From aac9def1d29ea682f9aebf3c35bfc6e482ce1b14 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 28 Nov 2024 05:08:37 +0000 Subject: [PATCH] Advisory Database Sync --- .../04/GHSA-wm2r-rp98-8pmh/GHSA-wm2r-rp98-8pmh.json | 8 ++------ .../05/GHSA-2x55-mg9r-24f7/GHSA-2x55-mg9r-24f7.json | 4 +--- .../10/GHSA-4m5p-5w5w-3jcf/GHSA-4m5p-5w5w-3jcf.json | 8 ++------ .../01/GHSA-vm74-j4wq-82xj/GHSA-vm74-j4wq-82xj.json | 4 +--- .../09/GHSA-7x4w-cj9r-h4v9/GHSA-7x4w-cj9r-h4v9.json | 4 +--- .../09/GHSA-jhg6-6qrx-38mr/GHSA-jhg6-6qrx-38mr.json | 4 ++-- .../09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json | 4 ++-- .../09/GHSA-r95w-889q-x2gx/GHSA-r95w-889q-x2gx.json | 4 ++-- .../09/GHSA-r9cr-qmfw-pmrc/GHSA-r9cr-qmfw-pmrc.json | 4 +--- .../10/GHSA-wwcp-26wc-3fxm/GHSA-wwcp-26wc-3fxm.json | 4 +--- .../11/GHSA-vjmm-r9gg-425m/GHSA-vjmm-r9gg-425m.json | 4 +--- .../12/GHSA-fcp5-xgmc-3mgm/GHSA-fcp5-xgmc-3mgm.json | 4 +--- .../12/GHSA-hcc9-4397-fcwc/GHSA-hcc9-4397-fcwc.json | 4 +--- .../02/GHSA-fv2j-f74f-8cgr/GHSA-fv2j-f74f-8cgr.json | 4 +--- .../03/GHSA-cg79-xxvp-6224/GHSA-cg79-xxvp-6224.json | 4 +--- .../04/GHSA-268w-8v2j-mm3q/GHSA-268w-8v2j-mm3q.json | 12 +++--------- .../04/GHSA-27j2-98fj-7r5w/GHSA-27j2-98fj-7r5w.json | 4 +--- .../04/GHSA-2qxr-5pf2-3p3h/GHSA-2qxr-5pf2-3p3h.json | 4 +--- .../04/GHSA-2vfm-65cj-5j48/GHSA-2vfm-65cj-5j48.json | 4 +--- .../04/GHSA-47wr-f5xm-h9x4/GHSA-47wr-f5xm-h9x4.json | 4 +--- .../04/GHSA-4cxq-fp26-wf3w/GHSA-4cxq-fp26-wf3w.json | 4 +--- .../04/GHSA-4hqp-qgvw-892g/GHSA-4hqp-qgvw-892g.json | 4 +--- .../04/GHSA-4w23-87xc-gg8q/GHSA-4w23-87xc-gg8q.json | 4 +--- .../04/GHSA-6v84-2ccf-99qx/GHSA-6v84-2ccf-99qx.json | 4 +--- .../04/GHSA-6x84-fx3m-vx33/GHSA-6x84-fx3m-vx33.json | 4 +--- .../04/GHSA-734j-8w33-h29h/GHSA-734j-8w33-h29h.json | 4 +--- .../04/GHSA-78cg-x7rx-442v/GHSA-78cg-x7rx-442v.json | 4 +--- .../04/GHSA-93jw-9wg6-48pf/GHSA-93jw-9wg6-48pf.json | 4 +--- .../04/GHSA-9j5j-gv7x-3rjf/GHSA-9j5j-gv7x-3rjf.json | 4 +--- .../04/GHSA-c2fj-f4xg-p3qr/GHSA-c2fj-f4xg-p3qr.json | 12 +++--------- .../04/GHSA-f27m-q7gr-7676/GHSA-f27m-q7gr-7676.json | 4 +--- .../04/GHSA-f4rg-w9qm-5f42/GHSA-f4rg-w9qm-5f42.json | 4 +--- .../04/GHSA-fmjf-pw3c-qpxg/GHSA-fmjf-pw3c-qpxg.json | 4 +--- .../04/GHSA-fpfj-wp86-qmrq/GHSA-fpfj-wp86-qmrq.json | 4 +--- .../04/GHSA-g9fr-9797-g6c3/GHSA-g9fr-9797-g6c3.json | 4 +--- .../04/GHSA-gc9v-rxqh-j677/GHSA-gc9v-rxqh-j677.json | 4 +--- .../04/GHSA-gx2c-m4w2-5499/GHSA-gx2c-m4w2-5499.json | 4 +--- .../04/GHSA-hgq7-cw57-j447/GHSA-hgq7-cw57-j447.json | 4 +--- .../04/GHSA-j784-xw9c-263h/GHSA-j784-xw9c-263h.json | 4 +--- .../04/GHSA-j8gx-mvv5-fx5w/GHSA-j8gx-mvv5-fx5w.json | 4 +--- .../04/GHSA-jrp8-rcj4-qwj2/GHSA-jrp8-rcj4-qwj2.json | 4 +--- .../04/GHSA-m4qj-mfxh-2v5c/GHSA-m4qj-mfxh-2v5c.json | 4 +--- .../04/GHSA-m5h3-6h9f-c785/GHSA-m5h3-6h9f-c785.json | 4 +--- .../04/GHSA-mpvv-4h9p-33x4/GHSA-mpvv-4h9p-33x4.json | 4 +--- .../04/GHSA-mrf8-4j8f-g2hr/GHSA-mrf8-4j8f-g2hr.json | 4 +--- .../04/GHSA-p4mq-j63q-grfw/GHSA-p4mq-j63q-grfw.json | 4 +--- .../04/GHSA-p7m9-59wp-jx9r/GHSA-p7m9-59wp-jx9r.json | 4 +--- .../04/GHSA-pp6m-h8ww-pq5r/GHSA-pp6m-h8ww-pq5r.json | 4 +--- .../04/GHSA-qr34-62c5-85qp/GHSA-qr34-62c5-85qp.json | 4 +--- .../04/GHSA-qrpm-2f6m-pf3c/GHSA-qrpm-2f6m-pf3c.json | 4 +--- .../04/GHSA-r3cc-j9xh-27gw/GHSA-r3cc-j9xh-27gw.json | 4 +--- .../04/GHSA-rv49-vc49-4rpp/GHSA-rv49-vc49-4rpp.json | 4 +--- .../04/GHSA-rxjg-q5c5-6q8f/GHSA-rxjg-q5c5-6q8f.json | 4 +--- .../04/GHSA-vhpp-73wq-mgfq/GHSA-vhpp-73wq-mgfq.json | 4 +--- .../04/GHSA-vpf5-gh59-9c93/GHSA-vpf5-gh59-9c93.json | 8 ++------ .../04/GHSA-vq7q-wrc4-2qv3/GHSA-vq7q-wrc4-2qv3.json | 12 +++--------- .../04/GHSA-vx7h-vmc2-6wp8/GHSA-vx7h-vmc2-6wp8.json | 8 ++------ .../04/GHSA-wcm4-m8qj-9r39/GHSA-wcm4-m8qj-9r39.json | 4 +--- .../04/GHSA-wv7p-48p2-xrvw/GHSA-wv7p-48p2-xrvw.json | 4 +--- .../04/GHSA-wxqh-rqgc-pfr9/GHSA-wxqh-rqgc-pfr9.json | 4 +--- .../04/GHSA-xhjm-9p9r-cp2g/GHSA-xhjm-9p9r-cp2g.json | 4 +--- .../04/GHSA-xr7v-8xc4-62vc/GHSA-xr7v-8xc4-62vc.json | 4 +--- .../05/GHSA-222g-mvfx-v2wm/GHSA-222g-mvfx-v2wm.json | 8 ++------ .../05/GHSA-22q7-qw7f-w974/GHSA-22q7-qw7f-w974.json | 8 ++------ .../05/GHSA-249q-hrhm-vgjq/GHSA-249q-hrhm-vgjq.json | 12 +++--------- .../05/GHSA-24gw-9fv3-3c2w/GHSA-24gw-9fv3-3c2w.json | 12 +++--------- .../05/GHSA-24pf-7g6m-7wcx/GHSA-24pf-7g6m-7wcx.json | 12 +++--------- .../05/GHSA-26qq-9jw6-r5h4/GHSA-26qq-9jw6-r5h4.json | 12 +++--------- .../05/GHSA-27m2-q889-735v/GHSA-27m2-q889-735v.json | 12 +++--------- .../05/GHSA-27q4-qhjq-3v56/GHSA-27q4-qhjq-3v56.json | 12 +++--------- .../05/GHSA-27q8-8p72-c44c/GHSA-27q8-8p72-c44c.json | 12 +++--------- .../05/GHSA-28j2-jrj9-6xv4/GHSA-28j2-jrj9-6xv4.json | 12 +++--------- .../05/GHSA-29g2-j2qf-h8qw/GHSA-29g2-j2qf-h8qw.json | 4 +--- .../05/GHSA-2cm3-h7wr-fg9v/GHSA-2cm3-h7wr-fg9v.json | 12 +++--------- .../05/GHSA-2f85-q754-r9h5/GHSA-2f85-q754-r9h5.json | 12 +++--------- .../05/GHSA-2hq4-6p2g-96ph/GHSA-2hq4-6p2g-96ph.json | 12 +++--------- .../05/GHSA-2jr6-2g4g-4jhj/GHSA-2jr6-2g4g-4jhj.json | 12 +++--------- .../05/GHSA-2jr7-hp8j-mvpq/GHSA-2jr7-hp8j-mvpq.json | 12 +++--------- .../05/GHSA-2jwh-f64h-x66g/GHSA-2jwh-f64h-x66g.json | 12 +++--------- .../05/GHSA-2jx7-jqgc-hgxg/GHSA-2jx7-jqgc-hgxg.json | 12 +++--------- .../05/GHSA-2m5x-jqmf-gr49/GHSA-2m5x-jqmf-gr49.json | 4 +--- .../05/GHSA-2mp2-8rhv-p755/GHSA-2mp2-8rhv-p755.json | 12 +++--------- .../05/GHSA-2pcr-jc7h-5447/GHSA-2pcr-jc7h-5447.json | 12 +++--------- .../05/GHSA-2pfw-56q4-cfv3/GHSA-2pfw-56q4-cfv3.json | 12 +++--------- .../05/GHSA-2qgp-6j4f-cwcw/GHSA-2qgp-6j4f-cwcw.json | 12 +++--------- .../05/GHSA-2v63-g4wq-72pq/GHSA-2v63-g4wq-72pq.json | 12 +++--------- .../05/GHSA-2wp7-476w-v7fh/GHSA-2wp7-476w-v7fh.json | 12 +++--------- .../05/GHSA-2x6m-qw3h-9vjw/GHSA-2x6m-qw3h-9vjw.json | 12 +++--------- .../05/GHSA-2x73-qq8h-xvxh/GHSA-2x73-qq8h-xvxh.json | 12 +++--------- .../05/GHSA-2xhj-75cm-7997/GHSA-2xhj-75cm-7997.json | 12 +++--------- .../05/GHSA-2xrc-mfj2-6vg5/GHSA-2xrc-mfj2-6vg5.json | 8 ++------ .../05/GHSA-2xrh-pxx5-48rp/GHSA-2xrh-pxx5-48rp.json | 8 ++------ .../05/GHSA-3269-hcm6-x235/GHSA-3269-hcm6-x235.json | 12 +++--------- .../05/GHSA-32f2-v4v8-76vw/GHSA-32f2-v4v8-76vw.json | 8 ++------ .../05/GHSA-33vf-v7x5-68hh/GHSA-33vf-v7x5-68hh.json | 12 +++--------- .../05/GHSA-33wp-4xj7-xwqx/GHSA-33wp-4xj7-xwqx.json | 12 +++--------- .../05/GHSA-3466-79gg-gm5r/GHSA-3466-79gg-gm5r.json | 4 +--- .../05/GHSA-3467-vmmf-hrxw/GHSA-3467-vmmf-hrxw.json | 12 +++--------- .../05/GHSA-34q3-rr2f-2gwp/GHSA-34q3-rr2f-2gwp.json | 4 +--- .../05/GHSA-356h-gg7j-mwv3/GHSA-356h-gg7j-mwv3.json | 8 ++------ .../05/GHSA-359w-ccrp-pqhg/GHSA-359w-ccrp-pqhg.json | 12 +++--------- .../05/GHSA-35fq-rqch-cg5p/GHSA-35fq-rqch-cg5p.json | 12 +++--------- .../05/GHSA-3692-hqvq-62f5/GHSA-3692-hqvq-62f5.json | 12 +++--------- .../05/GHSA-39h8-5656-9hw5/GHSA-39h8-5656-9hw5.json | 8 ++------ .../05/GHSA-3c68-5wgm-9f52/GHSA-3c68-5wgm-9f52.json | 12 +++--------- .../05/GHSA-3h75-cj34-c2gv/GHSA-3h75-cj34-c2gv.json | 12 +++--------- .../05/GHSA-3h8h-mjhw-3m3h/GHSA-3h8h-mjhw-3m3h.json | 8 ++------ .../05/GHSA-3j3f-m8pf-4gxv/GHSA-3j3f-m8pf-4gxv.json | 12 +++--------- .../05/GHSA-3jxc-895x-c94m/GHSA-3jxc-895x-c94m.json | 12 +++--------- .../05/GHSA-3m7v-3ggq-789x/GHSA-3m7v-3ggq-789x.json | 12 +++--------- .../05/GHSA-3mhh-q9gx-fwpr/GHSA-3mhh-q9gx-fwpr.json | 8 ++------ .../05/GHSA-3pgx-5h9r-2mg2/GHSA-3pgx-5h9r-2mg2.json | 12 +++--------- .../05/GHSA-3phq-67rm-2hq8/GHSA-3phq-67rm-2hq8.json | 12 +++--------- .../05/GHSA-3q76-8594-629m/GHSA-3q76-8594-629m.json | 12 +++--------- .../05/GHSA-3qc6-f467-3w44/GHSA-3qc6-f467-3w44.json | 12 +++--------- .../05/GHSA-3r42-8xcq-6f4v/GHSA-3r42-8xcq-6f4v.json | 12 +++--------- .../05/GHSA-3r7q-rhw3-rmxq/GHSA-3r7q-rhw3-rmxq.json | 12 +++--------- .../05/GHSA-3rpf-v574-x42r/GHSA-3rpf-v574-x42r.json | 8 ++------ .../05/GHSA-3vfv-q88q-85c4/GHSA-3vfv-q88q-85c4.json | 8 ++------ .../05/GHSA-3vv5-594j-w9p4/GHSA-3vv5-594j-w9p4.json | 12 +++--------- .../05/GHSA-3vwg-cxp6-wf3x/GHSA-3vwg-cxp6-wf3x.json | 12 +++--------- .../05/GHSA-3vww-prm4-rg7q/GHSA-3vww-prm4-rg7q.json | 12 +++--------- .../05/GHSA-3w65-mh9h-3g82/GHSA-3w65-mh9h-3g82.json | 8 ++------ .../05/GHSA-3wvx-cc6q-7chr/GHSA-3wvx-cc6q-7chr.json | 12 +++--------- .../05/GHSA-3xc7-8f3r-h948/GHSA-3xc7-8f3r-h948.json | 4 +--- .../05/GHSA-3xcq-2f3r-vpwr/GHSA-3xcq-2f3r-vpwr.json | 12 +++--------- .../05/GHSA-3xf3-x9jm-fgfc/GHSA-3xf3-x9jm-fgfc.json | 12 +++--------- .../05/GHSA-3xrv-3mx5-r2p6/GHSA-3xrv-3mx5-r2p6.json | 12 +++--------- .../05/GHSA-43jp-qxr7-8hf7/GHSA-43jp-qxr7-8hf7.json | 8 ++------ .../05/GHSA-447v-pq45-237q/GHSA-447v-pq45-237q.json | 12 +++--------- .../05/GHSA-44c7-rp6q-gcrh/GHSA-44c7-rp6q-gcrh.json | 12 +++--------- .../05/GHSA-456j-pp8g-p3qx/GHSA-456j-pp8g-p3qx.json | 4 +--- .../05/GHSA-467r-c55c-h73q/GHSA-467r-c55c-h73q.json | 12 +++--------- .../05/GHSA-46rx-rvqp-8rxj/GHSA-46rx-rvqp-8rxj.json | 12 +++--------- .../05/GHSA-4843-wqq7-hm2g/GHSA-4843-wqq7-hm2g.json | 12 +++--------- .../05/GHSA-48fp-w2fw-6wx7/GHSA-48fp-w2fw-6wx7.json | 12 +++--------- .../05/GHSA-48mj-hcv4-677q/GHSA-48mj-hcv4-677q.json | 12 +++--------- .../05/GHSA-495v-rjm6-p653/GHSA-495v-rjm6-p653.json | 12 +++--------- .../05/GHSA-49c3-f2f7-72vq/GHSA-49c3-f2f7-72vq.json | 12 +++--------- .../05/GHSA-49hc-qhr8-hc53/GHSA-49hc-qhr8-hc53.json | 8 ++------ .../05/GHSA-49j9-mppv-9hcj/GHSA-49j9-mppv-9hcj.json | 12 +++--------- .../05/GHSA-49jg-7gvc-2mhx/GHSA-49jg-7gvc-2mhx.json | 12 +++--------- .../05/GHSA-4c88-v3q4-r75x/GHSA-4c88-v3q4-r75x.json | 12 +++--------- .../05/GHSA-4ch8-97hr-6php/GHSA-4ch8-97hr-6php.json | 12 +++--------- .../05/GHSA-4fvh-g75j-hw4j/GHSA-4fvh-g75j-hw4j.json | 12 +++--------- .../05/GHSA-4g49-qqgp-g5cv/GHSA-4g49-qqgp-g5cv.json | 8 ++------ .../05/GHSA-4gg2-9pqf-2qqx/GHSA-4gg2-9pqf-2qqx.json | 12 +++--------- .../05/GHSA-4gj6-pp76-wxr5/GHSA-4gj6-pp76-wxr5.json | 8 ++------ .../05/GHSA-4gvp-5rhp-p6xg/GHSA-4gvp-5rhp-p6xg.json | 12 +++--------- .../05/GHSA-4h4q-q4v8-2vq3/GHSA-4h4q-q4v8-2vq3.json | 12 +++--------- .../05/GHSA-4hv9-r59c-6rwm/GHSA-4hv9-r59c-6rwm.json | 12 +++--------- .../05/GHSA-4hvc-j7g6-287c/GHSA-4hvc-j7g6-287c.json | 8 ++------ .../05/GHSA-4hxg-f64g-48jf/GHSA-4hxg-f64g-48jf.json | 12 +++--------- .../05/GHSA-4m37-jfjg-49pc/GHSA-4m37-jfjg-49pc.json | 8 ++------ .../05/GHSA-4m76-jxv9-f5pc/GHSA-4m76-jxv9-f5pc.json | 4 +--- .../05/GHSA-4pc3-99rp-r89j/GHSA-4pc3-99rp-r89j.json | 8 ++------ .../05/GHSA-4pvf-m5rq-4jwf/GHSA-4pvf-m5rq-4jwf.json | 4 +--- .../05/GHSA-4qvm-8x6x-vhwj/GHSA-4qvm-8x6x-vhwj.json | 12 +++--------- .../05/GHSA-4r86-rrx3-8x44/GHSA-4r86-rrx3-8x44.json | 4 +--- .../05/GHSA-4rfv-87fp-qxfm/GHSA-4rfv-87fp-qxfm.json | 8 ++------ .../05/GHSA-4rgc-4rc7-mg92/GHSA-4rgc-4rc7-mg92.json | 12 +++--------- .../05/GHSA-4rh7-2jj4-cgm5/GHSA-4rh7-2jj4-cgm5.json | 12 +++--------- .../05/GHSA-4rjf-927h-4fjw/GHSA-4rjf-927h-4fjw.json | 4 +--- .../05/GHSA-4rmj-jvqp-j56r/GHSA-4rmj-jvqp-j56r.json | 8 ++------ .../05/GHSA-4v29-x97x-vq7r/GHSA-4v29-x97x-vq7r.json | 8 ++------ .../05/GHSA-4v9p-4wgj-v3f6/GHSA-4v9p-4wgj-v3f6.json | 12 +++--------- .../05/GHSA-4vp4-vvrc-wvhx/GHSA-4vp4-vvrc-wvhx.json | 4 +--- .../05/GHSA-4vq3-2rwv-w7mg/GHSA-4vq3-2rwv-w7mg.json | 4 +--- .../05/GHSA-4w37-wxvx-pgmp/GHSA-4w37-wxvx-pgmp.json | 8 ++------ .../05/GHSA-4wch-cg8h-vqc6/GHSA-4wch-cg8h-vqc6.json | 4 +--- .../05/GHSA-4whf-mx4r-v53w/GHSA-4whf-mx4r-v53w.json | 8 ++------ .../05/GHSA-4wmp-vxgh-6898/GHSA-4wmp-vxgh-6898.json | 12 +++--------- .../05/GHSA-4wwx-wcpc-49m3/GHSA-4wwx-wcpc-49m3.json | 12 +++--------- .../05/GHSA-4x8v-74xf-h4g3/GHSA-4x8v-74xf-h4g3.json | 12 +++--------- .../05/GHSA-4xp3-xqhc-qc2g/GHSA-4xp3-xqhc-qc2g.json | 12 +++--------- .../05/GHSA-5295-c598-qcfh/GHSA-5295-c598-qcfh.json | 4 +--- .../05/GHSA-547c-mr84-jpm5/GHSA-547c-mr84-jpm5.json | 12 +++--------- .../05/GHSA-54x3-6856-52f3/GHSA-54x3-6856-52f3.json | 12 +++--------- .../05/GHSA-57fv-c5qh-rxvp/GHSA-57fv-c5qh-rxvp.json | 12 +++--------- .../05/GHSA-5869-5hjv-gvqp/GHSA-5869-5hjv-gvqp.json | 12 +++--------- .../05/GHSA-5889-mgfj-pp8r/GHSA-5889-mgfj-pp8r.json | 12 +++--------- .../05/GHSA-593f-7j6m-g5gq/GHSA-593f-7j6m-g5gq.json | 12 +++--------- .../05/GHSA-5f2h-r2x9-9p3v/GHSA-5f2h-r2x9-9p3v.json | 12 +++--------- .../05/GHSA-5g75-j346-c9xj/GHSA-5g75-j346-c9xj.json | 4 +--- .../05/GHSA-5gm2-9h87-hc2f/GHSA-5gm2-9h87-hc2f.json | 12 +++--------- .../05/GHSA-5h7g-3542-fw4q/GHSA-5h7g-3542-fw4q.json | 4 +--- .../05/GHSA-5jf4-jh9g-7766/GHSA-5jf4-jh9g-7766.json | 12 +++--------- .../05/GHSA-5m27-xjxh-cpq9/GHSA-5m27-xjxh-cpq9.json | 12 +++--------- .../05/GHSA-5mfp-2mj8-6gh2/GHSA-5mfp-2mj8-6gh2.json | 4 +--- .../05/GHSA-5mr2-62qq-29fg/GHSA-5mr2-62qq-29fg.json | 12 +++--------- .../05/GHSA-5mw6-ccfh-2c33/GHSA-5mw6-ccfh-2c33.json | 12 +++--------- .../05/GHSA-5pcr-82rc-g5mf/GHSA-5pcr-82rc-g5mf.json | 12 +++--------- .../05/GHSA-5pjj-3qp3-rjg3/GHSA-5pjj-3qp3-rjg3.json | 12 +++--------- .../05/GHSA-5pwx-hqqw-2m2r/GHSA-5pwx-hqqw-2m2r.json | 8 ++------ .../05/GHSA-5qwf-cc5w-wpvx/GHSA-5qwf-cc5w-wpvx.json | 12 +++--------- .../05/GHSA-5v5p-mmf9-j38j/GHSA-5v5p-mmf9-j38j.json | 12 +++--------- .../05/GHSA-5x59-c34p-cff9/GHSA-5x59-c34p-cff9.json | 12 +++--------- .../05/GHSA-6283-q875-5qpp/GHSA-6283-q875-5qpp.json | 4 +--- .../05/GHSA-62cc-g9f4-2r2g/GHSA-62cc-g9f4-2r2g.json | 12 +++--------- .../05/GHSA-645m-h3pw-m72w/GHSA-645m-h3pw-m72w.json | 12 +++--------- .../05/GHSA-6484-844c-qmh4/GHSA-6484-844c-qmh4.json | 8 ++------ .../05/GHSA-66ph-x3g8-qwxf/GHSA-66ph-x3g8-qwxf.json | 12 +++--------- .../05/GHSA-67rp-x49w-2277/GHSA-67rp-x49w-2277.json | 12 +++--------- .../05/GHSA-696f-85gv-7m8g/GHSA-696f-85gv-7m8g.json | 8 ++------ .../05/GHSA-69g2-j5hm-jq2w/GHSA-69g2-j5hm-jq2w.json | 12 +++--------- .../05/GHSA-69xv-rvvx-vm7w/GHSA-69xv-rvvx-vm7w.json | 8 ++------ .../05/GHSA-6cfc-j55p-2wvq/GHSA-6cfc-j55p-2wvq.json | 12 +++--------- .../05/GHSA-6chg-8whj-347g/GHSA-6chg-8whj-347g.json | 8 ++------ .../05/GHSA-6cpv-6hfh-4qwq/GHSA-6cpv-6hfh-4qwq.json | 12 +++--------- .../05/GHSA-6f6r-4rpp-w273/GHSA-6f6r-4rpp-w273.json | 12 +++--------- .../05/GHSA-6fp6-hh92-h5q5/GHSA-6fp6-hh92-h5q5.json | 12 +++--------- .../05/GHSA-6gpv-cjwj-gqjp/GHSA-6gpv-cjwj-gqjp.json | 12 +++--------- .../05/GHSA-6hjj-3x6q-6hr7/GHSA-6hjj-3x6q-6hr7.json | 12 +++--------- .../05/GHSA-6jr9-m575-w4wm/GHSA-6jr9-m575-w4wm.json | 12 +++--------- .../05/GHSA-6m69-7x27-4x5g/GHSA-6m69-7x27-4x5g.json | 12 +++--------- .../05/GHSA-6mch-cjgm-9hwc/GHSA-6mch-cjgm-9hwc.json | 12 +++--------- .../05/GHSA-6mpr-24px-gq7m/GHSA-6mpr-24px-gq7m.json | 4 +--- .../05/GHSA-6q44-g7gx-xp5f/GHSA-6q44-g7gx-xp5f.json | 12 +++--------- .../05/GHSA-6q4w-wc77-4rq6/GHSA-6q4w-wc77-4rq6.json | 4 +--- .../05/GHSA-6r3m-wrp5-v5m2/GHSA-6r3m-wrp5-v5m2.json | 12 +++--------- .../05/GHSA-6rqc-949w-3mj8/GHSA-6rqc-949w-3mj8.json | 12 +++--------- .../05/GHSA-6rrw-8mq7-2wvv/GHSA-6rrw-8mq7-2wvv.json | 12 +++--------- .../05/GHSA-6v85-6qpj-f798/GHSA-6v85-6qpj-f798.json | 12 +++--------- .../05/GHSA-6vxc-97r3-3qmp/GHSA-6vxc-97r3-3qmp.json | 8 ++------ .../05/GHSA-6w3p-7vr4-75hx/GHSA-6w3p-7vr4-75hx.json | 12 +++--------- .../05/GHSA-6xpc-pxw7-qhg3/GHSA-6xpc-pxw7-qhg3.json | 12 +++--------- .../05/GHSA-73g7-p5mh-vr2v/GHSA-73g7-p5mh-vr2v.json | 12 +++--------- .../05/GHSA-73q6-p6x5-9wrv/GHSA-73q6-p6x5-9wrv.json | 12 +++--------- .../05/GHSA-7426-cf9r-3rp5/GHSA-7426-cf9r-3rp5.json | 12 +++--------- .../05/GHSA-747q-6mj3-hj66/GHSA-747q-6mj3-hj66.json | 12 +++--------- .../05/GHSA-748x-8hcr-xg9h/GHSA-748x-8hcr-xg9h.json | 12 +++--------- .../05/GHSA-75vm-6gpr-f398/GHSA-75vm-6gpr-f398.json | 12 +++--------- .../05/GHSA-75xv-qqv2-qh22/GHSA-75xv-qqv2-qh22.json | 12 +++--------- .../05/GHSA-76c7-jr49-pvm9/GHSA-76c7-jr49-pvm9.json | 12 +++--------- .../05/GHSA-76fq-c73c-746h/GHSA-76fq-c73c-746h.json | 12 +++--------- .../05/GHSA-76h5-j8hw-99ch/GHSA-76h5-j8hw-99ch.json | 8 ++------ .../05/GHSA-76p7-xgvr-6gqw/GHSA-76p7-xgvr-6gqw.json | 12 +++--------- .../05/GHSA-77x2-39gg-vv6g/GHSA-77x2-39gg-vv6g.json | 12 +++--------- .../05/GHSA-79gj-xgq6-77vj/GHSA-79gj-xgq6-77vj.json | 12 +++--------- .../05/GHSA-79jw-wrqv-5vh6/GHSA-79jw-wrqv-5vh6.json | 8 ++------ .../05/GHSA-79q9-8ff3-x4g2/GHSA-79q9-8ff3-x4g2.json | 12 +++--------- .../05/GHSA-79rx-rpqc-99fp/GHSA-79rx-rpqc-99fp.json | 12 +++--------- .../05/GHSA-7cjv-794c-2mcw/GHSA-7cjv-794c-2mcw.json | 12 +++--------- .../05/GHSA-7f7c-fgq4-x53w/GHSA-7f7c-fgq4-x53w.json | 12 +++--------- .../05/GHSA-7f9m-x89m-cpp8/GHSA-7f9m-x89m-cpp8.json | 12 +++--------- .../05/GHSA-7fcj-v5v7-gm5g/GHSA-7fcj-v5v7-gm5g.json | 4 +--- .../05/GHSA-7g6p-9397-6cfc/GHSA-7g6p-9397-6cfc.json | 12 +++--------- .../05/GHSA-7hjv-846h-7wvc/GHSA-7hjv-846h-7wvc.json | 12 +++--------- .../05/GHSA-7hpx-p47p-jpq5/GHSA-7hpx-p47p-jpq5.json | 8 ++------ .../05/GHSA-7m84-qcqm-rgjv/GHSA-7m84-qcqm-rgjv.json | 12 +++--------- .../05/GHSA-7mqg-g2q4-78m2/GHSA-7mqg-g2q4-78m2.json | 12 +++--------- .../05/GHSA-7p3p-c3r9-hpgr/GHSA-7p3p-c3r9-hpgr.json | 12 +++--------- .../05/GHSA-7r2v-6w5p-52wm/GHSA-7r2v-6w5p-52wm.json | 12 +++--------- .../05/GHSA-7r52-mq4x-j9xf/GHSA-7r52-mq4x-j9xf.json | 12 +++--------- .../05/GHSA-7rq6-hg5q-vcx9/GHSA-7rq6-hg5q-vcx9.json | 4 +--- .../05/GHSA-7rx2-8574-5qv6/GHSA-7rx2-8574-5qv6.json | 12 +++--------- .../05/GHSA-7wcc-2hfr-r5m7/GHSA-7wcc-2hfr-r5m7.json | 12 +++--------- .../05/GHSA-7x4q-26xj-gjr7/GHSA-7x4q-26xj-gjr7.json | 12 +++--------- .../05/GHSA-822x-846c-2c22/GHSA-822x-846c-2c22.json | 12 +++--------- .../05/GHSA-83f7-7p5p-3hxm/GHSA-83f7-7p5p-3hxm.json | 8 ++------ .../05/GHSA-858h-9hh5-fvx2/GHSA-858h-9hh5-fvx2.json | 12 +++--------- .../05/GHSA-872v-39hw-4fr3/GHSA-872v-39hw-4fr3.json | 12 +++--------- .../05/GHSA-8746-f7wh-cvv9/GHSA-8746-f7wh-cvv9.json | 12 +++--------- .../05/GHSA-87g6-m6v4-rm4w/GHSA-87g6-m6v4-rm4w.json | 8 ++------ .../05/GHSA-87hj-px7p-jhf4/GHSA-87hj-px7p-jhf4.json | 12 +++--------- .../05/GHSA-87q2-rr35-r6c9/GHSA-87q2-rr35-r6c9.json | 12 +++--------- .../05/GHSA-89q8-rgqc-jpf8/GHSA-89q8-rgqc-jpf8.json | 12 +++--------- .../05/GHSA-8c6q-359m-h9qj/GHSA-8c6q-359m-h9qj.json | 8 ++------ .../05/GHSA-8cjc-5jv5-fj8c/GHSA-8cjc-5jv5-fj8c.json | 8 ++------ .../05/GHSA-8fcf-mp2j-j4w9/GHSA-8fcf-mp2j-j4w9.json | 4 +--- .../05/GHSA-8fgw-hcmw-fvqp/GHSA-8fgw-hcmw-fvqp.json | 4 +--- .../05/GHSA-8h2m-rx7g-r9gv/GHSA-8h2m-rx7g-r9gv.json | 8 ++------ .../05/GHSA-8j5m-96p7-j6g4/GHSA-8j5m-96p7-j6g4.json | 8 ++------ .../05/GHSA-8j72-4c3r-rgm9/GHSA-8j72-4c3r-rgm9.json | 8 ++------ .../05/GHSA-8jfm-678p-xw3j/GHSA-8jfm-678p-xw3j.json | 12 +++--------- .../05/GHSA-8mgg-gfxm-vwwc/GHSA-8mgg-gfxm-vwwc.json | 12 +++--------- .../05/GHSA-8mw2-4xfj-9rvq/GHSA-8mw2-4xfj-9rvq.json | 12 +++--------- .../05/GHSA-8p6h-pm5c-4w65/GHSA-8p6h-pm5c-4w65.json | 12 +++--------- .../05/GHSA-8p79-fcr2-m563/GHSA-8p79-fcr2-m563.json | 12 +++--------- .../05/GHSA-8pmp-qg97-8gmp/GHSA-8pmp-qg97-8gmp.json | 12 +++--------- .../05/GHSA-8qpr-v8hf-4323/GHSA-8qpr-v8hf-4323.json | 12 +++--------- .../05/GHSA-8rgw-25fw-5m5f/GHSA-8rgw-25fw-5m5f.json | 12 +++--------- .../05/GHSA-8v3p-6p83-784h/GHSA-8v3p-6p83-784h.json | 12 +++--------- .../05/GHSA-8v4x-g74w-cgg6/GHSA-8v4x-g74w-cgg6.json | 4 +--- .../05/GHSA-8vh5-q8fh-cmgp/GHSA-8vh5-q8fh-cmgp.json | 8 ++------ .../05/GHSA-8xpf-4773-x7fx/GHSA-8xpf-4773-x7fx.json | 12 +++--------- .../05/GHSA-92gq-cfj6-292h/GHSA-92gq-cfj6-292h.json | 12 +++--------- .../05/GHSA-932q-p83p-pj88/GHSA-932q-p83p-pj88.json | 12 +++--------- .../05/GHSA-93c5-v3v3-mpq3/GHSA-93c5-v3v3-mpq3.json | 4 +--- .../05/GHSA-94mg-mhw8-cfh2/GHSA-94mg-mhw8-cfh2.json | 12 +++--------- .../05/GHSA-964w-hfj4-c2g7/GHSA-964w-hfj4-c2g7.json | 12 +++--------- .../05/GHSA-96h9-3p6v-cqh2/GHSA-96h9-3p6v-cqh2.json | 4 +--- .../05/GHSA-96mw-vj87-32x5/GHSA-96mw-vj87-32x5.json | 8 ++------ .../05/GHSA-9743-23p2-9v8j/GHSA-9743-23p2-9v8j.json | 12 +++--------- .../05/GHSA-988j-mg6c-jcwh/GHSA-988j-mg6c-jcwh.json | 8 ++------ .../05/GHSA-98rw-w9v5-5j4m/GHSA-98rw-w9v5-5j4m.json | 12 +++--------- .../05/GHSA-997h-jrc2-j4f2/GHSA-997h-jrc2-j4f2.json | 8 ++------ .../05/GHSA-99gq-h68r-v2g7/GHSA-99gq-h68r-v2g7.json | 12 +++--------- .../05/GHSA-99jc-7925-7fc9/GHSA-99jc-7925-7fc9.json | 12 +++--------- .../05/GHSA-99vq-f459-jqrg/GHSA-99vq-f459-jqrg.json | 8 ++------ .../05/GHSA-99x7-636q-6hvj/GHSA-99x7-636q-6hvj.json | 12 +++--------- .../05/GHSA-9cq6-v6jc-rm85/GHSA-9cq6-v6jc-rm85.json | 12 +++--------- .../05/GHSA-9hj8-x5gx-9x3m/GHSA-9hj8-x5gx-9x3m.json | 12 +++--------- .../05/GHSA-9jw2-j35c-pjxc/GHSA-9jw2-j35c-pjxc.json | 12 +++--------- .../05/GHSA-9jwp-7vxc-w3x4/GHSA-9jwp-7vxc-w3x4.json | 4 +--- .../05/GHSA-9p75-w4p8-7gvx/GHSA-9p75-w4p8-7gvx.json | 4 +--- .../05/GHSA-9p96-p3x8-3838/GHSA-9p96-p3x8-3838.json | 12 +++--------- .../05/GHSA-9pm5-94qv-mm9q/GHSA-9pm5-94qv-mm9q.json | 12 +++--------- .../05/GHSA-9ppr-4hfx-mxgv/GHSA-9ppr-4hfx-mxgv.json | 12 +++--------- .../05/GHSA-9q2r-wcv4-qhr6/GHSA-9q2r-wcv4-qhr6.json | 12 +++--------- .../05/GHSA-9qj8-pjmh-gjc2/GHSA-9qj8-pjmh-gjc2.json | 8 ++------ .../05/GHSA-9qx7-c7pp-jxg6/GHSA-9qx7-c7pp-jxg6.json | 12 +++--------- .../05/GHSA-9w36-332v-p26x/GHSA-9w36-332v-p26x.json | 12 +++--------- .../05/GHSA-9xxv-5cr7-5gvp/GHSA-9xxv-5cr7-5gvp.json | 12 +++--------- .../05/GHSA-c277-639g-8944/GHSA-c277-639g-8944.json | 12 +++--------- .../05/GHSA-c4hf-6r23-8vgr/GHSA-c4hf-6r23-8vgr.json | 12 +++--------- .../05/GHSA-c59r-gh79-pmcm/GHSA-c59r-gh79-pmcm.json | 12 +++--------- .../05/GHSA-c5pc-gqv9-5rj6/GHSA-c5pc-gqv9-5rj6.json | 12 +++--------- .../05/GHSA-c5pq-336c-xh85/GHSA-c5pq-336c-xh85.json | 12 +++--------- .../05/GHSA-c6pw-c5gr-43f6/GHSA-c6pw-c5gr-43f6.json | 12 +++--------- .../05/GHSA-c82r-7mc6-9j7g/GHSA-c82r-7mc6-9j7g.json | 8 ++------ .../05/GHSA-c9j5-mrjc-hx8m/GHSA-c9j5-mrjc-hx8m.json | 4 +--- .../05/GHSA-c9p4-g3wp-gpxv/GHSA-c9p4-g3wp-gpxv.json | 8 ++------ .../05/GHSA-ch35-w937-rw95/GHSA-ch35-w937-rw95.json | 12 +++--------- .../05/GHSA-ch82-rwfx-hg86/GHSA-ch82-rwfx-hg86.json | 12 +++--------- .../05/GHSA-cj4c-7qch-h3mh/GHSA-cj4c-7qch-h3mh.json | 12 +++--------- .../05/GHSA-cm5h-jfjm-77x3/GHSA-cm5h-jfjm-77x3.json | 8 ++------ .../05/GHSA-cpv8-8r69-g4p6/GHSA-cpv8-8r69-g4p6.json | 8 ++------ .../05/GHSA-cq4h-jg73-mw34/GHSA-cq4h-jg73-mw34.json | 12 +++--------- .../05/GHSA-cq4q-7wp3-54j3/GHSA-cq4q-7wp3-54j3.json | 12 +++--------- .../05/GHSA-cq96-jp34-7gj8/GHSA-cq96-jp34-7gj8.json | 12 +++--------- .../05/GHSA-cqv9-cwr5-p6j4/GHSA-cqv9-cwr5-p6j4.json | 8 ++------ .../05/GHSA-cvgx-pvwp-mq8w/GHSA-cvgx-pvwp-mq8w.json | 8 ++------ .../05/GHSA-cvqp-x8wc-59j8/GHSA-cvqp-x8wc-59j8.json | 12 +++--------- .../05/GHSA-f268-9fq5-h8qf/GHSA-f268-9fq5-h8qf.json | 12 +++--------- .../05/GHSA-f3r5-9r3j-243r/GHSA-f3r5-9r3j-243r.json | 8 ++------ .../05/GHSA-f438-7fwh-rhhq/GHSA-f438-7fwh-rhhq.json | 12 +++--------- .../05/GHSA-f47q-w692-63wj/GHSA-f47q-w692-63wj.json | 12 +++--------- .../05/GHSA-f4hc-mjp6-wmcp/GHSA-f4hc-mjp6-wmcp.json | 8 ++------ .../05/GHSA-f5hx-6pcp-xgp3/GHSA-f5hx-6pcp-xgp3.json | 8 ++------ .../05/GHSA-f63f-3434-4v3m/GHSA-f63f-3434-4v3m.json | 8 ++------ .../05/GHSA-f6pq-354j-4f2p/GHSA-f6pq-354j-4f2p.json | 12 +++--------- .../05/GHSA-f8vw-827h-ffmp/GHSA-f8vw-827h-ffmp.json | 12 +++--------- .../05/GHSA-fc49-wm87-9q8m/GHSA-fc49-wm87-9q8m.json | 12 +++--------- .../05/GHSA-fg3g-4994-3829/GHSA-fg3g-4994-3829.json | 12 +++--------- .../05/GHSA-fgxx-cm7r-ghp7/GHSA-fgxx-cm7r-ghp7.json | 12 +++--------- .../05/GHSA-fr8r-x4x7-r5mv/GHSA-fr8r-x4x7-r5mv.json | 8 ++------ .../05/GHSA-frj8-cjrv-7f9q/GHSA-frj8-cjrv-7f9q.json | 4 +--- .../05/GHSA-frjv-h9wg-233r/GHSA-frjv-h9wg-233r.json | 12 +++--------- .../05/GHSA-frm6-q76c-62mx/GHSA-frm6-q76c-62mx.json | 12 +++--------- .../05/GHSA-fwgm-gxhm-fgf8/GHSA-fwgm-gxhm-fgf8.json | 12 +++--------- .../05/GHSA-fwxv-68qg-w737/GHSA-fwxv-68qg-w737.json | 8 ++------ .../05/GHSA-fxrv-qpg2-74h3/GHSA-fxrv-qpg2-74h3.json | 8 ++------ .../05/GHSA-fxvh-gv5w-rx6c/GHSA-fxvh-gv5w-rx6c.json | 4 +--- .../05/GHSA-g223-vgj2-7g9m/GHSA-g223-vgj2-7g9m.json | 12 +++--------- .../05/GHSA-g24h-qq74-84hq/GHSA-g24h-qq74-84hq.json | 12 +++--------- .../05/GHSA-g2fc-4mpm-58fg/GHSA-g2fc-4mpm-58fg.json | 12 +++--------- .../05/GHSA-g47h-wpv4-rfwf/GHSA-g47h-wpv4-rfwf.json | 12 +++--------- .../05/GHSA-g5mh-9cjj-vm5x/GHSA-g5mh-9cjj-vm5x.json | 12 +++--------- .../05/GHSA-g5x4-mhjm-x6qc/GHSA-g5x4-mhjm-x6qc.json | 8 ++------ .../05/GHSA-g624-89xp-hmx8/GHSA-g624-89xp-hmx8.json | 4 +--- .../05/GHSA-g77h-ghjv-vprw/GHSA-g77h-ghjv-vprw.json | 12 +++--------- .../05/GHSA-g83g-x6pg-6c84/GHSA-g83g-x6pg-6c84.json | 12 +++--------- .../05/GHSA-g968-q4r4-4gmq/GHSA-g968-q4r4-4gmq.json | 12 +++--------- .../05/GHSA-gf8j-j7q8-vhh5/GHSA-gf8j-j7q8-vhh5.json | 8 ++------ .../05/GHSA-gj53-2v73-4h48/GHSA-gj53-2v73-4h48.json | 12 +++--------- .../05/GHSA-gj76-9gq9-34xq/GHSA-gj76-9gq9-34xq.json | 12 +++--------- .../05/GHSA-gjgq-7qmc-vjmv/GHSA-gjgq-7qmc-vjmv.json | 8 ++------ .../05/GHSA-gjq4-c23m-6wgc/GHSA-gjq4-c23m-6wgc.json | 8 ++------ .../05/GHSA-gmhh-hvg9-g5rj/GHSA-gmhh-hvg9-g5rj.json | 12 +++--------- .../05/GHSA-gmjr-xhqw-c9qx/GHSA-gmjr-xhqw-c9qx.json | 12 +++--------- .../05/GHSA-gp9r-cv63-32fj/GHSA-gp9r-cv63-32fj.json | 12 +++--------- .../05/GHSA-gpq9-qcf2-pj58/GHSA-gpq9-qcf2-pj58.json | 8 ++------ .../05/GHSA-gpv3-wf7m-8269/GHSA-gpv3-wf7m-8269.json | 12 +++--------- .../05/GHSA-gr8p-66g9-4565/GHSA-gr8p-66g9-4565.json | 8 ++------ .../05/GHSA-gv39-q8v4-8v4w/GHSA-gv39-q8v4-8v4w.json | 12 +++--------- .../05/GHSA-gvvg-f3fg-w335/GHSA-gvvg-f3fg-w335.json | 12 +++--------- .../05/GHSA-gwm4-vr82-pwg9/GHSA-gwm4-vr82-pwg9.json | 4 +--- .../05/GHSA-gx75-66mx-pjmm/GHSA-gx75-66mx-pjmm.json | 12 +++--------- .../05/GHSA-h2hc-3hmw-fmq5/GHSA-h2hc-3hmw-fmq5.json | 4 +--- .../05/GHSA-h2w7-hfq4-7xgx/GHSA-h2w7-hfq4-7xgx.json | 8 ++------ .../05/GHSA-h34c-2r22-jc5j/GHSA-h34c-2r22-jc5j.json | 12 +++--------- .../05/GHSA-h398-v6mj-crpf/GHSA-h398-v6mj-crpf.json | 12 +++--------- .../05/GHSA-h3gx-q82j-vhq3/GHSA-h3gx-q82j-vhq3.json | 12 +++--------- .../05/GHSA-h3jq-gxm5-vhxg/GHSA-h3jq-gxm5-vhxg.json | 12 +++--------- .../05/GHSA-h4qw-99jp-7g9f/GHSA-h4qw-99jp-7g9f.json | 8 ++------ .../05/GHSA-h4vc-wv6x-gx67/GHSA-h4vc-wv6x-gx67.json | 12 +++--------- .../05/GHSA-h5m2-8pmw-gmg7/GHSA-h5m2-8pmw-gmg7.json | 4 +--- .../05/GHSA-h7c9-gjhc-27w5/GHSA-h7c9-gjhc-27w5.json | 12 +++--------- .../05/GHSA-h7m2-gw69-h6vr/GHSA-h7m2-gw69-h6vr.json | 12 +++--------- .../05/GHSA-hcmc-r7j6-4q4h/GHSA-hcmc-r7j6-4q4h.json | 12 +++--------- .../05/GHSA-hcrx-7wpm-hhwq/GHSA-hcrx-7wpm-hhwq.json | 8 ++------ .../05/GHSA-hfjc-qvjw-4cxm/GHSA-hfjc-qvjw-4cxm.json | 12 +++--------- .../05/GHSA-hgxf-cvh7-ghp4/GHSA-hgxf-cvh7-ghp4.json | 12 +++--------- .../05/GHSA-hh28-x8g4-gw96/GHSA-hh28-x8g4-gw96.json | 12 +++--------- .../05/GHSA-hh3p-v353-7rmj/GHSA-hh3p-v353-7rmj.json | 12 +++--------- .../05/GHSA-hhw9-pw8h-qc2h/GHSA-hhw9-pw8h-qc2h.json | 12 +++--------- .../05/GHSA-hj4p-qm6q-mm5m/GHSA-hj4p-qm6q-mm5m.json | 12 +++--------- .../05/GHSA-hjfg-8xqx-2vw8/GHSA-hjfg-8xqx-2vw8.json | 4 +--- .../05/GHSA-hp2p-gr52-7qp5/GHSA-hp2p-gr52-7qp5.json | 12 +++--------- .../05/GHSA-hp4h-vx4q-gj6m/GHSA-hp4h-vx4q-gj6m.json | 8 ++------ .../05/GHSA-hp8p-42mw-fvq9/GHSA-hp8p-42mw-fvq9.json | 12 +++--------- .../05/GHSA-hpg6-j356-pfwf/GHSA-hpg6-j356-pfwf.json | 12 +++--------- .../05/GHSA-hpmp-m758-4r73/GHSA-hpmp-m758-4r73.json | 4 +--- .../05/GHSA-hpxr-gm5p-rf22/GHSA-hpxr-gm5p-rf22.json | 12 +++--------- .../05/GHSA-hq45-w97p-p68r/GHSA-hq45-w97p-p68r.json | 4 +--- .../05/GHSA-hrrp-pp4j-hx63/GHSA-hrrp-pp4j-hx63.json | 12 +++--------- .../05/GHSA-hxgh-gx53-7hrw/GHSA-hxgh-gx53-7hrw.json | 4 +--- .../05/GHSA-hxq4-7jhg-m8g2/GHSA-hxq4-7jhg-m8g2.json | 4 +--- .../05/GHSA-j364-j4vw-rfhp/GHSA-j364-j4vw-rfhp.json | 12 +++--------- .../05/GHSA-j44r-m3r9-2886/GHSA-j44r-m3r9-2886.json | 12 +++--------- .../05/GHSA-j46x-fxq3-h2m3/GHSA-j46x-fxq3-h2m3.json | 8 ++------ .../05/GHSA-j65x-pp5m-j68h/GHSA-j65x-pp5m-j68h.json | 12 +++--------- .../05/GHSA-j68g-j7h6-gwqw/GHSA-j68g-j7h6-gwqw.json | 12 +++--------- .../05/GHSA-j8mv-4vjx-93p6/GHSA-j8mv-4vjx-93p6.json | 12 +++--------- .../05/GHSA-jcxc-5f87-vq5m/GHSA-jcxc-5f87-vq5m.json | 4 +--- .../05/GHSA-jgrm-xfcc-mqp9/GHSA-jgrm-xfcc-mqp9.json | 8 ++------ .../05/GHSA-jhm5-r427-j4rc/GHSA-jhm5-r427-j4rc.json | 12 +++--------- .../05/GHSA-jj26-78h6-475h/GHSA-jj26-78h6-475h.json | 4 +--- .../05/GHSA-jpcf-xprw-w8hm/GHSA-jpcf-xprw-w8hm.json | 8 ++------ .../05/GHSA-jpvg-r6vh-56w3/GHSA-jpvg-r6vh-56w3.json | 12 +++--------- .../05/GHSA-jqrc-77wc-2g85/GHSA-jqrc-77wc-2g85.json | 12 +++--------- .../05/GHSA-jqv9-2w7w-rccv/GHSA-jqv9-2w7w-rccv.json | 12 +++--------- .../05/GHSA-jr5w-49p5-gc6w/GHSA-jr5w-49p5-gc6w.json | 12 +++--------- .../05/GHSA-jr83-rwfm-7r6r/GHSA-jr83-rwfm-7r6r.json | 12 +++--------- .../05/GHSA-jrjm-wgrh-4c93/GHSA-jrjm-wgrh-4c93.json | 12 +++--------- .../05/GHSA-jv99-4g95-6mj4/GHSA-jv99-4g95-6mj4.json | 12 +++--------- .../05/GHSA-jvgf-c7c2-w98p/GHSA-jvgf-c7c2-w98p.json | 12 +++--------- .../05/GHSA-jwfx-6cm3-63qg/GHSA-jwfx-6cm3-63qg.json | 8 ++------ .../05/GHSA-jx95-62jp-r768/GHSA-jx95-62jp-r768.json | 12 +++--------- .../05/GHSA-jxf7-w6gg-cgmq/GHSA-jxf7-w6gg-cgmq.json | 8 ++------ .../05/GHSA-jxhx-2gqw-c77x/GHSA-jxhx-2gqw-c77x.json | 8 ++------ .../05/GHSA-jxhx-hv9q-4x3w/GHSA-jxhx-hv9q-4x3w.json | 12 +++--------- .../05/GHSA-m38r-xwvh-x735/GHSA-m38r-xwvh-x735.json | 12 +++--------- .../05/GHSA-m4mr-53v8-pj7x/GHSA-m4mr-53v8-pj7x.json | 12 +++--------- .../05/GHSA-m5f9-h82w-xx78/GHSA-m5f9-h82w-xx78.json | 12 +++--------- .../05/GHSA-m7m3-h648-r6cc/GHSA-m7m3-h648-r6cc.json | 12 +++--------- .../05/GHSA-m866-3jrq-785c/GHSA-m866-3jrq-785c.json | 12 +++--------- .../05/GHSA-m8pg-mx2h-fq4v/GHSA-m8pg-mx2h-fq4v.json | 12 +++--------- .../05/GHSA-m9gq-jrj4-fhfv/GHSA-m9gq-jrj4-fhfv.json | 12 +++--------- .../05/GHSA-mcjf-77cw-j8r2/GHSA-mcjf-77cw-j8r2.json | 12 +++--------- .../05/GHSA-mcx8-p4qf-qr6x/GHSA-mcx8-p4qf-qr6x.json | 12 +++--------- .../05/GHSA-mf37-6gxg-hj9q/GHSA-mf37-6gxg-hj9q.json | 12 +++--------- .../05/GHSA-mf4j-c7rg-8p9r/GHSA-mf4j-c7rg-8p9r.json | 12 +++--------- .../05/GHSA-mfxc-mwgf-fr5h/GHSA-mfxc-mwgf-fr5h.json | 12 +++--------- .../05/GHSA-mgg3-mrhh-rr8r/GHSA-mgg3-mrhh-rr8r.json | 12 +++--------- .../05/GHSA-mgvp-4j7j-cjr2/GHSA-mgvp-4j7j-cjr2.json | 12 +++--------- .../05/GHSA-mh77-9rrc-963m/GHSA-mh77-9rrc-963m.json | 12 +++--------- .../05/GHSA-mj5f-wfm2-8fw6/GHSA-mj5f-wfm2-8fw6.json | 12 +++--------- .../05/GHSA-mjcp-8594-qxpc/GHSA-mjcp-8594-qxpc.json | 12 +++--------- .../05/GHSA-mm5m-g4fx-pch2/GHSA-mm5m-g4fx-pch2.json | 4 +--- .../05/GHSA-mph2-w5gr-qrv5/GHSA-mph2-w5gr-qrv5.json | 12 +++--------- .../05/GHSA-mpp8-3fhh-c8rg/GHSA-mpp8-3fhh-c8rg.json | 8 ++------ .../05/GHSA-mpww-gpm7-w7qg/GHSA-mpww-gpm7-w7qg.json | 12 +++--------- .../05/GHSA-mq78-57jv-92wc/GHSA-mq78-57jv-92wc.json | 12 +++--------- .../05/GHSA-mqfh-r3g8-g7vm/GHSA-mqfh-r3g8-g7vm.json | 12 +++--------- .../05/GHSA-mrp2-f622-9548/GHSA-mrp2-f622-9548.json | 12 +++--------- .../05/GHSA-mrq8-9564-r9gh/GHSA-mrq8-9564-r9gh.json | 8 ++------ .../05/GHSA-mv96-qwpc-6552/GHSA-mv96-qwpc-6552.json | 12 +++--------- .../05/GHSA-mvgj-p4wx-27qf/GHSA-mvgj-p4wx-27qf.json | 12 +++--------- .../05/GHSA-mw9v-9fv9-jf3f/GHSA-mw9v-9fv9-jf3f.json | 12 +++--------- .../05/GHSA-mwgw-gwjh-gp7m/GHSA-mwgw-gwjh-gp7m.json | 12 +++--------- .../05/GHSA-mwpm-ch75-7qqj/GHSA-mwpm-ch75-7qqj.json | 8 ++------ .../05/GHSA-mxmq-cvc6-prfj/GHSA-mxmq-cvc6-prfj.json | 12 +++--------- .../05/GHSA-p2xr-m559-3m72/GHSA-p2xr-m559-3m72.json | 8 ++------ .../05/GHSA-p4rw-m677-p78f/GHSA-p4rw-m677-p78f.json | 12 +++--------- .../05/GHSA-p548-j649-rwfp/GHSA-p548-j649-rwfp.json | 12 +++--------- .../05/GHSA-p5cv-767r-2fpm/GHSA-p5cv-767r-2fpm.json | 12 +++--------- .../05/GHSA-p5xv-462h-xq5p/GHSA-p5xv-462h-xq5p.json | 12 +++--------- .../05/GHSA-p764-xffc-3rx4/GHSA-p764-xffc-3rx4.json | 12 +++--------- .../05/GHSA-pcm7-87gm-6p9c/GHSA-pcm7-87gm-6p9c.json | 8 ++------ .../05/GHSA-pf85-3hgc-m9ph/GHSA-pf85-3hgc-m9ph.json | 8 ++------ .../05/GHSA-pfjf-vfqg-5r4q/GHSA-pfjf-vfqg-5r4q.json | 8 ++------ .../05/GHSA-pgmq-fmcf-6fcm/GHSA-pgmq-fmcf-6fcm.json | 12 +++--------- .../05/GHSA-php4-mj74-f79r/GHSA-php4-mj74-f79r.json | 4 +--- .../05/GHSA-pjfj-8qjp-8vjv/GHSA-pjfj-8qjp-8vjv.json | 4 +--- .../05/GHSA-pm2v-2gwc-36m2/GHSA-pm2v-2gwc-36m2.json | 8 ++------ .../05/GHSA-pmgx-8jcm-w9ch/GHSA-pmgx-8jcm-w9ch.json | 12 +++--------- .../05/GHSA-pqpq-74m3-r29f/GHSA-pqpq-74m3-r29f.json | 12 +++--------- .../05/GHSA-pqxf-356j-9cf5/GHSA-pqxf-356j-9cf5.json | 12 +++--------- .../05/GHSA-pv86-pp92-5j64/GHSA-pv86-pp92-5j64.json | 12 +++--------- .../05/GHSA-q288-gx5w-rvx3/GHSA-q288-gx5w-rvx3.json | 12 +++--------- .../05/GHSA-q48v-f889-vqw2/GHSA-q48v-f889-vqw2.json | 12 +++--------- .../05/GHSA-q57j-mjmf-2rf4/GHSA-q57j-mjmf-2rf4.json | 4 +--- .../05/GHSA-q7x9-263m-286c/GHSA-q7x9-263m-286c.json | 12 +++--------- .../05/GHSA-q8p3-h862-x3xv/GHSA-q8p3-h862-x3xv.json | 8 ++------ .../05/GHSA-q96p-5qxq-68c4/GHSA-q96p-5qxq-68c4.json | 12 +++--------- .../05/GHSA-q98m-jc54-9j83/GHSA-q98m-jc54-9j83.json | 12 +++--------- .../05/GHSA-qcx8-9vm4-9g3r/GHSA-qcx8-9vm4-9g3r.json | 12 +++--------- .../05/GHSA-qf37-j9hx-38gx/GHSA-qf37-j9hx-38gx.json | 8 ++------ .../05/GHSA-qg5g-43r3-8gpr/GHSA-qg5g-43r3-8gpr.json | 12 +++--------- .../05/GHSA-qmqm-hvm5-wx4p/GHSA-qmqm-hvm5-wx4p.json | 12 +++--------- .../05/GHSA-qp47-5phq-m7xm/GHSA-qp47-5phq-m7xm.json | 12 +++--------- .../05/GHSA-qp5r-cxv5-wrq8/GHSA-qp5r-cxv5-wrq8.json | 8 ++------ .../05/GHSA-qpqv-23g8-wmfg/GHSA-qpqv-23g8-wmfg.json | 12 +++--------- .../05/GHSA-qqw6-6jqg-6w44/GHSA-qqw6-6jqg-6w44.json | 12 +++--------- .../05/GHSA-qr6w-xx8m-93mv/GHSA-qr6w-xx8m-93mv.json | 8 ++------ .../05/GHSA-qrmf-fv3g-9879/GHSA-qrmf-fv3g-9879.json | 4 +--- .../05/GHSA-qrpg-pg76-xv44/GHSA-qrpg-pg76-xv44.json | 12 +++--------- .../05/GHSA-qwvf-9vg7-643x/GHSA-qwvf-9vg7-643x.json | 8 ++------ .../05/GHSA-qx89-46x3-pwhf/GHSA-qx89-46x3-pwhf.json | 8 ++------ .../05/GHSA-qxjv-whw7-vp66/GHSA-qxjv-whw7-vp66.json | 4 +--- .../05/GHSA-r233-x568-m7xw/GHSA-r233-x568-m7xw.json | 12 +++--------- .../05/GHSA-r33p-vh3m-6j34/GHSA-r33p-vh3m-6j34.json | 12 +++--------- .../05/GHSA-r3hc-822r-fr95/GHSA-r3hc-822r-fr95.json | 12 +++--------- .../05/GHSA-r4gx-x67v-jqmv/GHSA-r4gx-x67v-jqmv.json | 12 +++--------- .../05/GHSA-r4mf-29c6-hhqm/GHSA-r4mf-29c6-hhqm.json | 12 +++--------- .../05/GHSA-r8vj-8v78-62h8/GHSA-r8vj-8v78-62h8.json | 12 +++--------- .../05/GHSA-r93h-8m5r-m5qw/GHSA-r93h-8m5r-m5qw.json | 12 +++--------- .../05/GHSA-r9vc-pgpj-x6f4/GHSA-r9vc-pgpj-x6f4.json | 12 +++--------- .../05/GHSA-r9vr-wvw6-c8v5/GHSA-r9vr-wvw6-c8v5.json | 12 +++--------- .../05/GHSA-rc37-w42j-7p74/GHSA-rc37-w42j-7p74.json | 8 ++------ .../05/GHSA-rc3c-4c69-rjx6/GHSA-rc3c-4c69-rjx6.json | 12 +++--------- .../05/GHSA-rcm9-p88f-cmqm/GHSA-rcm9-p88f-cmqm.json | 4 +--- .../05/GHSA-rcmf-fgmg-6243/GHSA-rcmf-fgmg-6243.json | 12 +++--------- .../05/GHSA-rcrf-wp3c-5926/GHSA-rcrf-wp3c-5926.json | 12 +++--------- .../05/GHSA-rffr-3rx2-ffxx/GHSA-rffr-3rx2-ffxx.json | 8 ++------ .../05/GHSA-rfmc-3x99-f7mh/GHSA-rfmc-3x99-f7mh.json | 8 ++------ .../05/GHSA-rgxm-j5wc-86wx/GHSA-rgxm-j5wc-86wx.json | 12 +++--------- .../05/GHSA-rhmf-xrpg-5wj8/GHSA-rhmf-xrpg-5wj8.json | 12 +++--------- .../05/GHSA-rjwh-c5gm-2fm3/GHSA-rjwh-c5gm-2fm3.json | 12 +++--------- .../05/GHSA-rm7j-f2x3-cwg3/GHSA-rm7j-f2x3-cwg3.json | 12 +++--------- .../05/GHSA-rmfw-qmvr-x823/GHSA-rmfw-qmvr-x823.json | 8 ++------ .../05/GHSA-rmmv-j9x6-f2v4/GHSA-rmmv-j9x6-f2v4.json | 12 +++--------- .../05/GHSA-rpw6-pjfj-6x6g/GHSA-rpw6-pjfj-6x6g.json | 12 +++--------- .../05/GHSA-rqc4-5489-hg7v/GHSA-rqc4-5489-hg7v.json | 4 +--- .../05/GHSA-rqw3-7f5v-7r6j/GHSA-rqw3-7f5v-7r6j.json | 8 ++------ .../05/GHSA-rrwp-p45h-xvj8/GHSA-rrwp-p45h-xvj8.json | 12 +++--------- .../05/GHSA-rrx7-84fw-cxr2/GHSA-rrx7-84fw-cxr2.json | 12 +++--------- .../05/GHSA-rv55-v2mj-w9hg/GHSA-rv55-v2mj-w9hg.json | 12 +++--------- .../05/GHSA-rwpv-9hw4-gq63/GHSA-rwpv-9hw4-gq63.json | 8 ++------ .../05/GHSA-rx4q-5jwm-r64w/GHSA-rx4q-5jwm-r64w.json | 8 ++------ .../05/GHSA-rxc8-x669-7284/GHSA-rxc8-x669-7284.json | 12 +++--------- .../05/GHSA-rxf3-275x-fff6/GHSA-rxf3-275x-fff6.json | 12 +++--------- .../05/GHSA-rxm3-cc74-v7p3/GHSA-rxm3-cc74-v7p3.json | 12 +++--------- .../05/GHSA-v223-v69f-prp5/GHSA-v223-v69f-prp5.json | 12 +++--------- .../05/GHSA-v2mj-wwf5-5hqj/GHSA-v2mj-wwf5-5hqj.json | 4 +--- .../05/GHSA-v37j-c88f-qxj8/GHSA-v37j-c88f-qxj8.json | 8 ++------ .../05/GHSA-v3jj-mj48-m8gv/GHSA-v3jj-mj48-m8gv.json | 12 +++--------- .../05/GHSA-v3wj-9m6p-vhvw/GHSA-v3wj-9m6p-vhvw.json | 12 +++--------- .../05/GHSA-v566-63q4-p5m6/GHSA-v566-63q4-p5m6.json | 12 +++--------- .../05/GHSA-v5mw-2gc6-7h62/GHSA-v5mw-2gc6-7h62.json | 12 +++--------- .../05/GHSA-v5pq-rgjj-rxgr/GHSA-v5pq-rgjj-rxgr.json | 8 ++------ .../05/GHSA-v62j-q62r-7cr9/GHSA-v62j-q62r-7cr9.json | 8 ++------ .../05/GHSA-v6g6-c9gr-qqp6/GHSA-v6g6-c9gr-qqp6.json | 8 ++------ .../05/GHSA-v6xp-4m9g-j2w9/GHSA-v6xp-4m9g-j2w9.json | 12 +++--------- .../05/GHSA-v84q-4crc-f5w4/GHSA-v84q-4crc-f5w4.json | 12 +++--------- .../05/GHSA-v8f8-f9x3-fqw4/GHSA-v8f8-f9x3-fqw4.json | 12 +++--------- .../05/GHSA-vc56-vmhr-h868/GHSA-vc56-vmhr-h868.json | 8 ++------ .../05/GHSA-vcx9-7p39-hwhg/GHSA-vcx9-7p39-hwhg.json | 12 +++--------- .../05/GHSA-vg9c-4w2h-c984/GHSA-vg9c-4w2h-c984.json | 8 ++------ .../05/GHSA-vh9x-535j-rc7j/GHSA-vh9x-535j-rc7j.json | 12 +++--------- .../05/GHSA-vj8w-5833-f867/GHSA-vj8w-5833-f867.json | 8 ++------ .../05/GHSA-vjh2-6hpx-j5rv/GHSA-vjh2-6hpx-j5rv.json | 12 +++--------- .../05/GHSA-vjxq-fxvh-23vc/GHSA-vjxq-fxvh-23vc.json | 12 +++--------- .../05/GHSA-vmqr-6q8r-ww5m/GHSA-vmqr-6q8r-ww5m.json | 12 +++--------- .../05/GHSA-vppp-x5c9-x4mg/GHSA-vppp-x5c9-x4mg.json | 12 +++--------- .../05/GHSA-vq77-78v5-mqfp/GHSA-vq77-78v5-mqfp.json | 4 +--- .../05/GHSA-vqmr-6f7c-q88q/GHSA-vqmr-6f7c-q88q.json | 12 +++--------- .../05/GHSA-vr74-fpq9-774p/GHSA-vr74-fpq9-774p.json | 12 +++--------- .../05/GHSA-vrcq-p73m-hmc8/GHSA-vrcq-p73m-hmc8.json | 8 ++------ .../05/GHSA-vrfp-mmr3-wph6/GHSA-vrfp-mmr3-wph6.json | 12 +++--------- .../05/GHSA-vrpr-p6w2-crwx/GHSA-vrpr-p6w2-crwx.json | 8 ++------ .../05/GHSA-vxf2-rc93-x6wf/GHSA-vxf2-rc93-x6wf.json | 12 +++--------- .../05/GHSA-vxv9-h8fr-8f88/GHSA-vxv9-h8fr-8f88.json | 4 +--- .../05/GHSA-vxw8-3jmr-prjr/GHSA-vxw8-3jmr-prjr.json | 12 +++--------- .../05/GHSA-w256-88g9-rh8j/GHSA-w256-88g9-rh8j.json | 12 +++--------- .../05/GHSA-w339-gvf7-98x9/GHSA-w339-gvf7-98x9.json | 4 +--- .../05/GHSA-w36j-549f-hchr/GHSA-w36j-549f-hchr.json | 12 +++--------- .../05/GHSA-w44r-j9pq-vv3v/GHSA-w44r-j9pq-vv3v.json | 12 +++--------- .../05/GHSA-w4j4-88w2-32g6/GHSA-w4j4-88w2-32g6.json | 12 +++--------- .../05/GHSA-w6qj-c53w-v49m/GHSA-w6qj-c53w-v49m.json | 12 +++--------- .../05/GHSA-w6rh-mrcc-6xc4/GHSA-w6rh-mrcc-6xc4.json | 12 +++--------- .../05/GHSA-w772-f4fj-g5xq/GHSA-w772-f4fj-g5xq.json | 8 ++------ .../05/GHSA-w7w7-v6c3-q554/GHSA-w7w7-v6c3-q554.json | 12 +++--------- .../05/GHSA-w8pp-7r52-g3fm/GHSA-w8pp-7r52-g3fm.json | 12 +++--------- .../05/GHSA-w8rm-5xr6-mmcj/GHSA-w8rm-5xr6-mmcj.json | 12 +++--------- .../05/GHSA-w8vp-84hv-6mqj/GHSA-w8vp-84hv-6mqj.json | 12 +++--------- .../05/GHSA-w9hw-62rh-37w6/GHSA-w9hw-62rh-37w6.json | 8 ++------ .../05/GHSA-wcv6-x2hg-7wqj/GHSA-wcv6-x2hg-7wqj.json | 8 ++------ .../05/GHSA-wgxw-w75w-6fm4/GHSA-wgxw-w75w-6fm4.json | 12 +++--------- .../05/GHSA-whrv-w3fp-5gf4/GHSA-whrv-w3fp-5gf4.json | 12 +++--------- .../05/GHSA-wjxh-p937-x4v8/GHSA-wjxh-p937-x4v8.json | 12 +++--------- .../05/GHSA-wqrj-5m22-cpfg/GHSA-wqrj-5m22-cpfg.json | 12 +++--------- .../05/GHSA-wr5r-rjww-hqwf/GHSA-wr5r-rjww-hqwf.json | 8 ++------ .../05/GHSA-wr7m-82gg-jpg8/GHSA-wr7m-82gg-jpg8.json | 12 +++--------- .../05/GHSA-wv8f-82g9-5vhw/GHSA-wv8f-82g9-5vhw.json | 12 +++--------- .../05/GHSA-wv8g-hc35-2wh7/GHSA-wv8g-hc35-2wh7.json | 12 +++--------- .../05/GHSA-wv97-733g-f484/GHSA-wv97-733g-f484.json | 12 +++--------- .../05/GHSA-wvcx-99hh-xjmx/GHSA-wvcx-99hh-xjmx.json | 8 ++------ .../05/GHSA-wvv9-x8pf-57jq/GHSA-wvv9-x8pf-57jq.json | 12 +++--------- .../05/GHSA-wvx4-cw49-456m/GHSA-wvx4-cw49-456m.json | 8 ++------ .../05/GHSA-wxqp-q88p-4h7r/GHSA-wxqp-q88p-4h7r.json | 12 +++--------- .../05/GHSA-wxxf-gxv9-5j54/GHSA-wxxf-gxv9-5j54.json | 12 +++--------- .../05/GHSA-x257-265c-9355/GHSA-x257-265c-9355.json | 12 +++--------- .../05/GHSA-x2gh-jj85-3r25/GHSA-x2gh-jj85-3r25.json | 8 ++------ .../05/GHSA-x36q-229j-mv7q/GHSA-x36q-229j-mv7q.json | 12 +++--------- .../05/GHSA-x3w4-7cmr-9gv2/GHSA-x3w4-7cmr-9gv2.json | 12 +++--------- .../05/GHSA-x4f4-vh84-45wp/GHSA-x4f4-vh84-45wp.json | 12 +++--------- .../05/GHSA-x4r5-gcgv-4cmp/GHSA-x4r5-gcgv-4cmp.json | 4 +--- .../05/GHSA-x65v-c8ff-h2m3/GHSA-x65v-c8ff-h2m3.json | 12 +++--------- .../05/GHSA-x687-4r8f-56rh/GHSA-x687-4r8f-56rh.json | 12 +++--------- .../05/GHSA-x6g7-8j99-h4fv/GHSA-x6g7-8j99-h4fv.json | 12 +++--------- .../05/GHSA-x6v5-8qcc-4q56/GHSA-x6v5-8qcc-4q56.json | 12 +++--------- .../05/GHSA-x75j-hvj7-cjwg/GHSA-x75j-hvj7-cjwg.json | 12 +++--------- .../05/GHSA-x8h6-fqp3-v7qr/GHSA-x8h6-fqp3-v7qr.json | 12 +++--------- .../05/GHSA-x8qg-82x8-gf44/GHSA-x8qg-82x8-gf44.json | 12 +++--------- .../05/GHSA-xcj9-hh7g-p7rq/GHSA-xcj9-hh7g-p7rq.json | 12 +++--------- .../05/GHSA-xcx2-w5f3-cw9g/GHSA-xcx2-w5f3-cw9g.json | 12 +++--------- .../05/GHSA-xf55-34cc-4qxw/GHSA-xf55-34cc-4qxw.json | 12 +++--------- .../05/GHSA-xfq9-m5c5-8p4q/GHSA-xfq9-m5c5-8p4q.json | 12 +++--------- .../05/GHSA-xg7m-wjrf-p6rf/GHSA-xg7m-wjrf-p6rf.json | 8 ++------ .../05/GHSA-xhj8-35xv-vj3p/GHSA-xhj8-35xv-vj3p.json | 12 +++--------- .../05/GHSA-xj7q-4ppq-c7ch/GHSA-xj7q-4ppq-c7ch.json | 12 +++--------- .../05/GHSA-xjx5-q997-jj79/GHSA-xjx5-q997-jj79.json | 12 +++--------- .../05/GHSA-xm4c-wwh2-mcv8/GHSA-xm4c-wwh2-mcv8.json | 12 +++--------- .../05/GHSA-xmvf-mpjx-5xvj/GHSA-xmvf-mpjx-5xvj.json | 8 ++------ .../05/GHSA-xp78-rqf2-cf9c/GHSA-xp78-rqf2-cf9c.json | 12 +++--------- .../05/GHSA-xq9m-fh33-jh35/GHSA-xq9m-fh33-jh35.json | 12 +++--------- .../05/GHSA-xr69-7fhc-h6vj/GHSA-xr69-7fhc-h6vj.json | 12 +++--------- .../05/GHSA-xr82-vj36-ch3w/GHSA-xr82-vj36-ch3w.json | 12 +++--------- .../05/GHSA-xrw7-9m6r-77jp/GHSA-xrw7-9m6r-77jp.json | 4 +--- .../05/GHSA-xvh3-9p5j-3q4f/GHSA-xvh3-9p5j-3q4f.json | 12 +++--------- .../05/GHSA-xwp8-fr9p-xj9v/GHSA-xwp8-fr9p-xj9v.json | 12 +++--------- .../05/GHSA-xxhg-xvhq-pmx2/GHSA-xxhg-xvhq-pmx2.json | 12 +++--------- .../05/GHSA-xxr3-85vr-f7wf/GHSA-xxr3-85vr-f7wf.json | 8 ++------ .../09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json | 8 ++------ .../09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json | 8 ++------ .../09/GHSA-27m4-83f2-2x77/GHSA-27m4-83f2-2x77.json | 4 +--- .../09/GHSA-29pj-cw86-x2fg/GHSA-29pj-cw86-x2fg.json | 4 +--- .../09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json | 8 ++------ .../09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json | 8 ++------ .../09/GHSA-5g39-p52c-vm53/GHSA-5g39-p52c-vm53.json | 4 +--- .../09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json | 8 ++------ .../09/GHSA-692h-cj57-w2g9/GHSA-692h-cj57-w2g9.json | 4 +--- .../09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json | 8 ++------ .../09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json | 8 ++------ .../09/GHSA-738c-cx4m-7gvx/GHSA-738c-cx4m-7gvx.json | 4 +--- .../09/GHSA-74m6-rqc7-wfvx/GHSA-74m6-rqc7-wfvx.json | 4 +--- .../09/GHSA-75p4-j454-hrjv/GHSA-75p4-j454-hrjv.json | 4 +--- .../09/GHSA-82hg-7wf7-rhvf/GHSA-82hg-7wf7-rhvf.json | 4 +--- .../09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json | 8 ++------ .../09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json | 8 ++------ .../09/GHSA-9fj7-9qg7-9fgc/GHSA-9fj7-9qg7-9fgc.json | 4 +--- .../09/GHSA-9rwx-hp6q-64m8/GHSA-9rwx-hp6q-64m8.json | 8 ++------ .../09/GHSA-c38j-ccr2-v3jw/GHSA-c38j-ccr2-v3jw.json | 4 +--- .../09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json | 8 ++------ .../09/GHSA-cfqx-4cch-8hgx/GHSA-cfqx-4cch-8hgx.json | 4 +--- .../09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json | 8 ++------ .../09/GHSA-m7rj-3phc-xm3w/GHSA-m7rj-3phc-xm3w.json | 4 +--- .../09/GHSA-mcxh-2w23-3cf7/GHSA-mcxh-2w23-3cf7.json | 4 +--- .../09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json | 8 ++------ .../09/GHSA-p235-xqcv-9xrg/GHSA-p235-xqcv-9xrg.json | 8 ++------ .../09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json | 8 ++------ .../09/GHSA-p8vh-mwc9-r3jw/GHSA-p8vh-mwc9-r3jw.json | 4 +--- .../09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json | 8 ++------ .../09/GHSA-qv87-xvw7-xfrc/GHSA-qv87-xvw7-xfrc.json | 4 +--- .../09/GHSA-r5vg-678j-p7m4/GHSA-r5vg-678j-p7m4.json | 4 +--- .../09/GHSA-rjp4-q5qr-3cqx/GHSA-rjp4-q5qr-3cqx.json | 4 +--- .../09/GHSA-v44q-v8rf-3m92/GHSA-v44q-v8rf-3m92.json | 4 +--- .../09/GHSA-v5mm-c2pr-7qgh/GHSA-v5mm-c2pr-7qgh.json | 4 +--- .../09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json | 8 ++------ .../09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json | 8 ++------ .../09/GHSA-xx24-pg44-2jhw/GHSA-xx24-pg44-2jhw.json | 4 +--- .../10/GHSA-25gc-rgw2-hc8g/GHSA-25gc-rgw2-hc8g.json | 8 ++------ .../10/GHSA-4rj6-gcf8-wchc/GHSA-4rj6-gcf8-wchc.json | 4 +--- .../10/GHSA-58rh-q4r8-94g3/GHSA-58rh-q4r8-94g3.json | 8 ++------ .../10/GHSA-64qv-9rcm-pfxv/GHSA-64qv-9rcm-pfxv.json | 8 ++------ .../10/GHSA-8658-c36g-5m8j/GHSA-8658-c36g-5m8j.json | 4 +--- .../10/GHSA-cpc4-rhwg-5qx7/GHSA-cpc4-rhwg-5qx7.json | 8 ++------ .../10/GHSA-f73x-whqx-6jm2/GHSA-f73x-whqx-6jm2.json | 8 ++------ .../10/GHSA-gcvm-jx53-vhrj/GHSA-gcvm-jx53-vhrj.json | 8 ++------ .../10/GHSA-gq3r-53wg-9xgg/GHSA-gq3r-53wg-9xgg.json | 8 ++------ .../10/GHSA-jj9p-6gqv-vr9g/GHSA-jj9p-6gqv-vr9g.json | 8 ++------ .../10/GHSA-m36r-vqcv-84cm/GHSA-m36r-vqcv-84cm.json | 8 ++------ .../10/GHSA-mm96-m286-2v7r/GHSA-mm96-m286-2v7r.json | 8 ++------ .../10/GHSA-p6m5-777x-4f3g/GHSA-p6m5-777x-4f3g.json | 8 ++------ .../10/GHSA-q598-jq34-rwrr/GHSA-q598-jq34-rwrr.json | 8 ++------ .../10/GHSA-qjvf-mwxj-x748/GHSA-qjvf-mwxj-x748.json | 4 +--- .../10/GHSA-rf3v-8qgp-pp24/GHSA-rf3v-8qgp-pp24.json | 4 +--- .../10/GHSA-rw3j-949g-mvhg/GHSA-rw3j-949g-mvhg.json | 8 ++------ .../10/GHSA-v94w-gwp7-675c/GHSA-v94w-gwp7-675c.json | 8 ++------ .../10/GHSA-vmjw-wrqg-9457/GHSA-vmjw-wrqg-9457.json | 8 ++------ .../10/GHSA-w4cr-xjrm-vrc8/GHSA-w4cr-xjrm-vrc8.json | 4 +--- .../10/GHSA-x4cp-qc28-2pqp/GHSA-x4cp-qc28-2pqp.json | 8 ++------ .../11/GHSA-745w-p4gm-x2vw/GHSA-745w-p4gm-x2vw.json | 4 +--- .../12/GHSA-993x-6558-2xmj/GHSA-993x-6558-2xmj.json | 8 ++------ .../12/GHSA-hh7f-cch9-52mr/GHSA-hh7f-cch9-52mr.json | 4 +--- .../01/GHSA-249j-645x-c97w/GHSA-249j-645x-c97w.json | 4 +--- .../01/GHSA-2x79-g9jx-q9f2/GHSA-2x79-g9jx-q9f2.json | 4 +--- .../01/GHSA-55c3-g238-6jv4/GHSA-55c3-g238-6jv4.json | 4 +--- .../01/GHSA-9749-rqrj-vcqj/GHSA-9749-rqrj-vcqj.json | 4 +--- .../01/GHSA-99v4-pprm-ghh2/GHSA-99v4-pprm-ghh2.json | 4 +--- .../01/GHSA-9j25-3cvc-f5hg/GHSA-9j25-3cvc-f5hg.json | 4 +--- .../01/GHSA-9m3w-rfcw-cvp3/GHSA-9m3w-rfcw-cvp3.json | 4 +--- .../01/GHSA-gf2w-gwrg-m3gv/GHSA-gf2w-gwrg-m3gv.json | 4 +--- .../01/GHSA-jgc3-x572-hr2h/GHSA-jgc3-x572-hr2h.json | 4 +--- .../01/GHSA-m9c9-fqf4-w6xr/GHSA-m9c9-fqf4-w6xr.json | 4 +--- .../01/GHSA-mp4c-w7j9-95f4/GHSA-mp4c-w7j9-95f4.json | 4 +--- .../01/GHSA-pfcx-mq53-xrff/GHSA-pfcx-mq53-xrff.json | 4 +--- .../01/GHSA-vc9r-97qq-w3qh/GHSA-vc9r-97qq-w3qh.json | 4 +--- .../02/GHSA-338m-rx6v-qqv5/GHSA-338m-rx6v-qqv5.json | 4 +--- .../02/GHSA-59rv-395v-g9xw/GHSA-59rv-395v-g9xw.json | 4 +--- .../02/GHSA-5fc7-wjrw-2jh4/GHSA-5fc7-wjrw-2jh4.json | 4 +--- .../02/GHSA-8p6c-rh83-4gp7/GHSA-8p6c-rh83-4gp7.json | 4 +--- .../02/GHSA-cwj4-5mgc-phhv/GHSA-cwj4-5mgc-phhv.json | 4 +--- .../02/GHSA-gw5r-2prc-4jj5/GHSA-gw5r-2prc-4jj5.json | 4 +--- .../02/GHSA-pp2p-5ghw-9ccc/GHSA-pp2p-5ghw-9ccc.json | 4 +--- .../03/GHSA-4gxr-wffq-h9jh/GHSA-4gxr-wffq-h9jh.json | 4 +--- .../03/GHSA-583v-9qpc-hx7x/GHSA-583v-9qpc-hx7x.json | 4 +--- .../03/GHSA-cqf6-7wvc-xg52/GHSA-cqf6-7wvc-xg52.json | 4 +--- .../03/GHSA-gcrf-r338-q8rq/GHSA-gcrf-r338-q8rq.json | 4 +--- .../03/GHSA-gx8c-7452-frr8/GHSA-gx8c-7452-frr8.json | 4 +--- .../05/GHSA-v972-h57q-v8pw/GHSA-v972-h57q-v8pw.json | 4 +--- .../06/GHSA-5fg8-8wg9-97x2/GHSA-5fg8-8wg9-97x2.json | 4 +--- .../07/GHSA-37c2-5chg-wwj7/GHSA-37c2-5chg-wwj7.json | 4 +--- .../07/GHSA-3f53-3vgw-49w5/GHSA-3f53-3vgw-49w5.json | 4 +--- .../07/GHSA-fj2m-7r3q-j27x/GHSA-fj2m-7r3q-j27x.json | 4 +--- .../07/GHSA-jhwx-fm67-385p/GHSA-jhwx-fm67-385p.json | 4 +--- .../07/GHSA-jr8r-v8q8-phf2/GHSA-jr8r-v8q8-phf2.json | 4 +--- .../03/GHSA-3537-379x-x582/GHSA-3537-379x-x582.json | 4 +--- .../03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json | 4 +--- .../03/GHSA-6j3q-64jm-q33g/GHSA-6j3q-64jm-q33g.json | 8 ++------ .../03/GHSA-g2m6-m2m8-q4qh/GHSA-g2m6-m2m8-q4qh.json | 4 +--- .../03/GHSA-g7cx-2g6j-fpvq/GHSA-g7cx-2g6j-fpvq.json | 4 +--- .../03/GHSA-q4fq-56x3-rq98/GHSA-q4fq-56x3-rq98.json | 4 +--- .../03/GHSA-qgvx-mvf3-xw8r/GHSA-qgvx-mvf3-xw8r.json | 4 +--- .../03/GHSA-rmxq-q4j3-rg8f/GHSA-rmxq-q4j3-rg8f.json | 8 ++------ .../03/GHSA-v5w3-8cw8-83hq/GHSA-v5w3-8cw8-83hq.json | 4 +--- .../03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json | 8 ++------ .../03/GHSA-xhm5-2j4f-4x4p/GHSA-xhm5-2j4f-4x4p.json | 4 +--- .../04/GHSA-9xj7-mrgq-4ccq/GHSA-9xj7-mrgq-4ccq.json | 4 +--- .../05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json | 8 ++------ .../05/GHSA-33w7-r9c3-9qwq/GHSA-33w7-r9c3-9qwq.json | 4 +--- .../05/GHSA-5g7f-2wxq-wj73/GHSA-5g7f-2wxq-wj73.json | 4 +--- .../05/GHSA-7jj8-vg94-4wqj/GHSA-7jj8-vg94-4wqj.json | 4 +--- .../05/GHSA-7v53-8wv7-fw3m/GHSA-7v53-8wv7-fw3m.json | 8 ++------ .../05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json | 8 ++------ .../05/GHSA-fpgv-fc8m-fmmm/GHSA-fpgv-fc8m-fmmm.json | 4 +--- .../05/GHSA-h347-4rgx-68rr/GHSA-h347-4rgx-68rr.json | 8 ++------ .../05/GHSA-hh52-hj46-fhvm/GHSA-hh52-hj46-fhvm.json | 4 +--- .../05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json | 8 ++------ .../06/GHSA-4xjp-m233-hj66/GHSA-4xjp-m233-hj66.json | 8 ++------ .../06/GHSA-hfwg-2mm4-h8c4/GHSA-hfwg-2mm4-h8c4.json | 4 +--- .../07/GHSA-6268-2vhw-q7hp/GHSA-6268-2vhw-q7hp.json | 4 +--- .../07/GHSA-68c9-v49q-x7mc/GHSA-68c9-v49q-x7mc.json | 12 +++--------- .../07/GHSA-8h2g-2763-hv4f/GHSA-8h2g-2763-hv4f.json | 12 +++--------- .../07/GHSA-8w62-4hrj-35fc/GHSA-8w62-4hrj-35fc.json | 12 +++--------- .../07/GHSA-9544-wf5c-4fgc/GHSA-9544-wf5c-4fgc.json | 12 +++--------- .../07/GHSA-9c47-8jgj-vm87/GHSA-9c47-8jgj-vm87.json | 12 +++--------- .../07/GHSA-jrcg-8r29-9778/GHSA-jrcg-8r29-9778.json | 12 +++--------- .../07/GHSA-m3gj-m97q-954q/GHSA-m3gj-m97q-954q.json | 4 +--- .../07/GHSA-mppf-86h8-5cj7/GHSA-mppf-86h8-5cj7.json | 12 +++--------- .../07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json | 4 +--- .../07/GHSA-p9pr-gh8g-j3cx/GHSA-p9pr-gh8g-j3cx.json | 8 ++------ .../07/GHSA-rgcc-23p4-9wq6/GHSA-rgcc-23p4-9wq6.json | 12 +++--------- .../07/GHSA-wc55-4jhw-4fw3/GHSA-wc55-4jhw-4fw3.json | 12 +++--------- .../07/GHSA-xc6h-2r52-3c4v/GHSA-xc6h-2r52-3c4v.json | 12 +++--------- .../07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json | 4 +--- .../09/GHSA-22rq-cmx2-gvr4/GHSA-22rq-cmx2-gvr4.json | 4 +--- .../09/GHSA-23g2-8hr8-76p4/GHSA-23g2-8hr8-76p4.json | 12 +++--------- .../09/GHSA-2973-q4qx-mjf5/GHSA-2973-q4qx-mjf5.json | 12 +++--------- .../09/GHSA-2p9x-h657-5mg3/GHSA-2p9x-h657-5mg3.json | 12 +++--------- .../09/GHSA-324v-cwrv-qmqr/GHSA-324v-cwrv-qmqr.json | 12 +++--------- .../09/GHSA-3j56-rc6g-pp7q/GHSA-3j56-rc6g-pp7q.json | 4 +--- .../09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json | 4 +--- .../09/GHSA-46cp-m7j2-3fh7/GHSA-46cp-m7j2-3fh7.json | 4 +--- .../09/GHSA-4qr8-v8vv-2g9w/GHSA-4qr8-v8vv-2g9w.json | 12 +++--------- .../09/GHSA-5937-rmjq-m7qm/GHSA-5937-rmjq-m7qm.json | 12 +++--------- .../09/GHSA-5m5p-hvxj-grxr/GHSA-5m5p-hvxj-grxr.json | 4 +--- .../09/GHSA-5p8v-m885-q5fg/GHSA-5p8v-m885-q5fg.json | 4 +--- .../09/GHSA-5pm9-6vq7-8mc4/GHSA-5pm9-6vq7-8mc4.json | 4 +--- .../09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json | 4 +--- .../09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json | 4 +--- .../09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json | 4 +--- .../09/GHSA-8vqf-p95r-7frg/GHSA-8vqf-p95r-7frg.json | 4 +--- .../09/GHSA-9387-xrfr-3wfr/GHSA-9387-xrfr-3wfr.json | 4 +--- .../09/GHSA-97r7-fmq6-w47h/GHSA-97r7-fmq6-w47h.json | 4 +--- .../09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json | 4 +--- .../09/GHSA-crwm-whhx-38v8/GHSA-crwm-whhx-38v8.json | 12 +++--------- .../09/GHSA-cwr3-4fc3-j8h8/GHSA-cwr3-4fc3-j8h8.json | 4 +--- .../09/GHSA-f7pg-xgpm-7pv6/GHSA-f7pg-xgpm-7pv6.json | 4 +--- .../09/GHSA-g38f-j3m7-3p88/GHSA-g38f-j3m7-3p88.json | 4 +--- .../09/GHSA-g399-5j3g-vm56/GHSA-g399-5j3g-vm56.json | 4 +--- .../09/GHSA-h85r-4358-hc66/GHSA-h85r-4358-hc66.json | 12 +++--------- .../09/GHSA-j54j-xh66-6rpm/GHSA-j54j-xh66-6rpm.json | 12 +++--------- .../09/GHSA-m58v-fvm4-hcrr/GHSA-m58v-fvm4-hcrr.json | 4 +--- .../09/GHSA-m83w-55jj-j9mx/GHSA-m83w-55jj-j9mx.json | 12 +++--------- .../09/GHSA-m92x-f2xf-6w5q/GHSA-m92x-f2xf-6w5q.json | 4 +--- .../09/GHSA-p357-q4ph-xr92/GHSA-p357-q4ph-xr92.json | 12 +++--------- .../09/GHSA-p5v6-vwvg-823j/GHSA-p5v6-vwvg-823j.json | 12 +++--------- .../09/GHSA-pw8w-hq42-r2hw/GHSA-pw8w-hq42-r2hw.json | 12 +++--------- .../09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json | 4 +--- .../09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json | 4 +--- .../09/GHSA-r288-8r34-4php/GHSA-r288-8r34-4php.json | 4 +--- .../09/GHSA-v7w6-282w-jqp8/GHSA-v7w6-282w-jqp8.json | 12 +++--------- .../09/GHSA-vggf-h36f-57fp/GHSA-vggf-h36f-57fp.json | 4 +--- .../09/GHSA-vrrc-qv8c-m5rg/GHSA-vrrc-qv8c-m5rg.json | 4 +--- .../09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json | 4 +--- .../09/GHSA-wjp8-2jq5-7v8q/GHSA-wjp8-2jq5-7v8q.json | 12 +++--------- .../09/GHSA-wp8q-76mh-g25x/GHSA-wp8q-76mh-g25x.json | 12 +++--------- .../09/GHSA-wpx8-pm5v-8hrp/GHSA-wpx8-pm5v-8hrp.json | 4 +--- .../09/GHSA-xp2m-m27g-f466/GHSA-xp2m-m27g-f466.json | 12 +++--------- .../09/GHSA-xrjg-w5fr-6ph9/GHSA-xrjg-w5fr-6ph9.json | 4 +--- .../09/GHSA-xrx8-f378-fwph/GHSA-xrx8-f378-fwph.json | 4 +--- .../10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json | 4 +--- .../10/GHSA-365x-gvhj-29hg/GHSA-365x-gvhj-29hg.json | 4 +--- .../10/GHSA-4c63-26fj-6f7h/GHSA-4c63-26fj-6f7h.json | 8 ++------ .../10/GHSA-5wgm-phpv-mgx7/GHSA-5wgm-phpv-mgx7.json | 8 ++------ .../10/GHSA-7hrq-p9p5-9fjx/GHSA-7hrq-p9p5-9fjx.json | 4 +--- .../10/GHSA-869q-v62p-q4p8/GHSA-869q-v62p-q4p8.json | 4 +--- .../10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json | 4 +--- .../10/GHSA-8xxh-66cx-j9cj/GHSA-8xxh-66cx-j9cj.json | 4 +--- .../10/GHSA-9x3x-8pcp-wvrj/GHSA-9x3x-8pcp-wvrj.json | 4 +--- .../10/GHSA-cp4c-qw43-fgxp/GHSA-cp4c-qw43-fgxp.json | 8 ++------ .../10/GHSA-cx2h-6865-57p7/GHSA-cx2h-6865-57p7.json | 4 +--- .../10/GHSA-f8cq-cpqj-phg9/GHSA-f8cq-cpqj-phg9.json | 4 +--- .../10/GHSA-ffwc-hfc6-c5gp/GHSA-ffwc-hfc6-c5gp.json | 4 +--- .../10/GHSA-g49h-wxrw-qwfh/GHSA-g49h-wxrw-qwfh.json | 4 +--- .../10/GHSA-g768-c2cp-rxc4/GHSA-g768-c2cp-rxc4.json | 4 +--- .../10/GHSA-gqp9-r7wj-r9hc/GHSA-gqp9-r7wj-r9hc.json | 8 ++------ .../10/GHSA-hr6h-7jqj-mx8j/GHSA-hr6h-7jqj-mx8j.json | 8 ++------ .../10/GHSA-hx4q-76p6-78cc/GHSA-hx4q-76p6-78cc.json | 4 +--- .../10/GHSA-jf2q-q2v4-h63r/GHSA-jf2q-q2v4-h63r.json | 4 +--- .../10/GHSA-jx8h-cfqr-f26f/GHSA-jx8h-cfqr-f26f.json | 4 +--- .../10/GHSA-m4qg-9xvx-47wq/GHSA-m4qg-9xvx-47wq.json | 8 ++------ .../10/GHSA-m6fg-p7cg-64mc/GHSA-m6fg-p7cg-64mc.json | 4 +--- .../10/GHSA-r5f6-w2pg-mf93/GHSA-r5f6-w2pg-mf93.json | 8 ++------ .../10/GHSA-vch3-xc23-jrf2/GHSA-vch3-xc23-jrf2.json | 8 ++------ .../10/GHSA-wr39-ggxq-3pf9/GHSA-wr39-ggxq-3pf9.json | 4 +--- .../10/GHSA-x75j-gc7f-rqjc/GHSA-x75j-gc7f-rqjc.json | 8 ++------ .../11/GHSA-226j-3v4h-8cg4/GHSA-226j-3v4h-8cg4.json | 8 ++------ .../11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json | 8 ++------ .../11/GHSA-2w43-52vj-94gx/GHSA-2w43-52vj-94gx.json | 4 +--- .../11/GHSA-3925-h58h-pr2m/GHSA-3925-h58h-pr2m.json | 4 +--- .../11/GHSA-3fgp-h8mw-wrh5/GHSA-3fgp-h8mw-wrh5.json | 4 +--- .../11/GHSA-3qgh-6635-p7pp/GHSA-3qgh-6635-p7pp.json | 4 +--- .../11/GHSA-3r6h-pxfq-6cr9/GHSA-3r6h-pxfq-6cr9.json | 4 +--- .../11/GHSA-436q-824j-g5cx/GHSA-436q-824j-g5cx.json | 4 +--- .../11/GHSA-4854-cq52-rmx6/GHSA-4854-cq52-rmx6.json | 4 +--- .../11/GHSA-49j5-25jj-6293/GHSA-49j5-25jj-6293.json | 4 +--- .../11/GHSA-5jgq-h327-whqc/GHSA-5jgq-h327-whqc.json | 4 +--- .../11/GHSA-66fc-89m5-fhwj/GHSA-66fc-89m5-fhwj.json | 4 +--- .../11/GHSA-6769-r74j-4rx4/GHSA-6769-r74j-4rx4.json | 4 +--- .../11/GHSA-6c68-97qr-gp9g/GHSA-6c68-97qr-gp9g.json | 4 +--- .../11/GHSA-6gjh-qqgg-32fj/GHSA-6gjh-qqgg-32fj.json | 4 +--- .../11/GHSA-6jgr-2pw9-g4rc/GHSA-6jgr-2pw9-g4rc.json | 4 +--- .../11/GHSA-6rcc-2x92-3rpg/GHSA-6rcc-2x92-3rpg.json | 4 +--- .../11/GHSA-72ch-892x-fp25/GHSA-72ch-892x-fp25.json | 4 +--- .../11/GHSA-742p-rh42-xg84/GHSA-742p-rh42-xg84.json | 4 +--- .../11/GHSA-74f8-hfjw-wvrf/GHSA-74f8-hfjw-wvrf.json | 4 +--- .../11/GHSA-7699-wpx7-684c/GHSA-7699-wpx7-684c.json | 4 +--- .../11/GHSA-79p2-24v8-gp9v/GHSA-79p2-24v8-gp9v.json | 4 +--- .../11/GHSA-7h5w-r4x3-245g/GHSA-7h5w-r4x3-245g.json | 4 +--- .../11/GHSA-7mr2-5hcp-6xwj/GHSA-7mr2-5hcp-6xwj.json | 4 +--- .../11/GHSA-7xwq-pp9q-q8hg/GHSA-7xwq-pp9q-q8hg.json | 4 +--- .../11/GHSA-87m5-7j63-58f7/GHSA-87m5-7j63-58f7.json | 4 +--- .../11/GHSA-8g7m-2r7v-c9gx/GHSA-8g7m-2r7v-c9gx.json | 4 +--- .../11/GHSA-8j22-qjv2-93w2/GHSA-8j22-qjv2-93w2.json | 4 +--- .../11/GHSA-8m29-g8hw-c32w/GHSA-8m29-g8hw-c32w.json | 4 +--- .../11/GHSA-8m3x-wq27-j7c8/GHSA-8m3x-wq27-j7c8.json | 12 +++--------- .../11/GHSA-8mfc-j52j-6m6v/GHSA-8mfc-j52j-6m6v.json | 8 ++------ .../11/GHSA-8w9v-ch8x-63jr/GHSA-8w9v-ch8x-63jr.json | 4 +--- .../11/GHSA-943q-7gr3-c56m/GHSA-943q-7gr3-c56m.json | 8 ++------ .../11/GHSA-94wv-j3jc-g3fm/GHSA-94wv-j3jc-g3fm.json | 4 +--- .../11/GHSA-976j-3f9q-58vp/GHSA-976j-3f9q-58vp.json | 4 +--- .../11/GHSA-98cj-759m-rr93/GHSA-98cj-759m-rr93.json | 4 +--- .../11/GHSA-9f6h-w476-68gc/GHSA-9f6h-w476-68gc.json | 8 ++------ .../11/GHSA-c4pf-hc84-698h/GHSA-c4pf-hc84-698h.json | 4 +--- .../11/GHSA-f578-gpwx-g2j4/GHSA-f578-gpwx-g2j4.json | 4 +--- .../11/GHSA-f7fq-hhg5-wjv8/GHSA-f7fq-hhg5-wjv8.json | 4 +--- .../11/GHSA-fjv6-j3p5-xvwr/GHSA-fjv6-j3p5-xvwr.json | 4 +--- .../11/GHSA-fr3h-4rcw-wvmj/GHSA-fr3h-4rcw-wvmj.json | 8 ++------ .../11/GHSA-fr3q-8g9r-hvpv/GHSA-fr3q-8g9r-hvpv.json | 4 +--- .../11/GHSA-g2jf-mr78-35jh/GHSA-g2jf-mr78-35jh.json | 4 +--- .../11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json | 4 +--- .../11/GHSA-g93m-8x6h-g5gv/GHSA-g93m-8x6h-g5gv.json | 4 +--- .../11/GHSA-gwr8-j573-qw62/GHSA-gwr8-j573-qw62.json | 4 +--- .../11/GHSA-h2c5-wxjr-xfwc/GHSA-h2c5-wxjr-xfwc.json | 4 +--- .../11/GHSA-h4jm-pc24-hx88/GHSA-h4jm-pc24-hx88.json | 4 +--- .../11/GHSA-hcpx-v556-ch6p/GHSA-hcpx-v556-ch6p.json | 8 ++------ .../11/GHSA-hhm7-rcc5-4hjc/GHSA-hhm7-rcc5-4hjc.json | 4 +--- .../11/GHSA-hmcg-rc8j-cqqx/GHSA-hmcg-rc8j-cqqx.json | 4 +--- .../11/GHSA-j7hj-68jp-pg28/GHSA-j7hj-68jp-pg28.json | 8 ++------ .../11/GHSA-j9g6-vvr6-x5wm/GHSA-j9g6-vvr6-x5wm.json | 4 +--- .../11/GHSA-jfqp-w655-72wj/GHSA-jfqp-w655-72wj.json | 4 +--- .../11/GHSA-jg3v-6rvm-6p3v/GHSA-jg3v-6rvm-6p3v.json | 4 +--- .../11/GHSA-jgqg-jqq9-5x4c/GHSA-jgqg-jqq9-5x4c.json | 4 +--- .../11/GHSA-jp5w-6447-j2m9/GHSA-jp5w-6447-j2m9.json | 8 ++------ .../11/GHSA-jv23-26jp-6g6v/GHSA-jv23-26jp-6g6v.json | 12 +++--------- .../11/GHSA-m7mj-xvm6-p76f/GHSA-m7mj-xvm6-p76f.json | 12 +++--------- .../11/GHSA-mfmj-7jv8-9x7x/GHSA-mfmj-7jv8-9x7x.json | 4 +--- .../11/GHSA-mhq2-gxcg-4hc8/GHSA-mhq2-gxcg-4hc8.json | 4 +--- .../11/GHSA-mw3p-xpcv-h9gq/GHSA-mw3p-xpcv-h9gq.json | 4 +--- .../11/GHSA-pcrp-7g2p-q7pj/GHSA-pcrp-7g2p-q7pj.json | 4 +--- .../11/GHSA-q37q-6c8j-qf6q/GHSA-q37q-6c8j-qf6q.json | 4 +--- .../11/GHSA-q97v-2cp6-jv6p/GHSA-q97v-2cp6-jv6p.json | 4 +--- .../11/GHSA-q9j8-8r5f-j3wm/GHSA-q9j8-8r5f-j3wm.json | 4 +--- .../11/GHSA-qrrf-258f-rprj/GHSA-qrrf-258f-rprj.json | 4 +--- .../11/GHSA-qw5j-33ph-5px7/GHSA-qw5j-33ph-5px7.json | 4 +--- .../11/GHSA-rq8f-77g8-6fm5/GHSA-rq8f-77g8-6fm5.json | 4 +--- .../11/GHSA-rxqh-7qx7-59m3/GHSA-rxqh-7qx7-59m3.json | 4 +--- .../11/GHSA-v957-pq3j-x7cq/GHSA-v957-pq3j-x7cq.json | 8 ++------ .../11/GHSA-vmh4-jpqm-9phr/GHSA-vmh4-jpqm-9phr.json | 4 +--- .../11/GHSA-w36j-hqcc-jvpp/GHSA-w36j-hqcc-jvpp.json | 4 +--- .../11/GHSA-w7fc-vcrq-2qq6/GHSA-w7fc-vcrq-2qq6.json | 4 +--- .../11/GHSA-w7p4-hj4q-wh7p/GHSA-w7p4-hj4q-wh7p.json | 4 +--- .../11/GHSA-wggp-3rr4-9fpj/GHSA-wggp-3rr4-9fpj.json | 4 +--- .../11/GHSA-wpp8-9p7m-8gx2/GHSA-wpp8-9p7m-8gx2.json | 4 +--- .../11/GHSA-wqmj-2mp9-xqmr/GHSA-wqmj-2mp9-xqmr.json | 4 +--- .../11/GHSA-wr5h-8pg2-5j9q/GHSA-wr5h-8pg2-5j9q.json | 4 +--- .../11/GHSA-wxg7-96h5-9qcc/GHSA-wxg7-96h5-9qcc.json | 4 +--- .../11/GHSA-x3fm-x4jg-jw2h/GHSA-x3fm-x4jg-jw2h.json | 4 +--- .../11/GHSA-xch5-v6mf-cvxj/GHSA-xch5-v6mf-cvxj.json | 4 +--- .../11/GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json | 4 +--- .../11/GHSA-xp7h-ghc6-47w2/GHSA-xp7h-ghc6-47w2.json | 4 +--- 916 files changed, 1952 insertions(+), 5844 deletions(-) diff --git a/advisories/github-reviewed/2022/04/GHSA-wm2r-rp98-8pmh/GHSA-wm2r-rp98-8pmh.json b/advisories/github-reviewed/2022/04/GHSA-wm2r-rp98-8pmh/GHSA-wm2r-rp98-8pmh.json index 9eba13ae32d..90c87c03a00 100644 --- a/advisories/github-reviewed/2022/04/GHSA-wm2r-rp98-8pmh/GHSA-wm2r-rp98-8pmh.json +++ b/advisories/github-reviewed/2022/04/GHSA-wm2r-rp98-8pmh/GHSA-wm2r-rp98-8pmh.json @@ -3,14 +3,10 @@ "id": "GHSA-wm2r-rp98-8pmh", "modified": "2022-04-27T21:09:13Z", "published": "2022-04-27T21:09:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "Exposure of SSH credentials in Rancher/Fleet", "details": "### Impact\nThis vulnerability only affects customers using Fleet for continuous delivery with authenticated Git and/or Helm repositories.\n\nA security vulnerability ([CVE-2022-29810](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29810)) was discovered in `go-getter` library in versions prior to [`v1.5.11`](https://github.com/hashicorp/go-getter/releases/tag/v1.5.11) that exposes SSH private keys in base64 format due to a failure in redacting such information from error messages. The vulnerable version of this library is used in Rancher through Fleet in versions of Fleet prior to [`v0.3.9`](https://github.com/rancher/fleet/releases/tag/v0.3.9). This issue affects Rancher versions 2.5.0 up to and including 2.5.12 and from 2.6.0 up to and including 2.6.3.\n\nWhen Git and/or Helm authentication is configured in [Fleet](https://rancher.com/docs/rancher/v2.6/en/deploy-across-clusters/fleet/) and Fleet is used to deploy a git repo through `Continuous Delivery`, the affected `go-getter` version will expose the configured SSH private key secret if Fleet fails to download the git repo due to a misconfigured URL. The exposed SSH key is logged in base64 format as a query parameter together with the git URL. The credentials can be seen in Rancher UI and in Fleet's deployment pod logs.\n\n### Patches\nPatched versions include releases 2.5.13, 2.6.4 and later versions.\n\n### Workarounds\nThere is not a direct mitigation besides upgrading to the patched Rancher versions. Until you are able to upgrade, limit access in Rancher to trusted users and carefully validate the URLs you are using are correct. Please note that the SSH key might still be compromised in valid URLs if the service goes down or a connection error happens when pulling from the repos.\n\n**Note:** If you believe that SSH keys might have been exposed in your environment, it's highly advised to rotate them.\n\n### Credits\nThis issue was found and reported by Dagan Henderson from Raft Engineering.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Reach out to [SUSE Rancher Security team](https://github.com/rancher/rancher/security/policy) for security related inquiries.\n* Open an issue in [Rancher](https://github.com/rancher/rancher/issues/new/choose) repository.\n* Verify our [support matrix](https://www.suse.com/suse-rancher/support-matrix/all-supported-versions/) and [product support lifecycle](https://www.suse.com/lifecycle/).", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-2x55-mg9r-24f7/GHSA-2x55-mg9r-24f7.json b/advisories/github-reviewed/2022/05/GHSA-2x55-mg9r-24f7/GHSA-2x55-mg9r-24f7.json index d37f5f64f3d..88b2d08c8a5 100644 --- a/advisories/github-reviewed/2022/05/GHSA-2x55-mg9r-24f7/GHSA-2x55-mg9r-24f7.json +++ b/advisories/github-reviewed/2022/05/GHSA-2x55-mg9r-24f7/GHSA-2x55-mg9r-24f7.json @@ -92,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-07-17T20:34:52Z", diff --git a/advisories/github-reviewed/2022/10/GHSA-4m5p-5w5w-3jcf/GHSA-4m5p-5w5w-3jcf.json b/advisories/github-reviewed/2022/10/GHSA-4m5p-5w5w-3jcf/GHSA-4m5p-5w5w-3jcf.json index 0c9aadd6bae..be59c82177f 100644 --- a/advisories/github-reviewed/2022/10/GHSA-4m5p-5w5w-3jcf/GHSA-4m5p-5w5w-3jcf.json +++ b/advisories/github-reviewed/2022/10/GHSA-4m5p-5w5w-3jcf/GHSA-4m5p-5w5w-3jcf.json @@ -3,14 +3,10 @@ "id": "GHSA-4m5p-5w5w-3jcf", "modified": "2024-03-01T15:01:10Z", "published": "2022-10-12T20:13:46Z", - "aliases": [ - - ], + "aliases": [], "summary": "com.enonic.xp:lib-auth vulnerable to Session Fixation", "details": "### Impact\nAll id-providers using lib-auth `login` method.\n\n### Patches\nhttps://github.com/enonic/xp/commit/0189975691e9e6407a9fee87006f730e84f734ff\nhttps://github.com/enonic/xp/commit/2abac31cec8679074debc4f1fb69c25930e40842\nhttps://github.com/enonic/xp/commit/1f44674eb9ab3fbab7103e8d08067846e88bace4\n\n### Workarounds\nDon't use lib-auth for `login`. \nJava API uses low-level structures and allows to invalidate previous session before auth-info is added.\n\n### References\n\nhttps://github.com/enonic/xp/issues/9253", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/01/GHSA-vm74-j4wq-82xj/GHSA-vm74-j4wq-82xj.json b/advisories/github-reviewed/2023/01/GHSA-vm74-j4wq-82xj/GHSA-vm74-j4wq-82xj.json index b2e8a21103a..f9e33a67fda 100644 --- a/advisories/github-reviewed/2023/01/GHSA-vm74-j4wq-82xj/GHSA-vm74-j4wq-82xj.json +++ b/advisories/github-reviewed/2023/01/GHSA-vm74-j4wq-82xj/GHSA-vm74-j4wq-82xj.json @@ -8,9 +8,7 @@ ], "summary": "Sisimai Inefficient Regular Expression Complexity vulnerability", "details": "A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the function `to_plain` of the file `lib/sisimai/string.rb`. The manipulation leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. Upgrading to version 4.25.14p12 is able to address this issue. The name of the patch is 51fe2e6521c9c02b421b383943dc9e4bbbe65d4e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218452.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/09/GHSA-7x4w-cj9r-h4v9/GHSA-7x4w-cj9r-h4v9.json b/advisories/github-reviewed/2024/09/GHSA-7x4w-cj9r-h4v9/GHSA-7x4w-cj9r-h4v9.json index 9214616136e..6acceaffcb2 100644 --- a/advisories/github-reviewed/2024/09/GHSA-7x4w-cj9r-h4v9/GHSA-7x4w-cj9r-h4v9.json +++ b/advisories/github-reviewed/2024/09/GHSA-7x4w-cj9r-h4v9/GHSA-7x4w-cj9r-h4v9.json @@ -3,9 +3,7 @@ "id": "GHSA-7x4w-cj9r-h4v9", "modified": "2024-09-18T15:48:29Z", "published": "2024-09-18T15:47:07Z", - "aliases": [ - - ], + "aliases": [], "summary": "Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185)", "details": "The [actions](https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/controllers/camaleon_cms/admin/media_controller.rb#L51-L52) defined inside of the MediaController class do not check whether a given path is inside a certain path (e.g. inside the media folder). If an attacker performed an account takeover of an administrator account (See: GHSL-2024-184) they could delete arbitrary files or folders on the server hosting Camaleon CMS. The [crop_url](https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/controllers/camaleon_cms/admin/media_controller.rb#L64-L65) action might make arbitrary file writes (similar impact to GHSL-2024-182) for any authenticated user possible, but it doesn't seem to work currently.\n\nArbitrary file deletion can be exploited with following code path: The parameter folder flows from the actions method:\n```ruby\n def actions\n authorize! :manage, :media if params[:media_action] != 'crop_url'\n params[:folder] = params[:folder].gsub('//', '/') if params[:folder].present?\n case params[:media_action]\n [..]\n when 'del_file'\n cama_uploader.delete_file(params[:folder].gsub('//', '/'))\n render plain: ''\n```\ninto the method delete_file of the CamaleonCmsLocalUploader class (when files are uploaded locally):\n```ruby\ndef delete_file(key)\n file = File.join(@root_folder, key)\n FileUtils.rm(file) if File.exist? file\n @instance.hooks_run('after_delete', key)\n get_media_collection.find_by_key(key).take.destroy\nend\n```\nWhere it is joined in an unchecked manner with the root folder and then deleted.\n\n**Proof of concept**\nThe following request would delete the file README.md in the top folder of the Ruby on Rails application. (The values for auth_token, X-CSRF-Token and _cms_session would also need to be replaced with authenticated values in the curl command below)\n```\ncurl --path-as-is -i -s -k -X $'POST' \\\n -H $'X-CSRF-Token: [..]' -H $'User-Agent: Mozilla/5.0' -H $'Content-Type: application/x-www-form-urlencoded; charset=UTF-8' -H $'Accept: */*' -H $'Connection: keep-alive' \\\n -b $'auth_token=[..]; _cms_session=[..]' \\\n --data-binary $'versions=&thumb_size=&formats=&media_formats=&dimension=&private=&folder=..%2F..%2F..%2FREADME.md&media_action=del_file' \\\n $'https:///admin/media/actions?actions=true'\n```\n**Impact**\nThis issue may lead to a defective CMS or system.\n\n**Remediation**\nNormalize all file paths constructed from untrusted user input before using them and check that the resulting path is inside the targeted directory. Additionally, do not allow character sequences such as .. in untrusted input that is used to build paths.\n\n**See also:**\n\n[CodeQL: Uncontrolled data used in path expression](https://codeql.github.com/codeql-query-help/ruby/rb-path-injection/)\n[OWASP: Path Traversal](https://owasp.org/www-community/attacks/Path_Traversal)", "severity": [ diff --git a/advisories/github-reviewed/2024/09/GHSA-jhg6-6qrx-38mr/GHSA-jhg6-6qrx-38mr.json b/advisories/github-reviewed/2024/09/GHSA-jhg6-6qrx-38mr/GHSA-jhg6-6qrx-38mr.json index d7d4f58ba68..a8f28f7f2ff 100644 --- a/advisories/github-reviewed/2024/09/GHSA-jhg6-6qrx-38mr/GHSA-jhg6-6qrx-38mr.json +++ b/advisories/github-reviewed/2024/09/GHSA-jhg6-6qrx-38mr/GHSA-jhg6-6qrx-38mr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhg6-6qrx-38mr", - "modified": "2024-09-18T19:26:18Z", + "modified": "2024-11-18T16:27:14Z", "published": "2024-09-18T17:42:46Z", "aliases": [ "CVE-2024-46989" @@ -66,7 +66,7 @@ "CWE-269", "CWE-285" ], - "severity": "LOW", + "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-09-18T17:42:46Z", "nvd_published_at": "2024-09-18T18:15:07Z" diff --git a/advisories/github-reviewed/2024/09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json b/advisories/github-reviewed/2024/09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json index 8805ae8f720..68f39fc79e4 100644 --- a/advisories/github-reviewed/2024/09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json +++ b/advisories/github-reviewed/2024/09/GHSA-qf6m-6m4g-rmrc/GHSA-qf6m-6m4g-rmrc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf6m-6m4g-rmrc", - "modified": "2024-09-18T22:06:13Z", + "modified": "2024-11-18T16:27:14Z", "published": "2024-09-18T22:06:13Z", "aliases": [ "CVE-2024-47051" @@ -118,7 +118,7 @@ "cwe_ids": [ "CWE-306" ], - "severity": "HIGH", + "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-09-18T22:06:13Z", "nvd_published_at": null diff --git a/advisories/github-reviewed/2024/09/GHSA-r95w-889q-x2gx/GHSA-r95w-889q-x2gx.json b/advisories/github-reviewed/2024/09/GHSA-r95w-889q-x2gx/GHSA-r95w-889q-x2gx.json index f2febf7269f..18891ae3952 100644 --- a/advisories/github-reviewed/2024/09/GHSA-r95w-889q-x2gx/GHSA-r95w-889q-x2gx.json +++ b/advisories/github-reviewed/2024/09/GHSA-r95w-889q-x2gx/GHSA-r95w-889q-x2gx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r95w-889q-x2gx", - "modified": "2024-09-18T19:23:07Z", + "modified": "2024-11-18T16:27:14Z", "published": "2024-09-18T14:26:16Z", "aliases": [ "CVE-2024-46978" @@ -115,7 +115,7 @@ "cwe_ids": [ "CWE-648" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-09-18T14:26:16Z", "nvd_published_at": "2024-09-18T18:15:06Z" diff --git a/advisories/github-reviewed/2024/09/GHSA-r9cr-qmfw-pmrc/GHSA-r9cr-qmfw-pmrc.json b/advisories/github-reviewed/2024/09/GHSA-r9cr-qmfw-pmrc/GHSA-r9cr-qmfw-pmrc.json index 1d0f0172f95..3250abb0e4b 100644 --- a/advisories/github-reviewed/2024/09/GHSA-r9cr-qmfw-pmrc/GHSA-r9cr-qmfw-pmrc.json +++ b/advisories/github-reviewed/2024/09/GHSA-r9cr-qmfw-pmrc/GHSA-r9cr-qmfw-pmrc.json @@ -3,9 +3,7 @@ "id": "GHSA-r9cr-qmfw-pmrc", "modified": "2024-09-18T15:47:57Z", "published": "2024-09-18T15:47:01Z", - "aliases": [ - - ], + "aliases": [], "summary": "Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)", "details": "A stored cross-site scripting has been found in the image upload functionality that can be used by normal registered users: It is possible to upload a SVG image containing JavaScript and it's also possible to upload a HTML document when the format parameter is manually changed to [documents](https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/uploaders/camaleon_cms_uploader.rb#L105-L106) or a string of an [unsupported format](https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/uploaders/camaleon_cms_uploader.rb#L110-L111). If an authenticated user or administrator visits that uploaded image or document malicious JavaScript can be executed on their behalf (e.g. changing or deleting content inside of the CMS.)\n\nProof of concept\nLogin as a normal user (if user signup is enabled).\nGo to the user's profile.\nAnd upload the following profile picture via drag and drop.\nThe content of the SVG file could be as follows (e.g. name it test-xss.svg):\n\n\n\n \n \n \n \n \n\nThe server might fail with a 500 internal server error, but the uploaded image should be available at a location like https:///media/1/test-xss-cookie.svg. If an authenticated user or administrator accesses that link their auth_token is reflected. Since the auth_token cookie contains a static [auth token](https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/models/concerns/camaleon_cms/user_methods.rb#L18-L19) value that only changes when a user changes their password.\n\nImpact\nThis issue may lead to account takeover due to reflected Cross-site scripting (XSS).\n\nRemediation\nOnly allow the upload of safe files such as PNG, TXT and others or serve all \"unsafe\" files such as SVG and other files with a content-disposition: attachment header, which should prevent browsers from displaying them.\n\nAdditionally, a [Content security policy (CSP)](https://web.dev/articles/csp) can be created that disallows inlined script. (Other parts of the application might need modification to continue functioning.)\n\nTo prevent the theft of the auth_token it could be marked with HttpOnly. This would however not prevent that actions could be performed as the authenticated user/administrator. Furthermore, it could make sense to use the authentication provided by Ruby on Rails, so that stolen tokens cannot be used anymore after some time.", "severity": [ diff --git a/advisories/github-reviewed/2024/10/GHSA-wwcp-26wc-3fxm/GHSA-wwcp-26wc-3fxm.json b/advisories/github-reviewed/2024/10/GHSA-wwcp-26wc-3fxm/GHSA-wwcp-26wc-3fxm.json index 7ae7b3f9bc3..cbc29415d26 100644 --- a/advisories/github-reviewed/2024/10/GHSA-wwcp-26wc-3fxm/GHSA-wwcp-26wc-3fxm.json +++ b/advisories/github-reviewed/2024/10/GHSA-wwcp-26wc-3fxm/GHSA-wwcp-26wc-3fxm.json @@ -58,9 +58,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-10-04T18:51:45Z", diff --git a/advisories/github-reviewed/2024/11/GHSA-vjmm-r9gg-425m/GHSA-vjmm-r9gg-425m.json b/advisories/github-reviewed/2024/11/GHSA-vjmm-r9gg-425m/GHSA-vjmm-r9gg-425m.json index 9328e0e38c9..661232809b0 100644 --- a/advisories/github-reviewed/2024/11/GHSA-vjmm-r9gg-425m/GHSA-vjmm-r9gg-425m.json +++ b/advisories/github-reviewed/2024/11/GHSA-vjmm-r9gg-425m/GHSA-vjmm-r9gg-425m.json @@ -119,9 +119,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-11-07T18:19:24Z", diff --git a/advisories/unreviewed/2021/12/GHSA-fcp5-xgmc-3mgm/GHSA-fcp5-xgmc-3mgm.json b/advisories/unreviewed/2021/12/GHSA-fcp5-xgmc-3mgm/GHSA-fcp5-xgmc-3mgm.json index 0a68069d2f3..97b712999ea 100644 --- a/advisories/unreviewed/2021/12/GHSA-fcp5-xgmc-3mgm/GHSA-fcp5-xgmc-3mgm.json +++ b/advisories/unreviewed/2021/12/GHSA-fcp5-xgmc-3mgm/GHSA-fcp5-xgmc-3mgm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2021/12/GHSA-hcc9-4397-fcwc/GHSA-hcc9-4397-fcwc.json b/advisories/unreviewed/2021/12/GHSA-hcc9-4397-fcwc/GHSA-hcc9-4397-fcwc.json index 7a0eab163c6..eab417ea71f 100644 --- a/advisories/unreviewed/2021/12/GHSA-hcc9-4397-fcwc/GHSA-hcc9-4397-fcwc.json +++ b/advisories/unreviewed/2021/12/GHSA-hcc9-4397-fcwc/GHSA-hcc9-4397-fcwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-fv2j-f74f-8cgr/GHSA-fv2j-f74f-8cgr.json b/advisories/unreviewed/2022/02/GHSA-fv2j-f74f-8cgr/GHSA-fv2j-f74f-8cgr.json index efa50ebd690..8aac4e56407 100644 --- a/advisories/unreviewed/2022/02/GHSA-fv2j-f74f-8cgr/GHSA-fv2j-f74f-8cgr.json +++ b/advisories/unreviewed/2022/02/GHSA-fv2j-f74f-8cgr/GHSA-fv2j-f74f-8cgr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-cg79-xxvp-6224/GHSA-cg79-xxvp-6224.json b/advisories/unreviewed/2022/03/GHSA-cg79-xxvp-6224/GHSA-cg79-xxvp-6224.json index 626f434b8d0..4b4b1d5d4fd 100644 --- a/advisories/unreviewed/2022/03/GHSA-cg79-xxvp-6224/GHSA-cg79-xxvp-6224.json +++ b/advisories/unreviewed/2022/03/GHSA-cg79-xxvp-6224/GHSA-cg79-xxvp-6224.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-268w-8v2j-mm3q/GHSA-268w-8v2j-mm3q.json b/advisories/unreviewed/2022/04/GHSA-268w-8v2j-mm3q/GHSA-268w-8v2j-mm3q.json index 7972f16bae2..44aab4a5b0f 100644 --- a/advisories/unreviewed/2022/04/GHSA-268w-8v2j-mm3q/GHSA-268w-8v2j-mm3q.json +++ b/advisories/unreviewed/2022/04/GHSA-268w-8v2j-mm3q/GHSA-268w-8v2j-mm3q.json @@ -7,12 +7,8 @@ "CVE-2002-1774" ], "details": "** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to send viruses that bypass the e-mail scanning via a NULL character in the MIME header before the virus. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the AutoProtect feature would detect the virus before it is executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-27j2-98fj-7r5w/GHSA-27j2-98fj-7r5w.json b/advisories/unreviewed/2022/04/GHSA-27j2-98fj-7r5w/GHSA-27j2-98fj-7r5w.json index f36f2ef1f0a..b068afa72fa 100644 --- a/advisories/unreviewed/2022/04/GHSA-27j2-98fj-7r5w/GHSA-27j2-98fj-7r5w.json +++ b/advisories/unreviewed/2022/04/GHSA-27j2-98fj-7r5w/GHSA-27j2-98fj-7r5w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2qxr-5pf2-3p3h/GHSA-2qxr-5pf2-3p3h.json b/advisories/unreviewed/2022/04/GHSA-2qxr-5pf2-3p3h/GHSA-2qxr-5pf2-3p3h.json index 46dfc89c888..e7d64c71ec8 100644 --- a/advisories/unreviewed/2022/04/GHSA-2qxr-5pf2-3p3h/GHSA-2qxr-5pf2-3p3h.json +++ b/advisories/unreviewed/2022/04/GHSA-2qxr-5pf2-3p3h/GHSA-2qxr-5pf2-3p3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2vfm-65cj-5j48/GHSA-2vfm-65cj-5j48.json b/advisories/unreviewed/2022/04/GHSA-2vfm-65cj-5j48/GHSA-2vfm-65cj-5j48.json index d64078f62d5..4fdabb8c10e 100644 --- a/advisories/unreviewed/2022/04/GHSA-2vfm-65cj-5j48/GHSA-2vfm-65cj-5j48.json +++ b/advisories/unreviewed/2022/04/GHSA-2vfm-65cj-5j48/GHSA-2vfm-65cj-5j48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-47wr-f5xm-h9x4/GHSA-47wr-f5xm-h9x4.json b/advisories/unreviewed/2022/04/GHSA-47wr-f5xm-h9x4/GHSA-47wr-f5xm-h9x4.json index e986f2a8d75..699264001de 100644 --- a/advisories/unreviewed/2022/04/GHSA-47wr-f5xm-h9x4/GHSA-47wr-f5xm-h9x4.json +++ b/advisories/unreviewed/2022/04/GHSA-47wr-f5xm-h9x4/GHSA-47wr-f5xm-h9x4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4cxq-fp26-wf3w/GHSA-4cxq-fp26-wf3w.json b/advisories/unreviewed/2022/04/GHSA-4cxq-fp26-wf3w/GHSA-4cxq-fp26-wf3w.json index c6e3b4d8878..473123407d6 100644 --- a/advisories/unreviewed/2022/04/GHSA-4cxq-fp26-wf3w/GHSA-4cxq-fp26-wf3w.json +++ b/advisories/unreviewed/2022/04/GHSA-4cxq-fp26-wf3w/GHSA-4cxq-fp26-wf3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4hqp-qgvw-892g/GHSA-4hqp-qgvw-892g.json b/advisories/unreviewed/2022/04/GHSA-4hqp-qgvw-892g/GHSA-4hqp-qgvw-892g.json index 7af3047734d..93a9c476424 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hqp-qgvw-892g/GHSA-4hqp-qgvw-892g.json +++ b/advisories/unreviewed/2022/04/GHSA-4hqp-qgvw-892g/GHSA-4hqp-qgvw-892g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4w23-87xc-gg8q/GHSA-4w23-87xc-gg8q.json b/advisories/unreviewed/2022/04/GHSA-4w23-87xc-gg8q/GHSA-4w23-87xc-gg8q.json index 0669ec97628..ec94900d6c6 100644 --- a/advisories/unreviewed/2022/04/GHSA-4w23-87xc-gg8q/GHSA-4w23-87xc-gg8q.json +++ b/advisories/unreviewed/2022/04/GHSA-4w23-87xc-gg8q/GHSA-4w23-87xc-gg8q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6v84-2ccf-99qx/GHSA-6v84-2ccf-99qx.json b/advisories/unreviewed/2022/04/GHSA-6v84-2ccf-99qx/GHSA-6v84-2ccf-99qx.json index a904ad6f8a1..5a9f6afc24d 100644 --- a/advisories/unreviewed/2022/04/GHSA-6v84-2ccf-99qx/GHSA-6v84-2ccf-99qx.json +++ b/advisories/unreviewed/2022/04/GHSA-6v84-2ccf-99qx/GHSA-6v84-2ccf-99qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6x84-fx3m-vx33/GHSA-6x84-fx3m-vx33.json b/advisories/unreviewed/2022/04/GHSA-6x84-fx3m-vx33/GHSA-6x84-fx3m-vx33.json index 845ca21f15b..6ddf3a1016e 100644 --- a/advisories/unreviewed/2022/04/GHSA-6x84-fx3m-vx33/GHSA-6x84-fx3m-vx33.json +++ b/advisories/unreviewed/2022/04/GHSA-6x84-fx3m-vx33/GHSA-6x84-fx3m-vx33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-734j-8w33-h29h/GHSA-734j-8w33-h29h.json b/advisories/unreviewed/2022/04/GHSA-734j-8w33-h29h/GHSA-734j-8w33-h29h.json index f4718f37066..c70c6173c2f 100644 --- a/advisories/unreviewed/2022/04/GHSA-734j-8w33-h29h/GHSA-734j-8w33-h29h.json +++ b/advisories/unreviewed/2022/04/GHSA-734j-8w33-h29h/GHSA-734j-8w33-h29h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-78cg-x7rx-442v/GHSA-78cg-x7rx-442v.json b/advisories/unreviewed/2022/04/GHSA-78cg-x7rx-442v/GHSA-78cg-x7rx-442v.json index 8b0d2098593..103685b82c4 100644 --- a/advisories/unreviewed/2022/04/GHSA-78cg-x7rx-442v/GHSA-78cg-x7rx-442v.json +++ b/advisories/unreviewed/2022/04/GHSA-78cg-x7rx-442v/GHSA-78cg-x7rx-442v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-93jw-9wg6-48pf/GHSA-93jw-9wg6-48pf.json b/advisories/unreviewed/2022/04/GHSA-93jw-9wg6-48pf/GHSA-93jw-9wg6-48pf.json index 713f7cdb7f3..81e51f2c0e0 100644 --- a/advisories/unreviewed/2022/04/GHSA-93jw-9wg6-48pf/GHSA-93jw-9wg6-48pf.json +++ b/advisories/unreviewed/2022/04/GHSA-93jw-9wg6-48pf/GHSA-93jw-9wg6-48pf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-9j5j-gv7x-3rjf/GHSA-9j5j-gv7x-3rjf.json b/advisories/unreviewed/2022/04/GHSA-9j5j-gv7x-3rjf/GHSA-9j5j-gv7x-3rjf.json index 66d0a1f42ea..b754a376d62 100644 --- a/advisories/unreviewed/2022/04/GHSA-9j5j-gv7x-3rjf/GHSA-9j5j-gv7x-3rjf.json +++ b/advisories/unreviewed/2022/04/GHSA-9j5j-gv7x-3rjf/GHSA-9j5j-gv7x-3rjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-c2fj-f4xg-p3qr/GHSA-c2fj-f4xg-p3qr.json b/advisories/unreviewed/2022/04/GHSA-c2fj-f4xg-p3qr/GHSA-c2fj-f4xg-p3qr.json index 839779851cd..2a14b33bf3a 100644 --- a/advisories/unreviewed/2022/04/GHSA-c2fj-f4xg-p3qr/GHSA-c2fj-f4xg-p3qr.json +++ b/advisories/unreviewed/2022/04/GHSA-c2fj-f4xg-p3qr/GHSA-c2fj-f4xg-p3qr.json @@ -7,12 +7,8 @@ "CVE-2002-1776" ], "details": "** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f27m-q7gr-7676/GHSA-f27m-q7gr-7676.json b/advisories/unreviewed/2022/04/GHSA-f27m-q7gr-7676/GHSA-f27m-q7gr-7676.json index 9f48bf43f1e..83a8ecb12b8 100644 --- a/advisories/unreviewed/2022/04/GHSA-f27m-q7gr-7676/GHSA-f27m-q7gr-7676.json +++ b/advisories/unreviewed/2022/04/GHSA-f27m-q7gr-7676/GHSA-f27m-q7gr-7676.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-f4rg-w9qm-5f42/GHSA-f4rg-w9qm-5f42.json b/advisories/unreviewed/2022/04/GHSA-f4rg-w9qm-5f42/GHSA-f4rg-w9qm-5f42.json index 5d595c535b6..8243819ea66 100644 --- a/advisories/unreviewed/2022/04/GHSA-f4rg-w9qm-5f42/GHSA-f4rg-w9qm-5f42.json +++ b/advisories/unreviewed/2022/04/GHSA-f4rg-w9qm-5f42/GHSA-f4rg-w9qm-5f42.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-fmjf-pw3c-qpxg/GHSA-fmjf-pw3c-qpxg.json b/advisories/unreviewed/2022/04/GHSA-fmjf-pw3c-qpxg/GHSA-fmjf-pw3c-qpxg.json index 3e407a8cdc9..903ce053268 100644 --- a/advisories/unreviewed/2022/04/GHSA-fmjf-pw3c-qpxg/GHSA-fmjf-pw3c-qpxg.json +++ b/advisories/unreviewed/2022/04/GHSA-fmjf-pw3c-qpxg/GHSA-fmjf-pw3c-qpxg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-fpfj-wp86-qmrq/GHSA-fpfj-wp86-qmrq.json b/advisories/unreviewed/2022/04/GHSA-fpfj-wp86-qmrq/GHSA-fpfj-wp86-qmrq.json index 3ec6b13cd59..88f8dca535f 100644 --- a/advisories/unreviewed/2022/04/GHSA-fpfj-wp86-qmrq/GHSA-fpfj-wp86-qmrq.json +++ b/advisories/unreviewed/2022/04/GHSA-fpfj-wp86-qmrq/GHSA-fpfj-wp86-qmrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-g9fr-9797-g6c3/GHSA-g9fr-9797-g6c3.json b/advisories/unreviewed/2022/04/GHSA-g9fr-9797-g6c3/GHSA-g9fr-9797-g6c3.json index efd3a6d842b..8020c005956 100644 --- a/advisories/unreviewed/2022/04/GHSA-g9fr-9797-g6c3/GHSA-g9fr-9797-g6c3.json +++ b/advisories/unreviewed/2022/04/GHSA-g9fr-9797-g6c3/GHSA-g9fr-9797-g6c3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gc9v-rxqh-j677/GHSA-gc9v-rxqh-j677.json b/advisories/unreviewed/2022/04/GHSA-gc9v-rxqh-j677/GHSA-gc9v-rxqh-j677.json index c7bb56d478e..82536dcc43e 100644 --- a/advisories/unreviewed/2022/04/GHSA-gc9v-rxqh-j677/GHSA-gc9v-rxqh-j677.json +++ b/advisories/unreviewed/2022/04/GHSA-gc9v-rxqh-j677/GHSA-gc9v-rxqh-j677.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gx2c-m4w2-5499/GHSA-gx2c-m4w2-5499.json b/advisories/unreviewed/2022/04/GHSA-gx2c-m4w2-5499/GHSA-gx2c-m4w2-5499.json index 5674b028bde..9689198087e 100644 --- a/advisories/unreviewed/2022/04/GHSA-gx2c-m4w2-5499/GHSA-gx2c-m4w2-5499.json +++ b/advisories/unreviewed/2022/04/GHSA-gx2c-m4w2-5499/GHSA-gx2c-m4w2-5499.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hgq7-cw57-j447/GHSA-hgq7-cw57-j447.json b/advisories/unreviewed/2022/04/GHSA-hgq7-cw57-j447/GHSA-hgq7-cw57-j447.json index 27d01343371..aa923a00e07 100644 --- a/advisories/unreviewed/2022/04/GHSA-hgq7-cw57-j447/GHSA-hgq7-cw57-j447.json +++ b/advisories/unreviewed/2022/04/GHSA-hgq7-cw57-j447/GHSA-hgq7-cw57-j447.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-j784-xw9c-263h/GHSA-j784-xw9c-263h.json b/advisories/unreviewed/2022/04/GHSA-j784-xw9c-263h/GHSA-j784-xw9c-263h.json index 62025215b07..d2297229c9f 100644 --- a/advisories/unreviewed/2022/04/GHSA-j784-xw9c-263h/GHSA-j784-xw9c-263h.json +++ b/advisories/unreviewed/2022/04/GHSA-j784-xw9c-263h/GHSA-j784-xw9c-263h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-j8gx-mvv5-fx5w/GHSA-j8gx-mvv5-fx5w.json b/advisories/unreviewed/2022/04/GHSA-j8gx-mvv5-fx5w/GHSA-j8gx-mvv5-fx5w.json index 4d80d1ce8a1..30191207c49 100644 --- a/advisories/unreviewed/2022/04/GHSA-j8gx-mvv5-fx5w/GHSA-j8gx-mvv5-fx5w.json +++ b/advisories/unreviewed/2022/04/GHSA-j8gx-mvv5-fx5w/GHSA-j8gx-mvv5-fx5w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-jrp8-rcj4-qwj2/GHSA-jrp8-rcj4-qwj2.json b/advisories/unreviewed/2022/04/GHSA-jrp8-rcj4-qwj2/GHSA-jrp8-rcj4-qwj2.json index 5c6b7a273e5..1cfc1eb0f8b 100644 --- a/advisories/unreviewed/2022/04/GHSA-jrp8-rcj4-qwj2/GHSA-jrp8-rcj4-qwj2.json +++ b/advisories/unreviewed/2022/04/GHSA-jrp8-rcj4-qwj2/GHSA-jrp8-rcj4-qwj2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-m4qj-mfxh-2v5c/GHSA-m4qj-mfxh-2v5c.json b/advisories/unreviewed/2022/04/GHSA-m4qj-mfxh-2v5c/GHSA-m4qj-mfxh-2v5c.json index abb4b5b4a73..2b30b8aa4ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-m4qj-mfxh-2v5c/GHSA-m4qj-mfxh-2v5c.json +++ b/advisories/unreviewed/2022/04/GHSA-m4qj-mfxh-2v5c/GHSA-m4qj-mfxh-2v5c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-m5h3-6h9f-c785/GHSA-m5h3-6h9f-c785.json b/advisories/unreviewed/2022/04/GHSA-m5h3-6h9f-c785/GHSA-m5h3-6h9f-c785.json index 495e95967ae..cea4ac015ec 100644 --- a/advisories/unreviewed/2022/04/GHSA-m5h3-6h9f-c785/GHSA-m5h3-6h9f-c785.json +++ b/advisories/unreviewed/2022/04/GHSA-m5h3-6h9f-c785/GHSA-m5h3-6h9f-c785.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mpvv-4h9p-33x4/GHSA-mpvv-4h9p-33x4.json b/advisories/unreviewed/2022/04/GHSA-mpvv-4h9p-33x4/GHSA-mpvv-4h9p-33x4.json index f57707f53b0..db565212816 100644 --- a/advisories/unreviewed/2022/04/GHSA-mpvv-4h9p-33x4/GHSA-mpvv-4h9p-33x4.json +++ b/advisories/unreviewed/2022/04/GHSA-mpvv-4h9p-33x4/GHSA-mpvv-4h9p-33x4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mrf8-4j8f-g2hr/GHSA-mrf8-4j8f-g2hr.json b/advisories/unreviewed/2022/04/GHSA-mrf8-4j8f-g2hr/GHSA-mrf8-4j8f-g2hr.json index 599ff9f3890..c9e35dd51ea 100644 --- a/advisories/unreviewed/2022/04/GHSA-mrf8-4j8f-g2hr/GHSA-mrf8-4j8f-g2hr.json +++ b/advisories/unreviewed/2022/04/GHSA-mrf8-4j8f-g2hr/GHSA-mrf8-4j8f-g2hr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-p4mq-j63q-grfw/GHSA-p4mq-j63q-grfw.json b/advisories/unreviewed/2022/04/GHSA-p4mq-j63q-grfw/GHSA-p4mq-j63q-grfw.json index 1b4765ac8da..2fbdd9f8368 100644 --- a/advisories/unreviewed/2022/04/GHSA-p4mq-j63q-grfw/GHSA-p4mq-j63q-grfw.json +++ b/advisories/unreviewed/2022/04/GHSA-p4mq-j63q-grfw/GHSA-p4mq-j63q-grfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-p7m9-59wp-jx9r/GHSA-p7m9-59wp-jx9r.json b/advisories/unreviewed/2022/04/GHSA-p7m9-59wp-jx9r/GHSA-p7m9-59wp-jx9r.json index ec0bcca84b1..aa017010d6a 100644 --- a/advisories/unreviewed/2022/04/GHSA-p7m9-59wp-jx9r/GHSA-p7m9-59wp-jx9r.json +++ b/advisories/unreviewed/2022/04/GHSA-p7m9-59wp-jx9r/GHSA-p7m9-59wp-jx9r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-pp6m-h8ww-pq5r/GHSA-pp6m-h8ww-pq5r.json b/advisories/unreviewed/2022/04/GHSA-pp6m-h8ww-pq5r/GHSA-pp6m-h8ww-pq5r.json index 06764948203..7dfb3463b4f 100644 --- a/advisories/unreviewed/2022/04/GHSA-pp6m-h8ww-pq5r/GHSA-pp6m-h8ww-pq5r.json +++ b/advisories/unreviewed/2022/04/GHSA-pp6m-h8ww-pq5r/GHSA-pp6m-h8ww-pq5r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qr34-62c5-85qp/GHSA-qr34-62c5-85qp.json b/advisories/unreviewed/2022/04/GHSA-qr34-62c5-85qp/GHSA-qr34-62c5-85qp.json index 60e7a7e4303..0464e70fbe2 100644 --- a/advisories/unreviewed/2022/04/GHSA-qr34-62c5-85qp/GHSA-qr34-62c5-85qp.json +++ b/advisories/unreviewed/2022/04/GHSA-qr34-62c5-85qp/GHSA-qr34-62c5-85qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qrpm-2f6m-pf3c/GHSA-qrpm-2f6m-pf3c.json b/advisories/unreviewed/2022/04/GHSA-qrpm-2f6m-pf3c/GHSA-qrpm-2f6m-pf3c.json index 44c59681087..2d07ac484c8 100644 --- a/advisories/unreviewed/2022/04/GHSA-qrpm-2f6m-pf3c/GHSA-qrpm-2f6m-pf3c.json +++ b/advisories/unreviewed/2022/04/GHSA-qrpm-2f6m-pf3c/GHSA-qrpm-2f6m-pf3c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-r3cc-j9xh-27gw/GHSA-r3cc-j9xh-27gw.json b/advisories/unreviewed/2022/04/GHSA-r3cc-j9xh-27gw/GHSA-r3cc-j9xh-27gw.json index 040537e05fb..4b76c7787fc 100644 --- a/advisories/unreviewed/2022/04/GHSA-r3cc-j9xh-27gw/GHSA-r3cc-j9xh-27gw.json +++ b/advisories/unreviewed/2022/04/GHSA-r3cc-j9xh-27gw/GHSA-r3cc-j9xh-27gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rv49-vc49-4rpp/GHSA-rv49-vc49-4rpp.json b/advisories/unreviewed/2022/04/GHSA-rv49-vc49-4rpp/GHSA-rv49-vc49-4rpp.json index 862b654321d..794d8d220ff 100644 --- a/advisories/unreviewed/2022/04/GHSA-rv49-vc49-4rpp/GHSA-rv49-vc49-4rpp.json +++ b/advisories/unreviewed/2022/04/GHSA-rv49-vc49-4rpp/GHSA-rv49-vc49-4rpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rxjg-q5c5-6q8f/GHSA-rxjg-q5c5-6q8f.json b/advisories/unreviewed/2022/04/GHSA-rxjg-q5c5-6q8f/GHSA-rxjg-q5c5-6q8f.json index 0e1ed83e5c8..7bc0deaebca 100644 --- a/advisories/unreviewed/2022/04/GHSA-rxjg-q5c5-6q8f/GHSA-rxjg-q5c5-6q8f.json +++ b/advisories/unreviewed/2022/04/GHSA-rxjg-q5c5-6q8f/GHSA-rxjg-q5c5-6q8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-vhpp-73wq-mgfq/GHSA-vhpp-73wq-mgfq.json b/advisories/unreviewed/2022/04/GHSA-vhpp-73wq-mgfq/GHSA-vhpp-73wq-mgfq.json index fcb0e04c48f..ff8e0940a8b 100644 --- a/advisories/unreviewed/2022/04/GHSA-vhpp-73wq-mgfq/GHSA-vhpp-73wq-mgfq.json +++ b/advisories/unreviewed/2022/04/GHSA-vhpp-73wq-mgfq/GHSA-vhpp-73wq-mgfq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-vpf5-gh59-9c93/GHSA-vpf5-gh59-9c93.json b/advisories/unreviewed/2022/04/GHSA-vpf5-gh59-9c93/GHSA-vpf5-gh59-9c93.json index 56635f4be91..fbf7491405c 100644 --- a/advisories/unreviewed/2022/04/GHSA-vpf5-gh59-9c93/GHSA-vpf5-gh59-9c93.json +++ b/advisories/unreviewed/2022/04/GHSA-vpf5-gh59-9c93/GHSA-vpf5-gh59-9c93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vq7q-wrc4-2qv3/GHSA-vq7q-wrc4-2qv3.json b/advisories/unreviewed/2022/04/GHSA-vq7q-wrc4-2qv3/GHSA-vq7q-wrc4-2qv3.json index e48cec2a3eb..a8dd0fcd911 100644 --- a/advisories/unreviewed/2022/04/GHSA-vq7q-wrc4-2qv3/GHSA-vq7q-wrc4-2qv3.json +++ b/advisories/unreviewed/2022/04/GHSA-vq7q-wrc4-2qv3/GHSA-vq7q-wrc4-2qv3.json @@ -7,12 +7,8 @@ "CVE-2002-1775" ], "details": "** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass the initial virus scan and cause NAV to prematurely stop scanning by using a non-RFC compliant MIME header. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the AutoProtect feature would detect the virus before it is executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vx7h-vmc2-6wp8/GHSA-vx7h-vmc2-6wp8.json b/advisories/unreviewed/2022/04/GHSA-vx7h-vmc2-6wp8/GHSA-vx7h-vmc2-6wp8.json index ae9ad0af501..f130f643c5d 100644 --- a/advisories/unreviewed/2022/04/GHSA-vx7h-vmc2-6wp8/GHSA-vx7h-vmc2-6wp8.json +++ b/advisories/unreviewed/2022/04/GHSA-vx7h-vmc2-6wp8/GHSA-vx7h-vmc2-6wp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wcm4-m8qj-9r39/GHSA-wcm4-m8qj-9r39.json b/advisories/unreviewed/2022/04/GHSA-wcm4-m8qj-9r39/GHSA-wcm4-m8qj-9r39.json index 6aa31a0eda8..c21c7107e27 100644 --- a/advisories/unreviewed/2022/04/GHSA-wcm4-m8qj-9r39/GHSA-wcm4-m8qj-9r39.json +++ b/advisories/unreviewed/2022/04/GHSA-wcm4-m8qj-9r39/GHSA-wcm4-m8qj-9r39.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wv7p-48p2-xrvw/GHSA-wv7p-48p2-xrvw.json b/advisories/unreviewed/2022/04/GHSA-wv7p-48p2-xrvw/GHSA-wv7p-48p2-xrvw.json index 256e1360e2e..b4a3ad64df5 100644 --- a/advisories/unreviewed/2022/04/GHSA-wv7p-48p2-xrvw/GHSA-wv7p-48p2-xrvw.json +++ b/advisories/unreviewed/2022/04/GHSA-wv7p-48p2-xrvw/GHSA-wv7p-48p2-xrvw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wxqh-rqgc-pfr9/GHSA-wxqh-rqgc-pfr9.json b/advisories/unreviewed/2022/04/GHSA-wxqh-rqgc-pfr9/GHSA-wxqh-rqgc-pfr9.json index e6da7e2394e..a3df1af55e5 100644 --- a/advisories/unreviewed/2022/04/GHSA-wxqh-rqgc-pfr9/GHSA-wxqh-rqgc-pfr9.json +++ b/advisories/unreviewed/2022/04/GHSA-wxqh-rqgc-pfr9/GHSA-wxqh-rqgc-pfr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-xhjm-9p9r-cp2g/GHSA-xhjm-9p9r-cp2g.json b/advisories/unreviewed/2022/04/GHSA-xhjm-9p9r-cp2g/GHSA-xhjm-9p9r-cp2g.json index 0d9dcc926dc..02dea87713f 100644 --- a/advisories/unreviewed/2022/04/GHSA-xhjm-9p9r-cp2g/GHSA-xhjm-9p9r-cp2g.json +++ b/advisories/unreviewed/2022/04/GHSA-xhjm-9p9r-cp2g/GHSA-xhjm-9p9r-cp2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-xr7v-8xc4-62vc/GHSA-xr7v-8xc4-62vc.json b/advisories/unreviewed/2022/04/GHSA-xr7v-8xc4-62vc/GHSA-xr7v-8xc4-62vc.json index bc6853a5712..e17f7014bbe 100644 --- a/advisories/unreviewed/2022/04/GHSA-xr7v-8xc4-62vc/GHSA-xr7v-8xc4-62vc.json +++ b/advisories/unreviewed/2022/04/GHSA-xr7v-8xc4-62vc/GHSA-xr7v-8xc4-62vc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-222g-mvfx-v2wm/GHSA-222g-mvfx-v2wm.json b/advisories/unreviewed/2022/05/GHSA-222g-mvfx-v2wm/GHSA-222g-mvfx-v2wm.json index f919b40b40f..e158878db40 100644 --- a/advisories/unreviewed/2022/05/GHSA-222g-mvfx-v2wm/GHSA-222g-mvfx-v2wm.json +++ b/advisories/unreviewed/2022/05/GHSA-222g-mvfx-v2wm/GHSA-222g-mvfx-v2wm.json @@ -7,12 +7,8 @@ "CVE-2019-16246" ], "details": "Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22q7-qw7f-w974/GHSA-22q7-qw7f-w974.json b/advisories/unreviewed/2022/05/GHSA-22q7-qw7f-w974/GHSA-22q7-qw7f-w974.json index 8151db1bee0..9684ea1d236 100644 --- a/advisories/unreviewed/2022/05/GHSA-22q7-qw7f-w974/GHSA-22q7-qw7f-w974.json +++ b/advisories/unreviewed/2022/05/GHSA-22q7-qw7f-w974/GHSA-22q7-qw7f-w974.json @@ -7,12 +7,8 @@ "CVE-2019-19546" ], "details": "Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-249q-hrhm-vgjq/GHSA-249q-hrhm-vgjq.json b/advisories/unreviewed/2022/05/GHSA-249q-hrhm-vgjq/GHSA-249q-hrhm-vgjq.json index 6be9f24a3d0..e2627e17542 100644 --- a/advisories/unreviewed/2022/05/GHSA-249q-hrhm-vgjq/GHSA-249q-hrhm-vgjq.json +++ b/advisories/unreviewed/2022/05/GHSA-249q-hrhm-vgjq/GHSA-249q-hrhm-vgjq.json @@ -7,12 +7,8 @@ "CVE-2019-13696" ], "details": "Use after free in JavaScript in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24gw-9fv3-3c2w/GHSA-24gw-9fv3-3c2w.json b/advisories/unreviewed/2022/05/GHSA-24gw-9fv3-3c2w/GHSA-24gw-9fv3-3c2w.json index d6e121b1cbf..8c78073f731 100644 --- a/advisories/unreviewed/2022/05/GHSA-24gw-9fv3-3c2w/GHSA-24gw-9fv3-3c2w.json +++ b/advisories/unreviewed/2022/05/GHSA-24gw-9fv3-3c2w/GHSA-24gw-9fv3-3c2w.json @@ -7,12 +7,8 @@ "CVE-2006-3547" ], "details": "** DISPUTED ** EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying that write access to the .vmx file enables other ways of stopping the virtual machine, so no privilege boundaries are crossed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24pf-7g6m-7wcx/GHSA-24pf-7g6m-7wcx.json b/advisories/unreviewed/2022/05/GHSA-24pf-7g6m-7wcx/GHSA-24pf-7g6m-7wcx.json index 340106ec735..a7f2889217e 100644 --- a/advisories/unreviewed/2022/05/GHSA-24pf-7g6m-7wcx/GHSA-24pf-7g6m-7wcx.json +++ b/advisories/unreviewed/2022/05/GHSA-24pf-7g6m-7wcx/GHSA-24pf-7g6m-7wcx.json @@ -7,12 +7,8 @@ "CVE-2019-13664" ], "details": "Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26qq-9jw6-r5h4/GHSA-26qq-9jw6-r5h4.json b/advisories/unreviewed/2022/05/GHSA-26qq-9jw6-r5h4/GHSA-26qq-9jw6-r5h4.json index 44222e03fcc..462a41a692c 100644 --- a/advisories/unreviewed/2022/05/GHSA-26qq-9jw6-r5h4/GHSA-26qq-9jw6-r5h4.json +++ b/advisories/unreviewed/2022/05/GHSA-26qq-9jw6-r5h4/GHSA-26qq-9jw6-r5h4.json @@ -7,12 +7,8 @@ "CVE-2019-15932" ], "details": "Intesync Solismed 3.3sp has Incorrect Access Control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-27m2-q889-735v/GHSA-27m2-q889-735v.json b/advisories/unreviewed/2022/05/GHSA-27m2-q889-735v/GHSA-27m2-q889-735v.json index 57d2a1bb64d..1a4ab09306a 100644 --- a/advisories/unreviewed/2022/05/GHSA-27m2-q889-735v/GHSA-27m2-q889-735v.json +++ b/advisories/unreviewed/2022/05/GHSA-27m2-q889-735v/GHSA-27m2-q889-735v.json @@ -7,12 +7,8 @@ "CVE-2019-18346" ], "details": "A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add a new admin user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-27q4-qhjq-3v56/GHSA-27q4-qhjq-3v56.json b/advisories/unreviewed/2022/05/GHSA-27q4-qhjq-3v56/GHSA-27q4-qhjq-3v56.json index 3901db305fd..eb086744244 100644 --- a/advisories/unreviewed/2022/05/GHSA-27q4-qhjq-3v56/GHSA-27q4-qhjq-3v56.json +++ b/advisories/unreviewed/2022/05/GHSA-27q4-qhjq-3v56/GHSA-27q4-qhjq-3v56.json @@ -7,12 +7,8 @@ "CVE-2019-0395" ], "details": "SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-27q8-8p72-c44c/GHSA-27q8-8p72-c44c.json b/advisories/unreviewed/2022/05/GHSA-27q8-8p72-c44c/GHSA-27q8-8p72-c44c.json index e55afdd5145..bb596915025 100644 --- a/advisories/unreviewed/2022/05/GHSA-27q8-8p72-c44c/GHSA-27q8-8p72-c44c.json +++ b/advisories/unreviewed/2022/05/GHSA-27q8-8p72-c44c/GHSA-27q8-8p72-c44c.json @@ -7,12 +7,8 @@ "CVE-2019-18190" ], "details": "Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28j2-jrj9-6xv4/GHSA-28j2-jrj9-6xv4.json b/advisories/unreviewed/2022/05/GHSA-28j2-jrj9-6xv4/GHSA-28j2-jrj9-6xv4.json index ce8464879af..ba0cc7b4251 100644 --- a/advisories/unreviewed/2022/05/GHSA-28j2-jrj9-6xv4/GHSA-28j2-jrj9-6xv4.json +++ b/advisories/unreviewed/2022/05/GHSA-28j2-jrj9-6xv4/GHSA-28j2-jrj9-6xv4.json @@ -7,12 +7,8 @@ "CVE-2019-18377" ], "details": "Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29g2-j2qf-h8qw/GHSA-29g2-j2qf-h8qw.json b/advisories/unreviewed/2022/05/GHSA-29g2-j2qf-h8qw/GHSA-29g2-j2qf-h8qw.json index 4f850f0178f..ebada8ec227 100644 --- a/advisories/unreviewed/2022/05/GHSA-29g2-j2qf-h8qw/GHSA-29g2-j2qf-h8qw.json +++ b/advisories/unreviewed/2022/05/GHSA-29g2-j2qf-h8qw/GHSA-29g2-j2qf-h8qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cm3-h7wr-fg9v/GHSA-2cm3-h7wr-fg9v.json b/advisories/unreviewed/2022/05/GHSA-2cm3-h7wr-fg9v/GHSA-2cm3-h7wr-fg9v.json index 4b02985bde4..e53f96d369c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cm3-h7wr-fg9v/GHSA-2cm3-h7wr-fg9v.json +++ b/advisories/unreviewed/2022/05/GHSA-2cm3-h7wr-fg9v/GHSA-2cm3-h7wr-fg9v.json @@ -7,12 +7,8 @@ "CVE-2018-0730" ], "details": "This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2f85-q754-r9h5/GHSA-2f85-q754-r9h5.json b/advisories/unreviewed/2022/05/GHSA-2f85-q754-r9h5/GHSA-2f85-q754-r9h5.json index 3a7365eb289..a502d9dbf87 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f85-q754-r9h5/GHSA-2f85-q754-r9h5.json +++ b/advisories/unreviewed/2022/05/GHSA-2f85-q754-r9h5/GHSA-2f85-q754-r9h5.json @@ -7,12 +7,8 @@ "CVE-2006-4445" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in CuteNews 1.3.x allow remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter to (1) show_news.php or (2) search.php. NOTE: CVE analysis as of 20060829 has not identified any scenarios in which these vectors could result in remote file inclusion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hq4-6p2g-96ph/GHSA-2hq4-6p2g-96ph.json b/advisories/unreviewed/2022/05/GHSA-2hq4-6p2g-96ph/GHSA-2hq4-6p2g-96ph.json index 96f4ccdd33b..8e12cc86d50 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hq4-6p2g-96ph/GHSA-2hq4-6p2g-96ph.json +++ b/advisories/unreviewed/2022/05/GHSA-2hq4-6p2g-96ph/GHSA-2hq4-6p2g-96ph.json @@ -7,12 +7,8 @@ "CVE-2019-15686" ], "details": "Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jr6-2g4g-4jhj/GHSA-2jr6-2g4g-4jhj.json b/advisories/unreviewed/2022/05/GHSA-2jr6-2g4g-4jhj/GHSA-2jr6-2g4g-4jhj.json index 0fcd4a65aac..23a1a11c05b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jr6-2g4g-4jhj/GHSA-2jr6-2g4g-4jhj.json +++ b/advisories/unreviewed/2022/05/GHSA-2jr6-2g4g-4jhj/GHSA-2jr6-2g4g-4jhj.json @@ -7,12 +7,8 @@ "CVE-2015-3406" ], "details": "The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jr7-hp8j-mvpq/GHSA-2jr7-hp8j-mvpq.json b/advisories/unreviewed/2022/05/GHSA-2jr7-hp8j-mvpq/GHSA-2jr7-hp8j-mvpq.json index 454d7a5e70b..6390aadcdf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jr7-hp8j-mvpq/GHSA-2jr7-hp8j-mvpq.json +++ b/advisories/unreviewed/2022/05/GHSA-2jr7-hp8j-mvpq/GHSA-2jr7-hp8j-mvpq.json @@ -7,12 +7,8 @@ "CVE-2019-13698" ], "details": "Out of bounds memory access in JavaScript in Google Chrome prior to 73.0.3683.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jwh-f64h-x66g/GHSA-2jwh-f64h-x66g.json b/advisories/unreviewed/2022/05/GHSA-2jwh-f64h-x66g/GHSA-2jwh-f64h-x66g.json index 8dd78551d72..c2cfcae0f1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jwh-f64h-x66g/GHSA-2jwh-f64h-x66g.json +++ b/advisories/unreviewed/2022/05/GHSA-2jwh-f64h-x66g/GHSA-2jwh-f64h-x66g.json @@ -7,12 +7,8 @@ "CVE-2019-1489" ], "details": "An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory, aka 'Remote Desktop Protocol Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jx7-jqgc-hgxg/GHSA-2jx7-jqgc-hgxg.json b/advisories/unreviewed/2022/05/GHSA-2jx7-jqgc-hgxg/GHSA-2jx7-jqgc-hgxg.json index e83956cb159..ef3e8c65d60 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jx7-jqgc-hgxg/GHSA-2jx7-jqgc-hgxg.json +++ b/advisories/unreviewed/2022/05/GHSA-2jx7-jqgc-hgxg/GHSA-2jx7-jqgc-hgxg.json @@ -7,12 +7,8 @@ "CVE-2017-7399" ], "details": "Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2m5x-jqmf-gr49/GHSA-2m5x-jqmf-gr49.json b/advisories/unreviewed/2022/05/GHSA-2m5x-jqmf-gr49/GHSA-2m5x-jqmf-gr49.json index 2a189dc9f85..533e06558ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m5x-jqmf-gr49/GHSA-2m5x-jqmf-gr49.json +++ b/advisories/unreviewed/2022/05/GHSA-2m5x-jqmf-gr49/GHSA-2m5x-jqmf-gr49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mp2-8rhv-p755/GHSA-2mp2-8rhv-p755.json b/advisories/unreviewed/2022/05/GHSA-2mp2-8rhv-p755/GHSA-2mp2-8rhv-p755.json index e29bf729c74..7eab680bdd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mp2-8rhv-p755/GHSA-2mp2-8rhv-p755.json +++ b/advisories/unreviewed/2022/05/GHSA-2mp2-8rhv-p755/GHSA-2mp2-8rhv-p755.json @@ -7,12 +7,8 @@ "CVE-2019-4130" ], "details": "IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2pcr-jc7h-5447/GHSA-2pcr-jc7h-5447.json b/advisories/unreviewed/2022/05/GHSA-2pcr-jc7h-5447/GHSA-2pcr-jc7h-5447.json index 0d2f56d027b..5d1d81bd4bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pcr-jc7h-5447/GHSA-2pcr-jc7h-5447.json +++ b/advisories/unreviewed/2022/05/GHSA-2pcr-jc7h-5447/GHSA-2pcr-jc7h-5447.json @@ -7,12 +7,8 @@ "CVE-2006-4557" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in plugins/plugins.php in Bob Jewell Discloser 0.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the type parameter. NOTE: another researcher has stated that an attacker cannot control the type parameter. As of 20060901, CVE analysis concurs with the dispute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2pfw-56q4-cfv3/GHSA-2pfw-56q4-cfv3.json b/advisories/unreviewed/2022/05/GHSA-2pfw-56q4-cfv3/GHSA-2pfw-56q4-cfv3.json index a005c515abd..7ae045f2098 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pfw-56q4-cfv3/GHSA-2pfw-56q4-cfv3.json +++ b/advisories/unreviewed/2022/05/GHSA-2pfw-56q4-cfv3/GHSA-2pfw-56q4-cfv3.json @@ -7,12 +7,8 @@ "CVE-2019-19529" ], "details": "In the Linux kernel before 5.3.11, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c driver, aka CID-4d6636498c41.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qgp-6j4f-cwcw/GHSA-2qgp-6j4f-cwcw.json b/advisories/unreviewed/2022/05/GHSA-2qgp-6j4f-cwcw/GHSA-2qgp-6j4f-cwcw.json index 5e70071b165..024950eceb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qgp-6j4f-cwcw/GHSA-2qgp-6j4f-cwcw.json +++ b/advisories/unreviewed/2022/05/GHSA-2qgp-6j4f-cwcw/GHSA-2qgp-6j4f-cwcw.json @@ -7,12 +7,8 @@ "CVE-2019-5857" ], "details": "Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2v63-g4wq-72pq/GHSA-2v63-g4wq-72pq.json b/advisories/unreviewed/2022/05/GHSA-2v63-g4wq-72pq/GHSA-2v63-g4wq-72pq.json index 97d768445b5..c0cc8f2a997 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v63-g4wq-72pq/GHSA-2v63-g4wq-72pq.json +++ b/advisories/unreviewed/2022/05/GHSA-2v63-g4wq-72pq/GHSA-2v63-g4wq-72pq.json @@ -7,12 +7,8 @@ "CVE-2019-12518" ], "details": "Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2wp7-476w-v7fh/GHSA-2wp7-476w-v7fh.json b/advisories/unreviewed/2022/05/GHSA-2wp7-476w-v7fh/GHSA-2wp7-476w-v7fh.json index ed82f05602b..249c0d355de 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wp7-476w-v7fh/GHSA-2wp7-476w-v7fh.json +++ b/advisories/unreviewed/2022/05/GHSA-2wp7-476w-v7fh/GHSA-2wp7-476w-v7fh.json @@ -7,12 +7,8 @@ "CVE-2019-5268" ], "details": "Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2x6m-qw3h-9vjw/GHSA-2x6m-qw3h-9vjw.json b/advisories/unreviewed/2022/05/GHSA-2x6m-qw3h-9vjw/GHSA-2x6m-qw3h-9vjw.json index 722e361c22e..d73fa2d0549 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x6m-qw3h-9vjw/GHSA-2x6m-qw3h-9vjw.json +++ b/advisories/unreviewed/2022/05/GHSA-2x6m-qw3h-9vjw/GHSA-2x6m-qw3h-9vjw.json @@ -7,12 +7,8 @@ "CVE-2019-5260" ], "details": "Huawei smartphones HUAWEI Y9 2019 and Honor View 20 have a denial of service vulnerability. Due to insufficient input validation of specific value when parsing the messages, an attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices to exploit this vulnerability. Successful exploit may cause an infinite loop and the device to reboot.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2x73-qq8h-xvxh/GHSA-2x73-qq8h-xvxh.json b/advisories/unreviewed/2022/05/GHSA-2x73-qq8h-xvxh/GHSA-2x73-qq8h-xvxh.json index 7d4d18ae4c1..6640ff8a1c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x73-qq8h-xvxh/GHSA-2x73-qq8h-xvxh.json +++ b/advisories/unreviewed/2022/05/GHSA-2x73-qq8h-xvxh/GHSA-2x73-qq8h-xvxh.json @@ -7,12 +7,8 @@ "CVE-2019-13695" ], "details": "Use after free in audio in Google Chrome on Android prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xhj-75cm-7997/GHSA-2xhj-75cm-7997.json b/advisories/unreviewed/2022/05/GHSA-2xhj-75cm-7997/GHSA-2xhj-75cm-7997.json index 9e514f6a3d6..efd9528ee00 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xhj-75cm-7997/GHSA-2xhj-75cm-7997.json +++ b/advisories/unreviewed/2022/05/GHSA-2xhj-75cm-7997/GHSA-2xhj-75cm-7997.json @@ -7,12 +7,8 @@ "CVE-2019-19387" ], "details": "A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xrc-mfj2-6vg5/GHSA-2xrc-mfj2-6vg5.json b/advisories/unreviewed/2022/05/GHSA-2xrc-mfj2-6vg5/GHSA-2xrc-mfj2-6vg5.json index 0624e5ff595..0acd6e8f618 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xrc-mfj2-6vg5/GHSA-2xrc-mfj2-6vg5.json +++ b/advisories/unreviewed/2022/05/GHSA-2xrc-mfj2-6vg5/GHSA-2xrc-mfj2-6vg5.json @@ -7,12 +7,8 @@ "CVE-2006-4863" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the langfile parameter is set to english.php in each file. NOTE: CVE also disputes a later report of this vulnerability in 1.2, because the langfile parameter is set to french.php in 1.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xrh-pxx5-48rp/GHSA-2xrh-pxx5-48rp.json b/advisories/unreviewed/2022/05/GHSA-2xrh-pxx5-48rp/GHSA-2xrh-pxx5-48rp.json index 7d187846de3..742db735bee 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xrh-pxx5-48rp/GHSA-2xrh-pxx5-48rp.json +++ b/advisories/unreviewed/2022/05/GHSA-2xrh-pxx5-48rp/GHSA-2xrh-pxx5-48rp.json @@ -7,12 +7,8 @@ "CVE-2019-18331" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could gain access to path and filenames on the server by sending specifically crafted packets to 1099/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3269-hcm6-x235/GHSA-3269-hcm6-x235.json b/advisories/unreviewed/2022/05/GHSA-3269-hcm6-x235/GHSA-3269-hcm6-x235.json index 0eb102cb3af..fc315ab8915 100644 --- a/advisories/unreviewed/2022/05/GHSA-3269-hcm6-x235/GHSA-3269-hcm6-x235.json +++ b/advisories/unreviewed/2022/05/GHSA-3269-hcm6-x235/GHSA-3269-hcm6-x235.json @@ -7,12 +7,8 @@ "CVE-2019-13932" ], "details": "A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated, causing the the application to behave in unexpected ways for legitimate users. Successful exploitation does not require for an attacker to be authenticated. A successful attack could allow the import of scripts or generation of malicious links. This could allow the attacker to read or modify contents of the web application. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-32f2-v4v8-76vw/GHSA-32f2-v4v8-76vw.json b/advisories/unreviewed/2022/05/GHSA-32f2-v4v8-76vw/GHSA-32f2-v4v8-76vw.json index ca76bee848d..288cbbc54e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-32f2-v4v8-76vw/GHSA-32f2-v4v8-76vw.json +++ b/advisories/unreviewed/2022/05/GHSA-32f2-v4v8-76vw/GHSA-32f2-v4v8-76vw.json @@ -7,12 +7,8 @@ "CVE-2019-19018" ], "details": "An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33vf-v7x5-68hh/GHSA-33vf-v7x5-68hh.json b/advisories/unreviewed/2022/05/GHSA-33vf-v7x5-68hh/GHSA-33vf-v7x5-68hh.json index f9d646bc9a0..638fdb6c465 100644 --- a/advisories/unreviewed/2022/05/GHSA-33vf-v7x5-68hh/GHSA-33vf-v7x5-68hh.json +++ b/advisories/unreviewed/2022/05/GHSA-33vf-v7x5-68hh/GHSA-33vf-v7x5-68hh.json @@ -7,12 +7,8 @@ "CVE-2019-13667" ], "details": "Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33wp-4xj7-xwqx/GHSA-33wp-4xj7-xwqx.json b/advisories/unreviewed/2022/05/GHSA-33wp-4xj7-xwqx/GHSA-33wp-4xj7-xwqx.json index 6a7d80ac33e..c9858193f36 100644 --- a/advisories/unreviewed/2022/05/GHSA-33wp-4xj7-xwqx/GHSA-33wp-4xj7-xwqx.json +++ b/advisories/unreviewed/2022/05/GHSA-33wp-4xj7-xwqx/GHSA-33wp-4xj7-xwqx.json @@ -7,12 +7,8 @@ "CVE-2019-19533" ], "details": "In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3466-79gg-gm5r/GHSA-3466-79gg-gm5r.json b/advisories/unreviewed/2022/05/GHSA-3466-79gg-gm5r/GHSA-3466-79gg-gm5r.json index 249a67bda4f..fed973beffb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3466-79gg-gm5r/GHSA-3466-79gg-gm5r.json +++ b/advisories/unreviewed/2022/05/GHSA-3466-79gg-gm5r/GHSA-3466-79gg-gm5r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3467-vmmf-hrxw/GHSA-3467-vmmf-hrxw.json b/advisories/unreviewed/2022/05/GHSA-3467-vmmf-hrxw/GHSA-3467-vmmf-hrxw.json index 9facefe6c13..2c198200dc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3467-vmmf-hrxw/GHSA-3467-vmmf-hrxw.json +++ b/advisories/unreviewed/2022/05/GHSA-3467-vmmf-hrxw/GHSA-3467-vmmf-hrxw.json @@ -7,12 +7,8 @@ "CVE-2019-5309" ], "details": "Honor play smartphones with versions earlier than 9.1.0.333(C00E333R1P1T8) have an information disclosure vulnerability in certain Huawei . An attacker could view certain information after a series of operation without unlock the screen lock. Successful exploit could cause an information disclosure condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34q3-rr2f-2gwp/GHSA-34q3-rr2f-2gwp.json b/advisories/unreviewed/2022/05/GHSA-34q3-rr2f-2gwp/GHSA-34q3-rr2f-2gwp.json index 1e6b8267faa..a422cee516b 100644 --- a/advisories/unreviewed/2022/05/GHSA-34q3-rr2f-2gwp/GHSA-34q3-rr2f-2gwp.json +++ b/advisories/unreviewed/2022/05/GHSA-34q3-rr2f-2gwp/GHSA-34q3-rr2f-2gwp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-356h-gg7j-mwv3/GHSA-356h-gg7j-mwv3.json b/advisories/unreviewed/2022/05/GHSA-356h-gg7j-mwv3/GHSA-356h-gg7j-mwv3.json index ee89792f525..2a68f5f4eb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-356h-gg7j-mwv3/GHSA-356h-gg7j-mwv3.json +++ b/advisories/unreviewed/2022/05/GHSA-356h-gg7j-mwv3/GHSA-356h-gg7j-mwv3.json @@ -7,12 +7,8 @@ "CVE-2019-18609" ], "details": "An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-359w-ccrp-pqhg/GHSA-359w-ccrp-pqhg.json b/advisories/unreviewed/2022/05/GHSA-359w-ccrp-pqhg/GHSA-359w-ccrp-pqhg.json index 97e6ded8775..3a28a3a7c63 100644 --- a/advisories/unreviewed/2022/05/GHSA-359w-ccrp-pqhg/GHSA-359w-ccrp-pqhg.json +++ b/advisories/unreviewed/2022/05/GHSA-359w-ccrp-pqhg/GHSA-359w-ccrp-pqhg.json @@ -7,12 +7,8 @@ "CVE-2019-18308" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a low privileged user account could gain root privileges by manipulating specific files in the local file system. This vulnerability is independent from CVE-2019-18309. Please note that an attacker needs to have local access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35fq-rqch-cg5p/GHSA-35fq-rqch-cg5p.json b/advisories/unreviewed/2022/05/GHSA-35fq-rqch-cg5p/GHSA-35fq-rqch-cg5p.json index 777a9093b65..d4232cbb4e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-35fq-rqch-cg5p/GHSA-35fq-rqch-cg5p.json +++ b/advisories/unreviewed/2022/05/GHSA-35fq-rqch-cg5p/GHSA-35fq-rqch-cg5p.json @@ -7,12 +7,8 @@ "CVE-2019-5250" ], "details": "Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation of certain privilege, the attacker could trick the user into installing a malicious application before the user turns on student mode function. Successful exploit could allow the attacker to bypass the limit of student mode function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3692-hqvq-62f5/GHSA-3692-hqvq-62f5.json b/advisories/unreviewed/2022/05/GHSA-3692-hqvq-62f5/GHSA-3692-hqvq-62f5.json index ceb66f57c85..137aa71b133 100644 --- a/advisories/unreviewed/2022/05/GHSA-3692-hqvq-62f5/GHSA-3692-hqvq-62f5.json +++ b/advisories/unreviewed/2022/05/GHSA-3692-hqvq-62f5/GHSA-3692-hqvq-62f5.json @@ -7,12 +7,8 @@ "CVE-2016-3192" ], "details": "Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-39h8-5656-9hw5/GHSA-39h8-5656-9hw5.json b/advisories/unreviewed/2022/05/GHSA-39h8-5656-9hw5/GHSA-39h8-5656-9hw5.json index 761ca0f51d8..f2da64d7d5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-39h8-5656-9hw5/GHSA-39h8-5656-9hw5.json +++ b/advisories/unreviewed/2022/05/GHSA-39h8-5656-9hw5/GHSA-39h8-5656-9hw5.json @@ -7,12 +7,8 @@ "CVE-2019-18315" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c68-5wgm-9f52/GHSA-3c68-5wgm-9f52.json b/advisories/unreviewed/2022/05/GHSA-3c68-5wgm-9f52/GHSA-3c68-5wgm-9f52.json index a176835a972..7b85be6c921 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c68-5wgm-9f52/GHSA-3c68-5wgm-9f52.json +++ b/advisories/unreviewed/2022/05/GHSA-3c68-5wgm-9f52/GHSA-3c68-5wgm-9f52.json @@ -7,12 +7,8 @@ "CVE-2019-13691" ], "details": "Insufficient validation of untrusted input in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3h75-cj34-c2gv/GHSA-3h75-cj34-c2gv.json b/advisories/unreviewed/2022/05/GHSA-3h75-cj34-c2gv/GHSA-3h75-cj34-c2gv.json index ea0388504e4..796e1080b13 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h75-cj34-c2gv/GHSA-3h75-cj34-c2gv.json +++ b/advisories/unreviewed/2022/05/GHSA-3h75-cj34-c2gv/GHSA-3h75-cj34-c2gv.json @@ -7,12 +7,8 @@ "CVE-2019-15960" ], "details": "A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page. To exploit this vulnerability, the attacker must be logged in as a low-level administrator. The vulnerability is due to insufficient access control validation. An attacker could exploit this vulnerability by submitting a crafted URL request to gain privileged access in the context of the affected page. A successful exploit could allow the attacker to elevate privileges in the Webex Recording Admin page, which could allow them to view or delete recordings that they would not normally be able to access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3h8h-mjhw-3m3h/GHSA-3h8h-mjhw-3m3h.json b/advisories/unreviewed/2022/05/GHSA-3h8h-mjhw-3m3h/GHSA-3h8h-mjhw-3m3h.json index 85803725e91..259ebeb305a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h8h-mjhw-3m3h/GHSA-3h8h-mjhw-3m3h.json +++ b/advisories/unreviewed/2022/05/GHSA-3h8h-mjhw-3m3h/GHSA-3h8h-mjhw-3m3h.json @@ -7,12 +7,8 @@ "CVE-2019-19463" ], "details": "The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3j3f-m8pf-4gxv/GHSA-3j3f-m8pf-4gxv.json b/advisories/unreviewed/2022/05/GHSA-3j3f-m8pf-4gxv/GHSA-3j3f-m8pf-4gxv.json index 6dd29dd810d..844cce78a87 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j3f-m8pf-4gxv/GHSA-3j3f-m8pf-4gxv.json +++ b/advisories/unreviewed/2022/05/GHSA-3j3f-m8pf-4gxv/GHSA-3j3f-m8pf-4gxv.json @@ -7,12 +7,8 @@ "CVE-2006-6023" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in phoo.base.php in Bill Roberts Bloo 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the descriptorFileList parameter. NOTE: this issue is disputed by CVE since $descriptorFileList is used in a function definition within phoo.base.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jxc-895x-c94m/GHSA-3jxc-895x-c94m.json b/advisories/unreviewed/2022/05/GHSA-3jxc-895x-c94m/GHSA-3jxc-895x-c94m.json index eb9685ba549..fbd2475d74c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jxc-895x-c94m/GHSA-3jxc-895x-c94m.json +++ b/advisories/unreviewed/2022/05/GHSA-3jxc-895x-c94m/GHSA-3jxc-895x-c94m.json @@ -7,12 +7,8 @@ "CVE-2019-5855" ], "details": "Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3m7v-3ggq-789x/GHSA-3m7v-3ggq-789x.json b/advisories/unreviewed/2022/05/GHSA-3m7v-3ggq-789x/GHSA-3m7v-3ggq-789x.json index 1556fe3de04..a6433f40fcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m7v-3ggq-789x/GHSA-3m7v-3ggq-789x.json +++ b/advisories/unreviewed/2022/05/GHSA-3m7v-3ggq-789x/GHSA-3m7v-3ggq-789x.json @@ -7,12 +7,8 @@ "CVE-2019-15973" ], "details": "A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected application. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected application. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mhh-q9gx-fwpr/GHSA-3mhh-q9gx-fwpr.json b/advisories/unreviewed/2022/05/GHSA-3mhh-q9gx-fwpr/GHSA-3mhh-q9gx-fwpr.json index a5b1d4bd99f..d80b714ca4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mhh-q9gx-fwpr/GHSA-3mhh-q9gx-fwpr.json +++ b/advisories/unreviewed/2022/05/GHSA-3mhh-q9gx-fwpr/GHSA-3mhh-q9gx-fwpr.json @@ -7,12 +7,8 @@ "CVE-2019-7365" ], "details": "DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may then leverage a DLL preloading vulnerability and execute code on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pgx-5h9r-2mg2/GHSA-3pgx-5h9r-2mg2.json b/advisories/unreviewed/2022/05/GHSA-3pgx-5h9r-2mg2/GHSA-3pgx-5h9r-2mg2.json index c0488461166..5e423da7986 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pgx-5h9r-2mg2/GHSA-3pgx-5h9r-2mg2.json +++ b/advisories/unreviewed/2022/05/GHSA-3pgx-5h9r-2mg2/GHSA-3pgx-5h9r-2mg2.json @@ -7,12 +7,8 @@ "CVE-2019-0404" ], "details": "SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3phq-67rm-2hq8/GHSA-3phq-67rm-2hq8.json b/advisories/unreviewed/2022/05/GHSA-3phq-67rm-2hq8/GHSA-3phq-67rm-2hq8.json index a4f00be691b..e6feb63415f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3phq-67rm-2hq8/GHSA-3phq-67rm-2hq8.json +++ b/advisories/unreviewed/2022/05/GHSA-3phq-67rm-2hq8/GHSA-3phq-67rm-2hq8.json @@ -7,12 +7,8 @@ "CVE-2019-13927" ], "details": "A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server (All firmware versions < V6.00.320). The device contains a vulnerability that could allow an attacker to cause a denial of service condition on the device's web server by sending a specially crafted HTTP message to the web server port (tcp/80). The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device's web service. While the device itself stays operational, the web server responds with HTTP status code 404 (Not found) to any further request. A reboot is required to recover the web interface. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3q76-8594-629m/GHSA-3q76-8594-629m.json b/advisories/unreviewed/2022/05/GHSA-3q76-8594-629m/GHSA-3q76-8594-629m.json index c004a3cdbf8..716aa6293cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q76-8594-629m/GHSA-3q76-8594-629m.json +++ b/advisories/unreviewed/2022/05/GHSA-3q76-8594-629m/GHSA-3q76-8594-629m.json @@ -7,12 +7,8 @@ "CVE-2006-3253" ], "details": "** DISPUTED ** Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that \"the userid parameter is run through our filtering system as an unsigned integer.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qc6-f467-3w44/GHSA-3qc6-f467-3w44.json b/advisories/unreviewed/2022/05/GHSA-3qc6-f467-3w44/GHSA-3qc6-f467-3w44.json index f930b3ae991..9d3cb8a6d76 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qc6-f467-3w44/GHSA-3qc6-f467-3w44.json +++ b/advisories/unreviewed/2022/05/GHSA-3qc6-f467-3w44/GHSA-3qc6-f467-3w44.json @@ -7,12 +7,8 @@ "CVE-2019-4612" ], "details": "IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3r42-8xcq-6f4v/GHSA-3r42-8xcq-6f4v.json b/advisories/unreviewed/2022/05/GHSA-3r42-8xcq-6f4v/GHSA-3r42-8xcq-6f4v.json index 2c36ef192df..8d31ce72299 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r42-8xcq-6f4v/GHSA-3r42-8xcq-6f4v.json +++ b/advisories/unreviewed/2022/05/GHSA-3r42-8xcq-6f4v/GHSA-3r42-8xcq-6f4v.json @@ -7,12 +7,8 @@ "CVE-2019-16753" ], "details": "An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations. This is a weak signature scheme design that would allow the reuse of signatures in some cases (or even the reuse of signatures, intended for one type of message, for another type). This also affects Private Instant Verified Transactions (PIVX) through 3.4.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3r7q-rhw3-rmxq/GHSA-3r7q-rhw3-rmxq.json b/advisories/unreviewed/2022/05/GHSA-3r7q-rhw3-rmxq/GHSA-3r7q-rhw3-rmxq.json index fa2612168b9..9da361d69ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r7q-rhw3-rmxq/GHSA-3r7q-rhw3-rmxq.json +++ b/advisories/unreviewed/2022/05/GHSA-3r7q-rhw3-rmxq/GHSA-3r7q-rhw3-rmxq.json @@ -7,12 +7,8 @@ "CVE-2019-4621" ], "details": "IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rpf-v574-x42r/GHSA-3rpf-v574-x42r.json b/advisories/unreviewed/2022/05/GHSA-3rpf-v574-x42r/GHSA-3rpf-v574-x42r.json index ade21bbb7b8..46e289122bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rpf-v574-x42r/GHSA-3rpf-v574-x42r.json +++ b/advisories/unreviewed/2022/05/GHSA-3rpf-v574-x42r/GHSA-3rpf-v574-x42r.json @@ -7,12 +7,8 @@ "CVE-2006-5957" ], "details": "** DISPUTED ** Multiple SQL injection vulnerabilities in INFINICART allow remote attackers to execute arbitrary SQL commands via the (1) groupid parameter in (a) browse_group.asp, (2) productid parameter in (b) added_to_cart.asp, and (3) catid and (4) subid parameter in (c) browsesubcat.asp. NOTE: the vendor has disputed this report, saying \"The vulnerabilities mentioned were never present in our official released products but only in the unofficial demo version. However we do appreciate the information. We have update our demo version and made sure all those vulnerabilities are fixed.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vfv-q88q-85c4/GHSA-3vfv-q88q-85c4.json b/advisories/unreviewed/2022/05/GHSA-3vfv-q88q-85c4/GHSA-3vfv-q88q-85c4.json index b8e77096e6c..751d86e532f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vfv-q88q-85c4/GHSA-3vfv-q88q-85c4.json +++ b/advisories/unreviewed/2022/05/GHSA-3vfv-q88q-85c4/GHSA-3vfv-q88q-85c4.json @@ -7,12 +7,8 @@ "CVE-2019-18289" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18293, CVE-2019-18295, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vv5-594j-w9p4/GHSA-3vv5-594j-w9p4.json b/advisories/unreviewed/2022/05/GHSA-3vv5-594j-w9p4/GHSA-3vv5-594j-w9p4.json index c1e7bb267b9..156cec8bcfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vv5-594j-w9p4/GHSA-3vv5-594j-w9p4.json +++ b/advisories/unreviewed/2022/05/GHSA-3vv5-594j-w9p4/GHSA-3vv5-594j-w9p4.json @@ -7,12 +7,8 @@ "CVE-2019-6183" ], "details": "A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause systems to experience a blue screen error. Lenovo Energy Management is a client utility. Lenovo XClarity Energy Manager is not affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vwg-cxp6-wf3x/GHSA-3vwg-cxp6-wf3x.json b/advisories/unreviewed/2022/05/GHSA-3vwg-cxp6-wf3x/GHSA-3vwg-cxp6-wf3x.json index 0683a1e7e11..35c7e2001af 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vwg-cxp6-wf3x/GHSA-3vwg-cxp6-wf3x.json +++ b/advisories/unreviewed/2022/05/GHSA-3vwg-cxp6-wf3x/GHSA-3vwg-cxp6-wf3x.json @@ -7,12 +7,8 @@ "CVE-2019-19597" ], "details": "D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vww-prm4-rg7q/GHSA-3vww-prm4-rg7q.json b/advisories/unreviewed/2022/05/GHSA-3vww-prm4-rg7q/GHSA-3vww-prm4-rg7q.json index 133999ca19a..a7d97bfed0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vww-prm4-rg7q/GHSA-3vww-prm4-rg7q.json +++ b/advisories/unreviewed/2022/05/GHSA-3vww-prm4-rg7q/GHSA-3vww-prm4-rg7q.json @@ -7,12 +7,8 @@ "CVE-2019-19133" ], "details": "The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookies or launch other attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3w65-mh9h-3g82/GHSA-3w65-mh9h-3g82.json b/advisories/unreviewed/2022/05/GHSA-3w65-mh9h-3g82/GHSA-3w65-mh9h-3g82.json index c06222d00e5..45cfe5c76ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w65-mh9h-3g82/GHSA-3w65-mh9h-3g82.json +++ b/advisories/unreviewed/2022/05/GHSA-3w65-mh9h-3g82/GHSA-3w65-mh9h-3g82.json @@ -7,12 +7,8 @@ "CVE-2019-14317" ], "details": "wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote attacker to compute the long term private key from several hundred DSA signatures via a lattice attack. The issue occurs because dsa.c fixes two bits of the generated nonces.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wvx-cc6q-7chr/GHSA-3wvx-cc6q-7chr.json b/advisories/unreviewed/2022/05/GHSA-3wvx-cc6q-7chr/GHSA-3wvx-cc6q-7chr.json index 64d532eeecd..3ae7f8867ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wvx-cc6q-7chr/GHSA-3wvx-cc6q-7chr.json +++ b/advisories/unreviewed/2022/05/GHSA-3wvx-cc6q-7chr/GHSA-3wvx-cc6q-7chr.json @@ -7,12 +7,8 @@ "CVE-2019-18463" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xc7-8f3r-h948/GHSA-3xc7-8f3r-h948.json b/advisories/unreviewed/2022/05/GHSA-3xc7-8f3r-h948/GHSA-3xc7-8f3r-h948.json index 68d3075db10..7a467182289 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xc7-8f3r-h948/GHSA-3xc7-8f3r-h948.json +++ b/advisories/unreviewed/2022/05/GHSA-3xc7-8f3r-h948/GHSA-3xc7-8f3r-h948.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xcq-2f3r-vpwr/GHSA-3xcq-2f3r-vpwr.json b/advisories/unreviewed/2022/05/GHSA-3xcq-2f3r-vpwr/GHSA-3xcq-2f3r-vpwr.json index ab008e7524e..0541250b353 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xcq-2f3r-vpwr/GHSA-3xcq-2f3r-vpwr.json +++ b/advisories/unreviewed/2022/05/GHSA-3xcq-2f3r-vpwr/GHSA-3xcq-2f3r-vpwr.json @@ -7,12 +7,8 @@ "CVE-2019-19252" ], "details": "vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write access to vcsu devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xf3-x9jm-fgfc/GHSA-3xf3-x9jm-fgfc.json b/advisories/unreviewed/2022/05/GHSA-3xf3-x9jm-fgfc/GHSA-3xf3-x9jm-fgfc.json index 90e33d4521e..2e005b4504c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xf3-x9jm-fgfc/GHSA-3xf3-x9jm-fgfc.json +++ b/advisories/unreviewed/2022/05/GHSA-3xf3-x9jm-fgfc/GHSA-3xf3-x9jm-fgfc.json @@ -7,12 +7,8 @@ "CVE-2019-2226" ], "details": "In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure in the Bluetooth server with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140152619", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xrv-3mx5-r2p6/GHSA-3xrv-3mx5-r2p6.json b/advisories/unreviewed/2022/05/GHSA-3xrv-3mx5-r2p6/GHSA-3xrv-3mx5-r2p6.json index b9b39b4112e..9e7a4ab1dd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xrv-3mx5-r2p6/GHSA-3xrv-3mx5-r2p6.json +++ b/advisories/unreviewed/2022/05/GHSA-3xrv-3mx5-r2p6/GHSA-3xrv-3mx5-r2p6.json @@ -7,12 +7,8 @@ "CVE-2019-13673" ], "details": "Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43jp-qxr7-8hf7/GHSA-43jp-qxr7-8hf7.json b/advisories/unreviewed/2022/05/GHSA-43jp-qxr7-8hf7/GHSA-43jp-qxr7-8hf7.json index 689acd4f3ff..df7e34abb68 100644 --- a/advisories/unreviewed/2022/05/GHSA-43jp-qxr7-8hf7/GHSA-43jp-qxr7-8hf7.json +++ b/advisories/unreviewed/2022/05/GHSA-43jp-qxr7-8hf7/GHSA-43jp-qxr7-8hf7.json @@ -7,12 +7,8 @@ "CVE-2019-18293" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18295, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-447v-pq45-237q/GHSA-447v-pq45-237q.json b/advisories/unreviewed/2022/05/GHSA-447v-pq45-237q/GHSA-447v-pq45-237q.json index 9c2fe6880f5..1aeff04d6d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-447v-pq45-237q/GHSA-447v-pq45-237q.json +++ b/advisories/unreviewed/2022/05/GHSA-447v-pq45-237q/GHSA-447v-pq45-237q.json @@ -7,12 +7,8 @@ "CVE-2019-11935" ], "details": "Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44c7-rp6q-gcrh/GHSA-44c7-rp6q-gcrh.json b/advisories/unreviewed/2022/05/GHSA-44c7-rp6q-gcrh/GHSA-44c7-rp6q-gcrh.json index 419ee90fbaa..804cc672d35 100644 --- a/advisories/unreviewed/2022/05/GHSA-44c7-rp6q-gcrh/GHSA-44c7-rp6q-gcrh.json +++ b/advisories/unreviewed/2022/05/GHSA-44c7-rp6q-gcrh/GHSA-44c7-rp6q-gcrh.json @@ -7,12 +7,8 @@ "CVE-2019-11937" ], "details": "In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-456j-pp8g-p3qx/GHSA-456j-pp8g-p3qx.json b/advisories/unreviewed/2022/05/GHSA-456j-pp8g-p3qx/GHSA-456j-pp8g-p3qx.json index e91668a047f..e40bae29755 100644 --- a/advisories/unreviewed/2022/05/GHSA-456j-pp8g-p3qx/GHSA-456j-pp8g-p3qx.json +++ b/advisories/unreviewed/2022/05/GHSA-456j-pp8g-p3qx/GHSA-456j-pp8g-p3qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-467r-c55c-h73q/GHSA-467r-c55c-h73q.json b/advisories/unreviewed/2022/05/GHSA-467r-c55c-h73q/GHSA-467r-c55c-h73q.json index 0cec4052f15..52c084b8e3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-467r-c55c-h73q/GHSA-467r-c55c-h73q.json +++ b/advisories/unreviewed/2022/05/GHSA-467r-c55c-h73q/GHSA-467r-c55c-h73q.json @@ -7,12 +7,8 @@ "CVE-2019-17388" ], "details": "Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46rx-rvqp-8rxj/GHSA-46rx-rvqp-8rxj.json b/advisories/unreviewed/2022/05/GHSA-46rx-rvqp-8rxj/GHSA-46rx-rvqp-8rxj.json index a812c17f7b3..f51dabfd780 100644 --- a/advisories/unreviewed/2022/05/GHSA-46rx-rvqp-8rxj/GHSA-46rx-rvqp-8rxj.json +++ b/advisories/unreviewed/2022/05/GHSA-46rx-rvqp-8rxj/GHSA-46rx-rvqp-8rxj.json @@ -7,12 +7,8 @@ "CVE-2019-19269" ], "details": "An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4843-wqq7-hm2g/GHSA-4843-wqq7-hm2g.json b/advisories/unreviewed/2022/05/GHSA-4843-wqq7-hm2g/GHSA-4843-wqq7-hm2g.json index cd4a6209047..86c9be65416 100644 --- a/advisories/unreviewed/2022/05/GHSA-4843-wqq7-hm2g/GHSA-4843-wqq7-hm2g.json +++ b/advisories/unreviewed/2022/05/GHSA-4843-wqq7-hm2g/GHSA-4843-wqq7-hm2g.json @@ -7,12 +7,8 @@ "CVE-2019-19698" ], "details": "marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48fp-w2fw-6wx7/GHSA-48fp-w2fw-6wx7.json b/advisories/unreviewed/2022/05/GHSA-48fp-w2fw-6wx7/GHSA-48fp-w2fw-6wx7.json index e681cd85d71..9b501082535 100644 --- a/advisories/unreviewed/2022/05/GHSA-48fp-w2fw-6wx7/GHSA-48fp-w2fw-6wx7.json +++ b/advisories/unreviewed/2022/05/GHSA-48fp-w2fw-6wx7/GHSA-48fp-w2fw-6wx7.json @@ -7,12 +7,8 @@ "CVE-2019-6668" ], "details": "The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.5, and 11.5.1-11.6.5 may allow unprivileged users to access files owned by root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-48mj-hcv4-677q/GHSA-48mj-hcv4-677q.json b/advisories/unreviewed/2022/05/GHSA-48mj-hcv4-677q/GHSA-48mj-hcv4-677q.json index 285cb62f91c..a0af18d04f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-48mj-hcv4-677q/GHSA-48mj-hcv4-677q.json +++ b/advisories/unreviewed/2022/05/GHSA-48mj-hcv4-677q/GHSA-48mj-hcv4-677q.json @@ -7,12 +7,8 @@ "CVE-2006-2473" ], "details": "** DISPUTED ** Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product. The vendor states \"You cannot insert code in a wikipage or via URL parameters as they are all escaped before usage, so nothing can be compromised at other sites.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-495v-rjm6-p653/GHSA-495v-rjm6-p653.json b/advisories/unreviewed/2022/05/GHSA-495v-rjm6-p653/GHSA-495v-rjm6-p653.json index cf18e78d67a..8e234520986 100644 --- a/advisories/unreviewed/2022/05/GHSA-495v-rjm6-p653/GHSA-495v-rjm6-p653.json +++ b/advisories/unreviewed/2022/05/GHSA-495v-rjm6-p653/GHSA-495v-rjm6-p653.json @@ -7,12 +7,8 @@ "CVE-2019-4428" ], "details": "IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162807.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49c3-f2f7-72vq/GHSA-49c3-f2f7-72vq.json b/advisories/unreviewed/2022/05/GHSA-49c3-f2f7-72vq/GHSA-49c3-f2f7-72vq.json index 51cd3554cab..738b38c691d 100644 --- a/advisories/unreviewed/2022/05/GHSA-49c3-f2f7-72vq/GHSA-49c3-f2f7-72vq.json +++ b/advisories/unreviewed/2022/05/GHSA-49c3-f2f7-72vq/GHSA-49c3-f2f7-72vq.json @@ -7,12 +7,8 @@ "CVE-2019-6670" ], "details": "On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5, vCMP hypervisors are incorrectly exposing the plaintext unit key for their vCMP guests on the filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49hc-qhr8-hc53/GHSA-49hc-qhr8-hc53.json b/advisories/unreviewed/2022/05/GHSA-49hc-qhr8-hc53/GHSA-49hc-qhr8-hc53.json index cab67d4aead..bfd3fbacf4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-49hc-qhr8-hc53/GHSA-49hc-qhr8-hc53.json +++ b/advisories/unreviewed/2022/05/GHSA-49hc-qhr8-hc53/GHSA-49hc-qhr8-hc53.json @@ -7,12 +7,8 @@ "CVE-2019-18299" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49j9-mppv-9hcj/GHSA-49j9-mppv-9hcj.json b/advisories/unreviewed/2022/05/GHSA-49j9-mppv-9hcj/GHSA-49j9-mppv-9hcj.json index b22042bd0b0..52af40ad40f 100644 --- a/advisories/unreviewed/2022/05/GHSA-49j9-mppv-9hcj/GHSA-49j9-mppv-9hcj.json +++ b/advisories/unreviewed/2022/05/GHSA-49j9-mppv-9hcj/GHSA-49j9-mppv-9hcj.json @@ -7,12 +7,8 @@ "CVE-2019-5862" ], "details": "Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49jg-7gvc-2mhx/GHSA-49jg-7gvc-2mhx.json b/advisories/unreviewed/2022/05/GHSA-49jg-7gvc-2mhx/GHSA-49jg-7gvc-2mhx.json index 98c89fe100c..85e8ef00a73 100644 --- a/advisories/unreviewed/2022/05/GHSA-49jg-7gvc-2mhx/GHSA-49jg-7gvc-2mhx.json +++ b/advisories/unreviewed/2022/05/GHSA-49jg-7gvc-2mhx/GHSA-49jg-7gvc-2mhx.json @@ -7,12 +7,8 @@ "CVE-2006-5899" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in install.php3 in @cid stats 2.3 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire parameter. NOTE: this issue has been disputed by a third party, who states that install.php3 is supposed to be deleted after installation and, if not deleted, intentionally allows setting repertoire without an inclusion attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c88-v3q4-r75x/GHSA-4c88-v3q4-r75x.json b/advisories/unreviewed/2022/05/GHSA-4c88-v3q4-r75x/GHSA-4c88-v3q4-r75x.json index c107b3a1224..7a2671a96e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c88-v3q4-r75x/GHSA-4c88-v3q4-r75x.json +++ b/advisories/unreviewed/2022/05/GHSA-4c88-v3q4-r75x/GHSA-4c88-v3q4-r75x.json @@ -7,12 +7,8 @@ "CVE-2019-12392" ], "details": "Anviz access control devices allow remote attackers to issue commands without a password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4ch8-97hr-6php/GHSA-4ch8-97hr-6php.json b/advisories/unreviewed/2022/05/GHSA-4ch8-97hr-6php/GHSA-4ch8-97hr-6php.json index e04b5b4a4f2..a1c3bbf141e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ch8-97hr-6php/GHSA-4ch8-97hr-6php.json +++ b/advisories/unreviewed/2022/05/GHSA-4ch8-97hr-6php/GHSA-4ch8-97hr-6php.json @@ -7,12 +7,8 @@ "CVE-2006-0756" ], "details": "** DISPUTED ** dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information. NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4fvh-g75j-hw4j/GHSA-4fvh-g75j-hw4j.json b/advisories/unreviewed/2022/05/GHSA-4fvh-g75j-hw4j/GHSA-4fvh-g75j-hw4j.json index 4c3bde98b73..85c761320f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fvh-g75j-hw4j/GHSA-4fvh-g75j-hw4j.json +++ b/advisories/unreviewed/2022/05/GHSA-4fvh-g75j-hw4j/GHSA-4fvh-g75j-hw4j.json @@ -7,12 +7,8 @@ "CVE-2019-2230" ], "details": "In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141170038", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4g49-qqgp-g5cv/GHSA-4g49-qqgp-g5cv.json b/advisories/unreviewed/2022/05/GHSA-4g49-qqgp-g5cv/GHSA-4g49-qqgp-g5cv.json index dfa63ad28a6..70fd4a98de3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g49-qqgp-g5cv/GHSA-4g49-qqgp-g5cv.json +++ b/advisories/unreviewed/2022/05/GHSA-4g49-qqgp-g5cv/GHSA-4g49-qqgp-g5cv.json @@ -7,12 +7,8 @@ "CVE-2019-18310" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent from CVE-2019-18311. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gg2-9pqf-2qqx/GHSA-4gg2-9pqf-2qqx.json b/advisories/unreviewed/2022/05/GHSA-4gg2-9pqf-2qqx/GHSA-4gg2-9pqf-2qqx.json index 2bea5e8d93b..a34f92c23f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gg2-9pqf-2qqx/GHSA-4gg2-9pqf-2qqx.json +++ b/advisories/unreviewed/2022/05/GHSA-4gg2-9pqf-2qqx/GHSA-4gg2-9pqf-2qqx.json @@ -7,12 +7,8 @@ "CVE-2019-15996" ], "details": "A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient restrictions during the execution of an affected CLI command. An attacker could exploit this vulnerability by leveraging the insufficient restrictions to modify sensitive files. A successful exploit could allow the attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gj6-pp76-wxr5/GHSA-4gj6-pp76-wxr5.json b/advisories/unreviewed/2022/05/GHSA-4gj6-pp76-wxr5/GHSA-4gj6-pp76-wxr5.json index d8ebbf56abc..20b96bdc437 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gj6-pp76-wxr5/GHSA-4gj6-pp76-wxr5.json +++ b/advisories/unreviewed/2022/05/GHSA-4gj6-pp76-wxr5/GHSA-4gj6-pp76-wxr5.json @@ -7,12 +7,8 @@ "CVE-2019-15958" ], "details": "A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA) configuration and registration process of an affected device. An attacker could exploit this vulnerability by uploading a malicious file during the HA registration period. A successful exploit could allow the attacker to execute arbitrary code with root-level privileges on the underlying operating system. Note: This vulnerability can only be exploited during the HA registration period. See the Details section for more information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gvp-5rhp-p6xg/GHSA-4gvp-5rhp-p6xg.json b/advisories/unreviewed/2022/05/GHSA-4gvp-5rhp-p6xg/GHSA-4gvp-5rhp-p6xg.json index 5ea225bf309..f5262713ef1 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gvp-5rhp-p6xg/GHSA-4gvp-5rhp-p6xg.json +++ b/advisories/unreviewed/2022/05/GHSA-4gvp-5rhp-p6xg/GHSA-4gvp-5rhp-p6xg.json @@ -7,12 +7,8 @@ "CVE-2019-4611" ], "details": "IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168519.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4h4q-q4v8-2vq3/GHSA-4h4q-q4v8-2vq3.json b/advisories/unreviewed/2022/05/GHSA-4h4q-q4v8-2vq3/GHSA-4h4q-q4v8-2vq3.json index eafa72cd36d..57fe4b9e00c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h4q-q4v8-2vq3/GHSA-4h4q-q4v8-2vq3.json +++ b/advisories/unreviewed/2022/05/GHSA-4h4q-q4v8-2vq3/GHSA-4h4q-q4v8-2vq3.json @@ -7,12 +7,8 @@ "CVE-2019-18679" ], "details": "An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hv9-r59c-6rwm/GHSA-4hv9-r59c-6rwm.json b/advisories/unreviewed/2022/05/GHSA-4hv9-r59c-6rwm/GHSA-4hv9-r59c-6rwm.json index 8bed4f345b2..61d4cc13c61 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hv9-r59c-6rwm/GHSA-4hv9-r59c-6rwm.json +++ b/advisories/unreviewed/2022/05/GHSA-4hv9-r59c-6rwm/GHSA-4hv9-r59c-6rwm.json @@ -7,12 +7,8 @@ "CVE-2019-13662" ], "details": "Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hvc-j7g6-287c/GHSA-4hvc-j7g6-287c.json b/advisories/unreviewed/2022/05/GHSA-4hvc-j7g6-287c/GHSA-4hvc-j7g6-287c.json index f1ec996f8f6..0834421e08a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hvc-j7g6-287c/GHSA-4hvc-j7g6-287c.json +++ b/advisories/unreviewed/2022/05/GHSA-4hvc-j7g6-287c/GHSA-4hvc-j7g6-287c.json @@ -7,12 +7,8 @@ "CVE-2019-2232" ], "details": "In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140632678", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hxg-f64g-48jf/GHSA-4hxg-f64g-48jf.json b/advisories/unreviewed/2022/05/GHSA-4hxg-f64g-48jf/GHSA-4hxg-f64g-48jf.json index 58df1ac0ea3..b968156acb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hxg-f64g-48jf/GHSA-4hxg-f64g-48jf.json +++ b/advisories/unreviewed/2022/05/GHSA-4hxg-f64g-48jf/GHSA-4hxg-f64g-48jf.json @@ -7,12 +7,8 @@ "CVE-2019-5271" ], "details": "There is an information leak vulnerability in Huawei smart speaker Myna. When the smart speaker is paired with the cloud through Wi-Fi, the speaker incorrectly processes some data. Attackers can exploit this vulnerability to read and modify specific configurations of speakers through a series of operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4m37-jfjg-49pc/GHSA-4m37-jfjg-49pc.json b/advisories/unreviewed/2022/05/GHSA-4m37-jfjg-49pc/GHSA-4m37-jfjg-49pc.json index 9a45bc68e92..2b4aa6a27a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m37-jfjg-49pc/GHSA-4m37-jfjg-49pc.json +++ b/advisories/unreviewed/2022/05/GHSA-4m37-jfjg-49pc/GHSA-4m37-jfjg-49pc.json @@ -7,12 +7,8 @@ "CVE-2019-5226" ], "details": "P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4m76-jxv9-f5pc/GHSA-4m76-jxv9-f5pc.json b/advisories/unreviewed/2022/05/GHSA-4m76-jxv9-f5pc/GHSA-4m76-jxv9-f5pc.json index 44cfdf1cb48..16f45fbff1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m76-jxv9-f5pc/GHSA-4m76-jxv9-f5pc.json +++ b/advisories/unreviewed/2022/05/GHSA-4m76-jxv9-f5pc/GHSA-4m76-jxv9-f5pc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pc3-99rp-r89j/GHSA-4pc3-99rp-r89j.json b/advisories/unreviewed/2022/05/GHSA-4pc3-99rp-r89j/GHSA-4pc3-99rp-r89j.json index a5c50e425d1..173545b5372 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pc3-99rp-r89j/GHSA-4pc3-99rp-r89j.json +++ b/advisories/unreviewed/2022/05/GHSA-4pc3-99rp-r89j/GHSA-4pc3-99rp-r89j.json @@ -7,12 +7,8 @@ "CVE-2019-19647" ], "details": "radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted input.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pvf-m5rq-4jwf/GHSA-4pvf-m5rq-4jwf.json b/advisories/unreviewed/2022/05/GHSA-4pvf-m5rq-4jwf/GHSA-4pvf-m5rq-4jwf.json index 359637ccc89..1f10bf5bc5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pvf-m5rq-4jwf/GHSA-4pvf-m5rq-4jwf.json +++ b/advisories/unreviewed/2022/05/GHSA-4pvf-m5rq-4jwf/GHSA-4pvf-m5rq-4jwf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qvm-8x6x-vhwj/GHSA-4qvm-8x6x-vhwj.json b/advisories/unreviewed/2022/05/GHSA-4qvm-8x6x-vhwj/GHSA-4qvm-8x6x-vhwj.json index 0bf2b901eed..2680f35c0e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qvm-8x6x-vhwj/GHSA-4qvm-8x6x-vhwj.json +++ b/advisories/unreviewed/2022/05/GHSA-4qvm-8x6x-vhwj/GHSA-4qvm-8x6x-vhwj.json @@ -7,12 +7,8 @@ "CVE-2006-5159" ], "details": "** DISPUTED ** Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving JavaScript. NOTE: the vendor and original researchers have released a follow-up comment disputing the severity of this issue, in which the researcher states that \"we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution. However, the code we presented did not in fact do this... I have not succeeded in making this code do anything more than cause a crash and eat up system resources\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4r86-rrx3-8x44/GHSA-4r86-rrx3-8x44.json b/advisories/unreviewed/2022/05/GHSA-4r86-rrx3-8x44/GHSA-4r86-rrx3-8x44.json index 01c92f87f50..94a28633684 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r86-rrx3-8x44/GHSA-4r86-rrx3-8x44.json +++ b/advisories/unreviewed/2022/05/GHSA-4r86-rrx3-8x44/GHSA-4r86-rrx3-8x44.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rfv-87fp-qxfm/GHSA-4rfv-87fp-qxfm.json b/advisories/unreviewed/2022/05/GHSA-4rfv-87fp-qxfm/GHSA-4rfv-87fp-qxfm.json index 372df2ed954..cf1de4b0661 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rfv-87fp-qxfm/GHSA-4rfv-87fp-qxfm.json +++ b/advisories/unreviewed/2022/05/GHSA-4rfv-87fp-qxfm/GHSA-4rfv-87fp-qxfm.json @@ -7,12 +7,8 @@ "CVE-2019-15629" ], "details": "Trend Micro Password Manager versions 3.x, 5.0, and 5.1 for Android is affected by a FLAG_MISUSE vulnerability that could be exploited to allow the application to share information to third-party applications on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rgc-4rc7-mg92/GHSA-4rgc-4rc7-mg92.json b/advisories/unreviewed/2022/05/GHSA-4rgc-4rc7-mg92/GHSA-4rgc-4rc7-mg92.json index 2c8842699b2..d2109715349 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rgc-4rc7-mg92/GHSA-4rgc-4rc7-mg92.json +++ b/advisories/unreviewed/2022/05/GHSA-4rgc-4rc7-mg92/GHSA-4rgc-4rc7-mg92.json @@ -7,12 +7,8 @@ "CVE-2005-4398" ], "details": "** DISPUTED ** NOTE: the vendor has disputed this issue. Cross-site scripting (XSS) vulnerability in lemoon 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the q parameter. NOTE: the vendor has disputed this issue, saying \"Sites are built on top of ASP.NET and you use lemoon core objects to easily manage and render content. The XSS vuln. you are referring to exists in one of our public sites built on lemoon i.e. a custom made site (as all sites are). The problem exists in a UserControl that handles form input and is in no way related to the lemoon core product.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rh7-2jj4-cgm5/GHSA-4rh7-2jj4-cgm5.json b/advisories/unreviewed/2022/05/GHSA-4rh7-2jj4-cgm5/GHSA-4rh7-2jj4-cgm5.json index ced8d073cfd..b325909f7d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rh7-2jj4-cgm5/GHSA-4rh7-2jj4-cgm5.json +++ b/advisories/unreviewed/2022/05/GHSA-4rh7-2jj4-cgm5/GHSA-4rh7-2jj4-cgm5.json @@ -7,12 +7,8 @@ "CVE-2019-3987" ], "details": "Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rjf-927h-4fjw/GHSA-4rjf-927h-4fjw.json b/advisories/unreviewed/2022/05/GHSA-4rjf-927h-4fjw/GHSA-4rjf-927h-4fjw.json index b1e28894ad7..29ff31b6435 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rjf-927h-4fjw/GHSA-4rjf-927h-4fjw.json +++ b/advisories/unreviewed/2022/05/GHSA-4rjf-927h-4fjw/GHSA-4rjf-927h-4fjw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rmj-jvqp-j56r/GHSA-4rmj-jvqp-j56r.json b/advisories/unreviewed/2022/05/GHSA-4rmj-jvqp-j56r/GHSA-4rmj-jvqp-j56r.json index 46af7ef1b00..76878eae561 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rmj-jvqp-j56r/GHSA-4rmj-jvqp-j56r.json +++ b/advisories/unreviewed/2022/05/GHSA-4rmj-jvqp-j56r/GHSA-4rmj-jvqp-j56r.json @@ -7,12 +7,8 @@ "CVE-2019-5290" ], "details": "Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform specific operations on affected devices. Because the pointer in the program is not processed properly, the vulnerability can be exploited to cause the device to be abnormal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4v29-x97x-vq7r/GHSA-4v29-x97x-vq7r.json b/advisories/unreviewed/2022/05/GHSA-4v29-x97x-vq7r/GHSA-4v29-x97x-vq7r.json index fd7498caa86..b3a51c70505 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v29-x97x-vq7r/GHSA-4v29-x97x-vq7r.json +++ b/advisories/unreviewed/2022/05/GHSA-4v29-x97x-vq7r/GHSA-4v29-x97x-vq7r.json @@ -7,12 +7,8 @@ "CVE-2019-5875" ], "details": "Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4v9p-4wgj-v3f6/GHSA-4v9p-4wgj-v3f6.json b/advisories/unreviewed/2022/05/GHSA-4v9p-4wgj-v3f6/GHSA-4v9p-4wgj-v3f6.json index af8a5d204bb..f9b3b9d70b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v9p-4wgj-v3f6/GHSA-4v9p-4wgj-v3f6.json +++ b/advisories/unreviewed/2022/05/GHSA-4v9p-4wgj-v3f6/GHSA-4v9p-4wgj-v3f6.json @@ -7,12 +7,8 @@ "CVE-2019-18450" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vp4-vvrc-wvhx/GHSA-4vp4-vvrc-wvhx.json b/advisories/unreviewed/2022/05/GHSA-4vp4-vvrc-wvhx/GHSA-4vp4-vvrc-wvhx.json index d02f5742433..5ff4d687c85 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vp4-vvrc-wvhx/GHSA-4vp4-vvrc-wvhx.json +++ b/advisories/unreviewed/2022/05/GHSA-4vp4-vvrc-wvhx/GHSA-4vp4-vvrc-wvhx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vq3-2rwv-w7mg/GHSA-4vq3-2rwv-w7mg.json b/advisories/unreviewed/2022/05/GHSA-4vq3-2rwv-w7mg/GHSA-4vq3-2rwv-w7mg.json index d39be7d9560..0d548c0f87e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vq3-2rwv-w7mg/GHSA-4vq3-2rwv-w7mg.json +++ b/advisories/unreviewed/2022/05/GHSA-4vq3-2rwv-w7mg/GHSA-4vq3-2rwv-w7mg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w37-wxvx-pgmp/GHSA-4w37-wxvx-pgmp.json b/advisories/unreviewed/2022/05/GHSA-4w37-wxvx-pgmp/GHSA-4w37-wxvx-pgmp.json index 3508fb2cdba..cde0ea24258 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w37-wxvx-pgmp/GHSA-4w37-wxvx-pgmp.json +++ b/advisories/unreviewed/2022/05/GHSA-4w37-wxvx-pgmp/GHSA-4w37-wxvx-pgmp.json @@ -7,12 +7,8 @@ "CVE-2019-15687" ], "details": "Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version of the product, host unique ID). Information Disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wch-cg8h-vqc6/GHSA-4wch-cg8h-vqc6.json b/advisories/unreviewed/2022/05/GHSA-4wch-cg8h-vqc6/GHSA-4wch-cg8h-vqc6.json index 5699672ec71..b0d40860a6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wch-cg8h-vqc6/GHSA-4wch-cg8h-vqc6.json +++ b/advisories/unreviewed/2022/05/GHSA-4wch-cg8h-vqc6/GHSA-4wch-cg8h-vqc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4whf-mx4r-v53w/GHSA-4whf-mx4r-v53w.json b/advisories/unreviewed/2022/05/GHSA-4whf-mx4r-v53w/GHSA-4whf-mx4r-v53w.json index c2df634bd5c..c54fa7712c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4whf-mx4r-v53w/GHSA-4whf-mx4r-v53w.json +++ b/advisories/unreviewed/2022/05/GHSA-4whf-mx4r-v53w/GHSA-4whf-mx4r-v53w.json @@ -7,12 +7,8 @@ "CVE-2019-4715" ], "details": "IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172093.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wmp-vxgh-6898/GHSA-4wmp-vxgh-6898.json b/advisories/unreviewed/2022/05/GHSA-4wmp-vxgh-6898/GHSA-4wmp-vxgh-6898.json index 263c2f3fdd6..d85e1b08c47 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wmp-vxgh-6898/GHSA-4wmp-vxgh-6898.json +++ b/advisories/unreviewed/2022/05/GHSA-4wmp-vxgh-6898/GHSA-4wmp-vxgh-6898.json @@ -7,12 +7,8 @@ "CVE-2019-19678" ], "details": "In \"Xray Test Management for Jira\" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic field entry point via the Generic Test Definition field of a new Generic Test issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4wwx-wcpc-49m3/GHSA-4wwx-wcpc-49m3.json b/advisories/unreviewed/2022/05/GHSA-4wwx-wcpc-49m3/GHSA-4wwx-wcpc-49m3.json index 2923101e9b5..8627616a22a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wwx-wcpc-49m3/GHSA-4wwx-wcpc-49m3.json +++ b/advisories/unreviewed/2022/05/GHSA-4wwx-wcpc-49m3/GHSA-4wwx-wcpc-49m3.json @@ -7,12 +7,8 @@ "CVE-2019-10555" ], "details": "Buffer overflow can occur due to usage of wrong datatype and missing length check before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x8v-74xf-h4g3/GHSA-4x8v-74xf-h4g3.json b/advisories/unreviewed/2022/05/GHSA-4x8v-74xf-h4g3/GHSA-4x8v-74xf-h4g3.json index 66768a6c537..d1ec5c89376 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x8v-74xf-h4g3/GHSA-4x8v-74xf-h4g3.json +++ b/advisories/unreviewed/2022/05/GHSA-4x8v-74xf-h4g3/GHSA-4x8v-74xf-h4g3.json @@ -7,12 +7,8 @@ "CVE-2015-1855" ], "details": "verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xp3-xqhc-qc2g/GHSA-4xp3-xqhc-qc2g.json b/advisories/unreviewed/2022/05/GHSA-4xp3-xqhc-qc2g/GHSA-4xp3-xqhc-qc2g.json index fcfb9e34f28..3a9bc7f5a4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xp3-xqhc-qc2g/GHSA-4xp3-xqhc-qc2g.json +++ b/advisories/unreviewed/2022/05/GHSA-4xp3-xqhc-qc2g/GHSA-4xp3-xqhc-qc2g.json @@ -7,12 +7,8 @@ "CVE-2019-13934" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5295-c598-qcfh/GHSA-5295-c598-qcfh.json b/advisories/unreviewed/2022/05/GHSA-5295-c598-qcfh/GHSA-5295-c598-qcfh.json index e0d8b9e3537..16a87b30973 100644 --- a/advisories/unreviewed/2022/05/GHSA-5295-c598-qcfh/GHSA-5295-c598-qcfh.json +++ b/advisories/unreviewed/2022/05/GHSA-5295-c598-qcfh/GHSA-5295-c598-qcfh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-547c-mr84-jpm5/GHSA-547c-mr84-jpm5.json b/advisories/unreviewed/2022/05/GHSA-547c-mr84-jpm5/GHSA-547c-mr84-jpm5.json index b7bc95dea46..2f1b4be7eed 100644 --- a/advisories/unreviewed/2022/05/GHSA-547c-mr84-jpm5/GHSA-547c-mr84-jpm5.json +++ b/advisories/unreviewed/2022/05/GHSA-547c-mr84-jpm5/GHSA-547c-mr84-jpm5.json @@ -7,12 +7,8 @@ "CVE-2019-10511" ], "details": "Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54x3-6856-52f3/GHSA-54x3-6856-52f3.json b/advisories/unreviewed/2022/05/GHSA-54x3-6856-52f3/GHSA-54x3-6856-52f3.json index 1f33f62583b..fee60325176 100644 --- a/advisories/unreviewed/2022/05/GHSA-54x3-6856-52f3/GHSA-54x3-6856-52f3.json +++ b/advisories/unreviewed/2022/05/GHSA-54x3-6856-52f3/GHSA-54x3-6856-52f3.json @@ -7,12 +7,8 @@ "CVE-2019-4465" ], "details": "IBM Cloud Pak System 2.3 and 2.3.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 163774.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57fv-c5qh-rxvp/GHSA-57fv-c5qh-rxvp.json b/advisories/unreviewed/2022/05/GHSA-57fv-c5qh-rxvp/GHSA-57fv-c5qh-rxvp.json index 1c239354ed7..ec6961a2745 100644 --- a/advisories/unreviewed/2022/05/GHSA-57fv-c5qh-rxvp/GHSA-57fv-c5qh-rxvp.json +++ b/advisories/unreviewed/2022/05/GHSA-57fv-c5qh-rxvp/GHSA-57fv-c5qh-rxvp.json @@ -7,12 +7,8 @@ "CVE-2019-18461" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5869-5hjv-gvqp/GHSA-5869-5hjv-gvqp.json b/advisories/unreviewed/2022/05/GHSA-5869-5hjv-gvqp/GHSA-5869-5hjv-gvqp.json index 662d53067f6..586bc26bd48 100644 --- a/advisories/unreviewed/2022/05/GHSA-5869-5hjv-gvqp/GHSA-5869-5hjv-gvqp.json +++ b/advisories/unreviewed/2022/05/GHSA-5869-5hjv-gvqp/GHSA-5869-5hjv-gvqp.json @@ -7,12 +7,8 @@ "CVE-2019-19528" ], "details": "In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5889-mgfj-pp8r/GHSA-5889-mgfj-pp8r.json b/advisories/unreviewed/2022/05/GHSA-5889-mgfj-pp8r/GHSA-5889-mgfj-pp8r.json index 6b916f4fcdd..bd335722193 100644 --- a/advisories/unreviewed/2022/05/GHSA-5889-mgfj-pp8r/GHSA-5889-mgfj-pp8r.json +++ b/advisories/unreviewed/2022/05/GHSA-5889-mgfj-pp8r/GHSA-5889-mgfj-pp8r.json @@ -7,12 +7,8 @@ "CVE-2019-4387" ], "details": "IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 162715.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-593f-7j6m-g5gq/GHSA-593f-7j6m-g5gq.json b/advisories/unreviewed/2022/05/GHSA-593f-7j6m-g5gq/GHSA-593f-7j6m-g5gq.json index b63f4608aab..0d627c04d3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-593f-7j6m-g5gq/GHSA-593f-7j6m-g5gq.json +++ b/advisories/unreviewed/2022/05/GHSA-593f-7j6m-g5gq/GHSA-593f-7j6m-g5gq.json @@ -7,12 +7,8 @@ "CVE-2019-18379" ], "details": "Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a vulnerable web application or access services available through the loopback interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5f2h-r2x9-9p3v/GHSA-5f2h-r2x9-9p3v.json b/advisories/unreviewed/2022/05/GHSA-5f2h-r2x9-9p3v/GHSA-5f2h-r2x9-9p3v.json index aa958d226ce..b687350a103 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f2h-r2x9-9p3v/GHSA-5f2h-r2x9-9p3v.json +++ b/advisories/unreviewed/2022/05/GHSA-5f2h-r2x9-9p3v/GHSA-5f2h-r2x9-9p3v.json @@ -7,12 +7,8 @@ "CVE-2019-19580" ], "details": "An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421. XSA-299 addressed several critical issues in restartable PV type change operations. Despite extensive testing and auditing, some corner cases were missed. A malicious PV guest administrator may be able to escalate their privilege to that of the host. All security-supported versions of Xen are vulnerable. Only x86 systems are affected. Arm systems are not affected. Only x86 PV guests can leverage the vulnerability. x86 HVM and PVH guests cannot leverage the vulnerability. Note that these attacks require very precise timing, which may be difficult to exploit in practice.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5g75-j346-c9xj/GHSA-5g75-j346-c9xj.json b/advisories/unreviewed/2022/05/GHSA-5g75-j346-c9xj/GHSA-5g75-j346-c9xj.json index 34ce120d41a..a9ba47f13bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g75-j346-c9xj/GHSA-5g75-j346-c9xj.json +++ b/advisories/unreviewed/2022/05/GHSA-5g75-j346-c9xj/GHSA-5g75-j346-c9xj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gm2-9h87-hc2f/GHSA-5gm2-9h87-hc2f.json b/advisories/unreviewed/2022/05/GHSA-5gm2-9h87-hc2f/GHSA-5gm2-9h87-hc2f.json index 5c6a730f1de..5b2a408e311 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gm2-9h87-hc2f/GHSA-5gm2-9h87-hc2f.json +++ b/advisories/unreviewed/2022/05/GHSA-5gm2-9h87-hc2f/GHSA-5gm2-9h87-hc2f.json @@ -7,12 +7,8 @@ "CVE-2019-2337" ], "details": "While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which may cause device to shutdown in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5h7g-3542-fw4q/GHSA-5h7g-3542-fw4q.json b/advisories/unreviewed/2022/05/GHSA-5h7g-3542-fw4q/GHSA-5h7g-3542-fw4q.json index 29b8d804b40..360120026fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h7g-3542-fw4q/GHSA-5h7g-3542-fw4q.json +++ b/advisories/unreviewed/2022/05/GHSA-5h7g-3542-fw4q/GHSA-5h7g-3542-fw4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jf4-jh9g-7766/GHSA-5jf4-jh9g-7766.json b/advisories/unreviewed/2022/05/GHSA-5jf4-jh9g-7766/GHSA-5jf4-jh9g-7766.json index 80d627b14be..155f3fcb2f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jf4-jh9g-7766/GHSA-5jf4-jh9g-7766.json +++ b/advisories/unreviewed/2022/05/GHSA-5jf4-jh9g-7766/GHSA-5jf4-jh9g-7766.json @@ -7,12 +7,8 @@ "CVE-2019-16767" ], "details": "The admin sys mode is now conditional and dedicated for the special case. By default, since ezmaster@5.2.11 no instance (container) is launched with advanced capabilities (not launched as root)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "WEB", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5m27-xjxh-cpq9/GHSA-5m27-xjxh-cpq9.json b/advisories/unreviewed/2022/05/GHSA-5m27-xjxh-cpq9/GHSA-5m27-xjxh-cpq9.json index d8784fcd818..09a7cab1452 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m27-xjxh-cpq9/GHSA-5m27-xjxh-cpq9.json +++ b/advisories/unreviewed/2022/05/GHSA-5m27-xjxh-cpq9/GHSA-5m27-xjxh-cpq9.json @@ -7,12 +7,8 @@ "CVE-2019-5263" ], "details": "HiSuite with 9.1.0.305 and earlier versions and 9.1.0.305(MAC) and earlier versions and HwBackup with earlier versions before 9.1.1.308 have a brute forcing encrypted backup data vulnerability. Huawei smartphone user backup information can be obtained by brute forcing the password for encrypting the backup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mfp-2mj8-6gh2/GHSA-5mfp-2mj8-6gh2.json b/advisories/unreviewed/2022/05/GHSA-5mfp-2mj8-6gh2/GHSA-5mfp-2mj8-6gh2.json index 750a9806ca8..ee9c8638cf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mfp-2mj8-6gh2/GHSA-5mfp-2mj8-6gh2.json +++ b/advisories/unreviewed/2022/05/GHSA-5mfp-2mj8-6gh2/GHSA-5mfp-2mj8-6gh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5mr2-62qq-29fg/GHSA-5mr2-62qq-29fg.json b/advisories/unreviewed/2022/05/GHSA-5mr2-62qq-29fg/GHSA-5mr2-62qq-29fg.json index a925ad035f7..d3a0f520bbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mr2-62qq-29fg/GHSA-5mr2-62qq-29fg.json +++ b/advisories/unreviewed/2022/05/GHSA-5mr2-62qq-29fg/GHSA-5mr2-62qq-29fg.json @@ -7,12 +7,8 @@ "CVE-2019-5212" ], "details": "There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to certain file from certain application. An attacker tricks the user into installing a malicious application then establishing a connect to the attacker through Huawei Share, successful exploit could cause information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mw6-ccfh-2c33/GHSA-5mw6-ccfh-2c33.json b/advisories/unreviewed/2022/05/GHSA-5mw6-ccfh-2c33/GHSA-5mw6-ccfh-2c33.json index 3045093d9ff..44e4ea7409b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mw6-ccfh-2c33/GHSA-5mw6-ccfh-2c33.json +++ b/advisories/unreviewed/2022/05/GHSA-5mw6-ccfh-2c33/GHSA-5mw6-ccfh-2c33.json @@ -7,12 +7,8 @@ "CVE-2019-12503" ], "details": "Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is unattended. In this way, an attacker can remotely take control over the victim's computer that is operated with an affected receiver of this device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pcr-82rc-g5mf/GHSA-5pcr-82rc-g5mf.json b/advisories/unreviewed/2022/05/GHSA-5pcr-82rc-g5mf/GHSA-5pcr-82rc-g5mf.json index e013cb321f3..64fbab589c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pcr-82rc-g5mf/GHSA-5pcr-82rc-g5mf.json +++ b/advisories/unreviewed/2022/05/GHSA-5pcr-82rc-g5mf/GHSA-5pcr-82rc-g5mf.json @@ -7,12 +7,8 @@ "CVE-2019-5871" ], "details": "Heap buffer overflow in Skia in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pjj-3qp3-rjg3/GHSA-5pjj-3qp3-rjg3.json b/advisories/unreviewed/2022/05/GHSA-5pjj-3qp3-rjg3/GHSA-5pjj-3qp3-rjg3.json index 41bdc4a3c85..85e11fc65c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pjj-3qp3-rjg3/GHSA-5pjj-3qp3-rjg3.json +++ b/advisories/unreviewed/2022/05/GHSA-5pjj-3qp3-rjg3/GHSA-5pjj-3qp3-rjg3.json @@ -7,12 +7,8 @@ "CVE-2019-19270" ], "details": "An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow clients whose certificates have been revoked to proceed with a connection to the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pwx-hqqw-2m2r/GHSA-5pwx-hqqw-2m2r.json b/advisories/unreviewed/2022/05/GHSA-5pwx-hqqw-2m2r/GHSA-5pwx-hqqw-2m2r.json index 66f56986692..afba012db05 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pwx-hqqw-2m2r/GHSA-5pwx-hqqw-2m2r.json +++ b/advisories/unreviewed/2022/05/GHSA-5pwx-hqqw-2m2r/GHSA-5pwx-hqqw-2m2r.json @@ -7,12 +7,8 @@ "CVE-2019-5211" ], "details": "The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management vulnerability. The attacker tricks the victim to perform certain operations on the mobile phone during file transfer. Because the file is not properly processed, successfully exploit may cause some files on the victim's mobile phone are deleted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5qwf-cc5w-wpvx/GHSA-5qwf-cc5w-wpvx.json b/advisories/unreviewed/2022/05/GHSA-5qwf-cc5w-wpvx/GHSA-5qwf-cc5w-wpvx.json index 10b0c6da54c..1c012fd5cfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qwf-cc5w-wpvx/GHSA-5qwf-cc5w-wpvx.json +++ b/advisories/unreviewed/2022/05/GHSA-5qwf-cc5w-wpvx/GHSA-5qwf-cc5w-wpvx.json @@ -7,12 +7,8 @@ "CVE-2019-13724" ], "details": "Out of bounds memory access in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5v5p-mmf9-j38j/GHSA-5v5p-mmf9-j38j.json b/advisories/unreviewed/2022/05/GHSA-5v5p-mmf9-j38j/GHSA-5v5p-mmf9-j38j.json index a8a9004bce9..cbe2cef81a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v5p-mmf9-j38j/GHSA-5v5p-mmf9-j38j.json +++ b/advisories/unreviewed/2022/05/GHSA-5v5p-mmf9-j38j/GHSA-5v5p-mmf9-j38j.json @@ -7,12 +7,8 @@ "CVE-2019-6673" ], "details": "On versions 15.0.0-15.0.1 and 14.0.0-14.1.2, when the BIG-IP is configured in HTTP/2 Full Proxy mode, specifically crafted requests may cause a disruption of service provided by the Traffic Management Microkernel (TMM).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5x59-c34p-cff9/GHSA-5x59-c34p-cff9.json b/advisories/unreviewed/2022/05/GHSA-5x59-c34p-cff9/GHSA-5x59-c34p-cff9.json index 05b22409223..c9203858d8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x59-c34p-cff9/GHSA-5x59-c34p-cff9.json +++ b/advisories/unreviewed/2022/05/GHSA-5x59-c34p-cff9/GHSA-5x59-c34p-cff9.json @@ -7,12 +7,8 @@ "CVE-2016-5724" ], "details": "Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6283-q875-5qpp/GHSA-6283-q875-5qpp.json b/advisories/unreviewed/2022/05/GHSA-6283-q875-5qpp/GHSA-6283-q875-5qpp.json index e3c5bf960ac..c1eca1f4ca2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6283-q875-5qpp/GHSA-6283-q875-5qpp.json +++ b/advisories/unreviewed/2022/05/GHSA-6283-q875-5qpp/GHSA-6283-q875-5qpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62cc-g9f4-2r2g/GHSA-62cc-g9f4-2r2g.json b/advisories/unreviewed/2022/05/GHSA-62cc-g9f4-2r2g/GHSA-62cc-g9f4-2r2g.json index 277bc3f2c64..5c2764075e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-62cc-g9f4-2r2g/GHSA-62cc-g9f4-2r2g.json +++ b/advisories/unreviewed/2022/05/GHSA-62cc-g9f4-2r2g/GHSA-62cc-g9f4-2r2g.json @@ -7,12 +7,8 @@ "CVE-2019-13721" ], "details": "Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-645m-h3pw-m72w/GHSA-645m-h3pw-m72w.json b/advisories/unreviewed/2022/05/GHSA-645m-h3pw-m72w/GHSA-645m-h3pw-m72w.json index 61f236102cc..613f3a2a81a 100644 --- a/advisories/unreviewed/2022/05/GHSA-645m-h3pw-m72w/GHSA-645m-h3pw-m72w.json +++ b/advisories/unreviewed/2022/05/GHSA-645m-h3pw-m72w/GHSA-645m-h3pw-m72w.json @@ -7,12 +7,8 @@ "CVE-2019-18460" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6484-844c-qmh4/GHSA-6484-844c-qmh4.json b/advisories/unreviewed/2022/05/GHSA-6484-844c-qmh4/GHSA-6484-844c-qmh4.json index 18d4f599ec9..0f430876637 100644 --- a/advisories/unreviewed/2022/05/GHSA-6484-844c-qmh4/GHSA-6484-844c-qmh4.json +++ b/advisories/unreviewed/2022/05/GHSA-6484-844c-qmh4/GHSA-6484-844c-qmh4.json @@ -7,12 +7,8 @@ "CVE-2019-2320" ], "details": "Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66ph-x3g8-qwxf/GHSA-66ph-x3g8-qwxf.json b/advisories/unreviewed/2022/05/GHSA-66ph-x3g8-qwxf/GHSA-66ph-x3g8-qwxf.json index 08522b21691..c11085e928f 100644 --- a/advisories/unreviewed/2022/05/GHSA-66ph-x3g8-qwxf/GHSA-66ph-x3g8-qwxf.json +++ b/advisories/unreviewed/2022/05/GHSA-66ph-x3g8-qwxf/GHSA-66ph-x3g8-qwxf.json @@ -7,12 +7,8 @@ "CVE-2019-7366" ], "details": "Buffer overflow vulnerability in Autodesk FBX Software Development Kit version 2019.5. A user may be tricked into opening a malicious FBX file which may exploit a buffer overflow vulnerability causing it to run arbitrary code on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-67rp-x49w-2277/GHSA-67rp-x49w-2277.json b/advisories/unreviewed/2022/05/GHSA-67rp-x49w-2277/GHSA-67rp-x49w-2277.json index cd4e1f92509..40100bcb277 100644 --- a/advisories/unreviewed/2022/05/GHSA-67rp-x49w-2277/GHSA-67rp-x49w-2277.json +++ b/advisories/unreviewed/2022/05/GHSA-67rp-x49w-2277/GHSA-67rp-x49w-2277.json @@ -7,12 +7,8 @@ "CVE-2019-19590" ], "details": "In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer overflow will result in a Use-After-Free for the buffer tokens, which can be filled with arbitrary malicious data after the free. This allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted input.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-696f-85gv-7m8g/GHSA-696f-85gv-7m8g.json b/advisories/unreviewed/2022/05/GHSA-696f-85gv-7m8g/GHSA-696f-85gv-7m8g.json index 82f8700998f..a22de73fffc 100644 --- a/advisories/unreviewed/2022/05/GHSA-696f-85gv-7m8g/GHSA-696f-85gv-7m8g.json +++ b/advisories/unreviewed/2022/05/GHSA-696f-85gv-7m8g/GHSA-696f-85gv-7m8g.json @@ -7,12 +7,8 @@ "CVE-2019-18295" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18293, and CVE-2019-18296. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69g2-j5hm-jq2w/GHSA-69g2-j5hm-jq2w.json b/advisories/unreviewed/2022/05/GHSA-69g2-j5hm-jq2w/GHSA-69g2-j5hm-jq2w.json index 8df12f6f6f4..28768f4928b 100644 --- a/advisories/unreviewed/2022/05/GHSA-69g2-j5hm-jq2w/GHSA-69g2-j5hm-jq2w.json +++ b/advisories/unreviewed/2022/05/GHSA-69g2-j5hm-jq2w/GHSA-69g2-j5hm-jq2w.json @@ -7,12 +7,8 @@ "CVE-2019-5098" ], "details": "An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69xv-rvvx-vm7w/GHSA-69xv-rvvx-vm7w.json b/advisories/unreviewed/2022/05/GHSA-69xv-rvvx-vm7w/GHSA-69xv-rvvx-vm7w.json index 893b92c1a63..2b4fd6a8b63 100644 --- a/advisories/unreviewed/2022/05/GHSA-69xv-rvvx-vm7w/GHSA-69xv-rvvx-vm7w.json +++ b/advisories/unreviewed/2022/05/GHSA-69xv-rvvx-vm7w/GHSA-69xv-rvvx-vm7w.json @@ -7,12 +7,8 @@ "CVE-2019-18329" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18324, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18328, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cfc-j55p-2wvq/GHSA-6cfc-j55p-2wvq.json b/advisories/unreviewed/2022/05/GHSA-6cfc-j55p-2wvq/GHSA-6cfc-j55p-2wvq.json index 6d80c7e1a5b..1bed8bb18a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cfc-j55p-2wvq/GHSA-6cfc-j55p-2wvq.json +++ b/advisories/unreviewed/2022/05/GHSA-6cfc-j55p-2wvq/GHSA-6cfc-j55p-2wvq.json @@ -7,12 +7,8 @@ "CVE-2019-13697" ], "details": "Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6chg-8whj-347g/GHSA-6chg-8whj-347g.json b/advisories/unreviewed/2022/05/GHSA-6chg-8whj-347g/GHSA-6chg-8whj-347g.json index c67ec10afde..ddbf453f194 100644 --- a/advisories/unreviewed/2022/05/GHSA-6chg-8whj-347g/GHSA-6chg-8whj-347g.json +++ b/advisories/unreviewed/2022/05/GHSA-6chg-8whj-347g/GHSA-6chg-8whj-347g.json @@ -7,12 +7,8 @@ "CVE-2019-18319" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is independent from CVE-2019-18317 and CVE-2019-18318. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cpv-6hfh-4qwq/GHSA-6cpv-6hfh-4qwq.json b/advisories/unreviewed/2022/05/GHSA-6cpv-6hfh-4qwq/GHSA-6cpv-6hfh-4qwq.json index 019b1ed57b0..049d8a5f164 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cpv-6hfh-4qwq/GHSA-6cpv-6hfh-4qwq.json +++ b/advisories/unreviewed/2022/05/GHSA-6cpv-6hfh-4qwq/GHSA-6cpv-6hfh-4qwq.json @@ -7,12 +7,8 @@ "CVE-2019-0405" ], "details": "SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of users, leading to a user enumeration vulnerability and Information Disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6f6r-4rpp-w273/GHSA-6f6r-4rpp-w273.json b/advisories/unreviewed/2022/05/GHSA-6f6r-4rpp-w273/GHSA-6f6r-4rpp-w273.json index 97774cbe59b..b083338c7a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f6r-4rpp-w273/GHSA-6f6r-4rpp-w273.json +++ b/advisories/unreviewed/2022/05/GHSA-6f6r-4rpp-w273/GHSA-6f6r-4rpp-w273.json @@ -7,12 +7,8 @@ "CVE-2019-4226" ], "details": "IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159243.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fp6-hh92-h5q5/GHSA-6fp6-hh92-h5q5.json b/advisories/unreviewed/2022/05/GHSA-6fp6-hh92-h5q5/GHSA-6fp6-hh92-h5q5.json index 7688f8acd41..52be3d7cfce 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fp6-hh92-h5q5/GHSA-6fp6-hh92-h5q5.json +++ b/advisories/unreviewed/2022/05/GHSA-6fp6-hh92-h5q5/GHSA-6fp6-hh92-h5q5.json @@ -7,12 +7,8 @@ "CVE-2019-15276" ], "details": "A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An attacker could exploit this vulnerability by authenticating with low privileges to an affected controller and submitting the crafted URL to the web interface of the affected device. Conversely, an unauthenticated attacker could exploit this vulnerability by persuading a user of the web interface to click the crafted URL. A successful exploit could allow the attacker to cause an unexpected restart of the device, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gpv-cjwj-gqjp/GHSA-6gpv-cjwj-gqjp.json b/advisories/unreviewed/2022/05/GHSA-6gpv-cjwj-gqjp/GHSA-6gpv-cjwj-gqjp.json index 84bc21fc911..4c7fc0d24ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gpv-cjwj-gqjp/GHSA-6gpv-cjwj-gqjp.json +++ b/advisories/unreviewed/2022/05/GHSA-6gpv-cjwj-gqjp/GHSA-6gpv-cjwj-gqjp.json @@ -7,12 +7,8 @@ "CVE-2019-19577" ], "details": "An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. When running on AMD systems with an IOMMU, Xen attempted to dynamically adapt the number of levels of pagetables (the pagetable height) in the IOMMU according to the guest's address space size. The code to select and update the height had several bugs. Notably, the update was done without taking a lock which is necessary for safe operation. A malicious guest administrator can cause Xen to access data structures while they are being modified, causing Xen to crash. Privilege escalation is thought to be very difficult but cannot be ruled out. Additionally, there is a potential memory leak of 4kb per guest boot, under memory pressure. Only Xen on AMD CPUs is vulnerable. Xen running on Intel CPUs is not vulnerable. ARM systems are not vulnerable. Only systems where guests are given direct access to physical devices are vulnerable. Systems which do not use PCI pass-through are not vulnerable. Only HVM guests can exploit the vulnerability. PV and PVH guests cannot. All versions of Xen with IOMMU support are vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hjj-3x6q-6hr7/GHSA-6hjj-3x6q-6hr7.json b/advisories/unreviewed/2022/05/GHSA-6hjj-3x6q-6hr7/GHSA-6hjj-3x6q-6hr7.json index b529c968717..c37de5a9350 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hjj-3x6q-6hr7/GHSA-6hjj-3x6q-6hr7.json +++ b/advisories/unreviewed/2022/05/GHSA-6hjj-3x6q-6hr7/GHSA-6hjj-3x6q-6hr7.json @@ -7,12 +7,8 @@ "CVE-2019-19007" ], "details": "Intelbras IWR 3000N 1.8.7 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled, a related issue to CVE-2019-17600.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6jr9-m575-w4wm/GHSA-6jr9-m575-w4wm.json b/advisories/unreviewed/2022/05/GHSA-6jr9-m575-w4wm/GHSA-6jr9-m575-w4wm.json index 06aedcda76f..80e0bc8724b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jr9-m575-w4wm/GHSA-6jr9-m575-w4wm.json +++ b/advisories/unreviewed/2022/05/GHSA-6jr9-m575-w4wm/GHSA-6jr9-m575-w4wm.json @@ -7,12 +7,8 @@ "CVE-2019-18451" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6m69-7x27-4x5g/GHSA-6m69-7x27-4x5g.json b/advisories/unreviewed/2022/05/GHSA-6m69-7x27-4x5g/GHSA-6m69-7x27-4x5g.json index 1dd8c3739a9..97418c1f00a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m69-7x27-4x5g/GHSA-6m69-7x27-4x5g.json +++ b/advisories/unreviewed/2022/05/GHSA-6m69-7x27-4x5g/GHSA-6m69-7x27-4x5g.json @@ -7,12 +7,8 @@ "CVE-2019-10545" ], "details": "Null pointer dereference issue in kernel due to missing check related to LLC support in GPU in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS605, SDM670, SDM710, SM6150, SM7150, SM8150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mch-cjgm-9hwc/GHSA-6mch-cjgm-9hwc.json b/advisories/unreviewed/2022/05/GHSA-6mch-cjgm-9hwc/GHSA-6mch-cjgm-9hwc.json index dd579a48622..3ab64d8d48b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mch-cjgm-9hwc/GHSA-6mch-cjgm-9hwc.json +++ b/advisories/unreviewed/2022/05/GHSA-6mch-cjgm-9hwc/GHSA-6mch-cjgm-9hwc.json @@ -7,12 +7,8 @@ "CVE-2019-19545" ], "details": "Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mpr-24px-gq7m/GHSA-6mpr-24px-gq7m.json b/advisories/unreviewed/2022/05/GHSA-6mpr-24px-gq7m/GHSA-6mpr-24px-gq7m.json index e7a7ebc4cc5..f8e8ab77268 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mpr-24px-gq7m/GHSA-6mpr-24px-gq7m.json +++ b/advisories/unreviewed/2022/05/GHSA-6mpr-24px-gq7m/GHSA-6mpr-24px-gq7m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q44-g7gx-xp5f/GHSA-6q44-g7gx-xp5f.json b/advisories/unreviewed/2022/05/GHSA-6q44-g7gx-xp5f/GHSA-6q44-g7gx-xp5f.json index fb0c3fd85f0..5f1dd33db0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q44-g7gx-xp5f/GHSA-6q44-g7gx-xp5f.json +++ b/advisories/unreviewed/2022/05/GHSA-6q44-g7gx-xp5f/GHSA-6q44-g7gx-xp5f.json @@ -7,12 +7,8 @@ "CVE-2019-4468" ], "details": "IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163777.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6q4w-wc77-4rq6/GHSA-6q4w-wc77-4rq6.json b/advisories/unreviewed/2022/05/GHSA-6q4w-wc77-4rq6/GHSA-6q4w-wc77-4rq6.json index 06aa66221ea..1da9f6f7b6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q4w-wc77-4rq6/GHSA-6q4w-wc77-4rq6.json +++ b/advisories/unreviewed/2022/05/GHSA-6q4w-wc77-4rq6/GHSA-6q4w-wc77-4rq6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r3m-wrp5-v5m2/GHSA-6r3m-wrp5-v5m2.json b/advisories/unreviewed/2022/05/GHSA-6r3m-wrp5-v5m2/GHSA-6r3m-wrp5-v5m2.json index 3ed200f8750..f5af9c695a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r3m-wrp5-v5m2/GHSA-6r3m-wrp5-v5m2.json +++ b/advisories/unreviewed/2022/05/GHSA-6r3m-wrp5-v5m2/GHSA-6r3m-wrp5-v5m2.json @@ -7,12 +7,8 @@ "CVE-2019-6669" ], "details": "On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, undisclosed traffic flow may cause TMM to restart under some circumstances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rqc-949w-3mj8/GHSA-6rqc-949w-3mj8.json b/advisories/unreviewed/2022/05/GHSA-6rqc-949w-3mj8/GHSA-6rqc-949w-3mj8.json index 57201b7dda8..9c749666f23 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rqc-949w-3mj8/GHSA-6rqc-949w-3mj8.json +++ b/advisories/unreviewed/2022/05/GHSA-6rqc-949w-3mj8/GHSA-6rqc-949w-3mj8.json @@ -7,12 +7,8 @@ "CVE-2019-13945" ], "details": "A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-200 SMART CPU family (All versions). There is an access mode used during manufacturing of S7-1200 CPUs that allows additional diagnostic functionality. The security vulnerability could be exploited by an attacker with physical access to the UART interface during boot process. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rrw-8mq7-2wvv/GHSA-6rrw-8mq7-2wvv.json b/advisories/unreviewed/2022/05/GHSA-6rrw-8mq7-2wvv/GHSA-6rrw-8mq7-2wvv.json index 92db5dbe3fe..a6c1ff92a73 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rrw-8mq7-2wvv/GHSA-6rrw-8mq7-2wvv.json +++ b/advisories/unreviewed/2022/05/GHSA-6rrw-8mq7-2wvv/GHSA-6rrw-8mq7-2wvv.json @@ -7,12 +7,8 @@ "CVE-2019-19777" ], "details": "stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6v85-6qpj-f798/GHSA-6v85-6qpj-f798.json b/advisories/unreviewed/2022/05/GHSA-6v85-6qpj-f798/GHSA-6v85-6qpj-f798.json index 2b53ecf11ee..c3cde41c22f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v85-6qpj-f798/GHSA-6v85-6qpj-f798.json +++ b/advisories/unreviewed/2022/05/GHSA-6v85-6qpj-f798/GHSA-6v85-6qpj-f798.json @@ -7,12 +7,8 @@ "CVE-2019-17405" ], "details": "Nokia IMPACT < 18A: has Reflected self XSS", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vxc-97r3-3qmp/GHSA-6vxc-97r3-3qmp.json b/advisories/unreviewed/2022/05/GHSA-6vxc-97r3-3qmp/GHSA-6vxc-97r3-3qmp.json index b6c34fb4cfe..459d33d72db 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vxc-97r3-3qmp/GHSA-6vxc-97r3-3qmp.json +++ b/advisories/unreviewed/2022/05/GHSA-6vxc-97r3-3qmp/GHSA-6vxc-97r3-3qmp.json @@ -7,12 +7,8 @@ "CVE-2019-13666" ], "details": "Information leak in storage in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6w3p-7vr4-75hx/GHSA-6w3p-7vr4-75hx.json b/advisories/unreviewed/2022/05/GHSA-6w3p-7vr4-75hx/GHSA-6w3p-7vr4-75hx.json index 1e702958af7..ea29ab063d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w3p-7vr4-75hx/GHSA-6w3p-7vr4-75hx.json +++ b/advisories/unreviewed/2022/05/GHSA-6w3p-7vr4-75hx/GHSA-6w3p-7vr4-75hx.json @@ -7,12 +7,8 @@ "CVE-2019-19230" ], "details": "An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6xpc-pxw7-qhg3/GHSA-6xpc-pxw7-qhg3.json b/advisories/unreviewed/2022/05/GHSA-6xpc-pxw7-qhg3/GHSA-6xpc-pxw7-qhg3.json index 185859a236f..ea00e89de3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xpc-pxw7-qhg3/GHSA-6xpc-pxw7-qhg3.json +++ b/advisories/unreviewed/2022/05/GHSA-6xpc-pxw7-qhg3/GHSA-6xpc-pxw7-qhg3.json @@ -7,12 +7,8 @@ "CVE-2019-2228" ], "details": "In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-111210196", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73g7-p5mh-vr2v/GHSA-73g7-p5mh-vr2v.json b/advisories/unreviewed/2022/05/GHSA-73g7-p5mh-vr2v/GHSA-73g7-p5mh-vr2v.json index 99d92e16a45..f9f2201a129 100644 --- a/advisories/unreviewed/2022/05/GHSA-73g7-p5mh-vr2v/GHSA-73g7-p5mh-vr2v.json +++ b/advisories/unreviewed/2022/05/GHSA-73g7-p5mh-vr2v/GHSA-73g7-p5mh-vr2v.json @@ -7,12 +7,8 @@ "CVE-2019-17437" ], "details": "An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions prior to 7.1.25; 8.0 versions prior to 8.0.20; 8.1 versions prior to 8.1.11; 9.0 versions prior to 9.0.5. PAN-OS version 7.0 and prior EOL versions have not been evaluated for this issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73q6-p6x5-9wrv/GHSA-73q6-p6x5-9wrv.json b/advisories/unreviewed/2022/05/GHSA-73q6-p6x5-9wrv/GHSA-73q6-p6x5-9wrv.json index 33fde68fecd..8461e3d6e7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-73q6-p6x5-9wrv/GHSA-73q6-p6x5-9wrv.json +++ b/advisories/unreviewed/2022/05/GHSA-73q6-p6x5-9wrv/GHSA-73q6-p6x5-9wrv.json @@ -7,12 +7,8 @@ "CVE-2019-19679" ], "details": "In \"Xray Test Management for Jira\" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create Pre-Condition action for a new Test Issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7426-cf9r-3rp5/GHSA-7426-cf9r-3rp5.json b/advisories/unreviewed/2022/05/GHSA-7426-cf9r-3rp5/GHSA-7426-cf9r-3rp5.json index 9888f741611..4929316f24d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7426-cf9r-3rp5/GHSA-7426-cf9r-3rp5.json +++ b/advisories/unreviewed/2022/05/GHSA-7426-cf9r-3rp5/GHSA-7426-cf9r-3rp5.json @@ -7,12 +7,8 @@ "CVE-2019-19502" ], "details": "pluginconfig.php in the Image Uploader and Browser plugin before 4.1.9 for CKEditor mishandles certain characters in pathnames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-747q-6mj3-hj66/GHSA-747q-6mj3-hj66.json b/advisories/unreviewed/2022/05/GHSA-747q-6mj3-hj66/GHSA-747q-6mj3-hj66.json index fe57b3e3905..5fd84400a25 100644 --- a/advisories/unreviewed/2022/05/GHSA-747q-6mj3-hj66/GHSA-747q-6mj3-hj66.json +++ b/advisories/unreviewed/2022/05/GHSA-747q-6mj3-hj66/GHSA-747q-6mj3-hj66.json @@ -7,12 +7,8 @@ "CVE-2019-18459" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-748x-8hcr-xg9h/GHSA-748x-8hcr-xg9h.json b/advisories/unreviewed/2022/05/GHSA-748x-8hcr-xg9h/GHSA-748x-8hcr-xg9h.json index e0f91359e94..2e9efe82787 100644 --- a/advisories/unreviewed/2022/05/GHSA-748x-8hcr-xg9h/GHSA-748x-8hcr-xg9h.json +++ b/advisories/unreviewed/2022/05/GHSA-748x-8hcr-xg9h/GHSA-748x-8hcr-xg9h.json @@ -7,12 +7,8 @@ "CVE-2019-19587" ], "details": "In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the source view in the Management Console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75vm-6gpr-f398/GHSA-75vm-6gpr-f398.json b/advisories/unreviewed/2022/05/GHSA-75vm-6gpr-f398/GHSA-75vm-6gpr-f398.json index eec157c856d..88169dde017 100644 --- a/advisories/unreviewed/2022/05/GHSA-75vm-6gpr-f398/GHSA-75vm-6gpr-f398.json +++ b/advisories/unreviewed/2022/05/GHSA-75vm-6gpr-f398/GHSA-75vm-6gpr-f398.json @@ -7,12 +7,8 @@ "CVE-2019-11293" ], "details": "Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-75xv-qqv2-qh22/GHSA-75xv-qqv2-qh22.json b/advisories/unreviewed/2022/05/GHSA-75xv-qqv2-qh22/GHSA-75xv-qqv2-qh22.json index edd98ea863b..5f86ddcd6c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-75xv-qqv2-qh22/GHSA-75xv-qqv2-qh22.json +++ b/advisories/unreviewed/2022/05/GHSA-75xv-qqv2-qh22/GHSA-75xv-qqv2-qh22.json @@ -7,12 +7,8 @@ "CVE-2019-18458" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76c7-jr49-pvm9/GHSA-76c7-jr49-pvm9.json b/advisories/unreviewed/2022/05/GHSA-76c7-jr49-pvm9/GHSA-76c7-jr49-pvm9.json index 1e95f3af490..b4874471b73 100644 --- a/advisories/unreviewed/2022/05/GHSA-76c7-jr49-pvm9/GHSA-76c7-jr49-pvm9.json +++ b/advisories/unreviewed/2022/05/GHSA-76c7-jr49-pvm9/GHSA-76c7-jr49-pvm9.json @@ -7,12 +7,8 @@ "CVE-2019-17406" ], "details": "Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76fq-c73c-746h/GHSA-76fq-c73c-746h.json b/advisories/unreviewed/2022/05/GHSA-76fq-c73c-746h/GHSA-76fq-c73c-746h.json index 323083272af..715474184bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-76fq-c73c-746h/GHSA-76fq-c73c-746h.json +++ b/advisories/unreviewed/2022/05/GHSA-76fq-c73c-746h/GHSA-76fq-c73c-746h.json @@ -7,12 +7,8 @@ "CVE-2019-15288" ], "details": "A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privileges to an unrestricted user of the restricted shell. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including specific arguments when opening an SSH connection to an affected device. A successful exploit could allow the attacker to gain unrestricted user access to the restricted shell of an affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76h5-j8hw-99ch/GHSA-76h5-j8hw-99ch.json b/advisories/unreviewed/2022/05/GHSA-76h5-j8hw-99ch/GHSA-76h5-j8hw-99ch.json index fc320d2c5b3..b2dbf12df80 100644 --- a/advisories/unreviewed/2022/05/GHSA-76h5-j8hw-99ch/GHSA-76h5-j8hw-99ch.json +++ b/advisories/unreviewed/2022/05/GHSA-76h5-j8hw-99ch/GHSA-76h5-j8hw-99ch.json @@ -7,12 +7,8 @@ "CVE-2006-3136" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar vulnerability to CVE-2006-2583. NOTE: this issue has been disputed by third parties, who state that the DIR_LIBS parameter is defined in an include file before being used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76p7-xgvr-6gqw/GHSA-76p7-xgvr-6gqw.json b/advisories/unreviewed/2022/05/GHSA-76p7-xgvr-6gqw/GHSA-76p7-xgvr-6gqw.json index 2898177606d..548a495ee8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-76p7-xgvr-6gqw/GHSA-76p7-xgvr-6gqw.json +++ b/advisories/unreviewed/2022/05/GHSA-76p7-xgvr-6gqw/GHSA-76p7-xgvr-6gqw.json @@ -7,12 +7,8 @@ "CVE-2019-19490" ], "details": "LiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the \"LiteManagerFree - Server\" folder, as demonstrated by ROMFUSClient.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77x2-39gg-vv6g/GHSA-77x2-39gg-vv6g.json b/advisories/unreviewed/2022/05/GHSA-77x2-39gg-vv6g/GHSA-77x2-39gg-vv6g.json index ce412eae1fb..423deafb48f 100644 --- a/advisories/unreviewed/2022/05/GHSA-77x2-39gg-vv6g/GHSA-77x2-39gg-vv6g.json +++ b/advisories/unreviewed/2022/05/GHSA-77x2-39gg-vv6g/GHSA-77x2-39gg-vv6g.json @@ -7,12 +7,8 @@ "CVE-2019-2231" ], "details": "In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-141955555", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79gj-xgq6-77vj/GHSA-79gj-xgq6-77vj.json b/advisories/unreviewed/2022/05/GHSA-79gj-xgq6-77vj/GHSA-79gj-xgq6-77vj.json index 6dfe08fed41..e866a38e9f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-79gj-xgq6-77vj/GHSA-79gj-xgq6-77vj.json +++ b/advisories/unreviewed/2022/05/GHSA-79gj-xgq6-77vj/GHSA-79gj-xgq6-77vj.json @@ -7,12 +7,8 @@ "CVE-2006-6285" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in index.php in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) 1.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the externalConfig parameter. NOTE: CVE and other third parties dispute this vulnerability because $externalConfig is defined before use.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79jw-wrqv-5vh6/GHSA-79jw-wrqv-5vh6.json b/advisories/unreviewed/2022/05/GHSA-79jw-wrqv-5vh6/GHSA-79jw-wrqv-5vh6.json index 6469d03b69a..96afd75a18e 100644 --- a/advisories/unreviewed/2022/05/GHSA-79jw-wrqv-5vh6/GHSA-79jw-wrqv-5vh6.json +++ b/advisories/unreviewed/2022/05/GHSA-79jw-wrqv-5vh6/GHSA-79jw-wrqv-5vh6.json @@ -7,12 +7,8 @@ "CVE-2019-13707" ], "details": "Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79q9-8ff3-x4g2/GHSA-79q9-8ff3-x4g2.json b/advisories/unreviewed/2022/05/GHSA-79q9-8ff3-x4g2/GHSA-79q9-8ff3-x4g2.json index 684e6f2871c..c8881759485 100644 --- a/advisories/unreviewed/2022/05/GHSA-79q9-8ff3-x4g2/GHSA-79q9-8ff3-x4g2.json +++ b/advisories/unreviewed/2022/05/GHSA-79q9-8ff3-x4g2/GHSA-79q9-8ff3-x4g2.json @@ -7,12 +7,8 @@ "CVE-2019-18449" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79rx-rpqc-99fp/GHSA-79rx-rpqc-99fp.json b/advisories/unreviewed/2022/05/GHSA-79rx-rpqc-99fp/GHSA-79rx-rpqc-99fp.json index 20b19d2c342..e516789fe30 100644 --- a/advisories/unreviewed/2022/05/GHSA-79rx-rpqc-99fp/GHSA-79rx-rpqc-99fp.json +++ b/advisories/unreviewed/2022/05/GHSA-79rx-rpqc-99fp/GHSA-79rx-rpqc-99fp.json @@ -7,12 +7,8 @@ "CVE-2019-13674" ], "details": "IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7cjv-794c-2mcw/GHSA-7cjv-794c-2mcw.json b/advisories/unreviewed/2022/05/GHSA-7cjv-794c-2mcw/GHSA-7cjv-794c-2mcw.json index c41b954bbd6..10d4ba0024a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cjv-794c-2mcw/GHSA-7cjv-794c-2mcw.json +++ b/advisories/unreviewed/2022/05/GHSA-7cjv-794c-2mcw/GHSA-7cjv-794c-2mcw.json @@ -7,12 +7,8 @@ "CVE-2019-5841" ], "details": "Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7f7c-fgq4-x53w/GHSA-7f7c-fgq4-x53w.json b/advisories/unreviewed/2022/05/GHSA-7f7c-fgq4-x53w/GHSA-7f7c-fgq4-x53w.json index efb467c8834..10179cbd89b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f7c-fgq4-x53w/GHSA-7f7c-fgq4-x53w.json +++ b/advisories/unreviewed/2022/05/GHSA-7f7c-fgq4-x53w/GHSA-7f7c-fgq4-x53w.json @@ -7,12 +7,8 @@ "CVE-2019-5881" ], "details": "Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7f9m-x89m-cpp8/GHSA-7f9m-x89m-cpp8.json b/advisories/unreviewed/2022/05/GHSA-7f9m-x89m-cpp8/GHSA-7f9m-x89m-cpp8.json index a460b9bdcc0..0198f1fa14d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f9m-x89m-cpp8/GHSA-7f9m-x89m-cpp8.json +++ b/advisories/unreviewed/2022/05/GHSA-7f9m-x89m-cpp8/GHSA-7f9m-x89m-cpp8.json @@ -7,12 +7,8 @@ "CVE-2006-6207" ], "details": "** DISPUTED ** SQL injection vulnerability in products.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the partno parameter. NOTE: the vendor disputes this issue, stating that it is a forced SQL error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7fcj-v5v7-gm5g/GHSA-7fcj-v5v7-gm5g.json b/advisories/unreviewed/2022/05/GHSA-7fcj-v5v7-gm5g/GHSA-7fcj-v5v7-gm5g.json index 7c63eb8bfb2..56e92c5ed95 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fcj-v5v7-gm5g/GHSA-7fcj-v5v7-gm5g.json +++ b/advisories/unreviewed/2022/05/GHSA-7fcj-v5v7-gm5g/GHSA-7fcj-v5v7-gm5g.json @@ -14,9 +14,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g6p-9397-6cfc/GHSA-7g6p-9397-6cfc.json b/advisories/unreviewed/2022/05/GHSA-7g6p-9397-6cfc/GHSA-7g6p-9397-6cfc.json index 28f22503a64..0add89f3f3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g6p-9397-6cfc/GHSA-7g6p-9397-6cfc.json +++ b/advisories/unreviewed/2022/05/GHSA-7g6p-9397-6cfc/GHSA-7g6p-9397-6cfc.json @@ -7,12 +7,8 @@ "CVE-2019-5232" ], "details": "There is a use of insufficiently random values vulnerability in Huawei ViewPoint products. An unauthenticated, remote attacker can guess information by a large number of attempts. Successful exploitation may cause information leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7hjv-846h-7wvc/GHSA-7hjv-846h-7wvc.json b/advisories/unreviewed/2022/05/GHSA-7hjv-846h-7wvc/GHSA-7hjv-846h-7wvc.json index 4830a62bfaa..0c5f35a3e6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hjv-846h-7wvc/GHSA-7hjv-846h-7wvc.json +++ b/advisories/unreviewed/2022/05/GHSA-7hjv-846h-7wvc/GHSA-7hjv-846h-7wvc.json @@ -7,12 +7,8 @@ "CVE-2019-1490" ], "details": "A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7hpx-p47p-jpq5/GHSA-7hpx-p47p-jpq5.json b/advisories/unreviewed/2022/05/GHSA-7hpx-p47p-jpq5/GHSA-7hpx-p47p-jpq5.json index ee33903bf79..aabd67187b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hpx-p47p-jpq5/GHSA-7hpx-p47p-jpq5.json +++ b/advisories/unreviewed/2022/05/GHSA-7hpx-p47p-jpq5/GHSA-7hpx-p47p-jpq5.json @@ -7,12 +7,8 @@ "CVE-2019-18306" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m84-qcqm-rgjv/GHSA-7m84-qcqm-rgjv.json b/advisories/unreviewed/2022/05/GHSA-7m84-qcqm-rgjv/GHSA-7m84-qcqm-rgjv.json index 36e2cbac675..f2e938bf854 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m84-qcqm-rgjv/GHSA-7m84-qcqm-rgjv.json +++ b/advisories/unreviewed/2022/05/GHSA-7m84-qcqm-rgjv/GHSA-7m84-qcqm-rgjv.json @@ -7,12 +7,8 @@ "CVE-2019-19636" ], "details": "An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7mqg-g2q4-78m2/GHSA-7mqg-g2q4-78m2.json b/advisories/unreviewed/2022/05/GHSA-7mqg-g2q4-78m2/GHSA-7mqg-g2q4-78m2.json index bf642dc2745..a8372b1034e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mqg-g2q4-78m2/GHSA-7mqg-g2q4-78m2.json +++ b/advisories/unreviewed/2022/05/GHSA-7mqg-g2q4-78m2/GHSA-7mqg-g2q4-78m2.json @@ -7,12 +7,8 @@ "CVE-2019-17358" ], "details": "Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7p3p-c3r9-hpgr/GHSA-7p3p-c3r9-hpgr.json b/advisories/unreviewed/2022/05/GHSA-7p3p-c3r9-hpgr/GHSA-7p3p-c3r9-hpgr.json index 4816a23f218..0af0071471a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p3p-c3r9-hpgr/GHSA-7p3p-c3r9-hpgr.json +++ b/advisories/unreviewed/2022/05/GHSA-7p3p-c3r9-hpgr/GHSA-7p3p-c3r9-hpgr.json @@ -7,12 +7,8 @@ "CVE-2019-19602" ], "details": "fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases on amd64, aka CID-59c4bd853abc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7r2v-6w5p-52wm/GHSA-7r2v-6w5p-52wm.json b/advisories/unreviewed/2022/05/GHSA-7r2v-6w5p-52wm/GHSA-7r2v-6w5p-52wm.json index 0ba79c118e5..153205432a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r2v-6w5p-52wm/GHSA-7r2v-6w5p-52wm.json +++ b/advisories/unreviewed/2022/05/GHSA-7r2v-6w5p-52wm/GHSA-7r2v-6w5p-52wm.json @@ -7,12 +7,8 @@ "CVE-2006-4455" ], "details": "** DISPUTED ** Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors involving the PRIVMSG command. NOTE: the vendor has disputed this vulnerability, stating that it does not affect 2.6.7 \"or any recent version\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7r52-mq4x-j9xf/GHSA-7r52-mq4x-j9xf.json b/advisories/unreviewed/2022/05/GHSA-7r52-mq4x-j9xf/GHSA-7r52-mq4x-j9xf.json index 518ba1f8ac1..5cbb5bfe848 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r52-mq4x-j9xf/GHSA-7r52-mq4x-j9xf.json +++ b/advisories/unreviewed/2022/05/GHSA-7r52-mq4x-j9xf/GHSA-7r52-mq4x-j9xf.json @@ -7,12 +7,8 @@ "CVE-2019-4095" ], "details": "IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158015.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rq6-hg5q-vcx9/GHSA-7rq6-hg5q-vcx9.json b/advisories/unreviewed/2022/05/GHSA-7rq6-hg5q-vcx9/GHSA-7rq6-hg5q-vcx9.json index df8789541fa..c3e79b59ca5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rq6-hg5q-vcx9/GHSA-7rq6-hg5q-vcx9.json +++ b/advisories/unreviewed/2022/05/GHSA-7rq6-hg5q-vcx9/GHSA-7rq6-hg5q-vcx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7rx2-8574-5qv6/GHSA-7rx2-8574-5qv6.json b/advisories/unreviewed/2022/05/GHSA-7rx2-8574-5qv6/GHSA-7rx2-8574-5qv6.json index c4261de3ed7..a5b0e855603 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rx2-8574-5qv6/GHSA-7rx2-8574-5qv6.json +++ b/advisories/unreviewed/2022/05/GHSA-7rx2-8574-5qv6/GHSA-7rx2-8574-5qv6.json @@ -7,12 +7,8 @@ "CVE-2019-5308" ], "details": "Mate 20 RS smartphones with versions earlier than 9.1.0.135(C786E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation in ADB mode, successful exploit could allow the attacker to switch to third desktop after a series of operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7wcc-2hfr-r5m7/GHSA-7wcc-2hfr-r5m7.json b/advisories/unreviewed/2022/05/GHSA-7wcc-2hfr-r5m7/GHSA-7wcc-2hfr-r5m7.json index 790674ac2c4..5bfa828736c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wcc-2hfr-r5m7/GHSA-7wcc-2hfr-r5m7.json +++ b/advisories/unreviewed/2022/05/GHSA-7wcc-2hfr-r5m7/GHSA-7wcc-2hfr-r5m7.json @@ -7,12 +7,8 @@ "CVE-2019-7183" ], "details": "This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7x4q-26xj-gjr7/GHSA-7x4q-26xj-gjr7.json b/advisories/unreviewed/2022/05/GHSA-7x4q-26xj-gjr7/GHSA-7x4q-26xj-gjr7.json index 58c7fb0baeb..962e66fa8d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x4q-26xj-gjr7/GHSA-7x4q-26xj-gjr7.json +++ b/advisories/unreviewed/2022/05/GHSA-7x4q-26xj-gjr7/GHSA-7x4q-26xj-gjr7.json @@ -7,12 +7,8 @@ "CVE-2006-0755" ], "details": "** DISPUTED ** Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-822x-846c-2c22/GHSA-822x-846c-2c22.json b/advisories/unreviewed/2022/05/GHSA-822x-846c-2c22/GHSA-822x-846c-2c22.json index 349274b7f0e..854a3fdf779 100644 --- a/advisories/unreviewed/2022/05/GHSA-822x-846c-2c22/GHSA-822x-846c-2c22.json +++ b/advisories/unreviewed/2022/05/GHSA-822x-846c-2c22/GHSA-822x-846c-2c22.json @@ -7,12 +7,8 @@ "CVE-2019-6192" ], "details": "A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83f7-7p5p-3hxm/GHSA-83f7-7p5p-3hxm.json b/advisories/unreviewed/2022/05/GHSA-83f7-7p5p-3hxm/GHSA-83f7-7p5p-3hxm.json index 1e363d46d2c..7efbdbd0162 100644 --- a/advisories/unreviewed/2022/05/GHSA-83f7-7p5p-3hxm/GHSA-83f7-7p5p-3hxm.json +++ b/advisories/unreviewed/2022/05/GHSA-83f7-7p5p-3hxm/GHSA-83f7-7p5p-3hxm.json @@ -7,12 +7,8 @@ "CVE-2019-19519" ], "details": "In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-858h-9hh5-fvx2/GHSA-858h-9hh5-fvx2.json b/advisories/unreviewed/2022/05/GHSA-858h-9hh5-fvx2/GHSA-858h-9hh5-fvx2.json index 937caf94407..7a3b07d69c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-858h-9hh5-fvx2/GHSA-858h-9hh5-fvx2.json +++ b/advisories/unreviewed/2022/05/GHSA-858h-9hh5-fvx2/GHSA-858h-9hh5-fvx2.json @@ -7,12 +7,8 @@ "CVE-2019-16670" ], "details": "An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-872v-39hw-4fr3/GHSA-872v-39hw-4fr3.json b/advisories/unreviewed/2022/05/GHSA-872v-39hw-4fr3/GHSA-872v-39hw-4fr3.json index e11d82d113e..39fdcc8fda1 100644 --- a/advisories/unreviewed/2022/05/GHSA-872v-39hw-4fr3/GHSA-872v-39hw-4fr3.json +++ b/advisories/unreviewed/2022/05/GHSA-872v-39hw-4fr3/GHSA-872v-39hw-4fr3.json @@ -7,12 +7,8 @@ "CVE-2019-10013" ], "details": "The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8746-f7wh-cvv9/GHSA-8746-f7wh-cvv9.json b/advisories/unreviewed/2022/05/GHSA-8746-f7wh-cvv9/GHSA-8746-f7wh-cvv9.json index 9fe4086adde..54e276d3a04 100644 --- a/advisories/unreviewed/2022/05/GHSA-8746-f7wh-cvv9/GHSA-8746-f7wh-cvv9.json +++ b/advisories/unreviewed/2022/05/GHSA-8746-f7wh-cvv9/GHSA-8746-f7wh-cvv9.json @@ -7,12 +7,8 @@ "CVE-2019-18381" ], "details": "Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87g6-m6v4-rm4w/GHSA-87g6-m6v4-rm4w.json b/advisories/unreviewed/2022/05/GHSA-87g6-m6v4-rm4w/GHSA-87g6-m6v4-rm4w.json index 0f51ec483dc..cc28d65947f 100644 --- a/advisories/unreviewed/2022/05/GHSA-87g6-m6v4-rm4w/GHSA-87g6-m6v4-rm4w.json +++ b/advisories/unreviewed/2022/05/GHSA-87g6-m6v4-rm4w/GHSA-87g6-m6v4-rm4w.json @@ -7,12 +7,8 @@ "CVE-2019-19462" ], "details": "relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87hj-px7p-jhf4/GHSA-87hj-px7p-jhf4.json b/advisories/unreviewed/2022/05/GHSA-87hj-px7p-jhf4/GHSA-87hj-px7p-jhf4.json index 3d7b743f46d..72f9a63d129 100644 --- a/advisories/unreviewed/2022/05/GHSA-87hj-px7p-jhf4/GHSA-87hj-px7p-jhf4.json +++ b/advisories/unreviewed/2022/05/GHSA-87hj-px7p-jhf4/GHSA-87hj-px7p-jhf4.json @@ -7,12 +7,8 @@ "CVE-2019-11934" ], "details": "Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87q2-rr35-r6c9/GHSA-87q2-rr35-r6c9.json b/advisories/unreviewed/2022/05/GHSA-87q2-rr35-r6c9/GHSA-87q2-rr35-r6c9.json index ee80fcbf18c..eee445372f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-87q2-rr35-r6c9/GHSA-87q2-rr35-r6c9.json +++ b/advisories/unreviewed/2022/05/GHSA-87q2-rr35-r6c9/GHSA-87q2-rr35-r6c9.json @@ -7,12 +7,8 @@ "CVE-2019-15271" ], "details": "A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89q8-rgqc-jpf8/GHSA-89q8-rgqc-jpf8.json b/advisories/unreviewed/2022/05/GHSA-89q8-rgqc-jpf8/GHSA-89q8-rgqc-jpf8.json index 022fe879a0b..0292a0096ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-89q8-rgqc-jpf8/GHSA-89q8-rgqc-jpf8.json +++ b/advisories/unreviewed/2022/05/GHSA-89q8-rgqc-jpf8/GHSA-89q8-rgqc-jpf8.json @@ -7,12 +7,8 @@ "CVE-2019-15990" ], "details": "A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based management interface. The vulnerability is due to improper authorization of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to view information displayed in the web-based management interface without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8c6q-359m-h9qj/GHSA-8c6q-359m-h9qj.json b/advisories/unreviewed/2022/05/GHSA-8c6q-359m-h9qj/GHSA-8c6q-359m-h9qj.json index 21baf6a8652..6b49399d576 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c6q-359m-h9qj/GHSA-8c6q-359m-h9qj.json +++ b/advisories/unreviewed/2022/05/GHSA-8c6q-359m-h9qj/GHSA-8c6q-359m-h9qj.json @@ -7,12 +7,8 @@ "CVE-2019-18317" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is independent from CVE-2019-18318 and CVE-2019-18319. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cjc-5jv5-fj8c/GHSA-8cjc-5jv5-fj8c.json b/advisories/unreviewed/2022/05/GHSA-8cjc-5jv5-fj8c/GHSA-8cjc-5jv5-fj8c.json index e9fc11159e5..575ac6f2d68 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cjc-5jv5-fj8c/GHSA-8cjc-5jv5-fj8c.json +++ b/advisories/unreviewed/2022/05/GHSA-8cjc-5jv5-fj8c/GHSA-8cjc-5jv5-fj8c.json @@ -7,12 +7,8 @@ "CVE-2019-5858" ], "details": "Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fcf-mp2j-j4w9/GHSA-8fcf-mp2j-j4w9.json b/advisories/unreviewed/2022/05/GHSA-8fcf-mp2j-j4w9/GHSA-8fcf-mp2j-j4w9.json index ef1e5715814..6e2f9de9373 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fcf-mp2j-j4w9/GHSA-8fcf-mp2j-j4w9.json +++ b/advisories/unreviewed/2022/05/GHSA-8fcf-mp2j-j4w9/GHSA-8fcf-mp2j-j4w9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fgw-hcmw-fvqp/GHSA-8fgw-hcmw-fvqp.json b/advisories/unreviewed/2022/05/GHSA-8fgw-hcmw-fvqp/GHSA-8fgw-hcmw-fvqp.json index e8b47b4941e..223ac085f89 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fgw-hcmw-fvqp/GHSA-8fgw-hcmw-fvqp.json +++ b/advisories/unreviewed/2022/05/GHSA-8fgw-hcmw-fvqp/GHSA-8fgw-hcmw-fvqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h2m-rx7g-r9gv/GHSA-8h2m-rx7g-r9gv.json b/advisories/unreviewed/2022/05/GHSA-8h2m-rx7g-r9gv/GHSA-8h2m-rx7g-r9gv.json index c5a2baa63f2..dc58cfe0730 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h2m-rx7g-r9gv/GHSA-8h2m-rx7g-r9gv.json +++ b/advisories/unreviewed/2022/05/GHSA-8h2m-rx7g-r9gv/GHSA-8h2m-rx7g-r9gv.json @@ -7,12 +7,8 @@ "CVE-2019-10694" ], "details": "The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8j5m-96p7-j6g4/GHSA-8j5m-96p7-j6g4.json b/advisories/unreviewed/2022/05/GHSA-8j5m-96p7-j6g4/GHSA-8j5m-96p7-j6g4.json index 028438ae384..037b59319b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j5m-96p7-j6g4/GHSA-8j5m-96p7-j6g4.json +++ b/advisories/unreviewed/2022/05/GHSA-8j5m-96p7-j6g4/GHSA-8j5m-96p7-j6g4.json @@ -7,12 +7,8 @@ "CVE-2019-18374" ], "details": "Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing authentication controls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8j72-4c3r-rgm9/GHSA-8j72-4c3r-rgm9.json b/advisories/unreviewed/2022/05/GHSA-8j72-4c3r-rgm9/GHSA-8j72-4c3r-rgm9.json index 1c2f01b23f8..a4a44cc3dd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j72-4c3r-rgm9/GHSA-8j72-4c3r-rgm9.json +++ b/advisories/unreviewed/2022/05/GHSA-8j72-4c3r-rgm9/GHSA-8j72-4c3r-rgm9.json @@ -7,12 +7,8 @@ "CVE-2019-18335" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could be able to gain access to logs and configuration files by sending specifically crafted packets to 80/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jfm-678p-xw3j/GHSA-8jfm-678p-xw3j.json b/advisories/unreviewed/2022/05/GHSA-8jfm-678p-xw3j/GHSA-8jfm-678p-xw3j.json index fd19b5de6fa..161edc5c3ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jfm-678p-xw3j/GHSA-8jfm-678p-xw3j.json +++ b/advisories/unreviewed/2022/05/GHSA-8jfm-678p-xw3j/GHSA-8jfm-678p-xw3j.json @@ -7,12 +7,8 @@ "CVE-2019-4244" ], "details": "IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mgg-gfxm-vwwc/GHSA-8mgg-gfxm-vwwc.json b/advisories/unreviewed/2022/05/GHSA-8mgg-gfxm-vwwc/GHSA-8mgg-gfxm-vwwc.json index ced6a2ca7f2..ed0d9caa5ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mgg-gfxm-vwwc/GHSA-8mgg-gfxm-vwwc.json +++ b/advisories/unreviewed/2022/05/GHSA-8mgg-gfxm-vwwc/GHSA-8mgg-gfxm-vwwc.json @@ -7,12 +7,8 @@ "CVE-2019-19708" ], "details": "The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mw2-4xfj-9rvq/GHSA-8mw2-4xfj-9rvq.json b/advisories/unreviewed/2022/05/GHSA-8mw2-4xfj-9rvq/GHSA-8mw2-4xfj-9rvq.json index 241d221e528..aa0b1ece1af 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mw2-4xfj-9rvq/GHSA-8mw2-4xfj-9rvq.json +++ b/advisories/unreviewed/2022/05/GHSA-8mw2-4xfj-9rvq/GHSA-8mw2-4xfj-9rvq.json @@ -7,12 +7,8 @@ "CVE-2006-3249" ], "details": "** DISPUTED ** SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the vendor has disputed this report, stating \"If a non positive integer or non-integer is used for the page parameter for a search URL, the search query will use a negative number for the LIMIT clause. This causes the query to break, showing no results. It IS NOT however a sql injection error.\" While the original report is from a researcher with mixed accuracy, as of 20060703, CVE does not have any additional information regarding this issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8p6h-pm5c-4w65/GHSA-8p6h-pm5c-4w65.json b/advisories/unreviewed/2022/05/GHSA-8p6h-pm5c-4w65/GHSA-8p6h-pm5c-4w65.json index 6c5e7e60666..d28ecc581b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p6h-pm5c-4w65/GHSA-8p6h-pm5c-4w65.json +++ b/advisories/unreviewed/2022/05/GHSA-8p6h-pm5c-4w65/GHSA-8p6h-pm5c-4w65.json @@ -7,12 +7,8 @@ "CVE-2019-5856" ], "details": "Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8p79-fcr2-m563/GHSA-8p79-fcr2-m563.json b/advisories/unreviewed/2022/05/GHSA-8p79-fcr2-m563/GHSA-8p79-fcr2-m563.json index b7e6b01d099..584843a13ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p79-fcr2-m563/GHSA-8p79-fcr2-m563.json +++ b/advisories/unreviewed/2022/05/GHSA-8p79-fcr2-m563/GHSA-8p79-fcr2-m563.json @@ -7,12 +7,8 @@ "CVE-2006-4663" ], "details": "** DISPUTED ** The source code tar archive of the Linux kernel 2.6.16, 2.6.17.11, and possibly other versions specifies weak permissions (0666 and 0777) for certain files and directories, which might allow local users to insert Trojan horse source code that would be used during the next kernel compilation. NOTE: another researcher disputes the vulnerability, stating that he finds \"Not a single world-writable file or directory.\" CVE analysis as of 20060908 indicates that permissions will only be weak under certain unusual or insecure scenarios.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8pmp-qg97-8gmp/GHSA-8pmp-qg97-8gmp.json b/advisories/unreviewed/2022/05/GHSA-8pmp-qg97-8gmp/GHSA-8pmp-qg97-8gmp.json index 07eccacd4fc..599845befe2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pmp-qg97-8gmp/GHSA-8pmp-qg97-8gmp.json +++ b/advisories/unreviewed/2022/05/GHSA-8pmp-qg97-8gmp/GHSA-8pmp-qg97-8gmp.json @@ -7,12 +7,8 @@ "CVE-2019-15956" ], "details": "A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could have a twofold impact: the attacker could either change the administrator password, gaining privileged access, or reset the network configuration details, causing a denial of service (DoS) condition. In both scenarios, manual intervention is required to restore normal operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8qpr-v8hf-4323/GHSA-8qpr-v8hf-4323.json b/advisories/unreviewed/2022/05/GHSA-8qpr-v8hf-4323/GHSA-8qpr-v8hf-4323.json index 4030bccd302..0524b59b3a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qpr-v8hf-4323/GHSA-8qpr-v8hf-4323.json +++ b/advisories/unreviewed/2022/05/GHSA-8qpr-v8hf-4323/GHSA-8qpr-v8hf-4323.json @@ -7,12 +7,8 @@ "CVE-2019-19635" ], "details": "An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8rgw-25fw-5m5f/GHSA-8rgw-25fw-5m5f.json b/advisories/unreviewed/2022/05/GHSA-8rgw-25fw-5m5f/GHSA-8rgw-25fw-5m5f.json index 90f4d8dfb83..9947a1cf224 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rgw-25fw-5m5f/GHSA-8rgw-25fw-5m5f.json +++ b/advisories/unreviewed/2022/05/GHSA-8rgw-25fw-5m5f/GHSA-8rgw-25fw-5m5f.json @@ -7,12 +7,8 @@ "CVE-2019-19642" ], "details": "On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in ShareHost or ShareName. The attacker can achieve a persistent backdoor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v3p-6p83-784h/GHSA-8v3p-6p83-784h.json b/advisories/unreviewed/2022/05/GHSA-8v3p-6p83-784h/GHSA-8v3p-6p83-784h.json index 42d6358fd7f..00664852608 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v3p-6p83-784h/GHSA-8v3p-6p83-784h.json +++ b/advisories/unreviewed/2022/05/GHSA-8v3p-6p83-784h/GHSA-8v3p-6p83-784h.json @@ -7,12 +7,8 @@ "CVE-2019-5872" ], "details": "Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8v4x-g74w-cgg6/GHSA-8v4x-g74w-cgg6.json b/advisories/unreviewed/2022/05/GHSA-8v4x-g74w-cgg6/GHSA-8v4x-g74w-cgg6.json index c8bcfbf973c..ac768508fb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v4x-g74w-cgg6/GHSA-8v4x-g74w-cgg6.json +++ b/advisories/unreviewed/2022/05/GHSA-8v4x-g74w-cgg6/GHSA-8v4x-g74w-cgg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vh5-q8fh-cmgp/GHSA-8vh5-q8fh-cmgp.json b/advisories/unreviewed/2022/05/GHSA-8vh5-q8fh-cmgp/GHSA-8vh5-q8fh-cmgp.json index bd87fe499af..57989114ed6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vh5-q8fh-cmgp/GHSA-8vh5-q8fh-cmgp.json +++ b/advisories/unreviewed/2022/05/GHSA-8vh5-q8fh-cmgp/GHSA-8vh5-q8fh-cmgp.json @@ -7,12 +7,8 @@ "CVE-2019-18321" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to read and write arbitrary files on the local file system by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18322. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xpf-4773-x7fx/GHSA-8xpf-4773-x7fx.json b/advisories/unreviewed/2022/05/GHSA-8xpf-4773-x7fx/GHSA-8xpf-4773-x7fx.json index 64d386ca596..5090a016017 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xpf-4773-x7fx/GHSA-8xpf-4773-x7fx.json +++ b/advisories/unreviewed/2022/05/GHSA-8xpf-4773-x7fx/GHSA-8xpf-4773-x7fx.json @@ -7,12 +7,8 @@ "CVE-2006-3053" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[http_path] parameter. NOTE: this issue has been disputed by the vendor, who states \"common.php is checked on the very first line of non-comment code that it is not being called directly. It has been this way in all 5.x version of Phorum.\" CVE analysis concurs with the vendor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92gq-cfj6-292h/GHSA-92gq-cfj6-292h.json b/advisories/unreviewed/2022/05/GHSA-92gq-cfj6-292h/GHSA-92gq-cfj6-292h.json index 05de1eb61b7..bffa7d822e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-92gq-cfj6-292h/GHSA-92gq-cfj6-292h.json +++ b/advisories/unreviewed/2022/05/GHSA-92gq-cfj6-292h/GHSA-92gq-cfj6-292h.json @@ -7,12 +7,8 @@ "CVE-2019-18347" ], "details": "A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-932q-p83p-pj88/GHSA-932q-p83p-pj88.json b/advisories/unreviewed/2022/05/GHSA-932q-p83p-pj88/GHSA-932q-p83p-pj88.json index 96e2aae8e1e..528ee4b4f15 100644 --- a/advisories/unreviewed/2022/05/GHSA-932q-p83p-pj88/GHSA-932q-p83p-pj88.json +++ b/advisories/unreviewed/2022/05/GHSA-932q-p83p-pj88/GHSA-932q-p83p-pj88.json @@ -7,12 +7,8 @@ "CVE-2019-15684" ], "details": "Kaspersky Protection extension for web browser Google Chrome prior to 30.112.62.0 was vulnerable to unauthorized access to its features remotely that could lead to removing other installed extensions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93c5-v3v3-mpq3/GHSA-93c5-v3v3-mpq3.json b/advisories/unreviewed/2022/05/GHSA-93c5-v3v3-mpq3/GHSA-93c5-v3v3-mpq3.json index 6e1577e59cc..75f846e05fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-93c5-v3v3-mpq3/GHSA-93c5-v3v3-mpq3.json +++ b/advisories/unreviewed/2022/05/GHSA-93c5-v3v3-mpq3/GHSA-93c5-v3v3-mpq3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94mg-mhw8-cfh2/GHSA-94mg-mhw8-cfh2.json b/advisories/unreviewed/2022/05/GHSA-94mg-mhw8-cfh2/GHSA-94mg-mhw8-cfh2.json index 1863ae6e67d..a1390292603 100644 --- a/advisories/unreviewed/2022/05/GHSA-94mg-mhw8-cfh2/GHSA-94mg-mhw8-cfh2.json +++ b/advisories/unreviewed/2022/05/GHSA-94mg-mhw8-cfh2/GHSA-94mg-mhw8-cfh2.json @@ -7,12 +7,8 @@ "CVE-2006-5906" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in modules/bannieres/bannieres.php in Jean-Christophe Ramos SCRIPT BANNIERES (aka ban 0.1 and PLS-Bannieres 1.21) allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter. NOTE: the issue is disputed by other researchers, who observe that $chemin is defined before use.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-964w-hfj4-c2g7/GHSA-964w-hfj4-c2g7.json b/advisories/unreviewed/2022/05/GHSA-964w-hfj4-c2g7/GHSA-964w-hfj4-c2g7.json index 4f9fb889556..8a19e567ab1 100644 --- a/advisories/unreviewed/2022/05/GHSA-964w-hfj4-c2g7/GHSA-964w-hfj4-c2g7.json +++ b/advisories/unreviewed/2022/05/GHSA-964w-hfj4-c2g7/GHSA-964w-hfj4-c2g7.json @@ -7,12 +7,8 @@ "CVE-2019-7193" ], "details": "This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-96h9-3p6v-cqh2/GHSA-96h9-3p6v-cqh2.json b/advisories/unreviewed/2022/05/GHSA-96h9-3p6v-cqh2/GHSA-96h9-3p6v-cqh2.json index 03a1b96845e..607c745bd53 100644 --- a/advisories/unreviewed/2022/05/GHSA-96h9-3p6v-cqh2/GHSA-96h9-3p6v-cqh2.json +++ b/advisories/unreviewed/2022/05/GHSA-96h9-3p6v-cqh2/GHSA-96h9-3p6v-cqh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96mw-vj87-32x5/GHSA-96mw-vj87-32x5.json b/advisories/unreviewed/2022/05/GHSA-96mw-vj87-32x5/GHSA-96mw-vj87-32x5.json index 0c3277f651f..a7aa901bb6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-96mw-vj87-32x5/GHSA-96mw-vj87-32x5.json +++ b/advisories/unreviewed/2022/05/GHSA-96mw-vj87-32x5/GHSA-96mw-vj87-32x5.json @@ -7,12 +7,8 @@ "CVE-2019-16674" ], "details": "An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie is predictable and can lead to admin password compromise when captured on the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9743-23p2-9v8j/GHSA-9743-23p2-9v8j.json b/advisories/unreviewed/2022/05/GHSA-9743-23p2-9v8j/GHSA-9743-23p2-9v8j.json index dc9e57c65c5..f2d707e6e34 100644 --- a/advisories/unreviewed/2022/05/GHSA-9743-23p2-9v8j/GHSA-9743-23p2-9v8j.json +++ b/advisories/unreviewed/2022/05/GHSA-9743-23p2-9v8j/GHSA-9743-23p2-9v8j.json @@ -7,12 +7,8 @@ "CVE-2019-5870" ], "details": "Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-988j-mg6c-jcwh/GHSA-988j-mg6c-jcwh.json b/advisories/unreviewed/2022/05/GHSA-988j-mg6c-jcwh/GHSA-988j-mg6c-jcwh.json index db2fb962e31..f7246e0bcea 100644 --- a/advisories/unreviewed/2022/05/GHSA-988j-mg6c-jcwh/GHSA-988j-mg6c-jcwh.json +++ b/advisories/unreviewed/2022/05/GHSA-988j-mg6c-jcwh/GHSA-988j-mg6c-jcwh.json @@ -7,12 +7,8 @@ "CVE-2019-2217" ], "details": "In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141003796", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98rw-w9v5-5j4m/GHSA-98rw-w9v5-5j4m.json b/advisories/unreviewed/2022/05/GHSA-98rw-w9v5-5j4m/GHSA-98rw-w9v5-5j4m.json index d9ba45ea4ed..336723006d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-98rw-w9v5-5j4m/GHSA-98rw-w9v5-5j4m.json +++ b/advisories/unreviewed/2022/05/GHSA-98rw-w9v5-5j4m/GHSA-98rw-w9v5-5j4m.json @@ -7,12 +7,8 @@ "CVE-2019-5842" ], "details": "Use after free in Blink in Google Chrome prior to 75.0.3770.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-997h-jrc2-j4f2/GHSA-997h-jrc2-j4f2.json b/advisories/unreviewed/2022/05/GHSA-997h-jrc2-j4f2/GHSA-997h-jrc2-j4f2.json index fe8ff95e229..f2d9eff072c 100644 --- a/advisories/unreviewed/2022/05/GHSA-997h-jrc2-j4f2/GHSA-997h-jrc2-j4f2.json +++ b/advisories/unreviewed/2022/05/GHSA-997h-jrc2-j4f2/GHSA-997h-jrc2-j4f2.json @@ -7,12 +7,8 @@ "CVE-2019-19493" ], "details": "Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-99gq-h68r-v2g7/GHSA-99gq-h68r-v2g7.json b/advisories/unreviewed/2022/05/GHSA-99gq-h68r-v2g7/GHSA-99gq-h68r-v2g7.json index c4a15ef3a82..a2061e35f39 100644 --- a/advisories/unreviewed/2022/05/GHSA-99gq-h68r-v2g7/GHSA-99gq-h68r-v2g7.json +++ b/advisories/unreviewed/2022/05/GHSA-99gq-h68r-v2g7/GHSA-99gq-h68r-v2g7.json @@ -7,12 +7,8 @@ "CVE-2019-18457" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99jc-7925-7fc9/GHSA-99jc-7925-7fc9.json b/advisories/unreviewed/2022/05/GHSA-99jc-7925-7fc9/GHSA-99jc-7925-7fc9.json index 57b5522955a..84657fa7804 100644 --- a/advisories/unreviewed/2022/05/GHSA-99jc-7925-7fc9/GHSA-99jc-7925-7fc9.json +++ b/advisories/unreviewed/2022/05/GHSA-99jc-7925-7fc9/GHSA-99jc-7925-7fc9.json @@ -7,12 +7,8 @@ "CVE-2019-15987" ], "details": "A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URLs. An attacker could exploit this vulnerability by sending a crafted request to the web interface. A successful exploit could allow the attacker to know if a given username is valid and find the real name of the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99vq-f459-jqrg/GHSA-99vq-f459-jqrg.json b/advisories/unreviewed/2022/05/GHSA-99vq-f459-jqrg/GHSA-99vq-f459-jqrg.json index 32d892238e2..fa70533612b 100644 --- a/advisories/unreviewed/2022/05/GHSA-99vq-f459-jqrg/GHSA-99vq-f459-jqrg.json +++ b/advisories/unreviewed/2022/05/GHSA-99vq-f459-jqrg/GHSA-99vq-f459-jqrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99x7-636q-6hvj/GHSA-99x7-636q-6hvj.json b/advisories/unreviewed/2022/05/GHSA-99x7-636q-6hvj/GHSA-99x7-636q-6hvj.json index b8277c30752..599d02f00aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-99x7-636q-6hvj/GHSA-99x7-636q-6hvj.json +++ b/advisories/unreviewed/2022/05/GHSA-99x7-636q-6hvj/GHSA-99x7-636q-6hvj.json @@ -7,12 +7,8 @@ "CVE-2019-19481" ], "details": "An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC certificates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9cq6-v6jc-rm85/GHSA-9cq6-v6jc-rm85.json b/advisories/unreviewed/2022/05/GHSA-9cq6-v6jc-rm85/GHSA-9cq6-v6jc-rm85.json index e56179341fd..12c9e8d48e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cq6-v6jc-rm85/GHSA-9cq6-v6jc-rm85.json +++ b/advisories/unreviewed/2022/05/GHSA-9cq6-v6jc-rm85/GHSA-9cq6-v6jc-rm85.json @@ -7,12 +7,8 @@ "CVE-2019-5854" ], "details": "Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hj8-x5gx-9x3m/GHSA-9hj8-x5gx-9x3m.json b/advisories/unreviewed/2022/05/GHSA-9hj8-x5gx-9x3m/GHSA-9hj8-x5gx-9x3m.json index c61bf55db63..2465ab4cc67 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hj8-x5gx-9x3m/GHSA-9hj8-x5gx-9x3m.json +++ b/advisories/unreviewed/2022/05/GHSA-9hj8-x5gx-9x3m/GHSA-9hj8-x5gx-9x3m.json @@ -7,12 +7,8 @@ "CVE-2019-10484" ], "details": "Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deallocated during previous command teardwon sequence in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8098, MSM8909W, Nicobar, QCS405, QCS605, SDA845, SDM660, SDM670, SDM710, SDM845, SDX24, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jw2-j35c-pjxc/GHSA-9jw2-j35c-pjxc.json b/advisories/unreviewed/2022/05/GHSA-9jw2-j35c-pjxc/GHSA-9jw2-j35c-pjxc.json index 9c8bfb29df0..b9f3f551a04 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jw2-j35c-pjxc/GHSA-9jw2-j35c-pjxc.json +++ b/advisories/unreviewed/2022/05/GHSA-9jw2-j35c-pjxc/GHSA-9jw2-j35c-pjxc.json @@ -7,12 +7,8 @@ "CVE-2019-16671" ], "details": "An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Remote authenticated users can crash a device with a special packet because of Uncontrolled Resource Consumption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jwp-7vxc-w3x4/GHSA-9jwp-7vxc-w3x4.json b/advisories/unreviewed/2022/05/GHSA-9jwp-7vxc-w3x4/GHSA-9jwp-7vxc-w3x4.json index b10cbec5c24..7db8e325c44 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jwp-7vxc-w3x4/GHSA-9jwp-7vxc-w3x4.json +++ b/advisories/unreviewed/2022/05/GHSA-9jwp-7vxc-w3x4/GHSA-9jwp-7vxc-w3x4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p75-w4p8-7gvx/GHSA-9p75-w4p8-7gvx.json b/advisories/unreviewed/2022/05/GHSA-9p75-w4p8-7gvx/GHSA-9p75-w4p8-7gvx.json index e4046d684fd..2541b1367a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p75-w4p8-7gvx/GHSA-9p75-w4p8-7gvx.json +++ b/advisories/unreviewed/2022/05/GHSA-9p75-w4p8-7gvx/GHSA-9p75-w4p8-7gvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p96-p3x8-3838/GHSA-9p96-p3x8-3838.json b/advisories/unreviewed/2022/05/GHSA-9p96-p3x8-3838/GHSA-9p96-p3x8-3838.json index e3bcdb183a5..4403f524638 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p96-p3x8-3838/GHSA-9p96-p3x8-3838.json +++ b/advisories/unreviewed/2022/05/GHSA-9p96-p3x8-3838/GHSA-9p96-p3x8-3838.json @@ -7,12 +7,8 @@ "CVE-2006-6165" ], "details": "** DISPUTED ** ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has been disputed by a third party, stating that it is the responsibility of the application to properly sanitize the environment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pm5-94qv-mm9q/GHSA-9pm5-94qv-mm9q.json b/advisories/unreviewed/2022/05/GHSA-9pm5-94qv-mm9q/GHSA-9pm5-94qv-mm9q.json index e2506a23fb3..761c480d70f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pm5-94qv-mm9q/GHSA-9pm5-94qv-mm9q.json +++ b/advisories/unreviewed/2022/05/GHSA-9pm5-94qv-mm9q/GHSA-9pm5-94qv-mm9q.json @@ -7,12 +7,8 @@ "CVE-2019-19378" ], "details": "In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9ppr-4hfx-mxgv/GHSA-9ppr-4hfx-mxgv.json b/advisories/unreviewed/2022/05/GHSA-9ppr-4hfx-mxgv/GHSA-9ppr-4hfx-mxgv.json index 7358850b9ea..36ecb783c05 100644 --- a/advisories/unreviewed/2022/05/GHSA-9ppr-4hfx-mxgv/GHSA-9ppr-4hfx-mxgv.json +++ b/advisories/unreviewed/2022/05/GHSA-9ppr-4hfx-mxgv/GHSA-9ppr-4hfx-mxgv.json @@ -7,12 +7,8 @@ "CVE-2019-19129" ], "details": "Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9q2r-wcv4-qhr6/GHSA-9q2r-wcv4-qhr6.json b/advisories/unreviewed/2022/05/GHSA-9q2r-wcv4-qhr6/GHSA-9q2r-wcv4-qhr6.json index b8a289c3122..4b75f802ccb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q2r-wcv4-qhr6/GHSA-9q2r-wcv4-qhr6.json +++ b/advisories/unreviewed/2022/05/GHSA-9q2r-wcv4-qhr6/GHSA-9q2r-wcv4-qhr6.json @@ -7,12 +7,8 @@ "CVE-2019-19198" ], "details": "The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qj8-pjmh-gjc2/GHSA-9qj8-pjmh-gjc2.json b/advisories/unreviewed/2022/05/GHSA-9qj8-pjmh-gjc2/GHSA-9qj8-pjmh-gjc2.json index 9a9c42c6eb9..7a06bed5190 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qj8-pjmh-gjc2/GHSA-9qj8-pjmh-gjc2.json +++ b/advisories/unreviewed/2022/05/GHSA-9qj8-pjmh-gjc2/GHSA-9qj8-pjmh-gjc2.json @@ -7,12 +7,8 @@ "CVE-2019-18296" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18289, CVE-2019-18293, and CVE-2019-18295. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qx7-c7pp-jxg6/GHSA-9qx7-c7pp-jxg6.json b/advisories/unreviewed/2022/05/GHSA-9qx7-c7pp-jxg6/GHSA-9qx7-c7pp-jxg6.json index 697f57c942f..ab8fec0601d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qx7-c7pp-jxg6/GHSA-9qx7-c7pp-jxg6.json +++ b/advisories/unreviewed/2022/05/GHSA-9qx7-c7pp-jxg6/GHSA-9qx7-c7pp-jxg6.json @@ -7,12 +7,8 @@ "CVE-2019-19501" ], "details": "VeraCrypt 1.24 allows Local Privilege Escalation during execution of VeraCryptExpander.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9w36-332v-p26x/GHSA-9w36-332v-p26x.json b/advisories/unreviewed/2022/05/GHSA-9w36-332v-p26x/GHSA-9w36-332v-p26x.json index fd5f5a210f4..9c6843291cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w36-332v-p26x/GHSA-9w36-332v-p26x.json +++ b/advisories/unreviewed/2022/05/GHSA-9w36-332v-p26x/GHSA-9w36-332v-p26x.json @@ -7,12 +7,8 @@ "CVE-2019-13679" ], "details": "Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xxv-5cr7-5gvp/GHSA-9xxv-5cr7-5gvp.json b/advisories/unreviewed/2022/05/GHSA-9xxv-5cr7-5gvp/GHSA-9xxv-5cr7-5gvp.json index 9aaa813496f..20b67d9e910 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xxv-5cr7-5gvp/GHSA-9xxv-5cr7-5gvp.json +++ b/advisories/unreviewed/2022/05/GHSA-9xxv-5cr7-5gvp/GHSA-9xxv-5cr7-5gvp.json @@ -7,12 +7,8 @@ "CVE-2019-18574" ], "details": "RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console administrators open the affected report, the injected scripts could potentially be executed in their browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c277-639g-8944/GHSA-c277-639g-8944.json b/advisories/unreviewed/2022/05/GHSA-c277-639g-8944/GHSA-c277-639g-8944.json index d1befb6f74e..4859b1a3e64 100644 --- a/advisories/unreviewed/2022/05/GHSA-c277-639g-8944/GHSA-c277-639g-8944.json +++ b/advisories/unreviewed/2022/05/GHSA-c277-639g-8944/GHSA-c277-639g-8944.json @@ -7,12 +7,8 @@ "CVE-2019-15300" ], "details": "A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4hf-6r23-8vgr/GHSA-c4hf-6r23-8vgr.json b/advisories/unreviewed/2022/05/GHSA-c4hf-6r23-8vgr/GHSA-c4hf-6r23-8vgr.json index d877913a9ee..4740ab41021 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4hf-6r23-8vgr/GHSA-c4hf-6r23-8vgr.json +++ b/advisories/unreviewed/2022/05/GHSA-c4hf-6r23-8vgr/GHSA-c4hf-6r23-8vgr.json @@ -7,12 +7,8 @@ "CVE-2019-16243" ], "details": "On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware updates via OmaService.js.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c59r-gh79-pmcm/GHSA-c59r-gh79-pmcm.json b/advisories/unreviewed/2022/05/GHSA-c59r-gh79-pmcm/GHSA-c59r-gh79-pmcm.json index 76cfd4744a7..84967bc3351 100644 --- a/advisories/unreviewed/2022/05/GHSA-c59r-gh79-pmcm/GHSA-c59r-gh79-pmcm.json +++ b/advisories/unreviewed/2022/05/GHSA-c59r-gh79-pmcm/GHSA-c59r-gh79-pmcm.json @@ -7,12 +7,8 @@ "CVE-2019-2222" ], "details": "n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140322595", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5pc-gqv9-5rj6/GHSA-c5pc-gqv9-5rj6.json b/advisories/unreviewed/2022/05/GHSA-c5pc-gqv9-5rj6/GHSA-c5pc-gqv9-5rj6.json index 78af4f66441..63383bcd321 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5pc-gqv9-5rj6/GHSA-c5pc-gqv9-5rj6.json +++ b/advisories/unreviewed/2022/05/GHSA-c5pc-gqv9-5rj6/GHSA-c5pc-gqv9-5rj6.json @@ -7,12 +7,8 @@ "CVE-2019-19796" ], "details": "Yabasic 2.86.2 has a heap-based buffer overflow in myformat in function.c via a crafted BASIC source file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5pq-336c-xh85/GHSA-c5pq-336c-xh85.json b/advisories/unreviewed/2022/05/GHSA-c5pq-336c-xh85/GHSA-c5pq-336c-xh85.json index a5823c05d85..ff61a158b8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5pq-336c-xh85/GHSA-c5pq-336c-xh85.json +++ b/advisories/unreviewed/2022/05/GHSA-c5pq-336c-xh85/GHSA-c5pq-336c-xh85.json @@ -7,12 +7,8 @@ "CVE-2006-5160" ], "details": "** DISPUTED ** Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher states that \"I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6pw-c5gr-43f6/GHSA-c6pw-c5gr-43f6.json b/advisories/unreviewed/2022/05/GHSA-c6pw-c5gr-43f6/GHSA-c6pw-c5gr-43f6.json index 36def9e4eb2..d158351d745 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6pw-c5gr-43f6/GHSA-c6pw-c5gr-43f6.json +++ b/advisories/unreviewed/2022/05/GHSA-c6pw-c5gr-43f6/GHSA-c6pw-c5gr-43f6.json @@ -7,12 +7,8 @@ "CVE-2019-15967" ], "details": "A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, local attacker to enable audio recording without notifying users. The vulnerability is due to the presence of unnecessary debug commands. An attacker could exploit this vulnerability by gaining unrestricted access to the restricted shell and using the specific debug commands. A successful exploit could allow the attacker to enable the microphone of an affected device to record audio without notifying users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c82r-7mc6-9j7g/GHSA-c82r-7mc6-9j7g.json b/advisories/unreviewed/2022/05/GHSA-c82r-7mc6-9j7g/GHSA-c82r-7mc6-9j7g.json index 6217389898f..3b2f749ec9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c82r-7mc6-9j7g/GHSA-c82r-7mc6-9j7g.json +++ b/advisories/unreviewed/2022/05/GHSA-c82r-7mc6-9j7g/GHSA-c82r-7mc6-9j7g.json @@ -7,12 +7,8 @@ "CVE-2019-18313" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could gain remote code execution by sending specifically crafted objects to one of the RPC services. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9j5-mrjc-hx8m/GHSA-c9j5-mrjc-hx8m.json b/advisories/unreviewed/2022/05/GHSA-c9j5-mrjc-hx8m/GHSA-c9j5-mrjc-hx8m.json index ac0338f8d0b..22aaddda962 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9j5-mrjc-hx8m/GHSA-c9j5-mrjc-hx8m.json +++ b/advisories/unreviewed/2022/05/GHSA-c9j5-mrjc-hx8m/GHSA-c9j5-mrjc-hx8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9p4-g3wp-gpxv/GHSA-c9p4-g3wp-gpxv.json b/advisories/unreviewed/2022/05/GHSA-c9p4-g3wp-gpxv/GHSA-c9p4-g3wp-gpxv.json index 21d980fde6b..75d480b0e09 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9p4-g3wp-gpxv/GHSA-c9p4-g3wp-gpxv.json +++ b/advisories/unreviewed/2022/05/GHSA-c9p4-g3wp-gpxv/GHSA-c9p4-g3wp-gpxv.json @@ -7,12 +7,8 @@ "CVE-2019-19397" ], "details": "There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algorithms by default. Attackers may exploit the vulnerability to cause information leaks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch35-w937-rw95/GHSA-ch35-w937-rw95.json b/advisories/unreviewed/2022/05/GHSA-ch35-w937-rw95/GHSA-ch35-w937-rw95.json index 7e6b847a1cb..4c1ca5184ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch35-w937-rw95/GHSA-ch35-w937-rw95.json +++ b/advisories/unreviewed/2022/05/GHSA-ch35-w937-rw95/GHSA-ch35-w937-rw95.json @@ -7,12 +7,8 @@ "CVE-2019-14251" ], "details": "An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch82-rwfx-hg86/GHSA-ch82-rwfx-hg86.json b/advisories/unreviewed/2022/05/GHSA-ch82-rwfx-hg86/GHSA-ch82-rwfx-hg86.json index e8a3721da9b..52d0b887286 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch82-rwfx-hg86/GHSA-ch82-rwfx-hg86.json +++ b/advisories/unreviewed/2022/05/GHSA-ch82-rwfx-hg86/GHSA-ch82-rwfx-hg86.json @@ -7,12 +7,8 @@ "CVE-2019-13693" ], "details": "Use after free in IndexedDB in Google Chrome prior to 77.0.3865.120 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cj4c-7qch-h3mh/GHSA-cj4c-7qch-h3mh.json b/advisories/unreviewed/2022/05/GHSA-cj4c-7qch-h3mh/GHSA-cj4c-7qch-h3mh.json index 9fd4deb359c..17e1bd05fb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj4c-7qch-h3mh/GHSA-cj4c-7qch-h3mh.json +++ b/advisories/unreviewed/2022/05/GHSA-cj4c-7qch-h3mh/GHSA-cj4c-7qch-h3mh.json @@ -7,12 +7,8 @@ "CVE-2019-9689" ], "details": "process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certificate handshake message with zero certificates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cm5h-jfjm-77x3/GHSA-cm5h-jfjm-77x3.json b/advisories/unreviewed/2022/05/GHSA-cm5h-jfjm-77x3/GHSA-cm5h-jfjm-77x3.json index c30562db517..03564c8ce74 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm5h-jfjm-77x3/GHSA-cm5h-jfjm-77x3.json +++ b/advisories/unreviewed/2022/05/GHSA-cm5h-jfjm-77x3/GHSA-cm5h-jfjm-77x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpv8-8r69-g4p6/GHSA-cpv8-8r69-g4p6.json b/advisories/unreviewed/2022/05/GHSA-cpv8-8r69-g4p6/GHSA-cpv8-8r69-g4p6.json index 1774ba262de..9e1605420ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpv8-8r69-g4p6/GHSA-cpv8-8r69-g4p6.json +++ b/advisories/unreviewed/2022/05/GHSA-cpv8-8r69-g4p6/GHSA-cpv8-8r69-g4p6.json @@ -7,12 +7,8 @@ "CVE-2019-18328" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18324, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq4h-jg73-mw34/GHSA-cq4h-jg73-mw34.json b/advisories/unreviewed/2022/05/GHSA-cq4h-jg73-mw34/GHSA-cq4h-jg73-mw34.json index a12175c7ccd..72725f80680 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq4h-jg73-mw34/GHSA-cq4h-jg73-mw34.json +++ b/advisories/unreviewed/2022/05/GHSA-cq4h-jg73-mw34/GHSA-cq4h-jg73-mw34.json @@ -7,12 +7,8 @@ "CVE-2006-3042" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.php, and the (2) go_info[server][classes_root] parameter in (b) app.inc.php, (c) login.php, and (d) trylogin.php. NOTE: this issue has been disputed by the vendor, who states that the original researcher \"reviewed the installation tarball that is not identical with the resulting system after installtion. The file, where the $go_info array is declared ... is created by the installer.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq4q-7wp3-54j3/GHSA-cq4q-7wp3-54j3.json b/advisories/unreviewed/2022/05/GHSA-cq4q-7wp3-54j3/GHSA-cq4q-7wp3-54j3.json index 21367486b53..917e20b8c88 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq4q-7wp3-54j3/GHSA-cq4q-7wp3-54j3.json +++ b/advisories/unreviewed/2022/05/GHSA-cq4q-7wp3-54j3/GHSA-cq4q-7wp3-54j3.json @@ -7,12 +7,8 @@ "CVE-2006-4545" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP code via the _SERVER parameter in (1) admin/avatar.php, (2) libs/archive.class.php, (3) libs/login.php, (4) libs/profiles.class.php, and (5) libs/profile/proccess.php. NOTE: CVE disputes this claim, as the _SERVER array and the _SERVER[DOCUMENT_ROOT] index are controlled by PHP and cannot be manipulated by an attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq96-jp34-7gj8/GHSA-cq96-jp34-7gj8.json b/advisories/unreviewed/2022/05/GHSA-cq96-jp34-7gj8/GHSA-cq96-jp34-7gj8.json index 477c03f11b5..1616d58189e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq96-jp34-7gj8/GHSA-cq96-jp34-7gj8.json +++ b/advisories/unreviewed/2022/05/GHSA-cq96-jp34-7gj8/GHSA-cq96-jp34-7gj8.json @@ -7,12 +7,8 @@ "CVE-2019-13670" ], "details": "Insufficient data validation in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqv9-cwr5-p6j4/GHSA-cqv9-cwr5-p6j4.json b/advisories/unreviewed/2022/05/GHSA-cqv9-cwr5-p6j4/GHSA-cqv9-cwr5-p6j4.json index 03c1f13b5be..43aee385c9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqv9-cwr5-p6j4/GHSA-cqv9-cwr5-p6j4.json +++ b/advisories/unreviewed/2022/05/GHSA-cqv9-cwr5-p6j4/GHSA-cqv9-cwr5-p6j4.json @@ -7,12 +7,8 @@ "CVE-2019-5873" ], "details": "Insufficient policy validation in navigation in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvgx-pvwp-mq8w/GHSA-cvgx-pvwp-mq8w.json b/advisories/unreviewed/2022/05/GHSA-cvgx-pvwp-mq8w/GHSA-cvgx-pvwp-mq8w.json index 3dcd23f9a16..ee8aaad6ac6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvgx-pvwp-mq8w/GHSA-cvgx-pvwp-mq8w.json +++ b/advisories/unreviewed/2022/05/GHSA-cvgx-pvwp-mq8w/GHSA-cvgx-pvwp-mq8w.json @@ -7,12 +7,8 @@ "CVE-2019-18322" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to read and write arbitrary files on the local file system by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18321. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvqp-x8wc-59j8/GHSA-cvqp-x8wc-59j8.json b/advisories/unreviewed/2022/05/GHSA-cvqp-x8wc-59j8/GHSA-cvqp-x8wc-59j8.json index d84868a0109..403cb3dee82 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvqp-x8wc-59j8/GHSA-cvqp-x8wc-59j8.json +++ b/advisories/unreviewed/2022/05/GHSA-cvqp-x8wc-59j8/GHSA-cvqp-x8wc-59j8.json @@ -7,12 +7,8 @@ "CVE-2019-13683" ], "details": "Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f268-9fq5-h8qf/GHSA-f268-9fq5-h8qf.json b/advisories/unreviewed/2022/05/GHSA-f268-9fq5-h8qf/GHSA-f268-9fq5-h8qf.json index 0221f7a3a75..c410cc620f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-f268-9fq5-h8qf/GHSA-f268-9fq5-h8qf.json +++ b/advisories/unreviewed/2022/05/GHSA-f268-9fq5-h8qf/GHSA-f268-9fq5-h8qf.json @@ -7,12 +7,8 @@ "CVE-2019-19229" ], "details": "admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f3r5-9r3j-243r/GHSA-f3r5-9r3j-243r.json b/advisories/unreviewed/2022/05/GHSA-f3r5-9r3j-243r/GHSA-f3r5-9r3j-243r.json index 345a5e798b3..b59061b5d78 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3r5-9r3j-243r/GHSA-f3r5-9r3j-243r.json +++ b/advisories/unreviewed/2022/05/GHSA-f3r5-9r3j-243r/GHSA-f3r5-9r3j-243r.json @@ -7,12 +7,8 @@ "CVE-2019-18284" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). The AdminService is available without authentication on the Application Server. An attacker can use methods exposed via this interface to receive password hashes of other users and to change user passwords. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f438-7fwh-rhhq/GHSA-f438-7fwh-rhhq.json b/advisories/unreviewed/2022/05/GHSA-f438-7fwh-rhhq/GHSA-f438-7fwh-rhhq.json index ba833c70cb3..afdbc050161 100644 --- a/advisories/unreviewed/2022/05/GHSA-f438-7fwh-rhhq/GHSA-f438-7fwh-rhhq.json +++ b/advisories/unreviewed/2022/05/GHSA-f438-7fwh-rhhq/GHSA-f438-7fwh-rhhq.json @@ -7,12 +7,8 @@ "CVE-2019-19491" ], "details": "TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f47q-w692-63wj/GHSA-f47q-w692-63wj.json b/advisories/unreviewed/2022/05/GHSA-f47q-w692-63wj/GHSA-f47q-w692-63wj.json index f77a6c0afbc..2d30773d988 100644 --- a/advisories/unreviewed/2022/05/GHSA-f47q-w692-63wj/GHSA-f47q-w692-63wj.json +++ b/advisories/unreviewed/2022/05/GHSA-f47q-w692-63wj/GHSA-f47q-w692-63wj.json @@ -7,12 +7,8 @@ "CVE-2019-13678" ], "details": "Incorrect data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f4hc-mjp6-wmcp/GHSA-f4hc-mjp6-wmcp.json b/advisories/unreviewed/2022/05/GHSA-f4hc-mjp6-wmcp/GHSA-f4hc-mjp6-wmcp.json index f74ec50cee9..4ba500843f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4hc-mjp6-wmcp/GHSA-f4hc-mjp6-wmcp.json +++ b/advisories/unreviewed/2022/05/GHSA-f4hc-mjp6-wmcp/GHSA-f4hc-mjp6-wmcp.json @@ -7,12 +7,8 @@ "CVE-2019-18326" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18324, CVE-2019-18325, CVE-2019-18327, CVE-2019-18328, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f5hx-6pcp-xgp3/GHSA-f5hx-6pcp-xgp3.json b/advisories/unreviewed/2022/05/GHSA-f5hx-6pcp-xgp3/GHSA-f5hx-6pcp-xgp3.json index 2ad39ffa34a..04e6199bc00 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5hx-6pcp-xgp3/GHSA-f5hx-6pcp-xgp3.json +++ b/advisories/unreviewed/2022/05/GHSA-f5hx-6pcp-xgp3/GHSA-f5hx-6pcp-xgp3.json @@ -7,12 +7,8 @@ "CVE-2015-9537" ], "details": "The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f63f-3434-4v3m/GHSA-f63f-3434-4v3m.json b/advisories/unreviewed/2022/05/GHSA-f63f-3434-4v3m/GHSA-f63f-3434-4v3m.json index f6266438eba..5c974ebdd02 100644 --- a/advisories/unreviewed/2022/05/GHSA-f63f-3434-4v3m/GHSA-f63f-3434-4v3m.json +++ b/advisories/unreviewed/2022/05/GHSA-f63f-3434-4v3m/GHSA-f63f-3434-4v3m.json @@ -7,12 +7,8 @@ "CVE-2019-18330" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18324, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18328, and CVE-2019-18329. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6pq-354j-4f2p/GHSA-f6pq-354j-4f2p.json b/advisories/unreviewed/2022/05/GHSA-f6pq-354j-4f2p/GHSA-f6pq-354j-4f2p.json index a0fd9f31044..ad5d11492dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6pq-354j-4f2p/GHSA-f6pq-354j-4f2p.json +++ b/advisories/unreviewed/2022/05/GHSA-f6pq-354j-4f2p/GHSA-f6pq-354j-4f2p.json @@ -7,12 +7,8 @@ "CVE-2019-3749" ], "details": "Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the \"Temp\\ICProgress\\Dell_InventoryCollector_Progress.xml\" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8vw-827h-ffmp/GHSA-f8vw-827h-ffmp.json b/advisories/unreviewed/2022/05/GHSA-f8vw-827h-ffmp/GHSA-f8vw-827h-ffmp.json index b7a6cab50b5..e7f0b653a02 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8vw-827h-ffmp/GHSA-f8vw-827h-ffmp.json +++ b/advisories/unreviewed/2022/05/GHSA-f8vw-827h-ffmp/GHSA-f8vw-827h-ffmp.json @@ -7,12 +7,8 @@ "CVE-2019-7197" ], "details": "A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fc49-wm87-9q8m/GHSA-fc49-wm87-9q8m.json b/advisories/unreviewed/2022/05/GHSA-fc49-wm87-9q8m/GHSA-fc49-wm87-9q8m.json index 3e066491ed9..da94027c678 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc49-wm87-9q8m/GHSA-fc49-wm87-9q8m.json +++ b/advisories/unreviewed/2022/05/GHSA-fc49-wm87-9q8m/GHSA-fc49-wm87-9q8m.json @@ -7,12 +7,8 @@ "CVE-2019-17387" ], "details": "An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fg3g-4994-3829/GHSA-fg3g-4994-3829.json b/advisories/unreviewed/2022/05/GHSA-fg3g-4994-3829/GHSA-fg3g-4994-3829.json index ae2d05a2eb7..8bc4fdbdf26 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg3g-4994-3829/GHSA-fg3g-4994-3829.json +++ b/advisories/unreviewed/2022/05/GHSA-fg3g-4994-3829/GHSA-fg3g-4994-3829.json @@ -7,12 +7,8 @@ "CVE-2006-6171" ], "details": "** DISPUTED ** ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgxx-cm7r-ghp7/GHSA-fgxx-cm7r-ghp7.json b/advisories/unreviewed/2022/05/GHSA-fgxx-cm7r-ghp7/GHSA-fgxx-cm7r-ghp7.json index d4a6d05e905..f33ca497b29 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgxx-cm7r-ghp7/GHSA-fgxx-cm7r-ghp7.json +++ b/advisories/unreviewed/2022/05/GHSA-fgxx-cm7r-ghp7/GHSA-fgxx-cm7r-ghp7.json @@ -7,12 +7,8 @@ "CVE-2019-12391" ], "details": "The Anviz Management System for access control has insufficient logging for device events such as door open requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr8r-x4x7-r5mv/GHSA-fr8r-x4x7-r5mv.json b/advisories/unreviewed/2022/05/GHSA-fr8r-x4x7-r5mv/GHSA-fr8r-x4x7-r5mv.json index c7f0e285fc8..1fd51da15ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr8r-x4x7-r5mv/GHSA-fr8r-x4x7-r5mv.json +++ b/advisories/unreviewed/2022/05/GHSA-fr8r-x4x7-r5mv/GHSA-fr8r-x4x7-r5mv.json @@ -7,12 +7,8 @@ "CVE-2019-18290" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frj8-cjrv-7f9q/GHSA-frj8-cjrv-7f9q.json b/advisories/unreviewed/2022/05/GHSA-frj8-cjrv-7f9q/GHSA-frj8-cjrv-7f9q.json index 74b57e18d53..a466950c3a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-frj8-cjrv-7f9q/GHSA-frj8-cjrv-7f9q.json +++ b/advisories/unreviewed/2022/05/GHSA-frj8-cjrv-7f9q/GHSA-frj8-cjrv-7f9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frjv-h9wg-233r/GHSA-frjv-h9wg-233r.json b/advisories/unreviewed/2022/05/GHSA-frjv-h9wg-233r/GHSA-frjv-h9wg-233r.json index 40f15b8164c..2ce301ff2cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-frjv-h9wg-233r/GHSA-frjv-h9wg-233r.json +++ b/advisories/unreviewed/2022/05/GHSA-frjv-h9wg-233r/GHSA-frjv-h9wg-233r.json @@ -7,12 +7,8 @@ "CVE-2015-2060" ], "details": "cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frm6-q76c-62mx/GHSA-frm6-q76c-62mx.json b/advisories/unreviewed/2022/05/GHSA-frm6-q76c-62mx/GHSA-frm6-q76c-62mx.json index d37ff8bf0eb..787aacc226b 100644 --- a/advisories/unreviewed/2022/05/GHSA-frm6-q76c-62mx/GHSA-frm6-q76c-62mx.json +++ b/advisories/unreviewed/2022/05/GHSA-frm6-q76c-62mx/GHSA-frm6-q76c-62mx.json @@ -7,12 +7,8 @@ "CVE-2019-13692" ], "details": "Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwgm-gxhm-fgf8/GHSA-fwgm-gxhm-fgf8.json b/advisories/unreviewed/2022/05/GHSA-fwgm-gxhm-fgf8/GHSA-fwgm-gxhm-fgf8.json index c5285de3f25..7b87a3f8589 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwgm-gxhm-fgf8/GHSA-fwgm-gxhm-fgf8.json +++ b/advisories/unreviewed/2022/05/GHSA-fwgm-gxhm-fgf8/GHSA-fwgm-gxhm-fgf8.json @@ -7,12 +7,8 @@ "CVE-2019-16673" ], "details": "An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with access to the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwxv-68qg-w737/GHSA-fwxv-68qg-w737.json b/advisories/unreviewed/2022/05/GHSA-fwxv-68qg-w737/GHSA-fwxv-68qg-w737.json index efda8501161..f5cbc4037dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwxv-68qg-w737/GHSA-fwxv-68qg-w737.json +++ b/advisories/unreviewed/2022/05/GHSA-fwxv-68qg-w737/GHSA-fwxv-68qg-w737.json @@ -7,12 +7,8 @@ "CVE-2009-2948" ], "details": "mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxrv-qpg2-74h3/GHSA-fxrv-qpg2-74h3.json b/advisories/unreviewed/2022/05/GHSA-fxrv-qpg2-74h3/GHSA-fxrv-qpg2-74h3.json index 8a669d3b6c2..17686d0a775 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxrv-qpg2-74h3/GHSA-fxrv-qpg2-74h3.json +++ b/advisories/unreviewed/2022/05/GHSA-fxrv-qpg2-74h3/GHSA-fxrv-qpg2-74h3.json @@ -7,12 +7,8 @@ "CVE-2019-13684" ], "details": "Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxvh-gv5w-rx6c/GHSA-fxvh-gv5w-rx6c.json b/advisories/unreviewed/2022/05/GHSA-fxvh-gv5w-rx6c/GHSA-fxvh-gv5w-rx6c.json index 0fdfad70a2c..b3c176e3767 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxvh-gv5w-rx6c/GHSA-fxvh-gv5w-rx6c.json +++ b/advisories/unreviewed/2022/05/GHSA-fxvh-gv5w-rx6c/GHSA-fxvh-gv5w-rx6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g223-vgj2-7g9m/GHSA-g223-vgj2-7g9m.json b/advisories/unreviewed/2022/05/GHSA-g223-vgj2-7g9m/GHSA-g223-vgj2-7g9m.json index 0465483a6a7..263e727c8ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-g223-vgj2-7g9m/GHSA-g223-vgj2-7g9m.json +++ b/advisories/unreviewed/2022/05/GHSA-g223-vgj2-7g9m/GHSA-g223-vgj2-7g9m.json @@ -7,12 +7,8 @@ "CVE-2019-18245" ], "details": "Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, which may allow execution of code with elevated privileges of the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g24h-qq74-84hq/GHSA-g24h-qq74-84hq.json b/advisories/unreviewed/2022/05/GHSA-g24h-qq74-84hq/GHSA-g24h-qq74-84hq.json index 2e2bb864d18..4cde29bf2bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-g24h-qq74-84hq/GHSA-g24h-qq74-84hq.json +++ b/advisories/unreviewed/2022/05/GHSA-g24h-qq74-84hq/GHSA-g24h-qq74-84hq.json @@ -7,12 +7,8 @@ "CVE-2019-15007" ], "details": "The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g2fc-4mpm-58fg/GHSA-g2fc-4mpm-58fg.json b/advisories/unreviewed/2022/05/GHSA-g2fc-4mpm-58fg/GHSA-g2fc-4mpm-58fg.json index 9373adca6a6..c2a2481a6e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2fc-4mpm-58fg/GHSA-g2fc-4mpm-58fg.json +++ b/advisories/unreviewed/2022/05/GHSA-g2fc-4mpm-58fg/GHSA-g2fc-4mpm-58fg.json @@ -7,12 +7,8 @@ "CVE-2019-4606" ], "details": "IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 168298.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g47h-wpv4-rfwf/GHSA-g47h-wpv4-rfwf.json b/advisories/unreviewed/2022/05/GHSA-g47h-wpv4-rfwf/GHSA-g47h-wpv4-rfwf.json index 9ecdb9ce6d1..36e691f92ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-g47h-wpv4-rfwf/GHSA-g47h-wpv4-rfwf.json +++ b/advisories/unreviewed/2022/05/GHSA-g47h-wpv4-rfwf/GHSA-g47h-wpv4-rfwf.json @@ -7,12 +7,8 @@ "CVE-2005-1244" ], "details": "** DISPUTED ** Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via \"..\" sequences in a GET request. NOTE: the vendor has disputed this issue, saying that \"neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5mh-9cjj-vm5x/GHSA-g5mh-9cjj-vm5x.json b/advisories/unreviewed/2022/05/GHSA-g5mh-9cjj-vm5x/GHSA-g5mh-9cjj-vm5x.json index 09b67b9aa6c..9a6193553fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5mh-9cjj-vm5x/GHSA-g5mh-9cjj-vm5x.json +++ b/advisories/unreviewed/2022/05/GHSA-g5mh-9cjj-vm5x/GHSA-g5mh-9cjj-vm5x.json @@ -7,12 +7,8 @@ "CVE-2019-5269" ], "details": "Some Huawei home routers have an improper authorization vulnerability. Due to improper authorization of certain programs, an attacker can exploit this vulnerability to execute uploaded malicious files and escalate privilege.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5x4-mhjm-x6qc/GHSA-g5x4-mhjm-x6qc.json b/advisories/unreviewed/2022/05/GHSA-g5x4-mhjm-x6qc/GHSA-g5x4-mhjm-x6qc.json index acbf35fd95a..9cfe6942767 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5x4-mhjm-x6qc/GHSA-g5x4-mhjm-x6qc.json +++ b/advisories/unreviewed/2022/05/GHSA-g5x4-mhjm-x6qc/GHSA-g5x4-mhjm-x6qc.json @@ -7,12 +7,8 @@ "CVE-2015-9539" ], "details": "The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g624-89xp-hmx8/GHSA-g624-89xp-hmx8.json b/advisories/unreviewed/2022/05/GHSA-g624-89xp-hmx8/GHSA-g624-89xp-hmx8.json index 3f1ea8fdb8f..4f595134d42 100644 --- a/advisories/unreviewed/2022/05/GHSA-g624-89xp-hmx8/GHSA-g624-89xp-hmx8.json +++ b/advisories/unreviewed/2022/05/GHSA-g624-89xp-hmx8/GHSA-g624-89xp-hmx8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g77h-ghjv-vprw/GHSA-g77h-ghjv-vprw.json b/advisories/unreviewed/2022/05/GHSA-g77h-ghjv-vprw/GHSA-g77h-ghjv-vprw.json index 84a7f10d04c..220339c3e61 100644 --- a/advisories/unreviewed/2022/05/GHSA-g77h-ghjv-vprw/GHSA-g77h-ghjv-vprw.json +++ b/advisories/unreviewed/2022/05/GHSA-g77h-ghjv-vprw/GHSA-g77h-ghjv-vprw.json @@ -7,12 +7,8 @@ "CVE-2019-5860" ], "details": "Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g83g-x6pg-6c84/GHSA-g83g-x6pg-6c84.json b/advisories/unreviewed/2022/05/GHSA-g83g-x6pg-6c84/GHSA-g83g-x6pg-6c84.json index b14f5d7f152..9c832824556 100644 --- a/advisories/unreviewed/2022/05/GHSA-g83g-x6pg-6c84/GHSA-g83g-x6pg-6c84.json +++ b/advisories/unreviewed/2022/05/GHSA-g83g-x6pg-6c84/GHSA-g83g-x6pg-6c84.json @@ -7,12 +7,8 @@ "CVE-2019-17270" ], "details": "Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the \"/pages/systemcall.php?command={COMMAND}\" page and parameter, where {COMMAND} will be executed and returning the results to the client. Affects Yachtcontrol webservers disclosed via Dutch GPRS/4G mobile IP-ranges. IP addresses vary due to DHCP client leasing of telco's.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g968-q4r4-4gmq/GHSA-g968-q4r4-4gmq.json b/advisories/unreviewed/2022/05/GHSA-g968-q4r4-4gmq/GHSA-g968-q4r4-4gmq.json index 968b2392c3a..cc27af74de3 100644 --- a/advisories/unreviewed/2022/05/GHSA-g968-q4r4-4gmq/GHSA-g968-q4r4-4gmq.json +++ b/advisories/unreviewed/2022/05/GHSA-g968-q4r4-4gmq/GHSA-g968-q4r4-4gmq.json @@ -7,12 +7,8 @@ "CVE-2019-19384" ], "details": "A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gf8j-j7q8-vhh5/GHSA-gf8j-j7q8-vhh5.json b/advisories/unreviewed/2022/05/GHSA-gf8j-j7q8-vhh5/GHSA-gf8j-j7q8-vhh5.json index 2add12f0980..32b66430f2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf8j-j7q8-vhh5/GHSA-gf8j-j7q8-vhh5.json +++ b/advisories/unreviewed/2022/05/GHSA-gf8j-j7q8-vhh5/GHSA-gf8j-j7q8-vhh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gj53-2v73-4h48/GHSA-gj53-2v73-4h48.json b/advisories/unreviewed/2022/05/GHSA-gj53-2v73-4h48/GHSA-gj53-2v73-4h48.json index a9c85f7f262..375cc1ae02e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj53-2v73-4h48/GHSA-gj53-2v73-4h48.json +++ b/advisories/unreviewed/2022/05/GHSA-gj53-2v73-4h48/GHSA-gj53-2v73-4h48.json @@ -7,12 +7,8 @@ "CVE-2019-13676" ], "details": "Insufficient policy enforcement in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gj76-9gq9-34xq/GHSA-gj76-9gq9-34xq.json b/advisories/unreviewed/2022/05/GHSA-gj76-9gq9-34xq/GHSA-gj76-9gq9-34xq.json index 94fc1c2396f..71ca97d9e88 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj76-9gq9-34xq/GHSA-gj76-9gq9-34xq.json +++ b/advisories/unreviewed/2022/05/GHSA-gj76-9gq9-34xq/GHSA-gj76-9gq9-34xq.json @@ -7,12 +7,8 @@ "CVE-2019-6667" ], "details": "On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under certain conditions, TMM may consume excessive resources when processing traffic for a Virtual Server with the FIX (Financial Information eXchange) profile applied.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjgq-7qmc-vjmv/GHSA-gjgq-7qmc-vjmv.json b/advisories/unreviewed/2022/05/GHSA-gjgq-7qmc-vjmv/GHSA-gjgq-7qmc-vjmv.json index 34099ae2379..6adcd361964 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjgq-7qmc-vjmv/GHSA-gjgq-7qmc-vjmv.json +++ b/advisories/unreviewed/2022/05/GHSA-gjgq-7qmc-vjmv/GHSA-gjgq-7qmc-vjmv.json @@ -7,12 +7,8 @@ "CVE-2019-18333" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could gain access to filenames on the server by sending specifically crafted packets to 8090/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjq4-c23m-6wgc/GHSA-gjq4-c23m-6wgc.json b/advisories/unreviewed/2022/05/GHSA-gjq4-c23m-6wgc/GHSA-gjq4-c23m-6wgc.json index 5f997a0e585..0fe90759198 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjq4-c23m-6wgc/GHSA-gjq4-c23m-6wgc.json +++ b/advisories/unreviewed/2022/05/GHSA-gjq4-c23m-6wgc/GHSA-gjq4-c23m-6wgc.json @@ -7,12 +7,8 @@ "CVE-2019-18283" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). The AdminService is available without authentication on the Application Server. An attacker can gain remote code execution by sending specifically crafted objects to one of its functions. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmhh-hvg9-g5rj/GHSA-gmhh-hvg9-g5rj.json b/advisories/unreviewed/2022/05/GHSA-gmhh-hvg9-g5rj/GHSA-gmhh-hvg9-g5rj.json index eb7a85a1248..7e423644f09 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmhh-hvg9-g5rj/GHSA-gmhh-hvg9-g5rj.json +++ b/advisories/unreviewed/2022/05/GHSA-gmhh-hvg9-g5rj/GHSA-gmhh-hvg9-g5rj.json @@ -7,12 +7,8 @@ "CVE-2019-13668" ], "details": "Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gmjr-xhqw-c9qx/GHSA-gmjr-xhqw-c9qx.json b/advisories/unreviewed/2022/05/GHSA-gmjr-xhqw-c9qx/GHSA-gmjr-xhqw-c9qx.json index e4417378349..4407b5aaf30 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmjr-xhqw-c9qx/GHSA-gmjr-xhqw-c9qx.json +++ b/advisories/unreviewed/2022/05/GHSA-gmjr-xhqw-c9qx/GHSA-gmjr-xhqw-c9qx.json @@ -7,12 +7,8 @@ "CVE-2019-19720" ], "details": "Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gp9r-cv63-32fj/GHSA-gp9r-cv63-32fj.json b/advisories/unreviewed/2022/05/GHSA-gp9r-cv63-32fj/GHSA-gp9r-cv63-32fj.json index a5644dbfe33..1b866f387c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp9r-cv63-32fj/GHSA-gp9r-cv63-32fj.json +++ b/advisories/unreviewed/2022/05/GHSA-gp9r-cv63-32fj/GHSA-gp9r-cv63-32fj.json @@ -7,12 +7,8 @@ "CVE-2019-15631" ], "details": "Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gpq9-qcf2-pj58/GHSA-gpq9-qcf2-pj58.json b/advisories/unreviewed/2022/05/GHSA-gpq9-qcf2-pj58/GHSA-gpq9-qcf2-pj58.json index 232f2554141..d6c661f64ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpq9-qcf2-pj58/GHSA-gpq9-qcf2-pj58.json +++ b/advisories/unreviewed/2022/05/GHSA-gpq9-qcf2-pj58/GHSA-gpq9-qcf2-pj58.json @@ -7,12 +7,8 @@ "CVE-2019-18303" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpv3-wf7m-8269/GHSA-gpv3-wf7m-8269.json b/advisories/unreviewed/2022/05/GHSA-gpv3-wf7m-8269/GHSA-gpv3-wf7m-8269.json index 5c68b50b9b3..f2660c40f06 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpv3-wf7m-8269/GHSA-gpv3-wf7m-8269.json +++ b/advisories/unreviewed/2022/05/GHSA-gpv3-wf7m-8269/GHSA-gpv3-wf7m-8269.json @@ -7,12 +7,8 @@ "CVE-2019-2223" ], "details": "In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140692129", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr8p-66g9-4565/GHSA-gr8p-66g9-4565.json b/advisories/unreviewed/2022/05/GHSA-gr8p-66g9-4565/GHSA-gr8p-66g9-4565.json index 5d976041889..a1478fa4f15 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr8p-66g9-4565/GHSA-gr8p-66g9-4565.json +++ b/advisories/unreviewed/2022/05/GHSA-gr8p-66g9-4565/GHSA-gr8p-66g9-4565.json @@ -7,12 +7,8 @@ "CVE-2019-19553" ], "details": "In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv39-q8v4-8v4w/GHSA-gv39-q8v4-8v4w.json b/advisories/unreviewed/2022/05/GHSA-gv39-q8v4-8v4w/GHSA-gv39-q8v4-8v4w.json index 2e0adb865d7..ba7505dc581 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv39-q8v4-8v4w/GHSA-gv39-q8v4-8v4w.json +++ b/advisories/unreviewed/2022/05/GHSA-gv39-q8v4-8v4w/GHSA-gv39-q8v4-8v4w.json @@ -7,12 +7,8 @@ "CVE-2019-2338" ], "details": "Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvvg-f3fg-w335/GHSA-gvvg-f3fg-w335.json b/advisories/unreviewed/2022/05/GHSA-gvvg-f3fg-w335/GHSA-gvvg-f3fg-w335.json index d71da10bbca..53c7354aad2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvvg-f3fg-w335/GHSA-gvvg-f3fg-w335.json +++ b/advisories/unreviewed/2022/05/GHSA-gvvg-f3fg-w335/GHSA-gvvg-f3fg-w335.json @@ -7,12 +7,8 @@ "CVE-2019-18309" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a low privileged user account could gain root privileges by manipulating specific files in the local file system. This vulnerability is independent from CVE-2019-18308. Please note that an attacker needs to have local access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwm4-vr82-pwg9/GHSA-gwm4-vr82-pwg9.json b/advisories/unreviewed/2022/05/GHSA-gwm4-vr82-pwg9/GHSA-gwm4-vr82-pwg9.json index 45476bed8fe..ce9df10d6f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwm4-vr82-pwg9/GHSA-gwm4-vr82-pwg9.json +++ b/advisories/unreviewed/2022/05/GHSA-gwm4-vr82-pwg9/GHSA-gwm4-vr82-pwg9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx75-66mx-pjmm/GHSA-gx75-66mx-pjmm.json b/advisories/unreviewed/2022/05/GHSA-gx75-66mx-pjmm/GHSA-gx75-66mx-pjmm.json index cdb43a275ef..826a3556faa 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx75-66mx-pjmm/GHSA-gx75-66mx-pjmm.json +++ b/advisories/unreviewed/2022/05/GHSA-gx75-66mx-pjmm/GHSA-gx75-66mx-pjmm.json @@ -7,12 +7,8 @@ "CVE-2019-18447" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2hc-3hmw-fmq5/GHSA-h2hc-3hmw-fmq5.json b/advisories/unreviewed/2022/05/GHSA-h2hc-3hmw-fmq5/GHSA-h2hc-3hmw-fmq5.json index e7f5889275d..f754b284776 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2hc-3hmw-fmq5/GHSA-h2hc-3hmw-fmq5.json +++ b/advisories/unreviewed/2022/05/GHSA-h2hc-3hmw-fmq5/GHSA-h2hc-3hmw-fmq5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2w7-hfq4-7xgx/GHSA-h2w7-hfq4-7xgx.json b/advisories/unreviewed/2022/05/GHSA-h2w7-hfq4-7xgx/GHSA-h2w7-hfq4-7xgx.json index cab837898ce..64822973c8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2w7-hfq4-7xgx/GHSA-h2w7-hfq4-7xgx.json +++ b/advisories/unreviewed/2022/05/GHSA-h2w7-hfq4-7xgx/GHSA-h2w7-hfq4-7xgx.json @@ -7,12 +7,8 @@ "CVE-2019-18250" ], "details": "In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h34c-2r22-jc5j/GHSA-h34c-2r22-jc5j.json b/advisories/unreviewed/2022/05/GHSA-h34c-2r22-jc5j/GHSA-h34c-2r22-jc5j.json index a66dc7c923d..62f200e652d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h34c-2r22-jc5j/GHSA-h34c-2r22-jc5j.json +++ b/advisories/unreviewed/2022/05/GHSA-h34c-2r22-jc5j/GHSA-h34c-2r22-jc5j.json @@ -7,12 +7,8 @@ "CVE-2006-6167" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in L. Brandon Stone and Nathanial P. Hendler Active PHP Bookmarks (APB) 1.1.02 allow remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS['apb_path'] parameter in (1) apb_common.php or (2) apb.php. NOTE: CVE and another third party dispute this vulnerability because these PHP scripts exit if the attack vectors are present in GPC variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h398-v6mj-crpf/GHSA-h398-v6mj-crpf.json b/advisories/unreviewed/2022/05/GHSA-h398-v6mj-crpf/GHSA-h398-v6mj-crpf.json index 9480e0ee4b8..d4dfbcebb55 100644 --- a/advisories/unreviewed/2022/05/GHSA-h398-v6mj-crpf/GHSA-h398-v6mj-crpf.json +++ b/advisories/unreviewed/2022/05/GHSA-h398-v6mj-crpf/GHSA-h398-v6mj-crpf.json @@ -7,12 +7,8 @@ "CVE-2019-19581" ], "details": "An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bounds access) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over all bits involves functions which may misbehave in certain corner cases: On 32-bit Arm accesses to bitmaps with bit a count which is a multiple of 32, an out of bounds access may occur. A malicious guest may cause a hypervisor crash or hang, resulting in a Denial of Service (DoS). All versions of Xen are vulnerable. 32-bit Arm systems are vulnerable. 64-bit Arm systems are not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h3gx-q82j-vhq3/GHSA-h3gx-q82j-vhq3.json b/advisories/unreviewed/2022/05/GHSA-h3gx-q82j-vhq3/GHSA-h3gx-q82j-vhq3.json index 5a1e9482ec0..c691b1a11db 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3gx-q82j-vhq3/GHSA-h3gx-q82j-vhq3.json +++ b/advisories/unreviewed/2022/05/GHSA-h3gx-q82j-vhq3/GHSA-h3gx-q82j-vhq3.json @@ -7,12 +7,8 @@ "CVE-2019-19228" ], "details": "Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h3jq-gxm5-vhxg/GHSA-h3jq-gxm5-vhxg.json b/advisories/unreviewed/2022/05/GHSA-h3jq-gxm5-vhxg/GHSA-h3jq-gxm5-vhxg.json index 547a44c1953..6b7bd1d7662 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3jq-gxm5-vhxg/GHSA-h3jq-gxm5-vhxg.json +++ b/advisories/unreviewed/2022/05/GHSA-h3jq-gxm5-vhxg/GHSA-h3jq-gxm5-vhxg.json @@ -7,12 +7,8 @@ "CVE-2019-19329" ], "details": "In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, aka XSS. This was addressed by introducing MathJax as a new mathematics rendering engine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h4qw-99jp-7g9f/GHSA-h4qw-99jp-7g9f.json b/advisories/unreviewed/2022/05/GHSA-h4qw-99jp-7g9f/GHSA-h4qw-99jp-7g9f.json index 1547fde322b..2d8c620252a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4qw-99jp-7g9f/GHSA-h4qw-99jp-7g9f.json +++ b/advisories/unreviewed/2022/05/GHSA-h4qw-99jp-7g9f/GHSA-h4qw-99jp-7g9f.json @@ -7,12 +7,8 @@ "CVE-2019-18311" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent from CVE-2019-18310. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4vc-wv6x-gx67/GHSA-h4vc-wv6x-gx67.json b/advisories/unreviewed/2022/05/GHSA-h4vc-wv6x-gx67/GHSA-h4vc-wv6x-gx67.json index 81a58fa56ec..346b39a86d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4vc-wv6x-gx67/GHSA-h4vc-wv6x-gx67.json +++ b/advisories/unreviewed/2022/05/GHSA-h4vc-wv6x-gx67/GHSA-h4vc-wv6x-gx67.json @@ -7,12 +7,8 @@ "CVE-2019-19516" ], "details": "Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5m2-8pmw-gmg7/GHSA-h5m2-8pmw-gmg7.json b/advisories/unreviewed/2022/05/GHSA-h5m2-8pmw-gmg7/GHSA-h5m2-8pmw-gmg7.json index 44acf15a303..cecf22871f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5m2-8pmw-gmg7/GHSA-h5m2-8pmw-gmg7.json +++ b/advisories/unreviewed/2022/05/GHSA-h5m2-8pmw-gmg7/GHSA-h5m2-8pmw-gmg7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7c9-gjhc-27w5/GHSA-h7c9-gjhc-27w5.json b/advisories/unreviewed/2022/05/GHSA-h7c9-gjhc-27w5/GHSA-h7c9-gjhc-27w5.json index 0873799586b..b9728e4259c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7c9-gjhc-27w5/GHSA-h7c9-gjhc-27w5.json +++ b/advisories/unreviewed/2022/05/GHSA-h7c9-gjhc-27w5/GHSA-h7c9-gjhc-27w5.json @@ -7,12 +7,8 @@ "CVE-2019-13931" ], "details": "A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow for an an attacker to craft the input in a form that is not expected, causing the application to behave in unexpected ways for legitimate users. Successful exploitation requires for an attacker to be authenticated to the web interface. A successful attack could cause the application to have unexpected behavior. This could allow the attacker to modify contents of the web application. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h7m2-gw69-h6vr/GHSA-h7m2-gw69-h6vr.json b/advisories/unreviewed/2022/05/GHSA-h7m2-gw69-h6vr/GHSA-h7m2-gw69-h6vr.json index 335cac69b19..02419fd6c1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7m2-gw69-h6vr/GHSA-h7m2-gw69-h6vr.json +++ b/advisories/unreviewed/2022/05/GHSA-h7m2-gw69-h6vr/GHSA-h7m2-gw69-h6vr.json @@ -7,12 +7,8 @@ "CVE-2006-1050" ], "details": "** DISPUTED ** Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: the vendor has disputed this vulnerability, stating that \"The kwikpay.mdb file supplied with kwikpay is a template for the database structure of user databases created by kwikpay and to store a demonstration payroll. It does not contain any sensitive user information. When a user payroll database is opened, the encryption of the database is checked and if the database is not encrypted, the user is prompted to encrypt the database, but the choice is the customers.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hcmc-r7j6-4q4h/GHSA-hcmc-r7j6-4q4h.json b/advisories/unreviewed/2022/05/GHSA-hcmc-r7j6-4q4h/GHSA-hcmc-r7j6-4q4h.json index c2f10afc10c..79e363f5147 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcmc-r7j6-4q4h/GHSA-hcmc-r7j6-4q4h.json +++ b/advisories/unreviewed/2022/05/GHSA-hcmc-r7j6-4q4h/GHSA-hcmc-r7j6-4q4h.json @@ -7,12 +7,8 @@ "CVE-2019-10485" ], "details": "Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hcrx-7wpm-hhwq/GHSA-hcrx-7wpm-hhwq.json b/advisories/unreviewed/2022/05/GHSA-hcrx-7wpm-hhwq/GHSA-hcrx-7wpm-hhwq.json index b9af8a1efa7..387bcce16c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcrx-7wpm-hhwq/GHSA-hcrx-7wpm-hhwq.json +++ b/advisories/unreviewed/2022/05/GHSA-hcrx-7wpm-hhwq/GHSA-hcrx-7wpm-hhwq.json @@ -7,12 +7,8 @@ "CVE-2019-5879" ], "details": "Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfjc-qvjw-4cxm/GHSA-hfjc-qvjw-4cxm.json b/advisories/unreviewed/2022/05/GHSA-hfjc-qvjw-4cxm/GHSA-hfjc-qvjw-4cxm.json index b8bbb9e245a..857ae5c771c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfjc-qvjw-4cxm/GHSA-hfjc-qvjw-4cxm.json +++ b/advisories/unreviewed/2022/05/GHSA-hfjc-qvjw-4cxm/GHSA-hfjc-qvjw-4cxm.json @@ -7,12 +7,8 @@ "CVE-2019-6665" ], "details": "On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, an attacker with access to the device communication between the BIG-IP ASM Central Policy Builder and the BIG-IQ/Enterprise Manager/F5 iWorkflow will be able to set up the proxy the same way and intercept the traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hgxf-cvh7-ghp4/GHSA-hgxf-cvh7-ghp4.json b/advisories/unreviewed/2022/05/GHSA-hgxf-cvh7-ghp4/GHSA-hgxf-cvh7-ghp4.json index f986395eb39..94e3fa52c8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgxf-cvh7-ghp4/GHSA-hgxf-cvh7-ghp4.json +++ b/advisories/unreviewed/2022/05/GHSA-hgxf-cvh7-ghp4/GHSA-hgxf-cvh7-ghp4.json @@ -7,12 +7,8 @@ "CVE-2019-19793" ], "details": "In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain can gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hh28-x8g4-gw96/GHSA-hh28-x8g4-gw96.json b/advisories/unreviewed/2022/05/GHSA-hh28-x8g4-gw96/GHSA-hh28-x8g4-gw96.json index 6b318f68efa..348e74da5d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh28-x8g4-gw96/GHSA-hh28-x8g4-gw96.json +++ b/advisories/unreviewed/2022/05/GHSA-hh28-x8g4-gw96/GHSA-hh28-x8g4-gw96.json @@ -7,12 +7,8 @@ "CVE-2019-19595" ], "details": "reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hh3p-v353-7rmj/GHSA-hh3p-v353-7rmj.json b/advisories/unreviewed/2022/05/GHSA-hh3p-v353-7rmj/GHSA-hh3p-v353-7rmj.json index 9b7846e9ecf..fcec77b0036 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh3p-v353-7rmj/GHSA-hh3p-v353-7rmj.json +++ b/advisories/unreviewed/2022/05/GHSA-hh3p-v353-7rmj/GHSA-hh3p-v353-7rmj.json @@ -7,12 +7,8 @@ "CVE-2019-10493" ], "details": "Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhw9-pw8h-qc2h/GHSA-hhw9-pw8h-qc2h.json b/advisories/unreviewed/2022/05/GHSA-hhw9-pw8h-qc2h/GHSA-hhw9-pw8h-qc2h.json index b5db2ce585c..f881361269d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhw9-pw8h-qc2h/GHSA-hhw9-pw8h-qc2h.json +++ b/advisories/unreviewed/2022/05/GHSA-hhw9-pw8h-qc2h/GHSA-hhw9-pw8h-qc2h.json @@ -7,12 +7,8 @@ "CVE-2006-5255" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in addnews.php in Greg Neustaetter gCards 1.13 allows remote attackers to execute arbitrary PHP code via a URL in the languagefile parameter. NOTE: another researcher has observed that languageFile is defined before use. CVE analysis as of 20061012 concurs with the dispute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hj4p-qm6q-mm5m/GHSA-hj4p-qm6q-mm5m.json b/advisories/unreviewed/2022/05/GHSA-hj4p-qm6q-mm5m/GHSA-hj4p-qm6q-mm5m.json index d97c8ad0ba4..5349399676a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj4p-qm6q-mm5m/GHSA-hj4p-qm6q-mm5m.json +++ b/advisories/unreviewed/2022/05/GHSA-hj4p-qm6q-mm5m/GHSA-hj4p-qm6q-mm5m.json @@ -7,12 +7,8 @@ "CVE-2019-19489" ], "details": "SMPlayer 19.5.0 has a buffer overflow via a long .m3u file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjfg-8xqx-2vw8/GHSA-hjfg-8xqx-2vw8.json b/advisories/unreviewed/2022/05/GHSA-hjfg-8xqx-2vw8/GHSA-hjfg-8xqx-2vw8.json index afeb6c411fd..7532de10120 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjfg-8xqx-2vw8/GHSA-hjfg-8xqx-2vw8.json +++ b/advisories/unreviewed/2022/05/GHSA-hjfg-8xqx-2vw8/GHSA-hjfg-8xqx-2vw8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp2p-gr52-7qp5/GHSA-hp2p-gr52-7qp5.json b/advisories/unreviewed/2022/05/GHSA-hp2p-gr52-7qp5/GHSA-hp2p-gr52-7qp5.json index d90d1712110..8bb3d654627 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp2p-gr52-7qp5/GHSA-hp2p-gr52-7qp5.json +++ b/advisories/unreviewed/2022/05/GHSA-hp2p-gr52-7qp5/GHSA-hp2p-gr52-7qp5.json @@ -7,12 +7,8 @@ "CVE-2019-4521" ], "details": "Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 165179.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp4h-vx4q-gj6m/GHSA-hp4h-vx4q-gj6m.json b/advisories/unreviewed/2022/05/GHSA-hp4h-vx4q-gj6m/GHSA-hp4h-vx4q-gj6m.json index f6d3ee5da79..6e43c781f40 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp4h-vx4q-gj6m/GHSA-hp4h-vx4q-gj6m.json +++ b/advisories/unreviewed/2022/05/GHSA-hp4h-vx4q-gj6m/GHSA-hp4h-vx4q-gj6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp8p-42mw-fvq9/GHSA-hp8p-42mw-fvq9.json b/advisories/unreviewed/2022/05/GHSA-hp8p-42mw-fvq9/GHSA-hp8p-42mw-fvq9.json index 7701d331abe..b8a557add52 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp8p-42mw-fvq9/GHSA-hp8p-42mw-fvq9.json +++ b/advisories/unreviewed/2022/05/GHSA-hp8p-42mw-fvq9/GHSA-hp8p-42mw-fvq9.json @@ -7,12 +7,8 @@ "CVE-2019-19537" ], "details": "In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpg6-j356-pfwf/GHSA-hpg6-j356-pfwf.json b/advisories/unreviewed/2022/05/GHSA-hpg6-j356-pfwf/GHSA-hpg6-j356-pfwf.json index 67ff174c670..8dbfe414318 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpg6-j356-pfwf/GHSA-hpg6-j356-pfwf.json +++ b/advisories/unreviewed/2022/05/GHSA-hpg6-j356-pfwf/GHSA-hpg6-j356-pfwf.json @@ -7,12 +7,8 @@ "CVE-2019-15009" ], "details": "The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpmp-m758-4r73/GHSA-hpmp-m758-4r73.json b/advisories/unreviewed/2022/05/GHSA-hpmp-m758-4r73/GHSA-hpmp-m758-4r73.json index 413f9e6ec95..9a200b258a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpmp-m758-4r73/GHSA-hpmp-m758-4r73.json +++ b/advisories/unreviewed/2022/05/GHSA-hpmp-m758-4r73/GHSA-hpmp-m758-4r73.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpxr-gm5p-rf22/GHSA-hpxr-gm5p-rf22.json b/advisories/unreviewed/2022/05/GHSA-hpxr-gm5p-rf22/GHSA-hpxr-gm5p-rf22.json index 96c43eb700b..c6eebd75708 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpxr-gm5p-rf22/GHSA-hpxr-gm5p-rf22.json +++ b/advisories/unreviewed/2022/05/GHSA-hpxr-gm5p-rf22/GHSA-hpxr-gm5p-rf22.json @@ -7,12 +7,8 @@ "CVE-2019-13685" ], "details": "Use after free in sharing view in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hq45-w97p-p68r/GHSA-hq45-w97p-p68r.json b/advisories/unreviewed/2022/05/GHSA-hq45-w97p-p68r/GHSA-hq45-w97p-p68r.json index 857f50219ed..a2939c0f560 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq45-w97p-p68r/GHSA-hq45-w97p-p68r.json +++ b/advisories/unreviewed/2022/05/GHSA-hq45-w97p-p68r/GHSA-hq45-w97p-p68r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrrp-pp4j-hx63/GHSA-hrrp-pp4j-hx63.json b/advisories/unreviewed/2022/05/GHSA-hrrp-pp4j-hx63/GHSA-hrrp-pp4j-hx63.json index a0fb40e58b2..be2df23c4d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrrp-pp4j-hx63/GHSA-hrrp-pp4j-hx63.json +++ b/advisories/unreviewed/2022/05/GHSA-hrrp-pp4j-hx63/GHSA-hrrp-pp4j-hx63.json @@ -7,12 +7,8 @@ "CVE-2019-13682" ], "details": "Insufficient policy enforcement in external protocol handling in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hxgh-gx53-7hrw/GHSA-hxgh-gx53-7hrw.json b/advisories/unreviewed/2022/05/GHSA-hxgh-gx53-7hrw/GHSA-hxgh-gx53-7hrw.json index 832a5b8cc9f..2ebec401fff 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxgh-gx53-7hrw/GHSA-hxgh-gx53-7hrw.json +++ b/advisories/unreviewed/2022/05/GHSA-hxgh-gx53-7hrw/GHSA-hxgh-gx53-7hrw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hxq4-7jhg-m8g2/GHSA-hxq4-7jhg-m8g2.json b/advisories/unreviewed/2022/05/GHSA-hxq4-7jhg-m8g2/GHSA-hxq4-7jhg-m8g2.json index 91354fa95d6..b4cf32a3f3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hxq4-7jhg-m8g2/GHSA-hxq4-7jhg-m8g2.json +++ b/advisories/unreviewed/2022/05/GHSA-hxq4-7jhg-m8g2/GHSA-hxq4-7jhg-m8g2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j364-j4vw-rfhp/GHSA-j364-j4vw-rfhp.json b/advisories/unreviewed/2022/05/GHSA-j364-j4vw-rfhp/GHSA-j364-j4vw-rfhp.json index 4bcb9b44905..2d7e6dd5160 100644 --- a/advisories/unreviewed/2022/05/GHSA-j364-j4vw-rfhp/GHSA-j364-j4vw-rfhp.json +++ b/advisories/unreviewed/2022/05/GHSA-j364-j4vw-rfhp/GHSA-j364-j4vw-rfhp.json @@ -7,12 +7,8 @@ "CVE-2019-19388" ], "details": "A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j44r-m3r9-2886/GHSA-j44r-m3r9-2886.json b/advisories/unreviewed/2022/05/GHSA-j44r-m3r9-2886/GHSA-j44r-m3r9-2886.json index efc05235e0d..6b711e0b95c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j44r-m3r9-2886/GHSA-j44r-m3r9-2886.json +++ b/advisories/unreviewed/2022/05/GHSA-j44r-m3r9-2886/GHSA-j44r-m3r9-2886.json @@ -7,12 +7,8 @@ "CVE-2019-4665" ], "details": "IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171247.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j46x-fxq3-h2m3/GHSA-j46x-fxq3-h2m3.json b/advisories/unreviewed/2022/05/GHSA-j46x-fxq3-h2m3/GHSA-j46x-fxq3-h2m3.json index 918a9ce324d..e80416c34c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-j46x-fxq3-h2m3/GHSA-j46x-fxq3-h2m3.json +++ b/advisories/unreviewed/2022/05/GHSA-j46x-fxq3-h2m3/GHSA-j46x-fxq3-h2m3.json @@ -7,12 +7,8 @@ "CVE-2019-5859" ], "details": "Insufficient filtering in URI schemes in Google Chrome on Windows prior to 76.0.3809.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j65x-pp5m-j68h/GHSA-j65x-pp5m-j68h.json b/advisories/unreviewed/2022/05/GHSA-j65x-pp5m-j68h/GHSA-j65x-pp5m-j68h.json index 29e761bae87..51a9d2bde24 100644 --- a/advisories/unreviewed/2022/05/GHSA-j65x-pp5m-j68h/GHSA-j65x-pp5m-j68h.json +++ b/advisories/unreviewed/2022/05/GHSA-j65x-pp5m-j68h/GHSA-j65x-pp5m-j68h.json @@ -7,12 +7,8 @@ "CVE-2019-9464" ], "details": "In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicating an app accessed the user's location. This could dissolve the trust in the platform's permission system, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141028068", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j68g-j7h6-gwqw/GHSA-j68g-j7h6-gwqw.json b/advisories/unreviewed/2022/05/GHSA-j68g-j7h6-gwqw/GHSA-j68g-j7h6-gwqw.json index 13567c8bba4..e8a16303c94 100644 --- a/advisories/unreviewed/2022/05/GHSA-j68g-j7h6-gwqw/GHSA-j68g-j7h6-gwqw.json +++ b/advisories/unreviewed/2022/05/GHSA-j68g-j7h6-gwqw/GHSA-j68g-j7h6-gwqw.json @@ -7,12 +7,8 @@ "CVE-2019-19247" ], "details": "Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8mv-4vjx-93p6/GHSA-j8mv-4vjx-93p6.json b/advisories/unreviewed/2022/05/GHSA-j8mv-4vjx-93p6/GHSA-j8mv-4vjx-93p6.json index cd61a35e3fd..1d75230641f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8mv-4vjx-93p6/GHSA-j8mv-4vjx-93p6.json +++ b/advisories/unreviewed/2022/05/GHSA-j8mv-4vjx-93p6/GHSA-j8mv-4vjx-93p6.json @@ -7,12 +7,8 @@ "CVE-2019-17392" ], "details": "Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jcxc-5f87-vq5m/GHSA-jcxc-5f87-vq5m.json b/advisories/unreviewed/2022/05/GHSA-jcxc-5f87-vq5m/GHSA-jcxc-5f87-vq5m.json index 4550ea43806..cd14b4f5440 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcxc-5f87-vq5m/GHSA-jcxc-5f87-vq5m.json +++ b/advisories/unreviewed/2022/05/GHSA-jcxc-5f87-vq5m/GHSA-jcxc-5f87-vq5m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgrm-xfcc-mqp9/GHSA-jgrm-xfcc-mqp9.json b/advisories/unreviewed/2022/05/GHSA-jgrm-xfcc-mqp9/GHSA-jgrm-xfcc-mqp9.json index e18797c71af..590dbcaaa8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgrm-xfcc-mqp9/GHSA-jgrm-xfcc-mqp9.json +++ b/advisories/unreviewed/2022/05/GHSA-jgrm-xfcc-mqp9/GHSA-jgrm-xfcc-mqp9.json @@ -7,12 +7,8 @@ "CVE-2019-13711" ], "details": "Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhm5-r427-j4rc/GHSA-jhm5-r427-j4rc.json b/advisories/unreviewed/2022/05/GHSA-jhm5-r427-j4rc/GHSA-jhm5-r427-j4rc.json index 397dc003997..3d62c870e27 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhm5-r427-j4rc/GHSA-jhm5-r427-j4rc.json +++ b/advisories/unreviewed/2022/05/GHSA-jhm5-r427-j4rc/GHSA-jhm5-r427-j4rc.json @@ -7,12 +7,8 @@ "CVE-2019-19520" ], "details": "xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jj26-78h6-475h/GHSA-jj26-78h6-475h.json b/advisories/unreviewed/2022/05/GHSA-jj26-78h6-475h/GHSA-jj26-78h6-475h.json index 23af45e16d8..64399e65dcd 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj26-78h6-475h/GHSA-jj26-78h6-475h.json +++ b/advisories/unreviewed/2022/05/GHSA-jj26-78h6-475h/GHSA-jj26-78h6-475h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpcf-xprw-w8hm/GHSA-jpcf-xprw-w8hm.json b/advisories/unreviewed/2022/05/GHSA-jpcf-xprw-w8hm/GHSA-jpcf-xprw-w8hm.json index da599a14ab3..a6f8abd8dbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpcf-xprw-w8hm/GHSA-jpcf-xprw-w8hm.json +++ b/advisories/unreviewed/2022/05/GHSA-jpcf-xprw-w8hm/GHSA-jpcf-xprw-w8hm.json @@ -7,12 +7,8 @@ "CVE-2019-2220" ], "details": "In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling application suspend. This could lead to local information disclosure no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-138636979", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpvg-r6vh-56w3/GHSA-jpvg-r6vh-56w3.json b/advisories/unreviewed/2022/05/GHSA-jpvg-r6vh-56w3/GHSA-jpvg-r6vh-56w3.json index a8146e3117c..2910b3899ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpvg-r6vh-56w3/GHSA-jpvg-r6vh-56w3.json +++ b/advisories/unreviewed/2022/05/GHSA-jpvg-r6vh-56w3/GHSA-jpvg-r6vh-56w3.json @@ -7,12 +7,8 @@ "CVE-2019-0403" ], "details": "SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqrc-77wc-2g85/GHSA-jqrc-77wc-2g85.json b/advisories/unreviewed/2022/05/GHSA-jqrc-77wc-2g85/GHSA-jqrc-77wc-2g85.json index 4df834b8360..ee1df5eec87 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqrc-77wc-2g85/GHSA-jqrc-77wc-2g85.json +++ b/advisories/unreviewed/2022/05/GHSA-jqrc-77wc-2g85/GHSA-jqrc-77wc-2g85.json @@ -7,12 +7,8 @@ "CVE-2019-11936" ], "details": "Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqv9-2w7w-rccv/GHSA-jqv9-2w7w-rccv.json b/advisories/unreviewed/2022/05/GHSA-jqv9-2w7w-rccv/GHSA-jqv9-2w7w-rccv.json index 3525e78624a..be4a9b3a5df 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqv9-2w7w-rccv/GHSA-jqv9-2w7w-rccv.json +++ b/advisories/unreviewed/2022/05/GHSA-jqv9-2w7w-rccv/GHSA-jqv9-2w7w-rccv.json @@ -7,12 +7,8 @@ "CVE-2019-19707" ], "details": "On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jr5w-49p5-gc6w/GHSA-jr5w-49p5-gc6w.json b/advisories/unreviewed/2022/05/GHSA-jr5w-49p5-gc6w/GHSA-jr5w-49p5-gc6w.json index 207d29b27d3..87ab93be74e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr5w-49p5-gc6w/GHSA-jr5w-49p5-gc6w.json +++ b/advisories/unreviewed/2022/05/GHSA-jr5w-49p5-gc6w/GHSA-jr5w-49p5-gc6w.json @@ -7,12 +7,8 @@ "CVE-2006-5234" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since \"PHPWS_SOURCE_DIR\" is defined as a constant, not accessed as a variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jr83-rwfm-7r6r/GHSA-jr83-rwfm-7r6r.json b/advisories/unreviewed/2022/05/GHSA-jr83-rwfm-7r6r/GHSA-jr83-rwfm-7r6r.json index b8148a6d492..0fd258fa5ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr83-rwfm-7r6r/GHSA-jr83-rwfm-7r6r.json +++ b/advisories/unreviewed/2022/05/GHSA-jr83-rwfm-7r6r/GHSA-jr83-rwfm-7r6r.json @@ -7,12 +7,8 @@ "CVE-2019-5861" ], "details": "Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrjm-wgrh-4c93/GHSA-jrjm-wgrh-4c93.json b/advisories/unreviewed/2022/05/GHSA-jrjm-wgrh-4c93/GHSA-jrjm-wgrh-4c93.json index e357e79c105..d3365c84cb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrjm-wgrh-4c93/GHSA-jrjm-wgrh-4c93.json +++ b/advisories/unreviewed/2022/05/GHSA-jrjm-wgrh-4c93/GHSA-jrjm-wgrh-4c93.json @@ -7,12 +7,8 @@ "CVE-2019-18456" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jv99-4g95-6mj4/GHSA-jv99-4g95-6mj4.json b/advisories/unreviewed/2022/05/GHSA-jv99-4g95-6mj4/GHSA-jv99-4g95-6mj4.json index 61eddea75aa..092b81bad5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv99-4g95-6mj4/GHSA-jv99-4g95-6mj4.json +++ b/advisories/unreviewed/2022/05/GHSA-jv99-4g95-6mj4/GHSA-jv99-4g95-6mj4.json @@ -7,12 +7,8 @@ "CVE-2019-2310" ], "details": "Out of bound read would occur while trying to read action category and action ID without validating the action length of the Rx Frame body in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCN7605, QCS605, SDA660, SDA845, SDM450, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM8150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvgf-c7c2-w98p/GHSA-jvgf-c7c2-w98p.json b/advisories/unreviewed/2022/05/GHSA-jvgf-c7c2-w98p/GHSA-jvgf-c7c2-w98p.json index c12454e2d60..6ea3a3a2dc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvgf-c7c2-w98p/GHSA-jvgf-c7c2-w98p.json +++ b/advisories/unreviewed/2022/05/GHSA-jvgf-c7c2-w98p/GHSA-jvgf-c7c2-w98p.json @@ -7,12 +7,8 @@ "CVE-2019-18678" ], "details": "An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwfx-6cm3-63qg/GHSA-jwfx-6cm3-63qg.json b/advisories/unreviewed/2022/05/GHSA-jwfx-6cm3-63qg/GHSA-jwfx-6cm3-63qg.json index 839159a9ed3..554e1ca4531 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwfx-6cm3-63qg/GHSA-jwfx-6cm3-63qg.json +++ b/advisories/unreviewed/2022/05/GHSA-jwfx-6cm3-63qg/GHSA-jwfx-6cm3-63qg.json @@ -7,12 +7,8 @@ "CVE-2019-18448" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx95-62jp-r768/GHSA-jx95-62jp-r768.json b/advisories/unreviewed/2022/05/GHSA-jx95-62jp-r768/GHSA-jx95-62jp-r768.json index ec6d68afa82..068c7f8200a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx95-62jp-r768/GHSA-jx95-62jp-r768.json +++ b/advisories/unreviewed/2022/05/GHSA-jx95-62jp-r768/GHSA-jx95-62jp-r768.json @@ -7,12 +7,8 @@ "CVE-2019-13675" ], "details": "Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable extensions via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jxf7-w6gg-cgmq/GHSA-jxf7-w6gg-cgmq.json b/advisories/unreviewed/2022/05/GHSA-jxf7-w6gg-cgmq/GHSA-jxf7-w6gg-cgmq.json index 516214c985b..b94c3637726 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxf7-w6gg-cgmq/GHSA-jxf7-w6gg-cgmq.json +++ b/advisories/unreviewed/2022/05/GHSA-jxf7-w6gg-cgmq/GHSA-jxf7-w6gg-cgmq.json @@ -7,12 +7,8 @@ "CVE-2019-18312" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to enumerate running RPC services. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxhx-2gqw-c77x/GHSA-jxhx-2gqw-c77x.json b/advisories/unreviewed/2022/05/GHSA-jxhx-2gqw-c77x/GHSA-jxhx-2gqw-c77x.json index f0013e2aafc..cab85d7120c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxhx-2gqw-c77x/GHSA-jxhx-2gqw-c77x.json +++ b/advisories/unreviewed/2022/05/GHSA-jxhx-2gqw-c77x/GHSA-jxhx-2gqw-c77x.json @@ -7,12 +7,8 @@ "CVE-2019-3690" ], "details": "The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxhx-hv9q-4x3w/GHSA-jxhx-hv9q-4x3w.json b/advisories/unreviewed/2022/05/GHSA-jxhx-hv9q-4x3w/GHSA-jxhx-hv9q-4x3w.json index adec38625f1..68b4b95d85a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxhx-hv9q-4x3w/GHSA-jxhx-hv9q-4x3w.json +++ b/advisories/unreviewed/2022/05/GHSA-jxhx-hv9q-4x3w/GHSA-jxhx-hv9q-4x3w.json @@ -7,12 +7,8 @@ "CVE-2006-5232" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in iSearch 2.16 allow remote attackers to execute arbitrary PHP code via a URL in the isearch_path parameter in (1) index.php, (2) viewcache.php, (3) sitemap.php, (4) isearch.inc.php, (5) google_sitemap.php, (6) stats.php, or (7) auto_spider_img.php. NOTE: this issue has been disputed by a third party who shows that $isearch_path is set to a constant value. CVE analysis as of 20061010 is inconclusive, although the original researcher is known to make mistakes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m38r-xwvh-x735/GHSA-m38r-xwvh-x735.json b/advisories/unreviewed/2022/05/GHSA-m38r-xwvh-x735/GHSA-m38r-xwvh-x735.json index 16efb9c971a..2c15769d626 100644 --- a/advisories/unreviewed/2022/05/GHSA-m38r-xwvh-x735/GHSA-m38r-xwvh-x735.json +++ b/advisories/unreviewed/2022/05/GHSA-m38r-xwvh-x735/GHSA-m38r-xwvh-x735.json @@ -7,12 +7,8 @@ "CVE-2019-19248" ], "details": "Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4mr-53v8-pj7x/GHSA-m4mr-53v8-pj7x.json b/advisories/unreviewed/2022/05/GHSA-m4mr-53v8-pj7x/GHSA-m4mr-53v8-pj7x.json index c57420cac9c..86dcefc2279 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4mr-53v8-pj7x/GHSA-m4mr-53v8-pj7x.json +++ b/advisories/unreviewed/2022/05/GHSA-m4mr-53v8-pj7x/GHSA-m4mr-53v8-pj7x.json @@ -7,12 +7,8 @@ "CVE-2019-19638" ], "details": "An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an integer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m5f9-h82w-xx78/GHSA-m5f9-h82w-xx78.json b/advisories/unreviewed/2022/05/GHSA-m5f9-h82w-xx78/GHSA-m5f9-h82w-xx78.json index fb829864d6c..e37fb3f57fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5f9-h82w-xx78/GHSA-m5f9-h82w-xx78.json +++ b/advisories/unreviewed/2022/05/GHSA-m5f9-h82w-xx78/GHSA-m5f9-h82w-xx78.json @@ -7,12 +7,8 @@ "CVE-2019-19543" ], "details": "In the Linux kernel before 5.1.6, there is a use-after-free in serial_ir_init_module() in drivers/media/rc/serial_ir.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7m3-h648-r6cc/GHSA-m7m3-h648-r6cc.json b/advisories/unreviewed/2022/05/GHSA-m7m3-h648-r6cc/GHSA-m7m3-h648-r6cc.json index 69e40c598cd..ff97fb3b400 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7m3-h648-r6cc/GHSA-m7m3-h648-r6cc.json +++ b/advisories/unreviewed/2022/05/GHSA-m7m3-h648-r6cc/GHSA-m7m3-h648-r6cc.json @@ -7,12 +7,8 @@ "CVE-2015-7542" ], "details": "An issue exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m866-3jrq-785c/GHSA-m866-3jrq-785c.json b/advisories/unreviewed/2022/05/GHSA-m866-3jrq-785c/GHSA-m866-3jrq-785c.json index eefff3a10db..6fdd5c31827 100644 --- a/advisories/unreviewed/2022/05/GHSA-m866-3jrq-785c/GHSA-m866-3jrq-785c.json +++ b/advisories/unreviewed/2022/05/GHSA-m866-3jrq-785c/GHSA-m866-3jrq-785c.json @@ -7,12 +7,8 @@ "CVE-2019-19464" ], "details": "The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8pg-mx2h-fq4v/GHSA-m8pg-mx2h-fq4v.json b/advisories/unreviewed/2022/05/GHSA-m8pg-mx2h-fq4v/GHSA-m8pg-mx2h-fq4v.json index 461fbd2a172..efd3e07de8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8pg-mx2h-fq4v/GHSA-m8pg-mx2h-fq4v.json +++ b/advisories/unreviewed/2022/05/GHSA-m8pg-mx2h-fq4v/GHSA-m8pg-mx2h-fq4v.json @@ -7,12 +7,8 @@ "CVE-2006-4428" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary PHP code via a URL in the template parameter. NOTE: CVE disputes this claim, since the $template variable is defined as a static value before it is referenced in an include statement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m9gq-jrj4-fhfv/GHSA-m9gq-jrj4-fhfv.json b/advisories/unreviewed/2022/05/GHSA-m9gq-jrj4-fhfv/GHSA-m9gq-jrj4-fhfv.json index d0eb97684d0..5be683e9d7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9gq-jrj4-fhfv/GHSA-m9gq-jrj4-fhfv.json +++ b/advisories/unreviewed/2022/05/GHSA-m9gq-jrj4-fhfv/GHSA-m9gq-jrj4-fhfv.json @@ -7,12 +7,8 @@ "CVE-2019-19748" ], "details": "The Work Time Calendar app before 4.7.1 for Jira allows XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mcjf-77cw-j8r2/GHSA-mcjf-77cw-j8r2.json b/advisories/unreviewed/2022/05/GHSA-mcjf-77cw-j8r2/GHSA-mcjf-77cw-j8r2.json index c703cf206b6..703079b7401 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcjf-77cw-j8r2/GHSA-mcjf-77cw-j8r2.json +++ b/advisories/unreviewed/2022/05/GHSA-mcjf-77cw-j8r2/GHSA-mcjf-77cw-j8r2.json @@ -7,12 +7,8 @@ "CVE-2019-3666" ], "details": "API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restricted websites via a carefully crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mcx8-p4qf-qr6x/GHSA-mcx8-p4qf-qr6x.json b/advisories/unreviewed/2022/05/GHSA-mcx8-p4qf-qr6x/GHSA-mcx8-p4qf-qr6x.json index 9bfdedc0e2b..b6566d036ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcx8-p4qf-qr6x/GHSA-mcx8-p4qf-qr6x.json +++ b/advisories/unreviewed/2022/05/GHSA-mcx8-p4qf-qr6x/GHSA-mcx8-p4qf-qr6x.json @@ -7,12 +7,8 @@ "CVE-2019-19379" ], "details": "In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mf37-6gxg-hj9q/GHSA-mf37-6gxg-hj9q.json b/advisories/unreviewed/2022/05/GHSA-mf37-6gxg-hj9q/GHSA-mf37-6gxg-hj9q.json index e4f7ac30513..9c12610922b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf37-6gxg-hj9q/GHSA-mf37-6gxg-hj9q.json +++ b/advisories/unreviewed/2022/05/GHSA-mf37-6gxg-hj9q/GHSA-mf37-6gxg-hj9q.json @@ -7,12 +7,8 @@ "CVE-2019-19374" ], "details": "An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can delete arbitrary files from the server during interaction with the File Upload field type, when a custom form exists. (This is related to an information disclosure issue within the File Upload field type that allows users to view the full path to uploaded files, including the product's web root directory.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mf4j-c7rg-8p9r/GHSA-mf4j-c7rg-8p9r.json b/advisories/unreviewed/2022/05/GHSA-mf4j-c7rg-8p9r/GHSA-mf4j-c7rg-8p9r.json index 986c3b73468..b1310d31781 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf4j-c7rg-8p9r/GHSA-mf4j-c7rg-8p9r.json +++ b/advisories/unreviewed/2022/05/GHSA-mf4j-c7rg-8p9r/GHSA-mf4j-c7rg-8p9r.json @@ -7,12 +7,8 @@ "CVE-2019-18251" ], "details": "In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mfxc-mwgf-fr5h/GHSA-mfxc-mwgf-fr5h.json b/advisories/unreviewed/2022/05/GHSA-mfxc-mwgf-fr5h/GHSA-mfxc-mwgf-fr5h.json index a2c3db30463..d40d3015317 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfxc-mwgf-fr5h/GHSA-mfxc-mwgf-fr5h.json +++ b/advisories/unreviewed/2022/05/GHSA-mfxc-mwgf-fr5h/GHSA-mfxc-mwgf-fr5h.json @@ -7,12 +7,8 @@ "CVE-2019-13694" ], "details": "Use after free in WebRTC in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgg3-mrhh-rr8r/GHSA-mgg3-mrhh-rr8r.json b/advisories/unreviewed/2022/05/GHSA-mgg3-mrhh-rr8r/GHSA-mgg3-mrhh-rr8r.json index c8cef522ba2..2b3d0e664e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgg3-mrhh-rr8r/GHSA-mgg3-mrhh-rr8r.json +++ b/advisories/unreviewed/2022/05/GHSA-mgg3-mrhh-rr8r/GHSA-mgg3-mrhh-rr8r.json @@ -7,12 +7,8 @@ "CVE-2019-10571" ], "details": "Snapshot of IB can lead to invalid address access due to missing check for size in the related function in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, Nicobar, QCN7605, QCS405, QCS605, QM215, SA6155P, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150, SM8250, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgvp-4j7j-cjr2/GHSA-mgvp-4j7j-cjr2.json b/advisories/unreviewed/2022/05/GHSA-mgvp-4j7j-cjr2/GHSA-mgvp-4j7j-cjr2.json index bd0bedd0be3..53baba18068 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgvp-4j7j-cjr2/GHSA-mgvp-4j7j-cjr2.json +++ b/advisories/unreviewed/2022/05/GHSA-mgvp-4j7j-cjr2/GHSA-mgvp-4j7j-cjr2.json @@ -7,12 +7,8 @@ "CVE-2006-4677" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in contrib/yabbse/poc.php in phpopenchat before 3.0.2 allows remote attackers to execute arbitrary PHP code via the sourcedir parameter. NOTE: this issue was disputed by a third-party researcher who stated that the _REQUEST parameters were dynamically unset at the beginning of the file. Another researcher noted, and CVE agrees, that the unset PHP function can be bypassed (CVE-2006-3017). If this issue is due to a vulnerability in PHP, then it should be excluded from CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mh77-9rrc-963m/GHSA-mh77-9rrc-963m.json b/advisories/unreviewed/2022/05/GHSA-mh77-9rrc-963m/GHSA-mh77-9rrc-963m.json index caf4b71bfe8..b22d5d9663d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh77-9rrc-963m/GHSA-mh77-9rrc-963m.json +++ b/advisories/unreviewed/2022/05/GHSA-mh77-9rrc-963m/GHSA-mh77-9rrc-963m.json @@ -7,12 +7,8 @@ "CVE-2019-13936" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a persistent XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mj5f-wfm2-8fw6/GHSA-mj5f-wfm2-8fw6.json b/advisories/unreviewed/2022/05/GHSA-mj5f-wfm2-8fw6/GHSA-mj5f-wfm2-8fw6.json index 2dfaf65e45f..76569294792 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj5f-wfm2-8fw6/GHSA-mj5f-wfm2-8fw6.json +++ b/advisories/unreviewed/2022/05/GHSA-mj5f-wfm2-8fw6/GHSA-mj5f-wfm2-8fw6.json @@ -7,12 +7,8 @@ "CVE-2019-13930" ], "details": "A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate user, who must be authenticated to the web interface. A successful attack could allow an attacker to trigger actions via the web interface that the legitimate user is allowed to perform. This could allow the attacker to read or modify contents of the web application. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjcp-8594-qxpc/GHSA-mjcp-8594-qxpc.json b/advisories/unreviewed/2022/05/GHSA-mjcp-8594-qxpc/GHSA-mjcp-8594-qxpc.json index 155a1a9fa5e..23518e0b53d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjcp-8594-qxpc/GHSA-mjcp-8594-qxpc.json +++ b/advisories/unreviewed/2022/05/GHSA-mjcp-8594-qxpc/GHSA-mjcp-8594-qxpc.json @@ -7,12 +7,8 @@ "CVE-2006-4429" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in handlers/email/mod.output.php in PHlyMail Lite 3.4.4 and earlier (Build 3.04.04) allows remote attackers to execute arbitrary PHP code via a URL in the _PM_[path][handler] parameter, a different vector than CVE-2006-4291. NOTE: This issue has been disputed by a third party, who states that the _IN_PHM_ declaration prevents this file from being called directly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm5m-g4fx-pch2/GHSA-mm5m-g4fx-pch2.json b/advisories/unreviewed/2022/05/GHSA-mm5m-g4fx-pch2/GHSA-mm5m-g4fx-pch2.json index 6c640e066ed..3287595402c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm5m-g4fx-pch2/GHSA-mm5m-g4fx-pch2.json +++ b/advisories/unreviewed/2022/05/GHSA-mm5m-g4fx-pch2/GHSA-mm5m-g4fx-pch2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mph2-w5gr-qrv5/GHSA-mph2-w5gr-qrv5.json b/advisories/unreviewed/2022/05/GHSA-mph2-w5gr-qrv5/GHSA-mph2-w5gr-qrv5.json index fb1bac1fc88..00d8a971a23 100644 --- a/advisories/unreviewed/2022/05/GHSA-mph2-w5gr-qrv5/GHSA-mph2-w5gr-qrv5.json +++ b/advisories/unreviewed/2022/05/GHSA-mph2-w5gr-qrv5/GHSA-mph2-w5gr-qrv5.json @@ -7,12 +7,8 @@ "CVE-2019-10592" ], "details": "Possible integer overflow while multiplying two integers of 32 bit in QDCM API of get display modes as there is no check on the maximum mode count in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mpp8-3fhh-c8rg/GHSA-mpp8-3fhh-c8rg.json b/advisories/unreviewed/2022/05/GHSA-mpp8-3fhh-c8rg/GHSA-mpp8-3fhh-c8rg.json index 3033f5e61b0..de8cadebdff 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpp8-3fhh-c8rg/GHSA-mpp8-3fhh-c8rg.json +++ b/advisories/unreviewed/2022/05/GHSA-mpp8-3fhh-c8rg/GHSA-mpp8-3fhh-c8rg.json @@ -7,12 +7,8 @@ "CVE-2005-4161" ], "details": "** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in MilliScripts 1.4 redirect script allow remote attackers to inject arbitrary web script or HTML via the domainname parameter to register.php, and other unspecified vectors. NOTE: the vendor has disputed this issue, stating \"No invalid input can reach the script.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpww-gpm7-w7qg/GHSA-mpww-gpm7-w7qg.json b/advisories/unreviewed/2022/05/GHSA-mpww-gpm7-w7qg/GHSA-mpww-gpm7-w7qg.json index bc1170581e9..8ec815673eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpww-gpm7-w7qg/GHSA-mpww-gpm7-w7qg.json +++ b/advisories/unreviewed/2022/05/GHSA-mpww-gpm7-w7qg/GHSA-mpww-gpm7-w7qg.json @@ -7,12 +7,8 @@ "CVE-2006-0070" ], "details": "** DISPUTED ** Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when \"Filtered HTML\" is enabled, and since \"Full HTML\" would not filter HTML by design, perhaps this should not be included in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mq78-57jv-92wc/GHSA-mq78-57jv-92wc.json b/advisories/unreviewed/2022/05/GHSA-mq78-57jv-92wc/GHSA-mq78-57jv-92wc.json index c81f11aa51c..9ff8b971dc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq78-57jv-92wc/GHSA-mq78-57jv-92wc.json +++ b/advisories/unreviewed/2022/05/GHSA-mq78-57jv-92wc/GHSA-mq78-57jv-92wc.json @@ -7,12 +7,8 @@ "CVE-2019-3665" ], "details": "Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked via a carefully crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mqfh-r3g8-g7vm/GHSA-mqfh-r3g8-g7vm.json b/advisories/unreviewed/2022/05/GHSA-mqfh-r3g8-g7vm/GHSA-mqfh-r3g8-g7vm.json index b96a4eea8d3..a5d2557a104 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqfh-r3g8-g7vm/GHSA-mqfh-r3g8-g7vm.json +++ b/advisories/unreviewed/2022/05/GHSA-mqfh-r3g8-g7vm/GHSA-mqfh-r3g8-g7vm.json @@ -7,12 +7,8 @@ "CVE-2019-3988" ], "details": "Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrp2-f622-9548/GHSA-mrp2-f622-9548.json b/advisories/unreviewed/2022/05/GHSA-mrp2-f622-9548/GHSA-mrp2-f622-9548.json index c9257305780..70cdcd0a928 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrp2-f622-9548/GHSA-mrp2-f622-9548.json +++ b/advisories/unreviewed/2022/05/GHSA-mrp2-f622-9548/GHSA-mrp2-f622-9548.json @@ -7,12 +7,8 @@ "CVE-2005-4159" ], "details": "** DISPUTED ** NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. NOTE: the vendor says that since only one character can be modified, there is no SQL injection. Thus this might be an \"invalid SQL syntax error.\" Multiple followups support the vendor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrq8-9564-r9gh/GHSA-mrq8-9564-r9gh.json b/advisories/unreviewed/2022/05/GHSA-mrq8-9564-r9gh/GHSA-mrq8-9564-r9gh.json index 87a6735408d..99348b571f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrq8-9564-r9gh/GHSA-mrq8-9564-r9gh.json +++ b/advisories/unreviewed/2022/05/GHSA-mrq8-9564-r9gh/GHSA-mrq8-9564-r9gh.json @@ -7,12 +7,8 @@ "CVE-2005-4349" ], "details": "** DISPUTED ** SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, saying that the main task of the program is to support query execution by authenticated users, and no external attack scenario exists without an auto-login configuration. Thus it is likely that this issue will be REJECTED. However, a closely related CSRF issue has been assigned CVE-2005-4450.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv96-qwpc-6552/GHSA-mv96-qwpc-6552.json b/advisories/unreviewed/2022/05/GHSA-mv96-qwpc-6552/GHSA-mv96-qwpc-6552.json index 37795370505..3a50b781484 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv96-qwpc-6552/GHSA-mv96-qwpc-6552.json +++ b/advisories/unreviewed/2022/05/GHSA-mv96-qwpc-6552/GHSA-mv96-qwpc-6552.json @@ -7,12 +7,8 @@ "CVE-2019-19383" ], "details": "freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mvgj-p4wx-27qf/GHSA-mvgj-p4wx-27qf.json b/advisories/unreviewed/2022/05/GHSA-mvgj-p4wx-27qf/GHSA-mvgj-p4wx-27qf.json index 4cce94f50bf..db53344ec6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvgj-p4wx-27qf/GHSA-mvgj-p4wx-27qf.json +++ b/advisories/unreviewed/2022/05/GHSA-mvgj-p4wx-27qf/GHSA-mvgj-p4wx-27qf.json @@ -7,12 +7,8 @@ "CVE-2019-5853" ], "details": "Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mw9v-9fv9-jf3f/GHSA-mw9v-9fv9-jf3f.json b/advisories/unreviewed/2022/05/GHSA-mw9v-9fv9-jf3f/GHSA-mw9v-9fv9-jf3f.json index e68fad9294d..4e97a9bf028 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw9v-9fv9-jf3f/GHSA-mw9v-9fv9-jf3f.json +++ b/advisories/unreviewed/2022/05/GHSA-mw9v-9fv9-jf3f/GHSA-mw9v-9fv9-jf3f.json @@ -7,12 +7,8 @@ "CVE-2019-19579" ], "details": "An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's \"assignable-add\" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these \"alternate\" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation. Only systems where guests are given direct access to physical devices capable of DMA (PCI pass-through) are vulnerable. Systems which do not use PCI pass-through are not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mwgw-gwjh-gp7m/GHSA-mwgw-gwjh-gp7m.json b/advisories/unreviewed/2022/05/GHSA-mwgw-gwjh-gp7m/GHSA-mwgw-gwjh-gp7m.json index 18ead4c3507..5bb27a1cce6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwgw-gwjh-gp7m/GHSA-mwgw-gwjh-gp7m.json +++ b/advisories/unreviewed/2022/05/GHSA-mwgw-gwjh-gp7m/GHSA-mwgw-gwjh-gp7m.json @@ -7,12 +7,8 @@ "CVE-2019-19385" ], "details": "A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mwpm-ch75-7qqj/GHSA-mwpm-ch75-7qqj.json b/advisories/unreviewed/2022/05/GHSA-mwpm-ch75-7qqj/GHSA-mwpm-ch75-7qqj.json index f6c8a6e01a2..772a846dd46 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwpm-ch75-7qqj/GHSA-mwpm-ch75-7qqj.json +++ b/advisories/unreviewed/2022/05/GHSA-mwpm-ch75-7qqj/GHSA-mwpm-ch75-7qqj.json @@ -7,12 +7,8 @@ "CVE-2019-18285" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). The RMI communication between the client and the Application Server is unencrypted. An attacker with access to the communication channel can read credentials of a valid user. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mxmq-cvc6-prfj/GHSA-mxmq-cvc6-prfj.json b/advisories/unreviewed/2022/05/GHSA-mxmq-cvc6-prfj/GHSA-mxmq-cvc6-prfj.json index 6ec29dcb85a..4b8cce58787 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxmq-cvc6-prfj/GHSA-mxmq-cvc6-prfj.json +++ b/advisories/unreviewed/2022/05/GHSA-mxmq-cvc6-prfj/GHSA-mxmq-cvc6-prfj.json @@ -7,12 +7,8 @@ "CVE-2019-13671" ], "details": "UI spoofing in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof security UI via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2xr-m559-3m72/GHSA-p2xr-m559-3m72.json b/advisories/unreviewed/2022/05/GHSA-p2xr-m559-3m72/GHSA-p2xr-m559-3m72.json index 832533f05be..6643d4b7220 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2xr-m559-3m72/GHSA-p2xr-m559-3m72.json +++ b/advisories/unreviewed/2022/05/GHSA-p2xr-m559-3m72/GHSA-p2xr-m559-3m72.json @@ -7,12 +7,8 @@ "CVE-2006-5840" ], "details": "** DISPUTED ** Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php. NOTE: the cat vector is already covered by CVE-2006-2853. NOTE: the vendor has notified CVE that the current version only creates static pages, and that slistl.php/slid never existed in any version.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4rw-m677-p78f/GHSA-p4rw-m677-p78f.json b/advisories/unreviewed/2022/05/GHSA-p4rw-m677-p78f/GHSA-p4rw-m677-p78f.json index ee0d5c96b4d..3144832ec68 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4rw-m677-p78f/GHSA-p4rw-m677-p78f.json +++ b/advisories/unreviewed/2022/05/GHSA-p4rw-m677-p78f/GHSA-p4rw-m677-p78f.json @@ -7,12 +7,8 @@ "CVE-2018-20090" ], "details": "An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p548-j649-rwfp/GHSA-p548-j649-rwfp.json b/advisories/unreviewed/2022/05/GHSA-p548-j649-rwfp/GHSA-p548-j649-rwfp.json index defa6724a22..8d67bb4276c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p548-j649-rwfp/GHSA-p548-j649-rwfp.json +++ b/advisories/unreviewed/2022/05/GHSA-p548-j649-rwfp/GHSA-p548-j649-rwfp.json @@ -7,12 +7,8 @@ "CVE-2019-18241" ], "details": "In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session and gain unauthorized access to the EC40/80 hub.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5cv-767r-2fpm/GHSA-p5cv-767r-2fpm.json b/advisories/unreviewed/2022/05/GHSA-p5cv-767r-2fpm/GHSA-p5cv-767r-2fpm.json index 3401b84e422..3be25aa9cb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5cv-767r-2fpm/GHSA-p5cv-767r-2fpm.json +++ b/advisories/unreviewed/2022/05/GHSA-p5cv-767r-2fpm/GHSA-p5cv-767r-2fpm.json @@ -7,12 +7,8 @@ "CVE-2019-15628" ], "details": "Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allow an attacker to use a specific service as an execution and/or persistence mechanism which could execute a malicious program each time the service is started.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5xv-462h-xq5p/GHSA-p5xv-462h-xq5p.json b/advisories/unreviewed/2022/05/GHSA-p5xv-462h-xq5p/GHSA-p5xv-462h-xq5p.json index 985a33f60a0..3fd2a91a755 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5xv-462h-xq5p/GHSA-p5xv-462h-xq5p.json +++ b/advisories/unreviewed/2022/05/GHSA-p5xv-462h-xq5p/GHSA-p5xv-462h-xq5p.json @@ -7,12 +7,8 @@ "CVE-2017-12945" ], "details": "Insufficient validation of user-supplied input for the Solstice Pod networking configuration enables authenticated attackers to execute arbitrary commands as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p764-xffc-3rx4/GHSA-p764-xffc-3rx4.json b/advisories/unreviewed/2022/05/GHSA-p764-xffc-3rx4/GHSA-p764-xffc-3rx4.json index 43ca586ea55..4bf489ba113 100644 --- a/advisories/unreviewed/2022/05/GHSA-p764-xffc-3rx4/GHSA-p764-xffc-3rx4.json +++ b/advisories/unreviewed/2022/05/GHSA-p764-xffc-3rx4/GHSA-p764-xffc-3rx4.json @@ -7,12 +7,8 @@ "CVE-2019-5877" ], "details": "Out of bounds memory access in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pcm7-87gm-6p9c/GHSA-pcm7-87gm-6p9c.json b/advisories/unreviewed/2022/05/GHSA-pcm7-87gm-6p9c/GHSA-pcm7-87gm-6p9c.json index 051ee55f23d..d769e603bb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcm7-87gm-6p9c/GHSA-pcm7-87gm-6p9c.json +++ b/advisories/unreviewed/2022/05/GHSA-pcm7-87gm-6p9c/GHSA-pcm7-87gm-6p9c.json @@ -7,12 +7,8 @@ "CVE-2019-18323" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18324, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18328, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf85-3hgc-m9ph/GHSA-pf85-3hgc-m9ph.json b/advisories/unreviewed/2022/05/GHSA-pf85-3hgc-m9ph/GHSA-pf85-3hgc-m9ph.json index 82346cf39f0..59e69186771 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf85-3hgc-m9ph/GHSA-pf85-3hgc-m9ph.json +++ b/advisories/unreviewed/2022/05/GHSA-pf85-3hgc-m9ph/GHSA-pf85-3hgc-m9ph.json @@ -7,12 +7,8 @@ "CVE-2019-17087" ], "details": "Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be exploited to enumerate and download files from the filesystem of the system running AcuToWeb, with the privileges of the account AcuToWeb is running under.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pfjf-vfqg-5r4q/GHSA-pfjf-vfqg-5r4q.json b/advisories/unreviewed/2022/05/GHSA-pfjf-vfqg-5r4q/GHSA-pfjf-vfqg-5r4q.json index 98de35be088..975cfe237f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfjf-vfqg-5r4q/GHSA-pfjf-vfqg-5r4q.json +++ b/advisories/unreviewed/2022/05/GHSA-pfjf-vfqg-5r4q/GHSA-pfjf-vfqg-5r4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgmq-fmcf-6fcm/GHSA-pgmq-fmcf-6fcm.json b/advisories/unreviewed/2022/05/GHSA-pgmq-fmcf-6fcm/GHSA-pgmq-fmcf-6fcm.json index 824ab3ba962..5ffa95c06ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgmq-fmcf-6fcm/GHSA-pgmq-fmcf-6fcm.json +++ b/advisories/unreviewed/2022/05/GHSA-pgmq-fmcf-6fcm/GHSA-pgmq-fmcf-6fcm.json @@ -7,12 +7,8 @@ "CVE-2019-18455" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-php4-mj74-f79r/GHSA-php4-mj74-f79r.json b/advisories/unreviewed/2022/05/GHSA-php4-mj74-f79r/GHSA-php4-mj74-f79r.json index f499910451e..2086f733a52 100644 --- a/advisories/unreviewed/2022/05/GHSA-php4-mj74-f79r/GHSA-php4-mj74-f79r.json +++ b/advisories/unreviewed/2022/05/GHSA-php4-mj74-f79r/GHSA-php4-mj74-f79r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjfj-8qjp-8vjv/GHSA-pjfj-8qjp-8vjv.json b/advisories/unreviewed/2022/05/GHSA-pjfj-8qjp-8vjv/GHSA-pjfj-8qjp-8vjv.json index 7c444b312f1..a3b15886c17 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjfj-8qjp-8vjv/GHSA-pjfj-8qjp-8vjv.json +++ b/advisories/unreviewed/2022/05/GHSA-pjfj-8qjp-8vjv/GHSA-pjfj-8qjp-8vjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm2v-2gwc-36m2/GHSA-pm2v-2gwc-36m2.json b/advisories/unreviewed/2022/05/GHSA-pm2v-2gwc-36m2/GHSA-pm2v-2gwc-36m2.json index cb66904e406..bce28492faa 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm2v-2gwc-36m2/GHSA-pm2v-2gwc-36m2.json +++ b/advisories/unreviewed/2022/05/GHSA-pm2v-2gwc-36m2/GHSA-pm2v-2gwc-36m2.json @@ -7,12 +7,8 @@ "CVE-2019-19459" ], "details": "An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pmgx-8jcm-w9ch/GHSA-pmgx-8jcm-w9ch.json b/advisories/unreviewed/2022/05/GHSA-pmgx-8jcm-w9ch/GHSA-pmgx-8jcm-w9ch.json index 10e160437de..d14cb6bf9e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmgx-8jcm-w9ch/GHSA-pmgx-8jcm-w9ch.json +++ b/advisories/unreviewed/2022/05/GHSA-pmgx-8jcm-w9ch/GHSA-pmgx-8jcm-w9ch.json @@ -7,12 +7,8 @@ "CVE-2019-5866" ], "details": "Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqpq-74m3-r29f/GHSA-pqpq-74m3-r29f.json b/advisories/unreviewed/2022/05/GHSA-pqpq-74m3-r29f/GHSA-pqpq-74m3-r29f.json index c443cb124f5..0131c737825 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqpq-74m3-r29f/GHSA-pqpq-74m3-r29f.json +++ b/advisories/unreviewed/2022/05/GHSA-pqpq-74m3-r29f/GHSA-pqpq-74m3-r29f.json @@ -7,12 +7,8 @@ "CVE-2006-5776" ], "details": "** DISPUTED ** Multiple PHP remote file inclusions in Ariadne 2.4.1 allows remote attackers to execute arbitrary PHP code via the ariadne parameter in (1) ftp/loader.php and (2) lib/includes/loader.cmd.php. NOTE: this issue is disputed by CVE, since installation instructions recommend that the files be placed outside of the web document root and require the administrator to modify $ariadne in an include file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqxf-356j-9cf5/GHSA-pqxf-356j-9cf5.json b/advisories/unreviewed/2022/05/GHSA-pqxf-356j-9cf5/GHSA-pqxf-356j-9cf5.json index 50346b158ad..e241f581c04 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqxf-356j-9cf5/GHSA-pqxf-356j-9cf5.json +++ b/advisories/unreviewed/2022/05/GHSA-pqxf-356j-9cf5/GHSA-pqxf-356j-9cf5.json @@ -7,12 +7,8 @@ "CVE-2019-2227" ], "details": "In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-140768453", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pv86-pp92-5j64/GHSA-pv86-pp92-5j64.json b/advisories/unreviewed/2022/05/GHSA-pv86-pp92-5j64/GHSA-pv86-pp92-5j64.json index 7f3dd879c6f..df7e301295b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv86-pp92-5j64/GHSA-pv86-pp92-5j64.json +++ b/advisories/unreviewed/2022/05/GHSA-pv86-pp92-5j64/GHSA-pv86-pp92-5j64.json @@ -7,12 +7,8 @@ "CVE-2019-5878" ], "details": "Use after free in V8 in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q288-gx5w-rvx3/GHSA-q288-gx5w-rvx3.json b/advisories/unreviewed/2022/05/GHSA-q288-gx5w-rvx3/GHSA-q288-gx5w-rvx3.json index 1e0363fd70c..3fc631836c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q288-gx5w-rvx3/GHSA-q288-gx5w-rvx3.json +++ b/advisories/unreviewed/2022/05/GHSA-q288-gx5w-rvx3/GHSA-q288-gx5w-rvx3.json @@ -7,12 +7,8 @@ "CVE-2019-12489" ], "details": "An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a command between two & characters in the mount parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q48v-f889-vqw2/GHSA-q48v-f889-vqw2.json b/advisories/unreviewed/2022/05/GHSA-q48v-f889-vqw2/GHSA-q48v-f889-vqw2.json index 01e7b1be2e3..315654ec593 100644 --- a/advisories/unreviewed/2022/05/GHSA-q48v-f889-vqw2/GHSA-q48v-f889-vqw2.json +++ b/advisories/unreviewed/2022/05/GHSA-q48v-f889-vqw2/GHSA-q48v-f889-vqw2.json @@ -7,12 +7,8 @@ "CVE-2019-5868" ], "details": "Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q57j-mjmf-2rf4/GHSA-q57j-mjmf-2rf4.json b/advisories/unreviewed/2022/05/GHSA-q57j-mjmf-2rf4/GHSA-q57j-mjmf-2rf4.json index ed76994d9c7..a5841d62481 100644 --- a/advisories/unreviewed/2022/05/GHSA-q57j-mjmf-2rf4/GHSA-q57j-mjmf-2rf4.json +++ b/advisories/unreviewed/2022/05/GHSA-q57j-mjmf-2rf4/GHSA-q57j-mjmf-2rf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7x9-263m-286c/GHSA-q7x9-263m-286c.json b/advisories/unreviewed/2022/05/GHSA-q7x9-263m-286c/GHSA-q7x9-263m-286c.json index 61f36a4b040..d01fb54fb3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7x9-263m-286c/GHSA-q7x9-263m-286c.json +++ b/advisories/unreviewed/2022/05/GHSA-q7x9-263m-286c/GHSA-q7x9-263m-286c.json @@ -7,12 +7,8 @@ "CVE-2019-4098" ], "details": "IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158020.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q8p3-h862-x3xv/GHSA-q8p3-h862-x3xv.json b/advisories/unreviewed/2022/05/GHSA-q8p3-h862-x3xv/GHSA-q8p3-h862-x3xv.json index 165edd40b9f..aa81342db1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8p3-h862-x3xv/GHSA-q8p3-h862-x3xv.json +++ b/advisories/unreviewed/2022/05/GHSA-q8p3-h862-x3xv/GHSA-q8p3-h862-x3xv.json @@ -7,12 +7,8 @@ "CVE-2019-13713" ], "details": "Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q96p-5qxq-68c4/GHSA-q96p-5qxq-68c4.json b/advisories/unreviewed/2022/05/GHSA-q96p-5qxq-68c4/GHSA-q96p-5qxq-68c4.json index e98ae6b0a21..fd205e1f01e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q96p-5qxq-68c4/GHSA-q96p-5qxq-68c4.json +++ b/advisories/unreviewed/2022/05/GHSA-q96p-5qxq-68c4/GHSA-q96p-5qxq-68c4.json @@ -7,12 +7,8 @@ "CVE-2019-13680" ], "details": "Inappropriate implementation in TLS in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof client IP address to websites via crafted TLS connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q98m-jc54-9j83/GHSA-q98m-jc54-9j83.json b/advisories/unreviewed/2022/05/GHSA-q98m-jc54-9j83/GHSA-q98m-jc54-9j83.json index b3e40455e42..e7fcdb260ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-q98m-jc54-9j83/GHSA-q98m-jc54-9j83.json +++ b/advisories/unreviewed/2022/05/GHSA-q98m-jc54-9j83/GHSA-q98m-jc54-9j83.json @@ -7,12 +7,8 @@ "CVE-2005-3981" ], "details": "** DISPUTED ** NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcx8-9vm4-9g3r/GHSA-qcx8-9vm4-9g3r.json b/advisories/unreviewed/2022/05/GHSA-qcx8-9vm4-9g3r/GHSA-qcx8-9vm4-9g3r.json index b9b81a39f48..4da65c27773 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcx8-9vm4-9g3r/GHSA-qcx8-9vm4-9g3r.json +++ b/advisories/unreviewed/2022/05/GHSA-qcx8-9vm4-9g3r/GHSA-qcx8-9vm4-9g3r.json @@ -7,12 +7,8 @@ "CVE-2019-19307" ], "details": "An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by sending a crafted MQTT protocol packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qf37-j9hx-38gx/GHSA-qf37-j9hx-38gx.json b/advisories/unreviewed/2022/05/GHSA-qf37-j9hx-38gx/GHSA-qf37-j9hx-38gx.json index 7e854a122d0..a850d596319 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf37-j9hx-38gx/GHSA-qf37-j9hx-38gx.json +++ b/advisories/unreviewed/2022/05/GHSA-qf37-j9hx-38gx/GHSA-qf37-j9hx-38gx.json @@ -7,12 +7,8 @@ "CVE-2019-2221" ], "details": "In hasActivityInVisibleTask of WindowProcessController.java there?s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138583650", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg5g-43r3-8gpr/GHSA-qg5g-43r3-8gpr.json b/advisories/unreviewed/2022/05/GHSA-qg5g-43r3-8gpr/GHSA-qg5g-43r3-8gpr.json index 0a3be73c8f2..27dcbfd3a39 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg5g-43r3-8gpr/GHSA-qg5g-43r3-8gpr.json +++ b/advisories/unreviewed/2022/05/GHSA-qg5g-43r3-8gpr/GHSA-qg5g-43r3-8gpr.json @@ -7,12 +7,8 @@ "CVE-2019-16241" ], "details": "On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the /data/local/tmp/ directory. The System application that implements the lock screen checks for the existence of a specific file and disables PIN authentication if it exists. This file would typically be created via Android Debug Bridge (adb) over USB.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmqm-hvm5-wx4p/GHSA-qmqm-hvm5-wx4p.json b/advisories/unreviewed/2022/05/GHSA-qmqm-hvm5-wx4p/GHSA-qmqm-hvm5-wx4p.json index 492cc71a109..d47b9a6b506 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmqm-hvm5-wx4p/GHSA-qmqm-hvm5-wx4p.json +++ b/advisories/unreviewed/2022/05/GHSA-qmqm-hvm5-wx4p/GHSA-qmqm-hvm5-wx4p.json @@ -7,12 +7,8 @@ "CVE-2019-19373" ], "details": "An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during processing of a Remote Content page type. This unserialization can be used to trigger the inclusion of arbitrary files on the filesystem (local file inclusion), and results in remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qp47-5phq-m7xm/GHSA-qp47-5phq-m7xm.json b/advisories/unreviewed/2022/05/GHSA-qp47-5phq-m7xm/GHSA-qp47-5phq-m7xm.json index 66839b64526..630f8dcee52 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp47-5phq-m7xm/GHSA-qp47-5phq-m7xm.json +++ b/advisories/unreviewed/2022/05/GHSA-qp47-5phq-m7xm/GHSA-qp47-5phq-m7xm.json @@ -7,12 +7,8 @@ "CVE-2019-11940" ], "details": "In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Proxygen from v0.29.0 until v2017.04.03.00.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qp5r-cxv5-wrq8/GHSA-qp5r-cxv5-wrq8.json b/advisories/unreviewed/2022/05/GHSA-qp5r-cxv5-wrq8/GHSA-qp5r-cxv5-wrq8.json index d86d0b58795..07035e700b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp5r-cxv5-wrq8/GHSA-qp5r-cxv5-wrq8.json +++ b/advisories/unreviewed/2022/05/GHSA-qp5r-cxv5-wrq8/GHSA-qp5r-cxv5-wrq8.json @@ -7,12 +7,8 @@ "CVE-2019-2229" ], "details": "In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139803872", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpqv-23g8-wmfg/GHSA-qpqv-23g8-wmfg.json b/advisories/unreviewed/2022/05/GHSA-qpqv-23g8-wmfg/GHSA-qpqv-23g8-wmfg.json index 906a45a3e7e..bd55423d197 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpqv-23g8-wmfg/GHSA-qpqv-23g8-wmfg.json +++ b/advisories/unreviewed/2022/05/GHSA-qpqv-23g8-wmfg/GHSA-qpqv-23g8-wmfg.json @@ -7,12 +7,8 @@ "CVE-2006-4556" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in index.php in the JIM component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: another researcher has stated that the product distribution does not include an index.php file. Also, this might be related to CVE-2006-4242.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqw6-6jqg-6w44/GHSA-qqw6-6jqg-6w44.json b/advisories/unreviewed/2022/05/GHSA-qqw6-6jqg-6w44/GHSA-qqw6-6jqg-6w44.json index 05ea4ba028c..e01c26df182 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqw6-6jqg-6w44/GHSA-qqw6-6jqg-6w44.json +++ b/advisories/unreviewed/2022/05/GHSA-qqw6-6jqg-6w44/GHSA-qqw6-6jqg-6w44.json @@ -7,12 +7,8 @@ "CVE-2019-19396" ], "details": "illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qr6w-xx8m-93mv/GHSA-qr6w-xx8m-93mv.json b/advisories/unreviewed/2022/05/GHSA-qr6w-xx8m-93mv/GHSA-qr6w-xx8m-93mv.json index 2d10a37f425..aeae96dc116 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr6w-xx8m-93mv/GHSA-qr6w-xx8m-93mv.json +++ b/advisories/unreviewed/2022/05/GHSA-qr6w-xx8m-93mv/GHSA-qr6w-xx8m-93mv.json @@ -7,12 +7,8 @@ "CVE-2019-5227" ], "details": "P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrmf-fv3g-9879/GHSA-qrmf-fv3g-9879.json b/advisories/unreviewed/2022/05/GHSA-qrmf-fv3g-9879/GHSA-qrmf-fv3g-9879.json index 23d8220dd17..69b555536af 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrmf-fv3g-9879/GHSA-qrmf-fv3g-9879.json +++ b/advisories/unreviewed/2022/05/GHSA-qrmf-fv3g-9879/GHSA-qrmf-fv3g-9879.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrpg-pg76-xv44/GHSA-qrpg-pg76-xv44.json b/advisories/unreviewed/2022/05/GHSA-qrpg-pg76-xv44/GHSA-qrpg-pg76-xv44.json index ee862b9cc4e..506fe5fe25c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrpg-pg76-xv44/GHSA-qrpg-pg76-xv44.json +++ b/advisories/unreviewed/2022/05/GHSA-qrpg-pg76-xv44/GHSA-qrpg-pg76-xv44.json @@ -7,12 +7,8 @@ "CVE-2019-15971" ], "details": "A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file types. An attacker could exploit this vulnerability by sending a crafted MP3 file through the targeted device. A successful exploit could allow the attacker to bypass configured content filters that would normally drop the email.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qwvf-9vg7-643x/GHSA-qwvf-9vg7-643x.json b/advisories/unreviewed/2022/05/GHSA-qwvf-9vg7-643x/GHSA-qwvf-9vg7-643x.json index ae0d1b1b768..f511df73e73 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwvf-9vg7-643x/GHSA-qwvf-9vg7-643x.json +++ b/advisories/unreviewed/2022/05/GHSA-qwvf-9vg7-643x/GHSA-qwvf-9vg7-643x.json @@ -7,12 +7,8 @@ "CVE-2019-13456" ], "details": "In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qx89-46x3-pwhf/GHSA-qx89-46x3-pwhf.json b/advisories/unreviewed/2022/05/GHSA-qx89-46x3-pwhf/GHSA-qx89-46x3-pwhf.json index ef0b871ebc3..a43e4c05395 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx89-46x3-pwhf/GHSA-qx89-46x3-pwhf.json +++ b/advisories/unreviewed/2022/05/GHSA-qx89-46x3-pwhf/GHSA-qx89-46x3-pwhf.json @@ -7,12 +7,8 @@ "CVE-2019-18314" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted objects via RMI. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxjv-whw7-vp66/GHSA-qxjv-whw7-vp66.json b/advisories/unreviewed/2022/05/GHSA-qxjv-whw7-vp66/GHSA-qxjv-whw7-vp66.json index 180138a697e..68dde4cbba1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxjv-whw7-vp66/GHSA-qxjv-whw7-vp66.json +++ b/advisories/unreviewed/2022/05/GHSA-qxjv-whw7-vp66/GHSA-qxjv-whw7-vp66.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r233-x568-m7xw/GHSA-r233-x568-m7xw.json b/advisories/unreviewed/2022/05/GHSA-r233-x568-m7xw/GHSA-r233-x568-m7xw.json index 7f617305ab0..0d2bd714d6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r233-x568-m7xw/GHSA-r233-x568-m7xw.json +++ b/advisories/unreviewed/2022/05/GHSA-r233-x568-m7xw/GHSA-r233-x568-m7xw.json @@ -7,12 +7,8 @@ "CVE-2019-2225" ], "details": "When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the user, and that device may be able to interact with the phone. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-110433804", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r33p-vh3m-6j34/GHSA-r33p-vh3m-6j34.json b/advisories/unreviewed/2022/05/GHSA-r33p-vh3m-6j34/GHSA-r33p-vh3m-6j34.json index 7b89e88c734..cb0e0c6630b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r33p-vh3m-6j34/GHSA-r33p-vh3m-6j34.json +++ b/advisories/unreviewed/2022/05/GHSA-r33p-vh3m-6j34/GHSA-r33p-vh3m-6j34.json @@ -7,12 +7,8 @@ "CVE-2019-12389" ], "details": "Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r3hc-822r-fr95/GHSA-r3hc-822r-fr95.json b/advisories/unreviewed/2022/05/GHSA-r3hc-822r-fr95/GHSA-r3hc-822r-fr95.json index 2d1b1a5ffff..d04fdc6abdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3hc-822r-fr95/GHSA-r3hc-822r-fr95.json +++ b/advisories/unreviewed/2022/05/GHSA-r3hc-822r-fr95/GHSA-r3hc-822r-fr95.json @@ -7,12 +7,8 @@ "CVE-2019-19594" ], "details": "reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r4gx-x67v-jqmv/GHSA-r4gx-x67v-jqmv.json b/advisories/unreviewed/2022/05/GHSA-r4gx-x67v-jqmv/GHSA-r4gx-x67v-jqmv.json index fffd07d4a3d..5953b978ccd 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4gx-x67v-jqmv/GHSA-r4gx-x67v-jqmv.json +++ b/advisories/unreviewed/2022/05/GHSA-r4gx-x67v-jqmv/GHSA-r4gx-x67v-jqmv.json @@ -7,12 +7,8 @@ "CVE-2019-19386" ], "details": "A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r4mf-29c6-hhqm/GHSA-r4mf-29c6-hhqm.json b/advisories/unreviewed/2022/05/GHSA-r4mf-29c6-hhqm/GHSA-r4mf-29c6-hhqm.json index 18c095406d0..0940d0d0ba7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4mf-29c6-hhqm/GHSA-r4mf-29c6-hhqm.json +++ b/advisories/unreviewed/2022/05/GHSA-r4mf-29c6-hhqm/GHSA-r4mf-29c6-hhqm.json @@ -7,12 +7,8 @@ "CVE-2019-18378" ], "details": "Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r8vj-8v78-62h8/GHSA-r8vj-8v78-62h8.json b/advisories/unreviewed/2022/05/GHSA-r8vj-8v78-62h8/GHSA-r8vj-8v78-62h8.json index f2775765d60..6b75ec4f65c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8vj-8v78-62h8/GHSA-r8vj-8v78-62h8.json +++ b/advisories/unreviewed/2022/05/GHSA-r8vj-8v78-62h8/GHSA-r8vj-8v78-62h8.json @@ -7,12 +7,8 @@ "CVE-2019-4663" ], "details": "IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r93h-8m5r-m5qw/GHSA-r93h-8m5r-m5qw.json b/advisories/unreviewed/2022/05/GHSA-r93h-8m5r-m5qw/GHSA-r93h-8m5r-m5qw.json index e0cd7206686..fcbba56219c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r93h-8m5r-m5qw/GHSA-r93h-8m5r-m5qw.json +++ b/advisories/unreviewed/2022/05/GHSA-r93h-8m5r-m5qw/GHSA-r93h-8m5r-m5qw.json @@ -7,12 +7,8 @@ "CVE-2019-18380" ], "details": "Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9vc-pgpj-x6f4/GHSA-r9vc-pgpj-x6f4.json b/advisories/unreviewed/2022/05/GHSA-r9vc-pgpj-x6f4/GHSA-r9vc-pgpj-x6f4.json index 6bf536bcdab..c8b678db145 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9vc-pgpj-x6f4/GHSA-r9vc-pgpj-x6f4.json +++ b/advisories/unreviewed/2022/05/GHSA-r9vc-pgpj-x6f4/GHSA-r9vc-pgpj-x6f4.json @@ -7,12 +7,8 @@ "CVE-2019-12388" ], "details": "Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when replying to query on port tcp/5010.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9vr-wvw6-c8v5/GHSA-r9vr-wvw6-c8v5.json b/advisories/unreviewed/2022/05/GHSA-r9vr-wvw6-c8v5/GHSA-r9vr-wvw6-c8v5.json index 07af2a299e1..926c105033f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9vr-wvw6-c8v5/GHSA-r9vr-wvw6-c8v5.json +++ b/advisories/unreviewed/2022/05/GHSA-r9vr-wvw6-c8v5/GHSA-r9vr-wvw6-c8v5.json @@ -7,12 +7,8 @@ "CVE-2019-19496" ], "details": "Alfresco Enterprise 5.2.4 allows stored XSS via an uploaded HTML document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rc37-w42j-7p74/GHSA-rc37-w42j-7p74.json b/advisories/unreviewed/2022/05/GHSA-rc37-w42j-7p74/GHSA-rc37-w42j-7p74.json index 3d4e96d3fae..8516cda3429 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc37-w42j-7p74/GHSA-rc37-w42j-7p74.json +++ b/advisories/unreviewed/2022/05/GHSA-rc37-w42j-7p74/GHSA-rc37-w42j-7p74.json @@ -7,12 +7,8 @@ "CVE-2019-19376" ], "details": "In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input validation and causes an application level denial of service condition. (The fix for this was also backported to LTS 2019.9.8 and LTS 2019.6.14.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rc3c-4c69-rjx6/GHSA-rc3c-4c69-rjx6.json b/advisories/unreviewed/2022/05/GHSA-rc3c-4c69-rjx6/GHSA-rc3c-4c69-rjx6.json index 4d98b06377c..1aeea2e3913 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc3c-4c69-rjx6/GHSA-rc3c-4c69-rjx6.json +++ b/advisories/unreviewed/2022/05/GHSA-rc3c-4c69-rjx6/GHSA-rc3c-4c69-rjx6.json @@ -7,12 +7,8 @@ "CVE-2006-3040" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in talkbox.php in Amr Talkbox allows remote attackers to execute arbitrary PHP code via a URL in the direct parameter. NOTE: this issue has been disputed by CVE, since the $direct variable is set to a static value just before the include statement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcm9-p88f-cmqm/GHSA-rcm9-p88f-cmqm.json b/advisories/unreviewed/2022/05/GHSA-rcm9-p88f-cmqm/GHSA-rcm9-p88f-cmqm.json index f1c72c4a9b4..34f69178bda 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcm9-p88f-cmqm/GHSA-rcm9-p88f-cmqm.json +++ b/advisories/unreviewed/2022/05/GHSA-rcm9-p88f-cmqm/GHSA-rcm9-p88f-cmqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcmf-fgmg-6243/GHSA-rcmf-fgmg-6243.json b/advisories/unreviewed/2022/05/GHSA-rcmf-fgmg-6243/GHSA-rcmf-fgmg-6243.json index 2cca3b34ffc..b0e80285a38 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcmf-fgmg-6243/GHSA-rcmf-fgmg-6243.json +++ b/advisories/unreviewed/2022/05/GHSA-rcmf-fgmg-6243/GHSA-rcmf-fgmg-6243.json @@ -7,12 +7,8 @@ "CVE-2019-19021" ], "details": "An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcrf-wp3c-5926/GHSA-rcrf-wp3c-5926.json b/advisories/unreviewed/2022/05/GHSA-rcrf-wp3c-5926/GHSA-rcrf-wp3c-5926.json index 48297900aff..132a637c44f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcrf-wp3c-5926/GHSA-rcrf-wp3c-5926.json +++ b/advisories/unreviewed/2022/05/GHSA-rcrf-wp3c-5926/GHSA-rcrf-wp3c-5926.json @@ -7,12 +7,8 @@ "CVE-2019-2224" ], "details": "In ReadMATImage of mat.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process when loading a MATLAB image file with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140328986", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rffr-3rx2-ffxx/GHSA-rffr-3rx2-ffxx.json b/advisories/unreviewed/2022/05/GHSA-rffr-3rx2-ffxx/GHSA-rffr-3rx2-ffxx.json index 20063b05c86..e9ac072a0a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rffr-3rx2-ffxx/GHSA-rffr-3rx2-ffxx.json +++ b/advisories/unreviewed/2022/05/GHSA-rffr-3rx2-ffxx/GHSA-rffr-3rx2-ffxx.json @@ -7,12 +7,8 @@ "CVE-2019-18302" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfmc-3x99-f7mh/GHSA-rfmc-3x99-f7mh.json b/advisories/unreviewed/2022/05/GHSA-rfmc-3x99-f7mh/GHSA-rfmc-3x99-f7mh.json index cfd9c026d80..b97cbb1b0c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfmc-3x99-f7mh/GHSA-rfmc-3x99-f7mh.json +++ b/advisories/unreviewed/2022/05/GHSA-rfmc-3x99-f7mh/GHSA-rfmc-3x99-f7mh.json @@ -7,12 +7,8 @@ "CVE-2019-18286" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). The Application Server exposes directory listings and files containing sensitive information. This vulnerability is independent from CVE-2019-18287. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgxm-j5wc-86wx/GHSA-rgxm-j5wc-86wx.json b/advisories/unreviewed/2022/05/GHSA-rgxm-j5wc-86wx/GHSA-rgxm-j5wc-86wx.json index d6ba18fde15..212d2d6bffc 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgxm-j5wc-86wx/GHSA-rgxm-j5wc-86wx.json +++ b/advisories/unreviewed/2022/05/GHSA-rgxm-j5wc-86wx/GHSA-rgxm-j5wc-86wx.json @@ -7,12 +7,8 @@ "CVE-2019-6666" ], "details": "On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may produce a core file when an upstream server or cache sends the BIG-IP an invalid age header value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rhmf-xrpg-5wj8/GHSA-rhmf-xrpg-5wj8.json b/advisories/unreviewed/2022/05/GHSA-rhmf-xrpg-5wj8/GHSA-rhmf-xrpg-5wj8.json index a4369b7a757..c718449c2d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhmf-xrpg-5wj8/GHSA-rhmf-xrpg-5wj8.json +++ b/advisories/unreviewed/2022/05/GHSA-rhmf-xrpg-5wj8/GHSA-rhmf-xrpg-5wj8.json @@ -7,12 +7,8 @@ "CVE-2019-13688" ], "details": "Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjwh-c5gm-2fm3/GHSA-rjwh-c5gm-2fm3.json b/advisories/unreviewed/2022/05/GHSA-rjwh-c5gm-2fm3/GHSA-rjwh-c5gm-2fm3.json index e1d7e4dd450..807fdd00d8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjwh-c5gm-2fm3/GHSA-rjwh-c5gm-2fm3.json +++ b/advisories/unreviewed/2022/05/GHSA-rjwh-c5gm-2fm3/GHSA-rjwh-c5gm-2fm3.json @@ -7,12 +7,8 @@ "CVE-2019-5247" ], "details": "Huawei Atlas 300, Atlas 500 have a buffer overflow vulnerability. A local, authenticated attacker may craft specific parameter and send to the process to exploit this vulnerability. Successfully exploit may cause service crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rm7j-f2x3-cwg3/GHSA-rm7j-f2x3-cwg3.json b/advisories/unreviewed/2022/05/GHSA-rm7j-f2x3-cwg3/GHSA-rm7j-f2x3-cwg3.json index 4c056952fbc..a646ac10c15 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm7j-f2x3-cwg3/GHSA-rm7j-f2x3-cwg3.json +++ b/advisories/unreviewed/2022/05/GHSA-rm7j-f2x3-cwg3/GHSA-rm7j-f2x3-cwg3.json @@ -7,12 +7,8 @@ "CVE-2015-0841" ], "details": "Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rmfw-qmvr-x823/GHSA-rmfw-qmvr-x823.json b/advisories/unreviewed/2022/05/GHSA-rmfw-qmvr-x823/GHSA-rmfw-qmvr-x823.json index 5fe902de750..e15cc8edef8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmfw-qmvr-x823/GHSA-rmfw-qmvr-x823.json +++ b/advisories/unreviewed/2022/05/GHSA-rmfw-qmvr-x823/GHSA-rmfw-qmvr-x823.json @@ -7,12 +7,8 @@ "CVE-2019-19479" ], "details": "An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmmv-j9x6-f2v4/GHSA-rmmv-j9x6-f2v4.json b/advisories/unreviewed/2022/05/GHSA-rmmv-j9x6-f2v4/GHSA-rmmv-j9x6-f2v4.json index 718d964889f..551fe3a9014 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmmv-j9x6-f2v4/GHSA-rmmv-j9x6-f2v4.json +++ b/advisories/unreviewed/2022/05/GHSA-rmmv-j9x6-f2v4/GHSA-rmmv-j9x6-f2v4.json @@ -7,12 +7,8 @@ "CVE-2019-14812" ], "details": "A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rpw6-pjfj-6x6g/GHSA-rpw6-pjfj-6x6g.json b/advisories/unreviewed/2022/05/GHSA-rpw6-pjfj-6x6g/GHSA-rpw6-pjfj-6x6g.json index aaf409a2fe6..f7930572cd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpw6-pjfj-6x6g/GHSA-rpw6-pjfj-6x6g.json +++ b/advisories/unreviewed/2022/05/GHSA-rpw6-pjfj-6x6g/GHSA-rpw6-pjfj-6x6g.json @@ -7,12 +7,8 @@ "CVE-2019-16752" ], "details": "An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user privacy, since it can possibly leak their IP address and the fact that they are using the product. This also affects Dash Core through 0.14.0.3 and Private Instant Verified Transactions (PIVX) through 3.4.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rqc4-5489-hg7v/GHSA-rqc4-5489-hg7v.json b/advisories/unreviewed/2022/05/GHSA-rqc4-5489-hg7v/GHSA-rqc4-5489-hg7v.json index f0a165e0a74..93b97891bd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqc4-5489-hg7v/GHSA-rqc4-5489-hg7v.json +++ b/advisories/unreviewed/2022/05/GHSA-rqc4-5489-hg7v/GHSA-rqc4-5489-hg7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rqw3-7f5v-7r6j/GHSA-rqw3-7f5v-7r6j.json b/advisories/unreviewed/2022/05/GHSA-rqw3-7f5v-7r6j/GHSA-rqw3-7f5v-7r6j.json index 6553dd3848f..31ec9370a4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqw3-7f5v-7r6j/GHSA-rqw3-7f5v-7r6j.json +++ b/advisories/unreviewed/2022/05/GHSA-rqw3-7f5v-7r6j/GHSA-rqw3-7f5v-7r6j.json @@ -7,12 +7,8 @@ "CVE-2019-5864" ], "details": "Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrwp-p45h-xvj8/GHSA-rrwp-p45h-xvj8.json b/advisories/unreviewed/2022/05/GHSA-rrwp-p45h-xvj8/GHSA-rrwp-p45h-xvj8.json index 483d31aa0a2..4cef0a51191 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrwp-p45h-xvj8/GHSA-rrwp-p45h-xvj8.json +++ b/advisories/unreviewed/2022/05/GHSA-rrwp-p45h-xvj8/GHSA-rrwp-p45h-xvj8.json @@ -7,12 +7,8 @@ "CVE-2019-19272" ], "details": "An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrx7-84fw-cxr2/GHSA-rrx7-84fw-cxr2.json b/advisories/unreviewed/2022/05/GHSA-rrx7-84fw-cxr2/GHSA-rrx7-84fw-cxr2.json index 001b6a93347..3399f9cbb00 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrx7-84fw-cxr2/GHSA-rrx7-84fw-cxr2.json +++ b/advisories/unreviewed/2022/05/GHSA-rrx7-84fw-cxr2/GHSA-rrx7-84fw-cxr2.json @@ -7,12 +7,8 @@ "CVE-2019-19795" ], "details": "samurai 0.7 has a heap-based buffer overflow in canonpath in util.c via a crafted build file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rv55-v2mj-w9hg/GHSA-rv55-v2mj-w9hg.json b/advisories/unreviewed/2022/05/GHSA-rv55-v2mj-w9hg/GHSA-rv55-v2mj-w9hg.json index ec619ea2e8a..7c3081f7311 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv55-v2mj-w9hg/GHSA-rv55-v2mj-w9hg.json +++ b/advisories/unreviewed/2022/05/GHSA-rv55-v2mj-w9hg/GHSA-rv55-v2mj-w9hg.json @@ -7,12 +7,8 @@ "CVE-2019-13669" ], "details": "Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwpv-9hw4-gq63/GHSA-rwpv-9hw4-gq63.json b/advisories/unreviewed/2022/05/GHSA-rwpv-9hw4-gq63/GHSA-rwpv-9hw4-gq63.json index 6cbad01c0a7..d525af0dd2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwpv-9hw4-gq63/GHSA-rwpv-9hw4-gq63.json +++ b/advisories/unreviewed/2022/05/GHSA-rwpv-9hw4-gq63/GHSA-rwpv-9hw4-gq63.json @@ -7,12 +7,8 @@ "CVE-2019-18320" ], "details": "A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could be able to upload arbitrary files without authentication. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx4q-5jwm-r64w/GHSA-rx4q-5jwm-r64w.json b/advisories/unreviewed/2022/05/GHSA-rx4q-5jwm-r64w/GHSA-rx4q-5jwm-r64w.json index 3115871e492..88ddf74461b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx4q-5jwm-r64w/GHSA-rx4q-5jwm-r64w.json +++ b/advisories/unreviewed/2022/05/GHSA-rx4q-5jwm-r64w/GHSA-rx4q-5jwm-r64w.json @@ -7,12 +7,8 @@ "CVE-2019-18184" ], "details": "Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxc8-x669-7284/GHSA-rxc8-x669-7284.json b/advisories/unreviewed/2022/05/GHSA-rxc8-x669-7284/GHSA-rxc8-x669-7284.json index d45656046df..46c575c87a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxc8-x669-7284/GHSA-rxc8-x669-7284.json +++ b/advisories/unreviewed/2022/05/GHSA-rxc8-x669-7284/GHSA-rxc8-x669-7284.json @@ -7,12 +7,8 @@ "CVE-2019-19620" ], "details": "In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\\SYSTEM permissions from a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rxf3-275x-fff6/GHSA-rxf3-275x-fff6.json b/advisories/unreviewed/2022/05/GHSA-rxf3-275x-fff6/GHSA-rxf3-275x-fff6.json index 88403db49c1..604a447c2ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxf3-275x-fff6/GHSA-rxf3-275x-fff6.json +++ b/advisories/unreviewed/2022/05/GHSA-rxf3-275x-fff6/GHSA-rxf3-275x-fff6.json @@ -7,12 +7,8 @@ "CVE-2019-19532" ], "details": "In the Linux kernel before 5.3.9, there are multiple out-of-bounds write bugs that can be caused by a malicious USB device in the Linux kernel HID drivers, aka CID-d9d4b1e46d95. This affects drivers/hid/hid-axff.c, drivers/hid/hid-dr.c, drivers/hid/hid-emsff.c, drivers/hid/hid-gaff.c, drivers/hid/hid-holtekff.c, drivers/hid/hid-lg2ff.c, drivers/hid/hid-lg3ff.c, drivers/hid/hid-lg4ff.c, drivers/hid/hid-lgff.c, drivers/hid/hid-logitech-hidpp.c, drivers/hid/hid-microsoft.c, drivers/hid/hid-sony.c, drivers/hid/hid-tmff.c, and drivers/hid/hid-zpff.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rxm3-cc74-v7p3/GHSA-rxm3-cc74-v7p3.json b/advisories/unreviewed/2022/05/GHSA-rxm3-cc74-v7p3/GHSA-rxm3-cc74-v7p3.json index a0354525b80..657e0bba65e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxm3-cc74-v7p3/GHSA-rxm3-cc74-v7p3.json +++ b/advisories/unreviewed/2022/05/GHSA-rxm3-cc74-v7p3/GHSA-rxm3-cc74-v7p3.json @@ -7,12 +7,8 @@ "CVE-2019-10618" ], "details": "Driver may access an invalid address while processing IO control due to lack of check of address validation in Snapdragon Connectivity in QCA6390", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v223-v69f-prp5/GHSA-v223-v69f-prp5.json b/advisories/unreviewed/2022/05/GHSA-v223-v69f-prp5/GHSA-v223-v69f-prp5.json index ef3ca180586..4afe8d87d95 100644 --- a/advisories/unreviewed/2022/05/GHSA-v223-v69f-prp5/GHSA-v223-v69f-prp5.json +++ b/advisories/unreviewed/2022/05/GHSA-v223-v69f-prp5/GHSA-v223-v69f-prp5.json @@ -7,12 +7,8 @@ "CVE-2019-1487" ], "details": "An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or later exists under specific conditions, aka 'Microsoft Authentication Library for Android Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2mj-wwf5-5hqj/GHSA-v2mj-wwf5-5hqj.json b/advisories/unreviewed/2022/05/GHSA-v2mj-wwf5-5hqj/GHSA-v2mj-wwf5-5hqj.json index 29f309e813c..d9e8597a934 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2mj-wwf5-5hqj/GHSA-v2mj-wwf5-5hqj.json +++ b/advisories/unreviewed/2022/05/GHSA-v2mj-wwf5-5hqj/GHSA-v2mj-wwf5-5hqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v37j-c88f-qxj8/GHSA-v37j-c88f-qxj8.json b/advisories/unreviewed/2022/05/GHSA-v37j-c88f-qxj8/GHSA-v37j-c88f-qxj8.json index c56c8c1c430..3f5774b7dc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v37j-c88f-qxj8/GHSA-v37j-c88f-qxj8.json +++ b/advisories/unreviewed/2022/05/GHSA-v37j-c88f-qxj8/GHSA-v37j-c88f-qxj8.json @@ -7,12 +7,8 @@ "CVE-2019-5874" ], "details": "Insufficient filtering in URI schemes in Google Chrome on Windows prior to 77.0.3865.75 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3jj-mj48-m8gv/GHSA-v3jj-mj48-m8gv.json b/advisories/unreviewed/2022/05/GHSA-v3jj-mj48-m8gv/GHSA-v3jj-mj48-m8gv.json index 560f77a5b38..1fc687eb923 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3jj-mj48-m8gv/GHSA-v3jj-mj48-m8gv.json +++ b/advisories/unreviewed/2022/05/GHSA-v3jj-mj48-m8gv/GHSA-v3jj-mj48-m8gv.json @@ -7,12 +7,8 @@ "CVE-2019-4426" ], "details": "The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162772.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v3wj-9m6p-vhvw/GHSA-v3wj-9m6p-vhvw.json b/advisories/unreviewed/2022/05/GHSA-v3wj-9m6p-vhvw/GHSA-v3wj-9m6p-vhvw.json index 64ddbf7210e..11eda387192 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3wj-9m6p-vhvw/GHSA-v3wj-9m6p-vhvw.json +++ b/advisories/unreviewed/2022/05/GHSA-v3wj-9m6p-vhvw/GHSA-v3wj-9m6p-vhvw.json @@ -7,12 +7,8 @@ "CVE-2015-3424" ], "details": "SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v566-63q4-p5m6/GHSA-v566-63q4-p5m6.json b/advisories/unreviewed/2022/05/GHSA-v566-63q4-p5m6/GHSA-v566-63q4-p5m6.json index 8aeb1aa2492..5795a0a10e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v566-63q4-p5m6/GHSA-v566-63q4-p5m6.json +++ b/advisories/unreviewed/2022/05/GHSA-v566-63q4-p5m6/GHSA-v566-63q4-p5m6.json @@ -7,12 +7,8 @@ "CVE-2019-2218" ], "details": "In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could lead to local escalation of privilege by installing malicious packages with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141169173", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5mw-2gc6-7h62/GHSA-v5mw-2gc6-7h62.json b/advisories/unreviewed/2022/05/GHSA-v5mw-2gc6-7h62/GHSA-v5mw-2gc6-7h62.json index 14728123f4e..78dede0ac3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5mw-2gc6-7h62/GHSA-v5mw-2gc6-7h62.json +++ b/advisories/unreviewed/2022/05/GHSA-v5mw-2gc6-7h62/GHSA-v5mw-2gc6-7h62.json @@ -7,12 +7,8 @@ "CVE-2019-19460" ], "details": "An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5pq-rgjj-rxgr/GHSA-v5pq-rgjj-rxgr.json b/advisories/unreviewed/2022/05/GHSA-v5pq-rgjj-rxgr/GHSA-v5pq-rgjj-rxgr.json index c4cfc2b8995..6b3016b8fe8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5pq-rgjj-rxgr/GHSA-v5pq-rgjj-rxgr.json +++ b/advisories/unreviewed/2022/05/GHSA-v5pq-rgjj-rxgr/GHSA-v5pq-rgjj-rxgr.json @@ -7,12 +7,8 @@ "CVE-2019-18324" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18328, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v62j-q62r-7cr9/GHSA-v62j-q62r-7cr9.json b/advisories/unreviewed/2022/05/GHSA-v62j-q62r-7cr9/GHSA-v62j-q62r-7cr9.json index e99663d1cfd..a6ecc8a083f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v62j-q62r-7cr9/GHSA-v62j-q62r-7cr9.json +++ b/advisories/unreviewed/2022/05/GHSA-v62j-q62r-7cr9/GHSA-v62j-q62r-7cr9.json @@ -7,12 +7,8 @@ "CVE-2019-5865" ], "details": "Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6g6-c9gr-qqp6/GHSA-v6g6-c9gr-qqp6.json b/advisories/unreviewed/2022/05/GHSA-v6g6-c9gr-qqp6/GHSA-v6g6-c9gr-qqp6.json index 78649c2bd11..924f873e470 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6g6-c9gr-qqp6/GHSA-v6g6-c9gr-qqp6.json +++ b/advisories/unreviewed/2022/05/GHSA-v6g6-c9gr-qqp6/GHSA-v6g6-c9gr-qqp6.json @@ -7,12 +7,8 @@ "CVE-2019-18300" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6xp-4m9g-j2w9/GHSA-v6xp-4m9g-j2w9.json b/advisories/unreviewed/2022/05/GHSA-v6xp-4m9g-j2w9/GHSA-v6xp-4m9g-j2w9.json index 595752ecbd4..574cbbd8285 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6xp-4m9g-j2w9/GHSA-v6xp-4m9g-j2w9.json +++ b/advisories/unreviewed/2022/05/GHSA-v6xp-4m9g-j2w9/GHSA-v6xp-4m9g-j2w9.json @@ -7,12 +7,8 @@ "CVE-2019-19382" ], "details": "Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replace a .exe or .dll file to achieve privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v84q-4crc-f5w4/GHSA-v84q-4crc-f5w4.json b/advisories/unreviewed/2022/05/GHSA-v84q-4crc-f5w4/GHSA-v84q-4crc-f5w4.json index d0a2ed9e68b..b4c9bad15f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v84q-4crc-f5w4/GHSA-v84q-4crc-f5w4.json +++ b/advisories/unreviewed/2022/05/GHSA-v84q-4crc-f5w4/GHSA-v84q-4crc-f5w4.json @@ -7,12 +7,8 @@ "CVE-2006-6018" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in mybic_server.php in Jim Plush My-BIC 0.6.5 allows remote attackers to execute arbitrary PHP code via a URL in the INC_PATH parameter, a different vector than CVE-2006-5089. NOTE: this issue is disputed by CVE and third party researchers because INC_PATH is a constant.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v8f8-f9x3-fqw4/GHSA-v8f8-f9x3-fqw4.json b/advisories/unreviewed/2022/05/GHSA-v8f8-f9x3-fqw4/GHSA-v8f8-f9x3-fqw4.json index 87b137b29ce..38e08a604a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8f8-f9x3-fqw4/GHSA-v8f8-f9x3-fqw4.json +++ b/advisories/unreviewed/2022/05/GHSA-v8f8-f9x3-fqw4/GHSA-v8f8-f9x3-fqw4.json @@ -7,12 +7,8 @@ "CVE-2019-19469" ], "details": "In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vc56-vmhr-h868/GHSA-vc56-vmhr-h868.json b/advisories/unreviewed/2022/05/GHSA-vc56-vmhr-h868/GHSA-vc56-vmhr-h868.json index c418340fbf5..21adad093d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc56-vmhr-h868/GHSA-vc56-vmhr-h868.json +++ b/advisories/unreviewed/2022/05/GHSA-vc56-vmhr-h868/GHSA-vc56-vmhr-h868.json @@ -7,12 +7,8 @@ "CVE-2019-18307" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, and CVE-2019-18306. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcx9-7p39-hwhg/GHSA-vcx9-7p39-hwhg.json b/advisories/unreviewed/2022/05/GHSA-vcx9-7p39-hwhg/GHSA-vcx9-7p39-hwhg.json index 0847b1864c8..73c2439113b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcx9-7p39-hwhg/GHSA-vcx9-7p39-hwhg.json +++ b/advisories/unreviewed/2022/05/GHSA-vcx9-7p39-hwhg/GHSA-vcx9-7p39-hwhg.json @@ -7,12 +7,8 @@ "CVE-2019-15972" ], "details": "A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vg9c-4w2h-c984/GHSA-vg9c-4w2h-c984.json b/advisories/unreviewed/2022/05/GHSA-vg9c-4w2h-c984/GHSA-vg9c-4w2h-c984.json index 9bc062b2fea..bb8700ef297 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg9c-4w2h-c984/GHSA-vg9c-4w2h-c984.json +++ b/advisories/unreviewed/2022/05/GHSA-vg9c-4w2h-c984/GHSA-vg9c-4w2h-c984.json @@ -7,12 +7,8 @@ "CVE-2019-18298" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vh9x-535j-rc7j/GHSA-vh9x-535j-rc7j.json b/advisories/unreviewed/2022/05/GHSA-vh9x-535j-rc7j/GHSA-vh9x-535j-rc7j.json index 45dce77b424..af2fcea6612 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh9x-535j-rc7j/GHSA-vh9x-535j-rc7j.json +++ b/advisories/unreviewed/2022/05/GHSA-vh9x-535j-rc7j/GHSA-vh9x-535j-rc7j.json @@ -7,12 +7,8 @@ "CVE-2019-19598" ], "details": "D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value. In HTTP requests, part of the HNAP_AUTH header is the timestamp used to determine the time when the user sent the request. If this value is equal to the value stored in the device's /var/hnap/timestamp file, the request will pass the HNAP_AUTH check function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vj8w-5833-f867/GHSA-vj8w-5833-f867.json b/advisories/unreviewed/2022/05/GHSA-vj8w-5833-f867/GHSA-vj8w-5833-f867.json index 2f5d338301b..3f18a107ac4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj8w-5833-f867/GHSA-vj8w-5833-f867.json +++ b/advisories/unreviewed/2022/05/GHSA-vj8w-5833-f867/GHSA-vj8w-5833-f867.json @@ -7,12 +7,8 @@ "CVE-2019-17428" ], "details": "An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vjh2-6hpx-j5rv/GHSA-vjh2-6hpx-j5rv.json b/advisories/unreviewed/2022/05/GHSA-vjh2-6hpx-j5rv/GHSA-vjh2-6hpx-j5rv.json index 9580e728131..4a21a44c06b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjh2-6hpx-j5rv/GHSA-vjh2-6hpx-j5rv.json +++ b/advisories/unreviewed/2022/05/GHSA-vjh2-6hpx-j5rv/GHSA-vjh2-6hpx-j5rv.json @@ -7,12 +7,8 @@ "CVE-2019-19020" ], "details": "An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup file that enables an attacker to execute arbitrary code by overwriting existing files or adding new PHP files under the web root. This requires the attacker to have access to a valid web interface account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjxq-fxvh-23vc/GHSA-vjxq-fxvh-23vc.json b/advisories/unreviewed/2022/05/GHSA-vjxq-fxvh-23vc/GHSA-vjxq-fxvh-23vc.json index f4cc7d1bade..57e06b4e405 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjxq-fxvh-23vc/GHSA-vjxq-fxvh-23vc.json +++ b/advisories/unreviewed/2022/05/GHSA-vjxq-fxvh-23vc/GHSA-vjxq-fxvh-23vc.json @@ -7,12 +7,8 @@ "CVE-2019-18446" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmqr-6q8r-ww5m/GHSA-vmqr-6q8r-ww5m.json b/advisories/unreviewed/2022/05/GHSA-vmqr-6q8r-ww5m/GHSA-vmqr-6q8r-ww5m.json index 49a828c3fd9..9d1b33edb8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmqr-6q8r-ww5m/GHSA-vmqr-6q8r-ww5m.json +++ b/advisories/unreviewed/2022/05/GHSA-vmqr-6q8r-ww5m/GHSA-vmqr-6q8r-ww5m.json @@ -7,12 +7,8 @@ "CVE-2019-15286" ], "details": "Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vppp-x5c9-x4mg/GHSA-vppp-x5c9-x4mg.json b/advisories/unreviewed/2022/05/GHSA-vppp-x5c9-x4mg/GHSA-vppp-x5c9-x4mg.json index 7abdf269211..6ccbe02dcb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vppp-x5c9-x4mg/GHSA-vppp-x5c9-x4mg.json +++ b/advisories/unreviewed/2022/05/GHSA-vppp-x5c9-x4mg/GHSA-vppp-x5c9-x4mg.json @@ -7,12 +7,8 @@ "CVE-2015-3425" ], "details": "Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq77-78v5-mqfp/GHSA-vq77-78v5-mqfp.json b/advisories/unreviewed/2022/05/GHSA-vq77-78v5-mqfp/GHSA-vq77-78v5-mqfp.json index dea19a6eac3..d83b179c03f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq77-78v5-mqfp/GHSA-vq77-78v5-mqfp.json +++ b/advisories/unreviewed/2022/05/GHSA-vq77-78v5-mqfp/GHSA-vq77-78v5-mqfp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqmr-6f7c-q88q/GHSA-vqmr-6f7c-q88q.json b/advisories/unreviewed/2022/05/GHSA-vqmr-6f7c-q88q/GHSA-vqmr-6f7c-q88q.json index 4b0f68d44ff..bd914bf405b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqmr-6f7c-q88q/GHSA-vqmr-6f7c-q88q.json +++ b/advisories/unreviewed/2022/05/GHSA-vqmr-6f7c-q88q/GHSA-vqmr-6f7c-q88q.json @@ -7,12 +7,8 @@ "CVE-2019-6674" ], "details": "On F5 SSL Orchestrator 15.0.0-15.0.1 and 14.0.0-14.1.2, TMM may crash when processing SSLO data in a service-chaining configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vr74-fpq9-774p/GHSA-vr74-fpq9-774p.json b/advisories/unreviewed/2022/05/GHSA-vr74-fpq9-774p/GHSA-vr74-fpq9-774p.json index 94a5fe2b1d7..d05b6272765 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr74-fpq9-774p/GHSA-vr74-fpq9-774p.json +++ b/advisories/unreviewed/2022/05/GHSA-vr74-fpq9-774p/GHSA-vr74-fpq9-774p.json @@ -7,12 +7,8 @@ "CVE-2019-5224" ], "details": "P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability. The system does not properly validate certain length parameter which an application transports to kernel. An attacker tricks the user to install a malicious application, successful exploit could cause out of bounds read and information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrcq-p73m-hmc8/GHSA-vrcq-p73m-hmc8.json b/advisories/unreviewed/2022/05/GHSA-vrcq-p73m-hmc8/GHSA-vrcq-p73m-hmc8.json index 034a4bbf8df..7ca89e62c11 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrcq-p73m-hmc8/GHSA-vrcq-p73m-hmc8.json +++ b/advisories/unreviewed/2022/05/GHSA-vrcq-p73m-hmc8/GHSA-vrcq-p73m-hmc8.json @@ -7,12 +7,8 @@ "CVE-2019-18305" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrfp-mmr3-wph6/GHSA-vrfp-mmr3-wph6.json b/advisories/unreviewed/2022/05/GHSA-vrfp-mmr3-wph6/GHSA-vrfp-mmr3-wph6.json index 2f527dfe07b..69f162c4a39 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrfp-mmr3-wph6/GHSA-vrfp-mmr3-wph6.json +++ b/advisories/unreviewed/2022/05/GHSA-vrfp-mmr3-wph6/GHSA-vrfp-mmr3-wph6.json @@ -7,12 +7,8 @@ "CVE-2019-13665" ], "details": "Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file download protection via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrpr-p6w2-crwx/GHSA-vrpr-p6w2-crwx.json b/advisories/unreviewed/2022/05/GHSA-vrpr-p6w2-crwx/GHSA-vrpr-p6w2-crwx.json index eadc398e265..7fb60d6bb5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrpr-p6w2-crwx/GHSA-vrpr-p6w2-crwx.json +++ b/advisories/unreviewed/2022/05/GHSA-vrpr-p6w2-crwx/GHSA-vrpr-p6w2-crwx.json @@ -7,12 +7,8 @@ "CVE-2019-2219" ], "details": "In System UI, there is a possible bypass of user's consent for access to sensor data due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-119041698", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxf2-rc93-x6wf/GHSA-vxf2-rc93-x6wf.json b/advisories/unreviewed/2022/05/GHSA-vxf2-rc93-x6wf/GHSA-vxf2-rc93-x6wf.json index f832248bfc2..71ef4496538 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxf2-rc93-x6wf/GHSA-vxf2-rc93-x6wf.json +++ b/advisories/unreviewed/2022/05/GHSA-vxf2-rc93-x6wf/GHSA-vxf2-rc93-x6wf.json @@ -7,12 +7,8 @@ "CVE-2019-15988" ], "details": "A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could exploit this vulnerability by crafting the URL in a particular way. A successful exploit could allow the attacker to bypass the URL reputation filters that are configured for the affected device, which could allow malicious URLs to pass through the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vxv9-h8fr-8f88/GHSA-vxv9-h8fr-8f88.json b/advisories/unreviewed/2022/05/GHSA-vxv9-h8fr-8f88/GHSA-vxv9-h8fr-8f88.json index ac061d3c686..4ff082cf648 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxv9-h8fr-8f88/GHSA-vxv9-h8fr-8f88.json +++ b/advisories/unreviewed/2022/05/GHSA-vxv9-h8fr-8f88/GHSA-vxv9-h8fr-8f88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxw8-3jmr-prjr/GHSA-vxw8-3jmr-prjr.json b/advisories/unreviewed/2022/05/GHSA-vxw8-3jmr-prjr/GHSA-vxw8-3jmr-prjr.json index dd06a50896f..76dffc3cf53 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxw8-3jmr-prjr/GHSA-vxw8-3jmr-prjr.json +++ b/advisories/unreviewed/2022/05/GHSA-vxw8-3jmr-prjr/GHSA-vxw8-3jmr-prjr.json @@ -7,12 +7,8 @@ "CVE-2019-16242" ], "details": "On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An attacker with physical access to the device can abuse this vulnerability to execute arbitrary OS commands as the root user via the application's UI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w256-88g9-rh8j/GHSA-w256-88g9-rh8j.json b/advisories/unreviewed/2022/05/GHSA-w256-88g9-rh8j/GHSA-w256-88g9-rh8j.json index 4df383fb492..3c2e53cc10a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w256-88g9-rh8j/GHSA-w256-88g9-rh8j.json +++ b/advisories/unreviewed/2022/05/GHSA-w256-88g9-rh8j/GHSA-w256-88g9-rh8j.json @@ -7,12 +7,8 @@ "CVE-2019-3986" ], "details": "Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w339-gvf7-98x9/GHSA-w339-gvf7-98x9.json b/advisories/unreviewed/2022/05/GHSA-w339-gvf7-98x9/GHSA-w339-gvf7-98x9.json index 770ab3b1f9a..651b4e0f23e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w339-gvf7-98x9/GHSA-w339-gvf7-98x9.json +++ b/advisories/unreviewed/2022/05/GHSA-w339-gvf7-98x9/GHSA-w339-gvf7-98x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w36j-549f-hchr/GHSA-w36j-549f-hchr.json b/advisories/unreviewed/2022/05/GHSA-w36j-549f-hchr/GHSA-w36j-549f-hchr.json index 2efe1918925..5087d8f11ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-w36j-549f-hchr/GHSA-w36j-549f-hchr.json +++ b/advisories/unreviewed/2022/05/GHSA-w36j-549f-hchr/GHSA-w36j-549f-hchr.json @@ -7,12 +7,8 @@ "CVE-2019-15998" ], "details": "A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected device. The vulnerability is due to a missing check in the NETCONF over SSH access control list (ACL). An attacker could exploit this vulnerability by connecting to an affected device using NETCONF over SSH. A successful exploit could allow the attacker to connect to the device on the NETCONF port. Valid credentials are required to access the device. This vulnerability does not affect connections to the default SSH process on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w44r-j9pq-vv3v/GHSA-w44r-j9pq-vv3v.json b/advisories/unreviewed/2022/05/GHSA-w44r-j9pq-vv3v/GHSA-w44r-j9pq-vv3v.json index 0e6a462a478..e11a3f03c04 100644 --- a/advisories/unreviewed/2022/05/GHSA-w44r-j9pq-vv3v/GHSA-w44r-j9pq-vv3v.json +++ b/advisories/unreviewed/2022/05/GHSA-w44r-j9pq-vv3v/GHSA-w44r-j9pq-vv3v.json @@ -7,12 +7,8 @@ "CVE-2019-16002" ], "details": "A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected instance of vManage. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4j4-88w2-32g6/GHSA-w4j4-88w2-32g6.json b/advisories/unreviewed/2022/05/GHSA-w4j4-88w2-32g6/GHSA-w4j4-88w2-32g6.json index d68d44cd5fd..3e03a884a62 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4j4-88w2-32g6/GHSA-w4j4-88w2-32g6.json +++ b/advisories/unreviewed/2022/05/GHSA-w4j4-88w2-32g6/GHSA-w4j4-88w2-32g6.json @@ -7,12 +7,8 @@ "CVE-2019-19555" ], "details": "read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6qj-c53w-v49m/GHSA-w6qj-c53w-v49m.json b/advisories/unreviewed/2022/05/GHSA-w6qj-c53w-v49m/GHSA-w6qj-c53w-v49m.json index 563abd6008d..33a60b852c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6qj-c53w-v49m/GHSA-w6qj-c53w-v49m.json +++ b/advisories/unreviewed/2022/05/GHSA-w6qj-c53w-v49m/GHSA-w6qj-c53w-v49m.json @@ -7,12 +7,8 @@ "CVE-2019-5850" ], "details": "Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6rh-mrcc-6xc4/GHSA-w6rh-mrcc-6xc4.json b/advisories/unreviewed/2022/05/GHSA-w6rh-mrcc-6xc4/GHSA-w6rh-mrcc-6xc4.json index c0aac38e2f8..9d84dcebd39 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6rh-mrcc-6xc4/GHSA-w6rh-mrcc-6xc4.json +++ b/advisories/unreviewed/2022/05/GHSA-w6rh-mrcc-6xc4/GHSA-w6rh-mrcc-6xc4.json @@ -7,12 +7,8 @@ "CVE-2019-5880" ], "details": "Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w772-f4fj-g5xq/GHSA-w772-f4fj-g5xq.json b/advisories/unreviewed/2022/05/GHSA-w772-f4fj-g5xq/GHSA-w772-f4fj-g5xq.json index ab10663e716..e013855799e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w772-f4fj-g5xq/GHSA-w772-f4fj-g5xq.json +++ b/advisories/unreviewed/2022/05/GHSA-w772-f4fj-g5xq/GHSA-w772-f4fj-g5xq.json @@ -7,12 +7,8 @@ "CVE-2019-18462" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7w7-v6c3-q554/GHSA-w7w7-v6c3-q554.json b/advisories/unreviewed/2022/05/GHSA-w7w7-v6c3-q554/GHSA-w7w7-v6c3-q554.json index 35be36e6ff2..85d76d18528 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7w7-v6c3-q554/GHSA-w7w7-v6c3-q554.json +++ b/advisories/unreviewed/2022/05/GHSA-w7w7-v6c3-q554/GHSA-w7w7-v6c3-q554.json @@ -7,12 +7,8 @@ "CVE-2019-2321" ], "details": "Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, IPQ4019, IPQ8074, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA8081, QCS404, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150, Snapdragon_High_Med_2016, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8pp-7r52-g3fm/GHSA-w8pp-7r52-g3fm.json b/advisories/unreviewed/2022/05/GHSA-w8pp-7r52-g3fm/GHSA-w8pp-7r52-g3fm.json index e62d5b6cdbf..a1ea5f32d63 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8pp-7r52-g3fm/GHSA-w8pp-7r52-g3fm.json +++ b/advisories/unreviewed/2022/05/GHSA-w8pp-7r52-g3fm/GHSA-w8pp-7r52-g3fm.json @@ -7,12 +7,8 @@ "CVE-2019-13677" ], "details": "Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8rm-5xr6-mmcj/GHSA-w8rm-5xr6-mmcj.json b/advisories/unreviewed/2022/05/GHSA-w8rm-5xr6-mmcj/GHSA-w8rm-5xr6-mmcj.json index b436b82d317..23b4e8d73d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8rm-5xr6-mmcj/GHSA-w8rm-5xr6-mmcj.json +++ b/advisories/unreviewed/2022/05/GHSA-w8rm-5xr6-mmcj/GHSA-w8rm-5xr6-mmcj.json @@ -7,12 +7,8 @@ "CVE-2019-16195" ], "details": "Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8vp-84hv-6mqj/GHSA-w8vp-84hv-6mqj.json b/advisories/unreviewed/2022/05/GHSA-w8vp-84hv-6mqj/GHSA-w8vp-84hv-6mqj.json index c86f9ec8781..d35ca69828d 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8vp-84hv-6mqj/GHSA-w8vp-84hv-6mqj.json +++ b/advisories/unreviewed/2022/05/GHSA-w8vp-84hv-6mqj/GHSA-w8vp-84hv-6mqj.json @@ -7,12 +7,8 @@ "CVE-2019-5876" ], "details": "Use after free in media in Google Chrome on Android prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w9hw-62rh-37w6/GHSA-w9hw-62rh-37w6.json b/advisories/unreviewed/2022/05/GHSA-w9hw-62rh-37w6/GHSA-w9hw-62rh-37w6.json index 32826d60262..d9a57c0ecd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9hw-62rh-37w6/GHSA-w9hw-62rh-37w6.json +++ b/advisories/unreviewed/2022/05/GHSA-w9hw-62rh-37w6/GHSA-w9hw-62rh-37w6.json @@ -7,12 +7,8 @@ "CVE-2019-18327" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18324, CVE-2019-18325, CVE-2019-18326, CVE-2019-18328, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wcv6-x2hg-7wqj/GHSA-wcv6-x2hg-7wqj.json b/advisories/unreviewed/2022/05/GHSA-wcv6-x2hg-7wqj/GHSA-wcv6-x2hg-7wqj.json index 7c6e85a7e6e..485ef05c152 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcv6-x2hg-7wqj/GHSA-wcv6-x2hg-7wqj.json +++ b/advisories/unreviewed/2022/05/GHSA-wcv6-x2hg-7wqj/GHSA-wcv6-x2hg-7wqj.json @@ -7,12 +7,8 @@ "CVE-2019-18292" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgxw-w75w-6fm4/GHSA-wgxw-w75w-6fm4.json b/advisories/unreviewed/2022/05/GHSA-wgxw-w75w-6fm4/GHSA-wgxw-w75w-6fm4.json index 93f8e0523ea..065b7af8425 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgxw-w75w-6fm4/GHSA-wgxw-w75w-6fm4.json +++ b/advisories/unreviewed/2022/05/GHSA-wgxw-w75w-6fm4/GHSA-wgxw-w75w-6fm4.json @@ -7,12 +7,8 @@ "CVE-2006-5783" ], "details": "** DISPUTED ** Firefox 1.5.0.7 on Kubuntu Linux allows remote attackers to cause a denial of service (crash) via a long URL in an A tag. NOTE: this issue has been disputed by several vendors, who could not reproduce the report. In addition, the scope of the impact - system freeze - suggests an issue that is not related to Firefox. Due to this impact, CVE concurs with the dispute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whrv-w3fp-5gf4/GHSA-whrv-w3fp-5gf4.json b/advisories/unreviewed/2022/05/GHSA-whrv-w3fp-5gf4/GHSA-whrv-w3fp-5gf4.json index 268e07d656c..deed85d465c 100644 --- a/advisories/unreviewed/2022/05/GHSA-whrv-w3fp-5gf4/GHSA-whrv-w3fp-5gf4.json +++ b/advisories/unreviewed/2022/05/GHSA-whrv-w3fp-5gf4/GHSA-whrv-w3fp-5gf4.json @@ -7,12 +7,8 @@ "CVE-2019-19637" ], "details": "An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wjxh-p937-x4v8/GHSA-wjxh-p937-x4v8.json b/advisories/unreviewed/2022/05/GHSA-wjxh-p937-x4v8/GHSA-wjxh-p937-x4v8.json index a000539dab7..099d3df4b52 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjxh-p937-x4v8/GHSA-wjxh-p937-x4v8.json +++ b/advisories/unreviewed/2022/05/GHSA-wjxh-p937-x4v8/GHSA-wjxh-p937-x4v8.json @@ -7,12 +7,8 @@ "CVE-2019-11923" ], "details": "In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowing for resource exhaustion or denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqrj-5m22-cpfg/GHSA-wqrj-5m22-cpfg.json b/advisories/unreviewed/2022/05/GHSA-wqrj-5m22-cpfg/GHSA-wqrj-5m22-cpfg.json index e1e3f2071fa..ecfe3ceb90a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqrj-5m22-cpfg/GHSA-wqrj-5m22-cpfg.json +++ b/advisories/unreviewed/2022/05/GHSA-wqrj-5m22-cpfg/GHSA-wqrj-5m22-cpfg.json @@ -7,12 +7,8 @@ "CVE-2019-15284" ], "details": "Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wr5r-rjww-hqwf/GHSA-wr5r-rjww-hqwf.json b/advisories/unreviewed/2022/05/GHSA-wr5r-rjww-hqwf/GHSA-wr5r-rjww-hqwf.json index 7cfd15c0d32..98da46bd176 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr5r-rjww-hqwf/GHSA-wr5r-rjww-hqwf.json +++ b/advisories/unreviewed/2022/05/GHSA-wr5r-rjww-hqwf/GHSA-wr5r-rjww-hqwf.json @@ -7,12 +7,8 @@ "CVE-2019-10494" ], "details": "Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF issue in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr7m-82gg-jpg8/GHSA-wr7m-82gg-jpg8.json b/advisories/unreviewed/2022/05/GHSA-wr7m-82gg-jpg8/GHSA-wr7m-82gg-jpg8.json index 16b5f7dd1c6..0cb956295a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr7m-82gg-jpg8/GHSA-wr7m-82gg-jpg8.json +++ b/advisories/unreviewed/2022/05/GHSA-wr7m-82gg-jpg8/GHSA-wr7m-82gg-jpg8.json @@ -7,12 +7,8 @@ "CVE-2019-15008" ], "details": "The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wv8f-82g9-5vhw/GHSA-wv8f-82g9-5vhw.json b/advisories/unreviewed/2022/05/GHSA-wv8f-82g9-5vhw/GHSA-wv8f-82g9-5vhw.json index 2a35e7bbdfe..d94996e2f78 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv8f-82g9-5vhw/GHSA-wv8f-82g9-5vhw.json +++ b/advisories/unreviewed/2022/05/GHSA-wv8f-82g9-5vhw/GHSA-wv8f-82g9-5vhw.json @@ -7,12 +7,8 @@ "CVE-2019-19582" ], "details": "An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over all bits involves functions which may misbehave in certain corner cases: On x86 accesses to bitmaps with a compile time known size of 64 may incur undefined behavior, which may in particular result in infinite loops. A malicious guest may cause a hypervisor crash or hang, resulting in a Denial of Service (DoS). All versions of Xen are vulnerable. x86 systems with 64 or more nodes are vulnerable (there might not be any such systems that Xen would run on). x86 systems with less than 64 nodes are not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wv8g-hc35-2wh7/GHSA-wv8g-hc35-2wh7.json b/advisories/unreviewed/2022/05/GHSA-wv8g-hc35-2wh7/GHSA-wv8g-hc35-2wh7.json index 1387b764d4a..9a81b193162 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv8g-hc35-2wh7/GHSA-wv8g-hc35-2wh7.json +++ b/advisories/unreviewed/2022/05/GHSA-wv8g-hc35-2wh7/GHSA-wv8g-hc35-2wh7.json @@ -7,12 +7,8 @@ "CVE-2019-2319" ], "details": "HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wv97-733g-f484/GHSA-wv97-733g-f484.json b/advisories/unreviewed/2022/05/GHSA-wv97-733g-f484/GHSA-wv97-733g-f484.json index 8f925d69ee1..2cc7d5292c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv97-733g-f484/GHSA-wv97-733g-f484.json +++ b/advisories/unreviewed/2022/05/GHSA-wv97-733g-f484/GHSA-wv97-733g-f484.json @@ -7,12 +7,8 @@ "CVE-2019-12393" ], "details": "Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvcx-99hh-xjmx/GHSA-wvcx-99hh-xjmx.json b/advisories/unreviewed/2022/05/GHSA-wvcx-99hh-xjmx/GHSA-wvcx-99hh-xjmx.json index 0ff37ef7c8a..a3bccf89478 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvcx-99hh-xjmx/GHSA-wvcx-99hh-xjmx.json +++ b/advisories/unreviewed/2022/05/GHSA-wvcx-99hh-xjmx/GHSA-wvcx-99hh-xjmx.json @@ -7,12 +7,8 @@ "CVE-2019-18294" ], "details": "A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvv9-x8pf-57jq/GHSA-wvv9-x8pf-57jq.json b/advisories/unreviewed/2022/05/GHSA-wvv9-x8pf-57jq/GHSA-wvv9-x8pf-57jq.json index 557112d5fdb..12ab479b8ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvv9-x8pf-57jq/GHSA-wvv9-x8pf-57jq.json +++ b/advisories/unreviewed/2022/05/GHSA-wvv9-x8pf-57jq/GHSA-wvv9-x8pf-57jq.json @@ -7,12 +7,8 @@ "CVE-2006-6308" ], "details": "** DISPUTED ** Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open \"Web Self-Service\" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may be necessary to terminate shstart.exe. If this is the case, then no privilege escalation occurs, and this is not a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvx4-cw49-456m/GHSA-wvx4-cw49-456m.json b/advisories/unreviewed/2022/05/GHSA-wvx4-cw49-456m/GHSA-wvx4-cw49-456m.json index 323181c7b82..062e139600a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvx4-cw49-456m/GHSA-wvx4-cw49-456m.json +++ b/advisories/unreviewed/2022/05/GHSA-wvx4-cw49-456m/GHSA-wvx4-cw49-456m.json @@ -7,12 +7,8 @@ "CVE-2019-10559" ], "details": "Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8939, MSM8953, MSM8996, MSM8996AU, Nicobar, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxqp-q88p-4h7r/GHSA-wxqp-q88p-4h7r.json b/advisories/unreviewed/2022/05/GHSA-wxqp-q88p-4h7r/GHSA-wxqp-q88p-4h7r.json index 2cb99a89934..99f10528d2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxqp-q88p-4h7r/GHSA-wxqp-q88p-4h7r.json +++ b/advisories/unreviewed/2022/05/GHSA-wxqp-q88p-4h7r/GHSA-wxqp-q88p-4h7r.json @@ -7,12 +7,8 @@ "CVE-2019-5843" ], "details": "Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wxxf-gxv9-5j54/GHSA-wxxf-gxv9-5j54.json b/advisories/unreviewed/2022/05/GHSA-wxxf-gxv9-5j54/GHSA-wxxf-gxv9-5j54.json index de976e122b0..1e329260720 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxxf-gxv9-5j54/GHSA-wxxf-gxv9-5j54.json +++ b/advisories/unreviewed/2022/05/GHSA-wxxf-gxv9-5j54/GHSA-wxxf-gxv9-5j54.json @@ -7,12 +7,8 @@ "CVE-2015-7892" ], "details": "Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x257-265c-9355/GHSA-x257-265c-9355.json b/advisories/unreviewed/2022/05/GHSA-x257-265c-9355/GHSA-x257-265c-9355.json index 2ddfa33b36a..904fabd2f2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x257-265c-9355/GHSA-x257-265c-9355.json +++ b/advisories/unreviewed/2022/05/GHSA-x257-265c-9355/GHSA-x257-265c-9355.json @@ -7,12 +7,8 @@ "CVE-2019-15688" ], "details": "Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2gh-jj85-3r25/GHSA-x2gh-jj85-3r25.json b/advisories/unreviewed/2022/05/GHSA-x2gh-jj85-3r25/GHSA-x2gh-jj85-3r25.json index b5d9c86ffc9..ed8399ebbe9 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2gh-jj85-3r25/GHSA-x2gh-jj85-3r25.json +++ b/advisories/unreviewed/2022/05/GHSA-x2gh-jj85-3r25/GHSA-x2gh-jj85-3r25.json @@ -7,12 +7,8 @@ "CVE-2019-6671" ], "details": "On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, under certain conditions tmm may leak memory when processing packet fragments, leading to resource starvation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x36q-229j-mv7q/GHSA-x36q-229j-mv7q.json b/advisories/unreviewed/2022/05/GHSA-x36q-229j-mv7q/GHSA-x36q-229j-mv7q.json index a7279d4a320..cb6304721b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x36q-229j-mv7q/GHSA-x36q-229j-mv7q.json +++ b/advisories/unreviewed/2022/05/GHSA-x36q-229j-mv7q/GHSA-x36q-229j-mv7q.json @@ -7,12 +7,8 @@ "CVE-2018-0728" ], "details": "This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3w4-7cmr-9gv2/GHSA-x3w4-7cmr-9gv2.json b/advisories/unreviewed/2022/05/GHSA-x3w4-7cmr-9gv2/GHSA-x3w4-7cmr-9gv2.json index 5ca9108f705..c98a626ace9 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3w4-7cmr-9gv2/GHSA-x3w4-7cmr-9gv2.json +++ b/advisories/unreviewed/2022/05/GHSA-x3w4-7cmr-9gv2/GHSA-x3w4-7cmr-9gv2.json @@ -7,12 +7,8 @@ "CVE-2019-16765" ], "details": "If an attacker can get a user to open a specially prepared directory tree as a workspace in Visual Studio Code with the CodeQL extension active, arbitrary code of the attacker's choosing may be executed on the user's behalf. This is fixed in version 1.0.1 of the extension. Users should upgrade to this version using Visual Studio Code Marketplace's upgrade mechanism. After upgrading, the codeQL.cli.executablePath setting can only be set in the per-user settings, and not in the per-workspace settings. More information about VS Code settings can be found here.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "WEB", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4f4-vh84-45wp/GHSA-x4f4-vh84-45wp.json b/advisories/unreviewed/2022/05/GHSA-x4f4-vh84-45wp/GHSA-x4f4-vh84-45wp.json index 76b2dd3c775..308a2d1d2de 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4f4-vh84-45wp/GHSA-x4f4-vh84-45wp.json +++ b/advisories/unreviewed/2022/05/GHSA-x4f4-vh84-45wp/GHSA-x4f4-vh84-45wp.json @@ -7,12 +7,8 @@ "CVE-2019-15685" ], "details": "Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4r5-gcgv-4cmp/GHSA-x4r5-gcgv-4cmp.json b/advisories/unreviewed/2022/05/GHSA-x4r5-gcgv-4cmp/GHSA-x4r5-gcgv-4cmp.json index 4f507117465..e3aa2e29ef0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4r5-gcgv-4cmp/GHSA-x4r5-gcgv-4cmp.json +++ b/advisories/unreviewed/2022/05/GHSA-x4r5-gcgv-4cmp/GHSA-x4r5-gcgv-4cmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x65v-c8ff-h2m3/GHSA-x65v-c8ff-h2m3.json b/advisories/unreviewed/2022/05/GHSA-x65v-c8ff-h2m3/GHSA-x65v-c8ff-h2m3.json index 21c4c91b277..36a0306a1b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-x65v-c8ff-h2m3/GHSA-x65v-c8ff-h2m3.json +++ b/advisories/unreviewed/2022/05/GHSA-x65v-c8ff-h2m3/GHSA-x65v-c8ff-h2m3.json @@ -7,12 +7,8 @@ "CVE-2019-19480" ], "details": "An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x687-4r8f-56rh/GHSA-x687-4r8f-56rh.json b/advisories/unreviewed/2022/05/GHSA-x687-4r8f-56rh/GHSA-x687-4r8f-56rh.json index 1e38f375baa..8244ef055c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-x687-4r8f-56rh/GHSA-x687-4r8f-56rh.json +++ b/advisories/unreviewed/2022/05/GHSA-x687-4r8f-56rh/GHSA-x687-4r8f-56rh.json @@ -7,12 +7,8 @@ "CVE-2016-9271" ], "details": "Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6g7-8j99-h4fv/GHSA-x6g7-8j99-h4fv.json b/advisories/unreviewed/2022/05/GHSA-x6g7-8j99-h4fv/GHSA-x6g7-8j99-h4fv.json index dd48b5f848b..2b43102d584 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6g7-8j99-h4fv/GHSA-x6g7-8j99-h4fv.json +++ b/advisories/unreviewed/2022/05/GHSA-x6g7-8j99-h4fv/GHSA-x6g7-8j99-h4fv.json @@ -7,12 +7,8 @@ "CVE-2019-18453" ], "details": "An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6v5-8qcc-4q56/GHSA-x6v5-8qcc-4q56.json b/advisories/unreviewed/2022/05/GHSA-x6v5-8qcc-4q56/GHSA-x6v5-8qcc-4q56.json index 4c17d0310ec..8b9e5c32e1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6v5-8qcc-4q56/GHSA-x6v5-8qcc-4q56.json +++ b/advisories/unreviewed/2022/05/GHSA-x6v5-8qcc-4q56/GHSA-x6v5-8qcc-4q56.json @@ -7,12 +7,8 @@ "CVE-2019-5291" ], "details": "Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x75j-hvj7-cjwg/GHSA-x75j-hvj7-cjwg.json b/advisories/unreviewed/2022/05/GHSA-x75j-hvj7-cjwg/GHSA-x75j-hvj7-cjwg.json index a5f8f738104..5ed13b962ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-x75j-hvj7-cjwg/GHSA-x75j-hvj7-cjwg.json +++ b/advisories/unreviewed/2022/05/GHSA-x75j-hvj7-cjwg/GHSA-x75j-hvj7-cjwg.json @@ -7,12 +7,8 @@ "CVE-2006-4848" ], "details": "** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php, (3) framepoint.php, (4) genpage.php, (5) lienvalider.php, (6) appreciation.php, (7) partenariat.php, (8) rechercher.php, (9) projet.php, (10) propoexample.php, (11) refererpoint.php, or (12) top50.php. NOTE: this issue has been disputed by a third party researcher, stating that REP_CLASS is initialized in an included file before being used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8h6-fqp3-v7qr/GHSA-x8h6-fqp3-v7qr.json b/advisories/unreviewed/2022/05/GHSA-x8h6-fqp3-v7qr/GHSA-x8h6-fqp3-v7qr.json index 63c2f80453d..3350eee5684 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8h6-fqp3-v7qr/GHSA-x8h6-fqp3-v7qr.json +++ b/advisories/unreviewed/2022/05/GHSA-x8h6-fqp3-v7qr/GHSA-x8h6-fqp3-v7qr.json @@ -7,12 +7,8 @@ "CVE-2019-4467" ], "details": "IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163776.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8qg-82x8-gf44/GHSA-x8qg-82x8-gf44.json b/advisories/unreviewed/2022/05/GHSA-x8qg-82x8-gf44/GHSA-x8qg-82x8-gf44.json index 29f1e89c393..f54808f33a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8qg-82x8-gf44/GHSA-x8qg-82x8-gf44.json +++ b/advisories/unreviewed/2022/05/GHSA-x8qg-82x8-gf44/GHSA-x8qg-82x8-gf44.json @@ -7,12 +7,8 @@ "CVE-2006-5920" ], "details": "** DISPUTED ** PHP remote file inclusion vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: SecurityFocus disputes this issue, saying \"further analysis reveals that the application is not vulnerable.\" NOTE: this issue may overlap CVE-2006-5113.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcj9-hh7g-p7rq/GHSA-xcj9-hh7g-p7rq.json b/advisories/unreviewed/2022/05/GHSA-xcj9-hh7g-p7rq/GHSA-xcj9-hh7g-p7rq.json index 1afd1c3a866..fe2b556a374 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcj9-hh7g-p7rq/GHSA-xcj9-hh7g-p7rq.json +++ b/advisories/unreviewed/2022/05/GHSA-xcj9-hh7g-p7rq/GHSA-xcj9-hh7g-p7rq.json @@ -7,12 +7,8 @@ "CVE-2019-19017" ], "details": "An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileges on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcx2-w5f3-cw9g/GHSA-xcx2-w5f3-cw9g.json b/advisories/unreviewed/2022/05/GHSA-xcx2-w5f3-cw9g/GHSA-xcx2-w5f3-cw9g.json index 8493d03a520..4101c858f6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcx2-w5f3-cw9g/GHSA-xcx2-w5f3-cw9g.json +++ b/advisories/unreviewed/2022/05/GHSA-xcx2-w5f3-cw9g/GHSA-xcx2-w5f3-cw9g.json @@ -7,12 +7,8 @@ "CVE-2019-5826" ], "details": "Use after free in IndexedDB in Google Chrome prior to 73.0.3683.86 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf55-34cc-4qxw/GHSA-xf55-34cc-4qxw.json b/advisories/unreviewed/2022/05/GHSA-xf55-34cc-4qxw/GHSA-xf55-34cc-4qxw.json index 4be577a8ac6..86d755b436e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf55-34cc-4qxw/GHSA-xf55-34cc-4qxw.json +++ b/advisories/unreviewed/2022/05/GHSA-xf55-34cc-4qxw/GHSA-xf55-34cc-4qxw.json @@ -7,12 +7,8 @@ "CVE-2019-18671" ], "details": "Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes on the stack via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xfq9-m5c5-8p4q/GHSA-xfq9-m5c5-8p4q.json b/advisories/unreviewed/2022/05/GHSA-xfq9-m5c5-8p4q/GHSA-xfq9-m5c5-8p4q.json index 6b7f562f1da..0ac798e9775 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfq9-m5c5-8p4q/GHSA-xfq9-m5c5-8p4q.json +++ b/advisories/unreviewed/2022/05/GHSA-xfq9-m5c5-8p4q/GHSA-xfq9-m5c5-8p4q.json @@ -7,12 +7,8 @@ "CVE-2016-6353" ], "details": "Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xg7m-wjrf-p6rf/GHSA-xg7m-wjrf-p6rf.json b/advisories/unreviewed/2022/05/GHSA-xg7m-wjrf-p6rf/GHSA-xg7m-wjrf-p6rf.json index b50d7a7959d..ac27f64063c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg7m-wjrf-p6rf/GHSA-xg7m-wjrf-p6rf.json +++ b/advisories/unreviewed/2022/05/GHSA-xg7m-wjrf-p6rf/GHSA-xg7m-wjrf-p6rf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xhj8-35xv-vj3p/GHSA-xhj8-35xv-vj3p.json b/advisories/unreviewed/2022/05/GHSA-xhj8-35xv-vj3p/GHSA-xhj8-35xv-vj3p.json index 6842e68a4b9..b8e43e25bf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhj8-35xv-vj3p/GHSA-xhj8-35xv-vj3p.json +++ b/advisories/unreviewed/2022/05/GHSA-xhj8-35xv-vj3p/GHSA-xhj8-35xv-vj3p.json @@ -7,12 +7,8 @@ "CVE-2019-5851" ], "details": "Use after free in WebAudio in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xj7q-4ppq-c7ch/GHSA-xj7q-4ppq-c7ch.json b/advisories/unreviewed/2022/05/GHSA-xj7q-4ppq-c7ch/GHSA-xj7q-4ppq-c7ch.json index 805d90689b6..609c741bbc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj7q-4ppq-c7ch/GHSA-xj7q-4ppq-c7ch.json +++ b/advisories/unreviewed/2022/05/GHSA-xj7q-4ppq-c7ch/GHSA-xj7q-4ppq-c7ch.json @@ -7,12 +7,8 @@ "CVE-2019-13681" ], "details": "Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass download restrictions via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjx5-q997-jj79/GHSA-xjx5-q997-jj79.json b/advisories/unreviewed/2022/05/GHSA-xjx5-q997-jj79/GHSA-xjx5-q997-jj79.json index a692be4b9fd..587eb584f90 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjx5-q997-jj79/GHSA-xjx5-q997-jj79.json +++ b/advisories/unreviewed/2022/05/GHSA-xjx5-q997-jj79/GHSA-xjx5-q997-jj79.json @@ -7,12 +7,8 @@ "CVE-2019-5218" ], "details": "There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xm4c-wwh2-mcv8/GHSA-xm4c-wwh2-mcv8.json b/advisories/unreviewed/2022/05/GHSA-xm4c-wwh2-mcv8/GHSA-xm4c-wwh2-mcv8.json index 7786b1048f1..8ebbb925939 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm4c-wwh2-mcv8/GHSA-xm4c-wwh2-mcv8.json +++ b/advisories/unreviewed/2022/05/GHSA-xm4c-wwh2-mcv8/GHSA-xm4c-wwh2-mcv8.json @@ -7,12 +7,8 @@ "CVE-2019-19578" ], "details": "An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. \"Linear pagetables\" is a technique which involves either pointing a pagetable at itself, or to another pagetable of the same or higher level. Xen has limited support for linear pagetables: A page may either point to itself, or point to another pagetable of the same level (i.e., L2 to L2, L3 to L3, and so on). XSA-240 introduced an additional restriction that limited the \"depth\" of such chains by allowing pages to either *point to* other pages of the same level, or *be pointed to* by other pages of the same level, but not both. To implement this, we keep track of the number of outstanding times a page points to or is pointed to another page table, to prevent both from happening at the same time. Unfortunately, the original commit introducing this reset this count when resuming validation of a partially-validated pagetable, incorrectly dropping some \"linear_pt_entry\" counts. If an attacker could engineer such a situation to occur, they might be able to make loops or other arbitrary chains of linear pagetables, as described in XSA-240. A malicious or buggy PV guest may cause the hypervisor to crash, resulting in Denial of Service (DoS) affecting the entire host. Privilege escalation and information leaks cannot be excluded. All versions of Xen are vulnerable. Only x86 systems are affected. Arm systems are not affected. Only x86 PV guests can leverage the vulnerability. x86 HVM and PVH guests cannot leverage the vulnerability. Only systems which have enabled linear pagetables are vulnerable. Systems which have disabled linear pagetables, either by selecting CONFIG_PV_LINEAR_PT=n when building the hypervisor, or adding pv-linear-pt=false on the command-line, are not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xmvf-mpjx-5xvj/GHSA-xmvf-mpjx-5xvj.json b/advisories/unreviewed/2022/05/GHSA-xmvf-mpjx-5xvj/GHSA-xmvf-mpjx-5xvj.json index 6f325285aae..f9eaab265dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmvf-mpjx-5xvj/GHSA-xmvf-mpjx-5xvj.json +++ b/advisories/unreviewed/2022/05/GHSA-xmvf-mpjx-5xvj/GHSA-xmvf-mpjx-5xvj.json @@ -7,12 +7,8 @@ "CVE-2019-18850" ], "details": "TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding to different HTTP methods, also via predictible responses when accessing and interacting with the \"SITE_PATH_QUERY\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp78-rqf2-cf9c/GHSA-xp78-rqf2-cf9c.json b/advisories/unreviewed/2022/05/GHSA-xp78-rqf2-cf9c/GHSA-xp78-rqf2-cf9c.json index e3e06a06bb3..55453401d60 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp78-rqf2-cf9c/GHSA-xp78-rqf2-cf9c.json +++ b/advisories/unreviewed/2022/05/GHSA-xp78-rqf2-cf9c/GHSA-xp78-rqf2-cf9c.json @@ -7,12 +7,8 @@ "CVE-2019-3667" ], "details": "DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xq9m-fh33-jh35/GHSA-xq9m-fh33-jh35.json b/advisories/unreviewed/2022/05/GHSA-xq9m-fh33-jh35/GHSA-xq9m-fh33-jh35.json index b0d5547400b..d2eb25f0095 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq9m-fh33-jh35/GHSA-xq9m-fh33-jh35.json +++ b/advisories/unreviewed/2022/05/GHSA-xq9m-fh33-jh35/GHSA-xq9m-fh33-jh35.json @@ -7,12 +7,8 @@ "CVE-2019-13687" ], "details": "Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xr69-7fhc-h6vj/GHSA-xr69-7fhc-h6vj.json b/advisories/unreviewed/2022/05/GHSA-xr69-7fhc-h6vj/GHSA-xr69-7fhc-h6vj.json index d8f0dd01525..c770286ada8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr69-7fhc-h6vj/GHSA-xr69-7fhc-h6vj.json +++ b/advisories/unreviewed/2022/05/GHSA-xr69-7fhc-h6vj/GHSA-xr69-7fhc-h6vj.json @@ -7,12 +7,8 @@ "CVE-2019-19308" ], "details": "In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xr82-vj36-ch3w/GHSA-xr82-vj36-ch3w.json b/advisories/unreviewed/2022/05/GHSA-xr82-vj36-ch3w/GHSA-xr82-vj36-ch3w.json index 080e0a7da44..c09228fcac0 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr82-vj36-ch3w/GHSA-xr82-vj36-ch3w.json +++ b/advisories/unreviewed/2022/05/GHSA-xr82-vj36-ch3w/GHSA-xr82-vj36-ch3w.json @@ -7,12 +7,8 @@ "CVE-2019-15298" ], "details": "A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xrw7-9m6r-77jp/GHSA-xrw7-9m6r-77jp.json b/advisories/unreviewed/2022/05/GHSA-xrw7-9m6r-77jp/GHSA-xrw7-9m6r-77jp.json index 6f84700d776..31cba813b6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrw7-9m6r-77jp/GHSA-xrw7-9m6r-77jp.json +++ b/advisories/unreviewed/2022/05/GHSA-xrw7-9m6r-77jp/GHSA-xrw7-9m6r-77jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvh3-9p5j-3q4f/GHSA-xvh3-9p5j-3q4f.json b/advisories/unreviewed/2022/05/GHSA-xvh3-9p5j-3q4f/GHSA-xvh3-9p5j-3q4f.json index 10c3788997c..10ac0a3f97d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvh3-9p5j-3q4f/GHSA-xvh3-9p5j-3q4f.json +++ b/advisories/unreviewed/2022/05/GHSA-xvh3-9p5j-3q4f/GHSA-xvh3-9p5j-3q4f.json @@ -7,12 +7,8 @@ "CVE-2019-13686" ], "details": "Use after free in offline mode in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwp8-fr9p-xj9v/GHSA-xwp8-fr9p-xj9v.json b/advisories/unreviewed/2022/05/GHSA-xwp8-fr9p-xj9v/GHSA-xwp8-fr9p-xj9v.json index ef69bf6265f..5d0205b0efc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwp8-fr9p-xj9v/GHSA-xwp8-fr9p-xj9v.json +++ b/advisories/unreviewed/2022/05/GHSA-xwp8-fr9p-xj9v/GHSA-xwp8-fr9p-xj9v.json @@ -7,12 +7,8 @@ "CVE-2006-0511" ], "details": "** DISPUTED ** Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, saying that \"This is a customer specific issue related to their Kerberos authentication single sign-on application and not a vulnerability in the Blackboard product.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xxhg-xvhq-pmx2/GHSA-xxhg-xvhq-pmx2.json b/advisories/unreviewed/2022/05/GHSA-xxhg-xvhq-pmx2/GHSA-xxhg-xvhq-pmx2.json index 587c032c7ef..d471711e840 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxhg-xvhq-pmx2/GHSA-xxhg-xvhq-pmx2.json +++ b/advisories/unreviewed/2022/05/GHSA-xxhg-xvhq-pmx2/GHSA-xxhg-xvhq-pmx2.json @@ -7,12 +7,8 @@ "CVE-2019-5869" ], "details": "Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xxr3-85vr-f7wf/GHSA-xxr3-85vr-f7wf.json b/advisories/unreviewed/2022/05/GHSA-xxr3-85vr-f7wf/GHSA-xxr3-85vr-f7wf.json index 2815b007afc..1065b88648e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxr3-85vr-f7wf/GHSA-xxr3-85vr-f7wf.json +++ b/advisories/unreviewed/2022/05/GHSA-xxr3-85vr-f7wf/GHSA-xxr3-85vr-f7wf.json @@ -7,12 +7,8 @@ "CVE-2019-19364" ], "details": "In Sony Catalyst Production Suite through 2019.1 (1.1.0.21) and Catalyst Browse through 2019.1 (1.1.0.21), an unprivileged user can obtain admin privileges, and execute a program as admin, after DLL hijacking of a DLL that is loaded during setup (installation).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json b/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json index e5d1dca7f70..ea06f6e342d 100644 --- a/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json +++ b/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json b/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json index 14640741ffa..b61307d802a 100644 --- a/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json +++ b/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-27m4-83f2-2x77/GHSA-27m4-83f2-2x77.json b/advisories/unreviewed/2022/09/GHSA-27m4-83f2-2x77/GHSA-27m4-83f2-2x77.json index 901ce533b7b..88b978d3751 100644 --- a/advisories/unreviewed/2022/09/GHSA-27m4-83f2-2x77/GHSA-27m4-83f2-2x77.json +++ b/advisories/unreviewed/2022/09/GHSA-27m4-83f2-2x77/GHSA-27m4-83f2-2x77.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-29pj-cw86-x2fg/GHSA-29pj-cw86-x2fg.json b/advisories/unreviewed/2022/09/GHSA-29pj-cw86-x2fg/GHSA-29pj-cw86-x2fg.json index c64e798af69..d5f82a79afb 100644 --- a/advisories/unreviewed/2022/09/GHSA-29pj-cw86-x2fg/GHSA-29pj-cw86-x2fg.json +++ b/advisories/unreviewed/2022/09/GHSA-29pj-cw86-x2fg/GHSA-29pj-cw86-x2fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json b/advisories/unreviewed/2022/09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json index 6a925fa434f..40eff9b7aab 100644 --- a/advisories/unreviewed/2022/09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json +++ b/advisories/unreviewed/2022/09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json b/advisories/unreviewed/2022/09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json index 49751794810..0a96528a4c8 100644 --- a/advisories/unreviewed/2022/09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json +++ b/advisories/unreviewed/2022/09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-5g39-p52c-vm53/GHSA-5g39-p52c-vm53.json b/advisories/unreviewed/2022/09/GHSA-5g39-p52c-vm53/GHSA-5g39-p52c-vm53.json index 5b2d30ff96d..5ebd67262ac 100644 --- a/advisories/unreviewed/2022/09/GHSA-5g39-p52c-vm53/GHSA-5g39-p52c-vm53.json +++ b/advisories/unreviewed/2022/09/GHSA-5g39-p52c-vm53/GHSA-5g39-p52c-vm53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json b/advisories/unreviewed/2022/09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json index cd65e73fd82..da9cf9097cd 100644 --- a/advisories/unreviewed/2022/09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json +++ b/advisories/unreviewed/2022/09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-692h-cj57-w2g9/GHSA-692h-cj57-w2g9.json b/advisories/unreviewed/2022/09/GHSA-692h-cj57-w2g9/GHSA-692h-cj57-w2g9.json index 7b328c98ed4..2ef8654bb82 100644 --- a/advisories/unreviewed/2022/09/GHSA-692h-cj57-w2g9/GHSA-692h-cj57-w2g9.json +++ b/advisories/unreviewed/2022/09/GHSA-692h-cj57-w2g9/GHSA-692h-cj57-w2g9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json b/advisories/unreviewed/2022/09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json index e5c10d456cb..90f825a7e08 100644 --- a/advisories/unreviewed/2022/09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json +++ b/advisories/unreviewed/2022/09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json b/advisories/unreviewed/2022/09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json index 0cc626f7610..12a210ff8d6 100644 --- a/advisories/unreviewed/2022/09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json +++ b/advisories/unreviewed/2022/09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-738c-cx4m-7gvx/GHSA-738c-cx4m-7gvx.json b/advisories/unreviewed/2022/09/GHSA-738c-cx4m-7gvx/GHSA-738c-cx4m-7gvx.json index 5b9c0ba60c3..fc004295a1b 100644 --- a/advisories/unreviewed/2022/09/GHSA-738c-cx4m-7gvx/GHSA-738c-cx4m-7gvx.json +++ b/advisories/unreviewed/2022/09/GHSA-738c-cx4m-7gvx/GHSA-738c-cx4m-7gvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-74m6-rqc7-wfvx/GHSA-74m6-rqc7-wfvx.json b/advisories/unreviewed/2022/09/GHSA-74m6-rqc7-wfvx/GHSA-74m6-rqc7-wfvx.json index 18b8995d9a9..201688421f2 100644 --- a/advisories/unreviewed/2022/09/GHSA-74m6-rqc7-wfvx/GHSA-74m6-rqc7-wfvx.json +++ b/advisories/unreviewed/2022/09/GHSA-74m6-rqc7-wfvx/GHSA-74m6-rqc7-wfvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-75p4-j454-hrjv/GHSA-75p4-j454-hrjv.json b/advisories/unreviewed/2022/09/GHSA-75p4-j454-hrjv/GHSA-75p4-j454-hrjv.json index 6b5023ee090..f451fac8928 100644 --- a/advisories/unreviewed/2022/09/GHSA-75p4-j454-hrjv/GHSA-75p4-j454-hrjv.json +++ b/advisories/unreviewed/2022/09/GHSA-75p4-j454-hrjv/GHSA-75p4-j454-hrjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-82hg-7wf7-rhvf/GHSA-82hg-7wf7-rhvf.json b/advisories/unreviewed/2022/09/GHSA-82hg-7wf7-rhvf/GHSA-82hg-7wf7-rhvf.json index 3814a678e27..62a965a7c2b 100644 --- a/advisories/unreviewed/2022/09/GHSA-82hg-7wf7-rhvf/GHSA-82hg-7wf7-rhvf.json +++ b/advisories/unreviewed/2022/09/GHSA-82hg-7wf7-rhvf/GHSA-82hg-7wf7-rhvf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json b/advisories/unreviewed/2022/09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json index 5b411777539..99020fe614f 100644 --- a/advisories/unreviewed/2022/09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json +++ b/advisories/unreviewed/2022/09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json b/advisories/unreviewed/2022/09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json index 483735ddba7..41648bcadea 100644 --- a/advisories/unreviewed/2022/09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json +++ b/advisories/unreviewed/2022/09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-9fj7-9qg7-9fgc/GHSA-9fj7-9qg7-9fgc.json b/advisories/unreviewed/2022/09/GHSA-9fj7-9qg7-9fgc/GHSA-9fj7-9qg7-9fgc.json index d881df5b681..a95276366e8 100644 --- a/advisories/unreviewed/2022/09/GHSA-9fj7-9qg7-9fgc/GHSA-9fj7-9qg7-9fgc.json +++ b/advisories/unreviewed/2022/09/GHSA-9fj7-9qg7-9fgc/GHSA-9fj7-9qg7-9fgc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-9rwx-hp6q-64m8/GHSA-9rwx-hp6q-64m8.json b/advisories/unreviewed/2022/09/GHSA-9rwx-hp6q-64m8/GHSA-9rwx-hp6q-64m8.json index 73bb2bb0dd6..a7cb2627ef3 100644 --- a/advisories/unreviewed/2022/09/GHSA-9rwx-hp6q-64m8/GHSA-9rwx-hp6q-64m8.json +++ b/advisories/unreviewed/2022/09/GHSA-9rwx-hp6q-64m8/GHSA-9rwx-hp6q-64m8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-c38j-ccr2-v3jw/GHSA-c38j-ccr2-v3jw.json b/advisories/unreviewed/2022/09/GHSA-c38j-ccr2-v3jw/GHSA-c38j-ccr2-v3jw.json index 759557efd2f..4bd27022aa9 100644 --- a/advisories/unreviewed/2022/09/GHSA-c38j-ccr2-v3jw/GHSA-c38j-ccr2-v3jw.json +++ b/advisories/unreviewed/2022/09/GHSA-c38j-ccr2-v3jw/GHSA-c38j-ccr2-v3jw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json b/advisories/unreviewed/2022/09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json index 6c838453824..713b817616d 100644 --- a/advisories/unreviewed/2022/09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json +++ b/advisories/unreviewed/2022/09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-cfqx-4cch-8hgx/GHSA-cfqx-4cch-8hgx.json b/advisories/unreviewed/2022/09/GHSA-cfqx-4cch-8hgx/GHSA-cfqx-4cch-8hgx.json index 839f26c43e9..81d34500cd2 100644 --- a/advisories/unreviewed/2022/09/GHSA-cfqx-4cch-8hgx/GHSA-cfqx-4cch-8hgx.json +++ b/advisories/unreviewed/2022/09/GHSA-cfqx-4cch-8hgx/GHSA-cfqx-4cch-8hgx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json b/advisories/unreviewed/2022/09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json index 0666e516ef5..a77dab9c451 100644 --- a/advisories/unreviewed/2022/09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json +++ b/advisories/unreviewed/2022/09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-m7rj-3phc-xm3w/GHSA-m7rj-3phc-xm3w.json b/advisories/unreviewed/2022/09/GHSA-m7rj-3phc-xm3w/GHSA-m7rj-3phc-xm3w.json index 10bcfb7ac6e..3e7572b6e02 100644 --- a/advisories/unreviewed/2022/09/GHSA-m7rj-3phc-xm3w/GHSA-m7rj-3phc-xm3w.json +++ b/advisories/unreviewed/2022/09/GHSA-m7rj-3phc-xm3w/GHSA-m7rj-3phc-xm3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-mcxh-2w23-3cf7/GHSA-mcxh-2w23-3cf7.json b/advisories/unreviewed/2022/09/GHSA-mcxh-2w23-3cf7/GHSA-mcxh-2w23-3cf7.json index 389500d97df..a3fc281cb0c 100644 --- a/advisories/unreviewed/2022/09/GHSA-mcxh-2w23-3cf7/GHSA-mcxh-2w23-3cf7.json +++ b/advisories/unreviewed/2022/09/GHSA-mcxh-2w23-3cf7/GHSA-mcxh-2w23-3cf7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json b/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json index 2f79266eae4..0b79b230c0b 100644 --- a/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json +++ b/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-p235-xqcv-9xrg/GHSA-p235-xqcv-9xrg.json b/advisories/unreviewed/2022/09/GHSA-p235-xqcv-9xrg/GHSA-p235-xqcv-9xrg.json index 31a00068f9d..586c9f69a9b 100644 --- a/advisories/unreviewed/2022/09/GHSA-p235-xqcv-9xrg/GHSA-p235-xqcv-9xrg.json +++ b/advisories/unreviewed/2022/09/GHSA-p235-xqcv-9xrg/GHSA-p235-xqcv-9xrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json b/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json index 67ada81dd38..188d92009c8 100644 --- a/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json +++ b/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-p8vh-mwc9-r3jw/GHSA-p8vh-mwc9-r3jw.json b/advisories/unreviewed/2022/09/GHSA-p8vh-mwc9-r3jw/GHSA-p8vh-mwc9-r3jw.json index c8978d29527..a4bd3e16add 100644 --- a/advisories/unreviewed/2022/09/GHSA-p8vh-mwc9-r3jw/GHSA-p8vh-mwc9-r3jw.json +++ b/advisories/unreviewed/2022/09/GHSA-p8vh-mwc9-r3jw/GHSA-p8vh-mwc9-r3jw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json b/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json index bb85bffd37f..25b3bda173c 100644 --- a/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json +++ b/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-qv87-xvw7-xfrc/GHSA-qv87-xvw7-xfrc.json b/advisories/unreviewed/2022/09/GHSA-qv87-xvw7-xfrc/GHSA-qv87-xvw7-xfrc.json index 3854f969097..5c40dde3f30 100644 --- a/advisories/unreviewed/2022/09/GHSA-qv87-xvw7-xfrc/GHSA-qv87-xvw7-xfrc.json +++ b/advisories/unreviewed/2022/09/GHSA-qv87-xvw7-xfrc/GHSA-qv87-xvw7-xfrc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-r5vg-678j-p7m4/GHSA-r5vg-678j-p7m4.json b/advisories/unreviewed/2022/09/GHSA-r5vg-678j-p7m4/GHSA-r5vg-678j-p7m4.json index 899ea0c246c..ff8e822bf7f 100644 --- a/advisories/unreviewed/2022/09/GHSA-r5vg-678j-p7m4/GHSA-r5vg-678j-p7m4.json +++ b/advisories/unreviewed/2022/09/GHSA-r5vg-678j-p7m4/GHSA-r5vg-678j-p7m4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-rjp4-q5qr-3cqx/GHSA-rjp4-q5qr-3cqx.json b/advisories/unreviewed/2022/09/GHSA-rjp4-q5qr-3cqx/GHSA-rjp4-q5qr-3cqx.json index 8824ceec7c3..0116ab97dc8 100644 --- a/advisories/unreviewed/2022/09/GHSA-rjp4-q5qr-3cqx/GHSA-rjp4-q5qr-3cqx.json +++ b/advisories/unreviewed/2022/09/GHSA-rjp4-q5qr-3cqx/GHSA-rjp4-q5qr-3cqx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-v44q-v8rf-3m92/GHSA-v44q-v8rf-3m92.json b/advisories/unreviewed/2022/09/GHSA-v44q-v8rf-3m92/GHSA-v44q-v8rf-3m92.json index f4c317f24b1..09b0a2d16e8 100644 --- a/advisories/unreviewed/2022/09/GHSA-v44q-v8rf-3m92/GHSA-v44q-v8rf-3m92.json +++ b/advisories/unreviewed/2022/09/GHSA-v44q-v8rf-3m92/GHSA-v44q-v8rf-3m92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-v5mm-c2pr-7qgh/GHSA-v5mm-c2pr-7qgh.json b/advisories/unreviewed/2022/09/GHSA-v5mm-c2pr-7qgh/GHSA-v5mm-c2pr-7qgh.json index 22a0481a389..470a746bff4 100644 --- a/advisories/unreviewed/2022/09/GHSA-v5mm-c2pr-7qgh/GHSA-v5mm-c2pr-7qgh.json +++ b/advisories/unreviewed/2022/09/GHSA-v5mm-c2pr-7qgh/GHSA-v5mm-c2pr-7qgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json b/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json index 88503699213..ff2dcb3f849 100644 --- a/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json +++ b/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json b/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json index 9e153c6d04b..313daa0c462 100644 --- a/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json +++ b/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-xx24-pg44-2jhw/GHSA-xx24-pg44-2jhw.json b/advisories/unreviewed/2022/09/GHSA-xx24-pg44-2jhw/GHSA-xx24-pg44-2jhw.json index 2ded2745c18..c3637c44ad8 100644 --- a/advisories/unreviewed/2022/09/GHSA-xx24-pg44-2jhw/GHSA-xx24-pg44-2jhw.json +++ b/advisories/unreviewed/2022/09/GHSA-xx24-pg44-2jhw/GHSA-xx24-pg44-2jhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-25gc-rgw2-hc8g/GHSA-25gc-rgw2-hc8g.json b/advisories/unreviewed/2022/10/GHSA-25gc-rgw2-hc8g/GHSA-25gc-rgw2-hc8g.json index 1f9561147e5..e800161e222 100644 --- a/advisories/unreviewed/2022/10/GHSA-25gc-rgw2-hc8g/GHSA-25gc-rgw2-hc8g.json +++ b/advisories/unreviewed/2022/10/GHSA-25gc-rgw2-hc8g/GHSA-25gc-rgw2-hc8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-4rj6-gcf8-wchc/GHSA-4rj6-gcf8-wchc.json b/advisories/unreviewed/2022/10/GHSA-4rj6-gcf8-wchc/GHSA-4rj6-gcf8-wchc.json index 9db50fa36c2..9dd1fbe4d6c 100644 --- a/advisories/unreviewed/2022/10/GHSA-4rj6-gcf8-wchc/GHSA-4rj6-gcf8-wchc.json +++ b/advisories/unreviewed/2022/10/GHSA-4rj6-gcf8-wchc/GHSA-4rj6-gcf8-wchc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-58rh-q4r8-94g3/GHSA-58rh-q4r8-94g3.json b/advisories/unreviewed/2022/10/GHSA-58rh-q4r8-94g3/GHSA-58rh-q4r8-94g3.json index 62936984ca8..bf8a679754d 100644 --- a/advisories/unreviewed/2022/10/GHSA-58rh-q4r8-94g3/GHSA-58rh-q4r8-94g3.json +++ b/advisories/unreviewed/2022/10/GHSA-58rh-q4r8-94g3/GHSA-58rh-q4r8-94g3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-64qv-9rcm-pfxv/GHSA-64qv-9rcm-pfxv.json b/advisories/unreviewed/2022/10/GHSA-64qv-9rcm-pfxv/GHSA-64qv-9rcm-pfxv.json index af7d53ab203..72a01c4654c 100644 --- a/advisories/unreviewed/2022/10/GHSA-64qv-9rcm-pfxv/GHSA-64qv-9rcm-pfxv.json +++ b/advisories/unreviewed/2022/10/GHSA-64qv-9rcm-pfxv/GHSA-64qv-9rcm-pfxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-8658-c36g-5m8j/GHSA-8658-c36g-5m8j.json b/advisories/unreviewed/2022/10/GHSA-8658-c36g-5m8j/GHSA-8658-c36g-5m8j.json index d0267d86e8e..fef07757572 100644 --- a/advisories/unreviewed/2022/10/GHSA-8658-c36g-5m8j/GHSA-8658-c36g-5m8j.json +++ b/advisories/unreviewed/2022/10/GHSA-8658-c36g-5m8j/GHSA-8658-c36g-5m8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-cpc4-rhwg-5qx7/GHSA-cpc4-rhwg-5qx7.json b/advisories/unreviewed/2022/10/GHSA-cpc4-rhwg-5qx7/GHSA-cpc4-rhwg-5qx7.json index 01fb4edbefa..2f6142489cd 100644 --- a/advisories/unreviewed/2022/10/GHSA-cpc4-rhwg-5qx7/GHSA-cpc4-rhwg-5qx7.json +++ b/advisories/unreviewed/2022/10/GHSA-cpc4-rhwg-5qx7/GHSA-cpc4-rhwg-5qx7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-f73x-whqx-6jm2/GHSA-f73x-whqx-6jm2.json b/advisories/unreviewed/2022/10/GHSA-f73x-whqx-6jm2/GHSA-f73x-whqx-6jm2.json index 6ad22f65cfa..fb876fb32b0 100644 --- a/advisories/unreviewed/2022/10/GHSA-f73x-whqx-6jm2/GHSA-f73x-whqx-6jm2.json +++ b/advisories/unreviewed/2022/10/GHSA-f73x-whqx-6jm2/GHSA-f73x-whqx-6jm2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-gcvm-jx53-vhrj/GHSA-gcvm-jx53-vhrj.json b/advisories/unreviewed/2022/10/GHSA-gcvm-jx53-vhrj/GHSA-gcvm-jx53-vhrj.json index 3621ad2b4c4..77db497978b 100644 --- a/advisories/unreviewed/2022/10/GHSA-gcvm-jx53-vhrj/GHSA-gcvm-jx53-vhrj.json +++ b/advisories/unreviewed/2022/10/GHSA-gcvm-jx53-vhrj/GHSA-gcvm-jx53-vhrj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-gq3r-53wg-9xgg/GHSA-gq3r-53wg-9xgg.json b/advisories/unreviewed/2022/10/GHSA-gq3r-53wg-9xgg/GHSA-gq3r-53wg-9xgg.json index 837414db24d..c7bc334e7c2 100644 --- a/advisories/unreviewed/2022/10/GHSA-gq3r-53wg-9xgg/GHSA-gq3r-53wg-9xgg.json +++ b/advisories/unreviewed/2022/10/GHSA-gq3r-53wg-9xgg/GHSA-gq3r-53wg-9xgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-jj9p-6gqv-vr9g/GHSA-jj9p-6gqv-vr9g.json b/advisories/unreviewed/2022/10/GHSA-jj9p-6gqv-vr9g/GHSA-jj9p-6gqv-vr9g.json index 91003669ff2..1648c7f8349 100644 --- a/advisories/unreviewed/2022/10/GHSA-jj9p-6gqv-vr9g/GHSA-jj9p-6gqv-vr9g.json +++ b/advisories/unreviewed/2022/10/GHSA-jj9p-6gqv-vr9g/GHSA-jj9p-6gqv-vr9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-m36r-vqcv-84cm/GHSA-m36r-vqcv-84cm.json b/advisories/unreviewed/2022/10/GHSA-m36r-vqcv-84cm/GHSA-m36r-vqcv-84cm.json index 69976d609a3..161d7e74583 100644 --- a/advisories/unreviewed/2022/10/GHSA-m36r-vqcv-84cm/GHSA-m36r-vqcv-84cm.json +++ b/advisories/unreviewed/2022/10/GHSA-m36r-vqcv-84cm/GHSA-m36r-vqcv-84cm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-mm96-m286-2v7r/GHSA-mm96-m286-2v7r.json b/advisories/unreviewed/2022/10/GHSA-mm96-m286-2v7r/GHSA-mm96-m286-2v7r.json index fa2d4195e64..cc11294a38e 100644 --- a/advisories/unreviewed/2022/10/GHSA-mm96-m286-2v7r/GHSA-mm96-m286-2v7r.json +++ b/advisories/unreviewed/2022/10/GHSA-mm96-m286-2v7r/GHSA-mm96-m286-2v7r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-p6m5-777x-4f3g/GHSA-p6m5-777x-4f3g.json b/advisories/unreviewed/2022/10/GHSA-p6m5-777x-4f3g/GHSA-p6m5-777x-4f3g.json index 42b8766ffdc..77ae11015cc 100644 --- a/advisories/unreviewed/2022/10/GHSA-p6m5-777x-4f3g/GHSA-p6m5-777x-4f3g.json +++ b/advisories/unreviewed/2022/10/GHSA-p6m5-777x-4f3g/GHSA-p6m5-777x-4f3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-q598-jq34-rwrr/GHSA-q598-jq34-rwrr.json b/advisories/unreviewed/2022/10/GHSA-q598-jq34-rwrr/GHSA-q598-jq34-rwrr.json index 7c8b37f3cdb..f4345617f47 100644 --- a/advisories/unreviewed/2022/10/GHSA-q598-jq34-rwrr/GHSA-q598-jq34-rwrr.json +++ b/advisories/unreviewed/2022/10/GHSA-q598-jq34-rwrr/GHSA-q598-jq34-rwrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-qjvf-mwxj-x748/GHSA-qjvf-mwxj-x748.json b/advisories/unreviewed/2022/10/GHSA-qjvf-mwxj-x748/GHSA-qjvf-mwxj-x748.json index dae87fe5148..3d69ba74401 100644 --- a/advisories/unreviewed/2022/10/GHSA-qjvf-mwxj-x748/GHSA-qjvf-mwxj-x748.json +++ b/advisories/unreviewed/2022/10/GHSA-qjvf-mwxj-x748/GHSA-qjvf-mwxj-x748.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-rf3v-8qgp-pp24/GHSA-rf3v-8qgp-pp24.json b/advisories/unreviewed/2022/10/GHSA-rf3v-8qgp-pp24/GHSA-rf3v-8qgp-pp24.json index 1a87e2f0475..1eaccfd7667 100644 --- a/advisories/unreviewed/2022/10/GHSA-rf3v-8qgp-pp24/GHSA-rf3v-8qgp-pp24.json +++ b/advisories/unreviewed/2022/10/GHSA-rf3v-8qgp-pp24/GHSA-rf3v-8qgp-pp24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-rw3j-949g-mvhg/GHSA-rw3j-949g-mvhg.json b/advisories/unreviewed/2022/10/GHSA-rw3j-949g-mvhg/GHSA-rw3j-949g-mvhg.json index 548352bc94c..969330a88fa 100644 --- a/advisories/unreviewed/2022/10/GHSA-rw3j-949g-mvhg/GHSA-rw3j-949g-mvhg.json +++ b/advisories/unreviewed/2022/10/GHSA-rw3j-949g-mvhg/GHSA-rw3j-949g-mvhg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-v94w-gwp7-675c/GHSA-v94w-gwp7-675c.json b/advisories/unreviewed/2022/10/GHSA-v94w-gwp7-675c/GHSA-v94w-gwp7-675c.json index 797694096f4..7b53cd20124 100644 --- a/advisories/unreviewed/2022/10/GHSA-v94w-gwp7-675c/GHSA-v94w-gwp7-675c.json +++ b/advisories/unreviewed/2022/10/GHSA-v94w-gwp7-675c/GHSA-v94w-gwp7-675c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-vmjw-wrqg-9457/GHSA-vmjw-wrqg-9457.json b/advisories/unreviewed/2022/10/GHSA-vmjw-wrqg-9457/GHSA-vmjw-wrqg-9457.json index 5c80006c1d4..75ca95bc58e 100644 --- a/advisories/unreviewed/2022/10/GHSA-vmjw-wrqg-9457/GHSA-vmjw-wrqg-9457.json +++ b/advisories/unreviewed/2022/10/GHSA-vmjw-wrqg-9457/GHSA-vmjw-wrqg-9457.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-w4cr-xjrm-vrc8/GHSA-w4cr-xjrm-vrc8.json b/advisories/unreviewed/2022/10/GHSA-w4cr-xjrm-vrc8/GHSA-w4cr-xjrm-vrc8.json index b1b9f104da7..83d9e1eb298 100644 --- a/advisories/unreviewed/2022/10/GHSA-w4cr-xjrm-vrc8/GHSA-w4cr-xjrm-vrc8.json +++ b/advisories/unreviewed/2022/10/GHSA-w4cr-xjrm-vrc8/GHSA-w4cr-xjrm-vrc8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-x4cp-qc28-2pqp/GHSA-x4cp-qc28-2pqp.json b/advisories/unreviewed/2022/10/GHSA-x4cp-qc28-2pqp/GHSA-x4cp-qc28-2pqp.json index 095ff954203..51733f62bb4 100644 --- a/advisories/unreviewed/2022/10/GHSA-x4cp-qc28-2pqp/GHSA-x4cp-qc28-2pqp.json +++ b/advisories/unreviewed/2022/10/GHSA-x4cp-qc28-2pqp/GHSA-x4cp-qc28-2pqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-745w-p4gm-x2vw/GHSA-745w-p4gm-x2vw.json b/advisories/unreviewed/2022/11/GHSA-745w-p4gm-x2vw/GHSA-745w-p4gm-x2vw.json index 20243d4772f..730f2bde451 100644 --- a/advisories/unreviewed/2022/11/GHSA-745w-p4gm-x2vw/GHSA-745w-p4gm-x2vw.json +++ b/advisories/unreviewed/2022/11/GHSA-745w-p4gm-x2vw/GHSA-745w-p4gm-x2vw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-993x-6558-2xmj/GHSA-993x-6558-2xmj.json b/advisories/unreviewed/2022/12/GHSA-993x-6558-2xmj/GHSA-993x-6558-2xmj.json index b86dbe8bd93..85c600444ad 100644 --- a/advisories/unreviewed/2022/12/GHSA-993x-6558-2xmj/GHSA-993x-6558-2xmj.json +++ b/advisories/unreviewed/2022/12/GHSA-993x-6558-2xmj/GHSA-993x-6558-2xmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-hh7f-cch9-52mr/GHSA-hh7f-cch9-52mr.json b/advisories/unreviewed/2022/12/GHSA-hh7f-cch9-52mr/GHSA-hh7f-cch9-52mr.json index cd4c47b0013..90347b59658 100644 --- a/advisories/unreviewed/2022/12/GHSA-hh7f-cch9-52mr/GHSA-hh7f-cch9-52mr.json +++ b/advisories/unreviewed/2022/12/GHSA-hh7f-cch9-52mr/GHSA-hh7f-cch9-52mr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-249j-645x-c97w/GHSA-249j-645x-c97w.json b/advisories/unreviewed/2023/01/GHSA-249j-645x-c97w/GHSA-249j-645x-c97w.json index 41b13ae9d8d..101f3485174 100644 --- a/advisories/unreviewed/2023/01/GHSA-249j-645x-c97w/GHSA-249j-645x-c97w.json +++ b/advisories/unreviewed/2023/01/GHSA-249j-645x-c97w/GHSA-249j-645x-c97w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-2x79-g9jx-q9f2/GHSA-2x79-g9jx-q9f2.json b/advisories/unreviewed/2023/01/GHSA-2x79-g9jx-q9f2/GHSA-2x79-g9jx-q9f2.json index f761eefd7b8..5b99393cddf 100644 --- a/advisories/unreviewed/2023/01/GHSA-2x79-g9jx-q9f2/GHSA-2x79-g9jx-q9f2.json +++ b/advisories/unreviewed/2023/01/GHSA-2x79-g9jx-q9f2/GHSA-2x79-g9jx-q9f2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-55c3-g238-6jv4/GHSA-55c3-g238-6jv4.json b/advisories/unreviewed/2023/01/GHSA-55c3-g238-6jv4/GHSA-55c3-g238-6jv4.json index 26babc97de2..4e8d106c660 100644 --- a/advisories/unreviewed/2023/01/GHSA-55c3-g238-6jv4/GHSA-55c3-g238-6jv4.json +++ b/advisories/unreviewed/2023/01/GHSA-55c3-g238-6jv4/GHSA-55c3-g238-6jv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-9749-rqrj-vcqj/GHSA-9749-rqrj-vcqj.json b/advisories/unreviewed/2023/01/GHSA-9749-rqrj-vcqj/GHSA-9749-rqrj-vcqj.json index 74e6c7b2a5d..9ba3a746b9f 100644 --- a/advisories/unreviewed/2023/01/GHSA-9749-rqrj-vcqj/GHSA-9749-rqrj-vcqj.json +++ b/advisories/unreviewed/2023/01/GHSA-9749-rqrj-vcqj/GHSA-9749-rqrj-vcqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-99v4-pprm-ghh2/GHSA-99v4-pprm-ghh2.json b/advisories/unreviewed/2023/01/GHSA-99v4-pprm-ghh2/GHSA-99v4-pprm-ghh2.json index c6945d9d0a4..5175a4cd2f0 100644 --- a/advisories/unreviewed/2023/01/GHSA-99v4-pprm-ghh2/GHSA-99v4-pprm-ghh2.json +++ b/advisories/unreviewed/2023/01/GHSA-99v4-pprm-ghh2/GHSA-99v4-pprm-ghh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-9j25-3cvc-f5hg/GHSA-9j25-3cvc-f5hg.json b/advisories/unreviewed/2023/01/GHSA-9j25-3cvc-f5hg/GHSA-9j25-3cvc-f5hg.json index 3ab22775a74..f1d2266a602 100644 --- a/advisories/unreviewed/2023/01/GHSA-9j25-3cvc-f5hg/GHSA-9j25-3cvc-f5hg.json +++ b/advisories/unreviewed/2023/01/GHSA-9j25-3cvc-f5hg/GHSA-9j25-3cvc-f5hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-9m3w-rfcw-cvp3/GHSA-9m3w-rfcw-cvp3.json b/advisories/unreviewed/2023/01/GHSA-9m3w-rfcw-cvp3/GHSA-9m3w-rfcw-cvp3.json index cd56c595b62..83821deb8da 100644 --- a/advisories/unreviewed/2023/01/GHSA-9m3w-rfcw-cvp3/GHSA-9m3w-rfcw-cvp3.json +++ b/advisories/unreviewed/2023/01/GHSA-9m3w-rfcw-cvp3/GHSA-9m3w-rfcw-cvp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-gf2w-gwrg-m3gv/GHSA-gf2w-gwrg-m3gv.json b/advisories/unreviewed/2023/01/GHSA-gf2w-gwrg-m3gv/GHSA-gf2w-gwrg-m3gv.json index 4adfac71db8..76d8d2e699f 100644 --- a/advisories/unreviewed/2023/01/GHSA-gf2w-gwrg-m3gv/GHSA-gf2w-gwrg-m3gv.json +++ b/advisories/unreviewed/2023/01/GHSA-gf2w-gwrg-m3gv/GHSA-gf2w-gwrg-m3gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-jgc3-x572-hr2h/GHSA-jgc3-x572-hr2h.json b/advisories/unreviewed/2023/01/GHSA-jgc3-x572-hr2h/GHSA-jgc3-x572-hr2h.json index a5d71008957..218a3a74784 100644 --- a/advisories/unreviewed/2023/01/GHSA-jgc3-x572-hr2h/GHSA-jgc3-x572-hr2h.json +++ b/advisories/unreviewed/2023/01/GHSA-jgc3-x572-hr2h/GHSA-jgc3-x572-hr2h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-m9c9-fqf4-w6xr/GHSA-m9c9-fqf4-w6xr.json b/advisories/unreviewed/2023/01/GHSA-m9c9-fqf4-w6xr/GHSA-m9c9-fqf4-w6xr.json index 320df3d5c07..90b44b26251 100644 --- a/advisories/unreviewed/2023/01/GHSA-m9c9-fqf4-w6xr/GHSA-m9c9-fqf4-w6xr.json +++ b/advisories/unreviewed/2023/01/GHSA-m9c9-fqf4-w6xr/GHSA-m9c9-fqf4-w6xr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-mp4c-w7j9-95f4/GHSA-mp4c-w7j9-95f4.json b/advisories/unreviewed/2023/01/GHSA-mp4c-w7j9-95f4/GHSA-mp4c-w7j9-95f4.json index a531148bfaf..49dd1387926 100644 --- a/advisories/unreviewed/2023/01/GHSA-mp4c-w7j9-95f4/GHSA-mp4c-w7j9-95f4.json +++ b/advisories/unreviewed/2023/01/GHSA-mp4c-w7j9-95f4/GHSA-mp4c-w7j9-95f4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-pfcx-mq53-xrff/GHSA-pfcx-mq53-xrff.json b/advisories/unreviewed/2023/01/GHSA-pfcx-mq53-xrff/GHSA-pfcx-mq53-xrff.json index ce5d83fcab1..d9a117350ff 100644 --- a/advisories/unreviewed/2023/01/GHSA-pfcx-mq53-xrff/GHSA-pfcx-mq53-xrff.json +++ b/advisories/unreviewed/2023/01/GHSA-pfcx-mq53-xrff/GHSA-pfcx-mq53-xrff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-vc9r-97qq-w3qh/GHSA-vc9r-97qq-w3qh.json b/advisories/unreviewed/2023/01/GHSA-vc9r-97qq-w3qh/GHSA-vc9r-97qq-w3qh.json index 9a795cb6cb5..9f47badbef5 100644 --- a/advisories/unreviewed/2023/01/GHSA-vc9r-97qq-w3qh/GHSA-vc9r-97qq-w3qh.json +++ b/advisories/unreviewed/2023/01/GHSA-vc9r-97qq-w3qh/GHSA-vc9r-97qq-w3qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-338m-rx6v-qqv5/GHSA-338m-rx6v-qqv5.json b/advisories/unreviewed/2023/02/GHSA-338m-rx6v-qqv5/GHSA-338m-rx6v-qqv5.json index 3105f93b17e..10dc97d25cf 100644 --- a/advisories/unreviewed/2023/02/GHSA-338m-rx6v-qqv5/GHSA-338m-rx6v-qqv5.json +++ b/advisories/unreviewed/2023/02/GHSA-338m-rx6v-qqv5/GHSA-338m-rx6v-qqv5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-59rv-395v-g9xw/GHSA-59rv-395v-g9xw.json b/advisories/unreviewed/2023/02/GHSA-59rv-395v-g9xw/GHSA-59rv-395v-g9xw.json index eea29618cbd..3233718ebe2 100644 --- a/advisories/unreviewed/2023/02/GHSA-59rv-395v-g9xw/GHSA-59rv-395v-g9xw.json +++ b/advisories/unreviewed/2023/02/GHSA-59rv-395v-g9xw/GHSA-59rv-395v-g9xw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-5fc7-wjrw-2jh4/GHSA-5fc7-wjrw-2jh4.json b/advisories/unreviewed/2023/02/GHSA-5fc7-wjrw-2jh4/GHSA-5fc7-wjrw-2jh4.json index 3c94dd1ce75..b3fb121f10a 100644 --- a/advisories/unreviewed/2023/02/GHSA-5fc7-wjrw-2jh4/GHSA-5fc7-wjrw-2jh4.json +++ b/advisories/unreviewed/2023/02/GHSA-5fc7-wjrw-2jh4/GHSA-5fc7-wjrw-2jh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-8p6c-rh83-4gp7/GHSA-8p6c-rh83-4gp7.json b/advisories/unreviewed/2023/02/GHSA-8p6c-rh83-4gp7/GHSA-8p6c-rh83-4gp7.json index 099fc82a34a..d3f0c26ee7e 100644 --- a/advisories/unreviewed/2023/02/GHSA-8p6c-rh83-4gp7/GHSA-8p6c-rh83-4gp7.json +++ b/advisories/unreviewed/2023/02/GHSA-8p6c-rh83-4gp7/GHSA-8p6c-rh83-4gp7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-cwj4-5mgc-phhv/GHSA-cwj4-5mgc-phhv.json b/advisories/unreviewed/2023/02/GHSA-cwj4-5mgc-phhv/GHSA-cwj4-5mgc-phhv.json index e507c17d6ea..3fbe285dc82 100644 --- a/advisories/unreviewed/2023/02/GHSA-cwj4-5mgc-phhv/GHSA-cwj4-5mgc-phhv.json +++ b/advisories/unreviewed/2023/02/GHSA-cwj4-5mgc-phhv/GHSA-cwj4-5mgc-phhv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-gw5r-2prc-4jj5/GHSA-gw5r-2prc-4jj5.json b/advisories/unreviewed/2023/02/GHSA-gw5r-2prc-4jj5/GHSA-gw5r-2prc-4jj5.json index 019b6bf1826..54b9cc569ca 100644 --- a/advisories/unreviewed/2023/02/GHSA-gw5r-2prc-4jj5/GHSA-gw5r-2prc-4jj5.json +++ b/advisories/unreviewed/2023/02/GHSA-gw5r-2prc-4jj5/GHSA-gw5r-2prc-4jj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-pp2p-5ghw-9ccc/GHSA-pp2p-5ghw-9ccc.json b/advisories/unreviewed/2023/02/GHSA-pp2p-5ghw-9ccc/GHSA-pp2p-5ghw-9ccc.json index 5ed54b6ccaa..451fce55480 100644 --- a/advisories/unreviewed/2023/02/GHSA-pp2p-5ghw-9ccc/GHSA-pp2p-5ghw-9ccc.json +++ b/advisories/unreviewed/2023/02/GHSA-pp2p-5ghw-9ccc/GHSA-pp2p-5ghw-9ccc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-4gxr-wffq-h9jh/GHSA-4gxr-wffq-h9jh.json b/advisories/unreviewed/2023/03/GHSA-4gxr-wffq-h9jh/GHSA-4gxr-wffq-h9jh.json index 1b390c6f9d6..b3938c83700 100644 --- a/advisories/unreviewed/2023/03/GHSA-4gxr-wffq-h9jh/GHSA-4gxr-wffq-h9jh.json +++ b/advisories/unreviewed/2023/03/GHSA-4gxr-wffq-h9jh/GHSA-4gxr-wffq-h9jh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-583v-9qpc-hx7x/GHSA-583v-9qpc-hx7x.json b/advisories/unreviewed/2023/03/GHSA-583v-9qpc-hx7x/GHSA-583v-9qpc-hx7x.json index 77f8ba2933b..3d226fca8e2 100644 --- a/advisories/unreviewed/2023/03/GHSA-583v-9qpc-hx7x/GHSA-583v-9qpc-hx7x.json +++ b/advisories/unreviewed/2023/03/GHSA-583v-9qpc-hx7x/GHSA-583v-9qpc-hx7x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-cqf6-7wvc-xg52/GHSA-cqf6-7wvc-xg52.json b/advisories/unreviewed/2023/03/GHSA-cqf6-7wvc-xg52/GHSA-cqf6-7wvc-xg52.json index 8381bc358cd..dc5481f158f 100644 --- a/advisories/unreviewed/2023/03/GHSA-cqf6-7wvc-xg52/GHSA-cqf6-7wvc-xg52.json +++ b/advisories/unreviewed/2023/03/GHSA-cqf6-7wvc-xg52/GHSA-cqf6-7wvc-xg52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-gcrf-r338-q8rq/GHSA-gcrf-r338-q8rq.json b/advisories/unreviewed/2023/03/GHSA-gcrf-r338-q8rq/GHSA-gcrf-r338-q8rq.json index bad32e9f018..f49aa2bb73b 100644 --- a/advisories/unreviewed/2023/03/GHSA-gcrf-r338-q8rq/GHSA-gcrf-r338-q8rq.json +++ b/advisories/unreviewed/2023/03/GHSA-gcrf-r338-q8rq/GHSA-gcrf-r338-q8rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/03/GHSA-gx8c-7452-frr8/GHSA-gx8c-7452-frr8.json b/advisories/unreviewed/2023/03/GHSA-gx8c-7452-frr8/GHSA-gx8c-7452-frr8.json index 80ef332a328..b505e8f685b 100644 --- a/advisories/unreviewed/2023/03/GHSA-gx8c-7452-frr8/GHSA-gx8c-7452-frr8.json +++ b/advisories/unreviewed/2023/03/GHSA-gx8c-7452-frr8/GHSA-gx8c-7452-frr8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-v972-h57q-v8pw/GHSA-v972-h57q-v8pw.json b/advisories/unreviewed/2023/05/GHSA-v972-h57q-v8pw/GHSA-v972-h57q-v8pw.json index 5ec8fd29317..df1851bfc81 100644 --- a/advisories/unreviewed/2023/05/GHSA-v972-h57q-v8pw/GHSA-v972-h57q-v8pw.json +++ b/advisories/unreviewed/2023/05/GHSA-v972-h57q-v8pw/GHSA-v972-h57q-v8pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-5fg8-8wg9-97x2/GHSA-5fg8-8wg9-97x2.json b/advisories/unreviewed/2023/06/GHSA-5fg8-8wg9-97x2/GHSA-5fg8-8wg9-97x2.json index b977d460044..08e41d610f4 100644 --- a/advisories/unreviewed/2023/06/GHSA-5fg8-8wg9-97x2/GHSA-5fg8-8wg9-97x2.json +++ b/advisories/unreviewed/2023/06/GHSA-5fg8-8wg9-97x2/GHSA-5fg8-8wg9-97x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-37c2-5chg-wwj7/GHSA-37c2-5chg-wwj7.json b/advisories/unreviewed/2023/07/GHSA-37c2-5chg-wwj7/GHSA-37c2-5chg-wwj7.json index 6036cbf33d1..6011b7ca1f4 100644 --- a/advisories/unreviewed/2023/07/GHSA-37c2-5chg-wwj7/GHSA-37c2-5chg-wwj7.json +++ b/advisories/unreviewed/2023/07/GHSA-37c2-5chg-wwj7/GHSA-37c2-5chg-wwj7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-3f53-3vgw-49w5/GHSA-3f53-3vgw-49w5.json b/advisories/unreviewed/2023/07/GHSA-3f53-3vgw-49w5/GHSA-3f53-3vgw-49w5.json index 3df42f48c37..44f8cf6209a 100644 --- a/advisories/unreviewed/2023/07/GHSA-3f53-3vgw-49w5/GHSA-3f53-3vgw-49w5.json +++ b/advisories/unreviewed/2023/07/GHSA-3f53-3vgw-49w5/GHSA-3f53-3vgw-49w5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-fj2m-7r3q-j27x/GHSA-fj2m-7r3q-j27x.json b/advisories/unreviewed/2023/07/GHSA-fj2m-7r3q-j27x/GHSA-fj2m-7r3q-j27x.json index 663c3522557..47ddddf9b4f 100644 --- a/advisories/unreviewed/2023/07/GHSA-fj2m-7r3q-j27x/GHSA-fj2m-7r3q-j27x.json +++ b/advisories/unreviewed/2023/07/GHSA-fj2m-7r3q-j27x/GHSA-fj2m-7r3q-j27x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-jhwx-fm67-385p/GHSA-jhwx-fm67-385p.json b/advisories/unreviewed/2023/07/GHSA-jhwx-fm67-385p/GHSA-jhwx-fm67-385p.json index 656dd948beb..f457169c1f5 100644 --- a/advisories/unreviewed/2023/07/GHSA-jhwx-fm67-385p/GHSA-jhwx-fm67-385p.json +++ b/advisories/unreviewed/2023/07/GHSA-jhwx-fm67-385p/GHSA-jhwx-fm67-385p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-jr8r-v8q8-phf2/GHSA-jr8r-v8q8-phf2.json b/advisories/unreviewed/2023/07/GHSA-jr8r-v8q8-phf2/GHSA-jr8r-v8q8-phf2.json index d5db4de05ee..959de1dc04f 100644 --- a/advisories/unreviewed/2023/07/GHSA-jr8r-v8q8-phf2/GHSA-jr8r-v8q8-phf2.json +++ b/advisories/unreviewed/2023/07/GHSA-jr8r-v8q8-phf2/GHSA-jr8r-v8q8-phf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-3537-379x-x582/GHSA-3537-379x-x582.json b/advisories/unreviewed/2024/03/GHSA-3537-379x-x582/GHSA-3537-379x-x582.json index a10a74c25f8..9413d259e84 100644 --- a/advisories/unreviewed/2024/03/GHSA-3537-379x-x582/GHSA-3537-379x-x582.json +++ b/advisories/unreviewed/2024/03/GHSA-3537-379x-x582/GHSA-3537-379x-x582.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json b/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json index 61be235e53a..ab0a5660638 100644 --- a/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json +++ b/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-6j3q-64jm-q33g/GHSA-6j3q-64jm-q33g.json b/advisories/unreviewed/2024/03/GHSA-6j3q-64jm-q33g/GHSA-6j3q-64jm-q33g.json index e465be700ef..4086049efc6 100644 --- a/advisories/unreviewed/2024/03/GHSA-6j3q-64jm-q33g/GHSA-6j3q-64jm-q33g.json +++ b/advisories/unreviewed/2024/03/GHSA-6j3q-64jm-q33g/GHSA-6j3q-64jm-q33g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -59,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-g2m6-m2m8-q4qh/GHSA-g2m6-m2m8-q4qh.json b/advisories/unreviewed/2024/03/GHSA-g2m6-m2m8-q4qh/GHSA-g2m6-m2m8-q4qh.json index 2856b04ca5a..406b21f2ff1 100644 --- a/advisories/unreviewed/2024/03/GHSA-g2m6-m2m8-q4qh/GHSA-g2m6-m2m8-q4qh.json +++ b/advisories/unreviewed/2024/03/GHSA-g2m6-m2m8-q4qh/GHSA-g2m6-m2m8-q4qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-g7cx-2g6j-fpvq/GHSA-g7cx-2g6j-fpvq.json b/advisories/unreviewed/2024/03/GHSA-g7cx-2g6j-fpvq/GHSA-g7cx-2g6j-fpvq.json index 2bd18db15a2..3cdb856b0a3 100644 --- a/advisories/unreviewed/2024/03/GHSA-g7cx-2g6j-fpvq/GHSA-g7cx-2g6j-fpvq.json +++ b/advisories/unreviewed/2024/03/GHSA-g7cx-2g6j-fpvq/GHSA-g7cx-2g6j-fpvq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-q4fq-56x3-rq98/GHSA-q4fq-56x3-rq98.json b/advisories/unreviewed/2024/03/GHSA-q4fq-56x3-rq98/GHSA-q4fq-56x3-rq98.json index 5bcdd2eb096..be94f22812b 100644 --- a/advisories/unreviewed/2024/03/GHSA-q4fq-56x3-rq98/GHSA-q4fq-56x3-rq98.json +++ b/advisories/unreviewed/2024/03/GHSA-q4fq-56x3-rq98/GHSA-q4fq-56x3-rq98.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-qgvx-mvf3-xw8r/GHSA-qgvx-mvf3-xw8r.json b/advisories/unreviewed/2024/03/GHSA-qgvx-mvf3-xw8r/GHSA-qgvx-mvf3-xw8r.json index 9adfd0520c3..a5d1c1ed114 100644 --- a/advisories/unreviewed/2024/03/GHSA-qgvx-mvf3-xw8r/GHSA-qgvx-mvf3-xw8r.json +++ b/advisories/unreviewed/2024/03/GHSA-qgvx-mvf3-xw8r/GHSA-qgvx-mvf3-xw8r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rmxq-q4j3-rg8f/GHSA-rmxq-q4j3-rg8f.json b/advisories/unreviewed/2024/03/GHSA-rmxq-q4j3-rg8f/GHSA-rmxq-q4j3-rg8f.json index 04da421a2c5..45c7228d2f1 100644 --- a/advisories/unreviewed/2024/03/GHSA-rmxq-q4j3-rg8f/GHSA-rmxq-q4j3-rg8f.json +++ b/advisories/unreviewed/2024/03/GHSA-rmxq-q4j3-rg8f/GHSA-rmxq-q4j3-rg8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -87,9 +85,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-v5w3-8cw8-83hq/GHSA-v5w3-8cw8-83hq.json b/advisories/unreviewed/2024/03/GHSA-v5w3-8cw8-83hq/GHSA-v5w3-8cw8-83hq.json index ce29d43d961..b8eb0aa39ad 100644 --- a/advisories/unreviewed/2024/03/GHSA-v5w3-8cw8-83hq/GHSA-v5w3-8cw8-83hq.json +++ b/advisories/unreviewed/2024/03/GHSA-v5w3-8cw8-83hq/GHSA-v5w3-8cw8-83hq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json b/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json index 528abdddde4..f29e98b66ab 100644 --- a/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json +++ b/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xhm5-2j4f-4x4p/GHSA-xhm5-2j4f-4x4p.json b/advisories/unreviewed/2024/03/GHSA-xhm5-2j4f-4x4p/GHSA-xhm5-2j4f-4x4p.json index 9c7ade04196..06eb4a4ff79 100644 --- a/advisories/unreviewed/2024/03/GHSA-xhm5-2j4f-4x4p/GHSA-xhm5-2j4f-4x4p.json +++ b/advisories/unreviewed/2024/03/GHSA-xhm5-2j4f-4x4p/GHSA-xhm5-2j4f-4x4p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-9xj7-mrgq-4ccq/GHSA-9xj7-mrgq-4ccq.json b/advisories/unreviewed/2024/04/GHSA-9xj7-mrgq-4ccq/GHSA-9xj7-mrgq-4ccq.json index 7bc9bf55e3b..7f9cb437210 100644 --- a/advisories/unreviewed/2024/04/GHSA-9xj7-mrgq-4ccq/GHSA-9xj7-mrgq-4ccq.json +++ b/advisories/unreviewed/2024/04/GHSA-9xj7-mrgq-4ccq/GHSA-9xj7-mrgq-4ccq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json b/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json index 519ef14101a..953252e2c46 100644 --- a/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json +++ b/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-33w7-r9c3-9qwq/GHSA-33w7-r9c3-9qwq.json b/advisories/unreviewed/2024/05/GHSA-33w7-r9c3-9qwq/GHSA-33w7-r9c3-9qwq.json index 1fa7a000e3e..6c07c533ef3 100644 --- a/advisories/unreviewed/2024/05/GHSA-33w7-r9c3-9qwq/GHSA-33w7-r9c3-9qwq.json +++ b/advisories/unreviewed/2024/05/GHSA-33w7-r9c3-9qwq/GHSA-33w7-r9c3-9qwq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-5g7f-2wxq-wj73/GHSA-5g7f-2wxq-wj73.json b/advisories/unreviewed/2024/05/GHSA-5g7f-2wxq-wj73/GHSA-5g7f-2wxq-wj73.json index 71e6981fbe6..bb032409f16 100644 --- a/advisories/unreviewed/2024/05/GHSA-5g7f-2wxq-wj73/GHSA-5g7f-2wxq-wj73.json +++ b/advisories/unreviewed/2024/05/GHSA-5g7f-2wxq-wj73/GHSA-5g7f-2wxq-wj73.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-7jj8-vg94-4wqj/GHSA-7jj8-vg94-4wqj.json b/advisories/unreviewed/2024/05/GHSA-7jj8-vg94-4wqj/GHSA-7jj8-vg94-4wqj.json index a541d930a2e..85a58e1093c 100644 --- a/advisories/unreviewed/2024/05/GHSA-7jj8-vg94-4wqj/GHSA-7jj8-vg94-4wqj.json +++ b/advisories/unreviewed/2024/05/GHSA-7jj8-vg94-4wqj/GHSA-7jj8-vg94-4wqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-7v53-8wv7-fw3m/GHSA-7v53-8wv7-fw3m.json b/advisories/unreviewed/2024/05/GHSA-7v53-8wv7-fw3m/GHSA-7v53-8wv7-fw3m.json index 3ba2b7541e7..fcb14599b44 100644 --- a/advisories/unreviewed/2024/05/GHSA-7v53-8wv7-fw3m/GHSA-7v53-8wv7-fw3m.json +++ b/advisories/unreviewed/2024/05/GHSA-7v53-8wv7-fw3m/GHSA-7v53-8wv7-fw3m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json b/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json index 59bb2d2f481..7fbd517a0ee 100644 --- a/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json +++ b/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fpgv-fc8m-fmmm/GHSA-fpgv-fc8m-fmmm.json b/advisories/unreviewed/2024/05/GHSA-fpgv-fc8m-fmmm/GHSA-fpgv-fc8m-fmmm.json index 22dc9261ad5..d7d63ec51f0 100644 --- a/advisories/unreviewed/2024/05/GHSA-fpgv-fc8m-fmmm/GHSA-fpgv-fc8m-fmmm.json +++ b/advisories/unreviewed/2024/05/GHSA-fpgv-fc8m-fmmm/GHSA-fpgv-fc8m-fmmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-h347-4rgx-68rr/GHSA-h347-4rgx-68rr.json b/advisories/unreviewed/2024/05/GHSA-h347-4rgx-68rr/GHSA-h347-4rgx-68rr.json index 310e8d89ecf..2741041e3ab 100644 --- a/advisories/unreviewed/2024/05/GHSA-h347-4rgx-68rr/GHSA-h347-4rgx-68rr.json +++ b/advisories/unreviewed/2024/05/GHSA-h347-4rgx-68rr/GHSA-h347-4rgx-68rr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hh52-hj46-fhvm/GHSA-hh52-hj46-fhvm.json b/advisories/unreviewed/2024/05/GHSA-hh52-hj46-fhvm/GHSA-hh52-hj46-fhvm.json index b4c1ce48906..5b004e592cf 100644 --- a/advisories/unreviewed/2024/05/GHSA-hh52-hj46-fhvm/GHSA-hh52-hj46-fhvm.json +++ b/advisories/unreviewed/2024/05/GHSA-hh52-hj46-fhvm/GHSA-hh52-hj46-fhvm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json b/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json index 79e1940c44c..7077c60f469 100644 --- a/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json +++ b/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-4xjp-m233-hj66/GHSA-4xjp-m233-hj66.json b/advisories/unreviewed/2024/06/GHSA-4xjp-m233-hj66/GHSA-4xjp-m233-hj66.json index 345406dacdd..b391ab25c37 100644 --- a/advisories/unreviewed/2024/06/GHSA-4xjp-m233-hj66/GHSA-4xjp-m233-hj66.json +++ b/advisories/unreviewed/2024/06/GHSA-4xjp-m233-hj66/GHSA-4xjp-m233-hj66.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-hfwg-2mm4-h8c4/GHSA-hfwg-2mm4-h8c4.json b/advisories/unreviewed/2024/06/GHSA-hfwg-2mm4-h8c4/GHSA-hfwg-2mm4-h8c4.json index 81a6320d69d..fe70c5cc7eb 100644 --- a/advisories/unreviewed/2024/06/GHSA-hfwg-2mm4-h8c4/GHSA-hfwg-2mm4-h8c4.json +++ b/advisories/unreviewed/2024/06/GHSA-hfwg-2mm4-h8c4/GHSA-hfwg-2mm4-h8c4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-6268-2vhw-q7hp/GHSA-6268-2vhw-q7hp.json b/advisories/unreviewed/2024/07/GHSA-6268-2vhw-q7hp/GHSA-6268-2vhw-q7hp.json index 10d06facc1d..4d75bea8436 100644 --- a/advisories/unreviewed/2024/07/GHSA-6268-2vhw-q7hp/GHSA-6268-2vhw-q7hp.json +++ b/advisories/unreviewed/2024/07/GHSA-6268-2vhw-q7hp/GHSA-6268-2vhw-q7hp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-68c9-v49q-x7mc/GHSA-68c9-v49q-x7mc.json b/advisories/unreviewed/2024/07/GHSA-68c9-v49q-x7mc/GHSA-68c9-v49q-x7mc.json index d45a095f359..504b323f2c1 100644 --- a/advisories/unreviewed/2024/07/GHSA-68c9-v49q-x7mc/GHSA-68c9-v49q-x7mc.json +++ b/advisories/unreviewed/2024/07/GHSA-68c9-v49q-x7mc/GHSA-68c9-v49q-x7mc.json @@ -7,12 +7,8 @@ "CVE-2022-48185" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-8h2g-2763-hv4f/GHSA-8h2g-2763-hv4f.json b/advisories/unreviewed/2024/07/GHSA-8h2g-2763-hv4f/GHSA-8h2g-2763-hv4f.json index faac1f649ad..3d69ed5b59d 100644 --- a/advisories/unreviewed/2024/07/GHSA-8h2g-2763-hv4f/GHSA-8h2g-2763-hv4f.json +++ b/advisories/unreviewed/2024/07/GHSA-8h2g-2763-hv4f/GHSA-8h2g-2763-hv4f.json @@ -7,12 +7,8 @@ "CVE-2019-19760" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-8w62-4hrj-35fc/GHSA-8w62-4hrj-35fc.json b/advisories/unreviewed/2024/07/GHSA-8w62-4hrj-35fc/GHSA-8w62-4hrj-35fc.json index ac3e22ef763..b403b7ab7d6 100644 --- a/advisories/unreviewed/2024/07/GHSA-8w62-4hrj-35fc/GHSA-8w62-4hrj-35fc.json +++ b/advisories/unreviewed/2024/07/GHSA-8w62-4hrj-35fc/GHSA-8w62-4hrj-35fc.json @@ -7,12 +7,8 @@ "CVE-2019-6185" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-9544-wf5c-4fgc/GHSA-9544-wf5c-4fgc.json b/advisories/unreviewed/2024/07/GHSA-9544-wf5c-4fgc/GHSA-9544-wf5c-4fgc.json index 0dfcf79ed3b..81be29e6481 100644 --- a/advisories/unreviewed/2024/07/GHSA-9544-wf5c-4fgc/GHSA-9544-wf5c-4fgc.json +++ b/advisories/unreviewed/2024/07/GHSA-9544-wf5c-4fgc/GHSA-9544-wf5c-4fgc.json @@ -7,12 +7,8 @@ "CVE-2019-6162" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-9c47-8jgj-vm87/GHSA-9c47-8jgj-vm87.json b/advisories/unreviewed/2024/07/GHSA-9c47-8jgj-vm87/GHSA-9c47-8jgj-vm87.json index 335c371a6b5..1f0e28cc8f0 100644 --- a/advisories/unreviewed/2024/07/GHSA-9c47-8jgj-vm87/GHSA-9c47-8jgj-vm87.json +++ b/advisories/unreviewed/2024/07/GHSA-9c47-8jgj-vm87/GHSA-9c47-8jgj-vm87.json @@ -7,12 +7,8 @@ "CVE-2019-6164" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-jrcg-8r29-9778/GHSA-jrcg-8r29-9778.json b/advisories/unreviewed/2024/07/GHSA-jrcg-8r29-9778/GHSA-jrcg-8r29-9778.json index 2ef34b3f7ae..2f938fa9bce 100644 --- a/advisories/unreviewed/2024/07/GHSA-jrcg-8r29-9778/GHSA-jrcg-8r29-9778.json +++ b/advisories/unreviewed/2024/07/GHSA-jrcg-8r29-9778/GHSA-jrcg-8r29-9778.json @@ -7,12 +7,8 @@ "CVE-2017-3766" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-m3gj-m97q-954q/GHSA-m3gj-m97q-954q.json b/advisories/unreviewed/2024/07/GHSA-m3gj-m97q-954q/GHSA-m3gj-m97q-954q.json index b2206620227..814cdde764d 100644 --- a/advisories/unreviewed/2024/07/GHSA-m3gj-m97q-954q/GHSA-m3gj-m97q-954q.json +++ b/advisories/unreviewed/2024/07/GHSA-m3gj-m97q-954q/GHSA-m3gj-m97q-954q.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-mppf-86h8-5cj7/GHSA-mppf-86h8-5cj7.json b/advisories/unreviewed/2024/07/GHSA-mppf-86h8-5cj7/GHSA-mppf-86h8-5cj7.json index a999f45de96..b134f8dc74a 100644 --- a/advisories/unreviewed/2024/07/GHSA-mppf-86h8-5cj7/GHSA-mppf-86h8-5cj7.json +++ b/advisories/unreviewed/2024/07/GHSA-mppf-86h8-5cj7/GHSA-mppf-86h8-5cj7.json @@ -7,12 +7,8 @@ "CVE-2019-6174" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json b/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json index e63fa7fe47f..cfedb36160f 100644 --- a/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json +++ b/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-p9pr-gh8g-j3cx/GHSA-p9pr-gh8g-j3cx.json b/advisories/unreviewed/2024/07/GHSA-p9pr-gh8g-j3cx/GHSA-p9pr-gh8g-j3cx.json index 46834c4e22c..ec12f8f4b7d 100644 --- a/advisories/unreviewed/2024/07/GHSA-p9pr-gh8g-j3cx/GHSA-p9pr-gh8g-j3cx.json +++ b/advisories/unreviewed/2024/07/GHSA-p9pr-gh8g-j3cx/GHSA-p9pr-gh8g-j3cx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rgcc-23p4-9wq6/GHSA-rgcc-23p4-9wq6.json b/advisories/unreviewed/2024/07/GHSA-rgcc-23p4-9wq6/GHSA-rgcc-23p4-9wq6.json index 2f862999b22..e00f0ee897e 100644 --- a/advisories/unreviewed/2024/07/GHSA-rgcc-23p4-9wq6/GHSA-rgcc-23p4-9wq6.json +++ b/advisories/unreviewed/2024/07/GHSA-rgcc-23p4-9wq6/GHSA-rgcc-23p4-9wq6.json @@ -7,12 +7,8 @@ "CVE-2017-3755" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-wc55-4jhw-4fw3/GHSA-wc55-4jhw-4fw3.json b/advisories/unreviewed/2024/07/GHSA-wc55-4jhw-4fw3/GHSA-wc55-4jhw-4fw3.json index b9d5e03a880..fb5aea71a7f 100644 --- a/advisories/unreviewed/2024/07/GHSA-wc55-4jhw-4fw3/GHSA-wc55-4jhw-4fw3.json +++ b/advisories/unreviewed/2024/07/GHSA-wc55-4jhw-4fw3/GHSA-wc55-4jhw-4fw3.json @@ -7,12 +7,8 @@ "CVE-2022-4038" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-xc6h-2r52-3c4v/GHSA-xc6h-2r52-3c4v.json b/advisories/unreviewed/2024/07/GHSA-xc6h-2r52-3c4v/GHSA-xc6h-2r52-3c4v.json index c4a4694e17a..243d81abc68 100644 --- a/advisories/unreviewed/2024/07/GHSA-xc6h-2r52-3c4v/GHSA-xc6h-2r52-3c4v.json +++ b/advisories/unreviewed/2024/07/GHSA-xc6h-2r52-3c4v/GHSA-xc6h-2r52-3c4v.json @@ -7,12 +7,8 @@ "CVE-2017-3769" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json b/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json index 06f5e51818b..bc5da5d722c 100644 --- a/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json +++ b/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-22rq-cmx2-gvr4/GHSA-22rq-cmx2-gvr4.json b/advisories/unreviewed/2024/09/GHSA-22rq-cmx2-gvr4/GHSA-22rq-cmx2-gvr4.json index 36e3b4c3215..30ce70821c5 100644 --- a/advisories/unreviewed/2024/09/GHSA-22rq-cmx2-gvr4/GHSA-22rq-cmx2-gvr4.json +++ b/advisories/unreviewed/2024/09/GHSA-22rq-cmx2-gvr4/GHSA-22rq-cmx2-gvr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-23g2-8hr8-76p4/GHSA-23g2-8hr8-76p4.json b/advisories/unreviewed/2024/09/GHSA-23g2-8hr8-76p4/GHSA-23g2-8hr8-76p4.json index 327ecca36b8..feebf1df8a6 100644 --- a/advisories/unreviewed/2024/09/GHSA-23g2-8hr8-76p4/GHSA-23g2-8hr8-76p4.json +++ b/advisories/unreviewed/2024/09/GHSA-23g2-8hr8-76p4/GHSA-23g2-8hr8-76p4.json @@ -7,12 +7,8 @@ "CVE-2024-46745" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: uinput - reject requests with unreasonable number of slots\n\n\nWhen exercising uinput interface syzkaller may try setting up device\nwith a really large number of slots, which causes memory allocation\nfailure in input_mt_init_slots(). While this allocation failure is\nhandled properly and request is rejected, it results in syzkaller\nreports. Additionally, such request may put undue burden on the\nsystem which will try to free a lot of memory for a bogus request.\n\nFix it by limiting allowed number of slots to 100. This can easily\nbe extended if we see devices that can track more than 100 contacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-2973-q4qx-mjf5/GHSA-2973-q4qx-mjf5.json b/advisories/unreviewed/2024/09/GHSA-2973-q4qx-mjf5/GHSA-2973-q4qx-mjf5.json index a3be295c2be..cceb6a8c75f 100644 --- a/advisories/unreviewed/2024/09/GHSA-2973-q4qx-mjf5/GHSA-2973-q4qx-mjf5.json +++ b/advisories/unreviewed/2024/09/GHSA-2973-q4qx-mjf5/GHSA-2973-q4qx-mjf5.json @@ -7,12 +7,8 @@ "CVE-2024-46753" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: handle errors from btrfs_dec_ref() properly\n\nIn walk_up_proc() we BUG_ON(ret) from btrfs_dec_ref(). This is\nincorrect, we have proper error handling here, return the error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-2p9x-h657-5mg3/GHSA-2p9x-h657-5mg3.json b/advisories/unreviewed/2024/09/GHSA-2p9x-h657-5mg3/GHSA-2p9x-h657-5mg3.json index 8e64d09818a..994d3dbb2ba 100644 --- a/advisories/unreviewed/2024/09/GHSA-2p9x-h657-5mg3/GHSA-2p9x-h657-5mg3.json +++ b/advisories/unreviewed/2024/09/GHSA-2p9x-h657-5mg3/GHSA-2p9x-h657-5mg3.json @@ -7,12 +7,8 @@ "CVE-2023-41611" ], "details": "Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-324v-cwrv-qmqr/GHSA-324v-cwrv-qmqr.json b/advisories/unreviewed/2024/09/GHSA-324v-cwrv-qmqr/GHSA-324v-cwrv-qmqr.json index 4ab96cc7418..fb9c3a45954 100644 --- a/advisories/unreviewed/2024/09/GHSA-324v-cwrv-qmqr/GHSA-324v-cwrv-qmqr.json +++ b/advisories/unreviewed/2024/09/GHSA-324v-cwrv-qmqr/GHSA-324v-cwrv-qmqr.json @@ -7,12 +7,8 @@ "CVE-2024-46764" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: add check for invalid name in btf_name_valid_section()\n\nIf the length of the name string is 1 and the value of name[0] is NULL\nbyte, an OOB vulnerability occurs in btf_name_valid_section() and the\nreturn value is true, so the invalid name passes the check.\n\nTo solve this, you need to check if the first position is NULL byte and\nif the first character is printable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-3j56-rc6g-pp7q/GHSA-3j56-rc6g-pp7q.json b/advisories/unreviewed/2024/09/GHSA-3j56-rc6g-pp7q/GHSA-3j56-rc6g-pp7q.json index 8cd045bacf1..ea5e176f4c2 100644 --- a/advisories/unreviewed/2024/09/GHSA-3j56-rc6g-pp7q/GHSA-3j56-rc6g-pp7q.json +++ b/advisories/unreviewed/2024/09/GHSA-3j56-rc6g-pp7q/GHSA-3j56-rc6g-pp7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json b/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json index 4a4e7f80d42..b757e55b4e1 100644 --- a/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json +++ b/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-46cp-m7j2-3fh7/GHSA-46cp-m7j2-3fh7.json b/advisories/unreviewed/2024/09/GHSA-46cp-m7j2-3fh7/GHSA-46cp-m7j2-3fh7.json index 56ad0332c2c..899b61d0bac 100644 --- a/advisories/unreviewed/2024/09/GHSA-46cp-m7j2-3fh7/GHSA-46cp-m7j2-3fh7.json +++ b/advisories/unreviewed/2024/09/GHSA-46cp-m7j2-3fh7/GHSA-46cp-m7j2-3fh7.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-4qr8-v8vv-2g9w/GHSA-4qr8-v8vv-2g9w.json b/advisories/unreviewed/2024/09/GHSA-4qr8-v8vv-2g9w/GHSA-4qr8-v8vv-2g9w.json index f0f2a75c496..c87a9e336f6 100644 --- a/advisories/unreviewed/2024/09/GHSA-4qr8-v8vv-2g9w/GHSA-4qr8-v8vv-2g9w.json +++ b/advisories/unreviewed/2024/09/GHSA-4qr8-v8vv-2g9w/GHSA-4qr8-v8vv-2g9w.json @@ -7,12 +7,8 @@ "CVE-2024-46716" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor\n\nRemove list_del call in msgdma_chan_desc_cleanup, this should be the role\nof msgdma_free_descriptor. In consequence replace list_add_tail with\nlist_move_tail in msgdma_free_descriptor.\n\nThis fixes the path:\n msgdma_free_chan_resources -> msgdma_free_descriptors ->\n msgdma_free_desc_list -> msgdma_free_descriptor\n\nwhich does not correctly free the descriptors as first nodes were not\nremoved from the list.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-5937-rmjq-m7qm/GHSA-5937-rmjq-m7qm.json b/advisories/unreviewed/2024/09/GHSA-5937-rmjq-m7qm/GHSA-5937-rmjq-m7qm.json index e9f5f34386d..a12250fca03 100644 --- a/advisories/unreviewed/2024/09/GHSA-5937-rmjq-m7qm/GHSA-5937-rmjq-m7qm.json +++ b/advisories/unreviewed/2024/09/GHSA-5937-rmjq-m7qm/GHSA-5937-rmjq-m7qm.json @@ -7,12 +7,8 @@ "CVE-2024-46792" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: misaligned: Restrict user access to kernel memory\n\nraw_copy_{to,from}_user() do not call access_ok(), so this code allowed\nuserspace to access any virtual memory address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-5m5p-hvxj-grxr/GHSA-5m5p-hvxj-grxr.json b/advisories/unreviewed/2024/09/GHSA-5m5p-hvxj-grxr/GHSA-5m5p-hvxj-grxr.json index 0a14e2584f8..994a8639ca8 100644 --- a/advisories/unreviewed/2024/09/GHSA-5m5p-hvxj-grxr/GHSA-5m5p-hvxj-grxr.json +++ b/advisories/unreviewed/2024/09/GHSA-5m5p-hvxj-grxr/GHSA-5m5p-hvxj-grxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-5p8v-m885-q5fg/GHSA-5p8v-m885-q5fg.json b/advisories/unreviewed/2024/09/GHSA-5p8v-m885-q5fg/GHSA-5p8v-m885-q5fg.json index a117359952f..20996e4f9fb 100644 --- a/advisories/unreviewed/2024/09/GHSA-5p8v-m885-q5fg/GHSA-5p8v-m885-q5fg.json +++ b/advisories/unreviewed/2024/09/GHSA-5p8v-m885-q5fg/GHSA-5p8v-m885-q5fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-5pm9-6vq7-8mc4/GHSA-5pm9-6vq7-8mc4.json b/advisories/unreviewed/2024/09/GHSA-5pm9-6vq7-8mc4/GHSA-5pm9-6vq7-8mc4.json index da6fc130d4a..0512b1be9c5 100644 --- a/advisories/unreviewed/2024/09/GHSA-5pm9-6vq7-8mc4/GHSA-5pm9-6vq7-8mc4.json +++ b/advisories/unreviewed/2024/09/GHSA-5pm9-6vq7-8mc4/GHSA-5pm9-6vq7-8mc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json b/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json index f4b980383c8..d03e8e1d3a5 100644 --- a/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json +++ b/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json b/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json index 92b43a77da9..b9f6d739115 100644 --- a/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json +++ b/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json b/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json index 33142489d70..dcb3165706c 100644 --- a/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json +++ b/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-8vqf-p95r-7frg/GHSA-8vqf-p95r-7frg.json b/advisories/unreviewed/2024/09/GHSA-8vqf-p95r-7frg/GHSA-8vqf-p95r-7frg.json index 7fb37be6a4e..fce04cb0b52 100644 --- a/advisories/unreviewed/2024/09/GHSA-8vqf-p95r-7frg/GHSA-8vqf-p95r-7frg.json +++ b/advisories/unreviewed/2024/09/GHSA-8vqf-p95r-7frg/GHSA-8vqf-p95r-7frg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-9387-xrfr-3wfr/GHSA-9387-xrfr-3wfr.json b/advisories/unreviewed/2024/09/GHSA-9387-xrfr-3wfr/GHSA-9387-xrfr-3wfr.json index 6a10cf3d884..500b2f51710 100644 --- a/advisories/unreviewed/2024/09/GHSA-9387-xrfr-3wfr/GHSA-9387-xrfr-3wfr.json +++ b/advisories/unreviewed/2024/09/GHSA-9387-xrfr-3wfr/GHSA-9387-xrfr-3wfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-97r7-fmq6-w47h/GHSA-97r7-fmq6-w47h.json b/advisories/unreviewed/2024/09/GHSA-97r7-fmq6-w47h/GHSA-97r7-fmq6-w47h.json index daac59763a8..3deada2449f 100644 --- a/advisories/unreviewed/2024/09/GHSA-97r7-fmq6-w47h/GHSA-97r7-fmq6-w47h.json +++ b/advisories/unreviewed/2024/09/GHSA-97r7-fmq6-w47h/GHSA-97r7-fmq6-w47h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json b/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json index 56ed4f4340f..f9cddf14c21 100644 --- a/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json +++ b/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-crwm-whhx-38v8/GHSA-crwm-whhx-38v8.json b/advisories/unreviewed/2024/09/GHSA-crwm-whhx-38v8/GHSA-crwm-whhx-38v8.json index b784d71e342..ac1d3e86c87 100644 --- a/advisories/unreviewed/2024/09/GHSA-crwm-whhx-38v8/GHSA-crwm-whhx-38v8.json +++ b/advisories/unreviewed/2024/09/GHSA-crwm-whhx-38v8/GHSA-crwm-whhx-38v8.json @@ -7,12 +7,8 @@ "CVE-2024-46754" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Remove tst_run from lwt_seg6local_prog_ops.\n\nThe syzbot reported that the lwt_seg6 related BPF ops can be invoked\nvia bpf_test_run() without without entering input_action_end_bpf()\nfirst.\n\nMartin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL\nprobably didn't work since it was introduced in commit 04d4b274e2a\n(\"ipv6: sr: Add seg6local action End.BPF\"). The reason is that the\nper-CPU variable seg6_bpf_srh_states::srh is never assigned in the self\ntest case but each BPF function expects it.\n\nRemove test_run for BPF_PROG_TYPE_LWT_SEG6LOCAL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-cwr3-4fc3-j8h8/GHSA-cwr3-4fc3-j8h8.json b/advisories/unreviewed/2024/09/GHSA-cwr3-4fc3-j8h8/GHSA-cwr3-4fc3-j8h8.json index b2f993f39a1..00a194dc5eb 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwr3-4fc3-j8h8/GHSA-cwr3-4fc3-j8h8.json +++ b/advisories/unreviewed/2024/09/GHSA-cwr3-4fc3-j8h8/GHSA-cwr3-4fc3-j8h8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-f7pg-xgpm-7pv6/GHSA-f7pg-xgpm-7pv6.json b/advisories/unreviewed/2024/09/GHSA-f7pg-xgpm-7pv6/GHSA-f7pg-xgpm-7pv6.json index f33f464bea9..23fb06e3e18 100644 --- a/advisories/unreviewed/2024/09/GHSA-f7pg-xgpm-7pv6/GHSA-f7pg-xgpm-7pv6.json +++ b/advisories/unreviewed/2024/09/GHSA-f7pg-xgpm-7pv6/GHSA-f7pg-xgpm-7pv6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-g38f-j3m7-3p88/GHSA-g38f-j3m7-3p88.json b/advisories/unreviewed/2024/09/GHSA-g38f-j3m7-3p88/GHSA-g38f-j3m7-3p88.json index 6f9650a7f8b..45ee96bf973 100644 --- a/advisories/unreviewed/2024/09/GHSA-g38f-j3m7-3p88/GHSA-g38f-j3m7-3p88.json +++ b/advisories/unreviewed/2024/09/GHSA-g38f-j3m7-3p88/GHSA-g38f-j3m7-3p88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-g399-5j3g-vm56/GHSA-g399-5j3g-vm56.json b/advisories/unreviewed/2024/09/GHSA-g399-5j3g-vm56/GHSA-g399-5j3g-vm56.json index 62fb25e55e9..bcc8ec9b108 100644 --- a/advisories/unreviewed/2024/09/GHSA-g399-5j3g-vm56/GHSA-g399-5j3g-vm56.json +++ b/advisories/unreviewed/2024/09/GHSA-g399-5j3g-vm56/GHSA-g399-5j3g-vm56.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-h85r-4358-hc66/GHSA-h85r-4358-hc66.json b/advisories/unreviewed/2024/09/GHSA-h85r-4358-hc66/GHSA-h85r-4358-hc66.json index b4ac837c3c6..40ad6b5583f 100644 --- a/advisories/unreviewed/2024/09/GHSA-h85r-4358-hc66/GHSA-h85r-4358-hc66.json +++ b/advisories/unreviewed/2024/09/GHSA-h85r-4358-hc66/GHSA-h85r-4358-hc66.json @@ -7,12 +7,8 @@ "CVE-2024-46767" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: Fix missing of_node_put() for leds\n\nThe call of of_get_child_by_name() will cause refcount incremented\nfor leds, if it succeeds, it should call of_node_put() to decrease\nit, fix it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-j54j-xh66-6rpm/GHSA-j54j-xh66-6rpm.json b/advisories/unreviewed/2024/09/GHSA-j54j-xh66-6rpm/GHSA-j54j-xh66-6rpm.json index 99030cb3b5d..732882356ec 100644 --- a/advisories/unreviewed/2024/09/GHSA-j54j-xh66-6rpm/GHSA-j54j-xh66-6rpm.json +++ b/advisories/unreviewed/2024/09/GHSA-j54j-xh66-6rpm/GHSA-j54j-xh66-6rpm.json @@ -7,12 +7,8 @@ "CVE-2024-46729" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix incorrect size calculation for loop\n\n[WHY]\nfe_clk_en has size of 5 but sizeof(fe_clk_en) has byte size 20 which is\nlager than the array size.\n\n[HOW]\nDivide byte size 20 by its element size.\n\nThis fixes 2 OVERRUN issues reported by Coverity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-m58v-fvm4-hcrr/GHSA-m58v-fvm4-hcrr.json b/advisories/unreviewed/2024/09/GHSA-m58v-fvm4-hcrr/GHSA-m58v-fvm4-hcrr.json index 38e0a693e7c..1d931d1e56e 100644 --- a/advisories/unreviewed/2024/09/GHSA-m58v-fvm4-hcrr/GHSA-m58v-fvm4-hcrr.json +++ b/advisories/unreviewed/2024/09/GHSA-m58v-fvm4-hcrr/GHSA-m58v-fvm4-hcrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-m83w-55jj-j9mx/GHSA-m83w-55jj-j9mx.json b/advisories/unreviewed/2024/09/GHSA-m83w-55jj-j9mx/GHSA-m83w-55jj-j9mx.json index bfee9e4d2e5..6cf1a0e2065 100644 --- a/advisories/unreviewed/2024/09/GHSA-m83w-55jj-j9mx/GHSA-m83w-55jj-j9mx.json +++ b/advisories/unreviewed/2024/09/GHSA-m83w-55jj-j9mx/GHSA-m83w-55jj-j9mx.json @@ -7,12 +7,8 @@ "CVE-2024-46752" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: replace BUG_ON() with error handling at update_ref_for_cow()\n\nInstead of a BUG_ON() just return an error, log an error message and\nabort the transaction in case we find an extent buffer belonging to the\nrelocation tree that doesn't have the full backref flag set. This is\nunexpected and should never happen (save for bugs or a potential bad\nmemory).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-m92x-f2xf-6w5q/GHSA-m92x-f2xf-6w5q.json b/advisories/unreviewed/2024/09/GHSA-m92x-f2xf-6w5q/GHSA-m92x-f2xf-6w5q.json index 00a7d0595bf..6f96b42f911 100644 --- a/advisories/unreviewed/2024/09/GHSA-m92x-f2xf-6w5q/GHSA-m92x-f2xf-6w5q.json +++ b/advisories/unreviewed/2024/09/GHSA-m92x-f2xf-6w5q/GHSA-m92x-f2xf-6w5q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-p357-q4ph-xr92/GHSA-p357-q4ph-xr92.json b/advisories/unreviewed/2024/09/GHSA-p357-q4ph-xr92/GHSA-p357-q4ph-xr92.json index 60b9719c716..52e9adbbfa2 100644 --- a/advisories/unreviewed/2024/09/GHSA-p357-q4ph-xr92/GHSA-p357-q4ph-xr92.json +++ b/advisories/unreviewed/2024/09/GHSA-p357-q4ph-xr92/GHSA-p357-q4ph-xr92.json @@ -7,12 +7,8 @@ "CVE-2024-46733" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix qgroup reserve leaks in cow_file_range\n\nIn the buffered write path, the dirty page owns the qgroup reserve until\nit creates an ordered_extent.\n\nTherefore, any errors that occur before the ordered_extent is created\nmust free that reservation, or else the space is leaked. The fstest\ngeneric/475 exercises various IO error paths, and is able to trigger\nerrors in cow_file_range where we fail to get to allocating the ordered\nextent. Note that because we *do* clear delalloc, we are likely to\nremove the inode from the delalloc list, so the inodes/pages to not have\ninvalidate/launder called on them in the commit abort path.\n\nThis results in failures at the unmount stage of the test that look like:\n\n BTRFS: error (device dm-8 state EA) in cleanup_transaction:2018: errno=-5 IO failure\n BTRFS: error (device dm-8 state EA) in btrfs_replace_file_extents:2416: errno=-5 IO failure\n BTRFS warning (device dm-8 state EA): qgroup 0/5 has unreleased space, type 0 rsv 28672\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 22588 at fs/btrfs/disk-io.c:4333 close_ctree+0x222/0x4d0 [btrfs]\n Modules linked in: btrfs blake2b_generic libcrc32c xor zstd_compress raid6_pq\n CPU: 3 PID: 22588 Comm: umount Kdump: loaded Tainted: G W 6.10.0-rc7-gab56fde445b8 #21\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014\n RIP: 0010:close_ctree+0x222/0x4d0 [btrfs]\n RSP: 0018:ffffb4465283be00 EFLAGS: 00010202\n RAX: 0000000000000001 RBX: ffffa1a1818e1000 RCX: 0000000000000001\n RDX: 0000000000000000 RSI: ffffb4465283bbe0 RDI: ffffa1a19374fcb8\n RBP: ffffa1a1818e13c0 R08: 0000000100028b16 R09: 0000000000000000\n R10: 0000000000000003 R11: 0000000000000003 R12: ffffa1a18ad7972c\n R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n FS: 00007f9168312b80(0000) GS:ffffa1a4afcc0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f91683c9140 CR3: 000000010acaa000 CR4: 00000000000006f0\n Call Trace:\n \n ? close_ctree+0x222/0x4d0 [btrfs]\n ? __warn.cold+0x8e/0xea\n ? close_ctree+0x222/0x4d0 [btrfs]\n ? report_bug+0xff/0x140\n ? handle_bug+0x3b/0x70\n ? exc_invalid_op+0x17/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? close_ctree+0x222/0x4d0 [btrfs]\n generic_shutdown_super+0x70/0x160\n kill_anon_super+0x11/0x40\n btrfs_kill_super+0x11/0x20 [btrfs]\n deactivate_locked_super+0x2e/0xa0\n cleanup_mnt+0xb5/0x150\n task_work_run+0x57/0x80\n syscall_exit_to_user_mode+0x121/0x130\n do_syscall_64+0xab/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n RIP: 0033:0x7f916847a887\n ---[ end trace 0000000000000000 ]---\n BTRFS error (device dm-8 state EA): qgroup reserved space leaked\n\nCases 2 and 3 in the out_reserve path both pertain to this type of leak\nand must free the reserved qgroup data. Because it is already an error\npath, I opted not to handle the possible errors in\nbtrfs_free_qgroup_data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-p5v6-vwvg-823j/GHSA-p5v6-vwvg-823j.json b/advisories/unreviewed/2024/09/GHSA-p5v6-vwvg-823j/GHSA-p5v6-vwvg-823j.json index 1f1c6884037..b7275bb74ba 100644 --- a/advisories/unreviewed/2024/09/GHSA-p5v6-vwvg-823j/GHSA-p5v6-vwvg-823j.json +++ b/advisories/unreviewed/2024/09/GHSA-p5v6-vwvg-823j/GHSA-p5v6-vwvg-823j.json @@ -7,12 +7,8 @@ "CVE-2024-46748" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Set the max subreq size for cache writes to MAX_RW_COUNT\n\nSet the maximum size of a subrequest that writes to cachefiles to be\nMAX_RW_COUNT so that we don't overrun the maximum write we can make to the\nbacking filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-pw8w-hq42-r2hw/GHSA-pw8w-hq42-r2hw.json b/advisories/unreviewed/2024/09/GHSA-pw8w-hq42-r2hw/GHSA-pw8w-hq42-r2hw.json index d66b72653b5..905e198bbb3 100644 --- a/advisories/unreviewed/2024/09/GHSA-pw8w-hq42-r2hw/GHSA-pw8w-hq42-r2hw.json +++ b/advisories/unreviewed/2024/09/GHSA-pw8w-hq42-r2hw/GHSA-pw8w-hq42-r2hw.json @@ -7,12 +7,8 @@ "CVE-2024-46734" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix race between direct IO write and fsync when using same fd\n\nIf we have 2 threads that are using the same file descriptor and one of\nthem is doing direct IO writes while the other is doing fsync, we have a\nrace where we can end up either:\n\n1) Attempt a fsync without holding the inode's lock, triggering an\n assertion failures when assertions are enabled;\n\n2) Do an invalid memory access from the fsync task because the file private\n points to memory allocated on stack by the direct IO task and it may be\n used by the fsync task after the stack was destroyed.\n\nThe race happens like this:\n\n1) A user space program opens a file descriptor with O_DIRECT;\n\n2) The program spawns 2 threads using libpthread for example;\n\n3) One of the threads uses the file descriptor to do direct IO writes,\n while the other calls fsync using the same file descriptor.\n\n4) Call task A the thread doing direct IO writes and task B the thread\n doing fsyncs;\n\n5) Task A does a direct IO write, and at btrfs_direct_write() sets the\n file's private to an on stack allocated private with the member\n 'fsync_skip_inode_lock' set to true;\n\n6) Task B enters btrfs_sync_file() and sees that there's a private\n structure associated to the file which has 'fsync_skip_inode_lock' set\n to true, so it skips locking the inode's VFS lock;\n\n7) Task A completes the direct IO write, and resets the file's private to\n NULL since it had no prior private and our private was stack allocated.\n Then it unlocks the inode's VFS lock;\n\n8) Task B enters btrfs_get_ordered_extents_for_logging(), then the\n assertion that checks the inode's VFS lock is held fails, since task B\n never locked it and task A has already unlocked it.\n\nThe stack trace produced is the following:\n\n assertion failed: inode_is_locked(&inode->vfs_inode), in fs/btrfs/ordered-data.c:983\n ------------[ cut here ]------------\n kernel BUG at fs/btrfs/ordered-data.c:983!\n Oops: invalid opcode: 0000 [#1] PREEMPT SMP PTI\n CPU: 9 PID: 5072 Comm: worker Tainted: G U OE 6.10.5-1-default #1 openSUSE Tumbleweed 69f48d427608e1c09e60ea24c6c55e2ca1b049e8\n Hardware name: Acer Predator PH315-52/Covini_CFS, BIOS V1.12 07/28/2020\n RIP: 0010:btrfs_get_ordered_extents_for_logging.cold+0x1f/0x42 [btrfs]\n Code: 50 d6 86 c0 e8 (...)\n RSP: 0018:ffff9e4a03dcfc78 EFLAGS: 00010246\n RAX: 0000000000000054 RBX: ffff9078a9868e98 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: ffff907dce4a7800 RDI: ffff907dce4a7800\n RBP: ffff907805518800 R08: 0000000000000000 R09: ffff9e4a03dcfb38\n R10: ffff9e4a03dcfb30 R11: 0000000000000003 R12: ffff907684ae7800\n R13: 0000000000000001 R14: ffff90774646b600 R15: 0000000000000000\n FS: 00007f04b96006c0(0000) GS:ffff907dce480000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f32acbfc000 CR3: 00000001fd4fa005 CR4: 00000000003726f0\n Call Trace:\n \n ? __die_body.cold+0x14/0x24\n ? die+0x2e/0x50\n ? do_trap+0xca/0x110\n ? do_error_trap+0x6a/0x90\n ? btrfs_get_ordered_extents_for_logging.cold+0x1f/0x42 [btrfs bb26272d49b4cdc847cf3f7faadd459b62caee9a]\n ? exc_invalid_op+0x50/0x70\n ? btrfs_get_ordered_extents_for_logging.cold+0x1f/0x42 [btrfs bb26272d49b4cdc847cf3f7faadd459b62caee9a]\n ? asm_exc_invalid_op+0x1a/0x20\n ? btrfs_get_ordered_extents_for_logging.cold+0x1f/0x42 [btrfs bb26272d49b4cdc847cf3f7faadd459b62caee9a]\n ? btrfs_get_ordered_extents_for_logging.cold+0x1f/0x42 [btrfs bb26272d49b4cdc847cf3f7faadd459b62caee9a]\n btrfs_sync_file+0x21a/0x4d0 [btrfs bb26272d49b4cdc847cf3f7faadd459b62caee9a]\n ? __seccomp_filter+0x31d/0x4f0\n __x64_sys_fdatasync+0x4f/0x90\n do_syscall_64+0x82/0x160\n ? do_futex+0xcb/0x190\n ? __x64_sys_futex+0x10e/0x1d0\n ? switch_fpu_return+0x4f/0xd0\n ? syscall_exit_to_user_mode+0x72/0x220\n ? do_syscall_64+0x8e/0x160\n ? syscall_exit_to_user_mod\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json b/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json index ffa17b3aafd..6a87760b1e1 100644 --- a/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json +++ b/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json b/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json index 15dc3bc1251..97c61fa606c 100644 --- a/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json +++ b/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-r288-8r34-4php/GHSA-r288-8r34-4php.json b/advisories/unreviewed/2024/09/GHSA-r288-8r34-4php/GHSA-r288-8r34-4php.json index 7052a2b69ca..832deb11a3f 100644 --- a/advisories/unreviewed/2024/09/GHSA-r288-8r34-4php/GHSA-r288-8r34-4php.json +++ b/advisories/unreviewed/2024/09/GHSA-r288-8r34-4php/GHSA-r288-8r34-4php.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-v7w6-282w-jqp8/GHSA-v7w6-282w-jqp8.json b/advisories/unreviewed/2024/09/GHSA-v7w6-282w-jqp8/GHSA-v7w6-282w-jqp8.json index c509a00c78a..04203f6d556 100644 --- a/advisories/unreviewed/2024/09/GHSA-v7w6-282w-jqp8/GHSA-v7w6-282w-jqp8.json +++ b/advisories/unreviewed/2024/09/GHSA-v7w6-282w-jqp8/GHSA-v7w6-282w-jqp8.json @@ -7,12 +7,8 @@ "CVE-2024-46736" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double put of @cfile in smb2_rename_path()\n\nIf smb2_set_path_attr() is called with a valid @cfile and returned\n-EINVAL, we need to call cifs_get_writable_path() again as the\nreference of @cfile was already dropped by previous smb2_compound_op()\ncall.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-vggf-h36f-57fp/GHSA-vggf-h36f-57fp.json b/advisories/unreviewed/2024/09/GHSA-vggf-h36f-57fp/GHSA-vggf-h36f-57fp.json index fa83a59d05d..0bc9ced3911 100644 --- a/advisories/unreviewed/2024/09/GHSA-vggf-h36f-57fp/GHSA-vggf-h36f-57fp.json +++ b/advisories/unreviewed/2024/09/GHSA-vggf-h36f-57fp/GHSA-vggf-h36f-57fp.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-vrrc-qv8c-m5rg/GHSA-vrrc-qv8c-m5rg.json b/advisories/unreviewed/2024/09/GHSA-vrrc-qv8c-m5rg/GHSA-vrrc-qv8c-m5rg.json index 5e96761ac60..cb5fce54d1f 100644 --- a/advisories/unreviewed/2024/09/GHSA-vrrc-qv8c-m5rg/GHSA-vrrc-qv8c-m5rg.json +++ b/advisories/unreviewed/2024/09/GHSA-vrrc-qv8c-m5rg/GHSA-vrrc-qv8c-m5rg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json b/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json index 87611700d19..eb80f43a91b 100644 --- a/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json +++ b/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-wjp8-2jq5-7v8q/GHSA-wjp8-2jq5-7v8q.json b/advisories/unreviewed/2024/09/GHSA-wjp8-2jq5-7v8q/GHSA-wjp8-2jq5-7v8q.json index 56afe568837..e44374266ea 100644 --- a/advisories/unreviewed/2024/09/GHSA-wjp8-2jq5-7v8q/GHSA-wjp8-2jq5-7v8q.json +++ b/advisories/unreviewed/2024/09/GHSA-wjp8-2jq5-7v8q/GHSA-wjp8-2jq5-7v8q.json @@ -7,12 +7,8 @@ "CVE-2024-46718" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Don't overmap identity VRAM mapping\n\nOvermapping the identity VRAM mapping is triggering hardware bugs on\ncertain platforms. Use 2M pages for the last unaligned (to 1G) VRAM\nchunk.\n\nv2:\n - Always use 2M pages for last chunk (Fei Yang)\n - break loop when 2M pages are used\n - Add assert for usable_size being 2M aligned\nv3:\n - Fix checkpatch", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-wp8q-76mh-g25x/GHSA-wp8q-76mh-g25x.json b/advisories/unreviewed/2024/09/GHSA-wp8q-76mh-g25x/GHSA-wp8q-76mh-g25x.json index 9f4e5798eb8..ed5e5416c04 100644 --- a/advisories/unreviewed/2024/09/GHSA-wp8q-76mh-g25x/GHSA-wp8q-76mh-g25x.json +++ b/advisories/unreviewed/2024/09/GHSA-wp8q-76mh-g25x/GHSA-wp8q-76mh-g25x.json @@ -7,12 +7,8 @@ "CVE-2024-46715" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver: iio: add missing checks on iio_info's callback access\n\nSome callbacks from iio_info structure are accessed without any check, so\nif a driver doesn't implement them trying to access the corresponding\nsysfs entries produce a kernel oops such as:\n\n[ 2203.527791] Unable to handle kernel NULL pointer dereference at virtual address 00000000 when execute\n[...]\n[ 2203.783416] Call trace:\n[ 2203.783429] iio_read_channel_info_avail from dev_attr_show+0x18/0x48\n[ 2203.789807] dev_attr_show from sysfs_kf_seq_show+0x90/0x120\n[ 2203.794181] sysfs_kf_seq_show from seq_read_iter+0xd0/0x4e4\n[ 2203.798555] seq_read_iter from vfs_read+0x238/0x2a0\n[ 2203.802236] vfs_read from ksys_read+0xa4/0xd4\n[ 2203.805385] ksys_read from ret_fast_syscall+0x0/0x54\n[ 2203.809135] Exception stack(0xe0badfa8 to 0xe0badff0)\n[ 2203.812880] dfa0: 00000003 b6f10f80 00000003 b6eab000 00020000 00000000\n[ 2203.819746] dfc0: 00000003 b6f10f80 7ff00000 00000003 00000003 00000000 00020000 00000000\n[ 2203.826619] dfe0: b6e1bc88 bed80958 b6e1bc94 b6e1bcb0\n[ 2203.830363] Code: bad PC value\n[ 2203.832695] ---[ end trace 0000000000000000 ]---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-wpx8-pm5v-8hrp/GHSA-wpx8-pm5v-8hrp.json b/advisories/unreviewed/2024/09/GHSA-wpx8-pm5v-8hrp/GHSA-wpx8-pm5v-8hrp.json index acaefb64f63..c0d676aba52 100644 --- a/advisories/unreviewed/2024/09/GHSA-wpx8-pm5v-8hrp/GHSA-wpx8-pm5v-8hrp.json +++ b/advisories/unreviewed/2024/09/GHSA-wpx8-pm5v-8hrp/GHSA-wpx8-pm5v-8hrp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-xp2m-m27g-f466/GHSA-xp2m-m27g-f466.json b/advisories/unreviewed/2024/09/GHSA-xp2m-m27g-f466/GHSA-xp2m-m27g-f466.json index 999d93a986c..be92dc44adb 100644 --- a/advisories/unreviewed/2024/09/GHSA-xp2m-m27g-f466/GHSA-xp2m-m27g-f466.json +++ b/advisories/unreviewed/2024/09/GHSA-xp2m-m27g-f466/GHSA-xp2m-m27g-f466.json @@ -7,12 +7,8 @@ "CVE-2024-46717" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: SHAMPO, Fix incorrect page release\n\nUnder the following conditions:\n1) No skb created yet\n2) header_size == 0 (no SHAMPO header)\n3) header_index + 1 % MLX5E_SHAMPO_WQ_HEADER_PER_PAGE == 0 (this is the\n last page fragment of a SHAMPO header page)\n\na new skb is formed with a page that is NOT a SHAMPO header page (it\nis a regular data page). Further down in the same function\n(mlx5e_handle_rx_cqe_mpwrq_shampo()), a SHAMPO header page from\nheader_index is released. This is wrong and it leads to SHAMPO header\npages being released more than once.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-xrjg-w5fr-6ph9/GHSA-xrjg-w5fr-6ph9.json b/advisories/unreviewed/2024/09/GHSA-xrjg-w5fr-6ph9/GHSA-xrjg-w5fr-6ph9.json index 710c09bbae8..d685b1b7e73 100644 --- a/advisories/unreviewed/2024/09/GHSA-xrjg-w5fr-6ph9/GHSA-xrjg-w5fr-6ph9.json +++ b/advisories/unreviewed/2024/09/GHSA-xrjg-w5fr-6ph9/GHSA-xrjg-w5fr-6ph9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-xrx8-f378-fwph/GHSA-xrx8-f378-fwph.json b/advisories/unreviewed/2024/09/GHSA-xrx8-f378-fwph/GHSA-xrx8-f378-fwph.json index c680b924b1f..88f01096172 100644 --- a/advisories/unreviewed/2024/09/GHSA-xrx8-f378-fwph/GHSA-xrx8-f378-fwph.json +++ b/advisories/unreviewed/2024/09/GHSA-xrx8-f378-fwph/GHSA-xrx8-f378-fwph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json b/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json index 2ef45153c94..5b68234fd5b 100644 --- a/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json +++ b/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-365x-gvhj-29hg/GHSA-365x-gvhj-29hg.json b/advisories/unreviewed/2024/10/GHSA-365x-gvhj-29hg/GHSA-365x-gvhj-29hg.json index 08de7171687..1302b8fabb7 100644 --- a/advisories/unreviewed/2024/10/GHSA-365x-gvhj-29hg/GHSA-365x-gvhj-29hg.json +++ b/advisories/unreviewed/2024/10/GHSA-365x-gvhj-29hg/GHSA-365x-gvhj-29hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-4c63-26fj-6f7h/GHSA-4c63-26fj-6f7h.json b/advisories/unreviewed/2024/10/GHSA-4c63-26fj-6f7h/GHSA-4c63-26fj-6f7h.json index e66f4a08165..8891cf9dd0e 100644 --- a/advisories/unreviewed/2024/10/GHSA-4c63-26fj-6f7h/GHSA-4c63-26fj-6f7h.json +++ b/advisories/unreviewed/2024/10/GHSA-4c63-26fj-6f7h/GHSA-4c63-26fj-6f7h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-5wgm-phpv-mgx7/GHSA-5wgm-phpv-mgx7.json b/advisories/unreviewed/2024/10/GHSA-5wgm-phpv-mgx7/GHSA-5wgm-phpv-mgx7.json index f15fcee88f9..2068b76fd00 100644 --- a/advisories/unreviewed/2024/10/GHSA-5wgm-phpv-mgx7/GHSA-5wgm-phpv-mgx7.json +++ b/advisories/unreviewed/2024/10/GHSA-5wgm-phpv-mgx7/GHSA-5wgm-phpv-mgx7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-7hrq-p9p5-9fjx/GHSA-7hrq-p9p5-9fjx.json b/advisories/unreviewed/2024/10/GHSA-7hrq-p9p5-9fjx/GHSA-7hrq-p9p5-9fjx.json index 61b386b51de..ee71e64a449 100644 --- a/advisories/unreviewed/2024/10/GHSA-7hrq-p9p5-9fjx/GHSA-7hrq-p9p5-9fjx.json +++ b/advisories/unreviewed/2024/10/GHSA-7hrq-p9p5-9fjx/GHSA-7hrq-p9p5-9fjx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-869q-v62p-q4p8/GHSA-869q-v62p-q4p8.json b/advisories/unreviewed/2024/10/GHSA-869q-v62p-q4p8/GHSA-869q-v62p-q4p8.json index fb4e1fc98f3..08f63610c91 100644 --- a/advisories/unreviewed/2024/10/GHSA-869q-v62p-q4p8/GHSA-869q-v62p-q4p8.json +++ b/advisories/unreviewed/2024/10/GHSA-869q-v62p-q4p8/GHSA-869q-v62p-q4p8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json b/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json index 360394486cb..05dcd5b3246 100644 --- a/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json +++ b/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-8xxh-66cx-j9cj/GHSA-8xxh-66cx-j9cj.json b/advisories/unreviewed/2024/10/GHSA-8xxh-66cx-j9cj/GHSA-8xxh-66cx-j9cj.json index 3658673a30e..e78d90d4446 100644 --- a/advisories/unreviewed/2024/10/GHSA-8xxh-66cx-j9cj/GHSA-8xxh-66cx-j9cj.json +++ b/advisories/unreviewed/2024/10/GHSA-8xxh-66cx-j9cj/GHSA-8xxh-66cx-j9cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-9x3x-8pcp-wvrj/GHSA-9x3x-8pcp-wvrj.json b/advisories/unreviewed/2024/10/GHSA-9x3x-8pcp-wvrj/GHSA-9x3x-8pcp-wvrj.json index 6f4ad135743..72c20d13f0f 100644 --- a/advisories/unreviewed/2024/10/GHSA-9x3x-8pcp-wvrj/GHSA-9x3x-8pcp-wvrj.json +++ b/advisories/unreviewed/2024/10/GHSA-9x3x-8pcp-wvrj/GHSA-9x3x-8pcp-wvrj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-cp4c-qw43-fgxp/GHSA-cp4c-qw43-fgxp.json b/advisories/unreviewed/2024/10/GHSA-cp4c-qw43-fgxp/GHSA-cp4c-qw43-fgxp.json index 3f211d654d5..bceb3ec9301 100644 --- a/advisories/unreviewed/2024/10/GHSA-cp4c-qw43-fgxp/GHSA-cp4c-qw43-fgxp.json +++ b/advisories/unreviewed/2024/10/GHSA-cp4c-qw43-fgxp/GHSA-cp4c-qw43-fgxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-cx2h-6865-57p7/GHSA-cx2h-6865-57p7.json b/advisories/unreviewed/2024/10/GHSA-cx2h-6865-57p7/GHSA-cx2h-6865-57p7.json index 91e3df7908f..594fe65acfb 100644 --- a/advisories/unreviewed/2024/10/GHSA-cx2h-6865-57p7/GHSA-cx2h-6865-57p7.json +++ b/advisories/unreviewed/2024/10/GHSA-cx2h-6865-57p7/GHSA-cx2h-6865-57p7.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-f8cq-cpqj-phg9/GHSA-f8cq-cpqj-phg9.json b/advisories/unreviewed/2024/10/GHSA-f8cq-cpqj-phg9/GHSA-f8cq-cpqj-phg9.json index d472592bc7b..fa6adb74cd2 100644 --- a/advisories/unreviewed/2024/10/GHSA-f8cq-cpqj-phg9/GHSA-f8cq-cpqj-phg9.json +++ b/advisories/unreviewed/2024/10/GHSA-f8cq-cpqj-phg9/GHSA-f8cq-cpqj-phg9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-ffwc-hfc6-c5gp/GHSA-ffwc-hfc6-c5gp.json b/advisories/unreviewed/2024/10/GHSA-ffwc-hfc6-c5gp/GHSA-ffwc-hfc6-c5gp.json index e0e94172208..fcb276f2c80 100644 --- a/advisories/unreviewed/2024/10/GHSA-ffwc-hfc6-c5gp/GHSA-ffwc-hfc6-c5gp.json +++ b/advisories/unreviewed/2024/10/GHSA-ffwc-hfc6-c5gp/GHSA-ffwc-hfc6-c5gp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-g49h-wxrw-qwfh/GHSA-g49h-wxrw-qwfh.json b/advisories/unreviewed/2024/10/GHSA-g49h-wxrw-qwfh/GHSA-g49h-wxrw-qwfh.json index 42953efaadd..067098712f4 100644 --- a/advisories/unreviewed/2024/10/GHSA-g49h-wxrw-qwfh/GHSA-g49h-wxrw-qwfh.json +++ b/advisories/unreviewed/2024/10/GHSA-g49h-wxrw-qwfh/GHSA-g49h-wxrw-qwfh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-g768-c2cp-rxc4/GHSA-g768-c2cp-rxc4.json b/advisories/unreviewed/2024/10/GHSA-g768-c2cp-rxc4/GHSA-g768-c2cp-rxc4.json index 3d4045738d1..990748cbf32 100644 --- a/advisories/unreviewed/2024/10/GHSA-g768-c2cp-rxc4/GHSA-g768-c2cp-rxc4.json +++ b/advisories/unreviewed/2024/10/GHSA-g768-c2cp-rxc4/GHSA-g768-c2cp-rxc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-gqp9-r7wj-r9hc/GHSA-gqp9-r7wj-r9hc.json b/advisories/unreviewed/2024/10/GHSA-gqp9-r7wj-r9hc/GHSA-gqp9-r7wj-r9hc.json index 4d646c421e2..40b21eb861a 100644 --- a/advisories/unreviewed/2024/10/GHSA-gqp9-r7wj-r9hc/GHSA-gqp9-r7wj-r9hc.json +++ b/advisories/unreviewed/2024/10/GHSA-gqp9-r7wj-r9hc/GHSA-gqp9-r7wj-r9hc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-hr6h-7jqj-mx8j/GHSA-hr6h-7jqj-mx8j.json b/advisories/unreviewed/2024/10/GHSA-hr6h-7jqj-mx8j/GHSA-hr6h-7jqj-mx8j.json index f9fbba33002..d995af0c0a5 100644 --- a/advisories/unreviewed/2024/10/GHSA-hr6h-7jqj-mx8j/GHSA-hr6h-7jqj-mx8j.json +++ b/advisories/unreviewed/2024/10/GHSA-hr6h-7jqj-mx8j/GHSA-hr6h-7jqj-mx8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-hx4q-76p6-78cc/GHSA-hx4q-76p6-78cc.json b/advisories/unreviewed/2024/10/GHSA-hx4q-76p6-78cc/GHSA-hx4q-76p6-78cc.json index 09b9f99f99a..7ee8aee0cf7 100644 --- a/advisories/unreviewed/2024/10/GHSA-hx4q-76p6-78cc/GHSA-hx4q-76p6-78cc.json +++ b/advisories/unreviewed/2024/10/GHSA-hx4q-76p6-78cc/GHSA-hx4q-76p6-78cc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-jf2q-q2v4-h63r/GHSA-jf2q-q2v4-h63r.json b/advisories/unreviewed/2024/10/GHSA-jf2q-q2v4-h63r/GHSA-jf2q-q2v4-h63r.json index 80c17c56dcf..58cf735dffe 100644 --- a/advisories/unreviewed/2024/10/GHSA-jf2q-q2v4-h63r/GHSA-jf2q-q2v4-h63r.json +++ b/advisories/unreviewed/2024/10/GHSA-jf2q-q2v4-h63r/GHSA-jf2q-q2v4-h63r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-jx8h-cfqr-f26f/GHSA-jx8h-cfqr-f26f.json b/advisories/unreviewed/2024/10/GHSA-jx8h-cfqr-f26f/GHSA-jx8h-cfqr-f26f.json index dd1925ef08a..b0b03d4730d 100644 --- a/advisories/unreviewed/2024/10/GHSA-jx8h-cfqr-f26f/GHSA-jx8h-cfqr-f26f.json +++ b/advisories/unreviewed/2024/10/GHSA-jx8h-cfqr-f26f/GHSA-jx8h-cfqr-f26f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-m4qg-9xvx-47wq/GHSA-m4qg-9xvx-47wq.json b/advisories/unreviewed/2024/10/GHSA-m4qg-9xvx-47wq/GHSA-m4qg-9xvx-47wq.json index ead03aa1f5b..ffe37372757 100644 --- a/advisories/unreviewed/2024/10/GHSA-m4qg-9xvx-47wq/GHSA-m4qg-9xvx-47wq.json +++ b/advisories/unreviewed/2024/10/GHSA-m4qg-9xvx-47wq/GHSA-m4qg-9xvx-47wq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-m6fg-p7cg-64mc/GHSA-m6fg-p7cg-64mc.json b/advisories/unreviewed/2024/10/GHSA-m6fg-p7cg-64mc/GHSA-m6fg-p7cg-64mc.json index de768143d2a..e0104488a88 100644 --- a/advisories/unreviewed/2024/10/GHSA-m6fg-p7cg-64mc/GHSA-m6fg-p7cg-64mc.json +++ b/advisories/unreviewed/2024/10/GHSA-m6fg-p7cg-64mc/GHSA-m6fg-p7cg-64mc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-r5f6-w2pg-mf93/GHSA-r5f6-w2pg-mf93.json b/advisories/unreviewed/2024/10/GHSA-r5f6-w2pg-mf93/GHSA-r5f6-w2pg-mf93.json index 81d6e22cc47..4fdb4a38a82 100644 --- a/advisories/unreviewed/2024/10/GHSA-r5f6-w2pg-mf93/GHSA-r5f6-w2pg-mf93.json +++ b/advisories/unreviewed/2024/10/GHSA-r5f6-w2pg-mf93/GHSA-r5f6-w2pg-mf93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-vch3-xc23-jrf2/GHSA-vch3-xc23-jrf2.json b/advisories/unreviewed/2024/10/GHSA-vch3-xc23-jrf2/GHSA-vch3-xc23-jrf2.json index c127abbab68..fa5c5be06ca 100644 --- a/advisories/unreviewed/2024/10/GHSA-vch3-xc23-jrf2/GHSA-vch3-xc23-jrf2.json +++ b/advisories/unreviewed/2024/10/GHSA-vch3-xc23-jrf2/GHSA-vch3-xc23-jrf2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-wr39-ggxq-3pf9/GHSA-wr39-ggxq-3pf9.json b/advisories/unreviewed/2024/10/GHSA-wr39-ggxq-3pf9/GHSA-wr39-ggxq-3pf9.json index 06f18e6d2c3..d82700e8aaa 100644 --- a/advisories/unreviewed/2024/10/GHSA-wr39-ggxq-3pf9/GHSA-wr39-ggxq-3pf9.json +++ b/advisories/unreviewed/2024/10/GHSA-wr39-ggxq-3pf9/GHSA-wr39-ggxq-3pf9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-x75j-gc7f-rqjc/GHSA-x75j-gc7f-rqjc.json b/advisories/unreviewed/2024/10/GHSA-x75j-gc7f-rqjc/GHSA-x75j-gc7f-rqjc.json index 22f3302accb..00e2c96f186 100644 --- a/advisories/unreviewed/2024/10/GHSA-x75j-gc7f-rqjc/GHSA-x75j-gc7f-rqjc.json +++ b/advisories/unreviewed/2024/10/GHSA-x75j-gc7f-rqjc/GHSA-x75j-gc7f-rqjc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-226j-3v4h-8cg4/GHSA-226j-3v4h-8cg4.json b/advisories/unreviewed/2024/11/GHSA-226j-3v4h-8cg4/GHSA-226j-3v4h-8cg4.json index 13d3941d168..cce400e160a 100644 --- a/advisories/unreviewed/2024/11/GHSA-226j-3v4h-8cg4/GHSA-226j-3v4h-8cg4.json +++ b/advisories/unreviewed/2024/11/GHSA-226j-3v4h-8cg4/GHSA-226j-3v4h-8cg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json b/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json index 5fd3abb4745..01726ee3ce7 100644 --- a/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json +++ b/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-2w43-52vj-94gx/GHSA-2w43-52vj-94gx.json b/advisories/unreviewed/2024/11/GHSA-2w43-52vj-94gx/GHSA-2w43-52vj-94gx.json index a2411c6ffe2..f91fac0da61 100644 --- a/advisories/unreviewed/2024/11/GHSA-2w43-52vj-94gx/GHSA-2w43-52vj-94gx.json +++ b/advisories/unreviewed/2024/11/GHSA-2w43-52vj-94gx/GHSA-2w43-52vj-94gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-3925-h58h-pr2m/GHSA-3925-h58h-pr2m.json b/advisories/unreviewed/2024/11/GHSA-3925-h58h-pr2m/GHSA-3925-h58h-pr2m.json index 7c2c556e9d4..63c1be38cba 100644 --- a/advisories/unreviewed/2024/11/GHSA-3925-h58h-pr2m/GHSA-3925-h58h-pr2m.json +++ b/advisories/unreviewed/2024/11/GHSA-3925-h58h-pr2m/GHSA-3925-h58h-pr2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-3fgp-h8mw-wrh5/GHSA-3fgp-h8mw-wrh5.json b/advisories/unreviewed/2024/11/GHSA-3fgp-h8mw-wrh5/GHSA-3fgp-h8mw-wrh5.json index ee62b1d7ede..e81809a1020 100644 --- a/advisories/unreviewed/2024/11/GHSA-3fgp-h8mw-wrh5/GHSA-3fgp-h8mw-wrh5.json +++ b/advisories/unreviewed/2024/11/GHSA-3fgp-h8mw-wrh5/GHSA-3fgp-h8mw-wrh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-3qgh-6635-p7pp/GHSA-3qgh-6635-p7pp.json b/advisories/unreviewed/2024/11/GHSA-3qgh-6635-p7pp/GHSA-3qgh-6635-p7pp.json index 46069a328ed..819bf73f3d6 100644 --- a/advisories/unreviewed/2024/11/GHSA-3qgh-6635-p7pp/GHSA-3qgh-6635-p7pp.json +++ b/advisories/unreviewed/2024/11/GHSA-3qgh-6635-p7pp/GHSA-3qgh-6635-p7pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-3r6h-pxfq-6cr9/GHSA-3r6h-pxfq-6cr9.json b/advisories/unreviewed/2024/11/GHSA-3r6h-pxfq-6cr9/GHSA-3r6h-pxfq-6cr9.json index edb5deb56ad..7bfa8326986 100644 --- a/advisories/unreviewed/2024/11/GHSA-3r6h-pxfq-6cr9/GHSA-3r6h-pxfq-6cr9.json +++ b/advisories/unreviewed/2024/11/GHSA-3r6h-pxfq-6cr9/GHSA-3r6h-pxfq-6cr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-436q-824j-g5cx/GHSA-436q-824j-g5cx.json b/advisories/unreviewed/2024/11/GHSA-436q-824j-g5cx/GHSA-436q-824j-g5cx.json index 2585ccd400e..f31727e22f2 100644 --- a/advisories/unreviewed/2024/11/GHSA-436q-824j-g5cx/GHSA-436q-824j-g5cx.json +++ b/advisories/unreviewed/2024/11/GHSA-436q-824j-g5cx/GHSA-436q-824j-g5cx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-4854-cq52-rmx6/GHSA-4854-cq52-rmx6.json b/advisories/unreviewed/2024/11/GHSA-4854-cq52-rmx6/GHSA-4854-cq52-rmx6.json index 35b86c63ec5..cfb9819b597 100644 --- a/advisories/unreviewed/2024/11/GHSA-4854-cq52-rmx6/GHSA-4854-cq52-rmx6.json +++ b/advisories/unreviewed/2024/11/GHSA-4854-cq52-rmx6/GHSA-4854-cq52-rmx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-49j5-25jj-6293/GHSA-49j5-25jj-6293.json b/advisories/unreviewed/2024/11/GHSA-49j5-25jj-6293/GHSA-49j5-25jj-6293.json index abdad3cbacd..13475730e0d 100644 --- a/advisories/unreviewed/2024/11/GHSA-49j5-25jj-6293/GHSA-49j5-25jj-6293.json +++ b/advisories/unreviewed/2024/11/GHSA-49j5-25jj-6293/GHSA-49j5-25jj-6293.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-5jgq-h327-whqc/GHSA-5jgq-h327-whqc.json b/advisories/unreviewed/2024/11/GHSA-5jgq-h327-whqc/GHSA-5jgq-h327-whqc.json index 70be772c884..159268f89c7 100644 --- a/advisories/unreviewed/2024/11/GHSA-5jgq-h327-whqc/GHSA-5jgq-h327-whqc.json +++ b/advisories/unreviewed/2024/11/GHSA-5jgq-h327-whqc/GHSA-5jgq-h327-whqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-66fc-89m5-fhwj/GHSA-66fc-89m5-fhwj.json b/advisories/unreviewed/2024/11/GHSA-66fc-89m5-fhwj/GHSA-66fc-89m5-fhwj.json index 8a5f2fd2a48..e0b50be206f 100644 --- a/advisories/unreviewed/2024/11/GHSA-66fc-89m5-fhwj/GHSA-66fc-89m5-fhwj.json +++ b/advisories/unreviewed/2024/11/GHSA-66fc-89m5-fhwj/GHSA-66fc-89m5-fhwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-6769-r74j-4rx4/GHSA-6769-r74j-4rx4.json b/advisories/unreviewed/2024/11/GHSA-6769-r74j-4rx4/GHSA-6769-r74j-4rx4.json index 4d63a3a0d43..cbb63fe51a6 100644 --- a/advisories/unreviewed/2024/11/GHSA-6769-r74j-4rx4/GHSA-6769-r74j-4rx4.json +++ b/advisories/unreviewed/2024/11/GHSA-6769-r74j-4rx4/GHSA-6769-r74j-4rx4.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Red" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-6c68-97qr-gp9g/GHSA-6c68-97qr-gp9g.json b/advisories/unreviewed/2024/11/GHSA-6c68-97qr-gp9g/GHSA-6c68-97qr-gp9g.json index 9980f6afa67..e0969a742a8 100644 --- a/advisories/unreviewed/2024/11/GHSA-6c68-97qr-gp9g/GHSA-6c68-97qr-gp9g.json +++ b/advisories/unreviewed/2024/11/GHSA-6c68-97qr-gp9g/GHSA-6c68-97qr-gp9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-6gjh-qqgg-32fj/GHSA-6gjh-qqgg-32fj.json b/advisories/unreviewed/2024/11/GHSA-6gjh-qqgg-32fj/GHSA-6gjh-qqgg-32fj.json index 56188c6e3f6..2afe7d00703 100644 --- a/advisories/unreviewed/2024/11/GHSA-6gjh-qqgg-32fj/GHSA-6gjh-qqgg-32fj.json +++ b/advisories/unreviewed/2024/11/GHSA-6gjh-qqgg-32fj/GHSA-6gjh-qqgg-32fj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-6jgr-2pw9-g4rc/GHSA-6jgr-2pw9-g4rc.json b/advisories/unreviewed/2024/11/GHSA-6jgr-2pw9-g4rc/GHSA-6jgr-2pw9-g4rc.json index 79b643b7a84..4f1c0459b17 100644 --- a/advisories/unreviewed/2024/11/GHSA-6jgr-2pw9-g4rc/GHSA-6jgr-2pw9-g4rc.json +++ b/advisories/unreviewed/2024/11/GHSA-6jgr-2pw9-g4rc/GHSA-6jgr-2pw9-g4rc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-6rcc-2x92-3rpg/GHSA-6rcc-2x92-3rpg.json b/advisories/unreviewed/2024/11/GHSA-6rcc-2x92-3rpg/GHSA-6rcc-2x92-3rpg.json index 03f184be4ee..883cc71fc4d 100644 --- a/advisories/unreviewed/2024/11/GHSA-6rcc-2x92-3rpg/GHSA-6rcc-2x92-3rpg.json +++ b/advisories/unreviewed/2024/11/GHSA-6rcc-2x92-3rpg/GHSA-6rcc-2x92-3rpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-72ch-892x-fp25/GHSA-72ch-892x-fp25.json b/advisories/unreviewed/2024/11/GHSA-72ch-892x-fp25/GHSA-72ch-892x-fp25.json index aed9c4307d5..d620c2aba12 100644 --- a/advisories/unreviewed/2024/11/GHSA-72ch-892x-fp25/GHSA-72ch-892x-fp25.json +++ b/advisories/unreviewed/2024/11/GHSA-72ch-892x-fp25/GHSA-72ch-892x-fp25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-742p-rh42-xg84/GHSA-742p-rh42-xg84.json b/advisories/unreviewed/2024/11/GHSA-742p-rh42-xg84/GHSA-742p-rh42-xg84.json index 222f393c9a9..962db046193 100644 --- a/advisories/unreviewed/2024/11/GHSA-742p-rh42-xg84/GHSA-742p-rh42-xg84.json +++ b/advisories/unreviewed/2024/11/GHSA-742p-rh42-xg84/GHSA-742p-rh42-xg84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-74f8-hfjw-wvrf/GHSA-74f8-hfjw-wvrf.json b/advisories/unreviewed/2024/11/GHSA-74f8-hfjw-wvrf/GHSA-74f8-hfjw-wvrf.json index 7f899695723..39d9eba4d7c 100644 --- a/advisories/unreviewed/2024/11/GHSA-74f8-hfjw-wvrf/GHSA-74f8-hfjw-wvrf.json +++ b/advisories/unreviewed/2024/11/GHSA-74f8-hfjw-wvrf/GHSA-74f8-hfjw-wvrf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-7699-wpx7-684c/GHSA-7699-wpx7-684c.json b/advisories/unreviewed/2024/11/GHSA-7699-wpx7-684c/GHSA-7699-wpx7-684c.json index cc6b17f8ff5..e4e6e4c6ce6 100644 --- a/advisories/unreviewed/2024/11/GHSA-7699-wpx7-684c/GHSA-7699-wpx7-684c.json +++ b/advisories/unreviewed/2024/11/GHSA-7699-wpx7-684c/GHSA-7699-wpx7-684c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-79p2-24v8-gp9v/GHSA-79p2-24v8-gp9v.json b/advisories/unreviewed/2024/11/GHSA-79p2-24v8-gp9v/GHSA-79p2-24v8-gp9v.json index 1cfefd44c64..b1eef0070ae 100644 --- a/advisories/unreviewed/2024/11/GHSA-79p2-24v8-gp9v/GHSA-79p2-24v8-gp9v.json +++ b/advisories/unreviewed/2024/11/GHSA-79p2-24v8-gp9v/GHSA-79p2-24v8-gp9v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-7h5w-r4x3-245g/GHSA-7h5w-r4x3-245g.json b/advisories/unreviewed/2024/11/GHSA-7h5w-r4x3-245g/GHSA-7h5w-r4x3-245g.json index 1571a5a9c2f..27f038e14d0 100644 --- a/advisories/unreviewed/2024/11/GHSA-7h5w-r4x3-245g/GHSA-7h5w-r4x3-245g.json +++ b/advisories/unreviewed/2024/11/GHSA-7h5w-r4x3-245g/GHSA-7h5w-r4x3-245g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-7mr2-5hcp-6xwj/GHSA-7mr2-5hcp-6xwj.json b/advisories/unreviewed/2024/11/GHSA-7mr2-5hcp-6xwj/GHSA-7mr2-5hcp-6xwj.json index cd9bcd661e8..5b8001daed1 100644 --- a/advisories/unreviewed/2024/11/GHSA-7mr2-5hcp-6xwj/GHSA-7mr2-5hcp-6xwj.json +++ b/advisories/unreviewed/2024/11/GHSA-7mr2-5hcp-6xwj/GHSA-7mr2-5hcp-6xwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-7xwq-pp9q-q8hg/GHSA-7xwq-pp9q-q8hg.json b/advisories/unreviewed/2024/11/GHSA-7xwq-pp9q-q8hg/GHSA-7xwq-pp9q-q8hg.json index 2ec42fdc712..dfcf92a99c0 100644 --- a/advisories/unreviewed/2024/11/GHSA-7xwq-pp9q-q8hg/GHSA-7xwq-pp9q-q8hg.json +++ b/advisories/unreviewed/2024/11/GHSA-7xwq-pp9q-q8hg/GHSA-7xwq-pp9q-q8hg.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Amber" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-87m5-7j63-58f7/GHSA-87m5-7j63-58f7.json b/advisories/unreviewed/2024/11/GHSA-87m5-7j63-58f7/GHSA-87m5-7j63-58f7.json index 08a4316b115..43395ae418f 100644 --- a/advisories/unreviewed/2024/11/GHSA-87m5-7j63-58f7/GHSA-87m5-7j63-58f7.json +++ b/advisories/unreviewed/2024/11/GHSA-87m5-7j63-58f7/GHSA-87m5-7j63-58f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8g7m-2r7v-c9gx/GHSA-8g7m-2r7v-c9gx.json b/advisories/unreviewed/2024/11/GHSA-8g7m-2r7v-c9gx/GHSA-8g7m-2r7v-c9gx.json index f67c2ac3e6c..0922464fcb6 100644 --- a/advisories/unreviewed/2024/11/GHSA-8g7m-2r7v-c9gx/GHSA-8g7m-2r7v-c9gx.json +++ b/advisories/unreviewed/2024/11/GHSA-8g7m-2r7v-c9gx/GHSA-8g7m-2r7v-c9gx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8j22-qjv2-93w2/GHSA-8j22-qjv2-93w2.json b/advisories/unreviewed/2024/11/GHSA-8j22-qjv2-93w2/GHSA-8j22-qjv2-93w2.json index 33f6b659c21..05638157795 100644 --- a/advisories/unreviewed/2024/11/GHSA-8j22-qjv2-93w2/GHSA-8j22-qjv2-93w2.json +++ b/advisories/unreviewed/2024/11/GHSA-8j22-qjv2-93w2/GHSA-8j22-qjv2-93w2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8m29-g8hw-c32w/GHSA-8m29-g8hw-c32w.json b/advisories/unreviewed/2024/11/GHSA-8m29-g8hw-c32w/GHSA-8m29-g8hw-c32w.json index 704d3349b1a..c75f8ca40c4 100644 --- a/advisories/unreviewed/2024/11/GHSA-8m29-g8hw-c32w/GHSA-8m29-g8hw-c32w.json +++ b/advisories/unreviewed/2024/11/GHSA-8m29-g8hw-c32w/GHSA-8m29-g8hw-c32w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8m3x-wq27-j7c8/GHSA-8m3x-wq27-j7c8.json b/advisories/unreviewed/2024/11/GHSA-8m3x-wq27-j7c8/GHSA-8m3x-wq27-j7c8.json index 8ae0cb2da03..756d11a95ef 100644 --- a/advisories/unreviewed/2024/11/GHSA-8m3x-wq27-j7c8/GHSA-8m3x-wq27-j7c8.json +++ b/advisories/unreviewed/2024/11/GHSA-8m3x-wq27-j7c8/GHSA-8m3x-wq27-j7c8.json @@ -7,12 +7,8 @@ "CVE-2019-20462" ], "details": "An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial interface and rebooting the device, a large amount of information is disclosed. This includes the view password and the password of the Wi-Fi access point that the device used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-8mfc-j52j-6m6v/GHSA-8mfc-j52j-6m6v.json b/advisories/unreviewed/2024/11/GHSA-8mfc-j52j-6m6v/GHSA-8mfc-j52j-6m6v.json index 7187c01142b..c9c3e7500d9 100644 --- a/advisories/unreviewed/2024/11/GHSA-8mfc-j52j-6m6v/GHSA-8mfc-j52j-6m6v.json +++ b/advisories/unreviewed/2024/11/GHSA-8mfc-j52j-6m6v/GHSA-8mfc-j52j-6m6v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-8w9v-ch8x-63jr/GHSA-8w9v-ch8x-63jr.json b/advisories/unreviewed/2024/11/GHSA-8w9v-ch8x-63jr/GHSA-8w9v-ch8x-63jr.json index e04f1f297be..f3f036c306e 100644 --- a/advisories/unreviewed/2024/11/GHSA-8w9v-ch8x-63jr/GHSA-8w9v-ch8x-63jr.json +++ b/advisories/unreviewed/2024/11/GHSA-8w9v-ch8x-63jr/GHSA-8w9v-ch8x-63jr.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-943q-7gr3-c56m/GHSA-943q-7gr3-c56m.json b/advisories/unreviewed/2024/11/GHSA-943q-7gr3-c56m/GHSA-943q-7gr3-c56m.json index a32bd636786..7ae8aa1ad65 100644 --- a/advisories/unreviewed/2024/11/GHSA-943q-7gr3-c56m/GHSA-943q-7gr3-c56m.json +++ b/advisories/unreviewed/2024/11/GHSA-943q-7gr3-c56m/GHSA-943q-7gr3-c56m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-94wv-j3jc-g3fm/GHSA-94wv-j3jc-g3fm.json b/advisories/unreviewed/2024/11/GHSA-94wv-j3jc-g3fm/GHSA-94wv-j3jc-g3fm.json index 1aa518e9a4d..bc52fb77e98 100644 --- a/advisories/unreviewed/2024/11/GHSA-94wv-j3jc-g3fm/GHSA-94wv-j3jc-g3fm.json +++ b/advisories/unreviewed/2024/11/GHSA-94wv-j3jc-g3fm/GHSA-94wv-j3jc-g3fm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-976j-3f9q-58vp/GHSA-976j-3f9q-58vp.json b/advisories/unreviewed/2024/11/GHSA-976j-3f9q-58vp/GHSA-976j-3f9q-58vp.json index 40869f1e821..803e8f31eb6 100644 --- a/advisories/unreviewed/2024/11/GHSA-976j-3f9q-58vp/GHSA-976j-3f9q-58vp.json +++ b/advisories/unreviewed/2024/11/GHSA-976j-3f9q-58vp/GHSA-976j-3f9q-58vp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-98cj-759m-rr93/GHSA-98cj-759m-rr93.json b/advisories/unreviewed/2024/11/GHSA-98cj-759m-rr93/GHSA-98cj-759m-rr93.json index afa3e799bff..e413db3e81e 100644 --- a/advisories/unreviewed/2024/11/GHSA-98cj-759m-rr93/GHSA-98cj-759m-rr93.json +++ b/advisories/unreviewed/2024/11/GHSA-98cj-759m-rr93/GHSA-98cj-759m-rr93.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-9f6h-w476-68gc/GHSA-9f6h-w476-68gc.json b/advisories/unreviewed/2024/11/GHSA-9f6h-w476-68gc/GHSA-9f6h-w476-68gc.json index 3d66643bf94..38f2bb97463 100644 --- a/advisories/unreviewed/2024/11/GHSA-9f6h-w476-68gc/GHSA-9f6h-w476-68gc.json +++ b/advisories/unreviewed/2024/11/GHSA-9f6h-w476-68gc/GHSA-9f6h-w476-68gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-c4pf-hc84-698h/GHSA-c4pf-hc84-698h.json b/advisories/unreviewed/2024/11/GHSA-c4pf-hc84-698h/GHSA-c4pf-hc84-698h.json index 9cdb4d3126b..f877647a9ce 100644 --- a/advisories/unreviewed/2024/11/GHSA-c4pf-hc84-698h/GHSA-c4pf-hc84-698h.json +++ b/advisories/unreviewed/2024/11/GHSA-c4pf-hc84-698h/GHSA-c4pf-hc84-698h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-f578-gpwx-g2j4/GHSA-f578-gpwx-g2j4.json b/advisories/unreviewed/2024/11/GHSA-f578-gpwx-g2j4/GHSA-f578-gpwx-g2j4.json index 030e28028f6..51f78c4f69d 100644 --- a/advisories/unreviewed/2024/11/GHSA-f578-gpwx-g2j4/GHSA-f578-gpwx-g2j4.json +++ b/advisories/unreviewed/2024/11/GHSA-f578-gpwx-g2j4/GHSA-f578-gpwx-g2j4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-f7fq-hhg5-wjv8/GHSA-f7fq-hhg5-wjv8.json b/advisories/unreviewed/2024/11/GHSA-f7fq-hhg5-wjv8/GHSA-f7fq-hhg5-wjv8.json index 97fabc379aa..a27734edb77 100644 --- a/advisories/unreviewed/2024/11/GHSA-f7fq-hhg5-wjv8/GHSA-f7fq-hhg5-wjv8.json +++ b/advisories/unreviewed/2024/11/GHSA-f7fq-hhg5-wjv8/GHSA-f7fq-hhg5-wjv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-fjv6-j3p5-xvwr/GHSA-fjv6-j3p5-xvwr.json b/advisories/unreviewed/2024/11/GHSA-fjv6-j3p5-xvwr/GHSA-fjv6-j3p5-xvwr.json index 3279f9aabef..0b747e466d1 100644 --- a/advisories/unreviewed/2024/11/GHSA-fjv6-j3p5-xvwr/GHSA-fjv6-j3p5-xvwr.json +++ b/advisories/unreviewed/2024/11/GHSA-fjv6-j3p5-xvwr/GHSA-fjv6-j3p5-xvwr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-fr3h-4rcw-wvmj/GHSA-fr3h-4rcw-wvmj.json b/advisories/unreviewed/2024/11/GHSA-fr3h-4rcw-wvmj/GHSA-fr3h-4rcw-wvmj.json index cef73726c8e..6995a897e80 100644 --- a/advisories/unreviewed/2024/11/GHSA-fr3h-4rcw-wvmj/GHSA-fr3h-4rcw-wvmj.json +++ b/advisories/unreviewed/2024/11/GHSA-fr3h-4rcw-wvmj/GHSA-fr3h-4rcw-wvmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-fr3q-8g9r-hvpv/GHSA-fr3q-8g9r-hvpv.json b/advisories/unreviewed/2024/11/GHSA-fr3q-8g9r-hvpv/GHSA-fr3q-8g9r-hvpv.json index bb8f8558ee5..cf6d2cd80c9 100644 --- a/advisories/unreviewed/2024/11/GHSA-fr3q-8g9r-hvpv/GHSA-fr3q-8g9r-hvpv.json +++ b/advisories/unreviewed/2024/11/GHSA-fr3q-8g9r-hvpv/GHSA-fr3q-8g9r-hvpv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-g2jf-mr78-35jh/GHSA-g2jf-mr78-35jh.json b/advisories/unreviewed/2024/11/GHSA-g2jf-mr78-35jh/GHSA-g2jf-mr78-35jh.json index 4b938c59b09..1d4fb7e4ec4 100644 --- a/advisories/unreviewed/2024/11/GHSA-g2jf-mr78-35jh/GHSA-g2jf-mr78-35jh.json +++ b/advisories/unreviewed/2024/11/GHSA-g2jf-mr78-35jh/GHSA-g2jf-mr78-35jh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json b/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json index 5dbd47f5009..723863938d5 100644 --- a/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json +++ b/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-g93m-8x6h-g5gv/GHSA-g93m-8x6h-g5gv.json b/advisories/unreviewed/2024/11/GHSA-g93m-8x6h-g5gv/GHSA-g93m-8x6h-g5gv.json index f12e1068eca..f034efebde9 100644 --- a/advisories/unreviewed/2024/11/GHSA-g93m-8x6h-g5gv/GHSA-g93m-8x6h-g5gv.json +++ b/advisories/unreviewed/2024/11/GHSA-g93m-8x6h-g5gv/GHSA-g93m-8x6h-g5gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-gwr8-j573-qw62/GHSA-gwr8-j573-qw62.json b/advisories/unreviewed/2024/11/GHSA-gwr8-j573-qw62/GHSA-gwr8-j573-qw62.json index 04d7600512b..0d626b3603c 100644 --- a/advisories/unreviewed/2024/11/GHSA-gwr8-j573-qw62/GHSA-gwr8-j573-qw62.json +++ b/advisories/unreviewed/2024/11/GHSA-gwr8-j573-qw62/GHSA-gwr8-j573-qw62.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-h2c5-wxjr-xfwc/GHSA-h2c5-wxjr-xfwc.json b/advisories/unreviewed/2024/11/GHSA-h2c5-wxjr-xfwc/GHSA-h2c5-wxjr-xfwc.json index b1d4ead2e06..c3b2043034f 100644 --- a/advisories/unreviewed/2024/11/GHSA-h2c5-wxjr-xfwc/GHSA-h2c5-wxjr-xfwc.json +++ b/advisories/unreviewed/2024/11/GHSA-h2c5-wxjr-xfwc/GHSA-h2c5-wxjr-xfwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-h4jm-pc24-hx88/GHSA-h4jm-pc24-hx88.json b/advisories/unreviewed/2024/11/GHSA-h4jm-pc24-hx88/GHSA-h4jm-pc24-hx88.json index 2781aa305a2..f168716e5f0 100644 --- a/advisories/unreviewed/2024/11/GHSA-h4jm-pc24-hx88/GHSA-h4jm-pc24-hx88.json +++ b/advisories/unreviewed/2024/11/GHSA-h4jm-pc24-hx88/GHSA-h4jm-pc24-hx88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-hcpx-v556-ch6p/GHSA-hcpx-v556-ch6p.json b/advisories/unreviewed/2024/11/GHSA-hcpx-v556-ch6p/GHSA-hcpx-v556-ch6p.json index c4156e2f02d..5f2620c07a1 100644 --- a/advisories/unreviewed/2024/11/GHSA-hcpx-v556-ch6p/GHSA-hcpx-v556-ch6p.json +++ b/advisories/unreviewed/2024/11/GHSA-hcpx-v556-ch6p/GHSA-hcpx-v556-ch6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-hhm7-rcc5-4hjc/GHSA-hhm7-rcc5-4hjc.json b/advisories/unreviewed/2024/11/GHSA-hhm7-rcc5-4hjc/GHSA-hhm7-rcc5-4hjc.json index a24940faec0..5d8cb4b87d2 100644 --- a/advisories/unreviewed/2024/11/GHSA-hhm7-rcc5-4hjc/GHSA-hhm7-rcc5-4hjc.json +++ b/advisories/unreviewed/2024/11/GHSA-hhm7-rcc5-4hjc/GHSA-hhm7-rcc5-4hjc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-hmcg-rc8j-cqqx/GHSA-hmcg-rc8j-cqqx.json b/advisories/unreviewed/2024/11/GHSA-hmcg-rc8j-cqqx/GHSA-hmcg-rc8j-cqqx.json index 0080e052460..2573c72bfbe 100644 --- a/advisories/unreviewed/2024/11/GHSA-hmcg-rc8j-cqqx/GHSA-hmcg-rc8j-cqqx.json +++ b/advisories/unreviewed/2024/11/GHSA-hmcg-rc8j-cqqx/GHSA-hmcg-rc8j-cqqx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-j7hj-68jp-pg28/GHSA-j7hj-68jp-pg28.json b/advisories/unreviewed/2024/11/GHSA-j7hj-68jp-pg28/GHSA-j7hj-68jp-pg28.json index d3607a664d1..dd24125dc96 100644 --- a/advisories/unreviewed/2024/11/GHSA-j7hj-68jp-pg28/GHSA-j7hj-68jp-pg28.json +++ b/advisories/unreviewed/2024/11/GHSA-j7hj-68jp-pg28/GHSA-j7hj-68jp-pg28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-j9g6-vvr6-x5wm/GHSA-j9g6-vvr6-x5wm.json b/advisories/unreviewed/2024/11/GHSA-j9g6-vvr6-x5wm/GHSA-j9g6-vvr6-x5wm.json index 45cf1abbe53..146ae3ed43c 100644 --- a/advisories/unreviewed/2024/11/GHSA-j9g6-vvr6-x5wm/GHSA-j9g6-vvr6-x5wm.json +++ b/advisories/unreviewed/2024/11/GHSA-j9g6-vvr6-x5wm/GHSA-j9g6-vvr6-x5wm.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:A/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Green" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-jfqp-w655-72wj/GHSA-jfqp-w655-72wj.json b/advisories/unreviewed/2024/11/GHSA-jfqp-w655-72wj/GHSA-jfqp-w655-72wj.json index d096349f3c1..aa0511ceba3 100644 --- a/advisories/unreviewed/2024/11/GHSA-jfqp-w655-72wj/GHSA-jfqp-w655-72wj.json +++ b/advisories/unreviewed/2024/11/GHSA-jfqp-w655-72wj/GHSA-jfqp-w655-72wj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-jg3v-6rvm-6p3v/GHSA-jg3v-6rvm-6p3v.json b/advisories/unreviewed/2024/11/GHSA-jg3v-6rvm-6p3v/GHSA-jg3v-6rvm-6p3v.json index 29aefe85f5f..0f91aaf394f 100644 --- a/advisories/unreviewed/2024/11/GHSA-jg3v-6rvm-6p3v/GHSA-jg3v-6rvm-6p3v.json +++ b/advisories/unreviewed/2024/11/GHSA-jg3v-6rvm-6p3v/GHSA-jg3v-6rvm-6p3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-jgqg-jqq9-5x4c/GHSA-jgqg-jqq9-5x4c.json b/advisories/unreviewed/2024/11/GHSA-jgqg-jqq9-5x4c/GHSA-jgqg-jqq9-5x4c.json index d2f5371020e..0f27008eb1c 100644 --- a/advisories/unreviewed/2024/11/GHSA-jgqg-jqq9-5x4c/GHSA-jgqg-jqq9-5x4c.json +++ b/advisories/unreviewed/2024/11/GHSA-jgqg-jqq9-5x4c/GHSA-jgqg-jqq9-5x4c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-jp5w-6447-j2m9/GHSA-jp5w-6447-j2m9.json b/advisories/unreviewed/2024/11/GHSA-jp5w-6447-j2m9/GHSA-jp5w-6447-j2m9.json index ff253995112..588cd4d505a 100644 --- a/advisories/unreviewed/2024/11/GHSA-jp5w-6447-j2m9/GHSA-jp5w-6447-j2m9.json +++ b/advisories/unreviewed/2024/11/GHSA-jp5w-6447-j2m9/GHSA-jp5w-6447-j2m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-jv23-26jp-6g6v/GHSA-jv23-26jp-6g6v.json b/advisories/unreviewed/2024/11/GHSA-jv23-26jp-6g6v/GHSA-jv23-26jp-6g6v.json index 69e67f73286..a13393c3e44 100644 --- a/advisories/unreviewed/2024/11/GHSA-jv23-26jp-6g6v/GHSA-jv23-26jp-6g6v.json +++ b/advisories/unreviewed/2024/11/GHSA-jv23-26jp-6g6v/GHSA-jv23-26jp-6g6v.json @@ -7,12 +7,8 @@ "CVE-2024-50157" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop\n\nDriver waits indefinitely for the fifo occupancy to go below a threshold\nas soon as the pacing interrupt is received. This can cause soft lockup on\none of the processors, if the rate of DB is very high.\n\nAdd a loop count for FPGA and exit the __wait_for_fifo_occupancy_below_th\nif the loop is taking more time. Pacing will be continuing until the\noccupancy is below the threshold. This is ensured by the checks in\nbnxt_re_pacing_timer_exp and further scheduling the work for pacing based\non the fifo occupancy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-m7mj-xvm6-p76f/GHSA-m7mj-xvm6-p76f.json b/advisories/unreviewed/2024/11/GHSA-m7mj-xvm6-p76f/GHSA-m7mj-xvm6-p76f.json index b56118e1965..b758221870c 100644 --- a/advisories/unreviewed/2024/11/GHSA-m7mj-xvm6-p76f/GHSA-m7mj-xvm6-p76f.json +++ b/advisories/unreviewed/2024/11/GHSA-m7mj-xvm6-p76f/GHSA-m7mj-xvm6-p76f.json @@ -7,12 +7,8 @@ "CVE-2024-36062" ], "details": "The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-mfmj-7jv8-9x7x/GHSA-mfmj-7jv8-9x7x.json b/advisories/unreviewed/2024/11/GHSA-mfmj-7jv8-9x7x/GHSA-mfmj-7jv8-9x7x.json index a4c09354ea2..7d7608a8b4d 100644 --- a/advisories/unreviewed/2024/11/GHSA-mfmj-7jv8-9x7x/GHSA-mfmj-7jv8-9x7x.json +++ b/advisories/unreviewed/2024/11/GHSA-mfmj-7jv8-9x7x/GHSA-mfmj-7jv8-9x7x.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-mhq2-gxcg-4hc8/GHSA-mhq2-gxcg-4hc8.json b/advisories/unreviewed/2024/11/GHSA-mhq2-gxcg-4hc8/GHSA-mhq2-gxcg-4hc8.json index 7325bcc3ea6..f362442d69c 100644 --- a/advisories/unreviewed/2024/11/GHSA-mhq2-gxcg-4hc8/GHSA-mhq2-gxcg-4hc8.json +++ b/advisories/unreviewed/2024/11/GHSA-mhq2-gxcg-4hc8/GHSA-mhq2-gxcg-4hc8.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-mw3p-xpcv-h9gq/GHSA-mw3p-xpcv-h9gq.json b/advisories/unreviewed/2024/11/GHSA-mw3p-xpcv-h9gq/GHSA-mw3p-xpcv-h9gq.json index cea4d00bef9..a82a9b88d13 100644 --- a/advisories/unreviewed/2024/11/GHSA-mw3p-xpcv-h9gq/GHSA-mw3p-xpcv-h9gq.json +++ b/advisories/unreviewed/2024/11/GHSA-mw3p-xpcv-h9gq/GHSA-mw3p-xpcv-h9gq.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-pcrp-7g2p-q7pj/GHSA-pcrp-7g2p-q7pj.json b/advisories/unreviewed/2024/11/GHSA-pcrp-7g2p-q7pj/GHSA-pcrp-7g2p-q7pj.json index 9420622da07..d687bbf45b9 100644 --- a/advisories/unreviewed/2024/11/GHSA-pcrp-7g2p-q7pj/GHSA-pcrp-7g2p-q7pj.json +++ b/advisories/unreviewed/2024/11/GHSA-pcrp-7g2p-q7pj/GHSA-pcrp-7g2p-q7pj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-q37q-6c8j-qf6q/GHSA-q37q-6c8j-qf6q.json b/advisories/unreviewed/2024/11/GHSA-q37q-6c8j-qf6q/GHSA-q37q-6c8j-qf6q.json index 7735b1674fa..b20b792b0d0 100644 --- a/advisories/unreviewed/2024/11/GHSA-q37q-6c8j-qf6q/GHSA-q37q-6c8j-qf6q.json +++ b/advisories/unreviewed/2024/11/GHSA-q37q-6c8j-qf6q/GHSA-q37q-6c8j-qf6q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-q97v-2cp6-jv6p/GHSA-q97v-2cp6-jv6p.json b/advisories/unreviewed/2024/11/GHSA-q97v-2cp6-jv6p/GHSA-q97v-2cp6-jv6p.json index 3e3e3a93b3c..f668749e886 100644 --- a/advisories/unreviewed/2024/11/GHSA-q97v-2cp6-jv6p/GHSA-q97v-2cp6-jv6p.json +++ b/advisories/unreviewed/2024/11/GHSA-q97v-2cp6-jv6p/GHSA-q97v-2cp6-jv6p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-q9j8-8r5f-j3wm/GHSA-q9j8-8r5f-j3wm.json b/advisories/unreviewed/2024/11/GHSA-q9j8-8r5f-j3wm/GHSA-q9j8-8r5f-j3wm.json index 77322b60f04..7958191b24e 100644 --- a/advisories/unreviewed/2024/11/GHSA-q9j8-8r5f-j3wm/GHSA-q9j8-8r5f-j3wm.json +++ b/advisories/unreviewed/2024/11/GHSA-q9j8-8r5f-j3wm/GHSA-q9j8-8r5f-j3wm.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:L/U:Amber" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-qrrf-258f-rprj/GHSA-qrrf-258f-rprj.json b/advisories/unreviewed/2024/11/GHSA-qrrf-258f-rprj/GHSA-qrrf-258f-rprj.json index f3804052143..5b0360f07c0 100644 --- a/advisories/unreviewed/2024/11/GHSA-qrrf-258f-rprj/GHSA-qrrf-258f-rprj.json +++ b/advisories/unreviewed/2024/11/GHSA-qrrf-258f-rprj/GHSA-qrrf-258f-rprj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-qw5j-33ph-5px7/GHSA-qw5j-33ph-5px7.json b/advisories/unreviewed/2024/11/GHSA-qw5j-33ph-5px7/GHSA-qw5j-33ph-5px7.json index 2df197c2b0a..472f5b24b86 100644 --- a/advisories/unreviewed/2024/11/GHSA-qw5j-33ph-5px7/GHSA-qw5j-33ph-5px7.json +++ b/advisories/unreviewed/2024/11/GHSA-qw5j-33ph-5px7/GHSA-qw5j-33ph-5px7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-rq8f-77g8-6fm5/GHSA-rq8f-77g8-6fm5.json b/advisories/unreviewed/2024/11/GHSA-rq8f-77g8-6fm5/GHSA-rq8f-77g8-6fm5.json index 471979e7701..eb2ac3a7858 100644 --- a/advisories/unreviewed/2024/11/GHSA-rq8f-77g8-6fm5/GHSA-rq8f-77g8-6fm5.json +++ b/advisories/unreviewed/2024/11/GHSA-rq8f-77g8-6fm5/GHSA-rq8f-77g8-6fm5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-rxqh-7qx7-59m3/GHSA-rxqh-7qx7-59m3.json b/advisories/unreviewed/2024/11/GHSA-rxqh-7qx7-59m3/GHSA-rxqh-7qx7-59m3.json index a8d1f0edfe8..e2e58d4ab15 100644 --- a/advisories/unreviewed/2024/11/GHSA-rxqh-7qx7-59m3/GHSA-rxqh-7qx7-59m3.json +++ b/advisories/unreviewed/2024/11/GHSA-rxqh-7qx7-59m3/GHSA-rxqh-7qx7-59m3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-v957-pq3j-x7cq/GHSA-v957-pq3j-x7cq.json b/advisories/unreviewed/2024/11/GHSA-v957-pq3j-x7cq/GHSA-v957-pq3j-x7cq.json index 5e4e565e2f6..188420ebca1 100644 --- a/advisories/unreviewed/2024/11/GHSA-v957-pq3j-x7cq/GHSA-v957-pq3j-x7cq.json +++ b/advisories/unreviewed/2024/11/GHSA-v957-pq3j-x7cq/GHSA-v957-pq3j-x7cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-vmh4-jpqm-9phr/GHSA-vmh4-jpqm-9phr.json b/advisories/unreviewed/2024/11/GHSA-vmh4-jpqm-9phr/GHSA-vmh4-jpqm-9phr.json index 5e533f3e3aa..155c9d68bcc 100644 --- a/advisories/unreviewed/2024/11/GHSA-vmh4-jpqm-9phr/GHSA-vmh4-jpqm-9phr.json +++ b/advisories/unreviewed/2024/11/GHSA-vmh4-jpqm-9phr/GHSA-vmh4-jpqm-9phr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-w36j-hqcc-jvpp/GHSA-w36j-hqcc-jvpp.json b/advisories/unreviewed/2024/11/GHSA-w36j-hqcc-jvpp/GHSA-w36j-hqcc-jvpp.json index f5706750400..5bf951585cf 100644 --- a/advisories/unreviewed/2024/11/GHSA-w36j-hqcc-jvpp/GHSA-w36j-hqcc-jvpp.json +++ b/advisories/unreviewed/2024/11/GHSA-w36j-hqcc-jvpp/GHSA-w36j-hqcc-jvpp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-w7fc-vcrq-2qq6/GHSA-w7fc-vcrq-2qq6.json b/advisories/unreviewed/2024/11/GHSA-w7fc-vcrq-2qq6/GHSA-w7fc-vcrq-2qq6.json index 163145266d1..deec9f5df20 100644 --- a/advisories/unreviewed/2024/11/GHSA-w7fc-vcrq-2qq6/GHSA-w7fc-vcrq-2qq6.json +++ b/advisories/unreviewed/2024/11/GHSA-w7fc-vcrq-2qq6/GHSA-w7fc-vcrq-2qq6.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-w7p4-hj4q-wh7p/GHSA-w7p4-hj4q-wh7p.json b/advisories/unreviewed/2024/11/GHSA-w7p4-hj4q-wh7p/GHSA-w7p4-hj4q-wh7p.json index 8b02c7c53fd..1252011477e 100644 --- a/advisories/unreviewed/2024/11/GHSA-w7p4-hj4q-wh7p/GHSA-w7p4-hj4q-wh7p.json +++ b/advisories/unreviewed/2024/11/GHSA-w7p4-hj4q-wh7p/GHSA-w7p4-hj4q-wh7p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-wggp-3rr4-9fpj/GHSA-wggp-3rr4-9fpj.json b/advisories/unreviewed/2024/11/GHSA-wggp-3rr4-9fpj/GHSA-wggp-3rr4-9fpj.json index f003c4d9460..4a8dc82342c 100644 --- a/advisories/unreviewed/2024/11/GHSA-wggp-3rr4-9fpj/GHSA-wggp-3rr4-9fpj.json +++ b/advisories/unreviewed/2024/11/GHSA-wggp-3rr4-9fpj/GHSA-wggp-3rr4-9fpj.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-wpp8-9p7m-8gx2/GHSA-wpp8-9p7m-8gx2.json b/advisories/unreviewed/2024/11/GHSA-wpp8-9p7m-8gx2/GHSA-wpp8-9p7m-8gx2.json index afed7e19c62..be146569e7e 100644 --- a/advisories/unreviewed/2024/11/GHSA-wpp8-9p7m-8gx2/GHSA-wpp8-9p7m-8gx2.json +++ b/advisories/unreviewed/2024/11/GHSA-wpp8-9p7m-8gx2/GHSA-wpp8-9p7m-8gx2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-wqmj-2mp9-xqmr/GHSA-wqmj-2mp9-xqmr.json b/advisories/unreviewed/2024/11/GHSA-wqmj-2mp9-xqmr/GHSA-wqmj-2mp9-xqmr.json index 0c7a63e00c0..957ad8049b7 100644 --- a/advisories/unreviewed/2024/11/GHSA-wqmj-2mp9-xqmr/GHSA-wqmj-2mp9-xqmr.json +++ b/advisories/unreviewed/2024/11/GHSA-wqmj-2mp9-xqmr/GHSA-wqmj-2mp9-xqmr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-wr5h-8pg2-5j9q/GHSA-wr5h-8pg2-5j9q.json b/advisories/unreviewed/2024/11/GHSA-wr5h-8pg2-5j9q/GHSA-wr5h-8pg2-5j9q.json index fb4be921662..cf29161a19c 100644 --- a/advisories/unreviewed/2024/11/GHSA-wr5h-8pg2-5j9q/GHSA-wr5h-8pg2-5j9q.json +++ b/advisories/unreviewed/2024/11/GHSA-wr5h-8pg2-5j9q/GHSA-wr5h-8pg2-5j9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-wxg7-96h5-9qcc/GHSA-wxg7-96h5-9qcc.json b/advisories/unreviewed/2024/11/GHSA-wxg7-96h5-9qcc/GHSA-wxg7-96h5-9qcc.json index 9440715bffd..d38283dd2be 100644 --- a/advisories/unreviewed/2024/11/GHSA-wxg7-96h5-9qcc/GHSA-wxg7-96h5-9qcc.json +++ b/advisories/unreviewed/2024/11/GHSA-wxg7-96h5-9qcc/GHSA-wxg7-96h5-9qcc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-x3fm-x4jg-jw2h/GHSA-x3fm-x4jg-jw2h.json b/advisories/unreviewed/2024/11/GHSA-x3fm-x4jg-jw2h/GHSA-x3fm-x4jg-jw2h.json index 14282c21e58..1f00881bea9 100644 --- a/advisories/unreviewed/2024/11/GHSA-x3fm-x4jg-jw2h/GHSA-x3fm-x4jg-jw2h.json +++ b/advisories/unreviewed/2024/11/GHSA-x3fm-x4jg-jw2h/GHSA-x3fm-x4jg-jw2h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-xch5-v6mf-cvxj/GHSA-xch5-v6mf-cvxj.json b/advisories/unreviewed/2024/11/GHSA-xch5-v6mf-cvxj/GHSA-xch5-v6mf-cvxj.json index ed710ae6b8a..07497aa18f3 100644 --- a/advisories/unreviewed/2024/11/GHSA-xch5-v6mf-cvxj/GHSA-xch5-v6mf-cvxj.json +++ b/advisories/unreviewed/2024/11/GHSA-xch5-v6mf-cvxj/GHSA-xch5-v6mf-cvxj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json b/advisories/unreviewed/2024/11/GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json index 27e2171850f..16674d47b54 100644 --- a/advisories/unreviewed/2024/11/GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json +++ b/advisories/unreviewed/2024/11/GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-xp7h-ghc6-47w2/GHSA-xp7h-ghc6-47w2.json b/advisories/unreviewed/2024/11/GHSA-xp7h-ghc6-47w2/GHSA-xp7h-ghc6-47w2.json index a527f326b98..515d13def92 100644 --- a/advisories/unreviewed/2024/11/GHSA-xp7h-ghc6-47w2/GHSA-xp7h-ghc6-47w2.json +++ b/advisories/unreviewed/2024/11/GHSA-xp7h-ghc6-47w2/GHSA-xp7h-ghc6-47w2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",