From bbb9d8f41db1f9bdbad9867c2d528a330ea32e65 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 30 Nov 2024 05:16:09 +0000 Subject: [PATCH] Advisory Database Sync --- .../01/GHSA-crhg-xgrg-vvcc/GHSA-crhg-xgrg-vvcc.json | 4 +--- .../06/GHSA-85rg-8m6h-825p/GHSA-85rg-8m6h-825p.json | 8 ++------ .../02/GHSA-43x4-rqpq-prmp/GHSA-43x4-rqpq-prmp.json | 4 +--- .../02/GHSA-4p74-9wgm-4fjq/GHSA-4p74-9wgm-4fjq.json | 4 +--- .../05/GHSA-225q-rmfw-6pfr/GHSA-225q-rmfw-6pfr.json | 8 ++------ .../05/GHSA-22pr-mvmh-vgg5/GHSA-22pr-mvmh-vgg5.json | 4 +--- .../05/GHSA-22px-9px7-pc64/GHSA-22px-9px7-pc64.json | 8 ++------ .../05/GHSA-22x4-mg72-m2h8/GHSA-22x4-mg72-m2h8.json | 8 ++------ .../05/GHSA-2356-6r88-539v/GHSA-2356-6r88-539v.json | 8 ++------ .../05/GHSA-23r5-px4g-3cgx/GHSA-23r5-px4g-3cgx.json | 8 ++------ .../05/GHSA-24v5-4mc2-gcq9/GHSA-24v5-4mc2-gcq9.json | 4 +--- .../05/GHSA-265x-jgfx-f3g8/GHSA-265x-jgfx-f3g8.json | 8 ++------ .../05/GHSA-26v5-q2r5-7mv2/GHSA-26v5-q2r5-7mv2.json | 4 +--- .../05/GHSA-27m5-g4hr-5cg5/GHSA-27m5-g4hr-5cg5.json | 12 +++--------- .../05/GHSA-28g7-74g3-r69w/GHSA-28g7-74g3-r69w.json | 12 +++--------- .../05/GHSA-28q6-prfq-9g82/GHSA-28q6-prfq-9g82.json | 8 ++------ .../05/GHSA-293x-mf2v-87jf/GHSA-293x-mf2v-87jf.json | 8 ++------ .../05/GHSA-295p-h6c6-4fjc/GHSA-295p-h6c6-4fjc.json | 8 ++------ .../05/GHSA-29pm-chqc-3mx4/GHSA-29pm-chqc-3mx4.json | 12 +++--------- .../05/GHSA-29pp-qfm3-p869/GHSA-29pp-qfm3-p869.json | 8 ++------ .../05/GHSA-2cmc-m5qq-rxxm/GHSA-2cmc-m5qq-rxxm.json | 12 +++--------- .../05/GHSA-2cp7-qmwg-qfxj/GHSA-2cp7-qmwg-qfxj.json | 12 +++--------- .../05/GHSA-2cqr-2p9g-vvwg/GHSA-2cqr-2p9g-vvwg.json | 12 +++--------- .../05/GHSA-2cqv-3cxq-c469/GHSA-2cqv-3cxq-c469.json | 8 ++------ .../05/GHSA-2f2h-qc39-72wh/GHSA-2f2h-qc39-72wh.json | 12 +++--------- .../05/GHSA-2f3m-7p38-8gpp/GHSA-2f3m-7p38-8gpp.json | 8 ++------ .../05/GHSA-2f86-j3w8-9473/GHSA-2f86-j3w8-9473.json | 8 ++------ .../05/GHSA-2f9r-whh5-m496/GHSA-2f9r-whh5-m496.json | 12 +++--------- .../05/GHSA-2fq6-65pq-cxpj/GHSA-2fq6-65pq-cxpj.json | 12 +++--------- .../05/GHSA-2g2p-3v97-37x7/GHSA-2g2p-3v97-37x7.json | 12 +++--------- .../05/GHSA-2gqj-p7m3-px6g/GHSA-2gqj-p7m3-px6g.json | 12 +++--------- .../05/GHSA-2h2m-3wv3-pqw4/GHSA-2h2m-3wv3-pqw4.json | 12 +++--------- .../05/GHSA-2h3g-g3x2-rqwp/GHSA-2h3g-g3x2-rqwp.json | 8 ++------ .../05/GHSA-2h6c-9r57-fm42/GHSA-2h6c-9r57-fm42.json | 12 +++--------- .../05/GHSA-2hf2-g7jc-242w/GHSA-2hf2-g7jc-242w.json | 8 ++------ .../05/GHSA-2hm7-jw48-h5x6/GHSA-2hm7-jw48-h5x6.json | 12 +++--------- .../05/GHSA-2hvg-v2h5-m85r/GHSA-2hvg-v2h5-m85r.json | 8 ++------ .../05/GHSA-2hxc-x8ph-68p8/GHSA-2hxc-x8ph-68p8.json | 12 +++--------- .../05/GHSA-2j3h-74w8-wpxm/GHSA-2j3h-74w8-wpxm.json | 12 +++--------- .../05/GHSA-2jpg-2mg3-565q/GHSA-2jpg-2mg3-565q.json | 8 ++------ .../05/GHSA-2m4j-g6x3-4mgf/GHSA-2m4j-g6x3-4mgf.json | 12 +++--------- .../05/GHSA-2mfq-w3fm-wxm3/GHSA-2mfq-w3fm-wxm3.json | 8 ++------ .../05/GHSA-2mgc-grxm-67g2/GHSA-2mgc-grxm-67g2.json | 12 +++--------- .../05/GHSA-2mjh-2x66-3p9p/GHSA-2mjh-2x66-3p9p.json | 4 +--- .../05/GHSA-2mm2-42pq-5qmv/GHSA-2mm2-42pq-5qmv.json | 8 ++------ .../05/GHSA-2qmj-w77m-fmvh/GHSA-2qmj-w77m-fmvh.json | 8 ++------ .../05/GHSA-2r65-q462-mppf/GHSA-2r65-q462-mppf.json | 12 +++--------- .../05/GHSA-2rgc-px3m-hcr7/GHSA-2rgc-px3m-hcr7.json | 8 ++------ .../05/GHSA-2v58-xw52-wr5c/GHSA-2v58-xw52-wr5c.json | 12 +++--------- .../05/GHSA-2w28-624x-pwr2/GHSA-2w28-624x-pwr2.json | 12 +++--------- .../05/GHSA-2wc8-fx5r-628m/GHSA-2wc8-fx5r-628m.json | 12 +++--------- .../05/GHSA-2x5j-ww8h-cc92/GHSA-2x5j-ww8h-cc92.json | 8 ++------ .../05/GHSA-3329-3jrm-gfjj/GHSA-3329-3jrm-gfjj.json | 12 +++--------- .../05/GHSA-3363-c452-8hxm/GHSA-3363-c452-8hxm.json | 8 ++------ .../05/GHSA-3489-8qg3-xgj4/GHSA-3489-8qg3-xgj4.json | 12 +++--------- .../05/GHSA-34mm-j386-76m3/GHSA-34mm-j386-76m3.json | 12 +++--------- .../05/GHSA-34mq-9xhj-j4rj/GHSA-34mq-9xhj-j4rj.json | 8 ++------ .../05/GHSA-34w2-p277-pp7p/GHSA-34w2-p277-pp7p.json | 8 ++------ .../05/GHSA-34wj-ch2p-7g5r/GHSA-34wj-ch2p-7g5r.json | 12 +++--------- .../05/GHSA-34x5-g49j-7c65/GHSA-34x5-g49j-7c65.json | 12 +++--------- .../05/GHSA-355w-pfx5-w3wr/GHSA-355w-pfx5-w3wr.json | 12 +++--------- .../05/GHSA-357r-rxw7-cg5w/GHSA-357r-rxw7-cg5w.json | 12 +++--------- .../05/GHSA-35xf-8pcf-3f8p/GHSA-35xf-8pcf-3f8p.json | 12 +++--------- .../05/GHSA-3622-x4mv-fpmp/GHSA-3622-x4mv-fpmp.json | 8 ++------ .../05/GHSA-3646-mf8v-hr3c/GHSA-3646-mf8v-hr3c.json | 12 +++--------- .../05/GHSA-369w-ch94-45q9/GHSA-369w-ch94-45q9.json | 12 +++--------- .../05/GHSA-36w5-5w82-56wp/GHSA-36w5-5w82-56wp.json | 8 ++------ .../05/GHSA-3754-5x4h-p35m/GHSA-3754-5x4h-p35m.json | 12 +++--------- .../05/GHSA-37q9-87mr-hp46/GHSA-37q9-87mr-hp46.json | 12 +++--------- .../05/GHSA-3876-89hf-c4pw/GHSA-3876-89hf-c4pw.json | 12 +++--------- .../05/GHSA-398g-pgqg-vjj2/GHSA-398g-pgqg-vjj2.json | 8 ++------ .../05/GHSA-3c2m-gxqv-2jrx/GHSA-3c2m-gxqv-2jrx.json | 8 ++------ .../05/GHSA-3c7q-vpq8-rccq/GHSA-3c7q-vpq8-rccq.json | 8 ++------ .../05/GHSA-3cmx-whgg-cr4j/GHSA-3cmx-whgg-cr4j.json | 8 ++------ .../05/GHSA-3fq3-m842-mpf8/GHSA-3fq3-m842-mpf8.json | 12 +++--------- .../05/GHSA-3fq6-wpf5-96cx/GHSA-3fq6-wpf5-96cx.json | 12 +++--------- .../05/GHSA-3ghh-mq29-47m6/GHSA-3ghh-mq29-47m6.json | 12 +++--------- .../05/GHSA-3gwv-97c2-3grr/GHSA-3gwv-97c2-3grr.json | 8 ++------ .../05/GHSA-3hm3-cqwp-pq23/GHSA-3hm3-cqwp-pq23.json | 12 +++--------- .../05/GHSA-3mp3-2m7f-5wff/GHSA-3mp3-2m7f-5wff.json | 8 ++------ .../05/GHSA-3p5g-mrxv-qj72/GHSA-3p5g-mrxv-qj72.json | 12 +++--------- .../05/GHSA-3phx-h87m-px77/GHSA-3phx-h87m-px77.json | 12 +++--------- .../05/GHSA-3prf-q3vf-746c/GHSA-3prf-q3vf-746c.json | 8 ++------ .../05/GHSA-3q9q-hxxg-xhhm/GHSA-3q9q-hxxg-xhhm.json | 12 +++--------- .../05/GHSA-3rvx-vp9r-j5fw/GHSA-3rvx-vp9r-j5fw.json | 12 +++--------- .../05/GHSA-3vpw-cpm2-3x8f/GHSA-3vpw-cpm2-3x8f.json | 8 ++------ .../05/GHSA-3vxw-2q8f-4h9h/GHSA-3vxw-2q8f-4h9h.json | 8 ++------ .../05/GHSA-3w8p-gqqp-6g99/GHSA-3w8p-gqqp-6g99.json | 12 +++--------- .../05/GHSA-3x9m-x83w-55fq/GHSA-3x9m-x83w-55fq.json | 12 +++--------- .../05/GHSA-3xm7-55j5-w53p/GHSA-3xm7-55j5-w53p.json | 12 +++--------- .../05/GHSA-3xmm-r55r-f598/GHSA-3xmm-r55r-f598.json | 8 ++------ .../05/GHSA-3xq3-mvf9-543x/GHSA-3xq3-mvf9-543x.json | 8 ++------ .../05/GHSA-42m6-9p28-3cfp/GHSA-42m6-9p28-3cfp.json | 12 +++--------- .../05/GHSA-43r7-fmc5-8629/GHSA-43r7-fmc5-8629.json | 8 ++------ .../05/GHSA-442m-4j9q-hhm9/GHSA-442m-4j9q-hhm9.json | 8 ++------ .../05/GHSA-44rp-ggw2-8gp5/GHSA-44rp-ggw2-8gp5.json | 12 +++--------- .../05/GHSA-45h8-9782-xf54/GHSA-45h8-9782-xf54.json | 12 +++--------- .../05/GHSA-45m2-r9w2-x69q/GHSA-45m2-r9w2-x69q.json | 8 ++------ .../05/GHSA-45rc-fw3m-7fq5/GHSA-45rc-fw3m-7fq5.json | 8 ++------ .../05/GHSA-464x-wmqf-g8q5/GHSA-464x-wmqf-g8q5.json | 12 +++--------- .../05/GHSA-4652-66x8-p2w6/GHSA-4652-66x8-p2w6.json | 12 +++--------- .../05/GHSA-46mx-vpj5-jqq4/GHSA-46mx-vpj5-jqq4.json | 12 +++--------- .../05/GHSA-4778-fgpq-p5vc/GHSA-4778-fgpq-p5vc.json | 8 ++------ .../05/GHSA-487w-fq2p-5mfh/GHSA-487w-fq2p-5mfh.json | 12 +++--------- .../05/GHSA-4c5g-m7r5-24rq/GHSA-4c5g-m7r5-24rq.json | 12 +++--------- .../05/GHSA-4c78-fmvp-hwrw/GHSA-4c78-fmvp-hwrw.json | 12 +++--------- .../05/GHSA-4c89-7wj7-fm5r/GHSA-4c89-7wj7-fm5r.json | 8 ++------ .../05/GHSA-4cmm-h58v-xqp3/GHSA-4cmm-h58v-xqp3.json | 8 ++------ .../05/GHSA-4f5q-9rv6-mx34/GHSA-4f5q-9rv6-mx34.json | 12 +++--------- .../05/GHSA-4f77-xqjh-98gr/GHSA-4f77-xqjh-98gr.json | 4 +--- .../05/GHSA-4f7q-xq4j-fmj8/GHSA-4f7q-xq4j-fmj8.json | 8 ++------ .../05/GHSA-4g8w-85qg-hc95/GHSA-4g8w-85qg-hc95.json | 8 ++------ .../05/GHSA-4gh4-8h8x-f2p8/GHSA-4gh4-8h8x-f2p8.json | 12 +++--------- .../05/GHSA-4h46-q5mh-hhfp/GHSA-4h46-q5mh-hhfp.json | 8 ++------ .../05/GHSA-4hq5-xhc8-26jr/GHSA-4hq5-xhc8-26jr.json | 12 +++--------- .../05/GHSA-4j9r-462v-9f34/GHSA-4j9r-462v-9f34.json | 8 ++------ .../05/GHSA-4jh2-4rxm-r2jw/GHSA-4jh2-4rxm-r2jw.json | 12 +++--------- .../05/GHSA-4jxj-cpjx-2v7r/GHSA-4jxj-cpjx-2v7r.json | 12 +++--------- .../05/GHSA-4m38-6q8p-p29r/GHSA-4m38-6q8p-p29r.json | 8 ++------ .../05/GHSA-4m6w-c9j7-h7cg/GHSA-4m6w-c9j7-h7cg.json | 4 +--- .../05/GHSA-4m93-727g-c564/GHSA-4m93-727g-c564.json | 8 ++------ .../05/GHSA-4p59-rrxq-mw63/GHSA-4p59-rrxq-mw63.json | 8 ++------ .../05/GHSA-4pvv-c564-5hw3/GHSA-4pvv-c564-5hw3.json | 8 ++------ .../05/GHSA-4pw5-9j6v-6728/GHSA-4pw5-9j6v-6728.json | 12 +++--------- .../05/GHSA-4qfq-vjf3-59qg/GHSA-4qfq-vjf3-59qg.json | 8 ++------ .../05/GHSA-4rxh-h76f-cjmm/GHSA-4rxh-h76f-cjmm.json | 12 +++--------- .../05/GHSA-4v4c-52hq-gphv/GHSA-4v4c-52hq-gphv.json | 12 +++--------- .../05/GHSA-4w7x-2gg8-jv5f/GHSA-4w7x-2gg8-jv5f.json | 8 ++------ .../05/GHSA-4wpf-xh32-76p2/GHSA-4wpf-xh32-76p2.json | 12 +++--------- .../05/GHSA-4wpv-93cp-fchh/GHSA-4wpv-93cp-fchh.json | 8 ++------ .../05/GHSA-4wqq-jmmx-m7qr/GHSA-4wqq-jmmx-m7qr.json | 12 +++--------- .../05/GHSA-4x4m-9cqh-w9qg/GHSA-4x4m-9cqh-w9qg.json | 8 ++------ .../05/GHSA-4x5p-qcrv-5jj7/GHSA-4x5p-qcrv-5jj7.json | 8 ++------ .../05/GHSA-4x9r-5p7j-xjmh/GHSA-4x9r-5p7j-xjmh.json | 12 +++--------- .../05/GHSA-4xj3-h4xr-2j4m/GHSA-4xj3-h4xr-2j4m.json | 8 ++------ .../05/GHSA-4xmg-fq3w-fh32/GHSA-4xmg-fq3w-fh32.json | 12 +++--------- .../05/GHSA-52px-jf69-7p9q/GHSA-52px-jf69-7p9q.json | 8 ++------ .../05/GHSA-52wp-gx9w-vjc8/GHSA-52wp-gx9w-vjc8.json | 12 +++--------- .../05/GHSA-53rq-8pvf-x2h9/GHSA-53rq-8pvf-x2h9.json | 8 ++------ .../05/GHSA-53vr-5mjf-jhrq/GHSA-53vr-5mjf-jhrq.json | 12 +++--------- .../05/GHSA-54fx-pxfw-65x8/GHSA-54fx-pxfw-65x8.json | 12 +++--------- .../05/GHSA-54m6-mr75-qr28/GHSA-54m6-mr75-qr28.json | 8 ++------ .../05/GHSA-54q9-347p-ccwv/GHSA-54q9-347p-ccwv.json | 8 ++------ .../05/GHSA-555p-5ggq-9px7/GHSA-555p-5ggq-9px7.json | 12 +++--------- .../05/GHSA-55x4-8xjx-px24/GHSA-55x4-8xjx-px24.json | 8 ++------ .../05/GHSA-56f6-p52g-2qj4/GHSA-56f6-p52g-2qj4.json | 12 +++--------- .../05/GHSA-5725-9883-g5fp/GHSA-5725-9883-g5fp.json | 12 +++--------- .../05/GHSA-576v-g6fq-v77x/GHSA-576v-g6fq-v77x.json | 12 +++--------- .../05/GHSA-57qc-j3cg-5m8r/GHSA-57qc-j3cg-5m8r.json | 12 +++--------- .../05/GHSA-5829-vp3g-4228/GHSA-5829-vp3g-4228.json | 12 +++--------- .../05/GHSA-58j2-m77g-wqq9/GHSA-58j2-m77g-wqq9.json | 12 +++--------- .../05/GHSA-58r6-g6vr-4gpp/GHSA-58r6-g6vr-4gpp.json | 8 ++------ .../05/GHSA-58vm-q7q4-jr96/GHSA-58vm-q7q4-jr96.json | 12 +++--------- .../05/GHSA-5c27-m4xg-q78c/GHSA-5c27-m4xg-q78c.json | 4 +--- .../05/GHSA-5cjp-4h3f-m7r2/GHSA-5cjp-4h3f-m7r2.json | 8 ++------ .../05/GHSA-5cq3-xc35-2mw2/GHSA-5cq3-xc35-2mw2.json | 8 ++------ .../05/GHSA-5f6g-pwch-7c2q/GHSA-5f6g-pwch-7c2q.json | 12 +++--------- .../05/GHSA-5fc8-452m-9frg/GHSA-5fc8-452m-9frg.json | 12 +++--------- .../05/GHSA-5fj2-j5qp-cp4j/GHSA-5fj2-j5qp-cp4j.json | 8 ++------ .../05/GHSA-5fp9-mpp5-899v/GHSA-5fp9-mpp5-899v.json | 8 ++------ .../05/GHSA-5fpq-4v47-vgxf/GHSA-5fpq-4v47-vgxf.json | 12 +++--------- .../05/GHSA-5fq6-q26j-jpfr/GHSA-5fq6-q26j-jpfr.json | 12 +++--------- .../05/GHSA-5g5j-x767-23r3/GHSA-5g5j-x767-23r3.json | 4 +--- .../05/GHSA-5gpp-vqxm-hc58/GHSA-5gpp-vqxm-hc58.json | 12 +++--------- .../05/GHSA-5h67-qrj6-3r9q/GHSA-5h67-qrj6-3r9q.json | 8 ++------ .../05/GHSA-5hqm-r2hv-cmwq/GHSA-5hqm-r2hv-cmwq.json | 12 +++--------- .../05/GHSA-5j3m-26vx-5q73/GHSA-5j3m-26vx-5q73.json | 8 ++------ .../05/GHSA-5jg2-wpmw-v3wh/GHSA-5jg2-wpmw-v3wh.json | 8 ++------ .../05/GHSA-5jvw-5r9c-59q7/GHSA-5jvw-5r9c-59q7.json | 8 ++------ .../05/GHSA-5m3c-wqgq-pc56/GHSA-5m3c-wqgq-pc56.json | 12 +++--------- .../05/GHSA-5m6x-3762-q523/GHSA-5m6x-3762-q523.json | 12 +++--------- .../05/GHSA-5ppj-p6hf-cfr4/GHSA-5ppj-p6hf-cfr4.json | 12 +++--------- .../05/GHSA-5pqr-784w-qv2q/GHSA-5pqr-784w-qv2q.json | 12 +++--------- .../05/GHSA-5pwg-c65h-qj7v/GHSA-5pwg-c65h-qj7v.json | 12 +++--------- .../05/GHSA-5qph-qc32-4f64/GHSA-5qph-qc32-4f64.json | 12 +++--------- .../05/GHSA-5qv7-c38f-wr8h/GHSA-5qv7-c38f-wr8h.json | 8 ++------ .../05/GHSA-5r2g-q7h9-fvcv/GHSA-5r2g-q7h9-fvcv.json | 12 +++--------- .../05/GHSA-5r5v-7gvp-6wc7/GHSA-5r5v-7gvp-6wc7.json | 8 ++------ .../05/GHSA-5w6w-7jh2-hxvv/GHSA-5w6w-7jh2-hxvv.json | 8 ++------ .../05/GHSA-5wj4-3vv6-hr3f/GHSA-5wj4-3vv6-hr3f.json | 8 ++------ .../05/GHSA-5x8c-h7cg-3vj8/GHSA-5x8c-h7cg-3vj8.json | 8 ++------ .../05/GHSA-5x9g-fm6c-gp28/GHSA-5x9g-fm6c-gp28.json | 8 ++------ .../05/GHSA-5xgj-4p79-5g3g/GHSA-5xgj-4p79-5g3g.json | 8 ++------ .../05/GHSA-5xrw-9wr4-v4rm/GHSA-5xrw-9wr4-v4rm.json | 8 ++------ .../05/GHSA-627f-jwxp-q2m6/GHSA-627f-jwxp-q2m6.json | 12 +++--------- .../05/GHSA-62pj-gfcc-pf2c/GHSA-62pj-gfcc-pf2c.json | 12 +++--------- .../05/GHSA-62xm-975c-rvp4/GHSA-62xm-975c-rvp4.json | 12 +++--------- .../05/GHSA-636j-5whr-3852/GHSA-636j-5whr-3852.json | 8 ++------ .../05/GHSA-6483-gg6m-x7w8/GHSA-6483-gg6m-x7w8.json | 12 +++--------- .../05/GHSA-648m-c4m3-gp59/GHSA-648m-c4m3-gp59.json | 8 ++------ .../05/GHSA-64hj-4677-7p5v/GHSA-64hj-4677-7p5v.json | 8 ++------ .../05/GHSA-64vp-7r78-2vqx/GHSA-64vp-7r78-2vqx.json | 12 +++--------- .../05/GHSA-6539-6fh5-h34x/GHSA-6539-6fh5-h34x.json | 12 +++--------- .../05/GHSA-6587-ppvj-ch5c/GHSA-6587-ppvj-ch5c.json | 12 +++--------- .../05/GHSA-65vm-wjw5-2x4h/GHSA-65vm-wjw5-2x4h.json | 12 +++--------- .../05/GHSA-6657-fppr-qr38/GHSA-6657-fppr-qr38.json | 12 +++--------- .../05/GHSA-66hj-88cq-2p6h/GHSA-66hj-88cq-2p6h.json | 12 +++--------- .../05/GHSA-6853-5v4j-v7vg/GHSA-6853-5v4j-v7vg.json | 8 ++------ .../05/GHSA-68m4-gw7r-wgrq/GHSA-68m4-gw7r-wgrq.json | 12 +++--------- .../05/GHSA-692h-q5hm-h622/GHSA-692h-q5hm-h622.json | 8 ++------ .../05/GHSA-69ch-7rh5-jhvc/GHSA-69ch-7rh5-jhvc.json | 12 +++--------- .../05/GHSA-69h5-wjg5-82pp/GHSA-69h5-wjg5-82pp.json | 8 ++------ .../05/GHSA-6ch8-h5p5-j54q/GHSA-6ch8-h5p5-j54q.json | 12 +++--------- .../05/GHSA-6f22-6f94-wc44/GHSA-6f22-6f94-wc44.json | 12 +++--------- .../05/GHSA-6f5f-78pr-p7q9/GHSA-6f5f-78pr-p7q9.json | 8 ++------ .../05/GHSA-6fx6-p6wj-5g53/GHSA-6fx6-p6wj-5g53.json | 12 +++--------- .../05/GHSA-6gg5-qx3q-wcv4/GHSA-6gg5-qx3q-wcv4.json | 12 +++--------- .../05/GHSA-6gjw-jvjh-pv8x/GHSA-6gjw-jvjh-pv8x.json | 12 +++--------- .../05/GHSA-6hfw-6qgf-qp2c/GHSA-6hfw-6qgf-qp2c.json | 8 ++------ .../05/GHSA-6hrr-25fh-jc7j/GHSA-6hrr-25fh-jc7j.json | 12 +++--------- .../05/GHSA-6jjp-26vv-mq6q/GHSA-6jjp-26vv-mq6q.json | 12 +++--------- .../05/GHSA-6jr2-9mj6-xwqc/GHSA-6jr2-9mj6-xwqc.json | 12 +++--------- .../05/GHSA-6mch-9mqr-vw5g/GHSA-6mch-9mqr-vw5g.json | 4 +--- .../05/GHSA-6mq7-ggq4-5r36/GHSA-6mq7-ggq4-5r36.json | 8 ++------ .../05/GHSA-6p9j-f6xp-23r3/GHSA-6p9j-f6xp-23r3.json | 8 ++------ .../05/GHSA-6q4x-rgwv-967m/GHSA-6q4x-rgwv-967m.json | 8 ++------ .../05/GHSA-6q64-4q4f-xg8j/GHSA-6q64-4q4f-xg8j.json | 12 +++--------- .../05/GHSA-6qh5-cp9g-4x2r/GHSA-6qh5-cp9g-4x2r.json | 12 +++--------- .../05/GHSA-6qqr-9g87-rcp3/GHSA-6qqr-9g87-rcp3.json | 8 ++------ .../05/GHSA-6v66-p7cp-7qq7/GHSA-6v66-p7cp-7qq7.json | 12 +++--------- .../05/GHSA-6wjr-v5v8-r9w2/GHSA-6wjr-v5v8-r9w2.json | 8 ++------ .../05/GHSA-6x24-hm2g-9f7x/GHSA-6x24-hm2g-9f7x.json | 12 +++--------- .../05/GHSA-6x2q-29mm-jmg2/GHSA-6x2q-29mm-jmg2.json | 12 +++--------- .../05/GHSA-72fv-wfpw-6q2x/GHSA-72fv-wfpw-6q2x.json | 12 +++--------- .../05/GHSA-734x-q67w-xmjv/GHSA-734x-q67w-xmjv.json | 4 +--- .../05/GHSA-7427-ffj8-874j/GHSA-7427-ffj8-874j.json | 12 +++--------- .../05/GHSA-74p7-386w-jw56/GHSA-74p7-386w-jw56.json | 8 ++------ .../05/GHSA-75hp-fjj5-wjf4/GHSA-75hp-fjj5-wjf4.json | 8 ++------ .../05/GHSA-76j4-qr57-p9fg/GHSA-76j4-qr57-p9fg.json | 8 ++------ .../05/GHSA-76xq-mh8g-37w6/GHSA-76xq-mh8g-37w6.json | 8 ++------ .../05/GHSA-788w-w3g2-24ww/GHSA-788w-w3g2-24ww.json | 8 ++------ .../05/GHSA-79fx-vxcw-m53c/GHSA-79fx-vxcw-m53c.json | 8 ++------ .../05/GHSA-7c3j-px25-gfc4/GHSA-7c3j-px25-gfc4.json | 8 ++------ .../05/GHSA-7chv-w23j-556x/GHSA-7chv-w23j-556x.json | 8 ++------ .../05/GHSA-7g9f-9vq9-79j8/GHSA-7g9f-9vq9-79j8.json | 12 +++--------- .../05/GHSA-7gx9-m7c6-98gf/GHSA-7gx9-m7c6-98gf.json | 8 ++------ .../05/GHSA-7gxg-937v-gfc4/GHSA-7gxg-937v-gfc4.json | 8 ++------ .../05/GHSA-7hf2-fvcc-82xj/GHSA-7hf2-fvcc-82xj.json | 8 ++------ .../05/GHSA-7hx7-952f-whmw/GHSA-7hx7-952f-whmw.json | 12 +++--------- .../05/GHSA-7j4h-6cq9-gmjv/GHSA-7j4h-6cq9-gmjv.json | 12 +++--------- .../05/GHSA-7jmm-wcvm-wvj4/GHSA-7jmm-wcvm-wvj4.json | 12 +++--------- .../05/GHSA-7jrf-mjm4-267q/GHSA-7jrf-mjm4-267q.json | 12 +++--------- .../05/GHSA-7mj2-j7j2-q79g/GHSA-7mj2-j7j2-q79g.json | 12 +++--------- .../05/GHSA-7pjv-6xh8-8m77/GHSA-7pjv-6xh8-8m77.json | 12 +++--------- .../05/GHSA-7pq4-47cm-wq26/GHSA-7pq4-47cm-wq26.json | 12 +++--------- .../05/GHSA-7qcx-m2gc-9659/GHSA-7qcx-m2gc-9659.json | 8 ++------ .../05/GHSA-7qvm-w8hm-h4c5/GHSA-7qvm-w8hm-h4c5.json | 12 +++--------- .../05/GHSA-7rv6-hgv9-m9mm/GHSA-7rv6-hgv9-m9mm.json | 12 +++--------- .../05/GHSA-7v28-w24g-89p5/GHSA-7v28-w24g-89p5.json | 12 +++--------- .../05/GHSA-7v38-8hc5-3fh5/GHSA-7v38-8hc5-3fh5.json | 12 +++--------- .../05/GHSA-7v4j-rp27-9f47/GHSA-7v4j-rp27-9f47.json | 12 +++--------- .../05/GHSA-7vcj-h4jh-xcfx/GHSA-7vcj-h4jh-xcfx.json | 12 +++--------- .../05/GHSA-7vcw-f634-pq9c/GHSA-7vcw-f634-pq9c.json | 8 ++------ .../05/GHSA-7vhc-pr5j-ph22/GHSA-7vhc-pr5j-ph22.json | 12 +++--------- .../05/GHSA-7w7m-m5q2-wx8m/GHSA-7w7m-m5q2-wx8m.json | 8 ++------ .../05/GHSA-7w8v-27p6-fvcw/GHSA-7w8v-27p6-fvcw.json | 8 ++------ .../05/GHSA-7whh-554c-6p33/GHSA-7whh-554c-6p33.json | 12 +++--------- .../05/GHSA-7xjf-9gpj-wwj4/GHSA-7xjf-9gpj-wwj4.json | 8 ++------ .../05/GHSA-7xwv-xhf6-x5cr/GHSA-7xwv-xhf6-x5cr.json | 8 ++------ .../05/GHSA-8235-3268-fjf9/GHSA-8235-3268-fjf9.json | 4 +--- .../05/GHSA-82mm-45xg-j4xh/GHSA-82mm-45xg-j4xh.json | 8 ++------ .../05/GHSA-82p8-66pg-8588/GHSA-82p8-66pg-8588.json | 12 +++--------- .../05/GHSA-82pj-27w3-mggj/GHSA-82pj-27w3-mggj.json | 8 ++------ .../05/GHSA-838j-jvxc-qx3c/GHSA-838j-jvxc-qx3c.json | 12 +++--------- .../05/GHSA-8434-xgm6-pw8h/GHSA-8434-xgm6-pw8h.json | 12 +++--------- .../05/GHSA-8558-rh5p-hjfm/GHSA-8558-rh5p-hjfm.json | 12 +++--------- .../05/GHSA-857q-ccvw-898p/GHSA-857q-ccvw-898p.json | 12 +++--------- .../05/GHSA-85q6-q3jc-qvmc/GHSA-85q6-q3jc-qvmc.json | 8 ++------ .../05/GHSA-85x4-4wvc-5rg9/GHSA-85x4-4wvc-5rg9.json | 12 +++--------- .../05/GHSA-8636-j732-qggq/GHSA-8636-j732-qggq.json | 12 +++--------- .../05/GHSA-868x-c2ph-qm3r/GHSA-868x-c2ph-qm3r.json | 8 ++------ .../05/GHSA-86mv-vrc5-mh9v/GHSA-86mv-vrc5-mh9v.json | 12 +++--------- .../05/GHSA-872c-p5hc-3585/GHSA-872c-p5hc-3585.json | 12 +++--------- .../05/GHSA-87gf-f47g-jf9m/GHSA-87gf-f47g-jf9m.json | 4 +--- .../05/GHSA-87h3-2wcq-m3cc/GHSA-87h3-2wcq-m3cc.json | 12 +++--------- .../05/GHSA-87hq-4572-qw4h/GHSA-87hq-4572-qw4h.json | 12 +++--------- .../05/GHSA-889c-x98f-cvvg/GHSA-889c-x98f-cvvg.json | 12 +++--------- .../05/GHSA-899p-97g6-x4h4/GHSA-899p-97g6-x4h4.json | 8 ++------ .../05/GHSA-89qr-gmvh-jqf2/GHSA-89qr-gmvh-jqf2.json | 8 ++------ .../05/GHSA-8c6r-qv58-w6fw/GHSA-8c6r-qv58-w6fw.json | 8 ++------ .../05/GHSA-8cpm-2q4p-34xp/GHSA-8cpm-2q4p-34xp.json | 12 +++--------- .../05/GHSA-8cx9-qhmg-8ch6/GHSA-8cx9-qhmg-8ch6.json | 12 +++--------- .../05/GHSA-8g95-97r6-4v76/GHSA-8g95-97r6-4v76.json | 4 +--- .../05/GHSA-8gj7-74p4-c853/GHSA-8gj7-74p4-c853.json | 8 ++------ .../05/GHSA-8jf5-j23h-mq23/GHSA-8jf5-j23h-mq23.json | 12 +++--------- .../05/GHSA-8jgx-w564-2r36/GHSA-8jgx-w564-2r36.json | 8 ++------ .../05/GHSA-8jjw-549q-phxx/GHSA-8jjw-549q-phxx.json | 12 +++--------- .../05/GHSA-8m2v-68m9-q2c7/GHSA-8m2v-68m9-q2c7.json | 4 +--- .../05/GHSA-8m2x-mm2c-xh64/GHSA-8m2x-mm2c-xh64.json | 8 ++------ .../05/GHSA-8m6j-xc56-ch65/GHSA-8m6j-xc56-ch65.json | 12 +++--------- .../05/GHSA-8p8h-5fcm-8gc4/GHSA-8p8h-5fcm-8gc4.json | 8 ++------ .../05/GHSA-8p9p-333g-f2cc/GHSA-8p9p-333g-f2cc.json | 8 ++------ .../05/GHSA-8pfj-wqp7-7x2c/GHSA-8pfj-wqp7-7x2c.json | 12 +++--------- .../05/GHSA-8pqm-hrrp-373j/GHSA-8pqm-hrrp-373j.json | 12 +++--------- .../05/GHSA-8prr-wvvw-94gv/GHSA-8prr-wvvw-94gv.json | 8 ++------ .../05/GHSA-8prw-qcgj-xjrj/GHSA-8prw-qcgj-xjrj.json | 12 +++--------- .../05/GHSA-8qf8-7w4h-xrpc/GHSA-8qf8-7w4h-xrpc.json | 8 ++------ .../05/GHSA-8r7w-7c78-x8mm/GHSA-8r7w-7c78-x8mm.json | 8 ++------ .../05/GHSA-8r83-7qrm-rvxc/GHSA-8r83-7qrm-rvxc.json | 12 +++--------- .../05/GHSA-8rmr-f55v-w9w6/GHSA-8rmr-f55v-w9w6.json | 8 ++------ .../05/GHSA-8rxp-98h2-676c/GHSA-8rxp-98h2-676c.json | 8 ++------ .../05/GHSA-8w4r-4r44-xw5g/GHSA-8w4r-4r44-xw5g.json | 12 +++--------- .../05/GHSA-8w6h-27hq-jp76/GHSA-8w6h-27hq-jp76.json | 4 +--- .../05/GHSA-8wjw-738x-7cm9/GHSA-8wjw-738x-7cm9.json | 4 +--- .../05/GHSA-8wp5-373j-qw7h/GHSA-8wp5-373j-qw7h.json | 12 +++--------- .../05/GHSA-8xjp-h5q2-g6vf/GHSA-8xjp-h5q2-g6vf.json | 12 +++--------- .../05/GHSA-92v9-v65f-f4q8/GHSA-92v9-v65f-f4q8.json | 12 +++--------- .../05/GHSA-934q-gq37-gq89/GHSA-934q-gq37-gq89.json | 8 ++------ .../05/GHSA-9495-xp2q-c4gc/GHSA-9495-xp2q-c4gc.json | 8 ++------ .../05/GHSA-94c8-qvx9-76vq/GHSA-94c8-qvx9-76vq.json | 8 ++------ .../05/GHSA-94fg-6w87-3r57/GHSA-94fg-6w87-3r57.json | 8 ++------ .../05/GHSA-94mw-474q-fxh5/GHSA-94mw-474q-fxh5.json | 8 ++------ .../05/GHSA-9568-6gjg-jgm8/GHSA-9568-6gjg-jgm8.json | 8 ++------ .../05/GHSA-95h4-prgr-h453/GHSA-95h4-prgr-h453.json | 12 +++--------- .../05/GHSA-964m-f4fc-h2mf/GHSA-964m-f4fc-h2mf.json | 8 ++------ .../05/GHSA-973q-jf8v-6q77/GHSA-973q-jf8v-6q77.json | 8 ++------ .../05/GHSA-9757-c955-9qqg/GHSA-9757-c955-9qqg.json | 12 +++--------- .../05/GHSA-97m8-rj8m-hvm2/GHSA-97m8-rj8m-hvm2.json | 12 +++--------- .../05/GHSA-98jw-m4q8-f849/GHSA-98jw-m4q8-f849.json | 8 ++------ .../05/GHSA-9c9h-855r-9r5v/GHSA-9c9h-855r-9r5v.json | 12 +++--------- .../05/GHSA-9cjg-xfcq-56f3/GHSA-9cjg-xfcq-56f3.json | 8 ++------ .../05/GHSA-9f5g-mr9p-4fxc/GHSA-9f5g-mr9p-4fxc.json | 8 ++------ .../05/GHSA-9fpm-9892-q4hp/GHSA-9fpm-9892-q4hp.json | 12 +++--------- .../05/GHSA-9g47-2766-9622/GHSA-9g47-2766-9622.json | 8 ++------ .../05/GHSA-9g77-h7cv-5vp5/GHSA-9g77-h7cv-5vp5.json | 12 +++--------- .../05/GHSA-9gjf-xc3f-w2j8/GHSA-9gjf-xc3f-w2j8.json | 8 ++------ .../05/GHSA-9h5x-7fqr-xqgx/GHSA-9h5x-7fqr-xqgx.json | 8 ++------ .../05/GHSA-9hc5-m4g5-3m3c/GHSA-9hc5-m4g5-3m3c.json | 8 ++------ .../05/GHSA-9j28-crwr-wvfx/GHSA-9j28-crwr-wvfx.json | 12 +++--------- .../05/GHSA-9j7c-3668-hr3c/GHSA-9j7c-3668-hr3c.json | 8 ++------ .../05/GHSA-9jhc-m2f9-xm2h/GHSA-9jhc-m2f9-xm2h.json | 8 ++------ .../05/GHSA-9jrp-h5gv-236v/GHSA-9jrp-h5gv-236v.json | 12 +++--------- .../05/GHSA-9jxx-wv7p-h3g3/GHSA-9jxx-wv7p-h3g3.json | 12 +++--------- .../05/GHSA-9mm7-wpqg-qhvm/GHSA-9mm7-wpqg-qhvm.json | 12 +++--------- .../05/GHSA-9p38-r99r-g3mg/GHSA-9p38-r99r-g3mg.json | 12 +++--------- .../05/GHSA-9p84-3w48-p6j6/GHSA-9p84-3w48-p6j6.json | 8 ++------ .../05/GHSA-9p9w-m487-54jr/GHSA-9p9w-m487-54jr.json | 12 +++--------- .../05/GHSA-9pcf-jg3j-pw83/GHSA-9pcf-jg3j-pw83.json | 8 ++------ .../05/GHSA-9ph4-xhrv-3pgx/GHSA-9ph4-xhrv-3pgx.json | 12 +++--------- .../05/GHSA-9pxh-q2v6-xvg6/GHSA-9pxh-q2v6-xvg6.json | 12 +++--------- .../05/GHSA-9q55-3953-mqgf/GHSA-9q55-3953-mqgf.json | 8 ++------ .../05/GHSA-9qwh-mr4w-j7m3/GHSA-9qwh-mr4w-j7m3.json | 12 +++--------- .../05/GHSA-9r24-f9qq-w8p5/GHSA-9r24-f9qq-w8p5.json | 8 ++------ .../05/GHSA-9r8f-8mgm-rgr6/GHSA-9r8f-8mgm-rgr6.json | 12 +++--------- .../05/GHSA-9r9m-3jrr-2qqp/GHSA-9r9m-3jrr-2qqp.json | 12 +++--------- .../05/GHSA-9rpc-7358-gg7j/GHSA-9rpc-7358-gg7j.json | 12 +++--------- .../05/GHSA-9rqj-h33r-qgm8/GHSA-9rqj-h33r-qgm8.json | 8 ++------ .../05/GHSA-9rvf-pr75-p78c/GHSA-9rvf-pr75-p78c.json | 12 +++--------- .../05/GHSA-9v6p-vgp6-gj4x/GHSA-9v6p-vgp6-gj4x.json | 4 +--- .../05/GHSA-9vpc-3ghg-r29c/GHSA-9vpc-3ghg-r29c.json | 12 +++--------- .../05/GHSA-9w4g-4569-rg67/GHSA-9w4g-4569-rg67.json | 12 +++--------- .../05/GHSA-9x54-gxfh-qxvm/GHSA-9x54-gxfh-qxvm.json | 12 +++--------- .../05/GHSA-9xgw-72w6-j5wc/GHSA-9xgw-72w6-j5wc.json | 12 +++--------- .../05/GHSA-9xx5-rr5h-pjg2/GHSA-9xx5-rr5h-pjg2.json | 12 +++--------- .../05/GHSA-c243-364q-9gwf/GHSA-c243-364q-9gwf.json | 4 +--- .../05/GHSA-c354-v653-2qqr/GHSA-c354-v653-2qqr.json | 8 ++------ .../05/GHSA-c3m7-gw6j-3wx2/GHSA-c3m7-gw6j-3wx2.json | 8 ++------ .../05/GHSA-c3w4-9cvr-8v4j/GHSA-c3w4-9cvr-8v4j.json | 12 +++--------- .../05/GHSA-c497-q93h-cf8j/GHSA-c497-q93h-cf8j.json | 8 ++------ .../05/GHSA-c4rm-hpgr-mj62/GHSA-c4rm-hpgr-mj62.json | 12 +++--------- .../05/GHSA-c56p-qjh9-5gqm/GHSA-c56p-qjh9-5gqm.json | 8 ++------ .../05/GHSA-c5mf-3x7w-27g9/GHSA-c5mf-3x7w-27g9.json | 12 +++--------- .../05/GHSA-c5r6-553p-7qm8/GHSA-c5r6-553p-7qm8.json | 8 ++------ .../05/GHSA-c7pc-2qhp-jgch/GHSA-c7pc-2qhp-jgch.json | 12 +++--------- .../05/GHSA-c8f9-q937-86mv/GHSA-c8f9-q937-86mv.json | 12 +++--------- .../05/GHSA-c8x2-fgvf-cxj9/GHSA-c8x2-fgvf-cxj9.json | 8 ++------ .../05/GHSA-c939-x98h-rxrc/GHSA-c939-x98h-rxrc.json | 8 ++------ .../05/GHSA-c99h-qrmx-p2vc/GHSA-c99h-qrmx-p2vc.json | 12 +++--------- .../05/GHSA-c9vc-847w-w9p5/GHSA-c9vc-847w-w9p5.json | 8 ++------ .../05/GHSA-cc6f-j84g-6gmr/GHSA-cc6f-j84g-6gmr.json | 8 ++------ .../05/GHSA-ccqm-h4g9-xv4v/GHSA-ccqm-h4g9-xv4v.json | 8 ++------ .../05/GHSA-cfgm-gh5v-x98w/GHSA-cfgm-gh5v-x98w.json | 8 ++------ .../05/GHSA-cg43-6rv4-f24m/GHSA-cg43-6rv4-f24m.json | 8 ++------ .../05/GHSA-cgvh-3r4w-r8v7/GHSA-cgvh-3r4w-r8v7.json | 8 ++------ .../05/GHSA-chfv-xhr2-p6ww/GHSA-chfv-xhr2-p6ww.json | 12 +++--------- .../05/GHSA-cjfc-p2gj-cv87/GHSA-cjfc-p2gj-cv87.json | 8 ++------ .../05/GHSA-cjmp-q329-278j/GHSA-cjmp-q329-278j.json | 8 ++------ .../05/GHSA-cm3f-4fjm-xqwf/GHSA-cm3f-4fjm-xqwf.json | 12 +++--------- .../05/GHSA-cm3p-j4f2-pc4m/GHSA-cm3p-j4f2-pc4m.json | 8 ++------ .../05/GHSA-cm69-2c6j-6pvp/GHSA-cm69-2c6j-6pvp.json | 8 ++------ .../05/GHSA-cmhq-396f-qxrf/GHSA-cmhq-396f-qxrf.json | 12 +++--------- .../05/GHSA-cmxj-r24c-gf8p/GHSA-cmxj-r24c-gf8p.json | 8 ++------ .../05/GHSA-cp2r-rvgm-x6rh/GHSA-cp2r-rvgm-x6rh.json | 4 +--- .../05/GHSA-cp5f-x2vj-pqgh/GHSA-cp5f-x2vj-pqgh.json | 8 ++------ .../05/GHSA-cpfg-9xhh-m7cm/GHSA-cpfg-9xhh-m7cm.json | 12 +++--------- .../05/GHSA-cpvp-q5mv-cx2q/GHSA-cpvp-q5mv-cx2q.json | 8 ++------ .../05/GHSA-cqhr-xwvr-x8f9/GHSA-cqhr-xwvr-x8f9.json | 4 +--- .../05/GHSA-cqqm-5v99-78h5/GHSA-cqqm-5v99-78h5.json | 8 ++------ .../05/GHSA-crvj-v2xg-pq76/GHSA-crvj-v2xg-pq76.json | 12 +++--------- .../05/GHSA-crwc-423j-w3mj/GHSA-crwc-423j-w3mj.json | 12 +++--------- .../05/GHSA-cw35-8jqv-8rfq/GHSA-cw35-8jqv-8rfq.json | 8 ++------ .../05/GHSA-cw8x-jrx2-378j/GHSA-cw8x-jrx2-378j.json | 8 ++------ .../05/GHSA-cwpm-59m6-8648/GHSA-cwpm-59m6-8648.json | 12 +++--------- .../05/GHSA-cwvc-jrh4-j53h/GHSA-cwvc-jrh4-j53h.json | 12 +++--------- .../05/GHSA-cxf9-4ff5-hx4j/GHSA-cxf9-4ff5-hx4j.json | 8 ++------ .../05/GHSA-cxm5-87x2-49fh/GHSA-cxm5-87x2-49fh.json | 12 +++--------- .../05/GHSA-cxrm-q29h-frv4/GHSA-cxrm-q29h-frv4.json | 12 +++--------- .../05/GHSA-cxvf-5j6c-r2hw/GHSA-cxvf-5j6c-r2hw.json | 12 +++--------- .../05/GHSA-cxxw-rfqc-pqx7/GHSA-cxxw-rfqc-pqx7.json | 8 ++------ .../05/GHSA-f2hj-jpwp-p6pp/GHSA-f2hj-jpwp-p6pp.json | 12 +++--------- .../05/GHSA-f2ph-fm4w-vfqw/GHSA-f2ph-fm4w-vfqw.json | 12 +++--------- .../05/GHSA-f38c-74h5-hh3j/GHSA-f38c-74h5-hh3j.json | 12 +++--------- .../05/GHSA-f3ww-5jpf-ch84/GHSA-f3ww-5jpf-ch84.json | 12 +++--------- .../05/GHSA-f47x-r3wj-9vxc/GHSA-f47x-r3wj-9vxc.json | 8 ++------ .../05/GHSA-f4v5-c35c-fm7m/GHSA-f4v5-c35c-fm7m.json | 12 +++--------- .../05/GHSA-f5m5-9gwg-wj8v/GHSA-f5m5-9gwg-wj8v.json | 8 ++------ .../05/GHSA-f66h-6w2v-hxhr/GHSA-f66h-6w2v-hxhr.json | 12 +++--------- .../05/GHSA-f6j8-h69q-85jh/GHSA-f6j8-h69q-85jh.json | 12 +++--------- .../05/GHSA-f77q-prc8-hp2f/GHSA-f77q-prc8-hp2f.json | 12 +++--------- .../05/GHSA-f8xr-vx48-q3fh/GHSA-f8xr-vx48-q3fh.json | 8 ++------ .../05/GHSA-f95v-w3cx-q9fg/GHSA-f95v-w3cx-q9fg.json | 12 +++--------- .../05/GHSA-f97x-f6x5-pmh9/GHSA-f97x-f6x5-pmh9.json | 12 +++--------- .../05/GHSA-f98m-j6f8-7632/GHSA-f98m-j6f8-7632.json | 8 ++------ .../05/GHSA-f9cg-jhm7-4fw7/GHSA-f9cg-jhm7-4fw7.json | 8 ++------ .../05/GHSA-f9gf-mv67-x4h6/GHSA-f9gf-mv67-x4h6.json | 8 ++------ .../05/GHSA-f9j8-wqgr-64w4/GHSA-f9j8-wqgr-64w4.json | 12 +++--------- .../05/GHSA-f9qg-252f-g8cg/GHSA-f9qg-252f-g8cg.json | 4 +--- .../05/GHSA-f9wq-3588-gpmc/GHSA-f9wq-3588-gpmc.json | 8 ++------ .../05/GHSA-fcm2-h2g5-2hxc/GHSA-fcm2-h2g5-2hxc.json | 8 ++------ .../05/GHSA-fcmq-72mc-hj3x/GHSA-fcmq-72mc-hj3x.json | 12 +++--------- .../05/GHSA-fcx4-3mfw-82qr/GHSA-fcx4-3mfw-82qr.json | 12 +++--------- .../05/GHSA-ff36-v98j-xr5x/GHSA-ff36-v98j-xr5x.json | 8 ++------ .../05/GHSA-fg7c-85hr-w8hp/GHSA-fg7c-85hr-w8hp.json | 12 +++--------- .../05/GHSA-fgc6-r27g-4r9x/GHSA-fgc6-r27g-4r9x.json | 8 ++------ .../05/GHSA-fgq5-6x94-h566/GHSA-fgq5-6x94-h566.json | 4 +--- .../05/GHSA-fj9m-wfgj-34gq/GHSA-fj9m-wfgj-34gq.json | 8 ++------ .../05/GHSA-fjc5-6pxf-p2h2/GHSA-fjc5-6pxf-p2h2.json | 12 +++--------- .../05/GHSA-fjgf-fwh5-r5mp/GHSA-fjgf-fwh5-r5mp.json | 8 ++------ .../05/GHSA-fm3m-c8g9-95rj/GHSA-fm3m-c8g9-95rj.json | 8 ++------ .../05/GHSA-fm4f-mfw8-25x9/GHSA-fm4f-mfw8-25x9.json | 8 ++------ .../05/GHSA-fmc4-4chw-q2xg/GHSA-fmc4-4chw-q2xg.json | 8 ++------ .../05/GHSA-fmjm-xh2h-5w4j/GHSA-fmjm-xh2h-5w4j.json | 12 +++--------- .../05/GHSA-fp6q-wmwj-3m9p/GHSA-fp6q-wmwj-3m9p.json | 8 ++------ .../05/GHSA-fpxv-r955-frj8/GHSA-fpxv-r955-frj8.json | 12 +++--------- .../05/GHSA-fqc6-r979-86v4/GHSA-fqc6-r979-86v4.json | 8 ++------ .../05/GHSA-frfj-xhqr-qppx/GHSA-frfj-xhqr-qppx.json | 12 +++--------- .../05/GHSA-frfq-mg43-f6jj/GHSA-frfq-mg43-f6jj.json | 8 ++------ .../05/GHSA-frm8-c9x4-2pg5/GHSA-frm8-c9x4-2pg5.json | 12 +++--------- .../05/GHSA-fwcv-f59x-qg35/GHSA-fwcv-f59x-qg35.json | 12 +++--------- .../05/GHSA-fwqw-65p3-5cgj/GHSA-fwqw-65p3-5cgj.json | 8 ++------ .../05/GHSA-fww6-qcmh-hvxh/GHSA-fww6-qcmh-hvxh.json | 8 ++------ .../05/GHSA-fx3m-586f-fprw/GHSA-fx3m-586f-fprw.json | 8 ++------ .../05/GHSA-fx72-qxjg-3p34/GHSA-fx72-qxjg-3p34.json | 12 +++--------- .../05/GHSA-fxfq-qgmr-6pwm/GHSA-fxfq-qgmr-6pwm.json | 4 +--- .../05/GHSA-g3ff-6f3f-hmmm/GHSA-g3ff-6f3f-hmmm.json | 12 +++--------- .../05/GHSA-g3g5-fx3c-q38p/GHSA-g3g5-fx3c-q38p.json | 12 +++--------- .../05/GHSA-g3rq-5w5q-9rf3/GHSA-g3rq-5w5q-9rf3.json | 12 +++--------- .../05/GHSA-g45r-9j86-hw63/GHSA-g45r-9j86-hw63.json | 12 +++--------- .../05/GHSA-g464-39xh-j4rf/GHSA-g464-39xh-j4rf.json | 4 +--- .../05/GHSA-g4fc-j79q-gjrh/GHSA-g4fc-j79q-gjrh.json | 12 +++--------- .../05/GHSA-g4w8-pfqw-c67x/GHSA-g4w8-pfqw-c67x.json | 8 ++------ .../05/GHSA-g582-rhhm-jpjg/GHSA-g582-rhhm-jpjg.json | 8 ++------ .../05/GHSA-g6mx-39w4-hq8g/GHSA-g6mx-39w4-hq8g.json | 12 +++--------- .../05/GHSA-g6v2-6f4v-g5x2/GHSA-g6v2-6f4v-g5x2.json | 12 +++--------- .../05/GHSA-g7cf-4hgh-v7qf/GHSA-g7cf-4hgh-v7qf.json | 4 +--- .../05/GHSA-g7wm-23xp-52w7/GHSA-g7wm-23xp-52w7.json | 12 +++--------- .../05/GHSA-g862-phf8-4g6f/GHSA-g862-phf8-4g6f.json | 12 +++--------- .../05/GHSA-g8rq-cfjj-j3hv/GHSA-g8rq-cfjj-j3hv.json | 8 ++------ .../05/GHSA-g9h8-qwjr-wjcp/GHSA-g9h8-qwjr-wjcp.json | 12 +++--------- .../05/GHSA-gc4c-2wvp-mgjx/GHSA-gc4c-2wvp-mgjx.json | 12 +++--------- .../05/GHSA-gc6j-585v-g367/GHSA-gc6j-585v-g367.json | 12 +++--------- .../05/GHSA-gcv5-33hh-8rwr/GHSA-gcv5-33hh-8rwr.json | 8 ++------ .../05/GHSA-gcxf-4jrr-qpg3/GHSA-gcxf-4jrr-qpg3.json | 8 ++------ .../05/GHSA-gf4j-2pqh-6c38/GHSA-gf4j-2pqh-6c38.json | 8 ++------ .../05/GHSA-gfmf-9j98-4w68/GHSA-gfmf-9j98-4w68.json | 12 +++--------- .../05/GHSA-gg35-v4g5-3323/GHSA-gg35-v4g5-3323.json | 12 +++--------- .../05/GHSA-ggcc-jfxp-hxph/GHSA-ggcc-jfxp-hxph.json | 8 ++------ .../05/GHSA-ggcm-cr9q-hv99/GHSA-ggcm-cr9q-hv99.json | 12 +++--------- .../05/GHSA-ggf5-69xh-578m/GHSA-ggf5-69xh-578m.json | 8 ++------ .../05/GHSA-gj43-r55q-5h6r/GHSA-gj43-r55q-5h6r.json | 8 ++------ .../05/GHSA-gjhp-fhfw-fvx3/GHSA-gjhp-fhfw-fvx3.json | 12 +++--------- .../05/GHSA-gjj2-426f-v32h/GHSA-gjj2-426f-v32h.json | 12 +++--------- .../05/GHSA-gp48-r6vg-ff9x/GHSA-gp48-r6vg-ff9x.json | 12 +++--------- .../05/GHSA-gpj5-98pq-4552/GHSA-gpj5-98pq-4552.json | 4 +--- .../05/GHSA-gpjh-g6x2-2qg7/GHSA-gpjh-g6x2-2qg7.json | 8 ++------ .../05/GHSA-gppg-373r-fpj5/GHSA-gppg-373r-fpj5.json | 8 ++------ .../05/GHSA-gpvc-2qwg-r73m/GHSA-gpvc-2qwg-r73m.json | 12 +++--------- .../05/GHSA-gqc5-fq98-6v4q/GHSA-gqc5-fq98-6v4q.json | 4 +--- .../05/GHSA-gqgg-4792-53wc/GHSA-gqgg-4792-53wc.json | 12 +++--------- .../05/GHSA-gr24-p6jg-5222/GHSA-gr24-p6jg-5222.json | 12 +++--------- .../05/GHSA-gr6c-576g-h3q2/GHSA-gr6c-576g-h3q2.json | 8 ++------ .../05/GHSA-grq2-2v86-6ppx/GHSA-grq2-2v86-6ppx.json | 4 +--- .../05/GHSA-gv66-cg63-7j52/GHSA-gv66-cg63-7j52.json | 12 +++--------- .../05/GHSA-gvph-v5gg-8pcr/GHSA-gvph-v5gg-8pcr.json | 12 +++--------- .../05/GHSA-gvww-85jq-9q22/GHSA-gvww-85jq-9q22.json | 12 +++--------- .../05/GHSA-gw58-6f33-3447/GHSA-gw58-6f33-3447.json | 8 ++------ .../05/GHSA-gw88-r7fv-vm9q/GHSA-gw88-r7fv-vm9q.json | 12 +++--------- .../05/GHSA-gwjf-hjm7-xvq3/GHSA-gwjf-hjm7-xvq3.json | 8 ++------ .../05/GHSA-gww8-rh9f-5mjq/GHSA-gww8-rh9f-5mjq.json | 4 +--- .../05/GHSA-gwwq-j5vg-7jc3/GHSA-gwwq-j5vg-7jc3.json | 8 ++------ .../05/GHSA-gwxq-89pj-48g2/GHSA-gwxq-89pj-48g2.json | 12 +++--------- .../05/GHSA-gx5h-wrvw-rqjf/GHSA-gx5h-wrvw-rqjf.json | 8 ++------ .../05/GHSA-gxwg-94gc-r879/GHSA-gxwg-94gc-r879.json | 12 +++--------- .../05/GHSA-h222-ch2w-vqfv/GHSA-h222-ch2w-vqfv.json | 8 ++------ .../05/GHSA-h3qw-4vm7-5c48/GHSA-h3qw-4vm7-5c48.json | 12 +++--------- .../05/GHSA-h3rv-9c6w-cv3x/GHSA-h3rv-9c6w-cv3x.json | 8 ++------ .../05/GHSA-h4cc-27hc-fw7g/GHSA-h4cc-27hc-fw7g.json | 8 ++------ .../05/GHSA-h5c4-m5m7-866w/GHSA-h5c4-m5m7-866w.json | 12 +++--------- .../05/GHSA-h633-35pq-jqw2/GHSA-h633-35pq-jqw2.json | 12 +++--------- .../05/GHSA-h6pw-5prw-wv25/GHSA-h6pw-5prw-wv25.json | 12 +++--------- .../05/GHSA-h724-3h22-3p4x/GHSA-h724-3h22-3p4x.json | 8 ++------ .../05/GHSA-h75m-rwwv-6vcq/GHSA-h75m-rwwv-6vcq.json | 8 ++------ .../05/GHSA-h78m-q2g5-r2v4/GHSA-h78m-q2g5-r2v4.json | 12 +++--------- .../05/GHSA-h7mv-xp82-8pqc/GHSA-h7mv-xp82-8pqc.json | 8 ++------ .../05/GHSA-h7rf-79wj-2jmh/GHSA-h7rf-79wj-2jmh.json | 12 +++--------- .../05/GHSA-h8gr-3vg4-vhgx/GHSA-h8gr-3vg4-vhgx.json | 12 +++--------- .../05/GHSA-h8hx-p593-xwmc/GHSA-h8hx-p593-xwmc.json | 8 ++------ .../05/GHSA-h9c7-5m8v-93ph/GHSA-h9c7-5m8v-93ph.json | 8 ++------ .../05/GHSA-h9pm-m4wm-2v5x/GHSA-h9pm-m4wm-2v5x.json | 8 ++------ .../05/GHSA-h9qq-297c-38mx/GHSA-h9qq-297c-38mx.json | 8 ++------ .../05/GHSA-hc37-45rc-736p/GHSA-hc37-45rc-736p.json | 8 ++------ .../05/GHSA-hc75-g4hp-4wp6/GHSA-hc75-g4hp-4wp6.json | 12 +++--------- .../05/GHSA-hc8p-gq8j-4gjq/GHSA-hc8p-gq8j-4gjq.json | 8 ++------ .../05/GHSA-hf2f-mj6g-rh32/GHSA-hf2f-mj6g-rh32.json | 8 ++------ .../05/GHSA-hf48-cw5q-wjpm/GHSA-hf48-cw5q-wjpm.json | 4 +--- .../05/GHSA-hff4-9w57-p64w/GHSA-hff4-9w57-p64w.json | 12 +++--------- .../05/GHSA-hfg4-62f6-fjff/GHSA-hfg4-62f6-fjff.json | 8 ++------ .../05/GHSA-hfh7-m9jr-j829/GHSA-hfh7-m9jr-j829.json | 8 ++------ .../05/GHSA-hfqm-gjfq-m7ph/GHSA-hfqm-gjfq-m7ph.json | 12 +++--------- .../05/GHSA-hfw9-q3f6-gv7r/GHSA-hfw9-q3f6-gv7r.json | 12 +++--------- .../05/GHSA-hfxg-ph49-2mw5/GHSA-hfxg-ph49-2mw5.json | 8 ++------ .../05/GHSA-hg99-6rrx-j29j/GHSA-hg99-6rrx-j29j.json | 12 +++--------- .../05/GHSA-hh5p-vgjc-p9vq/GHSA-hh5p-vgjc-p9vq.json | 12 +++--------- .../05/GHSA-hhcx-g8h7-2m9h/GHSA-hhcx-g8h7-2m9h.json | 8 ++------ .../05/GHSA-hhhm-592j-2r47/GHSA-hhhm-592j-2r47.json | 8 ++------ .../05/GHSA-hhjr-xgqf-mpfc/GHSA-hhjr-xgqf-mpfc.json | 8 ++------ .../05/GHSA-hhpx-68fp-4gm4/GHSA-hhpx-68fp-4gm4.json | 4 +--- .../05/GHSA-hj5w-45wx-h9rg/GHSA-hj5w-45wx-h9rg.json | 8 ++------ .../05/GHSA-hjg4-m8gp-mxjw/GHSA-hjg4-m8gp-mxjw.json | 12 +++--------- .../05/GHSA-hjrv-6xv3-c6x3/GHSA-hjrv-6xv3-c6x3.json | 4 +--- .../05/GHSA-hjwv-q93r-4mwm/GHSA-hjwv-q93r-4mwm.json | 12 +++--------- .../05/GHSA-hm75-8hcq-5577/GHSA-hm75-8hcq-5577.json | 12 +++--------- .../05/GHSA-hm86-5wcm-m7h2/GHSA-hm86-5wcm-m7h2.json | 8 ++------ .../05/GHSA-hp87-wrg5-gq65/GHSA-hp87-wrg5-gq65.json | 12 +++--------- .../05/GHSA-hpcp-c3rh-8639/GHSA-hpcp-c3rh-8639.json | 12 +++--------- .../05/GHSA-hpj4-57qp-2v2m/GHSA-hpj4-57qp-2v2m.json | 8 ++------ .../05/GHSA-hpj8-7jw7-hq79/GHSA-hpj8-7jw7-hq79.json | 8 ++------ .../05/GHSA-hq2m-v8jg-cf3p/GHSA-hq2m-v8jg-cf3p.json | 12 +++--------- .../05/GHSA-hqqc-whmx-mjmv/GHSA-hqqc-whmx-mjmv.json | 4 +--- .../05/GHSA-hqqf-qrw3-32h8/GHSA-hqqf-qrw3-32h8.json | 12 +++--------- .../05/GHSA-hv59-832h-f7j8/GHSA-hv59-832h-f7j8.json | 8 ++------ .../05/GHSA-hvm3-c8w4-35mp/GHSA-hvm3-c8w4-35mp.json | 8 ++------ .../05/GHSA-hvwp-vm7c-5726/GHSA-hvwp-vm7c-5726.json | 12 +++--------- .../05/GHSA-hw39-2f47-g9hg/GHSA-hw39-2f47-g9hg.json | 12 +++--------- .../05/GHSA-hw4x-r4pq-p2rw/GHSA-hw4x-r4pq-p2rw.json | 12 +++--------- .../05/GHSA-hw72-fhc8-8qf4/GHSA-hw72-fhc8-8qf4.json | 12 +++--------- .../05/GHSA-hwr5-xvv8-wh2p/GHSA-hwr5-xvv8-wh2p.json | 8 ++------ .../05/GHSA-hx73-9v9m-r63j/GHSA-hx73-9v9m-r63j.json | 12 +++--------- .../05/GHSA-j22h-wh6q-9q3g/GHSA-j22h-wh6q-9q3g.json | 12 +++--------- .../05/GHSA-j2xw-7659-7rj6/GHSA-j2xw-7659-7rj6.json | 12 +++--------- .../05/GHSA-j39x-23p8-9mpq/GHSA-j39x-23p8-9mpq.json | 12 +++--------- .../05/GHSA-j3qx-4gvc-v53m/GHSA-j3qx-4gvc-v53m.json | 8 ++------ .../05/GHSA-j3x8-q72p-pvhp/GHSA-j3x8-q72p-pvhp.json | 12 +++--------- .../05/GHSA-j5mp-hh89-pmcx/GHSA-j5mp-hh89-pmcx.json | 12 +++--------- .../05/GHSA-j5xw-6p2w-wwpf/GHSA-j5xw-6p2w-wwpf.json | 12 +++--------- .../05/GHSA-j688-25qj-6vvv/GHSA-j688-25qj-6vvv.json | 12 +++--------- .../05/GHSA-j6cj-94fh-962f/GHSA-j6cj-94fh-962f.json | 8 ++------ .../05/GHSA-j6h2-xp4h-4c6g/GHSA-j6h2-xp4h-4c6g.json | 12 +++--------- .../05/GHSA-j748-pf6h-h5f8/GHSA-j748-pf6h-h5f8.json | 8 ++------ .../05/GHSA-j776-m8gg-r576/GHSA-j776-m8gg-r576.json | 12 +++--------- .../05/GHSA-j79c-f2gc-9f4j/GHSA-j79c-f2gc-9f4j.json | 12 +++--------- .../05/GHSA-jccf-vqp8-v3mm/GHSA-jccf-vqp8-v3mm.json | 8 ++------ .../05/GHSA-jcj6-hcrj-4hgv/GHSA-jcj6-hcrj-4hgv.json | 8 ++------ .../05/GHSA-jcp2-cx35-47gg/GHSA-jcp2-cx35-47gg.json | 8 ++------ .../05/GHSA-jf2v-jqgc-vr97/GHSA-jf2v-jqgc-vr97.json | 8 ++------ .../05/GHSA-jf84-45wf-mjgm/GHSA-jf84-45wf-mjgm.json | 4 +--- .../05/GHSA-jg54-6p86-rp5q/GHSA-jg54-6p86-rp5q.json | 12 +++--------- .../05/GHSA-jghc-2mp4-x4fj/GHSA-jghc-2mp4-x4fj.json | 8 ++------ .../05/GHSA-jghx-rx2p-62q9/GHSA-jghx-rx2p-62q9.json | 8 ++------ .../05/GHSA-jgw4-3xpf-hvpv/GHSA-jgw4-3xpf-hvpv.json | 8 ++------ .../05/GHSA-jgwv-g855-m766/GHSA-jgwv-g855-m766.json | 12 +++--------- .../05/GHSA-jjmq-qm7v-gx76/GHSA-jjmq-qm7v-gx76.json | 8 ++------ .../05/GHSA-jjvw-69xc-975m/GHSA-jjvw-69xc-975m.json | 12 +++--------- .../05/GHSA-jm3v-7p2w-cvmp/GHSA-jm3v-7p2w-cvmp.json | 8 ++------ .../05/GHSA-jp5m-9hr9-82w2/GHSA-jp5m-9hr9-82w2.json | 8 ++------ .../05/GHSA-jp7p-c272-p959/GHSA-jp7p-c272-p959.json | 8 ++------ .../05/GHSA-jphx-j9jw-r6cr/GHSA-jphx-j9jw-r6cr.json | 12 +++--------- .../05/GHSA-jpp9-ph8w-g7g3/GHSA-jpp9-ph8w-g7g3.json | 12 +++--------- .../05/GHSA-jr28-h3mc-x46r/GHSA-jr28-h3mc-x46r.json | 12 +++--------- .../05/GHSA-jr8m-qx83-r6p3/GHSA-jr8m-qx83-r6p3.json | 12 +++--------- .../05/GHSA-jvj6-gw3m-g9hf/GHSA-jvj6-gw3m-g9hf.json | 8 ++------ .../05/GHSA-jwmg-q4wv-f75h/GHSA-jwmg-q4wv-f75h.json | 8 ++------ .../05/GHSA-m24v-9xcf-xr26/GHSA-m24v-9xcf-xr26.json | 12 +++--------- .../05/GHSA-m2m5-p4p4-3w6r/GHSA-m2m5-p4p4-3w6r.json | 8 ++------ .../05/GHSA-m373-x696-qcxc/GHSA-m373-x696-qcxc.json | 12 +++--------- .../05/GHSA-m439-jg5v-8cp2/GHSA-m439-jg5v-8cp2.json | 12 +++--------- .../05/GHSA-m4jf-3r59-83j5/GHSA-m4jf-3r59-83j5.json | 8 ++------ .../05/GHSA-m4w5-gcq7-74fp/GHSA-m4w5-gcq7-74fp.json | 12 +++--------- .../05/GHSA-m59h-qpxv-j78w/GHSA-m59h-qpxv-j78w.json | 12 +++--------- .../05/GHSA-m5jg-j887-v87q/GHSA-m5jg-j887-v87q.json | 12 +++--------- .../05/GHSA-m67h-g698-3wr3/GHSA-m67h-g698-3wr3.json | 8 ++------ .../05/GHSA-m6hh-6w6m-5h5c/GHSA-m6hh-6w6m-5h5c.json | 8 ++------ .../05/GHSA-m739-9w4c-mx4g/GHSA-m739-9w4c-mx4g.json | 12 +++--------- .../05/GHSA-m7mq-hvr6-vqf7/GHSA-m7mq-hvr6-vqf7.json | 12 +++--------- .../05/GHSA-m8qq-fqgv-mw3c/GHSA-m8qq-fqgv-mw3c.json | 12 +++--------- .../05/GHSA-m93c-j7hg-hwmj/GHSA-m93c-j7hg-hwmj.json | 4 +--- .../05/GHSA-m942-g3j4-p4jh/GHSA-m942-g3j4-p4jh.json | 4 +--- .../05/GHSA-m98h-48v7-g4f9/GHSA-m98h-48v7-g4f9.json | 8 ++------ .../05/GHSA-m9cm-8x3h-gr6j/GHSA-m9cm-8x3h-gr6j.json | 8 ++------ .../05/GHSA-mc2x-3fjp-hwc7/GHSA-mc2x-3fjp-hwc7.json | 8 ++------ .../05/GHSA-mchx-3rmv-f23h/GHSA-mchx-3rmv-f23h.json | 12 +++--------- .../05/GHSA-mcw3-qqp9-m3r9/GHSA-mcw3-qqp9-m3r9.json | 8 ++------ .../05/GHSA-mcwj-mj5h-p34c/GHSA-mcwj-mj5h-p34c.json | 8 ++------ .../05/GHSA-mf6j-54v8-45qr/GHSA-mf6j-54v8-45qr.json | 8 ++------ .../05/GHSA-mfcq-4jh5-jjj3/GHSA-mfcq-4jh5-jjj3.json | 12 +++--------- .../05/GHSA-mgqc-hq49-84rm/GHSA-mgqc-hq49-84rm.json | 12 +++--------- .../05/GHSA-mgr7-vch3-x89h/GHSA-mgr7-vch3-x89h.json | 8 ++------ .../05/GHSA-mhx2-29jj-rxfr/GHSA-mhx2-29jj-rxfr.json | 8 ++------ .../05/GHSA-mhxc-vmch-9frr/GHSA-mhxc-vmch-9frr.json | 12 +++--------- .../05/GHSA-mhxv-2pvp-28fg/GHSA-mhxv-2pvp-28fg.json | 12 +++--------- .../05/GHSA-mjg6-fgp9-mhgq/GHSA-mjg6-fgp9-mhgq.json | 8 ++------ .../05/GHSA-mjqw-m6f3-h86r/GHSA-mjqw-m6f3-h86r.json | 12 +++--------- .../05/GHSA-mjrp-x8v8-f2mx/GHSA-mjrp-x8v8-f2mx.json | 8 ++------ .../05/GHSA-mjrv-5v4q-78q6/GHSA-mjrv-5v4q-78q6.json | 12 +++--------- .../05/GHSA-mm72-4ppf-mcx7/GHSA-mm72-4ppf-mcx7.json | 8 ++------ .../05/GHSA-mp45-465m-vg8h/GHSA-mp45-465m-vg8h.json | 8 ++------ .../05/GHSA-mp66-x979-42jc/GHSA-mp66-x979-42jc.json | 4 +--- .../05/GHSA-mpq8-w9f5-qm6g/GHSA-mpq8-w9f5-qm6g.json | 8 ++------ .../05/GHSA-mq5c-744g-f8pj/GHSA-mq5c-744g-f8pj.json | 8 ++------ .../05/GHSA-mq98-f72q-hfx8/GHSA-mq98-f72q-hfx8.json | 8 ++------ .../05/GHSA-mqfq-wxw5-3h9w/GHSA-mqfq-wxw5-3h9w.json | 8 ++------ .../05/GHSA-mr2h-fcf6-jvx9/GHSA-mr2h-fcf6-jvx9.json | 8 ++------ .../05/GHSA-mr3f-mq88-r8jq/GHSA-mr3f-mq88-r8jq.json | 8 ++------ .../05/GHSA-mvjf-gwx8-f39c/GHSA-mvjf-gwx8-f39c.json | 12 +++--------- .../05/GHSA-mvjq-qw5h-9cj2/GHSA-mvjq-qw5h-9cj2.json | 8 ++------ .../05/GHSA-mw3j-855g-6jp8/GHSA-mw3j-855g-6jp8.json | 12 +++--------- .../05/GHSA-mwcr-69m6-hxrj/GHSA-mwcr-69m6-hxrj.json | 12 +++--------- .../05/GHSA-mwjx-c93w-r993/GHSA-mwjx-c93w-r993.json | 8 ++------ .../05/GHSA-mwr7-fm5x-rqch/GHSA-mwr7-fm5x-rqch.json | 8 ++------ .../05/GHSA-mwwv-4h92-28r2/GHSA-mwwv-4h92-28r2.json | 8 ++------ .../05/GHSA-mx5c-gqhr-8r8j/GHSA-mx5c-gqhr-8r8j.json | 8 ++------ .../05/GHSA-p2f3-wgvc-4w8q/GHSA-p2f3-wgvc-4w8q.json | 8 ++------ .../05/GHSA-p365-3j3h-vmq6/GHSA-p365-3j3h-vmq6.json | 12 +++--------- .../05/GHSA-p3r9-6fhw-hgv8/GHSA-p3r9-6fhw-hgv8.json | 8 ++------ .../05/GHSA-p463-qxf4-3j5v/GHSA-p463-qxf4-3j5v.json | 8 ++------ .../05/GHSA-p4g7-w48q-p4cp/GHSA-p4g7-w48q-p4cp.json | 8 ++------ .../05/GHSA-p4ww-48c6-98q5/GHSA-p4ww-48c6-98q5.json | 8 ++------ .../05/GHSA-p53v-96v3-p5jg/GHSA-p53v-96v3-p5jg.json | 8 ++------ .../05/GHSA-p5rv-qv72-qcfq/GHSA-p5rv-qv72-qcfq.json | 12 +++--------- .../05/GHSA-p5xr-f67h-9rw9/GHSA-p5xr-f67h-9rw9.json | 12 +++--------- .../05/GHSA-p64p-9fg8-c6rp/GHSA-p64p-9fg8-c6rp.json | 8 ++------ .../05/GHSA-p6m6-g28j-5g3h/GHSA-p6m6-g28j-5g3h.json | 8 ++------ .../05/GHSA-p6mq-mfwr-x238/GHSA-p6mq-mfwr-x238.json | 12 +++--------- .../05/GHSA-p79w-9c5j-r2gw/GHSA-p79w-9c5j-r2gw.json | 8 ++------ .../05/GHSA-p7m9-q5j5-3jgv/GHSA-p7m9-q5j5-3jgv.json | 4 +--- .../05/GHSA-p8h5-xqwr-ww86/GHSA-p8h5-xqwr-ww86.json | 12 +++--------- .../05/GHSA-p95x-f93r-h96r/GHSA-p95x-f93r-h96r.json | 12 +++--------- .../05/GHSA-p97q-qr3w-x236/GHSA-p97q-qr3w-x236.json | 8 ++------ .../05/GHSA-p9jm-j7j3-qc5g/GHSA-p9jm-j7j3-qc5g.json | 8 ++------ .../05/GHSA-pc3j-ph7x-cxh4/GHSA-pc3j-ph7x-cxh4.json | 8 ++------ .../05/GHSA-pc9g-xxwr-7rq9/GHSA-pc9g-xxwr-7rq9.json | 12 +++--------- .../05/GHSA-pfcx-4587-hw8m/GHSA-pfcx-4587-hw8m.json | 8 ++------ .../05/GHSA-pg5g-hrxm-397x/GHSA-pg5g-hrxm-397x.json | 12 +++--------- .../05/GHSA-pgj6-vc56-h2jc/GHSA-pgj6-vc56-h2jc.json | 12 +++--------- .../05/GHSA-pgwh-c5gq-c23j/GHSA-pgwh-c5gq-c23j.json | 8 ++------ .../05/GHSA-ph36-4xx4-6m84/GHSA-ph36-4xx4-6m84.json | 12 +++--------- .../05/GHSA-ph4x-78w5-h79j/GHSA-ph4x-78w5-h79j.json | 12 +++--------- .../05/GHSA-phfp-qm4g-g8c7/GHSA-phfp-qm4g-g8c7.json | 12 +++--------- .../05/GHSA-phm5-3cqw-r759/GHSA-phm5-3cqw-r759.json | 8 ++------ .../05/GHSA-pj33-fhmh-3r7r/GHSA-pj33-fhmh-3r7r.json | 12 +++--------- .../05/GHSA-pj47-cjfq-jwp4/GHSA-pj47-cjfq-jwp4.json | 8 ++------ .../05/GHSA-pj62-vwgh-4fwm/GHSA-pj62-vwgh-4fwm.json | 8 ++------ .../05/GHSA-pjr8-522j-xrv6/GHSA-pjr8-522j-xrv6.json | 8 ++------ .../05/GHSA-pjwq-vqfj-r3hh/GHSA-pjwq-vqfj-r3hh.json | 8 ++------ .../05/GHSA-pm4x-73f3-vvmv/GHSA-pm4x-73f3-vvmv.json | 12 +++--------- .../05/GHSA-pp29-fm35-p5hj/GHSA-pp29-fm35-p5hj.json | 8 ++------ .../05/GHSA-ppqc-qvpw-j83r/GHSA-ppqc-qvpw-j83r.json | 8 ++------ .../05/GHSA-ppv3-px64-q9mx/GHSA-ppv3-px64-q9mx.json | 8 ++------ .../05/GHSA-pqwp-2662-q9j8/GHSA-pqwp-2662-q9j8.json | 8 ++------ .../05/GHSA-prp3-p73x-mqjc/GHSA-prp3-p73x-mqjc.json | 8 ++------ .../05/GHSA-prw3-h4wf-qrgf/GHSA-prw3-h4wf-qrgf.json | 12 +++--------- .../05/GHSA-prxq-rjvh-533j/GHSA-prxq-rjvh-533j.json | 8 ++------ .../05/GHSA-pv42-mm82-grf7/GHSA-pv42-mm82-grf7.json | 12 +++--------- .../05/GHSA-pvc2-qp9x-6rgw/GHSA-pvc2-qp9x-6rgw.json | 12 +++--------- .../05/GHSA-pvc6-fjgm-h5wf/GHSA-pvc6-fjgm-h5wf.json | 8 ++------ .../05/GHSA-pvwv-hr7g-828h/GHSA-pvwv-hr7g-828h.json | 12 +++--------- .../05/GHSA-pxc3-xjvh-jq8g/GHSA-pxc3-xjvh-jq8g.json | 4 +--- .../05/GHSA-pxcf-wgw3-gwc6/GHSA-pxcf-wgw3-gwc6.json | 8 ++------ .../05/GHSA-q239-wm45-8mwc/GHSA-q239-wm45-8mwc.json | 12 +++--------- .../05/GHSA-q248-f2x7-fhcp/GHSA-q248-f2x7-fhcp.json | 12 +++--------- .../05/GHSA-q24c-8cpc-8x8c/GHSA-q24c-8cpc-8x8c.json | 8 ++------ .../05/GHSA-q3gh-3g45-67qg/GHSA-q3gh-3g45-67qg.json | 8 ++------ .../05/GHSA-q3jf-3m4m-hh56/GHSA-q3jf-3m4m-hh56.json | 12 +++--------- .../05/GHSA-q3x2-wj66-pg83/GHSA-q3x2-wj66-pg83.json | 12 +++--------- .../05/GHSA-q49f-7h5w-8672/GHSA-q49f-7h5w-8672.json | 8 ++------ .../05/GHSA-q4fx-wrwr-cfpx/GHSA-q4fx-wrwr-cfpx.json | 12 +++--------- .../05/GHSA-q4g3-xp8v-q7h5/GHSA-q4g3-xp8v-q7h5.json | 8 ++------ .../05/GHSA-q4h9-78vf-qm6j/GHSA-q4h9-78vf-qm6j.json | 12 +++--------- .../05/GHSA-q58c-f3v9-6f8q/GHSA-q58c-f3v9-6f8q.json | 12 +++--------- .../05/GHSA-q5fc-7mw8-7mpw/GHSA-q5fc-7mw8-7mpw.json | 12 +++--------- .../05/GHSA-q64v-qf3j-577f/GHSA-q64v-qf3j-577f.json | 4 +--- .../05/GHSA-q695-424c-rgvg/GHSA-q695-424c-rgvg.json | 8 ++------ .../05/GHSA-q748-4qm8-j85g/GHSA-q748-4qm8-j85g.json | 8 ++------ .../05/GHSA-q74g-chvp-h29w/GHSA-q74g-chvp-h29w.json | 12 +++--------- .../05/GHSA-q7ff-8r5v-7hm4/GHSA-q7ff-8r5v-7hm4.json | 12 +++--------- .../05/GHSA-q7wg-jhfm-jvvq/GHSA-q7wg-jhfm-jvvq.json | 12 +++--------- .../05/GHSA-q862-fq6m-jgm3/GHSA-q862-fq6m-jgm3.json | 12 +++--------- .../05/GHSA-q8fm-frxv-x679/GHSA-q8fm-frxv-x679.json | 8 ++------ .../05/GHSA-q8g3-jg66-m2gf/GHSA-q8g3-jg66-m2gf.json | 12 +++--------- .../05/GHSA-q9qw-rwr9-q48r/GHSA-q9qw-rwr9-q48r.json | 8 ++------ .../05/GHSA-qc4c-fq5f-8fqw/GHSA-qc4c-fq5f-8fqw.json | 12 +++--------- .../05/GHSA-qcr8-x47x-6hrg/GHSA-qcr8-x47x-6hrg.json | 4 +--- .../05/GHSA-qgcr-7985-q5m3/GHSA-qgcr-7985-q5m3.json | 8 ++------ .../05/GHSA-qgg5-3wjc-vv47/GHSA-qgg5-3wjc-vv47.json | 12 +++--------- .../05/GHSA-qgx9-8p23-fhf6/GHSA-qgx9-8p23-fhf6.json | 8 ++------ .../05/GHSA-qgxw-h3gp-6wg8/GHSA-qgxw-h3gp-6wg8.json | 4 +--- .../05/GHSA-qh8c-7g9x-xwm7/GHSA-qh8c-7g9x-xwm7.json | 8 ++------ .../05/GHSA-qhj7-w4rj-f7f3/GHSA-qhj7-w4rj-f7f3.json | 12 +++--------- .../05/GHSA-qjgm-rr3x-5q3q/GHSA-qjgm-rr3x-5q3q.json | 8 ++------ .../05/GHSA-qjh7-2cqf-c2cr/GHSA-qjh7-2cqf-c2cr.json | 8 ++------ .../05/GHSA-qm3w-g4qw-7r33/GHSA-qm3w-g4qw-7r33.json | 12 +++--------- .../05/GHSA-qmjx-9m9f-8g3v/GHSA-qmjx-9m9f-8g3v.json | 12 +++--------- .../05/GHSA-qmxj-6jrf-6cw3/GHSA-qmxj-6jrf-6cw3.json | 12 +++--------- .../05/GHSA-qpx8-2vr9-wqjr/GHSA-qpx8-2vr9-wqjr.json | 8 ++------ .../05/GHSA-qq7c-vp73-p9c7/GHSA-qq7c-vp73-p9c7.json | 8 ++------ .../05/GHSA-qq7x-7h3g-gmhc/GHSA-qq7x-7h3g-gmhc.json | 8 ++------ .../05/GHSA-qqw5-x59w-fv9f/GHSA-qqw5-x59w-fv9f.json | 12 +++--------- .../05/GHSA-qrh7-qfjj-49gm/GHSA-qrh7-qfjj-49gm.json | 8 ++------ .../05/GHSA-qrqq-2r8j-xm27/GHSA-qrqq-2r8j-xm27.json | 8 ++------ .../05/GHSA-qrv8-99h7-2c7v/GHSA-qrv8-99h7-2c7v.json | 8 ++------ .../05/GHSA-qv48-9r5g-g6qj/GHSA-qv48-9r5g-g6qj.json | 8 ++------ .../05/GHSA-qvxf-v2fx-5hqx/GHSA-qvxf-v2fx-5hqx.json | 12 +++--------- .../05/GHSA-qw3m-7664-26j4/GHSA-qw3m-7664-26j4.json | 8 ++------ .../05/GHSA-qw4x-8mrr-5fm7/GHSA-qw4x-8mrr-5fm7.json | 12 +++--------- .../05/GHSA-qw7j-7w7w-cprp/GHSA-qw7j-7w7w-cprp.json | 8 ++------ .../05/GHSA-qwgf-v45r-4m82/GHSA-qwgf-v45r-4m82.json | 12 +++--------- .../05/GHSA-qx5v-53hw-g8w8/GHSA-qx5v-53hw-g8w8.json | 12 +++--------- .../05/GHSA-qx8p-m7p2-h44c/GHSA-qx8p-m7p2-h44c.json | 4 +--- .../05/GHSA-qxgj-gjcq-4732/GHSA-qxgj-gjcq-4732.json | 8 ++------ .../05/GHSA-qxwc-mr69-cfh8/GHSA-qxwc-mr69-cfh8.json | 8 ++------ .../05/GHSA-r24w-f52g-qphg/GHSA-r24w-f52g-qphg.json | 12 +++--------- .../05/GHSA-r25w-hm87-5pjx/GHSA-r25w-hm87-5pjx.json | 8 ++------ .../05/GHSA-r2cc-3v4v-j29x/GHSA-r2cc-3v4v-j29x.json | 12 +++--------- .../05/GHSA-r2cg-mcjc-4mp7/GHSA-r2cg-mcjc-4mp7.json | 12 +++--------- .../05/GHSA-r32j-hx54-9256/GHSA-r32j-hx54-9256.json | 12 +++--------- .../05/GHSA-r34f-76fq-39vg/GHSA-r34f-76fq-39vg.json | 8 ++------ .../05/GHSA-r37m-h85m-jrhm/GHSA-r37m-h85m-jrhm.json | 12 +++--------- .../05/GHSA-r399-j3c6-85hw/GHSA-r399-j3c6-85hw.json | 12 +++--------- .../05/GHSA-r3ch-gwjw-g759/GHSA-r3ch-gwjw-g759.json | 8 ++------ .../05/GHSA-r3fq-9r25-fh69/GHSA-r3fq-9r25-fh69.json | 8 ++------ .../05/GHSA-r3wg-3ggv-hv7p/GHSA-r3wg-3ggv-hv7p.json | 12 +++--------- .../05/GHSA-r43g-pg3m-c7c5/GHSA-r43g-pg3m-c7c5.json | 8 ++------ .../05/GHSA-r43v-pq8h-xhmw/GHSA-r43v-pq8h-xhmw.json | 12 +++--------- .../05/GHSA-r556-vcf9-958h/GHSA-r556-vcf9-958h.json | 12 +++--------- .../05/GHSA-r5j4-m35f-mj7g/GHSA-r5j4-m35f-mj7g.json | 8 ++------ .../05/GHSA-r5mj-p5rf-5r3g/GHSA-r5mj-p5rf-5r3g.json | 12 +++--------- .../05/GHSA-r5xc-hjr7-x3g4/GHSA-r5xc-hjr7-x3g4.json | 12 +++--------- .../05/GHSA-r7c8-q64w-gv6f/GHSA-r7c8-q64w-gv6f.json | 8 ++------ .../05/GHSA-r83c-5fmh-9hmm/GHSA-r83c-5fmh-9hmm.json | 12 +++--------- .../05/GHSA-r83j-cg9q-23f3/GHSA-r83j-cg9q-23f3.json | 8 ++------ .../05/GHSA-r843-6qw6-7vvp/GHSA-r843-6qw6-7vvp.json | 12 +++--------- .../05/GHSA-r85w-66g6-gv5r/GHSA-r85w-66g6-gv5r.json | 8 ++------ .../05/GHSA-r8q9-j332-6p92/GHSA-r8q9-j332-6p92.json | 8 ++------ .../05/GHSA-r8qg-vjh8-h4m5/GHSA-r8qg-vjh8-h4m5.json | 12 +++--------- .../05/GHSA-r8wh-8j3r-h3qr/GHSA-r8wh-8j3r-h3qr.json | 4 +--- .../05/GHSA-rc8p-8p78-4qgh/GHSA-rc8p-8p78-4qgh.json | 12 +++--------- .../05/GHSA-rcxf-wcpq-j795/GHSA-rcxf-wcpq-j795.json | 8 ++------ .../05/GHSA-rf2j-3ww5-qfxx/GHSA-rf2j-3ww5-qfxx.json | 12 +++--------- .../05/GHSA-rff7-c4hg-7cp9/GHSA-rff7-c4hg-7cp9.json | 12 +++--------- .../05/GHSA-rfx5-7qrj-6p2g/GHSA-rfx5-7qrj-6p2g.json | 8 ++------ .../05/GHSA-rgc7-rwpc-cphv/GHSA-rgc7-rwpc-cphv.json | 12 +++--------- .../05/GHSA-rh3c-99q9-27v6/GHSA-rh3c-99q9-27v6.json | 8 ++------ .../05/GHSA-rjgr-fh4v-v8xv/GHSA-rjgr-fh4v-v8xv.json | 12 +++--------- .../05/GHSA-rjmh-r9pq-8xrg/GHSA-rjmh-r9pq-8xrg.json | 12 +++--------- .../05/GHSA-rjq7-8vwr-777h/GHSA-rjq7-8vwr-777h.json | 12 +++--------- .../05/GHSA-rm98-fj9p-fjh8/GHSA-rm98-fj9p-fjh8.json | 12 +++--------- .../05/GHSA-rmr6-xh33-9hqc/GHSA-rmr6-xh33-9hqc.json | 8 ++------ .../05/GHSA-rq6v-h9fq-jw26/GHSA-rq6v-h9fq-jw26.json | 12 +++--------- .../05/GHSA-rqjw-5w3g-3rjv/GHSA-rqjw-5w3g-3rjv.json | 8 ++------ .../05/GHSA-rqrm-jq4f-7ph5/GHSA-rqrm-jq4f-7ph5.json | 4 +--- .../05/GHSA-rr7q-672p-8qm6/GHSA-rr7q-672p-8qm6.json | 12 +++--------- .../05/GHSA-rrv7-xh4c-v8jh/GHSA-rrv7-xh4c-v8jh.json | 12 +++--------- .../05/GHSA-rrvv-g9v3-737h/GHSA-rrvv-g9v3-737h.json | 8 ++------ .../05/GHSA-rrxc-fgqr-57wq/GHSA-rrxc-fgqr-57wq.json | 8 ++------ .../05/GHSA-rv54-hf76-46cc/GHSA-rv54-hf76-46cc.json | 8 ++------ .../05/GHSA-rvh5-44hf-h5w5/GHSA-rvh5-44hf-h5w5.json | 12 +++--------- .../05/GHSA-rvhg-h22r-mpph/GHSA-rvhg-h22r-mpph.json | 12 +++--------- .../05/GHSA-rwww-93cx-4h2h/GHSA-rwww-93cx-4h2h.json | 8 ++------ .../05/GHSA-rx8x-hjvp-cgx4/GHSA-rx8x-hjvp-cgx4.json | 12 +++--------- .../05/GHSA-v2cx-5pw8-pvw6/GHSA-v2cx-5pw8-pvw6.json | 12 +++--------- .../05/GHSA-v33h-cmh6-v795/GHSA-v33h-cmh6-v795.json | 8 ++------ .../05/GHSA-v3pv-ppv6-v9rf/GHSA-v3pv-ppv6-v9rf.json | 8 ++------ .../05/GHSA-v437-m49g-58q6/GHSA-v437-m49g-58q6.json | 12 +++--------- .../05/GHSA-v4v8-c9m3-mrwp/GHSA-v4v8-c9m3-mrwp.json | 12 +++--------- .../05/GHSA-v5w8-8m8v-3989/GHSA-v5w8-8m8v-3989.json | 12 +++--------- .../05/GHSA-v675-xwpf-pp6q/GHSA-v675-xwpf-pp6q.json | 8 ++------ .../05/GHSA-v6g9-4phq-cqx8/GHSA-v6g9-4phq-cqx8.json | 12 +++--------- .../05/GHSA-v6gq-6h27-8r9r/GHSA-v6gq-6h27-8r9r.json | 8 ++------ .../05/GHSA-v73m-wrc8-8gw3/GHSA-v73m-wrc8-8gw3.json | 12 +++--------- .../05/GHSA-v7jg-mp2h-m48g/GHSA-v7jg-mp2h-m48g.json | 8 ++------ .../05/GHSA-v7vx-g8wp-cjcv/GHSA-v7vx-g8wp-cjcv.json | 12 +++--------- .../05/GHSA-v8qg-q79m-vp4q/GHSA-v8qg-q79m-vp4q.json | 8 ++------ .../05/GHSA-v8wj-8g43-8vw2/GHSA-v8wj-8g43-8vw2.json | 12 +++--------- .../05/GHSA-v9pj-jfcj-qq69/GHSA-v9pj-jfcj-qq69.json | 8 ++------ .../05/GHSA-v9q6-j8wj-34wm/GHSA-v9q6-j8wj-34wm.json | 12 +++--------- .../05/GHSA-v9qq-wx6r-3q6x/GHSA-v9qq-wx6r-3q6x.json | 8 ++------ .../05/GHSA-vcff-gxvc-qx5x/GHSA-vcff-gxvc-qx5x.json | 8 ++------ .../05/GHSA-vcfg-5rc5-3vvf/GHSA-vcfg-5rc5-3vvf.json | 12 +++--------- .../05/GHSA-vcp8-2pmm-wpgv/GHSA-vcp8-2pmm-wpgv.json | 12 +++--------- .../05/GHSA-vcvm-p9xp-25xg/GHSA-vcvm-p9xp-25xg.json | 8 ++------ .../05/GHSA-vf2x-qf2w-jf86/GHSA-vf2x-qf2w-jf86.json | 4 +--- .../05/GHSA-vfw2-75cg-hr92/GHSA-vfw2-75cg-hr92.json | 12 +++--------- .../05/GHSA-vg73-qc4g-3qvj/GHSA-vg73-qc4g-3qvj.json | 8 ++------ .../05/GHSA-vg7v-2g2w-49jx/GHSA-vg7v-2g2w-49jx.json | 12 +++--------- .../05/GHSA-vgh3-xgw7-fjj9/GHSA-vgh3-xgw7-fjj9.json | 12 +++--------- .../05/GHSA-vhj3-xqwr-7663/GHSA-vhj3-xqwr-7663.json | 12 +++--------- .../05/GHSA-vhpw-jc69-hpmx/GHSA-vhpw-jc69-hpmx.json | 12 +++--------- .../05/GHSA-vj8g-vgph-c6mr/GHSA-vj8g-vgph-c6mr.json | 12 +++--------- .../05/GHSA-vm96-6292-3wx4/GHSA-vm96-6292-3wx4.json | 12 +++--------- .../05/GHSA-vmwf-w2vq-x4fr/GHSA-vmwf-w2vq-x4fr.json | 12 +++--------- .../05/GHSA-vq4r-hh2c-c4j9/GHSA-vq4r-hh2c-c4j9.json | 12 +++--------- .../05/GHSA-vq99-6922-hw8g/GHSA-vq99-6922-hw8g.json | 12 +++--------- .../05/GHSA-vqrw-6c7v-3ccc/GHSA-vqrw-6c7v-3ccc.json | 12 +++--------- .../05/GHSA-vw4c-q8wp-8vfx/GHSA-vw4c-q8wp-8vfx.json | 12 +++--------- .../05/GHSA-vw4j-qcmc-x4wc/GHSA-vw4j-qcmc-x4wc.json | 12 +++--------- .../05/GHSA-vw6h-px5h-9j7r/GHSA-vw6h-px5h-9j7r.json | 8 ++------ .../05/GHSA-vw74-4mhg-3rhw/GHSA-vw74-4mhg-3rhw.json | 8 ++------ .../05/GHSA-vw8w-f3p8-wppg/GHSA-vw8w-f3p8-wppg.json | 8 ++------ .../05/GHSA-vwj3-mr37-6m94/GHSA-vwj3-mr37-6m94.json | 12 +++--------- .../05/GHSA-vx2r-9h83-x7p6/GHSA-vx2r-9h83-x7p6.json | 4 +--- .../05/GHSA-w2q7-6g2f-4fq6/GHSA-w2q7-6g2f-4fq6.json | 8 ++------ .../05/GHSA-w32f-37w4-xj86/GHSA-w32f-37w4-xj86.json | 12 +++--------- .../05/GHSA-w3vx-7cpg-r478/GHSA-w3vx-7cpg-r478.json | 8 ++------ .../05/GHSA-w488-94f6-hhmr/GHSA-w488-94f6-hhmr.json | 8 ++------ .../05/GHSA-w647-5772-8rc2/GHSA-w647-5772-8rc2.json | 12 +++--------- .../05/GHSA-w6ff-43j4-cwpw/GHSA-w6ff-43j4-cwpw.json | 12 +++--------- .../05/GHSA-w749-qfxr-r5v8/GHSA-w749-qfxr-r5v8.json | 4 +--- .../05/GHSA-w786-j2g7-7hq5/GHSA-w786-j2g7-7hq5.json | 4 +--- .../05/GHSA-w7pp-vj34-5798/GHSA-w7pp-vj34-5798.json | 12 +++--------- .../05/GHSA-w8j8-w96c-962r/GHSA-w8j8-w96c-962r.json | 12 +++--------- .../05/GHSA-w8pp-xqh8-jqw5/GHSA-w8pp-xqh8-jqw5.json | 8 ++------ .../05/GHSA-w8px-4rp9-9f6w/GHSA-w8px-4rp9-9f6w.json | 8 ++------ .../05/GHSA-w8vc-93r8-r74f/GHSA-w8vc-93r8-r74f.json | 12 +++--------- .../05/GHSA-w923-q36r-x526/GHSA-w923-q36r-x526.json | 12 +++--------- .../05/GHSA-w944-h3rr-xq2p/GHSA-w944-h3rr-xq2p.json | 12 +++--------- .../05/GHSA-w98f-cwfv-c3w3/GHSA-w98f-cwfv-c3w3.json | 12 +++--------- .../05/GHSA-w9rg-rxp3-7v7q/GHSA-w9rg-rxp3-7v7q.json | 8 ++------ .../05/GHSA-wc8m-7c87-vf87/GHSA-wc8m-7c87-vf87.json | 12 +++--------- .../05/GHSA-wchm-vxgq-6gpw/GHSA-wchm-vxgq-6gpw.json | 12 +++--------- .../05/GHSA-wf3m-v872-644c/GHSA-wf3m-v872-644c.json | 12 +++--------- .../05/GHSA-wf4j-m7h5-2p32/GHSA-wf4j-m7h5-2p32.json | 12 +++--------- .../05/GHSA-wfq7-wrm9-g8vv/GHSA-wfq7-wrm9-g8vv.json | 8 ++------ .../05/GHSA-wfq8-wvj5-jv7v/GHSA-wfq8-wvj5-jv7v.json | 12 +++--------- .../05/GHSA-wfvr-3f3w-jc9w/GHSA-wfvr-3f3w-jc9w.json | 12 +++--------- .../05/GHSA-wg5j-8jqj-w57c/GHSA-wg5j-8jqj-w57c.json | 12 +++--------- .../05/GHSA-wgc2-x6j9-625v/GHSA-wgc2-x6j9-625v.json | 8 ++------ .../05/GHSA-wgx4-mfw2-ccw7/GHSA-wgx4-mfw2-ccw7.json | 4 +--- .../05/GHSA-wh95-745x-qpqc/GHSA-wh95-745x-qpqc.json | 12 +++--------- .../05/GHSA-whch-jrm6-gwgp/GHSA-whch-jrm6-gwgp.json | 12 +++--------- .../05/GHSA-whh2-g8v3-hpgj/GHSA-whh2-g8v3-hpgj.json | 12 +++--------- .../05/GHSA-whhr-fp2m-r32m/GHSA-whhr-fp2m-r32m.json | 12 +++--------- .../05/GHSA-whqr-8g89-8vg2/GHSA-whqr-8g89-8vg2.json | 8 ++------ .../05/GHSA-whrv-gm55-4x34/GHSA-whrv-gm55-4x34.json | 12 +++--------- .../05/GHSA-wjj4-8gg2-x22g/GHSA-wjj4-8gg2-x22g.json | 8 ++------ .../05/GHSA-wjr5-qv82-83cr/GHSA-wjr5-qv82-83cr.json | 8 ++------ .../05/GHSA-wm6v-hw5v-whjx/GHSA-wm6v-hw5v-whjx.json | 12 +++--------- .../05/GHSA-wm8g-494w-jg7c/GHSA-wm8g-494w-jg7c.json | 12 +++--------- .../05/GHSA-wm9j-fw55-hv9g/GHSA-wm9j-fw55-hv9g.json | 8 ++------ .../05/GHSA-wmr5-5jr5-6x3m/GHSA-wmr5-5jr5-6x3m.json | 12 +++--------- .../05/GHSA-wr3h-m9xx-fcq4/GHSA-wr3h-m9xx-fcq4.json | 8 ++------ .../05/GHSA-wr7r-934x-8mmg/GHSA-wr7r-934x-8mmg.json | 12 +++--------- .../05/GHSA-wrg2-vhfj-3vvq/GHSA-wrg2-vhfj-3vvq.json | 12 +++--------- .../05/GHSA-wrg7-24rr-rgcq/GHSA-wrg7-24rr-rgcq.json | 8 ++------ .../05/GHSA-wrqj-gjcp-v24r/GHSA-wrqj-gjcp-v24r.json | 8 ++------ .../05/GHSA-ww3h-g64f-837r/GHSA-ww3h-g64f-837r.json | 8 ++------ .../05/GHSA-wxh7-2jp7-rww4/GHSA-wxh7-2jp7-rww4.json | 8 ++------ .../05/GHSA-x2g7-49qc-5qgg/GHSA-x2g7-49qc-5qgg.json | 12 +++--------- .../05/GHSA-x2pr-2f5w-h2hj/GHSA-x2pr-2f5w-h2hj.json | 12 +++--------- .../05/GHSA-x36w-m8p6-4mc4/GHSA-x36w-m8p6-4mc4.json | 8 ++------ .../05/GHSA-x39g-7rq2-35qp/GHSA-x39g-7rq2-35qp.json | 8 ++------ .../05/GHSA-x3gg-p3m6-jw8p/GHSA-x3gg-p3m6-jw8p.json | 12 +++--------- .../05/GHSA-x3mf-x7jh-9gfw/GHSA-x3mf-x7jh-9gfw.json | 12 +++--------- .../05/GHSA-x3v3-356g-f4j9/GHSA-x3v3-356g-f4j9.json | 4 +--- .../05/GHSA-x3vf-fcq8-6cpg/GHSA-x3vf-fcq8-6cpg.json | 4 +--- .../05/GHSA-x3x6-8r65-7c76/GHSA-x3x6-8r65-7c76.json | 12 +++--------- .../05/GHSA-x3xc-9hqw-jqwj/GHSA-x3xc-9hqw-jqwj.json | 12 +++--------- .../05/GHSA-x4gw-4hvm-h8g4/GHSA-x4gw-4hvm-h8g4.json | 12 +++--------- .../05/GHSA-x5v2-jx9x-fj53/GHSA-x5v2-jx9x-fj53.json | 8 ++------ .../05/GHSA-x5xh-7r6j-frrv/GHSA-x5xh-7r6j-frrv.json | 8 ++------ .../05/GHSA-x638-5w24-fwx2/GHSA-x638-5w24-fwx2.json | 12 +++--------- .../05/GHSA-x6h7-qx9x-c9h2/GHSA-x6h7-qx9x-c9h2.json | 12 +++--------- .../05/GHSA-x6m9-rgr7-fm6p/GHSA-x6m9-rgr7-fm6p.json | 8 ++------ .../05/GHSA-x6rv-m5p4-442f/GHSA-x6rv-m5p4-442f.json | 8 ++------ .../05/GHSA-x7m3-2gwh-f2gf/GHSA-x7m3-2gwh-f2gf.json | 12 +++--------- .../05/GHSA-x7r8-25j2-2f3f/GHSA-x7r8-25j2-2f3f.json | 12 +++--------- .../05/GHSA-x867-pp5j-mgrh/GHSA-x867-pp5j-mgrh.json | 8 ++------ .../05/GHSA-x943-vqmm-c5qp/GHSA-x943-vqmm-c5qp.json | 4 +--- .../05/GHSA-xcf9-rf7p-r7f6/GHSA-xcf9-rf7p-r7f6.json | 8 ++------ .../05/GHSA-xfgp-cg34-v578/GHSA-xfgp-cg34-v578.json | 12 +++--------- .../05/GHSA-xgg8-892p-f458/GHSA-xgg8-892p-f458.json | 8 ++------ .../05/GHSA-xhhh-8cg4-rhc7/GHSA-xhhh-8cg4-rhc7.json | 8 ++------ .../05/GHSA-xjhc-m7rm-mxvq/GHSA-xjhc-m7rm-mxvq.json | 8 ++------ .../05/GHSA-xmch-wgh7-x2fj/GHSA-xmch-wgh7-x2fj.json | 12 +++--------- .../05/GHSA-xprc-m22g-qgf9/GHSA-xprc-m22g-qgf9.json | 12 +++--------- .../05/GHSA-xqrv-hxv4-28ph/GHSA-xqrv-hxv4-28ph.json | 12 +++--------- .../05/GHSA-xr29-6gg3-jq8m/GHSA-xr29-6gg3-jq8m.json | 12 +++--------- .../05/GHSA-xr9m-34vg-p986/GHSA-xr9m-34vg-p986.json | 12 +++--------- .../05/GHSA-xrfv-jpgw-xhww/GHSA-xrfv-jpgw-xhww.json | 8 ++------ .../05/GHSA-xrgc-r968-f934/GHSA-xrgc-r968-f934.json | 12 +++--------- .../05/GHSA-xv49-7846-mhm4/GHSA-xv49-7846-mhm4.json | 8 ++------ .../05/GHSA-xvpm-v9x9-vg99/GHSA-xvpm-v9x9-vg99.json | 12 +++--------- .../05/GHSA-xw5r-2555-jwfv/GHSA-xw5r-2555-jwfv.json | 8 ++------ .../05/GHSA-xwhc-mqxq-rj7w/GHSA-xwhc-mqxq-rj7w.json | 8 ++------ .../05/GHSA-xwq2-3qq4-3p6h/GHSA-xwq2-3qq4-3p6h.json | 12 +++--------- .../05/GHSA-xwrf-mmfx-x4vx/GHSA-xwrf-mmfx-x4vx.json | 12 +++--------- .../05/GHSA-xx36-85fv-r3w7/GHSA-xx36-85fv-r3w7.json | 12 +++--------- .../05/GHSA-xx6w-2mwc-44g2/GHSA-xx6w-2mwc-44g2.json | 8 ++------ .../05/GHSA-xxcg-h8cr-979m/GHSA-xxcg-h8cr-979m.json | 8 ++------ .../05/GHSA-xxgp-5c5m-vvhc/GHSA-xxgp-5c5m-vvhc.json | 8 ++------ .../01/GHSA-33ff-c2wp-wfmh/GHSA-33ff-c2wp-wfmh.json | 4 +--- .../01/GHSA-48vq-44vm-p326/GHSA-48vq-44vm-p326.json | 4 +--- .../01/GHSA-4998-2mfr-v8x2/GHSA-4998-2mfr-v8x2.json | 4 +--- .../01/GHSA-7gf5-5hgq-mfgh/GHSA-7gf5-5hgq-mfgh.json | 4 +--- .../01/GHSA-9pg6-chjx-xpmr/GHSA-9pg6-chjx-xpmr.json | 4 +--- .../01/GHSA-c4hh-96wh-qcjh/GHSA-c4hh-96wh-qcjh.json | 4 +--- .../01/GHSA-g28r-954m-qc24/GHSA-g28r-954m-qc24.json | 4 +--- .../01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json | 8 ++------ .../01/GHSA-jmx5-53v7-75mr/GHSA-jmx5-53v7-75mr.json | 4 +--- .../01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json | 8 ++------ .../01/GHSA-wfr4-c7jj-8xgp/GHSA-wfr4-c7jj-8xgp.json | 4 +--- .../06/GHSA-296m-v66m-w8jp/GHSA-296m-v66m-w8jp.json | 4 +--- .../06/GHSA-32gm-gr8r-8r4x/GHSA-32gm-gr8r-8r4x.json | 4 +--- .../06/GHSA-3vmg-wgpj-fjxv/GHSA-3vmg-wgpj-fjxv.json | 4 +--- .../06/GHSA-3xjq-wgw3-893q/GHSA-3xjq-wgw3-893q.json | 4 +--- .../06/GHSA-4662-jh8w-4j8m/GHSA-4662-jh8w-4j8m.json | 4 +--- .../06/GHSA-4fxh-g6gh-xg2v/GHSA-4fxh-g6gh-xg2v.json | 4 +--- .../06/GHSA-4mhw-2p42-7v79/GHSA-4mhw-2p42-7v79.json | 8 ++------ .../06/GHSA-4x7j-mh3x-q8gv/GHSA-4x7j-mh3x-q8gv.json | 4 +--- .../06/GHSA-57f9-3232-gc7j/GHSA-57f9-3232-gc7j.json | 4 +--- .../06/GHSA-5pp6-xjm9-wv7v/GHSA-5pp6-xjm9-wv7v.json | 4 +--- .../06/GHSA-5qqv-7p5x-fvxp/GHSA-5qqv-7p5x-fvxp.json | 4 +--- .../06/GHSA-68m9-84vh-c378/GHSA-68m9-84vh-c378.json | 4 +--- .../06/GHSA-6c59-vxhc-2mqj/GHSA-6c59-vxhc-2mqj.json | 4 +--- .../06/GHSA-6c6m-p94j-g86j/GHSA-6c6m-p94j-g86j.json | 4 +--- .../06/GHSA-6ccp-94q2-9ggr/GHSA-6ccp-94q2-9ggr.json | 4 +--- .../06/GHSA-6crp-pv4g-xcj8/GHSA-6crp-pv4g-xcj8.json | 4 +--- .../06/GHSA-6q8w-cx85-gwxp/GHSA-6q8w-cx85-gwxp.json | 4 +--- .../06/GHSA-736q-qv2f-fcvr/GHSA-736q-qv2f-fcvr.json | 4 +--- .../06/GHSA-743f-g3w9-hfj2/GHSA-743f-g3w9-hfj2.json | 4 +--- .../06/GHSA-746c-7v72-3ccf/GHSA-746c-7v72-3ccf.json | 4 +--- .../06/GHSA-76c7-54r2-mq68/GHSA-76c7-54r2-mq68.json | 4 +--- .../06/GHSA-7hjv-959f-2qjf/GHSA-7hjv-959f-2qjf.json | 4 +--- .../06/GHSA-7j88-hp3g-mw9c/GHSA-7j88-hp3g-mw9c.json | 4 +--- .../06/GHSA-7jvc-5938-w5vc/GHSA-7jvc-5938-w5vc.json | 4 +--- .../06/GHSA-836g-2rjm-jcvv/GHSA-836g-2rjm-jcvv.json | 8 ++------ .../06/GHSA-8w36-643w-8rw9/GHSA-8w36-643w-8rw9.json | 4 +--- .../06/GHSA-92w6-g66f-qhgf/GHSA-92w6-g66f-qhgf.json | 4 +--- .../06/GHSA-93f8-hx2v-qxcp/GHSA-93f8-hx2v-qxcp.json | 4 +--- .../06/GHSA-94xv-rp86-287j/GHSA-94xv-rp86-287j.json | 4 +--- .../06/GHSA-95j6-2grv-6h9g/GHSA-95j6-2grv-6h9g.json | 4 +--- .../06/GHSA-c96x-jgjp-qrr3/GHSA-c96x-jgjp-qrr3.json | 4 +--- .../06/GHSA-cxhm-2gjg-5mq6/GHSA-cxhm-2gjg-5mq6.json | 4 +--- .../06/GHSA-f5jq-9q2m-347v/GHSA-f5jq-9q2m-347v.json | 4 +--- .../06/GHSA-f767-vqcm-8q38/GHSA-f767-vqcm-8q38.json | 4 +--- .../06/GHSA-fj35-7g9r-r874/GHSA-fj35-7g9r-r874.json | 4 +--- .../06/GHSA-fp5w-9974-qhvj/GHSA-fp5w-9974-qhvj.json | 4 +--- .../06/GHSA-g48v-4gfg-j84v/GHSA-g48v-4gfg-j84v.json | 4 +--- .../06/GHSA-g6f4-8v84-78c7/GHSA-g6f4-8v84-78c7.json | 4 +--- .../06/GHSA-gc6m-q9f7-723r/GHSA-gc6m-q9f7-723r.json | 4 +--- .../06/GHSA-gcjp-r2q8-c8r9/GHSA-gcjp-r2q8-c8r9.json | 4 +--- .../06/GHSA-gj9p-prj2-vr68/GHSA-gj9p-prj2-vr68.json | 4 +--- .../06/GHSA-h83c-hv8p-vjwx/GHSA-h83c-hv8p-vjwx.json | 4 +--- .../06/GHSA-h85c-h8jh-v47r/GHSA-h85c-h8jh-v47r.json | 4 +--- .../06/GHSA-hc4v-987m-2cmm/GHSA-hc4v-987m-2cmm.json | 4 +--- .../06/GHSA-hcgf-86c7-xfvc/GHSA-hcgf-86c7-xfvc.json | 4 +--- .../06/GHSA-hgp5-r8w2-frrr/GHSA-hgp5-r8w2-frrr.json | 4 +--- .../06/GHSA-hmr2-5mc5-frq6/GHSA-hmr2-5mc5-frq6.json | 4 +--- .../06/GHSA-hq2x-42qh-qfx6/GHSA-hq2x-42qh-qfx6.json | 4 +--- .../06/GHSA-hxfv-hmpx-xj28/GHSA-hxfv-hmpx-xj28.json | 4 +--- .../06/GHSA-j33r-v3xc-53j7/GHSA-j33r-v3xc-53j7.json | 4 +--- .../06/GHSA-j373-f2v6-57rr/GHSA-j373-f2v6-57rr.json | 4 +--- .../06/GHSA-j4m9-p3x7-cqvx/GHSA-j4m9-p3x7-cqvx.json | 4 +--- .../06/GHSA-jq42-q6c8-f44h/GHSA-jq42-q6c8-f44h.json | 12 +++--------- .../06/GHSA-jvf6-388x-r47w/GHSA-jvf6-388x-r47w.json | 4 +--- .../06/GHSA-m5f4-mxmv-gqwv/GHSA-m5f4-mxmv-gqwv.json | 4 +--- .../06/GHSA-m7r7-rm5j-fm89/GHSA-m7r7-rm5j-fm89.json | 4 +--- .../06/GHSA-mfx5-2wjg-73rv/GHSA-mfx5-2wjg-73rv.json | 4 +--- .../06/GHSA-mhvg-m4c7-2668/GHSA-mhvg-m4c7-2668.json | 4 +--- .../06/GHSA-mq78-vgg5-pj68/GHSA-mq78-vgg5-pj68.json | 8 ++------ .../06/GHSA-pwgr-2gfv-9676/GHSA-pwgr-2gfv-9676.json | 4 +--- .../06/GHSA-pxvr-66m2-jxg6/GHSA-pxvr-66m2-jxg6.json | 4 +--- .../06/GHSA-qc2p-795v-hjqh/GHSA-qc2p-795v-hjqh.json | 4 +--- .../06/GHSA-qphh-cq77-c378/GHSA-qphh-cq77-c378.json | 4 +--- .../06/GHSA-qrqq-9838-mwwm/GHSA-qrqq-9838-mwwm.json | 4 +--- .../06/GHSA-rfh8-hgh4-42q6/GHSA-rfh8-hgh4-42q6.json | 4 +--- .../06/GHSA-rhc6-qxqq-hhh6/GHSA-rhc6-qxqq-hhh6.json | 4 +--- .../06/GHSA-rhrf-hh3q-54pc/GHSA-rhrf-hh3q-54pc.json | 4 +--- .../06/GHSA-rp53-2ch4-r2gq/GHSA-rp53-2ch4-r2gq.json | 4 +--- .../06/GHSA-v6qm-969h-rr46/GHSA-v6qm-969h-rr46.json | 4 +--- .../06/GHSA-vhv2-v858-63v9/GHSA-vhv2-v858-63v9.json | 4 +--- .../06/GHSA-vvhp-c548-j66x/GHSA-vvhp-c548-j66x.json | 4 +--- .../06/GHSA-w939-7ww2-rwgw/GHSA-w939-7ww2-rwgw.json | 4 +--- .../06/GHSA-wh6c-gpx3-rw87/GHSA-wh6c-gpx3-rw87.json | 4 +--- .../06/GHSA-wvr3-gr3h-76jc/GHSA-wvr3-gr3h-76jc.json | 4 +--- .../06/GHSA-ww9h-9c2h-gx6j/GHSA-ww9h-9c2h-gx6j.json | 4 +--- .../06/GHSA-x28p-92qg-m6c6/GHSA-x28p-92qg-m6c6.json | 4 +--- .../06/GHSA-x7gw-ff28-c5mc/GHSA-x7gw-ff28-c5mc.json | 4 +--- .../06/GHSA-xfq8-j3ff-mc3p/GHSA-xfq8-j3ff-mc3p.json | 4 +--- 998 files changed, 2310 insertions(+), 6930 deletions(-) diff --git a/advisories/github-reviewed/2023/01/GHSA-crhg-xgrg-vvcc/GHSA-crhg-xgrg-vvcc.json b/advisories/github-reviewed/2023/01/GHSA-crhg-xgrg-vvcc/GHSA-crhg-xgrg-vvcc.json index 96842eb4b33..19e33179a61 100644 --- a/advisories/github-reviewed/2023/01/GHSA-crhg-xgrg-vvcc/GHSA-crhg-xgrg-vvcc.json +++ b/advisories/github-reviewed/2023/01/GHSA-crhg-xgrg-vvcc/GHSA-crhg-xgrg-vvcc.json @@ -3,9 +3,7 @@ "id": "GHSA-crhg-xgrg-vvcc", "modified": "2023-01-13T21:34:29Z", "published": "2023-01-13T21:34:29Z", - "aliases": [ - - ], + "aliases": [], "summary": "a12nserver vulnerable to potential SQL Injections via Knex dependency", "details": "### Impact\n\nUsers of a12nserver that use MySQL might be vulnerable to SQL injection bugs. \n\nIf you use a12nserver and MySQL, update as soon as possible. This SQL injection bug might let an attacker obtain OAuth2 Access Tokens for users unrelated to those that permitted OAuth2 clients.\n\n### Patches\n\nThe knex dependency has been updated to 2.4.0 in a12nserver 0.23.0\n\n### Workarounds\n\nNo further workarounds\n\n### References\n\n* https://github.com/knex/knex/issues/1227\n* https://nvd.nist.gov/vuln/detail/CVE-2016-20018\n* https://www.ghostccamm.com/blog/knex_sqli/\n", "severity": [ diff --git a/advisories/github-reviewed/2024/06/GHSA-85rg-8m6h-825p/GHSA-85rg-8m6h-825p.json b/advisories/github-reviewed/2024/06/GHSA-85rg-8m6h-825p/GHSA-85rg-8m6h-825p.json index 06f1d9b14b9..65a801479fa 100644 --- a/advisories/github-reviewed/2024/06/GHSA-85rg-8m6h-825p/GHSA-85rg-8m6h-825p.json +++ b/advisories/github-reviewed/2024/06/GHSA-85rg-8m6h-825p/GHSA-85rg-8m6h-825p.json @@ -3,14 +3,10 @@ "id": "GHSA-85rg-8m6h-825p", "modified": "2024-06-13T19:39:11Z", "published": "2024-06-13T19:39:11Z", - "aliases": [ - - ], + "aliases": [], "summary": "Vulnerabilities with the k8sGPT", "details": "### Summary\nBunch of vulnerabilities found in k8sGPT. Fixed in release https://github.com/k8sgpt-ai/k8sgpt/releases/tag/v0.3.33", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/unreviewed/2022/02/GHSA-43x4-rqpq-prmp/GHSA-43x4-rqpq-prmp.json b/advisories/unreviewed/2022/02/GHSA-43x4-rqpq-prmp/GHSA-43x4-rqpq-prmp.json index 12a60aba446..1b997576da0 100644 --- a/advisories/unreviewed/2022/02/GHSA-43x4-rqpq-prmp/GHSA-43x4-rqpq-prmp.json +++ b/advisories/unreviewed/2022/02/GHSA-43x4-rqpq-prmp/GHSA-43x4-rqpq-prmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-4p74-9wgm-4fjq/GHSA-4p74-9wgm-4fjq.json b/advisories/unreviewed/2022/02/GHSA-4p74-9wgm-4fjq/GHSA-4p74-9wgm-4fjq.json index 02119afea5e..2448c7ddffa 100644 --- a/advisories/unreviewed/2022/02/GHSA-4p74-9wgm-4fjq/GHSA-4p74-9wgm-4fjq.json +++ b/advisories/unreviewed/2022/02/GHSA-4p74-9wgm-4fjq/GHSA-4p74-9wgm-4fjq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-225q-rmfw-6pfr/GHSA-225q-rmfw-6pfr.json b/advisories/unreviewed/2022/05/GHSA-225q-rmfw-6pfr/GHSA-225q-rmfw-6pfr.json index 2f23409b241..beacb2f045a 100644 --- a/advisories/unreviewed/2022/05/GHSA-225q-rmfw-6pfr/GHSA-225q-rmfw-6pfr.json +++ b/advisories/unreviewed/2022/05/GHSA-225q-rmfw-6pfr/GHSA-225q-rmfw-6pfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-22pr-mvmh-vgg5/GHSA-22pr-mvmh-vgg5.json b/advisories/unreviewed/2022/05/GHSA-22pr-mvmh-vgg5/GHSA-22pr-mvmh-vgg5.json index 1da22a95693..af25e3a8f3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-22pr-mvmh-vgg5/GHSA-22pr-mvmh-vgg5.json +++ b/advisories/unreviewed/2022/05/GHSA-22pr-mvmh-vgg5/GHSA-22pr-mvmh-vgg5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22px-9px7-pc64/GHSA-22px-9px7-pc64.json b/advisories/unreviewed/2022/05/GHSA-22px-9px7-pc64/GHSA-22px-9px7-pc64.json index e5f880b6a0b..1c3bbc55b42 100644 --- a/advisories/unreviewed/2022/05/GHSA-22px-9px7-pc64/GHSA-22px-9px7-pc64.json +++ b/advisories/unreviewed/2022/05/GHSA-22px-9px7-pc64/GHSA-22px-9px7-pc64.json @@ -7,12 +7,8 @@ "CVE-2021-24588" ], "details": "The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22x4-mg72-m2h8/GHSA-22x4-mg72-m2h8.json b/advisories/unreviewed/2022/05/GHSA-22x4-mg72-m2h8/GHSA-22x4-mg72-m2h8.json index 12fa9c32647..de7b76dd473 100644 --- a/advisories/unreviewed/2022/05/GHSA-22x4-mg72-m2h8/GHSA-22x4-mg72-m2h8.json +++ b/advisories/unreviewed/2022/05/GHSA-22x4-mg72-m2h8/GHSA-22x4-mg72-m2h8.json @@ -7,12 +7,8 @@ "CVE-2005-4190" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2356-6r88-539v/GHSA-2356-6r88-539v.json b/advisories/unreviewed/2022/05/GHSA-2356-6r88-539v/GHSA-2356-6r88-539v.json index 17faad81225..385ab7108b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2356-6r88-539v/GHSA-2356-6r88-539v.json +++ b/advisories/unreviewed/2022/05/GHSA-2356-6r88-539v/GHSA-2356-6r88-539v.json @@ -7,12 +7,8 @@ "CVE-2021-1854" ], "details": "A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23r5-px4g-3cgx/GHSA-23r5-px4g-3cgx.json b/advisories/unreviewed/2022/05/GHSA-23r5-px4g-3cgx/GHSA-23r5-px4g-3cgx.json index 761e5ee5f2d..b5f8da2492e 100644 --- a/advisories/unreviewed/2022/05/GHSA-23r5-px4g-3cgx/GHSA-23r5-px4g-3cgx.json +++ b/advisories/unreviewed/2022/05/GHSA-23r5-px4g-3cgx/GHSA-23r5-px4g-3cgx.json @@ -7,12 +7,8 @@ "CVE-2021-38323" ], "details": "The RentPress WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selections parameter found in the ~/src/rentPress/AjaxRequests.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.6.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24v5-4mc2-gcq9/GHSA-24v5-4mc2-gcq9.json b/advisories/unreviewed/2022/05/GHSA-24v5-4mc2-gcq9/GHSA-24v5-4mc2-gcq9.json index 7be98f1aaf6..4ecd5718a51 100644 --- a/advisories/unreviewed/2022/05/GHSA-24v5-4mc2-gcq9/GHSA-24v5-4mc2-gcq9.json +++ b/advisories/unreviewed/2022/05/GHSA-24v5-4mc2-gcq9/GHSA-24v5-4mc2-gcq9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-265x-jgfx-f3g8/GHSA-265x-jgfx-f3g8.json b/advisories/unreviewed/2022/05/GHSA-265x-jgfx-f3g8/GHSA-265x-jgfx-f3g8.json index 172abbcfab0..980ed13622f 100644 --- a/advisories/unreviewed/2022/05/GHSA-265x-jgfx-f3g8/GHSA-265x-jgfx-f3g8.json +++ b/advisories/unreviewed/2022/05/GHSA-265x-jgfx-f3g8/GHSA-265x-jgfx-f3g8.json @@ -7,12 +7,8 @@ "CVE-2020-7865" ], "details": "A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download and execute an arbitrary file via httpDownload function. A successful exploit could allow the attacker to hijack vulnerable system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26v5-q2r5-7mv2/GHSA-26v5-q2r5-7mv2.json b/advisories/unreviewed/2022/05/GHSA-26v5-q2r5-7mv2/GHSA-26v5-q2r5-7mv2.json index 843b17a65c2..f645346ea29 100644 --- a/advisories/unreviewed/2022/05/GHSA-26v5-q2r5-7mv2/GHSA-26v5-q2r5-7mv2.json +++ b/advisories/unreviewed/2022/05/GHSA-26v5-q2r5-7mv2/GHSA-26v5-q2r5-7mv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27m5-g4hr-5cg5/GHSA-27m5-g4hr-5cg5.json b/advisories/unreviewed/2022/05/GHSA-27m5-g4hr-5cg5/GHSA-27m5-g4hr-5cg5.json index 55f363bca0e..07341976b5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-27m5-g4hr-5cg5/GHSA-27m5-g4hr-5cg5.json +++ b/advisories/unreviewed/2022/05/GHSA-27m5-g4hr-5cg5/GHSA-27m5-g4hr-5cg5.json @@ -7,12 +7,8 @@ "CVE-2005-4089" ], "details": "Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka \"CSSXSS\" and \"CSS Cross-Domain Information Disclosure Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28g7-74g3-r69w/GHSA-28g7-74g3-r69w.json b/advisories/unreviewed/2022/05/GHSA-28g7-74g3-r69w/GHSA-28g7-74g3-r69w.json index 2ef093a7913..5fae65f56f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-28g7-74g3-r69w/GHSA-28g7-74g3-r69w.json +++ b/advisories/unreviewed/2022/05/GHSA-28g7-74g3-r69w/GHSA-28g7-74g3-r69w.json @@ -7,12 +7,8 @@ "CVE-2005-4366" ], "details": "Multiple SQL injection vulnerabilities in DRZES HMS 3.2 allow remote attackers to execute arbitrary SQL commands via the (1) plan_id parameter to (a) domains.php, (b) viewusage.php, (c) pop_accounts.php, (d) databases.php, (e) ftp_users.php, (f) crons.php, (g) pass_dirs.php, (h) zone_files.php, (i) htaccess.php, and (j) software.php; (2) the customerPlanID parameter to viewplan.php; (3) the ref_id parameter to referred_plans.php; (4) customerPlanID parameter to listcharges.php; and (5) the domain parameter to (k) pop_accounts.php, (d) databases.php, (e) ftp_users.php, (f) crons.php, (g) pass_dirs.php, (h) zone_files.php, (i) htaccess.php, and (j) software.php. NOTE: the viewinvoice.php invoiceID vector is already covered by CVE-2005-4137.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28q6-prfq-9g82/GHSA-28q6-prfq-9g82.json b/advisories/unreviewed/2022/05/GHSA-28q6-prfq-9g82/GHSA-28q6-prfq-9g82.json index 3b6dc19d0a9..876273737ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-28q6-prfq-9g82/GHSA-28q6-prfq-9g82.json +++ b/advisories/unreviewed/2022/05/GHSA-28q6-prfq-9g82/GHSA-28q6-prfq-9g82.json @@ -7,12 +7,8 @@ "CVE-2021-33929" ], "details": "Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-293x-mf2v-87jf/GHSA-293x-mf2v-87jf.json b/advisories/unreviewed/2022/05/GHSA-293x-mf2v-87jf/GHSA-293x-mf2v-87jf.json index ee42c5de5bd..570c00872fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-293x-mf2v-87jf/GHSA-293x-mf2v-87jf.json +++ b/advisories/unreviewed/2022/05/GHSA-293x-mf2v-87jf/GHSA-293x-mf2v-87jf.json @@ -7,12 +7,8 @@ "CVE-2020-21081" ], "details": "A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-295p-h6c6-4fjc/GHSA-295p-h6c6-4fjc.json b/advisories/unreviewed/2022/05/GHSA-295p-h6c6-4fjc/GHSA-295p-h6c6-4fjc.json index 6c6817d347c..14f856eae0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-295p-h6c6-4fjc/GHSA-295p-h6c6-4fjc.json +++ b/advisories/unreviewed/2022/05/GHSA-295p-h6c6-4fjc/GHSA-295p-h6c6-4fjc.json @@ -7,12 +7,8 @@ "CVE-2021-28560" ], "details": "Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29pm-chqc-3mx4/GHSA-29pm-chqc-3mx4.json b/advisories/unreviewed/2022/05/GHSA-29pm-chqc-3mx4/GHSA-29pm-chqc-3mx4.json index d9e2a14d1e8..cd9e9e377d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-29pm-chqc-3mx4/GHSA-29pm-chqc-3mx4.json +++ b/advisories/unreviewed/2022/05/GHSA-29pm-chqc-3mx4/GHSA-29pm-chqc-3mx4.json @@ -7,12 +7,8 @@ "CVE-2021-30696" ], "details": "An attacker in a privileged network position may be able to misrepresent application state. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A logic issue was addressed with improved state management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29pp-qfm3-p869/GHSA-29pp-qfm3-p869.json b/advisories/unreviewed/2022/05/GHSA-29pp-qfm3-p869/GHSA-29pp-qfm3-p869.json index c8d32acc17c..193427eae69 100644 --- a/advisories/unreviewed/2022/05/GHSA-29pp-qfm3-p869/GHSA-29pp-qfm3-p869.json +++ b/advisories/unreviewed/2022/05/GHSA-29pp-qfm3-p869/GHSA-29pp-qfm3-p869.json @@ -7,12 +7,8 @@ "CVE-2021-30777" ], "details": "An injection issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A malicious application may be able to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cmc-m5qq-rxxm/GHSA-2cmc-m5qq-rxxm.json b/advisories/unreviewed/2022/05/GHSA-2cmc-m5qq-rxxm/GHSA-2cmc-m5qq-rxxm.json index b22cf2d1130..2368ae326c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cmc-m5qq-rxxm/GHSA-2cmc-m5qq-rxxm.json +++ b/advisories/unreviewed/2022/05/GHSA-2cmc-m5qq-rxxm/GHSA-2cmc-m5qq-rxxm.json @@ -7,12 +7,8 @@ "CVE-2005-3999" ], "details": "Cross-site scripting (XSS) vulnerability in Search.asp in SiteBeater MP3 Catalog 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2cp7-qmwg-qfxj/GHSA-2cp7-qmwg-qfxj.json b/advisories/unreviewed/2022/05/GHSA-2cp7-qmwg-qfxj/GHSA-2cp7-qmwg-qfxj.json index e74410e3826..9eb20733485 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cp7-qmwg-qfxj/GHSA-2cp7-qmwg-qfxj.json +++ b/advisories/unreviewed/2022/05/GHSA-2cp7-qmwg-qfxj/GHSA-2cp7-qmwg-qfxj.json @@ -7,12 +7,8 @@ "CVE-2005-4248" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in QuickPayPro 3.1 allow remote attackers to inject arbitrary web script or HTML via various fields, such as those in (1) communication/subscribers.tracking.add.php, (2) support/tickets.add.php, and (3) mycompany/categories.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2cqr-2p9g-vvwg/GHSA-2cqr-2p9g-vvwg.json b/advisories/unreviewed/2022/05/GHSA-2cqr-2p9g-vvwg/GHSA-2cqr-2p9g-vvwg.json index 148a6df57a7..edc9d95ac95 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cqr-2p9g-vvwg/GHSA-2cqr-2p9g-vvwg.json +++ b/advisories/unreviewed/2022/05/GHSA-2cqr-2p9g-vvwg/GHSA-2cqr-2p9g-vvwg.json @@ -7,12 +7,8 @@ "CVE-2005-3924" ], "details": "SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2cqv-3cxq-c469/GHSA-2cqv-3cxq-c469.json b/advisories/unreviewed/2022/05/GHSA-2cqv-3cxq-c469/GHSA-2cqv-3cxq-c469.json index 0e954cddddb..3f7cc11850f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cqv-3cxq-c469/GHSA-2cqv-3cxq-c469.json +++ b/advisories/unreviewed/2022/05/GHSA-2cqv-3cxq-c469/GHSA-2cqv-3cxq-c469.json @@ -7,12 +7,8 @@ "CVE-2021-34759" ], "details": "A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. To exploit this vulnerability, an attacker would need valid administrative credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f2h-qc39-72wh/GHSA-2f2h-qc39-72wh.json b/advisories/unreviewed/2022/05/GHSA-2f2h-qc39-72wh/GHSA-2f2h-qc39-72wh.json index 8a309900a15..a1d69cd923c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f2h-qc39-72wh/GHSA-2f2h-qc39-72wh.json +++ b/advisories/unreviewed/2022/05/GHSA-2f2h-qc39-72wh/GHSA-2f2h-qc39-72wh.json @@ -7,12 +7,8 @@ "CVE-2005-4277" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in toendaCMS before 0.7 Beta allows remote attackers to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2f3m-7p38-8gpp/GHSA-2f3m-7p38-8gpp.json b/advisories/unreviewed/2022/05/GHSA-2f3m-7p38-8gpp/GHSA-2f3m-7p38-8gpp.json index 360a5ba2ee5..490d60098cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f3m-7p38-8gpp/GHSA-2f3m-7p38-8gpp.json +++ b/advisories/unreviewed/2022/05/GHSA-2f3m-7p38-8gpp/GHSA-2f3m-7p38-8gpp.json @@ -7,12 +7,8 @@ "CVE-2021-1813" ], "details": "A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f86-j3w8-9473/GHSA-2f86-j3w8-9473.json b/advisories/unreviewed/2022/05/GHSA-2f86-j3w8-9473/GHSA-2f86-j3w8-9473.json index 05a6e1e9bea..f3309afacdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f86-j3w8-9473/GHSA-2f86-j3w8-9473.json +++ b/advisories/unreviewed/2022/05/GHSA-2f86-j3w8-9473/GHSA-2f86-j3w8-9473.json @@ -7,12 +7,8 @@ "CVE-2021-1934" ], "details": "Possible memory corruption due to improper check when application loader object is explicitly destructed while application is unloading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f9r-whh5-m496/GHSA-2f9r-whh5-m496.json b/advisories/unreviewed/2022/05/GHSA-2f9r-whh5-m496/GHSA-2f9r-whh5-m496.json index ef2b942e471..631acf14209 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f9r-whh5-m496/GHSA-2f9r-whh5-m496.json +++ b/advisories/unreviewed/2022/05/GHSA-2f9r-whh5-m496/GHSA-2f9r-whh5-m496.json @@ -7,12 +7,8 @@ "CVE-2005-3972" ], "details": "Cross-site scripting (XSS) vulnerability in extremesearch.php in Extreme Search Corporate Edition 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2fq6-65pq-cxpj/GHSA-2fq6-65pq-cxpj.json b/advisories/unreviewed/2022/05/GHSA-2fq6-65pq-cxpj/GHSA-2fq6-65pq-cxpj.json index 1f8541c0d96..bea2ded281d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fq6-65pq-cxpj/GHSA-2fq6-65pq-cxpj.json +++ b/advisories/unreviewed/2022/05/GHSA-2fq6-65pq-cxpj/GHSA-2fq6-65pq-cxpj.json @@ -7,12 +7,8 @@ "CVE-2005-4154" ], "details": "Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk frontend is loaded.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2g2p-3v97-37x7/GHSA-2g2p-3v97-37x7.json b/advisories/unreviewed/2022/05/GHSA-2g2p-3v97-37x7/GHSA-2g2p-3v97-37x7.json index 8dc27d9c8b1..9505d5b1866 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g2p-3v97-37x7/GHSA-2g2p-3v97-37x7.json +++ b/advisories/unreviewed/2022/05/GHSA-2g2p-3v97-37x7/GHSA-2g2p-3v97-37x7.json @@ -7,12 +7,8 @@ "CVE-2005-4012" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in PHP Web Statistik 1.4 allows remote attackers to inject arbitrary web script or HTML via (1) the lastnumber parameter to stat.php and (2) the HTTP referer to pixel.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2gqj-p7m3-px6g/GHSA-2gqj-p7m3-px6g.json b/advisories/unreviewed/2022/05/GHSA-2gqj-p7m3-px6g/GHSA-2gqj-p7m3-px6g.json index 2e3c9927e6e..fe1d27ab0be 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gqj-p7m3-px6g/GHSA-2gqj-p7m3-px6g.json +++ b/advisories/unreviewed/2022/05/GHSA-2gqj-p7m3-px6g/GHSA-2gqj-p7m3-px6g.json @@ -7,12 +7,8 @@ "CVE-2005-4241" ], "details": "Cross-site scripting (XSS) vulnerability in the category page in VCD-db 0.98 and earlier allows remote attackers to inject arbitrary web script or HTML via the batch parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2h2m-3wv3-pqw4/GHSA-2h2m-3wv3-pqw4.json b/advisories/unreviewed/2022/05/GHSA-2h2m-3wv3-pqw4/GHSA-2h2m-3wv3-pqw4.json index b57e3f3c92a..66b83ddfd20 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h2m-3wv3-pqw4/GHSA-2h2m-3wv3-pqw4.json +++ b/advisories/unreviewed/2022/05/GHSA-2h2m-3wv3-pqw4/GHSA-2h2m-3wv3-pqw4.json @@ -7,12 +7,8 @@ "CVE-2005-4269" ], "details": "mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the \"Delete\" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2h3g-g3x2-rqwp/GHSA-2h3g-g3x2-rqwp.json b/advisories/unreviewed/2022/05/GHSA-2h3g-g3x2-rqwp/GHSA-2h3g-g3x2-rqwp.json index efd0a7daea1..b7a8609d309 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h3g-g3x2-rqwp/GHSA-2h3g-g3x2-rqwp.json +++ b/advisories/unreviewed/2022/05/GHSA-2h3g-g3x2-rqwp/GHSA-2h3g-g3x2-rqwp.json @@ -7,12 +7,8 @@ "CVE-2021-33679" ], "details": "The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits that page, the stored malicious script will execute in their session, hence allowing the attacker to compromise their confidentiality and integrity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2h6c-9r57-fm42/GHSA-2h6c-9r57-fm42.json b/advisories/unreviewed/2022/05/GHSA-2h6c-9r57-fm42/GHSA-2h6c-9r57-fm42.json index 10c910b0b3a..0c988bf0151 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h6c-9r57-fm42/GHSA-2h6c-9r57-fm42.json +++ b/advisories/unreviewed/2022/05/GHSA-2h6c-9r57-fm42/GHSA-2h6c-9r57-fm42.json @@ -7,12 +7,8 @@ "CVE-2005-4141" ], "details": "Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hf2-g7jc-242w/GHSA-2hf2-g7jc-242w.json b/advisories/unreviewed/2022/05/GHSA-2hf2-g7jc-242w/GHSA-2hf2-g7jc-242w.json index d9fcd0e1d78..a04cebeb351 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hf2-g7jc-242w/GHSA-2hf2-g7jc-242w.json +++ b/advisories/unreviewed/2022/05/GHSA-2hf2-g7jc-242w/GHSA-2hf2-g7jc-242w.json @@ -7,12 +7,8 @@ "CVE-2021-34709" ], "details": "Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hm7-jw48-h5x6/GHSA-2hm7-jw48-h5x6.json b/advisories/unreviewed/2022/05/GHSA-2hm7-jw48-h5x6/GHSA-2hm7-jw48-h5x6.json index a7025ada6b4..36b35c79a86 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hm7-jw48-h5x6/GHSA-2hm7-jw48-h5x6.json +++ b/advisories/unreviewed/2022/05/GHSA-2hm7-jw48-h5x6/GHSA-2hm7-jw48-h5x6.json @@ -7,12 +7,8 @@ "CVE-2005-4259" ], "details": "Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2hvg-v2h5-m85r/GHSA-2hvg-v2h5-m85r.json b/advisories/unreviewed/2022/05/GHSA-2hvg-v2h5-m85r/GHSA-2hvg-v2h5-m85r.json index 4e630ea9567..dcab81a431d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hvg-v2h5-m85r/GHSA-2hvg-v2h5-m85r.json +++ b/advisories/unreviewed/2022/05/GHSA-2hvg-v2h5-m85r/GHSA-2hvg-v2h5-m85r.json @@ -7,12 +7,8 @@ "CVE-2020-19131" ], "details": "Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the \"invertImage()\" function in the component \"tiffcrop\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hxc-x8ph-68p8/GHSA-2hxc-x8ph-68p8.json b/advisories/unreviewed/2022/05/GHSA-2hxc-x8ph-68p8/GHSA-2hxc-x8ph-68p8.json index 2995d4da7cb..77171557752 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hxc-x8ph-68p8/GHSA-2hxc-x8ph-68p8.json +++ b/advisories/unreviewed/2022/05/GHSA-2hxc-x8ph-68p8/GHSA-2hxc-x8ph-68p8.json @@ -7,12 +7,8 @@ "CVE-2005-3913" ], "details": "Unspecified vulnerability in the domain alias management in Virtual Hosting Control System (VHCS) 2.4.6.2, related to \"creating and deleting forwards for domain aliases,\" allows users to hijack the forwardings of other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2j3h-74w8-wpxm/GHSA-2j3h-74w8-wpxm.json b/advisories/unreviewed/2022/05/GHSA-2j3h-74w8-wpxm/GHSA-2j3h-74w8-wpxm.json index 4fc6d074452..d135a13fb98 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j3h-74w8-wpxm/GHSA-2j3h-74w8-wpxm.json +++ b/advisories/unreviewed/2022/05/GHSA-2j3h-74w8-wpxm/GHSA-2j3h-74w8-wpxm.json @@ -7,12 +7,8 @@ "CVE-2021-30782" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A malicious application may be able to access restricted files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jpg-2mg3-565q/GHSA-2jpg-2mg3-565q.json b/advisories/unreviewed/2022/05/GHSA-2jpg-2mg3-565q/GHSA-2jpg-2mg3-565q.json index e14afbf735f..60af79ad2fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jpg-2mg3-565q/GHSA-2jpg-2mg3-565q.json +++ b/advisories/unreviewed/2022/05/GHSA-2jpg-2mg3-565q/GHSA-2jpg-2mg3-565q.json @@ -7,12 +7,8 @@ "CVE-2021-37729" ], "details": "A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.3, 8.6.0.9, 8.5.0.12, 8.3.0.16, 6.5.4.19, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2m4j-g6x3-4mgf/GHSA-2m4j-g6x3-4mgf.json b/advisories/unreviewed/2022/05/GHSA-2m4j-g6x3-4mgf/GHSA-2m4j-g6x3-4mgf.json index 9a1b92030ac..2c1e59f30b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2m4j-g6x3-4mgf/GHSA-2m4j-g6x3-4mgf.json +++ b/advisories/unreviewed/2022/05/GHSA-2m4j-g6x3-4mgf/GHSA-2m4j-g6x3-4mgf.json @@ -7,12 +7,8 @@ "CVE-2005-4307" ], "details": "Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user parameter to profile.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mfq-w3fm-wxm3/GHSA-2mfq-w3fm-wxm3.json b/advisories/unreviewed/2022/05/GHSA-2mfq-w3fm-wxm3/GHSA-2mfq-w3fm-wxm3.json index 1599d331b20..118ed7f1f0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mfq-w3fm-wxm3/GHSA-2mfq-w3fm-wxm3.json +++ b/advisories/unreviewed/2022/05/GHSA-2mfq-w3fm-wxm3/GHSA-2mfq-w3fm-wxm3.json @@ -7,12 +7,8 @@ "CVE-2021-32833" ], "details": "Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be patched in later versions. Known vulnerable routes are /Videos/Id/hls/PlaylistId/SegmentId.SegmentContainer, /Images/Ratings/theme/name and /Images/MediaInfo/theme/name. For more details including proof of concept code, refer to the referenced GHSL-2021-051. This issue may lead to unauthorized access to the system especially when Emby Server is configured to be accessible from the Internet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mgc-grxm-67g2/GHSA-2mgc-grxm-67g2.json b/advisories/unreviewed/2022/05/GHSA-2mgc-grxm-67g2/GHSA-2mgc-grxm-67g2.json index b12f025e0fb..9c9d6ebc699 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mgc-grxm-67g2/GHSA-2mgc-grxm-67g2.json +++ b/advisories/unreviewed/2022/05/GHSA-2mgc-grxm-67g2/GHSA-2mgc-grxm-67g2.json @@ -7,12 +7,8 @@ "CVE-2005-4280" ], "details": "Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mjh-2x66-3p9p/GHSA-2mjh-2x66-3p9p.json b/advisories/unreviewed/2022/05/GHSA-2mjh-2x66-3p9p/GHSA-2mjh-2x66-3p9p.json index 96eae045d10..371b088b921 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mjh-2x66-3p9p/GHSA-2mjh-2x66-3p9p.json +++ b/advisories/unreviewed/2022/05/GHSA-2mjh-2x66-3p9p/GHSA-2mjh-2x66-3p9p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mm2-42pq-5qmv/GHSA-2mm2-42pq-5qmv.json b/advisories/unreviewed/2022/05/GHSA-2mm2-42pq-5qmv/GHSA-2mm2-42pq-5qmv.json index 971419f55bf..5c2c4527703 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mm2-42pq-5qmv/GHSA-2mm2-42pq-5qmv.json +++ b/advisories/unreviewed/2022/05/GHSA-2mm2-42pq-5qmv/GHSA-2mm2-42pq-5qmv.json @@ -7,12 +7,8 @@ "CVE-2021-30689" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qmj-w77m-fmvh/GHSA-2qmj-w77m-fmvh.json b/advisories/unreviewed/2022/05/GHSA-2qmj-w77m-fmvh/GHSA-2qmj-w77m-fmvh.json index 1282f2b1767..fa973556553 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qmj-w77m-fmvh/GHSA-2qmj-w77m-fmvh.json +++ b/advisories/unreviewed/2022/05/GHSA-2qmj-w77m-fmvh/GHSA-2qmj-w77m-fmvh.json @@ -7,12 +7,8 @@ "CVE-2020-20344" ], "details": "WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2r65-q462-mppf/GHSA-2r65-q462-mppf.json b/advisories/unreviewed/2022/05/GHSA-2r65-q462-mppf/GHSA-2r65-q462-mppf.json index 88c1914d3b5..8c98347a4f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r65-q462-mppf/GHSA-2r65-q462-mppf.json +++ b/advisories/unreviewed/2022/05/GHSA-2r65-q462-mppf/GHSA-2r65-q462-mppf.json @@ -7,12 +7,8 @@ "CVE-2005-4339" ], "details": "Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to inject arbitrary web script or HTML via the context parameter to announcement.pl, which is reflected in the resulting page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rgc-px3m-hcr7/GHSA-2rgc-px3m-hcr7.json b/advisories/unreviewed/2022/05/GHSA-2rgc-px3m-hcr7/GHSA-2rgc-px3m-hcr7.json index 564a3b3f62e..265aceb9c66 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rgc-px3m-hcr7/GHSA-2rgc-px3m-hcr7.json +++ b/advisories/unreviewed/2022/05/GHSA-2rgc-px3m-hcr7/GHSA-2rgc-px3m-hcr7.json @@ -7,12 +7,8 @@ "CVE-2021-39285" ], "details": "A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v58-xw52-wr5c/GHSA-2v58-xw52-wr5c.json b/advisories/unreviewed/2022/05/GHSA-2v58-xw52-wr5c/GHSA-2v58-xw52-wr5c.json index 81fd97e31a0..0203654420a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v58-xw52-wr5c/GHSA-2v58-xw52-wr5c.json +++ b/advisories/unreviewed/2022/05/GHSA-2v58-xw52-wr5c/GHSA-2v58-xw52-wr5c.json @@ -7,12 +7,8 @@ "CVE-2005-4238" ], "details": "Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web script or HTML via the target_field parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2w28-624x-pwr2/GHSA-2w28-624x-pwr2.json b/advisories/unreviewed/2022/05/GHSA-2w28-624x-pwr2/GHSA-2w28-624x-pwr2.json index 73a812bc8d1..2b8642ccc8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w28-624x-pwr2/GHSA-2w28-624x-pwr2.json +++ b/advisories/unreviewed/2022/05/GHSA-2w28-624x-pwr2/GHSA-2w28-624x-pwr2.json @@ -7,12 +7,8 @@ "CVE-2005-4136" ], "details": "Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2wc8-fx5r-628m/GHSA-2wc8-fx5r-628m.json b/advisories/unreviewed/2022/05/GHSA-2wc8-fx5r-628m/GHSA-2wc8-fx5r-628m.json index c3c196417f2..d4c51e33fb3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wc8-fx5r-628m/GHSA-2wc8-fx5r-628m.json +++ b/advisories/unreviewed/2022/05/GHSA-2wc8-fx5r-628m/GHSA-2wc8-fx5r-628m.json @@ -7,12 +7,8 @@ "CVE-2005-4295" ], "details": "Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2x5j-ww8h-cc92/GHSA-2x5j-ww8h-cc92.json b/advisories/unreviewed/2022/05/GHSA-2x5j-ww8h-cc92/GHSA-2x5j-ww8h-cc92.json index 53432fb672c..b023fcbb47c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x5j-ww8h-cc92/GHSA-2x5j-ww8h-cc92.json +++ b/advisories/unreviewed/2022/05/GHSA-2x5j-ww8h-cc92/GHSA-2x5j-ww8h-cc92.json @@ -7,12 +7,8 @@ "CVE-2021-28571" ], "details": "Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debugging tool for JavaScript scripts. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3329-3jrm-gfjj/GHSA-3329-3jrm-gfjj.json b/advisories/unreviewed/2022/05/GHSA-3329-3jrm-gfjj/GHSA-3329-3jrm-gfjj.json index 194fe34649b..4a55a5ecbc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-3329-3jrm-gfjj/GHSA-3329-3jrm-gfjj.json +++ b/advisories/unreviewed/2022/05/GHSA-3329-3jrm-gfjj/GHSA-3329-3jrm-gfjj.json @@ -7,12 +7,8 @@ "CVE-2005-4169" ], "details": "Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlist action to authors.php and (2) sid parameter to viewstory.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3363-c452-8hxm/GHSA-3363-c452-8hxm.json b/advisories/unreviewed/2022/05/GHSA-3363-c452-8hxm/GHSA-3363-c452-8hxm.json index 525c999229d..35ec012a78b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3363-c452-8hxm/GHSA-3363-c452-8hxm.json +++ b/advisories/unreviewed/2022/05/GHSA-3363-c452-8hxm/GHSA-3363-c452-8hxm.json @@ -7,12 +7,8 @@ "CVE-2021-1876" ], "details": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing maliciously crafted web content may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3489-8qg3-xgj4/GHSA-3489-8qg3-xgj4.json b/advisories/unreviewed/2022/05/GHSA-3489-8qg3-xgj4/GHSA-3489-8qg3-xgj4.json index 61976216ab6..10084ca0d74 100644 --- a/advisories/unreviewed/2022/05/GHSA-3489-8qg3-xgj4/GHSA-3489-8qg3-xgj4.json +++ b/advisories/unreviewed/2022/05/GHSA-3489-8qg3-xgj4/GHSA-3489-8qg3-xgj4.json @@ -7,12 +7,8 @@ "CVE-2021-30654" ], "details": "This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34mm-j386-76m3/GHSA-34mm-j386-76m3.json b/advisories/unreviewed/2022/05/GHSA-34mm-j386-76m3/GHSA-34mm-j386-76m3.json index 315b2c73781..beeebf6e00b 100644 --- a/advisories/unreviewed/2022/05/GHSA-34mm-j386-76m3/GHSA-34mm-j386-76m3.json +++ b/advisories/unreviewed/2022/05/GHSA-34mm-j386-76m3/GHSA-34mm-j386-76m3.json @@ -7,12 +7,8 @@ "CVE-2021-36215" ], "details": "LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34mq-9xhj-j4rj/GHSA-34mq-9xhj-j4rj.json b/advisories/unreviewed/2022/05/GHSA-34mq-9xhj-j4rj/GHSA-34mq-9xhj-j4rj.json index b85351c7f75..37c5b99eb7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-34mq-9xhj-j4rj/GHSA-34mq-9xhj-j4rj.json +++ b/advisories/unreviewed/2022/05/GHSA-34mq-9xhj-j4rj/GHSA-34mq-9xhj-j4rj.json @@ -7,12 +7,8 @@ "CVE-2021-1853" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34w2-p277-pp7p/GHSA-34w2-p277-pp7p.json b/advisories/unreviewed/2022/05/GHSA-34w2-p277-pp7p/GHSA-34w2-p277-pp7p.json index 3358f8fa24c..31ec087cadd 100644 --- a/advisories/unreviewed/2022/05/GHSA-34w2-p277-pp7p/GHSA-34w2-p277-pp7p.json +++ b/advisories/unreviewed/2022/05/GHSA-34w2-p277-pp7p/GHSA-34w2-p277-pp7p.json @@ -7,12 +7,8 @@ "CVE-2021-3053" ], "details": "An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enables an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that causes the service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.9; PAN-OS 10.0 versions earlier than PAN-OS 10.0.5. This issue does not affect Prisma Access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34wj-ch2p-7g5r/GHSA-34wj-ch2p-7g5r.json b/advisories/unreviewed/2022/05/GHSA-34wj-ch2p-7g5r/GHSA-34wj-ch2p-7g5r.json index e099f2e9e96..b5149440091 100644 --- a/advisories/unreviewed/2022/05/GHSA-34wj-ch2p-7g5r/GHSA-34wj-ch2p-7g5r.json +++ b/advisories/unreviewed/2022/05/GHSA-34wj-ch2p-7g5r/GHSA-34wj-ch2p-7g5r.json @@ -7,12 +7,8 @@ "CVE-2021-30718" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A non-privileged user may be able to modify restricted settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-34x5-g49j-7c65/GHSA-34x5-g49j-7c65.json b/advisories/unreviewed/2022/05/GHSA-34x5-g49j-7c65/GHSA-34x5-g49j-7c65.json index b96ef22717f..2e7fac9041f 100644 --- a/advisories/unreviewed/2022/05/GHSA-34x5-g49j-7c65/GHSA-34x5-g49j-7c65.json +++ b/advisories/unreviewed/2022/05/GHSA-34x5-g49j-7c65/GHSA-34x5-g49j-7c65.json @@ -7,12 +7,8 @@ "CVE-2005-4361" ], "details": "Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-355w-pfx5-w3wr/GHSA-355w-pfx5-w3wr.json b/advisories/unreviewed/2022/05/GHSA-355w-pfx5-w3wr/GHSA-355w-pfx5-w3wr.json index 0e85322aeeb..e1cb0038847 100644 --- a/advisories/unreviewed/2022/05/GHSA-355w-pfx5-w3wr/GHSA-355w-pfx5-w3wr.json +++ b/advisories/unreviewed/2022/05/GHSA-355w-pfx5-w3wr/GHSA-355w-pfx5-w3wr.json @@ -7,12 +7,8 @@ "CVE-2005-4260" ], "details": "Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the \">\" in the tag with a \"<\", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-357r-rxw7-cg5w/GHSA-357r-rxw7-cg5w.json b/advisories/unreviewed/2022/05/GHSA-357r-rxw7-cg5w/GHSA-357r-rxw7-cg5w.json index 4017e0fb5bb..8d491292d1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-357r-rxw7-cg5w/GHSA-357r-rxw7-cg5w.json +++ b/advisories/unreviewed/2022/05/GHSA-357r-rxw7-cg5w/GHSA-357r-rxw7-cg5w.json @@ -7,12 +7,8 @@ "CVE-2005-4255" ], "details": "Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-35xf-8pcf-3f8p/GHSA-35xf-8pcf-3f8p.json b/advisories/unreviewed/2022/05/GHSA-35xf-8pcf-3f8p/GHSA-35xf-8pcf-3f8p.json index 2f4283957c8..0bc55c33886 100644 --- a/advisories/unreviewed/2022/05/GHSA-35xf-8pcf-3f8p/GHSA-35xf-8pcf-3f8p.json +++ b/advisories/unreviewed/2022/05/GHSA-35xf-8pcf-3f8p/GHSA-35xf-8pcf-3f8p.json @@ -7,12 +7,8 @@ "CVE-2005-4291" ], "details": "Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3622-x4mv-fpmp/GHSA-3622-x4mv-fpmp.json b/advisories/unreviewed/2022/05/GHSA-3622-x4mv-fpmp/GHSA-3622-x4mv-fpmp.json index d42c2dcfd10..a9991afa972 100644 --- a/advisories/unreviewed/2022/05/GHSA-3622-x4mv-fpmp/GHSA-3622-x4mv-fpmp.json +++ b/advisories/unreviewed/2022/05/GHSA-3622-x4mv-fpmp/GHSA-3622-x4mv-fpmp.json @@ -7,12 +7,8 @@ "CVE-2021-23040" ], "details": "On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This issue is exposed only when BIG-IP AFM is provisioned. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3646-mf8v-hr3c/GHSA-3646-mf8v-hr3c.json b/advisories/unreviewed/2022/05/GHSA-3646-mf8v-hr3c/GHSA-3646-mf8v-hr3c.json index a7c286730d9..d788524ae5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3646-mf8v-hr3c/GHSA-3646-mf8v-hr3c.json +++ b/advisories/unreviewed/2022/05/GHSA-3646-mf8v-hr3c/GHSA-3646-mf8v-hr3c.json @@ -7,12 +7,8 @@ "CVE-2021-34144" ], "details": "The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C BT SDK through 0.9.1 does not properly handle the reception of truncated LMP_SCO_Link_Request packets while no other BT connections are active, allowing attackers in radio range to prevent new BT connections (disabling the AB5301A inquiry and page scan procedures) via a crafted LMP packet. The user needs to manually perform a power cycle (restart) of the device to restore BT connectivity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-369w-ch94-45q9/GHSA-369w-ch94-45q9.json b/advisories/unreviewed/2022/05/GHSA-369w-ch94-45q9/GHSA-369w-ch94-45q9.json index 3971c65babf..041dcfaaf12 100644 --- a/advisories/unreviewed/2022/05/GHSA-369w-ch94-45q9/GHSA-369w-ch94-45q9.json +++ b/advisories/unreviewed/2022/05/GHSA-369w-ch94-45q9/GHSA-369w-ch94-45q9.json @@ -7,12 +7,8 @@ "CVE-2005-4223" ], "details": "Multiple \"potential\" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-36w5-5w82-56wp/GHSA-36w5-5w82-56wp.json b/advisories/unreviewed/2022/05/GHSA-36w5-5w82-56wp/GHSA-36w5-5w82-56wp.json index 0cd8aae7965..f2efeae6912 100644 --- a/advisories/unreviewed/2022/05/GHSA-36w5-5w82-56wp/GHSA-36w5-5w82-56wp.json +++ b/advisories/unreviewed/2022/05/GHSA-36w5-5w82-56wp/GHSA-36w5-5w82-56wp.json @@ -7,12 +7,8 @@ "CVE-2021-37731" ], "details": "A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3754-5x4h-p35m/GHSA-3754-5x4h-p35m.json b/advisories/unreviewed/2022/05/GHSA-3754-5x4h-p35m/GHSA-3754-5x4h-p35m.json index 26c59528ea0..fb0c2ed4105 100644 --- a/advisories/unreviewed/2022/05/GHSA-3754-5x4h-p35m/GHSA-3754-5x4h-p35m.json +++ b/advisories/unreviewed/2022/05/GHSA-3754-5x4h-p35m/GHSA-3754-5x4h-p35m.json @@ -7,12 +7,8 @@ "CVE-2005-4235" ], "details": "Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-37q9-87mr-hp46/GHSA-37q9-87mr-hp46.json b/advisories/unreviewed/2022/05/GHSA-37q9-87mr-hp46/GHSA-37q9-87mr-hp46.json index e9a0bd4d4eb..e466dd48419 100644 --- a/advisories/unreviewed/2022/05/GHSA-37q9-87mr-hp46/GHSA-37q9-87mr-hp46.json +++ b/advisories/unreviewed/2022/05/GHSA-37q9-87mr-hp46/GHSA-37q9-87mr-hp46.json @@ -7,12 +7,8 @@ "CVE-2005-4330" ], "details": "SQL injection vulnerability in browse.ihtml in iHTML Merchant Mall allows remote attackers to execute arbitrary SQL commands via the (1) id, (2) store, and (3) step parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3876-89hf-c4pw/GHSA-3876-89hf-c4pw.json b/advisories/unreviewed/2022/05/GHSA-3876-89hf-c4pw/GHSA-3876-89hf-c4pw.json index 492092de348..ca84fee0784 100644 --- a/advisories/unreviewed/2022/05/GHSA-3876-89hf-c4pw/GHSA-3876-89hf-c4pw.json +++ b/advisories/unreviewed/2022/05/GHSA-3876-89hf-c4pw/GHSA-3876-89hf-c4pw.json @@ -7,12 +7,8 @@ "CVE-2005-3948" ], "details": "Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-398g-pgqg-vjj2/GHSA-398g-pgqg-vjj2.json b/advisories/unreviewed/2022/05/GHSA-398g-pgqg-vjj2/GHSA-398g-pgqg-vjj2.json index 458026a1b1f..9442bf03694 100644 --- a/advisories/unreviewed/2022/05/GHSA-398g-pgqg-vjj2/GHSA-398g-pgqg-vjj2.json +++ b/advisories/unreviewed/2022/05/GHSA-398g-pgqg-vjj2/GHSA-398g-pgqg-vjj2.json @@ -7,12 +7,8 @@ "CVE-2021-30739" ], "details": "A local attacker may be able to elevate their privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A memory corruption issue was addressed with improved validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c2m-gxqv-2jrx/GHSA-3c2m-gxqv-2jrx.json b/advisories/unreviewed/2022/05/GHSA-3c2m-gxqv-2jrx/GHSA-3c2m-gxqv-2jrx.json index 81afa9412b3..458a48bc0ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c2m-gxqv-2jrx/GHSA-3c2m-gxqv-2jrx.json +++ b/advisories/unreviewed/2022/05/GHSA-3c2m-gxqv-2jrx/GHSA-3c2m-gxqv-2jrx.json @@ -7,12 +7,8 @@ "CVE-2021-1841" ], "details": "A malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. An out-of-bounds write issue was addressed with improved bounds checking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c7q-vpq8-rccq/GHSA-3c7q-vpq8-rccq.json b/advisories/unreviewed/2022/05/GHSA-3c7q-vpq8-rccq/GHSA-3c7q-vpq8-rccq.json index 0be79902ce4..6f4c03f275c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c7q-vpq8-rccq/GHSA-3c7q-vpq8-rccq.json +++ b/advisories/unreviewed/2022/05/GHSA-3c7q-vpq8-rccq/GHSA-3c7q-vpq8-rccq.json @@ -7,12 +7,8 @@ "CVE-2021-30735" ], "details": "A malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An out-of-bounds write issue was addressed with improved bounds checking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cmx-whgg-cr4j/GHSA-3cmx-whgg-cr4j.json b/advisories/unreviewed/2022/05/GHSA-3cmx-whgg-cr4j/GHSA-3cmx-whgg-cr4j.json index edf84c962e5..ad0b1a7870e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cmx-whgg-cr4j/GHSA-3cmx-whgg-cr4j.json +++ b/advisories/unreviewed/2022/05/GHSA-3cmx-whgg-cr4j/GHSA-3cmx-whgg-cr4j.json @@ -7,12 +7,8 @@ "CVE-2020-19268" ], "details": "A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fq3-m842-mpf8/GHSA-3fq3-m842-mpf8.json b/advisories/unreviewed/2022/05/GHSA-3fq3-m842-mpf8/GHSA-3fq3-m842-mpf8.json index 7ce15f776fb..cd9d56e4276 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fq3-m842-mpf8/GHSA-3fq3-m842-mpf8.json +++ b/advisories/unreviewed/2022/05/GHSA-3fq3-m842-mpf8/GHSA-3fq3-m842-mpf8.json @@ -7,12 +7,8 @@ "CVE-2021-34149" ], "details": "The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fq6-wpf5-96cx/GHSA-3fq6-wpf5-96cx.json b/advisories/unreviewed/2022/05/GHSA-3fq6-wpf5-96cx/GHSA-3fq6-wpf5-96cx.json index e5c2dd894ce..ebf8e543587 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fq6-wpf5-96cx/GHSA-3fq6-wpf5-96cx.json +++ b/advisories/unreviewed/2022/05/GHSA-3fq6-wpf5-96cx/GHSA-3fq6-wpf5-96cx.json @@ -7,12 +7,8 @@ "CVE-2005-4304" ], "details": "index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these details are uncertain because the original report has terminology problems and lack of relevant details. The description is based partially on feedback comments.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3ghh-mq29-47m6/GHSA-3ghh-mq29-47m6.json b/advisories/unreviewed/2022/05/GHSA-3ghh-mq29-47m6/GHSA-3ghh-mq29-47m6.json index 7afd33e8632..c06337fd8a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ghh-mq29-47m6/GHSA-3ghh-mq29-47m6.json +++ b/advisories/unreviewed/2022/05/GHSA-3ghh-mq29-47m6/GHSA-3ghh-mq29-47m6.json @@ -7,12 +7,8 @@ "CVE-2005-4290" ], "details": "Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3gwv-97c2-3grr/GHSA-3gwv-97c2-3grr.json b/advisories/unreviewed/2022/05/GHSA-3gwv-97c2-3grr/GHSA-3gwv-97c2-3grr.json index 7385094f129..de385313c21 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gwv-97c2-3grr/GHSA-3gwv-97c2-3grr.json +++ b/advisories/unreviewed/2022/05/GHSA-3gwv-97c2-3grr/GHSA-3gwv-97c2-3grr.json @@ -7,12 +7,8 @@ "CVE-2021-34719" ], "details": "Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hm3-cqwp-pq23/GHSA-3hm3-cqwp-pq23.json b/advisories/unreviewed/2022/05/GHSA-3hm3-cqwp-pq23/GHSA-3hm3-cqwp-pq23.json index 30757357918..aef7b53a812 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hm3-cqwp-pq23/GHSA-3hm3-cqwp-pq23.json +++ b/advisories/unreviewed/2022/05/GHSA-3hm3-cqwp-pq23/GHSA-3hm3-cqwp-pq23.json @@ -7,12 +7,8 @@ "CVE-2005-4334" ], "details": "SQL injection vulnerability in ZixForum 1.12 allows remote attackers to execute arbitrary SQL commands via the H_ID parameter to (1) zixforum/forum.asp, as used in (2) Headforums.asp and (3) Subject.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mp3-2m7f-5wff/GHSA-3mp3-2m7f-5wff.json b/advisories/unreviewed/2022/05/GHSA-3mp3-2m7f-5wff/GHSA-3mp3-2m7f-5wff.json index 1547934e31e..0ea46f87fbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mp3-2m7f-5wff/GHSA-3mp3-2m7f-5wff.json +++ b/advisories/unreviewed/2022/05/GHSA-3mp3-2m7f-5wff/GHSA-3mp3-2m7f-5wff.json @@ -7,12 +7,8 @@ "CVE-2021-1946" ], "details": "Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3p5g-mrxv-qj72/GHSA-3p5g-mrxv-qj72.json b/advisories/unreviewed/2022/05/GHSA-3p5g-mrxv-qj72/GHSA-3p5g-mrxv-qj72.json index f2424decd2d..e1ef50372a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p5g-mrxv-qj72/GHSA-3p5g-mrxv-qj72.json +++ b/advisories/unreviewed/2022/05/GHSA-3p5g-mrxv-qj72/GHSA-3p5g-mrxv-qj72.json @@ -7,12 +7,8 @@ "CVE-2005-4365" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in text.php and (2) frame parameter in forum.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3phx-h87m-px77/GHSA-3phx-h87m-px77.json b/advisories/unreviewed/2022/05/GHSA-3phx-h87m-px77/GHSA-3phx-h87m-px77.json index 1a94fae271c..a6101250224 100644 --- a/advisories/unreviewed/2022/05/GHSA-3phx-h87m-px77/GHSA-3phx-h87m-px77.json +++ b/advisories/unreviewed/2022/05/GHSA-3phx-h87m-px77/GHSA-3phx-h87m-px77.json @@ -7,12 +7,8 @@ "CVE-2021-30778" ], "details": "This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to bypass Privacy preferences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3prf-q3vf-746c/GHSA-3prf-q3vf-746c.json b/advisories/unreviewed/2022/05/GHSA-3prf-q3vf-746c/GHSA-3prf-q3vf-746c.json index 7956ff5a888..11308df7b0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3prf-q3vf-746c/GHSA-3prf-q3vf-746c.json +++ b/advisories/unreviewed/2022/05/GHSA-3prf-q3vf-746c/GHSA-3prf-q3vf-746c.json @@ -7,12 +7,8 @@ "CVE-2021-36582" ], "details": "In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3q9q-hxxg-xhhm/GHSA-3q9q-hxxg-xhhm.json b/advisories/unreviewed/2022/05/GHSA-3q9q-hxxg-xhhm/GHSA-3q9q-hxxg-xhhm.json index 186c60d389c..b342aae4a6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q9q-hxxg-xhhm/GHSA-3q9q-hxxg-xhhm.json +++ b/advisories/unreviewed/2022/05/GHSA-3q9q-hxxg-xhhm/GHSA-3q9q-hxxg-xhhm.json @@ -7,12 +7,8 @@ "CVE-2005-3968" ], "details": "SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rvx-vp9r-j5fw/GHSA-3rvx-vp9r-j5fw.json b/advisories/unreviewed/2022/05/GHSA-3rvx-vp9r-j5fw/GHSA-3rvx-vp9r-j5fw.json index a933e85bca9..5999e71e15f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rvx-vp9r-j5fw/GHSA-3rvx-vp9r-j5fw.json +++ b/advisories/unreviewed/2022/05/GHSA-3rvx-vp9r-j5fw/GHSA-3rvx-vp9r-j5fw.json @@ -7,12 +7,8 @@ "CVE-2005-4355" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in UStore allow remote attackers to inject arbitrary web script or HTML via the (1) Cat parameter in default.asp and the (2) accessdenied parameter in admin/default.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vpw-cpm2-3x8f/GHSA-3vpw-cpm2-3x8f.json b/advisories/unreviewed/2022/05/GHSA-3vpw-cpm2-3x8f/GHSA-3vpw-cpm2-3x8f.json index 908c53f49ba..b8ef6a965c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vpw-cpm2-3x8f/GHSA-3vpw-cpm2-3x8f.json +++ b/advisories/unreviewed/2022/05/GHSA-3vpw-cpm2-3x8f/GHSA-3vpw-cpm2-3x8f.json @@ -7,12 +7,8 @@ "CVE-2021-1834" ], "details": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vxw-2q8f-4h9h/GHSA-3vxw-2q8f-4h9h.json b/advisories/unreviewed/2022/05/GHSA-3vxw-2q8f-4h9h/GHSA-3vxw-2q8f-4h9h.json index 6f05b65f88c..cbcab4d4075 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vxw-2q8f-4h9h/GHSA-3vxw-2q8f-4h9h.json +++ b/advisories/unreviewed/2022/05/GHSA-3vxw-2q8f-4h9h/GHSA-3vxw-2q8f-4h9h.json @@ -7,12 +7,8 @@ "CVE-2021-1860" ], "details": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to disclose kernel memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w8p-gqqp-6g99/GHSA-3w8p-gqqp-6g99.json b/advisories/unreviewed/2022/05/GHSA-3w8p-gqqp-6g99/GHSA-3w8p-gqqp-6g99.json index d5c488cec52..fb4e7c20e44 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w8p-gqqp-6g99/GHSA-3w8p-gqqp-6g99.json +++ b/advisories/unreviewed/2022/05/GHSA-3w8p-gqqp-6g99/GHSA-3w8p-gqqp-6g99.json @@ -7,12 +7,8 @@ "CVE-2005-4301" ], "details": "Cross-site scripting (XSS) vulnerability in phpXplorer 0.9.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the address bar field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3x9m-x83w-55fq/GHSA-3x9m-x83w-55fq.json b/advisories/unreviewed/2022/05/GHSA-3x9m-x83w-55fq/GHSA-3x9m-x83w-55fq.json index d1908c8ef31..79823abdfe0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x9m-x83w-55fq/GHSA-3x9m-x83w-55fq.json +++ b/advisories/unreviewed/2022/05/GHSA-3x9m-x83w-55fq/GHSA-3x9m-x83w-55fq.json @@ -7,12 +7,8 @@ "CVE-2021-1848" ], "details": "The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xm7-55j5-w53p/GHSA-3xm7-55j5-w53p.json b/advisories/unreviewed/2022/05/GHSA-3xm7-55j5-w53p/GHSA-3xm7-55j5-w53p.json index 7bcc9790a26..d68be59cc14 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xm7-55j5-w53p/GHSA-3xm7-55j5-w53p.json +++ b/advisories/unreviewed/2022/05/GHSA-3xm7-55j5-w53p/GHSA-3xm7-55j5-w53p.json @@ -7,12 +7,8 @@ "CVE-2005-4345" ], "details": "Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xmm-r55r-f598/GHSA-3xmm-r55r-f598.json b/advisories/unreviewed/2022/05/GHSA-3xmm-r55r-f598/GHSA-3xmm-r55r-f598.json index 088c1e17813..ffb47c6b7b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xmm-r55r-f598/GHSA-3xmm-r55r-f598.json +++ b/advisories/unreviewed/2022/05/GHSA-3xmm-r55r-f598/GHSA-3xmm-r55r-f598.json @@ -7,12 +7,8 @@ "CVE-2021-1831" ], "details": "The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may allow shortcuts to access restricted files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xq3-mvf9-543x/GHSA-3xq3-mvf9-543x.json b/advisories/unreviewed/2022/05/GHSA-3xq3-mvf9-543x/GHSA-3xq3-mvf9-543x.json index 86387456b65..80623ad889b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xq3-mvf9-543x/GHSA-3xq3-mvf9-543x.json +++ b/advisories/unreviewed/2022/05/GHSA-3xq3-mvf9-543x/GHSA-3xq3-mvf9-543x.json @@ -7,12 +7,8 @@ "CVE-2021-37177" ], "details": "A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be manipulated by an unauthenticated attacker in the same network of the affected system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-42m6-9p28-3cfp/GHSA-42m6-9p28-3cfp.json b/advisories/unreviewed/2022/05/GHSA-42m6-9p28-3cfp/GHSA-42m6-9p28-3cfp.json index 58ecbdbe137..67ca5533975 100644 --- a/advisories/unreviewed/2022/05/GHSA-42m6-9p28-3cfp/GHSA-42m6-9p28-3cfp.json +++ b/advisories/unreviewed/2022/05/GHSA-42m6-9p28-3cfp/GHSA-42m6-9p28-3cfp.json @@ -7,12 +7,8 @@ "CVE-2005-4208" ], "details": "Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-43r7-fmc5-8629/GHSA-43r7-fmc5-8629.json b/advisories/unreviewed/2022/05/GHSA-43r7-fmc5-8629/GHSA-43r7-fmc5-8629.json index 5c057c53d2b..aac0b9b95c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-43r7-fmc5-8629/GHSA-43r7-fmc5-8629.json +++ b/advisories/unreviewed/2022/05/GHSA-43r7-fmc5-8629/GHSA-43r7-fmc5-8629.json @@ -7,12 +7,8 @@ "CVE-2021-30706" ], "details": "Processing a maliciously crafted image may lead to disclosure of user information. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. This issue was addressed with improved checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-442m-4j9q-hhm9/GHSA-442m-4j9q-hhm9.json b/advisories/unreviewed/2022/05/GHSA-442m-4j9q-hhm9/GHSA-442m-4j9q-hhm9.json index 01fa09d0deb..b7de6a79b70 100644 --- a/advisories/unreviewed/2022/05/GHSA-442m-4j9q-hhm9/GHSA-442m-4j9q-hhm9.json +++ b/advisories/unreviewed/2022/05/GHSA-442m-4j9q-hhm9/GHSA-442m-4j9q-hhm9.json @@ -7,12 +7,8 @@ "CVE-2005-4209" ], "details": "WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44rp-ggw2-8gp5/GHSA-44rp-ggw2-8gp5.json b/advisories/unreviewed/2022/05/GHSA-44rp-ggw2-8gp5/GHSA-44rp-ggw2-8gp5.json index c78fd880c3d..5b6bd11564e 100644 --- a/advisories/unreviewed/2022/05/GHSA-44rp-ggw2-8gp5/GHSA-44rp-ggw2-8gp5.json +++ b/advisories/unreviewed/2022/05/GHSA-44rp-ggw2-8gp5/GHSA-44rp-ggw2-8gp5.json @@ -7,12 +7,8 @@ "CVE-2005-4021" ], "details": "The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45h8-9782-xf54/GHSA-45h8-9782-xf54.json b/advisories/unreviewed/2022/05/GHSA-45h8-9782-xf54/GHSA-45h8-9782-xf54.json index fa5eb31cd77..15c5352c16f 100644 --- a/advisories/unreviewed/2022/05/GHSA-45h8-9782-xf54/GHSA-45h8-9782-xf54.json +++ b/advisories/unreviewed/2022/05/GHSA-45h8-9782-xf54/GHSA-45h8-9782-xf54.json @@ -7,12 +7,8 @@ "CVE-2005-4013" ], "details": "PHP Web Statistik 1.4 stores the stat.cfg file under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as statistics and the log directory location, possibly including the logdb.dta file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45m2-r9w2-x69q/GHSA-45m2-r9w2-x69q.json b/advisories/unreviewed/2022/05/GHSA-45m2-r9w2-x69q/GHSA-45m2-r9w2-x69q.json index 809d35a0a16..1d5e920b563 100644 --- a/advisories/unreviewed/2022/05/GHSA-45m2-r9w2-x69q/GHSA-45m2-r9w2-x69q.json +++ b/advisories/unreviewed/2022/05/GHSA-45m2-r9w2-x69q/GHSA-45m2-r9w2-x69q.json @@ -7,12 +7,8 @@ "CVE-2005-4244" ], "details": "SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45rc-fw3m-7fq5/GHSA-45rc-fw3m-7fq5.json b/advisories/unreviewed/2022/05/GHSA-45rc-fw3m-7fq5/GHSA-45rc-fw3m-7fq5.json index 3a5d5d5a465..c403048dc27 100644 --- a/advisories/unreviewed/2022/05/GHSA-45rc-fw3m-7fq5/GHSA-45rc-fw3m-7fq5.json +++ b/advisories/unreviewed/2022/05/GHSA-45rc-fw3m-7fq5/GHSA-45rc-fw3m-7fq5.json @@ -7,12 +7,8 @@ "CVE-2021-28911" ], "details": "BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. device serial number). Having those info, a possible loginId can be self-calculated in a brute force attack against BMX interface. This is usable and part of an attack chain to gain SSH root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-464x-wmqf-g8q5/GHSA-464x-wmqf-g8q5.json b/advisories/unreviewed/2022/05/GHSA-464x-wmqf-g8q5/GHSA-464x-wmqf-g8q5.json index 4ee1267a958..f51063eb6ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-464x-wmqf-g8q5/GHSA-464x-wmqf-g8q5.json +++ b/advisories/unreviewed/2022/05/GHSA-464x-wmqf-g8q5/GHSA-464x-wmqf-g8q5.json @@ -7,12 +7,8 @@ "CVE-2005-4032" ], "details": "Cross-site scripting (XSS) vulnerability in search.cgi in Easy Search System 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4652-66x8-p2w6/GHSA-4652-66x8-p2w6.json b/advisories/unreviewed/2022/05/GHSA-4652-66x8-p2w6/GHSA-4652-66x8-p2w6.json index 9e10a6190be..d524407f75d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4652-66x8-p2w6/GHSA-4652-66x8-p2w6.json +++ b/advisories/unreviewed/2022/05/GHSA-4652-66x8-p2w6/GHSA-4652-66x8-p2w6.json @@ -7,12 +7,8 @@ "CVE-2005-3909" ], "details": "SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46mx-vpj5-jqq4/GHSA-46mx-vpj5-jqq4.json b/advisories/unreviewed/2022/05/GHSA-46mx-vpj5-jqq4/GHSA-46mx-vpj5-jqq4.json index c12f8d63784..f3a4faf088f 100644 --- a/advisories/unreviewed/2022/05/GHSA-46mx-vpj5-jqq4/GHSA-46mx-vpj5-jqq4.json +++ b/advisories/unreviewed/2022/05/GHSA-46mx-vpj5-jqq4/GHSA-46mx-vpj5-jqq4.json @@ -7,12 +7,8 @@ "CVE-2005-4372" ], "details": "Cross-site scripting (XSS) vulnerability in account.html in Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4778-fgpq-p5vc/GHSA-4778-fgpq-p5vc.json b/advisories/unreviewed/2022/05/GHSA-4778-fgpq-p5vc/GHSA-4778-fgpq-p5vc.json index 7a341fa80ce..523f2e4833a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4778-fgpq-p5vc/GHSA-4778-fgpq-p5vc.json +++ b/advisories/unreviewed/2022/05/GHSA-4778-fgpq-p5vc/GHSA-4778-fgpq-p5vc.json @@ -7,12 +7,8 @@ "CVE-2021-36695" ], "details": "Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-487w-fq2p-5mfh/GHSA-487w-fq2p-5mfh.json b/advisories/unreviewed/2022/05/GHSA-487w-fq2p-5mfh/GHSA-487w-fq2p-5mfh.json index a140ea0e6ea..0c9d7106bdb 100644 --- a/advisories/unreviewed/2022/05/GHSA-487w-fq2p-5mfh/GHSA-487w-fq2p-5mfh.json +++ b/advisories/unreviewed/2022/05/GHSA-487w-fq2p-5mfh/GHSA-487w-fq2p-5mfh.json @@ -7,12 +7,8 @@ "CVE-2005-3925" ], "details": "Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c5g-m7r5-24rq/GHSA-4c5g-m7r5-24rq.json b/advisories/unreviewed/2022/05/GHSA-4c5g-m7r5-24rq/GHSA-4c5g-m7r5-24rq.json index 922e704795a..9027a4754ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c5g-m7r5-24rq/GHSA-4c5g-m7r5-24rq.json +++ b/advisories/unreviewed/2022/05/GHSA-4c5g-m7r5-24rq/GHSA-4c5g-m7r5-24rq.json @@ -7,12 +7,8 @@ "CVE-2005-4352" ], "details": "The securelevels implementation in NetBSD 2.1 and earlier, and Linux 2.6.15 and earlier, allows local users to bypass time setting restrictions and set the clock backwards by setting the clock ahead to the maximum unixtime value (19 Jan 2038), which then wraps around to the minimum value (13 Dec 1901), which can then be set ahead to the desired time, aka \"settimeofday() time wrap.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c78-fmvp-hwrw/GHSA-4c78-fmvp-hwrw.json b/advisories/unreviewed/2022/05/GHSA-4c78-fmvp-hwrw/GHSA-4c78-fmvp-hwrw.json index a89e0668793..e263dba39ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c78-fmvp-hwrw/GHSA-4c78-fmvp-hwrw.json +++ b/advisories/unreviewed/2022/05/GHSA-4c78-fmvp-hwrw/GHSA-4c78-fmvp-hwrw.json @@ -7,12 +7,8 @@ "CVE-2005-4344" ], "details": "Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which allows local users to create an object despite the specified configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c89-7wj7-fm5r/GHSA-4c89-7wj7-fm5r.json b/advisories/unreviewed/2022/05/GHSA-4c89-7wj7-fm5r/GHSA-4c89-7wj7-fm5r.json index 7b30a2874f4..376c5e958ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c89-7wj7-fm5r/GHSA-4c89-7wj7-fm5r.json +++ b/advisories/unreviewed/2022/05/GHSA-4c89-7wj7-fm5r/GHSA-4c89-7wj7-fm5r.json @@ -7,12 +7,8 @@ "CVE-2021-24513" ], "details": "The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4cmm-h58v-xqp3/GHSA-4cmm-h58v-xqp3.json b/advisories/unreviewed/2022/05/GHSA-4cmm-h58v-xqp3/GHSA-4cmm-h58v-xqp3.json index 4fd00885395..453082b4dd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cmm-h58v-xqp3/GHSA-4cmm-h58v-xqp3.json +++ b/advisories/unreviewed/2022/05/GHSA-4cmm-h58v-xqp3/GHSA-4cmm-h58v-xqp3.json @@ -7,12 +7,8 @@ "CVE-2021-30652" ], "details": "A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4f5q-9rv6-mx34/GHSA-4f5q-9rv6-mx34.json b/advisories/unreviewed/2022/05/GHSA-4f5q-9rv6-mx34/GHSA-4f5q-9rv6-mx34.json index c967b9c53e5..7238d43f1db 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f5q-9rv6-mx34/GHSA-4f5q-9rv6-mx34.json +++ b/advisories/unreviewed/2022/05/GHSA-4f5q-9rv6-mx34/GHSA-4f5q-9rv6-mx34.json @@ -7,12 +7,8 @@ "CVE-2005-4284" ], "details": "Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possibly the keywords parameter. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f77-xqjh-98gr/GHSA-4f77-xqjh-98gr.json b/advisories/unreviewed/2022/05/GHSA-4f77-xqjh-98gr/GHSA-4f77-xqjh-98gr.json index 125b3e3b27f..880374aa4bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f77-xqjh-98gr/GHSA-4f77-xqjh-98gr.json +++ b/advisories/unreviewed/2022/05/GHSA-4f77-xqjh-98gr/GHSA-4f77-xqjh-98gr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4f7q-xq4j-fmj8/GHSA-4f7q-xq4j-fmj8.json b/advisories/unreviewed/2022/05/GHSA-4f7q-xq4j-fmj8/GHSA-4f7q-xq4j-fmj8.json index 464a9254e3d..f630a0e6ab9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f7q-xq4j-fmj8/GHSA-4f7q-xq4j-fmj8.json +++ b/advisories/unreviewed/2022/05/GHSA-4f7q-xq4j-fmj8/GHSA-4f7q-xq4j-fmj8.json @@ -7,12 +7,8 @@ "CVE-2021-40537" ], "details": "Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap app. Administration role is necessary for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4g8w-85qg-hc95/GHSA-4g8w-85qg-hc95.json b/advisories/unreviewed/2022/05/GHSA-4g8w-85qg-hc95/GHSA-4g8w-85qg-hc95.json index 383e638c651..75b374dd6d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g8w-85qg-hc95/GHSA-4g8w-85qg-hc95.json +++ b/advisories/unreviewed/2022/05/GHSA-4g8w-85qg-hc95/GHSA-4g8w-85qg-hc95.json @@ -7,12 +7,8 @@ "CVE-2005-4214" ], "details": "phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message because the _CCFG['_PKG_PATH_DBSE'] variable is not defined.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gh4-8h8x-f2p8/GHSA-4gh4-8h8x-f2p8.json b/advisories/unreviewed/2022/05/GHSA-4gh4-8h8x-f2p8/GHSA-4gh4-8h8x-f2p8.json index 643c3cb0c58..9d3d188068e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gh4-8h8x-f2p8/GHSA-4gh4-8h8x-f2p8.json +++ b/advisories/unreviewed/2022/05/GHSA-4gh4-8h8x-f2p8/GHSA-4gh4-8h8x-f2p8.json @@ -7,12 +7,8 @@ "CVE-2021-30773" ], "details": "An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious application may be able to bypass code signing checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4h46-q5mh-hhfp/GHSA-4h46-q5mh-hhfp.json b/advisories/unreviewed/2022/05/GHSA-4h46-q5mh-hhfp/GHSA-4h46-q5mh-hhfp.json index a0c9458c592..40a7b4bd745 100644 --- a/advisories/unreviewed/2022/05/GHSA-4h46-q5mh-hhfp/GHSA-4h46-q5mh-hhfp.json +++ b/advisories/unreviewed/2022/05/GHSA-4h46-q5mh-hhfp/GHSA-4h46-q5mh-hhfp.json @@ -7,12 +7,8 @@ "CVE-2021-33688" ], "details": "SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hq5-xhc8-26jr/GHSA-4hq5-xhc8-26jr.json b/advisories/unreviewed/2022/05/GHSA-4hq5-xhc8-26jr/GHSA-4hq5-xhc8-26jr.json index 7ec615ba29f..052ee4ce159 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hq5-xhc8-26jr/GHSA-4hq5-xhc8-26jr.json +++ b/advisories/unreviewed/2022/05/GHSA-4hq5-xhc8-26jr/GHSA-4hq5-xhc8-26jr.json @@ -7,12 +7,8 @@ "CVE-2005-4323" ], "details": "Unspecified vulnerability in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to cause a denial of service of unspecified impact via repeated invalid requests to the Schedule component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4j9r-462v-9f34/GHSA-4j9r-462v-9f34.json b/advisories/unreviewed/2022/05/GHSA-4j9r-462v-9f34/GHSA-4j9r-462v-9f34.json index 35850bd8108..12e15ccaec1 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j9r-462v-9f34/GHSA-4j9r-462v-9f34.json +++ b/advisories/unreviewed/2022/05/GHSA-4j9r-462v-9f34/GHSA-4j9r-462v-9f34.json @@ -7,12 +7,8 @@ "CVE-2021-39500" ], "details": "Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject \"../\" to escape and write file to writeable directories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jh2-4rxm-r2jw/GHSA-4jh2-4rxm-r2jw.json b/advisories/unreviewed/2022/05/GHSA-4jh2-4rxm-r2jw/GHSA-4jh2-4rxm-r2jw.json index 4e739923c33..47cb827b133 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jh2-4rxm-r2jw/GHSA-4jh2-4rxm-r2jw.json +++ b/advisories/unreviewed/2022/05/GHSA-4jh2-4rxm-r2jw/GHSA-4jh2-4rxm-r2jw.json @@ -7,12 +7,8 @@ "CVE-2005-4137" ], "details": "SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jxj-cpjx-2v7r/GHSA-4jxj-cpjx-2v7r.json b/advisories/unreviewed/2022/05/GHSA-4jxj-cpjx-2v7r/GHSA-4jxj-cpjx-2v7r.json index 3bad7973ddb..4b6fd7b2d7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jxj-cpjx-2v7r/GHSA-4jxj-cpjx-2v7r.json +++ b/advisories/unreviewed/2022/05/GHSA-4jxj-cpjx-2v7r/GHSA-4jxj-cpjx-2v7r.json @@ -7,12 +7,8 @@ "CVE-2021-30781" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. A local attacker may be able to cause unexpected application termination or arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4m38-6q8p-p29r/GHSA-4m38-6q8p-p29r.json b/advisories/unreviewed/2022/05/GHSA-4m38-6q8p-p29r/GHSA-4m38-6q8p-p29r.json index 19d14c324be..6e5a4d5043e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m38-6q8p-p29r/GHSA-4m38-6q8p-p29r.json +++ b/advisories/unreviewed/2022/05/GHSA-4m38-6q8p-p29r/GHSA-4m38-6q8p-p29r.json @@ -7,12 +7,8 @@ "CVE-2021-1971" ], "details": "Possible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4m6w-c9j7-h7cg/GHSA-4m6w-c9j7-h7cg.json b/advisories/unreviewed/2022/05/GHSA-4m6w-c9j7-h7cg/GHSA-4m6w-c9j7-h7cg.json index e0e067268da..919b670239d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m6w-c9j7-h7cg/GHSA-4m6w-c9j7-h7cg.json +++ b/advisories/unreviewed/2022/05/GHSA-4m6w-c9j7-h7cg/GHSA-4m6w-c9j7-h7cg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4m93-727g-c564/GHSA-4m93-727g-c564.json b/advisories/unreviewed/2022/05/GHSA-4m93-727g-c564/GHSA-4m93-727g-c564.json index 354e1323850..eacf5e90438 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m93-727g-c564/GHSA-4m93-727g-c564.json +++ b/advisories/unreviewed/2022/05/GHSA-4m93-727g-c564/GHSA-4m93-727g-c564.json @@ -7,12 +7,8 @@ "CVE-2021-38177" ], "details": "SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4p59-rrxq-mw63/GHSA-4p59-rrxq-mw63.json b/advisories/unreviewed/2022/05/GHSA-4p59-rrxq-mw63/GHSA-4p59-rrxq-mw63.json index a57164cadf7..3616a0ae3e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p59-rrxq-mw63/GHSA-4p59-rrxq-mw63.json +++ b/advisories/unreviewed/2022/05/GHSA-4p59-rrxq-mw63/GHSA-4p59-rrxq-mw63.json @@ -7,12 +7,8 @@ "CVE-2020-7877" ], "details": "A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitrary command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pvv-c564-5hw3/GHSA-4pvv-c564-5hw3.json b/advisories/unreviewed/2022/05/GHSA-4pvv-c564-5hw3/GHSA-4pvv-c564-5hw3.json index f1e8b9de61f..90f79416d9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pvv-c564-5hw3/GHSA-4pvv-c564-5hw3.json +++ b/advisories/unreviewed/2022/05/GHSA-4pvv-c564-5hw3/GHSA-4pvv-c564-5hw3.json @@ -7,12 +7,8 @@ "CVE-2021-28909" ], "details": "BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers to access uncontrolled the login service at /webif/SecurityModule in a brute force attack. The password could be weak and default username is known as 'admin'. This is usable and part of an attack chain to gain SSH root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pw5-9j6v-6728/GHSA-4pw5-9j6v-6728.json b/advisories/unreviewed/2022/05/GHSA-4pw5-9j6v-6728/GHSA-4pw5-9j6v-6728.json index 75772410345..aa7fff65d56 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pw5-9j6v-6728/GHSA-4pw5-9j6v-6728.json +++ b/advisories/unreviewed/2022/05/GHSA-4pw5-9j6v-6728/GHSA-4pw5-9j6v-6728.json @@ -7,12 +7,8 @@ "CVE-2005-4219" ], "details": "setting.php in Innovative CMS (ICMS, formerly Imoel-CMS) contains username and password information in cleartext, which might allow attackers to obtain this information via a direct request to setting.php. NOTE: on a properly configured web server, it would be expected that a .php file would be processed before content is returned to the user, so this might not be a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4qfq-vjf3-59qg/GHSA-4qfq-vjf3-59qg.json b/advisories/unreviewed/2022/05/GHSA-4qfq-vjf3-59qg/GHSA-4qfq-vjf3-59qg.json index e06d652fa5b..e04b6ce20d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qfq-vjf3-59qg/GHSA-4qfq-vjf3-59qg.json +++ b/advisories/unreviewed/2022/05/GHSA-4qfq-vjf3-59qg/GHSA-4qfq-vjf3-59qg.json @@ -7,12 +7,8 @@ "CVE-2021-3051" ], "details": "An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 1578677; Cortex XSOAR 6.0.2 builds earlier than 1576452; Cortex XSOAR 6.1.0 builds earlier than 1578663; Cortex XSOAR 6.2.0 builds earlier than 1578666. All Cortex XSOAR instances hosted by Palo Alto Networks are protected from this vulnerability; no additional action is required for these instances.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rxh-h76f-cjmm/GHSA-4rxh-h76f-cjmm.json b/advisories/unreviewed/2022/05/GHSA-4rxh-h76f-cjmm/GHSA-4rxh-h76f-cjmm.json index 234b6610a03..5968daecac0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rxh-h76f-cjmm/GHSA-4rxh-h76f-cjmm.json +++ b/advisories/unreviewed/2022/05/GHSA-4rxh-h76f-cjmm/GHSA-4rxh-h76f-cjmm.json @@ -7,12 +7,8 @@ "CVE-2005-4196" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the ss parameter in SPT--QuickSearch.php; (2) ParentId parameter in SPT--BrowseResources.php; (3) the ResourceId parameter in SPT--FullRecord.php; (4) ResourceOffset parameter in SPT--Home.php, (5) F_SearchString parameter in SPT--QuickSearch.php; (6) F_UserName and (7) F_Password parameters in SPT--UserLogin.php; (8) F_SearchCat1, (9) F_TextField1, (10) F_SearchCat2, (11) F_TextField2, (12) F_SearchCat3, (13) F_TextField3, (14) F_SearchCat4, (15) F_TextField4, (16) ResourceType, (17) Language, (18) Audience, (19) Format parameters in SPT--AdvancedSearch.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v4c-52hq-gphv/GHSA-4v4c-52hq-gphv.json b/advisories/unreviewed/2022/05/GHSA-4v4c-52hq-gphv/GHSA-4v4c-52hq-gphv.json index 981eb642fe0..15b17cac246 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v4c-52hq-gphv/GHSA-4v4c-52hq-gphv.json +++ b/advisories/unreviewed/2022/05/GHSA-4v4c-52hq-gphv/GHSA-4v4c-52hq-gphv.json @@ -7,12 +7,8 @@ "CVE-2005-3934" ], "details": "Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application crash) via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4w7x-2gg8-jv5f/GHSA-4w7x-2gg8-jv5f.json b/advisories/unreviewed/2022/05/GHSA-4w7x-2gg8-jv5f/GHSA-4w7x-2gg8-jv5f.json index 78e5d7afe30..1e1e44c3703 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w7x-2gg8-jv5f/GHSA-4w7x-2gg8-jv5f.json +++ b/advisories/unreviewed/2022/05/GHSA-4w7x-2gg8-jv5f/GHSA-4w7x-2gg8-jv5f.json @@ -7,12 +7,8 @@ "CVE-2021-1846" ], "details": "Processing a maliciously crafted audio file may disclose restricted memory. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An out-of-bounds read was addressed with improved input validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wpf-xh32-76p2/GHSA-4wpf-xh32-76p2.json b/advisories/unreviewed/2022/05/GHSA-4wpf-xh32-76p2/GHSA-4wpf-xh32-76p2.json index 5ea31fd3d41..75487ce42a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wpf-xh32-76p2/GHSA-4wpf-xh32-76p2.json +++ b/advisories/unreviewed/2022/05/GHSA-4wpf-xh32-76p2/GHSA-4wpf-xh32-76p2.json @@ -7,12 +7,8 @@ "CVE-2005-4302" ], "details": "Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via \"..\" sequences in the p parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4wpv-93cp-fchh/GHSA-4wpv-93cp-fchh.json b/advisories/unreviewed/2022/05/GHSA-4wpv-93cp-fchh/GHSA-4wpv-93cp-fchh.json index bda7a8f5682..9131023f648 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wpv-93cp-fchh/GHSA-4wpv-93cp-fchh.json +++ b/advisories/unreviewed/2022/05/GHSA-4wpv-93cp-fchh/GHSA-4wpv-93cp-fchh.json @@ -7,12 +7,8 @@ "CVE-2021-34765" ], "details": "A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists because proper role-based access control (RBAC) filters are not applied to file download actions. An attacker could exploit this vulnerability by logging in to the application and then navigating to the directory listing and download functions. A successful exploit could allow the attacker to download sensitive files that should be restricted, which could result in disclosure of sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wqq-jmmx-m7qr/GHSA-4wqq-jmmx-m7qr.json b/advisories/unreviewed/2022/05/GHSA-4wqq-jmmx-m7qr/GHSA-4wqq-jmmx-m7qr.json index 0557812dfc2..0bc4b7a8c4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wqq-jmmx-m7qr/GHSA-4wqq-jmmx-m7qr.json +++ b/advisories/unreviewed/2022/05/GHSA-4wqq-jmmx-m7qr/GHSA-4wqq-jmmx-m7qr.json @@ -7,12 +7,8 @@ "CVE-2005-4016" ], "details": "SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the (1) property_id, (2) zip_code, (3) property_type_id, (4) price, and (5) city_id parameters to property.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x4m-9cqh-w9qg/GHSA-4x4m-9cqh-w9qg.json b/advisories/unreviewed/2022/05/GHSA-4x4m-9cqh-w9qg/GHSA-4x4m-9cqh-w9qg.json index 6c6cc2d3f42..18ef6a488ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x4m-9cqh-w9qg/GHSA-4x4m-9cqh-w9qg.json +++ b/advisories/unreviewed/2022/05/GHSA-4x4m-9cqh-w9qg/GHSA-4x4m-9cqh-w9qg.json @@ -7,12 +7,8 @@ "CVE-2021-39501" ], "details": "EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x5p-qcrv-5jj7/GHSA-4x5p-qcrv-5jj7.json b/advisories/unreviewed/2022/05/GHSA-4x5p-qcrv-5jj7/GHSA-4x5p-qcrv-5jj7.json index c23dad6d735..b51e3ccf650 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x5p-qcrv-5jj7/GHSA-4x5p-qcrv-5jj7.json +++ b/advisories/unreviewed/2022/05/GHSA-4x5p-qcrv-5jj7/GHSA-4x5p-qcrv-5jj7.json @@ -7,12 +7,8 @@ "CVE-2021-30789" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x9r-5p7j-xjmh/GHSA-4x9r-5p7j-xjmh.json b/advisories/unreviewed/2022/05/GHSA-4x9r-5p7j-xjmh/GHSA-4x9r-5p7j-xjmh.json index c24739ec702..e703fadaa68 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x9r-5p7j-xjmh/GHSA-4x9r-5p7j-xjmh.json +++ b/advisories/unreviewed/2022/05/GHSA-4x9r-5p7j-xjmh/GHSA-4x9r-5p7j-xjmh.json @@ -7,12 +7,8 @@ "CVE-2005-4010" ], "details": "SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to category.php and (2) search parameters to search.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xj3-h4xr-2j4m/GHSA-4xj3-h4xr-2j4m.json b/advisories/unreviewed/2022/05/GHSA-4xj3-h4xr-2j4m/GHSA-4xj3-h4xr-2j4m.json index 437bd66dea5..a34ba63f4a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xj3-h4xr-2j4m/GHSA-4xj3-h4xr-2j4m.json +++ b/advisories/unreviewed/2022/05/GHSA-4xj3-h4xr-2j4m/GHSA-4xj3-h4xr-2j4m.json @@ -7,12 +7,8 @@ "CVE-2021-28558" ], "details": "Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Heap-based buffer overflow vulnerability in the PDFLibTool component. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xmg-fq3w-fh32/GHSA-4xmg-fq3w-fh32.json b/advisories/unreviewed/2022/05/GHSA-4xmg-fq3w-fh32/GHSA-4xmg-fq3w-fh32.json index f22b9bc6e4b..d69e6ad68f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xmg-fq3w-fh32/GHSA-4xmg-fq3w-fh32.json +++ b/advisories/unreviewed/2022/05/GHSA-4xmg-fq3w-fh32/GHSA-4xmg-fq3w-fh32.json @@ -7,12 +7,8 @@ "CVE-2005-3901" ], "details": "Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52px-jf69-7p9q/GHSA-52px-jf69-7p9q.json b/advisories/unreviewed/2022/05/GHSA-52px-jf69-7p9q/GHSA-52px-jf69-7p9q.json index 3d0610fd66d..1e0a3184ca8 100644 --- a/advisories/unreviewed/2022/05/GHSA-52px-jf69-7p9q/GHSA-52px-jf69-7p9q.json +++ b/advisories/unreviewed/2022/05/GHSA-52px-jf69-7p9q/GHSA-52px-jf69-7p9q.json @@ -7,12 +7,8 @@ "CVE-2021-33673" ], "details": "Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an attacker to exploit a Stored Cross-Site Scripting (XSS) vulnerability when a user browses through the employee directory and to execute arbitrary code on the victim's browser. Due to the usage of ActiveX in the application, the attacker can further execute operating system level commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52wp-gx9w-vjc8/GHSA-52wp-gx9w-vjc8.json b/advisories/unreviewed/2022/05/GHSA-52wp-gx9w-vjc8/GHSA-52wp-gx9w-vjc8.json index 7db283b0dc9..5460e0a1418 100644 --- a/advisories/unreviewed/2022/05/GHSA-52wp-gx9w-vjc8/GHSA-52wp-gx9w-vjc8.json +++ b/advisories/unreviewed/2022/05/GHSA-52wp-gx9w-vjc8/GHSA-52wp-gx9w-vjc8.json @@ -7,12 +7,8 @@ "CVE-2021-40532" ], "details": "Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53rq-8pvf-x2h9/GHSA-53rq-8pvf-x2h9.json b/advisories/unreviewed/2022/05/GHSA-53rq-8pvf-x2h9/GHSA-53rq-8pvf-x2h9.json index baed7e937db..ee838e95263 100644 --- a/advisories/unreviewed/2022/05/GHSA-53rq-8pvf-x2h9/GHSA-53rq-8pvf-x2h9.json +++ b/advisories/unreviewed/2022/05/GHSA-53rq-8pvf-x2h9/GHSA-53rq-8pvf-x2h9.json @@ -7,12 +7,8 @@ "CVE-2021-38841" ], "details": "Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on the system_info page in classes/SystemSettings.php with an update_settings action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53vr-5mjf-jhrq/GHSA-53vr-5mjf-jhrq.json b/advisories/unreviewed/2022/05/GHSA-53vr-5mjf-jhrq/GHSA-53vr-5mjf-jhrq.json index 85dfd788355..e8ce3d2a1b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-53vr-5mjf-jhrq/GHSA-53vr-5mjf-jhrq.json +++ b/advisories/unreviewed/2022/05/GHSA-53vr-5mjf-jhrq/GHSA-53vr-5mjf-jhrq.json @@ -7,12 +7,8 @@ "CVE-2005-3929" ], "details": "Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and overwrite arbitrary files via \"..\" sequences in the module parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54fx-pxfw-65x8/GHSA-54fx-pxfw-65x8.json b/advisories/unreviewed/2022/05/GHSA-54fx-pxfw-65x8/GHSA-54fx-pxfw-65x8.json index 355bbb625f1..f9600cceaf0 100644 --- a/advisories/unreviewed/2022/05/GHSA-54fx-pxfw-65x8/GHSA-54fx-pxfw-65x8.json +++ b/advisories/unreviewed/2022/05/GHSA-54fx-pxfw-65x8/GHSA-54fx-pxfw-65x8.json @@ -7,12 +7,8 @@ "CVE-2005-4385" ], "details": "Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54m6-mr75-qr28/GHSA-54m6-mr75-qr28.json b/advisories/unreviewed/2022/05/GHSA-54m6-mr75-qr28/GHSA-54m6-mr75-qr28.json index 9312fbfb4e1..90c099a492d 100644 --- a/advisories/unreviewed/2022/05/GHSA-54m6-mr75-qr28/GHSA-54m6-mr75-qr28.json +++ b/advisories/unreviewed/2022/05/GHSA-54m6-mr75-qr28/GHSA-54m6-mr75-qr28.json @@ -7,12 +7,8 @@ "CVE-2021-37192" ], "details": "A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve a list of network devices a known user can manage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54q9-347p-ccwv/GHSA-54q9-347p-ccwv.json b/advisories/unreviewed/2022/05/GHSA-54q9-347p-ccwv/GHSA-54q9-347p-ccwv.json index de26beb54a9..9572323ef02 100644 --- a/advisories/unreviewed/2022/05/GHSA-54q9-347p-ccwv/GHSA-54q9-347p-ccwv.json +++ b/advisories/unreviewed/2022/05/GHSA-54q9-347p-ccwv/GHSA-54q9-347p-ccwv.json @@ -7,12 +7,8 @@ "CVE-2020-19144" ], "details": "Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-555p-5ggq-9px7/GHSA-555p-5ggq-9px7.json b/advisories/unreviewed/2022/05/GHSA-555p-5ggq-9px7/GHSA-555p-5ggq-9px7.json index ae3acbeeaf3..e8ea91a9851 100644 --- a/advisories/unreviewed/2022/05/GHSA-555p-5ggq-9px7/GHSA-555p-5ggq-9px7.json +++ b/advisories/unreviewed/2022/05/GHSA-555p-5ggq-9px7/GHSA-555p-5ggq-9px7.json @@ -7,12 +7,8 @@ "CVE-2005-3967" ], "details": "Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.queryString search module parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55x4-8xjx-px24/GHSA-55x4-8xjx-px24.json b/advisories/unreviewed/2022/05/GHSA-55x4-8xjx-px24/GHSA-55x4-8xjx-px24.json index dbd7472adf7..1bd91013bbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-55x4-8xjx-px24/GHSA-55x4-8xjx-px24.json +++ b/advisories/unreviewed/2022/05/GHSA-55x4-8xjx-px24/GHSA-55x4-8xjx-px24.json @@ -7,12 +7,8 @@ "CVE-2021-1974" ], "details": "Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56f6-p52g-2qj4/GHSA-56f6-p52g-2qj4.json b/advisories/unreviewed/2022/05/GHSA-56f6-p52g-2qj4/GHSA-56f6-p52g-2qj4.json index a60b996b989..de3e2fe58fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-56f6-p52g-2qj4/GHSA-56f6-p52g-2qj4.json +++ b/advisories/unreviewed/2022/05/GHSA-56f6-p52g-2qj4/GHSA-56f6-p52g-2qj4.json @@ -7,12 +7,8 @@ "CVE-2005-4229" ], "details": "Cross-site scripting (XSS) vulnerability in auction.pl in EveryAuction 1.53 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources and independently verified using source code inspection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5725-9883-g5fp/GHSA-5725-9883-g5fp.json b/advisories/unreviewed/2022/05/GHSA-5725-9883-g5fp/GHSA-5725-9883-g5fp.json index 5fab8a1f3f3..dac730d3db4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5725-9883-g5fp/GHSA-5725-9883-g5fp.json +++ b/advisories/unreviewed/2022/05/GHSA-5725-9883-g5fp/GHSA-5725-9883-g5fp.json @@ -7,12 +7,8 @@ "CVE-2021-30788" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-576v-g6fq-v77x/GHSA-576v-g6fq-v77x.json b/advisories/unreviewed/2022/05/GHSA-576v-g6fq-v77x/GHSA-576v-g6fq-v77x.json index c6263dde9c4..221be5f0aa8 100644 --- a/advisories/unreviewed/2022/05/GHSA-576v-g6fq-v77x/GHSA-576v-g6fq-v77x.json +++ b/advisories/unreviewed/2022/05/GHSA-576v-g6fq-v77x/GHSA-576v-g6fq-v77x.json @@ -7,12 +7,8 @@ "CVE-2005-3963" ], "details": "SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57qc-j3cg-5m8r/GHSA-57qc-j3cg-5m8r.json b/advisories/unreviewed/2022/05/GHSA-57qc-j3cg-5m8r/GHSA-57qc-j3cg-5m8r.json index 6fbe7c2ac43..72ebb5acb90 100644 --- a/advisories/unreviewed/2022/05/GHSA-57qc-j3cg-5m8r/GHSA-57qc-j3cg-5m8r.json +++ b/advisories/unreviewed/2022/05/GHSA-57qc-j3cg-5m8r/GHSA-57qc-j3cg-5m8r.json @@ -7,12 +7,8 @@ "CVE-2005-4308" ], "details": "index.php in ezUpload Pro 2.2 and earlier allows remote attackers to include files via the mode parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5829-vp3g-4228/GHSA-5829-vp3g-4228.json b/advisories/unreviewed/2022/05/GHSA-5829-vp3g-4228/GHSA-5829-vp3g-4228.json index 60fc6d2302f..5c59890133f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5829-vp3g-4228/GHSA-5829-vp3g-4228.json +++ b/advisories/unreviewed/2022/05/GHSA-5829-vp3g-4228/GHSA-5829-vp3g-4228.json @@ -7,12 +7,8 @@ "CVE-2005-4091" ], "details": "Cross-site scripting (XSS) vulnerability in 1search.cgi in 1-Script 1-Search 1.8 allows remote attackers to inject arbitrary web script or HTML via the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58j2-m77g-wqq9/GHSA-58j2-m77g-wqq9.json b/advisories/unreviewed/2022/05/GHSA-58j2-m77g-wqq9/GHSA-58j2-m77g-wqq9.json index 71bb4b00e22..78d0a104f94 100644 --- a/advisories/unreviewed/2022/05/GHSA-58j2-m77g-wqq9/GHSA-58j2-m77g-wqq9.json +++ b/advisories/unreviewed/2022/05/GHSA-58j2-m77g-wqq9/GHSA-58j2-m77g-wqq9.json @@ -7,12 +7,8 @@ "CVE-2005-4221" ], "details": "SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID (session ID) or (2) REQUEST_URI (query string).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-58r6-g6vr-4gpp/GHSA-58r6-g6vr-4gpp.json b/advisories/unreviewed/2022/05/GHSA-58r6-g6vr-4gpp/GHSA-58r6-g6vr-4gpp.json index ab227302fc2..bb821918616 100644 --- a/advisories/unreviewed/2022/05/GHSA-58r6-g6vr-4gpp/GHSA-58r6-g6vr-4gpp.json +++ b/advisories/unreviewed/2022/05/GHSA-58r6-g6vr-4gpp/GHSA-58r6-g6vr-4gpp.json @@ -7,12 +7,8 @@ "CVE-2021-25456" ], "details": "OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58vm-q7q4-jr96/GHSA-58vm-q7q4-jr96.json b/advisories/unreviewed/2022/05/GHSA-58vm-q7q4-jr96/GHSA-58vm-q7q4-jr96.json index c35d10537a0..58d2124e373 100644 --- a/advisories/unreviewed/2022/05/GHSA-58vm-q7q4-jr96/GHSA-58vm-q7q4-jr96.json +++ b/advisories/unreviewed/2022/05/GHSA-58vm-q7q4-jr96/GHSA-58vm-q7q4-jr96.json @@ -7,12 +7,8 @@ "CVE-2005-3942" ], "details": "SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5c27-m4xg-q78c/GHSA-5c27-m4xg-q78c.json b/advisories/unreviewed/2022/05/GHSA-5c27-m4xg-q78c/GHSA-5c27-m4xg-q78c.json index d2b66e2d775..2950aa5a7bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c27-m4xg-q78c/GHSA-5c27-m4xg-q78c.json +++ b/advisories/unreviewed/2022/05/GHSA-5c27-m4xg-q78c/GHSA-5c27-m4xg-q78c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5cjp-4h3f-m7r2/GHSA-5cjp-4h3f-m7r2.json b/advisories/unreviewed/2022/05/GHSA-5cjp-4h3f-m7r2/GHSA-5cjp-4h3f-m7r2.json index 2df63f840ee..d572e0b831f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cjp-4h3f-m7r2/GHSA-5cjp-4h3f-m7r2.json +++ b/advisories/unreviewed/2022/05/GHSA-5cjp-4h3f-m7r2/GHSA-5cjp-4h3f-m7r2.json @@ -7,12 +7,8 @@ "CVE-2021-23047" ], "details": "On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APM performs Online Certificate Status Protocol (OCSP) verification of a certificate that contains Authority Information Access (AIA), undisclosed requests may cause an increase in memory use. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5cq3-xc35-2mw2/GHSA-5cq3-xc35-2mw2.json b/advisories/unreviewed/2022/05/GHSA-5cq3-xc35-2mw2/GHSA-5cq3-xc35-2mw2.json index 569b9ca26b5..babf77224fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cq3-xc35-2mw2/GHSA-5cq3-xc35-2mw2.json +++ b/advisories/unreviewed/2022/05/GHSA-5cq3-xc35-2mw2/GHSA-5cq3-xc35-2mw2.json @@ -7,12 +7,8 @@ "CVE-2021-1928" ], "details": "Buffer over read could occur due to incorrect check of buffer size while flashing emmc devices in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5f6g-pwch-7c2q/GHSA-5f6g-pwch-7c2q.json b/advisories/unreviewed/2022/05/GHSA-5f6g-pwch-7c2q/GHSA-5f6g-pwch-7c2q.json index 91eedf52f05..0d74bd8b5ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-5f6g-pwch-7c2q/GHSA-5f6g-pwch-7c2q.json +++ b/advisories/unreviewed/2022/05/GHSA-5f6g-pwch-7c2q/GHSA-5f6g-pwch-7c2q.json @@ -7,12 +7,8 @@ "CVE-2021-30700" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted image may lead to disclosure of user information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fc8-452m-9frg/GHSA-5fc8-452m-9frg.json b/advisories/unreviewed/2022/05/GHSA-5fc8-452m-9frg/GHSA-5fc8-452m-9frg.json index aa5624e0502..a09d4dd22d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fc8-452m-9frg/GHSA-5fc8-452m-9frg.json +++ b/advisories/unreviewed/2022/05/GHSA-5fc8-452m-9frg/GHSA-5fc8-452m-9frg.json @@ -7,12 +7,8 @@ "CVE-2005-4341" ], "details": "Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id parameter to category.pl. NOTE: it is not clear whether this information is sensitive or not, so this might not be an exposure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fj2-j5qp-cp4j/GHSA-5fj2-j5qp-cp4j.json b/advisories/unreviewed/2022/05/GHSA-5fj2-j5qp-cp4j/GHSA-5fj2-j5qp-cp4j.json index d01011df128..5018f183b5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fj2-j5qp-cp4j/GHSA-5fj2-j5qp-cp4j.json +++ b/advisories/unreviewed/2022/05/GHSA-5fj2-j5qp-cp4j/GHSA-5fj2-j5qp-cp4j.json @@ -7,12 +7,8 @@ "CVE-2021-30726" ], "details": "A malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An out-of-bounds write issue was addressed with improved bounds checking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fp9-mpp5-899v/GHSA-5fp9-mpp5-899v.json b/advisories/unreviewed/2022/05/GHSA-5fp9-mpp5-899v/GHSA-5fp9-mpp5-899v.json index 7130d5ea417..d1b41fd24e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fp9-mpp5-899v/GHSA-5fp9-mpp5-899v.json +++ b/advisories/unreviewed/2022/05/GHSA-5fp9-mpp5-899v/GHSA-5fp9-mpp5-899v.json @@ -7,12 +7,8 @@ "CVE-2021-33674" ], "details": "Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability when creating a new email and to execute arbitrary code on the victim's browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fpq-4v47-vgxf/GHSA-5fpq-4v47-vgxf.json b/advisories/unreviewed/2022/05/GHSA-5fpq-4v47-vgxf/GHSA-5fpq-4v47-vgxf.json index e02e83fb2cf..f7777e1dd0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fpq-4v47-vgxf/GHSA-5fpq-4v47-vgxf.json +++ b/advisories/unreviewed/2022/05/GHSA-5fpq-4v47-vgxf/GHSA-5fpq-4v47-vgxf.json @@ -7,12 +7,8 @@ "CVE-2005-4322" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to inject arbitrary web script or HTML via the (1) Schedule and (2) Calendar components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fq6-q26j-jpfr/GHSA-5fq6-q26j-jpfr.json b/advisories/unreviewed/2022/05/GHSA-5fq6-q26j-jpfr/GHSA-5fq6-q26j-jpfr.json index c98abb40057..c5dafaf535e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fq6-q26j-jpfr/GHSA-5fq6-q26j-jpfr.json +++ b/advisories/unreviewed/2022/05/GHSA-5fq6-q26j-jpfr/GHSA-5fq6-q26j-jpfr.json @@ -7,12 +7,8 @@ "CVE-2005-4176" ], "details": "AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5g5j-x767-23r3/GHSA-5g5j-x767-23r3.json b/advisories/unreviewed/2022/05/GHSA-5g5j-x767-23r3/GHSA-5g5j-x767-23r3.json index 54a54e0225b..e3d14c9edc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g5j-x767-23r3/GHSA-5g5j-x767-23r3.json +++ b/advisories/unreviewed/2022/05/GHSA-5g5j-x767-23r3/GHSA-5g5j-x767-23r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gpp-vqxm-hc58/GHSA-5gpp-vqxm-hc58.json b/advisories/unreviewed/2022/05/GHSA-5gpp-vqxm-hc58/GHSA-5gpp-vqxm-hc58.json index 304f90083d8..dbbc67d269c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gpp-vqxm-hc58/GHSA-5gpp-vqxm-hc58.json +++ b/advisories/unreviewed/2022/05/GHSA-5gpp-vqxm-hc58/GHSA-5gpp-vqxm-hc58.json @@ -7,12 +7,8 @@ "CVE-2021-30676" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A local user may be able to cause unexpected system termination or read kernel memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5h67-qrj6-3r9q/GHSA-5h67-qrj6-3r9q.json b/advisories/unreviewed/2022/05/GHSA-5h67-qrj6-3r9q/GHSA-5h67-qrj6-3r9q.json index 88076e0b07c..6eddaeec38c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h67-qrj6-3r9q/GHSA-5h67-qrj6-3r9q.json +++ b/advisories/unreviewed/2022/05/GHSA-5h67-qrj6-3r9q/GHSA-5h67-qrj6-3r9q.json @@ -7,12 +7,8 @@ "CVE-2021-30607" ], "details": "Use after free in Permissions in Google Chrome prior to 93.0.4577.63 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5hqm-r2hv-cmwq/GHSA-5hqm-r2hv-cmwq.json b/advisories/unreviewed/2022/05/GHSA-5hqm-r2hv-cmwq/GHSA-5hqm-r2hv-cmwq.json index 95abbfb084d..0d5f6be04a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hqm-r2hv-cmwq/GHSA-5hqm-r2hv-cmwq.json +++ b/advisories/unreviewed/2022/05/GHSA-5hqm-r2hv-cmwq/GHSA-5hqm-r2hv-cmwq.json @@ -7,12 +7,8 @@ "CVE-2005-4240" ], "details": "SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5j3m-26vx-5q73/GHSA-5j3m-26vx-5q73.json b/advisories/unreviewed/2022/05/GHSA-5j3m-26vx-5q73/GHSA-5j3m-26vx-5q73.json index f3b9718f433..2656945b55a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j3m-26vx-5q73/GHSA-5j3m-26vx-5q73.json +++ b/advisories/unreviewed/2022/05/GHSA-5j3m-26vx-5q73/GHSA-5j3m-26vx-5q73.json @@ -7,12 +7,8 @@ "CVE-2020-19515" ], "details": "qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\\install\\modules\\database_config.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jg2-wpmw-v3wh/GHSA-5jg2-wpmw-v3wh.json b/advisories/unreviewed/2022/05/GHSA-5jg2-wpmw-v3wh/GHSA-5jg2-wpmw-v3wh.json index c53f2924da2..39457c5ece1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jg2-wpmw-v3wh/GHSA-5jg2-wpmw-v3wh.json +++ b/advisories/unreviewed/2022/05/GHSA-5jg2-wpmw-v3wh/GHSA-5jg2-wpmw-v3wh.json @@ -7,12 +7,8 @@ "CVE-2005-4092" ], "details": "Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified Sample Description Table size value, and possibly other vectors involving media files. NOTE: item 1 was originally identified by CVE-2005-4127 for a pre-patch announcement, and item 2 was originally identified by CVE-2005-4128 for a pre-patch announcement.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jvw-5r9c-59q7/GHSA-5jvw-5r9c-59q7.json b/advisories/unreviewed/2022/05/GHSA-5jvw-5r9c-59q7/GHSA-5jvw-5r9c-59q7.json index 1873cc7446a..594d44f5f9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jvw-5r9c-59q7/GHSA-5jvw-5r9c-59q7.json +++ b/advisories/unreviewed/2022/05/GHSA-5jvw-5r9c-59q7/GHSA-5jvw-5r9c-59q7.json @@ -7,12 +7,8 @@ "CVE-2005-4360" ], "details": "The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to \".dll\" followed by arguments such as \"~0\" through \"~9\", which causes ntdll.dll to produce a return value that is not correctly handled by IIS, as demonstrated using \"/_vti_bin/.dll/*/~0\". NOTE: the consequence was originally believed to be only a denial of service (application crash and reboot).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m3c-wqgq-pc56/GHSA-5m3c-wqgq-pc56.json b/advisories/unreviewed/2022/05/GHSA-5m3c-wqgq-pc56/GHSA-5m3c-wqgq-pc56.json index 090d043427e..40937376d28 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m3c-wqgq-pc56/GHSA-5m3c-wqgq-pc56.json +++ b/advisories/unreviewed/2022/05/GHSA-5m3c-wqgq-pc56/GHSA-5m3c-wqgq-pc56.json @@ -7,12 +7,8 @@ "CVE-2005-3969" ], "details": "SQL injection vulnerability in MXChange before 0.2.0-pre10 PL492 allows remote attackers to execute arbitrary SQL commands via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5m6x-3762-q523/GHSA-5m6x-3762-q523.json b/advisories/unreviewed/2022/05/GHSA-5m6x-3762-q523/GHSA-5m6x-3762-q523.json index abcaf32f875..92763149ee2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m6x-3762-q523/GHSA-5m6x-3762-q523.json +++ b/advisories/unreviewed/2022/05/GHSA-5m6x-3762-q523/GHSA-5m6x-3762-q523.json @@ -7,12 +7,8 @@ "CVE-2005-4333" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Binary Board System (BBS) 0.2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) inreplyto, (2) article, and (3) board parameters to reply.pl, (4) branch, (5) board, and (6) stats.pl parameters to (b) stats.pl, and (7) board parameter to (c) toc.pl.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5ppj-p6hf-cfr4/GHSA-5ppj-p6hf-cfr4.json b/advisories/unreviewed/2022/05/GHSA-5ppj-p6hf-cfr4/GHSA-5ppj-p6hf-cfr4.json index 506e632cf90..ec47719b65c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5ppj-p6hf-cfr4/GHSA-5ppj-p6hf-cfr4.json +++ b/advisories/unreviewed/2022/05/GHSA-5ppj-p6hf-cfr4/GHSA-5ppj-p6hf-cfr4.json @@ -7,12 +7,8 @@ "CVE-2021-31613" ], "details": "The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle the reception of a truncated LMP packet during the LMP auto rate procedure, allowing attackers in radio range to immediately crash (and restart) a device via a crafted LMP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pqr-784w-qv2q/GHSA-5pqr-784w-qv2q.json b/advisories/unreviewed/2022/05/GHSA-5pqr-784w-qv2q/GHSA-5pqr-784w-qv2q.json index 688869dd57a..28f1e8369fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pqr-784w-qv2q/GHSA-5pqr-784w-qv2q.json +++ b/advisories/unreviewed/2022/05/GHSA-5pqr-784w-qv2q/GHSA-5pqr-784w-qv2q.json @@ -7,12 +7,8 @@ "CVE-2005-4002" ], "details": "WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5pwg-c65h-qj7v/GHSA-5pwg-c65h-qj7v.json b/advisories/unreviewed/2022/05/GHSA-5pwg-c65h-qj7v/GHSA-5pwg-c65h-qj7v.json index cda6c6431f7..4be6017864a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pwg-c65h-qj7v/GHSA-5pwg-c65h-qj7v.json +++ b/advisories/unreviewed/2022/05/GHSA-5pwg-c65h-qj7v/GHSA-5pwg-c65h-qj7v.json @@ -7,12 +7,8 @@ "CVE-2005-4282" ], "details": "Cross-site scripting (XSS) vulnerability in Zaygo DomainCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML, possibly via the root parameter to zaygo.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qph-qc32-4f64/GHSA-5qph-qc32-4f64.json b/advisories/unreviewed/2022/05/GHSA-5qph-qc32-4f64/GHSA-5qph-qc32-4f64.json index faf7e2ad0da..0fdf856cc23 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qph-qc32-4f64/GHSA-5qph-qc32-4f64.json +++ b/advisories/unreviewed/2022/05/GHSA-5qph-qc32-4f64/GHSA-5qph-qc32-4f64.json @@ -7,12 +7,8 @@ "CVE-2005-4093" ], "details": "Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qv7-c38f-wr8h/GHSA-5qv7-c38f-wr8h.json b/advisories/unreviewed/2022/05/GHSA-5qv7-c38f-wr8h/GHSA-5qv7-c38f-wr8h.json index 1fa32f5228d..2556a87672e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qv7-c38f-wr8h/GHSA-5qv7-c38f-wr8h.json +++ b/advisories/unreviewed/2022/05/GHSA-5qv7-c38f-wr8h/GHSA-5qv7-c38f-wr8h.json @@ -7,12 +7,8 @@ "CVE-2021-20508" ], "details": "IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5r2g-q7h9-fvcv/GHSA-5r2g-q7h9-fvcv.json b/advisories/unreviewed/2022/05/GHSA-5r2g-q7h9-fvcv/GHSA-5r2g-q7h9-fvcv.json index 1cf5eb307e2..984035ce713 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r2g-q7h9-fvcv/GHSA-5r2g-q7h9-fvcv.json +++ b/advisories/unreviewed/2022/05/GHSA-5r2g-q7h9-fvcv/GHSA-5r2g-q7h9-fvcv.json @@ -7,12 +7,8 @@ "CVE-2005-4357" ], "details": "Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when \"Allowed HTML tags\" is enabled, allows remote attackers to inject arbitrary Javascript via a permitted HTML tag with \" (quote) characters and active attributes such as onmouseover.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5r5v-7gvp-6wc7/GHSA-5r5v-7gvp-6wc7.json b/advisories/unreviewed/2022/05/GHSA-5r5v-7gvp-6wc7/GHSA-5r5v-7gvp-6wc7.json index 8a5a4be8788..7e2409f8f2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r5v-7gvp-6wc7/GHSA-5r5v-7gvp-6wc7.json +++ b/advisories/unreviewed/2022/05/GHSA-5r5v-7gvp-6wc7/GHSA-5r5v-7gvp-6wc7.json @@ -7,12 +7,8 @@ "CVE-2021-30714" ], "details": "A race condition was addressed with improved state handling. This issue is fixed in iOS 14.6 and iPadOS 14.6. An application may be able to cause unexpected system termination or write kernel memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w6w-7jh2-hxvv/GHSA-5w6w-7jh2-hxvv.json b/advisories/unreviewed/2022/05/GHSA-5w6w-7jh2-hxvv/GHSA-5w6w-7jh2-hxvv.json index f471f746317..85812857fc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w6w-7jh2-hxvv/GHSA-5w6w-7jh2-hxvv.json +++ b/advisories/unreviewed/2022/05/GHSA-5w6w-7jh2-hxvv/GHSA-5w6w-7jh2-hxvv.json @@ -7,12 +7,8 @@ "CVE-2021-1916" ], "details": "Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wj4-3vv6-hr3f/GHSA-5wj4-3vv6-hr3f.json b/advisories/unreviewed/2022/05/GHSA-5wj4-3vv6-hr3f/GHSA-5wj4-3vv6-hr3f.json index fd47a77c57e..c5fcaad42ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wj4-3vv6-hr3f/GHSA-5wj4-3vv6-hr3f.json +++ b/advisories/unreviewed/2022/05/GHSA-5wj4-3vv6-hr3f/GHSA-5wj4-3vv6-hr3f.json @@ -7,12 +7,8 @@ "CVE-2021-1847" ], "details": "A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x8c-h7cg-3vj8/GHSA-5x8c-h7cg-3vj8.json b/advisories/unreviewed/2022/05/GHSA-5x8c-h7cg-3vj8/GHSA-5x8c-h7cg-3vj8.json index 1cc55f3c47c..06553b7fa5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x8c-h7cg-3vj8/GHSA-5x8c-h7cg-3vj8.json +++ b/advisories/unreviewed/2022/05/GHSA-5x8c-h7cg-3vj8/GHSA-5x8c-h7cg-3vj8.json @@ -7,12 +7,8 @@ "CVE-2021-38318" ], "details": "The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cover-carousel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x9g-fm6c-gp28/GHSA-5x9g-fm6c-gp28.json b/advisories/unreviewed/2022/05/GHSA-5x9g-fm6c-gp28/GHSA-5x9g-fm6c-gp28.json index e30b73999bc..46e445f79af 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x9g-fm6c-gp28/GHSA-5x9g-fm6c-gp28.json +++ b/advisories/unreviewed/2022/05/GHSA-5x9g-fm6c-gp28/GHSA-5x9g-fm6c-gp28.json @@ -7,12 +7,8 @@ "CVE-2021-1739" ], "details": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xgj-4p79-5g3g/GHSA-5xgj-4p79-5g3g.json b/advisories/unreviewed/2022/05/GHSA-5xgj-4p79-5g3g/GHSA-5xgj-4p79-5g3g.json index 584fda8f9bc..fe282e2282f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xgj-4p79-5g3g/GHSA-5xgj-4p79-5g3g.json +++ b/advisories/unreviewed/2022/05/GHSA-5xgj-4p79-5g3g/GHSA-5xgj-4p79-5g3g.json @@ -7,12 +7,8 @@ "CVE-2021-30707" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted audio file may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xrw-9wr4-v4rm/GHSA-5xrw-9wr4-v4rm.json b/advisories/unreviewed/2022/05/GHSA-5xrw-9wr4-v4rm/GHSA-5xrw-9wr4-v4rm.json index 6ccb996ca17..785da9f84eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xrw-9wr4-v4rm/GHSA-5xrw-9wr4-v4rm.json +++ b/advisories/unreviewed/2022/05/GHSA-5xrw-9wr4-v4rm/GHSA-5xrw-9wr4-v4rm.json @@ -7,12 +7,8 @@ "CVE-2021-30759" ], "details": "A stack overflow was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-627f-jwxp-q2m6/GHSA-627f-jwxp-q2m6.json b/advisories/unreviewed/2022/05/GHSA-627f-jwxp-q2m6/GHSA-627f-jwxp-q2m6.json index 4a514c229ef..da241a5d379 100644 --- a/advisories/unreviewed/2022/05/GHSA-627f-jwxp-q2m6/GHSA-627f-jwxp-q2m6.json +++ b/advisories/unreviewed/2022/05/GHSA-627f-jwxp-q2m6/GHSA-627f-jwxp-q2m6.json @@ -7,12 +7,8 @@ "CVE-2005-4035" ], "details": "Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-62pj-gfcc-pf2c/GHSA-62pj-gfcc-pf2c.json b/advisories/unreviewed/2022/05/GHSA-62pj-gfcc-pf2c/GHSA-62pj-gfcc-pf2c.json index 003be3370c4..2fa27911622 100644 --- a/advisories/unreviewed/2022/05/GHSA-62pj-gfcc-pf2c/GHSA-62pj-gfcc-pf2c.json +++ b/advisories/unreviewed/2022/05/GHSA-62pj-gfcc-pf2c/GHSA-62pj-gfcc-pf2c.json @@ -7,12 +7,8 @@ "CVE-2005-4152" ], "details": "Soti Pocket Controller-Professional 5.0 allows remote attackers to turn off, reboot, or hard reset a PDA via a series of initialization, command, and reset packets sent to port 5492.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-62xm-975c-rvp4/GHSA-62xm-975c-rvp4.json b/advisories/unreviewed/2022/05/GHSA-62xm-975c-rvp4/GHSA-62xm-975c-rvp4.json index 1a9c0cd29e9..4bee452e26a 100644 --- a/advisories/unreviewed/2022/05/GHSA-62xm-975c-rvp4/GHSA-62xm-975c-rvp4.json +++ b/advisories/unreviewed/2022/05/GHSA-62xm-975c-rvp4/GHSA-62xm-975c-rvp4.json @@ -7,12 +7,8 @@ "CVE-2005-3983" ], "details": "Unknown vulnerability in the login page for HP Systems Insight Manager (SIM) 4.0 and 4.1, when accessed by Microsoft Internet Explorer with the MS04-025 patch, leads to a denial of service (browser hang). NOTE: although the advisory is vague, this issue does not appear to involve an attacker at all. If not, then this issue is not a vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-636j-5whr-3852/GHSA-636j-5whr-3852.json b/advisories/unreviewed/2022/05/GHSA-636j-5whr-3852/GHSA-636j-5whr-3852.json index 059e9812cc8..4b43811215a 100644 --- a/advisories/unreviewed/2022/05/GHSA-636j-5whr-3852/GHSA-636j-5whr-3852.json +++ b/advisories/unreviewed/2022/05/GHSA-636j-5whr-3852/GHSA-636j-5whr-3852.json @@ -7,12 +7,8 @@ "CVE-2021-30614" ], "details": "Heap buffer overflow in TabStrip in Google Chrome prior to 93.0.4577.63 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6483-gg6m-x7w8/GHSA-6483-gg6m-x7w8.json b/advisories/unreviewed/2022/05/GHSA-6483-gg6m-x7w8/GHSA-6483-gg6m-x7w8.json index 3c356aa7043..dc213f23943 100644 --- a/advisories/unreviewed/2022/05/GHSA-6483-gg6m-x7w8/GHSA-6483-gg6m-x7w8.json +++ b/advisories/unreviewed/2022/05/GHSA-6483-gg6m-x7w8/GHSA-6483-gg6m-x7w8.json @@ -7,12 +7,8 @@ "CVE-2005-4178" ], "details": "Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code via unspecified inputs that cause insufficient memory to be allocated due to an incorrect expression that does not enforce the proper order of operations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-648m-c4m3-gp59/GHSA-648m-c4m3-gp59.json b/advisories/unreviewed/2022/05/GHSA-648m-c4m3-gp59/GHSA-648m-c4m3-gp59.json index 99bd8455e3b..67db3b65550 100644 --- a/advisories/unreviewed/2022/05/GHSA-648m-c4m3-gp59/GHSA-648m-c4m3-gp59.json +++ b/advisories/unreviewed/2022/05/GHSA-648m-c4m3-gp59/GHSA-648m-c4m3-gp59.json @@ -7,12 +7,8 @@ "CVE-2021-37728" ], "details": "A remote path traversal vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.8.0.1, 8.7.1.4, 8.6.0.11, 8.5.0.13. Aruba has released patches for ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64hj-4677-7p5v/GHSA-64hj-4677-7p5v.json b/advisories/unreviewed/2022/05/GHSA-64hj-4677-7p5v/GHSA-64hj-4677-7p5v.json index 0ca0f65b48f..0ac3cb4ab23 100644 --- a/advisories/unreviewed/2022/05/GHSA-64hj-4677-7p5v/GHSA-64hj-4677-7p5v.json +++ b/advisories/unreviewed/2022/05/GHSA-64hj-4677-7p5v/GHSA-64hj-4677-7p5v.json @@ -7,12 +7,8 @@ "CVE-2021-28581" ], "details": "Adobe Creative Cloud Desktop 3.5 (and earlier) is affected by an uncontrolled search path vulnerability that could result in elevation of privileges. Exploitation of this issue requires user interaction in that a victim must log on to the attacker's local machine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64vp-7r78-2vqx/GHSA-64vp-7r78-2vqx.json b/advisories/unreviewed/2022/05/GHSA-64vp-7r78-2vqx/GHSA-64vp-7r78-2vqx.json index beec4403599..57df7be60c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-64vp-7r78-2vqx/GHSA-64vp-7r78-2vqx.json +++ b/advisories/unreviewed/2022/05/GHSA-64vp-7r78-2vqx/GHSA-64vp-7r78-2vqx.json @@ -7,12 +7,8 @@ "CVE-2005-4381" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Caravel CMS 3.0 Beta 1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fileDN and (2) folderviewer_attrs parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6539-6fh5-h34x/GHSA-6539-6fh5-h34x.json b/advisories/unreviewed/2022/05/GHSA-6539-6fh5-h34x/GHSA-6539-6fh5-h34x.json index dded2c49a37..58180fd6d4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6539-6fh5-h34x/GHSA-6539-6fh5-h34x.json +++ b/advisories/unreviewed/2022/05/GHSA-6539-6fh5-h34x/GHSA-6539-6fh5-h34x.json @@ -7,12 +7,8 @@ "CVE-2021-34148" ], "details": "The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with a greater ACL Length after completion of the LMP setup procedure, allowing attackers in radio range to trigger a denial of service (firmware crash) via a crafted LMP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6587-ppvj-ch5c/GHSA-6587-ppvj-ch5c.json b/advisories/unreviewed/2022/05/GHSA-6587-ppvj-ch5c/GHSA-6587-ppvj-ch5c.json index afc37c94444..3fda015f6b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6587-ppvj-ch5c/GHSA-6587-ppvj-ch5c.json +++ b/advisories/unreviewed/2022/05/GHSA-6587-ppvj-ch5c/GHSA-6587-ppvj-ch5c.json @@ -7,12 +7,8 @@ "CVE-2005-4359" ], "details": "SQL injection vulnerability in includes/core.inc.php in ODFaq 2.1.0 allows remote attackers to execute arbitrary SQL commands via the (1) cat and (2) srcText parameters to faq.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65vm-wjw5-2x4h/GHSA-65vm-wjw5-2x4h.json b/advisories/unreviewed/2022/05/GHSA-65vm-wjw5-2x4h/GHSA-65vm-wjw5-2x4h.json index 8f9bae2b888..4c9ee11e60c 100644 --- a/advisories/unreviewed/2022/05/GHSA-65vm-wjw5-2x4h/GHSA-65vm-wjw5-2x4h.json +++ b/advisories/unreviewed/2022/05/GHSA-65vm-wjw5-2x4h/GHSA-65vm-wjw5-2x4h.json @@ -7,12 +7,8 @@ "CVE-2005-4225" ], "details": "Multiple \"potential\" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameters in adduser.php, (4) the post_id parameter in del.php, (5) the cat_id parameter in delcat.php, (6) the comment_id parameter in delcomment.php, (7) the id parameter in deluser.php, (8) the post_id and category parameter in edit.php, (9) the cat_id and cat_desc parameters in editcat.php, and (10) the id, level, and user parameters in edituser.php. NOTE: the username/login.php vector is already identified by CVE-2005-2838.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6657-fppr-qr38/GHSA-6657-fppr-qr38.json b/advisories/unreviewed/2022/05/GHSA-6657-fppr-qr38/GHSA-6657-fppr-qr38.json index 73d70a2640d..cbb50be0cdf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6657-fppr-qr38/GHSA-6657-fppr-qr38.json +++ b/advisories/unreviewed/2022/05/GHSA-6657-fppr-qr38/GHSA-6657-fppr-qr38.json @@ -7,12 +7,8 @@ "CVE-2005-4143" ], "details": "SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQL code after a numeric argument to a /read/attachment URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-66hj-88cq-2p6h/GHSA-66hj-88cq-2p6h.json b/advisories/unreviewed/2022/05/GHSA-66hj-88cq-2p6h/GHSA-66hj-88cq-2p6h.json index 460473a9984..614875073b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-66hj-88cq-2p6h/GHSA-66hj-88cq-2p6h.json +++ b/advisories/unreviewed/2022/05/GHSA-66hj-88cq-2p6h/GHSA-66hj-88cq-2p6h.json @@ -7,12 +7,8 @@ "CVE-2005-3977" ], "details": "Cross-site scripting (XSS) vulnerability in QualityEBiz Quality PPC 1553 allows remote attackers to inject web script or HTML via the REQ parameter to the search module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6853-5v4j-v7vg/GHSA-6853-5v4j-v7vg.json b/advisories/unreviewed/2022/05/GHSA-6853-5v4j-v7vg/GHSA-6853-5v4j-v7vg.json index e1d42638189..3e1de2b3407 100644 --- a/advisories/unreviewed/2022/05/GHSA-6853-5v4j-v7vg/GHSA-6853-5v4j-v7vg.json +++ b/advisories/unreviewed/2022/05/GHSA-6853-5v4j-v7vg/GHSA-6853-5v4j-v7vg.json @@ -7,12 +7,8 @@ "CVE-2021-37193" ], "details": "A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-68m4-gw7r-wgrq/GHSA-68m4-gw7r-wgrq.json b/advisories/unreviewed/2022/05/GHSA-68m4-gw7r-wgrq/GHSA-68m4-gw7r-wgrq.json index 276a23c5784..080d047c76d 100644 --- a/advisories/unreviewed/2022/05/GHSA-68m4-gw7r-wgrq/GHSA-68m4-gw7r-wgrq.json +++ b/advisories/unreviewed/2022/05/GHSA-68m4-gw7r-wgrq/GHSA-68m4-gw7r-wgrq.json @@ -7,12 +7,8 @@ "CVE-2005-3937" ], "details": "SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-692h-q5hm-h622/GHSA-692h-q5hm-h622.json b/advisories/unreviewed/2022/05/GHSA-692h-q5hm-h622/GHSA-692h-q5hm-h622.json index f292a28b96f..6b08c2b01a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-692h-q5hm-h622/GHSA-692h-q5hm-h622.json +++ b/advisories/unreviewed/2022/05/GHSA-692h-q5hm-h622/GHSA-692h-q5hm-h622.json @@ -7,12 +7,8 @@ "CVE-2021-1941" ], "details": "Possible buffer over read issue due to improper length check on WPA IE string sent by peer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-69ch-7rh5-jhvc/GHSA-69ch-7rh5-jhvc.json b/advisories/unreviewed/2022/05/GHSA-69ch-7rh5-jhvc/GHSA-69ch-7rh5-jhvc.json index 26857261e0f..68f48798270 100644 --- a/advisories/unreviewed/2022/05/GHSA-69ch-7rh5-jhvc/GHSA-69ch-7rh5-jhvc.json +++ b/advisories/unreviewed/2022/05/GHSA-69ch-7rh5-jhvc/GHSA-69ch-7rh5-jhvc.json @@ -7,12 +7,8 @@ "CVE-2005-3939" ], "details": "Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-69h5-wjg5-82pp/GHSA-69h5-wjg5-82pp.json b/advisories/unreviewed/2022/05/GHSA-69h5-wjg5-82pp/GHSA-69h5-wjg5-82pp.json index f8533229030..3ddc1ae3c13 100644 --- a/advisories/unreviewed/2022/05/GHSA-69h5-wjg5-82pp/GHSA-69h5-wjg5-82pp.json +++ b/advisories/unreviewed/2022/05/GHSA-69h5-wjg5-82pp/GHSA-69h5-wjg5-82pp.json @@ -7,12 +7,8 @@ "CVE-2021-38840" ], "details": "SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6ch8-h5p5-j54q/GHSA-6ch8-h5p5-j54q.json b/advisories/unreviewed/2022/05/GHSA-6ch8-h5p5-j54q/GHSA-6ch8-h5p5-j54q.json index 295171ef41b..0a1513cfd0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6ch8-h5p5-j54q/GHSA-6ch8-h5p5-j54q.json +++ b/advisories/unreviewed/2022/05/GHSA-6ch8-h5p5-j54q/GHSA-6ch8-h5p5-j54q.json @@ -7,12 +7,8 @@ "CVE-2005-4367" ], "details": "Cross-site scripting (XSS) vulnerability in register_domain.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the \"Domain Availability\" field. NOTE: this issue was later reported to affect CONTROLzx (renamed from DRZES) 3.3.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6f22-6f94-wc44/GHSA-6f22-6f94-wc44.json b/advisories/unreviewed/2022/05/GHSA-6f22-6f94-wc44/GHSA-6f22-6f94-wc44.json index d0cd98d8521..1d0ffd9a9b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f22-6f94-wc44/GHSA-6f22-6f94-wc44.json +++ b/advisories/unreviewed/2022/05/GHSA-6f22-6f94-wc44/GHSA-6f22-6f94-wc44.json @@ -7,12 +7,8 @@ "CVE-2005-4287" ], "details": "PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6f5f-78pr-p7q9/GHSA-6f5f-78pr-p7q9.json b/advisories/unreviewed/2022/05/GHSA-6f5f-78pr-p7q9/GHSA-6f5f-78pr-p7q9.json index e9baa43bd42..f29a4530feb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f5f-78pr-p7q9/GHSA-6f5f-78pr-p7q9.json +++ b/advisories/unreviewed/2022/05/GHSA-6f5f-78pr-p7q9/GHSA-6f5f-78pr-p7q9.json @@ -7,12 +7,8 @@ "CVE-2021-33599" ], "details": "A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive file can lead to denial-of-service (infinite loop and freezes AV engine scanner). The vulnerability can be exploit remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fx6-p6wj-5g53/GHSA-6fx6-p6wj-5g53.json b/advisories/unreviewed/2022/05/GHSA-6fx6-p6wj-5g53/GHSA-6fx6-p6wj-5g53.json index e0cf9d85b93..9647803eb33 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fx6-p6wj-5g53/GHSA-6fx6-p6wj-5g53.json +++ b/advisories/unreviewed/2022/05/GHSA-6fx6-p6wj-5g53/GHSA-6fx6-p6wj-5g53.json @@ -7,12 +7,8 @@ "CVE-2005-4155" ], "details": "registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in a NULL character, which bypasses the PHP regular expression check. NOTE: it is possible that this is actually a bug in PHP code, in which case this should not be treated as a vulnerability in ATutor.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gg5-qx3q-wcv4/GHSA-6gg5-qx3q-wcv4.json b/advisories/unreviewed/2022/05/GHSA-6gg5-qx3q-wcv4/GHSA-6gg5-qx3q-wcv4.json index 0114330d944..79901402440 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gg5-qx3q-wcv4/GHSA-6gg5-qx3q-wcv4.json +++ b/advisories/unreviewed/2022/05/GHSA-6gg5-qx3q-wcv4/GHSA-6gg5-qx3q-wcv4.json @@ -7,12 +7,8 @@ "CVE-2005-4076" ], "details": "Buffer overflow in Appfluent Technology Database IDS 2.0 allows local users to execute arbitrary code via a long APPFLUENT_HOME environment variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6gjw-jvjh-pv8x/GHSA-6gjw-jvjh-pv8x.json b/advisories/unreviewed/2022/05/GHSA-6gjw-jvjh-pv8x/GHSA-6gjw-jvjh-pv8x.json index 9fb542e7103..c13ec2e3b3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gjw-jvjh-pv8x/GHSA-6gjw-jvjh-pv8x.json +++ b/advisories/unreviewed/2022/05/GHSA-6gjw-jvjh-pv8x/GHSA-6gjw-jvjh-pv8x.json @@ -7,12 +7,8 @@ "CVE-2005-4400" ], "details": "Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hfw-6qgf-qp2c/GHSA-6hfw-6qgf-qp2c.json b/advisories/unreviewed/2022/05/GHSA-6hfw-6qgf-qp2c/GHSA-6hfw-6qgf-qp2c.json index 0c234f5da52..b785e57cf0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hfw-6qgf-qp2c/GHSA-6hfw-6qgf-qp2c.json +++ b/advisories/unreviewed/2022/05/GHSA-6hfw-6qgf-qp2c/GHSA-6hfw-6qgf-qp2c.json @@ -7,12 +7,8 @@ "CVE-2021-30610" ], "details": "Use after free in Extensions API in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hrr-25fh-jc7j/GHSA-6hrr-25fh-jc7j.json b/advisories/unreviewed/2022/05/GHSA-6hrr-25fh-jc7j/GHSA-6hrr-25fh-jc7j.json index d16b9ff6cda..82552a9779e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hrr-25fh-jc7j/GHSA-6hrr-25fh-jc7j.json +++ b/advisories/unreviewed/2022/05/GHSA-6hrr-25fh-jc7j/GHSA-6hrr-25fh-jc7j.json @@ -7,12 +7,8 @@ "CVE-2021-30768" ], "details": "A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. A sandboxed process may be able to circumvent sandbox restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6jjp-26vv-mq6q/GHSA-6jjp-26vv-mq6q.json b/advisories/unreviewed/2022/05/GHSA-6jjp-26vv-mq6q/GHSA-6jjp-26vv-mq6q.json index da48b1a220f..c9c5d781258 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jjp-26vv-mq6q/GHSA-6jjp-26vv-mq6q.json +++ b/advisories/unreviewed/2022/05/GHSA-6jjp-26vv-mq6q/GHSA-6jjp-26vv-mq6q.json @@ -7,12 +7,8 @@ "CVE-2005-3917" ], "details": "SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6jr2-9mj6-xwqc/GHSA-6jr2-9mj6-xwqc.json b/advisories/unreviewed/2022/05/GHSA-6jr2-9mj6-xwqc/GHSA-6jr2-9mj6-xwqc.json index 1f001e5398d..d2f916bf040 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jr2-9mj6-xwqc/GHSA-6jr2-9mj6-xwqc.json +++ b/advisories/unreviewed/2022/05/GHSA-6jr2-9mj6-xwqc/GHSA-6jr2-9mj6-xwqc.json @@ -7,12 +7,8 @@ "CVE-2005-4249" ], "details": "ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via requests to the forum/users directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6mch-9mqr-vw5g/GHSA-6mch-9mqr-vw5g.json b/advisories/unreviewed/2022/05/GHSA-6mch-9mqr-vw5g/GHSA-6mch-9mqr-vw5g.json index 4a6595d2303..390264a55be 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mch-9mqr-vw5g/GHSA-6mch-9mqr-vw5g.json +++ b/advisories/unreviewed/2022/05/GHSA-6mch-9mqr-vw5g/GHSA-6mch-9mqr-vw5g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mq7-ggq4-5r36/GHSA-6mq7-ggq4-5r36.json b/advisories/unreviewed/2022/05/GHSA-6mq7-ggq4-5r36/GHSA-6mq7-ggq4-5r36.json index 453c47a7202..f453a7919de 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mq7-ggq4-5r36/GHSA-6mq7-ggq4-5r36.json +++ b/advisories/unreviewed/2022/05/GHSA-6mq7-ggq4-5r36/GHSA-6mq7-ggq4-5r36.json @@ -7,12 +7,8 @@ "CVE-2021-30780" ], "details": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. A malicious application may be able to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6p9j-f6xp-23r3/GHSA-6p9j-f6xp-23r3.json b/advisories/unreviewed/2022/05/GHSA-6p9j-f6xp-23r3/GHSA-6p9j-f6xp-23r3.json index 051662633b0..79479335c71 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p9j-f6xp-23r3/GHSA-6p9j-f6xp-23r3.json +++ b/advisories/unreviewed/2022/05/GHSA-6p9j-f6xp-23r3/GHSA-6p9j-f6xp-23r3.json @@ -7,12 +7,8 @@ "CVE-2021-28914" ], "details": "BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an attack chain to gain SSH root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q4x-rgwv-967m/GHSA-6q4x-rgwv-967m.json b/advisories/unreviewed/2022/05/GHSA-6q4x-rgwv-967m/GHSA-6q4x-rgwv-967m.json index 77f8cd0a000..dcd08bafa7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q4x-rgwv-967m/GHSA-6q4x-rgwv-967m.json +++ b/advisories/unreviewed/2022/05/GHSA-6q4x-rgwv-967m/GHSA-6q4x-rgwv-967m.json @@ -7,12 +7,8 @@ "CVE-2020-19137" ], "details": "Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component \"autumn-cms/user/getAllUser/?page=1&limit=10\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q64-4q4f-xg8j/GHSA-6q64-4q4f-xg8j.json b/advisories/unreviewed/2022/05/GHSA-6q64-4q4f-xg8j/GHSA-6q64-4q4f-xg8j.json index 74abb8880ac..2ad844c3596 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q64-4q4f-xg8j/GHSA-6q64-4q4f-xg8j.json +++ b/advisories/unreviewed/2022/05/GHSA-6q64-4q4f-xg8j/GHSA-6q64-4q4f-xg8j.json @@ -7,12 +7,8 @@ "CVE-2005-4005" ], "details": "SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute arbitrary SQL commands via the srch_text parameter in a Search and Sort option to messages.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qh5-cp9g-4x2r/GHSA-6qh5-cp9g-4x2r.json b/advisories/unreviewed/2022/05/GHSA-6qh5-cp9g-4x2r/GHSA-6qh5-cp9g-4x2r.json index bc6dcd238aa..1e69194ffac 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qh5-cp9g-4x2r/GHSA-6qh5-cp9g-4x2r.json +++ b/advisories/unreviewed/2022/05/GHSA-6qh5-cp9g-4x2r/GHSA-6qh5-cp9g-4x2r.json @@ -7,12 +7,8 @@ "CVE-2021-30712" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qqr-9g87-rcp3/GHSA-6qqr-9g87-rcp3.json b/advisories/unreviewed/2022/05/GHSA-6qqr-9g87-rcp3/GHSA-6qqr-9g87-rcp3.json index 2b7c6941fb4..aed77f01d28 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qqr-9g87-rcp3/GHSA-6qqr-9g87-rcp3.json +++ b/advisories/unreviewed/2022/05/GHSA-6qqr-9g87-rcp3/GHSA-6qqr-9g87-rcp3.json @@ -7,12 +7,8 @@ "CVE-2021-38704" ], "details": "Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v66-p7cp-7qq7/GHSA-6v66-p7cp-7qq7.json b/advisories/unreviewed/2022/05/GHSA-6v66-p7cp-7qq7/GHSA-6v66-p7cp-7qq7.json index 33887e97483..f5f43b46e07 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v66-p7cp-7qq7/GHSA-6v66-p7cp-7qq7.json +++ b/advisories/unreviewed/2022/05/GHSA-6v66-p7cp-7qq7/GHSA-6v66-p7cp-7qq7.json @@ -7,12 +7,8 @@ "CVE-2005-4164" ], "details": "SQL injection vulnerability in view.php in PHP-addressbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6wjr-v5v8-r9w2/GHSA-6wjr-v5v8-r9w2.json b/advisories/unreviewed/2022/05/GHSA-6wjr-v5v8-r9w2/GHSA-6wjr-v5v8-r9w2.json index c358f882755..bd5a3ba0fbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wjr-v5v8-r9w2/GHSA-6wjr-v5v8-r9w2.json +++ b/advisories/unreviewed/2022/05/GHSA-6wjr-v5v8-r9w2/GHSA-6wjr-v5v8-r9w2.json @@ -7,12 +7,8 @@ "CVE-2021-3767" ], "details": "bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x24-hm2g-9f7x/GHSA-6x24-hm2g-9f7x.json b/advisories/unreviewed/2022/05/GHSA-6x24-hm2g-9f7x/GHSA-6x24-hm2g-9f7x.json index ef59051bea3..aaa3c9ab408 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x24-hm2g-9f7x/GHSA-6x24-hm2g-9f7x.json +++ b/advisories/unreviewed/2022/05/GHSA-6x24-hm2g-9f7x/GHSA-6x24-hm2g-9f7x.json @@ -7,12 +7,8 @@ "CVE-2005-4039" ], "details": "Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x2q-29mm-jmg2/GHSA-6x2q-29mm-jmg2.json b/advisories/unreviewed/2022/05/GHSA-6x2q-29mm-jmg2/GHSA-6x2q-29mm-jmg2.json index 2dac42f4379..66119070228 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x2q-29mm-jmg2/GHSA-6x2q-29mm-jmg2.json +++ b/advisories/unreviewed/2022/05/GHSA-6x2q-29mm-jmg2/GHSA-6x2q-29mm-jmg2.json @@ -7,12 +7,8 @@ "CVE-2005-4205" ], "details": "Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72fv-wfpw-6q2x/GHSA-72fv-wfpw-6q2x.json b/advisories/unreviewed/2022/05/GHSA-72fv-wfpw-6q2x/GHSA-72fv-wfpw-6q2x.json index c7ef19d6494..6ed5c48860a 100644 --- a/advisories/unreviewed/2022/05/GHSA-72fv-wfpw-6q2x/GHSA-72fv-wfpw-6q2x.json +++ b/advisories/unreviewed/2022/05/GHSA-72fv-wfpw-6q2x/GHSA-72fv-wfpw-6q2x.json @@ -7,12 +7,8 @@ "CVE-2005-4257" ], "details": "Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND). NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-734x-q67w-xmjv/GHSA-734x-q67w-xmjv.json b/advisories/unreviewed/2022/05/GHSA-734x-q67w-xmjv/GHSA-734x-q67w-xmjv.json index c77fefa9216..b19e49aa23e 100644 --- a/advisories/unreviewed/2022/05/GHSA-734x-q67w-xmjv/GHSA-734x-q67w-xmjv.json +++ b/advisories/unreviewed/2022/05/GHSA-734x-q67w-xmjv/GHSA-734x-q67w-xmjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7427-ffj8-874j/GHSA-7427-ffj8-874j.json b/advisories/unreviewed/2022/05/GHSA-7427-ffj8-874j/GHSA-7427-ffj8-874j.json index fe3f5d58578..a333b9211bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7427-ffj8-874j/GHSA-7427-ffj8-874j.json +++ b/advisories/unreviewed/2022/05/GHSA-7427-ffj8-874j/GHSA-7427-ffj8-874j.json @@ -7,12 +7,8 @@ "CVE-2005-4397" ], "details": "SQL injection vulnerability in RunScript.asp iCMS allows remote attackers to execute arbitrary SQL commands via the Event_ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74p7-386w-jw56/GHSA-74p7-386w-jw56.json b/advisories/unreviewed/2022/05/GHSA-74p7-386w-jw56/GHSA-74p7-386w-jw56.json index 89fd0844f3d..25bdc4a9fef 100644 --- a/advisories/unreviewed/2022/05/GHSA-74p7-386w-jw56/GHSA-74p7-386w-jw56.json +++ b/advisories/unreviewed/2022/05/GHSA-74p7-386w-jw56/GHSA-74p7-386w-jw56.json @@ -7,12 +7,8 @@ "CVE-2021-1877" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75hp-fjj5-wjf4/GHSA-75hp-fjj5-wjf4.json b/advisories/unreviewed/2022/05/GHSA-75hp-fjj5-wjf4/GHSA-75hp-fjj5-wjf4.json index 4ce4f533f9b..8460a632d8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-75hp-fjj5-wjf4/GHSA-75hp-fjj5-wjf4.json +++ b/advisories/unreviewed/2022/05/GHSA-75hp-fjj5-wjf4/GHSA-75hp-fjj5-wjf4.json @@ -7,12 +7,8 @@ "CVE-2021-1837" ], "details": "A certificate validation issue was addressed. This issue is fixed in iOS 14.5 and iPadOS 14.5. An attacker in a privileged network position may be able to alter network traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76j4-qr57-p9fg/GHSA-76j4-qr57-p9fg.json b/advisories/unreviewed/2022/05/GHSA-76j4-qr57-p9fg/GHSA-76j4-qr57-p9fg.json index 9931d56e809..4fcb072f6a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-76j4-qr57-p9fg/GHSA-76j4-qr57-p9fg.json +++ b/advisories/unreviewed/2022/05/GHSA-76j4-qr57-p9fg/GHSA-76j4-qr57-p9fg.json @@ -7,12 +7,8 @@ "CVE-2021-33484" ], "details": "An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile it, and discover a hardcoded IV used to encrypt the username and userid in the comment POST request. Additionally, the attacker can decrypt the encrypted encryption key (sent as a parameter in the comment form request) by setting this encrypted value as the username, which will appear on the comment page in its decrypted form. Using these two values (combined with the encryption functionality discovered in the decompiled installer), the attacker can encrypt another user's ID and username. These values can be used as part of the comment posting request in order to spoof the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76xq-mh8g-37w6/GHSA-76xq-mh8g-37w6.json b/advisories/unreviewed/2022/05/GHSA-76xq-mh8g-37w6/GHSA-76xq-mh8g-37w6.json index 2296ed1ba8d..cce109da750 100644 --- a/advisories/unreviewed/2022/05/GHSA-76xq-mh8g-37w6/GHSA-76xq-mh8g-37w6.json +++ b/advisories/unreviewed/2022/05/GHSA-76xq-mh8g-37w6/GHSA-76xq-mh8g-37w6.json @@ -7,12 +7,8 @@ "CVE-2021-38321" ], "details": "The Custom Menu Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selected_menu parameter found in the ~/custom-menus.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-788w-w3g2-24ww/GHSA-788w-w3g2-24ww.json b/advisories/unreviewed/2022/05/GHSA-788w-w3g2-24ww/GHSA-788w-w3g2-24ww.json index 8324c0971a3..9d0f4c1d82a 100644 --- a/advisories/unreviewed/2022/05/GHSA-788w-w3g2-24ww/GHSA-788w-w3g2-24ww.json +++ b/advisories/unreviewed/2022/05/GHSA-788w-w3g2-24ww/GHSA-788w-w3g2-24ww.json @@ -7,12 +7,8 @@ "CVE-2021-40355" ], "details": "A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The affected application contains Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to use user-supplied input to access objects directly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79fx-vxcw-m53c/GHSA-79fx-vxcw-m53c.json b/advisories/unreviewed/2022/05/GHSA-79fx-vxcw-m53c/GHSA-79fx-vxcw-m53c.json index c4b0b977e10..3032733d910 100644 --- a/advisories/unreviewed/2022/05/GHSA-79fx-vxcw-m53c/GHSA-79fx-vxcw-m53c.json +++ b/advisories/unreviewed/2022/05/GHSA-79fx-vxcw-m53c/GHSA-79fx-vxcw-m53c.json @@ -7,12 +7,8 @@ "CVE-2005-3979" ], "details": "relocate_server.php in Coppermine Photo Gallery (CPG) 1.4.2 and 1.4 beta is not removed after installation and does not use authentication, which allows remote attackers to obtain sensitive information, such as database configuration, via a direct request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7c3j-px25-gfc4/GHSA-7c3j-px25-gfc4.json b/advisories/unreviewed/2022/05/GHSA-7c3j-px25-gfc4/GHSA-7c3j-px25-gfc4.json index e749439bd67..d86b7e2ef5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c3j-px25-gfc4/GHSA-7c3j-px25-gfc4.json +++ b/advisories/unreviewed/2022/05/GHSA-7c3j-px25-gfc4/GHSA-7c3j-px25-gfc4.json @@ -7,12 +7,8 @@ "CVE-2005-4198" ], "details": "SQL injection vulnerability in index.php in Netref 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7chv-w23j-556x/GHSA-7chv-w23j-556x.json b/advisories/unreviewed/2022/05/GHSA-7chv-w23j-556x/GHSA-7chv-w23j-556x.json index 319533cf06d..824091655c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7chv-w23j-556x/GHSA-7chv-w23j-556x.json +++ b/advisories/unreviewed/2022/05/GHSA-7chv-w23j-556x/GHSA-7chv-w23j-556x.json @@ -7,12 +7,8 @@ "CVE-2021-21489" ], "details": "SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user related data, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with administrative privileges to store a malicious script on the portal. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of portal content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g9f-9vq9-79j8/GHSA-7g9f-9vq9-79j8.json b/advisories/unreviewed/2022/05/GHSA-7g9f-9vq9-79j8/GHSA-7g9f-9vq9-79j8.json index d5fe2574720..3d093fc132a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g9f-9vq9-79j8/GHSA-7g9f-9vq9-79j8.json +++ b/advisories/unreviewed/2022/05/GHSA-7g9f-9vq9-79j8/GHSA-7g9f-9vq9-79j8.json @@ -7,12 +7,8 @@ "CVE-2005-4031" ], "details": "Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the \"user language option,\" which is used as part of a dynamic class name that is processed using the eval function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7gx9-m7c6-98gf/GHSA-7gx9-m7c6-98gf.json b/advisories/unreviewed/2022/05/GHSA-7gx9-m7c6-98gf/GHSA-7gx9-m7c6-98gf.json index d9011837f4c..94e37dc85aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gx9-m7c6-98gf/GHSA-7gx9-m7c6-98gf.json +++ b/advisories/unreviewed/2022/05/GHSA-7gx9-m7c6-98gf/GHSA-7gx9-m7c6-98gf.json @@ -7,12 +7,8 @@ "CVE-2021-1825" ], "details": "An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gxg-937v-gfc4/GHSA-7gxg-937v-gfc4.json b/advisories/unreviewed/2022/05/GHSA-7gxg-937v-gfc4/GHSA-7gxg-937v-gfc4.json index dd02a880241..67080fb14e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gxg-937v-gfc4/GHSA-7gxg-937v-gfc4.json +++ b/advisories/unreviewed/2022/05/GHSA-7gxg-937v-gfc4/GHSA-7gxg-937v-gfc4.json @@ -7,12 +7,8 @@ "CVE-2021-22239" ], "details": "An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hf2-fvcc-82xj/GHSA-7hf2-fvcc-82xj.json b/advisories/unreviewed/2022/05/GHSA-7hf2-fvcc-82xj/GHSA-7hf2-fvcc-82xj.json index eae76a252dc..fb33a951933 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hf2-fvcc-82xj/GHSA-7hf2-fvcc-82xj.json +++ b/advisories/unreviewed/2022/05/GHSA-7hf2-fvcc-82xj/GHSA-7hf2-fvcc-82xj.json @@ -7,12 +7,8 @@ "CVE-2021-37724" ], "details": "A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released patches for ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hx7-952f-whmw/GHSA-7hx7-952f-whmw.json b/advisories/unreviewed/2022/05/GHSA-7hx7-952f-whmw/GHSA-7hx7-952f-whmw.json index 50945b694df..81e2414f2bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hx7-952f-whmw/GHSA-7hx7-952f-whmw.json +++ b/advisories/unreviewed/2022/05/GHSA-7hx7-952f-whmw/GHSA-7hx7-952f-whmw.json @@ -7,12 +7,8 @@ "CVE-2005-3966" ], "details": "Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7j4h-6cq9-gmjv/GHSA-7j4h-6cq9-gmjv.json b/advisories/unreviewed/2022/05/GHSA-7j4h-6cq9-gmjv/GHSA-7j4h-6cq9-gmjv.json index 0df24cb1a97..fee0be44bf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j4h-6cq9-gmjv/GHSA-7j4h-6cq9-gmjv.json +++ b/advisories/unreviewed/2022/05/GHSA-7j4h-6cq9-gmjv/GHSA-7j4h-6cq9-gmjv.json @@ -7,12 +7,8 @@ "CVE-2021-34145" ], "details": "The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with an invalid Baseband packet type (and LT_ADDRESS and LT_ADDR) after completion of the LMP setup procedure, allowing attackers in radio range to trigger a denial of service (firmware crash) via a crafted LMP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jmm-wcvm-wvj4/GHSA-7jmm-wcvm-wvj4.json b/advisories/unreviewed/2022/05/GHSA-7jmm-wcvm-wvj4/GHSA-7jmm-wcvm-wvj4.json index 7924a3a3e0b..46b66ca6ad1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jmm-wcvm-wvj4/GHSA-7jmm-wcvm-wvj4.json +++ b/advisories/unreviewed/2022/05/GHSA-7jmm-wcvm-wvj4/GHSA-7jmm-wcvm-wvj4.json @@ -7,12 +7,8 @@ "CVE-2005-4197" ], "details": "tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jrf-mjm4-267q/GHSA-7jrf-mjm4-267q.json b/advisories/unreviewed/2022/05/GHSA-7jrf-mjm4-267q/GHSA-7jrf-mjm4-267q.json index 99977b4db31..b0156b3356c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jrf-mjm4-267q/GHSA-7jrf-mjm4-267q.json +++ b/advisories/unreviewed/2022/05/GHSA-7jrf-mjm4-267q/GHSA-7jrf-mjm4-267q.json @@ -7,12 +7,8 @@ "CVE-2005-4346" ], "details": "Invalid SQL syntax error in blog.php in phpBB Blog 2.2.2 and earlier allows remote attackers to obtain the full path of the application via an invalid permalink parameter to index.php, which produces an invalid SQL query that leaks the full pathname in a SQL syntax error message. NOTE: this was originally claimed to be SQL injection, but a cleansing step strips all non-digit characters and leaves an empty permalink argument, which leads to the syntax error.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7mj2-j7j2-q79g/GHSA-7mj2-j7j2-q79g.json b/advisories/unreviewed/2022/05/GHSA-7mj2-j7j2-q79g/GHSA-7mj2-j7j2-q79g.json index 21dd11d994b..3237cdebd6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mj2-j7j2-q79g/GHSA-7mj2-j7j2-q79g.json +++ b/advisories/unreviewed/2022/05/GHSA-7mj2-j7j2-q79g/GHSA-7mj2-j7j2-q79g.json @@ -7,12 +7,8 @@ "CVE-2005-4018" ], "details": "SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pjv-6xh8-8m77/GHSA-7pjv-6xh8-8m77.json b/advisories/unreviewed/2022/05/GHSA-7pjv-6xh8-8m77/GHSA-7pjv-6xh8-8m77.json index 60b448ae5c8..85cd6f5a7c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pjv-6xh8-8m77/GHSA-7pjv-6xh8-8m77.json +++ b/advisories/unreviewed/2022/05/GHSA-7pjv-6xh8-8m77/GHSA-7pjv-6xh8-8m77.json @@ -7,12 +7,8 @@ "CVE-2020-19767" ], "details": "A lack of target address verification in the destroycontract() function of 0xRACER 1.0 allows attackers to steal tokens from victim users via a crafted script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7pq4-47cm-wq26/GHSA-7pq4-47cm-wq26.json b/advisories/unreviewed/2022/05/GHSA-7pq4-47cm-wq26/GHSA-7pq4-47cm-wq26.json index 69f51137966..4fc07b3ec8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pq4-47cm-wq26/GHSA-7pq4-47cm-wq26.json +++ b/advisories/unreviewed/2022/05/GHSA-7pq4-47cm-wq26/GHSA-7pq4-47cm-wq26.json @@ -7,12 +7,8 @@ "CVE-2005-3943" ], "details": "Multiple SQL injection vulnerabilities in ilyav FAQ System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) FAQ_ID and (2) action parameters in (a) viewFAQ.php; and (3) CATEGORY_ID parameter in (b) index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7qcx-m2gc-9659/GHSA-7qcx-m2gc-9659.json b/advisories/unreviewed/2022/05/GHSA-7qcx-m2gc-9659/GHSA-7qcx-m2gc-9659.json index 110560890f1..fc53294bca8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qcx-m2gc-9659/GHSA-7qcx-m2gc-9659.json +++ b/advisories/unreviewed/2022/05/GHSA-7qcx-m2gc-9659/GHSA-7qcx-m2gc-9659.json @@ -7,12 +7,8 @@ "CVE-2021-30758" ], "details": "A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qvm-w8hm-h4c5/GHSA-7qvm-w8hm-h4c5.json b/advisories/unreviewed/2022/05/GHSA-7qvm-w8hm-h4c5/GHSA-7qvm-w8hm-h4c5.json index 5c2b854bf5c..ca35f1b0935 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qvm-w8hm-h4c5/GHSA-7qvm-w8hm-h4c5.json +++ b/advisories/unreviewed/2022/05/GHSA-7qvm-w8hm-h4c5/GHSA-7qvm-w8hm-h4c5.json @@ -7,12 +7,8 @@ "CVE-2005-4157" ], "details": "Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to authenticate to the service using an account that has been disabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rv6-hgv9-m9mm/GHSA-7rv6-hgv9-m9mm.json b/advisories/unreviewed/2022/05/GHSA-7rv6-hgv9-m9mm/GHSA-7rv6-hgv9-m9mm.json index e8a66cf3741..7510c317ff6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rv6-hgv9-m9mm/GHSA-7rv6-hgv9-m9mm.json +++ b/advisories/unreviewed/2022/05/GHSA-7rv6-hgv9-m9mm/GHSA-7rv6-hgv9-m9mm.json @@ -7,12 +7,8 @@ "CVE-2021-30722" ], "details": "An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to leak sensitive user information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v28-w24g-89p5/GHSA-7v28-w24g-89p5.json b/advisories/unreviewed/2022/05/GHSA-7v28-w24g-89p5/GHSA-7v28-w24g-89p5.json index 11c4e58011a..0fd67bd4c69 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v28-w24g-89p5/GHSA-7v28-w24g-89p5.json +++ b/advisories/unreviewed/2022/05/GHSA-7v28-w24g-89p5/GHSA-7v28-w24g-89p5.json @@ -7,12 +7,8 @@ "CVE-2020-27942" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing a maliciously crafted font file may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v38-8hc5-3fh5/GHSA-7v38-8hc5-3fh5.json b/advisories/unreviewed/2022/05/GHSA-7v38-8hc5-3fh5/GHSA-7v38-8hc5-3fh5.json index c41a3691211..4ff89163e72 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v38-8hc5-3fh5/GHSA-7v38-8hc5-3fh5.json +++ b/advisories/unreviewed/2022/05/GHSA-7v38-8hc5-3fh5/GHSA-7v38-8hc5-3fh5.json @@ -7,12 +7,8 @@ "CVE-2005-4324" ], "details": "Hitachi Groupmax Mail SMTP 06-50 through 06-52-/A and 07-00 through 07-20 allows remote attackers to cause a denial of service (service stop) via an e-mail message with an \"invalid format.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v4j-rp27-9f47/GHSA-7v4j-rp27-9f47.json b/advisories/unreviewed/2022/05/GHSA-7v4j-rp27-9f47/GHSA-7v4j-rp27-9f47.json index c4d730d5014..2f74a783e19 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v4j-rp27-9f47/GHSA-7v4j-rp27-9f47.json +++ b/advisories/unreviewed/2022/05/GHSA-7v4j-rp27-9f47/GHSA-7v4j-rp27-9f47.json @@ -7,12 +7,8 @@ "CVE-2005-4327" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Michael Arndt WebCal 1.11-3.04 allow remote attackers to inject arbitrary web script or HTML via the (1) function, (2) year, and (3) date parameters to webcal.cgi, (4) new calendar entries, and (5) notes for entries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vcj-h4jh-xcfx/GHSA-7vcj-h4jh-xcfx.json b/advisories/unreviewed/2022/05/GHSA-7vcj-h4jh-xcfx/GHSA-7vcj-h4jh-xcfx.json index bce5d372c4e..e7791c9f8f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vcj-h4jh-xcfx/GHSA-7vcj-h4jh-xcfx.json +++ b/advisories/unreviewed/2022/05/GHSA-7vcj-h4jh-xcfx/GHSA-7vcj-h4jh-xcfx.json @@ -7,12 +7,8 @@ "CVE-2005-4090" ], "details": "Unspecified vulnerability in HP-UX B.11.00 to B.11.23, when IPSEC is running, allows remote attackers to have unknown impact.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vcw-f634-pq9c/GHSA-7vcw-f634-pq9c.json b/advisories/unreviewed/2022/05/GHSA-7vcw-f634-pq9c/GHSA-7vcw-f634-pq9c.json index b3423cf7b4a..1281e77e460 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vcw-f634-pq9c/GHSA-7vcw-f634-pq9c.json +++ b/advisories/unreviewed/2022/05/GHSA-7vcw-f634-pq9c/GHSA-7vcw-f634-pq9c.json @@ -7,12 +7,8 @@ "CVE-2005-4245" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vhc-pr5j-ph22/GHSA-7vhc-pr5j-ph22.json b/advisories/unreviewed/2022/05/GHSA-7vhc-pr5j-ph22/GHSA-7vhc-pr5j-ph22.json index 9443ab5c2bb..edc696f3e1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vhc-pr5j-ph22/GHSA-7vhc-pr5j-ph22.json +++ b/advisories/unreviewed/2022/05/GHSA-7vhc-pr5j-ph22/GHSA-7vhc-pr5j-ph22.json @@ -7,12 +7,8 @@ "CVE-2005-3997" ], "details": "Zen Cart 1.2.6d and earlier, under certain PHP configurations, allows remote attackers to obtain sensitive information via direct requests to files in the admin/includes directory, including (1) graphs/banner_daily.php, (2) graphs/banner_infobox.php, (3) graphs/banner_yearly.php, (4) graphs/banner_monthly.php, (5) application_bottom.php, (6) attributes_preview.php, (7) modules/category_product_listing.php, (8) modules/copy_to_confirm.php, (9) modules/delete_product_confirm.php, and (10) modules/move_product_confirm.php, which leaks the web server path in the resulting error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7w7m-m5q2-wx8m/GHSA-7w7m-m5q2-wx8m.json b/advisories/unreviewed/2022/05/GHSA-7w7m-m5q2-wx8m/GHSA-7w7m-m5q2-wx8m.json index 384fcc63835..25174de04a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w7m-m5q2-wx8m/GHSA-7w7m-m5q2-wx8m.json +++ b/advisories/unreviewed/2022/05/GHSA-7w7m-m5q2-wx8m/GHSA-7w7m-m5q2-wx8m.json @@ -7,12 +7,8 @@ "CVE-2021-24395" ], "details": "The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7w8v-27p6-fvcw/GHSA-7w8v-27p6-fvcw.json b/advisories/unreviewed/2022/05/GHSA-7w8v-27p6-fvcw/GHSA-7w8v-27p6-fvcw.json index 513b791481e..303706d62cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w8v-27p6-fvcw/GHSA-7w8v-27p6-fvcw.json +++ b/advisories/unreviewed/2022/05/GHSA-7w8v-27p6-fvcw/GHSA-7w8v-27p6-fvcw.json @@ -7,12 +7,8 @@ "CVE-2021-32568" ], "details": "mrdoc is vulnerable to Deserialization of Untrusted Data", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7whh-554c-6p33/GHSA-7whh-554c-6p33.json b/advisories/unreviewed/2022/05/GHSA-7whh-554c-6p33/GHSA-7whh-554c-6p33.json index d3ab7e759ec..4d2ad2eca54 100644 --- a/advisories/unreviewed/2022/05/GHSA-7whh-554c-6p33/GHSA-7whh-554c-6p33.json +++ b/advisories/unreviewed/2022/05/GHSA-7whh-554c-6p33/GHSA-7whh-554c-6p33.json @@ -7,12 +7,8 @@ "CVE-2005-4391" ], "details": "Cross-site scripting (XSS) vulnerability in damoon allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xjf-9gpj-wwj4/GHSA-7xjf-9gpj-wwj4.json b/advisories/unreviewed/2022/05/GHSA-7xjf-9gpj-wwj4/GHSA-7xjf-9gpj-wwj4.json index ef0c19f1dc1..9359e1f0c9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xjf-9gpj-wwj4/GHSA-7xjf-9gpj-wwj4.json +++ b/advisories/unreviewed/2022/05/GHSA-7xjf-9gpj-wwj4/GHSA-7xjf-9gpj-wwj4.json @@ -7,12 +7,8 @@ "CVE-2021-24393" ], "details": "A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xwv-xhf6-x5cr/GHSA-7xwv-xhf6-x5cr.json b/advisories/unreviewed/2022/05/GHSA-7xwv-xhf6-x5cr/GHSA-7xwv-xhf6-x5cr.json index c35012bf84c..3815edb63d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xwv-xhf6-x5cr/GHSA-7xwv-xhf6-x5cr.json +++ b/advisories/unreviewed/2022/05/GHSA-7xwv-xhf6-x5cr/GHSA-7xwv-xhf6-x5cr.json @@ -7,12 +7,8 @@ "CVE-2021-40356" ], "details": "A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8235-3268-fjf9/GHSA-8235-3268-fjf9.json b/advisories/unreviewed/2022/05/GHSA-8235-3268-fjf9/GHSA-8235-3268-fjf9.json index 72c703643d2..08d27b8bb06 100644 --- a/advisories/unreviewed/2022/05/GHSA-8235-3268-fjf9/GHSA-8235-3268-fjf9.json +++ b/advisories/unreviewed/2022/05/GHSA-8235-3268-fjf9/GHSA-8235-3268-fjf9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82mm-45xg-j4xh/GHSA-82mm-45xg-j4xh.json b/advisories/unreviewed/2022/05/GHSA-82mm-45xg-j4xh/GHSA-82mm-45xg-j4xh.json index 0d76dc636ae..aa4c9193ddb 100644 --- a/advisories/unreviewed/2022/05/GHSA-82mm-45xg-j4xh/GHSA-82mm-45xg-j4xh.json +++ b/advisories/unreviewed/2022/05/GHSA-82mm-45xg-j4xh/GHSA-82mm-45xg-j4xh.json @@ -7,12 +7,8 @@ "CVE-2021-40516" ], "details": "WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82p8-66pg-8588/GHSA-82p8-66pg-8588.json b/advisories/unreviewed/2022/05/GHSA-82p8-66pg-8588/GHSA-82p8-66pg-8588.json index 6850a1bd7ce..231377ccea8 100644 --- a/advisories/unreviewed/2022/05/GHSA-82p8-66pg-8588/GHSA-82p8-66pg-8588.json +++ b/advisories/unreviewed/2022/05/GHSA-82p8-66pg-8588/GHSA-82p8-66pg-8588.json @@ -7,12 +7,8 @@ "CVE-2020-27940" ], "details": "This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82pj-27w3-mggj/GHSA-82pj-27w3-mggj.json b/advisories/unreviewed/2022/05/GHSA-82pj-27w3-mggj/GHSA-82pj-27w3-mggj.json index 433a3c7c3b3..d2fed29e960 100644 --- a/advisories/unreviewed/2022/05/GHSA-82pj-27w3-mggj/GHSA-82pj-27w3-mggj.json +++ b/advisories/unreviewed/2022/05/GHSA-82pj-27w3-mggj/GHSA-82pj-27w3-mggj.json @@ -7,12 +7,8 @@ "CVE-2021-1816" ], "details": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-838j-jvxc-qx3c/GHSA-838j-jvxc-qx3c.json b/advisories/unreviewed/2022/05/GHSA-838j-jvxc-qx3c/GHSA-838j-jvxc-qx3c.json index 801f4b063fd..f6eff26caf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-838j-jvxc-qx3c/GHSA-838j-jvxc-qx3c.json +++ b/advisories/unreviewed/2022/05/GHSA-838j-jvxc-qx3c/GHSA-838j-jvxc-qx3c.json @@ -7,12 +7,8 @@ "CVE-2005-4139" ], "details": "Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8434-xgm6-pw8h/GHSA-8434-xgm6-pw8h.json b/advisories/unreviewed/2022/05/GHSA-8434-xgm6-pw8h/GHSA-8434-xgm6-pw8h.json index 43344223257..e27baef1eed 100644 --- a/advisories/unreviewed/2022/05/GHSA-8434-xgm6-pw8h/GHSA-8434-xgm6-pw8h.json +++ b/advisories/unreviewed/2022/05/GHSA-8434-xgm6-pw8h/GHSA-8434-xgm6-pw8h.json @@ -7,12 +7,8 @@ "CVE-2005-4095" ], "details": "Directory traversal vulnerability in connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to list arbitrary files and directories via \"..\" sequences in the Type parameter in a GetFoldersAndFiles command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8558-rh5p-hjfm/GHSA-8558-rh5p-hjfm.json b/advisories/unreviewed/2022/05/GHSA-8558-rh5p-hjfm/GHSA-8558-rh5p-hjfm.json index ffab540693d..93ad00b2166 100644 --- a/advisories/unreviewed/2022/05/GHSA-8558-rh5p-hjfm/GHSA-8558-rh5p-hjfm.json +++ b/advisories/unreviewed/2022/05/GHSA-8558-rh5p-hjfm/GHSA-8558-rh5p-hjfm.json @@ -7,12 +7,8 @@ "CVE-2021-30787" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to cause unexpected system termination or write kernel memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-857q-ccvw-898p/GHSA-857q-ccvw-898p.json b/advisories/unreviewed/2022/05/GHSA-857q-ccvw-898p/GHSA-857q-ccvw-898p.json index 997d449c9d9..929fe8404c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-857q-ccvw-898p/GHSA-857q-ccvw-898p.json +++ b/advisories/unreviewed/2022/05/GHSA-857q-ccvw-898p/GHSA-857q-ccvw-898p.json @@ -7,12 +7,8 @@ "CVE-2005-4145" ], "details": "The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space (\"lyris\" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85q6-q3jc-qvmc/GHSA-85q6-q3jc-qvmc.json b/advisories/unreviewed/2022/05/GHSA-85q6-q3jc-qvmc/GHSA-85q6-q3jc-qvmc.json index 991668cd7db..9a39c6e5e56 100644 --- a/advisories/unreviewed/2022/05/GHSA-85q6-q3jc-qvmc/GHSA-85q6-q3jc-qvmc.json +++ b/advisories/unreviewed/2022/05/GHSA-85q6-q3jc-qvmc/GHSA-85q6-q3jc-qvmc.json @@ -7,12 +7,8 @@ "CVE-2021-28559" ], "details": "Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Information Exposure vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to restricted data stored within global variables and objects.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85x4-4wvc-5rg9/GHSA-85x4-4wvc-5rg9.json b/advisories/unreviewed/2022/05/GHSA-85x4-4wvc-5rg9/GHSA-85x4-4wvc-5rg9.json index d67ef53046b..6da16092502 100644 --- a/advisories/unreviewed/2022/05/GHSA-85x4-4wvc-5rg9/GHSA-85x4-4wvc-5rg9.json +++ b/advisories/unreviewed/2022/05/GHSA-85x4-4wvc-5rg9/GHSA-85x4-4wvc-5rg9.json @@ -7,12 +7,8 @@ "CVE-2005-4335" ], "details": "ProjectForum 4.7.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted pageid parameter to admin/versions.html.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8636-j732-qggq/GHSA-8636-j732-qggq.json b/advisories/unreviewed/2022/05/GHSA-8636-j732-qggq/GHSA-8636-j732-qggq.json index fcfa35933a8..cfca1d841eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8636-j732-qggq/GHSA-8636-j732-qggq.json +++ b/advisories/unreviewed/2022/05/GHSA-8636-j732-qggq/GHSA-8636-j732-qggq.json @@ -7,12 +7,8 @@ "CVE-2005-3919" ], "details": "Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.php and (2) SendPm.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-868x-c2ph-qm3r/GHSA-868x-c2ph-qm3r.json b/advisories/unreviewed/2022/05/GHSA-868x-c2ph-qm3r/GHSA-868x-c2ph-qm3r.json index 3af449f8a28..57b7fac0e3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-868x-c2ph-qm3r/GHSA-868x-c2ph-qm3r.json +++ b/advisories/unreviewed/2022/05/GHSA-868x-c2ph-qm3r/GHSA-868x-c2ph-qm3r.json @@ -7,12 +7,8 @@ "CVE-2021-1826" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to universal cross site scripting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86mv-vrc5-mh9v/GHSA-86mv-vrc5-mh9v.json b/advisories/unreviewed/2022/05/GHSA-86mv-vrc5-mh9v/GHSA-86mv-vrc5-mh9v.json index 89699281799..a555c36e896 100644 --- a/advisories/unreviewed/2022/05/GHSA-86mv-vrc5-mh9v/GHSA-86mv-vrc5-mh9v.json +++ b/advisories/unreviewed/2022/05/GHSA-86mv-vrc5-mh9v/GHSA-86mv-vrc5-mh9v.json @@ -7,12 +7,8 @@ "CVE-2005-4362" ], "details": "SQL injection vulnerability in page.php in Komodo CMS 2.1 allows remote attackers to execute arbitrary SQL commands via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-872c-p5hc-3585/GHSA-872c-p5hc-3585.json b/advisories/unreviewed/2022/05/GHSA-872c-p5hc-3585/GHSA-872c-p5hc-3585.json index 215926f287f..0a279b3ff83 100644 --- a/advisories/unreviewed/2022/05/GHSA-872c-p5hc-3585/GHSA-872c-p5hc-3585.json +++ b/advisories/unreviewed/2022/05/GHSA-872c-p5hc-3585/GHSA-872c-p5hc-3585.json @@ -7,12 +7,8 @@ "CVE-2005-4189" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith H3 before 2.0.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Calendar name field when creating calendars, (2) event title field when deleting events, the (3) Category and (4) Location search fields, and the (5) attendees email address fields when editing event attendees, and possibly other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87gf-f47g-jf9m/GHSA-87gf-f47g-jf9m.json b/advisories/unreviewed/2022/05/GHSA-87gf-f47g-jf9m/GHSA-87gf-f47g-jf9m.json index 4e45eda145f..0af50305109 100644 --- a/advisories/unreviewed/2022/05/GHSA-87gf-f47g-jf9m/GHSA-87gf-f47g-jf9m.json +++ b/advisories/unreviewed/2022/05/GHSA-87gf-f47g-jf9m/GHSA-87gf-f47g-jf9m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87h3-2wcq-m3cc/GHSA-87h3-2wcq-m3cc.json b/advisories/unreviewed/2022/05/GHSA-87h3-2wcq-m3cc/GHSA-87h3-2wcq-m3cc.json index edf9671cdaf..742f36c4c71 100644 --- a/advisories/unreviewed/2022/05/GHSA-87h3-2wcq-m3cc/GHSA-87h3-2wcq-m3cc.json +++ b/advisories/unreviewed/2022/05/GHSA-87h3-2wcq-m3cc/GHSA-87h3-2wcq-m3cc.json @@ -7,12 +7,8 @@ "CVE-2005-4004" ], "details": "Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87hq-4572-qw4h/GHSA-87hq-4572-qw4h.json b/advisories/unreviewed/2022/05/GHSA-87hq-4572-qw4h/GHSA-87hq-4572-qw4h.json index 8a8abd4d567..a249b3a7980 100644 --- a/advisories/unreviewed/2022/05/GHSA-87hq-4572-qw4h/GHSA-87hq-4572-qw4h.json +++ b/advisories/unreviewed/2022/05/GHSA-87hq-4572-qw4h/GHSA-87hq-4572-qw4h.json @@ -7,12 +7,8 @@ "CVE-2005-4313" ], "details": "SQL injection vulnerability in index.php in AlmondSoft Almond Personals 4.05 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-889c-x98f-cvvg/GHSA-889c-x98f-cvvg.json b/advisories/unreviewed/2022/05/GHSA-889c-x98f-cvvg/GHSA-889c-x98f-cvvg.json index 3155dc68275..001679d7730 100644 --- a/advisories/unreviewed/2022/05/GHSA-889c-x98f-cvvg/GHSA-889c-x98f-cvvg.json +++ b/advisories/unreviewed/2022/05/GHSA-889c-x98f-cvvg/GHSA-889c-x98f-cvvg.json @@ -7,12 +7,8 @@ "CVE-2005-4222" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in guestbook.cgi in Lars Ellingsen Guestserver 4.13 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified message fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-899p-97g6-x4h4/GHSA-899p-97g6-x4h4.json b/advisories/unreviewed/2022/05/GHSA-899p-97g6-x4h4/GHSA-899p-97g6-x4h4.json index 4d39cb5b5fa..492048da16c 100644 --- a/advisories/unreviewed/2022/05/GHSA-899p-97g6-x4h4/GHSA-899p-97g6-x4h4.json +++ b/advisories/unreviewed/2022/05/GHSA-899p-97g6-x4h4/GHSA-899p-97g6-x4h4.json @@ -7,12 +7,8 @@ "CVE-2021-38319" ], "details": "The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/morefromgoogle.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89qr-gmvh-jqf2/GHSA-89qr-gmvh-jqf2.json b/advisories/unreviewed/2022/05/GHSA-89qr-gmvh-jqf2/GHSA-89qr-gmvh-jqf2.json index 21cdc120553..54cb1999e25 100644 --- a/advisories/unreviewed/2022/05/GHSA-89qr-gmvh-jqf2/GHSA-89qr-gmvh-jqf2.json +++ b/advisories/unreviewed/2022/05/GHSA-89qr-gmvh-jqf2/GHSA-89qr-gmvh-jqf2.json @@ -7,12 +7,8 @@ "CVE-2021-34786" ], "details": "Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8c6r-qv58-w6fw/GHSA-8c6r-qv58-w6fw.json b/advisories/unreviewed/2022/05/GHSA-8c6r-qv58-w6fw/GHSA-8c6r-qv58-w6fw.json index 85a39dc67e0..e4f444b16d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c6r-qv58-w6fw/GHSA-8c6r-qv58-w6fw.json +++ b/advisories/unreviewed/2022/05/GHSA-8c6r-qv58-w6fw/GHSA-8c6r-qv58-w6fw.json @@ -7,12 +7,8 @@ "CVE-2021-30708" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cpm-2q4p-34xp/GHSA-8cpm-2q4p-34xp.json b/advisories/unreviewed/2022/05/GHSA-8cpm-2q4p-34xp/GHSA-8cpm-2q4p-34xp.json index 693d26fb630..17a1119a8d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cpm-2q4p-34xp/GHSA-8cpm-2q4p-34xp.json +++ b/advisories/unreviewed/2022/05/GHSA-8cpm-2q4p-34xp/GHSA-8cpm-2q4p-34xp.json @@ -7,12 +7,8 @@ "CVE-2005-3976" ], "details": "SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote attackers to execute arbitrary SQL commands via the iType parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8cx9-qhmg-8ch6/GHSA-8cx9-qhmg-8ch6.json b/advisories/unreviewed/2022/05/GHSA-8cx9-qhmg-8ch6/GHSA-8cx9-qhmg-8ch6.json index b912788e866..fe65d7bf7f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cx9-qhmg-8ch6/GHSA-8cx9-qhmg-8ch6.json +++ b/advisories/unreviewed/2022/05/GHSA-8cx9-qhmg-8ch6/GHSA-8cx9-qhmg-8ch6.json @@ -7,12 +7,8 @@ "CVE-2005-4370" ], "details": "SQL injection vulnerability in main_content.asp in Acidcat 2.1.13 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter to default.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8g95-97r6-4v76/GHSA-8g95-97r6-4v76.json b/advisories/unreviewed/2022/05/GHSA-8g95-97r6-4v76/GHSA-8g95-97r6-4v76.json index 795cc02508d..c213072fc5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g95-97r6-4v76/GHSA-8g95-97r6-4v76.json +++ b/advisories/unreviewed/2022/05/GHSA-8g95-97r6-4v76/GHSA-8g95-97r6-4v76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gj7-74p4-c853/GHSA-8gj7-74p4-c853.json b/advisories/unreviewed/2022/05/GHSA-8gj7-74p4-c853/GHSA-8gj7-74p4-c853.json index deab8ffbe7b..d52563dd400 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gj7-74p4-c853/GHSA-8gj7-74p4-c853.json +++ b/advisories/unreviewed/2022/05/GHSA-8gj7-74p4-c853/GHSA-8gj7-74p4-c853.json @@ -7,12 +7,8 @@ "CVE-2021-23042" ], "details": "On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, and 12.1.x before 12.1.6, when an HTTP profile is configured on a virtual server, undisclosed requests can cause a significant increase in system resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jf5-j23h-mq23/GHSA-8jf5-j23h-mq23.json b/advisories/unreviewed/2022/05/GHSA-8jf5-j23h-mq23/GHSA-8jf5-j23h-mq23.json index 5b82294f1cf..4bf85ba6623 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jf5-j23h-mq23/GHSA-8jf5-j23h-mq23.json +++ b/advisories/unreviewed/2022/05/GHSA-8jf5-j23h-mq23/GHSA-8jf5-j23h-mq23.json @@ -7,12 +7,8 @@ "CVE-2005-3978" ], "details": "Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c) ViewItem.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8jgx-w564-2r36/GHSA-8jgx-w564-2r36.json b/advisories/unreviewed/2022/05/GHSA-8jgx-w564-2r36/GHSA-8jgx-w564-2r36.json index 3a960ab8800..98b05b25f2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jgx-w564-2r36/GHSA-8jgx-w564-2r36.json +++ b/advisories/unreviewed/2022/05/GHSA-8jgx-w564-2r36/GHSA-8jgx-w564-2r36.json @@ -7,12 +7,8 @@ "CVE-2021-39497" ], "details": "eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jjw-549q-phxx/GHSA-8jjw-549q-phxx.json b/advisories/unreviewed/2022/05/GHSA-8jjw-549q-phxx/GHSA-8jjw-549q-phxx.json index 8617908c225..1c39a59ed43 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jjw-549q-phxx/GHSA-8jjw-549q-phxx.json +++ b/advisories/unreviewed/2022/05/GHSA-8jjw-549q-phxx/GHSA-8jjw-549q-phxx.json @@ -7,12 +7,8 @@ "CVE-2005-4364" ], "details": "Cross-site scripting (XSS) vulnerability in index.cfm in Hot Banana Web Content Management Suite 5.3 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8m2v-68m9-q2c7/GHSA-8m2v-68m9-q2c7.json b/advisories/unreviewed/2022/05/GHSA-8m2v-68m9-q2c7/GHSA-8m2v-68m9-q2c7.json index 1311ac0246a..073f1dc255a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m2v-68m9-q2c7/GHSA-8m2v-68m9-q2c7.json +++ b/advisories/unreviewed/2022/05/GHSA-8m2v-68m9-q2c7/GHSA-8m2v-68m9-q2c7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m2x-mm2c-xh64/GHSA-8m2x-mm2c-xh64.json b/advisories/unreviewed/2022/05/GHSA-8m2x-mm2c-xh64/GHSA-8m2x-mm2c-xh64.json index ca423a64418..1ce37c86b24 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m2x-mm2c-xh64/GHSA-8m2x-mm2c-xh64.json +++ b/advisories/unreviewed/2022/05/GHSA-8m2x-mm2c-xh64/GHSA-8m2x-mm2c-xh64.json @@ -7,12 +7,8 @@ "CVE-2005-3984" ], "details": "SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_report_handler.php. NOTE: the startid/activity_log.php vector is already covered by CVE-2005-3949.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m6j-xc56-ch65/GHSA-8m6j-xc56-ch65.json b/advisories/unreviewed/2022/05/GHSA-8m6j-xc56-ch65/GHSA-8m6j-xc56-ch65.json index 81469d18232..235bc661a8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m6j-xc56-ch65/GHSA-8m6j-xc56-ch65.json +++ b/advisories/unreviewed/2022/05/GHSA-8m6j-xc56-ch65/GHSA-8m6j-xc56-ch65.json @@ -7,12 +7,8 @@ "CVE-2005-4001" ], "details": "Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8p8h-5fcm-8gc4/GHSA-8p8h-5fcm-8gc4.json b/advisories/unreviewed/2022/05/GHSA-8p8h-5fcm-8gc4/GHSA-8p8h-5fcm-8gc4.json index ae45c61e259..dcd2a9053ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p8h-5fcm-8gc4/GHSA-8p8h-5fcm-8gc4.json +++ b/advisories/unreviewed/2022/05/GHSA-8p8h-5fcm-8gc4/GHSA-8p8h-5fcm-8gc4.json @@ -7,12 +7,8 @@ "CVE-2020-19853" ], "details": "BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p9p-333g-f2cc/GHSA-8p9p-333g-f2cc.json b/advisories/unreviewed/2022/05/GHSA-8p9p-333g-f2cc/GHSA-8p9p-333g-f2cc.json index bcc08c963d9..f40f927ce3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p9p-333g-f2cc/GHSA-8p9p-333g-f2cc.json +++ b/advisories/unreviewed/2022/05/GHSA-8p9p-333g-f2cc/GHSA-8p9p-333g-f2cc.json @@ -7,12 +7,8 @@ "CVE-2021-30623" ], "details": "Use after free in Bookmarks in Google Chrome prior to 93.0.4577.63 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pfj-wqp7-7x2c/GHSA-8pfj-wqp7-7x2c.json b/advisories/unreviewed/2022/05/GHSA-8pfj-wqp7-7x2c/GHSA-8pfj-wqp7-7x2c.json index 829c76aa640..254f85ea5a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pfj-wqp7-7x2c/GHSA-8pfj-wqp7-7x2c.json +++ b/advisories/unreviewed/2022/05/GHSA-8pfj-wqp7-7x2c/GHSA-8pfj-wqp7-7x2c.json @@ -7,12 +7,8 @@ "CVE-2021-30804" ], "details": "A permissions issue was addressed with improved validation. This issue is fixed in iOS 14.7. A malicious application may be able to access Find My data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8pqm-hrrp-373j/GHSA-8pqm-hrrp-373j.json b/advisories/unreviewed/2022/05/GHSA-8pqm-hrrp-373j/GHSA-8pqm-hrrp-373j.json index c1761122690..ee1309e4af1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pqm-hrrp-373j/GHSA-8pqm-hrrp-373j.json +++ b/advisories/unreviewed/2022/05/GHSA-8pqm-hrrp-373j/GHSA-8pqm-hrrp-373j.json @@ -7,12 +7,8 @@ "CVE-2021-1957" ], "details": "Improper Access Control when ACL link encryption is failed and ACL link is not disconnected during reconnection with paired device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8prr-wvvw-94gv/GHSA-8prr-wvvw-94gv.json b/advisories/unreviewed/2022/05/GHSA-8prr-wvvw-94gv/GHSA-8prr-wvvw-94gv.json index 368973a81d3..f82fd352849 100644 --- a/advisories/unreviewed/2022/05/GHSA-8prr-wvvw-94gv/GHSA-8prr-wvvw-94gv.json +++ b/advisories/unreviewed/2022/05/GHSA-8prr-wvvw-94gv/GHSA-8prr-wvvw-94gv.json @@ -7,12 +7,8 @@ "CVE-2021-23049" ], "details": "On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used on a virtual server, undisclosed requests can cause an increase in Traffic Management Microkernel (TMM) memory utilization resulting in an out-of-memory condition and a denial-of-service (DoS). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8prw-qcgj-xjrj/GHSA-8prw-qcgj-xjrj.json b/advisories/unreviewed/2022/05/GHSA-8prw-qcgj-xjrj/GHSA-8prw-qcgj-xjrj.json index f7231060a6a..8ca218cc7e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8prw-qcgj-xjrj/GHSA-8prw-qcgj-xjrj.json +++ b/advisories/unreviewed/2022/05/GHSA-8prw-qcgj-xjrj/GHSA-8prw-qcgj-xjrj.json @@ -7,12 +7,8 @@ "CVE-2005-4142" ], "details": "The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8qf8-7w4h-xrpc/GHSA-8qf8-7w4h-xrpc.json b/advisories/unreviewed/2022/05/GHSA-8qf8-7w4h-xrpc/GHSA-8qf8-7w4h-xrpc.json index 22e88068c40..f6b8b7f521f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qf8-7w4h-xrpc/GHSA-8qf8-7w4h-xrpc.json +++ b/advisories/unreviewed/2022/05/GHSA-8qf8-7w4h-xrpc/GHSA-8qf8-7w4h-xrpc.json @@ -7,12 +7,8 @@ "CVE-2020-7874" ], "details": "Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or file extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8r7w-7c78-x8mm/GHSA-8r7w-7c78-x8mm.json b/advisories/unreviewed/2022/05/GHSA-8r7w-7c78-x8mm/GHSA-8r7w-7c78-x8mm.json index d0be58b8aeb..68b68e91f55 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r7w-7c78-x8mm/GHSA-8r7w-7c78-x8mm.json +++ b/advisories/unreviewed/2022/05/GHSA-8r7w-7c78-x8mm/GHSA-8r7w-7c78-x8mm.json @@ -7,12 +7,8 @@ "CVE-2021-32484" ], "details": "In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964917.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8r83-7qrm-rvxc/GHSA-8r83-7qrm-rvxc.json b/advisories/unreviewed/2022/05/GHSA-8r83-7qrm-rvxc/GHSA-8r83-7qrm-rvxc.json index 48f72a5fd8b..2d18b767e4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r83-7qrm-rvxc/GHSA-8r83-7qrm-rvxc.json +++ b/advisories/unreviewed/2022/05/GHSA-8r83-7qrm-rvxc/GHSA-8r83-7qrm-rvxc.json @@ -7,12 +7,8 @@ "CVE-2005-4171" ], "details": "The \"Upload new image\" command in the \"Manage Images\" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8rmr-f55v-w9w6/GHSA-8rmr-f55v-w9w6.json b/advisories/unreviewed/2022/05/GHSA-8rmr-f55v-w9w6/GHSA-8rmr-f55v-w9w6.json index 1c460538123..46625101474 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rmr-f55v-w9w6/GHSA-8rmr-f55v-w9w6.json +++ b/advisories/unreviewed/2022/05/GHSA-8rmr-f55v-w9w6/GHSA-8rmr-f55v-w9w6.json @@ -7,12 +7,8 @@ "CVE-2021-30785" ], "details": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted image may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rxp-98h2-676c/GHSA-8rxp-98h2-676c.json b/advisories/unreviewed/2022/05/GHSA-8rxp-98h2-676c/GHSA-8rxp-98h2-676c.json index 8a72abbe6b8..775a1e262dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rxp-98h2-676c/GHSA-8rxp-98h2-676c.json +++ b/advisories/unreviewed/2022/05/GHSA-8rxp-98h2-676c/GHSA-8rxp-98h2-676c.json @@ -7,12 +7,8 @@ "CVE-2021-25457" ], "details": "An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8w4r-4r44-xw5g/GHSA-8w4r-4r44-xw5g.json b/advisories/unreviewed/2022/05/GHSA-8w4r-4r44-xw5g/GHSA-8w4r-4r44-xw5g.json index cb7933a81f3..9098f77c21c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w4r-4r44-xw5g/GHSA-8w4r-4r44-xw5g.json +++ b/advisories/unreviewed/2022/05/GHSA-8w4r-4r44-xw5g/GHSA-8w4r-4r44-xw5g.json @@ -7,12 +7,8 @@ "CVE-2005-4173" ], "details": "eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8w6h-27hq-jp76/GHSA-8w6h-27hq-jp76.json b/advisories/unreviewed/2022/05/GHSA-8w6h-27hq-jp76/GHSA-8w6h-27hq-jp76.json index 04e41d62f21..3e3a7799459 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w6h-27hq-jp76/GHSA-8w6h-27hq-jp76.json +++ b/advisories/unreviewed/2022/05/GHSA-8w6h-27hq-jp76/GHSA-8w6h-27hq-jp76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wjw-738x-7cm9/GHSA-8wjw-738x-7cm9.json b/advisories/unreviewed/2022/05/GHSA-8wjw-738x-7cm9/GHSA-8wjw-738x-7cm9.json index 82225196d34..35ace7ff114 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wjw-738x-7cm9/GHSA-8wjw-738x-7cm9.json +++ b/advisories/unreviewed/2022/05/GHSA-8wjw-738x-7cm9/GHSA-8wjw-738x-7cm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wp5-373j-qw7h/GHSA-8wp5-373j-qw7h.json b/advisories/unreviewed/2022/05/GHSA-8wp5-373j-qw7h/GHSA-8wp5-373j-qw7h.json index 636dc8ffe9a..2517c6b2fb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wp5-373j-qw7h/GHSA-8wp5-373j-qw7h.json +++ b/advisories/unreviewed/2022/05/GHSA-8wp5-373j-qw7h/GHSA-8wp5-373j-qw7h.json @@ -7,12 +7,8 @@ "CVE-2005-3973" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xjp-h5q2-g6vf/GHSA-8xjp-h5q2-g6vf.json b/advisories/unreviewed/2022/05/GHSA-8xjp-h5q2-g6vf/GHSA-8xjp-h5q2-g6vf.json index aca01ec480a..c0eca94ab7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xjp-h5q2-g6vf/GHSA-8xjp-h5q2-g6vf.json +++ b/advisories/unreviewed/2022/05/GHSA-8xjp-h5q2-g6vf/GHSA-8xjp-h5q2-g6vf.json @@ -7,12 +7,8 @@ "CVE-2005-4080" ], "details": "Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-92v9-v65f-f4q8/GHSA-92v9-v65f-f4q8.json b/advisories/unreviewed/2022/05/GHSA-92v9-v65f-f4q8/GHSA-92v9-v65f-f4q8.json index 336fbfa086e..da3d9bebe15 100644 --- a/advisories/unreviewed/2022/05/GHSA-92v9-v65f-f4q8/GHSA-92v9-v65f-f4q8.json +++ b/advisories/unreviewed/2022/05/GHSA-92v9-v65f-f4q8/GHSA-92v9-v65f-f4q8.json @@ -7,12 +7,8 @@ "CVE-2005-4174" ], "details": "eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-934q-gq37-gq89/GHSA-934q-gq37-gq89.json b/advisories/unreviewed/2022/05/GHSA-934q-gq37-gq89/GHSA-934q-gq37-gq89.json index c055fc7e0e7..43416baea9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-934q-gq37-gq89/GHSA-934q-gq37-gq89.json +++ b/advisories/unreviewed/2022/05/GHSA-934q-gq37-gq89/GHSA-934q-gq37-gq89.json @@ -7,12 +7,8 @@ "CVE-2021-30619" ], "details": "Inappropriate implementation in Autofill in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to spoof security UI via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9495-xp2q-c4gc/GHSA-9495-xp2q-c4gc.json b/advisories/unreviewed/2022/05/GHSA-9495-xp2q-c4gc/GHSA-9495-xp2q-c4gc.json index 99085a8fd49..f21253cc11a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9495-xp2q-c4gc/GHSA-9495-xp2q-c4gc.json +++ b/advisories/unreviewed/2022/05/GHSA-9495-xp2q-c4gc/GHSA-9495-xp2q-c4gc.json @@ -7,12 +7,8 @@ "CVE-2021-37716" ], "details": "A remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94c8-qvx9-76vq/GHSA-94c8-qvx9-76vq.json b/advisories/unreviewed/2022/05/GHSA-94c8-qvx9-76vq/GHSA-94c8-qvx9-76vq.json index 9224e0ebb5e..78123c475e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-94c8-qvx9-76vq/GHSA-94c8-qvx9-76vq.json +++ b/advisories/unreviewed/2022/05/GHSA-94c8-qvx9-76vq/GHSA-94c8-qvx9-76vq.json @@ -7,12 +7,8 @@ "CVE-2020-19855" ], "details": "phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94fg-6w87-3r57/GHSA-94fg-6w87-3r57.json b/advisories/unreviewed/2022/05/GHSA-94fg-6w87-3r57/GHSA-94fg-6w87-3r57.json index c54c6807d71..b8fe458b6cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-94fg-6w87-3r57/GHSA-94fg-6w87-3r57.json +++ b/advisories/unreviewed/2022/05/GHSA-94fg-6w87-3r57/GHSA-94fg-6w87-3r57.json @@ -7,12 +7,8 @@ "CVE-2021-1935" ], "details": "Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94mw-474q-fxh5/GHSA-94mw-474q-fxh5.json b/advisories/unreviewed/2022/05/GHSA-94mw-474q-fxh5/GHSA-94mw-474q-fxh5.json index 49340a3b6db..ab50ca52fa5 100644 --- a/advisories/unreviewed/2022/05/GHSA-94mw-474q-fxh5/GHSA-94mw-474q-fxh5.json +++ b/advisories/unreviewed/2022/05/GHSA-94mw-474q-fxh5/GHSA-94mw-474q-fxh5.json @@ -7,12 +7,8 @@ "CVE-2020-19768" ], "details": "A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from victim users via a crafted script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9568-6gjg-jgm8/GHSA-9568-6gjg-jgm8.json b/advisories/unreviewed/2022/05/GHSA-9568-6gjg-jgm8/GHSA-9568-6gjg-jgm8.json index 2dd1bdb68ef..40f288d332a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9568-6gjg-jgm8/GHSA-9568-6gjg-jgm8.json +++ b/advisories/unreviewed/2022/05/GHSA-9568-6gjg-jgm8/GHSA-9568-6gjg-jgm8.json @@ -7,12 +7,8 @@ "CVE-2005-4267" ], "details": "Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends with a \"}\" character, as demonstrated using long (1) LIST, (2) LSUB, (3) SEARCH TEXT, (4) STATUS INBOX, (5) AUTHENTICATE, (6) FETCH, (7) SELECT, and (8) COPY commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95h4-prgr-h453/GHSA-95h4-prgr-h453.json b/advisories/unreviewed/2022/05/GHSA-95h4-prgr-h453/GHSA-95h4-prgr-h453.json index 866358b1f96..130e4e1e132 100644 --- a/advisories/unreviewed/2022/05/GHSA-95h4-prgr-h453/GHSA-95h4-prgr-h453.json +++ b/advisories/unreviewed/2022/05/GHSA-95h4-prgr-h453/GHSA-95h4-prgr-h453.json @@ -7,12 +7,8 @@ "CVE-2005-4234" ], "details": "SQL injection vulnerability in gallery.php in EncapsGallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-964m-f4fc-h2mf/GHSA-964m-f4fc-h2mf.json b/advisories/unreviewed/2022/05/GHSA-964m-f4fc-h2mf/GHSA-964m-f4fc-h2mf.json index c7d6badfdf4..61201522bc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-964m-f4fc-h2mf/GHSA-964m-f4fc-h2mf.json +++ b/advisories/unreviewed/2022/05/GHSA-964m-f4fc-h2mf/GHSA-964m-f4fc-h2mf.json @@ -7,12 +7,8 @@ "CVE-2021-30766" ], "details": "An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-973q-jf8v-6q77/GHSA-973q-jf8v-6q77.json b/advisories/unreviewed/2022/05/GHSA-973q-jf8v-6q77/GHSA-973q-jf8v-6q77.json index 22ac7bb1709..c41c251dbba 100644 --- a/advisories/unreviewed/2022/05/GHSA-973q-jf8v-6q77/GHSA-973q-jf8v-6q77.json +++ b/advisories/unreviewed/2022/05/GHSA-973q-jf8v-6q77/GHSA-973q-jf8v-6q77.json @@ -7,12 +7,8 @@ "CVE-2021-1858" ], "details": "Processing a maliciously crafted image may lead to arbitrary code execution. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An out-of-bounds write issue was addressed with improved bounds checking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9757-c955-9qqg/GHSA-9757-c955-9qqg.json b/advisories/unreviewed/2022/05/GHSA-9757-c955-9qqg/GHSA-9757-c955-9qqg.json index 1753a6f11be..8183ca98b68 100644 --- a/advisories/unreviewed/2022/05/GHSA-9757-c955-9qqg/GHSA-9757-c955-9qqg.json +++ b/advisories/unreviewed/2022/05/GHSA-9757-c955-9qqg/GHSA-9757-c955-9qqg.json @@ -7,12 +7,8 @@ "CVE-2005-3987" ], "details": "Multiple SQL injection vulnerabilities in Tradesoft CMS allow remote attackers to execute arbitrary SQL commands via unspecified attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-97m8-rj8m-hvm2/GHSA-97m8-rj8m-hvm2.json b/advisories/unreviewed/2022/05/GHSA-97m8-rj8m-hvm2/GHSA-97m8-rj8m-hvm2.json index 68a41ba079f..2c15420befb 100644 --- a/advisories/unreviewed/2022/05/GHSA-97m8-rj8m-hvm2/GHSA-97m8-rj8m-hvm2.json +++ b/advisories/unreviewed/2022/05/GHSA-97m8-rj8m-hvm2/GHSA-97m8-rj8m-hvm2.json @@ -7,12 +7,8 @@ "CVE-2005-4227" ], "details": "Multiple \"potential\" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_member_id, year, agid, day, day_s, hour, minute, month, month_s, and year_s parameters in calendar.php, (4) the cid parameter in contents.php, (5) the dcp5_member_id parameter in forums.php, (6) the bid parameter in go.php, (7) the lid parameter in golink.php, (8) the dcp5_member_id and mid parameters in inbox.php, (9) the catid, dcat, and dl parameters in index.php, (10) the dcp5_member_id in informer.php, (11) the nid parameter in news.php, (12) the type and rate parameters in rate.php, (13) the q parameter in search.php, and (14) the dcp5_member_id in update.php. NOTE: other vectors in the PHP-CHECKER report are also covered by CVE-2005-3365 and CVE-2005-0454.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-98jw-m4q8-f849/GHSA-98jw-m4q8-f849.json b/advisories/unreviewed/2022/05/GHSA-98jw-m4q8-f849/GHSA-98jw-m4q8-f849.json index 0b063354964..aa62998c85c 100644 --- a/advisories/unreviewed/2022/05/GHSA-98jw-m4q8-f849/GHSA-98jw-m4q8-f849.json +++ b/advisories/unreviewed/2022/05/GHSA-98jw-m4q8-f849/GHSA-98jw-m4q8-f849.json @@ -7,12 +7,8 @@ "CVE-2021-37203" ], "details": "A vulnerability has been identified in NX 1980 Series (All versions < V1984). The plmxmlAdapterIFC.dll contains an out-of-bounds read while parsing user supplied IFC files which could result in a read past the end of an allocated buffer. This could allow an attacker to cause a denial-of-service condition or read sensitive information from memory locations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c9h-855r-9r5v/GHSA-9c9h-855r-9r5v.json b/advisories/unreviewed/2022/05/GHSA-9c9h-855r-9r5v/GHSA-9c9h-855r-9r5v.json index e4e9c179b99..ab264f9edb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c9h-855r-9r5v/GHSA-9c9h-855r-9r5v.json +++ b/advisories/unreviewed/2022/05/GHSA-9c9h-855r-9r5v/GHSA-9c9h-855r-9r5v.json @@ -7,12 +7,8 @@ "CVE-2005-3940" ], "details": "SQL injection vulnerability in ringmaker.php in Orca Ringmaker 2.3c and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9cjg-xfcq-56f3/GHSA-9cjg-xfcq-56f3.json b/advisories/unreviewed/2022/05/GHSA-9cjg-xfcq-56f3/GHSA-9cjg-xfcq-56f3.json index 7d38293c365..f80d0ac82db 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cjg-xfcq-56f3/GHSA-9cjg-xfcq-56f3.json +++ b/advisories/unreviewed/2022/05/GHSA-9cjg-xfcq-56f3/GHSA-9cjg-xfcq-56f3.json @@ -7,12 +7,8 @@ "CVE-2021-30750" ], "details": "The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the user's recent contacts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f5g-mr9p-4fxc/GHSA-9f5g-mr9p-4fxc.json b/advisories/unreviewed/2022/05/GHSA-9f5g-mr9p-4fxc/GHSA-9f5g-mr9p-4fxc.json index c85873a9e86..afd342a0ac7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f5g-mr9p-4fxc/GHSA-9f5g-mr9p-4fxc.json +++ b/advisories/unreviewed/2022/05/GHSA-9f5g-mr9p-4fxc/GHSA-9f5g-mr9p-4fxc.json @@ -7,12 +7,8 @@ "CVE-2021-23043" ], "details": "On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to access arbitrary files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9fpm-9892-q4hp/GHSA-9fpm-9892-q4hp.json b/advisories/unreviewed/2022/05/GHSA-9fpm-9892-q4hp/GHSA-9fpm-9892-q4hp.json index d43a31e5eff..c21220baf25 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fpm-9892-q4hp/GHSA-9fpm-9892-q4hp.json +++ b/advisories/unreviewed/2022/05/GHSA-9fpm-9892-q4hp/GHSA-9fpm-9892-q4hp.json @@ -7,12 +7,8 @@ "CVE-2005-4144" ], "details": "Lyris ListManager 5.0 through 8.9a allows remote attackers to add \"ORDER BY\" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9g47-2766-9622/GHSA-9g47-2766-9622.json b/advisories/unreviewed/2022/05/GHSA-9g47-2766-9622/GHSA-9g47-2766-9622.json index 9d83b67bb84..55eb658ac6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g47-2766-9622/GHSA-9g47-2766-9622.json +++ b/advisories/unreviewed/2022/05/GHSA-9g47-2766-9622/GHSA-9g47-2766-9622.json @@ -7,12 +7,8 @@ "CVE-2021-28555" ], "details": "Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to sensitive information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g77-h7cv-5vp5/GHSA-9g77-h7cv-5vp5.json b/advisories/unreviewed/2022/05/GHSA-9g77-h7cv-5vp5/GHSA-9g77-h7cv-5vp5.json index ec78974befc..0483980baa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g77-h7cv-5vp5/GHSA-9g77-h7cv-5vp5.json +++ b/advisories/unreviewed/2022/05/GHSA-9g77-h7cv-5vp5/GHSA-9g77-h7cv-5vp5.json @@ -7,12 +7,8 @@ "CVE-2005-4081" ], "details": "Multiple SQL injection vulnerabilities in Alisveristr E-commerce allow remote attackers to bypass authentication and possibly execute arbitrary SQL commands via the username and password parameters in (1) the user login and (2) administrator login pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9gjf-xc3f-w2j8/GHSA-9gjf-xc3f-w2j8.json b/advisories/unreviewed/2022/05/GHSA-9gjf-xc3f-w2j8/GHSA-9gjf-xc3f-w2j8.json index 4a61057be26..0e2618c5954 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gjf-xc3f-w2j8/GHSA-9gjf-xc3f-w2j8.json +++ b/advisories/unreviewed/2022/05/GHSA-9gjf-xc3f-w2j8/GHSA-9gjf-xc3f-w2j8.json @@ -7,12 +7,8 @@ "CVE-2021-35946" ], "details": "A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate their own permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9h5x-7fqr-xqgx/GHSA-9h5x-7fqr-xqgx.json b/advisories/unreviewed/2022/05/GHSA-9h5x-7fqr-xqgx/GHSA-9h5x-7fqr-xqgx.json index 66a9014d928..095867e077c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h5x-7fqr-xqgx/GHSA-9h5x-7fqr-xqgx.json +++ b/advisories/unreviewed/2022/05/GHSA-9h5x-7fqr-xqgx/GHSA-9h5x-7fqr-xqgx.json @@ -7,12 +7,8 @@ "CVE-2021-1878" ], "details": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. An attacker in a privileged network position may be able to leak sensitive user information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hc5-m4g5-3m3c/GHSA-9hc5-m4g5-3m3c.json b/advisories/unreviewed/2022/05/GHSA-9hc5-m4g5-3m3c/GHSA-9hc5-m4g5-3m3c.json index a4b57fb3d1b..1e7a972a72e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hc5-m4g5-3m3c/GHSA-9hc5-m4g5-3m3c.json +++ b/advisories/unreviewed/2022/05/GHSA-9hc5-m4g5-3m3c/GHSA-9hc5-m4g5-3m3c.json @@ -7,12 +7,8 @@ "CVE-2021-1740" ], "details": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j28-crwr-wvfx/GHSA-9j28-crwr-wvfx.json b/advisories/unreviewed/2022/05/GHSA-9j28-crwr-wvfx/GHSA-9j28-crwr-wvfx.json index e55a6f65806..60bd199bb0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j28-crwr-wvfx/GHSA-9j28-crwr-wvfx.json +++ b/advisories/unreviewed/2022/05/GHSA-9j28-crwr-wvfx/GHSA-9j28-crwr-wvfx.json @@ -7,12 +7,8 @@ "CVE-2021-1872" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. Muting a CallKit call while ringing may not result in mute being enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9j7c-3668-hr3c/GHSA-9j7c-3668-hr3c.json b/advisories/unreviewed/2022/05/GHSA-9j7c-3668-hr3c/GHSA-9j7c-3668-hr3c.json index 18610a7a41a..3cc67d847e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j7c-3668-hr3c/GHSA-9j7c-3668-hr3c.json +++ b/advisories/unreviewed/2022/05/GHSA-9j7c-3668-hr3c/GHSA-9j7c-3668-hr3c.json @@ -7,12 +7,8 @@ "CVE-2021-34718" ], "details": "A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vulnerability is due to insufficient input validation of arguments that are supplied by the user for a specific file transfer method. An attacker with lower-level privileges could exploit this vulnerability by specifying Secure Copy Protocol (SCP) parameters when authenticating to a device. A successful exploit could allow the attacker to elevate their privileges and retrieve and upload files on a device that they should not have access to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jhc-m2f9-xm2h/GHSA-9jhc-m2f9-xm2h.json b/advisories/unreviewed/2022/05/GHSA-9jhc-m2f9-xm2h/GHSA-9jhc-m2f9-xm2h.json index 86059cfbf77..b1e663d10af 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jhc-m2f9-xm2h/GHSA-9jhc-m2f9-xm2h.json +++ b/advisories/unreviewed/2022/05/GHSA-9jhc-m2f9-xm2h/GHSA-9jhc-m2f9-xm2h.json @@ -7,12 +7,8 @@ "CVE-2021-25455" ], "details": "OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jrp-h5gv-236v/GHSA-9jrp-h5gv-236v.json b/advisories/unreviewed/2022/05/GHSA-9jrp-h5gv-236v/GHSA-9jrp-h5gv-236v.json index cb2900d5873..e0f3d208bf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jrp-h5gv-236v/GHSA-9jrp-h5gv-236v.json +++ b/advisories/unreviewed/2022/05/GHSA-9jrp-h5gv-236v/GHSA-9jrp-h5gv-236v.json @@ -7,12 +7,8 @@ "CVE-2005-4270" ], "details": "Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9jxx-wv7p-h3g3/GHSA-9jxx-wv7p-h3g3.json b/advisories/unreviewed/2022/05/GHSA-9jxx-wv7p-h3g3/GHSA-9jxx-wv7p-h3g3.json index 14183b91b6b..938d63966fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jxx-wv7p-h3g3/GHSA-9jxx-wv7p-h3g3.json +++ b/advisories/unreviewed/2022/05/GHSA-9jxx-wv7p-h3g3/GHSA-9jxx-wv7p-h3g3.json @@ -7,12 +7,8 @@ "CVE-2005-4319" ], "details": "Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbitrary PHP files via \"..\" sequences in the option parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mm7-wpqg-qhvm/GHSA-9mm7-wpqg-qhvm.json b/advisories/unreviewed/2022/05/GHSA-9mm7-wpqg-qhvm/GHSA-9mm7-wpqg-qhvm.json index cc60e6239d3..078bb72be40 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mm7-wpqg-qhvm/GHSA-9mm7-wpqg-qhvm.json +++ b/advisories/unreviewed/2022/05/GHSA-9mm7-wpqg-qhvm/GHSA-9mm7-wpqg-qhvm.json @@ -7,12 +7,8 @@ "CVE-2005-4036" ], "details": "Cross-site scripting (XSS) vulnerability in index.cgi in Web4Future KeyWord Frequency Counter 1.0 allows remote attackers to inject arbitrary web script or HTML via the \"remote URL.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9p38-r99r-g3mg/GHSA-9p38-r99r-g3mg.json b/advisories/unreviewed/2022/05/GHSA-9p38-r99r-g3mg/GHSA-9p38-r99r-g3mg.json index c923117dae0..7828600d3e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p38-r99r-g3mg/GHSA-9p38-r99r-g3mg.json +++ b/advisories/unreviewed/2022/05/GHSA-9p38-r99r-g3mg/GHSA-9p38-r99r-g3mg.json @@ -7,12 +7,8 @@ "CVE-2005-4037" ], "details": "SQL injection vulnerability in functions.php in Web4Future Affiliate Manager PRO 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9p84-3w48-p6j6/GHSA-9p84-3w48-p6j6.json b/advisories/unreviewed/2022/05/GHSA-9p84-3w48-p6j6/GHSA-9p84-3w48-p6j6.json index fd2f7376d8e..90ea08c3681 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p84-3w48-p6j6/GHSA-9p84-3w48-p6j6.json +++ b/advisories/unreviewed/2022/05/GHSA-9p84-3w48-p6j6/GHSA-9p84-3w48-p6j6.json @@ -7,12 +7,8 @@ "CVE-2021-34733" ], "details": "A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive information is not sufficiently secured when it is stored. An attacker could exploit this vulnerability by gaining unauthorized access to sensitive information on an affected system. A successful exploit could allow the attacker to create forged authentication requests and gain unauthorized access to the affected system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p9w-m487-54jr/GHSA-9p9w-m487-54jr.json b/advisories/unreviewed/2022/05/GHSA-9p9w-m487-54jr/GHSA-9p9w-m487-54jr.json index c9883605624..7d45ca84b20 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p9w-m487-54jr/GHSA-9p9w-m487-54jr.json +++ b/advisories/unreviewed/2022/05/GHSA-9p9w-m487-54jr/GHSA-9p9w-m487-54jr.json @@ -7,12 +7,8 @@ "CVE-2005-4020" ], "details": "SQL injection vulnerability in create.php in Widget Imprint 1.0.26 and earlier allows remote attackers to execute arbitrary SQL commands via the product_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pcf-jg3j-pw83/GHSA-9pcf-jg3j-pw83.json b/advisories/unreviewed/2022/05/GHSA-9pcf-jg3j-pw83/GHSA-9pcf-jg3j-pw83.json index 79246f8692f..3648f561ef1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pcf-jg3j-pw83/GHSA-9pcf-jg3j-pw83.json +++ b/advisories/unreviewed/2022/05/GHSA-9pcf-jg3j-pw83/GHSA-9pcf-jg3j-pw83.json @@ -7,12 +7,8 @@ "CVE-2021-30616" ], "details": "Use after free in Media in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9ph4-xhrv-3pgx/GHSA-9ph4-xhrv-3pgx.json b/advisories/unreviewed/2022/05/GHSA-9ph4-xhrv-3pgx/GHSA-9ph4-xhrv-3pgx.json index 13bfa7e2c45..71b768334b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9ph4-xhrv-3pgx/GHSA-9ph4-xhrv-3pgx.json +++ b/advisories/unreviewed/2022/05/GHSA-9ph4-xhrv-3pgx/GHSA-9ph4-xhrv-3pgx.json @@ -7,12 +7,8 @@ "CVE-2005-4088" ], "details": "SQL injection vulnerability in index.php in phpForumPro 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) parent and (2) day parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9pxh-q2v6-xvg6/GHSA-9pxh-q2v6-xvg6.json b/advisories/unreviewed/2022/05/GHSA-9pxh-q2v6-xvg6/GHSA-9pxh-q2v6-xvg6.json index 68e82b214cc..352e452585e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pxh-q2v6-xvg6/GHSA-9pxh-q2v6-xvg6.json +++ b/advisories/unreviewed/2022/05/GHSA-9pxh-q2v6-xvg6/GHSA-9pxh-q2v6-xvg6.json @@ -7,12 +7,8 @@ "CVE-2005-4168" ], "details": "Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9q55-3953-mqgf/GHSA-9q55-3953-mqgf.json b/advisories/unreviewed/2022/05/GHSA-9q55-3953-mqgf/GHSA-9q55-3953-mqgf.json index d322f1c288f..f3f9432cff8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q55-3953-mqgf/GHSA-9q55-3953-mqgf.json +++ b/advisories/unreviewed/2022/05/GHSA-9q55-3953-mqgf/GHSA-9q55-3953-mqgf.json @@ -7,12 +7,8 @@ "CVE-2021-37535" ], "details": "SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qwh-mr4w-j7m3/GHSA-9qwh-mr4w-j7m3.json b/advisories/unreviewed/2022/05/GHSA-9qwh-mr4w-j7m3/GHSA-9qwh-mr4w-j7m3.json index 834753f7f45..7d2e86674ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qwh-mr4w-j7m3/GHSA-9qwh-mr4w-j7m3.json +++ b/advisories/unreviewed/2022/05/GHSA-9qwh-mr4w-j7m3/GHSA-9qwh-mr4w-j7m3.json @@ -7,12 +7,8 @@ "CVE-2005-4371" ], "details": "Acidcat 2.1.13 and earlier stores the database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a request to databases/acidcat.mdb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r24-f9qq-w8p5/GHSA-9r24-f9qq-w8p5.json b/advisories/unreviewed/2022/05/GHSA-9r24-f9qq-w8p5/GHSA-9r24-f9qq-w8p5.json index 51fde3c5ccf..186aa7314dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r24-f9qq-w8p5/GHSA-9r24-f9qq-w8p5.json +++ b/advisories/unreviewed/2022/05/GHSA-9r24-f9qq-w8p5/GHSA-9r24-f9qq-w8p5.json @@ -7,12 +7,8 @@ "CVE-2021-34721" ], "details": "Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r8f-8mgm-rgr6/GHSA-9r8f-8mgm-rgr6.json b/advisories/unreviewed/2022/05/GHSA-9r8f-8mgm-rgr6/GHSA-9r8f-8mgm-rgr6.json index 065b94ed027..fbd86130da0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r8f-8mgm-rgr6/GHSA-9r8f-8mgm-rgr6.json +++ b/advisories/unreviewed/2022/05/GHSA-9r8f-8mgm-rgr6/GHSA-9r8f-8mgm-rgr6.json @@ -7,12 +7,8 @@ "CVE-2005-4191" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist's name or (2) description, when creating a new tasklist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r9m-3jrr-2qqp/GHSA-9r9m-3jrr-2qqp.json b/advisories/unreviewed/2022/05/GHSA-9r9m-3jrr-2qqp/GHSA-9r9m-3jrr-2qqp.json index 6198a8ef7d3..5f99798bfc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r9m-3jrr-2qqp/GHSA-9r9m-3jrr-2qqp.json +++ b/advisories/unreviewed/2022/05/GHSA-9r9m-3jrr-2qqp/GHSA-9r9m-3jrr-2qqp.json @@ -7,12 +7,8 @@ "CVE-2005-4377" ], "details": "Cross-site scripting (XSS) vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) PageID and (2) SiteNodeID parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rpc-7358-gg7j/GHSA-9rpc-7358-gg7j.json b/advisories/unreviewed/2022/05/GHSA-9rpc-7358-gg7j/GHSA-9rpc-7358-gg7j.json index 5ae6ba30b55..1bbf70d9415 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rpc-7358-gg7j/GHSA-9rpc-7358-gg7j.json +++ b/advisories/unreviewed/2022/05/GHSA-9rpc-7358-gg7j/GHSA-9rpc-7358-gg7j.json @@ -7,12 +7,8 @@ "CVE-2005-4389" ], "details": "search.cfm in CONTENS 3.0 and earlier allows remote attackers to obtain the full server path via invalid (1) submit.y, (2) bool, (3) itemsperpage, (4) submit, (5) submit.x, (6) criteria, (7) advanced, and (8) intern parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rqj-h33r-qgm8/GHSA-9rqj-h33r-qgm8.json b/advisories/unreviewed/2022/05/GHSA-9rqj-h33r-qgm8/GHSA-9rqj-h33r-qgm8.json index fb3882466f7..62031851e5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rqj-h33r-qgm8/GHSA-9rqj-h33r-qgm8.json +++ b/advisories/unreviewed/2022/05/GHSA-9rqj-h33r-qgm8/GHSA-9rqj-h33r-qgm8.json @@ -7,12 +7,8 @@ "CVE-2021-40523" ], "details": "In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to give the WILL/WONT or DO/DONT response for DO and WILL commands because of improper handling of exception condition, which leads to property violations and denial of service. Specifically, a server sometimes sends no response, because a fixed buffer space is available for all responses and that space may have been exhausted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rvf-pr75-p78c/GHSA-9rvf-pr75-p78c.json b/advisories/unreviewed/2022/05/GHSA-9rvf-pr75-p78c/GHSA-9rvf-pr75-p78c.json index 4ab15dabd2d..0da7093585b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rvf-pr75-p78c/GHSA-9rvf-pr75-p78c.json +++ b/advisories/unreviewed/2022/05/GHSA-9rvf-pr75-p78c/GHSA-9rvf-pr75-p78c.json @@ -7,12 +7,8 @@ "CVE-2021-1874" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9v6p-vgp6-gj4x/GHSA-9v6p-vgp6-gj4x.json b/advisories/unreviewed/2022/05/GHSA-9v6p-vgp6-gj4x/GHSA-9v6p-vgp6-gj4x.json index 462cad2bb3f..34dcf0423de 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v6p-vgp6-gj4x/GHSA-9v6p-vgp6-gj4x.json +++ b/advisories/unreviewed/2022/05/GHSA-9v6p-vgp6-gj4x/GHSA-9v6p-vgp6-gj4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vpc-3ghg-r29c/GHSA-9vpc-3ghg-r29c.json b/advisories/unreviewed/2022/05/GHSA-9vpc-3ghg-r29c/GHSA-9vpc-3ghg-r29c.json index b25cbf9f68a..f10c224640a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vpc-3ghg-r29c/GHSA-9vpc-3ghg-r29c.json +++ b/advisories/unreviewed/2022/05/GHSA-9vpc-3ghg-r29c/GHSA-9vpc-3ghg-r29c.json @@ -7,12 +7,8 @@ "CVE-2005-4086" ], "details": "Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to include arbitrary local files via \"..\" sequences in the beanFiles array parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9w4g-4569-rg67/GHSA-9w4g-4569-rg67.json b/advisories/unreviewed/2022/05/GHSA-9w4g-4569-rg67/GHSA-9w4g-4569-rg67.json index 50db3a8c20d..3c5fadf00be 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w4g-4569-rg67/GHSA-9w4g-4569-rg67.json +++ b/advisories/unreviewed/2022/05/GHSA-9w4g-4569-rg67/GHSA-9w4g-4569-rg67.json @@ -7,12 +7,8 @@ "CVE-2005-4253" ], "details": "Cross-site scripting (XSS) vulnerability in getdox.php in Torrential 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL. NOTE: this might be resultant from CVE-2005-4160.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9x54-gxfh-qxvm/GHSA-9x54-gxfh-qxvm.json b/advisories/unreviewed/2022/05/GHSA-9x54-gxfh-qxvm/GHSA-9x54-gxfh-qxvm.json index 44ebf40499d..ba451746df6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x54-gxfh-qxvm/GHSA-9x54-gxfh-qxvm.json +++ b/advisories/unreviewed/2022/05/GHSA-9x54-gxfh-qxvm/GHSA-9x54-gxfh-qxvm.json @@ -7,12 +7,8 @@ "CVE-2021-30779" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing a maliciously crafted image may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xgw-72w6-j5wc/GHSA-9xgw-72w6-j5wc.json b/advisories/unreviewed/2022/05/GHSA-9xgw-72w6-j5wc/GHSA-9xgw-72w6-j5wc.json index 68b179256a8..7f9d5a8ddd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xgw-72w6-j5wc/GHSA-9xgw-72w6-j5wc.json +++ b/advisories/unreviewed/2022/05/GHSA-9xgw-72w6-j5wc/GHSA-9xgw-72w6-j5wc.json @@ -7,12 +7,8 @@ "CVE-2005-4336" ], "details": "Cross-site scripting (XSS) vulnerability in ProjectForum 4.7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) fwd parameter in admin/adminsignin.html and (2) originalpageid parameter in admin/newpage.html associated with a group.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xx5-rr5h-pjg2/GHSA-9xx5-rr5h-pjg2.json b/advisories/unreviewed/2022/05/GHSA-9xx5-rr5h-pjg2/GHSA-9xx5-rr5h-pjg2.json index ea4f044c977..c3df00000e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xx5-rr5h-pjg2/GHSA-9xx5-rr5h-pjg2.json +++ b/advisories/unreviewed/2022/05/GHSA-9xx5-rr5h-pjg2/GHSA-9xx5-rr5h-pjg2.json @@ -7,12 +7,8 @@ "CVE-2005-4317" ], "details": "Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, which allows remote attackers to use the _SERVER[REMOTE_ADDR] parameter to (1) conduct cross-site scripting (XSS) attacks in the stats module or (2) execute arbitrary code via an eval injection attack in the wrapper option in index2.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c243-364q-9gwf/GHSA-c243-364q-9gwf.json b/advisories/unreviewed/2022/05/GHSA-c243-364q-9gwf/GHSA-c243-364q-9gwf.json index 67183d05dc2..bf8b5224831 100644 --- a/advisories/unreviewed/2022/05/GHSA-c243-364q-9gwf/GHSA-c243-364q-9gwf.json +++ b/advisories/unreviewed/2022/05/GHSA-c243-364q-9gwf/GHSA-c243-364q-9gwf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c354-v653-2qqr/GHSA-c354-v653-2qqr.json b/advisories/unreviewed/2022/05/GHSA-c354-v653-2qqr/GHSA-c354-v653-2qqr.json index a43e388153f..cef2940206b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c354-v653-2qqr/GHSA-c354-v653-2qqr.json +++ b/advisories/unreviewed/2022/05/GHSA-c354-v653-2qqr/GHSA-c354-v653-2qqr.json @@ -7,12 +7,8 @@ "CVE-2005-3946" ], "details": "Opera 8.50 allows remote attackers to cause a denial of service (crash) via a Java applet with a large string argument to the removeMember JNI method for the com.opera.JSObject class.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3m7-gw6j-3wx2/GHSA-c3m7-gw6j-3wx2.json b/advisories/unreviewed/2022/05/GHSA-c3m7-gw6j-3wx2/GHSA-c3m7-gw6j-3wx2.json index 61c1154ab6f..b6b0e7fe8ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3m7-gw6j-3wx2/GHSA-c3m7-gw6j-3wx2.json +++ b/advisories/unreviewed/2022/05/GHSA-c3m7-gw6j-3wx2/GHSA-c3m7-gw6j-3wx2.json @@ -7,12 +7,8 @@ "CVE-2021-24591" ], "details": "The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3w4-9cvr-8v4j/GHSA-c3w4-9cvr-8v4j.json b/advisories/unreviewed/2022/05/GHSA-c3w4-9cvr-8v4j/GHSA-c3w4-9cvr-8v4j.json index 8b45dd68069..42707d60905 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3w4-9cvr-8v4j/GHSA-c3w4-9cvr-8v4j.json +++ b/advisories/unreviewed/2022/05/GHSA-c3w4-9cvr-8v4j/GHSA-c3w4-9cvr-8v4j.json @@ -7,12 +7,8 @@ "CVE-2005-3960" ], "details": "Kadu 0.4.2 and 0.5.0pre allows remote attackers to cause a denial of service (crash or generated traffic) via a malformed message, possibly with incomplete information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c497-q93h-cf8j/GHSA-c497-q93h-cf8j.json b/advisories/unreviewed/2022/05/GHSA-c497-q93h-cf8j/GHSA-c497-q93h-cf8j.json index 76a2b4cfd9b..3561a88ad21 100644 --- a/advisories/unreviewed/2022/05/GHSA-c497-q93h-cf8j/GHSA-c497-q93h-cf8j.json +++ b/advisories/unreviewed/2022/05/GHSA-c497-q93h-cf8j/GHSA-c497-q93h-cf8j.json @@ -7,12 +7,8 @@ "CVE-2021-37414" ], "details": "Zoho ManageEngine DesktopCentral version 10.1.2119.7 and prior allows anyone to get a valid user's APIKEY without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c4rm-hpgr-mj62/GHSA-c4rm-hpgr-mj62.json b/advisories/unreviewed/2022/05/GHSA-c4rm-hpgr-mj62/GHSA-c4rm-hpgr-mj62.json index 1111231c8eb..a660d3227ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4rm-hpgr-mj62/GHSA-c4rm-hpgr-mj62.json +++ b/advisories/unreviewed/2022/05/GHSA-c4rm-hpgr-mj62/GHSA-c4rm-hpgr-mj62.json @@ -7,12 +7,8 @@ "CVE-2005-4175" ], "details": "Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c56p-qjh9-5gqm/GHSA-c56p-qjh9-5gqm.json b/advisories/unreviewed/2022/05/GHSA-c56p-qjh9-5gqm/GHSA-c56p-qjh9-5gqm.json index 66169dc8f7a..8312c339383 100644 --- a/advisories/unreviewed/2022/05/GHSA-c56p-qjh9-5gqm/GHSA-c56p-qjh9-5gqm.json +++ b/advisories/unreviewed/2022/05/GHSA-c56p-qjh9-5gqm/GHSA-c56p-qjh9-5gqm.json @@ -7,12 +7,8 @@ "CVE-2021-30710" ], "details": "A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may cause a denial of service or potentially disclose memory contents.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5mf-3x7w-27g9/GHSA-c5mf-3x7w-27g9.json b/advisories/unreviewed/2022/05/GHSA-c5mf-3x7w-27g9/GHSA-c5mf-3x7w-27g9.json index 978b3890e18..9848851af1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5mf-3x7w-27g9/GHSA-c5mf-3x7w-27g9.json +++ b/advisories/unreviewed/2022/05/GHSA-c5mf-3x7w-27g9/GHSA-c5mf-3x7w-27g9.json @@ -7,12 +7,8 @@ "CVE-2005-4347" ], "details": "The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the \"chroot barrier\" with util-vserver, which allows attackers to access files on the host system that are outside of the vserver.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5r6-553p-7qm8/GHSA-c5r6-553p-7qm8.json b/advisories/unreviewed/2022/05/GHSA-c5r6-553p-7qm8/GHSA-c5r6-553p-7qm8.json index 3dd251d3739..b1560c60eb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5r6-553p-7qm8/GHSA-c5r6-553p-7qm8.json +++ b/advisories/unreviewed/2022/05/GHSA-c5r6-553p-7qm8/GHSA-c5r6-553p-7qm8.json @@ -7,12 +7,8 @@ "CVE-2021-30791" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted file may disclose user information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7pc-2qhp-jgch/GHSA-c7pc-2qhp-jgch.json b/advisories/unreviewed/2022/05/GHSA-c7pc-2qhp-jgch/GHSA-c7pc-2qhp-jgch.json index 41018511a2f..4e30bfbbda5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7pc-2qhp-jgch/GHSA-c7pc-2qhp-jgch.json +++ b/advisories/unreviewed/2022/05/GHSA-c7pc-2qhp-jgch/GHSA-c7pc-2qhp-jgch.json @@ -7,12 +7,8 @@ "CVE-2005-4392" ], "details": "SQL injection vulnerability in printer_friendly.cfm in e-publish CMS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c8f9-q937-86mv/GHSA-c8f9-q937-86mv.json b/advisories/unreviewed/2022/05/GHSA-c8f9-q937-86mv/GHSA-c8f9-q937-86mv.json index 6c738e9ba65..f9b06d19358 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8f9-q937-86mv/GHSA-c8f9-q937-86mv.json +++ b/advisories/unreviewed/2022/05/GHSA-c8f9-q937-86mv/GHSA-c8f9-q937-86mv.json @@ -7,12 +7,8 @@ "CVE-2005-3923" ], "details": "NetObjects Fusion 9 (NOF9) allows remote attackers to obtain sensitive information, including passwords, by downloading the _versioning_repository_/rollbacklog.xml file, then using it to download and modify the associated ZIP file to edit and republish the site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c8x2-fgvf-cxj9/GHSA-c8x2-fgvf-cxj9.json b/advisories/unreviewed/2022/05/GHSA-c8x2-fgvf-cxj9/GHSA-c8x2-fgvf-cxj9.json index 454ae737ae5..2d82bb8b57f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8x2-fgvf-cxj9/GHSA-c8x2-fgvf-cxj9.json +++ b/advisories/unreviewed/2022/05/GHSA-c8x2-fgvf-cxj9/GHSA-c8x2-fgvf-cxj9.json @@ -7,12 +7,8 @@ "CVE-2021-35948" ], "details": "Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c939-x98h-rxrc/GHSA-c939-x98h-rxrc.json b/advisories/unreviewed/2022/05/GHSA-c939-x98h-rxrc/GHSA-c939-x98h-rxrc.json index db273c41147..40eb83365bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-c939-x98h-rxrc/GHSA-c939-x98h-rxrc.json +++ b/advisories/unreviewed/2022/05/GHSA-c939-x98h-rxrc/GHSA-c939-x98h-rxrc.json @@ -7,12 +7,8 @@ "CVE-2021-23041" ], "details": "On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the current logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c99h-qrmx-p2vc/GHSA-c99h-qrmx-p2vc.json b/advisories/unreviewed/2022/05/GHSA-c99h-qrmx-p2vc/GHSA-c99h-qrmx-p2vc.json index 58fb0366739..ccc011afd7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c99h-qrmx-p2vc/GHSA-c99h-qrmx-p2vc.json +++ b/advisories/unreviewed/2022/05/GHSA-c99h-qrmx-p2vc/GHSA-c99h-qrmx-p2vc.json @@ -7,12 +7,8 @@ "CVE-2005-4254" ], "details": "SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9vc-847w-w9p5/GHSA-c9vc-847w-w9p5.json b/advisories/unreviewed/2022/05/GHSA-c9vc-847w-w9p5/GHSA-c9vc-847w-w9p5.json index 457f77f9127..e4741e9130d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9vc-847w-w9p5/GHSA-c9vc-847w-w9p5.json +++ b/advisories/unreviewed/2022/05/GHSA-c9vc-847w-w9p5/GHSA-c9vc-847w-w9p5.json @@ -7,12 +7,8 @@ "CVE-2021-30802" ], "details": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc6f-j84g-6gmr/GHSA-cc6f-j84g-6gmr.json b/advisories/unreviewed/2022/05/GHSA-cc6f-j84g-6gmr/GHSA-cc6f-j84g-6gmr.json index 96d68b48abb..a1a972dc31f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc6f-j84g-6gmr/GHSA-cc6f-j84g-6gmr.json +++ b/advisories/unreviewed/2022/05/GHSA-cc6f-j84g-6gmr/GHSA-cc6f-j84g-6gmr.json @@ -7,12 +7,8 @@ "CVE-2021-36096" ], "details": "Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccqm-h4g9-xv4v/GHSA-ccqm-h4g9-xv4v.json b/advisories/unreviewed/2022/05/GHSA-ccqm-h4g9-xv4v/GHSA-ccqm-h4g9-xv4v.json index fb0d3a4f9bb..20ca456f12a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccqm-h4g9-xv4v/GHSA-ccqm-h4g9-xv4v.json +++ b/advisories/unreviewed/2022/05/GHSA-ccqm-h4g9-xv4v/GHSA-ccqm-h4g9-xv4v.json @@ -7,12 +7,8 @@ "CVE-2021-36216" ], "details": "LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfgm-gh5v-x98w/GHSA-cfgm-gh5v-x98w.json b/advisories/unreviewed/2022/05/GHSA-cfgm-gh5v-x98w/GHSA-cfgm-gh5v-x98w.json index e4122309022..14e070f6ccc 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfgm-gh5v-x98w/GHSA-cfgm-gh5v-x98w.json +++ b/advisories/unreviewed/2022/05/GHSA-cfgm-gh5v-x98w/GHSA-cfgm-gh5v-x98w.json @@ -7,12 +7,8 @@ "CVE-2021-38320" ], "details": "The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER[\"PHP_SELF\"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg43-6rv4-f24m/GHSA-cg43-6rv4-f24m.json b/advisories/unreviewed/2022/05/GHSA-cg43-6rv4-f24m/GHSA-cg43-6rv4-f24m.json index 8f3c2d68c57..a7f0671f57c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg43-6rv4-f24m/GHSA-cg43-6rv4-f24m.json +++ b/advisories/unreviewed/2022/05/GHSA-cg43-6rv4-f24m/GHSA-cg43-6rv4-f24m.json @@ -7,12 +7,8 @@ "CVE-2021-30805" ], "details": "A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgvh-3r4w-r8v7/GHSA-cgvh-3r4w-r8v7.json b/advisories/unreviewed/2022/05/GHSA-cgvh-3r4w-r8v7/GHSA-cgvh-3r4w-r8v7.json index 5900f854139..a13745cf049 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgvh-3r4w-r8v7/GHSA-cgvh-3r4w-r8v7.json +++ b/advisories/unreviewed/2022/05/GHSA-cgvh-3r4w-r8v7/GHSA-cgvh-3r4w-r8v7.json @@ -7,12 +7,8 @@ "CVE-2021-25452" ], "details": "An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-chfv-xhr2-p6ww/GHSA-chfv-xhr2-p6ww.json b/advisories/unreviewed/2022/05/GHSA-chfv-xhr2-p6ww/GHSA-chfv-xhr2-p6ww.json index 0c00e76fcc9..64b4e98a6ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-chfv-xhr2-p6ww/GHSA-chfv-xhr2-p6ww.json +++ b/advisories/unreviewed/2022/05/GHSA-chfv-xhr2-p6ww/GHSA-chfv-xhr2-p6ww.json @@ -7,12 +7,8 @@ "CVE-2005-4356" ], "details": "SQL injection vulnerability in UStore allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjfc-p2gj-cv87/GHSA-cjfc-p2gj-cv87.json b/advisories/unreviewed/2022/05/GHSA-cjfc-p2gj-cv87/GHSA-cjfc-p2gj-cv87.json index 808884e5361..d48f238ce90 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjfc-p2gj-cv87/GHSA-cjfc-p2gj-cv87.json +++ b/advisories/unreviewed/2022/05/GHSA-cjfc-p2gj-cv87/GHSA-cjfc-p2gj-cv87.json @@ -7,12 +7,8 @@ "CVE-2020-20349" ], "details": "WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cjmp-q329-278j/GHSA-cjmp-q329-278j.json b/advisories/unreviewed/2022/05/GHSA-cjmp-q329-278j/GHSA-cjmp-q329-278j.json index 36331591484..3ad9fea1ec9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjmp-q329-278j/GHSA-cjmp-q329-278j.json +++ b/advisories/unreviewed/2022/05/GHSA-cjmp-q329-278j/GHSA-cjmp-q329-278j.json @@ -7,12 +7,8 @@ "CVE-2021-28580" ], "details": "Medium by Adobe version 2.4.5.331 (and earlier) is affected by a buffer overflow vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cm3f-4fjm-xqwf/GHSA-cm3f-4fjm-xqwf.json b/advisories/unreviewed/2022/05/GHSA-cm3f-4fjm-xqwf/GHSA-cm3f-4fjm-xqwf.json index ae826761fb8..dbaeea95bb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm3f-4fjm-xqwf/GHSA-cm3f-4fjm-xqwf.json +++ b/advisories/unreviewed/2022/05/GHSA-cm3f-4fjm-xqwf/GHSA-cm3f-4fjm-xqwf.json @@ -7,12 +7,8 @@ "CVE-2005-4148" ], "details": "Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cm3p-j4f2-pc4m/GHSA-cm3p-j4f2-pc4m.json b/advisories/unreviewed/2022/05/GHSA-cm3p-j4f2-pc4m/GHSA-cm3p-j4f2-pc4m.json index 139896cf481..7d43f2689b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm3p-j4f2-pc4m/GHSA-cm3p-j4f2-pc4m.json +++ b/advisories/unreviewed/2022/05/GHSA-cm3p-j4f2-pc4m/GHSA-cm3p-j4f2-pc4m.json @@ -7,12 +7,8 @@ "CVE-2021-30621" ], "details": "Inappropriate implementation in Autofill in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to spoof security UI via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cm69-2c6j-6pvp/GHSA-cm69-2c6j-6pvp.json b/advisories/unreviewed/2022/05/GHSA-cm69-2c6j-6pvp/GHSA-cm69-2c6j-6pvp.json index 31b003b9238..88e591774de 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm69-2c6j-6pvp/GHSA-cm69-2c6j-6pvp.json +++ b/advisories/unreviewed/2022/05/GHSA-cm69-2c6j-6pvp/GHSA-cm69-2c6j-6pvp.json @@ -7,12 +7,8 @@ "CVE-2021-37725" ], "details": "A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.8.0.1, 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cmhq-396f-qxrf/GHSA-cmhq-396f-qxrf.json b/advisories/unreviewed/2022/05/GHSA-cmhq-396f-qxrf/GHSA-cmhq-396f-qxrf.json index e4f2f044e9f..fd379355bba 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmhq-396f-qxrf/GHSA-cmhq-396f-qxrf.json +++ b/advisories/unreviewed/2022/05/GHSA-cmhq-396f-qxrf/GHSA-cmhq-396f-qxrf.json @@ -7,12 +7,8 @@ "CVE-2005-4212" ], "details": "Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via \"..\" (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmxj-r24c-gf8p/GHSA-cmxj-r24c-gf8p.json b/advisories/unreviewed/2022/05/GHSA-cmxj-r24c-gf8p/GHSA-cmxj-r24c-gf8p.json index 3b55110636d..2917e1cb290 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmxj-r24c-gf8p/GHSA-cmxj-r24c-gf8p.json +++ b/advisories/unreviewed/2022/05/GHSA-cmxj-r24c-gf8p/GHSA-cmxj-r24c-gf8p.json @@ -7,12 +7,8 @@ "CVE-2021-1864" ], "details": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An attacker with JavaScript execution may be able to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cp2r-rvgm-x6rh/GHSA-cp2r-rvgm-x6rh.json b/advisories/unreviewed/2022/05/GHSA-cp2r-rvgm-x6rh/GHSA-cp2r-rvgm-x6rh.json index 27754e45344..0c9b9da6bf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp2r-rvgm-x6rh/GHSA-cp2r-rvgm-x6rh.json +++ b/advisories/unreviewed/2022/05/GHSA-cp2r-rvgm-x6rh/GHSA-cp2r-rvgm-x6rh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cp5f-x2vj-pqgh/GHSA-cp5f-x2vj-pqgh.json b/advisories/unreviewed/2022/05/GHSA-cp5f-x2vj-pqgh/GHSA-cp5f-x2vj-pqgh.json index 1d8f0708cc2..c32bfd6112d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp5f-x2vj-pqgh/GHSA-cp5f-x2vj-pqgh.json +++ b/advisories/unreviewed/2022/05/GHSA-cp5f-x2vj-pqgh/GHSA-cp5f-x2vj-pqgh.json @@ -7,12 +7,8 @@ "CVE-2020-19267" ], "details": "An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpfg-9xhh-m7cm/GHSA-cpfg-9xhh-m7cm.json b/advisories/unreviewed/2022/05/GHSA-cpfg-9xhh-m7cm/GHSA-cpfg-9xhh-m7cm.json index 65f5d40a89d..6d2334e5504 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpfg-9xhh-m7cm/GHSA-cpfg-9xhh-m7cm.json +++ b/advisories/unreviewed/2022/05/GHSA-cpfg-9xhh-m7cm/GHSA-cpfg-9xhh-m7cm.json @@ -7,12 +7,8 @@ "CVE-2005-4396" ], "details": "Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpvp-q5mv-cx2q/GHSA-cpvp-q5mv-cx2q.json b/advisories/unreviewed/2022/05/GHSA-cpvp-q5mv-cx2q/GHSA-cpvp-q5mv-cx2q.json index 9aeb03a082e..a8a3c69bf6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpvp-q5mv-cx2q/GHSA-cpvp-q5mv-cx2q.json +++ b/advisories/unreviewed/2022/05/GHSA-cpvp-q5mv-cx2q/GHSA-cpvp-q5mv-cx2q.json @@ -7,12 +7,8 @@ "CVE-2021-28495" ], "details": "In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqhr-xwvr-x8f9/GHSA-cqhr-xwvr-x8f9.json b/advisories/unreviewed/2022/05/GHSA-cqhr-xwvr-x8f9/GHSA-cqhr-xwvr-x8f9.json index 080d091b5e1..c3d2e561d89 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqhr-xwvr-x8f9/GHSA-cqhr-xwvr-x8f9.json +++ b/advisories/unreviewed/2022/05/GHSA-cqhr-xwvr-x8f9/GHSA-cqhr-xwvr-x8f9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cqqm-5v99-78h5/GHSA-cqqm-5v99-78h5.json b/advisories/unreviewed/2022/05/GHSA-cqqm-5v99-78h5/GHSA-cqqm-5v99-78h5.json index 73a1bf1e5de..6c7e0e457ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqqm-5v99-78h5/GHSA-cqqm-5v99-78h5.json +++ b/advisories/unreviewed/2022/05/GHSA-cqqm-5v99-78h5/GHSA-cqqm-5v99-78h5.json @@ -7,12 +7,8 @@ "CVE-2021-30664" ], "details": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crvj-v2xg-pq76/GHSA-crvj-v2xg-pq76.json b/advisories/unreviewed/2022/05/GHSA-crvj-v2xg-pq76/GHSA-crvj-v2xg-pq76.json index 0d1eab2631e..741209978e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-crvj-v2xg-pq76/GHSA-crvj-v2xg-pq76.json +++ b/advisories/unreviewed/2022/05/GHSA-crvj-v2xg-pq76/GHSA-crvj-v2xg-pq76.json @@ -7,12 +7,8 @@ "CVE-2005-4384" ], "details": "CitySoft Community Enterprise 4.x allows remote attackers to obtain the full path of the server via an invalid (1) fuseaction parameter to index.cfm and (2) documentid parameter to document/docWindow.cfm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-crwc-423j-w3mj/GHSA-crwc-423j-w3mj.json b/advisories/unreviewed/2022/05/GHSA-crwc-423j-w3mj/GHSA-crwc-423j-w3mj.json index ca244d5ea05..19c2af1e510 100644 --- a/advisories/unreviewed/2022/05/GHSA-crwc-423j-w3mj/GHSA-crwc-423j-w3mj.json +++ b/advisories/unreviewed/2022/05/GHSA-crwc-423j-w3mj/GHSA-crwc-423j-w3mj.json @@ -7,12 +7,8 @@ "CVE-2005-4281" ], "details": "Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to zaygo.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cw35-8jqv-8rfq/GHSA-cw35-8jqv-8rfq.json b/advisories/unreviewed/2022/05/GHSA-cw35-8jqv-8rfq/GHSA-cw35-8jqv-8rfq.json index 8d168de5207..29c914878a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw35-8jqv-8rfq/GHSA-cw35-8jqv-8rfq.json +++ b/advisories/unreviewed/2022/05/GHSA-cw35-8jqv-8rfq/GHSA-cw35-8jqv-8rfq.json @@ -7,12 +7,8 @@ "CVE-2020-19266" ], "details": "A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cw8x-jrx2-378j/GHSA-cw8x-jrx2-378j.json b/advisories/unreviewed/2022/05/GHSA-cw8x-jrx2-378j/GHSA-cw8x-jrx2-378j.json index b0b5637ca75..d6a45888da1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw8x-jrx2-378j/GHSA-cw8x-jrx2-378j.json +++ b/advisories/unreviewed/2022/05/GHSA-cw8x-jrx2-378j/GHSA-cw8x-jrx2-378j.json @@ -7,12 +7,8 @@ "CVE-2005-4228" ], "details": "Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwpm-59m6-8648/GHSA-cwpm-59m6-8648.json b/advisories/unreviewed/2022/05/GHSA-cwpm-59m6-8648/GHSA-cwpm-59m6-8648.json index 3c9d539848c..1d6479a6f56 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwpm-59m6-8648/GHSA-cwpm-59m6-8648.json +++ b/advisories/unreviewed/2022/05/GHSA-cwpm-59m6-8648/GHSA-cwpm-59m6-8648.json @@ -7,12 +7,8 @@ "CVE-2005-4078" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Ideal BB.NET 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) forumID, (2) boardID, and (3) topicRepeater1-p parameters in topics.aspx, (4) boardID parameter in categoryindex.aspx, (5) postID parameter in posts.aspx, (6) catID parameter in forums.aspx, and (7) memberID parameter in member.aspx.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cwvc-jrh4-j53h/GHSA-cwvc-jrh4-j53h.json b/advisories/unreviewed/2022/05/GHSA-cwvc-jrh4-j53h/GHSA-cwvc-jrh4-j53h.json index 9b4c65ec227..e2f5b09bb92 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwvc-jrh4-j53h/GHSA-cwvc-jrh4-j53h.json +++ b/advisories/unreviewed/2022/05/GHSA-cwvc-jrh4-j53h/GHSA-cwvc-jrh4-j53h.json @@ -7,12 +7,8 @@ "CVE-2021-30796" ], "details": "A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing a maliciously crafted image may lead to a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxf9-4ff5-hx4j/GHSA-cxf9-4ff5-hx4j.json b/advisories/unreviewed/2022/05/GHSA-cxf9-4ff5-hx4j/GHSA-cxf9-4ff5-hx4j.json index 06132ff502b..e16faa93703 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxf9-4ff5-hx4j/GHSA-cxf9-4ff5-hx4j.json +++ b/advisories/unreviewed/2022/05/GHSA-cxf9-4ff5-hx4j/GHSA-cxf9-4ff5-hx4j.json @@ -7,12 +7,8 @@ "CVE-2021-40222" ], "details": "Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is possible to introduce shell code to create a reverse shell in the PU-Hostname field of the TCP/IP Configuration dialog. Web application fails to sanitize user input on Network TCP/IP configuration page. This allows the attacker to inject commands as root on the device which will be executed once the data is received.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxm5-87x2-49fh/GHSA-cxm5-87x2-49fh.json b/advisories/unreviewed/2022/05/GHSA-cxm5-87x2-49fh/GHSA-cxm5-87x2-49fh.json index 713e01419c5..193b26c4484 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxm5-87x2-49fh/GHSA-cxm5-87x2-49fh.json +++ b/advisories/unreviewed/2022/05/GHSA-cxm5-87x2-49fh/GHSA-cxm5-87x2-49fh.json @@ -7,12 +7,8 @@ "CVE-2005-4299" ], "details": "Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) before and (2) ct parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxrm-q29h-frv4/GHSA-cxrm-q29h-frv4.json b/advisories/unreviewed/2022/05/GHSA-cxrm-q29h-frv4/GHSA-cxrm-q29h-frv4.json index c45fbddd939..5a6176671d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxrm-q29h-frv4/GHSA-cxrm-q29h-frv4.json +++ b/advisories/unreviewed/2022/05/GHSA-cxrm-q29h-frv4/GHSA-cxrm-q29h-frv4.json @@ -7,12 +7,8 @@ "CVE-2005-3912" ], "details": "Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary code via format string specifiers in the username parameter to the login form, which is ultimately used in a syslog call. NOTE: the code execution might be associated with an issue in Perl.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxvf-5j6c-r2hw/GHSA-cxvf-5j6c-r2hw.json b/advisories/unreviewed/2022/05/GHSA-cxvf-5j6c-r2hw/GHSA-cxvf-5j6c-r2hw.json index c11481ceb57..69b5eb4a404 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxvf-5j6c-r2hw/GHSA-cxvf-5j6c-r2hw.json +++ b/advisories/unreviewed/2022/05/GHSA-cxvf-5j6c-r2hw/GHSA-cxvf-5j6c-r2hw.json @@ -7,12 +7,8 @@ "CVE-2021-30674" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 14.6 and iPadOS 14.6. A malicious application may disclose restricted memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxxw-rfqc-pqx7/GHSA-cxxw-rfqc-pqx7.json b/advisories/unreviewed/2022/05/GHSA-cxxw-rfqc-pqx7/GHSA-cxxw-rfqc-pqx7.json index 01b4f26d48b..a9d33afcbfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxxw-rfqc-pqx7/GHSA-cxxw-rfqc-pqx7.json +++ b/advisories/unreviewed/2022/05/GHSA-cxxw-rfqc-pqx7/GHSA-cxxw-rfqc-pqx7.json @@ -7,12 +7,8 @@ "CVE-2021-30703" ], "details": "A double free issue was addressed with improved memory management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f2hj-jpwp-p6pp/GHSA-f2hj-jpwp-p6pp.json b/advisories/unreviewed/2022/05/GHSA-f2hj-jpwp-p6pp/GHSA-f2hj-jpwp-p6pp.json index 43bba6b1177..be759a24d92 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2hj-jpwp-p6pp/GHSA-f2hj-jpwp-p6pp.json +++ b/advisories/unreviewed/2022/05/GHSA-f2hj-jpwp-p6pp/GHSA-f2hj-jpwp-p6pp.json @@ -7,12 +7,8 @@ "CVE-2021-23032" ], "details": "On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a BIG-IP DNS system is configured with non-default Wide IP and pool settings, undisclosed DNS responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2ph-fm4w-vfqw/GHSA-f2ph-fm4w-vfqw.json b/advisories/unreviewed/2022/05/GHSA-f2ph-fm4w-vfqw/GHSA-f2ph-fm4w-vfqw.json index 28748ee648e..835a182c7d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2ph-fm4w-vfqw/GHSA-f2ph-fm4w-vfqw.json +++ b/advisories/unreviewed/2022/05/GHSA-f2ph-fm4w-vfqw/GHSA-f2ph-fm4w-vfqw.json @@ -7,12 +7,8 @@ "CVE-2005-4278" ], "details": "Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f38c-74h5-hh3j/GHSA-f38c-74h5-hh3j.json b/advisories/unreviewed/2022/05/GHSA-f38c-74h5-hh3j/GHSA-f38c-74h5-hh3j.json index 3975d8e55e2..c263e0e7d88 100644 --- a/advisories/unreviewed/2022/05/GHSA-f38c-74h5-hh3j/GHSA-f38c-74h5-hh3j.json +++ b/advisories/unreviewed/2022/05/GHSA-f38c-74h5-hh3j/GHSA-f38c-74h5-hh3j.json @@ -7,12 +7,8 @@ "CVE-2005-4193" ], "details": "Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER['PHP_SELF'] variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f3ww-5jpf-ch84/GHSA-f3ww-5jpf-ch84.json b/advisories/unreviewed/2022/05/GHSA-f3ww-5jpf-ch84/GHSA-f3ww-5jpf-ch84.json index 560561ad755..ba37cc93622 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3ww-5jpf-ch84/GHSA-f3ww-5jpf-ch84.json +++ b/advisories/unreviewed/2022/05/GHSA-f3ww-5jpf-ch84/GHSA-f3ww-5jpf-ch84.json @@ -7,12 +7,8 @@ "CVE-2005-4314" ], "details": "Cross-site scripting (XSS) vulnerability in ppcal.cgi in PPCal Shopping Cart 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) stop and (2) user parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f47x-r3wj-9vxc/GHSA-f47x-r3wj-9vxc.json b/advisories/unreviewed/2022/05/GHSA-f47x-r3wj-9vxc/GHSA-f47x-r3wj-9vxc.json index 73bd07b8e0a..f97fbc34584 100644 --- a/advisories/unreviewed/2022/05/GHSA-f47x-r3wj-9vxc/GHSA-f47x-r3wj-9vxc.json +++ b/advisories/unreviewed/2022/05/GHSA-f47x-r3wj-9vxc/GHSA-f47x-r3wj-9vxc.json @@ -7,12 +7,8 @@ "CVE-2021-1963" ], "details": "Possible use-after-free due to lack of validation for the rule count in filter table in IPA driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f4v5-c35c-fm7m/GHSA-f4v5-c35c-fm7m.json b/advisories/unreviewed/2022/05/GHSA-f4v5-c35c-fm7m/GHSA-f4v5-c35c-fm7m.json index eb90fce0fdc..a175f04c5a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4v5-c35c-fm7m/GHSA-f4v5-c35c-fm7m.json +++ b/advisories/unreviewed/2022/05/GHSA-f4v5-c35c-fm7m/GHSA-f4v5-c35c-fm7m.json @@ -7,12 +7,8 @@ "CVE-2005-4217" ], "details": "Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the \"$<\" variable to set uid, which allows attackers to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f5m5-9gwg-wj8v/GHSA-f5m5-9gwg-wj8v.json b/advisories/unreviewed/2022/05/GHSA-f5m5-9gwg-wj8v/GHSA-f5m5-9gwg-wj8v.json index 1735e02e88d..b29bd894ab5 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5m5-9gwg-wj8v/GHSA-f5m5-9gwg-wj8v.json +++ b/advisories/unreviewed/2022/05/GHSA-f5m5-9gwg-wj8v/GHSA-f5m5-9gwg-wj8v.json @@ -7,12 +7,8 @@ "CVE-2020-19765" ], "details": "An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a reentrancy attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f66h-6w2v-hxhr/GHSA-f66h-6w2v-hxhr.json b/advisories/unreviewed/2022/05/GHSA-f66h-6w2v-hxhr/GHSA-f66h-6w2v-hxhr.json index dd36b117435..30edba258fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-f66h-6w2v-hxhr/GHSA-f66h-6w2v-hxhr.json +++ b/advisories/unreviewed/2022/05/GHSA-f66h-6w2v-hxhr/GHSA-f66h-6w2v-hxhr.json @@ -7,12 +7,8 @@ "CVE-2005-4177" ], "details": "Cross-site scripting (XSS) vulnerability in book.cfm in Magic Book Personal and Professional 2.0 allows remote attackers to inject arbitrary web script or HTML via the StartRow parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f6j8-h69q-85jh/GHSA-f6j8-h69q-85jh.json b/advisories/unreviewed/2022/05/GHSA-f6j8-h69q-85jh/GHSA-f6j8-h69q-85jh.json index 100329dee1b..b7b4f930aec 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6j8-h69q-85jh/GHSA-f6j8-h69q-85jh.json +++ b/advisories/unreviewed/2022/05/GHSA-f6j8-h69q-85jh/GHSA-f6j8-h69q-85jh.json @@ -7,12 +7,8 @@ "CVE-2021-30716" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to perform denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f77q-prc8-hp2f/GHSA-f77q-prc8-hp2f.json b/advisories/unreviewed/2022/05/GHSA-f77q-prc8-hp2f/GHSA-f77q-prc8-hp2f.json index 3864340fe77..80ca9ffb57b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f77q-prc8-hp2f/GHSA-f77q-prc8-hp2f.json +++ b/advisories/unreviewed/2022/05/GHSA-f77q-prc8-hp2f/GHSA-f77q-prc8-hp2f.json @@ -7,12 +7,8 @@ "CVE-2021-30618" ], "details": "Inappropriate implementation in DevTools in Google Chrome prior to 93.0.4577.63 allowed a remote attacker who had convinced the user to use Chrome headless with remote debugging to execute arbitrary code via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f8xr-vx48-q3fh/GHSA-f8xr-vx48-q3fh.json b/advisories/unreviewed/2022/05/GHSA-f8xr-vx48-q3fh/GHSA-f8xr-vx48-q3fh.json index e0861d50cea..40c4aef6eb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8xr-vx48-q3fh/GHSA-f8xr-vx48-q3fh.json +++ b/advisories/unreviewed/2022/05/GHSA-f8xr-vx48-q3fh/GHSA-f8xr-vx48-q3fh.json @@ -7,12 +7,8 @@ "CVE-2021-37190" ], "details": "A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f95v-w3cx-q9fg/GHSA-f95v-w3cx-q9fg.json b/advisories/unreviewed/2022/05/GHSA-f95v-w3cx-q9fg/GHSA-f95v-w3cx-q9fg.json index 50d2ec9060f..c71ebab3563 100644 --- a/advisories/unreviewed/2022/05/GHSA-f95v-w3cx-q9fg/GHSA-f95v-w3cx-q9fg.json +++ b/advisories/unreviewed/2022/05/GHSA-f95v-w3cx-q9fg/GHSA-f95v-w3cx-q9fg.json @@ -7,12 +7,8 @@ "CVE-2005-4276" ], "details": "Westell Versalink 327W allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f97x-f6x5-pmh9/GHSA-f97x-f6x5-pmh9.json b/advisories/unreviewed/2022/05/GHSA-f97x-f6x5-pmh9/GHSA-f97x-f6x5-pmh9.json index 6dcb3a6a527..6ae080618df 100644 --- a/advisories/unreviewed/2022/05/GHSA-f97x-f6x5-pmh9/GHSA-f97x-f6x5-pmh9.json +++ b/advisories/unreviewed/2022/05/GHSA-f97x-f6x5-pmh9/GHSA-f97x-f6x5-pmh9.json @@ -7,12 +7,8 @@ "CVE-2005-4203" ], "details": "LogiSphere 0.9.9j does not restrict the number of messages that can be sent, which allows remote attackers to cause a denial of service by sending a large number of messages via the msg command. NOTE: due to lack of appropriate details by the original researcher, it is unclear whether this description accurately reflects the discloser's claim and is distinct from the XSS issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f98m-j6f8-7632/GHSA-f98m-j6f8-7632.json b/advisories/unreviewed/2022/05/GHSA-f98m-j6f8-7632/GHSA-f98m-j6f8-7632.json index 1d430e12933..9d1cf7fcb9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f98m-j6f8-7632/GHSA-f98m-j6f8-7632.json +++ b/advisories/unreviewed/2022/05/GHSA-f98m-j6f8-7632/GHSA-f98m-j6f8-7632.json @@ -7,12 +7,8 @@ "CVE-2021-1885" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9cg-jhm7-4fw7/GHSA-f9cg-jhm7-4fw7.json b/advisories/unreviewed/2022/05/GHSA-f9cg-jhm7-4fw7/GHSA-f9cg-jhm7-4fw7.json index 73d2db50cfe..b1e44f29bbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9cg-jhm7-4fw7/GHSA-f9cg-jhm7-4fw7.json +++ b/advisories/unreviewed/2022/05/GHSA-f9cg-jhm7-4fw7/GHSA-f9cg-jhm7-4fw7.json @@ -7,12 +7,8 @@ "CVE-2021-1960" ], "details": "Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9gf-mv67-x4h6/GHSA-f9gf-mv67-x4h6.json b/advisories/unreviewed/2022/05/GHSA-f9gf-mv67-x4h6/GHSA-f9gf-mv67-x4h6.json index cc732f7ef6a..c20e81d86ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9gf-mv67-x4h6/GHSA-f9gf-mv67-x4h6.json +++ b/advisories/unreviewed/2022/05/GHSA-f9gf-mv67-x4h6/GHSA-f9gf-mv67-x4h6.json @@ -7,12 +7,8 @@ "CVE-2021-32487" ], "details": "In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500736; Issue ID: ALPS04938456.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9j8-wqgr-64w4/GHSA-f9j8-wqgr-64w4.json b/advisories/unreviewed/2022/05/GHSA-f9j8-wqgr-64w4/GHSA-f9j8-wqgr-64w4.json index 73c50f407e9..ed084a81e1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9j8-wqgr-64w4/GHSA-f9j8-wqgr-64w4.json +++ b/advisories/unreviewed/2022/05/GHSA-f9j8-wqgr-64w4/GHSA-f9j8-wqgr-64w4.json @@ -7,12 +7,8 @@ "CVE-2005-4312" ], "details": "SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f9qg-252f-g8cg/GHSA-f9qg-252f-g8cg.json b/advisories/unreviewed/2022/05/GHSA-f9qg-252f-g8cg/GHSA-f9qg-252f-g8cg.json index d90a0680919..82035abe4ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9qg-252f-g8cg/GHSA-f9qg-252f-g8cg.json +++ b/advisories/unreviewed/2022/05/GHSA-f9qg-252f-g8cg/GHSA-f9qg-252f-g8cg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9wq-3588-gpmc/GHSA-f9wq-3588-gpmc.json b/advisories/unreviewed/2022/05/GHSA-f9wq-3588-gpmc/GHSA-f9wq-3588-gpmc.json index 8a3ac68972a..3f33a177ed0 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9wq-3588-gpmc/GHSA-f9wq-3588-gpmc.json +++ b/advisories/unreviewed/2022/05/GHSA-f9wq-3588-gpmc/GHSA-f9wq-3588-gpmc.json @@ -7,12 +7,8 @@ "CVE-2021-30668" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A person with physical access to a Mac may be able to bypass Login Window during a software update.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcm2-h2g5-2hxc/GHSA-fcm2-h2g5-2hxc.json b/advisories/unreviewed/2022/05/GHSA-fcm2-h2g5-2hxc/GHSA-fcm2-h2g5-2hxc.json index 65875e8bac2..709375139db 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcm2-h2g5-2hxc/GHSA-fcm2-h2g5-2hxc.json +++ b/advisories/unreviewed/2022/05/GHSA-fcm2-h2g5-2hxc/GHSA-fcm2-h2g5-2hxc.json @@ -7,12 +7,8 @@ "CVE-2021-40814" ], "details": "The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcmq-72mc-hj3x/GHSA-fcmq-72mc-hj3x.json b/advisories/unreviewed/2022/05/GHSA-fcmq-72mc-hj3x/GHSA-fcmq-72mc-hj3x.json index 7bcb697c5ae..7021f763b04 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcmq-72mc-hj3x/GHSA-fcmq-72mc-hj3x.json +++ b/advisories/unreviewed/2022/05/GHSA-fcmq-72mc-hj3x/GHSA-fcmq-72mc-hj3x.json @@ -7,12 +7,8 @@ "CVE-2005-4296" ], "details": "AppServ Open Project 2.5.3 allows remote attackers to cause a denial of service via a large HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fcx4-3mfw-82qr/GHSA-fcx4-3mfw-82qr.json b/advisories/unreviewed/2022/05/GHSA-fcx4-3mfw-82qr/GHSA-fcx4-3mfw-82qr.json index 0eb01ca8d09..fcd31fc4441 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcx4-3mfw-82qr/GHSA-fcx4-3mfw-82qr.json +++ b/advisories/unreviewed/2022/05/GHSA-fcx4-3mfw-82qr/GHSA-fcx4-3mfw-82qr.json @@ -7,12 +7,8 @@ "CVE-2005-3958" ], "details": "SQL injection vulnerability in index.php in Entergal MX 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idcat parameter in a showcat action and (2) the action parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ff36-v98j-xr5x/GHSA-ff36-v98j-xr5x.json b/advisories/unreviewed/2022/05/GHSA-ff36-v98j-xr5x/GHSA-ff36-v98j-xr5x.json index 4ffb0605503..2112099faae 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff36-v98j-xr5x/GHSA-ff36-v98j-xr5x.json +++ b/advisories/unreviewed/2022/05/GHSA-ff36-v98j-xr5x/GHSA-ff36-v98j-xr5x.json @@ -7,12 +7,8 @@ "CVE-2021-38725" ], "details": "Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fg7c-85hr-w8hp/GHSA-fg7c-85hr-w8hp.json b/advisories/unreviewed/2022/05/GHSA-fg7c-85hr-w8hp/GHSA-fg7c-85hr-w8hp.json index 0ff91c5d4de..7dae6abaacb 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg7c-85hr-w8hp/GHSA-fg7c-85hr-w8hp.json +++ b/advisories/unreviewed/2022/05/GHSA-fg7c-85hr-w8hp/GHSA-fg7c-85hr-w8hp.json @@ -7,12 +7,8 @@ "CVE-2005-4262" ], "details": "Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE-2005-4263).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgc6-r27g-4r9x/GHSA-fgc6-r27g-4r9x.json b/advisories/unreviewed/2022/05/GHSA-fgc6-r27g-4r9x/GHSA-fgc6-r27g-4r9x.json index 5b88b0b2b7d..c2a4e0e2a00 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgc6-r27g-4r9x/GHSA-fgc6-r27g-4r9x.json +++ b/advisories/unreviewed/2022/05/GHSA-fgc6-r27g-4r9x/GHSA-fgc6-r27g-4r9x.json @@ -7,12 +7,8 @@ "CVE-2021-1829" ], "details": "A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgq5-6x94-h566/GHSA-fgq5-6x94-h566.json b/advisories/unreviewed/2022/05/GHSA-fgq5-6x94-h566/GHSA-fgq5-6x94-h566.json index 20b648bef62..d3993e7bf29 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgq5-6x94-h566/GHSA-fgq5-6x94-h566.json +++ b/advisories/unreviewed/2022/05/GHSA-fgq5-6x94-h566/GHSA-fgq5-6x94-h566.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj9m-wfgj-34gq/GHSA-fj9m-wfgj-34gq.json b/advisories/unreviewed/2022/05/GHSA-fj9m-wfgj-34gq/GHSA-fj9m-wfgj-34gq.json index 4fe0b55bdad..00705987241 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj9m-wfgj-34gq/GHSA-fj9m-wfgj-34gq.json +++ b/advisories/unreviewed/2022/05/GHSA-fj9m-wfgj-34gq/GHSA-fj9m-wfgj-34gq.json @@ -7,12 +7,8 @@ "CVE-2021-30613" ], "details": "Use after free in Base internals in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjc5-6pxf-p2h2/GHSA-fjc5-6pxf-p2h2.json b/advisories/unreviewed/2022/05/GHSA-fjc5-6pxf-p2h2/GHSA-fjc5-6pxf-p2h2.json index f4d3f0397b9..6459cfe7f82 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjc5-6pxf-p2h2/GHSA-fjc5-6pxf-p2h2.json +++ b/advisories/unreviewed/2022/05/GHSA-fjc5-6pxf-p2h2/GHSA-fjc5-6pxf-p2h2.json @@ -7,12 +7,8 @@ "CVE-2005-4251" ], "details": "Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fjgf-fwh5-r5mp/GHSA-fjgf-fwh5-r5mp.json b/advisories/unreviewed/2022/05/GHSA-fjgf-fwh5-r5mp/GHSA-fjgf-fwh5-r5mp.json index adf819dc6a4..dfc5d64b4de 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjgf-fwh5-r5mp/GHSA-fjgf-fwh5-r5mp.json +++ b/advisories/unreviewed/2022/05/GHSA-fjgf-fwh5-r5mp/GHSA-fjgf-fwh5-r5mp.json @@ -7,12 +7,8 @@ "CVE-2021-38322" ], "details": "The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_TF_password parameter found in the ~/twitter-friends-widget.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm3m-c8g9-95rj/GHSA-fm3m-c8g9-95rj.json b/advisories/unreviewed/2022/05/GHSA-fm3m-c8g9-95rj/GHSA-fm3m-c8g9-95rj.json index 83379e6510e..364c4eca500 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm3m-c8g9-95rj/GHSA-fm3m-c8g9-95rj.json +++ b/advisories/unreviewed/2022/05/GHSA-fm3m-c8g9-95rj/GHSA-fm3m-c8g9-95rj.json @@ -7,12 +7,8 @@ "CVE-2020-19766" ], "details": "The time check operation of PepeAuctionSale 1.0 can be rendered ineffective by assigning a large number to the _duration variable, compromising access control to the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm4f-mfw8-25x9/GHSA-fm4f-mfw8-25x9.json b/advisories/unreviewed/2022/05/GHSA-fm4f-mfw8-25x9/GHSA-fm4f-mfw8-25x9.json index 1ac843106d4..d53dafe4c90 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm4f-mfw8-25x9/GHSA-fm4f-mfw8-25x9.json +++ b/advisories/unreviewed/2022/05/GHSA-fm4f-mfw8-25x9/GHSA-fm4f-mfw8-25x9.json @@ -7,12 +7,8 @@ "CVE-2021-25451" ], "details": "A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmc4-4chw-q2xg/GHSA-fmc4-4chw-q2xg.json b/advisories/unreviewed/2022/05/GHSA-fmc4-4chw-q2xg/GHSA-fmc4-4chw-q2xg.json index 139be7488c1..067eb17525e 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmc4-4chw-q2xg/GHSA-fmc4-4chw-q2xg.json +++ b/advisories/unreviewed/2022/05/GHSA-fmc4-4chw-q2xg/GHSA-fmc4-4chw-q2xg.json @@ -7,12 +7,8 @@ "CVE-2021-32485" ], "details": "In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964926.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmjm-xh2h-5w4j/GHSA-fmjm-xh2h-5w4j.json b/advisories/unreviewed/2022/05/GHSA-fmjm-xh2h-5w4j/GHSA-fmjm-xh2h-5w4j.json index f01faff13cd..6c3dee0a35f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmjm-xh2h-5w4j/GHSA-fmjm-xh2h-5w4j.json +++ b/advisories/unreviewed/2022/05/GHSA-fmjm-xh2h-5w4j/GHSA-fmjm-xh2h-5w4j.json @@ -7,12 +7,8 @@ "CVE-2005-3957" ], "details": "Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fp6q-wmwj-3m9p/GHSA-fp6q-wmwj-3m9p.json b/advisories/unreviewed/2022/05/GHSA-fp6q-wmwj-3m9p/GHSA-fp6q-wmwj-3m9p.json index 3f3ade570f8..7c4ed2867cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp6q-wmwj-3m9p/GHSA-fp6q-wmwj-3m9p.json +++ b/advisories/unreviewed/2022/05/GHSA-fp6q-wmwj-3m9p/GHSA-fp6q-wmwj-3m9p.json @@ -7,12 +7,8 @@ "CVE-2021-24517" ], "details": "The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpxv-r955-frj8/GHSA-fpxv-r955-frj8.json b/advisories/unreviewed/2022/05/GHSA-fpxv-r955-frj8/GHSA-fpxv-r955-frj8.json index 06f0c200f45..19cd7dfca91 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpxv-r955-frj8/GHSA-fpxv-r955-frj8.json +++ b/advisories/unreviewed/2022/05/GHSA-fpxv-r955-frj8/GHSA-fpxv-r955-frj8.json @@ -7,12 +7,8 @@ "CVE-2005-4332" ], "details": "Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmware_action.jsp, and (3) file.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fqc6-r979-86v4/GHSA-fqc6-r979-86v4.json b/advisories/unreviewed/2022/05/GHSA-fqc6-r979-86v4/GHSA-fqc6-r979-86v4.json index 4358d982baa..02ea6d4020c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqc6-r979-86v4/GHSA-fqc6-r979-86v4.json +++ b/advisories/unreviewed/2022/05/GHSA-fqc6-r979-86v4/GHSA-fqc6-r979-86v4.json @@ -7,12 +7,8 @@ "CVE-2021-38316" ], "details": "The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name parameter in the ~/admin-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.4.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frfj-xhqr-qppx/GHSA-frfj-xhqr-qppx.json b/advisories/unreviewed/2022/05/GHSA-frfj-xhqr-qppx/GHSA-frfj-xhqr-qppx.json index 0358ac652df..9e347a10be8 100644 --- a/advisories/unreviewed/2022/05/GHSA-frfj-xhqr-qppx/GHSA-frfj-xhqr-qppx.json +++ b/advisories/unreviewed/2022/05/GHSA-frfj-xhqr-qppx/GHSA-frfj-xhqr-qppx.json @@ -7,12 +7,8 @@ "CVE-2021-30715" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted message may lead to a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-frfq-mg43-f6jj/GHSA-frfq-mg43-f6jj.json b/advisories/unreviewed/2022/05/GHSA-frfq-mg43-f6jj/GHSA-frfq-mg43-f6jj.json index 02ade38c998..865258d653c 100644 --- a/advisories/unreviewed/2022/05/GHSA-frfq-mg43-f6jj/GHSA-frfq-mg43-f6jj.json +++ b/advisories/unreviewed/2022/05/GHSA-frfq-mg43-f6jj/GHSA-frfq-mg43-f6jj.json @@ -7,12 +7,8 @@ "CVE-2021-1762" ], "details": "An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frm8-c9x4-2pg5/GHSA-frm8-c9x4-2pg5.json b/advisories/unreviewed/2022/05/GHSA-frm8-c9x4-2pg5/GHSA-frm8-c9x4-2pg5.json index 5ad95f263df..0bebec871b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-frm8-c9x4-2pg5/GHSA-frm8-c9x4-2pg5.json +++ b/advisories/unreviewed/2022/05/GHSA-frm8-c9x4-2pg5/GHSA-frm8-c9x4-2pg5.json @@ -7,12 +7,8 @@ "CVE-2005-4250" ], "details": "Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwcv-f59x-qg35/GHSA-fwcv-f59x-qg35.json b/advisories/unreviewed/2022/05/GHSA-fwcv-f59x-qg35/GHSA-fwcv-f59x-qg35.json index 7d92aa468a4..bff9d8c4728 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwcv-f59x-qg35/GHSA-fwcv-f59x-qg35.json +++ b/advisories/unreviewed/2022/05/GHSA-fwcv-f59x-qg35/GHSA-fwcv-f59x-qg35.json @@ -7,12 +7,8 @@ "CVE-2005-4279" ], "details": "Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwqw-65p3-5cgj/GHSA-fwqw-65p3-5cgj.json b/advisories/unreviewed/2022/05/GHSA-fwqw-65p3-5cgj/GHSA-fwqw-65p3-5cgj.json index ad7cf991a5b..a85a0043620 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwqw-65p3-5cgj/GHSA-fwqw-65p3-5cgj.json +++ b/advisories/unreviewed/2022/05/GHSA-fwqw-65p3-5cgj/GHSA-fwqw-65p3-5cgj.json @@ -7,12 +7,8 @@ "CVE-2021-30775" ], "details": "A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted audio file may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fww6-qcmh-hvxh/GHSA-fww6-qcmh-hvxh.json b/advisories/unreviewed/2022/05/GHSA-fww6-qcmh-hvxh/GHSA-fww6-qcmh-hvxh.json index 5ff42a4a5b9..bbde7e05994 100644 --- a/advisories/unreviewed/2022/05/GHSA-fww6-qcmh-hvxh/GHSA-fww6-qcmh-hvxh.json +++ b/advisories/unreviewed/2022/05/GHSA-fww6-qcmh-hvxh/GHSA-fww6-qcmh-hvxh.json @@ -7,12 +7,8 @@ "CVE-2021-30611" ], "details": "Use after free in WebRTC in Google Chrome on Linux, ChromeOS prior to 93.0.4577.63 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx3m-586f-fprw/GHSA-fx3m-586f-fprw.json b/advisories/unreviewed/2022/05/GHSA-fx3m-586f-fprw/GHSA-fx3m-586f-fprw.json index c453574620b..05b8baa4344 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx3m-586f-fprw/GHSA-fx3m-586f-fprw.json +++ b/advisories/unreviewed/2022/05/GHSA-fx3m-586f-fprw/GHSA-fx3m-586f-fprw.json @@ -7,12 +7,8 @@ "CVE-2021-37200" ], "details": "A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). An attacker with access to the webserver of an affected system could download arbitrary files from the underlying filesystem by sending a specially crafted HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx72-qxjg-3p34/GHSA-fx72-qxjg-3p34.json b/advisories/unreviewed/2022/05/GHSA-fx72-qxjg-3p34/GHSA-fx72-qxjg-3p34.json index 2768b08542a..236198d9aef 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx72-qxjg-3p34/GHSA-fx72-qxjg-3p34.json +++ b/advisories/unreviewed/2022/05/GHSA-fx72-qxjg-3p34/GHSA-fx72-qxjg-3p34.json @@ -7,12 +7,8 @@ "CVE-2005-4305" ], "details": "Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fxfq-qgmr-6pwm/GHSA-fxfq-qgmr-6pwm.json b/advisories/unreviewed/2022/05/GHSA-fxfq-qgmr-6pwm/GHSA-fxfq-qgmr-6pwm.json index 242689c4875..10c63e7a24a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxfq-qgmr-6pwm/GHSA-fxfq-qgmr-6pwm.json +++ b/advisories/unreviewed/2022/05/GHSA-fxfq-qgmr-6pwm/GHSA-fxfq-qgmr-6pwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3ff-6f3f-hmmm/GHSA-g3ff-6f3f-hmmm.json b/advisories/unreviewed/2022/05/GHSA-g3ff-6f3f-hmmm/GHSA-g3ff-6f3f-hmmm.json index ae521c69f7f..972ad387eee 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3ff-6f3f-hmmm/GHSA-g3ff-6f3f-hmmm.json +++ b/advisories/unreviewed/2022/05/GHSA-g3ff-6f3f-hmmm/GHSA-g3ff-6f3f-hmmm.json @@ -7,12 +7,8 @@ "CVE-2005-4213" ], "details": "SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g3g5-fx3c-q38p/GHSA-g3g5-fx3c-q38p.json b/advisories/unreviewed/2022/05/GHSA-g3g5-fx3c-q38p/GHSA-g3g5-fx3c-q38p.json index 9a1eb0b5328..db318aa669e 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3g5-fx3c-q38p/GHSA-g3g5-fx3c-q38p.json +++ b/advisories/unreviewed/2022/05/GHSA-g3g5-fx3c-q38p/GHSA-g3g5-fx3c-q38p.json @@ -7,12 +7,8 @@ "CVE-2021-30677" ], "details": "This issue was addressed with improved environment sanitization. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to break out of its sandbox.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g3rq-5w5q-9rf3/GHSA-g3rq-5w5q-9rf3.json b/advisories/unreviewed/2022/05/GHSA-g3rq-5w5q-9rf3/GHSA-g3rq-5w5q-9rf3.json index fa0e3bbf7f1..2110abfd1ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3rq-5w5q-9rf3/GHSA-g3rq-5w5q-9rf3.json +++ b/advisories/unreviewed/2022/05/GHSA-g3rq-5w5q-9rf3/GHSA-g3rq-5w5q-9rf3.json @@ -7,12 +7,8 @@ "CVE-2005-4318" ], "details": "SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers to execute arbitrary SQL commands via the _SERVER[REMOTE_ADDR] parameter, which modifies the underlying $_SERVER variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g45r-9j86-hw63/GHSA-g45r-9j86-hw63.json b/advisories/unreviewed/2022/05/GHSA-g45r-9j86-hw63/GHSA-g45r-9j86-hw63.json index d64a48e41aa..b52705c44b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g45r-9j86-hw63/GHSA-g45r-9j86-hw63.json +++ b/advisories/unreviewed/2022/05/GHSA-g45r-9j86-hw63/GHSA-g45r-9j86-hw63.json @@ -7,12 +7,8 @@ "CVE-2005-3951" ], "details": "SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g464-39xh-j4rf/GHSA-g464-39xh-j4rf.json b/advisories/unreviewed/2022/05/GHSA-g464-39xh-j4rf/GHSA-g464-39xh-j4rf.json index 8778f10fbbd..14f796b0543 100644 --- a/advisories/unreviewed/2022/05/GHSA-g464-39xh-j4rf/GHSA-g464-39xh-j4rf.json +++ b/advisories/unreviewed/2022/05/GHSA-g464-39xh-j4rf/GHSA-g464-39xh-j4rf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g4fc-j79q-gjrh/GHSA-g4fc-j79q-gjrh.json b/advisories/unreviewed/2022/05/GHSA-g4fc-j79q-gjrh/GHSA-g4fc-j79q-gjrh.json index e40e44827ad..5d557fb1675 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4fc-j79q-gjrh/GHSA-g4fc-j79q-gjrh.json +++ b/advisories/unreviewed/2022/05/GHSA-g4fc-j79q-gjrh/GHSA-g4fc-j79q-gjrh.json @@ -7,12 +7,8 @@ "CVE-2005-4294" ], "details": "Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the username in the login page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g4w8-pfqw-c67x/GHSA-g4w8-pfqw-c67x.json b/advisories/unreviewed/2022/05/GHSA-g4w8-pfqw-c67x/GHSA-g4w8-pfqw-c67x.json index 51f8200b9fe..5d80482b76c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4w8-pfqw-c67x/GHSA-g4w8-pfqw-c67x.json +++ b/advisories/unreviewed/2022/05/GHSA-g4w8-pfqw-c67x/GHSA-g4w8-pfqw-c67x.json @@ -7,12 +7,8 @@ "CVE-2021-33685" ], "details": "SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or directories that are outside of the restricted directory. A successful attack allows access to high level sensitive data", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g582-rhhm-jpjg/GHSA-g582-rhhm-jpjg.json b/advisories/unreviewed/2022/05/GHSA-g582-rhhm-jpjg/GHSA-g582-rhhm-jpjg.json index 661817f929c..b3796f89171 100644 --- a/advisories/unreviewed/2022/05/GHSA-g582-rhhm-jpjg/GHSA-g582-rhhm-jpjg.json +++ b/advisories/unreviewed/2022/05/GHSA-g582-rhhm-jpjg/GHSA-g582-rhhm-jpjg.json @@ -7,12 +7,8 @@ "CVE-2005-4040" ], "details": "SQL injection vulnerability in FileLister 0.51 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameters, possibly the searchwhat parameter to definesearch.jsp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6mx-39w4-hq8g/GHSA-g6mx-39w4-hq8g.json b/advisories/unreviewed/2022/05/GHSA-g6mx-39w4-hq8g/GHSA-g6mx-39w4-hq8g.json index 4524d34c39c..d8cd4ba6258 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6mx-39w4-hq8g/GHSA-g6mx-39w4-hq8g.json +++ b/advisories/unreviewed/2022/05/GHSA-g6mx-39w4-hq8g/GHSA-g6mx-39w4-hq8g.json @@ -7,12 +7,8 @@ "CVE-2005-4226" ], "details": "Multiple \"potential\" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1) the ref parameter in download.php, (2) the direction, msg, sforum, reason, subname, and toform parameters in forum.php, (3) the msg and forum parameters in forum_edit.php, (4) the msg and forum parameters in forum_write.php, (5) the tekst parameter in guestbook.php, (6) the menuoption parameter in index.php, and the (7) sel_avatar parameter in myaccount.php. NOTE: the forum.php/forum vector is already identified by CVE-2005-3585.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6v2-6f4v-g5x2/GHSA-g6v2-6f4v-g5x2.json b/advisories/unreviewed/2022/05/GHSA-g6v2-6f4v-g5x2/GHSA-g6v2-6f4v-g5x2.json index 569854b5467..27e14cea263 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6v2-6f4v-g5x2/GHSA-g6v2-6f4v-g5x2.json +++ b/advisories/unreviewed/2022/05/GHSA-g6v2-6f4v-g5x2/GHSA-g6v2-6f4v-g5x2.json @@ -7,12 +7,8 @@ "CVE-2005-4369" ], "details": "Cross-site scripting (XSS) vulnerability in Acuity CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly strSearchKeywords to browse.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7cf-4hgh-v7qf/GHSA-g7cf-4hgh-v7qf.json b/advisories/unreviewed/2022/05/GHSA-g7cf-4hgh-v7qf/GHSA-g7cf-4hgh-v7qf.json index c5b7bd1cc37..12dade8e822 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7cf-4hgh-v7qf/GHSA-g7cf-4hgh-v7qf.json +++ b/advisories/unreviewed/2022/05/GHSA-g7cf-4hgh-v7qf/GHSA-g7cf-4hgh-v7qf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7wm-23xp-52w7/GHSA-g7wm-23xp-52w7.json b/advisories/unreviewed/2022/05/GHSA-g7wm-23xp-52w7/GHSA-g7wm-23xp-52w7.json index 27a5bb0d9d7..d06818d4c34 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7wm-23xp-52w7/GHSA-g7wm-23xp-52w7.json +++ b/advisories/unreviewed/2022/05/GHSA-g7wm-23xp-52w7/GHSA-g7wm-23xp-52w7.json @@ -7,12 +7,8 @@ "CVE-2005-3910" ], "details": "merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g862-phf8-4g6f/GHSA-g862-phf8-4g6f.json b/advisories/unreviewed/2022/05/GHSA-g862-phf8-4g6f/GHSA-g862-phf8-4g6f.json index af459eba53d..986fe1be88e 100644 --- a/advisories/unreviewed/2022/05/GHSA-g862-phf8-4g6f/GHSA-g862-phf8-4g6f.json +++ b/advisories/unreviewed/2022/05/GHSA-g862-phf8-4g6f/GHSA-g862-phf8-4g6f.json @@ -7,12 +7,8 @@ "CVE-2005-4399" ], "details": "Cross-site scripting (XSS) vulnerability in search/index.php in Libertas Enterprise CMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page_search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8rq-cfjj-j3hv/GHSA-g8rq-cfjj-j3hv.json b/advisories/unreviewed/2022/05/GHSA-g8rq-cfjj-j3hv/GHSA-g8rq-cfjj-j3hv.json index 90cf6d2f627..53512285c78 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8rq-cfjj-j3hv/GHSA-g8rq-cfjj-j3hv.json +++ b/advisories/unreviewed/2022/05/GHSA-g8rq-cfjj-j3hv/GHSA-g8rq-cfjj-j3hv.json @@ -7,12 +7,8 @@ "CVE-2021-32835" ], "details": "Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerability may lead to post-authentication Remote Code execution. This vulnerability is known to exist in the latest commit at the time of writing this CVE (commit a1c8dbe). For more details see the referenced GHSL-2021-063.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9h8-qwjr-wjcp/GHSA-g9h8-qwjr-wjcp.json b/advisories/unreviewed/2022/05/GHSA-g9h8-qwjr-wjcp/GHSA-g9h8-qwjr-wjcp.json index f0007e23952..0bbad4055e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9h8-qwjr-wjcp/GHSA-g9h8-qwjr-wjcp.json +++ b/advisories/unreviewed/2022/05/GHSA-g9h8-qwjr-wjcp/GHSA-g9h8-qwjr-wjcp.json @@ -7,12 +7,8 @@ "CVE-2005-4383" ], "details": "Cross-site scripting (XSS) vulnerability in index.cfm in CitySoft Community Enterprise 4.x allows remote attackers to inject arbitrary web script or HTML via the (1) presentationSite, (2) docPublishYear, (3) docDescription, (4) publishState, (5) docAuthor, (6) docTitle, (7) subTopic, (8) topic, (9) topicRadio, (10) topicOnly, (11) startrow, and (12) sortby parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gc4c-2wvp-mgjx/GHSA-gc4c-2wvp-mgjx.json b/advisories/unreviewed/2022/05/GHSA-gc4c-2wvp-mgjx/GHSA-gc4c-2wvp-mgjx.json index ce5c5a457f8..5e661f9b018 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc4c-2wvp-mgjx/GHSA-gc4c-2wvp-mgjx.json +++ b/advisories/unreviewed/2022/05/GHSA-gc4c-2wvp-mgjx/GHSA-gc4c-2wvp-mgjx.json @@ -7,12 +7,8 @@ "CVE-2005-4375" ], "details": "Cross-site scripting (XSS) vulnerability in Amaxus 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the change parameter. NOTE: it is possible that this is resultant from CVE-2005-4376.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gc6j-585v-g367/GHSA-gc6j-585v-g367.json b/advisories/unreviewed/2022/05/GHSA-gc6j-585v-g367/GHSA-gc6j-585v-g367.json index 5837e90f21b..497934f7ea2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc6j-585v-g367/GHSA-gc6j-585v-g367.json +++ b/advisories/unreviewed/2022/05/GHSA-gc6j-585v-g367/GHSA-gc6j-585v-g367.json @@ -7,12 +7,8 @@ "CVE-2021-30678" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcv5-33hh-8rwr/GHSA-gcv5-33hh-8rwr.json b/advisories/unreviewed/2022/05/GHSA-gcv5-33hh-8rwr/GHSA-gcv5-33hh-8rwr.json index a477b56cc1a..144586557f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcv5-33hh-8rwr/GHSA-gcv5-33hh-8rwr.json +++ b/advisories/unreviewed/2022/05/GHSA-gcv5-33hh-8rwr/GHSA-gcv5-33hh-8rwr.json @@ -7,12 +7,8 @@ "CVE-2020-20345" ], "details": "WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcxf-4jrr-qpg3/GHSA-gcxf-4jrr-qpg3.json b/advisories/unreviewed/2022/05/GHSA-gcxf-4jrr-qpg3/GHSA-gcxf-4jrr-qpg3.json index 28aeb803915..32555740eac 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcxf-4jrr-qpg3/GHSA-gcxf-4jrr-qpg3.json +++ b/advisories/unreviewed/2022/05/GHSA-gcxf-4jrr-qpg3/GHSA-gcxf-4jrr-qpg3.json @@ -7,12 +7,8 @@ "CVE-2021-34732" ], "details": "A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf4j-2pqh-6c38/GHSA-gf4j-2pqh-6c38.json b/advisories/unreviewed/2022/05/GHSA-gf4j-2pqh-6c38/GHSA-gf4j-2pqh-6c38.json index 837681f4401..962a162c30a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf4j-2pqh-6c38/GHSA-gf4j-2pqh-6c38.json +++ b/advisories/unreviewed/2022/05/GHSA-gf4j-2pqh-6c38/GHSA-gf4j-2pqh-6c38.json @@ -7,12 +7,8 @@ "CVE-2021-1865" ], "details": "An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfmf-9j98-4w68/GHSA-gfmf-9j98-4w68.json b/advisories/unreviewed/2022/05/GHSA-gfmf-9j98-4w68/GHSA-gfmf-9j98-4w68.json index dcfd6b65ae4..a4e9b08e541 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfmf-9j98-4w68/GHSA-gfmf-9j98-4w68.json +++ b/advisories/unreviewed/2022/05/GHSA-gfmf-9j98-4w68/GHSA-gfmf-9j98-4w68.json @@ -7,12 +7,8 @@ "CVE-2005-4163" ], "details": "Directory traversal vulnerability in captcha.php in Captcha PHP 0.9 allows remote attackers to read arbitrary files via the _tcf parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gg35-v4g5-3323/GHSA-gg35-v4g5-3323.json b/advisories/unreviewed/2022/05/GHSA-gg35-v4g5-3323/GHSA-gg35-v4g5-3323.json index e364faf6f84..0d140637054 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg35-v4g5-3323/GHSA-gg35-v4g5-3323.json +++ b/advisories/unreviewed/2022/05/GHSA-gg35-v4g5-3323/GHSA-gg35-v4g5-3323.json @@ -7,12 +7,8 @@ "CVE-2021-30774" ], "details": "A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. A malicious application may be able to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ggcc-jfxp-hxph/GHSA-ggcc-jfxp-hxph.json b/advisories/unreviewed/2022/05/GHSA-ggcc-jfxp-hxph/GHSA-ggcc-jfxp-hxph.json index 70236572c6d..ea6cd27b77e 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggcc-jfxp-hxph/GHSA-ggcc-jfxp-hxph.json +++ b/advisories/unreviewed/2022/05/GHSA-ggcc-jfxp-hxph/GHSA-ggcc-jfxp-hxph.json @@ -7,12 +7,8 @@ "CVE-2021-30769" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggcm-cr9q-hv99/GHSA-ggcm-cr9q-hv99.json b/advisories/unreviewed/2022/05/GHSA-ggcm-cr9q-hv99/GHSA-ggcm-cr9q-hv99.json index 35b807a8dad..1da217a57d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggcm-cr9q-hv99/GHSA-ggcm-cr9q-hv99.json +++ b/advisories/unreviewed/2022/05/GHSA-ggcm-cr9q-hv99/GHSA-ggcm-cr9q-hv99.json @@ -7,12 +7,8 @@ "CVE-2021-34713" ], "details": "A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot. This vulnerability is due to incorrect handling of specific Ethernet frames that cause a spin loop that can make the network processors unresponsive. An attacker could exploit this vulnerability by sending specific types of Ethernet frames on the segment where the affected line cards are attached. A successful exploit could allow the attacker to cause the affected line card to reboot.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ggf5-69xh-578m/GHSA-ggf5-69xh-578m.json b/advisories/unreviewed/2022/05/GHSA-ggf5-69xh-578m/GHSA-ggf5-69xh-578m.json index 5e6942c1cc9..2c4d8e08920 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggf5-69xh-578m/GHSA-ggf5-69xh-578m.json +++ b/advisories/unreviewed/2022/05/GHSA-ggf5-69xh-578m/GHSA-ggf5-69xh-578m.json @@ -7,12 +7,8 @@ "CVE-2021-37532" ], "details": "SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj43-r55q-5h6r/GHSA-gj43-r55q-5h6r.json b/advisories/unreviewed/2022/05/GHSA-gj43-r55q-5h6r/GHSA-gj43-r55q-5h6r.json index 7e849cf8010..d18927b7c81 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj43-r55q-5h6r/GHSA-gj43-r55q-5h6r.json +++ b/advisories/unreviewed/2022/05/GHSA-gj43-r55q-5h6r/GHSA-gj43-r55q-5h6r.json @@ -7,12 +7,8 @@ "CVE-2021-3758" ], "details": "bookstack is vulnerable to Server-Side Request Forgery (SSRF)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjhp-fhfw-fvx3/GHSA-gjhp-fhfw-fvx3.json b/advisories/unreviewed/2022/05/GHSA-gjhp-fhfw-fvx3/GHSA-gjhp-fhfw-fvx3.json index eaa62648f40..bf22fd958fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjhp-fhfw-fvx3/GHSA-gjhp-fhfw-fvx3.json +++ b/advisories/unreviewed/2022/05/GHSA-gjhp-fhfw-fvx3/GHSA-gjhp-fhfw-fvx3.json @@ -7,12 +7,8 @@ "CVE-2021-31609" ], "details": "The Bluetooth Classic implementation in Silicon Labs iWRAP 6.3.0 and earlier does not properly handle the reception of an oversized LMP packet greater than 17 bytes, allowing attackers in radio range to trigger a crash in WT32i via a crafted LMP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjj2-426f-v32h/GHSA-gjj2-426f-v32h.json b/advisories/unreviewed/2022/05/GHSA-gjj2-426f-v32h/GHSA-gjj2-426f-v32h.json index 89f8b37fd2c..1ec92246a47 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjj2-426f-v32h/GHSA-gjj2-426f-v32h.json +++ b/advisories/unreviewed/2022/05/GHSA-gjj2-426f-v32h/GHSA-gjj2-426f-v32h.json @@ -7,12 +7,8 @@ "CVE-2005-4083" ], "details": "Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gp48-r6vg-ff9x/GHSA-gp48-r6vg-ff9x.json b/advisories/unreviewed/2022/05/GHSA-gp48-r6vg-ff9x/GHSA-gp48-r6vg-ff9x.json index d373c4b886b..f30e5f4273a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp48-r6vg-ff9x/GHSA-gp48-r6vg-ff9x.json +++ b/advisories/unreviewed/2022/05/GHSA-gp48-r6vg-ff9x/GHSA-gp48-r6vg-ff9x.json @@ -7,12 +7,8 @@ "CVE-2005-4256" ], "details": "Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID. In addition, its accuracy is in question because \"forum_title\" does not appear to be specified in the source code for XM Forum RC3. It is possible, but not certain, that this is CVE-2004-2211.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gpj5-98pq-4552/GHSA-gpj5-98pq-4552.json b/advisories/unreviewed/2022/05/GHSA-gpj5-98pq-4552/GHSA-gpj5-98pq-4552.json index eef006d88c2..eae4b12e963 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpj5-98pq-4552/GHSA-gpj5-98pq-4552.json +++ b/advisories/unreviewed/2022/05/GHSA-gpj5-98pq-4552/GHSA-gpj5-98pq-4552.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-gpjh-g6x2-2qg7/GHSA-gpjh-g6x2-2qg7.json b/advisories/unreviewed/2022/05/GHSA-gpjh-g6x2-2qg7/GHSA-gpjh-g6x2-2qg7.json index 2477b6bdc4c..551aa4a4e79 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpjh-g6x2-2qg7/GHSA-gpjh-g6x2-2qg7.json +++ b/advisories/unreviewed/2022/05/GHSA-gpjh-g6x2-2qg7/GHSA-gpjh-g6x2-2qg7.json @@ -7,12 +7,8 @@ "CVE-2005-4195" ], "details": "Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the ParentId parameter in SPT--BrowseResources.php, (2) ResourceId parameter in SPT--FullRecord.php, (3) ResourceOffset parameter in SPT--Home.php, and (4) F_UserName and (5) F_Password in SPT--UserLogin.php. NOTE: it was later reported that vector 1 is also present in 1.4.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gppg-373r-fpj5/GHSA-gppg-373r-fpj5.json b/advisories/unreviewed/2022/05/GHSA-gppg-373r-fpj5/GHSA-gppg-373r-fpj5.json index 1857e482688..869e73c0133 100644 --- a/advisories/unreviewed/2022/05/GHSA-gppg-373r-fpj5/GHSA-gppg-373r-fpj5.json +++ b/advisories/unreviewed/2022/05/GHSA-gppg-373r-fpj5/GHSA-gppg-373r-fpj5.json @@ -7,12 +7,8 @@ "CVE-2021-30606" ], "details": "Use after free in Blink in Google Chrome prior to 93.0.4577.63 allowed an attacker who convinced a user to drag and drop a malicous folder to a page to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gpvc-2qwg-r73m/GHSA-gpvc-2qwg-r73m.json b/advisories/unreviewed/2022/05/GHSA-gpvc-2qwg-r73m/GHSA-gpvc-2qwg-r73m.json index 4e7d7796ce5..1930d3e5f13 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpvc-2qwg-r73m/GHSA-gpvc-2qwg-r73m.json +++ b/advisories/unreviewed/2022/05/GHSA-gpvc-2qwg-r73m/GHSA-gpvc-2qwg-r73m.json @@ -7,12 +7,8 @@ "CVE-2021-34143" ], "details": "The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after paging procedure. User intervention is required to restart the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqc5-fq98-6v4q/GHSA-gqc5-fq98-6v4q.json b/advisories/unreviewed/2022/05/GHSA-gqc5-fq98-6v4q/GHSA-gqc5-fq98-6v4q.json index dd2d3646467..967fcb7edac 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqc5-fq98-6v4q/GHSA-gqc5-fq98-6v4q.json +++ b/advisories/unreviewed/2022/05/GHSA-gqc5-fq98-6v4q/GHSA-gqc5-fq98-6v4q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqgg-4792-53wc/GHSA-gqgg-4792-53wc.json b/advisories/unreviewed/2022/05/GHSA-gqgg-4792-53wc/GHSA-gqgg-4792-53wc.json index abd62748944..fa7116ae125 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqgg-4792-53wc/GHSA-gqgg-4792-53wc.json +++ b/advisories/unreviewed/2022/05/GHSA-gqgg-4792-53wc/GHSA-gqgg-4792-53wc.json @@ -7,12 +7,8 @@ "CVE-2005-4075" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) newsid parameter in the news sector, and (3) cat parameter in the links sector.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr24-p6jg-5222/GHSA-gr24-p6jg-5222.json b/advisories/unreviewed/2022/05/GHSA-gr24-p6jg-5222/GHSA-gr24-p6jg-5222.json index fd0c6d93e48..e20f333c378 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr24-p6jg-5222/GHSA-gr24-p6jg-5222.json +++ b/advisories/unreviewed/2022/05/GHSA-gr24-p6jg-5222/GHSA-gr24-p6jg-5222.json @@ -7,12 +7,8 @@ "CVE-2005-4028" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in aMember allow remote attackers to inject arbitrary web script or HTML via the (1) lamember_login parameter to sendpass.php and (2) login parameter to member.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr6c-576g-h3q2/GHSA-gr6c-576g-h3q2.json b/advisories/unreviewed/2022/05/GHSA-gr6c-576g-h3q2/GHSA-gr6c-576g-h3q2.json index 5cc1ee5152a..3148ed6f50c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr6c-576g-h3q2/GHSA-gr6c-576g-h3q2.json +++ b/advisories/unreviewed/2022/05/GHSA-gr6c-576g-h3q2/GHSA-gr6c-576g-h3q2.json @@ -7,12 +7,8 @@ "CVE-2021-1857" ], "details": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitive user information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grq2-2v86-6ppx/GHSA-grq2-2v86-6ppx.json b/advisories/unreviewed/2022/05/GHSA-grq2-2v86-6ppx/GHSA-grq2-2v86-6ppx.json index 1be8d411bdf..7fb5a394eb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-grq2-2v86-6ppx/GHSA-grq2-2v86-6ppx.json +++ b/advisories/unreviewed/2022/05/GHSA-grq2-2v86-6ppx/GHSA-grq2-2v86-6ppx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv66-cg63-7j52/GHSA-gv66-cg63-7j52.json b/advisories/unreviewed/2022/05/GHSA-gv66-cg63-7j52/GHSA-gv66-cg63-7j52.json index 7e375d75dd7..d515cffdfa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv66-cg63-7j52/GHSA-gv66-cg63-7j52.json +++ b/advisories/unreviewed/2022/05/GHSA-gv66-cg63-7j52/GHSA-gv66-cg63-7j52.json @@ -7,12 +7,8 @@ "CVE-2005-4373" ], "details": "Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvph-v5gg-8pcr/GHSA-gvph-v5gg-8pcr.json b/advisories/unreviewed/2022/05/GHSA-gvph-v5gg-8pcr/GHSA-gvph-v5gg-8pcr.json index c2e9737117e..ab3f7a14097 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvph-v5gg-8pcr/GHSA-gvph-v5gg-8pcr.json +++ b/advisories/unreviewed/2022/05/GHSA-gvph-v5gg-8pcr/GHSA-gvph-v5gg-8pcr.json @@ -7,12 +7,8 @@ "CVE-2005-4343" ], "details": "Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka \"CFMAIL injection Vulnerability\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gvww-85jq-9q22/GHSA-gvww-85jq-9q22.json b/advisories/unreviewed/2022/05/GHSA-gvww-85jq-9q22/GHSA-gvww-85jq-9q22.json index fa1e866ca09..d8d9bb05543 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvww-85jq-9q22/GHSA-gvww-85jq-9q22.json +++ b/advisories/unreviewed/2022/05/GHSA-gvww-85jq-9q22/GHSA-gvww-85jq-9q22.json @@ -7,12 +7,8 @@ "CVE-2021-23048" ], "details": "On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, when GPRS Tunneling Protocol (GTP) iRules commands or a GTP profile is configured on a virtual server, undisclosed GTP messages can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gw58-6f33-3447/GHSA-gw58-6f33-3447.json b/advisories/unreviewed/2022/05/GHSA-gw58-6f33-3447/GHSA-gw58-6f33-3447.json index b839c0b4e71..baf196ae837 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw58-6f33-3447/GHSA-gw58-6f33-3447.json +++ b/advisories/unreviewed/2022/05/GHSA-gw58-6f33-3447/GHSA-gw58-6f33-3447.json @@ -7,12 +7,8 @@ "CVE-2021-22704" ], "details": "A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw88-r7fv-vm9q/GHSA-gw88-r7fv-vm9q.json b/advisories/unreviewed/2022/05/GHSA-gw88-r7fv-vm9q/GHSA-gw88-r7fv-vm9q.json index e7571ad53db..6b0eb54008f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw88-r7fv-vm9q/GHSA-gw88-r7fv-vm9q.json +++ b/advisories/unreviewed/2022/05/GHSA-gw88-r7fv-vm9q/GHSA-gw88-r7fv-vm9q.json @@ -7,12 +7,8 @@ "CVE-2005-4376" ], "details": "Directory traversal vulnerability in Amaxus 3 and earlier allows remote attackers to access arbitrary files via \"..\" sequences in the change parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwjf-hjm7-xvq3/GHSA-gwjf-hjm7-xvq3.json b/advisories/unreviewed/2022/05/GHSA-gwjf-hjm7-xvq3/GHSA-gwjf-hjm7-xvq3.json index 2226bda1d12..f9393c27d1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwjf-hjm7-xvq3/GHSA-gwjf-hjm7-xvq3.json +++ b/advisories/unreviewed/2022/05/GHSA-gwjf-hjm7-xvq3/GHSA-gwjf-hjm7-xvq3.json @@ -7,12 +7,8 @@ "CVE-2021-30755" ], "details": "Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5. An out-of-bounds read was addressed with improved input validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gww8-rh9f-5mjq/GHSA-gww8-rh9f-5mjq.json b/advisories/unreviewed/2022/05/GHSA-gww8-rh9f-5mjq/GHSA-gww8-rh9f-5mjq.json index a4e52ba1242..b197800fdf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gww8-rh9f-5mjq/GHSA-gww8-rh9f-5mjq.json +++ b/advisories/unreviewed/2022/05/GHSA-gww8-rh9f-5mjq/GHSA-gww8-rh9f-5mjq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwwq-j5vg-7jc3/GHSA-gwwq-j5vg-7jc3.json b/advisories/unreviewed/2022/05/GHSA-gwwq-j5vg-7jc3/GHSA-gwwq-j5vg-7jc3.json index f1ec807c9fd..e1503a84a00 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwwq-j5vg-7jc3/GHSA-gwwq-j5vg-7jc3.json +++ b/advisories/unreviewed/2022/05/GHSA-gwwq-j5vg-7jc3/GHSA-gwwq-j5vg-7jc3.json @@ -7,12 +7,8 @@ "CVE-2021-38317" ], "details": "The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in the ~/views/subscriptions.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.8.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwxq-89pj-48g2/GHSA-gwxq-89pj-48g2.json b/advisories/unreviewed/2022/05/GHSA-gwxq-89pj-48g2/GHSA-gwxq-89pj-48g2.json index f4a32224082..984788ce360 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwxq-89pj-48g2/GHSA-gwxq-89pj-48g2.json +++ b/advisories/unreviewed/2022/05/GHSA-gwxq-89pj-48g2/GHSA-gwxq-89pj-48g2.json @@ -7,12 +7,8 @@ "CVE-2005-4264" ], "details": "Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gx5h-wrvw-rqjf/GHSA-gx5h-wrvw-rqjf.json b/advisories/unreviewed/2022/05/GHSA-gx5h-wrvw-rqjf/GHSA-gx5h-wrvw-rqjf.json index 26f6706cbbb..711d58492c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx5h-wrvw-rqjf/GHSA-gx5h-wrvw-rqjf.json +++ b/advisories/unreviewed/2022/05/GHSA-gx5h-wrvw-rqjf/GHSA-gx5h-wrvw-rqjf.json @@ -7,12 +7,8 @@ "CVE-2005-4006" ], "details": "SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) insert_image.php, (3) insert_link.php, (4) insert_qcfile.php, and (5) edit.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxwg-94gc-r879/GHSA-gxwg-94gc-r879.json b/advisories/unreviewed/2022/05/GHSA-gxwg-94gc-r879/GHSA-gxwg-94gc-r879.json index a97246c1651..71909a50554 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxwg-94gc-r879/GHSA-gxwg-94gc-r879.json +++ b/advisories/unreviewed/2022/05/GHSA-gxwg-94gc-r879/GHSA-gxwg-94gc-r879.json @@ -7,12 +7,8 @@ "CVE-2021-34150" ], "details": "The Bluetooth Classic implementation on Bluetrum AB5301A devices with unknown firmware versions does not properly handle the reception of oversized DM1 LMP packets while no other BT connections are active, allowing attackers in radio range to prevent new BT connections (disabling the AB5301A inquiry and page scan procedures) via a crafted LMP packet. The user needs to manually perform a power cycle (restart) of the device to restore BT connectivity.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h222-ch2w-vqfv/GHSA-h222-ch2w-vqfv.json b/advisories/unreviewed/2022/05/GHSA-h222-ch2w-vqfv/GHSA-h222-ch2w-vqfv.json index 59c76ecb9cd..7a9abd889c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-h222-ch2w-vqfv/GHSA-h222-ch2w-vqfv.json +++ b/advisories/unreviewed/2022/05/GHSA-h222-ch2w-vqfv/GHSA-h222-ch2w-vqfv.json @@ -7,12 +7,8 @@ "CVE-2005-4320" ], "details": "Limbo CMS 1.0.4.2 and earlier allows remote attackers to obtain the installation path of the application via a direct request to (1) doc.inc.php, (2) element.inc.php, and (3) node.inc.php, which leaks the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3qw-4vm7-5c48/GHSA-h3qw-4vm7-5c48.json b/advisories/unreviewed/2022/05/GHSA-h3qw-4vm7-5c48/GHSA-h3qw-4vm7-5c48.json index c128eea9e32..a138914eec3 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3qw-4vm7-5c48/GHSA-h3qw-4vm7-5c48.json +++ b/advisories/unreviewed/2022/05/GHSA-h3qw-4vm7-5c48/GHSA-h3qw-4vm7-5c48.json @@ -7,12 +7,8 @@ "CVE-2005-4374" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Allinta 2.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to faq.asp and (2) searchQuery parameter to search.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h3rv-9c6w-cv3x/GHSA-h3rv-9c6w-cv3x.json b/advisories/unreviewed/2022/05/GHSA-h3rv-9c6w-cv3x/GHSA-h3rv-9c6w-cv3x.json index d5088170335..675a2727bc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3rv-9c6w-cv3x/GHSA-h3rv-9c6w-cv3x.json +++ b/advisories/unreviewed/2022/05/GHSA-h3rv-9c6w-cv3x/GHSA-h3rv-9c6w-cv3x.json @@ -7,12 +7,8 @@ "CVE-2021-1961" ], "details": "Possible buffer overflow due to lack of offset length check while updating the buffer value in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4cc-27hc-fw7g/GHSA-h4cc-27hc-fw7g.json b/advisories/unreviewed/2022/05/GHSA-h4cc-27hc-fw7g/GHSA-h4cc-27hc-fw7g.json index 396e6879343..9d75084b290 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4cc-27hc-fw7g/GHSA-h4cc-27hc-fw7g.json +++ b/advisories/unreviewed/2022/05/GHSA-h4cc-27hc-fw7g/GHSA-h4cc-27hc-fw7g.json @@ -7,12 +7,8 @@ "CVE-2021-1868" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5c4-m5m7-866w/GHSA-h5c4-m5m7-866w.json b/advisories/unreviewed/2022/05/GHSA-h5c4-m5m7-866w/GHSA-h5c4-m5m7-866w.json index af2c361f1fb..d46ed74d419 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5c4-m5m7-866w/GHSA-h5c4-m5m7-866w.json +++ b/advisories/unreviewed/2022/05/GHSA-h5c4-m5m7-866w/GHSA-h5c4-m5m7-866w.json @@ -7,12 +7,8 @@ "CVE-2005-4285" ], "details": "Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h633-35pq-jqw2/GHSA-h633-35pq-jqw2.json b/advisories/unreviewed/2022/05/GHSA-h633-35pq-jqw2/GHSA-h633-35pq-jqw2.json index 64637324ab1..4b888d1003c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h633-35pq-jqw2/GHSA-h633-35pq-jqw2.json +++ b/advisories/unreviewed/2022/05/GHSA-h633-35pq-jqw2/GHSA-h633-35pq-jqw2.json @@ -7,12 +7,8 @@ "CVE-2005-3970" ], "details": "Cross-site scripting (XSS) vulnerability in MXChange before 0.2.0-pre10 PL492 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h6pw-5prw-wv25/GHSA-h6pw-5prw-wv25.json b/advisories/unreviewed/2022/05/GHSA-h6pw-5prw-wv25/GHSA-h6pw-5prw-wv25.json index 67608e805a2..933304b2267 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6pw-5prw-wv25/GHSA-h6pw-5prw-wv25.json +++ b/advisories/unreviewed/2022/05/GHSA-h6pw-5prw-wv25/GHSA-h6pw-5prw-wv25.json @@ -7,12 +7,8 @@ "CVE-2005-4158" ], "details": "Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h724-3h22-3p4x/GHSA-h724-3h22-3p4x.json b/advisories/unreviewed/2022/05/GHSA-h724-3h22-3p4x/GHSA-h724-3h22-3p4x.json index 6c95c54b2d9..958c1203a1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h724-3h22-3p4x/GHSA-h724-3h22-3p4x.json +++ b/advisories/unreviewed/2022/05/GHSA-h724-3h22-3p4x/GHSA-h724-3h22-3p4x.json @@ -7,12 +7,8 @@ "CVE-2021-39279" ], "details": "Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h75m-rwwv-6vcq/GHSA-h75m-rwwv-6vcq.json b/advisories/unreviewed/2022/05/GHSA-h75m-rwwv-6vcq/GHSA-h75m-rwwv-6vcq.json index b73ba764af9..e1b7550df80 100644 --- a/advisories/unreviewed/2022/05/GHSA-h75m-rwwv-6vcq/GHSA-h75m-rwwv-6vcq.json +++ b/advisories/unreviewed/2022/05/GHSA-h75m-rwwv-6vcq/GHSA-h75m-rwwv-6vcq.json @@ -7,12 +7,8 @@ "CVE-2020-19263" ], "details": "A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to administrator via index.php?s=/user/ApiAdminUser/itemEdit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h78m-q2g5-r2v4/GHSA-h78m-q2g5-r2v4.json b/advisories/unreviewed/2022/05/GHSA-h78m-q2g5-r2v4/GHSA-h78m-q2g5-r2v4.json index 0d3021467c4..1a963900798 100644 --- a/advisories/unreviewed/2022/05/GHSA-h78m-q2g5-r2v4/GHSA-h78m-q2g5-r2v4.json +++ b/advisories/unreviewed/2022/05/GHSA-h78m-q2g5-r2v4/GHSA-h78m-q2g5-r2v4.json @@ -7,12 +7,8 @@ "CVE-2005-4321" ], "details": "The Internet Key Exchange version 1 (IKEv1) implementation in Apani Networks EpiForce 1.9 and earlier running IPSec, allow remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h7mv-xp82-8pqc/GHSA-h7mv-xp82-8pqc.json b/advisories/unreviewed/2022/05/GHSA-h7mv-xp82-8pqc/GHSA-h7mv-xp82-8pqc.json index f3c7cc52ad6..78b407ac7c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7mv-xp82-8pqc/GHSA-h7mv-xp82-8pqc.json +++ b/advisories/unreviewed/2022/05/GHSA-h7mv-xp82-8pqc/GHSA-h7mv-xp82-8pqc.json @@ -7,12 +7,8 @@ "CVE-2021-33938" ], "details": "Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7rf-79wj-2jmh/GHSA-h7rf-79wj-2jmh.json b/advisories/unreviewed/2022/05/GHSA-h7rf-79wj-2jmh/GHSA-h7rf-79wj-2jmh.json index 35e850fd358..cc31db5844b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7rf-79wj-2jmh/GHSA-h7rf-79wj-2jmh.json +++ b/advisories/unreviewed/2022/05/GHSA-h7rf-79wj-2jmh/GHSA-h7rf-79wj-2jmh.json @@ -7,12 +7,8 @@ "CVE-2005-4363" ], "details": "Cross-site scripting (XSS) vulnerability in the search engine in Komodo CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h8gr-3vg4-vhgx/GHSA-h8gr-3vg4-vhgx.json b/advisories/unreviewed/2022/05/GHSA-h8gr-3vg4-vhgx/GHSA-h8gr-3vg4-vhgx.json index 3e7dfad0e85..fa734bfa582 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8gr-3vg4-vhgx/GHSA-h8gr-3vg4-vhgx.json +++ b/advisories/unreviewed/2022/05/GHSA-h8gr-3vg4-vhgx/GHSA-h8gr-3vg4-vhgx.json @@ -7,12 +7,8 @@ "CVE-2005-4003" ], "details": "Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp. NOTE: the original disclosure was specifically only for an XSS issue, but the CVE description was for SQL injection. Since the original disclosure, SQL injection vectors have been reported. This CVE might be REJECTed or significantly altered pending additional information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h8hx-p593-xwmc/GHSA-h8hx-p593-xwmc.json b/advisories/unreviewed/2022/05/GHSA-h8hx-p593-xwmc/GHSA-h8hx-p593-xwmc.json index 281384be8f5..9114fb1b520 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8hx-p593-xwmc/GHSA-h8hx-p593-xwmc.json +++ b/advisories/unreviewed/2022/05/GHSA-h8hx-p593-xwmc/GHSA-h8hx-p593-xwmc.json @@ -7,12 +7,8 @@ "CVE-2021-22793" ], "details": "A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versions prior to V1.6.7) and AccuSine PCSn (Versions prior to V2.2.4) that could allow an authenticated attacker to access the device via FTP protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9c7-5m8v-93ph/GHSA-h9c7-5m8v-93ph.json b/advisories/unreviewed/2022/05/GHSA-h9c7-5m8v-93ph/GHSA-h9c7-5m8v-93ph.json index 9492da30c3e..46738a9481b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9c7-5m8v-93ph/GHSA-h9c7-5m8v-93ph.json +++ b/advisories/unreviewed/2022/05/GHSA-h9c7-5m8v-93ph/GHSA-h9c7-5m8v-93ph.json @@ -7,12 +7,8 @@ "CVE-2021-27022" ], "details": "A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9pm-m4wm-2v5x/GHSA-h9pm-m4wm-2v5x.json b/advisories/unreviewed/2022/05/GHSA-h9pm-m4wm-2v5x/GHSA-h9pm-m4wm-2v5x.json index 66026bcc305..d096cd27b21 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9pm-m4wm-2v5x/GHSA-h9pm-m4wm-2v5x.json +++ b/advisories/unreviewed/2022/05/GHSA-h9pm-m4wm-2v5x/GHSA-h9pm-m4wm-2v5x.json @@ -7,12 +7,8 @@ "CVE-2005-4263" ], "details": "SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9qq-297c-38mx/GHSA-h9qq-297c-38mx.json b/advisories/unreviewed/2022/05/GHSA-h9qq-297c-38mx/GHSA-h9qq-297c-38mx.json index a6f97b708c3..e2f831fbc4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9qq-297c-38mx/GHSA-h9qq-297c-38mx.json +++ b/advisories/unreviewed/2022/05/GHSA-h9qq-297c-38mx/GHSA-h9qq-297c-38mx.json @@ -7,12 +7,8 @@ "CVE-2021-1828" ], "details": "A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. An application may be able to cause unexpected system termination or write kernel memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc37-45rc-736p/GHSA-hc37-45rc-736p.json b/advisories/unreviewed/2022/05/GHSA-hc37-45rc-736p/GHSA-hc37-45rc-736p.json index b3a01448dd2..12733c166e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc37-45rc-736p/GHSA-hc37-45rc-736p.json +++ b/advisories/unreviewed/2022/05/GHSA-hc37-45rc-736p/GHSA-hc37-45rc-736p.json @@ -7,12 +7,8 @@ "CVE-2021-38705" ], "details": "ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user. This can be exploited to create a secondary administrator account for the attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc75-g4hp-4wp6/GHSA-hc75-g4hp-4wp6.json b/advisories/unreviewed/2022/05/GHSA-hc75-g4hp-4wp6/GHSA-hc75-g4hp-4wp6.json index b33ab382309..19a14ab610e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc75-g4hp-4wp6/GHSA-hc75-g4hp-4wp6.json +++ b/advisories/unreviewed/2022/05/GHSA-hc75-g4hp-4wp6/GHSA-hc75-g4hp-4wp6.json @@ -7,12 +7,8 @@ "CVE-2005-4009" ], "details": "Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (b) week.php, (c) month.php, and (d) year.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hc8p-gq8j-4gjq/GHSA-hc8p-gq8j-4gjq.json b/advisories/unreviewed/2022/05/GHSA-hc8p-gq8j-4gjq/GHSA-hc8p-gq8j-4gjq.json index f1cf475baa9..d75dd910538 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc8p-gq8j-4gjq/GHSA-hc8p-gq8j-4gjq.json +++ b/advisories/unreviewed/2022/05/GHSA-hc8p-gq8j-4gjq/GHSA-hc8p-gq8j-4gjq.json @@ -7,12 +7,8 @@ "CVE-2005-3955" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hf2f-mj6g-rh32/GHSA-hf2f-mj6g-rh32.json b/advisories/unreviewed/2022/05/GHSA-hf2f-mj6g-rh32/GHSA-hf2f-mj6g-rh32.json index 841868ee3fb..16f0d54f19f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf2f-mj6g-rh32/GHSA-hf2f-mj6g-rh32.json +++ b/advisories/unreviewed/2022/05/GHSA-hf2f-mj6g-rh32/GHSA-hf2f-mj6g-rh32.json @@ -7,12 +7,8 @@ "CVE-2005-4382" ], "details": "SQL injection vulnerability in CitySoft Community Enterprise 4.x allows remote attackers to execute arbitrary SQL commands via the (1) nodeID, (2) pageID, (3) ID, and (4) parentid parameter to index.cfm; and (5) documentFormatId parameter to document/docWindow.cfm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hf48-cw5q-wjpm/GHSA-hf48-cw5q-wjpm.json b/advisories/unreviewed/2022/05/GHSA-hf48-cw5q-wjpm/GHSA-hf48-cw5q-wjpm.json index bae7c717eef..7129711973f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf48-cw5q-wjpm/GHSA-hf48-cw5q-wjpm.json +++ b/advisories/unreviewed/2022/05/GHSA-hf48-cw5q-wjpm/GHSA-hf48-cw5q-wjpm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hff4-9w57-p64w/GHSA-hff4-9w57-p64w.json b/advisories/unreviewed/2022/05/GHSA-hff4-9w57-p64w/GHSA-hff4-9w57-p64w.json index 2acb3951b21..2346a7d26d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hff4-9w57-p64w/GHSA-hff4-9w57-p64w.json +++ b/advisories/unreviewed/2022/05/GHSA-hff4-9w57-p64w/GHSA-hff4-9w57-p64w.json @@ -7,12 +7,8 @@ "CVE-2005-4202" ], "details": "Multiple directory traversal vulnerabilities in LogiSphere 0.9.9j allow remote attackers to access arbitrary files via (1) .. (dot dot), (2) \"...\" (triple dot), and (3) \"..//\" sequences in the URL, (4) \"../\" sequences in the source parameter to viewsource.jsp, or (5) \"..\\\" (dot dot backslash) sequences in the NS-query-pat parameter to the search URL. URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfg4-62f6-fjff/GHSA-hfg4-62f6-fjff.json b/advisories/unreviewed/2022/05/GHSA-hfg4-62f6-fjff/GHSA-hfg4-62f6-fjff.json index dd246bd51cb..7b5fceebdbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfg4-62f6-fjff/GHSA-hfg4-62f6-fjff.json +++ b/advisories/unreviewed/2022/05/GHSA-hfg4-62f6-fjff/GHSA-hfg4-62f6-fjff.json @@ -7,12 +7,8 @@ "CVE-2021-38164" ], "details": "SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfh7-m9jr-j829/GHSA-hfh7-m9jr-j829.json b/advisories/unreviewed/2022/05/GHSA-hfh7-m9jr-j829/GHSA-hfh7-m9jr-j829.json index d506c207643..5a123ec5d56 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfh7-m9jr-j829/GHSA-hfh7-m9jr-j829.json +++ b/advisories/unreviewed/2022/05/GHSA-hfh7-m9jr-j829/GHSA-hfh7-m9jr-j829.json @@ -7,12 +7,8 @@ "CVE-2021-1875" ], "details": "A double free issue was addressed with improved memory management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted file may lead to heap corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hfqm-gjfq-m7ph/GHSA-hfqm-gjfq-m7ph.json b/advisories/unreviewed/2022/05/GHSA-hfqm-gjfq-m7ph/GHSA-hfqm-gjfq-m7ph.json index 45e30cfa9c5..22060f51823 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfqm-gjfq-m7ph/GHSA-hfqm-gjfq-m7ph.json +++ b/advisories/unreviewed/2022/05/GHSA-hfqm-gjfq-m7ph/GHSA-hfqm-gjfq-m7ph.json @@ -7,12 +7,8 @@ "CVE-2005-4311" ], "details": "Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfw9-q3f6-gv7r/GHSA-hfw9-q3f6-gv7r.json b/advisories/unreviewed/2022/05/GHSA-hfw9-q3f6-gv7r/GHSA-hfw9-q3f6-gv7r.json index 052bbccf02a..07b29983da7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfw9-q3f6-gv7r/GHSA-hfw9-q3f6-gv7r.json +++ b/advisories/unreviewed/2022/05/GHSA-hfw9-q3f6-gv7r/GHSA-hfw9-q3f6-gv7r.json @@ -7,12 +7,8 @@ "CVE-2005-4298" ], "details": "Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfxg-ph49-2mw5/GHSA-hfxg-ph49-2mw5.json b/advisories/unreviewed/2022/05/GHSA-hfxg-ph49-2mw5/GHSA-hfxg-ph49-2mw5.json index e3a14125bbb..bdb69434211 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfxg-ph49-2mw5/GHSA-hfxg-ph49-2mw5.json +++ b/advisories/unreviewed/2022/05/GHSA-hfxg-ph49-2mw5/GHSA-hfxg-ph49-2mw5.json @@ -7,12 +7,8 @@ "CVE-2021-40509" ], "details": "ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg99-6rrx-j29j/GHSA-hg99-6rrx-j29j.json b/advisories/unreviewed/2022/05/GHSA-hg99-6rrx-j29j/GHSA-hg99-6rrx-j29j.json index aa690e91b42..e3a2d884e2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg99-6rrx-j29j/GHSA-hg99-6rrx-j29j.json +++ b/advisories/unreviewed/2022/05/GHSA-hg99-6rrx-j29j/GHSA-hg99-6rrx-j29j.json @@ -7,12 +7,8 @@ "CVE-2005-4329" ], "details": "SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and (2) id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hh5p-vgjc-p9vq/GHSA-hh5p-vgjc-p9vq.json b/advisories/unreviewed/2022/05/GHSA-hh5p-vgjc-p9vq/GHSA-hh5p-vgjc-p9vq.json index 47baabdd0bb..fc53c33b87a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh5p-vgjc-p9vq/GHSA-hh5p-vgjc-p9vq.json +++ b/advisories/unreviewed/2022/05/GHSA-hh5p-vgjc-p9vq/GHSA-hh5p-vgjc-p9vq.json @@ -7,12 +7,8 @@ "CVE-2005-4204" ], "details": "Cross-site scripting (XSS) vulnerability in LogiSphere 0.9.9j allows remote attackers to inject arbitrary Javascript via the msg command. NOTE: due to lack of appropriate details by the original researcher, it is unclear whether this issue is distinct from the msg DoS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhcx-g8h7-2m9h/GHSA-hhcx-g8h7-2m9h.json b/advisories/unreviewed/2022/05/GHSA-hhcx-g8h7-2m9h/GHSA-hhcx-g8h7-2m9h.json index 1d05c3fdf0c..2d19f438b83 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhcx-g8h7-2m9h/GHSA-hhcx-g8h7-2m9h.json +++ b/advisories/unreviewed/2022/05/GHSA-hhcx-g8h7-2m9h/GHSA-hhcx-g8h7-2m9h.json @@ -7,12 +7,8 @@ "CVE-2021-1962" ], "details": "Buffer Overflow while processing IOCTL for getting peripheral endpoint information there is no proper validation for input maximum endpoint pair and its size in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhhm-592j-2r47/GHSA-hhhm-592j-2r47.json b/advisories/unreviewed/2022/05/GHSA-hhhm-592j-2r47/GHSA-hhhm-592j-2r47.json index 8f23d238903..4c890d51ccc 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhhm-592j-2r47/GHSA-hhhm-592j-2r47.json +++ b/advisories/unreviewed/2022/05/GHSA-hhhm-592j-2r47/GHSA-hhhm-592j-2r47.json @@ -7,12 +7,8 @@ "CVE-2021-30763" ], "details": "An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.7, watchOS 7.6. A shortcut may be able to bypass Internet permission requirements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhjr-xgqf-mpfc/GHSA-hhjr-xgqf-mpfc.json b/advisories/unreviewed/2022/05/GHSA-hhjr-xgqf-mpfc/GHSA-hhjr-xgqf-mpfc.json index 1850a567bfc..07ec5f84292 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhjr-xgqf-mpfc/GHSA-hhjr-xgqf-mpfc.json +++ b/advisories/unreviewed/2022/05/GHSA-hhjr-xgqf-mpfc/GHSA-hhjr-xgqf-mpfc.json @@ -7,12 +7,8 @@ "CVE-2021-37201" ], "details": "A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). The web interface of affected devices is vulnerable to a Cross-Site Request Forgery (CSRF) attack. This could allow an attacker to manipulate the SINEC NMS configuration by tricking an unsuspecting user with administrative privileges to click on a malicious link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hhpx-68fp-4gm4/GHSA-hhpx-68fp-4gm4.json b/advisories/unreviewed/2022/05/GHSA-hhpx-68fp-4gm4/GHSA-hhpx-68fp-4gm4.json index 6d8e26421ba..5654347633b 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhpx-68fp-4gm4/GHSA-hhpx-68fp-4gm4.json +++ b/advisories/unreviewed/2022/05/GHSA-hhpx-68fp-4gm4/GHSA-hhpx-68fp-4gm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hj5w-45wx-h9rg/GHSA-hj5w-45wx-h9rg.json b/advisories/unreviewed/2022/05/GHSA-hj5w-45wx-h9rg/GHSA-hj5w-45wx-h9rg.json index 4e62eb54d82..72fe7312317 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj5w-45wx-h9rg/GHSA-hj5w-45wx-h9rg.json +++ b/advisories/unreviewed/2022/05/GHSA-hj5w-45wx-h9rg/GHSA-hj5w-45wx-h9rg.json @@ -7,12 +7,8 @@ "CVE-2021-35947" ], "details": "The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjg4-m8gp-mxjw/GHSA-hjg4-m8gp-mxjw.json b/advisories/unreviewed/2022/05/GHSA-hjg4-m8gp-mxjw/GHSA-hjg4-m8gp-mxjw.json index 3c41a2e3f6c..1ad8a7e19e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjg4-m8gp-mxjw/GHSA-hjg4-m8gp-mxjw.json +++ b/advisories/unreviewed/2022/05/GHSA-hjg4-m8gp-mxjw/GHSA-hjg4-m8gp-mxjw.json @@ -7,12 +7,8 @@ "CVE-2005-4132" ], "details": "Unspecified \"security leak\" vulnerability in Contenido before 4.6.4, when register_globals is on and allow_url_fopen is true, has unspecified impact and attack vectors. NOTE: it is likely that this is a PHP remote file include vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hjrv-6xv3-c6x3/GHSA-hjrv-6xv3-c6x3.json b/advisories/unreviewed/2022/05/GHSA-hjrv-6xv3-c6x3/GHSA-hjrv-6xv3-c6x3.json index abc18cbca50..f3aebeb2b1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjrv-6xv3-c6x3/GHSA-hjrv-6xv3-c6x3.json +++ b/advisories/unreviewed/2022/05/GHSA-hjrv-6xv3-c6x3/GHSA-hjrv-6xv3-c6x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-hjwv-q93r-4mwm/GHSA-hjwv-q93r-4mwm.json b/advisories/unreviewed/2022/05/GHSA-hjwv-q93r-4mwm/GHSA-hjwv-q93r-4mwm.json index 62b86644a07..4955401da30 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjwv-q93r-4mwm/GHSA-hjwv-q93r-4mwm.json +++ b/advisories/unreviewed/2022/05/GHSA-hjwv-q93r-4mwm/GHSA-hjwv-q93r-4mwm.json @@ -7,12 +7,8 @@ "CVE-2021-30793" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hm75-8hcq-5577/GHSA-hm75-8hcq-5577.json b/advisories/unreviewed/2022/05/GHSA-hm75-8hcq-5577/GHSA-hm75-8hcq-5577.json index d2112163567..11ba778e673 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm75-8hcq-5577/GHSA-hm75-8hcq-5577.json +++ b/advisories/unreviewed/2022/05/GHSA-hm75-8hcq-5577/GHSA-hm75-8hcq-5577.json @@ -7,12 +7,8 @@ "CVE-2005-4131" ], "details": "Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka \"Brand new Microsoft Excel Vulnerability,\" as originally placed for sale on eBay as item number 7203336538.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -120,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hm86-5wcm-m7h2/GHSA-hm86-5wcm-m7h2.json b/advisories/unreviewed/2022/05/GHSA-hm86-5wcm-m7h2/GHSA-hm86-5wcm-m7h2.json index e80796f3b4d..1cf90563787 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm86-5wcm-m7h2/GHSA-hm86-5wcm-m7h2.json +++ b/advisories/unreviewed/2022/05/GHSA-hm86-5wcm-m7h2/GHSA-hm86-5wcm-m7h2.json @@ -7,12 +7,8 @@ "CVE-2021-23037" ], "details": "On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp87-wrg5-gq65/GHSA-hp87-wrg5-gq65.json b/advisories/unreviewed/2022/05/GHSA-hp87-wrg5-gq65/GHSA-hp87-wrg5-gq65.json index b36ec12513c..45c0139fa5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp87-wrg5-gq65/GHSA-hp87-wrg5-gq65.json +++ b/advisories/unreviewed/2022/05/GHSA-hp87-wrg5-gq65/GHSA-hp87-wrg5-gq65.json @@ -7,12 +7,8 @@ "CVE-2021-37423" ], "details": "Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpcp-c3rh-8639/GHSA-hpcp-c3rh-8639.json b/advisories/unreviewed/2022/05/GHSA-hpcp-c3rh-8639/GHSA-hpcp-c3rh-8639.json index 6dae04f3e42..b80bab23b9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpcp-c3rh-8639/GHSA-hpcp-c3rh-8639.json +++ b/advisories/unreviewed/2022/05/GHSA-hpcp-c3rh-8639/GHSA-hpcp-c3rh-8639.json @@ -7,12 +7,8 @@ "CVE-2005-4326" ], "details": "The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded), which allows remote attackers to sniff authentication credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hpj4-57qp-2v2m/GHSA-hpj4-57qp-2v2m.json b/advisories/unreviewed/2022/05/GHSA-hpj4-57qp-2v2m/GHSA-hpj4-57qp-2v2m.json index 19cbc5a56f0..382e2aaef58 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpj4-57qp-2v2m/GHSA-hpj4-57qp-2v2m.json +++ b/advisories/unreviewed/2022/05/GHSA-hpj4-57qp-2v2m/GHSA-hpj4-57qp-2v2m.json @@ -7,12 +7,8 @@ "CVE-2021-1909" ], "details": "Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpj8-7jw7-hq79/GHSA-hpj8-7jw7-hq79.json b/advisories/unreviewed/2022/05/GHSA-hpj8-7jw7-hq79/GHSA-hpj8-7jw7-hq79.json index 8f059734d58..25234af9087 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpj8-7jw7-hq79/GHSA-hpj8-7jw7-hq79.json +++ b/advisories/unreviewed/2022/05/GHSA-hpj8-7jw7-hq79/GHSA-hpj8-7jw7-hq79.json @@ -7,12 +7,8 @@ "CVE-2021-1770" ], "details": "A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A logic issue was addressed with improved state management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hq2m-v8jg-cf3p/GHSA-hq2m-v8jg-cf3p.json b/advisories/unreviewed/2022/05/GHSA-hq2m-v8jg-cf3p/GHSA-hq2m-v8jg-cf3p.json index 531d02cdf3a..a2a8c6ce31c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq2m-v8jg-cf3p/GHSA-hq2m-v8jg-cf3p.json +++ b/advisories/unreviewed/2022/05/GHSA-hq2m-v8jg-cf3p/GHSA-hq2m-v8jg-cf3p.json @@ -7,12 +7,8 @@ "CVE-2005-4014" ], "details": "stat.php in PHP Web Statistik 1.4 allows remote attackers to cause a denial of service (CPU consumption) via a large lastnumber value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqqc-whmx-mjmv/GHSA-hqqc-whmx-mjmv.json b/advisories/unreviewed/2022/05/GHSA-hqqc-whmx-mjmv/GHSA-hqqc-whmx-mjmv.json index 9f8528f3179..1e5854a618d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqqc-whmx-mjmv/GHSA-hqqc-whmx-mjmv.json +++ b/advisories/unreviewed/2022/05/GHSA-hqqc-whmx-mjmv/GHSA-hqqc-whmx-mjmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqqf-qrw3-32h8/GHSA-hqqf-qrw3-32h8.json b/advisories/unreviewed/2022/05/GHSA-hqqf-qrw3-32h8/GHSA-hqqf-qrw3-32h8.json index 3a7ce65f01e..98df1e09c31 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqqf-qrw3-32h8/GHSA-hqqf-qrw3-32h8.json +++ b/advisories/unreviewed/2022/05/GHSA-hqqf-qrw3-32h8/GHSA-hqqf-qrw3-32h8.json @@ -7,12 +7,8 @@ "CVE-2005-4236" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in CKGOLD allows remote attackers to inject arbitrary web script or HTML via the search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hv59-832h-f7j8/GHSA-hv59-832h-f7j8.json b/advisories/unreviewed/2022/05/GHSA-hv59-832h-f7j8/GHSA-hv59-832h-f7j8.json index 8732ce6764f..94ddb0beff2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hv59-832h-f7j8/GHSA-hv59-832h-f7j8.json +++ b/advisories/unreviewed/2022/05/GHSA-hv59-832h-f7j8/GHSA-hv59-832h-f7j8.json @@ -7,12 +7,8 @@ "CVE-2021-37191" ], "details": "A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvm3-c8w4-35mp/GHSA-hvm3-c8w4-35mp.json b/advisories/unreviewed/2022/05/GHSA-hvm3-c8w4-35mp/GHSA-hvm3-c8w4-35mp.json index 3b01e29aba4..56bf6208acc 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvm3-c8w4-35mp/GHSA-hvm3-c8w4-35mp.json +++ b/advisories/unreviewed/2022/05/GHSA-hvm3-c8w4-35mp/GHSA-hvm3-c8w4-35mp.json @@ -7,12 +7,8 @@ "CVE-2021-38355" ], "details": "The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter found in the ~/bug-library.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hvwp-vm7c-5726/GHSA-hvwp-vm7c-5726.json b/advisories/unreviewed/2022/05/GHSA-hvwp-vm7c-5726/GHSA-hvwp-vm7c-5726.json index f7cceb8afd0..26a7a10f461 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvwp-vm7c-5726/GHSA-hvwp-vm7c-5726.json +++ b/advisories/unreviewed/2022/05/GHSA-hvwp-vm7c-5726/GHSA-hvwp-vm7c-5726.json @@ -7,12 +7,8 @@ "CVE-2005-3993" ], "details": "Multiple unspecified vulnerabilities in MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allow attackers to cause a denial of service (crash) via invalid IMAP commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hw39-2f47-g9hg/GHSA-hw39-2f47-g9hg.json b/advisories/unreviewed/2022/05/GHSA-hw39-2f47-g9hg/GHSA-hw39-2f47-g9hg.json index 70d054f39c7..60d23e9680e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw39-2f47-g9hg/GHSA-hw39-2f47-g9hg.json +++ b/advisories/unreviewed/2022/05/GHSA-hw39-2f47-g9hg/GHSA-hw39-2f47-g9hg.json @@ -7,12 +7,8 @@ "CVE-2021-28155" ], "details": "The Bluetooth Classic implementation on JBL TUNE500BT devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown a device by flooding the target device with LMP Feature Response data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hw4x-r4pq-p2rw/GHSA-hw4x-r4pq-p2rw.json b/advisories/unreviewed/2022/05/GHSA-hw4x-r4pq-p2rw/GHSA-hw4x-r4pq-p2rw.json index 267336cd1c1..816e118ea83 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw4x-r4pq-p2rw/GHSA-hw4x-r4pq-p2rw.json +++ b/advisories/unreviewed/2022/05/GHSA-hw4x-r4pq-p2rw/GHSA-hw4x-r4pq-p2rw.json @@ -7,12 +7,8 @@ "CVE-2005-4019" ], "details": "SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the mls parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hw72-fhc8-8qf4/GHSA-hw72-fhc8-8qf4.json b/advisories/unreviewed/2022/05/GHSA-hw72-fhc8-8qf4/GHSA-hw72-fhc8-8qf4.json index 76c1436c5bb..f3f82ecc5be 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw72-fhc8-8qf4/GHSA-hw72-fhc8-8qf4.json +++ b/advisories/unreviewed/2022/05/GHSA-hw72-fhc8-8qf4/GHSA-hw72-fhc8-8qf4.json @@ -7,12 +7,8 @@ "CVE-2005-3926" ], "details": "Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via the _SERVER[REMOTE_ADDR] parameter, which is injected into a .inc script that is later included by the main script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwr5-xvv8-wh2p/GHSA-hwr5-xvv8-wh2p.json b/advisories/unreviewed/2022/05/GHSA-hwr5-xvv8-wh2p/GHSA-hwr5-xvv8-wh2p.json index df301a7ceee..e03f9c4da85 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwr5-xvv8-wh2p/GHSA-hwr5-xvv8-wh2p.json +++ b/advisories/unreviewed/2022/05/GHSA-hwr5-xvv8-wh2p/GHSA-hwr5-xvv8-wh2p.json @@ -7,12 +7,8 @@ "CVE-2021-25466" ], "details": "Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx73-9v9m-r63j/GHSA-hx73-9v9m-r63j.json b/advisories/unreviewed/2022/05/GHSA-hx73-9v9m-r63j/GHSA-hx73-9v9m-r63j.json index 2020d0c1e1e..aa03ac32e51 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx73-9v9m-r63j/GHSA-hx73-9v9m-r63j.json +++ b/advisories/unreviewed/2022/05/GHSA-hx73-9v9m-r63j/GHSA-hx73-9v9m-r63j.json @@ -7,12 +7,8 @@ "CVE-2005-3947" ], "details": "Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via \"../\" sequences in the filename parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j22h-wh6q-9q3g/GHSA-j22h-wh6q-9q3g.json b/advisories/unreviewed/2022/05/GHSA-j22h-wh6q-9q3g/GHSA-j22h-wh6q-9q3g.json index 742ec3d2a5b..b48d8b7fbe0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j22h-wh6q-9q3g/GHSA-j22h-wh6q-9q3g.json +++ b/advisories/unreviewed/2022/05/GHSA-j22h-wh6q-9q3g/GHSA-j22h-wh6q-9q3g.json @@ -7,12 +7,8 @@ "CVE-2005-4033" ], "details": "Nodezilla 0.4.13-corno-fulgure does not properly protect the evl_data directory, which could allow them to be shared when they are not protected by PRIVATEDATADIR in nodezilla.ini, which allows remote attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2xw-7659-7rj6/GHSA-j2xw-7659-7rj6.json b/advisories/unreviewed/2022/05/GHSA-j2xw-7659-7rj6/GHSA-j2xw-7659-7rj6.json index 3a2a59623f3..2243e2a7dc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2xw-7659-7rj6/GHSA-j2xw-7659-7rj6.json +++ b/advisories/unreviewed/2022/05/GHSA-j2xw-7659-7rj6/GHSA-j2xw-7659-7rj6.json @@ -7,12 +7,8 @@ "CVE-2005-4030" ], "details": "SQL injection vulnerability in Quicksilver Forums before 1.5.1 allows remote attackers to execute arbitrary SQL commands via the HTTP_USER_AGENT header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j39x-23p8-9mpq/GHSA-j39x-23p8-9mpq.json b/advisories/unreviewed/2022/05/GHSA-j39x-23p8-9mpq/GHSA-j39x-23p8-9mpq.json index 35597d3d28c..274f9342d6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j39x-23p8-9mpq/GHSA-j39x-23p8-9mpq.json +++ b/advisories/unreviewed/2022/05/GHSA-j39x-23p8-9mpq/GHSA-j39x-23p8-9mpq.json @@ -7,12 +7,8 @@ "CVE-2021-23044" ], "details": "On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x, when the Intel QuickAssist Technology (QAT) compression driver is used on affected BIG-IP hardware and BIG-IP Virtual Edition (VE) platforms, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j3qx-4gvc-v53m/GHSA-j3qx-4gvc-v53m.json b/advisories/unreviewed/2022/05/GHSA-j3qx-4gvc-v53m/GHSA-j3qx-4gvc-v53m.json index 420f4f92672..147f33fd27f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3qx-4gvc-v53m/GHSA-j3qx-4gvc-v53m.json +++ b/advisories/unreviewed/2022/05/GHSA-j3qx-4gvc-v53m/GHSA-j3qx-4gvc-v53m.json @@ -7,12 +7,8 @@ "CVE-2021-24603" ], "details": "The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j3x8-q72p-pvhp/GHSA-j3x8-q72p-pvhp.json b/advisories/unreviewed/2022/05/GHSA-j3x8-q72p-pvhp/GHSA-j3x8-q72p-pvhp.json index 4fe82dcffb5..04e77a9e6b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3x8-q72p-pvhp/GHSA-j3x8-q72p-pvhp.json +++ b/advisories/unreviewed/2022/05/GHSA-j3x8-q72p-pvhp/GHSA-j3x8-q72p-pvhp.json @@ -7,12 +7,8 @@ "CVE-2005-4354" ], "details": "Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5mp-hh89-pmcx/GHSA-j5mp-hh89-pmcx.json b/advisories/unreviewed/2022/05/GHSA-j5mp-hh89-pmcx/GHSA-j5mp-hh89-pmcx.json index 9293f66f4ab..43a25e15c2a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5mp-hh89-pmcx/GHSA-j5mp-hh89-pmcx.json +++ b/advisories/unreviewed/2022/05/GHSA-j5mp-hh89-pmcx/GHSA-j5mp-hh89-pmcx.json @@ -7,12 +7,8 @@ "CVE-2005-4309" ], "details": "SQL injection vulnerability in ezUpload Pro 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5xw-6p2w-wwpf/GHSA-j5xw-6p2w-wwpf.json b/advisories/unreviewed/2022/05/GHSA-j5xw-6p2w-wwpf/GHSA-j5xw-6p2w-wwpf.json index 1637628f2ff..1c81ae849f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5xw-6p2w-wwpf/GHSA-j5xw-6p2w-wwpf.json +++ b/advisories/unreviewed/2022/05/GHSA-j5xw-6p2w-wwpf/GHSA-j5xw-6p2w-wwpf.json @@ -7,12 +7,8 @@ "CVE-2005-3961" ], "details": "export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j688-25qj-6vvv/GHSA-j688-25qj-6vvv.json b/advisories/unreviewed/2022/05/GHSA-j688-25qj-6vvv/GHSA-j688-25qj-6vvv.json index ec4bc0e6575..13fcf94a155 100644 --- a/advisories/unreviewed/2022/05/GHSA-j688-25qj-6vvv/GHSA-j688-25qj-6vvv.json +++ b/advisories/unreviewed/2022/05/GHSA-j688-25qj-6vvv/GHSA-j688-25qj-6vvv.json @@ -7,12 +7,8 @@ "CVE-2005-3959" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j6cj-94fh-962f/GHSA-j6cj-94fh-962f.json b/advisories/unreviewed/2022/05/GHSA-j6cj-94fh-962f/GHSA-j6cj-94fh-962f.json index 4c87629c844..06e9cadfcbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6cj-94fh-962f/GHSA-j6cj-94fh-962f.json +++ b/advisories/unreviewed/2022/05/GHSA-j6cj-94fh-962f/GHSA-j6cj-94fh-962f.json @@ -7,12 +7,8 @@ "CVE-2020-20348" ], "details": "WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6h2-xp4h-4c6g/GHSA-j6h2-xp4h-4c6g.json b/advisories/unreviewed/2022/05/GHSA-j6h2-xp4h-4c6g/GHSA-j6h2-xp4h-4c6g.json index c539ee9ceae..2e974b20997 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6h2-xp4h-4c6g/GHSA-j6h2-xp4h-4c6g.json +++ b/advisories/unreviewed/2022/05/GHSA-j6h2-xp4h-4c6g/GHSA-j6h2-xp4h-4c6g.json @@ -7,12 +7,8 @@ "CVE-2005-4211" ], "details": "PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j748-pf6h-h5f8/GHSA-j748-pf6h-h5f8.json b/advisories/unreviewed/2022/05/GHSA-j748-pf6h-h5f8/GHSA-j748-pf6h-h5f8.json index d5a0f2f2687..efba43f8425 100644 --- a/advisories/unreviewed/2022/05/GHSA-j748-pf6h-h5f8/GHSA-j748-pf6h-h5f8.json +++ b/advisories/unreviewed/2022/05/GHSA-j748-pf6h-h5f8/GHSA-j748-pf6h-h5f8.json @@ -7,12 +7,8 @@ "CVE-2021-30765" ], "details": "An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j776-m8gg-r576/GHSA-j776-m8gg-r576.json b/advisories/unreviewed/2022/05/GHSA-j776-m8gg-r576/GHSA-j776-m8gg-r576.json index f7d8c071113..8e2556f6d5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j776-m8gg-r576/GHSA-j776-m8gg-r576.json +++ b/advisories/unreviewed/2022/05/GHSA-j776-m8gg-r576/GHSA-j776-m8gg-r576.json @@ -7,12 +7,8 @@ "CVE-2020-21048" ], "details": "An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j79c-f2gc-9f4j/GHSA-j79c-f2gc-9f4j.json b/advisories/unreviewed/2022/05/GHSA-j79c-f2gc-9f4j/GHSA-j79c-f2gc-9f4j.json index 3a731f56ae1..1e91016bc64 100644 --- a/advisories/unreviewed/2022/05/GHSA-j79c-f2gc-9f4j/GHSA-j79c-f2gc-9f4j.json +++ b/advisories/unreviewed/2022/05/GHSA-j79c-f2gc-9f4j/GHSA-j79c-f2gc-9f4j.json @@ -7,12 +7,8 @@ "CVE-2005-4273" ], "details": "Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jccf-vqp8-v3mm/GHSA-jccf-vqp8-v3mm.json b/advisories/unreviewed/2022/05/GHSA-jccf-vqp8-v3mm/GHSA-jccf-vqp8-v3mm.json index b275b57f872..71a885651a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jccf-vqp8-v3mm/GHSA-jccf-vqp8-v3mm.json +++ b/advisories/unreviewed/2022/05/GHSA-jccf-vqp8-v3mm/GHSA-jccf-vqp8-v3mm.json @@ -7,12 +7,8 @@ "CVE-2021-38706" ], "details": "messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcj6-hcrj-4hgv/GHSA-jcj6-hcrj-4hgv.json b/advisories/unreviewed/2022/05/GHSA-jcj6-hcrj-4hgv/GHSA-jcj6-hcrj-4hgv.json index c9f8f75943b..a368893bf57 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcj6-hcrj-4hgv/GHSA-jcj6-hcrj-4hgv.json +++ b/advisories/unreviewed/2022/05/GHSA-jcj6-hcrj-4hgv/GHSA-jcj6-hcrj-4hgv.json @@ -7,12 +7,8 @@ "CVE-2005-4380" ], "details": "Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcp2-cx35-47gg/GHSA-jcp2-cx35-47gg.json b/advisories/unreviewed/2022/05/GHSA-jcp2-cx35-47gg/GHSA-jcp2-cx35-47gg.json index b9f6eaa7177..f16801e3e0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcp2-cx35-47gg/GHSA-jcp2-cx35-47gg.json +++ b/advisories/unreviewed/2022/05/GHSA-jcp2-cx35-47gg/GHSA-jcp2-cx35-47gg.json @@ -7,12 +7,8 @@ "CVE-2021-36182" ], "details": "A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf2v-jqgc-vr97/GHSA-jf2v-jqgc-vr97.json b/advisories/unreviewed/2022/05/GHSA-jf2v-jqgc-vr97/GHSA-jf2v-jqgc-vr97.json index 9be545a4dee..16a55d215b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf2v-jqgc-vr97/GHSA-jf2v-jqgc-vr97.json +++ b/advisories/unreviewed/2022/05/GHSA-jf2v-jqgc-vr97/GHSA-jf2v-jqgc-vr97.json @@ -7,12 +7,8 @@ "CVE-2021-22775" ], "details": "A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevated privileges when installing the software.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf84-45wf-mjgm/GHSA-jf84-45wf-mjgm.json b/advisories/unreviewed/2022/05/GHSA-jf84-45wf-mjgm/GHSA-jf84-45wf-mjgm.json index 7bb3c722829..87b904ec7b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf84-45wf-mjgm/GHSA-jf84-45wf-mjgm.json +++ b/advisories/unreviewed/2022/05/GHSA-jf84-45wf-mjgm/GHSA-jf84-45wf-mjgm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jg54-6p86-rp5q/GHSA-jg54-6p86-rp5q.json b/advisories/unreviewed/2022/05/GHSA-jg54-6p86-rp5q/GHSA-jg54-6p86-rp5q.json index d2626c3464d..4de5bb27e94 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg54-6p86-rp5q/GHSA-jg54-6p86-rp5q.json +++ b/advisories/unreviewed/2022/05/GHSA-jg54-6p86-rp5q/GHSA-jg54-6p86-rp5q.json @@ -7,12 +7,8 @@ "CVE-2021-34146" ], "details": "The Bluetooth Classic implementation in the Cypress CYW920735Q60EVB does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and restart (crash) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jghc-2mp4-x4fj/GHSA-jghc-2mp4-x4fj.json b/advisories/unreviewed/2022/05/GHSA-jghc-2mp4-x4fj/GHSA-jghc-2mp4-x4fj.json index 528cfeef1b8..1916ee58cfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-jghc-2mp4-x4fj/GHSA-jghc-2mp4-x4fj.json +++ b/advisories/unreviewed/2022/05/GHSA-jghc-2mp4-x4fj/GHSA-jghc-2mp4-x4fj.json @@ -7,12 +7,8 @@ "CVE-2021-24590" ], "details": "The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jghx-rx2p-62q9/GHSA-jghx-rx2p-62q9.json b/advisories/unreviewed/2022/05/GHSA-jghx-rx2p-62q9/GHSA-jghx-rx2p-62q9.json index 8436126f5f2..7ded6cbc262 100644 --- a/advisories/unreviewed/2022/05/GHSA-jghx-rx2p-62q9/GHSA-jghx-rx2p-62q9.json +++ b/advisories/unreviewed/2022/05/GHSA-jghx-rx2p-62q9/GHSA-jghx-rx2p-62q9.json @@ -7,12 +7,8 @@ "CVE-2021-24435" ], "details": "The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgw4-3xpf-hvpv/GHSA-jgw4-3xpf-hvpv.json b/advisories/unreviewed/2022/05/GHSA-jgw4-3xpf-hvpv/GHSA-jgw4-3xpf-hvpv.json index e001b5cd93f..71d9dd3f94d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgw4-3xpf-hvpv/GHSA-jgw4-3xpf-hvpv.json +++ b/advisories/unreviewed/2022/05/GHSA-jgw4-3xpf-hvpv/GHSA-jgw4-3xpf-hvpv.json @@ -7,12 +7,8 @@ "CVE-2020-19265" ], "details": "A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgwv-g855-m766/GHSA-jgwv-g855-m766.json b/advisories/unreviewed/2022/05/GHSA-jgwv-g855-m766/GHSA-jgwv-g855-m766.json index 81010222895..a5d358a0f74 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgwv-g855-m766/GHSA-jgwv-g855-m766.json +++ b/advisories/unreviewed/2022/05/GHSA-jgwv-g855-m766/GHSA-jgwv-g855-m766.json @@ -7,12 +7,8 @@ "CVE-2005-4166" ], "details": "Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjmq-qm7v-gx76/GHSA-jjmq-qm7v-gx76.json b/advisories/unreviewed/2022/05/GHSA-jjmq-qm7v-gx76/GHSA-jjmq-qm7v-gx76.json index d2e8ddba603..6b04e48e70e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjmq-qm7v-gx76/GHSA-jjmq-qm7v-gx76.json +++ b/advisories/unreviewed/2022/05/GHSA-jjmq-qm7v-gx76/GHSA-jjmq-qm7v-gx76.json @@ -7,12 +7,8 @@ "CVE-2021-25454" ], "details": "OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jjvw-69xc-975m/GHSA-jjvw-69xc-975m.json b/advisories/unreviewed/2022/05/GHSA-jjvw-69xc-975m/GHSA-jjvw-69xc-975m.json index d8170992637..a23850e0ee5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjvw-69xc-975m/GHSA-jjvw-69xc-975m.json +++ b/advisories/unreviewed/2022/05/GHSA-jjvw-69xc-975m/GHSA-jjvw-69xc-975m.json @@ -7,12 +7,8 @@ "CVE-2005-4242" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jm3v-7p2w-cvmp/GHSA-jm3v-7p2w-cvmp.json b/advisories/unreviewed/2022/05/GHSA-jm3v-7p2w-cvmp/GHSA-jm3v-7p2w-cvmp.json index 58791bb0b51..5e9eaa42e28 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm3v-7p2w-cvmp/GHSA-jm3v-7p2w-cvmp.json +++ b/advisories/unreviewed/2022/05/GHSA-jm3v-7p2w-cvmp/GHSA-jm3v-7p2w-cvmp.json @@ -7,12 +7,8 @@ "CVE-2020-11264" ], "details": "Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp5m-9hr9-82w2/GHSA-jp5m-9hr9-82w2.json b/advisories/unreviewed/2022/05/GHSA-jp5m-9hr9-82w2/GHSA-jp5m-9hr9-82w2.json index a72ae4c63b6..144a52c153a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp5m-9hr9-82w2/GHSA-jp5m-9hr9-82w2.json +++ b/advisories/unreviewed/2022/05/GHSA-jp5m-9hr9-82w2/GHSA-jp5m-9hr9-82w2.json @@ -7,12 +7,8 @@ "CVE-2021-38707" ], "details": "Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. This can result in account takeover via session token theft.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp7p-c272-p959/GHSA-jp7p-c272-p959.json b/advisories/unreviewed/2022/05/GHSA-jp7p-c272-p959/GHSA-jp7p-c272-p959.json index 64d5cce18e6..ee23b73133c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp7p-c272-p959/GHSA-jp7p-c272-p959.json +++ b/advisories/unreviewed/2022/05/GHSA-jp7p-c272-p959/GHSA-jp7p-c272-p959.json @@ -7,12 +7,8 @@ "CVE-2021-40284" ], "details": "D-Link DSL-3782 EU v1.01:EU v1.03 is affected by a buffer overflow which can cause a denial of service. This vulnerability exists in the web interface \"/cgi-bin/New_GUI/Igmp.asp\". Authenticated remote attackers can trigger this vulnerability by sending a long string in parameter 'igmpsnoopEnable' via an HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jphx-j9jw-r6cr/GHSA-jphx-j9jw-r6cr.json b/advisories/unreviewed/2022/05/GHSA-jphx-j9jw-r6cr/GHSA-jphx-j9jw-r6cr.json index f50651d89ce..8a1c44b5531 100644 --- a/advisories/unreviewed/2022/05/GHSA-jphx-j9jw-r6cr/GHSA-jphx-j9jw-r6cr.json +++ b/advisories/unreviewed/2022/05/GHSA-jphx-j9jw-r6cr/GHSA-jphx-j9jw-r6cr.json @@ -7,12 +7,8 @@ "CVE-2005-3980" ], "details": "SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jpp9-ph8w-g7g3/GHSA-jpp9-ph8w-g7g3.json b/advisories/unreviewed/2022/05/GHSA-jpp9-ph8w-g7g3/GHSA-jpp9-ph8w-g7g3.json index 83d3760533d..85e13be2634 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpp9-ph8w-g7g3/GHSA-jpp9-ph8w-g7g3.json +++ b/advisories/unreviewed/2022/05/GHSA-jpp9-ph8w-g7g3/GHSA-jpp9-ph8w-g7g3.json @@ -7,12 +7,8 @@ "CVE-2005-4150" ], "details": "Cross-site scripting (XSS) vulnerability in the portal login page in Computer Associates CleverPath 4.7 allows remote attackers to execute Javascript via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jr28-h3mc-x46r/GHSA-jr28-h3mc-x46r.json b/advisories/unreviewed/2022/05/GHSA-jr28-h3mc-x46r/GHSA-jr28-h3mc-x46r.json index 3b40e610ed4..cc643383fba 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr28-h3mc-x46r/GHSA-jr28-h3mc-x46r.json +++ b/advisories/unreviewed/2022/05/GHSA-jr28-h3mc-x46r/GHSA-jr28-h3mc-x46r.json @@ -7,12 +7,8 @@ "CVE-2021-40540" ], "details": "ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check for certain malformed HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jr8m-qx83-r6p3/GHSA-jr8m-qx83-r6p3.json b/advisories/unreviewed/2022/05/GHSA-jr8m-qx83-r6p3/GHSA-jr8m-qx83-r6p3.json index f771cccec78..90f4652b458 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr8m-qx83-r6p3/GHSA-jr8m-qx83-r6p3.json +++ b/advisories/unreviewed/2022/05/GHSA-jr8m-qx83-r6p3/GHSA-jr8m-qx83-r6p3.json @@ -7,12 +7,8 @@ "CVE-2021-28139" ], "details": "The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, allowing attackers in radio range to trigger arbitrary code execution in ESP32 via a crafted Extended Features bitfield payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvj6-gw3m-g9hf/GHSA-jvj6-gw3m-g9hf.json b/advisories/unreviewed/2022/05/GHSA-jvj6-gw3m-g9hf/GHSA-jvj6-gw3m-g9hf.json index ad45b4e7a8c..d11def5ea49 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvj6-gw3m-g9hf/GHSA-jvj6-gw3m-g9hf.json +++ b/advisories/unreviewed/2022/05/GHSA-jvj6-gw3m-g9hf/GHSA-jvj6-gw3m-g9hf.json @@ -7,12 +7,8 @@ "CVE-2021-1972" ], "details": "Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwmg-q4wv-f75h/GHSA-jwmg-q4wv-f75h.json b/advisories/unreviewed/2022/05/GHSA-jwmg-q4wv-f75h/GHSA-jwmg-q4wv-f75h.json index fd596b99a97..41098e4b3f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwmg-q4wv-f75h/GHSA-jwmg-q4wv-f75h.json +++ b/advisories/unreviewed/2022/05/GHSA-jwmg-q4wv-f75h/GHSA-jwmg-q4wv-f75h.json @@ -7,12 +7,8 @@ "CVE-2021-40346" ], "details": "An integer overflow exists in HAProxy 2.0 through 2.5 in the htx_add_header() can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m24v-9xcf-xr26/GHSA-m24v-9xcf-xr26.json b/advisories/unreviewed/2022/05/GHSA-m24v-9xcf-xr26/GHSA-m24v-9xcf-xr26.json index 218c48b245f..0f630fe277e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m24v-9xcf-xr26/GHSA-m24v-9xcf-xr26.json +++ b/advisories/unreviewed/2022/05/GHSA-m24v-9xcf-xr26/GHSA-m24v-9xcf-xr26.json @@ -7,12 +7,8 @@ "CVE-2021-30800" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 14.7. Joining a malicious Wi-Fi network may result in a denial of service or arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2m5-p4p4-3w6r/GHSA-m2m5-p4p4-3w6r.json b/advisories/unreviewed/2022/05/GHSA-m2m5-p4p4-3w6r/GHSA-m2m5-p4p4-3w6r.json index 89d75360bb3..aab6707dbdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2m5-p4p4-3w6r/GHSA-m2m5-p4p4-3w6r.json +++ b/advisories/unreviewed/2022/05/GHSA-m2m5-p4p4-3w6r/GHSA-m2m5-p4p4-3w6r.json @@ -7,12 +7,8 @@ "CVE-2021-1881" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted font file may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m373-x696-qcxc/GHSA-m373-x696-qcxc.json b/advisories/unreviewed/2022/05/GHSA-m373-x696-qcxc/GHSA-m373-x696-qcxc.json index ad287d4c0de..00719f0b7db 100644 --- a/advisories/unreviewed/2022/05/GHSA-m373-x696-qcxc/GHSA-m373-x696-qcxc.json +++ b/advisories/unreviewed/2022/05/GHSA-m373-x696-qcxc/GHSA-m373-x696-qcxc.json @@ -7,12 +7,8 @@ "CVE-2021-1843" ], "details": "This issue was addressed with improved checks. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted image may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m439-jg5v-8cp2/GHSA-m439-jg5v-8cp2.json b/advisories/unreviewed/2022/05/GHSA-m439-jg5v-8cp2/GHSA-m439-jg5v-8cp2.json index 2eeedd3fcef..b4385ce8bd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-m439-jg5v-8cp2/GHSA-m439-jg5v-8cp2.json +++ b/advisories/unreviewed/2022/05/GHSA-m439-jg5v-8cp2/GHSA-m439-jg5v-8cp2.json @@ -7,12 +7,8 @@ "CVE-2005-3991" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via the medium parameter to (1) start_page.css.php and (2) style.css.php; or the From parameter to users_popupL.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m4jf-3r59-83j5/GHSA-m4jf-3r59-83j5.json b/advisories/unreviewed/2022/05/GHSA-m4jf-3r59-83j5/GHSA-m4jf-3r59-83j5.json index 3c4f9d39832..725c9e99010 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4jf-3r59-83j5/GHSA-m4jf-3r59-83j5.json +++ b/advisories/unreviewed/2022/05/GHSA-m4jf-3r59-83j5/GHSA-m4jf-3r59-83j5.json @@ -7,12 +7,8 @@ "CVE-2021-33483" ], "details": "An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4w5-gcq7-74fp/GHSA-m4w5-gcq7-74fp.json b/advisories/unreviewed/2022/05/GHSA-m4w5-gcq7-74fp/GHSA-m4w5-gcq7-74fp.json index dd0d6280cfd..7ad4ac1f7c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4w5-gcq7-74fp/GHSA-m4w5-gcq7-74fp.json +++ b/advisories/unreviewed/2022/05/GHSA-m4w5-gcq7-74fp/GHSA-m4w5-gcq7-74fp.json @@ -7,12 +7,8 @@ "CVE-2021-1880" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.4. Processing a maliciously crafted image may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m59h-qpxv-j78w/GHSA-m59h-qpxv-j78w.json b/advisories/unreviewed/2022/05/GHSA-m59h-qpxv-j78w/GHSA-m59h-qpxv-j78w.json index c0c5d5c5811..e6fd614b690 100644 --- a/advisories/unreviewed/2022/05/GHSA-m59h-qpxv-j78w/GHSA-m59h-qpxv-j78w.json +++ b/advisories/unreviewed/2022/05/GHSA-m59h-qpxv-j78w/GHSA-m59h-qpxv-j78w.json @@ -7,12 +7,8 @@ "CVE-2005-4289" ], "details": "Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m5jg-j887-v87q/GHSA-m5jg-j887-v87q.json b/advisories/unreviewed/2022/05/GHSA-m5jg-j887-v87q/GHSA-m5jg-j887-v87q.json index 4f98376ac32..70ebc33f0c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5jg-j887-v87q/GHSA-m5jg-j887-v87q.json +++ b/advisories/unreviewed/2022/05/GHSA-m5jg-j887-v87q/GHSA-m5jg-j887-v87q.json @@ -7,12 +7,8 @@ "CVE-2021-30731" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Catalina. An unprivileged application may be able to capture USB devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m67h-g698-3wr3/GHSA-m67h-g698-3wr3.json b/advisories/unreviewed/2022/05/GHSA-m67h-g698-3wr3/GHSA-m67h-g698-3wr3.json index 3dac4cd1bb9..ff9239142ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-m67h-g698-3wr3/GHSA-m67h-g698-3wr3.json +++ b/advisories/unreviewed/2022/05/GHSA-m67h-g698-3wr3/GHSA-m67h-g698-3wr3.json @@ -7,12 +7,8 @@ "CVE-2021-33930" ], "details": "Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6hh-6w6m-5h5c/GHSA-m6hh-6w6m-5h5c.json b/advisories/unreviewed/2022/05/GHSA-m6hh-6w6m-5h5c/GHSA-m6hh-6w6m-5h5c.json index 33e6fb4d756..06a395fde12 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6hh-6w6m-5h5c/GHSA-m6hh-6w6m-5h5c.json +++ b/advisories/unreviewed/2022/05/GHSA-m6hh-6w6m-5h5c/GHSA-m6hh-6w6m-5h5c.json @@ -7,12 +7,8 @@ "CVE-2021-37206" ], "details": "A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP200 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP300 (All versions < V8.80). Received webpackets are not properly processed. An unauthenticated remote attacker with access to any of the Ethernet interfaces could send specially crafted packets to force a restart of the target device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m739-9w4c-mx4g/GHSA-m739-9w4c-mx4g.json b/advisories/unreviewed/2022/05/GHSA-m739-9w4c-mx4g/GHSA-m739-9w4c-mx4g.json index a5ef61d603c..b8235884334 100644 --- a/advisories/unreviewed/2022/05/GHSA-m739-9w4c-mx4g/GHSA-m739-9w4c-mx4g.json +++ b/advisories/unreviewed/2022/05/GHSA-m739-9w4c-mx4g/GHSA-m739-9w4c-mx4g.json @@ -7,12 +7,8 @@ "CVE-2021-34147" ], "details": "The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 does not properly handle the reception of a malformed LMP timing accuracy response followed by multiple reconnections to the link slave, allowing attackers to exhaust device BT resources and eventually trigger a crash via multiple attempts of sending a crafted LMP timing accuracy response followed by a sudden reconnection with a random BDAddress.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m7mq-hvr6-vqf7/GHSA-m7mq-hvr6-vqf7.json b/advisories/unreviewed/2022/05/GHSA-m7mq-hvr6-vqf7/GHSA-m7mq-hvr6-vqf7.json index f0fa6538933..0520c98345a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7mq-hvr6-vqf7/GHSA-m7mq-hvr6-vqf7.json +++ b/advisories/unreviewed/2022/05/GHSA-m7mq-hvr6-vqf7/GHSA-m7mq-hvr6-vqf7.json @@ -7,12 +7,8 @@ "CVE-2005-4034" ], "details": "Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8qq-fqgv-mw3c/GHSA-m8qq-fqgv-mw3c.json b/advisories/unreviewed/2022/05/GHSA-m8qq-fqgv-mw3c/GHSA-m8qq-fqgv-mw3c.json index 78c6c888259..efd1d8cd122 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8qq-fqgv-mw3c/GHSA-m8qq-fqgv-mw3c.json +++ b/advisories/unreviewed/2022/05/GHSA-m8qq-fqgv-mw3c/GHSA-m8qq-fqgv-mw3c.json @@ -7,12 +7,8 @@ "CVE-2005-4215" ], "details": "Motorola SB5100E Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m93c-j7hg-hwmj/GHSA-m93c-j7hg-hwmj.json b/advisories/unreviewed/2022/05/GHSA-m93c-j7hg-hwmj/GHSA-m93c-j7hg-hwmj.json index 6f30cd12fa4..020f5e4081b 100644 --- a/advisories/unreviewed/2022/05/GHSA-m93c-j7hg-hwmj/GHSA-m93c-j7hg-hwmj.json +++ b/advisories/unreviewed/2022/05/GHSA-m93c-j7hg-hwmj/GHSA-m93c-j7hg-hwmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m942-g3j4-p4jh/GHSA-m942-g3j4-p4jh.json b/advisories/unreviewed/2022/05/GHSA-m942-g3j4-p4jh/GHSA-m942-g3j4-p4jh.json index be948bcc029..8e0fbe3dfce 100644 --- a/advisories/unreviewed/2022/05/GHSA-m942-g3j4-p4jh/GHSA-m942-g3j4-p4jh.json +++ b/advisories/unreviewed/2022/05/GHSA-m942-g3j4-p4jh/GHSA-m942-g3j4-p4jh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m98h-48v7-g4f9/GHSA-m98h-48v7-g4f9.json b/advisories/unreviewed/2022/05/GHSA-m98h-48v7-g4f9/GHSA-m98h-48v7-g4f9.json index 4c4f041e45d..4f00c07da8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m98h-48v7-g4f9/GHSA-m98h-48v7-g4f9.json +++ b/advisories/unreviewed/2022/05/GHSA-m98h-48v7-g4f9/GHSA-m98h-48v7-g4f9.json @@ -7,12 +7,8 @@ "CVE-2021-38360" ], "details": "The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote code execution, in versions up to and including 0.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9cm-8x3h-gr6j/GHSA-m9cm-8x3h-gr6j.json b/advisories/unreviewed/2022/05/GHSA-m9cm-8x3h-gr6j/GHSA-m9cm-8x3h-gr6j.json index 6d33a5174a9..d8705c91d9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9cm-8x3h-gr6j/GHSA-m9cm-8x3h-gr6j.json +++ b/advisories/unreviewed/2022/05/GHSA-m9cm-8x3h-gr6j/GHSA-m9cm-8x3h-gr6j.json @@ -7,12 +7,8 @@ "CVE-2021-30667" ], "details": "A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in WiFi range may be able to force a client to use a less secure authentication mechanism.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mc2x-3fjp-hwc7/GHSA-mc2x-3fjp-hwc7.json b/advisories/unreviewed/2022/05/GHSA-mc2x-3fjp-hwc7/GHSA-mc2x-3fjp-hwc7.json index 76fc930538a..d393adaaed9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc2x-3fjp-hwc7/GHSA-mc2x-3fjp-hwc7.json +++ b/advisories/unreviewed/2022/05/GHSA-mc2x-3fjp-hwc7/GHSA-mc2x-3fjp-hwc7.json @@ -7,12 +7,8 @@ "CVE-2021-30717" ], "details": "A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mchx-3rmv-f23h/GHSA-mchx-3rmv-f23h.json b/advisories/unreviewed/2022/05/GHSA-mchx-3rmv-f23h/GHSA-mchx-3rmv-f23h.json index 3fd15c88860..b260e060e26 100644 --- a/advisories/unreviewed/2022/05/GHSA-mchx-3rmv-f23h/GHSA-mchx-3rmv-f23h.json +++ b/advisories/unreviewed/2022/05/GHSA-mchx-3rmv-f23h/GHSA-mchx-3rmv-f23h.json @@ -7,12 +7,8 @@ "CVE-2005-4167" ], "details": "Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mcw3-qqp9-m3r9/GHSA-mcw3-qqp9-m3r9.json b/advisories/unreviewed/2022/05/GHSA-mcw3-qqp9-m3r9/GHSA-mcw3-qqp9-m3r9.json index e8d6262dd96..66c6fd66e8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcw3-qqp9-m3r9/GHSA-mcw3-qqp9-m3r9.json +++ b/advisories/unreviewed/2022/05/GHSA-mcw3-qqp9-m3r9/GHSA-mcw3-qqp9-m3r9.json @@ -7,12 +7,8 @@ "CVE-2021-30698" ], "details": "A null pointer dereference was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, Safari 14.1.1, iOS 14.6 and iPadOS 14.6. A remote attacker may be able to cause a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcwj-mj5h-p34c/GHSA-mcwj-mj5h-p34c.json b/advisories/unreviewed/2022/05/GHSA-mcwj-mj5h-p34c/GHSA-mcwj-mj5h-p34c.json index 0390458fbec..ae6a915d277 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcwj-mj5h-p34c/GHSA-mcwj-mj5h-p34c.json +++ b/advisories/unreviewed/2022/05/GHSA-mcwj-mj5h-p34c/GHSA-mcwj-mj5h-p34c.json @@ -7,12 +7,8 @@ "CVE-2021-30612" ], "details": "Use after free in WebRTC in Google Chrome on Linux, ChromeOS prior to 93.0.4577.63 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf6j-54v8-45qr/GHSA-mf6j-54v8-45qr.json b/advisories/unreviewed/2022/05/GHSA-mf6j-54v8-45qr/GHSA-mf6j-54v8-45qr.json index a6f5977eb7c..9e26b755649 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf6j-54v8-45qr/GHSA-mf6j-54v8-45qr.json +++ b/advisories/unreviewed/2022/05/GHSA-mf6j-54v8-45qr/GHSA-mf6j-54v8-45qr.json @@ -7,12 +7,8 @@ "CVE-2021-28564" ], "details": "Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Write vulnerability within the ImageTool component. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfcq-4jh5-jjj3/GHSA-mfcq-4jh5-jjj3.json b/advisories/unreviewed/2022/05/GHSA-mfcq-4jh5-jjj3/GHSA-mfcq-4jh5-jjj3.json index d4d27459284..df3eb5aa49a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfcq-4jh5-jjj3/GHSA-mfcq-4jh5-jjj3.json +++ b/advisories/unreviewed/2022/05/GHSA-mfcq-4jh5-jjj3/GHSA-mfcq-4jh5-jjj3.json @@ -7,12 +7,8 @@ "CVE-2005-4274" ], "details": "Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related to \"authentication mechanisms\" and \"form input.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgqc-hq49-84rm/GHSA-mgqc-hq49-84rm.json b/advisories/unreviewed/2022/05/GHSA-mgqc-hq49-84rm/GHSA-mgqc-hq49-84rm.json index c562ae8e59f..c3044b390e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgqc-hq49-84rm/GHSA-mgqc-hq49-84rm.json +++ b/advisories/unreviewed/2022/05/GHSA-mgqc-hq49-84rm/GHSA-mgqc-hq49-84rm.json @@ -7,12 +7,8 @@ "CVE-2005-4170" ], "details": "SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgr7-vch3-x89h/GHSA-mgr7-vch3-x89h.json b/advisories/unreviewed/2022/05/GHSA-mgr7-vch3-x89h/GHSA-mgr7-vch3-x89h.json index 630f674cb81..569e27f16fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgr7-vch3-x89h/GHSA-mgr7-vch3-x89h.json +++ b/advisories/unreviewed/2022/05/GHSA-mgr7-vch3-x89h/GHSA-mgr7-vch3-x89h.json @@ -7,12 +7,8 @@ "CVE-2021-36095" ], "details": "Malicious attacker is able to find out valid user logins by using the \"lost password\" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhx2-29jj-rxfr/GHSA-mhx2-29jj-rxfr.json b/advisories/unreviewed/2022/05/GHSA-mhx2-29jj-rxfr/GHSA-mhx2-29jj-rxfr.json index c3d9b174e64..b33b71d1c5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhx2-29jj-rxfr/GHSA-mhx2-29jj-rxfr.json +++ b/advisories/unreviewed/2022/05/GHSA-mhx2-29jj-rxfr/GHSA-mhx2-29jj-rxfr.json @@ -7,12 +7,8 @@ "CVE-2021-30786" ], "details": "A race condition was addressed with improved state handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhxc-vmch-9frr/GHSA-mhxc-vmch-9frr.json b/advisories/unreviewed/2022/05/GHSA-mhxc-vmch-9frr/GHSA-mhxc-vmch-9frr.json index 649f070dbb7..1f0f2f165eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhxc-vmch-9frr/GHSA-mhxc-vmch-9frr.json +++ b/advisories/unreviewed/2022/05/GHSA-mhxc-vmch-9frr/GHSA-mhxc-vmch-9frr.json @@ -7,12 +7,8 @@ "CVE-2005-3931" ], "details": "SQL injection vulnerability in default.asp in ASP-Rider 1.6 allows remote attackers to execute arbitrary SQL commands via the HTTP referer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhxv-2pvp-28fg/GHSA-mhxv-2pvp-28fg.json b/advisories/unreviewed/2022/05/GHSA-mhxv-2pvp-28fg/GHSA-mhxv-2pvp-28fg.json index e204498e044..df7457eed14 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhxv-2pvp-28fg/GHSA-mhxv-2pvp-28fg.json +++ b/advisories/unreviewed/2022/05/GHSA-mhxv-2pvp-28fg/GHSA-mhxv-2pvp-28fg.json @@ -7,12 +7,8 @@ "CVE-2005-3995" ], "details": "Format string vulnerability in the dosyslog function in the OBEX server (obexsrv.c) for Sobexsrv before 1.0.0-pre4, when the syslog (-S) function is enabled, allows remote attackers to execute arbitrary code via format string specifiers in file name arguments to OBEX commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjg6-fgp9-mhgq/GHSA-mjg6-fgp9-mhgq.json b/advisories/unreviewed/2022/05/GHSA-mjg6-fgp9-mhgq/GHSA-mjg6-fgp9-mhgq.json index 443604f40f7..a7d9c6c8e11 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjg6-fgp9-mhgq/GHSA-mjg6-fgp9-mhgq.json +++ b/advisories/unreviewed/2022/05/GHSA-mjg6-fgp9-mhgq/GHSA-mjg6-fgp9-mhgq.json @@ -7,12 +7,8 @@ "CVE-2021-30290" ], "details": "Possible null pointer dereference due to race condition between timeline fence signal and time line fence destroy in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjqw-m6f3-h86r/GHSA-mjqw-m6f3-h86r.json b/advisories/unreviewed/2022/05/GHSA-mjqw-m6f3-h86r/GHSA-mjqw-m6f3-h86r.json index 5895935e5fe..312eb4134e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjqw-m6f3-h86r/GHSA-mjqw-m6f3-h86r.json +++ b/advisories/unreviewed/2022/05/GHSA-mjqw-m6f3-h86r/GHSA-mjqw-m6f3-h86r.json @@ -7,12 +7,8 @@ "CVE-2021-30699" ], "details": "A window management issue was addressed with improved state management. This issue is fixed in iOS 14.6 and iPadOS 14.6. A user may be able to view restricted content from the lockscreen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjrp-x8v8-f2mx/GHSA-mjrp-x8v8-f2mx.json b/advisories/unreviewed/2022/05/GHSA-mjrp-x8v8-f2mx/GHSA-mjrp-x8v8-f2mx.json index 147e510e720..d24151481a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjrp-x8v8-f2mx/GHSA-mjrp-x8v8-f2mx.json +++ b/advisories/unreviewed/2022/05/GHSA-mjrp-x8v8-f2mx/GHSA-mjrp-x8v8-f2mx.json @@ -7,12 +7,8 @@ "CVE-2021-3768" ], "details": "bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjrv-5v4q-78q6/GHSA-mjrv-5v4q-78q6.json b/advisories/unreviewed/2022/05/GHSA-mjrv-5v4q-78q6/GHSA-mjrv-5v4q-78q6.json index 335bcb9c4ea..84a9de2b17e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjrv-5v4q-78q6/GHSA-mjrv-5v4q-78q6.json +++ b/advisories/unreviewed/2022/05/GHSA-mjrv-5v4q-78q6/GHSA-mjrv-5v4q-78q6.json @@ -7,12 +7,8 @@ "CVE-2021-30704" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mm72-4ppf-mcx7/GHSA-mm72-4ppf-mcx7.json b/advisories/unreviewed/2022/05/GHSA-mm72-4ppf-mcx7/GHSA-mm72-4ppf-mcx7.json index 1ff975d9db2..0b226f644fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-mm72-4ppf-mcx7/GHSA-mm72-4ppf-mcx7.json +++ b/advisories/unreviewed/2022/05/GHSA-mm72-4ppf-mcx7/GHSA-mm72-4ppf-mcx7.json @@ -7,12 +7,8 @@ "CVE-2021-1851" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp45-465m-vg8h/GHSA-mp45-465m-vg8h.json b/advisories/unreviewed/2022/05/GHSA-mp45-465m-vg8h/GHSA-mp45-465m-vg8h.json index cc59957d3e8..e652409b156 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp45-465m-vg8h/GHSA-mp45-465m-vg8h.json +++ b/advisories/unreviewed/2022/05/GHSA-mp45-465m-vg8h/GHSA-mp45-465m-vg8h.json @@ -7,12 +7,8 @@ "CVE-2021-25462" ], "details": "NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp66-x979-42jc/GHSA-mp66-x979-42jc.json b/advisories/unreviewed/2022/05/GHSA-mp66-x979-42jc/GHSA-mp66-x979-42jc.json index 5164fb50772..5bed9568d8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp66-x979-42jc/GHSA-mp66-x979-42jc.json +++ b/advisories/unreviewed/2022/05/GHSA-mp66-x979-42jc/GHSA-mp66-x979-42jc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpq8-w9f5-qm6g/GHSA-mpq8-w9f5-qm6g.json b/advisories/unreviewed/2022/05/GHSA-mpq8-w9f5-qm6g/GHSA-mpq8-w9f5-qm6g.json index 15876824a7f..b4c194e4868 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpq8-w9f5-qm6g/GHSA-mpq8-w9f5-qm6g.json +++ b/advisories/unreviewed/2022/05/GHSA-mpq8-w9f5-qm6g/GHSA-mpq8-w9f5-qm6g.json @@ -7,12 +7,8 @@ "CVE-2021-40357" ], "details": "A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.10), Teamcenter Active Workspace V5.0 (All versions < V5.0.8), Teamcenter Active Workspace V5.1 (All versions < V5.1.5), Teamcenter Active Workspace V5.2 (All versions < V5.2.1). A path traversal vulnerability in the application could allow an attacker to bypass certain restrictions such as direct access to other services within the host.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mq5c-744g-f8pj/GHSA-mq5c-744g-f8pj.json b/advisories/unreviewed/2022/05/GHSA-mq5c-744g-f8pj/GHSA-mq5c-744g-f8pj.json index 06231c09a53..724b758e4d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq5c-744g-f8pj/GHSA-mq5c-744g-f8pj.json +++ b/advisories/unreviewed/2022/05/GHSA-mq5c-744g-f8pj/GHSA-mq5c-744g-f8pj.json @@ -7,12 +7,8 @@ "CVE-2020-11301" ], "details": "Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mq98-f72q-hfx8/GHSA-mq98-f72q-hfx8.json b/advisories/unreviewed/2022/05/GHSA-mq98-f72q-hfx8/GHSA-mq98-f72q-hfx8.json index 1bebe8370f3..38990bb4374 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq98-f72q-hfx8/GHSA-mq98-f72q-hfx8.json +++ b/advisories/unreviewed/2022/05/GHSA-mq98-f72q-hfx8/GHSA-mq98-f72q-hfx8.json @@ -7,12 +7,8 @@ "CVE-2021-30795" ], "details": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqfq-wxw5-3h9w/GHSA-mqfq-wxw5-3h9w.json b/advisories/unreviewed/2022/05/GHSA-mqfq-wxw5-3h9w/GHSA-mqfq-wxw5-3h9w.json index 582cead7541..28b22933da4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqfq-wxw5-3h9w/GHSA-mqfq-wxw5-3h9w.json +++ b/advisories/unreviewed/2022/05/GHSA-mqfq-wxw5-3h9w/GHSA-mqfq-wxw5-3h9w.json @@ -7,12 +7,8 @@ "CVE-2021-28493" ], "details": "In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.32.0 and prior releases", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr2h-fcf6-jvx9/GHSA-mr2h-fcf6-jvx9.json b/advisories/unreviewed/2022/05/GHSA-mr2h-fcf6-jvx9/GHSA-mr2h-fcf6-jvx9.json index 6351186b3ad..0ad39fa3923 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr2h-fcf6-jvx9/GHSA-mr2h-fcf6-jvx9.json +++ b/advisories/unreviewed/2022/05/GHSA-mr2h-fcf6-jvx9/GHSA-mr2h-fcf6-jvx9.json @@ -7,12 +7,8 @@ "CVE-2021-35217" ], "details": "Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mr3f-mq88-r8jq/GHSA-mr3f-mq88-r8jq.json b/advisories/unreviewed/2022/05/GHSA-mr3f-mq88-r8jq/GHSA-mr3f-mq88-r8jq.json index 4e325c8e73d..a31221502fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr3f-mq88-r8jq/GHSA-mr3f-mq88-r8jq.json +++ b/advisories/unreviewed/2022/05/GHSA-mr3f-mq88-r8jq/GHSA-mr3f-mq88-r8jq.json @@ -7,12 +7,8 @@ "CVE-2020-19769" ], "details": "A lack of target address verification in the BurnMe() function of Rob The Bank 1.0 allows attackers to steal tokens from victim users via a crafted script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mvjf-gwx8-f39c/GHSA-mvjf-gwx8-f39c.json b/advisories/unreviewed/2022/05/GHSA-mvjf-gwx8-f39c/GHSA-mvjf-gwx8-f39c.json index af0ee845380..e76682f2fe1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvjf-gwx8-f39c/GHSA-mvjf-gwx8-f39c.json +++ b/advisories/unreviewed/2022/05/GHSA-mvjf-gwx8-f39c/GHSA-mvjf-gwx8-f39c.json @@ -7,12 +7,8 @@ "CVE-2005-4283" ], "details": "Cross-site scripting (XSS) vulnerability in The CITY Shop 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via parameters to the search module, possibly SKey to store.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mvjq-qw5h-9cj2/GHSA-mvjq-qw5h-9cj2.json b/advisories/unreviewed/2022/05/GHSA-mvjq-qw5h-9cj2/GHSA-mvjq-qw5h-9cj2.json index 019c1327740..183e4c548a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mvjq-qw5h-9cj2/GHSA-mvjq-qw5h-9cj2.json +++ b/advisories/unreviewed/2022/05/GHSA-mvjq-qw5h-9cj2/GHSA-mvjq-qw5h-9cj2.json @@ -7,12 +7,8 @@ "CVE-2020-7819" ], "details": "A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mw3j-855g-6jp8/GHSA-mw3j-855g-6jp8.json b/advisories/unreviewed/2022/05/GHSA-mw3j-855g-6jp8/GHSA-mw3j-855g-6jp8.json index b23b05e0a7f..1cb969d17d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-mw3j-855g-6jp8/GHSA-mw3j-855g-6jp8.json +++ b/advisories/unreviewed/2022/05/GHSA-mw3j-855g-6jp8/GHSA-mw3j-855g-6jp8.json @@ -7,12 +7,8 @@ "CVE-2005-4379" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to inject arbitrary web script or HTML via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; the (3) blog_id parameter to (e) blogs/view.php; and the (4) search field to (f) users/my_groups.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mwcr-69m6-hxrj/GHSA-mwcr-69m6-hxrj.json b/advisories/unreviewed/2022/05/GHSA-mwcr-69m6-hxrj/GHSA-mwcr-69m6-hxrj.json index a4ba6430715..87a70cc0ba1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwcr-69m6-hxrj/GHSA-mwcr-69m6-hxrj.json +++ b/advisories/unreviewed/2022/05/GHSA-mwcr-69m6-hxrj/GHSA-mwcr-69m6-hxrj.json @@ -7,12 +7,8 @@ "CVE-2005-4292" ], "details": "Cross-site scripting (XSS) vulnerability in CommerceSQL 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keywords parameter in the Quick Find feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mwjx-c93w-r993/GHSA-mwjx-c93w-r993.json b/advisories/unreviewed/2022/05/GHSA-mwjx-c93w-r993/GHSA-mwjx-c93w-r993.json index 38d87f84062..f864c1eec5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwjx-c93w-r993/GHSA-mwjx-c93w-r993.json +++ b/advisories/unreviewed/2022/05/GHSA-mwjx-c93w-r993/GHSA-mwjx-c93w-r993.json @@ -7,12 +7,8 @@ "CVE-2020-19264" ], "details": "A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/ApiAdminUser/itemAdd.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwr7-fm5x-rqch/GHSA-mwr7-fm5x-rqch.json b/advisories/unreviewed/2022/05/GHSA-mwr7-fm5x-rqch/GHSA-mwr7-fm5x-rqch.json index 16861d3c8c7..e2345470bec 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwr7-fm5x-rqch/GHSA-mwr7-fm5x-rqch.json +++ b/advisories/unreviewed/2022/05/GHSA-mwr7-fm5x-rqch/GHSA-mwr7-fm5x-rqch.json @@ -7,12 +7,8 @@ "CVE-2021-21086" ], "details": "Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Write vulnerability in the CoolType library. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwwv-4h92-28r2/GHSA-mwwv-4h92-28r2.json b/advisories/unreviewed/2022/05/GHSA-mwwv-4h92-28r2/GHSA-mwwv-4h92-28r2.json index bfbc6e01975..957d1de3034 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwwv-4h92-28r2/GHSA-mwwv-4h92-28r2.json +++ b/advisories/unreviewed/2022/05/GHSA-mwwv-4h92-28r2/GHSA-mwwv-4h92-28r2.json @@ -7,12 +7,8 @@ "CVE-2019-5318" ], "details": "A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x: all versions prior to 8.8.0.0. Aruba has released patches for ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx5c-gqhr-8r8j/GHSA-mx5c-gqhr-8r8j.json b/advisories/unreviewed/2022/05/GHSA-mx5c-gqhr-8r8j/GHSA-mx5c-gqhr-8r8j.json index d4a5b6930a0..f37f22e8443 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx5c-gqhr-8r8j/GHSA-mx5c-gqhr-8r8j.json +++ b/advisories/unreviewed/2022/05/GHSA-mx5c-gqhr-8r8j/GHSA-mx5c-gqhr-8r8j.json @@ -7,12 +7,8 @@ "CVE-2021-24601" ], "details": "The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2f3-wgvc-4w8q/GHSA-p2f3-wgvc-4w8q.json b/advisories/unreviewed/2022/05/GHSA-p2f3-wgvc-4w8q/GHSA-p2f3-wgvc-4w8q.json index 95087f9f867..ccf9f1c9783 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2f3-wgvc-4w8q/GHSA-p2f3-wgvc-4w8q.json +++ b/advisories/unreviewed/2022/05/GHSA-p2f3-wgvc-4w8q/GHSA-p2f3-wgvc-4w8q.json @@ -7,12 +7,8 @@ "CVE-2021-25458" ], "details": "NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p365-3j3h-vmq6/GHSA-p365-3j3h-vmq6.json b/advisories/unreviewed/2022/05/GHSA-p365-3j3h-vmq6/GHSA-p365-3j3h-vmq6.json index fc5d85fc4c0..b33f15a291c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p365-3j3h-vmq6/GHSA-p365-3j3h-vmq6.json +++ b/advisories/unreviewed/2022/05/GHSA-p365-3j3h-vmq6/GHSA-p365-3j3h-vmq6.json @@ -7,12 +7,8 @@ "CVE-2005-3998" ], "details": "Cross-site scripting (XSS) vulnerability in search.asp in Solupress News 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3r9-6fhw-hgv8/GHSA-p3r9-6fhw-hgv8.json b/advisories/unreviewed/2022/05/GHSA-p3r9-6fhw-hgv8/GHSA-p3r9-6fhw-hgv8.json index 4eba0d36056..959b0d1d5a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3r9-6fhw-hgv8/GHSA-p3r9-6fhw-hgv8.json +++ b/advisories/unreviewed/2022/05/GHSA-p3r9-6fhw-hgv8/GHSA-p3r9-6fhw-hgv8.json @@ -7,12 +7,8 @@ "CVE-2021-40530" ], "details": "The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p463-qxf4-3j5v/GHSA-p463-qxf4-3j5v.json b/advisories/unreviewed/2022/05/GHSA-p463-qxf4-3j5v/GHSA-p463-qxf4-3j5v.json index 1d273b5f9e4..6c10f9e890b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p463-qxf4-3j5v/GHSA-p463-qxf4-3j5v.json +++ b/advisories/unreviewed/2022/05/GHSA-p463-qxf4-3j5v/GHSA-p463-qxf4-3j5v.json @@ -7,12 +7,8 @@ "CVE-2021-40223" ], "details": "Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User Configuration dialog, Task Configuration dialog and set logging filter dialog). This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts). The XSS payload will be triggered when the user accesses some specific sections of the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4g7-w48q-p4cp/GHSA-p4g7-w48q-p4cp.json b/advisories/unreviewed/2022/05/GHSA-p4g7-w48q-p4cp/GHSA-p4g7-w48q-p4cp.json index 4af44f46820..bd0cc808232 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4g7-w48q-p4cp/GHSA-p4g7-w48q-p4cp.json +++ b/advisories/unreviewed/2022/05/GHSA-p4g7-w48q-p4cp/GHSA-p4g7-w48q-p4cp.json @@ -7,12 +7,8 @@ "CVE-2021-39499" ], "details": "A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4ww-48c6-98q5/GHSA-p4ww-48c6-98q5.json b/advisories/unreviewed/2022/05/GHSA-p4ww-48c6-98q5/GHSA-p4ww-48c6-98q5.json index 190cabb92f1..b2620c3901d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4ww-48c6-98q5/GHSA-p4ww-48c6-98q5.json +++ b/advisories/unreviewed/2022/05/GHSA-p4ww-48c6-98q5/GHSA-p4ww-48c6-98q5.json @@ -7,12 +7,8 @@ "CVE-2021-3646" ], "details": "btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p53v-96v3-p5jg/GHSA-p53v-96v3-p5jg.json b/advisories/unreviewed/2022/05/GHSA-p53v-96v3-p5jg/GHSA-p53v-96v3-p5jg.json index 2ec51f81462..17b2108f021 100644 --- a/advisories/unreviewed/2022/05/GHSA-p53v-96v3-p5jg/GHSA-p53v-96v3-p5jg.json +++ b/advisories/unreviewed/2022/05/GHSA-p53v-96v3-p5jg/GHSA-p53v-96v3-p5jg.json @@ -7,12 +7,8 @@ "CVE-2021-40524" ], "details": "In Pure-FTPd 1.0.49, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5rv-qv72-qcfq/GHSA-p5rv-qv72-qcfq.json b/advisories/unreviewed/2022/05/GHSA-p5rv-qv72-qcfq/GHSA-p5rv-qv72-qcfq.json index 29a0611fcff..56938e6e942 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5rv-qv72-qcfq/GHSA-p5rv-qv72-qcfq.json +++ b/advisories/unreviewed/2022/05/GHSA-p5rv-qv72-qcfq/GHSA-p5rv-qv72-qcfq.json @@ -7,12 +7,8 @@ "CVE-2005-4293" ], "details": "Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p5xr-f67h-9rw9/GHSA-p5xr-f67h-9rw9.json b/advisories/unreviewed/2022/05/GHSA-p5xr-f67h-9rw9/GHSA-p5xr-f67h-9rw9.json index c185bbb7271..bed4bbe9d3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5xr-f67h-9rw9/GHSA-p5xr-f67h-9rw9.json +++ b/advisories/unreviewed/2022/05/GHSA-p5xr-f67h-9rw9/GHSA-p5xr-f67h-9rw9.json @@ -7,12 +7,8 @@ "CVE-2005-4147" ], "details": "The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing \"@\" characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p64p-9fg8-c6rp/GHSA-p64p-9fg8-c6rp.json b/advisories/unreviewed/2022/05/GHSA-p64p-9fg8-c6rp/GHSA-p64p-9fg8-c6rp.json index 1b7c27721d0..6a8fabf2001 100644 --- a/advisories/unreviewed/2022/05/GHSA-p64p-9fg8-c6rp/GHSA-p64p-9fg8-c6rp.json +++ b/advisories/unreviewed/2022/05/GHSA-p64p-9fg8-c6rp/GHSA-p64p-9fg8-c6rp.json @@ -7,12 +7,8 @@ "CVE-2021-24394" ], "details": "An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6m6-g28j-5g3h/GHSA-p6m6-g28j-5g3h.json b/advisories/unreviewed/2022/05/GHSA-p6m6-g28j-5g3h/GHSA-p6m6-g28j-5g3h.json index 524c1cce782..5283b6b2ab7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6m6-g28j-5g3h/GHSA-p6m6-g28j-5g3h.json +++ b/advisories/unreviewed/2022/05/GHSA-p6m6-g28j-5g3h/GHSA-p6m6-g28j-5g3h.json @@ -7,12 +7,8 @@ "CVE-2021-37723" ], "details": "A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released patches for ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6mq-mfwr-x238/GHSA-p6mq-mfwr-x238.json b/advisories/unreviewed/2022/05/GHSA-p6mq-mfwr-x238/GHSA-p6mq-mfwr-x238.json index 76d5beb0a3e..bd4fe8d2abc 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6mq-mfwr-x238/GHSA-p6mq-mfwr-x238.json +++ b/advisories/unreviewed/2022/05/GHSA-p6mq-mfwr-x238/GHSA-p6mq-mfwr-x238.json @@ -7,12 +7,8 @@ "CVE-2005-4038" ], "details": "SQL injection vulnerability in comentarii.php in Web4Future Portal Solutions News Portal allows remote attackers to execute arbitrary SQL commands via the idp parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p79w-9c5j-r2gw/GHSA-p79w-9c5j-r2gw.json b/advisories/unreviewed/2022/05/GHSA-p79w-9c5j-r2gw/GHSA-p79w-9c5j-r2gw.json index 7383e557337..7797368621f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p79w-9c5j-r2gw/GHSA-p79w-9c5j-r2gw.json +++ b/advisories/unreviewed/2022/05/GHSA-p79w-9c5j-r2gw/GHSA-p79w-9c5j-r2gw.json @@ -7,12 +7,8 @@ "CVE-2021-36094" ], "details": "It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7m9-q5j5-3jgv/GHSA-p7m9-q5j5-3jgv.json b/advisories/unreviewed/2022/05/GHSA-p7m9-q5j5-3jgv/GHSA-p7m9-q5j5-3jgv.json index 271a0adc5dc..11f962117b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7m9-q5j5-3jgv/GHSA-p7m9-q5j5-3jgv.json +++ b/advisories/unreviewed/2022/05/GHSA-p7m9-q5j5-3jgv/GHSA-p7m9-q5j5-3jgv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8h5-xqwr-ww86/GHSA-p8h5-xqwr-ww86.json b/advisories/unreviewed/2022/05/GHSA-p8h5-xqwr-ww86/GHSA-p8h5-xqwr-ww86.json index b0ddbcac613..84ec1dc4475 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8h5-xqwr-ww86/GHSA-p8h5-xqwr-ww86.json +++ b/advisories/unreviewed/2022/05/GHSA-p8h5-xqwr-ww86/GHSA-p8h5-xqwr-ww86.json @@ -7,12 +7,8 @@ "CVE-2021-36093" ], "details": "It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p95x-f93r-h96r/GHSA-p95x-f93r-h96r.json b/advisories/unreviewed/2022/05/GHSA-p95x-f93r-h96r/GHSA-p95x-f93r-h96r.json index bc487740439..498f50a14b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p95x-f93r-h96r/GHSA-p95x-f93r-h96r.json +++ b/advisories/unreviewed/2022/05/GHSA-p95x-f93r-h96r/GHSA-p95x-f93r-h96r.json @@ -7,12 +7,8 @@ "CVE-2005-3982" ], "details": "CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p97q-qr3w-x236/GHSA-p97q-qr3w-x236.json b/advisories/unreviewed/2022/05/GHSA-p97q-qr3w-x236/GHSA-p97q-qr3w-x236.json index 547b863e4ab..ed80690145c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p97q-qr3w-x236/GHSA-p97q-qr3w-x236.json +++ b/advisories/unreviewed/2022/05/GHSA-p97q-qr3w-x236/GHSA-p97q-qr3w-x236.json @@ -7,12 +7,8 @@ "CVE-2021-28494" ], "details": "In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior releases", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9jm-j7j3-qc5g/GHSA-p9jm-j7j3-qc5g.json b/advisories/unreviewed/2022/05/GHSA-p9jm-j7j3-qc5g/GHSA-p9jm-j7j3-qc5g.json index d2dbb746318..f681cad41ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9jm-j7j3-qc5g/GHSA-p9jm-j7j3-qc5g.json +++ b/advisories/unreviewed/2022/05/GHSA-p9jm-j7j3-qc5g/GHSA-p9jm-j7j3-qc5g.json @@ -7,12 +7,8 @@ "CVE-2021-38721" ], "details": "FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc3j-ph7x-cxh4/GHSA-pc3j-ph7x-cxh4.json b/advisories/unreviewed/2022/05/GHSA-pc3j-ph7x-cxh4/GHSA-pc3j-ph7x-cxh4.json index 621f2d55c43..b16e3f502fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc3j-ph7x-cxh4/GHSA-pc3j-ph7x-cxh4.json +++ b/advisories/unreviewed/2022/05/GHSA-pc3j-ph7x-cxh4/GHSA-pc3j-ph7x-cxh4.json @@ -7,12 +7,8 @@ "CVE-2021-38408" ], "details": "A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc9g-xxwr-7rq9/GHSA-pc9g-xxwr-7rq9.json b/advisories/unreviewed/2022/05/GHSA-pc9g-xxwr-7rq9/GHSA-pc9g-xxwr-7rq9.json index a434ec46dbf..27e2d563ab3 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc9g-xxwr-7rq9/GHSA-pc9g-xxwr-7rq9.json +++ b/advisories/unreviewed/2022/05/GHSA-pc9g-xxwr-7rq9/GHSA-pc9g-xxwr-7rq9.json @@ -7,12 +7,8 @@ "CVE-2005-4258" ], "details": "Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pfcx-4587-hw8m/GHSA-pfcx-4587-hw8m.json b/advisories/unreviewed/2022/05/GHSA-pfcx-4587-hw8m/GHSA-pfcx-4587-hw8m.json index 111ac872b63..ebae76fb0d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-pfcx-4587-hw8m/GHSA-pfcx-4587-hw8m.json +++ b/advisories/unreviewed/2022/05/GHSA-pfcx-4587-hw8m/GHSA-pfcx-4587-hw8m.json @@ -7,12 +7,8 @@ "CVE-2021-37202" ], "details": "A vulnerability has been identified in NX 1980 Series (All versions < V1984). The IFC adapter in affected application contains a use-after-free vulnerability that could be triggered while parsing user-supplied IFC files. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg5g-hrxm-397x/GHSA-pg5g-hrxm-397x.json b/advisories/unreviewed/2022/05/GHSA-pg5g-hrxm-397x/GHSA-pg5g-hrxm-397x.json index 5ade8ac5664..4c31d6c86ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg5g-hrxm-397x/GHSA-pg5g-hrxm-397x.json +++ b/advisories/unreviewed/2022/05/GHSA-pg5g-hrxm-397x/GHSA-pg5g-hrxm-397x.json @@ -7,12 +7,8 @@ "CVE-2021-1810" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgj6-vc56-h2jc/GHSA-pgj6-vc56-h2jc.json b/advisories/unreviewed/2022/05/GHSA-pgj6-vc56-h2jc/GHSA-pgj6-vc56-h2jc.json index 4cc6d296d5c..9d7af687141 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgj6-vc56-h2jc/GHSA-pgj6-vc56-h2jc.json +++ b/advisories/unreviewed/2022/05/GHSA-pgj6-vc56-h2jc/GHSA-pgj6-vc56-h2jc.json @@ -7,12 +7,8 @@ "CVE-2005-4342" ], "details": "ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to \"bypass security controls,\" aka \"JRun Clustered Sandbox Security Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgwh-c5gq-c23j/GHSA-pgwh-c5gq-c23j.json b/advisories/unreviewed/2022/05/GHSA-pgwh-c5gq-c23j/GHSA-pgwh-c5gq-c23j.json index 2a5c256d50e..81f31fbaa28 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgwh-c5gq-c23j/GHSA-pgwh-c5gq-c23j.json +++ b/advisories/unreviewed/2022/05/GHSA-pgwh-c5gq-c23j/GHSA-pgwh-c5gq-c23j.json @@ -7,12 +7,8 @@ "CVE-2005-4246" ], "details": "SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php and (2) page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ph36-4xx4-6m84/GHSA-ph36-4xx4-6m84.json b/advisories/unreviewed/2022/05/GHSA-ph36-4xx4-6m84/GHSA-ph36-4xx4-6m84.json index 68c10ba3213..04e7d31c715 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph36-4xx4-6m84/GHSA-ph36-4xx4-6m84.json +++ b/advisories/unreviewed/2022/05/GHSA-ph36-4xx4-6m84/GHSA-ph36-4xx4-6m84.json @@ -7,12 +7,8 @@ "CVE-2005-4266" ], "details": "WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ph4x-78w5-h79j/GHSA-ph4x-78w5-h79j.json b/advisories/unreviewed/2022/05/GHSA-ph4x-78w5-h79j/GHSA-ph4x-78w5-h79j.json index 21adb1142dc..3ad25d1e04d 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph4x-78w5-h79j/GHSA-ph4x-78w5-h79j.json +++ b/advisories/unreviewed/2022/05/GHSA-ph4x-78w5-h79j/GHSA-ph4x-78w5-h79j.json @@ -7,12 +7,8 @@ "CVE-2005-4135" ], "details": "Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-phfp-qm4g-g8c7/GHSA-phfp-qm4g-g8c7.json b/advisories/unreviewed/2022/05/GHSA-phfp-qm4g-g8c7/GHSA-phfp-qm4g-g8c7.json index 9482b21ddd6..65641ee5668 100644 --- a/advisories/unreviewed/2022/05/GHSA-phfp-qm4g-g8c7/GHSA-phfp-qm4g-g8c7.json +++ b/advisories/unreviewed/2022/05/GHSA-phfp-qm4g-g8c7/GHSA-phfp-qm4g-g8c7.json @@ -7,12 +7,8 @@ "CVE-2021-1838" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-phm5-3cqw-r759/GHSA-phm5-3cqw-r759.json b/advisories/unreviewed/2022/05/GHSA-phm5-3cqw-r759/GHSA-phm5-3cqw-r759.json index 03c9de4a58d..91181cb38f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-phm5-3cqw-r759/GHSA-phm5-3cqw-r759.json +++ b/advisories/unreviewed/2022/05/GHSA-phm5-3cqw-r759/GHSA-phm5-3cqw-r759.json @@ -7,12 +7,8 @@ "CVE-2021-38325" ], "details": "The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter found in the ~/user-activation-email.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj33-fhmh-3r7r/GHSA-pj33-fhmh-3r7r.json b/advisories/unreviewed/2022/05/GHSA-pj33-fhmh-3r7r/GHSA-pj33-fhmh-3r7r.json index f713a2e1290..6c4165ea7a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj33-fhmh-3r7r/GHSA-pj33-fhmh-3r7r.json +++ b/advisories/unreviewed/2022/05/GHSA-pj33-fhmh-3r7r/GHSA-pj33-fhmh-3r7r.json @@ -7,12 +7,8 @@ "CVE-2005-3964" ], "details": "Multiple buffer overflows in libUil (libUil.so) in OpenMotif 2.2.3, and possibly other versions, allows attackers to execute arbitrary code via the (1) diag_issue_diagnostic function in UilDiags.c and (2) open_source_file function in UilSrcSrc.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pj47-cjfq-jwp4/GHSA-pj47-cjfq-jwp4.json b/advisories/unreviewed/2022/05/GHSA-pj47-cjfq-jwp4/GHSA-pj47-cjfq-jwp4.json index 6499c00d679..3dca09f0d6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj47-cjfq-jwp4/GHSA-pj47-cjfq-jwp4.json +++ b/advisories/unreviewed/2022/05/GHSA-pj47-cjfq-jwp4/GHSA-pj47-cjfq-jwp4.json @@ -7,12 +7,8 @@ "CVE-2021-30671" ], "details": "A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. A malicious application may be able to send unauthorized Apple events to Finder.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj62-vwgh-4fwm/GHSA-pj62-vwgh-4fwm.json b/advisories/unreviewed/2022/05/GHSA-pj62-vwgh-4fwm/GHSA-pj62-vwgh-4fwm.json index 363ab9831dd..14b4d737768 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj62-vwgh-4fwm/GHSA-pj62-vwgh-4fwm.json +++ b/advisories/unreviewed/2022/05/GHSA-pj62-vwgh-4fwm/GHSA-pj62-vwgh-4fwm.json @@ -7,12 +7,8 @@ "CVE-2021-24303" ], "details": "The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjr8-522j-xrv6/GHSA-pjr8-522j-xrv6.json b/advisories/unreviewed/2022/05/GHSA-pjr8-522j-xrv6/GHSA-pjr8-522j-xrv6.json index 4b34b19a9fb..8c2b10000a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjr8-522j-xrv6/GHSA-pjr8-522j-xrv6.json +++ b/advisories/unreviewed/2022/05/GHSA-pjr8-522j-xrv6/GHSA-pjr8-522j-xrv6.json @@ -7,12 +7,8 @@ "CVE-2021-30792" ], "details": "An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted image may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pjwq-vqfj-r3hh/GHSA-pjwq-vqfj-r3hh.json b/advisories/unreviewed/2022/05/GHSA-pjwq-vqfj-r3hh/GHSA-pjwq-vqfj-r3hh.json index 25c4c053ecb..f03e69e98b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjwq-vqfj-r3hh/GHSA-pjwq-vqfj-r3hh.json +++ b/advisories/unreviewed/2022/05/GHSA-pjwq-vqfj-r3hh/GHSA-pjwq-vqfj-r3hh.json @@ -7,12 +7,8 @@ "CVE-2021-23052" ], "details": "On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious user to build an open redirect URI. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm4x-73f3-vvmv/GHSA-pm4x-73f3-vvmv.json b/advisories/unreviewed/2022/05/GHSA-pm4x-73f3-vvmv/GHSA-pm4x-73f3-vvmv.json index e906ccb15e4..1a57e8b0fa9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm4x-73f3-vvmv/GHSA-pm4x-73f3-vvmv.json +++ b/advisories/unreviewed/2022/05/GHSA-pm4x-73f3-vvmv/GHSA-pm4x-73f3-vvmv.json @@ -7,12 +7,8 @@ "CVE-2005-3911" ], "details": "Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) category parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pp29-fm35-p5hj/GHSA-pp29-fm35-p5hj.json b/advisories/unreviewed/2022/05/GHSA-pp29-fm35-p5hj/GHSA-pp29-fm35-p5hj.json index a8408569547..2499149062a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp29-fm35-p5hj/GHSA-pp29-fm35-p5hj.json +++ b/advisories/unreviewed/2022/05/GHSA-pp29-fm35-p5hj/GHSA-pp29-fm35-p5hj.json @@ -7,12 +7,8 @@ "CVE-2020-19138" ], "details": "Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component \"/src/main/java/com/dotmarketing/filters/CMSFilter.java\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppqc-qvpw-j83r/GHSA-ppqc-qvpw-j83r.json b/advisories/unreviewed/2022/05/GHSA-ppqc-qvpw-j83r/GHSA-ppqc-qvpw-j83r.json index 62394f38b90..17f18093da7 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppqc-qvpw-j83r/GHSA-ppqc-qvpw-j83r.json +++ b/advisories/unreviewed/2022/05/GHSA-ppqc-qvpw-j83r/GHSA-ppqc-qvpw-j83r.json @@ -7,12 +7,8 @@ "CVE-2021-38358" ], "details": "The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/views/button-generator.html.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.4.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ppv3-px64-q9mx/GHSA-ppv3-px64-q9mx.json b/advisories/unreviewed/2022/05/GHSA-ppv3-px64-q9mx/GHSA-ppv3-px64-q9mx.json index 20004d3bc11..d33769f81bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppv3-px64-q9mx/GHSA-ppv3-px64-q9mx.json +++ b/advisories/unreviewed/2022/05/GHSA-ppv3-px64-q9mx/GHSA-ppv3-px64-q9mx.json @@ -7,12 +7,8 @@ "CVE-2021-40818" ], "details": "scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer overflow during FIDO2 signature validation in webauthn registration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqwp-2662-q9j8/GHSA-pqwp-2662-q9j8.json b/advisories/unreviewed/2022/05/GHSA-pqwp-2662-q9j8/GHSA-pqwp-2662-q9j8.json index 4870877d442..745df6c6aa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqwp-2662-q9j8/GHSA-pqwp-2662-q9j8.json +++ b/advisories/unreviewed/2022/05/GHSA-pqwp-2662-q9j8/GHSA-pqwp-2662-q9j8.json @@ -7,12 +7,8 @@ "CVE-2021-32486" ], "details": "In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964928.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prp3-p73x-mqjc/GHSA-prp3-p73x-mqjc.json b/advisories/unreviewed/2022/05/GHSA-prp3-p73x-mqjc/GHSA-prp3-p73x-mqjc.json index 8ec90011aea..3141330db6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-prp3-p73x-mqjc/GHSA-prp3-p73x-mqjc.json +++ b/advisories/unreviewed/2022/05/GHSA-prp3-p73x-mqjc/GHSA-prp3-p73x-mqjc.json @@ -7,12 +7,8 @@ "CVE-2021-28912" ], "details": "BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'eibPort string'. This is usable and the final part of an attack chain to gain SSH root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prw3-h4wf-qrgf/GHSA-prw3-h4wf-qrgf.json b/advisories/unreviewed/2022/05/GHSA-prw3-h4wf-qrgf/GHSA-prw3-h4wf-qrgf.json index cec40865a6a..6f5868da499 100644 --- a/advisories/unreviewed/2022/05/GHSA-prw3-h4wf-qrgf/GHSA-prw3-h4wf-qrgf.json +++ b/advisories/unreviewed/2022/05/GHSA-prw3-h4wf-qrgf/GHSA-prw3-h4wf-qrgf.json @@ -7,12 +7,8 @@ "CVE-2005-4015" ], "details": "PHP Web Statistik 1.4 does not rotate the log database or limit the size of the referer field, which allows remote attackers to fill the log files via a large number of requests, as demonstrated using pixel.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prxq-rjvh-533j/GHSA-prxq-rjvh-533j.json b/advisories/unreviewed/2022/05/GHSA-prxq-rjvh-533j/GHSA-prxq-rjvh-533j.json index df58998a19c..4faef57e52e 100644 --- a/advisories/unreviewed/2022/05/GHSA-prxq-rjvh-533j/GHSA-prxq-rjvh-533j.json +++ b/advisories/unreviewed/2022/05/GHSA-prxq-rjvh-533j/GHSA-prxq-rjvh-533j.json @@ -7,12 +7,8 @@ "CVE-2005-4386" ], "details": "Cross-site scripting (XSS) vulnerability in Colony CMS 2.75 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pv42-mm82-grf7/GHSA-pv42-mm82-grf7.json b/advisories/unreviewed/2022/05/GHSA-pv42-mm82-grf7/GHSA-pv42-mm82-grf7.json index 1bb4f8029ba..c93569d0024 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv42-mm82-grf7/GHSA-pv42-mm82-grf7.json +++ b/advisories/unreviewed/2022/05/GHSA-pv42-mm82-grf7/GHSA-pv42-mm82-grf7.json @@ -7,12 +7,8 @@ "CVE-2005-4146" ], "details": "Lyris ListManager before 8.9b allows remote attackers to obtain sensitive information via a request to the TCLHTTPd status module, which provides sensitive server configuration information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvc2-qp9x-6rgw/GHSA-pvc2-qp9x-6rgw.json b/advisories/unreviewed/2022/05/GHSA-pvc2-qp9x-6rgw/GHSA-pvc2-qp9x-6rgw.json index f324ec3c1d6..c72697018bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvc2-qp9x-6rgw/GHSA-pvc2-qp9x-6rgw.json +++ b/advisories/unreviewed/2022/05/GHSA-pvc2-qp9x-6rgw/GHSA-pvc2-qp9x-6rgw.json @@ -7,12 +7,8 @@ "CVE-2005-4000" ], "details": "Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater News System 4.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the sKeywords parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvc6-fjgm-h5wf/GHSA-pvc6-fjgm-h5wf.json b/advisories/unreviewed/2022/05/GHSA-pvc6-fjgm-h5wf/GHSA-pvc6-fjgm-h5wf.json index 240894b6690..37b8d6d556d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvc6-fjgm-h5wf/GHSA-pvc6-fjgm-h5wf.json +++ b/advisories/unreviewed/2022/05/GHSA-pvc6-fjgm-h5wf/GHSA-pvc6-fjgm-h5wf.json @@ -7,12 +7,8 @@ "CVE-2021-30608" ], "details": "Use after free in Web Share in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvwv-hr7g-828h/GHSA-pvwv-hr7g-828h.json b/advisories/unreviewed/2022/05/GHSA-pvwv-hr7g-828h/GHSA-pvwv-hr7g-828h.json index 5df6285e8ef..124f6c8f15a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvwv-hr7g-828h/GHSA-pvwv-hr7g-828h.json +++ b/advisories/unreviewed/2022/05/GHSA-pvwv-hr7g-828h/GHSA-pvwv-hr7g-828h.json @@ -7,12 +7,8 @@ "CVE-2005-4393" ], "details": "Cross-site scripting (XSS) vulnerability in show.cfm in e-publish CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) obcatid and (2) comid parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pxc3-xjvh-jq8g/GHSA-pxc3-xjvh-jq8g.json b/advisories/unreviewed/2022/05/GHSA-pxc3-xjvh-jq8g/GHSA-pxc3-xjvh-jq8g.json index a876838410f..f6a24f076b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxc3-xjvh-jq8g/GHSA-pxc3-xjvh-jq8g.json +++ b/advisories/unreviewed/2022/05/GHSA-pxc3-xjvh-jq8g/GHSA-pxc3-xjvh-jq8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxcf-wgw3-gwc6/GHSA-pxcf-wgw3-gwc6.json b/advisories/unreviewed/2022/05/GHSA-pxcf-wgw3-gwc6/GHSA-pxcf-wgw3-gwc6.json index 1c9bcaaa468..a041b98f0cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxcf-wgw3-gwc6/GHSA-pxcf-wgw3-gwc6.json +++ b/advisories/unreviewed/2022/05/GHSA-pxcf-wgw3-gwc6/GHSA-pxcf-wgw3-gwc6.json @@ -7,12 +7,8 @@ "CVE-2021-1920" ], "details": "Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q239-wm45-8mwc/GHSA-q239-wm45-8mwc.json b/advisories/unreviewed/2022/05/GHSA-q239-wm45-8mwc/GHSA-q239-wm45-8mwc.json index f419e10bac0..df642ed4475 100644 --- a/advisories/unreviewed/2022/05/GHSA-q239-wm45-8mwc/GHSA-q239-wm45-8mwc.json +++ b/advisories/unreviewed/2022/05/GHSA-q239-wm45-8mwc/GHSA-q239-wm45-8mwc.json @@ -7,12 +7,8 @@ "CVE-2021-30797" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q248-f2x7-fhcp/GHSA-q248-f2x7-fhcp.json b/advisories/unreviewed/2022/05/GHSA-q248-f2x7-fhcp/GHSA-q248-f2x7-fhcp.json index 7c76fc22501..66921285c18 100644 --- a/advisories/unreviewed/2022/05/GHSA-q248-f2x7-fhcp/GHSA-q248-f2x7-fhcp.json +++ b/advisories/unreviewed/2022/05/GHSA-q248-f2x7-fhcp/GHSA-q248-f2x7-fhcp.json @@ -7,12 +7,8 @@ "CVE-2005-3953" ], "details": "SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q24c-8cpc-8x8c/GHSA-q24c-8cpc-8x8c.json b/advisories/unreviewed/2022/05/GHSA-q24c-8cpc-8x8c/GHSA-q24c-8cpc-8x8c.json index 68b7b5a4488..ccdaedb7e08 100644 --- a/advisories/unreviewed/2022/05/GHSA-q24c-8cpc-8x8c/GHSA-q24c-8cpc-8x8c.json +++ b/advisories/unreviewed/2022/05/GHSA-q24c-8cpc-8x8c/GHSA-q24c-8cpc-8x8c.json @@ -7,12 +7,8 @@ "CVE-2021-1914" ], "details": "Loop with unreachable exit condition may occur due to improper handling of unsupported input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3gh-3g45-67qg/GHSA-q3gh-3g45-67qg.json b/advisories/unreviewed/2022/05/GHSA-q3gh-3g45-67qg/GHSA-q3gh-3g45-67qg.json index bfcc855f022..c8aaecd8269 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3gh-3g45-67qg/GHSA-q3gh-3g45-67qg.json +++ b/advisories/unreviewed/2022/05/GHSA-q3gh-3g45-67qg/GHSA-q3gh-3g45-67qg.json @@ -7,12 +7,8 @@ "CVE-2021-36696" ], "details": "Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3jf-3m4m-hh56/GHSA-q3jf-3m4m-hh56.json b/advisories/unreviewed/2022/05/GHSA-q3jf-3m4m-hh56/GHSA-q3jf-3m4m-hh56.json index 3f285c5489a..f9c72907ef6 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3jf-3m4m-hh56/GHSA-q3jf-3m4m-hh56.json +++ b/advisories/unreviewed/2022/05/GHSA-q3jf-3m4m-hh56/GHSA-q3jf-3m4m-hh56.json @@ -7,12 +7,8 @@ "CVE-2005-3989" ], "details": "Memory leak in Avaya TN2602AP IP Media Resource 320 circuit pack before vintage 9 firmware allows remote attackers to cause a denial of service (memory consumption) via crafted VoIP packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q3x2-wj66-pg83/GHSA-q3x2-wj66-pg83.json b/advisories/unreviewed/2022/05/GHSA-q3x2-wj66-pg83/GHSA-q3x2-wj66-pg83.json index 87143c3c8fe..7392508b20f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3x2-wj66-pg83/GHSA-q3x2-wj66-pg83.json +++ b/advisories/unreviewed/2022/05/GHSA-q3x2-wj66-pg83/GHSA-q3x2-wj66-pg83.json @@ -7,12 +7,8 @@ "CVE-2005-3914" ], "details": "Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q49f-7h5w-8672/GHSA-q49f-7h5w-8672.json b/advisories/unreviewed/2022/05/GHSA-q49f-7h5w-8672/GHSA-q49f-7h5w-8672.json index a5e44170527..a03ba19a20f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q49f-7h5w-8672/GHSA-q49f-7h5w-8672.json +++ b/advisories/unreviewed/2022/05/GHSA-q49f-7h5w-8672/GHSA-q49f-7h5w-8672.json @@ -7,12 +7,8 @@ "CVE-2020-20347" ], "details": "WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4fx-wrwr-cfpx/GHSA-q4fx-wrwr-cfpx.json b/advisories/unreviewed/2022/05/GHSA-q4fx-wrwr-cfpx/GHSA-q4fx-wrwr-cfpx.json index cdca8902aa5..d82e7bd94a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4fx-wrwr-cfpx/GHSA-q4fx-wrwr-cfpx.json +++ b/advisories/unreviewed/2022/05/GHSA-q4fx-wrwr-cfpx/GHSA-q4fx-wrwr-cfpx.json @@ -7,12 +7,8 @@ "CVE-2005-4316" ], "details": "HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a \"Rose Attack\" that involves sending a subset of small IP fragments that do not form a complete, larger packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4g3-xp8v-q7h5/GHSA-q4g3-xp8v-q7h5.json b/advisories/unreviewed/2022/05/GHSA-q4g3-xp8v-q7h5/GHSA-q4g3-xp8v-q7h5.json index 6ce5bb5501f..6cac1b86e02 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4g3-xp8v-q7h5/GHSA-q4g3-xp8v-q7h5.json +++ b/advisories/unreviewed/2022/05/GHSA-q4g3-xp8v-q7h5/GHSA-q4g3-xp8v-q7h5.json @@ -7,12 +7,8 @@ "CVE-2021-24611" ], "details": "The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting via a CSRF attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4h9-78vf-qm6j/GHSA-q4h9-78vf-qm6j.json b/advisories/unreviewed/2022/05/GHSA-q4h9-78vf-qm6j/GHSA-q4h9-78vf-qm6j.json index 37c8c93f1ef..d883861b5d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4h9-78vf-qm6j/GHSA-q4h9-78vf-qm6j.json +++ b/advisories/unreviewed/2022/05/GHSA-q4h9-78vf-qm6j/GHSA-q4h9-78vf-qm6j.json @@ -7,12 +7,8 @@ "CVE-2005-4025" ], "details": "Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q58c-f3v9-6f8q/GHSA-q58c-f3v9-6f8q.json b/advisories/unreviewed/2022/05/GHSA-q58c-f3v9-6f8q/GHSA-q58c-f3v9-6f8q.json index 7e74afaa229..bfffe9c6cc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q58c-f3v9-6f8q/GHSA-q58c-f3v9-6f8q.json +++ b/advisories/unreviewed/2022/05/GHSA-q58c-f3v9-6f8q/GHSA-q58c-f3v9-6f8q.json @@ -7,12 +7,8 @@ "CVE-2005-4272" ], "details": "Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q5fc-7mw8-7mpw/GHSA-q5fc-7mw8-7mpw.json b/advisories/unreviewed/2022/05/GHSA-q5fc-7mw8-7mpw/GHSA-q5fc-7mw8-7mpw.json index 3058c89027a..ba2a2e50dee 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5fc-7mw8-7mpw/GHSA-q5fc-7mw8-7mpw.json +++ b/advisories/unreviewed/2022/05/GHSA-q5fc-7mw8-7mpw/GHSA-q5fc-7mw8-7mpw.json @@ -7,12 +7,8 @@ "CVE-2005-4140" ], "details": "SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter, as used by the user field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q64v-qf3j-577f/GHSA-q64v-qf3j-577f.json b/advisories/unreviewed/2022/05/GHSA-q64v-qf3j-577f/GHSA-q64v-qf3j-577f.json index 0588b9a7b75..7932a33a794 100644 --- a/advisories/unreviewed/2022/05/GHSA-q64v-qf3j-577f/GHSA-q64v-qf3j-577f.json +++ b/advisories/unreviewed/2022/05/GHSA-q64v-qf3j-577f/GHSA-q64v-qf3j-577f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q695-424c-rgvg/GHSA-q695-424c-rgvg.json b/advisories/unreviewed/2022/05/GHSA-q695-424c-rgvg/GHSA-q695-424c-rgvg.json index cb8e08ef40a..cfa87c9b779 100644 --- a/advisories/unreviewed/2022/05/GHSA-q695-424c-rgvg/GHSA-q695-424c-rgvg.json +++ b/advisories/unreviewed/2022/05/GHSA-q695-424c-rgvg/GHSA-q695-424c-rgvg.json @@ -7,12 +7,8 @@ "CVE-2021-3055" ], "details": "An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that causes the service to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.10; PAN-OS 10.0 versions earlier than PAN-OS 10.0.6. This issue does not affect Prisma Access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q748-4qm8-j85g/GHSA-q748-4qm8-j85g.json b/advisories/unreviewed/2022/05/GHSA-q748-4qm8-j85g/GHSA-q748-4qm8-j85g.json index 4a7ba4af35f..04e05e28f2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q748-4qm8-j85g/GHSA-q748-4qm8-j85g.json +++ b/advisories/unreviewed/2022/05/GHSA-q748-4qm8-j85g/GHSA-q748-4qm8-j85g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q74g-chvp-h29w/GHSA-q74g-chvp-h29w.json b/advisories/unreviewed/2022/05/GHSA-q74g-chvp-h29w/GHSA-q74g-chvp-h29w.json index e14843def8c..6809428bd38 100644 --- a/advisories/unreviewed/2022/05/GHSA-q74g-chvp-h29w/GHSA-q74g-chvp-h29w.json +++ b/advisories/unreviewed/2022/05/GHSA-q74g-chvp-h29w/GHSA-q74g-chvp-h29w.json @@ -7,12 +7,8 @@ "CVE-2005-4133" ], "details": "Sun Update Connection in Sun Solaris 10, when configured to use a web proxy, allows local users to obtain the proxy authentication password via (1) an unspecified vector and (2) proxy log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q7ff-8r5v-7hm4/GHSA-q7ff-8r5v-7hm4.json b/advisories/unreviewed/2022/05/GHSA-q7ff-8r5v-7hm4/GHSA-q7ff-8r5v-7hm4.json index e5175d1c0fc..a68c2809e21 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7ff-8r5v-7hm4/GHSA-q7ff-8r5v-7hm4.json +++ b/advisories/unreviewed/2022/05/GHSA-q7ff-8r5v-7hm4/GHSA-q7ff-8r5v-7hm4.json @@ -7,12 +7,8 @@ "CVE-2005-3927" ], "details": "Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q7wg-jhfm-jvvq/GHSA-q7wg-jhfm-jvvq.json b/advisories/unreviewed/2022/05/GHSA-q7wg-jhfm-jvvq/GHSA-q7wg-jhfm-jvvq.json index 986b637df09..7faf63a9c65 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7wg-jhfm-jvvq/GHSA-q7wg-jhfm-jvvq.json +++ b/advisories/unreviewed/2022/05/GHSA-q7wg-jhfm-jvvq/GHSA-q7wg-jhfm-jvvq.json @@ -7,12 +7,8 @@ "CVE-2005-4194" ], "details": "Buffer overflow in MediaServerList.exe in Sights 'n Sounds Streaming Media Server 2.0.3.a allows remote attackers to cause a denial of service (application crash) via a long query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q862-fq6m-jgm3/GHSA-q862-fq6m-jgm3.json b/advisories/unreviewed/2022/05/GHSA-q862-fq6m-jgm3/GHSA-q862-fq6m-jgm3.json index fa6613cee4f..5eabaef08b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q862-fq6m-jgm3/GHSA-q862-fq6m-jgm3.json +++ b/advisories/unreviewed/2022/05/GHSA-q862-fq6m-jgm3/GHSA-q862-fq6m-jgm3.json @@ -7,12 +7,8 @@ "CVE-2021-30659" ], "details": "A validation issue was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. A malicious application may be able to leak sensitive user information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q8fm-frxv-x679/GHSA-q8fm-frxv-x679.json b/advisories/unreviewed/2022/05/GHSA-q8fm-frxv-x679/GHSA-q8fm-frxv-x679.json index 70faa071e81..98ec5f40402 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8fm-frxv-x679/GHSA-q8fm-frxv-x679.json +++ b/advisories/unreviewed/2022/05/GHSA-q8fm-frxv-x679/GHSA-q8fm-frxv-x679.json @@ -7,12 +7,8 @@ "CVE-2020-20343" ], "details": "WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8g3-jg66-m2gf/GHSA-q8g3-jg66-m2gf.json b/advisories/unreviewed/2022/05/GHSA-q8g3-jg66-m2gf/GHSA-q8g3-jg66-m2gf.json index 51522cd3a7f..aab5093f9ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8g3-jg66-m2gf/GHSA-q8g3-jg66-m2gf.json +++ b/advisories/unreviewed/2022/05/GHSA-q8g3-jg66-m2gf/GHSA-q8g3-jg66-m2gf.json @@ -7,12 +7,8 @@ "CVE-2021-30617" ], "details": "Policy bypass in Blink in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to bypass site isolation via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q9qw-rwr9-q48r/GHSA-q9qw-rwr9-q48r.json b/advisories/unreviewed/2022/05/GHSA-q9qw-rwr9-q48r/GHSA-q9qw-rwr9-q48r.json index 36240e21b1a..2c04d955f67 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9qw-rwr9-q48r/GHSA-q9qw-rwr9-q48r.json +++ b/advisories/unreviewed/2022/05/GHSA-q9qw-rwr9-q48r/GHSA-q9qw-rwr9-q48r.json @@ -7,12 +7,8 @@ "CVE-2021-24391" ], "details": "An editid GET parameter of the Cashtomer WordPress plugin through 1.0.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qc4c-fq5f-8fqw/GHSA-qc4c-fq5f-8fqw.json b/advisories/unreviewed/2022/05/GHSA-qc4c-fq5f-8fqw/GHSA-qc4c-fq5f-8fqw.json index 7e1d6a393fc..410fe6e5c40 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc4c-fq5f-8fqw/GHSA-qc4c-fq5f-8fqw.json +++ b/advisories/unreviewed/2022/05/GHSA-qc4c-fq5f-8fqw/GHSA-qc4c-fq5f-8fqw.json @@ -7,12 +7,8 @@ "CVE-2005-4017" ], "details": "property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcr8-x47x-6hrg/GHSA-qcr8-x47x-6hrg.json b/advisories/unreviewed/2022/05/GHSA-qcr8-x47x-6hrg/GHSA-qcr8-x47x-6hrg.json index ec2d53821f5..ae81be8eb91 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcr8-x47x-6hrg/GHSA-qcr8-x47x-6hrg.json +++ b/advisories/unreviewed/2022/05/GHSA-qcr8-x47x-6hrg/GHSA-qcr8-x47x-6hrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgcr-7985-q5m3/GHSA-qgcr-7985-q5m3.json b/advisories/unreviewed/2022/05/GHSA-qgcr-7985-q5m3/GHSA-qgcr-7985-q5m3.json index ef0edabf3dc..224e0ce0350 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgcr-7985-q5m3/GHSA-qgcr-7985-q5m3.json +++ b/advisories/unreviewed/2022/05/GHSA-qgcr-7985-q5m3/GHSA-qgcr-7985-q5m3.json @@ -7,12 +7,8 @@ "CVE-2005-3908" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgg5-3wjc-vv47/GHSA-qgg5-3wjc-vv47.json b/advisories/unreviewed/2022/05/GHSA-qgg5-3wjc-vv47/GHSA-qgg5-3wjc-vv47.json index 7cddddd5469..ebb59af8dae 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgg5-3wjc-vv47/GHSA-qgg5-3wjc-vv47.json +++ b/advisories/unreviewed/2022/05/GHSA-qgg5-3wjc-vv47/GHSA-qgg5-3wjc-vv47.json @@ -7,12 +7,8 @@ "CVE-2005-3956" ], "details": "Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qgx9-8p23-fhf6/GHSA-qgx9-8p23-fhf6.json b/advisories/unreviewed/2022/05/GHSA-qgx9-8p23-fhf6/GHSA-qgx9-8p23-fhf6.json index 66483dd90de..2c501047cfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgx9-8p23-fhf6/GHSA-qgx9-8p23-fhf6.json +++ b/advisories/unreviewed/2022/05/GHSA-qgx9-8p23-fhf6/GHSA-qgx9-8p23-fhf6.json @@ -7,12 +7,8 @@ "CVE-2021-39496" ], "details": "Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgxw-h3gp-6wg8/GHSA-qgxw-h3gp-6wg8.json b/advisories/unreviewed/2022/05/GHSA-qgxw-h3gp-6wg8/GHSA-qgxw-h3gp-6wg8.json index aebfedd7ceb..d0e602821ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgxw-h3gp-6wg8/GHSA-qgxw-h3gp-6wg8.json +++ b/advisories/unreviewed/2022/05/GHSA-qgxw-h3gp-6wg8/GHSA-qgxw-h3gp-6wg8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh8c-7g9x-xwm7/GHSA-qh8c-7g9x-xwm7.json b/advisories/unreviewed/2022/05/GHSA-qh8c-7g9x-xwm7/GHSA-qh8c-7g9x-xwm7.json index f6572c778ab..c753c35f729 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh8c-7g9x-xwm7/GHSA-qh8c-7g9x-xwm7.json +++ b/advisories/unreviewed/2022/05/GHSA-qh8c-7g9x-xwm7/GHSA-qh8c-7g9x-xwm7.json @@ -7,12 +7,8 @@ "CVE-2005-3996" ], "details": "SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhj7-w4rj-f7f3/GHSA-qhj7-w4rj-f7f3.json b/advisories/unreviewed/2022/05/GHSA-qhj7-w4rj-f7f3/GHSA-qhj7-w4rj-f7f3.json index 0975e600747..90c490de7cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhj7-w4rj-f7f3/GHSA-qhj7-w4rj-f7f3.json +++ b/advisories/unreviewed/2022/05/GHSA-qhj7-w4rj-f7f3/GHSA-qhj7-w4rj-f7f3.json @@ -7,12 +7,8 @@ "CVE-2005-4306" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pg, (2) tid, (3) cid, and (4) fid parameters to netboardr.cgi, or (5) cid parameter to search.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qjgm-rr3x-5q3q/GHSA-qjgm-rr3x-5q3q.json b/advisories/unreviewed/2022/05/GHSA-qjgm-rr3x-5q3q/GHSA-qjgm-rr3x-5q3q.json index c442ea337e3..de36e2b0b46 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjgm-rr3x-5q3q/GHSA-qjgm-rr3x-5q3q.json +++ b/advisories/unreviewed/2022/05/GHSA-qjgm-rr3x-5q3q/GHSA-qjgm-rr3x-5q3q.json @@ -7,12 +7,8 @@ "CVE-2021-30728" ], "details": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A malicious application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjh7-2cqf-c2cr/GHSA-qjh7-2cqf-c2cr.json b/advisories/unreviewed/2022/05/GHSA-qjh7-2cqf-c2cr/GHSA-qjh7-2cqf-c2cr.json index 6b8e0e73ee7..b8592746f14 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjh7-2cqf-c2cr/GHSA-qjh7-2cqf-c2cr.json +++ b/advisories/unreviewed/2022/05/GHSA-qjh7-2cqf-c2cr/GHSA-qjh7-2cqf-c2cr.json @@ -7,12 +7,8 @@ "CVE-2021-20569" ], "details": "IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. IBM X-Force ID: 199243.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qm3w-g4qw-7r33/GHSA-qm3w-g4qw-7r33.json b/advisories/unreviewed/2022/05/GHSA-qm3w-g4qw-7r33/GHSA-qm3w-g4qw-7r33.json index 8e4fdc987f6..862e2d582ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm3w-g4qw-7r33/GHSA-qm3w-g4qw-7r33.json +++ b/advisories/unreviewed/2022/05/GHSA-qm3w-g4qw-7r33/GHSA-qm3w-g4qw-7r33.json @@ -7,12 +7,8 @@ "CVE-2005-4085" ], "details": "Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.2.3 allows remote attackers to execute arbitrary code via a long Host: header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmjx-9m9f-8g3v/GHSA-qmjx-9m9f-8g3v.json b/advisories/unreviewed/2022/05/GHSA-qmjx-9m9f-8g3v/GHSA-qmjx-9m9f-8g3v.json index da28c5c28d2..00884c21d6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmjx-9m9f-8g3v/GHSA-qmjx-9m9f-8g3v.json +++ b/advisories/unreviewed/2022/05/GHSA-qmjx-9m9f-8g3v/GHSA-qmjx-9m9f-8g3v.json @@ -7,12 +7,8 @@ "CVE-2005-4138" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) Wohnort and (2) Beruf fields in editprofile.php, (3) user parameter array in v_profile.php, and (4) the action parameter in misc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qmxj-6jrf-6cw3/GHSA-qmxj-6jrf-6cw3.json b/advisories/unreviewed/2022/05/GHSA-qmxj-6jrf-6cw3/GHSA-qmxj-6jrf-6cw3.json index 4e70212c4b8..83841003b52 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmxj-6jrf-6cw3/GHSA-qmxj-6jrf-6cw3.json +++ b/advisories/unreviewed/2022/05/GHSA-qmxj-6jrf-6cw3/GHSA-qmxj-6jrf-6cw3.json @@ -7,12 +7,8 @@ "CVE-2005-4162" ], "details": "Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qpx8-2vr9-wqjr/GHSA-qpx8-2vr9-wqjr.json b/advisories/unreviewed/2022/05/GHSA-qpx8-2vr9-wqjr/GHSA-qpx8-2vr9-wqjr.json index 9fe54019775..7c4489f79c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpx8-2vr9-wqjr/GHSA-qpx8-2vr9-wqjr.json +++ b/advisories/unreviewed/2022/05/GHSA-qpx8-2vr9-wqjr/GHSA-qpx8-2vr9-wqjr.json @@ -7,12 +7,8 @@ "CVE-2020-19143" ], "details": "Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the \"TIFFVGetField\" funtion in the component 'libtiff/tif_dir.c'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qq7c-vp73-p9c7/GHSA-qq7c-vp73-p9c7.json b/advisories/unreviewed/2022/05/GHSA-qq7c-vp73-p9c7/GHSA-qq7c-vp73-p9c7.json index 916febe0168..770b430fabe 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq7c-vp73-p9c7/GHSA-qq7c-vp73-p9c7.json +++ b/advisories/unreviewed/2022/05/GHSA-qq7c-vp73-p9c7/GHSA-qq7c-vp73-p9c7.json @@ -7,12 +7,8 @@ "CVE-2021-38727" ], "details": "FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qq7x-7h3g-gmhc/GHSA-qq7x-7h3g-gmhc.json b/advisories/unreviewed/2022/05/GHSA-qq7x-7h3g-gmhc/GHSA-qq7x-7h3g-gmhc.json index 9a362dd99af..7cddcefff76 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq7x-7h3g-gmhc/GHSA-qq7x-7h3g-gmhc.json +++ b/advisories/unreviewed/2022/05/GHSA-qq7x-7h3g-gmhc/GHSA-qq7x-7h3g-gmhc.json @@ -7,12 +7,8 @@ "CVE-2021-30702" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A person with physical access to a Mac may be able to bypass Login Window.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqw5-x59w-fv9f/GHSA-qqw5-x59w-fv9f.json b/advisories/unreviewed/2022/05/GHSA-qqw5-x59w-fv9f/GHSA-qqw5-x59w-fv9f.json index e94a408893e..f6e50414eef 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqw5-x59w-fv9f/GHSA-qqw5-x59w-fv9f.json +++ b/advisories/unreviewed/2022/05/GHSA-qqw5-x59w-fv9f/GHSA-qqw5-x59w-fv9f.json @@ -7,12 +7,8 @@ "CVE-2005-4200" ], "details": "Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0 have unknown impact and attack vectors, a different set of vulnerabilities than those identified by CVE-2005-4199.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrh7-qfjj-49gm/GHSA-qrh7-qfjj-49gm.json b/advisories/unreviewed/2022/05/GHSA-qrh7-qfjj-49gm/GHSA-qrh7-qfjj-49gm.json index 6338e0c7420..1132c946a26 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrh7-qfjj-49gm/GHSA-qrh7-qfjj-49gm.json +++ b/advisories/unreviewed/2022/05/GHSA-qrh7-qfjj-49gm/GHSA-qrh7-qfjj-49gm.json @@ -7,12 +7,8 @@ "CVE-2021-37733" ], "details": "A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.11, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrqq-2r8j-xm27/GHSA-qrqq-2r8j-xm27.json b/advisories/unreviewed/2022/05/GHSA-qrqq-2r8j-xm27/GHSA-qrqq-2r8j-xm27.json index 1284bcaa011..c4e61955476 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrqq-2r8j-xm27/GHSA-qrqq-2r8j-xm27.json +++ b/advisories/unreviewed/2022/05/GHSA-qrqq-2r8j-xm27/GHSA-qrqq-2r8j-xm27.json @@ -7,12 +7,8 @@ "CVE-2020-19291" ], "details": "A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted Weibo.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrv8-99h7-2c7v/GHSA-qrv8-99h7-2c7v.json b/advisories/unreviewed/2022/05/GHSA-qrv8-99h7-2c7v/GHSA-qrv8-99h7-2c7v.json index 0f38109c904..10a39d11153 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrv8-99h7-2c7v/GHSA-qrv8-99h7-2c7v.json +++ b/advisories/unreviewed/2022/05/GHSA-qrv8-99h7-2c7v/GHSA-qrv8-99h7-2c7v.json @@ -7,12 +7,8 @@ "CVE-2021-33982" ], "details": "An insufficient session expiration vulnerability exists in the \"Fish | Hunt FL\" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv48-9r5g-g6qj/GHSA-qv48-9r5g-g6qj.json b/advisories/unreviewed/2022/05/GHSA-qv48-9r5g-g6qj/GHSA-qv48-9r5g-g6qj.json index 8a7aea06d98..f541ab8c3a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv48-9r5g-g6qj/GHSA-qv48-9r5g-g6qj.json +++ b/advisories/unreviewed/2022/05/GHSA-qv48-9r5g-g6qj/GHSA-qv48-9r5g-g6qj.json @@ -7,12 +7,8 @@ "CVE-2021-1948" ], "details": "Possible out of bound read due to lack of length check of data while parsing the beacon or probe response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvxf-v2fx-5hqx/GHSA-qvxf-v2fx-5hqx.json b/advisories/unreviewed/2022/05/GHSA-qvxf-v2fx-5hqx/GHSA-qvxf-v2fx-5hqx.json index 1907c750bfa..d0027d58f8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvxf-v2fx-5hqx/GHSA-qvxf-v2fx-5hqx.json +++ b/advisories/unreviewed/2022/05/GHSA-qvxf-v2fx-5hqx/GHSA-qvxf-v2fx-5hqx.json @@ -7,12 +7,8 @@ "CVE-2005-3916" ], "details": "SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw3m-7664-26j4/GHSA-qw3m-7664-26j4.json b/advisories/unreviewed/2022/05/GHSA-qw3m-7664-26j4/GHSA-qw3m-7664-26j4.json index 5e3f0973469..0e6dec003fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw3m-7664-26j4/GHSA-qw3m-7664-26j4.json +++ b/advisories/unreviewed/2022/05/GHSA-qw3m-7664-26j4/GHSA-qw3m-7664-26j4.json @@ -7,12 +7,8 @@ "CVE-2021-30770" ], "details": "A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw4x-8mrr-5fm7/GHSA-qw4x-8mrr-5fm7.json b/advisories/unreviewed/2022/05/GHSA-qw4x-8mrr-5fm7/GHSA-qw4x-8mrr-5fm7.json index 26b8902f385..15560db87a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw4x-8mrr-5fm7/GHSA-qw4x-8mrr-5fm7.json +++ b/advisories/unreviewed/2022/05/GHSA-qw4x-8mrr-5fm7/GHSA-qw4x-8mrr-5fm7.json @@ -7,12 +7,8 @@ "CVE-2005-4192" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in templates/notepads/notepads.inc in Horde Mnemo Note Manager H3 before 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) the notepad's name or (2) description, when creating a new notepad.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw7j-7w7w-cprp/GHSA-qw7j-7w7w-cprp.json b/advisories/unreviewed/2022/05/GHSA-qw7j-7w7w-cprp/GHSA-qw7j-7w7w-cprp.json index 2ed6da8be84..de837de4669 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw7j-7w7w-cprp/GHSA-qw7j-7w7w-cprp.json +++ b/advisories/unreviewed/2022/05/GHSA-qw7j-7w7w-cprp/GHSA-qw7j-7w7w-cprp.json @@ -7,12 +7,8 @@ "CVE-2005-4368" ], "details": "roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwgf-v45r-4m82/GHSA-qwgf-v45r-4m82.json b/advisories/unreviewed/2022/05/GHSA-qwgf-v45r-4m82/GHSA-qwgf-v45r-4m82.json index facdfb119c7..94e9868e3b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwgf-v45r-4m82/GHSA-qwgf-v45r-4m82.json +++ b/advisories/unreviewed/2022/05/GHSA-qwgf-v45r-4m82/GHSA-qwgf-v45r-4m82.json @@ -7,12 +7,8 @@ "CVE-2005-4094" ], "details": "connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to execute arbitrary PHP by using the FileUpload command to upload a file that appears to be an image but contains PHP script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qx5v-53hw-g8w8/GHSA-qx5v-53hw-g8w8.json b/advisories/unreviewed/2022/05/GHSA-qx5v-53hw-g8w8/GHSA-qx5v-53hw-g8w8.json index 3aa74fe26bc..1a0f723e9c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx5v-53hw-g8w8/GHSA-qx5v-53hw-g8w8.json +++ b/advisories/unreviewed/2022/05/GHSA-qx5v-53hw-g8w8/GHSA-qx5v-53hw-g8w8.json @@ -7,12 +7,8 @@ "CVE-2005-3985" ], "details": "The Internet Key Exchange version 1 (IKEv1) implementation in Astaro Security Linux before 6.102 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qx8p-m7p2-h44c/GHSA-qx8p-m7p2-h44c.json b/advisories/unreviewed/2022/05/GHSA-qx8p-m7p2-h44c/GHSA-qx8p-m7p2-h44c.json index 2b5aaca08b5..620b9785314 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx8p-m7p2-h44c/GHSA-qx8p-m7p2-h44c.json +++ b/advisories/unreviewed/2022/05/GHSA-qx8p-m7p2-h44c/GHSA-qx8p-m7p2-h44c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxgj-gjcq-4732/GHSA-qxgj-gjcq-4732.json b/advisories/unreviewed/2022/05/GHSA-qxgj-gjcq-4732/GHSA-qxgj-gjcq-4732.json index 2bdb8add328..a3b78864a16 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxgj-gjcq-4732/GHSA-qxgj-gjcq-4732.json +++ b/advisories/unreviewed/2022/05/GHSA-qxgj-gjcq-4732/GHSA-qxgj-gjcq-4732.json @@ -7,12 +7,8 @@ "CVE-2021-40492" ], "details": "A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxwc-mr69-cfh8/GHSA-qxwc-mr69-cfh8.json b/advisories/unreviewed/2022/05/GHSA-qxwc-mr69-cfh8/GHSA-qxwc-mr69-cfh8.json index ac95de53036..d89639285aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxwc-mr69-cfh8/GHSA-qxwc-mr69-cfh8.json +++ b/advisories/unreviewed/2022/05/GHSA-qxwc-mr69-cfh8/GHSA-qxwc-mr69-cfh8.json @@ -7,12 +7,8 @@ "CVE-2021-32202" ], "details": "In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the \"post description\" filed in the blog post creation page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r24w-f52g-qphg/GHSA-r24w-f52g-qphg.json b/advisories/unreviewed/2022/05/GHSA-r24w-f52g-qphg/GHSA-r24w-f52g-qphg.json index 93d70bc4538..7c297864dde 100644 --- a/advisories/unreviewed/2022/05/GHSA-r24w-f52g-qphg/GHSA-r24w-f52g-qphg.json +++ b/advisories/unreviewed/2022/05/GHSA-r24w-f52g-qphg/GHSA-r24w-f52g-qphg.json @@ -7,12 +7,8 @@ "CVE-2021-30738" ], "details": "A malicious application may be able to overwrite arbitrary files. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Mojave. An issue with path validation logic for hardlinks was addressed with improved path sanitization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r25w-hm87-5pjx/GHSA-r25w-hm87-5pjx.json b/advisories/unreviewed/2022/05/GHSA-r25w-hm87-5pjx/GHSA-r25w-hm87-5pjx.json index 48872fb71d0..15c20f45efb 100644 --- a/advisories/unreviewed/2022/05/GHSA-r25w-hm87-5pjx/GHSA-r25w-hm87-5pjx.json +++ b/advisories/unreviewed/2022/05/GHSA-r25w-hm87-5pjx/GHSA-r25w-hm87-5pjx.json @@ -7,12 +7,8 @@ "CVE-2021-28557" ], "details": "Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to leak sensitive system information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2cc-3v4v-j29x/GHSA-r2cc-3v4v-j29x.json b/advisories/unreviewed/2022/05/GHSA-r2cc-3v4v-j29x/GHSA-r2cc-3v4v-j29x.json index 2592f7ff95e..03080e324d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2cc-3v4v-j29x/GHSA-r2cc-3v4v-j29x.json +++ b/advisories/unreviewed/2022/05/GHSA-r2cc-3v4v-j29x/GHSA-r2cc-3v4v-j29x.json @@ -7,12 +7,8 @@ "CVE-2005-4079" ], "details": "The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import_blacklist variable in grab_globals.php, which can then be used to overwrite other variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r2cg-mcjc-4mp7/GHSA-r2cg-mcjc-4mp7.json b/advisories/unreviewed/2022/05/GHSA-r2cg-mcjc-4mp7/GHSA-r2cg-mcjc-4mp7.json index 2772f967ec7..fc65c4ee5b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2cg-mcjc-4mp7/GHSA-r2cg-mcjc-4mp7.json +++ b/advisories/unreviewed/2022/05/GHSA-r2cg-mcjc-4mp7/GHSA-r2cg-mcjc-4mp7.json @@ -7,12 +7,8 @@ "CVE-2005-3932" ], "details": "SQL injection vulnerability in okiraku.php in O-Kiraku Nikki 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the day_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r32j-hx54-9256/GHSA-r32j-hx54-9256.json b/advisories/unreviewed/2022/05/GHSA-r32j-hx54-9256/GHSA-r32j-hx54-9256.json index f29523fa454..1375fc072fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-r32j-hx54-9256/GHSA-r32j-hx54-9256.json +++ b/advisories/unreviewed/2022/05/GHSA-r32j-hx54-9256/GHSA-r32j-hx54-9256.json @@ -7,12 +7,8 @@ "CVE-2005-3915" ], "details": "The Internet Key Exchange version 1 (IKEv1) implementation in Clavister Client Web allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r34f-76fq-39vg/GHSA-r34f-76fq-39vg.json b/advisories/unreviewed/2022/05/GHSA-r34f-76fq-39vg/GHSA-r34f-76fq-39vg.json index 0b0b41cb8b5..a47908ebeec 100644 --- a/advisories/unreviewed/2022/05/GHSA-r34f-76fq-39vg/GHSA-r34f-76fq-39vg.json +++ b/advisories/unreviewed/2022/05/GHSA-r34f-76fq-39vg/GHSA-r34f-76fq-39vg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r37m-h85m-jrhm/GHSA-r37m-h85m-jrhm.json b/advisories/unreviewed/2022/05/GHSA-r37m-h85m-jrhm/GHSA-r37m-h85m-jrhm.json index a2dd6dd7447..8e75fefc607 100644 --- a/advisories/unreviewed/2022/05/GHSA-r37m-h85m-jrhm/GHSA-r37m-h85m-jrhm.json +++ b/advisories/unreviewed/2022/05/GHSA-r37m-h85m-jrhm/GHSA-r37m-h85m-jrhm.json @@ -7,12 +7,8 @@ "CVE-2005-3986" ], "details": "Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r399-j3c6-85hw/GHSA-r399-j3c6-85hw.json b/advisories/unreviewed/2022/05/GHSA-r399-j3c6-85hw/GHSA-r399-j3c6-85hw.json index 8399ddc8296..58894796953 100644 --- a/advisories/unreviewed/2022/05/GHSA-r399-j3c6-85hw/GHSA-r399-j3c6-85hw.json +++ b/advisories/unreviewed/2022/05/GHSA-r399-j3c6-85hw/GHSA-r399-j3c6-85hw.json @@ -7,12 +7,8 @@ "CVE-2021-1811" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted font may result in the disclosure of process memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r3ch-gwjw-g759/GHSA-r3ch-gwjw-g759.json b/advisories/unreviewed/2022/05/GHSA-r3ch-gwjw-g759/GHSA-r3ch-gwjw-g759.json index 563af0b7184..eb78eee7618 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3ch-gwjw-g759/GHSA-r3ch-gwjw-g759.json +++ b/advisories/unreviewed/2022/05/GHSA-r3ch-gwjw-g759/GHSA-r3ch-gwjw-g759.json @@ -7,12 +7,8 @@ "CVE-2021-38123" ], "details": "Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3fq-9r25-fh69/GHSA-r3fq-9r25-fh69.json b/advisories/unreviewed/2022/05/GHSA-r3fq-9r25-fh69/GHSA-r3fq-9r25-fh69.json index 56ef42d0811..94573f6cac5 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3fq-9r25-fh69/GHSA-r3fq-9r25-fh69.json +++ b/advisories/unreviewed/2022/05/GHSA-r3fq-9r25-fh69/GHSA-r3fq-9r25-fh69.json @@ -7,12 +7,8 @@ "CVE-2021-28910" ], "details": "BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal and external server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3wg-3ggv-hv7p/GHSA-r3wg-3ggv-hv7p.json b/advisories/unreviewed/2022/05/GHSA-r3wg-3ggv-hv7p/GHSA-r3wg-3ggv-hv7p.json index 70f2cad45cb..0d48857c86c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3wg-3ggv-hv7p/GHSA-r3wg-3ggv-hv7p.json +++ b/advisories/unreviewed/2022/05/GHSA-r3wg-3ggv-hv7p/GHSA-r3wg-3ggv-hv7p.json @@ -7,12 +7,8 @@ "CVE-2021-1812" ], "details": "A logic issue was addressed with improved validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A malicious application may be able to execute arbitrary code with system privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r43g-pg3m-c7c5/GHSA-r43g-pg3m-c7c5.json b/advisories/unreviewed/2022/05/GHSA-r43g-pg3m-c7c5/GHSA-r43g-pg3m-c7c5.json index 5e8fa06fede..26e0e3a8507 100644 --- a/advisories/unreviewed/2022/05/GHSA-r43g-pg3m-c7c5/GHSA-r43g-pg3m-c7c5.json +++ b/advisories/unreviewed/2022/05/GHSA-r43g-pg3m-c7c5/GHSA-r43g-pg3m-c7c5.json @@ -7,12 +7,8 @@ "CVE-2021-30624" ], "details": "Use after free in Autofill in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r43v-pq8h-xhmw/GHSA-r43v-pq8h-xhmw.json b/advisories/unreviewed/2022/05/GHSA-r43v-pq8h-xhmw/GHSA-r43v-pq8h-xhmw.json index dc32167bb7f..c95180c803c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r43v-pq8h-xhmw/GHSA-r43v-pq8h-xhmw.json +++ b/advisories/unreviewed/2022/05/GHSA-r43v-pq8h-xhmw/GHSA-r43v-pq8h-xhmw.json @@ -7,12 +7,8 @@ "CVE-2005-4126" ], "details": "** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows attackers to execute arbitrary code. NOTE: the information regarding this issue is extremely vague and does not provide any verifiable information. It has been posted by a reliable reporter with a prerelease disclosure policy. This item has only been assigned a CVE identifier for tracking purposes, and to serve as a concrete example for discussion of the newly emerging UNVERIFIABLE and PRERELEASE content decisions in CVE, which must be discussed by the Editorial Board. Without additional details or independent verification by reliable sources, it is possible that this item might be RECAST or REJECTED.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r556-vcf9-958h/GHSA-r556-vcf9-958h.json b/advisories/unreviewed/2022/05/GHSA-r556-vcf9-958h/GHSA-r556-vcf9-958h.json index 1c7651092c1..d86a7e1b01c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r556-vcf9-958h/GHSA-r556-vcf9-958h.json +++ b/advisories/unreviewed/2022/05/GHSA-r556-vcf9-958h/GHSA-r556-vcf9-958h.json @@ -7,12 +7,8 @@ "CVE-2005-4207" ], "details": "SQL injection vulnerability in BTGrup Admin WebController Script allows remote attackers to execute SQL commands via the (1) Username and (2) Password fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5j4-m35f-mj7g/GHSA-r5j4-m35f-mj7g.json b/advisories/unreviewed/2022/05/GHSA-r5j4-m35f-mj7g/GHSA-r5j4-m35f-mj7g.json index 40c7287cb3a..8161e4b1d39 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5j4-m35f-mj7g/GHSA-r5j4-m35f-mj7g.json +++ b/advisories/unreviewed/2022/05/GHSA-r5j4-m35f-mj7g/GHSA-r5j4-m35f-mj7g.json @@ -7,12 +7,8 @@ "CVE-2020-21082" ], "details": "A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the text fields for Chinese and English names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5mj-p5rf-5r3g/GHSA-r5mj-p5rf-5r3g.json b/advisories/unreviewed/2022/05/GHSA-r5mj-p5rf-5r3g/GHSA-r5mj-p5rf-5r3g.json index 2460d7d58de..4e0380b8e3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5mj-p5rf-5r3g/GHSA-r5mj-p5rf-5r3g.json +++ b/advisories/unreviewed/2022/05/GHSA-r5mj-p5rf-5r3g/GHSA-r5mj-p5rf-5r3g.json @@ -7,12 +7,8 @@ "CVE-2021-31610" ], "details": "The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (either restart or deadlock the device) by flooding a device with LMP_AU_rand data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5xc-hjr7-x3g4/GHSA-r5xc-hjr7-x3g4.json b/advisories/unreviewed/2022/05/GHSA-r5xc-hjr7-x3g4/GHSA-r5xc-hjr7-x3g4.json index 324a372bffa..05ff9e2a312 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5xc-hjr7-x3g4/GHSA-r5xc-hjr7-x3g4.json +++ b/advisories/unreviewed/2022/05/GHSA-r5xc-hjr7-x3g4/GHSA-r5xc-hjr7-x3g4.json @@ -7,12 +7,8 @@ "CVE-2005-4350" ], "details": "Unspecified vulnerability in WBEM Services A.01.x before A.01.05.12 and A.02.x before A.02.00.08 on HP-UX B.11.00 through B.11.23 allows remote attackers to cause an unspecified denial of service via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r7c8-q64w-gv6f/GHSA-r7c8-q64w-gv6f.json b/advisories/unreviewed/2022/05/GHSA-r7c8-q64w-gv6f/GHSA-r7c8-q64w-gv6f.json index 5913f78871f..ee746c2d93e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7c8-q64w-gv6f/GHSA-r7c8-q64w-gv6f.json +++ b/advisories/unreviewed/2022/05/GHSA-r7c8-q64w-gv6f/GHSA-r7c8-q64w-gv6f.json @@ -7,12 +7,8 @@ "CVE-2021-3054" ], "details": "A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11; PAN-OS 10.0 versions earlier than PAN-OS 10.0.7; PAN-OS 10.1 versions earlier than PAN-OS 10.1.2. This issue does not affect Prisma Access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r83c-5fmh-9hmm/GHSA-r83c-5fmh-9hmm.json b/advisories/unreviewed/2022/05/GHSA-r83c-5fmh-9hmm/GHSA-r83c-5fmh-9hmm.json index e0bbb86b51c..8f119700908 100644 --- a/advisories/unreviewed/2022/05/GHSA-r83c-5fmh-9hmm/GHSA-r83c-5fmh-9hmm.json +++ b/advisories/unreviewed/2022/05/GHSA-r83c-5fmh-9hmm/GHSA-r83c-5fmh-9hmm.json @@ -7,12 +7,8 @@ "CVE-2005-3950" ], "details": "nuauth in NuFW 1.0.x before 1.0.16 and 1.1 allows authenticated users to cause a denial of service via malformed packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r83j-cg9q-23f3/GHSA-r83j-cg9q-23f3.json b/advisories/unreviewed/2022/05/GHSA-r83j-cg9q-23f3/GHSA-r83j-cg9q-23f3.json index 70a85a3f0ac..36a9ffc4c0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-r83j-cg9q-23f3/GHSA-r83j-cg9q-23f3.json +++ b/advisories/unreviewed/2022/05/GHSA-r83j-cg9q-23f3/GHSA-r83j-cg9q-23f3.json @@ -7,12 +7,8 @@ "CVE-2021-30609" ], "details": "Use after free in Sign-In in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r843-6qw6-7vvp/GHSA-r843-6qw6-7vvp.json b/advisories/unreviewed/2022/05/GHSA-r843-6qw6-7vvp/GHSA-r843-6qw6-7vvp.json index 2bcd7b3f076..5480dccea4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r843-6qw6-7vvp/GHSA-r843-6qw6-7vvp.json +++ b/advisories/unreviewed/2022/05/GHSA-r843-6qw6-7vvp/GHSA-r843-6qw6-7vvp.json @@ -7,12 +7,8 @@ "CVE-2005-3920" ], "details": "SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r85w-66g6-gv5r/GHSA-r85w-66g6-gv5r.json b/advisories/unreviewed/2022/05/GHSA-r85w-66g6-gv5r/GHSA-r85w-66g6-gv5r.json index e5249c71ac5..87c5f29b645 100644 --- a/advisories/unreviewed/2022/05/GHSA-r85w-66g6-gv5r/GHSA-r85w-66g6-gv5r.json +++ b/advisories/unreviewed/2022/05/GHSA-r85w-66g6-gv5r/GHSA-r85w-66g6-gv5r.json @@ -7,12 +7,8 @@ "CVE-2005-4073" ], "details": "SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitrary SQL commands via the ListID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8q9-j332-6p92/GHSA-r8q9-j332-6p92.json b/advisories/unreviewed/2022/05/GHSA-r8q9-j332-6p92/GHSA-r8q9-j332-6p92.json index ee1b4c72921..66d3e132456 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8q9-j332-6p92/GHSA-r8q9-j332-6p92.json +++ b/advisories/unreviewed/2022/05/GHSA-r8q9-j332-6p92/GHSA-r8q9-j332-6p92.json @@ -7,12 +7,8 @@ "CVE-2021-34722" ], "details": "Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8qg-vjh8-h4m5/GHSA-r8qg-vjh8-h4m5.json b/advisories/unreviewed/2022/05/GHSA-r8qg-vjh8-h4m5/GHSA-r8qg-vjh8-h4m5.json index 8e21414a4f1..c3b363490f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8qg-vjh8-h4m5/GHSA-r8qg-vjh8-h4m5.json +++ b/advisories/unreviewed/2022/05/GHSA-r8qg-vjh8-h4m5/GHSA-r8qg-vjh8-h4m5.json @@ -7,12 +7,8 @@ "CVE-2005-3904" ], "details": "Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1.4.2 and later, 1.3.1 and later allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r8wh-8j3r-h3qr/GHSA-r8wh-8j3r-h3qr.json b/advisories/unreviewed/2022/05/GHSA-r8wh-8j3r-h3qr/GHSA-r8wh-8j3r-h3qr.json index 20cb10b92db..3f27fc27ff5 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8wh-8j3r-h3qr/GHSA-r8wh-8j3r-h3qr.json +++ b/advisories/unreviewed/2022/05/GHSA-r8wh-8j3r-h3qr/GHSA-r8wh-8j3r-h3qr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rc8p-8p78-4qgh/GHSA-rc8p-8p78-4qgh.json b/advisories/unreviewed/2022/05/GHSA-rc8p-8p78-4qgh/GHSA-rc8p-8p78-4qgh.json index 9c487907f41..5cd0b15a03e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc8p-8p78-4qgh/GHSA-rc8p-8p78-4qgh.json +++ b/advisories/unreviewed/2022/05/GHSA-rc8p-8p78-4qgh/GHSA-rc8p-8p78-4qgh.json @@ -7,12 +7,8 @@ "CVE-2005-4261" ], "details": "Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectors, related to \"a possible security flaw caused by a bug in Perl.\" NOTE: unless CP+ includes its own copy of Perl with CVE-2005-3962, this is a different vulnerability than CVE-2005-3962; however, there is insufficient information to be sure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcxf-wcpq-j795/GHSA-rcxf-wcpq-j795.json b/advisories/unreviewed/2022/05/GHSA-rcxf-wcpq-j795/GHSA-rcxf-wcpq-j795.json index 1f076cde8e4..06a8ee98ae9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcxf-wcpq-j795/GHSA-rcxf-wcpq-j795.json +++ b/advisories/unreviewed/2022/05/GHSA-rcxf-wcpq-j795/GHSA-rcxf-wcpq-j795.json @@ -7,12 +7,8 @@ "CVE-2021-23046" ], "details": "On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rf2j-3ww5-qfxx/GHSA-rf2j-3ww5-qfxx.json b/advisories/unreviewed/2022/05/GHSA-rf2j-3ww5-qfxx/GHSA-rf2j-3ww5-qfxx.json index f29bc67c289..73502f8376b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf2j-3ww5-qfxx/GHSA-rf2j-3ww5-qfxx.json +++ b/advisories/unreviewed/2022/05/GHSA-rf2j-3ww5-qfxx/GHSA-rf2j-3ww5-qfxx.json @@ -7,12 +7,8 @@ "CVE-2021-23050" ], "details": "On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3.5.0, when a cross-site request forgery (CSRF)-enabled policy is configured on a virtual server, an undisclosed HTML response may cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rff7-c4hg-7cp9/GHSA-rff7-c4hg-7cp9.json b/advisories/unreviewed/2022/05/GHSA-rff7-c4hg-7cp9/GHSA-rff7-c4hg-7cp9.json index 5a2e57a2c8b..e5ae01796a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rff7-c4hg-7cp9/GHSA-rff7-c4hg-7cp9.json +++ b/advisories/unreviewed/2022/05/GHSA-rff7-c4hg-7cp9/GHSA-rff7-c4hg-7cp9.json @@ -7,12 +7,8 @@ "CVE-2005-4243" ], "details": "Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) popupid parameter in popups.edit.php; (2) so, (3) sb, and (4) nr parameters in customer.tickets.view.php; (5) subrackingid parameter in subscribers.tracking.edit.php; (6) delete parameter in design.php; (7) trackingid parameter in tracking.details.php; and (8) customerid parameter in sales.view.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rfx5-7qrj-6p2g/GHSA-rfx5-7qrj-6p2g.json b/advisories/unreviewed/2022/05/GHSA-rfx5-7qrj-6p2g/GHSA-rfx5-7qrj-6p2g.json index a4806cc9846..b858723dd92 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfx5-7qrj-6p2g/GHSA-rfx5-7qrj-6p2g.json +++ b/advisories/unreviewed/2022/05/GHSA-rfx5-7qrj-6p2g/GHSA-rfx5-7qrj-6p2g.json @@ -7,12 +7,8 @@ "CVE-2021-1839" ], "details": "The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgc7-rwpc-cphv/GHSA-rgc7-rwpc-cphv.json b/advisories/unreviewed/2022/05/GHSA-rgc7-rwpc-cphv/GHSA-rgc7-rwpc-cphv.json index d27ce91d6da..e990c98aa3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgc7-rwpc-cphv/GHSA-rgc7-rwpc-cphv.json +++ b/advisories/unreviewed/2022/05/GHSA-rgc7-rwpc-cphv/GHSA-rgc7-rwpc-cphv.json @@ -7,12 +7,8 @@ "CVE-2005-4353" ], "details": "SQL injection vulnerability in index.php in toendaCMS 0.6.2.1, when configured to use a SQL database, allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rh3c-99q9-27v6/GHSA-rh3c-99q9-27v6.json b/advisories/unreviewed/2022/05/GHSA-rh3c-99q9-27v6/GHSA-rh3c-99q9-27v6.json index 8ddd87fb69e..d1c20b7890e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rh3c-99q9-27v6/GHSA-rh3c-99q9-27v6.json +++ b/advisories/unreviewed/2022/05/GHSA-rh3c-99q9-27v6/GHSA-rh3c-99q9-27v6.json @@ -7,12 +7,8 @@ "CVE-2021-30799" ], "details": "Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing maliciously crafted web content may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjgr-fh4v-v8xv/GHSA-rjgr-fh4v-v8xv.json b/advisories/unreviewed/2022/05/GHSA-rjgr-fh4v-v8xv/GHSA-rjgr-fh4v-v8xv.json index fdf522e7bd7..9e20fff4adb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjgr-fh4v-v8xv/GHSA-rjgr-fh4v-v8xv.json +++ b/advisories/unreviewed/2022/05/GHSA-rjgr-fh4v-v8xv/GHSA-rjgr-fh4v-v8xv.json @@ -7,12 +7,8 @@ "CVE-2005-4394" ], "details": "Cross-site scripting (XSS) vulnerability in EPiX 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search query parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjmh-r9pq-8xrg/GHSA-rjmh-r9pq-8xrg.json b/advisories/unreviewed/2022/05/GHSA-rjmh-r9pq-8xrg/GHSA-rjmh-r9pq-8xrg.json index 301d7ec61d6..023b9b300c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjmh-r9pq-8xrg/GHSA-rjmh-r9pq-8xrg.json +++ b/advisories/unreviewed/2022/05/GHSA-rjmh-r9pq-8xrg/GHSA-rjmh-r9pq-8xrg.json @@ -7,12 +7,8 @@ "CVE-2021-30620" ], "details": "Insufficient policy enforcement in Blink in Google Chrome prior to 93.0.4577.63 allowed a remote attacker to bypass content security policy via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjq7-8vwr-777h/GHSA-rjq7-8vwr-777h.json b/advisories/unreviewed/2022/05/GHSA-rjq7-8vwr-777h/GHSA-rjq7-8vwr-777h.json index bcdf83a9fc9..1b840d53454 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjq7-8vwr-777h/GHSA-rjq7-8vwr-777h.json +++ b/advisories/unreviewed/2022/05/GHSA-rjq7-8vwr-777h/GHSA-rjq7-8vwr-777h.json @@ -7,12 +7,8 @@ "CVE-2005-3954" ], "details": "Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rm98-fj9p-fjh8/GHSA-rm98-fj9p-fjh8.json b/advisories/unreviewed/2022/05/GHSA-rm98-fj9p-fjh8/GHSA-rm98-fj9p-fjh8.json index c63c03d566e..93c87c0ce84 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm98-fj9p-fjh8/GHSA-rm98-fj9p-fjh8.json +++ b/advisories/unreviewed/2022/05/GHSA-rm98-fj9p-fjh8/GHSA-rm98-fj9p-fjh8.json @@ -7,12 +7,8 @@ "CVE-2005-4231" ], "details": "Cross-site scripting (XSS) vulnerability in Link Up Gold 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) link parameter to tell_friend.php, (2) phrase[] parameter to search.php in a search_links_advanced action, and the (3) direction or (4) sort parameter to articles.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rmr6-xh33-9hqc/GHSA-rmr6-xh33-9hqc.json b/advisories/unreviewed/2022/05/GHSA-rmr6-xh33-9hqc/GHSA-rmr6-xh33-9hqc.json index 8e4cd2a12dc..a2da3563739 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmr6-xh33-9hqc/GHSA-rmr6-xh33-9hqc.json +++ b/advisories/unreviewed/2022/05/GHSA-rmr6-xh33-9hqc/GHSA-rmr6-xh33-9hqc.json @@ -7,12 +7,8 @@ "CVE-2021-30695" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rq6v-h9fq-jw26/GHSA-rq6v-h9fq-jw26.json b/advisories/unreviewed/2022/05/GHSA-rq6v-h9fq-jw26/GHSA-rq6v-h9fq-jw26.json index 48555960ebb..7fe83e957c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq6v-h9fq-jw26/GHSA-rq6v-h9fq-jw26.json +++ b/advisories/unreviewed/2022/05/GHSA-rq6v-h9fq-jw26/GHSA-rq6v-h9fq-jw26.json @@ -7,12 +7,8 @@ "CVE-2005-4007" ], "details": "Multiple unspecified vulnerabilities in SAPID CMS before 1.2.3.03, related to newly registered users and possibly authorization checks, have unknown impact and attack vectors involving (1) mvc/controller/user_request_analysis.inc.php and (2) usr/xml/ddc/authorization.xml.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rqjw-5w3g-3rjv/GHSA-rqjw-5w3g-3rjv.json b/advisories/unreviewed/2022/05/GHSA-rqjw-5w3g-3rjv/GHSA-rqjw-5w3g-3rjv.json index c2810a14a72..2c0ba489cd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqjw-5w3g-3rjv/GHSA-rqjw-5w3g-3rjv.json +++ b/advisories/unreviewed/2022/05/GHSA-rqjw-5w3g-3rjv/GHSA-rqjw-5w3g-3rjv.json @@ -7,12 +7,8 @@ "CVE-2021-1933" ], "details": "UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rqrm-jq4f-7ph5/GHSA-rqrm-jq4f-7ph5.json b/advisories/unreviewed/2022/05/GHSA-rqrm-jq4f-7ph5/GHSA-rqrm-jq4f-7ph5.json index 0e5d6b29e9c..262559a0f49 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqrm-jq4f-7ph5/GHSA-rqrm-jq4f-7ph5.json +++ b/advisories/unreviewed/2022/05/GHSA-rqrm-jq4f-7ph5/GHSA-rqrm-jq4f-7ph5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr7q-672p-8qm6/GHSA-rr7q-672p-8qm6.json b/advisories/unreviewed/2022/05/GHSA-rr7q-672p-8qm6/GHSA-rr7q-672p-8qm6.json index 98b7f1eeb01..8718f8ddc24 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr7q-672p-8qm6/GHSA-rr7q-672p-8qm6.json +++ b/advisories/unreviewed/2022/05/GHSA-rr7q-672p-8qm6/GHSA-rr7q-672p-8qm6.json @@ -7,12 +7,8 @@ "CVE-2005-3921" ], "details": "Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrv7-xh4c-v8jh/GHSA-rrv7-xh4c-v8jh.json b/advisories/unreviewed/2022/05/GHSA-rrv7-xh4c-v8jh/GHSA-rrv7-xh4c-v8jh.json index 91780005353..99a6926dd36 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrv7-xh4c-v8jh/GHSA-rrv7-xh4c-v8jh.json +++ b/advisories/unreviewed/2022/05/GHSA-rrv7-xh4c-v8jh/GHSA-rrv7-xh4c-v8jh.json @@ -7,12 +7,8 @@ "CVE-2005-3941" ], "details": "SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrvv-g9v3-737h/GHSA-rrvv-g9v3-737h.json b/advisories/unreviewed/2022/05/GHSA-rrvv-g9v3-737h/GHSA-rrvv-g9v3-737h.json index 2bfb2764a50..58ef85c74ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrvv-g9v3-737h/GHSA-rrvv-g9v3-737h.json +++ b/advisories/unreviewed/2022/05/GHSA-rrvv-g9v3-737h/GHSA-rrvv-g9v3-737h.json @@ -7,12 +7,8 @@ "CVE-2021-36179" ], "details": "A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands via crafted parameters in CLI command execution", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrxc-fgqr-57wq/GHSA-rrxc-fgqr-57wq.json b/advisories/unreviewed/2022/05/GHSA-rrxc-fgqr-57wq/GHSA-rrxc-fgqr-57wq.json index 6f671a92cb9..e7db273e24b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrxc-fgqr-57wq/GHSA-rrxc-fgqr-57wq.json +++ b/advisories/unreviewed/2022/05/GHSA-rrxc-fgqr-57wq/GHSA-rrxc-fgqr-57wq.json @@ -7,12 +7,8 @@ "CVE-2021-1919" ], "details": "Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rv54-hf76-46cc/GHSA-rv54-hf76-46cc.json b/advisories/unreviewed/2022/05/GHSA-rv54-hf76-46cc/GHSA-rv54-hf76-46cc.json index 1472c9b0291..a4f0f22b1b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv54-hf76-46cc/GHSA-rv54-hf76-46cc.json +++ b/advisories/unreviewed/2022/05/GHSA-rv54-hf76-46cc/GHSA-rv54-hf76-46cc.json @@ -7,12 +7,8 @@ "CVE-2021-30294" ], "details": "Potential null pointer dereference in KGSL GPU auxiliary command due to improper validation of user input in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvh5-44hf-h5w5/GHSA-rvh5-44hf-h5w5.json b/advisories/unreviewed/2022/05/GHSA-rvh5-44hf-h5w5/GHSA-rvh5-44hf-h5w5.json index debc938e744..38e8d8e3b4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvh5-44hf-h5w5/GHSA-rvh5-44hf-h5w5.json +++ b/advisories/unreviewed/2022/05/GHSA-rvh5-44hf-h5w5/GHSA-rvh5-44hf-h5w5.json @@ -7,12 +7,8 @@ "CVE-2005-3938" ], "details": "SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvhg-h22r-mpph/GHSA-rvhg-h22r-mpph.json b/advisories/unreviewed/2022/05/GHSA-rvhg-h22r-mpph/GHSA-rvhg-h22r-mpph.json index 32f3a5eb284..6f21dc73185 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvhg-h22r-mpph/GHSA-rvhg-h22r-mpph.json +++ b/advisories/unreviewed/2022/05/GHSA-rvhg-h22r-mpph/GHSA-rvhg-h22r-mpph.json @@ -7,12 +7,8 @@ "CVE-2005-4271" ], "details": "Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwww-93cx-4h2h/GHSA-rwww-93cx-4h2h.json b/advisories/unreviewed/2022/05/GHSA-rwww-93cx-4h2h/GHSA-rwww-93cx-4h2h.json index 2a62a400674..f7bf4f01a10 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwww-93cx-4h2h/GHSA-rwww-93cx-4h2h.json +++ b/advisories/unreviewed/2022/05/GHSA-rwww-93cx-4h2h/GHSA-rwww-93cx-4h2h.json @@ -7,12 +7,8 @@ "CVE-2021-36717" ], "details": "In order to perform a directory traversal attack, all an attacker needs is a web browser and some knowledge on where to blindly find any default files and directories on the system. on the \"Name\" parameter the attacker can return to the root directory and open the host file. This might give the attacker the ability to view restricted files, which could provide the attacker with more information required to further compromise the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx8x-hjvp-cgx4/GHSA-rx8x-hjvp-cgx4.json b/advisories/unreviewed/2022/05/GHSA-rx8x-hjvp-cgx4/GHSA-rx8x-hjvp-cgx4.json index 8e9dcb24d7c..715ee52a6fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx8x-hjvp-cgx4/GHSA-rx8x-hjvp-cgx4.json +++ b/advisories/unreviewed/2022/05/GHSA-rx8x-hjvp-cgx4/GHSA-rx8x-hjvp-cgx4.json @@ -7,12 +7,8 @@ "CVE-2005-3988" ], "details": "SQL injection vulnerability in article.php in Pineapple Technologies Lore 1.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2cx-5pw8-pvw6/GHSA-v2cx-5pw8-pvw6.json b/advisories/unreviewed/2022/05/GHSA-v2cx-5pw8-pvw6/GHSA-v2cx-5pw8-pvw6.json index 419f140a2d0..7a6b3b950a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2cx-5pw8-pvw6/GHSA-v2cx-5pw8-pvw6.json +++ b/advisories/unreviewed/2022/05/GHSA-v2cx-5pw8-pvw6/GHSA-v2cx-5pw8-pvw6.json @@ -7,12 +7,8 @@ "CVE-2005-4275" ], "details": "Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD), as demonstrated using hping2. NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v33h-cmh6-v795/GHSA-v33h-cmh6-v795.json b/advisories/unreviewed/2022/05/GHSA-v33h-cmh6-v795/GHSA-v33h-cmh6-v795.json index e67537ff185..e6cb0dd3d4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v33h-cmh6-v795/GHSA-v33h-cmh6-v795.json +++ b/advisories/unreviewed/2022/05/GHSA-v33h-cmh6-v795/GHSA-v33h-cmh6-v795.json @@ -7,12 +7,8 @@ "CVE-2021-30748" ], "details": "A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v3pv-ppv6-v9rf/GHSA-v3pv-ppv6-v9rf.json b/advisories/unreviewed/2022/05/GHSA-v3pv-ppv6-v9rf/GHSA-v3pv-ppv6-v9rf.json index ccae0888b46..6802086270c 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3pv-ppv6-v9rf/GHSA-v3pv-ppv6-v9rf.json +++ b/advisories/unreviewed/2022/05/GHSA-v3pv-ppv6-v9rf/GHSA-v3pv-ppv6-v9rf.json @@ -7,12 +7,8 @@ "CVE-2021-33672" ], "details": "Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets executed in their scope. Due to the usage of ActiveX in the application, the attacker can further execute operating system level commands in the chat recipient's scope. This could lead to a complete compromise of their confidentiality, integrity, and could temporarily impact their availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v437-m49g-58q6/GHSA-v437-m49g-58q6.json b/advisories/unreviewed/2022/05/GHSA-v437-m49g-58q6/GHSA-v437-m49g-58q6.json index 5bc62dec6b1..cbd89899a3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v437-m49g-58q6/GHSA-v437-m49g-58q6.json +++ b/advisories/unreviewed/2022/05/GHSA-v437-m49g-58q6/GHSA-v437-m49g-58q6.json @@ -7,12 +7,8 @@ "CVE-2005-3930" ], "details": "SQL injection vulnerability in index.php in N-13 News 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4v8-c9m3-mrwp/GHSA-v4v8-c9m3-mrwp.json b/advisories/unreviewed/2022/05/GHSA-v4v8-c9m3-mrwp/GHSA-v4v8-c9m3-mrwp.json index 7f63ed23d4a..f75632596bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4v8-c9m3-mrwp/GHSA-v4v8-c9m3-mrwp.json +++ b/advisories/unreviewed/2022/05/GHSA-v4v8-c9m3-mrwp/GHSA-v4v8-c9m3-mrwp.json @@ -7,12 +7,8 @@ "CVE-2005-4387" ], "details": "Cross-site scripting (XSS) vulnerability in home.php in contenite 0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5w8-8m8v-3989/GHSA-v5w8-8m8v-3989.json b/advisories/unreviewed/2022/05/GHSA-v5w8-8m8v-3989/GHSA-v5w8-8m8v-3989.json index 6d5443d0c47..9ca46391538 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5w8-8m8v-3989/GHSA-v5w8-8m8v-3989.json +++ b/advisories/unreviewed/2022/05/GHSA-v5w8-8m8v-3989/GHSA-v5w8-8m8v-3989.json @@ -7,12 +7,8 @@ "CVE-2005-4252" ], "details": "Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v675-xwpf-pp6q/GHSA-v675-xwpf-pp6q.json b/advisories/unreviewed/2022/05/GHSA-v675-xwpf-pp6q/GHSA-v675-xwpf-pp6q.json index 1433a62de84..541fd3bff6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v675-xwpf-pp6q/GHSA-v675-xwpf-pp6q.json +++ b/advisories/unreviewed/2022/05/GHSA-v675-xwpf-pp6q/GHSA-v675-xwpf-pp6q.json @@ -7,12 +7,8 @@ "CVE-2021-38723" ], "details": "FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6g9-4phq-cqx8/GHSA-v6g9-4phq-cqx8.json b/advisories/unreviewed/2022/05/GHSA-v6g9-4phq-cqx8/GHSA-v6g9-4phq-cqx8.json index f58e82ba631..317fb15cb78 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6g9-4phq-cqx8/GHSA-v6g9-4phq-cqx8.json +++ b/advisories/unreviewed/2022/05/GHSA-v6g9-4phq-cqx8/GHSA-v6g9-4phq-cqx8.json @@ -7,12 +7,8 @@ "CVE-2005-3902" ], "details": "Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6gq-6h27-8r9r/GHSA-v6gq-6h27-8r9r.json b/advisories/unreviewed/2022/05/GHSA-v6gq-6h27-8r9r/GHSA-v6gq-6h27-8r9r.json index 0b0cf099932..c882544dcd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6gq-6h27-8r9r/GHSA-v6gq-6h27-8r9r.json +++ b/advisories/unreviewed/2022/05/GHSA-v6gq-6h27-8r9r/GHSA-v6gq-6h27-8r9r.json @@ -7,12 +7,8 @@ "CVE-2020-21049" ], "details": "An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v73m-wrc8-8gw3/GHSA-v73m-wrc8-8gw3.json b/advisories/unreviewed/2022/05/GHSA-v73m-wrc8-8gw3/GHSA-v73m-wrc8-8gw3.json index be116c5ac06..876635fe2df 100644 --- a/advisories/unreviewed/2022/05/GHSA-v73m-wrc8-8gw3/GHSA-v73m-wrc8-8gw3.json +++ b/advisories/unreviewed/2022/05/GHSA-v73m-wrc8-8gw3/GHSA-v73m-wrc8-8gw3.json @@ -7,12 +7,8 @@ "CVE-2005-4233" ], "details": "SQL injection vulnerability in advertiser_statistic.php in Ad Manager Pro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ad_number parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v7jg-mp2h-m48g/GHSA-v7jg-mp2h-m48g.json b/advisories/unreviewed/2022/05/GHSA-v7jg-mp2h-m48g/GHSA-v7jg-mp2h-m48g.json index fcf4f9ae0da..f3103188a51 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7jg-mp2h-m48g/GHSA-v7jg-mp2h-m48g.json +++ b/advisories/unreviewed/2022/05/GHSA-v7jg-mp2h-m48g/GHSA-v7jg-mp2h-m48g.json @@ -7,12 +7,8 @@ "CVE-2021-33928" ], "details": "Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7vx-g8wp-cjcv/GHSA-v7vx-g8wp-cjcv.json b/advisories/unreviewed/2022/05/GHSA-v7vx-g8wp-cjcv/GHSA-v7vx-g8wp-cjcv.json index 2c71334d824..f62810ddbcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7vx-g8wp-cjcv/GHSA-v7vx-g8wp-cjcv.json +++ b/advisories/unreviewed/2022/05/GHSA-v7vx-g8wp-cjcv/GHSA-v7vx-g8wp-cjcv.json @@ -7,12 +7,8 @@ "CVE-2021-28497" ], "details": "In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v8qg-q79m-vp4q/GHSA-v8qg-q79m-vp4q.json b/advisories/unreviewed/2022/05/GHSA-v8qg-q79m-vp4q/GHSA-v8qg-q79m-vp4q.json index d269b68622d..56eb776369b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8qg-q79m-vp4q/GHSA-v8qg-q79m-vp4q.json +++ b/advisories/unreviewed/2022/05/GHSA-v8qg-q79m-vp4q/GHSA-v8qg-q79m-vp4q.json @@ -7,12 +7,8 @@ "CVE-2021-1863" ], "details": "An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phone calls to any phone number.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8wj-8g43-8vw2/GHSA-v8wj-8g43-8vw2.json b/advisories/unreviewed/2022/05/GHSA-v8wj-8g43-8vw2/GHSA-v8wj-8g43-8vw2.json index f937579cb3d..50d83d5598b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8wj-8g43-8vw2/GHSA-v8wj-8g43-8vw2.json +++ b/advisories/unreviewed/2022/05/GHSA-v8wj-8g43-8vw2/GHSA-v8wj-8g43-8vw2.json @@ -7,12 +7,8 @@ "CVE-2005-4160" ], "details": "Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via \"../\" sequences in the query string argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9pj-jfcj-qq69/GHSA-v9pj-jfcj-qq69.json b/advisories/unreviewed/2022/05/GHSA-v9pj-jfcj-qq69/GHSA-v9pj-jfcj-qq69.json index a7624c2fe3e..f029d797cfc 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9pj-jfcj-qq69/GHSA-v9pj-jfcj-qq69.json +++ b/advisories/unreviewed/2022/05/GHSA-v9pj-jfcj-qq69/GHSA-v9pj-jfcj-qq69.json @@ -7,12 +7,8 @@ "CVE-2021-1830" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9q6-j8wj-34wm/GHSA-v9q6-j8wj-34wm.json b/advisories/unreviewed/2022/05/GHSA-v9q6-j8wj-34wm/GHSA-v9q6-j8wj-34wm.json index ad21f808eeb..55270cf162d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9q6-j8wj-34wm/GHSA-v9q6-j8wj-34wm.json +++ b/advisories/unreviewed/2022/05/GHSA-v9q6-j8wj-34wm/GHSA-v9q6-j8wj-34wm.json @@ -7,12 +7,8 @@ "CVE-2005-4388" ], "details": "Cross-site scripting (XSS) vulnerability in search.cfm in CONTENS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the near parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9qq-wx6r-3q6x/GHSA-v9qq-wx6r-3q6x.json b/advisories/unreviewed/2022/05/GHSA-v9qq-wx6r-3q6x/GHSA-v9qq-wx6r-3q6x.json index ad02fbcfdc4..44faa6be165 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9qq-wx6r-3q6x/GHSA-v9qq-wx6r-3q6x.json +++ b/advisories/unreviewed/2022/05/GHSA-v9qq-wx6r-3q6x/GHSA-v9qq-wx6r-3q6x.json @@ -7,12 +7,8 @@ "CVE-2005-4027" ], "details": "SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcff-gxvc-qx5x/GHSA-vcff-gxvc-qx5x.json b/advisories/unreviewed/2022/05/GHSA-vcff-gxvc-qx5x/GHSA-vcff-gxvc-qx5x.json index 54cdef8bb2c..a37d15da625 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcff-gxvc-qx5x/GHSA-vcff-gxvc-qx5x.json +++ b/advisories/unreviewed/2022/05/GHSA-vcff-gxvc-qx5x/GHSA-vcff-gxvc-qx5x.json @@ -7,12 +7,8 @@ "CVE-2005-4247" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcfg-5rc5-3vvf/GHSA-vcfg-5rc5-3vvf.json b/advisories/unreviewed/2022/05/GHSA-vcfg-5rc5-3vvf/GHSA-vcfg-5rc5-3vvf.json index 154f0599923..718a72d2d3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcfg-5rc5-3vvf/GHSA-vcfg-5rc5-3vvf.json +++ b/advisories/unreviewed/2022/05/GHSA-vcfg-5rc5-3vvf/GHSA-vcfg-5rc5-3vvf.json @@ -7,12 +7,8 @@ "CVE-2005-3992" ], "details": "Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) PASS command to the FTP server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vcp8-2pmm-wpgv/GHSA-vcp8-2pmm-wpgv.json b/advisories/unreviewed/2022/05/GHSA-vcp8-2pmm-wpgv/GHSA-vcp8-2pmm-wpgv.json index 67e6f9781a7..651abb291b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcp8-2pmm-wpgv/GHSA-vcp8-2pmm-wpgv.json +++ b/advisories/unreviewed/2022/05/GHSA-vcp8-2pmm-wpgv/GHSA-vcp8-2pmm-wpgv.json @@ -7,12 +7,8 @@ "CVE-2005-4310" ], "details": "SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vcvm-p9xp-25xg/GHSA-vcvm-p9xp-25xg.json b/advisories/unreviewed/2022/05/GHSA-vcvm-p9xp-25xg/GHSA-vcvm-p9xp-25xg.json index 020abdeee69..470f400fc84 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcvm-p9xp-25xg/GHSA-vcvm-p9xp-25xg.json +++ b/advisories/unreviewed/2022/05/GHSA-vcvm-p9xp-25xg/GHSA-vcvm-p9xp-25xg.json @@ -7,12 +7,8 @@ "CVE-2020-29012" ], "details": "An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users configured on the device, should the attacker be able to obtain that session ID (via other, hypothetical attacks)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vf2x-qf2w-jf86/GHSA-vf2x-qf2w-jf86.json b/advisories/unreviewed/2022/05/GHSA-vf2x-qf2w-jf86/GHSA-vf2x-qf2w-jf86.json index bcbd1a378ef..8fbec8a15b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf2x-qf2w-jf86/GHSA-vf2x-qf2w-jf86.json +++ b/advisories/unreviewed/2022/05/GHSA-vf2x-qf2w-jf86/GHSA-vf2x-qf2w-jf86.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfw2-75cg-hr92/GHSA-vfw2-75cg-hr92.json b/advisories/unreviewed/2022/05/GHSA-vfw2-75cg-hr92/GHSA-vfw2-75cg-hr92.json index 8622ead1de9..69a43caa4a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfw2-75cg-hr92/GHSA-vfw2-75cg-hr92.json +++ b/advisories/unreviewed/2022/05/GHSA-vfw2-75cg-hr92/GHSA-vfw2-75cg-hr92.json @@ -7,12 +7,8 @@ "CVE-2005-4297" ], "details": "Cross-site scripting (XSS) vulnerability in bbBoard 2.56 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly via the \"keys\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vg73-qc4g-3qvj/GHSA-vg73-qc4g-3qvj.json b/advisories/unreviewed/2022/05/GHSA-vg73-qc4g-3qvj/GHSA-vg73-qc4g-3qvj.json index 2faae643a8d..689faaef438 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg73-qc4g-3qvj/GHSA-vg73-qc4g-3qvj.json +++ b/advisories/unreviewed/2022/05/GHSA-vg73-qc4g-3qvj/GHSA-vg73-qc4g-3qvj.json @@ -7,12 +7,8 @@ "CVE-2021-1835" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to access notes from the lock screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg7v-2g2w-49jx/GHSA-vg7v-2g2w-49jx.json b/advisories/unreviewed/2022/05/GHSA-vg7v-2g2w-49jx/GHSA-vg7v-2g2w-49jx.json index 15ee13397c3..f3d4ac4c68e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg7v-2g2w-49jx/GHSA-vg7v-2g2w-49jx.json +++ b/advisories/unreviewed/2022/05/GHSA-vg7v-2g2w-49jx/GHSA-vg7v-2g2w-49jx.json @@ -7,12 +7,8 @@ "CVE-2005-3928" ], "details": "Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vgh3-xgw7-fjj9/GHSA-vgh3-xgw7-fjj9.json b/advisories/unreviewed/2022/05/GHSA-vgh3-xgw7-fjj9/GHSA-vgh3-xgw7-fjj9.json index 1851aa2f0b8..510d5eba21e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgh3-xgw7-fjj9/GHSA-vgh3-xgw7-fjj9.json +++ b/advisories/unreviewed/2022/05/GHSA-vgh3-xgw7-fjj9/GHSA-vgh3-xgw7-fjj9.json @@ -7,12 +7,8 @@ "CVE-2005-4237" ], "details": "Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vhj3-xqwr-7663/GHSA-vhj3-xqwr-7663.json b/advisories/unreviewed/2022/05/GHSA-vhj3-xqwr-7663/GHSA-vhj3-xqwr-7663.json index 23a69dad0aa..86b46a19f7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhj3-xqwr-7663/GHSA-vhj3-xqwr-7663.json +++ b/advisories/unreviewed/2022/05/GHSA-vhj3-xqwr-7663/GHSA-vhj3-xqwr-7663.json @@ -7,12 +7,8 @@ "CVE-2005-4084" ], "details": "xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vhpw-jc69-hpmx/GHSA-vhpw-jc69-hpmx.json b/advisories/unreviewed/2022/05/GHSA-vhpw-jc69-hpmx/GHSA-vhpw-jc69-hpmx.json index a2e740fd2e6..caed9d1cbf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhpw-jc69-hpmx/GHSA-vhpw-jc69-hpmx.json +++ b/advisories/unreviewed/2022/05/GHSA-vhpw-jc69-hpmx/GHSA-vhpw-jc69-hpmx.json @@ -7,12 +7,8 @@ "CVE-2005-3945" ], "details": "The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vj8g-vgph-c6mr/GHSA-vj8g-vgph-c6mr.json b/advisories/unreviewed/2022/05/GHSA-vj8g-vgph-c6mr/GHSA-vj8g-vgph-c6mr.json index 61fd4f479d0..984ba0e038a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj8g-vgph-c6mr/GHSA-vj8g-vgph-c6mr.json +++ b/advisories/unreviewed/2022/05/GHSA-vj8g-vgph-c6mr/GHSA-vj8g-vgph-c6mr.json @@ -7,12 +7,8 @@ "CVE-2005-4149" ], "details": "Lyris ListManager 8.8 through 8.9b allows remote attackers to obtain sensitive information by causing errors in TML scripts, such as via direct requests, which leaks the installation path, SQL queries, or product code in diagnostic messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm96-6292-3wx4/GHSA-vm96-6292-3wx4.json b/advisories/unreviewed/2022/05/GHSA-vm96-6292-3wx4/GHSA-vm96-6292-3wx4.json index 131bb264947..ee930605e6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm96-6292-3wx4/GHSA-vm96-6292-3wx4.json +++ b/advisories/unreviewed/2022/05/GHSA-vm96-6292-3wx4/GHSA-vm96-6292-3wx4.json @@ -7,12 +7,8 @@ "CVE-2021-1833" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may be able to gain elevated privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmwf-w2vq-x4fr/GHSA-vmwf-w2vq-x4fr.json b/advisories/unreviewed/2022/05/GHSA-vmwf-w2vq-x4fr/GHSA-vmwf-w2vq-x4fr.json index 4b769d16497..4e01c316fdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmwf-w2vq-x4fr/GHSA-vmwf-w2vq-x4fr.json +++ b/advisories/unreviewed/2022/05/GHSA-vmwf-w2vq-x4fr/GHSA-vmwf-w2vq-x4fr.json @@ -7,12 +7,8 @@ "CVE-2005-4008" ], "details": "SQL injection vulnerability in jax_calendar.php in Jax Calendar 1.34 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter, and possibly the (2) Y and (3) m parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq4r-hh2c-c4j9/GHSA-vq4r-hh2c-c4j9.json b/advisories/unreviewed/2022/05/GHSA-vq4r-hh2c-c4j9/GHSA-vq4r-hh2c-c4j9.json index a6e83f12424..06eba94f92e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq4r-hh2c-c4j9/GHSA-vq4r-hh2c-c4j9.json +++ b/advisories/unreviewed/2022/05/GHSA-vq4r-hh2c-c4j9/GHSA-vq4r-hh2c-c4j9.json @@ -7,12 +7,8 @@ "CVE-2021-30764" ], "details": "Processing a maliciously crafted file may lead to arbitrary code execution. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. This issue was addressed with improved checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq99-6922-hw8g/GHSA-vq99-6922-hw8g.json b/advisories/unreviewed/2022/05/GHSA-vq99-6922-hw8g/GHSA-vq99-6922-hw8g.json index bc30a87c2b8..9ff736dee15 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq99-6922-hw8g/GHSA-vq99-6922-hw8g.json +++ b/advisories/unreviewed/2022/05/GHSA-vq99-6922-hw8g/GHSA-vq99-6922-hw8g.json @@ -7,12 +7,8 @@ "CVE-2005-4210" ], "details": "Opera before 8.51, when running on Windows with Input Method Editor (IME) installed, allows remote attackers to cause a denial of service (persistent application crash) by bookmarking a site with a long title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vqrw-6c7v-3ccc/GHSA-vqrw-6c7v-3ccc.json b/advisories/unreviewed/2022/05/GHSA-vqrw-6c7v-3ccc/GHSA-vqrw-6c7v-3ccc.json index d915d0633c6..7f3c1253bb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqrw-6c7v-3ccc/GHSA-vqrw-6c7v-3ccc.json +++ b/advisories/unreviewed/2022/05/GHSA-vqrw-6c7v-3ccc/GHSA-vqrw-6c7v-3ccc.json @@ -7,12 +7,8 @@ "CVE-2005-4325" ], "details": "Multiple unspecified vulnerabilities in Driverse before 0.56b have unknown impact and attack vectors, related to (1) a \"ptrace exploit\" and (2) \"some other potential security problems.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vw4c-q8wp-8vfx/GHSA-vw4c-q8wp-8vfx.json b/advisories/unreviewed/2022/05/GHSA-vw4c-q8wp-8vfx/GHSA-vw4c-q8wp-8vfx.json index 84dae1c419c..dbfc7f0071a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw4c-q8wp-8vfx/GHSA-vw4c-q8wp-8vfx.json +++ b/advisories/unreviewed/2022/05/GHSA-vw4c-q8wp-8vfx/GHSA-vw4c-q8wp-8vfx.json @@ -7,12 +7,8 @@ "CVE-2005-3935" ], "details": "SQL injection vulnerability in SocketKB 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) node and (2) art_id parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vw4j-qcmc-x4wc/GHSA-vw4j-qcmc-x4wc.json b/advisories/unreviewed/2022/05/GHSA-vw4j-qcmc-x4wc/GHSA-vw4j-qcmc-x4wc.json index 5b974e0275f..71cfa3aefc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw4j-qcmc-x4wc/GHSA-vw4j-qcmc-x4wc.json +++ b/advisories/unreviewed/2022/05/GHSA-vw4j-qcmc-x4wc/GHSA-vw4j-qcmc-x4wc.json @@ -7,12 +7,8 @@ "CVE-2005-4331" ], "details": "SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vw6h-px5h-9j7r/GHSA-vw6h-px5h-9j7r.json b/advisories/unreviewed/2022/05/GHSA-vw6h-px5h-9j7r/GHSA-vw6h-px5h-9j7r.json index a434626cbe3..e2a6980a5ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw6h-px5h-9j7r/GHSA-vw6h-px5h-9j7r.json +++ b/advisories/unreviewed/2022/05/GHSA-vw6h-px5h-9j7r/GHSA-vw6h-px5h-9j7r.json @@ -7,12 +7,8 @@ "CVE-2021-39278" ], "details": "Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw74-4mhg-3rhw/GHSA-vw74-4mhg-3rhw.json b/advisories/unreviewed/2022/05/GHSA-vw74-4mhg-3rhw/GHSA-vw74-4mhg-3rhw.json index e5e3a8e962d..f629baaa837 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw74-4mhg-3rhw/GHSA-vw74-4mhg-3rhw.json +++ b/advisories/unreviewed/2022/05/GHSA-vw74-4mhg-3rhw/GHSA-vw74-4mhg-3rhw.json @@ -7,12 +7,8 @@ "CVE-2021-30622" ], "details": "Use after free in WebApp Installs in Google Chrome prior to 93.0.4577.63 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw8w-f3p8-wppg/GHSA-vw8w-f3p8-wppg.json b/advisories/unreviewed/2022/05/GHSA-vw8w-f3p8-wppg/GHSA-vw8w-f3p8-wppg.json index 93fc20436ae..4137999b3f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw8w-f3p8-wppg/GHSA-vw8w-f3p8-wppg.json +++ b/advisories/unreviewed/2022/05/GHSA-vw8w-f3p8-wppg/GHSA-vw8w-f3p8-wppg.json @@ -7,12 +7,8 @@ "CVE-2021-1867" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5, macOS Big Sur 11.3. A malicious application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwj3-mr37-6m94/GHSA-vwj3-mr37-6m94.json b/advisories/unreviewed/2022/05/GHSA-vwj3-mr37-6m94/GHSA-vwj3-mr37-6m94.json index 8abf18413d1..0c058777317 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwj3-mr37-6m94/GHSA-vwj3-mr37-6m94.json +++ b/advisories/unreviewed/2022/05/GHSA-vwj3-mr37-6m94/GHSA-vwj3-mr37-6m94.json @@ -7,12 +7,8 @@ "CVE-2005-4224" ], "details": "Multiple \"potential\" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the email, hideemail, image, realname, signature, timezone, and xupexist parameters in signup.php, (2) the content_comment, content_rating, and content_summary parameters in subcontent.php, (3) the download_category and file_demo in upload.php, and (4) the email, hideemail, user_timezone, and user_xup parameters in usersettings.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vx2r-9h83-x7p6/GHSA-vx2r-9h83-x7p6.json b/advisories/unreviewed/2022/05/GHSA-vx2r-9h83-x7p6/GHSA-vx2r-9h83-x7p6.json index c668273420b..b782a0c3b1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx2r-9h83-x7p6/GHSA-vx2r-9h83-x7p6.json +++ b/advisories/unreviewed/2022/05/GHSA-vx2r-9h83-x7p6/GHSA-vx2r-9h83-x7p6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w2q7-6g2f-4fq6/GHSA-w2q7-6g2f-4fq6.json b/advisories/unreviewed/2022/05/GHSA-w2q7-6g2f-4fq6/GHSA-w2q7-6g2f-4fq6.json index 773440e4a2c..d7beb241a9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2q7-6g2f-4fq6/GHSA-w2q7-6g2f-4fq6.json +++ b/advisories/unreviewed/2022/05/GHSA-w2q7-6g2f-4fq6/GHSA-w2q7-6g2f-4fq6.json @@ -7,12 +7,8 @@ "CVE-2021-25450" ], "details": "Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w32f-37w4-xj86/GHSA-w32f-37w4-xj86.json b/advisories/unreviewed/2022/05/GHSA-w32f-37w4-xj86/GHSA-w32f-37w4-xj86.json index 87cc3abd871..9ee6b7337c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-w32f-37w4-xj86/GHSA-w32f-37w4-xj86.json +++ b/advisories/unreviewed/2022/05/GHSA-w32f-37w4-xj86/GHSA-w32f-37w4-xj86.json @@ -7,12 +7,8 @@ "CVE-2021-1956" ], "details": "Improper handling of ASB-U packet with L2CAP channel ID by slave host can lead to interference with piconet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w3vx-7cpg-r478/GHSA-w3vx-7cpg-r478.json b/advisories/unreviewed/2022/05/GHSA-w3vx-7cpg-r478/GHSA-w3vx-7cpg-r478.json index c48985e0c15..34cd64750bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3vx-7cpg-r478/GHSA-w3vx-7cpg-r478.json +++ b/advisories/unreviewed/2022/05/GHSA-w3vx-7cpg-r478/GHSA-w3vx-7cpg-r478.json @@ -7,12 +7,8 @@ "CVE-2021-38324" ], "details": "The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w488-94f6-hhmr/GHSA-w488-94f6-hhmr.json b/advisories/unreviewed/2022/05/GHSA-w488-94f6-hhmr/GHSA-w488-94f6-hhmr.json index 57fc6304190..ed873b5b786 100644 --- a/advisories/unreviewed/2022/05/GHSA-w488-94f6-hhmr/GHSA-w488-94f6-hhmr.json +++ b/advisories/unreviewed/2022/05/GHSA-w488-94f6-hhmr/GHSA-w488-94f6-hhmr.json @@ -7,12 +7,8 @@ "CVE-2021-28136" ], "details": "The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w647-5772-8rc2/GHSA-w647-5772-8rc2.json b/advisories/unreviewed/2022/05/GHSA-w647-5772-8rc2/GHSA-w647-5772-8rc2.json index 79ae5fe3e63..5ba6fbf9d42 100644 --- a/advisories/unreviewed/2022/05/GHSA-w647-5772-8rc2/GHSA-w647-5772-8rc2.json +++ b/advisories/unreviewed/2022/05/GHSA-w647-5772-8rc2/GHSA-w647-5772-8rc2.json @@ -7,12 +7,8 @@ "CVE-2021-1859" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. Locked Notes content may have been unexpectedly unlocked.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6ff-43j4-cwpw/GHSA-w6ff-43j4-cwpw.json b/advisories/unreviewed/2022/05/GHSA-w6ff-43j4-cwpw/GHSA-w6ff-43j4-cwpw.json index 31f3600c767..2266613946a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6ff-43j4-cwpw/GHSA-w6ff-43j4-cwpw.json +++ b/advisories/unreviewed/2022/05/GHSA-w6ff-43j4-cwpw/GHSA-w6ff-43j4-cwpw.json @@ -7,12 +7,8 @@ "CVE-2005-4351" ], "details": "The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files by mounting another filesystem that masks the immutable files while the system is running.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w749-qfxr-r5v8/GHSA-w749-qfxr-r5v8.json b/advisories/unreviewed/2022/05/GHSA-w749-qfxr-r5v8/GHSA-w749-qfxr-r5v8.json index 45dba369617..36e78fdfb5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w749-qfxr-r5v8/GHSA-w749-qfxr-r5v8.json +++ b/advisories/unreviewed/2022/05/GHSA-w749-qfxr-r5v8/GHSA-w749-qfxr-r5v8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w786-j2g7-7hq5/GHSA-w786-j2g7-7hq5.json b/advisories/unreviewed/2022/05/GHSA-w786-j2g7-7hq5/GHSA-w786-j2g7-7hq5.json index eb0d1b97abb..41683292ac4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w786-j2g7-7hq5/GHSA-w786-j2g7-7hq5.json +++ b/advisories/unreviewed/2022/05/GHSA-w786-j2g7-7hq5/GHSA-w786-j2g7-7hq5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7pp-vj34-5798/GHSA-w7pp-vj34-5798.json b/advisories/unreviewed/2022/05/GHSA-w7pp-vj34-5798/GHSA-w7pp-vj34-5798.json index efc59d9f7ac..c76a1cd34ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7pp-vj34-5798/GHSA-w7pp-vj34-5798.json +++ b/advisories/unreviewed/2022/05/GHSA-w7pp-vj34-5798/GHSA-w7pp-vj34-5798.json @@ -7,12 +7,8 @@ "CVE-2005-4338" ], "details": "announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator privileges by setting the context parameter to \"admin\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8j8-w96c-962r/GHSA-w8j8-w96c-962r.json b/advisories/unreviewed/2022/05/GHSA-w8j8-w96c-962r/GHSA-w8j8-w96c-962r.json index fbbedc2652b..935ec4b170a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8j8-w96c-962r/GHSA-w8j8-w96c-962r.json +++ b/advisories/unreviewed/2022/05/GHSA-w8j8-w96c-962r/GHSA-w8j8-w96c-962r.json @@ -7,12 +7,8 @@ "CVE-2005-4218" ], "details": "SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands via the msg parameter, a different vulnerability than CVE-2005-3585.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8pp-xqh8-jqw5/GHSA-w8pp-xqh8-jqw5.json b/advisories/unreviewed/2022/05/GHSA-w8pp-xqh8-jqw5/GHSA-w8pp-xqh8-jqw5.json index 45090f49f53..2633c46b086 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8pp-xqh8-jqw5/GHSA-w8pp-xqh8-jqw5.json +++ b/advisories/unreviewed/2022/05/GHSA-w8pp-xqh8-jqw5/GHSA-w8pp-xqh8-jqw5.json @@ -7,12 +7,8 @@ "CVE-2021-25465" ], "details": "An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8px-4rp9-9f6w/GHSA-w8px-4rp9-9f6w.json b/advisories/unreviewed/2022/05/GHSA-w8px-4rp9-9f6w/GHSA-w8px-4rp9-9f6w.json index b18a63765b5..23e0793847e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8px-4rp9-9f6w/GHSA-w8px-4rp9-9f6w.json +++ b/advisories/unreviewed/2022/05/GHSA-w8px-4rp9-9f6w/GHSA-w8px-4rp9-9f6w.json @@ -7,12 +7,8 @@ "CVE-2021-35949" ], "details": "The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w8vc-93r8-r74f/GHSA-w8vc-93r8-r74f.json b/advisories/unreviewed/2022/05/GHSA-w8vc-93r8-r74f/GHSA-w8vc-93r8-r74f.json index c4fa82531c1..d84c7167e9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8vc-93r8-r74f/GHSA-w8vc-93r8-r74f.json +++ b/advisories/unreviewed/2022/05/GHSA-w8vc-93r8-r74f/GHSA-w8vc-93r8-r74f.json @@ -7,12 +7,8 @@ "CVE-2005-3933" ], "details": "SQL injection vulnerability in index.php in 88Script's Event Calendar 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w923-q36r-x526/GHSA-w923-q36r-x526.json b/advisories/unreviewed/2022/05/GHSA-w923-q36r-x526/GHSA-w923-q36r-x526.json index 78de4e65e8c..19b1e92503f 100644 --- a/advisories/unreviewed/2022/05/GHSA-w923-q36r-x526/GHSA-w923-q36r-x526.json +++ b/advisories/unreviewed/2022/05/GHSA-w923-q36r-x526/GHSA-w923-q36r-x526.json @@ -7,12 +7,8 @@ "CVE-2005-4395" ], "details": "Cross-site scripting (XSS) vulnerability in FarCry 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the criteria parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w944-h3rr-xq2p/GHSA-w944-h3rr-xq2p.json b/advisories/unreviewed/2022/05/GHSA-w944-h3rr-xq2p/GHSA-w944-h3rr-xq2p.json index 1e6d39d0dcc..a4c320624ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-w944-h3rr-xq2p/GHSA-w944-h3rr-xq2p.json +++ b/advisories/unreviewed/2022/05/GHSA-w944-h3rr-xq2p/GHSA-w944-h3rr-xq2p.json @@ -7,12 +7,8 @@ "CVE-2005-3936" ], "details": "PHP file include vulnerability in SocketKB 1.1.0 and earlier allows remote attackers to include arbitrary local files via the __f parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w98f-cwfv-c3w3/GHSA-w98f-cwfv-c3w3.json b/advisories/unreviewed/2022/05/GHSA-w98f-cwfv-c3w3/GHSA-w98f-cwfv-c3w3.json index 2eb7dabe543..03cbce246e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w98f-cwfv-c3w3/GHSA-w98f-cwfv-c3w3.json +++ b/advisories/unreviewed/2022/05/GHSA-w98f-cwfv-c3w3/GHSA-w98f-cwfv-c3w3.json @@ -7,12 +7,8 @@ "CVE-2021-30784" ], "details": "Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.5. A local attacker may be able to execute code on the Apple T2 Security Chip.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w9rg-rxp3-7v7q/GHSA-w9rg-rxp3-7v7q.json b/advisories/unreviewed/2022/05/GHSA-w9rg-rxp3-7v7q/GHSA-w9rg-rxp3-7v7q.json index 733186bde9b..5b3f66fbf93 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9rg-rxp3-7v7q/GHSA-w9rg-rxp3-7v7q.json +++ b/advisories/unreviewed/2022/05/GHSA-w9rg-rxp3-7v7q/GHSA-w9rg-rxp3-7v7q.json @@ -7,12 +7,8 @@ "CVE-2005-4011" ], "details": "SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wc8m-7c87-vf87/GHSA-wc8m-7c87-vf87.json b/advisories/unreviewed/2022/05/GHSA-wc8m-7c87-vf87/GHSA-wc8m-7c87-vf87.json index 287dd98686e..0a0d4ff6e04 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc8m-7c87-vf87/GHSA-wc8m-7c87-vf87.json +++ b/advisories/unreviewed/2022/05/GHSA-wc8m-7c87-vf87/GHSA-wc8m-7c87-vf87.json @@ -7,12 +7,8 @@ "CVE-2021-30757" ], "details": "This issue was addressed by enabling hardened runtime. This issue is fixed in iMovie 10.2.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wchm-vxgq-6gpw/GHSA-wchm-vxgq-6gpw.json b/advisories/unreviewed/2022/05/GHSA-wchm-vxgq-6gpw/GHSA-wchm-vxgq-6gpw.json index a7006326a60..03883b9720a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wchm-vxgq-6gpw/GHSA-wchm-vxgq-6gpw.json +++ b/advisories/unreviewed/2022/05/GHSA-wchm-vxgq-6gpw/GHSA-wchm-vxgq-6gpw.json @@ -7,12 +7,8 @@ "CVE-2005-3944" ], "details": "SQL injection vulnerability in survey.php in ilyav Survey System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the SURVEY_ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wf3m-v872-644c/GHSA-wf3m-v872-644c.json b/advisories/unreviewed/2022/05/GHSA-wf3m-v872-644c/GHSA-wf3m-v872-644c.json index 30d848fc41f..cb9ff175da4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf3m-v872-644c/GHSA-wf3m-v872-644c.json +++ b/advisories/unreviewed/2022/05/GHSA-wf3m-v872-644c/GHSA-wf3m-v872-644c.json @@ -7,12 +7,8 @@ "CVE-2005-3905" ], "details": "Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors, a different vulnerability than CVE-2005-3906. NOTE: this is associated with the \"first issue\" identified in SUNALERT:102003.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wf4j-m7h5-2p32/GHSA-wf4j-m7h5-2p32.json b/advisories/unreviewed/2022/05/GHSA-wf4j-m7h5-2p32/GHSA-wf4j-m7h5-2p32.json index 62a3f053241..53ca1456c1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf4j-m7h5-2p32/GHSA-wf4j-m7h5-2p32.json +++ b/advisories/unreviewed/2022/05/GHSA-wf4j-m7h5-2p32/GHSA-wf4j-m7h5-2p32.json @@ -7,12 +7,8 @@ "CVE-2005-4029" ], "details": "WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out valid users via brute force methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfq7-wrm9-g8vv/GHSA-wfq7-wrm9-g8vv.json b/advisories/unreviewed/2022/05/GHSA-wfq7-wrm9-g8vv/GHSA-wfq7-wrm9-g8vv.json index b32e884f26b..a203765ef20 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfq7-wrm9-g8vv/GHSA-wfq7-wrm9-g8vv.json +++ b/advisories/unreviewed/2022/05/GHSA-wfq7-wrm9-g8vv/GHSA-wfq7-wrm9-g8vv.json @@ -7,12 +7,8 @@ "CVE-2021-33675" ], "details": "Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability through phishing and to execute arbitrary code on the victim's browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfq8-wvj5-jv7v/GHSA-wfq8-wvj5-jv7v.json b/advisories/unreviewed/2022/05/GHSA-wfq8-wvj5-jv7v/GHSA-wfq8-wvj5-jv7v.json index 47b177629cb..8dbe856a2b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfq8-wvj5-jv7v/GHSA-wfq8-wvj5-jv7v.json +++ b/advisories/unreviewed/2022/05/GHSA-wfq8-wvj5-jv7v/GHSA-wfq8-wvj5-jv7v.json @@ -7,12 +7,8 @@ "CVE-2005-4358" ], "details": "admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfvr-3f3w-jc9w/GHSA-wfvr-3f3w-jc9w.json b/advisories/unreviewed/2022/05/GHSA-wfvr-3f3w-jc9w/GHSA-wfvr-3f3w-jc9w.json index fef07aa8945..922029c99cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfvr-3f3w-jc9w/GHSA-wfvr-3f3w-jc9w.json +++ b/advisories/unreviewed/2022/05/GHSA-wfvr-3f3w-jc9w/GHSA-wfvr-3f3w-jc9w.json @@ -7,12 +7,8 @@ "CVE-2005-4390" ], "details": "SQL injection vulnerability in index.php in ContentServ 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the StoryID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wg5j-8jqj-w57c/GHSA-wg5j-8jqj-w57c.json b/advisories/unreviewed/2022/05/GHSA-wg5j-8jqj-w57c/GHSA-wg5j-8jqj-w57c.json index aac1fb5f216..407177d24b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg5j-8jqj-w57c/GHSA-wg5j-8jqj-w57c.json +++ b/advisories/unreviewed/2022/05/GHSA-wg5j-8jqj-w57c/GHSA-wg5j-8jqj-w57c.json @@ -7,12 +7,8 @@ "CVE-2005-3907" ], "details": "Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors involving untrusted Java applets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wgc2-x6j9-625v/GHSA-wgc2-x6j9-625v.json b/advisories/unreviewed/2022/05/GHSA-wgc2-x6j9-625v/GHSA-wgc2-x6j9-625v.json index 66d6c6e1100..fea1dc3258c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgc2-x6j9-625v/GHSA-wgc2-x6j9-625v.json +++ b/advisories/unreviewed/2022/05/GHSA-wgc2-x6j9-625v/GHSA-wgc2-x6j9-625v.json @@ -7,12 +7,8 @@ "CVE-2021-24392" ], "details": "An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgx4-mfw2-ccw7/GHSA-wgx4-mfw2-ccw7.json b/advisories/unreviewed/2022/05/GHSA-wgx4-mfw2-ccw7/GHSA-wgx4-mfw2-ccw7.json index e6c497edfb5..2c84d78b0ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgx4-mfw2-ccw7/GHSA-wgx4-mfw2-ccw7.json +++ b/advisories/unreviewed/2022/05/GHSA-wgx4-mfw2-ccw7/GHSA-wgx4-mfw2-ccw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh95-745x-qpqc/GHSA-wh95-745x-qpqc.json b/advisories/unreviewed/2022/05/GHSA-wh95-745x-qpqc/GHSA-wh95-745x-qpqc.json index aba28f3aefe..5789d1cf589 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh95-745x-qpqc/GHSA-wh95-745x-qpqc.json +++ b/advisories/unreviewed/2022/05/GHSA-wh95-745x-qpqc/GHSA-wh95-745x-qpqc.json @@ -7,12 +7,8 @@ "CVE-2021-1814" ], "details": "This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.4. Processing a maliciously crafted image may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whch-jrm6-gwgp/GHSA-whch-jrm6-gwgp.json b/advisories/unreviewed/2022/05/GHSA-whch-jrm6-gwgp/GHSA-whch-jrm6-gwgp.json index 295ddf73c2f..f4d7990868b 100644 --- a/advisories/unreviewed/2022/05/GHSA-whch-jrm6-gwgp/GHSA-whch-jrm6-gwgp.json +++ b/advisories/unreviewed/2022/05/GHSA-whch-jrm6-gwgp/GHSA-whch-jrm6-gwgp.json @@ -7,12 +7,8 @@ "CVE-2005-3975" ], "details": "Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Drupal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whh2-g8v3-hpgj/GHSA-whh2-g8v3-hpgj.json b/advisories/unreviewed/2022/05/GHSA-whh2-g8v3-hpgj/GHSA-whh2-g8v3-hpgj.json index 1b5e79b4259..482322bd40c 100644 --- a/advisories/unreviewed/2022/05/GHSA-whh2-g8v3-hpgj/GHSA-whh2-g8v3-hpgj.json +++ b/advisories/unreviewed/2022/05/GHSA-whh2-g8v3-hpgj/GHSA-whh2-g8v3-hpgj.json @@ -7,12 +7,8 @@ "CVE-2005-3897" ], "details": "Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Javascript BODY onload event that calls the window function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whhr-fp2m-r32m/GHSA-whhr-fp2m-r32m.json b/advisories/unreviewed/2022/05/GHSA-whhr-fp2m-r32m/GHSA-whhr-fp2m-r32m.json index 446aa3ed6aa..058f978cf23 100644 --- a/advisories/unreviewed/2022/05/GHSA-whhr-fp2m-r32m/GHSA-whhr-fp2m-r32m.json +++ b/advisories/unreviewed/2022/05/GHSA-whhr-fp2m-r32m/GHSA-whhr-fp2m-r32m.json @@ -7,12 +7,8 @@ "CVE-2005-3949" ], "details": "Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid parameter to admin_handler.php, (3) template parameter to edit_template.php, and (4) multiple parameters to export_handler.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whqr-8g89-8vg2/GHSA-whqr-8g89-8vg2.json b/advisories/unreviewed/2022/05/GHSA-whqr-8g89-8vg2/GHSA-whqr-8g89-8vg2.json index 393f448cf5e..c65f02d201c 100644 --- a/advisories/unreviewed/2022/05/GHSA-whqr-8g89-8vg2/GHSA-whqr-8g89-8vg2.json +++ b/advisories/unreviewed/2022/05/GHSA-whqr-8g89-8vg2/GHSA-whqr-8g89-8vg2.json @@ -7,12 +7,8 @@ "CVE-2005-4199" ], "details": "Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) before 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) month, (2) day, and (3) year parameters in an addevent action in calendar.php; (4) threadmode and (5) showcodebuttons in an options action in usercp.php; (6) list parameter in an editlists action to usercp.php; (7) rating parameter in a rate action in member.php; and (8) rating parameter in either showthread.php or ratethread.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whrv-gm55-4x34/GHSA-whrv-gm55-4x34.json b/advisories/unreviewed/2022/05/GHSA-whrv-gm55-4x34/GHSA-whrv-gm55-4x34.json index ccb548ed0db..700a0bc7b85 100644 --- a/advisories/unreviewed/2022/05/GHSA-whrv-gm55-4x34/GHSA-whrv-gm55-4x34.json +++ b/advisories/unreviewed/2022/05/GHSA-whrv-gm55-4x34/GHSA-whrv-gm55-4x34.json @@ -7,12 +7,8 @@ "CVE-2005-4239" ], "details": "Cross-site scripting (XSS) vulnerability in Search/DisplayResults.php in PHP JackKnife 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via URL-encoded values in the sKeywords parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wjj4-8gg2-x22g/GHSA-wjj4-8gg2-x22g.json b/advisories/unreviewed/2022/05/GHSA-wjj4-8gg2-x22g/GHSA-wjj4-8gg2-x22g.json index 1f9bbeb8d05..7eee9b4d6d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjj4-8gg2-x22g/GHSA-wjj4-8gg2-x22g.json +++ b/advisories/unreviewed/2022/05/GHSA-wjj4-8gg2-x22g/GHSA-wjj4-8gg2-x22g.json @@ -7,12 +7,8 @@ "CVE-2021-1882" ], "details": "A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to gain elevated privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjr5-qv82-83cr/GHSA-wjr5-qv82-83cr.json b/advisories/unreviewed/2022/05/GHSA-wjr5-qv82-83cr/GHSA-wjr5-qv82-83cr.json index ed30578c1dc..87aedb0cdf4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjr5-qv82-83cr/GHSA-wjr5-qv82-83cr.json +++ b/advisories/unreviewed/2022/05/GHSA-wjr5-qv82-83cr/GHSA-wjr5-qv82-83cr.json @@ -7,12 +7,8 @@ "CVE-2021-37531" ], "details": "SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-administrative authenticated attacker to craft a malicious XSL stylesheet file containing a script with OS-level commands, copy it into a location to be accessed by the system and then create a file which will trigger the XSLT engine to execute the script contained within the malicious XSL file. This can result in a full compromise of the confidentiality, integrity, and availability of the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wm6v-hw5v-whjx/GHSA-wm6v-hw5v-whjx.json b/advisories/unreviewed/2022/05/GHSA-wm6v-hw5v-whjx/GHSA-wm6v-hw5v-whjx.json index 6f5e243843c..f1821077cc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm6v-hw5v-whjx/GHSA-wm6v-hw5v-whjx.json +++ b/advisories/unreviewed/2022/05/GHSA-wm6v-hw5v-whjx/GHSA-wm6v-hw5v-whjx.json @@ -7,12 +7,8 @@ "CVE-2005-4300" ], "details": "Format string vulnerability in the lire_pop function in pop.c in libremail 1.1.0 and earlier, with compiled with the debug option, allows remote attackers to execute arbitrary code via a crafted e-mail or POP server response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wm8g-494w-jg7c/GHSA-wm8g-494w-jg7c.json b/advisories/unreviewed/2022/05/GHSA-wm8g-494w-jg7c/GHSA-wm8g-494w-jg7c.json index bc8285f065b..c6e8c56eeb8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm8g-494w-jg7c/GHSA-wm8g-494w-jg7c.json +++ b/advisories/unreviewed/2022/05/GHSA-wm8g-494w-jg7c/GHSA-wm8g-494w-jg7c.json @@ -7,12 +7,8 @@ "CVE-2005-4172" ], "details": "eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wm9j-fw55-hv9g/GHSA-wm9j-fw55-hv9g.json b/advisories/unreviewed/2022/05/GHSA-wm9j-fw55-hv9g/GHSA-wm9j-fw55-hv9g.json index 6808d258e7b..b4c9485e513 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm9j-fw55-hv9g/GHSA-wm9j-fw55-hv9g.json +++ b/advisories/unreviewed/2022/05/GHSA-wm9j-fw55-hv9g/GHSA-wm9j-fw55-hv9g.json @@ -7,12 +7,8 @@ "CVE-2021-1817" ], "details": "A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmr5-5jr5-6x3m/GHSA-wmr5-5jr5-6x3m.json b/advisories/unreviewed/2022/05/GHSA-wmr5-5jr5-6x3m/GHSA-wmr5-5jr5-6x3m.json index 93b76fb1a91..ded079fdb1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmr5-5jr5-6x3m/GHSA-wmr5-5jr5-6x3m.json +++ b/advisories/unreviewed/2022/05/GHSA-wmr5-5jr5-6x3m/GHSA-wmr5-5jr5-6x3m.json @@ -7,12 +7,8 @@ "CVE-2005-4286" ], "details": "Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving \"'smart' values for userid and password,\" probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wr3h-m9xx-fcq4/GHSA-wr3h-m9xx-fcq4.json b/advisories/unreviewed/2022/05/GHSA-wr3h-m9xx-fcq4/GHSA-wr3h-m9xx-fcq4.json index 0f371d4e6e1..43425ff8c47 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr3h-m9xx-fcq4/GHSA-wr3h-m9xx-fcq4.json +++ b/advisories/unreviewed/2022/05/GHSA-wr3h-m9xx-fcq4/GHSA-wr3h-m9xx-fcq4.json @@ -7,12 +7,8 @@ "CVE-2005-4220" ], "details": "Netgear RP114, and possibly other versions and devices, allows remote attackers to cause a denial of service via a SYN flood attack between one system on the internal interface and another on the external interface, which temporarily stops routing between the interfaces, as demonstrated using nmap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr7r-934x-8mmg/GHSA-wr7r-934x-8mmg.json b/advisories/unreviewed/2022/05/GHSA-wr7r-934x-8mmg/GHSA-wr7r-934x-8mmg.json index ffee9302631..5f091c6267b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr7r-934x-8mmg/GHSA-wr7r-934x-8mmg.json +++ b/advisories/unreviewed/2022/05/GHSA-wr7r-934x-8mmg/GHSA-wr7r-934x-8mmg.json @@ -7,12 +7,8 @@ "CVE-2005-4072" ], "details": "Cross-site scripting (XSS) vulnerability in CFMagic Magic Forum Personal 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the Words parameter in search_forums.cfm, as used in the \"Search For:\" field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrg2-vhfj-3vvq/GHSA-wrg2-vhfj-3vvq.json b/advisories/unreviewed/2022/05/GHSA-wrg2-vhfj-3vvq/GHSA-wrg2-vhfj-3vvq.json index dd4c8d81bcd..e342663cfed 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrg2-vhfj-3vvq/GHSA-wrg2-vhfj-3vvq.json +++ b/advisories/unreviewed/2022/05/GHSA-wrg2-vhfj-3vvq/GHSA-wrg2-vhfj-3vvq.json @@ -7,12 +7,8 @@ "CVE-2005-4230" ], "details": "SQL injection vulnerability in poll.php in Link Up Gold 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the number parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrg7-24rr-rgcq/GHSA-wrg7-24rr-rgcq.json b/advisories/unreviewed/2022/05/GHSA-wrg7-24rr-rgcq/GHSA-wrg7-24rr-rgcq.json index 6d57952edb3..7bdf010f98f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrg7-24rr-rgcq/GHSA-wrg7-24rr-rgcq.json +++ b/advisories/unreviewed/2022/05/GHSA-wrg7-24rr-rgcq/GHSA-wrg7-24rr-rgcq.json @@ -7,12 +7,8 @@ "CVE-2021-30669" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A malicious application may bypass Gatekeeper checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrqj-gjcp-v24r/GHSA-wrqj-gjcp-v24r.json b/advisories/unreviewed/2022/05/GHSA-wrqj-gjcp-v24r/GHSA-wrqj-gjcp-v24r.json index 07dea9e1916..1efbf284130 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrqj-gjcp-v24r/GHSA-wrqj-gjcp-v24r.json +++ b/advisories/unreviewed/2022/05/GHSA-wrqj-gjcp-v24r/GHSA-wrqj-gjcp-v24r.json @@ -7,12 +7,8 @@ "CVE-2021-40377" ], "details": "SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ww3h-g64f-837r/GHSA-ww3h-g64f-837r.json b/advisories/unreviewed/2022/05/GHSA-ww3h-g64f-837r/GHSA-ww3h-g64f-837r.json index 56637394c6d..1856c885b9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww3h-g64f-837r/GHSA-ww3h-g64f-837r.json +++ b/advisories/unreviewed/2022/05/GHSA-ww3h-g64f-837r/GHSA-ww3h-g64f-837r.json @@ -7,12 +7,8 @@ "CVE-2021-1849" ], "details": "An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wxh7-2jp7-rww4/GHSA-wxh7-2jp7-rww4.json b/advisories/unreviewed/2022/05/GHSA-wxh7-2jp7-rww4/GHSA-wxh7-2jp7-rww4.json index a3e9dd74575..59f4123a41b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxh7-2jp7-rww4/GHSA-wxh7-2jp7-rww4.json +++ b/advisories/unreviewed/2022/05/GHSA-wxh7-2jp7-rww4/GHSA-wxh7-2jp7-rww4.json @@ -7,12 +7,8 @@ "CVE-2020-7873" ], "details": "Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary file download and execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x2g7-49qc-5qgg/GHSA-x2g7-49qc-5qgg.json b/advisories/unreviewed/2022/05/GHSA-x2g7-49qc-5qgg/GHSA-x2g7-49qc-5qgg.json index 75c815e956a..5c9b661cbf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2g7-49qc-5qgg/GHSA-x2g7-49qc-5qgg.json +++ b/advisories/unreviewed/2022/05/GHSA-x2g7-49qc-5qgg/GHSA-x2g7-49qc-5qgg.json @@ -7,12 +7,8 @@ "CVE-2005-4130" ], "details": "** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows remote attackers to execute arbitrary code. NOTE: it is not known whether this issue should be MERGED with CVE-2005-4126. The information regarding this issue is extremely vague and does not provide any verifiable information. It has been posted by a reliable reporter with a prerelease disclosure policy. This item has only been assigned a CVE identifier for tracking purposes, and to serve as a concrete example for discussion of the newly emerging UNVERIFIABLE and PRERELEASE content decisions in CVE, which must be discussed by the Editorial Board. Without additional details or independent verification by reliable sources, it is possible that this item might be RECAST or REJECTED.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2pr-2f5w-h2hj/GHSA-x2pr-2f5w-h2hj.json b/advisories/unreviewed/2022/05/GHSA-x2pr-2f5w-h2hj/GHSA-x2pr-2f5w-h2hj.json index e7190cf81ba..07587c86a76 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2pr-2f5w-h2hj/GHSA-x2pr-2f5w-h2hj.json +++ b/advisories/unreviewed/2022/05/GHSA-x2pr-2f5w-h2hj/GHSA-x2pr-2f5w-h2hj.json @@ -7,12 +7,8 @@ "CVE-2021-1855" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. A malicious website may be able to force unnecessary network connections to fetch its favicon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x36w-m8p6-4mc4/GHSA-x36w-m8p6-4mc4.json b/advisories/unreviewed/2022/05/GHSA-x36w-m8p6-4mc4/GHSA-x36w-m8p6-4mc4.json index bf7e4a0f68d..c8deef4762e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x36w-m8p6-4mc4/GHSA-x36w-m8p6-4mc4.json +++ b/advisories/unreviewed/2022/05/GHSA-x36w-m8p6-4mc4/GHSA-x36w-m8p6-4mc4.json @@ -7,12 +7,8 @@ "CVE-2021-37184" ], "details": "A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker could change the the password of any user in the system under certain circumstances. With this an attacker could impersonate any valid user on an affected system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x39g-7rq2-35qp/GHSA-x39g-7rq2-35qp.json b/advisories/unreviewed/2022/05/GHSA-x39g-7rq2-35qp/GHSA-x39g-7rq2-35qp.json index 18a1fcdcfbc..fb97f54fb43 100644 --- a/advisories/unreviewed/2022/05/GHSA-x39g-7rq2-35qp/GHSA-x39g-7rq2-35qp.json +++ b/advisories/unreviewed/2022/05/GHSA-x39g-7rq2-35qp/GHSA-x39g-7rq2-35qp.json @@ -7,12 +7,8 @@ "CVE-2021-24568" ], "details": "The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3gg-p3m6-jw8p/GHSA-x3gg-p3m6-jw8p.json b/advisories/unreviewed/2022/05/GHSA-x3gg-p3m6-jw8p/GHSA-x3gg-p3m6-jw8p.json index 249ead2780e..965a9f43c9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3gg-p3m6-jw8p/GHSA-x3gg-p3m6-jw8p.json +++ b/advisories/unreviewed/2022/05/GHSA-x3gg-p3m6-jw8p/GHSA-x3gg-p3m6-jw8p.json @@ -7,12 +7,8 @@ "CVE-2005-4165" ], "details": "Multiple SQL injection vulnerabilities in ASP-DEV ASP Resources Forum allow remote attackers to execute arbitrary SQL commands via the (1) forum_id parameter to forum.asp, (2) unspecified parameters to register.asp, and (3) the \"Search For\" field in search.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3mf-x7jh-9gfw/GHSA-x3mf-x7jh-9gfw.json b/advisories/unreviewed/2022/05/GHSA-x3mf-x7jh-9gfw/GHSA-x3mf-x7jh-9gfw.json index be3bf220c5c..5150c00e645 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3mf-x7jh-9gfw/GHSA-x3mf-x7jh-9gfw.json +++ b/advisories/unreviewed/2022/05/GHSA-x3mf-x7jh-9gfw/GHSA-x3mf-x7jh-9gfw.json @@ -7,12 +7,8 @@ "CVE-2021-31612" ], "details": "The Bluetooth Classic implementation on Zhuhai Jieli AC690X devices does not properly handle the reception of an oversized LMP packet greater than 17 bytes during the LMP auto rate procedure, allowing attackers in radio range to trigger a deadlock via a crafted LMP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3v3-356g-f4j9/GHSA-x3v3-356g-f4j9.json b/advisories/unreviewed/2022/05/GHSA-x3v3-356g-f4j9/GHSA-x3v3-356g-f4j9.json index ff249f168a7..bf6fe764b09 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3v3-356g-f4j9/GHSA-x3v3-356g-f4j9.json +++ b/advisories/unreviewed/2022/05/GHSA-x3v3-356g-f4j9/GHSA-x3v3-356g-f4j9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3vf-fcq8-6cpg/GHSA-x3vf-fcq8-6cpg.json b/advisories/unreviewed/2022/05/GHSA-x3vf-fcq8-6cpg/GHSA-x3vf-fcq8-6cpg.json index 8857084fa10..e485e1894c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3vf-fcq8-6cpg/GHSA-x3vf-fcq8-6cpg.json +++ b/advisories/unreviewed/2022/05/GHSA-x3vf-fcq8-6cpg/GHSA-x3vf-fcq8-6cpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3x6-8r65-7c76/GHSA-x3x6-8r65-7c76.json b/advisories/unreviewed/2022/05/GHSA-x3x6-8r65-7c76/GHSA-x3x6-8r65-7c76.json index b8fcc66c2b8..77a51bf1889 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3x6-8r65-7c76/GHSA-x3x6-8r65-7c76.json +++ b/advisories/unreviewed/2022/05/GHSA-x3x6-8r65-7c76/GHSA-x3x6-8r65-7c76.json @@ -7,12 +7,8 @@ "CVE-2005-4201" ], "details": "Directory traversal vulnerability in My Album Online 1.0 allows remote attackers to access arbitrary files via \".../\" (triple dot) sequences in unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3xc-9hqw-jqwj/GHSA-x3xc-9hqw-jqwj.json b/advisories/unreviewed/2022/05/GHSA-x3xc-9hqw-jqwj/GHSA-x3xc-9hqw-jqwj.json index 20605fcb5b0..f27db7a7ab5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3xc-9hqw-jqwj/GHSA-x3xc-9hqw-jqwj.json +++ b/advisories/unreviewed/2022/05/GHSA-x3xc-9hqw-jqwj/GHSA-x3xc-9hqw-jqwj.json @@ -7,12 +7,8 @@ "CVE-2005-3974" ], "details": "Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the \"access user profiles\" permission.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x4gw-4hvm-h8g4/GHSA-x4gw-4hvm-h8g4.json b/advisories/unreviewed/2022/05/GHSA-x4gw-4hvm-h8g4/GHSA-x4gw-4hvm-h8g4.json index cd08b76606c..7b9b91b0e8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4gw-4hvm-h8g4/GHSA-x4gw-4hvm-h8g4.json +++ b/advisories/unreviewed/2022/05/GHSA-x4gw-4hvm-h8g4/GHSA-x4gw-4hvm-h8g4.json @@ -7,12 +7,8 @@ "CVE-2021-30705" ], "details": "This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted ASTC file may disclose memory contents.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5v2-jx9x-fj53/GHSA-x5v2-jx9x-fj53.json b/advisories/unreviewed/2022/05/GHSA-x5v2-jx9x-fj53/GHSA-x5v2-jx9x-fj53.json index d3ef6cf0eeb..2756283255a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5v2-jx9x-fj53/GHSA-x5v2-jx9x-fj53.json +++ b/advisories/unreviewed/2022/05/GHSA-x5v2-jx9x-fj53/GHSA-x5v2-jx9x-fj53.json @@ -7,12 +7,8 @@ "CVE-2021-28553" ], "details": "Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5xh-7r6j-frrv/GHSA-x5xh-7r6j-frrv.json b/advisories/unreviewed/2022/05/GHSA-x5xh-7r6j-frrv/GHSA-x5xh-7r6j-frrv.json index 96e5796626e..e3dd06ce43f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5xh-7r6j-frrv/GHSA-x5xh-7r6j-frrv.json +++ b/advisories/unreviewed/2022/05/GHSA-x5xh-7r6j-frrv/GHSA-x5xh-7r6j-frrv.json @@ -7,12 +7,8 @@ "CVE-2021-1923" ], "details": "Incorrect pointer argument passed to trusted application TA could result in un-intended memory operations in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x638-5w24-fwx2/GHSA-x638-5w24-fwx2.json b/advisories/unreviewed/2022/05/GHSA-x638-5w24-fwx2/GHSA-x638-5w24-fwx2.json index db1d7ac4f76..c175b9f76c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x638-5w24-fwx2/GHSA-x638-5w24-fwx2.json +++ b/advisories/unreviewed/2022/05/GHSA-x638-5w24-fwx2/GHSA-x638-5w24-fwx2.json @@ -7,12 +7,8 @@ "CVE-2021-23045" ], "details": "On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, 13.1.x before 13.1.4.1, and all versions of 12.1.x, when an SCTP profile with multiple paths is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6h7-qx9x-c9h2/GHSA-x6h7-qx9x-c9h2.json b/advisories/unreviewed/2022/05/GHSA-x6h7-qx9x-c9h2/GHSA-x6h7-qx9x-c9h2.json index 884c1d8ba10..ef64bafabe4 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6h7-qx9x-c9h2/GHSA-x6h7-qx9x-c9h2.json +++ b/advisories/unreviewed/2022/05/GHSA-x6h7-qx9x-c9h2/GHSA-x6h7-qx9x-c9h2.json @@ -7,12 +7,8 @@ "CVE-2005-4156" ], "details": "Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6m9-rgr7-fm6p/GHSA-x6m9-rgr7-fm6p.json b/advisories/unreviewed/2022/05/GHSA-x6m9-rgr7-fm6p/GHSA-x6m9-rgr7-fm6p.json index 262c89e1243..3b156b86211 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6m9-rgr7-fm6p/GHSA-x6m9-rgr7-fm6p.json +++ b/advisories/unreviewed/2022/05/GHSA-x6m9-rgr7-fm6p/GHSA-x6m9-rgr7-fm6p.json @@ -7,12 +7,8 @@ "CVE-2021-34737" ], "details": "A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition. This vulnerability exists because certain DHCPv4 messages are improperly validated when they are processed by an affected device. An attacker could exploit this vulnerability by sending a malformed DHCPv4 message to an affected device. A successful exploit could allow the attacker to cause a NULL pointer dereference, resulting in a crash of the dhcpd process. While the dhcpd process is restarting, which may take up to approximately two minutes, DHCPv4 server services are unavailable on the affected device. This could temporarily prevent network access to clients that join the network during that time period. Note: Only the dhcpd process crashes and eventually restarts automatically. The router does not reload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6rv-m5p4-442f/GHSA-x6rv-m5p4-442f.json b/advisories/unreviewed/2022/05/GHSA-x6rv-m5p4-442f/GHSA-x6rv-m5p4-442f.json index 7edbc84400a..db16e4c22ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6rv-m5p4-442f/GHSA-x6rv-m5p4-442f.json +++ b/advisories/unreviewed/2022/05/GHSA-x6rv-m5p4-442f/GHSA-x6rv-m5p4-442f.json @@ -7,12 +7,8 @@ "CVE-2021-30295" ], "details": "Possible heap overflow due to improper validation of local variable while storing current task information locally in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x7m3-2gwh-f2gf/GHSA-x7m3-2gwh-f2gf.json b/advisories/unreviewed/2022/05/GHSA-x7m3-2gwh-f2gf/GHSA-x7m3-2gwh-f2gf.json index 123b82d9f8c..f6cd214eb7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7m3-2gwh-f2gf/GHSA-x7m3-2gwh-f2gf.json +++ b/advisories/unreviewed/2022/05/GHSA-x7m3-2gwh-f2gf/GHSA-x7m3-2gwh-f2gf.json @@ -7,12 +7,8 @@ "CVE-2005-4303" ], "details": "SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x7r8-25j2-2f3f/GHSA-x7r8-25j2-2f3f.json b/advisories/unreviewed/2022/05/GHSA-x7r8-25j2-2f3f/GHSA-x7r8-25j2-2f3f.json index b4010a2d072..daaa3949bc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7r8-25j2-2f3f/GHSA-x7r8-25j2-2f3f.json +++ b/advisories/unreviewed/2022/05/GHSA-x7r8-25j2-2f3f/GHSA-x7r8-25j2-2f3f.json @@ -7,12 +7,8 @@ "CVE-2005-3971" ], "details": "Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x867-pp5j-mgrh/GHSA-x867-pp5j-mgrh.json b/advisories/unreviewed/2022/05/GHSA-x867-pp5j-mgrh/GHSA-x867-pp5j-mgrh.json index 44419f523f0..baacbf58320 100644 --- a/advisories/unreviewed/2022/05/GHSA-x867-pp5j-mgrh/GHSA-x867-pp5j-mgrh.json +++ b/advisories/unreviewed/2022/05/GHSA-x867-pp5j-mgrh/GHSA-x867-pp5j-mgrh.json @@ -7,12 +7,8 @@ "CVE-2021-30605" ], "details": "Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x943-vqmm-c5qp/GHSA-x943-vqmm-c5qp.json b/advisories/unreviewed/2022/05/GHSA-x943-vqmm-c5qp/GHSA-x943-vqmm-c5qp.json index 5e50283b421..de73e41e1f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x943-vqmm-c5qp/GHSA-x943-vqmm-c5qp.json +++ b/advisories/unreviewed/2022/05/GHSA-x943-vqmm-c5qp/GHSA-x943-vqmm-c5qp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcf9-rf7p-r7f6/GHSA-xcf9-rf7p-r7f6.json b/advisories/unreviewed/2022/05/GHSA-xcf9-rf7p-r7f6/GHSA-xcf9-rf7p-r7f6.json index f1dcb06fb0b..33ee8b22b33 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcf9-rf7p-r7f6/GHSA-xcf9-rf7p-r7f6.json +++ b/advisories/unreviewed/2022/05/GHSA-xcf9-rf7p-r7f6/GHSA-xcf9-rf7p-r7f6.json @@ -7,12 +7,8 @@ "CVE-2021-26603" ], "details": "A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. This vulnerability is due to missing support for string length check.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfgp-cg34-v578/GHSA-xfgp-cg34-v578.json b/advisories/unreviewed/2022/05/GHSA-xfgp-cg34-v578/GHSA-xfgp-cg34-v578.json index 2b1ff6f9b85..38c070312df 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfgp-cg34-v578/GHSA-xfgp-cg34-v578.json +++ b/advisories/unreviewed/2022/05/GHSA-xfgp-cg34-v578/GHSA-xfgp-cg34-v578.json @@ -7,12 +7,8 @@ "CVE-2005-4216" ], "details": "The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (application crash) via a malformed request with a single character to port 1111.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xgg8-892p-f458/GHSA-xgg8-892p-f458.json b/advisories/unreviewed/2022/05/GHSA-xgg8-892p-f458/GHSA-xgg8-892p-f458.json index 768540f22e3..22383e09a3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgg8-892p-f458/GHSA-xgg8-892p-f458.json +++ b/advisories/unreviewed/2022/05/GHSA-xgg8-892p-f458/GHSA-xgg8-892p-f458.json @@ -7,12 +7,8 @@ "CVE-2021-34728" ], "details": "Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhhh-8cg4-rhc7/GHSA-xhhh-8cg4-rhc7.json b/advisories/unreviewed/2022/05/GHSA-xhhh-8cg4-rhc7/GHSA-xhhh-8cg4-rhc7.json index 750feb49a36..10142f22eed 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhhh-8cg4-rhc7/GHSA-xhhh-8cg4-rhc7.json +++ b/advisories/unreviewed/2022/05/GHSA-xhhh-8cg4-rhc7/GHSA-xhhh-8cg4-rhc7.json @@ -7,12 +7,8 @@ "CVE-2021-36581" ], "details": "Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjhc-m7rm-mxvq/GHSA-xjhc-m7rm-mxvq.json b/advisories/unreviewed/2022/05/GHSA-xjhc-m7rm-mxvq/GHSA-xjhc-m7rm-mxvq.json index 2efde85efc1..78ef68380f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjhc-m7rm-mxvq/GHSA-xjhc-m7rm-mxvq.json +++ b/advisories/unreviewed/2022/05/GHSA-xjhc-m7rm-mxvq/GHSA-xjhc-m7rm-mxvq.json @@ -7,12 +7,8 @@ "CVE-2020-7832" ], "details": "A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectItem, DoOpenFile function.(CVE-2020-7832)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmch-wgh7-x2fj/GHSA-xmch-wgh7-x2fj.json b/advisories/unreviewed/2022/05/GHSA-xmch-wgh7-x2fj/GHSA-xmch-wgh7-x2fj.json index 88ed16f79fe..4bcab04777d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmch-wgh7-x2fj/GHSA-xmch-wgh7-x2fj.json +++ b/advisories/unreviewed/2022/05/GHSA-xmch-wgh7-x2fj/GHSA-xmch-wgh7-x2fj.json @@ -7,12 +7,8 @@ "CVE-2021-30697" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A local user may be able to leak sensitive user information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xprc-m22g-qgf9/GHSA-xprc-m22g-qgf9.json b/advisories/unreviewed/2022/05/GHSA-xprc-m22g-qgf9/GHSA-xprc-m22g-qgf9.json index 7b27cbb15bb..1270c8d03a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-xprc-m22g-qgf9/GHSA-xprc-m22g-qgf9.json +++ b/advisories/unreviewed/2022/05/GHSA-xprc-m22g-qgf9/GHSA-xprc-m22g-qgf9.json @@ -7,12 +7,8 @@ "CVE-2005-4337" ], "details": "The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a \"/\" in the encoded_pw parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xqrv-hxv4-28ph/GHSA-xqrv-hxv4-28ph.json b/advisories/unreviewed/2022/05/GHSA-xqrv-hxv4-28ph/GHSA-xqrv-hxv4-28ph.json index 9fbaf1cd10e..8a918bd6752 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqrv-hxv4-28ph/GHSA-xqrv-hxv4-28ph.json +++ b/advisories/unreviewed/2022/05/GHSA-xqrv-hxv4-28ph/GHSA-xqrv-hxv4-28ph.json @@ -7,12 +7,8 @@ "CVE-2005-4087" ], "details": "PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xr29-6gg3-jq8m/GHSA-xr29-6gg3-jq8m.json b/advisories/unreviewed/2022/05/GHSA-xr29-6gg3-jq8m/GHSA-xr29-6gg3-jq8m.json index ec897bc8da3..9b285f40ced 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr29-6gg3-jq8m/GHSA-xr29-6gg3-jq8m.json +++ b/advisories/unreviewed/2022/05/GHSA-xr29-6gg3-jq8m/GHSA-xr29-6gg3-jq8m.json @@ -7,12 +7,8 @@ "CVE-2005-4378" ], "details": "SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xr9m-34vg-p986/GHSA-xr9m-34vg-p986.json b/advisories/unreviewed/2022/05/GHSA-xr9m-34vg-p986/GHSA-xr9m-34vg-p986.json index c8741db678d..c28f005e82e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr9m-34vg-p986/GHSA-xr9m-34vg-p986.json +++ b/advisories/unreviewed/2022/05/GHSA-xr9m-34vg-p986/GHSA-xr9m-34vg-p986.json @@ -7,12 +7,8 @@ "CVE-2005-4151" ], "details": "The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xrfv-jpgw-xhww/GHSA-xrfv-jpgw-xhww.json b/advisories/unreviewed/2022/05/GHSA-xrfv-jpgw-xhww/GHSA-xrfv-jpgw-xhww.json index 3a3957bc67a..e215232cf43 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrfv-jpgw-xhww/GHSA-xrfv-jpgw-xhww.json +++ b/advisories/unreviewed/2022/05/GHSA-xrfv-jpgw-xhww/GHSA-xrfv-jpgw-xhww.json @@ -7,12 +7,8 @@ "CVE-2005-3952" ], "details": "SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters to viewcat.php, or (3) certain search parameters. NOTE: later a disclosure reported the affected version as 1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xrgc-r968-f934/GHSA-xrgc-r968-f934.json b/advisories/unreviewed/2022/05/GHSA-xrgc-r968-f934/GHSA-xrgc-r968-f934.json index ab814cb3114..edd3cd6f48e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrgc-r968-f934/GHSA-xrgc-r968-f934.json +++ b/advisories/unreviewed/2022/05/GHSA-xrgc-r968-f934/GHSA-xrgc-r968-f934.json @@ -7,12 +7,8 @@ "CVE-2005-4288" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xv49-7846-mhm4/GHSA-xv49-7846-mhm4.json b/advisories/unreviewed/2022/05/GHSA-xv49-7846-mhm4/GHSA-xv49-7846-mhm4.json index ba58826bb0d..5222fb36aed 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv49-7846-mhm4/GHSA-xv49-7846-mhm4.json +++ b/advisories/unreviewed/2022/05/GHSA-xv49-7846-mhm4/GHSA-xv49-7846-mhm4.json @@ -7,12 +7,8 @@ "CVE-2021-28569" ], "details": "Adobe Media Encoder version 15.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvpm-v9x9-vg99/GHSA-xvpm-v9x9-vg99.json b/advisories/unreviewed/2022/05/GHSA-xvpm-v9x9-vg99/GHSA-xvpm-v9x9-vg99.json index 07b08492f07..c8b31afbc00 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvpm-v9x9-vg99/GHSA-xvpm-v9x9-vg99.json +++ b/advisories/unreviewed/2022/05/GHSA-xvpm-v9x9-vg99/GHSA-xvpm-v9x9-vg99.json @@ -7,12 +7,8 @@ "CVE-2005-4328" ], "details": "Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw5r-2555-jwfv/GHSA-xw5r-2555-jwfv.json b/advisories/unreviewed/2022/05/GHSA-xw5r-2555-jwfv/GHSA-xw5r-2555-jwfv.json index f29bf8e47c8..c25a67a6d3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw5r-2555-jwfv/GHSA-xw5r-2555-jwfv.json +++ b/advisories/unreviewed/2022/05/GHSA-xw5r-2555-jwfv/GHSA-xw5r-2555-jwfv.json @@ -7,12 +7,8 @@ "CVE-2021-34708" ], "details": "Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwhc-mqxq-rj7w/GHSA-xwhc-mqxq-rj7w.json b/advisories/unreviewed/2022/05/GHSA-xwhc-mqxq-rj7w/GHSA-xwhc-mqxq-rj7w.json index 7e7805ebf76..6bb70024ee7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwhc-mqxq-rj7w/GHSA-xwhc-mqxq-rj7w.json +++ b/advisories/unreviewed/2022/05/GHSA-xwhc-mqxq-rj7w/GHSA-xwhc-mqxq-rj7w.json @@ -7,12 +7,8 @@ "CVE-2021-28913" ], "details": "BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to validate the so called and hard coded unique 'eibPort String' which acts as the root SSH key passphrase. This is usable and part of an attack chain to gain SSH root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwq2-3qq4-3p6h/GHSA-xwq2-3qq4-3p6h.json b/advisories/unreviewed/2022/05/GHSA-xwq2-3qq4-3p6h/GHSA-xwq2-3qq4-3p6h.json index aa2a4cab550..885f112b131 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwq2-3qq4-3p6h/GHSA-xwq2-3qq4-3p6h.json +++ b/advisories/unreviewed/2022/05/GHSA-xwq2-3qq4-3p6h/GHSA-xwq2-3qq4-3p6h.json @@ -7,12 +7,8 @@ "CVE-2005-3922" ], "details": "Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwrf-mmfx-x4vx/GHSA-xwrf-mmfx-x4vx.json b/advisories/unreviewed/2022/05/GHSA-xwrf-mmfx-x4vx/GHSA-xwrf-mmfx-x4vx.json index 42dac4cb024..709c7e90ed7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwrf-mmfx-x4vx/GHSA-xwrf-mmfx-x4vx.json +++ b/advisories/unreviewed/2022/05/GHSA-xwrf-mmfx-x4vx/GHSA-xwrf-mmfx-x4vx.json @@ -7,12 +7,8 @@ "CVE-2021-23051" ], "details": "On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This is due to an incomplete fix for CVE-2020-5862. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xx36-85fv-r3w7/GHSA-xx36-85fv-r3w7.json b/advisories/unreviewed/2022/05/GHSA-xx36-85fv-r3w7/GHSA-xx36-85fv-r3w7.json index 653578ec0e5..cc3f91d5a46 100644 --- a/advisories/unreviewed/2022/05/GHSA-xx36-85fv-r3w7/GHSA-xx36-85fv-r3w7.json +++ b/advisories/unreviewed/2022/05/GHSA-xx36-85fv-r3w7/GHSA-xx36-85fv-r3w7.json @@ -7,12 +7,8 @@ "CVE-2005-4082" ], "details": "The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xx6w-2mwc-44g2/GHSA-xx6w-2mwc-44g2.json b/advisories/unreviewed/2022/05/GHSA-xx6w-2mwc-44g2/GHSA-xx6w-2mwc-44g2.json index ea2602b9ad6..fcbdab1fc86 100644 --- a/advisories/unreviewed/2022/05/GHSA-xx6w-2mwc-44g2/GHSA-xx6w-2mwc-44g2.json +++ b/advisories/unreviewed/2022/05/GHSA-xx6w-2mwc-44g2/GHSA-xx6w-2mwc-44g2.json @@ -7,12 +7,8 @@ "CVE-2021-3052" ], "details": "A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrary actions in the PAN-OS web interface as the targeted authenticated administrator. This issue impacts: PAN-OS 8.1 versions earlier than 8.1.20; PAN-OS 9.0 versions earlier than 9.0.14; PAN-OS 9.1 versions earlier than 9.1.10; PAN-OS 10.0 versions earlier than 10.0.2. This issue does not affect Prisma Access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxcg-h8cr-979m/GHSA-xxcg-h8cr-979m.json b/advisories/unreviewed/2022/05/GHSA-xxcg-h8cr-979m/GHSA-xxcg-h8cr-979m.json index d737ecc1df1..ed9ef48d23c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxcg-h8cr-979m/GHSA-xxcg-h8cr-979m.json +++ b/advisories/unreviewed/2022/05/GHSA-xxcg-h8cr-979m/GHSA-xxcg-h8cr-979m.json @@ -7,12 +7,8 @@ "CVE-2021-37181" ], "details": "A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC Compact V5.0 (All versions < V5.0 QU1), Desigo CC V4.0 (All versions), Desigo CC V4.1 (All versions), Desigo CC V4.2 (All versions), Desigo CC V5.0 (All versions < V5.0 QU1). The application deserialises untrusted data without sufficient validations, that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected by the vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxgp-5c5m-vvhc/GHSA-xxgp-5c5m-vvhc.json b/advisories/unreviewed/2022/05/GHSA-xxgp-5c5m-vvhc/GHSA-xxgp-5c5m-vvhc.json index 1e0483986bc..bb089aee145 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxgp-5c5m-vvhc/GHSA-xxgp-5c5m-vvhc.json +++ b/advisories/unreviewed/2022/05/GHSA-xxgp-5c5m-vvhc/GHSA-xxgp-5c5m-vvhc.json @@ -7,12 +7,8 @@ "CVE-2021-37719" ], "details": "A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-33ff-c2wp-wfmh/GHSA-33ff-c2wp-wfmh.json b/advisories/unreviewed/2023/01/GHSA-33ff-c2wp-wfmh/GHSA-33ff-c2wp-wfmh.json index 07d99a8909f..6ba1c9cbca0 100644 --- a/advisories/unreviewed/2023/01/GHSA-33ff-c2wp-wfmh/GHSA-33ff-c2wp-wfmh.json +++ b/advisories/unreviewed/2023/01/GHSA-33ff-c2wp-wfmh/GHSA-33ff-c2wp-wfmh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-48vq-44vm-p326/GHSA-48vq-44vm-p326.json b/advisories/unreviewed/2023/01/GHSA-48vq-44vm-p326/GHSA-48vq-44vm-p326.json index 4d49f65d869..6e888c9d650 100644 --- a/advisories/unreviewed/2023/01/GHSA-48vq-44vm-p326/GHSA-48vq-44vm-p326.json +++ b/advisories/unreviewed/2023/01/GHSA-48vq-44vm-p326/GHSA-48vq-44vm-p326.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-4998-2mfr-v8x2/GHSA-4998-2mfr-v8x2.json b/advisories/unreviewed/2023/01/GHSA-4998-2mfr-v8x2/GHSA-4998-2mfr-v8x2.json index dde8b5577cd..6a569d3b8d1 100644 --- a/advisories/unreviewed/2023/01/GHSA-4998-2mfr-v8x2/GHSA-4998-2mfr-v8x2.json +++ b/advisories/unreviewed/2023/01/GHSA-4998-2mfr-v8x2/GHSA-4998-2mfr-v8x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-7gf5-5hgq-mfgh/GHSA-7gf5-5hgq-mfgh.json b/advisories/unreviewed/2023/01/GHSA-7gf5-5hgq-mfgh/GHSA-7gf5-5hgq-mfgh.json index c7a4e6110b0..f86b897361d 100644 --- a/advisories/unreviewed/2023/01/GHSA-7gf5-5hgq-mfgh/GHSA-7gf5-5hgq-mfgh.json +++ b/advisories/unreviewed/2023/01/GHSA-7gf5-5hgq-mfgh/GHSA-7gf5-5hgq-mfgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-9pg6-chjx-xpmr/GHSA-9pg6-chjx-xpmr.json b/advisories/unreviewed/2023/01/GHSA-9pg6-chjx-xpmr/GHSA-9pg6-chjx-xpmr.json index 2d797381e7e..a93196f56d6 100644 --- a/advisories/unreviewed/2023/01/GHSA-9pg6-chjx-xpmr/GHSA-9pg6-chjx-xpmr.json +++ b/advisories/unreviewed/2023/01/GHSA-9pg6-chjx-xpmr/GHSA-9pg6-chjx-xpmr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-c4hh-96wh-qcjh/GHSA-c4hh-96wh-qcjh.json b/advisories/unreviewed/2023/01/GHSA-c4hh-96wh-qcjh/GHSA-c4hh-96wh-qcjh.json index 151be751a4d..d6d51f2631a 100644 --- a/advisories/unreviewed/2023/01/GHSA-c4hh-96wh-qcjh/GHSA-c4hh-96wh-qcjh.json +++ b/advisories/unreviewed/2023/01/GHSA-c4hh-96wh-qcjh/GHSA-c4hh-96wh-qcjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-g28r-954m-qc24/GHSA-g28r-954m-qc24.json b/advisories/unreviewed/2023/01/GHSA-g28r-954m-qc24/GHSA-g28r-954m-qc24.json index 2e4fb6cd47e..4fc946ff449 100644 --- a/advisories/unreviewed/2023/01/GHSA-g28r-954m-qc24/GHSA-g28r-954m-qc24.json +++ b/advisories/unreviewed/2023/01/GHSA-g28r-954m-qc24/GHSA-g28r-954m-qc24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json b/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json index d41d314dc97..20a043585d4 100644 --- a/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json +++ b/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-jmx5-53v7-75mr/GHSA-jmx5-53v7-75mr.json b/advisories/unreviewed/2023/01/GHSA-jmx5-53v7-75mr/GHSA-jmx5-53v7-75mr.json index 714c808f66e..44533bf347e 100644 --- a/advisories/unreviewed/2023/01/GHSA-jmx5-53v7-75mr/GHSA-jmx5-53v7-75mr.json +++ b/advisories/unreviewed/2023/01/GHSA-jmx5-53v7-75mr/GHSA-jmx5-53v7-75mr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json b/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json index 4ade7687495..e7a66b38ac2 100644 --- a/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json +++ b/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-wfr4-c7jj-8xgp/GHSA-wfr4-c7jj-8xgp.json b/advisories/unreviewed/2023/01/GHSA-wfr4-c7jj-8xgp/GHSA-wfr4-c7jj-8xgp.json index 1d42e36a828..64dbf09cf67 100644 --- a/advisories/unreviewed/2023/01/GHSA-wfr4-c7jj-8xgp/GHSA-wfr4-c7jj-8xgp.json +++ b/advisories/unreviewed/2023/01/GHSA-wfr4-c7jj-8xgp/GHSA-wfr4-c7jj-8xgp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-296m-v66m-w8jp/GHSA-296m-v66m-w8jp.json b/advisories/unreviewed/2024/06/GHSA-296m-v66m-w8jp/GHSA-296m-v66m-w8jp.json index f2b8e9fb7a2..f268dd8c7cb 100644 --- a/advisories/unreviewed/2024/06/GHSA-296m-v66m-w8jp/GHSA-296m-v66m-w8jp.json +++ b/advisories/unreviewed/2024/06/GHSA-296m-v66m-w8jp/GHSA-296m-v66m-w8jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-32gm-gr8r-8r4x/GHSA-32gm-gr8r-8r4x.json b/advisories/unreviewed/2024/06/GHSA-32gm-gr8r-8r4x/GHSA-32gm-gr8r-8r4x.json index 4c038c50b05..8753fe88624 100644 --- a/advisories/unreviewed/2024/06/GHSA-32gm-gr8r-8r4x/GHSA-32gm-gr8r-8r4x.json +++ b/advisories/unreviewed/2024/06/GHSA-32gm-gr8r-8r4x/GHSA-32gm-gr8r-8r4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3vmg-wgpj-fjxv/GHSA-3vmg-wgpj-fjxv.json b/advisories/unreviewed/2024/06/GHSA-3vmg-wgpj-fjxv/GHSA-3vmg-wgpj-fjxv.json index 4d7b88cf111..1c10580808a 100644 --- a/advisories/unreviewed/2024/06/GHSA-3vmg-wgpj-fjxv/GHSA-3vmg-wgpj-fjxv.json +++ b/advisories/unreviewed/2024/06/GHSA-3vmg-wgpj-fjxv/GHSA-3vmg-wgpj-fjxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-3xjq-wgw3-893q/GHSA-3xjq-wgw3-893q.json b/advisories/unreviewed/2024/06/GHSA-3xjq-wgw3-893q/GHSA-3xjq-wgw3-893q.json index 8b326b43828..53fb705e997 100644 --- a/advisories/unreviewed/2024/06/GHSA-3xjq-wgw3-893q/GHSA-3xjq-wgw3-893q.json +++ b/advisories/unreviewed/2024/06/GHSA-3xjq-wgw3-893q/GHSA-3xjq-wgw3-893q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4662-jh8w-4j8m/GHSA-4662-jh8w-4j8m.json b/advisories/unreviewed/2024/06/GHSA-4662-jh8w-4j8m/GHSA-4662-jh8w-4j8m.json index 7b87abd65c0..b3a1eef37d3 100644 --- a/advisories/unreviewed/2024/06/GHSA-4662-jh8w-4j8m/GHSA-4662-jh8w-4j8m.json +++ b/advisories/unreviewed/2024/06/GHSA-4662-jh8w-4j8m/GHSA-4662-jh8w-4j8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4fxh-g6gh-xg2v/GHSA-4fxh-g6gh-xg2v.json b/advisories/unreviewed/2024/06/GHSA-4fxh-g6gh-xg2v/GHSA-4fxh-g6gh-xg2v.json index ce3934b68a5..51d1c21a513 100644 --- a/advisories/unreviewed/2024/06/GHSA-4fxh-g6gh-xg2v/GHSA-4fxh-g6gh-xg2v.json +++ b/advisories/unreviewed/2024/06/GHSA-4fxh-g6gh-xg2v/GHSA-4fxh-g6gh-xg2v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4mhw-2p42-7v79/GHSA-4mhw-2p42-7v79.json b/advisories/unreviewed/2024/06/GHSA-4mhw-2p42-7v79/GHSA-4mhw-2p42-7v79.json index 9582302294e..46f945e2d20 100644 --- a/advisories/unreviewed/2024/06/GHSA-4mhw-2p42-7v79/GHSA-4mhw-2p42-7v79.json +++ b/advisories/unreviewed/2024/06/GHSA-4mhw-2p42-7v79/GHSA-4mhw-2p42-7v79.json @@ -7,12 +7,8 @@ "CVE-2024-38282" ], "details": "Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations or shutdown the camera requiring a physical reboot of the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-4x7j-mh3x-q8gv/GHSA-4x7j-mh3x-q8gv.json b/advisories/unreviewed/2024/06/GHSA-4x7j-mh3x-q8gv/GHSA-4x7j-mh3x-q8gv.json index 0188e7a30df..b862eed9a9d 100644 --- a/advisories/unreviewed/2024/06/GHSA-4x7j-mh3x-q8gv/GHSA-4x7j-mh3x-q8gv.json +++ b/advisories/unreviewed/2024/06/GHSA-4x7j-mh3x-q8gv/GHSA-4x7j-mh3x-q8gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-57f9-3232-gc7j/GHSA-57f9-3232-gc7j.json b/advisories/unreviewed/2024/06/GHSA-57f9-3232-gc7j/GHSA-57f9-3232-gc7j.json index 99096f03871..59c8b18a74f 100644 --- a/advisories/unreviewed/2024/06/GHSA-57f9-3232-gc7j/GHSA-57f9-3232-gc7j.json +++ b/advisories/unreviewed/2024/06/GHSA-57f9-3232-gc7j/GHSA-57f9-3232-gc7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5pp6-xjm9-wv7v/GHSA-5pp6-xjm9-wv7v.json b/advisories/unreviewed/2024/06/GHSA-5pp6-xjm9-wv7v/GHSA-5pp6-xjm9-wv7v.json index 7a9973003fb..22bd5315dff 100644 --- a/advisories/unreviewed/2024/06/GHSA-5pp6-xjm9-wv7v/GHSA-5pp6-xjm9-wv7v.json +++ b/advisories/unreviewed/2024/06/GHSA-5pp6-xjm9-wv7v/GHSA-5pp6-xjm9-wv7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5qqv-7p5x-fvxp/GHSA-5qqv-7p5x-fvxp.json b/advisories/unreviewed/2024/06/GHSA-5qqv-7p5x-fvxp/GHSA-5qqv-7p5x-fvxp.json index 6d1b5bb2a84..bccc547ea8e 100644 --- a/advisories/unreviewed/2024/06/GHSA-5qqv-7p5x-fvxp/GHSA-5qqv-7p5x-fvxp.json +++ b/advisories/unreviewed/2024/06/GHSA-5qqv-7p5x-fvxp/GHSA-5qqv-7p5x-fvxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-68m9-84vh-c378/GHSA-68m9-84vh-c378.json b/advisories/unreviewed/2024/06/GHSA-68m9-84vh-c378/GHSA-68m9-84vh-c378.json index 33f88674b32..c38d3786a3c 100644 --- a/advisories/unreviewed/2024/06/GHSA-68m9-84vh-c378/GHSA-68m9-84vh-c378.json +++ b/advisories/unreviewed/2024/06/GHSA-68m9-84vh-c378/GHSA-68m9-84vh-c378.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6c59-vxhc-2mqj/GHSA-6c59-vxhc-2mqj.json b/advisories/unreviewed/2024/06/GHSA-6c59-vxhc-2mqj/GHSA-6c59-vxhc-2mqj.json index f924c4e9eb7..9772bf9580f 100644 --- a/advisories/unreviewed/2024/06/GHSA-6c59-vxhc-2mqj/GHSA-6c59-vxhc-2mqj.json +++ b/advisories/unreviewed/2024/06/GHSA-6c59-vxhc-2mqj/GHSA-6c59-vxhc-2mqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6c6m-p94j-g86j/GHSA-6c6m-p94j-g86j.json b/advisories/unreviewed/2024/06/GHSA-6c6m-p94j-g86j/GHSA-6c6m-p94j-g86j.json index 36790c9bba9..5e28abdf607 100644 --- a/advisories/unreviewed/2024/06/GHSA-6c6m-p94j-g86j/GHSA-6c6m-p94j-g86j.json +++ b/advisories/unreviewed/2024/06/GHSA-6c6m-p94j-g86j/GHSA-6c6m-p94j-g86j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6ccp-94q2-9ggr/GHSA-6ccp-94q2-9ggr.json b/advisories/unreviewed/2024/06/GHSA-6ccp-94q2-9ggr/GHSA-6ccp-94q2-9ggr.json index 106ed39ef30..fdb232effcb 100644 --- a/advisories/unreviewed/2024/06/GHSA-6ccp-94q2-9ggr/GHSA-6ccp-94q2-9ggr.json +++ b/advisories/unreviewed/2024/06/GHSA-6ccp-94q2-9ggr/GHSA-6ccp-94q2-9ggr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6crp-pv4g-xcj8/GHSA-6crp-pv4g-xcj8.json b/advisories/unreviewed/2024/06/GHSA-6crp-pv4g-xcj8/GHSA-6crp-pv4g-xcj8.json index 0c0f8f86066..1f3fde16387 100644 --- a/advisories/unreviewed/2024/06/GHSA-6crp-pv4g-xcj8/GHSA-6crp-pv4g-xcj8.json +++ b/advisories/unreviewed/2024/06/GHSA-6crp-pv4g-xcj8/GHSA-6crp-pv4g-xcj8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6q8w-cx85-gwxp/GHSA-6q8w-cx85-gwxp.json b/advisories/unreviewed/2024/06/GHSA-6q8w-cx85-gwxp/GHSA-6q8w-cx85-gwxp.json index 285acc689bd..e1c1fc54117 100644 --- a/advisories/unreviewed/2024/06/GHSA-6q8w-cx85-gwxp/GHSA-6q8w-cx85-gwxp.json +++ b/advisories/unreviewed/2024/06/GHSA-6q8w-cx85-gwxp/GHSA-6q8w-cx85-gwxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-736q-qv2f-fcvr/GHSA-736q-qv2f-fcvr.json b/advisories/unreviewed/2024/06/GHSA-736q-qv2f-fcvr/GHSA-736q-qv2f-fcvr.json index 15cc20633c3..584e88cb06a 100644 --- a/advisories/unreviewed/2024/06/GHSA-736q-qv2f-fcvr/GHSA-736q-qv2f-fcvr.json +++ b/advisories/unreviewed/2024/06/GHSA-736q-qv2f-fcvr/GHSA-736q-qv2f-fcvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-743f-g3w9-hfj2/GHSA-743f-g3w9-hfj2.json b/advisories/unreviewed/2024/06/GHSA-743f-g3w9-hfj2/GHSA-743f-g3w9-hfj2.json index 8850676e060..c9e9f2db0f3 100644 --- a/advisories/unreviewed/2024/06/GHSA-743f-g3w9-hfj2/GHSA-743f-g3w9-hfj2.json +++ b/advisories/unreviewed/2024/06/GHSA-743f-g3w9-hfj2/GHSA-743f-g3w9-hfj2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-746c-7v72-3ccf/GHSA-746c-7v72-3ccf.json b/advisories/unreviewed/2024/06/GHSA-746c-7v72-3ccf/GHSA-746c-7v72-3ccf.json index a9c351632d6..e9fcbb6a2c8 100644 --- a/advisories/unreviewed/2024/06/GHSA-746c-7v72-3ccf/GHSA-746c-7v72-3ccf.json +++ b/advisories/unreviewed/2024/06/GHSA-746c-7v72-3ccf/GHSA-746c-7v72-3ccf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-76c7-54r2-mq68/GHSA-76c7-54r2-mq68.json b/advisories/unreviewed/2024/06/GHSA-76c7-54r2-mq68/GHSA-76c7-54r2-mq68.json index da6b41027b9..9f4ba744b80 100644 --- a/advisories/unreviewed/2024/06/GHSA-76c7-54r2-mq68/GHSA-76c7-54r2-mq68.json +++ b/advisories/unreviewed/2024/06/GHSA-76c7-54r2-mq68/GHSA-76c7-54r2-mq68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7hjv-959f-2qjf/GHSA-7hjv-959f-2qjf.json b/advisories/unreviewed/2024/06/GHSA-7hjv-959f-2qjf/GHSA-7hjv-959f-2qjf.json index bf6aadcf039..d7e804f26cd 100644 --- a/advisories/unreviewed/2024/06/GHSA-7hjv-959f-2qjf/GHSA-7hjv-959f-2qjf.json +++ b/advisories/unreviewed/2024/06/GHSA-7hjv-959f-2qjf/GHSA-7hjv-959f-2qjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7j88-hp3g-mw9c/GHSA-7j88-hp3g-mw9c.json b/advisories/unreviewed/2024/06/GHSA-7j88-hp3g-mw9c/GHSA-7j88-hp3g-mw9c.json index 37c0e375ae6..08ab95672a2 100644 --- a/advisories/unreviewed/2024/06/GHSA-7j88-hp3g-mw9c/GHSA-7j88-hp3g-mw9c.json +++ b/advisories/unreviewed/2024/06/GHSA-7j88-hp3g-mw9c/GHSA-7j88-hp3g-mw9c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7jvc-5938-w5vc/GHSA-7jvc-5938-w5vc.json b/advisories/unreviewed/2024/06/GHSA-7jvc-5938-w5vc/GHSA-7jvc-5938-w5vc.json index 960ec57e7a0..03c489abc2b 100644 --- a/advisories/unreviewed/2024/06/GHSA-7jvc-5938-w5vc/GHSA-7jvc-5938-w5vc.json +++ b/advisories/unreviewed/2024/06/GHSA-7jvc-5938-w5vc/GHSA-7jvc-5938-w5vc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-836g-2rjm-jcvv/GHSA-836g-2rjm-jcvv.json b/advisories/unreviewed/2024/06/GHSA-836g-2rjm-jcvv/GHSA-836g-2rjm-jcvv.json index 82ad61dbc44..122f98807bc 100644 --- a/advisories/unreviewed/2024/06/GHSA-836g-2rjm-jcvv/GHSA-836g-2rjm-jcvv.json +++ b/advisories/unreviewed/2024/06/GHSA-836g-2rjm-jcvv/GHSA-836g-2rjm-jcvv.json @@ -7,12 +7,8 @@ "CVE-2024-38284" ], "details": "Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a replay attack to replicate calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8w36-643w-8rw9/GHSA-8w36-643w-8rw9.json b/advisories/unreviewed/2024/06/GHSA-8w36-643w-8rw9/GHSA-8w36-643w-8rw9.json index 57cc156b198..f07738a5cf3 100644 --- a/advisories/unreviewed/2024/06/GHSA-8w36-643w-8rw9/GHSA-8w36-643w-8rw9.json +++ b/advisories/unreviewed/2024/06/GHSA-8w36-643w-8rw9/GHSA-8w36-643w-8rw9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-92w6-g66f-qhgf/GHSA-92w6-g66f-qhgf.json b/advisories/unreviewed/2024/06/GHSA-92w6-g66f-qhgf/GHSA-92w6-g66f-qhgf.json index b5878320365..fda9ee42bdc 100644 --- a/advisories/unreviewed/2024/06/GHSA-92w6-g66f-qhgf/GHSA-92w6-g66f-qhgf.json +++ b/advisories/unreviewed/2024/06/GHSA-92w6-g66f-qhgf/GHSA-92w6-g66f-qhgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-93f8-hx2v-qxcp/GHSA-93f8-hx2v-qxcp.json b/advisories/unreviewed/2024/06/GHSA-93f8-hx2v-qxcp/GHSA-93f8-hx2v-qxcp.json index 9ece7a4d3fa..a7614da5dd7 100644 --- a/advisories/unreviewed/2024/06/GHSA-93f8-hx2v-qxcp/GHSA-93f8-hx2v-qxcp.json +++ b/advisories/unreviewed/2024/06/GHSA-93f8-hx2v-qxcp/GHSA-93f8-hx2v-qxcp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-94xv-rp86-287j/GHSA-94xv-rp86-287j.json b/advisories/unreviewed/2024/06/GHSA-94xv-rp86-287j/GHSA-94xv-rp86-287j.json index ad298865700..015f8a13dac 100644 --- a/advisories/unreviewed/2024/06/GHSA-94xv-rp86-287j/GHSA-94xv-rp86-287j.json +++ b/advisories/unreviewed/2024/06/GHSA-94xv-rp86-287j/GHSA-94xv-rp86-287j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-95j6-2grv-6h9g/GHSA-95j6-2grv-6h9g.json b/advisories/unreviewed/2024/06/GHSA-95j6-2grv-6h9g/GHSA-95j6-2grv-6h9g.json index d26b2b850c1..f94bc3fc98d 100644 --- a/advisories/unreviewed/2024/06/GHSA-95j6-2grv-6h9g/GHSA-95j6-2grv-6h9g.json +++ b/advisories/unreviewed/2024/06/GHSA-95j6-2grv-6h9g/GHSA-95j6-2grv-6h9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-c96x-jgjp-qrr3/GHSA-c96x-jgjp-qrr3.json b/advisories/unreviewed/2024/06/GHSA-c96x-jgjp-qrr3/GHSA-c96x-jgjp-qrr3.json index 288280337e1..d7b21b24163 100644 --- a/advisories/unreviewed/2024/06/GHSA-c96x-jgjp-qrr3/GHSA-c96x-jgjp-qrr3.json +++ b/advisories/unreviewed/2024/06/GHSA-c96x-jgjp-qrr3/GHSA-c96x-jgjp-qrr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-cxhm-2gjg-5mq6/GHSA-cxhm-2gjg-5mq6.json b/advisories/unreviewed/2024/06/GHSA-cxhm-2gjg-5mq6/GHSA-cxhm-2gjg-5mq6.json index 74d74ffedfa..130b1c774f4 100644 --- a/advisories/unreviewed/2024/06/GHSA-cxhm-2gjg-5mq6/GHSA-cxhm-2gjg-5mq6.json +++ b/advisories/unreviewed/2024/06/GHSA-cxhm-2gjg-5mq6/GHSA-cxhm-2gjg-5mq6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f5jq-9q2m-347v/GHSA-f5jq-9q2m-347v.json b/advisories/unreviewed/2024/06/GHSA-f5jq-9q2m-347v/GHSA-f5jq-9q2m-347v.json index 1a6753457c2..56ef2f27083 100644 --- a/advisories/unreviewed/2024/06/GHSA-f5jq-9q2m-347v/GHSA-f5jq-9q2m-347v.json +++ b/advisories/unreviewed/2024/06/GHSA-f5jq-9q2m-347v/GHSA-f5jq-9q2m-347v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-f767-vqcm-8q38/GHSA-f767-vqcm-8q38.json b/advisories/unreviewed/2024/06/GHSA-f767-vqcm-8q38/GHSA-f767-vqcm-8q38.json index 41631b93720..d6e5b4a49a2 100644 --- a/advisories/unreviewed/2024/06/GHSA-f767-vqcm-8q38/GHSA-f767-vqcm-8q38.json +++ b/advisories/unreviewed/2024/06/GHSA-f767-vqcm-8q38/GHSA-f767-vqcm-8q38.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-fj35-7g9r-r874/GHSA-fj35-7g9r-r874.json b/advisories/unreviewed/2024/06/GHSA-fj35-7g9r-r874/GHSA-fj35-7g9r-r874.json index f14402bbb02..ab7d3d092e0 100644 --- a/advisories/unreviewed/2024/06/GHSA-fj35-7g9r-r874/GHSA-fj35-7g9r-r874.json +++ b/advisories/unreviewed/2024/06/GHSA-fj35-7g9r-r874/GHSA-fj35-7g9r-r874.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-fp5w-9974-qhvj/GHSA-fp5w-9974-qhvj.json b/advisories/unreviewed/2024/06/GHSA-fp5w-9974-qhvj/GHSA-fp5w-9974-qhvj.json index efbfcd1707b..d4a9a4d2135 100644 --- a/advisories/unreviewed/2024/06/GHSA-fp5w-9974-qhvj/GHSA-fp5w-9974-qhvj.json +++ b/advisories/unreviewed/2024/06/GHSA-fp5w-9974-qhvj/GHSA-fp5w-9974-qhvj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-g48v-4gfg-j84v/GHSA-g48v-4gfg-j84v.json b/advisories/unreviewed/2024/06/GHSA-g48v-4gfg-j84v/GHSA-g48v-4gfg-j84v.json index 3f3de16ec70..42fd9102c6d 100644 --- a/advisories/unreviewed/2024/06/GHSA-g48v-4gfg-j84v/GHSA-g48v-4gfg-j84v.json +++ b/advisories/unreviewed/2024/06/GHSA-g48v-4gfg-j84v/GHSA-g48v-4gfg-j84v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-g6f4-8v84-78c7/GHSA-g6f4-8v84-78c7.json b/advisories/unreviewed/2024/06/GHSA-g6f4-8v84-78c7/GHSA-g6f4-8v84-78c7.json index ec882a54312..b7f3ec80b3c 100644 --- a/advisories/unreviewed/2024/06/GHSA-g6f4-8v84-78c7/GHSA-g6f4-8v84-78c7.json +++ b/advisories/unreviewed/2024/06/GHSA-g6f4-8v84-78c7/GHSA-g6f4-8v84-78c7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-gc6m-q9f7-723r/GHSA-gc6m-q9f7-723r.json b/advisories/unreviewed/2024/06/GHSA-gc6m-q9f7-723r/GHSA-gc6m-q9f7-723r.json index 98ab23c87c5..7940a95c44b 100644 --- a/advisories/unreviewed/2024/06/GHSA-gc6m-q9f7-723r/GHSA-gc6m-q9f7-723r.json +++ b/advisories/unreviewed/2024/06/GHSA-gc6m-q9f7-723r/GHSA-gc6m-q9f7-723r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-gcjp-r2q8-c8r9/GHSA-gcjp-r2q8-c8r9.json b/advisories/unreviewed/2024/06/GHSA-gcjp-r2q8-c8r9/GHSA-gcjp-r2q8-c8r9.json index c9c43454bd0..6a19842cd27 100644 --- a/advisories/unreviewed/2024/06/GHSA-gcjp-r2q8-c8r9/GHSA-gcjp-r2q8-c8r9.json +++ b/advisories/unreviewed/2024/06/GHSA-gcjp-r2q8-c8r9/GHSA-gcjp-r2q8-c8r9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-gj9p-prj2-vr68/GHSA-gj9p-prj2-vr68.json b/advisories/unreviewed/2024/06/GHSA-gj9p-prj2-vr68/GHSA-gj9p-prj2-vr68.json index 2aaafb85ebc..028c4e33407 100644 --- a/advisories/unreviewed/2024/06/GHSA-gj9p-prj2-vr68/GHSA-gj9p-prj2-vr68.json +++ b/advisories/unreviewed/2024/06/GHSA-gj9p-prj2-vr68/GHSA-gj9p-prj2-vr68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-h83c-hv8p-vjwx/GHSA-h83c-hv8p-vjwx.json b/advisories/unreviewed/2024/06/GHSA-h83c-hv8p-vjwx/GHSA-h83c-hv8p-vjwx.json index dfe2e881d73..c5e3e44841c 100644 --- a/advisories/unreviewed/2024/06/GHSA-h83c-hv8p-vjwx/GHSA-h83c-hv8p-vjwx.json +++ b/advisories/unreviewed/2024/06/GHSA-h83c-hv8p-vjwx/GHSA-h83c-hv8p-vjwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-h85c-h8jh-v47r/GHSA-h85c-h8jh-v47r.json b/advisories/unreviewed/2024/06/GHSA-h85c-h8jh-v47r/GHSA-h85c-h8jh-v47r.json index b6bfeb46c7e..4a496fa7466 100644 --- a/advisories/unreviewed/2024/06/GHSA-h85c-h8jh-v47r/GHSA-h85c-h8jh-v47r.json +++ b/advisories/unreviewed/2024/06/GHSA-h85c-h8jh-v47r/GHSA-h85c-h8jh-v47r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-hc4v-987m-2cmm/GHSA-hc4v-987m-2cmm.json b/advisories/unreviewed/2024/06/GHSA-hc4v-987m-2cmm/GHSA-hc4v-987m-2cmm.json index 95d4c674cd8..6d3a211dc5a 100644 --- a/advisories/unreviewed/2024/06/GHSA-hc4v-987m-2cmm/GHSA-hc4v-987m-2cmm.json +++ b/advisories/unreviewed/2024/06/GHSA-hc4v-987m-2cmm/GHSA-hc4v-987m-2cmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-hcgf-86c7-xfvc/GHSA-hcgf-86c7-xfvc.json b/advisories/unreviewed/2024/06/GHSA-hcgf-86c7-xfvc/GHSA-hcgf-86c7-xfvc.json index 8434e9e1e62..fd903ad3ac1 100644 --- a/advisories/unreviewed/2024/06/GHSA-hcgf-86c7-xfvc/GHSA-hcgf-86c7-xfvc.json +++ b/advisories/unreviewed/2024/06/GHSA-hcgf-86c7-xfvc/GHSA-hcgf-86c7-xfvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-hgp5-r8w2-frrr/GHSA-hgp5-r8w2-frrr.json b/advisories/unreviewed/2024/06/GHSA-hgp5-r8w2-frrr/GHSA-hgp5-r8w2-frrr.json index a75828e0a6f..6803b4bbc4a 100644 --- a/advisories/unreviewed/2024/06/GHSA-hgp5-r8w2-frrr/GHSA-hgp5-r8w2-frrr.json +++ b/advisories/unreviewed/2024/06/GHSA-hgp5-r8w2-frrr/GHSA-hgp5-r8w2-frrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-hmr2-5mc5-frq6/GHSA-hmr2-5mc5-frq6.json b/advisories/unreviewed/2024/06/GHSA-hmr2-5mc5-frq6/GHSA-hmr2-5mc5-frq6.json index df693da9784..2e635186ddb 100644 --- a/advisories/unreviewed/2024/06/GHSA-hmr2-5mc5-frq6/GHSA-hmr2-5mc5-frq6.json +++ b/advisories/unreviewed/2024/06/GHSA-hmr2-5mc5-frq6/GHSA-hmr2-5mc5-frq6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-hq2x-42qh-qfx6/GHSA-hq2x-42qh-qfx6.json b/advisories/unreviewed/2024/06/GHSA-hq2x-42qh-qfx6/GHSA-hq2x-42qh-qfx6.json index 66b406c89ee..84c7e1ea894 100644 --- a/advisories/unreviewed/2024/06/GHSA-hq2x-42qh-qfx6/GHSA-hq2x-42qh-qfx6.json +++ b/advisories/unreviewed/2024/06/GHSA-hq2x-42qh-qfx6/GHSA-hq2x-42qh-qfx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-hxfv-hmpx-xj28/GHSA-hxfv-hmpx-xj28.json b/advisories/unreviewed/2024/06/GHSA-hxfv-hmpx-xj28/GHSA-hxfv-hmpx-xj28.json index 701950f078e..9ad0f493dc0 100644 --- a/advisories/unreviewed/2024/06/GHSA-hxfv-hmpx-xj28/GHSA-hxfv-hmpx-xj28.json +++ b/advisories/unreviewed/2024/06/GHSA-hxfv-hmpx-xj28/GHSA-hxfv-hmpx-xj28.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j33r-v3xc-53j7/GHSA-j33r-v3xc-53j7.json b/advisories/unreviewed/2024/06/GHSA-j33r-v3xc-53j7/GHSA-j33r-v3xc-53j7.json index 8890013baf9..560c104cbbb 100644 --- a/advisories/unreviewed/2024/06/GHSA-j33r-v3xc-53j7/GHSA-j33r-v3xc-53j7.json +++ b/advisories/unreviewed/2024/06/GHSA-j33r-v3xc-53j7/GHSA-j33r-v3xc-53j7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j373-f2v6-57rr/GHSA-j373-f2v6-57rr.json b/advisories/unreviewed/2024/06/GHSA-j373-f2v6-57rr/GHSA-j373-f2v6-57rr.json index 1cfa806f2b6..ce4756bf56e 100644 --- a/advisories/unreviewed/2024/06/GHSA-j373-f2v6-57rr/GHSA-j373-f2v6-57rr.json +++ b/advisories/unreviewed/2024/06/GHSA-j373-f2v6-57rr/GHSA-j373-f2v6-57rr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-j4m9-p3x7-cqvx/GHSA-j4m9-p3x7-cqvx.json b/advisories/unreviewed/2024/06/GHSA-j4m9-p3x7-cqvx/GHSA-j4m9-p3x7-cqvx.json index 370995e72d5..9eaa2c70720 100644 --- a/advisories/unreviewed/2024/06/GHSA-j4m9-p3x7-cqvx/GHSA-j4m9-p3x7-cqvx.json +++ b/advisories/unreviewed/2024/06/GHSA-j4m9-p3x7-cqvx/GHSA-j4m9-p3x7-cqvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-jq42-q6c8-f44h/GHSA-jq42-q6c8-f44h.json b/advisories/unreviewed/2024/06/GHSA-jq42-q6c8-f44h/GHSA-jq42-q6c8-f44h.json index a00a35d32d4..1e87fbb8ee1 100644 --- a/advisories/unreviewed/2024/06/GHSA-jq42-q6c8-f44h/GHSA-jq42-q6c8-f44h.json +++ b/advisories/unreviewed/2024/06/GHSA-jq42-q6c8-f44h/GHSA-jq42-q6c8-f44h.json @@ -7,12 +7,8 @@ "CVE-2024-32924" ], "details": "In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-jvf6-388x-r47w/GHSA-jvf6-388x-r47w.json b/advisories/unreviewed/2024/06/GHSA-jvf6-388x-r47w/GHSA-jvf6-388x-r47w.json index 80f527874d2..623ae4e62d8 100644 --- a/advisories/unreviewed/2024/06/GHSA-jvf6-388x-r47w/GHSA-jvf6-388x-r47w.json +++ b/advisories/unreviewed/2024/06/GHSA-jvf6-388x-r47w/GHSA-jvf6-388x-r47w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-m5f4-mxmv-gqwv/GHSA-m5f4-mxmv-gqwv.json b/advisories/unreviewed/2024/06/GHSA-m5f4-mxmv-gqwv/GHSA-m5f4-mxmv-gqwv.json index a62b40b629f..cfeddb59d5e 100644 --- a/advisories/unreviewed/2024/06/GHSA-m5f4-mxmv-gqwv/GHSA-m5f4-mxmv-gqwv.json +++ b/advisories/unreviewed/2024/06/GHSA-m5f4-mxmv-gqwv/GHSA-m5f4-mxmv-gqwv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-m7r7-rm5j-fm89/GHSA-m7r7-rm5j-fm89.json b/advisories/unreviewed/2024/06/GHSA-m7r7-rm5j-fm89/GHSA-m7r7-rm5j-fm89.json index c40c66b9446..a14c9d753b6 100644 --- a/advisories/unreviewed/2024/06/GHSA-m7r7-rm5j-fm89/GHSA-m7r7-rm5j-fm89.json +++ b/advisories/unreviewed/2024/06/GHSA-m7r7-rm5j-fm89/GHSA-m7r7-rm5j-fm89.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mfx5-2wjg-73rv/GHSA-mfx5-2wjg-73rv.json b/advisories/unreviewed/2024/06/GHSA-mfx5-2wjg-73rv/GHSA-mfx5-2wjg-73rv.json index 355ab34ebc1..61835a18062 100644 --- a/advisories/unreviewed/2024/06/GHSA-mfx5-2wjg-73rv/GHSA-mfx5-2wjg-73rv.json +++ b/advisories/unreviewed/2024/06/GHSA-mfx5-2wjg-73rv/GHSA-mfx5-2wjg-73rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mhvg-m4c7-2668/GHSA-mhvg-m4c7-2668.json b/advisories/unreviewed/2024/06/GHSA-mhvg-m4c7-2668/GHSA-mhvg-m4c7-2668.json index 2cf7be6c1c9..5ba02c0ef72 100644 --- a/advisories/unreviewed/2024/06/GHSA-mhvg-m4c7-2668/GHSA-mhvg-m4c7-2668.json +++ b/advisories/unreviewed/2024/06/GHSA-mhvg-m4c7-2668/GHSA-mhvg-m4c7-2668.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mq78-vgg5-pj68/GHSA-mq78-vgg5-pj68.json b/advisories/unreviewed/2024/06/GHSA-mq78-vgg5-pj68/GHSA-mq78-vgg5-pj68.json index 5f7342104a3..e53212c9482 100644 --- a/advisories/unreviewed/2024/06/GHSA-mq78-vgg5-pj68/GHSA-mq78-vgg5-pj68.json +++ b/advisories/unreviewed/2024/06/GHSA-mq78-vgg5-pj68/GHSA-mq78-vgg5-pj68.json @@ -7,12 +7,8 @@ "CVE-2024-38283" ], "details": "Sensitive customer information is stored in the device without encryption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-pwgr-2gfv-9676/GHSA-pwgr-2gfv-9676.json b/advisories/unreviewed/2024/06/GHSA-pwgr-2gfv-9676/GHSA-pwgr-2gfv-9676.json index a288db7fb5c..1949383ea78 100644 --- a/advisories/unreviewed/2024/06/GHSA-pwgr-2gfv-9676/GHSA-pwgr-2gfv-9676.json +++ b/advisories/unreviewed/2024/06/GHSA-pwgr-2gfv-9676/GHSA-pwgr-2gfv-9676.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-pxvr-66m2-jxg6/GHSA-pxvr-66m2-jxg6.json b/advisories/unreviewed/2024/06/GHSA-pxvr-66m2-jxg6/GHSA-pxvr-66m2-jxg6.json index 806289ae809..30b4077d11b 100644 --- a/advisories/unreviewed/2024/06/GHSA-pxvr-66m2-jxg6/GHSA-pxvr-66m2-jxg6.json +++ b/advisories/unreviewed/2024/06/GHSA-pxvr-66m2-jxg6/GHSA-pxvr-66m2-jxg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qc2p-795v-hjqh/GHSA-qc2p-795v-hjqh.json b/advisories/unreviewed/2024/06/GHSA-qc2p-795v-hjqh/GHSA-qc2p-795v-hjqh.json index b6c11d2139a..ad833566b95 100644 --- a/advisories/unreviewed/2024/06/GHSA-qc2p-795v-hjqh/GHSA-qc2p-795v-hjqh.json +++ b/advisories/unreviewed/2024/06/GHSA-qc2p-795v-hjqh/GHSA-qc2p-795v-hjqh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qphh-cq77-c378/GHSA-qphh-cq77-c378.json b/advisories/unreviewed/2024/06/GHSA-qphh-cq77-c378/GHSA-qphh-cq77-c378.json index 2a49958894a..819c327f979 100644 --- a/advisories/unreviewed/2024/06/GHSA-qphh-cq77-c378/GHSA-qphh-cq77-c378.json +++ b/advisories/unreviewed/2024/06/GHSA-qphh-cq77-c378/GHSA-qphh-cq77-c378.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qrqq-9838-mwwm/GHSA-qrqq-9838-mwwm.json b/advisories/unreviewed/2024/06/GHSA-qrqq-9838-mwwm/GHSA-qrqq-9838-mwwm.json index 319e108653c..3d0e1fb6776 100644 --- a/advisories/unreviewed/2024/06/GHSA-qrqq-9838-mwwm/GHSA-qrqq-9838-mwwm.json +++ b/advisories/unreviewed/2024/06/GHSA-qrqq-9838-mwwm/GHSA-qrqq-9838-mwwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rfh8-hgh4-42q6/GHSA-rfh8-hgh4-42q6.json b/advisories/unreviewed/2024/06/GHSA-rfh8-hgh4-42q6/GHSA-rfh8-hgh4-42q6.json index b4c71487b3b..db5ed1afff5 100644 --- a/advisories/unreviewed/2024/06/GHSA-rfh8-hgh4-42q6/GHSA-rfh8-hgh4-42q6.json +++ b/advisories/unreviewed/2024/06/GHSA-rfh8-hgh4-42q6/GHSA-rfh8-hgh4-42q6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rhc6-qxqq-hhh6/GHSA-rhc6-qxqq-hhh6.json b/advisories/unreviewed/2024/06/GHSA-rhc6-qxqq-hhh6/GHSA-rhc6-qxqq-hhh6.json index 0dd589eb5e5..b8c03c23469 100644 --- a/advisories/unreviewed/2024/06/GHSA-rhc6-qxqq-hhh6/GHSA-rhc6-qxqq-hhh6.json +++ b/advisories/unreviewed/2024/06/GHSA-rhc6-qxqq-hhh6/GHSA-rhc6-qxqq-hhh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rhrf-hh3q-54pc/GHSA-rhrf-hh3q-54pc.json b/advisories/unreviewed/2024/06/GHSA-rhrf-hh3q-54pc/GHSA-rhrf-hh3q-54pc.json index 2b016f929b5..46a4f89359b 100644 --- a/advisories/unreviewed/2024/06/GHSA-rhrf-hh3q-54pc/GHSA-rhrf-hh3q-54pc.json +++ b/advisories/unreviewed/2024/06/GHSA-rhrf-hh3q-54pc/GHSA-rhrf-hh3q-54pc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rp53-2ch4-r2gq/GHSA-rp53-2ch4-r2gq.json b/advisories/unreviewed/2024/06/GHSA-rp53-2ch4-r2gq/GHSA-rp53-2ch4-r2gq.json index dfc31e33430..f665be099c7 100644 --- a/advisories/unreviewed/2024/06/GHSA-rp53-2ch4-r2gq/GHSA-rp53-2ch4-r2gq.json +++ b/advisories/unreviewed/2024/06/GHSA-rp53-2ch4-r2gq/GHSA-rp53-2ch4-r2gq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-v6qm-969h-rr46/GHSA-v6qm-969h-rr46.json b/advisories/unreviewed/2024/06/GHSA-v6qm-969h-rr46/GHSA-v6qm-969h-rr46.json index 0514eb07a6b..2fea319fe4c 100644 --- a/advisories/unreviewed/2024/06/GHSA-v6qm-969h-rr46/GHSA-v6qm-969h-rr46.json +++ b/advisories/unreviewed/2024/06/GHSA-v6qm-969h-rr46/GHSA-v6qm-969h-rr46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vhv2-v858-63v9/GHSA-vhv2-v858-63v9.json b/advisories/unreviewed/2024/06/GHSA-vhv2-v858-63v9/GHSA-vhv2-v858-63v9.json index d29ceed0cbb..df90014812b 100644 --- a/advisories/unreviewed/2024/06/GHSA-vhv2-v858-63v9/GHSA-vhv2-v858-63v9.json +++ b/advisories/unreviewed/2024/06/GHSA-vhv2-v858-63v9/GHSA-vhv2-v858-63v9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-vvhp-c548-j66x/GHSA-vvhp-c548-j66x.json b/advisories/unreviewed/2024/06/GHSA-vvhp-c548-j66x/GHSA-vvhp-c548-j66x.json index 57dfe08e18f..534aa4cdd65 100644 --- a/advisories/unreviewed/2024/06/GHSA-vvhp-c548-j66x/GHSA-vvhp-c548-j66x.json +++ b/advisories/unreviewed/2024/06/GHSA-vvhp-c548-j66x/GHSA-vvhp-c548-j66x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-w939-7ww2-rwgw/GHSA-w939-7ww2-rwgw.json b/advisories/unreviewed/2024/06/GHSA-w939-7ww2-rwgw/GHSA-w939-7ww2-rwgw.json index bc019c16a55..c7f8ed4649a 100644 --- a/advisories/unreviewed/2024/06/GHSA-w939-7ww2-rwgw/GHSA-w939-7ww2-rwgw.json +++ b/advisories/unreviewed/2024/06/GHSA-w939-7ww2-rwgw/GHSA-w939-7ww2-rwgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wh6c-gpx3-rw87/GHSA-wh6c-gpx3-rw87.json b/advisories/unreviewed/2024/06/GHSA-wh6c-gpx3-rw87/GHSA-wh6c-gpx3-rw87.json index 931be1fa38a..bc65cf461e2 100644 --- a/advisories/unreviewed/2024/06/GHSA-wh6c-gpx3-rw87/GHSA-wh6c-gpx3-rw87.json +++ b/advisories/unreviewed/2024/06/GHSA-wh6c-gpx3-rw87/GHSA-wh6c-gpx3-rw87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-wvr3-gr3h-76jc/GHSA-wvr3-gr3h-76jc.json b/advisories/unreviewed/2024/06/GHSA-wvr3-gr3h-76jc/GHSA-wvr3-gr3h-76jc.json index 538c8616d1c..6a94f8c64e0 100644 --- a/advisories/unreviewed/2024/06/GHSA-wvr3-gr3h-76jc/GHSA-wvr3-gr3h-76jc.json +++ b/advisories/unreviewed/2024/06/GHSA-wvr3-gr3h-76jc/GHSA-wvr3-gr3h-76jc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-ww9h-9c2h-gx6j/GHSA-ww9h-9c2h-gx6j.json b/advisories/unreviewed/2024/06/GHSA-ww9h-9c2h-gx6j/GHSA-ww9h-9c2h-gx6j.json index 83e2206af76..16af22c89d6 100644 --- a/advisories/unreviewed/2024/06/GHSA-ww9h-9c2h-gx6j/GHSA-ww9h-9c2h-gx6j.json +++ b/advisories/unreviewed/2024/06/GHSA-ww9h-9c2h-gx6j/GHSA-ww9h-9c2h-gx6j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x28p-92qg-m6c6/GHSA-x28p-92qg-m6c6.json b/advisories/unreviewed/2024/06/GHSA-x28p-92qg-m6c6/GHSA-x28p-92qg-m6c6.json index a665aefcf33..db8be397c11 100644 --- a/advisories/unreviewed/2024/06/GHSA-x28p-92qg-m6c6/GHSA-x28p-92qg-m6c6.json +++ b/advisories/unreviewed/2024/06/GHSA-x28p-92qg-m6c6/GHSA-x28p-92qg-m6c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x7gw-ff28-c5mc/GHSA-x7gw-ff28-c5mc.json b/advisories/unreviewed/2024/06/GHSA-x7gw-ff28-c5mc/GHSA-x7gw-ff28-c5mc.json index c830cccdce7..cfc571fd954 100644 --- a/advisories/unreviewed/2024/06/GHSA-x7gw-ff28-c5mc/GHSA-x7gw-ff28-c5mc.json +++ b/advisories/unreviewed/2024/06/GHSA-x7gw-ff28-c5mc/GHSA-x7gw-ff28-c5mc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-xfq8-j3ff-mc3p/GHSA-xfq8-j3ff-mc3p.json b/advisories/unreviewed/2024/06/GHSA-xfq8-j3ff-mc3p/GHSA-xfq8-j3ff-mc3p.json index 4ca57b16771..c976d5b6535 100644 --- a/advisories/unreviewed/2024/06/GHSA-xfq8-j3ff-mc3p/GHSA-xfq8-j3ff-mc3p.json +++ b/advisories/unreviewed/2024/06/GHSA-xfq8-j3ff-mc3p/GHSA-xfq8-j3ff-mc3p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",