diff --git a/advisories/github-reviewed/2017/10/GHSA-qqxp-xp9v-vvx6/GHSA-qqxp-xp9v-vvx6.json b/advisories/github-reviewed/2017/10/GHSA-qqxp-xp9v-vvx6/GHSA-qqxp-xp9v-vvx6.json index fb4eaa1688b..20b76a978ea 100644 --- a/advisories/github-reviewed/2017/10/GHSA-qqxp-xp9v-vvx6/GHSA-qqxp-xp9v-vvx6.json +++ b/advisories/github-reviewed/2017/10/GHSA-qqxp-xp9v-vvx6/GHSA-qqxp-xp9v-vvx6.json @@ -8,9 +8,7 @@ ], "summary": "jquery-ui Tooltip widget vulnerable to XSS", "details": "Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-39cx-xcwj-3rc4/GHSA-39cx-xcwj-3rc4.json b/advisories/github-reviewed/2020/09/GHSA-39cx-xcwj-3rc4/GHSA-39cx-xcwj-3rc4.json index 0cf9fb1d27a..a44a59145ad 100644 --- a/advisories/github-reviewed/2020/09/GHSA-39cx-xcwj-3rc4/GHSA-39cx-xcwj-3rc4.json +++ b/advisories/github-reviewed/2020/09/GHSA-39cx-xcwj-3rc4/GHSA-39cx-xcwj-3rc4.json @@ -8,9 +8,7 @@ ], "summary": "Cross-Site Scripting in dojo", "details": "Affected versions of `dojo` are susceptible to a cross-site scripting vulnerability in the `dijit.Editor` and `textarea` components, which execute their contents as Javascript, even when sanitized.\n\n\n## Recommendation\n\nUpdate to version 1.1.0 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/03/GHSA-pj73-v5mw-pm9j/GHSA-pj73-v5mw-pm9j.json b/advisories/github-reviewed/2023/03/GHSA-pj73-v5mw-pm9j/GHSA-pj73-v5mw-pm9j.json index 71e402207f9..c27b3ebb142 100644 --- a/advisories/github-reviewed/2023/03/GHSA-pj73-v5mw-pm9j/GHSA-pj73-v5mw-pm9j.json +++ b/advisories/github-reviewed/2023/03/GHSA-pj73-v5mw-pm9j/GHSA-pj73-v5mw-pm9j.json @@ -8,9 +8,7 @@ ], "summary": "Possible XSS Security Vulnerability in SafeBuffer#bytesplice", "details": "There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.\nThis vulnerability has been assigned the CVE identifier CVE-2023-28120.\n\nVersions Affected: All. Not affected: None Fixed Versions: 7.0.4.3, 6.1.7.3\n\n# Impact\n\nActiveSupport uses the SafeBuffer string subclass to tag strings as html_safe after they have been sanitized.\nWhen these strings are mutated, the tag is should be removed to mark them as no longer being html_safe.\n\nRuby 3.2 introduced a new bytesplice method which ActiveSupport did not yet understand to be a mutation.\nUsers on older versions of Ruby are likely unaffected.\n\nAll users running an affected release and using bytesplice should either upgrade or use one of the workarounds immediately.\n\n# Workarounds\n\nAvoid calling bytesplice on a SafeBuffer (html_safe) string with untrusted user input.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/01/GHSA-xgfm-fjx6-62mj/GHSA-xgfm-fjx6-62mj.json b/advisories/github-reviewed/2024/01/GHSA-xgfm-fjx6-62mj/GHSA-xgfm-fjx6-62mj.json index 5698aad6d89..bd30d1df025 100644 --- a/advisories/github-reviewed/2024/01/GHSA-xgfm-fjx6-62mj/GHSA-xgfm-fjx6-62mj.json +++ b/advisories/github-reviewed/2024/01/GHSA-xgfm-fjx6-62mj/GHSA-xgfm-fjx6-62mj.json @@ -3,9 +3,7 @@ "id": "GHSA-xgfm-fjx6-62mj", "modified": "2024-01-16T20:48:16Z", "published": "2024-01-16T20:48:16Z", - "aliases": [ - - ], + "aliases": [], "summary": "readthedocs-sphinx-search vulnerable to cross-site scripting when including search results from malicious projects", "details": "### Impact\n\nThis vulnerability could have allowed an attacker to include arbitrary HTML content in search results by having a user search a malicious project. This was due to our search client not correctly escaping all user content from search results. You can find more information in the [advisory published in our readthedocs.org repo](https://github.com/readthedocs/readthedocs.org/security/advisories/GHSA-qhqx-5j25-rv48).\n\nUsers of this extension should update to the 0.3.2 version, and trigger a new build.\n\nThis issue was discovered by a member of our team, and we have seen no signs that this vulnerability was exploited in the wild.\n\n### Patches\n\nThis issue has been patched in our 0.3.2 version. \n\n### References\n\n- https://github.com/readthedocs/readthedocs-sphinx-search/commit/8c6f6d01e88e72ef32ed0c220b6c19d1e1121c73\n\n### For more information\n\nIf you have any questions or comments about this advisory, email us at [security@readthedocs.org](mailto:security@readthedocs.org) ([PGP](https://docs.readthedocs.io/page/security.html#pgp-key))", "severity": [ diff --git a/advisories/github-reviewed/2024/02/GHSA-mf74-qq7w-6j7v/GHSA-mf74-qq7w-6j7v.json b/advisories/github-reviewed/2024/02/GHSA-mf74-qq7w-6j7v/GHSA-mf74-qq7w-6j7v.json index 1b89a22ff62..ee0ab02e71a 100644 --- a/advisories/github-reviewed/2024/02/GHSA-mf74-qq7w-6j7v/GHSA-mf74-qq7w-6j7v.json +++ b/advisories/github-reviewed/2024/02/GHSA-mf74-qq7w-6j7v/GHSA-mf74-qq7w-6j7v.json @@ -3,14 +3,10 @@ "id": "GHSA-mf74-qq7w-6j7v", "modified": "2024-05-14T22:02:19Z", "published": "2024-02-03T00:38:22Z", - "aliases": [ - - ], + "aliases": [], "summary": "Zmarkdown Server-Side Request Forgery (SSRF) in remark-download-images", "details": "### Impact\n\nA major blind SSRF has been found in `remark-images-download`, which allowed\nfor requests to be made to neighboring servers on local IP ranges.\nThe issue came from a loose filtering of URLs inside the module.\n\nImagine a server running on a private network `192.168.1.0/24`.\nA private service serving images is running on `192.168.1.2`, and\nis not expected to be accessed by users. A machine is running\n`remark-images-download` on the neighboring `192.168.1.3` host.\nAn user enters the following Markdown:\n\n```markdown\n![](http://192.168.1.2/private-img.png)\n```\n\nThe image is downloaded by the server and included inside the resulting\ndocument. Hence, the user has access to the private image.\n\nIt has been corrected by preventing images downloads from\nlocal IP ranges, both in IPv4 and IPv6.\nTo avoid malicious domain names, resolved local IPs from are also\nforbidden inside the module.\nThis vulnerability impact is moderate, as it is can allow access to\nunexposed documents on the local network, and is very easy\nto exploit.\n\n### Patches\n\nThe vulnerability has been patched in version 3.1.0.\nIf impacted, you should update to this version as soon as possible.\n\nPlease note that a minor version has been released instead of a bugfix.\nThis is due to a new option included to prevent another vulnerability,\nupgrading to the new version will not break compatibility.\n\n### Workarounds\n\nNo workaround is known, the package should be upgraded.\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [ZMarkdown](https://github.com/zestedesavoir/zmarkdown/issues).\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -43,9 +39,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-03T00:38:22Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-mq6v-w35g-3c97/GHSA-mq6v-w35g-3c97.json b/advisories/github-reviewed/2024/02/GHSA-mq6v-w35g-3c97/GHSA-mq6v-w35g-3c97.json index e048f5710b7..ba44b3451e2 100644 --- a/advisories/github-reviewed/2024/02/GHSA-mq6v-w35g-3c97/GHSA-mq6v-w35g-3c97.json +++ b/advisories/github-reviewed/2024/02/GHSA-mq6v-w35g-3c97/GHSA-mq6v-w35g-3c97.json @@ -3,14 +3,10 @@ "id": "GHSA-mq6v-w35g-3c97", "modified": "2024-05-14T22:01:12Z", "published": "2024-02-03T00:37:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "Local File Inclusion vulnerability in zmarkdown", "details": "### Impact\n\nA minor Local File Inclusion vulnerability has been found in\n`zmarkdown`, which allowed for images with a known path on\nthe host machine to be included inside a LaTeX document.\n\nTo prevent it, a new option has been created that allow to replace\ninvalid paths with a default image instead of linking the image on the\nhost directly. `zmarkdown` has been updated to make this setting the\ndefault.\n\nEvery user of `zmarkdown` is likely impacted, except if\ndisabling LaTeX generation or images download. Here\nis an example of including an image from an invalid path:\n\n```markdown\n![](/tmp/img.png)\n```\n\nWill effectively redownload and include the image\nfound at `/tmp/img.png`.\n\n### Patches\n\nThe vulnerability has been patched in version 10.1.3.\nIf impacted, you should update to this version as soon as possible.\n\n### Workarounds\n\nDisable images downloading, or sanitize paths.\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [ZMarkdown](https://github.com/zestedesavoir/zmarkdown/issues).\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -43,9 +39,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-02-03T00:37:56Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-338x-hfx8-vx9x/GHSA-338x-hfx8-vx9x.json b/advisories/github-reviewed/2024/05/GHSA-338x-hfx8-vx9x/GHSA-338x-hfx8-vx9x.json index ca5571a4a02..c3f7c6c4b3b 100644 --- a/advisories/github-reviewed/2024/05/GHSA-338x-hfx8-vx9x/GHSA-338x-hfx8-vx9x.json +++ b/advisories/github-reviewed/2024/05/GHSA-338x-hfx8-vx9x/GHSA-338x-hfx8-vx9x.json @@ -8,9 +8,7 @@ ], "summary": "Apache Karaf Cave: Cave SSRF and arbitrary file access ", "details": "This issue affects all versions of Apache Karaf Cave.\n\nAs this project is retired, there are no plans to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/06/GHSA-grjv-gjgr-66g2/GHSA-grjv-gjgr-66g2.json b/advisories/github-reviewed/2024/06/GHSA-grjv-gjgr-66g2/GHSA-grjv-gjgr-66g2.json index d5f1e2d3c41..ce7c24a3a7a 100644 --- a/advisories/github-reviewed/2024/06/GHSA-grjv-gjgr-66g2/GHSA-grjv-gjgr-66g2.json +++ b/advisories/github-reviewed/2024/06/GHSA-grjv-gjgr-66g2/GHSA-grjv-gjgr-66g2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-grjv-gjgr-66g2", - "modified": "2024-06-21T14:02:46Z", + "modified": "2024-11-18T16:26:46Z", "published": "2024-06-20T16:24:01Z", "aliases": [ "CVE-2024-38361" @@ -61,7 +61,7 @@ "cwe_ids": [ "CWE-281" ], - "severity": "LOW", + "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-06-20T16:24:01Z", "nvd_published_at": "2024-06-20T23:15:52Z" diff --git a/advisories/unreviewed/2022/01/GHSA-vr4w-w9w7-47f2/GHSA-vr4w-w9w7-47f2.json b/advisories/unreviewed/2022/01/GHSA-vr4w-w9w7-47f2/GHSA-vr4w-w9w7-47f2.json index b2e77d14633..ea03b0ab9e9 100644 --- a/advisories/unreviewed/2022/01/GHSA-vr4w-w9w7-47f2/GHSA-vr4w-w9w7-47f2.json +++ b/advisories/unreviewed/2022/01/GHSA-vr4w-w9w7-47f2/GHSA-vr4w-w9w7-47f2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-6hc3-539h-6xc6/GHSA-6hc3-539h-6xc6.json b/advisories/unreviewed/2022/02/GHSA-6hc3-539h-6xc6/GHSA-6hc3-539h-6xc6.json index 52cd6e7c369..6e469c443bf 100644 --- a/advisories/unreviewed/2022/02/GHSA-6hc3-539h-6xc6/GHSA-6hc3-539h-6xc6.json +++ b/advisories/unreviewed/2022/02/GHSA-6hc3-539h-6xc6/GHSA-6hc3-539h-6xc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2288-xjpv-v6jh/GHSA-2288-xjpv-v6jh.json b/advisories/unreviewed/2022/04/GHSA-2288-xjpv-v6jh/GHSA-2288-xjpv-v6jh.json index dfff2aa8c72..7e6e7846cf2 100644 --- a/advisories/unreviewed/2022/04/GHSA-2288-xjpv-v6jh/GHSA-2288-xjpv-v6jh.json +++ b/advisories/unreviewed/2022/04/GHSA-2288-xjpv-v6jh/GHSA-2288-xjpv-v6jh.json @@ -7,12 +7,8 @@ "CVE-2004-0643" ], "details": "Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-22vw-27vp-9fr9/GHSA-22vw-27vp-9fr9.json b/advisories/unreviewed/2022/04/GHSA-22vw-27vp-9fr9/GHSA-22vw-27vp-9fr9.json index f892285fb23..3345b12a1b0 100644 --- a/advisories/unreviewed/2022/04/GHSA-22vw-27vp-9fr9/GHSA-22vw-27vp-9fr9.json +++ b/advisories/unreviewed/2022/04/GHSA-22vw-27vp-9fr9/GHSA-22vw-27vp-9fr9.json @@ -7,12 +7,8 @@ "CVE-2004-0578" ], "details": "WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files via leading slash (//) characters in a URL request to the wingate-internal directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-236g-7xc8-897f/GHSA-236g-7xc8-897f.json b/advisories/unreviewed/2022/04/GHSA-236g-7xc8-897f/GHSA-236g-7xc8-897f.json index cee5dcc45b9..d440e39e6f2 100644 --- a/advisories/unreviewed/2022/04/GHSA-236g-7xc8-897f/GHSA-236g-7xc8-897f.json +++ b/advisories/unreviewed/2022/04/GHSA-236g-7xc8-897f/GHSA-236g-7xc8-897f.json @@ -7,12 +7,8 @@ "CVE-2004-0513" ], "details": "Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to \"logging when tracing system calls.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-25j9-9wxp-hpp7/GHSA-25j9-9wxp-hpp7.json b/advisories/unreviewed/2022/04/GHSA-25j9-9wxp-hpp7/GHSA-25j9-9wxp-hpp7.json index 3f431f72481..d44d8b657b5 100644 --- a/advisories/unreviewed/2022/04/GHSA-25j9-9wxp-hpp7/GHSA-25j9-9wxp-hpp7.json +++ b/advisories/unreviewed/2022/04/GHSA-25j9-9wxp-hpp7/GHSA-25j9-9wxp-hpp7.json @@ -7,12 +7,8 @@ "CVE-2004-0777" ], "details": "Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-27p7-xph2-64m7/GHSA-27p7-xph2-64m7.json b/advisories/unreviewed/2022/04/GHSA-27p7-xph2-64m7/GHSA-27p7-xph2-64m7.json index b5ba7ba7dc1..332273df17e 100644 --- a/advisories/unreviewed/2022/04/GHSA-27p7-xph2-64m7/GHSA-27p7-xph2-64m7.json +++ b/advisories/unreviewed/2022/04/GHSA-27p7-xph2-64m7/GHSA-27p7-xph2-64m7.json @@ -7,12 +7,8 @@ "CVE-2004-0733" ], "details": "Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-27wh-h3mm-7hf3/GHSA-27wh-h3mm-7hf3.json b/advisories/unreviewed/2022/04/GHSA-27wh-h3mm-7hf3/GHSA-27wh-h3mm-7hf3.json index fc9af6cd0eb..4dc27e61698 100644 --- a/advisories/unreviewed/2022/04/GHSA-27wh-h3mm-7hf3/GHSA-27wh-h3mm-7hf3.json +++ b/advisories/unreviewed/2022/04/GHSA-27wh-h3mm-7hf3/GHSA-27wh-h3mm-7hf3.json @@ -7,12 +7,8 @@ "CVE-2004-0618" ], "details": "FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-28rc-mq4v-8p47/GHSA-28rc-mq4v-8p47.json b/advisories/unreviewed/2022/04/GHSA-28rc-mq4v-8p47/GHSA-28rc-mq4v-8p47.json index b378162b5fa..3a22f8bedce 100644 --- a/advisories/unreviewed/2022/04/GHSA-28rc-mq4v-8p47/GHSA-28rc-mq4v-8p47.json +++ b/advisories/unreviewed/2022/04/GHSA-28rc-mq4v-8p47/GHSA-28rc-mq4v-8p47.json @@ -7,12 +7,8 @@ "CVE-2004-0843" ], "details": "Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the \"Plug-in Navigation Address Bar Spoofing Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2ff3-7vm4-rv8x/GHSA-2ff3-7vm4-rv8x.json b/advisories/unreviewed/2022/04/GHSA-2ff3-7vm4-rv8x/GHSA-2ff3-7vm4-rv8x.json index ee9118ffe7d..d02a9b6b83c 100644 --- a/advisories/unreviewed/2022/04/GHSA-2ff3-7vm4-rv8x/GHSA-2ff3-7vm4-rv8x.json +++ b/advisories/unreviewed/2022/04/GHSA-2ff3-7vm4-rv8x/GHSA-2ff3-7vm4-rv8x.json @@ -7,12 +7,8 @@ "CVE-2004-0824" ], "details": "PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2hwp-jrpr-6f78/GHSA-2hwp-jrpr-6f78.json b/advisories/unreviewed/2022/04/GHSA-2hwp-jrpr-6f78/GHSA-2hwp-jrpr-6f78.json index c289d55b778..4e32f8475cf 100644 --- a/advisories/unreviewed/2022/04/GHSA-2hwp-jrpr-6f78/GHSA-2hwp-jrpr-6f78.json +++ b/advisories/unreviewed/2022/04/GHSA-2hwp-jrpr-6f78/GHSA-2hwp-jrpr-6f78.json @@ -7,12 +7,8 @@ "CVE-2004-0779" ], "details": "The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2hx7-84c2-vv8q/GHSA-2hx7-84c2-vv8q.json b/advisories/unreviewed/2022/04/GHSA-2hx7-84c2-vv8q/GHSA-2hx7-84c2-vv8q.json index 31f38cd63a1..ed5556b1986 100644 --- a/advisories/unreviewed/2022/04/GHSA-2hx7-84c2-vv8q/GHSA-2hx7-84c2-vv8q.json +++ b/advisories/unreviewed/2022/04/GHSA-2hx7-84c2-vv8q/GHSA-2hx7-84c2-vv8q.json @@ -7,12 +7,8 @@ "CVE-2004-0549" ], "details": "The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a \"URL:\" prepended to a \"ms-its\" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2jpv-5fxc-x33v/GHSA-2jpv-5fxc-x33v.json b/advisories/unreviewed/2022/04/GHSA-2jpv-5fxc-x33v/GHSA-2jpv-5fxc-x33v.json index c2a338b9b66..2ac1a1f508a 100644 --- a/advisories/unreviewed/2022/04/GHSA-2jpv-5fxc-x33v/GHSA-2jpv-5fxc-x33v.json +++ b/advisories/unreviewed/2022/04/GHSA-2jpv-5fxc-x33v/GHSA-2jpv-5fxc-x33v.json @@ -7,12 +7,8 @@ "CVE-2004-0574" ], "details": "The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an \"unchecked buffer,\" leading to off-by-one and heap-based buffer overflows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2mcr-985f-frgr/GHSA-2mcr-985f-frgr.json b/advisories/unreviewed/2022/04/GHSA-2mcr-985f-frgr/GHSA-2mcr-985f-frgr.json index e263eb4b0a4..aac13ac635a 100644 --- a/advisories/unreviewed/2022/04/GHSA-2mcr-985f-frgr/GHSA-2mcr-985f-frgr.json +++ b/advisories/unreviewed/2022/04/GHSA-2mcr-985f-frgr/GHSA-2mcr-985f-frgr.json @@ -7,12 +7,8 @@ "CVE-2004-0769" ], "details": "Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the \"x\" option but also exploitable through \"l\" and \"v\", and fixed in header.c, a different issue than CVE-2004-0771.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2qch-pvpr-3hrv/GHSA-2qch-pvpr-3hrv.json b/advisories/unreviewed/2022/04/GHSA-2qch-pvpr-3hrv/GHSA-2qch-pvpr-3hrv.json index b68030baa29..3211dd60e64 100644 --- a/advisories/unreviewed/2022/04/GHSA-2qch-pvpr-3hrv/GHSA-2qch-pvpr-3hrv.json +++ b/advisories/unreviewed/2022/04/GHSA-2qch-pvpr-3hrv/GHSA-2qch-pvpr-3hrv.json @@ -7,12 +7,8 @@ "CVE-2004-0875" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2r9j-f6x6-6gpm/GHSA-2r9j-f6x6-6gpm.json b/advisories/unreviewed/2022/04/GHSA-2r9j-f6x6-6gpm/GHSA-2r9j-f6x6-6gpm.json index fc3e633af86..74293f549af 100644 --- a/advisories/unreviewed/2022/04/GHSA-2r9j-f6x6-6gpm/GHSA-2r9j-f6x6-6gpm.json +++ b/advisories/unreviewed/2022/04/GHSA-2r9j-f6x6-6gpm/GHSA-2r9j-f6x6-6gpm.json @@ -7,12 +7,8 @@ "CVE-2004-0781" ], "details": "Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2rvw-r7wq-2mq5/GHSA-2rvw-r7wq-2mq5.json b/advisories/unreviewed/2022/04/GHSA-2rvw-r7wq-2mq5/GHSA-2rvw-r7wq-2mq5.json index 800d053571f..b37d3517d4c 100644 --- a/advisories/unreviewed/2022/04/GHSA-2rvw-r7wq-2mq5/GHSA-2rvw-r7wq-2mq5.json +++ b/advisories/unreviewed/2022/04/GHSA-2rvw-r7wq-2mq5/GHSA-2rvw-r7wq-2mq5.json @@ -7,12 +7,8 @@ "CVE-2004-0569" ], "details": "The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2vv4-9m64-9pj6/GHSA-2vv4-9m64-9pj6.json b/advisories/unreviewed/2022/04/GHSA-2vv4-9m64-9pj6/GHSA-2vv4-9m64-9pj6.json index 0092f7c979c..debabfad183 100644 --- a/advisories/unreviewed/2022/04/GHSA-2vv4-9m64-9pj6/GHSA-2vv4-9m64-9pj6.json +++ b/advisories/unreviewed/2022/04/GHSA-2vv4-9m64-9pj6/GHSA-2vv4-9m64-9pj6.json @@ -7,12 +7,8 @@ "CVE-2004-0559" ], "details": "The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2ww6-g8rg-vh7g/GHSA-2ww6-g8rg-vh7g.json b/advisories/unreviewed/2022/04/GHSA-2ww6-g8rg-vh7g/GHSA-2ww6-g8rg-vh7g.json index 4e3782914a6..8709fc8d8c7 100644 --- a/advisories/unreviewed/2022/04/GHSA-2ww6-g8rg-vh7g/GHSA-2ww6-g8rg-vh7g.json +++ b/advisories/unreviewed/2022/04/GHSA-2ww6-g8rg-vh7g/GHSA-2ww6-g8rg-vh7g.json @@ -7,12 +7,8 @@ "CVE-2004-0739" ], "details": "Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-33hc-85x3-8vj6/GHSA-33hc-85x3-8vj6.json b/advisories/unreviewed/2022/04/GHSA-33hc-85x3-8vj6/GHSA-33hc-85x3-8vj6.json index aa729354199..cc7bf521c1c 100644 --- a/advisories/unreviewed/2022/04/GHSA-33hc-85x3-8vj6/GHSA-33hc-85x3-8vj6.json +++ b/advisories/unreviewed/2022/04/GHSA-33hc-85x3-8vj6/GHSA-33hc-85x3-8vj6.json @@ -7,12 +7,8 @@ "CVE-2004-0732" ], "details": "SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-33pc-wm38-7ffg/GHSA-33pc-wm38-7ffg.json b/advisories/unreviewed/2022/04/GHSA-33pc-wm38-7ffg/GHSA-33pc-wm38-7ffg.json index 7d648f3ee87..f682b96fc44 100644 --- a/advisories/unreviewed/2022/04/GHSA-33pc-wm38-7ffg/GHSA-33pc-wm38-7ffg.json +++ b/advisories/unreviewed/2022/04/GHSA-33pc-wm38-7ffg/GHSA-33pc-wm38-7ffg.json @@ -7,12 +7,8 @@ "CVE-2004-0568" ], "details": "HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-378g-wwv2-rpm8/GHSA-378g-wwv2-rpm8.json b/advisories/unreviewed/2022/04/GHSA-378g-wwv2-rpm8/GHSA-378g-wwv2-rpm8.json index 4a02f35cc57..cfbb20258e5 100644 --- a/advisories/unreviewed/2022/04/GHSA-378g-wwv2-rpm8/GHSA-378g-wwv2-rpm8.json +++ b/advisories/unreviewed/2022/04/GHSA-378g-wwv2-rpm8/GHSA-378g-wwv2-rpm8.json @@ -7,12 +7,8 @@ "CVE-2004-0636" ], "details": "Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-37w2-vq57-6j63/GHSA-37w2-vq57-6j63.json b/advisories/unreviewed/2022/04/GHSA-37w2-vq57-6j63/GHSA-37w2-vq57-6j63.json index b2f8c311d1e..895b0ee8871 100644 --- a/advisories/unreviewed/2022/04/GHSA-37w2-vq57-6j63/GHSA-37w2-vq57-6j63.json +++ b/advisories/unreviewed/2022/04/GHSA-37w2-vq57-6j63/GHSA-37w2-vq57-6j63.json @@ -7,12 +7,8 @@ "CVE-2004-0655" ], "details": "eupdatedb in esearch 0.6.1 and earlier allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-38gp-237c-7q54/GHSA-38gp-237c-7q54.json b/advisories/unreviewed/2022/04/GHSA-38gp-237c-7q54/GHSA-38gp-237c-7q54.json index 3b5af8a3022..0ca37beb993 100644 --- a/advisories/unreviewed/2022/04/GHSA-38gp-237c-7q54/GHSA-38gp-237c-7q54.json +++ b/advisories/unreviewed/2022/04/GHSA-38gp-237c-7q54/GHSA-38gp-237c-7q54.json @@ -7,12 +7,8 @@ "CVE-2004-0850" ], "details": "Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3975-v726-f8hr/GHSA-3975-v726-f8hr.json b/advisories/unreviewed/2022/04/GHSA-3975-v726-f8hr/GHSA-3975-v726-f8hr.json index eebc3767ffb..247949c5601 100644 --- a/advisories/unreviewed/2022/04/GHSA-3975-v726-f8hr/GHSA-3975-v726-f8hr.json +++ b/advisories/unreviewed/2022/04/GHSA-3975-v726-f8hr/GHSA-3975-v726-f8hr.json @@ -7,12 +7,8 @@ "CVE-2004-0497" ], "details": "Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-39hx-hjhc-q6p6/GHSA-39hx-hjhc-q6p6.json b/advisories/unreviewed/2022/04/GHSA-39hx-hjhc-q6p6/GHSA-39hx-hjhc-q6p6.json index 72d7e3f0799..fa2ceb41c58 100644 --- a/advisories/unreviewed/2022/04/GHSA-39hx-hjhc-q6p6/GHSA-39hx-hjhc-q6p6.json +++ b/advisories/unreviewed/2022/04/GHSA-39hx-hjhc-q6p6/GHSA-39hx-hjhc-q6p6.json @@ -7,12 +7,8 @@ "CVE-2004-0558" ], "details": "The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-39xc-jm8g-7f9g/GHSA-39xc-jm8g-7f9g.json b/advisories/unreviewed/2022/04/GHSA-39xc-jm8g-7f9g/GHSA-39xc-jm8g-7f9g.json index 9f9de9f4d54..5df1b2bc412 100644 --- a/advisories/unreviewed/2022/04/GHSA-39xc-jm8g-7f9g/GHSA-39xc-jm8g-7f9g.json +++ b/advisories/unreviewed/2022/04/GHSA-39xc-jm8g-7f9g/GHSA-39xc-jm8g-7f9g.json @@ -7,12 +7,8 @@ "CVE-2004-0662" ], "details": "PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3hf2-82q5-xrxw/GHSA-3hf2-82q5-xrxw.json b/advisories/unreviewed/2022/04/GHSA-3hf2-82q5-xrxw/GHSA-3hf2-82q5-xrxw.json index 16ef98a43ba..de4efc70a90 100644 --- a/advisories/unreviewed/2022/04/GHSA-3hf2-82q5-xrxw/GHSA-3hf2-82q5-xrxw.json +++ b/advisories/unreviewed/2022/04/GHSA-3hf2-82q5-xrxw/GHSA-3hf2-82q5-xrxw.json @@ -7,12 +7,8 @@ "CVE-2004-0537" ], "details": "Opera 7.50 and earlier allows remote web sites to provide a \"Shortcut Icon\" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3hgm-r654-2phm/GHSA-3hgm-r654-2phm.json b/advisories/unreviewed/2022/04/GHSA-3hgm-r654-2phm/GHSA-3hgm-r654-2phm.json index efa2f484438..bb95d90d965 100644 --- a/advisories/unreviewed/2022/04/GHSA-3hgm-r654-2phm/GHSA-3hgm-r654-2phm.json +++ b/advisories/unreviewed/2022/04/GHSA-3hgm-r654-2phm/GHSA-3hgm-r654-2phm.json @@ -7,12 +7,8 @@ "CVE-2004-0684" ], "details": "WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mqm-g7fr-36hv/GHSA-3mqm-g7fr-36hv.json b/advisories/unreviewed/2022/04/GHSA-3mqm-g7fr-36hv/GHSA-3mqm-g7fr-36hv.json index 128d155d20e..7f09446ce44 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mqm-g7fr-36hv/GHSA-3mqm-g7fr-36hv.json +++ b/advisories/unreviewed/2022/04/GHSA-3mqm-g7fr-36hv/GHSA-3mqm-g7fr-36hv.json @@ -7,12 +7,8 @@ "CVE-2004-0540" ], "details": "Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3vcj-6338-x74x/GHSA-3vcj-6338-x74x.json b/advisories/unreviewed/2022/04/GHSA-3vcj-6338-x74x/GHSA-3vcj-6338-x74x.json index 084af71090f..9fb68e53bbc 100644 --- a/advisories/unreviewed/2022/04/GHSA-3vcj-6338-x74x/GHSA-3vcj-6338-x74x.json +++ b/advisories/unreviewed/2022/04/GHSA-3vcj-6338-x74x/GHSA-3vcj-6338-x74x.json @@ -7,12 +7,8 @@ "CVE-2004-0470" ], "details": "BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3xqp-j7cf-5q64/GHSA-3xqp-j7cf-5q64.json b/advisories/unreviewed/2022/04/GHSA-3xqp-j7cf-5q64/GHSA-3xqp-j7cf-5q64.json index 880e916ddf5..bd7d9fde650 100644 --- a/advisories/unreviewed/2022/04/GHSA-3xqp-j7cf-5q64/GHSA-3xqp-j7cf-5q64.json +++ b/advisories/unreviewed/2022/04/GHSA-3xqp-j7cf-5q64/GHSA-3xqp-j7cf-5q64.json @@ -7,12 +7,8 @@ "CVE-2004-0658" ], "details": "Integer overflow in the hpsb_alloc_packet function (incorrectly reported as alloc_hpsb_packet) in IEEE 1394 (Firewire) driver 2.4 and 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via the functions (1) raw1394_write, (2) state_connected, (3) handle_remote_request, or (4) hpsb_make_writebpacket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4238-47vc-27hv/GHSA-4238-47vc-27hv.json b/advisories/unreviewed/2022/04/GHSA-4238-47vc-27hv/GHSA-4238-47vc-27hv.json index ef50b38101b..60974cedeca 100644 --- a/advisories/unreviewed/2022/04/GHSA-4238-47vc-27hv/GHSA-4238-47vc-27hv.json +++ b/advisories/unreviewed/2022/04/GHSA-4238-47vc-27hv/GHSA-4238-47vc-27hv.json @@ -7,12 +7,8 @@ "CVE-2004-0514" ], "details": "Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to \"handling of directory services lookups.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-42fp-4qf3-rqhj/GHSA-42fp-4qf3-rqhj.json b/advisories/unreviewed/2022/04/GHSA-42fp-4qf3-rqhj/GHSA-42fp-4qf3-rqhj.json index 3f211726703..340a8fe0e9d 100644 --- a/advisories/unreviewed/2022/04/GHSA-42fp-4qf3-rqhj/GHSA-42fp-4qf3-rqhj.json +++ b/advisories/unreviewed/2022/04/GHSA-42fp-4qf3-rqhj/GHSA-42fp-4qf3-rqhj.json @@ -7,12 +7,8 @@ "CVE-2004-0522" ], "details": "Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4422-2p52-phgf/GHSA-4422-2p52-phgf.json b/advisories/unreviewed/2022/04/GHSA-4422-2p52-phgf/GHSA-4422-2p52-phgf.json index 151a8775f0a..c7d4fd7f508 100644 --- a/advisories/unreviewed/2022/04/GHSA-4422-2p52-phgf/GHSA-4422-2p52-phgf.json +++ b/advisories/unreviewed/2022/04/GHSA-4422-2p52-phgf/GHSA-4422-2p52-phgf.json @@ -7,12 +7,8 @@ "CVE-2004-0622" ], "details": "Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-45rq-wggf-p92p/GHSA-45rq-wggf-p92p.json b/advisories/unreviewed/2022/04/GHSA-45rq-wggf-p92p/GHSA-45rq-wggf-p92p.json index ef065fa6701..da79eb13382 100644 --- a/advisories/unreviewed/2022/04/GHSA-45rq-wggf-p92p/GHSA-45rq-wggf-p92p.json +++ b/advisories/unreviewed/2022/04/GHSA-45rq-wggf-p92p/GHSA-45rq-wggf-p92p.json @@ -7,12 +7,8 @@ "CVE-2004-0534" ], "details": "Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-475h-mvc3-86vc/GHSA-475h-mvc3-86vc.json b/advisories/unreviewed/2022/04/GHSA-475h-mvc3-86vc/GHSA-475h-mvc3-86vc.json index e479cafacfb..4b7d6e57643 100644 --- a/advisories/unreviewed/2022/04/GHSA-475h-mvc3-86vc/GHSA-475h-mvc3-86vc.json +++ b/advisories/unreviewed/2022/04/GHSA-475h-mvc3-86vc/GHSA-475h-mvc3-86vc.json @@ -7,12 +7,8 @@ "CVE-2004-0731" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other users via the input field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4799-f54j-42m9/GHSA-4799-f54j-42m9.json b/advisories/unreviewed/2022/04/GHSA-4799-f54j-42m9/GHSA-4799-f54j-42m9.json index 7dab491a73c..f150dd92055 100644 --- a/advisories/unreviewed/2022/04/GHSA-4799-f54j-42m9/GHSA-4799-f54j-42m9.json +++ b/advisories/unreviewed/2022/04/GHSA-4799-f54j-42m9/GHSA-4799-f54j-42m9.json @@ -7,12 +7,8 @@ "CVE-2004-0711" ], "details": "The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in \"*\" as wildcards as if they were the legal \"/*\" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because the illegal patterns are properly rejected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-48xm-j6fj-6x92/GHSA-48xm-j6fj-6x92.json b/advisories/unreviewed/2022/04/GHSA-48xm-j6fj-6x92/GHSA-48xm-j6fj-6x92.json index c97559bd95d..59ea88654f9 100644 --- a/advisories/unreviewed/2022/04/GHSA-48xm-j6fj-6x92/GHSA-48xm-j6fj-6x92.json +++ b/advisories/unreviewed/2022/04/GHSA-48xm-j6fj-6x92/GHSA-48xm-j6fj-6x92.json @@ -7,12 +7,8 @@ "CVE-2004-0654" ], "details": "Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-49r8-767c-jxqc/GHSA-49r8-767c-jxqc.json b/advisories/unreviewed/2022/04/GHSA-49r8-767c-jxqc/GHSA-49r8-767c-jxqc.json index 1c491f799a1..950e8ba42ca 100644 --- a/advisories/unreviewed/2022/04/GHSA-49r8-767c-jxqc/GHSA-49r8-767c-jxqc.json +++ b/advisories/unreviewed/2022/04/GHSA-49r8-767c-jxqc/GHSA-49r8-767c-jxqc.json @@ -7,12 +7,8 @@ "CVE-2004-0593" ], "details": "Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4c9c-xpq8-2hv4/GHSA-4c9c-xpq8-2hv4.json b/advisories/unreviewed/2022/04/GHSA-4c9c-xpq8-2hv4/GHSA-4c9c-xpq8-2hv4.json index df21ea76311..40eabc44b86 100644 --- a/advisories/unreviewed/2022/04/GHSA-4c9c-xpq8-2hv4/GHSA-4c9c-xpq8-2hv4.json +++ b/advisories/unreviewed/2022/04/GHSA-4c9c-xpq8-2hv4/GHSA-4c9c-xpq8-2hv4.json @@ -7,12 +7,8 @@ "CVE-2004-0517" ], "details": "Unknown vulnerability in Mac OS X 10.3.4, related to \"handling of process IDs during package installation,\" a different vulnerability than CVE-2004-0516.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4gr5-3999-978f/GHSA-4gr5-3999-978f.json b/advisories/unreviewed/2022/04/GHSA-4gr5-3999-978f/GHSA-4gr5-3999-978f.json index d35b53befa5..93c5ef471f5 100644 --- a/advisories/unreviewed/2022/04/GHSA-4gr5-3999-978f/GHSA-4gr5-3999-978f.json +++ b/advisories/unreviewed/2022/04/GHSA-4gr5-3999-978f/GHSA-4gr5-3999-978f.json @@ -7,12 +7,8 @@ "CVE-2004-0723" ], "details": "Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the \"GET/Key\" and \"PUT/Key/Value\" commands, aka \"cross-site Java.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4wm5-p9jm-9qvv/GHSA-4wm5-p9jm-9qvv.json b/advisories/unreviewed/2022/04/GHSA-4wm5-p9jm-9qvv/GHSA-4wm5-p9jm-9qvv.json index 5d336f2ebcc..b2bc1a45d1d 100644 --- a/advisories/unreviewed/2022/04/GHSA-4wm5-p9jm-9qvv/GHSA-4wm5-p9jm-9qvv.json +++ b/advisories/unreviewed/2022/04/GHSA-4wm5-p9jm-9qvv/GHSA-4wm5-p9jm-9qvv.json @@ -7,12 +7,8 @@ "CVE-2004-0691" ], "details": "Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5253-q8v4-qcg9/GHSA-5253-q8v4-qcg9.json b/advisories/unreviewed/2022/04/GHSA-5253-q8v4-qcg9/GHSA-5253-q8v4-qcg9.json index aa0d9eda203..68b34ac5ec4 100644 --- a/advisories/unreviewed/2022/04/GHSA-5253-q8v4-qcg9/GHSA-5253-q8v4-qcg9.json +++ b/advisories/unreviewed/2022/04/GHSA-5253-q8v4-qcg9/GHSA-5253-q8v4-qcg9.json @@ -7,12 +7,8 @@ "CVE-2004-0648" ], "details": "Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5298-8jr5-5733/GHSA-5298-8jr5-5733.json b/advisories/unreviewed/2022/04/GHSA-5298-8jr5-5733/GHSA-5298-8jr5-5733.json index e28db2b7d13..e400cd54427 100644 --- a/advisories/unreviewed/2022/04/GHSA-5298-8jr5-5733/GHSA-5298-8jr5-5733.json +++ b/advisories/unreviewed/2022/04/GHSA-5298-8jr5-5733/GHSA-5298-8jr5-5733.json @@ -7,12 +7,8 @@ "CVE-2004-0650" ], "details": "UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-53xh-48pv-8445/GHSA-53xh-48pv-8445.json b/advisories/unreviewed/2022/04/GHSA-53xh-48pv-8445/GHSA-53xh-48pv-8445.json index 6e1bf9c8d76..dfb7b9e07bf 100644 --- a/advisories/unreviewed/2022/04/GHSA-53xh-48pv-8445/GHSA-53xh-48pv-8445.json +++ b/advisories/unreviewed/2022/04/GHSA-53xh-48pv-8445/GHSA-53xh-48pv-8445.json @@ -7,12 +7,8 @@ "CVE-2004-0673" ], "details": "Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5435-hp8c-m4q9/GHSA-5435-hp8c-m4q9.json b/advisories/unreviewed/2022/04/GHSA-5435-hp8c-m4q9/GHSA-5435-hp8c-m4q9.json index 8f7648d1b81..5798bc2139b 100644 --- a/advisories/unreviewed/2022/04/GHSA-5435-hp8c-m4q9/GHSA-5435-hp8c-m4q9.json +++ b/advisories/unreviewed/2022/04/GHSA-5435-hp8c-m4q9/GHSA-5435-hp8c-m4q9.json @@ -7,12 +7,8 @@ "CVE-2004-0478" ], "details": "Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascript with an infinite loop that continues to add input to a form, possibly as the result of inserting control characters, as demonstrated using an embedded ctrl-U.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-548c-v26q-5pvf/GHSA-548c-v26q-5pvf.json b/advisories/unreviewed/2022/04/GHSA-548c-v26q-5pvf/GHSA-548c-v26q-5pvf.json index 32c0f2fb37d..a4180249fa3 100644 --- a/advisories/unreviewed/2022/04/GHSA-548c-v26q-5pvf/GHSA-548c-v26q-5pvf.json +++ b/advisories/unreviewed/2022/04/GHSA-548c-v26q-5pvf/GHSA-548c-v26q-5pvf.json @@ -7,12 +7,8 @@ "CVE-2004-0683" ], "details": "Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive that contains a large number of directories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-55w2-52pp-35qg/GHSA-55w2-52pp-35qg.json b/advisories/unreviewed/2022/04/GHSA-55w2-52pp-35qg/GHSA-55w2-52pp-35qg.json index fcb69f66176..c46bd58d268 100644 --- a/advisories/unreviewed/2022/04/GHSA-55w2-52pp-35qg/GHSA-55w2-52pp-35qg.json +++ b/advisories/unreviewed/2022/04/GHSA-55w2-52pp-35qg/GHSA-55w2-52pp-35qg.json @@ -7,12 +7,8 @@ "CVE-2004-0481" ], "details": "The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-56r3-rhf9-5xfv/GHSA-56r3-rhf9-5xfv.json b/advisories/unreviewed/2022/04/GHSA-56r3-rhf9-5xfv/GHSA-56r3-rhf9-5xfv.json index e978fd68983..1b165f23166 100644 --- a/advisories/unreviewed/2022/04/GHSA-56r3-rhf9-5xfv/GHSA-56r3-rhf9-5xfv.json +++ b/advisories/unreviewed/2022/04/GHSA-56r3-rhf9-5xfv/GHSA-56r3-rhf9-5xfv.json @@ -7,12 +7,8 @@ "CVE-2004-0564" ], "details": "Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe \"is NOT designed to run setuid-root.\" Therefore this identifier applies *only* to those configurations and installations under which pppoe is run setuid root despite the developer's warnings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-56vw-hr2p-ff5f/GHSA-56vw-hr2p-ff5f.json b/advisories/unreviewed/2022/04/GHSA-56vw-hr2p-ff5f/GHSA-56vw-hr2p-ff5f.json index 0d27bf63a76..ae5c741194c 100644 --- a/advisories/unreviewed/2022/04/GHSA-56vw-hr2p-ff5f/GHSA-56vw-hr2p-ff5f.json +++ b/advisories/unreviewed/2022/04/GHSA-56vw-hr2p-ff5f/GHSA-56vw-hr2p-ff5f.json @@ -7,12 +7,8 @@ "CVE-2004-0473" ], "details": "Argument injection vulnerability in Opera before 7.50 does not properly filter \"-\" characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the \"-f\" option on Windows XP or (2) the \"-n\" option on Linux.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-596g-qg9p-5mvj/GHSA-596g-qg9p-5mvj.json b/advisories/unreviewed/2022/04/GHSA-596g-qg9p-5mvj/GHSA-596g-qg9p-5mvj.json index feb6712d90b..022b54dd90a 100644 --- a/advisories/unreviewed/2022/04/GHSA-596g-qg9p-5mvj/GHSA-596g-qg9p-5mvj.json +++ b/advisories/unreviewed/2022/04/GHSA-596g-qg9p-5mvj/GHSA-596g-qg9p-5mvj.json @@ -7,12 +7,8 @@ "CVE-2004-0571" ], "details": "Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka \"Table Conversion Vulnerability,\" a different vulnerability than CVE-2004-0901.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-59m9-8c72-5426/GHSA-59m9-8c72-5426.json b/advisories/unreviewed/2022/04/GHSA-59m9-8c72-5426/GHSA-59m9-8c72-5426.json index ed9fb040ea1..adb62312248 100644 --- a/advisories/unreviewed/2022/04/GHSA-59m9-8c72-5426/GHSA-59m9-8c72-5426.json +++ b/advisories/unreviewed/2022/04/GHSA-59m9-8c72-5426/GHSA-59m9-8c72-5426.json @@ -7,12 +7,8 @@ "CVE-2004-0755" ], "details": "The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5h68-87jm-pwv5/GHSA-5h68-87jm-pwv5.json b/advisories/unreviewed/2022/04/GHSA-5h68-87jm-pwv5/GHSA-5h68-87jm-pwv5.json index c3b2b99b48a..1be4829ec2c 100644 --- a/advisories/unreviewed/2022/04/GHSA-5h68-87jm-pwv5/GHSA-5h68-87jm-pwv5.json +++ b/advisories/unreviewed/2022/04/GHSA-5h68-87jm-pwv5/GHSA-5h68-87jm-pwv5.json @@ -7,12 +7,8 @@ "CVE-2004-0744" ], "details": "The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a \"Rose Attack\" that involves sending a subset of small IP fragments that do not form a complete, larger packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5p6g-jmm7-vr47/GHSA-5p6g-jmm7-vr47.json b/advisories/unreviewed/2022/04/GHSA-5p6g-jmm7-vr47/GHSA-5p6g-jmm7-vr47.json index 7ea360baf73..c01c5bdf6ff 100644 --- a/advisories/unreviewed/2022/04/GHSA-5p6g-jmm7-vr47/GHSA-5p6g-jmm7-vr47.json +++ b/advisories/unreviewed/2022/04/GHSA-5p6g-jmm7-vr47/GHSA-5p6g-jmm7-vr47.json @@ -7,12 +7,8 @@ "CVE-2004-0516" ], "details": "Unknown vulnerability in Mac OS X 10.3.4, related to \"package installation scripts,\" a different vulnerability than CVE-2004-0517.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5p78-xr8q-m3rj/GHSA-5p78-xr8q-m3rj.json b/advisories/unreviewed/2022/04/GHSA-5p78-xr8q-m3rj/GHSA-5p78-xr8q-m3rj.json index 3b442fb91e0..6c2b6ce3da1 100644 --- a/advisories/unreviewed/2022/04/GHSA-5p78-xr8q-m3rj/GHSA-5p78-xr8q-m3rj.json +++ b/advisories/unreviewed/2022/04/GHSA-5p78-xr8q-m3rj/GHSA-5p78-xr8q-m3rj.json @@ -7,12 +7,8 @@ "CVE-2004-0666" ], "details": "Off-by-one error in the POP3_readmsg function in popclient 3.0b6 allows remote attackers to cause a denial of service (application crash) via an e-mail message with a certain line length, which leads to a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5qp2-wwm4-h7fm/GHSA-5qp2-wwm4-h7fm.json b/advisories/unreviewed/2022/04/GHSA-5qp2-wwm4-h7fm/GHSA-5qp2-wwm4-h7fm.json index 6cb591bea5d..597813e07e6 100644 --- a/advisories/unreviewed/2022/04/GHSA-5qp2-wwm4-h7fm/GHSA-5qp2-wwm4-h7fm.json +++ b/advisories/unreviewed/2022/04/GHSA-5qp2-wwm4-h7fm/GHSA-5qp2-wwm4-h7fm.json @@ -7,12 +7,8 @@ "CVE-2004-0590" ], "details": "FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-signed certificate identifies an alternate Certificate Authority (CA) and spoofed issuer and subject.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5rq9-m7h9-8rgp/GHSA-5rq9-m7h9-8rgp.json b/advisories/unreviewed/2022/04/GHSA-5rq9-m7h9-8rgp/GHSA-5rq9-m7h9-8rgp.json index a41ea0430d9..c26850721ca 100644 --- a/advisories/unreviewed/2022/04/GHSA-5rq9-m7h9-8rgp/GHSA-5rq9-m7h9-8rgp.json +++ b/advisories/unreviewed/2022/04/GHSA-5rq9-m7h9-8rgp/GHSA-5rq9-m7h9-8rgp.json @@ -7,12 +7,8 @@ "CVE-2004-0706" ], "details": "Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5w5x-24p6-895v/GHSA-5w5x-24p6-895v.json b/advisories/unreviewed/2022/04/GHSA-5w5x-24p6-895v/GHSA-5w5x-24p6-895v.json index 3bfcbb73fd4..084abe6f681 100644 --- a/advisories/unreviewed/2022/04/GHSA-5w5x-24p6-895v/GHSA-5w5x-24p6-895v.json +++ b/advisories/unreviewed/2022/04/GHSA-5w5x-24p6-895v/GHSA-5w5x-24p6-895v.json @@ -7,12 +7,8 @@ "CVE-2004-0721" ], "details": "Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5xp3-6wvw-p3c8/GHSA-5xp3-6wvw-p3c8.json b/advisories/unreviewed/2022/04/GHSA-5xp3-6wvw-p3c8/GHSA-5xp3-6wvw-p3c8.json index 7463e56839b..39438e6df43 100644 --- a/advisories/unreviewed/2022/04/GHSA-5xp3-6wvw-p3c8/GHSA-5xp3-6wvw-p3c8.json +++ b/advisories/unreviewed/2022/04/GHSA-5xp3-6wvw-p3c8/GHSA-5xp3-6wvw-p3c8.json @@ -7,12 +7,8 @@ "CVE-2004-0560" ], "details": "Integer overflow in gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted content of a certain size that triggers the overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-624v-gqcq-xp7r/GHSA-624v-gqcq-xp7r.json b/advisories/unreviewed/2022/04/GHSA-624v-gqcq-xp7r/GHSA-624v-gqcq-xp7r.json index b77920f9375..cf2b1643437 100644 --- a/advisories/unreviewed/2022/04/GHSA-624v-gqcq-xp7r/GHSA-624v-gqcq-xp7r.json +++ b/advisories/unreviewed/2022/04/GHSA-624v-gqcq-xp7r/GHSA-624v-gqcq-xp7r.json @@ -7,12 +7,8 @@ "CVE-2004-0475" ], "details": "The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash (\"\\\\\") before the target CHM file, as demonstrated using an \"ms-its\" URL to ntshared.chm. NOTE: this bug may overlap CVE-2003-1041.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6446-v6gj-7jm6/GHSA-6446-v6gj-7jm6.json b/advisories/unreviewed/2022/04/GHSA-6446-v6gj-7jm6/GHSA-6446-v6gj-7jm6.json index 7c98a61b31b..3f0ef6300c7 100644 --- a/advisories/unreviewed/2022/04/GHSA-6446-v6gj-7jm6/GHSA-6446-v6gj-7jm6.json +++ b/advisories/unreviewed/2022/04/GHSA-6446-v6gj-7jm6/GHSA-6446-v6gj-7jm6.json @@ -7,12 +7,8 @@ "CVE-2004-0694" ], "details": "Buffer overflow in LHA 1.14 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to \"command line processing,\" a different vulnerability than CVE-2004-0771. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-67c4-9qg5-5597/GHSA-67c4-9qg5-5597.json b/advisories/unreviewed/2022/04/GHSA-67c4-9qg5-5597/GHSA-67c4-9qg5-5597.json index e0e902d30fb..60a6fb6e661 100644 --- a/advisories/unreviewed/2022/04/GHSA-67c4-9qg5-5597/GHSA-67c4-9qg5-5597.json +++ b/advisories/unreviewed/2022/04/GHSA-67c4-9qg5-5597/GHSA-67c4-9qg5-5597.json @@ -7,12 +7,8 @@ "CVE-2004-0592" ], "details": "The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type, a similar flaw to CVE-2004-0626.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-67q3-x38q-5454/GHSA-67q3-x38q-5454.json b/advisories/unreviewed/2022/04/GHSA-67q3-x38q-5454/GHSA-67q3-x38q-5454.json index 40678c79476..87f5ee7f32c 100644 --- a/advisories/unreviewed/2022/04/GHSA-67q3-x38q-5454/GHSA-67q3-x38q-5454.json +++ b/advisories/unreviewed/2022/04/GHSA-67q3-x38q-5454/GHSA-67q3-x38q-5454.json @@ -7,12 +7,8 @@ "CVE-2004-0498" ], "details": "The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-692f-vx63-5hrp/GHSA-692f-vx63-5hrp.json b/advisories/unreviewed/2022/04/GHSA-692f-vx63-5hrp/GHSA-692f-vx63-5hrp.json index ac440c0b96c..fa054609478 100644 --- a/advisories/unreviewed/2022/04/GHSA-692f-vx63-5hrp/GHSA-692f-vx63-5hrp.json +++ b/advisories/unreviewed/2022/04/GHSA-692f-vx63-5hrp/GHSA-692f-vx63-5hrp.json @@ -7,12 +7,8 @@ "CVE-2004-0736" ], "details": "The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) \"**\" or (2) \"+\" search patterns, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-694j-gvq7-rqg6/GHSA-694j-gvq7-rqg6.json b/advisories/unreviewed/2022/04/GHSA-694j-gvq7-rqg6/GHSA-694j-gvq7-rqg6.json index f1979fcebf3..808040a415b 100644 --- a/advisories/unreviewed/2022/04/GHSA-694j-gvq7-rqg6/GHSA-694j-gvq7-rqg6.json +++ b/advisories/unreviewed/2022/04/GHSA-694j-gvq7-rqg6/GHSA-694j-gvq7-rqg6.json @@ -7,12 +7,8 @@ "CVE-2004-0623" ], "details": "Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-69m4-h2jg-j943/GHSA-69m4-h2jg-j943.json b/advisories/unreviewed/2022/04/GHSA-69m4-h2jg-j943/GHSA-69m4-h2jg-j943.json index e0eb92f36e6..b07ac8ebc6a 100644 --- a/advisories/unreviewed/2022/04/GHSA-69m4-h2jg-j943/GHSA-69m4-h2jg-j943.json +++ b/advisories/unreviewed/2022/04/GHSA-69m4-h2jg-j943/GHSA-69m4-h2jg-j943.json @@ -7,12 +7,8 @@ "CVE-2004-0869" ], "details": "Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka \"Cross Security Boundary Cookie Injection.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6f26-27c8-j6cv/GHSA-6f26-27c8-j6cv.json b/advisories/unreviewed/2022/04/GHSA-6f26-27c8-j6cv/GHSA-6f26-27c8-j6cv.json index b8abcee322d..fb9a3ea6d40 100644 --- a/advisories/unreviewed/2022/04/GHSA-6f26-27c8-j6cv/GHSA-6f26-27c8-j6cv.json +++ b/advisories/unreviewed/2022/04/GHSA-6f26-27c8-j6cv/GHSA-6f26-27c8-j6cv.json @@ -7,12 +7,8 @@ "CVE-2004-0836" ], "details": "Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6f38-6h33-w674/GHSA-6f38-6h33-w674.json b/advisories/unreviewed/2022/04/GHSA-6f38-6h33-w674/GHSA-6f38-6h33-w674.json index 7effe4beacb..4611e3cf91c 100644 --- a/advisories/unreviewed/2022/04/GHSA-6f38-6h33-w674/GHSA-6f38-6h33-w674.json +++ b/advisories/unreviewed/2022/04/GHSA-6f38-6h33-w674/GHSA-6f38-6h33-w674.json @@ -7,12 +7,8 @@ "CVE-2004-0518" ], "details": "Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to \"the use of SSH and reporting errors,\" has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6qm5-wc6x-qvhj/GHSA-6qm5-wc6x-qvhj.json b/advisories/unreviewed/2022/04/GHSA-6qm5-wc6x-qvhj/GHSA-6qm5-wc6x-qvhj.json index 23bb2296cc0..433814edc0f 100644 --- a/advisories/unreviewed/2022/04/GHSA-6qm5-wc6x-qvhj/GHSA-6qm5-wc6x-qvhj.json +++ b/advisories/unreviewed/2022/04/GHSA-6qm5-wc6x-qvhj/GHSA-6qm5-wc6x-qvhj.json @@ -7,12 +7,8 @@ "CVE-2004-0610" ], "details": "The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6rfw-qh35-3qg2/GHSA-6rfw-qh35-3qg2.json b/advisories/unreviewed/2022/04/GHSA-6rfw-qh35-3qg2/GHSA-6rfw-qh35-3qg2.json index 2ce7a9761b9..5b63e43781f 100644 --- a/advisories/unreviewed/2022/04/GHSA-6rfw-qh35-3qg2/GHSA-6rfw-qh35-3qg2.json +++ b/advisories/unreviewed/2022/04/GHSA-6rfw-qh35-3qg2/GHSA-6rfw-qh35-3qg2.json @@ -7,12 +7,8 @@ "CVE-2004-0596" ], "details": "The Equalizer Load-balancer for serial network interfaces (eql.c) in Linux kernel 2.6.x up to 2.6.7 allows local users to cause a denial of service via a non-existent device name that triggers a null dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6vxj-9pwr-w3q9/GHSA-6vxj-9pwr-w3q9.json b/advisories/unreviewed/2022/04/GHSA-6vxj-9pwr-w3q9/GHSA-6vxj-9pwr-w3q9.json index a7f89c4cb05..5a63094afc8 100644 --- a/advisories/unreviewed/2022/04/GHSA-6vxj-9pwr-w3q9/GHSA-6vxj-9pwr-w3q9.json +++ b/advisories/unreviewed/2022/04/GHSA-6vxj-9pwr-w3q9/GHSA-6vxj-9pwr-w3q9.json @@ -7,12 +7,8 @@ "CVE-2004-0561" ], "details": "Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6wf7-h6x3-vqqj/GHSA-6wf7-h6x3-vqqj.json b/advisories/unreviewed/2022/04/GHSA-6wf7-h6x3-vqqj/GHSA-6wf7-h6x3-vqqj.json index 3382c24fe39..e9d04dce30e 100644 --- a/advisories/unreviewed/2022/04/GHSA-6wf7-h6x3-vqqj/GHSA-6wf7-h6x3-vqqj.json +++ b/advisories/unreviewed/2022/04/GHSA-6wf7-h6x3-vqqj/GHSA-6wf7-h6x3-vqqj.json @@ -7,12 +7,8 @@ "CVE-2004-0600" ], "details": "Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6xx6-74w2-pvf3/GHSA-6xx6-74w2-pvf3.json b/advisories/unreviewed/2022/04/GHSA-6xx6-74w2-pvf3/GHSA-6xx6-74w2-pvf3.json index aec7574661d..48a863a8a6b 100644 --- a/advisories/unreviewed/2022/04/GHSA-6xx6-74w2-pvf3/GHSA-6xx6-74w2-pvf3.json +++ b/advisories/unreviewed/2022/04/GHSA-6xx6-74w2-pvf3/GHSA-6xx6-74w2-pvf3.json @@ -7,12 +7,8 @@ "CVE-2004-0840" ], "details": "The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-72f5-gxfw-g5pj/GHSA-72f5-gxfw-g5pj.json b/advisories/unreviewed/2022/04/GHSA-72f5-gxfw-g5pj/GHSA-72f5-gxfw-g5pj.json index 002cf1d2424..4e124519f84 100644 --- a/advisories/unreviewed/2022/04/GHSA-72f5-gxfw-g5pj/GHSA-72f5-gxfw-g5pj.json +++ b/advisories/unreviewed/2022/04/GHSA-72f5-gxfw-g5pj/GHSA-72f5-gxfw-g5pj.json @@ -7,12 +7,8 @@ "CVE-2004-0487" ], "details": "A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-74rf-qhrr-fxrm/GHSA-74rf-qhrr-fxrm.json b/advisories/unreviewed/2022/04/GHSA-74rf-qhrr-fxrm/GHSA-74rf-qhrr-fxrm.json index c833aa39219..475086bc83d 100644 --- a/advisories/unreviewed/2022/04/GHSA-74rf-qhrr-fxrm/GHSA-74rf-qhrr-fxrm.json +++ b/advisories/unreviewed/2022/04/GHSA-74rf-qhrr-fxrm/GHSA-74rf-qhrr-fxrm.json @@ -7,12 +7,8 @@ "CVE-2004-0838" ], "details": "Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-75ph-gf88-2722/GHSA-75ph-gf88-2722.json b/advisories/unreviewed/2022/04/GHSA-75ph-gf88-2722/GHSA-75ph-gf88-2722.json index 7ae1f93bf77..91ac7a68b64 100644 --- a/advisories/unreviewed/2022/04/GHSA-75ph-gf88-2722/GHSA-75ph-gf88-2722.json +++ b/advisories/unreviewed/2022/04/GHSA-75ph-gf88-2722/GHSA-75ph-gf88-2722.json @@ -7,12 +7,8 @@ "CVE-2004-0835" ], "details": "MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-77xv-jf9g-qvgv/GHSA-77xv-jf9g-qvgv.json b/advisories/unreviewed/2022/04/GHSA-77xv-jf9g-qvgv/GHSA-77xv-jf9g-qvgv.json index c29e9b373a7..149d6046c49 100644 --- a/advisories/unreviewed/2022/04/GHSA-77xv-jf9g-qvgv/GHSA-77xv-jf9g-qvgv.json +++ b/advisories/unreviewed/2022/04/GHSA-77xv-jf9g-qvgv/GHSA-77xv-jf9g-qvgv.json @@ -7,12 +7,8 @@ "CVE-2004-0627" ], "details": "The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-78qg-2h6c-h3jf/GHSA-78qg-2h6c-h3jf.json b/advisories/unreviewed/2022/04/GHSA-78qg-2h6c-h3jf/GHSA-78qg-2h6c-h3jf.json index 4ccc460b39b..4b0daa9871c 100644 --- a/advisories/unreviewed/2022/04/GHSA-78qg-2h6c-h3jf/GHSA-78qg-2h6c-h3jf.json +++ b/advisories/unreviewed/2022/04/GHSA-78qg-2h6c-h3jf/GHSA-78qg-2h6c-h3jf.json @@ -7,12 +7,8 @@ "CVE-2004-0678" ], "details": "Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-78v6-755w-hx23/GHSA-78v6-755w-hx23.json b/advisories/unreviewed/2022/04/GHSA-78v6-755w-hx23/GHSA-78v6-755w-hx23.json index 24ae469ff24..9181fb70928 100644 --- a/advisories/unreviewed/2022/04/GHSA-78v6-755w-hx23/GHSA-78v6-755w-hx23.json +++ b/advisories/unreviewed/2022/04/GHSA-78v6-755w-hx23/GHSA-78v6-755w-hx23.json @@ -7,12 +7,8 @@ "CVE-2004-0743" ], "details": "Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected after the POST data and the user uses the forward or backward buttons, which may cause an information leak.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7c4j-3c7c-wh66/GHSA-7c4j-3c7c-wh66.json b/advisories/unreviewed/2022/04/GHSA-7c4j-3c7c-wh66/GHSA-7c4j-3c7c-wh66.json index 98a08deaf06..6420e976503 100644 --- a/advisories/unreviewed/2022/04/GHSA-7c4j-3c7c-wh66/GHSA-7c4j-3c7c-wh66.json +++ b/advisories/unreviewed/2022/04/GHSA-7c4j-3c7c-wh66/GHSA-7c4j-3c7c-wh66.json @@ -7,12 +7,8 @@ "CVE-2004-0598" ], "details": "The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7c6c-h82r-p2cf/GHSA-7c6c-h82r-p2cf.json b/advisories/unreviewed/2022/04/GHSA-7c6c-h82r-p2cf/GHSA-7c6c-h82r-p2cf.json index 4d77ef0e8f8..e44978652eb 100644 --- a/advisories/unreviewed/2022/04/GHSA-7c6c-h82r-p2cf/GHSA-7c6c-h82r-p2cf.json +++ b/advisories/unreviewed/2022/04/GHSA-7c6c-h82r-p2cf/GHSA-7c6c-h82r-p2cf.json @@ -7,12 +7,8 @@ "CVE-2004-0686" ], "details": "Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the \"mangling method = hash\" option is enabled in smb.conf, has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7fvf-4h9p-wfw6/GHSA-7fvf-4h9p-wfw6.json b/advisories/unreviewed/2022/04/GHSA-7fvf-4h9p-wfw6/GHSA-7fvf-4h9p-wfw6.json index 78d43287c1d..53d8bbda3d7 100644 --- a/advisories/unreviewed/2022/04/GHSA-7fvf-4h9p-wfw6/GHSA-7fvf-4h9p-wfw6.json +++ b/advisories/unreviewed/2022/04/GHSA-7fvf-4h9p-wfw6/GHSA-7fvf-4h9p-wfw6.json @@ -7,12 +7,8 @@ "CVE-2004-0846" ], "details": "Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7h4g-phhp-6jm7/GHSA-7h4g-phhp-6jm7.json b/advisories/unreviewed/2022/04/GHSA-7h4g-phhp-6jm7/GHSA-7h4g-phhp-6jm7.json index 6af04628081..69df11ad6ab 100644 --- a/advisories/unreviewed/2022/04/GHSA-7h4g-phhp-6jm7/GHSA-7h4g-phhp-6jm7.json +++ b/advisories/unreviewed/2022/04/GHSA-7h4g-phhp-6jm7/GHSA-7h4g-phhp-6jm7.json @@ -7,12 +7,8 @@ "CVE-2004-0589" ], "details": "Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers to cause a denial of service (device reload) via malformed BGP (1) OPEN or (2) UPDATE messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7hp5-737x-3jmh/GHSA-7hp5-737x-3jmh.json b/advisories/unreviewed/2022/04/GHSA-7hp5-737x-3jmh/GHSA-7hp5-737x-3jmh.json index 5e4ef0bf2ba..addb7166bea 100644 --- a/advisories/unreviewed/2022/04/GHSA-7hp5-737x-3jmh/GHSA-7hp5-737x-3jmh.json +++ b/advisories/unreviewed/2022/04/GHSA-7hp5-737x-3jmh/GHSA-7hp5-737x-3jmh.json @@ -7,12 +7,8 @@ "CVE-2004-0554" ], "details": "Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a \"crash.c\" program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7mwf-cmrh-q8j4/GHSA-7mwf-cmrh-q8j4.json b/advisories/unreviewed/2022/04/GHSA-7mwf-cmrh-q8j4/GHSA-7mwf-cmrh-q8j4.json index faf19c454b6..fce3769a74e 100644 --- a/advisories/unreviewed/2022/04/GHSA-7mwf-cmrh-q8j4/GHSA-7mwf-cmrh-q8j4.json +++ b/advisories/unreviewed/2022/04/GHSA-7mwf-cmrh-q8j4/GHSA-7mwf-cmrh-q8j4.json @@ -7,12 +7,8 @@ "CVE-2004-0474" ], "details": "Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an \"http://\" or \"file://\" argument to the topic parameter in an hcp:// URL. NOTE: since the initial report of this problem, several researchers have been unable to reproduce this issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7phx-pr8q-9fmf/GHSA-7phx-pr8q-9fmf.json b/advisories/unreviewed/2022/04/GHSA-7phx-pr8q-9fmf/GHSA-7phx-pr8q-9fmf.json index 5d45b024d91..95c6e388ff5 100644 --- a/advisories/unreviewed/2022/04/GHSA-7phx-pr8q-9fmf/GHSA-7phx-pr8q-9fmf.json +++ b/advisories/unreviewed/2022/04/GHSA-7phx-pr8q-9fmf/GHSA-7phx-pr8q-9fmf.json @@ -7,12 +7,8 @@ "CVE-2004-0632" ], "details": "Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that is not normally handled by Reader, triggering a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7q44-7gf4-9rcp/GHSA-7q44-7gf4-9rcp.json b/advisories/unreviewed/2022/04/GHSA-7q44-7gf4-9rcp/GHSA-7q44-7gf4-9rcp.json index 2cf37c99643..4784186be47 100644 --- a/advisories/unreviewed/2022/04/GHSA-7q44-7gf4-9rcp/GHSA-7q44-7gf4-9rcp.json +++ b/advisories/unreviewed/2022/04/GHSA-7q44-7gf4-9rcp/GHSA-7q44-7gf4-9rcp.json @@ -7,12 +7,8 @@ "CVE-2004-0606" ], "details": "Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTNAME option of a DHCP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7qqw-7g43-32fc/GHSA-7qqw-7g43-32fc.json b/advisories/unreviewed/2022/04/GHSA-7qqw-7g43-32fc/GHSA-7qqw-7g43-32fc.json index 09a08ae729e..a8564f92c65 100644 --- a/advisories/unreviewed/2022/04/GHSA-7qqw-7g43-32fc/GHSA-7qqw-7g43-32fc.json +++ b/advisories/unreviewed/2022/04/GHSA-7qqw-7g43-32fc/GHSA-7qqw-7g43-32fc.json @@ -7,12 +7,8 @@ "CVE-2004-0873" ], "details": "Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a \"link\" that references the program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7rr4-25h7-4mj3/GHSA-7rr4-25h7-4mj3.json b/advisories/unreviewed/2022/04/GHSA-7rr4-25h7-4mj3/GHSA-7rr4-25h7-4mj3.json index e28d0d882bc..d39c80d95d0 100644 --- a/advisories/unreviewed/2022/04/GHSA-7rr4-25h7-4mj3/GHSA-7rr4-25h7-4mj3.json +++ b/advisories/unreviewed/2022/04/GHSA-7rr4-25h7-4mj3/GHSA-7rr4-25h7-4mj3.json @@ -7,12 +7,8 @@ "CVE-2004-0823" ], "details": "OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7v9x-2x36-jcr3/GHSA-7v9x-2x36-jcr3.json b/advisories/unreviewed/2022/04/GHSA-7v9x-2x36-jcr3/GHSA-7v9x-2x36-jcr3.json index b0a12f514df..398eb9cce60 100644 --- a/advisories/unreviewed/2022/04/GHSA-7v9x-2x36-jcr3/GHSA-7v9x-2x36-jcr3.json +++ b/advisories/unreviewed/2022/04/GHSA-7v9x-2x36-jcr3/GHSA-7v9x-2x36-jcr3.json @@ -7,12 +7,8 @@ "CVE-2004-0709" ], "details": "HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which could allow remote attackers to bypass access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7wfm-r8jm-499h/GHSA-7wfm-r8jm-499h.json b/advisories/unreviewed/2022/04/GHSA-7wfm-r8jm-499h/GHSA-7wfm-r8jm-499h.json index 5bdc1953664..1d8487466b0 100644 --- a/advisories/unreviewed/2022/04/GHSA-7wfm-r8jm-499h/GHSA-7wfm-r8jm-499h.json +++ b/advisories/unreviewed/2022/04/GHSA-7wfm-r8jm-499h/GHSA-7wfm-r8jm-499h.json @@ -7,12 +7,8 @@ "CVE-2004-0494" ], "details": "Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7wv3-c4wx-9xjq/GHSA-7wv3-c4wx-9xjq.json b/advisories/unreviewed/2022/04/GHSA-7wv3-c4wx-9xjq/GHSA-7wv3-c4wx-9xjq.json index 32fa31ae608..92646f74a4c 100644 --- a/advisories/unreviewed/2022/04/GHSA-7wv3-c4wx-9xjq/GHSA-7wv3-c4wx-9xjq.json +++ b/advisories/unreviewed/2022/04/GHSA-7wv3-c4wx-9xjq/GHSA-7wv3-c4wx-9xjq.json @@ -7,12 +7,8 @@ "CVE-2004-0552" ], "details": "Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7xq5-jxmg-7hjc/GHSA-7xq5-jxmg-7hjc.json b/advisories/unreviewed/2022/04/GHSA-7xq5-jxmg-7hjc/GHSA-7xq5-jxmg-7hjc.json index d9eeb2b4b30..9103ecb175b 100644 --- a/advisories/unreviewed/2022/04/GHSA-7xq5-jxmg-7hjc/GHSA-7xq5-jxmg-7hjc.json +++ b/advisories/unreviewed/2022/04/GHSA-7xq5-jxmg-7hjc/GHSA-7xq5-jxmg-7hjc.json @@ -7,12 +7,8 @@ "CVE-2004-0848" ], "details": "Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) \"%00 (null byte) in .doc filenames or (2) \"%0a\" (carriage return) in .rtf filenames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-83x8-fwcx-3pmf/GHSA-83x8-fwcx-3pmf.json b/advisories/unreviewed/2022/04/GHSA-83x8-fwcx-3pmf/GHSA-83x8-fwcx-3pmf.json index 562df20dda3..79d29e8b3e5 100644 --- a/advisories/unreviewed/2022/04/GHSA-83x8-fwcx-3pmf/GHSA-83x8-fwcx-3pmf.json +++ b/advisories/unreviewed/2022/04/GHSA-83x8-fwcx-3pmf/GHSA-83x8-fwcx-3pmf.json @@ -7,12 +7,8 @@ "CVE-2004-0547" ], "details": "Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-878f-q47g-6pq6/GHSA-878f-q47g-6pq6.json b/advisories/unreviewed/2022/04/GHSA-878f-q47g-6pq6/GHSA-878f-q47g-6pq6.json index da49696d689..71ba6830421 100644 --- a/advisories/unreviewed/2022/04/GHSA-878f-q47g-6pq6/GHSA-878f-q47g-6pq6.json +++ b/advisories/unreviewed/2022/04/GHSA-878f-q47g-6pq6/GHSA-878f-q47g-6pq6.json @@ -7,12 +7,8 @@ "CVE-2004-0526" ], "details": "Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified \"alt\" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a \"phishing\" attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8c8w-44vm-45hw/GHSA-8c8w-44vm-45hw.json b/advisories/unreviewed/2022/04/GHSA-8c8w-44vm-45hw/GHSA-8c8w-44vm-45hw.json index 68bf8703440..9bdaa8cdb5d 100644 --- a/advisories/unreviewed/2022/04/GHSA-8c8w-44vm-45hw/GHSA-8c8w-44vm-45hw.json +++ b/advisories/unreviewed/2022/04/GHSA-8c8w-44vm-45hw/GHSA-8c8w-44vm-45hw.json @@ -7,12 +7,8 @@ "CVE-2004-0845" ], "details": "Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8g8f-28jw-7gwq/GHSA-8g8f-28jw-7gwq.json b/advisories/unreviewed/2022/04/GHSA-8g8f-28jw-7gwq/GHSA-8g8f-28jw-7gwq.json index ad6de168eb2..f6b3d63a262 100644 --- a/advisories/unreviewed/2022/04/GHSA-8g8f-28jw-7gwq/GHSA-8g8f-28jw-7gwq.json +++ b/advisories/unreviewed/2022/04/GHSA-8g8f-28jw-7gwq/GHSA-8g8f-28jw-7gwq.json @@ -7,12 +7,8 @@ "CVE-2004-0851" ], "details": "The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8j48-wxgf-pfpq/GHSA-8j48-wxgf-pfpq.json b/advisories/unreviewed/2022/04/GHSA-8j48-wxgf-pfpq/GHSA-8j48-wxgf-pfpq.json index 72ae65e4d0c..823ade20216 100644 --- a/advisories/unreviewed/2022/04/GHSA-8j48-wxgf-pfpq/GHSA-8j48-wxgf-pfpq.json +++ b/advisories/unreviewed/2022/04/GHSA-8j48-wxgf-pfpq/GHSA-8j48-wxgf-pfpq.json @@ -7,12 +7,8 @@ "CVE-2004-0866" ], "details": "Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8jv3-453f-rwfw/GHSA-8jv3-453f-rwfw.json b/advisories/unreviewed/2022/04/GHSA-8jv3-453f-rwfw/GHSA-8jv3-453f-rwfw.json index 3c031a030d4..840a4d0c30b 100644 --- a/advisories/unreviewed/2022/04/GHSA-8jv3-453f-rwfw/GHSA-8jv3-453f-rwfw.json +++ b/advisories/unreviewed/2022/04/GHSA-8jv3-453f-rwfw/GHSA-8jv3-453f-rwfw.json @@ -7,12 +7,8 @@ "CVE-2004-0620" ], "details": "Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8mg7-32mm-38xq/GHSA-8mg7-32mm-38xq.json b/advisories/unreviewed/2022/04/GHSA-8mg7-32mm-38xq/GHSA-8mg7-32mm-38xq.json index 6d58f0dc5cf..0de43af89e3 100644 --- a/advisories/unreviewed/2022/04/GHSA-8mg7-32mm-38xq/GHSA-8mg7-32mm-38xq.json +++ b/advisories/unreviewed/2022/04/GHSA-8mg7-32mm-38xq/GHSA-8mg7-32mm-38xq.json @@ -7,12 +7,8 @@ "CVE-2004-0668" ], "details": "Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as demonstrated using a large image attachment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8p34-xxjh-4hrg/GHSA-8p34-xxjh-4hrg.json b/advisories/unreviewed/2022/04/GHSA-8p34-xxjh-4hrg/GHSA-8p34-xxjh-4hrg.json index 319040d4406..a4da8126fa6 100644 --- a/advisories/unreviewed/2022/04/GHSA-8p34-xxjh-4hrg/GHSA-8p34-xxjh-4hrg.json +++ b/advisories/unreviewed/2022/04/GHSA-8p34-xxjh-4hrg/GHSA-8p34-xxjh-4hrg.json @@ -7,12 +7,8 @@ "CVE-2004-0837" ], "details": "MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8p78-6v29-xw89/GHSA-8p78-6v29-xw89.json b/advisories/unreviewed/2022/04/GHSA-8p78-6v29-xw89/GHSA-8p78-6v29-xw89.json index 66310682323..67f5c4eba8a 100644 --- a/advisories/unreviewed/2022/04/GHSA-8p78-6v29-xw89/GHSA-8p78-6v29-xw89.json +++ b/advisories/unreviewed/2022/04/GHSA-8p78-6v29-xw89/GHSA-8p78-6v29-xw89.json @@ -7,12 +7,8 @@ "CVE-2004-0768" ], "details": "libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8v38-vrv4-372w/GHSA-8v38-vrv4-372w.json b/advisories/unreviewed/2022/04/GHSA-8v38-vrv4-372w/GHSA-8v38-vrv4-372w.json index c8c6d4e6b0e..c68d59c65aa 100644 --- a/advisories/unreviewed/2022/04/GHSA-8v38-vrv4-372w/GHSA-8v38-vrv4-372w.json +++ b/advisories/unreviewed/2022/04/GHSA-8v38-vrv4-372w/GHSA-8v38-vrv4-372w.json @@ -7,12 +7,8 @@ "CVE-2004-0832" ], "details": "The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-92p7-84q6-6mj9/GHSA-92p7-84q6-6mj9.json b/advisories/unreviewed/2022/04/GHSA-92p7-84q6-6mj9/GHSA-92p7-84q6-6mj9.json index 6be08dd5a35..2b303ebab9b 100644 --- a/advisories/unreviewed/2022/04/GHSA-92p7-84q6-6mj9/GHSA-92p7-84q6-6mj9.json +++ b/advisories/unreviewed/2022/04/GHSA-92p7-84q6-6mj9/GHSA-92p7-84q6-6mj9.json @@ -7,12 +7,8 @@ "CVE-2004-0659" ], "details": "Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-95ff-4qr3-g2fv/GHSA-95ff-4qr3-g2fv.json b/advisories/unreviewed/2022/04/GHSA-95ff-4qr3-g2fv/GHSA-95ff-4qr3-g2fv.json index 39851e27450..54975b76c68 100644 --- a/advisories/unreviewed/2022/04/GHSA-95ff-4qr3-g2fv/GHSA-95ff-4qr3-g2fv.json +++ b/advisories/unreviewed/2022/04/GHSA-95ff-4qr3-g2fv/GHSA-95ff-4qr3-g2fv.json @@ -7,12 +7,8 @@ "CVE-2004-0712" ], "details": "The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 create a log file that contains the administrative username and password in cleartext, which could allow local users to gain privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-986j-hw45-768j/GHSA-986j-hw45-768j.json b/advisories/unreviewed/2022/04/GHSA-986j-hw45-768j/GHSA-986j-hw45-768j.json index 3a7c641a967..4d63837b355 100644 --- a/advisories/unreviewed/2022/04/GHSA-986j-hw45-768j/GHSA-986j-hw45-768j.json +++ b/advisories/unreviewed/2022/04/GHSA-986j-hw45-768j/GHSA-986j-hw45-768j.json @@ -7,12 +7,8 @@ "CVE-2004-0591" ], "details": "Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a \"message/delivery-status\" MIME Content-Type.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-98h2-xgjg-hjj2/GHSA-98h2-xgjg-hjj2.json b/advisories/unreviewed/2022/04/GHSA-98h2-xgjg-hjj2/GHSA-98h2-xgjg-hjj2.json index 77d19202904..0d23592238c 100644 --- a/advisories/unreviewed/2022/04/GHSA-98h2-xgjg-hjj2/GHSA-98h2-xgjg-hjj2.json +++ b/advisories/unreviewed/2022/04/GHSA-98h2-xgjg-hjj2/GHSA-98h2-xgjg-hjj2.json @@ -7,12 +7,8 @@ "CVE-2004-0780" ], "details": "Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-99p3-78jq-hvc7/GHSA-99p3-78jq-hvc7.json b/advisories/unreviewed/2022/04/GHSA-99p3-78jq-hvc7/GHSA-99p3-78jq-hvc7.json index 5ff676d9f75..229ead5101d 100644 --- a/advisories/unreviewed/2022/04/GHSA-99p3-78jq-hvc7/GHSA-99p3-78jq-hvc7.json +++ b/advisories/unreviewed/2022/04/GHSA-99p3-78jq-hvc7/GHSA-99p3-78jq-hvc7.json @@ -7,12 +7,8 @@ "CVE-2004-0612" ], "details": "The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not filter mobile code within an SSL encrypted session, which could allow remote attackers to bypass the mobile code filtering. NOTE: it has been disputed by the vendor that this behavior is required by the SSL specification.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9gjh-cfqr-c8q2/GHSA-9gjh-cfqr-c8q2.json b/advisories/unreviewed/2022/04/GHSA-9gjh-cfqr-c8q2/GHSA-9gjh-cfqr-c8q2.json index 280ca475058..1e2d8c45acc 100644 --- a/advisories/unreviewed/2022/04/GHSA-9gjh-cfqr-c8q2/GHSA-9gjh-cfqr-c8q2.json +++ b/advisories/unreviewed/2022/04/GHSA-9gjh-cfqr-c8q2/GHSA-9gjh-cfqr-c8q2.json @@ -7,12 +7,8 @@ "CVE-2004-0833" ], "details": "Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9pj7-4fqw-mqwq/GHSA-9pj7-4fqw-mqwq.json b/advisories/unreviewed/2022/04/GHSA-9pj7-4fqw-mqwq/GHSA-9pj7-4fqw-mqwq.json index ceca47edabb..272c338f55b 100644 --- a/advisories/unreviewed/2022/04/GHSA-9pj7-4fqw-mqwq/GHSA-9pj7-4fqw-mqwq.json +++ b/advisories/unreviewed/2022/04/GHSA-9pj7-4fqw-mqwq/GHSA-9pj7-4fqw-mqwq.json @@ -7,12 +7,8 @@ "CVE-2004-0651" ], "details": "Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote attackers to cause a denial of service (virtual machine hang).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9rqc-h87g-58h5/GHSA-9rqc-h87g-58h5.json b/advisories/unreviewed/2022/04/GHSA-9rqc-h87g-58h5/GHSA-9rqc-h87g-58h5.json index 2a0f1349fe5..71b7dcf5a8c 100644 --- a/advisories/unreviewed/2022/04/GHSA-9rqc-h87g-58h5/GHSA-9rqc-h87g-58h5.json +++ b/advisories/unreviewed/2022/04/GHSA-9rqc-h87g-58h5/GHSA-9rqc-h87g-58h5.json @@ -7,12 +7,8 @@ "CVE-2004-0671" ], "details": "Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying the id parameter in a viewMsgDetails.do request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9v82-w8v5-2v72/GHSA-9v82-w8v5-2v72.json b/advisories/unreviewed/2022/04/GHSA-9v82-w8v5-2v72/GHSA-9v82-w8v5-2v72.json index 6a372818091..ac3265a902c 100644 --- a/advisories/unreviewed/2022/04/GHSA-9v82-w8v5-2v72/GHSA-9v82-w8v5-2v72.json +++ b/advisories/unreviewed/2022/04/GHSA-9v82-w8v5-2v72/GHSA-9v82-w8v5-2v72.json @@ -7,12 +7,8 @@ "CVE-2004-0495" ], "details": "Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9vhh-79hg-xv8q/GHSA-9vhh-79hg-xv8q.json b/advisories/unreviewed/2022/04/GHSA-9vhh-79hg-xv8q/GHSA-9vhh-79hg-xv8q.json index 92cdaec367d..09d62319e07 100644 --- a/advisories/unreviewed/2022/04/GHSA-9vhh-79hg-xv8q/GHSA-9vhh-79hg-xv8q.json +++ b/advisories/unreviewed/2022/04/GHSA-9vhh-79hg-xv8q/GHSA-9vhh-79hg-xv8q.json @@ -7,12 +7,8 @@ "CVE-2004-0628" ], "details": "Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scramble string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9x4r-j47p-fgrx/GHSA-9x4r-j47p-fgrx.json b/advisories/unreviewed/2022/04/GHSA-9x4r-j47p-fgrx/GHSA-9x4r-j47p-fgrx.json index c55f8ed8910..e1730c6d9a3 100644 --- a/advisories/unreviewed/2022/04/GHSA-9x4r-j47p-fgrx/GHSA-9x4r-j47p-fgrx.json +++ b/advisories/unreviewed/2022/04/GHSA-9x4r-j47p-fgrx/GHSA-9x4r-j47p-fgrx.json @@ -7,12 +7,8 @@ "CVE-2004-0484" ], "details": "mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose \"float: left\" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c2xh-jwfq-qgr6/GHSA-c2xh-jwfq-qgr6.json b/advisories/unreviewed/2022/04/GHSA-c2xh-jwfq-qgr6/GHSA-c2xh-jwfq-qgr6.json index 89df7457a92..7688aa0306c 100644 --- a/advisories/unreviewed/2022/04/GHSA-c2xh-jwfq-qgr6/GHSA-c2xh-jwfq-qgr6.json +++ b/advisories/unreviewed/2022/04/GHSA-c2xh-jwfq-qgr6/GHSA-c2xh-jwfq-qgr6.json @@ -7,12 +7,8 @@ "CVE-2004-0641" ], "details": "Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c4rg-jcg2-4w8c/GHSA-c4rg-jcg2-4w8c.json b/advisories/unreviewed/2022/04/GHSA-c4rg-jcg2-4w8c/GHSA-c4rg-jcg2-4w8c.json index ab004046e0c..f061675dbae 100644 --- a/advisories/unreviewed/2022/04/GHSA-c4rg-jcg2-4w8c/GHSA-c4rg-jcg2-4w8c.json +++ b/advisories/unreviewed/2022/04/GHSA-c4rg-jcg2-4w8c/GHSA-c4rg-jcg2-4w8c.json @@ -7,12 +7,8 @@ "CVE-2004-0701" ], "details": "Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c4xq-7jc7-xfpp/GHSA-c4xq-7jc7-xfpp.json b/advisories/unreviewed/2022/04/GHSA-c4xq-7jc7-xfpp/GHSA-c4xq-7jc7-xfpp.json index cc78b9e0a87..99bd0a05266 100644 --- a/advisories/unreviewed/2022/04/GHSA-c4xq-7jc7-xfpp/GHSA-c4xq-7jc7-xfpp.json +++ b/advisories/unreviewed/2022/04/GHSA-c4xq-7jc7-xfpp/GHSA-c4xq-7jc7-xfpp.json @@ -7,12 +7,8 @@ "CVE-2004-0871" ], "details": "Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka \"Cross Security Boundary Cookie Injection.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c56g-5w2w-p8r7/GHSA-c56g-5w2w-p8r7.json b/advisories/unreviewed/2022/04/GHSA-c56g-5w2w-p8r7/GHSA-c56g-5w2w-p8r7.json index 7f004788d36..6e2cdfef8ef 100644 --- a/advisories/unreviewed/2022/04/GHSA-c56g-5w2w-p8r7/GHSA-c56g-5w2w-p8r7.json +++ b/advisories/unreviewed/2022/04/GHSA-c56g-5w2w-p8r7/GHSA-c56g-5w2w-p8r7.json @@ -7,12 +7,8 @@ "CVE-2004-0584" ], "details": "Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a \"security fix,\" does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c593-2gr9-g543/GHSA-c593-2gr9-g543.json b/advisories/unreviewed/2022/04/GHSA-c593-2gr9-g543/GHSA-c593-2gr9-g543.json index 0a9b307a747..cceee01fcf6 100644 --- a/advisories/unreviewed/2022/04/GHSA-c593-2gr9-g543/GHSA-c593-2gr9-g543.json +++ b/advisories/unreviewed/2022/04/GHSA-c593-2gr9-g543/GHSA-c593-2gr9-g543.json @@ -7,12 +7,8 @@ "CVE-2004-0737" ], "details": "Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (10) mod2, or (11) mod3 parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c72r-p5jr-pjvr/GHSA-c72r-p5jr-pjvr.json b/advisories/unreviewed/2022/04/GHSA-c72r-p5jr-pjvr/GHSA-c72r-p5jr-pjvr.json index 90c4e37d3fe..003828ac9da 100644 --- a/advisories/unreviewed/2022/04/GHSA-c72r-p5jr-pjvr/GHSA-c72r-p5jr-pjvr.json +++ b/advisories/unreviewed/2022/04/GHSA-c72r-p5jr-pjvr/GHSA-c72r-p5jr-pjvr.json @@ -7,12 +7,8 @@ "CVE-2004-0631" ], "details": "Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the uudecode command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ccf6-wjg8-65fx/GHSA-ccf6-wjg8-65fx.json b/advisories/unreviewed/2022/04/GHSA-ccf6-wjg8-65fx/GHSA-ccf6-wjg8-65fx.json index 6a633dd440b..2534e6f62de 100644 --- a/advisories/unreviewed/2022/04/GHSA-ccf6-wjg8-65fx/GHSA-ccf6-wjg8-65fx.json +++ b/advisories/unreviewed/2022/04/GHSA-ccf6-wjg8-65fx/GHSA-ccf6-wjg8-65fx.json @@ -7,12 +7,8 @@ "CVE-2004-0542" ], "details": "PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the \"%\", \"|\", or \">\" characters to the escapeshellcmd function, or (2) the \"%\" character to the escapeshellarg function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cf4p-4gq4-6v2f/GHSA-cf4p-4gq4-6v2f.json b/advisories/unreviewed/2022/04/GHSA-cf4p-4gq4-6v2f/GHSA-cf4p-4gq4-6v2f.json index 878c29f144a..d6f42f67e39 100644 --- a/advisories/unreviewed/2022/04/GHSA-cf4p-4gq4-6v2f/GHSA-cf4p-4gq4-6v2f.json +++ b/advisories/unreviewed/2022/04/GHSA-cf4p-4gq4-6v2f/GHSA-cf4p-4gq4-6v2f.json @@ -7,12 +7,8 @@ "CVE-2004-0729" ], "details": "PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-chw9-573p-28p6/GHSA-chw9-573p-28p6.json b/advisories/unreviewed/2022/04/GHSA-chw9-573p-28p6/GHSA-chw9-573p-28p6.json index f5d6e6ed95f..9b34b3f2cd5 100644 --- a/advisories/unreviewed/2022/04/GHSA-chw9-573p-28p6/GHSA-chw9-573p-28p6.json +++ b/advisories/unreviewed/2022/04/GHSA-chw9-573p-28p6/GHSA-chw9-573p-28p6.json @@ -7,12 +7,8 @@ "CVE-2004-0579" ], "details": "Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cm42-569j-qx8w/GHSA-cm42-569j-qx8w.json b/advisories/unreviewed/2022/04/GHSA-cm42-569j-qx8w/GHSA-cm42-569j-qx8w.json index 613e8e05411..74005433c34 100644 --- a/advisories/unreviewed/2022/04/GHSA-cm42-569j-qx8w/GHSA-cm42-569j-qx8w.json +++ b/advisories/unreviewed/2022/04/GHSA-cm42-569j-qx8w/GHSA-cm42-569j-qx8w.json @@ -7,12 +7,8 @@ "CVE-2004-0728" ], "details": "The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cpr4-jj9p-gwfc/GHSA-cpr4-jj9p-gwfc.json b/advisories/unreviewed/2022/04/GHSA-cpr4-jj9p-gwfc/GHSA-cpr4-jj9p-gwfc.json index 4caeb111639..b0e0fe65d4b 100644 --- a/advisories/unreviewed/2022/04/GHSA-cpr4-jj9p-gwfc/GHSA-cpr4-jj9p-gwfc.json +++ b/advisories/unreviewed/2022/04/GHSA-cpr4-jj9p-gwfc/GHSA-cpr4-jj9p-gwfc.json @@ -7,12 +7,8 @@ "CVE-2004-0500" ], "details": "Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cq5p-fgmw-rvxv/GHSA-cq5p-fgmw-rvxv.json b/advisories/unreviewed/2022/04/GHSA-cq5p-fgmw-rvxv/GHSA-cq5p-fgmw-rvxv.json index 4619212cc66..9b37771128a 100644 --- a/advisories/unreviewed/2022/04/GHSA-cq5p-fgmw-rvxv/GHSA-cq5p-fgmw-rvxv.json +++ b/advisories/unreviewed/2022/04/GHSA-cq5p-fgmw-rvxv/GHSA-cq5p-fgmw-rvxv.json @@ -7,12 +7,8 @@ "CVE-2004-0551" ], "details": "Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka \"TCP-ACK DoS attack.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cqhm-pgxc-87cv/GHSA-cqhm-pgxc-87cv.json b/advisories/unreviewed/2022/04/GHSA-cqhm-pgxc-87cv/GHSA-cqhm-pgxc-87cv.json index bef1f9441a7..3d7c39ec3d5 100644 --- a/advisories/unreviewed/2022/04/GHSA-cqhm-pgxc-87cv/GHSA-cqhm-pgxc-87cv.json +++ b/advisories/unreviewed/2022/04/GHSA-cqhm-pgxc-87cv/GHSA-cqhm-pgxc-87cv.json @@ -7,12 +7,8 @@ "CVE-2004-0690" ], "details": "The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f36j-2388-wq8x/GHSA-f36j-2388-wq8x.json b/advisories/unreviewed/2022/04/GHSA-f36j-2388-wq8x/GHSA-f36j-2388-wq8x.json index 0141b877fa5..86e3004bce2 100644 --- a/advisories/unreviewed/2022/04/GHSA-f36j-2388-wq8x/GHSA-f36j-2388-wq8x.json +++ b/advisories/unreviewed/2022/04/GHSA-f36j-2388-wq8x/GHSA-f36j-2388-wq8x.json @@ -7,12 +7,8 @@ "CVE-2004-0580" ], "details": "DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f6c5-3fww-hpc6/GHSA-f6c5-3fww-hpc6.json b/advisories/unreviewed/2022/04/GHSA-f6c5-3fww-hpc6/GHSA-f6c5-3fww-hpc6.json index 63a56385189..e50a0a88332 100644 --- a/advisories/unreviewed/2022/04/GHSA-f6c5-3fww-hpc6/GHSA-f6c5-3fww-hpc6.json +++ b/advisories/unreviewed/2022/04/GHSA-f6c5-3fww-hpc6/GHSA-f6c5-3fww-hpc6.json @@ -7,12 +7,8 @@ "CVE-2004-0581" ], "details": "ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f7fx-ph3w-4868/GHSA-f7fx-ph3w-4868.json b/advisories/unreviewed/2022/04/GHSA-f7fx-ph3w-4868/GHSA-f7fx-ph3w-4868.json index 743b92263ca..961303e9719 100644 --- a/advisories/unreviewed/2022/04/GHSA-f7fx-ph3w-4868/GHSA-f7fx-ph3w-4868.json +++ b/advisories/unreviewed/2022/04/GHSA-f7fx-ph3w-4868/GHSA-f7fx-ph3w-4868.json @@ -7,12 +7,8 @@ "CVE-2004-0633" ], "details": "The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f97q-pghf-w265/GHSA-f97q-pghf-w265.json b/advisories/unreviewed/2022/04/GHSA-f97q-pghf-w265/GHSA-f97q-pghf-w265.json index c3f4a4b45e9..7809a6b9508 100644 --- a/advisories/unreviewed/2022/04/GHSA-f97q-pghf-w265/GHSA-f97q-pghf-w265.json +++ b/advisories/unreviewed/2022/04/GHSA-f97q-pghf-w265/GHSA-f97q-pghf-w265.json @@ -7,12 +7,8 @@ "CVE-2004-0735" ], "details": "Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such as (1) the getinfo query, (2) the connect packet, and other unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f9g3-rf9g-hv5f/GHSA-f9g3-rf9g-hv5f.json b/advisories/unreviewed/2022/04/GHSA-f9g3-rf9g-hv5f/GHSA-f9g3-rf9g-hv5f.json index 0d1eafb0404..271b208815d 100644 --- a/advisories/unreviewed/2022/04/GHSA-f9g3-rf9g-hv5f/GHSA-f9g3-rf9g-hv5f.json +++ b/advisories/unreviewed/2022/04/GHSA-f9g3-rf9g-hv5f/GHSA-f9g3-rf9g-hv5f.json @@ -7,12 +7,8 @@ "CVE-2004-0665" ], "details": "csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fcqf-rh65-9268/GHSA-fcqf-rh65-9268.json b/advisories/unreviewed/2022/04/GHSA-fcqf-rh65-9268/GHSA-fcqf-rh65-9268.json index 45068405440..91c66c622cf 100644 --- a/advisories/unreviewed/2022/04/GHSA-fcqf-rh65-9268/GHSA-fcqf-rh65-9268.json +++ b/advisories/unreviewed/2022/04/GHSA-fcqf-rh65-9268/GHSA-fcqf-rh65-9268.json @@ -7,12 +7,8 @@ "CVE-2004-0716" ], "details": "Buffer overflow in the DCE daemon (DCED) for the DCE endpoint mapper (epmap) on HP-UX 11 allows remote attackers to execute arbitrary code via a request with a small fragment length and a large amount of data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fcxf-f24h-26mp/GHSA-fcxf-f24h-26mp.json b/advisories/unreviewed/2022/04/GHSA-fcxf-f24h-26mp/GHSA-fcxf-f24h-26mp.json index b4206ec2212..43c549d6549 100644 --- a/advisories/unreviewed/2022/04/GHSA-fcxf-f24h-26mp/GHSA-fcxf-f24h-26mp.json +++ b/advisories/unreviewed/2022/04/GHSA-fcxf-f24h-26mp/GHSA-fcxf-f24h-26mp.json @@ -7,12 +7,8 @@ "CVE-2004-0740" ], "details": "The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or hang) via an HTTP header with a long Host field, possibly triggering a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-ffrj-w536-5xrc/GHSA-ffrj-w536-5xrc.json b/advisories/unreviewed/2022/04/GHSA-ffrj-w536-5xrc/GHSA-ffrj-w536-5xrc.json index 84435765788..114084eb916 100644 --- a/advisories/unreviewed/2022/04/GHSA-ffrj-w536-5xrc/GHSA-ffrj-w536-5xrc.json +++ b/advisories/unreviewed/2022/04/GHSA-ffrj-w536-5xrc/GHSA-ffrj-w536-5xrc.json @@ -7,12 +7,8 @@ "CVE-2004-0809" ], "details": "The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fgjq-p2q2-66cx/GHSA-fgjq-p2q2-66cx.json b/advisories/unreviewed/2022/04/GHSA-fgjq-p2q2-66cx/GHSA-fgjq-p2q2-66cx.json index 7a3ba38f56a..deaaba67edd 100644 --- a/advisories/unreviewed/2022/04/GHSA-fgjq-p2q2-66cx/GHSA-fgjq-p2q2-66cx.json +++ b/advisories/unreviewed/2022/04/GHSA-fgjq-p2q2-66cx/GHSA-fgjq-p2q2-66cx.json @@ -7,12 +7,8 @@ "CVE-2004-0841" ], "details": "Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka \"HijackClick 3\" and the \"Script in Image Tag File Download Vulnerability.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fhrm-2hv9-qhh7/GHSA-fhrm-2hv9-qhh7.json b/advisories/unreviewed/2022/04/GHSA-fhrm-2hv9-qhh7/GHSA-fhrm-2hv9-qhh7.json index 9638bc00755..5b86a69fcc8 100644 --- a/advisories/unreviewed/2022/04/GHSA-fhrm-2hv9-qhh7/GHSA-fhrm-2hv9-qhh7.json +++ b/advisories/unreviewed/2022/04/GHSA-fhrm-2hv9-qhh7/GHSA-fhrm-2hv9-qhh7.json @@ -7,12 +7,8 @@ "CVE-2004-0640" ], "details": "Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fpjr-4p92-59hh/GHSA-fpjr-4p92-59hh.json b/advisories/unreviewed/2022/04/GHSA-fpjr-4p92-59hh/GHSA-fpjr-4p92-59hh.json index a210a6cca27..5d2ff10e6ce 100644 --- a/advisories/unreviewed/2022/04/GHSA-fpjr-4p92-59hh/GHSA-fpjr-4p92-59hh.json +++ b/advisories/unreviewed/2022/04/GHSA-fpjr-4p92-59hh/GHSA-fpjr-4p92-59hh.json @@ -7,12 +7,8 @@ "CVE-2004-0726" ], "details": "The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-frc6-442c-qxhp/GHSA-frc6-442c-qxhp.json b/advisories/unreviewed/2022/04/GHSA-frc6-442c-qxhp/GHSA-frc6-442c-qxhp.json index b0851428620..1e454d3431c 100644 --- a/advisories/unreviewed/2022/04/GHSA-frc6-442c-qxhp/GHSA-frc6-442c-qxhp.json +++ b/advisories/unreviewed/2022/04/GHSA-frc6-442c-qxhp/GHSA-frc6-442c-qxhp.json @@ -7,12 +7,8 @@ "CVE-2004-0852" ], "details": "Buffer overflow in htget 0.93 allows remote attackers to execute arbitrary code via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-frx4-6m64-vh55/GHSA-frx4-6m64-vh55.json b/advisories/unreviewed/2022/04/GHSA-frx4-6m64-vh55/GHSA-frx4-6m64-vh55.json index 5c7d2f79750..48aba378422 100644 --- a/advisories/unreviewed/2022/04/GHSA-frx4-6m64-vh55/GHSA-frx4-6m64-vh55.json +++ b/advisories/unreviewed/2022/04/GHSA-frx4-6m64-vh55/GHSA-frx4-6m64-vh55.json @@ -7,12 +7,8 @@ "CVE-2004-0887" ], "details": "SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fwjf-492q-44rh/GHSA-fwjf-492q-44rh.json b/advisories/unreviewed/2022/04/GHSA-fwjf-492q-44rh/GHSA-fwjf-492q-44rh.json index 46edbadc3f7..99363257524 100644 --- a/advisories/unreviewed/2022/04/GHSA-fwjf-492q-44rh/GHSA-fwjf-492q-44rh.json +++ b/advisories/unreviewed/2022/04/GHSA-fwjf-492q-44rh/GHSA-fwjf-492q-44rh.json @@ -7,12 +7,8 @@ "CVE-2004-0635" ], "details": "The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g33f-v4ch-cw4g/GHSA-g33f-v4ch-cw4g.json b/advisories/unreviewed/2022/04/GHSA-g33f-v4ch-cw4g/GHSA-g33f-v4ch-cw4g.json index e5f3d935655..e22ca8ed6e8 100644 --- a/advisories/unreviewed/2022/04/GHSA-g33f-v4ch-cw4g/GHSA-g33f-v4ch-cw4g.json +++ b/advisories/unreviewed/2022/04/GHSA-g33f-v4ch-cw4g/GHSA-g33f-v4ch-cw4g.json @@ -7,12 +7,8 @@ "CVE-2004-0565" ], "details": "Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g4pv-j73m-58hw/GHSA-g4pv-j73m-58hw.json b/advisories/unreviewed/2022/04/GHSA-g4pv-j73m-58hw/GHSA-g4pv-j73m-58hw.json index eb3cd8d2b35..beb04edcdbf 100644 --- a/advisories/unreviewed/2022/04/GHSA-g4pv-j73m-58hw/GHSA-g4pv-j73m-58hw.json +++ b/advisories/unreviewed/2022/04/GHSA-g4pv-j73m-58hw/GHSA-g4pv-j73m-58hw.json @@ -7,12 +7,8 @@ "CVE-2004-0539" ], "details": "The \"Show in Finder\" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g4wg-mc7p-pq74/GHSA-g4wg-mc7p-pq74.json b/advisories/unreviewed/2022/04/GHSA-g4wg-mc7p-pq74/GHSA-g4wg-mc7p-pq74.json index bd35ef5f8f4..45030d429e9 100644 --- a/advisories/unreviewed/2022/04/GHSA-g4wg-mc7p-pq74/GHSA-g4wg-mc7p-pq74.json +++ b/advisories/unreviewed/2022/04/GHSA-g4wg-mc7p-pq74/GHSA-g4wg-mc7p-pq74.json @@ -7,12 +7,8 @@ "CVE-2004-0775" ], "details": "Buffer overflow in WIDCOMM Bluetooth Connectivity Software, as used in products such as BTStackServer 1.3.2.7 and 1.4.2.10, Windows XP and Windows 98 with MSI Bluetooth Dongles, and HP IPAQ 5450 running WinCE 3.0, allows remote attackers to execute arbitrary code via certain service requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g4xq-83hp-jc9q/GHSA-g4xq-83hp-jc9q.json b/advisories/unreviewed/2022/04/GHSA-g4xq-83hp-jc9q/GHSA-g4xq-83hp-jc9q.json index b3d16f3cf88..557e72a78fa 100644 --- a/advisories/unreviewed/2022/04/GHSA-g4xq-83hp-jc9q/GHSA-g4xq-83hp-jc9q.json +++ b/advisories/unreviewed/2022/04/GHSA-g4xq-83hp-jc9q/GHSA-g4xq-83hp-jc9q.json @@ -7,12 +7,8 @@ "CVE-2004-0842" ], "details": "Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from \"memory corruption\") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the \"