From be93c96aca7fa53ce46e2f584a48133d29df6d67 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 05:13:31 +0000 Subject: [PATCH] Advisory Database Sync --- .../06/GHSA-hjx6-f647-mvf9/GHSA-hjx6-f647-mvf9.json | 4 +--- .../03/GHSA-285f-ccx8-rrvp/GHSA-285f-ccx8-rrvp.json | 4 +--- .../03/GHSA-364v-6m73-qv4g/GHSA-364v-6m73-qv4g.json | 8 ++------ .../03/GHSA-3p6p-69fx-rphw/GHSA-3p6p-69fx-rphw.json | 4 +--- .../03/GHSA-4985-wch3-93jr/GHSA-4985-wch3-93jr.json | 4 +--- .../03/GHSA-4m4q-85vx-69pj/GHSA-4m4q-85vx-69pj.json | 8 ++------ .../03/GHSA-54hx-qqpw-43w9/GHSA-54hx-qqpw-43w9.json | 4 +--- .../03/GHSA-56vq-m685-pfgq/GHSA-56vq-m685-pfgq.json | 4 +--- .../03/GHSA-586w-pwc3-98vf/GHSA-586w-pwc3-98vf.json | 8 ++------ .../03/GHSA-5pf6-9wpm-6x32/GHSA-5pf6-9wpm-6x32.json | 8 ++------ .../03/GHSA-6946-m5h6-646g/GHSA-6946-m5h6-646g.json | 4 +--- .../03/GHSA-6m6p-38qr-9hqw/GHSA-6m6p-38qr-9hqw.json | 8 ++------ .../03/GHSA-7p6g-c4hm-6rg9/GHSA-7p6g-c4hm-6rg9.json | 8 ++------ .../03/GHSA-823h-69v3-2v2f/GHSA-823h-69v3-2v2f.json | 4 +--- .../03/GHSA-85p5-q2pf-xrcr/GHSA-85p5-q2pf-xrcr.json | 8 ++------ .../03/GHSA-8gvv-h2j2-gq6f/GHSA-8gvv-h2j2-gq6f.json | 4 +--- .../03/GHSA-8pmq-fh43-m3pq/GHSA-8pmq-fh43-m3pq.json | 8 ++------ .../03/GHSA-8r95-ggqq-rp99/GHSA-8r95-ggqq-rp99.json | 4 +--- .../03/GHSA-93xr-277q-vq2q/GHSA-93xr-277q-vq2q.json | 8 ++------ .../03/GHSA-98rg-6g94-9qp6/GHSA-98rg-6g94-9qp6.json | 4 +--- .../03/GHSA-9fvc-c86x-ggw4/GHSA-9fvc-c86x-ggw4.json | 4 +--- .../03/GHSA-9hc8-qfq9-mhvp/GHSA-9hc8-qfq9-mhvp.json | 4 +--- .../03/GHSA-9p9h-ch93-4hfr/GHSA-9p9h-ch93-4hfr.json | 8 ++------ .../03/GHSA-c47g-vg34-vp63/GHSA-c47g-vg34-vp63.json | 8 ++------ .../03/GHSA-cw72-cqmc-6g9v/GHSA-cw72-cqmc-6g9v.json | 8 ++------ .../03/GHSA-fwqp-wm97-mvcp/GHSA-fwqp-wm97-mvcp.json | 8 ++------ .../03/GHSA-g4vr-fpgw-9fff/GHSA-g4vr-fpgw-9fff.json | 4 +--- .../03/GHSA-g664-p9gv-7fw8/GHSA-g664-p9gv-7fw8.json | 4 +--- .../03/GHSA-gwhc-2vxp-pjmv/GHSA-gwhc-2vxp-pjmv.json | 8 ++------ .../03/GHSA-h3hh-m6r7-4q65/GHSA-h3hh-m6r7-4q65.json | 4 +--- .../03/GHSA-h5p4-3w39-xhh2/GHSA-h5p4-3w39-xhh2.json | 8 ++------ .../03/GHSA-hg36-jrxh-5x76/GHSA-hg36-jrxh-5x76.json | 4 +--- .../03/GHSA-j7p5-68rj-fv5p/GHSA-j7p5-68rj-fv5p.json | 4 +--- .../03/GHSA-p37w-7mr9-5x89/GHSA-p37w-7mr9-5x89.json | 8 ++------ .../03/GHSA-p49c-25rw-2mwc/GHSA-p49c-25rw-2mwc.json | 4 +--- .../03/GHSA-pw32-vrq6-9pw3/GHSA-pw32-vrq6-9pw3.json | 4 +--- .../03/GHSA-q5p3-3mpm-hppr/GHSA-q5p3-3mpm-hppr.json | 4 +--- .../03/GHSA-qh5q-q7cg-53wf/GHSA-qh5q-q7cg-53wf.json | 4 +--- .../03/GHSA-r298-475q-q8x5/GHSA-r298-475q-q8x5.json | 8 ++------ .../03/GHSA-r39c-fhw7-34q8/GHSA-r39c-fhw7-34q8.json | 8 ++------ .../03/GHSA-rf8f-5xcx-f48m/GHSA-rf8f-5xcx-f48m.json | 4 +--- .../03/GHSA-rhh2-3rph-r2f2/GHSA-rhh2-3rph-r2f2.json | 8 ++------ .../03/GHSA-v224-v254-78v2/GHSA-v224-v254-78v2.json | 4 +--- .../03/GHSA-v5p2-gphf-gp4g/GHSA-v5p2-gphf-gp4g.json | 4 +--- .../03/GHSA-v5vh-45jw-f3fq/GHSA-v5vh-45jw-f3fq.json | 8 ++------ .../03/GHSA-v8rf-mvwx-cx29/GHSA-v8rf-mvwx-cx29.json | 4 +--- .../03/GHSA-vcw5-gvqx-q633/GHSA-vcw5-gvqx-q633.json | 8 ++------ .../03/GHSA-wqqg-j8m9-9rcc/GHSA-wqqg-j8m9-9rcc.json | 4 +--- .../03/GHSA-x65p-q2x9-3hcj/GHSA-x65p-q2x9-3hcj.json | 4 +--- .../03/GHSA-xmfv-pp4r-x7rf/GHSA-xmfv-pp4r-x7rf.json | 8 ++------ .../04/GHSA-24r6-29j2-hrjv/GHSA-24r6-29j2-hrjv.json | 12 +++--------- .../04/GHSA-25pv-5r6h-55j6/GHSA-25pv-5r6h-55j6.json | 12 +++--------- .../04/GHSA-25r5-69f6-hgcg/GHSA-25r5-69f6-hgcg.json | 8 ++------ .../04/GHSA-26m2-987p-rmm4/GHSA-26m2-987p-rmm4.json | 4 +--- .../04/GHSA-28m9-8pxg-9chc/GHSA-28m9-8pxg-9chc.json | 12 +++--------- .../04/GHSA-2ffp-463q-9cmj/GHSA-2ffp-463q-9cmj.json | 12 +++--------- .../04/GHSA-2gq8-wr55-679w/GHSA-2gq8-wr55-679w.json | 12 +++--------- .../04/GHSA-2j8h-wx6g-vcxm/GHSA-2j8h-wx6g-vcxm.json | 12 +++--------- .../04/GHSA-2mg2-8p2q-47h9/GHSA-2mg2-8p2q-47h9.json | 12 +++--------- .../04/GHSA-2rmh-3vpc-xqrj/GHSA-2rmh-3vpc-xqrj.json | 12 +++--------- .../04/GHSA-2w42-wj39-8g7h/GHSA-2w42-wj39-8g7h.json | 12 +++--------- .../04/GHSA-2xfg-fq6q-8vvj/GHSA-2xfg-fq6q-8vvj.json | 12 +++--------- .../04/GHSA-337w-g464-gv6c/GHSA-337w-g464-gv6c.json | 8 ++------ .../04/GHSA-3987-59ph-j5q3/GHSA-3987-59ph-j5q3.json | 12 +++--------- .../04/GHSA-3qw8-5c34-wm4v/GHSA-3qw8-5c34-wm4v.json | 4 +--- .../04/GHSA-3rjv-37hg-wc7j/GHSA-3rjv-37hg-wc7j.json | 12 +++--------- .../04/GHSA-3v52-43ch-8qcg/GHSA-3v52-43ch-8qcg.json | 12 +++--------- .../04/GHSA-3xf3-5r39-357f/GHSA-3xf3-5r39-357f.json | 8 ++------ .../04/GHSA-45rv-3qw6-q326/GHSA-45rv-3qw6-q326.json | 12 +++--------- .../04/GHSA-485w-vv83-53fx/GHSA-485w-vv83-53fx.json | 12 +++--------- .../04/GHSA-48mx-245h-4c59/GHSA-48mx-245h-4c59.json | 12 +++--------- .../04/GHSA-4hfc-c3hg-m9pr/GHSA-4hfc-c3hg-m9pr.json | 4 +--- .../04/GHSA-4pcm-9qq9-65qc/GHSA-4pcm-9qq9-65qc.json | 12 +++--------- .../04/GHSA-4pq5-c54c-qgxf/GHSA-4pq5-c54c-qgxf.json | 8 ++------ .../04/GHSA-4w6m-4639-4jgr/GHSA-4w6m-4639-4jgr.json | 12 +++--------- .../04/GHSA-52p2-82rj-4r39/GHSA-52p2-82rj-4r39.json | 12 +++--------- .../04/GHSA-56qh-54mj-8vvx/GHSA-56qh-54mj-8vvx.json | 4 +--- .../04/GHSA-58wj-rx92-f9qx/GHSA-58wj-rx92-f9qx.json | 8 ++------ .../04/GHSA-5jwc-8539-rgx6/GHSA-5jwc-8539-rgx6.json | 12 +++--------- .../04/GHSA-5pwv-v67v-mf36/GHSA-5pwv-v67v-mf36.json | 12 +++--------- .../04/GHSA-665p-mhgh-xxcv/GHSA-665p-mhgh-xxcv.json | 12 +++--------- .../04/GHSA-68cc-r228-pw9r/GHSA-68cc-r228-pw9r.json | 12 +++--------- .../04/GHSA-6983-p8mq-gp2h/GHSA-6983-p8mq-gp2h.json | 12 +++--------- .../04/GHSA-69fh-f7xf-67w9/GHSA-69fh-f7xf-67w9.json | 12 +++--------- .../04/GHSA-6f4p-554q-j3hv/GHSA-6f4p-554q-j3hv.json | 8 ++------ .../04/GHSA-6h3c-53gf-6qc3/GHSA-6h3c-53gf-6qc3.json | 12 +++--------- .../04/GHSA-6j7v-q8xr-8rhx/GHSA-6j7v-q8xr-8rhx.json | 12 +++--------- .../04/GHSA-6r6c-fvxf-rg87/GHSA-6r6c-fvxf-rg87.json | 12 +++--------- .../04/GHSA-6wwj-crch-j32j/GHSA-6wwj-crch-j32j.json | 4 +--- .../04/GHSA-6xqc-7566-x2pq/GHSA-6xqc-7566-x2pq.json | 8 ++------ .../04/GHSA-73jr-7f3r-3wxh/GHSA-73jr-7f3r-3wxh.json | 12 +++--------- .../04/GHSA-77q3-769w-pr25/GHSA-77q3-769w-pr25.json | 12 +++--------- .../04/GHSA-78c2-6wr9-gc88/GHSA-78c2-6wr9-gc88.json | 12 +++--------- .../04/GHSA-7g5j-fq3f-v5q2/GHSA-7g5j-fq3f-v5q2.json | 12 +++--------- .../04/GHSA-7gpq-38wj-hv97/GHSA-7gpq-38wj-hv97.json | 4 +--- .../04/GHSA-7j9c-jj55-7hhm/GHSA-7j9c-jj55-7hhm.json | 12 +++--------- .../04/GHSA-82f3-pqxp-8f9v/GHSA-82f3-pqxp-8f9v.json | 12 +++--------- .../04/GHSA-88fx-2h2r-88cj/GHSA-88fx-2h2r-88cj.json | 4 +--- .../04/GHSA-8cv8-cw5j-h98f/GHSA-8cv8-cw5j-h98f.json | 12 +++--------- .../04/GHSA-8wr3-5grg-gmwh/GHSA-8wr3-5grg-gmwh.json | 12 +++--------- .../04/GHSA-96v5-vfm2-f5hh/GHSA-96v5-vfm2-f5hh.json | 4 +--- .../04/GHSA-977m-wr29-gj29/GHSA-977m-wr29-gj29.json | 12 +++--------- .../04/GHSA-985h-mmq2-8vhw/GHSA-985h-mmq2-8vhw.json | 12 +++--------- .../04/GHSA-99c8-6rr7-v77j/GHSA-99c8-6rr7-v77j.json | 12 +++--------- .../04/GHSA-9c8x-vv79-pccg/GHSA-9c8x-vv79-pccg.json | 12 +++--------- .../04/GHSA-9hpg-q52c-898c/GHSA-9hpg-q52c-898c.json | 12 +++--------- .../04/GHSA-9jv8-f4cc-g337/GHSA-9jv8-f4cc-g337.json | 12 +++--------- .../04/GHSA-9mpp-c9vq-p5h7/GHSA-9mpp-c9vq-p5h7.json | 12 +++--------- .../04/GHSA-9p4q-mfc9-w6m9/GHSA-9p4q-mfc9-w6m9.json | 12 +++--------- .../04/GHSA-c4qc-qrx8-9prp/GHSA-c4qc-qrx8-9prp.json | 12 +++--------- .../04/GHSA-c5pm-gfqm-wxp7/GHSA-c5pm-gfqm-wxp7.json | 12 +++--------- .../04/GHSA-c9gg-qqjg-6v7f/GHSA-c9gg-qqjg-6v7f.json | 12 +++--------- .../04/GHSA-cf29-9472-gh5p/GHSA-cf29-9472-gh5p.json | 12 +++--------- .../04/GHSA-cf7g-gj99-69w3/GHSA-cf7g-gj99-69w3.json | 4 +--- .../04/GHSA-cghg-rv7h-488q/GHSA-cghg-rv7h-488q.json | 12 +++--------- .../04/GHSA-cm4m-9c34-c8p6/GHSA-cm4m-9c34-c8p6.json | 12 +++--------- .../04/GHSA-cmmr-4624-8pv4/GHSA-cmmr-4624-8pv4.json | 12 +++--------- .../04/GHSA-cvw6-7vx8-mh9x/GHSA-cvw6-7vx8-mh9x.json | 8 ++------ .../04/GHSA-f54q-8494-3hvh/GHSA-f54q-8494-3hvh.json | 12 +++--------- .../04/GHSA-f7cf-36r8-52q2/GHSA-f7cf-36r8-52q2.json | 12 +++--------- .../04/GHSA-fc9j-q76r-j649/GHSA-fc9j-q76r-j649.json | 12 +++--------- .../04/GHSA-ffjf-v6q2-h2mv/GHSA-ffjf-v6q2-h2mv.json | 12 +++--------- .../04/GHSA-fpcj-q3j2-7545/GHSA-fpcj-q3j2-7545.json | 12 +++--------- .../04/GHSA-fwxc-qvhc-7v9m/GHSA-fwxc-qvhc-7v9m.json | 12 +++--------- .../04/GHSA-fxx6-22cm-3977/GHSA-fxx6-22cm-3977.json | 4 +--- .../04/GHSA-g3fc-j6w6-4h4p/GHSA-g3fc-j6w6-4h4p.json | 4 +--- .../04/GHSA-gghx-4gcj-rpw8/GHSA-gghx-4gcj-rpw8.json | 12 +++--------- .../04/GHSA-gh92-r6m8-gq4c/GHSA-gh92-r6m8-gq4c.json | 12 +++--------- .../04/GHSA-gm9r-p48q-qmx6/GHSA-gm9r-p48q-qmx6.json | 12 +++--------- .../04/GHSA-gphm-f2g3-9rr5/GHSA-gphm-f2g3-9rr5.json | 12 +++--------- .../04/GHSA-gpr4-gfq8-c66q/GHSA-gpr4-gfq8-c66q.json | 8 ++------ .../04/GHSA-gx76-xx4m-wqw4/GHSA-gx76-xx4m-wqw4.json | 12 +++--------- .../04/GHSA-h362-xvf2-9x75/GHSA-h362-xvf2-9x75.json | 12 +++--------- .../04/GHSA-h3fp-c6fr-mp9h/GHSA-h3fp-c6fr-mp9h.json | 12 +++--------- .../04/GHSA-h5jp-6w68-72m2/GHSA-h5jp-6w68-72m2.json | 8 ++------ .../04/GHSA-h6mg-286x-2ggg/GHSA-h6mg-286x-2ggg.json | 8 ++------ .../04/GHSA-h83g-mghp-3gg7/GHSA-h83g-mghp-3gg7.json | 12 +++--------- .../04/GHSA-hh83-pff3-px95/GHSA-hh83-pff3-px95.json | 12 +++--------- .../04/GHSA-hhv3-85xh-f65h/GHSA-hhv3-85xh-f65h.json | 12 +++--------- .../04/GHSA-hqf4-9x6j-98g9/GHSA-hqf4-9x6j-98g9.json | 12 +++--------- .../04/GHSA-hv99-5fhv-j4mj/GHSA-hv99-5fhv-j4mj.json | 12 +++--------- .../04/GHSA-hvq3-qm62-8ff5/GHSA-hvq3-qm62-8ff5.json | 12 +++--------- .../04/GHSA-hx6m-rxfx-9j6c/GHSA-hx6m-rxfx-9j6c.json | 12 +++--------- .../04/GHSA-j5xj-256c-jv3v/GHSA-j5xj-256c-jv3v.json | 12 +++--------- .../04/GHSA-j74f-5rh4-57cv/GHSA-j74f-5rh4-57cv.json | 12 +++--------- .../04/GHSA-j7xp-993g-v2pc/GHSA-j7xp-993g-v2pc.json | 12 +++--------- .../04/GHSA-jc43-58xv-97mp/GHSA-jc43-58xv-97mp.json | 12 +++--------- .../04/GHSA-jhvw-wg26-wj9c/GHSA-jhvw-wg26-wj9c.json | 12 +++--------- .../04/GHSA-jr23-46j8-97mr/GHSA-jr23-46j8-97mr.json | 8 ++------ .../04/GHSA-m2cw-8f75-qf8v/GHSA-m2cw-8f75-qf8v.json | 12 +++--------- .../04/GHSA-m5jq-cp4v-64qc/GHSA-m5jq-cp4v-64qc.json | 12 +++--------- .../04/GHSA-m69c-hmx8-c8ph/GHSA-m69c-hmx8-c8ph.json | 12 +++--------- .../04/GHSA-m7mj-vcp8-4rpq/GHSA-m7mj-vcp8-4rpq.json | 12 +++--------- .../04/GHSA-m85g-37m6-fpww/GHSA-m85g-37m6-fpww.json | 12 +++--------- .../04/GHSA-mfrx-mc2c-9g9w/GHSA-mfrx-mc2c-9g9w.json | 12 +++--------- .../04/GHSA-mmrv-3fq5-g8jf/GHSA-mmrv-3fq5-g8jf.json | 12 +++--------- .../04/GHSA-mqgq-47w7-8ccc/GHSA-mqgq-47w7-8ccc.json | 12 +++--------- .../04/GHSA-mxfj-2pw5-7crq/GHSA-mxfj-2pw5-7crq.json | 12 +++--------- .../04/GHSA-p3qf-8c2m-c92q/GHSA-p3qf-8c2m-c92q.json | 12 +++--------- .../04/GHSA-p6c2-5pjm-qmjv/GHSA-p6c2-5pjm-qmjv.json | 12 +++--------- .../04/GHSA-p854-gmj6-9jfw/GHSA-p854-gmj6-9jfw.json | 12 +++--------- .../04/GHSA-p9p4-x3gf-gjm8/GHSA-p9p4-x3gf-gjm8.json | 4 +--- .../04/GHSA-pfr8-644q-f99g/GHSA-pfr8-644q-f99g.json | 12 +++--------- .../04/GHSA-pgpv-rcv8-q82m/GHSA-pgpv-rcv8-q82m.json | 12 +++--------- .../04/GHSA-pvc7-5x99-c9mm/GHSA-pvc7-5x99-c9mm.json | 12 +++--------- .../04/GHSA-pxcf-v9c2-vw3r/GHSA-pxcf-v9c2-vw3r.json | 12 +++--------- .../04/GHSA-pxpj-c4wv-6w3x/GHSA-pxpj-c4wv-6w3x.json | 12 +++--------- .../04/GHSA-r33h-6mqf-5rp3/GHSA-r33h-6mqf-5rp3.json | 12 +++--------- .../04/GHSA-r4c5-4hcj-q3cc/GHSA-r4c5-4hcj-q3cc.json | 12 +++--------- .../04/GHSA-rg52-qjhr-v639/GHSA-rg52-qjhr-v639.json | 8 ++------ .../04/GHSA-rg84-mjm4-xc43/GHSA-rg84-mjm4-xc43.json | 12 +++--------- .../04/GHSA-rhxq-hxv2-28cf/GHSA-rhxq-hxv2-28cf.json | 4 +--- .../04/GHSA-rpxp-9755-926w/GHSA-rpxp-9755-926w.json | 12 +++--------- .../04/GHSA-rv5h-jg6x-f3vp/GHSA-rv5h-jg6x-f3vp.json | 8 ++------ .../04/GHSA-rx3c-x33m-733h/GHSA-rx3c-x33m-733h.json | 12 +++--------- .../04/GHSA-rxr9-jwx6-w6jq/GHSA-rxr9-jwx6-w6jq.json | 12 +++--------- .../04/GHSA-rxxv-f2jp-v9vp/GHSA-rxxv-f2jp-v9vp.json | 12 +++--------- .../04/GHSA-v25j-6rjr-73r2/GHSA-v25j-6rjr-73r2.json | 12 +++--------- .../04/GHSA-v2g6-64p5-pq6w/GHSA-v2g6-64p5-pq6w.json | 12 +++--------- .../04/GHSA-v3p7-33wf-f77j/GHSA-v3p7-33wf-f77j.json | 12 +++--------- .../04/GHSA-v8cq-jwh7-j9xh/GHSA-v8cq-jwh7-j9xh.json | 4 +--- .../04/GHSA-vf9c-hw5f-pr3r/GHSA-vf9c-hw5f-pr3r.json | 12 +++--------- .../04/GHSA-vq3q-gw2w-fwwv/GHSA-vq3q-gw2w-fwwv.json | 12 +++--------- .../04/GHSA-vvh2-vwv7-8grx/GHSA-vvh2-vwv7-8grx.json | 12 +++--------- .../04/GHSA-vxp6-2m83-3w8p/GHSA-vxp6-2m83-3w8p.json | 12 +++--------- .../04/GHSA-w2fq-mj73-7568/GHSA-w2fq-mj73-7568.json | 12 +++--------- .../04/GHSA-w3g2-3297-gcrq/GHSA-w3g2-3297-gcrq.json | 12 +++--------- .../04/GHSA-wc6x-q3v9-6hjf/GHSA-wc6x-q3v9-6hjf.json | 12 +++--------- .../04/GHSA-wf72-vr87-m228/GHSA-wf72-vr87-m228.json | 12 +++--------- .../04/GHSA-wmhx-3hr4-6h39/GHSA-wmhx-3hr4-6h39.json | 12 +++--------- .../04/GHSA-wr34-64f9-xpxq/GHSA-wr34-64f9-xpxq.json | 8 ++------ .../04/GHSA-x4xf-2prm-xx25/GHSA-x4xf-2prm-xx25.json | 12 +++--------- .../04/GHSA-x5rf-j496-m69m/GHSA-x5rf-j496-m69m.json | 12 +++--------- .../04/GHSA-x635-xvwm-g4ww/GHSA-x635-xvwm-g4ww.json | 12 +++--------- .../04/GHSA-xc28-23vr-vh39/GHSA-xc28-23vr-vh39.json | 4 +--- .../04/GHSA-xfg8-c4cc-3fg2/GHSA-xfg8-c4cc-3fg2.json | 12 +++--------- .../04/GHSA-xfmh-wgwr-479f/GHSA-xfmh-wgwr-479f.json | 12 +++--------- .../04/GHSA-xhq3-46hw-hr5h/GHSA-xhq3-46hw-hr5h.json | 12 +++--------- .../04/GHSA-xpxm-j39p-5vcw/GHSA-xpxm-j39p-5vcw.json | 12 +++--------- .../04/GHSA-xq2m-9f8c-rr6w/GHSA-xq2m-9f8c-rr6w.json | 12 +++--------- .../04/GHSA-xxfm-q6cq-gcwc/GHSA-xxfm-q6cq-gcwc.json | 12 +++--------- .../05/GHSA-23cf-7m42-487j/GHSA-23cf-7m42-487j.json | 8 ++------ .../05/GHSA-23hx-gmq6-vwxq/GHSA-23hx-gmq6-vwxq.json | 8 ++------ .../05/GHSA-23hx-rv96-mjqx/GHSA-23hx-rv96-mjqx.json | 8 ++------ .../05/GHSA-256m-p2gv-r882/GHSA-256m-p2gv-r882.json | 8 ++------ .../05/GHSA-25hw-5mq3-gfwx/GHSA-25hw-5mq3-gfwx.json | 8 ++------ .../05/GHSA-26hg-qjgg-2868/GHSA-26hg-qjgg-2868.json | 8 ++------ .../05/GHSA-26r7-84w5-c8mf/GHSA-26r7-84w5-c8mf.json | 8 ++------ .../05/GHSA-26rg-mq58-rxvm/GHSA-26rg-mq58-rxvm.json | 8 ++------ .../05/GHSA-2795-x35v-6hgh/GHSA-2795-x35v-6hgh.json | 8 ++------ .../05/GHSA-28x2-h22v-2jv6/GHSA-28x2-h22v-2jv6.json | 8 ++------ .../05/GHSA-29jx-h9vr-rw83/GHSA-29jx-h9vr-rw83.json | 8 ++------ .../05/GHSA-2cq5-rh28-8vq5/GHSA-2cq5-rh28-8vq5.json | 8 ++------ .../05/GHSA-2cqw-h63q-28xj/GHSA-2cqw-h63q-28xj.json | 8 ++------ .../05/GHSA-2g4f-r7cc-55q9/GHSA-2g4f-r7cc-55q9.json | 8 ++------ .../05/GHSA-2g89-jxmp-m4m9/GHSA-2g89-jxmp-m4m9.json | 8 ++------ .../05/GHSA-2hxg-rh2v-hj3h/GHSA-2hxg-rh2v-hj3h.json | 8 ++------ .../05/GHSA-2jg5-5mqp-735q/GHSA-2jg5-5mqp-735q.json | 8 ++------ .../05/GHSA-2jrp-2x8m-mgrv/GHSA-2jrp-2x8m-mgrv.json | 8 ++------ .../05/GHSA-2jvv-ppmq-fvgf/GHSA-2jvv-ppmq-fvgf.json | 8 ++------ .../05/GHSA-2mrh-8f77-q7p2/GHSA-2mrh-8f77-q7p2.json | 8 ++------ .../05/GHSA-2q4w-gp3h-x66r/GHSA-2q4w-gp3h-x66r.json | 8 ++------ .../05/GHSA-2qvv-wf53-7c44/GHSA-2qvv-wf53-7c44.json | 8 ++------ .../05/GHSA-2rcf-f7rp-mvx7/GHSA-2rcf-f7rp-mvx7.json | 8 ++------ .../05/GHSA-2v2m-677r-5j24/GHSA-2v2m-677r-5j24.json | 8 ++------ .../05/GHSA-2v93-8mhc-6mf8/GHSA-2v93-8mhc-6mf8.json | 8 ++------ .../05/GHSA-2v9x-c45w-29qx/GHSA-2v9x-c45w-29qx.json | 8 ++------ .../05/GHSA-2vgw-q9j2-j47q/GHSA-2vgw-q9j2-j47q.json | 8 ++------ .../05/GHSA-2vhx-gg9g-r3h4/GHSA-2vhx-gg9g-r3h4.json | 8 ++------ .../05/GHSA-2xhv-xg6q-g23w/GHSA-2xhv-xg6q-g23w.json | 8 ++------ .../05/GHSA-2xrp-fqg8-p623/GHSA-2xrp-fqg8-p623.json | 8 ++------ .../05/GHSA-2xwv-qmvc-f3g6/GHSA-2xwv-qmvc-f3g6.json | 12 +++--------- .../05/GHSA-324v-4jgg-3xh9/GHSA-324v-4jgg-3xh9.json | 8 ++------ .../05/GHSA-3255-v6mp-wmgf/GHSA-3255-v6mp-wmgf.json | 8 ++------ .../05/GHSA-32m5-2pgc-wc86/GHSA-32m5-2pgc-wc86.json | 8 ++------ .../05/GHSA-32xw-6g8c-rxjj/GHSA-32xw-6g8c-rxjj.json | 8 ++------ .../05/GHSA-34f3-925w-mxhg/GHSA-34f3-925w-mxhg.json | 8 ++------ .../05/GHSA-35ch-vqm2-376r/GHSA-35ch-vqm2-376r.json | 8 ++------ .../05/GHSA-35q9-m24r-89m2/GHSA-35q9-m24r-89m2.json | 8 ++------ .../05/GHSA-35vj-pjgj-gmmg/GHSA-35vj-pjgj-gmmg.json | 8 ++------ .../05/GHSA-363c-g524-mqxp/GHSA-363c-g524-mqxp.json | 8 ++------ .../05/GHSA-36cv-vc44-8fvg/GHSA-36cv-vc44-8fvg.json | 8 ++------ .../05/GHSA-36ww-7vxr-9ggq/GHSA-36ww-7vxr-9ggq.json | 8 ++------ .../05/GHSA-3772-r33f-jvrg/GHSA-3772-r33f-jvrg.json | 8 ++------ .../05/GHSA-37cg-6ww4-3f68/GHSA-37cg-6ww4-3f68.json | 8 ++------ .../05/GHSA-37q6-vw96-q6q8/GHSA-37q6-vw96-q6q8.json | 8 ++------ .../05/GHSA-37vq-vv4q-ww53/GHSA-37vq-vv4q-ww53.json | 8 ++------ .../05/GHSA-37xm-62j3-375v/GHSA-37xm-62j3-375v.json | 8 ++------ .../05/GHSA-37xw-27xp-5499/GHSA-37xw-27xp-5499.json | 8 ++------ .../05/GHSA-3896-fhmw-qp2v/GHSA-3896-fhmw-qp2v.json | 8 ++------ .../05/GHSA-38jp-4v3p-cc3q/GHSA-38jp-4v3p-cc3q.json | 8 ++------ .../05/GHSA-38q3-wx89-qvg5/GHSA-38q3-wx89-qvg5.json | 8 ++------ .../05/GHSA-393j-8xcq-h729/GHSA-393j-8xcq-h729.json | 8 ++------ .../05/GHSA-3f89-7rr5-pcr2/GHSA-3f89-7rr5-pcr2.json | 8 ++------ .../05/GHSA-3fpm-hp83-g34v/GHSA-3fpm-hp83-g34v.json | 8 ++------ .../05/GHSA-3g7c-253j-whp9/GHSA-3g7c-253j-whp9.json | 8 ++------ .../05/GHSA-3h26-8wfg-f6vh/GHSA-3h26-8wfg-f6vh.json | 8 ++------ .../05/GHSA-3j89-v6qj-mgf2/GHSA-3j89-v6qj-mgf2.json | 12 +++--------- .../05/GHSA-3jjq-5484-vh7r/GHSA-3jjq-5484-vh7r.json | 12 +++--------- .../05/GHSA-3jr7-57xj-6hhm/GHSA-3jr7-57xj-6hhm.json | 8 ++------ .../05/GHSA-3mhr-8gcj-264p/GHSA-3mhr-8gcj-264p.json | 8 ++------ .../05/GHSA-3mpv-3cfr-mgjj/GHSA-3mpv-3cfr-mgjj.json | 12 +++--------- .../05/GHSA-3mr8-6hjm-446f/GHSA-3mr8-6hjm-446f.json | 8 ++------ .../05/GHSA-3mwp-vjrv-6crj/GHSA-3mwp-vjrv-6crj.json | 8 ++------ .../05/GHSA-3pjh-8rj7-xm2h/GHSA-3pjh-8rj7-xm2h.json | 8 ++------ .../05/GHSA-3qff-43xr-cvvj/GHSA-3qff-43xr-cvvj.json | 8 ++------ .../05/GHSA-3r7g-xhpj-j87w/GHSA-3r7g-xhpj-j87w.json | 8 ++------ .../05/GHSA-3rqh-g6r9-mr2r/GHSA-3rqh-g6r9-mr2r.json | 8 ++------ .../05/GHSA-3vqf-m3q8-grf7/GHSA-3vqf-m3q8-grf7.json | 8 ++------ .../05/GHSA-3vvv-pvc3-2gx5/GHSA-3vvv-pvc3-2gx5.json | 8 ++------ .../05/GHSA-3wm3-m3jr-6jpv/GHSA-3wm3-m3jr-6jpv.json | 8 ++------ .../05/GHSA-3wq6-8f7g-92vm/GHSA-3wq6-8f7g-92vm.json | 8 ++------ .../05/GHSA-3xx7-wxpj-hg7p/GHSA-3xx7-wxpj-hg7p.json | 8 ++------ .../05/GHSA-423g-qv8g-mgcc/GHSA-423g-qv8g-mgcc.json | 8 ++------ .../05/GHSA-427h-c47c-jgj4/GHSA-427h-c47c-jgj4.json | 8 ++------ .../05/GHSA-42p2-4vv3-9qv4/GHSA-42p2-4vv3-9qv4.json | 4 +--- .../05/GHSA-4328-wgfc-675c/GHSA-4328-wgfc-675c.json | 8 ++------ .../05/GHSA-43c2-x3q5-72p4/GHSA-43c2-x3q5-72p4.json | 8 ++------ .../05/GHSA-446c-h2fq-7hw2/GHSA-446c-h2fq-7hw2.json | 8 ++------ .../05/GHSA-44f9-r7rv-2634/GHSA-44f9-r7rv-2634.json | 8 ++------ .../05/GHSA-44vj-36hg-g8rr/GHSA-44vj-36hg-g8rr.json | 8 ++------ .../05/GHSA-45c8-47gc-rqw4/GHSA-45c8-47gc-rqw4.json | 12 +++--------- .../05/GHSA-45rr-9gf8-j69p/GHSA-45rr-9gf8-j69p.json | 8 ++------ .../05/GHSA-45v4-crhq-rhhc/GHSA-45v4-crhq-rhhc.json | 8 ++------ .../05/GHSA-45wx-vwj8-hhm4/GHSA-45wx-vwj8-hhm4.json | 8 ++------ .../05/GHSA-4684-g96f-9q97/GHSA-4684-g96f-9q97.json | 8 ++------ .../05/GHSA-473q-vgvv-5537/GHSA-473q-vgvv-5537.json | 8 ++------ .../05/GHSA-474h-r3hr-mrpj/GHSA-474h-r3hr-mrpj.json | 8 ++------ .../05/GHSA-47g9-557v-5c66/GHSA-47g9-557v-5c66.json | 8 ++------ .../05/GHSA-48fw-3qmc-rmp7/GHSA-48fw-3qmc-rmp7.json | 8 ++------ .../05/GHSA-497h-4hjg-c662/GHSA-497h-4hjg-c662.json | 8 ++------ .../05/GHSA-49hv-qhwg-6w6c/GHSA-49hv-qhwg-6w6c.json | 8 ++------ .../05/GHSA-49w9-82cj-xr48/GHSA-49w9-82cj-xr48.json | 8 ++------ .../05/GHSA-4g47-3fx3-5q52/GHSA-4g47-3fx3-5q52.json | 8 ++------ .../05/GHSA-4hgv-m59w-35vw/GHSA-4hgv-m59w-35vw.json | 8 ++------ .../05/GHSA-4j5w-hmf4-595g/GHSA-4j5w-hmf4-595g.json | 8 ++------ .../05/GHSA-4j8j-wj7m-vcx5/GHSA-4j8j-wj7m-vcx5.json | 8 ++------ .../05/GHSA-4m4f-3m29-78r8/GHSA-4m4f-3m29-78r8.json | 8 ++------ .../05/GHSA-4mmh-fcmv-q64r/GHSA-4mmh-fcmv-q64r.json | 8 ++------ .../05/GHSA-4p34-5qf5-wx5v/GHSA-4p34-5qf5-wx5v.json | 8 ++------ .../05/GHSA-4r6g-jg94-h27c/GHSA-4r6g-jg94-h27c.json | 12 +++--------- .../05/GHSA-4rc3-796r-hwf9/GHSA-4rc3-796r-hwf9.json | 8 ++------ .../05/GHSA-4rr2-x8jq-gqq7/GHSA-4rr2-x8jq-gqq7.json | 8 ++------ .../05/GHSA-4w6w-m7p6-hrwf/GHSA-4w6w-m7p6-hrwf.json | 8 ++------ .../05/GHSA-4wfq-6m2h-348v/GHSA-4wfq-6m2h-348v.json | 8 ++------ .../05/GHSA-4x7r-2g5v-6xmq/GHSA-4x7r-2g5v-6xmq.json | 8 ++------ .../05/GHSA-533p-xf32-32p2/GHSA-533p-xf32-32p2.json | 12 +++--------- .../05/GHSA-53cj-vhvg-mmqf/GHSA-53cj-vhvg-mmqf.json | 8 ++------ .../05/GHSA-53rf-x4vp-w2vq/GHSA-53rf-x4vp-w2vq.json | 4 +--- .../05/GHSA-53xh-4grp-ggrw/GHSA-53xh-4grp-ggrw.json | 8 ++------ .../05/GHSA-54j5-rqvj-pvhx/GHSA-54j5-rqvj-pvhx.json | 8 ++------ .../05/GHSA-54xg-w6ch-fmhh/GHSA-54xg-w6ch-fmhh.json | 8 ++------ .../05/GHSA-5537-hr6c-2jjc/GHSA-5537-hr6c-2jjc.json | 8 ++------ .../05/GHSA-555x-c8f3-84gj/GHSA-555x-c8f3-84gj.json | 8 ++------ .../05/GHSA-56fm-6jmc-6mvp/GHSA-56fm-6jmc-6mvp.json | 8 ++------ .../05/GHSA-56q5-36x8-qq3f/GHSA-56q5-36x8-qq3f.json | 8 ++------ .../05/GHSA-583r-j6r6-x57h/GHSA-583r-j6r6-x57h.json | 4 +--- .../05/GHSA-58pp-88x2-wf7f/GHSA-58pp-88x2-wf7f.json | 8 ++------ .../05/GHSA-59vv-g2mq-64c5/GHSA-59vv-g2mq-64c5.json | 8 ++------ .../05/GHSA-5c2c-2562-gwp9/GHSA-5c2c-2562-gwp9.json | 8 ++------ .../05/GHSA-5cx5-fcx6-4j7m/GHSA-5cx5-fcx6-4j7m.json | 8 ++------ .../05/GHSA-5fx7-6vcj-vqfc/GHSA-5fx7-6vcj-vqfc.json | 8 ++------ .../05/GHSA-5g2x-gm3x-pm24/GHSA-5g2x-gm3x-pm24.json | 8 ++------ .../05/GHSA-5h57-vhr8-8f95/GHSA-5h57-vhr8-8f95.json | 8 ++------ .../05/GHSA-5m57-mhq7-6vhf/GHSA-5m57-mhq7-6vhf.json | 8 ++------ .../05/GHSA-5m5r-ch84-vh95/GHSA-5m5r-ch84-vh95.json | 12 +++--------- .../05/GHSA-5mr8-rv5h-p6vv/GHSA-5mr8-rv5h-p6vv.json | 12 +++--------- .../05/GHSA-5rj7-m957-87g6/GHSA-5rj7-m957-87g6.json | 8 ++------ .../05/GHSA-5v7h-9v5g-w2x6/GHSA-5v7h-9v5g-w2x6.json | 8 ++------ .../05/GHSA-5v7p-whcg-3j32/GHSA-5v7p-whcg-3j32.json | 8 ++------ .../05/GHSA-5wh3-x3rh-6qff/GHSA-5wh3-x3rh-6qff.json | 8 ++------ .../05/GHSA-5x29-2xgq-48fc/GHSA-5x29-2xgq-48fc.json | 8 ++------ .../05/GHSA-5x7q-6f7m-fc5c/GHSA-5x7q-6f7m-fc5c.json | 8 ++------ .../05/GHSA-5xj2-h84j-jqmg/GHSA-5xj2-h84j-jqmg.json | 8 ++------ .../05/GHSA-5xx2-xmgx-crvj/GHSA-5xx2-xmgx-crvj.json | 8 ++------ .../05/GHSA-622c-r8r9-89jj/GHSA-622c-r8r9-89jj.json | 12 +++--------- .../05/GHSA-625c-v8wh-vppg/GHSA-625c-v8wh-vppg.json | 8 ++------ .../05/GHSA-6338-48mj-7qpp/GHSA-6338-48mj-7qpp.json | 8 ++------ .../05/GHSA-6343-5v5c-grr3/GHSA-6343-5v5c-grr3.json | 8 ++------ .../05/GHSA-6367-c2hm-87fh/GHSA-6367-c2hm-87fh.json | 8 ++------ .../05/GHSA-636w-6mqg-2rmv/GHSA-636w-6mqg-2rmv.json | 8 ++------ .../05/GHSA-63m9-h3h6-xrqx/GHSA-63m9-h3h6-xrqx.json | 12 +++--------- .../05/GHSA-63p4-w7wr-6hxg/GHSA-63p4-w7wr-6hxg.json | 8 ++------ .../05/GHSA-63qj-x5v8-6jj4/GHSA-63qj-x5v8-6jj4.json | 12 +++--------- .../05/GHSA-63vh-chmr-pr22/GHSA-63vh-chmr-pr22.json | 8 ++------ .../05/GHSA-6489-mq5r-6f8p/GHSA-6489-mq5r-6f8p.json | 8 ++------ .../05/GHSA-6496-p2qf-5gj8/GHSA-6496-p2qf-5gj8.json | 8 ++------ .../05/GHSA-64j2-vfrj-6r28/GHSA-64j2-vfrj-6r28.json | 8 ++------ .../05/GHSA-64m3-gx4j-jq98/GHSA-64m3-gx4j-jq98.json | 8 ++------ .../05/GHSA-6676-52pp-h5fg/GHSA-6676-52pp-h5fg.json | 4 +--- .../05/GHSA-66h6-4ppg-82p8/GHSA-66h6-4ppg-82p8.json | 8 ++------ .../05/GHSA-66j6-79mp-77p6/GHSA-66j6-79mp-77p6.json | 8 ++------ .../05/GHSA-66pq-mwg2-mc6q/GHSA-66pq-mwg2-mc6q.json | 8 ++------ .../05/GHSA-66q5-93c3-xq5w/GHSA-66q5-93c3-xq5w.json | 8 ++------ .../05/GHSA-6732-rrr9-72hv/GHSA-6732-rrr9-72hv.json | 8 ++------ .../05/GHSA-67r3-w458-w4x6/GHSA-67r3-w458-w4x6.json | 8 ++------ .../05/GHSA-685v-qm2g-x563/GHSA-685v-qm2g-x563.json | 8 ++------ .../05/GHSA-6927-m748-j36j/GHSA-6927-m748-j36j.json | 8 ++------ .../05/GHSA-697w-4mf4-ghh4/GHSA-697w-4mf4-ghh4.json | 8 ++------ .../05/GHSA-6995-mfw9-q3hp/GHSA-6995-mfw9-q3hp.json | 12 +++--------- .../05/GHSA-6c67-cppc-86v4/GHSA-6c67-cppc-86v4.json | 8 ++------ .../05/GHSA-6fm5-8wjh-r65x/GHSA-6fm5-8wjh-r65x.json | 8 ++------ .../05/GHSA-6g37-4jmq-qq2x/GHSA-6g37-4jmq-qq2x.json | 8 ++------ .../05/GHSA-6gcw-7qx9-8vhw/GHSA-6gcw-7qx9-8vhw.json | 8 ++------ .../05/GHSA-6gf9-qq8q-552j/GHSA-6gf9-qq8q-552j.json | 8 ++------ .../05/GHSA-6hhm-232w-8g2c/GHSA-6hhm-232w-8g2c.json | 4 +--- .../05/GHSA-6hw7-fjvh-gwx7/GHSA-6hw7-fjvh-gwx7.json | 8 ++------ .../05/GHSA-6j7q-rmrp-5g6f/GHSA-6j7q-rmrp-5g6f.json | 8 ++------ .../05/GHSA-6m4v-96f3-85ph/GHSA-6m4v-96f3-85ph.json | 8 ++------ .../05/GHSA-6mh7-r2rw-gp32/GHSA-6mh7-r2rw-gp32.json | 8 ++------ .../05/GHSA-6mpj-7w8c-wv4j/GHSA-6mpj-7w8c-wv4j.json | 8 ++------ .../05/GHSA-6mvg-7752-5v6p/GHSA-6mvg-7752-5v6p.json | 8 ++------ .../05/GHSA-6q5r-2gfw-g2w4/GHSA-6q5r-2gfw-g2w4.json | 8 ++------ .../05/GHSA-6r38-jm65-2wmh/GHSA-6r38-jm65-2wmh.json | 12 +++--------- .../05/GHSA-6rmx-66m4-ch79/GHSA-6rmx-66m4-ch79.json | 12 +++--------- .../05/GHSA-6rxh-rgmc-47h8/GHSA-6rxh-rgmc-47h8.json | 8 ++------ .../05/GHSA-6v6x-q433-6x54/GHSA-6v6x-q433-6x54.json | 8 ++------ .../05/GHSA-6v85-364q-mgv8/GHSA-6v85-364q-mgv8.json | 4 +--- .../05/GHSA-6v93-795h-j436/GHSA-6v93-795h-j436.json | 8 ++------ .../05/GHSA-6wfj-pw33-8cr3/GHSA-6wfj-pw33-8cr3.json | 4 +--- .../05/GHSA-6wfr-fw6j-w5x5/GHSA-6wfr-fw6j-w5x5.json | 8 ++------ .../05/GHSA-6xwv-85gf-vgjm/GHSA-6xwv-85gf-vgjm.json | 8 ++------ .../05/GHSA-72m9-347j-m934/GHSA-72m9-347j-m934.json | 8 ++------ .../05/GHSA-72qv-726v-82fq/GHSA-72qv-726v-82fq.json | 8 ++------ .../05/GHSA-7374-8xfw-v758/GHSA-7374-8xfw-v758.json | 8 ++------ .../05/GHSA-7456-9w6m-v94r/GHSA-7456-9w6m-v94r.json | 12 +++--------- .../05/GHSA-74m4-hfvx-8p4m/GHSA-74m4-hfvx-8p4m.json | 12 +++--------- .../05/GHSA-74pw-fvg5-f337/GHSA-74pw-fvg5-f337.json | 8 ++------ .../05/GHSA-7534-f3f3-w6x8/GHSA-7534-f3f3-w6x8.json | 12 +++--------- .../05/GHSA-77f7-r2cc-pcqm/GHSA-77f7-r2cc-pcqm.json | 8 ++------ .../05/GHSA-77hx-2hff-m8j5/GHSA-77hx-2hff-m8j5.json | 12 +++--------- .../05/GHSA-77mv-h93c-9885/GHSA-77mv-h93c-9885.json | 12 +++--------- .../05/GHSA-784w-4q35-257w/GHSA-784w-4q35-257w.json | 8 ++------ .../05/GHSA-7936-5qr9-9pvr/GHSA-7936-5qr9-9pvr.json | 8 ++------ .../05/GHSA-796m-4rjr-9mvw/GHSA-796m-4rjr-9mvw.json | 8 ++------ .../05/GHSA-79rf-9vhj-jq9w/GHSA-79rf-9vhj-jq9w.json | 8 ++------ .../05/GHSA-79rv-cc85-5qhh/GHSA-79rv-cc85-5qhh.json | 8 ++------ .../05/GHSA-7cfx-r8g4-h73j/GHSA-7cfx-r8g4-h73j.json | 8 ++------ .../05/GHSA-7f28-cgvx-h2cg/GHSA-7f28-cgvx-h2cg.json | 8 ++------ .../05/GHSA-7f68-748r-v7xr/GHSA-7f68-748r-v7xr.json | 8 ++------ .../05/GHSA-7fcf-g7ph-3mf3/GHSA-7fcf-g7ph-3mf3.json | 8 ++------ .../05/GHSA-7g47-vmvw-jcc2/GHSA-7g47-vmvw-jcc2.json | 8 ++------ .../05/GHSA-7ghp-chhf-mv7g/GHSA-7ghp-chhf-mv7g.json | 8 ++------ .../05/GHSA-7gxp-4wg5-p23f/GHSA-7gxp-4wg5-p23f.json | 8 ++------ .../05/GHSA-7jmj-qp68-j8hc/GHSA-7jmj-qp68-j8hc.json | 12 +++--------- .../05/GHSA-7m7p-mm4f-j6g6/GHSA-7m7p-mm4f-j6g6.json | 8 ++------ .../05/GHSA-7p3q-gmw8-3xm9/GHSA-7p3q-gmw8-3xm9.json | 8 ++------ .../05/GHSA-7q5m-m6v8-m536/GHSA-7q5m-m6v8-m536.json | 8 ++------ .../05/GHSA-7qj9-8gv5-jxwm/GHSA-7qj9-8gv5-jxwm.json | 8 ++------ .../05/GHSA-7vpr-695p-h2h2/GHSA-7vpr-695p-h2h2.json | 8 ++------ .../05/GHSA-7vq3-23jw-jjmm/GHSA-7vq3-23jw-jjmm.json | 8 ++------ .../05/GHSA-7w35-wqxc-h6cq/GHSA-7w35-wqxc-h6cq.json | 8 ++------ .../05/GHSA-7wgm-v99f-436j/GHSA-7wgm-v99f-436j.json | 8 ++------ .../05/GHSA-7xq7-m3j7-j4px/GHSA-7xq7-m3j7-j4px.json | 12 +++--------- .../05/GHSA-82gg-xqxc-f2wx/GHSA-82gg-xqxc-f2wx.json | 12 +++--------- .../05/GHSA-84vg-rpfp-p469/GHSA-84vg-rpfp-p469.json | 8 ++------ .../05/GHSA-86w2-3m2v-xrcg/GHSA-86w2-3m2v-xrcg.json | 8 ++------ .../05/GHSA-87f8-vqm8-p8wc/GHSA-87f8-vqm8-p8wc.json | 8 ++------ .../05/GHSA-87vv-9cj6-q2hc/GHSA-87vv-9cj6-q2hc.json | 8 ++------ .../05/GHSA-8845-33mf-9363/GHSA-8845-33mf-9363.json | 8 ++------ .../05/GHSA-8873-3662-5rmv/GHSA-8873-3662-5rmv.json | 8 ++------ .../05/GHSA-895q-vqrm-2jch/GHSA-895q-vqrm-2jch.json | 8 ++------ .../05/GHSA-89jc-hqfc-w5xg/GHSA-89jc-hqfc-w5xg.json | 8 ++------ .../05/GHSA-8cmf-w78x-mr9c/GHSA-8cmf-w78x-mr9c.json | 8 ++------ .../05/GHSA-8fr7-g775-588h/GHSA-8fr7-g775-588h.json | 8 ++------ .../05/GHSA-8g6h-grf2-7grg/GHSA-8g6h-grf2-7grg.json | 8 ++------ .../05/GHSA-8gq9-69qw-7cch/GHSA-8gq9-69qw-7cch.json | 8 ++------ .../05/GHSA-8hgw-v95f-3rr5/GHSA-8hgw-v95f-3rr5.json | 8 ++------ .../05/GHSA-8j5p-76rr-8r3x/GHSA-8j5p-76rr-8r3x.json | 8 ++------ .../05/GHSA-8jw9-px85-866f/GHSA-8jw9-px85-866f.json | 8 ++------ .../05/GHSA-8mc7-p65m-96vq/GHSA-8mc7-p65m-96vq.json | 8 ++------ .../05/GHSA-8mgg-4h42-8rj6/GHSA-8mgg-4h42-8rj6.json | 8 ++------ .../05/GHSA-8pw4-5frf-g53c/GHSA-8pw4-5frf-g53c.json | 8 ++------ .../05/GHSA-8q2c-xwcr-7mj4/GHSA-8q2c-xwcr-7mj4.json | 8 ++------ .../05/GHSA-8qww-xfxc-2wmf/GHSA-8qww-xfxc-2wmf.json | 8 ++------ .../05/GHSA-8r9p-9pp7-xxpc/GHSA-8r9p-9pp7-xxpc.json | 8 ++------ .../05/GHSA-8rmg-c6qw-6rm2/GHSA-8rmg-c6qw-6rm2.json | 8 ++------ .../05/GHSA-8rpm-95xj-h65p/GHSA-8rpm-95xj-h65p.json | 8 ++------ .../05/GHSA-8vgr-w2rm-8hjx/GHSA-8vgr-w2rm-8hjx.json | 8 ++------ .../05/GHSA-8vhf-89h2-fwh8/GHSA-8vhf-89h2-fwh8.json | 12 +++--------- .../05/GHSA-8w64-jvqw-g3qx/GHSA-8w64-jvqw-g3qx.json | 8 ++------ .../05/GHSA-8xph-6v8f-88rf/GHSA-8xph-6v8f-88rf.json | 12 +++--------- .../05/GHSA-8xr7-5cxh-6x35/GHSA-8xr7-5cxh-6x35.json | 8 ++------ .../05/GHSA-8xrx-q7v8-89j4/GHSA-8xrx-q7v8-89j4.json | 8 ++------ .../05/GHSA-92h4-jh72-6gpm/GHSA-92h4-jh72-6gpm.json | 8 ++------ .../05/GHSA-92w6-8752-jf23/GHSA-92w6-8752-jf23.json | 8 ++------ .../05/GHSA-93gx-49qx-8f59/GHSA-93gx-49qx-8f59.json | 8 ++------ .../05/GHSA-94rj-frv4-2p83/GHSA-94rj-frv4-2p83.json | 8 ++------ .../05/GHSA-956h-2q87-xrpg/GHSA-956h-2q87-xrpg.json | 8 ++------ .../05/GHSA-9666-j9h2-4p66/GHSA-9666-j9h2-4p66.json | 12 +++--------- .../05/GHSA-96p2-7r8j-8q3m/GHSA-96p2-7r8j-8q3m.json | 8 ++------ .../05/GHSA-96qj-2mm8-v8xv/GHSA-96qj-2mm8-v8xv.json | 8 ++------ .../05/GHSA-9724-33jf-7mj5/GHSA-9724-33jf-7mj5.json | 8 ++------ .../05/GHSA-993c-4hx4-cg4r/GHSA-993c-4hx4-cg4r.json | 8 ++------ .../05/GHSA-9c3c-p8mj-7wvw/GHSA-9c3c-p8mj-7wvw.json | 8 ++------ .../05/GHSA-9cfc-7fpm-w3g9/GHSA-9cfc-7fpm-w3g9.json | 8 ++------ .../05/GHSA-9cr8-cgwr-97w6/GHSA-9cr8-cgwr-97w6.json | 8 ++------ .../05/GHSA-9f46-jqh2-hfhm/GHSA-9f46-jqh2-hfhm.json | 8 ++------ .../05/GHSA-9ggp-g58q-5q4w/GHSA-9ggp-g58q-5q4w.json | 8 ++------ .../05/GHSA-9h3q-pjrc-xc8x/GHSA-9h3q-pjrc-xc8x.json | 8 ++------ .../05/GHSA-9h9g-23jj-fphh/GHSA-9h9g-23jj-fphh.json | 12 +++--------- .../05/GHSA-9hfm-mhvm-8rx7/GHSA-9hfm-mhvm-8rx7.json | 8 ++------ .../05/GHSA-9hp5-8ggx-fcqr/GHSA-9hp5-8ggx-fcqr.json | 8 ++------ .../05/GHSA-9j28-98vj-rxx9/GHSA-9j28-98vj-rxx9.json | 8 ++------ .../05/GHSA-9jqc-6f29-2rw7/GHSA-9jqc-6f29-2rw7.json | 8 ++------ .../05/GHSA-9pqc-vphg-mj93/GHSA-9pqc-vphg-mj93.json | 8 ++------ .../05/GHSA-9rp8-hcmg-4f3f/GHSA-9rp8-hcmg-4f3f.json | 8 ++------ .../05/GHSA-9vj3-52fm-gw3x/GHSA-9vj3-52fm-gw3x.json | 8 ++------ .../05/GHSA-9w6x-xx84-rm4g/GHSA-9w6x-xx84-rm4g.json | 8 ++------ .../05/GHSA-9x7w-7fh3-wph9/GHSA-9x7w-7fh3-wph9.json | 8 ++------ .../05/GHSA-9xqf-jv59-8prh/GHSA-9xqf-jv59-8prh.json | 8 ++------ .../05/GHSA-c289-566w-qgp4/GHSA-c289-566w-qgp4.json | 8 ++------ .../05/GHSA-c2xm-93vx-ccjf/GHSA-c2xm-93vx-ccjf.json | 8 ++------ .../05/GHSA-c34x-96jh-xq96/GHSA-c34x-96jh-xq96.json | 4 +--- .../05/GHSA-c36c-5h7j-842j/GHSA-c36c-5h7j-842j.json | 8 ++------ .../05/GHSA-c3f5-4g7m-3xfc/GHSA-c3f5-4g7m-3xfc.json | 8 ++------ .../05/GHSA-c43f-p3rv-7q34/GHSA-c43f-p3rv-7q34.json | 12 +++--------- .../05/GHSA-c529-rjcg-qqqv/GHSA-c529-rjcg-qqqv.json | 8 ++------ .../05/GHSA-c585-qfhx-g68f/GHSA-c585-qfhx-g68f.json | 8 ++------ .../05/GHSA-c5fc-m7pj-4vv5/GHSA-c5fc-m7pj-4vv5.json | 8 ++------ .../05/GHSA-c6gp-grvf-r987/GHSA-c6gp-grvf-r987.json | 8 ++------ .../05/GHSA-c6rr-v7p8-35wh/GHSA-c6rr-v7p8-35wh.json | 8 ++------ .../05/GHSA-c6vf-v2c4-qvvh/GHSA-c6vf-v2c4-qvvh.json | 8 ++------ .../05/GHSA-c7r4-5f37-6572/GHSA-c7r4-5f37-6572.json | 8 ++------ .../05/GHSA-c8qx-8jr7-qrj4/GHSA-c8qx-8jr7-qrj4.json | 8 ++------ .../05/GHSA-c94j-m65h-vm53/GHSA-c94j-m65h-vm53.json | 8 ++------ .../05/GHSA-c965-72mg-cpv5/GHSA-c965-72mg-cpv5.json | 8 ++------ .../05/GHSA-cfw4-vhm2-m225/GHSA-cfw4-vhm2-m225.json | 8 ++------ .../05/GHSA-cg9q-rwc5-c6x9/GHSA-cg9q-rwc5-c6x9.json | 8 ++------ .../05/GHSA-ch2j-pqr2-h9jh/GHSA-ch2j-pqr2-h9jh.json | 8 ++------ .../05/GHSA-ch7j-5vw3-j293/GHSA-ch7j-5vw3-j293.json | 8 ++------ .../05/GHSA-chj6-qg78-f8r4/GHSA-chj6-qg78-f8r4.json | 8 ++------ .../05/GHSA-cj5x-6j3p-rgxm/GHSA-cj5x-6j3p-rgxm.json | 8 ++------ .../05/GHSA-cj8v-r5w4-97v8/GHSA-cj8v-r5w4-97v8.json | 8 ++------ .../05/GHSA-cm7f-83pq-pfp3/GHSA-cm7f-83pq-pfp3.json | 8 ++------ .../05/GHSA-cm97-fwp9-pfjj/GHSA-cm97-fwp9-pfjj.json | 12 +++--------- .../05/GHSA-cq4c-8j48-3m6g/GHSA-cq4c-8j48-3m6g.json | 8 ++------ .../05/GHSA-crm8-2hrx-527c/GHSA-crm8-2hrx-527c.json | 8 ++------ .../05/GHSA-cvwh-p6q5-8546/GHSA-cvwh-p6q5-8546.json | 8 ++------ .../05/GHSA-cw4x-cxpm-9p3r/GHSA-cw4x-cxpm-9p3r.json | 8 ++------ .../05/GHSA-cwcm-c4j8-ww8c/GHSA-cwcm-c4j8-ww8c.json | 12 +++--------- .../05/GHSA-cwv7-82qm-9wqw/GHSA-cwv7-82qm-9wqw.json | 8 ++------ .../05/GHSA-cx9v-96cj-78q9/GHSA-cx9v-96cj-78q9.json | 8 ++------ .../05/GHSA-cxgj-mmp6-3j54/GHSA-cxgj-mmp6-3j54.json | 4 +--- .../05/GHSA-f329-5h54-9xp6/GHSA-f329-5h54-9xp6.json | 12 +++--------- .../05/GHSA-f34x-833g-jcxv/GHSA-f34x-833g-jcxv.json | 4 +--- .../05/GHSA-f3hv-32hf-cqw9/GHSA-f3hv-32hf-cqw9.json | 8 ++------ .../05/GHSA-f435-mvrp-xrqp/GHSA-f435-mvrp-xrqp.json | 8 ++------ .../05/GHSA-f47w-6h97-hppp/GHSA-f47w-6h97-hppp.json | 8 ++------ .../05/GHSA-f53r-gcpp-vf27/GHSA-f53r-gcpp-vf27.json | 8 ++------ .../05/GHSA-f64w-4rx7-rvrx/GHSA-f64w-4rx7-rvrx.json | 8 ++------ .../05/GHSA-f6c6-g5xq-fvm6/GHSA-f6c6-g5xq-fvm6.json | 8 ++------ .../05/GHSA-f6gr-xm3f-89xf/GHSA-f6gr-xm3f-89xf.json | 8 ++------ .../05/GHSA-f756-pwvp-9jmj/GHSA-f756-pwvp-9jmj.json | 12 +++--------- .../05/GHSA-f79g-9mrm-w496/GHSA-f79g-9mrm-w496.json | 12 +++--------- .../05/GHSA-f7v5-p6x6-2823/GHSA-f7v5-p6x6-2823.json | 8 ++------ .../05/GHSA-f8g3-m2c8-8x9w/GHSA-f8g3-m2c8-8x9w.json | 8 ++------ .../05/GHSA-f8r4-jggf-jmg8/GHSA-f8r4-jggf-jmg8.json | 8 ++------ .../05/GHSA-f92r-w6xq-p3pv/GHSA-f92r-w6xq-p3pv.json | 8 ++------ .../05/GHSA-f9j7-x88q-9m28/GHSA-f9j7-x88q-9m28.json | 8 ++------ .../05/GHSA-fcfc-3847-rccf/GHSA-fcfc-3847-rccf.json | 8 ++------ .../05/GHSA-fcfx-pc78-jw2m/GHSA-fcfx-pc78-jw2m.json | 8 ++------ .../05/GHSA-fgch-vc2g-g3c8/GHSA-fgch-vc2g-g3c8.json | 8 ++------ .../05/GHSA-fjv4-6mwc-7524/GHSA-fjv4-6mwc-7524.json | 8 ++------ .../05/GHSA-fm6w-v8h2-8q9w/GHSA-fm6w-v8h2-8q9w.json | 8 ++------ .../05/GHSA-fmh2-qxcv-pr3h/GHSA-fmh2-qxcv-pr3h.json | 12 +++--------- .../05/GHSA-fmh6-hqj7-h6hv/GHSA-fmh6-hqj7-h6hv.json | 8 ++------ .../05/GHSA-fmvr-p9qq-34gq/GHSA-fmvr-p9qq-34gq.json | 12 +++--------- .../05/GHSA-fmx8-rqgc-5vmx/GHSA-fmx8-rqgc-5vmx.json | 4 +--- .../05/GHSA-frhm-hx27-q4p6/GHSA-frhm-hx27-q4p6.json | 8 ++------ .../05/GHSA-fv42-5hcx-5cr6/GHSA-fv42-5hcx-5cr6.json | 4 +--- .../05/GHSA-fvq4-c84w-q2rx/GHSA-fvq4-c84w-q2rx.json | 8 ++------ .../05/GHSA-fw96-xwr9-54ff/GHSA-fw96-xwr9-54ff.json | 8 ++------ .../05/GHSA-fwfg-74jc-wgx8/GHSA-fwfg-74jc-wgx8.json | 8 ++------ .../05/GHSA-fwm5-6cq3-ch4p/GHSA-fwm5-6cq3-ch4p.json | 8 ++------ .../05/GHSA-fwrf-6v6g-jrvx/GHSA-fwrf-6v6g-jrvx.json | 8 ++------ .../05/GHSA-fwv4-f9xf-wp89/GHSA-fwv4-f9xf-wp89.json | 8 ++------ .../05/GHSA-fwxv-g739-m9fm/GHSA-fwxv-g739-m9fm.json | 8 ++------ .../05/GHSA-fxv5-3xrg-jgx5/GHSA-fxv5-3xrg-jgx5.json | 8 ++------ .../05/GHSA-g2ff-qw45-v2q6/GHSA-g2ff-qw45-v2q6.json | 4 +--- .../05/GHSA-g3q9-p77m-rp7m/GHSA-g3q9-p77m-rp7m.json | 8 ++------ .../05/GHSA-g49q-m8rg-qhw4/GHSA-g49q-m8rg-qhw4.json | 8 ++------ .../05/GHSA-g6c2-ghr3-xmvw/GHSA-g6c2-ghr3-xmvw.json | 8 ++------ .../05/GHSA-g79x-g6g2-hc4x/GHSA-g79x-g6g2-hc4x.json | 12 +++--------- .../05/GHSA-g7v3-hrfv-mjj2/GHSA-g7v3-hrfv-mjj2.json | 8 ++------ .../05/GHSA-g85v-4g67-6899/GHSA-g85v-4g67-6899.json | 8 ++------ .../05/GHSA-g862-hhr5-33gv/GHSA-g862-hhr5-33gv.json | 8 ++------ .../05/GHSA-g8q3-jq94-7x7p/GHSA-g8q3-jq94-7x7p.json | 8 ++------ .../05/GHSA-g929-vm5v-86gq/GHSA-g929-vm5v-86gq.json | 8 ++------ .../05/GHSA-gf85-jmcw-8cmh/GHSA-gf85-jmcw-8cmh.json | 8 ++------ .../05/GHSA-gfrg-r8xw-vpm9/GHSA-gfrg-r8xw-vpm9.json | 12 +++--------- .../05/GHSA-gg22-v8g3-2r42/GHSA-gg22-v8g3-2r42.json | 8 ++------ .../05/GHSA-ggc7-6cvg-qp72/GHSA-ggc7-6cvg-qp72.json | 8 ++------ .../05/GHSA-ggjq-g68v-5f3p/GHSA-ggjq-g68v-5f3p.json | 8 ++------ .../05/GHSA-ggrx-w8hv-q97q/GHSA-ggrx-w8hv-q97q.json | 8 ++------ .../05/GHSA-ggxv-vqqm-7f4w/GHSA-ggxv-vqqm-7f4w.json | 8 ++------ .../05/GHSA-ghgp-g2w8-92pm/GHSA-ghgp-g2w8-92pm.json | 8 ++------ .../05/GHSA-ghj2-hfg6-h8j7/GHSA-ghj2-hfg6-h8j7.json | 8 ++------ .../05/GHSA-ghvp-76xv-fjr5/GHSA-ghvp-76xv-fjr5.json | 8 ++------ .../05/GHSA-gj9f-3v8v-xvvr/GHSA-gj9f-3v8v-xvvr.json | 8 ++------ .../05/GHSA-gjfx-fqhh-mx8f/GHSA-gjfx-fqhh-mx8f.json | 8 ++------ .../05/GHSA-gjv5-9xrv-6pww/GHSA-gjv5-9xrv-6pww.json | 8 ++------ .../05/GHSA-gmgc-2jr6-mv52/GHSA-gmgc-2jr6-mv52.json | 8 ++------ .../05/GHSA-gmqq-hrf4-4gvf/GHSA-gmqq-hrf4-4gvf.json | 8 ++------ .../05/GHSA-gqq8-4hgw-g2fp/GHSA-gqq8-4hgw-g2fp.json | 8 ++------ .../05/GHSA-grmh-7h5f-7q6v/GHSA-grmh-7h5f-7q6v.json | 8 ++------ .../05/GHSA-gv37-4vjv-96xm/GHSA-gv37-4vjv-96xm.json | 8 ++------ .../05/GHSA-gv8v-gq5v-5rpc/GHSA-gv8v-gq5v-5rpc.json | 8 ++------ .../05/GHSA-gv97-chp3-8xhh/GHSA-gv97-chp3-8xhh.json | 8 ++------ .../05/GHSA-gvhj-p52g-rhm3/GHSA-gvhj-p52g-rhm3.json | 8 ++------ .../05/GHSA-gw7h-3fw6-97j4/GHSA-gw7h-3fw6-97j4.json | 8 ++------ .../05/GHSA-gwg7-mp6r-mj4h/GHSA-gwg7-mp6r-mj4h.json | 8 ++------ .../05/GHSA-gwhr-c723-m8fm/GHSA-gwhr-c723-m8fm.json | 8 ++------ .../05/GHSA-gx57-8c8v-6mj6/GHSA-gx57-8c8v-6mj6.json | 8 ++------ .../05/GHSA-gxgw-6q4v-hcj8/GHSA-gxgw-6q4v-hcj8.json | 8 ++------ .../05/GHSA-gxhq-4chx-5r72/GHSA-gxhq-4chx-5r72.json | 8 ++------ .../05/GHSA-h237-f2vg-f29q/GHSA-h237-f2vg-f29q.json | 8 ++------ .../05/GHSA-h273-mwpm-4f8q/GHSA-h273-mwpm-4f8q.json | 12 +++--------- .../05/GHSA-h2x8-6h3c-4jp7/GHSA-h2x8-6h3c-4jp7.json | 4 +--- .../05/GHSA-h3v7-cvf6-7jhw/GHSA-h3v7-cvf6-7jhw.json | 8 ++------ .../05/GHSA-h6fg-hfp3-3883/GHSA-h6fg-hfp3-3883.json | 8 ++------ .../05/GHSA-h6g5-q5mh-3mg9/GHSA-h6g5-q5mh-3mg9.json | 8 ++------ .../05/GHSA-h79q-qqcc-qw9h/GHSA-h79q-qqcc-qw9h.json | 8 ++------ .../05/GHSA-h7g5-p978-f45g/GHSA-h7g5-p978-f45g.json | 8 ++------ .../05/GHSA-h877-6h9f-xm6f/GHSA-h877-6h9f-xm6f.json | 8 ++------ .../05/GHSA-h88c-j84g-842h/GHSA-h88c-j84g-842h.json | 8 ++------ .../05/GHSA-h8pv-pv44-xcvw/GHSA-h8pv-pv44-xcvw.json | 8 ++------ .../05/GHSA-h9fm-r36v-gmw8/GHSA-h9fm-r36v-gmw8.json | 8 ++------ .../05/GHSA-h9gg-fc6x-px6c/GHSA-h9gg-fc6x-px6c.json | 8 ++------ .../05/GHSA-hcq4-pg2q-469j/GHSA-hcq4-pg2q-469j.json | 8 ++------ .../05/GHSA-hcv9-p733-v9fh/GHSA-hcv9-p733-v9fh.json | 12 +++--------- .../05/GHSA-hf7v-pc2m-3mm9/GHSA-hf7v-pc2m-3mm9.json | 12 +++--------- .../05/GHSA-hgpc-4547-p5wm/GHSA-hgpc-4547-p5wm.json | 8 ++------ .../05/GHSA-hh5h-m6rg-25r6/GHSA-hh5h-m6rg-25r6.json | 8 ++------ .../05/GHSA-hh5m-6r25-ccqm/GHSA-hh5m-6r25-ccqm.json | 8 ++------ .../05/GHSA-hjwx-j74m-7j88/GHSA-hjwx-j74m-7j88.json | 8 ++------ .../05/GHSA-hjx4-ghxm-xpj2/GHSA-hjx4-ghxm-xpj2.json | 8 ++------ .../05/GHSA-hmm3-wj4g-8w8g/GHSA-hmm3-wj4g-8w8g.json | 8 ++------ .../05/GHSA-hp39-4vrr-9cjg/GHSA-hp39-4vrr-9cjg.json | 12 +++--------- .../05/GHSA-hp87-jr7m-7m74/GHSA-hp87-jr7m-7m74.json | 8 ++------ .../05/GHSA-hpmf-2v4h-c97c/GHSA-hpmf-2v4h-c97c.json | 8 ++------ .../05/GHSA-hprx-w65c-9mfp/GHSA-hprx-w65c-9mfp.json | 8 ++------ .../05/GHSA-hq6f-9m26-g47r/GHSA-hq6f-9m26-g47r.json | 8 ++------ .../05/GHSA-hqcf-3xgv-jcpv/GHSA-hqcf-3xgv-jcpv.json | 8 ++------ .../05/GHSA-hqqw-v7w4-65wv/GHSA-hqqw-v7w4-65wv.json | 8 ++------ .../05/GHSA-hw26-j6mr-8w28/GHSA-hw26-j6mr-8w28.json | 8 ++------ .../05/GHSA-hwm9-775j-vf84/GHSA-hwm9-775j-vf84.json | 8 ++------ .../05/GHSA-hx2g-vqw8-rh9r/GHSA-hx2g-vqw8-rh9r.json | 8 ++------ .../05/GHSA-hx68-cxw3-7prp/GHSA-hx68-cxw3-7prp.json | 8 ++------ .../05/GHSA-j2w6-g3jh-8g4x/GHSA-j2w6-g3jh-8g4x.json | 8 ++------ .../05/GHSA-j2wg-wfjw-m5cq/GHSA-j2wg-wfjw-m5cq.json | 4 +--- .../05/GHSA-j39w-7p3g-g389/GHSA-j39w-7p3g-g389.json | 8 ++------ .../05/GHSA-j3w6-mx9r-j6qp/GHSA-j3w6-mx9r-j6qp.json | 12 +++--------- .../05/GHSA-j42c-839r-f79f/GHSA-j42c-839r-f79f.json | 8 ++------ .../05/GHSA-j42v-fg25-q7fp/GHSA-j42v-fg25-q7fp.json | 8 ++------ .../05/GHSA-j564-pmx9-wqcj/GHSA-j564-pmx9-wqcj.json | 8 ++------ .../05/GHSA-j5gx-c23h-6w7f/GHSA-j5gx-c23h-6w7f.json | 8 ++------ .../05/GHSA-j5q4-h79w-mh86/GHSA-j5q4-h79w-mh86.json | 8 ++------ .../05/GHSA-j67r-w3x2-72vq/GHSA-j67r-w3x2-72vq.json | 8 ++------ .../05/GHSA-j6h5-jcwm-38vr/GHSA-j6h5-jcwm-38vr.json | 8 ++------ .../05/GHSA-j6hf-ffpw-242h/GHSA-j6hf-ffpw-242h.json | 8 ++------ .../05/GHSA-j892-5fgm-v8hw/GHSA-j892-5fgm-v8hw.json | 8 ++------ .../05/GHSA-j8h5-g58p-q4rv/GHSA-j8h5-g58p-q4rv.json | 8 ++------ .../05/GHSA-j8r2-275f-f2p3/GHSA-j8r2-275f-f2p3.json | 8 ++------ .../05/GHSA-j8r6-c45m-jv6q/GHSA-j8r6-c45m-jv6q.json | 12 +++--------- .../05/GHSA-j93q-24g6-27r6/GHSA-j93q-24g6-27r6.json | 8 ++------ .../05/GHSA-jc86-jrjv-444j/GHSA-jc86-jrjv-444j.json | 8 ++------ .../05/GHSA-jcff-w8hg-gx77/GHSA-jcff-w8hg-gx77.json | 8 ++------ .../05/GHSA-jcvw-97mh-q338/GHSA-jcvw-97mh-q338.json | 8 ++------ .../05/GHSA-jhpp-6c5p-c4vj/GHSA-jhpp-6c5p-c4vj.json | 8 ++------ .../05/GHSA-jhv2-rwmc-cjh9/GHSA-jhv2-rwmc-cjh9.json | 8 ++------ .../05/GHSA-jj37-qmmg-fmgp/GHSA-jj37-qmmg-fmgp.json | 8 ++------ .../05/GHSA-jm5h-3x78-fpg8/GHSA-jm5h-3x78-fpg8.json | 8 ++------ .../05/GHSA-jmfv-2476-jhcq/GHSA-jmfv-2476-jhcq.json | 12 +++--------- .../05/GHSA-jmxf-gfr2-rfwj/GHSA-jmxf-gfr2-rfwj.json | 8 ++------ .../05/GHSA-jp62-q2mj-vpxc/GHSA-jp62-q2mj-vpxc.json | 8 ++------ .../05/GHSA-jpx3-8xrf-jxhx/GHSA-jpx3-8xrf-jxhx.json | 8 ++------ .../05/GHSA-jq8v-8c7p-26p2/GHSA-jq8v-8c7p-26p2.json | 8 ++------ .../05/GHSA-jqm2-jgff-xhhh/GHSA-jqm2-jgff-xhhh.json | 8 ++------ .../05/GHSA-jr5f-4v8f-4m67/GHSA-jr5f-4v8f-4m67.json | 8 ++------ .../05/GHSA-jrq7-2cwg-jfgc/GHSA-jrq7-2cwg-jfgc.json | 8 ++------ .../05/GHSA-jvq7-w5fg-7qjh/GHSA-jvq7-w5fg-7qjh.json | 8 ++------ .../05/GHSA-jvqg-jjfg-vv75/GHSA-jvqg-jjfg-vv75.json | 12 +++--------- .../05/GHSA-jvr7-4f7q-4v6w/GHSA-jvr7-4f7q-4v6w.json | 12 +++--------- .../05/GHSA-jvvx-4fhr-xxqv/GHSA-jvvx-4fhr-xxqv.json | 8 ++------ .../05/GHSA-jxgf-p2mp-g2wx/GHSA-jxgf-p2mp-g2wx.json | 8 ++------ .../05/GHSA-m37h-4w48-299w/GHSA-m37h-4w48-299w.json | 8 ++------ .../05/GHSA-m3j9-2rhw-rjxm/GHSA-m3j9-2rhw-rjxm.json | 8 ++------ .../05/GHSA-m4c5-25qf-rmm3/GHSA-m4c5-25qf-rmm3.json | 8 ++------ .../05/GHSA-m4f9-7fgw-p5j8/GHSA-m4f9-7fgw-p5j8.json | 8 ++------ .../05/GHSA-m4hr-5jvh-hpgq/GHSA-m4hr-5jvh-hpgq.json | 8 ++------ .../05/GHSA-m53v-fcjx-mpcr/GHSA-m53v-fcjx-mpcr.json | 8 ++------ .../05/GHSA-m6v6-xwrv-hp92/GHSA-m6v6-xwrv-hp92.json | 8 ++------ .../05/GHSA-m78f-9p7v-48h9/GHSA-m78f-9p7v-48h9.json | 8 ++------ .../05/GHSA-m7h8-8q5m-8g9r/GHSA-m7h8-8q5m-8g9r.json | 8 ++------ .../05/GHSA-m7wj-9xjx-8vhq/GHSA-m7wj-9xjx-8vhq.json | 8 ++------ .../05/GHSA-m7wp-c8qj-3fpc/GHSA-m7wp-c8qj-3fpc.json | 8 ++------ .../05/GHSA-m83f-px8c-c623/GHSA-m83f-px8c-c623.json | 4 +--- .../05/GHSA-m845-5gj8-66h2/GHSA-m845-5gj8-66h2.json | 8 ++------ .../05/GHSA-m85w-g475-q78j/GHSA-m85w-g475-q78j.json | 8 ++------ .../05/GHSA-m89x-hf4g-3j36/GHSA-m89x-hf4g-3j36.json | 8 ++------ .../05/GHSA-m944-5qpv-g8wv/GHSA-m944-5qpv-g8wv.json | 8 ++------ .../05/GHSA-m973-3r23-2c9h/GHSA-m973-3r23-2c9h.json | 8 ++------ .../05/GHSA-m9j8-w3jp-p7wq/GHSA-m9j8-w3jp-p7wq.json | 8 ++------ .../05/GHSA-m9vx-wm87-mjxm/GHSA-m9vx-wm87-mjxm.json | 8 ++------ .../05/GHSA-mcp4-jxrc-pg4f/GHSA-mcp4-jxrc-pg4f.json | 8 ++------ .../05/GHSA-mcv5-rv2r-2h7w/GHSA-mcv5-rv2r-2h7w.json | 8 ++------ .../05/GHSA-mf95-74qr-37vw/GHSA-mf95-74qr-37vw.json | 8 ++------ .../05/GHSA-mfc8-4qmg-g3x6/GHSA-mfc8-4qmg-g3x6.json | 8 ++------ .../05/GHSA-mffw-j524-mrjp/GHSA-mffw-j524-mrjp.json | 8 ++------ .../05/GHSA-mfw3-hgv3-pg44/GHSA-mfw3-hgv3-pg44.json | 8 ++------ .../05/GHSA-mfw8-gqh6-9gr8/GHSA-mfw8-gqh6-9gr8.json | 12 +++--------- .../05/GHSA-mg3m-w94w-vr47/GHSA-mg3m-w94w-vr47.json | 8 ++------ .../05/GHSA-mgm6-gx92-h348/GHSA-mgm6-gx92-h348.json | 8 ++------ .../05/GHSA-mgph-g68w-qpm4/GHSA-mgph-g68w-qpm4.json | 8 ++------ .../05/GHSA-mgvh-5mj6-fprr/GHSA-mgvh-5mj6-fprr.json | 8 ++------ .../05/GHSA-mh87-m65c-c4rq/GHSA-mh87-m65c-c4rq.json | 8 ++------ .../05/GHSA-mh8m-xx9m-xm5h/GHSA-mh8m-xx9m-xm5h.json | 8 ++------ .../05/GHSA-mh9j-g4g3-6xcv/GHSA-mh9j-g4g3-6xcv.json | 4 +--- .../05/GHSA-mhgc-wgp9-pgqm/GHSA-mhgc-wgp9-pgqm.json | 12 +++--------- .../05/GHSA-mhq4-2r6p-x7vh/GHSA-mhq4-2r6p-x7vh.json | 8 ++------ .../05/GHSA-mjhf-5xg4-c757/GHSA-mjhf-5xg4-c757.json | 8 ++------ .../05/GHSA-mjjv-qwjv-hg32/GHSA-mjjv-qwjv-hg32.json | 12 +++--------- .../05/GHSA-mmfm-f7qp-mmv3/GHSA-mmfm-f7qp-mmv3.json | 8 ++------ .../05/GHSA-mp76-8wmf-mx7x/GHSA-mp76-8wmf-mx7x.json | 8 ++------ .../05/GHSA-mqrh-3j77-m2cw/GHSA-mqrh-3j77-m2cw.json | 12 +++--------- .../05/GHSA-mr64-xwwr-mx4c/GHSA-mr64-xwwr-mx4c.json | 8 ++------ .../05/GHSA-mwv5-m2cr-5r9v/GHSA-mwv5-m2cr-5r9v.json | 8 ++------ .../05/GHSA-mx6v-gg5x-68cf/GHSA-mx6v-gg5x-68cf.json | 8 ++------ .../05/GHSA-p2hm-44w4-3mxj/GHSA-p2hm-44w4-3mxj.json | 8 ++------ .../05/GHSA-p2hx-qx96-fvxr/GHSA-p2hx-qx96-fvxr.json | 8 ++------ .../05/GHSA-p2p6-4q4c-7xqw/GHSA-p2p6-4q4c-7xqw.json | 12 +++--------- .../05/GHSA-p3v9-28pc-q5p2/GHSA-p3v9-28pc-q5p2.json | 8 ++------ .../05/GHSA-p6jx-ww27-x6x5/GHSA-p6jx-ww27-x6x5.json | 8 ++------ .../05/GHSA-p6mv-vmpw-j23r/GHSA-p6mv-vmpw-j23r.json | 12 +++--------- .../05/GHSA-p7jp-vf5p-fj78/GHSA-p7jp-vf5p-fj78.json | 8 ++------ .../05/GHSA-p7q8-r4h2-p9qq/GHSA-p7q8-r4h2-p9qq.json | 8 ++------ .../05/GHSA-p7rw-422j-w7qg/GHSA-p7rw-422j-w7qg.json | 8 ++------ .../05/GHSA-p8fx-hg9x-79mx/GHSA-p8fx-hg9x-79mx.json | 8 ++------ .../05/GHSA-p969-xjrf-27pm/GHSA-p969-xjrf-27pm.json | 8 ++------ .../05/GHSA-p9fx-r7r3-pm29/GHSA-p9fx-r7r3-pm29.json | 8 ++------ .../05/GHSA-pcmg-wjrm-9r44/GHSA-pcmg-wjrm-9r44.json | 8 ++------ .../05/GHSA-pcr3-5frq-ww46/GHSA-pcr3-5frq-ww46.json | 8 ++------ .../05/GHSA-pf65-88c2-hrfc/GHSA-pf65-88c2-hrfc.json | 12 +++--------- .../05/GHSA-pgjg-jx8c-q35f/GHSA-pgjg-jx8c-q35f.json | 8 ++------ .../05/GHSA-pm7g-wr2h-x45m/GHSA-pm7g-wr2h-x45m.json | 4 +--- .../05/GHSA-pqw8-9r2r-p4cp/GHSA-pqw8-9r2r-p4cp.json | 8 ++------ .../05/GHSA-prq6-5cg3-rr76/GHSA-prq6-5cg3-rr76.json | 8 ++------ .../05/GHSA-pw5j-659q-5r57/GHSA-pw5j-659q-5r57.json | 8 ++------ .../05/GHSA-pwmr-wm2x-h5p8/GHSA-pwmr-wm2x-h5p8.json | 8 ++------ .../05/GHSA-px9v-79j4-c67w/GHSA-px9v-79j4-c67w.json | 8 ++------ .../05/GHSA-pxc8-4fvh-x35v/GHSA-pxc8-4fvh-x35v.json | 8 ++------ .../05/GHSA-pxw9-25jj-hw97/GHSA-pxw9-25jj-hw97.json | 8 ++------ .../05/GHSA-q329-j6wm-vf6q/GHSA-q329-j6wm-vf6q.json | 8 ++------ .../05/GHSA-q3g8-363q-g9qq/GHSA-q3g8-363q-g9qq.json | 8 ++------ .../05/GHSA-q3gm-pqp8-wxcj/GHSA-q3gm-pqp8-wxcj.json | 8 ++------ .../05/GHSA-q3jv-fxmp-qgj5/GHSA-q3jv-fxmp-qgj5.json | 8 ++------ .../05/GHSA-q45w-6fj8-gjg7/GHSA-q45w-6fj8-gjg7.json | 8 ++------ .../05/GHSA-q477-jxcv-9pxw/GHSA-q477-jxcv-9pxw.json | 8 ++------ .../05/GHSA-q53r-4p37-g26v/GHSA-q53r-4p37-g26v.json | 8 ++------ .../05/GHSA-q5hg-75fp-r6wm/GHSA-q5hg-75fp-r6wm.json | 8 ++------ .../05/GHSA-q5qq-3694-7623/GHSA-q5qq-3694-7623.json | 8 ++------ .../05/GHSA-q5qw-2572-9j7r/GHSA-q5qw-2572-9j7r.json | 8 ++------ .../05/GHSA-q5x3-rg2c-6436/GHSA-q5x3-rg2c-6436.json | 8 ++------ .../05/GHSA-q6w2-7x26-wjhf/GHSA-q6w2-7x26-wjhf.json | 8 ++------ .../05/GHSA-q768-rrh4-6p7h/GHSA-q768-rrh4-6p7h.json | 8 ++------ .../05/GHSA-q7hp-c9hf-jfvx/GHSA-q7hp-c9hf-jfvx.json | 8 ++------ .../05/GHSA-q7pj-xc3r-rm4w/GHSA-q7pj-xc3r-rm4w.json | 8 ++------ .../05/GHSA-q835-q3qm-4v3c/GHSA-q835-q3qm-4v3c.json | 8 ++------ .../05/GHSA-q84j-ghmc-vjvj/GHSA-q84j-ghmc-vjvj.json | 4 +--- .../05/GHSA-q89m-rx2c-6v2g/GHSA-q89m-rx2c-6v2g.json | 8 ++------ .../05/GHSA-q9rx-4v2p-p884/GHSA-q9rx-4v2p-p884.json | 12 +++--------- .../05/GHSA-qcfr-j8mx-6wf3/GHSA-qcfr-j8mx-6wf3.json | 8 ++------ .../05/GHSA-qf9m-hx8v-j382/GHSA-qf9m-hx8v-j382.json | 8 ++------ .../05/GHSA-qfv7-mpwh-q7mf/GHSA-qfv7-mpwh-q7mf.json | 8 ++------ .../05/GHSA-qgxh-9fmh-3q95/GHSA-qgxh-9fmh-3q95.json | 8 ++------ .../05/GHSA-qh64-cxhv-8756/GHSA-qh64-cxhv-8756.json | 4 +--- .../05/GHSA-qh93-57jh-fhch/GHSA-qh93-57jh-fhch.json | 8 ++------ .../05/GHSA-qhv9-3j65-7jg9/GHSA-qhv9-3j65-7jg9.json | 8 ++------ .../05/GHSA-qj3c-vm3g-g389/GHSA-qj3c-vm3g-g389.json | 8 ++------ .../05/GHSA-qmhj-wg3r-x2h5/GHSA-qmhj-wg3r-x2h5.json | 8 ++------ .../05/GHSA-qp4c-cv95-gwhh/GHSA-qp4c-cv95-gwhh.json | 8 ++------ .../05/GHSA-qq7v-vpch-58j2/GHSA-qq7v-vpch-58j2.json | 12 +++--------- .../05/GHSA-qq9r-5mv8-w3px/GHSA-qq9r-5mv8-w3px.json | 8 ++------ .../05/GHSA-qqm4-x6m2-p2v9/GHSA-qqm4-x6m2-p2v9.json | 8 ++------ .../05/GHSA-qrhr-8558-526f/GHSA-qrhr-8558-526f.json | 8 ++------ .../05/GHSA-qrpp-2r5f-6xf2/GHSA-qrpp-2r5f-6xf2.json | 8 ++------ .../05/GHSA-qrrv-9vc8-gf2w/GHSA-qrrv-9vc8-gf2w.json | 8 ++------ .../05/GHSA-qv45-6hw7-469f/GHSA-qv45-6hw7-469f.json | 4 +--- .../05/GHSA-qvf3-c945-57wx/GHSA-qvf3-c945-57wx.json | 8 ++------ .../05/GHSA-qvw9-x4gw-6754/GHSA-qvw9-x4gw-6754.json | 8 ++------ .../05/GHSA-qw6q-h32m-cgfq/GHSA-qw6q-h32m-cgfq.json | 8 ++------ .../05/GHSA-r269-87mv-8wp9/GHSA-r269-87mv-8wp9.json | 8 ++------ .../05/GHSA-r295-fpcq-rg99/GHSA-r295-fpcq-rg99.json | 8 ++------ .../05/GHSA-r29f-v3vg-4fcq/GHSA-r29f-v3vg-4fcq.json | 8 ++------ .../05/GHSA-r2pg-5xw6-p694/GHSA-r2pg-5xw6-p694.json | 8 ++------ .../05/GHSA-r346-r4r7-jqhf/GHSA-r346-r4r7-jqhf.json | 4 +--- .../05/GHSA-r3q7-7pwq-hqq8/GHSA-r3q7-7pwq-hqq8.json | 8 ++------ .../05/GHSA-r4r6-76p6-65m4/GHSA-r4r6-76p6-65m4.json | 8 ++------ .../05/GHSA-r4rr-cgc8-x5v8/GHSA-r4rr-cgc8-x5v8.json | 8 ++------ .../05/GHSA-r4xm-6p48-p6gf/GHSA-r4xm-6p48-p6gf.json | 12 +++--------- .../05/GHSA-r78c-53rf-ghjm/GHSA-r78c-53rf-ghjm.json | 8 ++------ .../05/GHSA-r7mj-3g43-28gm/GHSA-r7mj-3g43-28gm.json | 8 ++------ .../05/GHSA-r7q6-f5hp-q2cq/GHSA-r7q6-f5hp-q2cq.json | 8 ++------ .../05/GHSA-r929-7jrv-6rh2/GHSA-r929-7jrv-6rh2.json | 8 ++------ .../05/GHSA-r9v7-wgfw-56p5/GHSA-r9v7-wgfw-56p5.json | 8 ++------ .../05/GHSA-r9xw-pv6r-fxr3/GHSA-r9xw-pv6r-fxr3.json | 8 ++------ .../05/GHSA-rc2q-p83g-48vc/GHSA-rc2q-p83g-48vc.json | 8 ++------ .../05/GHSA-rg38-723q-h7xm/GHSA-rg38-723q-h7xm.json | 12 +++--------- .../05/GHSA-rg4r-734p-28pq/GHSA-rg4r-734p-28pq.json | 8 ++------ .../05/GHSA-rhq4-w8hr-cp6m/GHSA-rhq4-w8hr-cp6m.json | 8 ++------ .../05/GHSA-rjcf-2qpv-xpv2/GHSA-rjcf-2qpv-xpv2.json | 8 ++------ .../05/GHSA-rjmp-wffv-9cmf/GHSA-rjmp-wffv-9cmf.json | 8 ++------ .../05/GHSA-rmcg-rw28-jg8f/GHSA-rmcg-rw28-jg8f.json | 8 ++------ .../05/GHSA-rmr6-x3v6-grqm/GHSA-rmr6-x3v6-grqm.json | 8 ++------ .../05/GHSA-rpv9-285j-r9jm/GHSA-rpv9-285j-r9jm.json | 12 +++--------- .../05/GHSA-rq59-f4hv-p8wv/GHSA-rq59-f4hv-p8wv.json | 8 ++------ .../05/GHSA-rqmv-893j-49p8/GHSA-rqmv-893j-49p8.json | 8 ++------ .../05/GHSA-rqqp-68qw-6v7r/GHSA-rqqp-68qw-6v7r.json | 8 ++------ .../05/GHSA-rrj2-qpwr-2v2h/GHSA-rrj2-qpwr-2v2h.json | 12 +++--------- .../05/GHSA-rrx8-fq2r-pjvj/GHSA-rrx8-fq2r-pjvj.json | 8 ++------ .../05/GHSA-rvr3-f3x4-3669/GHSA-rvr3-f3x4-3669.json | 8 ++------ .../05/GHSA-rxm3-3v27-86hh/GHSA-rxm3-3v27-86hh.json | 8 ++------ .../05/GHSA-v2fr-wv49-j53x/GHSA-v2fr-wv49-j53x.json | 8 ++------ .../05/GHSA-v2jc-8954-6fhq/GHSA-v2jc-8954-6fhq.json | 8 ++------ .../05/GHSA-v2m8-9547-v9wg/GHSA-v2m8-9547-v9wg.json | 8 ++------ .../05/GHSA-v439-79v8-38g8/GHSA-v439-79v8-38g8.json | 8 ++------ .../05/GHSA-v44r-mggx-92j8/GHSA-v44r-mggx-92j8.json | 8 ++------ .../05/GHSA-v4jv-x72w-cw2g/GHSA-v4jv-x72w-cw2g.json | 8 ++------ .../05/GHSA-v5jv-p23p-vwpj/GHSA-v5jv-p23p-vwpj.json | 8 ++------ .../05/GHSA-v67p-458v-rh8x/GHSA-v67p-458v-rh8x.json | 8 ++------ .../05/GHSA-v8w3-7f3w-x353/GHSA-v8w3-7f3w-x353.json | 8 ++------ .../05/GHSA-v96c-c8j8-qhm7/GHSA-v96c-c8j8-qhm7.json | 8 ++------ .../05/GHSA-v9mf-j57r-5vpr/GHSA-v9mf-j57r-5vpr.json | 8 ++------ .../05/GHSA-v9vh-7cjg-2wjm/GHSA-v9vh-7cjg-2wjm.json | 8 ++------ .../05/GHSA-v9wx-6724-hmcm/GHSA-v9wx-6724-hmcm.json | 8 ++------ .../05/GHSA-vc66-g998-2h5p/GHSA-vc66-g998-2h5p.json | 12 +++--------- .../05/GHSA-vccr-47hc-ff2r/GHSA-vccr-47hc-ff2r.json | 8 ++------ .../05/GHSA-vcfv-2wp3-p4hq/GHSA-vcfv-2wp3-p4hq.json | 8 ++------ .../05/GHSA-vcqm-hqq4-5mxm/GHSA-vcqm-hqq4-5mxm.json | 8 ++------ .../05/GHSA-vfx7-j9j3-864c/GHSA-vfx7-j9j3-864c.json | 8 ++------ .../05/GHSA-vg65-j6rw-4575/GHSA-vg65-j6rw-4575.json | 12 +++--------- .../05/GHSA-vh92-g5r3-22x9/GHSA-vh92-g5r3-22x9.json | 8 ++------ .../05/GHSA-vhf3-r7x4-jc34/GHSA-vhf3-r7x4-jc34.json | 8 ++------ .../05/GHSA-vjqg-vc39-94mj/GHSA-vjqg-vc39-94mj.json | 12 +++--------- .../05/GHSA-vmcm-jg37-m6m9/GHSA-vmcm-jg37-m6m9.json | 8 ++------ .../05/GHSA-vmhp-2g3x-cwwq/GHSA-vmhp-2g3x-cwwq.json | 8 ++------ .../05/GHSA-vp46-jgwp-q8w3/GHSA-vp46-jgwp-q8w3.json | 8 ++------ .../05/GHSA-vp7f-g57q-p9jx/GHSA-vp7f-g57q-p9jx.json | 4 +--- .../05/GHSA-vp7r-p47m-4jvg/GHSA-vp7r-p47m-4jvg.json | 12 +++--------- .../05/GHSA-vpr2-238v-xc3f/GHSA-vpr2-238v-xc3f.json | 8 ++------ .../05/GHSA-vq42-23mp-rqh2/GHSA-vq42-23mp-rqh2.json | 4 +--- .../05/GHSA-vr5w-372j-c5g6/GHSA-vr5w-372j-c5g6.json | 8 ++------ .../05/GHSA-vrp2-68hc-jc3m/GHSA-vrp2-68hc-jc3m.json | 8 ++------ .../05/GHSA-vvh2-xmj2-jf8r/GHSA-vvh2-xmj2-jf8r.json | 8 ++------ .../05/GHSA-vw67-8g5q-g6f3/GHSA-vw67-8g5q-g6f3.json | 8 ++------ .../05/GHSA-vxw2-5369-q2cg/GHSA-vxw2-5369-q2cg.json | 8 ++------ .../05/GHSA-w259-g563-xw2j/GHSA-w259-g563-xw2j.json | 8 ++------ .../05/GHSA-w3xv-vqgp-pqp7/GHSA-w3xv-vqgp-pqp7.json | 8 ++------ .../05/GHSA-w4rp-w99f-63vq/GHSA-w4rp-w99f-63vq.json | 8 ++------ .../05/GHSA-w4v7-6457-x826/GHSA-w4v7-6457-x826.json | 8 ++------ .../05/GHSA-w4x5-3c4x-9mmc/GHSA-w4x5-3c4x-9mmc.json | 8 ++------ .../05/GHSA-w55r-r9w2-g8ff/GHSA-w55r-r9w2-g8ff.json | 8 ++------ .../05/GHSA-w56g-cw97-958x/GHSA-w56g-cw97-958x.json | 8 ++------ .../05/GHSA-w664-p7q3-cm25/GHSA-w664-p7q3-cm25.json | 8 ++------ .../05/GHSA-w6cg-v47q-5p36/GHSA-w6cg-v47q-5p36.json | 8 ++------ .../05/GHSA-w7cr-rvwx-67q2/GHSA-w7cr-rvwx-67q2.json | 8 ++------ .../05/GHSA-w7fv-r9rg-26jv/GHSA-w7fv-r9rg-26jv.json | 8 ++------ .../05/GHSA-w7qc-fcjr-rrg9/GHSA-w7qc-fcjr-rrg9.json | 8 ++------ .../05/GHSA-w7rv-vxq3-894m/GHSA-w7rv-vxq3-894m.json | 8 ++------ .../05/GHSA-w837-6x9x-3ccv/GHSA-w837-6x9x-3ccv.json | 8 ++------ .../05/GHSA-w9cm-mhh5-jvr7/GHSA-w9cm-mhh5-jvr7.json | 8 ++------ .../05/GHSA-wf5j-wf7x-99jg/GHSA-wf5j-wf7x-99jg.json | 4 +--- .../05/GHSA-wf85-g3p6-xf4h/GHSA-wf85-g3p6-xf4h.json | 8 ++------ .../05/GHSA-wf9q-mxc5-jqf9/GHSA-wf9q-mxc5-jqf9.json | 8 ++------ .../05/GHSA-wfcr-2jqr-mq2c/GHSA-wfcr-2jqr-mq2c.json | 8 ++------ .../05/GHSA-wfwq-hhcq-h62r/GHSA-wfwq-hhcq-h62r.json | 8 ++------ .../05/GHSA-wg6c-hmh5-phq6/GHSA-wg6c-hmh5-phq6.json | 4 +--- .../05/GHSA-wggc-wwp7-29vw/GHSA-wggc-wwp7-29vw.json | 8 ++------ .../05/GHSA-whf5-659f-c55w/GHSA-whf5-659f-c55w.json | 8 ++------ .../05/GHSA-whwp-phv5-w844/GHSA-whwp-phv5-w844.json | 8 ++------ .../05/GHSA-whxp-588c-mcgq/GHSA-whxp-588c-mcgq.json | 8 ++------ .../05/GHSA-wj48-f7rr-8fm2/GHSA-wj48-f7rr-8fm2.json | 8 ++------ .../05/GHSA-wjp8-43wv-mq9c/GHSA-wjp8-43wv-mq9c.json | 8 ++------ .../05/GHSA-wjx5-v4h6-vg36/GHSA-wjx5-v4h6-vg36.json | 8 ++------ .../05/GHSA-wm4j-739m-prwh/GHSA-wm4j-739m-prwh.json | 8 ++------ .../05/GHSA-wmp5-r8m4-q4rf/GHSA-wmp5-r8m4-q4rf.json | 8 ++------ .../05/GHSA-wmxq-cjwf-h4w6/GHSA-wmxq-cjwf-h4w6.json | 8 ++------ .../05/GHSA-wp96-g7r8-wxf4/GHSA-wp96-g7r8-wxf4.json | 8 ++------ .../05/GHSA-wpf8-7mm6-jvgg/GHSA-wpf8-7mm6-jvgg.json | 8 ++------ .../05/GHSA-wpjg-4663-xp87/GHSA-wpjg-4663-xp87.json | 8 ++------ .../05/GHSA-wrc6-j5cv-23xc/GHSA-wrc6-j5cv-23xc.json | 8 ++------ .../05/GHSA-wrwc-95g6-4fm3/GHSA-wrwc-95g6-4fm3.json | 4 +--- .../05/GHSA-wv62-pfmm-x787/GHSA-wv62-pfmm-x787.json | 8 ++------ .../05/GHSA-wvgq-535m-4v9q/GHSA-wvgq-535m-4v9q.json | 8 ++------ .../05/GHSA-wvmj-h4cr-4hm5/GHSA-wvmj-h4cr-4hm5.json | 8 ++------ .../05/GHSA-wvqx-p547-9g79/GHSA-wvqx-p547-9g79.json | 4 +--- .../05/GHSA-wvrc-g9x3-j4vp/GHSA-wvrc-g9x3-j4vp.json | 12 +++--------- .../05/GHSA-x2mc-h9jg-q83c/GHSA-x2mc-h9jg-q83c.json | 8 ++------ .../05/GHSA-x4v5-j466-v6ph/GHSA-x4v5-j466-v6ph.json | 12 +++--------- .../05/GHSA-x5fh-cqhm-x62g/GHSA-x5fh-cqhm-x62g.json | 8 ++------ .../05/GHSA-x5v9-pwhj-pwmx/GHSA-x5v9-pwhj-pwmx.json | 12 +++--------- .../05/GHSA-x697-2xrm-fh6r/GHSA-x697-2xrm-fh6r.json | 8 ++------ .../05/GHSA-x6hc-2whc-99qv/GHSA-x6hc-2whc-99qv.json | 8 ++------ .../05/GHSA-x6mh-cwpq-vw2f/GHSA-x6mh-cwpq-vw2f.json | 8 ++------ .../05/GHSA-x6w9-f57m-rh5h/GHSA-x6w9-f57m-rh5h.json | 8 ++------ .../05/GHSA-x993-24wq-x7c4/GHSA-x993-24wq-x7c4.json | 8 ++------ .../05/GHSA-xcvh-gw38-q5j4/GHSA-xcvh-gw38-q5j4.json | 4 +--- .../05/GHSA-xfpf-x83h-3xxj/GHSA-xfpf-x83h-3xxj.json | 8 ++------ .../05/GHSA-xfr6-j4fr-qr42/GHSA-xfr6-j4fr-qr42.json | 8 ++------ .../05/GHSA-xg2h-6837-gq97/GHSA-xg2h-6837-gq97.json | 8 ++------ .../05/GHSA-xh5j-7f7g-7g5c/GHSA-xh5j-7f7g-7g5c.json | 8 ++------ .../05/GHSA-xm3x-2cx4-fh5j/GHSA-xm3x-2cx4-fh5j.json | 8 ++------ .../05/GHSA-xm7q-pmpg-2fgh/GHSA-xm7q-pmpg-2fgh.json | 8 ++------ .../05/GHSA-xpm4-75c2-wrgc/GHSA-xpm4-75c2-wrgc.json | 8 ++------ .../05/GHSA-xpp6-cm2v-hmmg/GHSA-xpp6-cm2v-hmmg.json | 8 ++------ .../05/GHSA-xprx-5rcx-fjcv/GHSA-xprx-5rcx-fjcv.json | 8 ++------ .../05/GHSA-xrrg-g9h8-vr6w/GHSA-xrrg-g9h8-vr6w.json | 8 ++------ .../05/GHSA-xv45-rrwp-wgf4/GHSA-xv45-rrwp-wgf4.json | 8 ++------ .../05/GHSA-xv4r-prr7-qwvx/GHSA-xv4r-prr7-qwvx.json | 8 ++------ .../05/GHSA-xv6f-5jw7-pmw8/GHSA-xv6f-5jw7-pmw8.json | 8 ++------ .../05/GHSA-xwgf-pv23-3mwx/GHSA-xwgf-pv23-3mwx.json | 8 ++------ .../05/GHSA-xwrh-p54h-h89c/GHSA-xwrh-p54h-h89c.json | 8 ++------ .../05/GHSA-xx27-x5jh-mcrm/GHSA-xx27-x5jh-mcrm.json | 8 ++------ .../05/GHSA-xxrm-mm6r-v5x3/GHSA-xxrm-mm6r-v5x3.json | 8 ++------ .../10/GHSA-7xh6-c3pp-j98r/GHSA-7xh6-c3pp-j98r.json | 4 +--- .../10/GHSA-fqpx-62jv-7r6r/GHSA-fqpx-62jv-7r6r.json | 4 +--- .../10/GHSA-jr2r-wpvw-6j23/GHSA-jr2r-wpvw-6j23.json | 4 +--- .../10/GHSA-m3hq-grv6-h853/GHSA-m3hq-grv6-h853.json | 4 +--- .../10/GHSA-x8jh-7xwf-ghj2/GHSA-x8jh-7xwf-ghj2.json | 4 +--- .../01/GHSA-86j9-qmrw-64jx/GHSA-86j9-qmrw-64jx.json | 4 +--- .../01/GHSA-g7w4-828g-mrpg/GHSA-g7w4-828g-mrpg.json | 4 +--- .../01/GHSA-jg35-qfcc-j9gj/GHSA-jg35-qfcc-j9gj.json | 8 ++------ .../01/GHSA-mcqq-vx7f-6ffh/GHSA-mcqq-vx7f-6ffh.json | 4 +--- .../04/GHSA-rgjq-f6gr-756j/GHSA-rgjq-f6gr-756j.json | 4 +--- .../05/GHSA-5cww-gpqh-ggqj/GHSA-5cww-gpqh-ggqj.json | 4 +--- .../05/GHSA-68gq-fqpm-jw4j/GHSA-68gq-fqpm-jw4j.json | 8 ++------ .../05/GHSA-7797-6fvm-v8xw/GHSA-7797-6fvm-v8xw.json | 4 +--- .../05/GHSA-9gjv-mqxv-j44m/GHSA-9gjv-mqxv-j44m.json | 4 +--- .../05/GHSA-c4fp-wmv9-q4cr/GHSA-c4fp-wmv9-q4cr.json | 4 +--- .../05/GHSA-j5rv-3m5p-q6rc/GHSA-j5rv-3m5p-q6rc.json | 4 +--- .../06/GHSA-68g3-2p3g-w9pq/GHSA-68g3-2p3g-w9pq.json | 4 +--- .../06/GHSA-888h-rm2r-vrc7/GHSA-888h-rm2r-vrc7.json | 4 +--- .../06/GHSA-rxx3-4978-3cc9/GHSA-rxx3-4978-3cc9.json | 4 +--- .../06/GHSA-wf52-5wvv-68vv/GHSA-wf52-5wvv-68vv.json | 4 +--- .../08/GHSA-5qcr-q6p5-3jp9/GHSA-5qcr-q6p5-3jp9.json | 4 +--- .../08/GHSA-qrgg-mgwx-hq8f/GHSA-qrgg-mgwx-hq8f.json | 4 +--- .../08/GHSA-xjvv-5w4r-hfmv/GHSA-xjvv-5w4r-hfmv.json | 4 +--- .../09/GHSA-3q5q-8rwq-gwp8/GHSA-3q5q-8rwq-gwp8.json | 4 +--- .../09/GHSA-892h-r6cr-53g4/GHSA-892h-r6cr-53g4.json | 4 +--- .../09/GHSA-8jhw-fpw9-r227/GHSA-8jhw-fpw9-r227.json | 4 +--- .../09/GHSA-c9xj-rf55-c64g/GHSA-c9xj-rf55-c64g.json | 4 +--- .../09/GHSA-g7f2-f4hp-4hmj/GHSA-g7f2-f4hp-4hmj.json | 8 ++------ .../09/GHSA-h69c-wjc7-8h9r/GHSA-h69c-wjc7-8h9r.json | 4 +--- .../09/GHSA-rxv8-v965-v333/GHSA-rxv8-v965-v333.json | 4 +--- .../09/GHSA-vq7j-gx56-rxjh/GHSA-vq7j-gx56-rxjh.json | 4 +--- .../09/GHSA-vv9m-32rr-3g55/GHSA-vv9m-32rr-3g55.json | 4 +--- .../10/GHSA-pcx2-r23v-3j7c/GHSA-pcx2-r23v-3j7c.json | 4 +--- .../12/GHSA-hw83-99pm-pwrr/GHSA-hw83-99pm-pwrr.json | 4 +--- .../02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json | 8 ++------ .../02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json | 8 ++------ .../04/GHSA-26mf-52p6-23pq/GHSA-26mf-52p6-23pq.json | 8 ++------ .../04/GHSA-273j-fjrx-gf2f/GHSA-273j-fjrx-gf2f.json | 8 ++------ .../04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json | 8 ++------ .../04/GHSA-3q47-w545-wgfv/GHSA-3q47-w545-wgfv.json | 8 ++------ .../04/GHSA-3v95-qw2c-cq5p/GHSA-3v95-qw2c-cq5p.json | 4 +--- .../04/GHSA-4cjh-m2w7-xg99/GHSA-4cjh-m2w7-xg99.json | 8 ++------ .../04/GHSA-55g5-m7rx-jf99/GHSA-55g5-m7rx-jf99.json | 8 ++------ .../04/GHSA-5xq9-rcpj-p52v/GHSA-5xq9-rcpj-p52v.json | 8 ++------ .../04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json | 8 ++------ .../04/GHSA-6qf6-cmc3-h6x2/GHSA-6qf6-cmc3-h6x2.json | 8 ++------ .../04/GHSA-7jxx-p3jr-r2x9/GHSA-7jxx-p3jr-r2x9.json | 8 ++------ .../04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json | 8 ++------ .../04/GHSA-8x4w-7h9g-pg2q/GHSA-8x4w-7h9g-pg2q.json | 8 ++------ .../04/GHSA-9cw3-8wpf-rpmg/GHSA-9cw3-8wpf-rpmg.json | 8 ++------ .../04/GHSA-9x55-44vc-363x/GHSA-9x55-44vc-363x.json | 4 +--- .../04/GHSA-gj63-qcjc-2fcw/GHSA-gj63-qcjc-2fcw.json | 8 ++------ .../04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json | 12 +++--------- .../04/GHSA-hcf3-w2q6-29cf/GHSA-hcf3-w2q6-29cf.json | 8 ++------ .../04/GHSA-hcm7-xw9m-99cx/GHSA-hcm7-xw9m-99cx.json | 8 ++------ .../04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json | 8 ++------ .../04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json | 4 +--- .../04/GHSA-jfv3-gh3j-c5r7/GHSA-jfv3-gh3j-c5r7.json | 8 ++------ .../04/GHSA-jmgx-64x4-v838/GHSA-jmgx-64x4-v838.json | 8 ++------ .../04/GHSA-mppc-j8fq-9mvg/GHSA-mppc-j8fq-9mvg.json | 12 +++--------- .../04/GHSA-pj4r-r8f8-qmcc/GHSA-pj4r-r8f8-qmcc.json | 4 +--- .../04/GHSA-pprv-m73j-58qg/GHSA-pprv-m73j-58qg.json | 8 ++------ .../04/GHSA-q66w-qfxv-vpx3/GHSA-q66w-qfxv-vpx3.json | 8 ++------ .../04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json | 8 ++------ .../04/GHSA-w8q4-gvf3-wvfq/GHSA-w8q4-gvf3-wvfq.json | 4 +--- .../04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json | 8 ++------ .../04/GHSA-wv9c-r7wv-3wph/GHSA-wv9c-r7wv-3wph.json | 4 +--- .../04/GHSA-x78r-qrp5-rmmf/GHSA-x78r-qrp5-rmmf.json | 4 +--- .../04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json | 8 ++------ .../06/GHSA-3qp4-cvq4-28r4/GHSA-3qp4-cvq4-28r4.json | 4 +--- .../06/GHSA-59h7-wrc6-2235/GHSA-59h7-wrc6-2235.json | 12 +++--------- .../06/GHSA-64f4-8h54-qf3g/GHSA-64f4-8h54-qf3g.json | 4 +--- .../06/GHSA-6c4c-5hcj-j9pj/GHSA-6c4c-5hcj-j9pj.json | 4 +--- .../06/GHSA-8j5r-4pfg-8q95/GHSA-8j5r-4pfg-8q95.json | 4 +--- .../06/GHSA-8qw7-56rp-hj8x/GHSA-8qw7-56rp-hj8x.json | 4 +--- .../06/GHSA-9hrm-g973-phrr/GHSA-9hrm-g973-phrr.json | 8 ++------ .../06/GHSA-f7c9-x7pc-54xj/GHSA-f7c9-x7pc-54xj.json | 4 +--- .../06/GHSA-g88v-q4m5-mhpr/GHSA-g88v-q4m5-mhpr.json | 12 +++--------- .../06/GHSA-jww8-w6cf-vwpg/GHSA-jww8-w6cf-vwpg.json | 4 +--- .../06/GHSA-mh63-325c-chrf/GHSA-mh63-325c-chrf.json | 4 +--- .../06/GHSA-qhx6-9fwx-wcfm/GHSA-qhx6-9fwx-wcfm.json | 4 +--- .../06/GHSA-rm55-jfvw-6g3r/GHSA-rm55-jfvw-6g3r.json | 4 +--- .../06/GHSA-v9pc-cxpw-3jr5/GHSA-v9pc-cxpw-3jr5.json | 12 +++--------- .../06/GHSA-w9f6-jf9g-658h/GHSA-w9f6-jf9g-658h.json | 4 +--- .../06/GHSA-x3q8-8r5q-xrq8/GHSA-x3q8-8r5q-xrq8.json | 4 +--- 970 files changed, 2010 insertions(+), 6030 deletions(-) diff --git a/advisories/github-reviewed/2024/06/GHSA-hjx6-f647-mvf9/GHSA-hjx6-f647-mvf9.json b/advisories/github-reviewed/2024/06/GHSA-hjx6-f647-mvf9/GHSA-hjx6-f647-mvf9.json index de1b057bf25..35650920b87 100644 --- a/advisories/github-reviewed/2024/06/GHSA-hjx6-f647-mvf9/GHSA-hjx6-f647-mvf9.json +++ b/advisories/github-reviewed/2024/06/GHSA-hjx6-f647-mvf9/GHSA-hjx6-f647-mvf9.json @@ -3,9 +3,7 @@ "id": "GHSA-hjx6-f647-mvf9", "modified": "2024-06-12T19:43:04Z", "published": "2024-06-12T19:43:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "Invenio-Communities has a Cross-Site Scripting (XSS) vulnerability in React components", "details": "# Impact\n\nWe have identified a Cross-Site Scripting (XSS) vulnerability within certain React components related to community members in the Invenio-Communities module. This vulnerability enables a user to inject a script tag into the Affiliations field during the account registration process. The malicious script is executed when the user creates a new community and is listed as a public member.\n\nThe script is triggered whenever any user visits the Members section of any community that includes the compromised user. This can potentially allow the attacker to access personal information, such as cookies, of the visiting user.\n\n# Patches\nThe problem has been patched in [v7.8.0](https://github.com/inveniosoftware/invenio-communities/releases/tag/v7.8.0). Patches also have been backported in versions [v4.2.2](https://github.com/inveniosoftware/invenio-communities/tree/v4.2.2) and [v2.8.11](https://github.com/inveniosoftware/invenio-communities/tree/v2.8.11).\n\n# Credits\n\nThanks to [Twitter.com/AliGoodLuck11](https://x.com/AliGoodLuck11) for reporting the vulnerability with a detailed description on how to reproduce it!\n\n# For more information\nIf you have any questions or comments about this advisory:\n\nEmail us at [info@inveniosoftware.org](mailto:info@inveniosoftware.org)\n", "severity": [ diff --git a/advisories/unreviewed/2022/03/GHSA-285f-ccx8-rrvp/GHSA-285f-ccx8-rrvp.json b/advisories/unreviewed/2022/03/GHSA-285f-ccx8-rrvp/GHSA-285f-ccx8-rrvp.json index 93f676d47b8..7f02e64bd14 100644 --- a/advisories/unreviewed/2022/03/GHSA-285f-ccx8-rrvp/GHSA-285f-ccx8-rrvp.json +++ b/advisories/unreviewed/2022/03/GHSA-285f-ccx8-rrvp/GHSA-285f-ccx8-rrvp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-364v-6m73-qv4g/GHSA-364v-6m73-qv4g.json b/advisories/unreviewed/2022/03/GHSA-364v-6m73-qv4g/GHSA-364v-6m73-qv4g.json index 5c989535502..d939ef75112 100644 --- a/advisories/unreviewed/2022/03/GHSA-364v-6m73-qv4g/GHSA-364v-6m73-qv4g.json +++ b/advisories/unreviewed/2022/03/GHSA-364v-6m73-qv4g/GHSA-364v-6m73-qv4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-3p6p-69fx-rphw/GHSA-3p6p-69fx-rphw.json b/advisories/unreviewed/2022/03/GHSA-3p6p-69fx-rphw/GHSA-3p6p-69fx-rphw.json index bf5e48fcb2d..4ece74d9577 100644 --- a/advisories/unreviewed/2022/03/GHSA-3p6p-69fx-rphw/GHSA-3p6p-69fx-rphw.json +++ b/advisories/unreviewed/2022/03/GHSA-3p6p-69fx-rphw/GHSA-3p6p-69fx-rphw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-4985-wch3-93jr/GHSA-4985-wch3-93jr.json b/advisories/unreviewed/2022/03/GHSA-4985-wch3-93jr/GHSA-4985-wch3-93jr.json index 43a49b12765..838f1b8aa26 100644 --- a/advisories/unreviewed/2022/03/GHSA-4985-wch3-93jr/GHSA-4985-wch3-93jr.json +++ b/advisories/unreviewed/2022/03/GHSA-4985-wch3-93jr/GHSA-4985-wch3-93jr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-4m4q-85vx-69pj/GHSA-4m4q-85vx-69pj.json b/advisories/unreviewed/2022/03/GHSA-4m4q-85vx-69pj/GHSA-4m4q-85vx-69pj.json index 4029f653ef7..c0ce3a6cabd 100644 --- a/advisories/unreviewed/2022/03/GHSA-4m4q-85vx-69pj/GHSA-4m4q-85vx-69pj.json +++ b/advisories/unreviewed/2022/03/GHSA-4m4q-85vx-69pj/GHSA-4m4q-85vx-69pj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-54hx-qqpw-43w9/GHSA-54hx-qqpw-43w9.json b/advisories/unreviewed/2022/03/GHSA-54hx-qqpw-43w9/GHSA-54hx-qqpw-43w9.json index 7447c1c6346..b642d7deaea 100644 --- a/advisories/unreviewed/2022/03/GHSA-54hx-qqpw-43w9/GHSA-54hx-qqpw-43w9.json +++ b/advisories/unreviewed/2022/03/GHSA-54hx-qqpw-43w9/GHSA-54hx-qqpw-43w9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-56vq-m685-pfgq/GHSA-56vq-m685-pfgq.json b/advisories/unreviewed/2022/03/GHSA-56vq-m685-pfgq/GHSA-56vq-m685-pfgq.json index 35f758c51e0..cf8ed973238 100644 --- a/advisories/unreviewed/2022/03/GHSA-56vq-m685-pfgq/GHSA-56vq-m685-pfgq.json +++ b/advisories/unreviewed/2022/03/GHSA-56vq-m685-pfgq/GHSA-56vq-m685-pfgq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-586w-pwc3-98vf/GHSA-586w-pwc3-98vf.json b/advisories/unreviewed/2022/03/GHSA-586w-pwc3-98vf/GHSA-586w-pwc3-98vf.json index c642adfef6f..041ad7f5627 100644 --- a/advisories/unreviewed/2022/03/GHSA-586w-pwc3-98vf/GHSA-586w-pwc3-98vf.json +++ b/advisories/unreviewed/2022/03/GHSA-586w-pwc3-98vf/GHSA-586w-pwc3-98vf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-5pf6-9wpm-6x32/GHSA-5pf6-9wpm-6x32.json b/advisories/unreviewed/2022/03/GHSA-5pf6-9wpm-6x32/GHSA-5pf6-9wpm-6x32.json index 8d4d4f9792a..2b36caa30c4 100644 --- a/advisories/unreviewed/2022/03/GHSA-5pf6-9wpm-6x32/GHSA-5pf6-9wpm-6x32.json +++ b/advisories/unreviewed/2022/03/GHSA-5pf6-9wpm-6x32/GHSA-5pf6-9wpm-6x32.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-6946-m5h6-646g/GHSA-6946-m5h6-646g.json b/advisories/unreviewed/2022/03/GHSA-6946-m5h6-646g/GHSA-6946-m5h6-646g.json index efba9386d72..316c8567b4f 100644 --- a/advisories/unreviewed/2022/03/GHSA-6946-m5h6-646g/GHSA-6946-m5h6-646g.json +++ b/advisories/unreviewed/2022/03/GHSA-6946-m5h6-646g/GHSA-6946-m5h6-646g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-6m6p-38qr-9hqw/GHSA-6m6p-38qr-9hqw.json b/advisories/unreviewed/2022/03/GHSA-6m6p-38qr-9hqw/GHSA-6m6p-38qr-9hqw.json index 53d64bcb816..7153a096b98 100644 --- a/advisories/unreviewed/2022/03/GHSA-6m6p-38qr-9hqw/GHSA-6m6p-38qr-9hqw.json +++ b/advisories/unreviewed/2022/03/GHSA-6m6p-38qr-9hqw/GHSA-6m6p-38qr-9hqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-7p6g-c4hm-6rg9/GHSA-7p6g-c4hm-6rg9.json b/advisories/unreviewed/2022/03/GHSA-7p6g-c4hm-6rg9/GHSA-7p6g-c4hm-6rg9.json index 407186691e5..fd2ab4637bf 100644 --- a/advisories/unreviewed/2022/03/GHSA-7p6g-c4hm-6rg9/GHSA-7p6g-c4hm-6rg9.json +++ b/advisories/unreviewed/2022/03/GHSA-7p6g-c4hm-6rg9/GHSA-7p6g-c4hm-6rg9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-823h-69v3-2v2f/GHSA-823h-69v3-2v2f.json b/advisories/unreviewed/2022/03/GHSA-823h-69v3-2v2f/GHSA-823h-69v3-2v2f.json index 60b2d3b3d31..04a49318f6e 100644 --- a/advisories/unreviewed/2022/03/GHSA-823h-69v3-2v2f/GHSA-823h-69v3-2v2f.json +++ b/advisories/unreviewed/2022/03/GHSA-823h-69v3-2v2f/GHSA-823h-69v3-2v2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-85p5-q2pf-xrcr/GHSA-85p5-q2pf-xrcr.json b/advisories/unreviewed/2022/03/GHSA-85p5-q2pf-xrcr/GHSA-85p5-q2pf-xrcr.json index 6849be0776b..5c11b9e7645 100644 --- a/advisories/unreviewed/2022/03/GHSA-85p5-q2pf-xrcr/GHSA-85p5-q2pf-xrcr.json +++ b/advisories/unreviewed/2022/03/GHSA-85p5-q2pf-xrcr/GHSA-85p5-q2pf-xrcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-8gvv-h2j2-gq6f/GHSA-8gvv-h2j2-gq6f.json b/advisories/unreviewed/2022/03/GHSA-8gvv-h2j2-gq6f/GHSA-8gvv-h2j2-gq6f.json index cab8a45b0c9..465d6822282 100644 --- a/advisories/unreviewed/2022/03/GHSA-8gvv-h2j2-gq6f/GHSA-8gvv-h2j2-gq6f.json +++ b/advisories/unreviewed/2022/03/GHSA-8gvv-h2j2-gq6f/GHSA-8gvv-h2j2-gq6f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-8pmq-fh43-m3pq/GHSA-8pmq-fh43-m3pq.json b/advisories/unreviewed/2022/03/GHSA-8pmq-fh43-m3pq/GHSA-8pmq-fh43-m3pq.json index 87df5182656..ca235b81c74 100644 --- a/advisories/unreviewed/2022/03/GHSA-8pmq-fh43-m3pq/GHSA-8pmq-fh43-m3pq.json +++ b/advisories/unreviewed/2022/03/GHSA-8pmq-fh43-m3pq/GHSA-8pmq-fh43-m3pq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-8r95-ggqq-rp99/GHSA-8r95-ggqq-rp99.json b/advisories/unreviewed/2022/03/GHSA-8r95-ggqq-rp99/GHSA-8r95-ggqq-rp99.json index e9d915ef211..de3493be7d9 100644 --- a/advisories/unreviewed/2022/03/GHSA-8r95-ggqq-rp99/GHSA-8r95-ggqq-rp99.json +++ b/advisories/unreviewed/2022/03/GHSA-8r95-ggqq-rp99/GHSA-8r95-ggqq-rp99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-93xr-277q-vq2q/GHSA-93xr-277q-vq2q.json b/advisories/unreviewed/2022/03/GHSA-93xr-277q-vq2q/GHSA-93xr-277q-vq2q.json index 76e083fc488..71ce45e658e 100644 --- a/advisories/unreviewed/2022/03/GHSA-93xr-277q-vq2q/GHSA-93xr-277q-vq2q.json +++ b/advisories/unreviewed/2022/03/GHSA-93xr-277q-vq2q/GHSA-93xr-277q-vq2q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-98rg-6g94-9qp6/GHSA-98rg-6g94-9qp6.json b/advisories/unreviewed/2022/03/GHSA-98rg-6g94-9qp6/GHSA-98rg-6g94-9qp6.json index cc3de377b06..25a54f8c96e 100644 --- a/advisories/unreviewed/2022/03/GHSA-98rg-6g94-9qp6/GHSA-98rg-6g94-9qp6.json +++ b/advisories/unreviewed/2022/03/GHSA-98rg-6g94-9qp6/GHSA-98rg-6g94-9qp6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-9fvc-c86x-ggw4/GHSA-9fvc-c86x-ggw4.json b/advisories/unreviewed/2022/03/GHSA-9fvc-c86x-ggw4/GHSA-9fvc-c86x-ggw4.json index fb6eb1545ae..b78e0474a3f 100644 --- a/advisories/unreviewed/2022/03/GHSA-9fvc-c86x-ggw4/GHSA-9fvc-c86x-ggw4.json +++ b/advisories/unreviewed/2022/03/GHSA-9fvc-c86x-ggw4/GHSA-9fvc-c86x-ggw4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-9hc8-qfq9-mhvp/GHSA-9hc8-qfq9-mhvp.json b/advisories/unreviewed/2022/03/GHSA-9hc8-qfq9-mhvp/GHSA-9hc8-qfq9-mhvp.json index 8a1fb666765..3a038745cc4 100644 --- a/advisories/unreviewed/2022/03/GHSA-9hc8-qfq9-mhvp/GHSA-9hc8-qfq9-mhvp.json +++ b/advisories/unreviewed/2022/03/GHSA-9hc8-qfq9-mhvp/GHSA-9hc8-qfq9-mhvp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-9p9h-ch93-4hfr/GHSA-9p9h-ch93-4hfr.json b/advisories/unreviewed/2022/03/GHSA-9p9h-ch93-4hfr/GHSA-9p9h-ch93-4hfr.json index 2d0f1f102b0..aada756f663 100644 --- a/advisories/unreviewed/2022/03/GHSA-9p9h-ch93-4hfr/GHSA-9p9h-ch93-4hfr.json +++ b/advisories/unreviewed/2022/03/GHSA-9p9h-ch93-4hfr/GHSA-9p9h-ch93-4hfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-c47g-vg34-vp63/GHSA-c47g-vg34-vp63.json b/advisories/unreviewed/2022/03/GHSA-c47g-vg34-vp63/GHSA-c47g-vg34-vp63.json index a2c3353af00..5b9e2140ee6 100644 --- a/advisories/unreviewed/2022/03/GHSA-c47g-vg34-vp63/GHSA-c47g-vg34-vp63.json +++ b/advisories/unreviewed/2022/03/GHSA-c47g-vg34-vp63/GHSA-c47g-vg34-vp63.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-cw72-cqmc-6g9v/GHSA-cw72-cqmc-6g9v.json b/advisories/unreviewed/2022/03/GHSA-cw72-cqmc-6g9v/GHSA-cw72-cqmc-6g9v.json index 8ce1205e1c7..76e45c0877d 100644 --- a/advisories/unreviewed/2022/03/GHSA-cw72-cqmc-6g9v/GHSA-cw72-cqmc-6g9v.json +++ b/advisories/unreviewed/2022/03/GHSA-cw72-cqmc-6g9v/GHSA-cw72-cqmc-6g9v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-fwqp-wm97-mvcp/GHSA-fwqp-wm97-mvcp.json b/advisories/unreviewed/2022/03/GHSA-fwqp-wm97-mvcp/GHSA-fwqp-wm97-mvcp.json index d5da8470533..346c3048bec 100644 --- a/advisories/unreviewed/2022/03/GHSA-fwqp-wm97-mvcp/GHSA-fwqp-wm97-mvcp.json +++ b/advisories/unreviewed/2022/03/GHSA-fwqp-wm97-mvcp/GHSA-fwqp-wm97-mvcp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-g4vr-fpgw-9fff/GHSA-g4vr-fpgw-9fff.json b/advisories/unreviewed/2022/03/GHSA-g4vr-fpgw-9fff/GHSA-g4vr-fpgw-9fff.json index e05d05cb63a..d6c1d460ba3 100644 --- a/advisories/unreviewed/2022/03/GHSA-g4vr-fpgw-9fff/GHSA-g4vr-fpgw-9fff.json +++ b/advisories/unreviewed/2022/03/GHSA-g4vr-fpgw-9fff/GHSA-g4vr-fpgw-9fff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-g664-p9gv-7fw8/GHSA-g664-p9gv-7fw8.json b/advisories/unreviewed/2022/03/GHSA-g664-p9gv-7fw8/GHSA-g664-p9gv-7fw8.json index a52900d4c4d..c854e036efc 100644 --- a/advisories/unreviewed/2022/03/GHSA-g664-p9gv-7fw8/GHSA-g664-p9gv-7fw8.json +++ b/advisories/unreviewed/2022/03/GHSA-g664-p9gv-7fw8/GHSA-g664-p9gv-7fw8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-gwhc-2vxp-pjmv/GHSA-gwhc-2vxp-pjmv.json b/advisories/unreviewed/2022/03/GHSA-gwhc-2vxp-pjmv/GHSA-gwhc-2vxp-pjmv.json index 4758f666d6e..f3abdfc772c 100644 --- a/advisories/unreviewed/2022/03/GHSA-gwhc-2vxp-pjmv/GHSA-gwhc-2vxp-pjmv.json +++ b/advisories/unreviewed/2022/03/GHSA-gwhc-2vxp-pjmv/GHSA-gwhc-2vxp-pjmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-h3hh-m6r7-4q65/GHSA-h3hh-m6r7-4q65.json b/advisories/unreviewed/2022/03/GHSA-h3hh-m6r7-4q65/GHSA-h3hh-m6r7-4q65.json index 554913c8238..552ddbd6f05 100644 --- a/advisories/unreviewed/2022/03/GHSA-h3hh-m6r7-4q65/GHSA-h3hh-m6r7-4q65.json +++ b/advisories/unreviewed/2022/03/GHSA-h3hh-m6r7-4q65/GHSA-h3hh-m6r7-4q65.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-h5p4-3w39-xhh2/GHSA-h5p4-3w39-xhh2.json b/advisories/unreviewed/2022/03/GHSA-h5p4-3w39-xhh2/GHSA-h5p4-3w39-xhh2.json index dcc1554768d..0b5f0848906 100644 --- a/advisories/unreviewed/2022/03/GHSA-h5p4-3w39-xhh2/GHSA-h5p4-3w39-xhh2.json +++ b/advisories/unreviewed/2022/03/GHSA-h5p4-3w39-xhh2/GHSA-h5p4-3w39-xhh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-hg36-jrxh-5x76/GHSA-hg36-jrxh-5x76.json b/advisories/unreviewed/2022/03/GHSA-hg36-jrxh-5x76/GHSA-hg36-jrxh-5x76.json index c5ce3254c98..2f3d3d49a2f 100644 --- a/advisories/unreviewed/2022/03/GHSA-hg36-jrxh-5x76/GHSA-hg36-jrxh-5x76.json +++ b/advisories/unreviewed/2022/03/GHSA-hg36-jrxh-5x76/GHSA-hg36-jrxh-5x76.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-j7p5-68rj-fv5p/GHSA-j7p5-68rj-fv5p.json b/advisories/unreviewed/2022/03/GHSA-j7p5-68rj-fv5p/GHSA-j7p5-68rj-fv5p.json index 4456564f3a7..4e73159ac4f 100644 --- a/advisories/unreviewed/2022/03/GHSA-j7p5-68rj-fv5p/GHSA-j7p5-68rj-fv5p.json +++ b/advisories/unreviewed/2022/03/GHSA-j7p5-68rj-fv5p/GHSA-j7p5-68rj-fv5p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-p37w-7mr9-5x89/GHSA-p37w-7mr9-5x89.json b/advisories/unreviewed/2022/03/GHSA-p37w-7mr9-5x89/GHSA-p37w-7mr9-5x89.json index be5a06fbf6c..9bc059add0d 100644 --- a/advisories/unreviewed/2022/03/GHSA-p37w-7mr9-5x89/GHSA-p37w-7mr9-5x89.json +++ b/advisories/unreviewed/2022/03/GHSA-p37w-7mr9-5x89/GHSA-p37w-7mr9-5x89.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-p49c-25rw-2mwc/GHSA-p49c-25rw-2mwc.json b/advisories/unreviewed/2022/03/GHSA-p49c-25rw-2mwc/GHSA-p49c-25rw-2mwc.json index 2b8018fe817..20a0bc56dfd 100644 --- a/advisories/unreviewed/2022/03/GHSA-p49c-25rw-2mwc/GHSA-p49c-25rw-2mwc.json +++ b/advisories/unreviewed/2022/03/GHSA-p49c-25rw-2mwc/GHSA-p49c-25rw-2mwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-pw32-vrq6-9pw3/GHSA-pw32-vrq6-9pw3.json b/advisories/unreviewed/2022/03/GHSA-pw32-vrq6-9pw3/GHSA-pw32-vrq6-9pw3.json index 1fc4ec285a0..32fc063cf60 100644 --- a/advisories/unreviewed/2022/03/GHSA-pw32-vrq6-9pw3/GHSA-pw32-vrq6-9pw3.json +++ b/advisories/unreviewed/2022/03/GHSA-pw32-vrq6-9pw3/GHSA-pw32-vrq6-9pw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-q5p3-3mpm-hppr/GHSA-q5p3-3mpm-hppr.json b/advisories/unreviewed/2022/03/GHSA-q5p3-3mpm-hppr/GHSA-q5p3-3mpm-hppr.json index 9c77e11e5b7..9b5ed42e965 100644 --- a/advisories/unreviewed/2022/03/GHSA-q5p3-3mpm-hppr/GHSA-q5p3-3mpm-hppr.json +++ b/advisories/unreviewed/2022/03/GHSA-q5p3-3mpm-hppr/GHSA-q5p3-3mpm-hppr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-qh5q-q7cg-53wf/GHSA-qh5q-q7cg-53wf.json b/advisories/unreviewed/2022/03/GHSA-qh5q-q7cg-53wf/GHSA-qh5q-q7cg-53wf.json index 1ed178a091a..44068d0ea4f 100644 --- a/advisories/unreviewed/2022/03/GHSA-qh5q-q7cg-53wf/GHSA-qh5q-q7cg-53wf.json +++ b/advisories/unreviewed/2022/03/GHSA-qh5q-q7cg-53wf/GHSA-qh5q-q7cg-53wf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-r298-475q-q8x5/GHSA-r298-475q-q8x5.json b/advisories/unreviewed/2022/03/GHSA-r298-475q-q8x5/GHSA-r298-475q-q8x5.json index e08531151d3..05f838fc520 100644 --- a/advisories/unreviewed/2022/03/GHSA-r298-475q-q8x5/GHSA-r298-475q-q8x5.json +++ b/advisories/unreviewed/2022/03/GHSA-r298-475q-q8x5/GHSA-r298-475q-q8x5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-r39c-fhw7-34q8/GHSA-r39c-fhw7-34q8.json b/advisories/unreviewed/2022/03/GHSA-r39c-fhw7-34q8/GHSA-r39c-fhw7-34q8.json index c8c4a20455b..b069ba15a8d 100644 --- a/advisories/unreviewed/2022/03/GHSA-r39c-fhw7-34q8/GHSA-r39c-fhw7-34q8.json +++ b/advisories/unreviewed/2022/03/GHSA-r39c-fhw7-34q8/GHSA-r39c-fhw7-34q8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-rf8f-5xcx-f48m/GHSA-rf8f-5xcx-f48m.json b/advisories/unreviewed/2022/03/GHSA-rf8f-5xcx-f48m/GHSA-rf8f-5xcx-f48m.json index afe52a125e1..8c11e36a620 100644 --- a/advisories/unreviewed/2022/03/GHSA-rf8f-5xcx-f48m/GHSA-rf8f-5xcx-f48m.json +++ b/advisories/unreviewed/2022/03/GHSA-rf8f-5xcx-f48m/GHSA-rf8f-5xcx-f48m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-rhh2-3rph-r2f2/GHSA-rhh2-3rph-r2f2.json b/advisories/unreviewed/2022/03/GHSA-rhh2-3rph-r2f2/GHSA-rhh2-3rph-r2f2.json index 13b2ad4f0f4..76af85680d9 100644 --- a/advisories/unreviewed/2022/03/GHSA-rhh2-3rph-r2f2/GHSA-rhh2-3rph-r2f2.json +++ b/advisories/unreviewed/2022/03/GHSA-rhh2-3rph-r2f2/GHSA-rhh2-3rph-r2f2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-v224-v254-78v2/GHSA-v224-v254-78v2.json b/advisories/unreviewed/2022/03/GHSA-v224-v254-78v2/GHSA-v224-v254-78v2.json index 66f4d4338cb..7fcf638bb2c 100644 --- a/advisories/unreviewed/2022/03/GHSA-v224-v254-78v2/GHSA-v224-v254-78v2.json +++ b/advisories/unreviewed/2022/03/GHSA-v224-v254-78v2/GHSA-v224-v254-78v2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-v5p2-gphf-gp4g/GHSA-v5p2-gphf-gp4g.json b/advisories/unreviewed/2022/03/GHSA-v5p2-gphf-gp4g/GHSA-v5p2-gphf-gp4g.json index 0e46654a24d..3d97ddbcaa7 100644 --- a/advisories/unreviewed/2022/03/GHSA-v5p2-gphf-gp4g/GHSA-v5p2-gphf-gp4g.json +++ b/advisories/unreviewed/2022/03/GHSA-v5p2-gphf-gp4g/GHSA-v5p2-gphf-gp4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-v5vh-45jw-f3fq/GHSA-v5vh-45jw-f3fq.json b/advisories/unreviewed/2022/03/GHSA-v5vh-45jw-f3fq/GHSA-v5vh-45jw-f3fq.json index 3a727e5788c..02de8804147 100644 --- a/advisories/unreviewed/2022/03/GHSA-v5vh-45jw-f3fq/GHSA-v5vh-45jw-f3fq.json +++ b/advisories/unreviewed/2022/03/GHSA-v5vh-45jw-f3fq/GHSA-v5vh-45jw-f3fq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-v8rf-mvwx-cx29/GHSA-v8rf-mvwx-cx29.json b/advisories/unreviewed/2022/03/GHSA-v8rf-mvwx-cx29/GHSA-v8rf-mvwx-cx29.json index 6707782f002..2f9b8321653 100644 --- a/advisories/unreviewed/2022/03/GHSA-v8rf-mvwx-cx29/GHSA-v8rf-mvwx-cx29.json +++ b/advisories/unreviewed/2022/03/GHSA-v8rf-mvwx-cx29/GHSA-v8rf-mvwx-cx29.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-vcw5-gvqx-q633/GHSA-vcw5-gvqx-q633.json b/advisories/unreviewed/2022/03/GHSA-vcw5-gvqx-q633/GHSA-vcw5-gvqx-q633.json index 3936be6eb52..9a90e189874 100644 --- a/advisories/unreviewed/2022/03/GHSA-vcw5-gvqx-q633/GHSA-vcw5-gvqx-q633.json +++ b/advisories/unreviewed/2022/03/GHSA-vcw5-gvqx-q633/GHSA-vcw5-gvqx-q633.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-wqqg-j8m9-9rcc/GHSA-wqqg-j8m9-9rcc.json b/advisories/unreviewed/2022/03/GHSA-wqqg-j8m9-9rcc/GHSA-wqqg-j8m9-9rcc.json index 29afe93cc27..a60f0d65059 100644 --- a/advisories/unreviewed/2022/03/GHSA-wqqg-j8m9-9rcc/GHSA-wqqg-j8m9-9rcc.json +++ b/advisories/unreviewed/2022/03/GHSA-wqqg-j8m9-9rcc/GHSA-wqqg-j8m9-9rcc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-x65p-q2x9-3hcj/GHSA-x65p-q2x9-3hcj.json b/advisories/unreviewed/2022/03/GHSA-x65p-q2x9-3hcj/GHSA-x65p-q2x9-3hcj.json index 1eca9c76b06..2c701e4ee47 100644 --- a/advisories/unreviewed/2022/03/GHSA-x65p-q2x9-3hcj/GHSA-x65p-q2x9-3hcj.json +++ b/advisories/unreviewed/2022/03/GHSA-x65p-q2x9-3hcj/GHSA-x65p-q2x9-3hcj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-xmfv-pp4r-x7rf/GHSA-xmfv-pp4r-x7rf.json b/advisories/unreviewed/2022/03/GHSA-xmfv-pp4r-x7rf/GHSA-xmfv-pp4r-x7rf.json index a9b6c6ea4fb..7dc1344e4e2 100644 --- a/advisories/unreviewed/2022/03/GHSA-xmfv-pp4r-x7rf/GHSA-xmfv-pp4r-x7rf.json +++ b/advisories/unreviewed/2022/03/GHSA-xmfv-pp4r-x7rf/GHSA-xmfv-pp4r-x7rf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-24r6-29j2-hrjv/GHSA-24r6-29j2-hrjv.json b/advisories/unreviewed/2022/04/GHSA-24r6-29j2-hrjv/GHSA-24r6-29j2-hrjv.json index ec0fb725913..52452f6151a 100644 --- a/advisories/unreviewed/2022/04/GHSA-24r6-29j2-hrjv/GHSA-24r6-29j2-hrjv.json +++ b/advisories/unreviewed/2022/04/GHSA-24r6-29j2-hrjv/GHSA-24r6-29j2-hrjv.json @@ -7,12 +7,8 @@ "CVE-2000-0645" ], "details": "WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-25pv-5r6h-55j6/GHSA-25pv-5r6h-55j6.json b/advisories/unreviewed/2022/04/GHSA-25pv-5r6h-55j6/GHSA-25pv-5r6h-55j6.json index e60be6259f5..f93fc722e62 100644 --- a/advisories/unreviewed/2022/04/GHSA-25pv-5r6h-55j6/GHSA-25pv-5r6h-55j6.json +++ b/advisories/unreviewed/2022/04/GHSA-25pv-5r6h-55j6/GHSA-25pv-5r6h-55j6.json @@ -7,12 +7,8 @@ "CVE-2000-0650" ], "details": "The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-25r5-69f6-hgcg/GHSA-25r5-69f6-hgcg.json b/advisories/unreviewed/2022/04/GHSA-25r5-69f6-hgcg/GHSA-25r5-69f6-hgcg.json index bc00671bc6a..51a9eb83091 100644 --- a/advisories/unreviewed/2022/04/GHSA-25r5-69f6-hgcg/GHSA-25r5-69f6-hgcg.json +++ b/advisories/unreviewed/2022/04/GHSA-25r5-69f6-hgcg/GHSA-25r5-69f6-hgcg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-26m2-987p-rmm4/GHSA-26m2-987p-rmm4.json b/advisories/unreviewed/2022/04/GHSA-26m2-987p-rmm4/GHSA-26m2-987p-rmm4.json index fc89d1ec789..54fbced44e9 100644 --- a/advisories/unreviewed/2022/04/GHSA-26m2-987p-rmm4/GHSA-26m2-987p-rmm4.json +++ b/advisories/unreviewed/2022/04/GHSA-26m2-987p-rmm4/GHSA-26m2-987p-rmm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-28m9-8pxg-9chc/GHSA-28m9-8pxg-9chc.json b/advisories/unreviewed/2022/04/GHSA-28m9-8pxg-9chc/GHSA-28m9-8pxg-9chc.json index 9d9c364c94e..d59d6ab7cf5 100644 --- a/advisories/unreviewed/2022/04/GHSA-28m9-8pxg-9chc/GHSA-28m9-8pxg-9chc.json +++ b/advisories/unreviewed/2022/04/GHSA-28m9-8pxg-9chc/GHSA-28m9-8pxg-9chc.json @@ -7,12 +7,8 @@ "CVE-2000-0540" ], "details": "JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2ffp-463q-9cmj/GHSA-2ffp-463q-9cmj.json b/advisories/unreviewed/2022/04/GHSA-2ffp-463q-9cmj/GHSA-2ffp-463q-9cmj.json index 08c249c775b..ab5d524fb68 100644 --- a/advisories/unreviewed/2022/04/GHSA-2ffp-463q-9cmj/GHSA-2ffp-463q-9cmj.json +++ b/advisories/unreviewed/2022/04/GHSA-2ffp-463q-9cmj/GHSA-2ffp-463q-9cmj.json @@ -7,12 +7,8 @@ "CVE-2000-0583" ], "details": "vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2gq8-wr55-679w/GHSA-2gq8-wr55-679w.json b/advisories/unreviewed/2022/04/GHSA-2gq8-wr55-679w/GHSA-2gq8-wr55-679w.json index 7abf77dbcee..212698f3cd5 100644 --- a/advisories/unreviewed/2022/04/GHSA-2gq8-wr55-679w/GHSA-2gq8-wr55-679w.json +++ b/advisories/unreviewed/2022/04/GHSA-2gq8-wr55-679w/GHSA-2gq8-wr55-679w.json @@ -7,12 +7,8 @@ "CVE-2000-0675" ], "details": "Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2j8h-wx6g-vcxm/GHSA-2j8h-wx6g-vcxm.json b/advisories/unreviewed/2022/04/GHSA-2j8h-wx6g-vcxm/GHSA-2j8h-wx6g-vcxm.json index 1055c935d16..bcb0fb0bbc7 100644 --- a/advisories/unreviewed/2022/04/GHSA-2j8h-wx6g-vcxm/GHSA-2j8h-wx6g-vcxm.json +++ b/advisories/unreviewed/2022/04/GHSA-2j8h-wx6g-vcxm/GHSA-2j8h-wx6g-vcxm.json @@ -7,12 +7,8 @@ "CVE-2000-0550" ], "details": "Kerberos 4 KDC program improperly frees memory twice (aka \"double-free\"), which allows remote attackers to cause a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2mg2-8p2q-47h9/GHSA-2mg2-8p2q-47h9.json b/advisories/unreviewed/2022/04/GHSA-2mg2-8p2q-47h9/GHSA-2mg2-8p2q-47h9.json index 560959f44bc..6278adaf8a5 100644 --- a/advisories/unreviewed/2022/04/GHSA-2mg2-8p2q-47h9/GHSA-2mg2-8p2q-47h9.json +++ b/advisories/unreviewed/2022/04/GHSA-2mg2-8p2q-47h9/GHSA-2mg2-8p2q-47h9.json @@ -7,12 +7,8 @@ "CVE-2000-0669" ], "details": "Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2rmh-3vpc-xqrj/GHSA-2rmh-3vpc-xqrj.json b/advisories/unreviewed/2022/04/GHSA-2rmh-3vpc-xqrj/GHSA-2rmh-3vpc-xqrj.json index 71cc52457b8..bacef62b2d1 100644 --- a/advisories/unreviewed/2022/04/GHSA-2rmh-3vpc-xqrj/GHSA-2rmh-3vpc-xqrj.json +++ b/advisories/unreviewed/2022/04/GHSA-2rmh-3vpc-xqrj/GHSA-2rmh-3vpc-xqrj.json @@ -7,12 +7,8 @@ "CVE-2000-0678" ], "details": "PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2w42-wj39-8g7h/GHSA-2w42-wj39-8g7h.json b/advisories/unreviewed/2022/04/GHSA-2w42-wj39-8g7h/GHSA-2w42-wj39-8g7h.json index bb019f9130c..79a9158a621 100644 --- a/advisories/unreviewed/2022/04/GHSA-2w42-wj39-8g7h/GHSA-2w42-wj39-8g7h.json +++ b/advisories/unreviewed/2022/04/GHSA-2w42-wj39-8g7h/GHSA-2w42-wj39-8g7h.json @@ -7,12 +7,8 @@ "CVE-2000-0646" ], "details": "WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2xfg-fq6q-8vvj/GHSA-2xfg-fq6q-8vvj.json b/advisories/unreviewed/2022/04/GHSA-2xfg-fq6q-8vvj/GHSA-2xfg-fq6q-8vvj.json index 337c948d3fb..352c2042191 100644 --- a/advisories/unreviewed/2022/04/GHSA-2xfg-fq6q-8vvj/GHSA-2xfg-fq6q-8vvj.json +++ b/advisories/unreviewed/2022/04/GHSA-2xfg-fq6q-8vvj/GHSA-2xfg-fq6q-8vvj.json @@ -7,12 +7,8 @@ "CVE-2000-0657" ], "details": "Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-337w-g464-gv6c/GHSA-337w-g464-gv6c.json b/advisories/unreviewed/2022/04/GHSA-337w-g464-gv6c/GHSA-337w-g464-gv6c.json index eefe4c739d3..46af880ca1a 100644 --- a/advisories/unreviewed/2022/04/GHSA-337w-g464-gv6c/GHSA-337w-g464-gv6c.json +++ b/advisories/unreviewed/2022/04/GHSA-337w-g464-gv6c/GHSA-337w-g464-gv6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3987-59ph-j5q3/GHSA-3987-59ph-j5q3.json b/advisories/unreviewed/2022/04/GHSA-3987-59ph-j5q3/GHSA-3987-59ph-j5q3.json index dab416b7a0a..50583195570 100644 --- a/advisories/unreviewed/2022/04/GHSA-3987-59ph-j5q3/GHSA-3987-59ph-j5q3.json +++ b/advisories/unreviewed/2022/04/GHSA-3987-59ph-j5q3/GHSA-3987-59ph-j5q3.json @@ -7,12 +7,8 @@ "CVE-2000-0629" ], "details": "The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3qw8-5c34-wm4v/GHSA-3qw8-5c34-wm4v.json b/advisories/unreviewed/2022/04/GHSA-3qw8-5c34-wm4v/GHSA-3qw8-5c34-wm4v.json index 129032b8e3c..51e9d6206c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-3qw8-5c34-wm4v/GHSA-3qw8-5c34-wm4v.json +++ b/advisories/unreviewed/2022/04/GHSA-3qw8-5c34-wm4v/GHSA-3qw8-5c34-wm4v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-3rjv-37hg-wc7j/GHSA-3rjv-37hg-wc7j.json b/advisories/unreviewed/2022/04/GHSA-3rjv-37hg-wc7j/GHSA-3rjv-37hg-wc7j.json index 091bc53394b..70195481636 100644 --- a/advisories/unreviewed/2022/04/GHSA-3rjv-37hg-wc7j/GHSA-3rjv-37hg-wc7j.json +++ b/advisories/unreviewed/2022/04/GHSA-3rjv-37hg-wc7j/GHSA-3rjv-37hg-wc7j.json @@ -7,12 +7,8 @@ "CVE-2000-0638" ], "details": "bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3v52-43ch-8qcg/GHSA-3v52-43ch-8qcg.json b/advisories/unreviewed/2022/04/GHSA-3v52-43ch-8qcg/GHSA-3v52-43ch-8qcg.json index 79c7b995442..79f2cccd09e 100644 --- a/advisories/unreviewed/2022/04/GHSA-3v52-43ch-8qcg/GHSA-3v52-43ch-8qcg.json +++ b/advisories/unreviewed/2022/04/GHSA-3v52-43ch-8qcg/GHSA-3v52-43ch-8qcg.json @@ -7,12 +7,8 @@ "CVE-2000-0632" ], "details": "Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3xf3-5r39-357f/GHSA-3xf3-5r39-357f.json b/advisories/unreviewed/2022/04/GHSA-3xf3-5r39-357f/GHSA-3xf3-5r39-357f.json index 9ae7a4b2a60..7c154a08a14 100644 --- a/advisories/unreviewed/2022/04/GHSA-3xf3-5r39-357f/GHSA-3xf3-5r39-357f.json +++ b/advisories/unreviewed/2022/04/GHSA-3xf3-5r39-357f/GHSA-3xf3-5r39-357f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-45rv-3qw6-q326/GHSA-45rv-3qw6-q326.json b/advisories/unreviewed/2022/04/GHSA-45rv-3qw6-q326/GHSA-45rv-3qw6-q326.json index 628137963bd..e258822a735 100644 --- a/advisories/unreviewed/2022/04/GHSA-45rv-3qw6-q326/GHSA-45rv-3qw6-q326.json +++ b/advisories/unreviewed/2022/04/GHSA-45rv-3qw6-q326/GHSA-45rv-3qw6-q326.json @@ -7,12 +7,8 @@ "CVE-2000-0598" ], "details": "Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-485w-vv83-53fx/GHSA-485w-vv83-53fx.json b/advisories/unreviewed/2022/04/GHSA-485w-vv83-53fx/GHSA-485w-vv83-53fx.json index 2677a3373fb..e52252b650e 100644 --- a/advisories/unreviewed/2022/04/GHSA-485w-vv83-53fx/GHSA-485w-vv83-53fx.json +++ b/advisories/unreviewed/2022/04/GHSA-485w-vv83-53fx/GHSA-485w-vv83-53fx.json @@ -7,12 +7,8 @@ "CVE-2000-0561" ], "details": "Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-48mx-245h-4c59/GHSA-48mx-245h-4c59.json b/advisories/unreviewed/2022/04/GHSA-48mx-245h-4c59/GHSA-48mx-245h-4c59.json index d87f1136d88..40d6403d6ef 100644 --- a/advisories/unreviewed/2022/04/GHSA-48mx-245h-4c59/GHSA-48mx-245h-4c59.json +++ b/advisories/unreviewed/2022/04/GHSA-48mx-245h-4c59/GHSA-48mx-245h-4c59.json @@ -7,12 +7,8 @@ "CVE-2000-0620" ], "details": "libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4hfc-c3hg-m9pr/GHSA-4hfc-c3hg-m9pr.json b/advisories/unreviewed/2022/04/GHSA-4hfc-c3hg-m9pr/GHSA-4hfc-c3hg-m9pr.json index 2a23dbe038e..d6972736001 100644 --- a/advisories/unreviewed/2022/04/GHSA-4hfc-c3hg-m9pr/GHSA-4hfc-c3hg-m9pr.json +++ b/advisories/unreviewed/2022/04/GHSA-4hfc-c3hg-m9pr/GHSA-4hfc-c3hg-m9pr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4pcm-9qq9-65qc/GHSA-4pcm-9qq9-65qc.json b/advisories/unreviewed/2022/04/GHSA-4pcm-9qq9-65qc/GHSA-4pcm-9qq9-65qc.json index cf08c035875..ab2f5c5f960 100644 --- a/advisories/unreviewed/2022/04/GHSA-4pcm-9qq9-65qc/GHSA-4pcm-9qq9-65qc.json +++ b/advisories/unreviewed/2022/04/GHSA-4pcm-9qq9-65qc/GHSA-4pcm-9qq9-65qc.json @@ -7,12 +7,8 @@ "CVE-2000-0630" ], "details": "IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the \"File Fragment Reading via .HTR\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4pq5-c54c-qgxf/GHSA-4pq5-c54c-qgxf.json b/advisories/unreviewed/2022/04/GHSA-4pq5-c54c-qgxf/GHSA-4pq5-c54c-qgxf.json index 8adec5168e7..5a9d7a702e5 100644 --- a/advisories/unreviewed/2022/04/GHSA-4pq5-c54c-qgxf/GHSA-4pq5-c54c-qgxf.json +++ b/advisories/unreviewed/2022/04/GHSA-4pq5-c54c-qgxf/GHSA-4pq5-c54c-qgxf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4w6m-4639-4jgr/GHSA-4w6m-4639-4jgr.json b/advisories/unreviewed/2022/04/GHSA-4w6m-4639-4jgr/GHSA-4w6m-4639-4jgr.json index ebdb7a4e4c8..83e03631b30 100644 --- a/advisories/unreviewed/2022/04/GHSA-4w6m-4639-4jgr/GHSA-4w6m-4639-4jgr.json +++ b/advisories/unreviewed/2022/04/GHSA-4w6m-4639-4jgr/GHSA-4w6m-4639-4jgr.json @@ -7,12 +7,8 @@ "CVE-2000-0567" ], "details": "Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the \"Malformed E-mail Header\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-52p2-82rj-4r39/GHSA-52p2-82rj-4r39.json b/advisories/unreviewed/2022/04/GHSA-52p2-82rj-4r39/GHSA-52p2-82rj-4r39.json index 94e94434f43..7f07b0ab17c 100644 --- a/advisories/unreviewed/2022/04/GHSA-52p2-82rj-4r39/GHSA-52p2-82rj-4r39.json +++ b/advisories/unreviewed/2022/04/GHSA-52p2-82rj-4r39/GHSA-52p2-82rj-4r39.json @@ -7,12 +7,8 @@ "CVE-2000-0642" ], "details": "The default configuration of WebActive HTTP Server 1.00 stores the web access log active.log in the document root, which allows remote attackers to view the logs by directly requesting the page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-56qh-54mj-8vvx/GHSA-56qh-54mj-8vvx.json b/advisories/unreviewed/2022/04/GHSA-56qh-54mj-8vvx/GHSA-56qh-54mj-8vvx.json index 89c9827d5f5..46d703d5038 100644 --- a/advisories/unreviewed/2022/04/GHSA-56qh-54mj-8vvx/GHSA-56qh-54mj-8vvx.json +++ b/advisories/unreviewed/2022/04/GHSA-56qh-54mj-8vvx/GHSA-56qh-54mj-8vvx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-58wj-rx92-f9qx/GHSA-58wj-rx92-f9qx.json b/advisories/unreviewed/2022/04/GHSA-58wj-rx92-f9qx/GHSA-58wj-rx92-f9qx.json index 40d40070021..52aa77176d4 100644 --- a/advisories/unreviewed/2022/04/GHSA-58wj-rx92-f9qx/GHSA-58wj-rx92-f9qx.json +++ b/advisories/unreviewed/2022/04/GHSA-58wj-rx92-f9qx/GHSA-58wj-rx92-f9qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5jwc-8539-rgx6/GHSA-5jwc-8539-rgx6.json b/advisories/unreviewed/2022/04/GHSA-5jwc-8539-rgx6/GHSA-5jwc-8539-rgx6.json index 5b129b9e273..2b5a130f069 100644 --- a/advisories/unreviewed/2022/04/GHSA-5jwc-8539-rgx6/GHSA-5jwc-8539-rgx6.json +++ b/advisories/unreviewed/2022/04/GHSA-5jwc-8539-rgx6/GHSA-5jwc-8539-rgx6.json @@ -7,12 +7,8 @@ "CVE-2000-0653" ], "details": "Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the \"Persistent Mail-Browser Link\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5pwv-v67v-mf36/GHSA-5pwv-v67v-mf36.json b/advisories/unreviewed/2022/04/GHSA-5pwv-v67v-mf36/GHSA-5pwv-v67v-mf36.json index 81fa929ce3f..c3f4aeb7d79 100644 --- a/advisories/unreviewed/2022/04/GHSA-5pwv-v67v-mf36/GHSA-5pwv-v67v-mf36.json +++ b/advisories/unreviewed/2022/04/GHSA-5pwv-v67v-mf36/GHSA-5pwv-v67v-mf36.json @@ -7,12 +7,8 @@ "CVE-2000-0549" ], "details": "Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-665p-mhgh-xxcv/GHSA-665p-mhgh-xxcv.json b/advisories/unreviewed/2022/04/GHSA-665p-mhgh-xxcv/GHSA-665p-mhgh-xxcv.json index 0d7bb956802..108415c5fb5 100644 --- a/advisories/unreviewed/2022/04/GHSA-665p-mhgh-xxcv/GHSA-665p-mhgh-xxcv.json +++ b/advisories/unreviewed/2022/04/GHSA-665p-mhgh-xxcv/GHSA-665p-mhgh-xxcv.json @@ -7,12 +7,8 @@ "CVE-2000-0608" ], "details": "NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-68cc-r228-pw9r/GHSA-68cc-r228-pw9r.json b/advisories/unreviewed/2022/04/GHSA-68cc-r228-pw9r/GHSA-68cc-r228-pw9r.json index f46abffb594..557f74e3339 100644 --- a/advisories/unreviewed/2022/04/GHSA-68cc-r228-pw9r/GHSA-68cc-r228-pw9r.json +++ b/advisories/unreviewed/2022/04/GHSA-68cc-r228-pw9r/GHSA-68cc-r228-pw9r.json @@ -7,12 +7,8 @@ "CVE-2000-0610" ], "details": "NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6983-p8mq-gp2h/GHSA-6983-p8mq-gp2h.json b/advisories/unreviewed/2022/04/GHSA-6983-p8mq-gp2h/GHSA-6983-p8mq-gp2h.json index ee583f0befc..05a95f62936 100644 --- a/advisories/unreviewed/2022/04/GHSA-6983-p8mq-gp2h/GHSA-6983-p8mq-gp2h.json +++ b/advisories/unreviewed/2022/04/GHSA-6983-p8mq-gp2h/GHSA-6983-p8mq-gp2h.json @@ -7,12 +7,8 @@ "CVE-2000-0643" ], "details": "Buffer overflow in WebActive HTTP Server 1.00 allows remote attackers to cause a denial of service via a long URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-69fh-f7xf-67w9/GHSA-69fh-f7xf-67w9.json b/advisories/unreviewed/2022/04/GHSA-69fh-f7xf-67w9/GHSA-69fh-f7xf-67w9.json index f86c82905d2..dafd4aa6a90 100644 --- a/advisories/unreviewed/2022/04/GHSA-69fh-f7xf-67w9/GHSA-69fh-f7xf-67w9.json +++ b/advisories/unreviewed/2022/04/GHSA-69fh-f7xf-67w9/GHSA-69fh-f7xf-67w9.json @@ -7,12 +7,8 @@ "CVE-2000-0634" ], "details": "The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6f4p-554q-j3hv/GHSA-6f4p-554q-j3hv.json b/advisories/unreviewed/2022/04/GHSA-6f4p-554q-j3hv/GHSA-6f4p-554q-j3hv.json index 54f3fe417d6..e2de1abc498 100644 --- a/advisories/unreviewed/2022/04/GHSA-6f4p-554q-j3hv/GHSA-6f4p-554q-j3hv.json +++ b/advisories/unreviewed/2022/04/GHSA-6f4p-554q-j3hv/GHSA-6f4p-554q-j3hv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6h3c-53gf-6qc3/GHSA-6h3c-53gf-6qc3.json b/advisories/unreviewed/2022/04/GHSA-6h3c-53gf-6qc3/GHSA-6h3c-53gf-6qc3.json index f59ede108f6..297d7b05725 100644 --- a/advisories/unreviewed/2022/04/GHSA-6h3c-53gf-6qc3/GHSA-6h3c-53gf-6qc3.json +++ b/advisories/unreviewed/2022/04/GHSA-6h3c-53gf-6qc3/GHSA-6h3c-53gf-6qc3.json @@ -7,12 +7,8 @@ "CVE-2000-0612" ], "details": "Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6j7v-q8xr-8rhx/GHSA-6j7v-q8xr-8rhx.json b/advisories/unreviewed/2022/04/GHSA-6j7v-q8xr-8rhx/GHSA-6j7v-q8xr-8rhx.json index 5a28dd0b0bb..1da9c1a3f2f 100644 --- a/advisories/unreviewed/2022/04/GHSA-6j7v-q8xr-8rhx/GHSA-6j7v-q8xr-8rhx.json +++ b/advisories/unreviewed/2022/04/GHSA-6j7v-q8xr-8rhx/GHSA-6j7v-q8xr-8rhx.json @@ -7,12 +7,8 @@ "CVE-2000-0545" ], "details": "Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (carbon copy) parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6r6c-fvxf-rg87/GHSA-6r6c-fvxf-rg87.json b/advisories/unreviewed/2022/04/GHSA-6r6c-fvxf-rg87/GHSA-6r6c-fvxf-rg87.json index e1fce8916ae..fdb8d3bcec8 100644 --- a/advisories/unreviewed/2022/04/GHSA-6r6c-fvxf-rg87/GHSA-6r6c-fvxf-rg87.json +++ b/advisories/unreviewed/2022/04/GHSA-6r6c-fvxf-rg87/GHSA-6r6c-fvxf-rg87.json @@ -7,12 +7,8 @@ "CVE-2000-0589" ], "details": "SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6wwj-crch-j32j/GHSA-6wwj-crch-j32j.json b/advisories/unreviewed/2022/04/GHSA-6wwj-crch-j32j/GHSA-6wwj-crch-j32j.json index ff76feaf382..dcd1e8eafb8 100644 --- a/advisories/unreviewed/2022/04/GHSA-6wwj-crch-j32j/GHSA-6wwj-crch-j32j.json +++ b/advisories/unreviewed/2022/04/GHSA-6wwj-crch-j32j/GHSA-6wwj-crch-j32j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6xqc-7566-x2pq/GHSA-6xqc-7566-x2pq.json b/advisories/unreviewed/2022/04/GHSA-6xqc-7566-x2pq/GHSA-6xqc-7566-x2pq.json index f291060c7a4..d1ff08c094d 100644 --- a/advisories/unreviewed/2022/04/GHSA-6xqc-7566-x2pq/GHSA-6xqc-7566-x2pq.json +++ b/advisories/unreviewed/2022/04/GHSA-6xqc-7566-x2pq/GHSA-6xqc-7566-x2pq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-73jr-7f3r-3wxh/GHSA-73jr-7f3r-3wxh.json b/advisories/unreviewed/2022/04/GHSA-73jr-7f3r-3wxh/GHSA-73jr-7f3r-3wxh.json index e6782b42bdf..1fb639ae25a 100644 --- a/advisories/unreviewed/2022/04/GHSA-73jr-7f3r-3wxh/GHSA-73jr-7f3r-3wxh.json +++ b/advisories/unreviewed/2022/04/GHSA-73jr-7f3r-3wxh/GHSA-73jr-7f3r-3wxh.json @@ -7,12 +7,8 @@ "CVE-2000-0544" ], "details": "Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-77q3-769w-pr25/GHSA-77q3-769w-pr25.json b/advisories/unreviewed/2022/04/GHSA-77q3-769w-pr25/GHSA-77q3-769w-pr25.json index 137026ce690..05b7c721045 100644 --- a/advisories/unreviewed/2022/04/GHSA-77q3-769w-pr25/GHSA-77q3-769w-pr25.json +++ b/advisories/unreviewed/2022/04/GHSA-77q3-769w-pr25/GHSA-77q3-769w-pr25.json @@ -7,12 +7,8 @@ "CVE-2000-0572" ], "details": "The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-78c2-6wr9-gc88/GHSA-78c2-6wr9-gc88.json b/advisories/unreviewed/2022/04/GHSA-78c2-6wr9-gc88/GHSA-78c2-6wr9-gc88.json index 2965719d325..0caaad04759 100644 --- a/advisories/unreviewed/2022/04/GHSA-78c2-6wr9-gc88/GHSA-78c2-6wr9-gc88.json +++ b/advisories/unreviewed/2022/04/GHSA-78c2-6wr9-gc88/GHSA-78c2-6wr9-gc88.json @@ -7,12 +7,8 @@ "CVE-2000-0652" ], "details": "IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the \"/servlet/file\" string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7g5j-fq3f-v5q2/GHSA-7g5j-fq3f-v5q2.json b/advisories/unreviewed/2022/04/GHSA-7g5j-fq3f-v5q2/GHSA-7g5j-fq3f-v5q2.json index 05e05e0772a..72bd1301287 100644 --- a/advisories/unreviewed/2022/04/GHSA-7g5j-fq3f-v5q2/GHSA-7g5j-fq3f-v5q2.json +++ b/advisories/unreviewed/2022/04/GHSA-7g5j-fq3f-v5q2/GHSA-7g5j-fq3f-v5q2.json @@ -7,12 +7,8 @@ "CVE-2000-0617" ], "details": "Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7gpq-38wj-hv97/GHSA-7gpq-38wj-hv97.json b/advisories/unreviewed/2022/04/GHSA-7gpq-38wj-hv97/GHSA-7gpq-38wj-hv97.json index fdf2d78ecd6..7cdcc12f4da 100644 --- a/advisories/unreviewed/2022/04/GHSA-7gpq-38wj-hv97/GHSA-7gpq-38wj-hv97.json +++ b/advisories/unreviewed/2022/04/GHSA-7gpq-38wj-hv97/GHSA-7gpq-38wj-hv97.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7j9c-jj55-7hhm/GHSA-7j9c-jj55-7hhm.json b/advisories/unreviewed/2022/04/GHSA-7j9c-jj55-7hhm/GHSA-7j9c-jj55-7hhm.json index 06a049e2641..7e50d931f1b 100644 --- a/advisories/unreviewed/2022/04/GHSA-7j9c-jj55-7hhm/GHSA-7j9c-jj55-7hhm.json +++ b/advisories/unreviewed/2022/04/GHSA-7j9c-jj55-7hhm/GHSA-7j9c-jj55-7hhm.json @@ -7,12 +7,8 @@ "CVE-2000-0626" ], "details": "Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-82f3-pqxp-8f9v/GHSA-82f3-pqxp-8f9v.json b/advisories/unreviewed/2022/04/GHSA-82f3-pqxp-8f9v/GHSA-82f3-pqxp-8f9v.json index 8df71179a27..9c8c7b2c5f3 100644 --- a/advisories/unreviewed/2022/04/GHSA-82f3-pqxp-8f9v/GHSA-82f3-pqxp-8f9v.json +++ b/advisories/unreviewed/2022/04/GHSA-82f3-pqxp-8f9v/GHSA-82f3-pqxp-8f9v.json @@ -7,12 +7,8 @@ "CVE-2000-0609" ], "details": "NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-88fx-2h2r-88cj/GHSA-88fx-2h2r-88cj.json b/advisories/unreviewed/2022/04/GHSA-88fx-2h2r-88cj/GHSA-88fx-2h2r-88cj.json index 4c1da005dcd..562b41dd6c5 100644 --- a/advisories/unreviewed/2022/04/GHSA-88fx-2h2r-88cj/GHSA-88fx-2h2r-88cj.json +++ b/advisories/unreviewed/2022/04/GHSA-88fx-2h2r-88cj/GHSA-88fx-2h2r-88cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-8cv8-cw5j-h98f/GHSA-8cv8-cw5j-h98f.json b/advisories/unreviewed/2022/04/GHSA-8cv8-cw5j-h98f/GHSA-8cv8-cw5j-h98f.json index 82ddf313c07..2f31c477102 100644 --- a/advisories/unreviewed/2022/04/GHSA-8cv8-cw5j-h98f/GHSA-8cv8-cw5j-h98f.json +++ b/advisories/unreviewed/2022/04/GHSA-8cv8-cw5j-h98f/GHSA-8cv8-cw5j-h98f.json @@ -7,12 +7,8 @@ "CVE-2000-0654" ], "details": "Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the \"DTS Password\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8wr3-5grg-gmwh/GHSA-8wr3-5grg-gmwh.json b/advisories/unreviewed/2022/04/GHSA-8wr3-5grg-gmwh/GHSA-8wr3-5grg-gmwh.json index 12294eaf36c..b512fe96be8 100644 --- a/advisories/unreviewed/2022/04/GHSA-8wr3-5grg-gmwh/GHSA-8wr3-5grg-gmwh.json +++ b/advisories/unreviewed/2022/04/GHSA-8wr3-5grg-gmwh/GHSA-8wr3-5grg-gmwh.json @@ -7,12 +7,8 @@ "CVE-2000-0554" ], "details": "Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-96v5-vfm2-f5hh/GHSA-96v5-vfm2-f5hh.json b/advisories/unreviewed/2022/04/GHSA-96v5-vfm2-f5hh/GHSA-96v5-vfm2-f5hh.json index 626e1b7c755..0565b837f25 100644 --- a/advisories/unreviewed/2022/04/GHSA-96v5-vfm2-f5hh/GHSA-96v5-vfm2-f5hh.json +++ b/advisories/unreviewed/2022/04/GHSA-96v5-vfm2-f5hh/GHSA-96v5-vfm2-f5hh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-977m-wr29-gj29/GHSA-977m-wr29-gj29.json b/advisories/unreviewed/2022/04/GHSA-977m-wr29-gj29/GHSA-977m-wr29-gj29.json index d38faa03e1d..8307c775ea3 100644 --- a/advisories/unreviewed/2022/04/GHSA-977m-wr29-gj29/GHSA-977m-wr29-gj29.json +++ b/advisories/unreviewed/2022/04/GHSA-977m-wr29-gj29/GHSA-977m-wr29-gj29.json @@ -7,12 +7,8 @@ "CVE-2000-0637" ], "details": "Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the \"Excel REGISTER.ID Function\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-985h-mmq2-8vhw/GHSA-985h-mmq2-8vhw.json b/advisories/unreviewed/2022/04/GHSA-985h-mmq2-8vhw/GHSA-985h-mmq2-8vhw.json index b86e83687b5..880908e164e 100644 --- a/advisories/unreviewed/2022/04/GHSA-985h-mmq2-8vhw/GHSA-985h-mmq2-8vhw.json +++ b/advisories/unreviewed/2022/04/GHSA-985h-mmq2-8vhw/GHSA-985h-mmq2-8vhw.json @@ -7,12 +7,8 @@ "CVE-2000-0557" ], "details": "Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-99c8-6rr7-v77j/GHSA-99c8-6rr7-v77j.json b/advisories/unreviewed/2022/04/GHSA-99c8-6rr7-v77j/GHSA-99c8-6rr7-v77j.json index 35501561afd..c15fdfe2650 100644 --- a/advisories/unreviewed/2022/04/GHSA-99c8-6rr7-v77j/GHSA-99c8-6rr7-v77j.json +++ b/advisories/unreviewed/2022/04/GHSA-99c8-6rr7-v77j/GHSA-99c8-6rr7-v77j.json @@ -7,12 +7,8 @@ "CVE-2000-0648" ], "details": "WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9c8x-vv79-pccg/GHSA-9c8x-vv79-pccg.json b/advisories/unreviewed/2022/04/GHSA-9c8x-vv79-pccg/GHSA-9c8x-vv79-pccg.json index 6263aec4b2b..9afe585a7c2 100644 --- a/advisories/unreviewed/2022/04/GHSA-9c8x-vv79-pccg/GHSA-9c8x-vv79-pccg.json +++ b/advisories/unreviewed/2022/04/GHSA-9c8x-vv79-pccg/GHSA-9c8x-vv79-pccg.json @@ -7,12 +7,8 @@ "CVE-2000-0568" ], "details": "Sybergen Secure Desktop 2.1 does not properly protect against false router advertisements (ICMP type 9), which allows remote attackers to modify default routes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9hpg-q52c-898c/GHSA-9hpg-q52c-898c.json b/advisories/unreviewed/2022/04/GHSA-9hpg-q52c-898c/GHSA-9hpg-q52c-898c.json index a6a37c0de35..59fcd4988c1 100644 --- a/advisories/unreviewed/2022/04/GHSA-9hpg-q52c-898c/GHSA-9hpg-q52c-898c.json +++ b/advisories/unreviewed/2022/04/GHSA-9hpg-q52c-898c/GHSA-9hpg-q52c-898c.json @@ -7,12 +7,8 @@ "CVE-2000-0578" ], "details": "SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allow local users to insert malicious contents into these files as they are being compiled by another user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9jv8-f4cc-g337/GHSA-9jv8-f4cc-g337.json b/advisories/unreviewed/2022/04/GHSA-9jv8-f4cc-g337/GHSA-9jv8-f4cc-g337.json index aa1bca3b8b0..c19ef64ae9c 100644 --- a/advisories/unreviewed/2022/04/GHSA-9jv8-f4cc-g337/GHSA-9jv8-f4cc-g337.json +++ b/advisories/unreviewed/2022/04/GHSA-9jv8-f4cc-g337/GHSA-9jv8-f4cc-g337.json @@ -7,12 +7,8 @@ "CVE-2000-0658" ], "details": "Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9mpp-c9vq-p5h7/GHSA-9mpp-c9vq-p5h7.json b/advisories/unreviewed/2022/04/GHSA-9mpp-c9vq-p5h7/GHSA-9mpp-c9vq-p5h7.json index 11efbc1b23e..5ded8363c9e 100644 --- a/advisories/unreviewed/2022/04/GHSA-9mpp-c9vq-p5h7/GHSA-9mpp-c9vq-p5h7.json +++ b/advisories/unreviewed/2022/04/GHSA-9mpp-c9vq-p5h7/GHSA-9mpp-c9vq-p5h7.json @@ -7,12 +7,8 @@ "CVE-2000-0628" ], "details": "The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9p4q-mfc9-w6m9/GHSA-9p4q-mfc9-w6m9.json b/advisories/unreviewed/2022/04/GHSA-9p4q-mfc9-w6m9/GHSA-9p4q-mfc9-w6m9.json index eefc2aa46a1..d10be52ff2c 100644 --- a/advisories/unreviewed/2022/04/GHSA-9p4q-mfc9-w6m9/GHSA-9p4q-mfc9-w6m9.json +++ b/advisories/unreviewed/2022/04/GHSA-9p4q-mfc9-w6m9/GHSA-9p4q-mfc9-w6m9.json @@ -7,12 +7,8 @@ "CVE-2000-0577" ], "details": "Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c4qc-qrx8-9prp/GHSA-c4qc-qrx8-9prp.json b/advisories/unreviewed/2022/04/GHSA-c4qc-qrx8-9prp/GHSA-c4qc-qrx8-9prp.json index 43ff6c74d7a..fc92dbea746 100644 --- a/advisories/unreviewed/2022/04/GHSA-c4qc-qrx8-9prp/GHSA-c4qc-qrx8-9prp.json +++ b/advisories/unreviewed/2022/04/GHSA-c4qc-qrx8-9prp/GHSA-c4qc-qrx8-9prp.json @@ -7,12 +7,8 @@ "CVE-2000-0644" ], "details": "WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c5pm-gfqm-wxp7/GHSA-c5pm-gfqm-wxp7.json b/advisories/unreviewed/2022/04/GHSA-c5pm-gfqm-wxp7/GHSA-c5pm-gfqm-wxp7.json index b9ed964681b..b9961b64b80 100644 --- a/advisories/unreviewed/2022/04/GHSA-c5pm-gfqm-wxp7/GHSA-c5pm-gfqm-wxp7.json +++ b/advisories/unreviewed/2022/04/GHSA-c5pm-gfqm-wxp7/GHSA-c5pm-gfqm-wxp7.json @@ -7,12 +7,8 @@ "CVE-2000-0662" ], "details": "Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c9gg-qqjg-6v7f/GHSA-c9gg-qqjg-6v7f.json b/advisories/unreviewed/2022/04/GHSA-c9gg-qqjg-6v7f/GHSA-c9gg-qqjg-6v7f.json index e3102d32582..e3c127469e1 100644 --- a/advisories/unreviewed/2022/04/GHSA-c9gg-qqjg-6v7f/GHSA-c9gg-qqjg-6v7f.json +++ b/advisories/unreviewed/2022/04/GHSA-c9gg-qqjg-6v7f/GHSA-c9gg-qqjg-6v7f.json @@ -7,12 +7,8 @@ "CVE-2000-0622" ], "details": "Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long \"keywords\" parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cf29-9472-gh5p/GHSA-cf29-9472-gh5p.json b/advisories/unreviewed/2022/04/GHSA-cf29-9472-gh5p/GHSA-cf29-9472-gh5p.json index d66993f3b2f..2750cb98ef6 100644 --- a/advisories/unreviewed/2022/04/GHSA-cf29-9472-gh5p/GHSA-cf29-9472-gh5p.json +++ b/advisories/unreviewed/2022/04/GHSA-cf29-9472-gh5p/GHSA-cf29-9472-gh5p.json @@ -7,12 +7,8 @@ "CVE-2000-0611" ], "details": "The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cf7g-gj99-69w3/GHSA-cf7g-gj99-69w3.json b/advisories/unreviewed/2022/04/GHSA-cf7g-gj99-69w3/GHSA-cf7g-gj99-69w3.json index 09d180f3b91..d2cbcead51b 100644 --- a/advisories/unreviewed/2022/04/GHSA-cf7g-gj99-69w3/GHSA-cf7g-gj99-69w3.json +++ b/advisories/unreviewed/2022/04/GHSA-cf7g-gj99-69w3/GHSA-cf7g-gj99-69w3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-cghg-rv7h-488q/GHSA-cghg-rv7h-488q.json b/advisories/unreviewed/2022/04/GHSA-cghg-rv7h-488q/GHSA-cghg-rv7h-488q.json index 9c45d462734..e1a5caf1d29 100644 --- a/advisories/unreviewed/2022/04/GHSA-cghg-rv7h-488q/GHSA-cghg-rv7h-488q.json +++ b/advisories/unreviewed/2022/04/GHSA-cghg-rv7h-488q/GHSA-cghg-rv7h-488q.json @@ -7,12 +7,8 @@ "CVE-2000-0681" ], "details": "Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cm4m-9c34-c8p6/GHSA-cm4m-9c34-c8p6.json b/advisories/unreviewed/2022/04/GHSA-cm4m-9c34-c8p6/GHSA-cm4m-9c34-c8p6.json index aff62d13767..7460213bcd6 100644 --- a/advisories/unreviewed/2022/04/GHSA-cm4m-9c34-c8p6/GHSA-cm4m-9c34-c8p6.json +++ b/advisories/unreviewed/2022/04/GHSA-cm4m-9c34-c8p6/GHSA-cm4m-9c34-c8p6.json @@ -7,12 +7,8 @@ "CVE-2000-0595" ], "details": "libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cmmr-4624-8pv4/GHSA-cmmr-4624-8pv4.json b/advisories/unreviewed/2022/04/GHSA-cmmr-4624-8pv4/GHSA-cmmr-4624-8pv4.json index a9a45b0fda9..c002300893b 100644 --- a/advisories/unreviewed/2022/04/GHSA-cmmr-4624-8pv4/GHSA-cmmr-4624-8pv4.json +++ b/advisories/unreviewed/2022/04/GHSA-cmmr-4624-8pv4/GHSA-cmmr-4624-8pv4.json @@ -7,12 +7,8 @@ "CVE-2000-0558" ], "details": "Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cvw6-7vx8-mh9x/GHSA-cvw6-7vx8-mh9x.json b/advisories/unreviewed/2022/04/GHSA-cvw6-7vx8-mh9x/GHSA-cvw6-7vx8-mh9x.json index 4d2633b489b..5548de58001 100644 --- a/advisories/unreviewed/2022/04/GHSA-cvw6-7vx8-mh9x/GHSA-cvw6-7vx8-mh9x.json +++ b/advisories/unreviewed/2022/04/GHSA-cvw6-7vx8-mh9x/GHSA-cvw6-7vx8-mh9x.json @@ -7,12 +7,8 @@ "CVE-2000-0588" ], "details": "SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-f54q-8494-3hvh/GHSA-f54q-8494-3hvh.json b/advisories/unreviewed/2022/04/GHSA-f54q-8494-3hvh/GHSA-f54q-8494-3hvh.json index bb8865be2f7..d2ce3178f13 100644 --- a/advisories/unreviewed/2022/04/GHSA-f54q-8494-3hvh/GHSA-f54q-8494-3hvh.json +++ b/advisories/unreviewed/2022/04/GHSA-f54q-8494-3hvh/GHSA-f54q-8494-3hvh.json @@ -7,12 +7,8 @@ "CVE-2000-0586" ], "details": "Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f7cf-36r8-52q2/GHSA-f7cf-36r8-52q2.json b/advisories/unreviewed/2022/04/GHSA-f7cf-36r8-52q2/GHSA-f7cf-36r8-52q2.json index bd7c09d17a9..2ea1ebfbd48 100644 --- a/advisories/unreviewed/2022/04/GHSA-f7cf-36r8-52q2/GHSA-f7cf-36r8-52q2.json +++ b/advisories/unreviewed/2022/04/GHSA-f7cf-36r8-52q2/GHSA-f7cf-36r8-52q2.json @@ -7,12 +7,8 @@ "CVE-2000-0635" ], "details": "The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fc9j-q76r-j649/GHSA-fc9j-q76r-j649.json b/advisories/unreviewed/2022/04/GHSA-fc9j-q76r-j649/GHSA-fc9j-q76r-j649.json index fe5fa11035e..8c93ed99153 100644 --- a/advisories/unreviewed/2022/04/GHSA-fc9j-q76r-j649/GHSA-fc9j-q76r-j649.json +++ b/advisories/unreviewed/2022/04/GHSA-fc9j-q76r-j649/GHSA-fc9j-q76r-j649.json @@ -7,12 +7,8 @@ "CVE-2000-0599" ], "details": "Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ffjf-v6q2-h2mv/GHSA-ffjf-v6q2-h2mv.json b/advisories/unreviewed/2022/04/GHSA-ffjf-v6q2-h2mv/GHSA-ffjf-v6q2-h2mv.json index 4f478b99f23..ec3c7348297 100644 --- a/advisories/unreviewed/2022/04/GHSA-ffjf-v6q2-h2mv/GHSA-ffjf-v6q2-h2mv.json +++ b/advisories/unreviewed/2022/04/GHSA-ffjf-v6q2-h2mv/GHSA-ffjf-v6q2-h2mv.json @@ -7,12 +7,8 @@ "CVE-2000-0565" ], "details": "SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fpcj-q3j2-7545/GHSA-fpcj-q3j2-7545.json b/advisories/unreviewed/2022/04/GHSA-fpcj-q3j2-7545/GHSA-fpcj-q3j2-7545.json index 2f32fd96649..86e3f2d323d 100644 --- a/advisories/unreviewed/2022/04/GHSA-fpcj-q3j2-7545/GHSA-fpcj-q3j2-7545.json +++ b/advisories/unreviewed/2022/04/GHSA-fpcj-q3j2-7545/GHSA-fpcj-q3j2-7545.json @@ -7,12 +7,8 @@ "CVE-2000-0600" ], "details": "Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fwxc-qvhc-7v9m/GHSA-fwxc-qvhc-7v9m.json b/advisories/unreviewed/2022/04/GHSA-fwxc-qvhc-7v9m/GHSA-fwxc-qvhc-7v9m.json index 54e0f853b46..f949a2b7db1 100644 --- a/advisories/unreviewed/2022/04/GHSA-fwxc-qvhc-7v9m/GHSA-fwxc-qvhc-7v9m.json +++ b/advisories/unreviewed/2022/04/GHSA-fwxc-qvhc-7v9m/GHSA-fwxc-qvhc-7v9m.json @@ -7,12 +7,8 @@ "CVE-2000-0575" ], "details": "SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fxx6-22cm-3977/GHSA-fxx6-22cm-3977.json b/advisories/unreviewed/2022/04/GHSA-fxx6-22cm-3977/GHSA-fxx6-22cm-3977.json index c0452c7fdf9..f6c56a0145b 100644 --- a/advisories/unreviewed/2022/04/GHSA-fxx6-22cm-3977/GHSA-fxx6-22cm-3977.json +++ b/advisories/unreviewed/2022/04/GHSA-fxx6-22cm-3977/GHSA-fxx6-22cm-3977.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-g3fc-j6w6-4h4p/GHSA-g3fc-j6w6-4h4p.json b/advisories/unreviewed/2022/04/GHSA-g3fc-j6w6-4h4p/GHSA-g3fc-j6w6-4h4p.json index 77edd026eb8..f2e82672461 100644 --- a/advisories/unreviewed/2022/04/GHSA-g3fc-j6w6-4h4p/GHSA-g3fc-j6w6-4h4p.json +++ b/advisories/unreviewed/2022/04/GHSA-g3fc-j6w6-4h4p/GHSA-g3fc-j6w6-4h4p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gghx-4gcj-rpw8/GHSA-gghx-4gcj-rpw8.json b/advisories/unreviewed/2022/04/GHSA-gghx-4gcj-rpw8/GHSA-gghx-4gcj-rpw8.json index b60bfc909ce..19a532338c0 100644 --- a/advisories/unreviewed/2022/04/GHSA-gghx-4gcj-rpw8/GHSA-gghx-4gcj-rpw8.json +++ b/advisories/unreviewed/2022/04/GHSA-gghx-4gcj-rpw8/GHSA-gghx-4gcj-rpw8.json @@ -7,12 +7,8 @@ "CVE-2000-0594" ], "details": "BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gh92-r6m8-gq4c/GHSA-gh92-r6m8-gq4c.json b/advisories/unreviewed/2022/04/GHSA-gh92-r6m8-gq4c/GHSA-gh92-r6m8-gq4c.json index 8f575be14f7..fa200b7ab9e 100644 --- a/advisories/unreviewed/2022/04/GHSA-gh92-r6m8-gq4c/GHSA-gh92-r6m8-gq4c.json +++ b/advisories/unreviewed/2022/04/GHSA-gh92-r6m8-gq4c/GHSA-gh92-r6m8-gq4c.json @@ -7,12 +7,8 @@ "CVE-2000-0581" ], "details": "Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gm9r-p48q-qmx6/GHSA-gm9r-p48q-qmx6.json b/advisories/unreviewed/2022/04/GHSA-gm9r-p48q-qmx6/GHSA-gm9r-p48q-qmx6.json index d795543c706..48d4c2fb239 100644 --- a/advisories/unreviewed/2022/04/GHSA-gm9r-p48q-qmx6/GHSA-gm9r-p48q-qmx6.json +++ b/advisories/unreviewed/2022/04/GHSA-gm9r-p48q-qmx6/GHSA-gm9r-p48q-qmx6.json @@ -7,12 +7,8 @@ "CVE-2000-0631" ], "details": "An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the \"Absent Directory Browser Argument\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gphm-f2g3-9rr5/GHSA-gphm-f2g3-9rr5.json b/advisories/unreviewed/2022/04/GHSA-gphm-f2g3-9rr5/GHSA-gphm-f2g3-9rr5.json index aa4320d24da..1eee3820944 100644 --- a/advisories/unreviewed/2022/04/GHSA-gphm-f2g3-9rr5/GHSA-gphm-f2g3-9rr5.json +++ b/advisories/unreviewed/2022/04/GHSA-gphm-f2g3-9rr5/GHSA-gphm-f2g3-9rr5.json @@ -7,12 +7,8 @@ "CVE-2000-0587" ], "details": "The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gpr4-gfq8-c66q/GHSA-gpr4-gfq8-c66q.json b/advisories/unreviewed/2022/04/GHSA-gpr4-gfq8-c66q/GHSA-gpr4-gfq8-c66q.json index e3ae7f34c06..9e547dfafb1 100644 --- a/advisories/unreviewed/2022/04/GHSA-gpr4-gfq8-c66q/GHSA-gpr4-gfq8-c66q.json +++ b/advisories/unreviewed/2022/04/GHSA-gpr4-gfq8-c66q/GHSA-gpr4-gfq8-c66q.json @@ -7,12 +7,8 @@ "CVE-2000-0548" ], "details": "Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-gx76-xx4m-wqw4/GHSA-gx76-xx4m-wqw4.json b/advisories/unreviewed/2022/04/GHSA-gx76-xx4m-wqw4/GHSA-gx76-xx4m-wqw4.json index 502f2d381d4..6ea8aa10e56 100644 --- a/advisories/unreviewed/2022/04/GHSA-gx76-xx4m-wqw4/GHSA-gx76-xx4m-wqw4.json +++ b/advisories/unreviewed/2022/04/GHSA-gx76-xx4m-wqw4/GHSA-gx76-xx4m-wqw4.json @@ -7,12 +7,8 @@ "CVE-2000-0555" ], "details": "Ceilidh allows remote attackers to cause a denial of service via a large number of POST requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h362-xvf2-9x75/GHSA-h362-xvf2-9x75.json b/advisories/unreviewed/2022/04/GHSA-h362-xvf2-9x75/GHSA-h362-xvf2-9x75.json index c5adcaaef98..7f27a2e2be6 100644 --- a/advisories/unreviewed/2022/04/GHSA-h362-xvf2-9x75/GHSA-h362-xvf2-9x75.json +++ b/advisories/unreviewed/2022/04/GHSA-h362-xvf2-9x75/GHSA-h362-xvf2-9x75.json @@ -7,12 +7,8 @@ "CVE-2000-0668" ], "details": "pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h3fp-c6fr-mp9h/GHSA-h3fp-c6fr-mp9h.json b/advisories/unreviewed/2022/04/GHSA-h3fp-c6fr-mp9h/GHSA-h3fp-c6fr-mp9h.json index 4f7740b0a2a..be07e790ac1 100644 --- a/advisories/unreviewed/2022/04/GHSA-h3fp-c6fr-mp9h/GHSA-h3fp-c6fr-mp9h.json +++ b/advisories/unreviewed/2022/04/GHSA-h3fp-c6fr-mp9h/GHSA-h3fp-c6fr-mp9h.json @@ -7,12 +7,8 @@ "CVE-2000-0604" ], "details": "gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h5jp-6w68-72m2/GHSA-h5jp-6w68-72m2.json b/advisories/unreviewed/2022/04/GHSA-h5jp-6w68-72m2/GHSA-h5jp-6w68-72m2.json index b69866003a9..5afbad06b5c 100644 --- a/advisories/unreviewed/2022/04/GHSA-h5jp-6w68-72m2/GHSA-h5jp-6w68-72m2.json +++ b/advisories/unreviewed/2022/04/GHSA-h5jp-6w68-72m2/GHSA-h5jp-6w68-72m2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h6mg-286x-2ggg/GHSA-h6mg-286x-2ggg.json b/advisories/unreviewed/2022/04/GHSA-h6mg-286x-2ggg/GHSA-h6mg-286x-2ggg.json index 568196bc869..5108ae81686 100644 --- a/advisories/unreviewed/2022/04/GHSA-h6mg-286x-2ggg/GHSA-h6mg-286x-2ggg.json +++ b/advisories/unreviewed/2022/04/GHSA-h6mg-286x-2ggg/GHSA-h6mg-286x-2ggg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-h83g-mghp-3gg7/GHSA-h83g-mghp-3gg7.json b/advisories/unreviewed/2022/04/GHSA-h83g-mghp-3gg7/GHSA-h83g-mghp-3gg7.json index 5d21ff306be..4557dbbe1f1 100644 --- a/advisories/unreviewed/2022/04/GHSA-h83g-mghp-3gg7/GHSA-h83g-mghp-3gg7.json +++ b/advisories/unreviewed/2022/04/GHSA-h83g-mghp-3gg7/GHSA-h83g-mghp-3gg7.json @@ -7,12 +7,8 @@ "CVE-2000-0541" ], "details": "The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hh83-pff3-px95/GHSA-hh83-pff3-px95.json b/advisories/unreviewed/2022/04/GHSA-hh83-pff3-px95/GHSA-hh83-pff3-px95.json index 1539c0b6c1a..6bf06d9e339 100644 --- a/advisories/unreviewed/2022/04/GHSA-hh83-pff3-px95/GHSA-hh83-pff3-px95.json +++ b/advisories/unreviewed/2022/04/GHSA-hh83-pff3-px95/GHSA-hh83-pff3-px95.json @@ -7,12 +7,8 @@ "CVE-2000-0665" ], "details": "GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hhv3-85xh-f65h/GHSA-hhv3-85xh-f65h.json b/advisories/unreviewed/2022/04/GHSA-hhv3-85xh-f65h/GHSA-hhv3-85xh-f65h.json index d91e214831f..c3ac8b7235e 100644 --- a/advisories/unreviewed/2022/04/GHSA-hhv3-85xh-f65h/GHSA-hhv3-85xh-f65h.json +++ b/advisories/unreviewed/2022/04/GHSA-hhv3-85xh-f65h/GHSA-hhv3-85xh-f65h.json @@ -7,12 +7,8 @@ "CVE-2000-0542" ], "details": "Tigris remote access server before 11.5.4.22 does not properly record Radius accounting information when a user fails the initial login authentication but subsequently succeeds.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hqf4-9x6j-98g9/GHSA-hqf4-9x6j-98g9.json b/advisories/unreviewed/2022/04/GHSA-hqf4-9x6j-98g9/GHSA-hqf4-9x6j-98g9.json index cb378ee6a81..d5feb95bb46 100644 --- a/advisories/unreviewed/2022/04/GHSA-hqf4-9x6j-98g9/GHSA-hqf4-9x6j-98g9.json +++ b/advisories/unreviewed/2022/04/GHSA-hqf4-9x6j-98g9/GHSA-hqf4-9x6j-98g9.json @@ -7,12 +7,8 @@ "CVE-2000-0596" ], "details": "Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the \"IE Script\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hv99-5fhv-j4mj/GHSA-hv99-5fhv-j4mj.json b/advisories/unreviewed/2022/04/GHSA-hv99-5fhv-j4mj/GHSA-hv99-5fhv-j4mj.json index 83e6bb3ead4..9fdc3b71d5f 100644 --- a/advisories/unreviewed/2022/04/GHSA-hv99-5fhv-j4mj/GHSA-hv99-5fhv-j4mj.json +++ b/advisories/unreviewed/2022/04/GHSA-hv99-5fhv-j4mj/GHSA-hv99-5fhv-j4mj.json @@ -7,12 +7,8 @@ "CVE-2000-0605" ], "details": "Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hvq3-qm62-8ff5/GHSA-hvq3-qm62-8ff5.json b/advisories/unreviewed/2022/04/GHSA-hvq3-qm62-8ff5/GHSA-hvq3-qm62-8ff5.json index ca1e1e32157..5ec3ae30b27 100644 --- a/advisories/unreviewed/2022/04/GHSA-hvq3-qm62-8ff5/GHSA-hvq3-qm62-8ff5.json +++ b/advisories/unreviewed/2022/04/GHSA-hvq3-qm62-8ff5/GHSA-hvq3-qm62-8ff5.json @@ -7,12 +7,8 @@ "CVE-2000-0591" ], "details": "Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hx6m-rxfx-9j6c/GHSA-hx6m-rxfx-9j6c.json b/advisories/unreviewed/2022/04/GHSA-hx6m-rxfx-9j6c/GHSA-hx6m-rxfx-9j6c.json index 830841ca2bc..2808c7a8b9a 100644 --- a/advisories/unreviewed/2022/04/GHSA-hx6m-rxfx-9j6c/GHSA-hx6m-rxfx-9j6c.json +++ b/advisories/unreviewed/2022/04/GHSA-hx6m-rxfx-9j6c/GHSA-hx6m-rxfx-9j6c.json @@ -7,12 +7,8 @@ "CVE-2000-0602" ], "details": "Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j5xj-256c-jv3v/GHSA-j5xj-256c-jv3v.json b/advisories/unreviewed/2022/04/GHSA-j5xj-256c-jv3v/GHSA-j5xj-256c-jv3v.json index 91400c5c6c2..4c37dc015cc 100644 --- a/advisories/unreviewed/2022/04/GHSA-j5xj-256c-jv3v/GHSA-j5xj-256c-jv3v.json +++ b/advisories/unreviewed/2022/04/GHSA-j5xj-256c-jv3v/GHSA-j5xj-256c-jv3v.json @@ -7,12 +7,8 @@ "CVE-2000-0636" ], "details": "HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j74f-5rh4-57cv/GHSA-j74f-5rh4-57cv.json b/advisories/unreviewed/2022/04/GHSA-j74f-5rh4-57cv/GHSA-j74f-5rh4-57cv.json index 5781e49a47b..4326981ae44 100644 --- a/advisories/unreviewed/2022/04/GHSA-j74f-5rh4-57cv/GHSA-j74f-5rh4-57cv.json +++ b/advisories/unreviewed/2022/04/GHSA-j74f-5rh4-57cv/GHSA-j74f-5rh4-57cv.json @@ -7,12 +7,8 @@ "CVE-2000-0633" ], "details": "Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j7xp-993g-v2pc/GHSA-j7xp-993g-v2pc.json b/advisories/unreviewed/2022/04/GHSA-j7xp-993g-v2pc/GHSA-j7xp-993g-v2pc.json index d10f0c26568..5310063e2d2 100644 --- a/advisories/unreviewed/2022/04/GHSA-j7xp-993g-v2pc/GHSA-j7xp-993g-v2pc.json +++ b/advisories/unreviewed/2022/04/GHSA-j7xp-993g-v2pc/GHSA-j7xp-993g-v2pc.json @@ -7,12 +7,8 @@ "CVE-2000-0639" ], "details": "The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jc43-58xv-97mp/GHSA-jc43-58xv-97mp.json b/advisories/unreviewed/2022/04/GHSA-jc43-58xv-97mp/GHSA-jc43-58xv-97mp.json index 95cd47e4658..b394d247d5f 100644 --- a/advisories/unreviewed/2022/04/GHSA-jc43-58xv-97mp/GHSA-jc43-58xv-97mp.json +++ b/advisories/unreviewed/2022/04/GHSA-jc43-58xv-97mp/GHSA-jc43-58xv-97mp.json @@ -7,12 +7,8 @@ "CVE-2000-0666" ], "details": "rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jhvw-wg26-wj9c/GHSA-jhvw-wg26-wj9c.json b/advisories/unreviewed/2022/04/GHSA-jhvw-wg26-wj9c/GHSA-jhvw-wg26-wj9c.json index 3fbce0272df..93ea9b0fb15 100644 --- a/advisories/unreviewed/2022/04/GHSA-jhvw-wg26-wj9c/GHSA-jhvw-wg26-wj9c.json +++ b/advisories/unreviewed/2022/04/GHSA-jhvw-wg26-wj9c/GHSA-jhvw-wg26-wj9c.json @@ -7,12 +7,8 @@ "CVE-2000-0680" ], "details": "The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jr23-46j8-97mr/GHSA-jr23-46j8-97mr.json b/advisories/unreviewed/2022/04/GHSA-jr23-46j8-97mr/GHSA-jr23-46j8-97mr.json index aae8665f544..e7878f24e1c 100644 --- a/advisories/unreviewed/2022/04/GHSA-jr23-46j8-97mr/GHSA-jr23-46j8-97mr.json +++ b/advisories/unreviewed/2022/04/GHSA-jr23-46j8-97mr/GHSA-jr23-46j8-97mr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m2cw-8f75-qf8v/GHSA-m2cw-8f75-qf8v.json b/advisories/unreviewed/2022/04/GHSA-m2cw-8f75-qf8v/GHSA-m2cw-8f75-qf8v.json index 80ce1712473..c8526800a92 100644 --- a/advisories/unreviewed/2022/04/GHSA-m2cw-8f75-qf8v/GHSA-m2cw-8f75-qf8v.json +++ b/advisories/unreviewed/2022/04/GHSA-m2cw-8f75-qf8v/GHSA-m2cw-8f75-qf8v.json @@ -7,12 +7,8 @@ "CVE-2000-0597" ], "details": "Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the \"Office HTML Script\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m5jq-cp4v-64qc/GHSA-m5jq-cp4v-64qc.json b/advisories/unreviewed/2022/04/GHSA-m5jq-cp4v-64qc/GHSA-m5jq-cp4v-64qc.json index 8cb4ce30977..a15b4af5c5a 100644 --- a/advisories/unreviewed/2022/04/GHSA-m5jq-cp4v-64qc/GHSA-m5jq-cp4v-64qc.json +++ b/advisories/unreviewed/2022/04/GHSA-m5jq-cp4v-64qc/GHSA-m5jq-cp4v-64qc.json @@ -7,12 +7,8 @@ "CVE-2000-0592" ], "details": "Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m69c-hmx8-c8ph/GHSA-m69c-hmx8-c8ph.json b/advisories/unreviewed/2022/04/GHSA-m69c-hmx8-c8ph/GHSA-m69c-hmx8-c8ph.json index 84c7b7a40e9..bcffcc9cfaa 100644 --- a/advisories/unreviewed/2022/04/GHSA-m69c-hmx8-c8ph/GHSA-m69c-hmx8-c8ph.json +++ b/advisories/unreviewed/2022/04/GHSA-m69c-hmx8-c8ph/GHSA-m69c-hmx8-c8ph.json @@ -7,12 +7,8 @@ "CVE-2000-0641" ], "details": "Savant web server allows remote attackers to execute arbitrary commands via a long GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m7mj-vcp8-4rpq/GHSA-m7mj-vcp8-4rpq.json b/advisories/unreviewed/2022/04/GHSA-m7mj-vcp8-4rpq/GHSA-m7mj-vcp8-4rpq.json index 0a9cd5a5f37..87232f93cbd 100644 --- a/advisories/unreviewed/2022/04/GHSA-m7mj-vcp8-4rpq/GHSA-m7mj-vcp8-4rpq.json +++ b/advisories/unreviewed/2022/04/GHSA-m7mj-vcp8-4rpq/GHSA-m7mj-vcp8-4rpq.json @@ -7,12 +7,8 @@ "CVE-2000-0543" ], "details": "The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not have a reverse DNS entry and they connect to port 4000.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m85g-37m6-fpww/GHSA-m85g-37m6-fpww.json b/advisories/unreviewed/2022/04/GHSA-m85g-37m6-fpww/GHSA-m85g-37m6-fpww.json index 3e4725f1745..a4bb001dff0 100644 --- a/advisories/unreviewed/2022/04/GHSA-m85g-37m6-fpww/GHSA-m85g-37m6-fpww.json +++ b/advisories/unreviewed/2022/04/GHSA-m85g-37m6-fpww/GHSA-m85g-37m6-fpww.json @@ -7,12 +7,8 @@ "CVE-2000-0624" ], "details": "Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mfrx-mc2c-9g9w/GHSA-mfrx-mc2c-9g9w.json b/advisories/unreviewed/2022/04/GHSA-mfrx-mc2c-9g9w/GHSA-mfrx-mc2c-9g9w.json index 0685575d82a..473aea0ed58 100644 --- a/advisories/unreviewed/2022/04/GHSA-mfrx-mc2c-9g9w/GHSA-mfrx-mc2c-9g9w.json +++ b/advisories/unreviewed/2022/04/GHSA-mfrx-mc2c-9g9w/GHSA-mfrx-mc2c-9g9w.json @@ -7,12 +7,8 @@ "CVE-2000-0559" ], "details": "eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mmrv-3fq5-g8jf/GHSA-mmrv-3fq5-g8jf.json b/advisories/unreviewed/2022/04/GHSA-mmrv-3fq5-g8jf/GHSA-mmrv-3fq5-g8jf.json index 7663a03e977..c5c16630b01 100644 --- a/advisories/unreviewed/2022/04/GHSA-mmrv-3fq5-g8jf/GHSA-mmrv-3fq5-g8jf.json +++ b/advisories/unreviewed/2022/04/GHSA-mmrv-3fq5-g8jf/GHSA-mmrv-3fq5-g8jf.json @@ -7,12 +7,8 @@ "CVE-2000-0671" ], "details": "Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mqgq-47w7-8ccc/GHSA-mqgq-47w7-8ccc.json b/advisories/unreviewed/2022/04/GHSA-mqgq-47w7-8ccc/GHSA-mqgq-47w7-8ccc.json index 8302b4aae02..158c9a459ab 100644 --- a/advisories/unreviewed/2022/04/GHSA-mqgq-47w7-8ccc/GHSA-mqgq-47w7-8ccc.json +++ b/advisories/unreviewed/2022/04/GHSA-mqgq-47w7-8ccc/GHSA-mqgq-47w7-8ccc.json @@ -7,12 +7,8 @@ "CVE-2000-0556" ], "details": "Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to cause a denial of service by sending a large user name to the user dialog running on port 8002.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mxfj-2pw5-7crq/GHSA-mxfj-2pw5-7crq.json b/advisories/unreviewed/2022/04/GHSA-mxfj-2pw5-7crq/GHSA-mxfj-2pw5-7crq.json index 819fe70c39b..5c3dc6c4c94 100644 --- a/advisories/unreviewed/2022/04/GHSA-mxfj-2pw5-7crq/GHSA-mxfj-2pw5-7crq.json +++ b/advisories/unreviewed/2022/04/GHSA-mxfj-2pw5-7crq/GHSA-mxfj-2pw5-7crq.json @@ -7,12 +7,8 @@ "CVE-2000-0570" ], "details": "FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p3qf-8c2m-c92q/GHSA-p3qf-8c2m-c92q.json b/advisories/unreviewed/2022/04/GHSA-p3qf-8c2m-c92q/GHSA-p3qf-8c2m-c92q.json index 284b8347b63..a67ab0506e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-p3qf-8c2m-c92q/GHSA-p3qf-8c2m-c92q.json +++ b/advisories/unreviewed/2022/04/GHSA-p3qf-8c2m-c92q/GHSA-p3qf-8c2m-c92q.json @@ -7,12 +7,8 @@ "CVE-2000-0590" ], "details": "Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p6c2-5pjm-qmjv/GHSA-p6c2-5pjm-qmjv.json b/advisories/unreviewed/2022/04/GHSA-p6c2-5pjm-qmjv/GHSA-p6c2-5pjm-qmjv.json index 12999f01617..92a60af5b6d 100644 --- a/advisories/unreviewed/2022/04/GHSA-p6c2-5pjm-qmjv/GHSA-p6c2-5pjm-qmjv.json +++ b/advisories/unreviewed/2022/04/GHSA-p6c2-5pjm-qmjv/GHSA-p6c2-5pjm-qmjv.json @@ -7,12 +7,8 @@ "CVE-2000-0607" ], "details": "Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p854-gmj6-9jfw/GHSA-p854-gmj6-9jfw.json b/advisories/unreviewed/2022/04/GHSA-p854-gmj6-9jfw/GHSA-p854-gmj6-9jfw.json index 2a5da88ecdb..d595affeb48 100644 --- a/advisories/unreviewed/2022/04/GHSA-p854-gmj6-9jfw/GHSA-p854-gmj6-9jfw.json +++ b/advisories/unreviewed/2022/04/GHSA-p854-gmj6-9jfw/GHSA-p854-gmj6-9jfw.json @@ -7,12 +7,8 @@ "CVE-2000-0563" ], "details": "The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p9p4-x3gf-gjm8/GHSA-p9p4-x3gf-gjm8.json b/advisories/unreviewed/2022/04/GHSA-p9p4-x3gf-gjm8/GHSA-p9p4-x3gf-gjm8.json index 9568bd3804b..2b9ee855eea 100644 --- a/advisories/unreviewed/2022/04/GHSA-p9p4-x3gf-gjm8/GHSA-p9p4-x3gf-gjm8.json +++ b/advisories/unreviewed/2022/04/GHSA-p9p4-x3gf-gjm8/GHSA-p9p4-x3gf-gjm8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-pfr8-644q-f99g/GHSA-pfr8-644q-f99g.json b/advisories/unreviewed/2022/04/GHSA-pfr8-644q-f99g/GHSA-pfr8-644q-f99g.json index 126ff9c678c..747e1996daf 100644 --- a/advisories/unreviewed/2022/04/GHSA-pfr8-644q-f99g/GHSA-pfr8-644q-f99g.json +++ b/advisories/unreviewed/2022/04/GHSA-pfr8-644q-f99g/GHSA-pfr8-644q-f99g.json @@ -7,12 +7,8 @@ "CVE-2000-0640" ], "details": "Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pgpv-rcv8-q82m/GHSA-pgpv-rcv8-q82m.json b/advisories/unreviewed/2022/04/GHSA-pgpv-rcv8-q82m/GHSA-pgpv-rcv8-q82m.json index 73d0d3be632..44183efccec 100644 --- a/advisories/unreviewed/2022/04/GHSA-pgpv-rcv8-q82m/GHSA-pgpv-rcv8-q82m.json +++ b/advisories/unreviewed/2022/04/GHSA-pgpv-rcv8-q82m/GHSA-pgpv-rcv8-q82m.json @@ -7,12 +7,8 @@ "CVE-2000-0664" ], "details": "AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pvc7-5x99-c9mm/GHSA-pvc7-5x99-c9mm.json b/advisories/unreviewed/2022/04/GHSA-pvc7-5x99-c9mm/GHSA-pvc7-5x99-c9mm.json index 41bfa9c2b82..8c96f1bfd5d 100644 --- a/advisories/unreviewed/2022/04/GHSA-pvc7-5x99-c9mm/GHSA-pvc7-5x99-c9mm.json +++ b/advisories/unreviewed/2022/04/GHSA-pvc7-5x99-c9mm/GHSA-pvc7-5x99-c9mm.json @@ -7,12 +7,8 @@ "CVE-2000-0582" ], "details": "Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pxcf-v9c2-vw3r/GHSA-pxcf-v9c2-vw3r.json b/advisories/unreviewed/2022/04/GHSA-pxcf-v9c2-vw3r/GHSA-pxcf-v9c2-vw3r.json index 981dfaefb59..98564acac5f 100644 --- a/advisories/unreviewed/2022/04/GHSA-pxcf-v9c2-vw3r/GHSA-pxcf-v9c2-vw3r.json +++ b/advisories/unreviewed/2022/04/GHSA-pxcf-v9c2-vw3r/GHSA-pxcf-v9c2-vw3r.json @@ -7,12 +7,8 @@ "CVE-2000-0613" ], "details": "Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pxpj-c4wv-6w3x/GHSA-pxpj-c4wv-6w3x.json b/advisories/unreviewed/2022/04/GHSA-pxpj-c4wv-6w3x/GHSA-pxpj-c4wv-6w3x.json index 7f9db52d6ff..d0bd10a95f6 100644 --- a/advisories/unreviewed/2022/04/GHSA-pxpj-c4wv-6w3x/GHSA-pxpj-c4wv-6w3x.json +++ b/advisories/unreviewed/2022/04/GHSA-pxpj-c4wv-6w3x/GHSA-pxpj-c4wv-6w3x.json @@ -7,12 +7,8 @@ "CVE-2000-0579" ], "details": "IRIX crontab creates temporary files with predictable file names and with the umask of the user, which could allow local users to modify another user's crontab file as it is being edited.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r33h-6mqf-5rp3/GHSA-r33h-6mqf-5rp3.json b/advisories/unreviewed/2022/04/GHSA-r33h-6mqf-5rp3/GHSA-r33h-6mqf-5rp3.json index bf1ca52d5d0..3b5ece88c15 100644 --- a/advisories/unreviewed/2022/04/GHSA-r33h-6mqf-5rp3/GHSA-r33h-6mqf-5rp3.json +++ b/advisories/unreviewed/2022/04/GHSA-r33h-6mqf-5rp3/GHSA-r33h-6mqf-5rp3.json @@ -7,12 +7,8 @@ "CVE-2000-0593" ], "details": "WinProxy 2.0 and 2.0.1 allows remote attackers to cause a denial of service by sending an HTTP GET request without listing an HTTP version number.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r4c5-4hcj-q3cc/GHSA-r4c5-4hcj-q3cc.json b/advisories/unreviewed/2022/04/GHSA-r4c5-4hcj-q3cc/GHSA-r4c5-4hcj-q3cc.json index 03523960144..c73cb7dfe89 100644 --- a/advisories/unreviewed/2022/04/GHSA-r4c5-4hcj-q3cc/GHSA-r4c5-4hcj-q3cc.json +++ b/advisories/unreviewed/2022/04/GHSA-r4c5-4hcj-q3cc/GHSA-r4c5-4hcj-q3cc.json @@ -7,12 +7,8 @@ "CVE-2000-0660" ], "details": "The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rg52-qjhr-v639/GHSA-rg52-qjhr-v639.json b/advisories/unreviewed/2022/04/GHSA-rg52-qjhr-v639/GHSA-rg52-qjhr-v639.json index 2613cc3e1d9..b37557ba45e 100644 --- a/advisories/unreviewed/2022/04/GHSA-rg52-qjhr-v639/GHSA-rg52-qjhr-v639.json +++ b/advisories/unreviewed/2022/04/GHSA-rg52-qjhr-v639/GHSA-rg52-qjhr-v639.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rg84-mjm4-xc43/GHSA-rg84-mjm4-xc43.json b/advisories/unreviewed/2022/04/GHSA-rg84-mjm4-xc43/GHSA-rg84-mjm4-xc43.json index 6b5c4ad143d..4c5cdeb4a67 100644 --- a/advisories/unreviewed/2022/04/GHSA-rg84-mjm4-xc43/GHSA-rg84-mjm4-xc43.json +++ b/advisories/unreviewed/2022/04/GHSA-rg84-mjm4-xc43/GHSA-rg84-mjm4-xc43.json @@ -7,12 +7,8 @@ "CVE-2000-0647" ], "details": "WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rhxq-hxv2-28cf/GHSA-rhxq-hxv2-28cf.json b/advisories/unreviewed/2022/04/GHSA-rhxq-hxv2-28cf/GHSA-rhxq-hxv2-28cf.json index fb03c4b2940..92af0d012ad 100644 --- a/advisories/unreviewed/2022/04/GHSA-rhxq-hxv2-28cf/GHSA-rhxq-hxv2-28cf.json +++ b/advisories/unreviewed/2022/04/GHSA-rhxq-hxv2-28cf/GHSA-rhxq-hxv2-28cf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rpxp-9755-926w/GHSA-rpxp-9755-926w.json b/advisories/unreviewed/2022/04/GHSA-rpxp-9755-926w/GHSA-rpxp-9755-926w.json index 129f53806e1..ec27b3112b3 100644 --- a/advisories/unreviewed/2022/04/GHSA-rpxp-9755-926w/GHSA-rpxp-9755-926w.json +++ b/advisories/unreviewed/2022/04/GHSA-rpxp-9755-926w/GHSA-rpxp-9755-926w.json @@ -7,12 +7,8 @@ "CVE-2000-0625" ], "details": "NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decrypt the password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rv5h-jg6x-f3vp/GHSA-rv5h-jg6x-f3vp.json b/advisories/unreviewed/2022/04/GHSA-rv5h-jg6x-f3vp/GHSA-rv5h-jg6x-f3vp.json index 065b08a7954..f5a47e0ad62 100644 --- a/advisories/unreviewed/2022/04/GHSA-rv5h-jg6x-f3vp/GHSA-rv5h-jg6x-f3vp.json +++ b/advisories/unreviewed/2022/04/GHSA-rv5h-jg6x-f3vp/GHSA-rv5h-jg6x-f3vp.json @@ -7,12 +7,8 @@ "CVE-2000-0649" ], "details": "IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rx3c-x33m-733h/GHSA-rx3c-x33m-733h.json b/advisories/unreviewed/2022/04/GHSA-rx3c-x33m-733h/GHSA-rx3c-x33m-733h.json index 8ddf0cc09a3..6be0cd322f5 100644 --- a/advisories/unreviewed/2022/04/GHSA-rx3c-x33m-733h/GHSA-rx3c-x33m-733h.json +++ b/advisories/unreviewed/2022/04/GHSA-rx3c-x33m-733h/GHSA-rx3c-x33m-733h.json @@ -7,12 +7,8 @@ "CVE-2000-0576" ], "details": "Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rxr9-jwx6-w6jq/GHSA-rxr9-jwx6-w6jq.json b/advisories/unreviewed/2022/04/GHSA-rxr9-jwx6-w6jq/GHSA-rxr9-jwx6-w6jq.json index cb5ed4305d9..21abfa7b9a5 100644 --- a/advisories/unreviewed/2022/04/GHSA-rxr9-jwx6-w6jq/GHSA-rxr9-jwx6-w6jq.json +++ b/advisories/unreviewed/2022/04/GHSA-rxr9-jwx6-w6jq/GHSA-rxr9-jwx6-w6jq.json @@ -7,12 +7,8 @@ "CVE-2000-0564" ], "details": "The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rxxv-f2jp-v9vp/GHSA-rxxv-f2jp-v9vp.json b/advisories/unreviewed/2022/04/GHSA-rxxv-f2jp-v9vp/GHSA-rxxv-f2jp-v9vp.json index 649bdf4e5a4..ddec8032b29 100644 --- a/advisories/unreviewed/2022/04/GHSA-rxxv-f2jp-v9vp/GHSA-rxxv-f2jp-v9vp.json +++ b/advisories/unreviewed/2022/04/GHSA-rxxv-f2jp-v9vp/GHSA-rxxv-f2jp-v9vp.json @@ -7,12 +7,8 @@ "CVE-2000-0606" ], "details": "Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v25j-6rjr-73r2/GHSA-v25j-6rjr-73r2.json b/advisories/unreviewed/2022/04/GHSA-v25j-6rjr-73r2/GHSA-v25j-6rjr-73r2.json index 37bc1c3e539..0a08f0ab1d2 100644 --- a/advisories/unreviewed/2022/04/GHSA-v25j-6rjr-73r2/GHSA-v25j-6rjr-73r2.json +++ b/advisories/unreviewed/2022/04/GHSA-v25j-6rjr-73r2/GHSA-v25j-6rjr-73r2.json @@ -7,12 +7,8 @@ "CVE-2000-0562" ], "details": "BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v2g6-64p5-pq6w/GHSA-v2g6-64p5-pq6w.json b/advisories/unreviewed/2022/04/GHSA-v2g6-64p5-pq6w/GHSA-v2g6-64p5-pq6w.json index 7c248de7ae7..90798650587 100644 --- a/advisories/unreviewed/2022/04/GHSA-v2g6-64p5-pq6w/GHSA-v2g6-64p5-pq6w.json +++ b/advisories/unreviewed/2022/04/GHSA-v2g6-64p5-pq6w/GHSA-v2g6-64p5-pq6w.json @@ -7,12 +7,8 @@ "CVE-2000-0569" ], "details": "Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v3p7-33wf-f77j/GHSA-v3p7-33wf-f77j.json b/advisories/unreviewed/2022/04/GHSA-v3p7-33wf-f77j/GHSA-v3p7-33wf-f77j.json index 98a1801739b..01e4403e95d 100644 --- a/advisories/unreviewed/2022/04/GHSA-v3p7-33wf-f77j/GHSA-v3p7-33wf-f77j.json +++ b/advisories/unreviewed/2022/04/GHSA-v3p7-33wf-f77j/GHSA-v3p7-33wf-f77j.json @@ -7,12 +7,8 @@ "CVE-2000-0580" ], "details": "Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v8cq-jwh7-j9xh/GHSA-v8cq-jwh7-j9xh.json b/advisories/unreviewed/2022/04/GHSA-v8cq-jwh7-j9xh/GHSA-v8cq-jwh7-j9xh.json index 74532dd4f27..c1938f7b590 100644 --- a/advisories/unreviewed/2022/04/GHSA-v8cq-jwh7-j9xh/GHSA-v8cq-jwh7-j9xh.json +++ b/advisories/unreviewed/2022/04/GHSA-v8cq-jwh7-j9xh/GHSA-v8cq-jwh7-j9xh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-vf9c-hw5f-pr3r/GHSA-vf9c-hw5f-pr3r.json b/advisories/unreviewed/2022/04/GHSA-vf9c-hw5f-pr3r/GHSA-vf9c-hw5f-pr3r.json index d6e519eff70..9ad011ef6bd 100644 --- a/advisories/unreviewed/2022/04/GHSA-vf9c-hw5f-pr3r/GHSA-vf9c-hw5f-pr3r.json +++ b/advisories/unreviewed/2022/04/GHSA-vf9c-hw5f-pr3r/GHSA-vf9c-hw5f-pr3r.json @@ -7,12 +7,8 @@ "CVE-2000-0603" ], "details": "Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the \"Stored Procedure Permissions\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vq3q-gw2w-fwwv/GHSA-vq3q-gw2w-fwwv.json b/advisories/unreviewed/2022/04/GHSA-vq3q-gw2w-fwwv/GHSA-vq3q-gw2w-fwwv.json index 60c7e78322e..a0e2f2fb91a 100644 --- a/advisories/unreviewed/2022/04/GHSA-vq3q-gw2w-fwwv/GHSA-vq3q-gw2w-fwwv.json +++ b/advisories/unreviewed/2022/04/GHSA-vq3q-gw2w-fwwv/GHSA-vq3q-gw2w-fwwv.json @@ -7,12 +7,8 @@ "CVE-2000-0659" ], "details": "Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vvh2-vwv7-8grx/GHSA-vvh2-vwv7-8grx.json b/advisories/unreviewed/2022/04/GHSA-vvh2-vwv7-8grx/GHSA-vvh2-vwv7-8grx.json index 5823bcaa914..0287a64ba2e 100644 --- a/advisories/unreviewed/2022/04/GHSA-vvh2-vwv7-8grx/GHSA-vvh2-vwv7-8grx.json +++ b/advisories/unreviewed/2022/04/GHSA-vvh2-vwv7-8grx/GHSA-vvh2-vwv7-8grx.json @@ -7,12 +7,8 @@ "CVE-2000-0621" ], "details": "Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the \"Cache Bypass\" vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vxp6-2m83-3w8p/GHSA-vxp6-2m83-3w8p.json b/advisories/unreviewed/2022/04/GHSA-vxp6-2m83-3w8p/GHSA-vxp6-2m83-3w8p.json index 99c08989634..fe1066c0419 100644 --- a/advisories/unreviewed/2022/04/GHSA-vxp6-2m83-3w8p/GHSA-vxp6-2m83-3w8p.json +++ b/advisories/unreviewed/2022/04/GHSA-vxp6-2m83-3w8p/GHSA-vxp6-2m83-3w8p.json @@ -7,12 +7,8 @@ "CVE-2000-0614" ], "details": "Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w2fq-mj73-7568/GHSA-w2fq-mj73-7568.json b/advisories/unreviewed/2022/04/GHSA-w2fq-mj73-7568/GHSA-w2fq-mj73-7568.json index 67576cfe1f7..7e8eb789dc1 100644 --- a/advisories/unreviewed/2022/04/GHSA-w2fq-mj73-7568/GHSA-w2fq-mj73-7568.json +++ b/advisories/unreviewed/2022/04/GHSA-w2fq-mj73-7568/GHSA-w2fq-mj73-7568.json @@ -7,12 +7,8 @@ "CVE-2000-0627" ], "details": "BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w3g2-3297-gcrq/GHSA-w3g2-3297-gcrq.json b/advisories/unreviewed/2022/04/GHSA-w3g2-3297-gcrq/GHSA-w3g2-3297-gcrq.json index e7822e45986..7fd720dc17a 100644 --- a/advisories/unreviewed/2022/04/GHSA-w3g2-3297-gcrq/GHSA-w3g2-3297-gcrq.json +++ b/advisories/unreviewed/2022/04/GHSA-w3g2-3297-gcrq/GHSA-w3g2-3297-gcrq.json @@ -7,12 +7,8 @@ "CVE-2000-0616" ], "details": "Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wc6x-q3v9-6hjf/GHSA-wc6x-q3v9-6hjf.json b/advisories/unreviewed/2022/04/GHSA-wc6x-q3v9-6hjf/GHSA-wc6x-q3v9-6hjf.json index bb02ab4b15b..d458aed1d00 100644 --- a/advisories/unreviewed/2022/04/GHSA-wc6x-q3v9-6hjf/GHSA-wc6x-q3v9-6hjf.json +++ b/advisories/unreviewed/2022/04/GHSA-wc6x-q3v9-6hjf/GHSA-wc6x-q3v9-6hjf.json @@ -7,12 +7,8 @@ "CVE-2000-0571" ], "details": "LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wf72-vr87-m228/GHSA-wf72-vr87-m228.json b/advisories/unreviewed/2022/04/GHSA-wf72-vr87-m228/GHSA-wf72-vr87-m228.json index 6b362aa1b40..3b7589ef45b 100644 --- a/advisories/unreviewed/2022/04/GHSA-wf72-vr87-m228/GHSA-wf72-vr87-m228.json +++ b/advisories/unreviewed/2022/04/GHSA-wf72-vr87-m228/GHSA-wf72-vr87-m228.json @@ -7,12 +7,8 @@ "CVE-2000-0651" ], "details": "The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wmhx-3hr4-6h39/GHSA-wmhx-3hr4-6h39.json b/advisories/unreviewed/2022/04/GHSA-wmhx-3hr4-6h39/GHSA-wmhx-3hr4-6h39.json index ecdd0bcb8b0..e478cb43e1c 100644 --- a/advisories/unreviewed/2022/04/GHSA-wmhx-3hr4-6h39/GHSA-wmhx-3hr4-6h39.json +++ b/advisories/unreviewed/2022/04/GHSA-wmhx-3hr4-6h39/GHSA-wmhx-3hr4-6h39.json @@ -7,12 +7,8 @@ "CVE-2000-0553" ], "details": "Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping \"return-rst\" and \"keep state\" rules, allows remote attackers to bypass access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wr34-64f9-xpxq/GHSA-wr34-64f9-xpxq.json b/advisories/unreviewed/2022/04/GHSA-wr34-64f9-xpxq/GHSA-wr34-64f9-xpxq.json index 5fbb5e1d93b..6e056710533 100644 --- a/advisories/unreviewed/2022/04/GHSA-wr34-64f9-xpxq/GHSA-wr34-64f9-xpxq.json +++ b/advisories/unreviewed/2022/04/GHSA-wr34-64f9-xpxq/GHSA-wr34-64f9-xpxq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x4xf-2prm-xx25/GHSA-x4xf-2prm-xx25.json b/advisories/unreviewed/2022/04/GHSA-x4xf-2prm-xx25/GHSA-x4xf-2prm-xx25.json index dd0ee141dd2..d4c2bd9e6e9 100644 --- a/advisories/unreviewed/2022/04/GHSA-x4xf-2prm-xx25/GHSA-x4xf-2prm-xx25.json +++ b/advisories/unreviewed/2022/04/GHSA-x4xf-2prm-xx25/GHSA-x4xf-2prm-xx25.json @@ -7,12 +7,8 @@ "CVE-2000-0618" ], "details": "Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x5rf-j496-m69m/GHSA-x5rf-j496-m69m.json b/advisories/unreviewed/2022/04/GHSA-x5rf-j496-m69m/GHSA-x5rf-j496-m69m.json index c622c8500ed..d211acec205 100644 --- a/advisories/unreviewed/2022/04/GHSA-x5rf-j496-m69m/GHSA-x5rf-j496-m69m.json +++ b/advisories/unreviewed/2022/04/GHSA-x5rf-j496-m69m/GHSA-x5rf-j496-m69m.json @@ -7,12 +7,8 @@ "CVE-2000-0601" ], "details": "LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x635-xvwm-g4ww/GHSA-x635-xvwm-g4ww.json b/advisories/unreviewed/2022/04/GHSA-x635-xvwm-g4ww/GHSA-x635-xvwm-g4ww.json index c489379aa47..b1182be0b57 100644 --- a/advisories/unreviewed/2022/04/GHSA-x635-xvwm-g4ww/GHSA-x635-xvwm-g4ww.json +++ b/advisories/unreviewed/2022/04/GHSA-x635-xvwm-g4ww/GHSA-x635-xvwm-g4ww.json @@ -7,12 +7,8 @@ "CVE-2000-0677" ], "details": "Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xc28-23vr-vh39/GHSA-xc28-23vr-vh39.json b/advisories/unreviewed/2022/04/GHSA-xc28-23vr-vh39/GHSA-xc28-23vr-vh39.json index 9f982ae5f55..4d5292c88b6 100644 --- a/advisories/unreviewed/2022/04/GHSA-xc28-23vr-vh39/GHSA-xc28-23vr-vh39.json +++ b/advisories/unreviewed/2022/04/GHSA-xc28-23vr-vh39/GHSA-xc28-23vr-vh39.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-xfg8-c4cc-3fg2/GHSA-xfg8-c4cc-3fg2.json b/advisories/unreviewed/2022/04/GHSA-xfg8-c4cc-3fg2/GHSA-xfg8-c4cc-3fg2.json index 191f10b91e6..7a6ca44d54b 100644 --- a/advisories/unreviewed/2022/04/GHSA-xfg8-c4cc-3fg2/GHSA-xfg8-c4cc-3fg2.json +++ b/advisories/unreviewed/2022/04/GHSA-xfg8-c4cc-3fg2/GHSA-xfg8-c4cc-3fg2.json @@ -7,12 +7,8 @@ "CVE-2000-0656" ], "details": "Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xfmh-wgwr-479f/GHSA-xfmh-wgwr-479f.json b/advisories/unreviewed/2022/04/GHSA-xfmh-wgwr-479f/GHSA-xfmh-wgwr-479f.json index 413dc853781..22fb027181f 100644 --- a/advisories/unreviewed/2022/04/GHSA-xfmh-wgwr-479f/GHSA-xfmh-wgwr-479f.json +++ b/advisories/unreviewed/2022/04/GHSA-xfmh-wgwr-479f/GHSA-xfmh-wgwr-479f.json @@ -7,12 +7,8 @@ "CVE-2000-0619" ], "details": "Top Layer AppSwitch 2500 allows remote attackers to cause a denial of service via malformed ICMP packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xhq3-46hw-hr5h/GHSA-xhq3-46hw-hr5h.json b/advisories/unreviewed/2022/04/GHSA-xhq3-46hw-hr5h/GHSA-xhq3-46hw-hr5h.json index d0ba645e3fd..e0d2c5ae68c 100644 --- a/advisories/unreviewed/2022/04/GHSA-xhq3-46hw-hr5h/GHSA-xhq3-46hw-hr5h.json +++ b/advisories/unreviewed/2022/04/GHSA-xhq3-46hw-hr5h/GHSA-xhq3-46hw-hr5h.json @@ -7,12 +7,8 @@ "CVE-2000-0661" ], "details": "WircSrv IRC Server 5.07s allows remote attackers to cause a denial of service via a long string to the server port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xpxm-j39p-5vcw/GHSA-xpxm-j39p-5vcw.json b/advisories/unreviewed/2022/04/GHSA-xpxm-j39p-5vcw/GHSA-xpxm-j39p-5vcw.json index ad31410c0b0..889d13fc2af 100644 --- a/advisories/unreviewed/2022/04/GHSA-xpxm-j39p-5vcw/GHSA-xpxm-j39p-5vcw.json +++ b/advisories/unreviewed/2022/04/GHSA-xpxm-j39p-5vcw/GHSA-xpxm-j39p-5vcw.json @@ -7,12 +7,8 @@ "CVE-2000-0667" ], "details": "Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xq2m-9f8c-rr6w/GHSA-xq2m-9f8c-rr6w.json b/advisories/unreviewed/2022/04/GHSA-xq2m-9f8c-rr6w/GHSA-xq2m-9f8c-rr6w.json index ec20d14907e..c12baab5ea0 100644 --- a/advisories/unreviewed/2022/04/GHSA-xq2m-9f8c-rr6w/GHSA-xq2m-9f8c-rr6w.json +++ b/advisories/unreviewed/2022/04/GHSA-xq2m-9f8c-rr6w/GHSA-xq2m-9f8c-rr6w.json @@ -7,12 +7,8 @@ "CVE-2000-0615" ], "details": "LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xxfm-q6cq-gcwc/GHSA-xxfm-q6cq-gcwc.json b/advisories/unreviewed/2022/04/GHSA-xxfm-q6cq-gcwc/GHSA-xxfm-q6cq-gcwc.json index 744fc72a809..4390b09a545 100644 --- a/advisories/unreviewed/2022/04/GHSA-xxfm-q6cq-gcwc/GHSA-xxfm-q6cq-gcwc.json +++ b/advisories/unreviewed/2022/04/GHSA-xxfm-q6cq-gcwc/GHSA-xxfm-q6cq-gcwc.json @@ -7,12 +7,8 @@ "CVE-2000-0623" ], "details": "Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23cf-7m42-487j/GHSA-23cf-7m42-487j.json b/advisories/unreviewed/2022/05/GHSA-23cf-7m42-487j/GHSA-23cf-7m42-487j.json index 9c22732aa54..97b4cc5e685 100644 --- a/advisories/unreviewed/2022/05/GHSA-23cf-7m42-487j/GHSA-23cf-7m42-487j.json +++ b/advisories/unreviewed/2022/05/GHSA-23cf-7m42-487j/GHSA-23cf-7m42-487j.json @@ -7,12 +7,8 @@ "CVE-2020-35604" ], "details": "An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23hx-gmq6-vwxq/GHSA-23hx-gmq6-vwxq.json b/advisories/unreviewed/2022/05/GHSA-23hx-gmq6-vwxq/GHSA-23hx-gmq6-vwxq.json index d22d1f220f1..2d8185af8e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-23hx-gmq6-vwxq/GHSA-23hx-gmq6-vwxq.json +++ b/advisories/unreviewed/2022/05/GHSA-23hx-gmq6-vwxq/GHSA-23hx-gmq6-vwxq.json @@ -7,12 +7,8 @@ "CVE-2020-35714" ], "details": "Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23hx-rv96-mjqx/GHSA-23hx-rv96-mjqx.json b/advisories/unreviewed/2022/05/GHSA-23hx-rv96-mjqx/GHSA-23hx-rv96-mjqx.json index 6cf5d616042..4c75f86aec6 100644 --- a/advisories/unreviewed/2022/05/GHSA-23hx-rv96-mjqx/GHSA-23hx-rv96-mjqx.json +++ b/advisories/unreviewed/2022/05/GHSA-23hx-rv96-mjqx/GHSA-23hx-rv96-mjqx.json @@ -7,12 +7,8 @@ "CVE-2020-4904" ], "details": "IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-256m-p2gv-r882/GHSA-256m-p2gv-r882.json b/advisories/unreviewed/2022/05/GHSA-256m-p2gv-r882/GHSA-256m-p2gv-r882.json index 3adc5c09bdb..efb035d5dd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-256m-p2gv-r882/GHSA-256m-p2gv-r882.json +++ b/advisories/unreviewed/2022/05/GHSA-256m-p2gv-r882/GHSA-256m-p2gv-r882.json @@ -7,12 +7,8 @@ "CVE-2020-25153" ], "details": "The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25hw-5mq3-gfwx/GHSA-25hw-5mq3-gfwx.json b/advisories/unreviewed/2022/05/GHSA-25hw-5mq3-gfwx/GHSA-25hw-5mq3-gfwx.json index 20a92a1be55..648624e7e2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-25hw-5mq3-gfwx/GHSA-25hw-5mq3-gfwx.json +++ b/advisories/unreviewed/2022/05/GHSA-25hw-5mq3-gfwx/GHSA-25hw-5mq3-gfwx.json @@ -7,12 +7,8 @@ "CVE-2020-29669" ], "details": "In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user (including root) can be dumped. The root hash can be cracked easily which results in a complete system compromise.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26hg-qjgg-2868/GHSA-26hg-qjgg-2868.json b/advisories/unreviewed/2022/05/GHSA-26hg-qjgg-2868/GHSA-26hg-qjgg-2868.json index 47786ae76c7..432d69bf510 100644 --- a/advisories/unreviewed/2022/05/GHSA-26hg-qjgg-2868/GHSA-26hg-qjgg-2868.json +++ b/advisories/unreviewed/2022/05/GHSA-26hg-qjgg-2868/GHSA-26hg-qjgg-2868.json @@ -7,12 +7,8 @@ "CVE-2020-12519" ], "details": "On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26r7-84w5-c8mf/GHSA-26r7-84w5-c8mf.json b/advisories/unreviewed/2022/05/GHSA-26r7-84w5-c8mf/GHSA-26r7-84w5-c8mf.json index ccd8ed59384..1e712000617 100644 --- a/advisories/unreviewed/2022/05/GHSA-26r7-84w5-c8mf/GHSA-26r7-84w5-c8mf.json +++ b/advisories/unreviewed/2022/05/GHSA-26r7-84w5-c8mf/GHSA-26r7-84w5-c8mf.json @@ -7,12 +7,8 @@ "CVE-2020-35133" ], "details": "irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26rg-mq58-rxvm/GHSA-26rg-mq58-rxvm.json b/advisories/unreviewed/2022/05/GHSA-26rg-mq58-rxvm/GHSA-26rg-mq58-rxvm.json index f099deeab94..d9ed7f42202 100644 --- a/advisories/unreviewed/2022/05/GHSA-26rg-mq58-rxvm/GHSA-26rg-mq58-rxvm.json +++ b/advisories/unreviewed/2022/05/GHSA-26rg-mq58-rxvm/GHSA-26rg-mq58-rxvm.json @@ -7,12 +7,8 @@ "CVE-2020-29571" ], "details": "An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the CPU observing consistent state. While the producer side uses appropriately ordered writes, the consumer side isn't protected against re-ordered reads, and may hence end up de-referencing a NULL pointer. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system. Only Arm systems may be vulnerable. Whether a system is vulnerable depends on the specific CPU. x86 systems are not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2795-x35v-6hgh/GHSA-2795-x35v-6hgh.json b/advisories/unreviewed/2022/05/GHSA-2795-x35v-6hgh/GHSA-2795-x35v-6hgh.json index bc4bc7e1191..60e9dbb92ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-2795-x35v-6hgh/GHSA-2795-x35v-6hgh.json +++ b/advisories/unreviewed/2022/05/GHSA-2795-x35v-6hgh/GHSA-2795-x35v-6hgh.json @@ -7,12 +7,8 @@ "CVE-2020-8462" ], "details": "A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-28x2-h22v-2jv6/GHSA-28x2-h22v-2jv6.json b/advisories/unreviewed/2022/05/GHSA-28x2-h22v-2jv6/GHSA-28x2-h22v-2jv6.json index 96c599f042b..16845711f85 100644 --- a/advisories/unreviewed/2022/05/GHSA-28x2-h22v-2jv6/GHSA-28x2-h22v-2jv6.json +++ b/advisories/unreviewed/2022/05/GHSA-28x2-h22v-2jv6/GHSA-28x2-h22v-2jv6.json @@ -7,12 +7,8 @@ "CVE-2020-35553" ], "details": "An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Qualcomm SM8250 chipsets) software. They allows attackers to cause a denial of service (unlock failure) by triggering a power-shortage incident that causes a false-positive attack detection. The Samsung ID is SVE-2020-19678 (December 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29jx-h9vr-rw83/GHSA-29jx-h9vr-rw83.json b/advisories/unreviewed/2022/05/GHSA-29jx-h9vr-rw83/GHSA-29jx-h9vr-rw83.json index c6ceb514754..f55a609ea1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-29jx-h9vr-rw83/GHSA-29jx-h9vr-rw83.json +++ b/advisories/unreviewed/2022/05/GHSA-29jx-h9vr-rw83/GHSA-29jx-h9vr-rw83.json @@ -7,12 +7,8 @@ "CVE-2020-27034" ], "details": "In createSimSelectNotification of SimSelectNotification.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153556754", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cq5-rh28-8vq5/GHSA-2cq5-rh28-8vq5.json b/advisories/unreviewed/2022/05/GHSA-2cq5-rh28-8vq5/GHSA-2cq5-rh28-8vq5.json index 0cfd016c1f2..3dda923e69f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cq5-rh28-8vq5/GHSA-2cq5-rh28-8vq5.json +++ b/advisories/unreviewed/2022/05/GHSA-2cq5-rh28-8vq5/GHSA-2cq5-rh28-8vq5.json @@ -7,12 +7,8 @@ "CVE-2020-20140" ], "details": "Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2cqw-h63q-28xj/GHSA-2cqw-h63q-28xj.json b/advisories/unreviewed/2022/05/GHSA-2cqw-h63q-28xj/GHSA-2cqw-h63q-28xj.json index b89c62c85c3..d79a00ebb92 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cqw-h63q-28xj/GHSA-2cqw-h63q-28xj.json +++ b/advisories/unreviewed/2022/05/GHSA-2cqw-h63q-28xj/GHSA-2cqw-h63q-28xj.json @@ -7,12 +7,8 @@ "CVE-2020-4657" ], "details": "IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186094.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g4f-r7cc-55q9/GHSA-2g4f-r7cc-55q9.json b/advisories/unreviewed/2022/05/GHSA-2g4f-r7cc-55q9/GHSA-2g4f-r7cc-55q9.json index 21e0819a28d..8a80437598b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g4f-r7cc-55q9/GHSA-2g4f-r7cc-55q9.json +++ b/advisories/unreviewed/2022/05/GHSA-2g4f-r7cc-55q9/GHSA-2g4f-r7cc-55q9.json @@ -7,12 +7,8 @@ "CVE-2020-12518" ], "details": "On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g89-jxmp-m4m9/GHSA-2g89-jxmp-m4m9.json b/advisories/unreviewed/2022/05/GHSA-2g89-jxmp-m4m9/GHSA-2g89-jxmp-m4m9.json index 25cb2978f71..4fa8a929b6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g89-jxmp-m4m9/GHSA-2g89-jxmp-m4m9.json +++ b/advisories/unreviewed/2022/05/GHSA-2g89-jxmp-m4m9/GHSA-2g89-jxmp-m4m9.json @@ -7,12 +7,8 @@ "CVE-2020-35188" ], "details": "The official chronograf docker images before 1.7.7-alpine (Alpine specific) contain a blank password for a root user. System using the chronograf docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hxg-rh2v-hj3h/GHSA-2hxg-rh2v-hj3h.json b/advisories/unreviewed/2022/05/GHSA-2hxg-rh2v-hj3h/GHSA-2hxg-rh2v-hj3h.json index f8cec979157..1f75a3bce91 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hxg-rh2v-hj3h/GHSA-2hxg-rh2v-hj3h.json +++ b/advisories/unreviewed/2022/05/GHSA-2hxg-rh2v-hj3h/GHSA-2hxg-rh2v-hj3h.json @@ -7,12 +7,8 @@ "CVE-2020-0480" ], "details": "In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to DocumentsProvider with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157320716", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jg5-5mqp-735q/GHSA-2jg5-5mqp-735q.json b/advisories/unreviewed/2022/05/GHSA-2jg5-5mqp-735q/GHSA-2jg5-5mqp-735q.json index 2d781a4aee3..ea7ff7fd4a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jg5-5mqp-735q/GHSA-2jg5-5mqp-735q.json +++ b/advisories/unreviewed/2022/05/GHSA-2jg5-5mqp-735q/GHSA-2jg5-5mqp-735q.json @@ -7,12 +7,8 @@ "CVE-2020-35376" ], "details": "Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jrp-2x8m-mgrv/GHSA-2jrp-2x8m-mgrv.json b/advisories/unreviewed/2022/05/GHSA-2jrp-2x8m-mgrv/GHSA-2jrp-2x8m-mgrv.json index c17edee65b7..c7c6d2a1516 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jrp-2x8m-mgrv/GHSA-2jrp-2x8m-mgrv.json +++ b/advisories/unreviewed/2022/05/GHSA-2jrp-2x8m-mgrv/GHSA-2jrp-2x8m-mgrv.json @@ -7,12 +7,8 @@ "CVE-2020-15293" ], "details": "Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input validation may lead to denial of service conditions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jvv-ppmq-fvgf/GHSA-2jvv-ppmq-fvgf.json b/advisories/unreviewed/2022/05/GHSA-2jvv-ppmq-fvgf/GHSA-2jvv-ppmq-fvgf.json index eecb7d032fb..cc7ef953ad3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jvv-ppmq-fvgf/GHSA-2jvv-ppmq-fvgf.json +++ b/advisories/unreviewed/2022/05/GHSA-2jvv-ppmq-fvgf/GHSA-2jvv-ppmq-fvgf.json @@ -7,12 +7,8 @@ "CVE-2020-13476" ], "details": "NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mrh-8f77-q7p2/GHSA-2mrh-8f77-q7p2.json b/advisories/unreviewed/2022/05/GHSA-2mrh-8f77-q7p2/GHSA-2mrh-8f77-q7p2.json index b2ca5354647..fde529b4731 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mrh-8f77-q7p2/GHSA-2mrh-8f77-q7p2.json +++ b/advisories/unreviewed/2022/05/GHSA-2mrh-8f77-q7p2/GHSA-2mrh-8f77-q7p2.json @@ -7,12 +7,8 @@ "CVE-2020-4846" ], "details": "IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190290.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2q4w-gp3h-x66r/GHSA-2q4w-gp3h-x66r.json b/advisories/unreviewed/2022/05/GHSA-2q4w-gp3h-x66r/GHSA-2q4w-gp3h-x66r.json index 808847088a0..0b399f3a575 100644 --- a/advisories/unreviewed/2022/05/GHSA-2q4w-gp3h-x66r/GHSA-2q4w-gp3h-x66r.json +++ b/advisories/unreviewed/2022/05/GHSA-2q4w-gp3h-x66r/GHSA-2q4w-gp3h-x66r.json @@ -7,12 +7,8 @@ "CVE-2020-35275" ], "details": "Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qvv-wf53-7c44/GHSA-2qvv-wf53-7c44.json b/advisories/unreviewed/2022/05/GHSA-2qvv-wf53-7c44/GHSA-2qvv-wf53-7c44.json index 08c4dc30bc7..162c4f635f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qvv-wf53-7c44/GHSA-2qvv-wf53-7c44.json +++ b/advisories/unreviewed/2022/05/GHSA-2qvv-wf53-7c44/GHSA-2qvv-wf53-7c44.json @@ -7,12 +7,8 @@ "CVE-2020-26411" ], "details": "A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rcf-f7rp-mvx7/GHSA-2rcf-f7rp-mvx7.json b/advisories/unreviewed/2022/05/GHSA-2rcf-f7rp-mvx7/GHSA-2rcf-f7rp-mvx7.json index 011aed8d0f0..2defcc1464a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rcf-f7rp-mvx7/GHSA-2rcf-f7rp-mvx7.json +++ b/advisories/unreviewed/2022/05/GHSA-2rcf-f7rp-mvx7/GHSA-2rcf-f7rp-mvx7.json @@ -7,12 +7,8 @@ "CVE-2020-28858" ], "details": "OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v2m-677r-5j24/GHSA-2v2m-677r-5j24.json b/advisories/unreviewed/2022/05/GHSA-2v2m-677r-5j24/GHSA-2v2m-677r-5j24.json index f0ac5b84899..f5ff4e3e433 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v2m-677r-5j24/GHSA-2v2m-677r-5j24.json +++ b/advisories/unreviewed/2022/05/GHSA-2v2m-677r-5j24/GHSA-2v2m-677r-5j24.json @@ -7,12 +7,8 @@ "CVE-2020-9137" ], "details": "There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may execute some specially crafted scripts in the affected products. Successful exploit will cause privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v93-8mhc-6mf8/GHSA-2v93-8mhc-6mf8.json b/advisories/unreviewed/2022/05/GHSA-2v93-8mhc-6mf8/GHSA-2v93-8mhc-6mf8.json index b1e500898e6..5f857ded5a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v93-8mhc-6mf8/GHSA-2v93-8mhc-6mf8.json +++ b/advisories/unreviewed/2022/05/GHSA-2v93-8mhc-6mf8/GHSA-2v93-8mhc-6mf8.json @@ -7,12 +7,8 @@ "CVE-2020-27338" ], "details": "An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows an unauthenticated remote attacker to cause an Out of Bounds Read, and possibly a Denial of Service via adjacent network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v9x-c45w-29qx/GHSA-2v9x-c45w-29qx.json b/advisories/unreviewed/2022/05/GHSA-2v9x-c45w-29qx/GHSA-2v9x-c45w-29qx.json index 2a53354baee..645e01d9c0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v9x-c45w-29qx/GHSA-2v9x-c45w-29qx.json +++ b/advisories/unreviewed/2022/05/GHSA-2v9x-c45w-29qx/GHSA-2v9x-c45w-29qx.json @@ -7,12 +7,8 @@ "CVE-2020-28095" ], "details": "On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vgw-q9j2-j47q/GHSA-2vgw-q9j2-j47q.json b/advisories/unreviewed/2022/05/GHSA-2vgw-q9j2-j47q/GHSA-2vgw-q9j2-j47q.json index 2a2c9be85f7..4a40707cf00 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vgw-q9j2-j47q/GHSA-2vgw-q9j2-j47q.json +++ b/advisories/unreviewed/2022/05/GHSA-2vgw-q9j2-j47q/GHSA-2vgw-q9j2-j47q.json @@ -7,12 +7,8 @@ "CVE-2020-25606" ], "details": "The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input validation, aka XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2vhx-gg9g-r3h4/GHSA-2vhx-gg9g-r3h4.json b/advisories/unreviewed/2022/05/GHSA-2vhx-gg9g-r3h4/GHSA-2vhx-gg9g-r3h4.json index e6bc03c4964..0a198021f9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vhx-gg9g-r3h4/GHSA-2vhx-gg9g-r3h4.json +++ b/advisories/unreviewed/2022/05/GHSA-2vhx-gg9g-r3h4/GHSA-2vhx-gg9g-r3h4.json @@ -7,12 +7,8 @@ "CVE-2020-35191" ], "details": "The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xhv-xg6q-g23w/GHSA-2xhv-xg6q-g23w.json b/advisories/unreviewed/2022/05/GHSA-2xhv-xg6q-g23w/GHSA-2xhv-xg6q-g23w.json index 122f83f2d37..db52e2b5539 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xhv-xg6q-g23w/GHSA-2xhv-xg6q-g23w.json +++ b/advisories/unreviewed/2022/05/GHSA-2xhv-xg6q-g23w/GHSA-2xhv-xg6q-g23w.json @@ -7,12 +7,8 @@ "CVE-2020-27050" ], "details": "In rw_i93_send_cmd_write_multi_blocks of rw_i93.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650365", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xrp-fqg8-p623/GHSA-2xrp-fqg8-p623.json b/advisories/unreviewed/2022/05/GHSA-2xrp-fqg8-p623/GHSA-2xrp-fqg8-p623.json index 5d52a8451bd..3a8eeb14093 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xrp-fqg8-p623/GHSA-2xrp-fqg8-p623.json +++ b/advisories/unreviewed/2022/05/GHSA-2xrp-fqg8-p623/GHSA-2xrp-fqg8-p623.json @@ -7,12 +7,8 @@ "CVE-2020-4747" ], "details": "IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xwv-qmvc-f3g6/GHSA-2xwv-qmvc-f3g6.json b/advisories/unreviewed/2022/05/GHSA-2xwv-qmvc-f3g6/GHSA-2xwv-qmvc-f3g6.json index a2e8df14a43..42738670b73 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xwv-qmvc-f3g6/GHSA-2xwv-qmvc-f3g6.json +++ b/advisories/unreviewed/2022/05/GHSA-2xwv-qmvc-f3g6/GHSA-2xwv-qmvc-f3g6.json @@ -7,12 +7,8 @@ "CVE-2020-17160" ], "details": ", aka 'RETRACTED'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-324v-4jgg-3xh9/GHSA-324v-4jgg-3xh9.json b/advisories/unreviewed/2022/05/GHSA-324v-4jgg-3xh9/GHSA-324v-4jgg-3xh9.json index 10fb6205f19..8d63774c769 100644 --- a/advisories/unreviewed/2022/05/GHSA-324v-4jgg-3xh9/GHSA-324v-4jgg-3xh9.json +++ b/advisories/unreviewed/2022/05/GHSA-324v-4jgg-3xh9/GHSA-324v-4jgg-3xh9.json @@ -7,12 +7,8 @@ "CVE-2020-6882" ], "details": "ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the device. The remote attacker could use this credential to connect to the MQTT server, so as to obtain information about other devices by sending specific topics. This affects:", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3255-v6mp-wmgf/GHSA-3255-v6mp-wmgf.json b/advisories/unreviewed/2022/05/GHSA-3255-v6mp-wmgf/GHSA-3255-v6mp-wmgf.json index 7dbe3fb1e73..4edfdfe2e9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3255-v6mp-wmgf/GHSA-3255-v6mp-wmgf.json +++ b/advisories/unreviewed/2022/05/GHSA-3255-v6mp-wmgf/GHSA-3255-v6mp-wmgf.json @@ -7,12 +7,8 @@ "CVE-2020-15375" ], "details": "Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. The vulnerability could allow a local authenticated user to run arbitrary commands and perform escalation of privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32m5-2pgc-wc86/GHSA-32m5-2pgc-wc86.json b/advisories/unreviewed/2022/05/GHSA-32m5-2pgc-wc86/GHSA-32m5-2pgc-wc86.json index ed70f1f7d5d..cf015d1d84f 100644 --- a/advisories/unreviewed/2022/05/GHSA-32m5-2pgc-wc86/GHSA-32m5-2pgc-wc86.json +++ b/advisories/unreviewed/2022/05/GHSA-32m5-2pgc-wc86/GHSA-32m5-2pgc-wc86.json @@ -7,12 +7,8 @@ "CVE-2019-14480" ], "details": "AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32xw-6g8c-rxjj/GHSA-32xw-6g8c-rxjj.json b/advisories/unreviewed/2022/05/GHSA-32xw-6g8c-rxjj/GHSA-32xw-6g8c-rxjj.json index 1b3df5bdaa1..60a1e506995 100644 --- a/advisories/unreviewed/2022/05/GHSA-32xw-6g8c-rxjj/GHSA-32xw-6g8c-rxjj.json +++ b/advisories/unreviewed/2022/05/GHSA-32xw-6g8c-rxjj/GHSA-32xw-6g8c-rxjj.json @@ -7,12 +7,8 @@ "CVE-2020-4555" ], "details": "IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-34f3-925w-mxhg/GHSA-34f3-925w-mxhg.json b/advisories/unreviewed/2022/05/GHSA-34f3-925w-mxhg/GHSA-34f3-925w-mxhg.json index c10011f881c..7eb564570ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-34f3-925w-mxhg/GHSA-34f3-925w-mxhg.json +++ b/advisories/unreviewed/2022/05/GHSA-34f3-925w-mxhg/GHSA-34f3-925w-mxhg.json @@ -7,12 +7,8 @@ "CVE-2020-4841" ], "details": "IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 190045.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35ch-vqm2-376r/GHSA-35ch-vqm2-376r.json b/advisories/unreviewed/2022/05/GHSA-35ch-vqm2-376r/GHSA-35ch-vqm2-376r.json index 848446be447..71b25f86b53 100644 --- a/advisories/unreviewed/2022/05/GHSA-35ch-vqm2-376r/GHSA-35ch-vqm2-376r.json +++ b/advisories/unreviewed/2022/05/GHSA-35ch-vqm2-376r/GHSA-35ch-vqm2-376r.json @@ -7,12 +7,8 @@ "CVE-2020-35710" ], "details": "Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client for use as a \"host\" value. In other words, after an attacker's web browser sent a request to the login form, it would automatically send a second request to a RASHTML5Gateway/socket.io URI with something like \"host\":\"192.168.###.###\" in the POST data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35q9-m24r-89m2/GHSA-35q9-m24r-89m2.json b/advisories/unreviewed/2022/05/GHSA-35q9-m24r-89m2/GHSA-35q9-m24r-89m2.json index 31938d478f4..df26470e89c 100644 --- a/advisories/unreviewed/2022/05/GHSA-35q9-m24r-89m2/GHSA-35q9-m24r-89m2.json +++ b/advisories/unreviewed/2022/05/GHSA-35q9-m24r-89m2/GHSA-35q9-m24r-89m2.json @@ -7,12 +7,8 @@ "CVE-2020-29303" ], "details": "A cross-site scripting (XSS) vulnerability in the SabaiApp Directories Pro plugin 1.3.45 for WordPress allows remote attackers to inject arbitrary web script or HTML via a POST to /wp-admin/admin.php?page=drts/directories&q=%2F with _drts_form_build_id parameter containing the XSS payload and _t_ parameter set to an invalid or non-existent CSRF token.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35vj-pjgj-gmmg/GHSA-35vj-pjgj-gmmg.json b/advisories/unreviewed/2022/05/GHSA-35vj-pjgj-gmmg/GHSA-35vj-pjgj-gmmg.json index 7113f6e2bda..c7acc570025 100644 --- a/advisories/unreviewed/2022/05/GHSA-35vj-pjgj-gmmg/GHSA-35vj-pjgj-gmmg.json +++ b/advisories/unreviewed/2022/05/GHSA-35vj-pjgj-gmmg/GHSA-35vj-pjgj-gmmg.json @@ -7,12 +7,8 @@ "CVE-2020-35778" ], "details": "Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-363c-g524-mqxp/GHSA-363c-g524-mqxp.json b/advisories/unreviewed/2022/05/GHSA-363c-g524-mqxp/GHSA-363c-g524-mqxp.json index 646dc283d4d..0129fa57456 100644 --- a/advisories/unreviewed/2022/05/GHSA-363c-g524-mqxp/GHSA-363c-g524-mqxp.json +++ b/advisories/unreviewed/2022/05/GHSA-363c-g524-mqxp/GHSA-363c-g524-mqxp.json @@ -7,12 +7,8 @@ "CVE-2020-35616" ], "details": "An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36cv-vc44-8fvg/GHSA-36cv-vc44-8fvg.json b/advisories/unreviewed/2022/05/GHSA-36cv-vc44-8fvg/GHSA-36cv-vc44-8fvg.json index 9d6a47d826d..51f01d83ac5 100644 --- a/advisories/unreviewed/2022/05/GHSA-36cv-vc44-8fvg/GHSA-36cv-vc44-8fvg.json +++ b/advisories/unreviewed/2022/05/GHSA-36cv-vc44-8fvg/GHSA-36cv-vc44-8fvg.json @@ -7,12 +7,8 @@ "CVE-2020-26032" ], "details": "An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can use this to request any URL via a GET request from the network interface of the server. This may lead to disclosure of information from intranet systems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-36ww-7vxr-9ggq/GHSA-36ww-7vxr-9ggq.json b/advisories/unreviewed/2022/05/GHSA-36ww-7vxr-9ggq/GHSA-36ww-7vxr-9ggq.json index aba1439a19c..26364bc1f10 100644 --- a/advisories/unreviewed/2022/05/GHSA-36ww-7vxr-9ggq/GHSA-36ww-7vxr-9ggq.json +++ b/advisories/unreviewed/2022/05/GHSA-36ww-7vxr-9ggq/GHSA-36ww-7vxr-9ggq.json @@ -7,12 +7,8 @@ "CVE-2020-28457" ], "details": "This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3772-r33f-jvrg/GHSA-3772-r33f-jvrg.json b/advisories/unreviewed/2022/05/GHSA-3772-r33f-jvrg/GHSA-3772-r33f-jvrg.json index 4da44f419ee..a069cc7d1d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3772-r33f-jvrg/GHSA-3772-r33f-jvrg.json +++ b/advisories/unreviewed/2022/05/GHSA-3772-r33f-jvrg/GHSA-3772-r33f-jvrg.json @@ -7,12 +7,8 @@ "CVE-2020-35735" ], "details": "Vidyo 02-09-/D allows clickjacking via the portal/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37cg-6ww4-3f68/GHSA-37cg-6ww4-3f68.json b/advisories/unreviewed/2022/05/GHSA-37cg-6ww4-3f68/GHSA-37cg-6ww4-3f68.json index 8d2e0008411..d6b7a95b403 100644 --- a/advisories/unreviewed/2022/05/GHSA-37cg-6ww4-3f68/GHSA-37cg-6ww4-3f68.json +++ b/advisories/unreviewed/2022/05/GHSA-37cg-6ww4-3f68/GHSA-37cg-6ww4-3f68.json @@ -7,12 +7,8 @@ "CVE-2020-35245" ], "details": "Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37q6-vw96-q6q8/GHSA-37q6-vw96-q6q8.json b/advisories/unreviewed/2022/05/GHSA-37q6-vw96-q6q8/GHSA-37q6-vw96-q6q8.json index 29b8b604967..506f8c3073f 100644 --- a/advisories/unreviewed/2022/05/GHSA-37q6-vw96-q6q8/GHSA-37q6-vw96-q6q8.json +++ b/advisories/unreviewed/2022/05/GHSA-37q6-vw96-q6q8/GHSA-37q6-vw96-q6q8.json @@ -7,12 +7,8 @@ "CVE-2020-24336" ], "details": "An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the answer's length is sane. Therefore, when copying an address of an arbitrary length, a buffer overflow can occur. This bug can be exploited whenever NAT64 is enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37vq-vv4q-ww53/GHSA-37vq-vv4q-ww53.json b/advisories/unreviewed/2022/05/GHSA-37vq-vv4q-ww53/GHSA-37vq-vv4q-ww53.json index a470783197d..559331782d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-37vq-vv4q-ww53/GHSA-37vq-vv4q-ww53.json +++ b/advisories/unreviewed/2022/05/GHSA-37vq-vv4q-ww53/GHSA-37vq-vv4q-ww53.json @@ -7,12 +7,8 @@ "CVE-2019-14477" ], "details": "AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37xm-62j3-375v/GHSA-37xm-62j3-375v.json b/advisories/unreviewed/2022/05/GHSA-37xm-62j3-375v/GHSA-37xm-62j3-375v.json index 5fcc7ee8cc8..f3c6e3b3832 100644 --- a/advisories/unreviewed/2022/05/GHSA-37xm-62j3-375v/GHSA-37xm-62j3-375v.json +++ b/advisories/unreviewed/2022/05/GHSA-37xm-62j3-375v/GHSA-37xm-62j3-375v.json @@ -7,12 +7,8 @@ "CVE-2020-35795" ], "details": "Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, CBK40 before 2.5.0.10, CBR40 before 2.5.0.10, D7800 before 1.0.1.58, EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX7500 before 1.0.0.68, MK62 before 1.0.5.102, MR60 before 1.0.5.102, MS60 before 1.0.5.102, R6120 before 1.0.0.70, R6220 before 1.1.0.100, R6230 before 1.1.0.100, R6260 before 1.1.0.76, R6330 before 1.1.0.76, R6350 before 1.1.0.76, R6400 before 1.0.1.62, R6400v2 before 1.0.4.98, R6700 before 1.0.2.16, R6700v2 before 1.2.0.72, R6700v3 before 1.0.4.98, R6800 before 1.2.0.72, R6850 before 1.1.0.76, R6900P before 1.3.2.124, R6900 before 1.0.2.16, R6900v2 before 1.2.0.72, R7000 before 1.0.11.106, R7000P before 1.3.2.124, R7200 before 1.2.0.72, R7350 before 1.2.0.72, R7400 before 1.2.0.72, R7450 before 1.2.0.72, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900 before 1.0.4.26, R7900P before 1.4.1.62, R7960P before 1.4.1.62, R8000 before 1.0.4.58, R8000P before 1.4.1.62, R8900 before 1.0.5.24, R9000 before 1.0.5.24, RAX120 before 1.0.1.136, RAX15 before 1.0.1.64, RAX20 before 1.0.1.64, RAX200 before 1.0.2.102, RAX45 before 1.0.2.64, RAX50 before 1.0.2.64, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK12 before 2.6.1.44, RBR10 before 2.6.1.44, RBS10 before 2.6.1.44, RBK20 before 2.6.1.38, RBR20 before 2.6.1.36, RBS20 before 2.6.1.38, RBK40 before 2.6.1.38, RBR40 before 2.6.1.36, RBS40 before 2.6.1.38, RBK50 before 2.6.1.40, RBR50 before 2.6.1.40, RBS50 before 2.6.1.40, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK842 before 3.2.16.6, RBR840 before 3.2.16.6, RBS840 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RS400 before 1.5.0.48, XR300 before 1.0.3.50, XR450 before 2.3.2.66, XR500 before 2.3.2.66, and XR700 before 1.0.1.34.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37xw-27xp-5499/GHSA-37xw-27xp-5499.json b/advisories/unreviewed/2022/05/GHSA-37xw-27xp-5499/GHSA-37xw-27xp-5499.json index 3b48b359227..ada9b2062d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-37xw-27xp-5499/GHSA-37xw-27xp-5499.json +++ b/advisories/unreviewed/2022/05/GHSA-37xw-27xp-5499/GHSA-37xw-27xp-5499.json @@ -7,12 +7,8 @@ "CVE-2020-2497" ], "details": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3896-fhmw-qp2v/GHSA-3896-fhmw-qp2v.json b/advisories/unreviewed/2022/05/GHSA-3896-fhmw-qp2v/GHSA-3896-fhmw-qp2v.json index 5381d3b2dc2..fa647449e01 100644 --- a/advisories/unreviewed/2022/05/GHSA-3896-fhmw-qp2v/GHSA-3896-fhmw-qp2v.json +++ b/advisories/unreviewed/2022/05/GHSA-3896-fhmw-qp2v/GHSA-3896-fhmw-qp2v.json @@ -7,12 +7,8 @@ "CVE-2020-35598" ], "details": "ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38jp-4v3p-cc3q/GHSA-38jp-4v3p-cc3q.json b/advisories/unreviewed/2022/05/GHSA-38jp-4v3p-cc3q/GHSA-38jp-4v3p-cc3q.json index 952540cf7ab..42b09f7f7b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-38jp-4v3p-cc3q/GHSA-38jp-4v3p-cc3q.json +++ b/advisories/unreviewed/2022/05/GHSA-38jp-4v3p-cc3q/GHSA-38jp-4v3p-cc3q.json @@ -7,12 +7,8 @@ "CVE-2020-24334" ], "details": "The code that processes DNS responses in uIP through 1.0, as used in Contiki and Contiki-NG, does not check whether the number of responses specified in the DNS packet header corresponds to the response data available in the DNS packet, leading to an out-of-bounds read and Denial-of-Service in resolv.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38q3-wx89-qvg5/GHSA-38q3-wx89-qvg5.json b/advisories/unreviewed/2022/05/GHSA-38q3-wx89-qvg5/GHSA-38q3-wx89-qvg5.json index 6805d7026cc..1ce445a865a 100644 --- a/advisories/unreviewed/2022/05/GHSA-38q3-wx89-qvg5/GHSA-38q3-wx89-qvg5.json +++ b/advisories/unreviewed/2022/05/GHSA-38q3-wx89-qvg5/GHSA-38q3-wx89-qvg5.json @@ -7,12 +7,8 @@ "CVE-2020-5682" ], "details": "Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier allows remote attackers to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-393j-8xcq-h729/GHSA-393j-8xcq-h729.json b/advisories/unreviewed/2022/05/GHSA-393j-8xcq-h729/GHSA-393j-8xcq-h729.json index 03a96fb98db..3ddd4dc140b 100644 --- a/advisories/unreviewed/2022/05/GHSA-393j-8xcq-h729/GHSA-393j-8xcq-h729.json +++ b/advisories/unreviewed/2022/05/GHSA-393j-8xcq-h729/GHSA-393j-8xcq-h729.json @@ -7,12 +7,8 @@ "CVE-2020-35463" ], "details": "Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f89-7rr5-pcr2/GHSA-3f89-7rr5-pcr2.json b/advisories/unreviewed/2022/05/GHSA-3f89-7rr5-pcr2/GHSA-3f89-7rr5-pcr2.json index e61cdd447d2..55190e97c7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f89-7rr5-pcr2/GHSA-3f89-7rr5-pcr2.json +++ b/advisories/unreviewed/2022/05/GHSA-3f89-7rr5-pcr2/GHSA-3f89-7rr5-pcr2.json @@ -7,12 +7,8 @@ "CVE-2020-27725" ], "details": "In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones. Zones can be listed via TMSH, iControl or SNMP; only users with access to those services can trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fpm-hp83-g34v/GHSA-3fpm-hp83-g34v.json b/advisories/unreviewed/2022/05/GHSA-3fpm-hp83-g34v/GHSA-3fpm-hp83-g34v.json index f512222d32c..16243298da0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fpm-hp83-g34v/GHSA-3fpm-hp83-g34v.json +++ b/advisories/unreviewed/2022/05/GHSA-3fpm-hp83-g34v/GHSA-3fpm-hp83-g34v.json @@ -7,12 +7,8 @@ "CVE-2018-15633" ], "details": "Cross-site scripting (XSS) issue in \"document\" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3g7c-253j-whp9/GHSA-3g7c-253j-whp9.json b/advisories/unreviewed/2022/05/GHSA-3g7c-253j-whp9/GHSA-3g7c-253j-whp9.json index ca208c7fd26..782835c444c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g7c-253j-whp9/GHSA-3g7c-253j-whp9.json +++ b/advisories/unreviewed/2022/05/GHSA-3g7c-253j-whp9/GHSA-3g7c-253j-whp9.json @@ -7,12 +7,8 @@ "CVE-2020-5806" ], "details": "An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3h26-8wfg-f6vh/GHSA-3h26-8wfg-f6vh.json b/advisories/unreviewed/2022/05/GHSA-3h26-8wfg-f6vh/GHSA-3h26-8wfg-f6vh.json index 969c0cc4aee..75a6dc53ffa 100644 --- a/advisories/unreviewed/2022/05/GHSA-3h26-8wfg-f6vh/GHSA-3h26-8wfg-f6vh.json +++ b/advisories/unreviewed/2022/05/GHSA-3h26-8wfg-f6vh/GHSA-3h26-8wfg-f6vh.json @@ -7,12 +7,8 @@ "CVE-2020-0487" ], "details": "In read_metadata_vorbiscomment_ of stream_decoder.c, there is possible memory exhaustion due to a memory leak. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124775381", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3j89-v6qj-mgf2/GHSA-3j89-v6qj-mgf2.json b/advisories/unreviewed/2022/05/GHSA-3j89-v6qj-mgf2/GHSA-3j89-v6qj-mgf2.json index 64b17733ad4..6fff553b0b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j89-v6qj-mgf2/GHSA-3j89-v6qj-mgf2.json +++ b/advisories/unreviewed/2022/05/GHSA-3j89-v6qj-mgf2/GHSA-3j89-v6qj-mgf2.json @@ -7,12 +7,8 @@ "CVE-2020-25096" ], "details": "LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different roles and privileges, intended to limit what data and services they can interact with. However, no access control is enforced for WebSocket-based communication to the PM application server, which will forward requests to any configured back-end server, regardless of whether the user's access rights should permit this. As a result, even the most low-privileged user can interact with any back-end component that has a LogRhythm agent installed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jjq-5484-vh7r/GHSA-3jjq-5484-vh7r.json b/advisories/unreviewed/2022/05/GHSA-3jjq-5484-vh7r/GHSA-3jjq-5484-vh7r.json index 7bcaabbacc7..3c64655e8ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jjq-5484-vh7r/GHSA-3jjq-5484-vh7r.json +++ b/advisories/unreviewed/2022/05/GHSA-3jjq-5484-vh7r/GHSA-3jjq-5484-vh7r.json @@ -7,12 +7,8 @@ "CVE-2020-17440" ], "details": "An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that domain names present in the DNS responses have '\\0' termination. This results in errors when calculating the offset of the pointer that jumps over domain name bytes in DNS response packets when a name lacks this termination, and eventually leads to dereferencing the pointer at an invalid/arbitrary address, within newdata() and parse_name() in resolv.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jr7-57xj-6hhm/GHSA-3jr7-57xj-6hhm.json b/advisories/unreviewed/2022/05/GHSA-3jr7-57xj-6hhm/GHSA-3jr7-57xj-6hhm.json index 63e4ed149f1..90577d85f54 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jr7-57xj-6hhm/GHSA-3jr7-57xj-6hhm.json +++ b/advisories/unreviewed/2022/05/GHSA-3jr7-57xj-6hhm/GHSA-3jr7-57xj-6hhm.json @@ -7,12 +7,8 @@ "CVE-2020-26409" ], "details": "A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mhr-8gcj-264p/GHSA-3mhr-8gcj-264p.json b/advisories/unreviewed/2022/05/GHSA-3mhr-8gcj-264p/GHSA-3mhr-8gcj-264p.json index 02748923586..e20b785d462 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mhr-8gcj-264p/GHSA-3mhr-8gcj-264p.json +++ b/advisories/unreviewed/2022/05/GHSA-3mhr-8gcj-264p/GHSA-3mhr-8gcj-264p.json @@ -7,12 +7,8 @@ "CVE-2018-15638" ], "details": "Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mpv-3cfr-mgjj/GHSA-3mpv-3cfr-mgjj.json b/advisories/unreviewed/2022/05/GHSA-3mpv-3cfr-mgjj/GHSA-3mpv-3cfr-mgjj.json index d1861cdd4c1..104c1d7083e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mpv-3cfr-mgjj/GHSA-3mpv-3cfr-mgjj.json +++ b/advisories/unreviewed/2022/05/GHSA-3mpv-3cfr-mgjj/GHSA-3mpv-3cfr-mgjj.json @@ -7,12 +7,8 @@ "CVE-2020-28912" ], "details": "With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3mr8-6hjm-446f/GHSA-3mr8-6hjm-446f.json b/advisories/unreviewed/2022/05/GHSA-3mr8-6hjm-446f/GHSA-3mr8-6hjm-446f.json index 1b10c8148a9..24c15d440db 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mr8-6hjm-446f/GHSA-3mr8-6hjm-446f.json +++ b/advisories/unreviewed/2022/05/GHSA-3mr8-6hjm-446f/GHSA-3mr8-6hjm-446f.json @@ -7,12 +7,8 @@ "CVE-2020-35659" ], "details": "The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to execute when the Pi-hole administrator visits the Query Log or Long-term data Query Log page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mwp-vjrv-6crj/GHSA-3mwp-vjrv-6crj.json b/advisories/unreviewed/2022/05/GHSA-3mwp-vjrv-6crj/GHSA-3mwp-vjrv-6crj.json index 8dd0e819b22..0d3a5e526fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mwp-vjrv-6crj/GHSA-3mwp-vjrv-6crj.json +++ b/advisories/unreviewed/2022/05/GHSA-3mwp-vjrv-6crj/GHSA-3mwp-vjrv-6crj.json @@ -7,12 +7,8 @@ "CVE-2020-35799" ], "details": "Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.78, D6200 before 1.1.00.32, D7000 before 1.0.1.68, D7800 before 1.0.1.56, DM200 before 1.0.0.61, EX2700 before 1.0.1.52, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, EX6200v2 before 1.0.1.74, EX6400 before 1.0.2.140, EX7300 before 1.0.2.140, EX8000 before 1.0.1.186, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38, R6050 before 1.0.1.18, R6080 before 1.0.0.38, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6230 before 1.1.0.80, R6260 before 1.1.0.40, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900v2 before 1.2.0.36, R7500v2 before 1.0.3.40, R7800 before 1.0.2.62, R8900 before 1.0.4.12, R9000 before 1.0.4.12, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBR40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, WN2000RPTv3 before 1.0.1.34, WN3000RPv2 before 1.0.0.78, WN3000RPv2 before 1.0.0.78, WN3000RPv3 before 1.0.2.78, WN3100RPv2 before 1.0.0.66, WNR2000v5 before 1.0.0.70, WNR2020 before 1.1.0.62, XR450 before 2.3.2.32, and XR500 before 2.3.2.32.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pjh-8rj7-xm2h/GHSA-3pjh-8rj7-xm2h.json b/advisories/unreviewed/2022/05/GHSA-3pjh-8rj7-xm2h/GHSA-3pjh-8rj7-xm2h.json index c7734d07fb0..feeff09a042 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pjh-8rj7-xm2h/GHSA-3pjh-8rj7-xm2h.json +++ b/advisories/unreviewed/2022/05/GHSA-3pjh-8rj7-xm2h/GHSA-3pjh-8rj7-xm2h.json @@ -7,12 +7,8 @@ "CVE-2020-13474" ], "details": "In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qff-43xr-cvvj/GHSA-3qff-43xr-cvvj.json b/advisories/unreviewed/2022/05/GHSA-3qff-43xr-cvvj/GHSA-3qff-43xr-cvvj.json index c8a82745390..2d260c4bfb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qff-43xr-cvvj/GHSA-3qff-43xr-cvvj.json +++ b/advisories/unreviewed/2022/05/GHSA-3qff-43xr-cvvj/GHSA-3qff-43xr-cvvj.json @@ -7,12 +7,8 @@ "CVE-2020-35623" ], "details": "An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able to login as a \"bureaucrat user\" who has a similar username, as demonstrated by usernames that differ only in (1) bidirectional override symbols or (2) blank space.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3r7g-xhpj-j87w/GHSA-3r7g-xhpj-j87w.json b/advisories/unreviewed/2022/05/GHSA-3r7g-xhpj-j87w/GHSA-3r7g-xhpj-j87w.json index 629d26a6db7..714d22e4553 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r7g-xhpj-j87w/GHSA-3r7g-xhpj-j87w.json +++ b/advisories/unreviewed/2022/05/GHSA-3r7g-xhpj-j87w/GHSA-3r7g-xhpj-j87w.json @@ -7,12 +7,8 @@ "CVE-2020-27199" ], "details": "The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token without the need for correct password to gain access to the mobile application as that victim user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rqh-g6r9-mr2r/GHSA-3rqh-g6r9-mr2r.json b/advisories/unreviewed/2022/05/GHSA-3rqh-g6r9-mr2r/GHSA-3rqh-g6r9-mr2r.json index 10520ead0e0..96e08233cc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rqh-g6r9-mr2r/GHSA-3rqh-g6r9-mr2r.json +++ b/advisories/unreviewed/2022/05/GHSA-3rqh-g6r9-mr2r/GHSA-3rqh-g6r9-mr2r.json @@ -7,12 +7,8 @@ "CVE-2020-5636" ], "details": "Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vqf-m3q8-grf7/GHSA-3vqf-m3q8-grf7.json b/advisories/unreviewed/2022/05/GHSA-3vqf-m3q8-grf7/GHSA-3vqf-m3q8-grf7.json index 5259fa78e52..27047405b17 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vqf-m3q8-grf7/GHSA-3vqf-m3q8-grf7.json +++ b/advisories/unreviewed/2022/05/GHSA-3vqf-m3q8-grf7/GHSA-3vqf-m3q8-grf7.json @@ -7,12 +7,8 @@ "CVE-2020-35338" ], "details": "The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of \"pokon.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vvv-pvc3-2gx5/GHSA-3vvv-pvc3-2gx5.json b/advisories/unreviewed/2022/05/GHSA-3vvv-pvc3-2gx5/GHSA-3vvv-pvc3-2gx5.json index 51fb6eb5734..4667b9f5c35 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vvv-pvc3-2gx5/GHSA-3vvv-pvc3-2gx5.json +++ b/advisories/unreviewed/2022/05/GHSA-3vvv-pvc3-2gx5/GHSA-3vvv-pvc3-2gx5.json @@ -7,12 +7,8 @@ "CVE-2019-16959" ], "details": "SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wm3-m3jr-6jpv/GHSA-3wm3-m3jr-6jpv.json b/advisories/unreviewed/2022/05/GHSA-3wm3-m3jr-6jpv/GHSA-3wm3-m3jr-6jpv.json index 7ca80b50c5e..9342eb7e834 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wm3-m3jr-6jpv/GHSA-3wm3-m3jr-6jpv.json +++ b/advisories/unreviewed/2022/05/GHSA-3wm3-m3jr-6jpv/GHSA-3wm3-m3jr-6jpv.json @@ -7,12 +7,8 @@ "CVE-2020-35789" ], "details": "NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wq6-8f7g-92vm/GHSA-3wq6-8f7g-92vm.json b/advisories/unreviewed/2022/05/GHSA-3wq6-8f7g-92vm/GHSA-3wq6-8f7g-92vm.json index 84342ec35be..39d99254893 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wq6-8f7g-92vm/GHSA-3wq6-8f7g-92vm.json +++ b/advisories/unreviewed/2022/05/GHSA-3wq6-8f7g-92vm/GHSA-3wq6-8f7g-92vm.json @@ -7,12 +7,8 @@ "CVE-2020-4080" ], "details": "HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3xx7-wxpj-hg7p/GHSA-3xx7-wxpj-hg7p.json b/advisories/unreviewed/2022/05/GHSA-3xx7-wxpj-hg7p/GHSA-3xx7-wxpj-hg7p.json index f50305c20c4..0f803307a4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xx7-wxpj-hg7p/GHSA-3xx7-wxpj-hg7p.json +++ b/advisories/unreviewed/2022/05/GHSA-3xx7-wxpj-hg7p/GHSA-3xx7-wxpj-hg7p.json @@ -7,12 +7,8 @@ "CVE-2018-1000892" ], "details": "Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-423g-qv8g-mgcc/GHSA-423g-qv8g-mgcc.json b/advisories/unreviewed/2022/05/GHSA-423g-qv8g-mgcc/GHSA-423g-qv8g-mgcc.json index cfd7a5f389e..87d4c0eb585 100644 --- a/advisories/unreviewed/2022/05/GHSA-423g-qv8g-mgcc/GHSA-423g-qv8g-mgcc.json +++ b/advisories/unreviewed/2022/05/GHSA-423g-qv8g-mgcc/GHSA-423g-qv8g-mgcc.json @@ -7,12 +7,8 @@ "CVE-2020-29486" ], "details": "An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node ownership has quota implications. Any guest can run another guest out of quota, or create an unbounded number of nodes owned by dom0, thus running xenstored out of memory A malicious guest administrator can cause a denial of service against a specific guest or against the whole host. All systems using oxenstored are vulnerable. Building and using oxenstored is the default in the upstream Xen distribution, if the Ocaml compiler is available. Systems using C xenstored are not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-427h-c47c-jgj4/GHSA-427h-c47c-jgj4.json b/advisories/unreviewed/2022/05/GHSA-427h-c47c-jgj4/GHSA-427h-c47c-jgj4.json index e1e23471e91..d7d536acf70 100644 --- a/advisories/unreviewed/2022/05/GHSA-427h-c47c-jgj4/GHSA-427h-c47c-jgj4.json +++ b/advisories/unreviewed/2022/05/GHSA-427h-c47c-jgj4/GHSA-427h-c47c-jgj4.json @@ -7,12 +7,8 @@ "CVE-2018-16795" ], "details": "OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-42p2-4vv3-9qv4/GHSA-42p2-4vv3-9qv4.json b/advisories/unreviewed/2022/05/GHSA-42p2-4vv3-9qv4/GHSA-42p2-4vv3-9qv4.json index 6f17212f817..0f9922ace31 100644 --- a/advisories/unreviewed/2022/05/GHSA-42p2-4vv3-9qv4/GHSA-42p2-4vv3-9qv4.json +++ b/advisories/unreviewed/2022/05/GHSA-42p2-4vv3-9qv4/GHSA-42p2-4vv3-9qv4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4328-wgfc-675c/GHSA-4328-wgfc-675c.json b/advisories/unreviewed/2022/05/GHSA-4328-wgfc-675c/GHSA-4328-wgfc-675c.json index 5f3af5871ea..9f2ee45f092 100644 --- a/advisories/unreviewed/2022/05/GHSA-4328-wgfc-675c/GHSA-4328-wgfc-675c.json +++ b/advisories/unreviewed/2022/05/GHSA-4328-wgfc-675c/GHSA-4328-wgfc-675c.json @@ -7,12 +7,8 @@ "CVE-2020-13473" ], "details": "NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43c2-x3q5-72p4/GHSA-43c2-x3q5-72p4.json b/advisories/unreviewed/2022/05/GHSA-43c2-x3q5-72p4/GHSA-43c2-x3q5-72p4.json index 19620dd9221..907af7805d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-43c2-x3q5-72p4/GHSA-43c2-x3q5-72p4.json +++ b/advisories/unreviewed/2022/05/GHSA-43c2-x3q5-72p4/GHSA-43c2-x3q5-72p4.json @@ -7,12 +7,8 @@ "CVE-2020-14224" ], "details": "A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the Notes application or inject code into the system which would execute with the privileges of the currently logged-in user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-446c-h2fq-7hw2/GHSA-446c-h2fq-7hw2.json b/advisories/unreviewed/2022/05/GHSA-446c-h2fq-7hw2/GHSA-446c-h2fq-7hw2.json index c09e4a971c1..3c64e0edd89 100644 --- a/advisories/unreviewed/2022/05/GHSA-446c-h2fq-7hw2/GHSA-446c-h2fq-7hw2.json +++ b/advisories/unreviewed/2022/05/GHSA-446c-h2fq-7hw2/GHSA-446c-h2fq-7hw2.json @@ -7,12 +7,8 @@ "CVE-2020-5637" ], "details": "Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to execute a malicious program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44f9-r7rv-2634/GHSA-44f9-r7rv-2634.json b/advisories/unreviewed/2022/05/GHSA-44f9-r7rv-2634/GHSA-44f9-r7rv-2634.json index 36f668d118d..fc14b5e0e79 100644 --- a/advisories/unreviewed/2022/05/GHSA-44f9-r7rv-2634/GHSA-44f9-r7rv-2634.json +++ b/advisories/unreviewed/2022/05/GHSA-44f9-r7rv-2634/GHSA-44f9-r7rv-2634.json @@ -7,12 +7,8 @@ "CVE-2020-35184" ], "details": "The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44vj-36hg-g8rr/GHSA-44vj-36hg-g8rr.json b/advisories/unreviewed/2022/05/GHSA-44vj-36hg-g8rr/GHSA-44vj-36hg-g8rr.json index 9e227511705..dd2c5b7f7e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-44vj-36hg-g8rr/GHSA-44vj-36hg-g8rr.json +++ b/advisories/unreviewed/2022/05/GHSA-44vj-36hg-g8rr/GHSA-44vj-36hg-g8rr.json @@ -7,12 +7,8 @@ "CVE-2020-35132" ], "details": "An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45c8-47gc-rqw4/GHSA-45c8-47gc-rqw4.json b/advisories/unreviewed/2022/05/GHSA-45c8-47gc-rqw4/GHSA-45c8-47gc-rqw4.json index bbe3bf5cdeb..94ca03cc12c 100644 --- a/advisories/unreviewed/2022/05/GHSA-45c8-47gc-rqw4/GHSA-45c8-47gc-rqw4.json +++ b/advisories/unreviewed/2022/05/GHSA-45c8-47gc-rqw4/GHSA-45c8-47gc-rqw4.json @@ -7,12 +7,8 @@ "CVE-2020-14874" ], "details": "Vulnerability in the Oracle Cloud Infrastructure Identity and Access Management product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure Identity and Access Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Cloud Infrastructure Identity and Access Management accessible data as well as unauthorized read access to a subset of Oracle Cloud Infrastructure Identity and Access Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Cloud Infrastructure Identity and Access Management. CVSS 3.1 Base Score 4.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-45rr-9gf8-j69p/GHSA-45rr-9gf8-j69p.json b/advisories/unreviewed/2022/05/GHSA-45rr-9gf8-j69p/GHSA-45rr-9gf8-j69p.json index 29f3fe576d0..f7ef7acf826 100644 --- a/advisories/unreviewed/2022/05/GHSA-45rr-9gf8-j69p/GHSA-45rr-9gf8-j69p.json +++ b/advisories/unreviewed/2022/05/GHSA-45rr-9gf8-j69p/GHSA-45rr-9gf8-j69p.json @@ -7,12 +7,8 @@ "CVE-2020-25110" ], "details": "An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is not checked, and is used for internal memory operations. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45v4-crhq-rhhc/GHSA-45v4-crhq-rhhc.json b/advisories/unreviewed/2022/05/GHSA-45v4-crhq-rhhc/GHSA-45v4-crhq-rhhc.json index ad917b2289f..d11c2f38b91 100644 --- a/advisories/unreviewed/2022/05/GHSA-45v4-crhq-rhhc/GHSA-45v4-crhq-rhhc.json +++ b/advisories/unreviewed/2022/05/GHSA-45v4-crhq-rhhc/GHSA-45v4-crhq-rhhc.json @@ -7,12 +7,8 @@ "CVE-2020-35777" ], "details": "NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45wx-vwj8-hhm4/GHSA-45wx-vwj8-hhm4.json b/advisories/unreviewed/2022/05/GHSA-45wx-vwj8-hhm4/GHSA-45wx-vwj8-hhm4.json index dff7a35f774..9001efa3bcb 100644 --- a/advisories/unreviewed/2022/05/GHSA-45wx-vwj8-hhm4/GHSA-45wx-vwj8-hhm4.json +++ b/advisories/unreviewed/2022/05/GHSA-45wx-vwj8-hhm4/GHSA-45wx-vwj8-hhm4.json @@ -7,12 +7,8 @@ "CVE-2020-0500" ], "details": "In startInputUncheckedLocked of InputMethodManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154913391", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4684-g96f-9q97/GHSA-4684-g96f-9q97.json b/advisories/unreviewed/2022/05/GHSA-4684-g96f-9q97/GHSA-4684-g96f-9q97.json index 2aca73968e0..b3e9cb43f50 100644 --- a/advisories/unreviewed/2022/05/GHSA-4684-g96f-9q97/GHSA-4684-g96f-9q97.json +++ b/advisories/unreviewed/2022/05/GHSA-4684-g96f-9q97/GHSA-4684-g96f-9q97.json @@ -7,12 +7,8 @@ "CVE-2020-27644" ], "details": "The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\\1E\\Client\\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges by placing a malicious cryptbase.dll file in %WINDIR%\\Temp\\.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-473q-vgvv-5537/GHSA-473q-vgvv-5537.json b/advisories/unreviewed/2022/05/GHSA-473q-vgvv-5537/GHSA-473q-vgvv-5537.json index 905b9db0308..f5727129552 100644 --- a/advisories/unreviewed/2022/05/GHSA-473q-vgvv-5537/GHSA-473q-vgvv-5537.json +++ b/advisories/unreviewed/2022/05/GHSA-473q-vgvv-5537/GHSA-473q-vgvv-5537.json @@ -7,12 +7,8 @@ "CVE-2020-29311" ], "details": "Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-474h-r3hr-mrpj/GHSA-474h-r3hr-mrpj.json b/advisories/unreviewed/2022/05/GHSA-474h-r3hr-mrpj/GHSA-474h-r3hr-mrpj.json index cbdcf9d0369..8f0e415f6dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-474h-r3hr-mrpj/GHSA-474h-r3hr-mrpj.json +++ b/advisories/unreviewed/2022/05/GHSA-474h-r3hr-mrpj/GHSA-474h-r3hr-mrpj.json @@ -7,12 +7,8 @@ "CVE-2020-27032" ], "details": "In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150857259", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-47g9-557v-5c66/GHSA-47g9-557v-5c66.json b/advisories/unreviewed/2022/05/GHSA-47g9-557v-5c66/GHSA-47g9-557v-5c66.json index bd843dba5b4..eec40cb05fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-47g9-557v-5c66/GHSA-47g9-557v-5c66.json +++ b/advisories/unreviewed/2022/05/GHSA-47g9-557v-5c66/GHSA-47g9-557v-5c66.json @@ -7,12 +7,8 @@ "CVE-2020-4843" ], "details": "IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authenticated user. IBM X-Force ID: 190048.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-48fw-3qmc-rmp7/GHSA-48fw-3qmc-rmp7.json b/advisories/unreviewed/2022/05/GHSA-48fw-3qmc-rmp7/GHSA-48fw-3qmc-rmp7.json index 74b51ec9345..fbda39fab54 100644 --- a/advisories/unreviewed/2022/05/GHSA-48fw-3qmc-rmp7/GHSA-48fw-3qmc-rmp7.json +++ b/advisories/unreviewed/2022/05/GHSA-48fw-3qmc-rmp7/GHSA-48fw-3qmc-rmp7.json @@ -7,12 +7,8 @@ "CVE-2020-26415" ], "details": "Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-497h-4hjg-c662/GHSA-497h-4hjg-c662.json b/advisories/unreviewed/2022/05/GHSA-497h-4hjg-c662/GHSA-497h-4hjg-c662.json index df712468c9c..9589ba0756d 100644 --- a/advisories/unreviewed/2022/05/GHSA-497h-4hjg-c662/GHSA-497h-4hjg-c662.json +++ b/advisories/unreviewed/2022/05/GHSA-497h-4hjg-c662/GHSA-497h-4hjg-c662.json @@ -7,12 +7,8 @@ "CVE-2020-8463" ], "details": "A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49hv-qhwg-6w6c/GHSA-49hv-qhwg-6w6c.json b/advisories/unreviewed/2022/05/GHSA-49hv-qhwg-6w6c/GHSA-49hv-qhwg-6w6c.json index 6289d225e48..369899dee45 100644 --- a/advisories/unreviewed/2022/05/GHSA-49hv-qhwg-6w6c/GHSA-49hv-qhwg-6w6c.json +++ b/advisories/unreviewed/2022/05/GHSA-49hv-qhwg-6w6c/GHSA-49hv-qhwg-6w6c.json @@ -7,12 +7,8 @@ "CVE-2020-24678" ], "details": "An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49w9-82cj-xr48/GHSA-49w9-82cj-xr48.json b/advisories/unreviewed/2022/05/GHSA-49w9-82cj-xr48/GHSA-49w9-82cj-xr48.json index 10804139c77..32c4b4a6441 100644 --- a/advisories/unreviewed/2022/05/GHSA-49w9-82cj-xr48/GHSA-49w9-82cj-xr48.json +++ b/advisories/unreviewed/2022/05/GHSA-49w9-82cj-xr48/GHSA-49w9-82cj-xr48.json @@ -7,12 +7,8 @@ "CVE-2020-28413" ], "details": "In MantisBT 2.24.3, SQL Injection can occur in the parameter \"access\" of the mc_project_get_users function through the API SOAP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4g47-3fx3-5q52/GHSA-4g47-3fx3-5q52.json b/advisories/unreviewed/2022/05/GHSA-4g47-3fx3-5q52/GHSA-4g47-3fx3-5q52.json index da22b435bd8..efbea4c332e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g47-3fx3-5q52/GHSA-4g47-3fx3-5q52.json +++ b/advisories/unreviewed/2022/05/GHSA-4g47-3fx3-5q52/GHSA-4g47-3fx3-5q52.json @@ -7,12 +7,8 @@ "CVE-2020-29667" ], "details": "In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4hgv-m59w-35vw/GHSA-4hgv-m59w-35vw.json b/advisories/unreviewed/2022/05/GHSA-4hgv-m59w-35vw/GHSA-4hgv-m59w-35vw.json index 61ff7c87027..5c0b69aa0b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hgv-m59w-35vw/GHSA-4hgv-m59w-35vw.json +++ b/advisories/unreviewed/2022/05/GHSA-4hgv-m59w-35vw/GHSA-4hgv-m59w-35vw.json @@ -7,12 +7,8 @@ "CVE-2020-35790" ], "details": "Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j5w-hmf4-595g/GHSA-4j5w-hmf4-595g.json b/advisories/unreviewed/2022/05/GHSA-4j5w-hmf4-595g/GHSA-4j5w-hmf4-595g.json index bcb66ec765e..aad32212284 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j5w-hmf4-595g/GHSA-4j5w-hmf4-595g.json +++ b/advisories/unreviewed/2022/05/GHSA-4j5w-hmf4-595g/GHSA-4j5w-hmf4-595g.json @@ -7,12 +7,8 @@ "CVE-2020-0495" ], "details": "In decode_Huffman of JBig2_SddProc.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155473137", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4j8j-wj7m-vcx5/GHSA-4j8j-wj7m-vcx5.json b/advisories/unreviewed/2022/05/GHSA-4j8j-wj7m-vcx5/GHSA-4j8j-wj7m-vcx5.json index ec1fa28eff2..8dfb467b7c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j8j-wj7m-vcx5/GHSA-4j8j-wj7m-vcx5.json +++ b/advisories/unreviewed/2022/05/GHSA-4j8j-wj7m-vcx5/GHSA-4j8j-wj7m-vcx5.json @@ -7,12 +7,8 @@ "CVE-2020-11720" ], "details": "An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the account admin and password 0000. After the installation, users/admins are not prompted to change this password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4m4f-3m29-78r8/GHSA-4m4f-3m29-78r8.json b/advisories/unreviewed/2022/05/GHSA-4m4f-3m29-78r8/GHSA-4m4f-3m29-78r8.json index cd304ce2e9e..b11076c40fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m4f-3m29-78r8/GHSA-4m4f-3m29-78r8.json +++ b/advisories/unreviewed/2022/05/GHSA-4m4f-3m29-78r8/GHSA-4m4f-3m29-78r8.json @@ -7,12 +7,8 @@ "CVE-2020-25187" ], "details": "Medtronic MyCareLink Smart 25000 all versions are vulnerable when an attacker who gains auth runs a debug command, which is sent to the reader causing heap overflow in the MCL Smart Reader stack. A heap overflow allows attacker to remotely execute code on the MCL Smart Reader, could lead to control of device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mmh-fcmv-q64r/GHSA-4mmh-fcmv-q64r.json b/advisories/unreviewed/2022/05/GHSA-4mmh-fcmv-q64r/GHSA-4mmh-fcmv-q64r.json index 1dd48ac9360..4fc87e3e8d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mmh-fcmv-q64r/GHSA-4mmh-fcmv-q64r.json +++ b/advisories/unreviewed/2022/05/GHSA-4mmh-fcmv-q64r/GHSA-4mmh-fcmv-q64r.json @@ -7,12 +7,8 @@ "CVE-2020-25612" ], "details": "The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control. Successful exploit could potentially allow an attacker to gain access to sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4p34-5qf5-wx5v/GHSA-4p34-5qf5-wx5v.json b/advisories/unreviewed/2022/05/GHSA-4p34-5qf5-wx5v/GHSA-4p34-5qf5-wx5v.json index 3689bc17350..68fe1d1abeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p34-5qf5-wx5v/GHSA-4p34-5qf5-wx5v.json +++ b/advisories/unreviewed/2022/05/GHSA-4p34-5qf5-wx5v/GHSA-4p34-5qf5-wx5v.json @@ -7,12 +7,8 @@ "CVE-2020-0492" ], "details": "In BitstreamFillCache of bitstream.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154058264", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4r6g-jg94-h27c/GHSA-4r6g-jg94-h27c.json b/advisories/unreviewed/2022/05/GHSA-4r6g-jg94-h27c/GHSA-4r6g-jg94-h27c.json index b4ae0425eac..887905da8c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r6g-jg94-h27c/GHSA-4r6g-jg94-h27c.json +++ b/advisories/unreviewed/2022/05/GHSA-4r6g-jg94-h27c/GHSA-4r6g-jg94-h27c.json @@ -7,12 +7,8 @@ "CVE-2020-35548" ], "details": "An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider allows attackers to cause a denial of service. The Samsung ID is SVE-2020-18629 (December 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rc3-796r-hwf9/GHSA-4rc3-796r-hwf9.json b/advisories/unreviewed/2022/05/GHSA-4rc3-796r-hwf9/GHSA-4rc3-796r-hwf9.json index 252cf91b8eb..3546e177f6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rc3-796r-hwf9/GHSA-4rc3-796r-hwf9.json +++ b/advisories/unreviewed/2022/05/GHSA-4rc3-796r-hwf9/GHSA-4rc3-796r-hwf9.json @@ -7,12 +7,8 @@ "CVE-2020-35395" ], "details": "XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4rr2-x8jq-gqq7/GHSA-4rr2-x8jq-gqq7.json b/advisories/unreviewed/2022/05/GHSA-4rr2-x8jq-gqq7/GHSA-4rr2-x8jq-gqq7.json index 779a6044dc1..322efd1d49d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rr2-x8jq-gqq7/GHSA-4rr2-x8jq-gqq7.json +++ b/advisories/unreviewed/2022/05/GHSA-4rr2-x8jq-gqq7/GHSA-4rr2-x8jq-gqq7.json @@ -7,12 +7,8 @@ "CVE-2020-0490" ], "details": "In floor1_info_unpack of floor1.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155560008", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w6w-m7p6-hrwf/GHSA-4w6w-m7p6-hrwf.json b/advisories/unreviewed/2022/05/GHSA-4w6w-m7p6-hrwf/GHSA-4w6w-m7p6-hrwf.json index 3ca75217221..89f25dba880 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w6w-m7p6-hrwf/GHSA-4w6w-m7p6-hrwf.json +++ b/advisories/unreviewed/2022/05/GHSA-4w6w-m7p6-hrwf/GHSA-4w6w-m7p6-hrwf.json @@ -7,12 +7,8 @@ "CVE-2020-27043" ], "details": "In nfc_enabled of nfc_main.cc, there is a possible out of bounds read due to an incorrect increment. This could lead to local information disclosure via firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155234594", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wfq-6m2h-348v/GHSA-4wfq-6m2h-348v.json b/advisories/unreviewed/2022/05/GHSA-4wfq-6m2h-348v/GHSA-4wfq-6m2h-348v.json index 0ab92577bde..5c72acb2f24 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wfq-6m2h-348v/GHSA-4wfq-6m2h-348v.json +++ b/advisories/unreviewed/2022/05/GHSA-4wfq-6m2h-348v/GHSA-4wfq-6m2h-348v.json @@ -7,12 +7,8 @@ "CVE-2020-0496" ], "details": "In CPDF_RenderStatus::LoadSMask of cpdf_renderstatus.cpp, there is a possible memory corruption due to a use-after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-149481220", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x7r-2g5v-6xmq/GHSA-4x7r-2g5v-6xmq.json b/advisories/unreviewed/2022/05/GHSA-4x7r-2g5v-6xmq/GHSA-4x7r-2g5v-6xmq.json index a0daf27b3fb..f93453d9fe4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x7r-2g5v-6xmq/GHSA-4x7r-2g5v-6xmq.json +++ b/advisories/unreviewed/2022/05/GHSA-4x7r-2g5v-6xmq/GHSA-4x7r-2g5v-6xmq.json @@ -7,12 +7,8 @@ "CVE-2020-16102" ], "details": "Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.XXX(MRX); 8.20 versions prior to 8.20.XXX(MRX); 8.10 versions prior to 8.10.XXX(MRX); 8.00 versions prior to 8.00.XXX(MRX); version 7.90 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-533p-xf32-32p2/GHSA-533p-xf32-32p2.json b/advisories/unreviewed/2022/05/GHSA-533p-xf32-32p2/GHSA-533p-xf32-32p2.json index f3291191fe4..771b5a088ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-533p-xf32-32p2/GHSA-533p-xf32-32p2.json +++ b/advisories/unreviewed/2022/05/GHSA-533p-xf32-32p2/GHSA-533p-xf32-32p2.json @@ -7,12 +7,8 @@ "CVE-2020-24693" ], "details": "The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system information due to insufficient output sanitization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53cj-vhvg-mmqf/GHSA-53cj-vhvg-mmqf.json b/advisories/unreviewed/2022/05/GHSA-53cj-vhvg-mmqf/GHSA-53cj-vhvg-mmqf.json index 3755b102e8a..44edefa3076 100644 --- a/advisories/unreviewed/2022/05/GHSA-53cj-vhvg-mmqf/GHSA-53cj-vhvg-mmqf.json +++ b/advisories/unreviewed/2022/05/GHSA-53cj-vhvg-mmqf/GHSA-53cj-vhvg-mmqf.json @@ -7,12 +7,8 @@ "CVE-2020-27336" ], "details": "An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a packet sent by an unauthenticated remote attacker could result in an out-of-bounds read of up to three bytes via network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53rf-x4vp-w2vq/GHSA-53rf-x4vp-w2vq.json b/advisories/unreviewed/2022/05/GHSA-53rf-x4vp-w2vq/GHSA-53rf-x4vp-w2vq.json index 35db96ffc61..c7e63155be1 100644 --- a/advisories/unreviewed/2022/05/GHSA-53rf-x4vp-w2vq/GHSA-53rf-x4vp-w2vq.json +++ b/advisories/unreviewed/2022/05/GHSA-53rf-x4vp-w2vq/GHSA-53rf-x4vp-w2vq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53xh-4grp-ggrw/GHSA-53xh-4grp-ggrw.json b/advisories/unreviewed/2022/05/GHSA-53xh-4grp-ggrw/GHSA-53xh-4grp-ggrw.json index 8c972bb6e08..d5b8d2e897c 100644 --- a/advisories/unreviewed/2022/05/GHSA-53xh-4grp-ggrw/GHSA-53xh-4grp-ggrw.json +++ b/advisories/unreviewed/2022/05/GHSA-53xh-4grp-ggrw/GHSA-53xh-4grp-ggrw.json @@ -7,12 +7,8 @@ "CVE-2020-35378" ], "details": "SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54j5-rqvj-pvhx/GHSA-54j5-rqvj-pvhx.json b/advisories/unreviewed/2022/05/GHSA-54j5-rqvj-pvhx/GHSA-54j5-rqvj-pvhx.json index a8445858c23..4f9becb74dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-54j5-rqvj-pvhx/GHSA-54j5-rqvj-pvhx.json +++ b/advisories/unreviewed/2022/05/GHSA-54j5-rqvj-pvhx/GHSA-54j5-rqvj-pvhx.json @@ -7,12 +7,8 @@ "CVE-2020-24339" ], "details": "An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The DNS domain name record decompression functionality in pico_dns_decompress_name() in pico_dns_common.c does not validate the compression pointer offset values with respect to the actual data present in a DNS response packet, causing out-of-bounds reads that lead to Denial-of-Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54xg-w6ch-fmhh/GHSA-54xg-w6ch-fmhh.json b/advisories/unreviewed/2022/05/GHSA-54xg-w6ch-fmhh/GHSA-54xg-w6ch-fmhh.json index 50074f35a45..e34c158c1fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-54xg-w6ch-fmhh/GHSA-54xg-w6ch-fmhh.json +++ b/advisories/unreviewed/2022/05/GHSA-54xg-w6ch-fmhh/GHSA-54xg-w6ch-fmhh.json @@ -7,12 +7,8 @@ "CVE-2020-9949" ], "details": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra, tvOS 14.0. An application may be able to execute arbitrary code with kernel privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5537-hr6c-2jjc/GHSA-5537-hr6c-2jjc.json b/advisories/unreviewed/2022/05/GHSA-5537-hr6c-2jjc/GHSA-5537-hr6c-2jjc.json index c009dda84d0..98b619ecfc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5537-hr6c-2jjc/GHSA-5537-hr6c-2jjc.json +++ b/advisories/unreviewed/2022/05/GHSA-5537-hr6c-2jjc/GHSA-5537-hr6c-2jjc.json @@ -7,12 +7,8 @@ "CVE-2020-27719" ], "details": "On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-555x-c8f3-84gj/GHSA-555x-c8f3-84gj.json b/advisories/unreviewed/2022/05/GHSA-555x-c8f3-84gj/GHSA-555x-c8f3-84gj.json index b2a18e2983f..89349d4db44 100644 --- a/advisories/unreviewed/2022/05/GHSA-555x-c8f3-84gj/GHSA-555x-c8f3-84gj.json +++ b/advisories/unreviewed/2022/05/GHSA-555x-c8f3-84gj/GHSA-555x-c8f3-84gj.json @@ -7,12 +7,8 @@ "CVE-2020-27049" ], "details": "In rw_t3t_send_raw_frame of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157649467", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56fm-6jmc-6mvp/GHSA-56fm-6jmc-6mvp.json b/advisories/unreviewed/2022/05/GHSA-56fm-6jmc-6mvp/GHSA-56fm-6jmc-6mvp.json index 0d3d1b8759d..f2ae593c32c 100644 --- a/advisories/unreviewed/2022/05/GHSA-56fm-6jmc-6mvp/GHSA-56fm-6jmc-6mvp.json +++ b/advisories/unreviewed/2022/05/GHSA-56fm-6jmc-6mvp/GHSA-56fm-6jmc-6mvp.json @@ -7,12 +7,8 @@ "CVE-2020-7541" ], "details": "A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of sensitive data when sending a specially crafted request to the controller over HTTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-56q5-36x8-qq3f/GHSA-56q5-36x8-qq3f.json b/advisories/unreviewed/2022/05/GHSA-56q5-36x8-qq3f/GHSA-56q5-36x8-qq3f.json index 765da90f544..d82688767cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-56q5-36x8-qq3f/GHSA-56q5-36x8-qq3f.json +++ b/advisories/unreviewed/2022/05/GHSA-56q5-36x8-qq3f/GHSA-56q5-36x8-qq3f.json @@ -7,12 +7,8 @@ "CVE-2020-28859" ], "details": "OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-583r-j6r6-x57h/GHSA-583r-j6r6-x57h.json b/advisories/unreviewed/2022/05/GHSA-583r-j6r6-x57h/GHSA-583r-j6r6-x57h.json index 33a7469bd49..31c81ce2b96 100644 --- a/advisories/unreviewed/2022/05/GHSA-583r-j6r6-x57h/GHSA-583r-j6r6-x57h.json +++ b/advisories/unreviewed/2022/05/GHSA-583r-j6r6-x57h/GHSA-583r-j6r6-x57h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58pp-88x2-wf7f/GHSA-58pp-88x2-wf7f.json b/advisories/unreviewed/2022/05/GHSA-58pp-88x2-wf7f/GHSA-58pp-88x2-wf7f.json index 5eb6e123741..0c04b0cc992 100644 --- a/advisories/unreviewed/2022/05/GHSA-58pp-88x2-wf7f/GHSA-58pp-88x2-wf7f.json +++ b/advisories/unreviewed/2022/05/GHSA-58pp-88x2-wf7f/GHSA-58pp-88x2-wf7f.json @@ -7,12 +7,8 @@ "CVE-2020-29484" ], "details": "An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watch will receive a Xenstore message containing the path of the modified Xenstore entry that triggered the watch, and the tag that was specified when registering the watch. Any communication with xenstored is done via Xenstore messages, consisting of a message header and the payload. The payload length is limited to 4096 bytes. Any request to xenstored resulting in a response with a payload longer than 4096 bytes will result in an error. When registering a watch, the payload length limit applies to the combined length of the watched path and the specified tag. Because watches for a specific path are also triggered for all nodes below that path, the payload of a watch event message can be longer than the payload needed to register the watch. A malicious guest that registers a watch using a very large tag (i.e., with a registration operation payload length close to the 4096 byte limit) can cause the generation of watch events with a payload length larger than 4096 bytes, by writing to Xenstore entries below the watched path. This will result in an error condition in xenstored. This error can result in a NULL pointer dereference, leading to a crash of xenstored. A malicious guest administrator can cause xenstored to crash, leading to a denial of service. Following a xenstored crash, domains may continue to run, but management operations will be impossible. Only C xenstored is affected, oxenstored is not affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59vv-g2mq-64c5/GHSA-59vv-g2mq-64c5.json b/advisories/unreviewed/2022/05/GHSA-59vv-g2mq-64c5/GHSA-59vv-g2mq-64c5.json index d0ae6e644a3..28160433d7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-59vv-g2mq-64c5/GHSA-59vv-g2mq-64c5.json +++ b/advisories/unreviewed/2022/05/GHSA-59vv-g2mq-64c5/GHSA-59vv-g2mq-64c5.json @@ -7,12 +7,8 @@ "CVE-2020-25010" ], "details": "An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a payload in the request parameters as an instruction to write a file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c2c-2562-gwp9/GHSA-5c2c-2562-gwp9.json b/advisories/unreviewed/2022/05/GHSA-5c2c-2562-gwp9/GHSA-5c2c-2562-gwp9.json index e8e22c735e2..10555fa89bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c2c-2562-gwp9/GHSA-5c2c-2562-gwp9.json +++ b/advisories/unreviewed/2022/05/GHSA-5c2c-2562-gwp9/GHSA-5c2c-2562-gwp9.json @@ -7,12 +7,8 @@ "CVE-2020-1848" ], "details": "There is a resource management error vulnerability in Jackman-AL00D versions 8.2.0.185(C00R2P1). Local attackers construct malicious application files, causing system applications to run abnormally.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5cx5-fcx6-4j7m/GHSA-5cx5-fcx6-4j7m.json b/advisories/unreviewed/2022/05/GHSA-5cx5-fcx6-4j7m/GHSA-5cx5-fcx6-4j7m.json index 54da39c356b..fa49817b635 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cx5-fcx6-4j7m/GHSA-5cx5-fcx6-4j7m.json +++ b/advisories/unreviewed/2022/05/GHSA-5cx5-fcx6-4j7m/GHSA-5cx5-fcx6-4j7m.json @@ -7,12 +7,8 @@ "CVE-2020-0444" ], "details": "In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150693166References: Upstream kernel", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fx7-6vcj-vqfc/GHSA-5fx7-6vcj-vqfc.json b/advisories/unreviewed/2022/05/GHSA-5fx7-6vcj-vqfc/GHSA-5fx7-6vcj-vqfc.json index 48a6e4a6fc8..d6ec677aad2 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fx7-6vcj-vqfc/GHSA-5fx7-6vcj-vqfc.json +++ b/advisories/unreviewed/2022/05/GHSA-5fx7-6vcj-vqfc/GHSA-5fx7-6vcj-vqfc.json @@ -7,12 +7,8 @@ "CVE-2020-25232" ], "details": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Due to the usage of an insecure random number generation function and a deprecated cryptographic function, an attacker could extract the key that is used when communicating with an affected device on port 8080/tcp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5g2x-gm3x-pm24/GHSA-5g2x-gm3x-pm24.json b/advisories/unreviewed/2022/05/GHSA-5g2x-gm3x-pm24/GHSA-5g2x-gm3x-pm24.json index da643939b89..b6cd0f50760 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g2x-gm3x-pm24/GHSA-5g2x-gm3x-pm24.json +++ b/advisories/unreviewed/2022/05/GHSA-5g2x-gm3x-pm24/GHSA-5g2x-gm3x-pm24.json @@ -7,12 +7,8 @@ "CVE-2020-2505" ], "details": "If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5h57-vhr8-8f95/GHSA-5h57-vhr8-8f95.json b/advisories/unreviewed/2022/05/GHSA-5h57-vhr8-8f95/GHSA-5h57-vhr8-8f95.json index 54320d513c0..94cd31458c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h57-vhr8-8f95/GHSA-5h57-vhr8-8f95.json +++ b/advisories/unreviewed/2022/05/GHSA-5h57-vhr8-8f95/GHSA-5h57-vhr8-8f95.json @@ -7,12 +7,8 @@ "CVE-2020-27051" ], "details": "In NFA_RwI93WriteMultipleBlocks of nfa_rw_api.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650338", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m57-mhq7-6vhf/GHSA-5m57-mhq7-6vhf.json b/advisories/unreviewed/2022/05/GHSA-5m57-mhq7-6vhf/GHSA-5m57-mhq7-6vhf.json index c54765b7fde..20b0ef13527 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m57-mhq7-6vhf/GHSA-5m57-mhq7-6vhf.json +++ b/advisories/unreviewed/2022/05/GHSA-5m57-mhq7-6vhf/GHSA-5m57-mhq7-6vhf.json @@ -7,12 +7,8 @@ "CVE-2020-26417" ], "details": "Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5m5r-ch84-vh95/GHSA-5m5r-ch84-vh95.json b/advisories/unreviewed/2022/05/GHSA-5m5r-ch84-vh95/GHSA-5m5r-ch84-vh95.json index 6e0c97f8e9b..c88598f2f13 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m5r-ch84-vh95/GHSA-5m5r-ch84-vh95.json +++ b/advisories/unreviewed/2022/05/GHSA-5m5r-ch84-vh95/GHSA-5m5r-ch84-vh95.json @@ -7,12 +7,8 @@ "CVE-2020-35388" ], "details": "rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mr8-rv5h-p6vv/GHSA-5mr8-rv5h-p6vv.json b/advisories/unreviewed/2022/05/GHSA-5mr8-rv5h-p6vv/GHSA-5mr8-rv5h-p6vv.json index a2bd0bdacbe..e79c11693f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mr8-rv5h-p6vv/GHSA-5mr8-rv5h-p6vv.json +++ b/advisories/unreviewed/2022/05/GHSA-5mr8-rv5h-p6vv/GHSA-5mr8-rv5h-p6vv.json @@ -7,12 +7,8 @@ "CVE-2020-35716" ], "details": "Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnly parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5rj7-m957-87g6/GHSA-5rj7-m957-87g6.json b/advisories/unreviewed/2022/05/GHSA-5rj7-m957-87g6/GHSA-5rj7-m957-87g6.json index 17207f205df..e3936e960ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rj7-m957-87g6/GHSA-5rj7-m957-87g6.json +++ b/advisories/unreviewed/2022/05/GHSA-5rj7-m957-87g6/GHSA-5rj7-m957-87g6.json @@ -7,12 +7,8 @@ "CVE-2020-35656" ], "details": "Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v7h-9v5g-w2x6/GHSA-5v7h-9v5g-w2x6.json b/advisories/unreviewed/2022/05/GHSA-5v7h-9v5g-w2x6/GHSA-5v7h-9v5g-w2x6.json index 9601bbf8e23..41d0f516b19 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v7h-9v5g-w2x6/GHSA-5v7h-9v5g-w2x6.json +++ b/advisories/unreviewed/2022/05/GHSA-5v7h-9v5g-w2x6/GHSA-5v7h-9v5g-w2x6.json @@ -7,12 +7,8 @@ "CVE-2020-9119" ], "details": "There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to physically contact the mobile phone and obtain higher privileges, and execute relevant commands, resulting in the user's privilege promotion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v7p-whcg-3j32/GHSA-5v7p-whcg-3j32.json b/advisories/unreviewed/2022/05/GHSA-5v7p-whcg-3j32/GHSA-5v7p-whcg-3j32.json index 484e6c2303c..971bbdeaa68 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v7p-whcg-3j32/GHSA-5v7p-whcg-3j32.json +++ b/advisories/unreviewed/2022/05/GHSA-5v7p-whcg-3j32/GHSA-5v7p-whcg-3j32.json @@ -7,12 +7,8 @@ "CVE-2020-24634" ], "details": "An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wh3-x3rh-6qff/GHSA-5wh3-x3rh-6qff.json b/advisories/unreviewed/2022/05/GHSA-5wh3-x3rh-6qff/GHSA-5wh3-x3rh-6qff.json index 3530bce73fc..d70af40acab 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wh3-x3rh-6qff/GHSA-5wh3-x3rh-6qff.json +++ b/advisories/unreviewed/2022/05/GHSA-5wh3-x3rh-6qff/GHSA-5wh3-x3rh-6qff.json @@ -7,12 +7,8 @@ "CVE-2020-26177" ], "details": "In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restriction is only applied client-side. Manipulating any of the greyed-out values in requests to /api/profile is not prohibited server-side.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x29-2xgq-48fc/GHSA-5x29-2xgq-48fc.json b/advisories/unreviewed/2022/05/GHSA-5x29-2xgq-48fc/GHSA-5x29-2xgq-48fc.json index a9bfa8ea71c..719f560089d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x29-2xgq-48fc/GHSA-5x29-2xgq-48fc.json +++ b/advisories/unreviewed/2022/05/GHSA-5x29-2xgq-48fc/GHSA-5x29-2xgq-48fc.json @@ -7,12 +7,8 @@ "CVE-2020-29472" ], "details": "EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x7q-6f7m-fc5c/GHSA-5x7q-6f7m-fc5c.json b/advisories/unreviewed/2022/05/GHSA-5x7q-6f7m-fc5c/GHSA-5x7q-6f7m-fc5c.json index 2a99990d0fe..ab9295155f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x7q-6f7m-fc5c/GHSA-5x7q-6f7m-fc5c.json +++ b/advisories/unreviewed/2022/05/GHSA-5x7q-6f7m-fc5c/GHSA-5x7q-6f7m-fc5c.json @@ -7,12 +7,8 @@ "CVE-2020-29485" ], "details": "An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request, not all tracking information is freed. A guest can cause unbounded memory usage in oxenstored. This can lead to a system-wide DoS. Only systems using the Ocaml Xenstored implementation are vulnerable. Systems using the C Xenstored implementation are not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xj2-h84j-jqmg/GHSA-5xj2-h84j-jqmg.json b/advisories/unreviewed/2022/05/GHSA-5xj2-h84j-jqmg/GHSA-5xj2-h84j-jqmg.json index 1ac2434113b..f7bb9c47d27 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xj2-h84j-jqmg/GHSA-5xj2-h84j-jqmg.json +++ b/advisories/unreviewed/2022/05/GHSA-5xj2-h84j-jqmg/GHSA-5xj2-h84j-jqmg.json @@ -7,12 +7,8 @@ "CVE-2020-25609" ], "details": "The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to view and modify user data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xx2-xmgx-crvj/GHSA-5xx2-xmgx-crvj.json b/advisories/unreviewed/2022/05/GHSA-5xx2-xmgx-crvj/GHSA-5xx2-xmgx-crvj.json index 62396aa8c11..dedc68af007 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xx2-xmgx-crvj/GHSA-5xx2-xmgx-crvj.json +++ b/advisories/unreviewed/2022/05/GHSA-5xx2-xmgx-crvj/GHSA-5xx2-xmgx-crvj.json @@ -7,12 +7,8 @@ "CVE-2020-27133" ], "details": "Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-622c-r8r9-89jj/GHSA-622c-r8r9-89jj.json b/advisories/unreviewed/2022/05/GHSA-622c-r8r9-89jj/GHSA-622c-r8r9-89jj.json index 42f0931c2cb..fe4e1bfd36a 100644 --- a/advisories/unreviewed/2022/05/GHSA-622c-r8r9-89jj/GHSA-622c-r8r9-89jj.json +++ b/advisories/unreviewed/2022/05/GHSA-622c-r8r9-89jj/GHSA-622c-r8r9-89jj.json @@ -7,12 +7,8 @@ "CVE-2020-27639" ], "details": "The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-625c-v8wh-vppg/GHSA-625c-v8wh-vppg.json b/advisories/unreviewed/2022/05/GHSA-625c-v8wh-vppg/GHSA-625c-v8wh-vppg.json index 549918fd3e8..708b0580c60 100644 --- a/advisories/unreviewed/2022/05/GHSA-625c-v8wh-vppg/GHSA-625c-v8wh-vppg.json +++ b/advisories/unreviewed/2022/05/GHSA-625c-v8wh-vppg/GHSA-625c-v8wh-vppg.json @@ -7,12 +7,8 @@ "CVE-2020-35676" ], "details": "BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration functionality. As such, an attacker can input a crafted payload that will execute upon the application's administrator browsing the registered users' list. Once the arbitrary Javascript is executed in the context of the admin, this will cause the attacker to gain administrative privileges, effectively leading into an application takeover. This affects app/membership_signup.php and app/admin/pageViewMembers.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6338-48mj-7qpp/GHSA-6338-48mj-7qpp.json b/advisories/unreviewed/2022/05/GHSA-6338-48mj-7qpp/GHSA-6338-48mj-7qpp.json index 956d39c1f21..7f5bf6edb05 100644 --- a/advisories/unreviewed/2022/05/GHSA-6338-48mj-7qpp/GHSA-6338-48mj-7qpp.json +++ b/advisories/unreviewed/2022/05/GHSA-6338-48mj-7qpp/GHSA-6338-48mj-7qpp.json @@ -7,12 +7,8 @@ "CVE-2020-35792" ], "details": "Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7500v2 before 1.0.3.48, R8900 before 1.0.5.2, R9000 before 1.0.5.2, and R7800 before 1.0.2.68.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6343-5v5c-grr3/GHSA-6343-5v5c-grr3.json b/advisories/unreviewed/2022/05/GHSA-6343-5v5c-grr3/GHSA-6343-5v5c-grr3.json index 22f29d6eef9..32e22130253 100644 --- a/advisories/unreviewed/2022/05/GHSA-6343-5v5c-grr3/GHSA-6343-5v5c-grr3.json +++ b/advisories/unreviewed/2022/05/GHSA-6343-5v5c-grr3/GHSA-6343-5v5c-grr3.json @@ -7,12 +7,8 @@ "CVE-2020-35364" ], "details": "Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a process, and then waiting for a Huorong services restart or a system reboot.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6367-c2hm-87fh/GHSA-6367-c2hm-87fh.json b/advisories/unreviewed/2022/05/GHSA-6367-c2hm-87fh/GHSA-6367-c2hm-87fh.json index 48e06a37e35..899090c9e7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6367-c2hm-87fh/GHSA-6367-c2hm-87fh.json +++ b/advisories/unreviewed/2022/05/GHSA-6367-c2hm-87fh/GHSA-6367-c2hm-87fh.json @@ -7,12 +7,8 @@ "CVE-2020-29233" ], "details": "WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and attacker can steal the cookie according to the crafted payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-636w-6mqg-2rmv/GHSA-636w-6mqg-2rmv.json b/advisories/unreviewed/2022/05/GHSA-636w-6mqg-2rmv/GHSA-636w-6mqg-2rmv.json index 9c226393f61..f417bd107f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-636w-6mqg-2rmv/GHSA-636w-6mqg-2rmv.json +++ b/advisories/unreviewed/2022/05/GHSA-636w-6mqg-2rmv/GHSA-636w-6mqg-2rmv.json @@ -7,12 +7,8 @@ "CVE-2020-16608" ], "details": "Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63m9-h3h6-xrqx/GHSA-63m9-h3h6-xrqx.json b/advisories/unreviewed/2022/05/GHSA-63m9-h3h6-xrqx/GHSA-63m9-h3h6-xrqx.json index 96e05b1d0b7..8211b0d78ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-63m9-h3h6-xrqx/GHSA-63m9-h3h6-xrqx.json +++ b/advisories/unreviewed/2022/05/GHSA-63m9-h3h6-xrqx/GHSA-63m9-h3h6-xrqx.json @@ -7,12 +7,8 @@ "CVE-2020-28841" ], "details": "MyDrivers64.sys in DriverGenius 9.61.3708.3054 allows attackers to cause a system crash via the ioctl command 0x9c402000 to \\\\.\\MyDrivers0_0_1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63p4-w7wr-6hxg/GHSA-63p4-w7wr-6hxg.json b/advisories/unreviewed/2022/05/GHSA-63p4-w7wr-6hxg/GHSA-63p4-w7wr-6hxg.json index f5999e45b62..c6789ee0452 100644 --- a/advisories/unreviewed/2022/05/GHSA-63p4-w7wr-6hxg/GHSA-63p4-w7wr-6hxg.json +++ b/advisories/unreviewed/2022/05/GHSA-63p4-w7wr-6hxg/GHSA-63p4-w7wr-6hxg.json @@ -7,12 +7,8 @@ "CVE-2020-13986" ], "details": "An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rpl_remove_header in net/rpl/rpl-ext-header.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63qj-x5v8-6jj4/GHSA-63qj-x5v8-6jj4.json b/advisories/unreviewed/2022/05/GHSA-63qj-x5v8-6jj4/GHSA-63qj-x5v8-6jj4.json index cb600fd815d..ad81072b5af 100644 --- a/advisories/unreviewed/2022/05/GHSA-63qj-x5v8-6jj4/GHSA-63qj-x5v8-6jj4.json +++ b/advisories/unreviewed/2022/05/GHSA-63qj-x5v8-6jj4/GHSA-63qj-x5v8-6jj4.json @@ -7,12 +7,8 @@ "CVE-2020-15898" ], "details": "In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version 4.21.4.1F and below releases in the 4.21.x train; EOS X-Series versions 4.21.11M and below releases in the 4.21.x train; 4.22.6M and below releases in the 4.22.x train; 4.23.4M and below releases in the 4.23.x train; 4.24.2.1F and below releases in the 4.24.x train.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-63vh-chmr-pr22/GHSA-63vh-chmr-pr22.json b/advisories/unreviewed/2022/05/GHSA-63vh-chmr-pr22/GHSA-63vh-chmr-pr22.json index 7cb7370af07..852919a8784 100644 --- a/advisories/unreviewed/2022/05/GHSA-63vh-chmr-pr22/GHSA-63vh-chmr-pr22.json +++ b/advisories/unreviewed/2022/05/GHSA-63vh-chmr-pr22/GHSA-63vh-chmr-pr22.json @@ -7,12 +7,8 @@ "CVE-2020-35382" ], "details": "SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6489-mq5r-6f8p/GHSA-6489-mq5r-6f8p.json b/advisories/unreviewed/2022/05/GHSA-6489-mq5r-6f8p/GHSA-6489-mq5r-6f8p.json index d5534cf2077..cc8888ef2da 100644 --- a/advisories/unreviewed/2022/05/GHSA-6489-mq5r-6f8p/GHSA-6489-mq5r-6f8p.json +++ b/advisories/unreviewed/2022/05/GHSA-6489-mq5r-6f8p/GHSA-6489-mq5r-6f8p.json @@ -7,12 +7,8 @@ "CVE-2020-0482" ], "details": "In command of IncidentService.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150706572", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6496-p2qf-5gj8/GHSA-6496-p2qf-5gj8.json b/advisories/unreviewed/2022/05/GHSA-6496-p2qf-5gj8/GHSA-6496-p2qf-5gj8.json index 2a1ac10ef15..6ef25440c69 100644 --- a/advisories/unreviewed/2022/05/GHSA-6496-p2qf-5gj8/GHSA-6496-p2qf-5gj8.json +++ b/advisories/unreviewed/2022/05/GHSA-6496-p2qf-5gj8/GHSA-6496-p2qf-5gj8.json @@ -7,12 +7,8 @@ "CVE-2020-9093" ], "details": "There is a use after free vulnerability in Taurus-AL00A versions 10.0.0.1(C00E1R1P1). A module does not deal with specific message properly, which makes a function refer to memory after it has been freed. Attackers can exploit this vulnerability by running a crafted application with common privilege. This would compromise normal service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64j2-vfrj-6r28/GHSA-64j2-vfrj-6r28.json b/advisories/unreviewed/2022/05/GHSA-64j2-vfrj-6r28/GHSA-64j2-vfrj-6r28.json index e3002a99017..a0057add10d 100644 --- a/advisories/unreviewed/2022/05/GHSA-64j2-vfrj-6r28/GHSA-64j2-vfrj-6r28.json +++ b/advisories/unreviewed/2022/05/GHSA-64j2-vfrj-6r28/GHSA-64j2-vfrj-6r28.json @@ -7,12 +7,8 @@ "CVE-2020-29654" ], "details": "Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-64m3-gx4j-jq98/GHSA-64m3-gx4j-jq98.json b/advisories/unreviewed/2022/05/GHSA-64m3-gx4j-jq98/GHSA-64m3-gx4j-jq98.json index f4ca51fd71c..4a8b3c9d196 100644 --- a/advisories/unreviewed/2022/05/GHSA-64m3-gx4j-jq98/GHSA-64m3-gx4j-jq98.json +++ b/advisories/unreviewed/2022/05/GHSA-64m3-gx4j-jq98/GHSA-64m3-gx4j-jq98.json @@ -7,12 +7,8 @@ "CVE-2020-25107" ], "details": "An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. There is no check on whether a domain name has '\\0' termination. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6676-52pp-h5fg/GHSA-6676-52pp-h5fg.json b/advisories/unreviewed/2022/05/GHSA-6676-52pp-h5fg/GHSA-6676-52pp-h5fg.json index 3f528daae30..0873c31a285 100644 --- a/advisories/unreviewed/2022/05/GHSA-6676-52pp-h5fg/GHSA-6676-52pp-h5fg.json +++ b/advisories/unreviewed/2022/05/GHSA-6676-52pp-h5fg/GHSA-6676-52pp-h5fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66h6-4ppg-82p8/GHSA-66h6-4ppg-82p8.json b/advisories/unreviewed/2022/05/GHSA-66h6-4ppg-82p8/GHSA-66h6-4ppg-82p8.json index 09d2a5a701e..4bbbfcf1e9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-66h6-4ppg-82p8/GHSA-66h6-4ppg-82p8.json +++ b/advisories/unreviewed/2022/05/GHSA-66h6-4ppg-82p8/GHSA-66h6-4ppg-82p8.json @@ -7,12 +7,8 @@ "CVE-2020-26412" ], "details": "Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66j6-79mp-77p6/GHSA-66j6-79mp-77p6.json b/advisories/unreviewed/2022/05/GHSA-66j6-79mp-77p6/GHSA-66j6-79mp-77p6.json index b173623e67f..009452ad968 100644 --- a/advisories/unreviewed/2022/05/GHSA-66j6-79mp-77p6/GHSA-66j6-79mp-77p6.json +++ b/advisories/unreviewed/2022/05/GHSA-66j6-79mp-77p6/GHSA-66j6-79mp-77p6.json @@ -7,12 +7,8 @@ "CVE-2020-35185" ], "details": "The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66pq-mwg2-mc6q/GHSA-66pq-mwg2-mc6q.json b/advisories/unreviewed/2022/05/GHSA-66pq-mwg2-mc6q/GHSA-66pq-mwg2-mc6q.json index 9ad98a553dc..c7ee36f2572 100644 --- a/advisories/unreviewed/2022/05/GHSA-66pq-mwg2-mc6q/GHSA-66pq-mwg2-mc6q.json +++ b/advisories/unreviewed/2022/05/GHSA-66pq-mwg2-mc6q/GHSA-66pq-mwg2-mc6q.json @@ -7,12 +7,8 @@ "CVE-2020-25507" ], "details": "An incorrect permission assignment (chmod 777) of /etc/environment during the installation script of No Magic TeamworkCloud 18.0 through 19.0 allows any local unprivileged user to write to /etc/environment. An attacker can escalate to root by writing arbitrary code to this file, which would be executed by root during the next login, reboot, or sourcing of the environment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66q5-93c3-xq5w/GHSA-66q5-93c3-xq5w.json b/advisories/unreviewed/2022/05/GHSA-66q5-93c3-xq5w/GHSA-66q5-93c3-xq5w.json index 316f4134a9b..b5c75e27560 100644 --- a/advisories/unreviewed/2022/05/GHSA-66q5-93c3-xq5w/GHSA-66q5-93c3-xq5w.json +++ b/advisories/unreviewed/2022/05/GHSA-66q5-93c3-xq5w/GHSA-66q5-93c3-xq5w.json @@ -7,12 +7,8 @@ "CVE-2020-25234" ], "details": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The LOGO! program files generated and used by the affected components offer the possibility to save user-defined functions (UDF) in a password protected way. This protection is implemented in the software that displays the information. An attacker could reverse engineer the UDFs directly from stored program files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6732-rrr9-72hv/GHSA-6732-rrr9-72hv.json b/advisories/unreviewed/2022/05/GHSA-6732-rrr9-72hv/GHSA-6732-rrr9-72hv.json index 7efbd3f9fcd..75f8187f27e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6732-rrr9-72hv/GHSA-6732-rrr9-72hv.json +++ b/advisories/unreviewed/2022/05/GHSA-6732-rrr9-72hv/GHSA-6732-rrr9-72hv.json @@ -7,12 +7,8 @@ "CVE-2020-0494" ], "details": "In ih264d_parse_ave of ih264d_sei.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-152895390", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67r3-w458-w4x6/GHSA-67r3-w458-w4x6.json b/advisories/unreviewed/2022/05/GHSA-67r3-w458-w4x6/GHSA-67r3-w458-w4x6.json index 925817a7738..b6ac1883429 100644 --- a/advisories/unreviewed/2022/05/GHSA-67r3-w458-w4x6/GHSA-67r3-w458-w4x6.json +++ b/advisories/unreviewed/2022/05/GHSA-67r3-w458-w4x6/GHSA-67r3-w458-w4x6.json @@ -7,12 +7,8 @@ "CVE-2020-27172" ], "details": "An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file restore mechanism to achieve arbitrary write that leads to elevation of privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-685v-qm2g-x563/GHSA-685v-qm2g-x563.json b/advisories/unreviewed/2022/05/GHSA-685v-qm2g-x563/GHSA-685v-qm2g-x563.json index e05c805b52d..460efae2335 100644 --- a/advisories/unreviewed/2022/05/GHSA-685v-qm2g-x563/GHSA-685v-qm2g-x563.json +++ b/advisories/unreviewed/2022/05/GHSA-685v-qm2g-x563/GHSA-685v-qm2g-x563.json @@ -7,12 +7,8 @@ "CVE-2020-35189" ], "details": "The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6927-m748-j36j/GHSA-6927-m748-j36j.json b/advisories/unreviewed/2022/05/GHSA-6927-m748-j36j/GHSA-6927-m748-j36j.json index 227f63928ba..ef695adbe6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6927-m748-j36j/GHSA-6927-m748-j36j.json +++ b/advisories/unreviewed/2022/05/GHSA-6927-m748-j36j/GHSA-6927-m748-j36j.json @@ -7,12 +7,8 @@ "CVE-2020-17444" ], "details": "An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv6 extension headers are valid) doesn't check whether the header extension length field would overflow. Therefore, if it wraps around to zero, iterating through the extension headers will not increment the current data pointer. This leads to an infinite loop and Denial-of-Service in pico_ipv6_check_headers_sequence() in pico_ipv6.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-697w-4mf4-ghh4/GHSA-697w-4mf4-ghh4.json b/advisories/unreviewed/2022/05/GHSA-697w-4mf4-ghh4/GHSA-697w-4mf4-ghh4.json index f492d9bab98..e9bd161a4ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-697w-4mf4-ghh4/GHSA-697w-4mf4-ghh4.json +++ b/advisories/unreviewed/2022/05/GHSA-697w-4mf4-ghh4/GHSA-697w-4mf4-ghh4.json @@ -7,12 +7,8 @@ "CVE-2020-27054" ], "details": "In onFactoryReset of BluetoothManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-159061926", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6995-mfw9-q3hp/GHSA-6995-mfw9-q3hp.json b/advisories/unreviewed/2022/05/GHSA-6995-mfw9-q3hp/GHSA-6995-mfw9-q3hp.json index 43bb4e6ca20..f2013668b76 100644 --- a/advisories/unreviewed/2022/05/GHSA-6995-mfw9-q3hp/GHSA-6995-mfw9-q3hp.json +++ b/advisories/unreviewed/2022/05/GHSA-6995-mfw9-q3hp/GHSA-6995-mfw9-q3hp.json @@ -7,12 +7,8 @@ "CVE-2020-27728" ], "details": "On BIG-IP ASM & Advanced WAF versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, under certain conditions, Analytics, Visibility, and Reporting daemon (AVRD) may generate a core file and restart on the BIG-IP system when processing requests sent from mobile devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c67-cppc-86v4/GHSA-6c67-cppc-86v4.json b/advisories/unreviewed/2022/05/GHSA-6c67-cppc-86v4/GHSA-6c67-cppc-86v4.json index 02c759b9fa5..81e8833b90d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c67-cppc-86v4/GHSA-6c67-cppc-86v4.json +++ b/advisories/unreviewed/2022/05/GHSA-6c67-cppc-86v4/GHSA-6c67-cppc-86v4.json @@ -7,12 +7,8 @@ "CVE-2020-35627" ], "details": "Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function \"Custom Gift Card Template\", the function of uploading a custom image is used, changing the name of the image extension to PHP and executing PHP code on the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fm5-8wjh-r65x/GHSA-6fm5-8wjh-r65x.json b/advisories/unreviewed/2022/05/GHSA-6fm5-8wjh-r65x/GHSA-6fm5-8wjh-r65x.json index 720ea1c971d..a90712e0f2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fm5-8wjh-r65x/GHSA-6fm5-8wjh-r65x.json +++ b/advisories/unreviewed/2022/05/GHSA-6fm5-8wjh-r65x/GHSA-6fm5-8wjh-r65x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6g37-4jmq-qq2x/GHSA-6g37-4jmq-qq2x.json b/advisories/unreviewed/2022/05/GHSA-6g37-4jmq-qq2x/GHSA-6g37-4jmq-qq2x.json index f2e4155d74b..f79a14c226a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g37-4jmq-qq2x/GHSA-6g37-4jmq-qq2x.json +++ b/advisories/unreviewed/2022/05/GHSA-6g37-4jmq-qq2x/GHSA-6g37-4jmq-qq2x.json @@ -7,12 +7,8 @@ "CVE-2020-8935" ], "details": "An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untrusted code and overwrite sections of the Enclave memory address. We recommend updating your library.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gcw-7qx9-8vhw/GHSA-6gcw-7qx9-8vhw.json b/advisories/unreviewed/2022/05/GHSA-6gcw-7qx9-8vhw/GHSA-6gcw-7qx9-8vhw.json index dcdeccc5f9c..9b357965234 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gcw-7qx9-8vhw/GHSA-6gcw-7qx9-8vhw.json +++ b/advisories/unreviewed/2022/05/GHSA-6gcw-7qx9-8vhw/GHSA-6gcw-7qx9-8vhw.json @@ -7,12 +7,8 @@ "CVE-2020-35787" ], "details": "Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.36, D7000 before 1.0.1.70, EX6200v2 before 1.0.1.78, EX7000 before 1.0.1.78, EX8000 before 1.0.1.186, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.42, R6050 before 1.0.1.18, R6080 before 1.0.0.42, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6260 before 1.1.0.64, R6300v2 before 1.0.4.34, R6700 before 1.0.2.6, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900 before 1.0.2.4, R6900P before 1.3.1.64, R6900v2 before 1.2.0.36, R7000 before 1.0.9.42, R7000P before 1.3.1.64, R7800 before 1.0.2.60, R8900 before 1.0.4.12, R9000 before 1.0.4.12, and XR500 before 2.3.2.40.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6gf9-qq8q-552j/GHSA-6gf9-qq8q-552j.json b/advisories/unreviewed/2022/05/GHSA-6gf9-qq8q-552j/GHSA-6gf9-qq8q-552j.json index 1ad8130018f..f42d931fee9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gf9-qq8q-552j/GHSA-6gf9-qq8q-552j.json +++ b/advisories/unreviewed/2022/05/GHSA-6gf9-qq8q-552j/GHSA-6gf9-qq8q-552j.json @@ -7,12 +7,8 @@ "CVE-2020-29590" ], "details": "Versions of the Official teamspeak Docker images through 3.6.0 contain a blank password for the root user. Systems deployed using affected versions of the teamspeak container may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hhm-232w-8g2c/GHSA-6hhm-232w-8g2c.json b/advisories/unreviewed/2022/05/GHSA-6hhm-232w-8g2c/GHSA-6hhm-232w-8g2c.json index 86bec9ae50f..30bd832af78 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hhm-232w-8g2c/GHSA-6hhm-232w-8g2c.json +++ b/advisories/unreviewed/2022/05/GHSA-6hhm-232w-8g2c/GHSA-6hhm-232w-8g2c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hw7-fjvh-gwx7/GHSA-6hw7-fjvh-gwx7.json b/advisories/unreviewed/2022/05/GHSA-6hw7-fjvh-gwx7/GHSA-6hw7-fjvh-gwx7.json index cc3eb63bce9..90d86bce2fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hw7-fjvh-gwx7/GHSA-6hw7-fjvh-gwx7.json +++ b/advisories/unreviewed/2022/05/GHSA-6hw7-fjvh-gwx7/GHSA-6hw7-fjvh-gwx7.json @@ -7,12 +7,8 @@ "CVE-2020-35807" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, RAX120 before 1.0.0.78, RBK22 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and WN3000RPv2 before 1.0.0.78.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j7q-rmrp-5g6f/GHSA-6j7q-rmrp-5g6f.json b/advisories/unreviewed/2022/05/GHSA-6j7q-rmrp-5g6f/GHSA-6j7q-rmrp-5g6f.json index 31d2e59f6cc..88d7fc3a01e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j7q-rmrp-5g6f/GHSA-6j7q-rmrp-5g6f.json +++ b/advisories/unreviewed/2022/05/GHSA-6j7q-rmrp-5g6f/GHSA-6j7q-rmrp-5g6f.json @@ -7,12 +7,8 @@ "CVE-2020-11719" ], "details": "An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6m4v-96f3-85ph/GHSA-6m4v-96f3-85ph.json b/advisories/unreviewed/2022/05/GHSA-6m4v-96f3-85ph/GHSA-6m4v-96f3-85ph.json index 4cb109b7d54..cc772697dd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m4v-96f3-85ph/GHSA-6m4v-96f3-85ph.json +++ b/advisories/unreviewed/2022/05/GHSA-6m4v-96f3-85ph/GHSA-6m4v-96f3-85ph.json @@ -7,12 +7,8 @@ "CVE-2020-25494" ], "details": "Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mh7-r2rw-gp32/GHSA-6mh7-r2rw-gp32.json b/advisories/unreviewed/2022/05/GHSA-6mh7-r2rw-gp32/GHSA-6mh7-r2rw-gp32.json index d4f8542623e..814c52ba04f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mh7-r2rw-gp32/GHSA-6mh7-r2rw-gp32.json +++ b/advisories/unreviewed/2022/05/GHSA-6mh7-r2rw-gp32/GHSA-6mh7-r2rw-gp32.json @@ -7,12 +7,8 @@ "CVE-2020-25095" ], "details": "LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CSWH). If a logged-in PM user visits a malicious site in the same browser session, that site can perform a CSRF attack to create a WebSocket from the victim client to the vulnerable PM server. Once the socket is created, the malicious site can interact with the vulnerable web server in the context of the logged-in user. This can include WebSocket payloads that result in command execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mpj-7w8c-wv4j/GHSA-6mpj-7w8c-wv4j.json b/advisories/unreviewed/2022/05/GHSA-6mpj-7w8c-wv4j/GHSA-6mpj-7w8c-wv4j.json index 51d3a2b6c09..0dcc8284304 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mpj-7w8c-wv4j/GHSA-6mpj-7w8c-wv4j.json +++ b/advisories/unreviewed/2022/05/GHSA-6mpj-7w8c-wv4j/GHSA-6mpj-7w8c-wv4j.json @@ -7,12 +7,8 @@ "CVE-2020-35793" ], "details": "Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.5.2, and R9000 before 1.0.5.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mvg-7752-5v6p/GHSA-6mvg-7752-5v6p.json b/advisories/unreviewed/2022/05/GHSA-6mvg-7752-5v6p/GHSA-6mvg-7752-5v6p.json index 64d87b2e453..44e519a1689 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mvg-7752-5v6p/GHSA-6mvg-7752-5v6p.json +++ b/advisories/unreviewed/2022/05/GHSA-6mvg-7752-5v6p/GHSA-6mvg-7752-5v6p.json @@ -7,12 +7,8 @@ "CVE-2020-35704" ], "details": "Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6q5r-2gfw-g2w4/GHSA-6q5r-2gfw-g2w4.json b/advisories/unreviewed/2022/05/GHSA-6q5r-2gfw-g2w4/GHSA-6q5r-2gfw-g2w4.json index 8674f177d92..fdcf2b8876e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q5r-2gfw-g2w4/GHSA-6q5r-2gfw-g2w4.json +++ b/advisories/unreviewed/2022/05/GHSA-6q5r-2gfw-g2w4/GHSA-6q5r-2gfw-g2w4.json @@ -7,12 +7,8 @@ "CVE-2020-28186" ], "details": "Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r38-jm65-2wmh/GHSA-6r38-jm65-2wmh.json b/advisories/unreviewed/2022/05/GHSA-6r38-jm65-2wmh/GHSA-6r38-jm65-2wmh.json index 2efe0c22759..27363307774 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r38-jm65-2wmh/GHSA-6r38-jm65-2wmh.json +++ b/advisories/unreviewed/2022/05/GHSA-6r38-jm65-2wmh/GHSA-6r38-jm65-2wmh.json @@ -7,12 +7,8 @@ "CVE-2020-35550" ], "details": "An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via StatusBar. The Samsung ID is SVE-2020-17888 (December 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rmx-66m4-ch79/GHSA-6rmx-66m4-ch79.json b/advisories/unreviewed/2022/05/GHSA-6rmx-66m4-ch79/GHSA-6rmx-66m4-ch79.json index 618341ef02e..39b9945709b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rmx-66m4-ch79/GHSA-6rmx-66m4-ch79.json +++ b/advisories/unreviewed/2022/05/GHSA-6rmx-66m4-ch79/GHSA-6rmx-66m4-ch79.json @@ -7,12 +7,8 @@ "CVE-2020-4988" ], "details": "Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or possibly execute code. IBM X-Force ID: 192706.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6rxh-rgmc-47h8/GHSA-6rxh-rgmc-47h8.json b/advisories/unreviewed/2022/05/GHSA-6rxh-rgmc-47h8/GHSA-6rxh-rgmc-47h8.json index 5f1ebb953c1..4422a46f8da 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rxh-rgmc-47h8/GHSA-6rxh-rgmc-47h8.json +++ b/advisories/unreviewed/2022/05/GHSA-6rxh-rgmc-47h8/GHSA-6rxh-rgmc-47h8.json @@ -7,12 +7,8 @@ "CVE-2020-29254" ], "details": "TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected system. An attacker could exploit this vulnerability by persuading a user of the interface to follow a maliciously crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These action include allowing attackers to submit their own code through an authenticated user resulting in local file Inclusion. If an authenticated user who is able to edit TikiWiki templates visits an malicious website, template code can be edited.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v6x-q433-6x54/GHSA-6v6x-q433-6x54.json b/advisories/unreviewed/2022/05/GHSA-6v6x-q433-6x54/GHSA-6v6x-q433-6x54.json index f14319db3a3..3366a2407d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v6x-q433-6x54/GHSA-6v6x-q433-6x54.json +++ b/advisories/unreviewed/2022/05/GHSA-6v6x-q433-6x54/GHSA-6v6x-q433-6x54.json @@ -7,12 +7,8 @@ "CVE-2020-25620" ], "details": "An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named support@n-able.com and nableadmin@n-able.com. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v85-364q-mgv8/GHSA-6v85-364q-mgv8.json b/advisories/unreviewed/2022/05/GHSA-6v85-364q-mgv8/GHSA-6v85-364q-mgv8.json index e7f1030ac8c..a5552a2258f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v85-364q-mgv8/GHSA-6v85-364q-mgv8.json +++ b/advisories/unreviewed/2022/05/GHSA-6v85-364q-mgv8/GHSA-6v85-364q-mgv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v93-795h-j436/GHSA-6v93-795h-j436.json b/advisories/unreviewed/2022/05/GHSA-6v93-795h-j436/GHSA-6v93-795h-j436.json index d145c8c9532..b45d59c0915 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v93-795h-j436/GHSA-6v93-795h-j436.json +++ b/advisories/unreviewed/2022/05/GHSA-6v93-795h-j436/GHSA-6v93-795h-j436.json @@ -7,12 +7,8 @@ "CVE-2020-7837" ], "details": "An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strings in parameters given by attacker. And it finally leads to a stack-based buffer overflow via access to crafted web page. This issue affects: Infraware ML Report 2.19.312.0000.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wfj-pw33-8cr3/GHSA-6wfj-pw33-8cr3.json b/advisories/unreviewed/2022/05/GHSA-6wfj-pw33-8cr3/GHSA-6wfj-pw33-8cr3.json index 1a48c914b3e..4e2f53c3585 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wfj-pw33-8cr3/GHSA-6wfj-pw33-8cr3.json +++ b/advisories/unreviewed/2022/05/GHSA-6wfj-pw33-8cr3/GHSA-6wfj-pw33-8cr3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wfr-fw6j-w5x5/GHSA-6wfr-fw6j-w5x5.json b/advisories/unreviewed/2022/05/GHSA-6wfr-fw6j-w5x5/GHSA-6wfr-fw6j-w5x5.json index 642c2ee2194..7d55f9500ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wfr-fw6j-w5x5/GHSA-6wfr-fw6j-w5x5.json +++ b/advisories/unreviewed/2022/05/GHSA-6wfr-fw6j-w5x5/GHSA-6wfr-fw6j-w5x5.json @@ -7,12 +7,8 @@ "CVE-2020-21378" ], "details": "SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xwv-85gf-vgjm/GHSA-6xwv-85gf-vgjm.json b/advisories/unreviewed/2022/05/GHSA-6xwv-85gf-vgjm/GHSA-6xwv-85gf-vgjm.json index 007d5fd0956..50fbca6ba75 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xwv-85gf-vgjm/GHSA-6xwv-85gf-vgjm.json +++ b/advisories/unreviewed/2022/05/GHSA-6xwv-85gf-vgjm/GHSA-6xwv-85gf-vgjm.json @@ -7,12 +7,8 @@ "CVE-2020-25191" ], "details": "Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that could reboot the CompactRIO (Driver versions prior to 20.5) remotely.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72m9-347j-m934/GHSA-72m9-347j-m934.json b/advisories/unreviewed/2022/05/GHSA-72m9-347j-m934/GHSA-72m9-347j-m934.json index 10cda2b1145..a90739682ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-72m9-347j-m934/GHSA-72m9-347j-m934.json +++ b/advisories/unreviewed/2022/05/GHSA-72m9-347j-m934/GHSA-72m9-347j-m934.json @@ -7,12 +7,8 @@ "CVE-2020-35815" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBK40 before 2.3.5.30, RBK40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72qv-726v-82fq/GHSA-72qv-726v-82fq.json b/advisories/unreviewed/2022/05/GHSA-72qv-726v-82fq/GHSA-72qv-726v-82fq.json index 0d51e5f2197..aeac67afd77 100644 --- a/advisories/unreviewed/2022/05/GHSA-72qv-726v-82fq/GHSA-72qv-726v-82fq.json +++ b/advisories/unreviewed/2022/05/GHSA-72qv-726v-82fq/GHSA-72qv-726v-82fq.json @@ -7,12 +7,8 @@ "CVE-2020-27713" ], "details": "In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server and the BIG-IP system receives a request with specific characteristics, the connection is reset and the Traffic Management Microkernel (TMM) leaks memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7374-8xfw-v758/GHSA-7374-8xfw-v758.json b/advisories/unreviewed/2022/05/GHSA-7374-8xfw-v758/GHSA-7374-8xfw-v758.json index 15017d95a04..65bd7895488 100644 --- a/advisories/unreviewed/2022/05/GHSA-7374-8xfw-v758/GHSA-7374-8xfw-v758.json +++ b/advisories/unreviewed/2022/05/GHSA-7374-8xfw-v758/GHSA-7374-8xfw-v758.json @@ -7,12 +7,8 @@ "CVE-2020-25757" ], "details": "A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with firmware 3.14 and 3.17.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7456-9w6m-v94r/GHSA-7456-9w6m-v94r.json b/advisories/unreviewed/2022/05/GHSA-7456-9w6m-v94r/GHSA-7456-9w6m-v94r.json index b7afd37ab06..0d4d29ae0b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7456-9w6m-v94r/GHSA-7456-9w6m-v94r.json +++ b/advisories/unreviewed/2022/05/GHSA-7456-9w6m-v94r/GHSA-7456-9w6m-v94r.json @@ -7,12 +7,8 @@ "CVE-2020-27721" ], "details": "In versions 16.0.0-16.0.0.1, 15.1.0-15.1.1, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, in a BIG-IP DNS / BIG-IP LTM GSLB deployment, under certain circumstances, the BIG-IP DNS system may stop using a BIG-IP LTM virtual server for DNS response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74m4-hfvx-8p4m/GHSA-74m4-hfvx-8p4m.json b/advisories/unreviewed/2022/05/GHSA-74m4-hfvx-8p4m/GHSA-74m4-hfvx-8p4m.json index 503bc75d608..c3eb794701e 100644 --- a/advisories/unreviewed/2022/05/GHSA-74m4-hfvx-8p4m/GHSA-74m4-hfvx-8p4m.json +++ b/advisories/unreviewed/2022/05/GHSA-74m4-hfvx-8p4m/GHSA-74m4-hfvx-8p4m.json @@ -7,12 +7,8 @@ "CVE-2020-35554" ], "details": "An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. There is a WebView SSL error-handler vulnerability. The LG ID is LVE-SMP-200026 (December 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74pw-fvg5-f337/GHSA-74pw-fvg5-f337.json b/advisories/unreviewed/2022/05/GHSA-74pw-fvg5-f337/GHSA-74pw-fvg5-f337.json index 1c5ef9a9cd7..76efecad2d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-74pw-fvg5-f337/GHSA-74pw-fvg5-f337.json +++ b/advisories/unreviewed/2022/05/GHSA-74pw-fvg5-f337/GHSA-74pw-fvg5-f337.json @@ -7,12 +7,8 @@ "CVE-2020-8938" ], "details": "An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to FromkLinuxSockAddr with attacker controlled content and size of klinux_addr which allows an attacker to write memory values from within the enclave. We recommend upgrading past commit a37fb6a0e7daf30134dbbf357c9a518a1026aa02", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7534-f3f3-w6x8/GHSA-7534-f3f3-w6x8.json b/advisories/unreviewed/2022/05/GHSA-7534-f3f3-w6x8/GHSA-7534-f3f3-w6x8.json index 24227b04f4c..c3b8de5f72f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7534-f3f3-w6x8/GHSA-7534-f3f3-w6x8.json +++ b/advisories/unreviewed/2022/05/GHSA-7534-f3f3-w6x8/GHSA-7534-f3f3-w6x8.json @@ -7,12 +7,8 @@ "CVE-2020-27716" ], "details": "On versions 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.5, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when a BIG-IP APM virtual server processes traffic of an undisclosed nature, the Traffic Management Microkernel (TMM) stops responding and restarts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77f7-r2cc-pcqm/GHSA-77f7-r2cc-pcqm.json b/advisories/unreviewed/2022/05/GHSA-77f7-r2cc-pcqm/GHSA-77f7-r2cc-pcqm.json index e71d6faa651..d5ffdf8802a 100644 --- a/advisories/unreviewed/2022/05/GHSA-77f7-r2cc-pcqm/GHSA-77f7-r2cc-pcqm.json +++ b/advisories/unreviewed/2022/05/GHSA-77f7-r2cc-pcqm/GHSA-77f7-r2cc-pcqm.json @@ -7,12 +7,8 @@ "CVE-2019-11785" ], "details": "Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77hx-2hff-m8j5/GHSA-77hx-2hff-m8j5.json b/advisories/unreviewed/2022/05/GHSA-77hx-2hff-m8j5/GHSA-77hx-2hff-m8j5.json index 344c9e2202f..767e9671cad 100644 --- a/advisories/unreviewed/2022/05/GHSA-77hx-2hff-m8j5/GHSA-77hx-2hff-m8j5.json +++ b/advisories/unreviewed/2022/05/GHSA-77hx-2hff-m8j5/GHSA-77hx-2hff-m8j5.json @@ -7,12 +7,8 @@ "CVE-2020-29589" ], "details": "Versions of the Official kapacitor Docker images through 1.5.0-alpine contain a blank password for the root user. Systems deployed using affected versions of the kapacitor container may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77mv-h93c-9885/GHSA-77mv-h93c-9885.json b/advisories/unreviewed/2022/05/GHSA-77mv-h93c-9885/GHSA-77mv-h93c-9885.json index 0485aab47d5..c37069734a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-77mv-h93c-9885/GHSA-77mv-h93c-9885.json +++ b/advisories/unreviewed/2022/05/GHSA-77mv-h93c-9885/GHSA-77mv-h93c-9885.json @@ -7,12 +7,8 @@ "CVE-2020-26569" ], "details": "In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M and below releases in the 4.21.x train; 4.22.7M and below releases in the 4.22.x train; 4.23.5M and below releases in the 4.23.x train; 4.24.2F and below releases in the 4.24.x train.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-784w-4q35-257w/GHSA-784w-4q35-257w.json b/advisories/unreviewed/2022/05/GHSA-784w-4q35-257w/GHSA-784w-4q35-257w.json index 8c01180dbf3..147f732b650 100644 --- a/advisories/unreviewed/2022/05/GHSA-784w-4q35-257w/GHSA-784w-4q35-257w.json +++ b/advisories/unreviewed/2022/05/GHSA-784w-4q35-257w/GHSA-784w-4q35-257w.json @@ -7,12 +7,8 @@ "CVE-2020-8461" ], "details": "A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7936-5qr9-9pvr/GHSA-7936-5qr9-9pvr.json b/advisories/unreviewed/2022/05/GHSA-7936-5qr9-9pvr/GHSA-7936-5qr9-9pvr.json index 7106413e800..10415ae8d86 100644 --- a/advisories/unreviewed/2022/05/GHSA-7936-5qr9-9pvr/GHSA-7936-5qr9-9pvr.json +++ b/advisories/unreviewed/2022/05/GHSA-7936-5qr9-9pvr/GHSA-7936-5qr9-9pvr.json @@ -7,12 +7,8 @@ "CVE-2020-0016" ], "details": "In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-171413483", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-796m-4rjr-9mvw/GHSA-796m-4rjr-9mvw.json b/advisories/unreviewed/2022/05/GHSA-796m-4rjr-9mvw/GHSA-796m-4rjr-9mvw.json index de8d568e329..59774830478 100644 --- a/advisories/unreviewed/2022/05/GHSA-796m-4rjr-9mvw/GHSA-796m-4rjr-9mvw.json +++ b/advisories/unreviewed/2022/05/GHSA-796m-4rjr-9mvw/GHSA-796m-4rjr-9mvw.json @@ -7,12 +7,8 @@ "CVE-2019-4738" ], "details": "IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79rf-9vhj-jq9w/GHSA-79rf-9vhj-jq9w.json b/advisories/unreviewed/2022/05/GHSA-79rf-9vhj-jq9w/GHSA-79rf-9vhj-jq9w.json index 67bceb72cab..9bf49685748 100644 --- a/advisories/unreviewed/2022/05/GHSA-79rf-9vhj-jq9w/GHSA-79rf-9vhj-jq9w.json +++ b/advisories/unreviewed/2022/05/GHSA-79rf-9vhj-jq9w/GHSA-79rf-9vhj-jq9w.json @@ -7,12 +7,8 @@ "CVE-2020-26407" ], "details": "A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79rv-cc85-5qhh/GHSA-79rv-cc85-5qhh.json b/advisories/unreviewed/2022/05/GHSA-79rv-cc85-5qhh/GHSA-79rv-cc85-5qhh.json index 9e973191247..2030ec3e5ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-79rv-cc85-5qhh/GHSA-79rv-cc85-5qhh.json +++ b/advisories/unreviewed/2022/05/GHSA-79rv-cc85-5qhh/GHSA-79rv-cc85-5qhh.json @@ -7,12 +7,8 @@ "CVE-2020-28187" ], "details": "Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to /tos/index.php?editor/fileGet, Event parameter to /include/ajax/logtable.php, or opt parameter to /include/core/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7cfx-r8g4-h73j/GHSA-7cfx-r8g4-h73j.json b/advisories/unreviewed/2022/05/GHSA-7cfx-r8g4-h73j/GHSA-7cfx-r8g4-h73j.json index 030a0925137..48793cc1e15 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cfx-r8g4-h73j/GHSA-7cfx-r8g4-h73j.json +++ b/advisories/unreviewed/2022/05/GHSA-7cfx-r8g4-h73j/GHSA-7cfx-r8g4-h73j.json @@ -7,12 +7,8 @@ "CVE-2020-8942" ], "details": "An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_read whose return size was not validated against the requrested size. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading past commit b1d120a2c7d7446d2cc58d517e20a1b184b82200", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f28-cgvx-h2cg/GHSA-7f28-cgvx-h2cg.json b/advisories/unreviewed/2022/05/GHSA-7f28-cgvx-h2cg/GHSA-7f28-cgvx-h2cg.json index d7b5244f91c..647a892bcf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f28-cgvx-h2cg/GHSA-7f28-cgvx-h2cg.json +++ b/advisories/unreviewed/2022/05/GHSA-7f28-cgvx-h2cg/GHSA-7f28-cgvx-h2cg.json @@ -7,12 +7,8 @@ "CVE-2020-26049" ], "details": "Nifty-PM CPE 2.3 is affected by stored HTML injection. The impact is remote arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f68-748r-v7xr/GHSA-7f68-748r-v7xr.json b/advisories/unreviewed/2022/05/GHSA-7f68-748r-v7xr/GHSA-7f68-748r-v7xr.json index 83e6c2c7222..e98137abb7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f68-748r-v7xr/GHSA-7f68-748r-v7xr.json +++ b/advisories/unreviewed/2022/05/GHSA-7f68-748r-v7xr/GHSA-7f68-748r-v7xr.json @@ -7,12 +7,8 @@ "CVE-2020-7536" ], "details": "A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3.4 BMXNOE0110 (H) versions prior to V6.6 BMXNOR0200H all versions), that could cause the device to be unreachable when modifying network parameters over SNMP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7fcf-g7ph-3mf3/GHSA-7fcf-g7ph-3mf3.json b/advisories/unreviewed/2022/05/GHSA-7fcf-g7ph-3mf3/GHSA-7fcf-g7ph-3mf3.json index 2f037292ee7..802b80442b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7fcf-g7ph-3mf3/GHSA-7fcf-g7ph-3mf3.json +++ b/advisories/unreviewed/2022/05/GHSA-7fcf-g7ph-3mf3/GHSA-7fcf-g7ph-3mf3.json @@ -7,12 +7,8 @@ "CVE-2020-35122" ], "details": "An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g47-vmvw-jcc2/GHSA-7g47-vmvw-jcc2.json b/advisories/unreviewed/2022/05/GHSA-7g47-vmvw-jcc2/GHSA-7g47-vmvw-jcc2.json index 551cf7af168..7858befa9e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g47-vmvw-jcc2/GHSA-7g47-vmvw-jcc2.json +++ b/advisories/unreviewed/2022/05/GHSA-7g47-vmvw-jcc2/GHSA-7g47-vmvw-jcc2.json @@ -7,12 +7,8 @@ "CVE-2020-13985" ], "details": "An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rpl_remove_header in net/rpl/rpl-ext-header.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7ghp-chhf-mv7g/GHSA-7ghp-chhf-mv7g.json b/advisories/unreviewed/2022/05/GHSA-7ghp-chhf-mv7g/GHSA-7ghp-chhf-mv7g.json index bae3d9b7c06..2b622bfcde3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7ghp-chhf-mv7g/GHSA-7ghp-chhf-mv7g.json +++ b/advisories/unreviewed/2022/05/GHSA-7ghp-chhf-mv7g/GHSA-7ghp-chhf-mv7g.json @@ -7,12 +7,8 @@ "CVE-2020-4907" ], "details": "IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gxp-4wg5-p23f/GHSA-7gxp-4wg5-p23f.json b/advisories/unreviewed/2022/05/GHSA-7gxp-4wg5-p23f/GHSA-7gxp-4wg5-p23f.json index 4fe20329bfc..e5e5e30f14a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gxp-4wg5-p23f/GHSA-7gxp-4wg5-p23f.json +++ b/advisories/unreviewed/2022/05/GHSA-7gxp-4wg5-p23f/GHSA-7gxp-4wg5-p23f.json @@ -7,12 +7,8 @@ "CVE-2020-2493" ], "details": "This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in Multimedia Console 1.1.5 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7jmj-qp68-j8hc/GHSA-7jmj-qp68-j8hc.json b/advisories/unreviewed/2022/05/GHSA-7jmj-qp68-j8hc/GHSA-7jmj-qp68-j8hc.json index 12539e07c9a..4b74fa035f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jmj-qp68-j8hc/GHSA-7jmj-qp68-j8hc.json +++ b/advisories/unreviewed/2022/05/GHSA-7jmj-qp68-j8hc/GHSA-7jmj-qp68-j8hc.json @@ -7,12 +7,8 @@ "CVE-2020-27714" ], "details": "On the BIG-IP AFM version 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when a Protocol Inspection Profile is attached to a FastL4 virtual server with the protocol field configured to either Other or All Protocols, the TMM may experience a restart if the profile processes non-TCP traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7m7p-mm4f-j6g6/GHSA-7m7p-mm4f-j6g6.json b/advisories/unreviewed/2022/05/GHSA-7m7p-mm4f-j6g6/GHSA-7m7p-mm4f-j6g6.json index 1aafa985b26..92a9d449bfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m7p-mm4f-j6g6/GHSA-7m7p-mm4f-j6g6.json +++ b/advisories/unreviewed/2022/05/GHSA-7m7p-mm4f-j6g6/GHSA-7m7p-mm4f-j6g6.json @@ -7,12 +7,8 @@ "CVE-2020-35462" ], "details": "Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the CoScale agent container may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7p3q-gmw8-3xm9/GHSA-7p3q-gmw8-3xm9.json b/advisories/unreviewed/2022/05/GHSA-7p3q-gmw8-3xm9/GHSA-7p3q-gmw8-3xm9.json index b646cd65cd5..c658962e89e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p3q-gmw8-3xm9/GHSA-7p3q-gmw8-3xm9.json +++ b/advisories/unreviewed/2022/05/GHSA-7p3q-gmw8-3xm9/GHSA-7p3q-gmw8-3xm9.json @@ -7,12 +7,8 @@ "CVE-2020-29203" ], "details": "struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7q5m-m6v8-m536/GHSA-7q5m-m6v8-m536.json b/advisories/unreviewed/2022/05/GHSA-7q5m-m6v8-m536/GHSA-7q5m-m6v8-m536.json index 99ef286473e..f3e42a921d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q5m-m6v8-m536/GHSA-7q5m-m6v8-m536.json +++ b/advisories/unreviewed/2022/05/GHSA-7q5m-m6v8-m536/GHSA-7q5m-m6v8-m536.json @@ -7,12 +7,8 @@ "CVE-2020-28860" ], "details": "OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qj9-8gv5-jxwm/GHSA-7qj9-8gv5-jxwm.json b/advisories/unreviewed/2022/05/GHSA-7qj9-8gv5-jxwm/GHSA-7qj9-8gv5-jxwm.json index 4070abca9d5..ee9a73b0f6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qj9-8gv5-jxwm/GHSA-7qj9-8gv5-jxwm.json +++ b/advisories/unreviewed/2022/05/GHSA-7qj9-8gv5-jxwm/GHSA-7qj9-8gv5-jxwm.json @@ -7,12 +7,8 @@ "CVE-2020-35467" ], "details": "The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vpr-695p-h2h2/GHSA-7vpr-695p-h2h2.json b/advisories/unreviewed/2022/05/GHSA-7vpr-695p-h2h2/GHSA-7vpr-695p-h2h2.json index a12c8737f83..7ad83702b03 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vpr-695p-h2h2/GHSA-7vpr-695p-h2h2.json +++ b/advisories/unreviewed/2022/05/GHSA-7vpr-695p-h2h2/GHSA-7vpr-695p-h2h2.json @@ -7,12 +7,8 @@ "CVE-2020-27727" ], "details": "On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system does not sufficiently validate user input, allowing the user read access to the filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vq3-23jw-jjmm/GHSA-7vq3-23jw-jjmm.json b/advisories/unreviewed/2022/05/GHSA-7vq3-23jw-jjmm/GHSA-7vq3-23jw-jjmm.json index f3668f6edb2..f171bc6f6ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vq3-23jw-jjmm/GHSA-7vq3-23jw-jjmm.json +++ b/advisories/unreviewed/2022/05/GHSA-7vq3-23jw-jjmm/GHSA-7vq3-23jw-jjmm.json @@ -7,12 +7,8 @@ "CVE-2020-5359" ], "details": "Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to modify and corrupt the encrypted data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7w35-wqxc-h6cq/GHSA-7w35-wqxc-h6cq.json b/advisories/unreviewed/2022/05/GHSA-7w35-wqxc-h6cq/GHSA-7w35-wqxc-h6cq.json index d50d91d794e..3f6ba551edb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w35-wqxc-h6cq/GHSA-7w35-wqxc-h6cq.json +++ b/advisories/unreviewed/2022/05/GHSA-7w35-wqxc-h6cq/GHSA-7w35-wqxc-h6cq.json @@ -7,12 +7,8 @@ "CVE-2020-35396" ], "details": "EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wgm-v99f-436j/GHSA-7wgm-v99f-436j.json b/advisories/unreviewed/2022/05/GHSA-7wgm-v99f-436j/GHSA-7wgm-v99f-436j.json index 26e644f1d29..fb0d481db0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wgm-v99f-436j/GHSA-7wgm-v99f-436j.json +++ b/advisories/unreviewed/2022/05/GHSA-7wgm-v99f-436j/GHSA-7wgm-v99f-436j.json @@ -7,12 +7,8 @@ "CVE-2020-26030" ], "details": "An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7xq7-m3j7-j4px/GHSA-7xq7-m3j7-j4px.json b/advisories/unreviewed/2022/05/GHSA-7xq7-m3j7-j4px/GHSA-7xq7-m3j7-j4px.json index 64b1a86b5f7..d78a120aefd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xq7-m3j7-j4px/GHSA-7xq7-m3j7-j4px.json +++ b/advisories/unreviewed/2022/05/GHSA-7xq7-m3j7-j4px/GHSA-7xq7-m3j7-j4px.json @@ -7,12 +7,8 @@ "CVE-2020-27508" ], "details": "In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82gg-xqxc-f2wx/GHSA-82gg-xqxc-f2wx.json b/advisories/unreviewed/2022/05/GHSA-82gg-xqxc-f2wx/GHSA-82gg-xqxc-f2wx.json index 68918364bf7..926fdca10b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-82gg-xqxc-f2wx/GHSA-82gg-xqxc-f2wx.json +++ b/advisories/unreviewed/2022/05/GHSA-82gg-xqxc-f2wx/GHSA-82gg-xqxc-f2wx.json @@ -7,12 +7,8 @@ "CVE-2020-29666" ], "details": "In Lan ATMService M3 ATM Monitoring System 6.1.0, due to a directory-listing vulnerability, a remote attacker can view log files, located in /websocket/logs/, that contain a user's cookie values and the predefined developer's cookie value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-84vg-rpfp-p469/GHSA-84vg-rpfp-p469.json b/advisories/unreviewed/2022/05/GHSA-84vg-rpfp-p469/GHSA-84vg-rpfp-p469.json index 5bcda5c0510..e97daea2dfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-84vg-rpfp-p469/GHSA-84vg-rpfp-p469.json +++ b/advisories/unreviewed/2022/05/GHSA-84vg-rpfp-p469/GHSA-84vg-rpfp-p469.json @@ -7,12 +7,8 @@ "CVE-2020-25495" ], "details": "A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86w2-3m2v-xrcg/GHSA-86w2-3m2v-xrcg.json b/advisories/unreviewed/2022/05/GHSA-86w2-3m2v-xrcg/GHSA-86w2-3m2v-xrcg.json index da273c35ac7..99f9d8b05d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-86w2-3m2v-xrcg/GHSA-86w2-3m2v-xrcg.json +++ b/advisories/unreviewed/2022/05/GHSA-86w2-3m2v-xrcg/GHSA-86w2-3m2v-xrcg.json @@ -7,12 +7,8 @@ "CVE-2020-27154" ], "details": "The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. A successful exploit could allow an attacker to view the user information and application data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87f8-vqm8-p8wc/GHSA-87f8-vqm8-p8wc.json b/advisories/unreviewed/2022/05/GHSA-87f8-vqm8-p8wc/GHSA-87f8-vqm8-p8wc.json index fee7e4b4f81..492f82ef5c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-87f8-vqm8-p8wc/GHSA-87f8-vqm8-p8wc.json +++ b/advisories/unreviewed/2022/05/GHSA-87f8-vqm8-p8wc/GHSA-87f8-vqm8-p8wc.json @@ -7,12 +7,8 @@ "CVE-2020-25967" ], "details": "The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87vv-9cj6-q2hc/GHSA-87vv-9cj6-q2hc.json b/advisories/unreviewed/2022/05/GHSA-87vv-9cj6-q2hc/GHSA-87vv-9cj6-q2hc.json index 1635a836557..f45c23e9e70 100644 --- a/advisories/unreviewed/2022/05/GHSA-87vv-9cj6-q2hc/GHSA-87vv-9cj6-q2hc.json +++ b/advisories/unreviewed/2022/05/GHSA-87vv-9cj6-q2hc/GHSA-87vv-9cj6-q2hc.json @@ -7,12 +7,8 @@ "CVE-2020-5684" ], "details": "iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8845-33mf-9363/GHSA-8845-33mf-9363.json b/advisories/unreviewed/2022/05/GHSA-8845-33mf-9363/GHSA-8845-33mf-9363.json index b57d28e279c..923a36f1f3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8845-33mf-9363/GHSA-8845-33mf-9363.json +++ b/advisories/unreviewed/2022/05/GHSA-8845-33mf-9363/GHSA-8845-33mf-9363.json @@ -7,12 +7,8 @@ "CVE-2020-35347" ], "details": "CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8873-3662-5rmv/GHSA-8873-3662-5rmv.json b/advisories/unreviewed/2022/05/GHSA-8873-3662-5rmv/GHSA-8873-3662-5rmv.json index 081b8993f89..cefd61011fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-8873-3662-5rmv/GHSA-8873-3662-5rmv.json +++ b/advisories/unreviewed/2022/05/GHSA-8873-3662-5rmv/GHSA-8873-3662-5rmv.json @@ -7,12 +7,8 @@ "CVE-2020-20142" ], "details": "Cross Site Scripting (XSS) vulnerability in the \"To Remote CSV\" component under \"Open\" Menu in Flexmonster Pivot Table & Charts 2.7.17.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-895q-vqrm-2jch/GHSA-895q-vqrm-2jch.json b/advisories/unreviewed/2022/05/GHSA-895q-vqrm-2jch/GHSA-895q-vqrm-2jch.json index 9c32d296753..867f4a87e4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-895q-vqrm-2jch/GHSA-895q-vqrm-2jch.json +++ b/advisories/unreviewed/2022/05/GHSA-895q-vqrm-2jch/GHSA-895q-vqrm-2jch.json @@ -7,12 +7,8 @@ "CVE-2020-24674" ], "details": "In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89jc-hqfc-w5xg/GHSA-89jc-hqfc-w5xg.json b/advisories/unreviewed/2022/05/GHSA-89jc-hqfc-w5xg/GHSA-89jc-hqfc-w5xg.json index d092eb64f62..80956882697 100644 --- a/advisories/unreviewed/2022/05/GHSA-89jc-hqfc-w5xg/GHSA-89jc-hqfc-w5xg.json +++ b/advisories/unreviewed/2022/05/GHSA-89jc-hqfc-w5xg/GHSA-89jc-hqfc-w5xg.json @@ -7,12 +7,8 @@ "CVE-2020-8282" ], "details": "A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cmf-w78x-mr9c/GHSA-8cmf-w78x-mr9c.json b/advisories/unreviewed/2022/05/GHSA-8cmf-w78x-mr9c/GHSA-8cmf-w78x-mr9c.json index c4f4d076aad..7b3c090d884 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cmf-w78x-mr9c/GHSA-8cmf-w78x-mr9c.json +++ b/advisories/unreviewed/2022/05/GHSA-8cmf-w78x-mr9c/GHSA-8cmf-w78x-mr9c.json @@ -7,12 +7,8 @@ "CVE-2020-27337" ], "details": "An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthenticated remote attacker to cause an Out of Bounds Write, and possibly a Denial of Service via network access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8fr7-g775-588h/GHSA-8fr7-g775-588h.json b/advisories/unreviewed/2022/05/GHSA-8fr7-g775-588h/GHSA-8fr7-g775-588h.json index 7660001926a..2702a2f4561 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fr7-g775-588h/GHSA-8fr7-g775-588h.json +++ b/advisories/unreviewed/2022/05/GHSA-8fr7-g775-588h/GHSA-8fr7-g775-588h.json @@ -7,12 +7,8 @@ "CVE-2019-16955" ], "details": "SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g6h-grf2-7grg/GHSA-8g6h-grf2-7grg.json b/advisories/unreviewed/2022/05/GHSA-8g6h-grf2-7grg/GHSA-8g6h-grf2-7grg.json index ab2c112491f..1d8082f91f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g6h-grf2-7grg/GHSA-8g6h-grf2-7grg.json +++ b/advisories/unreviewed/2022/05/GHSA-8g6h-grf2-7grg/GHSA-8g6h-grf2-7grg.json @@ -7,12 +7,8 @@ "CVE-2020-24675" ], "details": "In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gq9-69qw-7cch/GHSA-8gq9-69qw-7cch.json b/advisories/unreviewed/2022/05/GHSA-8gq9-69qw-7cch/GHSA-8gq9-69qw-7cch.json index 93292c5982c..034b7ee5aa8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gq9-69qw-7cch/GHSA-8gq9-69qw-7cch.json +++ b/advisories/unreviewed/2022/05/GHSA-8gq9-69qw-7cch/GHSA-8gq9-69qw-7cch.json @@ -7,12 +7,8 @@ "CVE-2020-8940" ], "details": "An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvmsg using an attacker controlled result parameter. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading or past commit fa6485c5d16a7355eab047d4a44345a73bc9131e", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hgw-v95f-3rr5/GHSA-8hgw-v95f-3rr5.json b/advisories/unreviewed/2022/05/GHSA-8hgw-v95f-3rr5/GHSA-8hgw-v95f-3rr5.json index 7e870c189ce..65cc2b7f930 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hgw-v95f-3rr5/GHSA-8hgw-v95f-3rr5.json +++ b/advisories/unreviewed/2022/05/GHSA-8hgw-v95f-3rr5/GHSA-8hgw-v95f-3rr5.json @@ -7,12 +7,8 @@ "CVE-2020-0459" ], "details": "In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configuration data due to a missing permission check. This could lead to local information disclosure of WiFi network names with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-159373687", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8j5p-76rr-8r3x/GHSA-8j5p-76rr-8r3x.json b/advisories/unreviewed/2022/05/GHSA-8j5p-76rr-8r3x/GHSA-8j5p-76rr-8r3x.json index fda4f3beccf..adcbdbe5599 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j5p-76rr-8r3x/GHSA-8j5p-76rr-8r3x.json +++ b/advisories/unreviewed/2022/05/GHSA-8j5p-76rr-8r3x/GHSA-8j5p-76rr-8r3x.json @@ -7,12 +7,8 @@ "CVE-2020-29474" ], "details": "EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jw9-px85-866f/GHSA-8jw9-px85-866f.json b/advisories/unreviewed/2022/05/GHSA-8jw9-px85-866f/GHSA-8jw9-px85-866f.json index 358e07b3015..528a1662f4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jw9-px85-866f/GHSA-8jw9-px85-866f.json +++ b/advisories/unreviewed/2022/05/GHSA-8jw9-px85-866f/GHSA-8jw9-px85-866f.json @@ -7,12 +7,8 @@ "CVE-2020-0463" ], "details": "In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Android-8.1 Android-9Android ID: A-169342531", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mc7-p65m-96vq/GHSA-8mc7-p65m-96vq.json b/advisories/unreviewed/2022/05/GHSA-8mc7-p65m-96vq/GHSA-8mc7-p65m-96vq.json index 812b504cfb8..7e404ff5657 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mc7-p65m-96vq/GHSA-8mc7-p65m-96vq.json +++ b/advisories/unreviewed/2022/05/GHSA-8mc7-p65m-96vq/GHSA-8mc7-p65m-96vq.json @@ -7,12 +7,8 @@ "CVE-2020-15733" ], "details": "An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus Plus versions prior to 25.0.7.29.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mgg-4h42-8rj6/GHSA-8mgg-4h42-8rj6.json b/advisories/unreviewed/2022/05/GHSA-8mgg-4h42-8rj6/GHSA-8mgg-4h42-8rj6.json index 7fb39efda59..2c98be59a8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mgg-4h42-8rj6/GHSA-8mgg-4h42-8rj6.json +++ b/advisories/unreviewed/2022/05/GHSA-8mgg-4h42-8rj6/GHSA-8mgg-4h42-8rj6.json @@ -7,12 +7,8 @@ "CVE-2020-8939" ], "details": "An out of bounds read on the enc_untrusted_inet_ntop function allows an attack to extend the result size that is used by memcpy() to read memory from within the enclave heap. We recommend upgrading past commit 6ff3b77ffe110a33a2f93848a6333f33616f02c4", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pw4-5frf-g53c/GHSA-8pw4-5frf-g53c.json b/advisories/unreviewed/2022/05/GHSA-8pw4-5frf-g53c/GHSA-8pw4-5frf-g53c.json index 38d5aa19fff..4b80a9fc9cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pw4-5frf-g53c/GHSA-8pw4-5frf-g53c.json +++ b/advisories/unreviewed/2022/05/GHSA-8pw4-5frf-g53c/GHSA-8pw4-5frf-g53c.json @@ -7,12 +7,8 @@ "CVE-2020-35269" ], "details": "There is a Cross Site Request Forgery (CSRF) vulnerability in Nagios Core 4.2.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q2c-xwcr-7mj4/GHSA-8q2c-xwcr-7mj4.json b/advisories/unreviewed/2022/05/GHSA-8q2c-xwcr-7mj4/GHSA-8q2c-xwcr-7mj4.json index 844f793bf00..a54234c1cf4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q2c-xwcr-7mj4/GHSA-8q2c-xwcr-7mj4.json +++ b/advisories/unreviewed/2022/05/GHSA-8q2c-xwcr-7mj4/GHSA-8q2c-xwcr-7mj4.json @@ -7,12 +7,8 @@ "CVE-2020-25847" ], "details": "This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qww-xfxc-2wmf/GHSA-8qww-xfxc-2wmf.json b/advisories/unreviewed/2022/05/GHSA-8qww-xfxc-2wmf/GHSA-8qww-xfxc-2wmf.json index a104ae81e1a..4bb6a25f869 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qww-xfxc-2wmf/GHSA-8qww-xfxc-2wmf.json +++ b/advisories/unreviewed/2022/05/GHSA-8qww-xfxc-2wmf/GHSA-8qww-xfxc-2wmf.json @@ -7,12 +7,8 @@ "CVE-2019-11781" ], "details": "Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8r9p-9pp7-xxpc/GHSA-8r9p-9pp7-xxpc.json b/advisories/unreviewed/2022/05/GHSA-8r9p-9pp7-xxpc/GHSA-8r9p-9pp7-xxpc.json index a3ce8d1bbd0..254fb6f4aa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r9p-9pp7-xxpc/GHSA-8r9p-9pp7-xxpc.json +++ b/advisories/unreviewed/2022/05/GHSA-8r9p-9pp7-xxpc/GHSA-8r9p-9pp7-xxpc.json @@ -7,12 +7,8 @@ "CVE-2020-35713" ], "details": "Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rmg-c6qw-6rm2/GHSA-8rmg-c6qw-6rm2.json b/advisories/unreviewed/2022/05/GHSA-8rmg-c6qw-6rm2/GHSA-8rmg-c6qw-6rm2.json index dcb86759fd0..a5a20d8f8a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rmg-c6qw-6rm2/GHSA-8rmg-c6qw-6rm2.json +++ b/advisories/unreviewed/2022/05/GHSA-8rmg-c6qw-6rm2/GHSA-8rmg-c6qw-6rm2.json @@ -7,12 +7,8 @@ "CVE-2020-14270" ], "details": "HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages software running on the Domino server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rpm-95xj-h65p/GHSA-8rpm-95xj-h65p.json b/advisories/unreviewed/2022/05/GHSA-8rpm-95xj-h65p/GHSA-8rpm-95xj-h65p.json index 64521e03e5f..68a467b6d0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rpm-95xj-h65p/GHSA-8rpm-95xj-h65p.json +++ b/advisories/unreviewed/2022/05/GHSA-8rpm-95xj-h65p/GHSA-8rpm-95xj-h65p.json @@ -7,12 +7,8 @@ "CVE-2020-27056" ], "details": "In SELinux policies of mls, there is a missing permission check. This could lead to local information disclosure of package metadata with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-161356067", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vgr-w2rm-8hjx/GHSA-8vgr-w2rm-8hjx.json b/advisories/unreviewed/2022/05/GHSA-8vgr-w2rm-8hjx/GHSA-8vgr-w2rm-8hjx.json index 5e403ba9445..59dbcf1ae38 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vgr-w2rm-8hjx/GHSA-8vgr-w2rm-8hjx.json +++ b/advisories/unreviewed/2022/05/GHSA-8vgr-w2rm-8hjx/GHSA-8vgr-w2rm-8hjx.json @@ -7,12 +7,8 @@ "CVE-2020-24633" ], "details": "There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vhf-89h2-fwh8/GHSA-8vhf-89h2-fwh8.json b/advisories/unreviewed/2022/05/GHSA-8vhf-89h2-fwh8/GHSA-8vhf-89h2-fwh8.json index 6e328d7378b..e872526c723 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vhf-89h2-fwh8/GHSA-8vhf-89h2-fwh8.json +++ b/advisories/unreviewed/2022/05/GHSA-8vhf-89h2-fwh8/GHSA-8vhf-89h2-fwh8.json @@ -7,12 +7,8 @@ "CVE-2020-28190" ], "details": "TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attackers are able to intercept these requests and serve a weaponized/infected version of applications or updates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8w64-jvqw-g3qx/GHSA-8w64-jvqw-g3qx.json b/advisories/unreviewed/2022/05/GHSA-8w64-jvqw-g3qx/GHSA-8w64-jvqw-g3qx.json index 448d6e78651..74bdb9bb15e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w64-jvqw-g3qx/GHSA-8w64-jvqw-g3qx.json +++ b/advisories/unreviewed/2022/05/GHSA-8w64-jvqw-g3qx/GHSA-8w64-jvqw-g3qx.json @@ -7,12 +7,8 @@ "CVE-2020-35611" ], "details": "An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xph-6v8f-88rf/GHSA-8xph-6v8f-88rf.json b/advisories/unreviewed/2022/05/GHSA-8xph-6v8f-88rf/GHSA-8xph-6v8f-88rf.json index 806059fd4ff..1869f3b05b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xph-6v8f-88rf/GHSA-8xph-6v8f-88rf.json +++ b/advisories/unreviewed/2022/05/GHSA-8xph-6v8f-88rf/GHSA-8xph-6v8f-88rf.json @@ -7,12 +7,8 @@ "CVE-2020-35783" ], "details": "Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, GS116Ev2 before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and JGS524PE before 2.6.0.48.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xr7-5cxh-6x35/GHSA-8xr7-5cxh-6x35.json b/advisories/unreviewed/2022/05/GHSA-8xr7-5cxh-6x35/GHSA-8xr7-5cxh-6x35.json index f87ad91c3f3..ea08166ad37 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xr7-5cxh-6x35/GHSA-8xr7-5cxh-6x35.json +++ b/advisories/unreviewed/2022/05/GHSA-8xr7-5cxh-6x35/GHSA-8xr7-5cxh-6x35.json @@ -7,12 +7,8 @@ "CVE-2020-35609" ], "details": "A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xrx-q7v8-89j4/GHSA-8xrx-q7v8-89j4.json b/advisories/unreviewed/2022/05/GHSA-8xrx-q7v8-89j4/GHSA-8xrx-q7v8-89j4.json index cce6745148f..8315d08ea12 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xrx-q7v8-89j4/GHSA-8xrx-q7v8-89j4.json +++ b/advisories/unreviewed/2022/05/GHSA-8xrx-q7v8-89j4/GHSA-8xrx-q7v8-89j4.json @@ -7,12 +7,8 @@ "CVE-2020-15376" ], "details": "Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with \"user\" privileges if it is not associated with any groups.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92h4-jh72-6gpm/GHSA-92h4-jh72-6gpm.json b/advisories/unreviewed/2022/05/GHSA-92h4-jh72-6gpm/GHSA-92h4-jh72-6gpm.json index 1725365ae88..0ac9f7519b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-92h4-jh72-6gpm/GHSA-92h4-jh72-6gpm.json +++ b/advisories/unreviewed/2022/05/GHSA-92h4-jh72-6gpm/GHSA-92h4-jh72-6gpm.json @@ -7,12 +7,8 @@ "CVE-2020-35273" ], "details": "EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92w6-8752-jf23/GHSA-92w6-8752-jf23.json b/advisories/unreviewed/2022/05/GHSA-92w6-8752-jf23/GHSA-92w6-8752-jf23.json index bc1ed942f88..b2f323c6918 100644 --- a/advisories/unreviewed/2022/05/GHSA-92w6-8752-jf23/GHSA-92w6-8752-jf23.json +++ b/advisories/unreviewed/2022/05/GHSA-92w6-8752-jf23/GHSA-92w6-8752-jf23.json @@ -7,12 +7,8 @@ "CVE-2020-27035" ], "details": "In priorLinearAllocation of C2AllocatorIon.cpp, there is a possible use-after-free due to improper locking. This could lead to local information disclosure in the media codec with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-152239213", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93gx-49qx-8f59/GHSA-93gx-49qx-8f59.json b/advisories/unreviewed/2022/05/GHSA-93gx-49qx-8f59/GHSA-93gx-49qx-8f59.json index 381f3482f31..918f363ef6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-93gx-49qx-8f59/GHSA-93gx-49qx-8f59.json +++ b/advisories/unreviewed/2022/05/GHSA-93gx-49qx-8f59/GHSA-93gx-49qx-8f59.json @@ -7,12 +7,8 @@ "CVE-2020-25712" ], "details": "A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94rj-frv4-2p83/GHSA-94rj-frv4-2p83.json b/advisories/unreviewed/2022/05/GHSA-94rj-frv4-2p83/GHSA-94rj-frv4-2p83.json index 92bc36bf95a..be88ccae576 100644 --- a/advisories/unreviewed/2022/05/GHSA-94rj-frv4-2p83/GHSA-94rj-frv4-2p83.json +++ b/advisories/unreviewed/2022/05/GHSA-94rj-frv4-2p83/GHSA-94rj-frv4-2p83.json @@ -7,12 +7,8 @@ "CVE-2020-27038" ], "details": "In process of C2SoftVorbisDec.cpp, there is a possible resource exhaustion due to a memory leak. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154302257", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-956h-2q87-xrpg/GHSA-956h-2q87-xrpg.json b/advisories/unreviewed/2022/05/GHSA-956h-2q87-xrpg/GHSA-956h-2q87-xrpg.json index aa6d34adb7c..22ba75464cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-956h-2q87-xrpg/GHSA-956h-2q87-xrpg.json +++ b/advisories/unreviewed/2022/05/GHSA-956h-2q87-xrpg/GHSA-956h-2q87-xrpg.json @@ -7,12 +7,8 @@ "CVE-2020-27055" ], "details": "In isSubmittable and showWarningMessagesIfAppropriate of WifiConfigController.java and WifiConfigController2.java, there is a possible insecure WiFi configuration due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-161378819", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9666-j9h2-4p66/GHSA-9666-j9h2-4p66.json b/advisories/unreviewed/2022/05/GHSA-9666-j9h2-4p66/GHSA-9666-j9h2-4p66.json index a4136f8be5a..2a90736a1ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-9666-j9h2-4p66/GHSA-9666-j9h2-4p66.json +++ b/advisories/unreviewed/2022/05/GHSA-9666-j9h2-4p66/GHSA-9666-j9h2-4p66.json @@ -7,12 +7,8 @@ "CVE-2020-7200" ], "details": "A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-96p2-7r8j-8q3m/GHSA-96p2-7r8j-8q3m.json b/advisories/unreviewed/2022/05/GHSA-96p2-7r8j-8q3m/GHSA-96p2-7r8j-8q3m.json index 78e5ce3ee99..0c9c6ac5f3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-96p2-7r8j-8q3m/GHSA-96p2-7r8j-8q3m.json +++ b/advisories/unreviewed/2022/05/GHSA-96p2-7r8j-8q3m/GHSA-96p2-7r8j-8q3m.json @@ -7,12 +7,8 @@ "CVE-2020-0019" ], "details": "In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-171413798", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-96qj-2mm8-v8xv/GHSA-96qj-2mm8-v8xv.json b/advisories/unreviewed/2022/05/GHSA-96qj-2mm8-v8xv/GHSA-96qj-2mm8-v8xv.json index 322cc61ac0c..a96ae4713f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-96qj-2mm8-v8xv/GHSA-96qj-2mm8-v8xv.json +++ b/advisories/unreviewed/2022/05/GHSA-96qj-2mm8-v8xv/GHSA-96qj-2mm8-v8xv.json @@ -7,12 +7,8 @@ "CVE-2020-4905" ], "details": "IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote attacker to obtain sensitive information, caused by a man in the middle attack. By SSL striping, an attacker could exploit this vulnerability to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9724-33jf-7mj5/GHSA-9724-33jf-7mj5.json b/advisories/unreviewed/2022/05/GHSA-9724-33jf-7mj5/GHSA-9724-33jf-7mj5.json index 04362ef85f6..63bce5a1125 100644 --- a/advisories/unreviewed/2022/05/GHSA-9724-33jf-7mj5/GHSA-9724-33jf-7mj5.json +++ b/advisories/unreviewed/2022/05/GHSA-9724-33jf-7mj5/GHSA-9724-33jf-7mj5.json @@ -7,12 +7,8 @@ "CVE-2020-35186" ], "details": "The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-993c-4hx4-cg4r/GHSA-993c-4hx4-cg4r.json b/advisories/unreviewed/2022/05/GHSA-993c-4hx4-cg4r/GHSA-993c-4hx4-cg4r.json index a0279d90eb3..51cc5e6b257 100644 --- a/advisories/unreviewed/2022/05/GHSA-993c-4hx4-cg4r/GHSA-993c-4hx4-cg4r.json +++ b/advisories/unreviewed/2022/05/GHSA-993c-4hx4-cg4r/GHSA-993c-4hx4-cg4r.json @@ -7,12 +7,8 @@ "CVE-2020-27645" ], "details": "The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\\1E\\Client\\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9c3c-p8mj-7wvw/GHSA-9c3c-p8mj-7wvw.json b/advisories/unreviewed/2022/05/GHSA-9c3c-p8mj-7wvw/GHSA-9c3c-p8mj-7wvw.json index 2d27fe635bc..2fd11e709d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c3c-p8mj-7wvw/GHSA-9c3c-p8mj-7wvw.json +++ b/advisories/unreviewed/2022/05/GHSA-9c3c-p8mj-7wvw/GHSA-9c3c-p8mj-7wvw.json @@ -7,12 +7,8 @@ "CVE-2020-35709" ], "details": "bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with \"Content-Type: application/octet-stream\") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cfc-7fpm-w3g9/GHSA-9cfc-7fpm-w3g9.json b/advisories/unreviewed/2022/05/GHSA-9cfc-7fpm-w3g9/GHSA-9cfc-7fpm-w3g9.json index 439735134f9..bedcf0a27d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cfc-7fpm-w3g9/GHSA-9cfc-7fpm-w3g9.json +++ b/advisories/unreviewed/2022/05/GHSA-9cfc-7fpm-w3g9/GHSA-9cfc-7fpm-w3g9.json @@ -7,12 +7,8 @@ "CVE-2020-35192" ], "details": "The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cr8-cgwr-97w6/GHSA-9cr8-cgwr-97w6.json b/advisories/unreviewed/2022/05/GHSA-9cr8-cgwr-97w6/GHSA-9cr8-cgwr-97w6.json index 0d2956391d5..e312e4d04be 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cr8-cgwr-97w6/GHSA-9cr8-cgwr-97w6.json +++ b/advisories/unreviewed/2022/05/GHSA-9cr8-cgwr-97w6/GHSA-9cr8-cgwr-97w6.json @@ -7,12 +7,8 @@ "CVE-2020-35705" ], "details": "Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f46-jqh2-hfhm/GHSA-9f46-jqh2-hfhm.json b/advisories/unreviewed/2022/05/GHSA-9f46-jqh2-hfhm/GHSA-9f46-jqh2-hfhm.json index 6d5bffee8fa..e78d47b4580 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f46-jqh2-hfhm/GHSA-9f46-jqh2-hfhm.json +++ b/advisories/unreviewed/2022/05/GHSA-9f46-jqh2-hfhm/GHSA-9f46-jqh2-hfhm.json @@ -7,12 +7,8 @@ "CVE-2020-20139" ], "details": "Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9ggp-g58q-5q4w/GHSA-9ggp-g58q-5q4w.json b/advisories/unreviewed/2022/05/GHSA-9ggp-g58q-5q4w/GHSA-9ggp-g58q-5q4w.json index 00c8a432634..cf66480ef6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9ggp-g58q-5q4w/GHSA-9ggp-g58q-5q4w.json +++ b/advisories/unreviewed/2022/05/GHSA-9ggp-g58q-5q4w/GHSA-9ggp-g58q-5q4w.json @@ -7,12 +7,8 @@ "CVE-2020-28215" ], "details": "A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9h3q-pjrc-xc8x/GHSA-9h3q-pjrc-xc8x.json b/advisories/unreviewed/2022/05/GHSA-9h3q-pjrc-xc8x/GHSA-9h3q-pjrc-xc8x.json index 458014b93d4..97ce53acef0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h3q-pjrc-xc8x/GHSA-9h3q-pjrc-xc8x.json +++ b/advisories/unreviewed/2022/05/GHSA-9h3q-pjrc-xc8x/GHSA-9h3q-pjrc-xc8x.json @@ -7,12 +7,8 @@ "CVE-2020-27052" ], "details": "In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158833495", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9h9g-23jj-fphh/GHSA-9h9g-23jj-fphh.json b/advisories/unreviewed/2022/05/GHSA-9h9g-23jj-fphh/GHSA-9h9g-23jj-fphh.json index 982e0a73db0..f9e2a9395a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h9g-23jj-fphh/GHSA-9h9g-23jj-fphh.json +++ b/advisories/unreviewed/2022/05/GHSA-9h9g-23jj-fphh/GHSA-9h9g-23jj-fphh.json @@ -7,12 +7,8 @@ "CVE-2020-28094" ], "details": "On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to download malware named elive or CNKI E-Learning.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9hfm-mhvm-8rx7/GHSA-9hfm-mhvm-8rx7.json b/advisories/unreviewed/2022/05/GHSA-9hfm-mhvm-8rx7/GHSA-9hfm-mhvm-8rx7.json index 3e0b478b876..4f54c9ba252 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hfm-mhvm-8rx7/GHSA-9hfm-mhvm-8rx7.json +++ b/advisories/unreviewed/2022/05/GHSA-9hfm-mhvm-8rx7/GHSA-9hfm-mhvm-8rx7.json @@ -7,12 +7,8 @@ "CVE-2020-29257" ], "details": "Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hp5-8ggx-fcqr/GHSA-9hp5-8ggx-fcqr.json b/advisories/unreviewed/2022/05/GHSA-9hp5-8ggx-fcqr/GHSA-9hp5-8ggx-fcqr.json index 9134a2aa78b..d02366465e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hp5-8ggx-fcqr/GHSA-9hp5-8ggx-fcqr.json +++ b/advisories/unreviewed/2022/05/GHSA-9hp5-8ggx-fcqr/GHSA-9hp5-8ggx-fcqr.json @@ -7,12 +7,8 @@ "CVE-2020-35706" ], "details": "Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j28-98vj-rxx9/GHSA-9j28-98vj-rxx9.json b/advisories/unreviewed/2022/05/GHSA-9j28-98vj-rxx9/GHSA-9j28-98vj-rxx9.json index e5e2028f71a..e36da53ff69 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j28-98vj-rxx9/GHSA-9j28-98vj-rxx9.json +++ b/advisories/unreviewed/2022/05/GHSA-9j28-98vj-rxx9/GHSA-9j28-98vj-rxx9.json @@ -7,12 +7,8 @@ "CVE-2020-27515" ], "details": "A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script or HTML via the Skype ID field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9jqc-6f29-2rw7/GHSA-9jqc-6f29-2rw7.json b/advisories/unreviewed/2022/05/GHSA-9jqc-6f29-2rw7/GHSA-9jqc-6f29-2rw7.json index fffaa56b640..d9e24b9942c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9jqc-6f29-2rw7/GHSA-9jqc-6f29-2rw7.json +++ b/advisories/unreviewed/2022/05/GHSA-9jqc-6f29-2rw7/GHSA-9jqc-6f29-2rw7.json @@ -7,12 +7,8 @@ "CVE-2020-25608" ], "details": "The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pqc-vphg-mj93/GHSA-9pqc-vphg-mj93.json b/advisories/unreviewed/2022/05/GHSA-9pqc-vphg-mj93/GHSA-9pqc-vphg-mj93.json index c23ce97ddf5..59be2531d02 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pqc-vphg-mj93/GHSA-9pqc-vphg-mj93.json +++ b/advisories/unreviewed/2022/05/GHSA-9pqc-vphg-mj93/GHSA-9pqc-vphg-mj93.json @@ -7,12 +7,8 @@ "CVE-2020-35810" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rp8-hcmg-4f3f/GHSA-9rp8-hcmg-4f3f.json b/advisories/unreviewed/2022/05/GHSA-9rp8-hcmg-4f3f/GHSA-9rp8-hcmg-4f3f.json index 16315574e90..0828f070da9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rp8-hcmg-4f3f/GHSA-9rp8-hcmg-4f3f.json +++ b/advisories/unreviewed/2022/05/GHSA-9rp8-hcmg-4f3f/GHSA-9rp8-hcmg-4f3f.json @@ -7,12 +7,8 @@ "CVE-2019-11784" ], "details": "Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party to.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vj3-52fm-gw3x/GHSA-9vj3-52fm-gw3x.json b/advisories/unreviewed/2022/05/GHSA-9vj3-52fm-gw3x/GHSA-9vj3-52fm-gw3x.json index 284c1add257..17892179377 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vj3-52fm-gw3x/GHSA-9vj3-52fm-gw3x.json +++ b/advisories/unreviewed/2022/05/GHSA-9vj3-52fm-gw3x/GHSA-9vj3-52fm-gw3x.json @@ -7,12 +7,8 @@ "CVE-2020-7537" ], "details": "A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9w6x-xx84-rm4g/GHSA-9w6x-xx84-rm4g.json b/advisories/unreviewed/2022/05/GHSA-9w6x-xx84-rm4g/GHSA-9w6x-xx84-rm4g.json index 4ec05ec00a0..9d1f2938e62 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w6x-xx84-rm4g/GHSA-9w6x-xx84-rm4g.json +++ b/advisories/unreviewed/2022/05/GHSA-9w6x-xx84-rm4g/GHSA-9w6x-xx84-rm4g.json @@ -7,12 +7,8 @@ "CVE-2020-35625" ], "details": "An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (defined within PHP or MediaWiki) via a crafted HTML comment, related to a Smarty template. For example, a person in the Widget Editors group could use \\MediaWiki\\Shell\\Shell::command within a comment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9x7w-7fh3-wph9/GHSA-9x7w-7fh3-wph9.json b/advisories/unreviewed/2022/05/GHSA-9x7w-7fh3-wph9/GHSA-9x7w-7fh3-wph9.json index 871d6b12e46..7ddacdd6060 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x7w-7fh3-wph9/GHSA-9x7w-7fh3-wph9.json +++ b/advisories/unreviewed/2022/05/GHSA-9x7w-7fh3-wph9/GHSA-9x7w-7fh3-wph9.json @@ -7,12 +7,8 @@ "CVE-2020-8283" ], "details": "An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xqf-jv59-8prh/GHSA-9xqf-jv59-8prh.json b/advisories/unreviewed/2022/05/GHSA-9xqf-jv59-8prh/GHSA-9xqf-jv59-8prh.json index 5c4a33d3588..2549b830097 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xqf-jv59-8prh/GHSA-9xqf-jv59-8prh.json +++ b/advisories/unreviewed/2022/05/GHSA-9xqf-jv59-8prh/GHSA-9xqf-jv59-8prh.json @@ -7,12 +7,8 @@ "CVE-2020-27045" ], "details": "In CE_SendRawFrame of ce_main.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157649398", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c289-566w-qgp4/GHSA-c289-566w-qgp4.json b/advisories/unreviewed/2022/05/GHSA-c289-566w-qgp4/GHSA-c289-566w-qgp4.json index 6ffea219c85..34b68da115f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c289-566w-qgp4/GHSA-c289-566w-qgp4.json +++ b/advisories/unreviewed/2022/05/GHSA-c289-566w-qgp4/GHSA-c289-566w-qgp4.json @@ -7,12 +7,8 @@ "CVE-2020-14244" ], "details": "A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which would execute with the privileges of the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c2xm-93vx-ccjf/GHSA-c2xm-93vx-ccjf.json b/advisories/unreviewed/2022/05/GHSA-c2xm-93vx-ccjf/GHSA-c2xm-93vx-ccjf.json index be3e0435ff4..91f900e0361 100644 --- a/advisories/unreviewed/2022/05/GHSA-c2xm-93vx-ccjf/GHSA-c2xm-93vx-ccjf.json +++ b/advisories/unreviewed/2022/05/GHSA-c2xm-93vx-ccjf/GHSA-c2xm-93vx-ccjf.json @@ -7,12 +7,8 @@ "CVE-2020-0244" ], "details": "In writeBurstBufferBytes of SPDIFEncoder.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no clear exfiltration path, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145262423", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c34x-96jh-xq96/GHSA-c34x-96jh-xq96.json b/advisories/unreviewed/2022/05/GHSA-c34x-96jh-xq96/GHSA-c34x-96jh-xq96.json index 506f1562c8e..a7f3f2b6041 100644 --- a/advisories/unreviewed/2022/05/GHSA-c34x-96jh-xq96/GHSA-c34x-96jh-xq96.json +++ b/advisories/unreviewed/2022/05/GHSA-c34x-96jh-xq96/GHSA-c34x-96jh-xq96.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c36c-5h7j-842j/GHSA-c36c-5h7j-842j.json b/advisories/unreviewed/2022/05/GHSA-c36c-5h7j-842j/GHSA-c36c-5h7j-842j.json index c67778b9c4d..5ac8445d70a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c36c-5h7j-842j/GHSA-c36c-5h7j-842j.json +++ b/advisories/unreviewed/2022/05/GHSA-c36c-5h7j-842j/GHSA-c36c-5h7j-842j.json @@ -7,12 +7,8 @@ "CVE-2020-7542" ], "details": "A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3f5-4g7m-3xfc/GHSA-c3f5-4g7m-3xfc.json b/advisories/unreviewed/2022/05/GHSA-c3f5-4g7m-3xfc/GHSA-c3f5-4g7m-3xfc.json index da72de55da2..7952c636968 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3f5-4g7m-3xfc/GHSA-c3f5-4g7m-3xfc.json +++ b/advisories/unreviewed/2022/05/GHSA-c3f5-4g7m-3xfc/GHSA-c3f5-4g7m-3xfc.json @@ -7,12 +7,8 @@ "CVE-2020-27729" ], "details": "In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP APM virtual server allows a malicious user to build an open redirect URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c43f-p3rv-7q34/GHSA-c43f-p3rv-7q34.json b/advisories/unreviewed/2022/05/GHSA-c43f-p3rv-7q34/GHSA-c43f-p3rv-7q34.json index 60434a1f172..8378308e453 100644 --- a/advisories/unreviewed/2022/05/GHSA-c43f-p3rv-7q34/GHSA-c43f-p3rv-7q34.json +++ b/advisories/unreviewed/2022/05/GHSA-c43f-p3rv-7q34/GHSA-c43f-p3rv-7q34.json @@ -7,12 +7,8 @@ "CVE-2020-24637" ], "details": "Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this vulnerability this could lead to remote compromise of system integrity by allowing an attacker to load an untrusted or modified kernel in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c529-rjcg-qqqv/GHSA-c529-rjcg-qqqv.json b/advisories/unreviewed/2022/05/GHSA-c529-rjcg-qqqv/GHSA-c529-rjcg-qqqv.json index 4eacec9ff7c..5e0448342b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-c529-rjcg-qqqv/GHSA-c529-rjcg-qqqv.json +++ b/advisories/unreviewed/2022/05/GHSA-c529-rjcg-qqqv/GHSA-c529-rjcg-qqqv.json @@ -7,12 +7,8 @@ "CVE-2020-27036" ], "details": "In phNxpNciHal_send_ext_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153731369", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c585-qfhx-g68f/GHSA-c585-qfhx-g68f.json b/advisories/unreviewed/2022/05/GHSA-c585-qfhx-g68f/GHSA-c585-qfhx-g68f.json index 0332b7fb4bb..0c315790985 100644 --- a/advisories/unreviewed/2022/05/GHSA-c585-qfhx-g68f/GHSA-c585-qfhx-g68f.json +++ b/advisories/unreviewed/2022/05/GHSA-c585-qfhx-g68f/GHSA-c585-qfhx-g68f.json @@ -7,12 +7,8 @@ "CVE-2020-35796" ], "details": "Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5.0.10, D6220 before 1.0.0.60, D6400 before 1.0.0.94, D7000v2 before 1.0.0.62, D8500 before 1.0.3.50, DC112A before 1.0.0.48, DGN2200v4 before 1.0.0.114, EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX3700 before 1.0.0.84, EX3800 before 1.0.0.84, EX3920 before 1.0.0.84, EX6000 before 1.0.0.44, EX6100 before 1.0.2.28, EX6120 before 1.0.0.54, EX6130 before 1.0.0.36, EX6150 before 1.0.0.46, EX6200 before 1.0.3.94, EX6920 before 1.0.0.54, EX7000 before 1.0.1.90, EX7500 before 1.0.0.68, MK62 before 1.0.5.102, MR60 before 1.0.5.102, MS60 before 1.0.5.102, R6250 before 1.0.4.42, R6300v2 before 1.0.4.42, R6400 before 1.0.1.62, R6400v2 before 1.0.4.98, R6700v3 before 1.0.4.98, R6700 before 1.0.2.16, R6900P before 1.3.2.124, R6900 before 1.0.2.16, R7000 before 1.0.11.106, R7000P before 1.3.2.124, R7100LG before 1.0.0.56, R7850 before 1.0.5.60, R7900 before 1.0.4.26, R7900P before 1.4.1.62, R7960P before 1.4.1.62, R8000 before 1.0.4.58, R8000P before 1.4.1.62, R8300 before 1.0.2.134, R8500 before 1.0.2.134, RAX15 before 1.0.1.64, RAX20 before 1.0.1.64, RAX200 before 1.0.2.102, RAX45 before 1.0.2.32, RAX50 before 1.0.2.32, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK842 before 3.2.16.6, RBR840 before 3.2.16.6, RBS840 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RBS40V-200 before 1.0.0.46, RBW30 before 2.5.0.4, RS400 before 1.5.0.48, WN2500RPv2 before 1.0.1.56, WN3500RP before 1.0.0.28, WNDR3400v3 before 1.0.1.32, WNR1000v3 before 1.0.2.78, WNR2000v2 before 1.2.0.12, WNR3500Lv2 before 1.2.0.62, and XR300 before 1.0.3.50.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5fc-m7pj-4vv5/GHSA-c5fc-m7pj-4vv5.json b/advisories/unreviewed/2022/05/GHSA-c5fc-m7pj-4vv5/GHSA-c5fc-m7pj-4vv5.json index b04df8e92ec..1713619df15 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5fc-m7pj-4vv5/GHSA-c5fc-m7pj-4vv5.json +++ b/advisories/unreviewed/2022/05/GHSA-c5fc-m7pj-4vv5/GHSA-c5fc-m7pj-4vv5.json @@ -7,12 +7,8 @@ "CVE-2020-25179" ], "details": "GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6gp-grvf-r987/GHSA-c6gp-grvf-r987.json b/advisories/unreviewed/2022/05/GHSA-c6gp-grvf-r987/GHSA-c6gp-grvf-r987.json index 9fa275ae0a3..fa9f4547d6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6gp-grvf-r987/GHSA-c6gp-grvf-r987.json +++ b/advisories/unreviewed/2022/05/GHSA-c6gp-grvf-r987/GHSA-c6gp-grvf-r987.json @@ -7,12 +7,8 @@ "CVE-2019-11783" ], "details": "Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6rr-v7p8-35wh/GHSA-c6rr-v7p8-35wh.json b/advisories/unreviewed/2022/05/GHSA-c6rr-v7p8-35wh/GHSA-c6rr-v7p8-35wh.json index 654d41caf55..ee9a5133ba2 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6rr-v7p8-35wh/GHSA-c6rr-v7p8-35wh.json +++ b/advisories/unreviewed/2022/05/GHSA-c6rr-v7p8-35wh/GHSA-c6rr-v7p8-35wh.json @@ -7,12 +7,8 @@ "CVE-2020-25230" ], "details": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Due to the usage of an outdated cipher mode on port 10005/tcp, an attacker could extract the encryption key from a captured communication with the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c6vf-v2c4-qvvh/GHSA-c6vf-v2c4-qvvh.json b/advisories/unreviewed/2022/05/GHSA-c6vf-v2c4-qvvh/GHSA-c6vf-v2c4-qvvh.json index f8cc31e96f9..20128c310fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6vf-v2c4-qvvh/GHSA-c6vf-v2c4-qvvh.json +++ b/advisories/unreviewed/2022/05/GHSA-c6vf-v2c4-qvvh/GHSA-c6vf-v2c4-qvvh.json @@ -7,12 +7,8 @@ "CVE-2020-28456" ], "details": "The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7r4-5f37-6572/GHSA-c7r4-5f37-6572.json b/advisories/unreviewed/2022/05/GHSA-c7r4-5f37-6572/GHSA-c7r4-5f37-6572.json index 822b79f8c06..9721f8b12b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7r4-5f37-6572/GHSA-c7r4-5f37-6572.json +++ b/advisories/unreviewed/2022/05/GHSA-c7r4-5f37-6572/GHSA-c7r4-5f37-6572.json @@ -7,12 +7,8 @@ "CVE-2020-5948" ], "details": "On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8qx-8jr7-qrj4/GHSA-c8qx-8jr7-qrj4.json b/advisories/unreviewed/2022/05/GHSA-c8qx-8jr7-qrj4/GHSA-c8qx-8jr7-qrj4.json index a1599b05ff7..59687e340ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8qx-8jr7-qrj4/GHSA-c8qx-8jr7-qrj4.json +++ b/advisories/unreviewed/2022/05/GHSA-c8qx-8jr7-qrj4/GHSA-c8qx-8jr7-qrj4.json @@ -7,12 +7,8 @@ "CVE-2020-8466" ], "details": "A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c94j-m65h-vm53/GHSA-c94j-m65h-vm53.json b/advisories/unreviewed/2022/05/GHSA-c94j-m65h-vm53/GHSA-c94j-m65h-vm53.json index 9b1cef125e3..128db062166 100644 --- a/advisories/unreviewed/2022/05/GHSA-c94j-m65h-vm53/GHSA-c94j-m65h-vm53.json +++ b/advisories/unreviewed/2022/05/GHSA-c94j-m65h-vm53/GHSA-c94j-m65h-vm53.json @@ -7,12 +7,8 @@ "CVE-2020-35613" ], "details": "An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c965-72mg-cpv5/GHSA-c965-72mg-cpv5.json b/advisories/unreviewed/2022/05/GHSA-c965-72mg-cpv5/GHSA-c965-72mg-cpv5.json index 119d62ccedf..fb9111ae12f 100644 --- a/advisories/unreviewed/2022/05/GHSA-c965-72mg-cpv5/GHSA-c965-72mg-cpv5.json +++ b/advisories/unreviewed/2022/05/GHSA-c965-72mg-cpv5/GHSA-c965-72mg-cpv5.json @@ -7,12 +7,8 @@ "CVE-2020-29172" ], "details": "A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfw4-vhm2-m225/GHSA-cfw4-vhm2-m225.json b/advisories/unreviewed/2022/05/GHSA-cfw4-vhm2-m225/GHSA-cfw4-vhm2-m225.json index de4f4e55c71..a066639d2b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfw4-vhm2-m225/GHSA-cfw4-vhm2-m225.json +++ b/advisories/unreviewed/2022/05/GHSA-cfw4-vhm2-m225/GHSA-cfw4-vhm2-m225.json @@ -7,12 +7,8 @@ "CVE-2020-25758" ], "details": "An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. These entries are executed as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg9q-rwc5-c6x9/GHSA-cg9q-rwc5-c6x9.json b/advisories/unreviewed/2022/05/GHSA-cg9q-rwc5-c6x9/GHSA-cg9q-rwc5-c6x9.json index 3f9d7aef327..b12f08b12c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg9q-rwc5-c6x9/GHSA-cg9q-rwc5-c6x9.json +++ b/advisories/unreviewed/2022/05/GHSA-cg9q-rwc5-c6x9/GHSA-cg9q-rwc5-c6x9.json @@ -7,12 +7,8 @@ "CVE-2020-26031" ], "details": "An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch2j-pqr2-h9jh/GHSA-ch2j-pqr2-h9jh.json b/advisories/unreviewed/2022/05/GHSA-ch2j-pqr2-h9jh/GHSA-ch2j-pqr2-h9jh.json index acd433629d5..6990a429589 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch2j-pqr2-h9jh/GHSA-ch2j-pqr2-h9jh.json +++ b/advisories/unreviewed/2022/05/GHSA-ch2j-pqr2-h9jh/GHSA-ch2j-pqr2-h9jh.json @@ -7,12 +7,8 @@ "CVE-2020-35590" ], "details": "LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited to perform a brute force attack, because the client IP header accepts any arbitrary string. When randomizing the header input, the login count does not ever reach the maximum allowed retries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch7j-5vw3-j293/GHSA-ch7j-5vw3-j293.json b/advisories/unreviewed/2022/05/GHSA-ch7j-5vw3-j293/GHSA-ch7j-5vw3-j293.json index 4abe6b56723..21b37441d1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch7j-5vw3-j293/GHSA-ch7j-5vw3-j293.json +++ b/advisories/unreviewed/2022/05/GHSA-ch7j-5vw3-j293/GHSA-ch7j-5vw3-j293.json @@ -7,12 +7,8 @@ "CVE-2020-25228" ], "details": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on port 10005/tcp of the affected devices could allow complete access to all services without authorization. An attacker could gain full control over an affected device, if he has access to this service. The system manual recommends to protect access to this port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-chj6-qg78-f8r4/GHSA-chj6-qg78-f8r4.json b/advisories/unreviewed/2022/05/GHSA-chj6-qg78-f8r4/GHSA-chj6-qg78-f8r4.json index f200d2077db..b48d0a96eee 100644 --- a/advisories/unreviewed/2022/05/GHSA-chj6-qg78-f8r4/GHSA-chj6-qg78-f8r4.json +++ b/advisories/unreviewed/2022/05/GHSA-chj6-qg78-f8r4/GHSA-chj6-qg78-f8r4.json @@ -7,12 +7,8 @@ "CVE-2020-5683" ], "details": "Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier allows remote attackers to alter the data by uploading a specially crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj5x-6j3p-rgxm/GHSA-cj5x-6j3p-rgxm.json b/advisories/unreviewed/2022/05/GHSA-cj5x-6j3p-rgxm/GHSA-cj5x-6j3p-rgxm.json index 21f4ede0b6d..aecf2a32875 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj5x-6j3p-rgxm/GHSA-cj5x-6j3p-rgxm.json +++ b/advisories/unreviewed/2022/05/GHSA-cj5x-6j3p-rgxm/GHSA-cj5x-6j3p-rgxm.json @@ -7,12 +7,8 @@ "CVE-2020-26173" ], "details": "An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj8v-r5w4-97v8/GHSA-cj8v-r5w4-97v8.json b/advisories/unreviewed/2022/05/GHSA-cj8v-r5w4-97v8/GHSA-cj8v-r5w4-97v8.json index 7a9996e4442..c108485f781 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj8v-r5w4-97v8/GHSA-cj8v-r5w4-97v8.json +++ b/advisories/unreviewed/2022/05/GHSA-cj8v-r5w4-97v8/GHSA-cj8v-r5w4-97v8.json @@ -7,12 +7,8 @@ "CVE-2020-29447" ], "details": "Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews. The affected versions are before version 4.7.4, and from version 4.8.0 before 4.8.5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cm7f-83pq-pfp3/GHSA-cm7f-83pq-pfp3.json b/advisories/unreviewed/2022/05/GHSA-cm7f-83pq-pfp3/GHSA-cm7f-83pq-pfp3.json index 9884423521f..2538cdc7e49 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm7f-83pq-pfp3/GHSA-cm7f-83pq-pfp3.json +++ b/advisories/unreviewed/2022/05/GHSA-cm7f-83pq-pfp3/GHSA-cm7f-83pq-pfp3.json @@ -7,12 +7,8 @@ "CVE-2020-25917" ], "details": "Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with \"helpdesk\" privileges, can perform privileged operations including adding a new administrator to the platform via the easyadmin/user/submitCreateTCUser.do page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cm97-fwp9-pfjj/GHSA-cm97-fwp9-pfjj.json b/advisories/unreviewed/2022/05/GHSA-cm97-fwp9-pfjj/GHSA-cm97-fwp9-pfjj.json index 087cb5877c9..edcab270393 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm97-fwp9-pfjj/GHSA-cm97-fwp9-pfjj.json +++ b/advisories/unreviewed/2022/05/GHSA-cm97-fwp9-pfjj/GHSA-cm97-fwp9-pfjj.json @@ -7,12 +7,8 @@ "CVE-2020-35693" ], "details": "On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Low Energy (BLE) device to pair silently with a vulnerable target device, without any user interaction, when the target device's Bluetooth is on, and it is running an app that offers a connectable BLE advertisement. An example of such an app could be a Bluetooth-based contact tracing app, such as Australia's COVIDSafe app, Singapore's TraceTogether app, or France's TousAntiCovid (formerly StopCovid). As part of the pairing process, two pieces (among others) of personally identifiable information are exchanged: the Identity Address of the Bluetooth adapter of the target device, and its associated Identity Resolving Key (IRK). Either one of these identifiers can be used to perform re-identification of the target device for long term tracking. The list of affected devices includes (but is not limited to): Galaxy Note 5, Galaxy S6 Edge, Galaxy A3, Tab A (2017), J2 Pro (2018), Galaxy Note 4, and Galaxy S5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cq4c-8j48-3m6g/GHSA-cq4c-8j48-3m6g.json b/advisories/unreviewed/2022/05/GHSA-cq4c-8j48-3m6g/GHSA-cq4c-8j48-3m6g.json index 635ac3abe05..738dcc2fdc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq4c-8j48-3m6g/GHSA-cq4c-8j48-3m6g.json +++ b/advisories/unreviewed/2022/05/GHSA-cq4c-8j48-3m6g/GHSA-cq4c-8j48-3m6g.json @@ -7,12 +7,8 @@ "CVE-2020-27010" ], "details": "A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product in a manner separate from the similar CVE-2020-8462.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crm8-2hrx-527c/GHSA-crm8-2hrx-527c.json b/advisories/unreviewed/2022/05/GHSA-crm8-2hrx-527c/GHSA-crm8-2hrx-527c.json index 40f6b786695..b4d7042e77d 100644 --- a/advisories/unreviewed/2022/05/GHSA-crm8-2hrx-527c/GHSA-crm8-2hrx-527c.json +++ b/advisories/unreviewed/2022/05/GHSA-crm8-2hrx-527c/GHSA-crm8-2hrx-527c.json @@ -7,12 +7,8 @@ "CVE-2020-29596" ], "details": "MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cvwh-p6q5-8546/GHSA-cvwh-p6q5-8546.json b/advisories/unreviewed/2022/05/GHSA-cvwh-p6q5-8546/GHSA-cvwh-p6q5-8546.json index 59126ea91e0..488b9a51ac9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvwh-p6q5-8546/GHSA-cvwh-p6q5-8546.json +++ b/advisories/unreviewed/2022/05/GHSA-cvwh-p6q5-8546/GHSA-cvwh-p6q5-8546.json @@ -7,12 +7,8 @@ "CVE-2020-29436" ], "details": "Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cw4x-cxpm-9p3r/GHSA-cw4x-cxpm-9p3r.json b/advisories/unreviewed/2022/05/GHSA-cw4x-cxpm-9p3r/GHSA-cw4x-cxpm-9p3r.json index 8192730d2e3..5b73808dac6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw4x-cxpm-9p3r/GHSA-cw4x-cxpm-9p3r.json +++ b/advisories/unreviewed/2022/05/GHSA-cw4x-cxpm-9p3r/GHSA-cw4x-cxpm-9p3r.json @@ -7,12 +7,8 @@ "CVE-2019-14479" ], "details": "AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwcm-c4j8-ww8c/GHSA-cwcm-c4j8-ww8c.json b/advisories/unreviewed/2022/05/GHSA-cwcm-c4j8-ww8c/GHSA-cwcm-c4j8-ww8c.json index f2e983b34d0..d8352c97bba 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwcm-c4j8-ww8c/GHSA-cwcm-c4j8-ww8c.json +++ b/advisories/unreviewed/2022/05/GHSA-cwcm-c4j8-ww8c/GHSA-cwcm-c4j8-ww8c.json @@ -7,12 +7,8 @@ "CVE-2020-35555" ], "details": "An issue was discovered on LG mobile devices with Android OS 10 software. When a dual-screen configuration is supported, the device does not lock upon disconnection of a call with the cover closed. The LG ID is LVE-SMP-200027 (December 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cwv7-82qm-9wqw/GHSA-cwv7-82qm-9wqw.json b/advisories/unreviewed/2022/05/GHSA-cwv7-82qm-9wqw/GHSA-cwv7-82qm-9wqw.json index 89576f63097..baa56e5be5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwv7-82qm-9wqw/GHSA-cwv7-82qm-9wqw.json +++ b/advisories/unreviewed/2022/05/GHSA-cwv7-82qm-9wqw/GHSA-cwv7-82qm-9wqw.json @@ -7,12 +7,8 @@ "CVE-2016-9021" ], "details": "Exponent CMS before 2.6.0 has improper input validation in storeController.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx9v-96cj-78q9/GHSA-cx9v-96cj-78q9.json b/advisories/unreviewed/2022/05/GHSA-cx9v-96cj-78q9/GHSA-cx9v-96cj-78q9.json index 9833ec49bb4..326256917a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx9v-96cj-78q9/GHSA-cx9v-96cj-78q9.json +++ b/advisories/unreviewed/2022/05/GHSA-cx9v-96cj-78q9/GHSA-cx9v-96cj-78q9.json @@ -7,12 +7,8 @@ "CVE-2020-13988" ], "details": "An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsing TCP MSS options of IPv4 network packets in uip_process in net/ipv4/uip.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxgj-mmp6-3j54/GHSA-cxgj-mmp6-3j54.json b/advisories/unreviewed/2022/05/GHSA-cxgj-mmp6-3j54/GHSA-cxgj-mmp6-3j54.json index 17565cf3604..8e56ce1d5c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxgj-mmp6-3j54/GHSA-cxgj-mmp6-3j54.json +++ b/advisories/unreviewed/2022/05/GHSA-cxgj-mmp6-3j54/GHSA-cxgj-mmp6-3j54.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f329-5h54-9xp6/GHSA-f329-5h54-9xp6.json b/advisories/unreviewed/2022/05/GHSA-f329-5h54-9xp6/GHSA-f329-5h54-9xp6.json index 5bb679cf702..99f7c6a59b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-f329-5h54-9xp6/GHSA-f329-5h54-9xp6.json +++ b/advisories/unreviewed/2022/05/GHSA-f329-5h54-9xp6/GHSA-f329-5h54-9xp6.json @@ -7,12 +7,8 @@ "CVE-2020-35173" ], "details": "The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP server (aka services.ftpservice.FTPReceiver.ACTION_START_FTPSERVER and services.ftpservice.FTPReceiver.ACTION_STOP_FTPSERVER).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f34x-833g-jcxv/GHSA-f34x-833g-jcxv.json b/advisories/unreviewed/2022/05/GHSA-f34x-833g-jcxv/GHSA-f34x-833g-jcxv.json index 729bf03e536..c53187054ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-f34x-833g-jcxv/GHSA-f34x-833g-jcxv.json +++ b/advisories/unreviewed/2022/05/GHSA-f34x-833g-jcxv/GHSA-f34x-833g-jcxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3hv-32hf-cqw9/GHSA-f3hv-32hf-cqw9.json b/advisories/unreviewed/2022/05/GHSA-f3hv-32hf-cqw9/GHSA-f3hv-32hf-cqw9.json index e2a08236873..868fc5a8b11 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3hv-32hf-cqw9/GHSA-f3hv-32hf-cqw9.json +++ b/advisories/unreviewed/2022/05/GHSA-f3hv-32hf-cqw9/GHSA-f3hv-32hf-cqw9.json @@ -7,12 +7,8 @@ "CVE-2020-5807" ], "details": "An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer (FTDiagViewer.exe) to view the log entry. Observed in FactoryTalk Diagnostics 6.11. All versions of FactoryTalk Diagnostics are affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f435-mvrp-xrqp/GHSA-f435-mvrp-xrqp.json b/advisories/unreviewed/2022/05/GHSA-f435-mvrp-xrqp/GHSA-f435-mvrp-xrqp.json index 080814a01e2..126e3502fb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f435-mvrp-xrqp/GHSA-f435-mvrp-xrqp.json +++ b/advisories/unreviewed/2022/05/GHSA-f435-mvrp-xrqp/GHSA-f435-mvrp-xrqp.json @@ -7,12 +7,8 @@ "CVE-2020-0476" ], "details": "In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to logs. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162014574", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f47w-6h97-hppp/GHSA-f47w-6h97-hppp.json b/advisories/unreviewed/2022/05/GHSA-f47w-6h97-hppp/GHSA-f47w-6h97-hppp.json index 7df92d5e6d7..72d4b0dd38d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f47w-6h97-hppp/GHSA-f47w-6h97-hppp.json +++ b/advisories/unreviewed/2022/05/GHSA-f47w-6h97-hppp/GHSA-f47w-6h97-hppp.json @@ -7,12 +7,8 @@ "CVE-2020-7543" ], "details": "A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f53r-gcpp-vf27/GHSA-f53r-gcpp-vf27.json b/advisories/unreviewed/2022/05/GHSA-f53r-gcpp-vf27/GHSA-f53r-gcpp-vf27.json index 3a1e5e8ff05..71d1261c351 100644 --- a/advisories/unreviewed/2022/05/GHSA-f53r-gcpp-vf27/GHSA-f53r-gcpp-vf27.json +++ b/advisories/unreviewed/2022/05/GHSA-f53r-gcpp-vf27/GHSA-f53r-gcpp-vf27.json @@ -7,12 +7,8 @@ "CVE-2020-35346" ], "details": "CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of admin.php?c=content&a=add.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f64w-4rx7-rvrx/GHSA-f64w-4rx7-rvrx.json b/advisories/unreviewed/2022/05/GHSA-f64w-4rx7-rvrx/GHSA-f64w-4rx7-rvrx.json index f1bf9350483..ad433b6269f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f64w-4rx7-rvrx/GHSA-f64w-4rx7-rvrx.json +++ b/advisories/unreviewed/2022/05/GHSA-f64w-4rx7-rvrx/GHSA-f64w-4rx7-rvrx.json @@ -7,12 +7,8 @@ "CVE-2019-14476" ], "details": "AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6c6-g5xq-fvm6/GHSA-f6c6-g5xq-fvm6.json b/advisories/unreviewed/2022/05/GHSA-f6c6-g5xq-fvm6/GHSA-f6c6-g5xq-fvm6.json index 7ba8f2d69a5..ecf6c11dbc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6c6-g5xq-fvm6/GHSA-f6c6-g5xq-fvm6.json +++ b/advisories/unreviewed/2022/05/GHSA-f6c6-g5xq-fvm6/GHSA-f6c6-g5xq-fvm6.json @@ -7,12 +7,8 @@ "CVE-2020-6881" ], "details": "ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to verify the validity of abnormal messages. A remote attacker could connect to the MQTT server and send an MQTT exception message to the specified device, which will cause the device to deny service. This affects:", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6gr-xm3f-89xf/GHSA-f6gr-xm3f-89xf.json b/advisories/unreviewed/2022/05/GHSA-f6gr-xm3f-89xf/GHSA-f6gr-xm3f-89xf.json index c63e5596b3a..7581d62c62c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6gr-xm3f-89xf/GHSA-f6gr-xm3f-89xf.json +++ b/advisories/unreviewed/2022/05/GHSA-f6gr-xm3f-89xf/GHSA-f6gr-xm3f-89xf.json @@ -7,12 +7,8 @@ "CVE-2020-35785" ], "details": "NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-2020-0365).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f756-pwvp-9jmj/GHSA-f756-pwvp-9jmj.json b/advisories/unreviewed/2022/05/GHSA-f756-pwvp-9jmj/GHSA-f756-pwvp-9jmj.json index d1afb551477..7f4c595b755 100644 --- a/advisories/unreviewed/2022/05/GHSA-f756-pwvp-9jmj/GHSA-f756-pwvp-9jmj.json +++ b/advisories/unreviewed/2022/05/GHSA-f756-pwvp-9jmj/GHSA-f756-pwvp-9jmj.json @@ -7,12 +7,8 @@ "CVE-2020-29594" ], "details": "Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f79g-9mrm-w496/GHSA-f79g-9mrm-w496.json b/advisories/unreviewed/2022/05/GHSA-f79g-9mrm-w496/GHSA-f79g-9mrm-w496.json index a6afcc6a485..bcb313de2a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-f79g-9mrm-w496/GHSA-f79g-9mrm-w496.json +++ b/advisories/unreviewed/2022/05/GHSA-f79g-9mrm-w496/GHSA-f79g-9mrm-w496.json @@ -7,12 +7,8 @@ "CVE-2020-27723" ], "details": "In versions 14.1.0-14.1.3 and 13.1.0-13.1.3.4, a BIG-IP APM virtual server processing PingAccess requests may lead to a restart of the Traffic Management Microkernel (TMM) process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7v5-p6x6-2823/GHSA-f7v5-p6x6-2823.json b/advisories/unreviewed/2022/05/GHSA-f7v5-p6x6-2823/GHSA-f7v5-p6x6-2823.json index d4e64bb6a78..a5469fd6ffc 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7v5-p6x6-2823/GHSA-f7v5-p6x6-2823.json +++ b/advisories/unreviewed/2022/05/GHSA-f7v5-p6x6-2823/GHSA-f7v5-p6x6-2823.json @@ -7,12 +7,8 @@ "CVE-2020-29258" ], "details": "Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the w parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8g3-m2c8-8x9w/GHSA-f8g3-m2c8-8x9w.json b/advisories/unreviewed/2022/05/GHSA-f8g3-m2c8-8x9w/GHSA-f8g3-m2c8-8x9w.json index 585eed51ddb..167157e85f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8g3-m2c8-8x9w/GHSA-f8g3-m2c8-8x9w.json +++ b/advisories/unreviewed/2022/05/GHSA-f8g3-m2c8-8x9w/GHSA-f8g3-m2c8-8x9w.json @@ -7,12 +7,8 @@ "CVE-2020-35586" ], "details": "In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f8r4-jggf-jmg8/GHSA-f8r4-jggf-jmg8.json b/advisories/unreviewed/2022/05/GHSA-f8r4-jggf-jmg8/GHSA-f8r4-jggf-jmg8.json index cd9c18007f7..1dfafdcad68 100644 --- a/advisories/unreviewed/2022/05/GHSA-f8r4-jggf-jmg8/GHSA-f8r4-jggf-jmg8.json +++ b/advisories/unreviewed/2022/05/GHSA-f8r4-jggf-jmg8/GHSA-f8r4-jggf-jmg8.json @@ -7,12 +7,8 @@ "CVE-2020-25617" ], "details": "An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), leading to execution of OS commands as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f92r-w6xq-p3pv/GHSA-f92r-w6xq-p3pv.json b/advisories/unreviewed/2022/05/GHSA-f92r-w6xq-p3pv/GHSA-f92r-w6xq-p3pv.json index 94972187f2a..58209bc42ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-f92r-w6xq-p3pv/GHSA-f92r-w6xq-p3pv.json +++ b/advisories/unreviewed/2022/05/GHSA-f92r-w6xq-p3pv/GHSA-f92r-w6xq-p3pv.json @@ -7,12 +7,8 @@ "CVE-2020-14273" ], "details": "HCL Domino v10 and v11 is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to crash the Domino server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f9j7-x88q-9m28/GHSA-f9j7-x88q-9m28.json b/advisories/unreviewed/2022/05/GHSA-f9j7-x88q-9m28/GHSA-f9j7-x88q-9m28.json index cd3422510b1..e23ffc5fd53 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9j7-x88q-9m28/GHSA-f9j7-x88q-9m28.json +++ b/advisories/unreviewed/2022/05/GHSA-f9j7-x88q-9m28/GHSA-f9j7-x88q-9m28.json @@ -7,12 +7,8 @@ "CVE-2020-35236" ], "details": "The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcfc-3847-rccf/GHSA-fcfc-3847-rccf.json b/advisories/unreviewed/2022/05/GHSA-fcfc-3847-rccf/GHSA-fcfc-3847-rccf.json index 596e8fb63e2..7e9777bf2bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcfc-3847-rccf/GHSA-fcfc-3847-rccf.json +++ b/advisories/unreviewed/2022/05/GHSA-fcfc-3847-rccf/GHSA-fcfc-3847-rccf.json @@ -7,12 +7,8 @@ "CVE-2020-17445" ], "details": "An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 destination options does not check for a valid length of the destination options header. This results in an Out-of-Bounds Read, and, depending on the memory protection mechanism, this may result in Denial-of-Service in pico_ipv6_process_destopt() in pico_ipv6.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcfx-pc78-jw2m/GHSA-fcfx-pc78-jw2m.json b/advisories/unreviewed/2022/05/GHSA-fcfx-pc78-jw2m/GHSA-fcfx-pc78-jw2m.json index 3eef259c92e..15d520c6ab8 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcfx-pc78-jw2m/GHSA-fcfx-pc78-jw2m.json +++ b/advisories/unreviewed/2022/05/GHSA-fcfx-pc78-jw2m/GHSA-fcfx-pc78-jw2m.json @@ -7,12 +7,8 @@ "CVE-2020-24677" ], "details": "Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgch-vc2g-g3c8/GHSA-fgch-vc2g-g3c8.json b/advisories/unreviewed/2022/05/GHSA-fgch-vc2g-g3c8/GHSA-fgch-vc2g-g3c8.json index 4e421b09aa5..de8896169d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgch-vc2g-g3c8/GHSA-fgch-vc2g-g3c8.json +++ b/advisories/unreviewed/2022/05/GHSA-fgch-vc2g-g3c8/GHSA-fgch-vc2g-g3c8.json @@ -7,12 +7,8 @@ "CVE-2020-8464" ], "details": "A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin interface to users who would not normally have access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjv4-6mwc-7524/GHSA-fjv4-6mwc-7524.json b/advisories/unreviewed/2022/05/GHSA-fjv4-6mwc-7524/GHSA-fjv4-6mwc-7524.json index 12c9f9e27cc..89096dcc0e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjv4-6mwc-7524/GHSA-fjv4-6mwc-7524.json +++ b/advisories/unreviewed/2022/05/GHSA-fjv4-6mwc-7524/GHSA-fjv4-6mwc-7524.json @@ -7,12 +7,8 @@ "CVE-2020-29189" ], "details": "Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder within the NAS", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm6w-v8h2-8q9w/GHSA-fm6w-v8h2-8q9w.json b/advisories/unreviewed/2022/05/GHSA-fm6w-v8h2-8q9w/GHSA-fm6w-v8h2-8q9w.json index 02b7cfc46bc..ce0aec669ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm6w-v8h2-8q9w/GHSA-fm6w-v8h2-8q9w.json +++ b/advisories/unreviewed/2022/05/GHSA-fm6w-v8h2-8q9w/GHSA-fm6w-v8h2-8q9w.json @@ -7,12 +7,8 @@ "CVE-2020-35811" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmh2-qxcv-pr3h/GHSA-fmh2-qxcv-pr3h.json b/advisories/unreviewed/2022/05/GHSA-fmh2-qxcv-pr3h/GHSA-fmh2-qxcv-pr3h.json index 70bd2b69c44..37d6bb2537d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmh2-qxcv-pr3h/GHSA-fmh2-qxcv-pr3h.json +++ b/advisories/unreviewed/2022/05/GHSA-fmh2-qxcv-pr3h/GHSA-fmh2-qxcv-pr3h.json @@ -7,12 +7,8 @@ "CVE-2020-28096" ], "details": "FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmh6-hqj7-h6hv/GHSA-fmh6-hqj7-h6hv.json b/advisories/unreviewed/2022/05/GHSA-fmh6-hqj7-h6hv/GHSA-fmh6-hqj7-h6hv.json index 9a94157cee7..de974ca5aa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmh6-hqj7-h6hv/GHSA-fmh6-hqj7-h6hv.json +++ b/advisories/unreviewed/2022/05/GHSA-fmh6-hqj7-h6hv/GHSA-fmh6-hqj7-h6hv.json @@ -7,12 +7,8 @@ "CVE-2020-27041" ], "details": "In showProvisioningNotification of ConnectivityService.java, there is an unsafe PendingIntent. This could lead to local information disclosure of notification data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154928507", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmvr-p9qq-34gq/GHSA-fmvr-p9qq-34gq.json b/advisories/unreviewed/2022/05/GHSA-fmvr-p9qq-34gq/GHSA-fmvr-p9qq-34gq.json index f31492ce880..4547ef40efa 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmvr-p9qq-34gq/GHSA-fmvr-p9qq-34gq.json +++ b/advisories/unreviewed/2022/05/GHSA-fmvr-p9qq-34gq/GHSA-fmvr-p9qq-34gq.json @@ -7,12 +7,8 @@ "CVE-2020-27715" ], "details": "On BIG-IP 15.1.0-15.1.0.5 and 14.1.0-14.1.3, crafted TLS request to the BIG-IP management interface via port 443 can cause high (~100%) CPU utilization by the httpd daemon.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmx8-rqgc-5vmx/GHSA-fmx8-rqgc-5vmx.json b/advisories/unreviewed/2022/05/GHSA-fmx8-rqgc-5vmx/GHSA-fmx8-rqgc-5vmx.json index fb5a6cdd38a..29b580094ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmx8-rqgc-5vmx/GHSA-fmx8-rqgc-5vmx.json +++ b/advisories/unreviewed/2022/05/GHSA-fmx8-rqgc-5vmx/GHSA-fmx8-rqgc-5vmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-frhm-hx27-q4p6/GHSA-frhm-hx27-q4p6.json b/advisories/unreviewed/2022/05/GHSA-frhm-hx27-q4p6/GHSA-frhm-hx27-q4p6.json index ecb8b38ec51..be68f980b0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-frhm-hx27-q4p6/GHSA-frhm-hx27-q4p6.json +++ b/advisories/unreviewed/2022/05/GHSA-frhm-hx27-q4p6/GHSA-frhm-hx27-q4p6.json @@ -7,12 +7,8 @@ "CVE-2020-0489" ], "details": "In Parse_data of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151096540", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv42-5hcx-5cr6/GHSA-fv42-5hcx-5cr6.json b/advisories/unreviewed/2022/05/GHSA-fv42-5hcx-5cr6/GHSA-fv42-5hcx-5cr6.json index 013ddb09918..c4e8a01dead 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv42-5hcx-5cr6/GHSA-fv42-5hcx-5cr6.json +++ b/advisories/unreviewed/2022/05/GHSA-fv42-5hcx-5cr6/GHSA-fv42-5hcx-5cr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvq4-c84w-q2rx/GHSA-fvq4-c84w-q2rx.json b/advisories/unreviewed/2022/05/GHSA-fvq4-c84w-q2rx/GHSA-fvq4-c84w-q2rx.json index 9773a8a4d93..d15658b806f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvq4-c84w-q2rx/GHSA-fvq4-c84w-q2rx.json +++ b/advisories/unreviewed/2022/05/GHSA-fvq4-c84w-q2rx/GHSA-fvq4-c84w-q2rx.json @@ -7,12 +7,8 @@ "CVE-2020-28861" ], "details": "OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw96-xwr9-54ff/GHSA-fw96-xwr9-54ff.json b/advisories/unreviewed/2022/05/GHSA-fw96-xwr9-54ff/GHSA-fw96-xwr9-54ff.json index e76295d20ef..6dc28b97191 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw96-xwr9-54ff/GHSA-fw96-xwr9-54ff.json +++ b/advisories/unreviewed/2022/05/GHSA-fw96-xwr9-54ff/GHSA-fw96-xwr9-54ff.json @@ -7,12 +7,8 @@ "CVE-2020-13969" ], "details": "CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter. This is path-independent.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwfg-74jc-wgx8/GHSA-fwfg-74jc-wgx8.json b/advisories/unreviewed/2022/05/GHSA-fwfg-74jc-wgx8/GHSA-fwfg-74jc-wgx8.json index 0f6431db66e..0fc12b3688d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwfg-74jc-wgx8/GHSA-fwfg-74jc-wgx8.json +++ b/advisories/unreviewed/2022/05/GHSA-fwfg-74jc-wgx8/GHSA-fwfg-74jc-wgx8.json @@ -7,12 +7,8 @@ "CVE-2020-12523" ], "details": "On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwm5-6cq3-ch4p/GHSA-fwm5-6cq3-ch4p.json b/advisories/unreviewed/2022/05/GHSA-fwm5-6cq3-ch4p/GHSA-fwm5-6cq3-ch4p.json index e43c360578e..1fc4acb2584 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwm5-6cq3-ch4p/GHSA-fwm5-6cq3-ch4p.json +++ b/advisories/unreviewed/2022/05/GHSA-fwm5-6cq3-ch4p/GHSA-fwm5-6cq3-ch4p.json @@ -7,12 +7,8 @@ "CVE-2020-35243" ], "details": "Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwrf-6v6g-jrvx/GHSA-fwrf-6v6g-jrvx.json b/advisories/unreviewed/2022/05/GHSA-fwrf-6v6g-jrvx/GHSA-fwrf-6v6g-jrvx.json index f2b40f2308e..699617573c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwrf-6v6g-jrvx/GHSA-fwrf-6v6g-jrvx.json +++ b/advisories/unreviewed/2022/05/GHSA-fwrf-6v6g-jrvx/GHSA-fwrf-6v6g-jrvx.json @@ -7,12 +7,8 @@ "CVE-2020-2499" ], "details": "A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwv4-f9xf-wp89/GHSA-fwv4-f9xf-wp89.json b/advisories/unreviewed/2022/05/GHSA-fwv4-f9xf-wp89/GHSA-fwv4-f9xf-wp89.json index 54652d10eba..74a1b18a526 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwv4-f9xf-wp89/GHSA-fwv4-f9xf-wp89.json +++ b/advisories/unreviewed/2022/05/GHSA-fwv4-f9xf-wp89/GHSA-fwv4-f9xf-wp89.json @@ -7,12 +7,8 @@ "CVE-2020-24676" ], "details": "In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwxv-g739-m9fm/GHSA-fwxv-g739-m9fm.json b/advisories/unreviewed/2022/05/GHSA-fwxv-g739-m9fm/GHSA-fwxv-g739-m9fm.json index f62f69d9aa7..4a40e4ccb97 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwxv-g739-m9fm/GHSA-fwxv-g739-m9fm.json +++ b/advisories/unreviewed/2022/05/GHSA-fwxv-g739-m9fm/GHSA-fwxv-g739-m9fm.json @@ -7,12 +7,8 @@ "CVE-2020-25196" ], "details": "The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxv5-3xrg-jgx5/GHSA-fxv5-3xrg-jgx5.json b/advisories/unreviewed/2022/05/GHSA-fxv5-3xrg-jgx5/GHSA-fxv5-3xrg-jgx5.json index b1acd3401dc..9b69bca53b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxv5-3xrg-jgx5/GHSA-fxv5-3xrg-jgx5.json +++ b/advisories/unreviewed/2022/05/GHSA-fxv5-3xrg-jgx5/GHSA-fxv5-3xrg-jgx5.json @@ -7,12 +7,8 @@ "CVE-2020-5635" ], "details": "Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2ff-qw45-v2q6/GHSA-g2ff-qw45-v2q6.json b/advisories/unreviewed/2022/05/GHSA-g2ff-qw45-v2q6/GHSA-g2ff-qw45-v2q6.json index b661b05d7d6..f3ca4575448 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2ff-qw45-v2q6/GHSA-g2ff-qw45-v2q6.json +++ b/advisories/unreviewed/2022/05/GHSA-g2ff-qw45-v2q6/GHSA-g2ff-qw45-v2q6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g3q9-p77m-rp7m/GHSA-g3q9-p77m-rp7m.json b/advisories/unreviewed/2022/05/GHSA-g3q9-p77m-rp7m/GHSA-g3q9-p77m-rp7m.json index 490c669b83a..a60fbb5477c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3q9-p77m-rp7m/GHSA-g3q9-p77m-rp7m.json +++ b/advisories/unreviewed/2022/05/GHSA-g3q9-p77m-rp7m/GHSA-g3q9-p77m-rp7m.json @@ -7,12 +7,8 @@ "CVE-2020-35677" ], "details": "BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEditGroup.php to create a new group, resulting in Stored XSS. The caveat here is that an attacker would need administrative privileges in order to create the payload. One might think this completely mitigates the privilege-escalation impact as there is only one high-privileged role. However, it was discovered that the endpoint responsible for creating the group lacks CSRF protection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g49q-m8rg-qhw4/GHSA-g49q-m8rg-qhw4.json b/advisories/unreviewed/2022/05/GHSA-g49q-m8rg-qhw4/GHSA-g49q-m8rg-qhw4.json index f66c6f75529..f323afbdaf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-g49q-m8rg-qhw4/GHSA-g49q-m8rg-qhw4.json +++ b/advisories/unreviewed/2022/05/GHSA-g49q-m8rg-qhw4/GHSA-g49q-m8rg-qhw4.json @@ -7,12 +7,8 @@ "CVE-2020-28856" ], "details": "OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6c2-ghr3-xmvw/GHSA-g6c2-ghr3-xmvw.json b/advisories/unreviewed/2022/05/GHSA-g6c2-ghr3-xmvw/GHSA-g6c2-ghr3-xmvw.json index 093f9ac124d..369f55e2385 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6c2-ghr3-xmvw/GHSA-g6c2-ghr3-xmvw.json +++ b/advisories/unreviewed/2022/05/GHSA-g6c2-ghr3-xmvw/GHSA-g6c2-ghr3-xmvw.json @@ -7,12 +7,8 @@ "CVE-2020-9200" ], "details": "There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g79x-g6g2-hc4x/GHSA-g79x-g6g2-hc4x.json b/advisories/unreviewed/2022/05/GHSA-g79x-g6g2-hc4x/GHSA-g79x-g6g2-hc4x.json index 91ebdbc49dc..bd16db01382 100644 --- a/advisories/unreviewed/2022/05/GHSA-g79x-g6g2-hc4x/GHSA-g79x-g6g2-hc4x.json +++ b/advisories/unreviewed/2022/05/GHSA-g79x-g6g2-hc4x/GHSA-g79x-g6g2-hc4x.json @@ -7,12 +7,8 @@ "CVE-2020-0469" ], "details": "In addEscrowToken of LockSettingsService.java, there is a possible loss of the synthetic password due to logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168692734", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7v3-hrfv-mjj2/GHSA-g7v3-hrfv-mjj2.json b/advisories/unreviewed/2022/05/GHSA-g7v3-hrfv-mjj2/GHSA-g7v3-hrfv-mjj2.json index c1ee867c74a..9b40b916d46 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7v3-hrfv-mjj2/GHSA-g7v3-hrfv-mjj2.json +++ b/advisories/unreviewed/2022/05/GHSA-g7v3-hrfv-mjj2/GHSA-g7v3-hrfv-mjj2.json @@ -7,12 +7,8 @@ "CVE-2020-4829" ], "details": "IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root privileges. IBM X-Force ID: 189960.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g85v-4g67-6899/GHSA-g85v-4g67-6899.json b/advisories/unreviewed/2022/05/GHSA-g85v-4g67-6899/GHSA-g85v-4g67-6899.json index 6aeb579baaf..aeb19e858a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g85v-4g67-6899/GHSA-g85v-4g67-6899.json +++ b/advisories/unreviewed/2022/05/GHSA-g85v-4g67-6899/GHSA-g85v-4g67-6899.json @@ -7,12 +7,8 @@ "CVE-2020-24340" ], "details": "An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The code that processes DNS responses in pico_mdns_handle_data_as_answers_generic() in pico_mdns.c does not check whether the number of answers/responses specified in a DNS packet header corresponds to the response data available in the packet, leading to an out-of-bounds read, invalid pointer dereference, and Denial-of-Service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g862-hhr5-33gv/GHSA-g862-hhr5-33gv.json b/advisories/unreviewed/2022/05/GHSA-g862-hhr5-33gv/GHSA-g862-hhr5-33gv.json index 45a87f2f1d6..82fd0b03e08 100644 --- a/advisories/unreviewed/2022/05/GHSA-g862-hhr5-33gv/GHSA-g862-hhr5-33gv.json +++ b/advisories/unreviewed/2022/05/GHSA-g862-hhr5-33gv/GHSA-g862-hhr5-33gv.json @@ -7,12 +7,8 @@ "CVE-2020-26174" ], "details": "tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction is enforced in the browser (client-side) and can be circumvented. This allows an attacker to upload any file as an attachment to a workitem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8q3-jq94-7x7p/GHSA-g8q3-jq94-7x7p.json b/advisories/unreviewed/2022/05/GHSA-g8q3-jq94-7x7p/GHSA-g8q3-jq94-7x7p.json index 390a9613464..a83d35b230b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8q3-jq94-7x7p/GHSA-g8q3-jq94-7x7p.json +++ b/advisories/unreviewed/2022/05/GHSA-g8q3-jq94-7x7p/GHSA-g8q3-jq94-7x7p.json @@ -7,12 +7,8 @@ "CVE-2020-14231" ], "details": "A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g929-vm5v-86gq/GHSA-g929-vm5v-86gq.json b/advisories/unreviewed/2022/05/GHSA-g929-vm5v-86gq/GHSA-g929-vm5v-86gq.json index b6877eb8652..b00a018bca8 100644 --- a/advisories/unreviewed/2022/05/GHSA-g929-vm5v-86gq/GHSA-g929-vm5v-86gq.json +++ b/advisories/unreviewed/2022/05/GHSA-g929-vm5v-86gq/GHSA-g929-vm5v-86gq.json @@ -7,12 +7,8 @@ "CVE-2020-26028" ], "details": "An issue was discovered in Zammad before 3.4.1. Admin Users without a ticket.* permission can access Tickets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf85-jmcw-8cmh/GHSA-gf85-jmcw-8cmh.json b/advisories/unreviewed/2022/05/GHSA-gf85-jmcw-8cmh/GHSA-gf85-jmcw-8cmh.json index d6f2180fad1..e7202269888 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf85-jmcw-8cmh/GHSA-gf85-jmcw-8cmh.json +++ b/advisories/unreviewed/2022/05/GHSA-gf85-jmcw-8cmh/GHSA-gf85-jmcw-8cmh.json @@ -7,12 +7,8 @@ "CVE-2020-4849" ], "details": "IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 190294.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfrg-r8xw-vpm9/GHSA-gfrg-r8xw-vpm9.json b/advisories/unreviewed/2022/05/GHSA-gfrg-r8xw-vpm9/GHSA-gfrg-r8xw-vpm9.json index 0d6b7cc1e3e..52b798c3ba2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfrg-r8xw-vpm9/GHSA-gfrg-r8xw-vpm9.json +++ b/advisories/unreviewed/2022/05/GHSA-gfrg-r8xw-vpm9/GHSA-gfrg-r8xw-vpm9.json @@ -7,12 +7,8 @@ "CVE-2020-25619" ], "details": "An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH feature (port forwarding with a temporary key pair) to access network services on the 127.0.0.1 interface, even though this feature was only intended for user-to-agent communication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gg22-v8g3-2r42/GHSA-gg22-v8g3-2r42.json b/advisories/unreviewed/2022/05/GHSA-gg22-v8g3-2r42/GHSA-gg22-v8g3-2r42.json index 1be7a2f432d..cc7fd8941b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg22-v8g3-2r42/GHSA-gg22-v8g3-2r42.json +++ b/advisories/unreviewed/2022/05/GHSA-gg22-v8g3-2r42/GHSA-gg22-v8g3-2r42.json @@ -7,12 +7,8 @@ "CVE-2020-4842" ], "details": "IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190046.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggc7-6cvg-qp72/GHSA-ggc7-6cvg-qp72.json b/advisories/unreviewed/2022/05/GHSA-ggc7-6cvg-qp72/GHSA-ggc7-6cvg-qp72.json index 7b5c22b25d8..972edf7172b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggc7-6cvg-qp72/GHSA-ggc7-6cvg-qp72.json +++ b/advisories/unreviewed/2022/05/GHSA-ggc7-6cvg-qp72/GHSA-ggc7-6cvg-qp72.json @@ -7,12 +7,8 @@ "CVE-2020-28184" ], "details": "Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggjq-g68v-5f3p/GHSA-ggjq-g68v-5f3p.json b/advisories/unreviewed/2022/05/GHSA-ggjq-g68v-5f3p/GHSA-ggjq-g68v-5f3p.json index 4966fcc9711..38e426c74fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggjq-g68v-5f3p/GHSA-ggjq-g68v-5f3p.json +++ b/advisories/unreviewed/2022/05/GHSA-ggjq-g68v-5f3p/GHSA-ggjq-g68v-5f3p.json @@ -7,12 +7,8 @@ "CVE-2020-27029" ], "details": "In TextView of TextView.java, there is a possible app hang due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-140218875", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggrx-w8hv-q97q/GHSA-ggrx-w8hv-q97q.json b/advisories/unreviewed/2022/05/GHSA-ggrx-w8hv-q97q/GHSA-ggrx-w8hv-q97q.json index 68b7b4267d1..530da6b2d9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggrx-w8hv-q97q/GHSA-ggrx-w8hv-q97q.json +++ b/advisories/unreviewed/2022/05/GHSA-ggrx-w8hv-q97q/GHSA-ggrx-w8hv-q97q.json @@ -7,12 +7,8 @@ "CVE-2020-27026" ], "details": "During boot, the device unlock interface behaves differently depending on if a fingerprint registered to the device is present. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-79776455", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggxv-vqqm-7f4w/GHSA-ggxv-vqqm-7f4w.json b/advisories/unreviewed/2022/05/GHSA-ggxv-vqqm-7f4w/GHSA-ggxv-vqqm-7f4w.json index aadc87cc5c0..089a19c04ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggxv-vqqm-7f4w/GHSA-ggxv-vqqm-7f4w.json +++ b/advisories/unreviewed/2022/05/GHSA-ggxv-vqqm-7f4w/GHSA-ggxv-vqqm-7f4w.json @@ -7,12 +7,8 @@ "CVE-2020-28216" ], "details": "A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghgp-g2w8-92pm/GHSA-ghgp-g2w8-92pm.json b/advisories/unreviewed/2022/05/GHSA-ghgp-g2w8-92pm/GHSA-ghgp-g2w8-92pm.json index 6a0f4f07f04..93d26c65d92 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghgp-g2w8-92pm/GHSA-ghgp-g2w8-92pm.json +++ b/advisories/unreviewed/2022/05/GHSA-ghgp-g2w8-92pm/GHSA-ghgp-g2w8-92pm.json @@ -7,12 +7,8 @@ "CVE-2020-27067" ], "details": "In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-152409173", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghj2-hfg6-h8j7/GHSA-ghj2-hfg6-h8j7.json b/advisories/unreviewed/2022/05/GHSA-ghj2-hfg6-h8j7/GHSA-ghj2-hfg6-h8j7.json index 7c91f8a27b6..1ea029d098e 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghj2-hfg6-h8j7/GHSA-ghj2-hfg6-h8j7.json +++ b/advisories/unreviewed/2022/05/GHSA-ghj2-hfg6-h8j7/GHSA-ghj2-hfg6-h8j7.json @@ -7,12 +7,8 @@ "CVE-2020-35816" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghvp-76xv-fjr5/GHSA-ghvp-76xv-fjr5.json b/advisories/unreviewed/2022/05/GHSA-ghvp-76xv-fjr5/GHSA-ghvp-76xv-fjr5.json index 96e78145b3a..9a4b6773b53 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghvp-76xv-fjr5/GHSA-ghvp-76xv-fjr5.json +++ b/advisories/unreviewed/2022/05/GHSA-ghvp-76xv-fjr5/GHSA-ghvp-76xv-fjr5.json @@ -7,12 +7,8 @@ "CVE-2020-20189" ], "details": "SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\\newpost.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gj9f-3v8v-xvvr/GHSA-gj9f-3v8v-xvvr.json b/advisories/unreviewed/2022/05/GHSA-gj9f-3v8v-xvvr/GHSA-gj9f-3v8v-xvvr.json index 7b8cd241574..fdb0caf1f05 100644 --- a/advisories/unreviewed/2022/05/GHSA-gj9f-3v8v-xvvr/GHSA-gj9f-3v8v-xvvr.json +++ b/advisories/unreviewed/2022/05/GHSA-gj9f-3v8v-xvvr/GHSA-gj9f-3v8v-xvvr.json @@ -7,12 +7,8 @@ "CVE-2020-17443" ], "details": "An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6 echo request packet's size is shorter than 8 bytes. If the size of the incoming ICMPv6 request packet is shorter than this, the operation that calculates the size of the ICMPv6 echo replies has an integer wrap around, leading to memory corruption and, eventually, Denial-of-Service in pico_icmp6_send_echoreply_not_frag in pico_icmp6.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjfx-fqhh-mx8f/GHSA-gjfx-fqhh-mx8f.json b/advisories/unreviewed/2022/05/GHSA-gjfx-fqhh-mx8f/GHSA-gjfx-fqhh-mx8f.json index 04cbb6e5a9b..1a51d616a04 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjfx-fqhh-mx8f/GHSA-gjfx-fqhh-mx8f.json +++ b/advisories/unreviewed/2022/05/GHSA-gjfx-fqhh-mx8f/GHSA-gjfx-fqhh-mx8f.json @@ -7,12 +7,8 @@ "CVE-2020-8257" ], "details": "Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjv5-9xrv-6pww/GHSA-gjv5-9xrv-6pww.json b/advisories/unreviewed/2022/05/GHSA-gjv5-9xrv-6pww/GHSA-gjv5-9xrv-6pww.json index f199381f541..934acb46467 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjv5-9xrv-6pww/GHSA-gjv5-9xrv-6pww.json +++ b/advisories/unreviewed/2022/05/GHSA-gjv5-9xrv-6pww/GHSA-gjv5-9xrv-6pww.json @@ -7,12 +7,8 @@ "CVE-2020-25066" ], "details": "A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmgc-2jr6-mv52/GHSA-gmgc-2jr6-mv52.json b/advisories/unreviewed/2022/05/GHSA-gmgc-2jr6-mv52/GHSA-gmgc-2jr6-mv52.json index 0ee68921b4d..123a770c718 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmgc-2jr6-mv52/GHSA-gmgc-2jr6-mv52.json +++ b/advisories/unreviewed/2022/05/GHSA-gmgc-2jr6-mv52/GHSA-gmgc-2jr6-mv52.json @@ -7,12 +7,8 @@ "CVE-2020-35197" ], "details": "The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmqq-hrf4-4gvf/GHSA-gmqq-hrf4-4gvf.json b/advisories/unreviewed/2022/05/GHSA-gmqq-hrf4-4gvf/GHSA-gmqq-hrf4-4gvf.json index e1fa4e9a81a..bf358ebd8e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmqq-hrf4-4gvf/GHSA-gmqq-hrf4-4gvf.json +++ b/advisories/unreviewed/2022/05/GHSA-gmqq-hrf4-4gvf/GHSA-gmqq-hrf4-4gvf.json @@ -7,12 +7,8 @@ "CVE-2020-27718" ], "details": "When a BIG-IP ASM or Advanced WAF system running version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, or 11.6.1-11.6.5.2 processes requests with JSON payload, an unusually large number of parameters can cause excessive CPU usage in the BIG-IP ASM bd process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqq8-4hgw-g2fp/GHSA-gqq8-4hgw-g2fp.json b/advisories/unreviewed/2022/05/GHSA-gqq8-4hgw-g2fp/GHSA-gqq8-4hgw-g2fp.json index 8e332ac7b4b..acd7d703877 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqq8-4hgw-g2fp/GHSA-gqq8-4hgw-g2fp.json +++ b/advisories/unreviewed/2022/05/GHSA-gqq8-4hgw-g2fp/GHSA-gqq8-4hgw-g2fp.json @@ -7,12 +7,8 @@ "CVE-2020-4908" ], "details": "IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the login dialog. This information could be used in further attacks against the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grmh-7h5f-7q6v/GHSA-grmh-7h5f-7q6v.json b/advisories/unreviewed/2022/05/GHSA-grmh-7h5f-7q6v/GHSA-grmh-7h5f-7q6v.json index 0e3c127fbae..f118e944c80 100644 --- a/advisories/unreviewed/2022/05/GHSA-grmh-7h5f-7q6v/GHSA-grmh-7h5f-7q6v.json +++ b/advisories/unreviewed/2022/05/GHSA-grmh-7h5f-7q6v/GHSA-grmh-7h5f-7q6v.json @@ -7,12 +7,8 @@ "CVE-2020-35252" ], "details": "Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv37-4vjv-96xm/GHSA-gv37-4vjv-96xm.json b/advisories/unreviewed/2022/05/GHSA-gv37-4vjv-96xm/GHSA-gv37-4vjv-96xm.json index 344d045385e..0f458287f9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv37-4vjv-96xm/GHSA-gv37-4vjv-96xm.json +++ b/advisories/unreviewed/2022/05/GHSA-gv37-4vjv-96xm/GHSA-gv37-4vjv-96xm.json @@ -7,12 +7,8 @@ "CVE-2020-35551" ], "details": "An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a related issue to CVE-2020-13799. The Samsung ID is SVE-2020-18100 (December 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv8v-gq5v-5rpc/GHSA-gv8v-gq5v-5rpc.json b/advisories/unreviewed/2022/05/GHSA-gv8v-gq5v-5rpc/GHSA-gv8v-gq5v-5rpc.json index e678fa82f89..21d94fefc65 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv8v-gq5v-5rpc/GHSA-gv8v-gq5v-5rpc.json +++ b/advisories/unreviewed/2022/05/GHSA-gv8v-gq5v-5rpc/GHSA-gv8v-gq5v-5rpc.json @@ -7,12 +7,8 @@ "CVE-2020-20300" ], "details": "SQL injection vulnerability in the wp_where function in WeiPHP 5.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gv97-chp3-8xhh/GHSA-gv97-chp3-8xhh.json b/advisories/unreviewed/2022/05/GHSA-gv97-chp3-8xhh/GHSA-gv97-chp3-8xhh.json index 859308d106b..e9ecbc6e21f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gv97-chp3-8xhh/GHSA-gv97-chp3-8xhh.json +++ b/advisories/unreviewed/2022/05/GHSA-gv97-chp3-8xhh/GHSA-gv97-chp3-8xhh.json @@ -7,12 +7,8 @@ "CVE-2020-27147" ], "details": "The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretically allows an unauthenticated attacker with network access to obtain an authenticated login URL for the affected system via a REST API. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: version 6.2.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gvhj-p52g-rhm3/GHSA-gvhj-p52g-rhm3.json b/advisories/unreviewed/2022/05/GHSA-gvhj-p52g-rhm3/GHSA-gvhj-p52g-rhm3.json index 9e564a6c169..36a9a797e12 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvhj-p52g-rhm3/GHSA-gvhj-p52g-rhm3.json +++ b/advisories/unreviewed/2022/05/GHSA-gvhj-p52g-rhm3/GHSA-gvhj-p52g-rhm3.json @@ -7,12 +7,8 @@ "CVE-2020-27057" ], "details": "In getGpuStatsGlobalInfo and getGpuStatsAppInfo of GpuService.cpp, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of gpu statistics with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-161903239", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gw7h-3fw6-97j4/GHSA-gw7h-3fw6-97j4.json b/advisories/unreviewed/2022/05/GHSA-gw7h-3fw6-97j4/GHSA-gw7h-3fw6-97j4.json index e7935268823..94be47059e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw7h-3fw6-97j4/GHSA-gw7h-3fw6-97j4.json +++ b/advisories/unreviewed/2022/05/GHSA-gw7h-3fw6-97j4/GHSA-gw7h-3fw6-97j4.json @@ -7,12 +7,8 @@ "CVE-2020-28930" ], "details": "A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is executed by an administrator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwg7-mp6r-mj4h/GHSA-gwg7-mp6r-mj4h.json b/advisories/unreviewed/2022/05/GHSA-gwg7-mp6r-mj4h/GHSA-gwg7-mp6r-mj4h.json index 4b82b95b9ea..005c12ec4b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwg7-mp6r-mj4h/GHSA-gwg7-mp6r-mj4h.json +++ b/advisories/unreviewed/2022/05/GHSA-gwg7-mp6r-mj4h/GHSA-gwg7-mp6r-mj4h.json @@ -7,12 +7,8 @@ "CVE-2020-28857" ], "details": "OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gwhr-c723-m8fm/GHSA-gwhr-c723-m8fm.json b/advisories/unreviewed/2022/05/GHSA-gwhr-c723-m8fm/GHSA-gwhr-c723-m8fm.json index 47c81f3f17e..260087d7d49 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwhr-c723-m8fm/GHSA-gwhr-c723-m8fm.json +++ b/advisories/unreviewed/2022/05/GHSA-gwhr-c723-m8fm/GHSA-gwhr-c723-m8fm.json @@ -7,12 +7,8 @@ "CVE-2020-35545" ], "details": "Time-based SQL injection exists in Spotweb 1.4.9 via the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx57-8c8v-6mj6/GHSA-gx57-8c8v-6mj6.json b/advisories/unreviewed/2022/05/GHSA-gx57-8c8v-6mj6/GHSA-gx57-8c8v-6mj6.json index 3eb7072fd0c..4c2540cc736 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx57-8c8v-6mj6/GHSA-gx57-8c8v-6mj6.json +++ b/advisories/unreviewed/2022/05/GHSA-gx57-8c8v-6mj6/GHSA-gx57-8c8v-6mj6.json @@ -7,12 +7,8 @@ "CVE-2020-35284" ], "details": "Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; however, this computation occurs on the client side, and the computation details can be easily determined because the product's source code is available.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxgw-6q4v-hcj8/GHSA-gxgw-6q4v-hcj8.json b/advisories/unreviewed/2022/05/GHSA-gxgw-6q4v-hcj8/GHSA-gxgw-6q4v-hcj8.json index 66245c2e98d..17b92e2e27d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxgw-6q4v-hcj8/GHSA-gxgw-6q4v-hcj8.json +++ b/advisories/unreviewed/2022/05/GHSA-gxgw-6q4v-hcj8/GHSA-gxgw-6q4v-hcj8.json @@ -7,12 +7,8 @@ "CVE-2020-27687" ], "details": "ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxhq-4chx-5r72/GHSA-gxhq-4chx-5r72.json b/advisories/unreviewed/2022/05/GHSA-gxhq-4chx-5r72/GHSA-gxhq-4chx-5r72.json index c29851e8865..7bf2329c30a 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxhq-4chx-5r72/GHSA-gxhq-4chx-5r72.json +++ b/advisories/unreviewed/2022/05/GHSA-gxhq-4chx-5r72/GHSA-gxhq-4chx-5r72.json @@ -7,12 +7,8 @@ "CVE-2020-9202" ], "details": "There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attacker can gain information in the victim's device to launch the attack, successful exploit could cause information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h237-f2vg-f29q/GHSA-h237-f2vg-f29q.json b/advisories/unreviewed/2022/05/GHSA-h237-f2vg-f29q/GHSA-h237-f2vg-f29q.json index cdb71ef43e8..6bdc0ea5766 100644 --- a/advisories/unreviewed/2022/05/GHSA-h237-f2vg-f29q/GHSA-h237-f2vg-f29q.json +++ b/advisories/unreviewed/2022/05/GHSA-h237-f2vg-f29q/GHSA-h237-f2vg-f29q.json @@ -7,12 +7,8 @@ "CVE-2020-25190" ], "details": "The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h273-mwpm-4f8q/GHSA-h273-mwpm-4f8q.json b/advisories/unreviewed/2022/05/GHSA-h273-mwpm-4f8q/GHSA-h273-mwpm-4f8q.json index 584cf133931..eabea589a67 100644 --- a/advisories/unreviewed/2022/05/GHSA-h273-mwpm-4f8q/GHSA-h273-mwpm-4f8q.json +++ b/advisories/unreviewed/2022/05/GHSA-h273-mwpm-4f8q/GHSA-h273-mwpm-4f8q.json @@ -7,12 +7,8 @@ "CVE-2020-35803" ], "details": "Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.46, R6080 before 1.0.0.46, R6120 before 1.0.0.72, R6220 before 1.1.0.100, R6230 before 1.1.0.100, R6260 before 1.1.0.76, R6700v2 before 1.2.0.74, R6800 before 1.2.0.74, R6900v2 before 1.2.0.74, R7450 before 1.2.0.74, AC2100 before 1.2.0.74, AC2400 before 1.2.0.74, and AC2600 before 1.2.0.74.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2x8-6h3c-4jp7/GHSA-h2x8-6h3c-4jp7.json b/advisories/unreviewed/2022/05/GHSA-h2x8-6h3c-4jp7/GHSA-h2x8-6h3c-4jp7.json index f9c5c95cb94..260d9f5c708 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2x8-6h3c-4jp7/GHSA-h2x8-6h3c-4jp7.json +++ b/advisories/unreviewed/2022/05/GHSA-h2x8-6h3c-4jp7/GHSA-h2x8-6h3c-4jp7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h3v7-cvf6-7jhw/GHSA-h3v7-cvf6-7jhw.json b/advisories/unreviewed/2022/05/GHSA-h3v7-cvf6-7jhw/GHSA-h3v7-cvf6-7jhw.json index 10ac14fd1a9..7eb4399c687 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3v7-cvf6-7jhw/GHSA-h3v7-cvf6-7jhw.json +++ b/advisories/unreviewed/2022/05/GHSA-h3v7-cvf6-7jhw/GHSA-h3v7-cvf6-7jhw.json @@ -7,12 +7,8 @@ "CVE-2020-25610" ], "details": "The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6fg-hfp3-3883/GHSA-h6fg-hfp3-3883.json b/advisories/unreviewed/2022/05/GHSA-h6fg-hfp3-3883/GHSA-h6fg-hfp3-3883.json index e1a8f1af585..cf64bceb9bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6fg-hfp3-3883/GHSA-h6fg-hfp3-3883.json +++ b/advisories/unreviewed/2022/05/GHSA-h6fg-hfp3-3883/GHSA-h6fg-hfp3-3883.json @@ -7,12 +7,8 @@ "CVE-2020-27722" ], "details": "In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-control protocol causing excessive resource consumption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6g5-q5mh-3mg9/GHSA-h6g5-q5mh-3mg9.json b/advisories/unreviewed/2022/05/GHSA-h6g5-q5mh-3mg9/GHSA-h6g5-q5mh-3mg9.json index f79b2bee5dd..313f4ee9665 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6g5-q5mh-3mg9/GHSA-h6g5-q5mh-3mg9.json +++ b/advisories/unreviewed/2022/05/GHSA-h6g5-q5mh-3mg9/GHSA-h6g5-q5mh-3mg9.json @@ -7,12 +7,8 @@ "CVE-2019-14481" ], "details": "AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to account takeover.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h79q-qqcc-qw9h/GHSA-h79q-qqcc-qw9h.json b/advisories/unreviewed/2022/05/GHSA-h79q-qqcc-qw9h/GHSA-h79q-qqcc-qw9h.json index 08882ae0f0c..dcdadbe9f80 100644 --- a/advisories/unreviewed/2022/05/GHSA-h79q-qqcc-qw9h/GHSA-h79q-qqcc-qw9h.json +++ b/advisories/unreviewed/2022/05/GHSA-h79q-qqcc-qw9h/GHSA-h79q-qqcc-qw9h.json @@ -7,12 +7,8 @@ "CVE-2020-27030" ], "details": "In onCreate of HandleApiCalls.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege that allows an app to set or dismiss the alarm with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150612638", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7g5-p978-f45g/GHSA-h7g5-p978-f45g.json b/advisories/unreviewed/2022/05/GHSA-h7g5-p978-f45g/GHSA-h7g5-p978-f45g.json index e4c63596b03..c77daeeea5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7g5-p978-f45g/GHSA-h7g5-p978-f45g.json +++ b/advisories/unreviewed/2022/05/GHSA-h7g5-p978-f45g/GHSA-h7g5-p978-f45g.json @@ -7,12 +7,8 @@ "CVE-2020-28641" ], "details": "In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h877-6h9f-xm6f/GHSA-h877-6h9f-xm6f.json b/advisories/unreviewed/2022/05/GHSA-h877-6h9f-xm6f/GHSA-h877-6h9f-xm6f.json index 53eaecbd38e..6345c223ef7 100644 --- a/advisories/unreviewed/2022/05/GHSA-h877-6h9f-xm6f/GHSA-h877-6h9f-xm6f.json +++ b/advisories/unreviewed/2022/05/GHSA-h877-6h9f-xm6f/GHSA-h877-6h9f-xm6f.json @@ -7,12 +7,8 @@ "CVE-2020-27053" ], "details": "In broadcastWifiCredentialChanged of ClientModeImpl.java, there is a possible location permission bypass due to a missing permission check. This could lead to local information disclosure of the WiFi network name with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-159371448", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h88c-j84g-842h/GHSA-h88c-j84g-842h.json b/advisories/unreviewed/2022/05/GHSA-h88c-j84g-842h/GHSA-h88c-j84g-842h.json index 23982559040..2810247bfe0 100644 --- a/advisories/unreviewed/2022/05/GHSA-h88c-j84g-842h/GHSA-h88c-j84g-842h.json +++ b/advisories/unreviewed/2022/05/GHSA-h88c-j84g-842h/GHSA-h88c-j84g-842h.json @@ -7,12 +7,8 @@ "CVE-2020-29480" ], "details": "An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for every created, modified, and deleted key. A guest administrator can also use the special watches, which will cause a notification every time a domain is created and destroyed. Data may include: number, type, and domids of other VMs; existence and domids of driver domains; numbers of virtual interfaces, block devices, vcpus; existence of virtual framebuffers and their backend style (e.g., existence of VNC service); Xen VM UUIDs for other domains; timing information about domain creation and device setup; and some hints at the backend provisioning of VMs and their devices. The watch events do not contain values stored in xenstore, only key names. A guest administrator can observe non-sensitive domain and device lifecycle events relating to other guests. This information allows some insight into overall system configuration (including the number and general nature of other guests), and configuration of other guests (including the number and general nature of other guests' devices). This information might be commercially interesting or might make other attacks easier. There is not believed to be exposure of sensitive data. Specifically, there is no exposure of VNC passwords, port numbers, pathnames in host and guest filesystems, cryptographic keys, or within-guest data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8pv-pv44-xcvw/GHSA-h8pv-pv44-xcvw.json b/advisories/unreviewed/2022/05/GHSA-h8pv-pv44-xcvw/GHSA-h8pv-pv44-xcvw.json index d86f2877d3e..c1bd95f7b44 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8pv-pv44-xcvw/GHSA-h8pv-pv44-xcvw.json +++ b/advisories/unreviewed/2022/05/GHSA-h8pv-pv44-xcvw/GHSA-h8pv-pv44-xcvw.json @@ -7,12 +7,8 @@ "CVE-2020-35615" ], "details": "An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9fm-r36v-gmw8/GHSA-h9fm-r36v-gmw8.json b/advisories/unreviewed/2022/05/GHSA-h9fm-r36v-gmw8/GHSA-h9fm-r36v-gmw8.json index 5f34e6e8d67..15df69e1662 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9fm-r36v-gmw8/GHSA-h9fm-r36v-gmw8.json +++ b/advisories/unreviewed/2022/05/GHSA-h9fm-r36v-gmw8/GHSA-h9fm-r36v-gmw8.json @@ -7,12 +7,8 @@ "CVE-2020-29247" ], "details": "WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, and the attacker can able to steal the cookie according to the crafted payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9gg-fc6x-px6c/GHSA-h9gg-fc6x-px6c.json b/advisories/unreviewed/2022/05/GHSA-h9gg-fc6x-px6c/GHSA-h9gg-fc6x-px6c.json index 57352069f1d..bde2e88d6c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9gg-fc6x-px6c/GHSA-h9gg-fc6x-px6c.json +++ b/advisories/unreviewed/2022/05/GHSA-h9gg-fc6x-px6c/GHSA-h9gg-fc6x-px6c.json @@ -7,12 +7,8 @@ "CVE-2020-26416" ], "details": "Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcq4-pg2q-469j/GHSA-hcq4-pg2q-469j.json b/advisories/unreviewed/2022/05/GHSA-hcq4-pg2q-469j/GHSA-hcq4-pg2q-469j.json index 49c19723b5b..aa1b0031912 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcq4-pg2q-469j/GHSA-hcq4-pg2q-469j.json +++ b/advisories/unreviewed/2022/05/GHSA-hcq4-pg2q-469j/GHSA-hcq4-pg2q-469j.json @@ -7,12 +7,8 @@ "CVE-2020-25622" ], "details": "An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcv9-p733-v9fh/GHSA-hcv9-p733-v9fh.json b/advisories/unreviewed/2022/05/GHSA-hcv9-p733-v9fh/GHSA-hcv9-p733-v9fh.json index 0dfa1f6a109..8ff3b6a2093 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcv9-p733-v9fh/GHSA-hcv9-p733-v9fh.json +++ b/advisories/unreviewed/2022/05/GHSA-hcv9-p733-v9fh/GHSA-hcv9-p733-v9fh.json @@ -7,12 +7,8 @@ "CVE-2020-9120" ], "details": "CloudEngine 1800V versions V100R019C10SPC500 has a resource management error vulnerability. Remote unauthorized attackers could send specific types of messages to the device, resulting in the message received by the system can't be forwarded normally.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hf7v-pc2m-3mm9/GHSA-hf7v-pc2m-3mm9.json b/advisories/unreviewed/2022/05/GHSA-hf7v-pc2m-3mm9/GHSA-hf7v-pc2m-3mm9.json index ba8483ec70f..a5d5c4f55d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf7v-pc2m-3mm9/GHSA-hf7v-pc2m-3mm9.json +++ b/advisories/unreviewed/2022/05/GHSA-hf7v-pc2m-3mm9/GHSA-hf7v-pc2m-3mm9.json @@ -7,12 +7,8 @@ "CVE-2020-35780" ], "details": "NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hgpc-4547-p5wm/GHSA-hgpc-4547-p5wm.json b/advisories/unreviewed/2022/05/GHSA-hgpc-4547-p5wm/GHSA-hgpc-4547-p5wm.json index 7112188635d..232d8dc6755 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgpc-4547-p5wm/GHSA-hgpc-4547-p5wm.json +++ b/advisories/unreviewed/2022/05/GHSA-hgpc-4547-p5wm/GHSA-hgpc-4547-p5wm.json @@ -7,12 +7,8 @@ "CVE-2020-28217" ], "details": "A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hh5h-m6rg-25r6/GHSA-hh5h-m6rg-25r6.json b/advisories/unreviewed/2022/05/GHSA-hh5h-m6rg-25r6/GHSA-hh5h-m6rg-25r6.json index 8873b4d538c..211545ca6a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh5h-m6rg-25r6/GHSA-hh5h-m6rg-25r6.json +++ b/advisories/unreviewed/2022/05/GHSA-hh5h-m6rg-25r6/GHSA-hh5h-m6rg-25r6.json @@ -7,12 +7,8 @@ "CVE-2020-27028" ], "details": "In filter_incoming_event of hci_layer.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-141618611", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hh5m-6r25-ccqm/GHSA-hh5m-6r25-ccqm.json b/advisories/unreviewed/2022/05/GHSA-hh5m-6r25-ccqm/GHSA-hh5m-6r25-ccqm.json index 59e4051048c..0f48ec4e35e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh5m-6r25-ccqm/GHSA-hh5m-6r25-ccqm.json +++ b/advisories/unreviewed/2022/05/GHSA-hh5m-6r25-ccqm/GHSA-hh5m-6r25-ccqm.json @@ -7,12 +7,8 @@ "CVE-2020-29158" ], "details": "An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjwx-j74m-7j88/GHSA-hjwx-j74m-7j88.json b/advisories/unreviewed/2022/05/GHSA-hjwx-j74m-7j88/GHSA-hjwx-j74m-7j88.json index bf7a27c8c89..5ac61a4f100 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjwx-j74m-7j88/GHSA-hjwx-j74m-7j88.json +++ b/advisories/unreviewed/2022/05/GHSA-hjwx-j74m-7j88/GHSA-hjwx-j74m-7j88.json @@ -7,12 +7,8 @@ "CVE-2020-35707" ], "details": "Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjx4-ghxm-xpj2/GHSA-hjx4-ghxm-xpj2.json b/advisories/unreviewed/2022/05/GHSA-hjx4-ghxm-xpj2/GHSA-hjx4-ghxm-xpj2.json index dfe015dd769..6ad93d29f70 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjx4-ghxm-xpj2/GHSA-hjx4-ghxm-xpj2.json +++ b/advisories/unreviewed/2022/05/GHSA-hjx4-ghxm-xpj2/GHSA-hjx4-ghxm-xpj2.json @@ -7,12 +7,8 @@ "CVE-2020-26178" ], "details": "In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hmm3-wj4g-8w8g/GHSA-hmm3-wj4g-8w8g.json b/advisories/unreviewed/2022/05/GHSA-hmm3-wj4g-8w8g/GHSA-hmm3-wj4g-8w8g.json index 17c483edbf5..4ad473bdf68 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmm3-wj4g-8w8g/GHSA-hmm3-wj4g-8w8g.json +++ b/advisories/unreviewed/2022/05/GHSA-hmm3-wj4g-8w8g/GHSA-hmm3-wj4g-8w8g.json @@ -7,12 +7,8 @@ "CVE-2020-27340" ], "details": "The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hp39-4vrr-9cjg/GHSA-hp39-4vrr-9cjg.json b/advisories/unreviewed/2022/05/GHSA-hp39-4vrr-9cjg/GHSA-hp39-4vrr-9cjg.json index 45956902653..6dbcacbbddc 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp39-4vrr-9cjg/GHSA-hp39-4vrr-9cjg.json +++ b/advisories/unreviewed/2022/05/GHSA-hp39-4vrr-9cjg/GHSA-hp39-4vrr-9cjg.json @@ -7,12 +7,8 @@ "CVE-2020-27720" ], "details": "On BIG-IP LTM/CGNAT version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.5, when processing NAT66 traffic with Port Block Allocation (PBA) mode and SP-DAG enabled, and dag-ipv6-prefix-len configured with a value less than the default of 128, an undisclosed traffic pattern may cause the Traffic Management Microkernel (TMM) to restart.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp87-jr7m-7m74/GHSA-hp87-jr7m-7m74.json b/advisories/unreviewed/2022/05/GHSA-hp87-jr7m-7m74/GHSA-hp87-jr7m-7m74.json index 207a5ceb307..33ea68ac54a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp87-jr7m-7m74/GHSA-hp87-jr7m-7m74.json +++ b/advisories/unreviewed/2022/05/GHSA-hp87-jr7m-7m74/GHSA-hp87-jr7m-7m74.json @@ -7,12 +7,8 @@ "CVE-2020-35794" ], "details": "Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBS40V before 2.6.1.4, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpmf-2v4h-c97c/GHSA-hpmf-2v4h-c97c.json b/advisories/unreviewed/2022/05/GHSA-hpmf-2v4h-c97c/GHSA-hpmf-2v4h-c97c.json index d2b56c41b13..970e601c2aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpmf-2v4h-c97c/GHSA-hpmf-2v4h-c97c.json +++ b/advisories/unreviewed/2022/05/GHSA-hpmf-2v4h-c97c/GHSA-hpmf-2v4h-c97c.json @@ -7,12 +7,8 @@ "CVE-2020-5360" ], "details": "Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hprx-w65c-9mfp/GHSA-hprx-w65c-9mfp.json b/advisories/unreviewed/2022/05/GHSA-hprx-w65c-9mfp/GHSA-hprx-w65c-9mfp.json index b612d21292d..f407ce8a2bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-hprx-w65c-9mfp/GHSA-hprx-w65c-9mfp.json +++ b/advisories/unreviewed/2022/05/GHSA-hprx-w65c-9mfp/GHSA-hprx-w65c-9mfp.json @@ -7,12 +7,8 @@ "CVE-2020-25231" ], "details": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The encryption of program data for the affected devices uses a static key. An attacker could use this key to extract confidential information from protected program files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hq6f-9m26-g47r/GHSA-hq6f-9m26-g47r.json b/advisories/unreviewed/2022/05/GHSA-hq6f-9m26-g47r/GHSA-hq6f-9m26-g47r.json index 7487d15da56..4126fef0390 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq6f-9m26-g47r/GHSA-hq6f-9m26-g47r.json +++ b/advisories/unreviewed/2022/05/GHSA-hq6f-9m26-g47r/GHSA-hq6f-9m26-g47r.json @@ -7,12 +7,8 @@ "CVE-2020-35575" ], "details": "A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqcf-3xgv-jcpv/GHSA-hqcf-3xgv-jcpv.json b/advisories/unreviewed/2022/05/GHSA-hqcf-3xgv-jcpv/GHSA-hqcf-3xgv-jcpv.json index e4536f4a54f..fd003fc0977 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqcf-3xgv-jcpv/GHSA-hqcf-3xgv-jcpv.json +++ b/advisories/unreviewed/2022/05/GHSA-hqcf-3xgv-jcpv/GHSA-hqcf-3xgv-jcpv.json @@ -7,12 +7,8 @@ "CVE-2020-35614" ], "details": "An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hqqw-v7w4-65wv/GHSA-hqqw-v7w4-65wv.json b/advisories/unreviewed/2022/05/GHSA-hqqw-v7w4-65wv/GHSA-hqqw-v7w4-65wv.json index a83eca12e10..177b28ef525 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqqw-v7w4-65wv/GHSA-hqqw-v7w4-65wv.json +++ b/advisories/unreviewed/2022/05/GHSA-hqqw-v7w4-65wv/GHSA-hqqw-v7w4-65wv.json @@ -7,12 +7,8 @@ "CVE-2020-24447" ], "details": "Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw26-j6mr-8w28/GHSA-hw26-j6mr-8w28.json b/advisories/unreviewed/2022/05/GHSA-hw26-j6mr-8w28/GHSA-hw26-j6mr-8w28.json index 25e09c2df94..8561ed6437f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw26-j6mr-8w28/GHSA-hw26-j6mr-8w28.json +++ b/advisories/unreviewed/2022/05/GHSA-hw26-j6mr-8w28/GHSA-hw26-j6mr-8w28.json @@ -7,12 +7,8 @@ "CVE-2020-35468" ], "details": "The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwm9-775j-vf84/GHSA-hwm9-775j-vf84.json b/advisories/unreviewed/2022/05/GHSA-hwm9-775j-vf84/GHSA-hwm9-775j-vf84.json index 8beb8e7e59c..218883100c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwm9-775j-vf84/GHSA-hwm9-775j-vf84.json +++ b/advisories/unreviewed/2022/05/GHSA-hwm9-775j-vf84/GHSA-hwm9-775j-vf84.json @@ -7,12 +7,8 @@ "CVE-2020-12517" ], "details": "On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx2g-vqw8-rh9r/GHSA-hx2g-vqw8-rh9r.json b/advisories/unreviewed/2022/05/GHSA-hx2g-vqw8-rh9r/GHSA-hx2g-vqw8-rh9r.json index f6e65493850..83dc7e65385 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx2g-vqw8-rh9r/GHSA-hx2g-vqw8-rh9r.json +++ b/advisories/unreviewed/2022/05/GHSA-hx2g-vqw8-rh9r/GHSA-hx2g-vqw8-rh9r.json @@ -7,12 +7,8 @@ "CVE-2020-35370" ], "details": "A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can login as \"admin\", then to modify specific shell file to achieve remote code execution(RCE) on the hosting server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx68-cxw3-7prp/GHSA-hx68-cxw3-7prp.json b/advisories/unreviewed/2022/05/GHSA-hx68-cxw3-7prp/GHSA-hx68-cxw3-7prp.json index 0bc38e9db7d..b45a6a8d9ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx68-cxw3-7prp/GHSA-hx68-cxw3-7prp.json +++ b/advisories/unreviewed/2022/05/GHSA-hx68-cxw3-7prp/GHSA-hx68-cxw3-7prp.json @@ -7,12 +7,8 @@ "CVE-2020-11718" ], "details": "An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2w6-g3jh-8g4x/GHSA-j2w6-g3jh-8g4x.json b/advisories/unreviewed/2022/05/GHSA-j2w6-g3jh-8g4x/GHSA-j2w6-g3jh-8g4x.json index 99411962758..f1a6e3ab089 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2w6-g3jh-8g4x/GHSA-j2w6-g3jh-8g4x.json +++ b/advisories/unreviewed/2022/05/GHSA-j2w6-g3jh-8g4x/GHSA-j2w6-g3jh-8g4x.json @@ -7,12 +7,8 @@ "CVE-2020-5803" ], "details": "Relative Path Traversal in Marvell QConvergeConsole GUI 5.5.0.74 allows a remote, authenticated attacker to delete arbitrary files on disk as SYSTEM or root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2wg-wfjw-m5cq/GHSA-j2wg-wfjw-m5cq.json b/advisories/unreviewed/2022/05/GHSA-j2wg-wfjw-m5cq/GHSA-j2wg-wfjw-m5cq.json index cc2abecae07..3ead49e993a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2wg-wfjw-m5cq/GHSA-j2wg-wfjw-m5cq.json +++ b/advisories/unreviewed/2022/05/GHSA-j2wg-wfjw-m5cq/GHSA-j2wg-wfjw-m5cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j39w-7p3g-g389/GHSA-j39w-7p3g-g389.json b/advisories/unreviewed/2022/05/GHSA-j39w-7p3g-g389/GHSA-j39w-7p3g-g389.json index 6755745fbc7..d1a5efb2cab 100644 --- a/advisories/unreviewed/2022/05/GHSA-j39w-7p3g-g389/GHSA-j39w-7p3g-g389.json +++ b/advisories/unreviewed/2022/05/GHSA-j39w-7p3g-g389/GHSA-j39w-7p3g-g389.json @@ -7,12 +7,8 @@ "CVE-2020-35813" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, XR700 before 1.0.1.10, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, XR500 before 2.3.2.56, and RAX120 before 1.0.0.78.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j3w6-mx9r-j6qp/GHSA-j3w6-mx9r-j6qp.json b/advisories/unreviewed/2022/05/GHSA-j3w6-mx9r-j6qp/GHSA-j3w6-mx9r-j6qp.json index 61356638a45..948aaaf79a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3w6-mx9r-j6qp/GHSA-j3w6-mx9r-j6qp.json +++ b/advisories/unreviewed/2022/05/GHSA-j3w6-mx9r-j6qp/GHSA-j3w6-mx9r-j6qp.json @@ -7,12 +7,8 @@ "CVE-2020-20184" ], "details": "GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j42c-839r-f79f/GHSA-j42c-839r-f79f.json b/advisories/unreviewed/2022/05/GHSA-j42c-839r-f79f/GHSA-j42c-839r-f79f.json index 2fbea32ed70..ed0c8425441 100644 --- a/advisories/unreviewed/2022/05/GHSA-j42c-839r-f79f/GHSA-j42c-839r-f79f.json +++ b/advisories/unreviewed/2022/05/GHSA-j42c-839r-f79f/GHSA-j42c-839r-f79f.json @@ -7,12 +7,8 @@ "CVE-2020-8941" ], "details": "An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_inet_pton using an attacker controlled klinux_addr_buffer parameter. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading past commit 8fed5e334131abaf9c5e17307642fbf6ce4a57ec", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j42v-fg25-q7fp/GHSA-j42v-fg25-q7fp.json b/advisories/unreviewed/2022/05/GHSA-j42v-fg25-q7fp/GHSA-j42v-fg25-q7fp.json index e63ae7a9d4e..34a7d4a4da8 100644 --- a/advisories/unreviewed/2022/05/GHSA-j42v-fg25-q7fp/GHSA-j42v-fg25-q7fp.json +++ b/advisories/unreviewed/2022/05/GHSA-j42v-fg25-q7fp/GHSA-j42v-fg25-q7fp.json @@ -7,12 +7,8 @@ "CVE-2020-26408" ], "details": "A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j564-pmx9-wqcj/GHSA-j564-pmx9-wqcj.json b/advisories/unreviewed/2022/05/GHSA-j564-pmx9-wqcj/GHSA-j564-pmx9-wqcj.json index 6c97762ad99..3b3200799cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-j564-pmx9-wqcj/GHSA-j564-pmx9-wqcj.json +++ b/advisories/unreviewed/2022/05/GHSA-j564-pmx9-wqcj/GHSA-j564-pmx9-wqcj.json @@ -7,12 +7,8 @@ "CVE-2020-14248" ], "details": "BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5gx-c23h-6w7f/GHSA-j5gx-c23h-6w7f.json b/advisories/unreviewed/2022/05/GHSA-j5gx-c23h-6w7f/GHSA-j5gx-c23h-6w7f.json index 7f5d5b7e1ae..f26d87a1b5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5gx-c23h-6w7f/GHSA-j5gx-c23h-6w7f.json +++ b/advisories/unreviewed/2022/05/GHSA-j5gx-c23h-6w7f/GHSA-j5gx-c23h-6w7f.json @@ -7,12 +7,8 @@ "CVE-2020-35668" ], "details": "RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as an alias that has not yet been introduced.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5q4-h79w-mh86/GHSA-j5q4-h79w-mh86.json b/advisories/unreviewed/2022/05/GHSA-j5q4-h79w-mh86/GHSA-j5q4-h79w-mh86.json index a6d797e6c8b..09469717e48 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5q4-h79w-mh86/GHSA-j5q4-h79w-mh86.json +++ b/advisories/unreviewed/2022/05/GHSA-j5q4-h79w-mh86/GHSA-j5q4-h79w-mh86.json @@ -7,12 +7,8 @@ "CVE-2020-24679" ], "details": "A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j67r-w3x2-72vq/GHSA-j67r-w3x2-72vq.json b/advisories/unreviewed/2022/05/GHSA-j67r-w3x2-72vq/GHSA-j67r-w3x2-72vq.json index bb6e760bc1f..8cc6ed7a825 100644 --- a/advisories/unreviewed/2022/05/GHSA-j67r-w3x2-72vq/GHSA-j67r-w3x2-72vq.json +++ b/advisories/unreviewed/2022/05/GHSA-j67r-w3x2-72vq/GHSA-j67r-w3x2-72vq.json @@ -7,12 +7,8 @@ "CVE-2020-0479" ], "details": "In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malicious app to access files available to the DocumentProvider without user permission, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157294893", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6h5-jcwm-38vr/GHSA-j6h5-jcwm-38vr.json b/advisories/unreviewed/2022/05/GHSA-j6h5-jcwm-38vr/GHSA-j6h5-jcwm-38vr.json index 9a58d869a65..3e180012acc 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6h5-jcwm-38vr/GHSA-j6h5-jcwm-38vr.json +++ b/advisories/unreviewed/2022/05/GHSA-j6h5-jcwm-38vr/GHSA-j6h5-jcwm-38vr.json @@ -7,12 +7,8 @@ "CVE-2020-26413" ], "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6hf-ffpw-242h/GHSA-j6hf-ffpw-242h.json b/advisories/unreviewed/2022/05/GHSA-j6hf-ffpw-242h/GHSA-j6hf-ffpw-242h.json index 3f1af39a63b..d440c805729 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6hf-ffpw-242h/GHSA-j6hf-ffpw-242h.json +++ b/advisories/unreviewed/2022/05/GHSA-j6hf-ffpw-242h/GHSA-j6hf-ffpw-242h.json @@ -7,12 +7,8 @@ "CVE-2020-27039" ], "details": "In postNotification of ServiceRecord.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153878498", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j892-5fgm-v8hw/GHSA-j892-5fgm-v8hw.json b/advisories/unreviewed/2022/05/GHSA-j892-5fgm-v8hw/GHSA-j892-5fgm-v8hw.json index c0ec1e1a930..474ca19ad5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j892-5fgm-v8hw/GHSA-j892-5fgm-v8hw.json +++ b/advisories/unreviewed/2022/05/GHSA-j892-5fgm-v8hw/GHSA-j892-5fgm-v8hw.json @@ -7,12 +7,8 @@ "CVE-2020-25233" ], "details": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The firmware update of affected devices contains the private RSA key that is used as a basis for encryption of communication with the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8h5-g58p-q4rv/GHSA-j8h5-g58p-q4rv.json b/advisories/unreviewed/2022/05/GHSA-j8h5-g58p-q4rv/GHSA-j8h5-g58p-q4rv.json index 020fda5435a..ed1515d8a3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8h5-g58p-q4rv/GHSA-j8h5-g58p-q4rv.json +++ b/advisories/unreviewed/2022/05/GHSA-j8h5-g58p-q4rv/GHSA-j8h5-g58p-q4rv.json @@ -7,12 +7,8 @@ "CVE-2020-25112" ], "details": "An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths. This leads to Denial-of-Service and potential Remote Code Execution via a crafted ICMPv6 echo packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8r2-275f-f2p3/GHSA-j8r2-275f-f2p3.json b/advisories/unreviewed/2022/05/GHSA-j8r2-275f-f2p3/GHSA-j8r2-275f-f2p3.json index 2f7f4dc6679..82d520d9d7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8r2-275f-f2p3/GHSA-j8r2-275f-f2p3.json +++ b/advisories/unreviewed/2022/05/GHSA-j8r2-275f-f2p3/GHSA-j8r2-275f-f2p3.json @@ -7,12 +7,8 @@ "CVE-2018-15641" ], "details": "Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8r6-c45m-jv6q/GHSA-j8r6-c45m-jv6q.json b/advisories/unreviewed/2022/05/GHSA-j8r6-c45m-jv6q/GHSA-j8r6-c45m-jv6q.json index 0a26e57eaeb..ef3b44b3561 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8r6-c45m-jv6q/GHSA-j8r6-c45m-jv6q.json +++ b/advisories/unreviewed/2022/05/GHSA-j8r6-c45m-jv6q/GHSA-j8r6-c45m-jv6q.json @@ -7,12 +7,8 @@ "CVE-2020-35782" ], "details": "Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j93q-24g6-27r6/GHSA-j93q-24g6-27r6.json b/advisories/unreviewed/2022/05/GHSA-j93q-24g6-27r6/GHSA-j93q-24g6-27r6.json index a0e4fdedc94..eb7a5ab633e 100644 --- a/advisories/unreviewed/2022/05/GHSA-j93q-24g6-27r6/GHSA-j93q-24g6-27r6.json +++ b/advisories/unreviewed/2022/05/GHSA-j93q-24g6-27r6/GHSA-j93q-24g6-27r6.json @@ -7,12 +7,8 @@ "CVE-2020-35489" ], "details": "The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc86-jrjv-444j/GHSA-jc86-jrjv-444j.json b/advisories/unreviewed/2022/05/GHSA-jc86-jrjv-444j/GHSA-jc86-jrjv-444j.json index 3190068fde7..29312b074bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc86-jrjv-444j/GHSA-jc86-jrjv-444j.json +++ b/advisories/unreviewed/2022/05/GHSA-jc86-jrjv-444j/GHSA-jc86-jrjv-444j.json @@ -7,12 +7,8 @@ "CVE-2020-2504" ], "details": "If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcff-w8hg-gx77/GHSA-jcff-w8hg-gx77.json b/advisories/unreviewed/2022/05/GHSA-jcff-w8hg-gx77/GHSA-jcff-w8hg-gx77.json index 91d55615807..152f8666eb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcff-w8hg-gx77/GHSA-jcff-w8hg-gx77.json +++ b/advisories/unreviewed/2022/05/GHSA-jcff-w8hg-gx77/GHSA-jcff-w8hg-gx77.json @@ -7,12 +7,8 @@ "CVE-2020-29228" ], "details": "EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jcvw-97mh-q338/GHSA-jcvw-97mh-q338.json b/advisories/unreviewed/2022/05/GHSA-jcvw-97mh-q338/GHSA-jcvw-97mh-q338.json index c8a60e5a644..fb24e5313e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcvw-97mh-q338/GHSA-jcvw-97mh-q338.json +++ b/advisories/unreviewed/2022/05/GHSA-jcvw-97mh-q338/GHSA-jcvw-97mh-q338.json @@ -7,12 +7,8 @@ "CVE-2020-27040" ], "details": "In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153731880", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhpp-6c5p-c4vj/GHSA-jhpp-6c5p-c4vj.json b/advisories/unreviewed/2022/05/GHSA-jhpp-6c5p-c4vj/GHSA-jhpp-6c5p-c4vj.json index fb3d899dffe..66dd70e8192 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhpp-6c5p-c4vj/GHSA-jhpp-6c5p-c4vj.json +++ b/advisories/unreviewed/2022/05/GHSA-jhpp-6c5p-c4vj/GHSA-jhpp-6c5p-c4vj.json @@ -7,12 +7,8 @@ "CVE-2020-8943" ], "details": "An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvfrom whose return size was not validated against the requested size. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading past commit 6e158d558abd3c29a0208e30c97c9a8c5bd4230f", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jhv2-rwmc-cjh9/GHSA-jhv2-rwmc-cjh9.json b/advisories/unreviewed/2022/05/GHSA-jhv2-rwmc-cjh9/GHSA-jhv2-rwmc-cjh9.json index d72479415b0..dee453b6837 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhv2-rwmc-cjh9/GHSA-jhv2-rwmc-cjh9.json +++ b/advisories/unreviewed/2022/05/GHSA-jhv2-rwmc-cjh9/GHSA-jhv2-rwmc-cjh9.json @@ -7,12 +7,8 @@ "CVE-2020-35469" ], "details": "The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS container may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jj37-qmmg-fmgp/GHSA-jj37-qmmg-fmgp.json b/advisories/unreviewed/2022/05/GHSA-jj37-qmmg-fmgp/GHSA-jj37-qmmg-fmgp.json index 94d85d9a0c5..0e572b5b86d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj37-qmmg-fmgp/GHSA-jj37-qmmg-fmgp.json +++ b/advisories/unreviewed/2022/05/GHSA-jj37-qmmg-fmgp/GHSA-jj37-qmmg-fmgp.json @@ -7,12 +7,8 @@ "CVE-2020-26172" ], "details": "Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not contain an expiration timestamp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jm5h-3x78-fpg8/GHSA-jm5h-3x78-fpg8.json b/advisories/unreviewed/2022/05/GHSA-jm5h-3x78-fpg8/GHSA-jm5h-3x78-fpg8.json index f5c06e44e2b..7a3fc50f829 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm5h-3x78-fpg8/GHSA-jm5h-3x78-fpg8.json +++ b/advisories/unreviewed/2022/05/GHSA-jm5h-3x78-fpg8/GHSA-jm5h-3x78-fpg8.json @@ -7,12 +7,8 @@ "CVE-2019-11786" ], "details": "Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jmfv-2476-jhcq/GHSA-jmfv-2476-jhcq.json b/advisories/unreviewed/2022/05/GHSA-jmfv-2476-jhcq/GHSA-jmfv-2476-jhcq.json index ee891688e43..1895bce117c 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmfv-2476-jhcq/GHSA-jmfv-2476-jhcq.json +++ b/advisories/unreviewed/2022/05/GHSA-jmfv-2476-jhcq/GHSA-jmfv-2476-jhcq.json @@ -7,12 +7,8 @@ "CVE-2020-29227" ], "details": "An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the \"page\" parameter, to cause local file inclusion resulting in code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jmxf-gfr2-rfwj/GHSA-jmxf-gfr2-rfwj.json b/advisories/unreviewed/2022/05/GHSA-jmxf-gfr2-rfwj/GHSA-jmxf-gfr2-rfwj.json index 063a9e08e74..8c92ddb1aad 100644 --- a/advisories/unreviewed/2022/05/GHSA-jmxf-gfr2-rfwj/GHSA-jmxf-gfr2-rfwj.json +++ b/advisories/unreviewed/2022/05/GHSA-jmxf-gfr2-rfwj/GHSA-jmxf-gfr2-rfwj.json @@ -7,12 +7,8 @@ "CVE-2020-9439" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows authenticated remote attackers to inject arbitrary web script or HTML via the search_key GET Parameter in TinCan_Content_List_Table.php, message GET Parameter in licensing.php, tc_filter_group parameter in reporting-admin-menu.php, tc_filter_user parameter in reporting-admin-menu.php, tc_filter_course parameter in reporting-admin-menu.php, tc_filter_lesson parameter in reporting-admin-menu.php, tc_filter_module parameter in reporting-admin-menu.php, tc_filter_action parameter in reporting-admin-menu.php, tc_filter_data_range parameter in reporting-admin-menu.php, or tc_filter_data_range_last parameter in reporting-admin-menu.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp62-q2mj-vpxc/GHSA-jp62-q2mj-vpxc.json b/advisories/unreviewed/2022/05/GHSA-jp62-q2mj-vpxc/GHSA-jp62-q2mj-vpxc.json index 14f7da3eca4..cdd71457a70 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp62-q2mj-vpxc/GHSA-jp62-q2mj-vpxc.json +++ b/advisories/unreviewed/2022/05/GHSA-jp62-q2mj-vpxc/GHSA-jp62-q2mj-vpxc.json @@ -7,12 +7,8 @@ "CVE-2020-8995" ], "details": "Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jpx3-8xrf-jxhx/GHSA-jpx3-8xrf-jxhx.json b/advisories/unreviewed/2022/05/GHSA-jpx3-8xrf-jxhx/GHSA-jpx3-8xrf-jxhx.json index ee30c0db889..632514bc911 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpx3-8xrf-jxhx/GHSA-jpx3-8xrf-jxhx.json +++ b/advisories/unreviewed/2022/05/GHSA-jpx3-8xrf-jxhx/GHSA-jpx3-8xrf-jxhx.json @@ -7,12 +7,8 @@ "CVE-2020-4764" ], "details": "IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 188898.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq8v-8c7p-26p2/GHSA-jq8v-8c7p-26p2.json b/advisories/unreviewed/2022/05/GHSA-jq8v-8c7p-26p2/GHSA-jq8v-8c7p-26p2.json index a2fc357340e..0f04bfa6876 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq8v-8c7p-26p2/GHSA-jq8v-8c7p-26p2.json +++ b/advisories/unreviewed/2022/05/GHSA-jq8v-8c7p-26p2/GHSA-jq8v-8c7p-26p2.json @@ -7,12 +7,8 @@ "CVE-2020-4794" ], "details": "IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqm2-jgff-xhhh/GHSA-jqm2-jgff-xhhh.json b/advisories/unreviewed/2022/05/GHSA-jqm2-jgff-xhhh/GHSA-jqm2-jgff-xhhh.json index 4649eb2ca20..5379aec6611 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqm2-jgff-xhhh/GHSA-jqm2-jgff-xhhh.json +++ b/advisories/unreviewed/2022/05/GHSA-jqm2-jgff-xhhh/GHSA-jqm2-jgff-xhhh.json @@ -7,12 +7,8 @@ "CVE-2020-7535" ], "details": "A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of information when sending a specially crafted request to the controller over HTTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jr5f-4v8f-4m67/GHSA-jr5f-4v8f-4m67.json b/advisories/unreviewed/2022/05/GHSA-jr5f-4v8f-4m67/GHSA-jr5f-4v8f-4m67.json index 32243d700d2..2a43c7f66f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr5f-4v8f-4m67/GHSA-jr5f-4v8f-4m67.json +++ b/advisories/unreviewed/2022/05/GHSA-jr5f-4v8f-4m67/GHSA-jr5f-4v8f-4m67.json @@ -7,12 +7,8 @@ "CVE-2018-15632" ], "details": "Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrq7-2cwg-jfgc/GHSA-jrq7-2cwg-jfgc.json b/advisories/unreviewed/2022/05/GHSA-jrq7-2cwg-jfgc/GHSA-jrq7-2cwg-jfgc.json index a5c986275db..0774ce28796 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrq7-2cwg-jfgc/GHSA-jrq7-2cwg-jfgc.json +++ b/advisories/unreviewed/2022/05/GHSA-jrq7-2cwg-jfgc/GHSA-jrq7-2cwg-jfgc.json @@ -7,12 +7,8 @@ "CVE-2020-35798" ], "details": "Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900 before 1.0.4.26, R7960P before 1.4.1.50, R8000 before 1.0.4.52, R7900P before 1.4.1.50, R8000P before 1.4.1.50, RAX15 before 1.0.1.64, RAX20 before 1.0.1.64, RAX200 before 1.0.1.12, RAX45 before 1.0.2.66, RAX50 before 1.0.2.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, RBS850 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RS400 before 1.5.0.48, and XR300 before 1.0.3.50.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvq7-w5fg-7qjh/GHSA-jvq7-w5fg-7qjh.json b/advisories/unreviewed/2022/05/GHSA-jvq7-w5fg-7qjh/GHSA-jvq7-w5fg-7qjh.json index b44c1c65260..ec535bc59ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvq7-w5fg-7qjh/GHSA-jvq7-w5fg-7qjh.json +++ b/advisories/unreviewed/2022/05/GHSA-jvq7-w5fg-7qjh/GHSA-jvq7-w5fg-7qjh.json @@ -7,12 +7,8 @@ "CVE-2020-35786" ], "details": "NETGEAR R7800 devices before 1.0.2.74 are affected by a buffer overflow by an authenticated user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvqg-jjfg-vv75/GHSA-jvqg-jjfg-vv75.json b/advisories/unreviewed/2022/05/GHSA-jvqg-jjfg-vv75/GHSA-jvqg-jjfg-vv75.json index 5338bfe6819..2bf54392499 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvqg-jjfg-vv75/GHSA-jvqg-jjfg-vv75.json +++ b/advisories/unreviewed/2022/05/GHSA-jvqg-jjfg-vv75/GHSA-jvqg-jjfg-vv75.json @@ -7,12 +7,8 @@ "CVE-2020-20298" ], "details": "Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvr7-4f7q-4v6w/GHSA-jvr7-4f7q-4v6w.json b/advisories/unreviewed/2022/05/GHSA-jvr7-4f7q-4v6w/GHSA-jvr7-4f7q-4v6w.json index 9371f692b04..0ab05ad704d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvr7-4f7q-4v6w/GHSA-jvr7-4f7q-4v6w.json +++ b/advisories/unreviewed/2022/05/GHSA-jvr7-4f7q-4v6w/GHSA-jvr7-4f7q-4v6w.json @@ -7,12 +7,8 @@ "CVE-2020-4642" ], "details": "IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the \"DB2 Management Service\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jvvx-4fhr-xxqv/GHSA-jvvx-4fhr-xxqv.json b/advisories/unreviewed/2022/05/GHSA-jvvx-4fhr-xxqv/GHSA-jvvx-4fhr-xxqv.json index 4051e2dd2d3..37898de0fec 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvvx-4fhr-xxqv/GHSA-jvvx-4fhr-xxqv.json +++ b/advisories/unreviewed/2022/05/GHSA-jvvx-4fhr-xxqv/GHSA-jvvx-4fhr-xxqv.json @@ -7,12 +7,8 @@ "CVE-2020-35123" ], "details": "In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxgf-p2mp-g2wx/GHSA-jxgf-p2mp-g2wx.json b/advisories/unreviewed/2022/05/GHSA-jxgf-p2mp-g2wx/GHSA-jxgf-p2mp-g2wx.json index 8a1d3ee9415..3d8adc4269b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxgf-p2mp-g2wx/GHSA-jxgf-p2mp-g2wx.json +++ b/advisories/unreviewed/2022/05/GHSA-jxgf-p2mp-g2wx/GHSA-jxgf-p2mp-g2wx.json @@ -7,12 +7,8 @@ "CVE-2020-35791" ], "details": "Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.68, R8900 before 1.0.5.2, and R9000 before 1.0.5.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m37h-4w48-299w/GHSA-m37h-4w48-299w.json b/advisories/unreviewed/2022/05/GHSA-m37h-4w48-299w/GHSA-m37h-4w48-299w.json index 2a5a6e93267..6951d997d6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m37h-4w48-299w/GHSA-m37h-4w48-299w.json +++ b/advisories/unreviewed/2022/05/GHSA-m37h-4w48-299w/GHSA-m37h-4w48-299w.json @@ -7,12 +7,8 @@ "CVE-2020-27724" ], "details": "In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may consume excessive resources by sending specially-crafted malicious traffic over the tunnel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3j9-2rhw-rjxm/GHSA-m3j9-2rhw-rjxm.json b/advisories/unreviewed/2022/05/GHSA-m3j9-2rhw-rjxm/GHSA-m3j9-2rhw-rjxm.json index a6d6263554e..e0690c1d64d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3j9-2rhw-rjxm/GHSA-m3j9-2rhw-rjxm.json +++ b/advisories/unreviewed/2022/05/GHSA-m3j9-2rhw-rjxm/GHSA-m3j9-2rhw-rjxm.json @@ -7,12 +7,8 @@ "CVE-2020-27021" ], "details": "In avrc_ctrl_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168712245", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4c5-25qf-rmm3/GHSA-m4c5-25qf-rmm3.json b/advisories/unreviewed/2022/05/GHSA-m4c5-25qf-rmm3/GHSA-m4c5-25qf-rmm3.json index fdbf5151d39..b3096b0b6d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4c5-25qf-rmm3/GHSA-m4c5-25qf-rmm3.json +++ b/advisories/unreviewed/2022/05/GHSA-m4c5-25qf-rmm3/GHSA-m4c5-25qf-rmm3.json @@ -7,12 +7,8 @@ "CVE-2019-19287" ], "details": "A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow attackers to traverse through the file system of the server based by sending specially crafted packets over the network without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4f9-7fgw-p5j8/GHSA-m4f9-7fgw-p5j8.json b/advisories/unreviewed/2022/05/GHSA-m4f9-7fgw-p5j8/GHSA-m4f9-7fgw-p5j8.json index e0db3e47e75..29340799d1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4f9-7fgw-p5j8/GHSA-m4f9-7fgw-p5j8.json +++ b/advisories/unreviewed/2022/05/GHSA-m4f9-7fgw-p5j8/GHSA-m4f9-7fgw-p5j8.json @@ -7,12 +7,8 @@ "CVE-2020-27132" ], "details": "Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4hr-5jvh-hpgq/GHSA-m4hr-5jvh-hpgq.json b/advisories/unreviewed/2022/05/GHSA-m4hr-5jvh-hpgq/GHSA-m4hr-5jvh-hpgq.json index e674300f254..fd12e28fcbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4hr-5jvh-hpgq/GHSA-m4hr-5jvh-hpgq.json +++ b/advisories/unreviewed/2022/05/GHSA-m4hr-5jvh-hpgq/GHSA-m4hr-5jvh-hpgq.json @@ -7,12 +7,8 @@ "CVE-2018-16243" ], "details": "SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m53v-fcjx-mpcr/GHSA-m53v-fcjx-mpcr.json b/advisories/unreviewed/2022/05/GHSA-m53v-fcjx-mpcr/GHSA-m53v-fcjx-mpcr.json index d958ecbf098..bb07d656460 100644 --- a/advisories/unreviewed/2022/05/GHSA-m53v-fcjx-mpcr/GHSA-m53v-fcjx-mpcr.json +++ b/advisories/unreviewed/2022/05/GHSA-m53v-fcjx-mpcr/GHSA-m53v-fcjx-mpcr.json @@ -7,12 +7,8 @@ "CVE-2020-35788" ], "details": "NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m6v6-xwrv-hp92/GHSA-m6v6-xwrv-hp92.json b/advisories/unreviewed/2022/05/GHSA-m6v6-xwrv-hp92/GHSA-m6v6-xwrv-hp92.json index 018531a6c51..7af672fdf98 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6v6-xwrv-hp92/GHSA-m6v6-xwrv-hp92.json +++ b/advisories/unreviewed/2022/05/GHSA-m6v6-xwrv-hp92/GHSA-m6v6-xwrv-hp92.json @@ -7,12 +7,8 @@ "CVE-2020-24680" ], "details": "In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m78f-9p7v-48h9/GHSA-m78f-9p7v-48h9.json b/advisories/unreviewed/2022/05/GHSA-m78f-9p7v-48h9/GHSA-m78f-9p7v-48h9.json index 09de0c1071f..0d7b37d7faa 100644 --- a/advisories/unreviewed/2022/05/GHSA-m78f-9p7v-48h9/GHSA-m78f-9p7v-48h9.json +++ b/advisories/unreviewed/2022/05/GHSA-m78f-9p7v-48h9/GHSA-m78f-9p7v-48h9.json @@ -7,12 +7,8 @@ "CVE-2020-27023" ], "details": "In setErrorPlaybackState of BluetoothMediaBrowserService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156009462", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7h8-8q5m-8g9r/GHSA-m7h8-8q5m-8g9r.json b/advisories/unreviewed/2022/05/GHSA-m7h8-8q5m-8g9r/GHSA-m7h8-8q5m-8g9r.json index 96c69575136..2b74f48c8b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7h8-8q5m-8g9r/GHSA-m7h8-8q5m-8g9r.json +++ b/advisories/unreviewed/2022/05/GHSA-m7h8-8q5m-8g9r/GHSA-m7h8-8q5m-8g9r.json @@ -7,12 +7,8 @@ "CVE-2020-25621" ], "details": "An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7wj-9xjx-8vhq/GHSA-m7wj-9xjx-8vhq.json b/advisories/unreviewed/2022/05/GHSA-m7wj-9xjx-8vhq/GHSA-m7wj-9xjx-8vhq.json index 20192a3c6f3..c2323d6a928 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7wj-9xjx-8vhq/GHSA-m7wj-9xjx-8vhq.json +++ b/advisories/unreviewed/2022/05/GHSA-m7wj-9xjx-8vhq/GHSA-m7wj-9xjx-8vhq.json @@ -7,12 +7,8 @@ "CVE-2019-14483" ], "details": "AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private keys, private keys' passwords, and root passwords stored in the credential manager. Every administrator can read the ESX and Windows passwords stored in the credential manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7wp-c8qj-3fpc/GHSA-m7wp-c8qj-3fpc.json b/advisories/unreviewed/2022/05/GHSA-m7wp-c8qj-3fpc/GHSA-m7wp-c8qj-3fpc.json index d5d58039f81..946559fc1ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7wp-c8qj-3fpc/GHSA-m7wp-c8qj-3fpc.json +++ b/advisories/unreviewed/2022/05/GHSA-m7wp-c8qj-3fpc/GHSA-m7wp-c8qj-3fpc.json @@ -7,12 +7,8 @@ "CVE-2020-27027" ], "details": "In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-122358602", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m83f-px8c-c623/GHSA-m83f-px8c-c623.json b/advisories/unreviewed/2022/05/GHSA-m83f-px8c-c623/GHSA-m83f-px8c-c623.json index 008eb658790..b08e4db341d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m83f-px8c-c623/GHSA-m83f-px8c-c623.json +++ b/advisories/unreviewed/2022/05/GHSA-m83f-px8c-c623/GHSA-m83f-px8c-c623.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m845-5gj8-66h2/GHSA-m845-5gj8-66h2.json b/advisories/unreviewed/2022/05/GHSA-m845-5gj8-66h2/GHSA-m845-5gj8-66h2.json index 708c39e96fe..79bf4916e68 100644 --- a/advisories/unreviewed/2022/05/GHSA-m845-5gj8-66h2/GHSA-m845-5gj8-66h2.json +++ b/advisories/unreviewed/2022/05/GHSA-m845-5gj8-66h2/GHSA-m845-5gj8-66h2.json @@ -7,12 +7,8 @@ "CVE-2020-35624" ], "details": "An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m85w-g475-q78j/GHSA-m85w-g475-q78j.json b/advisories/unreviewed/2022/05/GHSA-m85w-g475-q78j/GHSA-m85w-g475-q78j.json index 6d0df41dc1f..acda87bf495 100644 --- a/advisories/unreviewed/2022/05/GHSA-m85w-g475-q78j/GHSA-m85w-g475-q78j.json +++ b/advisories/unreviewed/2022/05/GHSA-m85w-g475-q78j/GHSA-m85w-g475-q78j.json @@ -7,12 +7,8 @@ "CVE-2020-27037" ], "details": "In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153731335", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m89x-hf4g-3j36/GHSA-m89x-hf4g-3j36.json b/advisories/unreviewed/2022/05/GHSA-m89x-hf4g-3j36/GHSA-m89x-hf4g-3j36.json index 4f651d35e03..c8e53da7c2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m89x-hf4g-3j36/GHSA-m89x-hf4g-3j36.json +++ b/advisories/unreviewed/2022/05/GHSA-m89x-hf4g-3j36/GHSA-m89x-hf4g-3j36.json @@ -7,12 +7,8 @@ "CVE-2020-24337" ], "details": "An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. When an unsupported TCP option with zero length is provided in an incoming TCP packet, it is possible to cause a Denial-of-Service by achieving an infinite loop in the code that parses TCP options, aka tcp_parse_options() in pico_tcp.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m944-5qpv-g8wv/GHSA-m944-5qpv-g8wv.json b/advisories/unreviewed/2022/05/GHSA-m944-5qpv-g8wv/GHSA-m944-5qpv-g8wv.json index 220a340044b..1a3e6ebad3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-m944-5qpv-g8wv/GHSA-m944-5qpv-g8wv.json +++ b/advisories/unreviewed/2022/05/GHSA-m944-5qpv-g8wv/GHSA-m944-5qpv-g8wv.json @@ -7,12 +7,8 @@ "CVE-2020-35194" ], "details": "The official influxdb docker images before 1.7.3-meta-alpine (Alpine specific) contain a blank password for a root user. System using the influxdb docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m973-3r23-2c9h/GHSA-m973-3r23-2c9h.json b/advisories/unreviewed/2022/05/GHSA-m973-3r23-2c9h/GHSA-m973-3r23-2c9h.json index d44816f2f78..d4ef098e2be 100644 --- a/advisories/unreviewed/2022/05/GHSA-m973-3r23-2c9h/GHSA-m973-3r23-2c9h.json +++ b/advisories/unreviewed/2022/05/GHSA-m973-3r23-2c9h/GHSA-m973-3r23-2c9h.json @@ -7,12 +7,8 @@ "CVE-2020-19142" ], "details": "iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9j8-w3jp-p7wq/GHSA-m9j8-w3jp-p7wq.json b/advisories/unreviewed/2022/05/GHSA-m9j8-w3jp-p7wq/GHSA-m9j8-w3jp-p7wq.json index 45357f5e702..fd35e796669 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9j8-w3jp-p7wq/GHSA-m9j8-w3jp-p7wq.json +++ b/advisories/unreviewed/2022/05/GHSA-m9j8-w3jp-p7wq/GHSA-m9j8-w3jp-p7wq.json @@ -7,12 +7,8 @@ "CVE-2020-35234" ], "details": "The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m9vx-wm87-mjxm/GHSA-m9vx-wm87-mjxm.json b/advisories/unreviewed/2022/05/GHSA-m9vx-wm87-mjxm/GHSA-m9vx-wm87-mjxm.json index 9076354e9d1..c8941b72669 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9vx-wm87-mjxm/GHSA-m9vx-wm87-mjxm.json +++ b/advisories/unreviewed/2022/05/GHSA-m9vx-wm87-mjxm/GHSA-m9vx-wm87-mjxm.json @@ -7,12 +7,8 @@ "CVE-2020-21377" ], "details": "SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcp4-jxrc-pg4f/GHSA-mcp4-jxrc-pg4f.json b/advisories/unreviewed/2022/05/GHSA-mcp4-jxrc-pg4f/GHSA-mcp4-jxrc-pg4f.json index 10ed22c9fe6..191d8d8f713 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcp4-jxrc-pg4f/GHSA-mcp4-jxrc-pg4f.json +++ b/advisories/unreviewed/2022/05/GHSA-mcp4-jxrc-pg4f/GHSA-mcp4-jxrc-pg4f.json @@ -7,12 +7,8 @@ "CVE-2020-14368" ], "details": "A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE doesn't properly set the SameSite value, allowing a Cross-Site Request Forgery (CSRF) and consequently allowing a cross-site WebSocket hijack on Theia IDE. This flaw allows an attacker to gain full access to the victim's workspace through the /services endpoint. To perform a successful attack, the attacker conducts a Man-in-the-middle attack (MITM) and tricks the victim into executing a request via an untrusted link, which performs the CSRF and the Socket hijack. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mcv5-rv2r-2h7w/GHSA-mcv5-rv2r-2h7w.json b/advisories/unreviewed/2022/05/GHSA-mcv5-rv2r-2h7w/GHSA-mcv5-rv2r-2h7w.json index a049c3f217a..fc57027191e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcv5-rv2r-2h7w/GHSA-mcv5-rv2r-2h7w.json +++ b/advisories/unreviewed/2022/05/GHSA-mcv5-rv2r-2h7w/GHSA-mcv5-rv2r-2h7w.json @@ -7,12 +7,8 @@ "CVE-2019-16957" ], "details": "SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mf95-74qr-37vw/GHSA-mf95-74qr-37vw.json b/advisories/unreviewed/2022/05/GHSA-mf95-74qr-37vw/GHSA-mf95-74qr-37vw.json index e5084ccdd86..e27a16ca46e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mf95-74qr-37vw/GHSA-mf95-74qr-37vw.json +++ b/advisories/unreviewed/2022/05/GHSA-mf95-74qr-37vw/GHSA-mf95-74qr-37vw.json @@ -7,12 +7,8 @@ "CVE-2020-35802" ], "details": "Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.14, RBW30 before 2.6.1.4, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RBK842 before 3.2.16.6, RBR840 before 3.2.16.6, RBS840 before 3.2.16.6, and RBS40V before 2.6.1.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfc8-4qmg-g3x6/GHSA-mfc8-4qmg-g3x6.json b/advisories/unreviewed/2022/05/GHSA-mfc8-4qmg-g3x6/GHSA-mfc8-4qmg-g3x6.json index a69a8da8861..0b3e71d91b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfc8-4qmg-g3x6/GHSA-mfc8-4qmg-g3x6.json +++ b/advisories/unreviewed/2022/05/GHSA-mfc8-4qmg-g3x6/GHSA-mfc8-4qmg-g3x6.json @@ -7,12 +7,8 @@ "CVE-2020-8290" ], "details": "Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mffw-j524-mrjp/GHSA-mffw-j524-mrjp.json b/advisories/unreviewed/2022/05/GHSA-mffw-j524-mrjp/GHSA-mffw-j524-mrjp.json index f958eed59ad..85fc5326a31 100644 --- a/advisories/unreviewed/2022/05/GHSA-mffw-j524-mrjp/GHSA-mffw-j524-mrjp.json +++ b/advisories/unreviewed/2022/05/GHSA-mffw-j524-mrjp/GHSA-mffw-j524-mrjp.json @@ -7,12 +7,8 @@ "CVE-2020-15796" ], "details": "A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500 Software Controller (V20.8). The web server of the affected products contains a vulnerability that could allow a remote attacker to trigger a denial-of-service condition by sending a specially crafted HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfw3-hgv3-pg44/GHSA-mfw3-hgv3-pg44.json b/advisories/unreviewed/2022/05/GHSA-mfw3-hgv3-pg44/GHSA-mfw3-hgv3-pg44.json index 5558e1c9724..6536f60bf9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfw3-hgv3-pg44/GHSA-mfw3-hgv3-pg44.json +++ b/advisories/unreviewed/2022/05/GHSA-mfw3-hgv3-pg44/GHSA-mfw3-hgv3-pg44.json @@ -7,12 +7,8 @@ "CVE-2020-27351" ], "details": "Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfw8-gqh6-9gr8/GHSA-mfw8-gqh6-9gr8.json b/advisories/unreviewed/2022/05/GHSA-mfw8-gqh6-9gr8/GHSA-mfw8-gqh6-9gr8.json index 6307f98c011..fba30910045 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfw8-gqh6-9gr8/GHSA-mfw8-gqh6-9gr8.json +++ b/advisories/unreviewed/2022/05/GHSA-mfw8-gqh6-9gr8/GHSA-mfw8-gqh6-9gr8.json @@ -7,12 +7,8 @@ "CVE-2020-28185" ], "details": "User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mg3m-w94w-vr47/GHSA-mg3m-w94w-vr47.json b/advisories/unreviewed/2022/05/GHSA-mg3m-w94w-vr47/GHSA-mg3m-w94w-vr47.json index 4da3e072b02..311d8a322b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg3m-w94w-vr47/GHSA-mg3m-w94w-vr47.json +++ b/advisories/unreviewed/2022/05/GHSA-mg3m-w94w-vr47/GHSA-mg3m-w94w-vr47.json @@ -7,12 +7,8 @@ "CVE-2020-7549" ], "details": "A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause denial of HTTP and FTP services when a series of specially crafted requests is sent to the controller over HTTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgm6-gx92-h348/GHSA-mgm6-gx92-h348.json b/advisories/unreviewed/2022/05/GHSA-mgm6-gx92-h348/GHSA-mgm6-gx92-h348.json index 101607ef452..134cf0d6283 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgm6-gx92-h348/GHSA-mgm6-gx92-h348.json +++ b/advisories/unreviewed/2022/05/GHSA-mgm6-gx92-h348/GHSA-mgm6-gx92-h348.json @@ -7,12 +7,8 @@ "CVE-2018-1000891" ], "details": "Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgph-g68w-qpm4/GHSA-mgph-g68w-qpm4.json b/advisories/unreviewed/2022/05/GHSA-mgph-g68w-qpm4/GHSA-mgph-g68w-qpm4.json index 2da4f22266c..eb4affbabb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgph-g68w-qpm4/GHSA-mgph-g68w-qpm4.json +++ b/advisories/unreviewed/2022/05/GHSA-mgph-g68w-qpm4/GHSA-mgph-g68w-qpm4.json @@ -7,12 +7,8 @@ "CVE-2020-0481" ], "details": "In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a non-system app to send a broadcast it shouldn't have permissions to send, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157472962", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgvh-5mj6-fprr/GHSA-mgvh-5mj6-fprr.json b/advisories/unreviewed/2022/05/GHSA-mgvh-5mj6-fprr/GHSA-mgvh-5mj6-fprr.json index 5a86fa62861..187fb3a4a61 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgvh-5mj6-fprr/GHSA-mgvh-5mj6-fprr.json +++ b/advisories/unreviewed/2022/05/GHSA-mgvh-5mj6-fprr/GHSA-mgvh-5mj6-fprr.json @@ -7,12 +7,8 @@ "CVE-2020-9301" ], "details": "Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh87-m65c-c4rq/GHSA-mh87-m65c-c4rq.json b/advisories/unreviewed/2022/05/GHSA-mh87-m65c-c4rq/GHSA-mh87-m65c-c4rq.json index b422a01b023..0ffbc2dbe7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh87-m65c-c4rq/GHSA-mh87-m65c-c4rq.json +++ b/advisories/unreviewed/2022/05/GHSA-mh87-m65c-c4rq/GHSA-mh87-m65c-c4rq.json @@ -7,12 +7,8 @@ "CVE-2020-7201" ], "details": "A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh8m-xx9m-xm5h/GHSA-mh8m-xx9m-xm5h.json b/advisories/unreviewed/2022/05/GHSA-mh8m-xx9m-xm5h/GHSA-mh8m-xx9m-xm5h.json index 2d412da3bfc..eb5ad48e140 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh8m-xx9m-xm5h/GHSA-mh8m-xx9m-xm5h.json +++ b/advisories/unreviewed/2022/05/GHSA-mh8m-xx9m-xm5h/GHSA-mh8m-xx9m-xm5h.json @@ -7,12 +7,8 @@ "CVE-2020-0484" ], "details": "In destroyResources of ComposerClient.h, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155769496", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh9j-g4g3-6xcv/GHSA-mh9j-g4g3-6xcv.json b/advisories/unreviewed/2022/05/GHSA-mh9j-g4g3-6xcv/GHSA-mh9j-g4g3-6xcv.json index 52c8ba3224a..023e3f5ea16 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh9j-g4g3-6xcv/GHSA-mh9j-g4g3-6xcv.json +++ b/advisories/unreviewed/2022/05/GHSA-mh9j-g4g3-6xcv/GHSA-mh9j-g4g3-6xcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhgc-wgp9-pgqm/GHSA-mhgc-wgp9-pgqm.json b/advisories/unreviewed/2022/05/GHSA-mhgc-wgp9-pgqm/GHSA-mhgc-wgp9-pgqm.json index e1ed7475529..f43b39257be 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhgc-wgp9-pgqm/GHSA-mhgc-wgp9-pgqm.json +++ b/advisories/unreviewed/2022/05/GHSA-mhgc-wgp9-pgqm/GHSA-mhgc-wgp9-pgqm.json @@ -7,12 +7,8 @@ "CVE-2020-27640" ], "details": "The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhq4-2r6p-x7vh/GHSA-mhq4-2r6p-x7vh.json b/advisories/unreviewed/2022/05/GHSA-mhq4-2r6p-x7vh/GHSA-mhq4-2r6p-x7vh.json index d5f4cf56956..ce92820576d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhq4-2r6p-x7vh/GHSA-mhq4-2r6p-x7vh.json +++ b/advisories/unreviewed/2022/05/GHSA-mhq4-2r6p-x7vh/GHSA-mhq4-2r6p-x7vh.json @@ -7,12 +7,8 @@ "CVE-2020-25011" ], "details": "A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to get username and password by request /cgi-bin/webadminget.cgi script via the browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjhf-5xg4-c757/GHSA-mjhf-5xg4-c757.json b/advisories/unreviewed/2022/05/GHSA-mjhf-5xg4-c757/GHSA-mjhf-5xg4-c757.json index cd3b23d5b11..fa16ea9af2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjhf-5xg4-c757/GHSA-mjhf-5xg4-c757.json +++ b/advisories/unreviewed/2022/05/GHSA-mjhf-5xg4-c757/GHSA-mjhf-5xg4-c757.json @@ -7,12 +7,8 @@ "CVE-2020-8936" ], "details": "An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to UntrustedCall. UntrustedCall failed to validate the buffer range within sgx_params and allowed the host to return a pointer that was an address within the enclave memory. This allowed an attacker to read memory values from within the enclave.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjjv-qwjv-hg32/GHSA-mjjv-qwjv-hg32.json b/advisories/unreviewed/2022/05/GHSA-mjjv-qwjv-hg32/GHSA-mjjv-qwjv-hg32.json index 51c3c7642cb..73ca118b673 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjjv-qwjv-hg32/GHSA-mjjv-qwjv-hg32.json +++ b/advisories/unreviewed/2022/05/GHSA-mjjv-qwjv-hg32/GHSA-mjjv-qwjv-hg32.json @@ -7,12 +7,8 @@ "CVE-2020-35549" ], "details": "An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Any application may establish itself as the default dialer, without user interaction. The Samsung ID is SVE-2020-19172 (December 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mmfm-f7qp-mmv3/GHSA-mmfm-f7qp-mmv3.json b/advisories/unreviewed/2022/05/GHSA-mmfm-f7qp-mmv3/GHSA-mmfm-f7qp-mmv3.json index 509459c0dbf..3366897bf6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmfm-f7qp-mmv3/GHSA-mmfm-f7qp-mmv3.json +++ b/advisories/unreviewed/2022/05/GHSA-mmfm-f7qp-mmv3/GHSA-mmfm-f7qp-mmv3.json @@ -7,12 +7,8 @@ "CVE-2020-29607" ], "details": "A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the \"manage files\" functionality, which may result in remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp76-8wmf-mx7x/GHSA-mp76-8wmf-mx7x.json b/advisories/unreviewed/2022/05/GHSA-mp76-8wmf-mx7x/GHSA-mp76-8wmf-mx7x.json index e4082caf794..9d8288830e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp76-8wmf-mx7x/GHSA-mp76-8wmf-mx7x.json +++ b/advisories/unreviewed/2022/05/GHSA-mp76-8wmf-mx7x/GHSA-mp76-8wmf-mx7x.json @@ -7,12 +7,8 @@ "CVE-2020-35244" ], "details": "Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mqrh-3j77-m2cw/GHSA-mqrh-3j77-m2cw.json b/advisories/unreviewed/2022/05/GHSA-mqrh-3j77-m2cw/GHSA-mqrh-3j77-m2cw.json index 3e372df44fe..38200a92b36 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqrh-3j77-m2cw/GHSA-mqrh-3j77-m2cw.json +++ b/advisories/unreviewed/2022/05/GHSA-mqrh-3j77-m2cw/GHSA-mqrh-3j77-m2cw.json @@ -7,12 +7,8 @@ "CVE-2020-15294" ], "details": "Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results in multiple dereferences to the same pointer. If the pointer is located in memory-mapped from the guest space, this may cause a race-condition where the generated code would dereference the same address twice, thus obtaining different values, which may lead to arbitrary code execution. This issue affects: Bitdefender Hypervisor Introspection versions prior to 1.132.2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mr64-xwwr-mx4c/GHSA-mr64-xwwr-mx4c.json b/advisories/unreviewed/2022/05/GHSA-mr64-xwwr-mx4c/GHSA-mr64-xwwr-mx4c.json index 9fe4ee3c8e0..3a517639e76 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr64-xwwr-mx4c/GHSA-mr64-xwwr-mx4c.json +++ b/advisories/unreviewed/2022/05/GHSA-mr64-xwwr-mx4c/GHSA-mr64-xwwr-mx4c.json @@ -7,12 +7,8 @@ "CVE-2020-29566" ], "details": "An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must be temporarily de-scheduled. The device model will signal Xen when it has completed its operation, via an event channel, so that the relevant vCPU is rescheduled. If the device model were to signal Xen without having actually completed the operation, the de-schedule / re-schedule cycle would repeat. If, in addition, Xen is resignalled very quickly, the re-schedule may occur before the de-schedule was fully complete, triggering a shortcut. This potentially repeating process uses ordinary recursive function calls, and thus could result in a stack overflow. A malicious or buggy stubdomain serving a HVM guest can cause Xen to crash, resulting in a Denial of Service (DoS) to the entire host. Only x86 systems are affected. Arm systems are not affected. Only x86 stubdomains serving HVM guests can exploit the vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwv5-m2cr-5r9v/GHSA-mwv5-m2cr-5r9v.json b/advisories/unreviewed/2022/05/GHSA-mwv5-m2cr-5r9v/GHSA-mwv5-m2cr-5r9v.json index f524ac2d862..2b51000a565 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwv5-m2cr-5r9v/GHSA-mwv5-m2cr-5r9v.json +++ b/advisories/unreviewed/2022/05/GHSA-mwv5-m2cr-5r9v/GHSA-mwv5-m2cr-5r9v.json @@ -7,12 +7,8 @@ "CVE-2020-27134" ], "details": "Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx6v-gg5x-68cf/GHSA-mx6v-gg5x-68cf.json b/advisories/unreviewed/2022/05/GHSA-mx6v-gg5x-68cf/GHSA-mx6v-gg5x-68cf.json index d5be91b54ba..d5b09d4fb2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx6v-gg5x-68cf/GHSA-mx6v-gg5x-68cf.json +++ b/advisories/unreviewed/2022/05/GHSA-mx6v-gg5x-68cf/GHSA-mx6v-gg5x-68cf.json @@ -7,12 +7,8 @@ "CVE-2020-8944" ], "details": "An arbitrary memory write vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to ecall_restore using the attribute output which fails to check the range of a pointer. An attacker can use this pointer to write to arbitrary memory addresses including those within the secure enclave We recommend upgrading past commit 382da2b8b09cbf928668a2445efb778f76bd9c8a", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2hm-44w4-3mxj/GHSA-p2hm-44w4-3mxj.json b/advisories/unreviewed/2022/05/GHSA-p2hm-44w4-3mxj/GHSA-p2hm-44w4-3mxj.json index 2cdb766ba57..9425293621e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2hm-44w4-3mxj/GHSA-p2hm-44w4-3mxj.json +++ b/advisories/unreviewed/2022/05/GHSA-p2hm-44w4-3mxj/GHSA-p2hm-44w4-3mxj.json @@ -7,12 +7,8 @@ "CVE-2020-25192" ], "details": "The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be displayed without proper authorization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2hx-qx96-fvxr/GHSA-p2hx-qx96-fvxr.json b/advisories/unreviewed/2022/05/GHSA-p2hx-qx96-fvxr/GHSA-p2hx-qx96-fvxr.json index 3dfa91f0507..f334aaae796 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2hx-qx96-fvxr/GHSA-p2hx-qx96-fvxr.json +++ b/advisories/unreviewed/2022/05/GHSA-p2hx-qx96-fvxr/GHSA-p2hx-qx96-fvxr.json @@ -7,12 +7,8 @@ "CVE-2020-25759" ], "details": "An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p2p6-4q4c-7xqw/GHSA-p2p6-4q4c-7xqw.json b/advisories/unreviewed/2022/05/GHSA-p2p6-4q4c-7xqw/GHSA-p2p6-4q4c-7xqw.json index 11d02368872..e34219bd0ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2p6-4q4c-7xqw/GHSA-p2p6-4q4c-7xqw.json +++ b/advisories/unreviewed/2022/05/GHSA-p2p6-4q4c-7xqw/GHSA-p2p6-4q4c-7xqw.json @@ -7,12 +7,8 @@ "CVE-2020-14232" ], "details": "A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3v9-28pc-q5p2/GHSA-p3v9-28pc-q5p2.json b/advisories/unreviewed/2022/05/GHSA-p3v9-28pc-q5p2/GHSA-p3v9-28pc-q5p2.json index 8f70296a877..5696a1c93ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3v9-28pc-q5p2/GHSA-p3v9-28pc-q5p2.json +++ b/advisories/unreviewed/2022/05/GHSA-p3v9-28pc-q5p2/GHSA-p3v9-28pc-q5p2.json @@ -7,12 +7,8 @@ "CVE-2020-35712" ], "details": "Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6jx-ww27-x6x5/GHSA-p6jx-ww27-x6x5.json b/advisories/unreviewed/2022/05/GHSA-p6jx-ww27-x6x5/GHSA-p6jx-ww27-x6x5.json index 200c75a7c33..5ec525cc78c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6jx-ww27-x6x5/GHSA-p6jx-ww27-x6x5.json +++ b/advisories/unreviewed/2022/05/GHSA-p6jx-ww27-x6x5/GHSA-p6jx-ww27-x6x5.json @@ -7,12 +7,8 @@ "CVE-2020-35743" ], "details": "HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6mv-vmpw-j23r/GHSA-p6mv-vmpw-j23r.json b/advisories/unreviewed/2022/05/GHSA-p6mv-vmpw-j23r/GHSA-p6mv-vmpw-j23r.json index 460f9cefa1f..51eda9cf158 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6mv-vmpw-j23r/GHSA-p6mv-vmpw-j23r.json +++ b/advisories/unreviewed/2022/05/GHSA-p6mv-vmpw-j23r/GHSA-p6mv-vmpw-j23r.json @@ -7,12 +7,8 @@ "CVE-2020-29510" ], "details": "The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p7jp-vf5p-fj78/GHSA-p7jp-vf5p-fj78.json b/advisories/unreviewed/2022/05/GHSA-p7jp-vf5p-fj78/GHSA-p7jp-vf5p-fj78.json index 3cd8ae4c5d4..87094f8fc7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7jp-vf5p-fj78/GHSA-p7jp-vf5p-fj78.json +++ b/advisories/unreviewed/2022/05/GHSA-p7jp-vf5p-fj78/GHSA-p7jp-vf5p-fj78.json @@ -7,12 +7,8 @@ "CVE-2020-35805" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7q8-r4h2-p9qq/GHSA-p7q8-r4h2-p9qq.json b/advisories/unreviewed/2022/05/GHSA-p7q8-r4h2-p9qq/GHSA-p7q8-r4h2-p9qq.json index 941a57df644..c9b00037bc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7q8-r4h2-p9qq/GHSA-p7q8-r4h2-p9qq.json +++ b/advisories/unreviewed/2022/05/GHSA-p7q8-r4h2-p9qq/GHSA-p7q8-r4h2-p9qq.json @@ -7,12 +7,8 @@ "CVE-2020-9201" ], "details": "There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages including crafted parameter. Successful exploit could cause certain service abnormal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7rw-422j-w7qg/GHSA-p7rw-422j-w7qg.json b/advisories/unreviewed/2022/05/GHSA-p7rw-422j-w7qg/GHSA-p7rw-422j-w7qg.json index ca5c3b43594..588f31a6163 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7rw-422j-w7qg/GHSA-p7rw-422j-w7qg.json +++ b/advisories/unreviewed/2022/05/GHSA-p7rw-422j-w7qg/GHSA-p7rw-422j-w7qg.json @@ -7,12 +7,8 @@ "CVE-2020-35622" ], "details": "An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function was not being properly escaped, allowing for XSS under certain conditions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p8fx-hg9x-79mx/GHSA-p8fx-hg9x-79mx.json b/advisories/unreviewed/2022/05/GHSA-p8fx-hg9x-79mx/GHSA-p8fx-hg9x-79mx.json index 2f6589bd3fc..a4074c9fd32 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8fx-hg9x-79mx/GHSA-p8fx-hg9x-79mx.json +++ b/advisories/unreviewed/2022/05/GHSA-p8fx-hg9x-79mx/GHSA-p8fx-hg9x-79mx.json @@ -7,12 +7,8 @@ "CVE-2019-20808" ], "details": "In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p969-xjrf-27pm/GHSA-p969-xjrf-27pm.json b/advisories/unreviewed/2022/05/GHSA-p969-xjrf-27pm/GHSA-p969-xjrf-27pm.json index 33a826c3c09..d47ac1bf3ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-p969-xjrf-27pm/GHSA-p969-xjrf-27pm.json +++ b/advisories/unreviewed/2022/05/GHSA-p969-xjrf-27pm/GHSA-p969-xjrf-27pm.json @@ -7,12 +7,8 @@ "CVE-2018-15645" ], "details": "Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9fx-r7r3-pm29/GHSA-p9fx-r7r3-pm29.json b/advisories/unreviewed/2022/05/GHSA-p9fx-r7r3-pm29/GHSA-p9fx-r7r3-pm29.json index fd7963570f1..03fcd28acef 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9fx-r7r3-pm29/GHSA-p9fx-r7r3-pm29.json +++ b/advisories/unreviewed/2022/05/GHSA-p9fx-r7r3-pm29/GHSA-p9fx-r7r3-pm29.json @@ -7,12 +7,8 @@ "CVE-2020-35274" ], "details": "DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pcmg-wjrm-9r44/GHSA-pcmg-wjrm-9r44.json b/advisories/unreviewed/2022/05/GHSA-pcmg-wjrm-9r44/GHSA-pcmg-wjrm-9r44.json index 57a88c38f36..88036e289ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcmg-wjrm-9r44/GHSA-pcmg-wjrm-9r44.json +++ b/advisories/unreviewed/2022/05/GHSA-pcmg-wjrm-9r44/GHSA-pcmg-wjrm-9r44.json @@ -7,12 +7,8 @@ "CVE-2020-28931" ], "details": "Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an administrator to execute external POST requests by visiting a malicious website.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pcr3-5frq-ww46/GHSA-pcr3-5frq-ww46.json b/advisories/unreviewed/2022/05/GHSA-pcr3-5frq-ww46/GHSA-pcr3-5frq-ww46.json index 1e883105f41..446ee250bd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcr3-5frq-ww46/GHSA-pcr3-5frq-ww46.json +++ b/advisories/unreviewed/2022/05/GHSA-pcr3-5frq-ww46/GHSA-pcr3-5frq-ww46.json @@ -7,12 +7,8 @@ "CVE-2020-20299" ], "details": "WeiPHP 5.0 does not properly restrict access to pages, related to using POST.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf65-88c2-hrfc/GHSA-pf65-88c2-hrfc.json b/advisories/unreviewed/2022/05/GHSA-pf65-88c2-hrfc/GHSA-pf65-88c2-hrfc.json index a20367a6a88..a830a911758 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf65-88c2-hrfc/GHSA-pf65-88c2-hrfc.json +++ b/advisories/unreviewed/2022/05/GHSA-pf65-88c2-hrfc/GHSA-pf65-88c2-hrfc.json @@ -7,12 +7,8 @@ "CVE-2020-35784" ], "details": "Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, JGS524PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and GS116Ev2 before 2.6.0.48.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgjg-jx8c-q35f/GHSA-pgjg-jx8c-q35f.json b/advisories/unreviewed/2022/05/GHSA-pgjg-jx8c-q35f/GHSA-pgjg-jx8c-q35f.json index 536d4df5f2f..d35739019c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgjg-jx8c-q35f/GHSA-pgjg-jx8c-q35f.json +++ b/advisories/unreviewed/2022/05/GHSA-pgjg-jx8c-q35f/GHSA-pgjg-jx8c-q35f.json @@ -7,12 +7,8 @@ "CVE-2020-27780" ], "details": "A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm7g-wr2h-x45m/GHSA-pm7g-wr2h-x45m.json b/advisories/unreviewed/2022/05/GHSA-pm7g-wr2h-x45m/GHSA-pm7g-wr2h-x45m.json index 07e42f99bda..911dc6f9d88 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm7g-wr2h-x45m/GHSA-pm7g-wr2h-x45m.json +++ b/advisories/unreviewed/2022/05/GHSA-pm7g-wr2h-x45m/GHSA-pm7g-wr2h-x45m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pqw8-9r2r-p4cp/GHSA-pqw8-9r2r-p4cp.json b/advisories/unreviewed/2022/05/GHSA-pqw8-9r2r-p4cp/GHSA-pqw8-9r2r-p4cp.json index 38a87fc80e7..b98801cdf2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqw8-9r2r-p4cp/GHSA-pqw8-9r2r-p4cp.json +++ b/advisories/unreviewed/2022/05/GHSA-pqw8-9r2r-p4cp/GHSA-pqw8-9r2r-p4cp.json @@ -7,12 +7,8 @@ "CVE-2020-14268" ], "details": "A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which would execute with the privileges of the client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prq6-5cg3-rr76/GHSA-prq6-5cg3-rr76.json b/advisories/unreviewed/2022/05/GHSA-prq6-5cg3-rr76/GHSA-prq6-5cg3-rr76.json index 49ab156cfb4..d6174f28e56 100644 --- a/advisories/unreviewed/2022/05/GHSA-prq6-5cg3-rr76/GHSA-prq6-5cg3-rr76.json +++ b/advisories/unreviewed/2022/05/GHSA-prq6-5cg3-rr76/GHSA-prq6-5cg3-rr76.json @@ -7,12 +7,8 @@ "CVE-2020-28219" ], "details": "A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1), that could cause exposure of credentials to server-side users when web users are logged in to Virtual ViewX.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw5j-659q-5r57/GHSA-pw5j-659q-5r57.json b/advisories/unreviewed/2022/05/GHSA-pw5j-659q-5r57/GHSA-pw5j-659q-5r57.json index 85737036e7b..e358ee7ee38 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw5j-659q-5r57/GHSA-pw5j-659q-5r57.json +++ b/advisories/unreviewed/2022/05/GHSA-pw5j-659q-5r57/GHSA-pw5j-659q-5r57.json @@ -7,12 +7,8 @@ "CVE-2020-0493" ], "details": "In CPDF_SampledFunc::v_Call of cpdf_sampledfunc.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150615407", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwmr-wm2x-h5p8/GHSA-pwmr-wm2x-h5p8.json b/advisories/unreviewed/2022/05/GHSA-pwmr-wm2x-h5p8/GHSA-pwmr-wm2x-h5p8.json index 587816491a0..286d2aa51ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwmr-wm2x-h5p8/GHSA-pwmr-wm2x-h5p8.json +++ b/advisories/unreviewed/2022/05/GHSA-pwmr-wm2x-h5p8/GHSA-pwmr-wm2x-h5p8.json @@ -7,12 +7,8 @@ "CVE-2020-0474" ], "details": "In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169282240", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-px9v-79j4-c67w/GHSA-px9v-79j4-c67w.json b/advisories/unreviewed/2022/05/GHSA-px9v-79j4-c67w/GHSA-px9v-79j4-c67w.json index 341efebd102..d695900818a 100644 --- a/advisories/unreviewed/2022/05/GHSA-px9v-79j4-c67w/GHSA-px9v-79j4-c67w.json +++ b/advisories/unreviewed/2022/05/GHSA-px9v-79j4-c67w/GHSA-px9v-79j4-c67w.json @@ -7,12 +7,8 @@ "CVE-2020-0477" ], "details": "In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of the current network configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162246414", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxc8-4fvh-x35v/GHSA-pxc8-4fvh-x35v.json b/advisories/unreviewed/2022/05/GHSA-pxc8-4fvh-x35v/GHSA-pxc8-4fvh-x35v.json index a921a11a240..c3d9e3fc93b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxc8-4fvh-x35v/GHSA-pxc8-4fvh-x35v.json +++ b/advisories/unreviewed/2022/05/GHSA-pxc8-4fvh-x35v/GHSA-pxc8-4fvh-x35v.json @@ -7,12 +7,8 @@ "CVE-2020-0497" ], "details": "In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158481661", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxw9-25jj-hw97/GHSA-pxw9-25jj-hw97.json b/advisories/unreviewed/2022/05/GHSA-pxw9-25jj-hw97/GHSA-pxw9-25jj-hw97.json index e40e3965827..110c3e46df0 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxw9-25jj-hw97/GHSA-pxw9-25jj-hw97.json +++ b/advisories/unreviewed/2022/05/GHSA-pxw9-25jj-hw97/GHSA-pxw9-25jj-hw97.json @@ -7,12 +7,8 @@ "CVE-2020-5681" ], "details": "Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q329-j6wm-vf6q/GHSA-q329-j6wm-vf6q.json b/advisories/unreviewed/2022/05/GHSA-q329-j6wm-vf6q/GHSA-q329-j6wm-vf6q.json index 9d51a68994f..e8d57c0d816 100644 --- a/advisories/unreviewed/2022/05/GHSA-q329-j6wm-vf6q/GHSA-q329-j6wm-vf6q.json +++ b/advisories/unreviewed/2022/05/GHSA-q329-j6wm-vf6q/GHSA-q329-j6wm-vf6q.json @@ -7,12 +7,8 @@ "CVE-2020-29487" ], "details": "An issue was discovered in Xen XAPI before 2020-12-15. Certain xenstore keys provide feedback from the guest, and are therefore watched by toolstack. Specifically, keys are watched by xenopsd, and data are forwarded via RPC through message-switch to xapi. The watching logic in xenopsd sends one RPC update containing all data, any time any single xenstore key is updated, and therefore has O(N^2) time complexity. Furthermore, message-switch retains recent (currently 128) RPC messages for diagnostic purposes, yielding O(M*N) space complexity. The quantity of memory a single guest can monopolise is bounded by xenstored quota, but the quota is fairly large. It is believed to be in excess of 1G per malicious guest. In practice, this manifests as a host denial of service, either through message-switch thrashing against swap, or OOMing entirely, depending on dom0's configuration. (There are no quotas in xenopsd to limit the quantity of keys that result in RPC traffic.) A buggy or malicious guest can cause unreasonable memory usage in dom0, resulting in a host denial of service. All versions of XAPI are vulnerable. Systems that are not using the XAPI toolstack are not vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3g8-363q-g9qq/GHSA-q3g8-363q-g9qq.json b/advisories/unreviewed/2022/05/GHSA-q3g8-363q-g9qq/GHSA-q3g8-363q-g9qq.json index 79a7dda2d1f..2a01bf7b663 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3g8-363q-g9qq/GHSA-q3g8-363q-g9qq.json +++ b/advisories/unreviewed/2022/05/GHSA-q3g8-363q-g9qq/GHSA-q3g8-363q-g9qq.json @@ -7,12 +7,8 @@ "CVE-2020-17441" ], "details": "An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 payload length field is equal to the actual size of the payload, which leads to an Out-of-Bounds read during the ICMPv6 checksum calculation, resulting in either Denial-of-Service or Information Disclosure. This affects pico_ipv6_extension_headers and pico_checksum_adder (in pico_ipv6.c and pico_frame.c).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3gm-pqp8-wxcj/GHSA-q3gm-pqp8-wxcj.json b/advisories/unreviewed/2022/05/GHSA-q3gm-pqp8-wxcj/GHSA-q3gm-pqp8-wxcj.json index 5c02292be95..e3514a1668e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3gm-pqp8-wxcj/GHSA-q3gm-pqp8-wxcj.json +++ b/advisories/unreviewed/2022/05/GHSA-q3gm-pqp8-wxcj/GHSA-q3gm-pqp8-wxcj.json @@ -7,12 +7,8 @@ "CVE-2018-1000893" ], "details": "Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3jv-fxmp-qgj5/GHSA-q3jv-fxmp-qgj5.json b/advisories/unreviewed/2022/05/GHSA-q3jv-fxmp-qgj5/GHSA-q3jv-fxmp-qgj5.json index c145cb499d4..2dd67c8173c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3jv-fxmp-qgj5/GHSA-q3jv-fxmp-qgj5.json +++ b/advisories/unreviewed/2022/05/GHSA-q3jv-fxmp-qgj5/GHSA-q3jv-fxmp-qgj5.json @@ -7,12 +7,8 @@ "CVE-2020-15292" ], "details": "Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTaskDumpTree may lead to out-of-bounds read or it could cause DoS due to integer-overflor (IntPeGetDirectory), TOCTOU (IntPeParseUnwindData) or insufficient validations.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q45w-6fj8-gjg7/GHSA-q45w-6fj8-gjg7.json b/advisories/unreviewed/2022/05/GHSA-q45w-6fj8-gjg7/GHSA-q45w-6fj8-gjg7.json index 63da05f4731..0f1f86101ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-q45w-6fj8-gjg7/GHSA-q45w-6fj8-gjg7.json +++ b/advisories/unreviewed/2022/05/GHSA-q45w-6fj8-gjg7/GHSA-q45w-6fj8-gjg7.json @@ -7,12 +7,8 @@ "CVE-2020-27031" ], "details": "In nfc_data_event of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151313205", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q477-jxcv-9pxw/GHSA-q477-jxcv-9pxw.json b/advisories/unreviewed/2022/05/GHSA-q477-jxcv-9pxw/GHSA-q477-jxcv-9pxw.json index 1309ed0e268..66d935ed2da 100644 --- a/advisories/unreviewed/2022/05/GHSA-q477-jxcv-9pxw/GHSA-q477-jxcv-9pxw.json +++ b/advisories/unreviewed/2022/05/GHSA-q477-jxcv-9pxw/GHSA-q477-jxcv-9pxw.json @@ -7,12 +7,8 @@ "CVE-2020-13357" ], "details": "An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q53r-4p37-g26v/GHSA-q53r-4p37-g26v.json b/advisories/unreviewed/2022/05/GHSA-q53r-4p37-g26v/GHSA-q53r-4p37-g26v.json index 202cf434d13..41e4a8c1c9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q53r-4p37-g26v/GHSA-q53r-4p37-g26v.json +++ b/advisories/unreviewed/2022/05/GHSA-q53r-4p37-g26v/GHSA-q53r-4p37-g26v.json @@ -7,12 +7,8 @@ "CVE-2020-7838" ], "details": "A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrary code when the user access to crafted web page. This issue affects: Smilegate STOVE Client 0.0.4.72.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5hg-75fp-r6wm/GHSA-q5hg-75fp-r6wm.json b/advisories/unreviewed/2022/05/GHSA-q5hg-75fp-r6wm/GHSA-q5hg-75fp-r6wm.json index 4052514338d..db7110c9c40 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5hg-75fp-r6wm/GHSA-q5hg-75fp-r6wm.json +++ b/advisories/unreviewed/2022/05/GHSA-q5hg-75fp-r6wm/GHSA-q5hg-75fp-r6wm.json @@ -7,12 +7,8 @@ "CVE-2020-28218" ], "details": "A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5qq-3694-7623/GHSA-q5qq-3694-7623.json b/advisories/unreviewed/2022/05/GHSA-q5qq-3694-7623/GHSA-q5qq-3694-7623.json index 8ab16a05374..12012680903 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5qq-3694-7623/GHSA-q5qq-3694-7623.json +++ b/advisories/unreviewed/2022/05/GHSA-q5qq-3694-7623/GHSA-q5qq-3694-7623.json @@ -7,12 +7,8 @@ "CVE-2020-4633" ], "details": "IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5qw-2572-9j7r/GHSA-q5qw-2572-9j7r.json b/advisories/unreviewed/2022/05/GHSA-q5qw-2572-9j7r/GHSA-q5qw-2572-9j7r.json index 0dc9974426f..c6787b41717 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5qw-2572-9j7r/GHSA-q5qw-2572-9j7r.json +++ b/advisories/unreviewed/2022/05/GHSA-q5qw-2572-9j7r/GHSA-q5qw-2572-9j7r.json @@ -7,12 +7,8 @@ "CVE-2020-27047" ], "details": "In ce_t4t_update_binary of ce_t4t.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157649298", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5x3-rg2c-6436/GHSA-q5x3-rg2c-6436.json b/advisories/unreviewed/2022/05/GHSA-q5x3-rg2c-6436/GHSA-q5x3-rg2c-6436.json index df940416087..1bc0c6dcd5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5x3-rg2c-6436/GHSA-q5x3-rg2c-6436.json +++ b/advisories/unreviewed/2022/05/GHSA-q5x3-rg2c-6436/GHSA-q5x3-rg2c-6436.json @@ -7,12 +7,8 @@ "CVE-2020-35127" ], "details": "Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6w2-7x26-wjhf/GHSA-q6w2-7x26-wjhf.json b/advisories/unreviewed/2022/05/GHSA-q6w2-7x26-wjhf/GHSA-q6w2-7x26-wjhf.json index ec24beed3c7..49f1b00cb3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6w2-7x26-wjhf/GHSA-q6w2-7x26-wjhf.json +++ b/advisories/unreviewed/2022/05/GHSA-q6w2-7x26-wjhf/GHSA-q6w2-7x26-wjhf.json @@ -7,12 +7,8 @@ "CVE-2020-35242" ], "details": "Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q768-rrh4-6p7h/GHSA-q768-rrh4-6p7h.json b/advisories/unreviewed/2022/05/GHSA-q768-rrh4-6p7h/GHSA-q768-rrh4-6p7h.json index 8f624ba2877..87677bb756c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q768-rrh4-6p7h/GHSA-q768-rrh4-6p7h.json +++ b/advisories/unreviewed/2022/05/GHSA-q768-rrh4-6p7h/GHSA-q768-rrh4-6p7h.json @@ -7,12 +7,8 @@ "CVE-2020-13968" ], "details": "CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7hp-c9hf-jfvx/GHSA-q7hp-c9hf-jfvx.json b/advisories/unreviewed/2022/05/GHSA-q7hp-c9hf-jfvx/GHSA-q7hp-c9hf-jfvx.json index 0ab626c7f17..74a31a3cc6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7hp-c9hf-jfvx/GHSA-q7hp-c9hf-jfvx.json +++ b/advisories/unreviewed/2022/05/GHSA-q7hp-c9hf-jfvx/GHSA-q7hp-c9hf-jfvx.json @@ -7,12 +7,8 @@ "CVE-2020-29455" ], "details": "A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressPlugin.js 3.2 allows remote attackers to inject arbitrary web script or HTML via any address parameter (e.g., street or country).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7pj-xc3r-rm4w/GHSA-q7pj-xc3r-rm4w.json b/advisories/unreviewed/2022/05/GHSA-q7pj-xc3r-rm4w/GHSA-q7pj-xc3r-rm4w.json index c97d4a53ae6..ef66b72326e 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7pj-xc3r-rm4w/GHSA-q7pj-xc3r-rm4w.json +++ b/advisories/unreviewed/2022/05/GHSA-q7pj-xc3r-rm4w/GHSA-q7pj-xc3r-rm4w.json @@ -7,12 +7,8 @@ "CVE-2020-35666" ], "details": "Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q835-q3qm-4v3c/GHSA-q835-q3qm-4v3c.json b/advisories/unreviewed/2022/05/GHSA-q835-q3qm-4v3c/GHSA-q835-q3qm-4v3c.json index 9af115ad61d..b6a8316d433 100644 --- a/advisories/unreviewed/2022/05/GHSA-q835-q3qm-4v3c/GHSA-q835-q3qm-4v3c.json +++ b/advisories/unreviewed/2022/05/GHSA-q835-q3qm-4v3c/GHSA-q835-q3qm-4v3c.json @@ -7,12 +7,8 @@ "CVE-2020-23957" ], "details": "Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q84j-ghmc-vjvj/GHSA-q84j-ghmc-vjvj.json b/advisories/unreviewed/2022/05/GHSA-q84j-ghmc-vjvj/GHSA-q84j-ghmc-vjvj.json index a5655217a92..6beb37c9825 100644 --- a/advisories/unreviewed/2022/05/GHSA-q84j-ghmc-vjvj/GHSA-q84j-ghmc-vjvj.json +++ b/advisories/unreviewed/2022/05/GHSA-q84j-ghmc-vjvj/GHSA-q84j-ghmc-vjvj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q89m-rx2c-6v2g/GHSA-q89m-rx2c-6v2g.json b/advisories/unreviewed/2022/05/GHSA-q89m-rx2c-6v2g/GHSA-q89m-rx2c-6v2g.json index 3a011b4759a..46ad61219ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-q89m-rx2c-6v2g/GHSA-q89m-rx2c-6v2g.json +++ b/advisories/unreviewed/2022/05/GHSA-q89m-rx2c-6v2g/GHSA-q89m-rx2c-6v2g.json @@ -7,12 +7,8 @@ "CVE-2020-29483" ], "details": "An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest violates this protocol, xenstored will drop the connection to that guest. Unfortunately, this is done by just removing the guest from xenstored's internal management, resulting in the same actions as if the guest had been destroyed, including sending an @releaseDomain event. @releaseDomain events do not say that the guest has been removed. All watchers of this event must look at the states of all guests to find the guest that has been removed. When an @releaseDomain is generated due to a domain xenstored protocol violation, because the guest is still running, the watchers will not react. Later, when the guest is actually destroyed, xenstored will no longer have it stored in its internal data base, so no further @releaseDomain event will be sent. This can lead to a zombie domain; memory mappings of that guest's memory will not be removed, due to the missing event. This zombie domain will be cleaned up only after another domain is destroyed, as that will trigger another @releaseDomain event. If the device model of the guest that violated the Xenstore protocol is running in a stub-domain, a use-after-free case could happen in xenstored, after having removed the guest from its internal data base, possibly resulting in a crash of xenstored. A malicious guest can block resources of the host for a period after its own death. Guests with a stub domain device model can eventually crash xenstored, resulting in a more serious denial of service (the prevention of any further domain management operations). Only the C variant of Xenstore is affected; the Ocaml variant is not affected. Only HVM guests with a stubdom device model can cause a serious DoS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9rx-4v2p-p884/GHSA-q9rx-4v2p-p884.json b/advisories/unreviewed/2022/05/GHSA-q9rx-4v2p-p884/GHSA-q9rx-4v2p-p884.json index cedeec6d41d..3f0ea9f07f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9rx-4v2p-p884/GHSA-q9rx-4v2p-p884.json +++ b/advisories/unreviewed/2022/05/GHSA-q9rx-4v2p-p884/GHSA-q9rx-4v2p-p884.json @@ -7,12 +7,8 @@ "CVE-2020-5949" ], "details": "On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcfr-j8mx-6wf3/GHSA-qcfr-j8mx-6wf3.json b/advisories/unreviewed/2022/05/GHSA-qcfr-j8mx-6wf3/GHSA-qcfr-j8mx-6wf3.json index 0ce618ee510..e682d19a670 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcfr-j8mx-6wf3/GHSA-qcfr-j8mx-6wf3.json +++ b/advisories/unreviewed/2022/05/GHSA-qcfr-j8mx-6wf3/GHSA-qcfr-j8mx-6wf3.json @@ -7,12 +7,8 @@ "CVE-2020-28073" ], "details": "SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf9m-hx8v-j382/GHSA-qf9m-hx8v-j382.json b/advisories/unreviewed/2022/05/GHSA-qf9m-hx8v-j382/GHSA-qf9m-hx8v-j382.json index a47020bb128..ea641dd93a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf9m-hx8v-j382/GHSA-qf9m-hx8v-j382.json +++ b/advisories/unreviewed/2022/05/GHSA-qf9m-hx8v-j382/GHSA-qf9m-hx8v-j382.json @@ -7,12 +7,8 @@ "CVE-2020-25848" ], "details": "HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfv7-mpwh-q7mf/GHSA-qfv7-mpwh-q7mf.json b/advisories/unreviewed/2022/05/GHSA-qfv7-mpwh-q7mf/GHSA-qfv7-mpwh-q7mf.json index 4de78cfb3af..3ce302cf136 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfv7-mpwh-q7mf/GHSA-qfv7-mpwh-q7mf.json +++ b/advisories/unreviewed/2022/05/GHSA-qfv7-mpwh-q7mf/GHSA-qfv7-mpwh-q7mf.json @@ -7,12 +7,8 @@ "CVE-2020-27044" ], "details": "In restartWrite of Parcel.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157066561", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgxh-9fmh-3q95/GHSA-qgxh-9fmh-3q95.json b/advisories/unreviewed/2022/05/GHSA-qgxh-9fmh-3q95/GHSA-qgxh-9fmh-3q95.json index 8a7b5e8027d..8a4ef36bd82 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgxh-9fmh-3q95/GHSA-qgxh-9fmh-3q95.json +++ b/advisories/unreviewed/2022/05/GHSA-qgxh-9fmh-3q95/GHSA-qgxh-9fmh-3q95.json @@ -7,12 +7,8 @@ "CVE-2020-28071" ], "details": "SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh64-cxhv-8756/GHSA-qh64-cxhv-8756.json b/advisories/unreviewed/2022/05/GHSA-qh64-cxhv-8756/GHSA-qh64-cxhv-8756.json index 6cbfe6b6c89..a7cf628b162 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh64-cxhv-8756/GHSA-qh64-cxhv-8756.json +++ b/advisories/unreviewed/2022/05/GHSA-qh64-cxhv-8756/GHSA-qh64-cxhv-8756.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qh93-57jh-fhch/GHSA-qh93-57jh-fhch.json b/advisories/unreviewed/2022/05/GHSA-qh93-57jh-fhch/GHSA-qh93-57jh-fhch.json index 9d0016dd1b8..1945875d325 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh93-57jh-fhch/GHSA-qh93-57jh-fhch.json +++ b/advisories/unreviewed/2022/05/GHSA-qh93-57jh-fhch/GHSA-qh93-57jh-fhch.json @@ -7,12 +7,8 @@ "CVE-2020-35121" ], "details": "An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could insert arbitrary JavaScript into saved macro parameters that would execute when a user viewed a page with that instance of the macro.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qhv9-3j65-7jg9/GHSA-qhv9-3j65-7jg9.json b/advisories/unreviewed/2022/05/GHSA-qhv9-3j65-7jg9/GHSA-qhv9-3j65-7jg9.json index e608a7ada5b..45346fd2c35 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhv9-3j65-7jg9/GHSA-qhv9-3j65-7jg9.json +++ b/advisories/unreviewed/2022/05/GHSA-qhv9-3j65-7jg9/GHSA-qhv9-3j65-7jg9.json @@ -7,12 +7,8 @@ "CVE-2020-35362" ], "details": "DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct fileOrgName value).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qj3c-vm3g-g389/GHSA-qj3c-vm3g-g389.json b/advisories/unreviewed/2022/05/GHSA-qj3c-vm3g-g389/GHSA-qj3c-vm3g-g389.json index 18515b64b6a..1b771fde41e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj3c-vm3g-g389/GHSA-qj3c-vm3g-g389.json +++ b/advisories/unreviewed/2022/05/GHSA-qj3c-vm3g-g389/GHSA-qj3c-vm3g-g389.json @@ -7,12 +7,8 @@ "CVE-2020-24341" ], "details": "An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The TCP input data processing function in pico_tcp.c does not validate the length of incoming TCP packets, which leads to an out-of-bounds read when assembling received packets into a data segment, eventually causing Denial-of-Service or an information leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qmhj-wg3r-x2h5/GHSA-qmhj-wg3r-x2h5.json b/advisories/unreviewed/2022/05/GHSA-qmhj-wg3r-x2h5/GHSA-qmhj-wg3r-x2h5.json index 7aaed3dde4f..7551386b35b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmhj-wg3r-x2h5/GHSA-qmhj-wg3r-x2h5.json +++ b/advisories/unreviewed/2022/05/GHSA-qmhj-wg3r-x2h5/GHSA-qmhj-wg3r-x2h5.json @@ -7,12 +7,8 @@ "CVE-2020-27252" ], "details": "Medtronic MyCareLink Smart 25000 all versions are vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp4c-cv95-gwhh/GHSA-qp4c-cv95-gwhh.json b/advisories/unreviewed/2022/05/GHSA-qp4c-cv95-gwhh/GHSA-qp4c-cv95-gwhh.json index af5b815bc20..e0f6e4b98ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp4c-cv95-gwhh/GHSA-qp4c-cv95-gwhh.json +++ b/advisories/unreviewed/2022/05/GHSA-qp4c-cv95-gwhh/GHSA-qp4c-cv95-gwhh.json @@ -7,12 +7,8 @@ "CVE-2020-0499" ], "details": "In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qq7v-vpch-58j2/GHSA-qq7v-vpch-58j2.json b/advisories/unreviewed/2022/05/GHSA-qq7v-vpch-58j2/GHSA-qq7v-vpch-58j2.json index 404c665fb95..4bcb24c00e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq7v-vpch-58j2/GHSA-qq7v-vpch-58j2.json +++ b/advisories/unreviewed/2022/05/GHSA-qq7v-vpch-58j2/GHSA-qq7v-vpch-58j2.json @@ -7,12 +7,8 @@ "CVE-2020-35779" ], "details": "NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qq9r-5mv8-w3px/GHSA-qq9r-5mv8-w3px.json b/advisories/unreviewed/2022/05/GHSA-qq9r-5mv8-w3px/GHSA-qq9r-5mv8-w3px.json index 4fd3fb706b4..c925ad35abd 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq9r-5mv8-w3px/GHSA-qq9r-5mv8-w3px.json +++ b/advisories/unreviewed/2022/05/GHSA-qq9r-5mv8-w3px/GHSA-qq9r-5mv8-w3px.json @@ -7,12 +7,8 @@ "CVE-2020-35657" ], "details": "Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqm4-x6m2-p2v9/GHSA-qqm4-x6m2-p2v9.json b/advisories/unreviewed/2022/05/GHSA-qqm4-x6m2-p2v9/GHSA-qqm4-x6m2-p2v9.json index 89a49b9177b..c5b9bdf121f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqm4-x6m2-p2v9/GHSA-qqm4-x6m2-p2v9.json +++ b/advisories/unreviewed/2022/05/GHSA-qqm4-x6m2-p2v9/GHSA-qqm4-x6m2-p2v9.json @@ -7,12 +7,8 @@ "CVE-2020-5808" ], "details": "In certain scenarios in Tenable.sc prior to 5.17.0, a scanner could potentially be used outside the user's defined scan zone without a particular zone being specified within the Automatic Distribution configuration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrhr-8558-526f/GHSA-qrhr-8558-526f.json b/advisories/unreviewed/2022/05/GHSA-qrhr-8558-526f/GHSA-qrhr-8558-526f.json index 7d1a0c843d4..3b231d9c4b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrhr-8558-526f/GHSA-qrhr-8558-526f.json +++ b/advisories/unreviewed/2022/05/GHSA-qrhr-8558-526f/GHSA-qrhr-8558-526f.json @@ -7,12 +7,8 @@ "CVE-2020-0456" ], "details": "There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170378843", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrpp-2r5f-6xf2/GHSA-qrpp-2r5f-6xf2.json b/advisories/unreviewed/2022/05/GHSA-qrpp-2r5f-6xf2/GHSA-qrpp-2r5f-6xf2.json index e05d62967f6..df3c47e5bd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrpp-2r5f-6xf2/GHSA-qrpp-2r5f-6xf2.json +++ b/advisories/unreviewed/2022/05/GHSA-qrpp-2r5f-6xf2/GHSA-qrpp-2r5f-6xf2.json @@ -7,12 +7,8 @@ "CVE-2020-35450" ], "details": "Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrrv-9vc8-gf2w/GHSA-qrrv-9vc8-gf2w.json b/advisories/unreviewed/2022/05/GHSA-qrrv-9vc8-gf2w/GHSA-qrrv-9vc8-gf2w.json index c34e6277214..2d2e871ada4 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrrv-9vc8-gf2w/GHSA-qrrv-9vc8-gf2w.json +++ b/advisories/unreviewed/2022/05/GHSA-qrrv-9vc8-gf2w/GHSA-qrrv-9vc8-gf2w.json @@ -7,12 +7,8 @@ "CVE-2020-12522" ], "details": "The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv45-6hw7-469f/GHSA-qv45-6hw7-469f.json b/advisories/unreviewed/2022/05/GHSA-qv45-6hw7-469f/GHSA-qv45-6hw7-469f.json index d04c4891d2e..b45446707b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv45-6hw7-469f/GHSA-qv45-6hw7-469f.json +++ b/advisories/unreviewed/2022/05/GHSA-qv45-6hw7-469f/GHSA-qv45-6hw7-469f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvf3-c945-57wx/GHSA-qvf3-c945-57wx.json b/advisories/unreviewed/2022/05/GHSA-qvf3-c945-57wx/GHSA-qvf3-c945-57wx.json index 68f24cb8d6b..523251fa6df 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvf3-c945-57wx/GHSA-qvf3-c945-57wx.json +++ b/advisories/unreviewed/2022/05/GHSA-qvf3-c945-57wx/GHSA-qvf3-c945-57wx.json @@ -7,12 +7,8 @@ "CVE-2020-27025" ], "details": "In EapFailureNotifier.java and SimRequiredNotifier.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156008365", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qvw9-x4gw-6754/GHSA-qvw9-x4gw-6754.json b/advisories/unreviewed/2022/05/GHSA-qvw9-x4gw-6754/GHSA-qvw9-x4gw-6754.json index 196acd8d3f3..e1167154204 100644 --- a/advisories/unreviewed/2022/05/GHSA-qvw9-x4gw-6754/GHSA-qvw9-x4gw-6754.json +++ b/advisories/unreviewed/2022/05/GHSA-qvw9-x4gw-6754/GHSA-qvw9-x4gw-6754.json @@ -7,12 +7,8 @@ "CVE-2020-20138" ], "details": "Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw6q-h32m-cgfq/GHSA-qw6q-h32m-cgfq.json b/advisories/unreviewed/2022/05/GHSA-qw6q-h32m-cgfq/GHSA-qw6q-h32m-cgfq.json index 98357b5cd39..b6b960f45d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw6q-h32m-cgfq/GHSA-qw6q-h32m-cgfq.json +++ b/advisories/unreviewed/2022/05/GHSA-qw6q-h32m-cgfq/GHSA-qw6q-h32m-cgfq.json @@ -7,12 +7,8 @@ "CVE-2020-35715" ], "details": "Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r269-87mv-8wp9/GHSA-r269-87mv-8wp9.json b/advisories/unreviewed/2022/05/GHSA-r269-87mv-8wp9/GHSA-r269-87mv-8wp9.json index 4d577c2c879..1591cec00b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r269-87mv-8wp9/GHSA-r269-87mv-8wp9.json +++ b/advisories/unreviewed/2022/05/GHSA-r269-87mv-8wp9/GHSA-r269-87mv-8wp9.json @@ -7,12 +7,8 @@ "CVE-2020-8258" ], "details": "Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r295-fpcq-rg99/GHSA-r295-fpcq-rg99.json b/advisories/unreviewed/2022/05/GHSA-r295-fpcq-rg99/GHSA-r295-fpcq-rg99.json index 0a937f283e9..5f22ecfccde 100644 --- a/advisories/unreviewed/2022/05/GHSA-r295-fpcq-rg99/GHSA-r295-fpcq-rg99.json +++ b/advisories/unreviewed/2022/05/GHSA-r295-fpcq-rg99/GHSA-r295-fpcq-rg99.json @@ -7,12 +7,8 @@ "CVE-2020-25838" ], "details": "Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x versions. The vulnerability could be exploited to disclose unauthorized sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r29f-v3vg-4fcq/GHSA-r29f-v3vg-4fcq.json b/advisories/unreviewed/2022/05/GHSA-r29f-v3vg-4fcq/GHSA-r29f-v3vg-4fcq.json index e0d9462b273..1bdc8d845ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-r29f-v3vg-4fcq/GHSA-r29f-v3vg-4fcq.json +++ b/advisories/unreviewed/2022/05/GHSA-r29f-v3vg-4fcq/GHSA-r29f-v3vg-4fcq.json @@ -7,12 +7,8 @@ "CVE-2020-35589" ], "details": "The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2pg-5xw6-p694/GHSA-r2pg-5xw6-p694.json b/advisories/unreviewed/2022/05/GHSA-r2pg-5xw6-p694/GHSA-r2pg-5xw6-p694.json index 158694c93f1..c835b6b56b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2pg-5xw6-p694/GHSA-r2pg-5xw6-p694.json +++ b/advisories/unreviewed/2022/05/GHSA-r2pg-5xw6-p694/GHSA-r2pg-5xw6-p694.json @@ -7,12 +7,8 @@ "CVE-2020-27024" ], "details": "In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure triggered by a malformed Bluetooth packet, with no additional execution privileges needed. User interaction is not needed for exploitation. Bounds Sanitizer mitigates this in the default configuration.Product: AndroidVersions: Android-11Android ID: A-162327732", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r346-r4r7-jqhf/GHSA-r346-r4r7-jqhf.json b/advisories/unreviewed/2022/05/GHSA-r346-r4r7-jqhf/GHSA-r346-r4r7-jqhf.json index 93a87245551..4a859ab70d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-r346-r4r7-jqhf/GHSA-r346-r4r7-jqhf.json +++ b/advisories/unreviewed/2022/05/GHSA-r346-r4r7-jqhf/GHSA-r346-r4r7-jqhf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3q7-7pwq-hqq8/GHSA-r3q7-7pwq-hqq8.json b/advisories/unreviewed/2022/05/GHSA-r3q7-7pwq-hqq8/GHSA-r3q7-7pwq-hqq8.json index c96b3581968..d5a68220b91 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3q7-7pwq-hqq8/GHSA-r3q7-7pwq-hqq8.json +++ b/advisories/unreviewed/2022/05/GHSA-r3q7-7pwq-hqq8/GHSA-r3q7-7pwq-hqq8.json @@ -7,12 +7,8 @@ "CVE-2020-24683" ], "details": "The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network communication or endpoints for these applications are not protected, unauthorized actors can bypass authentication and make unauthorized connections to the server application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4r6-76p6-65m4/GHSA-r4r6-76p6-65m4.json b/advisories/unreviewed/2022/05/GHSA-r4r6-76p6-65m4/GHSA-r4r6-76p6-65m4.json index 77734324d65..8134f754ebd 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4r6-76p6-65m4/GHSA-r4r6-76p6-65m4.json +++ b/advisories/unreviewed/2022/05/GHSA-r4r6-76p6-65m4/GHSA-r4r6-76p6-65m4.json @@ -7,12 +7,8 @@ "CVE-2020-28070" ], "details": "SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4rr-cgc8-x5v8/GHSA-r4rr-cgc8-x5v8.json b/advisories/unreviewed/2022/05/GHSA-r4rr-cgc8-x5v8/GHSA-r4rr-cgc8-x5v8.json index 46125a94f6f..6315280ed6b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4rr-cgc8-x5v8/GHSA-r4rr-cgc8-x5v8.json +++ b/advisories/unreviewed/2022/05/GHSA-r4rr-cgc8-x5v8/GHSA-r4rr-cgc8-x5v8.json @@ -7,12 +7,8 @@ "CVE-2020-4845" ], "details": "IBM Security Key Lifecycle Manager 3.0.1 and 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190289.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r4xm-6p48-p6gf/GHSA-r4xm-6p48-p6gf.json b/advisories/unreviewed/2022/05/GHSA-r4xm-6p48-p6gf/GHSA-r4xm-6p48-p6gf.json index 62fea8791f6..607c06468e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4xm-6p48-p6gf/GHSA-r4xm-6p48-p6gf.json +++ b/advisories/unreviewed/2022/05/GHSA-r4xm-6p48-p6gf/GHSA-r4xm-6p48-p6gf.json @@ -7,12 +7,8 @@ "CVE-2020-27717" ], "details": "On BIG-IP DNS 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, undisclosed series of DNS requests may cause TMM to restart and generate a core file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r78c-53rf-ghjm/GHSA-r78c-53rf-ghjm.json b/advisories/unreviewed/2022/05/GHSA-r78c-53rf-ghjm/GHSA-r78c-53rf-ghjm.json index 8c6c07bc192..4ab1c9fc9ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-r78c-53rf-ghjm/GHSA-r78c-53rf-ghjm.json +++ b/advisories/unreviewed/2022/05/GHSA-r78c-53rf-ghjm/GHSA-r78c-53rf-ghjm.json @@ -7,12 +7,8 @@ "CVE-2020-8465" ], "details": "A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r7mj-3g43-28gm/GHSA-r7mj-3g43-28gm.json b/advisories/unreviewed/2022/05/GHSA-r7mj-3g43-28gm/GHSA-r7mj-3g43-28gm.json index abc1d6bc546..17285df3cd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7mj-3g43-28gm/GHSA-r7mj-3g43-28gm.json +++ b/advisories/unreviewed/2022/05/GHSA-r7mj-3g43-28gm/GHSA-r7mj-3g43-28gm.json @@ -7,12 +7,8 @@ "CVE-2020-35276" ], "details": "EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r7q6-f5hp-q2cq/GHSA-r7q6-f5hp-q2cq.json b/advisories/unreviewed/2022/05/GHSA-r7q6-f5hp-q2cq/GHSA-r7q6-f5hp-q2cq.json index 8b590a56919..330637bc167 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7q6-f5hp-q2cq/GHSA-r7q6-f5hp-q2cq.json +++ b/advisories/unreviewed/2022/05/GHSA-r7q6-f5hp-q2cq/GHSA-r7q6-f5hp-q2cq.json @@ -7,12 +7,8 @@ "CVE-2020-5639" ], "details": "Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific directory via unspecified vectors. As a result, an arbitrary OS command may be executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r929-7jrv-6rh2/GHSA-r929-7jrv-6rh2.json b/advisories/unreviewed/2022/05/GHSA-r929-7jrv-6rh2/GHSA-r929-7jrv-6rh2.json index 8e637f09435..cb6c55061bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-r929-7jrv-6rh2/GHSA-r929-7jrv-6rh2.json +++ b/advisories/unreviewed/2022/05/GHSA-r929-7jrv-6rh2/GHSA-r929-7jrv-6rh2.json @@ -7,12 +7,8 @@ "CVE-2020-25094" ], "details": "LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9v7-wgfw-56p5/GHSA-r9v7-wgfw-56p5.json b/advisories/unreviewed/2022/05/GHSA-r9v7-wgfw-56p5/GHSA-r9v7-wgfw-56p5.json index 733d1ea8e65..79f76ac85bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9v7-wgfw-56p5/GHSA-r9v7-wgfw-56p5.json +++ b/advisories/unreviewed/2022/05/GHSA-r9v7-wgfw-56p5/GHSA-r9v7-wgfw-56p5.json @@ -7,12 +7,8 @@ "CVE-2020-35187" ], "details": "The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9xw-pv6r-fxr3/GHSA-r9xw-pv6r-fxr3.json b/advisories/unreviewed/2022/05/GHSA-r9xw-pv6r-fxr3/GHSA-r9xw-pv6r-fxr3.json index e9893ccb561..ae5c333ab04 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9xw-pv6r-fxr3/GHSA-r9xw-pv6r-fxr3.json +++ b/advisories/unreviewed/2022/05/GHSA-r9xw-pv6r-fxr3/GHSA-r9xw-pv6r-fxr3.json @@ -7,12 +7,8 @@ "CVE-2020-5665" ], "details": "Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attacker to cause a denial-of-service (DoS) condition on program execution and communication by sending a specially crafted ARP packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rc2q-p83g-48vc/GHSA-rc2q-p83g-48vc.json b/advisories/unreviewed/2022/05/GHSA-rc2q-p83g-48vc/GHSA-rc2q-p83g-48vc.json index 7eb68d88a5f..d84c7a17537 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc2q-p83g-48vc/GHSA-rc2q-p83g-48vc.json +++ b/advisories/unreviewed/2022/05/GHSA-rc2q-p83g-48vc/GHSA-rc2q-p83g-48vc.json @@ -7,12 +7,8 @@ "CVE-2020-27397" ], "details": "Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server via uploading a maliciously crafted PHP file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rg38-723q-h7xm/GHSA-rg38-723q-h7xm.json b/advisories/unreviewed/2022/05/GHSA-rg38-723q-h7xm/GHSA-rg38-723q-h7xm.json index b3e3f039f1e..3d5559d51af 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg38-723q-h7xm/GHSA-rg38-723q-h7xm.json +++ b/advisories/unreviewed/2022/05/GHSA-rg38-723q-h7xm/GHSA-rg38-723q-h7xm.json @@ -7,12 +7,8 @@ "CVE-2020-14225" ], "details": "HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rg4r-734p-28pq/GHSA-rg4r-734p-28pq.json b/advisories/unreviewed/2022/05/GHSA-rg4r-734p-28pq/GHSA-rg4r-734p-28pq.json index c6290887ec5..1b58a99edfa 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg4r-734p-28pq/GHSA-rg4r-734p-28pq.json +++ b/advisories/unreviewed/2022/05/GHSA-rg4r-734p-28pq/GHSA-rg4r-734p-28pq.json @@ -7,12 +7,8 @@ "CVE-2020-28074" ], "details": "SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhq4-w8hr-cp6m/GHSA-rhq4-w8hr-cp6m.json b/advisories/unreviewed/2022/05/GHSA-rhq4-w8hr-cp6m/GHSA-rhq4-w8hr-cp6m.json index ebe5ebc2bc6..38cc29a65f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhq4-w8hr-cp6m/GHSA-rhq4-w8hr-cp6m.json +++ b/advisories/unreviewed/2022/05/GHSA-rhq4-w8hr-cp6m/GHSA-rhq4-w8hr-cp6m.json @@ -7,12 +7,8 @@ "CVE-2020-19165" ], "details": "PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjcf-2qpv-xpv2/GHSA-rjcf-2qpv-xpv2.json b/advisories/unreviewed/2022/05/GHSA-rjcf-2qpv-xpv2/GHSA-rjcf-2qpv-xpv2.json index 1ecff9a6704..e949f27f55e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjcf-2qpv-xpv2/GHSA-rjcf-2qpv-xpv2.json +++ b/advisories/unreviewed/2022/05/GHSA-rjcf-2qpv-xpv2/GHSA-rjcf-2qpv-xpv2.json @@ -7,12 +7,8 @@ "CVE-2020-5950" ], "details": "On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjmp-wffv-9cmf/GHSA-rjmp-wffv-9cmf.json b/advisories/unreviewed/2022/05/GHSA-rjmp-wffv-9cmf/GHSA-rjmp-wffv-9cmf.json index 3187d417e97..596828cc058 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjmp-wffv-9cmf/GHSA-rjmp-wffv-9cmf.json +++ b/advisories/unreviewed/2022/05/GHSA-rjmp-wffv-9cmf/GHSA-rjmp-wffv-9cmf.json @@ -7,12 +7,8 @@ "CVE-2020-29230" ], "details": "EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie according to the crafted payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmcg-rw28-jg8f/GHSA-rmcg-rw28-jg8f.json b/advisories/unreviewed/2022/05/GHSA-rmcg-rw28-jg8f/GHSA-rmcg-rw28-jg8f.json index 78cc024f348..056e9f45815 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmcg-rw28-jg8f/GHSA-rmcg-rw28-jg8f.json +++ b/advisories/unreviewed/2022/05/GHSA-rmcg-rw28-jg8f/GHSA-rmcg-rw28-jg8f.json @@ -7,12 +7,8 @@ "CVE-2020-35195" ], "details": "The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmr6-x3v6-grqm/GHSA-rmr6-x3v6-grqm.json b/advisories/unreviewed/2022/05/GHSA-rmr6-x3v6-grqm/GHSA-rmr6-x3v6-grqm.json index 5e6bd74f9ef..8326c3dc06d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmr6-x3v6-grqm/GHSA-rmr6-x3v6-grqm.json +++ b/advisories/unreviewed/2022/05/GHSA-rmr6-x3v6-grqm/GHSA-rmr6-x3v6-grqm.json @@ -7,12 +7,8 @@ "CVE-2020-27046" ], "details": "In nfc_ncif_proc_ee_action of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157649306", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpv9-285j-r9jm/GHSA-rpv9-285j-r9jm.json b/advisories/unreviewed/2022/05/GHSA-rpv9-285j-r9jm/GHSA-rpv9-285j-r9jm.json index a3b19cb5188..d78c3aad7a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpv9-285j-r9jm/GHSA-rpv9-285j-r9jm.json +++ b/advisories/unreviewed/2022/05/GHSA-rpv9-285j-r9jm/GHSA-rpv9-285j-r9jm.json @@ -7,12 +7,8 @@ "CVE-2020-35470" ], "details": "Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rq59-f4hv-p8wv/GHSA-rq59-f4hv-p8wv.json b/advisories/unreviewed/2022/05/GHSA-rq59-f4hv-p8wv/GHSA-rq59-f4hv-p8wv.json index 78aa65d1c40..456dcfae2bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq59-f4hv-p8wv/GHSA-rq59-f4hv-p8wv.json +++ b/advisories/unreviewed/2022/05/GHSA-rq59-f4hv-p8wv/GHSA-rq59-f4hv-p8wv.json @@ -7,12 +7,8 @@ "CVE-2020-25194" ], "details": "The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rqmv-893j-49p8/GHSA-rqmv-893j-49p8.json b/advisories/unreviewed/2022/05/GHSA-rqmv-893j-49p8/GHSA-rqmv-893j-49p8.json index 312f44236ad..db3074c7af2 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqmv-893j-49p8/GHSA-rqmv-893j-49p8.json +++ b/advisories/unreviewed/2022/05/GHSA-rqmv-893j-49p8/GHSA-rqmv-893j-49p8.json @@ -7,12 +7,8 @@ "CVE-2020-29570" ], "details": "An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialized, that the latter are also ready for use. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rqqp-68qw-6v7r/GHSA-rqqp-68qw-6v7r.json b/advisories/unreviewed/2022/05/GHSA-rqqp-68qw-6v7r/GHSA-rqqp-68qw-6v7r.json index 4fa7e4c2732..e7a125bba4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqqp-68qw-6v7r/GHSA-rqqp-68qw-6v7r.json +++ b/advisories/unreviewed/2022/05/GHSA-rqqp-68qw-6v7r/GHSA-rqqp-68qw-6v7r.json @@ -7,12 +7,8 @@ "CVE-2020-25618" ], "details": "An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rrj2-qpwr-2v2h/GHSA-rrj2-qpwr-2v2h.json b/advisories/unreviewed/2022/05/GHSA-rrj2-qpwr-2v2h/GHSA-rrj2-qpwr-2v2h.json index 153da8fc30a..d79d2f30019 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrj2-qpwr-2v2h/GHSA-rrj2-qpwr-2v2h.json +++ b/advisories/unreviewed/2022/05/GHSA-rrj2-qpwr-2v2h/GHSA-rrj2-qpwr-2v2h.json @@ -7,12 +7,8 @@ "CVE-2020-35552" ], "details": "An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (non-Qualcomm chipsets) software. Attackers can obtain sensitive location information because the configuration file is incorrect. The Samsung ID is SVE-2020-18678 (December 2020).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrx8-fq2r-pjvj/GHSA-rrx8-fq2r-pjvj.json b/advisories/unreviewed/2022/05/GHSA-rrx8-fq2r-pjvj/GHSA-rrx8-fq2r-pjvj.json index 297790fb00e..d83e3531d2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrx8-fq2r-pjvj/GHSA-rrx8-fq2r-pjvj.json +++ b/advisories/unreviewed/2022/05/GHSA-rrx8-fq2r-pjvj/GHSA-rrx8-fq2r-pjvj.json @@ -7,12 +7,8 @@ "CVE-2020-26766" ], "details": "A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvr3-f3x4-3669/GHSA-rvr3-f3x4-3669.json b/advisories/unreviewed/2022/05/GHSA-rvr3-f3x4-3669/GHSA-rvr3-f3x4-3669.json index ad7f0db5951..358ea4ac69d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvr3-f3x4-3669/GHSA-rvr3-f3x4-3669.json +++ b/advisories/unreviewed/2022/05/GHSA-rvr3-f3x4-3669/GHSA-rvr3-f3x4-3669.json @@ -7,12 +7,8 @@ "CVE-2020-26029" ], "details": "An issue was discovered in Zammad before 3.4.1. There are wrong authorization checks for impersonation requests via X-On-Behalf-Of. The authorization checks are performed for the actual user and not the one given in the X-On-Behalf-Of header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rxm3-3v27-86hh/GHSA-rxm3-3v27-86hh.json b/advisories/unreviewed/2022/05/GHSA-rxm3-3v27-86hh/GHSA-rxm3-3v27-86hh.json index f036f81961c..2a5657f9013 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxm3-3v27-86hh/GHSA-rxm3-3v27-86hh.json +++ b/advisories/unreviewed/2022/05/GHSA-rxm3-3v27-86hh/GHSA-rxm3-3v27-86hh.json @@ -7,12 +7,8 @@ "CVE-2020-14271" ], "details": "HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2fr-wv49-j53x/GHSA-v2fr-wv49-j53x.json b/advisories/unreviewed/2022/05/GHSA-v2fr-wv49-j53x/GHSA-v2fr-wv49-j53x.json index 9110fa568ae..437b8ef8c36 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2fr-wv49-j53x/GHSA-v2fr-wv49-j53x.json +++ b/advisories/unreviewed/2022/05/GHSA-v2fr-wv49-j53x/GHSA-v2fr-wv49-j53x.json @@ -7,12 +7,8 @@ "CVE-2020-29574" ], "details": "An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2jc-8954-6fhq/GHSA-v2jc-8954-6fhq.json b/advisories/unreviewed/2022/05/GHSA-v2jc-8954-6fhq/GHSA-v2jc-8954-6fhq.json index bdcb28fb319..99fdd60c33e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2jc-8954-6fhq/GHSA-v2jc-8954-6fhq.json +++ b/advisories/unreviewed/2022/05/GHSA-v2jc-8954-6fhq/GHSA-v2jc-8954-6fhq.json @@ -7,12 +7,8 @@ "CVE-2020-35806" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, RAX120 before 1.0.0.78, RBK22 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and WN3000RPv2 before 1.0.0.78.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2m8-9547-v9wg/GHSA-v2m8-9547-v9wg.json b/advisories/unreviewed/2022/05/GHSA-v2m8-9547-v9wg/GHSA-v2m8-9547-v9wg.json index 045138c6307..6f89beb5d8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2m8-9547-v9wg/GHSA-v2m8-9547-v9wg.json +++ b/advisories/unreviewed/2022/05/GHSA-v2m8-9547-v9wg/GHSA-v2m8-9547-v9wg.json @@ -7,12 +7,8 @@ "CVE-2020-0473" ], "details": "In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical possession of the device to transfer files to it over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160691486", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v439-79v8-38g8/GHSA-v439-79v8-38g8.json b/advisories/unreviewed/2022/05/GHSA-v439-79v8-38g8/GHSA-v439-79v8-38g8.json index c8e5f5a80c3..86741ecf20a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v439-79v8-38g8/GHSA-v439-79v8-38g8.json +++ b/advisories/unreviewed/2022/05/GHSA-v439-79v8-38g8/GHSA-v439-79v8-38g8.json @@ -7,12 +7,8 @@ "CVE-2020-35708" ], "details": "phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the \"Config - Import Administrators\" page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v44r-mggx-92j8/GHSA-v44r-mggx-92j8.json b/advisories/unreviewed/2022/05/GHSA-v44r-mggx-92j8/GHSA-v44r-mggx-92j8.json index 97d4caf5019..ac098fda0df 100644 --- a/advisories/unreviewed/2022/05/GHSA-v44r-mggx-92j8/GHSA-v44r-mggx-92j8.json +++ b/advisories/unreviewed/2022/05/GHSA-v44r-mggx-92j8/GHSA-v44r-mggx-92j8.json @@ -7,12 +7,8 @@ "CVE-2018-15634" ], "details": "Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4jv-x72w-cw2g/GHSA-v4jv-x72w-cw2g.json b/advisories/unreviewed/2022/05/GHSA-v4jv-x72w-cw2g/GHSA-v4jv-x72w-cw2g.json index 40783a9958e..e5041c66558 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4jv-x72w-cw2g/GHSA-v4jv-x72w-cw2g.json +++ b/advisories/unreviewed/2022/05/GHSA-v4jv-x72w-cw2g/GHSA-v4jv-x72w-cw2g.json @@ -7,12 +7,8 @@ "CVE-2020-25175" ], "details": "GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5jv-p23p-vwpj/GHSA-v5jv-p23p-vwpj.json b/advisories/unreviewed/2022/05/GHSA-v5jv-p23p-vwpj/GHSA-v5jv-p23p-vwpj.json index 779566d2925..3aa71f4bda0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5jv-p23p-vwpj/GHSA-v5jv-p23p-vwpj.json +++ b/advisories/unreviewed/2022/05/GHSA-v5jv-p23p-vwpj/GHSA-v5jv-p23p-vwpj.json @@ -7,12 +7,8 @@ "CVE-2020-0498" ], "details": "In decode_packed_entry_number of codebook.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160633884", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v67p-458v-rh8x/GHSA-v67p-458v-rh8x.json b/advisories/unreviewed/2022/05/GHSA-v67p-458v-rh8x/GHSA-v67p-458v-rh8x.json index 52012a707cc..7feaa02ab33 100644 --- a/advisories/unreviewed/2022/05/GHSA-v67p-458v-rh8x/GHSA-v67p-458v-rh8x.json +++ b/advisories/unreviewed/2022/05/GHSA-v67p-458v-rh8x/GHSA-v67p-458v-rh8x.json @@ -7,12 +7,8 @@ "CVE-2020-0280" ], "details": "In nci_proc_ee_management_rsp of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136565424", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8w3-7f3w-x353/GHSA-v8w3-7f3w-x353.json b/advisories/unreviewed/2022/05/GHSA-v8w3-7f3w-x353/GHSA-v8w3-7f3w-x353.json index b2fc96c5b8f..776cbe42d68 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8w3-7f3w-x353/GHSA-v8w3-7f3w-x353.json +++ b/advisories/unreviewed/2022/05/GHSA-v8w3-7f3w-x353/GHSA-v8w3-7f3w-x353.json @@ -7,12 +7,8 @@ "CVE-2020-26175" ], "details": "In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v96c-c8j8-qhm7/GHSA-v96c-c8j8-qhm7.json b/advisories/unreviewed/2022/05/GHSA-v96c-c8j8-qhm7/GHSA-v96c-c8j8-qhm7.json index 78ceed5ac0b..fa167f48969 100644 --- a/advisories/unreviewed/2022/05/GHSA-v96c-c8j8-qhm7/GHSA-v96c-c8j8-qhm7.json +++ b/advisories/unreviewed/2022/05/GHSA-v96c-c8j8-qhm7/GHSA-v96c-c8j8-qhm7.json @@ -7,12 +7,8 @@ "CVE-2020-2503" ], "details": "If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9mf-j57r-5vpr/GHSA-v9mf-j57r-5vpr.json b/advisories/unreviewed/2022/05/GHSA-v9mf-j57r-5vpr/GHSA-v9mf-j57r-5vpr.json index e017825fb82..38197685ca7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9mf-j57r-5vpr/GHSA-v9mf-j57r-5vpr.json +++ b/advisories/unreviewed/2022/05/GHSA-v9mf-j57r-5vpr/GHSA-v9mf-j57r-5vpr.json @@ -7,12 +7,8 @@ "CVE-2020-35190" ], "details": "The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9vh-7cjg-2wjm/GHSA-v9vh-7cjg-2wjm.json b/advisories/unreviewed/2022/05/GHSA-v9vh-7cjg-2wjm/GHSA-v9vh-7cjg-2wjm.json index 5d7e2f23f2a..28cccf41833 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9vh-7cjg-2wjm/GHSA-v9vh-7cjg-2wjm.json +++ b/advisories/unreviewed/2022/05/GHSA-v9vh-7cjg-2wjm/GHSA-v9vh-7cjg-2wjm.json @@ -7,12 +7,8 @@ "CVE-2020-35650" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgm_code_redeem POST Parameter in user-code-redemption.php, the ulgm_user_first POST Parameter in user-registration-form.php, the ulgm_user_last POST Parameter in user-registration-form.php, the ulgm_user_email POST Parameter in user-registration-form.php, the ulgm_code_registration POST Parameter in user-registration-form.php, the ulgm_terms_conditions POST Parameter in user-registration-form.php, the _ulgm_total_seats POST Parameter in frontend-uo_groups_buy_courses.php, the uncanny_group_signup_user_first POST Parameter in group-registration-form.php, the uncanny_group_signup_user_last POST Parameter in group-registration-form.php, the uncanny_group_signup_user_login POST Parameter in group-registration-form.php, the uncanny_group_signup_user_email POST Parameter in group-registration-form.php, the success-invited GET Parameter in frontend-uo_groups.php, the bulk-errors GET Parameter in frontend-uo_groups.php, or the message GET Parameter in frontend-uo_groups.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v9wx-6724-hmcm/GHSA-v9wx-6724-hmcm.json b/advisories/unreviewed/2022/05/GHSA-v9wx-6724-hmcm/GHSA-v9wx-6724-hmcm.json index f97b971b20d..b0e06b7dfc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9wx-6724-hmcm/GHSA-v9wx-6724-hmcm.json +++ b/advisories/unreviewed/2022/05/GHSA-v9wx-6724-hmcm/GHSA-v9wx-6724-hmcm.json @@ -7,12 +7,8 @@ "CVE-2020-25106" ], "details": "Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and then upload a Trojan horse with the Supremo.exe filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vc66-g998-2h5p/GHSA-vc66-g998-2h5p.json b/advisories/unreviewed/2022/05/GHSA-vc66-g998-2h5p/GHSA-vc66-g998-2h5p.json index 4e4c48af8d0..cfe3c0dd550 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc66-g998-2h5p/GHSA-vc66-g998-2h5p.json +++ b/advisories/unreviewed/2022/05/GHSA-vc66-g998-2h5p/GHSA-vc66-g998-2h5p.json @@ -7,12 +7,8 @@ "CVE-2020-35471" ], "details": "Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vccr-47hc-ff2r/GHSA-vccr-47hc-ff2r.json b/advisories/unreviewed/2022/05/GHSA-vccr-47hc-ff2r/GHSA-vccr-47hc-ff2r.json index 59d4e17de9e..bb7d9327f88 100644 --- a/advisories/unreviewed/2022/05/GHSA-vccr-47hc-ff2r/GHSA-vccr-47hc-ff2r.json +++ b/advisories/unreviewed/2022/05/GHSA-vccr-47hc-ff2r/GHSA-vccr-47hc-ff2r.json @@ -7,12 +7,8 @@ "CVE-2020-20141" ], "details": "Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcfv-2wp3-p4hq/GHSA-vcfv-2wp3-p4hq.json b/advisories/unreviewed/2022/05/GHSA-vcfv-2wp3-p4hq/GHSA-vcfv-2wp3-p4hq.json index a195dd96851..00126478605 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcfv-2wp3-p4hq/GHSA-vcfv-2wp3-p4hq.json +++ b/advisories/unreviewed/2022/05/GHSA-vcfv-2wp3-p4hq/GHSA-vcfv-2wp3-p4hq.json @@ -7,12 +7,8 @@ "CVE-2020-25108" ], "details": "An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The DNS response data length is not checked (it can be set to an arbitrary value from a packet). This may lead to successful Denial-of-Service, and possibly Remote Code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcqm-hqq4-5mxm/GHSA-vcqm-hqq4-5mxm.json b/advisories/unreviewed/2022/05/GHSA-vcqm-hqq4-5mxm/GHSA-vcqm-hqq4-5mxm.json index 65b66075fcb..b6d0497f6d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcqm-hqq4-5mxm/GHSA-vcqm-hqq4-5mxm.json +++ b/advisories/unreviewed/2022/05/GHSA-vcqm-hqq4-5mxm/GHSA-vcqm-hqq4-5mxm.json @@ -7,12 +7,8 @@ "CVE-2020-29481" ], "details": "An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/ are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfx7-j9j3-864c/GHSA-vfx7-j9j3-864c.json b/advisories/unreviewed/2022/05/GHSA-vfx7-j9j3-864c/GHSA-vfx7-j9j3-864c.json index c27b6eabdae..effb77223a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfx7-j9j3-864c/GHSA-vfx7-j9j3-864c.json +++ b/advisories/unreviewed/2022/05/GHSA-vfx7-j9j3-864c/GHSA-vfx7-j9j3-864c.json @@ -7,12 +7,8 @@ "CVE-2019-19288" ], "details": "A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vg65-j6rw-4575/GHSA-vg65-j6rw-4575.json b/advisories/unreviewed/2022/05/GHSA-vg65-j6rw-4575/GHSA-vg65-j6rw-4575.json index db8af3fd5e1..d20a9a2e3a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-vg65-j6rw-4575/GHSA-vg65-j6rw-4575.json +++ b/advisories/unreviewed/2022/05/GHSA-vg65-j6rw-4575/GHSA-vg65-j6rw-4575.json @@ -7,12 +7,8 @@ "CVE-2020-0460" ], "details": "In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-163413737", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vh92-g5r3-22x9/GHSA-vh92-g5r3-22x9.json b/advisories/unreviewed/2022/05/GHSA-vh92-g5r3-22x9/GHSA-vh92-g5r3-22x9.json index b7788db34e9..983964d55c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-vh92-g5r3-22x9/GHSA-vh92-g5r3-22x9.json +++ b/advisories/unreviewed/2022/05/GHSA-vh92-g5r3-22x9/GHSA-vh92-g5r3-22x9.json @@ -7,12 +7,8 @@ "CVE-2020-4906" ], "details": "IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhf3-r7x4-jc34/GHSA-vhf3-r7x4-jc34.json b/advisories/unreviewed/2022/05/GHSA-vhf3-r7x4-jc34/GHSA-vhf3-r7x4-jc34.json index 93414b6cb52..3d7cc72e3ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhf3-r7x4-jc34/GHSA-vhf3-r7x4-jc34.json +++ b/advisories/unreviewed/2022/05/GHSA-vhf3-r7x4-jc34/GHSA-vhf3-r7x4-jc34.json @@ -7,12 +7,8 @@ "CVE-2020-35349" ], "details": "Savsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vjqg-vc39-94mj/GHSA-vjqg-vc39-94mj.json b/advisories/unreviewed/2022/05/GHSA-vjqg-vc39-94mj/GHSA-vjqg-vc39-94mj.json index 33dd72cb04d..9f280d0e94f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjqg-vc39-94mj/GHSA-vjqg-vc39-94mj.json +++ b/advisories/unreviewed/2022/05/GHSA-vjqg-vc39-94mj/GHSA-vjqg-vc39-94mj.json @@ -7,12 +7,8 @@ "CVE-2020-35781" ], "details": "NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmcm-jg37-m6m9/GHSA-vmcm-jg37-m6m9.json b/advisories/unreviewed/2022/05/GHSA-vmcm-jg37-m6m9/GHSA-vmcm-jg37-m6m9.json index 4189767d678..d16fa83f627 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmcm-jg37-m6m9/GHSA-vmcm-jg37-m6m9.json +++ b/advisories/unreviewed/2022/05/GHSA-vmcm-jg37-m6m9/GHSA-vmcm-jg37-m6m9.json @@ -7,12 +7,8 @@ "CVE-2020-24673" ], "details": "In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. This can lead to a loss of confidentiality and data integrity or even affect the product behavior and its availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmhp-2g3x-cwwq/GHSA-vmhp-2g3x-cwwq.json b/advisories/unreviewed/2022/05/GHSA-vmhp-2g3x-cwwq/GHSA-vmhp-2g3x-cwwq.json index 0c2141c3ce6..b1d0c24e0d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmhp-2g3x-cwwq/GHSA-vmhp-2g3x-cwwq.json +++ b/advisories/unreviewed/2022/05/GHSA-vmhp-2g3x-cwwq/GHSA-vmhp-2g3x-cwwq.json @@ -7,12 +7,8 @@ "CVE-2020-0491" ], "details": "In readBlock of MatroskaExtractor.cpp, there is a possible denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156819528", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp46-jgwp-q8w3/GHSA-vp46-jgwp-q8w3.json b/advisories/unreviewed/2022/05/GHSA-vp46-jgwp-q8w3/GHSA-vp46-jgwp-q8w3.json index fd2edde74ba..8bbbcc7a768 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp46-jgwp-q8w3/GHSA-vp46-jgwp-q8w3.json +++ b/advisories/unreviewed/2022/05/GHSA-vp46-jgwp-q8w3/GHSA-vp46-jgwp-q8w3.json @@ -7,12 +7,8 @@ "CVE-2020-12521" ], "details": "On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system services or a complete reboot.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp7f-g57q-p9jx/GHSA-vp7f-g57q-p9jx.json b/advisories/unreviewed/2022/05/GHSA-vp7f-g57q-p9jx/GHSA-vp7f-g57q-p9jx.json index 3f0ab941fa5..da4b4848cad 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp7f-g57q-p9jx/GHSA-vp7f-g57q-p9jx.json +++ b/advisories/unreviewed/2022/05/GHSA-vp7f-g57q-p9jx/GHSA-vp7f-g57q-p9jx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp7r-p47m-4jvg/GHSA-vp7r-p47m-4jvg.json b/advisories/unreviewed/2022/05/GHSA-vp7r-p47m-4jvg/GHSA-vp7r-p47m-4jvg.json index 1fe92681b2c..36c850ebc13 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp7r-p47m-4jvg/GHSA-vp7r-p47m-4jvg.json +++ b/advisories/unreviewed/2022/05/GHSA-vp7r-p47m-4jvg/GHSA-vp7r-p47m-4jvg.json @@ -7,12 +7,8 @@ "CVE-2020-29159" ], "details": "An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpr2-238v-xc3f/GHSA-vpr2-238v-xc3f.json b/advisories/unreviewed/2022/05/GHSA-vpr2-238v-xc3f/GHSA-vpr2-238v-xc3f.json index 59295188658..c37e88c30ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpr2-238v-xc3f/GHSA-vpr2-238v-xc3f.json +++ b/advisories/unreviewed/2022/05/GHSA-vpr2-238v-xc3f/GHSA-vpr2-238v-xc3f.json @@ -7,12 +7,8 @@ "CVE-2020-27033" ], "details": "In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153655153", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq42-23mp-rqh2/GHSA-vq42-23mp-rqh2.json b/advisories/unreviewed/2022/05/GHSA-vq42-23mp-rqh2/GHSA-vq42-23mp-rqh2.json index 95cfe07b6a3..67a15d61338 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq42-23mp-rqh2/GHSA-vq42-23mp-rqh2.json +++ b/advisories/unreviewed/2022/05/GHSA-vq42-23mp-rqh2/GHSA-vq42-23mp-rqh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vr5w-372j-c5g6/GHSA-vr5w-372j-c5g6.json b/advisories/unreviewed/2022/05/GHSA-vr5w-372j-c5g6/GHSA-vr5w-372j-c5g6.json index 8717709dd92..6ac0aa2714b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr5w-372j-c5g6/GHSA-vr5w-372j-c5g6.json +++ b/advisories/unreviewed/2022/05/GHSA-vr5w-372j-c5g6/GHSA-vr5w-372j-c5g6.json @@ -7,12 +7,8 @@ "CVE-2020-4658" ], "details": "IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vrp2-68hc-jc3m/GHSA-vrp2-68hc-jc3m.json b/advisories/unreviewed/2022/05/GHSA-vrp2-68hc-jc3m/GHSA-vrp2-68hc-jc3m.json index fc685a7a91d..bfecb2341a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrp2-68hc-jc3m/GHSA-vrp2-68hc-jc3m.json +++ b/advisories/unreviewed/2022/05/GHSA-vrp2-68hc-jc3m/GHSA-vrp2-68hc-jc3m.json @@ -7,12 +7,8 @@ "CVE-2020-29469" ], "details": "WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload in the Setting - Menu and each time any user will visits the website directory, the XSS triggers and attacker can steal the cookie according to the crafted payload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvh2-xmj2-jf8r/GHSA-vvh2-xmj2-jf8r.json b/advisories/unreviewed/2022/05/GHSA-vvh2-xmj2-jf8r/GHSA-vvh2-xmj2-jf8r.json index e1e118b94f6..3b01fed2096 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvh2-xmj2-jf8r/GHSA-vvh2-xmj2-jf8r.json +++ b/advisories/unreviewed/2022/05/GHSA-vvh2-xmj2-jf8r/GHSA-vvh2-xmj2-jf8r.json @@ -7,12 +7,8 @@ "CVE-2020-28203" ], "details": "An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null pointer access/dereference while opening a crafted PDF file, leading the application to crash (denial of service).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw67-8g5q-g6f3/GHSA-vw67-8g5q-g6f3.json b/advisories/unreviewed/2022/05/GHSA-vw67-8g5q-g6f3/GHSA-vw67-8g5q-g6f3.json index 116a0b7c2bf..f963f4563c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw67-8g5q-g6f3/GHSA-vw67-8g5q-g6f3.json +++ b/advisories/unreviewed/2022/05/GHSA-vw67-8g5q-g6f3/GHSA-vw67-8g5q-g6f3.json @@ -7,12 +7,8 @@ "CVE-2020-0478" ], "details": "In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150780418", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxw2-5369-q2cg/GHSA-vxw2-5369-q2cg.json b/advisories/unreviewed/2022/05/GHSA-vxw2-5369-q2cg/GHSA-vxw2-5369-q2cg.json index d66a883f881..3705862180d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxw2-5369-q2cg/GHSA-vxw2-5369-q2cg.json +++ b/advisories/unreviewed/2022/05/GHSA-vxw2-5369-q2cg/GHSA-vxw2-5369-q2cg.json @@ -7,12 +7,8 @@ "CVE-2020-2496" ], "details": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w259-g563-xw2j/GHSA-w259-g563-xw2j.json b/advisories/unreviewed/2022/05/GHSA-w259-g563-xw2j/GHSA-w259-g563-xw2j.json index 64e1f3d0d7d..18c55f90d82 100644 --- a/advisories/unreviewed/2022/05/GHSA-w259-g563-xw2j/GHSA-w259-g563-xw2j.json +++ b/advisories/unreviewed/2022/05/GHSA-w259-g563-xw2j/GHSA-w259-g563-xw2j.json @@ -7,12 +7,8 @@ "CVE-2020-28214" ], "details": "A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an attacker to pre-compute the hash value using dictionary attack technique such as rainbow tables, effectively disabling the protection that an unpredictable salt would provide.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3xv-vqgp-pqp7/GHSA-w3xv-vqgp-pqp7.json b/advisories/unreviewed/2022/05/GHSA-w3xv-vqgp-pqp7/GHSA-w3xv-vqgp-pqp7.json index b68207b5053..4ebb10b0b06 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3xv-vqgp-pqp7/GHSA-w3xv-vqgp-pqp7.json +++ b/advisories/unreviewed/2022/05/GHSA-w3xv-vqgp-pqp7/GHSA-w3xv-vqgp-pqp7.json @@ -7,12 +7,8 @@ "CVE-2020-16104" ], "details": "SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if EDI is configured to import data from this database. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); 8.00 versions prior to 8.00.1228(MR6); version 7.90 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4rp-w99f-63vq/GHSA-w4rp-w99f-63vq.json b/advisories/unreviewed/2022/05/GHSA-w4rp-w99f-63vq/GHSA-w4rp-w99f-63vq.json index 26918cb5d37..9aa89e6ccb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4rp-w99f-63vq/GHSA-w4rp-w99f-63vq.json +++ b/advisories/unreviewed/2022/05/GHSA-w4rp-w99f-63vq/GHSA-w4rp-w99f-63vq.json @@ -7,12 +7,8 @@ "CVE-2020-13984" ], "details": "An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processing IPv6 extension headers in ext_hdr_options_process in net/ipv6/uip6.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4v7-6457-x826/GHSA-w4v7-6457-x826.json b/advisories/unreviewed/2022/05/GHSA-w4v7-6457-x826/GHSA-w4v7-6457-x826.json index cb1e3fa5120..0a37010b7c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4v7-6457-x826/GHSA-w4v7-6457-x826.json +++ b/advisories/unreviewed/2022/05/GHSA-w4v7-6457-x826/GHSA-w4v7-6457-x826.json @@ -7,12 +7,8 @@ "CVE-2020-35729" ], "details": "KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4x5-3c4x-9mmc/GHSA-w4x5-3c4x-9mmc.json b/advisories/unreviewed/2022/05/GHSA-w4x5-3c4x-9mmc/GHSA-w4x5-3c4x-9mmc.json index 65bb395fd3a..a6067277f8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4x5-3c4x-9mmc/GHSA-w4x5-3c4x-9mmc.json +++ b/advisories/unreviewed/2022/05/GHSA-w4x5-3c4x-9mmc/GHSA-w4x5-3c4x-9mmc.json @@ -7,12 +7,8 @@ "CVE-2020-27048" ], "details": "In RW_SendRawFrame of rw_main.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650117", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w55r-r9w2-g8ff/GHSA-w55r-r9w2-g8ff.json b/advisories/unreviewed/2022/05/GHSA-w55r-r9w2-g8ff/GHSA-w55r-r9w2-g8ff.json index 449baa21e79..2cb5b5d4df4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w55r-r9w2-g8ff/GHSA-w55r-r9w2-g8ff.json +++ b/advisories/unreviewed/2022/05/GHSA-w55r-r9w2-g8ff/GHSA-w55r-r9w2-g8ff.json @@ -7,12 +7,8 @@ "CVE-2020-29591" ], "details": "Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w56g-cw97-958x/GHSA-w56g-cw97-958x.json b/advisories/unreviewed/2022/05/GHSA-w56g-cw97-958x/GHSA-w56g-cw97-958x.json index 0505d05fa3b..ba3e527e54a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w56g-cw97-958x/GHSA-w56g-cw97-958x.json +++ b/advisories/unreviewed/2022/05/GHSA-w56g-cw97-958x/GHSA-w56g-cw97-958x.json @@ -7,12 +7,8 @@ "CVE-2020-24658" ], "details": "Arm Compiler 5 through 5.06u6 has an error in a stack protection feature designed to help spot stack-based buffer overflows in local arrays. When this feature is enabled, a protected function writes a guard value to the stack prior to (above) any vulnerable arrays in the stack. The guard value is checked for corruption on function return; corruption leads to an error-handler call. In certain circumstances, the reference value that is compared against the guard value is itself also written to the stack (after any vulnerable arrays). The reference value is written to the stack when the function runs out of registers to use for other temporary data. If both the reference value and the guard value are written to the stack, then the stack protection will fail to spot corruption when both values are overwritten with the same value. For both the reference value and the guard value to be corrupted, there would need to be both a buffer overflow and a buffer underflow in the vulnerable arrays (or some other vulnerability that causes two separated stack entries to be corrupted).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w664-p7q3-cm25/GHSA-w664-p7q3-cm25.json b/advisories/unreviewed/2022/05/GHSA-w664-p7q3-cm25/GHSA-w664-p7q3-cm25.json index 16ae4280d1b..935a3c0f33c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w664-p7q3-cm25/GHSA-w664-p7q3-cm25.json +++ b/advisories/unreviewed/2022/05/GHSA-w664-p7q3-cm25/GHSA-w664-p7q3-cm25.json @@ -7,12 +7,8 @@ "CVE-2020-26176" ], "details": "An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document//attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather valid attachment IDs for workitems that do not belong to them.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6cg-v47q-5p36/GHSA-w6cg-v47q-5p36.json b/advisories/unreviewed/2022/05/GHSA-w6cg-v47q-5p36/GHSA-w6cg-v47q-5p36.json index a713fddbac4..8584df9922a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6cg-v47q-5p36/GHSA-w6cg-v47q-5p36.json +++ b/advisories/unreviewed/2022/05/GHSA-w6cg-v47q-5p36/GHSA-w6cg-v47q-5p36.json @@ -7,12 +7,8 @@ "CVE-2020-35585" ], "details": "In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7cr-rvwx-67q2/GHSA-w7cr-rvwx-67q2.json b/advisories/unreviewed/2022/05/GHSA-w7cr-rvwx-67q2/GHSA-w7cr-rvwx-67q2.json index 371672c4491..27c5391a025 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7cr-rvwx-67q2/GHSA-w7cr-rvwx-67q2.json +++ b/advisories/unreviewed/2022/05/GHSA-w7cr-rvwx-67q2/GHSA-w7cr-rvwx-67q2.json @@ -7,12 +7,8 @@ "CVE-2020-24444" ], "details": "AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability could be exploited by an unauthenticated attacker to gather information about internal systems that reside on the same network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7fv-r9rg-26jv/GHSA-w7fv-r9rg-26jv.json b/advisories/unreviewed/2022/05/GHSA-w7fv-r9rg-26jv/GHSA-w7fv-r9rg-26jv.json index 1671c0dffa6..aabfb3a43b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7fv-r9rg-26jv/GHSA-w7fv-r9rg-26jv.json +++ b/advisories/unreviewed/2022/05/GHSA-w7fv-r9rg-26jv/GHSA-w7fv-r9rg-26jv.json @@ -7,12 +7,8 @@ "CVE-2020-20276" ], "details": "An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7qc-fcjr-rrg9/GHSA-w7qc-fcjr-rrg9.json b/advisories/unreviewed/2022/05/GHSA-w7qc-fcjr-rrg9/GHSA-w7qc-fcjr-rrg9.json index e873af5adea..0e9b7593f4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7qc-fcjr-rrg9/GHSA-w7qc-fcjr-rrg9.json +++ b/advisories/unreviewed/2022/05/GHSA-w7qc-fcjr-rrg9/GHSA-w7qc-fcjr-rrg9.json @@ -7,12 +7,8 @@ "CVE-2020-0486" ], "details": "In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege to change contact data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150857116", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7rv-vxq3-894m/GHSA-w7rv-vxq3-894m.json b/advisories/unreviewed/2022/05/GHSA-w7rv-vxq3-894m/GHSA-w7rv-vxq3-894m.json index 6e36b3c5371..47acbda49c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7rv-vxq3-894m/GHSA-w7rv-vxq3-894m.json +++ b/advisories/unreviewed/2022/05/GHSA-w7rv-vxq3-894m/GHSA-w7rv-vxq3-894m.json @@ -7,12 +7,8 @@ "CVE-2020-35359" ], "details": "Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w837-6x9x-3ccv/GHSA-w837-6x9x-3ccv.json b/advisories/unreviewed/2022/05/GHSA-w837-6x9x-3ccv/GHSA-w837-6x9x-3ccv.json index 4d8c583a32a..fc1b7e3de1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w837-6x9x-3ccv/GHSA-w837-6x9x-3ccv.json +++ b/advisories/unreviewed/2022/05/GHSA-w837-6x9x-3ccv/GHSA-w837-6x9x-3ccv.json @@ -7,12 +7,8 @@ "CVE-2020-0470" ], "details": "In extend_frame_highbd of restoration.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-166268541", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w9cm-mhh5-jvr7/GHSA-w9cm-mhh5-jvr7.json b/advisories/unreviewed/2022/05/GHSA-w9cm-mhh5-jvr7/GHSA-w9cm-mhh5-jvr7.json index 46617986967..c567eb19ad6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9cm-mhh5-jvr7/GHSA-w9cm-mhh5-jvr7.json +++ b/advisories/unreviewed/2022/05/GHSA-w9cm-mhh5-jvr7/GHSA-w9cm-mhh5-jvr7.json @@ -7,12 +7,8 @@ "CVE-2020-25109" ], "details": "An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in a DNS header) is not checked against the data present. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wf5j-wf7x-99jg/GHSA-wf5j-wf7x-99jg.json b/advisories/unreviewed/2022/05/GHSA-wf5j-wf7x-99jg/GHSA-wf5j-wf7x-99jg.json index 300e5fa763a..83cb43fc2c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf5j-wf7x-99jg/GHSA-wf5j-wf7x-99jg.json +++ b/advisories/unreviewed/2022/05/GHSA-wf5j-wf7x-99jg/GHSA-wf5j-wf7x-99jg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wf85-g3p6-xf4h/GHSA-wf85-g3p6-xf4h.json b/advisories/unreviewed/2022/05/GHSA-wf85-g3p6-xf4h/GHSA-wf85-g3p6-xf4h.json index 4ef132a115e..7bc27d4d370 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf85-g3p6-xf4h/GHSA-wf85-g3p6-xf4h.json +++ b/advisories/unreviewed/2022/05/GHSA-wf85-g3p6-xf4h/GHSA-wf85-g3p6-xf4h.json @@ -7,12 +7,8 @@ "CVE-2020-29385" ], "details": "GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop run infinitely. This bug can, for example, be triggered by calling this function with a GIF image with LZW compression that is crafted in a special way.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wf9q-mxc5-jqf9/GHSA-wf9q-mxc5-jqf9.json b/advisories/unreviewed/2022/05/GHSA-wf9q-mxc5-jqf9/GHSA-wf9q-mxc5-jqf9.json index 204770fb787..ea74192a3de 100644 --- a/advisories/unreviewed/2022/05/GHSA-wf9q-mxc5-jqf9/GHSA-wf9q-mxc5-jqf9.json +++ b/advisories/unreviewed/2022/05/GHSA-wf9q-mxc5-jqf9/GHSA-wf9q-mxc5-jqf9.json @@ -7,12 +7,8 @@ "CVE-2020-16268" ], "details": "The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a TRANSFORM (MST) with the option to disable the installation of the Nomad module. An attacker may craft a .reg file in a specific location that will be able to write to any registry key as an elevated user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfcr-2jqr-mq2c/GHSA-wfcr-2jqr-mq2c.json b/advisories/unreviewed/2022/05/GHSA-wfcr-2jqr-mq2c/GHSA-wfcr-2jqr-mq2c.json index a9bbe3baa32..622f4173dda 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfcr-2jqr-mq2c/GHSA-wfcr-2jqr-mq2c.json +++ b/advisories/unreviewed/2022/05/GHSA-wfcr-2jqr-mq2c/GHSA-wfcr-2jqr-mq2c.json @@ -7,12 +7,8 @@ "CVE-2020-35658" ], "details": "SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfwq-hhcq-h62r/GHSA-wfwq-hhcq-h62r.json b/advisories/unreviewed/2022/05/GHSA-wfwq-hhcq-h62r/GHSA-wfwq-hhcq-h62r.json index 42811950738..74d0ff2ba68 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfwq-hhcq-h62r/GHSA-wfwq-hhcq-h62r.json +++ b/advisories/unreviewed/2022/05/GHSA-wfwq-hhcq-h62r/GHSA-wfwq-hhcq-h62r.json @@ -7,12 +7,8 @@ "CVE-2020-14254" ], "details": "TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg6c-hmh5-phq6/GHSA-wg6c-hmh5-phq6.json b/advisories/unreviewed/2022/05/GHSA-wg6c-hmh5-phq6/GHSA-wg6c-hmh5-phq6.json index 0cbe10833e7..47b001d4fa4 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg6c-hmh5-phq6/GHSA-wg6c-hmh5-phq6.json +++ b/advisories/unreviewed/2022/05/GHSA-wg6c-hmh5-phq6/GHSA-wg6c-hmh5-phq6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wggc-wwp7-29vw/GHSA-wggc-wwp7-29vw.json b/advisories/unreviewed/2022/05/GHSA-wggc-wwp7-29vw/GHSA-wggc-wwp7-29vw.json index b571afe9ac5..e3d63ef8f78 100644 --- a/advisories/unreviewed/2022/05/GHSA-wggc-wwp7-29vw/GHSA-wggc-wwp7-29vw.json +++ b/advisories/unreviewed/2022/05/GHSA-wggc-wwp7-29vw/GHSA-wggc-wwp7-29vw.json @@ -7,12 +7,8 @@ "CVE-2020-4840" ], "details": "IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 190044.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whf5-659f-c55w/GHSA-whf5-659f-c55w.json b/advisories/unreviewed/2022/05/GHSA-whf5-659f-c55w/GHSA-whf5-659f-c55w.json index 3257637c096..558838ea32b 100644 --- a/advisories/unreviewed/2022/05/GHSA-whf5-659f-c55w/GHSA-whf5-659f-c55w.json +++ b/advisories/unreviewed/2022/05/GHSA-whf5-659f-c55w/GHSA-whf5-659f-c55w.json @@ -7,12 +7,8 @@ "CVE-2020-2491" ], "details": "This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whwp-phv5-w844/GHSA-whwp-phv5-w844.json b/advisories/unreviewed/2022/05/GHSA-whwp-phv5-w844/GHSA-whwp-phv5-w844.json index e2c8abcb8a6..dd49b823fd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-whwp-phv5-w844/GHSA-whwp-phv5-w844.json +++ b/advisories/unreviewed/2022/05/GHSA-whwp-phv5-w844/GHSA-whwp-phv5-w844.json @@ -7,12 +7,8 @@ "CVE-2020-17520" ], "details": "In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-whxp-588c-mcgq/GHSA-whxp-588c-mcgq.json b/advisories/unreviewed/2022/05/GHSA-whxp-588c-mcgq/GHSA-whxp-588c-mcgq.json index 2e3dd516713..3a83b3ca56f 100644 --- a/advisories/unreviewed/2022/05/GHSA-whxp-588c-mcgq/GHSA-whxp-588c-mcgq.json +++ b/advisories/unreviewed/2022/05/GHSA-whxp-588c-mcgq/GHSA-whxp-588c-mcgq.json @@ -7,12 +7,8 @@ "CVE-2020-35626" ], "details": "An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wj48-f7rr-8fm2/GHSA-wj48-f7rr-8fm2.json b/advisories/unreviewed/2022/05/GHSA-wj48-f7rr-8fm2/GHSA-wj48-f7rr-8fm2.json index a70cd28e341..e6e395b6534 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj48-f7rr-8fm2/GHSA-wj48-f7rr-8fm2.json +++ b/advisories/unreviewed/2022/05/GHSA-wj48-f7rr-8fm2/GHSA-wj48-f7rr-8fm2.json @@ -7,12 +7,8 @@ "CVE-2020-25195" ], "details": "The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjp8-43wv-mq9c/GHSA-wjp8-43wv-mq9c.json b/advisories/unreviewed/2022/05/GHSA-wjp8-43wv-mq9c/GHSA-wjp8-43wv-mq9c.json index f8dcf94fa32..a42b8a80dcc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjp8-43wv-mq9c/GHSA-wjp8-43wv-mq9c.json +++ b/advisories/unreviewed/2022/05/GHSA-wjp8-43wv-mq9c/GHSA-wjp8-43wv-mq9c.json @@ -7,12 +7,8 @@ "CVE-2020-28072" ], "details": "A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjx5-v4h6-vg36/GHSA-wjx5-v4h6-vg36.json b/advisories/unreviewed/2022/05/GHSA-wjx5-v4h6-vg36/GHSA-wjx5-v4h6-vg36.json index 6b3e5356a98..12611a15fa5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjx5-v4h6-vg36/GHSA-wjx5-v4h6-vg36.json +++ b/advisories/unreviewed/2022/05/GHSA-wjx5-v4h6-vg36/GHSA-wjx5-v4h6-vg36.json @@ -7,12 +7,8 @@ "CVE-2020-27066" ], "details": "In xfrm6_tunnel_free_spi of net/ipv6/xfrm6_tunnel.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168043318", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wm4j-739m-prwh/GHSA-wm4j-739m-prwh.json b/advisories/unreviewed/2022/05/GHSA-wm4j-739m-prwh/GHSA-wm4j-739m-prwh.json index 52f7055387d..a457fcc90ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm4j-739m-prwh/GHSA-wm4j-739m-prwh.json +++ b/advisories/unreviewed/2022/05/GHSA-wm4j-739m-prwh/GHSA-wm4j-739m-prwh.json @@ -7,12 +7,8 @@ "CVE-2020-19527" ], "details": "iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmp5-r8m4-q4rf/GHSA-wmp5-r8m4-q4rf.json b/advisories/unreviewed/2022/05/GHSA-wmp5-r8m4-q4rf/GHSA-wmp5-r8m4-q4rf.json index deb5667a756..8e8552c8fd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmp5-r8m4-q4rf/GHSA-wmp5-r8m4-q4rf.json +++ b/advisories/unreviewed/2022/05/GHSA-wmp5-r8m4-q4rf/GHSA-wmp5-r8m4-q4rf.json @@ -7,12 +7,8 @@ "CVE-2020-11717" ], "details": "An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmxq-cjwf-h4w6/GHSA-wmxq-cjwf-h4w6.json b/advisories/unreviewed/2022/05/GHSA-wmxq-cjwf-h4w6/GHSA-wmxq-cjwf-h4w6.json index f43cf95227e..0cefb5ae9af 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmxq-cjwf-h4w6/GHSA-wmxq-cjwf-h4w6.json +++ b/advisories/unreviewed/2022/05/GHSA-wmxq-cjwf-h4w6/GHSA-wmxq-cjwf-h4w6.json @@ -7,12 +7,8 @@ "CVE-2020-20285" ], "details": "There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wp96-g7r8-wxf4/GHSA-wp96-g7r8-wxf4.json b/advisories/unreviewed/2022/05/GHSA-wp96-g7r8-wxf4/GHSA-wp96-g7r8-wxf4.json index 15b5f164925..86273d3e078 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp96-g7r8-wxf4/GHSA-wp96-g7r8-wxf4.json +++ b/advisories/unreviewed/2022/05/GHSA-wp96-g7r8-wxf4/GHSA-wp96-g7r8-wxf4.json @@ -7,12 +7,8 @@ "CVE-2020-17438" ], "details": "An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incoming packet specified in its IP header, as well as the fragmentation offset value specified in the IP header. By crafting a packet with specific values of the IP header length and the fragmentation offset, attackers can write into the .bss section of the program (past the statically allocated buffer that is used for storing the fragmented data) and cause a denial of service in uip_reass() in uip.c, or possibly execute arbitrary code on some target architectures.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpf8-7mm6-jvgg/GHSA-wpf8-7mm6-jvgg.json b/advisories/unreviewed/2022/05/GHSA-wpf8-7mm6-jvgg/GHSA-wpf8-7mm6-jvgg.json index 682ad30a320..fff61725997 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpf8-7mm6-jvgg/GHSA-wpf8-7mm6-jvgg.json +++ b/advisories/unreviewed/2022/05/GHSA-wpf8-7mm6-jvgg/GHSA-wpf8-7mm6-jvgg.json @@ -7,12 +7,8 @@ "CVE-2020-35797" ], "details": "NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpjg-4663-xp87/GHSA-wpjg-4663-xp87.json b/advisories/unreviewed/2022/05/GHSA-wpjg-4663-xp87/GHSA-wpjg-4663-xp87.json index cf1c4a7a99d..7e94b721958 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpjg-4663-xp87/GHSA-wpjg-4663-xp87.json +++ b/advisories/unreviewed/2022/05/GHSA-wpjg-4663-xp87/GHSA-wpjg-4663-xp87.json @@ -7,12 +7,8 @@ "CVE-2020-0488" ], "details": "In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158484516", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrc6-j5cv-23xc/GHSA-wrc6-j5cv-23xc.json b/advisories/unreviewed/2022/05/GHSA-wrc6-j5cv-23xc/GHSA-wrc6-j5cv-23xc.json index e2389ea1f0a..d8c7bba3925 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrc6-j5cv-23xc/GHSA-wrc6-j5cv-23xc.json +++ b/advisories/unreviewed/2022/05/GHSA-wrc6-j5cv-23xc/GHSA-wrc6-j5cv-23xc.json @@ -7,12 +7,8 @@ "CVE-2020-28929" ], "details": "Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrwc-95g6-4fm3/GHSA-wrwc-95g6-4fm3.json b/advisories/unreviewed/2022/05/GHSA-wrwc-95g6-4fm3/GHSA-wrwc-95g6-4fm3.json index 8c684554fa7..eba842143ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrwc-95g6-4fm3/GHSA-wrwc-95g6-4fm3.json +++ b/advisories/unreviewed/2022/05/GHSA-wrwc-95g6-4fm3/GHSA-wrwc-95g6-4fm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv62-pfmm-x787/GHSA-wv62-pfmm-x787.json b/advisories/unreviewed/2022/05/GHSA-wv62-pfmm-x787/GHSA-wv62-pfmm-x787.json index c12e4f9f063..59873278655 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv62-pfmm-x787/GHSA-wv62-pfmm-x787.json +++ b/advisories/unreviewed/2022/05/GHSA-wv62-pfmm-x787/GHSA-wv62-pfmm-x787.json @@ -7,12 +7,8 @@ "CVE-2020-8937" ], "details": "An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to enc_untrusted_create_wait_queue that uses a pointer queue that relies on UntrustedLocalMemcpy, which fails to validate where the pointer is located. This allows an attacker to write memory values from within the enclave. We recommend upgrading past commit a37fb6a0e7daf30134dbbf357c9a518a1026aa02", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvgq-535m-4v9q/GHSA-wvgq-535m-4v9q.json b/advisories/unreviewed/2022/05/GHSA-wvgq-535m-4v9q/GHSA-wvgq-535m-4v9q.json index 68ac0c7ef01..0dd7b83a3c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvgq-535m-4v9q/GHSA-wvgq-535m-4v9q.json +++ b/advisories/unreviewed/2022/05/GHSA-wvgq-535m-4v9q/GHSA-wvgq-535m-4v9q.json @@ -7,12 +7,8 @@ "CVE-2020-9987" ], "details": "An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 14.0. Visiting a malicious website may lead to address bar spoofing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvmj-h4cr-4hm5/GHSA-wvmj-h4cr-4hm5.json b/advisories/unreviewed/2022/05/GHSA-wvmj-h4cr-4hm5/GHSA-wvmj-h4cr-4hm5.json index 9102fdc3d2d..5876643d884 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvmj-h4cr-4hm5/GHSA-wvmj-h4cr-4hm5.json +++ b/advisories/unreviewed/2022/05/GHSA-wvmj-h4cr-4hm5/GHSA-wvmj-h4cr-4hm5.json @@ -7,12 +7,8 @@ "CVE-2020-35497" ], "details": "A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvqx-p547-9g79/GHSA-wvqx-p547-9g79.json b/advisories/unreviewed/2022/05/GHSA-wvqx-p547-9g79/GHSA-wvqx-p547-9g79.json index cbb5585d210..4a1b7982578 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvqx-p547-9g79/GHSA-wvqx-p547-9g79.json +++ b/advisories/unreviewed/2022/05/GHSA-wvqx-p547-9g79/GHSA-wvqx-p547-9g79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvrc-g9x3-j4vp/GHSA-wvrc-g9x3-j4vp.json b/advisories/unreviewed/2022/05/GHSA-wvrc-g9x3-j4vp/GHSA-wvrc-g9x3-j4vp.json index 735eb35ad78..eda5cdd6c02 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvrc-g9x3-j4vp/GHSA-wvrc-g9x3-j4vp.json +++ b/advisories/unreviewed/2022/05/GHSA-wvrc-g9x3-j4vp/GHSA-wvrc-g9x3-j4vp.json @@ -7,12 +7,8 @@ "CVE-2020-7203" ], "details": "A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2mc-h9jg-q83c/GHSA-x2mc-h9jg-q83c.json b/advisories/unreviewed/2022/05/GHSA-x2mc-h9jg-q83c/GHSA-x2mc-h9jg-q83c.json index 41c641cd106..b629b76cc30 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2mc-h9jg-q83c/GHSA-x2mc-h9jg-q83c.json +++ b/advisories/unreviewed/2022/05/GHSA-x2mc-h9jg-q83c/GHSA-x2mc-h9jg-q83c.json @@ -7,12 +7,8 @@ "CVE-2020-17442" ], "details": "An issue was discovered in picoTCP 1.7.0. The code for parsing the hop-by-hop IPv6 extension headers does not validate the bounds of the extension header length value, which may result in Integer Wraparound. Therefore, a crafted extension header length value may cause Denial-of-Service because it affects the loop in which the extension headers are parsed in pico_ipv6_process_hopbyhop() in pico_ipv6.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4v5-j466-v6ph/GHSA-x4v5-j466-v6ph.json b/advisories/unreviewed/2022/05/GHSA-x4v5-j466-v6ph/GHSA-x4v5-j466-v6ph.json index 57219fddb53..7ea4869e5f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4v5-j466-v6ph/GHSA-x4v5-j466-v6ph.json +++ b/advisories/unreviewed/2022/05/GHSA-x4v5-j466-v6ph/GHSA-x4v5-j466-v6ph.json @@ -7,12 +7,8 @@ "CVE-2020-35584" ], "details": "In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5fh-cqhm-x62g/GHSA-x5fh-cqhm-x62g.json b/advisories/unreviewed/2022/05/GHSA-x5fh-cqhm-x62g/GHSA-x5fh-cqhm-x62g.json index c41013f8c3b..6aad7a01e4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5fh-cqhm-x62g/GHSA-x5fh-cqhm-x62g.json +++ b/advisories/unreviewed/2022/05/GHSA-x5fh-cqhm-x62g/GHSA-x5fh-cqhm-x62g.json @@ -7,12 +7,8 @@ "CVE-2020-7540" ], "details": "A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause unauthenticated command execution in the controller when sending special HTTP requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5v9-pwhj-pwmx/GHSA-x5v9-pwhj-pwmx.json b/advisories/unreviewed/2022/05/GHSA-x5v9-pwhj-pwmx/GHSA-x5v9-pwhj-pwmx.json index f85d0756dd9..e0e2ca61be2 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5v9-pwhj-pwmx/GHSA-x5v9-pwhj-pwmx.json +++ b/advisories/unreviewed/2022/05/GHSA-x5v9-pwhj-pwmx/GHSA-x5v9-pwhj-pwmx.json @@ -7,12 +7,8 @@ "CVE-2020-29194" ], "details": "Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a physical reset to restore administrative control) via Randomnum=99AC8CEC6E845B28&mode=1 in a POST request to the cgi-bin/set_factory URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x697-2xrm-fh6r/GHSA-x697-2xrm-fh6r.json b/advisories/unreviewed/2022/05/GHSA-x697-2xrm-fh6r/GHSA-x697-2xrm-fh6r.json index 8da1e28a8d0..5d85c424072 100644 --- a/advisories/unreviewed/2022/05/GHSA-x697-2xrm-fh6r/GHSA-x697-2xrm-fh6r.json +++ b/advisories/unreviewed/2022/05/GHSA-x697-2xrm-fh6r/GHSA-x697-2xrm-fh6r.json @@ -7,12 +7,8 @@ "CVE-2020-3999" ], "details": "VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual machine can crash the virtual machine's vmx process leading to a denial of service condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6hc-2whc-99qv/GHSA-x6hc-2whc-99qv.json b/advisories/unreviewed/2022/05/GHSA-x6hc-2whc-99qv/GHSA-x6hc-2whc-99qv.json index 99b5cef64d1..03da1fac93a 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6hc-2whc-99qv/GHSA-x6hc-2whc-99qv.json +++ b/advisories/unreviewed/2022/05/GHSA-x6hc-2whc-99qv/GHSA-x6hc-2whc-99qv.json @@ -7,12 +7,8 @@ "CVE-2020-7539" ], "details": "A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause a denial of service vulnerability when a specially crafted packet is sent to the controller over HTTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6mh-cwpq-vw2f/GHSA-x6mh-cwpq-vw2f.json b/advisories/unreviewed/2022/05/GHSA-x6mh-cwpq-vw2f/GHSA-x6mh-cwpq-vw2f.json index 73766650164..39469911801 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6mh-cwpq-vw2f/GHSA-x6mh-cwpq-vw2f.json +++ b/advisories/unreviewed/2022/05/GHSA-x6mh-cwpq-vw2f/GHSA-x6mh-cwpq-vw2f.json @@ -7,12 +7,8 @@ "CVE-2020-35809" ], "details": "Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.74, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6w9-f57m-rh5h/GHSA-x6w9-f57m-rh5h.json b/advisories/unreviewed/2022/05/GHSA-x6w9-f57m-rh5h/GHSA-x6w9-f57m-rh5h.json index abef6a7e385..c83ddc39997 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6w9-f57m-rh5h/GHSA-x6w9-f57m-rh5h.json +++ b/advisories/unreviewed/2022/05/GHSA-x6w9-f57m-rh5h/GHSA-x6w9-f57m-rh5h.json @@ -7,12 +7,8 @@ "CVE-2020-24440" ], "details": "Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x993-24wq-x7c4/GHSA-x993-24wq-x7c4.json b/advisories/unreviewed/2022/05/GHSA-x993-24wq-x7c4/GHSA-x993-24wq-x7c4.json index 82099653213..566df419d34 100644 --- a/advisories/unreviewed/2022/05/GHSA-x993-24wq-x7c4/GHSA-x993-24wq-x7c4.json +++ b/advisories/unreviewed/2022/05/GHSA-x993-24wq-x7c4/GHSA-x993-24wq-x7c4.json @@ -7,12 +7,8 @@ "CVE-2020-29567" ], "details": "An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated and de-allocated on the relevant CPUs. De-allocation has to happen when certain constraints are met. If these conditions are not met when first checked, the checking CPU may send an interrupt to itself, in the expectation that this IRQ will be delivered only after the condition preventing the cleanup has cleared. For two specific IRQ vectors, this expectation was violated, resulting in a continuous stream of self-interrupts, which renders the CPU effectively unusable. A domain with a passed through PCI device can cause lockup of a physical CPU, resulting in a Denial of Service (DoS) to the entire host. Only x86 systems are vulnerable. Arm systems are not vulnerable. Only guests with physical PCI devices passed through to them can exploit the vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xcvh-gw38-q5j4/GHSA-xcvh-gw38-q5j4.json b/advisories/unreviewed/2022/05/GHSA-xcvh-gw38-q5j4/GHSA-xcvh-gw38-q5j4.json index c8dacf1ed9d..92ca74426c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcvh-gw38-q5j4/GHSA-xcvh-gw38-q5j4.json +++ b/advisories/unreviewed/2022/05/GHSA-xcvh-gw38-q5j4/GHSA-xcvh-gw38-q5j4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfpf-x83h-3xxj/GHSA-xfpf-x83h-3xxj.json b/advisories/unreviewed/2022/05/GHSA-xfpf-x83h-3xxj/GHSA-xfpf-x83h-3xxj.json index 1facd530f9d..5e0bbcf9b7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfpf-x83h-3xxj/GHSA-xfpf-x83h-3xxj.json +++ b/advisories/unreviewed/2022/05/GHSA-xfpf-x83h-3xxj/GHSA-xfpf-x83h-3xxj.json @@ -7,12 +7,8 @@ "CVE-2020-28220" ], "details": "A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfr6-j4fr-qr42/GHSA-xfr6-j4fr-qr42.json b/advisories/unreviewed/2022/05/GHSA-xfr6-j4fr-qr42/GHSA-xfr6-j4fr-qr42.json index a0988de17ba..3f4f97e05b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfr6-j4fr-qr42/GHSA-xfr6-j4fr-qr42.json +++ b/advisories/unreviewed/2022/05/GHSA-xfr6-j4fr-qr42/GHSA-xfr6-j4fr-qr42.json @@ -7,12 +7,8 @@ "CVE-2020-35742" ], "details": "HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg2h-6837-gq97/GHSA-xg2h-6837-gq97.json b/advisories/unreviewed/2022/05/GHSA-xg2h-6837-gq97/GHSA-xg2h-6837-gq97.json index 1caf22fa625..186bfc39d4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg2h-6837-gq97/GHSA-xg2h-6837-gq97.json +++ b/advisories/unreviewed/2022/05/GHSA-xg2h-6837-gq97/GHSA-xg2h-6837-gq97.json @@ -7,12 +7,8 @@ "CVE-2020-29304" ], "details": "A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and previous, allows attackers who have convinced a site administrator to import a specially crafted CSV file to inject arbitrary web script or HTML as the victim is proceeding through the file import workflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh5j-7f7g-7g5c/GHSA-xh5j-7f7g-7g5c.json b/advisories/unreviewed/2022/05/GHSA-xh5j-7f7g-7g5c/GHSA-xh5j-7f7g-7g5c.json index 5b4d8fdf66c..9524d164a11 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh5j-7f7g-7g5c/GHSA-xh5j-7f7g-7g5c.json +++ b/advisories/unreviewed/2022/05/GHSA-xh5j-7f7g-7g5c/GHSA-xh5j-7f7g-7g5c.json @@ -7,12 +7,8 @@ "CVE-2020-8919" ], "details": "An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm3x-2cx4-fh5j/GHSA-xm3x-2cx4-fh5j.json b/advisories/unreviewed/2022/05/GHSA-xm3x-2cx4-fh5j/GHSA-xm3x-2cx4-fh5j.json index 8a66c51144f..a1eeb70bcd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm3x-2cx4-fh5j/GHSA-xm3x-2cx4-fh5j.json +++ b/advisories/unreviewed/2022/05/GHSA-xm3x-2cx4-fh5j/GHSA-xm3x-2cx4-fh5j.json @@ -7,12 +7,8 @@ "CVE-2020-0483" ], "details": "In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155647761", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm7q-pmpg-2fgh/GHSA-xm7q-pmpg-2fgh.json b/advisories/unreviewed/2022/05/GHSA-xm7q-pmpg-2fgh/GHSA-xm7q-pmpg-2fgh.json index 83b75ea5d95..9f452259a9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm7q-pmpg-2fgh/GHSA-xm7q-pmpg-2fgh.json +++ b/advisories/unreviewed/2022/05/GHSA-xm7q-pmpg-2fgh/GHSA-xm7q-pmpg-2fgh.json @@ -7,12 +7,8 @@ "CVE-2020-35464" ], "details": "Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xpm4-75c2-wrgc/GHSA-xpm4-75c2-wrgc.json b/advisories/unreviewed/2022/05/GHSA-xpm4-75c2-wrgc/GHSA-xpm4-75c2-wrgc.json index 800b051b118..0a024d990b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpm4-75c2-wrgc/GHSA-xpm4-75c2-wrgc.json +++ b/advisories/unreviewed/2022/05/GHSA-xpm4-75c2-wrgc/GHSA-xpm4-75c2-wrgc.json @@ -7,12 +7,8 @@ "CVE-2020-27837" ], "details": "A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xpp6-cm2v-hmmg/GHSA-xpp6-cm2v-hmmg.json b/advisories/unreviewed/2022/05/GHSA-xpp6-cm2v-hmmg/GHSA-xpp6-cm2v-hmmg.json index ce2e74f349b..3f1d5757ac9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpp6-cm2v-hmmg/GHSA-xpp6-cm2v-hmmg.json +++ b/advisories/unreviewed/2022/05/GHSA-xpp6-cm2v-hmmg/GHSA-xpp6-cm2v-hmmg.json @@ -7,12 +7,8 @@ "CVE-2020-35193" ], "details": "The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xprx-5rcx-fjcv/GHSA-xprx-5rcx-fjcv.json b/advisories/unreviewed/2022/05/GHSA-xprx-5rcx-fjcv/GHSA-xprx-5rcx-fjcv.json index 304287e9e80..52c455f0baf 100644 --- a/advisories/unreviewed/2022/05/GHSA-xprx-5rcx-fjcv/GHSA-xprx-5rcx-fjcv.json +++ b/advisories/unreviewed/2022/05/GHSA-xprx-5rcx-fjcv/GHSA-xprx-5rcx-fjcv.json @@ -7,12 +7,8 @@ "CVE-2020-35474" ], "details": "In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xrrg-g9h8-vr6w/GHSA-xrrg-g9h8-vr6w.json b/advisories/unreviewed/2022/05/GHSA-xrrg-g9h8-vr6w/GHSA-xrrg-g9h8-vr6w.json index 257d868cb40..1666b443499 100644 --- a/advisories/unreviewed/2022/05/GHSA-xrrg-g9h8-vr6w/GHSA-xrrg-g9h8-vr6w.json +++ b/advisories/unreviewed/2022/05/GHSA-xrrg-g9h8-vr6w/GHSA-xrrg-g9h8-vr6w.json @@ -7,12 +7,8 @@ "CVE-2020-25235" ], "details": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for authentication for the LOGO! Website and the LOGO! Access Tool is sent in a recoverable format. An attacker with access to the network traffic could derive valid logins.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv45-rrwp-wgf4/GHSA-xv45-rrwp-wgf4.json b/advisories/unreviewed/2022/05/GHSA-xv45-rrwp-wgf4/GHSA-xv45-rrwp-wgf4.json index 5187c84b4d1..2604907a4cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv45-rrwp-wgf4/GHSA-xv45-rrwp-wgf4.json +++ b/advisories/unreviewed/2022/05/GHSA-xv45-rrwp-wgf4/GHSA-xv45-rrwp-wgf4.json @@ -7,12 +7,8 @@ "CVE-2020-35196" ], "details": "The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv4r-prr7-qwvx/GHSA-xv4r-prr7-qwvx.json b/advisories/unreviewed/2022/05/GHSA-xv4r-prr7-qwvx/GHSA-xv4r-prr7-qwvx.json index 3f39f8e6eca..7ce22d1c30b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv4r-prr7-qwvx/GHSA-xv4r-prr7-qwvx.json +++ b/advisories/unreviewed/2022/05/GHSA-xv4r-prr7-qwvx/GHSA-xv4r-prr7-qwvx.json @@ -7,12 +7,8 @@ "CVE-2020-27726" ], "details": "In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv6f-5jw7-pmw8/GHSA-xv6f-5jw7-pmw8.json b/advisories/unreviewed/2022/05/GHSA-xv6f-5jw7-pmw8/GHSA-xv6f-5jw7-pmw8.json index ca97e2a82c2..32d609d318d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv6f-5jw7-pmw8/GHSA-xv6f-5jw7-pmw8.json +++ b/advisories/unreviewed/2022/05/GHSA-xv6f-5jw7-pmw8/GHSA-xv6f-5jw7-pmw8.json @@ -7,12 +7,8 @@ "CVE-2020-26171" ], "details": "In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwgf-pv23-3mwx/GHSA-xwgf-pv23-3mwx.json b/advisories/unreviewed/2022/05/GHSA-xwgf-pv23-3mwx/GHSA-xwgf-pv23-3mwx.json index 3e69bd6585e..4c4f927e542 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwgf-pv23-3mwx/GHSA-xwgf-pv23-3mwx.json +++ b/advisories/unreviewed/2022/05/GHSA-xwgf-pv23-3mwx/GHSA-xwgf-pv23-3mwx.json @@ -7,12 +7,8 @@ "CVE-2020-25611" ], "details": "The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an attacker to view user conference information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwrh-p54h-h89c/GHSA-xwrh-p54h-h89c.json b/advisories/unreviewed/2022/05/GHSA-xwrh-p54h-h89c/GHSA-xwrh-p54h-h89c.json index 6e9070a3ffc..858ca16e7e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwrh-p54h-h89c/GHSA-xwrh-p54h-h89c.json +++ b/advisories/unreviewed/2022/05/GHSA-xwrh-p54h-h89c/GHSA-xwrh-p54h-h89c.json @@ -7,12 +7,8 @@ "CVE-2020-2495" ], "details": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xx27-x5jh-mcrm/GHSA-xx27-x5jh-mcrm.json b/advisories/unreviewed/2022/05/GHSA-xx27-x5jh-mcrm/GHSA-xx27-x5jh-mcrm.json index 4f3450d4744..3bf1f3e44eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xx27-x5jh-mcrm/GHSA-xx27-x5jh-mcrm.json +++ b/advisories/unreviewed/2022/05/GHSA-xx27-x5jh-mcrm/GHSA-xx27-x5jh-mcrm.json @@ -7,12 +7,8 @@ "CVE-2020-0464" ], "details": "In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150371903", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxrm-mm6r-v5x3/GHSA-xxrm-mm6r-v5x3.json b/advisories/unreviewed/2022/05/GHSA-xxrm-mm6r-v5x3/GHSA-xxrm-mm6r-v5x3.json index 5d6bf5687f7..9a124617384 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxrm-mm6r-v5x3/GHSA-xxrm-mm6r-v5x3.json +++ b/advisories/unreviewed/2022/05/GHSA-xxrm-mm6r-v5x3/GHSA-xxrm-mm6r-v5x3.json @@ -7,12 +7,8 @@ "CVE-2019-11782" ], "details": "Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-7xh6-c3pp-j98r/GHSA-7xh6-c3pp-j98r.json b/advisories/unreviewed/2022/10/GHSA-7xh6-c3pp-j98r/GHSA-7xh6-c3pp-j98r.json index a3d8519a11c..a4239b9fcd7 100644 --- a/advisories/unreviewed/2022/10/GHSA-7xh6-c3pp-j98r/GHSA-7xh6-c3pp-j98r.json +++ b/advisories/unreviewed/2022/10/GHSA-7xh6-c3pp-j98r/GHSA-7xh6-c3pp-j98r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-fqpx-62jv-7r6r/GHSA-fqpx-62jv-7r6r.json b/advisories/unreviewed/2022/10/GHSA-fqpx-62jv-7r6r/GHSA-fqpx-62jv-7r6r.json index b33c2c52350..da6f57decfb 100644 --- a/advisories/unreviewed/2022/10/GHSA-fqpx-62jv-7r6r/GHSA-fqpx-62jv-7r6r.json +++ b/advisories/unreviewed/2022/10/GHSA-fqpx-62jv-7r6r/GHSA-fqpx-62jv-7r6r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-jr2r-wpvw-6j23/GHSA-jr2r-wpvw-6j23.json b/advisories/unreviewed/2022/10/GHSA-jr2r-wpvw-6j23/GHSA-jr2r-wpvw-6j23.json index d2ca8fcf55c..ce1565a03a7 100644 --- a/advisories/unreviewed/2022/10/GHSA-jr2r-wpvw-6j23/GHSA-jr2r-wpvw-6j23.json +++ b/advisories/unreviewed/2022/10/GHSA-jr2r-wpvw-6j23/GHSA-jr2r-wpvw-6j23.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-m3hq-grv6-h853/GHSA-m3hq-grv6-h853.json b/advisories/unreviewed/2022/10/GHSA-m3hq-grv6-h853/GHSA-m3hq-grv6-h853.json index 05e0a83c7b2..f6b707f29e1 100644 --- a/advisories/unreviewed/2022/10/GHSA-m3hq-grv6-h853/GHSA-m3hq-grv6-h853.json +++ b/advisories/unreviewed/2022/10/GHSA-m3hq-grv6-h853/GHSA-m3hq-grv6-h853.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/10/GHSA-x8jh-7xwf-ghj2/GHSA-x8jh-7xwf-ghj2.json b/advisories/unreviewed/2022/10/GHSA-x8jh-7xwf-ghj2/GHSA-x8jh-7xwf-ghj2.json index 72c6641f5b3..490dab45cbf 100644 --- a/advisories/unreviewed/2022/10/GHSA-x8jh-7xwf-ghj2/GHSA-x8jh-7xwf-ghj2.json +++ b/advisories/unreviewed/2022/10/GHSA-x8jh-7xwf-ghj2/GHSA-x8jh-7xwf-ghj2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-86j9-qmrw-64jx/GHSA-86j9-qmrw-64jx.json b/advisories/unreviewed/2023/01/GHSA-86j9-qmrw-64jx/GHSA-86j9-qmrw-64jx.json index 5562d329b9b..ed22f224dc7 100644 --- a/advisories/unreviewed/2023/01/GHSA-86j9-qmrw-64jx/GHSA-86j9-qmrw-64jx.json +++ b/advisories/unreviewed/2023/01/GHSA-86j9-qmrw-64jx/GHSA-86j9-qmrw-64jx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-g7w4-828g-mrpg/GHSA-g7w4-828g-mrpg.json b/advisories/unreviewed/2023/01/GHSA-g7w4-828g-mrpg/GHSA-g7w4-828g-mrpg.json index a591e3897e4..c11036d5b9c 100644 --- a/advisories/unreviewed/2023/01/GHSA-g7w4-828g-mrpg/GHSA-g7w4-828g-mrpg.json +++ b/advisories/unreviewed/2023/01/GHSA-g7w4-828g-mrpg/GHSA-g7w4-828g-mrpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-jg35-qfcc-j9gj/GHSA-jg35-qfcc-j9gj.json b/advisories/unreviewed/2023/01/GHSA-jg35-qfcc-j9gj/GHSA-jg35-qfcc-j9gj.json index e8df672e9c6..b05d2ddcfc8 100644 --- a/advisories/unreviewed/2023/01/GHSA-jg35-qfcc-j9gj/GHSA-jg35-qfcc-j9gj.json +++ b/advisories/unreviewed/2023/01/GHSA-jg35-qfcc-j9gj/GHSA-jg35-qfcc-j9gj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-mcqq-vx7f-6ffh/GHSA-mcqq-vx7f-6ffh.json b/advisories/unreviewed/2023/01/GHSA-mcqq-vx7f-6ffh/GHSA-mcqq-vx7f-6ffh.json index 22f2f7c1db0..ec215dfa842 100644 --- a/advisories/unreviewed/2023/01/GHSA-mcqq-vx7f-6ffh/GHSA-mcqq-vx7f-6ffh.json +++ b/advisories/unreviewed/2023/01/GHSA-mcqq-vx7f-6ffh/GHSA-mcqq-vx7f-6ffh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-rgjq-f6gr-756j/GHSA-rgjq-f6gr-756j.json b/advisories/unreviewed/2023/04/GHSA-rgjq-f6gr-756j/GHSA-rgjq-f6gr-756j.json index 9befd19b0f7..1529c2c1027 100644 --- a/advisories/unreviewed/2023/04/GHSA-rgjq-f6gr-756j/GHSA-rgjq-f6gr-756j.json +++ b/advisories/unreviewed/2023/04/GHSA-rgjq-f6gr-756j/GHSA-rgjq-f6gr-756j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-5cww-gpqh-ggqj/GHSA-5cww-gpqh-ggqj.json b/advisories/unreviewed/2023/05/GHSA-5cww-gpqh-ggqj/GHSA-5cww-gpqh-ggqj.json index 2404cecc5ab..ac48ab96220 100644 --- a/advisories/unreviewed/2023/05/GHSA-5cww-gpqh-ggqj/GHSA-5cww-gpqh-ggqj.json +++ b/advisories/unreviewed/2023/05/GHSA-5cww-gpqh-ggqj/GHSA-5cww-gpqh-ggqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-68gq-fqpm-jw4j/GHSA-68gq-fqpm-jw4j.json b/advisories/unreviewed/2023/05/GHSA-68gq-fqpm-jw4j/GHSA-68gq-fqpm-jw4j.json index 77b94c018e6..ce0e54c6290 100644 --- a/advisories/unreviewed/2023/05/GHSA-68gq-fqpm-jw4j/GHSA-68gq-fqpm-jw4j.json +++ b/advisories/unreviewed/2023/05/GHSA-68gq-fqpm-jw4j/GHSA-68gq-fqpm-jw4j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-7797-6fvm-v8xw/GHSA-7797-6fvm-v8xw.json b/advisories/unreviewed/2023/05/GHSA-7797-6fvm-v8xw/GHSA-7797-6fvm-v8xw.json index f75bd5db4cd..aa8a7e2f457 100644 --- a/advisories/unreviewed/2023/05/GHSA-7797-6fvm-v8xw/GHSA-7797-6fvm-v8xw.json +++ b/advisories/unreviewed/2023/05/GHSA-7797-6fvm-v8xw/GHSA-7797-6fvm-v8xw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-9gjv-mqxv-j44m/GHSA-9gjv-mqxv-j44m.json b/advisories/unreviewed/2023/05/GHSA-9gjv-mqxv-j44m/GHSA-9gjv-mqxv-j44m.json index 0304187396f..3a0a1493537 100644 --- a/advisories/unreviewed/2023/05/GHSA-9gjv-mqxv-j44m/GHSA-9gjv-mqxv-j44m.json +++ b/advisories/unreviewed/2023/05/GHSA-9gjv-mqxv-j44m/GHSA-9gjv-mqxv-j44m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-c4fp-wmv9-q4cr/GHSA-c4fp-wmv9-q4cr.json b/advisories/unreviewed/2023/05/GHSA-c4fp-wmv9-q4cr/GHSA-c4fp-wmv9-q4cr.json index 0e25212305d..fd436e23a8f 100644 --- a/advisories/unreviewed/2023/05/GHSA-c4fp-wmv9-q4cr/GHSA-c4fp-wmv9-q4cr.json +++ b/advisories/unreviewed/2023/05/GHSA-c4fp-wmv9-q4cr/GHSA-c4fp-wmv9-q4cr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/05/GHSA-j5rv-3m5p-q6rc/GHSA-j5rv-3m5p-q6rc.json b/advisories/unreviewed/2023/05/GHSA-j5rv-3m5p-q6rc/GHSA-j5rv-3m5p-q6rc.json index af32b21883d..4559c76b609 100644 --- a/advisories/unreviewed/2023/05/GHSA-j5rv-3m5p-q6rc/GHSA-j5rv-3m5p-q6rc.json +++ b/advisories/unreviewed/2023/05/GHSA-j5rv-3m5p-q6rc/GHSA-j5rv-3m5p-q6rc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-68g3-2p3g-w9pq/GHSA-68g3-2p3g-w9pq.json b/advisories/unreviewed/2023/06/GHSA-68g3-2p3g-w9pq/GHSA-68g3-2p3g-w9pq.json index 01d81d19e56..641387dd5dd 100644 --- a/advisories/unreviewed/2023/06/GHSA-68g3-2p3g-w9pq/GHSA-68g3-2p3g-w9pq.json +++ b/advisories/unreviewed/2023/06/GHSA-68g3-2p3g-w9pq/GHSA-68g3-2p3g-w9pq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-888h-rm2r-vrc7/GHSA-888h-rm2r-vrc7.json b/advisories/unreviewed/2023/06/GHSA-888h-rm2r-vrc7/GHSA-888h-rm2r-vrc7.json index 8e6261078b7..a58736363e3 100644 --- a/advisories/unreviewed/2023/06/GHSA-888h-rm2r-vrc7/GHSA-888h-rm2r-vrc7.json +++ b/advisories/unreviewed/2023/06/GHSA-888h-rm2r-vrc7/GHSA-888h-rm2r-vrc7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-rxx3-4978-3cc9/GHSA-rxx3-4978-3cc9.json b/advisories/unreviewed/2023/06/GHSA-rxx3-4978-3cc9/GHSA-rxx3-4978-3cc9.json index 68fcb919ea2..f6d5d0cda17 100644 --- a/advisories/unreviewed/2023/06/GHSA-rxx3-4978-3cc9/GHSA-rxx3-4978-3cc9.json +++ b/advisories/unreviewed/2023/06/GHSA-rxx3-4978-3cc9/GHSA-rxx3-4978-3cc9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-wf52-5wvv-68vv/GHSA-wf52-5wvv-68vv.json b/advisories/unreviewed/2023/06/GHSA-wf52-5wvv-68vv/GHSA-wf52-5wvv-68vv.json index 0c1ca8d97a5..002110b8d7b 100644 --- a/advisories/unreviewed/2023/06/GHSA-wf52-5wvv-68vv/GHSA-wf52-5wvv-68vv.json +++ b/advisories/unreviewed/2023/06/GHSA-wf52-5wvv-68vv/GHSA-wf52-5wvv-68vv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-5qcr-q6p5-3jp9/GHSA-5qcr-q6p5-3jp9.json b/advisories/unreviewed/2023/08/GHSA-5qcr-q6p5-3jp9/GHSA-5qcr-q6p5-3jp9.json index f3b04f75c60..4ce2b1fbb17 100644 --- a/advisories/unreviewed/2023/08/GHSA-5qcr-q6p5-3jp9/GHSA-5qcr-q6p5-3jp9.json +++ b/advisories/unreviewed/2023/08/GHSA-5qcr-q6p5-3jp9/GHSA-5qcr-q6p5-3jp9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-qrgg-mgwx-hq8f/GHSA-qrgg-mgwx-hq8f.json b/advisories/unreviewed/2023/08/GHSA-qrgg-mgwx-hq8f/GHSA-qrgg-mgwx-hq8f.json index 5a62979b0d9..b36a8f667a8 100644 --- a/advisories/unreviewed/2023/08/GHSA-qrgg-mgwx-hq8f/GHSA-qrgg-mgwx-hq8f.json +++ b/advisories/unreviewed/2023/08/GHSA-qrgg-mgwx-hq8f/GHSA-qrgg-mgwx-hq8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-xjvv-5w4r-hfmv/GHSA-xjvv-5w4r-hfmv.json b/advisories/unreviewed/2023/08/GHSA-xjvv-5w4r-hfmv/GHSA-xjvv-5w4r-hfmv.json index ecae0f2c4f5..2af38a1109a 100644 --- a/advisories/unreviewed/2023/08/GHSA-xjvv-5w4r-hfmv/GHSA-xjvv-5w4r-hfmv.json +++ b/advisories/unreviewed/2023/08/GHSA-xjvv-5w4r-hfmv/GHSA-xjvv-5w4r-hfmv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-3q5q-8rwq-gwp8/GHSA-3q5q-8rwq-gwp8.json b/advisories/unreviewed/2023/09/GHSA-3q5q-8rwq-gwp8/GHSA-3q5q-8rwq-gwp8.json index 96ac06e98de..60a63b3ef40 100644 --- a/advisories/unreviewed/2023/09/GHSA-3q5q-8rwq-gwp8/GHSA-3q5q-8rwq-gwp8.json +++ b/advisories/unreviewed/2023/09/GHSA-3q5q-8rwq-gwp8/GHSA-3q5q-8rwq-gwp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-892h-r6cr-53g4/GHSA-892h-r6cr-53g4.json b/advisories/unreviewed/2023/09/GHSA-892h-r6cr-53g4/GHSA-892h-r6cr-53g4.json index 66292e1d02f..d34e2e882a6 100644 --- a/advisories/unreviewed/2023/09/GHSA-892h-r6cr-53g4/GHSA-892h-r6cr-53g4.json +++ b/advisories/unreviewed/2023/09/GHSA-892h-r6cr-53g4/GHSA-892h-r6cr-53g4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-8jhw-fpw9-r227/GHSA-8jhw-fpw9-r227.json b/advisories/unreviewed/2023/09/GHSA-8jhw-fpw9-r227/GHSA-8jhw-fpw9-r227.json index 665dc528c36..ce73f159a97 100644 --- a/advisories/unreviewed/2023/09/GHSA-8jhw-fpw9-r227/GHSA-8jhw-fpw9-r227.json +++ b/advisories/unreviewed/2023/09/GHSA-8jhw-fpw9-r227/GHSA-8jhw-fpw9-r227.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-c9xj-rf55-c64g/GHSA-c9xj-rf55-c64g.json b/advisories/unreviewed/2023/09/GHSA-c9xj-rf55-c64g/GHSA-c9xj-rf55-c64g.json index 5792fb7d1bf..81de6f00c27 100644 --- a/advisories/unreviewed/2023/09/GHSA-c9xj-rf55-c64g/GHSA-c9xj-rf55-c64g.json +++ b/advisories/unreviewed/2023/09/GHSA-c9xj-rf55-c64g/GHSA-c9xj-rf55-c64g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-g7f2-f4hp-4hmj/GHSA-g7f2-f4hp-4hmj.json b/advisories/unreviewed/2023/09/GHSA-g7f2-f4hp-4hmj/GHSA-g7f2-f4hp-4hmj.json index 501f533ac44..758335051e6 100644 --- a/advisories/unreviewed/2023/09/GHSA-g7f2-f4hp-4hmj/GHSA-g7f2-f4hp-4hmj.json +++ b/advisories/unreviewed/2023/09/GHSA-g7f2-f4hp-4hmj/GHSA-g7f2-f4hp-4hmj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/09/GHSA-h69c-wjc7-8h9r/GHSA-h69c-wjc7-8h9r.json b/advisories/unreviewed/2023/09/GHSA-h69c-wjc7-8h9r/GHSA-h69c-wjc7-8h9r.json index 9f3d42ef822..bcc1f1f4613 100644 --- a/advisories/unreviewed/2023/09/GHSA-h69c-wjc7-8h9r/GHSA-h69c-wjc7-8h9r.json +++ b/advisories/unreviewed/2023/09/GHSA-h69c-wjc7-8h9r/GHSA-h69c-wjc7-8h9r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-rxv8-v965-v333/GHSA-rxv8-v965-v333.json b/advisories/unreviewed/2023/09/GHSA-rxv8-v965-v333/GHSA-rxv8-v965-v333.json index 338c7bcad8a..895b7969ab2 100644 --- a/advisories/unreviewed/2023/09/GHSA-rxv8-v965-v333/GHSA-rxv8-v965-v333.json +++ b/advisories/unreviewed/2023/09/GHSA-rxv8-v965-v333/GHSA-rxv8-v965-v333.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-vq7j-gx56-rxjh/GHSA-vq7j-gx56-rxjh.json b/advisories/unreviewed/2023/09/GHSA-vq7j-gx56-rxjh/GHSA-vq7j-gx56-rxjh.json index e36a9e86c28..25c8a783f8c 100644 --- a/advisories/unreviewed/2023/09/GHSA-vq7j-gx56-rxjh/GHSA-vq7j-gx56-rxjh.json +++ b/advisories/unreviewed/2023/09/GHSA-vq7j-gx56-rxjh/GHSA-vq7j-gx56-rxjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-vv9m-32rr-3g55/GHSA-vv9m-32rr-3g55.json b/advisories/unreviewed/2023/09/GHSA-vv9m-32rr-3g55/GHSA-vv9m-32rr-3g55.json index 693b1bfd2b9..dc7e2c7d703 100644 --- a/advisories/unreviewed/2023/09/GHSA-vv9m-32rr-3g55/GHSA-vv9m-32rr-3g55.json +++ b/advisories/unreviewed/2023/09/GHSA-vv9m-32rr-3g55/GHSA-vv9m-32rr-3g55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-pcx2-r23v-3j7c/GHSA-pcx2-r23v-3j7c.json b/advisories/unreviewed/2023/10/GHSA-pcx2-r23v-3j7c/GHSA-pcx2-r23v-3j7c.json index e08bfbef243..57624b846a4 100644 --- a/advisories/unreviewed/2023/10/GHSA-pcx2-r23v-3j7c/GHSA-pcx2-r23v-3j7c.json +++ b/advisories/unreviewed/2023/10/GHSA-pcx2-r23v-3j7c/GHSA-pcx2-r23v-3j7c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-hw83-99pm-pwrr/GHSA-hw83-99pm-pwrr.json b/advisories/unreviewed/2023/12/GHSA-hw83-99pm-pwrr/GHSA-hw83-99pm-pwrr.json index 6b9ce0c76cf..fa256a0a13e 100644 --- a/advisories/unreviewed/2023/12/GHSA-hw83-99pm-pwrr/GHSA-hw83-99pm-pwrr.json +++ b/advisories/unreviewed/2023/12/GHSA-hw83-99pm-pwrr/GHSA-hw83-99pm-pwrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json index 3f4fd6543ac..e7787ead8cc 100644 --- a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json +++ b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json index f5c2ed8d25b..40eb330ed01 100644 --- a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json +++ b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-26mf-52p6-23pq/GHSA-26mf-52p6-23pq.json b/advisories/unreviewed/2024/04/GHSA-26mf-52p6-23pq/GHSA-26mf-52p6-23pq.json index c30651aa15d..dec73b9602f 100644 --- a/advisories/unreviewed/2024/04/GHSA-26mf-52p6-23pq/GHSA-26mf-52p6-23pq.json +++ b/advisories/unreviewed/2024/04/GHSA-26mf-52p6-23pq/GHSA-26mf-52p6-23pq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-273j-fjrx-gf2f/GHSA-273j-fjrx-gf2f.json b/advisories/unreviewed/2024/04/GHSA-273j-fjrx-gf2f/GHSA-273j-fjrx-gf2f.json index e7b5270e0b9..bf99690e45b 100644 --- a/advisories/unreviewed/2024/04/GHSA-273j-fjrx-gf2f/GHSA-273j-fjrx-gf2f.json +++ b/advisories/unreviewed/2024/04/GHSA-273j-fjrx-gf2f/GHSA-273j-fjrx-gf2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json b/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json index 449bcde4f43..8cb98c163e5 100644 --- a/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json +++ b/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3q47-w545-wgfv/GHSA-3q47-w545-wgfv.json b/advisories/unreviewed/2024/04/GHSA-3q47-w545-wgfv/GHSA-3q47-w545-wgfv.json index 0823a7f1df0..2e3fb37c03e 100644 --- a/advisories/unreviewed/2024/04/GHSA-3q47-w545-wgfv/GHSA-3q47-w545-wgfv.json +++ b/advisories/unreviewed/2024/04/GHSA-3q47-w545-wgfv/GHSA-3q47-w545-wgfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3v95-qw2c-cq5p/GHSA-3v95-qw2c-cq5p.json b/advisories/unreviewed/2024/04/GHSA-3v95-qw2c-cq5p/GHSA-3v95-qw2c-cq5p.json index ad445e54bce..a0888828d8a 100644 --- a/advisories/unreviewed/2024/04/GHSA-3v95-qw2c-cq5p/GHSA-3v95-qw2c-cq5p.json +++ b/advisories/unreviewed/2024/04/GHSA-3v95-qw2c-cq5p/GHSA-3v95-qw2c-cq5p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4cjh-m2w7-xg99/GHSA-4cjh-m2w7-xg99.json b/advisories/unreviewed/2024/04/GHSA-4cjh-m2w7-xg99/GHSA-4cjh-m2w7-xg99.json index 44f84646507..dd0a1720210 100644 --- a/advisories/unreviewed/2024/04/GHSA-4cjh-m2w7-xg99/GHSA-4cjh-m2w7-xg99.json +++ b/advisories/unreviewed/2024/04/GHSA-4cjh-m2w7-xg99/GHSA-4cjh-m2w7-xg99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-55g5-m7rx-jf99/GHSA-55g5-m7rx-jf99.json b/advisories/unreviewed/2024/04/GHSA-55g5-m7rx-jf99/GHSA-55g5-m7rx-jf99.json index 1224ff694b6..e3978263f9c 100644 --- a/advisories/unreviewed/2024/04/GHSA-55g5-m7rx-jf99/GHSA-55g5-m7rx-jf99.json +++ b/advisories/unreviewed/2024/04/GHSA-55g5-m7rx-jf99/GHSA-55g5-m7rx-jf99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5xq9-rcpj-p52v/GHSA-5xq9-rcpj-p52v.json b/advisories/unreviewed/2024/04/GHSA-5xq9-rcpj-p52v/GHSA-5xq9-rcpj-p52v.json index af4eebc4350..5d41715f4af 100644 --- a/advisories/unreviewed/2024/04/GHSA-5xq9-rcpj-p52v/GHSA-5xq9-rcpj-p52v.json +++ b/advisories/unreviewed/2024/04/GHSA-5xq9-rcpj-p52v/GHSA-5xq9-rcpj-p52v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json b/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json index 084dc593693..3abd8443e5c 100644 --- a/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json +++ b/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6qf6-cmc3-h6x2/GHSA-6qf6-cmc3-h6x2.json b/advisories/unreviewed/2024/04/GHSA-6qf6-cmc3-h6x2/GHSA-6qf6-cmc3-h6x2.json index ae8a9810349..ba025ebef79 100644 --- a/advisories/unreviewed/2024/04/GHSA-6qf6-cmc3-h6x2/GHSA-6qf6-cmc3-h6x2.json +++ b/advisories/unreviewed/2024/04/GHSA-6qf6-cmc3-h6x2/GHSA-6qf6-cmc3-h6x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7jxx-p3jr-r2x9/GHSA-7jxx-p3jr-r2x9.json b/advisories/unreviewed/2024/04/GHSA-7jxx-p3jr-r2x9/GHSA-7jxx-p3jr-r2x9.json index 95b03a9f2f7..d94fdb1059e 100644 --- a/advisories/unreviewed/2024/04/GHSA-7jxx-p3jr-r2x9/GHSA-7jxx-p3jr-r2x9.json +++ b/advisories/unreviewed/2024/04/GHSA-7jxx-p3jr-r2x9/GHSA-7jxx-p3jr-r2x9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json b/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json index 8e007d1c38a..0e3d58b4b2f 100644 --- a/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json +++ b/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8x4w-7h9g-pg2q/GHSA-8x4w-7h9g-pg2q.json b/advisories/unreviewed/2024/04/GHSA-8x4w-7h9g-pg2q/GHSA-8x4w-7h9g-pg2q.json index d2efe839703..3610fe12b88 100644 --- a/advisories/unreviewed/2024/04/GHSA-8x4w-7h9g-pg2q/GHSA-8x4w-7h9g-pg2q.json +++ b/advisories/unreviewed/2024/04/GHSA-8x4w-7h9g-pg2q/GHSA-8x4w-7h9g-pg2q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9cw3-8wpf-rpmg/GHSA-9cw3-8wpf-rpmg.json b/advisories/unreviewed/2024/04/GHSA-9cw3-8wpf-rpmg/GHSA-9cw3-8wpf-rpmg.json index 912adb0a0f8..a1ab60ef388 100644 --- a/advisories/unreviewed/2024/04/GHSA-9cw3-8wpf-rpmg/GHSA-9cw3-8wpf-rpmg.json +++ b/advisories/unreviewed/2024/04/GHSA-9cw3-8wpf-rpmg/GHSA-9cw3-8wpf-rpmg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9x55-44vc-363x/GHSA-9x55-44vc-363x.json b/advisories/unreviewed/2024/04/GHSA-9x55-44vc-363x/GHSA-9x55-44vc-363x.json index 04a3ea9911f..32149235cae 100644 --- a/advisories/unreviewed/2024/04/GHSA-9x55-44vc-363x/GHSA-9x55-44vc-363x.json +++ b/advisories/unreviewed/2024/04/GHSA-9x55-44vc-363x/GHSA-9x55-44vc-363x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-gj63-qcjc-2fcw/GHSA-gj63-qcjc-2fcw.json b/advisories/unreviewed/2024/04/GHSA-gj63-qcjc-2fcw/GHSA-gj63-qcjc-2fcw.json index 62c4caa3e82..9558bcfdbce 100644 --- a/advisories/unreviewed/2024/04/GHSA-gj63-qcjc-2fcw/GHSA-gj63-qcjc-2fcw.json +++ b/advisories/unreviewed/2024/04/GHSA-gj63-qcjc-2fcw/GHSA-gj63-qcjc-2fcw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json b/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json index 90cef86629a..d43412fea3e 100644 --- a/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json +++ b/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json @@ -7,12 +7,8 @@ "CVE-2024-2439" ], "details": "The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hcf3-w2q6-29cf/GHSA-hcf3-w2q6-29cf.json b/advisories/unreviewed/2024/04/GHSA-hcf3-w2q6-29cf/GHSA-hcf3-w2q6-29cf.json index ae699ce7195..eba9d260448 100644 --- a/advisories/unreviewed/2024/04/GHSA-hcf3-w2q6-29cf/GHSA-hcf3-w2q6-29cf.json +++ b/advisories/unreviewed/2024/04/GHSA-hcf3-w2q6-29cf/GHSA-hcf3-w2q6-29cf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hcm7-xw9m-99cx/GHSA-hcm7-xw9m-99cx.json b/advisories/unreviewed/2024/04/GHSA-hcm7-xw9m-99cx/GHSA-hcm7-xw9m-99cx.json index d6ebdb04ca9..99af8d471b2 100644 --- a/advisories/unreviewed/2024/04/GHSA-hcm7-xw9m-99cx/GHSA-hcm7-xw9m-99cx.json +++ b/advisories/unreviewed/2024/04/GHSA-hcm7-xw9m-99cx/GHSA-hcm7-xw9m-99cx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json b/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json index cc542f36623..b572f45560d 100644 --- a/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json +++ b/advisories/unreviewed/2024/04/GHSA-hqqq-4jv4-jmj5/GHSA-hqqq-4jv4-jmj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json b/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json index 78b24c2ca51..5d3bf7f90c8 100644 --- a/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json +++ b/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-jfv3-gh3j-c5r7/GHSA-jfv3-gh3j-c5r7.json b/advisories/unreviewed/2024/04/GHSA-jfv3-gh3j-c5r7/GHSA-jfv3-gh3j-c5r7.json index 1c94ee42e6f..a0d986e42cc 100644 --- a/advisories/unreviewed/2024/04/GHSA-jfv3-gh3j-c5r7/GHSA-jfv3-gh3j-c5r7.json +++ b/advisories/unreviewed/2024/04/GHSA-jfv3-gh3j-c5r7/GHSA-jfv3-gh3j-c5r7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jmgx-64x4-v838/GHSA-jmgx-64x4-v838.json b/advisories/unreviewed/2024/04/GHSA-jmgx-64x4-v838/GHSA-jmgx-64x4-v838.json index 83114be2b4f..4e71bd10998 100644 --- a/advisories/unreviewed/2024/04/GHSA-jmgx-64x4-v838/GHSA-jmgx-64x4-v838.json +++ b/advisories/unreviewed/2024/04/GHSA-jmgx-64x4-v838/GHSA-jmgx-64x4-v838.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mppc-j8fq-9mvg/GHSA-mppc-j8fq-9mvg.json b/advisories/unreviewed/2024/04/GHSA-mppc-j8fq-9mvg/GHSA-mppc-j8fq-9mvg.json index b2ba8b16b9f..b173d728bc0 100644 --- a/advisories/unreviewed/2024/04/GHSA-mppc-j8fq-9mvg/GHSA-mppc-j8fq-9mvg.json +++ b/advisories/unreviewed/2024/04/GHSA-mppc-j8fq-9mvg/GHSA-mppc-j8fq-9mvg.json @@ -7,12 +7,8 @@ "CVE-2024-22632" ], "details": "Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pj4r-r8f8-qmcc/GHSA-pj4r-r8f8-qmcc.json b/advisories/unreviewed/2024/04/GHSA-pj4r-r8f8-qmcc/GHSA-pj4r-r8f8-qmcc.json index e208661dc72..4fa6412f62d 100644 --- a/advisories/unreviewed/2024/04/GHSA-pj4r-r8f8-qmcc/GHSA-pj4r-r8f8-qmcc.json +++ b/advisories/unreviewed/2024/04/GHSA-pj4r-r8f8-qmcc/GHSA-pj4r-r8f8-qmcc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-pprv-m73j-58qg/GHSA-pprv-m73j-58qg.json b/advisories/unreviewed/2024/04/GHSA-pprv-m73j-58qg/GHSA-pprv-m73j-58qg.json index 6ab25a63f11..6e1aac92670 100644 --- a/advisories/unreviewed/2024/04/GHSA-pprv-m73j-58qg/GHSA-pprv-m73j-58qg.json +++ b/advisories/unreviewed/2024/04/GHSA-pprv-m73j-58qg/GHSA-pprv-m73j-58qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q66w-qfxv-vpx3/GHSA-q66w-qfxv-vpx3.json b/advisories/unreviewed/2024/04/GHSA-q66w-qfxv-vpx3/GHSA-q66w-qfxv-vpx3.json index ae2699c8f95..0a93765c3f4 100644 --- a/advisories/unreviewed/2024/04/GHSA-q66w-qfxv-vpx3/GHSA-q66w-qfxv-vpx3.json +++ b/advisories/unreviewed/2024/04/GHSA-q66w-qfxv-vpx3/GHSA-q66w-qfxv-vpx3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json b/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json index dc53192dd83..3f957930f31 100644 --- a/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json +++ b/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w8q4-gvf3-wvfq/GHSA-w8q4-gvf3-wvfq.json b/advisories/unreviewed/2024/04/GHSA-w8q4-gvf3-wvfq/GHSA-w8q4-gvf3-wvfq.json index cd80750350f..14227c553dd 100644 --- a/advisories/unreviewed/2024/04/GHSA-w8q4-gvf3-wvfq/GHSA-w8q4-gvf3-wvfq.json +++ b/advisories/unreviewed/2024/04/GHSA-w8q4-gvf3-wvfq/GHSA-w8q4-gvf3-wvfq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json b/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json index eea5b68ca44..a516c06c941 100644 --- a/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json +++ b/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wv9c-r7wv-3wph/GHSA-wv9c-r7wv-3wph.json b/advisories/unreviewed/2024/04/GHSA-wv9c-r7wv-3wph/GHSA-wv9c-r7wv-3wph.json index 96738931499..85fc47e6ea3 100644 --- a/advisories/unreviewed/2024/04/GHSA-wv9c-r7wv-3wph/GHSA-wv9c-r7wv-3wph.json +++ b/advisories/unreviewed/2024/04/GHSA-wv9c-r7wv-3wph/GHSA-wv9c-r7wv-3wph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-x78r-qrp5-rmmf/GHSA-x78r-qrp5-rmmf.json b/advisories/unreviewed/2024/04/GHSA-x78r-qrp5-rmmf/GHSA-x78r-qrp5-rmmf.json index cd2c7114c8d..62c9fe0997d 100644 --- a/advisories/unreviewed/2024/04/GHSA-x78r-qrp5-rmmf/GHSA-x78r-qrp5-rmmf.json +++ b/advisories/unreviewed/2024/04/GHSA-x78r-qrp5-rmmf/GHSA-x78r-qrp5-rmmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json b/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json index 18c0cfb574b..e5f27e28c9a 100644 --- a/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json +++ b/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-3qp4-cvq4-28r4/GHSA-3qp4-cvq4-28r4.json b/advisories/unreviewed/2024/06/GHSA-3qp4-cvq4-28r4/GHSA-3qp4-cvq4-28r4.json index bf91b0471d6..b6f9f9f3e02 100644 --- a/advisories/unreviewed/2024/06/GHSA-3qp4-cvq4-28r4/GHSA-3qp4-cvq4-28r4.json +++ b/advisories/unreviewed/2024/06/GHSA-3qp4-cvq4-28r4/GHSA-3qp4-cvq4-28r4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-59h7-wrc6-2235/GHSA-59h7-wrc6-2235.json b/advisories/unreviewed/2024/06/GHSA-59h7-wrc6-2235/GHSA-59h7-wrc6-2235.json index 0e47e89fbb0..d1f030e30b7 100644 --- a/advisories/unreviewed/2024/06/GHSA-59h7-wrc6-2235/GHSA-59h7-wrc6-2235.json +++ b/advisories/unreviewed/2024/06/GHSA-59h7-wrc6-2235/GHSA-59h7-wrc6-2235.json @@ -7,12 +7,8 @@ "CVE-2024-5777" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-64f4-8h54-qf3g/GHSA-64f4-8h54-qf3g.json b/advisories/unreviewed/2024/06/GHSA-64f4-8h54-qf3g/GHSA-64f4-8h54-qf3g.json index d12fba64508..5cbcf838dc1 100644 --- a/advisories/unreviewed/2024/06/GHSA-64f4-8h54-qf3g/GHSA-64f4-8h54-qf3g.json +++ b/advisories/unreviewed/2024/06/GHSA-64f4-8h54-qf3g/GHSA-64f4-8h54-qf3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6c4c-5hcj-j9pj/GHSA-6c4c-5hcj-j9pj.json b/advisories/unreviewed/2024/06/GHSA-6c4c-5hcj-j9pj/GHSA-6c4c-5hcj-j9pj.json index a744b7a7c58..eba1dc839d1 100644 --- a/advisories/unreviewed/2024/06/GHSA-6c4c-5hcj-j9pj/GHSA-6c4c-5hcj-j9pj.json +++ b/advisories/unreviewed/2024/06/GHSA-6c4c-5hcj-j9pj/GHSA-6c4c-5hcj-j9pj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8j5r-4pfg-8q95/GHSA-8j5r-4pfg-8q95.json b/advisories/unreviewed/2024/06/GHSA-8j5r-4pfg-8q95/GHSA-8j5r-4pfg-8q95.json index 4347421ffe7..9ef4795ec25 100644 --- a/advisories/unreviewed/2024/06/GHSA-8j5r-4pfg-8q95/GHSA-8j5r-4pfg-8q95.json +++ b/advisories/unreviewed/2024/06/GHSA-8j5r-4pfg-8q95/GHSA-8j5r-4pfg-8q95.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8qw7-56rp-hj8x/GHSA-8qw7-56rp-hj8x.json b/advisories/unreviewed/2024/06/GHSA-8qw7-56rp-hj8x/GHSA-8qw7-56rp-hj8x.json index fb714f36838..189afd29635 100644 --- a/advisories/unreviewed/2024/06/GHSA-8qw7-56rp-hj8x/GHSA-8qw7-56rp-hj8x.json +++ b/advisories/unreviewed/2024/06/GHSA-8qw7-56rp-hj8x/GHSA-8qw7-56rp-hj8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-9hrm-g973-phrr/GHSA-9hrm-g973-phrr.json b/advisories/unreviewed/2024/06/GHSA-9hrm-g973-phrr/GHSA-9hrm-g973-phrr.json index 2d787b842f6..5fd8be674c0 100644 --- a/advisories/unreviewed/2024/06/GHSA-9hrm-g973-phrr/GHSA-9hrm-g973-phrr.json +++ b/advisories/unreviewed/2024/06/GHSA-9hrm-g973-phrr/GHSA-9hrm-g973-phrr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-f7c9-x7pc-54xj/GHSA-f7c9-x7pc-54xj.json b/advisories/unreviewed/2024/06/GHSA-f7c9-x7pc-54xj/GHSA-f7c9-x7pc-54xj.json index efca72158f6..2b9b0e466d3 100644 --- a/advisories/unreviewed/2024/06/GHSA-f7c9-x7pc-54xj/GHSA-f7c9-x7pc-54xj.json +++ b/advisories/unreviewed/2024/06/GHSA-f7c9-x7pc-54xj/GHSA-f7c9-x7pc-54xj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-g88v-q4m5-mhpr/GHSA-g88v-q4m5-mhpr.json b/advisories/unreviewed/2024/06/GHSA-g88v-q4m5-mhpr/GHSA-g88v-q4m5-mhpr.json index 95c75bcec3a..60188b29978 100644 --- a/advisories/unreviewed/2024/06/GHSA-g88v-q4m5-mhpr/GHSA-g88v-q4m5-mhpr.json +++ b/advisories/unreviewed/2024/06/GHSA-g88v-q4m5-mhpr/GHSA-g88v-q4m5-mhpr.json @@ -7,12 +7,8 @@ "CVE-2024-5873" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-jww8-w6cf-vwpg/GHSA-jww8-w6cf-vwpg.json b/advisories/unreviewed/2024/06/GHSA-jww8-w6cf-vwpg/GHSA-jww8-w6cf-vwpg.json index 7b4f1682f46..29f6e5967a7 100644 --- a/advisories/unreviewed/2024/06/GHSA-jww8-w6cf-vwpg/GHSA-jww8-w6cf-vwpg.json +++ b/advisories/unreviewed/2024/06/GHSA-jww8-w6cf-vwpg/GHSA-jww8-w6cf-vwpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mh63-325c-chrf/GHSA-mh63-325c-chrf.json b/advisories/unreviewed/2024/06/GHSA-mh63-325c-chrf/GHSA-mh63-325c-chrf.json index ae5ee403b33..cb572d54e03 100644 --- a/advisories/unreviewed/2024/06/GHSA-mh63-325c-chrf/GHSA-mh63-325c-chrf.json +++ b/advisories/unreviewed/2024/06/GHSA-mh63-325c-chrf/GHSA-mh63-325c-chrf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-qhx6-9fwx-wcfm/GHSA-qhx6-9fwx-wcfm.json b/advisories/unreviewed/2024/06/GHSA-qhx6-9fwx-wcfm/GHSA-qhx6-9fwx-wcfm.json index e285374ee06..c3edb1ededd 100644 --- a/advisories/unreviewed/2024/06/GHSA-qhx6-9fwx-wcfm/GHSA-qhx6-9fwx-wcfm.json +++ b/advisories/unreviewed/2024/06/GHSA-qhx6-9fwx-wcfm/GHSA-qhx6-9fwx-wcfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rm55-jfvw-6g3r/GHSA-rm55-jfvw-6g3r.json b/advisories/unreviewed/2024/06/GHSA-rm55-jfvw-6g3r/GHSA-rm55-jfvw-6g3r.json index c365dd51519..d1d575d7daf 100644 --- a/advisories/unreviewed/2024/06/GHSA-rm55-jfvw-6g3r/GHSA-rm55-jfvw-6g3r.json +++ b/advisories/unreviewed/2024/06/GHSA-rm55-jfvw-6g3r/GHSA-rm55-jfvw-6g3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-v9pc-cxpw-3jr5/GHSA-v9pc-cxpw-3jr5.json b/advisories/unreviewed/2024/06/GHSA-v9pc-cxpw-3jr5/GHSA-v9pc-cxpw-3jr5.json index ae3c0562cb8..299f371c959 100644 --- a/advisories/unreviewed/2024/06/GHSA-v9pc-cxpw-3jr5/GHSA-v9pc-cxpw-3jr5.json +++ b/advisories/unreviewed/2024/06/GHSA-v9pc-cxpw-3jr5/GHSA-v9pc-cxpw-3jr5.json @@ -7,12 +7,8 @@ "CVE-2024-5776" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-w9f6-jf9g-658h/GHSA-w9f6-jf9g-658h.json b/advisories/unreviewed/2024/06/GHSA-w9f6-jf9g-658h/GHSA-w9f6-jf9g-658h.json index 2e8d24ac699..ea9be204129 100644 --- a/advisories/unreviewed/2024/06/GHSA-w9f6-jf9g-658h/GHSA-w9f6-jf9g-658h.json +++ b/advisories/unreviewed/2024/06/GHSA-w9f6-jf9g-658h/GHSA-w9f6-jf9g-658h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-x3q8-8r5q-xrq8/GHSA-x3q8-8r5q-xrq8.json b/advisories/unreviewed/2024/06/GHSA-x3q8-8r5q-xrq8/GHSA-x3q8-8r5q-xrq8.json index 7c4e3e2f9c9..ad12ca4649a 100644 --- a/advisories/unreviewed/2024/06/GHSA-x3q8-8r5q-xrq8/GHSA-x3q8-8r5q-xrq8.json +++ b/advisories/unreviewed/2024/06/GHSA-x3q8-8r5q-xrq8/GHSA-x3q8-8r5q-xrq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",