq43-hhq2/GHSA-h6m9-gq43-hhq2.json b/advisories/unreviewed/2024/02/GHSA-h6m9-gq43-hhq2/GHSA-h6m9-gq43-hhq2.json index 808fe6113b7..950771da575 100644 --- a/advisories/unreviewed/2024/02/GHSA-h6m9-gq43-hhq2/GHSA-h6m9-gq43-hhq2.json +++ b/advisories/unreviewed/2024/02/GHSA-h6m9-gq43-hhq2/GHSA-h6m9-gq43-hhq2.json @@ -7,12 +7,8 @@ "CVE-2021-47026" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-clt: destroy sysfs after removing session from active list\n\nA session can be removed dynamically by sysfs interface \"remove_path\" that\neventually calls rtrs_clt_remove_path_from_sysfs function. The current\nrtrs_clt_remove_path_from_sysfs first removes the sysfs interfaces and\nfrees sess->stats object. Second it removes the session from the active\nlist.\n\nTherefore some functions could access non-connected session and access the\nfreed sess->stats object even-if they check the session status before\naccessing the session.\n\nFor instance rtrs_clt_request and get_next_path_min_inflight check the\nsession status and try to send IO to the session. The session status\ncould be changed when they are trying to send IO but they could not catch\nthe change and update the statistics information in sess->stats object,\nand generate use-after-free problem.\n(see: \"RDMA/rtrs-clt: Check state of the rtrs_clt_sess before reading its\nstats\")\n\nThis patch changes the rtrs_clt_remove_path_from_sysfs to remove the\nsession from the active session list and then destroy the sysfs\ninterfaces.\n\nEach function still should check the session status because closing or\nerror recovery paths can change the status.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-h78p-v7hc-728f/GHSA-h78p-v7hc-728f.json b/advisories/unreviewed/2024/02/GHSA-h78p-v7hc-728f/GHSA-h78p-v7hc-728f.json index d2fb7451999..99024c582c2 100644 --- a/advisories/unreviewed/2024/02/GHSA-h78p-v7hc-728f/GHSA-h78p-v7hc-728f.json +++ b/advisories/unreviewed/2024/02/GHSA-h78p-v7hc-728f/GHSA-h78p-v7hc-728f.json @@ -7,12 +7,8 @@ "CVE-2021-46986" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: gadget: Free gadget structure only after freeing endpoints\n\nAs part of commit e81a7018d93a (\"usb: dwc3: allocate gadget structure\ndynamically\") the dwc3_gadget_release() was added which will free\nthe dwc->gadget structure upon the device's removal when\nusb_del_gadget_udc() is called in dwc3_gadget_exit().\n\nHowever, simply freeing the gadget results a dangling pointer\nsituation: the endpoints created in dwc3_gadget_init_endpoints()\nhave their dep->endpoint.ep_list members chained off the list_head\nanchored at dwc->gadget->ep_list. Thus when dwc->gadget is freed,\nthe first dwc3_ep in the list now has a dangling prev pointer and\nlikewise for the next pointer of the dwc3_ep at the tail of the list.\nThe dwc3_gadget_free_endpoints() that follows will result in a\nuse-after-free when it calls list_del().\n\nThis was caught by enabling KASAN and performing a driver unbind.\nThe recent commit 568262bf5492 (\"usb: dwc3: core: Add shutdown\ncallback for dwc3\") also exposes this as a panic during shutdown.\n\nThere are a few possibilities to fix this. One could be to perform\na list_del() of the gadget->ep_list itself which removes it from\nthe rest of the dwc3_ep chain.\n\nAnother approach is what this patch does, by splitting up the\nusb_del_gadget_udc() call into its separate \"del\" and \"put\"\ncomponents. This allows dwc3_gadget_free_endpoints() to be\ncalled before the gadget is finally freed with usb_put_gadget().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-h7g2-m8qw-9mfj/GHSA-h7g2-m8qw-9mfj.json b/advisories/unreviewed/2024/02/GHSA-h7g2-m8qw-9mfj/GHSA-h7g2-m8qw-9mfj.json index ca8e2618a56..41c3773ca71 100644 --- a/advisories/unreviewed/2024/02/GHSA-h7g2-m8qw-9mfj/GHSA-h7g2-m8qw-9mfj.json +++ b/advisories/unreviewed/2024/02/GHSA-h7g2-m8qw-9mfj/GHSA-h7g2-m8qw-9mfj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-h958-4cw7-rqgr/GHSA-h958-4cw7-rqgr.json b/advisories/unreviewed/2024/02/GHSA-h958-4cw7-rqgr/GHSA-h958-4cw7-rqgr.json index 544064c2774..f70de50dda4 100644 --- a/advisories/unreviewed/2024/02/GHSA-h958-4cw7-rqgr/GHSA-h958-4cw7-rqgr.json +++ b/advisories/unreviewed/2024/02/GHSA-h958-4cw7-rqgr/GHSA-h958-4cw7-rqgr.json @@ -7,12 +7,8 @@ "CVE-2021-47036" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudp: skip L4 aggregation for UDP tunnel packets\n\nIf NETIF_F_GRO_FRAGLIST or NETIF_F_GRO_UDP_FWD are enabled, and there\nare UDP tunnels available in the system, udp_gro_receive() could end-up\ndoing L4 aggregation (either SKB_GSO_UDP_L4 or SKB_GSO_FRAGLIST) at\nthe outer UDP tunnel level for packets effectively carrying and UDP\ntunnel header.\n\nThat could cause inner protocol corruption. If e.g. the relevant\npackets carry a vxlan header, different vxlan ids will be ignored/\naggregated to the same GSO packet. Inner headers will be ignored, too,\nso that e.g. TCP over vxlan push packets will be held in the GRO\nengine till the next flush, etc.\n\nJust skip the SKB_GSO_UDP_L4 and SKB_GSO_FRAGLIST code path if the\ncurrent packet could land in a UDP tunnel, and let udp_gro_receive()\ndo GRO via udp_sk(sk)->gro_receive.\n\nThe check implemented in this patch is broader than what is strictly\nneeded, as the existing UDP tunnel could be e.g. configured on top of\na different device: we could end-up skipping GRO at-all for some packets.\n\nAnyhow, that is a very thin corner case and covering it will add quite\na bit of complexity.\n\nv1 -> v2:\n - hopefully clarify the commit message", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-hhq7-4gxq-q8mp/GHSA-hhq7-4gxq-q8mp.json b/advisories/unreviewed/2024/02/GHSA-hhq7-4gxq-q8mp/GHSA-hhq7-4gxq-q8mp.json index d38d7b7edc5..fc3df7516d1 100644 --- a/advisories/unreviewed/2024/02/GHSA-hhq7-4gxq-q8mp/GHSA-hhq7-4gxq-q8mp.json +++ b/advisories/unreviewed/2024/02/GHSA-hhq7-4gxq-q8mp/GHSA-hhq7-4gxq-q8mp.json @@ -7,12 +7,8 @@ "CVE-2021-47048" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-zynqmp-gqspi: fix use-after-free in zynqmp_qspi_exec_op\n\nWhen handling op->addr, it is using the buffer \"tmpbuf\" which has been\nfreed. This will trigger a use-after-free KASAN warning. Let's use\ntemporary variables to store op->addr.val and op->cmd.opcode to fix\nthis issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-jfh3-wq2r-73gg/GHSA-jfh3-wq2r-73gg.json b/advisories/unreviewed/2024/02/GHSA-jfh3-wq2r-73gg/GHSA-jfh3-wq2r-73gg.json index 743b9cb5e32..fa2a5e958ea 100644 --- a/advisories/unreviewed/2024/02/GHSA-jfh3-wq2r-73gg/GHSA-jfh3-wq2r-73gg.json +++ b/advisories/unreviewed/2024/02/GHSA-jfh3-wq2r-73gg/GHSA-jfh3-wq2r-73gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-jfrp-h2rj-4pmw/GHSA-jfrp-h2rj-4pmw.json b/advisories/unreviewed/2024/02/GHSA-jfrp-h2rj-4pmw/GHSA-jfrp-h2rj-4pmw.json index 1d5bc397517..44203ea263e 100644 --- a/advisories/unreviewed/2024/02/GHSA-jfrp-h2rj-4pmw/GHSA-jfrp-h2rj-4pmw.json +++ b/advisories/unreviewed/2024/02/GHSA-jfrp-h2rj-4pmw/GHSA-jfrp-h2rj-4pmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-jhxj-w2j8-p3gf/GHSA-jhxj-w2j8-p3gf.json b/advisories/unreviewed/2024/02/GHSA-jhxj-w2j8-p3gf/GHSA-jhxj-w2j8-p3gf.json index 963c8c2b786..78035c54ff0 100644 --- a/advisories/unreviewed/2024/02/GHSA-jhxj-w2j8-p3gf/GHSA-jhxj-w2j8-p3gf.json +++ b/advisories/unreviewed/2024/02/GHSA-jhxj-w2j8-p3gf/GHSA-jhxj-w2j8-p3gf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-jvv7-jhh3-m96v/GHSA-jvv7-jhh3-m96v.json b/advisories/unreviewed/2024/02/GHSA-jvv7-jhh3-m96v/GHSA-jvv7-jhh3-m96v.json index 975c31131ac..b8c4a94f960 100644 --- a/advisories/unreviewed/2024/02/GHSA-jvv7-jhh3-m96v/GHSA-jvv7-jhh3-m96v.json +++ b/advisories/unreviewed/2024/02/GHSA-jvv7-jhh3-m96v/GHSA-jvv7-jhh3-m96v.json @@ -7,12 +7,8 @@ "CVE-2021-47011" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: memcontrol: slab: fix obtain a reference to a freeing memcg\n\nPatch series \"Use obj_cgroup APIs to charge kmem pages\", v5.\n\nSince Roman's series \"The new cgroup slab memory controller\" applied.\nAll slab objects are charged with the new APIs of obj_cgroup. The new\nAPIs introduce a struct obj_cgroup to charge slab objects. It prevents\nlong-living objects from pinning the original memory cgroup in the\nmemory. But there are still some corner objects (e.g. allocations\nlarger than order-1 page on SLUB) which are not charged with the new\nAPIs. Those objects (include the pages which are allocated from buddy\nallocator directly) are charged as kmem pages which still hold a\nreference to the memory cgroup.\n\nE.g. We know that the kernel stack is charged as kmem pages because the\nsize of the kernel stack can be greater than 2 pages (e.g. 16KB on\nx86_64 or arm64). If we create a thread (suppose the thread stack is\ncharged to memory cgroup A) and then move it from memory cgroup A to\nmemory cgroup B. Because the kernel stack of the thread hold a\nreference to the memory cgroup A. The thread can pin the memory cgroup\nA in the memory even if we remove the cgroup A. If we want to see this\nscenario by using the following script. We can see that the system has\nadded 500 dying cgroups (This is not a real world issue, just a script\nto show that the large kmallocs are charged as kmem pages which can pin\nthe memory cgroup in the memory).\n\n\t#!/bin/bash\n\n\tcat /proc/cgroups | grep memory\n\n\tcd /sys/fs/cgroup/memory\n\techo 1 > memory.move_charge_at_immigrate\n\n\tfor i in range{1..500}\n\tdo\n\t\tmkdir kmem_test\n\t\techo $$ > kmem_test/cgroup.procs\n\t\tsleep 3600 &\n\t\techo $$ > cgroup.procs\n\t\techo `cat kmem_test/cgroup.procs` > cgroup.procs\n\t\trmdir kmem_test\n\tdone\n\n\tcat /proc/cgroups | grep memory\n\nThis patchset aims to make those kmem pages to drop the reference to\nmemory cgroup by using the APIs of obj_cgroup. Finally, we can see that\nthe number of the dying cgroups will not increase if we run the above test\nscript.\n\nThis patch (of 7):\n\nThe rcu_read_lock/unlock only can guarantee that the memcg will not be\nfreed, but it cannot guarantee the success of css_get (which is in the\nrefill_stock when cached memcg changed) to memcg.\n\n rcu_read_lock()\n memcg = obj_cgroup_memcg(old)\n __memcg_kmem_uncharge(memcg)\n refill_stock(memcg)\n if (stock->cached != memcg)\n // css_get can change the ref counter from 0 back to 1.\n css_get(&memcg->css)\n rcu_read_unlock()\n\nThis fix is very like the commit:\n\n eefbfa7fd678 (\"mm: memcg/slab: fix use after free in obj_cgroup_charge\")\n\nFix this by holding a reference to the memcg which is passed to the\n__memcg_kmem_uncharge() before calling __memcg_kmem_uncharge().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-jxg2-8mcp-74q3/GHSA-jxg2-8mcp-74q3.json b/advisories/unreviewed/2024/02/GHSA-jxg2-8mcp-74q3/GHSA-jxg2-8mcp-74q3.json index 18e92abb798..abe4627c066 100644 --- a/advisories/unreviewed/2024/02/GHSA-jxg2-8mcp-74q3/GHSA-jxg2-8mcp-74q3.json +++ b/advisories/unreviewed/2024/02/GHSA-jxg2-8mcp-74q3/GHSA-jxg2-8mcp-74q3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-m99h-2hm4-q649/GHSA-m99h-2hm4-q649.json b/advisories/unreviewed/2024/02/GHSA-m99h-2hm4-q649/GHSA-m99h-2hm4-q649.json index 93beb47ea4c..abf43f8aa5d 100644 --- a/advisories/unreviewed/2024/02/GHSA-m99h-2hm4-q649/GHSA-m99h-2hm4-q649.json +++ b/advisories/unreviewed/2024/02/GHSA-m99h-2hm4-q649/GHSA-m99h-2hm4-q649.json @@ -7,12 +7,8 @@ "CVE-2021-46977" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: VMX: Disable preemption when probing user return MSRs\n\nDisable preemption when probing a user return MSR via RDSMR/WRMSR. If\nthe MSR holds a different value per logical CPU, the WRMSR could corrupt\nthe host's value if KVM is preempted between the RDMSR and WRMSR, and\nthen rescheduled on a different CPU.\n\nOpportunistically land the helper in common x86, SVM will use the helper\nin a future commit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-mvm9-g6f5-rfmr/GHSA-mvm9-g6f5-rfmr.json b/advisories/unreviewed/2024/02/GHSA-mvm9-g6f5-rfmr/GHSA-mvm9-g6f5-rfmr.json index 00d711a5f19..79c512a86c1 100644 --- a/advisories/unreviewed/2024/02/GHSA-mvm9-g6f5-rfmr/GHSA-mvm9-g6f5-rfmr.json +++ b/advisories/unreviewed/2024/02/GHSA-mvm9-g6f5-rfmr/GHSA-mvm9-g6f5-rfmr.json @@ -7,12 +7,8 @@ "CVE-2021-47015" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix RX consumer index logic in the error path.\n\nIn bnxt_rx_pkt(), the RX buffers are expected to complete in order.\nIf the RX consumer index indicates an out of order buffer completion,\nit means we are hitting a hardware bug and the driver will abort all\nremaining RX packets and reset the RX ring. The RX consumer index\nthat we pass to bnxt_discard_rx() is not correct. We should be\npassing the current index (tmp_raw_cons) instead of the old index\n(raw_cons). This bug can cause us to be at the wrong index when\ntrying to abort the next RX packet. It can crash like this:\n\n #0 [ffff9bbcdf5c39a8] machine_kexec at ffffffff9b05e007\n #1 [ffff9bbcdf5c3a00] __crash_kexec at ffffffff9b111232\n #2 [ffff9bbcdf5c3ad0] panic at ffffffff9b07d61e\n #3 [ffff9bbcdf5c3b50] oops_end at ffffffff9b030978\n #4 [ffff9bbcdf5c3b78] no_context at ffffffff9b06aaf0\n #5 [ffff9bbcdf5c3bd8] __bad_area_nosemaphore at ffffffff9b06ae2e\n #6 [ffff9bbcdf5c3c28] bad_area_nosemaphore at ffffffff9b06af24\n #7 [ffff9bbcdf5c3c38] __do_page_fault at ffffffff9b06b67e\n #8 [ffff9bbcdf5c3cb0] do_page_fault at ffffffff9b06bb12\n #9 [ffff9bbcdf5c3ce0] page_fault at ffffffff9bc015c5\n [exception RIP: bnxt_rx_pkt+237]\n RIP: ffffffffc0259cdd RSP: ffff9bbcdf5c3d98 RFLAGS: 00010213\n RAX: 000000005dd8097f RBX: ffff9ba4cb11b7e0 RCX: ffffa923cf6e9000\n RDX: 0000000000000fff RSI: 0000000000000627 RDI: 0000000000001000\n RBP: ffff9bbcdf5c3e60 R8: 0000000000420003 R9: 000000000000020d\n R10: ffffa923cf6ec138 R11: ffff9bbcdf5c3e83 R12: ffff9ba4d6f928c0\n R13: ffff9ba4cac28080 R14: ffff9ba4cb11b7f0 R15: ffff9ba4d5a30000\n ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-p4fh-q7qh-cv87/GHSA-p4fh-q7qh-cv87.json b/advisories/unreviewed/2024/02/GHSA-p4fh-q7qh-cv87/GHSA-p4fh-q7qh-cv87.json index 7e4261956cb..7a693c4acef 100644 --- a/advisories/unreviewed/2024/02/GHSA-p4fh-q7qh-cv87/GHSA-p4fh-q7qh-cv87.json +++ b/advisories/unreviewed/2024/02/GHSA-p4fh-q7qh-cv87/GHSA-p4fh-q7qh-cv87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-p6cw-fvmc-r6vh/GHSA-p6cw-fvmc-r6vh.json b/advisories/unreviewed/2024/02/GHSA-p6cw-fvmc-r6vh/GHSA-p6cw-fvmc-r6vh.json index 86295c7ae37..0186bc2300c 100644 --- a/advisories/unreviewed/2024/02/GHSA-p6cw-fvmc-r6vh/GHSA-p6cw-fvmc-r6vh.json +++ b/advisories/unreviewed/2024/02/GHSA-p6cw-fvmc-r6vh/GHSA-p6cw-fvmc-r6vh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-p768-cw2x-34vr/GHSA-p768-cw2x-34vr.json b/advisories/unreviewed/2024/02/GHSA-p768-cw2x-34vr/GHSA-p768-cw2x-34vr.json index ef3832cf80c..ee1cd17a48a 100644 --- a/advisories/unreviewed/2024/02/GHSA-p768-cw2x-34vr/GHSA-p768-cw2x-34vr.json +++ b/advisories/unreviewed/2024/02/GHSA-p768-cw2x-34vr/GHSA-p768-cw2x-34vr.json @@ -7,12 +7,8 @@ "CVE-2021-47018" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/64: Fix the definition of the fixmap area\n\nAt the time being, the fixmap area is defined at the top of\nthe address space or just below KASAN.\n\nThis definition is not valid for PPC64.\n\nFor PPC64, use the top of the I/O space.\n\nBecause of circular dependencies, it is not possible to include\nasm/fixmap.h in asm/book3s/64/pgtable.h , so define a fixed size\nAREA at the top of the I/O space for fixmap and ensure during\nbuild that the size is big enough.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-p822-5pxq-5x9h/GHSA-p822-5pxq-5x9h.json b/advisories/unreviewed/2024/02/GHSA-p822-5pxq-5x9h/GHSA-p822-5pxq-5x9h.json index 23cc07593f5..bd9c2b6316c 100644 --- a/advisories/unreviewed/2024/02/GHSA-p822-5pxq-5x9h/GHSA-p822-5pxq-5x9h.json +++ b/advisories/unreviewed/2024/02/GHSA-p822-5pxq-5x9h/GHSA-p822-5pxq-5x9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-phj2-fhf8-vr32/GHSA-phj2-fhf8-vr32.json b/advisories/unreviewed/2024/02/GHSA-phj2-fhf8-vr32/GHSA-phj2-fhf8-vr32.json index c76fc434855..5b93adf11cd 100644 --- a/advisories/unreviewed/2024/02/GHSA-phj2-fhf8-vr32/GHSA-phj2-fhf8-vr32.json +++ b/advisories/unreviewed/2024/02/GHSA-phj2-fhf8-vr32/GHSA-phj2-fhf8-vr32.json @@ -7,12 +7,8 @@ "CVE-2021-46982" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: compress: fix race condition of overwrite vs truncate\n\npos_fsstress testcase complains a panic as belew:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/compress.c:1082!\ninvalid opcode: 0000 [#1] SMP PTI\nCPU: 4 PID: 2753477 Comm: kworker/u16:2 Tainted: G OE 5.12.0-rc1-custom #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\nWorkqueue: writeback wb_workfn (flush-252:16)\nRIP: 0010:prepare_compress_overwrite+0x4c0/0x760 [f2fs]\nCall Trace:\n f2fs_prepare_compress_overwrite+0x5f/0x80 [f2fs]\n f2fs_write_cache_pages+0x468/0x8a0 [f2fs]\n f2fs_write_data_pages+0x2a4/0x2f0 [f2fs]\n do_writepages+0x38/0xc0\n __writeback_single_inode+0x44/0x2a0\n writeback_sb_inodes+0x223/0x4d0\n __writeback_inodes_wb+0x56/0xf0\n wb_writeback+0x1dd/0x290\n wb_workfn+0x309/0x500\n process_one_work+0x220/0x3c0\n worker_thread+0x53/0x420\n kthread+0x12f/0x150\n ret_from_fork+0x22/0x30\n\nThe root cause is truncate() may race with overwrite as below,\nso that one reference count left in page can not guarantee the\npage attaching in mapping tree all the time, after truncation,\nlater find_lock_page() may return NULL pointer.\n\n- prepare_compress_overwrite\n - f2fs_pagecache_get_page\n - unlock_page\n\t\t\t\t\t- f2fs_setattr\n\t\t\t\t\t - truncate_setsize\n\t\t\t\t\t - truncate_inode_page\n\t\t\t\t\t - delete_from_page_cache\n - find_lock_page\n\nFix this by avoiding referencing updated page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-phvq-9637-vp75/GHSA-phvq-9637-vp75.json b/advisories/unreviewed/2024/02/GHSA-phvq-9637-vp75/GHSA-phvq-9637-vp75.json index 3a648f51b47..ef82bb67b51 100644 --- a/advisories/unreviewed/2024/02/GHSA-phvq-9637-vp75/GHSA-phvq-9637-vp75.json +++ b/advisories/unreviewed/2024/02/GHSA-phvq-9637-vp75/GHSA-phvq-9637-vp75.json @@ -7,12 +7,8 @@ "CVE-2021-47040" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: fix overflows checks in provide buffers\n\nColin reported before possible overflow and sign extension problems in\nio_provide_buffers_prep(). As Linus pointed out previous attempt did nothing\nuseful, see d81269fecb8ce (\"io_uring: fix provide_buffers sign extension\").\n\nDo that with help of check__overflow helpers. And fix struct\nio_provide_buf::len type, as it doesn't make much sense to keep it\nsigned.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-q4h6-6373-whjg/GHSA-q4h6-6373-whjg.json b/advisories/unreviewed/2024/02/GHSA-q4h6-6373-whjg/GHSA-q4h6-6373-whjg.json index c28a2afa6b4..095a4ad92e0 100644 --- a/advisories/unreviewed/2024/02/GHSA-q4h6-6373-whjg/GHSA-q4h6-6373-whjg.json +++ b/advisories/unreviewed/2024/02/GHSA-q4h6-6373-whjg/GHSA-q4h6-6373-whjg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-qc2p-p8wc-jp2h/GHSA-qc2p-p8wc-jp2h.json b/advisories/unreviewed/2024/02/GHSA-qc2p-p8wc-jp2h/GHSA-qc2p-p8wc-jp2h.json index b9cb5c8dd90..27c390521b9 100644 --- a/advisories/unreviewed/2024/02/GHSA-qc2p-p8wc-jp2h/GHSA-qc2p-p8wc-jp2h.json +++ b/advisories/unreviewed/2024/02/GHSA-qc2p-p8wc-jp2h/GHSA-qc2p-p8wc-jp2h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-qp35-683c-hfxv/GHSA-qp35-683c-hfxv.json b/advisories/unreviewed/2024/02/GHSA-qp35-683c-hfxv/GHSA-qp35-683c-hfxv.json index 69b1ab1a51a..4b523af0d0a 100644 --- a/advisories/unreviewed/2024/02/GHSA-qp35-683c-hfxv/GHSA-qp35-683c-hfxv.json +++ b/advisories/unreviewed/2024/02/GHSA-qp35-683c-hfxv/GHSA-qp35-683c-hfxv.json @@ -7,12 +7,8 @@ "CVE-2021-47035" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Remove WO permissions on second-level paging entries\n\nWhen the first level page table is used for IOVA translation, it only\nsupports Read-Only and Read-Write permissions. The Write-Only permission\nis not supported as the PRESENT bit (implying Read permission) should\nalways set. When using second level, we still give separate permissions\nthat allows WriteOnly which seems inconsistent and awkward. We want to\nhave consistent behavior. After moving to 1st level, we don't want things\nto work sometimes, and break if we use 2nd level for the same mappings.\nHence remove this configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-qq69-34qx-5j24/GHSA-qq69-34qx-5j24.json b/advisories/unreviewed/2024/02/GHSA-qq69-34qx-5j24/GHSA-qq69-34qx-5j24.json index 415fa6bbeec..91f4d2d5b33 100644 --- a/advisories/unreviewed/2024/02/GHSA-qq69-34qx-5j24/GHSA-qq69-34qx-5j24.json +++ b/advisories/unreviewed/2024/02/GHSA-qq69-34qx-5j24/GHSA-qq69-34qx-5j24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-rxx8-hw28-8whc/GHSA-rxx8-hw28-8whc.json b/advisories/unreviewed/2024/02/GHSA-rxx8-hw28-8whc/GHSA-rxx8-hw28-8whc.json index 8f705d01ca6..42e749f2432 100644 --- a/advisories/unreviewed/2024/02/GHSA-rxx8-hw28-8whc/GHSA-rxx8-hw28-8whc.json +++ b/advisories/unreviewed/2024/02/GHSA-rxx8-hw28-8whc/GHSA-rxx8-hw28-8whc.json @@ -7,12 +7,8 @@ "CVE-2021-47030" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7615: fix memory leak in mt7615_coredump_work\n\nSimilar to the issue fixed in mt7921_coredump_work, fix a possible memory\nleak in mt7615_coredump_work routine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-v368-7gcx-f4wj/GHSA-v368-7gcx-f4wj.json b/advisories/unreviewed/2024/02/GHSA-v368-7gcx-f4wj/GHSA-v368-7gcx-f4wj.json index 9ba5cc9b1f2..db49142bc9f 100644 --- a/advisories/unreviewed/2024/02/GHSA-v368-7gcx-f4wj/GHSA-v368-7gcx-f4wj.json +++ b/advisories/unreviewed/2024/02/GHSA-v368-7gcx-f4wj/GHSA-v368-7gcx-f4wj.json @@ -7,12 +7,8 @@ "CVE-2021-47042" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Free local data after use\n\nFixes the following memory leak in dc_link_construct():\n\nunreferenced object 0xffffa03e81471400 (size 1024):\ncomm \"amd_module_load\", pid 2486, jiffies 4294946026 (age 10.544s)\nhex dump (first 32 bytes):\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\nbacktrace:\n[<000000000bdf5c4a>] kmem_cache_alloc_trace+0x30a/0x4a0\n[<00000000e7c59f0e>] link_create+0xce/0xac0 [amdgpu]\n[<000000002fb6c072>] dc_create+0x370/0x720 [amdgpu]\n[<000000000094d1f3>] amdgpu_dm_init+0x18e/0x17a0 [amdgpu]\n[<00000000bec048fd>] dm_hw_init+0x12/0x20 [amdgpu]\n[<00000000a2bb7cf6>] amdgpu_device_init+0x1463/0x1e60 [amdgpu]\n[<0000000032d3bb13>] amdgpu_driver_load_kms+0x5b/0x330 [amdgpu]\n[<00000000a27834f9>] amdgpu_pci_probe+0x192/0x280 [amdgpu]\n[<00000000fec7d291>] local_pci_probe+0x47/0xa0\n[<0000000055dbbfa7>] pci_device_probe+0xe3/0x180\n[<00000000815da970>] really_probe+0x1c4/0x4e0\n[<00000000b4b6974b>] driver_probe_device+0x62/0x150\n[<000000000f9ecc61>] device_driver_attach+0x58/0x60\n[<000000000f65c843>] __driver_attach+0xd6/0x150\n[<000000002f5e3683>] bus_for_each_dev+0x6a/0xc0\n[<00000000a1cfc897>] driver_attach+0x1e/0x20", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-vw5q-4j3r-jcj8/GHSA-vw5q-4j3r-jcj8.json b/advisories/unreviewed/2024/02/GHSA-vw5q-4j3r-jcj8/GHSA-vw5q-4j3r-jcj8.json index ecc6e9c93f9..3e86281a70f 100644 --- a/advisories/unreviewed/2024/02/GHSA-vw5q-4j3r-jcj8/GHSA-vw5q-4j3r-jcj8.json +++ b/advisories/unreviewed/2024/02/GHSA-vw5q-4j3r-jcj8/GHSA-vw5q-4j3r-jcj8.json @@ -7,12 +7,8 @@ "CVE-2021-47049" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: Use after free in __vmbus_open()\n\nThe \"open_info\" variable is added to the &vmbus_connection.chn_msg_list,\nbut the error handling frees \"open_info\" without removing it from the\nlist. This will result in a use after free. First remove it from the\nlist, and then free it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-vwgp-x2rf-chq4/GHSA-vwgp-x2rf-chq4.json b/advisories/unreviewed/2024/02/GHSA-vwgp-x2rf-chq4/GHSA-vwgp-x2rf-chq4.json index 0d918e3a2a6..8c5c3183ed8 100644 --- a/advisories/unreviewed/2024/02/GHSA-vwgp-x2rf-chq4/GHSA-vwgp-x2rf-chq4.json +++ b/advisories/unreviewed/2024/02/GHSA-vwgp-x2rf-chq4/GHSA-vwgp-x2rf-chq4.json @@ -7,12 +7,8 @@ "CVE-2023-41165" ], "details": "An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious JavaScript elements that can result in data theft.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w36p-947m-7c32/GHSA-w36p-947m-7c32.json b/advisories/unreviewed/2024/02/GHSA-w36p-947m-7c32/GHSA-w36p-947m-7c32.json index 289d98bb373..f83ac3e3c66 100644 --- a/advisories/unreviewed/2024/02/GHSA-w36p-947m-7c32/GHSA-w36p-947m-7c32.json +++ b/advisories/unreviewed/2024/02/GHSA-w36p-947m-7c32/GHSA-w36p-947m-7c32.json @@ -7,12 +7,8 @@ "CVE-2021-46988" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: release page in error path to avoid BUG_ON\n\nConsider the following sequence of events:\n\n1. Userspace issues a UFFD ioctl, which ends up calling into\n shmem_mfill_atomic_pte(). We successfully account the blocks, we\n shmem_alloc_page(), but then the copy_from_user() fails. We return\n -ENOENT. We don't release the page we allocated.\n2. Our caller detects this error code, tries the copy_from_user() after\n dropping the mmap_lock, and retries, calling back into\n shmem_mfill_atomic_pte().\n3. Meanwhile, let's say another process filled up the tmpfs being used.\n4. So shmem_mfill_atomic_pte() fails to account blocks this time, and\n immediately returns - without releasing the page.\n\nThis triggers a BUG_ON in our caller, which asserts that the page\nshould always be consumed, unless -ENOENT is returned.\n\nTo fix this, detect if we have such a \"dangling\" page when accounting\nfails, and if so, release it before returning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w7xf-wp34-j8rv/GHSA-w7xf-wp34-j8rv.json b/advisories/unreviewed/2024/02/GHSA-w7xf-wp34-j8rv/GHSA-w7xf-wp34-j8rv.json index 30394d8df76..398e7408e7d 100644 --- a/advisories/unreviewed/2024/02/GHSA-w7xf-wp34-j8rv/GHSA-w7xf-wp34-j8rv.json +++ b/advisories/unreviewed/2024/02/GHSA-w7xf-wp34-j8rv/GHSA-w7xf-wp34-j8rv.json @@ -7,12 +7,8 @@ "CVE-2021-47025" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/mediatek: Always enable the clk on resume\n\nIn mtk_iommu_runtime_resume always enable the clk, even\nif m4u_dom is null. Otherwise the 'suspend' cb might\ndisable the clk which is already disabled causing the warning:\n\n[ 1.586104] infra_m4u already disabled\n[ 1.586133] WARNING: CPU: 0 PID: 121 at drivers/clk/clk.c:952 clk_core_disable+0xb0/0xb8\n[ 1.594391] mtk-iommu 10205000.iommu: bound 18001000.larb (ops mtk_smi_larb_component_ops)\n[ 1.598108] Modules linked in:\n[ 1.598114] CPU: 0 PID: 121 Comm: kworker/0:2 Not tainted 5.12.0-rc5 #69\n[ 1.609246] mtk-iommu 10205000.iommu: bound 14027000.larb (ops mtk_smi_larb_component_ops)\n[ 1.617487] Hardware name: Google Elm (DT)\n[ 1.617491] Workqueue: pm pm_runtime_work\n[ 1.620545] mtk-iommu 10205000.iommu: bound 19001000.larb (ops mtk_smi_larb_component_ops)\n\n[ 1.627229] pstate: 60000085 (nZCv daIf -PAN -UAO -TCO BTYPE=--)\n[ 1.659297] pc : clk_core_disable+0xb0/0xb8\n[ 1.663475] lr : clk_core_disable+0xb0/0xb8\n[ 1.667652] sp : ffff800011b9bbe0\n[ 1.670959] x29: ffff800011b9bbe0 x28: 0000000000000000\n[ 1.676267] x27: ffff800011448000 x26: ffff8000100cfd98\n[ 1.681574] x25: ffff800011b9bd48 x24: 0000000000000000\n[ 1.686882] x23: 0000000000000000 x22: ffff8000106fad90\n[ 1.692189] x21: 000000000000000a x20: ffff0000c0048500\n[ 1.697496] x19: ffff0000c0048500 x18: ffffffffffffffff\n[ 1.702804] x17: 0000000000000000 x16: 0000000000000000\n[ 1.708112] x15: ffff800011460300 x14: fffffffffffe0000\n[ 1.713420] x13: ffff8000114602d8 x12: 0720072007200720\n[ 1.718727] x11: 0720072007200720 x10: 0720072007200720\n[ 1.724035] x9 : ffff800011b9bbe0 x8 : ffff800011b9bbe0\n[ 1.729342] x7 : 0000000000000009 x6 : ffff8000114b8328\n[ 1.734649] x5 : 0000000000000000 x4 : 0000000000000000\n[ 1.739956] x3 : 00000000ffffffff x2 : ffff800011460298\n[ 1.745263] x1 : 1af1d7de276f4500 x0 : 0000000000000000\n[ 1.750572] Call trace:\n[ 1.753010] clk_core_disable+0xb0/0xb8\n[ 1.756840] clk_core_disable_lock+0x24/0x40\n[ 1.761105] clk_disable+0x20/0x30\n[ 1.764501] mtk_iommu_runtime_suspend+0x88/0xa8\n[ 1.769114] pm_generic_runtime_suspend+0x2c/0x48\n[ 1.773815] __rpm_callback+0xe0/0x178\n[ 1.777559] rpm_callback+0x24/0x88\n[ 1.781041] rpm_suspend+0xdc/0x470\n[ 1.784523] rpm_idle+0x12c/0x170\n[ 1.787831] pm_runtime_work+0xa8/0xc0\n[ 1.791573] process_one_work+0x1e8/0x360\n[ 1.795580] worker_thread+0x44/0x478\n[ 1.799237] kthread+0x150/0x158\n[ 1.802460] ret_from_fork+0x10/0x30\n[ 1.806034] ---[ end trace 82402920ef64573b ]---\n[ 1.810728] ------------[ cut here ]------------\n\nIn addition, we now don't need to enable the clock from the\nfunction mtk_iommu_hw_init since it is already enabled by the resume.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w953-7xrr-xmmq/GHSA-w953-7xrr-xmmq.json b/advisories/unreviewed/2024/02/GHSA-w953-7xrr-xmmq/GHSA-w953-7xrr-xmmq.json index e9ece23859a..b5ce73e7c2d 100644 --- a/advisories/unreviewed/2024/02/GHSA-w953-7xrr-xmmq/GHSA-w953-7xrr-xmmq.json +++ b/advisories/unreviewed/2024/02/GHSA-w953-7xrr-xmmq/GHSA-w953-7xrr-xmmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w9w6-r588-cpmx/GHSA-w9w6-r588-cpmx.json b/advisories/unreviewed/2024/02/GHSA-w9w6-r588-cpmx/GHSA-w9w6-r588-cpmx.json index c5d9450eb3a..bfafe0df603 100644 --- a/advisories/unreviewed/2024/02/GHSA-w9w6-r588-cpmx/GHSA-w9w6-r588-cpmx.json +++ b/advisories/unreviewed/2024/02/GHSA-w9w6-r588-cpmx/GHSA-w9w6-r588-cpmx.json @@ -7,12 +7,8 @@ "CVE-2021-46976" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix crash in auto_retire\n\nThe retire logic uses the 2 lower bits of the pointer to the retire\nfunction to store flags. However, the auto_retire function is not\nguaranteed to be aligned to a multiple of 4, which causes crashes as\nwe jump to the wrong address, for example like this:\n\n2021-04-24T18:03:53.804300Z WARNING kernel: [ 516.876901] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n2021-04-24T18:03:53.804310Z WARNING kernel: [ 516.876906] CPU: 7 PID: 146 Comm: kworker/u16:6 Tainted: G U 5.4.105-13595-g3cd84167b2df #1\n2021-04-24T18:03:53.804311Z WARNING kernel: [ 516.876907] Hardware name: Google Volteer2/Volteer2, BIOS Google_Volteer2.13672.76.0 02/22/2021\n2021-04-24T18:03:53.804312Z WARNING kernel: [ 516.876911] Workqueue: events_unbound active_work\n2021-04-24T18:03:53.804313Z WARNING kernel: [ 516.876914] RIP: 0010:auto_retire+0x1/0x20\n2021-04-24T18:03:53.804314Z WARNING kernel: [ 516.876916] Code: e8 01 f2 ff ff eb 02 31 db 48 89 d8 5b 5d c3 0f 1f 44 00 00 55 48 89 e5 f0 ff 87 c8 00 00 00 0f 88 ab 47 4a 00 31 c0 5d c3 0f <1f> 44 00 00 55 48 89 e5 f0 ff 8f c8 00 00 00 0f 88 9a 47 4a 00 74\n2021-04-24T18:03:53.804319Z WARNING kernel: [ 516.876918] RSP: 0018:ffff9b4d809fbe38 EFLAGS: 00010286\n2021-04-24T18:03:53.804320Z WARNING kernel: [ 516.876919] RAX: 0000000000000007 RBX: ffff927915079600 RCX: 0000000000000007\n2021-04-24T18:03:53.804320Z WARNING kernel: [ 516.876921] RDX: ffff9b4d809fbe40 RSI: 0000000000000286 RDI: ffff927915079600\n2021-04-24T18:03:53.804321Z WARNING kernel: [ 516.876922] RBP: ffff9b4d809fbe68 R08: 8080808080808080 R09: fefefefefefefeff\n2021-04-24T18:03:53.804321Z WARNING kernel: [ 516.876924] R10: 0000000000000010 R11: ffffffff92e44bd8 R12: ffff9279150796a0\n2021-04-24T18:03:53.804322Z WARNING kernel: [ 516.876925] R13: ffff92791c368180 R14: ffff927915079640 R15: 000000001c867605\n2021-04-24T18:03:53.804323Z WARNING kernel: [ 516.876926] FS: 0000000000000000(0000) GS:ffff92791ffc0000(0000) knlGS:0000000000000000\n2021-04-24T18:03:53.804323Z WARNING kernel: [ 516.876928] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n2021-04-24T18:03:53.804324Z WARNING kernel: [ 516.876929] CR2: 0000239514955000 CR3: 00000007f82da001 CR4: 0000000000760ee0\n2021-04-24T18:03:53.804325Z WARNING kernel: [ 516.876930] PKRU: 55555554\n2021-04-24T18:03:53.804325Z WARNING kernel: [ 516.876931] Call Trace:\n2021-04-24T18:03:53.804326Z WARNING kernel: [ 516.876935] __active_retire+0x77/0xcf\n2021-04-24T18:03:53.804326Z WARNING kernel: [ 516.876939] process_one_work+0x1da/0x394\n2021-04-24T18:03:53.804327Z WARNING kernel: [ 516.876941] worker_thread+0x216/0x375\n2021-04-24T18:03:53.804327Z WARNING kernel: [ 516.876944] kthread+0x147/0x156\n2021-04-24T18:03:53.804335Z WARNING kernel: [ 516.876946] ? pr_cont_work+0x58/0x58\n2021-04-24T18:03:53.804335Z WARNING kernel: [ 516.876948] ? kthread_blkcg+0x2e/0x2e\n2021-04-24T18:03:53.804336Z WARNING kernel: [ 516.876950] ret_from_fork+0x1f/0x40\n2021-04-24T18:03:53.804336Z WARNING kernel: [ 516.876952] Modules linked in: cdc_mbim cdc_ncm cdc_wdm xt_cgroup rfcomm cmac algif_hash algif_skcipher af_alg xt_MASQUERADE uinput snd_soc_rt5682_sdw snd_soc_rt5682 snd_soc_max98373_sdw snd_soc_max98373 snd_soc_rl6231 regmap_sdw snd_soc_sof_sdw snd_soc_hdac_hdmi snd_soc_dmic snd_hda_codec_hdmi snd_sof_pci snd_sof_intel_hda_common intel_ipu6_psys snd_sof_xtensa_dsp soundwire_intel soundwire_generic_allocation soundwire_cadence snd_sof_intel_hda snd_sof snd_soc_hdac_hda snd_soc_acpi_intel_match snd_soc_acpi snd_hda_ext_core soundwire_bus snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hwdep snd_hda_core intel_ipu6_isys videobuf2_dma_contig videobuf2_v4l2 videobuf2_common videobuf2_memops mei_hdcp intel_ipu6 ov2740 ov8856 at24 sx9310 dw9768 v4l2_fwnode cros_ec_typec intel_pmc_mux roles acpi_als typec fuse iio_trig_sysfs cros_ec_light_prox cros_ec_lid_angle cros_ec_sensors cros\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-wwcj-mm94-5r39/GHSA-wwcj-mm94-5r39.json b/advisories/unreviewed/2024/02/GHSA-wwcj-mm94-5r39/GHSA-wwcj-mm94-5r39.json index db5ddfa66d6..4eda4480093 100644 --- a/advisories/unreviewed/2024/02/GHSA-wwcj-mm94-5r39/GHSA-wwcj-mm94-5r39.json +++ b/advisories/unreviewed/2024/02/GHSA-wwcj-mm94-5r39/GHSA-wwcj-mm94-5r39.json @@ -7,12 +7,8 @@ "CVE-2021-47024" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: free queued packets when closing socket\n\nAs reported by syzbot [1], there is a memory leak while closing the\nsocket. We partially solved this issue with commit ac03046ece2b\n(\"vsock/virtio: free packets during the socket release\"), but we\nforgot to drain the RX queue when the socket is definitely closed by\nthe scheduled work.\n\nTo avoid future issues, let's use the new virtio_transport_remove_sock()\nto drain the RX queue before removing the socket from the af_vsock lists\ncalling vsock_remove_sock().\n\n[1] https://syzkaller.appspot.com/bug?extid=24452624fc4c571eedd9", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-xgg4-mwfh-3vj5/GHSA-xgg4-mwfh-3vj5.json b/advisories/unreviewed/2024/02/GHSA-xgg4-mwfh-3vj5/GHSA-xgg4-mwfh-3vj5.json index a7c5d72abd2..4fc0a375302 100644 --- a/advisories/unreviewed/2024/02/GHSA-xgg4-mwfh-3vj5/GHSA-xgg4-mwfh-3vj5.json +++ b/advisories/unreviewed/2024/02/GHSA-xgg4-mwfh-3vj5/GHSA-xgg4-mwfh-3vj5.json @@ -7,12 +7,8 @@ "CVE-2021-46981" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: Fix NULL pointer in flush_workqueue\n\nOpen /dev/nbdX first, the config_refs will be 1 and\nthe pointers in nbd_device are still null. Disconnect\n/dev/nbdX, then reference a null recv_workq. The\nprotection by config_refs in nbd_genl_disconnect is useless.\n\n[ 656.366194] BUG: kernel NULL pointer dereference, address: 0000000000000020\n[ 656.368943] #PF: supervisor write access in kernel mode\n[ 656.369844] #PF: error_code(0x0002) - not-present page\n[ 656.370717] PGD 10cc87067 P4D 10cc87067 PUD 1074b4067 PMD 0\n[ 656.371693] Oops: 0002 [#1] SMP\n[ 656.372242] CPU: 5 PID: 7977 Comm: nbd-client Not tainted 5.11.0-rc5-00040-g76c057c84d28 #1\n[ 656.373661] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS ?-20190727_073836-buildvm-ppc64le-16.ppc.fedoraproject.org-3.fc31 04/01/2014\n[ 656.375904] RIP: 0010:mutex_lock+0x29/0x60\n[ 656.376627] Code: 00 0f 1f 44 00 00 55 48 89 fd 48 83 05 6f d7 fe 08 01 e8 7a c3 ff ff 48 83 05 6a d7 fe 08 01 31 c0 65 48 8b 14 25 00 6d 01 00 48 0f b1 55 d\n[ 656.378934] RSP: 0018:ffffc900005eb9b0 EFLAGS: 00010246\n[ 656.379350] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000\n[ 656.379915] RDX: ffff888104cf2600 RSI: ffffffffaae8f452 RDI: 0000000000000020\n[ 656.380473] RBP: 0000000000000020 R08: 0000000000000000 R09: ffff88813bd6b318\n[ 656.381039] R10: 00000000000000c7 R11: fefefefefefefeff R12: ffff888102710b40\n[ 656.381599] R13: ffffc900005eb9e0 R14: ffffffffb2930680 R15: ffff88810770ef00\n[ 656.382166] FS: 00007fdf117ebb40(0000) GS:ffff88813bd40000(0000) knlGS:0000000000000000\n[ 656.382806] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 656.383261] CR2: 0000000000000020 CR3: 0000000100c84000 CR4: 00000000000006e0\n[ 656.383819] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 656.384370] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 656.384927] Call Trace:\n[ 656.385111] flush_workqueue+0x92/0x6c0\n[ 656.385395] nbd_disconnect_and_put+0x81/0xd0\n[ 656.385716] nbd_genl_disconnect+0x125/0x2a0\n[ 656.386034] genl_family_rcv_msg_doit.isra.0+0x102/0x1b0\n[ 656.386422] genl_rcv_msg+0xfc/0x2b0\n[ 656.386685] ? nbd_ioctl+0x490/0x490\n[ 656.386954] ? genl_family_rcv_msg_doit.isra.0+0x1b0/0x1b0\n[ 656.387354] netlink_rcv_skb+0x62/0x180\n[ 656.387638] genl_rcv+0x34/0x60\n[ 656.387874] netlink_unicast+0x26d/0x590\n[ 656.388162] netlink_sendmsg+0x398/0x6c0\n[ 656.388451] ? netlink_rcv_skb+0x180/0x180\n[ 656.388750] ____sys_sendmsg+0x1da/0x320\n[ 656.389038] ? ____sys_recvmsg+0x130/0x220\n[ 656.389334] ___sys_sendmsg+0x8e/0xf0\n[ 656.389605] ? ___sys_recvmsg+0xa2/0xf0\n[ 656.389889] ? handle_mm_fault+0x1671/0x21d0\n[ 656.390201] __sys_sendmsg+0x6d/0xe0\n[ 656.390464] __x64_sys_sendmsg+0x23/0x30\n[ 656.390751] do_syscall_64+0x45/0x70\n[ 656.391017] entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\nTo fix it, just add if (nbd->recv_workq) to nbd_disconnect_and_put().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-xhhv-vj84-84fm/GHSA-xhhv-vj84-84fm.json b/advisories/unreviewed/2024/02/GHSA-xhhv-vj84-84fm/GHSA-xhhv-vj84-84fm.json index f22ed660449..4e76d022ae6 100644 --- a/advisories/unreviewed/2024/02/GHSA-xhhv-vj84-84fm/GHSA-xhhv-vj84-84fm.json +++ b/advisories/unreviewed/2024/02/GHSA-xhhv-vj84-84fm/GHSA-xhhv-vj84-84fm.json @@ -7,12 +7,8 @@ "CVE-2021-47033" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7615: fix tx skb dma unmap\n\nThe first pointer in the txp needs to be unmapped as well, otherwise it will\nleak DMA mapping entries", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-xppg-r7h5-74wm/GHSA-xppg-r7h5-74wm.json b/advisories/unreviewed/2024/02/GHSA-xppg-r7h5-74wm/GHSA-xppg-r7h5-74wm.json index 4f8327ad8a0..43a89647566 100644 --- a/advisories/unreviewed/2024/02/GHSA-xppg-r7h5-74wm/GHSA-xppg-r7h5-74wm.json +++ b/advisories/unreviewed/2024/02/GHSA-xppg-r7h5-74wm/GHSA-xppg-r7h5-74wm.json @@ -7,12 +7,8 @@ "CVE-2021-47047" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-zynqmp-gqspi: return -ENOMEM if dma_map_single fails\n\nThe spi controller supports 44-bit address space on AXI in DMA mode,\nso set dma_addr_t width to 44-bit to avoid using a swiotlb mapping.\nIn addition, if dma_map_single fails, it should return immediately\ninstead of continuing doing the DMA operation which bases on invalid\naddress.\n\nThis fixes the following crash which occurs in reading a big block\nfrom flash:\n\n[ 123.633577] zynqmp-qspi ff0f0000.spi: swiotlb buffer is full (sz: 4194304 bytes), total 32768 (slots), used 0 (slots)\n[ 123.644230] zynqmp-qspi ff0f0000.spi: ERR:rxdma:memory not mapped\n[ 123.784625] Unable to handle kernel paging request at virtual address 00000000003fffc0\n[ 123.792536] Mem abort info:\n[ 123.795313] ESR = 0x96000145\n[ 123.798351] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 123.803655] SET = 0, FnV = 0\n[ 123.806693] EA = 0, S1PTW = 0\n[ 123.809818] Data abort info:\n[ 123.812683] ISV = 0, ISS = 0x00000145\n[ 123.816503] CM = 1, WnR = 1\n[ 123.819455] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000805047000\n[ 123.825887] [00000000003fffc0] pgd=0000000803b45003, p4d=0000000803b45003, pud=0000000000000000\n[ 123.834586] Internal error: Oops: 96000145 [#1] PREEMPT SMP", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5xf8-64vx-2fcm/GHSA-5xf8-64vx-2fcm.json b/advisories/unreviewed/2024/03/GHSA-5xf8-64vx-2fcm/GHSA-5xf8-64vx-2fcm.json index e4ef04e6aad..ddb9c749ad6 100644 --- a/advisories/unreviewed/2024/03/GHSA-5xf8-64vx-2fcm/GHSA-5xf8-64vx-2fcm.json +++ b/advisories/unreviewed/2024/03/GHSA-5xf8-64vx-2fcm/GHSA-5xf8-64vx-2fcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8vmv-4hfm-2fv8/GHSA-8vmv-4hfm-2fv8.json b/advisories/unreviewed/2024/03/GHSA-8vmv-4hfm-2fv8/GHSA-8vmv-4hfm-2fv8.json index fc00d0eedff..ff62ce1db6c 100644 --- a/advisories/unreviewed/2024/03/GHSA-8vmv-4hfm-2fv8/GHSA-8vmv-4hfm-2fv8.json +++ b/advisories/unreviewed/2024/03/GHSA-8vmv-4hfm-2fv8/GHSA-8vmv-4hfm-2fv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-j9rq-gcmr-fp62/GHSA-j9rq-gcmr-fp62.json b/advisories/unreviewed/2024/03/GHSA-j9rq-gcmr-fp62/GHSA-j9rq-gcmr-fp62.json index fc28c261027..ad9dcb2943f 100644 --- a/advisories/unreviewed/2024/03/GHSA-j9rq-gcmr-fp62/GHSA-j9rq-gcmr-fp62.json +++ b/advisories/unreviewed/2024/03/GHSA-j9rq-gcmr-fp62/GHSA-j9rq-gcmr-fp62.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-m9rc-7xvh-66c4/GHSA-m9rc-7xvh-66c4.json b/advisories/unreviewed/2024/03/GHSA-m9rc-7xvh-66c4/GHSA-m9rc-7xvh-66c4.json index 487e9742d2b..2e428e42d22 100644 --- a/advisories/unreviewed/2024/03/GHSA-m9rc-7xvh-66c4/GHSA-m9rc-7xvh-66c4.json +++ b/advisories/unreviewed/2024/03/GHSA-m9rc-7xvh-66c4/GHSA-m9rc-7xvh-66c4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-q943-f628-cf96/GHSA-q943-f628-cf96.json b/advisories/unreviewed/2024/03/GHSA-q943-f628-cf96/GHSA-q943-f628-cf96.json index be9fd57683f..c726cd5f1f4 100644 --- a/advisories/unreviewed/2024/03/GHSA-q943-f628-cf96/GHSA-q943-f628-cf96.json +++ b/advisories/unreviewed/2024/03/GHSA-q943-f628-cf96/GHSA-q943-f628-cf96.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-42c2-hx35-9cg7/GHSA-42c2-hx35-9cg7.json b/advisories/unreviewed/2024/04/GHSA-42c2-hx35-9cg7/GHSA-42c2-hx35-9cg7.json index f35a9305afc..7f984744b19 100644 --- a/advisories/unreviewed/2024/04/GHSA-42c2-hx35-9cg7/GHSA-42c2-hx35-9cg7.json +++ b/advisories/unreviewed/2024/04/GHSA-42c2-hx35-9cg7/GHSA-42c2-hx35-9cg7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5wwr-98rp-48m6/GHSA-5wwr-98rp-48m6.json b/advisories/unreviewed/2024/04/GHSA-5wwr-98rp-48m6/GHSA-5wwr-98rp-48m6.json index e3d542c15ca..71a11a9c9e1 100644 --- a/advisories/unreviewed/2024/04/GHSA-5wwr-98rp-48m6/GHSA-5wwr-98rp-48m6.json +++ b/advisories/unreviewed/2024/04/GHSA-5wwr-98rp-48m6/GHSA-5wwr-98rp-48m6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-6975-7v7f-f626/GHSA-6975-7v7f-f626.json b/advisories/unreviewed/2024/04/GHSA-6975-7v7f-f626/GHSA-6975-7v7f-f626.json index cfe34c44640..3e9e5325040 100644 --- a/advisories/unreviewed/2024/04/GHSA-6975-7v7f-f626/GHSA-6975-7v7f-f626.json +++ b/advisories/unreviewed/2024/04/GHSA-6975-7v7f-f626/GHSA-6975-7v7f-f626.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8j3g-2mm6-wf76/GHSA-8j3g-2mm6-wf76.json b/advisories/unreviewed/2024/04/GHSA-8j3g-2mm6-wf76/GHSA-8j3g-2mm6-wf76.json index c238cdfab45..f20b14ee12f 100644 --- a/advisories/unreviewed/2024/04/GHSA-8j3g-2mm6-wf76/GHSA-8j3g-2mm6-wf76.json +++ b/advisories/unreviewed/2024/04/GHSA-8j3g-2mm6-wf76/GHSA-8j3g-2mm6-wf76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-h93c-r23q-x4wc/GHSA-h93c-r23q-x4wc.json b/advisories/unreviewed/2024/04/GHSA-h93c-r23q-x4wc/GHSA-h93c-r23q-x4wc.json index af090462141..33d69c9e5b6 100644 --- a/advisories/unreviewed/2024/04/GHSA-h93c-r23q-x4wc/GHSA-h93c-r23q-x4wc.json +++ b/advisories/unreviewed/2024/04/GHSA-h93c-r23q-x4wc/GHSA-h93c-r23q-x4wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mqjv-j25q-vx8x/GHSA-mqjv-j25q-vx8x.json b/advisories/unreviewed/2024/04/GHSA-mqjv-j25q-vx8x/GHSA-mqjv-j25q-vx8x.json index f74459e1a15..2373c4f2447 100644 --- a/advisories/unreviewed/2024/04/GHSA-mqjv-j25q-vx8x/GHSA-mqjv-j25q-vx8x.json +++ b/advisories/unreviewed/2024/04/GHSA-mqjv-j25q-vx8x/GHSA-mqjv-j25q-vx8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-qcxf-qfvg-cqc5/GHSA-qcxf-qfvg-cqc5.json b/advisories/unreviewed/2024/04/GHSA-qcxf-qfvg-cqc5/GHSA-qcxf-qfvg-cqc5.json index 99792c0a3ad..ed345c9f9e9 100644 --- a/advisories/unreviewed/2024/04/GHSA-qcxf-qfvg-cqc5/GHSA-qcxf-qfvg-cqc5.json +++ b/advisories/unreviewed/2024/04/GHSA-qcxf-qfvg-cqc5/GHSA-qcxf-qfvg-cqc5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qpxw-94mq-gcrh/GHSA-qpxw-94mq-gcrh.json b/advisories/unreviewed/2024/04/GHSA-qpxw-94mq-gcrh/GHSA-qpxw-94mq-gcrh.json index 58f5b545d19..a56071e589e 100644 --- a/advisories/unreviewed/2024/04/GHSA-qpxw-94mq-gcrh/GHSA-qpxw-94mq-gcrh.json +++ b/advisories/unreviewed/2024/04/GHSA-qpxw-94mq-gcrh/GHSA-qpxw-94mq-gcrh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-v55p-hqx9-66gf/GHSA-v55p-hqx9-66gf.json b/advisories/unreviewed/2024/04/GHSA-v55p-hqx9-66gf/GHSA-v55p-hqx9-66gf.json index ed5ee2cf2ae..6406717c2e2 100644 --- a/advisories/unreviewed/2024/04/GHSA-v55p-hqx9-66gf/GHSA-v55p-hqx9-66gf.json +++ b/advisories/unreviewed/2024/04/GHSA-v55p-hqx9-66gf/GHSA-v55p-hqx9-66gf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wm4r-wfxq-54cf/GHSA-wm4r-wfxq-54cf.json b/advisories/unreviewed/2024/04/GHSA-wm4r-wfxq-54cf/GHSA-wm4r-wfxq-54cf.json index 9aecea78c93..f0f01d2b3c0 100644 --- a/advisories/unreviewed/2024/04/GHSA-wm4r-wfxq-54cf/GHSA-wm4r-wfxq-54cf.json +++ b/advisories/unreviewed/2024/04/GHSA-wm4r-wfxq-54cf/GHSA-wm4r-wfxq-54cf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-x2xf-rph3-7jqp/GHSA-x2xf-rph3-7jqp.json b/advisories/unreviewed/2024/04/GHSA-x2xf-rph3-7jqp/GHSA-x2xf-rph3-7jqp.json index c9b2019aa8b..cdd6dc38de2 100644 --- a/advisories/unreviewed/2024/04/GHSA-x2xf-rph3-7jqp/GHSA-x2xf-rph3-7jqp.json +++ b/advisories/unreviewed/2024/04/GHSA-x2xf-rph3-7jqp/GHSA-x2xf-rph3-7jqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2qm9-92xg-cr8h/GHSA-2qm9-92xg-cr8h.json b/advisories/unreviewed/2024/05/GHSA-2qm9-92xg-cr8h/GHSA-2qm9-92xg-cr8h.json index 26456491fb1..717a40467f4 100644 --- a/advisories/unreviewed/2024/05/GHSA-2qm9-92xg-cr8h/GHSA-2qm9-92xg-cr8h.json +++ b/advisories/unreviewed/2024/05/GHSA-2qm9-92xg-cr8h/GHSA-2qm9-92xg-cr8h.json @@ -7,12 +7,8 @@ "CVE-2023-52754" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: imon: fix access to invalid resource for the second interface\n\nimon driver probes two USB interfaces, and at the probe of the second\ninterface, the driver assumes blindly that the first interface got\nbound with the same imon driver. It's usually true, but it's still\npossible that the first interface is bound with another driver via a\nmalformed descriptor. Then it may lead to a memory corruption, as\nspotted by syzkaller; imon driver accesses the data from drvdata as\nstruct imon_context object although it's a completely different one\nthat was assigned by another driver.\n\nThis patch adds a sanity check -- whether the first interface is\nreally bound with the imon driver or not -- for avoiding the problem\nabove at the probe time.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2v26-28rg-whvc/GHSA-2v26-28rg-whvc.json b/advisories/unreviewed/2024/05/GHSA-2v26-28rg-whvc/GHSA-2v26-28rg-whvc.json index d299f4d8418..cc18de2ef8e 100644 --- a/advisories/unreviewed/2024/05/GHSA-2v26-28rg-whvc/GHSA-2v26-28rg-whvc.json +++ b/advisories/unreviewed/2024/05/GHSA-2v26-28rg-whvc/GHSA-2v26-28rg-whvc.json @@ -7,12 +7,8 @@ "CVE-2021-47385" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field\n\nIf driver read val value sufficient for\n(val & 0x08) && (!(val & 0x80)) && ((val & 0x7) == ((val >> 4) & 0x7))\nfrom device then Null pointer dereference occurs.\n(It is possible if tmp = 0b0xyz1xyz, where same literals mean same numbers)\nAlso lm75[] does not serve a purpose anymore after switching to\ndevm_i2c_new_dummy_device() in w83791d_detect_subclients().\n\nThe patch fixes possible NULL pointer dereference by removing lm75[].\n\nFound by Linux Driver Verification project (linuxtesting.org).\n\n[groeck: Dropped unnecessary continuation lines, fixed multipline alignment]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-338f-47mv-53ch/GHSA-338f-47mv-53ch.json b/advisories/unreviewed/2024/05/GHSA-338f-47mv-53ch/GHSA-338f-47mv-53ch.json index 4d9eb83f85d..93a2b8bca67 100644 --- a/advisories/unreviewed/2024/05/GHSA-338f-47mv-53ch/GHSA-338f-47mv-53ch.json +++ b/advisories/unreviewed/2024/05/GHSA-338f-47mv-53ch/GHSA-338f-47mv-53ch.json @@ -7,12 +7,8 @@ "CVE-2024-1721" ], "details": "Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3f2p-fcxq-w4cm/GHSA-3f2p-fcxq-w4cm.json b/advisories/unreviewed/2024/05/GHSA-3f2p-fcxq-w4cm/GHSA-3f2p-fcxq-w4cm.json index cc22037df3c..1179054f537 100644 --- a/advisories/unreviewed/2024/05/GHSA-3f2p-fcxq-w4cm/GHSA-3f2p-fcxq-w4cm.json +++ b/advisories/unreviewed/2024/05/GHSA-3f2p-fcxq-w4cm/GHSA-3f2p-fcxq-w4cm.json @@ -7,12 +7,8 @@ "CVE-2023-52764" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: gspca: cpia1: shift-out-of-bounds in set_flicker\n\nSyzkaller reported the following issue:\nUBSAN: shift-out-of-bounds in drivers/media/usb/gspca/cpia1.c:1031:27\nshift exponent 245 is too large for 32-bit type 'int'\n\nWhen the value of the variable \"sd->params.exposure.gain\" exceeds the\nnumber of bits in an integer, a shift-out-of-bounds error is reported. It\nis triggered because the variable \"currentexp\" cannot be left-shifted by\nmore than the number of bits in an integer. In order to avoid invalid\nrange during left-shift, the conditional expression is added.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3vpw-pw66-4mjh/GHSA-3vpw-pw66-4mjh.json b/advisories/unreviewed/2024/05/GHSA-3vpw-pw66-4mjh/GHSA-3vpw-pw66-4mjh.json index 9794a9b8626..4181ee43eb9 100644 --- a/advisories/unreviewed/2024/05/GHSA-3vpw-pw66-4mjh/GHSA-3vpw-pw66-4mjh.json +++ b/advisories/unreviewed/2024/05/GHSA-3vpw-pw66-4mjh/GHSA-3vpw-pw66-4mjh.json @@ -7,12 +7,8 @@ "CVE-2021-47392" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cma: Fix listener leak in rdma_cma_listen_on_all() failure\n\nIf cma_listen_on_all() fails it leaves the per-device ID still on the\nlisten_list but the state is not set to RDMA_CM_ADDR_BOUND.\n\nWhen the cmid is eventually destroyed cma_cancel_listens() is not called\ndue to the wrong state, however the per-device IDs are still holding the\nrefcount preventing the ID from being destroyed, thus deadlocking:\n\n task:rping state:D stack: 0 pid:19605 ppid: 47036 flags:0x00000084\n Call Trace:\n __schedule+0x29a/0x780\n ? free_unref_page_commit+0x9b/0x110\n schedule+0x3c/0xa0\n schedule_timeout+0x215/0x2b0\n ? __flush_work+0x19e/0x1e0\n wait_for_completion+0x8d/0xf0\n _destroy_id+0x144/0x210 [rdma_cm]\n ucma_close_id+0x2b/0x40 [rdma_ucm]\n __destroy_id+0x93/0x2c0 [rdma_ucm]\n ? __xa_erase+0x4a/0xa0\n ucma_destroy_id+0x9a/0x120 [rdma_ucm]\n ucma_write+0xb8/0x130 [rdma_ucm]\n vfs_write+0xb4/0x250\n ksys_write+0xb5/0xd0\n ? syscall_trace_enter.isra.19+0x123/0x190\n do_syscall_64+0x33/0x40\n entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\nEnsure that cma_listen_on_all() atomically unwinds its action under the\nlock during error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-44v6-xcjw-whc3/GHSA-44v6-xcjw-whc3.json b/advisories/unreviewed/2024/05/GHSA-44v6-xcjw-whc3/GHSA-44v6-xcjw-whc3.json index 35a4dc8a7e4..575b7623384 100644 --- a/advisories/unreviewed/2024/05/GHSA-44v6-xcjw-whc3/GHSA-44v6-xcjw-whc3.json +++ b/advisories/unreviewed/2024/05/GHSA-44v6-xcjw-whc3/GHSA-44v6-xcjw-whc3.json @@ -7,12 +7,8 @@ "CVE-2023-52818" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd: Fix UBSAN array-index-out-of-bounds for SMU7\n\nFor pptable structs that use flexible array sizes, use flexible arrays.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4fxc-v2fq-wgmf/GHSA-4fxc-v2fq-wgmf.json b/advisories/unreviewed/2024/05/GHSA-4fxc-v2fq-wgmf/GHSA-4fxc-v2fq-wgmf.json index cac70990b2f..37d66f0d02f 100644 --- a/advisories/unreviewed/2024/05/GHSA-4fxc-v2fq-wgmf/GHSA-4fxc-v2fq-wgmf.json +++ b/advisories/unreviewed/2024/05/GHSA-4fxc-v2fq-wgmf/GHSA-4fxc-v2fq-wgmf.json @@ -7,12 +7,8 @@ "CVE-2021-47417" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibbpf: Fix memory leak in strset\n\nFree struct strset itself, not just its internal parts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4g8g-hf76-7rpm/GHSA-4g8g-hf76-7rpm.json b/advisories/unreviewed/2024/05/GHSA-4g8g-hf76-7rpm/GHSA-4g8g-hf76-7rpm.json index 9838cb0d3d8..bc581e5154b 100644 --- a/advisories/unreviewed/2024/05/GHSA-4g8g-hf76-7rpm/GHSA-4g8g-hf76-7rpm.json +++ b/advisories/unreviewed/2024/05/GHSA-4g8g-hf76-7rpm/GHSA-4g8g-hf76-7rpm.json @@ -7,12 +7,8 @@ "CVE-2023-52852" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: compress: fix to avoid use-after-free on dic\n\nCall trace:\n __memcpy+0x128/0x250\n f2fs_read_multi_pages+0x940/0xf7c\n f2fs_mpage_readpages+0x5a8/0x624\n f2fs_readahead+0x5c/0x110\n page_cache_ra_unbounded+0x1b8/0x590\n do_sync_mmap_readahead+0x1dc/0x2e4\n filemap_fault+0x254/0xa8c\n f2fs_filemap_fault+0x2c/0x104\n __do_fault+0x7c/0x238\n do_handle_mm_fault+0x11bc/0x2d14\n do_mem_abort+0x3a8/0x1004\n el0_da+0x3c/0xa0\n el0t_64_sync_handler+0xc4/0xec\n el0t_64_sync+0x1b4/0x1b8\n\nIn f2fs_read_multi_pages(), once f2fs_decompress_cluster() was called if\nwe hit cached page in compress_inode's cache, dic may be released, it needs\nbreak the loop rather than continuing it, in order to avoid accessing\ninvalid dic pointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4mc8-63f2-q4p2/GHSA-4mc8-63f2-q4p2.json b/advisories/unreviewed/2024/05/GHSA-4mc8-63f2-q4p2/GHSA-4mc8-63f2-q4p2.json index c8f46094bfe..b47a83cd677 100644 --- a/advisories/unreviewed/2024/05/GHSA-4mc8-63f2-q4p2/GHSA-4mc8-63f2-q4p2.json +++ b/advisories/unreviewed/2024/05/GHSA-4mc8-63f2-q4p2/GHSA-4mc8-63f2-q4p2.json @@ -7,12 +7,8 @@ "CVE-2023-52826" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panel/panel-tpo-tpg110: fix a possible null pointer dereference\n\nIn tpg110_get_modes(), the return value of drm_mode_duplicate() is\nassigned to mode, which will lead to a NULL pointer dereference on\nfailure of drm_mode_duplicate(). Add a check to avoid npd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4q4j-hm78-5vmp/GHSA-4q4j-hm78-5vmp.json b/advisories/unreviewed/2024/05/GHSA-4q4j-hm78-5vmp/GHSA-4q4j-hm78-5vmp.json index aaca76de3ca..2cd967e6de4 100644 --- a/advisories/unreviewed/2024/05/GHSA-4q4j-hm78-5vmp/GHSA-4q4j-hm78-5vmp.json +++ b/advisories/unreviewed/2024/05/GHSA-4q4j-hm78-5vmp/GHSA-4q4j-hm78-5vmp.json @@ -7,12 +7,8 @@ "CVE-2021-47325" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/arm-smmu: Fix arm_smmu_device refcount leak in address translation\n\nThe reference counting issue happens in several exception handling paths\nof arm_smmu_iova_to_phys_hard(). When those error scenarios occur, the\nfunction forgets to decrease the refcount of \"smmu\" increased by\narm_smmu_rpm_get(), causing a refcount leak.\n\nFix this issue by jumping to \"out\" label when those error scenarios\noccur.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5f2f-22g2-g2gq/GHSA-5f2f-22g2-g2gq.json b/advisories/unreviewed/2024/05/GHSA-5f2f-22g2-g2gq/GHSA-5f2f-22g2-g2gq.json index 7fd283f6b7e..da057082087 100644 --- a/advisories/unreviewed/2024/05/GHSA-5f2f-22g2-g2gq/GHSA-5f2f-22g2-g2gq.json +++ b/advisories/unreviewed/2024/05/GHSA-5f2f-22g2-g2gq/GHSA-5f2f-22g2-g2gq.json @@ -7,12 +7,8 @@ "CVE-2023-52863" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (axi-fan-control) Fix possible NULL pointer dereference\n\naxi_fan_control_irq_handler(), dependent on the private\naxi_fan_control_data structure, might be called before the hwmon\ndevice is registered. That will cause an \"Unable to handle kernel\nNULL pointer dereference\" error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5h67-9rvr-r9x6/GHSA-5h67-9rvr-r9x6.json b/advisories/unreviewed/2024/05/GHSA-5h67-9rvr-r9x6/GHSA-5h67-9rvr-r9x6.json index f61faba7e92..3b9999230e6 100644 --- a/advisories/unreviewed/2024/05/GHSA-5h67-9rvr-r9x6/GHSA-5h67-9rvr-r9x6.json +++ b/advisories/unreviewed/2024/05/GHSA-5h67-9rvr-r9x6/GHSA-5h67-9rvr-r9x6.json @@ -7,12 +7,8 @@ "CVE-2023-52874" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/tdx: Zero out the missing RSI in TDX_HYPERCALL macro\n\nIn the TDX_HYPERCALL asm, after the TDCALL instruction returns from the\nuntrusted VMM, the registers that the TDX guest shares to the VMM need\nto be cleared to avoid speculative execution of VMM-provided values.\n\nRSI is specified in the bitmap of those registers, but it is missing\nwhen zeroing out those registers in the current TDX_HYPERCALL.\n\nIt was there when it was originally added in commit 752d13305c78\n(\"x86/tdx: Expand __tdx_hypercall() to handle more arguments\"), but was\nlater removed in commit 1e70c680375a (\"x86/tdx: Do not corrupt\nframe-pointer in __tdx_hypercall()\"), which was correct because %rsi is\nlater restored in the \"pop %rsi\". However a later commit 7a3a401874be\n(\"x86/tdx: Drop flags from __tdx_hypercall()\") removed that \"pop %rsi\"\nbut forgot to add the \"xor %rsi, %rsi\" back.\n\nFix by adding it back.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5j57-53hq-vmc7/GHSA-5j57-53hq-vmc7.json b/advisories/unreviewed/2024/05/GHSA-5j57-53hq-vmc7/GHSA-5j57-53hq-vmc7.json index f1feb415242..0753ce0d03d 100644 --- a/advisories/unreviewed/2024/05/GHSA-5j57-53hq-vmc7/GHSA-5j57-53hq-vmc7.json +++ b/advisories/unreviewed/2024/05/GHSA-5j57-53hq-vmc7/GHSA-5j57-53hq-vmc7.json @@ -7,12 +7,8 @@ "CVE-2021-47278" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: pci_generic: Fix possible use-after-free in mhi_pci_remove()\n\nThis driver's remove path calls del_timer(). However, that function\ndoes not wait until the timer handler finishes. This means that the\ntimer handler may still be running after the driver's remove function\nhas finished, which would result in a use-after-free.\n\nFix by calling del_timer_sync(), which makes sure the timer handler\nhas finished, and unable to re-schedule itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5p87-vhr3-gp4q/GHSA-5p87-vhr3-gp4q.json b/advisories/unreviewed/2024/05/GHSA-5p87-vhr3-gp4q/GHSA-5p87-vhr3-gp4q.json index a79b7bf4cd1..acd211f68d3 100644 --- a/advisories/unreviewed/2024/05/GHSA-5p87-vhr3-gp4q/GHSA-5p87-vhr3-gp4q.json +++ b/advisories/unreviewed/2024/05/GHSA-5p87-vhr3-gp4q/GHSA-5p87-vhr3-gp4q.json @@ -7,12 +7,8 @@ "CVE-2023-52845" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Change nla_policy for bearer-related names to NLA_NUL_STRING\n\nsyzbot reported the following uninit-value access issue [1]:\n\n=====================================================\nBUG: KMSAN: uninit-value in strlen lib/string.c:418 [inline]\nBUG: KMSAN: uninit-value in strstr+0xb8/0x2f0 lib/string.c:756\n strlen lib/string.c:418 [inline]\n strstr+0xb8/0x2f0 lib/string.c:756\n tipc_nl_node_reset_link_stats+0x3ea/0xb50 net/tipc/node.c:2595\n genl_family_rcv_msg_doit net/netlink/genetlink.c:971 [inline]\n genl_family_rcv_msg net/netlink/genetlink.c:1051 [inline]\n genl_rcv_msg+0x11ec/0x1290 net/netlink/genetlink.c:1066\n netlink_rcv_skb+0x371/0x650 net/netlink/af_netlink.c:2545\n genl_rcv+0x40/0x60 net/netlink/genetlink.c:1075\n netlink_unicast_kernel net/netlink/af_netlink.c:1342 [inline]\n netlink_unicast+0xf47/0x1250 net/netlink/af_netlink.c:1368\n netlink_sendmsg+0x1238/0x13d0 net/netlink/af_netlink.c:1910\n sock_sendmsg_nosec net/socket.c:730 [inline]\n sock_sendmsg net/socket.c:753 [inline]\n ____sys_sendmsg+0x9c2/0xd60 net/socket.c:2541\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2595\n __sys_sendmsg net/socket.c:2624 [inline]\n __do_sys_sendmsg net/socket.c:2633 [inline]\n __se_sys_sendmsg net/socket.c:2631 [inline]\n __x64_sys_sendmsg+0x307/0x490 net/socket.c:2631\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nUninit was created at:\n slab_post_alloc_hook+0x12f/0xb70 mm/slab.h:767\n slab_alloc_node mm/slub.c:3478 [inline]\n kmem_cache_alloc_node+0x577/0xa80 mm/slub.c:3523\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:559\n __alloc_skb+0x318/0x740 net/core/skbuff.c:650\n alloc_skb include/linux/skbuff.h:1286 [inline]\n netlink_alloc_large_skb net/netlink/af_netlink.c:1214 [inline]\n netlink_sendmsg+0xb34/0x13d0 net/netlink/af_netlink.c:1885\n sock_sendmsg_nosec net/socket.c:730 [inline]\n sock_sendmsg net/socket.c:753 [inline]\n ____sys_sendmsg+0x9c2/0xd60 net/socket.c:2541\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2595\n __sys_sendmsg net/socket.c:2624 [inline]\n __do_sys_sendmsg net/socket.c:2633 [inline]\n __se_sys_sendmsg net/socket.c:2631 [inline]\n __x64_sys_sendmsg+0x307/0x490 net/socket.c:2631\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nTIPC bearer-related names including link names must be null-terminated\nstrings. If a link name which is not null-terminated is passed through\nnetlink, strstr() and similar functions can cause buffer overrun. This\ncauses the above issue.\n\nThis patch changes the nla_policy for bearer-related names from NLA_STRING\nto NLA_NUL_STRING. This resolves the issue by ensuring that only\nnull-terminated strings are accepted as bearer-related names.\n\nsyzbot reported similar uninit-value issue related to bearer names [2]. The\nroot cause of this issue is that a non-null-terminated bearer name was\npassed. This patch also resolved this issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5v39-jw9p-3jfp/GHSA-5v39-jw9p-3jfp.json b/advisories/unreviewed/2024/05/GHSA-5v39-jw9p-3jfp/GHSA-5v39-jw9p-3jfp.json index 24d0639912f..4cda6b97554 100644 --- a/advisories/unreviewed/2024/05/GHSA-5v39-jw9p-3jfp/GHSA-5v39-jw9p-3jfp.json +++ b/advisories/unreviewed/2024/05/GHSA-5v39-jw9p-3jfp/GHSA-5v39-jw9p-3jfp.json @@ -7,12 +7,8 @@ "CVE-2023-52701" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: use a bounce buffer for copying skb->mark\n\nsyzbot found arm64 builds would crash in sock_recv_mark()\nwhen CONFIG_HARDENED_USERCOPY=y\n\nx86 and powerpc are not detecting the issue because\nthey define user_access_begin.\nThis will be handled in a different patch,\nbecause a check_object_size() is missing.\n\nOnly data from skb->cb[] can be copied directly to/from user space,\nas explained in commit 79a8a642bf05 (\"net: Whitelist\nthe skbuff_head_cache \"cb\" field\")\n\nsyzbot report was:\nusercopy: Kernel memory exposure attempt detected from SLUB object 'skbuff_head_cache' (offset 168, size 4)!\n------------[ cut here ]------------\nkernel BUG at mm/usercopy.c:102 !\nInternal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\nModules linked in:\nCPU: 0 PID: 4410 Comm: syz-executor533 Not tainted 6.2.0-rc7-syzkaller-17907-g2d3827b3f393 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/21/2023\npstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : usercopy_abort+0x90/0x94 mm/usercopy.c:90\nlr : usercopy_abort+0x90/0x94 mm/usercopy.c:90\nsp : ffff80000fb9b9a0\nx29: ffff80000fb9b9b0 x28: ffff0000c6073400 x27: 0000000020001a00\nx26: 0000000000000014 x25: ffff80000cf52000 x24: fffffc0000000000\nx23: 05ffc00000000200 x22: fffffc000324bf80 x21: ffff0000c92fe1a8\nx20: 0000000000000001 x19: 0000000000000004 x18: 0000000000000000\nx17: 656a626f2042554c x16: ffff0000c6073dd0 x15: ffff80000dbd2118\nx14: ffff0000c6073400 x13: 00000000ffffffff x12: ffff0000c6073400\nx11: ff808000081bbb4c x10: 0000000000000000 x9 : 7b0572d7cc0ccf00\nx8 : 7b0572d7cc0ccf00 x7 : ffff80000bf650d4 x6 : 0000000000000000\nx5 : 0000000000000001 x4 : 0000000000000001 x3 : 0000000000000000\nx2 : ffff0001fefbff08 x1 : 0000000100000000 x0 : 000000000000006c\nCall trace:\nusercopy_abort+0x90/0x94 mm/usercopy.c:90\n__check_heap_object+0xa8/0x100 mm/slub.c:4761\ncheck_heap_object mm/usercopy.c:196 [inline]\n__check_object_size+0x208/0x6b8 mm/usercopy.c:251\ncheck_object_size include/linux/thread_info.h:199 [inline]\n__copy_to_user include/linux/uaccess.h:115 [inline]\nput_cmsg+0x408/0x464 net/core/scm.c:238\nsock_recv_mark net/socket.c:975 [inline]\n__sock_recv_cmsgs+0x1fc/0x248 net/socket.c:984\nsock_recv_cmsgs include/net/sock.h:2728 [inline]\npacket_recvmsg+0x2d8/0x678 net/packet/af_packet.c:3482\n____sys_recvmsg+0x110/0x3a0\n___sys_recvmsg net/socket.c:2737 [inline]\n__sys_recvmsg+0x194/0x210 net/socket.c:2767\n__do_sys_recvmsg net/socket.c:2777 [inline]\n__se_sys_recvmsg net/socket.c:2774 [inline]\n__arm64_sys_recvmsg+0x2c/0x3c net/socket.c:2774\n__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]\ninvoke_syscall+0x64/0x178 arch/arm64/kernel/syscall.c:52\nel0_svc_common+0xbc/0x180 arch/arm64/kernel/syscall.c:142\ndo_el0_svc+0x48/0x110 arch/arm64/kernel/syscall.c:193\nel0_svc+0x58/0x14c arch/arm64/kernel/entry-common.c:637\nel0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655\nel0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:591\nCode: 91388800 aa0903e1 f90003e8 94e6d752 (d4210000)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5vvx-6299-h82w/GHSA-5vvx-6299-h82w.json b/advisories/unreviewed/2024/05/GHSA-5vvx-6299-h82w/GHSA-5vvx-6299-h82w.json index bc4dc9fcf44..db98035dcc4 100644 --- a/advisories/unreviewed/2024/05/GHSA-5vvx-6299-h82w/GHSA-5vvx-6299-h82w.json +++ b/advisories/unreviewed/2024/05/GHSA-5vvx-6299-h82w/GHSA-5vvx-6299-h82w.json @@ -7,12 +7,8 @@ "CVE-2021-47337" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Fix bad pointer dereference when ehandler kthread is invalid\n\nCommit 66a834d09293 (\"scsi: core: Fix error handling of scsi_host_alloc()\")\nchanged the allocation logic to call put_device() to perform host cleanup\nwith the assumption that IDA removal and stopping the kthread would\nproperly be performed in scsi_host_dev_release(). However, in the unlikely\ncase that the error handler thread fails to spawn, shost->ehandler is set\nto ERR_PTR(-ENOMEM).\n\nThe error handler cleanup code in scsi_host_dev_release() will call\nkthread_stop() if shost->ehandler != NULL which will always be the case\nwhether the kthread was successfully spawned or not. In the case that it\nfailed to spawn this has the nasty side effect of trying to dereference an\ninvalid pointer when kthread_stop() is called. The following splat provides\nan example of this behavior in the wild:\n\nscsi host11: error handler thread failed to spawn, error = -4\nKernel attempted to read user page (10c) - exploit attempt? (uid: 0)\nBUG: Kernel NULL pointer dereference on read at 0x0000010c\nFaulting instruction address: 0xc00000000818e9a8\nOops: Kernel access of bad area, sig: 11 [#1]\nLE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries\nModules linked in: ibmvscsi(+) scsi_transport_srp dm_multipath dm_mirror dm_region\n hash dm_log dm_mod fuse overlay squashfs loop\nCPU: 12 PID: 274 Comm: systemd-udevd Not tainted 5.13.0-rc7 #1\nNIP: c00000000818e9a8 LR: c0000000089846e8 CTR: 0000000000007ee8\nREGS: c000000037d12ea0 TRAP: 0300 Not tainted (5.13.0-rc7)\nMSR: 800000000280b033 <SF,VEC,VSX,EE,FP,ME,IR,DR,RI,LE> CR: 28228228\nXER: 20040001\nCFAR: c0000000089846e4 DAR: 000000000000010c DSISR: 40000000 IRQMASK: 0\nGPR00: c0000000089846e8 c000000037d13140 c000000009cc1100 fffffffffffffffc\nGPR04: 0000000000000001 0000000000000000 0000000000000000 c000000037dc0000\nGPR08: 0000000000000000 c000000037dc0000 0000000000000001 00000000fffff7ff\nGPR12: 0000000000008000 c00000000a049000 c000000037d13d00 000000011134d5a0\nGPR16: 0000000000001740 c0080000190d0000 c0080000190d1740 c000000009129288\nGPR20: c000000037d13bc0 0000000000000001 c000000037d13bc0 c0080000190b7898\nGPR24: c0080000190b7708 0000000000000000 c000000033bb2c48 0000000000000000\nGPR28: c000000046b28280 0000000000000000 000000000000010c fffffffffffffffc\nNIP [c00000000818e9a8] kthread_stop+0x38/0x230\nLR [c0000000089846e8] scsi_host_dev_release+0x98/0x160\nCall Trace:\n[c000000033bb2c48] 0xc000000033bb2c48 (unreliable)\n[c0000000089846e8] scsi_host_dev_release+0x98/0x160\n[c00000000891e960] device_release+0x60/0x100\n[c0000000087e55c4] kobject_release+0x84/0x210\n[c00000000891ec78] put_device+0x28/0x40\n[c000000008984ea4] scsi_host_alloc+0x314/0x430\n[c0080000190b38bc] ibmvscsi_probe+0x54/0xad0 [ibmvscsi]\n[c000000008110104] vio_bus_probe+0xa4/0x4b0\n[c00000000892a860] really_probe+0x140/0x680\n[c00000000892aefc] driver_probe_device+0x15c/0x200\n[c00000000892b63c] device_driver_attach+0xcc/0xe0\n[c00000000892b740] __driver_attach+0xf0/0x200\n[c000000008926f28] bus_for_each_dev+0xa8/0x130\n[c000000008929ce4] driver_attach+0x34/0x50\n[c000000008928fc0] bus_add_driver+0x1b0/0x300\n[c00000000892c798] driver_register+0x98/0x1a0\n[c00000000810eb60] __vio_register_driver+0x80/0xe0\n[c0080000190b4a30] ibmvscsi_module_init+0x9c/0xdc [ibmvscsi]\n[c0000000080121d0] do_one_initcall+0x60/0x2d0\n[c000000008261abc] do_init_module+0x7c/0x320\n[c000000008265700] load_module+0x2350/0x25b0\n[c000000008265cb4] __do_sys_finit_module+0xd4/0x160\n[c000000008031110] system_call_exception+0x150/0x2d0\n[c00000000800d35c] system_call_common+0xec/0x278\n\nFix this be nulling shost->ehandler when the kthread fails to spawn.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5w29-44gv-2g38/GHSA-5w29-44gv-2g38.json b/advisories/unreviewed/2024/05/GHSA-5w29-44gv-2g38/GHSA-5w29-44gv-2g38.json index 52ea998850b..76dcd7d95b7 100644 --- a/advisories/unreviewed/2024/05/GHSA-5w29-44gv-2g38/GHSA-5w29-44gv-2g38.json +++ b/advisories/unreviewed/2024/05/GHSA-5w29-44gv-2g38/GHSA-5w29-44gv-2g38.json @@ -7,12 +7,8 @@ "CVE-2023-52708" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mmc_spi: fix error handling in mmc_spi_probe()\n\nIf mmc_add_host() fails, it doesn't need to call mmc_remove_host(),\nor it will cause null-ptr-deref, because of deleting a not added\ndevice in mmc_remove_host().\n\nTo fix this, goto label 'fail_glue_init', if mmc_add_host() fails,\nand change the label 'fail_add_host' to 'fail_gpiod_request'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-64v3-vwp6-q2hj/GHSA-64v3-vwp6-q2hj.json b/advisories/unreviewed/2024/05/GHSA-64v3-vwp6-q2hj/GHSA-64v3-vwp6-q2hj.json index 4f5abfb856e..baecc1238fc 100644 --- a/advisories/unreviewed/2024/05/GHSA-64v3-vwp6-q2hj/GHSA-64v3-vwp6-q2hj.json +++ b/advisories/unreviewed/2024/05/GHSA-64v3-vwp6-q2hj/GHSA-64v3-vwp6-q2hj.json @@ -7,12 +7,8 @@ "CVE-2023-52730" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: sdio: fix possible resource leaks in some error paths\n\nIf sdio_add_func() or sdio_init_func() fails, sdio_remove_func() can\nnot release the resources, because the sdio function is not presented\nin these two cases, it won't call of_node_put() or put_device().\n\nTo fix these leaks, make sdio_func_present() only control whether\ndevice_del() needs to be called or not, then always call of_node_put()\nand put_device().\n\nIn error case in sdio_init_func(), the reference of 'card->dev' is\nnot get, to avoid redundant put in sdio_free_func_cis(), move the\nget_device() to sdio_alloc_func() and put_device() to sdio_release_func(),\nit can keep the get/put function be balanced.\n\nWithout this patch, while doing fault inject test, it can get the\nfollowing leak reports, after this fix, the leak is gone.\n\nunreferenced object 0xffff888112514000 (size 2048):\n comm \"kworker/3:2\", pid 65, jiffies 4294741614 (age 124.774s)\n hex dump (first 32 bytes):\n 00 e0 6f 12 81 88 ff ff 60 58 8d 06 81 88 ff ff ..o.....`X......\n 10 40 51 12 81 88 ff ff 10 40 51 12 81 88 ff ff .@Q......@Q.....\n backtrace:\n [<000000009e5931da>] kmalloc_trace+0x21/0x110\n [<000000002f839ccb>] mmc_alloc_card+0x38/0xb0 [mmc_core]\n [<0000000004adcbf6>] mmc_sdio_init_card+0xde/0x170 [mmc_core]\n [<000000007538fea0>] mmc_attach_sdio+0xcb/0x1b0 [mmc_core]\n [<00000000d4fdeba7>] mmc_rescan+0x54a/0x640 [mmc_core]\n\nunreferenced object 0xffff888112511000 (size 2048):\n comm \"kworker/3:2\", pid 65, jiffies 4294741623 (age 124.766s)\n hex dump (first 32 bytes):\n 00 40 51 12 81 88 ff ff e0 58 8d 06 81 88 ff ff .@Q......X......\n 10 10 51 12 81 88 ff ff 10 10 51 12 81 88 ff ff ..Q.......Q.....\n backtrace:\n [<000000009e5931da>] kmalloc_trace+0x21/0x110\n [<00000000fcbe706c>] sdio_alloc_func+0x35/0x100 [mmc_core]\n [<00000000c68f4b50>] mmc_attach_sdio.cold.18+0xb1/0x395 [mmc_core]\n [<00000000d4fdeba7>] mmc_rescan+0x54a/0x640 [mmc_core]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6g88-wmq7-m8g5/GHSA-6g88-wmq7-m8g5.json b/advisories/unreviewed/2024/05/GHSA-6g88-wmq7-m8g5/GHSA-6g88-wmq7-m8g5.json index f9c4ee9cf6b..16310a74636 100644 --- a/advisories/unreviewed/2024/05/GHSA-6g88-wmq7-m8g5/GHSA-6g88-wmq7-m8g5.json +++ b/advisories/unreviewed/2024/05/GHSA-6g88-wmq7-m8g5/GHSA-6g88-wmq7-m8g5.json @@ -7,12 +7,8 @@ "CVE-2021-47412" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: don't call rq_qos_ops->done_bio if the bio isn't tracked\n\nrq_qos framework is only applied on request based driver, so:\n\n1) rq_qos_done_bio() needn't to be called for bio based driver\n\n2) rq_qos_done_bio() needn't to be called for bio which isn't tracked,\nsuch as bios ended from error handling code.\n\nEspecially in bio_endio():\n\n1) request queue is referred via bio->bi_bdev->bd_disk->queue, which\nmay be gone since request queue refcount may not be held in above two\ncases\n\n2) q->rq_qos may be freed in blk_cleanup_queue() when calling into\n__rq_qos_done_bio()\n\nFix the potential kernel panic by not calling rq_qos_ops->done_bio if\nthe bio isn't tracked. This way is safe because both ioc_rqos_done_bio()\nand blkcg_iolatency_done_bio() are nop if the bio isn't tracked.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6hmf-7mx4-83j8/GHSA-6hmf-7mx4-83j8.json b/advisories/unreviewed/2024/05/GHSA-6hmf-7mx4-83j8/GHSA-6hmf-7mx4-83j8.json index d953941b680..14e5b48cd35 100644 --- a/advisories/unreviewed/2024/05/GHSA-6hmf-7mx4-83j8/GHSA-6hmf-7mx4-83j8.json +++ b/advisories/unreviewed/2024/05/GHSA-6hmf-7mx4-83j8/GHSA-6hmf-7mx4-83j8.json @@ -7,12 +7,8 @@ "CVE-2021-47372" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: fix use after free on rmmod\n\nplat_dev->dev->platform_data is released by platform_device_unregister(),\nuse of pclk and hclk is a use-after-free. Since device unregister won't\nneed a clk device we adjust the function call sequence to fix this issue.\n\n[ 31.261225] BUG: KASAN: use-after-free in macb_remove+0x77/0xc6 [macb_pci]\n[ 31.275563] Freed by task 306:\n[ 30.276782] platform_device_release+0x25/0x80", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7h7v-xpwq-j3w4/GHSA-7h7v-xpwq-j3w4.json b/advisories/unreviewed/2024/05/GHSA-7h7v-xpwq-j3w4/GHSA-7h7v-xpwq-j3w4.json index 010f9b6fd35..105fd71e736 100644 --- a/advisories/unreviewed/2024/05/GHSA-7h7v-xpwq-j3w4/GHSA-7h7v-xpwq-j3w4.json +++ b/advisories/unreviewed/2024/05/GHSA-7h7v-xpwq-j3w4/GHSA-7h7v-xpwq-j3w4.json @@ -7,12 +7,8 @@ "CVE-2023-52849" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/mem: Fix shutdown order\n\nIra reports that removing cxl_mock_mem causes a crash with the following\ntrace:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000044\n [..]\n RIP: 0010:cxl_region_decode_reset+0x7f/0x180 [cxl_core]\n [..]\n Call Trace:\n \n cxl_region_detach+0xe8/0x210 [cxl_core]\n cxl_decoder_kill_region+0x27/0x40 [cxl_core]\n cxld_unregister+0x29/0x40 [cxl_core]\n devres_release_all+0xb8/0x110\n device_unbind_cleanup+0xe/0x70\n device_release_driver_internal+0x1d2/0x210\n bus_remove_device+0xd7/0x150\n device_del+0x155/0x3e0\n device_unregister+0x13/0x60\n devm_release_action+0x4d/0x90\n ? __pfx_unregister_port+0x10/0x10 [cxl_core]\n delete_endpoint+0x121/0x130 [cxl_core]\n devres_release_all+0xb8/0x110\n device_unbind_cleanup+0xe/0x70\n device_release_driver_internal+0x1d2/0x210\n bus_remove_device+0xd7/0x150\n device_del+0x155/0x3e0\n ? lock_release+0x142/0x290\n cdev_device_del+0x15/0x50\n cxl_memdev_unregister+0x54/0x70 [cxl_core]\n\nThis crash is due to the clearing out the cxl_memdev's driver context\n(@cxlds) before the subsystem is done with it. This is ultimately due to\nthe region(s), that this memdev is a member, being torn down and expecting\nto be able to de-reference @cxlds, like here:\n\nstatic int cxl_region_decode_reset(struct cxl_region *cxlr, int count)\n...\n if (cxlds->rcd)\n goto endpoint_reset;\n...\n\nFix it by keeping the driver context valid until memdev-device\nunregistration, and subsequently the entire stack of related\ndependencies, unwinds.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7rxw-gv4w-f8w6/GHSA-7rxw-gv4w-f8w6.json b/advisories/unreviewed/2024/05/GHSA-7rxw-gv4w-f8w6/GHSA-7rxw-gv4w-f8w6.json index 1422047fd27..6ef10780d61 100644 --- a/advisories/unreviewed/2024/05/GHSA-7rxw-gv4w-f8w6/GHSA-7rxw-gv4w-f8w6.json +++ b/advisories/unreviewed/2024/05/GHSA-7rxw-gv4w-f8w6/GHSA-7rxw-gv4w-f8w6.json @@ -7,12 +7,8 @@ "CVE-2023-52877" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: Fix NULL pointer dereference in tcpm_pd_svdm()\n\nIt is possible that typec_register_partner() returns ERR_PTR on failure.\nWhen port->partner is an error, a NULL pointer dereference may occur as\nshown below.\n\n[91222.095236][ T319] typec port0: failed to register partner (-17)\n...\n[91225.061491][ T319] Unable to handle kernel NULL pointer dereference\nat virtual address 000000000000039f\n[91225.274642][ T319] pc : tcpm_pd_data_request+0x310/0x13fc\n[91225.274646][ T319] lr : tcpm_pd_data_request+0x298/0x13fc\n[91225.308067][ T319] Call trace:\n[91225.308070][ T319] tcpm_pd_data_request+0x310/0x13fc\n[91225.308073][ T319] tcpm_pd_rx_handler+0x100/0x9e8\n[91225.355900][ T319] kthread_worker_fn+0x178/0x58c\n[91225.355902][ T319] kthread+0x150/0x200\n[91225.355905][ T319] ret_from_fork+0x10/0x30\n\nAdd a check for port->partner to avoid dereferencing a NULL pointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7wxc-v995-9mmf/GHSA-7wxc-v995-9mmf.json b/advisories/unreviewed/2024/05/GHSA-7wxc-v995-9mmf/GHSA-7wxc-v995-9mmf.json index 2b3999d392b..1b017820c71 100644 --- a/advisories/unreviewed/2024/05/GHSA-7wxc-v995-9mmf/GHSA-7wxc-v995-9mmf.json +++ b/advisories/unreviewed/2024/05/GHSA-7wxc-v995-9mmf/GHSA-7wxc-v995-9mmf.json @@ -7,12 +7,8 @@ "CVE-2021-47430" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/entry: Clear X86_FEATURE_SMAP when CONFIG_X86_SMAP=n\n\nCommit\n\n 3c73b81a9164 (\"x86/entry, selftests: Further improve user entry sanity checks\")\n\nadded a warning if AC is set when in the kernel.\n\nCommit\n\n 662a0221893a3d (\"x86/entry: Fix AC assertion\")\n\nchanged the warning to only fire if the CPU supports SMAP.\n\nHowever, the warning can still trigger on a machine that supports SMAP\nbut where it's disabled in the kernel config and when running the\nsyscall_nt selftest, for example:\n\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 49 at irqentry_enter_from_user_mode\n CPU: 0 PID: 49 Comm: init Tainted: G T 5.15.0-rc4+ #98 e6202628ee053b4f310759978284bd8bb0ce6905\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1ubuntu1 04/01/2014\n RIP: 0010:irqentry_enter_from_user_mode\n ...\n Call Trace:\n ? irqentry_enter\n ? exc_general_protection\n ? asm_exc_general_protection\n ? asm_exc_general_protectio\n\nIS_ENABLED(CONFIG_X86_SMAP) could be added to the warning condition, but\neven this would not be enough in case SMAP is disabled at boot time with\nthe \"nosmap\" parameter.\n\nTo be consistent with \"nosmap\" behaviour, clear X86_FEATURE_SMAP when\n!CONFIG_X86_SMAP.\n\nFound using entry-fuzz + satrandconfig.\n\n [ bp: Massage commit message. ]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7xqf-4p6f-w78m/GHSA-7xqf-4p6f-w78m.json b/advisories/unreviewed/2024/05/GHSA-7xqf-4p6f-w78m/GHSA-7xqf-4p6f-w78m.json index 765057d083b..b55a196fd6d 100644 --- a/advisories/unreviewed/2024/05/GHSA-7xqf-4p6f-w78m/GHSA-7xqf-4p6f-w78m.json +++ b/advisories/unreviewed/2024/05/GHSA-7xqf-4p6f-w78m/GHSA-7xqf-4p6f-w78m.json @@ -7,12 +7,8 @@ "CVE-2023-52860" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/perf: hisi: use cpuhp_state_remove_instance_nocalls() for hisi_hns3_pmu uninit process\n\nWhen tearing down a 'hisi_hns3' PMU, we mistakenly run the CPU hotplug\ncallbacks after the device has been unregistered, leading to fireworks\nwhen we try to execute empty function callbacks within the driver:\n\n | Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n | CPU: 0 PID: 15 Comm: cpuhp/0 Tainted: G W O 5.12.0-rc4+ #1\n | Hardware name: , BIOS KpxxxFPGA 1P B600 V143 04/22/2021\n | pstate: 80400009 (Nzcv daif +PAN -UAO -TCO BTYPE=--)\n | pc : perf_pmu_migrate_context+0x98/0x38c\n | lr : perf_pmu_migrate_context+0x94/0x38c\n |\n | Call trace:\n | perf_pmu_migrate_context+0x98/0x38c\n | hisi_hns3_pmu_offline_cpu+0x104/0x12c [hisi_hns3_pmu]\n\nUse cpuhp_state_remove_instance_nocalls() instead of\ncpuhp_state_remove_instance() so that the notifiers don't execute after\nthe PMU device has been unregistered.\n\n[will: Rewrote commit message]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8j5h-5p5c-hg7m/GHSA-8j5h-5p5c-hg7m.json b/advisories/unreviewed/2024/05/GHSA-8j5h-5p5c-hg7m/GHSA-8j5h-5p5c-hg7m.json index 99095a42e6c..732faea29c1 100644 --- a/advisories/unreviewed/2024/05/GHSA-8j5h-5p5c-hg7m/GHSA-8j5h-5p5c-hg7m.json +++ b/advisories/unreviewed/2024/05/GHSA-8j5h-5p5c-hg7m/GHSA-8j5h-5p5c-hg7m.json @@ -7,12 +7,8 @@ "CVE-2023-52879" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Have trace_event_file have ref counters\n\nThe following can crash the kernel:\n\n # cd /sys/kernel/tracing\n # echo 'p:sched schedule' > kprobe_events\n # exec 5>>events/kprobes/sched/enable\n # > kprobe_events\n # exec 5>&-\n\nThe above commands:\n\n 1. Change directory to the tracefs directory\n 2. Create a kprobe event (doesn't matter what one)\n 3. Open bash file descriptor 5 on the enable file of the kprobe event\n 4. Delete the kprobe event (removes the files too)\n 5. Close the bash file descriptor 5\n\nThe above causes a crash!\n\n BUG: kernel NULL pointer dereference, address: 0000000000000028\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 6 PID: 877 Comm: bash Not tainted 6.5.0-rc4-test-00008-g2c6b6b1029d4-dirty #186\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014\n RIP: 0010:tracing_release_file_tr+0xc/0x50\n\nWhat happens here is that the kprobe event creates a trace_event_file\n\"file\" descriptor that represents the file in tracefs to the event. It\nmaintains state of the event (is it enabled for the given instance?).\nOpening the \"enable\" file gets a reference to the event \"file\" descriptor\nvia the open file descriptor. When the kprobe event is deleted, the file is\nalso deleted from the tracefs system which also frees the event \"file\"\ndescriptor.\n\nBut as the tracefs file is still opened by user space, it will not be\ntotally removed until the final dput() is called on it. But this is not\ntrue with the event \"file\" descriptor that is already freed. If the user\ndoes a write to or simply closes the file descriptor it will reference the\nevent \"file\" descriptor that was just freed, causing a use-after-free bug.\n\nTo solve this, add a ref count to the event \"file\" descriptor as well as a\nnew flag called \"FREED\". The \"file\" will not be freed until the last\nreference is released. But the FREE flag will be set when the event is\nremoved to prevent any more modifications to that event from happening,\neven if there's still a reference to the event \"file\" descriptor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8jfw-gf5v-vvhx/GHSA-8jfw-gf5v-vvhx.json b/advisories/unreviewed/2024/05/GHSA-8jfw-gf5v-vvhx/GHSA-8jfw-gf5v-vvhx.json index 8cc69045eca..db49d790a68 100644 --- a/advisories/unreviewed/2024/05/GHSA-8jfw-gf5v-vvhx/GHSA-8jfw-gf5v-vvhx.json +++ b/advisories/unreviewed/2024/05/GHSA-8jfw-gf5v-vvhx/GHSA-8jfw-gf5v-vvhx.json @@ -7,12 +7,8 @@ "CVE-2023-52868" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: core: prevent potential string overflow\n\nThe dev->id value comes from ida_alloc() so it's a number between zero\nand INT_MAX. If it's too high then these sprintf()s will overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8r4c-vj8m-g96m/GHSA-8r4c-vj8m-g96m.json b/advisories/unreviewed/2024/05/GHSA-8r4c-vj8m-g96m/GHSA-8r4c-vj8m-g96m.json index 2c3db01815d..038d49f7295 100644 --- a/advisories/unreviewed/2024/05/GHSA-8r4c-vj8m-g96m/GHSA-8r4c-vj8m-g96m.json +++ b/advisories/unreviewed/2024/05/GHSA-8r4c-vj8m-g96m/GHSA-8r4c-vj8m-g96m.json @@ -7,12 +7,8 @@ "CVE-2023-52875" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt2701: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8rjh-f75w-mvh9/GHSA-8rjh-f75w-mvh9.json b/advisories/unreviewed/2024/05/GHSA-8rjh-f75w-mvh9/GHSA-8rjh-f75w-mvh9.json index 5767b8653dd..abf4a7ca626 100644 --- a/advisories/unreviewed/2024/05/GHSA-8rjh-f75w-mvh9/GHSA-8rjh-f75w-mvh9.json +++ b/advisories/unreviewed/2024/05/GHSA-8rjh-f75w-mvh9/GHSA-8rjh-f75w-mvh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8w7f-4crr-6cfr/GHSA-8w7f-4crr-6cfr.json b/advisories/unreviewed/2024/05/GHSA-8w7f-4crr-6cfr/GHSA-8w7f-4crr-6cfr.json index 843f10f195b..8de4c54be0e 100644 --- a/advisories/unreviewed/2024/05/GHSA-8w7f-4crr-6cfr/GHSA-8w7f-4crr-6cfr.json +++ b/advisories/unreviewed/2024/05/GHSA-8w7f-4crr-6cfr/GHSA-8w7f-4crr-6cfr.json @@ -7,12 +7,8 @@ "CVE-2022-48709" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: switch: fix potential memleak in ice_add_adv_recipe()\n\nWhen ice_add_special_words() fails, the 'rm' is not released, which will\nlead to a memory leak. Fix this up by going to 'err_unroll' label.\n\nCompile tested only.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-97cf-h8mh-89rg/GHSA-97cf-h8mh-89rg.json b/advisories/unreviewed/2024/05/GHSA-97cf-h8mh-89rg/GHSA-97cf-h8mh-89rg.json index da232a8f951..63cb7142812 100644 --- a/advisories/unreviewed/2024/05/GHSA-97cf-h8mh-89rg/GHSA-97cf-h8mh-89rg.json +++ b/advisories/unreviewed/2024/05/GHSA-97cf-h8mh-89rg/GHSA-97cf-h8mh-89rg.json @@ -7,12 +7,8 @@ "CVE-2023-52876" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt7629-eth: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9mq7-wpm3-gv26/GHSA-9mq7-wpm3-gv26.json b/advisories/unreviewed/2024/05/GHSA-9mq7-wpm3-gv26/GHSA-9mq7-wpm3-gv26.json index c1fb80fd271..17abdad3074 100644 --- a/advisories/unreviewed/2024/05/GHSA-9mq7-wpm3-gv26/GHSA-9mq7-wpm3-gv26.json +++ b/advisories/unreviewed/2024/05/GHSA-9mq7-wpm3-gv26/GHSA-9mq7-wpm3-gv26.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9q5q-4f67-9x48/GHSA-9q5q-4f67-9x48.json b/advisories/unreviewed/2024/05/GHSA-9q5q-4f67-9x48/GHSA-9q5q-4f67-9x48.json index 6b8c60ad2a9..6279a276c23 100644 --- a/advisories/unreviewed/2024/05/GHSA-9q5q-4f67-9x48/GHSA-9q5q-4f67-9x48.json +++ b/advisories/unreviewed/2024/05/GHSA-9q5q-4f67-9x48/GHSA-9q5q-4f67-9x48.json @@ -7,12 +7,8 @@ "CVE-2023-52763" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: mipi-i3c-hci: Fix a kernel panic for accessing DAT_data.\n\nThe `i3c_master_bus_init` function may attach the I2C devices before the\nI3C bus initialization. In this flow, the DAT `alloc_entry`` will be used\nbefore the DAT `init`. Additionally, if the `i3c_master_bus_init` fails,\nthe DAT `cleanup` will execute before the device is detached, which will\nexecue DAT `free_entry` function. The above scenario can cause the driver\nto use DAT_data when it is NULL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c228-4gh7-9r76/GHSA-c228-4gh7-9r76.json b/advisories/unreviewed/2024/05/GHSA-c228-4gh7-9r76/GHSA-c228-4gh7-9r76.json index 4fe50954871..cecd1d90f5b 100644 --- a/advisories/unreviewed/2024/05/GHSA-c228-4gh7-9r76/GHSA-c228-4gh7-9r76.json +++ b/advisories/unreviewed/2024/05/GHSA-c228-4gh7-9r76/GHSA-c228-4gh7-9r76.json @@ -7,12 +7,8 @@ "CVE-2023-52848" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to drop meta_inode's page cache in f2fs_put_super()\n\nsyzbot reports a kernel bug as below:\n\nF2FS-fs (loop1): detect filesystem reference count leak during umount, type: 10, count: 1\nkernel BUG at fs/f2fs/super.c:1639!\nCPU: 0 PID: 15451 Comm: syz-executor.1 Not tainted 6.5.0-syzkaller-09338-ge0152e7481c6 #0\nRIP: 0010:f2fs_put_super+0xce1/0xed0 fs/f2fs/super.c:1639\nCall Trace:\n generic_shutdown_super+0x161/0x3c0 fs/super.c:693\n kill_block_super+0x3b/0x70 fs/super.c:1646\n kill_f2fs_super+0x2b7/0x3d0 fs/f2fs/super.c:4879\n deactivate_locked_super+0x9a/0x170 fs/super.c:481\n deactivate_super+0xde/0x100 fs/super.c:514\n cleanup_mnt+0x222/0x3d0 fs/namespace.c:1254\n task_work_run+0x14d/0x240 kernel/task_work.c:179\n resume_user_mode_work include/linux/resume_user_mode.h:49 [inline]\n exit_to_user_mode_loop kernel/entry/common.c:171 [inline]\n exit_to_user_mode_prepare+0x210/0x240 kernel/entry/common.c:204\n __syscall_exit_to_user_mode_work kernel/entry/common.c:285 [inline]\n syscall_exit_to_user_mode+0x1d/0x60 kernel/entry/common.c:296\n do_syscall_64+0x44/0xb0 arch/x86/entry/common.c:86\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nIn f2fs_put_super(), it tries to do sanity check on dirty and IO\nreference count of f2fs, once there is any reference count leak,\nit will trigger panic.\n\nThe root case is, during f2fs_put_super(), if there is any IO error\nin f2fs_wait_on_all_pages(), we missed to truncate meta_inode's page\ncache later, result in panic, fix this case.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c5rq-j6hh-2mxr/GHSA-c5rq-j6hh-2mxr.json b/advisories/unreviewed/2024/05/GHSA-c5rq-j6hh-2mxr/GHSA-c5rq-j6hh-2mxr.json index 1cef44a6bc2..30a6135a808 100644 --- a/advisories/unreviewed/2024/05/GHSA-c5rq-j6hh-2mxr/GHSA-c5rq-j6hh-2mxr.json +++ b/advisories/unreviewed/2024/05/GHSA-c5rq-j6hh-2mxr/GHSA-c5rq-j6hh-2mxr.json @@ -7,12 +7,8 @@ "CVE-2022-48706" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa: ifcvf: Do proper cleanup if IFCVF init fails\n\nifcvf_mgmt_dev leaks memory if it is not freed before\nreturning. Call is made to correct return statement\nso memory does not leak. ifcvf_init_hw does not take\ncare of this so it is needed to do it here.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cc2x-949j-9v5x/GHSA-cc2x-949j-9v5x.json b/advisories/unreviewed/2024/05/GHSA-cc2x-949j-9v5x/GHSA-cc2x-949j-9v5x.json index 7a1a12c8e99..04b88c7cdd7 100644 --- a/advisories/unreviewed/2024/05/GHSA-cc2x-949j-9v5x/GHSA-cc2x-949j-9v5x.json +++ b/advisories/unreviewed/2024/05/GHSA-cc2x-949j-9v5x/GHSA-cc2x-949j-9v5x.json @@ -7,12 +7,8 @@ "CVE-2021-47362" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Update intermediate power state for SI\n\nUpdate the current state as boot state during dpm initialization.\nDuring the subsequent initialization, set_power_state gets called to\ntransition to the final power state. set_power_state refers to values\nfrom the current state and without current state populated, it could\nresult in NULL pointer dereference.\n\nFor ex: on platforms where PCI speed change is supported through ACPI\nATCS method, the link speed of current state needs to be queried before\ndeciding on changing to final power state's link speed. The logic to query\nATCS-support was broken on certain platforms. The issue became visible\nwhen broken ATCS-support logic got fixed with commit\nf9b7f3703ff9 (\"drm/amdgpu/acpi: make ATPX/ATCS structures global (v2)\").\n\nBug: https://gitlab.freedesktop.org/drm/amd/-/issues/1698", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-f8m5-x3mv-32wr/GHSA-f8m5-x3mv-32wr.json b/advisories/unreviewed/2024/05/GHSA-f8m5-x3mv-32wr/GHSA-f8m5-x3mv-32wr.json index 7a126e589bc..5fa29e2d8e3 100644 --- a/advisories/unreviewed/2024/05/GHSA-f8m5-x3mv-32wr/GHSA-f8m5-x3mv-32wr.json +++ b/advisories/unreviewed/2024/05/GHSA-f8m5-x3mv-32wr/GHSA-f8m5-x3mv-32wr.json @@ -7,12 +7,8 @@ "CVE-2023-52850" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: hantro: Check whether reset op is defined before use\n\nThe i.MX8MM/N/P does not define the .reset op since reset of the VPU is\ndone by genpd. Check whether the .reset op is defined before calling it\nto avoid NULL pointer dereference.\n\nNote that the Fixes tag is set to the commit which removed the reset op\nfrom i.MX8M Hantro G2 implementation, this is because before this commit\nall the implementations did define the .reset op.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-ffvm-4h72-qwr5/GHSA-ffvm-4h72-qwr5.json b/advisories/unreviewed/2024/05/GHSA-ffvm-4h72-qwr5/GHSA-ffvm-4h72-qwr5.json index f7e758306b1..4b3c1fd3ba5 100644 --- a/advisories/unreviewed/2024/05/GHSA-ffvm-4h72-qwr5/GHSA-ffvm-4h72-qwr5.json +++ b/advisories/unreviewed/2024/05/GHSA-ffvm-4h72-qwr5/GHSA-ffvm-4h72-qwr5.json @@ -7,12 +7,8 @@ "CVE-2023-52751" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in smb2_query_info_compound()\n\nThe following UAF was triggered when running fstests generic/072 with\nKASAN enabled against Windows Server 2022 and mount options\n'multichannel,max_channels=2,vers=3.1.1,mfsymlinks,noperm'\n\n BUG: KASAN: slab-use-after-free in smb2_query_info_compound+0x423/0x6d0 [cifs]\n Read of size 8 at addr ffff888014941048 by task xfs_io/27534\n\n CPU: 0 PID: 27534 Comm: xfs_io Not tainted 6.6.0-rc7 #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS\n rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014\n Call Trace:\n dump_stack_lvl+0x4a/0x80\n print_report+0xcf/0x650\n ? srso_alias_return_thunk+0x5/0x7f\n ? srso_alias_return_thunk+0x5/0x7f\n ? __phys_addr+0x46/0x90\n kasan_report+0xda/0x110\n ? smb2_query_info_compound+0x423/0x6d0 [cifs]\n ? smb2_query_info_compound+0x423/0x6d0 [cifs]\n smb2_query_info_compound+0x423/0x6d0 [cifs]\n ? __pfx_smb2_query_info_compound+0x10/0x10 [cifs]\n ? srso_alias_return_thunk+0x5/0x7f\n ? __stack_depot_save+0x39/0x480\n ? kasan_save_stack+0x33/0x60\n ? kasan_set_track+0x25/0x30\n ? ____kasan_slab_free+0x126/0x170\n smb2_queryfs+0xc2/0x2c0 [cifs]\n ? __pfx_smb2_queryfs+0x10/0x10 [cifs]\n ? __pfx___lock_acquire+0x10/0x10\n smb311_queryfs+0x210/0x220 [cifs]\n ? __pfx_smb311_queryfs+0x10/0x10 [cifs]\n ? srso_alias_return_thunk+0x5/0x7f\n ? __lock_acquire+0x480/0x26c0\n ? lock_release+0x1ed/0x640\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_raw_spin_unlock+0x9b/0x100\n cifs_statfs+0x18c/0x4b0 [cifs]\n statfs_by_dentry+0x9b/0xf0\n fd_statfs+0x4e/0xb0\n __do_sys_fstatfs+0x7f/0xe0\n ? __pfx___do_sys_fstatfs+0x10/0x10\n ? srso_alias_return_thunk+0x5/0x7f\n ? lockdep_hardirqs_on_prepare+0x136/0x200\n ? srso_alias_return_thunk+0x5/0x7f\n do_syscall_64+0x3f/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n Allocated by task 27534:\n kasan_save_stack+0x33/0x60\n kasan_set_track+0x25/0x30\n __kasan_kmalloc+0x8f/0xa0\n open_cached_dir+0x71b/0x1240 [cifs]\n smb2_query_info_compound+0x5c3/0x6d0 [cifs]\n smb2_queryfs+0xc2/0x2c0 [cifs]\n smb311_queryfs+0x210/0x220 [cifs]\n cifs_statfs+0x18c/0x4b0 [cifs]\n statfs_by_dentry+0x9b/0xf0\n fd_statfs+0x4e/0xb0\n __do_sys_fstatfs+0x7f/0xe0\n do_syscall_64+0x3f/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n Freed by task 27534:\n kasan_save_stack+0x33/0x60\n kasan_set_track+0x25/0x30\n kasan_save_free_info+0x2b/0x50\n ____kasan_slab_free+0x126/0x170\n slab_free_freelist_hook+0xd0/0x1e0\n __kmem_cache_free+0x9d/0x1b0\n open_cached_dir+0xff5/0x1240 [cifs]\n smb2_query_info_compound+0x5c3/0x6d0 [cifs]\n smb2_queryfs+0xc2/0x2c0 [cifs]\n\nThis is a race between open_cached_dir() and cached_dir_lease_break()\nwhere the cache entry for the open directory handle receives a lease\nbreak while creating it. And before returning from open_cached_dir(),\nwe put the last reference of the new @cfid because of\n!@cfid->has_lease.\n\nBesides the UAF, while running xfstests a lot of missed lease breaks\nhave been noticed in tests that run several concurrent statfs(2) calls\non those cached fids\n\n CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame...\n CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1...\n CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 00000000715bfe83 len 108\n CIFS: VFS: Dump pending requests:\n CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame...\n CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1...\n CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 000000005aa7316e len 108\n ...\n\nTo fix both, in open_cached_dir() ensure that @cfid->has_lease is set\nright before sending out compounded request so that any potential\nlease break will be get processed by demultiplex thread while we're\nstill caching @cfid. And, if open failed for some reason, re-check\n@cfid->has_lease to decide whether or not put lease reference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fhgv-9f93-wpvr/GHSA-fhgv-9f93-wpvr.json b/advisories/unreviewed/2024/05/GHSA-fhgv-9f93-wpvr/GHSA-fhgv-9f93-wpvr.json index c46939fbd1d..9f9652718d9 100644 --- a/advisories/unreviewed/2024/05/GHSA-fhgv-9f93-wpvr/GHSA-fhgv-9f93-wpvr.json +++ b/advisories/unreviewed/2024/05/GHSA-fhgv-9f93-wpvr/GHSA-fhgv-9f93-wpvr.json @@ -7,12 +7,8 @@ "CVE-2023-52878" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: dev: can_put_echo_skb(): don't crash kernel if can_priv::echo_skb is accessed out of bounds\n\nIf the \"struct can_priv::echoo_skb\" is accessed out of bounds, this\nwould cause a kernel crash. Instead, issue a meaningful warning\nmessage and return with an error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g3g2-rm55-27fj/GHSA-g3g2-rm55-27fj.json b/advisories/unreviewed/2024/05/GHSA-g3g2-rm55-27fj/GHSA-g3g2-rm55-27fj.json index 83e42f69382..f83805d2dde 100644 --- a/advisories/unreviewed/2024/05/GHSA-g3g2-rm55-27fj/GHSA-g3g2-rm55-27fj.json +++ b/advisories/unreviewed/2024/05/GHSA-g3g2-rm55-27fj/GHSA-g3g2-rm55-27fj.json @@ -7,12 +7,8 @@ "CVE-2023-52846" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: Prevent use after free in prp_create_tagged_frame()\n\nThe prp_fill_rct() function can fail. In that situation, it frees the\nskb and returns NULL. Meanwhile on the success path, it returns the\noriginal skb. So it's straight forward to fix bug by using the returned\nvalue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g7rf-8xcx-vfgm/GHSA-g7rf-8xcx-vfgm.json b/advisories/unreviewed/2024/05/GHSA-g7rf-8xcx-vfgm/GHSA-g7rf-8xcx-vfgm.json index 310fd47d152..ebcd3b8b33f 100644 --- a/advisories/unreviewed/2024/05/GHSA-g7rf-8xcx-vfgm/GHSA-g7rf-8xcx-vfgm.json +++ b/advisories/unreviewed/2024/05/GHSA-g7rf-8xcx-vfgm/GHSA-g7rf-8xcx-vfgm.json @@ -7,12 +7,8 @@ "CVE-2023-52865" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt6797: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g7x7-27fq-c7pw/GHSA-g7x7-27fq-c7pw.json b/advisories/unreviewed/2024/05/GHSA-g7x7-27fq-c7pw/GHSA-g7x7-27fq-c7pw.json index 61f4de89f2b..eb0122fc31c 100644 --- a/advisories/unreviewed/2024/05/GHSA-g7x7-27fq-c7pw/GHSA-g7x7-27fq-c7pw.json +++ b/advisories/unreviewed/2024/05/GHSA-g7x7-27fq-c7pw/GHSA-g7x7-27fq-c7pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gj4h-wmhg-vp66/GHSA-gj4h-wmhg-vp66.json b/advisories/unreviewed/2024/05/GHSA-gj4h-wmhg-vp66/GHSA-gj4h-wmhg-vp66.json index b7e4be77448..d0445267b34 100644 --- a/advisories/unreviewed/2024/05/GHSA-gj4h-wmhg-vp66/GHSA-gj4h-wmhg-vp66.json +++ b/advisories/unreviewed/2024/05/GHSA-gj4h-wmhg-vp66/GHSA-gj4h-wmhg-vp66.json @@ -7,12 +7,8 @@ "CVE-2023-52854" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npadata: Fix refcnt handling in padata_free_shell()\n\nIn a high-load arm64 environment, the pcrypt_aead01 test in LTP can lead\nto system UAF (Use-After-Free) issues. Due to the lengthy analysis of\nthe pcrypt_aead01 function call, I'll describe the problem scenario\nusing a simplified model:\n\nSuppose there's a user of padata named `user_function` that adheres to\nthe padata requirement of calling `padata_free_shell` after `serial()`\nhas been invoked, as demonstrated in the following code:\n\n```c\nstruct request {\n struct padata_priv padata;\n struct completion *done;\n};\n\nvoid parallel(struct padata_priv *padata) {\n do_something();\n}\n\nvoid serial(struct padata_priv *padata) {\n struct request *request = container_of(padata,\n \t\t\t\tstruct request,\n\t\t\t\tpadata);\n complete(request->done);\n}\n\nvoid user_function() {\n DECLARE_COMPLETION(done)\n padata->parallel = parallel;\n padata->serial = serial;\n padata_do_parallel();\n wait_for_completion(&done);\n padata_free_shell();\n}\n```\n\nIn the corresponding padata.c file, there's the following code:\n\n```c\nstatic void padata_serial_worker(struct work_struct *serial_work) {\n ...\n cnt = 0;\n\n while (!list_empty(&local_list)) {\n ...\n padata->serial(padata);\n cnt++;\n }\n\n local_bh_enable();\n\n if (refcount_sub_and_test(cnt, &pd->refcnt))\n padata_free_pd(pd);\n}\n```\n\nBecause of the high system load and the accumulation of unexecuted\nsoftirq at this moment, `local_bh_enable()` in padata takes longer\nto execute than usual. Subsequently, when accessing `pd->refcnt`,\n`pd` has already been released by `padata_free_shell()`, resulting\nin a UAF issue with `pd->refcnt`.\n\nThe fix is straightforward: add `refcount_dec_and_test` before calling\n`padata_free_pd` in `padata_free_shell`.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gp9f-xh95-x98x/GHSA-gp9f-xh95-x98x.json b/advisories/unreviewed/2024/05/GHSA-gp9f-xh95-x98x/GHSA-gp9f-xh95-x98x.json index 24fbd814b65..40df7aadf3f 100644 --- a/advisories/unreviewed/2024/05/GHSA-gp9f-xh95-x98x/GHSA-gp9f-xh95-x98x.json +++ b/advisories/unreviewed/2024/05/GHSA-gp9f-xh95-x98x/GHSA-gp9f-xh95-x98x.json @@ -7,12 +7,8 @@ "CVE-2023-52702" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix possible memory leak in ovs_meter_cmd_set()\n\nold_meter needs to be free after it is detached regardless of whether\nthe new meter is successfully attached.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h7hm-j4cr-jwhq/GHSA-h7hm-j4cr-jwhq.json b/advisories/unreviewed/2024/05/GHSA-h7hm-j4cr-jwhq/GHSA-h7hm-j4cr-jwhq.json index 7a7a788333e..267a0d8fe6b 100644 --- a/advisories/unreviewed/2024/05/GHSA-h7hm-j4cr-jwhq/GHSA-h7hm-j4cr-jwhq.json +++ b/advisories/unreviewed/2024/05/GHSA-h7hm-j4cr-jwhq/GHSA-h7hm-j4cr-jwhq.json @@ -7,12 +7,8 @@ "CVE-2021-47383" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: Fix out-of-bound vmalloc access in imageblit\n\nThis issue happens when a userspace program does an ioctl\nFBIOPUT_VSCREENINFO passing the fb_var_screeninfo struct\ncontaining only the fields xres, yres, and bits_per_pixel\nwith values.\n\nIf this struct is the same as the previous ioctl, the\nvc_resize() detects it and doesn't call the resize_screen(),\nleaving the fb_var_screeninfo incomplete. And this leads to\nthe updatescrollmode() calculates a wrong value to\nfbcon_display->vrows, which makes the real_y() return a\nwrong value of y, and that value, eventually, causes\nthe imageblit to access an out-of-bound address value.\n\nTo solve this issue I made the resize_screen() be called\neven if the screen does not need any resizing, so it will\n\"fix and fill\" the fb_var_screeninfo independently.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hf7w-m8fc-q8fp/GHSA-hf7w-m8fc-q8fp.json b/advisories/unreviewed/2024/05/GHSA-hf7w-m8fc-q8fp/GHSA-hf7w-m8fc-q8fp.json index 2ffa3d9d54e..a384be9ad7e 100644 --- a/advisories/unreviewed/2024/05/GHSA-hf7w-m8fc-q8fp/GHSA-hf7w-m8fc-q8fp.json +++ b/advisories/unreviewed/2024/05/GHSA-hf7w-m8fc-q8fp/GHSA-hf7w-m8fc-q8fp.json @@ -7,12 +7,8 @@ "CVE-2021-47424" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix freeing of uninitialized misc IRQ vector\n\nWhen VSI set up failed in i40e_probe() as part of PF switch set up\ndriver was trying to free misc IRQ vectors in\ni40e_clear_interrupt_scheme and produced a kernel Oops:\n\n Trying to free already-free IRQ 266\n WARNING: CPU: 0 PID: 5 at kernel/irq/manage.c:1731 __free_irq+0x9a/0x300\n Workqueue: events work_for_cpu_fn\n RIP: 0010:__free_irq+0x9a/0x300\n Call Trace:\n ? synchronize_irq+0x3a/0xa0\n free_irq+0x2e/0x60\n i40e_clear_interrupt_scheme+0x53/0x190 [i40e]\n i40e_probe.part.108+0x134b/0x1a40 [i40e]\n ? kmem_cache_alloc+0x158/0x1c0\n ? acpi_ut_update_ref_count.part.1+0x8e/0x345\n ? acpi_ut_update_object_reference+0x15e/0x1e2\n ? strstr+0x21/0x70\n ? irq_get_irq_data+0xa/0x20\n ? mp_check_pin_attr+0x13/0xc0\n ? irq_get_irq_data+0xa/0x20\n ? mp_map_pin_to_irq+0xd3/0x2f0\n ? acpi_register_gsi_ioapic+0x93/0x170\n ? pci_conf1_read+0xa4/0x100\n ? pci_bus_read_config_word+0x49/0x70\n ? do_pci_enable_device+0xcc/0x100\n local_pci_probe+0x41/0x90\n work_for_cpu_fn+0x16/0x20\n process_one_work+0x1a7/0x360\n worker_thread+0x1cf/0x390\n ? create_worker+0x1a0/0x1a0\n kthread+0x112/0x130\n ? kthread_flush_work_fn+0x10/0x10\n ret_from_fork+0x1f/0x40\n\nThe problem is that at that point misc IRQ vectors\nwere not allocated yet and we get a call trace\nthat driver is trying to free already free IRQ vectors.\n\nAdd a check in i40e_clear_interrupt_scheme for __I40E_MISC_IRQ_REQUESTED\nPF state before calling i40e_free_misc_vector. This state is set only if\nmisc IRQ vectors were properly initialized.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j469-qwv3-79fj/GHSA-j469-qwv3-79fj.json b/advisories/unreviewed/2024/05/GHSA-j469-qwv3-79fj/GHSA-j469-qwv3-79fj.json index ee6e4b5cde9..c25e159a39a 100644 --- a/advisories/unreviewed/2024/05/GHSA-j469-qwv3-79fj/GHSA-j469-qwv3-79fj.json +++ b/advisories/unreviewed/2024/05/GHSA-j469-qwv3-79fj/GHSA-j469-qwv3-79fj.json @@ -7,12 +7,8 @@ "CVE-2021-47355" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\natm: nicstar: Fix possible use-after-free in nicstar_cleanup()\n\nThis module's remove path calls del_timer(). However, that function\ndoes not wait until the timer handler finishes. This means that the\ntimer handler may still be running after the driver's remove function\nhas finished, which would result in a use-after-free.\n\nFix by calling del_timer_sync(), which makes sure the timer handler\nhas finished, and unable to re-schedule itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j8cp-h624-v86v/GHSA-j8cp-h624-v86v.json b/advisories/unreviewed/2024/05/GHSA-j8cp-h624-v86v/GHSA-j8cp-h624-v86v.json index c9d7b8a98b3..803b984e0b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-j8cp-h624-v86v/GHSA-j8cp-h624-v86v.json +++ b/advisories/unreviewed/2024/05/GHSA-j8cp-h624-v86v/GHSA-j8cp-h624-v86v.json @@ -7,12 +7,8 @@ "CVE-2021-47416" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: mdio: fix memory leak\n\nSyzbot reported memory leak in MDIO bus interface, the problem was in\nwrong state logic.\n\nMDIOBUS_ALLOCATED indicates 2 states:\n\t1. Bus is only allocated\n\t2. Bus allocated and __mdiobus_register() fails, but\n\t device_register() was called\n\nIn case of device_register() has been called we should call put_device()\nto correctly free the memory allocated for this device, but mdiobus_free()\ncalls just kfree(dev) in case of MDIOBUS_ALLOCATED state\n\nTo avoid this behaviour we need to set bus->state to MDIOBUS_UNREGISTERED\n_before_ calling device_register(), because put_device() should be\ncalled even in case of device_register() failure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jm7v-c85h-4vvr/GHSA-jm7v-c85h-4vvr.json b/advisories/unreviewed/2024/05/GHSA-jm7v-c85h-4vvr/GHSA-jm7v-c85h-4vvr.json index 86b8fc7f974..b3c2362c518 100644 --- a/advisories/unreviewed/2024/05/GHSA-jm7v-c85h-4vvr/GHSA-jm7v-c85h-4vvr.json +++ b/advisories/unreviewed/2024/05/GHSA-jm7v-c85h-4vvr/GHSA-jm7v-c85h-4vvr.json @@ -7,12 +7,8 @@ "CVE-2023-52843" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nllc: verify mac len before reading mac header\n\nLLC reads the mac header with eth_hdr without verifying that the skb\nhas an Ethernet header.\n\nSyzbot was able to enter llc_rcv on a tun device. Tun can insert\npackets without mac len and with user configurable skb->protocol\n(passing a tun_pi header when not configuring IFF_NO_PI).\n\n BUG: KMSAN: uninit-value in llc_station_ac_send_test_r net/llc/llc_station.c:81 [inline]\n BUG: KMSAN: uninit-value in llc_station_rcv+0x6fb/0x1290 net/llc/llc_station.c:111\n llc_station_ac_send_test_r net/llc/llc_station.c:81 [inline]\n llc_station_rcv+0x6fb/0x1290 net/llc/llc_station.c:111\n llc_rcv+0xc5d/0x14a0 net/llc/llc_input.c:218\n __netif_receive_skb_one_core net/core/dev.c:5523 [inline]\n __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5637\n netif_receive_skb_internal net/core/dev.c:5723 [inline]\n netif_receive_skb+0x58/0x660 net/core/dev.c:5782\n tun_rx_batched+0x3ee/0x980 drivers/net/tun.c:1555\n tun_get_user+0x54c5/0x69c0 drivers/net/tun.c:2002\n\nAdd a mac_len test before all three eth_hdr(skb) calls under net/llc.\n\nThere are further uses in include/net/llc_pdu.h. All these are\nprotected by a test skb->protocol == ETH_P_802_2. Which does not\nprotect against this tun scenario.\n\nBut the mac_len test added in this patch in llc_fixup_skb will\nindirectly protect those too. That is called from llc_rcv before any\nother LLC code.\n\nIt is tempting to just add a blanket mac_len check in llc_rcv, but\nnot sure whether that could break valid LLC paths that do not assume\nan Ethernet header. 802.2 LLC may be used on top of non-802.3\nprotocols in principle. The below referenced commit shows that used\nto, on top of Token Ring.\n\nAt least one of the three eth_hdr uses goes back to before the start\nof git history. But the one that syzbot exercises is introduced in\nthis commit. That commit is old enough (2008), that effectively all\nstable kernels should receive this.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jwv9-vf83-vjmw/GHSA-jwv9-vf83-vjmw.json b/advisories/unreviewed/2024/05/GHSA-jwv9-vf83-vjmw/GHSA-jwv9-vf83-vjmw.json index fc0d7c6dd50..63255801941 100644 --- a/advisories/unreviewed/2024/05/GHSA-jwv9-vf83-vjmw/GHSA-jwv9-vf83-vjmw.json +++ b/advisories/unreviewed/2024/05/GHSA-jwv9-vf83-vjmw/GHSA-jwv9-vf83-vjmw.json @@ -7,12 +7,8 @@ "CVE-2021-47387" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: schedutil: Use kobject release() method to free sugov_tunables\n\nThe struct sugov_tunables is protected by the kobject, so we can't free\nit directly. Otherwise we would get a call trace like this:\n ODEBUG: free active (active state 0) object type: timer_list hint: delayed_work_timer_fn+0x0/0x30\n WARNING: CPU: 3 PID: 720 at lib/debugobjects.c:505 debug_print_object+0xb8/0x100\n Modules linked in:\n CPU: 3 PID: 720 Comm: a.sh Tainted: G W 5.14.0-rc1-next-20210715-yocto-standard+ #507\n Hardware name: Marvell OcteonTX CN96XX board (DT)\n pstate: 40400009 (nZcv daif +PAN -UAO -TCO BTYPE=--)\n pc : debug_print_object+0xb8/0x100\n lr : debug_print_object+0xb8/0x100\n sp : ffff80001ecaf910\n x29: ffff80001ecaf910 x28: ffff00011b10b8d0 x27: ffff800011043d80\n x26: ffff00011a8f0000 x25: ffff800013cb3ff0 x24: 0000000000000000\n x23: ffff80001142aa68 x22: ffff800011043d80 x21: ffff00010de46f20\n x20: ffff800013c0c520 x19: ffff800011d8f5b0 x18: 0000000000000010\n x17: 6e6968207473696c x16: 5f72656d6974203a x15: 6570797420746365\n x14: 6a626f2029302065 x13: 303378302f307830 x12: 2b6e665f72656d69\n x11: ffff8000124b1560 x10: ffff800012331520 x9 : ffff8000100ca6b0\n x8 : 000000000017ffe8 x7 : c0000000fffeffff x6 : 0000000000000001\n x5 : ffff800011d8c000 x4 : ffff800011d8c740 x3 : 0000000000000000\n x2 : ffff0001108301c0 x1 : ab3c90eedf9c0f00 x0 : 0000000000000000\n Call trace:\n debug_print_object+0xb8/0x100\n __debug_check_no_obj_freed+0x1c0/0x230\n debug_check_no_obj_freed+0x20/0x88\n slab_free_freelist_hook+0x154/0x1c8\n kfree+0x114/0x5d0\n sugov_exit+0xbc/0xc0\n cpufreq_exit_governor+0x44/0x90\n cpufreq_set_policy+0x268/0x4a8\n store_scaling_governor+0xe0/0x128\n store+0xc0/0xf0\n sysfs_kf_write+0x54/0x80\n kernfs_fop_write_iter+0x128/0x1c0\n new_sync_write+0xf0/0x190\n vfs_write+0x2d4/0x478\n ksys_write+0x74/0x100\n __arm64_sys_write+0x24/0x30\n invoke_syscall.constprop.0+0x54/0xe0\n do_el0_svc+0x64/0x158\n el0_svc+0x2c/0xb0\n el0t_64_sync_handler+0xb0/0xb8\n el0t_64_sync+0x198/0x19c\n irq event stamp: 5518\n hardirqs last enabled at (5517): [] console_unlock+0x554/0x6c8\n hardirqs last disabled at (5518): [] el1_dbg+0x28/0xa0\n softirqs last enabled at (5504): [] __do_softirq+0x4d0/0x6c0\n softirqs last disabled at (5483): [] irq_exit+0x1b0/0x1b8\n\nSo split the original sugov_tunables_free() into two functions,\nsugov_clear_global_tunables() is just used to clear the global_tunables\nand the new sugov_tunables_free() is used as kobj_type::release to\nrelease the sugov_tunables safely.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mwgq-3h9h-3q6g/GHSA-mwgq-3h9h-3q6g.json b/advisories/unreviewed/2024/05/GHSA-mwgq-3h9h-3q6g/GHSA-mwgq-3h9h-3q6g.json index 96632cffb53..e843da46226 100644 --- a/advisories/unreviewed/2024/05/GHSA-mwgq-3h9h-3q6g/GHSA-mwgq-3h9h-3q6g.json +++ b/advisories/unreviewed/2024/05/GHSA-mwgq-3h9h-3q6g/GHSA-mwgq-3h9h-3q6g.json @@ -7,12 +7,8 @@ "CVE-2023-52857" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: Fix coverity issue with unintentional integer overflow\n\n1. Instead of multiplying 2 variable of different types. Change to\nassign a value of one variable and then multiply the other variable.\n\n2. Add a int variable for multiplier calculation instead of calculating\ndifferent types multiplier with dma_addr_t variable directly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p4g6-hq7c-h438/GHSA-p4g6-hq7c-h438.json b/advisories/unreviewed/2024/05/GHSA-p4g6-hq7c-h438/GHSA-p4g6-hq7c-h438.json index c0efcef7a3c..71502ad591d 100644 --- a/advisories/unreviewed/2024/05/GHSA-p4g6-hq7c-h438/GHSA-p4g6-hq7c-h438.json +++ b/advisories/unreviewed/2024/05/GHSA-p4g6-hq7c-h438/GHSA-p4g6-hq7c-h438.json @@ -7,12 +7,8 @@ "CVE-2023-52745" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/IPoIB: Fix legacy IPoIB due to wrong number of queues\n\nThe cited commit creates child PKEY interfaces over netlink will\nmultiple tx and rx queues, but some devices doesn't support more than 1\ntx and 1 rx queues. This causes to a crash when traffic is sent over the\nPKEY interface due to the parent having a single queue but the child\nhaving multiple queues.\n\nThis patch fixes the number of queues to 1 for legacy IPoIB at the\nearliest possible point in time.\n\nBUG: kernel NULL pointer dereference, address: 000000000000036b\nPGD 0 P4D 0\nOops: 0000 [#1] SMP\nCPU: 4 PID: 209665 Comm: python3 Not tainted 6.1.0_for_upstream_min_debug_2022_12_12_17_02 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:kmem_cache_alloc+0xcb/0x450\nCode: ce 7e 49 8b 50 08 49 83 78 10 00 4d 8b 28 0f 84 cb 02 00 00 4d 85 ed 0f 84 c2 02 00 00 41 8b 44 24 28 48 8d 4a\n01 49 8b 3c 24 <49> 8b 5c 05 00 4c 89 e8 65 48 0f c7 0f 0f 94 c0 84 c0 74 b8 41 8b\nRSP: 0018:ffff88822acbbab8 EFLAGS: 00010202\nRAX: 0000000000000070 RBX: ffff8881c28e3e00 RCX: 00000000064f8dae\nRDX: 00000000064f8dad RSI: 0000000000000a20 RDI: 0000000000030d00\nRBP: 0000000000000a20 R08: ffff8882f5d30d00 R09: ffff888104032f40\nR10: ffff88810fade828 R11: 736f6d6570736575 R12: ffff88810081c000\nR13: 00000000000002fb R14: ffffffff817fc865 R15: 0000000000000000\nFS: 00007f9324ff9700(0000) GS:ffff8882f5d00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000000000036b CR3: 00000001125af004 CR4: 0000000000370ea0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n skb_clone+0x55/0xd0\n ip6_finish_output2+0x3fe/0x690\n ip6_finish_output+0xfa/0x310\n ip6_send_skb+0x1e/0x60\n udp_v6_send_skb+0x1e5/0x420\n udpv6_sendmsg+0xb3c/0xe60\n ? ip_mc_finish_output+0x180/0x180\n ? __switch_to_asm+0x3a/0x60\n ? __switch_to_asm+0x34/0x60\n sock_sendmsg+0x33/0x40\n __sys_sendto+0x103/0x160\n ? _copy_to_user+0x21/0x30\n ? kvm_clock_get_cycles+0xd/0x10\n ? ktime_get_ts64+0x49/0xe0\n __x64_sys_sendto+0x25/0x30\n do_syscall_64+0x3d/0x90\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\nRIP: 0033:0x7f9374f1ed14\nCode: 42 41 f8 ff 44 8b 4c 24 2c 4c 8b 44 24 20 89 c5 44 8b 54 24 28 48 8b 54 24 18 b8 2c 00 00 00 48 8b 74 24 10 8b\n7c 24 08 0f 05 <48> 3d 00 f0 ff ff 77 34 89 ef 48 89 44 24 08 e8 68 41 f8 ff 48 8b\nRSP: 002b:00007f9324ff7bd0 EFLAGS: 00000293 ORIG_RAX: 000000000000002c\nRAX: ffffffffffffffda RBX: 00007f9324ff7cc8 RCX: 00007f9374f1ed14\nRDX: 00000000000002fb RSI: 00007f93000052f0 RDI: 0000000000000030\nRBP: 0000000000000000 R08: 00007f9324ff7d40 R09: 000000000000001c\nR10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000000\nR13: 000000012a05f200 R14: 0000000000000001 R15: 00007f9374d57bdc\n ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pj5g-v5v3-3c22/GHSA-pj5g-v5v3-3c22.json b/advisories/unreviewed/2024/05/GHSA-pj5g-v5v3-3c22/GHSA-pj5g-v5v3-3c22.json index 95f16724646..5ff5ebd77e0 100644 --- a/advisories/unreviewed/2024/05/GHSA-pj5g-v5v3-3c22/GHSA-pj5g-v5v3-3c22.json +++ b/advisories/unreviewed/2024/05/GHSA-pj5g-v5v3-3c22/GHSA-pj5g-v5v3-3c22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-pmrx-2gv3-hv52/GHSA-pmrx-2gv3-hv52.json b/advisories/unreviewed/2024/05/GHSA-pmrx-2gv3-hv52/GHSA-pmrx-2gv3-hv52.json index 95020ecca31..2b1fe9d9010 100644 --- a/advisories/unreviewed/2024/05/GHSA-pmrx-2gv3-hv52/GHSA-pmrx-2gv3-hv52.json +++ b/advisories/unreviewed/2024/05/GHSA-pmrx-2gv3-hv52/GHSA-pmrx-2gv3-hv52.json @@ -7,12 +7,8 @@ "CVE-2021-47332" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usx2y: Don't call free_pages_exact() with NULL address\n\nUnlike some other functions, we can't pass NULL pointer to\nfree_pages_exact(). Add a proper NULL check for avoiding possible\nOops.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pqx6-2262-g74w/GHSA-pqx6-2262-g74w.json b/advisories/unreviewed/2024/05/GHSA-pqx6-2262-g74w/GHSA-pqx6-2262-g74w.json index 19389021bb0..fbfabb486fe 100644 --- a/advisories/unreviewed/2024/05/GHSA-pqx6-2262-g74w/GHSA-pqx6-2262-g74w.json +++ b/advisories/unreviewed/2024/05/GHSA-pqx6-2262-g74w/GHSA-pqx6-2262-g74w.json @@ -7,12 +7,8 @@ "CVE-2022-48708" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: single: fix potential NULL dereference\n\nAdded checking of pointer \"function\" in pcs_set_mux().\npinmux_generic_get_function() can return NULL and the pointer\n\"function\" was dereferenced without checking against NULL.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q44p-8h6w-57m6/GHSA-q44p-8h6w-57m6.json b/advisories/unreviewed/2024/05/GHSA-q44p-8h6w-57m6/GHSA-q44p-8h6w-57m6.json index 0db535af94e..9824dd7e97e 100644 --- a/advisories/unreviewed/2024/05/GHSA-q44p-8h6w-57m6/GHSA-q44p-8h6w-57m6.json +++ b/advisories/unreviewed/2024/05/GHSA-q44p-8h6w-57m6/GHSA-q44p-8h6w-57m6.json @@ -7,12 +7,8 @@ "CVE-2021-47388" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211: fix use-after-free in CCMP/GCMP RX\n\nWhen PN checking is done in mac80211, for fragmentation we need\nto copy the PN to the RX struct so we can later use it to do a\ncomparison, since commit bf30ca922a0c (\"mac80211: check defrag\nPN against current frame\").\n\nUnfortunately, in that commit I used the 'hdr' variable without\nit being necessarily valid, so use-after-free could occur if it\nwas necessary to reallocate (parts of) the frame.\n\nFix this by reloading the variable after the code that results\nin the reallocations, if any.\n\nThis fixes https://bugzilla.kernel.org/show_bug.cgi?id=214401.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q77h-85v7-m3mw/GHSA-q77h-85v7-m3mw.json b/advisories/unreviewed/2024/05/GHSA-q77h-85v7-m3mw/GHSA-q77h-85v7-m3mw.json index e70b8e081aa..cc77ee90830 100644 --- a/advisories/unreviewed/2024/05/GHSA-q77h-85v7-m3mw/GHSA-q77h-85v7-m3mw.json +++ b/advisories/unreviewed/2024/05/GHSA-q77h-85v7-m3mw/GHSA-q77h-85v7-m3mw.json @@ -7,12 +7,8 @@ "CVE-2021-47382" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/qeth: fix deadlock during failing recovery\n\nCommit 0b9902c1fcc5 (\"s390/qeth: fix deadlock during recovery\") removed\ntaking discipline_mutex inside qeth_do_reset(), fixing potential\ndeadlocks. An error path was missed though, that still takes\ndiscipline_mutex and thus has the original deadlock potential.\n\nIntermittent deadlocks were seen when a qeth channel path is configured\noffline, causing a race between qeth_do_reset and ccwgroup_remove.\nCall qeth_set_offline() directly in the qeth_do_reset() error case and\nthen a new variant of ccwgroup_set_offline(), without taking\ndiscipline_mutex.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qh8g-p933-67r9/GHSA-qh8g-p933-67r9.json b/advisories/unreviewed/2024/05/GHSA-qh8g-p933-67r9/GHSA-qh8g-p933-67r9.json index 1797eb3df37..50590730231 100644 --- a/advisories/unreviewed/2024/05/GHSA-qh8g-p933-67r9/GHSA-qh8g-p933-67r9.json +++ b/advisories/unreviewed/2024/05/GHSA-qh8g-p933-67r9/GHSA-qh8g-p933-67r9.json @@ -7,12 +7,8 @@ "CVE-2021-47398" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hfi1: Fix kernel pointer leak\n\nPointers should be printed with %p or %px rather than cast to 'unsigned\nlong long' and printed with %llx. Change %llx to %p to print the secured\npointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qj4q-cgq8-w2m4/GHSA-qj4q-cgq8-w2m4.json b/advisories/unreviewed/2024/05/GHSA-qj4q-cgq8-w2m4/GHSA-qj4q-cgq8-w2m4.json index 87957ce2c84..fada795a478 100644 --- a/advisories/unreviewed/2024/05/GHSA-qj4q-cgq8-w2m4/GHSA-qj4q-cgq8-w2m4.json +++ b/advisories/unreviewed/2024/05/GHSA-qj4q-cgq8-w2m4/GHSA-qj4q-cgq8-w2m4.json @@ -7,12 +7,8 @@ "CVE-2021-47413" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: chipidea: ci_hdrc_imx: Also search for 'phys' phandle\n\nWhen passing 'phys' in the devicetree to describe the USB PHY phandle\n(which is the recommended way according to\nDocumentation/devicetree/bindings/usb/ci-hdrc-usb2.txt) the\nfollowing NULL pointer dereference is observed on i.MX7 and i.MX8MM:\n\n[ 1.489344] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000098\n[ 1.498170] Mem abort info:\n[ 1.500966] ESR = 0x96000044\n[ 1.504030] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 1.509356] SET = 0, FnV = 0\n[ 1.512416] EA = 0, S1PTW = 0\n[ 1.515569] FSC = 0x04: level 0 translation fault\n[ 1.520458] Data abort info:\n[ 1.523349] ISV = 0, ISS = 0x00000044\n[ 1.527196] CM = 0, WnR = 1\n[ 1.530176] [0000000000000098] user address but active_mm is swapper\n[ 1.536544] Internal error: Oops: 96000044 [#1] PREEMPT SMP\n[ 1.542125] Modules linked in:\n[ 1.545190] CPU: 3 PID: 7 Comm: kworker/u8:0 Not tainted 5.14.0-dirty #3\n[ 1.551901] Hardware name: Kontron i.MX8MM N801X S (DT)\n[ 1.557133] Workqueue: events_unbound deferred_probe_work_func\n[ 1.562984] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO BTYPE=--)\n[ 1.568998] pc : imx7d_charger_detection+0x3f0/0x510\n[ 1.573973] lr : imx7d_charger_detection+0x22c/0x510\n\nThis happens because the charger functions check for the phy presence\ninside the imx_usbmisc_data structure (data->usb_phy), but the chipidea\ncore populates the usb_phy passed via 'phys' inside 'struct ci_hdrc'\n(ci->usb_phy) instead.\n\nThis causes the NULL pointer dereference inside imx7d_charger_detection().\n\nFix it by also searching for 'phys' in case 'fsl,usbphy' is not found.\n\nTested on a imx7s-warp board.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qm6m-jh59-wxwp/GHSA-qm6m-jh59-wxwp.json b/advisories/unreviewed/2024/05/GHSA-qm6m-jh59-wxwp/GHSA-qm6m-jh59-wxwp.json index 7ea3cb00529..e2d15a6fbaf 100644 --- a/advisories/unreviewed/2024/05/GHSA-qm6m-jh59-wxwp/GHSA-qm6m-jh59-wxwp.json +++ b/advisories/unreviewed/2024/05/GHSA-qm6m-jh59-wxwp/GHSA-qm6m-jh59-wxwp.json @@ -7,12 +7,8 @@ "CVE-2023-52749" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: Fix null dereference on suspend\n\nA race condition exists where a synchronous (noqueue) transfer can be\nactive during a system suspend. This can cause a null pointer\ndereference exception to occur when the system resumes.\n\nExample order of events leading to the exception:\n1. spi_sync() calls __spi_transfer_message_noqueue() which sets\n ctlr->cur_msg\n2. Spi transfer begins via spi_transfer_one_message()\n3. System is suspended interrupting the transfer context\n4. System is resumed\n6. spi_controller_resume() calls spi_start_queue() which resets cur_msg\n to NULL\n7. Spi transfer context resumes and spi_finalize_current_message() is\n called which dereferences cur_msg (which is now NULL)\n\nWait for synchronous transfers to complete before suspending by\nacquiring the bus mutex and setting/checking a suspend flag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qp48-7h94-95cp/GHSA-qp48-7h94-95cp.json b/advisories/unreviewed/2024/05/GHSA-qp48-7h94-95cp/GHSA-qp48-7h94-95cp.json index bb27a3165a9..2229e981510 100644 --- a/advisories/unreviewed/2024/05/GHSA-qp48-7h94-95cp/GHSA-qp48-7h94-95cp.json +++ b/advisories/unreviewed/2024/05/GHSA-qp48-7h94-95cp/GHSA-qp48-7h94-95cp.json @@ -7,12 +7,8 @@ "CVE-2023-52866" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: uclogic: Fix user-memory-access bug in uclogic_params_ugee_v2_init_event_hooks()\n\nWhen CONFIG_HID_UCLOGIC=y and CONFIG_KUNIT_ALL_TESTS=y, launch kernel and\nthen the below user-memory-access bug occurs.\n\nIn hid_test_uclogic_params_cleanup_event_hooks(),it call\nuclogic_params_ugee_v2_init_event_hooks() with the first arg=NULL, so\nwhen it calls uclogic_params_ugee_v2_has_battery(), the hid_get_drvdata()\nwill access hdev->dev with hdev=NULL, which will cause below\nuser-memory-access.\n\nSo add a fake_device with quirks member and call hid_set_drvdata()\nto assign hdev->dev->driver_data which avoids the null-ptr-def bug\nfor drvdata->quirks in uclogic_params_ugee_v2_has_battery(). After applying\nthis patch, the below user-memory-access bug never occurs.\n\n general protection fault, probably for non-canonical address 0xdffffc0000000329: 0000 [#1] PREEMPT SMP KASAN\n KASAN: probably user-memory-access in range [0x0000000000001948-0x000000000000194f]\n CPU: 5 PID: 2189 Comm: kunit_try_catch Tainted: G B W N 6.6.0-rc2+ #30\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:uclogic_params_ugee_v2_init_event_hooks+0x87/0x600\n Code: f3 f3 65 48 8b 14 25 28 00 00 00 48 89 54 24 60 31 d2 48 89 fa c7 44 24 30 00 00 00 00 48 c7 44 24 28 02 f8 02 01 48 c1 ea 03 <80> 3c 02 00 0f 85 2c 04 00 00 48 8b 9d 48 19 00 00 48 b8 00 00 00\n RSP: 0000:ffff88810679fc88 EFLAGS: 00010202\n RAX: dffffc0000000000 RBX: 0000000000000004 RCX: 0000000000000000\n RDX: 0000000000000329 RSI: ffff88810679fd88 RDI: 0000000000001948\n RBP: 0000000000000000 R08: 0000000000000000 R09: ffffed1020f639f0\n R10: ffff888107b1cf87 R11: 0000000000000400 R12: 1ffff11020cf3f92\n R13: ffff88810679fd88 R14: ffff888100b97b08 R15: ffff8881030bb080\n FS: 0000000000000000(0000) GS:ffff888119e80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 0000000005286001 CR4: 0000000000770ee0\n DR0: ffffffff8fdd6cf4 DR1: ffffffff8fdd6cf5 DR2: ffffffff8fdd6cf6\n DR3: ffffffff8fdd6cf7 DR6: 00000000fffe0ff0 DR7: 0000000000000600\n PKRU: 55555554\n Call Trace:\n \n ? die_addr+0x3d/0xa0\n ? exc_general_protection+0x144/0x220\n ? asm_exc_general_protection+0x22/0x30\n ? uclogic_params_ugee_v2_init_event_hooks+0x87/0x600\n ? sched_clock_cpu+0x69/0x550\n ? uclogic_parse_ugee_v2_desc_gen_params+0x70/0x70\n ? load_balance+0x2950/0x2950\n ? rcu_trc_cmpxchg_need_qs+0x67/0xa0\n hid_test_uclogic_params_cleanup_event_hooks+0x9e/0x1a0\n ? uclogic_params_ugee_v2_init_event_hooks+0x600/0x600\n ? __switch_to+0x5cf/0xe60\n ? migrate_enable+0x260/0x260\n ? __kthread_parkme+0x83/0x150\n ? kunit_try_run_case_cleanup+0xe0/0xe0\n kunit_generic_run_threadfn_adapter+0x4a/0x90\n ? kunit_try_catch_throw+0x80/0x80\n kthread+0x2b5/0x380\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x2d/0x70\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork_asm+0x11/0x20\n \n Modules linked in:\n Dumping ftrace buffer:\n (ftrace buffer empty)\n ---[ end trace 0000000000000000 ]---\n RIP: 0010:uclogic_params_ugee_v2_init_event_hooks+0x87/0x600\n Code: f3 f3 65 48 8b 14 25 28 00 00 00 48 89 54 24 60 31 d2 48 89 fa c7 44 24 30 00 00 00 00 48 c7 44 24 28 02 f8 02 01 48 c1 ea 03 <80> 3c 02 00 0f 85 2c 04 00 00 48 8b 9d 48 19 00 00 48 b8 00 00 00\n RSP: 0000:ffff88810679fc88 EFLAGS: 00010202\n RAX: dffffc0000000000 RBX: 0000000000000004 RCX: 0000000000000000\n RDX: 0000000000000329 RSI: ffff88810679fd88 RDI: 0000000000001948\n RBP: 0000000000000000 R08: 0000000000000000 R09: ffffed1020f639f0\n R10: ffff888107b1cf87 R11: 0000000000000400 R12: 1ffff11020cf3f92\n R13: ffff88810679fd88 R14: ffff888100b97b08 R15: ffff8881030bb080\n FS: 0000000000000000(0000) GS:ffff888119e80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 0000000005286001 CR4: 0000000000770ee0\n DR0: ffffffff8fdd6cf4 DR1: \n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qp63-w47q-g9vj/GHSA-qp63-w47q-g9vj.json b/advisories/unreviewed/2024/05/GHSA-qp63-w47q-g9vj/GHSA-qp63-w47q-g9vj.json index b227b66f121..2e15845f529 100644 --- a/advisories/unreviewed/2024/05/GHSA-qp63-w47q-g9vj/GHSA-qp63-w47q-g9vj.json +++ b/advisories/unreviewed/2024/05/GHSA-qp63-w47q-g9vj/GHSA-qp63-w47q-g9vj.json @@ -7,12 +7,8 @@ "CVE-2021-47269" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: ep0: fix NULL pointer exception\n\nThere is no validation of the index from dwc3_wIndex_to_dep() and we might\nbe referring a non-existing ep and trigger a NULL pointer exception. In\ncertain configurations we might use fewer eps and the index might wrongly\nindicate a larger ep index than existing.\n\nBy adding this validation from the patch we can actually report a wrong\nindex back to the caller.\n\nIn our usecase we are using a composite device on an older kernel, but\nupstream might use this fix also. Unfortunately, I cannot describe the\nhardware for others to reproduce the issue as it is a proprietary\nimplementation.\n\n[ 82.958261] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a4\n[ 82.966891] Mem abort info:\n[ 82.969663] ESR = 0x96000006\n[ 82.972703] Exception class = DABT (current EL), IL = 32 bits\n[ 82.978603] SET = 0, FnV = 0\n[ 82.981642] EA = 0, S1PTW = 0\n[ 82.984765] Data abort info:\n[ 82.987631] ISV = 0, ISS = 0x00000006\n[ 82.991449] CM = 0, WnR = 0\n[ 82.994409] user pgtable: 4k pages, 39-bit VAs, pgdp = 00000000c6210ccc\n[ 83.000999] [00000000000000a4] pgd=0000000053aa5003, pud=0000000053aa5003, pmd=0000000000000000\n[ 83.009685] Internal error: Oops: 96000006 [#1] PREEMPT SMP\n[ 83.026433] Process irq/62-dwc3 (pid: 303, stack limit = 0x000000003985154c)\n[ 83.033470] CPU: 0 PID: 303 Comm: irq/62-dwc3 Not tainted 4.19.124 #1\n[ 83.044836] pstate: 60000085 (nZCv daIf -PAN -UAO)\n[ 83.049628] pc : dwc3_ep0_handle_feature+0x414/0x43c\n[ 83.054558] lr : dwc3_ep0_interrupt+0x3b4/0xc94\n\n...\n\n[ 83.141788] Call trace:\n[ 83.144227] dwc3_ep0_handle_feature+0x414/0x43c\n[ 83.148823] dwc3_ep0_interrupt+0x3b4/0xc94\n[ 83.181546] ---[ end trace aac6b5267d84c32f ]---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qwvj-ww5h-jh39/GHSA-qwvj-ww5h-jh39.json b/advisories/unreviewed/2024/05/GHSA-qwvj-ww5h-jh39/GHSA-qwvj-ww5h-jh39.json index b886fc99fb6..4400f646dc6 100644 --- a/advisories/unreviewed/2024/05/GHSA-qwvj-ww5h-jh39/GHSA-qwvj-ww5h-jh39.json +++ b/advisories/unreviewed/2024/05/GHSA-qwvj-ww5h-jh39/GHSA-qwvj-ww5h-jh39.json @@ -7,12 +7,8 @@ "CVE-2023-52813" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: pcrypt - Fix hungtask for PADATA_RESET\n\nWe found a hungtask bug in test_aead_vec_cfg as follows:\n\nINFO: task cryptomgr_test:391009 blocked for more than 120 seconds.\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\nCall trace:\n __switch_to+0x98/0xe0\n __schedule+0x6c4/0xf40\n schedule+0xd8/0x1b4\n schedule_timeout+0x474/0x560\n wait_for_common+0x368/0x4e0\n wait_for_completion+0x20/0x30\n wait_for_completion+0x20/0x30\n test_aead_vec_cfg+0xab4/0xd50\n test_aead+0x144/0x1f0\n alg_test_aead+0xd8/0x1e0\n alg_test+0x634/0x890\n cryptomgr_test+0x40/0x70\n kthread+0x1e0/0x220\n ret_from_fork+0x10/0x18\n Kernel panic - not syncing: hung_task: blocked tasks\n\nFor padata_do_parallel, when the return err is 0 or -EBUSY, it will call\nwait_for_completion(&wait->completion) in test_aead_vec_cfg. In normal\ncase, aead_request_complete() will be called in pcrypt_aead_serial and the\nreturn err is 0 for padata_do_parallel. But, when pinst->flags is\nPADATA_RESET, the return err is -EBUSY for padata_do_parallel, and it\nwon't call aead_request_complete(). Therefore, test_aead_vec_cfg will\nhung at wait_for_completion(&wait->completion), which will cause\nhungtask.\n\nThe problem comes as following:\n(padata_do_parallel) |\n rcu_read_lock_bh(); |\n err = -EINVAL; | (padata_replace)\n | pinst->flags |= PADATA_RESET;\n err = -EBUSY |\n if (pinst->flags & PADATA_RESET) |\n rcu_read_unlock_bh() |\n return err\n\nIn order to resolve the problem, we replace the return err -EBUSY with\n-EAGAIN, which means parallel_data is changing, and the caller should call\nit again.\n\nv3:\nremove retry and just change the return err.\nv2:\nintroduce padata_try_do_parallel() in pcrypt_aead_encrypt and\npcrypt_aead_decrypt to solve the hungtask.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-r2r3-fm28-9g3h/GHSA-r2r3-fm28-9g3h.json b/advisories/unreviewed/2024/05/GHSA-r2r3-fm28-9g3h/GHSA-r2r3-fm28-9g3h.json index 7449238d916..7fd8b056f8e 100644 --- a/advisories/unreviewed/2024/05/GHSA-r2r3-fm28-9g3h/GHSA-r2r3-fm28-9g3h.json +++ b/advisories/unreviewed/2024/05/GHSA-r2r3-fm28-9g3h/GHSA-r2r3-fm28-9g3h.json @@ -7,12 +7,8 @@ "CVE-2021-47390" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Fix stack-out-of-bounds memory access from ioapic_write_indirect()\n\nKASAN reports the following issue:\n\n BUG: KASAN: stack-out-of-bounds in kvm_make_vcpus_request_mask+0x174/0x440 [kvm]\n Read of size 8 at addr ffffc9001364f638 by task qemu-kvm/4798\n\n CPU: 0 PID: 4798 Comm: qemu-kvm Tainted: G X --------- ---\n Hardware name: AMD Corporation DAYTONA_X/DAYTONA_X, BIOS RYM0081C 07/13/2020\n Call Trace:\n dump_stack+0xa5/0xe6\n print_address_description.constprop.0+0x18/0x130\n ? kvm_make_vcpus_request_mask+0x174/0x440 [kvm]\n __kasan_report.cold+0x7f/0x114\n ? kvm_make_vcpus_request_mask+0x174/0x440 [kvm]\n kasan_report+0x38/0x50\n kasan_check_range+0xf5/0x1d0\n kvm_make_vcpus_request_mask+0x174/0x440 [kvm]\n kvm_make_scan_ioapic_request_mask+0x84/0xc0 [kvm]\n ? kvm_arch_exit+0x110/0x110 [kvm]\n ? sched_clock+0x5/0x10\n ioapic_write_indirect+0x59f/0x9e0 [kvm]\n ? static_obj+0xc0/0xc0\n ? __lock_acquired+0x1d2/0x8c0\n ? kvm_ioapic_eoi_inject_work+0x120/0x120 [kvm]\n\nThe problem appears to be that 'vcpu_bitmap' is allocated as a single long\non stack and it should really be KVM_MAX_VCPUS long. We also seem to clear\nthe lower 16 bits of it with bitmap_zero() for no particular reason (my\nguess would be that 'bitmap' and 'vcpu_bitmap' variables in\nkvm_bitmap_or_dest_vcpus() caused the confusion: while the later is indeed\n16-bit long, the later should accommodate all possible vCPUs).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rgj4-j68m-986v/GHSA-rgj4-j68m-986v.json b/advisories/unreviewed/2024/05/GHSA-rgj4-j68m-986v/GHSA-rgj4-j68m-986v.json index a8267b0201c..dc7a106c279 100644 --- a/advisories/unreviewed/2024/05/GHSA-rgj4-j68m-986v/GHSA-rgj4-j68m-986v.json +++ b/advisories/unreviewed/2024/05/GHSA-rgj4-j68m-986v/GHSA-rgj4-j68m-986v.json @@ -7,12 +7,8 @@ "CVE-2021-47276" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Do not blindly read the ip address in ftrace_bug()\n\nIt was reported that a bug on arm64 caused a bad ip address to be used for\nupdating into a nop in ftrace_init(), but the error path (rightfully)\nreturned -EINVAL and not -EFAULT, as the bug caused more than one error to\noccur. But because -EINVAL was returned, the ftrace_bug() tried to report\nwhat was at the location of the ip address, and read it directly. This\ncaused the machine to panic, as the ip was not pointing to a valid memory\naddress.\n\nInstead, read the ip address with copy_from_kernel_nofault() to safely\naccess the memory, and if it faults, report that the address faulted,\notherwise report what was in that location.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rx7p-m6c3-777g/GHSA-rx7p-m6c3-777g.json b/advisories/unreviewed/2024/05/GHSA-rx7p-m6c3-777g/GHSA-rx7p-m6c3-777g.json index 440fbde1e73..7068df39b4b 100644 --- a/advisories/unreviewed/2024/05/GHSA-rx7p-m6c3-777g/GHSA-rx7p-m6c3-777g.json +++ b/advisories/unreviewed/2024/05/GHSA-rx7p-m6c3-777g/GHSA-rx7p-m6c3-777g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-rxcf-2w24-j9pq/GHSA-rxcf-2w24-j9pq.json b/advisories/unreviewed/2024/05/GHSA-rxcf-2w24-j9pq/GHSA-rxcf-2w24-j9pq.json index 64d15a79b58..1933482068c 100644 --- a/advisories/unreviewed/2024/05/GHSA-rxcf-2w24-j9pq/GHSA-rxcf-2w24-j9pq.json +++ b/advisories/unreviewed/2024/05/GHSA-rxcf-2w24-j9pq/GHSA-rxcf-2w24-j9pq.json @@ -7,12 +7,8 @@ "CVE-2021-47427" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: iscsi: Fix iscsi_task use after free\n\nCommit d39df158518c (\"scsi: iscsi: Have abort handler get ref to conn\")\nadded iscsi_get_conn()/iscsi_put_conn() calls during abort handling but\nthen also changed the handling of the case where we detect an already\ncompleted task where we now end up doing a goto to the common put/cleanup\ncode. This results in a iscsi_task use after free, because the common\ncleanup code will do a put on the iscsi_task.\n\nThis reverts the goto and moves the iscsi_get_conn() to after we've checked\nif the iscsi_task is valid.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-v8p3-mfrc-9v8j/GHSA-v8p3-mfrc-9v8j.json b/advisories/unreviewed/2024/05/GHSA-v8p3-mfrc-9v8j/GHSA-v8p3-mfrc-9v8j.json index 759437812bd..b4006256a97 100644 --- a/advisories/unreviewed/2024/05/GHSA-v8p3-mfrc-9v8j/GHSA-v8p3-mfrc-9v8j.json +++ b/advisories/unreviewed/2024/05/GHSA-v8p3-mfrc-9v8j/GHSA-v8p3-mfrc-9v8j.json @@ -7,12 +7,8 @@ "CVE-2021-47397" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: break out if skb_header_pointer returns NULL in sctp_rcv_ootb\n\nWe should always check if skb_header_pointer's return is NULL before\nusing it, otherwise it may cause null-ptr-deref, as syzbot reported:\n\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n RIP: 0010:sctp_rcv_ootb net/sctp/input.c:705 [inline]\n RIP: 0010:sctp_rcv+0x1d84/0x3220 net/sctp/input.c:196\n Call Trace:\n \n sctp6_rcv+0x38/0x60 net/sctp/ipv6.c:1109\n ip6_protocol_deliver_rcu+0x2e9/0x1ca0 net/ipv6/ip6_input.c:422\n ip6_input_finish+0x62/0x170 net/ipv6/ip6_input.c:463\n NF_HOOK include/linux/netfilter.h:307 [inline]\n NF_HOOK include/linux/netfilter.h:301 [inline]\n ip6_input+0x9c/0xd0 net/ipv6/ip6_input.c:472\n dst_input include/net/dst.h:460 [inline]\n ip6_rcv_finish net/ipv6/ip6_input.c:76 [inline]\n NF_HOOK include/linux/netfilter.h:307 [inline]\n NF_HOOK include/linux/netfilter.h:301 [inline]\n ipv6_rcv+0x28c/0x3c0 net/ipv6/ip6_input.c:297", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vcc4-4xc8-8rmc/GHSA-vcc4-4xc8-8rmc.json b/advisories/unreviewed/2024/05/GHSA-vcc4-4xc8-8rmc/GHSA-vcc4-4xc8-8rmc.json index 698365b8dfb..f43fa91160e 100644 --- a/advisories/unreviewed/2024/05/GHSA-vcc4-4xc8-8rmc/GHSA-vcc4-4xc8-8rmc.json +++ b/advisories/unreviewed/2024/05/GHSA-vcc4-4xc8-8rmc/GHSA-vcc4-4xc8-8rmc.json @@ -7,12 +7,8 @@ "CVE-2023-52748" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: avoid format-overflow warning\n\nWith gcc and W=1 option, there's a warning like this:\n\nfs/f2fs/compress.c: In function ‘f2fs_init_page_array_cache’:\nfs/f2fs/compress.c:1984:47: error: ‘%u’ directive writing between\n1 and 7 bytes into a region of size between 5 and 8\n[-Werror=format-overflow=]\n 1984 | sprintf(slab_name, \"f2fs_page_array_entry-%u:%u\", MAJOR(dev),\n\t\tMINOR(dev));\n | ^~\n\nString \"f2fs_page_array_entry-%u:%u\" can up to 35. The first \"%u\" can up\nto 4 and the second \"%u\" can up to 7, so total size is \"24 + 4 + 7 = 35\".\nslab_name's size should be 35 rather than 32.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vr35-f6m3-rh89/GHSA-vr35-f6m3-rh89.json b/advisories/unreviewed/2024/05/GHSA-vr35-f6m3-rh89/GHSA-vr35-f6m3-rh89.json index 99f6c957576..e23d8e91772 100644 --- a/advisories/unreviewed/2024/05/GHSA-vr35-f6m3-rh89/GHSA-vr35-f6m3-rh89.json +++ b/advisories/unreviewed/2024/05/GHSA-vr35-f6m3-rh89/GHSA-vr35-f6m3-rh89.json @@ -7,12 +7,8 @@ "CVE-2023-52767" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix NULL deref on tls_sw_splice_eof() with empty record\n\nsyzkaller discovered that if tls_sw_splice_eof() is executed as part of\nsendfile() when the plaintext/ciphertext sk_msg are empty, the send path\ngets confused because the empty ciphertext buffer does not have enough\nspace for the encryption overhead. This causes tls_push_record() to go on\nthe `split = true` path (which is only supposed to be used when interacting\nwith an attached BPF program), and then get further confused and hit the\ntls_merge_open_record() path, which then assumes that there must be at\nleast one populated buffer element, leading to a NULL deref.\n\nIt is possible to have empty plaintext/ciphertext buffers if we previously\nbailed from tls_sw_sendmsg_locked() via the tls_trim_both_msgs() path.\ntls_sw_push_pending_record() already handles this case correctly; let's do\nthe same check in tls_sw_splice_eof().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vrmw-4324-6mfp/GHSA-vrmw-4324-6mfp.json b/advisories/unreviewed/2024/05/GHSA-vrmw-4324-6mfp/GHSA-vrmw-4324-6mfp.json index b64186871d4..e9edcae968a 100644 --- a/advisories/unreviewed/2024/05/GHSA-vrmw-4324-6mfp/GHSA-vrmw-4324-6mfp.json +++ b/advisories/unreviewed/2024/05/GHSA-vrmw-4324-6mfp/GHSA-vrmw-4324-6mfp.json @@ -7,12 +7,8 @@ "CVE-2023-52770" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: split initial and dynamic conditions for extent_cache\n\nLet's allocate the extent_cache tree without dynamic conditions to avoid a\nmissing condition causing a panic as below.\n\n # create a file w/ a compressed flag\n # disable the compression\n # panic while updating extent_cache\n\nF2FS-fs (dm-64): Swapfile: last extent is not aligned to section\nF2FS-fs (dm-64): Swapfile (3) is not align to section: 1) creat(), 2) ioctl(F2FS_IOC_SET_PIN_FILE), 3) fallocate(2097152 * N)\nAdding 124996k swap on ./swap-file. Priority:0 extents:2 across:17179494468k\n==================================================================\nBUG: KASAN: null-ptr-deref in instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline]\nBUG: KASAN: null-ptr-deref in atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline]\nBUG: KASAN: null-ptr-deref in queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline]\nBUG: KASAN: null-ptr-deref in __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline]\nBUG: KASAN: null-ptr-deref in _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295\nWrite of size 4 at addr 0000000000000030 by task syz-executor154/3327\n\nCPU: 0 PID: 3327 Comm: syz-executor154 Tainted: G O 5.10.185 #1\nHardware name: emulation qemu-x86/qemu-x86, BIOS 2023.01-21885-gb3cc1cd24d 01/01/2023\nCall Trace:\n __dump_stack out/common/lib/dump_stack.c:77 [inline]\n dump_stack_lvl+0x17e/0x1c4 out/common/lib/dump_stack.c:118\n __kasan_report+0x16c/0x260 out/common/mm/kasan/report.c:415\n kasan_report+0x51/0x70 out/common/mm/kasan/report.c:428\n kasan_check_range+0x2f3/0x340 out/common/mm/kasan/generic.c:186\n __kasan_check_write+0x14/0x20 out/common/mm/kasan/shadow.c:37\n instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline]\n atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline]\n queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline]\n __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline]\n _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295\n __drop_extent_tree+0xdf/0x2f0 out/common/fs/f2fs/extent_cache.c:1155\n f2fs_drop_extent_tree+0x17/0x30 out/common/fs/f2fs/extent_cache.c:1172\n f2fs_insert_range out/common/fs/f2fs/file.c:1600 [inline]\n f2fs_fallocate+0x19fd/0x1f40 out/common/fs/f2fs/file.c:1764\n vfs_fallocate+0x514/0x9b0 out/common/fs/open.c:310\n ksys_fallocate out/common/fs/open.c:333 [inline]\n __do_sys_fallocate out/common/fs/open.c:341 [inline]\n __se_sys_fallocate out/common/fs/open.c:339 [inline]\n __x64_sys_fallocate+0xb8/0x100 out/common/fs/open.c:339\n do_syscall_64+0x35/0x50 out/common/arch/x86/entry/common.c:46", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w33v-fh8v-9mhx/GHSA-w33v-fh8v-9mhx.json b/advisories/unreviewed/2024/05/GHSA-w33v-fh8v-9mhx/GHSA-w33v-fh8v-9mhx.json index 4afa4be5421..fc7b8e46caa 100644 --- a/advisories/unreviewed/2024/05/GHSA-w33v-fh8v-9mhx/GHSA-w33v-fh8v-9mhx.json +++ b/advisories/unreviewed/2024/05/GHSA-w33v-fh8v-9mhx/GHSA-w33v-fh8v-9mhx.json @@ -7,12 +7,8 @@ "CVE-2023-52864" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: wmi: Fix opening of char device\n\nSince commit fa1f68db6ca7 (\"drivers: misc: pass miscdevice pointer via\nfile private data\"), the miscdevice stores a pointer to itself inside\nfilp->private_data, which means that private_data will not be NULL when\nwmi_char_open() is called. This might cause memory corruption should\nwmi_char_open() be unable to find its driver, something which can\nhappen when the associated WMI device is deleted in wmi_free_devices().\n\nFix the problem by using the miscdevice pointer to retrieve the WMI\ndevice data associated with a char device using container_of(). This\nalso avoids wmi_char_open() picking a wrong WMI device bound to a\ndriver with the same name as the original driver.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w492-g7j4-gr3w/GHSA-w492-g7j4-gr3w.json b/advisories/unreviewed/2024/05/GHSA-w492-g7j4-gr3w/GHSA-w492-g7j4-gr3w.json index 07034a003cb..a3a03872899 100644 --- a/advisories/unreviewed/2024/05/GHSA-w492-g7j4-gr3w/GHSA-w492-g7j4-gr3w.json +++ b/advisories/unreviewed/2024/05/GHSA-w492-g7j4-gr3w/GHSA-w492-g7j4-gr3w.json @@ -7,12 +7,8 @@ "CVE-2023-52871" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: llcc: Handle a second device without data corruption\n\nUsually there is only one llcc device. But if there were a second, even\na failed probe call would modify the global drv_data pointer. So check\nif drv_data is valid before overwriting it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-w9cr-rpv2-57qv/GHSA-w9cr-rpv2-57qv.json b/advisories/unreviewed/2024/05/GHSA-w9cr-rpv2-57qv/GHSA-w9cr-rpv2-57qv.json index e8a9730dbfb..0e19bb63377 100644 --- a/advisories/unreviewed/2024/05/GHSA-w9cr-rpv2-57qv/GHSA-w9cr-rpv2-57qv.json +++ b/advisories/unreviewed/2024/05/GHSA-w9cr-rpv2-57qv/GHSA-w9cr-rpv2-57qv.json @@ -7,12 +7,8 @@ "CVE-2021-47379" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: fix UAF by grabbing blkcg lock before destroying blkg pd\n\nKASAN reports a use-after-free report when doing fuzz test:\n\n[693354.104835] ==================================================================\n[693354.105094] BUG: KASAN: use-after-free in bfq_io_set_weight_legacy+0xd3/0x160\n[693354.105336] Read of size 4 at addr ffff888be0a35664 by task sh/1453338\n\n[693354.105607] CPU: 41 PID: 1453338 Comm: sh Kdump: loaded Not tainted 4.18.0-147\n[693354.105610] Hardware name: Huawei 2288H V5/BC11SPSCB0, BIOS 0.81 07/02/2018\n[693354.105612] Call Trace:\n[693354.105621] dump_stack+0xf1/0x19b\n[693354.105626] ? show_regs_print_info+0x5/0x5\n[693354.105634] ? printk+0x9c/0xc3\n[693354.105638] ? cpumask_weight+0x1f/0x1f\n[693354.105648] print_address_description+0x70/0x360\n[693354.105654] kasan_report+0x1b2/0x330\n[693354.105659] ? bfq_io_set_weight_legacy+0xd3/0x160\n[693354.105665] ? bfq_io_set_weight_legacy+0xd3/0x160\n[693354.105670] bfq_io_set_weight_legacy+0xd3/0x160\n[693354.105675] ? bfq_cpd_init+0x20/0x20\n[693354.105683] cgroup_file_write+0x3aa/0x510\n[693354.105693] ? ___slab_alloc+0x507/0x540\n[693354.105698] ? cgroup_file_poll+0x60/0x60\n[693354.105702] ? 0xffffffff89600000\n[693354.105708] ? usercopy_abort+0x90/0x90\n[693354.105716] ? mutex_lock+0xef/0x180\n[693354.105726] kernfs_fop_write+0x1ab/0x280\n[693354.105732] ? cgroup_file_poll+0x60/0x60\n[693354.105738] vfs_write+0xe7/0x230\n[693354.105744] ksys_write+0xb0/0x140\n[693354.105749] ? __ia32_sys_read+0x50/0x50\n[693354.105760] do_syscall_64+0x112/0x370\n[693354.105766] ? syscall_return_slowpath+0x260/0x260\n[693354.105772] ? do_page_fault+0x9b/0x270\n[693354.105779] ? prepare_exit_to_usermode+0xf9/0x1a0\n[693354.105784] ? enter_from_user_mode+0x30/0x30\n[693354.105793] entry_SYSCALL_64_after_hwframe+0x65/0xca\n\n[693354.105875] Allocated by task 1453337:\n[693354.106001] kasan_kmalloc+0xa0/0xd0\n[693354.106006] kmem_cache_alloc_node_trace+0x108/0x220\n[693354.106010] bfq_pd_alloc+0x96/0x120\n[693354.106015] blkcg_activate_policy+0x1b7/0x2b0\n[693354.106020] bfq_create_group_hierarchy+0x1e/0x80\n[693354.106026] bfq_init_queue+0x678/0x8c0\n[693354.106031] blk_mq_init_sched+0x1f8/0x460\n[693354.106037] elevator_switch_mq+0xe1/0x240\n[693354.106041] elevator_switch+0x25/0x40\n[693354.106045] elv_iosched_store+0x1a1/0x230\n[693354.106049] queue_attr_store+0x78/0xb0\n[693354.106053] kernfs_fop_write+0x1ab/0x280\n[693354.106056] vfs_write+0xe7/0x230\n[693354.106060] ksys_write+0xb0/0x140\n[693354.106064] do_syscall_64+0x112/0x370\n[693354.106069] entry_SYSCALL_64_after_hwframe+0x65/0xca\n\n[693354.106114] Freed by task 1453336:\n[693354.106225] __kasan_slab_free+0x130/0x180\n[693354.106229] kfree+0x90/0x1b0\n[693354.106233] blkcg_deactivate_policy+0x12c/0x220\n[693354.106238] bfq_exit_queue+0xf5/0x110\n[693354.106241] blk_mq_exit_sched+0x104/0x130\n[693354.106245] __elevator_exit+0x45/0x60\n[693354.106249] elevator_switch_mq+0xd6/0x240\n[693354.106253] elevator_switch+0x25/0x40\n[693354.106257] elv_iosched_store+0x1a1/0x230\n[693354.106261] queue_attr_store+0x78/0xb0\n[693354.106264] kernfs_fop_write+0x1ab/0x280\n[693354.106268] vfs_write+0xe7/0x230\n[693354.106271] ksys_write+0xb0/0x140\n[693354.106275] do_syscall_64+0x112/0x370\n[693354.106280] entry_SYSCALL_64_after_hwframe+0x65/0xca\n\n[693354.106329] The buggy address belongs to the object at ffff888be0a35580\n which belongs to the cache kmalloc-1k of size 1024\n[693354.106736] The buggy address is located 228 bytes inside of\n 1024-byte region [ffff888be0a35580, ffff888be0a35980)\n[693354.107114] The buggy address belongs to the page:\n[693354.107273] page:ffffea002f828c00 count:1 mapcount:0 mapping:ffff888107c17080 index:0x0 compound_mapcount: 0\n[693354.107606] flags: 0x17ffffc0008100(slab|head)\n[693354.107760] raw: 0017ffffc0008100 ffffea002fcbc808 ffffea0030bd3a08 ffff888107c17080\n[693354.108020] r\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-whrp-vxvh-9rj2/GHSA-whrp-vxvh-9rj2.json b/advisories/unreviewed/2024/05/GHSA-whrp-vxvh-9rj2/GHSA-whrp-vxvh-9rj2.json index f5da1d4679a..7c0e873523d 100644 --- a/advisories/unreviewed/2024/05/GHSA-whrp-vxvh-9rj2/GHSA-whrp-vxvh-9rj2.json +++ b/advisories/unreviewed/2024/05/GHSA-whrp-vxvh-9rj2/GHSA-whrp-vxvh-9rj2.json @@ -7,12 +7,8 @@ "CVE-2021-47414" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Flush current cpu icache before other cpus\n\nOn SiFive Unmatched, I recently fell onto the following BUG when booting:\n\n[ 0.000000] ftrace: allocating 36610 entries in 144 pages\n[ 0.000000] Oops - illegal instruction [#1]\n[ 0.000000] Modules linked in:\n[ 0.000000] CPU: 0 PID: 0 Comm: swapper Not tainted 5.13.1+ #5\n[ 0.000000] Hardware name: SiFive HiFive Unmatched A00 (DT)\n[ 0.000000] epc : riscv_cpuid_to_hartid_mask+0x6/0xae\n[ 0.000000] ra : __sbi_rfence_v02+0xc8/0x10a\n[ 0.000000] epc : ffffffff80007240 ra : ffffffff80009964 sp : ffffffff81803e10\n[ 0.000000] gp : ffffffff81a1ea70 tp : ffffffff8180f500 t0 : ffffffe07fe30000\n[ 0.000000] t1 : 0000000000000004 t2 : 0000000000000000 s0 : ffffffff81803e60\n[ 0.000000] s1 : 0000000000000000 a0 : ffffffff81a22238 a1 : ffffffff81803e10\n[ 0.000000] a2 : 0000000000000000 a3 : 0000000000000000 a4 : 0000000000000000\n[ 0.000000] a5 : 0000000000000000 a6 : ffffffff8000989c a7 : 0000000052464e43\n[ 0.000000] s2 : ffffffff81a220c8 s3 : 0000000000000000 s4 : 0000000000000000\n[ 0.000000] s5 : 0000000000000000 s6 : 0000000200000100 s7 : 0000000000000001\n[ 0.000000] s8 : ffffffe07fe04040 s9 : ffffffff81a22c80 s10: 0000000000001000\n[ 0.000000] s11: 0000000000000004 t3 : 0000000000000001 t4 : 0000000000000008\n[ 0.000000] t5 : ffffffcf04000808 t6 : ffffffe3ffddf188\n[ 0.000000] status: 0000000200000100 badaddr: 0000000000000000 cause: 0000000000000002\n[ 0.000000] [] riscv_cpuid_to_hartid_mask+0x6/0xae\n[ 0.000000] [] sbi_remote_fence_i+0x1e/0x26\n[ 0.000000] [] flush_icache_all+0x12/0x1a\n[ 0.000000] [] patch_text_nosync+0x26/0x32\n[ 0.000000] [] ftrace_init_nop+0x52/0x8c\n[ 0.000000] [] ftrace_process_locs.isra.0+0x29c/0x360\n[ 0.000000] [] ftrace_init+0x80/0x130\n[ 0.000000] [] start_kernel+0x5c4/0x8f6\n[ 0.000000] ---[ end trace f67eb9af4d8d492b ]---\n[ 0.000000] Kernel panic - not syncing: Attempted to kill the idle task!\n[ 0.000000] ---[ end Kernel panic - not syncing: Attempted to kill the idle task! ]---\n\nWhile ftrace is looping over a list of addresses to patch, it always failed\nwhen patching the same function: riscv_cpuid_to_hartid_mask. Looking at the\nbacktrace, the illegal instruction is encountered in this same function.\nHowever, patch_text_nosync, after patching the instructions, calls\nflush_icache_range. But looking at what happens in this function:\n\nflush_icache_range -> flush_icache_all\n -> sbi_remote_fence_i\n -> __sbi_rfence_v02\n -> riscv_cpuid_to_hartid_mask\n\nThe icache and dcache of the current cpu are never synchronized between the\npatching of riscv_cpuid_to_hartid_mask and calling this same function.\n\nSo fix this by flushing the current cpu's icache before asking for the other\ncpus to do the same.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wjg2-c8g7-rjjr/GHSA-wjg2-c8g7-rjjr.json b/advisories/unreviewed/2024/05/GHSA-wjg2-c8g7-rjjr/GHSA-wjg2-c8g7-rjjr.json index 989f3c5c821..ceba53b7ca1 100644 --- a/advisories/unreviewed/2024/05/GHSA-wjg2-c8g7-rjjr/GHSA-wjg2-c8g7-rjjr.json +++ b/advisories/unreviewed/2024/05/GHSA-wjg2-c8g7-rjjr/GHSA-wjg2-c8g7-rjjr.json @@ -7,12 +7,8 @@ "CVE-2023-52873" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt6779: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wppq-9h6p-crxg/GHSA-wppq-9h6p-crxg.json b/advisories/unreviewed/2024/05/GHSA-wppq-9h6p-crxg/GHSA-wppq-9h6p-crxg.json index ecdf9ba43f7..db183a90471 100644 --- a/advisories/unreviewed/2024/05/GHSA-wppq-9h6p-crxg/GHSA-wppq-9h6p-crxg.json +++ b/advisories/unreviewed/2024/05/GHSA-wppq-9h6p-crxg/GHSA-wppq-9h6p-crxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wwqr-5vx2-25qx/GHSA-wwqr-5vx2-25qx.json b/advisories/unreviewed/2024/05/GHSA-wwqr-5vx2-25qx/GHSA-wwqr-5vx2-25qx.json index af616c76b98..d6a4c9aa1ba 100644 --- a/advisories/unreviewed/2024/05/GHSA-wwqr-5vx2-25qx/GHSA-wwqr-5vx2-25qx.json +++ b/advisories/unreviewed/2024/05/GHSA-wwqr-5vx2-25qx/GHSA-wwqr-5vx2-25qx.json @@ -7,12 +7,8 @@ "CVE-2023-52762" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-blk: fix implicit overflow on virtio_max_dma_size\n\nThe following codes have an implicit conversion from size_t to u32:\n(u32)max_size = (size_t)virtio_max_dma_size(vdev);\n\nThis may lead overflow, Ex (size_t)4G -> (u32)0. Once\nvirtio_max_dma_size() has a larger size than U32_MAX, use U32_MAX\ninstead.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x858-gx5h-mfp9/GHSA-x858-gx5h-mfp9.json b/advisories/unreviewed/2024/05/GHSA-x858-gx5h-mfp9/GHSA-x858-gx5h-mfp9.json index 892c7c054be..2a450423c6d 100644 --- a/advisories/unreviewed/2024/05/GHSA-x858-gx5h-mfp9/GHSA-x858-gx5h-mfp9.json +++ b/advisories/unreviewed/2024/05/GHSA-x858-gx5h-mfp9/GHSA-x858-gx5h-mfp9.json @@ -7,12 +7,8 @@ "CVE-2021-47425" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: acpi: fix resource leak in reconfiguration device addition\n\nacpi_i2c_find_adapter_by_handle() calls bus_find_device() which takes a\nreference on the adapter which is never released which will result in a\nreference count leak and render the adapter unremovable. Make sure to\nput the adapter after creating the client in the same manner that we do\nfor OF.\n\n[wsa: fixed title]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xj33-wwm4-p8mw/GHSA-xj33-wwm4-p8mw.json b/advisories/unreviewed/2024/05/GHSA-xj33-wwm4-p8mw/GHSA-xj33-wwm4-p8mw.json index 3d2d88655c8..da5025f9bdb 100644 --- a/advisories/unreviewed/2024/05/GHSA-xj33-wwm4-p8mw/GHSA-xj33-wwm4-p8mw.json +++ b/advisories/unreviewed/2024/05/GHSA-xj33-wwm4-p8mw/GHSA-xj33-wwm4-p8mw.json @@ -7,12 +7,8 @@ "CVE-2021-47426" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, s390: Fix potential memory leak about jit_data\n\nMake sure to free jit_data through kfree() in the error path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xm9j-x4hp-v2x3/GHSA-xm9j-x4hp-v2x3.json b/advisories/unreviewed/2024/05/GHSA-xm9j-x4hp-v2x3/GHSA-xm9j-x4hp-v2x3.json index 2b795034c6e..9fdc887cd95 100644 --- a/advisories/unreviewed/2024/05/GHSA-xm9j-x4hp-v2x3/GHSA-xm9j-x4hp-v2x3.json +++ b/advisories/unreviewed/2024/05/GHSA-xm9j-x4hp-v2x3/GHSA-xm9j-x4hp-v2x3.json @@ -7,12 +7,8 @@ "CVE-2021-47422" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/kms/nv50-: fix file release memory leak\n\nWhen using single_open() for opening, single_release() should be\ncalled, otherwise the 'op' allocated in single_open() will be leaked.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xmph-r8h2-5h79/GHSA-xmph-r8h2-5h79.json b/advisories/unreviewed/2024/05/GHSA-xmph-r8h2-5h79/GHSA-xmph-r8h2-5h79.json index 2aa06b1a25c..f4e22fcc43a 100644 --- a/advisories/unreviewed/2024/05/GHSA-xmph-r8h2-5h79/GHSA-xmph-r8h2-5h79.json +++ b/advisories/unreviewed/2024/05/GHSA-xmph-r8h2-5h79/GHSA-xmph-r8h2-5h79.json @@ -7,12 +7,8 @@ "CVE-2023-52867" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: possible buffer overflow\n\nBuffer 'afmt_status' of size 6 could overflow, since index 'afmt_idx' is\nchecked after access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-39xv-4j8v-hp84/GHSA-39xv-4j8v-hp84.json b/advisories/unreviewed/2024/06/GHSA-39xv-4j8v-hp84/GHSA-39xv-4j8v-hp84.json index 60cf6dcc302..21b6ddb6063 100644 --- a/advisories/unreviewed/2024/06/GHSA-39xv-4j8v-hp84/GHSA-39xv-4j8v-hp84.json +++ b/advisories/unreviewed/2024/06/GHSA-39xv-4j8v-hp84/GHSA-39xv-4j8v-hp84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-28pw-27gw-65v8/GHSA-28pw-27gw-65v8.json b/advisories/unreviewed/2024/08/GHSA-28pw-27gw-65v8/GHSA-28pw-27gw-65v8.json index c62ca0bf69e..ae703934c4f 100644 --- a/advisories/unreviewed/2024/08/GHSA-28pw-27gw-65v8/GHSA-28pw-27gw-65v8.json +++ b/advisories/unreviewed/2024/08/GHSA-28pw-27gw-65v8/GHSA-28pw-27gw-65v8.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-5gj6-wwjq-frjh/GHSA-5gj6-wwjq-frjh.json b/advisories/unreviewed/2024/08/GHSA-5gj6-wwjq-frjh/GHSA-5gj6-wwjq-frjh.json index b63133eb175..46c4e024fc1 100644 --- a/advisories/unreviewed/2024/08/GHSA-5gj6-wwjq-frjh/GHSA-5gj6-wwjq-frjh.json +++ b/advisories/unreviewed/2024/08/GHSA-5gj6-wwjq-frjh/GHSA-5gj6-wwjq-frjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-hrr6-ghrm-hggq/GHSA-hrr6-ghrm-hggq.json b/advisories/unreviewed/2024/08/GHSA-hrr6-ghrm-hggq/GHSA-hrr6-ghrm-hggq.json index 9087cf7f0f5..94e1e0fb2b4 100644 --- a/advisories/unreviewed/2024/08/GHSA-hrr6-ghrm-hggq/GHSA-hrr6-ghrm-hggq.json +++ b/advisories/unreviewed/2024/08/GHSA-hrr6-ghrm-hggq/GHSA-hrr6-ghrm-hggq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-pqx2-f9cx-8825/GHSA-pqx2-f9cx-8825.json b/advisories/unreviewed/2024/08/GHSA-pqx2-f9cx-8825/GHSA-pqx2-f9cx-8825.json index 667b3b3580a..8af5944ae57 100644 --- a/advisories/unreviewed/2024/08/GHSA-pqx2-f9cx-8825/GHSA-pqx2-f9cx-8825.json +++ b/advisories/unreviewed/2024/08/GHSA-pqx2-f9cx-8825/GHSA-pqx2-f9cx-8825.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-34h3-77mg-mfgh/GHSA-34h3-77mg-mfgh.json b/advisories/unreviewed/2024/09/GHSA-34h3-77mg-mfgh/GHSA-34h3-77mg-mfgh.json index de9d7d279f9..3df9ab076f9 100644 --- a/advisories/unreviewed/2024/09/GHSA-34h3-77mg-mfgh/GHSA-34h3-77mg-mfgh.json +++ b/advisories/unreviewed/2024/09/GHSA-34h3-77mg-mfgh/GHSA-34h3-77mg-mfgh.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-3frm-3q2w-pp83/GHSA-3frm-3q2w-pp83.json b/advisories/unreviewed/2024/09/GHSA-3frm-3q2w-pp83/GHSA-3frm-3q2w-pp83.json index 5dacf6a57d8..7960fc52518 100644 --- a/advisories/unreviewed/2024/09/GHSA-3frm-3q2w-pp83/GHSA-3frm-3q2w-pp83.json +++ b/advisories/unreviewed/2024/09/GHSA-3frm-3q2w-pp83/GHSA-3frm-3q2w-pp83.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json b/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json index 3cc137140b3..431d6d29f52 100644 --- a/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json +++ b/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-77rm-8jvr-hfgm/GHSA-77rm-8jvr-hfgm.json b/advisories/unreviewed/2024/09/GHSA-77rm-8jvr-hfgm/GHSA-77rm-8jvr-hfgm.json index 9acd87e3cd8..5aa7374875a 100644 --- a/advisories/unreviewed/2024/09/GHSA-77rm-8jvr-hfgm/GHSA-77rm-8jvr-hfgm.json +++ b/advisories/unreviewed/2024/09/GHSA-77rm-8jvr-hfgm/GHSA-77rm-8jvr-hfgm.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-899w-w5qq-hg5v/GHSA-899w-w5qq-hg5v.json b/advisories/unreviewed/2024/09/GHSA-899w-w5qq-hg5v/GHSA-899w-w5qq-hg5v.json index 707b11684fd..2c5373b3d23 100644 --- a/advisories/unreviewed/2024/09/GHSA-899w-w5qq-hg5v/GHSA-899w-w5qq-hg5v.json +++ b/advisories/unreviewed/2024/09/GHSA-899w-w5qq-hg5v/GHSA-899w-w5qq-hg5v.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-c7c7-8frm-jcmp/GHSA-c7c7-8frm-jcmp.json b/advisories/unreviewed/2024/09/GHSA-c7c7-8frm-jcmp/GHSA-c7c7-8frm-jcmp.json index 57659c7dbef..b51d4fc4c3e 100644 --- a/advisories/unreviewed/2024/09/GHSA-c7c7-8frm-jcmp/GHSA-c7c7-8frm-jcmp.json +++ b/advisories/unreviewed/2024/09/GHSA-c7c7-8frm-jcmp/GHSA-c7c7-8frm-jcmp.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",