From a661d2f52666a7d4fddfabe8222cdebc6fe73f9c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 05:04:26 +0000 Subject: [PATCH] Advisory Database Sync --- .../11/GHSA-959p-vvwh-xj92/GHSA-959p-vvwh-xj92.json | 4 +--- .../11/GHSA-gjrp-cpc9-h4r7/GHSA-gjrp-cpc9-h4r7.json | 4 +--- .../11/GHSA-jpp8-232v-26fc/GHSA-jpp8-232v-26fc.json | 4 +--- .../12/GHSA-mj29-93c5-p3pr/GHSA-mj29-93c5-p3pr.json | 8 ++------ .../01/GHSA-cf77-6c9v-56mf/GHSA-cf77-6c9v-56mf.json | 4 +--- .../01/GHSA-j5wx-jhwh-qm36/GHSA-j5wx-jhwh-qm36.json | 4 +--- .../01/GHSA-wvq2-357p-vcgg/GHSA-wvq2-357p-vcgg.json | 8 ++------ .../03/GHSA-mxm3-g2j6-276p/GHSA-mxm3-g2j6-276p.json | 4 +--- .../03/GHSA-q9rw-8758-hccj/GHSA-q9rw-8758-hccj.json | 4 +--- .../04/GHSA-2m7r-8x5f-v32g/GHSA-2m7r-8x5f-v32g.json | 12 +++--------- .../04/GHSA-2qwq-f37f-3q37/GHSA-2qwq-f37f-3q37.json | 12 +++--------- .../04/GHSA-2r2v-2jgp-6j72/GHSA-2r2v-2jgp-6j72.json | 12 +++--------- .../04/GHSA-2vjq-g46g-w383/GHSA-2vjq-g46g-w383.json | 12 +++--------- .../04/GHSA-32xp-8gq9-j2vq/GHSA-32xp-8gq9-j2vq.json | 12 +++--------- .../04/GHSA-359x-29v3-4rrm/GHSA-359x-29v3-4rrm.json | 12 +++--------- .../04/GHSA-37gr-95fp-3q54/GHSA-37gr-95fp-3q54.json | 12 +++--------- .../04/GHSA-37rm-6wgr-cv7j/GHSA-37rm-6wgr-cv7j.json | 12 +++--------- .../04/GHSA-397w-gc7r-9x5j/GHSA-397w-gc7r-9x5j.json | 12 +++--------- .../04/GHSA-3f9g-p7qm-mjjp/GHSA-3f9g-p7qm-mjjp.json | 12 +++--------- .../04/GHSA-3gx5-q8r9-268f/GHSA-3gx5-q8r9-268f.json | 12 +++--------- .../04/GHSA-3h69-7jmr-q5h4/GHSA-3h69-7jmr-q5h4.json | 12 +++--------- .../04/GHSA-3hfj-vjmw-rjj4/GHSA-3hfj-vjmw-rjj4.json | 12 +++--------- .../04/GHSA-3jcq-7m4x-57r2/GHSA-3jcq-7m4x-57r2.json | 12 +++--------- .../04/GHSA-3mwg-wvg9-ghpc/GHSA-3mwg-wvg9-ghpc.json | 12 +++--------- .../04/GHSA-3p8c-x7m5-892x/GHSA-3p8c-x7m5-892x.json | 12 +++--------- .../04/GHSA-3pxp-67jr-6qw6/GHSA-3pxp-67jr-6qw6.json | 12 +++--------- .../04/GHSA-3q3m-3ccv-7882/GHSA-3q3m-3ccv-7882.json | 12 +++--------- .../04/GHSA-3v49-5224-w9p6/GHSA-3v49-5224-w9p6.json | 12 +++--------- .../04/GHSA-3vjc-m2jj-cq2m/GHSA-3vjc-m2jj-cq2m.json | 12 +++--------- .../04/GHSA-3wf7-ph6r-pvj6/GHSA-3wf7-ph6r-pvj6.json | 12 +++--------- .../04/GHSA-43vf-262m-2h43/GHSA-43vf-262m-2h43.json | 12 +++--------- .../04/GHSA-449v-w7gx-8c56/GHSA-449v-w7gx-8c56.json | 12 +++--------- .../04/GHSA-47jj-8xrh-9rgj/GHSA-47jj-8xrh-9rgj.json | 12 +++--------- .../04/GHSA-4975-vpm3-gpxg/GHSA-4975-vpm3-gpxg.json | 12 +++--------- .../04/GHSA-4f9v-p38h-gqrh/GHSA-4f9v-p38h-gqrh.json | 12 +++--------- .../04/GHSA-4fw3-934j-23xh/GHSA-4fw3-934j-23xh.json | 12 +++--------- .../04/GHSA-4h7m-m3ch-jghg/GHSA-4h7m-m3ch-jghg.json | 12 +++--------- .../04/GHSA-4hm3-9cfc-p6pj/GHSA-4hm3-9cfc-p6pj.json | 12 +++--------- .../04/GHSA-4hmg-2h4v-rc9v/GHSA-4hmg-2h4v-rc9v.json | 12 +++--------- .../04/GHSA-4j49-9f55-6qxq/GHSA-4j49-9f55-6qxq.json | 12 +++--------- .../04/GHSA-4mpx-5p7r-233r/GHSA-4mpx-5p7r-233r.json | 12 +++--------- .../04/GHSA-4q4v-qgcp-x9q2/GHSA-4q4v-qgcp-x9q2.json | 12 +++--------- .../04/GHSA-4w5x-6pmj-4m2q/GHSA-4w5x-6pmj-4m2q.json | 12 +++--------- .../04/GHSA-4wpr-qcp7-qmrj/GHSA-4wpr-qcp7-qmrj.json | 12 +++--------- .../04/GHSA-4xvp-v8m6-p35p/GHSA-4xvp-v8m6-p35p.json | 12 +++--------- .../04/GHSA-53qq-7f4q-p4vg/GHSA-53qq-7f4q-p4vg.json | 12 +++--------- .../04/GHSA-5426-8hx3-xgr4/GHSA-5426-8hx3-xgr4.json | 12 +++--------- .../04/GHSA-55wv-gf82-7jgw/GHSA-55wv-gf82-7jgw.json | 12 +++--------- .../04/GHSA-574g-c88f-3c4p/GHSA-574g-c88f-3c4p.json | 12 +++--------- .../04/GHSA-574q-v35c-h2h9/GHSA-574q-v35c-h2h9.json | 12 +++--------- .../04/GHSA-578c-6gc2-pwhw/GHSA-578c-6gc2-pwhw.json | 12 +++--------- .../04/GHSA-57cw-xj8m-j9g4/GHSA-57cw-xj8m-j9g4.json | 12 +++--------- .../04/GHSA-57h3-4hgq-6hc9/GHSA-57h3-4hgq-6hc9.json | 12 +++--------- .../04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json | 4 +--- .../04/GHSA-5ghm-fxvf-qqww/GHSA-5ghm-fxvf-qqww.json | 12 +++--------- .../04/GHSA-5j4q-p8r9-g32c/GHSA-5j4q-p8r9-g32c.json | 8 ++------ .../04/GHSA-5p96-h7hc-r39x/GHSA-5p96-h7hc-r39x.json | 12 +++--------- .../04/GHSA-5rfj-g58v-h7w2/GHSA-5rfj-g58v-h7w2.json | 12 +++--------- .../04/GHSA-5wrm-j5hw-2wjj/GHSA-5wrm-j5hw-2wjj.json | 12 +++--------- .../04/GHSA-5xw5-44j8-6h82/GHSA-5xw5-44j8-6h82.json | 12 +++--------- .../04/GHSA-6569-w2hm-vh9q/GHSA-6569-w2hm-vh9q.json | 12 +++--------- .../04/GHSA-66ff-xg83-gqqx/GHSA-66ff-xg83-gqqx.json | 12 +++--------- .../04/GHSA-6hhc-9578-w8h2/GHSA-6hhc-9578-w8h2.json | 12 +++--------- .../04/GHSA-6m87-jr5w-7c85/GHSA-6m87-jr5w-7c85.json | 12 +++--------- .../04/GHSA-6m92-qjr5-r83w/GHSA-6m92-qjr5-r83w.json | 12 +++--------- .../04/GHSA-6mgc-h6hw-q65q/GHSA-6mgc-h6hw-q65q.json | 12 +++--------- .../04/GHSA-6mhg-8xpv-r877/GHSA-6mhg-8xpv-r877.json | 12 +++--------- .../04/GHSA-6mxv-f2hm-j5mm/GHSA-6mxv-f2hm-j5mm.json | 12 +++--------- .../04/GHSA-6r2q-2w5h-xffp/GHSA-6r2q-2w5h-xffp.json | 12 +++--------- .../04/GHSA-6r6r-2p6c-hcvv/GHSA-6r6r-2p6c-hcvv.json | 12 +++--------- .../04/GHSA-6wh4-77gr-x4gj/GHSA-6wh4-77gr-x4gj.json | 12 +++--------- .../04/GHSA-6x5x-c996-pqhh/GHSA-6x5x-c996-pqhh.json | 12 +++--------- .../04/GHSA-6xc9-5x2c-v57j/GHSA-6xc9-5x2c-v57j.json | 12 +++--------- .../04/GHSA-72jm-m44p-fqqc/GHSA-72jm-m44p-fqqc.json | 12 +++--------- .../04/GHSA-72pr-qpg4-f6xj/GHSA-72pr-qpg4-f6xj.json | 12 +++--------- .../04/GHSA-763p-5832-h4vj/GHSA-763p-5832-h4vj.json | 12 +++--------- .../04/GHSA-7gjr-q697-2f77/GHSA-7gjr-q697-2f77.json | 12 +++--------- .../04/GHSA-7mr8-86xj-xmxp/GHSA-7mr8-86xj-xmxp.json | 12 +++--------- .../04/GHSA-7pvr-mj99-7r8h/GHSA-7pvr-mj99-7r8h.json | 12 +++--------- .../04/GHSA-7v39-48jj-rjrh/GHSA-7v39-48jj-rjrh.json | 12 +++--------- .../04/GHSA-7wmc-wm7f-rg53/GHSA-7wmc-wm7f-rg53.json | 12 +++--------- .../04/GHSA-8cvx-3rg5-x9j3/GHSA-8cvx-3rg5-x9j3.json | 4 +--- .../04/GHSA-8fpx-4fc3-m2g2/GHSA-8fpx-4fc3-m2g2.json | 12 +++--------- .../04/GHSA-8j36-g58p-4q96/GHSA-8j36-g58p-4q96.json | 12 +++--------- .../04/GHSA-8qpv-69qh-f6fm/GHSA-8qpv-69qh-f6fm.json | 12 +++--------- .../04/GHSA-8rc7-gfvj-2hjx/GHSA-8rc7-gfvj-2hjx.json | 8 ++------ .../04/GHSA-8rv5-m3x9-445f/GHSA-8rv5-m3x9-445f.json | 12 +++--------- .../04/GHSA-9725-v8gc-7c9f/GHSA-9725-v8gc-7c9f.json | 12 +++--------- .../04/GHSA-99g5-8fv2-6cgr/GHSA-99g5-8fv2-6cgr.json | 12 +++--------- .../04/GHSA-9cm9-mwhq-5792/GHSA-9cm9-mwhq-5792.json | 12 +++--------- .../04/GHSA-9r9h-3x7g-qvjq/GHSA-9r9h-3x7g-qvjq.json | 12 +++--------- .../04/GHSA-9rg5-49f6-x8mf/GHSA-9rg5-49f6-x8mf.json | 12 +++--------- .../04/GHSA-9rpj-3h3j-f5ch/GHSA-9rpj-3h3j-f5ch.json | 12 +++--------- .../04/GHSA-9vfc-272p-57xp/GHSA-9vfc-272p-57xp.json | 12 +++--------- .../04/GHSA-9vmq-vwpx-f975/GHSA-9vmq-vwpx-f975.json | 12 +++--------- .../04/GHSA-9x27-fwpx-qjx8/GHSA-9x27-fwpx-qjx8.json | 12 +++--------- .../04/GHSA-c3mw-fh2q-7xx4/GHSA-c3mw-fh2q-7xx4.json | 8 ++------ .../04/GHSA-c5xw-hcq7-rj2g/GHSA-c5xw-hcq7-rj2g.json | 12 +++--------- .../04/GHSA-c8hp-7fgw-gpw8/GHSA-c8hp-7fgw-gpw8.json | 12 +++--------- .../04/GHSA-cf67-7j7r-89q3/GHSA-cf67-7j7r-89q3.json | 8 ++------ .../04/GHSA-cfrm-mc6g-2q3f/GHSA-cfrm-mc6g-2q3f.json | 12 +++--------- .../04/GHSA-cfxp-7mcx-7phh/GHSA-cfxp-7mcx-7phh.json | 12 +++--------- .../04/GHSA-cqh3-66qm-fc26/GHSA-cqh3-66qm-fc26.json | 12 +++--------- .../04/GHSA-f4rg-5qc9-c5v5/GHSA-f4rg-5qc9-c5v5.json | 12 +++--------- .../04/GHSA-f6px-r4ch-xrcj/GHSA-f6px-r4ch-xrcj.json | 12 +++--------- .../04/GHSA-frch-j9xm-v3rx/GHSA-frch-j9xm-v3rx.json | 12 +++--------- .../04/GHSA-fvfp-vfmf-mhwp/GHSA-fvfp-vfmf-mhwp.json | 12 +++--------- .../04/GHSA-g2gh-64hj-766p/GHSA-g2gh-64hj-766p.json | 12 +++--------- .../04/GHSA-g4v6-4jj6-xg55/GHSA-g4v6-4jj6-xg55.json | 12 +++--------- .../04/GHSA-g8qj-v5c9-523w/GHSA-g8qj-v5c9-523w.json | 12 +++--------- .../04/GHSA-g9fc-7w7p-pf73/GHSA-g9fc-7w7p-pf73.json | 12 +++--------- .../04/GHSA-g9rj-hq2r-84cm/GHSA-g9rj-hq2r-84cm.json | 12 +++--------- .../04/GHSA-gffr-5pg9-5cr5/GHSA-gffr-5pg9-5cr5.json | 12 +++--------- .../04/GHSA-gr28-8w72-h95f/GHSA-gr28-8w72-h95f.json | 12 +++--------- .../04/GHSA-gvcm-7pcm-j9rm/GHSA-gvcm-7pcm-j9rm.json | 12 +++--------- .../04/GHSA-gxx7-gprx-vg86/GHSA-gxx7-gprx-vg86.json | 12 +++--------- .../04/GHSA-h24f-7cpg-rrpm/GHSA-h24f-7cpg-rrpm.json | 12 +++--------- .../04/GHSA-h35f-36ph-rqj8/GHSA-h35f-36ph-rqj8.json | 12 +++--------- .../04/GHSA-h3jp-chmm-392r/GHSA-h3jp-chmm-392r.json | 12 +++--------- .../04/GHSA-h3mh-53x4-8jwr/GHSA-h3mh-53x4-8jwr.json | 12 +++--------- .../04/GHSA-h46r-7fc6-g355/GHSA-h46r-7fc6-g355.json | 12 +++--------- .../04/GHSA-h6g7-m2qw-2j9q/GHSA-h6g7-m2qw-2j9q.json | 12 +++--------- .../04/GHSA-h6j8-h5j9-864g/GHSA-h6j8-h5j9-864g.json | 12 +++--------- .../04/GHSA-hcqp-hpgw-2hmj/GHSA-hcqp-hpgw-2hmj.json | 12 +++--------- .../04/GHSA-hf24-j27r-97jc/GHSA-hf24-j27r-97jc.json | 12 +++--------- .../04/GHSA-hffm-jhvp-jhqx/GHSA-hffm-jhvp-jhqx.json | 12 +++--------- .../04/GHSA-hgx4-c8m2-fq38/GHSA-hgx4-c8m2-fq38.json | 12 +++--------- .../04/GHSA-hj48-8q8c-q7g9/GHSA-hj48-8q8c-q7g9.json | 12 +++--------- .../04/GHSA-hq49-5fpc-c85q/GHSA-hq49-5fpc-c85q.json | 12 +++--------- .../04/GHSA-hvgg-hv8j-3qv8/GHSA-hvgg-hv8j-3qv8.json | 12 +++--------- .../04/GHSA-j37c-fr9j-g7mj/GHSA-j37c-fr9j-g7mj.json | 12 +++--------- .../04/GHSA-j3mm-cmpj-cv2w/GHSA-j3mm-cmpj-cv2w.json | 12 +++--------- .../04/GHSA-j3vg-5xcr-9g3j/GHSA-j3vg-5xcr-9g3j.json | 12 +++--------- .../04/GHSA-j55q-v3p6-qfvv/GHSA-j55q-v3p6-qfvv.json | 12 +++--------- .../04/GHSA-j85p-6g22-63v4/GHSA-j85p-6g22-63v4.json | 12 +++--------- .../04/GHSA-j8fp-ff64-g7r6/GHSA-j8fp-ff64-g7r6.json | 8 ++------ .../04/GHSA-jgqq-gwfm-cchw/GHSA-jgqq-gwfm-cchw.json | 12 +++--------- .../04/GHSA-jj5f-c84c-p5jc/GHSA-jj5f-c84c-p5jc.json | 12 +++--------- .../04/GHSA-jvxq-q97r-j8hm/GHSA-jvxq-q97r-j8hm.json | 12 +++--------- .../04/GHSA-jw79-gm26-2pgj/GHSA-jw79-gm26-2pgj.json | 12 +++--------- .../04/GHSA-m2mc-vwqx-3chc/GHSA-m2mc-vwqx-3chc.json | 12 +++--------- .../04/GHSA-m3c3-46rf-v3c3/GHSA-m3c3-46rf-v3c3.json | 12 +++--------- .../04/GHSA-mq3p-hf2w-4fg4/GHSA-mq3p-hf2w-4fg4.json | 12 +++--------- .../04/GHSA-p235-73wr-c3m7/GHSA-p235-73wr-c3m7.json | 4 +--- .../04/GHSA-p2qq-q635-wcgr/GHSA-p2qq-q635-wcgr.json | 12 +++--------- .../04/GHSA-p564-2rfx-wgpg/GHSA-p564-2rfx-wgpg.json | 12 +++--------- .../04/GHSA-p98c-hcw6-4j4f/GHSA-p98c-hcw6-4j4f.json | 12 +++--------- .../04/GHSA-pfgr-89g7-q7q8/GHSA-pfgr-89g7-q7q8.json | 12 +++--------- .../04/GHSA-pfqm-c4ph-rv4v/GHSA-pfqm-c4ph-rv4v.json | 12 +++--------- .../04/GHSA-pgq6-85cf-x6w3/GHSA-pgq6-85cf-x6w3.json | 12 +++--------- .../04/GHSA-pj48-hggv-4w8h/GHSA-pj48-hggv-4w8h.json | 12 +++--------- .../04/GHSA-pmp3-x433-rm9r/GHSA-pmp3-x433-rm9r.json | 12 +++--------- .../04/GHSA-pqwg-424h-mwmq/GHSA-pqwg-424h-mwmq.json | 12 +++--------- .../04/GHSA-pwcj-h5hm-9qvx/GHSA-pwcj-h5hm-9qvx.json | 12 +++--------- .../04/GHSA-pwcm-4994-52jq/GHSA-pwcm-4994-52jq.json | 12 +++--------- .../04/GHSA-q3ph-w9hq-wf9p/GHSA-q3ph-w9hq-wf9p.json | 12 +++--------- .../04/GHSA-q4j5-jpvw-4ww8/GHSA-q4j5-jpvw-4ww8.json | 12 +++--------- .../04/GHSA-q78g-73j3-mh33/GHSA-q78g-73j3-mh33.json | 12 +++--------- .../04/GHSA-q9x4-57vc-x2vp/GHSA-q9x4-57vc-x2vp.json | 12 +++--------- .../04/GHSA-qfqh-96cv-x4mp/GHSA-qfqh-96cv-x4mp.json | 8 ++------ .../04/GHSA-qjfh-cqv7-7vp4/GHSA-qjfh-cqv7-7vp4.json | 12 +++--------- .../04/GHSA-qq6r-xf5p-xmg4/GHSA-qq6r-xf5p-xmg4.json | 12 +++--------- .../04/GHSA-qqw5-9xgq-fw5j/GHSA-qqw5-9xgq-fw5j.json | 12 +++--------- .../04/GHSA-qrjq-m326-9xph/GHSA-qrjq-m326-9xph.json | 12 +++--------- .../04/GHSA-qxc5-37gj-mcj7/GHSA-qxc5-37gj-mcj7.json | 12 +++--------- .../04/GHSA-r52p-h476-w962/GHSA-r52p-h476-w962.json | 12 +++--------- .../04/GHSA-r5cc-6x6f-2359/GHSA-r5cc-6x6f-2359.json | 12 +++--------- .../04/GHSA-r5fv-qp85-97wv/GHSA-r5fv-qp85-97wv.json | 12 +++--------- .../04/GHSA-r6p3-vmjf-9hgh/GHSA-r6p3-vmjf-9hgh.json | 12 +++--------- .../04/GHSA-r75w-3v4r-7qm9/GHSA-r75w-3v4r-7qm9.json | 12 +++--------- .../04/GHSA-rc47-jfx2-55pr/GHSA-rc47-jfx2-55pr.json | 12 +++--------- .../04/GHSA-rm65-jp7g-4mvw/GHSA-rm65-jp7g-4mvw.json | 12 +++--------- .../04/GHSA-rmgf-3gj9-gmrr/GHSA-rmgf-3gj9-gmrr.json | 12 +++--------- .../04/GHSA-rq54-jrj8-62cm/GHSA-rq54-jrj8-62cm.json | 12 +++--------- .../04/GHSA-rwcj-93v2-99j2/GHSA-rwcj-93v2-99j2.json | 12 +++--------- .../04/GHSA-rwq7-fqhw-gq6p/GHSA-rwq7-fqhw-gq6p.json | 12 +++--------- .../04/GHSA-rx47-h3h8-2fqr/GHSA-rx47-h3h8-2fqr.json | 12 +++--------- .../04/GHSA-v2px-5cf8-vr46/GHSA-v2px-5cf8-vr46.json | 12 +++--------- .../04/GHSA-v3h5-fhg8-jp65/GHSA-v3h5-fhg8-jp65.json | 12 +++--------- .../04/GHSA-v3jq-qw95-xr88/GHSA-v3jq-qw95-xr88.json | 12 +++--------- .../04/GHSA-v5h8-96h5-6hm4/GHSA-v5h8-96h5-6hm4.json | 12 +++--------- .../04/GHSA-v6wh-fw29-g4mg/GHSA-v6wh-fw29-g4mg.json | 12 +++--------- .../04/GHSA-v97r-xxvr-6fc5/GHSA-v97r-xxvr-6fc5.json | 12 +++--------- .../04/GHSA-v9mf-r73m-jrrh/GHSA-v9mf-r73m-jrrh.json | 12 +++--------- .../04/GHSA-v9vp-j7qm-2rcj/GHSA-v9vp-j7qm-2rcj.json | 12 +++--------- .../04/GHSA-vfwv-p32r-49c7/GHSA-vfwv-p32r-49c7.json | 12 +++--------- .../04/GHSA-vgc7-vcfh-c73q/GHSA-vgc7-vcfh-c73q.json | 12 +++--------- .../04/GHSA-vmwj-5crv-3q5f/GHSA-vmwj-5crv-3q5f.json | 12 +++--------- .../04/GHSA-vq5p-68xq-c2fv/GHSA-vq5p-68xq-c2fv.json | 12 +++--------- .../04/GHSA-vwp5-j5cp-r3jp/GHSA-vwp5-j5cp-r3jp.json | 12 +++--------- .../04/GHSA-vx22-3cf4-63m3/GHSA-vx22-3cf4-63m3.json | 12 +++--------- .../04/GHSA-w42r-hrg2-j8mr/GHSA-w42r-hrg2-j8mr.json | 12 +++--------- .../04/GHSA-w546-2ph3-cg79/GHSA-w546-2ph3-cg79.json | 12 +++--------- .../04/GHSA-w8wv-4gwp-hvv3/GHSA-w8wv-4gwp-hvv3.json | 12 +++--------- .../04/GHSA-wcwp-7mcr-w7wx/GHSA-wcwp-7mcr-w7wx.json | 8 ++------ .../04/GHSA-wj9g-86pf-x73r/GHSA-wj9g-86pf-x73r.json | 12 +++--------- .../04/GHSA-wjpj-j5w8-2m2p/GHSA-wjpj-j5w8-2m2p.json | 4 +--- .../04/GHSA-wq5g-65xw-2w6q/GHSA-wq5g-65xw-2w6q.json | 12 +++--------- .../04/GHSA-wqf3-h5g7-w9q8/GHSA-wqf3-h5g7-w9q8.json | 4 +--- .../04/GHSA-wvh4-6wwm-47c4/GHSA-wvh4-6wwm-47c4.json | 12 +++--------- .../04/GHSA-wx5p-jq7w-xjqv/GHSA-wx5p-jq7w-xjqv.json | 12 +++--------- .../04/GHSA-x4gh-vmc2-6j3g/GHSA-x4gh-vmc2-6j3g.json | 12 +++--------- .../04/GHSA-x664-g64f-4m6f/GHSA-x664-g64f-4m6f.json | 12 +++--------- .../04/GHSA-x6cc-4gc4-jf7f/GHSA-x6cc-4gc4-jf7f.json | 12 +++--------- .../04/GHSA-x9xv-j4wv-rqf5/GHSA-x9xv-j4wv-rqf5.json | 12 +++--------- .../04/GHSA-xcc8-gv7j-57r8/GHSA-xcc8-gv7j-57r8.json | 12 +++--------- .../04/GHSA-xf2g-7fqj-9q58/GHSA-xf2g-7fqj-9q58.json | 12 +++--------- .../04/GHSA-xm72-c99x-fm79/GHSA-xm72-c99x-fm79.json | 12 +++--------- .../04/GHSA-xp9f-5q2c-rrp4/GHSA-xp9f-5q2c-rrp4.json | 12 +++--------- .../04/GHSA-xrcm-f723-98ww/GHSA-xrcm-f723-98ww.json | 12 +++--------- .../04/GHSA-xwc7-g658-j4rq/GHSA-xwc7-g658-j4rq.json | 12 +++--------- .../04/GHSA-xxv9-fp7w-qg3h/GHSA-xxv9-fp7w-qg3h.json | 12 +++--------- .../05/GHSA-22hp-gvgq-7pg5/GHSA-22hp-gvgq-7pg5.json | 12 +++--------- .../05/GHSA-22rf-57mq-wq43/GHSA-22rf-57mq-wq43.json | 12 +++--------- .../05/GHSA-2454-7cjj-wj2v/GHSA-2454-7cjj-wj2v.json | 12 +++--------- .../05/GHSA-25h7-qcgx-8445/GHSA-25h7-qcgx-8445.json | 8 ++------ .../05/GHSA-2669-2gh7-hrr6/GHSA-2669-2gh7-hrr6.json | 12 +++--------- .../05/GHSA-28cw-3j6f-3fv3/GHSA-28cw-3j6f-3fv3.json | 12 +++--------- .../05/GHSA-2f3r-62xx-976q/GHSA-2f3r-62xx-976q.json | 12 +++--------- .../05/GHSA-2fx9-jj4f-fr73/GHSA-2fx9-jj4f-fr73.json | 12 +++--------- .../05/GHSA-2m2f-v78g-328f/GHSA-2m2f-v78g-328f.json | 12 +++--------- .../05/GHSA-2prm-99p5-f5cr/GHSA-2prm-99p5-f5cr.json | 12 +++--------- .../05/GHSA-2r34-57wf-fc67/GHSA-2r34-57wf-fc67.json | 12 +++--------- .../05/GHSA-2rxj-7r53-f46w/GHSA-2rxj-7r53-f46w.json | 12 +++--------- .../05/GHSA-2v68-cx38-874x/GHSA-2v68-cx38-874x.json | 12 +++--------- .../05/GHSA-2w7w-5xvh-2987/GHSA-2w7w-5xvh-2987.json | 12 +++--------- .../05/GHSA-2wmv-9ccc-rw9w/GHSA-2wmv-9ccc-rw9w.json | 8 ++------ .../05/GHSA-2wrc-cg26-jf7m/GHSA-2wrc-cg26-jf7m.json | 4 +--- .../05/GHSA-2x43-7p4j-28px/GHSA-2x43-7p4j-28px.json | 8 ++------ .../05/GHSA-2xfg-59p6-ww64/GHSA-2xfg-59p6-ww64.json | 12 +++--------- .../05/GHSA-32x5-673x-7q8q/GHSA-32x5-673x-7q8q.json | 12 +++--------- .../05/GHSA-34pg-m6c7-g8w8/GHSA-34pg-m6c7-g8w8.json | 4 +--- .../05/GHSA-34rw-6hrg-mxr5/GHSA-34rw-6hrg-mxr5.json | 8 ++------ .../05/GHSA-3583-6263-6c39/GHSA-3583-6263-6c39.json | 12 +++--------- .../05/GHSA-37jw-9hhw-q8w8/GHSA-37jw-9hhw-q8w8.json | 8 ++------ .../05/GHSA-3cgh-jhhf-99jx/GHSA-3cgh-jhhf-99jx.json | 12 +++--------- .../05/GHSA-3cqj-w9mm-gpc5/GHSA-3cqj-w9mm-gpc5.json | 8 ++------ .../05/GHSA-3f9w-43j6-x43v/GHSA-3f9w-43j6-x43v.json | 12 +++--------- .../05/GHSA-3fvg-pj2g-c428/GHSA-3fvg-pj2g-c428.json | 12 +++--------- .../05/GHSA-3gg6-9p4q-x3pp/GHSA-3gg6-9p4q-x3pp.json | 12 +++--------- .../05/GHSA-3h29-6jm6-hw9v/GHSA-3h29-6jm6-hw9v.json | 12 +++--------- .../05/GHSA-3h98-pjm4-888p/GHSA-3h98-pjm4-888p.json | 8 ++------ .../05/GHSA-3hc3-rj8c-gwj9/GHSA-3hc3-rj8c-gwj9.json | 12 +++--------- .../05/GHSA-3jh7-385x-jfrq/GHSA-3jh7-385x-jfrq.json | 12 +++--------- .../05/GHSA-3jhm-f5jx-jwjj/GHSA-3jhm-f5jx-jwjj.json | 12 +++--------- .../05/GHSA-3p23-x5x3-gwjm/GHSA-3p23-x5x3-gwjm.json | 12 +++--------- .../05/GHSA-3p3f-h63v-47c5/GHSA-3p3f-h63v-47c5.json | 4 +--- .../05/GHSA-3p77-prh6-2vh7/GHSA-3p77-prh6-2vh7.json | 12 +++--------- .../05/GHSA-3p9g-h722-84r2/GHSA-3p9g-h722-84r2.json | 8 ++------ .../05/GHSA-3pp4-hx37-v55w/GHSA-3pp4-hx37-v55w.json | 8 ++------ .../05/GHSA-3px5-5wr3-7444/GHSA-3px5-5wr3-7444.json | 12 +++--------- .../05/GHSA-3q34-45m9-2pqp/GHSA-3q34-45m9-2pqp.json | 12 +++--------- .../05/GHSA-3q43-4596-jvg6/GHSA-3q43-4596-jvg6.json | 12 +++--------- .../05/GHSA-3rg7-72j5-5xpv/GHSA-3rg7-72j5-5xpv.json | 12 +++--------- .../05/GHSA-3rqm-h9m6-6rw6/GHSA-3rqm-h9m6-6rw6.json | 12 +++--------- .../05/GHSA-3vf8-2x93-3hff/GHSA-3vf8-2x93-3hff.json | 8 ++------ .../05/GHSA-3xfp-j69g-wh2v/GHSA-3xfp-j69g-wh2v.json | 12 +++--------- .../05/GHSA-43p9-75r2-vgfm/GHSA-43p9-75r2-vgfm.json | 12 +++--------- .../05/GHSA-45ff-f59c-34h9/GHSA-45ff-f59c-34h9.json | 12 +++--------- .../05/GHSA-45fw-qrx2-rj7m/GHSA-45fw-qrx2-rj7m.json | 4 +--- .../05/GHSA-469r-x3h6-wx66/GHSA-469r-x3h6-wx66.json | 8 ++------ .../05/GHSA-479q-9rv9-rggg/GHSA-479q-9rv9-rggg.json | 8 ++------ .../05/GHSA-485p-7896-665h/GHSA-485p-7896-665h.json | 12 +++--------- .../05/GHSA-492m-hh57-3gv9/GHSA-492m-hh57-3gv9.json | 4 +--- .../05/GHSA-4crc-pq4f-rh77/GHSA-4crc-pq4f-rh77.json | 12 +++--------- .../05/GHSA-4f9x-p86g-x88m/GHSA-4f9x-p86g-x88m.json | 4 +--- .../05/GHSA-4fg8-hr8g-58rr/GHSA-4fg8-hr8g-58rr.json | 4 +--- .../05/GHSA-4g9m-q8c4-5m6x/GHSA-4g9m-q8c4-5m6x.json | 12 +++--------- .../05/GHSA-4gg5-pmq6-mj4h/GHSA-4gg5-pmq6-mj4h.json | 8 ++------ .../05/GHSA-4ggw-3x5g-hjm6/GHSA-4ggw-3x5g-hjm6.json | 12 +++--------- .../05/GHSA-4gp5-h62v-pf2f/GHSA-4gp5-h62v-pf2f.json | 4 +--- .../05/GHSA-4gpq-jpqc-j6v2/GHSA-4gpq-jpqc-j6v2.json | 4 +--- .../05/GHSA-4hv9-pmwc-92h3/GHSA-4hv9-pmwc-92h3.json | 12 +++--------- .../05/GHSA-4mqr-g5p6-c895/GHSA-4mqr-g5p6-c895.json | 8 ++------ .../05/GHSA-4mrc-xcpw-vx8p/GHSA-4mrc-xcpw-vx8p.json | 12 +++--------- .../05/GHSA-4p7q-hvhp-3r8p/GHSA-4p7q-hvhp-3r8p.json | 12 +++--------- .../05/GHSA-4prf-w3jr-7gjh/GHSA-4prf-w3jr-7gjh.json | 12 +++--------- .../05/GHSA-4qgv-f49m-hw36/GHSA-4qgv-f49m-hw36.json | 12 +++--------- .../05/GHSA-4qp8-g498-pjrc/GHSA-4qp8-g498-pjrc.json | 12 +++--------- .../05/GHSA-4qqg-r6qm-rxgh/GHSA-4qqg-r6qm-rxgh.json | 8 ++------ .../05/GHSA-4qwg-gc27-7p3m/GHSA-4qwg-gc27-7p3m.json | 12 +++--------- .../05/GHSA-4rg7-5qhh-6v5f/GHSA-4rg7-5qhh-6v5f.json | 12 +++--------- .../05/GHSA-4rjg-59m2-p2v5/GHSA-4rjg-59m2-p2v5.json | 12 +++--------- .../05/GHSA-4x8f-6m48-c263/GHSA-4x8f-6m48-c263.json | 12 +++--------- .../05/GHSA-4x96-gfcf-h2wp/GHSA-4x96-gfcf-h2wp.json | 8 ++------ .../05/GHSA-4xhc-v448-j5jx/GHSA-4xhc-v448-j5jx.json | 4 +--- .../05/GHSA-4xrc-jppf-j6qq/GHSA-4xrc-jppf-j6qq.json | 12 +++--------- .../05/GHSA-524h-35w7-86xp/GHSA-524h-35w7-86xp.json | 4 +--- .../05/GHSA-52x8-4mc9-26r2/GHSA-52x8-4mc9-26r2.json | 8 ++------ .../05/GHSA-53f8-p3cp-57m5/GHSA-53f8-p3cp-57m5.json | 12 +++--------- .../05/GHSA-53h4-f555-qg3c/GHSA-53h4-f555-qg3c.json | 12 +++--------- .../05/GHSA-54m5-9ph9-j9cr/GHSA-54m5-9ph9-j9cr.json | 12 +++--------- .../05/GHSA-553c-2cmm-9m3c/GHSA-553c-2cmm-9m3c.json | 4 +--- .../05/GHSA-559m-xqw9-mvgm/GHSA-559m-xqw9-mvgm.json | 12 +++--------- .../05/GHSA-55c3-672v-cpq4/GHSA-55c3-672v-cpq4.json | 8 ++------ .../05/GHSA-55fp-xjf8-j279/GHSA-55fp-xjf8-j279.json | 4 +--- .../05/GHSA-56rm-922m-cgc9/GHSA-56rm-922m-cgc9.json | 12 +++--------- .../05/GHSA-574c-4j7x-8x44/GHSA-574c-4j7x-8x44.json | 8 ++------ .../05/GHSA-57f7-3g6g-rwhr/GHSA-57f7-3g6g-rwhr.json | 12 +++--------- .../05/GHSA-57jh-54r4-h5x5/GHSA-57jh-54r4-h5x5.json | 12 +++--------- .../05/GHSA-58gq-w922-g4r3/GHSA-58gq-w922-g4r3.json | 4 +--- .../05/GHSA-596g-3hr3-g6jr/GHSA-596g-3hr3-g6jr.json | 12 +++--------- .../05/GHSA-5975-gjm3-px87/GHSA-5975-gjm3-px87.json | 12 +++--------- .../05/GHSA-59fx-725p-7v33/GHSA-59fx-725p-7v33.json | 12 +++--------- .../05/GHSA-5chj-x66r-7pp7/GHSA-5chj-x66r-7pp7.json | 8 ++------ .../05/GHSA-5mv6-488r-v66h/GHSA-5mv6-488r-v66h.json | 8 ++------ .../05/GHSA-5p3f-pvrx-fr9p/GHSA-5p3f-pvrx-fr9p.json | 12 +++--------- .../05/GHSA-5pf2-53q8-pj6c/GHSA-5pf2-53q8-pj6c.json | 12 +++--------- .../05/GHSA-5v5r-fxmr-wmpv/GHSA-5v5r-fxmr-wmpv.json | 12 +++--------- .../05/GHSA-5vp4-9q2j-p8f9/GHSA-5vp4-9q2j-p8f9.json | 12 +++--------- .../05/GHSA-5w4q-5c4v-rhrm/GHSA-5w4q-5c4v-rhrm.json | 8 ++------ .../05/GHSA-636c-p97j-wvv8/GHSA-636c-p97j-wvv8.json | 12 +++--------- .../05/GHSA-637w-622v-jh63/GHSA-637w-622v-jh63.json | 12 +++--------- .../05/GHSA-63gg-x38q-g49x/GHSA-63gg-x38q-g49x.json | 12 +++--------- .../05/GHSA-64fg-mcxw-p5ww/GHSA-64fg-mcxw-p5ww.json | 12 +++--------- .../05/GHSA-66f6-j4qh-gpfh/GHSA-66f6-j4qh-gpfh.json | 8 ++------ .../05/GHSA-676j-vqr4-6w3h/GHSA-676j-vqr4-6w3h.json | 4 +--- .../05/GHSA-67rg-fq6q-r5cf/GHSA-67rg-fq6q-r5cf.json | 12 +++--------- .../05/GHSA-689r-q44r-f9rq/GHSA-689r-q44r-f9rq.json | 8 ++------ .../05/GHSA-68gc-2m5p-7376/GHSA-68gc-2m5p-7376.json | 8 ++------ .../05/GHSA-68x7-9v8m-4jrv/GHSA-68x7-9v8m-4jrv.json | 8 ++------ .../05/GHSA-6925-92m9-84w6/GHSA-6925-92m9-84w6.json | 12 +++--------- .../05/GHSA-6929-p5cx-qmg5/GHSA-6929-p5cx-qmg5.json | 12 +++--------- .../05/GHSA-698p-4j7j-49fx/GHSA-698p-4j7j-49fx.json | 12 +++--------- .../05/GHSA-6c2p-9hhc-8hc8/GHSA-6c2p-9hhc-8hc8.json | 12 +++--------- .../05/GHSA-6gmh-pw6w-cww4/GHSA-6gmh-pw6w-cww4.json | 4 +--- .../05/GHSA-6h5p-h3h7-6vpp/GHSA-6h5p-h3h7-6vpp.json | 12 +++--------- .../05/GHSA-6hf9-2c4c-m4j4/GHSA-6hf9-2c4c-m4j4.json | 12 +++--------- .../05/GHSA-6j42-h33x-2c8v/GHSA-6j42-h33x-2c8v.json | 12 +++--------- .../05/GHSA-6j89-cjff-693q/GHSA-6j89-cjff-693q.json | 12 +++--------- .../05/GHSA-6j9g-q4qp-mq4x/GHSA-6j9g-q4qp-mq4x.json | 8 ++------ .../05/GHSA-6jw7-r2qx-ffpf/GHSA-6jw7-r2qx-ffpf.json | 12 +++--------- .../05/GHSA-6mjj-xrpg-96vg/GHSA-6mjj-xrpg-96vg.json | 8 ++------ .../05/GHSA-6p27-p48f-vh67/GHSA-6p27-p48f-vh67.json | 8 ++------ .../05/GHSA-6pc5-ccr3-mpqp/GHSA-6pc5-ccr3-mpqp.json | 4 +--- .../05/GHSA-6pv9-5752-c3xg/GHSA-6pv9-5752-c3xg.json | 4 +--- .../05/GHSA-6wrp-x54h-p8g6/GHSA-6wrp-x54h-p8g6.json | 12 +++--------- .../05/GHSA-6wx3-3pp4-7q95/GHSA-6wx3-3pp4-7q95.json | 4 +--- .../05/GHSA-6x26-67wc-v4f7/GHSA-6x26-67wc-v4f7.json | 12 +++--------- .../05/GHSA-6x62-3gfm-2xvv/GHSA-6x62-3gfm-2xvv.json | 8 ++------ .../05/GHSA-72g9-2j95-6787/GHSA-72g9-2j95-6787.json | 8 ++------ .../05/GHSA-72mg-2w2h-2qqq/GHSA-72mg-2w2h-2qqq.json | 8 ++------ .../05/GHSA-739r-mw5v-58r2/GHSA-739r-mw5v-58r2.json | 12 +++--------- .../05/GHSA-73g2-m4v3-6c2h/GHSA-73g2-m4v3-6c2h.json | 8 ++------ .../05/GHSA-75j8-p3jh-jwj6/GHSA-75j8-p3jh-jwj6.json | 12 +++--------- .../05/GHSA-773f-f929-qgjj/GHSA-773f-f929-qgjj.json | 8 ++------ .../05/GHSA-775r-4pcv-6q97/GHSA-775r-4pcv-6q97.json | 8 ++------ .../05/GHSA-7822-rrh7-pwm7/GHSA-7822-rrh7-pwm7.json | 12 +++--------- .../05/GHSA-7855-9v87-wfg5/GHSA-7855-9v87-wfg5.json | 12 +++--------- .../05/GHSA-789c-r6w2-66gw/GHSA-789c-r6w2-66gw.json | 4 +--- .../05/GHSA-79wh-vc9g-6xpc/GHSA-79wh-vc9g-6xpc.json | 12 +++--------- .../05/GHSA-7c76-fmgr-wqq7/GHSA-7c76-fmgr-wqq7.json | 8 ++------ .../05/GHSA-7f3r-v9w2-q5pm/GHSA-7f3r-v9w2-q5pm.json | 8 ++------ .../05/GHSA-7fmj-8v6q-jrwf/GHSA-7fmj-8v6q-jrwf.json | 12 +++--------- .../05/GHSA-7fxc-wh73-vhv8/GHSA-7fxc-wh73-vhv8.json | 8 ++------ .../05/GHSA-7gxm-25cp-2h59/GHSA-7gxm-25cp-2h59.json | 8 ++------ .../05/GHSA-7hcv-63gc-jpmm/GHSA-7hcv-63gc-jpmm.json | 12 +++--------- .../05/GHSA-7hpv-rcx2-vjx9/GHSA-7hpv-rcx2-vjx9.json | 12 +++--------- .../05/GHSA-7j2j-qc6h-m8h2/GHSA-7j2j-qc6h-m8h2.json | 12 +++--------- .../05/GHSA-7mxf-255f-8cvv/GHSA-7mxf-255f-8cvv.json | 8 ++------ .../05/GHSA-7prc-v6jr-7frc/GHSA-7prc-v6jr-7frc.json | 12 +++--------- .../05/GHSA-7prw-wc7c-g95v/GHSA-7prw-wc7c-g95v.json | 12 +++--------- .../05/GHSA-7rj2-cq4p-3wqr/GHSA-7rj2-cq4p-3wqr.json | 8 ++------ .../05/GHSA-7rxf-2gc2-527c/GHSA-7rxf-2gc2-527c.json | 8 ++------ .../05/GHSA-7vrg-q6mv-3q9x/GHSA-7vrg-q6mv-3q9x.json | 12 +++--------- .../05/GHSA-7wcr-m98q-w3q3/GHSA-7wcr-m98q-w3q3.json | 8 ++------ .../05/GHSA-7x97-rv2f-vj3r/GHSA-7x97-rv2f-vj3r.json | 8 ++------ .../05/GHSA-82f7-mq8m-2w9x/GHSA-82f7-mq8m-2w9x.json | 12 +++--------- .../05/GHSA-82jm-c3f2-7937/GHSA-82jm-c3f2-7937.json | 4 +--- .../05/GHSA-83v9-v5rx-wg6x/GHSA-83v9-v5rx-wg6x.json | 12 +++--------- .../05/GHSA-849p-5hj4-w47q/GHSA-849p-5hj4-w47q.json | 4 +--- .../05/GHSA-84j4-ccmw-hwpg/GHSA-84j4-ccmw-hwpg.json | 8 ++------ .../05/GHSA-85jc-qvvj-q8jw/GHSA-85jc-qvvj-q8jw.json | 8 ++------ .../05/GHSA-875h-7jq2-c5fp/GHSA-875h-7jq2-c5fp.json | 12 +++--------- .../05/GHSA-8848-7789-w387/GHSA-8848-7789-w387.json | 12 +++--------- .../05/GHSA-88gc-h5ch-vcch/GHSA-88gc-h5ch-vcch.json | 12 +++--------- .../05/GHSA-8922-85wm-q7vh/GHSA-8922-85wm-q7vh.json | 12 +++--------- .../05/GHSA-89fj-r9xp-r6c9/GHSA-89fj-r9xp-r6c9.json | 12 +++--------- .../05/GHSA-8c2f-jx3v-cm8h/GHSA-8c2f-jx3v-cm8h.json | 4 +--- .../05/GHSA-8f34-ccvf-c6jf/GHSA-8f34-ccvf-c6jf.json | 12 +++--------- .../05/GHSA-8g54-6pcx-c3vq/GHSA-8g54-6pcx-c3vq.json | 12 +++--------- .../05/GHSA-8h7f-c83v-885w/GHSA-8h7f-c83v-885w.json | 12 +++--------- .../05/GHSA-8h98-4756-r8r4/GHSA-8h98-4756-r8r4.json | 8 ++------ .../05/GHSA-8hff-gxvr-v39f/GHSA-8hff-gxvr-v39f.json | 4 +--- .../05/GHSA-8qwq-9r56-cp3v/GHSA-8qwq-9r56-cp3v.json | 8 ++------ .../05/GHSA-8rj5-wwmx-vj53/GHSA-8rj5-wwmx-vj53.json | 4 +--- .../05/GHSA-8rm3-jg2c-hvfh/GHSA-8rm3-jg2c-hvfh.json | 4 +--- .../05/GHSA-8rph-mpfm-vxvh/GHSA-8rph-mpfm-vxvh.json | 8 ++------ .../05/GHSA-8v2w-6qhm-pxp7/GHSA-8v2w-6qhm-pxp7.json | 8 ++------ .../05/GHSA-8w7m-j7xw-2xc9/GHSA-8w7m-j7xw-2xc9.json | 12 +++--------- .../05/GHSA-8x83-r79c-88mg/GHSA-8x83-r79c-88mg.json | 12 +++--------- .../05/GHSA-8xhv-724q-h3f3/GHSA-8xhv-724q-h3f3.json | 12 +++--------- .../05/GHSA-9275-c4xq-9m4g/GHSA-9275-c4xq-9m4g.json | 12 +++--------- .../05/GHSA-9397-r359-47hx/GHSA-9397-r359-47hx.json | 8 ++------ .../05/GHSA-93qf-3vmf-gxvm/GHSA-93qf-3vmf-gxvm.json | 12 +++--------- .../05/GHSA-93r3-cg65-gvx6/GHSA-93r3-cg65-gvx6.json | 8 ++------ .../05/GHSA-96qc-rwrq-72pr/GHSA-96qc-rwrq-72pr.json | 12 +++--------- .../05/GHSA-97xf-5qr7-4cw3/GHSA-97xf-5qr7-4cw3.json | 12 +++--------- .../05/GHSA-989v-c64c-jq57/GHSA-989v-c64c-jq57.json | 12 +++--------- .../05/GHSA-98qh-xxww-5r96/GHSA-98qh-xxww-5r96.json | 12 +++--------- .../05/GHSA-993c-67fv-pmjq/GHSA-993c-67fv-pmjq.json | 8 ++------ .../05/GHSA-9fqw-5vfg-2mfq/GHSA-9fqw-5vfg-2mfq.json | 12 +++--------- .../05/GHSA-9fv5-j7w3-ph59/GHSA-9fv5-j7w3-ph59.json | 12 +++--------- .../05/GHSA-9fvq-rcpx-h4hh/GHSA-9fvq-rcpx-h4hh.json | 8 ++------ .../05/GHSA-9g7m-mw8w-mqc5/GHSA-9g7m-mw8w-mqc5.json | 8 ++------ .../05/GHSA-9gp9-35p2-qvpw/GHSA-9gp9-35p2-qvpw.json | 12 +++--------- .../05/GHSA-9gvc-6g9v-v5rp/GHSA-9gvc-6g9v-v5rp.json | 8 ++------ .../05/GHSA-9mm4-gp88-mrch/GHSA-9mm4-gp88-mrch.json | 8 ++------ .../05/GHSA-9q3x-qq6c-v6jx/GHSA-9q3x-qq6c-v6jx.json | 8 ++------ .../05/GHSA-9qhv-29p6-wwp6/GHSA-9qhv-29p6-wwp6.json | 8 ++------ .../05/GHSA-9qx8-h7w2-x7mp/GHSA-9qx8-h7w2-x7mp.json | 12 +++--------- .../05/GHSA-9rh6-9x9j-x842/GHSA-9rh6-9x9j-x842.json | 8 ++------ .../05/GHSA-9rmg-8r3f-xrq7/GHSA-9rmg-8r3f-xrq7.json | 4 +--- .../05/GHSA-9v5f-rvh9-wc7c/GHSA-9v5f-rvh9-wc7c.json | 12 +++--------- .../05/GHSA-9v6x-99vx-fw68/GHSA-9v6x-99vx-fw68.json | 12 +++--------- .../05/GHSA-9w6w-9279-x57j/GHSA-9w6w-9279-x57j.json | 8 ++------ .../05/GHSA-9w82-5jc2-rr7m/GHSA-9w82-5jc2-rr7m.json | 12 +++--------- .../05/GHSA-9xqg-wjcv-qqxq/GHSA-9xqg-wjcv-qqxq.json | 4 +--- .../05/GHSA-c2pp-46rf-cqg2/GHSA-c2pp-46rf-cqg2.json | 4 +--- .../05/GHSA-c2w5-xj35-qmx4/GHSA-c2w5-xj35-qmx4.json | 8 ++------ .../05/GHSA-c3h3-5867-mxh8/GHSA-c3h3-5867-mxh8.json | 12 +++--------- .../05/GHSA-c4r5-4x67-4w7c/GHSA-c4r5-4x67-4w7c.json | 12 +++--------- .../05/GHSA-c5v9-3j87-cvp7/GHSA-c5v9-3j87-cvp7.json | 12 +++--------- .../05/GHSA-c683-386m-9r6m/GHSA-c683-386m-9r6m.json | 12 +++--------- .../05/GHSA-c6v6-mvg4-h5hx/GHSA-c6v6-mvg4-h5hx.json | 4 +--- .../05/GHSA-c743-9hfh-9968/GHSA-c743-9hfh-9968.json | 12 +++--------- .../05/GHSA-c85x-m577-qjhw/GHSA-c85x-m577-qjhw.json | 8 ++------ .../05/GHSA-c93v-xv7q-4w4c/GHSA-c93v-xv7q-4w4c.json | 4 +--- .../05/GHSA-c9q3-58pp-r6v9/GHSA-c9q3-58pp-r6v9.json | 8 ++------ .../05/GHSA-c9vp-hrfr-vhvj/GHSA-c9vp-hrfr-vhvj.json | 12 +++--------- .../05/GHSA-cc6p-97f5-f8v5/GHSA-cc6p-97f5-f8v5.json | 12 +++--------- .../05/GHSA-cc7x-rwq6-84vw/GHSA-cc7x-rwq6-84vw.json | 12 +++--------- .../05/GHSA-cf89-hfgx-84qg/GHSA-cf89-hfgx-84qg.json | 8 ++------ .../05/GHSA-cf9m-v68h-2766/GHSA-cf9m-v68h-2766.json | 12 +++--------- .../05/GHSA-cfp9-244f-h66c/GHSA-cfp9-244f-h66c.json | 8 ++------ .../05/GHSA-cjff-rmqv-m6mx/GHSA-cjff-rmqv-m6mx.json | 8 ++------ .../05/GHSA-cjqq-8xv6-575p/GHSA-cjqq-8xv6-575p.json | 4 +--- .../05/GHSA-cmjj-xxq8-8mvx/GHSA-cmjj-xxq8-8mvx.json | 12 +++--------- .../05/GHSA-crqp-mv88-vcm6/GHSA-crqp-mv88-vcm6.json | 8 ++------ .../05/GHSA-crrc-w592-ff65/GHSA-crrc-w592-ff65.json | 12 +++--------- .../05/GHSA-crvx-qrfr-h2c3/GHSA-crvx-qrfr-h2c3.json | 12 +++--------- .../05/GHSA-cvr9-hv4p-wfcw/GHSA-cvr9-hv4p-wfcw.json | 12 +++--------- .../05/GHSA-cw48-h2hv-c97j/GHSA-cw48-h2hv-c97j.json | 12 +++--------- .../05/GHSA-cwh6-w644-6v8q/GHSA-cwh6-w644-6v8q.json | 12 +++--------- .../05/GHSA-cx3p-94m9-cwxv/GHSA-cx3p-94m9-cwxv.json | 12 +++--------- .../05/GHSA-cx89-wvj2-xr57/GHSA-cx89-wvj2-xr57.json | 8 ++------ .../05/GHSA-f35f-35hv-6fqx/GHSA-f35f-35hv-6fqx.json | 12 +++--------- .../05/GHSA-f3ch-8xx9-vh6w/GHSA-f3ch-8xx9-vh6w.json | 12 +++--------- .../05/GHSA-f4hm-h8qw-mxvc/GHSA-f4hm-h8qw-mxvc.json | 8 ++------ .../05/GHSA-f4j6-89m7-5455/GHSA-f4j6-89m7-5455.json | 12 +++--------- .../05/GHSA-f65h-hwp6-2vff/GHSA-f65h-hwp6-2vff.json | 12 +++--------- .../05/GHSA-f6v8-7355-p32v/GHSA-f6v8-7355-p32v.json | 8 ++------ .../05/GHSA-f75r-mrmx-746p/GHSA-f75r-mrmx-746p.json | 12 +++--------- .../05/GHSA-f8wm-8xgf-589m/GHSA-f8wm-8xgf-589m.json | 12 +++--------- .../05/GHSA-f98w-46q5-27jx/GHSA-f98w-46q5-27jx.json | 8 ++------ .../05/GHSA-fc7c-rcm4-rg4c/GHSA-fc7c-rcm4-rg4c.json | 12 +++--------- .../05/GHSA-fc8w-q5c3-5m5f/GHSA-fc8w-q5c3-5m5f.json | 12 +++--------- .../05/GHSA-ff89-95cf-8ph8/GHSA-ff89-95cf-8ph8.json | 12 +++--------- .../05/GHSA-fg49-r89g-929j/GHSA-fg49-r89g-929j.json | 12 +++--------- .../05/GHSA-fg77-pcc5-vccg/GHSA-fg77-pcc5-vccg.json | 12 +++--------- .../05/GHSA-fgp4-fc5g-6f22/GHSA-fgp4-fc5g-6f22.json | 12 +++--------- .../05/GHSA-fgp5-4x9f-m743/GHSA-fgp5-4x9f-m743.json | 12 +++--------- .../05/GHSA-fh59-cj56-8q9p/GHSA-fh59-cj56-8q9p.json | 12 +++--------- .../05/GHSA-fh77-2jcj-5hq7/GHSA-fh77-2jcj-5hq7.json | 12 +++--------- .../05/GHSA-fhfv-jf9p-qv4g/GHSA-fhfv-jf9p-qv4g.json | 12 +++--------- .../05/GHSA-fjjv-vm6w-5mgj/GHSA-fjjv-vm6w-5mgj.json | 12 +++--------- .../05/GHSA-fjvc-pwrq-34wq/GHSA-fjvc-pwrq-34wq.json | 12 +++--------- .../05/GHSA-fmgx-83vj-44hh/GHSA-fmgx-83vj-44hh.json | 12 +++--------- .../05/GHSA-fmj5-xxrq-8cg3/GHSA-fmj5-xxrq-8cg3.json | 12 +++--------- .../05/GHSA-fpxw-h673-x56j/GHSA-fpxw-h673-x56j.json | 12 +++--------- .../05/GHSA-fqx8-r72c-v8q3/GHSA-fqx8-r72c-v8q3.json | 12 +++--------- .../05/GHSA-frm2-v695-xcw7/GHSA-frm2-v695-xcw7.json | 8 ++------ .../05/GHSA-frqw-rmjg-h7x3/GHSA-frqw-rmjg-h7x3.json | 8 ++------ .../05/GHSA-fv6p-x8x2-5jcc/GHSA-fv6p-x8x2-5jcc.json | 4 +--- .../05/GHSA-fw45-wg5f-8735/GHSA-fw45-wg5f-8735.json | 12 +++--------- .../05/GHSA-fw7j-849m-mpv4/GHSA-fw7j-849m-mpv4.json | 4 +--- .../05/GHSA-fwh4-xh88-xxmp/GHSA-fwh4-xh88-xxmp.json | 12 +++--------- .../05/GHSA-fx28-fjmc-jx5r/GHSA-fx28-fjmc-jx5r.json | 8 ++------ .../05/GHSA-g2m6-f6m6-qjg5/GHSA-g2m6-f6m6-qjg5.json | 8 ++------ .../05/GHSA-g3r4-m5pw-xpp9/GHSA-g3r4-m5pw-xpp9.json | 12 +++--------- .../05/GHSA-g464-q8qp-3vg4/GHSA-g464-q8qp-3vg4.json | 8 ++------ .../05/GHSA-g4pp-mvp2-qf9j/GHSA-g4pp-mvp2-qf9j.json | 12 +++--------- .../05/GHSA-g587-x8m2-frwg/GHSA-g587-x8m2-frwg.json | 4 +--- .../05/GHSA-g5ww-c573-jq43/GHSA-g5ww-c573-jq43.json | 12 +++--------- .../05/GHSA-g655-76mw-qxpx/GHSA-g655-76mw-qxpx.json | 12 +++--------- .../05/GHSA-g66h-pm5j-hvrm/GHSA-g66h-pm5j-hvrm.json | 8 ++------ .../05/GHSA-g672-q742-m6vg/GHSA-g672-q742-m6vg.json | 12 +++--------- .../05/GHSA-g69r-p4mx-3r83/GHSA-g69r-p4mx-3r83.json | 4 +--- .../05/GHSA-g6x5-mv8j-5pq8/GHSA-g6x5-mv8j-5pq8.json | 12 +++--------- .../05/GHSA-g8gr-9g9f-c52h/GHSA-g8gr-9g9f-c52h.json | 4 +--- .../05/GHSA-g8qr-xv6v-97fw/GHSA-g8qr-xv6v-97fw.json | 8 ++------ .../05/GHSA-g8x9-c837-mpx5/GHSA-g8x9-c837-mpx5.json | 12 +++--------- .../05/GHSA-g9mj-m82f-cqc8/GHSA-g9mj-m82f-cqc8.json | 12 +++--------- .../05/GHSA-gg7c-xf3j-7669/GHSA-gg7c-xf3j-7669.json | 12 +++--------- .../05/GHSA-gh8m-4j9x-6g55/GHSA-gh8m-4j9x-6g55.json | 12 +++--------- .../05/GHSA-ghw7-5298-r4fj/GHSA-ghw7-5298-r4fj.json | 12 +++--------- .../05/GHSA-gjqw-r32j-j6wq/GHSA-gjqw-r32j-j6wq.json | 4 +--- .../05/GHSA-gpcg-4vgv-2224/GHSA-gpcg-4vgv-2224.json | 12 +++--------- .../05/GHSA-gphc-f36c-q273/GHSA-gphc-f36c-q273.json | 12 +++--------- .../05/GHSA-gq32-8f5q-75g2/GHSA-gq32-8f5q-75g2.json | 8 ++------ .../05/GHSA-gqc3-253j-25g7/GHSA-gqc3-253j-25g7.json | 8 ++------ .../05/GHSA-gqf3-7r7j-gmrf/GHSA-gqf3-7r7j-gmrf.json | 12 +++--------- .../05/GHSA-gqq2-f4ch-q2pw/GHSA-gqq2-f4ch-q2pw.json | 12 +++--------- .../05/GHSA-gqr3-72h3-gh3f/GHSA-gqr3-72h3-gh3f.json | 12 +++--------- .../05/GHSA-gr25-37rj-jwmm/GHSA-gr25-37rj-jwmm.json | 12 +++--------- .../05/GHSA-grj8-px67-9rpf/GHSA-grj8-px67-9rpf.json | 12 +++--------- .../05/GHSA-gv84-p8rq-pwr4/GHSA-gv84-p8rq-pwr4.json | 12 +++--------- .../05/GHSA-gvgq-x76m-m83j/GHSA-gvgq-x76m-m83j.json | 8 ++------ .../05/GHSA-gwv8-m93q-xcpc/GHSA-gwv8-m93q-xcpc.json | 12 +++--------- .../05/GHSA-gx29-r9g9-prgp/GHSA-gx29-r9g9-prgp.json | 12 +++--------- .../05/GHSA-h23m-44mr-9m6c/GHSA-h23m-44mr-9m6c.json | 8 ++------ .../05/GHSA-h282-h9wq-4cqg/GHSA-h282-h9wq-4cqg.json | 8 ++------ .../05/GHSA-h3cg-q59m-96g4/GHSA-h3cg-q59m-96g4.json | 8 ++------ .../05/GHSA-h4rm-8p4f-gfh7/GHSA-h4rm-8p4f-gfh7.json | 8 ++------ .../05/GHSA-h5j6-53fx-wcr7/GHSA-h5j6-53fx-wcr7.json | 12 +++--------- .../05/GHSA-h5xc-3wh4-4q43/GHSA-h5xc-3wh4-4q43.json | 12 +++--------- .../05/GHSA-h6fx-jmr6-xg2g/GHSA-h6fx-jmr6-xg2g.json | 4 +--- .../05/GHSA-hccp-6fqj-76m5/GHSA-hccp-6fqj-76m5.json | 8 ++------ .../05/GHSA-hcrv-c4wc-hj94/GHSA-hcrv-c4wc-hj94.json | 12 +++--------- .../05/GHSA-hf7q-w9cp-7xhr/GHSA-hf7q-w9cp-7xhr.json | 8 ++------ .../05/GHSA-hfr2-5qrv-2xpv/GHSA-hfr2-5qrv-2xpv.json | 8 ++------ .../05/GHSA-hg6j-pj42-qfx4/GHSA-hg6j-pj42-qfx4.json | 12 +++--------- .../05/GHSA-hh33-ch53-7qrr/GHSA-hh33-ch53-7qrr.json | 12 +++--------- .../05/GHSA-hhh7-3xf8-52v6/GHSA-hhh7-3xf8-52v6.json | 8 ++------ .../05/GHSA-hj26-rh6r-85r8/GHSA-hj26-rh6r-85r8.json | 4 +--- .../05/GHSA-hj75-p7pw-3fv5/GHSA-hj75-p7pw-3fv5.json | 12 +++--------- .../05/GHSA-hjvc-f345-6395/GHSA-hjvc-f345-6395.json | 12 +++--------- .../05/GHSA-hm27-4fw9-4w6f/GHSA-hm27-4fw9-4w6f.json | 12 +++--------- .../05/GHSA-hpcm-hcj8-c96c/GHSA-hpcm-hcj8-c96c.json | 12 +++--------- .../05/GHSA-hr7c-pjw8-9v89/GHSA-hr7c-pjw8-9v89.json | 12 +++--------- .../05/GHSA-hrqc-2rrc-vr54/GHSA-hrqc-2rrc-vr54.json | 12 +++--------- .../05/GHSA-hrwv-7vp5-r8pf/GHSA-hrwv-7vp5-r8pf.json | 8 ++------ .../05/GHSA-hrxp-m6vj-m2rc/GHSA-hrxp-m6vj-m2rc.json | 8 ++------ .../05/GHSA-hv2p-7mr9-q6gg/GHSA-hv2p-7mr9-q6gg.json | 4 +--- .../05/GHSA-hvc7-h6c3-f6mq/GHSA-hvc7-h6c3-f6mq.json | 12 +++--------- .../05/GHSA-hw2c-wqq9-98qm/GHSA-hw2c-wqq9-98qm.json | 12 +++--------- .../05/GHSA-hwcv-f7qg-ch9g/GHSA-hwcv-f7qg-ch9g.json | 12 +++--------- .../05/GHSA-hwfc-h7h7-q7gp/GHSA-hwfc-h7h7-q7gp.json | 12 +++--------- .../05/GHSA-j29r-h8wr-v5v8/GHSA-j29r-h8wr-v5v8.json | 8 ++------ .../05/GHSA-j334-hj6g-m96m/GHSA-j334-hj6g-m96m.json | 4 +--- .../05/GHSA-j35w-gjxg-946m/GHSA-j35w-gjxg-946m.json | 12 +++--------- .../05/GHSA-j5hv-hr2w-w46g/GHSA-j5hv-hr2w-w46g.json | 12 +++--------- .../05/GHSA-j6cv-ghpp-phc2/GHSA-j6cv-ghpp-phc2.json | 12 +++--------- .../05/GHSA-j74f-6554-w8gh/GHSA-j74f-6554-w8gh.json | 12 +++--------- .../05/GHSA-j773-5h44-w4h6/GHSA-j773-5h44-w4h6.json | 4 +--- .../05/GHSA-j7jp-jhjq-rm3c/GHSA-j7jp-jhjq-rm3c.json | 8 ++------ .../05/GHSA-j7v8-j8px-7phx/GHSA-j7v8-j8px-7phx.json | 12 +++--------- .../05/GHSA-j8c7-28mr-344v/GHSA-j8c7-28mr-344v.json | 8 ++------ .../05/GHSA-j8wq-fvx8-fqfh/GHSA-j8wq-fvx8-fqfh.json | 12 +++--------- .../05/GHSA-j92j-5hg7-f7hx/GHSA-j92j-5hg7-f7hx.json | 12 +++--------- .../05/GHSA-jc9x-w38w-r8hg/GHSA-jc9x-w38w-r8hg.json | 12 +++--------- .../05/GHSA-jccq-8hwf-xp6j/GHSA-jccq-8hwf-xp6j.json | 4 +--- .../05/GHSA-jfc5-j6cj-cj2x/GHSA-jfc5-j6cj-cj2x.json | 8 ++------ .../05/GHSA-jfmh-q68r-88fp/GHSA-jfmh-q68r-88fp.json | 8 ++------ .../05/GHSA-jfr5-5g87-p347/GHSA-jfr5-5g87-p347.json | 8 ++------ .../05/GHSA-jfw2-jwr5-36c3/GHSA-jfw2-jwr5-36c3.json | 12 +++--------- .../05/GHSA-jgfm-rcjw-3pmx/GHSA-jgfm-rcjw-3pmx.json | 4 +--- .../05/GHSA-jgq8-388h-mw24/GHSA-jgq8-388h-mw24.json | 12 +++--------- .../05/GHSA-jgv7-8w3p-77p5/GHSA-jgv7-8w3p-77p5.json | 12 +++--------- .../05/GHSA-jgxm-7vmw-79h7/GHSA-jgxm-7vmw-79h7.json | 4 +--- .../05/GHSA-jh29-7cwf-26xx/GHSA-jh29-7cwf-26xx.json | 12 +++--------- .../05/GHSA-jh2w-2p46-2685/GHSA-jh2w-2p46-2685.json | 12 +++--------- .../05/GHSA-jm92-fqw4-8r6p/GHSA-jm92-fqw4-8r6p.json | 8 ++------ .../05/GHSA-jq6x-7xcv-6267/GHSA-jq6x-7xcv-6267.json | 8 ++------ .../05/GHSA-jv3p-j4h6-73qw/GHSA-jv3p-j4h6-73qw.json | 12 +++--------- .../05/GHSA-jwh5-q83f-2jjc/GHSA-jwh5-q83f-2jjc.json | 4 +--- .../05/GHSA-jwqg-fhhf-42x8/GHSA-jwqg-fhhf-42x8.json | 12 +++--------- .../05/GHSA-jx66-38hf-gj2w/GHSA-jx66-38hf-gj2w.json | 12 +++--------- .../05/GHSA-m2q5-mwp7-c7mq/GHSA-m2q5-mwp7-c7mq.json | 12 +++--------- .../05/GHSA-m2wv-mhjc-g978/GHSA-m2wv-mhjc-g978.json | 12 +++--------- .../05/GHSA-m32c-wxrg-vpxg/GHSA-m32c-wxrg-vpxg.json | 12 +++--------- .../05/GHSA-m3qw-hq38-7qj5/GHSA-m3qw-hq38-7qj5.json | 12 +++--------- .../05/GHSA-m4v3-rhqc-gh4h/GHSA-m4v3-rhqc-gh4h.json | 12 +++--------- .../05/GHSA-m6q7-68x5-3882/GHSA-m6q7-68x5-3882.json | 8 ++------ .../05/GHSA-m7vr-2fp3-h865/GHSA-m7vr-2fp3-h865.json | 8 ++------ .../05/GHSA-m855-9ph3-r6p4/GHSA-m855-9ph3-r6p4.json | 8 ++------ .../05/GHSA-m8j7-9fh7-7c8r/GHSA-m8j7-9fh7-7c8r.json | 12 +++--------- .../05/GHSA-mc3w-m29g-7p95/GHSA-mc3w-m29g-7p95.json | 12 +++--------- .../05/GHSA-mc63-vj63-gr49/GHSA-mc63-vj63-gr49.json | 8 ++------ .../05/GHSA-mg3r-9jh8-33r9/GHSA-mg3r-9jh8-33r9.json | 12 +++--------- .../05/GHSA-mh78-crmf-67j2/GHSA-mh78-crmf-67j2.json | 12 +++--------- .../05/GHSA-mhgv-m547-f82g/GHSA-mhgv-m547-f82g.json | 12 +++--------- .../05/GHSA-mhm7-fjjw-2fgr/GHSA-mhm7-fjjw-2fgr.json | 8 ++------ .../05/GHSA-mjhm-wvpj-x6hc/GHSA-mjhm-wvpj-x6hc.json | 12 +++--------- .../05/GHSA-mjwg-frjf-m53m/GHSA-mjwg-frjf-m53m.json | 12 +++--------- .../05/GHSA-mmg6-qg4h-p87j/GHSA-mmg6-qg4h-p87j.json | 12 +++--------- .../05/GHSA-mph7-jw9x-c242/GHSA-mph7-jw9x-c242.json | 12 +++--------- .../05/GHSA-mq2p-3w9c-34j8/GHSA-mq2p-3w9c-34j8.json | 12 +++--------- .../05/GHSA-mq62-3882-pq59/GHSA-mq62-3882-pq59.json | 12 +++--------- .../05/GHSA-mr9w-f6pg-jp2v/GHSA-mr9w-f6pg-jp2v.json | 8 ++------ .../05/GHSA-mw2x-vj87-7rxr/GHSA-mw2x-vj87-7rxr.json | 12 +++--------- .../05/GHSA-mxm2-76x3-3frq/GHSA-mxm2-76x3-3frq.json | 12 +++--------- .../05/GHSA-p23h-x6wc-8w4g/GHSA-p23h-x6wc-8w4g.json | 4 +--- .../05/GHSA-p2c2-jv92-hvch/GHSA-p2c2-jv92-hvch.json | 12 +++--------- .../05/GHSA-p2m9-83f8-9277/GHSA-p2m9-83f8-9277.json | 8 ++------ .../05/GHSA-p2xq-9789-ph6p/GHSA-p2xq-9789-ph6p.json | 12 +++--------- .../05/GHSA-p4c4-cqrr-xxhq/GHSA-p4c4-cqrr-xxhq.json | 8 ++------ .../05/GHSA-p5pr-qp45-63pf/GHSA-p5pr-qp45-63pf.json | 12 +++--------- .../05/GHSA-p5v3-7243-m33v/GHSA-p5v3-7243-m33v.json | 12 +++--------- .../05/GHSA-p634-9p2p-jq6r/GHSA-p634-9p2p-jq6r.json | 12 +++--------- .../05/GHSA-p6hv-349c-8qpj/GHSA-p6hv-349c-8qpj.json | 8 ++------ .../05/GHSA-p7p7-mm6x-7q2p/GHSA-p7p7-mm6x-7q2p.json | 12 +++--------- .../05/GHSA-p8wr-hxwm-p363/GHSA-p8wr-hxwm-p363.json | 12 +++--------- .../05/GHSA-p9c5-ggpr-4rpq/GHSA-p9c5-ggpr-4rpq.json | 8 ++------ .../05/GHSA-p9mv-7pgj-886r/GHSA-p9mv-7pgj-886r.json | 12 +++--------- .../05/GHSA-pf9w-9r28-c4x6/GHSA-pf9w-9r28-c4x6.json | 8 ++------ .../05/GHSA-pg7h-v386-fw8h/GHSA-pg7h-v386-fw8h.json | 4 +--- .../05/GHSA-pg9j-r44q-jhmf/GHSA-pg9j-r44q-jhmf.json | 12 +++--------- .../05/GHSA-pgp4-m4pc-4jr6/GHSA-pgp4-m4pc-4jr6.json | 8 ++------ .../05/GHSA-pgrg-v7x5-jj2w/GHSA-pgrg-v7x5-jj2w.json | 12 +++--------- .../05/GHSA-phhf-gj3g-w9rj/GHSA-phhf-gj3g-w9rj.json | 12 +++--------- .../05/GHSA-pjx6-jj7c-74m7/GHSA-pjx6-jj7c-74m7.json | 4 +--- .../05/GHSA-pmxc-pvr4-wcxp/GHSA-pmxc-pvr4-wcxp.json | 12 +++--------- .../05/GHSA-pp6j-7q29-2wxx/GHSA-pp6j-7q29-2wxx.json | 4 +--- .../05/GHSA-pwjv-ccmv-j29q/GHSA-pwjv-ccmv-j29q.json | 12 +++--------- .../05/GHSA-pwwq-q65q-v9q6/GHSA-pwwq-q65q-v9q6.json | 8 ++------ .../05/GHSA-px6h-7v38-8hhr/GHSA-px6h-7v38-8hhr.json | 12 +++--------- .../05/GHSA-pxj3-7mxw-535w/GHSA-pxj3-7mxw-535w.json | 12 +++--------- .../05/GHSA-q2mw-237c-cpjv/GHSA-q2mw-237c-cpjv.json | 8 ++------ .../05/GHSA-q2qc-9pjq-74f3/GHSA-q2qc-9pjq-74f3.json | 12 +++--------- .../05/GHSA-q3cq-7q8h-4w5c/GHSA-q3cq-7q8h-4w5c.json | 12 +++--------- .../05/GHSA-q3pf-hhq3-r6v2/GHSA-q3pf-hhq3-r6v2.json | 12 +++--------- .../05/GHSA-q3xf-jx9c-m8c9/GHSA-q3xf-jx9c-m8c9.json | 12 +++--------- .../05/GHSA-q62q-9vgf-p9j3/GHSA-q62q-9vgf-p9j3.json | 4 +--- .../05/GHSA-q694-5rvh-m24r/GHSA-q694-5rvh-m24r.json | 8 ++------ .../05/GHSA-q6x3-474p-vpgf/GHSA-q6x3-474p-vpgf.json | 12 +++--------- .../05/GHSA-q7fc-v93r-h333/GHSA-q7fc-v93r-h333.json | 8 ++------ .../05/GHSA-q7r4-p4gw-mfp9/GHSA-q7r4-p4gw-mfp9.json | 12 +++--------- .../05/GHSA-q847-89jp-97gr/GHSA-q847-89jp-97gr.json | 12 +++--------- .../05/GHSA-q86m-xf2x-qj8j/GHSA-q86m-xf2x-qj8j.json | 4 +--- .../05/GHSA-q8w4-7mqg-63h9/GHSA-q8w4-7mqg-63h9.json | 12 +++--------- .../05/GHSA-q9jr-wwq5-4qxm/GHSA-q9jr-wwq5-4qxm.json | 8 ++------ .../05/GHSA-qg4c-57xc-qmr9/GHSA-qg4c-57xc-qmr9.json | 12 +++--------- .../05/GHSA-qm53-rcwv-78qc/GHSA-qm53-rcwv-78qc.json | 12 +++--------- .../05/GHSA-qpc7-j67r-rgx7/GHSA-qpc7-j67r-rgx7.json | 12 +++--------- .../05/GHSA-qphx-chwr-chm3/GHSA-qphx-chwr-chm3.json | 12 +++--------- .../05/GHSA-qq86-2628-gqpg/GHSA-qq86-2628-gqpg.json | 12 +++--------- .../05/GHSA-qq9w-3xhq-6rxf/GHSA-qq9w-3xhq-6rxf.json | 8 ++------ .../05/GHSA-qrhw-r9hg-cwcm/GHSA-qrhw-r9hg-cwcm.json | 4 +--- .../05/GHSA-qrj4-928f-f3h2/GHSA-qrj4-928f-f3h2.json | 4 +--- .../05/GHSA-qrqv-r3qh-3qch/GHSA-qrqv-r3qh-3qch.json | 8 ++------ .../05/GHSA-qvcv-qmqr-mm5j/GHSA-qvcv-qmqr-mm5j.json | 12 +++--------- .../05/GHSA-qvh7-2qrg-6v75/GHSA-qvh7-2qrg-6v75.json | 4 +--- .../05/GHSA-qwh3-64hp-pv93/GHSA-qwh3-64hp-pv93.json | 12 +++--------- .../05/GHSA-qwmp-427r-mgjp/GHSA-qwmp-427r-mgjp.json | 12 +++--------- .../05/GHSA-qww4-6xrg-jp26/GHSA-qww4-6xrg-jp26.json | 12 +++--------- .../05/GHSA-qx8g-5v5g-5jwf/GHSA-qx8g-5v5g-5jwf.json | 12 +++--------- .../05/GHSA-qxp2-p463-6f3f/GHSA-qxp2-p463-6f3f.json | 8 ++------ .../05/GHSA-r234-xxf3-j66w/GHSA-r234-xxf3-j66w.json | 12 +++--------- .../05/GHSA-r3xc-9hm9-gf29/GHSA-r3xc-9hm9-gf29.json | 8 ++------ .../05/GHSA-r57g-7g9f-4m59/GHSA-r57g-7g9f-4m59.json | 12 +++--------- .../05/GHSA-r5f8-qh3m-c2jv/GHSA-r5f8-qh3m-c2jv.json | 12 +++--------- .../05/GHSA-r5qv-ggx3-m45h/GHSA-r5qv-ggx3-m45h.json | 12 +++--------- .../05/GHSA-r659-cjpw-fq42/GHSA-r659-cjpw-fq42.json | 8 ++------ .../05/GHSA-r8h6-7wjg-5hcv/GHSA-r8h6-7wjg-5hcv.json | 8 ++------ .../05/GHSA-r8r8-pg44-2g9h/GHSA-r8r8-pg44-2g9h.json | 12 +++--------- .../05/GHSA-r928-prgx-2wf8/GHSA-r928-prgx-2wf8.json | 12 +++--------- .../05/GHSA-r9h3-wq94-qjg7/GHSA-r9h3-wq94-qjg7.json | 12 +++--------- .../05/GHSA-r9w3-8xmh-6j5v/GHSA-r9w3-8xmh-6j5v.json | 12 +++--------- .../05/GHSA-rc2g-mp7j-69r8/GHSA-rc2g-mp7j-69r8.json | 12 +++--------- .../05/GHSA-rc79-v6cr-35gr/GHSA-rc79-v6cr-35gr.json | 12 +++--------- .../05/GHSA-rcxr-7wqj-r3gh/GHSA-rcxr-7wqj-r3gh.json | 8 ++------ .../05/GHSA-rf74-pjr5-fx8f/GHSA-rf74-pjr5-fx8f.json | 12 +++--------- .../05/GHSA-rfp5-cghp-26q7/GHSA-rfp5-cghp-26q7.json | 12 +++--------- .../05/GHSA-rg4w-pmq3-w38h/GHSA-rg4w-pmq3-w38h.json | 8 ++------ .../05/GHSA-rjjr-9j82-pc8r/GHSA-rjjr-9j82-pc8r.json | 8 ++------ .../05/GHSA-rjmm-h25r-cqxf/GHSA-rjmm-h25r-cqxf.json | 8 ++------ .../05/GHSA-rjp2-9xwv-c3mp/GHSA-rjp2-9xwv-c3mp.json | 8 ++------ .../05/GHSA-rm33-h23j-qcgg/GHSA-rm33-h23j-qcgg.json | 12 +++--------- .../05/GHSA-rp99-4vgc-7q2h/GHSA-rp99-4vgc-7q2h.json | 8 ++------ .../05/GHSA-rprf-22xr-7gr9/GHSA-rprf-22xr-7gr9.json | 12 +++--------- .../05/GHSA-rprg-5xpx-hm4h/GHSA-rprg-5xpx-hm4h.json | 12 +++--------- .../05/GHSA-rvvc-h3jc-25vx/GHSA-rvvc-h3jc-25vx.json | 12 +++--------- .../05/GHSA-rw25-fj2c-r3cf/GHSA-rw25-fj2c-r3cf.json | 12 +++--------- .../05/GHSA-rxjg-qv62-7h6c/GHSA-rxjg-qv62-7h6c.json | 8 ++------ .../05/GHSA-v24j-qh4f-h3p9/GHSA-v24j-qh4f-h3p9.json | 12 +++--------- .../05/GHSA-v332-vxq6-2g47/GHSA-v332-vxq6-2g47.json | 8 ++------ .../05/GHSA-v3rv-628p-7xrq/GHSA-v3rv-628p-7xrq.json | 4 +--- .../05/GHSA-v4f9-rmvp-3fj3/GHSA-v4f9-rmvp-3fj3.json | 8 ++------ .../05/GHSA-v4pf-jxx8-c862/GHSA-v4pf-jxx8-c862.json | 8 ++------ .../05/GHSA-v5xw-43vp-r66x/GHSA-v5xw-43vp-r66x.json | 12 +++--------- .../05/GHSA-v6ph-x2c7-6g37/GHSA-v6ph-x2c7-6g37.json | 4 +--- .../05/GHSA-v7ff-8293-rf9q/GHSA-v7ff-8293-rf9q.json | 12 +++--------- .../05/GHSA-v827-8qrw-cxmg/GHSA-v827-8qrw-cxmg.json | 8 ++------ .../05/GHSA-v88m-pxx4-rpwh/GHSA-v88m-pxx4-rpwh.json | 12 +++--------- .../05/GHSA-v8hv-78vf-x9fr/GHSA-v8hv-78vf-x9fr.json | 4 +--- .../05/GHSA-v8pj-w2gf-97p5/GHSA-v8pj-w2gf-97p5.json | 12 +++--------- .../05/GHSA-v8pq-r8j2-c95m/GHSA-v8pq-r8j2-c95m.json | 12 +++--------- .../05/GHSA-v9pw-w8q4-wvjx/GHSA-v9pw-w8q4-wvjx.json | 8 ++------ .../05/GHSA-vf2p-4grj-v3x6/GHSA-vf2p-4grj-v3x6.json | 12 +++--------- .../05/GHSA-vfjj-qc2j-f9fm/GHSA-vfjj-qc2j-f9fm.json | 8 ++------ .../05/GHSA-vg2x-vv9h-gh22/GHSA-vg2x-vv9h-gh22.json | 8 ++------ .../05/GHSA-vgr6-5xvp-97cc/GHSA-vgr6-5xvp-97cc.json | 12 +++--------- .../05/GHSA-vjmv-w2p6-c95q/GHSA-vjmv-w2p6-c95q.json | 8 ++------ .../05/GHSA-vm7p-7vqv-5rq2/GHSA-vm7p-7vqv-5rq2.json | 8 ++------ .../05/GHSA-vp53-9vpq-jfg7/GHSA-vp53-9vpq-jfg7.json | 4 +--- .../05/GHSA-vp8r-c28c-cc69/GHSA-vp8r-c28c-cc69.json | 12 +++--------- .../05/GHSA-vpvj-7qfp-4qgg/GHSA-vpvj-7qfp-4qgg.json | 12 +++--------- .../05/GHSA-vqjv-866h-qv94/GHSA-vqjv-866h-qv94.json | 4 +--- .../05/GHSA-vqmw-xc69-r5c5/GHSA-vqmw-xc69-r5c5.json | 12 +++--------- .../05/GHSA-vqpg-rq94-24x7/GHSA-vqpg-rq94-24x7.json | 8 ++------ .../05/GHSA-vrgf-6qrc-hmmg/GHSA-vrgf-6qrc-hmmg.json | 8 ++------ .../05/GHSA-vv73-vfwf-c289/GHSA-vv73-vfwf-c289.json | 8 ++------ .../05/GHSA-vxmj-7jcq-859j/GHSA-vxmj-7jcq-859j.json | 12 +++--------- .../05/GHSA-w22c-hvvf-f3qp/GHSA-w22c-hvvf-f3qp.json | 12 +++--------- .../05/GHSA-w23p-q69p-ffp6/GHSA-w23p-q69p-ffp6.json | 12 +++--------- .../05/GHSA-w3m2-2x65-hm4m/GHSA-w3m2-2x65-hm4m.json | 12 +++--------- .../05/GHSA-w4jc-4p46-64m5/GHSA-w4jc-4p46-64m5.json | 12 +++--------- .../05/GHSA-w4r7-r278-c53j/GHSA-w4r7-r278-c53j.json | 8 ++------ .../05/GHSA-w4w8-866m-jm68/GHSA-w4w8-866m-jm68.json | 8 ++------ .../05/GHSA-w56w-fjv4-mc6j/GHSA-w56w-fjv4-mc6j.json | 12 +++--------- .../05/GHSA-w589-g2rj-2m9m/GHSA-w589-g2rj-2m9m.json | 4 +--- .../05/GHSA-w659-xcxv-5rqq/GHSA-w659-xcxv-5rqq.json | 8 ++------ .../05/GHSA-w6fg-5cg7-v6wj/GHSA-w6fg-5cg7-v6wj.json | 8 ++------ .../05/GHSA-w72r-jmv8-r4gh/GHSA-w72r-jmv8-r4gh.json | 12 +++--------- .../05/GHSA-w7c2-4qqr-9227/GHSA-w7c2-4qqr-9227.json | 12 +++--------- .../05/GHSA-w7h4-8f3v-m646/GHSA-w7h4-8f3v-m646.json | 12 +++--------- .../05/GHSA-w8x8-8rp7-r92g/GHSA-w8x8-8rp7-r92g.json | 4 +--- .../05/GHSA-w97w-4jr9-q2r8/GHSA-w97w-4jr9-q2r8.json | 8 ++------ .../05/GHSA-wc48-v74h-3jcf/GHSA-wc48-v74h-3jcf.json | 12 +++--------- .../05/GHSA-wc7j-rv6h-gcx6/GHSA-wc7j-rv6h-gcx6.json | 12 +++--------- .../05/GHSA-wfm6-393x-c6r9/GHSA-wfm6-393x-c6r9.json | 4 +--- .../05/GHSA-wm5p-263x-pww3/GHSA-wm5p-263x-pww3.json | 8 ++------ .../05/GHSA-wprw-q57v-22f2/GHSA-wprw-q57v-22f2.json | 12 +++--------- .../05/GHSA-wqw3-26w4-7wmj/GHSA-wqw3-26w4-7wmj.json | 12 +++--------- .../05/GHSA-wqwc-q68g-5fjg/GHSA-wqwc-q68g-5fjg.json | 8 ++------ .../05/GHSA-wv3c-r29g-ph8x/GHSA-wv3c-r29g-ph8x.json | 12 +++--------- .../05/GHSA-wvp2-97x3-gw55/GHSA-wvp2-97x3-gw55.json | 8 ++------ .../05/GHSA-ww65-5fcm-v6g6/GHSA-ww65-5fcm-v6g6.json | 12 +++--------- .../05/GHSA-ww68-p9c4-2353/GHSA-ww68-p9c4-2353.json | 12 +++--------- .../05/GHSA-wwcj-f9h3-rh3w/GHSA-wwcj-f9h3-rh3w.json | 12 +++--------- .../05/GHSA-wwvm-hxm2-p9r6/GHSA-wwvm-hxm2-p9r6.json | 12 +++--------- .../05/GHSA-wx5c-xgrp-9rgr/GHSA-wx5c-xgrp-9rgr.json | 8 ++------ .../05/GHSA-wxcg-g67v-xrp9/GHSA-wxcg-g67v-xrp9.json | 8 ++------ .../05/GHSA-wxf8-vxfr-r99r/GHSA-wxf8-vxfr-r99r.json | 8 ++------ .../05/GHSA-wxpv-w4p2-2m5c/GHSA-wxpv-w4p2-2m5c.json | 12 +++--------- .../05/GHSA-wxvf-3cjv-fx8w/GHSA-wxvf-3cjv-fx8w.json | 12 +++--------- .../05/GHSA-x26m-wcf2-85xw/GHSA-x26m-wcf2-85xw.json | 12 +++--------- .../05/GHSA-x2jg-9c23-q285/GHSA-x2jg-9c23-q285.json | 12 +++--------- .../05/GHSA-x3rm-hggx-j4q8/GHSA-x3rm-hggx-j4q8.json | 12 +++--------- .../05/GHSA-x4w6-j83j-vvp2/GHSA-x4w6-j83j-vvp2.json | 12 +++--------- .../05/GHSA-x5v3-cvv7-9qg6/GHSA-x5v3-cvv7-9qg6.json | 8 ++------ .../05/GHSA-x625-w2w3-862f/GHSA-x625-w2w3-862f.json | 8 ++------ .../05/GHSA-x6vc-43v3-pjqr/GHSA-x6vc-43v3-pjqr.json | 12 +++--------- .../05/GHSA-x754-7v35-2h8f/GHSA-x754-7v35-2h8f.json | 8 ++------ .../05/GHSA-x7q7-3cr3-m2q3/GHSA-x7q7-3cr3-m2q3.json | 8 ++------ .../05/GHSA-x7v4-2v57-r86h/GHSA-x7v4-2v57-r86h.json | 8 ++------ .../05/GHSA-x83r-934g-7qwg/GHSA-x83r-934g-7qwg.json | 12 +++--------- .../05/GHSA-x97m-9ccg-7rgv/GHSA-x97m-9ccg-7rgv.json | 12 +++--------- .../05/GHSA-xf3x-83h2-c6pg/GHSA-xf3x-83h2-c6pg.json | 8 ++------ .../05/GHSA-xf43-jf45-47p8/GHSA-xf43-jf45-47p8.json | 12 +++--------- .../05/GHSA-xf93-r8jp-jh8m/GHSA-xf93-r8jp-jh8m.json | 12 +++--------- .../05/GHSA-xfpp-fwv2-hrqc/GHSA-xfpp-fwv2-hrqc.json | 8 ++------ .../05/GHSA-xgpv-wxj8-c795/GHSA-xgpv-wxj8-c795.json | 12 +++--------- .../05/GHSA-xh8j-8x8h-3f2m/GHSA-xh8j-8x8h-3f2m.json | 8 ++------ .../05/GHSA-xjpq-582q-q6mh/GHSA-xjpq-582q-q6mh.json | 8 ++------ .../05/GHSA-xm74-phc9-jvhx/GHSA-xm74-phc9-jvhx.json | 4 +--- .../05/GHSA-xp68-m4r3-hpqf/GHSA-xp68-m4r3-hpqf.json | 12 +++--------- .../05/GHSA-xphj-x7cg-4hjw/GHSA-xphj-x7cg-4hjw.json | 12 +++--------- .../05/GHSA-xvmg-x4v3-5v98/GHSA-xvmg-x4v3-5v98.json | 12 +++--------- .../05/GHSA-xvxj-48v4-h2xv/GHSA-xvxj-48v4-h2xv.json | 12 +++--------- .../05/GHSA-xw2w-mmgv-hf8h/GHSA-xw2w-mmgv-hf8h.json | 8 ++------ .../06/GHSA-28c6-247x-r9mw/GHSA-28c6-247x-r9mw.json | 4 +--- .../06/GHSA-575v-67px-9r7c/GHSA-575v-67px-9r7c.json | 4 +--- .../06/GHSA-734g-rvc3-rx28/GHSA-734g-rvc3-rx28.json | 4 +--- .../06/GHSA-87mg-gx7c-q5gr/GHSA-87mg-gx7c-q5gr.json | 4 +--- .../06/GHSA-88gw-64r5-49m9/GHSA-88gw-64r5-49m9.json | 4 +--- .../06/GHSA-j6mf-6qf9-6f8r/GHSA-j6mf-6qf9-6f8r.json | 4 +--- .../06/GHSA-jc44-gwj5-3hqm/GHSA-jc44-gwj5-3hqm.json | 4 +--- .../06/GHSA-q8jm-f67m-5xxq/GHSA-q8jm-f67m-5xxq.json | 4 +--- .../07/GHSA-4rg9-gh8p-52q4/GHSA-4rg9-gh8p-52q4.json | 8 ++------ .../07/GHSA-9533-x7q2-r9j9/GHSA-9533-x7q2-r9j9.json | 4 +--- .../07/GHSA-gxw5-2w8j-82xf/GHSA-gxw5-2w8j-82xf.json | 4 +--- .../07/GHSA-w2rh-hf85-pfh4/GHSA-w2rh-hf85-pfh4.json | 4 +--- .../08/GHSA-3gv2-2xxr-9jgq/GHSA-3gv2-2xxr-9jgq.json | 4 +--- .../08/GHSA-9c2p-jfmw-fgw7/GHSA-9c2p-jfmw-fgw7.json | 4 +--- .../08/GHSA-9r25-j996-8h38/GHSA-9r25-j996-8h38.json | 4 +--- .../08/GHSA-h7f6-hc46-frrv/GHSA-h7f6-hc46-frrv.json | 4 +--- .../08/GHSA-qj75-j4wq-j748/GHSA-qj75-j4wq-j748.json | 4 +--- .../08/GHSA-r8mv-jqpq-mx92/GHSA-r8mv-jqpq-mx92.json | 4 +--- .../09/GHSA-74rw-pw87-v75g/GHSA-74rw-pw87-v75g.json | 4 +--- .../09/GHSA-8cq9-p78m-67v8/GHSA-8cq9-p78m-67v8.json | 4 +--- .../09/GHSA-cvjg-9hcx-pvx4/GHSA-cvjg-9hcx-pvx4.json | 8 ++------ .../09/GHSA-gv26-x27m-rfg3/GHSA-gv26-x27m-rfg3.json | 4 +--- .../09/GHSA-hpgr-7w89-8xm5/GHSA-hpgr-7w89-8xm5.json | 4 +--- .../09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json | 4 +--- .../09/GHSA-qjwx-hqg3-vv75/GHSA-qjwx-hqg3-vv75.json | 4 +--- .../09/GHSA-qpvc-9998-hvx9/GHSA-qpvc-9998-hvx9.json | 4 +--- .../11/GHSA-494r-cmj8-94j9/GHSA-494r-cmj8-94j9.json | 4 +--- .../11/GHSA-4cwx-87j2-xc8v/GHSA-4cwx-87j2-xc8v.json | 4 +--- .../11/GHSA-5x3r-56hw-m9mp/GHSA-5x3r-56hw-m9mp.json | 4 +--- .../11/GHSA-7crr-gq7j-5wcr/GHSA-7crr-gq7j-5wcr.json | 8 ++------ .../11/GHSA-j7rp-w7cg-34p9/GHSA-j7rp-w7cg-34p9.json | 8 ++------ .../11/GHSA-p326-98p9-wprv/GHSA-p326-98p9-wprv.json | 4 +--- .../12/GHSA-36qx-76wj-5vqw/GHSA-36qx-76wj-5vqw.json | 8 ++------ .../12/GHSA-55pf-9mrw-9459/GHSA-55pf-9mrw-9459.json | 4 +--- .../12/GHSA-82mr-xx64-4rjv/GHSA-82mr-xx64-4rjv.json | 4 +--- .../12/GHSA-86q3-6wjf-3984/GHSA-86q3-6wjf-3984.json | 4 +--- .../12/GHSA-x4qc-6q9c-46qw/GHSA-x4qc-6q9c-46qw.json | 4 +--- .../12/GHSA-xgxj-cfph-mm49/GHSA-xgxj-cfph-mm49.json | 4 +--- .../01/GHSA-4q2q-9g24-gmxw/GHSA-4q2q-9g24-gmxw.json | 4 +--- .../01/GHSA-5c53-mg2q-8qhc/GHSA-5c53-mg2q-8qhc.json | 4 +--- .../01/GHSA-66vq-r792-85wm/GHSA-66vq-r792-85wm.json | 4 +--- .../01/GHSA-cr29-8xj3-v4f9/GHSA-cr29-8xj3-v4f9.json | 4 +--- .../01/GHSA-fc86-55vx-x268/GHSA-fc86-55vx-x268.json | 4 +--- .../01/GHSA-g29v-3m9r-f46w/GHSA-g29v-3m9r-f46w.json | 4 +--- .../01/GHSA-hxf9-8vg6-w44v/GHSA-hxf9-8vg6-w44v.json | 4 +--- .../01/GHSA-pxr2-3jg8-8m32/GHSA-pxr2-3jg8-8m32.json | 4 +--- .../01/GHSA-qwwx-hvjj-2vq7/GHSA-qwwx-hvjj-2vq7.json | 4 +--- .../01/GHSA-r5c5-3whr-qfrr/GHSA-r5c5-3whr-qfrr.json | 4 +--- .../01/GHSA-r5mg-x7hq-vwwm/GHSA-r5mg-x7hq-vwwm.json | 4 +--- .../01/GHSA-wrv4-jq6j-75pm/GHSA-wrv4-jq6j-75pm.json | 8 ++------ .../01/GHSA-wvx9-2gv8-v8jp/GHSA-wvx9-2gv8-v8jp.json | 4 +--- .../01/GHSA-x75h-jr86-mj5x/GHSA-x75h-jr86-mj5x.json | 4 +--- .../01/GHSA-xf2q-qxhf-rqh5/GHSA-xf2q-qxhf-rqh5.json | 4 +--- .../02/GHSA-22x3-2qf6-f5mp/GHSA-22x3-2qf6-f5mp.json | 4 +--- .../02/GHSA-2ww8-f9rj-2xg5/GHSA-2ww8-f9rj-2xg5.json | 8 ++------ .../02/GHSA-4gmg-r65m-fr2x/GHSA-4gmg-r65m-fr2x.json | 4 +--- .../02/GHSA-6fr7-2fr2-7jh9/GHSA-6fr7-2fr2-7jh9.json | 4 +--- .../02/GHSA-qq8v-cw34-3r3m/GHSA-qq8v-cw34-3r3m.json | 4 +--- .../02/GHSA-wg3r-23qv-fhj6/GHSA-wg3r-23qv-fhj6.json | 4 +--- .../03/GHSA-h2q8-mvpc-6j4j/GHSA-h2q8-mvpc-6j4j.json | 4 +--- .../03/GHSA-hcgv-rjpx-8qjc/GHSA-hcgv-rjpx-8qjc.json | 4 +--- .../03/GHSA-mm5q-h234-59mj/GHSA-mm5q-h234-59mj.json | 4 +--- .../06/GHSA-23vj-5jhc-26rp/GHSA-23vj-5jhc-26rp.json | 8 ++------ .../06/GHSA-6c6g-97p2-3xrq/GHSA-6c6g-97p2-3xrq.json | 4 +--- .../06/GHSA-cp8j-9c47-62cg/GHSA-cp8j-9c47-62cg.json | 4 +--- .../09/GHSA-7wwm-57j8-wx2j/GHSA-7wwm-57j8-wx2j.json | 4 +--- .../10/GHSA-3wvh-wgv4-8fvc/GHSA-3wvh-wgv4-8fvc.json | 4 +--- .../10/GHSA-7cq2-v5ph-5463/GHSA-7cq2-v5ph-5463.json | 4 +--- .../10/GHSA-99vx-9c28-97p2/GHSA-99vx-9c28-97p2.json | 4 +--- .../10/GHSA-9hm3-chgj-45rm/GHSA-9hm3-chgj-45rm.json | 4 +--- .../10/GHSA-cw9h-crjm-c99p/GHSA-cw9h-crjm-c99p.json | 4 +--- .../10/GHSA-m772-7wx3-fv6x/GHSA-m772-7wx3-fv6x.json | 4 +--- .../10/GHSA-pr32-36pm-7395/GHSA-pr32-36pm-7395.json | 4 +--- .../10/GHSA-rgrr-m4xm-32mh/GHSA-rgrr-m4xm-32mh.json | 4 +--- .../10/GHSA-xm85-mgcm-6w3f/GHSA-xm85-mgcm-6w3f.json | 8 ++------ .../11/GHSA-3285-g6w2-x8q4/GHSA-3285-g6w2-x8q4.json | 4 +--- .../11/GHSA-3gm2-64xq-8fp3/GHSA-3gm2-64xq-8fp3.json | 4 +--- .../11/GHSA-3xwf-jqhp-f89m/GHSA-3xwf-jqhp-f89m.json | 4 +--- .../11/GHSA-3xxj-rfjr-w6h5/GHSA-3xxj-rfjr-w6h5.json | 4 +--- .../11/GHSA-422j-w5mv-f3f3/GHSA-422j-w5mv-f3f3.json | 4 +--- .../11/GHSA-4742-9c9c-4wf7/GHSA-4742-9c9c-4wf7.json | 8 ++------ .../11/GHSA-4g2c-9347-58ff/GHSA-4g2c-9347-58ff.json | 4 +--- .../11/GHSA-4gw7-ppxh-mmrp/GHSA-4gw7-ppxh-mmrp.json | 4 +--- .../11/GHSA-583v-xw8h-qw2h/GHSA-583v-xw8h-qw2h.json | 4 +--- .../11/GHSA-5fvg-7q6x-mgh2/GHSA-5fvg-7q6x-mgh2.json | 4 +--- .../11/GHSA-5mx5-qh58-rrh2/GHSA-5mx5-qh58-rrh2.json | 4 +--- .../11/GHSA-5qhh-783c-vpmm/GHSA-5qhh-783c-vpmm.json | 4 +--- .../11/GHSA-6jhm-w7qq-9788/GHSA-6jhm-w7qq-9788.json | 4 +--- .../11/GHSA-6q7p-2x27-26vg/GHSA-6q7p-2x27-26vg.json | 4 +--- .../11/GHSA-6w75-vqq2-8cjx/GHSA-6w75-vqq2-8cjx.json | 4 +--- .../11/GHSA-72vx-6xj8-m752/GHSA-72vx-6xj8-m752.json | 4 +--- .../11/GHSA-77h7-f57j-cjv2/GHSA-77h7-f57j-cjv2.json | 4 +--- .../11/GHSA-794f-9q36-972h/GHSA-794f-9q36-972h.json | 4 +--- .../11/GHSA-7j49-vjx9-cwp7/GHSA-7j49-vjx9-cwp7.json | 4 +--- .../11/GHSA-7m4h-4frj-xvm5/GHSA-7m4h-4frj-xvm5.json | 4 +--- .../11/GHSA-84p4-j9qr-gxr6/GHSA-84p4-j9qr-gxr6.json | 4 +--- .../11/GHSA-94x4-p49x-fp3r/GHSA-94x4-p49x-fp3r.json | 4 +--- .../11/GHSA-9fr8-m3gw-gcm4/GHSA-9fr8-m3gw-gcm4.json | 8 ++------ .../11/GHSA-9p54-wmmc-452q/GHSA-9p54-wmmc-452q.json | 4 +--- .../11/GHSA-c2v4-q7c8-8w9w/GHSA-c2v4-q7c8-8w9w.json | 4 +--- .../11/GHSA-c65v-cwf9-f69v/GHSA-c65v-cwf9-f69v.json | 4 +--- .../11/GHSA-chvm-3c2v-p6qg/GHSA-chvm-3c2v-p6qg.json | 4 +--- .../11/GHSA-cjpq-3xp9-4722/GHSA-cjpq-3xp9-4722.json | 4 +--- .../11/GHSA-cm77-ccvm-f7p6/GHSA-cm77-ccvm-f7p6.json | 8 ++------ .../11/GHSA-cx3g-f3g3-5494/GHSA-cx3g-f3g3-5494.json | 4 +--- .../11/GHSA-fpmx-qfph-4r6r/GHSA-fpmx-qfph-4r6r.json | 4 +--- .../11/GHSA-h42p-m2rq-vxxg/GHSA-h42p-m2rq-vxxg.json | 4 +--- .../11/GHSA-h4gp-9r63-7fgw/GHSA-h4gp-9r63-7fgw.json | 4 +--- .../11/GHSA-hh28-6v7m-3v52/GHSA-hh28-6v7m-3v52.json | 4 +--- .../11/GHSA-j2vx-8xmx-87hp/GHSA-j2vx-8xmx-87hp.json | 4 +--- .../11/GHSA-j3qr-8pp8-m4vp/GHSA-j3qr-8pp8-m4vp.json | 4 +--- .../11/GHSA-j4gp-vqp3-jp8r/GHSA-j4gp-vqp3-jp8r.json | 4 +--- .../11/GHSA-j97j-w85x-cvvq/GHSA-j97j-w85x-cvvq.json | 4 +--- .../11/GHSA-jfv3-2638-xrwh/GHSA-jfv3-2638-xrwh.json | 4 +--- .../11/GHSA-jj53-4h2j-9gmj/GHSA-jj53-4h2j-9gmj.json | 4 +--- .../11/GHSA-pc7h-cpmv-65jh/GHSA-pc7h-cpmv-65jh.json | 4 +--- .../11/GHSA-ph4g-vfg9-83hr/GHSA-ph4g-vfg9-83hr.json | 4 +--- .../11/GHSA-qhq7-4fq9-2fp7/GHSA-qhq7-4fq9-2fp7.json | 4 +--- .../11/GHSA-rmr9-43mw-mv87/GHSA-rmr9-43mw-mv87.json | 4 +--- .../11/GHSA-rrcf-fxfm-g3vr/GHSA-rrcf-fxfm-g3vr.json | 4 +--- .../11/GHSA-v93c-j63p-5mqw/GHSA-v93c-j63p-5mqw.json | 4 +--- .../11/GHSA-vjw9-jcfv-rggv/GHSA-vjw9-jcfv-rggv.json | 4 +--- .../11/GHSA-vw4m-22hh-wjmj/GHSA-vw4m-22hh-wjmj.json | 4 +--- .../11/GHSA-w86m-2494-94vf/GHSA-w86m-2494-94vf.json | 4 +--- .../11/GHSA-w95x-2qq3-w4mr/GHSA-w95x-2qq3-w4mr.json | 4 +--- .../11/GHSA-xf6r-6c2v-5fv9/GHSA-xf6r-6c2v-5fv9.json | 4 +--- .../11/GHSA-xpj7-v9x5-6gh9/GHSA-xpj7-v9x5-6gh9.json | 4 +--- .../12/GHSA-ggf8-3x7x-9mpw/GHSA-ggf8-3x7x-9mpw.json | 8 ++------ .../12/GHSA-r74q-rghm-f66p/GHSA-r74q-rghm-f66p.json | 4 +--- .../12/GHSA-vcvx-r925-7vh9/GHSA-vcvx-r925-7vh9.json | 4 +--- .../01/GHSA-9jwq-vg3g-gxcc/GHSA-9jwq-vg3g-gxcc.json | 4 +--- .../01/GHSA-g3jm-7w7w-rf6f/GHSA-g3jm-7w7w-rf6f.json | 4 +--- .../01/GHSA-m426-263c-vx86/GHSA-m426-263c-vx86.json | 4 +--- .../01/GHSA-vhqw-mw84-hph6/GHSA-vhqw-mw84-hph6.json | 4 +--- .../03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json | 8 ++------ .../03/GHSA-4xc2-vg9r-33pp/GHSA-4xc2-vg9r-33pp.json | 4 +--- .../03/GHSA-84hj-9c53-vjg2/GHSA-84hj-9c53-vjg2.json | 4 +--- .../03/GHSA-8rqc-wx6q-m4qc/GHSA-8rqc-wx6q-m4qc.json | 4 +--- .../03/GHSA-8wfm-cwf4-qvjj/GHSA-8wfm-cwf4-qvjj.json | 8 ++------ .../03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json | 8 ++------ .../03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json | 4 +--- .../03/GHSA-m3xv-gj54-x2wv/GHSA-m3xv-gj54-x2wv.json | 8 ++------ .../03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json | 4 +--- .../03/GHSA-p84f-xgwp-4frf/GHSA-p84f-xgwp-4frf.json | 8 ++------ .../03/GHSA-q3m8-4vff-qr66/GHSA-q3m8-4vff-qr66.json | 4 +--- .../03/GHSA-q4g5-6262-6h9p/GHSA-q4g5-6262-6h9p.json | 8 ++------ .../03/GHSA-r6x7-5742-mcv8/GHSA-r6x7-5742-mcv8.json | 8 ++------ .../03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json | 8 ++------ .../03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json | 4 +--- .../07/GHSA-2jh9-8qjc-9f2q/GHSA-2jh9-8qjc-9f2q.json | 4 +--- .../07/GHSA-2mx5-rvwp-q23x/GHSA-2mx5-rvwp-q23x.json | 4 +--- .../07/GHSA-2vh5-8cw9-qhj3/GHSA-2vh5-8cw9-qhj3.json | 4 +--- .../07/GHSA-2x77-g6vw-wxgr/GHSA-2x77-g6vw-wxgr.json | 4 +--- .../07/GHSA-322j-cfcv-3q95/GHSA-322j-cfcv-3q95.json | 4 +--- .../07/GHSA-3c73-87fp-87pp/GHSA-3c73-87fp-87pp.json | 4 +--- .../07/GHSA-43qr-7pjx-rp3v/GHSA-43qr-7pjx-rp3v.json | 4 +--- .../07/GHSA-47mw-6wvv-9mwc/GHSA-47mw-6wvv-9mwc.json | 4 +--- .../07/GHSA-4r5f-q294-8gxm/GHSA-4r5f-q294-8gxm.json | 4 +--- .../07/GHSA-4xhw-j298-f2jr/GHSA-4xhw-j298-f2jr.json | 4 +--- .../07/GHSA-5pxw-5627-vff9/GHSA-5pxw-5627-vff9.json | 4 +--- .../07/GHSA-638p-9h38-r62f/GHSA-638p-9h38-r62f.json | 4 +--- .../07/GHSA-77wf-fqrm-cw5j/GHSA-77wf-fqrm-cw5j.json | 4 +--- .../07/GHSA-7c38-xxmq-vp5q/GHSA-7c38-xxmq-vp5q.json | 4 +--- .../07/GHSA-7gw9-g3qq-5q97/GHSA-7gw9-g3qq-5q97.json | 4 +--- .../07/GHSA-7p2v-48c8-pmwc/GHSA-7p2v-48c8-pmwc.json | 4 +--- .../07/GHSA-7wh7-x56j-7rrv/GHSA-7wh7-x56j-7rrv.json | 4 +--- .../07/GHSA-95gx-prcc-xj69/GHSA-95gx-prcc-xj69.json | 4 +--- .../07/GHSA-c5gh-whxc-hf9p/GHSA-c5gh-whxc-hf9p.json | 4 +--- .../07/GHSA-fgp4-99c3-x4g4/GHSA-fgp4-99c3-x4g4.json | 4 +--- .../07/GHSA-fw5j-h477-4x76/GHSA-fw5j-h477-4x76.json | 4 +--- .../07/GHSA-g57x-f29r-g9gv/GHSA-g57x-f29r-g9gv.json | 4 +--- .../07/GHSA-gh8h-m29v-xxxf/GHSA-gh8h-m29v-xxxf.json | 4 +--- .../07/GHSA-h332-g3fr-x4pf/GHSA-h332-g3fr-x4pf.json | 4 +--- .../07/GHSA-hg8c-6p2v-p3vw/GHSA-hg8c-6p2v-p3vw.json | 4 +--- .../07/GHSA-hjpm-vq95-vrqg/GHSA-hjpm-vq95-vrqg.json | 4 +--- .../07/GHSA-m2rg-fx69-8xcm/GHSA-m2rg-fx69-8xcm.json | 4 +--- .../07/GHSA-mq87-5qcr-hvqj/GHSA-mq87-5qcr-hvqj.json | 4 +--- .../07/GHSA-pcgf-phm5-g292/GHSA-pcgf-phm5-g292.json | 4 +--- .../07/GHSA-pg44-5crw-w36x/GHSA-pg44-5crw-w36x.json | 4 +--- .../07/GHSA-ppcc-8c3j-x247/GHSA-ppcc-8c3j-x247.json | 4 +--- .../07/GHSA-qhfr-qp56-p7x5/GHSA-qhfr-qp56-p7x5.json | 4 +--- .../07/GHSA-qv6h-284f-5rfg/GHSA-qv6h-284f-5rfg.json | 4 +--- .../07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json | 4 +--- .../07/GHSA-r42q-2ccv-h7pg/GHSA-r42q-2ccv-h7pg.json | 4 +--- .../07/GHSA-r5x2-w7xx-rrpc/GHSA-r5x2-w7xx-rrpc.json | 4 +--- .../07/GHSA-rc4x-vgmq-9jch/GHSA-rc4x-vgmq-9jch.json | 4 +--- .../07/GHSA-rcwx-8xvc-26gh/GHSA-rcwx-8xvc-26gh.json | 4 +--- .../07/GHSA-rm5h-63rx-5j7f/GHSA-rm5h-63rx-5j7f.json | 4 +--- .../07/GHSA-vpr8-gfxc-fwmm/GHSA-vpr8-gfxc-fwmm.json | 4 +--- .../07/GHSA-vxm8-9f5p-7wcw/GHSA-vxm8-9f5p-7wcw.json | 4 +--- .../07/GHSA-wf73-c9rj-g2f9/GHSA-wf73-c9rj-g2f9.json | 4 +--- .../07/GHSA-wp4f-2cvh-fwpc/GHSA-wp4f-2cvh-fwpc.json | 4 +--- .../07/GHSA-wp4p-9qfg-737p/GHSA-wp4p-9qfg-737p.json | 4 +--- .../07/GHSA-wqw5-3mgq-446w/GHSA-wqw5-3mgq-446w.json | 4 +--- .../07/GHSA-wvf7-262j-g8m8/GHSA-wvf7-262j-g8m8.json | 4 +--- .../07/GHSA-wxrv-qfwq-9wqq/GHSA-wxrv-qfwq-9wqq.json | 4 +--- .../07/GHSA-x2v6-734p-pjc6/GHSA-x2v6-734p-pjc6.json | 4 +--- .../07/GHSA-xvc4-h3h9-rjwx/GHSA-xvc4-h3h9-rjwx.json | 4 +--- 960 files changed, 2179 insertions(+), 6537 deletions(-) diff --git a/advisories/unreviewed/2021/11/GHSA-959p-vvwh-xj92/GHSA-959p-vvwh-xj92.json b/advisories/unreviewed/2021/11/GHSA-959p-vvwh-xj92/GHSA-959p-vvwh-xj92.json index e84cb134347..2fe39664d6b 100644 --- a/advisories/unreviewed/2021/11/GHSA-959p-vvwh-xj92/GHSA-959p-vvwh-xj92.json +++ b/advisories/unreviewed/2021/11/GHSA-959p-vvwh-xj92/GHSA-959p-vvwh-xj92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-gjrp-cpc9-h4r7/GHSA-gjrp-cpc9-h4r7.json b/advisories/unreviewed/2021/11/GHSA-gjrp-cpc9-h4r7/GHSA-gjrp-cpc9-h4r7.json index 7bc2328b1b7..36582db08b1 100644 --- a/advisories/unreviewed/2021/11/GHSA-gjrp-cpc9-h4r7/GHSA-gjrp-cpc9-h4r7.json +++ b/advisories/unreviewed/2021/11/GHSA-gjrp-cpc9-h4r7/GHSA-gjrp-cpc9-h4r7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/11/GHSA-jpp8-232v-26fc/GHSA-jpp8-232v-26fc.json b/advisories/unreviewed/2021/11/GHSA-jpp8-232v-26fc/GHSA-jpp8-232v-26fc.json index 4f962fb5e88..82d20129c8f 100644 --- a/advisories/unreviewed/2021/11/GHSA-jpp8-232v-26fc/GHSA-jpp8-232v-26fc.json +++ b/advisories/unreviewed/2021/11/GHSA-jpp8-232v-26fc/GHSA-jpp8-232v-26fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-mj29-93c5-p3pr/GHSA-mj29-93c5-p3pr.json b/advisories/unreviewed/2021/12/GHSA-mj29-93c5-p3pr/GHSA-mj29-93c5-p3pr.json index 8df856483bb..7c04a82ac0d 100644 --- a/advisories/unreviewed/2021/12/GHSA-mj29-93c5-p3pr/GHSA-mj29-93c5-p3pr.json +++ b/advisories/unreviewed/2021/12/GHSA-mj29-93c5-p3pr/GHSA-mj29-93c5-p3pr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/01/GHSA-cf77-6c9v-56mf/GHSA-cf77-6c9v-56mf.json b/advisories/unreviewed/2022/01/GHSA-cf77-6c9v-56mf/GHSA-cf77-6c9v-56mf.json index a4983c69fda..1a699d34708 100644 --- a/advisories/unreviewed/2022/01/GHSA-cf77-6c9v-56mf/GHSA-cf77-6c9v-56mf.json +++ b/advisories/unreviewed/2022/01/GHSA-cf77-6c9v-56mf/GHSA-cf77-6c9v-56mf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-j5wx-jhwh-qm36/GHSA-j5wx-jhwh-qm36.json b/advisories/unreviewed/2022/01/GHSA-j5wx-jhwh-qm36/GHSA-j5wx-jhwh-qm36.json index a6519d942e9..ebabef43b9f 100644 --- a/advisories/unreviewed/2022/01/GHSA-j5wx-jhwh-qm36/GHSA-j5wx-jhwh-qm36.json +++ b/advisories/unreviewed/2022/01/GHSA-j5wx-jhwh-qm36/GHSA-j5wx-jhwh-qm36.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/01/GHSA-wvq2-357p-vcgg/GHSA-wvq2-357p-vcgg.json b/advisories/unreviewed/2022/01/GHSA-wvq2-357p-vcgg/GHSA-wvq2-357p-vcgg.json index f890f5a91c8..8a804482761 100644 --- a/advisories/unreviewed/2022/01/GHSA-wvq2-357p-vcgg/GHSA-wvq2-357p-vcgg.json +++ b/advisories/unreviewed/2022/01/GHSA-wvq2-357p-vcgg/GHSA-wvq2-357p-vcgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-mxm3-g2j6-276p/GHSA-mxm3-g2j6-276p.json b/advisories/unreviewed/2022/03/GHSA-mxm3-g2j6-276p/GHSA-mxm3-g2j6-276p.json index 3f7e852e14a..9daf06bb056 100644 --- a/advisories/unreviewed/2022/03/GHSA-mxm3-g2j6-276p/GHSA-mxm3-g2j6-276p.json +++ b/advisories/unreviewed/2022/03/GHSA-mxm3-g2j6-276p/GHSA-mxm3-g2j6-276p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-q9rw-8758-hccj/GHSA-q9rw-8758-hccj.json b/advisories/unreviewed/2022/03/GHSA-q9rw-8758-hccj/GHSA-q9rw-8758-hccj.json index fb38eddd371..79e31136913 100644 --- a/advisories/unreviewed/2022/03/GHSA-q9rw-8758-hccj/GHSA-q9rw-8758-hccj.json +++ b/advisories/unreviewed/2022/03/GHSA-q9rw-8758-hccj/GHSA-q9rw-8758-hccj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2m7r-8x5f-v32g/GHSA-2m7r-8x5f-v32g.json b/advisories/unreviewed/2022/04/GHSA-2m7r-8x5f-v32g/GHSA-2m7r-8x5f-v32g.json index 6f6e3ce0bf5..0e2e1b28b05 100644 --- a/advisories/unreviewed/2022/04/GHSA-2m7r-8x5f-v32g/GHSA-2m7r-8x5f-v32g.json +++ b/advisories/unreviewed/2022/04/GHSA-2m7r-8x5f-v32g/GHSA-2m7r-8x5f-v32g.json @@ -7,12 +7,8 @@ "CVE-2004-1565" ], "details": "list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2qwq-f37f-3q37/GHSA-2qwq-f37f-3q37.json b/advisories/unreviewed/2022/04/GHSA-2qwq-f37f-3q37/GHSA-2qwq-f37f-3q37.json index b6495206fe7..0840d1ac324 100644 --- a/advisories/unreviewed/2022/04/GHSA-2qwq-f37f-3q37/GHSA-2qwq-f37f-3q37.json +++ b/advisories/unreviewed/2022/04/GHSA-2qwq-f37f-3q37/GHSA-2qwq-f37f-3q37.json @@ -7,12 +7,8 @@ "CVE-2004-1624" ], "details": "Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2r2v-2jgp-6j72/GHSA-2r2v-2jgp-6j72.json b/advisories/unreviewed/2022/04/GHSA-2r2v-2jgp-6j72/GHSA-2r2v-2jgp-6j72.json index 6b0a59c5d5c..7dfaf33f97e 100644 --- a/advisories/unreviewed/2022/04/GHSA-2r2v-2jgp-6j72/GHSA-2r2v-2jgp-6j72.json +++ b/advisories/unreviewed/2022/04/GHSA-2r2v-2jgp-6j72/GHSA-2r2v-2jgp-6j72.json @@ -7,12 +7,8 @@ "CVE-2004-1577" ], "details": "index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2vjq-g46g-w383/GHSA-2vjq-g46g-w383.json b/advisories/unreviewed/2022/04/GHSA-2vjq-g46g-w383/GHSA-2vjq-g46g-w383.json index 7a9defc9f73..d87bc223ec4 100644 --- a/advisories/unreviewed/2022/04/GHSA-2vjq-g46g-w383/GHSA-2vjq-g46g-w383.json +++ b/advisories/unreviewed/2022/04/GHSA-2vjq-g46g-w383/GHSA-2vjq-g46g-w383.json @@ -7,12 +7,8 @@ "CVE-2004-1705" ], "details": "Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-32xp-8gq9-j2vq/GHSA-32xp-8gq9-j2vq.json b/advisories/unreviewed/2022/04/GHSA-32xp-8gq9-j2vq/GHSA-32xp-8gq9-j2vq.json index b325ebefae0..59df8a6bbf3 100644 --- a/advisories/unreviewed/2022/04/GHSA-32xp-8gq9-j2vq/GHSA-32xp-8gq9-j2vq.json +++ b/advisories/unreviewed/2022/04/GHSA-32xp-8gq9-j2vq/GHSA-32xp-8gq9-j2vq.json @@ -7,12 +7,8 @@ "CVE-2004-1574" ], "details": "Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-359x-29v3-4rrm/GHSA-359x-29v3-4rrm.json b/advisories/unreviewed/2022/04/GHSA-359x-29v3-4rrm/GHSA-359x-29v3-4rrm.json index 646a595b4ce..bb548bc7c18 100644 --- a/advisories/unreviewed/2022/04/GHSA-359x-29v3-4rrm/GHSA-359x-29v3-4rrm.json +++ b/advisories/unreviewed/2022/04/GHSA-359x-29v3-4rrm/GHSA-359x-29v3-4rrm.json @@ -7,12 +7,8 @@ "CVE-2004-1579" ], "details": "index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-37gr-95fp-3q54/GHSA-37gr-95fp-3q54.json b/advisories/unreviewed/2022/04/GHSA-37gr-95fp-3q54/GHSA-37gr-95fp-3q54.json index fd48b716b89..8ac7dcc0f34 100644 --- a/advisories/unreviewed/2022/04/GHSA-37gr-95fp-3q54/GHSA-37gr-95fp-3q54.json +++ b/advisories/unreviewed/2022/04/GHSA-37gr-95fp-3q54/GHSA-37gr-95fp-3q54.json @@ -7,12 +7,8 @@ "CVE-2004-1658" ], "details": "Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \\device\\physicalmemory to restore the running kernel's SDT ServiceTable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-37rm-6wgr-cv7j/GHSA-37rm-6wgr-cv7j.json b/advisories/unreviewed/2022/04/GHSA-37rm-6wgr-cv7j/GHSA-37rm-6wgr-cv7j.json index 420d998d7a4..a73b21272ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-37rm-6wgr-cv7j/GHSA-37rm-6wgr-cv7j.json +++ b/advisories/unreviewed/2022/04/GHSA-37rm-6wgr-cv7j/GHSA-37rm-6wgr-cv7j.json @@ -7,12 +7,8 @@ "CVE-2004-1749" ], "details": "Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-397w-gc7r-9x5j/GHSA-397w-gc7r-9x5j.json b/advisories/unreviewed/2022/04/GHSA-397w-gc7r-9x5j/GHSA-397w-gc7r-9x5j.json index 5f8a164788b..36e2f69af31 100644 --- a/advisories/unreviewed/2022/04/GHSA-397w-gc7r-9x5j/GHSA-397w-gc7r-9x5j.json +++ b/advisories/unreviewed/2022/04/GHSA-397w-gc7r-9x5j/GHSA-397w-gc7r-9x5j.json @@ -7,12 +7,8 @@ "CVE-2004-1667" ], "details": "Off-by-one error in Halo Combat Evolved 1.04 and earlier allows remote attackers to cause a denial of service (server crash) via a long client response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3f9g-p7qm-mjjp/GHSA-3f9g-p7qm-mjjp.json b/advisories/unreviewed/2022/04/GHSA-3f9g-p7qm-mjjp/GHSA-3f9g-p7qm-mjjp.json index a4114604742..124d579569b 100644 --- a/advisories/unreviewed/2022/04/GHSA-3f9g-p7qm-mjjp/GHSA-3f9g-p7qm-mjjp.json +++ b/advisories/unreviewed/2022/04/GHSA-3f9g-p7qm-mjjp/GHSA-3f9g-p7qm-mjjp.json @@ -7,12 +7,8 @@ "CVE-2004-1612" ], "details": "Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3gx5-q8r9-268f/GHSA-3gx5-q8r9-268f.json b/advisories/unreviewed/2022/04/GHSA-3gx5-q8r9-268f/GHSA-3gx5-q8r9-268f.json index 1d1970d39ed..e7bdaf0e6d4 100644 --- a/advisories/unreviewed/2022/04/GHSA-3gx5-q8r9-268f/GHSA-3gx5-q8r9-268f.json +++ b/advisories/unreviewed/2022/04/GHSA-3gx5-q8r9-268f/GHSA-3gx5-q8r9-268f.json @@ -7,12 +7,8 @@ "CVE-2004-1716" ], "details": "Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3h69-7jmr-q5h4/GHSA-3h69-7jmr-q5h4.json b/advisories/unreviewed/2022/04/GHSA-3h69-7jmr-q5h4/GHSA-3h69-7jmr-q5h4.json index b16733c57ad..e24925040e8 100644 --- a/advisories/unreviewed/2022/04/GHSA-3h69-7jmr-q5h4/GHSA-3h69-7jmr-q5h4.json +++ b/advisories/unreviewed/2022/04/GHSA-3h69-7jmr-q5h4/GHSA-3h69-7jmr-q5h4.json @@ -7,12 +7,8 @@ "CVE-2004-1572" ], "details": "AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3hfj-vjmw-rjj4/GHSA-3hfj-vjmw-rjj4.json b/advisories/unreviewed/2022/04/GHSA-3hfj-vjmw-rjj4/GHSA-3hfj-vjmw-rjj4.json index eecd988cece..81a16ee99ab 100644 --- a/advisories/unreviewed/2022/04/GHSA-3hfj-vjmw-rjj4/GHSA-3hfj-vjmw-rjj4.json +++ b/advisories/unreviewed/2022/04/GHSA-3hfj-vjmw-rjj4/GHSA-3hfj-vjmw-rjj4.json @@ -7,12 +7,8 @@ "CVE-2004-1620" ], "details": "CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3jcq-7m4x-57r2/GHSA-3jcq-7m4x-57r2.json b/advisories/unreviewed/2022/04/GHSA-3jcq-7m4x-57r2/GHSA-3jcq-7m4x-57r2.json index 9bc7e5efb80..c1444b7e5d3 100644 --- a/advisories/unreviewed/2022/04/GHSA-3jcq-7m4x-57r2/GHSA-3jcq-7m4x-57r2.json +++ b/advisories/unreviewed/2022/04/GHSA-3jcq-7m4x-57r2/GHSA-3jcq-7m4x-57r2.json @@ -7,12 +7,8 @@ "CVE-2004-1758" ], "details": "BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mwg-wvg9-ghpc/GHSA-3mwg-wvg9-ghpc.json b/advisories/unreviewed/2022/04/GHSA-3mwg-wvg9-ghpc/GHSA-3mwg-wvg9-ghpc.json index 768dc1ca763..2c11af11145 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mwg-wvg9-ghpc/GHSA-3mwg-wvg9-ghpc.json +++ b/advisories/unreviewed/2022/04/GHSA-3mwg-wvg9-ghpc/GHSA-3mwg-wvg9-ghpc.json @@ -7,12 +7,8 @@ "CVE-2004-1720" ], "details": "The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3p8c-x7m5-892x/GHSA-3p8c-x7m5-892x.json b/advisories/unreviewed/2022/04/GHSA-3p8c-x7m5-892x/GHSA-3p8c-x7m5-892x.json index 00c66cd7165..8a6c7f98419 100644 --- a/advisories/unreviewed/2022/04/GHSA-3p8c-x7m5-892x/GHSA-3p8c-x7m5-892x.json +++ b/advisories/unreviewed/2022/04/GHSA-3p8c-x7m5-892x/GHSA-3p8c-x7m5-892x.json @@ -7,12 +7,8 @@ "CVE-2004-1583" ], "details": "Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3pxp-67jr-6qw6/GHSA-3pxp-67jr-6qw6.json b/advisories/unreviewed/2022/04/GHSA-3pxp-67jr-6qw6/GHSA-3pxp-67jr-6qw6.json index a119f6bb8ec..d8a4cc87f46 100644 --- a/advisories/unreviewed/2022/04/GHSA-3pxp-67jr-6qw6/GHSA-3pxp-67jr-6qw6.json +++ b/advisories/unreviewed/2022/04/GHSA-3pxp-67jr-6qw6/GHSA-3pxp-67jr-6qw6.json @@ -7,12 +7,8 @@ "CVE-2004-1665" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3q3m-3ccv-7882/GHSA-3q3m-3ccv-7882.json b/advisories/unreviewed/2022/04/GHSA-3q3m-3ccv-7882/GHSA-3q3m-3ccv-7882.json index 118736a3493..2e293626d22 100644 --- a/advisories/unreviewed/2022/04/GHSA-3q3m-3ccv-7882/GHSA-3q3m-3ccv-7882.json +++ b/advisories/unreviewed/2022/04/GHSA-3q3m-3ccv-7882/GHSA-3q3m-3ccv-7882.json @@ -7,12 +7,8 @@ "CVE-2004-1660" ], "details": "PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3v49-5224-w9p6/GHSA-3v49-5224-w9p6.json b/advisories/unreviewed/2022/04/GHSA-3v49-5224-w9p6/GHSA-3v49-5224-w9p6.json index 9215b0d3e84..a377fe7f303 100644 --- a/advisories/unreviewed/2022/04/GHSA-3v49-5224-w9p6/GHSA-3v49-5224-w9p6.json +++ b/advisories/unreviewed/2022/04/GHSA-3v49-5224-w9p6/GHSA-3v49-5224-w9p6.json @@ -7,12 +7,8 @@ "CVE-2004-1619" ], "details": "Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3vjc-m2jj-cq2m/GHSA-3vjc-m2jj-cq2m.json b/advisories/unreviewed/2022/04/GHSA-3vjc-m2jj-cq2m/GHSA-3vjc-m2jj-cq2m.json index 077ef1ddd01..4f9fb9059d5 100644 --- a/advisories/unreviewed/2022/04/GHSA-3vjc-m2jj-cq2m/GHSA-3vjc-m2jj-cq2m.json +++ b/advisories/unreviewed/2022/04/GHSA-3vjc-m2jj-cq2m/GHSA-3vjc-m2jj-cq2m.json @@ -7,12 +7,8 @@ "CVE-2004-1589" ], "details": "Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3wf7-ph6r-pvj6/GHSA-3wf7-ph6r-pvj6.json b/advisories/unreviewed/2022/04/GHSA-3wf7-ph6r-pvj6/GHSA-3wf7-ph6r-pvj6.json index cdf14bf07dc..5f3b439c17b 100644 --- a/advisories/unreviewed/2022/04/GHSA-3wf7-ph6r-pvj6/GHSA-3wf7-ph6r-pvj6.json +++ b/advisories/unreviewed/2022/04/GHSA-3wf7-ph6r-pvj6/GHSA-3wf7-ph6r-pvj6.json @@ -7,12 +7,8 @@ "CVE-2004-1710" ], "details": "page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-43vf-262m-2h43/GHSA-43vf-262m-2h43.json b/advisories/unreviewed/2022/04/GHSA-43vf-262m-2h43/GHSA-43vf-262m-2h43.json index 7af0dda8475..d495fff3693 100644 --- a/advisories/unreviewed/2022/04/GHSA-43vf-262m-2h43/GHSA-43vf-262m-2h43.json +++ b/advisories/unreviewed/2022/04/GHSA-43vf-262m-2h43/GHSA-43vf-262m-2h43.json @@ -7,12 +7,8 @@ "CVE-2004-1738" ], "details": "Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-449v-w7gx-8c56/GHSA-449v-w7gx-8c56.json b/advisories/unreviewed/2022/04/GHSA-449v-w7gx-8c56/GHSA-449v-w7gx-8c56.json index 6e09c313ab4..64a88cc6ecb 100644 --- a/advisories/unreviewed/2022/04/GHSA-449v-w7gx-8c56/GHSA-449v-w7gx-8c56.json +++ b/advisories/unreviewed/2022/04/GHSA-449v-w7gx-8c56/GHSA-449v-w7gx-8c56.json @@ -7,12 +7,8 @@ "CVE-2004-1566" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-47jj-8xrh-9rgj/GHSA-47jj-8xrh-9rgj.json b/advisories/unreviewed/2022/04/GHSA-47jj-8xrh-9rgj/GHSA-47jj-8xrh-9rgj.json index 33a8138ab36..84b2e906272 100644 --- a/advisories/unreviewed/2022/04/GHSA-47jj-8xrh-9rgj/GHSA-47jj-8xrh-9rgj.json +++ b/advisories/unreviewed/2022/04/GHSA-47jj-8xrh-9rgj/GHSA-47jj-8xrh-9rgj.json @@ -7,12 +7,8 @@ "CVE-2004-1601" ], "details": "Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4975-vpm3-gpxg/GHSA-4975-vpm3-gpxg.json b/advisories/unreviewed/2022/04/GHSA-4975-vpm3-gpxg/GHSA-4975-vpm3-gpxg.json index cb3aef20cea..7455f8850ef 100644 --- a/advisories/unreviewed/2022/04/GHSA-4975-vpm3-gpxg/GHSA-4975-vpm3-gpxg.json +++ b/advisories/unreviewed/2022/04/GHSA-4975-vpm3-gpxg/GHSA-4975-vpm3-gpxg.json @@ -7,12 +7,8 @@ "CVE-2004-1567" ], "details": "profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4f9v-p38h-gqrh/GHSA-4f9v-p38h-gqrh.json b/advisories/unreviewed/2022/04/GHSA-4f9v-p38h-gqrh/GHSA-4f9v-p38h-gqrh.json index 728b65ba0eb..956007e6bee 100644 --- a/advisories/unreviewed/2022/04/GHSA-4f9v-p38h-gqrh/GHSA-4f9v-p38h-gqrh.json +++ b/advisories/unreviewed/2022/04/GHSA-4f9v-p38h-gqrh/GHSA-4f9v-p38h-gqrh.json @@ -7,12 +7,8 @@ "CVE-2004-1632" ], "details": "Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4fw3-934j-23xh/GHSA-4fw3-934j-23xh.json b/advisories/unreviewed/2022/04/GHSA-4fw3-934j-23xh/GHSA-4fw3-934j-23xh.json index 853629dce6a..e4776b9f393 100644 --- a/advisories/unreviewed/2022/04/GHSA-4fw3-934j-23xh/GHSA-4fw3-934j-23xh.json +++ b/advisories/unreviewed/2022/04/GHSA-4fw3-934j-23xh/GHSA-4fw3-934j-23xh.json @@ -7,12 +7,8 @@ "CVE-2004-1622" ], "details": "SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4h7m-m3ch-jghg/GHSA-4h7m-m3ch-jghg.json b/advisories/unreviewed/2022/04/GHSA-4h7m-m3ch-jghg/GHSA-4h7m-m3ch-jghg.json index ebc34d57b5f..567bfb90587 100644 --- a/advisories/unreviewed/2022/04/GHSA-4h7m-m3ch-jghg/GHSA-4h7m-m3ch-jghg.json +++ b/advisories/unreviewed/2022/04/GHSA-4h7m-m3ch-jghg/GHSA-4h7m-m3ch-jghg.json @@ -7,12 +7,8 @@ "CVE-2004-1663" ], "details": "Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4hm3-9cfc-p6pj/GHSA-4hm3-9cfc-p6pj.json b/advisories/unreviewed/2022/04/GHSA-4hm3-9cfc-p6pj/GHSA-4hm3-9cfc-p6pj.json index 4761dca2aa1..04e59f24327 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hm3-9cfc-p6pj/GHSA-4hm3-9cfc-p6pj.json +++ b/advisories/unreviewed/2022/04/GHSA-4hm3-9cfc-p6pj/GHSA-4hm3-9cfc-p6pj.json @@ -7,12 +7,8 @@ "CVE-2004-1595" ], "details": "Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4hmg-2h4v-rc9v/GHSA-4hmg-2h4v-rc9v.json b/advisories/unreviewed/2022/04/GHSA-4hmg-2h4v-rc9v/GHSA-4hmg-2h4v-rc9v.json index bf3d14bb46d..1710184df58 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hmg-2h4v-rc9v/GHSA-4hmg-2h4v-rc9v.json +++ b/advisories/unreviewed/2022/04/GHSA-4hmg-2h4v-rc9v/GHSA-4hmg-2h4v-rc9v.json @@ -7,12 +7,8 @@ "CVE-2004-1638" ], "details": "Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4j49-9f55-6qxq/GHSA-4j49-9f55-6qxq.json b/advisories/unreviewed/2022/04/GHSA-4j49-9f55-6qxq/GHSA-4j49-9f55-6qxq.json index ae18ba0b6e1..789f0875083 100644 --- a/advisories/unreviewed/2022/04/GHSA-4j49-9f55-6qxq/GHSA-4j49-9f55-6qxq.json +++ b/advisories/unreviewed/2022/04/GHSA-4j49-9f55-6qxq/GHSA-4j49-9f55-6qxq.json @@ -7,12 +7,8 @@ "CVE-2004-1692" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4mpx-5p7r-233r/GHSA-4mpx-5p7r-233r.json b/advisories/unreviewed/2022/04/GHSA-4mpx-5p7r-233r/GHSA-4mpx-5p7r-233r.json index 40916004e81..19b660e19a4 100644 --- a/advisories/unreviewed/2022/04/GHSA-4mpx-5p7r-233r/GHSA-4mpx-5p7r-233r.json +++ b/advisories/unreviewed/2022/04/GHSA-4mpx-5p7r-233r/GHSA-4mpx-5p7r-233r.json @@ -7,12 +7,8 @@ "CVE-2004-1743" ], "details": "Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to view arbitrary files via an HTTP request for the disk_c virtual folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4q4v-qgcp-x9q2/GHSA-4q4v-qgcp-x9q2.json b/advisories/unreviewed/2022/04/GHSA-4q4v-qgcp-x9q2/GHSA-4q4v-qgcp-x9q2.json index 0876281f441..62def4e3454 100644 --- a/advisories/unreviewed/2022/04/GHSA-4q4v-qgcp-x9q2/GHSA-4q4v-qgcp-x9q2.json +++ b/advisories/unreviewed/2022/04/GHSA-4q4v-qgcp-x9q2/GHSA-4q4v-qgcp-x9q2.json @@ -7,12 +7,8 @@ "CVE-2004-1655" ], "details": "Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4w5x-6pmj-4m2q/GHSA-4w5x-6pmj-4m2q.json b/advisories/unreviewed/2022/04/GHSA-4w5x-6pmj-4m2q/GHSA-4w5x-6pmj-4m2q.json index e54867ddd9f..c01399de222 100644 --- a/advisories/unreviewed/2022/04/GHSA-4w5x-6pmj-4m2q/GHSA-4w5x-6pmj-4m2q.json +++ b/advisories/unreviewed/2022/04/GHSA-4w5x-6pmj-4m2q/GHSA-4w5x-6pmj-4m2q.json @@ -7,12 +7,8 @@ "CVE-2004-1748" ], "details": "NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4wpr-qcp7-qmrj/GHSA-4wpr-qcp7-qmrj.json b/advisories/unreviewed/2022/04/GHSA-4wpr-qcp7-qmrj/GHSA-4wpr-qcp7-qmrj.json index b9769985ccf..57bf86b548a 100644 --- a/advisories/unreviewed/2022/04/GHSA-4wpr-qcp7-qmrj/GHSA-4wpr-qcp7-qmrj.json +++ b/advisories/unreviewed/2022/04/GHSA-4wpr-qcp7-qmrj/GHSA-4wpr-qcp7-qmrj.json @@ -7,12 +7,8 @@ "CVE-2004-1680" ], "details": "application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4xvp-v8m6-p35p/GHSA-4xvp-v8m6-p35p.json b/advisories/unreviewed/2022/04/GHSA-4xvp-v8m6-p35p/GHSA-4xvp-v8m6-p35p.json index d8fe864a196..c4d09055770 100644 --- a/advisories/unreviewed/2022/04/GHSA-4xvp-v8m6-p35p/GHSA-4xvp-v8m6-p35p.json +++ b/advisories/unreviewed/2022/04/GHSA-4xvp-v8m6-p35p/GHSA-4xvp-v8m6-p35p.json @@ -7,12 +7,8 @@ "CVE-2004-1752" ], "details": "Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-53qq-7f4q-p4vg/GHSA-53qq-7f4q-p4vg.json b/advisories/unreviewed/2022/04/GHSA-53qq-7f4q-p4vg/GHSA-53qq-7f4q-p4vg.json index 3d650bea8d9..263618e7ec1 100644 --- a/advisories/unreviewed/2022/04/GHSA-53qq-7f4q-p4vg/GHSA-53qq-7f4q-p4vg.json +++ b/advisories/unreviewed/2022/04/GHSA-53qq-7f4q-p4vg/GHSA-53qq-7f4q-p4vg.json @@ -7,12 +7,8 @@ "CVE-2004-1689" ], "details": "sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5426-8hx3-xgr4/GHSA-5426-8hx3-xgr4.json b/advisories/unreviewed/2022/04/GHSA-5426-8hx3-xgr4/GHSA-5426-8hx3-xgr4.json index fde56f72f47..372665b8c5d 100644 --- a/advisories/unreviewed/2022/04/GHSA-5426-8hx3-xgr4/GHSA-5426-8hx3-xgr4.json +++ b/advisories/unreviewed/2022/04/GHSA-5426-8hx3-xgr4/GHSA-5426-8hx3-xgr4.json @@ -7,12 +7,8 @@ "CVE-2004-1627" ], "details": "Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-55wv-gf82-7jgw/GHSA-55wv-gf82-7jgw.json b/advisories/unreviewed/2022/04/GHSA-55wv-gf82-7jgw/GHSA-55wv-gf82-7jgw.json index d5406ba8717..a134fe678d5 100644 --- a/advisories/unreviewed/2022/04/GHSA-55wv-gf82-7jgw/GHSA-55wv-gf82-7jgw.json +++ b/advisories/unreviewed/2022/04/GHSA-55wv-gf82-7jgw/GHSA-55wv-gf82-7jgw.json @@ -7,12 +7,8 @@ "CVE-2004-1745" ], "details": "Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-574g-c88f-3c4p/GHSA-574g-c88f-3c4p.json b/advisories/unreviewed/2022/04/GHSA-574g-c88f-3c4p/GHSA-574g-c88f-3c4p.json index 8b732007581..3a9182076ef 100644 --- a/advisories/unreviewed/2022/04/GHSA-574g-c88f-3c4p/GHSA-574g-c88f-3c4p.json +++ b/advisories/unreviewed/2022/04/GHSA-574g-c88f-3c4p/GHSA-574g-c88f-3c4p.json @@ -7,12 +7,8 @@ "CVE-2004-1605" ], "details": "SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-574q-v35c-h2h9/GHSA-574q-v35c-h2h9.json b/advisories/unreviewed/2022/04/GHSA-574q-v35c-h2h9/GHSA-574q-v35c-h2h9.json index e678558046c..ee47807017c 100644 --- a/advisories/unreviewed/2022/04/GHSA-574q-v35c-h2h9/GHSA-574q-v35c-h2h9.json +++ b/advisories/unreviewed/2022/04/GHSA-574q-v35c-h2h9/GHSA-574q-v35c-h2h9.json @@ -7,12 +7,8 @@ "CVE-2004-1610" ], "details": "SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-578c-6gc2-pwhw/GHSA-578c-6gc2-pwhw.json b/advisories/unreviewed/2022/04/GHSA-578c-6gc2-pwhw/GHSA-578c-6gc2-pwhw.json index 0449ff98f4a..c79868b81e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-578c-6gc2-pwhw/GHSA-578c-6gc2-pwhw.json +++ b/advisories/unreviewed/2022/04/GHSA-578c-6gc2-pwhw/GHSA-578c-6gc2-pwhw.json @@ -7,12 +7,8 @@ "CVE-2004-1669" ], "details": "Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-57cw-xj8m-j9g4/GHSA-57cw-xj8m-j9g4.json b/advisories/unreviewed/2022/04/GHSA-57cw-xj8m-j9g4/GHSA-57cw-xj8m-j9g4.json index 7c825f08a68..0436f1973b9 100644 --- a/advisories/unreviewed/2022/04/GHSA-57cw-xj8m-j9g4/GHSA-57cw-xj8m-j9g4.json +++ b/advisories/unreviewed/2022/04/GHSA-57cw-xj8m-j9g4/GHSA-57cw-xj8m-j9g4.json @@ -7,12 +7,8 @@ "CVE-2004-1693" ], "details": "PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-57h3-4hgq-6hc9/GHSA-57h3-4hgq-6hc9.json b/advisories/unreviewed/2022/04/GHSA-57h3-4hgq-6hc9/GHSA-57h3-4hgq-6hc9.json index fd4b17adad8..2d411b97bcb 100644 --- a/advisories/unreviewed/2022/04/GHSA-57h3-4hgq-6hc9/GHSA-57h3-4hgq-6hc9.json +++ b/advisories/unreviewed/2022/04/GHSA-57h3-4hgq-6hc9/GHSA-57h3-4hgq-6hc9.json @@ -7,12 +7,8 @@ "CVE-2004-1633" ], "details": "process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json b/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json index e05a87f357a..4f43ed33659 100644 --- a/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json +++ b/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-5ghm-fxvf-qqww/GHSA-5ghm-fxvf-qqww.json b/advisories/unreviewed/2022/04/GHSA-5ghm-fxvf-qqww/GHSA-5ghm-fxvf-qqww.json index 63be9ec9b9f..4bc63565f0d 100644 --- a/advisories/unreviewed/2022/04/GHSA-5ghm-fxvf-qqww/GHSA-5ghm-fxvf-qqww.json +++ b/advisories/unreviewed/2022/04/GHSA-5ghm-fxvf-qqww/GHSA-5ghm-fxvf-qqww.json @@ -7,12 +7,8 @@ "CVE-2004-1722" ], "details": "SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5j4q-p8r9-g32c/GHSA-5j4q-p8r9-g32c.json b/advisories/unreviewed/2022/04/GHSA-5j4q-p8r9-g32c/GHSA-5j4q-p8r9-g32c.json index cc0b0946668..2df7a9a898c 100644 --- a/advisories/unreviewed/2022/04/GHSA-5j4q-p8r9-g32c/GHSA-5j4q-p8r9-g32c.json +++ b/advisories/unreviewed/2022/04/GHSA-5j4q-p8r9-g32c/GHSA-5j4q-p8r9-g32c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5p96-h7hc-r39x/GHSA-5p96-h7hc-r39x.json b/advisories/unreviewed/2022/04/GHSA-5p96-h7hc-r39x/GHSA-5p96-h7hc-r39x.json index ef526fff172..6c809a5b883 100644 --- a/advisories/unreviewed/2022/04/GHSA-5p96-h7hc-r39x/GHSA-5p96-h7hc-r39x.json +++ b/advisories/unreviewed/2022/04/GHSA-5p96-h7hc-r39x/GHSA-5p96-h7hc-r39x.json @@ -7,12 +7,8 @@ "CVE-2004-1719" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an tag, or (15) the subject of an e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5rfj-g58v-h7w2/GHSA-5rfj-g58v-h7w2.json b/advisories/unreviewed/2022/04/GHSA-5rfj-g58v-h7w2/GHSA-5rfj-g58v-h7w2.json index cdc387b02fc..009486edf68 100644 --- a/advisories/unreviewed/2022/04/GHSA-5rfj-g58v-h7w2/GHSA-5rfj-g58v-h7w2.json +++ b/advisories/unreviewed/2022/04/GHSA-5rfj-g58v-h7w2/GHSA-5rfj-g58v-h7w2.json @@ -7,12 +7,8 @@ "CVE-2004-1730" ], "details": "Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup.php, (3) action parameter to login_select_proj_page.php, or (4) hide_status parameter to view_all_set.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5wrm-j5hw-2wjj/GHSA-5wrm-j5hw-2wjj.json b/advisories/unreviewed/2022/04/GHSA-5wrm-j5hw-2wjj/GHSA-5wrm-j5hw-2wjj.json index 5ef55f0ef78..97c663af258 100644 --- a/advisories/unreviewed/2022/04/GHSA-5wrm-j5hw-2wjj/GHSA-5wrm-j5hw-2wjj.json +++ b/advisories/unreviewed/2022/04/GHSA-5wrm-j5hw-2wjj/GHSA-5wrm-j5hw-2wjj.json @@ -7,12 +7,8 @@ "CVE-2004-1688" ], "details": "Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sent to port 3103.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5xw5-44j8-6h82/GHSA-5xw5-44j8-6h82.json b/advisories/unreviewed/2022/04/GHSA-5xw5-44j8-6h82/GHSA-5xw5-44j8-6h82.json index 36df12affe4..42a8fd8caa7 100644 --- a/advisories/unreviewed/2022/04/GHSA-5xw5-44j8-6h82/GHSA-5xw5-44j8-6h82.json +++ b/advisories/unreviewed/2022/04/GHSA-5xw5-44j8-6h82/GHSA-5xw5-44j8-6h82.json @@ -7,12 +7,8 @@ "CVE-2004-1731" ], "details": "signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6569-w2hm-vh9q/GHSA-6569-w2hm-vh9q.json b/advisories/unreviewed/2022/04/GHSA-6569-w2hm-vh9q/GHSA-6569-w2hm-vh9q.json index cf4404f77c0..1b4742e7704 100644 --- a/advisories/unreviewed/2022/04/GHSA-6569-w2hm-vh9q/GHSA-6569-w2hm-vh9q.json +++ b/advisories/unreviewed/2022/04/GHSA-6569-w2hm-vh9q/GHSA-6569-w2hm-vh9q.json @@ -7,12 +7,8 @@ "CVE-2004-1742" ], "details": "Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-66ff-xg83-gqqx/GHSA-66ff-xg83-gqqx.json b/advisories/unreviewed/2022/04/GHSA-66ff-xg83-gqqx/GHSA-66ff-xg83-gqqx.json index 9f28cd8d2ca..2bdf7e018d9 100644 --- a/advisories/unreviewed/2022/04/GHSA-66ff-xg83-gqqx/GHSA-66ff-xg83-gqqx.json +++ b/advisories/unreviewed/2022/04/GHSA-66ff-xg83-gqqx/GHSA-66ff-xg83-gqqx.json @@ -7,12 +7,8 @@ "CVE-2004-1707" ], "details": "The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6hhc-9578-w8h2/GHSA-6hhc-9578-w8h2.json b/advisories/unreviewed/2022/04/GHSA-6hhc-9578-w8h2/GHSA-6hhc-9578-w8h2.json index 88550fdba13..a0ff7137f06 100644 --- a/advisories/unreviewed/2022/04/GHSA-6hhc-9578-w8h2/GHSA-6hhc-9578-w8h2.json +++ b/advisories/unreviewed/2022/04/GHSA-6hhc-9578-w8h2/GHSA-6hhc-9578-w8h2.json @@ -7,12 +7,8 @@ "CVE-2004-1607" ], "details": "slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6m87-jr5w-7c85/GHSA-6m87-jr5w-7c85.json b/advisories/unreviewed/2022/04/GHSA-6m87-jr5w-7c85/GHSA-6m87-jr5w-7c85.json index b1341da4628..78dc4e31fec 100644 --- a/advisories/unreviewed/2022/04/GHSA-6m87-jr5w-7c85/GHSA-6m87-jr5w-7c85.json +++ b/advisories/unreviewed/2022/04/GHSA-6m87-jr5w-7c85/GHSA-6m87-jr5w-7c85.json @@ -7,12 +7,8 @@ "CVE-2004-1547" ], "details": "The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6m92-qjr5-r83w/GHSA-6m92-qjr5-r83w.json b/advisories/unreviewed/2022/04/GHSA-6m92-qjr5-r83w/GHSA-6m92-qjr5-r83w.json index 61baaa8ab51..a16e58b2d93 100644 --- a/advisories/unreviewed/2022/04/GHSA-6m92-qjr5-r83w/GHSA-6m92-qjr5-r83w.json +++ b/advisories/unreviewed/2022/04/GHSA-6m92-qjr5-r83w/GHSA-6m92-qjr5-r83w.json @@ -7,12 +7,8 @@ "CVE-2004-1647" ], "details": "SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6mgc-h6hw-q65q/GHSA-6mgc-h6hw-q65q.json b/advisories/unreviewed/2022/04/GHSA-6mgc-h6hw-q65q/GHSA-6mgc-h6hw-q65q.json index 2ae744df23f..ffbfb9cd31b 100644 --- a/advisories/unreviewed/2022/04/GHSA-6mgc-h6hw-q65q/GHSA-6mgc-h6hw-q65q.json +++ b/advisories/unreviewed/2022/04/GHSA-6mgc-h6hw-q65q/GHSA-6mgc-h6hw-q65q.json @@ -7,12 +7,8 @@ "CVE-2004-1649" ], "details": "Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6mhg-8xpv-r877/GHSA-6mhg-8xpv-r877.json b/advisories/unreviewed/2022/04/GHSA-6mhg-8xpv-r877/GHSA-6mhg-8xpv-r877.json index 6b397d0b293..fbbc4e97f85 100644 --- a/advisories/unreviewed/2022/04/GHSA-6mhg-8xpv-r877/GHSA-6mhg-8xpv-r877.json +++ b/advisories/unreviewed/2022/04/GHSA-6mhg-8xpv-r877/GHSA-6mhg-8xpv-r877.json @@ -7,12 +7,8 @@ "CVE-2004-1718" ], "details": "The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the \"oa\" argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6mxv-f2hm-j5mm/GHSA-6mxv-f2hm-j5mm.json b/advisories/unreviewed/2022/04/GHSA-6mxv-f2hm-j5mm/GHSA-6mxv-f2hm-j5mm.json index cfaa44d9907..cf93cd27de8 100644 --- a/advisories/unreviewed/2022/04/GHSA-6mxv-f2hm-j5mm/GHSA-6mxv-f2hm-j5mm.json +++ b/advisories/unreviewed/2022/04/GHSA-6mxv-f2hm-j5mm/GHSA-6mxv-f2hm-j5mm.json @@ -7,12 +7,8 @@ "CVE-2004-1673" ], "details": "accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text files with arbitrary content via the accountid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6r2q-2w5h-xffp/GHSA-6r2q-2w5h-xffp.json b/advisories/unreviewed/2022/04/GHSA-6r2q-2w5h-xffp/GHSA-6r2q-2w5h-xffp.json index ecdc3ef6e17..9bb2fac77b9 100644 --- a/advisories/unreviewed/2022/04/GHSA-6r2q-2w5h-xffp/GHSA-6r2q-2w5h-xffp.json +++ b/advisories/unreviewed/2022/04/GHSA-6r2q-2w5h-xffp/GHSA-6r2q-2w5h-xffp.json @@ -7,12 +7,8 @@ "CVE-2004-1664" ], "details": "Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection mechanism. NOTE: this issue might overlap CVE-2005-0430.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6r6r-2p6c-hcvv/GHSA-6r6r-2p6c-hcvv.json b/advisories/unreviewed/2022/04/GHSA-6r6r-2p6c-hcvv/GHSA-6r6r-2p6c-hcvv.json index 44209e45d28..4819a950adf 100644 --- a/advisories/unreviewed/2022/04/GHSA-6r6r-2p6c-hcvv/GHSA-6r6r-2p6c-hcvv.json +++ b/advisories/unreviewed/2022/04/GHSA-6r6r-2p6c-hcvv/GHSA-6r6r-2p6c-hcvv.json @@ -7,12 +7,8 @@ "CVE-2004-1631" ], "details": "Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the results.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6wh4-77gr-x4gj/GHSA-6wh4-77gr-x4gj.json b/advisories/unreviewed/2022/04/GHSA-6wh4-77gr-x4gj/GHSA-6wh4-77gr-x4gj.json index 87897232807..a5e59b4387a 100644 --- a/advisories/unreviewed/2022/04/GHSA-6wh4-77gr-x4gj/GHSA-6wh4-77gr-x4gj.json +++ b/advisories/unreviewed/2022/04/GHSA-6wh4-77gr-x4gj/GHSA-6wh4-77gr-x4gj.json @@ -7,12 +7,8 @@ "CVE-2004-1636" ], "details": "Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6x5x-c996-pqhh/GHSA-6x5x-c996-pqhh.json b/advisories/unreviewed/2022/04/GHSA-6x5x-c996-pqhh/GHSA-6x5x-c996-pqhh.json index 2677dc70cd9..cffc33a19b4 100644 --- a/advisories/unreviewed/2022/04/GHSA-6x5x-c996-pqhh/GHSA-6x5x-c996-pqhh.json +++ b/advisories/unreviewed/2022/04/GHSA-6x5x-c996-pqhh/GHSA-6x5x-c996-pqhh.json @@ -7,12 +7,8 @@ "CVE-2004-1729" ], "details": "Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6xc9-5x2c-v57j/GHSA-6xc9-5x2c-v57j.json b/advisories/unreviewed/2022/04/GHSA-6xc9-5x2c-v57j/GHSA-6xc9-5x2c-v57j.json index ad831070f6a..ccdfc1a937a 100644 --- a/advisories/unreviewed/2022/04/GHSA-6xc9-5x2c-v57j/GHSA-6xc9-5x2c-v57j.json +++ b/advisories/unreviewed/2022/04/GHSA-6xc9-5x2c-v57j/GHSA-6xc9-5x2c-v57j.json @@ -7,12 +7,8 @@ "CVE-2004-1709" ], "details": "Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token and the driver, which could allow local users to obtain the PINs of other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-72jm-m44p-fqqc/GHSA-72jm-m44p-fqqc.json b/advisories/unreviewed/2022/04/GHSA-72jm-m44p-fqqc/GHSA-72jm-m44p-fqqc.json index f930c45624d..55e96d8ecf0 100644 --- a/advisories/unreviewed/2022/04/GHSA-72jm-m44p-fqqc/GHSA-72jm-m44p-fqqc.json +++ b/advisories/unreviewed/2022/04/GHSA-72jm-m44p-fqqc/GHSA-72jm-m44p-fqqc.json @@ -7,12 +7,8 @@ "CVE-2004-1672" ], "details": "attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attachments by specifying the username and message ID in an HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-72pr-qpg4-f6xj/GHSA-72pr-qpg4-f6xj.json b/advisories/unreviewed/2022/04/GHSA-72pr-qpg4-f6xj/GHSA-72pr-qpg4-f6xj.json index 36d34333b8b..22dcadefede 100644 --- a/advisories/unreviewed/2022/04/GHSA-72pr-qpg4-f6xj/GHSA-72pr-qpg4-f6xj.json +++ b/advisories/unreviewed/2022/04/GHSA-72pr-qpg4-f6xj/GHSA-72pr-qpg4-f6xj.json @@ -7,12 +7,8 @@ "CVE-2004-1695" ], "details": "EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-763p-5832-h4vj/GHSA-763p-5832-h4vj.json b/advisories/unreviewed/2022/04/GHSA-763p-5832-h4vj/GHSA-763p-5832-h4vj.json index d0cccb79b1f..edd6790739a 100644 --- a/advisories/unreviewed/2022/04/GHSA-763p-5832-h4vj/GHSA-763p-5832-h4vj.json +++ b/advisories/unreviewed/2022/04/GHSA-763p-5832-h4vj/GHSA-763p-5832-h4vj.json @@ -7,12 +7,8 @@ "CVE-2004-1581" ], "details": "BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7gjr-q697-2f77/GHSA-7gjr-q697-2f77.json b/advisories/unreviewed/2022/04/GHSA-7gjr-q697-2f77/GHSA-7gjr-q697-2f77.json index 205b02c696d..77b781d5c36 100644 --- a/advisories/unreviewed/2022/04/GHSA-7gjr-q697-2f77/GHSA-7gjr-q697-2f77.json +++ b/advisories/unreviewed/2022/04/GHSA-7gjr-q697-2f77/GHSA-7gjr-q697-2f77.json @@ -7,12 +7,8 @@ "CVE-2004-1698" ], "details": "The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7mr8-86xj-xmxp/GHSA-7mr8-86xj-xmxp.json b/advisories/unreviewed/2022/04/GHSA-7mr8-86xj-xmxp/GHSA-7mr8-86xj-xmxp.json index 9df1dd41dff..ebb37853f9b 100644 --- a/advisories/unreviewed/2022/04/GHSA-7mr8-86xj-xmxp/GHSA-7mr8-86xj-xmxp.json +++ b/advisories/unreviewed/2022/04/GHSA-7mr8-86xj-xmxp/GHSA-7mr8-86xj-xmxp.json @@ -7,12 +7,8 @@ "CVE-2004-1656" ], "details": "CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7pvr-mj99-7r8h/GHSA-7pvr-mj99-7r8h.json b/advisories/unreviewed/2022/04/GHSA-7pvr-mj99-7r8h/GHSA-7pvr-mj99-7r8h.json index 866645f913e..98afea09ff6 100644 --- a/advisories/unreviewed/2022/04/GHSA-7pvr-mj99-7r8h/GHSA-7pvr-mj99-7r8h.json +++ b/advisories/unreviewed/2022/04/GHSA-7pvr-mj99-7r8h/GHSA-7pvr-mj99-7r8h.json @@ -7,12 +7,8 @@ "CVE-2004-1697" ], "details": "The \"Forgot your Password\" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7v39-48jj-rjrh/GHSA-7v39-48jj-rjrh.json b/advisories/unreviewed/2022/04/GHSA-7v39-48jj-rjrh/GHSA-7v39-48jj-rjrh.json index a0154151c44..14d75fa9303 100644 --- a/advisories/unreviewed/2022/04/GHSA-7v39-48jj-rjrh/GHSA-7v39-48jj-rjrh.json +++ b/advisories/unreviewed/2022/04/GHSA-7v39-48jj-rjrh/GHSA-7v39-48jj-rjrh.json @@ -7,12 +7,8 @@ "CVE-2004-1598" ], "details": "Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7wmc-wm7f-rg53/GHSA-7wmc-wm7f-rg53.json b/advisories/unreviewed/2022/04/GHSA-7wmc-wm7f-rg53/GHSA-7wmc-wm7f-rg53.json index 0bd9d230ca3..7a26b2831f0 100644 --- a/advisories/unreviewed/2022/04/GHSA-7wmc-wm7f-rg53/GHSA-7wmc-wm7f-rg53.json +++ b/advisories/unreviewed/2022/04/GHSA-7wmc-wm7f-rg53/GHSA-7wmc-wm7f-rg53.json @@ -7,12 +7,8 @@ "CVE-2004-1576" ], "details": "Format string vulnerability in Judge Dredd: Dredd vs. Death 1.01 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a chat message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8cvx-3rg5-x9j3/GHSA-8cvx-3rg5-x9j3.json b/advisories/unreviewed/2022/04/GHSA-8cvx-3rg5-x9j3/GHSA-8cvx-3rg5-x9j3.json index 8be22c5dc62..b842c83f612 100644 --- a/advisories/unreviewed/2022/04/GHSA-8cvx-3rg5-x9j3/GHSA-8cvx-3rg5-x9j3.json +++ b/advisories/unreviewed/2022/04/GHSA-8cvx-3rg5-x9j3/GHSA-8cvx-3rg5-x9j3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-8fpx-4fc3-m2g2/GHSA-8fpx-4fc3-m2g2.json b/advisories/unreviewed/2022/04/GHSA-8fpx-4fc3-m2g2/GHSA-8fpx-4fc3-m2g2.json index 4a12dc50f03..07cc8783aa5 100644 --- a/advisories/unreviewed/2022/04/GHSA-8fpx-4fc3-m2g2/GHSA-8fpx-4fc3-m2g2.json +++ b/advisories/unreviewed/2022/04/GHSA-8fpx-4fc3-m2g2/GHSA-8fpx-4fc3-m2g2.json @@ -7,12 +7,8 @@ "CVE-2004-1751" ], "details": "Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet, which generates a \"Message too long\" socket error that is treated as a critical error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8j36-g58p-4q96/GHSA-8j36-g58p-4q96.json b/advisories/unreviewed/2022/04/GHSA-8j36-g58p-4q96/GHSA-8j36-g58p-4q96.json index 8e598e459e2..a605dfd08bc 100644 --- a/advisories/unreviewed/2022/04/GHSA-8j36-g58p-4q96/GHSA-8j36-g58p-4q96.json +++ b/advisories/unreviewed/2022/04/GHSA-8j36-g58p-4q96/GHSA-8j36-g58p-4q96.json @@ -7,12 +7,8 @@ "CVE-2004-1700" ], "details": "Cross-site scripting (XSS) vulnerability in SettingsBase.php in Pinnacle ShowCenter 1.51 build 121 allows remote attackers to inject arbitrary HTML or web script via the Skin parameter, which is echoed in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8qpv-69qh-f6fm/GHSA-8qpv-69qh-f6fm.json b/advisories/unreviewed/2022/04/GHSA-8qpv-69qh-f6fm/GHSA-8qpv-69qh-f6fm.json index 5d8975b7ab8..a8d6f493f87 100644 --- a/advisories/unreviewed/2022/04/GHSA-8qpv-69qh-f6fm/GHSA-8qpv-69qh-f6fm.json +++ b/advisories/unreviewed/2022/04/GHSA-8qpv-69qh-f6fm/GHSA-8qpv-69qh-f6fm.json @@ -7,12 +7,8 @@ "CVE-2004-1736" ], "details": "Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8rc7-gfvj-2hjx/GHSA-8rc7-gfvj-2hjx.json b/advisories/unreviewed/2022/04/GHSA-8rc7-gfvj-2hjx/GHSA-8rc7-gfvj-2hjx.json index cd11fe20c17..3e3f7688991 100644 --- a/advisories/unreviewed/2022/04/GHSA-8rc7-gfvj-2hjx/GHSA-8rc7-gfvj-2hjx.json +++ b/advisories/unreviewed/2022/04/GHSA-8rc7-gfvj-2hjx/GHSA-8rc7-gfvj-2hjx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8rv5-m3x9-445f/GHSA-8rv5-m3x9-445f.json b/advisories/unreviewed/2022/04/GHSA-8rv5-m3x9-445f/GHSA-8rv5-m3x9-445f.json index 8e3e8c7d02a..093c65407c2 100644 --- a/advisories/unreviewed/2022/04/GHSA-8rv5-m3x9-445f/GHSA-8rv5-m3x9-445f.json +++ b/advisories/unreviewed/2022/04/GHSA-8rv5-m3x9-445f/GHSA-8rv5-m3x9-445f.json @@ -7,12 +7,8 @@ "CVE-2004-1683" ], "details": "A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9725-v8gc-7c9f/GHSA-9725-v8gc-7c9f.json b/advisories/unreviewed/2022/04/GHSA-9725-v8gc-7c9f/GHSA-9725-v8gc-7c9f.json index 007f51c320f..bda447a50de 100644 --- a/advisories/unreviewed/2022/04/GHSA-9725-v8gc-7c9f/GHSA-9725-v8gc-7c9f.json +++ b/advisories/unreviewed/2022/04/GHSA-9725-v8gc-7c9f/GHSA-9725-v8gc-7c9f.json @@ -7,12 +7,8 @@ "CVE-2004-1580" ], "details": "SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-99g5-8fv2-6cgr/GHSA-99g5-8fv2-6cgr.json b/advisories/unreviewed/2022/04/GHSA-99g5-8fv2-6cgr/GHSA-99g5-8fv2-6cgr.json index 3e96010d2d5..c2617e2ea1d 100644 --- a/advisories/unreviewed/2022/04/GHSA-99g5-8fv2-6cgr/GHSA-99g5-8fv2-6cgr.json +++ b/advisories/unreviewed/2022/04/GHSA-99g5-8fv2-6cgr/GHSA-99g5-8fv2-6cgr.json @@ -7,12 +7,8 @@ "CVE-2004-1715" ], "details": "Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via \"..\\\\\", \"..\\\", and similar dot dot sequences in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9cm9-mwhq-5792/GHSA-9cm9-mwhq-5792.json b/advisories/unreviewed/2022/04/GHSA-9cm9-mwhq-5792/GHSA-9cm9-mwhq-5792.json index db05b26807a..cacf97663d2 100644 --- a/advisories/unreviewed/2022/04/GHSA-9cm9-mwhq-5792/GHSA-9cm9-mwhq-5792.json +++ b/advisories/unreviewed/2022/04/GHSA-9cm9-mwhq-5792/GHSA-9cm9-mwhq-5792.json @@ -7,12 +7,8 @@ "CVE-2004-1563" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9r9h-3x7g-qvjq/GHSA-9r9h-3x7g-qvjq.json b/advisories/unreviewed/2022/04/GHSA-9r9h-3x7g-qvjq/GHSA-9r9h-3x7g-qvjq.json index 544366ced78..bbbac333290 100644 --- a/advisories/unreviewed/2022/04/GHSA-9r9h-3x7g-qvjq/GHSA-9r9h-3x7g-qvjq.json +++ b/advisories/unreviewed/2022/04/GHSA-9r9h-3x7g-qvjq/GHSA-9r9h-3x7g-qvjq.json @@ -7,12 +7,8 @@ "CVE-2004-1734" ], "details": "PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter to relationship_api.php to reference a URL on a remote web server that contains the code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9rg5-49f6-x8mf/GHSA-9rg5-49f6-x8mf.json b/advisories/unreviewed/2022/04/GHSA-9rg5-49f6-x8mf/GHSA-9rg5-49f6-x8mf.json index 277defac5e8..4fb36aa9d56 100644 --- a/advisories/unreviewed/2022/04/GHSA-9rg5-49f6-x8mf/GHSA-9rg5-49f6-x8mf.json +++ b/advisories/unreviewed/2022/04/GHSA-9rg5-49f6-x8mf/GHSA-9rg5-49f6-x8mf.json @@ -7,12 +7,8 @@ "CVE-2004-1750" ], "details": "RealVNC 4.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of connections to port 5900.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9rpj-3h3j-f5ch/GHSA-9rpj-3h3j-f5ch.json b/advisories/unreviewed/2022/04/GHSA-9rpj-3h3j-f5ch/GHSA-9rpj-3h3j-f5ch.json index 521b6fb5b4a..ade71956015 100644 --- a/advisories/unreviewed/2022/04/GHSA-9rpj-3h3j-f5ch/GHSA-9rpj-3h3j-f5ch.json +++ b/advisories/unreviewed/2022/04/GHSA-9rpj-3h3j-f5ch/GHSA-9rpj-3h3j-f5ch.json @@ -7,12 +7,8 @@ "CVE-2004-1616" ], "details": "Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9vfc-272p-57xp/GHSA-9vfc-272p-57xp.json b/advisories/unreviewed/2022/04/GHSA-9vfc-272p-57xp/GHSA-9vfc-272p-57xp.json index b6a2e374a27..b6a46fa59fc 100644 --- a/advisories/unreviewed/2022/04/GHSA-9vfc-272p-57xp/GHSA-9vfc-272p-57xp.json +++ b/advisories/unreviewed/2022/04/GHSA-9vfc-272p-57xp/GHSA-9vfc-272p-57xp.json @@ -7,12 +7,8 @@ "CVE-2004-1681" ], "details": "Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) command line parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9vmq-vwpx-f975/GHSA-9vmq-vwpx-f975.json b/advisories/unreviewed/2022/04/GHSA-9vmq-vwpx-f975/GHSA-9vmq-vwpx-f975.json index 374d7773ba3..297cfe48cf9 100644 --- a/advisories/unreviewed/2022/04/GHSA-9vmq-vwpx-f975/GHSA-9vmq-vwpx-f975.json +++ b/advisories/unreviewed/2022/04/GHSA-9vmq-vwpx-f975/GHSA-9vmq-vwpx-f975.json @@ -7,12 +7,8 @@ "CVE-2004-1679" ], "details": "Directory traversal vulnerability in TwinFTP 1.0.3 R2 allows remote attackers to create arbitrary files via a .../ (triple dot) in the (1) CWD, (2) STOR, or (3) RETR commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9x27-fwpx-qjx8/GHSA-9x27-fwpx-qjx8.json b/advisories/unreviewed/2022/04/GHSA-9x27-fwpx-qjx8/GHSA-9x27-fwpx-qjx8.json index a0bcbf35b37..abbc0461c57 100644 --- a/advisories/unreviewed/2022/04/GHSA-9x27-fwpx-qjx8/GHSA-9x27-fwpx-qjx8.json +++ b/advisories/unreviewed/2022/04/GHSA-9x27-fwpx-qjx8/GHSA-9x27-fwpx-qjx8.json @@ -7,12 +7,8 @@ "CVE-2004-1639" ], "details": "Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c3mw-fh2q-7xx4/GHSA-c3mw-fh2q-7xx4.json b/advisories/unreviewed/2022/04/GHSA-c3mw-fh2q-7xx4/GHSA-c3mw-fh2q-7xx4.json index c2c75a00ab0..9cf7874d57b 100644 --- a/advisories/unreviewed/2022/04/GHSA-c3mw-fh2q-7xx4/GHSA-c3mw-fh2q-7xx4.json +++ b/advisories/unreviewed/2022/04/GHSA-c3mw-fh2q-7xx4/GHSA-c3mw-fh2q-7xx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c5xw-hcq7-rj2g/GHSA-c5xw-hcq7-rj2g.json b/advisories/unreviewed/2022/04/GHSA-c5xw-hcq7-rj2g/GHSA-c5xw-hcq7-rj2g.json index 8b295108f1e..289458914ae 100644 --- a/advisories/unreviewed/2022/04/GHSA-c5xw-hcq7-rj2g/GHSA-c5xw-hcq7-rj2g.json +++ b/advisories/unreviewed/2022/04/GHSA-c5xw-hcq7-rj2g/GHSA-c5xw-hcq7-rj2g.json @@ -7,12 +7,8 @@ "CVE-2004-1685" ], "details": "SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c8hp-7fgw-gpw8/GHSA-c8hp-7fgw-gpw8.json b/advisories/unreviewed/2022/04/GHSA-c8hp-7fgw-gpw8/GHSA-c8hp-7fgw-gpw8.json index 4fbc4a498a9..3be24f471a6 100644 --- a/advisories/unreviewed/2022/04/GHSA-c8hp-7fgw-gpw8/GHSA-c8hp-7fgw-gpw8.json +++ b/advisories/unreviewed/2022/04/GHSA-c8hp-7fgw-gpw8/GHSA-c8hp-7fgw-gpw8.json @@ -7,12 +7,8 @@ "CVE-2004-1691" ], "details": "The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cf67-7j7r-89q3/GHSA-cf67-7j7r-89q3.json b/advisories/unreviewed/2022/04/GHSA-cf67-7j7r-89q3/GHSA-cf67-7j7r-89q3.json index 1e27c677a8f..0f70b68a1e2 100644 --- a/advisories/unreviewed/2022/04/GHSA-cf67-7j7r-89q3/GHSA-cf67-7j7r-89q3.json +++ b/advisories/unreviewed/2022/04/GHSA-cf67-7j7r-89q3/GHSA-cf67-7j7r-89q3.json @@ -7,12 +7,8 @@ "CVE-2004-1628" ], "details": "Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-cfrm-mc6g-2q3f/GHSA-cfrm-mc6g-2q3f.json b/advisories/unreviewed/2022/04/GHSA-cfrm-mc6g-2q3f/GHSA-cfrm-mc6g-2q3f.json index 160d8ac84a9..de228f24a11 100644 --- a/advisories/unreviewed/2022/04/GHSA-cfrm-mc6g-2q3f/GHSA-cfrm-mc6g-2q3f.json +++ b/advisories/unreviewed/2022/04/GHSA-cfrm-mc6g-2q3f/GHSA-cfrm-mc6g-2q3f.json @@ -7,12 +7,8 @@ "CVE-2004-1614" ], "details": "Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an \"unusual combination of visual elements,\" including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cfxp-7mcx-7phh/GHSA-cfxp-7mcx-7phh.json b/advisories/unreviewed/2022/04/GHSA-cfxp-7mcx-7phh/GHSA-cfxp-7mcx-7phh.json index c01957870d9..222e1086109 100644 --- a/advisories/unreviewed/2022/04/GHSA-cfxp-7mcx-7phh/GHSA-cfxp-7mcx-7phh.json +++ b/advisories/unreviewed/2022/04/GHSA-cfxp-7mcx-7phh/GHSA-cfxp-7mcx-7phh.json @@ -7,12 +7,8 @@ "CVE-2004-1662" ], "details": "YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cqh3-66qm-fc26/GHSA-cqh3-66qm-fc26.json b/advisories/unreviewed/2022/04/GHSA-cqh3-66qm-fc26/GHSA-cqh3-66qm-fc26.json index a12355cdc79..2112a418145 100644 --- a/advisories/unreviewed/2022/04/GHSA-cqh3-66qm-fc26/GHSA-cqh3-66qm-fc26.json +++ b/advisories/unreviewed/2022/04/GHSA-cqh3-66qm-fc26/GHSA-cqh3-66qm-fc26.json @@ -7,12 +7,8 @@ "CVE-2004-1569" ], "details": "Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or execute arbitrary code via a .pls or .m3u playlist that contains long File1 (filename) fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f4rg-5qc9-c5v5/GHSA-f4rg-5qc9-c5v5.json b/advisories/unreviewed/2022/04/GHSA-f4rg-5qc9-c5v5/GHSA-f4rg-5qc9-c5v5.json index 74575210704..09c0cf38c9f 100644 --- a/advisories/unreviewed/2022/04/GHSA-f4rg-5qc9-c5v5/GHSA-f4rg-5qc9-c5v5.json +++ b/advisories/unreviewed/2022/04/GHSA-f4rg-5qc9-c5v5/GHSA-f4rg-5qc9-c5v5.json @@ -7,12 +7,8 @@ "CVE-2004-1584" ], "details": "CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f6px-r4ch-xrcj/GHSA-f6px-r4ch-xrcj.json b/advisories/unreviewed/2022/04/GHSA-f6px-r4ch-xrcj/GHSA-f6px-r4ch-xrcj.json index f34e13c0604..b6a69ab390b 100644 --- a/advisories/unreviewed/2022/04/GHSA-f6px-r4ch-xrcj/GHSA-f6px-r4ch-xrcj.json +++ b/advisories/unreviewed/2022/04/GHSA-f6px-r4ch-xrcj/GHSA-f6px-r4ch-xrcj.json @@ -7,12 +7,8 @@ "CVE-2004-1694" ], "details": "Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-frch-j9xm-v3rx/GHSA-frch-j9xm-v3rx.json b/advisories/unreviewed/2022/04/GHSA-frch-j9xm-v3rx/GHSA-frch-j9xm-v3rx.json index daf3a40b5fa..19ae373dd61 100644 --- a/advisories/unreviewed/2022/04/GHSA-frch-j9xm-v3rx/GHSA-frch-j9xm-v3rx.json +++ b/advisories/unreviewed/2022/04/GHSA-frch-j9xm-v3rx/GHSA-frch-j9xm-v3rx.json @@ -7,12 +7,8 @@ "CVE-2004-1578" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fvfp-vfmf-mhwp/GHSA-fvfp-vfmf-mhwp.json b/advisories/unreviewed/2022/04/GHSA-fvfp-vfmf-mhwp/GHSA-fvfp-vfmf-mhwp.json index 7b656905054..a139a5ae783 100644 --- a/advisories/unreviewed/2022/04/GHSA-fvfp-vfmf-mhwp/GHSA-fvfp-vfmf-mhwp.json +++ b/advisories/unreviewed/2022/04/GHSA-fvfp-vfmf-mhwp/GHSA-fvfp-vfmf-mhwp.json @@ -7,12 +7,8 @@ "CVE-2004-1608" ], "details": "SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g2gh-64hj-766p/GHSA-g2gh-64hj-766p.json b/advisories/unreviewed/2022/04/GHSA-g2gh-64hj-766p/GHSA-g2gh-64hj-766p.json index 5883567ee2d..b90fb7c4e09 100644 --- a/advisories/unreviewed/2022/04/GHSA-g2gh-64hj-766p/GHSA-g2gh-64hj-766p.json +++ b/advisories/unreviewed/2022/04/GHSA-g2gh-64hj-766p/GHSA-g2gh-64hj-766p.json @@ -7,12 +7,8 @@ "CVE-2004-1666" ], "details": "Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g4v6-4jj6-xg55/GHSA-g4v6-4jj6-xg55.json b/advisories/unreviewed/2022/04/GHSA-g4v6-4jj6-xg55/GHSA-g4v6-4jj6-xg55.json index 2319c7a7526..e811518ad24 100644 --- a/advisories/unreviewed/2022/04/GHSA-g4v6-4jj6-xg55/GHSA-g4v6-4jj6-xg55.json +++ b/advisories/unreviewed/2022/04/GHSA-g4v6-4jj6-xg55/GHSA-g4v6-4jj6-xg55.json @@ -7,12 +7,8 @@ "CVE-2004-1571" ], "details": "AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) ount-article-views.php, (4) kses.php, (5) custom-quick-tags.php, (6) disable-all-comments.php, (7) easy-date-format.php, (8) enable-disable-comments.php, (9) filter-by-author.php, (10) format-switcher.php, (11) long-to-short.php, (12) prospective-posting.php, or (13) sort-by-xfield.php, which displays the full path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g8qj-v5c9-523w/GHSA-g8qj-v5c9-523w.json b/advisories/unreviewed/2022/04/GHSA-g8qj-v5c9-523w/GHSA-g8qj-v5c9-523w.json index 81ab126e0a1..ac30e83e120 100644 --- a/advisories/unreviewed/2022/04/GHSA-g8qj-v5c9-523w/GHSA-g8qj-v5c9-523w.json +++ b/advisories/unreviewed/2022/04/GHSA-g8qj-v5c9-523w/GHSA-g8qj-v5c9-523w.json @@ -7,12 +7,8 @@ "CVE-2004-1704" ], "details": "WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g9fc-7w7p-pf73/GHSA-g9fc-7w7p-pf73.json b/advisories/unreviewed/2022/04/GHSA-g9fc-7w7p-pf73/GHSA-g9fc-7w7p-pf73.json index d9b65704c4f..30ceee31cac 100644 --- a/advisories/unreviewed/2022/04/GHSA-g9fc-7w7p-pf73/GHSA-g9fc-7w7p-pf73.json +++ b/advisories/unreviewed/2022/04/GHSA-g9fc-7w7p-pf73/GHSA-g9fc-7w7p-pf73.json @@ -7,12 +7,8 @@ "CVE-2004-1725" ], "details": "Stack-based buffer overflow in xvbmp.c in XV allows remote attackers to execute arbitrary code via a crafted image file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g9rj-hq2r-84cm/GHSA-g9rj-hq2r-84cm.json b/advisories/unreviewed/2022/04/GHSA-g9rj-hq2r-84cm/GHSA-g9rj-hq2r-84cm.json index dc48f784e58..b81943dcd2b 100644 --- a/advisories/unreviewed/2022/04/GHSA-g9rj-hq2r-84cm/GHSA-g9rj-hq2r-84cm.json +++ b/advisories/unreviewed/2022/04/GHSA-g9rj-hq2r-84cm/GHSA-g9rj-hq2r-84cm.json @@ -7,12 +7,8 @@ "CVE-2004-1671" ], "details": "Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct request to (1) accountsettings_add.html or (2) topmenu.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gffr-5pg9-5cr5/GHSA-gffr-5pg9-5cr5.json b/advisories/unreviewed/2022/04/GHSA-gffr-5pg9-5cr5/GHSA-gffr-5pg9-5cr5.json index aa518481cb1..24168306eaf 100644 --- a/advisories/unreviewed/2022/04/GHSA-gffr-5pg9-5cr5/GHSA-gffr-5pg9-5cr5.json +++ b/advisories/unreviewed/2022/04/GHSA-gffr-5pg9-5cr5/GHSA-gffr-5pg9-5cr5.json @@ -7,12 +7,8 @@ "CVE-2004-1629" ], "details": "Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gr28-8w72-h95f/GHSA-gr28-8w72-h95f.json b/advisories/unreviewed/2022/04/GHSA-gr28-8w72-h95f/GHSA-gr28-8w72-h95f.json index bcad3953ae3..e0642a70abc 100644 --- a/advisories/unreviewed/2022/04/GHSA-gr28-8w72-h95f/GHSA-gr28-8w72-h95f.json +++ b/advisories/unreviewed/2022/04/GHSA-gr28-8w72-h95f/GHSA-gr28-8w72-h95f.json @@ -7,12 +7,8 @@ "CVE-2004-1652" ], "details": "phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gvcm-7pcm-j9rm/GHSA-gvcm-7pcm-j9rm.json b/advisories/unreviewed/2022/04/GHSA-gvcm-7pcm-j9rm/GHSA-gvcm-7pcm-j9rm.json index bb688db0421..2989cb8e2c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-gvcm-7pcm-j9rm/GHSA-gvcm-7pcm-j9rm.json +++ b/advisories/unreviewed/2022/04/GHSA-gvcm-7pcm-j9rm/GHSA-gvcm-7pcm-j9rm.json @@ -7,12 +7,8 @@ "CVE-2004-1713" ], "details": "Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gxx7-gprx-vg86/GHSA-gxx7-gprx-vg86.json b/advisories/unreviewed/2022/04/GHSA-gxx7-gprx-vg86/GHSA-gxx7-gprx-vg86.json index 1e1c6895c7d..c2f5619ed76 100644 --- a/advisories/unreviewed/2022/04/GHSA-gxx7-gprx-vg86/GHSA-gxx7-gprx-vg86.json +++ b/advisories/unreviewed/2022/04/GHSA-gxx7-gprx-vg86/GHSA-gxx7-gprx-vg86.json @@ -7,12 +7,8 @@ "CVE-2004-1587" ], "details": "Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h24f-7cpg-rrpm/GHSA-h24f-7cpg-rrpm.json b/advisories/unreviewed/2022/04/GHSA-h24f-7cpg-rrpm/GHSA-h24f-7cpg-rrpm.json index 031cc563b47..d375b8d66c2 100644 --- a/advisories/unreviewed/2022/04/GHSA-h24f-7cpg-rrpm/GHSA-h24f-7cpg-rrpm.json +++ b/advisories/unreviewed/2022/04/GHSA-h24f-7cpg-rrpm/GHSA-h24f-7cpg-rrpm.json @@ -7,12 +7,8 @@ "CVE-2004-1684" ], "details": "Zyxel P681 running ZyNOS Vt020225a contains portions of memory in an ARP request, which allows remote attackers to obtain sensitive information by sniffing the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h35f-36ph-rqj8/GHSA-h35f-36ph-rqj8.json b/advisories/unreviewed/2022/04/GHSA-h35f-36ph-rqj8/GHSA-h35f-36ph-rqj8.json index 3ae5979012d..a919820d9e0 100644 --- a/advisories/unreviewed/2022/04/GHSA-h35f-36ph-rqj8/GHSA-h35f-36ph-rqj8.json +++ b/advisories/unreviewed/2022/04/GHSA-h35f-36ph-rqj8/GHSA-h35f-36ph-rqj8.json @@ -7,12 +7,8 @@ "CVE-2004-1588" ], "details": "SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h3jp-chmm-392r/GHSA-h3jp-chmm-392r.json b/advisories/unreviewed/2022/04/GHSA-h3jp-chmm-392r/GHSA-h3jp-chmm-392r.json index 70958e4f738..7378ebcb8bc 100644 --- a/advisories/unreviewed/2022/04/GHSA-h3jp-chmm-392r/GHSA-h3jp-chmm-392r.json +++ b/advisories/unreviewed/2022/04/GHSA-h3jp-chmm-392r/GHSA-h3jp-chmm-392r.json @@ -7,12 +7,8 @@ "CVE-2004-1564" ], "details": "CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h3mh-53x4-8jwr/GHSA-h3mh-53x4-8jwr.json b/advisories/unreviewed/2022/04/GHSA-h3mh-53x4-8jwr/GHSA-h3mh-53x4-8jwr.json index bcc489a4775..480d09aa4f7 100644 --- a/advisories/unreviewed/2022/04/GHSA-h3mh-53x4-8jwr/GHSA-h3mh-53x4-8jwr.json +++ b/advisories/unreviewed/2022/04/GHSA-h3mh-53x4-8jwr/GHSA-h3mh-53x4-8jwr.json @@ -7,12 +7,8 @@ "CVE-2004-1625" ], "details": "pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows remote attackers to cause a denial of service by connecting via Remote Desktop and clicking restart or shutdown.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h46r-7fc6-g355/GHSA-h46r-7fc6-g355.json b/advisories/unreviewed/2022/04/GHSA-h46r-7fc6-g355/GHSA-h46r-7fc6-g355.json index d493b5b6198..2fe19cd2b29 100644 --- a/advisories/unreviewed/2022/04/GHSA-h46r-7fc6-g355/GHSA-h46r-7fc6-g355.json +++ b/advisories/unreviewed/2022/04/GHSA-h46r-7fc6-g355/GHSA-h46r-7fc6-g355.json @@ -7,12 +7,8 @@ "CVE-2004-1702" ], "details": "The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of service (crash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h6g7-m2qw-2j9q/GHSA-h6g7-m2qw-2j9q.json b/advisories/unreviewed/2022/04/GHSA-h6g7-m2qw-2j9q/GHSA-h6g7-m2qw-2j9q.json index adb1527ade9..e8caf139b85 100644 --- a/advisories/unreviewed/2022/04/GHSA-h6g7-m2qw-2j9q/GHSA-h6g7-m2qw-2j9q.json +++ b/advisories/unreviewed/2022/04/GHSA-h6g7-m2qw-2j9q/GHSA-h6g7-m2qw-2j9q.json @@ -7,12 +7,8 @@ "CVE-2004-1606" ], "details": "slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h6j8-h5j9-864g/GHSA-h6j8-h5j9-864g.json b/advisories/unreviewed/2022/04/GHSA-h6j8-h5j9-864g/GHSA-h6j8-h5j9-864g.json index 92b9202878d..71cb0f571b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-h6j8-h5j9-864g/GHSA-h6j8-h5j9-864g.json +++ b/advisories/unreviewed/2022/04/GHSA-h6j8-h5j9-864g/GHSA-h6j8-h5j9-864g.json @@ -7,12 +7,8 @@ "CVE-2004-1597" ], "details": "RIM Blackberry 7230 running RIM Blackberry OS 3.7 SP1 allows remote attackers to cause a denial of service (device reboot and possibly data corruption) via a calendar message with a long Location field, which triggers a watchdog while the message is being stored.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hcqp-hpgw-2hmj/GHSA-hcqp-hpgw-2hmj.json b/advisories/unreviewed/2022/04/GHSA-hcqp-hpgw-2hmj/GHSA-hcqp-hpgw-2hmj.json index 1fcbc62db3f..f6b38e6c92e 100644 --- a/advisories/unreviewed/2022/04/GHSA-hcqp-hpgw-2hmj/GHSA-hcqp-hpgw-2hmj.json +++ b/advisories/unreviewed/2022/04/GHSA-hcqp-hpgw-2hmj/GHSA-hcqp-hpgw-2hmj.json @@ -7,12 +7,8 @@ "CVE-2004-1755" ], "details": "The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hf24-j27r-97jc/GHSA-hf24-j27r-97jc.json b/advisories/unreviewed/2022/04/GHSA-hf24-j27r-97jc/GHSA-hf24-j27r-97jc.json index b20927f3955..b25d65caed3 100644 --- a/advisories/unreviewed/2022/04/GHSA-hf24-j27r-97jc/GHSA-hf24-j27r-97jc.json +++ b/advisories/unreviewed/2022/04/GHSA-hf24-j27r-97jc/GHSA-hf24-j27r-97jc.json @@ -7,12 +7,8 @@ "CVE-2004-1623" ], "details": "The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hffm-jhvp-jhqx/GHSA-hffm-jhvp-jhqx.json b/advisories/unreviewed/2022/04/GHSA-hffm-jhvp-jhqx/GHSA-hffm-jhvp-jhqx.json index dcad96a5194..55fc1876929 100644 --- a/advisories/unreviewed/2022/04/GHSA-hffm-jhvp-jhqx/GHSA-hffm-jhvp-jhqx.json +++ b/advisories/unreviewed/2022/04/GHSA-hffm-jhvp-jhqx/GHSA-hffm-jhvp-jhqx.json @@ -7,12 +7,8 @@ "CVE-2004-1676" ], "details": "Heap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG_MSG_IMAGE_REPLY message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hgx4-c8m2-fq38/GHSA-hgx4-c8m2-fq38.json b/advisories/unreviewed/2022/04/GHSA-hgx4-c8m2-fq38/GHSA-hgx4-c8m2-fq38.json index acc9a37e9d0..638270d942c 100644 --- a/advisories/unreviewed/2022/04/GHSA-hgx4-c8m2-fq38/GHSA-hgx4-c8m2-fq38.json +++ b/advisories/unreviewed/2022/04/GHSA-hgx4-c8m2-fq38/GHSA-hgx4-c8m2-fq38.json @@ -7,12 +7,8 @@ "CVE-2004-1626" ], "details": "Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hj48-8q8c-q7g9/GHSA-hj48-8q8c-q7g9.json b/advisories/unreviewed/2022/04/GHSA-hj48-8q8c-q7g9/GHSA-hj48-8q8c-q7g9.json index e88919e9146..a24b2f25f33 100644 --- a/advisories/unreviewed/2022/04/GHSA-hj48-8q8c-q7g9/GHSA-hj48-8q8c-q7g9.json +++ b/advisories/unreviewed/2022/04/GHSA-hj48-8q8c-q7g9/GHSA-hj48-8q8c-q7g9.json @@ -7,12 +7,8 @@ "CVE-2004-1711" ], "details": "Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hq49-5fpc-c85q/GHSA-hq49-5fpc-c85q.json b/advisories/unreviewed/2022/04/GHSA-hq49-5fpc-c85q/GHSA-hq49-5fpc-c85q.json index 504525a0b2b..17a78b86f7a 100644 --- a/advisories/unreviewed/2022/04/GHSA-hq49-5fpc-c85q/GHSA-hq49-5fpc-c85q.json +++ b/advisories/unreviewed/2022/04/GHSA-hq49-5fpc-c85q/GHSA-hq49-5fpc-c85q.json @@ -7,12 +7,8 @@ "CVE-2004-1678" ], "details": "Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via \"..\" sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hvgg-hv8j-3qv8/GHSA-hvgg-hv8j-3qv8.json b/advisories/unreviewed/2022/04/GHSA-hvgg-hv8j-3qv8/GHSA-hvgg-hv8j-3qv8.json index 4f087e58e62..e591ea143ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-hvgg-hv8j-3qv8/GHSA-hvgg-hv8j-3qv8.json +++ b/advisories/unreviewed/2022/04/GHSA-hvgg-hv8j-3qv8/GHSA-hvgg-hv8j-3qv8.json @@ -7,12 +7,8 @@ "CVE-2004-1635" ], "details": "Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, description, MIME type, or review flags, which allows remote authenticated users to obtain sensitive information when (1) viewing the bug activity log or (2) receiving bug change notification mails.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j37c-fr9j-g7mj/GHSA-j37c-fr9j-g7mj.json b/advisories/unreviewed/2022/04/GHSA-j37c-fr9j-g7mj/GHSA-j37c-fr9j-g7mj.json index 1dfc4101a3c..8e31c265aba 100644 --- a/advisories/unreviewed/2022/04/GHSA-j37c-fr9j-g7mj/GHSA-j37c-fr9j-g7mj.json +++ b/advisories/unreviewed/2022/04/GHSA-j37c-fr9j-g7mj/GHSA-j37c-fr9j-g7mj.json @@ -7,12 +7,8 @@ "CVE-2004-1657" ], "details": "Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j3mm-cmpj-cv2w/GHSA-j3mm-cmpj-cv2w.json b/advisories/unreviewed/2022/04/GHSA-j3mm-cmpj-cv2w/GHSA-j3mm-cmpj-cv2w.json index 0797e46b3b7..f3332616986 100644 --- a/advisories/unreviewed/2022/04/GHSA-j3mm-cmpj-cv2w/GHSA-j3mm-cmpj-cv2w.json +++ b/advisories/unreviewed/2022/04/GHSA-j3mm-cmpj-cv2w/GHSA-j3mm-cmpj-cv2w.json @@ -7,12 +7,8 @@ "CVE-2004-1701" ], "details": "Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j3vg-5xcr-9g3j/GHSA-j3vg-5xcr-9g3j.json b/advisories/unreviewed/2022/04/GHSA-j3vg-5xcr-9g3j/GHSA-j3vg-5xcr-9g3j.json index d5a2790fc5a..19241477bc2 100644 --- a/advisories/unreviewed/2022/04/GHSA-j3vg-5xcr-9g3j/GHSA-j3vg-5xcr-9g3j.json +++ b/advisories/unreviewed/2022/04/GHSA-j3vg-5xcr-9g3j/GHSA-j3vg-5xcr-9g3j.json @@ -7,12 +7,8 @@ "CVE-2004-1650" ], "details": "D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j55q-v3p6-qfvv/GHSA-j55q-v3p6-qfvv.json b/advisories/unreviewed/2022/04/GHSA-j55q-v3p6-qfvv/GHSA-j55q-v3p6-qfvv.json index 1a5720b9cab..7d0404926b6 100644 --- a/advisories/unreviewed/2022/04/GHSA-j55q-v3p6-qfvv/GHSA-j55q-v3p6-qfvv.json +++ b/advisories/unreviewed/2022/04/GHSA-j55q-v3p6-qfvv/GHSA-j55q-v3p6-qfvv.json @@ -7,12 +7,8 @@ "CVE-2004-1568" ], "details": "Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j85p-6g22-63v4/GHSA-j85p-6g22-63v4.json b/advisories/unreviewed/2022/04/GHSA-j85p-6g22-63v4/GHSA-j85p-6g22-63v4.json index d29e99a5240..b4591c5f34c 100644 --- a/advisories/unreviewed/2022/04/GHSA-j85p-6g22-63v4/GHSA-j85p-6g22-63v4.json +++ b/advisories/unreviewed/2022/04/GHSA-j85p-6g22-63v4/GHSA-j85p-6g22-63v4.json @@ -7,12 +7,8 @@ "CVE-2004-1604" ], "details": "cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j8fp-ff64-g7r6/GHSA-j8fp-ff64-g7r6.json b/advisories/unreviewed/2022/04/GHSA-j8fp-ff64-g7r6/GHSA-j8fp-ff64-g7r6.json index 71be0d4c680..4924ee6b083 100644 --- a/advisories/unreviewed/2022/04/GHSA-j8fp-ff64-g7r6/GHSA-j8fp-ff64-g7r6.json +++ b/advisories/unreviewed/2022/04/GHSA-j8fp-ff64-g7r6/GHSA-j8fp-ff64-g7r6.json @@ -7,12 +7,8 @@ "CVE-2004-1617" ], "details": "Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and (2) a large tag name in an element that is not terminated, as demonstrated by mangleme. NOTE: a followup suggests that the relevant trigger for this issue is the large COLS value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-jgqq-gwfm-cchw/GHSA-jgqq-gwfm-cchw.json b/advisories/unreviewed/2022/04/GHSA-jgqq-gwfm-cchw/GHSA-jgqq-gwfm-cchw.json index 4fbb83e7e53..7b76d0a9ea1 100644 --- a/advisories/unreviewed/2022/04/GHSA-jgqq-gwfm-cchw/GHSA-jgqq-gwfm-cchw.json +++ b/advisories/unreviewed/2022/04/GHSA-jgqq-gwfm-cchw/GHSA-jgqq-gwfm-cchw.json @@ -7,12 +7,8 @@ "CVE-2004-1561" ], "details": "Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jj5f-c84c-p5jc/GHSA-jj5f-c84c-p5jc.json b/advisories/unreviewed/2022/04/GHSA-jj5f-c84c-p5jc/GHSA-jj5f-c84c-p5jc.json index 84a6b5cc5f5..7fc3bdb919d 100644 --- a/advisories/unreviewed/2022/04/GHSA-jj5f-c84c-p5jc/GHSA-jj5f-c84c-p5jc.json +++ b/advisories/unreviewed/2022/04/GHSA-jj5f-c84c-p5jc/GHSA-jj5f-c84c-p5jc.json @@ -7,12 +7,8 @@ "CVE-2004-1735" ], "details": "Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jvxq-q97r-j8hm/GHSA-jvxq-q97r-j8hm.json b/advisories/unreviewed/2022/04/GHSA-jvxq-q97r-j8hm/GHSA-jvxq-q97r-j8hm.json index f7f6ba5ea1e..54b0a30c8a9 100644 --- a/advisories/unreviewed/2022/04/GHSA-jvxq-q97r-j8hm/GHSA-jvxq-q97r-j8hm.json +++ b/advisories/unreviewed/2022/04/GHSA-jvxq-q97r-j8hm/GHSA-jvxq-q97r-j8hm.json @@ -7,12 +7,8 @@ "CVE-2004-1739" ], "details": "Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jw79-gm26-2pgj/GHSA-jw79-gm26-2pgj.json b/advisories/unreviewed/2022/04/GHSA-jw79-gm26-2pgj/GHSA-jw79-gm26-2pgj.json index a3a27ffc862..febf97ba7b6 100644 --- a/advisories/unreviewed/2022/04/GHSA-jw79-gm26-2pgj/GHSA-jw79-gm26-2pgj.json +++ b/advisories/unreviewed/2022/04/GHSA-jw79-gm26-2pgj/GHSA-jw79-gm26-2pgj.json @@ -7,12 +7,8 @@ "CVE-2004-1592" ], "details": "PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a remote web server that contains a malicious funcs.php script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m2mc-vwqx-3chc/GHSA-m2mc-vwqx-3chc.json b/advisories/unreviewed/2022/04/GHSA-m2mc-vwqx-3chc/GHSA-m2mc-vwqx-3chc.json index 354824072bf..7da9a664181 100644 --- a/advisories/unreviewed/2022/04/GHSA-m2mc-vwqx-3chc/GHSA-m2mc-vwqx-3chc.json +++ b/advisories/unreviewed/2022/04/GHSA-m2mc-vwqx-3chc/GHSA-m2mc-vwqx-3chc.json @@ -7,12 +7,8 @@ "CVE-2004-1618" ], "details": "Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m3c3-46rf-v3c3/GHSA-m3c3-46rf-v3c3.json b/advisories/unreviewed/2022/04/GHSA-m3c3-46rf-v3c3/GHSA-m3c3-46rf-v3c3.json index 4b47e2a47d8..4d467610d29 100644 --- a/advisories/unreviewed/2022/04/GHSA-m3c3-46rf-v3c3/GHSA-m3c3-46rf-v3c3.json +++ b/advisories/unreviewed/2022/04/GHSA-m3c3-46rf-v3c3/GHSA-m3c3-46rf-v3c3.json @@ -7,12 +7,8 @@ "CVE-2004-1648" ], "details": "Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mq3p-hf2w-4fg4/GHSA-mq3p-hf2w-4fg4.json b/advisories/unreviewed/2022/04/GHSA-mq3p-hf2w-4fg4/GHSA-mq3p-hf2w-4fg4.json index 5f2190b2ba0..c02761e6d55 100644 --- a/advisories/unreviewed/2022/04/GHSA-mq3p-hf2w-4fg4/GHSA-mq3p-hf2w-4fg4.json +++ b/advisories/unreviewed/2022/04/GHSA-mq3p-hf2w-4fg4/GHSA-mq3p-hf2w-4fg4.json @@ -7,12 +7,8 @@ "CVE-2004-1744" ], "details": "Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p235-73wr-c3m7/GHSA-p235-73wr-c3m7.json b/advisories/unreviewed/2022/04/GHSA-p235-73wr-c3m7/GHSA-p235-73wr-c3m7.json index 3e3ea4d1fab..5e27a60c195 100644 --- a/advisories/unreviewed/2022/04/GHSA-p235-73wr-c3m7/GHSA-p235-73wr-c3m7.json +++ b/advisories/unreviewed/2022/04/GHSA-p235-73wr-c3m7/GHSA-p235-73wr-c3m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-p2qq-q635-wcgr/GHSA-p2qq-q635-wcgr.json b/advisories/unreviewed/2022/04/GHSA-p2qq-q635-wcgr/GHSA-p2qq-q635-wcgr.json index c46690ceb07..a2329f7dc05 100644 --- a/advisories/unreviewed/2022/04/GHSA-p2qq-q635-wcgr/GHSA-p2qq-q635-wcgr.json +++ b/advisories/unreviewed/2022/04/GHSA-p2qq-q635-wcgr/GHSA-p2qq-q635-wcgr.json @@ -7,12 +7,8 @@ "CVE-2004-1599" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p564-2rfx-wgpg/GHSA-p564-2rfx-wgpg.json b/advisories/unreviewed/2022/04/GHSA-p564-2rfx-wgpg/GHSA-p564-2rfx-wgpg.json index 6dce086e0fc..955f96d4039 100644 --- a/advisories/unreviewed/2022/04/GHSA-p564-2rfx-wgpg/GHSA-p564-2rfx-wgpg.json +++ b/advisories/unreviewed/2022/04/GHSA-p564-2rfx-wgpg/GHSA-p564-2rfx-wgpg.json @@ -7,12 +7,8 @@ "CVE-2004-1708" ], "details": "Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p98c-hcw6-4j4f/GHSA-p98c-hcw6-4j4f.json b/advisories/unreviewed/2022/04/GHSA-p98c-hcw6-4j4f/GHSA-p98c-hcw6-4j4f.json index 8fec755ba54..5118ea1a18d 100644 --- a/advisories/unreviewed/2022/04/GHSA-p98c-hcw6-4j4f/GHSA-p98c-hcw6-4j4f.json +++ b/advisories/unreviewed/2022/04/GHSA-p98c-hcw6-4j4f/GHSA-p98c-hcw6-4j4f.json @@ -7,12 +7,8 @@ "CVE-2004-1642" ], "details": "WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pfgr-89g7-q7q8/GHSA-pfgr-89g7-q7q8.json b/advisories/unreviewed/2022/04/GHSA-pfgr-89g7-q7q8/GHSA-pfgr-89g7-q7q8.json index edcf87fb222..80483221e03 100644 --- a/advisories/unreviewed/2022/04/GHSA-pfgr-89g7-q7q8/GHSA-pfgr-89g7-q7q8.json +++ b/advisories/unreviewed/2022/04/GHSA-pfgr-89g7-q7q8/GHSA-pfgr-89g7-q7q8.json @@ -7,12 +7,8 @@ "CVE-2004-1641" ], "details": "Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pfqm-c4ph-rv4v/GHSA-pfqm-c4ph-rv4v.json b/advisories/unreviewed/2022/04/GHSA-pfqm-c4ph-rv4v/GHSA-pfqm-c4ph-rv4v.json index 5b11e6c6f49..77ad496a1b5 100644 --- a/advisories/unreviewed/2022/04/GHSA-pfqm-c4ph-rv4v/GHSA-pfqm-c4ph-rv4v.json +++ b/advisories/unreviewed/2022/04/GHSA-pfqm-c4ph-rv4v/GHSA-pfqm-c4ph-rv4v.json @@ -7,12 +7,8 @@ "CVE-2004-1753" ], "details": "The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pgq6-85cf-x6w3/GHSA-pgq6-85cf-x6w3.json b/advisories/unreviewed/2022/04/GHSA-pgq6-85cf-x6w3/GHSA-pgq6-85cf-x6w3.json index 9a618209ced..38047ba110a 100644 --- a/advisories/unreviewed/2022/04/GHSA-pgq6-85cf-x6w3/GHSA-pgq6-85cf-x6w3.json +++ b/advisories/unreviewed/2022/04/GHSA-pgq6-85cf-x6w3/GHSA-pgq6-85cf-x6w3.json @@ -7,12 +7,8 @@ "CVE-2004-1670" ], "details": "Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ....// (doubled dot dot) in the folderold or folder parameters to folders.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pj48-hggv-4w8h/GHSA-pj48-hggv-4w8h.json b/advisories/unreviewed/2022/04/GHSA-pj48-hggv-4w8h/GHSA-pj48-hggv-4w8h.json index b01d98f766d..4e518c5f20e 100644 --- a/advisories/unreviewed/2022/04/GHSA-pj48-hggv-4w8h/GHSA-pj48-hggv-4w8h.json +++ b/advisories/unreviewed/2022/04/GHSA-pj48-hggv-4w8h/GHSA-pj48-hggv-4w8h.json @@ -7,12 +7,8 @@ "CVE-2004-1677" ], "details": "pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pmp3-x433-rm9r/GHSA-pmp3-x433-rm9r.json b/advisories/unreviewed/2022/04/GHSA-pmp3-x433-rm9r/GHSA-pmp3-x433-rm9r.json index 89053e5df3d..6a933caf38c 100644 --- a/advisories/unreviewed/2022/04/GHSA-pmp3-x433-rm9r/GHSA-pmp3-x433-rm9r.json +++ b/advisories/unreviewed/2022/04/GHSA-pmp3-x433-rm9r/GHSA-pmp3-x433-rm9r.json @@ -7,12 +7,8 @@ "CVE-2004-1591" ], "details": "The web interface for Micronet Wireless Broadband Router SP916BM running firmware before 1.9 08/04/2004 resets the password to the default password when the router is shut off, which could allow remote attackers to gain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pqwg-424h-mwmq/GHSA-pqwg-424h-mwmq.json b/advisories/unreviewed/2022/04/GHSA-pqwg-424h-mwmq/GHSA-pqwg-424h-mwmq.json index 9caa9f6e902..39662319d01 100644 --- a/advisories/unreviewed/2022/04/GHSA-pqwg-424h-mwmq/GHSA-pqwg-424h-mwmq.json +++ b/advisories/unreviewed/2022/04/GHSA-pqwg-424h-mwmq/GHSA-pqwg-424h-mwmq.json @@ -7,12 +7,8 @@ "CVE-2004-1613" ], "details": "Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pwcj-h5hm-9qvx/GHSA-pwcj-h5hm-9qvx.json b/advisories/unreviewed/2022/04/GHSA-pwcj-h5hm-9qvx/GHSA-pwcj-h5hm-9qvx.json index a6d96a8c0aa..3cb4f2b4319 100644 --- a/advisories/unreviewed/2022/04/GHSA-pwcj-h5hm-9qvx/GHSA-pwcj-h5hm-9qvx.json +++ b/advisories/unreviewed/2022/04/GHSA-pwcj-h5hm-9qvx/GHSA-pwcj-h5hm-9qvx.json @@ -7,12 +7,8 @@ "CVE-2004-1596" ], "details": "The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to app_sta.stm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pwcm-4994-52jq/GHSA-pwcm-4994-52jq.json b/advisories/unreviewed/2022/04/GHSA-pwcm-4994-52jq/GHSA-pwcm-4994-52jq.json index a641f769704..8f12a23db78 100644 --- a/advisories/unreviewed/2022/04/GHSA-pwcm-4994-52jq/GHSA-pwcm-4994-52jq.json +++ b/advisories/unreviewed/2022/04/GHSA-pwcm-4994-52jq/GHSA-pwcm-4994-52jq.json @@ -7,12 +7,8 @@ "CVE-2004-1721" ], "details": "The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q3ph-w9hq-wf9p/GHSA-q3ph-w9hq-wf9p.json b/advisories/unreviewed/2022/04/GHSA-q3ph-w9hq-wf9p/GHSA-q3ph-w9hq-wf9p.json index 59f956bbc01..859648fa47c 100644 --- a/advisories/unreviewed/2022/04/GHSA-q3ph-w9hq-wf9p/GHSA-q3ph-w9hq-wf9p.json +++ b/advisories/unreviewed/2022/04/GHSA-q3ph-w9hq-wf9p/GHSA-q3ph-w9hq-wf9p.json @@ -7,12 +7,8 @@ "CVE-2004-1733" ], "details": "Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q4j5-jpvw-4ww8/GHSA-q4j5-jpvw-4ww8.json b/advisories/unreviewed/2022/04/GHSA-q4j5-jpvw-4ww8/GHSA-q4j5-jpvw-4ww8.json index 9d856cb4838..373421ca1fb 100644 --- a/advisories/unreviewed/2022/04/GHSA-q4j5-jpvw-4ww8/GHSA-q4j5-jpvw-4ww8.json +++ b/advisories/unreviewed/2022/04/GHSA-q4j5-jpvw-4ww8/GHSA-q4j5-jpvw-4ww8.json @@ -7,12 +7,8 @@ "CVE-2004-1727" ], "details": "BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q78g-73j3-mh33/GHSA-q78g-73j3-mh33.json b/advisories/unreviewed/2022/04/GHSA-q78g-73j3-mh33/GHSA-q78g-73j3-mh33.json index 12b061fdfed..f6f03b15a25 100644 --- a/advisories/unreviewed/2022/04/GHSA-q78g-73j3-mh33/GHSA-q78g-73j3-mh33.json +++ b/advisories/unreviewed/2022/04/GHSA-q78g-73j3-mh33/GHSA-q78g-73j3-mh33.json @@ -7,12 +7,8 @@ "CVE-2004-1645" ], "details": "Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q9x4-57vc-x2vp/GHSA-q9x4-57vc-x2vp.json b/advisories/unreviewed/2022/04/GHSA-q9x4-57vc-x2vp/GHSA-q9x4-57vc-x2vp.json index 8d49289745c..64cd60dfede 100644 --- a/advisories/unreviewed/2022/04/GHSA-q9x4-57vc-x2vp/GHSA-q9x4-57vc-x2vp.json +++ b/advisories/unreviewed/2022/04/GHSA-q9x4-57vc-x2vp/GHSA-q9x4-57vc-x2vp.json @@ -7,12 +7,8 @@ "CVE-2004-1659" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qfqh-96cv-x4mp/GHSA-qfqh-96cv-x4mp.json b/advisories/unreviewed/2022/04/GHSA-qfqh-96cv-x4mp/GHSA-qfqh-96cv-x4mp.json index cccc2704ebc..dfbe7a83ba5 100644 --- a/advisories/unreviewed/2022/04/GHSA-qfqh-96cv-x4mp/GHSA-qfqh-96cv-x4mp.json +++ b/advisories/unreviewed/2022/04/GHSA-qfqh-96cv-x4mp/GHSA-qfqh-96cv-x4mp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qjfh-cqv7-7vp4/GHSA-qjfh-cqv7-7vp4.json b/advisories/unreviewed/2022/04/GHSA-qjfh-cqv7-7vp4/GHSA-qjfh-cqv7-7vp4.json index fdc39e66c0d..29cdccaad9c 100644 --- a/advisories/unreviewed/2022/04/GHSA-qjfh-cqv7-7vp4/GHSA-qjfh-cqv7-7vp4.json +++ b/advisories/unreviewed/2022/04/GHSA-qjfh-cqv7-7vp4/GHSA-qjfh-cqv7-7vp4.json @@ -7,12 +7,8 @@ "CVE-2004-1585" ], "details": "Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qq6r-xf5p-xmg4/GHSA-qq6r-xf5p-xmg4.json b/advisories/unreviewed/2022/04/GHSA-qq6r-xf5p-xmg4/GHSA-qq6r-xf5p-xmg4.json index b1c2f13dd0f..debea36c228 100644 --- a/advisories/unreviewed/2022/04/GHSA-qq6r-xf5p-xmg4/GHSA-qq6r-xf5p-xmg4.json +++ b/advisories/unreviewed/2022/04/GHSA-qq6r-xf5p-xmg4/GHSA-qq6r-xf5p-xmg4.json @@ -7,12 +7,8 @@ "CVE-2004-1726" ], "details": "Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qqw5-9xgq-fw5j/GHSA-qqw5-9xgq-fw5j.json b/advisories/unreviewed/2022/04/GHSA-qqw5-9xgq-fw5j/GHSA-qqw5-9xgq-fw5j.json index 52c14a5719f..7d10deb5dec 100644 --- a/advisories/unreviewed/2022/04/GHSA-qqw5-9xgq-fw5j/GHSA-qqw5-9xgq-fw5j.json +++ b/advisories/unreviewed/2022/04/GHSA-qqw5-9xgq-fw5j/GHSA-qqw5-9xgq-fw5j.json @@ -7,12 +7,8 @@ "CVE-2004-1732" ], "details": "SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qrjq-m326-9xph/GHSA-qrjq-m326-9xph.json b/advisories/unreviewed/2022/04/GHSA-qrjq-m326-9xph/GHSA-qrjq-m326-9xph.json index e51724f2aca..6bb490838fd 100644 --- a/advisories/unreviewed/2022/04/GHSA-qrjq-m326-9xph/GHSA-qrjq-m326-9xph.json +++ b/advisories/unreviewed/2022/04/GHSA-qrjq-m326-9xph/GHSA-qrjq-m326-9xph.json @@ -7,12 +7,8 @@ "CVE-2004-1634" ], "details": "show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qxc5-37gj-mcj7/GHSA-qxc5-37gj-mcj7.json b/advisories/unreviewed/2022/04/GHSA-qxc5-37gj-mcj7/GHSA-qxc5-37gj-mcj7.json index 5d5d64fd0df..7b65be22bb9 100644 --- a/advisories/unreviewed/2022/04/GHSA-qxc5-37gj-mcj7/GHSA-qxc5-37gj-mcj7.json +++ b/advisories/unreviewed/2022/04/GHSA-qxc5-37gj-mcj7/GHSA-qxc5-37gj-mcj7.json @@ -7,12 +7,8 @@ "CVE-2004-1651" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r52p-h476-w962/GHSA-r52p-h476-w962.json b/advisories/unreviewed/2022/04/GHSA-r52p-h476-w962/GHSA-r52p-h476-w962.json index 4788b465bd8..9ec2d6d1834 100644 --- a/advisories/unreviewed/2022/04/GHSA-r52p-h476-w962/GHSA-r52p-h476-w962.json +++ b/advisories/unreviewed/2022/04/GHSA-r52p-h476-w962/GHSA-r52p-h476-w962.json @@ -7,12 +7,8 @@ "CVE-2004-1653" ], "details": "The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r5cc-6x6f-2359/GHSA-r5cc-6x6f-2359.json b/advisories/unreviewed/2022/04/GHSA-r5cc-6x6f-2359/GHSA-r5cc-6x6f-2359.json index b98290fdcb5..c2c05bd0187 100644 --- a/advisories/unreviewed/2022/04/GHSA-r5cc-6x6f-2359/GHSA-r5cc-6x6f-2359.json +++ b/advisories/unreviewed/2022/04/GHSA-r5cc-6x6f-2359/GHSA-r5cc-6x6f-2359.json @@ -7,12 +7,8 @@ "CVE-2004-1740" ], "details": "Music daemon (musicd) 0.0.3 and earlier allows remote attackers to read arbitrary files by calling LOAD with a full pathname, then calling SHOWLIST.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r5fv-qp85-97wv/GHSA-r5fv-qp85-97wv.json b/advisories/unreviewed/2022/04/GHSA-r5fv-qp85-97wv/GHSA-r5fv-qp85-97wv.json index 4a5dcf9ff9b..6506e38508b 100644 --- a/advisories/unreviewed/2022/04/GHSA-r5fv-qp85-97wv/GHSA-r5fv-qp85-97wv.json +++ b/advisories/unreviewed/2022/04/GHSA-r5fv-qp85-97wv/GHSA-r5fv-qp85-97wv.json @@ -7,12 +7,8 @@ "CVE-2004-1728" ], "details": "Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the client with a long string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r6p3-vmjf-9hgh/GHSA-r6p3-vmjf-9hgh.json b/advisories/unreviewed/2022/04/GHSA-r6p3-vmjf-9hgh/GHSA-r6p3-vmjf-9hgh.json index 587940ae169..7e8f38c0daf 100644 --- a/advisories/unreviewed/2022/04/GHSA-r6p3-vmjf-9hgh/GHSA-r6p3-vmjf-9hgh.json +++ b/advisories/unreviewed/2022/04/GHSA-r6p3-vmjf-9hgh/GHSA-r6p3-vmjf-9hgh.json @@ -7,12 +7,8 @@ "CVE-2004-1712" ], "details": "Cross-site scripting (XSS) vulnerability in TypePad allows remote attackers to inject arbitrary Javascript via the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r75w-3v4r-7qm9/GHSA-r75w-3v4r-7qm9.json b/advisories/unreviewed/2022/04/GHSA-r75w-3v4r-7qm9/GHSA-r75w-3v4r-7qm9.json index 6321a0d75ae..65ae21d72c4 100644 --- a/advisories/unreviewed/2022/04/GHSA-r75w-3v4r-7qm9/GHSA-r75w-3v4r-7qm9.json +++ b/advisories/unreviewed/2022/04/GHSA-r75w-3v4r-7qm9/GHSA-r75w-3v4r-7qm9.json @@ -7,12 +7,8 @@ "CVE-2004-1690" ], "details": "Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rc47-jfx2-55pr/GHSA-rc47-jfx2-55pr.json b/advisories/unreviewed/2022/04/GHSA-rc47-jfx2-55pr/GHSA-rc47-jfx2-55pr.json index a659479b0a7..5b982f8c1ca 100644 --- a/advisories/unreviewed/2022/04/GHSA-rc47-jfx2-55pr/GHSA-rc47-jfx2-55pr.json +++ b/advisories/unreviewed/2022/04/GHSA-rc47-jfx2-55pr/GHSA-rc47-jfx2-55pr.json @@ -7,12 +7,8 @@ "CVE-2004-1686" ], "details": "Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrated using the DesignScience MathPlayer ActiveX plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rm65-jp7g-4mvw/GHSA-rm65-jp7g-4mvw.json b/advisories/unreviewed/2022/04/GHSA-rm65-jp7g-4mvw/GHSA-rm65-jp7g-4mvw.json index 2c6ceb1c465..cd44873b3ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-rm65-jp7g-4mvw/GHSA-rm65-jp7g-4mvw.json +++ b/advisories/unreviewed/2022/04/GHSA-rm65-jp7g-4mvw/GHSA-rm65-jp7g-4mvw.json @@ -7,12 +7,8 @@ "CVE-2004-1674" ], "details": "viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary files via the originalfolder parameter or (2) move arbitrary files via the messageid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rmgf-3gj9-gmrr/GHSA-rmgf-3gj9-gmrr.json b/advisories/unreviewed/2022/04/GHSA-rmgf-3gj9-gmrr/GHSA-rmgf-3gj9-gmrr.json index b13fde0acb5..b4a06cd4414 100644 --- a/advisories/unreviewed/2022/04/GHSA-rmgf-3gj9-gmrr/GHSA-rmgf-3gj9-gmrr.json +++ b/advisories/unreviewed/2022/04/GHSA-rmgf-3gj9-gmrr/GHSA-rmgf-3gj9-gmrr.json @@ -7,12 +7,8 @@ "CVE-2004-1549" ], "details": "The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rq54-jrj8-62cm/GHSA-rq54-jrj8-62cm.json b/advisories/unreviewed/2022/04/GHSA-rq54-jrj8-62cm/GHSA-rq54-jrj8-62cm.json index fbeed6137b3..86b4d1ec14f 100644 --- a/advisories/unreviewed/2022/04/GHSA-rq54-jrj8-62cm/GHSA-rq54-jrj8-62cm.json +++ b/advisories/unreviewed/2022/04/GHSA-rq54-jrj8-62cm/GHSA-rq54-jrj8-62cm.json @@ -7,12 +7,8 @@ "CVE-2004-1754" ], "details": "The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query response that contains authoritative or additional records.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rwcj-93v2-99j2/GHSA-rwcj-93v2-99j2.json b/advisories/unreviewed/2022/04/GHSA-rwcj-93v2-99j2/GHSA-rwcj-93v2-99j2.json index 9a9aa582fbf..c56847d9810 100644 --- a/advisories/unreviewed/2022/04/GHSA-rwcj-93v2-99j2/GHSA-rwcj-93v2-99j2.json +++ b/advisories/unreviewed/2022/04/GHSA-rwcj-93v2-99j2/GHSA-rwcj-93v2-99j2.json @@ -7,12 +7,8 @@ "CVE-2004-1682" ], "details": "Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rwq7-fqhw-gq6p/GHSA-rwq7-fqhw-gq6p.json b/advisories/unreviewed/2022/04/GHSA-rwq7-fqhw-gq6p/GHSA-rwq7-fqhw-gq6p.json index b0c34b1c2af..47eadae4b7d 100644 --- a/advisories/unreviewed/2022/04/GHSA-rwq7-fqhw-gq6p/GHSA-rwq7-fqhw-gq6p.json +++ b/advisories/unreviewed/2022/04/GHSA-rwq7-fqhw-gq6p/GHSA-rwq7-fqhw-gq6p.json @@ -7,12 +7,8 @@ "CVE-2004-1723" ], "details": "The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rx47-h3h8-2fqr/GHSA-rx47-h3h8-2fqr.json b/advisories/unreviewed/2022/04/GHSA-rx47-h3h8-2fqr/GHSA-rx47-h3h8-2fqr.json index 5c0cc86aef6..ec41745f4c8 100644 --- a/advisories/unreviewed/2022/04/GHSA-rx47-h3h8-2fqr/GHSA-rx47-h3h8-2fqr.json +++ b/advisories/unreviewed/2022/04/GHSA-rx47-h3h8-2fqr/GHSA-rx47-h3h8-2fqr.json @@ -7,12 +7,8 @@ "CVE-2004-1582" ], "details": "PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called \"libpach\") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v2px-5cf8-vr46/GHSA-v2px-5cf8-vr46.json b/advisories/unreviewed/2022/04/GHSA-v2px-5cf8-vr46/GHSA-v2px-5cf8-vr46.json index 0e6f24af528..bdb839d3eb3 100644 --- a/advisories/unreviewed/2022/04/GHSA-v2px-5cf8-vr46/GHSA-v2px-5cf8-vr46.json +++ b/advisories/unreviewed/2022/04/GHSA-v2px-5cf8-vr46/GHSA-v2px-5cf8-vr46.json @@ -7,12 +7,8 @@ "CVE-2004-1630" ], "details": "Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v3h5-fhg8-jp65/GHSA-v3h5-fhg8-jp65.json b/advisories/unreviewed/2022/04/GHSA-v3h5-fhg8-jp65/GHSA-v3h5-fhg8-jp65.json index f1b95b57dab..11220208ca6 100644 --- a/advisories/unreviewed/2022/04/GHSA-v3h5-fhg8-jp65/GHSA-v3h5-fhg8-jp65.json +++ b/advisories/unreviewed/2022/04/GHSA-v3h5-fhg8-jp65/GHSA-v3h5-fhg8-jp65.json @@ -7,12 +7,8 @@ "CVE-2004-1737" ], "details": "SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v3jq-qw95-xr88/GHSA-v3jq-qw95-xr88.json b/advisories/unreviewed/2022/04/GHSA-v3jq-qw95-xr88/GHSA-v3jq-qw95-xr88.json index 567ce30783f..95973fe6e90 100644 --- a/advisories/unreviewed/2022/04/GHSA-v3jq-qw95-xr88/GHSA-v3jq-qw95-xr88.json +++ b/advisories/unreviewed/2022/04/GHSA-v3jq-qw95-xr88/GHSA-v3jq-qw95-xr88.json @@ -7,12 +7,8 @@ "CVE-2004-1575" ], "details": "The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v5h8-96h5-6hm4/GHSA-v5h8-96h5-6hm4.json b/advisories/unreviewed/2022/04/GHSA-v5h8-96h5-6hm4/GHSA-v5h8-96h5-6hm4.json index 109b4c34533..0347d77ddd1 100644 --- a/advisories/unreviewed/2022/04/GHSA-v5h8-96h5-6hm4/GHSA-v5h8-96h5-6hm4.json +++ b/advisories/unreviewed/2022/04/GHSA-v5h8-96h5-6hm4/GHSA-v5h8-96h5-6hm4.json @@ -7,12 +7,8 @@ "CVE-2004-1699" ], "details": "SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v6wh-fw29-g4mg/GHSA-v6wh-fw29-g4mg.json b/advisories/unreviewed/2022/04/GHSA-v6wh-fw29-g4mg/GHSA-v6wh-fw29-g4mg.json index 2bb41f18f31..e2a66b0757a 100644 --- a/advisories/unreviewed/2022/04/GHSA-v6wh-fw29-g4mg/GHSA-v6wh-fw29-g4mg.json +++ b/advisories/unreviewed/2022/04/GHSA-v6wh-fw29-g4mg/GHSA-v6wh-fw29-g4mg.json @@ -7,12 +7,8 @@ "CVE-2004-1654" ], "details": "SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v97r-xxvr-6fc5/GHSA-v97r-xxvr-6fc5.json b/advisories/unreviewed/2022/04/GHSA-v97r-xxvr-6fc5/GHSA-v97r-xxvr-6fc5.json index 758338c9fd7..09e06a3e27a 100644 --- a/advisories/unreviewed/2022/04/GHSA-v97r-xxvr-6fc5/GHSA-v97r-xxvr-6fc5.json +++ b/advisories/unreviewed/2022/04/GHSA-v97r-xxvr-6fc5/GHSA-v97r-xxvr-6fc5.json @@ -7,12 +7,8 @@ "CVE-2004-1615" ], "details": "Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web page or HTML email that contains a TBODY tag with a large COL SPAN value, as demonstrated by mangleme.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v9mf-r73m-jrrh/GHSA-v9mf-r73m-jrrh.json b/advisories/unreviewed/2022/04/GHSA-v9mf-r73m-jrrh/GHSA-v9mf-r73m-jrrh.json index c0c30e34f20..b19f9dbfcaa 100644 --- a/advisories/unreviewed/2022/04/GHSA-v9mf-r73m-jrrh/GHSA-v9mf-r73m-jrrh.json +++ b/advisories/unreviewed/2022/04/GHSA-v9mf-r73m-jrrh/GHSA-v9mf-r73m-jrrh.json @@ -7,12 +7,8 @@ "CVE-2004-1600" ], "details": "index.php in CoolPHP 1.0-stable allows remote attackers to gain sensitive information via an invalid op parameter, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v9vp-j7qm-2rcj/GHSA-v9vp-j7qm-2rcj.json b/advisories/unreviewed/2022/04/GHSA-v9vp-j7qm-2rcj/GHSA-v9vp-j7qm-2rcj.json index c03ee918a43..e90db4f38d0 100644 --- a/advisories/unreviewed/2022/04/GHSA-v9vp-j7qm-2rcj/GHSA-v9vp-j7qm-2rcj.json +++ b/advisories/unreviewed/2022/04/GHSA-v9vp-j7qm-2rcj/GHSA-v9vp-j7qm-2rcj.json @@ -7,12 +7,8 @@ "CVE-2004-1696" ], "details": "EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vfwv-p32r-49c7/GHSA-vfwv-p32r-49c7.json b/advisories/unreviewed/2022/04/GHSA-vfwv-p32r-49c7/GHSA-vfwv-p32r-49c7.json index 3d22654de0a..57d56a4230e 100644 --- a/advisories/unreviewed/2022/04/GHSA-vfwv-p32r-49c7/GHSA-vfwv-p32r-49c7.json +++ b/advisories/unreviewed/2022/04/GHSA-vfwv-p32r-49c7/GHSA-vfwv-p32r-49c7.json @@ -7,12 +7,8 @@ "CVE-2004-1558" ], "details": "Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USER command or (2) SMTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vgc7-vcfh-c73q/GHSA-vgc7-vcfh-c73q.json b/advisories/unreviewed/2022/04/GHSA-vgc7-vcfh-c73q/GHSA-vgc7-vcfh-c73q.json index 421d57bbce5..2d9bdb5a164 100644 --- a/advisories/unreviewed/2022/04/GHSA-vgc7-vcfh-c73q/GHSA-vgc7-vcfh-c73q.json +++ b/advisories/unreviewed/2022/04/GHSA-vgc7-vcfh-c73q/GHSA-vgc7-vcfh-c73q.json @@ -7,12 +7,8 @@ "CVE-2004-1756" ], "details": "BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vmwj-5crv-3q5f/GHSA-vmwj-5crv-3q5f.json b/advisories/unreviewed/2022/04/GHSA-vmwj-5crv-3q5f/GHSA-vmwj-5crv-3q5f.json index 3617af4a433..2d167602330 100644 --- a/advisories/unreviewed/2022/04/GHSA-vmwj-5crv-3q5f/GHSA-vmwj-5crv-3q5f.json +++ b/advisories/unreviewed/2022/04/GHSA-vmwj-5crv-3q5f/GHSA-vmwj-5crv-3q5f.json @@ -7,12 +7,8 @@ "CVE-2004-1746" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via the (1) cat_select or (2) show parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vq5p-68xq-c2fv/GHSA-vq5p-68xq-c2fv.json b/advisories/unreviewed/2022/04/GHSA-vq5p-68xq-c2fv/GHSA-vq5p-68xq-c2fv.json index 426de29c99b..364869f1d90 100644 --- a/advisories/unreviewed/2022/04/GHSA-vq5p-68xq-c2fv/GHSA-vq5p-68xq-c2fv.json +++ b/advisories/unreviewed/2022/04/GHSA-vq5p-68xq-c2fv/GHSA-vq5p-68xq-c2fv.json @@ -7,12 +7,8 @@ "CVE-2004-1609" ], "details": "SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vwp5-j5cp-r3jp/GHSA-vwp5-j5cp-r3jp.json b/advisories/unreviewed/2022/04/GHSA-vwp5-j5cp-r3jp/GHSA-vwp5-j5cp-r3jp.json index 892587f3f2a..1fd41598387 100644 --- a/advisories/unreviewed/2022/04/GHSA-vwp5-j5cp-r3jp/GHSA-vwp5-j5cp-r3jp.json +++ b/advisories/unreviewed/2022/04/GHSA-vwp5-j5cp-r3jp/GHSA-vwp5-j5cp-r3jp.json @@ -7,12 +7,8 @@ "CVE-2004-1646" ], "details": "Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vx22-3cf4-63m3/GHSA-vx22-3cf4-63m3.json b/advisories/unreviewed/2022/04/GHSA-vx22-3cf4-63m3/GHSA-vx22-3cf4-63m3.json index 8b7e597f1a1..bf75e0ce571 100644 --- a/advisories/unreviewed/2022/04/GHSA-vx22-3cf4-63m3/GHSA-vx22-3cf4-63m3.json +++ b/advisories/unreviewed/2022/04/GHSA-vx22-3cf4-63m3/GHSA-vx22-3cf4-63m3.json @@ -7,12 +7,8 @@ "CVE-2004-1724" ], "details": "The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w42r-hrg2-j8mr/GHSA-w42r-hrg2-j8mr.json b/advisories/unreviewed/2022/04/GHSA-w42r-hrg2-j8mr/GHSA-w42r-hrg2-j8mr.json index f49c6fc58e1..074fe068289 100644 --- a/advisories/unreviewed/2022/04/GHSA-w42r-hrg2-j8mr/GHSA-w42r-hrg2-j8mr.json +++ b/advisories/unreviewed/2022/04/GHSA-w42r-hrg2-j8mr/GHSA-w42r-hrg2-j8mr.json @@ -7,12 +7,8 @@ "CVE-2004-1559" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w546-2ph3-cg79/GHSA-w546-2ph3-cg79.json b/advisories/unreviewed/2022/04/GHSA-w546-2ph3-cg79/GHSA-w546-2ph3-cg79.json index fa98c4306b2..23b9fd1aa8a 100644 --- a/advisories/unreviewed/2022/04/GHSA-w546-2ph3-cg79/GHSA-w546-2ph3-cg79.json +++ b/advisories/unreviewed/2022/04/GHSA-w546-2ph3-cg79/GHSA-w546-2ph3-cg79.json @@ -7,12 +7,8 @@ "CVE-2004-1593" ], "details": "Cross-site scripting (XSS) vulnerability in render.UserLayoutRootNode.uP in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via the utf parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w8wv-4gwp-hvv3/GHSA-w8wv-4gwp-hvv3.json b/advisories/unreviewed/2022/04/GHSA-w8wv-4gwp-hvv3/GHSA-w8wv-4gwp-hvv3.json index 90ef01ab76f..f82c97cfef7 100644 --- a/advisories/unreviewed/2022/04/GHSA-w8wv-4gwp-hvv3/GHSA-w8wv-4gwp-hvv3.json +++ b/advisories/unreviewed/2022/04/GHSA-w8wv-4gwp-hvv3/GHSA-w8wv-4gwp-hvv3.json @@ -7,12 +7,8 @@ "CVE-2004-1644" ], "details": "Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wcwp-7mcr-w7wx/GHSA-wcwp-7mcr-w7wx.json b/advisories/unreviewed/2022/04/GHSA-wcwp-7mcr-w7wx/GHSA-wcwp-7mcr-w7wx.json index 7ad8dd68bb3..558857745de 100644 --- a/advisories/unreviewed/2022/04/GHSA-wcwp-7mcr-w7wx/GHSA-wcwp-7mcr-w7wx.json +++ b/advisories/unreviewed/2022/04/GHSA-wcwp-7mcr-w7wx/GHSA-wcwp-7mcr-w7wx.json @@ -7,12 +7,8 @@ "CVE-2004-1675" ], "details": "Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wj9g-86pf-x73r/GHSA-wj9g-86pf-x73r.json b/advisories/unreviewed/2022/04/GHSA-wj9g-86pf-x73r/GHSA-wj9g-86pf-x73r.json index 9cd26ec0700..a9bcf79f2e8 100644 --- a/advisories/unreviewed/2022/04/GHSA-wj9g-86pf-x73r/GHSA-wj9g-86pf-x73r.json +++ b/advisories/unreviewed/2022/04/GHSA-wj9g-86pf-x73r/GHSA-wj9g-86pf-x73r.json @@ -7,12 +7,8 @@ "CVE-2004-1668" ], "details": "Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wjpj-j5w8-2m2p/GHSA-wjpj-j5w8-2m2p.json b/advisories/unreviewed/2022/04/GHSA-wjpj-j5w8-2m2p/GHSA-wjpj-j5w8-2m2p.json index 591bbce6bd6..e72cabb520c 100644 --- a/advisories/unreviewed/2022/04/GHSA-wjpj-j5w8-2m2p/GHSA-wjpj-j5w8-2m2p.json +++ b/advisories/unreviewed/2022/04/GHSA-wjpj-j5w8-2m2p/GHSA-wjpj-j5w8-2m2p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wq5g-65xw-2w6q/GHSA-wq5g-65xw-2w6q.json b/advisories/unreviewed/2022/04/GHSA-wq5g-65xw-2w6q/GHSA-wq5g-65xw-2w6q.json index f2af21a95ed..f3e7723b5fa 100644 --- a/advisories/unreviewed/2022/04/GHSA-wq5g-65xw-2w6q/GHSA-wq5g-65xw-2w6q.json +++ b/advisories/unreviewed/2022/04/GHSA-wq5g-65xw-2w6q/GHSA-wq5g-65xw-2w6q.json @@ -7,12 +7,8 @@ "CVE-2004-1590" ], "details": "Clientexec allows remote attackers to gain sensitive information via an HTTP request to phpinfo.php, which calls the phpinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wqf3-h5g7-w9q8/GHSA-wqf3-h5g7-w9q8.json b/advisories/unreviewed/2022/04/GHSA-wqf3-h5g7-w9q8/GHSA-wqf3-h5g7-w9q8.json index 4bbdc0add7e..c3e6a7d9a17 100644 --- a/advisories/unreviewed/2022/04/GHSA-wqf3-h5g7-w9q8/GHSA-wqf3-h5g7-w9q8.json +++ b/advisories/unreviewed/2022/04/GHSA-wqf3-h5g7-w9q8/GHSA-wqf3-h5g7-w9q8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wvh4-6wwm-47c4/GHSA-wvh4-6wwm-47c4.json b/advisories/unreviewed/2022/04/GHSA-wvh4-6wwm-47c4/GHSA-wvh4-6wwm-47c4.json index 9a275a8d4b6..872e081d5b7 100644 --- a/advisories/unreviewed/2022/04/GHSA-wvh4-6wwm-47c4/GHSA-wvh4-6wwm-47c4.json +++ b/advisories/unreviewed/2022/04/GHSA-wvh4-6wwm-47c4/GHSA-wvh4-6wwm-47c4.json @@ -7,12 +7,8 @@ "CVE-2004-1611" ], "details": "SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port 1707.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wx5p-jq7w-xjqv/GHSA-wx5p-jq7w-xjqv.json b/advisories/unreviewed/2022/04/GHSA-wx5p-jq7w-xjqv/GHSA-wx5p-jq7w-xjqv.json index 74723bcf18d..41d4c6783a8 100644 --- a/advisories/unreviewed/2022/04/GHSA-wx5p-jq7w-xjqv/GHSA-wx5p-jq7w-xjqv.json +++ b/advisories/unreviewed/2022/04/GHSA-wx5p-jq7w-xjqv/GHSA-wx5p-jq7w-xjqv.json @@ -7,12 +7,8 @@ "CVE-2004-1570" ], "details": "SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x4gh-vmc2-6j3g/GHSA-x4gh-vmc2-6j3g.json b/advisories/unreviewed/2022/04/GHSA-x4gh-vmc2-6j3g/GHSA-x4gh-vmc2-6j3g.json index 9a2f132376e..8e7030221ad 100644 --- a/advisories/unreviewed/2022/04/GHSA-x4gh-vmc2-6j3g/GHSA-x4gh-vmc2-6j3g.json +++ b/advisories/unreviewed/2022/04/GHSA-x4gh-vmc2-6j3g/GHSA-x4gh-vmc2-6j3g.json @@ -7,12 +7,8 @@ "CVE-2004-1747" ], "details": "Cross-site scripting (XSS) vulnerability in NetworkEverywhere NR041 running firmware 1.2 Release 03 allows remote attackers to inject arbitrary web script or HTML via the DHCP HOSTNAME option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x664-g64f-4m6f/GHSA-x664-g64f-4m6f.json b/advisories/unreviewed/2022/04/GHSA-x664-g64f-4m6f/GHSA-x664-g64f-4m6f.json index da09620c361..35420705e6e 100644 --- a/advisories/unreviewed/2022/04/GHSA-x664-g64f-4m6f/GHSA-x664-g64f-4m6f.json +++ b/advisories/unreviewed/2022/04/GHSA-x664-g64f-4m6f/GHSA-x664-g64f-4m6f.json @@ -7,12 +7,8 @@ "CVE-2004-1741" ], "details": "Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument, then calling SHOWLIST.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x6cc-4gc4-jf7f/GHSA-x6cc-4gc4-jf7f.json b/advisories/unreviewed/2022/04/GHSA-x6cc-4gc4-jf7f/GHSA-x6cc-4gc4-jf7f.json index bebfdd163c5..b07566e6811 100644 --- a/advisories/unreviewed/2022/04/GHSA-x6cc-4gc4-jf7f/GHSA-x6cc-4gc4-jf7f.json +++ b/advisories/unreviewed/2022/04/GHSA-x6cc-4gc4-jf7f/GHSA-x6cc-4gc4-jf7f.json @@ -7,12 +7,8 @@ "CVE-2004-1640" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x9xv-j4wv-rqf5/GHSA-x9xv-j4wv-rqf5.json b/advisories/unreviewed/2022/04/GHSA-x9xv-j4wv-rqf5/GHSA-x9xv-j4wv-rqf5.json index ef4034c1c67..e02eb1d78e0 100644 --- a/advisories/unreviewed/2022/04/GHSA-x9xv-j4wv-rqf5/GHSA-x9xv-j4wv-rqf5.json +++ b/advisories/unreviewed/2022/04/GHSA-x9xv-j4wv-rqf5/GHSA-x9xv-j4wv-rqf5.json @@ -7,12 +7,8 @@ "CVE-2004-1637" ], "details": "The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xcc8-gv7j-57r8/GHSA-xcc8-gv7j-57r8.json b/advisories/unreviewed/2022/04/GHSA-xcc8-gv7j-57r8/GHSA-xcc8-gv7j-57r8.json index e91d9b5c62b..dd2d36bb93b 100644 --- a/advisories/unreviewed/2022/04/GHSA-xcc8-gv7j-57r8/GHSA-xcc8-gv7j-57r8.json +++ b/advisories/unreviewed/2022/04/GHSA-xcc8-gv7j-57r8/GHSA-xcc8-gv7j-57r8.json @@ -7,12 +7,8 @@ "CVE-2004-1594" ], "details": "Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xf2g-7fqj-9q58/GHSA-xf2g-7fqj-9q58.json b/advisories/unreviewed/2022/04/GHSA-xf2g-7fqj-9q58/GHSA-xf2g-7fqj-9q58.json index e17023ae68d..ef6a2b6f1bf 100644 --- a/advisories/unreviewed/2022/04/GHSA-xf2g-7fqj-9q58/GHSA-xf2g-7fqj-9q58.json +++ b/advisories/unreviewed/2022/04/GHSA-xf2g-7fqj-9q58/GHSA-xf2g-7fqj-9q58.json @@ -7,12 +7,8 @@ "CVE-2004-1562" ], "details": "SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xm72-c99x-fm79/GHSA-xm72-c99x-fm79.json b/advisories/unreviewed/2022/04/GHSA-xm72-c99x-fm79/GHSA-xm72-c99x-fm79.json index 4c2130814e0..7e577de6767 100644 --- a/advisories/unreviewed/2022/04/GHSA-xm72-c99x-fm79/GHSA-xm72-c99x-fm79.json +++ b/advisories/unreviewed/2022/04/GHSA-xm72-c99x-fm79/GHSA-xm72-c99x-fm79.json @@ -7,12 +7,8 @@ "CVE-2004-1573" ], "details": "The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xp9f-5q2c-rrp4/GHSA-xp9f-5q2c-rrp4.json b/advisories/unreviewed/2022/04/GHSA-xp9f-5q2c-rrp4/GHSA-xp9f-5q2c-rrp4.json index 4e8077a3223..422ebca3344 100644 --- a/advisories/unreviewed/2022/04/GHSA-xp9f-5q2c-rrp4/GHSA-xp9f-5q2c-rrp4.json +++ b/advisories/unreviewed/2022/04/GHSA-xp9f-5q2c-rrp4/GHSA-xp9f-5q2c-rrp4.json @@ -7,12 +7,8 @@ "CVE-2004-1661" ], "details": "MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains \"auth=1\" and \"uId=1.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xrcm-f723-98ww/GHSA-xrcm-f723-98ww.json b/advisories/unreviewed/2022/04/GHSA-xrcm-f723-98ww/GHSA-xrcm-f723-98ww.json index f15dbdfc115..014364ce660 100644 --- a/advisories/unreviewed/2022/04/GHSA-xrcm-f723-98ww/GHSA-xrcm-f723-98ww.json +++ b/advisories/unreviewed/2022/04/GHSA-xrcm-f723-98ww/GHSA-xrcm-f723-98ww.json @@ -7,12 +7,8 @@ "CVE-2004-1687" ], "details": "CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xwc7-g658-j4rq/GHSA-xwc7-g658-j4rq.json b/advisories/unreviewed/2022/04/GHSA-xwc7-g658-j4rq/GHSA-xwc7-g658-j4rq.json index 2ff0fae8918..b0098a7c28a 100644 --- a/advisories/unreviewed/2022/04/GHSA-xwc7-g658-j4rq/GHSA-xwc7-g658-j4rq.json +++ b/advisories/unreviewed/2022/04/GHSA-xwc7-g658-j4rq/GHSA-xwc7-g658-j4rq.json @@ -7,12 +7,8 @@ "CVE-2004-1717" ], "details": "Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xxv9-fp7w-qg3h/GHSA-xxv9-fp7w-qg3h.json b/advisories/unreviewed/2022/04/GHSA-xxv9-fp7w-qg3h/GHSA-xxv9-fp7w-qg3h.json index a58bf5be592..95fdbce945e 100644 --- a/advisories/unreviewed/2022/04/GHSA-xxv9-fp7w-qg3h/GHSA-xxv9-fp7w-qg3h.json +++ b/advisories/unreviewed/2022/04/GHSA-xxv9-fp7w-qg3h/GHSA-xxv9-fp7w-qg3h.json @@ -7,12 +7,8 @@ "CVE-2004-1586" ], "details": "Flash Messaging clients can ignore disconnecting commands such as \"shutdown\" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-22hp-gvgq-7pg5/GHSA-22hp-gvgq-7pg5.json b/advisories/unreviewed/2022/05/GHSA-22hp-gvgq-7pg5/GHSA-22hp-gvgq-7pg5.json index fb20892758d..e59ba45664a 100644 --- a/advisories/unreviewed/2022/05/GHSA-22hp-gvgq-7pg5/GHSA-22hp-gvgq-7pg5.json +++ b/advisories/unreviewed/2022/05/GHSA-22hp-gvgq-7pg5/GHSA-22hp-gvgq-7pg5.json @@ -7,12 +7,8 @@ "CVE-2020-14572" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-22rf-57mq-wq43/GHSA-22rf-57mq-wq43.json b/advisories/unreviewed/2022/05/GHSA-22rf-57mq-wq43/GHSA-22rf-57mq-wq43.json index 99a3a4573e1..4bd68f7ed77 100644 --- a/advisories/unreviewed/2022/05/GHSA-22rf-57mq-wq43/GHSA-22rf-57mq-wq43.json +++ b/advisories/unreviewed/2022/05/GHSA-22rf-57mq-wq43/GHSA-22rf-57mq-wq43.json @@ -7,12 +7,8 @@ "CVE-2020-14696" ], "details": "Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Layout Templates). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data as well as unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2454-7cjj-wj2v/GHSA-2454-7cjj-wj2v.json b/advisories/unreviewed/2022/05/GHSA-2454-7cjj-wj2v/GHSA-2454-7cjj-wj2v.json index 80fd044eadb..160ab1862ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-2454-7cjj-wj2v/GHSA-2454-7cjj-wj2v.json +++ b/advisories/unreviewed/2022/05/GHSA-2454-7cjj-wj2v/GHSA-2454-7cjj-wj2v.json @@ -7,12 +7,8 @@ "CVE-2020-5767" ], "details": "Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25h7-qcgx-8445/GHSA-25h7-qcgx-8445.json b/advisories/unreviewed/2022/05/GHSA-25h7-qcgx-8445/GHSA-25h7-qcgx-8445.json index 981a4908d2f..4388cfa4faf 100644 --- a/advisories/unreviewed/2022/05/GHSA-25h7-qcgx-8445/GHSA-25h7-qcgx-8445.json +++ b/advisories/unreviewed/2022/05/GHSA-25h7-qcgx-8445/GHSA-25h7-qcgx-8445.json @@ -7,12 +7,8 @@ "CVE-2020-1371" ], "details": "An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1365.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2669-2gh7-hrr6/GHSA-2669-2gh7-hrr6.json b/advisories/unreviewed/2022/05/GHSA-2669-2gh7-hrr6/GHSA-2669-2gh7-hrr6.json index 21256e0331f..04cca7be7c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2669-2gh7-hrr6/GHSA-2669-2gh7-hrr6.json +++ b/advisories/unreviewed/2022/05/GHSA-2669-2gh7-hrr6/GHSA-2669-2gh7-hrr6.json @@ -7,12 +7,8 @@ "CVE-2020-14600" ], "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28cw-3j6f-3fv3/GHSA-28cw-3j6f-3fv3.json b/advisories/unreviewed/2022/05/GHSA-28cw-3j6f-3fv3/GHSA-28cw-3j6f-3fv3.json index 472de408dc4..c258684f85b 100644 --- a/advisories/unreviewed/2022/05/GHSA-28cw-3j6f-3fv3/GHSA-28cw-3j6f-3fv3.json +++ b/advisories/unreviewed/2022/05/GHSA-28cw-3j6f-3fv3/GHSA-28cw-3j6f-3fv3.json @@ -7,12 +7,8 @@ "CVE-2020-7825" ], "details": "A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2f3r-62xx-976q/GHSA-2f3r-62xx-976q.json b/advisories/unreviewed/2022/05/GHSA-2f3r-62xx-976q/GHSA-2f3r-62xx-976q.json index 0500eab0212..9814e55972f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f3r-62xx-976q/GHSA-2f3r-62xx-976q.json +++ b/advisories/unreviewed/2022/05/GHSA-2f3r-62xx-976q/GHSA-2f3r-62xx-976q.json @@ -7,12 +7,8 @@ "CVE-2020-4372" ], "details": "IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2fx9-jj4f-fr73/GHSA-2fx9-jj4f-fr73.json b/advisories/unreviewed/2022/05/GHSA-2fx9-jj4f-fr73/GHSA-2fx9-jj4f-fr73.json index 442abb41d50..c1b9f524e88 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fx9-jj4f-fr73/GHSA-2fx9-jj4f-fr73.json +++ b/advisories/unreviewed/2022/05/GHSA-2fx9-jj4f-fr73/GHSA-2fx9-jj4f-fr73.json @@ -7,12 +7,8 @@ "CVE-2020-14710" ], "details": "Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to a subset of Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2m2f-v78g-328f/GHSA-2m2f-v78g-328f.json b/advisories/unreviewed/2022/05/GHSA-2m2f-v78g-328f/GHSA-2m2f-v78g-328f.json index c71433a6c40..1cd5b2012dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m2f-v78g-328f/GHSA-2m2f-v78g-328f.json +++ b/advisories/unreviewed/2022/05/GHSA-2m2f-v78g-328f/GHSA-2m2f-v78g-328f.json @@ -7,12 +7,8 @@ "CVE-2019-12783" ], "details": "An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by attackers to \"crowdsource\" bruteforce login attempts on the target site, allowing them to guess and potentially compromise valid credentials without ever sending any traffic from their own machine to the target site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2prm-99p5-f5cr/GHSA-2prm-99p5-f5cr.json b/advisories/unreviewed/2022/05/GHSA-2prm-99p5-f5cr/GHSA-2prm-99p5-f5cr.json index c060ef54ded..54ef4e16a52 100644 --- a/advisories/unreviewed/2022/05/GHSA-2prm-99p5-f5cr/GHSA-2prm-99p5-f5cr.json +++ b/advisories/unreviewed/2022/05/GHSA-2prm-99p5-f5cr/GHSA-2prm-99p5-f5cr.json @@ -7,12 +7,8 @@ "CVE-2020-1449" ], "details": "A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2r34-57wf-fc67/GHSA-2r34-57wf-fc67.json b/advisories/unreviewed/2022/05/GHSA-2r34-57wf-fc67/GHSA-2r34-57wf-fc67.json index ea53aa5f09f..0b882c6d95d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r34-57wf-fc67/GHSA-2r34-57wf-fc67.json +++ b/advisories/unreviewed/2022/05/GHSA-2r34-57wf-fc67/GHSA-2r34-57wf-fc67.json @@ -7,12 +7,8 @@ "CVE-2020-10284" ], "details": "No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but as in xarm_studio 1.3.0 the option is missing from the menu. Assuming manual control, even by forcefully removing the current operator from an active session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rxj-7r53-f46w/GHSA-2rxj-7r53-f46w.json b/advisories/unreviewed/2022/05/GHSA-2rxj-7r53-f46w/GHSA-2rxj-7r53-f46w.json index 30a3e6b0fc9..84734e4216d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rxj-7r53-f46w/GHSA-2rxj-7r53-f46w.json +++ b/advisories/unreviewed/2022/05/GHSA-2rxj-7r53-f46w/GHSA-2rxj-7r53-f46w.json @@ -7,12 +7,8 @@ "CVE-2020-14064" ], "details": "IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2v68-cx38-874x/GHSA-2v68-cx38-874x.json b/advisories/unreviewed/2022/05/GHSA-2v68-cx38-874x/GHSA-2v68-cx38-874x.json index 6b3ab70f2d5..11483d1840b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v68-cx38-874x/GHSA-2v68-cx38-874x.json +++ b/advisories/unreviewed/2022/05/GHSA-2v68-cx38-874x/GHSA-2v68-cx38-874x.json @@ -7,12 +7,8 @@ "CVE-2020-4369" ], "details": "IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2w7w-5xvh-2987/GHSA-2w7w-5xvh-2987.json b/advisories/unreviewed/2022/05/GHSA-2w7w-5xvh-2987/GHSA-2w7w-5xvh-2987.json index 01bde430e89..fcc29130b85 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w7w-5xvh-2987/GHSA-2w7w-5xvh-2987.json +++ b/advisories/unreviewed/2022/05/GHSA-2w7w-5xvh-2987/GHSA-2w7w-5xvh-2987.json @@ -7,12 +7,8 @@ "CVE-2020-14721" ], "details": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Communications Broker accessible data as well as unauthorized read access to a subset of Oracle Enterprise Communications Broker accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2wmv-9ccc-rw9w/GHSA-2wmv-9ccc-rw9w.json b/advisories/unreviewed/2022/05/GHSA-2wmv-9ccc-rw9w/GHSA-2wmv-9ccc-rw9w.json index 5da05437b05..ec0d20cb579 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wmv-9ccc-rw9w/GHSA-2wmv-9ccc-rw9w.json +++ b/advisories/unreviewed/2022/05/GHSA-2wmv-9ccc-rw9w/GHSA-2wmv-9ccc-rw9w.json @@ -7,12 +7,8 @@ "CVE-2020-1365" ], "details": "An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1371.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wrc-cg26-jf7m/GHSA-2wrc-cg26-jf7m.json b/advisories/unreviewed/2022/05/GHSA-2wrc-cg26-jf7m/GHSA-2wrc-cg26-jf7m.json index f5af05bd65a..64733c8ad93 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wrc-cg26-jf7m/GHSA-2wrc-cg26-jf7m.json +++ b/advisories/unreviewed/2022/05/GHSA-2wrc-cg26-jf7m/GHSA-2wrc-cg26-jf7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2x43-7p4j-28px/GHSA-2x43-7p4j-28px.json b/advisories/unreviewed/2022/05/GHSA-2x43-7p4j-28px/GHSA-2x43-7p4j-28px.json index d9da44659c8..fbeff24c450 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x43-7p4j-28px/GHSA-2x43-7p4j-28px.json +++ b/advisories/unreviewed/2022/05/GHSA-2x43-7p4j-28px/GHSA-2x43-7p4j-28px.json @@ -7,12 +7,8 @@ "CVE-2020-14542" ], "details": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: libsuri). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Solaris accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xfg-59p6-ww64/GHSA-2xfg-59p6-ww64.json b/advisories/unreviewed/2022/05/GHSA-2xfg-59p6-ww64/GHSA-2xfg-59p6-ww64.json index 9d7f968e54f..9441407b39a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xfg-59p6-ww64/GHSA-2xfg-59p6-ww64.json +++ b/advisories/unreviewed/2022/05/GHSA-2xfg-59p6-ww64/GHSA-2xfg-59p6-ww64.json @@ -7,12 +7,8 @@ "CVE-2020-14687" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32x5-673x-7q8q/GHSA-32x5-673x-7q8q.json b/advisories/unreviewed/2022/05/GHSA-32x5-673x-7q8q/GHSA-32x5-673x-7q8q.json index efdaba80502..7a7cce59c61 100644 --- a/advisories/unreviewed/2022/05/GHSA-32x5-673x-7q8q/GHSA-32x5-673x-7q8q.json +++ b/advisories/unreviewed/2022/05/GHSA-32x5-673x-7q8q/GHSA-32x5-673x-7q8q.json @@ -7,12 +7,8 @@ "CVE-2019-4091" ], "details": "\"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. \"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34pg-m6c7-g8w8/GHSA-34pg-m6c7-g8w8.json b/advisories/unreviewed/2022/05/GHSA-34pg-m6c7-g8w8/GHSA-34pg-m6c7-g8w8.json index 6e9bedad1f1..65372c7969a 100644 --- a/advisories/unreviewed/2022/05/GHSA-34pg-m6c7-g8w8/GHSA-34pg-m6c7-g8w8.json +++ b/advisories/unreviewed/2022/05/GHSA-34pg-m6c7-g8w8/GHSA-34pg-m6c7-g8w8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34rw-6hrg-mxr5/GHSA-34rw-6hrg-mxr5.json b/advisories/unreviewed/2022/05/GHSA-34rw-6hrg-mxr5/GHSA-34rw-6hrg-mxr5.json index 23c4000bbc7..e2b547c45ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-34rw-6hrg-mxr5/GHSA-34rw-6hrg-mxr5.json +++ b/advisories/unreviewed/2022/05/GHSA-34rw-6hrg-mxr5/GHSA-34rw-6hrg-mxr5.json @@ -7,12 +7,8 @@ "CVE-2020-1641" ], "details": "A Race Condition vulnerability in Juniper Networks Junos OS LLDP implementation allows an attacker to cause LLDP to crash leading to a Denial of Service (DoS). This issue occurs when crafted LLDP packets are received by the device from an adjacent device. Multiple LACP flaps will occur after LLDP crashes. An indicator of compromise is to evaluate log file details for lldp with RLIMIT. Intervention should occur before 85% threshold of used KB versus maximum available KB memory is reached. show log messages | match RLIMIT | match lldp | last 20 Matching statement is \" /kernel: %KERNEL-[number]: Process ([pid #],lldpd) has exceeded 85% of RLIMIT_DATA: \" with [] as variable data to evaluate for. This issue affects: Juniper Networks Junos OS: 12.3 versions prior to 12.3R12-S15; 12.3X48 versions prior to 12.3X48-D95; 15.1 versions prior to 15.1R7-S6; 15.1X49 versions prior to 15.1X49-D200; 15.1X53 versions prior to 15.1X53-D593; 16.1 versions prior to 16.1R7-S7; 17.1 versions prior to 17.1R2-S11, 17.1R3-S2; 17.2 versions prior to 17.2R1-S9, 17.2R3-S3; 17.3 versions prior to 17.3R2-S5, 17.3R3-S6; 17.4 versions prior to 17.4R2-S4, 17.4R3; 18.1 versions prior to 18.1R3-S5; 18.2 versions prior to 18.2R2-S7, 18.2R3; 18.2X75 versions prior to 18.2X75-D12, 18.2X75-D33, 18.2X75-D50, 18.2X75-D420; 18.3 versions prior to 18.3R1-S7, 18.3R2-S3, 18.3R3; 18.4 versions prior to 18.4R1-S5, 18.4R2; 19.1 versions prior to 19.1R1-S4, 19.1R2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3583-6263-6c39/GHSA-3583-6263-6c39.json b/advisories/unreviewed/2022/05/GHSA-3583-6263-6c39/GHSA-3583-6263-6c39.json index 5ceb26199ec..44fb0663398 100644 --- a/advisories/unreviewed/2022/05/GHSA-3583-6263-6c39/GHSA-3583-6263-6c39.json +++ b/advisories/unreviewed/2022/05/GHSA-3583-6263-6c39/GHSA-3583-6263-6c39.json @@ -7,12 +7,8 @@ "CVE-2020-6101" ], "details": "An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability can be triggered from a HYPER-V guest using the RemoteFX feature, leading to executing the vulnerable code on the HYPER-V host (inside of the rdvgm.exe process). Theoretically this vulnerability could be also triggered from web browser (using webGL and webassembly).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-37jw-9hhw-q8w8/GHSA-37jw-9hhw-q8w8.json b/advisories/unreviewed/2022/05/GHSA-37jw-9hhw-q8w8/GHSA-37jw-9hhw-q8w8.json index 705424c99f8..f27b776c01a 100644 --- a/advisories/unreviewed/2022/05/GHSA-37jw-9hhw-q8w8/GHSA-37jw-9hhw-q8w8.json +++ b/advisories/unreviewed/2022/05/GHSA-37jw-9hhw-q8w8/GHSA-37jw-9hhw-q8w8.json @@ -7,12 +7,8 @@ "CVE-2020-1363" ], "details": "An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cgh-jhhf-99jx/GHSA-3cgh-jhhf-99jx.json b/advisories/unreviewed/2022/05/GHSA-3cgh-jhhf-99jx/GHSA-3cgh-jhhf-99jx.json index 3a2dbb99579..aaeb620cda0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cgh-jhhf-99jx/GHSA-3cgh-jhhf-99jx.json +++ b/advisories/unreviewed/2022/05/GHSA-3cgh-jhhf-99jx/GHSA-3cgh-jhhf-99jx.json @@ -7,12 +7,8 @@ "CVE-2020-14534" ], "details": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popups). The supported version that is affected is 12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cqj-w9mm-gpc5/GHSA-3cqj-w9mm-gpc5.json b/advisories/unreviewed/2022/05/GHSA-3cqj-w9mm-gpc5/GHSA-3cqj-w9mm-gpc5.json index 65cf31e2fc4..54f0129b148 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cqj-w9mm-gpc5/GHSA-3cqj-w9mm-gpc5.json +++ b/advisories/unreviewed/2022/05/GHSA-3cqj-w9mm-gpc5/GHSA-3cqj-w9mm-gpc5.json @@ -7,12 +7,8 @@ "CVE-2020-1649" ], "details": "When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and IPIP, the packet forwarding engine (PFE) will become disabled upon receipt of small fragments requiring reassembly, generating the following error messages: [LOG: Err] MQSS(2): WO: Packet Error - Error Packets 1, Connection 29 [LOG: Err] eachip_hmcif_rx_intr_handler(7259): EA[2:0]: HMCIF Rx: Injected checksum error detected on WO response - Chunk Address 0x0 [LOG: Err] MQSS(2): DRD: RORD1: CMD reorder ID error - Command 11, Reorder ID 1960, QID 0 [LOG: Err] MQSS(2): DRD: UNROLL0: HMC chunk address error in stage 5 - Chunk Address: 0xc38fb1 [LOG: Notice] Error: /fpc/0/pfe/0/cm/0/MQSS(2)/2/MQSS_CMERROR_DRD_RORD_ENG_INT_REG_CMD_FSM_STATE_ERR (0x2203cc), scope: pfe, category: functional, severity: major, module: MQSS(2), type: DRD_RORD_ENG_INT: CMD FSM State Error [LOG: Notice] Performing action cmalarm for error /fpc/0/pfe/0/cm/0/MQSS(2)/2/MQSS_CMERROR_DRD_RORD_ENG_INT_REG_CMD_FSM_STATE_ERR (0x2203cc) in module: MQSS(2) with scope: pfe category: functional level: major [LOG: Notice] Performing action get-state for error /fpc/0/pfe/0/cm/0/MQSS(2)/2/MQSS_CMERROR_DRD_RORD_ENG_INT_REG_CMD_FSM_STATE_ERR (0x2203cc) in module: MQSS(2) with scope: pfe category: functional level: major [LOG: Notice] Performing action disable-pfe for error /fpc/0/pfe/0/cm/0/MQSS(2)/2/MQSS_CMERROR_DRD_RORD_ENG_INT_REG_CMD_FSM_STATE_ERR (0x2203cc) in module: MQSS(2) with scope: pfe category: functional level: major By continuously sending fragmented packets that cannot be reassembled, an attacker can repeatedly disable the PFE causing a sustained Denial of Service (DoS). This issue affects Juniper Networks Junos OS: 17.2 versions prior to 17.2R3-S4 on MX Series; 17.3 versions prior to 17.3R3-S8 on MX Series; 17.4 versions prior to 17.4R2-S9, 17.4R3-S1 on MX Series; 18.1 versions prior to 18.1R3-S10 on MX Series; 18.2 versions prior to 18.2R2-S6, 18.2R3-S3 on MX Series; 18.2X75 versions prior to 18.2X75-D34, 18.2X75-D41, 18.2X75-D53, 18.2X75-D65, 18.2X75-D430 on MX Series; 18.3 versions prior to 18.3R1-S7, 18.3R2-S4, 18.3R3-S2 on MX Series; 18.4 versions prior to 18.4R1-S6, 18.4R2-S4, 18.4R3 on MX Series; 19.1 versions prior to 19.1R1-S4, 19.1R2-S1, 19.1R3 on MX Series; 19.2 versions prior to 19.2R1-S3, 19.2R2 on MX Series; 19.3 versions prior to 19.3R2-S2, 19.3R3 on MX Series. This issue is specific to inline IP reassembly, introduced in Junos OS 17.2. Versions of Junos OS prior to 17.2 are unaffected by this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f9w-43j6-x43v/GHSA-3f9w-43j6-x43v.json b/advisories/unreviewed/2022/05/GHSA-3f9w-43j6-x43v/GHSA-3f9w-43j6-x43v.json index c77e260deb9..f58a827895a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f9w-43j6-x43v/GHSA-3f9w-43j6-x43v.json +++ b/advisories/unreviewed/2022/05/GHSA-3f9w-43j6-x43v/GHSA-3f9w-43j6-x43v.json @@ -7,12 +7,8 @@ "CVE-2020-5757" ], "details": "Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's \"New\" HTTPS API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fvg-pj2g-c428/GHSA-3fvg-pj2g-c428.json b/advisories/unreviewed/2022/05/GHSA-3fvg-pj2g-c428/GHSA-3fvg-pj2g-c428.json index 7dc8dae7b01..a6d650e6643 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fvg-pj2g-c428/GHSA-3fvg-pj2g-c428.json +++ b/advisories/unreviewed/2022/05/GHSA-3fvg-pj2g-c428/GHSA-3fvg-pj2g-c428.json @@ -7,12 +7,8 @@ "CVE-2020-14543" ], "details": "Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Installation). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3gg6-9p4q-x3pp/GHSA-3gg6-9p4q-x3pp.json b/advisories/unreviewed/2022/05/GHSA-3gg6-9p4q-x3pp/GHSA-3gg6-9p4q-x3pp.json index 2c20e188ef1..9844c57dcc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gg6-9p4q-x3pp/GHSA-3gg6-9p4q-x3pp.json +++ b/advisories/unreviewed/2022/05/GHSA-3gg6-9p4q-x3pp/GHSA-3gg6-9p4q-x3pp.json @@ -7,12 +7,8 @@ "CVE-2020-14688" ], "details": "Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Common Applications accessible data as well as unauthorized update, insert or delete access to some of Oracle Common Applications accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3h29-6jm6-hw9v/GHSA-3h29-6jm6-hw9v.json b/advisories/unreviewed/2022/05/GHSA-3h29-6jm6-hw9v/GHSA-3h29-6jm6-hw9v.json index 10c00c796d9..df1e5d62af4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h29-6jm6-hw9v/GHSA-3h29-6jm6-hw9v.json +++ b/advisories/unreviewed/2022/05/GHSA-3h29-6jm6-hw9v/GHSA-3h29-6jm6-hw9v.json @@ -7,12 +7,8 @@ "CVE-2020-0122" ], "details": "In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-147247775", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3h98-pjm4-888p/GHSA-3h98-pjm4-888p.json b/advisories/unreviewed/2022/05/GHSA-3h98-pjm4-888p/GHSA-3h98-pjm4-888p.json index cf7577a1115..de6ecc9542a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h98-pjm4-888p/GHSA-3h98-pjm4-888p.json +++ b/advisories/unreviewed/2022/05/GHSA-3h98-pjm4-888p/GHSA-3h98-pjm4-888p.json @@ -7,12 +7,8 @@ "CVE-2020-15816" ], "details": "In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hc3-rj8c-gwj9/GHSA-3hc3-rj8c-gwj9.json b/advisories/unreviewed/2022/05/GHSA-3hc3-rj8c-gwj9/GHSA-3hc3-rj8c-gwj9.json index 8f1d70041ea..8de1719853d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hc3-rj8c-gwj9/GHSA-3hc3-rj8c-gwj9.json +++ b/advisories/unreviewed/2022/05/GHSA-3hc3-rj8c-gwj9/GHSA-3hc3-rj8c-gwj9.json @@ -7,12 +7,8 @@ "CVE-2020-14595" ], "details": "Vulnerability in the Oracle iLearning product of Oracle iLearning (component: Assessment Manager). Supported versions that are affected are 6.1 and 6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iLearning accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle iLearning. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jh7-385x-jfrq/GHSA-3jh7-385x-jfrq.json b/advisories/unreviewed/2022/05/GHSA-3jh7-385x-jfrq/GHSA-3jh7-385x-jfrq.json index c6a952ca36e..8be7153aec0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jh7-385x-jfrq/GHSA-3jh7-385x-jfrq.json +++ b/advisories/unreviewed/2022/05/GHSA-3jh7-385x-jfrq/GHSA-3jh7-385x-jfrq.json @@ -7,12 +7,8 @@ "CVE-2020-14066" ], "details": "IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jhm-f5jx-jwjj/GHSA-3jhm-f5jx-jwjj.json b/advisories/unreviewed/2022/05/GHSA-3jhm-f5jx-jwjj/GHSA-3jhm-f5jx-jwjj.json index f64971ab64e..92ae7fd0635 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jhm-f5jx-jwjj/GHSA-3jhm-f5jx-jwjj.json +++ b/advisories/unreviewed/2022/05/GHSA-3jhm-f5jx-jwjj/GHSA-3jhm-f5jx-jwjj.json @@ -7,12 +7,8 @@ "CVE-2020-3197" ], "details": "A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insufficient protection mechanisms for the TURN server credentials. An attacker could exploit this vulnerability by intercepting the legitimate traffic that is generated by an affected system. An exploit could allow the attacker to obtain the TURN server credentials, which the attacker could use to place audio/video calls and forward packets through the configured TURN server. The attacker would not be able to take control of the TURN server unless the same credentials were used in multiple systems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3p23-x5x3-gwjm/GHSA-3p23-x5x3-gwjm.json b/advisories/unreviewed/2022/05/GHSA-3p23-x5x3-gwjm/GHSA-3p23-x5x3-gwjm.json index 618571d3041..050f963a70c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p23-x5x3-gwjm/GHSA-3p23-x5x3-gwjm.json +++ b/advisories/unreviewed/2022/05/GHSA-3p23-x5x3-gwjm/GHSA-3p23-x5x3-gwjm.json @@ -7,12 +7,8 @@ "CVE-2020-6292" ], "details": "Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3p3f-h63v-47c5/GHSA-3p3f-h63v-47c5.json b/advisories/unreviewed/2022/05/GHSA-3p3f-h63v-47c5/GHSA-3p3f-h63v-47c5.json index a4625259bb3..b73c3ba1743 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p3f-h63v-47c5/GHSA-3p3f-h63v-47c5.json +++ b/advisories/unreviewed/2022/05/GHSA-3p3f-h63v-47c5/GHSA-3p3f-h63v-47c5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3p77-prh6-2vh7/GHSA-3p77-prh6-2vh7.json b/advisories/unreviewed/2022/05/GHSA-3p77-prh6-2vh7/GHSA-3p77-prh6-2vh7.json index 5d398549975..8c8b04e4245 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p77-prh6-2vh7/GHSA-3p77-prh6-2vh7.json +++ b/advisories/unreviewed/2022/05/GHSA-3p77-prh6-2vh7/GHSA-3p77-prh6-2vh7.json @@ -7,12 +7,8 @@ "CVE-2020-9256" ], "details": "Huawei Mate 30 Pro smartphones with versions earlier than 10.1.0.150(C00E136R5P3) have an improper authorization vulnerability. The system does not properly restrict the use of system service by applications, the attacker should trick the user into installing a malicious application, successful exploit could cause a denial of audio service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3p9g-h722-84r2/GHSA-3p9g-h722-84r2.json b/advisories/unreviewed/2022/05/GHSA-3p9g-h722-84r2/GHSA-3p9g-h722-84r2.json index a6d049dc8dc..e0f1f5463d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p9g-h722-84r2/GHSA-3p9g-h722-84r2.json +++ b/advisories/unreviewed/2022/05/GHSA-3p9g-h722-84r2/GHSA-3p9g-h722-84r2.json @@ -7,12 +7,8 @@ "CVE-2020-1356" ], "details": "An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations, aka 'Windows iSCSI Target Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pp4-hx37-v55w/GHSA-3pp4-hx37-v55w.json b/advisories/unreviewed/2022/05/GHSA-3pp4-hx37-v55w/GHSA-3pp4-hx37-v55w.json index 95e140f781a..0da0b0a0187 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pp4-hx37-v55w/GHSA-3pp4-hx37-v55w.json +++ b/advisories/unreviewed/2022/05/GHSA-3pp4-hx37-v55w/GHSA-3pp4-hx37-v55w.json @@ -7,12 +7,8 @@ "CVE-2020-14511" ], "details": "Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3px5-5wr3-7444/GHSA-3px5-5wr3-7444.json b/advisories/unreviewed/2022/05/GHSA-3px5-5wr3-7444/GHSA-3px5-5wr3-7444.json index 64fe3fd50a9..5b3893659aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-3px5-5wr3-7444/GHSA-3px5-5wr3-7444.json +++ b/advisories/unreviewed/2022/05/GHSA-3px5-5wr3-7444/GHSA-3px5-5wr3-7444.json @@ -7,12 +7,8 @@ "CVE-2020-14599" ], "details": "Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway for Mobile Devices. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Gateway for Mobile Devices accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Gateway for Mobile Devices accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q34-45m9-2pqp/GHSA-3q34-45m9-2pqp.json b/advisories/unreviewed/2022/05/GHSA-3q34-45m9-2pqp/GHSA-3q34-45m9-2pqp.json index 56896b0c46a..ae10112fba2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q34-45m9-2pqp/GHSA-3q34-45m9-2pqp.json +++ b/advisories/unreviewed/2022/05/GHSA-3q34-45m9-2pqp/GHSA-3q34-45m9-2pqp.json @@ -7,12 +7,8 @@ "CVE-2020-14606" ], "details": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications Applications (component: User Interface). Supported versions that are affected are 8.2 and 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge. While the vulnerability is in Oracle SD-WAN Edge, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle SD-WAN Edge. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q43-4596-jvg6/GHSA-3q43-4596-jvg6.json b/advisories/unreviewed/2022/05/GHSA-3q43-4596-jvg6/GHSA-3q43-4596-jvg6.json index e0b584cd0ba..f99effd9a83 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q43-4596-jvg6/GHSA-3q43-4596-jvg6.json +++ b/advisories/unreviewed/2022/05/GHSA-3q43-4596-jvg6/GHSA-3q43-4596-jvg6.json @@ -7,12 +7,8 @@ "CVE-2020-14718" ], "details": "Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: JVMCI). Supported versions that are affected are 19.3.2 and 20.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rg7-72j5-5xpv/GHSA-3rg7-72j5-5xpv.json b/advisories/unreviewed/2022/05/GHSA-3rg7-72j5-5xpv/GHSA-3rg7-72j5-5xpv.json index b70f19a5704..a0da2340022 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rg7-72j5-5xpv/GHSA-3rg7-72j5-5xpv.json +++ b/advisories/unreviewed/2022/05/GHSA-3rg7-72j5-5xpv/GHSA-3rg7-72j5-5xpv.json @@ -7,12 +7,8 @@ "CVE-2020-14928" ], "details": "evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a \"begin TLS\" response, eds reads additional data and evaluates it in a TLS context, aka \"response injection.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rqm-h9m6-6rw6/GHSA-3rqm-h9m6-6rw6.json b/advisories/unreviewed/2022/05/GHSA-3rqm-h9m6-6rw6/GHSA-3rqm-h9m6-6rw6.json index 9e2c7263442..8bf117ae936 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rqm-h9m6-6rw6/GHSA-3rqm-h9m6-6rw6.json +++ b/advisories/unreviewed/2022/05/GHSA-3rqm-h9m6-6rw6/GHSA-3rqm-h9m6-6rw6.json @@ -7,12 +7,8 @@ "CVE-2019-12773" ], "details": "An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to embed arbitrary content inside of an iFrame. Attackers may use this in conjunction with social engineering to embed malicious scripts or phishing pages on a site where this product is installed, given the attacker can convince a victim to visit a crafted link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vf8-2x93-3hff/GHSA-3vf8-2x93-3hff.json b/advisories/unreviewed/2022/05/GHSA-3vf8-2x93-3hff/GHSA-3vf8-2x93-3hff.json index 6326c56c826..70f3314e8f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vf8-2x93-3hff/GHSA-3vf8-2x93-3hff.json +++ b/advisories/unreviewed/2022/05/GHSA-3vf8-2x93-3hff/GHSA-3vf8-2x93-3hff.json @@ -7,12 +7,8 @@ "CVE-2020-1646" ], "details": "On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP peer can lead to a routing process daemon (RPD) crash and restart. This issue occurs only when the device is receiving and processing the BGP UPDATE for an EBGP peer. This issue does not occur when the device is receiving and processing the BGP UPDATE for an IBGP peer. However, the offending BGP UPDATE can originally come from an EBGP peer, propagates through the network via IBGP peers without causing crash, then it causes RPD crash when it is processed for a BGP UPDATE towards an EBGP peer. Repeated receipt and processing of the same specific BGP UPDATE can result in an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 17.3R3-S6, 17.4R2-S7, and 18.1R3-S7. Juniper Networks Junos OS Evolved 19.2R2-EVO and later versions, prior to 19.3R1-EVO. Other Junos OS releases are not affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xfp-j69g-wh2v/GHSA-3xfp-j69g-wh2v.json b/advisories/unreviewed/2022/05/GHSA-3xfp-j69g-wh2v/GHSA-3xfp-j69g-wh2v.json index ea3b45860b7..875d1dbe7ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xfp-j69g-wh2v/GHSA-3xfp-j69g-wh2v.json +++ b/advisories/unreviewed/2022/05/GHSA-3xfp-j69g-wh2v/GHSA-3xfp-j69g-wh2v.json @@ -7,12 +7,8 @@ "CVE-2020-10989" ], "details": "An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43p9-75r2-vgfm/GHSA-43p9-75r2-vgfm.json b/advisories/unreviewed/2022/05/GHSA-43p9-75r2-vgfm/GHSA-43p9-75r2-vgfm.json index 883fe732289..096addce9fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-43p9-75r2-vgfm/GHSA-43p9-75r2-vgfm.json +++ b/advisories/unreviewed/2022/05/GHSA-43p9-75r2-vgfm/GHSA-43p9-75r2-vgfm.json @@ -7,12 +7,8 @@ "CVE-2020-3406" ], "details": "A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45ff-f59c-34h9/GHSA-45ff-f59c-34h9.json b/advisories/unreviewed/2022/05/GHSA-45ff-f59c-34h9/GHSA-45ff-f59c-34h9.json index 5da81626836..5fe0cdc44aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-45ff-f59c-34h9/GHSA-45ff-f59c-34h9.json +++ b/advisories/unreviewed/2022/05/GHSA-45ff-f59c-34h9/GHSA-45ff-f59c-34h9.json @@ -7,12 +7,8 @@ "CVE-2020-14558" ], "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45fw-qrx2-rj7m/GHSA-45fw-qrx2-rj7m.json b/advisories/unreviewed/2022/05/GHSA-45fw-qrx2-rj7m/GHSA-45fw-qrx2-rj7m.json index f4a2dd3bb78..bbb46e3c27b 100644 --- a/advisories/unreviewed/2022/05/GHSA-45fw-qrx2-rj7m/GHSA-45fw-qrx2-rj7m.json +++ b/advisories/unreviewed/2022/05/GHSA-45fw-qrx2-rj7m/GHSA-45fw-qrx2-rj7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-469r-x3h6-wx66/GHSA-469r-x3h6-wx66.json b/advisories/unreviewed/2022/05/GHSA-469r-x3h6-wx66/GHSA-469r-x3h6-wx66.json index 3cb52e86197..dad59193208 100644 --- a/advisories/unreviewed/2022/05/GHSA-469r-x3h6-wx66/GHSA-469r-x3h6-wx66.json +++ b/advisories/unreviewed/2022/05/GHSA-469r-x3h6-wx66/GHSA-469r-x3h6-wx66.json @@ -7,12 +7,8 @@ "CVE-2020-1396" ], "details": "An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Windows ALPC Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-479q-9rv9-rggg/GHSA-479q-9rv9-rggg.json b/advisories/unreviewed/2022/05/GHSA-479q-9rv9-rggg/GHSA-479q-9rv9-rggg.json index 53210405e47..caf6b2accdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-479q-9rv9-rggg/GHSA-479q-9rv9-rggg.json +++ b/advisories/unreviewed/2022/05/GHSA-479q-9rv9-rggg/GHSA-479q-9rv9-rggg.json @@ -7,12 +7,8 @@ "CVE-2020-1398" ], "details": "An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vulnerability by ensuring that the Ease of Access dialog is handled properly., aka 'Windows Lockscreen Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-485p-7896-665h/GHSA-485p-7896-665h.json b/advisories/unreviewed/2022/05/GHSA-485p-7896-665h/GHSA-485p-7896-665h.json index 90364604f7c..569fffadbb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-485p-7896-665h/GHSA-485p-7896-665h.json +++ b/advisories/unreviewed/2022/05/GHSA-485p-7896-665h/GHSA-485p-7896-665h.json @@ -7,12 +7,8 @@ "CVE-2020-14569" ], "details": "Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Investor Servicing accessible data as well as unauthorized access to critical data or complete access to all Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-492m-hh57-3gv9/GHSA-492m-hh57-3gv9.json b/advisories/unreviewed/2022/05/GHSA-492m-hh57-3gv9/GHSA-492m-hh57-3gv9.json index 1b0f81e42c2..093c6fc9689 100644 --- a/advisories/unreviewed/2022/05/GHSA-492m-hh57-3gv9/GHSA-492m-hh57-3gv9.json +++ b/advisories/unreviewed/2022/05/GHSA-492m-hh57-3gv9/GHSA-492m-hh57-3gv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4crc-pq4f-rh77/GHSA-4crc-pq4f-rh77.json b/advisories/unreviewed/2022/05/GHSA-4crc-pq4f-rh77/GHSA-4crc-pq4f-rh77.json index a85e2141e5e..ad3aa69ccae 100644 --- a/advisories/unreviewed/2022/05/GHSA-4crc-pq4f-rh77/GHSA-4crc-pq4f-rh77.json +++ b/advisories/unreviewed/2022/05/GHSA-4crc-pq4f-rh77/GHSA-4crc-pq4f-rh77.json @@ -7,12 +7,8 @@ "CVE-2020-2562" ], "details": "Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Investor Module). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as well as unauthorized read access to a subset of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f9x-p86g-x88m/GHSA-4f9x-p86g-x88m.json b/advisories/unreviewed/2022/05/GHSA-4f9x-p86g-x88m/GHSA-4f9x-p86g-x88m.json index 485ad3fe5c7..64e0313f172 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f9x-p86g-x88m/GHSA-4f9x-p86g-x88m.json +++ b/advisories/unreviewed/2022/05/GHSA-4f9x-p86g-x88m/GHSA-4f9x-p86g-x88m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fg8-hr8g-58rr/GHSA-4fg8-hr8g-58rr.json b/advisories/unreviewed/2022/05/GHSA-4fg8-hr8g-58rr/GHSA-4fg8-hr8g-58rr.json index 0c7d2508192..382c308b89a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fg8-hr8g-58rr/GHSA-4fg8-hr8g-58rr.json +++ b/advisories/unreviewed/2022/05/GHSA-4fg8-hr8g-58rr/GHSA-4fg8-hr8g-58rr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4g9m-q8c4-5m6x/GHSA-4g9m-q8c4-5m6x.json b/advisories/unreviewed/2022/05/GHSA-4g9m-q8c4-5m6x/GHSA-4g9m-q8c4-5m6x.json index 6cd465c6fe3..2311abec158 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g9m-q8c4-5m6x/GHSA-4g9m-q8c4-5m6x.json +++ b/advisories/unreviewed/2022/05/GHSA-4g9m-q8c4-5m6x/GHSA-4g9m-q8c4-5m6x.json @@ -7,12 +7,8 @@ "CVE-2020-3144" ], "details": "A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary commands with administrative commands on an affected device. The vulnerability is due to improper session management on affected devices. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gg5-pmq6-mj4h/GHSA-4gg5-pmq6-mj4h.json b/advisories/unreviewed/2022/05/GHSA-4gg5-pmq6-mj4h/GHSA-4gg5-pmq6-mj4h.json index 609d963b8ab..a4716057e94 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gg5-pmq6-mj4h/GHSA-4gg5-pmq6-mj4h.json +++ b/advisories/unreviewed/2022/05/GHSA-4gg5-pmq6-mj4h/GHSA-4gg5-pmq6-mj4h.json @@ -7,12 +7,8 @@ "CVE-2020-14695" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4ggw-3x5g-hjm6/GHSA-4ggw-3x5g-hjm6.json b/advisories/unreviewed/2022/05/GHSA-4ggw-3x5g-hjm6/GHSA-4ggw-3x5g-hjm6.json index 28f1f01a54b..6b848d269f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ggw-3x5g-hjm6/GHSA-4ggw-3x5g-hjm6.json +++ b/advisories/unreviewed/2022/05/GHSA-4ggw-3x5g-hjm6/GHSA-4ggw-3x5g-hjm6.json @@ -7,12 +7,8 @@ "CVE-2020-5130" ], "details": "SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gp5-h62v-pf2f/GHSA-4gp5-h62v-pf2f.json b/advisories/unreviewed/2022/05/GHSA-4gp5-h62v-pf2f/GHSA-4gp5-h62v-pf2f.json index f4d5942dfec..23a3b705adf 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gp5-h62v-pf2f/GHSA-4gp5-h62v-pf2f.json +++ b/advisories/unreviewed/2022/05/GHSA-4gp5-h62v-pf2f/GHSA-4gp5-h62v-pf2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gpq-jpqc-j6v2/GHSA-4gpq-jpqc-j6v2.json b/advisories/unreviewed/2022/05/GHSA-4gpq-jpqc-j6v2/GHSA-4gpq-jpqc-j6v2.json index 5b3a1108838..d3e150acffd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gpq-jpqc-j6v2/GHSA-4gpq-jpqc-j6v2.json +++ b/advisories/unreviewed/2022/05/GHSA-4gpq-jpqc-j6v2/GHSA-4gpq-jpqc-j6v2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hv9-pmwc-92h3/GHSA-4hv9-pmwc-92h3.json b/advisories/unreviewed/2022/05/GHSA-4hv9-pmwc-92h3/GHSA-4hv9-pmwc-92h3.json index 031d572610b..3447437ad65 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hv9-pmwc-92h3/GHSA-4hv9-pmwc-92h3.json +++ b/advisories/unreviewed/2022/05/GHSA-4hv9-pmwc-92h3/GHSA-4hv9-pmwc-92h3.json @@ -7,12 +7,8 @@ "CVE-2020-14660" ], "details": "Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4mqr-g5p6-c895/GHSA-4mqr-g5p6-c895.json b/advisories/unreviewed/2022/05/GHSA-4mqr-g5p6-c895/GHSA-4mqr-g5p6-c895.json index 9e0c83ef825..26e5d02f162 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mqr-g5p6-c895/GHSA-4mqr-g5p6-c895.json +++ b/advisories/unreviewed/2022/05/GHSA-4mqr-g5p6-c895/GHSA-4mqr-g5p6-c895.json @@ -7,12 +7,8 @@ "CVE-2020-9102" ], "details": "There is a information leak vulnerability in some Huawei products, and it could allow a local attacker to get information. The vulnerability is due to the improper management of the username. An attacker with the ability to access the device and cause the username information leak. Affected product versions include: CloudEngine 12800 versions V200R002C50SPC800, V200R003C00SPC810, V200R005C00SPC800, V200R005C10SPC800, V200R019C00SPC800; CloudEngine 5800 versions V200R002C50SPC800, V200R003C00SPC810, V200R005C00SPC800, V200R005C10SPC800, V200R019C00SPC800; CloudEngine 6800 versions V200R002C50SPC800, V200R003C00SPC810, V200R005C00SPC800, V200R005C10SPC800, V200R005C20SPC800, V200R019C00SPC800; CloudEngine 7800 versions V200R002C50SPC800, V200R003C00SPC810, V200R005C00SPC800, V200R005C10SPC800, V200R019C00SPC800", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mrc-xcpw-vx8p/GHSA-4mrc-xcpw-vx8p.json b/advisories/unreviewed/2022/05/GHSA-4mrc-xcpw-vx8p/GHSA-4mrc-xcpw-vx8p.json index 4cefd75a073..adf3c19ee85 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mrc-xcpw-vx8p/GHSA-4mrc-xcpw-vx8p.json +++ b/advisories/unreviewed/2022/05/GHSA-4mrc-xcpw-vx8p/GHSA-4mrc-xcpw-vx8p.json @@ -7,12 +7,8 @@ "CVE-2020-14715" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p7q-hvhp-3r8p/GHSA-4p7q-hvhp-3r8p.json b/advisories/unreviewed/2022/05/GHSA-4p7q-hvhp-3r8p/GHSA-4p7q-hvhp-3r8p.json index f56a682ce68..d8b9b822ab4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p7q-hvhp-3r8p/GHSA-4p7q-hvhp-3r8p.json +++ b/advisories/unreviewed/2022/05/GHSA-4p7q-hvhp-3r8p/GHSA-4p7q-hvhp-3r8p.json @@ -7,12 +7,8 @@ "CVE-2020-4462" ], "details": "IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181482.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4prf-w3jr-7gjh/GHSA-4prf-w3jr-7gjh.json b/advisories/unreviewed/2022/05/GHSA-4prf-w3jr-7gjh/GHSA-4prf-w3jr-7gjh.json index 162cf7b5edd..f74ceb591af 100644 --- a/advisories/unreviewed/2022/05/GHSA-4prf-w3jr-7gjh/GHSA-4prf-w3jr-7gjh.json +++ b/advisories/unreviewed/2022/05/GHSA-4prf-w3jr-7gjh/GHSA-4prf-w3jr-7gjh.json @@ -7,12 +7,8 @@ "CVE-2020-14642" ], "details": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: CacheStore). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qgv-f49m-hw36/GHSA-4qgv-f49m-hw36.json b/advisories/unreviewed/2022/05/GHSA-4qgv-f49m-hw36/GHSA-4qgv-f49m-hw36.json index 5c124e7d2de..e0f0dae3603 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qgv-f49m-hw36/GHSA-4qgv-f49m-hw36.json +++ b/advisories/unreviewed/2022/05/GHSA-4qgv-f49m-hw36/GHSA-4qgv-f49m-hw36.json @@ -7,12 +7,8 @@ "CVE-2020-14665" ], "details": "Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Invoice). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qp8-g498-pjrc/GHSA-4qp8-g498-pjrc.json b/advisories/unreviewed/2022/05/GHSA-4qp8-g498-pjrc/GHSA-4qp8-g498-pjrc.json index b7682393d3f..5e3a97976ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qp8-g498-pjrc/GHSA-4qp8-g498-pjrc.json +++ b/advisories/unreviewed/2022/05/GHSA-4qp8-g498-pjrc/GHSA-4qp8-g498-pjrc.json @@ -7,12 +7,8 @@ "CVE-2020-3150" ], "details": "A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote attacker to download sensitive information from the device, which could include the device configuration. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing a specific URI on the web-based management interface of the router, but only after any valid user has opened a specific file on the device since the last reboot. A successful exploit would allow the attacker to view sensitive information, which should be restricted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qqg-r6qm-rxgh/GHSA-4qqg-r6qm-rxgh.json b/advisories/unreviewed/2022/05/GHSA-4qqg-r6qm-rxgh/GHSA-4qqg-r6qm-rxgh.json index 78d69daa5c0..c34ea748fb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qqg-r6qm-rxgh/GHSA-4qqg-r6qm-rxgh.json +++ b/advisories/unreviewed/2022/05/GHSA-4qqg-r6qm-rxgh/GHSA-4qqg-r6qm-rxgh.json @@ -7,12 +7,8 @@ "CVE-2020-0107" ], "details": "In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146570216", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qwg-gc27-7p3m/GHSA-4qwg-gc27-7p3m.json b/advisories/unreviewed/2022/05/GHSA-4qwg-gc27-7p3m/GHSA-4qwg-gc27-7p3m.json index d85dff74c59..05fa88fd2e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qwg-gc27-7p3m/GHSA-4qwg-gc27-7p3m.json +++ b/advisories/unreviewed/2022/05/GHSA-4qwg-gc27-7p3m/GHSA-4qwg-gc27-7p3m.json @@ -7,12 +7,8 @@ "CVE-2020-2972" ], "details": "Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rg7-5qhh-6v5f/GHSA-4rg7-5qhh-6v5f.json b/advisories/unreviewed/2022/05/GHSA-4rg7-5qhh-6v5f/GHSA-4rg7-5qhh-6v5f.json index 5eb5e15c754..5da23e56717 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rg7-5qhh-6v5f/GHSA-4rg7-5qhh-6v5f.json +++ b/advisories/unreviewed/2022/05/GHSA-4rg7-5qhh-6v5f/GHSA-4rg7-5qhh-6v5f.json @@ -7,12 +7,8 @@ "CVE-2020-14617" ], "details": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform, Mobile App). Supported versions that are affected are 16.1, 16.2, 17.7-17.12, 18.8 and 19.12; Mobile App: Prior to 20.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera Unifier accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rjg-59m2-p2v5/GHSA-4rjg-59m2-p2v5.json b/advisories/unreviewed/2022/05/GHSA-4rjg-59m2-p2v5/GHSA-4rjg-59m2-p2v5.json index cd394ec50b0..6e9ab6bfeb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rjg-59m2-p2v5/GHSA-4rjg-59m2-p2v5.json +++ b/advisories/unreviewed/2022/05/GHSA-4rjg-59m2-p2v5/GHSA-4rjg-59m2-p2v5.json @@ -7,12 +7,8 @@ "CVE-2020-2969" ], "details": "Vulnerability in the Data Pump component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows high privileged attacker having DBA role account privilege with network access via Oracle Net to compromise Data Pump. Successful attacks of this vulnerability can result in takeover of Data Pump. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x8f-6m48-c263/GHSA-4x8f-6m48-c263.json b/advisories/unreviewed/2022/05/GHSA-4x8f-6m48-c263/GHSA-4x8f-6m48-c263.json index b7bf0120d8a..739560b896b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x8f-6m48-c263/GHSA-4x8f-6m48-c263.json +++ b/advisories/unreviewed/2022/05/GHSA-4x8f-6m48-c263/GHSA-4x8f-6m48-c263.json @@ -7,12 +7,8 @@ "CVE-2019-20914" ], "details": "An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x96-gfcf-h2wp/GHSA-4x96-gfcf-h2wp.json b/advisories/unreviewed/2022/05/GHSA-4x96-gfcf-h2wp/GHSA-4x96-gfcf-h2wp.json index ba315f2ed34..83e21f414d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x96-gfcf-h2wp/GHSA-4x96-gfcf-h2wp.json +++ b/advisories/unreviewed/2022/05/GHSA-4x96-gfcf-h2wp/GHSA-4x96-gfcf-h2wp.json @@ -7,12 +7,8 @@ "CVE-2020-1374" ], "details": "A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xhc-v448-j5jx/GHSA-4xhc-v448-j5jx.json b/advisories/unreviewed/2022/05/GHSA-4xhc-v448-j5jx/GHSA-4xhc-v448-j5jx.json index 9eb31c9f7ca..8926ddd301c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xhc-v448-j5jx/GHSA-4xhc-v448-j5jx.json +++ b/advisories/unreviewed/2022/05/GHSA-4xhc-v448-j5jx/GHSA-4xhc-v448-j5jx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xrc-jppf-j6qq/GHSA-4xrc-jppf-j6qq.json b/advisories/unreviewed/2022/05/GHSA-4xrc-jppf-j6qq/GHSA-4xrc-jppf-j6qq.json index fb9250b9137..8c854ec7400 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xrc-jppf-j6qq/GHSA-4xrc-jppf-j6qq.json +++ b/advisories/unreviewed/2022/05/GHSA-4xrc-jppf-j6qq/GHSA-4xrc-jppf-j6qq.json @@ -7,12 +7,8 @@ "CVE-2020-3348" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a customized link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-524h-35w7-86xp/GHSA-524h-35w7-86xp.json b/advisories/unreviewed/2022/05/GHSA-524h-35w7-86xp/GHSA-524h-35w7-86xp.json index 7099d34a267..125bd94b6f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-524h-35w7-86xp/GHSA-524h-35w7-86xp.json +++ b/advisories/unreviewed/2022/05/GHSA-524h-35w7-86xp/GHSA-524h-35w7-86xp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52x8-4mc9-26r2/GHSA-52x8-4mc9-26r2.json b/advisories/unreviewed/2022/05/GHSA-52x8-4mc9-26r2/GHSA-52x8-4mc9-26r2.json index 18f9c622107..586c739d5d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-52x8-4mc9-26r2/GHSA-52x8-4mc9-26r2.json +++ b/advisories/unreviewed/2022/05/GHSA-52x8-4mc9-26r2/GHSA-52x8-4mc9-26r2.json @@ -7,12 +7,8 @@ "CVE-2020-1648" ], "details": "On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead to a routing process daemon (RPD) crash and restart. This issue can occur even before the BGP session with the peer is established. Repeated receipt of this specific BGP packet can result in an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 18.2X75 versions starting from 18.2X75-D50.8, 18.2X75-D60 and later versions, prior to 18.2X75-D52.8, 18.2X75-D53, 18.2X75-D60.2, 18.2X75-D65.1, 18.2X75-D70; 19.4 versions 19.4R1 and 19.4R1-S1; 20.1 versions prior to 20.1R1-S2, 20.1R2. Juniper Networks Junos OS Evolved: 19.4-EVO versions prior to 19.4R2-S2-EVO; 20.1-EVO versions prior to 20.1R2-EVO. This issue does not affect: Juniper Networks Junos OS releases prior to 19.4R1. Juniper Networks Junos OS Evolved releases prior to 19.4R1-EVO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53f8-p3cp-57m5/GHSA-53f8-p3cp-57m5.json b/advisories/unreviewed/2022/05/GHSA-53f8-p3cp-57m5/GHSA-53f8-p3cp-57m5.json index 63b6b863b74..7cc473470ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-53f8-p3cp-57m5/GHSA-53f8-p3cp-57m5.json +++ b/advisories/unreviewed/2022/05/GHSA-53f8-p3cp-57m5/GHSA-53f8-p3cp-57m5.json @@ -7,12 +7,8 @@ "CVE-2020-10287" ], "details": "The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of our research, we found multiple production systems running these exact default credentials and consider thereby this an exposure that should be mitigated. Moreover, future deployments should consider that these defaults should be forbidden (user should be forced to change them).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53h4-f555-qg3c/GHSA-53h4-f555-qg3c.json b/advisories/unreviewed/2022/05/GHSA-53h4-f555-qg3c/GHSA-53h4-f555-qg3c.json index 1093f095822..71fefb16ad9 100644 --- a/advisories/unreviewed/2022/05/GHSA-53h4-f555-qg3c/GHSA-53h4-f555-qg3c.json +++ b/advisories/unreviewed/2022/05/GHSA-53h4-f555-qg3c/GHSA-53h4-f555-qg3c.json @@ -7,12 +7,8 @@ "CVE-2020-1644" ], "details": "On Juniper Networks Junos OS and Junos OS Evolved devices, the receipt of a specific BGP UPDATE packet causes an internal counter to be incremented incorrectly, which over time can lead to the routing protocols process (RPD) crash and restart. This issue affects both IBGP and EBGP multihop deployment in IPv4 or IPv6 network. This issue affects: Juniper Networks Junos OS: 17.2X75 versions prior to 17.2X75-D105.19; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S10, 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S4; 18.2X75 versions prior to 18.2X75-D13, 18.2X75-D411.1, 18.2X75-D420.18, 18.2X75-D52.3, 18.2X75-D60; 18.3 versions prior to 18.3R2-S4, 18.3R3-S2; 18.4 versions prior to 18.4R1-S7, 18.4R2-S4, 18.4R3-S2; 19.1 versions prior to 19.1R1-S5, 19.1R2-S1, 19.1R3; 19.2 versions prior to 19.2R1-S5, 19.2R2; 19.3 versions prior to 19.3R2-S2, 19.3R3; 19.4 versions prior to 19.4R1-S2, 19.4R2. Juniper Networks Junos OS Evolved: any releases prior to 20.1R2-EVO. This issue does not affect Juniper Networks Junos OS releases prior to 17.3R1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54m5-9ph9-j9cr/GHSA-54m5-9ph9-j9cr.json b/advisories/unreviewed/2022/05/GHSA-54m5-9ph9-j9cr/GHSA-54m5-9ph9-j9cr.json index 10eee2b6cf8..6ce44659a56 100644 --- a/advisories/unreviewed/2022/05/GHSA-54m5-9ph9-j9cr/GHSA-54m5-9ph9-j9cr.json +++ b/advisories/unreviewed/2022/05/GHSA-54m5-9ph9-j9cr/GHSA-54m5-9ph9-j9cr.json @@ -7,12 +7,8 @@ "CVE-2020-3145" ], "details": "Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabilities are due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit these vulnerabilities by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-553c-2cmm-9m3c/GHSA-553c-2cmm-9m3c.json b/advisories/unreviewed/2022/05/GHSA-553c-2cmm-9m3c/GHSA-553c-2cmm-9m3c.json index 8691c1cf411..e1a8713e810 100644 --- a/advisories/unreviewed/2022/05/GHSA-553c-2cmm-9m3c/GHSA-553c-2cmm-9m3c.json +++ b/advisories/unreviewed/2022/05/GHSA-553c-2cmm-9m3c/GHSA-553c-2cmm-9m3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-559m-xqw9-mvgm/GHSA-559m-xqw9-mvgm.json b/advisories/unreviewed/2022/05/GHSA-559m-xqw9-mvgm/GHSA-559m-xqw9-mvgm.json index df387d2414d..97918194567 100644 --- a/advisories/unreviewed/2022/05/GHSA-559m-xqw9-mvgm/GHSA-559m-xqw9-mvgm.json +++ b/advisories/unreviewed/2022/05/GHSA-559m-xqw9-mvgm/GHSA-559m-xqw9-mvgm.json @@ -7,12 +7,8 @@ "CVE-2020-5759" ], "details": "Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted \"unset\" command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55c3-672v-cpq4/GHSA-55c3-672v-cpq4.json b/advisories/unreviewed/2022/05/GHSA-55c3-672v-cpq4/GHSA-55c3-672v-cpq4.json index 2aa0d49d70f..a8b57d73384 100644 --- a/advisories/unreviewed/2022/05/GHSA-55c3-672v-cpq4/GHSA-55c3-672v-cpq4.json +++ b/advisories/unreviewed/2022/05/GHSA-55c3-672v-cpq4/GHSA-55c3-672v-cpq4.json @@ -7,12 +7,8 @@ "CVE-2020-1413" ], "details": "An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55fp-xjf8-j279/GHSA-55fp-xjf8-j279.json b/advisories/unreviewed/2022/05/GHSA-55fp-xjf8-j279/GHSA-55fp-xjf8-j279.json index f7429dbbe0c..cbd274ef884 100644 --- a/advisories/unreviewed/2022/05/GHSA-55fp-xjf8-j279/GHSA-55fp-xjf8-j279.json +++ b/advisories/unreviewed/2022/05/GHSA-55fp-xjf8-j279/GHSA-55fp-xjf8-j279.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56rm-922m-cgc9/GHSA-56rm-922m-cgc9.json b/advisories/unreviewed/2022/05/GHSA-56rm-922m-cgc9/GHSA-56rm-922m-cgc9.json index dc65407495b..ea9b9c6446d 100644 --- a/advisories/unreviewed/2022/05/GHSA-56rm-922m-cgc9/GHSA-56rm-922m-cgc9.json +++ b/advisories/unreviewed/2022/05/GHSA-56rm-922m-cgc9/GHSA-56rm-922m-cgc9.json @@ -7,12 +7,8 @@ "CVE-2020-14712" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-574c-4j7x-8x44/GHSA-574c-4j7x-8x44.json b/advisories/unreviewed/2022/05/GHSA-574c-4j7x-8x44/GHSA-574c-4j7x-8x44.json index fab88b304b5..266d158aa54 100644 --- a/advisories/unreviewed/2022/05/GHSA-574c-4j7x-8x44/GHSA-574c-4j7x-8x44.json +++ b/advisories/unreviewed/2022/05/GHSA-574c-4j7x-8x44/GHSA-574c-4j7x-8x44.json @@ -7,12 +7,8 @@ "CVE-2020-14635" ], "details": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Logging). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-57f7-3g6g-rwhr/GHSA-57f7-3g6g-rwhr.json b/advisories/unreviewed/2022/05/GHSA-57f7-3g6g-rwhr/GHSA-57f7-3g6g-rwhr.json index 953ce4b8e0f..c2a39219112 100644 --- a/advisories/unreviewed/2022/05/GHSA-57f7-3g6g-rwhr/GHSA-57f7-3g6g-rwhr.json +++ b/advisories/unreviewed/2022/05/GHSA-57f7-3g6g-rwhr/GHSA-57f7-3g6g-rwhr.json @@ -7,12 +7,8 @@ "CVE-2020-14592" ], "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57jh-54r4-h5x5/GHSA-57jh-54r4-h5x5.json b/advisories/unreviewed/2022/05/GHSA-57jh-54r4-h5x5/GHSA-57jh-54r4-h5x5.json index 72aaf44a735..91ac8ce874a 100644 --- a/advisories/unreviewed/2022/05/GHSA-57jh-54r4-h5x5/GHSA-57jh-54r4-h5x5.json +++ b/advisories/unreviewed/2022/05/GHSA-57jh-54r4-h5x5/GHSA-57jh-54r4-h5x5.json @@ -7,12 +7,8 @@ "CVE-2020-4464" ], "details": "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58gq-w922-g4r3/GHSA-58gq-w922-g4r3.json b/advisories/unreviewed/2022/05/GHSA-58gq-w922-g4r3/GHSA-58gq-w922-g4r3.json index b4fb4397682..2c1d819dda5 100644 --- a/advisories/unreviewed/2022/05/GHSA-58gq-w922-g4r3/GHSA-58gq-w922-g4r3.json +++ b/advisories/unreviewed/2022/05/GHSA-58gq-w922-g4r3/GHSA-58gq-w922-g4r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-596g-3hr3-g6jr/GHSA-596g-3hr3-g6jr.json b/advisories/unreviewed/2022/05/GHSA-596g-3hr3-g6jr/GHSA-596g-3hr3-g6jr.json index 9c87d6acc56..26aab7ab684 100644 --- a/advisories/unreviewed/2022/05/GHSA-596g-3hr3-g6jr/GHSA-596g-3hr3-g6jr.json +++ b/advisories/unreviewed/2022/05/GHSA-596g-3hr3-g6jr/GHSA-596g-3hr3-g6jr.json @@ -7,12 +7,8 @@ "CVE-2020-14645" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5975-gjm3-px87/GHSA-5975-gjm3-px87.json b/advisories/unreviewed/2022/05/GHSA-5975-gjm3-px87/GHSA-5975-gjm3-px87.json index 365f18ea50a..b8d58f257e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5975-gjm3-px87/GHSA-5975-gjm3-px87.json +++ b/advisories/unreviewed/2022/05/GHSA-5975-gjm3-px87/GHSA-5975-gjm3-px87.json @@ -7,12 +7,8 @@ "CVE-2020-3385" ], "details": "A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient handling of malformed packets. An attacker could exploit this vulnerability by sending crafted packets through an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59fx-725p-7v33/GHSA-59fx-725p-7v33.json b/advisories/unreviewed/2022/05/GHSA-59fx-725p-7v33/GHSA-59fx-725p-7v33.json index 2ee4bcdf304..93897a153ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-59fx-725p-7v33/GHSA-59fx-725p-7v33.json +++ b/advisories/unreviewed/2022/05/GHSA-59fx-725p-7v33/GHSA-59fx-725p-7v33.json @@ -7,12 +7,8 @@ "CVE-2020-11953" ], "details": "An issue was discovered on Rittal PDU-3C002DEC through 5.15.40 and CMCIII-PU-9333E0FB through 3.15.70_4 devices. Attackers can execute code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5chj-x66r-7pp7/GHSA-5chj-x66r-7pp7.json b/advisories/unreviewed/2022/05/GHSA-5chj-x66r-7pp7/GHSA-5chj-x66r-7pp7.json index 4b931a7872c..fb199879a5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5chj-x66r-7pp7/GHSA-5chj-x66r-7pp7.json +++ b/advisories/unreviewed/2022/05/GHSA-5chj-x66r-7pp7/GHSA-5chj-x66r-7pp7.json @@ -7,12 +7,8 @@ "CVE-2020-14698" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5mv6-488r-v66h/GHSA-5mv6-488r-v66h.json b/advisories/unreviewed/2022/05/GHSA-5mv6-488r-v66h/GHSA-5mv6-488r-v66h.json index e6e71f5591d..369bb6b7e3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mv6-488r-v66h/GHSA-5mv6-488r-v66h.json +++ b/advisories/unreviewed/2022/05/GHSA-5mv6-488r-v66h/GHSA-5mv6-488r-v66h.json @@ -7,12 +7,8 @@ "CVE-2020-1437" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Network Location Awareness Service handles objects in memory, aka 'Windows Network Location Awareness Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5p3f-pvrx-fr9p/GHSA-5p3f-pvrx-fr9p.json b/advisories/unreviewed/2022/05/GHSA-5p3f-pvrx-fr9p/GHSA-5p3f-pvrx-fr9p.json index 3e989a10af8..bc4b9a81cdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p3f-pvrx-fr9p/GHSA-5p3f-pvrx-fr9p.json +++ b/advisories/unreviewed/2022/05/GHSA-5p3f-pvrx-fr9p/GHSA-5p3f-pvrx-fr9p.json @@ -7,12 +7,8 @@ "CVE-2020-14528" ], "details": "Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as well as unauthorized read access to a subset of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pf2-53q8-pj6c/GHSA-5pf2-53q8-pj6c.json b/advisories/unreviewed/2022/05/GHSA-5pf2-53q8-pj6c/GHSA-5pf2-53q8-pj6c.json index 460f04327dd..6f08a4e8006 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pf2-53q8-pj6c/GHSA-5pf2-53q8-pj6c.json +++ b/advisories/unreviewed/2022/05/GHSA-5pf2-53q8-pj6c/GHSA-5pf2-53q8-pj6c.json @@ -7,12 +7,8 @@ "CVE-2020-14570" ], "details": "Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v5r-fxmr-wmpv/GHSA-5v5r-fxmr-wmpv.json b/advisories/unreviewed/2022/05/GHSA-5v5r-fxmr-wmpv/GHSA-5v5r-fxmr-wmpv.json index a0f63acd602..eb8be70badb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v5r-fxmr-wmpv/GHSA-5v5r-fxmr-wmpv.json +++ b/advisories/unreviewed/2022/05/GHSA-5v5r-fxmr-wmpv/GHSA-5v5r-fxmr-wmpv.json @@ -7,12 +7,8 @@ "CVE-2020-1454" ], "details": "This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vp4-9q2j-p8f9/GHSA-5vp4-9q2j-p8f9.json b/advisories/unreviewed/2022/05/GHSA-5vp4-9q2j-p8f9/GHSA-5vp4-9q2j-p8f9.json index f7d122eec54..53e87d173fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vp4-9q2j-p8f9/GHSA-5vp4-9q2j-p8f9.json +++ b/advisories/unreviewed/2022/05/GHSA-5vp4-9q2j-p8f9/GHSA-5vp4-9q2j-p8f9.json @@ -7,12 +7,8 @@ "CVE-2020-14529" ], "details": "Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Investor Module). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as well as unauthorized read access to a subset of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5w4q-5c4v-rhrm/GHSA-5w4q-5c4v-rhrm.json b/advisories/unreviewed/2022/05/GHSA-5w4q-5c4v-rhrm/GHSA-5w4q-5c4v-rhrm.json index bcd8ec9f65c..b71f7ef6286 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w4q-5c4v-rhrm/GHSA-5w4q-5c4v-rhrm.json +++ b/advisories/unreviewed/2022/05/GHSA-5w4q-5c4v-rhrm/GHSA-5w4q-5c4v-rhrm.json @@ -7,12 +7,8 @@ "CVE-2020-9297" ], "details": "Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error message template being passed to ConstraintValidatorContext.buildConstraintViolationWithTemplate() argument, they will be able to run arbitrary Java code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-636c-p97j-wvv8/GHSA-636c-p97j-wvv8.json b/advisories/unreviewed/2022/05/GHSA-636c-p97j-wvv8/GHSA-636c-p97j-wvv8.json index 9719a295070..df204696ab8 100644 --- a/advisories/unreviewed/2022/05/GHSA-636c-p97j-wvv8/GHSA-636c-p97j-wvv8.json +++ b/advisories/unreviewed/2022/05/GHSA-636c-p97j-wvv8/GHSA-636c-p97j-wvv8.json @@ -7,12 +7,8 @@ "CVE-2020-14551" ], "details": "Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Security). The supported version that is affected is 21.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle AutoVue. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle AutoVue accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-637w-622v-jh63/GHSA-637w-622v-jh63.json b/advisories/unreviewed/2022/05/GHSA-637w-622v-jh63/GHSA-637w-622v-jh63.json index 05a264f6be9..6105319a88e 100644 --- a/advisories/unreviewed/2022/05/GHSA-637w-622v-jh63/GHSA-637w-622v-jh63.json +++ b/advisories/unreviewed/2022/05/GHSA-637w-622v-jh63/GHSA-637w-622v-jh63.json @@ -7,12 +7,8 @@ "CVE-2020-14537" ], "details": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Packaging Scripts). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63gg-x38q-g49x/GHSA-63gg-x38q-g49x.json b/advisories/unreviewed/2022/05/GHSA-63gg-x38q-g49x/GHSA-63gg-x38q-g49x.json index cd9b4b63bf4..be845dfed1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-63gg-x38q-g49x/GHSA-63gg-x38q-g49x.json +++ b/advisories/unreviewed/2022/05/GHSA-63gg-x38q-g49x/GHSA-63gg-x38q-g49x.json @@ -7,12 +7,8 @@ "CVE-2020-14657" ], "details": "Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-64fg-mcxw-p5ww/GHSA-64fg-mcxw-p5ww.json b/advisories/unreviewed/2022/05/GHSA-64fg-mcxw-p5ww/GHSA-64fg-mcxw-p5ww.json index 9394bc43c41..2e4c1c64d04 100644 --- a/advisories/unreviewed/2022/05/GHSA-64fg-mcxw-p5ww/GHSA-64fg-mcxw-p5ww.json +++ b/advisories/unreviewed/2022/05/GHSA-64fg-mcxw-p5ww/GHSA-64fg-mcxw-p5ww.json @@ -7,12 +7,8 @@ "CVE-2019-20913" ], "details": "An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-66f6-j4qh-gpfh/GHSA-66f6-j4qh-gpfh.json b/advisories/unreviewed/2022/05/GHSA-66f6-j4qh-gpfh/GHSA-66f6-j4qh-gpfh.json index d7629225800..ed752af851b 100644 --- a/advisories/unreviewed/2022/05/GHSA-66f6-j4qh-gpfh/GHSA-66f6-j4qh-gpfh.json +++ b/advisories/unreviewed/2022/05/GHSA-66f6-j4qh-gpfh/GHSA-66f6-j4qh-gpfh.json @@ -7,12 +7,8 @@ "CVE-2020-9258" ], "details": "HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerability. An attribution in a module is not set correctly and some verification is lacked. Attackers with local access can exploit this vulnerability by injecting malicious fragment. This may lead to user information leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-676j-vqr4-6w3h/GHSA-676j-vqr4-6w3h.json b/advisories/unreviewed/2022/05/GHSA-676j-vqr4-6w3h/GHSA-676j-vqr4-6w3h.json index c867df93450..0151350a8f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-676j-vqr4-6w3h/GHSA-676j-vqr4-6w3h.json +++ b/advisories/unreviewed/2022/05/GHSA-676j-vqr4-6w3h/GHSA-676j-vqr4-6w3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67rg-fq6q-r5cf/GHSA-67rg-fq6q-r5cf.json b/advisories/unreviewed/2022/05/GHSA-67rg-fq6q-r5cf/GHSA-67rg-fq6q-r5cf.json index 5d709a5d1f7..b603ac80d36 100644 --- a/advisories/unreviewed/2022/05/GHSA-67rg-fq6q-r5cf/GHSA-67rg-fq6q-r5cf.json +++ b/advisories/unreviewed/2022/05/GHSA-67rg-fq6q-r5cf/GHSA-67rg-fq6q-r5cf.json @@ -7,12 +7,8 @@ "CVE-2020-10044" ], "details": "A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the network could be able to install specially crafted firmware to the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-689r-q44r-f9rq/GHSA-689r-q44r-f9rq.json b/advisories/unreviewed/2022/05/GHSA-689r-q44r-f9rq/GHSA-689r-q44r-f9rq.json index 7bb154f0c1b..ca842f4b3eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-689r-q44r-f9rq/GHSA-689r-q44r-f9rq.json +++ b/advisories/unreviewed/2022/05/GHSA-689r-q44r-f9rq/GHSA-689r-q44r-f9rq.json @@ -7,12 +7,8 @@ "CVE-2020-14694" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68gc-2m5p-7376/GHSA-68gc-2m5p-7376.json b/advisories/unreviewed/2022/05/GHSA-68gc-2m5p-7376/GHSA-68gc-2m5p-7376.json index 6d17f643bbb..5c764aeabd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-68gc-2m5p-7376/GHSA-68gc-2m5p-7376.json +++ b/advisories/unreviewed/2022/05/GHSA-68gc-2m5p-7376/GHSA-68gc-2m5p-7376.json @@ -7,12 +7,8 @@ "CVE-2020-1418" ], "details": "An elevation of privilege vulnerability exists when the Windows Diagnostics Execution Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1393.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68x7-9v8m-4jrv/GHSA-68x7-9v8m-4jrv.json b/advisories/unreviewed/2022/05/GHSA-68x7-9v8m-4jrv/GHSA-68x7-9v8m-4jrv.json index 4d8c8b412fd..5b4ac05bf02 100644 --- a/advisories/unreviewed/2022/05/GHSA-68x7-9v8m-4jrv/GHSA-68x7-9v8m-4jrv.json +++ b/advisories/unreviewed/2022/05/GHSA-68x7-9v8m-4jrv/GHSA-68x7-9v8m-4jrv.json @@ -7,12 +7,8 @@ "CVE-2020-1364" ], "details": "A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6925-92m9-84w6/GHSA-6925-92m9-84w6.json b/advisories/unreviewed/2022/05/GHSA-6925-92m9-84w6/GHSA-6925-92m9-84w6.json index dbadfe166c1..46b7395e3a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6925-92m9-84w6/GHSA-6925-92m9-84w6.json +++ b/advisories/unreviewed/2022/05/GHSA-6925-92m9-84w6/GHSA-6925-92m9-84w6.json @@ -7,12 +7,8 @@ "CVE-2020-3330" ], "details": "A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unauthenticated, remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. An attacker could exploit this vulnerability by using this default account to connect to the affected system. A successful exploit could allow the attacker to gain full control of an affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6929-p5cx-qmg5/GHSA-6929-p5cx-qmg5.json b/advisories/unreviewed/2022/05/GHSA-6929-p5cx-qmg5/GHSA-6929-p5cx-qmg5.json index c9f0f16faa6..8bc9358664b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6929-p5cx-qmg5/GHSA-6929-p5cx-qmg5.json +++ b/advisories/unreviewed/2022/05/GHSA-6929-p5cx-qmg5/GHSA-6929-p5cx-qmg5.json @@ -7,12 +7,8 @@ "CVE-2020-5374" ], "details": "Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic key vulnerability. A remote unauthenticated attacker may exploit this vulnerability to gain access to the appliance data for remotely managed devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-698p-4j7j-49fx/GHSA-698p-4j7j-49fx.json b/advisories/unreviewed/2022/05/GHSA-698p-4j7j-49fx/GHSA-698p-4j7j-49fx.json index 2ddf6f03f3c..02e770a0ac3 100644 --- a/advisories/unreviewed/2022/05/GHSA-698p-4j7j-49fx/GHSA-698p-4j7j-49fx.json +++ b/advisories/unreviewed/2022/05/GHSA-698p-4j7j-49fx/GHSA-698p-4j7j-49fx.json @@ -7,12 +7,8 @@ "CVE-2020-14724" ], "details": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c2p-9hhc-8hc8/GHSA-6c2p-9hhc-8hc8.json b/advisories/unreviewed/2022/05/GHSA-6c2p-9hhc-8hc8/GHSA-6c2p-9hhc-8hc8.json index d0e01498ab3..51f96c51805 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c2p-9hhc-8hc8/GHSA-6c2p-9hhc-8hc8.json +++ b/advisories/unreviewed/2022/05/GHSA-6c2p-9hhc-8hc8/GHSA-6c2p-9hhc-8hc8.json @@ -7,12 +7,8 @@ "CVE-2020-1442" ], "details": "A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gmh-pw6w-cww4/GHSA-6gmh-pw6w-cww4.json b/advisories/unreviewed/2022/05/GHSA-6gmh-pw6w-cww4/GHSA-6gmh-pw6w-cww4.json index 409b1cc202e..6aa6315e26e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gmh-pw6w-cww4/GHSA-6gmh-pw6w-cww4.json +++ b/advisories/unreviewed/2022/05/GHSA-6gmh-pw6w-cww4/GHSA-6gmh-pw6w-cww4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6h5p-h3h7-6vpp/GHSA-6h5p-h3h7-6vpp.json b/advisories/unreviewed/2022/05/GHSA-6h5p-h3h7-6vpp/GHSA-6h5p-h3h7-6vpp.json index 7361c52964c..afaa3122f33 100644 --- a/advisories/unreviewed/2022/05/GHSA-6h5p-h3h7-6vpp/GHSA-6h5p-h3h7-6vpp.json +++ b/advisories/unreviewed/2022/05/GHSA-6h5p-h3h7-6vpp/GHSA-6h5p-h3h7-6vpp.json @@ -7,12 +7,8 @@ "CVE-2020-14605" ], "details": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hf9-2c4c-m4j4/GHSA-6hf9-2c4c-m4j4.json b/advisories/unreviewed/2022/05/GHSA-6hf9-2c4c-m4j4/GHSA-6hf9-2c4c-m4j4.json index d3a160cb793..5df4461c4cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hf9-2c4c-m4j4/GHSA-6hf9-2c4c-m4j4.json +++ b/advisories/unreviewed/2022/05/GHSA-6hf9-2c4c-m4j4/GHSA-6hf9-2c4c-m4j4.json @@ -7,12 +7,8 @@ "CVE-2020-14561" ], "details": "Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Installation). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j42-h33x-2c8v/GHSA-6j42-h33x-2c8v.json b/advisories/unreviewed/2022/05/GHSA-6j42-h33x-2c8v/GHSA-6j42-h33x-2c8v.json index e2ecac841f7..43513bbced0 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j42-h33x-2c8v/GHSA-6j42-h33x-2c8v.json +++ b/advisories/unreviewed/2022/05/GHSA-6j42-h33x-2c8v/GHSA-6j42-h33x-2c8v.json @@ -7,12 +7,8 @@ "CVE-2020-14565" ], "details": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Unified Directory. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j89-cjff-693q/GHSA-6j89-cjff-693q.json b/advisories/unreviewed/2022/05/GHSA-6j89-cjff-693q/GHSA-6j89-cjff-693q.json index b364ad65cf1..9dab644f2c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j89-cjff-693q/GHSA-6j89-cjff-693q.json +++ b/advisories/unreviewed/2022/05/GHSA-6j89-cjff-693q/GHSA-6j89-cjff-693q.json @@ -7,12 +7,8 @@ "CVE-2020-3351" ], "details": "A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of fields in Cisco SD-WAN peering messages that are encapsulated in UDP packets. An attacker could exploit this vulnerability by sending crafted UDP messages to the targeted system. A successful exploit could allow the attacker to cause services on the device to fail, resulting in a DoS condition that could impact the targeted device and other devices that depend on it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6j9g-q4qp-mq4x/GHSA-6j9g-q4qp-mq4x.json b/advisories/unreviewed/2022/05/GHSA-6j9g-q4qp-mq4x/GHSA-6j9g-q4qp-mq4x.json index 81196975f13..c00150e9d3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j9g-q4qp-mq4x/GHSA-6j9g-q4qp-mq4x.json +++ b/advisories/unreviewed/2022/05/GHSA-6j9g-q4qp-mq4x/GHSA-6j9g-q4qp-mq4x.json @@ -7,12 +7,8 @@ "CVE-2020-13923" ], "details": "IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jw7-r2qx-ffpf/GHSA-6jw7-r2qx-ffpf.json b/advisories/unreviewed/2022/05/GHSA-6jw7-r2qx-ffpf/GHSA-6jw7-r2qx-ffpf.json index c3b0631cd80..c6a3d6358c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jw7-r2qx-ffpf/GHSA-6jw7-r2qx-ffpf.json +++ b/advisories/unreviewed/2022/05/GHSA-6jw7-r2qx-ffpf/GHSA-6jw7-r2qx-ffpf.json @@ -7,12 +7,8 @@ "CVE-2020-1043" ], "details": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mjj-xrpg-96vg/GHSA-6mjj-xrpg-96vg.json b/advisories/unreviewed/2022/05/GHSA-6mjj-xrpg-96vg/GHSA-6mjj-xrpg-96vg.json index 7147db62eb5..a8af12462c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mjj-xrpg-96vg/GHSA-6mjj-xrpg-96vg.json +++ b/advisories/unreviewed/2022/05/GHSA-6mjj-xrpg-96vg/GHSA-6mjj-xrpg-96vg.json @@ -7,12 +7,8 @@ "CVE-2020-14571" ], "details": "Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data as well as unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6p27-p48f-vh67/GHSA-6p27-p48f-vh67.json b/advisories/unreviewed/2022/05/GHSA-6p27-p48f-vh67/GHSA-6p27-p48f-vh67.json index 96b327d1c90..27f4b371f3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p27-p48f-vh67/GHSA-6p27-p48f-vh67.json +++ b/advisories/unreviewed/2022/05/GHSA-6p27-p48f-vh67/GHSA-6p27-p48f-vh67.json @@ -7,12 +7,8 @@ "CVE-2020-12027" ], "details": "All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pc5-ccr3-mpqp/GHSA-6pc5-ccr3-mpqp.json b/advisories/unreviewed/2022/05/GHSA-6pc5-ccr3-mpqp/GHSA-6pc5-ccr3-mpqp.json index d778b3ed14c..0e71450283e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pc5-ccr3-mpqp/GHSA-6pc5-ccr3-mpqp.json +++ b/advisories/unreviewed/2022/05/GHSA-6pc5-ccr3-mpqp/GHSA-6pc5-ccr3-mpqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6pv9-5752-c3xg/GHSA-6pv9-5752-c3xg.json b/advisories/unreviewed/2022/05/GHSA-6pv9-5752-c3xg/GHSA-6pv9-5752-c3xg.json index aba02373cbf..6a200143448 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pv9-5752-c3xg/GHSA-6pv9-5752-c3xg.json +++ b/advisories/unreviewed/2022/05/GHSA-6pv9-5752-c3xg/GHSA-6pv9-5752-c3xg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wrp-x54h-p8g6/GHSA-6wrp-x54h-p8g6.json b/advisories/unreviewed/2022/05/GHSA-6wrp-x54h-p8g6/GHSA-6wrp-x54h-p8g6.json index 8dba4be83a0..ddf383bd54d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wrp-x54h-p8g6/GHSA-6wrp-x54h-p8g6.json +++ b/advisories/unreviewed/2022/05/GHSA-6wrp-x54h-p8g6/GHSA-6wrp-x54h-p8g6.json @@ -7,12 +7,8 @@ "CVE-2020-14648" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6wx3-3pp4-7q95/GHSA-6wx3-3pp4-7q95.json b/advisories/unreviewed/2022/05/GHSA-6wx3-3pp4-7q95/GHSA-6wx3-3pp4-7q95.json index aebd67621d4..fe84af67791 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wx3-3pp4-7q95/GHSA-6wx3-3pp4-7q95.json +++ b/advisories/unreviewed/2022/05/GHSA-6wx3-3pp4-7q95/GHSA-6wx3-3pp4-7q95.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x26-67wc-v4f7/GHSA-6x26-67wc-v4f7.json b/advisories/unreviewed/2022/05/GHSA-6x26-67wc-v4f7/GHSA-6x26-67wc-v4f7.json index 2e6b6af72a5..aa27de5e0fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x26-67wc-v4f7/GHSA-6x26-67wc-v4f7.json +++ b/advisories/unreviewed/2022/05/GHSA-6x26-67wc-v4f7/GHSA-6x26-67wc-v4f7.json @@ -7,12 +7,8 @@ "CVE-2020-14684" ], "details": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x62-3gfm-2xvv/GHSA-6x62-3gfm-2xvv.json b/advisories/unreviewed/2022/05/GHSA-6x62-3gfm-2xvv/GHSA-6x62-3gfm-2xvv.json index a683256d916..6b48dc21d95 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x62-3gfm-2xvv/GHSA-6x62-3gfm-2xvv.json +++ b/advisories/unreviewed/2022/05/GHSA-6x62-3gfm-2xvv/GHSA-6x62-3gfm-2xvv.json @@ -7,12 +7,8 @@ "CVE-2020-1369" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1344, CVE-2020-1362.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72g9-2j95-6787/GHSA-72g9-2j95-6787.json b/advisories/unreviewed/2022/05/GHSA-72g9-2j95-6787/GHSA-72g9-2j95-6787.json index 5eb68eb7271..3565cd851dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-72g9-2j95-6787/GHSA-72g9-2j95-6787.json +++ b/advisories/unreviewed/2022/05/GHSA-72g9-2j95-6787/GHSA-72g9-2j95-6787.json @@ -7,12 +7,8 @@ "CVE-2020-1426" ], "details": "An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1419.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72mg-2w2h-2qqq/GHSA-72mg-2w2h-2qqq.json b/advisories/unreviewed/2022/05/GHSA-72mg-2w2h-2qqq/GHSA-72mg-2w2h-2qqq.json index 14430d59f10..0eaf79c7186 100644 --- a/advisories/unreviewed/2022/05/GHSA-72mg-2w2h-2qqq/GHSA-72mg-2w2h-2qqq.json +++ b/advisories/unreviewed/2022/05/GHSA-72mg-2w2h-2qqq/GHSA-72mg-2w2h-2qqq.json @@ -7,12 +7,8 @@ "CVE-2020-1430" ], "details": "An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1354.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-739r-mw5v-58r2/GHSA-739r-mw5v-58r2.json b/advisories/unreviewed/2022/05/GHSA-739r-mw5v-58r2/GHSA-739r-mw5v-58r2.json index 2ee415bb597..60a3df6cc81 100644 --- a/advisories/unreviewed/2022/05/GHSA-739r-mw5v-58r2/GHSA-739r-mw5v-58r2.json +++ b/advisories/unreviewed/2022/05/GHSA-739r-mw5v-58r2/GHSA-739r-mw5v-58r2.json @@ -7,12 +7,8 @@ "CVE-2020-14711" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: The CVE-2020-14711 is applicable to macOS host only. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73g2-m4v3-6c2h/GHSA-73g2-m4v3-6c2h.json b/advisories/unreviewed/2022/05/GHSA-73g2-m4v3-6c2h/GHSA-73g2-m4v3-6c2h.json index eb0bab676b3..34c1e1e9153 100644 --- a/advisories/unreviewed/2022/05/GHSA-73g2-m4v3-6c2h/GHSA-73g2-m4v3-6c2h.json +++ b/advisories/unreviewed/2022/05/GHSA-73g2-m4v3-6c2h/GHSA-73g2-m4v3-6c2h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75j8-p3jh-jwj6/GHSA-75j8-p3jh-jwj6.json b/advisories/unreviewed/2022/05/GHSA-75j8-p3jh-jwj6/GHSA-75j8-p3jh-jwj6.json index e458b43db5a..d985065d3cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-75j8-p3jh-jwj6/GHSA-75j8-p3jh-jwj6.json +++ b/advisories/unreviewed/2022/05/GHSA-75j8-p3jh-jwj6/GHSA-75j8-p3jh-jwj6.json @@ -7,12 +7,8 @@ "CVE-2020-14671" ], "details": "Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-773f-f929-qgjj/GHSA-773f-f929-qgjj.json b/advisories/unreviewed/2022/05/GHSA-773f-f929-qgjj/GHSA-773f-f929-qgjj.json index 0454941e22f..f8d34606886 100644 --- a/advisories/unreviewed/2022/05/GHSA-773f-f929-qgjj/GHSA-773f-f929-qgjj.json +++ b/advisories/unreviewed/2022/05/GHSA-773f-f929-qgjj/GHSA-773f-f929-qgjj.json @@ -7,12 +7,8 @@ "CVE-2020-15841" ], "details": "Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-775r-4pcv-6q97/GHSA-775r-4pcv-6q97.json b/advisories/unreviewed/2022/05/GHSA-775r-4pcv-6q97/GHSA-775r-4pcv-6q97.json index 572bd00dd3c..ba43ab2bf5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-775r-4pcv-6q97/GHSA-775r-4pcv-6q97.json +++ b/advisories/unreviewed/2022/05/GHSA-775r-4pcv-6q97/GHSA-775r-4pcv-6q97.json @@ -7,12 +7,8 @@ "CVE-2020-1432" ], "details": "An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7822-rrh7-pwm7/GHSA-7822-rrh7-pwm7.json b/advisories/unreviewed/2022/05/GHSA-7822-rrh7-pwm7/GHSA-7822-rrh7-pwm7.json index 0ba3e9f9ea9..e1d0e8d15b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-7822-rrh7-pwm7/GHSA-7822-rrh7-pwm7.json +++ b/advisories/unreviewed/2022/05/GHSA-7822-rrh7-pwm7/GHSA-7822-rrh7-pwm7.json @@ -7,12 +7,8 @@ "CVE-2020-14669" ], "details": "Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: UI Servlet). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Configurator, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data as well as unauthorized update, insert or delete access to some of Oracle Configurator accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7855-9v87-wfg5/GHSA-7855-9v87-wfg5.json b/advisories/unreviewed/2022/05/GHSA-7855-9v87-wfg5/GHSA-7855-9v87-wfg5.json index 0a7d8c6fa74..aae746bc961 100644 --- a/advisories/unreviewed/2022/05/GHSA-7855-9v87-wfg5/GHSA-7855-9v87-wfg5.json +++ b/advisories/unreviewed/2022/05/GHSA-7855-9v87-wfg5/GHSA-7855-9v87-wfg5.json @@ -7,12 +7,8 @@ "CVE-2020-14611" ], "details": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized read access to a subset of Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-789c-r6w2-66gw/GHSA-789c-r6w2-66gw.json b/advisories/unreviewed/2022/05/GHSA-789c-r6w2-66gw/GHSA-789c-r6w2-66gw.json index 185832b6c01..cc3b8816ecc 100644 --- a/advisories/unreviewed/2022/05/GHSA-789c-r6w2-66gw/GHSA-789c-r6w2-66gw.json +++ b/advisories/unreviewed/2022/05/GHSA-789c-r6w2-66gw/GHSA-789c-r6w2-66gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79wh-vc9g-6xpc/GHSA-79wh-vc9g-6xpc.json b/advisories/unreviewed/2022/05/GHSA-79wh-vc9g-6xpc/GHSA-79wh-vc9g-6xpc.json index 47d16fc68f2..84607b7c6f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-79wh-vc9g-6xpc/GHSA-79wh-vc9g-6xpc.json +++ b/advisories/unreviewed/2022/05/GHSA-79wh-vc9g-6xpc/GHSA-79wh-vc9g-6xpc.json @@ -7,12 +7,8 @@ "CVE-2019-20911" ], "details": "An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7c76-fmgr-wqq7/GHSA-7c76-fmgr-wqq7.json b/advisories/unreviewed/2022/05/GHSA-7c76-fmgr-wqq7/GHSA-7c76-fmgr-wqq7.json index 589f453bfcd..0dbb30f3d14 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c76-fmgr-wqq7/GHSA-7c76-fmgr-wqq7.json +++ b/advisories/unreviewed/2022/05/GHSA-7c76-fmgr-wqq7/GHSA-7c76-fmgr-wqq7.json @@ -7,12 +7,8 @@ "CVE-2020-14548" ], "details": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 3.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f3r-v9w2-q5pm/GHSA-7f3r-v9w2-q5pm.json b/advisories/unreviewed/2022/05/GHSA-7f3r-v9w2-q5pm/GHSA-7f3r-v9w2-q5pm.json index 2757d0716ee..b6cbf9a2d7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f3r-v9w2-q5pm/GHSA-7f3r-v9w2-q5pm.json +++ b/advisories/unreviewed/2022/05/GHSA-7f3r-v9w2-q5pm/GHSA-7f3r-v9w2-q5pm.json @@ -7,12 +7,8 @@ "CVE-2020-14700" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fmj-8v6q-jrwf/GHSA-7fmj-8v6q-jrwf.json b/advisories/unreviewed/2022/05/GHSA-7fmj-8v6q-jrwf/GHSA-7fmj-8v6q-jrwf.json index 04b08df8319..9858ced1ba4 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fmj-8v6q-jrwf/GHSA-7fmj-8v6q-jrwf.json +++ b/advisories/unreviewed/2022/05/GHSA-7fmj-8v6q-jrwf/GHSA-7fmj-8v6q-jrwf.json @@ -7,12 +7,8 @@ "CVE-2020-15603" ], "details": "An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a system call operation with an invalid address, resulting in a potential system crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fxc-wh73-vhv8/GHSA-7fxc-wh73-vhv8.json b/advisories/unreviewed/2022/05/GHSA-7fxc-wh73-vhv8/GHSA-7fxc-wh73-vhv8.json index 8931f8b923d..e7b34df8140 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fxc-wh73-vhv8/GHSA-7fxc-wh73-vhv8.json +++ b/advisories/unreviewed/2022/05/GHSA-7fxc-wh73-vhv8/GHSA-7fxc-wh73-vhv8.json @@ -7,12 +7,8 @@ "CVE-2020-1427" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1373, CVE-2020-1390, CVE-2020-1428, CVE-2020-1438.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gxm-25cp-2h59/GHSA-7gxm-25cp-2h59.json b/advisories/unreviewed/2022/05/GHSA-7gxm-25cp-2h59/GHSA-7gxm-25cp-2h59.json index e53a1dfc86e..07ff1b38d2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gxm-25cp-2h59/GHSA-7gxm-25cp-2h59.json +++ b/advisories/unreviewed/2022/05/GHSA-7gxm-25cp-2h59/GHSA-7gxm-25cp-2h59.json @@ -7,12 +7,8 @@ "CVE-2020-9688" ], "details": "Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hcv-63gc-jpmm/GHSA-7hcv-63gc-jpmm.json b/advisories/unreviewed/2022/05/GHSA-7hcv-63gc-jpmm/GHSA-7hcv-63gc-jpmm.json index 22b6ea7e219..36e37f55caa 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hcv-63gc-jpmm/GHSA-7hcv-63gc-jpmm.json +++ b/advisories/unreviewed/2022/05/GHSA-7hcv-63gc-jpmm/GHSA-7hcv-63gc-jpmm.json @@ -7,12 +7,8 @@ "CVE-2020-14659" ], "details": "Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7hpv-rcx2-vjx9/GHSA-7hpv-rcx2-vjx9.json b/advisories/unreviewed/2022/05/GHSA-7hpv-rcx2-vjx9/GHSA-7hpv-rcx2-vjx9.json index f018f6c642f..01bc802c5f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hpv-rcx2-vjx9/GHSA-7hpv-rcx2-vjx9.json +++ b/advisories/unreviewed/2022/05/GHSA-7hpv-rcx2-vjx9/GHSA-7hpv-rcx2-vjx9.json @@ -7,12 +7,8 @@ "CVE-2020-4316" ], "details": "IBM Publishing Engine 6.0.6, 6.0.6.1, and 7.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 177354.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7j2j-qc6h-m8h2/GHSA-7j2j-qc6h-m8h2.json b/advisories/unreviewed/2022/05/GHSA-7j2j-qc6h-m8h2/GHSA-7j2j-qc6h-m8h2.json index a204c02b0d0..f6a2a96a016 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j2j-qc6h-m8h2/GHSA-7j2j-qc6h-m8h2.json +++ b/advisories/unreviewed/2022/05/GHSA-7j2j-qc6h-m8h2/GHSA-7j2j-qc6h-m8h2.json @@ -7,12 +7,8 @@ "CVE-2020-14682" ], "details": "Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Depot Repair, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data as well as unauthorized update, insert or delete access to some of Oracle Depot Repair accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7mxf-255f-8cvv/GHSA-7mxf-255f-8cvv.json b/advisories/unreviewed/2022/05/GHSA-7mxf-255f-8cvv/GHSA-7mxf-255f-8cvv.json index f5c45aec596..48eb6632ec5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mxf-255f-8cvv/GHSA-7mxf-255f-8cvv.json +++ b/advisories/unreviewed/2022/05/GHSA-7mxf-255f-8cvv/GHSA-7mxf-255f-8cvv.json @@ -7,12 +7,8 @@ "CVE-2020-1435" ], "details": "A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7prc-v6jr-7frc/GHSA-7prc-v6jr-7frc.json b/advisories/unreviewed/2022/05/GHSA-7prc-v6jr-7frc/GHSA-7prc-v6jr-7frc.json index 8db48ac372a..3bd7b631b1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7prc-v6jr-7frc/GHSA-7prc-v6jr-7frc.json +++ b/advisories/unreviewed/2022/05/GHSA-7prc-v6jr-7frc/GHSA-7prc-v6jr-7frc.json @@ -7,12 +7,8 @@ "CVE-2020-14717" ], "details": "Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Common Applications accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7prw-wc7c-g95v/GHSA-7prw-wc7c-g95v.json b/advisories/unreviewed/2022/05/GHSA-7prw-wc7c-g95v/GHSA-7prw-wc7c-g95v.json index dc80d39e098..37b377a471b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7prw-wc7c-g95v/GHSA-7prw-wc7c-g95v.json +++ b/advisories/unreviewed/2022/05/GHSA-7prw-wc7c-g95v/GHSA-7prw-wc7c-g95v.json @@ -7,12 +7,8 @@ "CVE-2020-3331" ], "details": "A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input data by the web-based management interface. An attacker could exploit this vulnerability by sending crafted requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rj2-cq4p-3wqr/GHSA-7rj2-cq4p-3wqr.json b/advisories/unreviewed/2022/05/GHSA-7rj2-cq4p-3wqr/GHSA-7rj2-cq4p-3wqr.json index 6a581184b51..680a8ef8a02 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rj2-cq4p-3wqr/GHSA-7rj2-cq4p-3wqr.json +++ b/advisories/unreviewed/2022/05/GHSA-7rj2-cq4p-3wqr/GHSA-7rj2-cq4p-3wqr.json @@ -7,12 +7,8 @@ "CVE-2020-1372" ], "details": "An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles objects in memory, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1405.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rxf-2gc2-527c/GHSA-7rxf-2gc2-527c.json b/advisories/unreviewed/2022/05/GHSA-7rxf-2gc2-527c/GHSA-7rxf-2gc2-527c.json index 2486af5f887..72239df1cb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rxf-2gc2-527c/GHSA-7rxf-2gc2-527c.json +++ b/advisories/unreviewed/2022/05/GHSA-7rxf-2gc2-527c/GHSA-7rxf-2gc2-527c.json @@ -7,12 +7,8 @@ "CVE-2020-3379" ], "details": "A vulnerability in Cisco SD-WAN Solution Software could allow an authenticated, local attacker to elevate privileges to Administrator on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain administrative privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vrg-q6mv-3q9x/GHSA-7vrg-q6mv-3q9x.json b/advisories/unreviewed/2022/05/GHSA-7vrg-q6mv-3q9x/GHSA-7vrg-q6mv-3q9x.json index 44cb7c3441b..1675e56a8a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vrg-q6mv-3q9x/GHSA-7vrg-q6mv-3q9x.json +++ b/advisories/unreviewed/2022/05/GHSA-7vrg-q6mv-3q9x/GHSA-7vrg-q6mv-3q9x.json @@ -7,12 +7,8 @@ "CVE-2020-1439" ], "details": "A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7wcr-m98q-w3q3/GHSA-7wcr-m98q-w3q3.json b/advisories/unreviewed/2022/05/GHSA-7wcr-m98q-w3q3/GHSA-7wcr-m98q-w3q3.json index 8a819a11a81..468db6e12c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wcr-m98q-w3q3/GHSA-7wcr-m98q-w3q3.json +++ b/advisories/unreviewed/2022/05/GHSA-7wcr-m98q-w3q3/GHSA-7wcr-m98q-w3q3.json @@ -7,12 +7,8 @@ "CVE-2020-1386" ], "details": "An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connected User Experiences and Telemetry Service Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7x97-rv2f-vj3r/GHSA-7x97-rv2f-vj3r.json b/advisories/unreviewed/2022/05/GHSA-7x97-rv2f-vj3r/GHSA-7x97-rv2f-vj3r.json index aef71ba51dc..c592beb0fef 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x97-rv2f-vj3r/GHSA-7x97-rv2f-vj3r.json +++ b/advisories/unreviewed/2022/05/GHSA-7x97-rv2f-vj3r/GHSA-7x97-rv2f-vj3r.json @@ -7,12 +7,8 @@ "CVE-2020-1404" ], "details": "An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82f7-mq8m-2w9x/GHSA-82f7-mq8m-2w9x.json b/advisories/unreviewed/2022/05/GHSA-82f7-mq8m-2w9x/GHSA-82f7-mq8m-2w9x.json index b030f69bc2d..dee18ebf1c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-82f7-mq8m-2w9x/GHSA-82f7-mq8m-2w9x.json +++ b/advisories/unreviewed/2022/05/GHSA-82f7-mq8m-2w9x/GHSA-82f7-mq8m-2w9x.json @@ -7,12 +7,8 @@ "CVE-2020-15896" ], "details": "An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessible by any unauthorized user, e.g., logout.php and login.php. This occurs because of checking the value of NO_NEED_AUTH. If the value of NO_NEED_AUTH is 1, the user has direct access to the webpage without any authentication. By appending a query string NO_NEED_AUTH with the value of 1 to any protected URL, any unauthorized user can access the application directly, as demonstrated by bsc_lan.php?NO_NEED_AUTH=1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82jm-c3f2-7937/GHSA-82jm-c3f2-7937.json b/advisories/unreviewed/2022/05/GHSA-82jm-c3f2-7937/GHSA-82jm-c3f2-7937.json index 8e319c29855..051e823a69f 100644 --- a/advisories/unreviewed/2022/05/GHSA-82jm-c3f2-7937/GHSA-82jm-c3f2-7937.json +++ b/advisories/unreviewed/2022/05/GHSA-82jm-c3f2-7937/GHSA-82jm-c3f2-7937.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83v9-v5rx-wg6x/GHSA-83v9-v5rx-wg6x.json b/advisories/unreviewed/2022/05/GHSA-83v9-v5rx-wg6x/GHSA-83v9-v5rx-wg6x.json index 62a92ff0c22..bd092350c15 100644 --- a/advisories/unreviewed/2022/05/GHSA-83v9-v5rx-wg6x/GHSA-83v9-v5rx-wg6x.json +++ b/advisories/unreviewed/2022/05/GHSA-83v9-v5rx-wg6x/GHSA-83v9-v5rx-wg6x.json @@ -7,12 +7,8 @@ "CVE-2020-10605" ], "details": "Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-849p-5hj4-w47q/GHSA-849p-5hj4-w47q.json b/advisories/unreviewed/2022/05/GHSA-849p-5hj4-w47q/GHSA-849p-5hj4-w47q.json index 0f418f40fe6..4db205124db 100644 --- a/advisories/unreviewed/2022/05/GHSA-849p-5hj4-w47q/GHSA-849p-5hj4-w47q.json +++ b/advisories/unreviewed/2022/05/GHSA-849p-5hj4-w47q/GHSA-849p-5hj4-w47q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84j4-ccmw-hwpg/GHSA-84j4-ccmw-hwpg.json b/advisories/unreviewed/2022/05/GHSA-84j4-ccmw-hwpg/GHSA-84j4-ccmw-hwpg.json index 812f6b3ee46..b34ec344124 100644 --- a/advisories/unreviewed/2022/05/GHSA-84j4-ccmw-hwpg/GHSA-84j4-ccmw-hwpg.json +++ b/advisories/unreviewed/2022/05/GHSA-84j4-ccmw-hwpg/GHSA-84j4-ccmw-hwpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85jc-qvvj-q8jw/GHSA-85jc-qvvj-q8jw.json b/advisories/unreviewed/2022/05/GHSA-85jc-qvvj-q8jw/GHSA-85jc-qvvj-q8jw.json index 1b16585f8d0..6cfa05f91f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-85jc-qvvj-q8jw/GHSA-85jc-qvvj-q8jw.json +++ b/advisories/unreviewed/2022/05/GHSA-85jc-qvvj-q8jw/GHSA-85jc-qvvj-q8jw.json @@ -7,12 +7,8 @@ "CVE-2020-1373" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1390, CVE-2020-1427, CVE-2020-1428, CVE-2020-1438.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-875h-7jq2-c5fp/GHSA-875h-7jq2-c5fp.json b/advisories/unreviewed/2022/05/GHSA-875h-7jq2-c5fp/GHSA-875h-7jq2-c5fp.json index 85abc7aea36..7d85704f4f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-875h-7jq2-c5fp/GHSA-875h-7jq2-c5fp.json +++ b/advisories/unreviewed/2022/05/GHSA-875h-7jq2-c5fp/GHSA-875h-7jq2-c5fp.json @@ -7,12 +7,8 @@ "CVE-2020-3140" ], "details": "A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of user input on the web management interface. An attacker could exploit this vulnerability by submitting a malicious request to an affected system. An exploit could allow the attacker to gain administrative-level privileges on the system. The attacker needs a valid username to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8848-7789-w387/GHSA-8848-7789-w387.json b/advisories/unreviewed/2022/05/GHSA-8848-7789-w387/GHSA-8848-7789-w387.json index c469b7c3122..3f92c29854e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8848-7789-w387/GHSA-8848-7789-w387.json +++ b/advisories/unreviewed/2022/05/GHSA-8848-7789-w387/GHSA-8848-7789-w387.json @@ -7,12 +7,8 @@ "CVE-2020-6871" ], "details": "The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the authentication of the server and execute some commands for high-level users. This affects: ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88gc-h5ch-vcch/GHSA-88gc-h5ch-vcch.json b/advisories/unreviewed/2022/05/GHSA-88gc-h5ch-vcch/GHSA-88gc-h5ch-vcch.json index cf7d33ef59d..1da0c3617c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-88gc-h5ch-vcch/GHSA-88gc-h5ch-vcch.json +++ b/advisories/unreviewed/2022/05/GHSA-88gc-h5ch-vcch/GHSA-88gc-h5ch-vcch.json @@ -7,12 +7,8 @@ "CVE-2020-15718" ], "details": "RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8922-85wm-q7vh/GHSA-8922-85wm-q7vh.json b/advisories/unreviewed/2022/05/GHSA-8922-85wm-q7vh/GHSA-8922-85wm-q7vh.json index 54c9d97d10d..3c59fffeb83 100644 --- a/advisories/unreviewed/2022/05/GHSA-8922-85wm-q7vh/GHSA-8922-85wm-q7vh.json +++ b/advisories/unreviewed/2022/05/GHSA-8922-85wm-q7vh/GHSA-8922-85wm-q7vh.json @@ -7,12 +7,8 @@ "CVE-2020-2968" ], "details": "Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java VM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89fj-r9xp-r6c9/GHSA-89fj-r9xp-r6c9.json b/advisories/unreviewed/2022/05/GHSA-89fj-r9xp-r6c9/GHSA-89fj-r9xp-r6c9.json index b221b783bbf..59701a21a2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-89fj-r9xp-r6c9/GHSA-89fj-r9xp-r6c9.json +++ b/advisories/unreviewed/2022/05/GHSA-89fj-r9xp-r6c9/GHSA-89fj-r9xp-r6c9.json @@ -7,12 +7,8 @@ "CVE-2020-14533" ], "details": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.1, 11.2 and prior to 11.3.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as unauthorized read access to a subset of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 3.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8c2f-jx3v-cm8h/GHSA-8c2f-jx3v-cm8h.json b/advisories/unreviewed/2022/05/GHSA-8c2f-jx3v-cm8h/GHSA-8c2f-jx3v-cm8h.json index 2d1ef811a72..ddf3da73815 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c2f-jx3v-cm8h/GHSA-8c2f-jx3v-cm8h.json +++ b/advisories/unreviewed/2022/05/GHSA-8c2f-jx3v-cm8h/GHSA-8c2f-jx3v-cm8h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8f34-ccvf-c6jf/GHSA-8f34-ccvf-c6jf.json b/advisories/unreviewed/2022/05/GHSA-8f34-ccvf-c6jf/GHSA-8f34-ccvf-c6jf.json index 6f962ddd0a6..5c3c0871726 100644 --- a/advisories/unreviewed/2022/05/GHSA-8f34-ccvf-c6jf/GHSA-8f34-ccvf-c6jf.json +++ b/advisories/unreviewed/2022/05/GHSA-8f34-ccvf-c6jf/GHSA-8f34-ccvf-c6jf.json @@ -7,12 +7,8 @@ "CVE-2020-1042" ], "details": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1043.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8g54-6pcx-c3vq/GHSA-8g54-6pcx-c3vq.json b/advisories/unreviewed/2022/05/GHSA-8g54-6pcx-c3vq/GHSA-8g54-6pcx-c3vq.json index f5dc91450a8..3ccec04974f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g54-6pcx-c3vq/GHSA-8g54-6pcx-c3vq.json +++ b/advisories/unreviewed/2022/05/GHSA-8g54-6pcx-c3vq/GHSA-8g54-6pcx-c3vq.json @@ -7,12 +7,8 @@ "CVE-2020-14584" ], "details": "Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8h7f-c83v-885w/GHSA-8h7f-c83v-885w.json b/advisories/unreviewed/2022/05/GHSA-8h7f-c83v-885w/GHSA-8h7f-c83v-885w.json index adef39164f8..6340a22185e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h7f-c83v-885w/GHSA-8h7f-c83v-885w.json +++ b/advisories/unreviewed/2022/05/GHSA-8h7f-c83v-885w/GHSA-8h7f-c83v-885w.json @@ -7,12 +7,8 @@ "CVE-2020-14574" ], "details": "Vulnerability in the Oracle Communications Interactive Session Recorder product of Oracle Communications Applications (component: FACE). Supported versions that are affected are 6.1-6.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Interactive Session Recorder executes to compromise Oracle Communications Interactive Session Recorder. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Interactive Session Recorder accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Interactive Session Recorder accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8h98-4756-r8r4/GHSA-8h98-4756-r8r4.json b/advisories/unreviewed/2022/05/GHSA-8h98-4756-r8r4/GHSA-8h98-4756-r8r4.json index 433b0cf6e98..2cbfbb80cd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h98-4756-r8r4/GHSA-8h98-4756-r8r4.json +++ b/advisories/unreviewed/2022/05/GHSA-8h98-4756-r8r4/GHSA-8h98-4756-r8r4.json @@ -7,12 +7,8 @@ "CVE-2020-1359" ], "details": "An elevation of privilege vulnerability exists when the Windows Cryptography Next Generation (CNG) Key Isolation service improperly handles memory, aka 'Windows CNG Key Isolation Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1384.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hff-gxvr-v39f/GHSA-8hff-gxvr-v39f.json b/advisories/unreviewed/2022/05/GHSA-8hff-gxvr-v39f/GHSA-8hff-gxvr-v39f.json index 3765840c397..3e312b81fc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hff-gxvr-v39f/GHSA-8hff-gxvr-v39f.json +++ b/advisories/unreviewed/2022/05/GHSA-8hff-gxvr-v39f/GHSA-8hff-gxvr-v39f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qwq-9r56-cp3v/GHSA-8qwq-9r56-cp3v.json b/advisories/unreviewed/2022/05/GHSA-8qwq-9r56-cp3v/GHSA-8qwq-9r56-cp3v.json index f80c37a2d3f..4252a038fb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qwq-9r56-cp3v/GHSA-8qwq-9r56-cp3v.json +++ b/advisories/unreviewed/2022/05/GHSA-8qwq-9r56-cp3v/GHSA-8qwq-9r56-cp3v.json @@ -7,12 +7,8 @@ "CVE-2020-3345" ], "details": "A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values within affected pages. An attacker could exploit this vulnerability by persuading a user to follow a crafted link that is designed to pass HTML code into an affected parameter. A successful exploit could allow the attacker to alter the contents of a web page to redirect the user to potentially malicious web sites, or the attacker could leverage this vulnerability to conduct further client-side attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rj5-wwmx-vj53/GHSA-8rj5-wwmx-vj53.json b/advisories/unreviewed/2022/05/GHSA-8rj5-wwmx-vj53/GHSA-8rj5-wwmx-vj53.json index 6b06977f811..bcf30b369d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rj5-wwmx-vj53/GHSA-8rj5-wwmx-vj53.json +++ b/advisories/unreviewed/2022/05/GHSA-8rj5-wwmx-vj53/GHSA-8rj5-wwmx-vj53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rm3-jg2c-hvfh/GHSA-8rm3-jg2c-hvfh.json b/advisories/unreviewed/2022/05/GHSA-8rm3-jg2c-hvfh/GHSA-8rm3-jg2c-hvfh.json index 4a96e968501..f1969a03de6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rm3-jg2c-hvfh/GHSA-8rm3-jg2c-hvfh.json +++ b/advisories/unreviewed/2022/05/GHSA-8rm3-jg2c-hvfh/GHSA-8rm3-jg2c-hvfh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rph-mpfm-vxvh/GHSA-8rph-mpfm-vxvh.json b/advisories/unreviewed/2022/05/GHSA-8rph-mpfm-vxvh/GHSA-8rph-mpfm-vxvh.json index 86b1753e513..544574a687b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rph-mpfm-vxvh/GHSA-8rph-mpfm-vxvh.json +++ b/advisories/unreviewed/2022/05/GHSA-8rph-mpfm-vxvh/GHSA-8rph-mpfm-vxvh.json @@ -7,12 +7,8 @@ "CVE-2020-1362" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1344, CVE-2020-1369.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8v2w-6qhm-pxp7/GHSA-8v2w-6qhm-pxp7.json b/advisories/unreviewed/2022/05/GHSA-8v2w-6qhm-pxp7/GHSA-8v2w-6qhm-pxp7.json index 1f209619e5d..17037c9261b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v2w-6qhm-pxp7/GHSA-8v2w-6qhm-pxp7.json +++ b/advisories/unreviewed/2022/05/GHSA-8v2w-6qhm-pxp7/GHSA-8v2w-6qhm-pxp7.json @@ -7,12 +7,8 @@ "CVE-2019-20908" ], "details": "An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8w7m-j7xw-2xc9/GHSA-8w7m-j7xw-2xc9.json b/advisories/unreviewed/2022/05/GHSA-8w7m-j7xw-2xc9/GHSA-8w7m-j7xw-2xc9.json index 550d1cb8820..b1d18aef6ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w7m-j7xw-2xc9/GHSA-8w7m-j7xw-2xc9.json +++ b/advisories/unreviewed/2022/05/GHSA-8w7m-j7xw-2xc9/GHSA-8w7m-j7xw-2xc9.json @@ -7,12 +7,8 @@ "CVE-2020-15696" ], "details": "An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8x83-r79c-88mg/GHSA-8x83-r79c-88mg.json b/advisories/unreviewed/2022/05/GHSA-8x83-r79c-88mg/GHSA-8x83-r79c-88mg.json index a2ce2c6744f..08f9f2b3370 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x83-r79c-88mg/GHSA-8x83-r79c-88mg.json +++ b/advisories/unreviewed/2022/05/GHSA-8x83-r79c-88mg/GHSA-8x83-r79c-88mg.json @@ -7,12 +7,8 @@ "CVE-2020-14714" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xhv-724q-h3f3/GHSA-8xhv-724q-h3f3.json b/advisories/unreviewed/2022/05/GHSA-8xhv-724q-h3f3/GHSA-8xhv-724q-h3f3.json index b5ed91400f9..30657be706e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xhv-724q-h3f3/GHSA-8xhv-724q-h3f3.json +++ b/advisories/unreviewed/2022/05/GHSA-8xhv-724q-h3f3/GHSA-8xhv-724q-h3f3.json @@ -7,12 +7,8 @@ "CVE-2020-0120" ], "details": "In notifyErrorForPendingRequests of QCamera3HWI.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-149995442", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9275-c4xq-9m4g/GHSA-9275-c4xq-9m4g.json b/advisories/unreviewed/2022/05/GHSA-9275-c4xq-9m4g/GHSA-9275-c4xq-9m4g.json index 7f89c3d2460..074fb3fa8b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9275-c4xq-9m4g/GHSA-9275-c4xq-9m4g.json +++ b/advisories/unreviewed/2022/05/GHSA-9275-c4xq-9m4g/GHSA-9275-c4xq-9m4g.json @@ -7,12 +7,8 @@ "CVE-2020-14668" ], "details": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: DBI Setups). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle E-Business Intelligence, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data as well as unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9397-r359-47hx/GHSA-9397-r359-47hx.json b/advisories/unreviewed/2022/05/GHSA-9397-r359-47hx/GHSA-9397-r359-47hx.json index 154fb2a6269..b28b9a6caab 100644 --- a/advisories/unreviewed/2022/05/GHSA-9397-r359-47hx/GHSA-9397-r359-47hx.json +++ b/advisories/unreviewed/2022/05/GHSA-9397-r359-47hx/GHSA-9397-r359-47hx.json @@ -7,12 +7,8 @@ "CVE-2020-1412" ], "details": "A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93qf-3vmf-gxvm/GHSA-93qf-3vmf-gxvm.json b/advisories/unreviewed/2022/05/GHSA-93qf-3vmf-gxvm/GHSA-93qf-3vmf-gxvm.json index b55157e7f18..82b7a637670 100644 --- a/advisories/unreviewed/2022/05/GHSA-93qf-3vmf-gxvm/GHSA-93qf-3vmf-gxvm.json +++ b/advisories/unreviewed/2022/05/GHSA-93qf-3vmf-gxvm/GHSA-93qf-3vmf-gxvm.json @@ -7,12 +7,8 @@ "CVE-2020-14706" ], "details": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 17.1.0.0-17.12.17.1, 18.1.0.0-18.8.19 and 19.12.0-19.12.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera P6 Enterprise Project Portfolio Management accessible data as well as unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93r3-cg65-gvx6/GHSA-93r3-cg65-gvx6.json b/advisories/unreviewed/2022/05/GHSA-93r3-cg65-gvx6/GHSA-93r3-cg65-gvx6.json index 8905abc2e4b..3df2b7e69c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-93r3-cg65-gvx6/GHSA-93r3-cg65-gvx6.json +++ b/advisories/unreviewed/2022/05/GHSA-93r3-cg65-gvx6/GHSA-93r3-cg65-gvx6.json @@ -7,12 +7,8 @@ "CVE-2020-14699" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96qc-rwrq-72pr/GHSA-96qc-rwrq-72pr.json b/advisories/unreviewed/2022/05/GHSA-96qc-rwrq-72pr/GHSA-96qc-rwrq-72pr.json index c7ac44fb463..bedcd0720a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-96qc-rwrq-72pr/GHSA-96qc-rwrq-72pr.json +++ b/advisories/unreviewed/2022/05/GHSA-96qc-rwrq-72pr/GHSA-96qc-rwrq-72pr.json @@ -7,12 +7,8 @@ "CVE-2019-4747" ], "details": "IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172887.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-97xf-5qr7-4cw3/GHSA-97xf-5qr7-4cw3.json b/advisories/unreviewed/2022/05/GHSA-97xf-5qr7-4cw3/GHSA-97xf-5qr7-4cw3.json index 7e05598145b..42fe48cfd05 100644 --- a/advisories/unreviewed/2022/05/GHSA-97xf-5qr7-4cw3/GHSA-97xf-5qr7-4cw3.json +++ b/advisories/unreviewed/2022/05/GHSA-97xf-5qr7-4cw3/GHSA-97xf-5qr7-4cw3.json @@ -7,12 +7,8 @@ "CVE-2020-14497" ], "details": "Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -168,9 +164,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-989v-c64c-jq57/GHSA-989v-c64c-jq57.json b/advisories/unreviewed/2022/05/GHSA-989v-c64c-jq57/GHSA-989v-c64c-jq57.json index 2f9ad7f6f4a..9684356c743 100644 --- a/advisories/unreviewed/2022/05/GHSA-989v-c64c-jq57/GHSA-989v-c64c-jq57.json +++ b/advisories/unreviewed/2022/05/GHSA-989v-c64c-jq57/GHSA-989v-c64c-jq57.json @@ -7,12 +7,8 @@ "CVE-2020-10038" ], "details": "A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the device's web server might be able to execute administrative commands without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98qh-xxww-5r96/GHSA-98qh-xxww-5r96.json b/advisories/unreviewed/2022/05/GHSA-98qh-xxww-5r96/GHSA-98qh-xxww-5r96.json index 53468e5b52a..ec3b6fc477e 100644 --- a/advisories/unreviewed/2022/05/GHSA-98qh-xxww-5r96/GHSA-98qh-xxww-5r96.json +++ b/advisories/unreviewed/2022/05/GHSA-98qh-xxww-5r96/GHSA-98qh-xxww-5r96.json @@ -7,12 +7,8 @@ "CVE-2020-1040" ], "details": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-993c-67fv-pmjq/GHSA-993c-67fv-pmjq.json b/advisories/unreviewed/2022/05/GHSA-993c-67fv-pmjq/GHSA-993c-67fv-pmjq.json index cd18bf7c75b..c06985b7481 100644 --- a/advisories/unreviewed/2022/05/GHSA-993c-67fv-pmjq/GHSA-993c-67fv-pmjq.json +++ b/advisories/unreviewed/2022/05/GHSA-993c-67fv-pmjq/GHSA-993c-67fv-pmjq.json @@ -7,12 +7,8 @@ "CVE-2020-1415" ], "details": "An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1422.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9fqw-5vfg-2mfq/GHSA-9fqw-5vfg-2mfq.json b/advisories/unreviewed/2022/05/GHSA-9fqw-5vfg-2mfq/GHSA-9fqw-5vfg-2mfq.json index fad3e2292b2..91daa6bfc6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fqw-5vfg-2mfq/GHSA-9fqw-5vfg-2mfq.json +++ b/advisories/unreviewed/2022/05/GHSA-9fqw-5vfg-2mfq/GHSA-9fqw-5vfg-2mfq.json @@ -7,12 +7,8 @@ "CVE-2020-7578" ], "details": "A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users could have access to resources they normally would not have. This vulnerability could allow an attacker to view internal information and perform unauthorized changes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fv5-j7w3-ph59/GHSA-9fv5-j7w3-ph59.json b/advisories/unreviewed/2022/05/GHSA-9fv5-j7w3-ph59/GHSA-9fv5-j7w3-ph59.json index 33303c5c873..9e98f94c234 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fv5-j7w3-ph59/GHSA-9fv5-j7w3-ph59.json +++ b/advisories/unreviewed/2022/05/GHSA-9fv5-j7w3-ph59/GHSA-9fv5-j7w3-ph59.json @@ -7,12 +7,8 @@ "CVE-2020-1643" ], "details": "Execution of the \"show ospf interface extensive\" or \"show ospf interface detail\" CLI commands on a Juniper Networks device running Junos OS may cause the routing protocols process (RPD) to crash and restart if OSPF interface authentication is configured, leading to a Denial of Service (DoS). By continuously executing the same CLI commands, a local attacker can repeatedly crash the RPD process causing a sustained Denial of Service. Note: Only systems utilizing ARM processors, found on the EX2300 and EX3400, are vulnerable to this issue. Systems shipped with other processor architectures are not vulnerable to this issue. The processor architecture can be displayed via the 'uname -a' command. For example: ARM (vulnerable): % uname -a | awk '{print $NF}' arm PowerPC (not vulnerable): % uname -a | awk '{print $NF}' powerpc AMD (not vulnerable): % uname -a | awk '{print $NF}' amd64 Intel (not vulnerable): % uname -a | awk '{print $NF}' i386 This issue affects Juniper Networks Junos OS: 12.3X48 versions prior to 12.3X48-D100; 14.1X53 versions prior to 14.1X53-D140, 14.1X53-D54; 15.1 versions prior to 15.1R7-S7; 15.1X49 versions prior to 15.1X49-D210; 15.1X53 versions prior to 15.1X53-D593; 16.1 versions prior to 16.1R7-S8; 17.1 versions prior to 17.1R2-S12; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S2, 17.4R3; 18.1 versions prior to 18.1R3-S2; 18.2 versions prior to 18.2R2, 18.2R3; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S2, 18.3R2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fvq-rcpx-h4hh/GHSA-9fvq-rcpx-h4hh.json b/advisories/unreviewed/2022/05/GHSA-9fvq-rcpx-h4hh/GHSA-9fvq-rcpx-h4hh.json index 3515a5f96c5..fedca26c090 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fvq-rcpx-h4hh/GHSA-9fvq-rcpx-h4hh.json +++ b/advisories/unreviewed/2022/05/GHSA-9fvq-rcpx-h4hh/GHSA-9fvq-rcpx-h4hh.json @@ -7,12 +7,8 @@ "CVE-2020-1354" ], "details": "An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1430.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g7m-mw8w-mqc5/GHSA-9g7m-mw8w-mqc5.json b/advisories/unreviewed/2022/05/GHSA-9g7m-mw8w-mqc5/GHSA-9g7m-mw8w-mqc5.json index c7f3f61a187..b5575844489 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g7m-mw8w-mqc5/GHSA-9g7m-mw8w-mqc5.json +++ b/advisories/unreviewed/2022/05/GHSA-9g7m-mw8w-mqc5/GHSA-9g7m-mw8w-mqc5.json @@ -7,12 +7,8 @@ "CVE-2019-16244" ], "details": "OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gp9-35p2-qvpw/GHSA-9gp9-35p2-qvpw.json b/advisories/unreviewed/2022/05/GHSA-9gp9-35p2-qvpw/GHSA-9gp9-35p2-qvpw.json index 671ac04089f..505a046abb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gp9-35p2-qvpw/GHSA-9gp9-35p2-qvpw.json +++ b/advisories/unreviewed/2022/05/GHSA-9gp9-35p2-qvpw/GHSA-9gp9-35p2-qvpw.json @@ -7,12 +7,8 @@ "CVE-2020-1041" ], "details": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1040, CVE-2020-1042, CVE-2020-1043.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gvc-6g9v-v5rp/GHSA-9gvc-6g9v-v5rp.json b/advisories/unreviewed/2022/05/GHSA-9gvc-6g9v-v5rp/GHSA-9gvc-6g9v-v5rp.json index e4ea3323b20..f465044660f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gvc-6g9v-v5rp/GHSA-9gvc-6g9v-v5rp.json +++ b/advisories/unreviewed/2022/05/GHSA-9gvc-6g9v-v5rp/GHSA-9gvc-6g9v-v5rp.json @@ -7,12 +7,8 @@ "CVE-2020-11956" ], "details": "An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a least privilege violation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mm4-gp88-mrch/GHSA-9mm4-gp88-mrch.json b/advisories/unreviewed/2022/05/GHSA-9mm4-gp88-mrch/GHSA-9mm4-gp88-mrch.json index 5c483eaf992..7d96daa0fd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mm4-gp88-mrch/GHSA-9mm4-gp88-mrch.json +++ b/advisories/unreviewed/2022/05/GHSA-9mm4-gp88-mrch/GHSA-9mm4-gp88-mrch.json @@ -7,12 +7,8 @@ "CVE-2020-1428" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1373, CVE-2020-1390, CVE-2020-1427, CVE-2020-1438.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9q3x-qq6c-v6jx/GHSA-9q3x-qq6c-v6jx.json b/advisories/unreviewed/2022/05/GHSA-9q3x-qq6c-v6jx/GHSA-9q3x-qq6c-v6jx.json index 8e4f59cfa1a..1e2b2318d3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q3x-qq6c-v6jx/GHSA-9q3x-qq6c-v6jx.json +++ b/advisories/unreviewed/2022/05/GHSA-9q3x-qq6c-v6jx/GHSA-9q3x-qq6c-v6jx.json @@ -7,12 +7,8 @@ "CVE-2020-9671" ], "details": "Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qhv-29p6-wwp6/GHSA-9qhv-29p6-wwp6.json b/advisories/unreviewed/2022/05/GHSA-9qhv-29p6-wwp6/GHSA-9qhv-29p6-wwp6.json index 30bb30d78c7..81a01e50bc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qhv-29p6-wwp6/GHSA-9qhv-29p6-wwp6.json +++ b/advisories/unreviewed/2022/05/GHSA-9qhv-29p6-wwp6/GHSA-9qhv-29p6-wwp6.json @@ -7,12 +7,8 @@ "CVE-2020-1650" ], "details": "On Juniper Networks Junos MX Series with service card configured, receipt of a stream of specific packets may crash the MS-PIC component on MS-MIC or MS-MPC. By continuously sending these specific packets, an attacker can repeatedly bring down MS-PIC on MS-MIC/MS-MPC causing a prolonged Denial of Service. This issue affects MX Series devices using MS-PIC, MS-MIC or MS-MPC service cards with any service configured. This issue affects Juniper Networks Junos OS on MX Series: 17.2R2-S7; 17.3R3-S4, 17.3R3-S5; 17.4R2-S4 and the subsequent SRs (17.4R2-S5, 17.4R2-S6, etc.); 17.4R3; 18.1R3-S3, 18.1R3-S4, 18.1R3-S5, 18.1R3-S6, 18.1R3-S7, 18.1R3-S8; 18.2R3, 18.2R3-S1, 18.2R3-S2; 18.3R2 and the SRs based on 18.3R2; 18.4R2 and the SRs based on 18.4R2; 19.1R1 and the SRs based on 19.1R1; 19.2R1 and the SRs based on 19.2R1; 19.3R1 and the SRs based on 19.3R1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qx8-h7w2-x7mp/GHSA-9qx8-h7w2-x7mp.json b/advisories/unreviewed/2022/05/GHSA-9qx8-h7w2-x7mp/GHSA-9qx8-h7w2-x7mp.json index 5f9b47626ed..5ce8b6400e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qx8-h7w2-x7mp/GHSA-9qx8-h7w2-x7mp.json +++ b/advisories/unreviewed/2022/05/GHSA-9qx8-h7w2-x7mp/GHSA-9qx8-h7w2-x7mp.json @@ -7,12 +7,8 @@ "CVE-2020-6291" ], "details": "SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rh6-9x9j-x842/GHSA-9rh6-9x9j-x842.json b/advisories/unreviewed/2022/05/GHSA-9rh6-9x9j-x842/GHSA-9rh6-9x9j-x842.json index da1cf0b403f..74f532b7cbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rh6-9x9j-x842/GHSA-9rh6-9x9j-x842.json +++ b/advisories/unreviewed/2022/05/GHSA-9rh6-9x9j-x842/GHSA-9rh6-9x9j-x842.json @@ -7,12 +7,8 @@ "CVE-2020-1448" ], "details": "A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rmg-8r3f-xrq7/GHSA-9rmg-8r3f-xrq7.json b/advisories/unreviewed/2022/05/GHSA-9rmg-8r3f-xrq7/GHSA-9rmg-8r3f-xrq7.json index 1bfa651d91a..86d3e35f4da 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rmg-8r3f-xrq7/GHSA-9rmg-8r3f-xrq7.json +++ b/advisories/unreviewed/2022/05/GHSA-9rmg-8r3f-xrq7/GHSA-9rmg-8r3f-xrq7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v5f-rvh9-wc7c/GHSA-9v5f-rvh9-wc7c.json b/advisories/unreviewed/2022/05/GHSA-9v5f-rvh9-wc7c/GHSA-9v5f-rvh9-wc7c.json index 749b84bd921..b28cc3ba3ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v5f-rvh9-wc7c/GHSA-9v5f-rvh9-wc7c.json +++ b/advisories/unreviewed/2022/05/GHSA-9v5f-rvh9-wc7c/GHSA-9v5f-rvh9-wc7c.json @@ -7,12 +7,8 @@ "CVE-2019-4748" ], "details": "IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173174.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9v6x-99vx-fw68/GHSA-9v6x-99vx-fw68.json b/advisories/unreviewed/2022/05/GHSA-9v6x-99vx-fw68/GHSA-9v6x-99vx-fw68.json index 013c8e6ee5e..e0fefcf3263 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v6x-99vx-fw68/GHSA-9v6x-99vx-fw68.json +++ b/advisories/unreviewed/2022/05/GHSA-9v6x-99vx-fw68/GHSA-9v6x-99vx-fw68.json @@ -7,12 +7,8 @@ "CVE-2020-9252" ], "details": "HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) have a path traversal vulnerability. The system does not sufficiently validate certain pathname from certain process, successful exploit could allow the attacker write files to a crafted path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9w6w-9279-x57j/GHSA-9w6w-9279-x57j.json b/advisories/unreviewed/2022/05/GHSA-9w6w-9279-x57j/GHSA-9w6w-9279-x57j.json index 48e59346691..219879af53c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w6w-9279-x57j/GHSA-9w6w-9279-x57j.json +++ b/advisories/unreviewed/2022/05/GHSA-9w6w-9279-x57j/GHSA-9w6w-9279-x57j.json @@ -7,12 +7,8 @@ "CVE-2020-1462" ], "details": "An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9w82-5jc2-rr7m/GHSA-9w82-5jc2-rr7m.json b/advisories/unreviewed/2022/05/GHSA-9w82-5jc2-rr7m/GHSA-9w82-5jc2-rr7m.json index 92d4a718851..379a84d9b07 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w82-5jc2-rr7m/GHSA-9w82-5jc2-rr7m.json +++ b/advisories/unreviewed/2022/05/GHSA-9w82-5jc2-rr7m/GHSA-9w82-5jc2-rr7m.json @@ -7,12 +7,8 @@ "CVE-2020-1647" ], "details": "On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) due to processing of a specific HTTP message. Continued processing of this specific HTTP message may result in an extended Denial of Service (DoS). The offending HTTP message that causes this issue may originate both from the HTTP server or the client. This issue affects Juniper Networks Junos OS on SRX Series: 18.1 versions prior to 18.1R3-S9; 18.2 versions prior to 18.2R3-S3; 18.3 versions prior to 18.3R2-S4, 18.3R3-S1; 18.4 versions prior to 18.4R2-S5, 18.4R3; 19.1 versions prior to 19.1R2; 19.2 versions prior to 19.2R1-S2, 19.2R2; 19.3 versions prior to 19.3R2. This issue does not affect Juniper Networks Junos OS prior to 18.1R1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xqg-wjcv-qqxq/GHSA-9xqg-wjcv-qqxq.json b/advisories/unreviewed/2022/05/GHSA-9xqg-wjcv-qqxq/GHSA-9xqg-wjcv-qqxq.json index 54546d4b23c..817dfb63bbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xqg-wjcv-qqxq/GHSA-9xqg-wjcv-qqxq.json +++ b/advisories/unreviewed/2022/05/GHSA-9xqg-wjcv-qqxq/GHSA-9xqg-wjcv-qqxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2pp-46rf-cqg2/GHSA-c2pp-46rf-cqg2.json b/advisories/unreviewed/2022/05/GHSA-c2pp-46rf-cqg2/GHSA-c2pp-46rf-cqg2.json index db1ae2c6de0..6c04b027726 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2pp-46rf-cqg2/GHSA-c2pp-46rf-cqg2.json +++ b/advisories/unreviewed/2022/05/GHSA-c2pp-46rf-cqg2/GHSA-c2pp-46rf-cqg2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2w5-xj35-qmx4/GHSA-c2w5-xj35-qmx4.json b/advisories/unreviewed/2022/05/GHSA-c2w5-xj35-qmx4/GHSA-c2w5-xj35-qmx4.json index a709f943e99..523dec9cf5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2w5-xj35-qmx4/GHSA-c2w5-xj35-qmx4.json +++ b/advisories/unreviewed/2022/05/GHSA-c2w5-xj35-qmx4/GHSA-c2w5-xj35-qmx4.json @@ -7,12 +7,8 @@ "CVE-2020-1385" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Credential Picker handles objects in memory, aka 'Windows Credential Picker Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3h3-5867-mxh8/GHSA-c3h3-5867-mxh8.json b/advisories/unreviewed/2022/05/GHSA-c3h3-5867-mxh8/GHSA-c3h3-5867-mxh8.json index e57bd5572bb..15b3fae9aba 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3h3-5867-mxh8/GHSA-c3h3-5867-mxh8.json +++ b/advisories/unreviewed/2022/05/GHSA-c3h3-5867-mxh8/GHSA-c3h3-5867-mxh8.json @@ -7,12 +7,8 @@ "CVE-2020-9257" ], "details": "HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a buffer overflow vulnerability. The software access data past the end, or before the beginning, of the intended buffer when handling certain operations of certificate, the attacker should trick the user into installing a malicious application, successful exploit may cause code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4r5-4x67-4w7c/GHSA-c4r5-4x67-4w7c.json b/advisories/unreviewed/2022/05/GHSA-c4r5-4x67-4w7c/GHSA-c4r5-4x67-4w7c.json index 29a60f90f29..e6233c2aeff 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4r5-4x67-4w7c/GHSA-c4r5-4x67-4w7c.json +++ b/advisories/unreviewed/2022/05/GHSA-c4r5-4x67-4w7c/GHSA-c4r5-4x67-4w7c.json @@ -7,12 +7,8 @@ "CVE-2020-15717" ], "details": "RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5v9-3j87-cvp7/GHSA-c5v9-3j87-cvp7.json b/advisories/unreviewed/2022/05/GHSA-c5v9-3j87-cvp7/GHSA-c5v9-3j87-cvp7.json index 0c6934d9811..be29442f85c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5v9-3j87-cvp7/GHSA-c5v9-3j87-cvp7.json +++ b/advisories/unreviewed/2022/05/GHSA-c5v9-3j87-cvp7/GHSA-c5v9-3j87-cvp7.json @@ -7,12 +7,8 @@ "CVE-2020-6103" ], "details": "An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability can be triggered from a HYPER-V guest using the RemoteFX feature, leading to executing the vulnerable code on the HYPER-V host (inside of the rdvgm.exe process). Theoretically this vulnerability could be also triggered from web browser (using webGL and webassembly).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c683-386m-9r6m/GHSA-c683-386m-9r6m.json b/advisories/unreviewed/2022/05/GHSA-c683-386m-9r6m/GHSA-c683-386m-9r6m.json index 1a405abdb50..73b2af5fe0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c683-386m-9r6m/GHSA-c683-386m-9r6m.json +++ b/advisories/unreviewed/2022/05/GHSA-c683-386m-9r6m/GHSA-c683-386m-9r6m.json @@ -7,12 +7,8 @@ "CVE-2020-12007" ], "details": "A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior; ICONICS GenBroker32 version 9.5 and prior.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6v6-mvg4-h5hx/GHSA-c6v6-mvg4-h5hx.json b/advisories/unreviewed/2022/05/GHSA-c6v6-mvg4-h5hx/GHSA-c6v6-mvg4-h5hx.json index 8c8d0cc8dc1..25d49a7c54f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6v6-mvg4-h5hx/GHSA-c6v6-mvg4-h5hx.json +++ b/advisories/unreviewed/2022/05/GHSA-c6v6-mvg4-h5hx/GHSA-c6v6-mvg4-h5hx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c743-9hfh-9968/GHSA-c743-9hfh-9968.json b/advisories/unreviewed/2022/05/GHSA-c743-9hfh-9968/GHSA-c743-9hfh-9968.json index b7470aa3491..832f3327059 100644 --- a/advisories/unreviewed/2022/05/GHSA-c743-9hfh-9968/GHSA-c743-9hfh-9968.json +++ b/advisories/unreviewed/2022/05/GHSA-c743-9hfh-9968/GHSA-c743-9hfh-9968.json @@ -7,12 +7,8 @@ "CVE-2020-14601" ], "details": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c85x-m577-qjhw/GHSA-c85x-m577-qjhw.json b/advisories/unreviewed/2022/05/GHSA-c85x-m577-qjhw/GHSA-c85x-m577-qjhw.json index 03f82f7c534..4d6028917cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-c85x-m577-qjhw/GHSA-c85x-m577-qjhw.json +++ b/advisories/unreviewed/2022/05/GHSA-c85x-m577-qjhw/GHSA-c85x-m577-qjhw.json @@ -7,12 +7,8 @@ "CVE-2020-1481" ], "details": "A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c93v-xv7q-4w4c/GHSA-c93v-xv7q-4w4c.json b/advisories/unreviewed/2022/05/GHSA-c93v-xv7q-4w4c/GHSA-c93v-xv7q-4w4c.json index 1fcea7d8e5f..f3e1e06fc53 100644 --- a/advisories/unreviewed/2022/05/GHSA-c93v-xv7q-4w4c/GHSA-c93v-xv7q-4w4c.json +++ b/advisories/unreviewed/2022/05/GHSA-c93v-xv7q-4w4c/GHSA-c93v-xv7q-4w4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9q3-58pp-r6v9/GHSA-c9q3-58pp-r6v9.json b/advisories/unreviewed/2022/05/GHSA-c9q3-58pp-r6v9/GHSA-c9q3-58pp-r6v9.json index 480276fd71f..21c3fe7269e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9q3-58pp-r6v9/GHSA-c9q3-58pp-r6v9.json +++ b/advisories/unreviewed/2022/05/GHSA-c9q3-58pp-r6v9/GHSA-c9q3-58pp-r6v9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -75,9 +73,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9vp-hrfr-vhvj/GHSA-c9vp-hrfr-vhvj.json b/advisories/unreviewed/2022/05/GHSA-c9vp-hrfr-vhvj/GHSA-c9vp-hrfr-vhvj.json index 10cfb9f24d6..230b4418ddc 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9vp-hrfr-vhvj/GHSA-c9vp-hrfr-vhvj.json +++ b/advisories/unreviewed/2022/05/GHSA-c9vp-hrfr-vhvj/GHSA-c9vp-hrfr-vhvj.json @@ -7,12 +7,8 @@ "CVE-2020-1451" ], "details": "A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1450, CVE-2020-1456.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cc6p-97f5-f8v5/GHSA-cc6p-97f5-f8v5.json b/advisories/unreviewed/2022/05/GHSA-cc6p-97f5-f8v5/GHSA-cc6p-97f5-f8v5.json index d9aef6285cf..924195a6682 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc6p-97f5-f8v5/GHSA-cc6p-97f5-f8v5.json +++ b/advisories/unreviewed/2022/05/GHSA-cc6p-97f5-f8v5/GHSA-cc6p-97f5-f8v5.json @@ -7,12 +7,8 @@ "CVE-2020-14707" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cc7x-rwq6-84vw/GHSA-cc7x-rwq6-84vw.json b/advisories/unreviewed/2022/05/GHSA-cc7x-rwq6-84vw/GHSA-cc7x-rwq6-84vw.json index 1bc2be6cc9a..c9e0c98fb43 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc7x-rwq6-84vw/GHSA-cc7x-rwq6-84vw.json +++ b/advisories/unreviewed/2022/05/GHSA-cc7x-rwq6-84vw/GHSA-cc7x-rwq6-84vw.json @@ -7,12 +7,8 @@ "CVE-2020-14549" ], "details": "Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Server). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera Portfolio Management accessible data as well as unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cf89-hfgx-84qg/GHSA-cf89-hfgx-84qg.json b/advisories/unreviewed/2022/05/GHSA-cf89-hfgx-84qg/GHSA-cf89-hfgx-84qg.json index 8ebeb79e67c..fb3b3625b30 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf89-hfgx-84qg/GHSA-cf89-hfgx-84qg.json +++ b/advisories/unreviewed/2022/05/GHSA-cf89-hfgx-84qg/GHSA-cf89-hfgx-84qg.json @@ -7,12 +7,8 @@ "CVE-2020-1390" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1373, CVE-2020-1427, CVE-2020-1428, CVE-2020-1438.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cf9m-v68h-2766/GHSA-cf9m-v68h-2766.json b/advisories/unreviewed/2022/05/GHSA-cf9m-v68h-2766/GHSA-cf9m-v68h-2766.json index 8d519d22297..52b8975d8e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf9m-v68h-2766/GHSA-cf9m-v68h-2766.json +++ b/advisories/unreviewed/2022/05/GHSA-cf9m-v68h-2766/GHSA-cf9m-v68h-2766.json @@ -7,12 +7,8 @@ "CVE-2020-14541" ], "details": "Vulnerability in the Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Close Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hyperion Financial Close Management accessible data. CVSS 3.1 Base Score 2.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cfp9-244f-h66c/GHSA-cfp9-244f-h66c.json b/advisories/unreviewed/2022/05/GHSA-cfp9-244f-h66c/GHSA-cfp9-244f-h66c.json index f1189365d79..7b6e6bcac8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfp9-244f-h66c/GHSA-cfp9-244f-h66c.json +++ b/advisories/unreviewed/2022/05/GHSA-cfp9-244f-h66c/GHSA-cfp9-244f-h66c.json @@ -7,12 +7,8 @@ "CVE-2020-15572" ], "details": "Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cjff-rmqv-m6mx/GHSA-cjff-rmqv-m6mx.json b/advisories/unreviewed/2022/05/GHSA-cjff-rmqv-m6mx/GHSA-cjff-rmqv-m6mx.json index 71cf92c1881..61baa8b1542 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjff-rmqv-m6mx/GHSA-cjff-rmqv-m6mx.json +++ b/advisories/unreviewed/2022/05/GHSA-cjff-rmqv-m6mx/GHSA-cjff-rmqv-m6mx.json @@ -7,12 +7,8 @@ "CVE-2020-1388" ], "details": "An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1392, CVE-2020-1394, CVE-2020-1395.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cjqq-8xv6-575p/GHSA-cjqq-8xv6-575p.json b/advisories/unreviewed/2022/05/GHSA-cjqq-8xv6-575p/GHSA-cjqq-8xv6-575p.json index 8820da33ba7..99a959582a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjqq-8xv6-575p/GHSA-cjqq-8xv6-575p.json +++ b/advisories/unreviewed/2022/05/GHSA-cjqq-8xv6-575p/GHSA-cjqq-8xv6-575p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmjj-xxq8-8mvx/GHSA-cmjj-xxq8-8mvx.json b/advisories/unreviewed/2022/05/GHSA-cmjj-xxq8-8mvx/GHSA-cmjj-xxq8-8mvx.json index 1ee4f0c9820..1895f5b7130 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmjj-xxq8-8mvx/GHSA-cmjj-xxq8-8mvx.json +++ b/advisories/unreviewed/2022/05/GHSA-cmjj-xxq8-8mvx/GHSA-cmjj-xxq8-8mvx.json @@ -7,12 +7,8 @@ "CVE-2020-14708" ], "details": "Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-crqp-mv88-vcm6/GHSA-crqp-mv88-vcm6.json b/advisories/unreviewed/2022/05/GHSA-crqp-mv88-vcm6/GHSA-crqp-mv88-vcm6.json index b30f52d85e5..e4d46de7ad1 100644 --- a/advisories/unreviewed/2022/05/GHSA-crqp-mv88-vcm6/GHSA-crqp-mv88-vcm6.json +++ b/advisories/unreviewed/2022/05/GHSA-crqp-mv88-vcm6/GHSA-crqp-mv88-vcm6.json @@ -7,12 +7,8 @@ "CVE-2020-1352" ], "details": "An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows USO Core Worker Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crrc-w592-ff65/GHSA-crrc-w592-ff65.json b/advisories/unreviewed/2022/05/GHSA-crrc-w592-ff65/GHSA-crrc-w592-ff65.json index 9c205358b97..0e0927ed70b 100644 --- a/advisories/unreviewed/2022/05/GHSA-crrc-w592-ff65/GHSA-crrc-w592-ff65.json +++ b/advisories/unreviewed/2022/05/GHSA-crrc-w592-ff65/GHSA-crrc-w592-ff65.json @@ -7,12 +7,8 @@ "CVE-2020-9673" ], "details": "Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-crvx-qrfr-h2c3/GHSA-crvx-qrfr-h2c3.json b/advisories/unreviewed/2022/05/GHSA-crvx-qrfr-h2c3/GHSA-crvx-qrfr-h2c3.json index 89a2ed49b47..94eefc0b15d 100644 --- a/advisories/unreviewed/2022/05/GHSA-crvx-qrfr-h2c3/GHSA-crvx-qrfr-h2c3.json +++ b/advisories/unreviewed/2022/05/GHSA-crvx-qrfr-h2c3/GHSA-crvx-qrfr-h2c3.json @@ -7,12 +7,8 @@ "CVE-2020-1640" ], "details": "An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (routing protocols process) daemon allows an attacker to crash RPD thereby causing a Denial of Service (DoS) condition. This framework requires these packets to be passed. By continuously sending any of these types of formatted genuine packets, an attacker can repeatedly crash the RPD process causing a sustained Denial of Service. Authentication to the BGP peer is not required. This issue can be initiated or propagated through eBGP and iBGP and can impact devices in either modes of use as long as the devices are configured to support the compromised framework and a BGP path is activated or active. This issue affects: Juniper Networks Junos OS 16.1 versions 16.1R7-S6 and later versions prior to 16.1R7-S8; 17.3 versions 17.3R2-S5, 17.3R3-S6 and later versions prior to 17.3R3-S8; 17.4 versions 17.4R2-S7, 17.4R3 and later versions prior to 17.4R2-S11, 17.4R3-S2; 18.1 versions 18.1R3-S7 and later versions prior to 18.1R3-S10; 18.2 versions 18.2R2-S6, 18.2R3-S2 and later versions prior to 18.2R2-S7, 18.2R3-S5; 18.2X75 versions 18.2X75-D12, 18.2X75-D32, 18.2X75-D33, 18.2X75-D51, 18.2X75-D60, 18.2X75-D411, 18.2X75-D420 and later versions prior to 18.2X75-D32, 18.2X75-D33, 18.2X75-D420, 18.2X75-D52, 18.2X75-D60, 18.2X75-D65, 18.2X75-D70;(*1) 18.3 versions 18.3R1-S6, 18.3R2-S3, 18.3R3 and later versions prior to 18.3R2-S4, 18.3R3-S2; 18.4 versions 18.4R1-S5, 18.4R2-S4, 18.4R3 and later versions prior to 18.4R1-S7, 18.4R2-S5, 18.4R3-S3(*2); 19.1 versions 19.1R1-S3, 19.1R2 and later versions prior to 19.1R1-S5, 19.1R2-S2, 19.1R3-S2; 19.2 versions 19.2R1-S2, 19.2R2 and later versions prior to 19.2R1-S5, 19.2R2, 19.2R3; 19.3 versions prior to 19.3R2-S3, 19.3R3; 19.4 versions prior to 19.4R1-S2, 19.4R2, 19.4R3; 20.1 versions prior to 20.1R1-S1, 20.1R2. This issue does not affect Junos OS prior to 16.1R1. This issue affects IPv4 and IPv6 traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cvr9-hv4p-wfcw/GHSA-cvr9-hv4p-wfcw.json b/advisories/unreviewed/2022/05/GHSA-cvr9-hv4p-wfcw/GHSA-cvr9-hv4p-wfcw.json index 82a3be197bc..33e81b48def 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvr9-hv4p-wfcw/GHSA-cvr9-hv4p-wfcw.json +++ b/advisories/unreviewed/2022/05/GHSA-cvr9-hv4p-wfcw/GHSA-cvr9-hv4p-wfcw.json @@ -7,12 +7,8 @@ "CVE-2020-1645" ], "details": "When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing \"URL Filtering service\", may crash, causing the Services PIC to restart. While the Services PIC is restarting, all PIC services including DNS filtering service (DNS sink holing) will be bypassed until the Services PIC completes its boot process. If the issue occurs, system core-dumps output will show a crash of mspmand process: root@device> show system core-dumps -rw-rw---- 1 nobody wheel 575685123 /var/tmp/pics/mspmand.core.<*>.gz This issue affects Juniper Networks Junos OS: 17.3 versions prior to 17.3R3-S8; 18.3 versions prior to 18.3R2-S4, 18.3R3-S1; 18.4 versions prior to 18.4R2-S5, 18.4R3; 19.1 versions prior to 19.1R2-S2, 19.1R3; 19.2 versions prior to 19.2R1-S5, 19.2R2; 19.3 versions prior to 19.3R2-S3, 19.3R3; 19.4 versions prior to 19.4R1-S3, 19.4R2. This issue does not affect Juniper Networks Junos OS releases prior to 17.3R2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cw48-h2hv-c97j/GHSA-cw48-h2hv-c97j.json b/advisories/unreviewed/2022/05/GHSA-cw48-h2hv-c97j/GHSA-cw48-h2hv-c97j.json index c8c77718d33..4e0b2d11e35 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw48-h2hv-c97j/GHSA-cw48-h2hv-c97j.json +++ b/advisories/unreviewed/2022/05/GHSA-cw48-h2hv-c97j/GHSA-cw48-h2hv-c97j.json @@ -7,12 +7,8 @@ "CVE-2020-5131" ], "details": "SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 9.0.815 and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cwh6-w644-6v8q/GHSA-cwh6-w644-6v8q.json b/advisories/unreviewed/2022/05/GHSA-cwh6-w644-6v8q/GHSA-cwh6-w644-6v8q.json index f3852abdc4c..010df02d509 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwh6-w644-6v8q/GHSA-cwh6-w644-6v8q.json +++ b/advisories/unreviewed/2022/05/GHSA-cwh6-w644-6v8q/GHSA-cwh6-w644-6v8q.json @@ -7,12 +7,8 @@ "CVE-2020-1036" ], "details": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cx3p-94m9-cwxv/GHSA-cx3p-94m9-cwxv.json b/advisories/unreviewed/2022/05/GHSA-cx3p-94m9-cwxv/GHSA-cx3p-94m9-cwxv.json index c74b4d48ab4..0283c6e6bde 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx3p-94m9-cwxv/GHSA-cx3p-94m9-cwxv.json +++ b/advisories/unreviewed/2022/05/GHSA-cx3p-94m9-cwxv/GHSA-cx3p-94m9-cwxv.json @@ -7,12 +7,8 @@ "CVE-2020-1431" ], "details": "An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cx89-wvj2-xr57/GHSA-cx89-wvj2-xr57.json b/advisories/unreviewed/2022/05/GHSA-cx89-wvj2-xr57/GHSA-cx89-wvj2-xr57.json index 27cec988540..aa08d02f019 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx89-wvj2-xr57/GHSA-cx89-wvj2-xr57.json +++ b/advisories/unreviewed/2022/05/GHSA-cx89-wvj2-xr57/GHSA-cx89-wvj2-xr57.json @@ -7,12 +7,8 @@ "CVE-2020-1375" ], "details": "An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f35f-35hv-6fqx/GHSA-f35f-35hv-6fqx.json b/advisories/unreviewed/2022/05/GHSA-f35f-35hv-6fqx/GHSA-f35f-35hv-6fqx.json index cc223e02d7e..3a829b5d276 100644 --- a/advisories/unreviewed/2022/05/GHSA-f35f-35hv-6fqx/GHSA-f35f-35hv-6fqx.json +++ b/advisories/unreviewed/2022/05/GHSA-f35f-35hv-6fqx/GHSA-f35f-35hv-6fqx.json @@ -7,12 +7,8 @@ "CVE-2020-9670" ], "details": "Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f3ch-8xx9-vh6w/GHSA-f3ch-8xx9-vh6w.json b/advisories/unreviewed/2022/05/GHSA-f3ch-8xx9-vh6w/GHSA-f3ch-8xx9-vh6w.json index e6ea00fc849..ce64e180b3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3ch-8xx9-vh6w/GHSA-f3ch-8xx9-vh6w.json +++ b/advisories/unreviewed/2022/05/GHSA-f3ch-8xx9-vh6w/GHSA-f3ch-8xx9-vh6w.json @@ -7,12 +7,8 @@ "CVE-2020-3369" ], "details": "A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of FTP traffic. An attacker could exploit this vulnerability by sending crafted FTP packets through an affected device. A successful exploit could allow the attacker to make the device reboot continuously, causing a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f4hm-h8qw-mxvc/GHSA-f4hm-h8qw-mxvc.json b/advisories/unreviewed/2022/05/GHSA-f4hm-h8qw-mxvc/GHSA-f4hm-h8qw-mxvc.json index 8aaa1ffdae8..948194cad67 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4hm-h8qw-mxvc/GHSA-f4hm-h8qw-mxvc.json +++ b/advisories/unreviewed/2022/05/GHSA-f4hm-h8qw-mxvc/GHSA-f4hm-h8qw-mxvc.json @@ -7,12 +7,8 @@ "CVE-2020-1389" ], "details": "An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1419, CVE-2020-1426.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4j6-89m7-5455/GHSA-f4j6-89m7-5455.json b/advisories/unreviewed/2022/05/GHSA-f4j6-89m7-5455/GHSA-f4j6-89m7-5455.json index f812232f80a..793da51dc3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4j6-89m7-5455/GHSA-f4j6-89m7-5455.json +++ b/advisories/unreviewed/2022/05/GHSA-f4j6-89m7-5455/GHSA-f4j6-89m7-5455.json @@ -7,12 +7,8 @@ "CVE-2020-0231" ], "details": "There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156333727", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f65h-hwp6-2vff/GHSA-f65h-hwp6-2vff.json b/advisories/unreviewed/2022/05/GHSA-f65h-hwp6-2vff/GHSA-f65h-hwp6-2vff.json index 17eb0102c49..c2d24607e21 100644 --- a/advisories/unreviewed/2022/05/GHSA-f65h-hwp6-2vff/GHSA-f65h-hwp6-2vff.json +++ b/advisories/unreviewed/2022/05/GHSA-f65h-hwp6-2vff/GHSA-f65h-hwp6-2vff.json @@ -7,12 +7,8 @@ "CVE-2020-14662" ], "details": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f6v8-7355-p32v/GHSA-f6v8-7355-p32v.json b/advisories/unreviewed/2022/05/GHSA-f6v8-7355-p32v/GHSA-f6v8-7355-p32v.json index 49cbbb7c85e..b893c3ab25e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6v8-7355-p32v/GHSA-f6v8-7355-p32v.json +++ b/advisories/unreviewed/2022/05/GHSA-f6v8-7355-p32v/GHSA-f6v8-7355-p32v.json @@ -7,12 +7,8 @@ "CVE-2020-1267" ], "details": "This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Service Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f75r-mrmx-746p/GHSA-f75r-mrmx-746p.json b/advisories/unreviewed/2022/05/GHSA-f75r-mrmx-746p/GHSA-f75r-mrmx-746p.json index fc1cdc9b4a2..dd03475b219 100644 --- a/advisories/unreviewed/2022/05/GHSA-f75r-mrmx-746p/GHSA-f75r-mrmx-746p.json +++ b/advisories/unreviewed/2022/05/GHSA-f75r-mrmx-746p/GHSA-f75r-mrmx-746p.json @@ -7,12 +7,8 @@ "CVE-2020-1421" ], "details": "A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8wm-8xgf-589m/GHSA-f8wm-8xgf-589m.json b/advisories/unreviewed/2022/05/GHSA-f8wm-8xgf-589m/GHSA-f8wm-8xgf-589m.json index 7bd0dc91fd4..70d5d09276b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8wm-8xgf-589m/GHSA-f8wm-8xgf-589m.json +++ b/advisories/unreviewed/2022/05/GHSA-f8wm-8xgf-589m/GHSA-f8wm-8xgf-589m.json @@ -7,12 +7,8 @@ "CVE-2020-14530" ], "details": "Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: None). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Security Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Security Service accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f98w-46q5-27jx/GHSA-f98w-46q5-27jx.json b/advisories/unreviewed/2022/05/GHSA-f98w-46q5-27jx/GHSA-f98w-46q5-27jx.json index 473f206a74c..fe19e795ad0 100644 --- a/advisories/unreviewed/2022/05/GHSA-f98w-46q5-27jx/GHSA-f98w-46q5-27jx.json +++ b/advisories/unreviewed/2022/05/GHSA-f98w-46q5-27jx/GHSA-f98w-46q5-27jx.json @@ -7,12 +7,8 @@ "CVE-2020-1419" ], "details": "An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1426.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fc7c-rcm4-rg4c/GHSA-fc7c-rcm4-rg4c.json b/advisories/unreviewed/2022/05/GHSA-fc7c-rcm4-rg4c/GHSA-fc7c-rcm4-rg4c.json index 81df4302de7..68625390023 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc7c-rcm4-rg4c/GHSA-fc7c-rcm4-rg4c.json +++ b/advisories/unreviewed/2022/05/GHSA-fc7c-rcm4-rg4c/GHSA-fc7c-rcm4-rg4c.json @@ -7,12 +7,8 @@ "CVE-2020-2513" ], "details": "Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fc8w-q5c3-5m5f/GHSA-fc8w-q5c3-5m5f.json b/advisories/unreviewed/2022/05/GHSA-fc8w-q5c3-5m5f/GHSA-fc8w-q5c3-5m5f.json index 59470134496..3b84300ba92 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc8w-q5c3-5m5f/GHSA-fc8w-q5c3-5m5f.json +++ b/advisories/unreviewed/2022/05/GHSA-fc8w-q5c3-5m5f/GHSA-fc8w-q5c3-5m5f.json @@ -7,12 +7,8 @@ "CVE-2020-5758" ], "details": "Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's \"Old\" HTTPS API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ff89-95cf-8ph8/GHSA-ff89-95cf-8ph8.json b/advisories/unreviewed/2022/05/GHSA-ff89-95cf-8ph8/GHSA-ff89-95cf-8ph8.json index 8b84265fb6d..057eff45995 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff89-95cf-8ph8/GHSA-ff89-95cf-8ph8.json +++ b/advisories/unreviewed/2022/05/GHSA-ff89-95cf-8ph8/GHSA-ff89-95cf-8ph8.json @@ -7,12 +7,8 @@ "CVE-2020-7818" ], "details": "DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fg49-r89g-929j/GHSA-fg49-r89g-929j.json b/advisories/unreviewed/2022/05/GHSA-fg49-r89g-929j/GHSA-fg49-r89g-929j.json index 661c3da1f23..8780fab8795 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg49-r89g-929j/GHSA-fg49-r89g-929j.json +++ b/advisories/unreviewed/2022/05/GHSA-fg49-r89g-929j/GHSA-fg49-r89g-929j.json @@ -7,12 +7,8 @@ "CVE-2020-14602" ], "details": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data as well as unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fg77-pcc5-vccg/GHSA-fg77-pcc5-vccg.json b/advisories/unreviewed/2022/05/GHSA-fg77-pcc5-vccg/GHSA-fg77-pcc5-vccg.json index d27d91e8ca1..52fcd7b046a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg77-pcc5-vccg/GHSA-fg77-pcc5-vccg.json +++ b/advisories/unreviewed/2022/05/GHSA-fg77-pcc5-vccg/GHSA-fg77-pcc5-vccg.json @@ -7,12 +7,8 @@ "CVE-2020-2974" ], "details": "Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgp4-fc5g-6f22/GHSA-fgp4-fc5g-6f22.json b/advisories/unreviewed/2022/05/GHSA-fgp4-fc5g-6f22/GHSA-fgp4-fc5g-6f22.json index 6cd9ad28c0f..c8b5b64735e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgp4-fc5g-6f22/GHSA-fgp4-fc5g-6f22.json +++ b/advisories/unreviewed/2022/05/GHSA-fgp4-fc5g-6f22/GHSA-fgp4-fc5g-6f22.json @@ -7,12 +7,8 @@ "CVE-2020-14527" ], "details": "Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera Portfolio Management accessible data as well as unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgp5-4x9f-m743/GHSA-fgp5-4x9f-m743.json b/advisories/unreviewed/2022/05/GHSA-fgp5-4x9f-m743/GHSA-fgp5-4x9f-m743.json index 30a91feff21..df6eab79dbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgp5-4x9f-m743/GHSA-fgp5-4x9f-m743.json +++ b/advisories/unreviewed/2022/05/GHSA-fgp5-4x9f-m743/GHSA-fgp5-4x9f-m743.json @@ -7,12 +7,8 @@ "CVE-2020-14658" ], "details": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Marketing accessible data as well as unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fh59-cj56-8q9p/GHSA-fh59-cj56-8q9p.json b/advisories/unreviewed/2022/05/GHSA-fh59-cj56-8q9p/GHSA-fh59-cj56-8q9p.json index 7d485613083..222e77d5792 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh59-cj56-8q9p/GHSA-fh59-cj56-8q9p.json +++ b/advisories/unreviewed/2022/05/GHSA-fh59-cj56-8q9p/GHSA-fh59-cj56-8q9p.json @@ -7,12 +7,8 @@ "CVE-2020-3332" ], "details": "A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device. The vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary shell commands or scripts with root privileges on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fh77-2jcj-5hq7/GHSA-fh77-2jcj-5hq7.json b/advisories/unreviewed/2022/05/GHSA-fh77-2jcj-5hq7/GHSA-fh77-2jcj-5hq7.json index 1e6608a5038..eafa31899dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh77-2jcj-5hq7/GHSA-fh77-2jcj-5hq7.json +++ b/advisories/unreviewed/2022/05/GHSA-fh77-2jcj-5hq7/GHSA-fh77-2jcj-5hq7.json @@ -7,12 +7,8 @@ "CVE-2020-14681" ], "details": "Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: DBI Setups). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle E-Business Intelligence, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data as well as unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhfv-jf9p-qv4g/GHSA-fhfv-jf9p-qv4g.json b/advisories/unreviewed/2022/05/GHSA-fhfv-jf9p-qv4g/GHSA-fhfv-jf9p-qv4g.json index 84f73b38369..27437e82002 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhfv-jf9p-qv4g/GHSA-fhfv-jf9p-qv4g.json +++ b/advisories/unreviewed/2022/05/GHSA-fhfv-jf9p-qv4g/GHSA-fhfv-jf9p-qv4g.json @@ -7,12 +7,8 @@ "CVE-2020-4371" ], "details": "IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a local user in further attacks against the system. IBM X-Force ID: 179008.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fjjv-vm6w-5mgj/GHSA-fjjv-vm6w-5mgj.json b/advisories/unreviewed/2022/05/GHSA-fjjv-vm6w-5mgj/GHSA-fjjv-vm6w-5mgj.json index d7193650097..d38782dde27 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjjv-vm6w-5mgj/GHSA-fjjv-vm6w-5mgj.json +++ b/advisories/unreviewed/2022/05/GHSA-fjjv-vm6w-5mgj/GHSA-fjjv-vm6w-5mgj.json @@ -7,12 +7,8 @@ "CVE-2020-14598" ], "details": "Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway for Mobile Devices. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Gateway for Mobile Devices accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Gateway for Mobile Devices accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fjvc-pwrq-34wq/GHSA-fjvc-pwrq-34wq.json b/advisories/unreviewed/2022/05/GHSA-fjvc-pwrq-34wq/GHSA-fjvc-pwrq-34wq.json index 60279130200..dd95a2e45a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjvc-pwrq-34wq/GHSA-fjvc-pwrq-34wq.json +++ b/advisories/unreviewed/2022/05/GHSA-fjvc-pwrq-34wq/GHSA-fjvc-pwrq-34wq.json @@ -7,12 +7,8 @@ "CVE-2020-3450" ], "details": "A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative credentials to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the web-based management interface and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain data that is stored in the underlying database, including hashed user credentials. To exploit this vulnerability, an attacker would need valid administrative credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmgx-83vj-44hh/GHSA-fmgx-83vj-44hh.json b/advisories/unreviewed/2022/05/GHSA-fmgx-83vj-44hh/GHSA-fmgx-83vj-44hh.json index d6212c5a913..3e02362a9e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmgx-83vj-44hh/GHSA-fmgx-83vj-44hh.json +++ b/advisories/unreviewed/2022/05/GHSA-fmgx-83vj-44hh/GHSA-fmgx-83vj-44hh.json @@ -7,12 +7,8 @@ "CVE-2020-14546" ], "details": "Vulnerability in the Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Close Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Hyperion Financial Close Management accessible data. CVSS 3.1 Base Score 4.2 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmj5-xxrq-8cg3/GHSA-fmj5-xxrq-8cg3.json b/advisories/unreviewed/2022/05/GHSA-fmj5-xxrq-8cg3/GHSA-fmj5-xxrq-8cg3.json index 356835c0800..2cb8595bc74 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmj5-xxrq-8cg3/GHSA-fmj5-xxrq-8cg3.json +++ b/advisories/unreviewed/2022/05/GHSA-fmj5-xxrq-8cg3/GHSA-fmj5-xxrq-8cg3.json @@ -7,12 +7,8 @@ "CVE-2020-14719" ], "details": "Vulnerability in the Oracle Internet Expenses product of Oracle E-Business Suite (component: Mobile Expenses Admin Utilities). Supported versions that are affected are 12.2.4-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Internet Expenses. While the vulnerability is in Oracle Internet Expenses, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Expenses accessible data. CVSS 3.1 Base Score 7.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpxw-h673-x56j/GHSA-fpxw-h673-x56j.json b/advisories/unreviewed/2022/05/GHSA-fpxw-h673-x56j/GHSA-fpxw-h673-x56j.json index aafaf3de18e..10562f50d8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpxw-h673-x56j/GHSA-fpxw-h673-x56j.json +++ b/advisories/unreviewed/2022/05/GHSA-fpxw-h673-x56j/GHSA-fpxw-h673-x56j.json @@ -7,12 +7,8 @@ "CVE-2020-14491" ], "details": "OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to access privileged information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fqx8-r72c-v8q3/GHSA-fqx8-r72c-v8q3.json b/advisories/unreviewed/2022/05/GHSA-fqx8-r72c-v8q3/GHSA-fqx8-r72c-v8q3.json index cb33157ea78..f24165bd714 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqx8-r72c-v8q3/GHSA-fqx8-r72c-v8q3.json +++ b/advisories/unreviewed/2022/05/GHSA-fqx8-r72c-v8q3/GHSA-fqx8-r72c-v8q3.json @@ -7,12 +7,8 @@ "CVE-2020-15053" ], "details": "An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System Events, Proxy Events, Proxy Objects, and Firewall objects.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frm2-v695-xcw7/GHSA-frm2-v695-xcw7.json b/advisories/unreviewed/2022/05/GHSA-frm2-v695-xcw7/GHSA-frm2-v695-xcw7.json index 2f63720a14c..270929b549b 100644 --- a/advisories/unreviewed/2022/05/GHSA-frm2-v695-xcw7/GHSA-frm2-v695-xcw7.json +++ b/advisories/unreviewed/2022/05/GHSA-frm2-v695-xcw7/GHSA-frm2-v695-xcw7.json @@ -7,12 +7,8 @@ "CVE-2020-1370" ], "details": "An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frqw-rmjg-h7x3/GHSA-frqw-rmjg-h7x3.json b/advisories/unreviewed/2022/05/GHSA-frqw-rmjg-h7x3/GHSA-frqw-rmjg-h7x3.json index 86c299b0643..57a9f1f9c91 100644 --- a/advisories/unreviewed/2022/05/GHSA-frqw-rmjg-h7x3/GHSA-frqw-rmjg-h7x3.json +++ b/advisories/unreviewed/2022/05/GHSA-frqw-rmjg-h7x3/GHSA-frqw-rmjg-h7x3.json @@ -7,12 +7,8 @@ "CVE-2020-1465" ], "details": "An elevation of privilege vulnerability exists in Microsoft OneDrive that allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft OneDrive Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv6p-x8x2-5jcc/GHSA-fv6p-x8x2-5jcc.json b/advisories/unreviewed/2022/05/GHSA-fv6p-x8x2-5jcc/GHSA-fv6p-x8x2-5jcc.json index 2a820a598b7..493292b1c72 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv6p-x8x2-5jcc/GHSA-fv6p-x8x2-5jcc.json +++ b/advisories/unreviewed/2022/05/GHSA-fv6p-x8x2-5jcc/GHSA-fv6p-x8x2-5jcc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw45-wg5f-8735/GHSA-fw45-wg5f-8735.json b/advisories/unreviewed/2022/05/GHSA-fw45-wg5f-8735/GHSA-fw45-wg5f-8735.json index 333d47c788c..758ebe709e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw45-wg5f-8735/GHSA-fw45-wg5f-8735.json +++ b/advisories/unreviewed/2022/05/GHSA-fw45-wg5f-8735/GHSA-fw45-wg5f-8735.json @@ -7,12 +7,8 @@ "CVE-2020-9255" ], "details": "Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4) have a denial of service vulnerability. Certain service in the system does not sufficiently validate certain parameter which is received, the attacker should trick the user into installing a malicious application, successful exploit could cause a denial of service condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fw7j-849m-mpv4/GHSA-fw7j-849m-mpv4.json b/advisories/unreviewed/2022/05/GHSA-fw7j-849m-mpv4/GHSA-fw7j-849m-mpv4.json index faef64d4479..ce3dc624377 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw7j-849m-mpv4/GHSA-fw7j-849m-mpv4.json +++ b/advisories/unreviewed/2022/05/GHSA-fw7j-849m-mpv4/GHSA-fw7j-849m-mpv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwh4-xh88-xxmp/GHSA-fwh4-xh88-xxmp.json b/advisories/unreviewed/2022/05/GHSA-fwh4-xh88-xxmp/GHSA-fwh4-xh88-xxmp.json index 7ce71514549..ecc3e459d13 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwh4-xh88-xxmp/GHSA-fwh4-xh88-xxmp.json +++ b/advisories/unreviewed/2022/05/GHSA-fwh4-xh88-xxmp/GHSA-fwh4-xh88-xxmp.json @@ -7,12 +7,8 @@ "CVE-2020-14609" ], "details": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Answers). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fx28-fjmc-jx5r/GHSA-fx28-fjmc-jx5r.json b/advisories/unreviewed/2022/05/GHSA-fx28-fjmc-jx5r/GHSA-fx28-fjmc-jx5r.json index d339ec87531..c37eeb219a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx28-fjmc-jx5r/GHSA-fx28-fjmc-jx5r.json +++ b/advisories/unreviewed/2022/05/GHSA-fx28-fjmc-jx5r/GHSA-fx28-fjmc-jx5r.json @@ -7,12 +7,8 @@ "CVE-2020-1393" ], "details": "An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1418.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2m6-f6m6-qjg5/GHSA-g2m6-f6m6-qjg5.json b/advisories/unreviewed/2022/05/GHSA-g2m6-f6m6-qjg5/GHSA-g2m6-f6m6-qjg5.json index 7489f35e757..a95663df520 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2m6-f6m6-qjg5/GHSA-g2m6-f6m6-qjg5.json +++ b/advisories/unreviewed/2022/05/GHSA-g2m6-f6m6-qjg5/GHSA-g2m6-f6m6-qjg5.json @@ -7,12 +7,8 @@ "CVE-2020-14704" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3r4-m5pw-xpp9/GHSA-g3r4-m5pw-xpp9.json b/advisories/unreviewed/2022/05/GHSA-g3r4-m5pw-xpp9/GHSA-g3r4-m5pw-xpp9.json index d041ec5cd2b..5ef9e5ca239 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3r4-m5pw-xpp9/GHSA-g3r4-m5pw-xpp9.json +++ b/advisories/unreviewed/2022/05/GHSA-g3r4-m5pw-xpp9/GHSA-g3r4-m5pw-xpp9.json @@ -7,12 +7,8 @@ "CVE-2020-14552" ], "details": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g464-q8qp-3vg4/GHSA-g464-q8qp-3vg4.json b/advisories/unreviewed/2022/05/GHSA-g464-q8qp-3vg4/GHSA-g464-q8qp-3vg4.json index 1c9735b349c..9127f79f70d 100644 --- a/advisories/unreviewed/2022/05/GHSA-g464-q8qp-3vg4/GHSA-g464-q8qp-3vg4.json +++ b/advisories/unreviewed/2022/05/GHSA-g464-q8qp-3vg4/GHSA-g464-q8qp-3vg4.json @@ -7,12 +7,8 @@ "CVE-2020-1655" ], "details": "When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and IPIP, the packet forwarding engine (PFE) will become disabled upon receipt of large packets requiring fragmentation, generating the following error messages: [LOG: Err] MQSS(0): WO: Packet Error - Error Packets 1, Connection 29 [LOG: Err] eachip_hmcif_rx_intr_handler(7259): EA[0:0]: HMCIF Rx: Injected checksum error detected on WO response - Chunk Address 0x0 [LOG: Err] MQSS(0): DRD: RORD1: CMD reorder ID error - Command 11, Reorder ID 1838, QID 0 [LOG: Err] MQSS(0): DRD: UNROLL0: HMC chunk length error in stage 5 - Chunk Address: 0x4321f3 [LOG: Err] MQSS(0): DRD: UNROLL0: HMC chunk address error in stage 5 - Chunk Address: 0x0 [LOG: Notice] Error: /fpc/8/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_DRD_RORD_ENG_INT_REG_CMD_FSM_STATE_ERR (0x2203cc), scope: pfe, category: functional, severity: major, module: MQSS(0), type: DRD_RORD_ENG_INT: CMD FSM State Error [LOG: Notice] Performing action cmalarm for error /fpc/8/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_DRD_RORD_ENG_INT_REG_CMD_FSM_STATE_ERR (0x2203cc) in module: MQSS(0) with scope: pfe category: functional level: major [LOG: Notice] Performing action get-state for error /fpc/8/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_DRD_RORD_ENG_INT_REG_CMD_FSM_STATE_ERR (0x2203cc) in module: MQSS(0) with scope: pfe category: functional level: major [LOG: Notice] Performing action disable-pfe for error /fpc/8/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_DRD_RORD_ENG_INT_REG_CMD_FSM_STATE_ERR (0x2203cc) in module: MQSS(0) with scope: pfe category: functional level: major By continuously sending fragmented packets that cannot be reassembled, an attacker can repeatedly disable the PFE causing a sustained Denial of Service (DoS). This issue affects Juniper Networks Junos OS: 17.2 versions prior to 17.2R3-S4 on MX Series; 17.3 versions prior to 17.3R3-S8 on MX Series; 17.4 versions prior to 17.4R2-S10, 17.4R3-S2 on MX Series; 18.1 versions prior to 18.1R3-S10 on MX Series; 18.2 versions prior to 18.2R3-S3 on MX Series; 18.2X75 versions prior to 18.2X75-D41, 18.2X75-D430, 18.2X75-D65 on MX Series; 18.3 versions prior to 18.3R1-S7, 18.3R2-S4, 18.3R3-S1 on MX Series; 18.4 versions prior to 18.4R1-S7, 18.4R2-S4, 18.4R3 on MX Series; 19.1 versions prior to 19.1R1-S5, 19.1R2-S1, 19.1R3 on MX Series; 19.2 versions prior to 19.2R1-S4, 19.2R2 on MX Series; 19.3 versions prior to 19.3R2-S2, 19.3R3 on MX Series. This issue is specific to inline IP reassembly, introduced in Junos OS 17.2. Versions of Junos OS prior to 17.2 are unaffected by this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g4pp-mvp2-qf9j/GHSA-g4pp-mvp2-qf9j.json b/advisories/unreviewed/2022/05/GHSA-g4pp-mvp2-qf9j/GHSA-g4pp-mvp2-qf9j.json index ee28f13d8ec..afa8efb8057 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4pp-mvp2-qf9j/GHSA-g4pp-mvp2-qf9j.json +++ b/advisories/unreviewed/2022/05/GHSA-g4pp-mvp2-qf9j/GHSA-g4pp-mvp2-qf9j.json @@ -7,12 +7,8 @@ "CVE-2020-10039" ], "details": "A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker in a privileged network position between a legitimate user and the web server might be able to conduct a Man-in-the-middle attack and gain read and write access to the transmitted data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g587-x8m2-frwg/GHSA-g587-x8m2-frwg.json b/advisories/unreviewed/2022/05/GHSA-g587-x8m2-frwg/GHSA-g587-x8m2-frwg.json index 73e5c8b1f77..6a45f5983a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-g587-x8m2-frwg/GHSA-g587-x8m2-frwg.json +++ b/advisories/unreviewed/2022/05/GHSA-g587-x8m2-frwg/GHSA-g587-x8m2-frwg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5ww-c573-jq43/GHSA-g5ww-c573-jq43.json b/advisories/unreviewed/2022/05/GHSA-g5ww-c573-jq43/GHSA-g5ww-c573-jq43.json index d3deb119b74..7f063dcad59 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5ww-c573-jq43/GHSA-g5ww-c573-jq43.json +++ b/advisories/unreviewed/2022/05/GHSA-g5ww-c573-jq43/GHSA-g5ww-c573-jq43.json @@ -7,12 +7,8 @@ "CVE-2020-14679" ], "details": "Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle CRM Technical Foundation. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g655-76mw-qxpx/GHSA-g655-76mw-qxpx.json b/advisories/unreviewed/2022/05/GHSA-g655-76mw-qxpx/GHSA-g655-76mw-qxpx.json index df6db6401fe..563e57e12f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g655-76mw-qxpx/GHSA-g655-76mw-qxpx.json +++ b/advisories/unreviewed/2022/05/GHSA-g655-76mw-qxpx/GHSA-g655-76mw-qxpx.json @@ -7,12 +7,8 @@ "CVE-2020-1450" ], "details": "A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1451, CVE-2020-1456.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g66h-pm5j-hvrm/GHSA-g66h-pm5j-hvrm.json b/advisories/unreviewed/2022/05/GHSA-g66h-pm5j-hvrm/GHSA-g66h-pm5j-hvrm.json index c11cf1e3b1b..14e9fd1c335 100644 --- a/advisories/unreviewed/2022/05/GHSA-g66h-pm5j-hvrm/GHSA-g66h-pm5j-hvrm.json +++ b/advisories/unreviewed/2022/05/GHSA-g66h-pm5j-hvrm/GHSA-g66h-pm5j-hvrm.json @@ -7,12 +7,8 @@ "CVE-2020-1433" ], "details": "An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g672-q742-m6vg/GHSA-g672-q742-m6vg.json b/advisories/unreviewed/2022/05/GHSA-g672-q742-m6vg/GHSA-g672-q742-m6vg.json index 91931cda42c..62181e428f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g672-q742-m6vg/GHSA-g672-q742-m6vg.json +++ b/advisories/unreviewed/2022/05/GHSA-g672-q742-m6vg/GHSA-g672-q742-m6vg.json @@ -7,12 +7,8 @@ "CVE-2020-15602" ], "details": "An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from its current directory, an arbitrary DLL could also be loaded with the same privileges as the installer if run as Administrator. User interaction is required to exploit the vulnerbaility in that the target must open a malicious directory or device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g69r-p4mx-3r83/GHSA-g69r-p4mx-3r83.json b/advisories/unreviewed/2022/05/GHSA-g69r-p4mx-3r83/GHSA-g69r-p4mx-3r83.json index 008ba76647c..2fc7c670bc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g69r-p4mx-3r83/GHSA-g69r-p4mx-3r83.json +++ b/advisories/unreviewed/2022/05/GHSA-g69r-p4mx-3r83/GHSA-g69r-p4mx-3r83.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6x5-mv8j-5pq8/GHSA-g6x5-mv8j-5pq8.json b/advisories/unreviewed/2022/05/GHSA-g6x5-mv8j-5pq8/GHSA-g6x5-mv8j-5pq8.json index 16d3dca6e1f..94429e2b890 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6x5-mv8j-5pq8/GHSA-g6x5-mv8j-5pq8.json +++ b/advisories/unreviewed/2022/05/GHSA-g6x5-mv8j-5pq8/GHSA-g6x5-mv8j-5pq8.json @@ -7,12 +7,8 @@ "CVE-2020-10043" ], "details": "A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8gr-9g9f-c52h/GHSA-g8gr-9g9f-c52h.json b/advisories/unreviewed/2022/05/GHSA-g8gr-9g9f-c52h/GHSA-g8gr-9g9f-c52h.json index d5e681cc3a0..33d52883256 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8gr-9g9f-c52h/GHSA-g8gr-9g9f-c52h.json +++ b/advisories/unreviewed/2022/05/GHSA-g8gr-9g9f-c52h/GHSA-g8gr-9g9f-c52h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8qr-xv6v-97fw/GHSA-g8qr-xv6v-97fw.json b/advisories/unreviewed/2022/05/GHSA-g8qr-xv6v-97fw/GHSA-g8qr-xv6v-97fw.json index 547e4e0ec21..e886c33b0ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8qr-xv6v-97fw/GHSA-g8qr-xv6v-97fw.json +++ b/advisories/unreviewed/2022/05/GHSA-g8qr-xv6v-97fw/GHSA-g8qr-xv6v-97fw.json @@ -7,12 +7,8 @@ "CVE-2020-1405" ], "details": "An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1372.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8x9-c837-mpx5/GHSA-g8x9-c837-mpx5.json b/advisories/unreviewed/2022/05/GHSA-g8x9-c837-mpx5/GHSA-g8x9-c837-mpx5.json index de687b11f1d..64d78ee9dc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8x9-c837-mpx5/GHSA-g8x9-c837-mpx5.json +++ b/advisories/unreviewed/2022/05/GHSA-g8x9-c837-mpx5/GHSA-g8x9-c837-mpx5.json @@ -7,12 +7,8 @@ "CVE-2020-15027" ], "details": "ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g9mj-m82f-cqc8/GHSA-g9mj-m82f-cqc8.json b/advisories/unreviewed/2022/05/GHSA-g9mj-m82f-cqc8/GHSA-g9mj-m82f-cqc8.json index 498ef259f5f..afee4c53066 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9mj-m82f-cqc8/GHSA-g9mj-m82f-cqc8.json +++ b/advisories/unreviewed/2022/05/GHSA-g9mj-m82f-cqc8/GHSA-g9mj-m82f-cqc8.json @@ -7,12 +7,8 @@ "CVE-2020-14627" ], "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gg7c-xf3j-7669/GHSA-gg7c-xf3j-7669.json b/advisories/unreviewed/2022/05/GHSA-gg7c-xf3j-7669/GHSA-gg7c-xf3j-7669.json index 5c62989aced..e0c43b4a5d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg7c-xf3j-7669/GHSA-gg7c-xf3j-7669.json +++ b/advisories/unreviewed/2022/05/GHSA-gg7c-xf3j-7669/GHSA-gg7c-xf3j-7669.json @@ -7,12 +7,8 @@ "CVE-2020-9649" ], "details": "Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gh8m-4j9x-6g55/GHSA-gh8m-4j9x-6g55.json b/advisories/unreviewed/2022/05/GHSA-gh8m-4j9x-6g55/GHSA-gh8m-4j9x-6g55.json index 2f30e328bf7..5b88dfb5b12 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh8m-4j9x-6g55/GHSA-gh8m-4j9x-6g55.json +++ b/advisories/unreviewed/2022/05/GHSA-gh8m-4j9x-6g55/GHSA-gh8m-4j9x-6g55.json @@ -7,12 +7,8 @@ "CVE-2020-14693" ], "details": "Vulnerability in the Oracle Insurance Accounting Analyzer product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6-8.0.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Accounting Analyzer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Accounting Analyzer accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ghw7-5298-r4fj/GHSA-ghw7-5298-r4fj.json b/advisories/unreviewed/2022/05/GHSA-ghw7-5298-r4fj/GHSA-ghw7-5298-r4fj.json index 98d5eee1b7a..02882a3439d 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghw7-5298-r4fj/GHSA-ghw7-5298-r4fj.json +++ b/advisories/unreviewed/2022/05/GHSA-ghw7-5298-r4fj/GHSA-ghw7-5298-r4fj.json @@ -7,12 +7,8 @@ "CVE-2020-14652" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjqw-r32j-j6wq/GHSA-gjqw-r32j-j6wq.json b/advisories/unreviewed/2022/05/GHSA-gjqw-r32j-j6wq/GHSA-gjqw-r32j-j6wq.json index 5137094cea8..9ca4aa470f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjqw-r32j-j6wq/GHSA-gjqw-r32j-j6wq.json +++ b/advisories/unreviewed/2022/05/GHSA-gjqw-r32j-j6wq/GHSA-gjqw-r32j-j6wq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpcg-4vgv-2224/GHSA-gpcg-4vgv-2224.json b/advisories/unreviewed/2022/05/GHSA-gpcg-4vgv-2224/GHSA-gpcg-4vgv-2224.json index a73ad864a0d..aece83f815b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpcg-4vgv-2224/GHSA-gpcg-4vgv-2224.json +++ b/advisories/unreviewed/2022/05/GHSA-gpcg-4vgv-2224/GHSA-gpcg-4vgv-2224.json @@ -7,12 +7,8 @@ "CVE-2020-0230" ], "details": "There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156337262", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gphc-f36c-q273/GHSA-gphc-f36c-q273.json b/advisories/unreviewed/2022/05/GHSA-gphc-f36c-q273/GHSA-gphc-f36c-q273.json index 2c9884fdf08..5b39be63780 100644 --- a/advisories/unreviewed/2022/05/GHSA-gphc-f36c-q273/GHSA-gphc-f36c-q273.json +++ b/advisories/unreviewed/2022/05/GHSA-gphc-f36c-q273/GHSA-gphc-f36c-q273.json @@ -7,12 +7,8 @@ "CVE-2020-4361" ], "details": "IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addresses in HTTP responses. IBM X-Force ID: 178766.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gq32-8f5q-75g2/GHSA-gq32-8f5q-75g2.json b/advisories/unreviewed/2022/05/GHSA-gq32-8f5q-75g2/GHSA-gq32-8f5q-75g2.json index ad7ec939980..6e696683747 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq32-8f5q-75g2/GHSA-gq32-8f5q-75g2.json +++ b/advisories/unreviewed/2022/05/GHSA-gq32-8f5q-75g2/GHSA-gq32-8f5q-75g2.json @@ -7,12 +7,8 @@ "CVE-2020-1360" ], "details": "An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles file operations, aka 'Windows Profile Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqc3-253j-25g7/GHSA-gqc3-253j-25g7.json b/advisories/unreviewed/2022/05/GHSA-gqc3-253j-25g7/GHSA-gqc3-253j-25g7.json index 219877ec654..89405683db2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqc3-253j-25g7/GHSA-gqc3-253j-25g7.json +++ b/advisories/unreviewed/2022/05/GHSA-gqc3-253j-25g7/GHSA-gqc3-253j-25g7.json @@ -7,12 +7,8 @@ "CVE-2020-1351" ], "details": "An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqf3-7r7j-gmrf/GHSA-gqf3-7r7j-gmrf.json b/advisories/unreviewed/2022/05/GHSA-gqf3-7r7j-gmrf/GHSA-gqf3-7r7j-gmrf.json index 7f36aef81bc..df78828f9c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqf3-7r7j-gmrf/GHSA-gqf3-7r7j-gmrf.json +++ b/advisories/unreviewed/2022/05/GHSA-gqf3-7r7j-gmrf/GHSA-gqf3-7r7j-gmrf.json @@ -7,12 +7,8 @@ "CVE-2020-6872" ], "details": "The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqq2-f4ch-q2pw/GHSA-gqq2-f4ch-q2pw.json b/advisories/unreviewed/2022/05/GHSA-gqq2-f4ch-q2pw/GHSA-gqq2-f4ch-q2pw.json index a8bd80afb83..547932909e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqq2-f4ch-q2pw/GHSA-gqq2-f4ch-q2pw.json +++ b/advisories/unreviewed/2022/05/GHSA-gqq2-f4ch-q2pw/GHSA-gqq2-f4ch-q2pw.json @@ -7,12 +7,8 @@ "CVE-2020-2976" ], "details": "Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqr3-72h3-gh3f/GHSA-gqr3-72h3-gh3f.json b/advisories/unreviewed/2022/05/GHSA-gqr3-72h3-gh3f/GHSA-gqr3-72h3-gh3f.json index 7778f1c833c..e85a853d682 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqr3-72h3-gh3f/GHSA-gqr3-72h3-gh3f.json +++ b/advisories/unreviewed/2022/05/GHSA-gqr3-72h3-gh3f/GHSA-gqr3-72h3-gh3f.json @@ -7,12 +7,8 @@ "CVE-2020-14582" ], "details": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Registration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr25-37rj-jwmm/GHSA-gr25-37rj-jwmm.json b/advisories/unreviewed/2022/05/GHSA-gr25-37rj-jwmm/GHSA-gr25-37rj-jwmm.json index e31a469c549..a5b9578911e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr25-37rj-jwmm/GHSA-gr25-37rj-jwmm.json +++ b/advisories/unreviewed/2022/05/GHSA-gr25-37rj-jwmm/GHSA-gr25-37rj-jwmm.json @@ -7,12 +7,8 @@ "CVE-2020-14499" ], "details": "Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-grj8-px67-9rpf/GHSA-grj8-px67-9rpf.json b/advisories/unreviewed/2022/05/GHSA-grj8-px67-9rpf/GHSA-grj8-px67-9rpf.json index a9ac507185b..6f770e06c09 100644 --- a/advisories/unreviewed/2022/05/GHSA-grj8-px67-9rpf/GHSA-grj8-px67-9rpf.json +++ b/advisories/unreviewed/2022/05/GHSA-grj8-px67-9rpf/GHSA-grj8-px67-9rpf.json @@ -7,12 +7,8 @@ "CVE-2020-14563" ], "details": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Communications Broker, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Communications Broker accessible data as well as unauthorized read access to a subset of Oracle Enterprise Communications Broker accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gv84-p8rq-pwr4/GHSA-gv84-p8rq-pwr4.json b/advisories/unreviewed/2022/05/GHSA-gv84-p8rq-pwr4/GHSA-gv84-p8rq-pwr4.json index 361b5565217..acb69c71b50 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv84-p8rq-pwr4/GHSA-gv84-p8rq-pwr4.json +++ b/advisories/unreviewed/2022/05/GHSA-gv84-p8rq-pwr4/GHSA-gv84-p8rq-pwr4.json @@ -7,12 +7,8 @@ "CVE-2020-1458" ], "details": "A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvgq-x76m-m83j/GHSA-gvgq-x76m-m83j.json b/advisories/unreviewed/2022/05/GHSA-gvgq-x76m-m83j/GHSA-gvgq-x76m-m83j.json index 77a7f0a8ffd..3a16baab2ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvgq-x76m-m83j/GHSA-gvgq-x76m-m83j.json +++ b/advisories/unreviewed/2022/05/GHSA-gvgq-x76m-m83j/GHSA-gvgq-x76m-m83j.json @@ -7,12 +7,8 @@ "CVE-2020-1444" ], "details": "A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwv8-m93q-xcpc/GHSA-gwv8-m93q-xcpc.json b/advisories/unreviewed/2022/05/GHSA-gwv8-m93q-xcpc/GHSA-gwv8-m93q-xcpc.json index 6b94235beb6..ad938274817 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwv8-m93q-xcpc/GHSA-gwv8-m93q-xcpc.json +++ b/advisories/unreviewed/2022/05/GHSA-gwv8-m93q-xcpc/GHSA-gwv8-m93q-xcpc.json @@ -7,12 +7,8 @@ "CVE-2020-14637" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gx29-r9g9-prgp/GHSA-gx29-r9g9-prgp.json b/advisories/unreviewed/2022/05/GHSA-gx29-r9g9-prgp/GHSA-gx29-r9g9-prgp.json index 5e83e3b1108..4c73f6ca5d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx29-r9g9-prgp/GHSA-gx29-r9g9-prgp.json +++ b/advisories/unreviewed/2022/05/GHSA-gx29-r9g9-prgp/GHSA-gx29-r9g9-prgp.json @@ -7,12 +7,8 @@ "CVE-2020-2977" ], "details": "Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h23m-44mr-9m6c/GHSA-h23m-44mr-9m6c.json b/advisories/unreviewed/2022/05/GHSA-h23m-44mr-9m6c/GHSA-h23m-44mr-9m6c.json index 40fbdc45b7a..4d36c8cf3b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-h23m-44mr-9m6c/GHSA-h23m-44mr-9m6c.json +++ b/advisories/unreviewed/2022/05/GHSA-h23m-44mr-9m6c/GHSA-h23m-44mr-9m6c.json @@ -7,12 +7,8 @@ "CVE-2020-6285" ], "details": "SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h282-h9wq-4cqg/GHSA-h282-h9wq-4cqg.json b/advisories/unreviewed/2022/05/GHSA-h282-h9wq-4cqg/GHSA-h282-h9wq-4cqg.json index b9ed453d95d..eb498ef5911 100644 --- a/advisories/unreviewed/2022/05/GHSA-h282-h9wq-4cqg/GHSA-h282-h9wq-4cqg.json +++ b/advisories/unreviewed/2022/05/GHSA-h282-h9wq-4cqg/GHSA-h282-h9wq-4cqg.json @@ -7,12 +7,8 @@ "CVE-2020-1463" ], "details": "An elevation of privilege vulnerability exists in the way that the SharedStream Library handles objects in memory, aka 'Windows SharedStream Library Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3cg-q59m-96g4/GHSA-h3cg-q59m-96g4.json b/advisories/unreviewed/2022/05/GHSA-h3cg-q59m-96g4/GHSA-h3cg-q59m-96g4.json index 533381c6824..43ac85cbfcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3cg-q59m-96g4/GHSA-h3cg-q59m-96g4.json +++ b/advisories/unreviewed/2022/05/GHSA-h3cg-q59m-96g4/GHSA-h3cg-q59m-96g4.json @@ -7,12 +7,8 @@ "CVE-2020-1366" ], "details": "An elevation of privilege vulnerability exists when the Windows Print Workflow Service improperly handles objects in memory, aka 'Windows Print Workflow Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4rm-8p4f-gfh7/GHSA-h4rm-8p4f-gfh7.json b/advisories/unreviewed/2022/05/GHSA-h4rm-8p4f-gfh7/GHSA-h4rm-8p4f-gfh7.json index e24f533f162..47febb47908 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4rm-8p4f-gfh7/GHSA-h4rm-8p4f-gfh7.json +++ b/advisories/unreviewed/2022/05/GHSA-h4rm-8p4f-gfh7/GHSA-h4rm-8p4f-gfh7.json @@ -7,12 +7,8 @@ "CVE-2020-1407" ], "details": "A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1401.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5j6-53fx-wcr7/GHSA-h5j6-53fx-wcr7.json b/advisories/unreviewed/2022/05/GHSA-h5j6-53fx-wcr7/GHSA-h5j6-53fx-wcr7.json index 0af3751bfa2..2f6695a6cd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5j6-53fx-wcr7/GHSA-h5j6-53fx-wcr7.json +++ b/advisories/unreviewed/2022/05/GHSA-h5j6-53fx-wcr7/GHSA-h5j6-53fx-wcr7.json @@ -7,12 +7,8 @@ "CVE-2020-9646" ], "details": "Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5xc-3wh4-4q43/GHSA-h5xc-3wh4-4q43.json b/advisories/unreviewed/2022/05/GHSA-h5xc-3wh4-4q43/GHSA-h5xc-3wh4-4q43.json index 99410082a9e..5a733e9f1de 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5xc-3wh4-4q43/GHSA-h5xc-3wh4-4q43.json +++ b/advisories/unreviewed/2022/05/GHSA-h5xc-3wh4-4q43/GHSA-h5xc-3wh4-4q43.json @@ -7,12 +7,8 @@ "CVE-2020-11955" ], "details": "An issue was discovered on Rittal PDU-3C002DEC through 5.15.70 and CMCIII-PU-9333E0FB through 3.15.70 devices. There are insecure permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6fx-jmr6-xg2g/GHSA-h6fx-jmr6-xg2g.json b/advisories/unreviewed/2022/05/GHSA-h6fx-jmr6-xg2g/GHSA-h6fx-jmr6-xg2g.json index c034b244ac0..8c4597f21c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6fx-jmr6-xg2g/GHSA-h6fx-jmr6-xg2g.json +++ b/advisories/unreviewed/2022/05/GHSA-h6fx-jmr6-xg2g/GHSA-h6fx-jmr6-xg2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hccp-6fqj-76m5/GHSA-hccp-6fqj-76m5.json b/advisories/unreviewed/2022/05/GHSA-hccp-6fqj-76m5/GHSA-hccp-6fqj-76m5.json index 642949f8150..4ec7a2b0843 100644 --- a/advisories/unreviewed/2022/05/GHSA-hccp-6fqj-76m5/GHSA-hccp-6fqj-76m5.json +++ b/advisories/unreviewed/2022/05/GHSA-hccp-6fqj-76m5/GHSA-hccp-6fqj-76m5.json @@ -7,12 +7,8 @@ "CVE-2019-12000" ], "details": "HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3.2 and update the HTTPS configuration as described in the HPE MSE Messaging Gateway Configuration and Operations Guide.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcrv-c4wc-hj94/GHSA-hcrv-c4wc-hj94.json b/advisories/unreviewed/2022/05/GHSA-hcrv-c4wc-hj94/GHSA-hcrv-c4wc-hj94.json index 7769d8d6d1a..83e5e3898d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcrv-c4wc-hj94/GHSA-hcrv-c4wc-hj94.json +++ b/advisories/unreviewed/2022/05/GHSA-hcrv-c4wc-hj94/GHSA-hcrv-c4wc-hj94.json @@ -7,12 +7,8 @@ "CVE-2020-5756" ], "details": "Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hf7q-w9cp-7xhr/GHSA-hf7q-w9cp-7xhr.json b/advisories/unreviewed/2022/05/GHSA-hf7q-w9cp-7xhr/GHSA-hf7q-w9cp-7xhr.json index f4d745a075c..244a0746c45 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf7q-w9cp-7xhr/GHSA-hf7q-w9cp-7xhr.json +++ b/advisories/unreviewed/2022/05/GHSA-hf7q-w9cp-7xhr/GHSA-hf7q-w9cp-7xhr.json @@ -7,12 +7,8 @@ "CVE-2020-1344" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1362, CVE-2020-1369.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfr2-5qrv-2xpv/GHSA-hfr2-5qrv-2xpv.json b/advisories/unreviewed/2022/05/GHSA-hfr2-5qrv-2xpv/GHSA-hfr2-5qrv-2xpv.json index 841dd0e62c4..e38d99344e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfr2-5qrv-2xpv/GHSA-hfr2-5qrv-2xpv.json +++ b/advisories/unreviewed/2022/05/GHSA-hfr2-5qrv-2xpv/GHSA-hfr2-5qrv-2xpv.json @@ -7,12 +7,8 @@ "CVE-2020-14639" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg6j-pj42-qfx4/GHSA-hg6j-pj42-qfx4.json b/advisories/unreviewed/2022/05/GHSA-hg6j-pj42-qfx4/GHSA-hg6j-pj42-qfx4.json index 77f5c53c0e1..249297d568d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg6j-pj42-qfx4/GHSA-hg6j-pj42-qfx4.json +++ b/advisories/unreviewed/2022/05/GHSA-hg6j-pj42-qfx4/GHSA-hg6j-pj42-qfx4.json @@ -7,12 +7,8 @@ "CVE-2020-14507" ], "details": "Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hh33-ch53-7qrr/GHSA-hh33-ch53-7qrr.json b/advisories/unreviewed/2022/05/GHSA-hh33-ch53-7qrr/GHSA-hh33-ch53-7qrr.json index b90e3389b50..14f1c19f427 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh33-ch53-7qrr/GHSA-hh33-ch53-7qrr.json +++ b/advisories/unreviewed/2022/05/GHSA-hh33-ch53-7qrr/GHSA-hh33-ch53-7qrr.json @@ -7,12 +7,8 @@ "CVE-2020-14673" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhh7-3xf8-52v6/GHSA-hhh7-3xf8-52v6.json b/advisories/unreviewed/2022/05/GHSA-hhh7-3xf8-52v6/GHSA-hhh7-3xf8-52v6.json index bf8bbe7bb99..0b60a7d1633 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhh7-3xf8-52v6/GHSA-hhh7-3xf8-52v6.json +++ b/advisories/unreviewed/2022/05/GHSA-hhh7-3xf8-52v6/GHSA-hhh7-3xf8-52v6.json @@ -7,12 +7,8 @@ "CVE-2020-1446" ], "details": "A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj26-rh6r-85r8/GHSA-hj26-rh6r-85r8.json b/advisories/unreviewed/2022/05/GHSA-hj26-rh6r-85r8/GHSA-hj26-rh6r-85r8.json index 43d54e39166..1007fcf54ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj26-rh6r-85r8/GHSA-hj26-rh6r-85r8.json +++ b/advisories/unreviewed/2022/05/GHSA-hj26-rh6r-85r8/GHSA-hj26-rh6r-85r8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj75-p7pw-3fv5/GHSA-hj75-p7pw-3fv5.json b/advisories/unreviewed/2022/05/GHSA-hj75-p7pw-3fv5/GHSA-hj75-p7pw-3fv5.json index ba24566a2ca..97bede1c9cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj75-p7pw-3fv5/GHSA-hj75-p7pw-3fv5.json +++ b/advisories/unreviewed/2022/05/GHSA-hj75-p7pw-3fv5/GHSA-hj75-p7pw-3fv5.json @@ -7,12 +7,8 @@ "CVE-2020-14622" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjvc-f345-6395/GHSA-hjvc-f345-6395.json b/advisories/unreviewed/2022/05/GHSA-hjvc-f345-6395/GHSA-hjvc-f345-6395.json index 1af77cd6cab..a5550c4526c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjvc-f345-6395/GHSA-hjvc-f345-6395.json +++ b/advisories/unreviewed/2022/05/GHSA-hjvc-f345-6395/GHSA-hjvc-f345-6395.json @@ -7,12 +7,8 @@ "CVE-2020-15807" ], "details": "GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hm27-4fw9-4w6f/GHSA-hm27-4fw9-4w6f.json b/advisories/unreviewed/2022/05/GHSA-hm27-4fw9-4w6f/GHSA-hm27-4fw9-4w6f.json index f3579ef06a0..6d25569e9a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm27-4fw9-4w6f/GHSA-hm27-4fw9-4w6f.json +++ b/advisories/unreviewed/2022/05/GHSA-hm27-4fw9-4w6f/GHSA-hm27-4fw9-4w6f.json @@ -7,12 +7,8 @@ "CVE-2020-7292" ], "details": "Inappropriate Encoding for output context in McAfee Web Gateway (MWG) prior to 9.2.1 allows remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpcm-hcj8-c96c/GHSA-hpcm-hcj8-c96c.json b/advisories/unreviewed/2022/05/GHSA-hpcm-hcj8-c96c/GHSA-hpcm-hcj8-c96c.json index 70d589af383..6fc46a71841 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpcm-hcj8-c96c/GHSA-hpcm-hcj8-c96c.json +++ b/advisories/unreviewed/2022/05/GHSA-hpcm-hcj8-c96c/GHSA-hpcm-hcj8-c96c.json @@ -7,12 +7,8 @@ "CVE-2020-15720" ], "details": "In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class, such as the pki-server command, may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases. This is fixed in 10.9.0-b1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hr7c-pjw8-9v89/GHSA-hr7c-pjw8-9v89.json b/advisories/unreviewed/2022/05/GHSA-hr7c-pjw8-9v89/GHSA-hr7c-pjw8-9v89.json index 90c01217ba8..7ff762d7b64 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr7c-pjw8-9v89/GHSA-hr7c-pjw8-9v89.json +++ b/advisories/unreviewed/2022/05/GHSA-hr7c-pjw8-9v89/GHSA-hr7c-pjw8-9v89.json @@ -7,12 +7,8 @@ "CVE-2020-14701" ], "details": "Vulnerability in the Oracle SD-WAN Aware product of Oracle Communications Applications (component: User Interface). The supported version that is affected is 8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Aware. While the vulnerability is in Oracle SD-WAN Aware, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle SD-WAN Aware. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrqc-2rrc-vr54/GHSA-hrqc-2rrc-vr54.json b/advisories/unreviewed/2022/05/GHSA-hrqc-2rrc-vr54/GHSA-hrqc-2rrc-vr54.json index 8461abdfcae..df714b0596e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrqc-2rrc-vr54/GHSA-hrqc-2rrc-vr54.json +++ b/advisories/unreviewed/2022/05/GHSA-hrqc-2rrc-vr54/GHSA-hrqc-2rrc-vr54.json @@ -7,12 +7,8 @@ "CVE-2020-14603" ], "details": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrwv-7vp5-r8pf/GHSA-hrwv-7vp5-r8pf.json b/advisories/unreviewed/2022/05/GHSA-hrwv-7vp5-r8pf/GHSA-hrwv-7vp5-r8pf.json index 217e104dda8..a083f289a57 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrwv-7vp5-r8pf/GHSA-hrwv-7vp5-r8pf.json +++ b/advisories/unreviewed/2022/05/GHSA-hrwv-7vp5-r8pf/GHSA-hrwv-7vp5-r8pf.json @@ -7,12 +7,8 @@ "CVE-2020-3437" ], "details": "A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope limiting. An attacker could exploit this vulnerability by creating a specific file reference on the filesystem and then accessing it through the web-based management interface. A successful exploit could allow the attacker to read arbitrary files from the filesystem of the underlying operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrxp-m6vj-m2rc/GHSA-hrxp-m6vj-m2rc.json b/advisories/unreviewed/2022/05/GHSA-hrxp-m6vj-m2rc/GHSA-hrxp-m6vj-m2rc.json index c1d359c3333..e11aeb3c7ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrxp-m6vj-m2rc/GHSA-hrxp-m6vj-m2rc.json +++ b/advisories/unreviewed/2022/05/GHSA-hrxp-m6vj-m2rc/GHSA-hrxp-m6vj-m2rc.json @@ -7,12 +7,8 @@ "CVE-2020-1423" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hv2p-7mr9-q6gg/GHSA-hv2p-7mr9-q6gg.json b/advisories/unreviewed/2022/05/GHSA-hv2p-7mr9-q6gg/GHSA-hv2p-7mr9-q6gg.json index b5786bc0752..169c9866eb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv2p-7mr9-q6gg/GHSA-hv2p-7mr9-q6gg.json +++ b/advisories/unreviewed/2022/05/GHSA-hv2p-7mr9-q6gg/GHSA-hv2p-7mr9-q6gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvc7-h6c3-f6mq/GHSA-hvc7-h6c3-f6mq.json b/advisories/unreviewed/2022/05/GHSA-hvc7-h6c3-f6mq/GHSA-hvc7-h6c3-f6mq.json index b88d62a701e..2936b33c718 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvc7-h6c3-f6mq/GHSA-hvc7-h6c3-f6mq.json +++ b/advisories/unreviewed/2022/05/GHSA-hvc7-h6c3-f6mq/GHSA-hvc7-h6c3-f6mq.json @@ -7,12 +7,8 @@ "CVE-2020-14646" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hw2c-wqq9-98qm/GHSA-hw2c-wqq9-98qm.json b/advisories/unreviewed/2022/05/GHSA-hw2c-wqq9-98qm/GHSA-hw2c-wqq9-98qm.json index d657d546ee7..be6ce06fedd 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw2c-wqq9-98qm/GHSA-hw2c-wqq9-98qm.json +++ b/advisories/unreviewed/2022/05/GHSA-hw2c-wqq9-98qm/GHSA-hw2c-wqq9-98qm.json @@ -7,12 +7,8 @@ "CVE-2020-1408" ], "details": "A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwcv-f7qg-ch9g/GHSA-hwcv-f7qg-ch9g.json b/advisories/unreviewed/2022/05/GHSA-hwcv-f7qg-ch9g/GHSA-hwcv-f7qg-ch9g.json index 58ddf9d628e..42c04914ad6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwcv-f7qg-ch9g/GHSA-hwcv-f7qg-ch9g.json +++ b/advisories/unreviewed/2022/05/GHSA-hwcv-f7qg-ch9g/GHSA-hwcv-f7qg-ch9g.json @@ -7,12 +7,8 @@ "CVE-2020-4466" ], "details": "IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow a remote authenticated attacker could cause a denial of service due to an error within the Queue processing function. IBM X-Force ID: 181563.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwfc-h7h7-q7gp/GHSA-hwfc-h7h7-q7gp.json b/advisories/unreviewed/2022/05/GHSA-hwfc-h7h7-q7gp/GHSA-hwfc-h7h7-q7gp.json index fdd018673c5..045de812b11 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwfc-h7h7-q7gp/GHSA-hwfc-h7h7-q7gp.json +++ b/advisories/unreviewed/2022/05/GHSA-hwfc-h7h7-q7gp/GHSA-hwfc-h7h7-q7gp.json @@ -7,12 +7,8 @@ "CVE-2020-9669" ], "details": "Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Successful exploitation could lead to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j29r-h8wr-v5v8/GHSA-j29r-h8wr-v5v8.json b/advisories/unreviewed/2022/05/GHSA-j29r-h8wr-v5v8/GHSA-j29r-h8wr-v5v8.json index 6e68a40c460..0a12d38651d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j29r-h8wr-v5v8/GHSA-j29r-h8wr-v5v8.json +++ b/advisories/unreviewed/2022/05/GHSA-j29r-h8wr-v5v8/GHSA-j29r-h8wr-v5v8.json @@ -7,12 +7,8 @@ "CVE-2020-15889" ], "details": "Lua through 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j334-hj6g-m96m/GHSA-j334-hj6g-m96m.json b/advisories/unreviewed/2022/05/GHSA-j334-hj6g-m96m/GHSA-j334-hj6g-m96m.json index 8b28b2bc382..17288346cf0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j334-hj6g-m96m/GHSA-j334-hj6g-m96m.json +++ b/advisories/unreviewed/2022/05/GHSA-j334-hj6g-m96m/GHSA-j334-hj6g-m96m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j35w-gjxg-946m/GHSA-j35w-gjxg-946m.json b/advisories/unreviewed/2022/05/GHSA-j35w-gjxg-946m/GHSA-j35w-gjxg-946m.json index 6b7687dfc83..fae53d0ba2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j35w-gjxg-946m/GHSA-j35w-gjxg-946m.json +++ b/advisories/unreviewed/2022/05/GHSA-j35w-gjxg-946m/GHSA-j35w-gjxg-946m.json @@ -7,12 +7,8 @@ "CVE-2020-2981" ], "details": "Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 18.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5hv-hr2w-w46g/GHSA-j5hv-hr2w-w46g.json b/advisories/unreviewed/2022/05/GHSA-j5hv-hr2w-w46g/GHSA-j5hv-hr2w-w46g.json index c315921b86e..01f2e046c0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5hv-hr2w-w46g/GHSA-j5hv-hr2w-w46g.json +++ b/advisories/unreviewed/2022/05/GHSA-j5hv-hr2w-w46g/GHSA-j5hv-hr2w-w46g.json @@ -7,12 +7,8 @@ "CVE-2020-9259" ], "details": "Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerability. The system does not sufficiently validate certain parameter passed from the bottom level, the attacker should trick the user into installing a malicious application and control the bottom level, successful exploit could cause information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6cv-ghpp-phc2/GHSA-j6cv-ghpp-phc2.json b/advisories/unreviewed/2022/05/GHSA-j6cv-ghpp-phc2/GHSA-j6cv-ghpp-phc2.json index d79dcfff1bc..f31af9440b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6cv-ghpp-phc2/GHSA-j6cv-ghpp-phc2.json +++ b/advisories/unreviewed/2022/05/GHSA-j6cv-ghpp-phc2/GHSA-j6cv-ghpp-phc2.json @@ -7,12 +7,8 @@ "CVE-2020-9672" ], "details": "Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j74f-6554-w8gh/GHSA-j74f-6554-w8gh.json b/advisories/unreviewed/2022/05/GHSA-j74f-6554-w8gh/GHSA-j74f-6554-w8gh.json index e6ed36caadd..794897303ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-j74f-6554-w8gh/GHSA-j74f-6554-w8gh.json +++ b/advisories/unreviewed/2022/05/GHSA-j74f-6554-w8gh/GHSA-j74f-6554-w8gh.json @@ -7,12 +7,8 @@ "CVE-2020-5769" ], "details": "Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by injecting malicious client-side code into the 'URL/ Host / Connection' form in the 'DATA TO SERVER' configuration section.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j773-5h44-w4h6/GHSA-j773-5h44-w4h6.json b/advisories/unreviewed/2022/05/GHSA-j773-5h44-w4h6/GHSA-j773-5h44-w4h6.json index 84024dded61..c1541290c1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j773-5h44-w4h6/GHSA-j773-5h44-w4h6.json +++ b/advisories/unreviewed/2022/05/GHSA-j773-5h44-w4h6/GHSA-j773-5h44-w4h6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7jp-jhjq-rm3c/GHSA-j7jp-jhjq-rm3c.json b/advisories/unreviewed/2022/05/GHSA-j7jp-jhjq-rm3c/GHSA-j7jp-jhjq-rm3c.json index 7c099e712ab..6e37a3efc91 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7jp-jhjq-rm3c/GHSA-j7jp-jhjq-rm3c.json +++ b/advisories/unreviewed/2022/05/GHSA-j7jp-jhjq-rm3c/GHSA-j7jp-jhjq-rm3c.json @@ -7,12 +7,8 @@ "CVE-2020-1358" ], "details": "An information disclosure vulnerability exists when the Windows Resource Policy component improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Resource Policy Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7v8-j8px-7phx/GHSA-j7v8-j8px-7phx.json b/advisories/unreviewed/2022/05/GHSA-j7v8-j8px-7phx/GHSA-j7v8-j8px-7phx.json index 261c840dfe3..20145a9f5e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7v8-j8px-7phx/GHSA-j7v8-j8px-7phx.json +++ b/advisories/unreviewed/2022/05/GHSA-j7v8-j8px-7phx/GHSA-j7v8-j8px-7phx.json @@ -7,12 +7,8 @@ "CVE-2020-3380" ], "details": "A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient restrictions during the execution of an affected CLI command. An attacker could exploit this vulnerability by authenticating as the fmserver user and submitting malicious input to a specific command. A successful exploit could allow the attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8c7-28mr-344v/GHSA-j8c7-28mr-344v.json b/advisories/unreviewed/2022/05/GHSA-j8c7-28mr-344v/GHSA-j8c7-28mr-344v.json index 579bda94eeb..7be2b35167c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8c7-28mr-344v/GHSA-j8c7-28mr-344v.json +++ b/advisories/unreviewed/2022/05/GHSA-j8c7-28mr-344v/GHSA-j8c7-28mr-344v.json @@ -7,12 +7,8 @@ "CVE-2020-1402" ], "details": "An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8wq-fvx8-fqfh/GHSA-j8wq-fvx8-fqfh.json b/advisories/unreviewed/2022/05/GHSA-j8wq-fvx8-fqfh/GHSA-j8wq-fvx8-fqfh.json index ac929d9466d..8f58cf6ac92 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8wq-fvx8-fqfh/GHSA-j8wq-fvx8-fqfh.json +++ b/advisories/unreviewed/2022/05/GHSA-j8wq-fvx8-fqfh/GHSA-j8wq-fvx8-fqfh.json @@ -7,12 +7,8 @@ "CVE-2020-10040" ], "details": "A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in clear text.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j92j-5hg7-f7hx/GHSA-j92j-5hg7-f7hx.json b/advisories/unreviewed/2022/05/GHSA-j92j-5hg7-f7hx/GHSA-j92j-5hg7-f7hx.json index c58920e7496..99a979d4f26 100644 --- a/advisories/unreviewed/2022/05/GHSA-j92j-5hg7-f7hx/GHSA-j92j-5hg7-f7hx.json +++ b/advisories/unreviewed/2022/05/GHSA-j92j-5hg7-f7hx/GHSA-j92j-5hg7-f7hx.json @@ -7,12 +7,8 @@ "CVE-2020-1032" ], "details": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jc9x-w38w-r8hg/GHSA-jc9x-w38w-r8hg.json b/advisories/unreviewed/2022/05/GHSA-jc9x-w38w-r8hg/GHSA-jc9x-w38w-r8hg.json index 9629d4f61af..4bd0e1ea3ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc9x-w38w-r8hg/GHSA-jc9x-w38w-r8hg.json +++ b/advisories/unreviewed/2022/05/GHSA-jc9x-w38w-r8hg/GHSA-jc9x-w38w-r8hg.json @@ -7,12 +7,8 @@ "CVE-2020-15695" ], "details": "An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jccq-8hwf-xp6j/GHSA-jccq-8hwf-xp6j.json b/advisories/unreviewed/2022/05/GHSA-jccq-8hwf-xp6j/GHSA-jccq-8hwf-xp6j.json index acdb1929534..ff06bf6306c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jccq-8hwf-xp6j/GHSA-jccq-8hwf-xp6j.json +++ b/advisories/unreviewed/2022/05/GHSA-jccq-8hwf-xp6j/GHSA-jccq-8hwf-xp6j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfc5-j6cj-cj2x/GHSA-jfc5-j6cj-cj2x.json b/advisories/unreviewed/2022/05/GHSA-jfc5-j6cj-cj2x/GHSA-jfc5-j6cj-cj2x.json index 785f9bc98cb..6429c547c40 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfc5-j6cj-cj2x/GHSA-jfc5-j6cj-cj2x.json +++ b/advisories/unreviewed/2022/05/GHSA-jfc5-j6cj-cj2x/GHSA-jfc5-j6cj-cj2x.json @@ -7,12 +7,8 @@ "CVE-2020-10285" ], "details": "The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfmh-q68r-88fp/GHSA-jfmh-q68r-88fp.json b/advisories/unreviewed/2022/05/GHSA-jfmh-q68r-88fp/GHSA-jfmh-q68r-88fp.json index de3569fefc2..c3e64f6ff5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfmh-q68r-88fp/GHSA-jfmh-q68r-88fp.json +++ b/advisories/unreviewed/2022/05/GHSA-jfmh-q68r-88fp/GHSA-jfmh-q68r-88fp.json @@ -7,12 +7,8 @@ "CVE-2020-14675" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jfr5-5g87-p347/GHSA-jfr5-5g87-p347.json b/advisories/unreviewed/2022/05/GHSA-jfr5-5g87-p347/GHSA-jfr5-5g87-p347.json index 46c269f0242..34b83f00ed4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfr5-5g87-p347/GHSA-jfr5-5g87-p347.json +++ b/advisories/unreviewed/2022/05/GHSA-jfr5-5g87-p347/GHSA-jfr5-5g87-p347.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfw2-jwr5-36c3/GHSA-jfw2-jwr5-36c3.json b/advisories/unreviewed/2022/05/GHSA-jfw2-jwr5-36c3/GHSA-jfw2-jwr5-36c3.json index ce9f0f80659..7da86a90b9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfw2-jwr5-36c3/GHSA-jfw2-jwr5-36c3.json +++ b/advisories/unreviewed/2022/05/GHSA-jfw2-jwr5-36c3/GHSA-jfw2-jwr5-36c3.json @@ -7,12 +7,8 @@ "CVE-2020-12015" ], "details": "A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior; ICONICS GenBroker32 version 9.5 and prior.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgfm-rcjw-3pmx/GHSA-jgfm-rcjw-3pmx.json b/advisories/unreviewed/2022/05/GHSA-jgfm-rcjw-3pmx/GHSA-jgfm-rcjw-3pmx.json index b12485f7e7e..5af4be1b865 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgfm-rcjw-3pmx/GHSA-jgfm-rcjw-3pmx.json +++ b/advisories/unreviewed/2022/05/GHSA-jgfm-rcjw-3pmx/GHSA-jgfm-rcjw-3pmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgq8-388h-mw24/GHSA-jgq8-388h-mw24.json b/advisories/unreviewed/2022/05/GHSA-jgq8-388h-mw24/GHSA-jgq8-388h-mw24.json index a3418fe963e..fcddbdbd429 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgq8-388h-mw24/GHSA-jgq8-388h-mw24.json +++ b/advisories/unreviewed/2022/05/GHSA-jgq8-388h-mw24/GHSA-jgq8-388h-mw24.json @@ -7,12 +7,8 @@ "CVE-2020-14640" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgv7-8w3p-77p5/GHSA-jgv7-8w3p-77p5.json b/advisories/unreviewed/2022/05/GHSA-jgv7-8w3p-77p5/GHSA-jgv7-8w3p-77p5.json index 5e2661ec5af..1eed88b146b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgv7-8w3p-77p5/GHSA-jgv7-8w3p-77p5.json +++ b/advisories/unreviewed/2022/05/GHSA-jgv7-8w3p-77p5/GHSA-jgv7-8w3p-77p5.json @@ -7,12 +7,8 @@ "CVE-2020-14692" ], "details": "Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6-8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Loan Loss Forecasting and Provisioning. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Loan Loss Forecasting and Provisioning accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgxm-7vmw-79h7/GHSA-jgxm-7vmw-79h7.json b/advisories/unreviewed/2022/05/GHSA-jgxm-7vmw-79h7/GHSA-jgxm-7vmw-79h7.json index da9d05cac2a..3ab7a739a34 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgxm-7vmw-79h7/GHSA-jgxm-7vmw-79h7.json +++ b/advisories/unreviewed/2022/05/GHSA-jgxm-7vmw-79h7/GHSA-jgxm-7vmw-79h7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jh29-7cwf-26xx/GHSA-jh29-7cwf-26xx.json b/advisories/unreviewed/2022/05/GHSA-jh29-7cwf-26xx/GHSA-jh29-7cwf-26xx.json index a8b48658290..5db69d83b84 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh29-7cwf-26xx/GHSA-jh29-7cwf-26xx.json +++ b/advisories/unreviewed/2022/05/GHSA-jh29-7cwf-26xx/GHSA-jh29-7cwf-26xx.json @@ -7,12 +7,8 @@ "CVE-2020-4527" ], "details": "IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the Secure flag for the session cookie in TLS mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 182631.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jh2w-2p46-2685/GHSA-jh2w-2p46-2685.json b/advisories/unreviewed/2022/05/GHSA-jh2w-2p46-2685/GHSA-jh2w-2p46-2685.json index e9ca3408aa8..98e34df3a82 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh2w-2p46-2685/GHSA-jh2w-2p46-2685.json +++ b/advisories/unreviewed/2022/05/GHSA-jh2w-2p46-2685/GHSA-jh2w-2p46-2685.json @@ -7,12 +7,8 @@ "CVE-2020-14612" ], "details": "Vulnerability in the PeopleSoft Enterprise HRMS product of Oracle PeopleSoft (component: Time and Labor). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HRMS accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HRMS accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jm92-fqw4-8r6p/GHSA-jm92-fqw4-8r6p.json b/advisories/unreviewed/2022/05/GHSA-jm92-fqw4-8r6p/GHSA-jm92-fqw4-8r6p.json index 7175d9c3363..6eb59ffd704 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm92-fqw4-8r6p/GHSA-jm92-fqw4-8r6p.json +++ b/advisories/unreviewed/2022/05/GHSA-jm92-fqw4-8r6p/GHSA-jm92-fqw4-8r6p.json @@ -7,12 +7,8 @@ "CVE-2020-1424" ], "details": "An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq6x-7xcv-6267/GHSA-jq6x-7xcv-6267.json b/advisories/unreviewed/2022/05/GHSA-jq6x-7xcv-6267/GHSA-jq6x-7xcv-6267.json index 21c8f486b5b..317b2a29a9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq6x-7xcv-6267/GHSA-jq6x-7xcv-6267.json +++ b/advisories/unreviewed/2022/05/GHSA-jq6x-7xcv-6267/GHSA-jq6x-7xcv-6267.json @@ -7,12 +7,8 @@ "CVE-2020-1468" ], "details": "An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jv3p-j4h6-73qw/GHSA-jv3p-j4h6-73qw.json b/advisories/unreviewed/2022/05/GHSA-jv3p-j4h6-73qw/GHSA-jv3p-j4h6-73qw.json index 309c9ee2794..d05a9876993 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv3p-j4h6-73qw/GHSA-jv3p-j4h6-73qw.json +++ b/advisories/unreviewed/2022/05/GHSA-jv3p-j4h6-73qw/GHSA-jv3p-j4h6-73qw.json @@ -7,12 +7,8 @@ "CVE-2020-7577" ], "details": "A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Through the use of several vulnerable fields of the application, an authenticated user could perform an SQL Injection attack by passing a modified SQL query downstream to the back-end server. The exploit of this vulnerability could be used to read, and potentially modify application data to which the user has access to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwh5-q83f-2jjc/GHSA-jwh5-q83f-2jjc.json b/advisories/unreviewed/2022/05/GHSA-jwh5-q83f-2jjc/GHSA-jwh5-q83f-2jjc.json index 9a9c5c92db9..09c7f70d3b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwh5-q83f-2jjc/GHSA-jwh5-q83f-2jjc.json +++ b/advisories/unreviewed/2022/05/GHSA-jwh5-q83f-2jjc/GHSA-jwh5-q83f-2jjc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwqg-fhhf-42x8/GHSA-jwqg-fhhf-42x8.json b/advisories/unreviewed/2022/05/GHSA-jwqg-fhhf-42x8/GHSA-jwqg-fhhf-42x8.json index 188ff0e5d4a..45ad253d538 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwqg-fhhf-42x8/GHSA-jwqg-fhhf-42x8.json +++ b/advisories/unreviewed/2022/05/GHSA-jwqg-fhhf-42x8/GHSA-jwqg-fhhf-42x8.json @@ -7,12 +7,8 @@ "CVE-2020-1654" ], "details": "On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, processing a malformed HTTP message can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) Continued processing of this malformed HTTP message may result in an extended Denial of Service (DoS) condition. The offending HTTP message that causes this issue may originate both from the HTTP server or the HTTP client. This issue affects Juniper Networks Junos OS on SRX Series: 18.1 versions prior to 18.1R3-S9 ; 18.2 versions prior to 18.2R2-S7, 18.2R3-S3; 18.3 versions prior to 18.3R1-S7, 18.3R2-S4, 18.3R3-S1; 18.4 versions prior to 18.4R1-S7, 18.4R2-S4, 18.4R3; 19.1 versions prior to 19.1R1-S5, 19.1R2; 19.2 versions prior to 19.2R1-S2, 19.2R2; 19.3 versions prior to 19.3R2. This issue does not affect Juniper Networks Junos OS prior to 18.1R1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jx66-38hf-gj2w/GHSA-jx66-38hf-gj2w.json b/advisories/unreviewed/2022/05/GHSA-jx66-38hf-gj2w/GHSA-jx66-38hf-gj2w.json index f9f67150132..84ab5ab922b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx66-38hf-gj2w/GHSA-jx66-38hf-gj2w.json +++ b/advisories/unreviewed/2022/05/GHSA-jx66-38hf-gj2w/GHSA-jx66-38hf-gj2w.json @@ -7,12 +7,8 @@ "CVE-2020-4104" ], "details": "HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2q5-mwp7-c7mq/GHSA-m2q5-mwp7-c7mq.json b/advisories/unreviewed/2022/05/GHSA-m2q5-mwp7-c7mq/GHSA-m2q5-mwp7-c7mq.json index a0be5a31e3a..fc1dcaa51ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2q5-mwp7-c7mq/GHSA-m2q5-mwp7-c7mq.json +++ b/advisories/unreviewed/2022/05/GHSA-m2q5-mwp7-c7mq/GHSA-m2q5-mwp7-c7mq.json @@ -7,12 +7,8 @@ "CVE-2020-3349" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a customized link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2wv-mhjc-g978/GHSA-m2wv-mhjc-g978.json b/advisories/unreviewed/2022/05/GHSA-m2wv-mhjc-g978/GHSA-m2wv-mhjc-g978.json index 6411c98cb9e..19852a8c642 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2wv-mhjc-g978/GHSA-m2wv-mhjc-g978.json +++ b/advisories/unreviewed/2022/05/GHSA-m2wv-mhjc-g978/GHSA-m2wv-mhjc-g978.json @@ -7,12 +7,8 @@ "CVE-2020-14557" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m32c-wxrg-vpxg/GHSA-m32c-wxrg-vpxg.json b/advisories/unreviewed/2022/05/GHSA-m32c-wxrg-vpxg/GHSA-m32c-wxrg-vpxg.json index f90c8f93d4a..04e9964e17a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m32c-wxrg-vpxg/GHSA-m32c-wxrg-vpxg.json +++ b/advisories/unreviewed/2022/05/GHSA-m32c-wxrg-vpxg/GHSA-m32c-wxrg-vpxg.json @@ -7,12 +7,8 @@ "CVE-2020-14503" ], "details": "Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this vulnerability could allow an attacker to remotely execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3qw-hq38-7qj5/GHSA-m3qw-hq38-7qj5.json b/advisories/unreviewed/2022/05/GHSA-m3qw-hq38-7qj5/GHSA-m3qw-hq38-7qj5.json index 1274f639268..3a568cc864d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3qw-hq38-7qj5/GHSA-m3qw-hq38-7qj5.json +++ b/advisories/unreviewed/2022/05/GHSA-m3qw-hq38-7qj5/GHSA-m3qw-hq38-7qj5.json @@ -7,12 +7,8 @@ "CVE-2020-14554" ], "details": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4v3-rhqc-gh4h/GHSA-m4v3-rhqc-gh4h.json b/advisories/unreviewed/2022/05/GHSA-m4v3-rhqc-gh4h/GHSA-m4v3-rhqc-gh4h.json index 79ceb2ee68b..c949939769f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4v3-rhqc-gh4h/GHSA-m4v3-rhqc-gh4h.json +++ b/advisories/unreviewed/2022/05/GHSA-m4v3-rhqc-gh4h/GHSA-m4v3-rhqc-gh4h.json @@ -7,12 +7,8 @@ "CVE-2020-14501" ], "details": "Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulnerability may allow an attacker to obtain the information of the user table, including the administrator credentials in plain text. An attacker may also delete the administrator account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m6q7-68x5-3882/GHSA-m6q7-68x5-3882.json b/advisories/unreviewed/2022/05/GHSA-m6q7-68x5-3882/GHSA-m6q7-68x5-3882.json index d35f2207569..32528d48ce7 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6q7-68x5-3882/GHSA-m6q7-68x5-3882.json +++ b/advisories/unreviewed/2022/05/GHSA-m6q7-68x5-3882/GHSA-m6q7-68x5-3882.json @@ -7,12 +7,8 @@ "CVE-2020-1346" ], "details": "An elevation of privilege vulnerability exists when the Windows Modules Installer improperly handles file operations, aka 'Windows Modules Installer Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7vr-2fp3-h865/GHSA-m7vr-2fp3-h865.json b/advisories/unreviewed/2022/05/GHSA-m7vr-2fp3-h865/GHSA-m7vr-2fp3-h865.json index bbf74b2b811..5cd4b13eb79 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7vr-2fp3-h865/GHSA-m7vr-2fp3-h865.json +++ b/advisories/unreviewed/2022/05/GHSA-m7vr-2fp3-h865/GHSA-m7vr-2fp3-h865.json @@ -7,12 +7,8 @@ "CVE-2020-0228" ], "details": "There is an improper configuration of recorder related service. Product: AndroidVersions: Android SoCAndroid ID: A-156333723", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m855-9ph3-r6p4/GHSA-m855-9ph3-r6p4.json b/advisories/unreviewed/2022/05/GHSA-m855-9ph3-r6p4/GHSA-m855-9ph3-r6p4.json index a31065dbcbd..6bdd849bf70 100644 --- a/advisories/unreviewed/2022/05/GHSA-m855-9ph3-r6p4/GHSA-m855-9ph3-r6p4.json +++ b/advisories/unreviewed/2022/05/GHSA-m855-9ph3-r6p4/GHSA-m855-9ph3-r6p4.json @@ -7,12 +7,8 @@ "CVE-2020-12013" ], "details": "A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8j7-9fh7-7c8r/GHSA-m8j7-9fh7-7c8r.json b/advisories/unreviewed/2022/05/GHSA-m8j7-9fh7-7c8r/GHSA-m8j7-9fh7-7c8r.json index 21ce25b1d90..a65a63486c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8j7-9fh7-7c8r/GHSA-m8j7-9fh7-7c8r.json +++ b/advisories/unreviewed/2022/05/GHSA-m8j7-9fh7-7c8r/GHSA-m8j7-9fh7-7c8r.json @@ -7,12 +7,8 @@ "CVE-2020-2982" ], "details": "Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.3.0.0 and 13.4.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mc3w-m29g-7p95/GHSA-mc3w-m29g-7p95.json b/advisories/unreviewed/2022/05/GHSA-mc3w-m29g-7p95/GHSA-mc3w-m29g-7p95.json index 73852402616..ed5bbf0e28a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc3w-m29g-7p95/GHSA-mc3w-m29g-7p95.json +++ b/advisories/unreviewed/2022/05/GHSA-mc3w-m29g-7p95/GHSA-mc3w-m29g-7p95.json @@ -7,12 +7,8 @@ "CVE-2020-14709" ], "details": "Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Card). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to a subset of Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mc63-vj63-gr49/GHSA-mc63-vj63-gr49.json b/advisories/unreviewed/2022/05/GHSA-mc63-vj63-gr49/GHSA-mc63-vj63-gr49.json index b7e8289eda8..bf171e925b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc63-vj63-gr49/GHSA-mc63-vj63-gr49.json +++ b/advisories/unreviewed/2022/05/GHSA-mc63-vj63-gr49/GHSA-mc63-vj63-gr49.json @@ -7,12 +7,8 @@ "CVE-2020-9254" ], "details": "HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a logic check error vulnerability. A logic error occurs when the software checking the size of certain parameter, the attacker should trick the user into installing a malicious application, successful exploit may cause code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg3r-9jh8-33r9/GHSA-mg3r-9jh8-33r9.json b/advisories/unreviewed/2022/05/GHSA-mg3r-9jh8-33r9/GHSA-mg3r-9jh8-33r9.json index e799202b14e..3d4fde1625b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg3r-9jh8-33r9/GHSA-mg3r-9jh8-33r9.json +++ b/advisories/unreviewed/2022/05/GHSA-mg3r-9jh8-33r9/GHSA-mg3r-9jh8-33r9.json @@ -7,12 +7,8 @@ "CVE-2020-15842" ], "details": "Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mh78-crmf-67j2/GHSA-mh78-crmf-67j2.json b/advisories/unreviewed/2022/05/GHSA-mh78-crmf-67j2/GHSA-mh78-crmf-67j2.json index 9cf5613ef06..b145fd2b5c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh78-crmf-67j2/GHSA-mh78-crmf-67j2.json +++ b/advisories/unreviewed/2022/05/GHSA-mh78-crmf-67j2/GHSA-mh78-crmf-67j2.json @@ -7,12 +7,8 @@ "CVE-2020-14555" ], "details": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhgv-m547-f82g/GHSA-mhgv-m547-f82g.json b/advisories/unreviewed/2022/05/GHSA-mhgv-m547-f82g/GHSA-mhgv-m547-f82g.json index 7e8b69046dd..e80cdafc7e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhgv-m547-f82g/GHSA-mhgv-m547-f82g.json +++ b/advisories/unreviewed/2022/05/GHSA-mhgv-m547-f82g/GHSA-mhgv-m547-f82g.json @@ -7,12 +7,8 @@ "CVE-2020-7592" ], "details": "A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC HMI KTP700F Mobile Arctic (All versions), SIMATIC HMI Mobile Panels 2nd Generation (All versions), SIMATIC WinCC Runtime Advanced (All versions). Unencrypted communication between the configuration software and the respective device could allow an attacker to capture potential plain text communication and have access to sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhm7-fjjw-2fgr/GHSA-mhm7-fjjw-2fgr.json b/advisories/unreviewed/2022/05/GHSA-mhm7-fjjw-2fgr/GHSA-mhm7-fjjw-2fgr.json index 7decd032b50..732d7c1d2ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhm7-fjjw-2fgr/GHSA-mhm7-fjjw-2fgr.json +++ b/advisories/unreviewed/2022/05/GHSA-mhm7-fjjw-2fgr/GHSA-mhm7-fjjw-2fgr.json @@ -7,12 +7,8 @@ "CVE-2020-1342" ], "details": "An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjhm-wvpj-x6hc/GHSA-mjhm-wvpj-x6hc.json b/advisories/unreviewed/2022/05/GHSA-mjhm-wvpj-x6hc/GHSA-mjhm-wvpj-x6hc.json index 6ea3f250a59..dfe62a8bac9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjhm-wvpj-x6hc/GHSA-mjhm-wvpj-x6hc.json +++ b/advisories/unreviewed/2022/05/GHSA-mjhm-wvpj-x6hc/GHSA-mjhm-wvpj-x6hc.json @@ -7,12 +7,8 @@ "CVE-2020-15052" ], "details": "An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjwg-frjf-m53m/GHSA-mjwg-frjf-m53m.json b/advisories/unreviewed/2022/05/GHSA-mjwg-frjf-m53m/GHSA-mjwg-frjf-m53m.json index 40020bd90b9..3a16d30dd1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjwg-frjf-m53m/GHSA-mjwg-frjf-m53m.json +++ b/advisories/unreviewed/2022/05/GHSA-mjwg-frjf-m53m/GHSA-mjwg-frjf-m53m.json @@ -7,12 +7,8 @@ "CVE-2020-1381" ], "details": "An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1382.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mmg6-qg4h-p87j/GHSA-mmg6-qg4h-p87j.json b/advisories/unreviewed/2022/05/GHSA-mmg6-qg4h-p87j/GHSA-mmg6-qg4h-p87j.json index 86a627f4511..c9650640557 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmg6-qg4h-p87j/GHSA-mmg6-qg4h-p87j.json +++ b/advisories/unreviewed/2022/05/GHSA-mmg6-qg4h-p87j/GHSA-mmg6-qg4h-p87j.json @@ -7,12 +7,8 @@ "CVE-2020-14618" ], "details": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Mobile App). The supported version that is affected is Prior to 20.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera Unifier accessible data as well as unauthorized update, insert or delete access to some of Primavera Unifier accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mph7-jw9x-c242/GHSA-mph7-jw9x-c242.json b/advisories/unreviewed/2022/05/GHSA-mph7-jw9x-c242/GHSA-mph7-jw9x-c242.json index 325165b1c31..8e2c62fd489 100644 --- a/advisories/unreviewed/2022/05/GHSA-mph7-jw9x-c242/GHSA-mph7-jw9x-c242.json +++ b/advisories/unreviewed/2022/05/GHSA-mph7-jw9x-c242/GHSA-mph7-jw9x-c242.json @@ -7,12 +7,8 @@ "CVE-2020-6290" ], "details": "SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mq2p-3w9c-34j8/GHSA-mq2p-3w9c-34j8.json b/advisories/unreviewed/2022/05/GHSA-mq2p-3w9c-34j8/GHSA-mq2p-3w9c-34j8.json index c5cf374cf65..613423d772f 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq2p-3w9c-34j8/GHSA-mq2p-3w9c-34j8.json +++ b/advisories/unreviewed/2022/05/GHSA-mq2p-3w9c-34j8/GHSA-mq2p-3w9c-34j8.json @@ -7,12 +7,8 @@ "CVE-2020-14685" ], "details": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mq62-3882-pq59/GHSA-mq62-3882-pq59.json b/advisories/unreviewed/2022/05/GHSA-mq62-3882-pq59/GHSA-mq62-3882-pq59.json index 54f7a5f5909..fe2b0e13111 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq62-3882-pq59/GHSA-mq62-3882-pq59.json +++ b/advisories/unreviewed/2022/05/GHSA-mq62-3882-pq59/GHSA-mq62-3882-pq59.json @@ -7,12 +7,8 @@ "CVE-2020-14713" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mr9w-f6pg-jp2v/GHSA-mr9w-f6pg-jp2v.json b/advisories/unreviewed/2022/05/GHSA-mr9w-f6pg-jp2v/GHSA-mr9w-f6pg-jp2v.json index e17a524c21f..bb1f456c208 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr9w-f6pg-jp2v/GHSA-mr9w-f6pg-jp2v.json +++ b/advisories/unreviewed/2022/05/GHSA-mr9w-f6pg-jp2v/GHSA-mr9w-f6pg-jp2v.json @@ -7,12 +7,8 @@ "CVE-2020-1399" ], "details": "An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw2x-vj87-7rxr/GHSA-mw2x-vj87-7rxr.json b/advisories/unreviewed/2022/05/GHSA-mw2x-vj87-7rxr/GHSA-mw2x-vj87-7rxr.json index 90d269cefb9..ea7f670d1b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw2x-vj87-7rxr/GHSA-mw2x-vj87-7rxr.json +++ b/advisories/unreviewed/2022/05/GHSA-mw2x-vj87-7rxr/GHSA-mw2x-vj87-7rxr.json @@ -7,12 +7,8 @@ "CVE-2020-14588" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mxm2-76x3-3frq/GHSA-mxm2-76x3-3frq.json b/advisories/unreviewed/2022/05/GHSA-mxm2-76x3-3frq/GHSA-mxm2-76x3-3frq.json index 7c1ad8f8c6b..60848ef6989 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxm2-76x3-3frq/GHSA-mxm2-76x3-3frq.json +++ b/advisories/unreviewed/2022/05/GHSA-mxm2-76x3-3frq/GHSA-mxm2-76x3-3frq.json @@ -7,12 +7,8 @@ "CVE-2020-14670" ], "details": "Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Settings). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p23h-x6wc-8w4g/GHSA-p23h-x6wc-8w4g.json b/advisories/unreviewed/2022/05/GHSA-p23h-x6wc-8w4g/GHSA-p23h-x6wc-8w4g.json index 3d8612be7a2..46b2c77f0a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-p23h-x6wc-8w4g/GHSA-p23h-x6wc-8w4g.json +++ b/advisories/unreviewed/2022/05/GHSA-p23h-x6wc-8w4g/GHSA-p23h-x6wc-8w4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2c2-jv92-hvch/GHSA-p2c2-jv92-hvch.json b/advisories/unreviewed/2022/05/GHSA-p2c2-jv92-hvch/GHSA-p2c2-jv92-hvch.json index 35d192715d1..914c61cfff9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2c2-jv92-hvch/GHSA-p2c2-jv92-hvch.json +++ b/advisories/unreviewed/2022/05/GHSA-p2c2-jv92-hvch/GHSA-p2c2-jv92-hvch.json @@ -7,12 +7,8 @@ "CVE-2020-2983" ], "details": "Vulnerability in the Oracle Data Masking and Subsetting product of Oracle Enterprise Manager (component: Data Masking). Supported versions that are affected are 13.3.0.0 and 13.4.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Masking and Subsetting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Masking and Subsetting accessible data as well as unauthorized update, insert or delete access to some of Oracle Data Masking and Subsetting accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2m9-83f8-9277/GHSA-p2m9-83f8-9277.json b/advisories/unreviewed/2022/05/GHSA-p2m9-83f8-9277/GHSA-p2m9-83f8-9277.json index e95acd6ee81..d82a818b97a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2m9-83f8-9277/GHSA-p2m9-83f8-9277.json +++ b/advisories/unreviewed/2022/05/GHSA-p2m9-83f8-9277/GHSA-p2m9-83f8-9277.json @@ -7,12 +7,8 @@ "CVE-2020-14677" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2xq-9789-ph6p/GHSA-p2xq-9789-ph6p.json b/advisories/unreviewed/2022/05/GHSA-p2xq-9789-ph6p/GHSA-p2xq-9789-ph6p.json index aa1fa5341d2..1c92fccb19d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2xq-9789-ph6p/GHSA-p2xq-9789-ph6p.json +++ b/advisories/unreviewed/2022/05/GHSA-p2xq-9789-ph6p/GHSA-p2xq-9789-ph6p.json @@ -7,12 +7,8 @@ "CVE-2020-14690" ], "details": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p4c4-cqrr-xxhq/GHSA-p4c4-cqrr-xxhq.json b/advisories/unreviewed/2022/05/GHSA-p4c4-cqrr-xxhq/GHSA-p4c4-cqrr-xxhq.json index af28fd9bf52..786e8daf0f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4c4-cqrr-xxhq/GHSA-p4c4-cqrr-xxhq.json +++ b/advisories/unreviewed/2022/05/GHSA-p4c4-cqrr-xxhq/GHSA-p4c4-cqrr-xxhq.json @@ -7,12 +7,8 @@ "CVE-2020-14636" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5pr-qp45-63pf/GHSA-p5pr-qp45-63pf.json b/advisories/unreviewed/2022/05/GHSA-p5pr-qp45-63pf/GHSA-p5pr-qp45-63pf.json index cfe891025fb..aa7cb0391e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5pr-qp45-63pf/GHSA-p5pr-qp45-63pf.json +++ b/advisories/unreviewed/2022/05/GHSA-p5pr-qp45-63pf/GHSA-p5pr-qp45-63pf.json @@ -7,12 +7,8 @@ "CVE-2020-2973" ], "details": "Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5v3-7243-m33v/GHSA-p5v3-7243-m33v.json b/advisories/unreviewed/2022/05/GHSA-p5v3-7243-m33v/GHSA-p5v3-7243-m33v.json index f2250c6c29e..a50e123c0d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5v3-7243-m33v/GHSA-p5v3-7243-m33v.json +++ b/advisories/unreviewed/2022/05/GHSA-p5v3-7243-m33v/GHSA-p5v3-7243-m33v.json @@ -7,12 +7,8 @@ "CVE-2019-20912" ], "details": "An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bit_read_TF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p634-9p2p-jq6r/GHSA-p634-9p2p-jq6r.json b/advisories/unreviewed/2022/05/GHSA-p634-9p2p-jq6r/GHSA-p634-9p2p-jq6r.json index 3f49e99cbb4..dbe2b0b6b6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p634-9p2p-jq6r/GHSA-p634-9p2p-jq6r.json +++ b/advisories/unreviewed/2022/05/GHSA-p634-9p2p-jq6r/GHSA-p634-9p2p-jq6r.json @@ -7,12 +7,8 @@ "CVE-2020-14667" ], "details": "Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6hv-349c-8qpj/GHSA-p6hv-349c-8qpj.json b/advisories/unreviewed/2022/05/GHSA-p6hv-349c-8qpj/GHSA-p6hv-349c-8qpj.json index 195c4331042..34fd8e03d9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6hv-349c-8qpj/GHSA-p6hv-349c-8qpj.json +++ b/advisories/unreviewed/2022/05/GHSA-p6hv-349c-8qpj/GHSA-p6hv-349c-8qpj.json @@ -7,12 +7,8 @@ "CVE-2020-0226" ], "details": "In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150226994", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7p7-mm6x-7q2p/GHSA-p7p7-mm6x-7q2p.json b/advisories/unreviewed/2022/05/GHSA-p7p7-mm6x-7q2p/GHSA-p7p7-mm6x-7q2p.json index 4c94ed659e2..a0ce7f765a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7p7-mm6x-7q2p/GHSA-p7p7-mm6x-7q2p.json +++ b/advisories/unreviewed/2022/05/GHSA-p7p7-mm6x-7q2p/GHSA-p7p7-mm6x-7q2p.json @@ -7,12 +7,8 @@ "CVE-2020-9227" ], "details": "Huawei Smart Phones Moana-AL00B with versions earlier than 10.1.0.166 have a missing initialization of resource vulnerability. An attacker tricks the user into installing then running a crafted application. Due to improper initialization of specific parameters, successful exploit of this vulnerability may cause device exceptions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8wr-hxwm-p363/GHSA-p8wr-hxwm-p363.json b/advisories/unreviewed/2022/05/GHSA-p8wr-hxwm-p363/GHSA-p8wr-hxwm-p363.json index 863e56f2e3b..68414264f75 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8wr-hxwm-p363/GHSA-p8wr-hxwm-p363.json +++ b/advisories/unreviewed/2022/05/GHSA-p8wr-hxwm-p363/GHSA-p8wr-hxwm-p363.json @@ -7,12 +7,8 @@ "CVE-2020-12011" ], "details": "A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior; GenBroker32 version 9.5 and prior.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p9c5-ggpr-4rpq/GHSA-p9c5-ggpr-4rpq.json b/advisories/unreviewed/2022/05/GHSA-p9c5-ggpr-4rpq/GHSA-p9c5-ggpr-4rpq.json index c800a1a40af..40353f6e04f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9c5-ggpr-4rpq/GHSA-p9c5-ggpr-4rpq.json +++ b/advisories/unreviewed/2022/05/GHSA-p9c5-ggpr-4rpq/GHSA-p9c5-ggpr-4rpq.json @@ -7,12 +7,8 @@ "CVE-2020-1411" ], "details": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1336.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9mv-7pgj-886r/GHSA-p9mv-7pgj-886r.json b/advisories/unreviewed/2022/05/GHSA-p9mv-7pgj-886r/GHSA-p9mv-7pgj-886r.json index ef8fcc1e4d1..93e9c59e787 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9mv-7pgj-886r/GHSA-p9mv-7pgj-886r.json +++ b/advisories/unreviewed/2022/05/GHSA-p9mv-7pgj-886r/GHSA-p9mv-7pgj-886r.json @@ -7,12 +7,8 @@ "CVE-2020-14616" ], "details": "Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pf9w-9r28-c4x6/GHSA-pf9w-9r28-c4x6.json b/advisories/unreviewed/2022/05/GHSA-pf9w-9r28-c4x6/GHSA-pf9w-9r28-c4x6.json index 9e881ec978c..3abd5d4f827 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf9w-9r28-c4x6/GHSA-pf9w-9r28-c4x6.json +++ b/advisories/unreviewed/2022/05/GHSA-pf9w-9r28-c4x6/GHSA-pf9w-9r28-c4x6.json @@ -7,12 +7,8 @@ "CVE-2020-1414" ], "details": "An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1415, CVE-2020-1422.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg7h-v386-fw8h/GHSA-pg7h-v386-fw8h.json b/advisories/unreviewed/2022/05/GHSA-pg7h-v386-fw8h/GHSA-pg7h-v386-fw8h.json index 028b2cc3723..e9cfd406212 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg7h-v386-fw8h/GHSA-pg7h-v386-fw8h.json +++ b/advisories/unreviewed/2022/05/GHSA-pg7h-v386-fw8h/GHSA-pg7h-v386-fw8h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg9j-r44q-jhmf/GHSA-pg9j-r44q-jhmf.json b/advisories/unreviewed/2022/05/GHSA-pg9j-r44q-jhmf/GHSA-pg9j-r44q-jhmf.json index 19392d6cbb8..6502b134561 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg9j-r44q-jhmf/GHSA-pg9j-r44q-jhmf.json +++ b/advisories/unreviewed/2022/05/GHSA-pg9j-r44q-jhmf/GHSA-pg9j-r44q-jhmf.json @@ -7,12 +7,8 @@ "CVE-2020-14649" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgp4-m4pc-4jr6/GHSA-pgp4-m4pc-4jr6.json b/advisories/unreviewed/2022/05/GHSA-pgp4-m4pc-4jr6/GHSA-pgp4-m4pc-4jr6.json index c16f727e664..67ce7f53db6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgp4-m4pc-4jr6/GHSA-pgp4-m4pc-4jr6.json +++ b/advisories/unreviewed/2022/05/GHSA-pgp4-m4pc-4jr6/GHSA-pgp4-m4pc-4jr6.json @@ -7,12 +7,8 @@ "CVE-2009-2282" ], "details": "The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local control-domain users to gain guest-domain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgrg-v7x5-jj2w/GHSA-pgrg-v7x5-jj2w.json b/advisories/unreviewed/2022/05/GHSA-pgrg-v7x5-jj2w/GHSA-pgrg-v7x5-jj2w.json index ca2a5bf9382..3f895161226 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgrg-v7x5-jj2w/GHSA-pgrg-v7x5-jj2w.json +++ b/advisories/unreviewed/2022/05/GHSA-pgrg-v7x5-jj2w/GHSA-pgrg-v7x5-jj2w.json @@ -7,12 +7,8 @@ "CVE-2020-8958" ], "details": "Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the boaform/admin/formPing Dest IP Address field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-phhf-gj3g-w9rj/GHSA-phhf-gj3g-w9rj.json b/advisories/unreviewed/2022/05/GHSA-phhf-gj3g-w9rj/GHSA-phhf-gj3g-w9rj.json index 816877e1b2f..2898f5fe508 100644 --- a/advisories/unreviewed/2022/05/GHSA-phhf-gj3g-w9rj/GHSA-phhf-gj3g-w9rj.json +++ b/advisories/unreviewed/2022/05/GHSA-phhf-gj3g-w9rj/GHSA-phhf-gj3g-w9rj.json @@ -7,12 +7,8 @@ "CVE-2020-14615" ], "details": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pjx6-jj7c-74m7/GHSA-pjx6-jj7c-74m7.json b/advisories/unreviewed/2022/05/GHSA-pjx6-jj7c-74m7/GHSA-pjx6-jj7c-74m7.json index 006179b1ee2..68311b8589b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjx6-jj7c-74m7/GHSA-pjx6-jj7c-74m7.json +++ b/advisories/unreviewed/2022/05/GHSA-pjx6-jj7c-74m7/GHSA-pjx6-jj7c-74m7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pmxc-pvr4-wcxp/GHSA-pmxc-pvr4-wcxp.json b/advisories/unreviewed/2022/05/GHSA-pmxc-pvr4-wcxp/GHSA-pmxc-pvr4-wcxp.json index 0bf47ae23f3..5dc7453474c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmxc-pvr4-wcxp/GHSA-pmxc-pvr4-wcxp.json +++ b/advisories/unreviewed/2022/05/GHSA-pmxc-pvr4-wcxp/GHSA-pmxc-pvr4-wcxp.json @@ -7,12 +7,8 @@ "CVE-2020-5766" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pp6j-7q29-2wxx/GHSA-pp6j-7q29-2wxx.json b/advisories/unreviewed/2022/05/GHSA-pp6j-7q29-2wxx/GHSA-pp6j-7q29-2wxx.json index 658cc3abefd..bb86301862b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp6j-7q29-2wxx/GHSA-pp6j-7q29-2wxx.json +++ b/advisories/unreviewed/2022/05/GHSA-pp6j-7q29-2wxx/GHSA-pp6j-7q29-2wxx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwjv-ccmv-j29q/GHSA-pwjv-ccmv-j29q.json b/advisories/unreviewed/2022/05/GHSA-pwjv-ccmv-j29q/GHSA-pwjv-ccmv-j29q.json index d002f4d1952..b358808569f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwjv-ccmv-j29q/GHSA-pwjv-ccmv-j29q.json +++ b/advisories/unreviewed/2022/05/GHSA-pwjv-ccmv-j29q/GHSA-pwjv-ccmv-j29q.json @@ -7,12 +7,8 @@ "CVE-2020-2984" ], "details": "Vulnerability in the Oracle Configuration Manager product of Oracle Enterprise Manager (component: Discovery and collection script). The supported version that is affected is 12.1.2.0.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configuration Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configuration Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Configuration Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pwwq-q65q-v9q6/GHSA-pwwq-q65q-v9q6.json b/advisories/unreviewed/2022/05/GHSA-pwwq-q65q-v9q6/GHSA-pwwq-q65q-v9q6.json index 8b80762602d..b7e489116c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwwq-q65q-v9q6/GHSA-pwwq-q65q-v9q6.json +++ b/advisories/unreviewed/2022/05/GHSA-pwwq-q65q-v9q6/GHSA-pwwq-q65q-v9q6.json @@ -7,12 +7,8 @@ "CVE-2020-1384" ], "details": "An elevation of privilege vulnerability exists when the Windows Cryptography Next Generation (CNG) Key Isolation service improperly handles memory, aka 'Windows CNG Key Isolation Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1359.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-px6h-7v38-8hhr/GHSA-px6h-7v38-8hhr.json b/advisories/unreviewed/2022/05/GHSA-px6h-7v38-8hhr/GHSA-px6h-7v38-8hhr.json index 44d7fbeb297..86144da7ac8 100644 --- a/advisories/unreviewed/2022/05/GHSA-px6h-7v38-8hhr/GHSA-px6h-7v38-8hhr.json +++ b/advisories/unreviewed/2022/05/GHSA-px6h-7v38-8hhr/GHSA-px6h-7v38-8hhr.json @@ -7,12 +7,8 @@ "CVE-2020-6281" ], "details": "SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pxj3-7mxw-535w/GHSA-pxj3-7mxw-535w.json b/advisories/unreviewed/2022/05/GHSA-pxj3-7mxw-535w/GHSA-pxj3-7mxw-535w.json index 55ac648c13b..4ccf7b722ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxj3-7mxw-535w/GHSA-pxj3-7mxw-535w.json +++ b/advisories/unreviewed/2022/05/GHSA-pxj3-7mxw-535w/GHSA-pxj3-7mxw-535w.json @@ -7,12 +7,8 @@ "CVE-2020-5373" ], "details": "Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to retrieve the system inventory data of the managed device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q2mw-237c-cpjv/GHSA-q2mw-237c-cpjv.json b/advisories/unreviewed/2022/05/GHSA-q2mw-237c-cpjv/GHSA-q2mw-237c-cpjv.json index 2beb77c944b..5c513c9a443 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2mw-237c-cpjv/GHSA-q2mw-237c-cpjv.json +++ b/advisories/unreviewed/2022/05/GHSA-q2mw-237c-cpjv/GHSA-q2mw-237c-cpjv.json @@ -7,12 +7,8 @@ "CVE-2020-11827" ], "details": "In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious code in a Trojan horse GalaxyClientService.exe. After that, the attacker can re-start this service as an unprivileged user to escalate his/her privileges and run commands on the machine with SYSTEM rights.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2qc-9pjq-74f3/GHSA-q2qc-9pjq-74f3.json b/advisories/unreviewed/2022/05/GHSA-q2qc-9pjq-74f3/GHSA-q2qc-9pjq-74f3.json index 4b9c6f7da12..8e9f4a0d36c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2qc-9pjq-74f3/GHSA-q2qc-9pjq-74f3.json +++ b/advisories/unreviewed/2022/05/GHSA-q2qc-9pjq-74f3/GHSA-q2qc-9pjq-74f3.json @@ -7,12 +7,8 @@ "CVE-2020-14610" ], "details": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). The supported version that is affected is 12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q3cq-7q8h-4w5c/GHSA-q3cq-7q8h-4w5c.json b/advisories/unreviewed/2022/05/GHSA-q3cq-7q8h-4w5c/GHSA-q3cq-7q8h-4w5c.json index 2e6f997dfca..f39472cd45a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3cq-7q8h-4w5c/GHSA-q3cq-7q8h-4w5c.json +++ b/advisories/unreviewed/2022/05/GHSA-q3cq-7q8h-4w5c/GHSA-q3cq-7q8h-4w5c.json @@ -7,12 +7,8 @@ "CVE-2020-14604" ], "details": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q3pf-hhq3-r6v2/GHSA-q3pf-hhq3-r6v2.json b/advisories/unreviewed/2022/05/GHSA-q3pf-hhq3-r6v2/GHSA-q3pf-hhq3-r6v2.json index f189eaee2d5..6a91facff7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3pf-hhq3-r6v2/GHSA-q3pf-hhq3-r6v2.json +++ b/advisories/unreviewed/2022/05/GHSA-q3pf-hhq3-r6v2/GHSA-q3pf-hhq3-r6v2.json @@ -7,12 +7,8 @@ "CVE-2020-11951" ], "details": "An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a Backdoor root account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q3xf-jx9c-m8c9/GHSA-q3xf-jx9c-m8c9.json b/advisories/unreviewed/2022/05/GHSA-q3xf-jx9c-m8c9/GHSA-q3xf-jx9c-m8c9.json index cbb2f2148dc..1dda91da2ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3xf-jx9c-m8c9/GHSA-q3xf-jx9c-m8c9.json +++ b/advisories/unreviewed/2022/05/GHSA-q3xf-jx9c-m8c9/GHSA-q3xf-jx9c-m8c9.json @@ -7,12 +7,8 @@ "CVE-2020-10288" ], "details": "IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q62q-9vgf-p9j3/GHSA-q62q-9vgf-p9j3.json b/advisories/unreviewed/2022/05/GHSA-q62q-9vgf-p9j3/GHSA-q62q-9vgf-p9j3.json index b6dbaa76146..2e46f7db87d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q62q-9vgf-p9j3/GHSA-q62q-9vgf-p9j3.json +++ b/advisories/unreviewed/2022/05/GHSA-q62q-9vgf-p9j3/GHSA-q62q-9vgf-p9j3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q694-5rvh-m24r/GHSA-q694-5rvh-m24r.json b/advisories/unreviewed/2022/05/GHSA-q694-5rvh-m24r/GHSA-q694-5rvh-m24r.json index 3eb3bdbf56d..88a9fcb3101 100644 --- a/advisories/unreviewed/2022/05/GHSA-q694-5rvh-m24r/GHSA-q694-5rvh-m24r.json +++ b/advisories/unreviewed/2022/05/GHSA-q694-5rvh-m24r/GHSA-q694-5rvh-m24r.json @@ -7,12 +7,8 @@ "CVE-2020-1653" ], "details": "On Juniper Networks Junos OS devices, a stream of TCP packets sent to the Routing Engine (RE) may cause mbuf leak which can lead to Flexible PIC Concentrator (FPC) crash or the system to crash and restart (vmcore). This issue can be trigged by IPv4 or IPv6 and it is caused only by TCP packets. This issue is not related to any specific configuration and it affects Junos OS releases starting from 17.4R1. However, this issue does not affect Junos OS releases prior to 18.2R1 when Nonstop active routing (NSR) is configured [edit routing-options nonstop-routing]. The number of mbufs is platform dependent. The following command provides the number of mbufs counter that are currently in use and maximum number of mbufs that can be allocated on a platform: user@host> show system buffers 2437/3143/5580 mbufs in use (current/cache/total) Once the device runs out of mbufs, the FPC crashes or the vmcore occurs and the device might become inaccessible requiring a manual restart. This issue affects Juniper Networks Junos OS 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S5; 18.2X75 versions prior to 18.2X75-D41, 18.2X75-D420.12, 18.2X75-D51, 18.2X75-D60, 18.2X75-D34; 18.3 versions prior to 18.3R2-S4, 18.3R3-S2; 18.4 versions prior to 18.4R1-S7, 18.4R2-S4, 18.4R3-S1; 19.1 versions prior to 19.1R1-S5, 19.1R2-S1, 19.1R3; 19.2 versions prior to 19.2R1-S5, 19.2R2; 19.3 versions prior to 19.3R2-S3, 19.3R3; 19.4 versions prior to 19.4R1-S2, 19.4R2. Versions of Junos OS prior to 17.4R1 are unaffected by this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6x3-474p-vpgf/GHSA-q6x3-474p-vpgf.json b/advisories/unreviewed/2022/05/GHSA-q6x3-474p-vpgf/GHSA-q6x3-474p-vpgf.json index 42f06d75cc9..b898ebca43e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6x3-474p-vpgf/GHSA-q6x3-474p-vpgf.json +++ b/advisories/unreviewed/2022/05/GHSA-q6x3-474p-vpgf/GHSA-q6x3-474p-vpgf.json @@ -7,12 +7,8 @@ "CVE-2019-4090" ], "details": "\"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q7fc-v93r-h333/GHSA-q7fc-v93r-h333.json b/advisories/unreviewed/2022/05/GHSA-q7fc-v93r-h333/GHSA-q7fc-v93r-h333.json index 4ec16a3f908..d5479d46b7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7fc-v93r-h333/GHSA-q7fc-v93r-h333.json +++ b/advisories/unreviewed/2022/05/GHSA-q7fc-v93r-h333/GHSA-q7fc-v93r-h333.json @@ -7,12 +7,8 @@ "CVE-2020-3370" ], "details": "A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to bypass URL filtering on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted, malicious HTTP request to an affected device. A successful exploit could allow the attacker to redirect users to malicious sites.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7r4-p4gw-mfp9/GHSA-q7r4-p4gw-mfp9.json b/advisories/unreviewed/2022/05/GHSA-q7r4-p4gw-mfp9/GHSA-q7r4-p4gw-mfp9.json index e1204558e66..32c0f406897 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7r4-p4gw-mfp9/GHSA-q7r4-p4gw-mfp9.json +++ b/advisories/unreviewed/2022/05/GHSA-q7r4-p4gw-mfp9/GHSA-q7r4-p4gw-mfp9.json @@ -7,12 +7,8 @@ "CVE-2020-14647" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q847-89jp-97gr/GHSA-q847-89jp-97gr.json b/advisories/unreviewed/2022/05/GHSA-q847-89jp-97gr/GHSA-q847-89jp-97gr.json index ad44e419ad6..a4b77824ff1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q847-89jp-97gr/GHSA-q847-89jp-97gr.json +++ b/advisories/unreviewed/2022/05/GHSA-q847-89jp-97gr/GHSA-q847-89jp-97gr.json @@ -7,12 +7,8 @@ "CVE-2020-15051" ], "details": "An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Address, Group Name, MYSQL Server, Database, MYSQL Username, Group Name, and Task Description fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q86m-xf2x-qj8j/GHSA-q86m-xf2x-qj8j.json b/advisories/unreviewed/2022/05/GHSA-q86m-xf2x-qj8j/GHSA-q86m-xf2x-qj8j.json index 809f1c6dee7..6f403ffe658 100644 --- a/advisories/unreviewed/2022/05/GHSA-q86m-xf2x-qj8j/GHSA-q86m-xf2x-qj8j.json +++ b/advisories/unreviewed/2022/05/GHSA-q86m-xf2x-qj8j/GHSA-q86m-xf2x-qj8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8w4-7mqg-63h9/GHSA-q8w4-7mqg-63h9.json b/advisories/unreviewed/2022/05/GHSA-q8w4-7mqg-63h9/GHSA-q8w4-7mqg-63h9.json index 0a554e15aa1..604a711aefb 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8w4-7mqg-63h9/GHSA-q8w4-7mqg-63h9.json +++ b/advisories/unreviewed/2022/05/GHSA-q8w4-7mqg-63h9/GHSA-q8w4-7mqg-63h9.json @@ -7,12 +7,8 @@ "CVE-2020-14545" ], "details": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9jr-wwq5-4qxm/GHSA-q9jr-wwq5-4qxm.json b/advisories/unreviewed/2022/05/GHSA-q9jr-wwq5-4qxm/GHSA-q9jr-wwq5-4qxm.json index ef8372261fe..f10d99adb66 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9jr-wwq5-4qxm/GHSA-q9jr-wwq5-4qxm.json +++ b/advisories/unreviewed/2022/05/GHSA-q9jr-wwq5-4qxm/GHSA-q9jr-wwq5-4qxm.json @@ -7,12 +7,8 @@ "CVE-2020-1387" ], "details": "An elevation of privilege vulnerability exists in the way the Windows Push Notification Service handles objects in memory, aka 'Windows Push Notification Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg4c-57xc-qmr9/GHSA-qg4c-57xc-qmr9.json b/advisories/unreviewed/2022/05/GHSA-qg4c-57xc-qmr9/GHSA-qg4c-57xc-qmr9.json index 7df5b7b35e1..79d4e13c8d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg4c-57xc-qmr9/GHSA-qg4c-57xc-qmr9.json +++ b/advisories/unreviewed/2022/05/GHSA-qg4c-57xc-qmr9/GHSA-qg4c-57xc-qmr9.json @@ -7,12 +7,8 @@ "CVE-2019-20910" ], "details": "An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qm53-rcwv-78qc/GHSA-qm53-rcwv-78qc.json b/advisories/unreviewed/2022/05/GHSA-qm53-rcwv-78qc/GHSA-qm53-rcwv-78qc.json index fa5929c8af4..8125f3e8aea 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm53-rcwv-78qc/GHSA-qm53-rcwv-78qc.json +++ b/advisories/unreviewed/2022/05/GHSA-qm53-rcwv-78qc/GHSA-qm53-rcwv-78qc.json @@ -7,12 +7,8 @@ "CVE-2020-14065" ], "details": "IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qpc7-j67r-rgx7/GHSA-qpc7-j67r-rgx7.json b/advisories/unreviewed/2022/05/GHSA-qpc7-j67r-rgx7/GHSA-qpc7-j67r-rgx7.json index 8c8597a2ae9..0ad3827be2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpc7-j67r-rgx7/GHSA-qpc7-j67r-rgx7.json +++ b/advisories/unreviewed/2022/05/GHSA-qpc7-j67r-rgx7/GHSA-qpc7-j67r-rgx7.json @@ -7,12 +7,8 @@ "CVE-2020-14587" ], "details": "Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Expenses accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise FIN Expenses accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qphx-chwr-chm3/GHSA-qphx-chwr-chm3.json b/advisories/unreviewed/2022/05/GHSA-qphx-chwr-chm3/GHSA-qphx-chwr-chm3.json index b7167dd2dda..c3838a4d75c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qphx-chwr-chm3/GHSA-qphx-chwr-chm3.json +++ b/advisories/unreviewed/2022/05/GHSA-qphx-chwr-chm3/GHSA-qphx-chwr-chm3.json @@ -7,12 +7,8 @@ "CVE-2020-6282" ], "details": "SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qq86-2628-gqpg/GHSA-qq86-2628-gqpg.json b/advisories/unreviewed/2022/05/GHSA-qq86-2628-gqpg/GHSA-qq86-2628-gqpg.json index ebf5f40d9ee..d7a3b8141f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq86-2628-gqpg/GHSA-qq86-2628-gqpg.json +++ b/advisories/unreviewed/2022/05/GHSA-qq86-2628-gqpg/GHSA-qq86-2628-gqpg.json @@ -7,12 +7,8 @@ "CVE-2020-14590" ], "details": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Page Request). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qq9w-3xhq-6rxf/GHSA-qq9w-3xhq-6rxf.json b/advisories/unreviewed/2022/05/GHSA-qq9w-3xhq-6rxf/GHSA-qq9w-3xhq-6rxf.json index 07b5125a8aa..c981279cc24 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq9w-3xhq-6rxf/GHSA-qq9w-3xhq-6rxf.json +++ b/advisories/unreviewed/2022/05/GHSA-qq9w-3xhq-6rxf/GHSA-qq9w-3xhq-6rxf.json @@ -7,12 +7,8 @@ "CVE-2020-1403" ], "details": "A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrhw-r9hg-cwcm/GHSA-qrhw-r9hg-cwcm.json b/advisories/unreviewed/2022/05/GHSA-qrhw-r9hg-cwcm/GHSA-qrhw-r9hg-cwcm.json index 23a32e1b1e3..71d5f175c08 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrhw-r9hg-cwcm/GHSA-qrhw-r9hg-cwcm.json +++ b/advisories/unreviewed/2022/05/GHSA-qrhw-r9hg-cwcm/GHSA-qrhw-r9hg-cwcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrj4-928f-f3h2/GHSA-qrj4-928f-f3h2.json b/advisories/unreviewed/2022/05/GHSA-qrj4-928f-f3h2/GHSA-qrj4-928f-f3h2.json index 3453102bb19..95561966a07 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrj4-928f-f3h2/GHSA-qrj4-928f-f3h2.json +++ b/advisories/unreviewed/2022/05/GHSA-qrj4-928f-f3h2/GHSA-qrj4-928f-f3h2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrqv-r3qh-3qch/GHSA-qrqv-r3qh-3qch.json b/advisories/unreviewed/2022/05/GHSA-qrqv-r3qh-3qch/GHSA-qrqv-r3qh-3qch.json index dbacb0f1d53..dfdbfdf4423 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrqv-r3qh-3qch/GHSA-qrqv-r3qh-3qch.json +++ b/advisories/unreviewed/2022/05/GHSA-qrqv-r3qh-3qch/GHSA-qrqv-r3qh-3qch.json @@ -7,12 +7,8 @@ "CVE-2020-15698" ], "details": "An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvcv-qmqr-mm5j/GHSA-qvcv-qmqr-mm5j.json b/advisories/unreviewed/2022/05/GHSA-qvcv-qmqr-mm5j/GHSA-qvcv-qmqr-mm5j.json index 5f820fa650f..5acc7f61f08 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvcv-qmqr-mm5j/GHSA-qvcv-qmqr-mm5j.json +++ b/advisories/unreviewed/2022/05/GHSA-qvcv-qmqr-mm5j/GHSA-qvcv-qmqr-mm5j.json @@ -7,12 +7,8 @@ "CVE-2020-6276" ], "details": "SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qvh7-2qrg-6v75/GHSA-qvh7-2qrg-6v75.json b/advisories/unreviewed/2022/05/GHSA-qvh7-2qrg-6v75/GHSA-qvh7-2qrg-6v75.json index 06c631c4941..385651653bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvh7-2qrg-6v75/GHSA-qvh7-2qrg-6v75.json +++ b/advisories/unreviewed/2022/05/GHSA-qvh7-2qrg-6v75/GHSA-qvh7-2qrg-6v75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwh3-64hp-pv93/GHSA-qwh3-64hp-pv93.json b/advisories/unreviewed/2022/05/GHSA-qwh3-64hp-pv93/GHSA-qwh3-64hp-pv93.json index 813c123bec0..6596c2191e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwh3-64hp-pv93/GHSA-qwh3-64hp-pv93.json +++ b/advisories/unreviewed/2022/05/GHSA-qwh3-64hp-pv93/GHSA-qwh3-64hp-pv93.json @@ -7,12 +7,8 @@ "CVE-2020-2975" ], "details": "Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qwmp-427r-mgjp/GHSA-qwmp-427r-mgjp.json b/advisories/unreviewed/2022/05/GHSA-qwmp-427r-mgjp/GHSA-qwmp-427r-mgjp.json index 40d4202033c..a40af6775ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwmp-427r-mgjp/GHSA-qwmp-427r-mgjp.json +++ b/advisories/unreviewed/2022/05/GHSA-qwmp-427r-mgjp/GHSA-qwmp-427r-mgjp.json @@ -7,12 +7,8 @@ "CVE-2020-5768" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qww4-6xrg-jp26/GHSA-qww4-6xrg-jp26.json b/advisories/unreviewed/2022/05/GHSA-qww4-6xrg-jp26/GHSA-qww4-6xrg-jp26.json index cc94c935677..9c9fe6bbe9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qww4-6xrg-jp26/GHSA-qww4-6xrg-jp26.json +++ b/advisories/unreviewed/2022/05/GHSA-qww4-6xrg-jp26/GHSA-qww4-6xrg-jp26.json @@ -7,12 +7,8 @@ "CVE-2020-1410" ], "details": "A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vcard files.To exploit the vulnerability, an attacker could send a malicious vcard that a victim opens using Windows Address Book (WAB), aka 'Windows Address Book Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qx8g-5v5g-5jwf/GHSA-qx8g-5v5g-5jwf.json b/advisories/unreviewed/2022/05/GHSA-qx8g-5v5g-5jwf/GHSA-qx8g-5v5g-5jwf.json index f095fe26342..35b22225ca0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx8g-5v5g-5jwf/GHSA-qx8g-5v5g-5jwf.json +++ b/advisories/unreviewed/2022/05/GHSA-qx8g-5v5g-5jwf/GHSA-qx8g-5v5g-5jwf.json @@ -7,12 +7,8 @@ "CVE-2020-14705" ], "details": "Vulnerability in the Oracle GoldenGate product of Oracle GoldenGate (component: Process Management). The supported version that is affected is Prior to 19.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate executes to compromise Oracle GoldenGate. While the vulnerability is in Oracle GoldenGate, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxp2-p463-6f3f/GHSA-qxp2-p463-6f3f.json b/advisories/unreviewed/2022/05/GHSA-qxp2-p463-6f3f/GHSA-qxp2-p463-6f3f.json index fc8f85304c3..e98cd5b8778 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxp2-p463-6f3f/GHSA-qxp2-p463-6f3f.json +++ b/advisories/unreviewed/2022/05/GHSA-qxp2-p463-6f3f/GHSA-qxp2-p463-6f3f.json @@ -7,12 +7,8 @@ "CVE-2020-1406" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Network List Service handles objects in memory, aka 'Windows Network List Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r234-xxf3-j66w/GHSA-r234-xxf3-j66w.json b/advisories/unreviewed/2022/05/GHSA-r234-xxf3-j66w/GHSA-r234-xxf3-j66w.json index ac38633b191..564da9f77be 100644 --- a/advisories/unreviewed/2022/05/GHSA-r234-xxf3-j66w/GHSA-r234-xxf3-j66w.json +++ b/advisories/unreviewed/2022/05/GHSA-r234-xxf3-j66w/GHSA-r234-xxf3-j66w.json @@ -7,12 +7,8 @@ "CVE-2020-14982" ], "details": "A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker with the Employee, Supervisor, or Timekeeper role to read sensitive data from the database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r3xc-9hm9-gf29/GHSA-r3xc-9hm9-gf29.json b/advisories/unreviewed/2022/05/GHSA-r3xc-9hm9-gf29/GHSA-r3xc-9hm9-gf29.json index d4cee73562b..67ecce853db 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3xc-9hm9-gf29/GHSA-r3xc-9hm9-gf29.json +++ b/advisories/unreviewed/2022/05/GHSA-r3xc-9hm9-gf29/GHSA-r3xc-9hm9-gf29.json @@ -7,12 +7,8 @@ "CVE-2020-10987" ], "details": "The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r57g-7g9f-4m59/GHSA-r57g-7g9f-4m59.json b/advisories/unreviewed/2022/05/GHSA-r57g-7g9f-4m59/GHSA-r57g-7g9f-4m59.json index ac6261c915d..e752ebe0e28 100644 --- a/advisories/unreviewed/2022/05/GHSA-r57g-7g9f-4m59/GHSA-r57g-7g9f-4m59.json +++ b/advisories/unreviewed/2022/05/GHSA-r57g-7g9f-4m59/GHSA-r57g-7g9f-4m59.json @@ -7,12 +7,8 @@ "CVE-2020-15700" ], "details": "An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5f8-qh3m-c2jv/GHSA-r5f8-qh3m-c2jv.json b/advisories/unreviewed/2022/05/GHSA-r5f8-qh3m-c2jv/GHSA-r5f8-qh3m-c2jv.json index b44abd88502..a586485f058 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5f8-qh3m-c2jv/GHSA-r5f8-qh3m-c2jv.json +++ b/advisories/unreviewed/2022/05/GHSA-r5f8-qh3m-c2jv/GHSA-r5f8-qh3m-c2jv.json @@ -7,12 +7,8 @@ "CVE-2020-7826" ], "details": "EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting the arguments to the vulnerable method. This can be leveraged for code execution. When the vulnerable method is called, they fail to properly check the parameters that are passed to it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5qv-ggx3-m45h/GHSA-r5qv-ggx3-m45h.json b/advisories/unreviewed/2022/05/GHSA-r5qv-ggx3-m45h/GHSA-r5qv-ggx3-m45h.json index 6ac8595dac9..1782dea93c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5qv-ggx3-m45h/GHSA-r5qv-ggx3-m45h.json +++ b/advisories/unreviewed/2022/05/GHSA-r5qv-ggx3-m45h/GHSA-r5qv-ggx3-m45h.json @@ -7,12 +7,8 @@ "CVE-2020-14666" ], "details": "Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Display). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Email Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r659-cjpw-fq42/GHSA-r659-cjpw-fq42.json b/advisories/unreviewed/2022/05/GHSA-r659-cjpw-fq42/GHSA-r659-cjpw-fq42.json index 8ef5ad43254..c996b3bce6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r659-cjpw-fq42/GHSA-r659-cjpw-fq42.json +++ b/advisories/unreviewed/2022/05/GHSA-r659-cjpw-fq42/GHSA-r659-cjpw-fq42.json @@ -7,12 +7,8 @@ "CVE-2020-4095" ], "details": "\"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8h6-7wjg-5hcv/GHSA-r8h6-7wjg-5hcv.json b/advisories/unreviewed/2022/05/GHSA-r8h6-7wjg-5hcv/GHSA-r8h6-7wjg-5hcv.json index 7063d8e0268..7f66ddc8f8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8h6-7wjg-5hcv/GHSA-r8h6-7wjg-5hcv.json +++ b/advisories/unreviewed/2022/05/GHSA-r8h6-7wjg-5hcv/GHSA-r8h6-7wjg-5hcv.json @@ -7,12 +7,8 @@ "CVE-2020-14676" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8r8-pg44-2g9h/GHSA-r8r8-pg44-2g9h.json b/advisories/unreviewed/2022/05/GHSA-r8r8-pg44-2g9h/GHSA-r8r8-pg44-2g9h.json index 5faace8e4f2..19918e6eac2 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8r8-pg44-2g9h/GHSA-r8r8-pg44-2g9h.json +++ b/advisories/unreviewed/2022/05/GHSA-r8r8-pg44-2g9h/GHSA-r8r8-pg44-2g9h.json @@ -7,12 +7,8 @@ "CVE-2020-14655" ], "details": "Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: SSL API). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Security Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Security Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Security Service accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r928-prgx-2wf8/GHSA-r928-prgx-2wf8.json b/advisories/unreviewed/2022/05/GHSA-r928-prgx-2wf8/GHSA-r928-prgx-2wf8.json index 35a2d31854a..f706a169ae9 100644 --- a/advisories/unreviewed/2022/05/GHSA-r928-prgx-2wf8/GHSA-r928-prgx-2wf8.json +++ b/advisories/unreviewed/2022/05/GHSA-r928-prgx-2wf8/GHSA-r928-prgx-2wf8.json @@ -7,12 +7,8 @@ "CVE-2020-14661" ], "details": "Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9h3-wq94-qjg7/GHSA-r9h3-wq94-qjg7.json b/advisories/unreviewed/2022/05/GHSA-r9h3-wq94-qjg7/GHSA-r9h3-wq94-qjg7.json index 2ecaca6527b..6c65ce69334 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9h3-wq94-qjg7/GHSA-r9h3-wq94-qjg7.json +++ b/advisories/unreviewed/2022/05/GHSA-r9h3-wq94-qjg7/GHSA-r9h3-wq94-qjg7.json @@ -7,12 +7,8 @@ "CVE-2020-0225" ], "details": "In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142546668", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9w3-8xmh-6j5v/GHSA-r9w3-8xmh-6j5v.json b/advisories/unreviewed/2022/05/GHSA-r9w3-8xmh-6j5v/GHSA-r9w3-8xmh-6j5v.json index 1cac32ff4a4..8ce4b00bd71 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9w3-8xmh-6j5v/GHSA-r9w3-8xmh-6j5v.json +++ b/advisories/unreviewed/2022/05/GHSA-r9w3-8xmh-6j5v/GHSA-r9w3-8xmh-6j5v.json @@ -7,12 +7,8 @@ "CVE-2020-4364" ], "details": "IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178961.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rc2g-mp7j-69r8/GHSA-rc2g-mp7j-69r8.json b/advisories/unreviewed/2022/05/GHSA-rc2g-mp7j-69r8/GHSA-rc2g-mp7j-69r8.json index c9093257fbe..246281dc1f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc2g-mp7j-69r8/GHSA-rc2g-mp7j-69r8.json +++ b/advisories/unreviewed/2022/05/GHSA-rc2g-mp7j-69r8/GHSA-rc2g-mp7j-69r8.json @@ -7,12 +7,8 @@ "CVE-2020-3146" ], "details": "Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabilities are due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit these vulnerabilities by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rc79-v6cr-35gr/GHSA-rc79-v6cr-35gr.json b/advisories/unreviewed/2022/05/GHSA-rc79-v6cr-35gr/GHSA-rc79-v6cr-35gr.json index 0e143967c9f..6c7ce1ee0f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc79-v6cr-35gr/GHSA-rc79-v6cr-35gr.json +++ b/advisories/unreviewed/2022/05/GHSA-rc79-v6cr-35gr/GHSA-rc79-v6cr-35gr.json @@ -7,12 +7,8 @@ "CVE-2020-14630" ], "details": "Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications Applications (component: File Upload). Supported versions that are affected are 8.1.0, 8.2.0 and 8.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Session Border Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Session Border Controller as well as unauthorized update, insert or delete access to some of Oracle Enterprise Session Border Controller accessible data and unauthorized read access to a subset of Oracle Enterprise Session Border Controller accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcxr-7wqj-r3gh/GHSA-rcxr-7wqj-r3gh.json b/advisories/unreviewed/2022/05/GHSA-rcxr-7wqj-r3gh/GHSA-rcxr-7wqj-r3gh.json index c8220527960..a30ca8f5fcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcxr-7wqj-r3gh/GHSA-rcxr-7wqj-r3gh.json +++ b/advisories/unreviewed/2022/05/GHSA-rcxr-7wqj-r3gh/GHSA-rcxr-7wqj-r3gh.json @@ -7,12 +7,8 @@ "CVE-2020-1438" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1373, CVE-2020-1390, CVE-2020-1427, CVE-2020-1428.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rf74-pjr5-fx8f/GHSA-rf74-pjr5-fx8f.json b/advisories/unreviewed/2022/05/GHSA-rf74-pjr5-fx8f/GHSA-rf74-pjr5-fx8f.json index 1f331561213..8cd4498cfb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf74-pjr5-fx8f/GHSA-rf74-pjr5-fx8f.json +++ b/advisories/unreviewed/2022/05/GHSA-rf74-pjr5-fx8f/GHSA-rf74-pjr5-fx8f.json @@ -7,12 +7,8 @@ "CVE-2020-14628" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: The CVE-2020-14628 is applicable to Windows VM only. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rfp5-cghp-26q7/GHSA-rfp5-cghp-26q7.json b/advisories/unreviewed/2022/05/GHSA-rfp5-cghp-26q7/GHSA-rfp5-cghp-26q7.json index 463d0ddcfcd..4b4938e0105 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfp5-cghp-26q7/GHSA-rfp5-cghp-26q7.json +++ b/advisories/unreviewed/2022/05/GHSA-rfp5-cghp-26q7/GHSA-rfp5-cghp-26q7.json @@ -7,12 +7,8 @@ "CVE-2020-14531" ], "details": "Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supported versions that are affected are 20.6 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel UI Framework accessible data as well as unauthorized update, insert or delete access to some of Siebel UI Framework accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rg4w-pmq3-w38h/GHSA-rg4w-pmq3-w38h.json b/advisories/unreviewed/2022/05/GHSA-rg4w-pmq3-w38h/GHSA-rg4w-pmq3-w38h.json index 552da0ea13a..734107c8fbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg4w-pmq3-w38h/GHSA-rg4w-pmq3-w38h.json +++ b/advisories/unreviewed/2022/05/GHSA-rg4w-pmq3-w38h/GHSA-rg4w-pmq3-w38h.json @@ -7,12 +7,8 @@ "CVE-2020-1361" ], "details": "An information disclosure vulnerability exists in the way that the WalletService handles memory.To exploit the vulnerability, an attacker would first need code execution on a victim system, aka 'Windows WalletService Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjjr-9j82-pc8r/GHSA-rjjr-9j82-pc8r.json b/advisories/unreviewed/2022/05/GHSA-rjjr-9j82-pc8r/GHSA-rjjr-9j82-pc8r.json index 22233bd536c..15b3e6b1b71 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjjr-9j82-pc8r/GHSA-rjjr-9j82-pc8r.json +++ b/advisories/unreviewed/2022/05/GHSA-rjjr-9j82-pc8r/GHSA-rjjr-9j82-pc8r.json @@ -7,12 +7,8 @@ "CVE-2020-14703" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjmm-h25r-cqxf/GHSA-rjmm-h25r-cqxf.json b/advisories/unreviewed/2022/05/GHSA-rjmm-h25r-cqxf/GHSA-rjmm-h25r-cqxf.json index 2a9f6408db9..eeb3d988db0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjmm-h25r-cqxf/GHSA-rjmm-h25r-cqxf.json +++ b/advisories/unreviewed/2022/05/GHSA-rjmm-h25r-cqxf/GHSA-rjmm-h25r-cqxf.json @@ -7,12 +7,8 @@ "CVE-2020-3358" ], "details": "A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an unauthenticated, remote attacker to cause the device to unexpectedly restart, causing a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request over an SSL connection to the targeted device. A successful exploit could allow the attacker to cause a reload, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjp2-9xwv-c3mp/GHSA-rjp2-9xwv-c3mp.json b/advisories/unreviewed/2022/05/GHSA-rjp2-9xwv-c3mp/GHSA-rjp2-9xwv-c3mp.json index 4befbef6c25..2e0ea5c1600 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjp2-9xwv-c3mp/GHSA-rjp2-9xwv-c3mp.json +++ b/advisories/unreviewed/2022/05/GHSA-rjp2-9xwv-c3mp/GHSA-rjp2-9xwv-c3mp.json @@ -7,12 +7,8 @@ "CVE-2020-11546" ], "details": "SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rm33-h23j-qcgg/GHSA-rm33-h23j-qcgg.json b/advisories/unreviewed/2022/05/GHSA-rm33-h23j-qcgg/GHSA-rm33-h23j-qcgg.json index e40a4485192..a8e73f5e01f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm33-h23j-qcgg/GHSA-rm33-h23j-qcgg.json +++ b/advisories/unreviewed/2022/05/GHSA-rm33-h23j-qcgg/GHSA-rm33-h23j-qcgg.json @@ -7,12 +7,8 @@ "CVE-2019-17639" ], "details": "In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This allows whatever value happens to be in the return register at that time to be used as if it matches the method's declared return type.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rp99-4vgc-7q2h/GHSA-rp99-4vgc-7q2h.json b/advisories/unreviewed/2022/05/GHSA-rp99-4vgc-7q2h/GHSA-rp99-4vgc-7q2h.json index 70b8909bb8e..6d9c1b58de9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp99-4vgc-7q2h/GHSA-rp99-4vgc-7q2h.json +++ b/advisories/unreviewed/2022/05/GHSA-rp99-4vgc-7q2h/GHSA-rp99-4vgc-7q2h.json @@ -7,12 +7,8 @@ "CVE-2020-3323" ], "details": "A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system of the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rprf-22xr-7gr9/GHSA-rprf-22xr-7gr9.json b/advisories/unreviewed/2022/05/GHSA-rprf-22xr-7gr9/GHSA-rprf-22xr-7gr9.json index 5a2de43c1e3..a8ed34390bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rprf-22xr-7gr9/GHSA-rprf-22xr-7gr9.json +++ b/advisories/unreviewed/2022/05/GHSA-rprf-22xr-7gr9/GHSA-rprf-22xr-7gr9.json @@ -7,12 +7,8 @@ "CVE-2020-14589" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rprg-5xpx-hm4h/GHSA-rprg-5xpx-hm4h.json b/advisories/unreviewed/2022/05/GHSA-rprg-5xpx-hm4h/GHSA-rprg-5xpx-hm4h.json index 9f77ac30537..ec2fc28dea2 100644 --- a/advisories/unreviewed/2022/05/GHSA-rprg-5xpx-hm4h/GHSA-rprg-5xpx-hm4h.json +++ b/advisories/unreviewed/2022/05/GHSA-rprg-5xpx-hm4h/GHSA-rprg-5xpx-hm4h.json @@ -7,12 +7,8 @@ "CVE-2020-2966" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvvc-h3jc-25vx/GHSA-rvvc-h3jc-25vx.json b/advisories/unreviewed/2022/05/GHSA-rvvc-h3jc-25vx/GHSA-rvvc-h3jc-25vx.json index 6ce2a630a2d..4f7f341a775 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvvc-h3jc-25vx/GHSA-rvvc-h3jc-25vx.json +++ b/advisories/unreviewed/2022/05/GHSA-rvvc-h3jc-25vx/GHSA-rvvc-h3jc-25vx.json @@ -7,12 +7,8 @@ "CVE-2020-14535" ], "details": "Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). Supported versions that are affected are 11.1, 11.2 and prior to 11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Service Center accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Service Center accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rw25-fj2c-r3cf/GHSA-rw25-fj2c-r3cf.json b/advisories/unreviewed/2022/05/GHSA-rw25-fj2c-r3cf/GHSA-rw25-fj2c-r3cf.json index 163e519faff..501646c32cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw25-fj2c-r3cf/GHSA-rw25-fj2c-r3cf.json +++ b/advisories/unreviewed/2022/05/GHSA-rw25-fj2c-r3cf/GHSA-rw25-fj2c-r3cf.json @@ -7,12 +7,8 @@ "CVE-2020-14596" ], "details": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Address Book). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rxjg-qv62-7h6c/GHSA-rxjg-qv62-7h6c.json b/advisories/unreviewed/2022/05/GHSA-rxjg-qv62-7h6c/GHSA-rxjg-qv62-7h6c.json index 11165f53f0f..15f98771908 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxjg-qv62-7h6c/GHSA-rxjg-qv62-7h6c.json +++ b/advisories/unreviewed/2022/05/GHSA-rxjg-qv62-7h6c/GHSA-rxjg-qv62-7h6c.json @@ -7,12 +7,8 @@ "CVE-2020-1392" ], "details": "An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1388, CVE-2020-1394, CVE-2020-1395.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v24j-qh4f-h3p9/GHSA-v24j-qh4f-h3p9.json b/advisories/unreviewed/2022/05/GHSA-v24j-qh4f-h3p9/GHSA-v24j-qh4f-h3p9.json index 2c23d640cfb..6d6ef103559 100644 --- a/advisories/unreviewed/2022/05/GHSA-v24j-qh4f-h3p9/GHSA-v24j-qh4f-h3p9.json +++ b/advisories/unreviewed/2022/05/GHSA-v24j-qh4f-h3p9/GHSA-v24j-qh4f-h3p9.json @@ -7,12 +7,8 @@ "CVE-2020-14686" ], "details": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iSupport accessible data as well as unauthorized update, insert or delete access to some of Oracle iSupport accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v332-vxq6-2g47/GHSA-v332-vxq6-2g47.json b/advisories/unreviewed/2022/05/GHSA-v332-vxq6-2g47/GHSA-v332-vxq6-2g47.json index fa79f0c190d..18ab25677a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-v332-vxq6-2g47/GHSA-v332-vxq6-2g47.json +++ b/advisories/unreviewed/2022/05/GHSA-v332-vxq6-2g47/GHSA-v332-vxq6-2g47.json @@ -7,12 +7,8 @@ "CVE-2020-1445" ], "details": "An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3rv-628p-7xrq/GHSA-v3rv-628p-7xrq.json b/advisories/unreviewed/2022/05/GHSA-v3rv-628p-7xrq/GHSA-v3rv-628p-7xrq.json index 11b48ef4a41..f0d1c1b3416 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3rv-628p-7xrq/GHSA-v3rv-628p-7xrq.json +++ b/advisories/unreviewed/2022/05/GHSA-v3rv-628p-7xrq/GHSA-v3rv-628p-7xrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4f9-rmvp-3fj3/GHSA-v4f9-rmvp-3fj3.json b/advisories/unreviewed/2022/05/GHSA-v4f9-rmvp-3fj3/GHSA-v4f9-rmvp-3fj3.json index 0eece9ece11..759f0093441 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4f9-rmvp-3fj3/GHSA-v4f9-rmvp-3fj3.json +++ b/advisories/unreviewed/2022/05/GHSA-v4f9-rmvp-3fj3/GHSA-v4f9-rmvp-3fj3.json @@ -7,12 +7,8 @@ "CVE-2020-14544" ], "details": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Data, Domain & Function Security). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4pf-jxx8-c862/GHSA-v4pf-jxx8-c862.json b/advisories/unreviewed/2022/05/GHSA-v4pf-jxx8-c862/GHSA-v4pf-jxx8-c862.json index b1066247eab..5af63ad5d55 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4pf-jxx8-c862/GHSA-v4pf-jxx8-c862.json +++ b/advisories/unreviewed/2022/05/GHSA-v4pf-jxx8-c862/GHSA-v4pf-jxx8-c862.json @@ -7,12 +7,8 @@ "CVE-2020-1461" ], "details": "An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5xw-43vp-r66x/GHSA-v5xw-43vp-r66x.json b/advisories/unreviewed/2022/05/GHSA-v5xw-43vp-r66x/GHSA-v5xw-43vp-r66x.json index 0dc0a30961a..9dae3081f40 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5xw-43vp-r66x/GHSA-v5xw-43vp-r66x.json +++ b/advisories/unreviewed/2022/05/GHSA-v5xw-43vp-r66x/GHSA-v5xw-43vp-r66x.json @@ -7,12 +7,8 @@ "CVE-2020-4100" ], "details": "\"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtime; however, dynamically loaded components are only loaded as they are specifically requested. While this can have a positive impact on performance, or grant additional functionality (for example, a non-invasive update feature), it can also open the application to loading unintended code if not implemented properly.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6ph-x2c7-6g37/GHSA-v6ph-x2c7-6g37.json b/advisories/unreviewed/2022/05/GHSA-v6ph-x2c7-6g37/GHSA-v6ph-x2c7-6g37.json index c5d2fd37ea7..a9275fba9b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6ph-x2c7-6g37/GHSA-v6ph-x2c7-6g37.json +++ b/advisories/unreviewed/2022/05/GHSA-v6ph-x2c7-6g37/GHSA-v6ph-x2c7-6g37.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7ff-8293-rf9q/GHSA-v7ff-8293-rf9q.json b/advisories/unreviewed/2022/05/GHSA-v7ff-8293-rf9q/GHSA-v7ff-8293-rf9q.json index 16f8d671502..e018f02a2b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7ff-8293-rf9q/GHSA-v7ff-8293-rf9q.json +++ b/advisories/unreviewed/2022/05/GHSA-v7ff-8293-rf9q/GHSA-v7ff-8293-rf9q.json @@ -7,12 +7,8 @@ "CVE-2020-3405" ], "details": "A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files within the affected application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v827-8qrw-cxmg/GHSA-v827-8qrw-cxmg.json b/advisories/unreviewed/2022/05/GHSA-v827-8qrw-cxmg/GHSA-v827-8qrw-cxmg.json index f14819b26cc..e9538e4595f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v827-8qrw-cxmg/GHSA-v827-8qrw-cxmg.json +++ b/advisories/unreviewed/2022/05/GHSA-v827-8qrw-cxmg/GHSA-v827-8qrw-cxmg.json @@ -7,12 +7,8 @@ "CVE-2020-1347" ], "details": "An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations, aka 'Windows Storage Services Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v88m-pxx4-rpwh/GHSA-v88m-pxx4-rpwh.json b/advisories/unreviewed/2022/05/GHSA-v88m-pxx4-rpwh/GHSA-v88m-pxx4-rpwh.json index 55e1afd8e47..8dd2277a693 100644 --- a/advisories/unreviewed/2022/05/GHSA-v88m-pxx4-rpwh/GHSA-v88m-pxx4-rpwh.json +++ b/advisories/unreviewed/2022/05/GHSA-v88m-pxx4-rpwh/GHSA-v88m-pxx4-rpwh.json @@ -7,12 +7,8 @@ "CVE-2020-4511" ], "details": "IBM QRadar SIEM 7.3 and 7.4 could allow an authenticated user to cause a denial of service of the qflow process by sending a malformed sflow command. IBM X-Force ID: 182366.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v8hv-78vf-x9fr/GHSA-v8hv-78vf-x9fr.json b/advisories/unreviewed/2022/05/GHSA-v8hv-78vf-x9fr/GHSA-v8hv-78vf-x9fr.json index dc778fcc9c5..5af776e6654 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8hv-78vf-x9fr/GHSA-v8hv-78vf-x9fr.json +++ b/advisories/unreviewed/2022/05/GHSA-v8hv-78vf-x9fr/GHSA-v8hv-78vf-x9fr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8pj-w2gf-97p5/GHSA-v8pj-w2gf-97p5.json b/advisories/unreviewed/2022/05/GHSA-v8pj-w2gf-97p5/GHSA-v8pj-w2gf-97p5.json index ec58a90dc3b..c9f80f31ddf 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8pj-w2gf-97p5/GHSA-v8pj-w2gf-97p5.json +++ b/advisories/unreviewed/2022/05/GHSA-v8pj-w2gf-97p5/GHSA-v8pj-w2gf-97p5.json @@ -7,12 +7,8 @@ "CVE-2020-14716" ], "details": "Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Common Applications accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v8pq-r8j2-c95m/GHSA-v8pq-r8j2-c95m.json b/advisories/unreviewed/2022/05/GHSA-v8pq-r8j2-c95m/GHSA-v8pq-r8j2-c95m.json index 6b3232e6c67..f8b0a8951b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8pq-r8j2-c95m/GHSA-v8pq-r8j2-c95m.json +++ b/advisories/unreviewed/2022/05/GHSA-v8pq-r8j2-c95m/GHSA-v8pq-r8j2-c95m.json @@ -7,12 +7,8 @@ "CVE-2020-9650" ], "details": "Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9pw-w8q4-wvjx/GHSA-v9pw-w8q4-wvjx.json b/advisories/unreviewed/2022/05/GHSA-v9pw-w8q4-wvjx/GHSA-v9pw-w8q4-wvjx.json index 1311d4929f2..e91d69368eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9pw-w8q4-wvjx/GHSA-v9pw-w8q4-wvjx.json +++ b/advisories/unreviewed/2022/05/GHSA-v9pw-w8q4-wvjx/GHSA-v9pw-w8q4-wvjx.json @@ -7,12 +7,8 @@ "CVE-2020-9682" ], "details": "Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to arbitrary file system write.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vf2p-4grj-v3x6/GHSA-vf2p-4grj-v3x6.json b/advisories/unreviewed/2022/05/GHSA-vf2p-4grj-v3x6/GHSA-vf2p-4grj-v3x6.json index 2f63d93e053..d15dcab5c66 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf2p-4grj-v3x6/GHSA-vf2p-4grj-v3x6.json +++ b/advisories/unreviewed/2022/05/GHSA-vf2p-4grj-v3x6/GHSA-vf2p-4grj-v3x6.json @@ -7,12 +7,8 @@ "CVE-2020-1652" ], "details": "OpenNMS is accessible via port 9443", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vfjj-qc2j-f9fm/GHSA-vfjj-qc2j-f9fm.json b/advisories/unreviewed/2022/05/GHSA-vfjj-qc2j-f9fm/GHSA-vfjj-qc2j-f9fm.json index 73d350e588f..7bd04d31152 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfjj-qc2j-f9fm/GHSA-vfjj-qc2j-f9fm.json +++ b/advisories/unreviewed/2022/05/GHSA-vfjj-qc2j-f9fm/GHSA-vfjj-qc2j-f9fm.json @@ -7,12 +7,8 @@ "CVE-2020-1355" ], "details": "A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correcting how the Windows Font Driver Host handles memory., aka 'Windows Font Driver Host Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg2x-vv9h-gh22/GHSA-vg2x-vv9h-gh22.json b/advisories/unreviewed/2022/05/GHSA-vg2x-vv9h-gh22/GHSA-vg2x-vv9h-gh22.json index 307d47e4a91..3bf606c4180 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg2x-vv9h-gh22/GHSA-vg2x-vv9h-gh22.json +++ b/advisories/unreviewed/2022/05/GHSA-vg2x-vv9h-gh22/GHSA-vg2x-vv9h-gh22.json @@ -7,12 +7,8 @@ "CVE-2020-1353" ], "details": "An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vgr6-5xvp-97cc/GHSA-vgr6-5xvp-97cc.json b/advisories/unreviewed/2022/05/GHSA-vgr6-5xvp-97cc/GHSA-vgr6-5xvp-97cc.json index d21aaf87233..4e07adca1d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgr6-5xvp-97cc/GHSA-vgr6-5xvp-97cc.json +++ b/advisories/unreviewed/2022/05/GHSA-vgr6-5xvp-97cc/GHSA-vgr6-5xvp-97cc.json @@ -7,12 +7,8 @@ "CVE-2020-2967" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjmv-w2p6-c95q/GHSA-vjmv-w2p6-c95q.json b/advisories/unreviewed/2022/05/GHSA-vjmv-w2p6-c95q/GHSA-vjmv-w2p6-c95q.json index 286fbf1dae4..260f90108df 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjmv-w2p6-c95q/GHSA-vjmv-w2p6-c95q.json +++ b/advisories/unreviewed/2022/05/GHSA-vjmv-w2p6-c95q/GHSA-vjmv-w2p6-c95q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm7p-7vqv-5rq2/GHSA-vm7p-7vqv-5rq2.json b/advisories/unreviewed/2022/05/GHSA-vm7p-7vqv-5rq2/GHSA-vm7p-7vqv-5rq2.json index f9a3c9e12a4..69d3d161e4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm7p-7vqv-5rq2/GHSA-vm7p-7vqv-5rq2.json +++ b/advisories/unreviewed/2022/05/GHSA-vm7p-7vqv-5rq2/GHSA-vm7p-7vqv-5rq2.json @@ -7,12 +7,8 @@ "CVE-2020-10286" ], "details": "the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp53-9vpq-jfg7/GHSA-vp53-9vpq-jfg7.json b/advisories/unreviewed/2022/05/GHSA-vp53-9vpq-jfg7/GHSA-vp53-9vpq-jfg7.json index c917cc7d486..720bd4d84a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp53-9vpq-jfg7/GHSA-vp53-9vpq-jfg7.json +++ b/advisories/unreviewed/2022/05/GHSA-vp53-9vpq-jfg7/GHSA-vp53-9vpq-jfg7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp8r-c28c-cc69/GHSA-vp8r-c28c-cc69.json b/advisories/unreviewed/2022/05/GHSA-vp8r-c28c-cc69/GHSA-vp8r-c28c-cc69.json index fef694fb1e0..ea76efa42b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp8r-c28c-cc69/GHSA-vp8r-c28c-cc69.json +++ b/advisories/unreviewed/2022/05/GHSA-vp8r-c28c-cc69/GHSA-vp8r-c28c-cc69.json @@ -7,12 +7,8 @@ "CVE-2020-10037" ], "details": "A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). By performing a flooding attack against the web server, an attacker might be able to gain read access to the device's memory, possibly revealing confidential information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpvj-7qfp-4qgg/GHSA-vpvj-7qfp-4qgg.json b/advisories/unreviewed/2022/05/GHSA-vpvj-7qfp-4qgg/GHSA-vpvj-7qfp-4qgg.json index 3c68b4755f6..ea9e6b61ffc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpvj-7qfp-4qgg/GHSA-vpvj-7qfp-4qgg.json +++ b/advisories/unreviewed/2022/05/GHSA-vpvj-7qfp-4qgg/GHSA-vpvj-7qfp-4qgg.json @@ -7,12 +7,8 @@ "CVE-2020-7584" ], "details": "A vulnerability has been identified in SIMATIC S7-200 SMART CPU family (All versions >= V2.2 < V2.5.1). Affected devices do not properly handle large numbers of new incomming connections and could crash under certain circumstances. An attacker may leverage this to cause a Denial-of-Service situation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vqjv-866h-qv94/GHSA-vqjv-866h-qv94.json b/advisories/unreviewed/2022/05/GHSA-vqjv-866h-qv94/GHSA-vqjv-866h-qv94.json index 59d52dbea42..35640bd44c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqjv-866h-qv94/GHSA-vqjv-866h-qv94.json +++ b/advisories/unreviewed/2022/05/GHSA-vqjv-866h-qv94/GHSA-vqjv-866h-qv94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqmw-xc69-r5c5/GHSA-vqmw-xc69-r5c5.json b/advisories/unreviewed/2022/05/GHSA-vqmw-xc69-r5c5/GHSA-vqmw-xc69-r5c5.json index c40e529255c..b0e5d1bd7e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqmw-xc69-r5c5/GHSA-vqmw-xc69-r5c5.json +++ b/advisories/unreviewed/2022/05/GHSA-vqmw-xc69-r5c5/GHSA-vqmw-xc69-r5c5.json @@ -7,12 +7,8 @@ "CVE-2020-9101" ], "details": "There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot. Affected product versions include: IPS Module versions V500R005C00, V500R005C10; NGFW Module versions V500R005C00, V500R005C10; Secospace USG6300 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; Secospace USG6500 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; Secospace USG6600 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; USG9500 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vqpg-rq94-24x7/GHSA-vqpg-rq94-24x7.json b/advisories/unreviewed/2022/05/GHSA-vqpg-rq94-24x7/GHSA-vqpg-rq94-24x7.json index 87b9032c318..137dcd439e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqpg-rq94-24x7/GHSA-vqpg-rq94-24x7.json +++ b/advisories/unreviewed/2022/05/GHSA-vqpg-rq94-24x7/GHSA-vqpg-rq94-24x7.json @@ -7,12 +7,8 @@ "CVE-2020-1434" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Sync Host Service handles objects in memory, aka 'Windows Sync Host Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrgf-6qrc-hmmg/GHSA-vrgf-6qrc-hmmg.json b/advisories/unreviewed/2022/05/GHSA-vrgf-6qrc-hmmg/GHSA-vrgf-6qrc-hmmg.json index 9beaeaa9f70..b25a792c2af 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrgf-6qrc-hmmg/GHSA-vrgf-6qrc-hmmg.json +++ b/advisories/unreviewed/2022/05/GHSA-vrgf-6qrc-hmmg/GHSA-vrgf-6qrc-hmmg.json @@ -7,12 +7,8 @@ "CVE-2020-1409" ], "details": "A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vv73-vfwf-c289/GHSA-vv73-vfwf-c289.json b/advisories/unreviewed/2022/05/GHSA-vv73-vfwf-c289/GHSA-vv73-vfwf-c289.json index 67d0c0ffd1f..9dea82afa67 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv73-vfwf-c289/GHSA-vv73-vfwf-c289.json +++ b/advisories/unreviewed/2022/05/GHSA-vv73-vfwf-c289/GHSA-vv73-vfwf-c289.json @@ -7,12 +7,8 @@ "CVE-2020-1394" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Geolocation Framework handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1388, CVE-2020-1392, CVE-2020-1395.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxmj-7jcq-859j/GHSA-vxmj-7jcq-859j.json b/advisories/unreviewed/2022/05/GHSA-vxmj-7jcq-859j/GHSA-vxmj-7jcq-859j.json index fe3d06a3d0c..520ea7fb12d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxmj-7jcq-859j/GHSA-vxmj-7jcq-859j.json +++ b/advisories/unreviewed/2022/05/GHSA-vxmj-7jcq-859j/GHSA-vxmj-7jcq-859j.json @@ -7,12 +7,8 @@ "CVE-2020-14722" ], "details": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Communications Broker, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Communications Broker accessible data as well as unauthorized read access to a subset of Oracle Enterprise Communications Broker accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 5.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w22c-hvvf-f3qp/GHSA-w22c-hvvf-f3qp.json b/advisories/unreviewed/2022/05/GHSA-w22c-hvvf-f3qp/GHSA-w22c-hvvf-f3qp.json index 976702def3a..05ffb722fae 100644 --- a/advisories/unreviewed/2022/05/GHSA-w22c-hvvf-f3qp/GHSA-w22c-hvvf-f3qp.json +++ b/advisories/unreviewed/2022/05/GHSA-w22c-hvvf-f3qp/GHSA-w22c-hvvf-f3qp.json @@ -7,12 +7,8 @@ "CVE-2020-14653" ], "details": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 16.1.0.0-16.2.20.1, 17.1.0.0-17.12.17.1 and 18.1.0.0-18.8.18.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w23p-q69p-ffp6/GHSA-w23p-q69p-ffp6.json b/advisories/unreviewed/2022/05/GHSA-w23p-q69p-ffp6/GHSA-w23p-q69p-ffp6.json index 8d579dc0ada..b4011cf8930 100644 --- a/advisories/unreviewed/2022/05/GHSA-w23p-q69p-ffp6/GHSA-w23p-q69p-ffp6.json +++ b/advisories/unreviewed/2022/05/GHSA-w23p-q69p-ffp6/GHSA-w23p-q69p-ffp6.json @@ -7,12 +7,8 @@ "CVE-2020-2971" ], "details": "Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w3m2-2x65-hm4m/GHSA-w3m2-2x65-hm4m.json b/advisories/unreviewed/2022/05/GHSA-w3m2-2x65-hm4m/GHSA-w3m2-2x65-hm4m.json index 2172d9bae08..90b9c89104c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3m2-2x65-hm4m/GHSA-w3m2-2x65-hm4m.json +++ b/advisories/unreviewed/2022/05/GHSA-w3m2-2x65-hm4m/GHSA-w3m2-2x65-hm4m.json @@ -7,12 +7,8 @@ "CVE-2019-20915" ], "details": "An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4jc-4p46-64m5/GHSA-w4jc-4p46-64m5.json b/advisories/unreviewed/2022/05/GHSA-w4jc-4p46-64m5/GHSA-w4jc-4p46-64m5.json index a4eead784de..d727114068b 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4jc-4p46-64m5/GHSA-w4jc-4p46-64m5.json +++ b/advisories/unreviewed/2022/05/GHSA-w4jc-4p46-64m5/GHSA-w4jc-4p46-64m5.json @@ -7,12 +7,8 @@ "CVE-2020-14720" ], "details": "Vulnerability in the Oracle Internet Expenses product of Oracle E-Business Suite (component: Mobile Expenses Admin Utilities). Supported versions that are affected are 12.2.4-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Internet Expenses. While the vulnerability is in Oracle Internet Expenses, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Internet Expenses accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4r7-r278-c53j/GHSA-w4r7-r278-c53j.json b/advisories/unreviewed/2022/05/GHSA-w4r7-r278-c53j/GHSA-w4r7-r278-c53j.json index 61c8f954236..b9cf4d59a39 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4r7-r278-c53j/GHSA-w4r7-r278-c53j.json +++ b/advisories/unreviewed/2022/05/GHSA-w4r7-r278-c53j/GHSA-w4r7-r278-c53j.json @@ -7,12 +7,8 @@ "CVE-2020-1367" ], "details": "An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1389, CVE-2020-1419, CVE-2020-1426.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4w8-866m-jm68/GHSA-w4w8-866m-jm68.json b/advisories/unreviewed/2022/05/GHSA-w4w8-866m-jm68/GHSA-w4w8-866m-jm68.json index 0da7d49b28a..91413e6aceb 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4w8-866m-jm68/GHSA-w4w8-866m-jm68.json +++ b/advisories/unreviewed/2022/05/GHSA-w4w8-866m-jm68/GHSA-w4w8-866m-jm68.json @@ -7,12 +7,8 @@ "CVE-2020-0224" ], "details": "In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could lead to remote code execution when processing a proxy configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-147664838", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w56w-fjv4-mc6j/GHSA-w56w-fjv4-mc6j.json b/advisories/unreviewed/2022/05/GHSA-w56w-fjv4-mc6j/GHSA-w56w-fjv4-mc6j.json index 5164887f2a3..b9647c70d0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w56w-fjv4-mc6j/GHSA-w56w-fjv4-mc6j.json +++ b/advisories/unreviewed/2022/05/GHSA-w56w-fjv4-mc6j/GHSA-w56w-fjv4-mc6j.json @@ -7,12 +7,8 @@ "CVE-2020-5765" ], "details": "Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit this vulnerability to execute arbitrary code in a user's session. Tenable has implemented additional input validation mechanisms to correct this issue in Nessus 8.11.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w589-g2rj-2m9m/GHSA-w589-g2rj-2m9m.json b/advisories/unreviewed/2022/05/GHSA-w589-g2rj-2m9m/GHSA-w589-g2rj-2m9m.json index 0251531173a..dbb2618a9cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-w589-g2rj-2m9m/GHSA-w589-g2rj-2m9m.json +++ b/advisories/unreviewed/2022/05/GHSA-w589-g2rj-2m9m/GHSA-w589-g2rj-2m9m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w659-xcxv-5rqq/GHSA-w659-xcxv-5rqq.json b/advisories/unreviewed/2022/05/GHSA-w659-xcxv-5rqq/GHSA-w659-xcxv-5rqq.json index 91c21d43467..4606969c566 100644 --- a/advisories/unreviewed/2022/05/GHSA-w659-xcxv-5rqq/GHSA-w659-xcxv-5rqq.json +++ b/advisories/unreviewed/2022/05/GHSA-w659-xcxv-5rqq/GHSA-w659-xcxv-5rqq.json @@ -7,12 +7,8 @@ "CVE-2020-1357" ], "details": "An elevation of privilege vulnerability exists when the Windows System Events Broker improperly handles file operations, aka 'Windows System Events Broker Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6fg-5cg7-v6wj/GHSA-w6fg-5cg7-v6wj.json b/advisories/unreviewed/2022/05/GHSA-w6fg-5cg7-v6wj/GHSA-w6fg-5cg7-v6wj.json index 23573289be3..fe25e08b52f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6fg-5cg7-v6wj/GHSA-w6fg-5cg7-v6wj.json +++ b/advisories/unreviewed/2022/05/GHSA-w6fg-5cg7-v6wj/GHSA-w6fg-5cg7-v6wj.json @@ -7,12 +7,8 @@ "CVE-2020-14674" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w72r-jmv8-r4gh/GHSA-w72r-jmv8-r4gh.json b/advisories/unreviewed/2022/05/GHSA-w72r-jmv8-r4gh/GHSA-w72r-jmv8-r4gh.json index 6f0b11655a5..4d67dd05092 100644 --- a/advisories/unreviewed/2022/05/GHSA-w72r-jmv8-r4gh/GHSA-w72r-jmv8-r4gh.json +++ b/advisories/unreviewed/2022/05/GHSA-w72r-jmv8-r4gh/GHSA-w72r-jmv8-r4gh.json @@ -7,12 +7,8 @@ "CVE-2020-6100" ], "details": "An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially crafted pixel shader can cause memory corruption vulnerability. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability potentially could be triggered from guest machines running virtualization environments (ie. VMware, qemu, VirtualBox etc.) in order to perform guest-to-host escape - as it was demonstrated before (TALOS-2018-0533, TALOS-2018-0568, etc.). Theoretically this vulnerability could be also triggered from web browser (using webGL and webassembly). This vulnerability was triggered from HYPER-V guest using RemoteFX feature leading to executing the vulnerable code on the HYPER-V host (inside of the rdvgm.exe process).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w7c2-4qqr-9227/GHSA-w7c2-4qqr-9227.json b/advisories/unreviewed/2022/05/GHSA-w7c2-4qqr-9227/GHSA-w7c2-4qqr-9227.json index dad77cc1a27..e4e31f31b57 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7c2-4qqr-9227/GHSA-w7c2-4qqr-9227.json +++ b/advisories/unreviewed/2022/05/GHSA-w7c2-4qqr-9227/GHSA-w7c2-4qqr-9227.json @@ -7,12 +7,8 @@ "CVE-2020-15697" ], "details": "An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w7h4-8f3v-m646/GHSA-w7h4-8f3v-m646.json b/advisories/unreviewed/2022/05/GHSA-w7h4-8f3v-m646/GHSA-w7h4-8f3v-m646.json index 65cae793e64..a9834005f78 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7h4-8f3v-m646/GHSA-w7h4-8f3v-m646.json +++ b/advisories/unreviewed/2022/05/GHSA-w7h4-8f3v-m646/GHSA-w7h4-8f3v-m646.json @@ -7,12 +7,8 @@ "CVE-2020-14691" ], "details": "Vulnerability in the Oracle Financial Services Liquidity Risk Management product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.0.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Liquidity Risk Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Liquidity Risk Management accessible data as well as unauthorized read access to a subset of Oracle Financial Services Liquidity Risk Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8x8-8rp7-r92g/GHSA-w8x8-8rp7-r92g.json b/advisories/unreviewed/2022/05/GHSA-w8x8-8rp7-r92g/GHSA-w8x8-8rp7-r92g.json index 85ec53fa69c..276d44153ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8x8-8rp7-r92g/GHSA-w8x8-8rp7-r92g.json +++ b/advisories/unreviewed/2022/05/GHSA-w8x8-8rp7-r92g/GHSA-w8x8-8rp7-r92g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w97w-4jr9-q2r8/GHSA-w97w-4jr9-q2r8.json b/advisories/unreviewed/2022/05/GHSA-w97w-4jr9-q2r8/GHSA-w97w-4jr9-q2r8.json index a6054b74a05..627b06faac6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w97w-4jr9-q2r8/GHSA-w97w-4jr9-q2r8.json +++ b/advisories/unreviewed/2022/05/GHSA-w97w-4jr9-q2r8/GHSA-w97w-4jr9-q2r8.json @@ -7,12 +7,8 @@ "CVE-2020-1443" ], "details": "A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc48-v74h-3jcf/GHSA-wc48-v74h-3jcf.json b/advisories/unreviewed/2022/05/GHSA-wc48-v74h-3jcf/GHSA-wc48-v74h-3jcf.json index 126ef79a25b..4c1ec64a204 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc48-v74h-3jcf/GHSA-wc48-v74h-3jcf.json +++ b/advisories/unreviewed/2022/05/GHSA-wc48-v74h-3jcf/GHSA-wc48-v74h-3jcf.json @@ -7,12 +7,8 @@ "CVE-2020-15009" ], "details": "AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wc7j-rv6h-gcx6/GHSA-wc7j-rv6h-gcx6.json b/advisories/unreviewed/2022/05/GHSA-wc7j-rv6h-gcx6/GHSA-wc7j-rv6h-gcx6.json index 92699c9ccae..e2bbc529a72 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc7j-rv6h-gcx6/GHSA-wc7j-rv6h-gcx6.json +++ b/advisories/unreviewed/2022/05/GHSA-wc7j-rv6h-gcx6/GHSA-wc7j-rv6h-gcx6.json @@ -7,12 +7,8 @@ "CVE-2020-15716" ], "details": "RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfm6-393x-c6r9/GHSA-wfm6-393x-c6r9.json b/advisories/unreviewed/2022/05/GHSA-wfm6-393x-c6r9/GHSA-wfm6-393x-c6r9.json index 22e9270ebb2..63a085546c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfm6-393x-c6r9/GHSA-wfm6-393x-c6r9.json +++ b/advisories/unreviewed/2022/05/GHSA-wfm6-393x-c6r9/GHSA-wfm6-393x-c6r9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wm5p-263x-pww3/GHSA-wm5p-263x-pww3.json b/advisories/unreviewed/2022/05/GHSA-wm5p-263x-pww3/GHSA-wm5p-263x-pww3.json index 8a7499a51a9..43e0c640ff7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm5p-263x-pww3/GHSA-wm5p-263x-pww3.json +++ b/advisories/unreviewed/2022/05/GHSA-wm5p-263x-pww3/GHSA-wm5p-263x-pww3.json @@ -7,12 +7,8 @@ "CVE-2020-1395" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Speech Brokered API handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1388, CVE-2020-1392, CVE-2020-1394.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wprw-q57v-22f2/GHSA-wprw-q57v-22f2.json b/advisories/unreviewed/2022/05/GHSA-wprw-q57v-22f2/GHSA-wprw-q57v-22f2.json index c6a4421cdea..d598bef3bc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wprw-q57v-22f2/GHSA-wprw-q57v-22f2.json +++ b/advisories/unreviewed/2022/05/GHSA-wprw-q57v-22f2/GHSA-wprw-q57v-22f2.json @@ -7,12 +7,8 @@ "CVE-2019-12784" ], "details": "An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to \"crowdsource\" bruteforce login attempts on the target site, allowing them to guess and potentially compromise valid credentials without ever sending any traffic from their own machine to the target site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqw3-26w4-7wmj/GHSA-wqw3-26w4-7wmj.json b/advisories/unreviewed/2022/05/GHSA-wqw3-26w4-7wmj/GHSA-wqw3-26w4-7wmj.json index a7d757f9e24..70839b6123b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqw3-26w4-7wmj/GHSA-wqw3-26w4-7wmj.json +++ b/advisories/unreviewed/2022/05/GHSA-wqw3-26w4-7wmj/GHSA-wqw3-26w4-7wmj.json @@ -7,12 +7,8 @@ "CVE-2020-15699" ], "details": "An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqwc-q68g-5fjg/GHSA-wqwc-q68g-5fjg.json b/advisories/unreviewed/2022/05/GHSA-wqwc-q68g-5fjg/GHSA-wqwc-q68g-5fjg.json index d03667b1115..7e5eb8edeb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqwc-q68g-5fjg/GHSA-wqwc-q68g-5fjg.json +++ b/advisories/unreviewed/2022/05/GHSA-wqwc-q68g-5fjg/GHSA-wqwc-q68g-5fjg.json @@ -7,12 +7,8 @@ "CVE-2020-15722" ], "details": "In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking could execute arbitrary code on the Local system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv3c-r29g-ph8x/GHSA-wv3c-r29g-ph8x.json b/advisories/unreviewed/2022/05/GHSA-wv3c-r29g-ph8x/GHSA-wv3c-r29g-ph8x.json index f0eea6ca4f9..9e80bfcff57 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv3c-r29g-ph8x/GHSA-wv3c-r29g-ph8x.json +++ b/advisories/unreviewed/2022/05/GHSA-wv3c-r29g-ph8x/GHSA-wv3c-r29g-ph8x.json @@ -7,12 +7,8 @@ "CVE-2020-3468" ], "details": "A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates values within SQL queries. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database or the operating system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvp2-97x3-gw55/GHSA-wvp2-97x3-gw55.json b/advisories/unreviewed/2022/05/GHSA-wvp2-97x3-gw55/GHSA-wvp2-97x3-gw55.json index 0adcad7220a..9d6481f9bfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvp2-97x3-gw55/GHSA-wvp2-97x3-gw55.json +++ b/advisories/unreviewed/2022/05/GHSA-wvp2-97x3-gw55/GHSA-wvp2-97x3-gw55.json @@ -7,12 +7,8 @@ "CVE-2020-1397" ], "details": "An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ww65-5fcm-v6g6/GHSA-ww65-5fcm-v6g6.json b/advisories/unreviewed/2022/05/GHSA-ww65-5fcm-v6g6/GHSA-ww65-5fcm-v6g6.json index 94b20815a81..188f911edd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww65-5fcm-v6g6/GHSA-ww65-5fcm-v6g6.json +++ b/advisories/unreviewed/2022/05/GHSA-ww65-5fcm-v6g6/GHSA-ww65-5fcm-v6g6.json @@ -7,12 +7,8 @@ "CVE-2020-12009" ], "details": "A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ww68-p9c4-2353/GHSA-ww68-p9c4-2353.json b/advisories/unreviewed/2022/05/GHSA-ww68-p9c4-2353/GHSA-ww68-p9c4-2353.json index eb856b874e5..864bce211cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww68-p9c4-2353/GHSA-ww68-p9c4-2353.json +++ b/advisories/unreviewed/2022/05/GHSA-ww68-p9c4-2353/GHSA-ww68-p9c4-2353.json @@ -7,12 +7,8 @@ "CVE-2020-14607" ], "details": "Vulnerability in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Tile Server). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Fusion Middleware MapViewer, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Fusion Middleware MapViewer accessible data as well as unauthorized read access to a subset of Oracle Fusion Middleware MapViewer accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwcj-f9h3-rh3w/GHSA-wwcj-f9h3-rh3w.json b/advisories/unreviewed/2022/05/GHSA-wwcj-f9h3-rh3w/GHSA-wwcj-f9h3-rh3w.json index 5eef984da0a..778cdfe98f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwcj-f9h3-rh3w/GHSA-wwcj-f9h3-rh3w.json +++ b/advisories/unreviewed/2022/05/GHSA-wwcj-f9h3-rh3w/GHSA-wwcj-f9h3-rh3w.json @@ -7,12 +7,8 @@ "CVE-2020-14613" ], "details": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced User Interface). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data as well as unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wwvm-hxm2-p9r6/GHSA-wwvm-hxm2-p9r6.json b/advisories/unreviewed/2022/05/GHSA-wwvm-hxm2-p9r6/GHSA-wwvm-hxm2-p9r6.json index bd8c6973c7d..1ea9d706f49 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwvm-hxm2-p9r6/GHSA-wwvm-hxm2-p9r6.json +++ b/advisories/unreviewed/2022/05/GHSA-wwvm-hxm2-p9r6/GHSA-wwvm-hxm2-p9r6.json @@ -7,12 +7,8 @@ "CVE-2020-14566" ], "details": "Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx5c-xgrp-9rgr/GHSA-wx5c-xgrp-9rgr.json b/advisories/unreviewed/2022/05/GHSA-wx5c-xgrp-9rgr/GHSA-wx5c-xgrp-9rgr.json index 1c0a87853b5..cd1d165e683 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx5c-xgrp-9rgr/GHSA-wx5c-xgrp-9rgr.json +++ b/advisories/unreviewed/2022/05/GHSA-wx5c-xgrp-9rgr/GHSA-wx5c-xgrp-9rgr.json @@ -7,12 +7,8 @@ "CVE-2020-12025" ], "details": "Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxcg-g67v-xrp9/GHSA-wxcg-g67v-xrp9.json b/advisories/unreviewed/2022/05/GHSA-wxcg-g67v-xrp9/GHSA-wxcg-g67v-xrp9.json index 6936d30ef65..8a560edc5df 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxcg-g67v-xrp9/GHSA-wxcg-g67v-xrp9.json +++ b/advisories/unreviewed/2022/05/GHSA-wxcg-g67v-xrp9/GHSA-wxcg-g67v-xrp9.json @@ -7,12 +7,8 @@ "CVE-2020-7206" ], "details": "HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxf8-vxfr-r99r/GHSA-wxf8-vxfr-r99r.json b/advisories/unreviewed/2022/05/GHSA-wxf8-vxfr-r99r/GHSA-wxf8-vxfr-r99r.json index 6ae49ad5589..9407e769f43 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxf8-vxfr-r99r/GHSA-wxf8-vxfr-r99r.json +++ b/advisories/unreviewed/2022/05/GHSA-wxf8-vxfr-r99r/GHSA-wxf8-vxfr-r99r.json @@ -7,12 +7,8 @@ "CVE-2020-1391" ], "details": "An information disclosure vulnerability exists when the Windows Agent Activation Runtime (AarSvc) fails to properly handle objects in memory, aka 'Windows Agent Activation Runtime Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxpv-w4p2-2m5c/GHSA-wxpv-w4p2-2m5c.json b/advisories/unreviewed/2022/05/GHSA-wxpv-w4p2-2m5c/GHSA-wxpv-w4p2-2m5c.json index e8ec26a4c84..f1fcb05b797 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxpv-w4p2-2m5c/GHSA-wxpv-w4p2-2m5c.json +++ b/advisories/unreviewed/2022/05/GHSA-wxpv-w4p2-2m5c/GHSA-wxpv-w4p2-2m5c.json @@ -7,12 +7,8 @@ "CVE-2020-14580" ], "details": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications Applications (component: System Admin). Supported versions that are affected are 8.1.0, 8.2.0 and 8.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Communications Session Border Controller. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Session Border Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Session Border Controller accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Session Border Controller accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wxvf-3cjv-fx8w/GHSA-wxvf-3cjv-fx8w.json b/advisories/unreviewed/2022/05/GHSA-wxvf-3cjv-fx8w/GHSA-wxvf-3cjv-fx8w.json index b42a28a502a..5f895af2096 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxvf-3cjv-fx8w/GHSA-wxvf-3cjv-fx8w.json +++ b/advisories/unreviewed/2022/05/GHSA-wxvf-3cjv-fx8w/GHSA-wxvf-3cjv-fx8w.json @@ -7,12 +7,8 @@ "CVE-2020-14536" ], "details": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Workbench). Supported versions that are affected are 11.0, 11.1, 11.2 and prior to 11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x26m-wcf2-85xw/GHSA-x26m-wcf2-85xw.json b/advisories/unreviewed/2022/05/GHSA-x26m-wcf2-85xw/GHSA-x26m-wcf2-85xw.json index 14324970201..c378d294567 100644 --- a/advisories/unreviewed/2022/05/GHSA-x26m-wcf2-85xw/GHSA-x26m-wcf2-85xw.json +++ b/advisories/unreviewed/2022/05/GHSA-x26m-wcf2-85xw/GHSA-x26m-wcf2-85xw.json @@ -7,12 +7,8 @@ "CVE-2020-7593" ], "details": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.01), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.02). A buffer overflow vulnerability exists in the Web Server functionality of the device. A remote unauthenticated attacker could send a specially crafted HTTP request to cause a memory corruption, potentially resulting in remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2jg-9c23-q285/GHSA-x2jg-9c23-q285.json b/advisories/unreviewed/2022/05/GHSA-x2jg-9c23-q285/GHSA-x2jg-9c23-q285.json index 8fb19a84bac..eac78855437 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2jg-9c23-q285/GHSA-x2jg-9c23-q285.json +++ b/advisories/unreviewed/2022/05/GHSA-x2jg-9c23-q285/GHSA-x2jg-9c23-q285.json @@ -7,12 +7,8 @@ "CVE-2020-14608" ], "details": "Vulnerability in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Tile Server). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Fusion Middleware MapViewer accessible data as well as unauthorized read access to a subset of Oracle Fusion Middleware MapViewer accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3rm-hggx-j4q8/GHSA-x3rm-hggx-j4q8.json b/advisories/unreviewed/2022/05/GHSA-x3rm-hggx-j4q8/GHSA-x3rm-hggx-j4q8.json index b25ddc37072..a899a8ffe6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3rm-hggx-j4q8/GHSA-x3rm-hggx-j4q8.json +++ b/advisories/unreviewed/2022/05/GHSA-x3rm-hggx-j4q8/GHSA-x3rm-hggx-j4q8.json @@ -7,12 +7,8 @@ "CVE-2020-4512" ], "details": "IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4w6-j83j-vvp2/GHSA-x4w6-j83j-vvp2.json b/advisories/unreviewed/2022/05/GHSA-x4w6-j83j-vvp2/GHSA-x4w6-j83j-vvp2.json index 03f35f98e80..bc92bdc95c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4w6-j83j-vvp2/GHSA-x4w6-j83j-vvp2.json +++ b/advisories/unreviewed/2022/05/GHSA-x4w6-j83j-vvp2/GHSA-x4w6-j83j-vvp2.json @@ -7,12 +7,8 @@ "CVE-2020-14560" ], "details": "Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion BI+ accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5v3-cvv7-9qg6/GHSA-x5v3-cvv7-9qg6.json b/advisories/unreviewed/2022/05/GHSA-x5v3-cvv7-9qg6/GHSA-x5v3-cvv7-9qg6.json index fe3fde56ae7..9590700c53f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5v3-cvv7-9qg6/GHSA-x5v3-cvv7-9qg6.json +++ b/advisories/unreviewed/2022/05/GHSA-x5v3-cvv7-9qg6/GHSA-x5v3-cvv7-9qg6.json @@ -7,12 +7,8 @@ "CVE-2020-1382" ], "details": "An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1381.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x625-w2w3-862f/GHSA-x625-w2w3-862f.json b/advisories/unreviewed/2022/05/GHSA-x625-w2w3-862f/GHSA-x625-w2w3-862f.json index 44fcabf6ecd..7e813770d77 100644 --- a/advisories/unreviewed/2022/05/GHSA-x625-w2w3-862f/GHSA-x625-w2w3-862f.json +++ b/advisories/unreviewed/2022/05/GHSA-x625-w2w3-862f/GHSA-x625-w2w3-862f.json @@ -7,12 +7,8 @@ "CVE-2020-1422" ], "details": "An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6vc-43v3-pjqr/GHSA-x6vc-43v3-pjqr.json b/advisories/unreviewed/2022/05/GHSA-x6vc-43v3-pjqr/GHSA-x6vc-43v3-pjqr.json index 722e05e2a4f..a44f8df37e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6vc-43v3-pjqr/GHSA-x6vc-43v3-pjqr.json +++ b/advisories/unreviewed/2022/05/GHSA-x6vc-43v3-pjqr/GHSA-x6vc-43v3-pjqr.json @@ -7,12 +7,8 @@ "CVE-2020-14585" ], "details": "Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x754-7v35-2h8f/GHSA-x754-7v35-2h8f.json b/advisories/unreviewed/2022/05/GHSA-x754-7v35-2h8f/GHSA-x754-7v35-2h8f.json index a0dc09ebbc1..abc3349e351 100644 --- a/advisories/unreviewed/2022/05/GHSA-x754-7v35-2h8f/GHSA-x754-7v35-2h8f.json +++ b/advisories/unreviewed/2022/05/GHSA-x754-7v35-2h8f/GHSA-x754-7v35-2h8f.json @@ -7,12 +7,8 @@ "CVE-2020-1368" ], "details": "An elevation of privilege vulnerability exists in the way that the Credential Enrollment Manager service handles objects in memory, aka 'Windows Credential Enrollment Manager Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7q7-3cr3-m2q3/GHSA-x7q7-3cr3-m2q3.json b/advisories/unreviewed/2022/05/GHSA-x7q7-3cr3-m2q3/GHSA-x7q7-3cr3-m2q3.json index f23cd7fb297..b70025954f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7q7-3cr3-m2q3/GHSA-x7q7-3cr3-m2q3.json +++ b/advisories/unreviewed/2022/05/GHSA-x7q7-3cr3-m2q3/GHSA-x7q7-3cr3-m2q3.json @@ -7,12 +7,8 @@ "CVE-2020-1651" ], "details": "On Juniper Networks MX series, receipt of a stream of specific Layer 2 frames may cause a memory leak resulting in the packet forwarding engine (PFE) on the line card to crash and restart, causing traffic interruption. By continuously sending this stream of specific layer 2 frame, an attacker connected to the same broadcast domain can repeatedly crash the PFE, causing a prolonged Denial of Service (DoS). This issue affects Juniper Networks Junos OS on MX Series: 17.2 versions prior to 17.2R3-S4; 17.2X75 versions prior to 17.2X75-D105.19; 17.3 versions prior to 17.3R3-S7; 17.4 versions prior to 17.4R1-S3, 17.4R2; 18.1 versions prior to 18.1R2. This issue does not affect Juniper Networks Junos OS releases prior to 17.2R1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7v4-2v57-r86h/GHSA-x7v4-2v57-r86h.json b/advisories/unreviewed/2022/05/GHSA-x7v4-2v57-r86h/GHSA-x7v4-2v57-r86h.json index 26ed92097e0..05cc670d6b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7v4-2v57-r86h/GHSA-x7v4-2v57-r86h.json +++ b/advisories/unreviewed/2022/05/GHSA-x7v4-2v57-r86h/GHSA-x7v4-2v57-r86h.json @@ -7,12 +7,8 @@ "CVE-2020-3357" ], "details": "A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause the device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because HTTP requests are not properly validated. An attacker could exploit this vulnerability by sending a crafted HTTP request over an SSL connection to an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device or cause the device to reload, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x83r-934g-7qwg/GHSA-x83r-934g-7qwg.json b/advisories/unreviewed/2022/05/GHSA-x83r-934g-7qwg/GHSA-x83r-934g-7qwg.json index 966357dbed5..c2a3e425ff4 100644 --- a/advisories/unreviewed/2022/05/GHSA-x83r-934g-7qwg/GHSA-x83r-934g-7qwg.json +++ b/advisories/unreviewed/2022/05/GHSA-x83r-934g-7qwg/GHSA-x83r-934g-7qwg.json @@ -7,12 +7,8 @@ "CVE-2020-14485" ], "details": "OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality, which may allow execution of admin functions such as SQL queries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x97m-9ccg-7rgv/GHSA-x97m-9ccg-7rgv.json b/advisories/unreviewed/2022/05/GHSA-x97m-9ccg-7rgv/GHSA-x97m-9ccg-7rgv.json index 96048b6d5ef..1c58ff75de8 100644 --- a/advisories/unreviewed/2022/05/GHSA-x97m-9ccg-7rgv/GHSA-x97m-9ccg-7rgv.json +++ b/advisories/unreviewed/2022/05/GHSA-x97m-9ccg-7rgv/GHSA-x97m-9ccg-7rgv.json @@ -7,12 +7,8 @@ "CVE-2020-14650" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf3x-83h2-c6pg/GHSA-xf3x-83h2-c6pg.json b/advisories/unreviewed/2022/05/GHSA-xf3x-83h2-c6pg/GHSA-xf3x-83h2-c6pg.json index 11104aa530b..01176f473aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf3x-83h2-c6pg/GHSA-xf3x-83h2-c6pg.json +++ b/advisories/unreviewed/2022/05/GHSA-xf3x-83h2-c6pg/GHSA-xf3x-83h2-c6pg.json @@ -7,12 +7,8 @@ "CVE-2020-1429" ], "details": "An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf43-jf45-47p8/GHSA-xf43-jf45-47p8.json b/advisories/unreviewed/2022/05/GHSA-xf43-jf45-47p8/GHSA-xf43-jf45-47p8.json index 39e2ffd5d08..e556a69b2fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf43-jf45-47p8/GHSA-xf43-jf45-47p8.json +++ b/advisories/unreviewed/2022/05/GHSA-xf43-jf45-47p8/GHSA-xf43-jf45-47p8.json @@ -7,12 +7,8 @@ "CVE-2020-14629" ], "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf93-r8jp-jh8m/GHSA-xf93-r8jp-jh8m.json b/advisories/unreviewed/2022/05/GHSA-xf93-r8jp-jh8m/GHSA-xf93-r8jp-jh8m.json index fb06f433771..c540fb947b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf93-r8jp-jh8m/GHSA-xf93-r8jp-jh8m.json +++ b/advisories/unreviewed/2022/05/GHSA-xf93-r8jp-jh8m/GHSA-xf93-r8jp-jh8m.json @@ -7,12 +7,8 @@ "CVE-2020-14532" ], "details": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.1, 11.2 and prior to 11.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xfpp-fwv2-hrqc/GHSA-xfpp-fwv2-hrqc.json b/advisories/unreviewed/2022/05/GHSA-xfpp-fwv2-hrqc/GHSA-xfpp-fwv2-hrqc.json index cb3f5a35d22..072246327c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfpp-fwv2-hrqc/GHSA-xfpp-fwv2-hrqc.json +++ b/advisories/unreviewed/2022/05/GHSA-xfpp-fwv2-hrqc/GHSA-xfpp-fwv2-hrqc.json @@ -7,12 +7,8 @@ "CVE-2020-1420" ], "details": "An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgpv-wxj8-c795/GHSA-xgpv-wxj8-c795.json b/advisories/unreviewed/2022/05/GHSA-xgpv-wxj8-c795/GHSA-xgpv-wxj8-c795.json index 759b6011846..71edd022dad 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgpv-wxj8-c795/GHSA-xgpv-wxj8-c795.json +++ b/advisories/unreviewed/2022/05/GHSA-xgpv-wxj8-c795/GHSA-xgpv-wxj8-c795.json @@ -7,12 +7,8 @@ "CVE-2020-10041" ], "details": "A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). A stored Cross-Site-Scripting (XSS) vulnerability is present in different locations of the web application. An attacker might be able to take over a session of a legitimate user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xh8j-8x8h-3f2m/GHSA-xh8j-8x8h-3f2m.json b/advisories/unreviewed/2022/05/GHSA-xh8j-8x8h-3f2m/GHSA-xh8j-8x8h-3f2m.json index da50ebb0529..ae3553c0791 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh8j-8x8h-3f2m/GHSA-xh8j-8x8h-3f2m.json +++ b/advisories/unreviewed/2022/05/GHSA-xh8j-8x8h-3f2m/GHSA-xh8j-8x8h-3f2m.json @@ -7,12 +7,8 @@ "CVE-2020-14494" ], "details": "OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjpq-582q-q6mh/GHSA-xjpq-582q-q6mh.json b/advisories/unreviewed/2022/05/GHSA-xjpq-582q-q6mh/GHSA-xjpq-582q-q6mh.json index c6304490da4..a9315b4f770 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjpq-582q-q6mh/GHSA-xjpq-582q-q6mh.json +++ b/advisories/unreviewed/2022/05/GHSA-xjpq-582q-q6mh/GHSA-xjpq-582q-q6mh.json @@ -7,12 +7,8 @@ "CVE-2020-1401" ], "details": "A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1407.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm74-phc9-jvhx/GHSA-xm74-phc9-jvhx.json b/advisories/unreviewed/2022/05/GHSA-xm74-phc9-jvhx/GHSA-xm74-phc9-jvhx.json index 64e9910adf7..ae359a1a7f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm74-phc9-jvhx/GHSA-xm74-phc9-jvhx.json +++ b/advisories/unreviewed/2022/05/GHSA-xm74-phc9-jvhx/GHSA-xm74-phc9-jvhx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp68-m4r3-hpqf/GHSA-xp68-m4r3-hpqf.json b/advisories/unreviewed/2022/05/GHSA-xp68-m4r3-hpqf/GHSA-xp68-m4r3-hpqf.json index f73b523f328..02fcf04c5c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp68-m4r3-hpqf/GHSA-xp68-m4r3-hpqf.json +++ b/advisories/unreviewed/2022/05/GHSA-xp68-m4r3-hpqf/GHSA-xp68-m4r3-hpqf.json @@ -7,12 +7,8 @@ "CVE-2020-6286" ], "details": "The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xphj-x7cg-4hjw/GHSA-xphj-x7cg-4hjw.json b/advisories/unreviewed/2022/05/GHSA-xphj-x7cg-4hjw/GHSA-xphj-x7cg-4hjw.json index 95b2b4bc155..40b11a909ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-xphj-x7cg-4hjw/GHSA-xphj-x7cg-4hjw.json +++ b/advisories/unreviewed/2022/05/GHSA-xphj-x7cg-4hjw/GHSA-xphj-x7cg-4hjw.json @@ -7,12 +7,8 @@ "CVE-2020-14638" ], "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xvmg-x4v3-5v98/GHSA-xvmg-x4v3-5v98.json b/advisories/unreviewed/2022/05/GHSA-xvmg-x4v3-5v98/GHSA-xvmg-x4v3-5v98.json index 5063fa2d471..4e2797b06df 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvmg-x4v3-5v98/GHSA-xvmg-x4v3-5v98.json +++ b/advisories/unreviewed/2022/05/GHSA-xvmg-x4v3-5v98/GHSA-xvmg-x4v3-5v98.json @@ -7,12 +7,8 @@ "CVE-2020-14594" ], "details": "Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Inventory Integration). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xvxj-48v4-h2xv/GHSA-xvxj-48v4-h2xv.json b/advisories/unreviewed/2022/05/GHSA-xvxj-48v4-h2xv/GHSA-xvxj-48v4-h2xv.json index 562521093c6..294213b1eee 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvxj-48v4-h2xv/GHSA-xvxj-48v4-h2xv.json +++ b/advisories/unreviewed/2022/05/GHSA-xvxj-48v4-h2xv/GHSA-xvxj-48v4-h2xv.json @@ -7,12 +7,8 @@ "CVE-2019-20909" ], "details": "An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw2w-mmgv-hf8h/GHSA-xw2w-mmgv-hf8h.json b/advisories/unreviewed/2022/05/GHSA-xw2w-mmgv-hf8h/GHSA-xw2w-mmgv-hf8h.json index f27dc4a5f9c..118b613b151 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw2w-mmgv-hf8h/GHSA-xw2w-mmgv-hf8h.json +++ b/advisories/unreviewed/2022/05/GHSA-xw2w-mmgv-hf8h/GHSA-xw2w-mmgv-hf8h.json @@ -7,12 +7,8 @@ "CVE-2020-1447" ], "details": "A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-28c6-247x-r9mw/GHSA-28c6-247x-r9mw.json b/advisories/unreviewed/2022/06/GHSA-28c6-247x-r9mw/GHSA-28c6-247x-r9mw.json index eace15d714d..88e63ed6aef 100644 --- a/advisories/unreviewed/2022/06/GHSA-28c6-247x-r9mw/GHSA-28c6-247x-r9mw.json +++ b/advisories/unreviewed/2022/06/GHSA-28c6-247x-r9mw/GHSA-28c6-247x-r9mw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-575v-67px-9r7c/GHSA-575v-67px-9r7c.json b/advisories/unreviewed/2022/06/GHSA-575v-67px-9r7c/GHSA-575v-67px-9r7c.json index ea04d8a3321..5a899b5fe7a 100644 --- a/advisories/unreviewed/2022/06/GHSA-575v-67px-9r7c/GHSA-575v-67px-9r7c.json +++ b/advisories/unreviewed/2022/06/GHSA-575v-67px-9r7c/GHSA-575v-67px-9r7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-734g-rvc3-rx28/GHSA-734g-rvc3-rx28.json b/advisories/unreviewed/2022/06/GHSA-734g-rvc3-rx28/GHSA-734g-rvc3-rx28.json index da19749c932..2c3e5a67731 100644 --- a/advisories/unreviewed/2022/06/GHSA-734g-rvc3-rx28/GHSA-734g-rvc3-rx28.json +++ b/advisories/unreviewed/2022/06/GHSA-734g-rvc3-rx28/GHSA-734g-rvc3-rx28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-87mg-gx7c-q5gr/GHSA-87mg-gx7c-q5gr.json b/advisories/unreviewed/2022/06/GHSA-87mg-gx7c-q5gr/GHSA-87mg-gx7c-q5gr.json index 9567f08681b..947ecf95fc7 100644 --- a/advisories/unreviewed/2022/06/GHSA-87mg-gx7c-q5gr/GHSA-87mg-gx7c-q5gr.json +++ b/advisories/unreviewed/2022/06/GHSA-87mg-gx7c-q5gr/GHSA-87mg-gx7c-q5gr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-88gw-64r5-49m9/GHSA-88gw-64r5-49m9.json b/advisories/unreviewed/2022/06/GHSA-88gw-64r5-49m9/GHSA-88gw-64r5-49m9.json index c1d50283a58..12951ed4ffc 100644 --- a/advisories/unreviewed/2022/06/GHSA-88gw-64r5-49m9/GHSA-88gw-64r5-49m9.json +++ b/advisories/unreviewed/2022/06/GHSA-88gw-64r5-49m9/GHSA-88gw-64r5-49m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-j6mf-6qf9-6f8r/GHSA-j6mf-6qf9-6f8r.json b/advisories/unreviewed/2022/06/GHSA-j6mf-6qf9-6f8r/GHSA-j6mf-6qf9-6f8r.json index 8230ee4d2dd..c15f83d549f 100644 --- a/advisories/unreviewed/2022/06/GHSA-j6mf-6qf9-6f8r/GHSA-j6mf-6qf9-6f8r.json +++ b/advisories/unreviewed/2022/06/GHSA-j6mf-6qf9-6f8r/GHSA-j6mf-6qf9-6f8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-jc44-gwj5-3hqm/GHSA-jc44-gwj5-3hqm.json b/advisories/unreviewed/2022/06/GHSA-jc44-gwj5-3hqm/GHSA-jc44-gwj5-3hqm.json index b9fab2fccab..8743e3831e7 100644 --- a/advisories/unreviewed/2022/06/GHSA-jc44-gwj5-3hqm/GHSA-jc44-gwj5-3hqm.json +++ b/advisories/unreviewed/2022/06/GHSA-jc44-gwj5-3hqm/GHSA-jc44-gwj5-3hqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-q8jm-f67m-5xxq/GHSA-q8jm-f67m-5xxq.json b/advisories/unreviewed/2022/06/GHSA-q8jm-f67m-5xxq/GHSA-q8jm-f67m-5xxq.json index 591e2effeac..364ecb03e28 100644 --- a/advisories/unreviewed/2022/06/GHSA-q8jm-f67m-5xxq/GHSA-q8jm-f67m-5xxq.json +++ b/advisories/unreviewed/2022/06/GHSA-q8jm-f67m-5xxq/GHSA-q8jm-f67m-5xxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-4rg9-gh8p-52q4/GHSA-4rg9-gh8p-52q4.json b/advisories/unreviewed/2022/07/GHSA-4rg9-gh8p-52q4/GHSA-4rg9-gh8p-52q4.json index 8e622586614..169c8f21696 100644 --- a/advisories/unreviewed/2022/07/GHSA-4rg9-gh8p-52q4/GHSA-4rg9-gh8p-52q4.json +++ b/advisories/unreviewed/2022/07/GHSA-4rg9-gh8p-52q4/GHSA-4rg9-gh8p-52q4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-9533-x7q2-r9j9/GHSA-9533-x7q2-r9j9.json b/advisories/unreviewed/2022/07/GHSA-9533-x7q2-r9j9/GHSA-9533-x7q2-r9j9.json index 2c518856d73..c6be556030f 100644 --- a/advisories/unreviewed/2022/07/GHSA-9533-x7q2-r9j9/GHSA-9533-x7q2-r9j9.json +++ b/advisories/unreviewed/2022/07/GHSA-9533-x7q2-r9j9/GHSA-9533-x7q2-r9j9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-gxw5-2w8j-82xf/GHSA-gxw5-2w8j-82xf.json b/advisories/unreviewed/2022/07/GHSA-gxw5-2w8j-82xf/GHSA-gxw5-2w8j-82xf.json index 968810591c0..dd491845fe0 100644 --- a/advisories/unreviewed/2022/07/GHSA-gxw5-2w8j-82xf/GHSA-gxw5-2w8j-82xf.json +++ b/advisories/unreviewed/2022/07/GHSA-gxw5-2w8j-82xf/GHSA-gxw5-2w8j-82xf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-w2rh-hf85-pfh4/GHSA-w2rh-hf85-pfh4.json b/advisories/unreviewed/2022/07/GHSA-w2rh-hf85-pfh4/GHSA-w2rh-hf85-pfh4.json index 2d9f406605e..3cc1b02cc23 100644 --- a/advisories/unreviewed/2022/07/GHSA-w2rh-hf85-pfh4/GHSA-w2rh-hf85-pfh4.json +++ b/advisories/unreviewed/2022/07/GHSA-w2rh-hf85-pfh4/GHSA-w2rh-hf85-pfh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-3gv2-2xxr-9jgq/GHSA-3gv2-2xxr-9jgq.json b/advisories/unreviewed/2022/08/GHSA-3gv2-2xxr-9jgq/GHSA-3gv2-2xxr-9jgq.json index 650c9093c23..d7fc13f78b5 100644 --- a/advisories/unreviewed/2022/08/GHSA-3gv2-2xxr-9jgq/GHSA-3gv2-2xxr-9jgq.json +++ b/advisories/unreviewed/2022/08/GHSA-3gv2-2xxr-9jgq/GHSA-3gv2-2xxr-9jgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-9c2p-jfmw-fgw7/GHSA-9c2p-jfmw-fgw7.json b/advisories/unreviewed/2022/08/GHSA-9c2p-jfmw-fgw7/GHSA-9c2p-jfmw-fgw7.json index 24fa25b44cf..5db0b0d62e1 100644 --- a/advisories/unreviewed/2022/08/GHSA-9c2p-jfmw-fgw7/GHSA-9c2p-jfmw-fgw7.json +++ b/advisories/unreviewed/2022/08/GHSA-9c2p-jfmw-fgw7/GHSA-9c2p-jfmw-fgw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-9r25-j996-8h38/GHSA-9r25-j996-8h38.json b/advisories/unreviewed/2022/08/GHSA-9r25-j996-8h38/GHSA-9r25-j996-8h38.json index f36f18b8c34..a9d9533476d 100644 --- a/advisories/unreviewed/2022/08/GHSA-9r25-j996-8h38/GHSA-9r25-j996-8h38.json +++ b/advisories/unreviewed/2022/08/GHSA-9r25-j996-8h38/GHSA-9r25-j996-8h38.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-h7f6-hc46-frrv/GHSA-h7f6-hc46-frrv.json b/advisories/unreviewed/2022/08/GHSA-h7f6-hc46-frrv/GHSA-h7f6-hc46-frrv.json index 3b5c353890c..42324ef78e3 100644 --- a/advisories/unreviewed/2022/08/GHSA-h7f6-hc46-frrv/GHSA-h7f6-hc46-frrv.json +++ b/advisories/unreviewed/2022/08/GHSA-h7f6-hc46-frrv/GHSA-h7f6-hc46-frrv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-qj75-j4wq-j748/GHSA-qj75-j4wq-j748.json b/advisories/unreviewed/2022/08/GHSA-qj75-j4wq-j748/GHSA-qj75-j4wq-j748.json index 96c4e27c9c1..d4306a49311 100644 --- a/advisories/unreviewed/2022/08/GHSA-qj75-j4wq-j748/GHSA-qj75-j4wq-j748.json +++ b/advisories/unreviewed/2022/08/GHSA-qj75-j4wq-j748/GHSA-qj75-j4wq-j748.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-r8mv-jqpq-mx92/GHSA-r8mv-jqpq-mx92.json b/advisories/unreviewed/2022/08/GHSA-r8mv-jqpq-mx92/GHSA-r8mv-jqpq-mx92.json index 650d00bff6c..e078509124a 100644 --- a/advisories/unreviewed/2022/08/GHSA-r8mv-jqpq-mx92/GHSA-r8mv-jqpq-mx92.json +++ b/advisories/unreviewed/2022/08/GHSA-r8mv-jqpq-mx92/GHSA-r8mv-jqpq-mx92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-74rw-pw87-v75g/GHSA-74rw-pw87-v75g.json b/advisories/unreviewed/2022/09/GHSA-74rw-pw87-v75g/GHSA-74rw-pw87-v75g.json index 482ded9b5c9..f1389510739 100644 --- a/advisories/unreviewed/2022/09/GHSA-74rw-pw87-v75g/GHSA-74rw-pw87-v75g.json +++ b/advisories/unreviewed/2022/09/GHSA-74rw-pw87-v75g/GHSA-74rw-pw87-v75g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-8cq9-p78m-67v8/GHSA-8cq9-p78m-67v8.json b/advisories/unreviewed/2022/09/GHSA-8cq9-p78m-67v8/GHSA-8cq9-p78m-67v8.json index dfe1ca4ee3d..87dadb0eca3 100644 --- a/advisories/unreviewed/2022/09/GHSA-8cq9-p78m-67v8/GHSA-8cq9-p78m-67v8.json +++ b/advisories/unreviewed/2022/09/GHSA-8cq9-p78m-67v8/GHSA-8cq9-p78m-67v8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-cvjg-9hcx-pvx4/GHSA-cvjg-9hcx-pvx4.json b/advisories/unreviewed/2022/09/GHSA-cvjg-9hcx-pvx4/GHSA-cvjg-9hcx-pvx4.json index 766d37b5268..58d53f373fd 100644 --- a/advisories/unreviewed/2022/09/GHSA-cvjg-9hcx-pvx4/GHSA-cvjg-9hcx-pvx4.json +++ b/advisories/unreviewed/2022/09/GHSA-cvjg-9hcx-pvx4/GHSA-cvjg-9hcx-pvx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-gv26-x27m-rfg3/GHSA-gv26-x27m-rfg3.json b/advisories/unreviewed/2022/09/GHSA-gv26-x27m-rfg3/GHSA-gv26-x27m-rfg3.json index 8a47d1d62e8..0656ad47cbf 100644 --- a/advisories/unreviewed/2022/09/GHSA-gv26-x27m-rfg3/GHSA-gv26-x27m-rfg3.json +++ b/advisories/unreviewed/2022/09/GHSA-gv26-x27m-rfg3/GHSA-gv26-x27m-rfg3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-hpgr-7w89-8xm5/GHSA-hpgr-7w89-8xm5.json b/advisories/unreviewed/2022/09/GHSA-hpgr-7w89-8xm5/GHSA-hpgr-7w89-8xm5.json index 82eade636a7..412ab6c5690 100644 --- a/advisories/unreviewed/2022/09/GHSA-hpgr-7w89-8xm5/GHSA-hpgr-7w89-8xm5.json +++ b/advisories/unreviewed/2022/09/GHSA-hpgr-7w89-8xm5/GHSA-hpgr-7w89-8xm5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json b/advisories/unreviewed/2022/09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json index 68abd2cf23c..015edfde752 100644 --- a/advisories/unreviewed/2022/09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json +++ b/advisories/unreviewed/2022/09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-qjwx-hqg3-vv75/GHSA-qjwx-hqg3-vv75.json b/advisories/unreviewed/2022/09/GHSA-qjwx-hqg3-vv75/GHSA-qjwx-hqg3-vv75.json index edf3f1fc8d1..76b6349d829 100644 --- a/advisories/unreviewed/2022/09/GHSA-qjwx-hqg3-vv75/GHSA-qjwx-hqg3-vv75.json +++ b/advisories/unreviewed/2022/09/GHSA-qjwx-hqg3-vv75/GHSA-qjwx-hqg3-vv75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-qpvc-9998-hvx9/GHSA-qpvc-9998-hvx9.json b/advisories/unreviewed/2022/09/GHSA-qpvc-9998-hvx9/GHSA-qpvc-9998-hvx9.json index a36ab4be5b7..96aac8b2168 100644 --- a/advisories/unreviewed/2022/09/GHSA-qpvc-9998-hvx9/GHSA-qpvc-9998-hvx9.json +++ b/advisories/unreviewed/2022/09/GHSA-qpvc-9998-hvx9/GHSA-qpvc-9998-hvx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-494r-cmj8-94j9/GHSA-494r-cmj8-94j9.json b/advisories/unreviewed/2022/11/GHSA-494r-cmj8-94j9/GHSA-494r-cmj8-94j9.json index 5bdf9164a46..aec7b8993cc 100644 --- a/advisories/unreviewed/2022/11/GHSA-494r-cmj8-94j9/GHSA-494r-cmj8-94j9.json +++ b/advisories/unreviewed/2022/11/GHSA-494r-cmj8-94j9/GHSA-494r-cmj8-94j9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-4cwx-87j2-xc8v/GHSA-4cwx-87j2-xc8v.json b/advisories/unreviewed/2022/11/GHSA-4cwx-87j2-xc8v/GHSA-4cwx-87j2-xc8v.json index edf482a29e5..01be96875e3 100644 --- a/advisories/unreviewed/2022/11/GHSA-4cwx-87j2-xc8v/GHSA-4cwx-87j2-xc8v.json +++ b/advisories/unreviewed/2022/11/GHSA-4cwx-87j2-xc8v/GHSA-4cwx-87j2-xc8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-5x3r-56hw-m9mp/GHSA-5x3r-56hw-m9mp.json b/advisories/unreviewed/2022/11/GHSA-5x3r-56hw-m9mp/GHSA-5x3r-56hw-m9mp.json index d30983c23b6..641326ae30c 100644 --- a/advisories/unreviewed/2022/11/GHSA-5x3r-56hw-m9mp/GHSA-5x3r-56hw-m9mp.json +++ b/advisories/unreviewed/2022/11/GHSA-5x3r-56hw-m9mp/GHSA-5x3r-56hw-m9mp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-7crr-gq7j-5wcr/GHSA-7crr-gq7j-5wcr.json b/advisories/unreviewed/2022/11/GHSA-7crr-gq7j-5wcr/GHSA-7crr-gq7j-5wcr.json index da22fe66acd..fb34121b86d 100644 --- a/advisories/unreviewed/2022/11/GHSA-7crr-gq7j-5wcr/GHSA-7crr-gq7j-5wcr.json +++ b/advisories/unreviewed/2022/11/GHSA-7crr-gq7j-5wcr/GHSA-7crr-gq7j-5wcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-j7rp-w7cg-34p9/GHSA-j7rp-w7cg-34p9.json b/advisories/unreviewed/2022/11/GHSA-j7rp-w7cg-34p9/GHSA-j7rp-w7cg-34p9.json index 860a3dfc1a0..f8c258f4f8f 100644 --- a/advisories/unreviewed/2022/11/GHSA-j7rp-w7cg-34p9/GHSA-j7rp-w7cg-34p9.json +++ b/advisories/unreviewed/2022/11/GHSA-j7rp-w7cg-34p9/GHSA-j7rp-w7cg-34p9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-p326-98p9-wprv/GHSA-p326-98p9-wprv.json b/advisories/unreviewed/2022/11/GHSA-p326-98p9-wprv/GHSA-p326-98p9-wprv.json index 0095c58a8de..c75a0bff80c 100644 --- a/advisories/unreviewed/2022/11/GHSA-p326-98p9-wprv/GHSA-p326-98p9-wprv.json +++ b/advisories/unreviewed/2022/11/GHSA-p326-98p9-wprv/GHSA-p326-98p9-wprv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-36qx-76wj-5vqw/GHSA-36qx-76wj-5vqw.json b/advisories/unreviewed/2022/12/GHSA-36qx-76wj-5vqw/GHSA-36qx-76wj-5vqw.json index b30f1907ae3..4b39e803753 100644 --- a/advisories/unreviewed/2022/12/GHSA-36qx-76wj-5vqw/GHSA-36qx-76wj-5vqw.json +++ b/advisories/unreviewed/2022/12/GHSA-36qx-76wj-5vqw/GHSA-36qx-76wj-5vqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-55pf-9mrw-9459/GHSA-55pf-9mrw-9459.json b/advisories/unreviewed/2022/12/GHSA-55pf-9mrw-9459/GHSA-55pf-9mrw-9459.json index 18cb2d022b5..84eac4e4b1b 100644 --- a/advisories/unreviewed/2022/12/GHSA-55pf-9mrw-9459/GHSA-55pf-9mrw-9459.json +++ b/advisories/unreviewed/2022/12/GHSA-55pf-9mrw-9459/GHSA-55pf-9mrw-9459.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-82mr-xx64-4rjv/GHSA-82mr-xx64-4rjv.json b/advisories/unreviewed/2022/12/GHSA-82mr-xx64-4rjv/GHSA-82mr-xx64-4rjv.json index 4f3829b7e9a..fe7600a6043 100644 --- a/advisories/unreviewed/2022/12/GHSA-82mr-xx64-4rjv/GHSA-82mr-xx64-4rjv.json +++ b/advisories/unreviewed/2022/12/GHSA-82mr-xx64-4rjv/GHSA-82mr-xx64-4rjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-86q3-6wjf-3984/GHSA-86q3-6wjf-3984.json b/advisories/unreviewed/2022/12/GHSA-86q3-6wjf-3984/GHSA-86q3-6wjf-3984.json index 199a906813a..237256814a1 100644 --- a/advisories/unreviewed/2022/12/GHSA-86q3-6wjf-3984/GHSA-86q3-6wjf-3984.json +++ b/advisories/unreviewed/2022/12/GHSA-86q3-6wjf-3984/GHSA-86q3-6wjf-3984.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-x4qc-6q9c-46qw/GHSA-x4qc-6q9c-46qw.json b/advisories/unreviewed/2022/12/GHSA-x4qc-6q9c-46qw/GHSA-x4qc-6q9c-46qw.json index a9586c4ce3b..df1d080059f 100644 --- a/advisories/unreviewed/2022/12/GHSA-x4qc-6q9c-46qw/GHSA-x4qc-6q9c-46qw.json +++ b/advisories/unreviewed/2022/12/GHSA-x4qc-6q9c-46qw/GHSA-x4qc-6q9c-46qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-xgxj-cfph-mm49/GHSA-xgxj-cfph-mm49.json b/advisories/unreviewed/2022/12/GHSA-xgxj-cfph-mm49/GHSA-xgxj-cfph-mm49.json index 3a08d992209..39aa46f6443 100644 --- a/advisories/unreviewed/2022/12/GHSA-xgxj-cfph-mm49/GHSA-xgxj-cfph-mm49.json +++ b/advisories/unreviewed/2022/12/GHSA-xgxj-cfph-mm49/GHSA-xgxj-cfph-mm49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-4q2q-9g24-gmxw/GHSA-4q2q-9g24-gmxw.json b/advisories/unreviewed/2023/01/GHSA-4q2q-9g24-gmxw/GHSA-4q2q-9g24-gmxw.json index e24dd028f04..3f31cb3293d 100644 --- a/advisories/unreviewed/2023/01/GHSA-4q2q-9g24-gmxw/GHSA-4q2q-9g24-gmxw.json +++ b/advisories/unreviewed/2023/01/GHSA-4q2q-9g24-gmxw/GHSA-4q2q-9g24-gmxw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-5c53-mg2q-8qhc/GHSA-5c53-mg2q-8qhc.json b/advisories/unreviewed/2023/01/GHSA-5c53-mg2q-8qhc/GHSA-5c53-mg2q-8qhc.json index c00239393eb..c647b8a3eed 100644 --- a/advisories/unreviewed/2023/01/GHSA-5c53-mg2q-8qhc/GHSA-5c53-mg2q-8qhc.json +++ b/advisories/unreviewed/2023/01/GHSA-5c53-mg2q-8qhc/GHSA-5c53-mg2q-8qhc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-66vq-r792-85wm/GHSA-66vq-r792-85wm.json b/advisories/unreviewed/2023/01/GHSA-66vq-r792-85wm/GHSA-66vq-r792-85wm.json index f5e5cff8518..c515f058db8 100644 --- a/advisories/unreviewed/2023/01/GHSA-66vq-r792-85wm/GHSA-66vq-r792-85wm.json +++ b/advisories/unreviewed/2023/01/GHSA-66vq-r792-85wm/GHSA-66vq-r792-85wm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-cr29-8xj3-v4f9/GHSA-cr29-8xj3-v4f9.json b/advisories/unreviewed/2023/01/GHSA-cr29-8xj3-v4f9/GHSA-cr29-8xj3-v4f9.json index 18f5474a213..268a876a4ee 100644 --- a/advisories/unreviewed/2023/01/GHSA-cr29-8xj3-v4f9/GHSA-cr29-8xj3-v4f9.json +++ b/advisories/unreviewed/2023/01/GHSA-cr29-8xj3-v4f9/GHSA-cr29-8xj3-v4f9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-fc86-55vx-x268/GHSA-fc86-55vx-x268.json b/advisories/unreviewed/2023/01/GHSA-fc86-55vx-x268/GHSA-fc86-55vx-x268.json index dfabf266eaf..dbe36afbe34 100644 --- a/advisories/unreviewed/2023/01/GHSA-fc86-55vx-x268/GHSA-fc86-55vx-x268.json +++ b/advisories/unreviewed/2023/01/GHSA-fc86-55vx-x268/GHSA-fc86-55vx-x268.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-g29v-3m9r-f46w/GHSA-g29v-3m9r-f46w.json b/advisories/unreviewed/2023/01/GHSA-g29v-3m9r-f46w/GHSA-g29v-3m9r-f46w.json index d34b7f5b2ee..e3d0305fa2f 100644 --- a/advisories/unreviewed/2023/01/GHSA-g29v-3m9r-f46w/GHSA-g29v-3m9r-f46w.json +++ b/advisories/unreviewed/2023/01/GHSA-g29v-3m9r-f46w/GHSA-g29v-3m9r-f46w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-hxf9-8vg6-w44v/GHSA-hxf9-8vg6-w44v.json b/advisories/unreviewed/2023/01/GHSA-hxf9-8vg6-w44v/GHSA-hxf9-8vg6-w44v.json index a8c4e7f400f..53904611385 100644 --- a/advisories/unreviewed/2023/01/GHSA-hxf9-8vg6-w44v/GHSA-hxf9-8vg6-w44v.json +++ b/advisories/unreviewed/2023/01/GHSA-hxf9-8vg6-w44v/GHSA-hxf9-8vg6-w44v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-pxr2-3jg8-8m32/GHSA-pxr2-3jg8-8m32.json b/advisories/unreviewed/2023/01/GHSA-pxr2-3jg8-8m32/GHSA-pxr2-3jg8-8m32.json index 72a5d3396c4..1f2b244c7f5 100644 --- a/advisories/unreviewed/2023/01/GHSA-pxr2-3jg8-8m32/GHSA-pxr2-3jg8-8m32.json +++ b/advisories/unreviewed/2023/01/GHSA-pxr2-3jg8-8m32/GHSA-pxr2-3jg8-8m32.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-qwwx-hvjj-2vq7/GHSA-qwwx-hvjj-2vq7.json b/advisories/unreviewed/2023/01/GHSA-qwwx-hvjj-2vq7/GHSA-qwwx-hvjj-2vq7.json index abd36218451..e6542df73c4 100644 --- a/advisories/unreviewed/2023/01/GHSA-qwwx-hvjj-2vq7/GHSA-qwwx-hvjj-2vq7.json +++ b/advisories/unreviewed/2023/01/GHSA-qwwx-hvjj-2vq7/GHSA-qwwx-hvjj-2vq7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-r5c5-3whr-qfrr/GHSA-r5c5-3whr-qfrr.json b/advisories/unreviewed/2023/01/GHSA-r5c5-3whr-qfrr/GHSA-r5c5-3whr-qfrr.json index 0f2c71662d1..0cc084e799d 100644 --- a/advisories/unreviewed/2023/01/GHSA-r5c5-3whr-qfrr/GHSA-r5c5-3whr-qfrr.json +++ b/advisories/unreviewed/2023/01/GHSA-r5c5-3whr-qfrr/GHSA-r5c5-3whr-qfrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-r5mg-x7hq-vwwm/GHSA-r5mg-x7hq-vwwm.json b/advisories/unreviewed/2023/01/GHSA-r5mg-x7hq-vwwm/GHSA-r5mg-x7hq-vwwm.json index edc77e1c20b..b40e34cd66b 100644 --- a/advisories/unreviewed/2023/01/GHSA-r5mg-x7hq-vwwm/GHSA-r5mg-x7hq-vwwm.json +++ b/advisories/unreviewed/2023/01/GHSA-r5mg-x7hq-vwwm/GHSA-r5mg-x7hq-vwwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-wrv4-jq6j-75pm/GHSA-wrv4-jq6j-75pm.json b/advisories/unreviewed/2023/01/GHSA-wrv4-jq6j-75pm/GHSA-wrv4-jq6j-75pm.json index 8df3967beaa..b98277634d9 100644 --- a/advisories/unreviewed/2023/01/GHSA-wrv4-jq6j-75pm/GHSA-wrv4-jq6j-75pm.json +++ b/advisories/unreviewed/2023/01/GHSA-wrv4-jq6j-75pm/GHSA-wrv4-jq6j-75pm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-wvx9-2gv8-v8jp/GHSA-wvx9-2gv8-v8jp.json b/advisories/unreviewed/2023/01/GHSA-wvx9-2gv8-v8jp/GHSA-wvx9-2gv8-v8jp.json index 7ae1eb98f1e..3c607fef7e7 100644 --- a/advisories/unreviewed/2023/01/GHSA-wvx9-2gv8-v8jp/GHSA-wvx9-2gv8-v8jp.json +++ b/advisories/unreviewed/2023/01/GHSA-wvx9-2gv8-v8jp/GHSA-wvx9-2gv8-v8jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-x75h-jr86-mj5x/GHSA-x75h-jr86-mj5x.json b/advisories/unreviewed/2023/01/GHSA-x75h-jr86-mj5x/GHSA-x75h-jr86-mj5x.json index 19c345a1af2..8b3bac29f18 100644 --- a/advisories/unreviewed/2023/01/GHSA-x75h-jr86-mj5x/GHSA-x75h-jr86-mj5x.json +++ b/advisories/unreviewed/2023/01/GHSA-x75h-jr86-mj5x/GHSA-x75h-jr86-mj5x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-xf2q-qxhf-rqh5/GHSA-xf2q-qxhf-rqh5.json b/advisories/unreviewed/2023/01/GHSA-xf2q-qxhf-rqh5/GHSA-xf2q-qxhf-rqh5.json index da0b05b62de..cdb50e6c234 100644 --- a/advisories/unreviewed/2023/01/GHSA-xf2q-qxhf-rqh5/GHSA-xf2q-qxhf-rqh5.json +++ b/advisories/unreviewed/2023/01/GHSA-xf2q-qxhf-rqh5/GHSA-xf2q-qxhf-rqh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-22x3-2qf6-f5mp/GHSA-22x3-2qf6-f5mp.json b/advisories/unreviewed/2023/02/GHSA-22x3-2qf6-f5mp/GHSA-22x3-2qf6-f5mp.json index dd8823f3211..56d0fa45a4a 100644 --- a/advisories/unreviewed/2023/02/GHSA-22x3-2qf6-f5mp/GHSA-22x3-2qf6-f5mp.json +++ b/advisories/unreviewed/2023/02/GHSA-22x3-2qf6-f5mp/GHSA-22x3-2qf6-f5mp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-2ww8-f9rj-2xg5/GHSA-2ww8-f9rj-2xg5.json b/advisories/unreviewed/2023/02/GHSA-2ww8-f9rj-2xg5/GHSA-2ww8-f9rj-2xg5.json index 42aaaf9ada4..7e3a4af55e2 100644 --- a/advisories/unreviewed/2023/02/GHSA-2ww8-f9rj-2xg5/GHSA-2ww8-f9rj-2xg5.json +++ b/advisories/unreviewed/2023/02/GHSA-2ww8-f9rj-2xg5/GHSA-2ww8-f9rj-2xg5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-4gmg-r65m-fr2x/GHSA-4gmg-r65m-fr2x.json b/advisories/unreviewed/2023/02/GHSA-4gmg-r65m-fr2x/GHSA-4gmg-r65m-fr2x.json index a7a2d36b5da..f660cd79825 100644 --- a/advisories/unreviewed/2023/02/GHSA-4gmg-r65m-fr2x/GHSA-4gmg-r65m-fr2x.json +++ b/advisories/unreviewed/2023/02/GHSA-4gmg-r65m-fr2x/GHSA-4gmg-r65m-fr2x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-6fr7-2fr2-7jh9/GHSA-6fr7-2fr2-7jh9.json b/advisories/unreviewed/2023/02/GHSA-6fr7-2fr2-7jh9/GHSA-6fr7-2fr2-7jh9.json index f22059b7084..39ac2dd0269 100644 --- a/advisories/unreviewed/2023/02/GHSA-6fr7-2fr2-7jh9/GHSA-6fr7-2fr2-7jh9.json +++ b/advisories/unreviewed/2023/02/GHSA-6fr7-2fr2-7jh9/GHSA-6fr7-2fr2-7jh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-qq8v-cw34-3r3m/GHSA-qq8v-cw34-3r3m.json b/advisories/unreviewed/2023/02/GHSA-qq8v-cw34-3r3m/GHSA-qq8v-cw34-3r3m.json index a5c79a27bd6..1b57031a91a 100644 --- a/advisories/unreviewed/2023/02/GHSA-qq8v-cw34-3r3m/GHSA-qq8v-cw34-3r3m.json +++ b/advisories/unreviewed/2023/02/GHSA-qq8v-cw34-3r3m/GHSA-qq8v-cw34-3r3m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-wg3r-23qv-fhj6/GHSA-wg3r-23qv-fhj6.json b/advisories/unreviewed/2023/02/GHSA-wg3r-23qv-fhj6/GHSA-wg3r-23qv-fhj6.json index 91b355b5d0b..70828ac27f1 100644 --- a/advisories/unreviewed/2023/02/GHSA-wg3r-23qv-fhj6/GHSA-wg3r-23qv-fhj6.json +++ b/advisories/unreviewed/2023/02/GHSA-wg3r-23qv-fhj6/GHSA-wg3r-23qv-fhj6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-h2q8-mvpc-6j4j/GHSA-h2q8-mvpc-6j4j.json b/advisories/unreviewed/2023/03/GHSA-h2q8-mvpc-6j4j/GHSA-h2q8-mvpc-6j4j.json index 452becbb172..d67dcdcc2d8 100644 --- a/advisories/unreviewed/2023/03/GHSA-h2q8-mvpc-6j4j/GHSA-h2q8-mvpc-6j4j.json +++ b/advisories/unreviewed/2023/03/GHSA-h2q8-mvpc-6j4j/GHSA-h2q8-mvpc-6j4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-hcgv-rjpx-8qjc/GHSA-hcgv-rjpx-8qjc.json b/advisories/unreviewed/2023/03/GHSA-hcgv-rjpx-8qjc/GHSA-hcgv-rjpx-8qjc.json index c2d8034956c..410224b3d7c 100644 --- a/advisories/unreviewed/2023/03/GHSA-hcgv-rjpx-8qjc/GHSA-hcgv-rjpx-8qjc.json +++ b/advisories/unreviewed/2023/03/GHSA-hcgv-rjpx-8qjc/GHSA-hcgv-rjpx-8qjc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-mm5q-h234-59mj/GHSA-mm5q-h234-59mj.json b/advisories/unreviewed/2023/03/GHSA-mm5q-h234-59mj/GHSA-mm5q-h234-59mj.json index e22eb7b91dd..4c8eefc79f0 100644 --- a/advisories/unreviewed/2023/03/GHSA-mm5q-h234-59mj/GHSA-mm5q-h234-59mj.json +++ b/advisories/unreviewed/2023/03/GHSA-mm5q-h234-59mj/GHSA-mm5q-h234-59mj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-23vj-5jhc-26rp/GHSA-23vj-5jhc-26rp.json b/advisories/unreviewed/2023/06/GHSA-23vj-5jhc-26rp/GHSA-23vj-5jhc-26rp.json index 63b44f0440d..c0f06831956 100644 --- a/advisories/unreviewed/2023/06/GHSA-23vj-5jhc-26rp/GHSA-23vj-5jhc-26rp.json +++ b/advisories/unreviewed/2023/06/GHSA-23vj-5jhc-26rp/GHSA-23vj-5jhc-26rp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-6c6g-97p2-3xrq/GHSA-6c6g-97p2-3xrq.json b/advisories/unreviewed/2023/06/GHSA-6c6g-97p2-3xrq/GHSA-6c6g-97p2-3xrq.json index d22b9e6224f..b626f07130f 100644 --- a/advisories/unreviewed/2023/06/GHSA-6c6g-97p2-3xrq/GHSA-6c6g-97p2-3xrq.json +++ b/advisories/unreviewed/2023/06/GHSA-6c6g-97p2-3xrq/GHSA-6c6g-97p2-3xrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-cp8j-9c47-62cg/GHSA-cp8j-9c47-62cg.json b/advisories/unreviewed/2023/06/GHSA-cp8j-9c47-62cg/GHSA-cp8j-9c47-62cg.json index 6b696af049a..1d25064fdb5 100644 --- a/advisories/unreviewed/2023/06/GHSA-cp8j-9c47-62cg/GHSA-cp8j-9c47-62cg.json +++ b/advisories/unreviewed/2023/06/GHSA-cp8j-9c47-62cg/GHSA-cp8j-9c47-62cg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-7wwm-57j8-wx2j/GHSA-7wwm-57j8-wx2j.json b/advisories/unreviewed/2023/09/GHSA-7wwm-57j8-wx2j/GHSA-7wwm-57j8-wx2j.json index cd27aedc68d..2dcce05bf28 100644 --- a/advisories/unreviewed/2023/09/GHSA-7wwm-57j8-wx2j/GHSA-7wwm-57j8-wx2j.json +++ b/advisories/unreviewed/2023/09/GHSA-7wwm-57j8-wx2j/GHSA-7wwm-57j8-wx2j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2023/10/GHSA-3wvh-wgv4-8fvc/GHSA-3wvh-wgv4-8fvc.json b/advisories/unreviewed/2023/10/GHSA-3wvh-wgv4-8fvc/GHSA-3wvh-wgv4-8fvc.json index 53a6aa075dc..96c7b463616 100644 --- a/advisories/unreviewed/2023/10/GHSA-3wvh-wgv4-8fvc/GHSA-3wvh-wgv4-8fvc.json +++ b/advisories/unreviewed/2023/10/GHSA-3wvh-wgv4-8fvc/GHSA-3wvh-wgv4-8fvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-7cq2-v5ph-5463/GHSA-7cq2-v5ph-5463.json b/advisories/unreviewed/2023/10/GHSA-7cq2-v5ph-5463/GHSA-7cq2-v5ph-5463.json index 74bc107450d..ead0149a35f 100644 --- a/advisories/unreviewed/2023/10/GHSA-7cq2-v5ph-5463/GHSA-7cq2-v5ph-5463.json +++ b/advisories/unreviewed/2023/10/GHSA-7cq2-v5ph-5463/GHSA-7cq2-v5ph-5463.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-99vx-9c28-97p2/GHSA-99vx-9c28-97p2.json b/advisories/unreviewed/2023/10/GHSA-99vx-9c28-97p2/GHSA-99vx-9c28-97p2.json index 063d6b0079b..c3cb860cc8b 100644 --- a/advisories/unreviewed/2023/10/GHSA-99vx-9c28-97p2/GHSA-99vx-9c28-97p2.json +++ b/advisories/unreviewed/2023/10/GHSA-99vx-9c28-97p2/GHSA-99vx-9c28-97p2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-9hm3-chgj-45rm/GHSA-9hm3-chgj-45rm.json b/advisories/unreviewed/2023/10/GHSA-9hm3-chgj-45rm/GHSA-9hm3-chgj-45rm.json index 8583b2a8f7e..048a797b353 100644 --- a/advisories/unreviewed/2023/10/GHSA-9hm3-chgj-45rm/GHSA-9hm3-chgj-45rm.json +++ b/advisories/unreviewed/2023/10/GHSA-9hm3-chgj-45rm/GHSA-9hm3-chgj-45rm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-cw9h-crjm-c99p/GHSA-cw9h-crjm-c99p.json b/advisories/unreviewed/2023/10/GHSA-cw9h-crjm-c99p/GHSA-cw9h-crjm-c99p.json index 83c02ef2b1d..c51b2e3d378 100644 --- a/advisories/unreviewed/2023/10/GHSA-cw9h-crjm-c99p/GHSA-cw9h-crjm-c99p.json +++ b/advisories/unreviewed/2023/10/GHSA-cw9h-crjm-c99p/GHSA-cw9h-crjm-c99p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-m772-7wx3-fv6x/GHSA-m772-7wx3-fv6x.json b/advisories/unreviewed/2023/10/GHSA-m772-7wx3-fv6x/GHSA-m772-7wx3-fv6x.json index 914f48d23b4..723e7018479 100644 --- a/advisories/unreviewed/2023/10/GHSA-m772-7wx3-fv6x/GHSA-m772-7wx3-fv6x.json +++ b/advisories/unreviewed/2023/10/GHSA-m772-7wx3-fv6x/GHSA-m772-7wx3-fv6x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-pr32-36pm-7395/GHSA-pr32-36pm-7395.json b/advisories/unreviewed/2023/10/GHSA-pr32-36pm-7395/GHSA-pr32-36pm-7395.json index 2f4debb6f74..11c0aee29d8 100644 --- a/advisories/unreviewed/2023/10/GHSA-pr32-36pm-7395/GHSA-pr32-36pm-7395.json +++ b/advisories/unreviewed/2023/10/GHSA-pr32-36pm-7395/GHSA-pr32-36pm-7395.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-rgrr-m4xm-32mh/GHSA-rgrr-m4xm-32mh.json b/advisories/unreviewed/2023/10/GHSA-rgrr-m4xm-32mh/GHSA-rgrr-m4xm-32mh.json index 39d63a02545..191e2245d08 100644 --- a/advisories/unreviewed/2023/10/GHSA-rgrr-m4xm-32mh/GHSA-rgrr-m4xm-32mh.json +++ b/advisories/unreviewed/2023/10/GHSA-rgrr-m4xm-32mh/GHSA-rgrr-m4xm-32mh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-xm85-mgcm-6w3f/GHSA-xm85-mgcm-6w3f.json b/advisories/unreviewed/2023/10/GHSA-xm85-mgcm-6w3f/GHSA-xm85-mgcm-6w3f.json index bc3100d309f..b87c643bcba 100644 --- a/advisories/unreviewed/2023/10/GHSA-xm85-mgcm-6w3f/GHSA-xm85-mgcm-6w3f.json +++ b/advisories/unreviewed/2023/10/GHSA-xm85-mgcm-6w3f/GHSA-xm85-mgcm-6w3f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-3285-g6w2-x8q4/GHSA-3285-g6w2-x8q4.json b/advisories/unreviewed/2023/11/GHSA-3285-g6w2-x8q4/GHSA-3285-g6w2-x8q4.json index 0b8cd984576..8c1ef8a2c15 100644 --- a/advisories/unreviewed/2023/11/GHSA-3285-g6w2-x8q4/GHSA-3285-g6w2-x8q4.json +++ b/advisories/unreviewed/2023/11/GHSA-3285-g6w2-x8q4/GHSA-3285-g6w2-x8q4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-3gm2-64xq-8fp3/GHSA-3gm2-64xq-8fp3.json b/advisories/unreviewed/2023/11/GHSA-3gm2-64xq-8fp3/GHSA-3gm2-64xq-8fp3.json index b057da45ff3..8772d80bc49 100644 --- a/advisories/unreviewed/2023/11/GHSA-3gm2-64xq-8fp3/GHSA-3gm2-64xq-8fp3.json +++ b/advisories/unreviewed/2023/11/GHSA-3gm2-64xq-8fp3/GHSA-3gm2-64xq-8fp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-3xwf-jqhp-f89m/GHSA-3xwf-jqhp-f89m.json b/advisories/unreviewed/2023/11/GHSA-3xwf-jqhp-f89m/GHSA-3xwf-jqhp-f89m.json index 24fbdd460d5..bf249b9b6f5 100644 --- a/advisories/unreviewed/2023/11/GHSA-3xwf-jqhp-f89m/GHSA-3xwf-jqhp-f89m.json +++ b/advisories/unreviewed/2023/11/GHSA-3xwf-jqhp-f89m/GHSA-3xwf-jqhp-f89m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-3xxj-rfjr-w6h5/GHSA-3xxj-rfjr-w6h5.json b/advisories/unreviewed/2023/11/GHSA-3xxj-rfjr-w6h5/GHSA-3xxj-rfjr-w6h5.json index 1ba03b43ce4..269b0a147a7 100644 --- a/advisories/unreviewed/2023/11/GHSA-3xxj-rfjr-w6h5/GHSA-3xxj-rfjr-w6h5.json +++ b/advisories/unreviewed/2023/11/GHSA-3xxj-rfjr-w6h5/GHSA-3xxj-rfjr-w6h5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-422j-w5mv-f3f3/GHSA-422j-w5mv-f3f3.json b/advisories/unreviewed/2023/11/GHSA-422j-w5mv-f3f3/GHSA-422j-w5mv-f3f3.json index c764644f677..70bf2d39974 100644 --- a/advisories/unreviewed/2023/11/GHSA-422j-w5mv-f3f3/GHSA-422j-w5mv-f3f3.json +++ b/advisories/unreviewed/2023/11/GHSA-422j-w5mv-f3f3/GHSA-422j-w5mv-f3f3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-4742-9c9c-4wf7/GHSA-4742-9c9c-4wf7.json b/advisories/unreviewed/2023/11/GHSA-4742-9c9c-4wf7/GHSA-4742-9c9c-4wf7.json index 239b4d6a424..33fcd809d58 100644 --- a/advisories/unreviewed/2023/11/GHSA-4742-9c9c-4wf7/GHSA-4742-9c9c-4wf7.json +++ b/advisories/unreviewed/2023/11/GHSA-4742-9c9c-4wf7/GHSA-4742-9c9c-4wf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-4g2c-9347-58ff/GHSA-4g2c-9347-58ff.json b/advisories/unreviewed/2023/11/GHSA-4g2c-9347-58ff/GHSA-4g2c-9347-58ff.json index 1170059f4c0..7e42103d961 100644 --- a/advisories/unreviewed/2023/11/GHSA-4g2c-9347-58ff/GHSA-4g2c-9347-58ff.json +++ b/advisories/unreviewed/2023/11/GHSA-4g2c-9347-58ff/GHSA-4g2c-9347-58ff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-4gw7-ppxh-mmrp/GHSA-4gw7-ppxh-mmrp.json b/advisories/unreviewed/2023/11/GHSA-4gw7-ppxh-mmrp/GHSA-4gw7-ppxh-mmrp.json index 5e5bcfa74f7..30411a4ad3d 100644 --- a/advisories/unreviewed/2023/11/GHSA-4gw7-ppxh-mmrp/GHSA-4gw7-ppxh-mmrp.json +++ b/advisories/unreviewed/2023/11/GHSA-4gw7-ppxh-mmrp/GHSA-4gw7-ppxh-mmrp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-583v-xw8h-qw2h/GHSA-583v-xw8h-qw2h.json b/advisories/unreviewed/2023/11/GHSA-583v-xw8h-qw2h/GHSA-583v-xw8h-qw2h.json index 5132f361eb2..d4398491332 100644 --- a/advisories/unreviewed/2023/11/GHSA-583v-xw8h-qw2h/GHSA-583v-xw8h-qw2h.json +++ b/advisories/unreviewed/2023/11/GHSA-583v-xw8h-qw2h/GHSA-583v-xw8h-qw2h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-5fvg-7q6x-mgh2/GHSA-5fvg-7q6x-mgh2.json b/advisories/unreviewed/2023/11/GHSA-5fvg-7q6x-mgh2/GHSA-5fvg-7q6x-mgh2.json index a5bf1beb6ba..76e03bb42ca 100644 --- a/advisories/unreviewed/2023/11/GHSA-5fvg-7q6x-mgh2/GHSA-5fvg-7q6x-mgh2.json +++ b/advisories/unreviewed/2023/11/GHSA-5fvg-7q6x-mgh2/GHSA-5fvg-7q6x-mgh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-5mx5-qh58-rrh2/GHSA-5mx5-qh58-rrh2.json b/advisories/unreviewed/2023/11/GHSA-5mx5-qh58-rrh2/GHSA-5mx5-qh58-rrh2.json index ef360e30962..260744312bf 100644 --- a/advisories/unreviewed/2023/11/GHSA-5mx5-qh58-rrh2/GHSA-5mx5-qh58-rrh2.json +++ b/advisories/unreviewed/2023/11/GHSA-5mx5-qh58-rrh2/GHSA-5mx5-qh58-rrh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-5qhh-783c-vpmm/GHSA-5qhh-783c-vpmm.json b/advisories/unreviewed/2023/11/GHSA-5qhh-783c-vpmm/GHSA-5qhh-783c-vpmm.json index 93172a38528..e724ad0ee8e 100644 --- a/advisories/unreviewed/2023/11/GHSA-5qhh-783c-vpmm/GHSA-5qhh-783c-vpmm.json +++ b/advisories/unreviewed/2023/11/GHSA-5qhh-783c-vpmm/GHSA-5qhh-783c-vpmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-6jhm-w7qq-9788/GHSA-6jhm-w7qq-9788.json b/advisories/unreviewed/2023/11/GHSA-6jhm-w7qq-9788/GHSA-6jhm-w7qq-9788.json index af41fb8c1cf..a5cd78d7c12 100644 --- a/advisories/unreviewed/2023/11/GHSA-6jhm-w7qq-9788/GHSA-6jhm-w7qq-9788.json +++ b/advisories/unreviewed/2023/11/GHSA-6jhm-w7qq-9788/GHSA-6jhm-w7qq-9788.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-6q7p-2x27-26vg/GHSA-6q7p-2x27-26vg.json b/advisories/unreviewed/2023/11/GHSA-6q7p-2x27-26vg/GHSA-6q7p-2x27-26vg.json index 9e9ff833281..777c8e5a88b 100644 --- a/advisories/unreviewed/2023/11/GHSA-6q7p-2x27-26vg/GHSA-6q7p-2x27-26vg.json +++ b/advisories/unreviewed/2023/11/GHSA-6q7p-2x27-26vg/GHSA-6q7p-2x27-26vg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-6w75-vqq2-8cjx/GHSA-6w75-vqq2-8cjx.json b/advisories/unreviewed/2023/11/GHSA-6w75-vqq2-8cjx/GHSA-6w75-vqq2-8cjx.json index 8cc9a310c56..bbca34799ce 100644 --- a/advisories/unreviewed/2023/11/GHSA-6w75-vqq2-8cjx/GHSA-6w75-vqq2-8cjx.json +++ b/advisories/unreviewed/2023/11/GHSA-6w75-vqq2-8cjx/GHSA-6w75-vqq2-8cjx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-72vx-6xj8-m752/GHSA-72vx-6xj8-m752.json b/advisories/unreviewed/2023/11/GHSA-72vx-6xj8-m752/GHSA-72vx-6xj8-m752.json index eba834bc8ba..90a108118e9 100644 --- a/advisories/unreviewed/2023/11/GHSA-72vx-6xj8-m752/GHSA-72vx-6xj8-m752.json +++ b/advisories/unreviewed/2023/11/GHSA-72vx-6xj8-m752/GHSA-72vx-6xj8-m752.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-77h7-f57j-cjv2/GHSA-77h7-f57j-cjv2.json b/advisories/unreviewed/2023/11/GHSA-77h7-f57j-cjv2/GHSA-77h7-f57j-cjv2.json index 6a136cfa8ee..afe73375eea 100644 --- a/advisories/unreviewed/2023/11/GHSA-77h7-f57j-cjv2/GHSA-77h7-f57j-cjv2.json +++ b/advisories/unreviewed/2023/11/GHSA-77h7-f57j-cjv2/GHSA-77h7-f57j-cjv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-794f-9q36-972h/GHSA-794f-9q36-972h.json b/advisories/unreviewed/2023/11/GHSA-794f-9q36-972h/GHSA-794f-9q36-972h.json index fccab72afdc..c2afcfe8f0a 100644 --- a/advisories/unreviewed/2023/11/GHSA-794f-9q36-972h/GHSA-794f-9q36-972h.json +++ b/advisories/unreviewed/2023/11/GHSA-794f-9q36-972h/GHSA-794f-9q36-972h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-7j49-vjx9-cwp7/GHSA-7j49-vjx9-cwp7.json b/advisories/unreviewed/2023/11/GHSA-7j49-vjx9-cwp7/GHSA-7j49-vjx9-cwp7.json index 52effc0d714..b48ec1c57ee 100644 --- a/advisories/unreviewed/2023/11/GHSA-7j49-vjx9-cwp7/GHSA-7j49-vjx9-cwp7.json +++ b/advisories/unreviewed/2023/11/GHSA-7j49-vjx9-cwp7/GHSA-7j49-vjx9-cwp7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-7m4h-4frj-xvm5/GHSA-7m4h-4frj-xvm5.json b/advisories/unreviewed/2023/11/GHSA-7m4h-4frj-xvm5/GHSA-7m4h-4frj-xvm5.json index f1467514dc1..4cde07a0d65 100644 --- a/advisories/unreviewed/2023/11/GHSA-7m4h-4frj-xvm5/GHSA-7m4h-4frj-xvm5.json +++ b/advisories/unreviewed/2023/11/GHSA-7m4h-4frj-xvm5/GHSA-7m4h-4frj-xvm5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-84p4-j9qr-gxr6/GHSA-84p4-j9qr-gxr6.json b/advisories/unreviewed/2023/11/GHSA-84p4-j9qr-gxr6/GHSA-84p4-j9qr-gxr6.json index e0c183d4a69..0a397a2fbe3 100644 --- a/advisories/unreviewed/2023/11/GHSA-84p4-j9qr-gxr6/GHSA-84p4-j9qr-gxr6.json +++ b/advisories/unreviewed/2023/11/GHSA-84p4-j9qr-gxr6/GHSA-84p4-j9qr-gxr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-94x4-p49x-fp3r/GHSA-94x4-p49x-fp3r.json b/advisories/unreviewed/2023/11/GHSA-94x4-p49x-fp3r/GHSA-94x4-p49x-fp3r.json index 08adeb6ef07..5da41f44995 100644 --- a/advisories/unreviewed/2023/11/GHSA-94x4-p49x-fp3r/GHSA-94x4-p49x-fp3r.json +++ b/advisories/unreviewed/2023/11/GHSA-94x4-p49x-fp3r/GHSA-94x4-p49x-fp3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-9fr8-m3gw-gcm4/GHSA-9fr8-m3gw-gcm4.json b/advisories/unreviewed/2023/11/GHSA-9fr8-m3gw-gcm4/GHSA-9fr8-m3gw-gcm4.json index a217e2df187..4528b260aac 100644 --- a/advisories/unreviewed/2023/11/GHSA-9fr8-m3gw-gcm4/GHSA-9fr8-m3gw-gcm4.json +++ b/advisories/unreviewed/2023/11/GHSA-9fr8-m3gw-gcm4/GHSA-9fr8-m3gw-gcm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-9p54-wmmc-452q/GHSA-9p54-wmmc-452q.json b/advisories/unreviewed/2023/11/GHSA-9p54-wmmc-452q/GHSA-9p54-wmmc-452q.json index 2b80dfd3047..00877f3977c 100644 --- a/advisories/unreviewed/2023/11/GHSA-9p54-wmmc-452q/GHSA-9p54-wmmc-452q.json +++ b/advisories/unreviewed/2023/11/GHSA-9p54-wmmc-452q/GHSA-9p54-wmmc-452q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-c2v4-q7c8-8w9w/GHSA-c2v4-q7c8-8w9w.json b/advisories/unreviewed/2023/11/GHSA-c2v4-q7c8-8w9w/GHSA-c2v4-q7c8-8w9w.json index 4e3a33f9bbb..693898a319c 100644 --- a/advisories/unreviewed/2023/11/GHSA-c2v4-q7c8-8w9w/GHSA-c2v4-q7c8-8w9w.json +++ b/advisories/unreviewed/2023/11/GHSA-c2v4-q7c8-8w9w/GHSA-c2v4-q7c8-8w9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-c65v-cwf9-f69v/GHSA-c65v-cwf9-f69v.json b/advisories/unreviewed/2023/11/GHSA-c65v-cwf9-f69v/GHSA-c65v-cwf9-f69v.json index 5d09722848f..d3d4f2366a9 100644 --- a/advisories/unreviewed/2023/11/GHSA-c65v-cwf9-f69v/GHSA-c65v-cwf9-f69v.json +++ b/advisories/unreviewed/2023/11/GHSA-c65v-cwf9-f69v/GHSA-c65v-cwf9-f69v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-chvm-3c2v-p6qg/GHSA-chvm-3c2v-p6qg.json b/advisories/unreviewed/2023/11/GHSA-chvm-3c2v-p6qg/GHSA-chvm-3c2v-p6qg.json index 1f732344f94..de11f519e9d 100644 --- a/advisories/unreviewed/2023/11/GHSA-chvm-3c2v-p6qg/GHSA-chvm-3c2v-p6qg.json +++ b/advisories/unreviewed/2023/11/GHSA-chvm-3c2v-p6qg/GHSA-chvm-3c2v-p6qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-cjpq-3xp9-4722/GHSA-cjpq-3xp9-4722.json b/advisories/unreviewed/2023/11/GHSA-cjpq-3xp9-4722/GHSA-cjpq-3xp9-4722.json index 1a2945943e9..45d40e53e86 100644 --- a/advisories/unreviewed/2023/11/GHSA-cjpq-3xp9-4722/GHSA-cjpq-3xp9-4722.json +++ b/advisories/unreviewed/2023/11/GHSA-cjpq-3xp9-4722/GHSA-cjpq-3xp9-4722.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-cm77-ccvm-f7p6/GHSA-cm77-ccvm-f7p6.json b/advisories/unreviewed/2023/11/GHSA-cm77-ccvm-f7p6/GHSA-cm77-ccvm-f7p6.json index 2d1cd63dc85..0c7ea071f3a 100644 --- a/advisories/unreviewed/2023/11/GHSA-cm77-ccvm-f7p6/GHSA-cm77-ccvm-f7p6.json +++ b/advisories/unreviewed/2023/11/GHSA-cm77-ccvm-f7p6/GHSA-cm77-ccvm-f7p6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-cx3g-f3g3-5494/GHSA-cx3g-f3g3-5494.json b/advisories/unreviewed/2023/11/GHSA-cx3g-f3g3-5494/GHSA-cx3g-f3g3-5494.json index e6caf19a9ee..1b63788eb80 100644 --- a/advisories/unreviewed/2023/11/GHSA-cx3g-f3g3-5494/GHSA-cx3g-f3g3-5494.json +++ b/advisories/unreviewed/2023/11/GHSA-cx3g-f3g3-5494/GHSA-cx3g-f3g3-5494.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-fpmx-qfph-4r6r/GHSA-fpmx-qfph-4r6r.json b/advisories/unreviewed/2023/11/GHSA-fpmx-qfph-4r6r/GHSA-fpmx-qfph-4r6r.json index 93ff7430de7..6e26d0474ba 100644 --- a/advisories/unreviewed/2023/11/GHSA-fpmx-qfph-4r6r/GHSA-fpmx-qfph-4r6r.json +++ b/advisories/unreviewed/2023/11/GHSA-fpmx-qfph-4r6r/GHSA-fpmx-qfph-4r6r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-h42p-m2rq-vxxg/GHSA-h42p-m2rq-vxxg.json b/advisories/unreviewed/2023/11/GHSA-h42p-m2rq-vxxg/GHSA-h42p-m2rq-vxxg.json index c2fa85645ee..60ddc2d0bd8 100644 --- a/advisories/unreviewed/2023/11/GHSA-h42p-m2rq-vxxg/GHSA-h42p-m2rq-vxxg.json +++ b/advisories/unreviewed/2023/11/GHSA-h42p-m2rq-vxxg/GHSA-h42p-m2rq-vxxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-h4gp-9r63-7fgw/GHSA-h4gp-9r63-7fgw.json b/advisories/unreviewed/2023/11/GHSA-h4gp-9r63-7fgw/GHSA-h4gp-9r63-7fgw.json index 0e1d1b46873..ca4adbe9a7a 100644 --- a/advisories/unreviewed/2023/11/GHSA-h4gp-9r63-7fgw/GHSA-h4gp-9r63-7fgw.json +++ b/advisories/unreviewed/2023/11/GHSA-h4gp-9r63-7fgw/GHSA-h4gp-9r63-7fgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-hh28-6v7m-3v52/GHSA-hh28-6v7m-3v52.json b/advisories/unreviewed/2023/11/GHSA-hh28-6v7m-3v52/GHSA-hh28-6v7m-3v52.json index ded69244333..3ac68984756 100644 --- a/advisories/unreviewed/2023/11/GHSA-hh28-6v7m-3v52/GHSA-hh28-6v7m-3v52.json +++ b/advisories/unreviewed/2023/11/GHSA-hh28-6v7m-3v52/GHSA-hh28-6v7m-3v52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-j2vx-8xmx-87hp/GHSA-j2vx-8xmx-87hp.json b/advisories/unreviewed/2023/11/GHSA-j2vx-8xmx-87hp/GHSA-j2vx-8xmx-87hp.json index dd93093c96a..c24c5f16012 100644 --- a/advisories/unreviewed/2023/11/GHSA-j2vx-8xmx-87hp/GHSA-j2vx-8xmx-87hp.json +++ b/advisories/unreviewed/2023/11/GHSA-j2vx-8xmx-87hp/GHSA-j2vx-8xmx-87hp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-j3qr-8pp8-m4vp/GHSA-j3qr-8pp8-m4vp.json b/advisories/unreviewed/2023/11/GHSA-j3qr-8pp8-m4vp/GHSA-j3qr-8pp8-m4vp.json index e4964a2615a..7f4fa90b824 100644 --- a/advisories/unreviewed/2023/11/GHSA-j3qr-8pp8-m4vp/GHSA-j3qr-8pp8-m4vp.json +++ b/advisories/unreviewed/2023/11/GHSA-j3qr-8pp8-m4vp/GHSA-j3qr-8pp8-m4vp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-j4gp-vqp3-jp8r/GHSA-j4gp-vqp3-jp8r.json b/advisories/unreviewed/2023/11/GHSA-j4gp-vqp3-jp8r/GHSA-j4gp-vqp3-jp8r.json index 87f51197197..25725b11c31 100644 --- a/advisories/unreviewed/2023/11/GHSA-j4gp-vqp3-jp8r/GHSA-j4gp-vqp3-jp8r.json +++ b/advisories/unreviewed/2023/11/GHSA-j4gp-vqp3-jp8r/GHSA-j4gp-vqp3-jp8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-j97j-w85x-cvvq/GHSA-j97j-w85x-cvvq.json b/advisories/unreviewed/2023/11/GHSA-j97j-w85x-cvvq/GHSA-j97j-w85x-cvvq.json index 47e80f6bd36..94b98122550 100644 --- a/advisories/unreviewed/2023/11/GHSA-j97j-w85x-cvvq/GHSA-j97j-w85x-cvvq.json +++ b/advisories/unreviewed/2023/11/GHSA-j97j-w85x-cvvq/GHSA-j97j-w85x-cvvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-jfv3-2638-xrwh/GHSA-jfv3-2638-xrwh.json b/advisories/unreviewed/2023/11/GHSA-jfv3-2638-xrwh/GHSA-jfv3-2638-xrwh.json index b829d77d1c2..6bcfa421c59 100644 --- a/advisories/unreviewed/2023/11/GHSA-jfv3-2638-xrwh/GHSA-jfv3-2638-xrwh.json +++ b/advisories/unreviewed/2023/11/GHSA-jfv3-2638-xrwh/GHSA-jfv3-2638-xrwh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-jj53-4h2j-9gmj/GHSA-jj53-4h2j-9gmj.json b/advisories/unreviewed/2023/11/GHSA-jj53-4h2j-9gmj/GHSA-jj53-4h2j-9gmj.json index ddf6402e078..e42f004512b 100644 --- a/advisories/unreviewed/2023/11/GHSA-jj53-4h2j-9gmj/GHSA-jj53-4h2j-9gmj.json +++ b/advisories/unreviewed/2023/11/GHSA-jj53-4h2j-9gmj/GHSA-jj53-4h2j-9gmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-pc7h-cpmv-65jh/GHSA-pc7h-cpmv-65jh.json b/advisories/unreviewed/2023/11/GHSA-pc7h-cpmv-65jh/GHSA-pc7h-cpmv-65jh.json index dfc3c817aaf..e765ed36967 100644 --- a/advisories/unreviewed/2023/11/GHSA-pc7h-cpmv-65jh/GHSA-pc7h-cpmv-65jh.json +++ b/advisories/unreviewed/2023/11/GHSA-pc7h-cpmv-65jh/GHSA-pc7h-cpmv-65jh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-ph4g-vfg9-83hr/GHSA-ph4g-vfg9-83hr.json b/advisories/unreviewed/2023/11/GHSA-ph4g-vfg9-83hr/GHSA-ph4g-vfg9-83hr.json index fa58cc14c04..167abb644ab 100644 --- a/advisories/unreviewed/2023/11/GHSA-ph4g-vfg9-83hr/GHSA-ph4g-vfg9-83hr.json +++ b/advisories/unreviewed/2023/11/GHSA-ph4g-vfg9-83hr/GHSA-ph4g-vfg9-83hr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-qhq7-4fq9-2fp7/GHSA-qhq7-4fq9-2fp7.json b/advisories/unreviewed/2023/11/GHSA-qhq7-4fq9-2fp7/GHSA-qhq7-4fq9-2fp7.json index 5d8907d7416..d688b7c2165 100644 --- a/advisories/unreviewed/2023/11/GHSA-qhq7-4fq9-2fp7/GHSA-qhq7-4fq9-2fp7.json +++ b/advisories/unreviewed/2023/11/GHSA-qhq7-4fq9-2fp7/GHSA-qhq7-4fq9-2fp7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-rmr9-43mw-mv87/GHSA-rmr9-43mw-mv87.json b/advisories/unreviewed/2023/11/GHSA-rmr9-43mw-mv87/GHSA-rmr9-43mw-mv87.json index 6e02ac576fb..4b94d8505f6 100644 --- a/advisories/unreviewed/2023/11/GHSA-rmr9-43mw-mv87/GHSA-rmr9-43mw-mv87.json +++ b/advisories/unreviewed/2023/11/GHSA-rmr9-43mw-mv87/GHSA-rmr9-43mw-mv87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-rrcf-fxfm-g3vr/GHSA-rrcf-fxfm-g3vr.json b/advisories/unreviewed/2023/11/GHSA-rrcf-fxfm-g3vr/GHSA-rrcf-fxfm-g3vr.json index f304f9493ff..6fc962a2bb6 100644 --- a/advisories/unreviewed/2023/11/GHSA-rrcf-fxfm-g3vr/GHSA-rrcf-fxfm-g3vr.json +++ b/advisories/unreviewed/2023/11/GHSA-rrcf-fxfm-g3vr/GHSA-rrcf-fxfm-g3vr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-v93c-j63p-5mqw/GHSA-v93c-j63p-5mqw.json b/advisories/unreviewed/2023/11/GHSA-v93c-j63p-5mqw/GHSA-v93c-j63p-5mqw.json index 9047b281bb3..bcc6e9dc035 100644 --- a/advisories/unreviewed/2023/11/GHSA-v93c-j63p-5mqw/GHSA-v93c-j63p-5mqw.json +++ b/advisories/unreviewed/2023/11/GHSA-v93c-j63p-5mqw/GHSA-v93c-j63p-5mqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-vjw9-jcfv-rggv/GHSA-vjw9-jcfv-rggv.json b/advisories/unreviewed/2023/11/GHSA-vjw9-jcfv-rggv/GHSA-vjw9-jcfv-rggv.json index 0fe4d53127e..9e6f2b8f478 100644 --- a/advisories/unreviewed/2023/11/GHSA-vjw9-jcfv-rggv/GHSA-vjw9-jcfv-rggv.json +++ b/advisories/unreviewed/2023/11/GHSA-vjw9-jcfv-rggv/GHSA-vjw9-jcfv-rggv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-vw4m-22hh-wjmj/GHSA-vw4m-22hh-wjmj.json b/advisories/unreviewed/2023/11/GHSA-vw4m-22hh-wjmj/GHSA-vw4m-22hh-wjmj.json index 5b1a6aa0959..59315d9ac8b 100644 --- a/advisories/unreviewed/2023/11/GHSA-vw4m-22hh-wjmj/GHSA-vw4m-22hh-wjmj.json +++ b/advisories/unreviewed/2023/11/GHSA-vw4m-22hh-wjmj/GHSA-vw4m-22hh-wjmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-w86m-2494-94vf/GHSA-w86m-2494-94vf.json b/advisories/unreviewed/2023/11/GHSA-w86m-2494-94vf/GHSA-w86m-2494-94vf.json index c53d9383fce..e63f92305a5 100644 --- a/advisories/unreviewed/2023/11/GHSA-w86m-2494-94vf/GHSA-w86m-2494-94vf.json +++ b/advisories/unreviewed/2023/11/GHSA-w86m-2494-94vf/GHSA-w86m-2494-94vf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-w95x-2qq3-w4mr/GHSA-w95x-2qq3-w4mr.json b/advisories/unreviewed/2023/11/GHSA-w95x-2qq3-w4mr/GHSA-w95x-2qq3-w4mr.json index 8183628393f..9c74be7e4c4 100644 --- a/advisories/unreviewed/2023/11/GHSA-w95x-2qq3-w4mr/GHSA-w95x-2qq3-w4mr.json +++ b/advisories/unreviewed/2023/11/GHSA-w95x-2qq3-w4mr/GHSA-w95x-2qq3-w4mr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-xf6r-6c2v-5fv9/GHSA-xf6r-6c2v-5fv9.json b/advisories/unreviewed/2023/11/GHSA-xf6r-6c2v-5fv9/GHSA-xf6r-6c2v-5fv9.json index 713f7e91a3f..8cf4f1f9d55 100644 --- a/advisories/unreviewed/2023/11/GHSA-xf6r-6c2v-5fv9/GHSA-xf6r-6c2v-5fv9.json +++ b/advisories/unreviewed/2023/11/GHSA-xf6r-6c2v-5fv9/GHSA-xf6r-6c2v-5fv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-xpj7-v9x5-6gh9/GHSA-xpj7-v9x5-6gh9.json b/advisories/unreviewed/2023/11/GHSA-xpj7-v9x5-6gh9/GHSA-xpj7-v9x5-6gh9.json index efe9b37b34e..cbaadfbea02 100644 --- a/advisories/unreviewed/2023/11/GHSA-xpj7-v9x5-6gh9/GHSA-xpj7-v9x5-6gh9.json +++ b/advisories/unreviewed/2023/11/GHSA-xpj7-v9x5-6gh9/GHSA-xpj7-v9x5-6gh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-ggf8-3x7x-9mpw/GHSA-ggf8-3x7x-9mpw.json b/advisories/unreviewed/2023/12/GHSA-ggf8-3x7x-9mpw/GHSA-ggf8-3x7x-9mpw.json index 39ec1fcbb17..56b608eb855 100644 --- a/advisories/unreviewed/2023/12/GHSA-ggf8-3x7x-9mpw/GHSA-ggf8-3x7x-9mpw.json +++ b/advisories/unreviewed/2023/12/GHSA-ggf8-3x7x-9mpw/GHSA-ggf8-3x7x-9mpw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/12/GHSA-r74q-rghm-f66p/GHSA-r74q-rghm-f66p.json b/advisories/unreviewed/2023/12/GHSA-r74q-rghm-f66p/GHSA-r74q-rghm-f66p.json index 7629b3b45e1..b10595f1fe8 100644 --- a/advisories/unreviewed/2023/12/GHSA-r74q-rghm-f66p/GHSA-r74q-rghm-f66p.json +++ b/advisories/unreviewed/2023/12/GHSA-r74q-rghm-f66p/GHSA-r74q-rghm-f66p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-vcvx-r925-7vh9/GHSA-vcvx-r925-7vh9.json b/advisories/unreviewed/2023/12/GHSA-vcvx-r925-7vh9/GHSA-vcvx-r925-7vh9.json index 6d758943de6..d33e9d9b492 100644 --- a/advisories/unreviewed/2023/12/GHSA-vcvx-r925-7vh9/GHSA-vcvx-r925-7vh9.json +++ b/advisories/unreviewed/2023/12/GHSA-vcvx-r925-7vh9/GHSA-vcvx-r925-7vh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-9jwq-vg3g-gxcc/GHSA-9jwq-vg3g-gxcc.json b/advisories/unreviewed/2024/01/GHSA-9jwq-vg3g-gxcc/GHSA-9jwq-vg3g-gxcc.json index be5736d7a4f..b960f62b19e 100644 --- a/advisories/unreviewed/2024/01/GHSA-9jwq-vg3g-gxcc/GHSA-9jwq-vg3g-gxcc.json +++ b/advisories/unreviewed/2024/01/GHSA-9jwq-vg3g-gxcc/GHSA-9jwq-vg3g-gxcc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-g3jm-7w7w-rf6f/GHSA-g3jm-7w7w-rf6f.json b/advisories/unreviewed/2024/01/GHSA-g3jm-7w7w-rf6f/GHSA-g3jm-7w7w-rf6f.json index 7aa8898b8df..33ce31dbf6f 100644 --- a/advisories/unreviewed/2024/01/GHSA-g3jm-7w7w-rf6f/GHSA-g3jm-7w7w-rf6f.json +++ b/advisories/unreviewed/2024/01/GHSA-g3jm-7w7w-rf6f/GHSA-g3jm-7w7w-rf6f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-m426-263c-vx86/GHSA-m426-263c-vx86.json b/advisories/unreviewed/2024/01/GHSA-m426-263c-vx86/GHSA-m426-263c-vx86.json index f0742950d97..ef43badd804 100644 --- a/advisories/unreviewed/2024/01/GHSA-m426-263c-vx86/GHSA-m426-263c-vx86.json +++ b/advisories/unreviewed/2024/01/GHSA-m426-263c-vx86/GHSA-m426-263c-vx86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-vhqw-mw84-hph6/GHSA-vhqw-mw84-hph6.json b/advisories/unreviewed/2024/01/GHSA-vhqw-mw84-hph6/GHSA-vhqw-mw84-hph6.json index 6e4c8e36bd7..578128db0ff 100644 --- a/advisories/unreviewed/2024/01/GHSA-vhqw-mw84-hph6/GHSA-vhqw-mw84-hph6.json +++ b/advisories/unreviewed/2024/01/GHSA-vhqw-mw84-hph6/GHSA-vhqw-mw84-hph6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json b/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json index 0edbe7c3294..57c76950f21 100644 --- a/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json +++ b/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4xc2-vg9r-33pp/GHSA-4xc2-vg9r-33pp.json b/advisories/unreviewed/2024/03/GHSA-4xc2-vg9r-33pp/GHSA-4xc2-vg9r-33pp.json index ec00a40f62f..7604c3d5f34 100644 --- a/advisories/unreviewed/2024/03/GHSA-4xc2-vg9r-33pp/GHSA-4xc2-vg9r-33pp.json +++ b/advisories/unreviewed/2024/03/GHSA-4xc2-vg9r-33pp/GHSA-4xc2-vg9r-33pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-84hj-9c53-vjg2/GHSA-84hj-9c53-vjg2.json b/advisories/unreviewed/2024/03/GHSA-84hj-9c53-vjg2/GHSA-84hj-9c53-vjg2.json index 433bcff5efb..bbff7374c5e 100644 --- a/advisories/unreviewed/2024/03/GHSA-84hj-9c53-vjg2/GHSA-84hj-9c53-vjg2.json +++ b/advisories/unreviewed/2024/03/GHSA-84hj-9c53-vjg2/GHSA-84hj-9c53-vjg2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-8rqc-wx6q-m4qc/GHSA-8rqc-wx6q-m4qc.json b/advisories/unreviewed/2024/03/GHSA-8rqc-wx6q-m4qc/GHSA-8rqc-wx6q-m4qc.json index 8c4bb9002ca..b951f1f14a8 100644 --- a/advisories/unreviewed/2024/03/GHSA-8rqc-wx6q-m4qc/GHSA-8rqc-wx6q-m4qc.json +++ b/advisories/unreviewed/2024/03/GHSA-8rqc-wx6q-m4qc/GHSA-8rqc-wx6q-m4qc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-8wfm-cwf4-qvjj/GHSA-8wfm-cwf4-qvjj.json b/advisories/unreviewed/2024/03/GHSA-8wfm-cwf4-qvjj/GHSA-8wfm-cwf4-qvjj.json index 3e9f9715d89..2c498560945 100644 --- a/advisories/unreviewed/2024/03/GHSA-8wfm-cwf4-qvjj/GHSA-8wfm-cwf4-qvjj.json +++ b/advisories/unreviewed/2024/03/GHSA-8wfm-cwf4-qvjj/GHSA-8wfm-cwf4-qvjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json b/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json index 533f9524d1a..7716f021469 100644 --- a/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json +++ b/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json b/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json index 888b33a32e6..16d753e2ca2 100644 --- a/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json +++ b/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-m3xv-gj54-x2wv/GHSA-m3xv-gj54-x2wv.json b/advisories/unreviewed/2024/03/GHSA-m3xv-gj54-x2wv/GHSA-m3xv-gj54-x2wv.json index ab83df6d2f4..76f3b806f0a 100644 --- a/advisories/unreviewed/2024/03/GHSA-m3xv-gj54-x2wv/GHSA-m3xv-gj54-x2wv.json +++ b/advisories/unreviewed/2024/03/GHSA-m3xv-gj54-x2wv/GHSA-m3xv-gj54-x2wv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json b/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json index 0a97265f939..4c93b3e5d25 100644 --- a/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json +++ b/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-p84f-xgwp-4frf/GHSA-p84f-xgwp-4frf.json b/advisories/unreviewed/2024/03/GHSA-p84f-xgwp-4frf/GHSA-p84f-xgwp-4frf.json index 65ed22badb3..a460e0af4be 100644 --- a/advisories/unreviewed/2024/03/GHSA-p84f-xgwp-4frf/GHSA-p84f-xgwp-4frf.json +++ b/advisories/unreviewed/2024/03/GHSA-p84f-xgwp-4frf/GHSA-p84f-xgwp-4frf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-q3m8-4vff-qr66/GHSA-q3m8-4vff-qr66.json b/advisories/unreviewed/2024/03/GHSA-q3m8-4vff-qr66/GHSA-q3m8-4vff-qr66.json index 4ebac95f67f..1495bec49ea 100644 --- a/advisories/unreviewed/2024/03/GHSA-q3m8-4vff-qr66/GHSA-q3m8-4vff-qr66.json +++ b/advisories/unreviewed/2024/03/GHSA-q3m8-4vff-qr66/GHSA-q3m8-4vff-qr66.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-q4g5-6262-6h9p/GHSA-q4g5-6262-6h9p.json b/advisories/unreviewed/2024/03/GHSA-q4g5-6262-6h9p/GHSA-q4g5-6262-6h9p.json index 36e958b49d7..b8434811f09 100644 --- a/advisories/unreviewed/2024/03/GHSA-q4g5-6262-6h9p/GHSA-q4g5-6262-6h9p.json +++ b/advisories/unreviewed/2024/03/GHSA-q4g5-6262-6h9p/GHSA-q4g5-6262-6h9p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r6x7-5742-mcv8/GHSA-r6x7-5742-mcv8.json b/advisories/unreviewed/2024/03/GHSA-r6x7-5742-mcv8/GHSA-r6x7-5742-mcv8.json index 81b6a6aec6a..31fe189d79b 100644 --- a/advisories/unreviewed/2024/03/GHSA-r6x7-5742-mcv8/GHSA-r6x7-5742-mcv8.json +++ b/advisories/unreviewed/2024/03/GHSA-r6x7-5742-mcv8/GHSA-r6x7-5742-mcv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json b/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json index d3102e70bae..8e561f3ef75 100644 --- a/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json +++ b/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json b/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json index 05cb07df0bf..9d6352ee356 100644 --- a/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json +++ b/advisories/unreviewed/2024/03/GHSA-vrgq-j293-jcx7/GHSA-vrgq-j293-jcx7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2jh9-8qjc-9f2q/GHSA-2jh9-8qjc-9f2q.json b/advisories/unreviewed/2024/07/GHSA-2jh9-8qjc-9f2q/GHSA-2jh9-8qjc-9f2q.json index f5280690a03..8c889f0c488 100644 --- a/advisories/unreviewed/2024/07/GHSA-2jh9-8qjc-9f2q/GHSA-2jh9-8qjc-9f2q.json +++ b/advisories/unreviewed/2024/07/GHSA-2jh9-8qjc-9f2q/GHSA-2jh9-8qjc-9f2q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2mx5-rvwp-q23x/GHSA-2mx5-rvwp-q23x.json b/advisories/unreviewed/2024/07/GHSA-2mx5-rvwp-q23x/GHSA-2mx5-rvwp-q23x.json index a25fd74c7ad..630c89d8c44 100644 --- a/advisories/unreviewed/2024/07/GHSA-2mx5-rvwp-q23x/GHSA-2mx5-rvwp-q23x.json +++ b/advisories/unreviewed/2024/07/GHSA-2mx5-rvwp-q23x/GHSA-2mx5-rvwp-q23x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2vh5-8cw9-qhj3/GHSA-2vh5-8cw9-qhj3.json b/advisories/unreviewed/2024/07/GHSA-2vh5-8cw9-qhj3/GHSA-2vh5-8cw9-qhj3.json index 578369313b2..3b51ea3c1d5 100644 --- a/advisories/unreviewed/2024/07/GHSA-2vh5-8cw9-qhj3/GHSA-2vh5-8cw9-qhj3.json +++ b/advisories/unreviewed/2024/07/GHSA-2vh5-8cw9-qhj3/GHSA-2vh5-8cw9-qhj3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2x77-g6vw-wxgr/GHSA-2x77-g6vw-wxgr.json b/advisories/unreviewed/2024/07/GHSA-2x77-g6vw-wxgr/GHSA-2x77-g6vw-wxgr.json index 47a3770e4d7..3f31b490333 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x77-g6vw-wxgr/GHSA-2x77-g6vw-wxgr.json +++ b/advisories/unreviewed/2024/07/GHSA-2x77-g6vw-wxgr/GHSA-2x77-g6vw-wxgr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-322j-cfcv-3q95/GHSA-322j-cfcv-3q95.json b/advisories/unreviewed/2024/07/GHSA-322j-cfcv-3q95/GHSA-322j-cfcv-3q95.json index cfae81fba2e..de0d85c47fc 100644 --- a/advisories/unreviewed/2024/07/GHSA-322j-cfcv-3q95/GHSA-322j-cfcv-3q95.json +++ b/advisories/unreviewed/2024/07/GHSA-322j-cfcv-3q95/GHSA-322j-cfcv-3q95.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-3c73-87fp-87pp/GHSA-3c73-87fp-87pp.json b/advisories/unreviewed/2024/07/GHSA-3c73-87fp-87pp/GHSA-3c73-87fp-87pp.json index b41fc369f9b..09e1bfe02c7 100644 --- a/advisories/unreviewed/2024/07/GHSA-3c73-87fp-87pp/GHSA-3c73-87fp-87pp.json +++ b/advisories/unreviewed/2024/07/GHSA-3c73-87fp-87pp/GHSA-3c73-87fp-87pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-43qr-7pjx-rp3v/GHSA-43qr-7pjx-rp3v.json b/advisories/unreviewed/2024/07/GHSA-43qr-7pjx-rp3v/GHSA-43qr-7pjx-rp3v.json index 5e18c0302db..f9781b8d028 100644 --- a/advisories/unreviewed/2024/07/GHSA-43qr-7pjx-rp3v/GHSA-43qr-7pjx-rp3v.json +++ b/advisories/unreviewed/2024/07/GHSA-43qr-7pjx-rp3v/GHSA-43qr-7pjx-rp3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-47mw-6wvv-9mwc/GHSA-47mw-6wvv-9mwc.json b/advisories/unreviewed/2024/07/GHSA-47mw-6wvv-9mwc/GHSA-47mw-6wvv-9mwc.json index 897cc212cf4..7cc285f5f0a 100644 --- a/advisories/unreviewed/2024/07/GHSA-47mw-6wvv-9mwc/GHSA-47mw-6wvv-9mwc.json +++ b/advisories/unreviewed/2024/07/GHSA-47mw-6wvv-9mwc/GHSA-47mw-6wvv-9mwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-4r5f-q294-8gxm/GHSA-4r5f-q294-8gxm.json b/advisories/unreviewed/2024/07/GHSA-4r5f-q294-8gxm/GHSA-4r5f-q294-8gxm.json index 000b9badfef..a0eb77c726a 100644 --- a/advisories/unreviewed/2024/07/GHSA-4r5f-q294-8gxm/GHSA-4r5f-q294-8gxm.json +++ b/advisories/unreviewed/2024/07/GHSA-4r5f-q294-8gxm/GHSA-4r5f-q294-8gxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-4xhw-j298-f2jr/GHSA-4xhw-j298-f2jr.json b/advisories/unreviewed/2024/07/GHSA-4xhw-j298-f2jr/GHSA-4xhw-j298-f2jr.json index b0933352dec..1c1a92d7c42 100644 --- a/advisories/unreviewed/2024/07/GHSA-4xhw-j298-f2jr/GHSA-4xhw-j298-f2jr.json +++ b/advisories/unreviewed/2024/07/GHSA-4xhw-j298-f2jr/GHSA-4xhw-j298-f2jr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-5pxw-5627-vff9/GHSA-5pxw-5627-vff9.json b/advisories/unreviewed/2024/07/GHSA-5pxw-5627-vff9/GHSA-5pxw-5627-vff9.json index 7c0e4a60922..ec3fa9e41ed 100644 --- a/advisories/unreviewed/2024/07/GHSA-5pxw-5627-vff9/GHSA-5pxw-5627-vff9.json +++ b/advisories/unreviewed/2024/07/GHSA-5pxw-5627-vff9/GHSA-5pxw-5627-vff9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-638p-9h38-r62f/GHSA-638p-9h38-r62f.json b/advisories/unreviewed/2024/07/GHSA-638p-9h38-r62f/GHSA-638p-9h38-r62f.json index a79910656a8..a3c51fbfb51 100644 --- a/advisories/unreviewed/2024/07/GHSA-638p-9h38-r62f/GHSA-638p-9h38-r62f.json +++ b/advisories/unreviewed/2024/07/GHSA-638p-9h38-r62f/GHSA-638p-9h38-r62f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-77wf-fqrm-cw5j/GHSA-77wf-fqrm-cw5j.json b/advisories/unreviewed/2024/07/GHSA-77wf-fqrm-cw5j/GHSA-77wf-fqrm-cw5j.json index 41797af2374..2b73e05477f 100644 --- a/advisories/unreviewed/2024/07/GHSA-77wf-fqrm-cw5j/GHSA-77wf-fqrm-cw5j.json +++ b/advisories/unreviewed/2024/07/GHSA-77wf-fqrm-cw5j/GHSA-77wf-fqrm-cw5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-7c38-xxmq-vp5q/GHSA-7c38-xxmq-vp5q.json b/advisories/unreviewed/2024/07/GHSA-7c38-xxmq-vp5q/GHSA-7c38-xxmq-vp5q.json index 43e36a546b0..1091a637e39 100644 --- a/advisories/unreviewed/2024/07/GHSA-7c38-xxmq-vp5q/GHSA-7c38-xxmq-vp5q.json +++ b/advisories/unreviewed/2024/07/GHSA-7c38-xxmq-vp5q/GHSA-7c38-xxmq-vp5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-7gw9-g3qq-5q97/GHSA-7gw9-g3qq-5q97.json b/advisories/unreviewed/2024/07/GHSA-7gw9-g3qq-5q97/GHSA-7gw9-g3qq-5q97.json index 16329232c15..15f8dd99cba 100644 --- a/advisories/unreviewed/2024/07/GHSA-7gw9-g3qq-5q97/GHSA-7gw9-g3qq-5q97.json +++ b/advisories/unreviewed/2024/07/GHSA-7gw9-g3qq-5q97/GHSA-7gw9-g3qq-5q97.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-7p2v-48c8-pmwc/GHSA-7p2v-48c8-pmwc.json b/advisories/unreviewed/2024/07/GHSA-7p2v-48c8-pmwc/GHSA-7p2v-48c8-pmwc.json index 1411eba6ee4..032c5f02c19 100644 --- a/advisories/unreviewed/2024/07/GHSA-7p2v-48c8-pmwc/GHSA-7p2v-48c8-pmwc.json +++ b/advisories/unreviewed/2024/07/GHSA-7p2v-48c8-pmwc/GHSA-7p2v-48c8-pmwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-7wh7-x56j-7rrv/GHSA-7wh7-x56j-7rrv.json b/advisories/unreviewed/2024/07/GHSA-7wh7-x56j-7rrv/GHSA-7wh7-x56j-7rrv.json index 2517afbb991..e80d1e606e2 100644 --- a/advisories/unreviewed/2024/07/GHSA-7wh7-x56j-7rrv/GHSA-7wh7-x56j-7rrv.json +++ b/advisories/unreviewed/2024/07/GHSA-7wh7-x56j-7rrv/GHSA-7wh7-x56j-7rrv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-95gx-prcc-xj69/GHSA-95gx-prcc-xj69.json b/advisories/unreviewed/2024/07/GHSA-95gx-prcc-xj69/GHSA-95gx-prcc-xj69.json index 79e0dedd18e..933f3c66387 100644 --- a/advisories/unreviewed/2024/07/GHSA-95gx-prcc-xj69/GHSA-95gx-prcc-xj69.json +++ b/advisories/unreviewed/2024/07/GHSA-95gx-prcc-xj69/GHSA-95gx-prcc-xj69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-c5gh-whxc-hf9p/GHSA-c5gh-whxc-hf9p.json b/advisories/unreviewed/2024/07/GHSA-c5gh-whxc-hf9p/GHSA-c5gh-whxc-hf9p.json index 5bdb22d0890..b60197e3704 100644 --- a/advisories/unreviewed/2024/07/GHSA-c5gh-whxc-hf9p/GHSA-c5gh-whxc-hf9p.json +++ b/advisories/unreviewed/2024/07/GHSA-c5gh-whxc-hf9p/GHSA-c5gh-whxc-hf9p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-fgp4-99c3-x4g4/GHSA-fgp4-99c3-x4g4.json b/advisories/unreviewed/2024/07/GHSA-fgp4-99c3-x4g4/GHSA-fgp4-99c3-x4g4.json index 4fd5635156d..e3b18d93813 100644 --- a/advisories/unreviewed/2024/07/GHSA-fgp4-99c3-x4g4/GHSA-fgp4-99c3-x4g4.json +++ b/advisories/unreviewed/2024/07/GHSA-fgp4-99c3-x4g4/GHSA-fgp4-99c3-x4g4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-fw5j-h477-4x76/GHSA-fw5j-h477-4x76.json b/advisories/unreviewed/2024/07/GHSA-fw5j-h477-4x76/GHSA-fw5j-h477-4x76.json index ac6df02abb5..39fa84575db 100644 --- a/advisories/unreviewed/2024/07/GHSA-fw5j-h477-4x76/GHSA-fw5j-h477-4x76.json +++ b/advisories/unreviewed/2024/07/GHSA-fw5j-h477-4x76/GHSA-fw5j-h477-4x76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-g57x-f29r-g9gv/GHSA-g57x-f29r-g9gv.json b/advisories/unreviewed/2024/07/GHSA-g57x-f29r-g9gv/GHSA-g57x-f29r-g9gv.json index a9b01b91057..118c3270509 100644 --- a/advisories/unreviewed/2024/07/GHSA-g57x-f29r-g9gv/GHSA-g57x-f29r-g9gv.json +++ b/advisories/unreviewed/2024/07/GHSA-g57x-f29r-g9gv/GHSA-g57x-f29r-g9gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-gh8h-m29v-xxxf/GHSA-gh8h-m29v-xxxf.json b/advisories/unreviewed/2024/07/GHSA-gh8h-m29v-xxxf/GHSA-gh8h-m29v-xxxf.json index 740f6d1707e..a91347665ed 100644 --- a/advisories/unreviewed/2024/07/GHSA-gh8h-m29v-xxxf/GHSA-gh8h-m29v-xxxf.json +++ b/advisories/unreviewed/2024/07/GHSA-gh8h-m29v-xxxf/GHSA-gh8h-m29v-xxxf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-h332-g3fr-x4pf/GHSA-h332-g3fr-x4pf.json b/advisories/unreviewed/2024/07/GHSA-h332-g3fr-x4pf/GHSA-h332-g3fr-x4pf.json index 17f13245cd0..6a2cddf8fa8 100644 --- a/advisories/unreviewed/2024/07/GHSA-h332-g3fr-x4pf/GHSA-h332-g3fr-x4pf.json +++ b/advisories/unreviewed/2024/07/GHSA-h332-g3fr-x4pf/GHSA-h332-g3fr-x4pf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-hg8c-6p2v-p3vw/GHSA-hg8c-6p2v-p3vw.json b/advisories/unreviewed/2024/07/GHSA-hg8c-6p2v-p3vw/GHSA-hg8c-6p2v-p3vw.json index d628bb8bece..e149ce47fa5 100644 --- a/advisories/unreviewed/2024/07/GHSA-hg8c-6p2v-p3vw/GHSA-hg8c-6p2v-p3vw.json +++ b/advisories/unreviewed/2024/07/GHSA-hg8c-6p2v-p3vw/GHSA-hg8c-6p2v-p3vw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-hjpm-vq95-vrqg/GHSA-hjpm-vq95-vrqg.json b/advisories/unreviewed/2024/07/GHSA-hjpm-vq95-vrqg/GHSA-hjpm-vq95-vrqg.json index 8d4334330d8..92352996784 100644 --- a/advisories/unreviewed/2024/07/GHSA-hjpm-vq95-vrqg/GHSA-hjpm-vq95-vrqg.json +++ b/advisories/unreviewed/2024/07/GHSA-hjpm-vq95-vrqg/GHSA-hjpm-vq95-vrqg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-m2rg-fx69-8xcm/GHSA-m2rg-fx69-8xcm.json b/advisories/unreviewed/2024/07/GHSA-m2rg-fx69-8xcm/GHSA-m2rg-fx69-8xcm.json index e65f1995f73..a972c9f9acf 100644 --- a/advisories/unreviewed/2024/07/GHSA-m2rg-fx69-8xcm/GHSA-m2rg-fx69-8xcm.json +++ b/advisories/unreviewed/2024/07/GHSA-m2rg-fx69-8xcm/GHSA-m2rg-fx69-8xcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-mq87-5qcr-hvqj/GHSA-mq87-5qcr-hvqj.json b/advisories/unreviewed/2024/07/GHSA-mq87-5qcr-hvqj/GHSA-mq87-5qcr-hvqj.json index f930c275bf9..d7de8b3122b 100644 --- a/advisories/unreviewed/2024/07/GHSA-mq87-5qcr-hvqj/GHSA-mq87-5qcr-hvqj.json +++ b/advisories/unreviewed/2024/07/GHSA-mq87-5qcr-hvqj/GHSA-mq87-5qcr-hvqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-pcgf-phm5-g292/GHSA-pcgf-phm5-g292.json b/advisories/unreviewed/2024/07/GHSA-pcgf-phm5-g292/GHSA-pcgf-phm5-g292.json index c1d0946d046..35131bff8ef 100644 --- a/advisories/unreviewed/2024/07/GHSA-pcgf-phm5-g292/GHSA-pcgf-phm5-g292.json +++ b/advisories/unreviewed/2024/07/GHSA-pcgf-phm5-g292/GHSA-pcgf-phm5-g292.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-pg44-5crw-w36x/GHSA-pg44-5crw-w36x.json b/advisories/unreviewed/2024/07/GHSA-pg44-5crw-w36x/GHSA-pg44-5crw-w36x.json index b0c5ac403ad..d58d88f60f6 100644 --- a/advisories/unreviewed/2024/07/GHSA-pg44-5crw-w36x/GHSA-pg44-5crw-w36x.json +++ b/advisories/unreviewed/2024/07/GHSA-pg44-5crw-w36x/GHSA-pg44-5crw-w36x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-ppcc-8c3j-x247/GHSA-ppcc-8c3j-x247.json b/advisories/unreviewed/2024/07/GHSA-ppcc-8c3j-x247/GHSA-ppcc-8c3j-x247.json index a8ef925c878..613e958b7b5 100644 --- a/advisories/unreviewed/2024/07/GHSA-ppcc-8c3j-x247/GHSA-ppcc-8c3j-x247.json +++ b/advisories/unreviewed/2024/07/GHSA-ppcc-8c3j-x247/GHSA-ppcc-8c3j-x247.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-qhfr-qp56-p7x5/GHSA-qhfr-qp56-p7x5.json b/advisories/unreviewed/2024/07/GHSA-qhfr-qp56-p7x5/GHSA-qhfr-qp56-p7x5.json index c40e5c02e7e..5152a820230 100644 --- a/advisories/unreviewed/2024/07/GHSA-qhfr-qp56-p7x5/GHSA-qhfr-qp56-p7x5.json +++ b/advisories/unreviewed/2024/07/GHSA-qhfr-qp56-p7x5/GHSA-qhfr-qp56-p7x5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-qv6h-284f-5rfg/GHSA-qv6h-284f-5rfg.json b/advisories/unreviewed/2024/07/GHSA-qv6h-284f-5rfg/GHSA-qv6h-284f-5rfg.json index 03ed196e95c..bae7c111c90 100644 --- a/advisories/unreviewed/2024/07/GHSA-qv6h-284f-5rfg/GHSA-qv6h-284f-5rfg.json +++ b/advisories/unreviewed/2024/07/GHSA-qv6h-284f-5rfg/GHSA-qv6h-284f-5rfg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json b/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json index 9b9564ef2c1..010c1b5805f 100644 --- a/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json +++ b/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-r42q-2ccv-h7pg/GHSA-r42q-2ccv-h7pg.json b/advisories/unreviewed/2024/07/GHSA-r42q-2ccv-h7pg/GHSA-r42q-2ccv-h7pg.json index 11674219ccc..11207c0decb 100644 --- a/advisories/unreviewed/2024/07/GHSA-r42q-2ccv-h7pg/GHSA-r42q-2ccv-h7pg.json +++ b/advisories/unreviewed/2024/07/GHSA-r42q-2ccv-h7pg/GHSA-r42q-2ccv-h7pg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-r5x2-w7xx-rrpc/GHSA-r5x2-w7xx-rrpc.json b/advisories/unreviewed/2024/07/GHSA-r5x2-w7xx-rrpc/GHSA-r5x2-w7xx-rrpc.json index e1cb6f48365..1c4902872fd 100644 --- a/advisories/unreviewed/2024/07/GHSA-r5x2-w7xx-rrpc/GHSA-r5x2-w7xx-rrpc.json +++ b/advisories/unreviewed/2024/07/GHSA-r5x2-w7xx-rrpc/GHSA-r5x2-w7xx-rrpc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-rc4x-vgmq-9jch/GHSA-rc4x-vgmq-9jch.json b/advisories/unreviewed/2024/07/GHSA-rc4x-vgmq-9jch/GHSA-rc4x-vgmq-9jch.json index f1b5ea918ff..e103b90553d 100644 --- a/advisories/unreviewed/2024/07/GHSA-rc4x-vgmq-9jch/GHSA-rc4x-vgmq-9jch.json +++ b/advisories/unreviewed/2024/07/GHSA-rc4x-vgmq-9jch/GHSA-rc4x-vgmq-9jch.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-rcwx-8xvc-26gh/GHSA-rcwx-8xvc-26gh.json b/advisories/unreviewed/2024/07/GHSA-rcwx-8xvc-26gh/GHSA-rcwx-8xvc-26gh.json index 43ae4919d57..df9adc2675a 100644 --- a/advisories/unreviewed/2024/07/GHSA-rcwx-8xvc-26gh/GHSA-rcwx-8xvc-26gh.json +++ b/advisories/unreviewed/2024/07/GHSA-rcwx-8xvc-26gh/GHSA-rcwx-8xvc-26gh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-rm5h-63rx-5j7f/GHSA-rm5h-63rx-5j7f.json b/advisories/unreviewed/2024/07/GHSA-rm5h-63rx-5j7f/GHSA-rm5h-63rx-5j7f.json index 6c7c75d228f..9fc0a8a79bd 100644 --- a/advisories/unreviewed/2024/07/GHSA-rm5h-63rx-5j7f/GHSA-rm5h-63rx-5j7f.json +++ b/advisories/unreviewed/2024/07/GHSA-rm5h-63rx-5j7f/GHSA-rm5h-63rx-5j7f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-vpr8-gfxc-fwmm/GHSA-vpr8-gfxc-fwmm.json b/advisories/unreviewed/2024/07/GHSA-vpr8-gfxc-fwmm/GHSA-vpr8-gfxc-fwmm.json index 449c3654471..2f3495d8aeb 100644 --- a/advisories/unreviewed/2024/07/GHSA-vpr8-gfxc-fwmm/GHSA-vpr8-gfxc-fwmm.json +++ b/advisories/unreviewed/2024/07/GHSA-vpr8-gfxc-fwmm/GHSA-vpr8-gfxc-fwmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-vxm8-9f5p-7wcw/GHSA-vxm8-9f5p-7wcw.json b/advisories/unreviewed/2024/07/GHSA-vxm8-9f5p-7wcw/GHSA-vxm8-9f5p-7wcw.json index 7879c4b305f..d2a2766e341 100644 --- a/advisories/unreviewed/2024/07/GHSA-vxm8-9f5p-7wcw/GHSA-vxm8-9f5p-7wcw.json +++ b/advisories/unreviewed/2024/07/GHSA-vxm8-9f5p-7wcw/GHSA-vxm8-9f5p-7wcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wf73-c9rj-g2f9/GHSA-wf73-c9rj-g2f9.json b/advisories/unreviewed/2024/07/GHSA-wf73-c9rj-g2f9/GHSA-wf73-c9rj-g2f9.json index 77c7d47102b..9141bbd9916 100644 --- a/advisories/unreviewed/2024/07/GHSA-wf73-c9rj-g2f9/GHSA-wf73-c9rj-g2f9.json +++ b/advisories/unreviewed/2024/07/GHSA-wf73-c9rj-g2f9/GHSA-wf73-c9rj-g2f9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wp4f-2cvh-fwpc/GHSA-wp4f-2cvh-fwpc.json b/advisories/unreviewed/2024/07/GHSA-wp4f-2cvh-fwpc/GHSA-wp4f-2cvh-fwpc.json index 9995676d131..a4c2497d510 100644 --- a/advisories/unreviewed/2024/07/GHSA-wp4f-2cvh-fwpc/GHSA-wp4f-2cvh-fwpc.json +++ b/advisories/unreviewed/2024/07/GHSA-wp4f-2cvh-fwpc/GHSA-wp4f-2cvh-fwpc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wp4p-9qfg-737p/GHSA-wp4p-9qfg-737p.json b/advisories/unreviewed/2024/07/GHSA-wp4p-9qfg-737p/GHSA-wp4p-9qfg-737p.json index a0af5d7c68e..9dabaa60bbb 100644 --- a/advisories/unreviewed/2024/07/GHSA-wp4p-9qfg-737p/GHSA-wp4p-9qfg-737p.json +++ b/advisories/unreviewed/2024/07/GHSA-wp4p-9qfg-737p/GHSA-wp4p-9qfg-737p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wqw5-3mgq-446w/GHSA-wqw5-3mgq-446w.json b/advisories/unreviewed/2024/07/GHSA-wqw5-3mgq-446w/GHSA-wqw5-3mgq-446w.json index 6afb0811b6d..d382b23d619 100644 --- a/advisories/unreviewed/2024/07/GHSA-wqw5-3mgq-446w/GHSA-wqw5-3mgq-446w.json +++ b/advisories/unreviewed/2024/07/GHSA-wqw5-3mgq-446w/GHSA-wqw5-3mgq-446w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wvf7-262j-g8m8/GHSA-wvf7-262j-g8m8.json b/advisories/unreviewed/2024/07/GHSA-wvf7-262j-g8m8/GHSA-wvf7-262j-g8m8.json index d1f0570a3e4..d0006b53603 100644 --- a/advisories/unreviewed/2024/07/GHSA-wvf7-262j-g8m8/GHSA-wvf7-262j-g8m8.json +++ b/advisories/unreviewed/2024/07/GHSA-wvf7-262j-g8m8/GHSA-wvf7-262j-g8m8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-wxrv-qfwq-9wqq/GHSA-wxrv-qfwq-9wqq.json b/advisories/unreviewed/2024/07/GHSA-wxrv-qfwq-9wqq/GHSA-wxrv-qfwq-9wqq.json index d0662241866..ee13600c905 100644 --- a/advisories/unreviewed/2024/07/GHSA-wxrv-qfwq-9wqq/GHSA-wxrv-qfwq-9wqq.json +++ b/advisories/unreviewed/2024/07/GHSA-wxrv-qfwq-9wqq/GHSA-wxrv-qfwq-9wqq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-x2v6-734p-pjc6/GHSA-x2v6-734p-pjc6.json b/advisories/unreviewed/2024/07/GHSA-x2v6-734p-pjc6/GHSA-x2v6-734p-pjc6.json index c4a95927f71..fe8ac527185 100644 --- a/advisories/unreviewed/2024/07/GHSA-x2v6-734p-pjc6/GHSA-x2v6-734p-pjc6.json +++ b/advisories/unreviewed/2024/07/GHSA-x2v6-734p-pjc6/GHSA-x2v6-734p-pjc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-xvc4-h3h9-rjwx/GHSA-xvc4-h3h9-rjwx.json b/advisories/unreviewed/2024/07/GHSA-xvc4-h3h9-rjwx/GHSA-xvc4-h3h9-rjwx.json index 2b5979b31a3..247cbf8c988 100644 --- a/advisories/unreviewed/2024/07/GHSA-xvc4-h3h9-rjwx/GHSA-xvc4-h3h9-rjwx.json +++ b/advisories/unreviewed/2024/07/GHSA-xvc4-h3h9-rjwx/GHSA-xvc4-h3h9-rjwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",