diff --git a/advisories/github-reviewed/2020/09/GHSA-255r-pghp-r5wh/GHSA-255r-pghp-r5wh.json b/advisories/github-reviewed/2020/09/GHSA-255r-pghp-r5wh/GHSA-255r-pghp-r5wh.json index 24693f75b25..371e4486679 100644 --- a/advisories/github-reviewed/2020/09/GHSA-255r-pghp-r5wh/GHSA-255r-pghp-r5wh.json +++ b/advisories/github-reviewed/2020/09/GHSA-255r-pghp-r5wh/GHSA-255r-pghp-r5wh.json @@ -3,9 +3,7 @@ "id": "GHSA-255r-pghp-r5wh", "modified": "2021-10-01T21:02:17Z", "published": "2020-09-03T17:05:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in hdeky", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-28f4-mjfq-qrvf/GHSA-28f4-mjfq-qrvf.json b/advisories/github-reviewed/2020/09/GHSA-28f4-mjfq-qrvf/GHSA-28f4-mjfq-qrvf.json index 5a3f76e3b10..5caf129f526 100644 --- a/advisories/github-reviewed/2020/09/GHSA-28f4-mjfq-qrvf/GHSA-28f4-mjfq-qrvf.json +++ b/advisories/github-reviewed/2020/09/GHSA-28f4-mjfq-qrvf/GHSA-28f4-mjfq-qrvf.json @@ -3,9 +3,7 @@ "id": "GHSA-28f4-mjfq-qrvf", "modified": "2021-09-29T21:26:03Z", "published": "2020-09-03T22:18:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffes-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-29fh-xcjr-p7rx/GHSA-29fh-xcjr-p7rx.json b/advisories/github-reviewed/2020/09/GHSA-29fh-xcjr-p7rx/GHSA-29fh-xcjr-p7rx.json index 9c868bfb173..acac42a87b1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-29fh-xcjr-p7rx/GHSA-29fh-xcjr-p7rx.json +++ b/advisories/github-reviewed/2020/09/GHSA-29fh-xcjr-p7rx/GHSA-29fh-xcjr-p7rx.json @@ -3,9 +3,7 @@ "id": "GHSA-29fh-xcjr-p7rx", "modified": "2021-10-04T19:10:02Z", "published": "2020-09-03T17:02:22Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in web3-eht", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-2fwq-wx47-hm6x/GHSA-2fwq-wx47-hm6x.json b/advisories/github-reviewed/2020/09/GHSA-2fwq-wx47-hm6x/GHSA-2fwq-wx47-hm6x.json index c5ba2a63850..66e86da7b22 100644 --- a/advisories/github-reviewed/2020/09/GHSA-2fwq-wx47-hm6x/GHSA-2fwq-wx47-hm6x.json +++ b/advisories/github-reviewed/2020/09/GHSA-2fwq-wx47-hm6x/GHSA-2fwq-wx47-hm6x.json @@ -3,9 +3,7 @@ "id": "GHSA-2fwq-wx47-hm6x", "modified": "2021-10-01T20:30:20Z", "published": "2020-09-04T15:31:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bcion", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-2jm5-2cqf-6vw9/GHSA-2jm5-2cqf-6vw9.json b/advisories/github-reviewed/2020/09/GHSA-2jm5-2cqf-6vw9/GHSA-2jm5-2cqf-6vw9.json index bfdf4e79332..edbc5c0dc0e 100644 --- a/advisories/github-reviewed/2020/09/GHSA-2jm5-2cqf-6vw9/GHSA-2jm5-2cqf-6vw9.json +++ b/advisories/github-reviewed/2020/09/GHSA-2jm5-2cqf-6vw9/GHSA-2jm5-2cqf-6vw9.json @@ -3,9 +3,7 @@ "id": "GHSA-2jm5-2cqf-6vw9", "modified": "2021-10-01T20:29:19Z", "published": "2020-09-04T15:30:32Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in baes-x", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-2mj8-pj3j-h362/GHSA-2mj8-pj3j-h362.json b/advisories/github-reviewed/2020/09/GHSA-2mj8-pj3j-h362/GHSA-2mj8-pj3j-h362.json index ebe8d636c17..364683204a8 100644 --- a/advisories/github-reviewed/2020/09/GHSA-2mj8-pj3j-h362/GHSA-2mj8-pj3j-h362.json +++ b/advisories/github-reviewed/2020/09/GHSA-2mj8-pj3j-h362/GHSA-2mj8-pj3j-h362.json @@ -3,14 +3,10 @@ "id": "GHSA-2mj8-pj3j-h362", "modified": "2020-08-31T18:59:12Z", "published": "2020-09-04T17:17:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "Symlink reference outside of node_modules in bin-links", "details": "Versions of `bin-links` prior to 1.1.5 are vulnerable to a Symlink reference outside of node_modules. It is possible to create symlinks to files outside of the`node_modules` folder through the `bin` field. This may allow attackers to access unauthorized files.\n\n\n## Recommendation\n\nUpgrade to version 1.1.5 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:59:12Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-2mxc-m4c3-wqhq/GHSA-2mxc-m4c3-wqhq.json b/advisories/github-reviewed/2020/09/GHSA-2mxc-m4c3-wqhq/GHSA-2mxc-m4c3-wqhq.json index 9d3054930fe..88a4ecbde5f 100644 --- a/advisories/github-reviewed/2020/09/GHSA-2mxc-m4c3-wqhq/GHSA-2mxc-m4c3-wqhq.json +++ b/advisories/github-reviewed/2020/09/GHSA-2mxc-m4c3-wqhq/GHSA-2mxc-m4c3-wqhq.json @@ -3,9 +3,7 @@ "id": "GHSA-2mxc-m4c3-wqhq", "modified": "2021-09-30T16:18:32Z", "published": "2020-09-03T22:50:46Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in ruffer-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-2w8q-69fh-9gq6/GHSA-2w8q-69fh-9gq6.json b/advisories/github-reviewed/2020/09/GHSA-2w8q-69fh-9gq6/GHSA-2w8q-69fh-9gq6.json index 104817c735f..92655336e1f 100644 --- a/advisories/github-reviewed/2020/09/GHSA-2w8q-69fh-9gq6/GHSA-2w8q-69fh-9gq6.json +++ b/advisories/github-reviewed/2020/09/GHSA-2w8q-69fh-9gq6/GHSA-2w8q-69fh-9gq6.json @@ -3,9 +3,7 @@ "id": "GHSA-2w8q-69fh-9gq6", "modified": "2021-09-29T21:27:54Z", "published": "2020-09-03T22:25:09Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bufger-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-36r8-9qq7-mh43/GHSA-36r8-9qq7-mh43.json b/advisories/github-reviewed/2020/09/GHSA-36r8-9qq7-mh43/GHSA-36r8-9qq7-mh43.json index ab76dbeb08e..018901f198d 100644 --- a/advisories/github-reviewed/2020/09/GHSA-36r8-9qq7-mh43/GHSA-36r8-9qq7-mh43.json +++ b/advisories/github-reviewed/2020/09/GHSA-36r8-9qq7-mh43/GHSA-36r8-9qq7-mh43.json @@ -3,9 +3,7 @@ "id": "GHSA-36r8-9qq7-mh43", "modified": "2021-10-04T19:09:44Z", "published": "2020-09-03T17:02:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in we3b", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-37vc-gwvp-6cgv/GHSA-37vc-gwvp-6cgv.json b/advisories/github-reviewed/2020/09/GHSA-37vc-gwvp-6cgv/GHSA-37vc-gwvp-6cgv.json index b1efb69e3d7..30435979d3e 100644 --- a/advisories/github-reviewed/2020/09/GHSA-37vc-gwvp-6cgv/GHSA-37vc-gwvp-6cgv.json +++ b/advisories/github-reviewed/2020/09/GHSA-37vc-gwvp-6cgv/GHSA-37vc-gwvp-6cgv.json @@ -3,9 +3,7 @@ "id": "GHSA-37vc-gwvp-6cgv", "modified": "2021-10-01T20:39:59Z", "published": "2020-09-04T15:42:49Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcoijns-lib", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-3cpj-mj3q-82wr/GHSA-3cpj-mj3q-82wr.json b/advisories/github-reviewed/2020/09/GHSA-3cpj-mj3q-82wr/GHSA-3cpj-mj3q-82wr.json index 65399cdce53..3a242dd6b5a 100644 --- a/advisories/github-reviewed/2020/09/GHSA-3cpj-mj3q-82wr/GHSA-3cpj-mj3q-82wr.json +++ b/advisories/github-reviewed/2020/09/GHSA-3cpj-mj3q-82wr/GHSA-3cpj-mj3q-82wr.json @@ -3,9 +3,7 @@ "id": "GHSA-3cpj-mj3q-82wr", "modified": "2021-10-01T20:49:46Z", "published": "2020-09-04T16:49:43Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bs58chek", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-3gpc-w23c-w59w/GHSA-3gpc-w23c-w59w.json b/advisories/github-reviewed/2020/09/GHSA-3gpc-w23c-w59w/GHSA-3gpc-w23c-w59w.json index 989bc80f7a0..cae1047794c 100644 --- a/advisories/github-reviewed/2020/09/GHSA-3gpc-w23c-w59w/GHSA-3gpc-w23c-w59w.json +++ b/advisories/github-reviewed/2020/09/GHSA-3gpc-w23c-w59w/GHSA-3gpc-w23c-w59w.json @@ -3,14 +3,10 @@ "id": "GHSA-3gpc-w23c-w59w", "modified": "2021-04-21T19:45:42Z", "published": "2020-09-04T15:02:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "Sandbox Breakout / Arbitrary Code Execution in pitboss-ng", "details": "All versions of `pitboss-ng` are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through `this.constructor.constructor` . This may allow attackers to execute arbitrary code in the system. Evaluating the payload `this.constructor.constructor('return process.env')()` prints the contents of `process.env`.\n \n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:55:00Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-3h99-v4qw-p2h5/GHSA-3h99-v4qw-p2h5.json b/advisories/github-reviewed/2020/09/GHSA-3h99-v4qw-p2h5/GHSA-3h99-v4qw-p2h5.json index 280233c8ca9..25c97b86162 100644 --- a/advisories/github-reviewed/2020/09/GHSA-3h99-v4qw-p2h5/GHSA-3h99-v4qw-p2h5.json +++ b/advisories/github-reviewed/2020/09/GHSA-3h99-v4qw-p2h5/GHSA-3h99-v4qw-p2h5.json @@ -3,9 +3,7 @@ "id": "GHSA-3h99-v4qw-p2h5", "modified": "2021-10-01T20:57:40Z", "published": "2020-09-03T19:41:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in coinpayment", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-3h9m-9g3g-5wqx/GHSA-3h9m-9g3g-5wqx.json b/advisories/github-reviewed/2020/09/GHSA-3h9m-9g3g-5wqx/GHSA-3h9m-9g3g-5wqx.json index 9da737f5cb2..28a3a9d10b9 100644 --- a/advisories/github-reviewed/2020/09/GHSA-3h9m-9g3g-5wqx/GHSA-3h9m-9g3g-5wqx.json +++ b/advisories/github-reviewed/2020/09/GHSA-3h9m-9g3g-5wqx/GHSA-3h9m-9g3g-5wqx.json @@ -3,9 +3,7 @@ "id": "GHSA-3h9m-9g3g-5wqx", "modified": "2021-09-29T21:13:02Z", "published": "2020-09-03T22:13:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-xov", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-3mhm-jvqj-fvhg/GHSA-3mhm-jvqj-fvhg.json b/advisories/github-reviewed/2020/09/GHSA-3mhm-jvqj-fvhg/GHSA-3mhm-jvqj-fvhg.json index 80cae607298..413b5a3420e 100644 --- a/advisories/github-reviewed/2020/09/GHSA-3mhm-jvqj-fvhg/GHSA-3mhm-jvqj-fvhg.json +++ b/advisories/github-reviewed/2020/09/GHSA-3mhm-jvqj-fvhg/GHSA-3mhm-jvqj-fvhg.json @@ -3,9 +3,7 @@ "id": "GHSA-3mhm-jvqj-fvhg", "modified": "2021-09-30T17:14:42Z", "published": "2020-09-03T23:09:37Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-sia3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-435c-qcpm-wjw5/GHSA-435c-qcpm-wjw5.json b/advisories/github-reviewed/2020/09/GHSA-435c-qcpm-wjw5/GHSA-435c-qcpm-wjw5.json index 7c19db24dce..e24ab6169a0 100644 --- a/advisories/github-reviewed/2020/09/GHSA-435c-qcpm-wjw5/GHSA-435c-qcpm-wjw5.json +++ b/advisories/github-reviewed/2020/09/GHSA-435c-qcpm-wjw5/GHSA-435c-qcpm-wjw5.json @@ -3,9 +3,7 @@ "id": "GHSA-435c-qcpm-wjw5", "modified": "2021-10-01T21:02:01Z", "published": "2020-09-03T17:05:43Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in fs-extar", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-4363-x42f-xph6/GHSA-4363-x42f-xph6.json b/advisories/github-reviewed/2020/09/GHSA-4363-x42f-xph6/GHSA-4363-x42f-xph6.json index cf14fd8c9d2..2897b241fc8 100644 --- a/advisories/github-reviewed/2020/09/GHSA-4363-x42f-xph6/GHSA-4363-x42f-xph6.json +++ b/advisories/github-reviewed/2020/09/GHSA-4363-x42f-xph6/GHSA-4363-x42f-xph6.json @@ -3,9 +3,7 @@ "id": "GHSA-4363-x42f-xph6", "modified": "2021-10-01T21:03:00Z", "published": "2020-09-03T17:05:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in hw-trnasport-u2f", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-49c6-3wr4-8jr4/GHSA-49c6-3wr4-8jr4.json b/advisories/github-reviewed/2020/09/GHSA-49c6-3wr4-8jr4/GHSA-49c6-3wr4-8jr4.json index 3b3d2ea989f..c74bbb49299 100644 --- a/advisories/github-reviewed/2020/09/GHSA-49c6-3wr4-8jr4/GHSA-49c6-3wr4-8jr4.json +++ b/advisories/github-reviewed/2020/09/GHSA-49c6-3wr4-8jr4/GHSA-49c6-3wr4-8jr4.json @@ -3,9 +3,7 @@ "id": "GHSA-49c6-3wr4-8jr4", "modified": "2021-10-01T20:07:48Z", "published": "2020-09-04T15:05:26Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in malicious-npm-package", "details": "All versions of `malicious-npm-package` contain malicious code. The malware targets Windows systems. It runs a powershell command that downloads an executable file from a remote server and runs it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-4fqg-89cc-5pv5/GHSA-4fqg-89cc-5pv5.json b/advisories/github-reviewed/2020/09/GHSA-4fqg-89cc-5pv5/GHSA-4fqg-89cc-5pv5.json index ab1843f3124..97a1432137b 100644 --- a/advisories/github-reviewed/2020/09/GHSA-4fqg-89cc-5pv5/GHSA-4fqg-89cc-5pv5.json +++ b/advisories/github-reviewed/2020/09/GHSA-4fqg-89cc-5pv5/GHSA-4fqg-89cc-5pv5.json @@ -3,9 +3,7 @@ "id": "GHSA-4fqg-89cc-5pv5", "modified": "2021-10-01T17:21:38Z", "published": "2020-09-04T14:58:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in sj-labc", "details": "All versions of `sj-labc` contain malicious code. The package downloads and runs a script that opens a reverse shell in the system.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-4hfc-fv33-ph9p/GHSA-4hfc-fv33-ph9p.json b/advisories/github-reviewed/2020/09/GHSA-4hfc-fv33-ph9p/GHSA-4hfc-fv33-ph9p.json index ae1c2ef2f38..1ccd83f4e55 100644 --- a/advisories/github-reviewed/2020/09/GHSA-4hfc-fv33-ph9p/GHSA-4hfc-fv33-ph9p.json +++ b/advisories/github-reviewed/2020/09/GHSA-4hfc-fv33-ph9p/GHSA-4hfc-fv33-ph9p.json @@ -3,9 +3,7 @@ "id": "GHSA-4hfc-fv33-ph9p", "modified": "2021-10-01T16:15:37Z", "published": "2020-09-03T23:26:33Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in sj-tw-abc", "details": "All versions of `sj-tw-abc` contain malicious code. The package downloads and runs a script that opens a reverse shell in the system.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-4hq8-v42x-9wx3/GHSA-4hq8-v42x-9wx3.json b/advisories/github-reviewed/2020/09/GHSA-4hq8-v42x-9wx3/GHSA-4hq8-v42x-9wx3.json index 003f83405b6..bdad55bd569 100644 --- a/advisories/github-reviewed/2020/09/GHSA-4hq8-v42x-9wx3/GHSA-4hq8-v42x-9wx3.json +++ b/advisories/github-reviewed/2020/09/GHSA-4hq8-v42x-9wx3/GHSA-4hq8-v42x-9wx3.json @@ -3,9 +3,7 @@ "id": "GHSA-4hq8-v42x-9wx3", "modified": "2021-10-01T20:56:40Z", "published": "2020-09-04T16:51:52Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bs85check", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-4m3j-h8f2-4xh4/GHSA-4m3j-h8f2-4xh4.json b/advisories/github-reviewed/2020/09/GHSA-4m3j-h8f2-4xh4/GHSA-4m3j-h8f2-4xh4.json index f4efbaacbde..b8738e20b50 100644 --- a/advisories/github-reviewed/2020/09/GHSA-4m3j-h8f2-4xh4/GHSA-4m3j-h8f2-4xh4.json +++ b/advisories/github-reviewed/2020/09/GHSA-4m3j-h8f2-4xh4/GHSA-4m3j-h8f2-4xh4.json @@ -3,9 +3,7 @@ "id": "GHSA-4m3j-h8f2-4xh4", "modified": "2021-10-01T20:58:35Z", "published": "2020-09-03T19:41:31Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in coinstrig", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-4m3p-x2hp-2pgx/GHSA-4m3p-x2hp-2pgx.json b/advisories/github-reviewed/2020/09/GHSA-4m3p-x2hp-2pgx/GHSA-4m3p-x2hp-2pgx.json index d7cf0540dbf..5e857965e10 100644 --- a/advisories/github-reviewed/2020/09/GHSA-4m3p-x2hp-2pgx/GHSA-4m3p-x2hp-2pgx.json +++ b/advisories/github-reviewed/2020/09/GHSA-4m3p-x2hp-2pgx/GHSA-4m3p-x2hp-2pgx.json @@ -3,9 +3,7 @@ "id": "GHSA-4m3p-x2hp-2pgx", "modified": "2021-10-01T20:44:10Z", "published": "2020-09-04T16:45:23Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcroe-lib", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-52c9-458g-whrf/GHSA-52c9-458g-whrf.json b/advisories/github-reviewed/2020/09/GHSA-52c9-458g-whrf/GHSA-52c9-458g-whrf.json index 746db2382b9..de500811387 100644 --- a/advisories/github-reviewed/2020/09/GHSA-52c9-458g-whrf/GHSA-52c9-458g-whrf.json +++ b/advisories/github-reviewed/2020/09/GHSA-52c9-458g-whrf/GHSA-52c9-458g-whrf.json @@ -3,9 +3,7 @@ "id": "GHSA-52c9-458g-whrf", "modified": "2021-09-30T17:00:43Z", "published": "2020-09-03T22:58:17Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-3ha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-5327-gfq5-8f4m/GHSA-5327-gfq5-8f4m.json b/advisories/github-reviewed/2020/09/GHSA-5327-gfq5-8f4m/GHSA-5327-gfq5-8f4m.json index d246dbf15ba..6618a4cd741 100644 --- a/advisories/github-reviewed/2020/09/GHSA-5327-gfq5-8f4m/GHSA-5327-gfq5-8f4m.json +++ b/advisories/github-reviewed/2020/09/GHSA-5327-gfq5-8f4m/GHSA-5327-gfq5-8f4m.json @@ -3,9 +3,7 @@ "id": "GHSA-5327-gfq5-8f4m", "modified": "2021-09-29T21:04:17Z", "published": "2020-09-03T21:56:23Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-xmr", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-533p-g2hq-qr26/GHSA-533p-g2hq-qr26.json b/advisories/github-reviewed/2020/09/GHSA-533p-g2hq-qr26/GHSA-533p-g2hq-qr26.json index 949427465b2..11398d59451 100644 --- a/advisories/github-reviewed/2020/09/GHSA-533p-g2hq-qr26/GHSA-533p-g2hq-qr26.json +++ b/advisories/github-reviewed/2020/09/GHSA-533p-g2hq-qr26/GHSA-533p-g2hq-qr26.json @@ -3,14 +3,10 @@ "id": "GHSA-533p-g2hq-qr26", "modified": "2020-08-31T18:59:07Z", "published": "2020-09-04T17:16:35Z", - "aliases": [ - - ], + "aliases": [], "summary": "Command Injection in treekill", "details": "All versions of `treekill` are vulnerable to Command Injection. The package fails to sanitize values passed to the `kill` function. If this value is user-controlled it may allow attackers to run arbitrary commands in the server. The issue only affects Windows systems.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-536f-268f-6gxc/GHSA-536f-268f-6gxc.json b/advisories/github-reviewed/2020/09/GHSA-536f-268f-6gxc/GHSA-536f-268f-6gxc.json index 7f99b604779..057e5de2270 100644 --- a/advisories/github-reviewed/2020/09/GHSA-536f-268f-6gxc/GHSA-536f-268f-6gxc.json +++ b/advisories/github-reviewed/2020/09/GHSA-536f-268f-6gxc/GHSA-536f-268f-6gxc.json @@ -3,9 +3,7 @@ "id": "GHSA-536f-268f-6gxc", "modified": "2021-09-29T21:25:46Z", "published": "2020-09-03T22:17:36Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffermxor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-54qm-37qr-w5wq/GHSA-54qm-37qr-w5wq.json b/advisories/github-reviewed/2020/09/GHSA-54qm-37qr-w5wq/GHSA-54qm-37qr-w5wq.json index 8cea849846d..5a55f89b9b4 100644 --- a/advisories/github-reviewed/2020/09/GHSA-54qm-37qr-w5wq/GHSA-54qm-37qr-w5wq.json +++ b/advisories/github-reviewed/2020/09/GHSA-54qm-37qr-w5wq/GHSA-54qm-37qr-w5wq.json @@ -3,14 +3,10 @@ "id": "GHSA-54qm-37qr-w5wq", "modified": "2020-08-31T18:55:05Z", "published": "2020-09-04T15:04:20Z", - "aliases": [ - - ], + "aliases": [], "summary": "Sandbox Breakout / Arbitrary Code Execution in veval", "details": "All versions of `veval` are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through `this.constructor.constructor` . This may allow attackers to execute arbitrary code in the system. Evaluating the payload `this.constructor.constructor('return process.env')()` prints the contents of `process.env`.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:55:05Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-563h-49v8-g7x4/GHSA-563h-49v8-g7x4.json b/advisories/github-reviewed/2020/09/GHSA-563h-49v8-g7x4/GHSA-563h-49v8-g7x4.json index 55ccf79119f..c36ffe03574 100644 --- a/advisories/github-reviewed/2020/09/GHSA-563h-49v8-g7x4/GHSA-563h-49v8-g7x4.json +++ b/advisories/github-reviewed/2020/09/GHSA-563h-49v8-g7x4/GHSA-563h-49v8-g7x4.json @@ -3,9 +3,7 @@ "id": "GHSA-563h-49v8-g7x4", "modified": "2021-10-01T16:10:30Z", "published": "2020-09-03T23:17:01Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in ks-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-5wq6-v5cw-jvfr/GHSA-5wq6-v5cw-jvfr.json b/advisories/github-reviewed/2020/09/GHSA-5wq6-v5cw-jvfr/GHSA-5wq6-v5cw-jvfr.json index 42ad8c530c2..76a7a79441e 100644 --- a/advisories/github-reviewed/2020/09/GHSA-5wq6-v5cw-jvfr/GHSA-5wq6-v5cw-jvfr.json +++ b/advisories/github-reviewed/2020/09/GHSA-5wq6-v5cw-jvfr/GHSA-5wq6-v5cw-jvfr.json @@ -3,9 +3,7 @@ "id": "GHSA-5wq6-v5cw-jvfr", "modified": "2021-09-30T17:12:55Z", "published": "2020-09-03T23:03:36Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-shas", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-629c-j867-3v45/GHSA-629c-j867-3v45.json b/advisories/github-reviewed/2020/09/GHSA-629c-j867-3v45/GHSA-629c-j867-3v45.json index 30086ce2fe4..f1aca70a6d6 100644 --- a/advisories/github-reviewed/2020/09/GHSA-629c-j867-3v45/GHSA-629c-j867-3v45.json +++ b/advisories/github-reviewed/2020/09/GHSA-629c-j867-3v45/GHSA-629c-j867-3v45.json @@ -3,9 +3,7 @@ "id": "GHSA-629c-j867-3v45", "modified": "2021-10-01T20:43:02Z", "published": "2020-09-04T16:41:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcoisnj-lib", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-6343-m2qr-66gf/GHSA-6343-m2qr-66gf.json b/advisories/github-reviewed/2020/09/GHSA-6343-m2qr-66gf/GHSA-6343-m2qr-66gf.json index 5d3ce93ba3c..e651b31f28c 100644 --- a/advisories/github-reviewed/2020/09/GHSA-6343-m2qr-66gf/GHSA-6343-m2qr-66gf.json +++ b/advisories/github-reviewed/2020/09/GHSA-6343-m2qr-66gf/GHSA-6343-m2qr-66gf.json @@ -3,9 +3,7 @@ "id": "GHSA-6343-m2qr-66gf", "modified": "2021-09-30T17:14:57Z", "published": "2020-09-03T23:10:41Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-sja3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-657v-jjf8-83gh/GHSA-657v-jjf8-83gh.json b/advisories/github-reviewed/2020/09/GHSA-657v-jjf8-83gh/GHSA-657v-jjf8-83gh.json index 6a5ae2add2f..677e6b6d9da 100644 --- a/advisories/github-reviewed/2020/09/GHSA-657v-jjf8-83gh/GHSA-657v-jjf8-83gh.json +++ b/advisories/github-reviewed/2020/09/GHSA-657v-jjf8-83gh/GHSA-657v-jjf8-83gh.json @@ -3,9 +3,7 @@ "id": "GHSA-657v-jjf8-83gh", "modified": "2021-10-01T14:37:41Z", "published": "2020-09-03T23:14:55Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in jsmsha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-65xx-c85x-wg76/GHSA-65xx-c85x-wg76.json b/advisories/github-reviewed/2020/09/GHSA-65xx-c85x-wg76/GHSA-65xx-c85x-wg76.json index c91f9319121..4a682c55557 100644 --- a/advisories/github-reviewed/2020/09/GHSA-65xx-c85x-wg76/GHSA-65xx-c85x-wg76.json +++ b/advisories/github-reviewed/2020/09/GHSA-65xx-c85x-wg76/GHSA-65xx-c85x-wg76.json @@ -3,14 +3,10 @@ "id": "GHSA-65xx-c85x-wg76", "modified": "2020-08-31T18:59:26Z", "published": "2020-09-04T17:20:52Z", - "aliases": [ - - ], + "aliases": [], "summary": "Command Injection in plotter", "details": "All versions of `plotter` are vulnerable to Command Injection. The package fails to sanitize plot titles, which may allow attackers to execute arbitrary code in the system if the title value is supplied by a user. The following proof-of-concept creates a `testing` file in the current directory:\n\n```\nvar plot = require('plotter').plot;\n\nconst title = 'Example \"\\nset title system(\"touch testing\")#';\n\nplot({\ndata: [ 3, 1, 2, 3, 4 ],\nfilename: 'output.pdf',\nstyle: 'linespoints',\ntitle: title,\nlogscale: true,\nxlabel: 'time',\nylabel: 'length of string',\nformat: 'pdf'\n});\n\n```\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-674r-xx4c-gj7x/GHSA-674r-xx4c-gj7x.json b/advisories/github-reviewed/2020/09/GHSA-674r-xx4c-gj7x/GHSA-674r-xx4c-gj7x.json index 149ad00715a..7773c0b3665 100644 --- a/advisories/github-reviewed/2020/09/GHSA-674r-xx4c-gj7x/GHSA-674r-xx4c-gj7x.json +++ b/advisories/github-reviewed/2020/09/GHSA-674r-xx4c-gj7x/GHSA-674r-xx4c-gj7x.json @@ -3,9 +3,7 @@ "id": "GHSA-674r-xx4c-gj7x", "modified": "2021-10-04T14:28:19Z", "published": "2020-09-03T17:04:05Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in sb58", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-67mp-pcv9-vvq6/GHSA-67mp-pcv9-vvq6.json b/advisories/github-reviewed/2020/09/GHSA-67mp-pcv9-vvq6/GHSA-67mp-pcv9-vvq6.json index 0d1f0dd7df1..6de1cecf514 100644 --- a/advisories/github-reviewed/2020/09/GHSA-67mp-pcv9-vvq6/GHSA-67mp-pcv9-vvq6.json +++ b/advisories/github-reviewed/2020/09/GHSA-67mp-pcv9-vvq6/GHSA-67mp-pcv9-vvq6.json @@ -3,9 +3,7 @@ "id": "GHSA-67mp-pcv9-vvq6", "modified": "2021-09-30T16:35:36Z", "published": "2020-09-03T22:57:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in jr-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-692h-g37c-qv44/GHSA-692h-g37c-qv44.json b/advisories/github-reviewed/2020/09/GHSA-692h-g37c-qv44/GHSA-692h-g37c-qv44.json index a35f9ef3da2..5f6d7e64ecd 100644 --- a/advisories/github-reviewed/2020/09/GHSA-692h-g37c-qv44/GHSA-692h-g37c-qv44.json +++ b/advisories/github-reviewed/2020/09/GHSA-692h-g37c-qv44/GHSA-692h-g37c-qv44.json @@ -3,9 +3,7 @@ "id": "GHSA-692h-g37c-qv44", "modified": "2021-10-01T16:15:23Z", "published": "2020-09-03T23:25:30Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in sj-tw-sec", "details": "All versions of `sj-tw-sec` contain malicious code. The package downloads and runs a script that opens a reverse shell in the system.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-69mf-2cw2-38m8/GHSA-69mf-2cw2-38m8.json b/advisories/github-reviewed/2020/09/GHSA-69mf-2cw2-38m8/GHSA-69mf-2cw2-38m8.json index 27ee059e423..c6d902b9554 100644 --- a/advisories/github-reviewed/2020/09/GHSA-69mf-2cw2-38m8/GHSA-69mf-2cw2-38m8.json +++ b/advisories/github-reviewed/2020/09/GHSA-69mf-2cw2-38m8/GHSA-69mf-2cw2-38m8.json @@ -3,9 +3,7 @@ "id": "GHSA-69mf-2cw2-38m8", "modified": "2021-09-30T17:13:22Z", "published": "2020-09-03T23:04:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-shc3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-6f93-xj8r-jp82/GHSA-6f93-xj8r-jp82.json b/advisories/github-reviewed/2020/09/GHSA-6f93-xj8r-jp82/GHSA-6f93-xj8r-jp82.json index 97d58b73ac2..74c5891b6ca 100644 --- a/advisories/github-reviewed/2020/09/GHSA-6f93-xj8r-jp82/GHSA-6f93-xj8r-jp82.json +++ b/advisories/github-reviewed/2020/09/GHSA-6f93-xj8r-jp82/GHSA-6f93-xj8r-jp82.json @@ -3,9 +3,7 @@ "id": "GHSA-6f93-xj8r-jp82", "modified": "2021-09-29T21:36:55Z", "published": "2020-09-03T22:28:21Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bunfer-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-6fh5-8wq8-w3wr/GHSA-6fh5-8wq8-w3wr.json b/advisories/github-reviewed/2020/09/GHSA-6fh5-8wq8-w3wr/GHSA-6fh5-8wq8-w3wr.json index 9d48d7cd919..d251452d50c 100644 --- a/advisories/github-reviewed/2020/09/GHSA-6fh5-8wq8-w3wr/GHSA-6fh5-8wq8-w3wr.json +++ b/advisories/github-reviewed/2020/09/GHSA-6fh5-8wq8-w3wr/GHSA-6fh5-8wq8-w3wr.json @@ -3,14 +3,10 @@ "id": "GHSA-6fh5-8wq8-w3wr", "modified": "2020-08-31T18:55:18Z", "published": "2020-09-04T15:09:55Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in unflatten", "details": "All versions of `unflatten` are vulnerable to prototype pollution. The function `unflatten` does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-6mrq-7r7m-hh4p/GHSA-6mrq-7r7m-hh4p.json b/advisories/github-reviewed/2020/09/GHSA-6mrq-7r7m-hh4p/GHSA-6mrq-7r7m-hh4p.json index c5ce7b571c1..9a3a34e6dc3 100644 --- a/advisories/github-reviewed/2020/09/GHSA-6mrq-7r7m-hh4p/GHSA-6mrq-7r7m-hh4p.json +++ b/advisories/github-reviewed/2020/09/GHSA-6mrq-7r7m-hh4p/GHSA-6mrq-7r7m-hh4p.json @@ -3,9 +3,7 @@ "id": "GHSA-6mrq-7r7m-hh4p", "modified": "2021-09-30T16:21:58Z", "published": "2020-09-03T22:52:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in hs-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-6qgx-f452-7699/GHSA-6qgx-f452-7699.json b/advisories/github-reviewed/2020/09/GHSA-6qgx-f452-7699/GHSA-6qgx-f452-7699.json index 037431c60c5..72ab577d054 100644 --- a/advisories/github-reviewed/2020/09/GHSA-6qgx-f452-7699/GHSA-6qgx-f452-7699.json +++ b/advisories/github-reviewed/2020/09/GHSA-6qgx-f452-7699/GHSA-6qgx-f452-7699.json @@ -3,9 +3,7 @@ "id": "GHSA-6qgx-f452-7699", "modified": "2021-10-01T17:07:59Z", "published": "2020-09-03T23:28:39Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in superhappyfuntime", "details": "All versions of `superhappyfuntime` contain malicious code. The package downloads and runs a script that opens a reverse shell in the system.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-6xm4-p6r2-mwrc/GHSA-6xm4-p6r2-mwrc.json b/advisories/github-reviewed/2020/09/GHSA-6xm4-p6r2-mwrc/GHSA-6xm4-p6r2-mwrc.json index 00789a38d62..e52903aad7e 100644 --- a/advisories/github-reviewed/2020/09/GHSA-6xm4-p6r2-mwrc/GHSA-6xm4-p6r2-mwrc.json +++ b/advisories/github-reviewed/2020/09/GHSA-6xm4-p6r2-mwrc/GHSA-6xm4-p6r2-mwrc.json @@ -3,9 +3,7 @@ "id": "GHSA-6xm4-p6r2-mwrc", "modified": "2021-09-30T16:14:12Z", "published": "2020-09-03T22:47:30Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in cuffer-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-73c6-vwjh-g3qh/GHSA-73c6-vwjh-g3qh.json b/advisories/github-reviewed/2020/09/GHSA-73c6-vwjh-g3qh/GHSA-73c6-vwjh-g3qh.json index e240ac60236..0cdfe8c94dc 100644 --- a/advisories/github-reviewed/2020/09/GHSA-73c6-vwjh-g3qh/GHSA-73c6-vwjh-g3qh.json +++ b/advisories/github-reviewed/2020/09/GHSA-73c6-vwjh-g3qh/GHSA-73c6-vwjh-g3qh.json @@ -3,9 +3,7 @@ "id": "GHSA-73c6-vwjh-g3qh", "modified": "2021-10-01T21:00:05Z", "published": "2020-09-03T19:40:46Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in crpyto-js", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-74hh-4rcv-pp27/GHSA-74hh-4rcv-pp27.json b/advisories/github-reviewed/2020/09/GHSA-74hh-4rcv-pp27/GHSA-74hh-4rcv-pp27.json index d94e430f1ab..d7176735a91 100644 --- a/advisories/github-reviewed/2020/09/GHSA-74hh-4rcv-pp27/GHSA-74hh-4rcv-pp27.json +++ b/advisories/github-reviewed/2020/09/GHSA-74hh-4rcv-pp27/GHSA-74hh-4rcv-pp27.json @@ -3,9 +3,7 @@ "id": "GHSA-74hh-4rcv-pp27", "modified": "2021-10-01T20:43:53Z", "published": "2020-09-04T16:44:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitconijs-lib", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-762c-v946-pf25/GHSA-762c-v946-pf25.json b/advisories/github-reviewed/2020/09/GHSA-762c-v946-pf25/GHSA-762c-v946-pf25.json index 469ac7e9bee..802423a40e6 100644 --- a/advisories/github-reviewed/2020/09/GHSA-762c-v946-pf25/GHSA-762c-v946-pf25.json +++ b/advisories/github-reviewed/2020/09/GHSA-762c-v946-pf25/GHSA-762c-v946-pf25.json @@ -3,9 +3,7 @@ "id": "GHSA-762c-v946-pf25", "modified": "2021-10-01T20:44:46Z", "published": "2020-09-04T16:47:33Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bpi39", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-766v-7gjx-55hf/GHSA-766v-7gjx-55hf.json b/advisories/github-reviewed/2020/09/GHSA-766v-7gjx-55hf/GHSA-766v-7gjx-55hf.json index 2383f1aa9ed..5ca08174332 100644 --- a/advisories/github-reviewed/2020/09/GHSA-766v-7gjx-55hf/GHSA-766v-7gjx-55hf.json +++ b/advisories/github-reviewed/2020/09/GHSA-766v-7gjx-55hf/GHSA-766v-7gjx-55hf.json @@ -3,9 +3,7 @@ "id": "GHSA-766v-7gjx-55hf", "modified": "2021-09-30T17:14:27Z", "published": "2020-09-03T23:08:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-shq3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-7696-qr5q-pg37/GHSA-7696-qr5q-pg37.json b/advisories/github-reviewed/2020/09/GHSA-7696-qr5q-pg37/GHSA-7696-qr5q-pg37.json index 55fc9643597..71ff24152ff 100644 --- a/advisories/github-reviewed/2020/09/GHSA-7696-qr5q-pg37/GHSA-7696-qr5q-pg37.json +++ b/advisories/github-reviewed/2020/09/GHSA-7696-qr5q-pg37/GHSA-7696-qr5q-pg37.json @@ -3,9 +3,7 @@ "id": "GHSA-7696-qr5q-pg37", "modified": "2021-10-01T16:10:59Z", "published": "2020-09-03T23:19:08Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in zs-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-785g-gx74-gr39/GHSA-785g-gx74-gr39.json b/advisories/github-reviewed/2020/09/GHSA-785g-gx74-gr39/GHSA-785g-gx74-gr39.json index 1c6f109ac05..f1b919be9e1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-785g-gx74-gr39/GHSA-785g-gx74-gr39.json +++ b/advisories/github-reviewed/2020/09/GHSA-785g-gx74-gr39/GHSA-785g-gx74-gr39.json @@ -3,9 +3,7 @@ "id": "GHSA-785g-gx74-gr39", "modified": "2021-10-01T14:35:20Z", "published": "2020-09-03T23:12:48Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-wha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-7frr-c83r-fm22/GHSA-7frr-c83r-fm22.json b/advisories/github-reviewed/2020/09/GHSA-7frr-c83r-fm22/GHSA-7frr-c83r-fm22.json index d16ee41df23..81e7c0b9d63 100644 --- a/advisories/github-reviewed/2020/09/GHSA-7frr-c83r-fm22/GHSA-7frr-c83r-fm22.json +++ b/advisories/github-reviewed/2020/09/GHSA-7frr-c83r-fm22/GHSA-7frr-c83r-fm22.json @@ -3,9 +3,7 @@ "id": "GHSA-7frr-c83r-fm22", "modified": "2021-09-29T21:26:37Z", "published": "2020-09-03T22:20:49Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffez-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-7j93-5m2h-rvjx/GHSA-7j93-5m2h-rvjx.json b/advisories/github-reviewed/2020/09/GHSA-7j93-5m2h-rvjx/GHSA-7j93-5m2h-rvjx.json index cb88f1f440a..ee937d4581f 100644 --- a/advisories/github-reviewed/2020/09/GHSA-7j93-5m2h-rvjx/GHSA-7j93-5m2h-rvjx.json +++ b/advisories/github-reviewed/2020/09/GHSA-7j93-5m2h-rvjx/GHSA-7j93-5m2h-rvjx.json @@ -3,9 +3,7 @@ "id": "GHSA-7j93-5m2h-rvjx", "modified": "2021-10-01T20:37:33Z", "published": "2020-09-04T15:32:46Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bconi", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-7qg7-6g3g-8vxg/GHSA-7qg7-6g3g-8vxg.json b/advisories/github-reviewed/2020/09/GHSA-7qg7-6g3g-8vxg/GHSA-7qg7-6g3g-8vxg.json index fc85ff4fe53..dd321461085 100644 --- a/advisories/github-reviewed/2020/09/GHSA-7qg7-6g3g-8vxg/GHSA-7qg7-6g3g-8vxg.json +++ b/advisories/github-reviewed/2020/09/GHSA-7qg7-6g3g-8vxg/GHSA-7qg7-6g3g-8vxg.json @@ -3,9 +3,7 @@ "id": "GHSA-7qg7-6g3g-8vxg", "modified": "2021-09-30T15:46:17Z", "published": "2020-09-03T22:46:25Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bwffer-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-7r9x-hr76-jr96/GHSA-7r9x-hr76-jr96.json b/advisories/github-reviewed/2020/09/GHSA-7r9x-hr76-jr96/GHSA-7r9x-hr76-jr96.json index 988cde0e30a..47dd0127ef2 100644 --- a/advisories/github-reviewed/2020/09/GHSA-7r9x-hr76-jr96/GHSA-7r9x-hr76-jr96.json +++ b/advisories/github-reviewed/2020/09/GHSA-7r9x-hr76-jr96/GHSA-7r9x-hr76-jr96.json @@ -3,14 +3,10 @@ "id": "GHSA-7r9x-hr76-jr96", "modified": "2020-08-31T18:59:37Z", "published": "2020-09-04T17:26:18Z", - "aliases": [ - - ], + "aliases": [], "summary": "Command Injection in giting", "details": "All versions of `gitting` are vulnerable to Command Injection. The package fails to sanitize input and passes it directly to an `exec` call, which may allow attackers to execute arbitrary code in the system. The `pull` function is vulnerable through the `branch` variable.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-7w7c-867m-4mqc/GHSA-7w7c-867m-4mqc.json b/advisories/github-reviewed/2020/09/GHSA-7w7c-867m-4mqc/GHSA-7w7c-867m-4mqc.json index 38df7fda6a4..518280a79cb 100644 --- a/advisories/github-reviewed/2020/09/GHSA-7w7c-867m-4mqc/GHSA-7w7c-867m-4mqc.json +++ b/advisories/github-reviewed/2020/09/GHSA-7w7c-867m-4mqc/GHSA-7w7c-867m-4mqc.json @@ -3,9 +3,7 @@ "id": "GHSA-7w7c-867m-4mqc", "modified": "2021-10-01T21:04:09Z", "published": "2020-09-03T17:04:55Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in rceat", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-7xc4-793x-25jp/GHSA-7xc4-793x-25jp.json b/advisories/github-reviewed/2020/09/GHSA-7xc4-793x-25jp/GHSA-7xc4-793x-25jp.json index a71221aba1e..b2a921f2387 100644 --- a/advisories/github-reviewed/2020/09/GHSA-7xc4-793x-25jp/GHSA-7xc4-793x-25jp.json +++ b/advisories/github-reviewed/2020/09/GHSA-7xc4-793x-25jp/GHSA-7xc4-793x-25jp.json @@ -3,9 +3,7 @@ "id": "GHSA-7xc4-793x-25jp", "modified": "2021-10-01T20:49:13Z", "published": "2020-09-04T16:48:38Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bpi66", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-7xf6-cpxm-5mx9/GHSA-7xf6-cpxm-5mx9.json b/advisories/github-reviewed/2020/09/GHSA-7xf6-cpxm-5mx9/GHSA-7xf6-cpxm-5mx9.json index bcf0c474060..c0689b2a13f 100644 --- a/advisories/github-reviewed/2020/09/GHSA-7xf6-cpxm-5mx9/GHSA-7xf6-cpxm-5mx9.json +++ b/advisories/github-reviewed/2020/09/GHSA-7xf6-cpxm-5mx9/GHSA-7xf6-cpxm-5mx9.json @@ -3,9 +3,7 @@ "id": "GHSA-7xf6-cpxm-5mx9", "modified": "2021-09-29T21:35:53Z", "published": "2020-09-03T22:27:18Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bufner-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-7xf9-74cp-8hx3/GHSA-7xf9-74cp-8hx3.json b/advisories/github-reviewed/2020/09/GHSA-7xf9-74cp-8hx3/GHSA-7xf9-74cp-8hx3.json index 94cbb65e179..4ac43e18af6 100644 --- a/advisories/github-reviewed/2020/09/GHSA-7xf9-74cp-8hx3/GHSA-7xf9-74cp-8hx3.json +++ b/advisories/github-reviewed/2020/09/GHSA-7xf9-74cp-8hx3/GHSA-7xf9-74cp-8hx3.json @@ -3,9 +3,7 @@ "id": "GHSA-7xf9-74cp-8hx3", "modified": "2021-09-30T17:00:58Z", "published": "2020-09-03T22:59:21Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-cha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-83pq-466j-fc6j/GHSA-83pq-466j-fc6j.json b/advisories/github-reviewed/2020/09/GHSA-83pq-466j-fc6j/GHSA-83pq-466j-fc6j.json index e5cd1f696a6..f9e338107d7 100644 --- a/advisories/github-reviewed/2020/09/GHSA-83pq-466j-fc6j/GHSA-83pq-466j-fc6j.json +++ b/advisories/github-reviewed/2020/09/GHSA-83pq-466j-fc6j/GHSA-83pq-466j-fc6j.json @@ -3,14 +3,10 @@ "id": "GHSA-83pq-466j-fc6j", "modified": "2020-08-31T18:55:34Z", "published": "2020-09-04T15:17:50Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in sahmat", "details": "All versions of `sahmat ` are vulnerable to prototype pollution. The package does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-85q4-v37c-wfpc/GHSA-85q4-v37c-wfpc.json b/advisories/github-reviewed/2020/09/GHSA-85q4-v37c-wfpc/GHSA-85q4-v37c-wfpc.json index b2f29b60347..26fee10ba18 100644 --- a/advisories/github-reviewed/2020/09/GHSA-85q4-v37c-wfpc/GHSA-85q4-v37c-wfpc.json +++ b/advisories/github-reviewed/2020/09/GHSA-85q4-v37c-wfpc/GHSA-85q4-v37c-wfpc.json @@ -3,9 +3,7 @@ "id": "GHSA-85q4-v37c-wfpc", "modified": "2021-10-01T20:39:09Z", "published": "2020-09-04T15:39:28Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcion-ops", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-88xx-23mf-rcj2/GHSA-88xx-23mf-rcj2.json b/advisories/github-reviewed/2020/09/GHSA-88xx-23mf-rcj2/GHSA-88xx-23mf-rcj2.json index 4116dffd843..023e407f15d 100644 --- a/advisories/github-reviewed/2020/09/GHSA-88xx-23mf-rcj2/GHSA-88xx-23mf-rcj2.json +++ b/advisories/github-reviewed/2020/09/GHSA-88xx-23mf-rcj2/GHSA-88xx-23mf-rcj2.json @@ -3,9 +3,7 @@ "id": "GHSA-88xx-23mf-rcj2", "modified": "2021-09-30T16:18:52Z", "published": "2020-09-03T22:51:52Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bs-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-8g3r-968r-c644/GHSA-8g3r-968r-c644.json b/advisories/github-reviewed/2020/09/GHSA-8g3r-968r-c644/GHSA-8g3r-968r-c644.json index bb8260c2250..92a2ff7ab7d 100644 --- a/advisories/github-reviewed/2020/09/GHSA-8g3r-968r-c644/GHSA-8g3r-968r-c644.json +++ b/advisories/github-reviewed/2020/09/GHSA-8g3r-968r-c644/GHSA-8g3r-968r-c644.json @@ -3,9 +3,7 @@ "id": "GHSA-8g3r-968r-c644", "modified": "2021-10-01T14:37:54Z", "published": "2020-09-03T23:15:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in jw-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-8g64-9cm2-838j/GHSA-8g64-9cm2-838j.json b/advisories/github-reviewed/2020/09/GHSA-8g64-9cm2-838j/GHSA-8g64-9cm2-838j.json index 2e870982de7..bf914e34cb2 100644 --- a/advisories/github-reviewed/2020/09/GHSA-8g64-9cm2-838j/GHSA-8g64-9cm2-838j.json +++ b/advisories/github-reviewed/2020/09/GHSA-8g64-9cm2-838j/GHSA-8g64-9cm2-838j.json @@ -3,9 +3,7 @@ "id": "GHSA-8g64-9cm2-838j", "modified": "2021-09-29T21:36:41Z", "published": "2020-09-03T22:29:26Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bugfer-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-8gc6-65mm-xr6r/GHSA-8gc6-65mm-xr6r.json b/advisories/github-reviewed/2020/09/GHSA-8gc6-65mm-xr6r/GHSA-8gc6-65mm-xr6r.json index 6e244749132..964877b1a43 100644 --- a/advisories/github-reviewed/2020/09/GHSA-8gc6-65mm-xr6r/GHSA-8gc6-65mm-xr6r.json +++ b/advisories/github-reviewed/2020/09/GHSA-8gc6-65mm-xr6r/GHSA-8gc6-65mm-xr6r.json @@ -3,9 +3,7 @@ "id": "GHSA-8gc6-65mm-xr6r", "modified": "2021-10-01T20:44:26Z", "published": "2020-09-04T16:46:28Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bp66", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-8hqw-qp6r-vqcm/GHSA-8hqw-qp6r-vqcm.json b/advisories/github-reviewed/2020/09/GHSA-8hqw-qp6r-vqcm/GHSA-8hqw-qp6r-vqcm.json index b5384e8d213..433abb469f2 100644 --- a/advisories/github-reviewed/2020/09/GHSA-8hqw-qp6r-vqcm/GHSA-8hqw-qp6r-vqcm.json +++ b/advisories/github-reviewed/2020/09/GHSA-8hqw-qp6r-vqcm/GHSA-8hqw-qp6r-vqcm.json @@ -3,9 +3,7 @@ "id": "GHSA-8hqw-qp6r-vqcm", "modified": "2021-10-01T20:42:42Z", "published": "2020-09-04T16:40:00Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcoin-sweep", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-8j49-49jq-vwcq/GHSA-8j49-49jq-vwcq.json b/advisories/github-reviewed/2020/09/GHSA-8j49-49jq-vwcq/GHSA-8j49-49jq-vwcq.json index 263023762b5..bd14fa7c669 100644 --- a/advisories/github-reviewed/2020/09/GHSA-8j49-49jq-vwcq/GHSA-8j49-49jq-vwcq.json +++ b/advisories/github-reviewed/2020/09/GHSA-8j49-49jq-vwcq/GHSA-8j49-49jq-vwcq.json @@ -3,14 +3,10 @@ "id": "GHSA-8j49-49jq-vwcq", "modified": "2020-08-31T18:55:30Z", "published": "2020-09-04T15:15:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in getsetdeep", "details": "All versions of `getsetdeep` are vulnerable to prototype pollution. The `setDeep()` function does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-8pwx-j4r6-5v38/GHSA-8pwx-j4r6-5v38.json b/advisories/github-reviewed/2020/09/GHSA-8pwx-j4r6-5v38/GHSA-8pwx-j4r6-5v38.json index 2a38b45995c..794c3b2eff5 100644 --- a/advisories/github-reviewed/2020/09/GHSA-8pwx-j4r6-5v38/GHSA-8pwx-j4r6-5v38.json +++ b/advisories/github-reviewed/2020/09/GHSA-8pwx-j4r6-5v38/GHSA-8pwx-j4r6-5v38.json @@ -3,9 +3,7 @@ "id": "GHSA-8pwx-j4r6-5v38", "modified": "2021-10-01T21:02:37Z", "published": "2020-09-03T17:05:25Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in hdkye", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-9272-59x2-gwf2/GHSA-9272-59x2-gwf2.json b/advisories/github-reviewed/2020/09/GHSA-9272-59x2-gwf2/GHSA-9272-59x2-gwf2.json index fb25312f8ad..2d63986d912 100644 --- a/advisories/github-reviewed/2020/09/GHSA-9272-59x2-gwf2/GHSA-9272-59x2-gwf2.json +++ b/advisories/github-reviewed/2020/09/GHSA-9272-59x2-gwf2/GHSA-9272-59x2-gwf2.json @@ -3,9 +3,7 @@ "id": "GHSA-9272-59x2-gwf2", "modified": "2021-10-01T21:04:39Z", "published": "2020-09-03T17:04:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in ripedm160", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-9298-m7jf-55h2/GHSA-9298-m7jf-55h2.json b/advisories/github-reviewed/2020/09/GHSA-9298-m7jf-55h2/GHSA-9298-m7jf-55h2.json index 5d88111f5c7..33a59836cdf 100644 --- a/advisories/github-reviewed/2020/09/GHSA-9298-m7jf-55h2/GHSA-9298-m7jf-55h2.json +++ b/advisories/github-reviewed/2020/09/GHSA-9298-m7jf-55h2/GHSA-9298-m7jf-55h2.json @@ -3,9 +3,7 @@ "id": "GHSA-9298-m7jf-55h2", "modified": "2021-10-01T20:43:38Z", "published": "2020-09-04T16:42:08Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitconid-rpc", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-95cg-3r4g-7w6j/GHSA-95cg-3r4g-7w6j.json b/advisories/github-reviewed/2020/09/GHSA-95cg-3r4g-7w6j/GHSA-95cg-3r4g-7w6j.json index a80f29bdea0..27c72f65f9d 100644 --- a/advisories/github-reviewed/2020/09/GHSA-95cg-3r4g-7w6j/GHSA-95cg-3r4g-7w6j.json +++ b/advisories/github-reviewed/2020/09/GHSA-95cg-3r4g-7w6j/GHSA-95cg-3r4g-7w6j.json @@ -3,9 +3,7 @@ "id": "GHSA-95cg-3r4g-7w6j", "modified": "2021-09-30T17:10:32Z", "published": "2020-09-03T23:01:29Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-rha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-97mg-3cr6-3x4c/GHSA-97mg-3cr6-3x4c.json b/advisories/github-reviewed/2020/09/GHSA-97mg-3cr6-3x4c/GHSA-97mg-3cr6-3x4c.json index d1166f387e7..970db8892ce 100644 --- a/advisories/github-reviewed/2020/09/GHSA-97mg-3cr6-3x4c/GHSA-97mg-3cr6-3x4c.json +++ b/advisories/github-reviewed/2020/09/GHSA-97mg-3cr6-3x4c/GHSA-97mg-3cr6-3x4c.json @@ -3,14 +3,10 @@ "id": "GHSA-97mg-3cr6-3x4c", "modified": "2020-08-31T18:59:39Z", "published": "2020-09-04T17:27:23Z", - "aliases": [ - - ], + "aliases": [], "summary": "Remote Code Execution in mongodb-query-parser", "details": "Versions of `mongodb-query-parser` prior to 2.0.0 are vulnerable to Remote Code Execution. The package fails to sanitize queries, allowing attackers to execute arbitrary code in the system. Parsing the following payload executes `touch test-file`: \n\n```'(function () { return (clearImmediate.constructor(\"return process;\")()).mainModule.require(\"child_process\").execSync(\"touch test-file\").toString()})()'```\n\n\n\n## Recommendation\n\nUpgrade to version 2.0.0 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:59:39Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-97mp-9g5c-6c93/GHSA-97mp-9g5c-6c93.json b/advisories/github-reviewed/2020/09/GHSA-97mp-9g5c-6c93/GHSA-97mp-9g5c-6c93.json index 6202ba91f05..9276a8ec343 100644 --- a/advisories/github-reviewed/2020/09/GHSA-97mp-9g5c-6c93/GHSA-97mp-9g5c-6c93.json +++ b/advisories/github-reviewed/2020/09/GHSA-97mp-9g5c-6c93/GHSA-97mp-9g5c-6c93.json @@ -3,9 +3,7 @@ "id": "GHSA-97mp-9g5c-6c93", "modified": "2021-10-01T20:49:31Z", "published": "2020-09-04T16:50:48Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bs58chcek", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-9cph-cqqh-36pw/GHSA-9cph-cqqh-36pw.json b/advisories/github-reviewed/2020/09/GHSA-9cph-cqqh-36pw/GHSA-9cph-cqqh-36pw.json index f113c30463e..26b87ec3ba9 100644 --- a/advisories/github-reviewed/2020/09/GHSA-9cph-cqqh-36pw/GHSA-9cph-cqqh-36pw.json +++ b/advisories/github-reviewed/2020/09/GHSA-9cph-cqqh-36pw/GHSA-9cph-cqqh-36pw.json @@ -3,9 +3,7 @@ "id": "GHSA-9cph-cqqh-36pw", "modified": "2021-10-01T20:17:59Z", "published": "2020-09-04T15:29:25Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in babel-loqder", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-9gxr-rhx6-4jgv/GHSA-9gxr-rhx6-4jgv.json b/advisories/github-reviewed/2020/09/GHSA-9gxr-rhx6-4jgv/GHSA-9gxr-rhx6-4jgv.json index 38086d64989..a3f9836357b 100644 --- a/advisories/github-reviewed/2020/09/GHSA-9gxr-rhx6-4jgv/GHSA-9gxr-rhx6-4jgv.json +++ b/advisories/github-reviewed/2020/09/GHSA-9gxr-rhx6-4jgv/GHSA-9gxr-rhx6-4jgv.json @@ -3,14 +3,10 @@ "id": "GHSA-9gxr-rhx6-4jgv", "modified": "2020-08-31T18:55:36Z", "published": "2020-09-04T15:18:57Z", - "aliases": [ - - ], + "aliases": [], "summary": "Sandbox Breakout / Prototype Pollution in notevil", "details": "Versions of `notevil` prior to 1.3.3 are vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing attacker to add or modify an object's prototype.\n\nEvaluating the payload ```try{a[b];}catch(e){e.constructor.constructor('return __proto__.arguments.callee.__proto__.polluted=true')()}``` add the `polluted` property to Function.\n\n\n## Recommendation\n\nUpgrade to version 1.3.3 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-9p2w-rmx4-9mw7/GHSA-9p2w-rmx4-9mw7.json b/advisories/github-reviewed/2020/09/GHSA-9p2w-rmx4-9mw7/GHSA-9p2w-rmx4-9mw7.json index 8a6b0afac41..c4ad44c4456 100644 --- a/advisories/github-reviewed/2020/09/GHSA-9p2w-rmx4-9mw7/GHSA-9p2w-rmx4-9mw7.json +++ b/advisories/github-reviewed/2020/09/GHSA-9p2w-rmx4-9mw7/GHSA-9p2w-rmx4-9mw7.json @@ -3,14 +3,10 @@ "id": "GHSA-9p2w-rmx4-9mw7", "modified": "2021-10-04T19:12:12Z", "published": "2020-09-04T16:54:02Z", - "aliases": [ - - ], + "aliases": [], "summary": "Command Injection in strapi", "details": "Versions of `strapi` before 3.0.0-beta.17.8 are vulnerable to Command Injection. The package fails to sanitize plugin names in the `/admin/plugins/install/` route. This may allow an authenticated attacker with admin privileges to run arbitrary commands in the server.\n\n\n## Recommendation\n\nUpgrade to version 3.0.0-beta.17.8 or later", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-9qrg-h9g8-c65q/GHSA-9qrg-h9g8-c65q.json b/advisories/github-reviewed/2020/09/GHSA-9qrg-h9g8-c65q/GHSA-9qrg-h9g8-c65q.json index fd62219ad89..e51a300d4e2 100644 --- a/advisories/github-reviewed/2020/09/GHSA-9qrg-h9g8-c65q/GHSA-9qrg-h9g8-c65q.json +++ b/advisories/github-reviewed/2020/09/GHSA-9qrg-h9g8-c65q/GHSA-9qrg-h9g8-c65q.json @@ -3,14 +3,10 @@ "id": "GHSA-9qrg-h9g8-c65q", "modified": "2020-08-31T18:55:28Z", "published": "2020-09-04T15:14:26Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in deep-setter", "details": "All versions of `deep-setter` are vulnerable to prototype pollution. The package does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-c2g6-57fp-22wp/GHSA-c2g6-57fp-22wp.json b/advisories/github-reviewed/2020/09/GHSA-c2g6-57fp-22wp/GHSA-c2g6-57fp-22wp.json index 95deada1a47..7798edbd293 100644 --- a/advisories/github-reviewed/2020/09/GHSA-c2g6-57fp-22wp/GHSA-c2g6-57fp-22wp.json +++ b/advisories/github-reviewed/2020/09/GHSA-c2g6-57fp-22wp/GHSA-c2g6-57fp-22wp.json @@ -3,9 +3,7 @@ "id": "GHSA-c2g6-57fp-22wp", "modified": "2021-09-30T16:14:29Z", "published": "2020-09-03T22:48:35Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in fuffer-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-c3hq-7mxh-mqxf/GHSA-c3hq-7mxh-mqxf.json b/advisories/github-reviewed/2020/09/GHSA-c3hq-7mxh-mqxf/GHSA-c3hq-7mxh-mqxf.json index a4af864c387..fe8fd1a2ebc 100644 --- a/advisories/github-reviewed/2020/09/GHSA-c3hq-7mxh-mqxf/GHSA-c3hq-7mxh-mqxf.json +++ b/advisories/github-reviewed/2020/09/GHSA-c3hq-7mxh-mqxf/GHSA-c3hq-7mxh-mqxf.json @@ -3,14 +3,10 @@ "id": "GHSA-c3hq-7mxh-mqxf", "modified": "2020-08-31T18:54:55Z", "published": "2020-09-04T14:59:50Z", - "aliases": [ - - ], + "aliases": [], "summary": "Sandbox Breakout / Arbitrary Code Execution in lighter-vm", "details": "All versions of `lighter-vm` are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through `this.constructor.constructor` . This may allow attackers to execute arbitrary code in the system. Evaluating the payload `this.constructor.constructor('return process.env')()` prints the contents of `process.env`.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:54:55Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-c4hh-fg8x-6h9p/GHSA-c4hh-fg8x-6h9p.json b/advisories/github-reviewed/2020/09/GHSA-c4hh-fg8x-6h9p/GHSA-c4hh-fg8x-6h9p.json index b0ae98344bb..fa3c1f645f4 100644 --- a/advisories/github-reviewed/2020/09/GHSA-c4hh-fg8x-6h9p/GHSA-c4hh-fg8x-6h9p.json +++ b/advisories/github-reviewed/2020/09/GHSA-c4hh-fg8x-6h9p/GHSA-c4hh-fg8x-6h9p.json @@ -3,9 +3,7 @@ "id": "GHSA-c4hh-fg8x-6h9p", "modified": "2021-09-29T21:04:32Z", "published": "2020-09-03T21:57:29Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-xnr", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-c5xm-m64m-f2vq/GHSA-c5xm-m64m-f2vq.json b/advisories/github-reviewed/2020/09/GHSA-c5xm-m64m-f2vq/GHSA-c5xm-m64m-f2vq.json index d1bf2853515..f9ecc96296e 100644 --- a/advisories/github-reviewed/2020/09/GHSA-c5xm-m64m-f2vq/GHSA-c5xm-m64m-f2vq.json +++ b/advisories/github-reviewed/2020/09/GHSA-c5xm-m64m-f2vq/GHSA-c5xm-m64m-f2vq.json @@ -3,9 +3,7 @@ "id": "GHSA-c5xm-m64m-f2vq", "modified": "2021-10-01T20:13:30Z", "published": "2020-09-04T15:23:47Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in cxct", "details": "All versions of `cxct` contain malicious code. The package finds and exfiltrates cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-cfc5-x58f-869w/GHSA-cfc5-x58f-869w.json b/advisories/github-reviewed/2020/09/GHSA-cfc5-x58f-869w/GHSA-cfc5-x58f-869w.json index c7c01b59941..a087d75219f 100644 --- a/advisories/github-reviewed/2020/09/GHSA-cfc5-x58f-869w/GHSA-cfc5-x58f-869w.json +++ b/advisories/github-reviewed/2020/09/GHSA-cfc5-x58f-869w/GHSA-cfc5-x58f-869w.json @@ -3,9 +3,7 @@ "id": "GHSA-cfc5-x58f-869w", "modified": "2021-10-01T20:59:50Z", "published": "2020-09-03T19:40:55Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in conistring", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-cfwc-xjfp-44jg/GHSA-cfwc-xjfp-44jg.json b/advisories/github-reviewed/2020/09/GHSA-cfwc-xjfp-44jg/GHSA-cfwc-xjfp-44jg.json index 9a25d0bf164..a68a1863893 100644 --- a/advisories/github-reviewed/2020/09/GHSA-cfwc-xjfp-44jg/GHSA-cfwc-xjfp-44jg.json +++ b/advisories/github-reviewed/2020/09/GHSA-cfwc-xjfp-44jg/GHSA-cfwc-xjfp-44jg.json @@ -3,14 +3,10 @@ "id": "GHSA-cfwc-xjfp-44jg", "modified": "2020-08-31T18:59:23Z", "published": "2020-09-04T17:19:48Z", - "aliases": [ - - ], + "aliases": [], "summary": "Command Injection in gnuplot", "details": "All versions of `gnuplot` are vulnerable to Command Injection. The package fails to sanitize plot titles, which may allow attackers to execute arbitrary code in the system if the title value is supplied by a user. The following proof-of-concept creates a `testing` file in the current directory:\n\n```\nvar gnuplot = require('gnuplot');\n\nconst title = '\"\\nset title system(\"touch testing\")\\n#';\n\ngnuplot()\n.set('term png')\n.set('output \"out.png\"')\n.set(`title \"${title}\"`)\n.set('xrange [-10:10]')\n.set('yrange [-2:2]')\n.set('zeroaxis')\n.plot('(x/4)**2, sin(x), 1/x')\n.end();\n```\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-cgvm-rvfv-c92r/GHSA-cgvm-rvfv-c92r.json b/advisories/github-reviewed/2020/09/GHSA-cgvm-rvfv-c92r/GHSA-cgvm-rvfv-c92r.json index e357c2d3e5b..ebfadcf02b6 100644 --- a/advisories/github-reviewed/2020/09/GHSA-cgvm-rvfv-c92r/GHSA-cgvm-rvfv-c92r.json +++ b/advisories/github-reviewed/2020/09/GHSA-cgvm-rvfv-c92r/GHSA-cgvm-rvfv-c92r.json @@ -3,9 +3,7 @@ "id": "GHSA-cgvm-rvfv-c92r", "modified": "2021-10-01T21:01:46Z", "published": "2020-09-03T17:05:51Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in ecuvre", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-ch82-gqh6-9xj9/GHSA-ch82-gqh6-9xj9.json b/advisories/github-reviewed/2020/09/GHSA-ch82-gqh6-9xj9/GHSA-ch82-gqh6-9xj9.json index 11f5ecc020f..caa2a70b811 100644 --- a/advisories/github-reviewed/2020/09/GHSA-ch82-gqh6-9xj9/GHSA-ch82-gqh6-9xj9.json +++ b/advisories/github-reviewed/2020/09/GHSA-ch82-gqh6-9xj9/GHSA-ch82-gqh6-9xj9.json @@ -3,14 +3,10 @@ "id": "GHSA-ch82-gqh6-9xj9", "modified": "2020-08-31T18:55:25Z", "published": "2020-09-04T15:13:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in get-setter", "details": "All versions of `get-setter` are vulnerable to prototype pollution. The function `set` does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-cr4x-w2v7-4mmf/GHSA-cr4x-w2v7-4mmf.json b/advisories/github-reviewed/2020/09/GHSA-cr4x-w2v7-4mmf/GHSA-cr4x-w2v7-4mmf.json index c2f40057f33..4a6576260f3 100644 --- a/advisories/github-reviewed/2020/09/GHSA-cr4x-w2v7-4mmf/GHSA-cr4x-w2v7-4mmf.json +++ b/advisories/github-reviewed/2020/09/GHSA-cr4x-w2v7-4mmf/GHSA-cr4x-w2v7-4mmf.json @@ -3,9 +3,7 @@ "id": "GHSA-cr4x-w2v7-4mmf", "modified": "2021-09-29T21:36:13Z", "published": "2020-09-03T22:26:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bufver-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-crfh-jmv2-2f9v/GHSA-crfh-jmv2-2f9v.json b/advisories/github-reviewed/2020/09/GHSA-crfh-jmv2-2f9v/GHSA-crfh-jmv2-2f9v.json index 8340ac39f74..e23caed8966 100644 --- a/advisories/github-reviewed/2020/09/GHSA-crfh-jmv2-2f9v/GHSA-crfh-jmv2-2f9v.json +++ b/advisories/github-reviewed/2020/09/GHSA-crfh-jmv2-2f9v/GHSA-crfh-jmv2-2f9v.json @@ -3,9 +3,7 @@ "id": "GHSA-crfh-jmv2-2f9v", "modified": "2021-10-04T15:43:43Z", "published": "2020-09-03T17:03:11Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in singale", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-f294-27fc-wgj7/GHSA-f294-27fc-wgj7.json b/advisories/github-reviewed/2020/09/GHSA-f294-27fc-wgj7/GHSA-f294-27fc-wgj7.json index 855aa214ba8..cd95b551633 100644 --- a/advisories/github-reviewed/2020/09/GHSA-f294-27fc-wgj7/GHSA-f294-27fc-wgj7.json +++ b/advisories/github-reviewed/2020/09/GHSA-f294-27fc-wgj7/GHSA-f294-27fc-wgj7.json @@ -3,9 +3,7 @@ "id": "GHSA-f294-27fc-wgj7", "modified": "2021-09-29T21:25:27Z", "published": "2020-09-03T22:16:31Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-zor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-f52g-6jhx-586p/GHSA-f52g-6jhx-586p.json b/advisories/github-reviewed/2020/09/GHSA-f52g-6jhx-586p/GHSA-f52g-6jhx-586p.json index 53362a6431a..d4f8657d592 100644 --- a/advisories/github-reviewed/2020/09/GHSA-f52g-6jhx-586p/GHSA-f52g-6jhx-586p.json +++ b/advisories/github-reviewed/2020/09/GHSA-f52g-6jhx-586p/GHSA-f52g-6jhx-586p.json @@ -3,14 +3,10 @@ "id": "GHSA-f52g-6jhx-586p", "modified": "2020-08-31T18:54:21Z", "published": "2020-09-03T23:20:12Z", - "aliases": [ - - ], + "aliases": [], "summary": "Denial of Service in handlebars", "details": "Affected versions of `handlebars` are vulnerable to Denial of Service. The package's parser may be forced into an endless loop while processing specially-crafted templates. This may allow attackers to exhaust system resources leading to Denial of Service.\n\n\n## Recommendation\n\nUpgrade to version 4.4.5 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-f72h-wf57-7xwh/GHSA-f72h-wf57-7xwh.json b/advisories/github-reviewed/2020/09/GHSA-f72h-wf57-7xwh/GHSA-f72h-wf57-7xwh.json index 601ad3f6262..41bb1d0008a 100644 --- a/advisories/github-reviewed/2020/09/GHSA-f72h-wf57-7xwh/GHSA-f72h-wf57-7xwh.json +++ b/advisories/github-reviewed/2020/09/GHSA-f72h-wf57-7xwh/GHSA-f72h-wf57-7xwh.json @@ -3,9 +3,7 @@ "id": "GHSA-f72h-wf57-7xwh", "modified": "2021-09-29T21:04:48Z", "published": "2020-09-03T21:58:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-xo2", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-f7gc-6hcj-wc42/GHSA-f7gc-6hcj-wc42.json b/advisories/github-reviewed/2020/09/GHSA-f7gc-6hcj-wc42/GHSA-f7gc-6hcj-wc42.json index 116890358d2..a976c9ffa09 100644 --- a/advisories/github-reviewed/2020/09/GHSA-f7gc-6hcj-wc42/GHSA-f7gc-6hcj-wc42.json +++ b/advisories/github-reviewed/2020/09/GHSA-f7gc-6hcj-wc42/GHSA-f7gc-6hcj-wc42.json @@ -3,9 +3,7 @@ "id": "GHSA-f7gc-6hcj-wc42", "modified": "2021-10-01T21:03:55Z", "published": "2020-09-03T17:05:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in path-to-regxep", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-f8jj-45fj-44r6/GHSA-f8jj-45fj-44r6.json b/advisories/github-reviewed/2020/09/GHSA-f8jj-45fj-44r6/GHSA-f8jj-45fj-44r6.json index c4fe695d87b..13aa3daac57 100644 --- a/advisories/github-reviewed/2020/09/GHSA-f8jj-45fj-44r6/GHSA-f8jj-45fj-44r6.json +++ b/advisories/github-reviewed/2020/09/GHSA-f8jj-45fj-44r6/GHSA-f8jj-45fj-44r6.json @@ -3,9 +3,7 @@ "id": "GHSA-f8jj-45fj-44r6", "modified": "2021-09-30T17:13:39Z", "published": "2020-09-03T23:05:43Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-she3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-f8vf-6hwg-hw55/GHSA-f8vf-6hwg-hw55.json b/advisories/github-reviewed/2020/09/GHSA-f8vf-6hwg-hw55/GHSA-f8vf-6hwg-hw55.json index 92b0b622252..7a36b18eb99 100644 --- a/advisories/github-reviewed/2020/09/GHSA-f8vf-6hwg-hw55/GHSA-f8vf-6hwg-hw55.json +++ b/advisories/github-reviewed/2020/09/GHSA-f8vf-6hwg-hw55/GHSA-f8vf-6hwg-hw55.json @@ -3,9 +3,7 @@ "id": "GHSA-f8vf-6hwg-hw55", "modified": "2021-10-01T20:38:33Z", "published": "2020-09-04T15:38:21Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bictore-lib", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-ff6g-gm92-rf32/GHSA-ff6g-gm92-rf32.json b/advisories/github-reviewed/2020/09/GHSA-ff6g-gm92-rf32/GHSA-ff6g-gm92-rf32.json index 039537b8b1b..5bf5dda48ab 100644 --- a/advisories/github-reviewed/2020/09/GHSA-ff6g-gm92-rf32/GHSA-ff6g-gm92-rf32.json +++ b/advisories/github-reviewed/2020/09/GHSA-ff6g-gm92-rf32/GHSA-ff6g-gm92-rf32.json @@ -3,9 +3,7 @@ "id": "GHSA-ff6g-gm92-rf32", "modified": "2021-10-01T20:58:19Z", "published": "2020-09-03T19:42:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in coinstirng", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-fpf2-pr3j-4cm3/GHSA-fpf2-pr3j-4cm3.json b/advisories/github-reviewed/2020/09/GHSA-fpf2-pr3j-4cm3/GHSA-fpf2-pr3j-4cm3.json index c7238cbab98..48fdb296aa1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-fpf2-pr3j-4cm3/GHSA-fpf2-pr3j-4cm3.json +++ b/advisories/github-reviewed/2020/09/GHSA-fpf2-pr3j-4cm3/GHSA-fpf2-pr3j-4cm3.json @@ -3,9 +3,7 @@ "id": "GHSA-fpf2-pr3j-4cm3", "modified": "2021-10-01T21:01:31Z", "published": "2020-09-03T17:06:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in ecruve", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-fpgg-r39h-3x5x/GHSA-fpgg-r39h-3x5x.json b/advisories/github-reviewed/2020/09/GHSA-fpgg-r39h-3x5x/GHSA-fpgg-r39h-3x5x.json index a3c29244f5e..3127c5dbdf3 100644 --- a/advisories/github-reviewed/2020/09/GHSA-fpgg-r39h-3x5x/GHSA-fpgg-r39h-3x5x.json +++ b/advisories/github-reviewed/2020/09/GHSA-fpgg-r39h-3x5x/GHSA-fpgg-r39h-3x5x.json @@ -3,9 +3,7 @@ "id": "GHSA-fpgg-r39h-3x5x", "modified": "2021-10-01T21:00:43Z", "published": "2020-09-03T17:06:22Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in cxt", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-fwvq-x4j9-hr5f/GHSA-fwvq-x4j9-hr5f.json b/advisories/github-reviewed/2020/09/GHSA-fwvq-x4j9-hr5f/GHSA-fwvq-x4j9-hr5f.json index 4bb1c358f37..494a9c49ef5 100644 --- a/advisories/github-reviewed/2020/09/GHSA-fwvq-x4j9-hr5f/GHSA-fwvq-x4j9-hr5f.json +++ b/advisories/github-reviewed/2020/09/GHSA-fwvq-x4j9-hr5f/GHSA-fwvq-x4j9-hr5f.json @@ -3,9 +3,7 @@ "id": "GHSA-fwvq-x4j9-hr5f", "modified": "2021-10-01T20:50:01Z", "published": "2020-09-03T19:43:09Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bs58chekc", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-g2c4-4m64-vxm3/GHSA-g2c4-4m64-vxm3.json b/advisories/github-reviewed/2020/09/GHSA-g2c4-4m64-vxm3/GHSA-g2c4-4m64-vxm3.json index 40ea3275f1f..e563fe4ffbf 100644 --- a/advisories/github-reviewed/2020/09/GHSA-g2c4-4m64-vxm3/GHSA-g2c4-4m64-vxm3.json +++ b/advisories/github-reviewed/2020/09/GHSA-g2c4-4m64-vxm3/GHSA-g2c4-4m64-vxm3.json @@ -3,9 +3,7 @@ "id": "GHSA-g2c4-4m64-vxm3", "modified": "2021-09-29T21:25:10Z", "published": "2020-09-03T22:15:25Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-yor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-g37j-v5gh-g25c/GHSA-g37j-v5gh-g25c.json b/advisories/github-reviewed/2020/09/GHSA-g37j-v5gh-g25c/GHSA-g37j-v5gh-g25c.json index 263f98fdd17..f8c9144b810 100644 --- a/advisories/github-reviewed/2020/09/GHSA-g37j-v5gh-g25c/GHSA-g37j-v5gh-g25c.json +++ b/advisories/github-reviewed/2020/09/GHSA-g37j-v5gh-g25c/GHSA-g37j-v5gh-g25c.json @@ -3,9 +3,7 @@ "id": "GHSA-g37j-v5gh-g25c", "modified": "2021-09-30T17:14:07Z", "published": "2020-09-03T23:06:48Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-shi3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-g7h8-p22m-2rvx/GHSA-g7h8-p22m-2rvx.json b/advisories/github-reviewed/2020/09/GHSA-g7h8-p22m-2rvx/GHSA-g7h8-p22m-2rvx.json index de513e916ae..a276cc75c87 100644 --- a/advisories/github-reviewed/2020/09/GHSA-g7h8-p22m-2rvx/GHSA-g7h8-p22m-2rvx.json +++ b/advisories/github-reviewed/2020/09/GHSA-g7h8-p22m-2rvx/GHSA-g7h8-p22m-2rvx.json @@ -3,14 +3,10 @@ "id": "GHSA-g7h8-p22m-2rvx", "modified": "2020-08-31T18:55:16Z", "published": "2020-09-04T15:08:46Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in flat-wrap", "details": "All versions of `flat-wrap` are vulnerable to prototype pollution. The function `unflatten` does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-g9r4-xpmj-mj65/GHSA-g9r4-xpmj-mj65.json b/advisories/github-reviewed/2020/09/GHSA-g9r4-xpmj-mj65/GHSA-g9r4-xpmj-mj65.json index c99d83bb5c8..d5a6b2c2f7b 100644 --- a/advisories/github-reviewed/2020/09/GHSA-g9r4-xpmj-mj65/GHSA-g9r4-xpmj-mj65.json +++ b/advisories/github-reviewed/2020/09/GHSA-g9r4-xpmj-mj65/GHSA-g9r4-xpmj-mj65.json @@ -3,14 +3,10 @@ "id": "GHSA-g9r4-xpmj-mj65", "modified": "2020-08-31T18:55:14Z", "published": "2020-09-04T15:06:32Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in handlebars", "details": "Versions of `handlebars` prior to 3.0.8 or 4.5.3 are vulnerable to prototype pollution. It is possible to add or modify properties to the Object prototype through a malicious template. This may allow attackers to crash the application or execute Arbitrary Code in specific conditions.\n\n\n## Recommendation\n\nUpgrade to version 3.0.8, 4.5.3 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-gc25-3vc5-2jf9/GHSA-gc25-3vc5-2jf9.json b/advisories/github-reviewed/2020/09/GHSA-gc25-3vc5-2jf9/GHSA-gc25-3vc5-2jf9.json index 6295724b326..3ff5a6408c8 100644 --- a/advisories/github-reviewed/2020/09/GHSA-gc25-3vc5-2jf9/GHSA-gc25-3vc5-2jf9.json +++ b/advisories/github-reviewed/2020/09/GHSA-gc25-3vc5-2jf9/GHSA-gc25-3vc5-2jf9.json @@ -3,14 +3,10 @@ "id": "GHSA-gc25-3vc5-2jf9", "modified": "2020-08-31T18:54:57Z", "published": "2020-09-04T15:00:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "Sandbox Breakout / Arbitrary Code Execution in sandbox", "details": "All versions of `sandbox` are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through `this.constructor.constructor` . This may allow attackers to execute arbitrary code in the system. Evaluating the payload `this.constructor.constructor('return process.env')()` prints the contents of `process.env`.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:54:57Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-gfj6-p24g-6hpm/GHSA-gfj6-p24g-6hpm.json b/advisories/github-reviewed/2020/09/GHSA-gfj6-p24g-6hpm/GHSA-gfj6-p24g-6hpm.json index 22ab50c5f13..7ec08c8af01 100644 --- a/advisories/github-reviewed/2020/09/GHSA-gfj6-p24g-6hpm/GHSA-gfj6-p24g-6hpm.json +++ b/advisories/github-reviewed/2020/09/GHSA-gfj6-p24g-6hpm/GHSA-gfj6-p24g-6hpm.json @@ -3,9 +3,7 @@ "id": "GHSA-gfj6-p24g-6hpm", "modified": "2021-09-30T16:35:07Z", "published": "2020-09-03T22:55:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in jc-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-gmjp-776j-2394/GHSA-gmjp-776j-2394.json b/advisories/github-reviewed/2020/09/GHSA-gmjp-776j-2394/GHSA-gmjp-776j-2394.json index de0dfec70cd..f370f8ee668 100644 --- a/advisories/github-reviewed/2020/09/GHSA-gmjp-776j-2394/GHSA-gmjp-776j-2394.json +++ b/advisories/github-reviewed/2020/09/GHSA-gmjp-776j-2394/GHSA-gmjp-776j-2394.json @@ -3,9 +3,7 @@ "id": "GHSA-gmjp-776j-2394", "modified": "2021-10-01T21:04:56Z", "published": "2020-09-03T17:04:24Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in ripmed160", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-gpg2-7r7j-4pm9/GHSA-gpg2-7r7j-4pm9.json b/advisories/github-reviewed/2020/09/GHSA-gpg2-7r7j-4pm9/GHSA-gpg2-7r7j-4pm9.json index aa62ec56226..2011d725b80 100644 --- a/advisories/github-reviewed/2020/09/GHSA-gpg2-7r7j-4pm9/GHSA-gpg2-7r7j-4pm9.json +++ b/advisories/github-reviewed/2020/09/GHSA-gpg2-7r7j-4pm9/GHSA-gpg2-7r7j-4pm9.json @@ -3,9 +3,7 @@ "id": "GHSA-gpg2-7r7j-4pm9", "modified": "2021-09-29T21:05:05Z", "published": "2020-09-03T22:09:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-xob", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-gqf6-75v8-vr26/GHSA-gqf6-75v8-vr26.json b/advisories/github-reviewed/2020/09/GHSA-gqf6-75v8-vr26/GHSA-gqf6-75v8-vr26.json index 5ce024ff770..169cf106c98 100644 --- a/advisories/github-reviewed/2020/09/GHSA-gqf6-75v8-vr26/GHSA-gqf6-75v8-vr26.json +++ b/advisories/github-reviewed/2020/09/GHSA-gqf6-75v8-vr26/GHSA-gqf6-75v8-vr26.json @@ -3,14 +3,10 @@ "id": "GHSA-gqf6-75v8-vr26", "modified": "2020-08-31T18:58:56Z", "published": "2020-09-04T16:56:11Z", - "aliases": [ - - ], + "aliases": [], "summary": "Arbitrary File Write in bin-links", "details": "Versions of `bin-links` prior to 1.1.5 are vulnerable to an Arbitrary File Write. The package fails to restrict access to folders outside of the intended `node_modules` folder through the `bin` field. This allows attackers to create arbitrary files in the system. Note it is not possible to overwrite files that already exist.\n\n\n## Recommendation\n\nUpgrade to version 1.1.5 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:58:56Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-gqq4-937c-2282/GHSA-gqq4-937c-2282.json b/advisories/github-reviewed/2020/09/GHSA-gqq4-937c-2282/GHSA-gqq4-937c-2282.json index 371d3134853..5f82b184ce9 100644 --- a/advisories/github-reviewed/2020/09/GHSA-gqq4-937c-2282/GHSA-gqq4-937c-2282.json +++ b/advisories/github-reviewed/2020/09/GHSA-gqq4-937c-2282/GHSA-gqq4-937c-2282.json @@ -3,9 +3,7 @@ "id": "GHSA-gqq4-937c-2282", "modified": "2021-09-30T16:18:15Z", "published": "2020-09-03T22:49:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in juffer-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-gvm7-8fq3-qjj2/GHSA-gvm7-8fq3-qjj2.json b/advisories/github-reviewed/2020/09/GHSA-gvm7-8fq3-qjj2/GHSA-gvm7-8fq3-qjj2.json index 7e03b349a83..011cbd5bf9d 100644 --- a/advisories/github-reviewed/2020/09/GHSA-gvm7-8fq3-qjj2/GHSA-gvm7-8fq3-qjj2.json +++ b/advisories/github-reviewed/2020/09/GHSA-gvm7-8fq3-qjj2/GHSA-gvm7-8fq3-qjj2.json @@ -3,9 +3,7 @@ "id": "GHSA-gvm7-8fq3-qjj2", "modified": "2021-10-01T20:50:15Z", "published": "2020-09-03T19:43:18Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bs85", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-h24p-2c3m-5qf4/GHSA-h24p-2c3m-5qf4.json b/advisories/github-reviewed/2020/09/GHSA-h24p-2c3m-5qf4/GHSA-h24p-2c3m-5qf4.json index 412acb2a912..26c31771da4 100644 --- a/advisories/github-reviewed/2020/09/GHSA-h24p-2c3m-5qf4/GHSA-h24p-2c3m-5qf4.json +++ b/advisories/github-reviewed/2020/09/GHSA-h24p-2c3m-5qf4/GHSA-h24p-2c3m-5qf4.json @@ -3,9 +3,7 @@ "id": "GHSA-h24p-2c3m-5qf4", "modified": "2021-10-01T16:14:52Z", "published": "2020-09-03T23:23:23Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in owl-orchard-apple-sunshine", "details": "All versions of `owl-orchard-apple-sunshine` contain malicious code. The package downloads and runs a script that opens a reverse shell in the system.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-h2j3-gg8w-4858/GHSA-h2j3-gg8w-4858.json b/advisories/github-reviewed/2020/09/GHSA-h2j3-gg8w-4858/GHSA-h2j3-gg8w-4858.json index 6f1f829237e..c7d25ff4fbe 100644 --- a/advisories/github-reviewed/2020/09/GHSA-h2j3-gg8w-4858/GHSA-h2j3-gg8w-4858.json +++ b/advisories/github-reviewed/2020/09/GHSA-h2j3-gg8w-4858/GHSA-h2j3-gg8w-4858.json @@ -3,9 +3,7 @@ "id": "GHSA-h2j3-gg8w-4858", "modified": "2021-09-29T21:12:39Z", "published": "2020-09-03T22:12:09Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-xos", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-h6m3-cx24-9626/GHSA-h6m3-cx24-9626.json b/advisories/github-reviewed/2020/09/GHSA-h6m3-cx24-9626/GHSA-h6m3-cx24-9626.json index af4cb59252b..f48734035c3 100644 --- a/advisories/github-reviewed/2020/09/GHSA-h6m3-cx24-9626/GHSA-h6m3-cx24-9626.json +++ b/advisories/github-reviewed/2020/09/GHSA-h6m3-cx24-9626/GHSA-h6m3-cx24-9626.json @@ -3,9 +3,7 @@ "id": "GHSA-h6m3-cx24-9626", "modified": "2021-10-01T14:15:57Z", "published": "2020-09-03T23:11:45Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-sla3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-hg79-j56m-fxgv/GHSA-hg79-j56m-fxgv.json b/advisories/github-reviewed/2020/09/GHSA-hg79-j56m-fxgv/GHSA-hg79-j56m-fxgv.json index 9e85d365aca..3d289d06835 100644 --- a/advisories/github-reviewed/2020/09/GHSA-hg79-j56m-fxgv/GHSA-hg79-j56m-fxgv.json +++ b/advisories/github-reviewed/2020/09/GHSA-hg79-j56m-fxgv/GHSA-hg79-j56m-fxgv.json @@ -3,14 +3,10 @@ "id": "GHSA-hg79-j56m-fxgv", "modified": "2021-10-01T20:15:16Z", "published": "2020-09-04T15:26:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "Cross-Site Scripting in react", "details": "Versions of `react` prior to 0.14.0 are vulnerable to Cross-Site Scripting (XSS). The package's `createElement` function fails to properly validate its input object, allowing attackers to execute arbitrary JavaScript in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 0.14.0 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-hg7w-2pf7-mxm2/GHSA-hg7w-2pf7-mxm2.json b/advisories/github-reviewed/2020/09/GHSA-hg7w-2pf7-mxm2/GHSA-hg7w-2pf7-mxm2.json index d8344439314..2c77b495f1e 100644 --- a/advisories/github-reviewed/2020/09/GHSA-hg7w-2pf7-mxm2/GHSA-hg7w-2pf7-mxm2.json +++ b/advisories/github-reviewed/2020/09/GHSA-hg7w-2pf7-mxm2/GHSA-hg7w-2pf7-mxm2.json @@ -3,9 +3,7 @@ "id": "GHSA-hg7w-2pf7-mxm2", "modified": "2021-10-04T16:37:42Z", "published": "2020-09-03T17:02:31Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in wbe3", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-hj5w-xgw9-w4rj/GHSA-hj5w-xgw9-w4rj.json b/advisories/github-reviewed/2020/09/GHSA-hj5w-xgw9-w4rj/GHSA-hj5w-xgw9-w4rj.json index b51aec749c6..d7d1dab6ff5 100644 --- a/advisories/github-reviewed/2020/09/GHSA-hj5w-xgw9-w4rj/GHSA-hj5w-xgw9-w4rj.json +++ b/advisories/github-reviewed/2020/09/GHSA-hj5w-xgw9-w4rj/GHSA-hj5w-xgw9-w4rj.json @@ -3,9 +3,7 @@ "id": "GHSA-hj5w-xgw9-w4rj", "modified": "2021-10-01T20:58:49Z", "published": "2020-09-03T19:41:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in coinstrng", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-hrpp-f84w-xhfg/GHSA-hrpp-f84w-xhfg.json b/advisories/github-reviewed/2020/09/GHSA-hrpp-f84w-xhfg/GHSA-hrpp-f84w-xhfg.json index 2d822cf390d..db1cfb41661 100644 --- a/advisories/github-reviewed/2020/09/GHSA-hrpp-f84w-xhfg/GHSA-hrpp-f84w-xhfg.json +++ b/advisories/github-reviewed/2020/09/GHSA-hrpp-f84w-xhfg/GHSA-hrpp-f84w-xhfg.json @@ -3,9 +3,7 @@ "id": "GHSA-hrpp-f84w-xhfg", "modified": "2021-10-04T19:13:23Z", "published": "2020-09-04T16:55:06Z", - "aliases": [ - - ], + "aliases": [], "summary": "Outdated Static Dependency in vue-moment", "details": "Versions of `vue-moment` prior to 4.1.0 contain an Outdated Static Dependency. The package depends on `moment` and has it loaded statically instead of as a dependency that can be updated. It has `moment@2.19.1` that contains a Regular Expression Denial of Service vulnerability.\n\n\n## Recommendation\n\nUpgrade to version 4.1.0 or later.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-hvgc-mggg-pxr2/GHSA-hvgc-mggg-pxr2.json b/advisories/github-reviewed/2020/09/GHSA-hvgc-mggg-pxr2/GHSA-hvgc-mggg-pxr2.json index 1749b80befd..3b22ec72406 100644 --- a/advisories/github-reviewed/2020/09/GHSA-hvgc-mggg-pxr2/GHSA-hvgc-mggg-pxr2.json +++ b/advisories/github-reviewed/2020/09/GHSA-hvgc-mggg-pxr2/GHSA-hvgc-mggg-pxr2.json @@ -3,9 +3,7 @@ "id": "GHSA-hvgc-mggg-pxr2", "modified": "2021-09-30T17:12:40Z", "published": "2020-09-03T23:02:33Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-sha7", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-hwh3-fhf6-73x9/GHSA-hwh3-fhf6-73x9.json b/advisories/github-reviewed/2020/09/GHSA-hwh3-fhf6-73x9/GHSA-hwh3-fhf6-73x9.json index 713fd7b36c5..ae6cb6880d0 100644 --- a/advisories/github-reviewed/2020/09/GHSA-hwh3-fhf6-73x9/GHSA-hwh3-fhf6-73x9.json +++ b/advisories/github-reviewed/2020/09/GHSA-hwh3-fhf6-73x9/GHSA-hwh3-fhf6-73x9.json @@ -3,9 +3,7 @@ "id": "GHSA-hwh3-fhf6-73x9", "modified": "2021-10-01T20:38:19Z", "published": "2020-09-04T15:36:09Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bictoinjs-lib", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-j67m-jg9p-ppg4/GHSA-j67m-jg9p-ppg4.json b/advisories/github-reviewed/2020/09/GHSA-j67m-jg9p-ppg4/GHSA-j67m-jg9p-ppg4.json index bb87970f4ac..832d48b90a2 100644 --- a/advisories/github-reviewed/2020/09/GHSA-j67m-jg9p-ppg4/GHSA-j67m-jg9p-ppg4.json +++ b/advisories/github-reviewed/2020/09/GHSA-j67m-jg9p-ppg4/GHSA-j67m-jg9p-ppg4.json @@ -3,9 +3,7 @@ "id": "GHSA-j67m-jg9p-ppg4", "modified": "2021-10-01T16:10:45Z", "published": "2020-09-03T23:18:05Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in ns-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-j6x7-42x2-hpcf/GHSA-j6x7-42x2-hpcf.json b/advisories/github-reviewed/2020/09/GHSA-j6x7-42x2-hpcf/GHSA-j6x7-42x2-hpcf.json index e1e58ab7dd7..97d7666d4fd 100644 --- a/advisories/github-reviewed/2020/09/GHSA-j6x7-42x2-hpcf/GHSA-j6x7-42x2-hpcf.json +++ b/advisories/github-reviewed/2020/09/GHSA-j6x7-42x2-hpcf/GHSA-j6x7-42x2-hpcf.json @@ -3,9 +3,7 @@ "id": "GHSA-j6x7-42x2-hpcf", "modified": "2021-09-29T21:15:09Z", "published": "2020-09-03T22:14:20Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-xoz", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-jh67-3wqw-cvhr/GHSA-jh67-3wqw-cvhr.json b/advisories/github-reviewed/2020/09/GHSA-jh67-3wqw-cvhr/GHSA-jh67-3wqw-cvhr.json index 349f963ec5a..61cf20fe459 100644 --- a/advisories/github-reviewed/2020/09/GHSA-jh67-3wqw-cvhr/GHSA-jh67-3wqw-cvhr.json +++ b/advisories/github-reviewed/2020/09/GHSA-jh67-3wqw-cvhr/GHSA-jh67-3wqw-cvhr.json @@ -3,9 +3,7 @@ "id": "GHSA-jh67-3wqw-cvhr", "modified": "2021-10-01T14:35:02Z", "published": "2020-09-03T23:13:52Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-sxa3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-jp99-5h8w-gmxc/GHSA-jp99-5h8w-gmxc.json b/advisories/github-reviewed/2020/09/GHSA-jp99-5h8w-gmxc/GHSA-jp99-5h8w-gmxc.json index 1eac12faa6e..b58c50065a6 100644 --- a/advisories/github-reviewed/2020/09/GHSA-jp99-5h8w-gmxc/GHSA-jp99-5h8w-gmxc.json +++ b/advisories/github-reviewed/2020/09/GHSA-jp99-5h8w-gmxc/GHSA-jp99-5h8w-gmxc.json @@ -3,14 +3,10 @@ "id": "GHSA-jp99-5h8w-gmxc", "modified": "2020-08-31T18:55:02Z", "published": "2020-09-04T15:03:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "Sandbox Breakout / Arbitrary Code Execution in @zhaoyao91/eval-in-vm", "details": "All versions of `@zhaoyao91/eval-in-vm` are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through `this.constructor.constructor` . This may allow attackers to execute arbitrary code in the system. Evaluating the payload `this.constructor.constructor('return process.env')()` prints the contents of `process.env`.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:55:02Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-jqjg-v355-hr9q/GHSA-jqjg-v355-hr9q.json b/advisories/github-reviewed/2020/09/GHSA-jqjg-v355-hr9q/GHSA-jqjg-v355-hr9q.json index d7b76fe20c4..a37f93d0948 100644 --- a/advisories/github-reviewed/2020/09/GHSA-jqjg-v355-hr9q/GHSA-jqjg-v355-hr9q.json +++ b/advisories/github-reviewed/2020/09/GHSA-jqjg-v355-hr9q/GHSA-jqjg-v355-hr9q.json @@ -3,9 +3,7 @@ "id": "GHSA-jqjg-v355-hr9q", "modified": "2021-09-29T21:12:22Z", "published": "2020-09-03T22:11:02Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-xop", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-jqvv-r4w3-8f7w/GHSA-jqvv-r4w3-8f7w.json b/advisories/github-reviewed/2020/09/GHSA-jqvv-r4w3-8f7w/GHSA-jqvv-r4w3-8f7w.json index d08e06221d6..5fc93a04079 100644 --- a/advisories/github-reviewed/2020/09/GHSA-jqvv-r4w3-8f7w/GHSA-jqvv-r4w3-8f7w.json +++ b/advisories/github-reviewed/2020/09/GHSA-jqvv-r4w3-8f7w/GHSA-jqvv-r4w3-8f7w.json @@ -3,9 +3,7 @@ "id": "GHSA-jqvv-r4w3-8f7w", "modified": "2021-10-01T20:38:02Z", "published": "2020-09-04T15:35:00Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bictoind-rpc", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-jrj9-5qp6-2v8q/GHSA-jrj9-5qp6-2v8q.json b/advisories/github-reviewed/2020/09/GHSA-jrj9-5qp6-2v8q/GHSA-jrj9-5qp6-2v8q.json index fe82d47c634..cdc7b8e7897 100644 --- a/advisories/github-reviewed/2020/09/GHSA-jrj9-5qp6-2v8q/GHSA-jrj9-5qp6-2v8q.json +++ b/advisories/github-reviewed/2020/09/GHSA-jrj9-5qp6-2v8q/GHSA-jrj9-5qp6-2v8q.json @@ -3,14 +3,10 @@ "id": "GHSA-jrj9-5qp6-2v8q", "modified": "2020-08-31T18:54:28Z", "published": "2020-09-03T23:22:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Machine-In-The-Middle in airtable", "details": "Affected versions of `airtable` are vulnerable to Machine-In-The-Middle. The package has SSL certificate validation disabled by default unintentionally. This may allow attackers in a privileged network position to decrypt intercepted traffic.\n\n\n## Recommendation\n\nUpgrade to version 0.7.2 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:54:28Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-m4fq-xh7w-jhfm/GHSA-m4fq-xh7w-jhfm.json b/advisories/github-reviewed/2020/09/GHSA-m4fq-xh7w-jhfm/GHSA-m4fq-xh7w-jhfm.json index e832adb6f1e..3a1a5fa0e9e 100644 --- a/advisories/github-reviewed/2020/09/GHSA-m4fq-xh7w-jhfm/GHSA-m4fq-xh7w-jhfm.json +++ b/advisories/github-reviewed/2020/09/GHSA-m4fq-xh7w-jhfm/GHSA-m4fq-xh7w-jhfm.json @@ -3,9 +3,7 @@ "id": "GHSA-m4fq-xh7w-jhfm", "modified": "2021-10-01T21:00:29Z", "published": "2020-09-03T19:39:46Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in crytpo-js", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-m6q2-9pfm-2wvr/GHSA-m6q2-9pfm-2wvr.json b/advisories/github-reviewed/2020/09/GHSA-m6q2-9pfm-2wvr/GHSA-m6q2-9pfm-2wvr.json index 41287d199d8..5185a2801ed 100644 --- a/advisories/github-reviewed/2020/09/GHSA-m6q2-9pfm-2wvr/GHSA-m6q2-9pfm-2wvr.json +++ b/advisories/github-reviewed/2020/09/GHSA-m6q2-9pfm-2wvr/GHSA-m6q2-9pfm-2wvr.json @@ -3,9 +3,7 @@ "id": "GHSA-m6q2-9pfm-2wvr", "modified": "2021-10-04T15:56:06Z", "published": "2020-09-03T17:02:49Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in wallet-address-vaildator", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-m794-qv59-gj7c/GHSA-m794-qv59-gj7c.json b/advisories/github-reviewed/2020/09/GHSA-m794-qv59-gj7c/GHSA-m794-qv59-gj7c.json index ef8ccc37f58..064989fcdae 100644 --- a/advisories/github-reviewed/2020/09/GHSA-m794-qv59-gj7c/GHSA-m794-qv59-gj7c.json +++ b/advisories/github-reviewed/2020/09/GHSA-m794-qv59-gj7c/GHSA-m794-qv59-gj7c.json @@ -3,9 +3,7 @@ "id": "GHSA-m794-qv59-gj7c", "modified": "2021-10-04T15:43:26Z", "published": "2020-09-03T17:03:22Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in signqle", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-mgff-xpg3-3gwc/GHSA-mgff-xpg3-3gwc.json b/advisories/github-reviewed/2020/09/GHSA-mgff-xpg3-3gwc/GHSA-mgff-xpg3-3gwc.json index fe074a48f0c..0473ff7ae05 100644 --- a/advisories/github-reviewed/2020/09/GHSA-mgff-xpg3-3gwc/GHSA-mgff-xpg3-3gwc.json +++ b/advisories/github-reviewed/2020/09/GHSA-mgff-xpg3-3gwc/GHSA-mgff-xpg3-3gwc.json @@ -3,9 +3,7 @@ "id": "GHSA-mgff-xpg3-3gwc", "modified": "2021-10-01T20:57:02Z", "published": "2020-09-03T19:42:25Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bsae-x", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-mhxg-pr3j-v9gr/GHSA-mhxg-pr3j-v9gr.json b/advisories/github-reviewed/2020/09/GHSA-mhxg-pr3j-v9gr/GHSA-mhxg-pr3j-v9gr.json index 8f8e42110c7..fa06ee39a8b 100644 --- a/advisories/github-reviewed/2020/09/GHSA-mhxg-pr3j-v9gr/GHSA-mhxg-pr3j-v9gr.json +++ b/advisories/github-reviewed/2020/09/GHSA-mhxg-pr3j-v9gr/GHSA-mhxg-pr3j-v9gr.json @@ -3,9 +3,7 @@ "id": "GHSA-mhxg-pr3j-v9gr", "modified": "2021-10-01T20:59:03Z", "published": "2020-09-03T19:41:22Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in colne", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-mmqv-m45h-q2hp/GHSA-mmqv-m45h-q2hp.json b/advisories/github-reviewed/2020/09/GHSA-mmqv-m45h-q2hp/GHSA-mmqv-m45h-q2hp.json index 6153578ac81..f34761b4c80 100644 --- a/advisories/github-reviewed/2020/09/GHSA-mmqv-m45h-q2hp/GHSA-mmqv-m45h-q2hp.json +++ b/advisories/github-reviewed/2020/09/GHSA-mmqv-m45h-q2hp/GHSA-mmqv-m45h-q2hp.json @@ -3,14 +3,10 @@ "id": "GHSA-mmqv-m45h-q2hp", "modified": "2022-03-14T23:59:01Z", "published": "2020-09-04T15:22:40Z", - "aliases": [ - - ], + "aliases": [], "summary": "Sandbox Breakout / Arbitrary Code Execution in localeval", "details": "All versions of `localeval` are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through `constructor.constructor`. This may allow attackers to execute arbitrary code in the system. Evaluating the payload \n```\nconstructor.constructor(\"return process.env\")()\n``` \n\nreturns the contents of `process.env`.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -51,9 +47,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:55:41Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-p3jx-g34v-q56j/GHSA-p3jx-g34v-q56j.json b/advisories/github-reviewed/2020/09/GHSA-p3jx-g34v-q56j/GHSA-p3jx-g34v-q56j.json index 60e39b313ec..53068c4c794 100644 --- a/advisories/github-reviewed/2020/09/GHSA-p3jx-g34v-q56j/GHSA-p3jx-g34v-q56j.json +++ b/advisories/github-reviewed/2020/09/GHSA-p3jx-g34v-q56j/GHSA-p3jx-g34v-q56j.json @@ -3,9 +3,7 @@ "id": "GHSA-p3jx-g34v-q56j", "modified": "2021-09-30T16:31:54Z", "published": "2020-09-03T22:54:02Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in j3-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-p4mf-4qvh-w8g5/GHSA-p4mf-4qvh-w8g5.json b/advisories/github-reviewed/2020/09/GHSA-p4mf-4qvh-w8g5/GHSA-p4mf-4qvh-w8g5.json index 9129067c540..0595f8538f4 100644 --- a/advisories/github-reviewed/2020/09/GHSA-p4mf-4qvh-w8g5/GHSA-p4mf-4qvh-w8g5.json +++ b/advisories/github-reviewed/2020/09/GHSA-p4mf-4qvh-w8g5/GHSA-p4mf-4qvh-w8g5.json @@ -3,9 +3,7 @@ "id": "GHSA-p4mf-4qvh-w8g5", "modified": "2021-10-01T20:39:41Z", "published": "2020-09-04T15:41:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcionjslib", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-p5p2-rhc3-wmf3/GHSA-p5p2-rhc3-wmf3.json b/advisories/github-reviewed/2020/09/GHSA-p5p2-rhc3-wmf3/GHSA-p5p2-rhc3-wmf3.json index 4b3bc47f97c..703d07222ba 100644 --- a/advisories/github-reviewed/2020/09/GHSA-p5p2-rhc3-wmf3/GHSA-p5p2-rhc3-wmf3.json +++ b/advisories/github-reviewed/2020/09/GHSA-p5p2-rhc3-wmf3/GHSA-p5p2-rhc3-wmf3.json @@ -3,9 +3,7 @@ "id": "GHSA-p5p2-rhc3-wmf3", "modified": "2021-10-04T15:40:00Z", "published": "2020-09-03T17:03:31Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in siganle", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-p7qp-3fh7-pv4p/GHSA-p7qp-3fh7-pv4p.json b/advisories/github-reviewed/2020/09/GHSA-p7qp-3fh7-pv4p/GHSA-p7qp-3fh7-pv4p.json index ccfae878202..6c93bf370df 100644 --- a/advisories/github-reviewed/2020/09/GHSA-p7qp-3fh7-pv4p/GHSA-p7qp-3fh7-pv4p.json +++ b/advisories/github-reviewed/2020/09/GHSA-p7qp-3fh7-pv4p/GHSA-p7qp-3fh7-pv4p.json @@ -3,9 +3,7 @@ "id": "GHSA-p7qp-3fh7-pv4p", "modified": "2021-09-29T21:27:36Z", "published": "2020-09-03T22:24:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffur-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-pc7q-c837-3wjq/GHSA-pc7q-c837-3wjq.json b/advisories/github-reviewed/2020/09/GHSA-pc7q-c837-3wjq/GHSA-pc7q-c837-3wjq.json index 4449c18d877..4322414dd35 100644 --- a/advisories/github-reviewed/2020/09/GHSA-pc7q-c837-3wjq/GHSA-pc7q-c837-3wjq.json +++ b/advisories/github-reviewed/2020/09/GHSA-pc7q-c837-3wjq/GHSA-pc7q-c837-3wjq.json @@ -3,9 +3,7 @@ "id": "GHSA-pc7q-c837-3wjq", "modified": "2021-10-04T15:56:21Z", "published": "2020-09-03T17:02:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in wallet-address-validtaor", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-q2c6-c6pm-g3gh/GHSA-q2c6-c6pm-g3gh.json b/advisories/github-reviewed/2020/09/GHSA-q2c6-c6pm-g3gh/GHSA-q2c6-c6pm-g3gh.json index cb47a167289..51355f5c9f6 100644 --- a/advisories/github-reviewed/2020/09/GHSA-q2c6-c6pm-g3gh/GHSA-q2c6-c6pm-g3gh.json +++ b/advisories/github-reviewed/2020/09/GHSA-q2c6-c6pm-g3gh/GHSA-q2c6-c6pm-g3gh.json @@ -3,14 +3,10 @@ "id": "GHSA-q2c6-c6pm-g3gh", "modified": "2020-08-31T18:55:11Z", "published": "2020-09-04T15:07:38Z", - "aliases": [ - - ], + "aliases": [], "summary": "Arbitrary Code Execution in handlebars", "details": "Versions of `handlebars` prior to 3.0.8 or 4.5.3 are vulnerable to Arbitrary Code Execution. The package's lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript in the system. It is due to an incomplete fix for a [previous issue](https://www.npmjs.com/advisories/1316). This vulnerability can be used to run arbitrary code in a server processing Handlebars templates or on a victim's browser (effectively serving as Cross-Site Scripting).\n\n\n## Recommendation\n\nUpgrade to version 3.0.8, 4.5.3 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -58,9 +54,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:55:11Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-q9wr-gcjc-hq52/GHSA-q9wr-gcjc-hq52.json b/advisories/github-reviewed/2020/09/GHSA-q9wr-gcjc-hq52/GHSA-q9wr-gcjc-hq52.json index abdd9512266..57d97003a04 100644 --- a/advisories/github-reviewed/2020/09/GHSA-q9wr-gcjc-hq52/GHSA-q9wr-gcjc-hq52.json +++ b/advisories/github-reviewed/2020/09/GHSA-q9wr-gcjc-hq52/GHSA-q9wr-gcjc-hq52.json @@ -3,14 +3,10 @@ "id": "GHSA-q9wr-gcjc-hq52", "modified": "2020-08-31T18:55:23Z", "published": "2020-09-04T15:12:13Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in reggae", "details": "All versions of `reggae` are vulnerable to prototype pollution. The function `set` does not restrict the modification of an Object's prototype, which may allow a malicious to add or modify an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-qccf-q7p4-3q3j/GHSA-qccf-q7p4-3q3j.json b/advisories/github-reviewed/2020/09/GHSA-qccf-q7p4-3q3j/GHSA-qccf-q7p4-3q3j.json index 7d950b846dc..98323c22c9f 100644 --- a/advisories/github-reviewed/2020/09/GHSA-qccf-q7p4-3q3j/GHSA-qccf-q7p4-3q3j.json +++ b/advisories/github-reviewed/2020/09/GHSA-qccf-q7p4-3q3j/GHSA-qccf-q7p4-3q3j.json @@ -3,14 +3,10 @@ "id": "GHSA-qccf-q7p4-3q3j", "modified": "2020-08-31T18:55:32Z", "published": "2020-09-04T15:16:42Z", - "aliases": [ - - ], + "aliases": [], "summary": "Prototype Pollution in safe-object2", "details": "All versions of `safe-object2` are vulnerable to prototype pollution. The `settter()` function does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-qmgf-fp85-55gr/GHSA-qmgf-fp85-55gr.json b/advisories/github-reviewed/2020/09/GHSA-qmgf-fp85-55gr/GHSA-qmgf-fp85-55gr.json index d3f385c9cf5..9a020ffedd9 100644 --- a/advisories/github-reviewed/2020/09/GHSA-qmgf-fp85-55gr/GHSA-qmgf-fp85-55gr.json +++ b/advisories/github-reviewed/2020/09/GHSA-qmgf-fp85-55gr/GHSA-qmgf-fp85-55gr.json @@ -3,9 +3,7 @@ "id": "GHSA-qmgf-fp85-55gr", "modified": "2021-10-01T20:39:27Z", "published": "2020-09-04T15:40:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcionjs", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-qp6m-jqfr-2f7v/GHSA-qp6m-jqfr-2f7v.json b/advisories/github-reviewed/2020/09/GHSA-qp6m-jqfr-2f7v/GHSA-qp6m-jqfr-2f7v.json index 3fbd9f64664..85bd1071f4f 100644 --- a/advisories/github-reviewed/2020/09/GHSA-qp6m-jqfr-2f7v/GHSA-qp6m-jqfr-2f7v.json +++ b/advisories/github-reviewed/2020/09/GHSA-qp6m-jqfr-2f7v/GHSA-qp6m-jqfr-2f7v.json @@ -3,9 +3,7 @@ "id": "GHSA-qp6m-jqfr-2f7v", "modified": "2021-10-01T20:17:24Z", "published": "2020-09-04T15:27:11Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in babel-laoder", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-qxrj-x7rm-2h49/GHSA-qxrj-x7rm-2h49.json b/advisories/github-reviewed/2020/09/GHSA-qxrj-x7rm-2h49/GHSA-qxrj-x7rm-2h49.json index b5ed27aa7c6..c94de0ab589 100644 --- a/advisories/github-reviewed/2020/09/GHSA-qxrj-x7rm-2h49/GHSA-qxrj-x7rm-2h49.json +++ b/advisories/github-reviewed/2020/09/GHSA-qxrj-x7rm-2h49/GHSA-qxrj-x7rm-2h49.json @@ -3,9 +3,7 @@ "id": "GHSA-qxrj-x7rm-2h49", "modified": "2021-10-01T21:01:13Z", "published": "2020-09-03T17:05:59Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in dhkey", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-r742-7j4h-hjr8/GHSA-r742-7j4h-hjr8.json b/advisories/github-reviewed/2020/09/GHSA-r742-7j4h-hjr8/GHSA-r742-7j4h-hjr8.json index f37f5c8c767..1c827bd5543 100644 --- a/advisories/github-reviewed/2020/09/GHSA-r742-7j4h-hjr8/GHSA-r742-7j4h-hjr8.json +++ b/advisories/github-reviewed/2020/09/GHSA-r742-7j4h-hjr8/GHSA-r742-7j4h-hjr8.json @@ -3,9 +3,7 @@ "id": "GHSA-r742-7j4h-hjr8", "modified": "2021-10-01T17:07:41Z", "published": "2020-09-03T23:27:36Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in arsenic-tabasco-cyborg-peanut-butter", "details": "All versions of `arsenic-tabasco-cyborg-peanut-butter` contain malicious code. The package downloads and runs a script that opens a reverse shell in the system.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-r8hx-3qx6-hxq9/GHSA-r8hx-3qx6-hxq9.json b/advisories/github-reviewed/2020/09/GHSA-r8hx-3qx6-hxq9/GHSA-r8hx-3qx6-hxq9.json index abc3d0962a1..f39994b52aa 100644 --- a/advisories/github-reviewed/2020/09/GHSA-r8hx-3qx6-hxq9/GHSA-r8hx-3qx6-hxq9.json +++ b/advisories/github-reviewed/2020/09/GHSA-r8hx-3qx6-hxq9/GHSA-r8hx-3qx6-hxq9.json @@ -3,9 +3,7 @@ "id": "GHSA-r8hx-3qx6-hxq9", "modified": "2021-10-01T20:59:17Z", "published": "2020-09-03T19:41:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in commandre", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-r9cj-xj33-4q42/GHSA-r9cj-xj33-4q42.json b/advisories/github-reviewed/2020/09/GHSA-r9cj-xj33-4q42/GHSA-r9cj-xj33-4q42.json index 6ffb5a04d92..1725e579ed3 100644 --- a/advisories/github-reviewed/2020/09/GHSA-r9cj-xj33-4q42/GHSA-r9cj-xj33-4q42.json +++ b/advisories/github-reviewed/2020/09/GHSA-r9cj-xj33-4q42/GHSA-r9cj-xj33-4q42.json @@ -3,9 +3,7 @@ "id": "GHSA-r9cj-xj33-4q42", "modified": "2021-09-29T21:26:56Z", "published": "2020-09-03T22:21:54Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffgr-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-rcv7-4w2m-gj9v/GHSA-rcv7-4w2m-gj9v.json b/advisories/github-reviewed/2020/09/GHSA-rcv7-4w2m-gj9v/GHSA-rcv7-4w2m-gj9v.json index c0c972324d7..03a72825ad4 100644 --- a/advisories/github-reviewed/2020/09/GHSA-rcv7-4w2m-gj9v/GHSA-rcv7-4w2m-gj9v.json +++ b/advisories/github-reviewed/2020/09/GHSA-rcv7-4w2m-gj9v/GHSA-rcv7-4w2m-gj9v.json @@ -3,9 +3,7 @@ "id": "GHSA-rcv7-4w2m-gj9v", "modified": "2021-10-01T16:15:09Z", "published": "2020-09-03T23:24:26Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in sj-tw-test-security", "details": "All versions of `sj-tw-test-security` contain malicious code. The package downloads and runs a script that opens a reverse shell in the system.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-rv6q-p3x7-43fx/GHSA-rv6q-p3x7-43fx.json b/advisories/github-reviewed/2020/09/GHSA-rv6q-p3x7-43fx/GHSA-rv6q-p3x7-43fx.json index c23bd1a4d16..f5287309dc2 100644 --- a/advisories/github-reviewed/2020/09/GHSA-rv6q-p3x7-43fx/GHSA-rv6q-p3x7-43fx.json +++ b/advisories/github-reviewed/2020/09/GHSA-rv6q-p3x7-43fx/GHSA-rv6q-p3x7-43fx.json @@ -3,9 +3,7 @@ "id": "GHSA-rv6q-p3x7-43fx", "modified": "2021-10-01T20:42:01Z", "published": "2020-09-04T16:37:50Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcoimjs-lib", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-rw53-q8x7-ccx8/GHSA-rw53-q8x7-ccx8.json b/advisories/github-reviewed/2020/09/GHSA-rw53-q8x7-ccx8/GHSA-rw53-q8x7-ccx8.json index aa13cd01274..8047b7a131e 100644 --- a/advisories/github-reviewed/2020/09/GHSA-rw53-q8x7-ccx8/GHSA-rw53-q8x7-ccx8.json +++ b/advisories/github-reviewed/2020/09/GHSA-rw53-q8x7-ccx8/GHSA-rw53-q8x7-ccx8.json @@ -3,9 +3,7 @@ "id": "GHSA-rw53-q8x7-ccx8", "modified": "2021-09-29T21:04:00Z", "published": "2020-09-03T21:55:17Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffer-xkr", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-rwcq-qpm6-7867/GHSA-rwcq-qpm6-7867.json b/advisories/github-reviewed/2020/09/GHSA-rwcq-qpm6-7867/GHSA-rwcq-qpm6-7867.json index 3c889aee0a5..ef0fbe16618 100644 --- a/advisories/github-reviewed/2020/09/GHSA-rwcq-qpm6-7867/GHSA-rwcq-qpm6-7867.json +++ b/advisories/github-reviewed/2020/09/GHSA-rwcq-qpm6-7867/GHSA-rwcq-qpm6-7867.json @@ -3,9 +3,7 @@ "id": "GHSA-rwcq-qpm6-7867", "modified": "2021-10-01T21:04:25Z", "published": "2020-09-03T17:04:32Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in riped160", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-rwmv-c7v8-v9vf/GHSA-rwmv-c7v8-v9vf.json b/advisories/github-reviewed/2020/09/GHSA-rwmv-c7v8-v9vf/GHSA-rwmv-c7v8-v9vf.json index dbbc42bc03e..772597371ab 100644 --- a/advisories/github-reviewed/2020/09/GHSA-rwmv-c7v8-v9vf/GHSA-rwmv-c7v8-v9vf.json +++ b/advisories/github-reviewed/2020/09/GHSA-rwmv-c7v8-v9vf/GHSA-rwmv-c7v8-v9vf.json @@ -3,9 +3,7 @@ "id": "GHSA-rwmv-c7v8-v9vf", "modified": "2021-10-01T20:40:15Z", "published": "2020-09-04T16:36:45Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcoimd-rpc", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-v45m-2wcp-gg98/GHSA-v45m-2wcp-gg98.json b/advisories/github-reviewed/2020/09/GHSA-v45m-2wcp-gg98/GHSA-v45m-2wcp-gg98.json index eca5304e4c1..1081ff20f03 100644 --- a/advisories/github-reviewed/2020/09/GHSA-v45m-2wcp-gg98/GHSA-v45m-2wcp-gg98.json +++ b/advisories/github-reviewed/2020/09/GHSA-v45m-2wcp-gg98/GHSA-v45m-2wcp-gg98.json @@ -3,14 +3,10 @@ "id": "GHSA-v45m-2wcp-gg98", "modified": "2020-08-31T18:59:19Z", "published": "2020-09-04T17:18:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "Global node_modules Binary Overwrite in bin-links", "details": "Versions of `bin-links` prior to 1.1.6 are vulnerable to a Global node_modules Binary Overwrite. It fails to prevent globally-installed binaries to be overwritten by other package installs. For example, if a package was installed globally and created a `serve` binary, any subsequent installs of packages that also create a `serve` binary would overwrite the first binary. This behavior is still allowed in local installations.\n\n\n## Recommendation\n\nUpgrade to version 1.1.6 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -39,9 +35,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2020-08-31T18:59:19Z", diff --git a/advisories/github-reviewed/2020/09/GHSA-v6c5-hwqg-3x5q/GHSA-v6c5-hwqg-3x5q.json b/advisories/github-reviewed/2020/09/GHSA-v6c5-hwqg-3x5q/GHSA-v6c5-hwqg-3x5q.json index b30f04b1f75..792241a7fd1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-v6c5-hwqg-3x5q/GHSA-v6c5-hwqg-3x5q.json +++ b/advisories/github-reviewed/2020/09/GHSA-v6c5-hwqg-3x5q/GHSA-v6c5-hwqg-3x5q.json @@ -8,9 +8,7 @@ ], "summary": "Improper Authorization in passport-cognito", "details": "All versions of `passport-cognito` are vulnerable to Improper Authorization. The package fails to properly scope the variables containing authorization information, such as access token, refresh token and ID token. This causes a race condition where simultaneous authenticated users may receive authorization tokens for a different user. This would allow a user to take actions on another user's behalf.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-v8g7-9qv2-j865/GHSA-v8g7-9qv2-j865.json b/advisories/github-reviewed/2020/09/GHSA-v8g7-9qv2-j865/GHSA-v8g7-9qv2-j865.json index 4b252afd14c..b7f17ace92c 100644 --- a/advisories/github-reviewed/2020/09/GHSA-v8g7-9qv2-j865/GHSA-v8g7-9qv2-j865.json +++ b/advisories/github-reviewed/2020/09/GHSA-v8g7-9qv2-j865/GHSA-v8g7-9qv2-j865.json @@ -3,9 +3,7 @@ "id": "GHSA-v8g7-9qv2-j865", "modified": "2021-10-01T20:42:19Z", "published": "2020-09-04T16:38:55Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitcoin-osp", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-vf5m-q45w-8mh9/GHSA-vf5m-q45w-8mh9.json b/advisories/github-reviewed/2020/09/GHSA-vf5m-q45w-8mh9/GHSA-vf5m-q45w-8mh9.json index 59861d70fbc..2a5d5cd96bf 100644 --- a/advisories/github-reviewed/2020/09/GHSA-vf5m-q45w-8mh9/GHSA-vf5m-q45w-8mh9.json +++ b/advisories/github-reviewed/2020/09/GHSA-vf5m-q45w-8mh9/GHSA-vf5m-q45w-8mh9.json @@ -3,9 +3,7 @@ "id": "GHSA-vf5m-q45w-8mh9", "modified": "2021-09-30T17:01:14Z", "published": "2020-09-03T23:00:25Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in js-qha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-vrxj-4qhw-5vwq/GHSA-vrxj-4qhw-5vwq.json b/advisories/github-reviewed/2020/09/GHSA-vrxj-4qhw-5vwq/GHSA-vrxj-4qhw-5vwq.json index 50b9ae13925..c2063badfdc 100644 --- a/advisories/github-reviewed/2020/09/GHSA-vrxj-4qhw-5vwq/GHSA-vrxj-4qhw-5vwq.json +++ b/advisories/github-reviewed/2020/09/GHSA-vrxj-4qhw-5vwq/GHSA-vrxj-4qhw-5vwq.json @@ -3,9 +3,7 @@ "id": "GHSA-vrxj-4qhw-5vwq", "modified": "2021-10-04T14:29:03Z", "published": "2020-09-03T17:03:41Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in scryptys", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-vv7g-pjw9-4qj9/GHSA-vv7g-pjw9-4qj9.json b/advisories/github-reviewed/2020/09/GHSA-vv7g-pjw9-4qj9/GHSA-vv7g-pjw9-4qj9.json index 00b95263379..a9fb596cb7c 100644 --- a/advisories/github-reviewed/2020/09/GHSA-vv7g-pjw9-4qj9/GHSA-vv7g-pjw9-4qj9.json +++ b/advisories/github-reviewed/2020/09/GHSA-vv7g-pjw9-4qj9/GHSA-vv7g-pjw9-4qj9.json @@ -3,9 +3,7 @@ "id": "GHSA-vv7g-pjw9-4qj9", "modified": "2021-10-04T15:24:14Z", "published": "2020-09-03T17:03:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in scrytsy", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-vvfh-mvjv-w38q/GHSA-vvfh-mvjv-w38q.json b/advisories/github-reviewed/2020/09/GHSA-vvfh-mvjv-w38q/GHSA-vvfh-mvjv-w38q.json index f82857d13e6..7ab8359f9e1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-vvfh-mvjv-w38q/GHSA-vvfh-mvjv-w38q.json +++ b/advisories/github-reviewed/2020/09/GHSA-vvfh-mvjv-w38q/GHSA-vvfh-mvjv-w38q.json @@ -3,9 +3,7 @@ "id": "GHSA-vvfh-mvjv-w38q", "modified": "2021-10-01T20:17:42Z", "published": "2020-09-04T15:28:19Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in babel-loadre", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-w9hw-v97w-g5f5/GHSA-w9hw-v97w-g5f5.json b/advisories/github-reviewed/2020/09/GHSA-w9hw-v97w-g5f5/GHSA-w9hw-v97w-g5f5.json index 5edc477b17a..e5987ee8a22 100644 --- a/advisories/github-reviewed/2020/09/GHSA-w9hw-v97w-g5f5/GHSA-w9hw-v97w-g5f5.json +++ b/advisories/github-reviewed/2020/09/GHSA-w9hw-v97w-g5f5/GHSA-w9hw-v97w-g5f5.json @@ -3,9 +3,7 @@ "id": "GHSA-w9hw-v97w-g5f5", "modified": "2021-10-01T20:43:23Z", "published": "2020-09-04T16:43:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bitconi-ops", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-wch2-46wj-6x5j/GHSA-wch2-46wj-6x5j.json b/advisories/github-reviewed/2020/09/GHSA-wch2-46wj-6x5j/GHSA-wch2-46wj-6x5j.json index 71486ff12de..fbc3d8022d7 100644 --- a/advisories/github-reviewed/2020/09/GHSA-wch2-46wj-6x5j/GHSA-wch2-46wj-6x5j.json +++ b/advisories/github-reviewed/2020/09/GHSA-wch2-46wj-6x5j/GHSA-wch2-46wj-6x5j.json @@ -3,9 +3,7 @@ "id": "GHSA-wch2-46wj-6x5j", "modified": "2021-10-01T20:38:52Z", "published": "2020-09-04T15:37:15Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bip30", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-whv6-rj84-2vh2/GHSA-whv6-rj84-2vh2.json b/advisories/github-reviewed/2020/09/GHSA-whv6-rj84-2vh2/GHSA-whv6-rj84-2vh2.json index e3efbe87186..218c2403a21 100644 --- a/advisories/github-reviewed/2020/09/GHSA-whv6-rj84-2vh2/GHSA-whv6-rj84-2vh2.json +++ b/advisories/github-reviewed/2020/09/GHSA-whv6-rj84-2vh2/GHSA-whv6-rj84-2vh2.json @@ -3,14 +3,10 @@ "id": "GHSA-whv6-rj84-2vh2", "modified": "2021-10-04T20:36:41Z", "published": "2020-09-04T17:21:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "Cross-Site Scripting in nextcloud-vue-collections", "details": "Versions of `nextcloud-vue-collections` prior to 0.4.2 are vulnerable to Cross-Site Scripting (XSS). The `v-tooltip` component has an insecure `defaultHTML` configuration that allows arbitrary JavaScript to be injected in the tooltip of a collection item. This allows attackers to execute arbitrary code in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 0.4.2 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-wjpj-gmc3-5w56/GHSA-wjpj-gmc3-5w56.json b/advisories/github-reviewed/2020/09/GHSA-wjpj-gmc3-5w56/GHSA-wjpj-gmc3-5w56.json index cbc29aa98db..fbb1e92fda7 100644 --- a/advisories/github-reviewed/2020/09/GHSA-wjpj-gmc3-5w56/GHSA-wjpj-gmc3-5w56.json +++ b/advisories/github-reviewed/2020/09/GHSA-wjpj-gmc3-5w56/GHSA-wjpj-gmc3-5w56.json @@ -3,9 +3,7 @@ "id": "GHSA-wjpj-gmc3-5w56", "modified": "2021-09-30T15:46:02Z", "published": "2020-09-03T22:30:31Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buvfer-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-wv39-cgmm-cq29/GHSA-wv39-cgmm-cq29.json b/advisories/github-reviewed/2020/09/GHSA-wv39-cgmm-cq29/GHSA-wv39-cgmm-cq29.json index 59e4a296b10..a651bb3e495 100644 --- a/advisories/github-reviewed/2020/09/GHSA-wv39-cgmm-cq29/GHSA-wv39-cgmm-cq29.json +++ b/advisories/github-reviewed/2020/09/GHSA-wv39-cgmm-cq29/GHSA-wv39-cgmm-cq29.json @@ -3,9 +3,7 @@ "id": "GHSA-wv39-cgmm-cq29", "modified": "2021-09-29T21:27:19Z", "published": "2020-09-03T22:23:00Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffmr-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-wx77-rp39-c6vg/GHSA-wx77-rp39-c6vg.json b/advisories/github-reviewed/2020/09/GHSA-wx77-rp39-c6vg/GHSA-wx77-rp39-c6vg.json index 60f90f265c4..ccc24656fb1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-wx77-rp39-c6vg/GHSA-wx77-rp39-c6vg.json +++ b/advisories/github-reviewed/2020/09/GHSA-wx77-rp39-c6vg/GHSA-wx77-rp39-c6vg.json @@ -3,14 +3,10 @@ "id": "GHSA-wx77-rp39-c6vg", "modified": "2022-03-24T22:10:13Z", "published": "2020-09-04T15:11:03Z", - "aliases": [ - - ], + "aliases": [], "summary": "Regular Expression Denial of Service in markdown", "details": "All versions of `markdown` are vulnerable to Regular Expression Denial of Service (ReDoS). The `markdown.toHTML()` function has significantly degraded performance when parsing long strings containing underscores. This may lead to Denial of Service if the parser accepts user input.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-x3w4-mrmv-cw2x/GHSA-x3w4-mrmv-cw2x.json b/advisories/github-reviewed/2020/09/GHSA-x3w4-mrmv-cw2x/GHSA-x3w4-mrmv-cw2x.json index 1b0fcf6059a..3e9620c48fe 100644 --- a/advisories/github-reviewed/2020/09/GHSA-x3w4-mrmv-cw2x/GHSA-x3w4-mrmv-cw2x.json +++ b/advisories/github-reviewed/2020/09/GHSA-x3w4-mrmv-cw2x/GHSA-x3w4-mrmv-cw2x.json @@ -3,9 +3,7 @@ "id": "GHSA-x3w4-mrmv-cw2x", "modified": "2021-09-29T21:26:19Z", "published": "2020-09-03T22:19:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in buffev-xor", "details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-x8m7-cv39-xmg9/GHSA-x8m7-cv39-xmg9.json b/advisories/github-reviewed/2020/09/GHSA-x8m7-cv39-xmg9/GHSA-x8m7-cv39-xmg9.json index a555bca862b..f21e1bc302b 100644 --- a/advisories/github-reviewed/2020/09/GHSA-x8m7-cv39-xmg9/GHSA-x8m7-cv39-xmg9.json +++ b/advisories/github-reviewed/2020/09/GHSA-x8m7-cv39-xmg9/GHSA-x8m7-cv39-xmg9.json @@ -3,9 +3,7 @@ "id": "GHSA-x8m7-cv39-xmg9", "modified": "2021-09-30T16:35:22Z", "published": "2020-09-03T22:56:10Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in jq-sha3", "details": "Version 0.8.0 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-xcgx-27q5-7634/GHSA-xcgx-27q5-7634.json b/advisories/github-reviewed/2020/09/GHSA-xcgx-27q5-7634/GHSA-xcgx-27q5-7634.json index 994c9f13444..3e2f1e42e1c 100644 --- a/advisories/github-reviewed/2020/09/GHSA-xcgx-27q5-7634/GHSA-xcgx-27q5-7634.json +++ b/advisories/github-reviewed/2020/09/GHSA-xcgx-27q5-7634/GHSA-xcgx-27q5-7634.json @@ -3,9 +3,7 @@ "id": "GHSA-xcgx-27q5-7634", "modified": "2021-10-01T20:59:32Z", "published": "2020-09-03T19:41:05Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in commanedr", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-xf64-2f9p-6pqq/GHSA-xf64-2f9p-6pqq.json b/advisories/github-reviewed/2020/09/GHSA-xf64-2f9p-6pqq/GHSA-xf64-2f9p-6pqq.json index 2aac63f1cc2..0d249109d84 100644 --- a/advisories/github-reviewed/2020/09/GHSA-xf64-2f9p-6pqq/GHSA-xf64-2f9p-6pqq.json +++ b/advisories/github-reviewed/2020/09/GHSA-xf64-2f9p-6pqq/GHSA-xf64-2f9p-6pqq.json @@ -3,14 +3,10 @@ "id": "GHSA-xf64-2f9p-6pqq", "modified": "2020-08-31T18:59:32Z", "published": "2020-09-04T17:24:08Z", - "aliases": [ - - ], + "aliases": [], "summary": "Information Exposure in type-graphql", "details": "Versions of `type-graphql` prior to 0.17.6 are vulnerable to Information Exposure. The package leaks the resolver source code in an error message. It is possible to force this error when no subscription topics are provided in the request.\n\n\n## Recommendation\n\nUpgrade to version 0.17.6 or later.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2020/09/GHSA-xh8g-j88w-6v59/GHSA-xh8g-j88w-6v59.json b/advisories/github-reviewed/2020/09/GHSA-xh8g-j88w-6v59/GHSA-xh8g-j88w-6v59.json index d7a96afbe78..e92ea4c4405 100644 --- a/advisories/github-reviewed/2020/09/GHSA-xh8g-j88w-6v59/GHSA-xh8g-j88w-6v59.json +++ b/advisories/github-reviewed/2020/09/GHSA-xh8g-j88w-6v59/GHSA-xh8g-j88w-6v59.json @@ -3,9 +3,7 @@ "id": "GHSA-xh8g-j88w-6v59", "modified": "2021-10-01T20:57:22Z", "published": "2020-09-03T19:42:16Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in cionstring", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-xr3g-4gg5-w3wq/GHSA-xr3g-4gg5-w3wq.json b/advisories/github-reviewed/2020/09/GHSA-xr3g-4gg5-w3wq/GHSA-xr3g-4gg5-w3wq.json index bc1bd9b1f4a..e4437a56b53 100644 --- a/advisories/github-reviewed/2020/09/GHSA-xr3g-4gg5-w3wq/GHSA-xr3g-4gg5-w3wq.json +++ b/advisories/github-reviewed/2020/09/GHSA-xr3g-4gg5-w3wq/GHSA-xr3g-4gg5-w3wq.json @@ -3,9 +3,7 @@ "id": "GHSA-xr3g-4gg5-w3wq", "modified": "2021-10-01T21:00:58Z", "published": "2020-09-03T17:06:14Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in degbu", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2020/09/GHSA-xrrg-wfwc-c7r3/GHSA-xrrg-wfwc-c7r3.json b/advisories/github-reviewed/2020/09/GHSA-xrrg-wfwc-c7r3/GHSA-xrrg-wfwc-c7r3.json index d3c98735be9..1b802a47371 100644 --- a/advisories/github-reviewed/2020/09/GHSA-xrrg-wfwc-c7r3/GHSA-xrrg-wfwc-c7r3.json +++ b/advisories/github-reviewed/2020/09/GHSA-xrrg-wfwc-c7r3/GHSA-xrrg-wfwc-c7r3.json @@ -3,9 +3,7 @@ "id": "GHSA-xrrg-wfwc-c7r3", "modified": "2021-10-01T20:37:47Z", "published": "2020-09-04T15:33:52Z", - "aliases": [ - - ], + "aliases": [], "summary": "Malicious Package in bictoin-ops", "details": "All versions of this package contained malware. The package was designed to find and exfiltrate cryptocurrency wallets.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", "severity": [ diff --git a/advisories/github-reviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json b/advisories/github-reviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json index f8e0c80ae52..0be9c7a8b83 100644 --- a/advisories/github-reviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json +++ b/advisories/github-reviewed/2024/06/GHSA-869c-j7wc-8jqv/GHSA-869c-j7wc-8jqv.json @@ -89,9 +89,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-07-01T21:30:24Z", diff --git a/advisories/unreviewed/2022/02/GHSA-8jv5-qv7g-fm4r/GHSA-8jv5-qv7g-fm4r.json b/advisories/unreviewed/2022/02/GHSA-8jv5-qv7g-fm4r/GHSA-8jv5-qv7g-fm4r.json index 2cae72975c4..de360607191 100644 --- a/advisories/unreviewed/2022/02/GHSA-8jv5-qv7g-fm4r/GHSA-8jv5-qv7g-fm4r.json +++ b/advisories/unreviewed/2022/02/GHSA-8jv5-qv7g-fm4r/GHSA-8jv5-qv7g-fm4r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22v5-h5m8-j4hf/GHSA-22v5-h5m8-j4hf.json b/advisories/unreviewed/2022/05/GHSA-22v5-h5m8-j4hf/GHSA-22v5-h5m8-j4hf.json index 81f65df694e..ec776d28214 100644 --- a/advisories/unreviewed/2022/05/GHSA-22v5-h5m8-j4hf/GHSA-22v5-h5m8-j4hf.json +++ b/advisories/unreviewed/2022/05/GHSA-22v5-h5m8-j4hf/GHSA-22v5-h5m8-j4hf.json @@ -7,12 +7,8 @@ "CVE-2008-0475" ], "details": "ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the \"/-\" URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2334-74rr-746w/GHSA-2334-74rr-746w.json b/advisories/unreviewed/2022/05/GHSA-2334-74rr-746w/GHSA-2334-74rr-746w.json index 535ff711cb9..3807789b031 100644 --- a/advisories/unreviewed/2022/05/GHSA-2334-74rr-746w/GHSA-2334-74rr-746w.json +++ b/advisories/unreviewed/2022/05/GHSA-2334-74rr-746w/GHSA-2334-74rr-746w.json @@ -7,12 +7,8 @@ "CVE-2008-0389" ], "details": "Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-237j-ffh5-w965/GHSA-237j-ffh5-w965.json b/advisories/unreviewed/2022/05/GHSA-237j-ffh5-w965/GHSA-237j-ffh5-w965.json index a9e0726c071..876c465433c 100644 --- a/advisories/unreviewed/2022/05/GHSA-237j-ffh5-w965/GHSA-237j-ffh5-w965.json +++ b/advisories/unreviewed/2022/05/GHSA-237j-ffh5-w965/GHSA-237j-ffh5-w965.json @@ -7,12 +7,8 @@ "CVE-2008-0647" ], "details": "Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23fq-26rx-3gc4/GHSA-23fq-26rx-3gc4.json b/advisories/unreviewed/2022/05/GHSA-23fq-26rx-3gc4/GHSA-23fq-26rx-3gc4.json index 1a1535f5ed1..aabacbc7314 100644 --- a/advisories/unreviewed/2022/05/GHSA-23fq-26rx-3gc4/GHSA-23fq-26rx-3gc4.json +++ b/advisories/unreviewed/2022/05/GHSA-23fq-26rx-3gc4/GHSA-23fq-26rx-3gc4.json @@ -7,12 +7,8 @@ "CVE-2008-0899" ], "details": "Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-23h3-7c7m-q7q6/GHSA-23h3-7c7m-q7q6.json b/advisories/unreviewed/2022/05/GHSA-23h3-7c7m-q7q6/GHSA-23h3-7c7m-q7q6.json index 1a7aad8e96e..a3d13042e3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-23h3-7c7m-q7q6/GHSA-23h3-7c7m-q7q6.json +++ b/advisories/unreviewed/2022/05/GHSA-23h3-7c7m-q7q6/GHSA-23h3-7c7m-q7q6.json @@ -7,12 +7,8 @@ "CVE-2008-0636" ], "details": "Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct request to About/SC_About.htm, which provides version and patch information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24hf-8w68-m6w3/GHSA-24hf-8w68-m6w3.json b/advisories/unreviewed/2022/05/GHSA-24hf-8w68-m6w3/GHSA-24hf-8w68-m6w3.json index d5bd604a27c..1bd837f6e1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-24hf-8w68-m6w3/GHSA-24hf-8w68-m6w3.json +++ b/advisories/unreviewed/2022/05/GHSA-24hf-8w68-m6w3/GHSA-24hf-8w68-m6w3.json @@ -7,12 +7,8 @@ "CVE-2008-0512" ], "details": "SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-24mr-37ph-25xf/GHSA-24mr-37ph-25xf.json b/advisories/unreviewed/2022/05/GHSA-24mr-37ph-25xf/GHSA-24mr-37ph-25xf.json index 072e441222c..9fc911dc66b 100644 --- a/advisories/unreviewed/2022/05/GHSA-24mr-37ph-25xf/GHSA-24mr-37ph-25xf.json +++ b/advisories/unreviewed/2022/05/GHSA-24mr-37ph-25xf/GHSA-24mr-37ph-25xf.json @@ -7,12 +7,8 @@ "CVE-2019-1373" ], "details": "A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2556-mvh4-2wcq/GHSA-2556-mvh4-2wcq.json b/advisories/unreviewed/2022/05/GHSA-2556-mvh4-2wcq/GHSA-2556-mvh4-2wcq.json index b41a985f3d8..901091167a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2556-mvh4-2wcq/GHSA-2556-mvh4-2wcq.json +++ b/advisories/unreviewed/2022/05/GHSA-2556-mvh4-2wcq/GHSA-2556-mvh4-2wcq.json @@ -7,12 +7,8 @@ "CVE-2008-0907" ], "details": "SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-25rw-v6g3-5hgc/GHSA-25rw-v6g3-5hgc.json b/advisories/unreviewed/2022/05/GHSA-25rw-v6g3-5hgc/GHSA-25rw-v6g3-5hgc.json index 0358363e481..cb5182f89c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-25rw-v6g3-5hgc/GHSA-25rw-v6g3-5hgc.json +++ b/advisories/unreviewed/2022/05/GHSA-25rw-v6g3-5hgc/GHSA-25rw-v6g3-5hgc.json @@ -7,12 +7,8 @@ "CVE-2008-0933" ], "details": "Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_restore.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26r4-c2j9-3fcx/GHSA-26r4-c2j9-3fcx.json b/advisories/unreviewed/2022/05/GHSA-26r4-c2j9-3fcx/GHSA-26r4-c2j9-3fcx.json index 6e34fe2cf8c..d81e96500f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-26r4-c2j9-3fcx/GHSA-26r4-c2j9-3fcx.json +++ b/advisories/unreviewed/2022/05/GHSA-26r4-c2j9-3fcx/GHSA-26r4-c2j9-3fcx.json @@ -7,12 +7,8 @@ "CVE-2008-0920" ], "details": "SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26vv-46rq-5vmv/GHSA-26vv-46rq-5vmv.json b/advisories/unreviewed/2022/05/GHSA-26vv-46rq-5vmv/GHSA-26vv-46rq-5vmv.json index 2394565b736..a9deb2e8773 100644 --- a/advisories/unreviewed/2022/05/GHSA-26vv-46rq-5vmv/GHSA-26vv-46rq-5vmv.json +++ b/advisories/unreviewed/2022/05/GHSA-26vv-46rq-5vmv/GHSA-26vv-46rq-5vmv.json @@ -7,12 +7,8 @@ "CVE-2008-0766" ], "details": "Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a \"Receive data file\" LPD command. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-27xx-mxf2-ph5m/GHSA-27xx-mxf2-ph5m.json b/advisories/unreviewed/2022/05/GHSA-27xx-mxf2-ph5m/GHSA-27xx-mxf2-ph5m.json index 82af2af3ae6..1c42efb26ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-27xx-mxf2-ph5m/GHSA-27xx-mxf2-ph5m.json +++ b/advisories/unreviewed/2022/05/GHSA-27xx-mxf2-ph5m/GHSA-27xx-mxf2-ph5m.json @@ -7,12 +7,8 @@ "CVE-2008-0474" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29qf-mcv8-6r89/GHSA-29qf-mcv8-6r89.json b/advisories/unreviewed/2022/05/GHSA-29qf-mcv8-6r89/GHSA-29qf-mcv8-6r89.json index 96eb154453e..942929eee54 100644 --- a/advisories/unreviewed/2022/05/GHSA-29qf-mcv8-6r89/GHSA-29qf-mcv8-6r89.json +++ b/advisories/unreviewed/2022/05/GHSA-29qf-mcv8-6r89/GHSA-29qf-mcv8-6r89.json @@ -7,12 +7,8 @@ "CVE-2008-0717" ], "details": "Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1 through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2c3x-qj3p-24h2/GHSA-2c3x-qj3p-24h2.json b/advisories/unreviewed/2022/05/GHSA-2c3x-qj3p-24h2/GHSA-2c3x-qj3p-24h2.json index beb5358564c..0411003d7ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c3x-qj3p-24h2/GHSA-2c3x-qj3p-24h2.json +++ b/advisories/unreviewed/2022/05/GHSA-2c3x-qj3p-24h2/GHSA-2c3x-qj3p-24h2.json @@ -7,12 +7,8 @@ "CVE-2019-2169" ], "details": "In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118492282", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2f25-c9pg-f9fc/GHSA-2f25-c9pg-f9fc.json b/advisories/unreviewed/2022/05/GHSA-2f25-c9pg-f9fc/GHSA-2f25-c9pg-f9fc.json index 7af74b7e686..dcee770f152 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f25-c9pg-f9fc/GHSA-2f25-c9pg-f9fc.json +++ b/advisories/unreviewed/2022/05/GHSA-2f25-c9pg-f9fc/GHSA-2f25-c9pg-f9fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fv2-h6jq-8fhx/GHSA-2fv2-h6jq-8fhx.json b/advisories/unreviewed/2022/05/GHSA-2fv2-h6jq-8fhx/GHSA-2fv2-h6jq-8fhx.json index 306c496c881..84cee2f23ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fv2-h6jq-8fhx/GHSA-2fv2-h6jq-8fhx.json +++ b/advisories/unreviewed/2022/05/GHSA-2fv2-h6jq-8fhx/GHSA-2fv2-h6jq-8fhx.json @@ -7,12 +7,8 @@ "CVE-2008-0980" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the url or type parameter to docs/examples/redirect.spy; (2) the x parameter to docs/examples/handlervalidate.spy; (3) the name parameter to spyce/examples/request.spy; (4) the Name parameter to spyce/examples/getpost.spy; (5) the mytextarea parameter, the mypass parameter, or an empty parameter to spyce/examples/formtag.spy; (6) the newline parameter to the default URI under demos/chat/; (7) the text1 parameter to docs/examples/formintro.spy; or (8) the mytext or mydate parameter to docs/examples/formtag.spy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hv2-87wf-9q3h/GHSA-2hv2-87wf-9q3h.json b/advisories/unreviewed/2022/05/GHSA-2hv2-87wf-9q3h/GHSA-2hv2-87wf-9q3h.json index d3784b40ec4..eb81decfc58 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hv2-87wf-9q3h/GHSA-2hv2-87wf-9q3h.json +++ b/advisories/unreviewed/2022/05/GHSA-2hv2-87wf-9q3h/GHSA-2hv2-87wf-9q3h.json @@ -7,12 +7,8 @@ "CVE-2008-0713" ], "details": "Unspecified vulnerability in the FTP server for HP-UX B.11.11, B.11.23, and B.11.31 allows remote authenticated users to cause a denial of service (FTP server outage) via unknown attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jgq-w4vv-qrcg/GHSA-2jgq-w4vv-qrcg.json b/advisories/unreviewed/2022/05/GHSA-2jgq-w4vv-qrcg/GHSA-2jgq-w4vv-qrcg.json index 275c8251f18..438908cdbbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jgq-w4vv-qrcg/GHSA-2jgq-w4vv-qrcg.json +++ b/advisories/unreviewed/2022/05/GHSA-2jgq-w4vv-qrcg/GHSA-2jgq-w4vv-qrcg.json @@ -7,12 +7,8 @@ "CVE-2008-0657" ], "details": "Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jgv-j3mm-j599/GHSA-2jgv-j3mm-j599.json b/advisories/unreviewed/2022/05/GHSA-2jgv-j3mm-j599/GHSA-2jgv-j3mm-j599.json index eb9e0f38cca..e26c42ee567 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jgv-j3mm-j599/GHSA-2jgv-j3mm-j599.json +++ b/advisories/unreviewed/2022/05/GHSA-2jgv-j3mm-j599/GHSA-2jgv-j3mm-j599.json @@ -7,12 +7,8 @@ "CVE-2008-0939" ], "details": "Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name function. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jq4-cxqg-p845/GHSA-2jq4-cxqg-p845.json b/advisories/unreviewed/2022/05/GHSA-2jq4-cxqg-p845/GHSA-2jq4-cxqg-p845.json index 931152f495a..07e22408866 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jq4-cxqg-p845/GHSA-2jq4-cxqg-p845.json +++ b/advisories/unreviewed/2022/05/GHSA-2jq4-cxqg-p845/GHSA-2jq4-cxqg-p845.json @@ -7,12 +7,8 @@ "CVE-2008-0672" ], "details": "The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to cause a denial of service (application crash) via a YES message without a newline character, which triggers a NULL dereference.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jwc-65g4-xvmm/GHSA-2jwc-65g4-xvmm.json b/advisories/unreviewed/2022/05/GHSA-2jwc-65g4-xvmm/GHSA-2jwc-65g4-xvmm.json index 4e4d5a217c3..aca9ed0910e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jwc-65g4-xvmm/GHSA-2jwc-65g4-xvmm.json +++ b/advisories/unreviewed/2022/05/GHSA-2jwc-65g4-xvmm/GHSA-2jwc-65g4-xvmm.json @@ -7,12 +7,8 @@ "CVE-2008-0472" ], "details": "Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jx4-7qpj-c9gc/GHSA-2jx4-7qpj-c9gc.json b/advisories/unreviewed/2022/05/GHSA-2jx4-7qpj-c9gc/GHSA-2jx4-7qpj-c9gc.json index 99a4c215ed1..e6d0d71298b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jx4-7qpj-c9gc/GHSA-2jx4-7qpj-c9gc.json +++ b/advisories/unreviewed/2022/05/GHSA-2jx4-7qpj-c9gc/GHSA-2jx4-7qpj-c9gc.json @@ -7,12 +7,8 @@ "CVE-2008-0394" ], "details": "Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2mrv-739m-rgj5/GHSA-2mrv-739m-rgj5.json b/advisories/unreviewed/2022/05/GHSA-2mrv-739m-rgj5/GHSA-2mrv-739m-rgj5.json index a373d176950..e7e6065f75e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mrv-739m-rgj5/GHSA-2mrv-739m-rgj5.json +++ b/advisories/unreviewed/2022/05/GHSA-2mrv-739m-rgj5/GHSA-2mrv-739m-rgj5.json @@ -7,12 +7,8 @@ "CVE-2008-0916" ], "details": "SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qr7-7g7g-79mr/GHSA-2qr7-7g7g-79mr.json b/advisories/unreviewed/2022/05/GHSA-2qr7-7g7g-79mr/GHSA-2qr7-7g7g-79mr.json index 079535ba733..9b2e9472340 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qr7-7g7g-79mr/GHSA-2qr7-7g7g-79mr.json +++ b/advisories/unreviewed/2022/05/GHSA-2qr7-7g7g-79mr/GHSA-2qr7-7g7g-79mr.json @@ -7,12 +7,8 @@ "CVE-2008-0897" ], "details": "Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without \"receive\" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rcj-xx33-m8j8/GHSA-2rcj-xx33-m8j8.json b/advisories/unreviewed/2022/05/GHSA-2rcj-xx33-m8j8/GHSA-2rcj-xx33-m8j8.json index 2f0cad7befa..a1d91b2d57b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rcj-xx33-m8j8/GHSA-2rcj-xx33-m8j8.json +++ b/advisories/unreviewed/2022/05/GHSA-2rcj-xx33-m8j8/GHSA-2rcj-xx33-m8j8.json @@ -7,12 +7,8 @@ "CVE-2008-0926" ], "details": "The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2rxc-55rq-5r4c/GHSA-2rxc-55rq-5r4c.json b/advisories/unreviewed/2022/05/GHSA-2rxc-55rq-5r4c/GHSA-2rxc-55rq-5r4c.json index ef5e5cf86cf..b9f7cd69141 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rxc-55rq-5r4c/GHSA-2rxc-55rq-5r4c.json +++ b/advisories/unreviewed/2022/05/GHSA-2rxc-55rq-5r4c/GHSA-2rxc-55rq-5r4c.json @@ -7,12 +7,8 @@ "CVE-2008-0418" ], "details": "Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using \"flat\" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v6c-27m4-v7m9/GHSA-2v6c-27m4-v7m9.json b/advisories/unreviewed/2022/05/GHSA-2v6c-27m4-v7m9/GHSA-2v6c-27m4-v7m9.json index f415000bafc..5f9afbb0dab 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v6c-27m4-v7m9/GHSA-2v6c-27m4-v7m9.json +++ b/advisories/unreviewed/2022/05/GHSA-2v6c-27m4-v7m9/GHSA-2v6c-27m4-v7m9.json @@ -7,12 +7,8 @@ "CVE-2008-0768" ], "details": "Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2w84-rx82-9hcw/GHSA-2w84-rx82-9hcw.json b/advisories/unreviewed/2022/05/GHSA-2w84-rx82-9hcw/GHSA-2w84-rx82-9hcw.json index 4a6b7c70c94..6c4dcdb0613 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w84-rx82-9hcw/GHSA-2w84-rx82-9hcw.json +++ b/advisories/unreviewed/2022/05/GHSA-2w84-rx82-9hcw/GHSA-2w84-rx82-9hcw.json @@ -7,12 +7,8 @@ "CVE-2019-2161" ], "details": "In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112553431", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2w9x-qwqq-9qpw/GHSA-2w9x-qwqq-9qpw.json b/advisories/unreviewed/2022/05/GHSA-2w9x-qwqq-9qpw/GHSA-2w9x-qwqq-9qpw.json index 52429c0a7cd..2b558ac6401 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w9x-qwqq-9qpw/GHSA-2w9x-qwqq-9qpw.json +++ b/advisories/unreviewed/2022/05/GHSA-2w9x-qwqq-9qpw/GHSA-2w9x-qwqq-9qpw.json @@ -7,12 +7,8 @@ "CVE-2008-0531" ], "details": "Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xwr-53m3-98jw/GHSA-2xwr-53m3-98jw.json b/advisories/unreviewed/2022/05/GHSA-2xwr-53m3-98jw/GHSA-2xwr-53m3-98jw.json index 04d484afb73..90e45feed7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xwr-53m3-98jw/GHSA-2xwr-53m3-98jw.json +++ b/advisories/unreviewed/2022/05/GHSA-2xwr-53m3-98jw/GHSA-2xwr-53m3-98jw.json @@ -7,12 +7,8 @@ "CVE-2008-0753" ], "details": "SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32p8-xhh6-v239/GHSA-32p8-xhh6-v239.json b/advisories/unreviewed/2022/05/GHSA-32p8-xhh6-v239/GHSA-32p8-xhh6-v239.json index 4a6c656d5f5..d538ba18f06 100644 --- a/advisories/unreviewed/2022/05/GHSA-32p8-xhh6-v239/GHSA-32p8-xhh6-v239.json +++ b/advisories/unreviewed/2022/05/GHSA-32p8-xhh6-v239/GHSA-32p8-xhh6-v239.json @@ -7,12 +7,8 @@ "CVE-2008-0799" ], "details": "SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35vm-xh8x-vfc2/GHSA-35vm-xh8x-vfc2.json b/advisories/unreviewed/2022/05/GHSA-35vm-xh8x-vfc2/GHSA-35vm-xh8x-vfc2.json index d072a775c7b..5baaf2e8dd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-35vm-xh8x-vfc2/GHSA-35vm-xh8x-vfc2.json +++ b/advisories/unreviewed/2022/05/GHSA-35vm-xh8x-vfc2/GHSA-35vm-xh8x-vfc2.json @@ -7,12 +7,8 @@ "CVE-2008-0380" ], "details": "Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-378j-qh98-9px6/GHSA-378j-qh98-9px6.json b/advisories/unreviewed/2022/05/GHSA-378j-qh98-9px6/GHSA-378j-qh98-9px6.json index 4793d537d36..dcd60c27fda 100644 --- a/advisories/unreviewed/2022/05/GHSA-378j-qh98-9px6/GHSA-378j-qh98-9px6.json +++ b/advisories/unreviewed/2022/05/GHSA-378j-qh98-9px6/GHSA-378j-qh98-9px6.json @@ -7,12 +7,8 @@ "CVE-2008-0914" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37hm-h4p2-3xrx/GHSA-37hm-h4p2-3xrx.json b/advisories/unreviewed/2022/05/GHSA-37hm-h4p2-3xrx/GHSA-37hm-h4p2-3xrx.json index 27f33226018..d84f7ebc4e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-37hm-h4p2-3xrx/GHSA-37hm-h4p2-3xrx.json +++ b/advisories/unreviewed/2022/05/GHSA-37hm-h4p2-3xrx/GHSA-37hm-h4p2-3xrx.json @@ -7,12 +7,8 @@ "CVE-2008-0581" ], "details": "Geert Moernaut LSrunasE allows local users to gain privileges by obtaining the encrypted password from a batch file, and constructing a modified batch file that specifies this password in the /password switch and specifies an arbitrary program in the /command switch.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3876-f57v-xhhx/GHSA-3876-f57v-xhhx.json b/advisories/unreviewed/2022/05/GHSA-3876-f57v-xhhx/GHSA-3876-f57v-xhhx.json index 587b9f31c06..78d8a8671a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3876-f57v-xhhx/GHSA-3876-f57v-xhhx.json +++ b/advisories/unreviewed/2022/05/GHSA-3876-f57v-xhhx/GHSA-3876-f57v-xhhx.json @@ -7,12 +7,8 @@ "CVE-2008-0583" ], "details": "Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) \"Add video to chat\" or (2) \"Add video to mood\" dialog, a different vector than CVE-2008-0454.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cmm-mg55-9jrh/GHSA-3cmm-mg55-9jrh.json b/advisories/unreviewed/2022/05/GHSA-3cmm-mg55-9jrh/GHSA-3cmm-mg55-9jrh.json index 31dc3cd5dac..3b058e4c10b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cmm-mg55-9jrh/GHSA-3cmm-mg55-9jrh.json +++ b/advisories/unreviewed/2022/05/GHSA-3cmm-mg55-9jrh/GHSA-3cmm-mg55-9jrh.json @@ -7,12 +7,8 @@ "CVE-2008-0744" ], "details": "SQL injection vulnerability in user_login.asp in PreProjects.com Pre Hotels & Resorts Management System allows remote attackers to execute arbitrary SQL commands via the login page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3cqm-8m32-2pf5/GHSA-3cqm-8m32-2pf5.json b/advisories/unreviewed/2022/05/GHSA-3cqm-8m32-2pf5/GHSA-3cqm-8m32-2pf5.json index 78a6e2ad8df..f93e86ec97a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cqm-8m32-2pf5/GHSA-3cqm-8m32-2pf5.json +++ b/advisories/unreviewed/2022/05/GHSA-3cqm-8m32-2pf5/GHSA-3cqm-8m32-2pf5.json @@ -7,12 +7,8 @@ "CVE-2008-0496" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web script or HTML via the limit parameter in a search action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fjm-f94p-cw3r/GHSA-3fjm-f94p-cw3r.json b/advisories/unreviewed/2022/05/GHSA-3fjm-f94p-cw3r/GHSA-3fjm-f94p-cw3r.json index 77ea33b55dd..734b9bf90fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fjm-f94p-cw3r/GHSA-3fjm-f94p-cw3r.json +++ b/advisories/unreviewed/2022/05/GHSA-3fjm-f94p-cw3r/GHSA-3fjm-f94p-cw3r.json @@ -7,12 +7,8 @@ "CVE-2008-0392" ], "details": "Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3fxc-v5p5-h2wv/GHSA-3fxc-v5p5-h2wv.json b/advisories/unreviewed/2022/05/GHSA-3fxc-v5p5-h2wv/GHSA-3fxc-v5p5-h2wv.json index c4c1ef6747c..7fb85bad97e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fxc-v5p5-h2wv/GHSA-3fxc-v5p5-h2wv.json +++ b/advisories/unreviewed/2022/05/GHSA-3fxc-v5p5-h2wv/GHSA-3fxc-v5p5-h2wv.json @@ -7,12 +7,8 @@ "CVE-2008-0614" ], "details": "SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL commands via the pic parameter in a showpic action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3g3r-hw6p-fjh8/GHSA-3g3r-hw6p-fjh8.json b/advisories/unreviewed/2022/05/GHSA-3g3r-hw6p-fjh8/GHSA-3g3r-hw6p-fjh8.json index 24203ec795f..b58fcbd404f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g3r-hw6p-fjh8/GHSA-3g3r-hw6p-fjh8.json +++ b/advisories/unreviewed/2022/05/GHSA-3g3r-hw6p-fjh8/GHSA-3g3r-hw6p-fjh8.json @@ -7,12 +7,8 @@ "CVE-2008-0618" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jxx-mhp5-7g48/GHSA-3jxx-mhp5-7g48.json b/advisories/unreviewed/2022/05/GHSA-3jxx-mhp5-7g48/GHSA-3jxx-mhp5-7g48.json index a42f3ee623e..f8fcdf45565 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jxx-mhp5-7g48/GHSA-3jxx-mhp5-7g48.json +++ b/advisories/unreviewed/2022/05/GHSA-3jxx-mhp5-7g48/GHSA-3jxx-mhp5-7g48.json @@ -7,12 +7,8 @@ "CVE-2008-0959" ], "details": "Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3q2g-h6qw-ffgj/GHSA-3q2g-h6qw-ffgj.json b/advisories/unreviewed/2022/05/GHSA-3q2g-h6qw-ffgj/GHSA-3q2g-h6qw-ffgj.json index 8c1d618e4eb..70f9ef7a424 100644 --- a/advisories/unreviewed/2022/05/GHSA-3q2g-h6qw-ffgj/GHSA-3q2g-h6qw-ffgj.json +++ b/advisories/unreviewed/2022/05/GHSA-3q2g-h6qw-ffgj/GHSA-3q2g-h6qw-ffgj.json @@ -7,12 +7,8 @@ "CVE-2008-0881" ], "details": "SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3qxq-rx8j-qpmj/GHSA-3qxq-rx8j-qpmj.json b/advisories/unreviewed/2022/05/GHSA-3qxq-rx8j-qpmj/GHSA-3qxq-rx8j-qpmj.json index b0b7a10c2ba..bab4a43e221 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qxq-rx8j-qpmj/GHSA-3qxq-rx8j-qpmj.json +++ b/advisories/unreviewed/2022/05/GHSA-3qxq-rx8j-qpmj/GHSA-3qxq-rx8j-qpmj.json @@ -7,12 +7,8 @@ "CVE-2008-0808" ], "details": "Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rhp-x8rm-9rvr/GHSA-3rhp-x8rm-9rvr.json b/advisories/unreviewed/2022/05/GHSA-3rhp-x8rm-9rvr/GHSA-3rhp-x8rm-9rvr.json index 7acb4df2afd..195b0ef297e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rhp-x8rm-9rvr/GHSA-3rhp-x8rm-9rvr.json +++ b/advisories/unreviewed/2022/05/GHSA-3rhp-x8rm-9rvr/GHSA-3rhp-x8rm-9rvr.json @@ -7,12 +7,8 @@ "CVE-2008-0455" ], "details": "Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w49-vm5v-775f/GHSA-3w49-vm5v-775f.json b/advisories/unreviewed/2022/05/GHSA-3w49-vm5v-775f/GHSA-3w49-vm5v-775f.json index d3358aaa278..faf4e61edfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w49-vm5v-775f/GHSA-3w49-vm5v-775f.json +++ b/advisories/unreviewed/2022/05/GHSA-3w49-vm5v-775f/GHSA-3w49-vm5v-775f.json @@ -7,12 +7,8 @@ "CVE-2008-0529" ], "details": "Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w95-95fc-gjxf/GHSA-3w95-95fc-gjxf.json b/advisories/unreviewed/2022/05/GHSA-3w95-95fc-gjxf/GHSA-3w95-95fc-gjxf.json index 944cad6457c..92b8d68c872 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w95-95fc-gjxf/GHSA-3w95-95fc-gjxf.json +++ b/advisories/unreviewed/2022/05/GHSA-3w95-95fc-gjxf/GHSA-3w95-95fc-gjxf.json @@ -7,12 +7,8 @@ "CVE-2008-0750" ], "details": "SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wpp-3rf9-gggw/GHSA-3wpp-3rf9-gggw.json b/advisories/unreviewed/2022/05/GHSA-3wpp-3rf9-gggw/GHSA-3wpp-3rf9-gggw.json index 488fb82cff2..7d1d27f181c 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wpp-3rf9-gggw/GHSA-3wpp-3rf9-gggw.json +++ b/advisories/unreviewed/2022/05/GHSA-3wpp-3rf9-gggw/GHSA-3wpp-3rf9-gggw.json @@ -7,12 +7,8 @@ "CVE-2008-0546" ], "details": "Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid parameter to (b) ajax/ajax_getBrands.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wxv-vvvq-84p8/GHSA-3wxv-vvvq-84p8.json b/advisories/unreviewed/2022/05/GHSA-3wxv-vvvq-84p8/GHSA-3wxv-vvvq-84p8.json index 739fef6050e..8dde8f6eef1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wxv-vvvq-84p8/GHSA-3wxv-vvvq-84p8.json +++ b/advisories/unreviewed/2022/05/GHSA-3wxv-vvvq-84p8/GHSA-3wxv-vvvq-84p8.json @@ -7,12 +7,8 @@ "CVE-2008-0375" ], "details": "Unspecified vulnerability in OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 allows remote attackers to set the password and obtain administrative access via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3x27-pvp2-3h6m/GHSA-3x27-pvp2-3h6m.json b/advisories/unreviewed/2022/05/GHSA-3x27-pvp2-3h6m/GHSA-3x27-pvp2-3h6m.json index 74af3c136ec..fc49cadc8b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x27-pvp2-3h6m/GHSA-3x27-pvp2-3h6m.json +++ b/advisories/unreviewed/2022/05/GHSA-3x27-pvp2-3h6m/GHSA-3x27-pvp2-3h6m.json @@ -7,12 +7,8 @@ "CVE-2008-0537" ], "details": "Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link, allows remote attackers to cause a denial of service (blocked queue, device restart, or memory leak) via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xp4-6gjh-55fh/GHSA-3xp4-6gjh-55fh.json b/advisories/unreviewed/2022/05/GHSA-3xp4-6gjh-55fh/GHSA-3xp4-6gjh-55fh.json index 8144a698314..42997482b5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xp4-6gjh-55fh/GHSA-3xp4-6gjh-55fh.json +++ b/advisories/unreviewed/2022/05/GHSA-3xp4-6gjh-55fh/GHSA-3xp4-6gjh-55fh.json @@ -7,12 +7,8 @@ "CVE-2008-0411" ], "details": "Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-42q2-w7pp-mx38/GHSA-42q2-w7pp-mx38.json b/advisories/unreviewed/2022/05/GHSA-42q2-w7pp-mx38/GHSA-42q2-w7pp-mx38.json index 2baf0ac6a84..8138fbc55a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-42q2-w7pp-mx38/GHSA-42q2-w7pp-mx38.json +++ b/advisories/unreviewed/2022/05/GHSA-42q2-w7pp-mx38/GHSA-42q2-w7pp-mx38.json @@ -7,12 +7,8 @@ "CVE-2008-0585" ], "details": "sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to \"alter the behavior of\" this client by overwriting these files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-42q8-j57q-84vc/GHSA-42q8-j57q-84vc.json b/advisories/unreviewed/2022/05/GHSA-42q8-j57q-84vc/GHSA-42q8-j57q-84vc.json index 738d17f020f..f861c479984 100644 --- a/advisories/unreviewed/2022/05/GHSA-42q8-j57q-84vc/GHSA-42q8-j57q-84vc.json +++ b/advisories/unreviewed/2022/05/GHSA-42q8-j57q-84vc/GHSA-42q8-j57q-84vc.json @@ -7,12 +7,8 @@ "CVE-2008-0908" ], "details": "SQL injection vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to execute arbitrary SQL commands via the c parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-436q-6vh3-cx7q/GHSA-436q-6vh3-cx7q.json b/advisories/unreviewed/2022/05/GHSA-436q-6vh3-cx7q/GHSA-436q-6vh3-cx7q.json index 783fe027684..538c4dfd05f 100644 --- a/advisories/unreviewed/2022/05/GHSA-436q-6vh3-cx7q/GHSA-436q-6vh3-cx7q.json +++ b/advisories/unreviewed/2022/05/GHSA-436q-6vh3-cx7q/GHSA-436q-6vh3-cx7q.json @@ -7,12 +7,8 @@ "CVE-2008-0490" ], "details": "SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43pc-gr5c-56gh/GHSA-43pc-gr5c-56gh.json b/advisories/unreviewed/2022/05/GHSA-43pc-gr5c-56gh/GHSA-43pc-gr5c-56gh.json index 66ae6178a90..904144162f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-43pc-gr5c-56gh/GHSA-43pc-gr5c-56gh.json +++ b/advisories/unreviewed/2022/05/GHSA-43pc-gr5c-56gh/GHSA-43pc-gr5c-56gh.json @@ -7,12 +7,8 @@ "CVE-2008-0683" ], "details": "SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-442g-3x58-f2rv/GHSA-442g-3x58-f2rv.json b/advisories/unreviewed/2022/05/GHSA-442g-3x58-f2rv/GHSA-442g-3x58-f2rv.json index fe75e59d31e..0cbd2b79b52 100644 --- a/advisories/unreviewed/2022/05/GHSA-442g-3x58-f2rv/GHSA-442g-3x58-f2rv.json +++ b/advisories/unreviewed/2022/05/GHSA-442g-3x58-f2rv/GHSA-442g-3x58-f2rv.json @@ -7,12 +7,8 @@ "CVE-2008-0732" ], "details": "The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44c3-rvfv-fxw4/GHSA-44c3-rvfv-fxw4.json b/advisories/unreviewed/2022/05/GHSA-44c3-rvfv-fxw4/GHSA-44c3-rvfv-fxw4.json index 948a09f6d48..353f82fec94 100644 --- a/advisories/unreviewed/2022/05/GHSA-44c3-rvfv-fxw4/GHSA-44c3-rvfv-fxw4.json +++ b/advisories/unreviewed/2022/05/GHSA-44c3-rvfv-fxw4/GHSA-44c3-rvfv-fxw4.json @@ -7,12 +7,8 @@ "CVE-2008-0404" ], "details": "Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the \"Most active bugs\" summary.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44fq-q5qw-h5w4/GHSA-44fq-q5qw-h5w4.json b/advisories/unreviewed/2022/05/GHSA-44fq-q5qw-h5w4/GHSA-44fq-q5qw-h5w4.json index 22de93c062a..7b9ab00d1cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-44fq-q5qw-h5w4/GHSA-44fq-q5qw-h5w4.json +++ b/advisories/unreviewed/2022/05/GHSA-44fq-q5qw-h5w4/GHSA-44fq-q5qw-h5w4.json @@ -7,12 +7,8 @@ "CVE-2008-0533" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4563-34p5-3rhw/GHSA-4563-34p5-3rhw.json b/advisories/unreviewed/2022/05/GHSA-4563-34p5-3rhw/GHSA-4563-34p5-3rhw.json index fb103f4caa7..f15af4733b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-4563-34p5-3rhw/GHSA-4563-34p5-3rhw.json +++ b/advisories/unreviewed/2022/05/GHSA-4563-34p5-3rhw/GHSA-4563-34p5-3rhw.json @@ -7,12 +7,8 @@ "CVE-2008-0783" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-45j8-9x8w-r4vm/GHSA-45j8-9x8w-r4vm.json b/advisories/unreviewed/2022/05/GHSA-45j8-9x8w-r4vm/GHSA-45j8-9x8w-r4vm.json index 5b63ff10352..40551fdb5f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-45j8-9x8w-r4vm/GHSA-45j8-9x8w-r4vm.json +++ b/advisories/unreviewed/2022/05/GHSA-45j8-9x8w-r4vm/GHSA-45j8-9x8w-r4vm.json @@ -7,12 +7,8 @@ "CVE-2008-0651" ], "details": "SQL injection vulnerability in login.php in Pedro Santana Codice CMS allows remote attackers to execute arbitrary SQL commands via the username field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4636-2x9q-q8q7/GHSA-4636-2x9q-q8q7.json b/advisories/unreviewed/2022/05/GHSA-4636-2x9q-q8q7/GHSA-4636-2x9q-q8q7.json index f86ba8ad19f..6e549c5379c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4636-2x9q-q8q7/GHSA-4636-2x9q-q8q7.json +++ b/advisories/unreviewed/2022/05/GHSA-4636-2x9q-q8q7/GHSA-4636-2x9q-q8q7.json @@ -7,12 +7,8 @@ "CVE-2008-0757" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private message (PM) preview. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46fr-522j-965p/GHSA-46fr-522j-965p.json b/advisories/unreviewed/2022/05/GHSA-46fr-522j-965p/GHSA-46fr-522j-965p.json index b20b7761866..ff19c4c95c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-46fr-522j-965p/GHSA-46fr-522j-965p.json +++ b/advisories/unreviewed/2022/05/GHSA-46fr-522j-965p/GHSA-46fr-522j-965p.json @@ -7,12 +7,8 @@ "CVE-2008-0745" ], "details": "Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-49r8-c332-m7fj/GHSA-49r8-c332-m7fj.json b/advisories/unreviewed/2022/05/GHSA-49r8-c332-m7fj/GHSA-49r8-c332-m7fj.json index 23ba94b732a..6341127bc82 100644 --- a/advisories/unreviewed/2022/05/GHSA-49r8-c332-m7fj/GHSA-49r8-c332-m7fj.json +++ b/advisories/unreviewed/2022/05/GHSA-49r8-c332-m7fj/GHSA-49r8-c332-m7fj.json @@ -7,12 +7,8 @@ "CVE-2008-0977" ], "details": "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon crash) via a certain long packet that triggers an attempt to allocate a large amount of memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cf7-c756-w64m/GHSA-4cf7-c756-w64m.json b/advisories/unreviewed/2022/05/GHSA-4cf7-c756-w64m/GHSA-4cf7-c756-w64m.json index eb9b3807057..07b7a1e9a75 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cf7-c756-w64m/GHSA-4cf7-c756-w64m.json +++ b/advisories/unreviewed/2022/05/GHSA-4cf7-c756-w64m/GHSA-4cf7-c756-w64m.json @@ -7,12 +7,8 @@ "CVE-2008-0397" ], "details": "Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4f86-7p6f-wpvq/GHSA-4f86-7p6f-wpvq.json b/advisories/unreviewed/2022/05/GHSA-4f86-7p6f-wpvq/GHSA-4f86-7p6f-wpvq.json index a79da15d190..2cf1d3bb9be 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f86-7p6f-wpvq/GHSA-4f86-7p6f-wpvq.json +++ b/advisories/unreviewed/2022/05/GHSA-4f86-7p6f-wpvq/GHSA-4f86-7p6f-wpvq.json @@ -7,12 +7,8 @@ "CVE-2019-1380" ], "details": "A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f9x-5pm2-qfqx/GHSA-4f9x-5pm2-qfqx.json b/advisories/unreviewed/2022/05/GHSA-4f9x-5pm2-qfqx/GHSA-4f9x-5pm2-qfqx.json index b974f3cd994..e2c47b2c446 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f9x-5pm2-qfqx/GHSA-4f9x-5pm2-qfqx.json +++ b/advisories/unreviewed/2022/05/GHSA-4f9x-5pm2-qfqx/GHSA-4f9x-5pm2-qfqx.json @@ -7,12 +7,8 @@ "CVE-2008-0654" ], "details": "Multiple directory traversal vulnerabilities in Azucar CMS 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _VIEW (view) parameter to (1) index.php, (2) html/sitio/index.php, or (3) src/sistema/vistas/template/tpl_inicio.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fpx-8qhx-64c3/GHSA-4fpx-8qhx-64c3.json b/advisories/unreviewed/2022/05/GHSA-4fpx-8qhx-64c3/GHSA-4fpx-8qhx-64c3.json index 7a47ba66d04..a179f49cffd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fpx-8qhx-64c3/GHSA-4fpx-8qhx-64c3.json +++ b/advisories/unreviewed/2022/05/GHSA-4fpx-8qhx-64c3/GHSA-4fpx-8qhx-64c3.json @@ -7,12 +7,8 @@ "CVE-2008-0396" ], "details": "Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4fw6-r22r-32px/GHSA-4fw6-r22r-32px.json b/advisories/unreviewed/2022/05/GHSA-4fw6-r22r-32px/GHSA-4fw6-r22r-32px.json index 0a3dd1c6c44..10578fac8f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4fw6-r22r-32px/GHSA-4fw6-r22r-32px.json +++ b/advisories/unreviewed/2022/05/GHSA-4fw6-r22r-32px/GHSA-4fw6-r22r-32px.json @@ -7,12 +7,8 @@ "CVE-2008-0695" ], "details": "SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gfw-r3c2-mc2g/GHSA-4gfw-r3c2-mc2g.json b/advisories/unreviewed/2022/05/GHSA-4gfw-r3c2-mc2g/GHSA-4gfw-r3c2-mc2g.json index 952e0746168..d6b6e7eb39d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gfw-r3c2-mc2g/GHSA-4gfw-r3c2-mc2g.json +++ b/advisories/unreviewed/2022/05/GHSA-4gfw-r3c2-mc2g/GHSA-4gfw-r3c2-mc2g.json @@ -7,12 +7,8 @@ "CVE-2008-0675" ], "details": "SQL injection vulnerability in cms/index.pl in The Everything Development Engine in The Everything Development System Pre-1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the node_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gr3-prqp-v6r3/GHSA-4gr3-prqp-v6r3.json b/advisories/unreviewed/2022/05/GHSA-4gr3-prqp-v6r3/GHSA-4gr3-prqp-v6r3.json index eaf59046750..2b693b90ac7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gr3-prqp-v6r3/GHSA-4gr3-prqp-v6r3.json +++ b/advisories/unreviewed/2022/05/GHSA-4gr3-prqp-v6r3/GHSA-4gr3-prqp-v6r3.json @@ -7,12 +7,8 @@ "CVE-2008-0928" ], "details": "Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -108,9 +104,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4j92-xcjv-q7vq/GHSA-4j92-xcjv-q7vq.json b/advisories/unreviewed/2022/05/GHSA-4j92-xcjv-q7vq/GHSA-4j92-xcjv-q7vq.json index ee70857d6de..3a3e8505423 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j92-xcjv-q7vq/GHSA-4j92-xcjv-q7vq.json +++ b/advisories/unreviewed/2022/05/GHSA-4j92-xcjv-q7vq/GHSA-4j92-xcjv-q7vq.json @@ -7,12 +7,8 @@ "CVE-2008-0572" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP code via a URL in the MM_GLOBALS[home] parameter to (1) acweb/admin_index.php; and (2) ask.inc.php, (3) learn.inc.php, (4) manage.inc.php, (5) mind.inc.php, and (6) sensory.inc.php in include/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jmj-xq3w-8f72/GHSA-4jmj-xq3w-8f72.json b/advisories/unreviewed/2022/05/GHSA-4jmj-xq3w-8f72/GHSA-4jmj-xq3w-8f72.json index a01b62d0d2b..f5cca903036 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jmj-xq3w-8f72/GHSA-4jmj-xq3w-8f72.json +++ b/advisories/unreviewed/2022/05/GHSA-4jmj-xq3w-8f72/GHSA-4jmj-xq3w-8f72.json @@ -7,12 +7,8 @@ "CVE-2008-0639" ], "details": "Stack-based buffer overflow in the EnumPrinters function in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2, SP3, and SP4 for Windows allows remote attackers to execute arbitrary code via a crafted RPC request, aka Novell bug 353138, a different vulnerability than CVE-2006-5854. NOTE: this issue exists because of an incomplete fix for CVE-2007-6701.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4jw9-2c2q-5f3c/GHSA-4jw9-2c2q-5f3c.json b/advisories/unreviewed/2022/05/GHSA-4jw9-2c2q-5f3c/GHSA-4jw9-2c2q-5f3c.json index d540ef4c9bf..731c22be3b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jw9-2c2q-5f3c/GHSA-4jw9-2c2q-5f3c.json +++ b/advisories/unreviewed/2022/05/GHSA-4jw9-2c2q-5f3c/GHSA-4jw9-2c2q-5f3c.json @@ -7,12 +7,8 @@ "CVE-2008-0925" ], "details": "Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within \"error messages of the HTTP stack.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pww-r3c9-8vff/GHSA-4pww-r3c9-8vff.json b/advisories/unreviewed/2022/05/GHSA-4pww-r3c9-8vff/GHSA-4pww-r3c9-8vff.json index ff85a1206a7..fbe9fa41afd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pww-r3c9-8vff/GHSA-4pww-r3c9-8vff.json +++ b/advisories/unreviewed/2022/05/GHSA-4pww-r3c9-8vff/GHSA-4pww-r3c9-8vff.json @@ -7,12 +7,8 @@ "CVE-2008-0653" ], "details": "SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showYNews action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pxf-c3wq-87j3/GHSA-4pxf-c3wq-87j3.json b/advisories/unreviewed/2022/05/GHSA-4pxf-c3wq-87j3/GHSA-4pxf-c3wq-87j3.json index 200a0e5f1b9..278fa57dcdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pxf-c3wq-87j3/GHSA-4pxf-c3wq-87j3.json +++ b/advisories/unreviewed/2022/05/GHSA-4pxf-c3wq-87j3/GHSA-4pxf-c3wq-87j3.json @@ -7,12 +7,8 @@ "CVE-2008-0981" ], "details": "Open redirect vulnerability in spyce/examples/redirect.spy in Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4q2f-9jg4-5cr7/GHSA-4q2f-9jg4-5cr7.json b/advisories/unreviewed/2022/05/GHSA-4q2f-9jg4-5cr7/GHSA-4q2f-9jg4-5cr7.json index 23a71c5b9c5..5f24e24e857 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q2f-9jg4-5cr7/GHSA-4q2f-9jg4-5cr7.json +++ b/advisories/unreviewed/2022/05/GHSA-4q2f-9jg4-5cr7/GHSA-4q2f-9jg4-5cr7.json @@ -7,12 +7,8 @@ "CVE-2008-0556" ], "details": "Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized actions as authorized users via a link or IMG tag to RAServer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4q95-263m-g434/GHSA-4q95-263m-g434.json b/advisories/unreviewed/2022/05/GHSA-4q95-263m-g434/GHSA-4q95-263m-g434.json index 6d10d3619f1..e2b7fa39479 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q95-263m-g434/GHSA-4q95-263m-g434.json +++ b/advisories/unreviewed/2022/05/GHSA-4q95-263m-g434/GHSA-4q95-263m-g434.json @@ -7,12 +7,8 @@ "CVE-2008-0495" ], "details": "Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4r67-552x-9f24/GHSA-4r67-552x-9f24.json b/advisories/unreviewed/2022/05/GHSA-4r67-552x-9f24/GHSA-4r67-552x-9f24.json index fbe3242cbf5..c99e2de44f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-4r67-552x-9f24/GHSA-4r67-552x-9f24.json +++ b/advisories/unreviewed/2022/05/GHSA-4r67-552x-9f24/GHSA-4r67-552x-9f24.json @@ -7,12 +7,8 @@ "CVE-2008-0500" ], "details": "Multiple unspecified vulnerabilities in Mambo LaiThai 4.5.5 have unknown impact and attack vectors related to (1) mod_login and (2) mod_template_chooser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v2q-r7pp-6g8x/GHSA-4v2q-r7pp-6g8x.json b/advisories/unreviewed/2022/05/GHSA-4v2q-r7pp-6g8x/GHSA-4v2q-r7pp-6g8x.json index 6d2965d88fe..7fc26bd9425 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v2q-r7pp-6g8x/GHSA-4v2q-r7pp-6g8x.json +++ b/advisories/unreviewed/2022/05/GHSA-4v2q-r7pp-6g8x/GHSA-4v2q-r7pp-6g8x.json @@ -7,12 +7,8 @@ "CVE-2008-0664" ], "details": "The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vrj-64wh-8ch5/GHSA-4vrj-64wh-8ch5.json b/advisories/unreviewed/2022/05/GHSA-4vrj-64wh-8ch5/GHSA-4vrj-64wh-8ch5.json index 5a99b73f603..751f7d016f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vrj-64wh-8ch5/GHSA-4vrj-64wh-8ch5.json +++ b/advisories/unreviewed/2022/05/GHSA-4vrj-64wh-8ch5/GHSA-4vrj-64wh-8ch5.json @@ -7,12 +7,8 @@ "CVE-2008-0384" ], "details": "OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vv2-rcfp-82jf/GHSA-4vv2-rcfp-82jf.json b/advisories/unreviewed/2022/05/GHSA-4vv2-rcfp-82jf/GHSA-4vv2-rcfp-82jf.json index 9f0988db6c8..b0044dc8f4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vv2-rcfp-82jf/GHSA-4vv2-rcfp-82jf.json +++ b/advisories/unreviewed/2022/05/GHSA-4vv2-rcfp-82jf/GHSA-4vv2-rcfp-82jf.json @@ -7,12 +7,8 @@ "CVE-2008-0749" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a calimero_webpage action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w77-2m4x-xmjp/GHSA-4w77-2m4x-xmjp.json b/advisories/unreviewed/2022/05/GHSA-4w77-2m4x-xmjp/GHSA-4w77-2m4x-xmjp.json index 9fa6b9182bd..c7a58a94f04 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w77-2m4x-xmjp/GHSA-4w77-2m4x-xmjp.json +++ b/advisories/unreviewed/2022/05/GHSA-4w77-2m4x-xmjp/GHSA-4w77-2m4x-xmjp.json @@ -7,12 +7,8 @@ "CVE-2019-1381" ], "details": "An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4whx-p2jg-86xc/GHSA-4whx-p2jg-86xc.json b/advisories/unreviewed/2022/05/GHSA-4whx-p2jg-86xc/GHSA-4whx-p2jg-86xc.json index 0a0293c4909..c5d55c245dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4whx-p2jg-86xc/GHSA-4whx-p2jg-86xc.json +++ b/advisories/unreviewed/2022/05/GHSA-4whx-p2jg-86xc/GHSA-4whx-p2jg-86xc.json @@ -7,12 +7,8 @@ "CVE-2008-0383" ], "details": "Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter in a do_multimovethreads action to (a) moderation.php; or (4) gid parameter to (b) admin/usergroups.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xmp-mw9m-r2jm/GHSA-4xmp-mw9m-r2jm.json b/advisories/unreviewed/2022/05/GHSA-4xmp-mw9m-r2jm/GHSA-4xmp-mw9m-r2jm.json index b1905f5e0c2..4d5ae5c2694 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xmp-mw9m-r2jm/GHSA-4xmp-mw9m-r2jm.json +++ b/advisories/unreviewed/2022/05/GHSA-4xmp-mw9m-r2jm/GHSA-4xmp-mw9m-r2jm.json @@ -7,12 +7,8 @@ "CVE-2008-0519" ], "details": "SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a CatView action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52ch-cf4w-m93w/GHSA-52ch-cf4w-m93w.json b/advisories/unreviewed/2022/05/GHSA-52ch-cf4w-m93w/GHSA-52ch-cf4w-m93w.json index 624ac6bd0da..9cec7ddaacc 100644 --- a/advisories/unreviewed/2022/05/GHSA-52ch-cf4w-m93w/GHSA-52ch-cf4w-m93w.json +++ b/advisories/unreviewed/2022/05/GHSA-52ch-cf4w-m93w/GHSA-52ch-cf4w-m93w.json @@ -7,12 +7,8 @@ "CVE-2008-0665" ], "details": "wml_backend/p1_ipp/ipp.src in Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52j9-c2rv-pfxh/GHSA-52j9-c2rv-pfxh.json b/advisories/unreviewed/2022/05/GHSA-52j9-c2rv-pfxh/GHSA-52j9-c2rv-pfxh.json index 9e6329e9f7a..34b36a94137 100644 --- a/advisories/unreviewed/2022/05/GHSA-52j9-c2rv-pfxh/GHSA-52j9-c2rv-pfxh.json +++ b/advisories/unreviewed/2022/05/GHSA-52j9-c2rv-pfxh/GHSA-52j9-c2rv-pfxh.json @@ -7,12 +7,8 @@ "CVE-2019-9319" ], "details": "In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111762100", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52qg-8f5r-jg8w/GHSA-52qg-8f5r-jg8w.json b/advisories/unreviewed/2022/05/GHSA-52qg-8f5r-jg8w/GHSA-52qg-8f5r-jg8w.json index b9f279c5e0a..e784122712e 100644 --- a/advisories/unreviewed/2022/05/GHSA-52qg-8f5r-jg8w/GHSA-52qg-8f5r-jg8w.json +++ b/advisories/unreviewed/2022/05/GHSA-52qg-8f5r-jg8w/GHSA-52qg-8f5r-jg8w.json @@ -7,12 +7,8 @@ "CVE-2008-0434" ], "details": "Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53gg-xjq8-rw6x/GHSA-53gg-xjq8-rw6x.json b/advisories/unreviewed/2022/05/GHSA-53gg-xjq8-rw6x/GHSA-53gg-xjq8-rw6x.json index b39472bd4ba..2f146f7707b 100644 --- a/advisories/unreviewed/2022/05/GHSA-53gg-xjq8-rw6x/GHSA-53gg-xjq8-rw6x.json +++ b/advisories/unreviewed/2022/05/GHSA-53gg-xjq8-rw6x/GHSA-53gg-xjq8-rw6x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53jw-q7qq-mxwr/GHSA-53jw-q7qq-mxwr.json b/advisories/unreviewed/2022/05/GHSA-53jw-q7qq-mxwr/GHSA-53jw-q7qq-mxwr.json index 03b3d6dc28b..dd462fe8779 100644 --- a/advisories/unreviewed/2022/05/GHSA-53jw-q7qq-mxwr/GHSA-53jw-q7qq-mxwr.json +++ b/advisories/unreviewed/2022/05/GHSA-53jw-q7qq-mxwr/GHSA-53jw-q7qq-mxwr.json @@ -7,12 +7,8 @@ "CVE-2008-0575" ], "details": "Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmin privilege level to arbitrary accounts as administrators via an \"update member\" action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54hm-whm8-53qp/GHSA-54hm-whm8-53qp.json b/advisories/unreviewed/2022/05/GHSA-54hm-whm8-53qp/GHSA-54hm-whm8-53qp.json index 098a2a35214..65f8310a615 100644 --- a/advisories/unreviewed/2022/05/GHSA-54hm-whm8-53qp/GHSA-54hm-whm8-53qp.json +++ b/advisories/unreviewed/2022/05/GHSA-54hm-whm8-53qp/GHSA-54hm-whm8-53qp.json @@ -7,12 +7,8 @@ "CVE-2008-0513" ], "details": "Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to parser/parser.php, as demonstrated by a filename ending with %00.gif, a different vector than CVE-2005-1840.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-54xh-jmx9-967x/GHSA-54xh-jmx9-967x.json b/advisories/unreviewed/2022/05/GHSA-54xh-jmx9-967x/GHSA-54xh-jmx9-967x.json index 8f0e9453b1a..7a618463cd5 100644 --- a/advisories/unreviewed/2022/05/GHSA-54xh-jmx9-967x/GHSA-54xh-jmx9-967x.json +++ b/advisories/unreviewed/2022/05/GHSA-54xh-jmx9-967x/GHSA-54xh-jmx9-967x.json @@ -7,12 +7,8 @@ "CVE-2008-0898" ], "details": "The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55v6-ppr3-q8jr/GHSA-55v6-ppr3-q8jr.json b/advisories/unreviewed/2022/05/GHSA-55v6-ppr3-q8jr/GHSA-55v6-ppr3-q8jr.json index b9553a9ac30..718381f90a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-55v6-ppr3-q8jr/GHSA-55v6-ppr3-q8jr.json +++ b/advisories/unreviewed/2022/05/GHSA-55v6-ppr3-q8jr/GHSA-55v6-ppr3-q8jr.json @@ -7,12 +7,8 @@ "CVE-2008-0377" ], "details": "MicroNews allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55wv-q22p-frqh/GHSA-55wv-q22p-frqh.json b/advisories/unreviewed/2022/05/GHSA-55wv-q22p-frqh/GHSA-55wv-q22p-frqh.json index 4a8c96a2bbc..e576a0b8929 100644 --- a/advisories/unreviewed/2022/05/GHSA-55wv-q22p-frqh/GHSA-55wv-q22p-frqh.json +++ b/advisories/unreviewed/2022/05/GHSA-55wv-q22p-frqh/GHSA-55wv-q22p-frqh.json @@ -7,12 +7,8 @@ "CVE-2008-0915" ], "details": "The Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 stores the number of remaining allowed login attempts in a cookie, which makes it easier for remote attackers to conduct brute force attacks by manipulating this cookie's value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-56c4-p2fx-g63c/GHSA-56c4-p2fx-g63c.json b/advisories/unreviewed/2022/05/GHSA-56c4-p2fx-g63c/GHSA-56c4-p2fx-g63c.json index 0d800d5ab09..014e9c865c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-56c4-p2fx-g63c/GHSA-56c4-p2fx-g63c.json +++ b/advisories/unreviewed/2022/05/GHSA-56c4-p2fx-g63c/GHSA-56c4-p2fx-g63c.json @@ -7,12 +7,8 @@ "CVE-2008-0978" ], "details": "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to obtain sensitive information via a packet of type (1) 0x2728, which provides operating system and path information; (2) 0x274e, which lists Ethernet adapters; (3) 0x2726, which provides filesystem information; (4) 0x274f, which specifies the printer driver; or (5) 0x2757, which provides recent log entries.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-573r-pcmm-438p/GHSA-573r-pcmm-438p.json b/advisories/unreviewed/2022/05/GHSA-573r-pcmm-438p/GHSA-573r-pcmm-438p.json index 8701b70fc12..428815ab106 100644 --- a/advisories/unreviewed/2022/05/GHSA-573r-pcmm-438p/GHSA-573r-pcmm-438p.json +++ b/advisories/unreviewed/2022/05/GHSA-573r-pcmm-438p/GHSA-573r-pcmm-438p.json @@ -7,12 +7,8 @@ "CVE-2008-0579" ], "details": "SQL injection vulnerability in index.php in the buslicense (com_buslicense) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in a list action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-586g-gjq9-j47w/GHSA-586g-gjq9-j47w.json b/advisories/unreviewed/2022/05/GHSA-586g-gjq9-j47w/GHSA-586g-gjq9-j47w.json index bd08db84e73..897bb556488 100644 --- a/advisories/unreviewed/2022/05/GHSA-586g-gjq9-j47w/GHSA-586g-gjq9-j47w.json +++ b/advisories/unreviewed/2022/05/GHSA-586g-gjq9-j47w/GHSA-586g-gjq9-j47w.json @@ -7,12 +7,8 @@ "CVE-2008-0774" ], "details": "Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58jg-8r7f-phv2/GHSA-58jg-8r7f-phv2.json b/advisories/unreviewed/2022/05/GHSA-58jg-8r7f-phv2/GHSA-58jg-8r7f-phv2.json index a8ca46488da..4c6c3da56f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-58jg-8r7f-phv2/GHSA-58jg-8r7f-phv2.json +++ b/advisories/unreviewed/2022/05/GHSA-58jg-8r7f-phv2/GHSA-58jg-8r7f-phv2.json @@ -7,12 +7,8 @@ "CVE-2008-0461" ], "details": "SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a comments action to modules.php. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58jm-m2rm-9hg3/GHSA-58jm-m2rm-9hg3.json b/advisories/unreviewed/2022/05/GHSA-58jm-m2rm-9hg3/GHSA-58jm-m2rm-9hg3.json index d5ddbb90d88..0595e609c6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-58jm-m2rm-9hg3/GHSA-58jm-m2rm-9hg3.json +++ b/advisories/unreviewed/2022/05/GHSA-58jm-m2rm-9hg3/GHSA-58jm-m2rm-9hg3.json @@ -7,12 +7,8 @@ "CVE-2008-0854" ], "details": "SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-594f-mwhc-9rfx/GHSA-594f-mwhc-9rfx.json b/advisories/unreviewed/2022/05/GHSA-594f-mwhc-9rfx/GHSA-594f-mwhc-9rfx.json index 3feebd2fce5..d53ae810a33 100644 --- a/advisories/unreviewed/2022/05/GHSA-594f-mwhc-9rfx/GHSA-594f-mwhc-9rfx.json +++ b/advisories/unreviewed/2022/05/GHSA-594f-mwhc-9rfx/GHSA-594f-mwhc-9rfx.json @@ -7,12 +7,8 @@ "CVE-2008-0682" ], "details": "SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-594g-399p-4cf5/GHSA-594g-399p-4cf5.json b/advisories/unreviewed/2022/05/GHSA-594g-399p-4cf5/GHSA-594g-399p-4cf5.json index 8b8e78d6749..1bbb4cff092 100644 --- a/advisories/unreviewed/2022/05/GHSA-594g-399p-4cf5/GHSA-594g-399p-4cf5.json +++ b/advisories/unreviewed/2022/05/GHSA-594g-399p-4cf5/GHSA-594g-399p-4cf5.json @@ -7,12 +7,8 @@ "CVE-2008-0604" ], "details": "The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-598f-74h8-7546/GHSA-598f-74h8-7546.json b/advisories/unreviewed/2022/05/GHSA-598f-74h8-7546/GHSA-598f-74h8-7546.json index 5e8b53edb8b..f1b1af53ed0 100644 --- a/advisories/unreviewed/2022/05/GHSA-598f-74h8-7546/GHSA-598f-74h8-7546.json +++ b/advisories/unreviewed/2022/05/GHSA-598f-74h8-7546/GHSA-598f-74h8-7546.json @@ -7,12 +7,8 @@ "CVE-2008-0538" ], "details": "Multiple SQL injection vulnerabilities in phpIP Management 4.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) password parameter to login.php, the (2) id parameter to display.php, and unspecified other vectors. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59hc-rfcg-f7w2/GHSA-59hc-rfcg-f7w2.json b/advisories/unreviewed/2022/05/GHSA-59hc-rfcg-f7w2/GHSA-59hc-rfcg-f7w2.json index aad1492dcfe..717404aa0f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-59hc-rfcg-f7w2/GHSA-59hc-rfcg-f7w2.json +++ b/advisories/unreviewed/2022/05/GHSA-59hc-rfcg-f7w2/GHSA-59hc-rfcg-f7w2.json @@ -7,12 +7,8 @@ "CVE-2019-1402" ], "details": "An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5c4f-f362-97p5/GHSA-5c4f-f362-97p5.json b/advisories/unreviewed/2022/05/GHSA-5c4f-f362-97p5/GHSA-5c4f-f362-97p5.json index b77dfca7377..019fe6e2040 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c4f-f362-97p5/GHSA-5c4f-f362-97p5.json +++ b/advisories/unreviewed/2022/05/GHSA-5c4f-f362-97p5/GHSA-5c4f-f362-97p5.json @@ -7,12 +7,8 @@ "CVE-2008-0652" ], "details": "SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5ccq-m78m-43f5/GHSA-5ccq-m78m-43f5.json b/advisories/unreviewed/2022/05/GHSA-5ccq-m78m-43f5/GHSA-5ccq-m78m-43f5.json index 09d0196bb12..3450fab5091 100644 --- a/advisories/unreviewed/2022/05/GHSA-5ccq-m78m-43f5/GHSA-5ccq-m78m-43f5.json +++ b/advisories/unreviewed/2022/05/GHSA-5ccq-m78m-43f5/GHSA-5ccq-m78m-43f5.json @@ -7,12 +7,8 @@ "CVE-2008-0545" ], "details": "Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5cw9-xm55-9vh3/GHSA-5cw9-xm55-9vh3.json b/advisories/unreviewed/2022/05/GHSA-5cw9-xm55-9vh3/GHSA-5cw9-xm55-9vh3.json index 17532073e96..c164288667c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cw9-xm55-9vh3/GHSA-5cw9-xm55-9vh3.json +++ b/advisories/unreviewed/2022/05/GHSA-5cw9-xm55-9vh3/GHSA-5cw9-xm55-9vh3.json @@ -7,12 +7,8 @@ "CVE-2008-0748" ], "details": "Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fjc-m72h-6w3x/GHSA-5fjc-m72h-6w3x.json b/advisories/unreviewed/2022/05/GHSA-5fjc-m72h-6w3x/GHSA-5fjc-m72h-6w3x.json index 0d49ece2e18..40bc1d63cd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fjc-m72h-6w3x/GHSA-5fjc-m72h-6w3x.json +++ b/advisories/unreviewed/2022/05/GHSA-5fjc-m72h-6w3x/GHSA-5fjc-m72h-6w3x.json @@ -7,12 +7,8 @@ "CVE-2008-0648" ], "details": "Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) indexFooter.php; and (2) DatabaseManager.php, (3) FieldManager.php, (4) Filter.php, (5) Form.php, (6) FormManager.php, (7) LoginManager.php, and (8) Filters/SingleFilter.php in scripts/classes/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5g4w-m5hx-7hw6/GHSA-5g4w-m5hx-7hw6.json b/advisories/unreviewed/2022/05/GHSA-5g4w-m5hx-7hw6/GHSA-5g4w-m5hx-7hw6.json index 1a6f60e7664..06f4a93de01 100644 --- a/advisories/unreviewed/2022/05/GHSA-5g4w-m5hx-7hw6/GHSA-5g4w-m5hx-7hw6.json +++ b/advisories/unreviewed/2022/05/GHSA-5g4w-m5hx-7hw6/GHSA-5g4w-m5hx-7hw6.json @@ -7,12 +7,8 @@ "CVE-2008-0764" ], "details": "Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allow remote attackers to execute arbitrary code via format string specifiers in a USEP command on TCP port 3114.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5gj9-j32c-8ch5/GHSA-5gj9-j32c-8ch5.json b/advisories/unreviewed/2022/05/GHSA-5gj9-j32c-8ch5/GHSA-5gj9-j32c-8ch5.json index 5b61866a8c1..397da15f271 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gj9-j32c-8ch5/GHSA-5gj9-j32c-8ch5.json +++ b/advisories/unreviewed/2022/05/GHSA-5gj9-j32c-8ch5/GHSA-5gj9-j32c-8ch5.json @@ -7,12 +7,8 @@ "CVE-2008-0550" ], "details": "Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5h47-r32g-f8qg/GHSA-5h47-r32g-f8qg.json b/advisories/unreviewed/2022/05/GHSA-5h47-r32g-f8qg/GHSA-5h47-r32g-f8qg.json index edc9cf4113a..99266372a0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5h47-r32g-f8qg/GHSA-5h47-r32g-f8qg.json +++ b/advisories/unreviewed/2022/05/GHSA-5h47-r32g-f8qg/GHSA-5h47-r32g-f8qg.json @@ -7,12 +7,8 @@ "CVE-2008-0540" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5j6c-q96x-3gv8/GHSA-5j6c-q96x-3gv8.json b/advisories/unreviewed/2022/05/GHSA-5j6c-q96x-3gv8/GHSA-5j6c-q96x-3gv8.json index 45d2a702fe4..29a9ac8af46 100644 --- a/advisories/unreviewed/2022/05/GHSA-5j6c-q96x-3gv8/GHSA-5j6c-q96x-3gv8.json +++ b/advisories/unreviewed/2022/05/GHSA-5j6c-q96x-3gv8/GHSA-5j6c-q96x-3gv8.json @@ -7,12 +7,8 @@ "CVE-2008-0741" ], "details": "Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5mfq-9688-q734/GHSA-5mfq-9688-q734.json b/advisories/unreviewed/2022/05/GHSA-5mfq-9688-q734/GHSA-5mfq-9688-q734.json index 800cabda58c..25b40892e1a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mfq-9688-q734/GHSA-5mfq-9688-q734.json +++ b/advisories/unreviewed/2022/05/GHSA-5mfq-9688-q734/GHSA-5mfq-9688-q734.json @@ -7,12 +7,8 @@ "CVE-2008-0561" ], "details": "SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5mjg-w552-cfpq/GHSA-5mjg-w552-cfpq.json b/advisories/unreviewed/2022/05/GHSA-5mjg-w552-cfpq/GHSA-5mjg-w552-cfpq.json index 65e1970d59e..6ccca32938a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5mjg-w552-cfpq/GHSA-5mjg-w552-cfpq.json +++ b/advisories/unreviewed/2022/05/GHSA-5mjg-w552-cfpq/GHSA-5mjg-w552-cfpq.json @@ -7,12 +7,8 @@ "CVE-2008-0785" ], "details": "Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php, (3) local_graph_id parameter to graph_xport.php, and (4) login_username parameter to index.php/login.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5pq3-34hp-fv5c/GHSA-5pq3-34hp-fv5c.json b/advisories/unreviewed/2022/05/GHSA-5pq3-34hp-fv5c/GHSA-5pq3-34hp-fv5c.json index 2ada7be3e5e..1f7fd89cb11 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pq3-34hp-fv5c/GHSA-5pq3-34hp-fv5c.json +++ b/advisories/unreviewed/2022/05/GHSA-5pq3-34hp-fv5c/GHSA-5pq3-34hp-fv5c.json @@ -7,12 +7,8 @@ "CVE-2008-0557" ], "details": "SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5prg-69vq-2qg9/GHSA-5prg-69vq-2qg9.json b/advisories/unreviewed/2022/05/GHSA-5prg-69vq-2qg9/GHSA-5prg-69vq-2qg9.json index 34cb1d935c1..4b8a7b87a63 100644 --- a/advisories/unreviewed/2022/05/GHSA-5prg-69vq-2qg9/GHSA-5prg-69vq-2qg9.json +++ b/advisories/unreviewed/2022/05/GHSA-5prg-69vq-2qg9/GHSA-5prg-69vq-2qg9.json @@ -7,12 +7,8 @@ "CVE-2008-0577" ], "details": "The Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal (1) does not restrict the extensions of attached files when the Upload module is enabled for issue nodes, which allows remote attackers to upload and possibly execute arbitrary files; and (2) accepts the .html extension within the bundled file-upload functionality, which allows remote attackers to upload files containing arbitrary web script or HTML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5qc7-3rq9-3wc2/GHSA-5qc7-3rq9-3wc2.json b/advisories/unreviewed/2022/05/GHSA-5qc7-3rq9-3wc2/GHSA-5qc7-3rq9-3wc2.json index baa5ae06b96..98f453f24f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qc7-3rq9-3wc2/GHSA-5qc7-3rq9-3wc2.json +++ b/advisories/unreviewed/2022/05/GHSA-5qc7-3rq9-3wc2/GHSA-5qc7-3rq9-3wc2.json @@ -7,12 +7,8 @@ "CVE-2008-0684" ], "details": "Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTML via the CatID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5v7g-8gw8-v4x9/GHSA-5v7g-8gw8-v4x9.json b/advisories/unreviewed/2022/05/GHSA-5v7g-8gw8-v4x9/GHSA-5v7g-8gw8-v4x9.json index 376aaa02d01..743ca530f44 100644 --- a/advisories/unreviewed/2022/05/GHSA-5v7g-8gw8-v4x9/GHSA-5v7g-8gw8-v4x9.json +++ b/advisories/unreviewed/2022/05/GHSA-5v7g-8gw8-v4x9/GHSA-5v7g-8gw8-v4x9.json @@ -7,12 +7,8 @@ "CVE-2008-0464" ], "details": "Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5vr5-42hq-vv72/GHSA-5vr5-42hq-vv72.json b/advisories/unreviewed/2022/05/GHSA-5vr5-42hq-vv72/GHSA-5vr5-42hq-vv72.json index 35cc90aacd7..2a937669c9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vr5-42hq-vv72/GHSA-5vr5-42hq-vv72.json +++ b/advisories/unreviewed/2022/05/GHSA-5vr5-42hq-vv72/GHSA-5vr5-42hq-vv72.json @@ -7,12 +7,8 @@ "CVE-2008-0532" ], "details": "Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly unspecified other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wrh-mqrh-qmxx/GHSA-5wrh-mqrh-qmxx.json b/advisories/unreviewed/2022/05/GHSA-5wrh-mqrh-qmxx/GHSA-5wrh-mqrh-qmxx.json index de68f492f81..2ef7149e77a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wrh-mqrh-qmxx/GHSA-5wrh-mqrh-qmxx.json +++ b/advisories/unreviewed/2022/05/GHSA-5wrh-mqrh-qmxx/GHSA-5wrh-mqrh-qmxx.json @@ -7,12 +7,8 @@ "CVE-2008-0685" ], "details": "SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5x75-7qcc-g97p/GHSA-5x75-7qcc-g97p.json b/advisories/unreviewed/2022/05/GHSA-5x75-7qcc-g97p/GHSA-5x75-7qcc-g97p.json index 6f0d37b4367..d6596b4c7ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x75-7qcc-g97p/GHSA-5x75-7qcc-g97p.json +++ b/advisories/unreviewed/2022/05/GHSA-5x75-7qcc-g97p/GHSA-5x75-7qcc-g97p.json @@ -7,12 +7,8 @@ "CVE-2008-0422" ], "details": "SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xcv-g3q8-q748/GHSA-5xcv-g3q8-q748.json b/advisories/unreviewed/2022/05/GHSA-5xcv-g3q8-q748/GHSA-5xcv-g3q8-q748.json index c7ac9df627c..62be2edfef5 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xcv-g3q8-q748/GHSA-5xcv-g3q8-q748.json +++ b/advisories/unreviewed/2022/05/GHSA-5xcv-g3q8-q748/GHSA-5xcv-g3q8-q748.json @@ -7,12 +7,8 @@ "CVE-2008-0777" ], "details": "The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xx9-j974-r78v/GHSA-5xx9-j974-r78v.json b/advisories/unreviewed/2022/05/GHSA-5xx9-j974-r78v/GHSA-5xx9-j974-r78v.json index b3486d66110..25ca494c08e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xx9-j974-r78v/GHSA-5xx9-j974-r78v.json +++ b/advisories/unreviewed/2022/05/GHSA-5xx9-j974-r78v/GHSA-5xx9-j974-r78v.json @@ -7,12 +7,8 @@ "CVE-2008-0949" ], "details": "Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 7.x through 11.x allows remote attackers to gain privileges via a malformed connection request packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-62j9-25gg-9w4w/GHSA-62j9-25gg-9w4w.json b/advisories/unreviewed/2022/05/GHSA-62j9-25gg-9w4w/GHSA-62j9-25gg-9w4w.json index 9f67ba163ed..9ffbd6c6023 100644 --- a/advisories/unreviewed/2022/05/GHSA-62j9-25gg-9w4w/GHSA-62j9-25gg-9w4w.json +++ b/advisories/unreviewed/2022/05/GHSA-62j9-25gg-9w4w/GHSA-62j9-25gg-9w4w.json @@ -7,12 +7,8 @@ "CVE-2008-0945" ], "details": "Format string vulnerability in the logging function in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in an IP address field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63j4-pqpq-mx6j/GHSA-63j4-pqpq-mx6j.json b/advisories/unreviewed/2022/05/GHSA-63j4-pqpq-mx6j/GHSA-63j4-pqpq-mx6j.json index a6f3e72b6de..56af51ca6b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-63j4-pqpq-mx6j/GHSA-63j4-pqpq-mx6j.json +++ b/advisories/unreviewed/2022/05/GHSA-63j4-pqpq-mx6j/GHSA-63j4-pqpq-mx6j.json @@ -7,12 +7,8 @@ "CVE-2008-0877" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) frontend, (2) set_frontend, (3) jz_path, (4) theme, and (5) set_theme parameters to (a) index.php; the frontend, theme, and (6) language parameters to (b) ajax_request.php; the jz_path parameter to (c) slim.php; the frontend, theme, and jz_path parameters to (d) popup.php; the (13) PATH_INFO to index.php and (e) slim.php; and the (14) query parameter in a playlistedit action and (15) siteNewsData parameter in a sitenews action to (f) popup.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6659-x3qw-v7p5/GHSA-6659-x3qw-v7p5.json b/advisories/unreviewed/2022/05/GHSA-6659-x3qw-v7p5/GHSA-6659-x3qw-v7p5.json index 9f14f48b7d2..f80c13983a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6659-x3qw-v7p5/GHSA-6659-x3qw-v7p5.json +++ b/advisories/unreviewed/2022/05/GHSA-6659-x3qw-v7p5/GHSA-6659-x3qw-v7p5.json @@ -7,12 +7,8 @@ "CVE-2019-1391" ], "details": "A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2018-12207.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-666g-7q89-v43p/GHSA-666g-7q89-v43p.json b/advisories/unreviewed/2022/05/GHSA-666g-7q89-v43p/GHSA-666g-7q89-v43p.json index 06ebea57136..02b28030d8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-666g-7q89-v43p/GHSA-666g-7q89-v43p.json +++ b/advisories/unreviewed/2022/05/GHSA-666g-7q89-v43p/GHSA-666g-7q89-v43p.json @@ -7,12 +7,8 @@ "CVE-2008-0547" ], "details": "Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-678v-x23j-wprq/GHSA-678v-x23j-wprq.json b/advisories/unreviewed/2022/05/GHSA-678v-x23j-wprq/GHSA-678v-x23j-wprq.json index 969b1ee15a9..9b22c81b16a 100644 --- a/advisories/unreviewed/2022/05/GHSA-678v-x23j-wprq/GHSA-678v-x23j-wprq.json +++ b/advisories/unreviewed/2022/05/GHSA-678v-x23j-wprq/GHSA-678v-x23j-wprq.json @@ -7,12 +7,8 @@ "CVE-2008-0441" ], "details": "IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-67q9-w47f-fvr8/GHSA-67q9-w47f-fvr8.json b/advisories/unreviewed/2022/05/GHSA-67q9-w47f-fvr8/GHSA-67q9-w47f-fvr8.json index 65fe90ca9ce..f4ba3e4bba2 100644 --- a/advisories/unreviewed/2022/05/GHSA-67q9-w47f-fvr8/GHSA-67q9-w47f-fvr8.json +++ b/advisories/unreviewed/2022/05/GHSA-67q9-w47f-fvr8/GHSA-67q9-w47f-fvr8.json @@ -7,12 +7,8 @@ "CVE-2019-1390" ], "details": "A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-687h-28h6-mpf8/GHSA-687h-28h6-mpf8.json b/advisories/unreviewed/2022/05/GHSA-687h-28h6-mpf8/GHSA-687h-28h6-mpf8.json index da7b7226dec..66e3c45fe0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-687h-28h6-mpf8/GHSA-687h-28h6-mpf8.json +++ b/advisories/unreviewed/2022/05/GHSA-687h-28h6-mpf8/GHSA-687h-28h6-mpf8.json @@ -7,12 +7,8 @@ "CVE-2008-0940" ], "details": "Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.4.24 allows remote attackers to inject arbitrary web script or HTML when creating a username, a different vulnerability than CVE-2007-0407.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6958-9457-vvw5/GHSA-6958-9457-vvw5.json b/advisories/unreviewed/2022/05/GHSA-6958-9457-vvw5/GHSA-6958-9457-vvw5.json index 2d93789fc84..47e8fbdc9d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6958-9457-vvw5/GHSA-6958-9457-vvw5.json +++ b/advisories/unreviewed/2022/05/GHSA-6958-9457-vvw5/GHSA-6958-9457-vvw5.json @@ -7,12 +7,8 @@ "CVE-2008-0871" ], "details": "Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6c8r-rp57-8jc3/GHSA-6c8r-rp57-8jc3.json b/advisories/unreviewed/2022/05/GHSA-6c8r-rp57-8jc3/GHSA-6c8r-rp57-8jc3.json index ed30673f41e..3bc1a6ea3b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c8r-rp57-8jc3/GHSA-6c8r-rp57-8jc3.json +++ b/advisories/unreviewed/2022/05/GHSA-6c8r-rp57-8jc3/GHSA-6c8r-rp57-8jc3.json @@ -7,12 +7,8 @@ "CVE-2008-0427" ], "details": "Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cgj-54pv-ggm2/GHSA-6cgj-54pv-ggm2.json b/advisories/unreviewed/2022/05/GHSA-6cgj-54pv-ggm2/GHSA-6cgj-54pv-ggm2.json index 313764798fc..83e4861d9f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cgj-54pv-ggm2/GHSA-6cgj-54pv-ggm2.json +++ b/advisories/unreviewed/2022/05/GHSA-6cgj-54pv-ggm2/GHSA-6cgj-54pv-ggm2.json @@ -7,12 +7,8 @@ "CVE-2008-0420" ], "details": "modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cmr-65fv-jmxc/GHSA-6cmr-65fv-jmxc.json b/advisories/unreviewed/2022/05/GHSA-6cmr-65fv-jmxc/GHSA-6cmr-65fv-jmxc.json index 6ed5208572d..ba0bd6ffb8c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cmr-65fv-jmxc/GHSA-6cmr-65fv-jmxc.json +++ b/advisories/unreviewed/2022/05/GHSA-6cmr-65fv-jmxc/GHSA-6cmr-65fv-jmxc.json @@ -7,12 +7,8 @@ "CVE-2008-0602" ], "details": "Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the class_name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6cpp-547f-8pvw/GHSA-6cpp-547f-8pvw.json b/advisories/unreviewed/2022/05/GHSA-6cpp-547f-8pvw/GHSA-6cpp-547f-8pvw.json index eb40bffc28b..668a551d29b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6cpp-547f-8pvw/GHSA-6cpp-547f-8pvw.json +++ b/advisories/unreviewed/2022/05/GHSA-6cpp-547f-8pvw/GHSA-6cpp-547f-8pvw.json @@ -7,12 +7,8 @@ "CVE-2008-0523" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SoftCart.exe in SoftCart 5.1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) License_Plate, (2) License_State, (3) Ticket_Date, and (4) Ticket_Number parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f4f-mvfg-v7fq/GHSA-6f4f-mvfg-v7fq.json b/advisories/unreviewed/2022/05/GHSA-6f4f-mvfg-v7fq/GHSA-6f4f-mvfg-v7fq.json index 215009e1ca5..fade62da07f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f4f-mvfg-v7fq/GHSA-6f4f-mvfg-v7fq.json +++ b/advisories/unreviewed/2022/05/GHSA-6f4f-mvfg-v7fq/GHSA-6f4f-mvfg-v7fq.json @@ -7,12 +7,8 @@ "CVE-2008-0494" ], "details": "Cross-site scripting (XSS) vulnerability in vpnum/userslist.php in Endian Firewall 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the psearch parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6f9f-7fcw-8qj9/GHSA-6f9f-7fcw-8qj9.json b/advisories/unreviewed/2022/05/GHSA-6f9f-7fcw-8qj9/GHSA-6f9f-7fcw-8qj9.json index d29a543eedb..a86a6b48365 100644 --- a/advisories/unreviewed/2022/05/GHSA-6f9f-7fcw-8qj9/GHSA-6f9f-7fcw-8qj9.json +++ b/advisories/unreviewed/2022/05/GHSA-6f9f-7fcw-8qj9/GHSA-6f9f-7fcw-8qj9.json @@ -7,12 +7,8 @@ "CVE-2008-0569" ], "details": "The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fgq-4c34-h75j/GHSA-6fgq-4c34-h75j.json b/advisories/unreviewed/2022/05/GHSA-6fgq-4c34-h75j/GHSA-6fgq-4c34-h75j.json index 81b2c5348c0..12f70df6cdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fgq-4c34-h75j/GHSA-6fgq-4c34-h75j.json +++ b/advisories/unreviewed/2022/05/GHSA-6fgq-4c34-h75j/GHSA-6fgq-4c34-h75j.json @@ -7,12 +7,8 @@ "CVE-2008-0656" ], "details": "Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hjr-3r96-ph8v/GHSA-6hjr-3r96-ph8v.json b/advisories/unreviewed/2022/05/GHSA-6hjr-3r96-ph8v/GHSA-6hjr-3r96-ph8v.json index 3f5eb712476..176e9b2001a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hjr-3r96-ph8v/GHSA-6hjr-3r96-ph8v.json +++ b/advisories/unreviewed/2022/05/GHSA-6hjr-3r96-ph8v/GHSA-6hjr-3r96-ph8v.json @@ -7,12 +7,8 @@ "CVE-2008-0403" ], "details": "The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jrf-c5m2-vhqj/GHSA-6jrf-c5m2-vhqj.json b/advisories/unreviewed/2022/05/GHSA-6jrf-c5m2-vhqj/GHSA-6jrf-c5m2-vhqj.json index 753c2b6f32d..7467fba7fc7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jrf-c5m2-vhqj/GHSA-6jrf-c5m2-vhqj.json +++ b/advisories/unreviewed/2022/05/GHSA-6jrf-c5m2-vhqj/GHSA-6jrf-c5m2-vhqj.json @@ -7,12 +7,8 @@ "CVE-2008-0794" ], "details": "Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jrv-5rfh-444c/GHSA-6jrv-5rfh-444c.json b/advisories/unreviewed/2022/05/GHSA-6jrv-5rfh-444c/GHSA-6jrv-5rfh-444c.json index 2f74da2678a..4d291d1650d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jrv-5rfh-444c/GHSA-6jrv-5rfh-444c.json +++ b/advisories/unreviewed/2022/05/GHSA-6jrv-5rfh-444c/GHSA-6jrv-5rfh-444c.json @@ -7,12 +7,8 @@ "CVE-2008-0669" ], "details": "Cross-site scripting (XSS) vulnerability in search.cgi in Sift Unity allows remote attackers to inject arbitrary web script or HTML via the qt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6m6r-34m3-5m2p/GHSA-6m6r-34m3-5m2p.json b/advisories/unreviewed/2022/05/GHSA-6m6r-34m3-5m2p/GHSA-6m6r-34m3-5m2p.json index 4ddd66885f4..52d540f8a7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m6r-34m3-5m2p/GHSA-6m6r-34m3-5m2p.json +++ b/advisories/unreviewed/2022/05/GHSA-6m6r-34m3-5m2p/GHSA-6m6r-34m3-5m2p.json @@ -7,12 +7,8 @@ "CVE-2008-0612" ], "details": "Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6m84-667v-m265/GHSA-6m84-667v-m265.json b/advisories/unreviewed/2022/05/GHSA-6m84-667v-m265/GHSA-6m84-667v-m265.json index c7c9d73003a..136b0e0fc6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m84-667v-m265/GHSA-6m84-667v-m265.json +++ b/advisories/unreviewed/2022/05/GHSA-6m84-667v-m265/GHSA-6m84-667v-m265.json @@ -7,12 +7,8 @@ "CVE-2008-0930" ], "details": "w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6qhc-v2h9-m47w/GHSA-6qhc-v2h9-m47w.json b/advisories/unreviewed/2022/05/GHSA-6qhc-v2h9-m47w/GHSA-6qhc-v2h9-m47w.json index 4949b71adb9..779281b5231 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qhc-v2h9-m47w/GHSA-6qhc-v2h9-m47w.json +++ b/advisories/unreviewed/2022/05/GHSA-6qhc-v2h9-m47w/GHSA-6qhc-v2h9-m47w.json @@ -7,12 +7,8 @@ "CVE-2008-0903" ], "details": "Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause a denial of service (web server crash) via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qxg-xc5c-vm8h/GHSA-6qxg-xc5c-vm8h.json b/advisories/unreviewed/2022/05/GHSA-6qxg-xc5c-vm8h/GHSA-6qxg-xc5c-vm8h.json index a7cac609695..c96b5be5560 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qxg-xc5c-vm8h/GHSA-6qxg-xc5c-vm8h.json +++ b/advisories/unreviewed/2022/05/GHSA-6qxg-xc5c-vm8h/GHSA-6qxg-xc5c-vm8h.json @@ -7,12 +7,8 @@ "CVE-2019-2163" ], "details": "In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118138797", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6r33-h68m-pxhm/GHSA-6r33-h68m-pxhm.json b/advisories/unreviewed/2022/05/GHSA-6r33-h68m-pxhm/GHSA-6r33-h68m-pxhm.json index c42909b9d36..7a3fedc0c7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r33-h68m-pxhm/GHSA-6r33-h68m-pxhm.json +++ b/advisories/unreviewed/2022/05/GHSA-6r33-h68m-pxhm/GHSA-6r33-h68m-pxhm.json @@ -7,12 +7,8 @@ "CVE-2008-0597" ], "details": "Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (crash) via crafted IPP packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6vr8-qvq2-r64x/GHSA-6vr8-qvq2-r64x.json b/advisories/unreviewed/2022/05/GHSA-6vr8-qvq2-r64x/GHSA-6vr8-qvq2-r64x.json index be85ef7e11c..8ed3f028ab7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6vr8-qvq2-r64x/GHSA-6vr8-qvq2-r64x.json +++ b/advisories/unreviewed/2022/05/GHSA-6vr8-qvq2-r64x/GHSA-6vr8-qvq2-r64x.json @@ -7,12 +7,8 @@ "CVE-2008-0729" ], "details": "Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain JavaScript code that constructs a long string and an array containing long string elements, possibly a related issue to CVE-2006-3677. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x9q-4j27-hghp/GHSA-6x9q-4j27-hghp.json b/advisories/unreviewed/2022/05/GHSA-6x9q-4j27-hghp/GHSA-6x9q-4j27-hghp.json index c0b94764c17..5556099c0d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x9q-4j27-hghp/GHSA-6x9q-4j27-hghp.json +++ b/advisories/unreviewed/2022/05/GHSA-6x9q-4j27-hghp/GHSA-6x9q-4j27-hghp.json @@ -7,12 +7,8 @@ "CVE-2008-0721" ], "details": "SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to execute arbitrary SQL commands via the gid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xf6-c569-9p45/GHSA-6xf6-c569-9p45.json b/advisories/unreviewed/2022/05/GHSA-6xf6-c569-9p45/GHSA-6xf6-c569-9p45.json index 553bb185d7d..88bad68c6b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xf6-c569-9p45/GHSA-6xf6-c569-9p45.json +++ b/advisories/unreviewed/2022/05/GHSA-6xf6-c569-9p45/GHSA-6xf6-c569-9p45.json @@ -7,12 +7,8 @@ "CVE-2008-0957" ], "details": "Multiple stack-based buffer overflows in the PhotoStockPlus Uploader Tool ActiveX control (PSPUploader.ocx) allow remote attackers to execute arbitrary code via unspecified initialization parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xjx-jphh-cf8v/GHSA-6xjx-jphh-cf8v.json b/advisories/unreviewed/2022/05/GHSA-6xjx-jphh-cf8v/GHSA-6xjx-jphh-cf8v.json index bad217d65e1..2cd208d5eb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xjx-jphh-cf8v/GHSA-6xjx-jphh-cf8v.json +++ b/advisories/unreviewed/2022/05/GHSA-6xjx-jphh-cf8v/GHSA-6xjx-jphh-cf8v.json @@ -7,12 +7,8 @@ "CVE-2012-1572" ], "details": "OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6xv8-9fq3-w8xq/GHSA-6xv8-9fq3-w8xq.json b/advisories/unreviewed/2022/05/GHSA-6xv8-9fq3-w8xq/GHSA-6xv8-9fq3-w8xq.json index 9537c8d9015..3b6a8332dab 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xv8-9fq3-w8xq/GHSA-6xv8-9fq3-w8xq.json +++ b/advisories/unreviewed/2022/05/GHSA-6xv8-9fq3-w8xq/GHSA-6xv8-9fq3-w8xq.json @@ -7,12 +7,8 @@ "CVE-2008-0793" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in search.asp in Tendenci CMS allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) searchtext, (3) jobcategoryid, (4) contactcompany, and unspecified other parameters. NOTE: some of these details are obtained from third party information. NOTE: it is not clear whether this affects Tendenci Enterprise Edition in addition to the product's deployment on Tendenci's own server farm. If only the latter was affected, then this issue should not be included in CVE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72r3-j5vh-qx4c/GHSA-72r3-j5vh-qx4c.json b/advisories/unreviewed/2022/05/GHSA-72r3-j5vh-qx4c/GHSA-72r3-j5vh-qx4c.json index 31ce0511e47..b59e448b08b 100644 --- a/advisories/unreviewed/2022/05/GHSA-72r3-j5vh-qx4c/GHSA-72r3-j5vh-qx4c.json +++ b/advisories/unreviewed/2022/05/GHSA-72r3-j5vh-qx4c/GHSA-72r3-j5vh-qx4c.json @@ -7,12 +7,8 @@ "CVE-2008-0630" ], "details": "Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823 allows remote attackers to execute arbitrary code via a crafted URL that prevents the IPv6 parsing code from setting a pointer to NULL, which causes the buffer to be reused by the unescape code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-732p-4r7p-jxmm/GHSA-732p-4r7p-jxmm.json b/advisories/unreviewed/2022/05/GHSA-732p-4r7p-jxmm/GHSA-732p-4r7p-jxmm.json index 7d6bf2108f4..359829e719b 100644 --- a/advisories/unreviewed/2022/05/GHSA-732p-4r7p-jxmm/GHSA-732p-4r7p-jxmm.json +++ b/advisories/unreviewed/2022/05/GHSA-732p-4r7p-jxmm/GHSA-732p-4r7p-jxmm.json @@ -7,12 +7,8 @@ "CVE-2008-0701" ], "details": "ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73hp-87pm-246v/GHSA-73hp-87pm-246v.json b/advisories/unreviewed/2022/05/GHSA-73hp-87pm-246v/GHSA-73hp-87pm-246v.json index 4e71359d6fb..511aee61c73 100644 --- a/advisories/unreviewed/2022/05/GHSA-73hp-87pm-246v/GHSA-73hp-87pm-246v.json +++ b/advisories/unreviewed/2022/05/GHSA-73hp-87pm-246v/GHSA-73hp-87pm-246v.json @@ -7,12 +7,8 @@ "CVE-2019-1309" ], "details": "A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1310, CVE-2019-1399.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73v2-jpg5-227f/GHSA-73v2-jpg5-227f.json b/advisories/unreviewed/2022/05/GHSA-73v2-jpg5-227f/GHSA-73v2-jpg5-227f.json index 39340104ddc..70bc9d383e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-73v2-jpg5-227f/GHSA-73v2-jpg5-227f.json +++ b/advisories/unreviewed/2022/05/GHSA-73v2-jpg5-227f/GHSA-73v2-jpg5-227f.json @@ -7,12 +7,8 @@ "CVE-2008-0524" ], "details": "Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73wm-mmp3-692g/GHSA-73wm-mmp3-692g.json b/advisories/unreviewed/2022/05/GHSA-73wm-mmp3-692g/GHSA-73wm-mmp3-692g.json index 7eb1c5d6975..8cef1b2ed05 100644 --- a/advisories/unreviewed/2022/05/GHSA-73wm-mmp3-692g/GHSA-73wm-mmp3-692g.json +++ b/advisories/unreviewed/2022/05/GHSA-73wm-mmp3-692g/GHSA-73wm-mmp3-692g.json @@ -7,12 +7,8 @@ "CVE-2008-0409" ], "details": "Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76h3-fg2p-v3m4/GHSA-76h3-fg2p-v3m4.json b/advisories/unreviewed/2022/05/GHSA-76h3-fg2p-v3m4/GHSA-76h3-fg2p-v3m4.json index a9de945097e..e0b1d3ec337 100644 --- a/advisories/unreviewed/2022/05/GHSA-76h3-fg2p-v3m4/GHSA-76h3-fg2p-v3m4.json +++ b/advisories/unreviewed/2022/05/GHSA-76h3-fg2p-v3m4/GHSA-76h3-fg2p-v3m4.json @@ -7,12 +7,8 @@ "CVE-2008-0738" ], "details": "Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust parameter to (a) ajax_getTiers.asp and (b) ajax_getCust.asp in ajax/, and the (2) tableName parameter to (c) ajax/ajax_tableFields.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77xw-gwf8-4mv7/GHSA-77xw-gwf8-4mv7.json b/advisories/unreviewed/2022/05/GHSA-77xw-gwf8-4mv7/GHSA-77xw-gwf8-4mv7.json index 8b86327b275..f91a7ab3f39 100644 --- a/advisories/unreviewed/2022/05/GHSA-77xw-gwf8-4mv7/GHSA-77xw-gwf8-4mv7.json +++ b/advisories/unreviewed/2022/05/GHSA-77xw-gwf8-4mv7/GHSA-77xw-gwf8-4mv7.json @@ -7,12 +7,8 @@ "CVE-2008-0680" ], "details": "SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7843-hchm-wf25/GHSA-7843-hchm-wf25.json b/advisories/unreviewed/2022/05/GHSA-7843-hchm-wf25/GHSA-7843-hchm-wf25.json index 6d4b85a37e9..b5060464ba4 100644 --- a/advisories/unreviewed/2022/05/GHSA-7843-hchm-wf25/GHSA-7843-hchm-wf25.json +++ b/advisories/unreviewed/2022/05/GHSA-7843-hchm-wf25/GHSA-7843-hchm-wf25.json @@ -7,12 +7,8 @@ "CVE-2008-0555" ], "details": "The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78g2-xjfj-jhp5/GHSA-78g2-xjfj-jhp5.json b/advisories/unreviewed/2022/05/GHSA-78g2-xjfj-jhp5/GHSA-78g2-xjfj-jhp5.json index 7f6d1adf98a..9489b953521 100644 --- a/advisories/unreviewed/2022/05/GHSA-78g2-xjfj-jhp5/GHSA-78g2-xjfj-jhp5.json +++ b/advisories/unreviewed/2022/05/GHSA-78g2-xjfj-jhp5/GHSA-78g2-xjfj-jhp5.json @@ -7,12 +7,8 @@ "CVE-2008-0864" ], "details": "Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78gp-485q-x3wf/GHSA-78gp-485q-x3wf.json b/advisories/unreviewed/2022/05/GHSA-78gp-485q-x3wf/GHSA-78gp-485q-x3wf.json index 3cab6d55ff7..448ee288905 100644 --- a/advisories/unreviewed/2022/05/GHSA-78gp-485q-x3wf/GHSA-78gp-485q-x3wf.json +++ b/advisories/unreviewed/2022/05/GHSA-78gp-485q-x3wf/GHSA-78gp-485q-x3wf.json @@ -7,12 +7,8 @@ "CVE-2008-0663" ], "details": "Novell Challenge Response Client (LCM) 2.7.5 and earlier, as used with Novell Client for Windows 4.91 SP4, allows users with physical access to a locked system to obtain contents of the clipboard by pasting the contents into the Challenge Question field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-792g-cwgg-vq55/GHSA-792g-cwgg-vq55.json b/advisories/unreviewed/2022/05/GHSA-792g-cwgg-vq55/GHSA-792g-cwgg-vq55.json index 6fee398024f..9b1392daf69 100644 --- a/advisories/unreviewed/2022/05/GHSA-792g-cwgg-vq55/GHSA-792g-cwgg-vq55.json +++ b/advisories/unreviewed/2022/05/GHSA-792g-cwgg-vq55/GHSA-792g-cwgg-vq55.json @@ -7,12 +7,8 @@ "CVE-2019-1374" ], "details": "An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-79j3-hc9x-7c9p/GHSA-79j3-hc9x-7c9p.json b/advisories/unreviewed/2022/05/GHSA-79j3-hc9x-7c9p/GHSA-79j3-hc9x-7c9p.json index 0cc62e19a3a..2a8bca576b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-79j3-hc9x-7c9p/GHSA-79j3-hc9x-7c9p.json +++ b/advisories/unreviewed/2022/05/GHSA-79j3-hc9x-7c9p/GHSA-79j3-hc9x-7c9p.json @@ -7,12 +7,8 @@ "CVE-2008-0725" ], "details": "Multiple heap-based buffer overflows in the (1) FTP service and (2) administration service in Titan FTP Server 6.0.5.549 allow remote attackers to cause a denial of service (daemon hang) and possibly execute arbitrary code via a long command. NOTE: the USER and PASS commands for the FTP service are covered by CVE-2008-0702.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gf4-whwv-4j38/GHSA-7gf4-whwv-4j38.json b/advisories/unreviewed/2022/05/GHSA-7gf4-whwv-4j38/GHSA-7gf4-whwv-4j38.json index 691a49d5f89..ac15b0499e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gf4-whwv-4j38/GHSA-7gf4-whwv-4j38.json +++ b/advisories/unreviewed/2022/05/GHSA-7gf4-whwv-4j38/GHSA-7gf4-whwv-4j38.json @@ -7,12 +7,8 @@ "CVE-2008-0754" ], "details": "Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id parameter in a viewcategorysrecipes action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7gm8-63p6-q3r8/GHSA-7gm8-63p6-q3r8.json b/advisories/unreviewed/2022/05/GHSA-7gm8-63p6-q3r8/GHSA-7gm8-63p6-q3r8.json index e864bc5c81b..7a8428e0478 100644 --- a/advisories/unreviewed/2022/05/GHSA-7gm8-63p6-q3r8/GHSA-7gm8-63p6-q3r8.json +++ b/advisories/unreviewed/2022/05/GHSA-7gm8-63p6-q3r8/GHSA-7gm8-63p6-q3r8.json @@ -7,12 +7,8 @@ "CVE-2008-0956" ], "details": "Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pvx-fpc9-x3m6/GHSA-7pvx-fpc9-x3m6.json b/advisories/unreviewed/2022/05/GHSA-7pvx-fpc9-x3m6/GHSA-7pvx-fpc9-x3m6.json index 59264b382d4..31e7f71cb7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pvx-fpc9-x3m6/GHSA-7pvx-fpc9-x3m6.json +++ b/advisories/unreviewed/2022/05/GHSA-7pvx-fpc9-x3m6/GHSA-7pvx-fpc9-x3m6.json @@ -7,12 +7,8 @@ "CVE-2008-0478" ], "details": "Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set parameter, as demonstrated by sending a certain CLIENT_IP HTTP header in an enter action to index.php, and injecting PHP sequences into files/enter.set, which is then included by index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qpv-46q8-gxjc/GHSA-7qpv-46q8-gxjc.json b/advisories/unreviewed/2022/05/GHSA-7qpv-46q8-gxjc/GHSA-7qpv-46q8-gxjc.json index 53cc8b53266..48fbbe4f7bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qpv-46q8-gxjc/GHSA-7qpv-46q8-gxjc.json +++ b/advisories/unreviewed/2022/05/GHSA-7qpv-46q8-gxjc/GHSA-7qpv-46q8-gxjc.json @@ -7,12 +7,8 @@ "CVE-2008-0761" ], "details": "SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a players action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vg7-f23p-g49g/GHSA-7vg7-f23p-g49g.json b/advisories/unreviewed/2022/05/GHSA-7vg7-f23p-g49g/GHSA-7vg7-f23p-g49g.json index 6a0ef1e6afa..e9b02d538b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vg7-f23p-g49g/GHSA-7vg7-f23p-g49g.json +++ b/advisories/unreviewed/2022/05/GHSA-7vg7-f23p-g49g/GHSA-7vg7-f23p-g49g.json @@ -7,12 +7,8 @@ "CVE-2008-0613" ], "details": "Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the xoops_redirect parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7wr6-m3x7-mq75/GHSA-7wr6-m3x7-mq75.json b/advisories/unreviewed/2022/05/GHSA-7wr6-m3x7-mq75/GHSA-7wr6-m3x7-mq75.json index a327f12a5ad..2a02c37a521 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wr6-m3x7-mq75/GHSA-7wr6-m3x7-mq75.json +++ b/advisories/unreviewed/2022/05/GHSA-7wr6-m3x7-mq75/GHSA-7wr6-m3x7-mq75.json @@ -7,12 +7,8 @@ "CVE-2008-0594" ], "details": "Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote attackers to conduct phishing attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -156,9 +152,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7x66-5cj5-5342/GHSA-7x66-5cj5-5342.json b/advisories/unreviewed/2022/05/GHSA-7x66-5cj5-5342/GHSA-7x66-5cj5-5342.json index 59744b5357c..d292d0728c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x66-5cj5-5342/GHSA-7x66-5cj5-5342.json +++ b/advisories/unreviewed/2022/05/GHSA-7x66-5cj5-5342/GHSA-7x66-5cj5-5342.json @@ -7,12 +7,8 @@ "CVE-2008-0623" ], "details": "Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7x72-m5pv-w2m4/GHSA-7x72-m5pv-w2m4.json b/advisories/unreviewed/2022/05/GHSA-7x72-m5pv-w2m4/GHSA-7x72-m5pv-w2m4.json index 6ff6256fa82..e23ff5f5a96 100644 --- a/advisories/unreviewed/2022/05/GHSA-7x72-m5pv-w2m4/GHSA-7x72-m5pv-w2m4.json +++ b/advisories/unreviewed/2022/05/GHSA-7x72-m5pv-w2m4/GHSA-7x72-m5pv-w2m4.json @@ -7,12 +7,8 @@ "CVE-2008-0442" ], "details": "PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8234-r487-52gh/GHSA-8234-r487-52gh.json b/advisories/unreviewed/2022/05/GHSA-8234-r487-52gh/GHSA-8234-r487-52gh.json index 702043cea43..735e09290b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8234-r487-52gh/GHSA-8234-r487-52gh.json +++ b/advisories/unreviewed/2022/05/GHSA-8234-r487-52gh/GHSA-8234-r487-52gh.json @@ -7,12 +7,8 @@ "CVE-2008-0506" ], "details": "include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8343-6fr5-65gm/GHSA-8343-6fr5-65gm.json b/advisories/unreviewed/2022/05/GHSA-8343-6fr5-65gm/GHSA-8343-6fr5-65gm.json index ef792b6c458..957919a8d67 100644 --- a/advisories/unreviewed/2022/05/GHSA-8343-6fr5-65gm/GHSA-8343-6fr5-65gm.json +++ b/advisories/unreviewed/2022/05/GHSA-8343-6fr5-65gm/GHSA-8343-6fr5-65gm.json @@ -7,12 +7,8 @@ "CVE-2008-0976" ], "details": "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed packet, as demonstrated by a packet of type (1) 0x2722 or (2) 0x272a.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-837m-69vg-m44j/GHSA-837m-69vg-m44j.json b/advisories/unreviewed/2022/05/GHSA-837m-69vg-m44j/GHSA-837m-69vg-m44j.json index 4d47c36fe6d..6575e290be2 100644 --- a/advisories/unreviewed/2022/05/GHSA-837m-69vg-m44j/GHSA-837m-69vg-m44j.json +++ b/advisories/unreviewed/2022/05/GHSA-837m-69vg-m44j/GHSA-837m-69vg-m44j.json @@ -7,12 +7,8 @@ "CVE-2008-0737" ], "details": "SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the helpfield parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83fc-xq52-pccx/GHSA-83fc-xq52-pccx.json b/advisories/unreviewed/2022/05/GHSA-83fc-xq52-pccx/GHSA-83fc-xq52-pccx.json index b274d1fa637..7bb049cbe32 100644 --- a/advisories/unreviewed/2022/05/GHSA-83fc-xq52-pccx/GHSA-83fc-xq52-pccx.json +++ b/advisories/unreviewed/2022/05/GHSA-83fc-xq52-pccx/GHSA-83fc-xq52-pccx.json @@ -7,12 +7,8 @@ "CVE-2008-0739" ], "details": "SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the FedExAccount parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-83j3-7fmr-cphx/GHSA-83j3-7fmr-cphx.json b/advisories/unreviewed/2022/05/GHSA-83j3-7fmr-cphx/GHSA-83j3-7fmr-cphx.json index e35d61ee8fa..8ba7ea5174f 100644 --- a/advisories/unreviewed/2022/05/GHSA-83j3-7fmr-cphx/GHSA-83j3-7fmr-cphx.json +++ b/advisories/unreviewed/2022/05/GHSA-83j3-7fmr-cphx/GHSA-83j3-7fmr-cphx.json @@ -7,12 +7,8 @@ "CVE-2008-0650" ], "details": "SQL injection vulnerability in login.php in Simple OS CMS 0.1c beta allows remote attackers to execute arbitrary SQL commands via the username field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84ph-43p3-259x/GHSA-84ph-43p3-259x.json b/advisories/unreviewed/2022/05/GHSA-84ph-43p3-259x/GHSA-84ph-43p3-259x.json index d12b2d2c68c..a059235b376 100644 --- a/advisories/unreviewed/2022/05/GHSA-84ph-43p3-259x/GHSA-84ph-43p3-259x.json +++ b/advisories/unreviewed/2022/05/GHSA-84ph-43p3-259x/GHSA-84ph-43p3-259x.json @@ -7,12 +7,8 @@ "CVE-2008-0893" ], "details": "Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows remote attackers to perform administrative actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-84qp-mhvx-q83f/GHSA-84qp-mhvx-q83f.json b/advisories/unreviewed/2022/05/GHSA-84qp-mhvx-q83f/GHSA-84qp-mhvx-q83f.json index 54a3be9ac4d..c5191a3c676 100644 --- a/advisories/unreviewed/2022/05/GHSA-84qp-mhvx-q83f/GHSA-84qp-mhvx-q83f.json +++ b/advisories/unreviewed/2022/05/GHSA-84qp-mhvx-q83f/GHSA-84qp-mhvx-q83f.json @@ -7,12 +7,8 @@ "CVE-2008-0797" ], "details": "Directory traversal vulnerability in lib/download.php in iTheora 1.0 rc1 allows remote attackers to read arbitrary files via directory traversal sequences in the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84wp-pp4c-2j5h/GHSA-84wp-pp4c-2j5h.json b/advisories/unreviewed/2022/05/GHSA-84wp-pp4c-2j5h/GHSA-84wp-pp4c-2j5h.json index a96b07cc453..4116e35094f 100644 --- a/advisories/unreviewed/2022/05/GHSA-84wp-pp4c-2j5h/GHSA-84wp-pp4c-2j5h.json +++ b/advisories/unreviewed/2022/05/GHSA-84wp-pp4c-2j5h/GHSA-84wp-pp4c-2j5h.json @@ -7,12 +7,8 @@ "CVE-2008-0759" ], "details": "ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allows remote attackers to cause a denial of service (daemon crash) via an invalid UAM field in a request to the Apple Filing Protocol (AFP) service on TCP port 548.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-853q-qqmx-f5hg/GHSA-853q-qqmx-f5hg.json b/advisories/unreviewed/2022/05/GHSA-853q-qqmx-f5hg/GHSA-853q-qqmx-f5hg.json index bc0725625fb..17e2ad39971 100644 --- a/advisories/unreviewed/2022/05/GHSA-853q-qqmx-f5hg/GHSA-853q-qqmx-f5hg.json +++ b/advisories/unreviewed/2022/05/GHSA-853q-qqmx-f5hg/GHSA-853q-qqmx-f5hg.json @@ -7,12 +7,8 @@ "CVE-2008-0631" ], "details": "Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or (2) modify files via the AddStringToFile method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-855p-w5fp-7588/GHSA-855p-w5fp-7588.json b/advisories/unreviewed/2022/05/GHSA-855p-w5fp-7588/GHSA-855p-w5fp-7588.json index b9b4c3f2555..4532e941bcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-855p-w5fp-7588/GHSA-855p-w5fp-7588.json +++ b/advisories/unreviewed/2022/05/GHSA-855p-w5fp-7588/GHSA-855p-w5fp-7588.json @@ -7,12 +7,8 @@ "CVE-2019-1412" ], "details": "An information disclosure vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka 'OpenType Font Driver Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85pc-mc7f-26qw/GHSA-85pc-mc7f-26qw.json b/advisories/unreviewed/2022/05/GHSA-85pc-mc7f-26qw/GHSA-85pc-mc7f-26qw.json index 658e8e35a87..8a8b296c927 100644 --- a/advisories/unreviewed/2022/05/GHSA-85pc-mc7f-26qw/GHSA-85pc-mc7f-26qw.json +++ b/advisories/unreviewed/2022/05/GHSA-85pc-mc7f-26qw/GHSA-85pc-mc7f-26qw.json @@ -7,12 +7,8 @@ "CVE-2008-0567" ], "details": "Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php, (2) Writer.php, and (3) PPS.php in excelwriter/; and (4) BIFFwriter.php, (5) Workbook.php, (6) Worksheet.php, and (7) Format.php in excelwriter/Writer/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-85wj-c2g2-23c7/GHSA-85wj-c2g2-23c7.json b/advisories/unreviewed/2022/05/GHSA-85wj-c2g2-23c7/GHSA-85wj-c2g2-23c7.json index c4c0a663370..12016f33e3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-85wj-c2g2-23c7/GHSA-85wj-c2g2-23c7.json +++ b/advisories/unreviewed/2022/05/GHSA-85wj-c2g2-23c7/GHSA-85wj-c2g2-23c7.json @@ -7,12 +7,8 @@ "CVE-2019-9272" ], "details": "In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to determine device location with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-11596047", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-878m-jp48-9823/GHSA-878m-jp48-9823.json b/advisories/unreviewed/2022/05/GHSA-878m-jp48-9823/GHSA-878m-jp48-9823.json index 1495b1782a2..933a49ee647 100644 --- a/advisories/unreviewed/2022/05/GHSA-878m-jp48-9823/GHSA-878m-jp48-9823.json +++ b/advisories/unreviewed/2022/05/GHSA-878m-jp48-9823/GHSA-878m-jp48-9823.json @@ -7,12 +7,8 @@ "CVE-2008-0628" ], "details": "The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the \"external general entities\" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8792-2rhw-hhh3/GHSA-8792-2rhw-hhh3.json b/advisories/unreviewed/2022/05/GHSA-8792-2rhw-hhh3/GHSA-8792-2rhw-hhh3.json index c20a3c1386f..8055241a664 100644 --- a/advisories/unreviewed/2022/05/GHSA-8792-2rhw-hhh3/GHSA-8792-2rhw-hhh3.json +++ b/advisories/unreviewed/2022/05/GHSA-8792-2rhw-hhh3/GHSA-8792-2rhw-hhh3.json @@ -7,12 +7,8 @@ "CVE-2008-0919" ], "details": "Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-87wg-c7r7-p6p5/GHSA-87wg-c7r7-p6p5.json b/advisories/unreviewed/2022/05/GHSA-87wg-c7r7-p6p5/GHSA-87wg-c7r7-p6p5.json index b7cf7ee0f14..3ba9c5aac09 100644 --- a/advisories/unreviewed/2022/05/GHSA-87wg-c7r7-p6p5/GHSA-87wg-c7r7-p6p5.json +++ b/advisories/unreviewed/2022/05/GHSA-87wg-c7r7-p6p5/GHSA-87wg-c7r7-p6p5.json @@ -7,12 +7,8 @@ "CVE-2008-0469" ], "details": "SQL injection vulnerability in index.php in Tiger Php News System (TPNS) 1.0b and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newscat action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-884f-qmw7-8v2m/GHSA-884f-qmw7-8v2m.json b/advisories/unreviewed/2022/05/GHSA-884f-qmw7-8v2m/GHSA-884f-qmw7-8v2m.json index 80df321794d..878761c5f31 100644 --- a/advisories/unreviewed/2022/05/GHSA-884f-qmw7-8v2m/GHSA-884f-qmw7-8v2m.json +++ b/advisories/unreviewed/2022/05/GHSA-884f-qmw7-8v2m/GHSA-884f-qmw7-8v2m.json @@ -7,12 +7,8 @@ "CVE-2008-0911" ], "details": "SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8936-4f3c-vg7r/GHSA-8936-4f3c-vg7r.json b/advisories/unreviewed/2022/05/GHSA-8936-4f3c-vg7r/GHSA-8936-4f3c-vg7r.json index 6dd05395acc..cb4dca42aad 100644 --- a/advisories/unreviewed/2022/05/GHSA-8936-4f3c-vg7r/GHSA-8936-4f3c-vg7r.json +++ b/advisories/unreviewed/2022/05/GHSA-8936-4f3c-vg7r/GHSA-8936-4f3c-vg7r.json @@ -7,12 +7,8 @@ "CVE-2008-0856" ], "details": "Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) iframe.php and (2) print.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8c72-52qr-5hg9/GHSA-8c72-52qr-5hg9.json b/advisories/unreviewed/2022/05/GHSA-8c72-52qr-5hg9/GHSA-8c72-52qr-5hg9.json index 45332f65a34..9dcadc418b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c72-52qr-5hg9/GHSA-8c72-52qr-5hg9.json +++ b/advisories/unreviewed/2022/05/GHSA-8c72-52qr-5hg9/GHSA-8c72-52qr-5hg9.json @@ -7,12 +7,8 @@ "CVE-2008-0497" ], "details": "Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted when processing PHP_SELF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cf9-698j-7r7j/GHSA-8cf9-698j-7r7j.json b/advisories/unreviewed/2022/05/GHSA-8cf9-698j-7r7j/GHSA-8cf9-698j-7r7j.json index 6905c05d767..3453e194b5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cf9-698j-7r7j/GHSA-8cf9-698j-7r7j.json +++ b/advisories/unreviewed/2022/05/GHSA-8cf9-698j-7r7j/GHSA-8cf9-698j-7r7j.json @@ -7,12 +7,8 @@ "CVE-2008-0936" ], "details": "SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8ch2-ghp3-r727/GHSA-8ch2-ghp3-r727.json b/advisories/unreviewed/2022/05/GHSA-8ch2-ghp3-r727/GHSA-8ch2-ghp3-r727.json index a92e7530dfe..7a88e7f99d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8ch2-ghp3-r727/GHSA-8ch2-ghp3-r727.json +++ b/advisories/unreviewed/2022/05/GHSA-8ch2-ghp3-r727/GHSA-8ch2-ghp3-r727.json @@ -7,12 +7,8 @@ "CVE-2008-0719" ], "details": "SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8frx-mxpf-4r9p/GHSA-8frx-mxpf-4r9p.json b/advisories/unreviewed/2022/05/GHSA-8frx-mxpf-4r9p/GHSA-8frx-mxpf-4r9p.json index 4e00da93c2a..4e260b6fa5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8frx-mxpf-4r9p/GHSA-8frx-mxpf-4r9p.json +++ b/advisories/unreviewed/2022/05/GHSA-8frx-mxpf-4r9p/GHSA-8frx-mxpf-4r9p.json @@ -7,12 +7,8 @@ "CVE-2008-0965" ], "details": "Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hfr-p2v4-j977/GHSA-8hfr-p2v4-j977.json b/advisories/unreviewed/2022/05/GHSA-8hfr-p2v4-j977/GHSA-8hfr-p2v4-j977.json index b49eeb3e9b5..ab6f19eff51 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hfr-p2v4-j977/GHSA-8hfr-p2v4-j977.json +++ b/advisories/unreviewed/2022/05/GHSA-8hfr-p2v4-j977/GHSA-8hfr-p2v4-j977.json @@ -7,12 +7,8 @@ "CVE-2008-0922" ], "details": "SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modules.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8hwf-6gqc-hpw6/GHSA-8hwf-6gqc-hpw6.json b/advisories/unreviewed/2022/05/GHSA-8hwf-6gqc-hpw6/GHSA-8hwf-6gqc-hpw6.json index 47966c6eac4..5cf55fe9b15 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hwf-6gqc-hpw6/GHSA-8hwf-6gqc-hpw6.json +++ b/advisories/unreviewed/2022/05/GHSA-8hwf-6gqc-hpw6/GHSA-8hwf-6gqc-hpw6.json @@ -7,12 +7,8 @@ "CVE-2008-0607" ], "details": "SQL injection vulnerability in index.php in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) 2.5.3 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jxx-3x82-42h5/GHSA-8jxx-3x82-42h5.json b/advisories/unreviewed/2022/05/GHSA-8jxx-3x82-42h5/GHSA-8jxx-3x82-42h5.json index 913c5032b6a..fc52fe74192 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jxx-3x82-42h5/GHSA-8jxx-3x82-42h5.json +++ b/advisories/unreviewed/2022/05/GHSA-8jxx-3x82-42h5/GHSA-8jxx-3x82-42h5.json @@ -7,12 +7,8 @@ "CVE-2008-0423" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8m98-qjh5-33jj/GHSA-8m98-qjh5-33jj.json b/advisories/unreviewed/2022/05/GHSA-8m98-qjh5-33jj/GHSA-8m98-qjh5-33jj.json index 8141c825540..2dea748f974 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m98-qjh5-33jj/GHSA-8m98-qjh5-33jj.json +++ b/advisories/unreviewed/2022/05/GHSA-8m98-qjh5-33jj/GHSA-8m98-qjh5-33jj.json @@ -7,12 +7,8 @@ "CVE-2008-0674" ], "details": "Buffer overflow in PCRE before 7.6 allows remote attackers to execute arbitrary code via a regular expression containing a character class with a large number of characters with Unicode code points greater than 255.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mff-wqx9-7fr3/GHSA-8mff-wqx9-7fr3.json b/advisories/unreviewed/2022/05/GHSA-8mff-wqx9-7fr3/GHSA-8mff-wqx9-7fr3.json index 173972ef6dc..2ac203175e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mff-wqx9-7fr3/GHSA-8mff-wqx9-7fr3.json +++ b/advisories/unreviewed/2022/05/GHSA-8mff-wqx9-7fr3/GHSA-8mff-wqx9-7fr3.json @@ -7,12 +7,8 @@ "CVE-2008-0851" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to main/admin/session_list.php in a show_message action, and (5) an avatar image to main/auth/profile.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pc6-h9qw-hq8q/GHSA-8pc6-h9qw-hq8q.json b/advisories/unreviewed/2022/05/GHSA-8pc6-h9qw-hq8q/GHSA-8pc6-h9qw-hq8q.json index 0f90613ad1e..29628104b6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pc6-h9qw-hq8q/GHSA-8pc6-h9qw-hq8q.json +++ b/advisories/unreviewed/2022/05/GHSA-8pc6-h9qw-hq8q/GHSA-8pc6-h9qw-hq8q.json @@ -7,12 +7,8 @@ "CVE-2008-0659" ], "details": "Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8pjp-4jf2-xrmw/GHSA-8pjp-4jf2-xrmw.json b/advisories/unreviewed/2022/05/GHSA-8pjp-4jf2-xrmw/GHSA-8pjp-4jf2-xrmw.json index 4006290fdcd..0ffdd0dea13 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pjp-4jf2-xrmw/GHSA-8pjp-4jf2-xrmw.json +++ b/advisories/unreviewed/2022/05/GHSA-8pjp-4jf2-xrmw/GHSA-8pjp-4jf2-xrmw.json @@ -7,12 +7,8 @@ "CVE-2008-0393" ], "details": "Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qj7-7p8r-jhqj/GHSA-8qj7-7p8r-jhqj.json b/advisories/unreviewed/2022/05/GHSA-8qj7-7p8r-jhqj/GHSA-8qj7-7p8r-jhqj.json index c3ccde7f227..28e989e5f0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qj7-7p8r-jhqj/GHSA-8qj7-7p8r-jhqj.json +++ b/advisories/unreviewed/2022/05/GHSA-8qj7-7p8r-jhqj/GHSA-8qj7-7p8r-jhqj.json @@ -7,12 +7,8 @@ "CVE-2008-0658" ], "details": "slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -132,9 +128,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8r7w-qmfc-f4gc/GHSA-8r7w-qmfc-f4gc.json b/advisories/unreviewed/2022/05/GHSA-8r7w-qmfc-f4gc/GHSA-8r7w-qmfc-f4gc.json index 52ccfa3193a..8c06c6aa543 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r7w-qmfc-f4gc/GHSA-8r7w-qmfc-f4gc.json +++ b/advisories/unreviewed/2022/05/GHSA-8r7w-qmfc-f4gc/GHSA-8r7w-qmfc-f4gc.json @@ -7,12 +7,8 @@ "CVE-2008-0381" ], "details": "Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rjr-4c5q-xwf6/GHSA-8rjr-4c5q-xwf6.json b/advisories/unreviewed/2022/05/GHSA-8rjr-4c5q-xwf6/GHSA-8rjr-4c5q-xwf6.json index 967c0f411c9..e5d5980f6a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rjr-4c5q-xwf6/GHSA-8rjr-4c5q-xwf6.json +++ b/advisories/unreviewed/2022/05/GHSA-8rjr-4c5q-xwf6/GHSA-8rjr-4c5q-xwf6.json @@ -7,12 +7,8 @@ "CVE-2008-0938" ], "details": "Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8vf9-wm7f-wh7m/GHSA-8vf9-wm7f-wh7m.json b/advisories/unreviewed/2022/05/GHSA-8vf9-wm7f-wh7m/GHSA-8vf9-wm7f-wh7m.json index 1fa645461f5..083165916c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vf9-wm7f-wh7m/GHSA-8vf9-wm7f-wh7m.json +++ b/advisories/unreviewed/2022/05/GHSA-8vf9-wm7f-wh7m/GHSA-8vf9-wm7f-wh7m.json @@ -7,12 +7,8 @@ "CVE-2008-0687" ], "details": "Cross-site scripting (XSS) vulnerability in siteadmin/editor_files/includes/load_message.php in the Youtube Clone Script allows remote attackers to inject arbitrary web script or HTML via the lang[please_wait] parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wh6-mr76-hmrp/GHSA-8wh6-mr76-hmrp.json b/advisories/unreviewed/2022/05/GHSA-8wh6-mr76-hmrp/GHSA-8wh6-mr76-hmrp.json index 23d6728e263..56f30215e2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wh6-mr76-hmrp/GHSA-8wh6-mr76-hmrp.json +++ b/advisories/unreviewed/2022/05/GHSA-8wh6-mr76-hmrp/GHSA-8wh6-mr76-hmrp.json @@ -7,12 +7,8 @@ "CVE-2008-0457" ], "details": "Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wxg-6qq5-7mhm/GHSA-8wxg-6qq5-7mhm.json b/advisories/unreviewed/2022/05/GHSA-8wxg-6qq5-7mhm/GHSA-8wxg-6qq5-7mhm.json index 84ccfcf709e..3c5ebc7d21a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wxg-6qq5-7mhm/GHSA-8wxg-6qq5-7mhm.json +++ b/advisories/unreviewed/2022/05/GHSA-8wxg-6qq5-7mhm/GHSA-8wxg-6qq5-7mhm.json @@ -7,12 +7,8 @@ "CVE-2008-0974" ], "details": "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon termination) via (1) a large vector value, which raises a \"vector too long\" exception; or (2) a certain packet that raises an ospace/time/src\\date.cpp exception.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9289-97hw-35m8/GHSA-9289-97hw-35m8.json b/advisories/unreviewed/2022/05/GHSA-9289-97hw-35m8/GHSA-9289-97hw-35m8.json index 03ca0aed8fb..38573d30915 100644 --- a/advisories/unreviewed/2022/05/GHSA-9289-97hw-35m8/GHSA-9289-97hw-35m8.json +++ b/advisories/unreviewed/2022/05/GHSA-9289-97hw-35m8/GHSA-9289-97hw-35m8.json @@ -7,12 +7,8 @@ "CVE-2008-0514" ], "details": "SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92cc-ggv3-9g6m/GHSA-92cc-ggv3-9g6m.json b/advisories/unreviewed/2022/05/GHSA-92cc-ggv3-9g6m/GHSA-92cc-ggv3-9g6m.json index a1059e6a83e..5b6eaa55aa9 100644 --- a/advisories/unreviewed/2022/05/GHSA-92cc-ggv3-9g6m/GHSA-92cc-ggv3-9g6m.json +++ b/advisories/unreviewed/2022/05/GHSA-92cc-ggv3-9g6m/GHSA-92cc-ggv3-9g6m.json @@ -7,12 +7,8 @@ "CVE-2008-0679" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in BlogPHP 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92hw-2m7p-xj5c/GHSA-92hw-2m7p-xj5c.json b/advisories/unreviewed/2022/05/GHSA-92hw-2m7p-xj5c/GHSA-92hw-2m7p-xj5c.json index cfba4d40b4a..bf28c214694 100644 --- a/advisories/unreviewed/2022/05/GHSA-92hw-2m7p-xj5c/GHSA-92hw-2m7p-xj5c.json +++ b/advisories/unreviewed/2022/05/GHSA-92hw-2m7p-xj5c/GHSA-92hw-2m7p-xj5c.json @@ -7,12 +7,8 @@ "CVE-2008-0428" ], "details": "Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93cr-868g-mqgf/GHSA-93cr-868g-mqgf.json b/advisories/unreviewed/2022/05/GHSA-93cr-868g-mqgf/GHSA-93cr-868g-mqgf.json index 03e9fbef9f6..4ff6a9ccd5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-93cr-868g-mqgf/GHSA-93cr-868g-mqgf.json +++ b/advisories/unreviewed/2022/05/GHSA-93cr-868g-mqgf/GHSA-93cr-868g-mqgf.json @@ -7,12 +7,8 @@ "CVE-2008-0643" ], "details": "Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94ch-c66r-hw64/GHSA-94ch-c66r-hw64.json b/advisories/unreviewed/2022/05/GHSA-94ch-c66r-hw64/GHSA-94ch-c66r-hw64.json index a1c60d6df41..e299e150155 100644 --- a/advisories/unreviewed/2022/05/GHSA-94ch-c66r-hw64/GHSA-94ch-c66r-hw64.json +++ b/advisories/unreviewed/2022/05/GHSA-94ch-c66r-hw64/GHSA-94ch-c66r-hw64.json @@ -7,12 +7,8 @@ "CVE-2008-0861" ], "details": "Cross-site scripting (XSS) vulnerability in leg/Main.nsf in IBM Lotus Quickplace 7.0 allows remote attackers to inject arbitrary web script or HTML via an h_SearchString sub-parameter in the PreSetFields parameter of an EditDocument action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95r5-99mc-hv7q/GHSA-95r5-99mc-hv7q.json b/advisories/unreviewed/2022/05/GHSA-95r5-99mc-hv7q/GHSA-95r5-99mc-hv7q.json index 14813105055..a3d60b40834 100644 --- a/advisories/unreviewed/2022/05/GHSA-95r5-99mc-hv7q/GHSA-95r5-99mc-hv7q.json +++ b/advisories/unreviewed/2022/05/GHSA-95r5-99mc-hv7q/GHSA-95r5-99mc-hv7q.json @@ -7,12 +7,8 @@ "CVE-2008-0638" ], "details": "Heap-based buffer overflow in the Veritas Enterprise Administrator (VEA) service (aka vxsvc.exe) in Symantec Veritas Storage Foundation 5.0 allows remote attackers to execute arbitrary code via a packet with a crafted value of a certain size field, which is not checked for consistency with the actual buffer size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98xc-m39m-h44g/GHSA-98xc-m39m-h44g.json b/advisories/unreviewed/2022/05/GHSA-98xc-m39m-h44g/GHSA-98xc-m39m-h44g.json index 254b9b41580..94a564c1a43 100644 --- a/advisories/unreviewed/2022/05/GHSA-98xc-m39m-h44g/GHSA-98xc-m39m-h44g.json +++ b/advisories/unreviewed/2022/05/GHSA-98xc-m39m-h44g/GHSA-98xc-m39m-h44g.json @@ -7,12 +7,8 @@ "CVE-2008-0802" ], "details": "SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the albumnum parameter in a contact action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-993f-87r7-p76m/GHSA-993f-87r7-p76m.json b/advisories/unreviewed/2022/05/GHSA-993f-87r7-p76m/GHSA-993f-87r7-p76m.json index 9eb9d6ca2bb..afc92f5d30c 100644 --- a/advisories/unreviewed/2022/05/GHSA-993f-87r7-p76m/GHSA-993f-87r7-p76m.json +++ b/advisories/unreviewed/2022/05/GHSA-993f-87r7-p76m/GHSA-993f-87r7-p76m.json @@ -7,12 +7,8 @@ "CVE-2008-0894" ], "details": "Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitmap (BMP) or (2) GIF file, a related issue to CVE-2008-0420.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9c9w-285g-2x4j/GHSA-9c9w-285g-2x4j.json b/advisories/unreviewed/2022/05/GHSA-9c9w-285g-2x4j/GHSA-9c9w-285g-2x4j.json index 55f933cfe9d..9313e7de5ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c9w-285g-2x4j/GHSA-9c9w-285g-2x4j.json +++ b/advisories/unreviewed/2022/05/GHSA-9c9w-285g-2x4j/GHSA-9c9w-285g-2x4j.json @@ -7,12 +7,8 @@ "CVE-2008-0471" ], "details": "Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cg5-gw8m-xw4v/GHSA-9cg5-gw8m-xw4v.json b/advisories/unreviewed/2022/05/GHSA-9cg5-gw8m-xw4v/GHSA-9cg5-gw8m-xw4v.json index 8b1e1aa540f..99c160d779c 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cg5-gw8m-xw4v/GHSA-9cg5-gw8m-xw4v.json +++ b/advisories/unreviewed/2022/05/GHSA-9cg5-gw8m-xw4v/GHSA-9cg5-gw8m-xw4v.json @@ -7,12 +7,8 @@ "CVE-2008-0453" ], "details": "SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9g39-gfvp-6mm7/GHSA-9g39-gfvp-6mm7.json b/advisories/unreviewed/2022/05/GHSA-9g39-gfvp-6mm7/GHSA-9g39-gfvp-6mm7.json index b5aade35e57..ff1024a31e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g39-gfvp-6mm7/GHSA-9g39-gfvp-6mm7.json +++ b/advisories/unreviewed/2022/05/GHSA-9g39-gfvp-6mm7/GHSA-9g39-gfvp-6mm7.json @@ -7,12 +7,8 @@ "CVE-2008-0508" ], "details": "Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gjh-f72q-j9mf/GHSA-9gjh-f72q-j9mf.json b/advisories/unreviewed/2022/05/GHSA-9gjh-f72q-j9mf/GHSA-9gjh-f72q-j9mf.json index 6a8e29683e8..d7821b8dae3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gjh-f72q-j9mf/GHSA-9gjh-f72q-j9mf.json +++ b/advisories/unreviewed/2022/05/GHSA-9gjh-f72q-j9mf/GHSA-9gjh-f72q-j9mf.json @@ -7,12 +7,8 @@ "CVE-2008-0775" ], "details": "Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with \"&#\", contain the desired script, and end with \";\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gwc-84g5-9wgc/GHSA-9gwc-84g5-9wgc.json b/advisories/unreviewed/2022/05/GHSA-9gwc-84g5-9wgc/GHSA-9gwc-84g5-9wgc.json index 5c8c34fc908..d45901f5c64 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gwc-84g5-9wgc/GHSA-9gwc-84g5-9wgc.json +++ b/advisories/unreviewed/2022/05/GHSA-9gwc-84g5-9wgc/GHSA-9gwc-84g5-9wgc.json @@ -7,12 +7,8 @@ "CVE-2008-0733" ], "details": "SQL injection vulnerability in index.php in CS Team Counter Strike Portals allows remote attackers to execute arbitrary SQL commands via the id parameter, as demonstrated using the downloads page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hwx-82rg-g37j/GHSA-9hwx-82rg-g37j.json b/advisories/unreviewed/2022/05/GHSA-9hwx-82rg-g37j/GHSA-9hwx-82rg-g37j.json index 5b6f563b606..52510dd4adb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hwx-82rg-g37j/GHSA-9hwx-82rg-g37j.json +++ b/advisories/unreviewed/2022/05/GHSA-9hwx-82rg-g37j/GHSA-9hwx-82rg-g37j.json @@ -7,12 +7,8 @@ "CVE-2008-0559" ], "details": "Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the permalink parameter in core.php, accessed through index.php; and (2) the thispost parameter in comments.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j5x-xhcr-q8vq/GHSA-9j5x-xhcr-q8vq.json b/advisories/unreviewed/2022/05/GHSA-9j5x-xhcr-q8vq/GHSA-9j5x-xhcr-q8vq.json index ffa52583ab1..7e97da31a4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j5x-xhcr-q8vq/GHSA-9j5x-xhcr-q8vq.json +++ b/advisories/unreviewed/2022/05/GHSA-9j5x-xhcr-q8vq/GHSA-9j5x-xhcr-q8vq.json @@ -7,12 +7,8 @@ "CVE-2008-0562" ], "details": "SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m3m-gpf3-gvw3/GHSA-9m3m-gpf3-gvw3.json b/advisories/unreviewed/2022/05/GHSA-9m3m-gpf3-gvw3/GHSA-9m3m-gpf3-gvw3.json index c8f271b1acf..c308d9e1c88 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m3m-gpf3-gvw3/GHSA-9m3m-gpf3-gvw3.json +++ b/advisories/unreviewed/2022/05/GHSA-9m3m-gpf3-gvw3/GHSA-9m3m-gpf3-gvw3.json @@ -7,12 +7,8 @@ "CVE-2008-0787" ], "details": "SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m4h-7g4v-j826/GHSA-9m4h-7g4v-j826.json b/advisories/unreviewed/2022/05/GHSA-9m4h-7g4v-j826/GHSA-9m4h-7g4v-j826.json index d1b058b22a8..8c50e3171af 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m4h-7g4v-j826/GHSA-9m4h-7g4v-j826.json +++ b/advisories/unreviewed/2022/05/GHSA-9m4h-7g4v-j826/GHSA-9m4h-7g4v-j826.json @@ -7,12 +7,8 @@ "CVE-2008-0786" ], "details": "CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k, when running on older PHP interpreters, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9m5g-m3px-3x6r/GHSA-9m5g-m3px-3x6r.json b/advisories/unreviewed/2022/05/GHSA-9m5g-m3px-3x6r/GHSA-9m5g-m3px-3x6r.json index 82ebebc03c9..536faaa76df 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m5g-m3px-3x6r/GHSA-9m5g-m3px-3x6r.json +++ b/advisories/unreviewed/2022/05/GHSA-9m5g-m3px-3x6r/GHSA-9m5g-m3px-3x6r.json @@ -7,12 +7,8 @@ "CVE-2008-0973" ], "details": "Buffer overflow in Double-Take (aka HP StorageWorks Storage Mirroring) 4.5.0.1629, and other 4.5.0.x versions, allows remote attackers to have an unknown impact via a packet with a long string in the username field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qjv-6f4r-w76q/GHSA-9qjv-6f4r-w76q.json b/advisories/unreviewed/2022/05/GHSA-9qjv-6f4r-w76q/GHSA-9qjv-6f4r-w76q.json index 710506bc76a..c827e30c8b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qjv-6f4r-w76q/GHSA-9qjv-6f4r-w76q.json +++ b/advisories/unreviewed/2022/05/GHSA-9qjv-6f4r-w76q/GHSA-9qjv-6f4r-w76q.json @@ -7,12 +7,8 @@ "CVE-2008-0948" ], "details": "Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering a large number of open file descriptors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r96-778p-rvvg/GHSA-9r96-778p-rvvg.json b/advisories/unreviewed/2022/05/GHSA-9r96-778p-rvvg/GHSA-9r96-778p-rvvg.json index 24a8fa120cf..94e5d451cae 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r96-778p-rvvg/GHSA-9r96-778p-rvvg.json +++ b/advisories/unreviewed/2022/05/GHSA-9r96-778p-rvvg/GHSA-9r96-778p-rvvg.json @@ -7,12 +7,8 @@ "CVE-2008-0795" ], "details": "SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rq6-pq33-gmw9/GHSA-9rq6-pq33-gmw9.json b/advisories/unreviewed/2022/05/GHSA-9rq6-pq33-gmw9/GHSA-9rq6-pq33-gmw9.json index 5d257fe63f3..92db7097e16 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rq6-pq33-gmw9/GHSA-9rq6-pq33-gmw9.json +++ b/advisories/unreviewed/2022/05/GHSA-9rq6-pq33-gmw9/GHSA-9rq6-pq33-gmw9.json @@ -7,12 +7,8 @@ "CVE-2008-0525" ], "details": "PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v2g-635q-h56f/GHSA-9v2g-635q-h56f.json b/advisories/unreviewed/2022/05/GHSA-9v2g-635q-h56f/GHSA-9v2g-635q-h56f.json index 398d55d1168..e55a58d4f32 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v2g-635q-h56f/GHSA-9v2g-635q-h56f.json +++ b/advisories/unreviewed/2022/05/GHSA-9v2g-635q-h56f/GHSA-9v2g-635q-h56f.json @@ -7,12 +7,8 @@ "CVE-2008-0771" ], "details": "Multiple SQL injection vulnerabilities in default.asp in Site2Nite allow remote attackers to execute arbitrary SQL commands via the (1) txtUserName and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v48-2p62-wqxh/GHSA-9v48-2p62-wqxh.json b/advisories/unreviewed/2022/05/GHSA-9v48-2p62-wqxh/GHSA-9v48-2p62-wqxh.json index 69b6ff52373..b38f54a3216 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v48-2p62-wqxh/GHSA-9v48-2p62-wqxh.json +++ b/advisories/unreviewed/2022/05/GHSA-9v48-2p62-wqxh/GHSA-9v48-2p62-wqxh.json @@ -7,12 +7,8 @@ "CVE-2008-0692" ], "details": "SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v49-x7c5-2j9j/GHSA-9v49-x7c5-2j9j.json b/advisories/unreviewed/2022/05/GHSA-9v49-x7c5-2j9j/GHSA-9v49-x7c5-2j9j.json index 46b4b7317be..c9d9afefe11 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v49-x7c5-2j9j/GHSA-9v49-x7c5-2j9j.json +++ b/advisories/unreviewed/2022/05/GHSA-9v49-x7c5-2j9j/GHSA-9v49-x7c5-2j9j.json @@ -7,12 +7,8 @@ "CVE-2008-0644" ], "details": "Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism for applications via unspecified vectors related to the setEncoding function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9wj4-c5x9-5hgv/GHSA-9wj4-c5x9-5hgv.json b/advisories/unreviewed/2022/05/GHSA-9wj4-c5x9-5hgv/GHSA-9wj4-c5x9-5hgv.json index ea20961eca3..81f3efb6d54 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wj4-c5x9-5hgv/GHSA-9wj4-c5x9-5hgv.json +++ b/advisories/unreviewed/2022/05/GHSA-9wj4-c5x9-5hgv/GHSA-9wj4-c5x9-5hgv.json @@ -7,12 +7,8 @@ "CVE-2008-0535" ], "details": "Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device instability) via \"SSH credentials that attempt to change the authentication method,\" aka Bug ID CSCsm14239.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c32q-6gh5-pjg9/GHSA-c32q-6gh5-pjg9.json b/advisories/unreviewed/2022/05/GHSA-c32q-6gh5-pjg9/GHSA-c32q-6gh5-pjg9.json index dc9e75b7558..2d90f92f74c 100644 --- a/advisories/unreviewed/2022/05/GHSA-c32q-6gh5-pjg9/GHSA-c32q-6gh5-pjg9.json +++ b/advisories/unreviewed/2022/05/GHSA-c32q-6gh5-pjg9/GHSA-c32q-6gh5-pjg9.json @@ -7,12 +7,8 @@ "CVE-2008-0670" ], "details": "SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detalhe action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c33x-6cpq-83r7/GHSA-c33x-6cpq-83r7.json b/advisories/unreviewed/2022/05/GHSA-c33x-6cpq-83r7/GHSA-c33x-6cpq-83r7.json index ecbff790fd2..4a79203dc3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c33x-6cpq-83r7/GHSA-c33x-6cpq-83r7.json +++ b/advisories/unreviewed/2022/05/GHSA-c33x-6cpq-83r7/GHSA-c33x-6cpq-83r7.json @@ -7,12 +7,8 @@ "CVE-2008-0548" ], "details": "Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL dereference when malloc fails.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3cp-rcm6-572j/GHSA-c3cp-rcm6-572j.json b/advisories/unreviewed/2022/05/GHSA-c3cp-rcm6-572j/GHSA-c3cp-rcm6-572j.json index 4cdb0c1e69c..03644dc9fba 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3cp-rcm6-572j/GHSA-c3cp-rcm6-572j.json +++ b/advisories/unreviewed/2022/05/GHSA-c3cp-rcm6-572j/GHSA-c3cp-rcm6-572j.json @@ -7,12 +7,8 @@ "CVE-2008-0625" ], "details": "Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddBitmap method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3vf-92xj-4r66/GHSA-c3vf-92xj-4r66.json b/advisories/unreviewed/2022/05/GHSA-c3vf-92xj-4r66/GHSA-c3vf-92xj-4r66.json index 9af1aec6ca3..b7592d75306 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3vf-92xj-4r66/GHSA-c3vf-92xj-4r66.json +++ b/advisories/unreviewed/2022/05/GHSA-c3vf-92xj-4r66/GHSA-c3vf-92xj-4r66.json @@ -7,12 +7,8 @@ "CVE-2008-0395" ], "details": "Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c499-4h79-p847/GHSA-c499-4h79-p847.json b/advisories/unreviewed/2022/05/GHSA-c499-4h79-p847/GHSA-c499-4h79-p847.json index 1a4ba3f83fc..38388b628fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-c499-4h79-p847/GHSA-c499-4h79-p847.json +++ b/advisories/unreviewed/2022/05/GHSA-c499-4h79-p847/GHSA-c499-4h79-p847.json @@ -7,12 +7,8 @@ "CVE-2008-0763" ], "details": "Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arbitrary code via a long argument in a LICENSE command on TCP port 3114.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c879-cmwr-8qxc/GHSA-c879-cmwr-8qxc.json b/advisories/unreviewed/2022/05/GHSA-c879-cmwr-8qxc/GHSA-c879-cmwr-8qxc.json index d292a522072..63babea270e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c879-cmwr-8qxc/GHSA-c879-cmwr-8qxc.json +++ b/advisories/unreviewed/2022/05/GHSA-c879-cmwr-8qxc/GHSA-c879-cmwr-8qxc.json @@ -7,12 +7,8 @@ "CVE-2008-0756" ], "details": "The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; allows remote attackers to cause a denial of service (daemon crash) via a connection that begins with (1) a \"Send queue state\" LPD command 3 or (2) a \"Send queue state\" LPD command 4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c8fc-phxf-4w3r/GHSA-c8fc-phxf-4w3r.json b/advisories/unreviewed/2022/05/GHSA-c8fc-phxf-4w3r/GHSA-c8fc-phxf-4w3r.json index 9d1371bd0a7..50774f7800e 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8fc-phxf-4w3r/GHSA-c8fc-phxf-4w3r.json +++ b/advisories/unreviewed/2022/05/GHSA-c8fc-phxf-4w3r/GHSA-c8fc-phxf-4w3r.json @@ -7,12 +7,8 @@ "CVE-2008-0578" ], "details": "Cross-site scripting (XSS) vulnerability in the web management login page in Tripwire Enterprise 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8qm-5qp8-rf5v/GHSA-c8qm-5qp8-rf5v.json b/advisories/unreviewed/2022/05/GHSA-c8qm-5qp8-rf5v/GHSA-c8qm-5qp8-rf5v.json index 9ea02606c84..8c9a76612ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8qm-5qp8-rf5v/GHSA-c8qm-5qp8-rf5v.json +++ b/advisories/unreviewed/2022/05/GHSA-c8qm-5qp8-rf5v/GHSA-c8qm-5qp8-rf5v.json @@ -7,12 +7,8 @@ "CVE-2019-2170" ], "details": "In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118615735", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c8r4-mr69-33v6/GHSA-c8r4-mr69-33v6.json b/advisories/unreviewed/2022/05/GHSA-c8r4-mr69-33v6/GHSA-c8r4-mr69-33v6.json index 5003870c254..50c128c24e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8r4-mr69-33v6/GHSA-c8r4-mr69-33v6.json +++ b/advisories/unreviewed/2022/05/GHSA-c8r4-mr69-33v6/GHSA-c8r4-mr69-33v6.json @@ -7,12 +7,8 @@ "CVE-2019-1370" ], "details": "An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c8w7-2m57-pv7f/GHSA-c8w7-2m57-pv7f.json b/advisories/unreviewed/2022/05/GHSA-c8w7-2m57-pv7f/GHSA-c8w7-2m57-pv7f.json index 4750e897334..dbad456a0c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8w7-2m57-pv7f/GHSA-c8w7-2m57-pv7f.json +++ b/advisories/unreviewed/2022/05/GHSA-c8w7-2m57-pv7f/GHSA-c8w7-2m57-pv7f.json @@ -7,12 +7,8 @@ "CVE-2008-0634" ], "details": "Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9m8-8cfg-x353/GHSA-c9m8-8cfg-x353.json b/advisories/unreviewed/2022/05/GHSA-c9m8-8cfg-x353/GHSA-c9m8-8cfg-x353.json index afef1f50dc4..7cd98c06228 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9m8-8cfg-x353/GHSA-c9m8-8cfg-x353.json +++ b/advisories/unreviewed/2022/05/GHSA-c9m8-8cfg-x353/GHSA-c9m8-8cfg-x353.json @@ -7,12 +7,8 @@ "CVE-2008-0952" ], "details": "The AppendStringToFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to create files with arbitrary content via a full pathname in the first argument and the content in the second argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9x8-4v35-37qf/GHSA-c9x8-4v35-37qf.json b/advisories/unreviewed/2022/05/GHSA-c9x8-4v35-37qf/GHSA-c9x8-4v35-37qf.json index 4d33c58c947..30e76b1ec61 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9x8-4v35-37qf/GHSA-c9x8-4v35-37qf.json +++ b/advisories/unreviewed/2022/05/GHSA-c9x8-4v35-37qf/GHSA-c9x8-4v35-37qf.json @@ -7,12 +7,8 @@ "CVE-2019-0719" ], "details": "A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cf3v-5qp2-v938/GHSA-cf3v-5qp2-v938.json b/advisories/unreviewed/2022/05/GHSA-cf3v-5qp2-v938/GHSA-cf3v-5qp2-v938.json index 77ea420ea81..53704708137 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf3v-5qp2-v938/GHSA-cf3v-5qp2-v938.json +++ b/advisories/unreviewed/2022/05/GHSA-cf3v-5qp2-v938/GHSA-cf3v-5qp2-v938.json @@ -7,12 +7,8 @@ "CVE-2008-0565" ], "details": "SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cfg4-8p2r-9w6q/GHSA-cfg4-8p2r-9w6q.json b/advisories/unreviewed/2022/05/GHSA-cfg4-8p2r-9w6q/GHSA-cfg4-8p2r-9w6q.json index e7a2f576738..b1ca24aeeaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-cfg4-8p2r-9w6q/GHSA-cfg4-8p2r-9w6q.json +++ b/advisories/unreviewed/2022/05/GHSA-cfg4-8p2r-9w6q/GHSA-cfg4-8p2r-9w6q.json @@ -7,12 +7,8 @@ "CVE-2008-0573" ], "details": "IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cg2c-3gw3-2vcg/GHSA-cg2c-3gw3-2vcg.json b/advisories/unreviewed/2022/05/GHSA-cg2c-3gw3-2vcg/GHSA-cg2c-3gw3-2vcg.json index c87339bdbef..519ab1d84f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg2c-3gw3-2vcg/GHSA-cg2c-3gw3-2vcg.json +++ b/advisories/unreviewed/2022/05/GHSA-cg2c-3gw3-2vcg/GHSA-cg2c-3gw3-2vcg.json @@ -7,12 +7,8 @@ "CVE-2008-0892" ], "details": "The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cgg9-v4j6-6hmm/GHSA-cgg9-v4j6-6hmm.json b/advisories/unreviewed/2022/05/GHSA-cgg9-v4j6-6hmm/GHSA-cgg9-v4j6-6hmm.json index dde901d16d0..2b6de763731 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgg9-v4j6-6hmm/GHSA-cgg9-v4j6-6hmm.json +++ b/advisories/unreviewed/2022/05/GHSA-cgg9-v4j6-6hmm/GHSA-cgg9-v4j6-6hmm.json @@ -7,12 +7,8 @@ "CVE-2008-0875" ], "details": "Unspecified vulnerability in Hitachi EUR Print Manager, and related Client and Local Server products, 05-06 through 05-06-/B and 05-08 allows remote attackers to cause a denial of service (service hang or termination) via unspecified vectors related to \"unexpected data.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch5j-g9p9-gv8m/GHSA-ch5j-g9p9-gv8m.json b/advisories/unreviewed/2022/05/GHSA-ch5j-g9p9-gv8m/GHSA-ch5j-g9p9-gv8m.json index 7edf2f1b20e..f605d79b58c 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch5j-g9p9-gv8m/GHSA-ch5j-g9p9-gv8m.json +++ b/advisories/unreviewed/2022/05/GHSA-ch5j-g9p9-gv8m/GHSA-ch5j-g9p9-gv8m.json @@ -7,12 +7,8 @@ "CVE-2008-0740" ], "details": "IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch62-xvfr-2jjq/GHSA-ch62-xvfr-2jjq.json b/advisories/unreviewed/2022/05/GHSA-ch62-xvfr-2jjq/GHSA-ch62-xvfr-2jjq.json index 0c5724cda6b..03769fe11fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch62-xvfr-2jjq/GHSA-ch62-xvfr-2jjq.json +++ b/advisories/unreviewed/2022/05/GHSA-ch62-xvfr-2jjq/GHSA-ch62-xvfr-2jjq.json @@ -7,12 +7,8 @@ "CVE-2008-0551" ], "details": "The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj4c-5gff-3x9p/GHSA-cj4c-5gff-3x9p.json b/advisories/unreviewed/2022/05/GHSA-cj4c-5gff-3x9p/GHSA-cj4c-5gff-3x9p.json index 2f3fc6257ee..6e2b3148f34 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj4c-5gff-3x9p/GHSA-cj4c-5gff-3x9p.json +++ b/advisories/unreviewed/2022/05/GHSA-cj4c-5gff-3x9p/GHSA-cj4c-5gff-3x9p.json @@ -7,12 +7,8 @@ "CVE-2008-0412" ], "details": "The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableFrame::GetFrameAtOrBefore, (2) nsAccessibilityService::GetAccessible, (3) nsBindingManager::GetNestedInsertionPoint, (4) nsXBLPrototypeBinding::AttributeChanged, (5) nsColumnSetFrame::GetContentInsertionFrame, and (6) nsLineLayout::TrimTrailingWhiteSpaceIn methods, and other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -280,9 +276,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cp6v-vwwq-5gw4/GHSA-cp6v-vwwq-5gw4.json b/advisories/unreviewed/2022/05/GHSA-cp6v-vwwq-5gw4/GHSA-cp6v-vwwq-5gw4.json index 767d4ed8da5..d51626e65fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp6v-vwwq-5gw4/GHSA-cp6v-vwwq-5gw4.json +++ b/advisories/unreviewed/2022/05/GHSA-cp6v-vwwq-5gw4/GHSA-cp6v-vwwq-5gw4.json @@ -7,12 +7,8 @@ "CVE-2008-0905" ], "details": "Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cp6x-jg23-5w9v/GHSA-cp6x-jg23-5w9v.json b/advisories/unreviewed/2022/05/GHSA-cp6x-jg23-5w9v/GHSA-cp6x-jg23-5w9v.json index 4d48734d8ce..3f75cc57b28 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp6x-jg23-5w9v/GHSA-cp6x-jg23-5w9v.json +++ b/advisories/unreviewed/2022/05/GHSA-cp6x-jg23-5w9v/GHSA-cp6x-jg23-5w9v.json @@ -7,12 +7,8 @@ "CVE-2019-1382" ], "details": "An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to files without proper authentication, aka 'Microsoft ActiveX Installer Service Elevation of Privilege Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxg2-m6hr-2jp6/GHSA-cxg2-m6hr-2jp6.json b/advisories/unreviewed/2022/05/GHSA-cxg2-m6hr-2jp6/GHSA-cxg2-m6hr-2jp6.json index b6d7b8d7f2e..0be191c2ebb 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxg2-m6hr-2jp6/GHSA-cxg2-m6hr-2jp6.json +++ b/advisories/unreviewed/2022/05/GHSA-cxg2-m6hr-2jp6/GHSA-cxg2-m6hr-2jp6.json @@ -7,12 +7,8 @@ "CVE-2008-0772" ], "details": "SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxjg-c3fc-c47q/GHSA-cxjg-c3fc-c47q.json b/advisories/unreviewed/2022/05/GHSA-cxjg-c3fc-c47q/GHSA-cxjg-c3fc-c47q.json index c1d5ec296c3..fd248b5dc47 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxjg-c3fc-c47q/GHSA-cxjg-c3fc-c47q.json +++ b/advisories/unreviewed/2022/05/GHSA-cxjg-c3fc-c47q/GHSA-cxjg-c3fc-c47q.json @@ -7,12 +7,8 @@ "CVE-2008-0963" ], "details": "Format string vulnerability in EMC DiskXtender MediaStor 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted message to the RPC interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f286-r7gg-78m6/GHSA-f286-r7gg-78m6.json b/advisories/unreviewed/2022/05/GHSA-f286-r7gg-78m6/GHSA-f286-r7gg-78m6.json index fd3746dcba4..1b92c1318c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-f286-r7gg-78m6/GHSA-f286-r7gg-78m6.json +++ b/advisories/unreviewed/2022/05/GHSA-f286-r7gg-78m6/GHSA-f286-r7gg-78m6.json @@ -7,12 +7,8 @@ "CVE-2008-0476" ], "details": "ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive information and change settings via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3cg-58h9-xv3v/GHSA-f3cg-58h9-xv3v.json b/advisories/unreviewed/2022/05/GHSA-f3cg-58h9-xv3v/GHSA-f3cg-58h9-xv3v.json index e373c5c0d61..d44362cf6d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3cg-58h9-xv3v/GHSA-f3cg-58h9-xv3v.json +++ b/advisories/unreviewed/2022/05/GHSA-f3cg-58h9-xv3v/GHSA-f3cg-58h9-xv3v.json @@ -7,12 +7,8 @@ "CVE-2008-0712" ], "details": "Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f44m-72vx-4m92/GHSA-f44m-72vx-4m92.json b/advisories/unreviewed/2022/05/GHSA-f44m-72vx-4m92/GHSA-f44m-72vx-4m92.json index 160d88cba22..015b2bd7b2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f44m-72vx-4m92/GHSA-f44m-72vx-4m92.json +++ b/advisories/unreviewed/2022/05/GHSA-f44m-72vx-4m92/GHSA-f44m-72vx-4m92.json @@ -7,12 +7,8 @@ "CVE-2008-0896" ], "details": "BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f66p-x258-2m6x/GHSA-f66p-x258-2m6x.json b/advisories/unreviewed/2022/05/GHSA-f66p-x258-2m6x/GHSA-f66p-x258-2m6x.json index 29754f8d90c..620a3b4cbdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-f66p-x258-2m6x/GHSA-f66p-x258-2m6x.json +++ b/advisories/unreviewed/2022/05/GHSA-f66p-x258-2m6x/GHSA-f66p-x258-2m6x.json @@ -7,12 +7,8 @@ "CVE-2008-0676" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in A-Blog 2 allows remote attackers to inject arbitrary web script or HTML via the words parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6qx-7qq9-x6fq/GHSA-f6qx-7qq9-x6fq.json b/advisories/unreviewed/2022/05/GHSA-f6qx-7qq9-x6fq/GHSA-f6qx-7qq9-x6fq.json index bde0c7d8ee6..9d40388dfe2 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6qx-7qq9-x6fq/GHSA-f6qx-7qq9-x6fq.json +++ b/advisories/unreviewed/2022/05/GHSA-f6qx-7qq9-x6fq/GHSA-f6qx-7qq9-x6fq.json @@ -7,12 +7,8 @@ "CVE-2008-0629" ], "details": "Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7g2-363m-f9wg/GHSA-f7g2-363m-f9wg.json b/advisories/unreviewed/2022/05/GHSA-f7g2-363m-f9wg/GHSA-f7g2-363m-f9wg.json index b081827bb12..fdbe9c71341 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7g2-363m-f9wg/GHSA-f7g2-363m-f9wg.json +++ b/advisories/unreviewed/2022/05/GHSA-f7g2-363m-f9wg/GHSA-f7g2-363m-f9wg.json @@ -7,12 +7,8 @@ "CVE-2008-0874" ], "details": "SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f7pv-mwq4-v6qp/GHSA-f7pv-mwq4-v6qp.json b/advisories/unreviewed/2022/05/GHSA-f7pv-mwq4-v6qp/GHSA-f7pv-mwq4-v6qp.json index a3bedbe10fe..b5e7fed7fee 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7pv-mwq4-v6qp/GHSA-f7pv-mwq4-v6qp.json +++ b/advisories/unreviewed/2022/05/GHSA-f7pv-mwq4-v6qp/GHSA-f7pv-mwq4-v6qp.json @@ -7,12 +7,8 @@ "CVE-2008-0632" ], "details": "Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the blog's root directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7q7-hw5g-fcvf/GHSA-f7q7-hw5g-fcvf.json b/advisories/unreviewed/2022/05/GHSA-f7q7-hw5g-fcvf/GHSA-f7q7-hw5g-fcvf.json index 47d9506b6e9..2d84275c137 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7q7-hw5g-fcvf/GHSA-f7q7-hw5g-fcvf.json +++ b/advisories/unreviewed/2022/05/GHSA-f7q7-hw5g-fcvf/GHSA-f7q7-hw5g-fcvf.json @@ -7,12 +7,8 @@ "CVE-2008-0624" ], "details": "Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddButton method, a different vulnerability than CVE-2008-0623.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcg2-cvfp-6qwf/GHSA-fcg2-cvfp-6qwf.json b/advisories/unreviewed/2022/05/GHSA-fcg2-cvfp-6qwf/GHSA-fcg2-cvfp-6qwf.json index 38b21db967c..b40c888d8a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcg2-cvfp-6qwf/GHSA-fcg2-cvfp-6qwf.json +++ b/advisories/unreviewed/2022/05/GHSA-fcg2-cvfp-6qwf/GHSA-fcg2-cvfp-6qwf.json @@ -7,12 +7,8 @@ "CVE-2008-0867" ], "details": "Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff4f-v6jp-3hhm/GHSA-ff4f-v6jp-3hhm.json b/advisories/unreviewed/2022/05/GHSA-ff4f-v6jp-3hhm/GHSA-ff4f-v6jp-3hhm.json index fcfeb40bcd8..d5f188cdbc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff4f-v6jp-3hhm/GHSA-ff4f-v6jp-3hhm.json +++ b/advisories/unreviewed/2022/05/GHSA-ff4f-v6jp-3hhm/GHSA-ff4f-v6jp-3hhm.json @@ -7,12 +7,8 @@ "CVE-2008-0515" ], "details": "SQL injection vulnerability in index.php in the musepoes (com_musepoes) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff87-x3fm-p744/GHSA-ff87-x3fm-p744.json b/advisories/unreviewed/2022/05/GHSA-ff87-x3fm-p744/GHSA-ff87-x3fm-p744.json index a534102a061..ec2323cd56c 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff87-x3fm-p744/GHSA-ff87-x3fm-p744.json +++ b/advisories/unreviewed/2022/05/GHSA-ff87-x3fm-p744/GHSA-ff87-x3fm-p744.json @@ -7,12 +7,8 @@ "CVE-2008-0668" ], "details": "The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to an integer overflow. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -92,9 +88,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fffx-94h7-8772/GHSA-fffx-94h7-8772.json b/advisories/unreviewed/2022/05/GHSA-fffx-94h7-8772/GHSA-fffx-94h7-8772.json index 3c7de26c0e9..6099a6756b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-fffx-94h7-8772/GHSA-fffx-94h7-8772.json +++ b/advisories/unreviewed/2022/05/GHSA-fffx-94h7-8772/GHSA-fffx-94h7-8772.json @@ -7,12 +7,8 @@ "CVE-2008-0660" ], "details": "Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgcx-54w9-284g/GHSA-fgcx-54w9-284g.json b/advisories/unreviewed/2022/05/GHSA-fgcx-54w9-284g/GHSA-fgcx-54w9-284g.json index 5604be0b487..e9fc6944da0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgcx-54w9-284g/GHSA-fgcx-54w9-284g.json +++ b/advisories/unreviewed/2022/05/GHSA-fgcx-54w9-284g/GHSA-fgcx-54w9-284g.json @@ -7,12 +7,8 @@ "CVE-2008-0609" ], "details": "Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgwj-2pr9-mh8q/GHSA-fgwj-2pr9-mh8q.json b/advisories/unreviewed/2022/05/GHSA-fgwj-2pr9-mh8q/GHSA-fgwj-2pr9-mh8q.json index 2a41bd174fa..ba3353a568b 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgwj-2pr9-mh8q/GHSA-fgwj-2pr9-mh8q.json +++ b/advisories/unreviewed/2022/05/GHSA-fgwj-2pr9-mh8q/GHSA-fgwj-2pr9-mh8q.json @@ -7,12 +7,8 @@ "CVE-2008-0449" ], "details": "SQL injection vulnerability in paypalresult.asp in VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjph-hqxw-hjp5/GHSA-fjph-hqxw-hjp5.json b/advisories/unreviewed/2022/05/GHSA-fjph-hqxw-hjp5/GHSA-fjph-hqxw-hjp5.json index cf2b323dd62..77868daae87 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjph-hqxw-hjp5/GHSA-fjph-hqxw-hjp5.json +++ b/advisories/unreviewed/2022/05/GHSA-fjph-hqxw-hjp5/GHSA-fjph-hqxw-hjp5.json @@ -7,12 +7,8 @@ "CVE-2008-0405" ], "details": "Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a \"/?%0a\" sequence followed by the data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm43-2p79-w753/GHSA-fm43-2p79-w753.json b/advisories/unreviewed/2022/05/GHSA-fm43-2p79-w753/GHSA-fm43-2p79-w753.json index d365364f89d..671897197ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm43-2p79-w753/GHSA-fm43-2p79-w753.json +++ b/advisories/unreviewed/2022/05/GHSA-fm43-2p79-w753/GHSA-fm43-2p79-w753.json @@ -7,12 +7,8 @@ "CVE-2008-0503" ], "details": "Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filedata parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp67-x7qp-fg72/GHSA-fp67-x7qp-fg72.json b/advisories/unreviewed/2022/05/GHSA-fp67-x7qp-fg72/GHSA-fp67-x7qp-fg72.json index 98a5704d698..ae307b3bec4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp67-x7qp-fg72/GHSA-fp67-x7qp-fg72.json +++ b/advisories/unreviewed/2022/05/GHSA-fp67-x7qp-fg72/GHSA-fp67-x7qp-fg72.json @@ -7,12 +7,8 @@ "CVE-2008-0943" ], "details": "Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fp7p-c7mx-vx9v/GHSA-fp7p-c7mx-vx9v.json b/advisories/unreviewed/2022/05/GHSA-fp7p-c7mx-vx9v/GHSA-fp7p-c7mx-vx9v.json index bc27280e226..95afd4074e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-fp7p-c7mx-vx9v/GHSA-fp7p-c7mx-vx9v.json +++ b/advisories/unreviewed/2022/05/GHSA-fp7p-c7mx-vx9v/GHSA-fp7p-c7mx-vx9v.json @@ -7,12 +7,8 @@ "CVE-2008-0479" ], "details": "Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\\\\ in the sub parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fqv9-pv7p-j837/GHSA-fqv9-pv7p-j837.json b/advisories/unreviewed/2022/05/GHSA-fqv9-pv7p-j837/GHSA-fqv9-pv7p-j837.json index 4e5201158fd..ef2cb5e6ae7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqv9-pv7p-j837/GHSA-fqv9-pv7p-j837.json +++ b/advisories/unreviewed/2022/05/GHSA-fqv9-pv7p-j837/GHSA-fqv9-pv7p-j837.json @@ -7,12 +7,8 @@ "CVE-2008-0527" ], "details": "The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fqwg-7xrq-7vq6/GHSA-fqwg-7xrq-7vq6.json b/advisories/unreviewed/2022/05/GHSA-fqwg-7xrq-7vq6/GHSA-fqwg-7xrq-7vq6.json index e63e66bc445..6be4f2cca34 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqwg-7xrq-7vq6/GHSA-fqwg-7xrq-7vq6.json +++ b/advisories/unreviewed/2022/05/GHSA-fqwg-7xrq-7vq6/GHSA-fqwg-7xrq-7vq6.json @@ -7,12 +7,8 @@ "CVE-2008-0463" ], "details": "Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before 4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving node properties.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fr96-6wx7-355w/GHSA-fr96-6wx7-355w.json b/advisories/unreviewed/2022/05/GHSA-fr96-6wx7-355w/GHSA-fr96-6wx7-355w.json index 8d1940e6395..0e8c1e4df50 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr96-6wx7-355w/GHSA-fr96-6wx7-355w.json +++ b/advisories/unreviewed/2022/05/GHSA-fr96-6wx7-355w/GHSA-fr96-6wx7-355w.json @@ -7,12 +7,8 @@ "CVE-2008-0571" ], "details": "The point moderation form in the Userpoints 4.7.x before 4.7.x-2.3, 5.x-2 before 5.x-2.16, and 5.x-3 before 5.x-3.3 module for Drupal does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and manipulate points.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fv36-6343-2p98/GHSA-fv36-6343-2p98.json b/advisories/unreviewed/2022/05/GHSA-fv36-6343-2p98/GHSA-fv36-6343-2p98.json index 3b1a61c4a2d..54d7999f551 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv36-6343-2p98/GHSA-fv36-6343-2p98.json +++ b/advisories/unreviewed/2022/05/GHSA-fv36-6343-2p98/GHSA-fv36-6343-2p98.json @@ -7,12 +7,8 @@ "CVE-2019-13357" ], "details": "In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTEM-level code execution can be achieved when the ccSchedulerSVC service runs the affected executable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fv5h-cqqr-6frj/GHSA-fv5h-cqqr-6frj.json b/advisories/unreviewed/2022/05/GHSA-fv5h-cqqr-6frj/GHSA-fv5h-cqqr-6frj.json index c62b19aa284..948de1fed87 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv5h-cqqr-6frj/GHSA-fv5h-cqqr-6frj.json +++ b/advisories/unreviewed/2022/05/GHSA-fv5h-cqqr-6frj/GHSA-fv5h-cqqr-6frj.json @@ -7,12 +7,8 @@ "CVE-2008-0773" ], "details": "SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvp5-66cv-3hpg/GHSA-fvp5-66cv-3hpg.json b/advisories/unreviewed/2022/05/GHSA-fvp5-66cv-3hpg/GHSA-fvp5-66cv-3hpg.json index 12b3ce31ace..c1f916b47d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvp5-66cv-3hpg/GHSA-fvp5-66cv-3hpg.json +++ b/advisories/unreviewed/2022/05/GHSA-fvp5-66cv-3hpg/GHSA-fvp5-66cv-3hpg.json @@ -7,12 +7,8 @@ "CVE-2008-0568" ], "details": "Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackers to gain the privileges of a user who has authenticated from behind the same proxy server as the attacker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fwpq-7jcm-8q4c/GHSA-fwpq-7jcm-8q4c.json b/advisories/unreviewed/2022/05/GHSA-fwpq-7jcm-8q4c/GHSA-fwpq-7jcm-8q4c.json index 129b2062dd8..d23ca526ffd 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwpq-7jcm-8q4c/GHSA-fwpq-7jcm-8q4c.json +++ b/advisories/unreviewed/2022/05/GHSA-fwpq-7jcm-8q4c/GHSA-fwpq-7jcm-8q4c.json @@ -7,12 +7,8 @@ "CVE-2008-0645" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) config/conf-activation.php, (2) menu/item.php, and (3) modules/conf_modules.php in admin/system/; and (4) system/login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fx8p-9q3f-f3m3/GHSA-fx8p-9q3f-f3m3.json b/advisories/unreviewed/2022/05/GHSA-fx8p-9q3f-f3m3/GHSA-fx8p-9q3f-f3m3.json index d270ebbb430..d612dfd1bf0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fx8p-9q3f-f3m3/GHSA-fx8p-9q3f-f3m3.json +++ b/advisories/unreviewed/2022/05/GHSA-fx8p-9q3f-f3m3/GHSA-fx8p-9q3f-f3m3.json @@ -7,12 +7,8 @@ "CVE-2008-0900" ], "details": "Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fxrf-v868-58jw/GHSA-fxrf-v868-58jw.json b/advisories/unreviewed/2022/05/GHSA-fxrf-v868-58jw/GHSA-fxrf-v868-58jw.json index a9055eda0b4..079fc1089ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxrf-v868-58jw/GHSA-fxrf-v868-58jw.json +++ b/advisories/unreviewed/2022/05/GHSA-fxrf-v868-58jw/GHSA-fxrf-v868-58jw.json @@ -7,12 +7,8 @@ "CVE-2008-0983" ], "details": "lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g229-jwh8-gqpv/GHSA-g229-jwh8-gqpv.json b/advisories/unreviewed/2022/05/GHSA-g229-jwh8-gqpv/GHSA-g229-jwh8-gqpv.json index 9cbed877cdd..0fdc2768e12 100644 --- a/advisories/unreviewed/2022/05/GHSA-g229-jwh8-gqpv/GHSA-g229-jwh8-gqpv.json +++ b/advisories/unreviewed/2022/05/GHSA-g229-jwh8-gqpv/GHSA-g229-jwh8-gqpv.json @@ -7,12 +7,8 @@ "CVE-2008-0391" ], "details": "inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g24j-mq2h-pp72/GHSA-g24j-mq2h-pp72.json b/advisories/unreviewed/2022/05/GHSA-g24j-mq2h-pp72/GHSA-g24j-mq2h-pp72.json index 75a7c8c6e6f..309da71360b 100644 --- a/advisories/unreviewed/2022/05/GHSA-g24j-mq2h-pp72/GHSA-g24j-mq2h-pp72.json +++ b/advisories/unreviewed/2022/05/GHSA-g24j-mq2h-pp72/GHSA-g24j-mq2h-pp72.json @@ -7,12 +7,8 @@ "CVE-2008-0576" ], "details": "Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors that write to summary table pages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g44r-fq78-q8px/GHSA-g44r-fq78-q8px.json b/advisories/unreviewed/2022/05/GHSA-g44r-fq78-q8px/GHSA-g44r-fq78-q8px.json index c9447370605..cc25b42a93e 100644 --- a/advisories/unreviewed/2022/05/GHSA-g44r-fq78-q8px/GHSA-g44r-fq78-q8px.json +++ b/advisories/unreviewed/2022/05/GHSA-g44r-fq78-q8px/GHSA-g44r-fq78-q8px.json @@ -7,12 +7,8 @@ "CVE-2008-0635" ], "details": "Unspecified vulnerability in the delivery engine in Openads 2.4.0 through 2.4.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g549-m5gj-5w5g/GHSA-g549-m5gj-5w5g.json b/advisories/unreviewed/2022/05/GHSA-g549-m5gj-5w5g/GHSA-g549-m5gj-5w5g.json index 4f44667ab80..98f75222ff5 100644 --- a/advisories/unreviewed/2022/05/GHSA-g549-m5gj-5w5g/GHSA-g549-m5gj-5w5g.json +++ b/advisories/unreviewed/2022/05/GHSA-g549-m5gj-5w5g/GHSA-g549-m5gj-5w5g.json @@ -7,12 +7,8 @@ "CVE-2008-0454" ], "details": "Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the \"Add video to chat\" dialog, aka \"videomood XSS.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g67r-rgg8-9pxj/GHSA-g67r-rgg8-9pxj.json b/advisories/unreviewed/2022/05/GHSA-g67r-rgg8-9pxj/GHSA-g67r-rgg8-9pxj.json index 1e767d300e0..3d8e2626245 100644 --- a/advisories/unreviewed/2022/05/GHSA-g67r-rgg8-9pxj/GHSA-g67r-rgg8-9pxj.json +++ b/advisories/unreviewed/2022/05/GHSA-g67r-rgg8-9pxj/GHSA-g67r-rgg8-9pxj.json @@ -7,12 +7,8 @@ "CVE-2008-0399" ], "details": "Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6f2-vq83-q999/GHSA-g6f2-vq83-q999.json b/advisories/unreviewed/2022/05/GHSA-g6f2-vq83-q999/GHSA-g6f2-vq83-q999.json index cf76351a8c9..70469395045 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6f2-vq83-q999/GHSA-g6f2-vq83-q999.json +++ b/advisories/unreviewed/2022/05/GHSA-g6f2-vq83-q999/GHSA-g6f2-vq83-q999.json @@ -7,12 +7,8 @@ "CVE-2008-0953" ], "details": "The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g6jx-3h74-6fm8/GHSA-g6jx-3h74-6fm8.json b/advisories/unreviewed/2022/05/GHSA-g6jx-3h74-6fm8/GHSA-g6jx-3h74-6fm8.json index 17a76c93181..71569c74083 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6jx-3h74-6fm8/GHSA-g6jx-3h74-6fm8.json +++ b/advisories/unreviewed/2022/05/GHSA-g6jx-3h74-6fm8/GHSA-g6jx-3h74-6fm8.json @@ -7,12 +7,8 @@ "CVE-2008-0445" ], "details": "The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g7g8-qgr2-hjq9/GHSA-g7g8-qgr2-hjq9.json b/advisories/unreviewed/2022/05/GHSA-g7g8-qgr2-hjq9/GHSA-g7g8-qgr2-hjq9.json index 9f4555091a5..efbcc3b4a90 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7g8-qgr2-hjq9/GHSA-g7g8-qgr2-hjq9.json +++ b/advisories/unreviewed/2022/05/GHSA-g7g8-qgr2-hjq9/GHSA-g7g8-qgr2-hjq9.json @@ -7,12 +7,8 @@ "CVE-2008-0622" ], "details": "Cross-site scripting (XSS) vulnerability in RaidenHTTPD 2.0.19 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the ulang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g847-ccm8-h7fr/GHSA-g847-ccm8-h7fr.json b/advisories/unreviewed/2022/05/GHSA-g847-ccm8-h7fr/GHSA-g847-ccm8-h7fr.json index 6681b64240d..fe49b63a753 100644 --- a/advisories/unreviewed/2022/05/GHSA-g847-ccm8-h7fr/GHSA-g847-ccm8-h7fr.json +++ b/advisories/unreviewed/2022/05/GHSA-g847-ccm8-h7fr/GHSA-g847-ccm8-h7fr.json @@ -7,12 +7,8 @@ "CVE-2008-0796" ], "details": "SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via the ssid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8fj-6vr7-948q/GHSA-g8fj-6vr7-948q.json b/advisories/unreviewed/2022/05/GHSA-g8fj-6vr7-948q/GHSA-g8fj-6vr7-948q.json index d69a1ce191b..4e65cf61ae4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8fj-6vr7-948q/GHSA-g8fj-6vr7-948q.json +++ b/advisories/unreviewed/2022/05/GHSA-g8fj-6vr7-948q/GHSA-g8fj-6vr7-948q.json @@ -7,12 +7,8 @@ "CVE-2008-0603" ], "details": "SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter in a viewlist task.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9w3-mq78-c86r/GHSA-g9w3-mq78-c86r.json b/advisories/unreviewed/2022/05/GHSA-g9w3-mq78-c86r/GHSA-g9w3-mq78-c86r.json index cfd1ac508a7..62292fabbd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9w3-mq78-c86r/GHSA-g9w3-mq78-c86r.json +++ b/advisories/unreviewed/2022/05/GHSA-g9w3-mq78-c86r/GHSA-g9w3-mq78-c86r.json @@ -7,12 +7,8 @@ "CVE-2008-0984" ], "details": "The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gc8w-mw8v-8fmc/GHSA-gc8w-mw8v-8fmc.json b/advisories/unreviewed/2022/05/GHSA-gc8w-mw8v-8fmc/GHSA-gc8w-mw8v-8fmc.json index 72cbc14771e..e2e30575e64 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc8w-mw8v-8fmc/GHSA-gc8w-mw8v-8fmc.json +++ b/advisories/unreviewed/2022/05/GHSA-gc8w-mw8v-8fmc/GHSA-gc8w-mw8v-8fmc.json @@ -7,12 +7,8 @@ "CVE-2008-0935" ], "details": "Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.34 allows remote attackers to execute arbitrary code via a long argument to the ExecuteRequest method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gchv-r656-x69r/GHSA-gchv-r656-x69r.json b/advisories/unreviewed/2022/05/GHSA-gchv-r656-x69r/GHSA-gchv-r656-x69r.json index 1714cdc77a6..7ccd1a2baa5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gchv-r656-x69r/GHSA-gchv-r656-x69r.json +++ b/advisories/unreviewed/2022/05/GHSA-gchv-r656-x69r/GHSA-gchv-r656-x69r.json @@ -7,12 +7,8 @@ "CVE-2008-0415" ], "details": "Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka \"JavaScript privilege escalation bugs.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf6q-3v4w-8wh8/GHSA-gf6q-3v4w-8wh8.json b/advisories/unreviewed/2022/05/GHSA-gf6q-3v4w-8wh8/GHSA-gf6q-3v4w-8wh8.json index a6a87e729b4..96cd97b241b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf6q-3v4w-8wh8/GHSA-gf6q-3v4w-8wh8.json +++ b/advisories/unreviewed/2022/05/GHSA-gf6q-3v4w-8wh8/GHSA-gf6q-3v4w-8wh8.json @@ -7,12 +7,8 @@ "CVE-2008-0589" ], "details": "The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gff7-c3px-752j/GHSA-gff7-c3px-752j.json b/advisories/unreviewed/2022/05/GHSA-gff7-c3px-752j/GHSA-gff7-c3px-752j.json index e44d51aaa1e..dbab6887c43 100644 --- a/advisories/unreviewed/2022/05/GHSA-gff7-c3px-752j/GHSA-gff7-c3px-752j.json +++ b/advisories/unreviewed/2022/05/GHSA-gff7-c3px-752j/GHSA-gff7-c3px-752j.json @@ -7,12 +7,8 @@ "CVE-2008-0485" ], "details": "Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gfr7-vjm7-2h33/GHSA-gfr7-vjm7-2h33.json b/advisories/unreviewed/2022/05/GHSA-gfr7-vjm7-2h33/GHSA-gfr7-vjm7-2h33.json index 50d755470c5..8e99de28436 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfr7-vjm7-2h33/GHSA-gfr7-vjm7-2h33.json +++ b/advisories/unreviewed/2022/05/GHSA-gfr7-vjm7-2h33/GHSA-gfr7-vjm7-2h33.json @@ -7,12 +7,8 @@ "CVE-2008-0480" ], "details": "Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfv7-jxhj-vh42/GHSA-gfv7-jxhj-vh42.json b/advisories/unreviewed/2022/05/GHSA-gfv7-jxhj-vh42/GHSA-gfv7-jxhj-vh42.json index 9932ea368f8..e4ede4e92fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfv7-jxhj-vh42/GHSA-gfv7-jxhj-vh42.json +++ b/advisories/unreviewed/2022/05/GHSA-gfv7-jxhj-vh42/GHSA-gfv7-jxhj-vh42.json @@ -7,12 +7,8 @@ "CVE-2008-0691" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wp_footnotes_current_settings[priority], (2) wp_footnotes_current_settings[style_rules], (3) wp_footnotes_current_settings[pre_footnotes], and (4) wp_footnotes_current_settings[post_footnotes] parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfx2-rhjx-wx78/GHSA-gfx2-rhjx-wx78.json b/advisories/unreviewed/2022/05/GHSA-gfx2-rhjx-wx78/GHSA-gfx2-rhjx-wx78.json index 7f41655cefb..9b925c7a2db 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfx2-rhjx-wx78/GHSA-gfx2-rhjx-wx78.json +++ b/advisories/unreviewed/2022/05/GHSA-gfx2-rhjx-wx78/GHSA-gfx2-rhjx-wx78.json @@ -7,12 +7,8 @@ "CVE-2008-0510" ], "details": "SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggfh-c25x-c875/GHSA-ggfh-c25x-c875.json b/advisories/unreviewed/2022/05/GHSA-ggfh-c25x-c875/GHSA-ggfh-c25x-c875.json index d1657f444c9..7fed10f0cc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggfh-c25x-c875/GHSA-ggfh-c25x-c875.json +++ b/advisories/unreviewed/2022/05/GHSA-ggfh-c25x-c875/GHSA-ggfh-c25x-c875.json @@ -7,12 +7,8 @@ "CVE-2008-0621" ], "details": "Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via long arguments to the (1) 0x01, (2) 0x02, (3) 0x03, (4) 0x04, and (5) 0x05 LPD commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ggq4-3r94-cq28/GHSA-ggq4-3r94-cq28.json b/advisories/unreviewed/2022/05/GHSA-ggq4-3r94-cq28/GHSA-ggq4-3r94-cq28.json index cfe51bf5ac8..783300727b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggq4-3r94-cq28/GHSA-ggq4-3r94-cq28.json +++ b/advisories/unreviewed/2022/05/GHSA-ggq4-3r94-cq28/GHSA-ggq4-3r94-cq28.json @@ -7,12 +7,8 @@ "CVE-2008-0792" ], "details": "Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ggr9-gq8g-j6c3/GHSA-ggr9-gq8g-j6c3.json b/advisories/unreviewed/2022/05/GHSA-ggr9-gq8g-j6c3/GHSA-ggr9-gq8g-j6c3.json index a37ee825940..f7b119fe54f 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggr9-gq8g-j6c3/GHSA-ggr9-gq8g-j6c3.json +++ b/advisories/unreviewed/2022/05/GHSA-ggr9-gq8g-j6c3/GHSA-ggr9-gq8g-j6c3.json @@ -7,12 +7,8 @@ "CVE-2008-0433" ], "details": "PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter, a different vector than CVE-2007-6614.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gh56-x5j7-wgqm/GHSA-gh56-x5j7-wgqm.json b/advisories/unreviewed/2022/05/GHSA-gh56-x5j7-wgqm/GHSA-gh56-x5j7-wgqm.json index 5a2023911d5..e3aacbee398 100644 --- a/advisories/unreviewed/2022/05/GHSA-gh56-x5j7-wgqm/GHSA-gh56-x5j7-wgqm.json +++ b/advisories/unreviewed/2022/05/GHSA-gh56-x5j7-wgqm/GHSA-gh56-x5j7-wgqm.json @@ -7,12 +7,8 @@ "CVE-2008-0869" ], "details": "Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a \"framework defined request parameter\" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmj2-prqf-4r46/GHSA-gmj2-prqf-4r46.json b/advisories/unreviewed/2022/05/GHSA-gmj2-prqf-4r46/GHSA-gmj2-prqf-4r46.json index 7bb66c9049e..918636790e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmj2-prqf-4r46/GHSA-gmj2-prqf-4r46.json +++ b/advisories/unreviewed/2022/05/GHSA-gmj2-prqf-4r46/GHSA-gmj2-prqf-4r46.json @@ -7,12 +7,8 @@ "CVE-2008-0798" ], "details": "Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ta parameter to artmedic_index.php, reached through index.php; and the (2) date parameter to artmedic_print.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmrh-86v3-r98c/GHSA-gmrh-86v3-r98c.json b/advisories/unreviewed/2022/05/GHSA-gmrh-86v3-r98c/GHSA-gmrh-86v3-r98c.json index dead20a540a..699dd830e21 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmrh-86v3-r98c/GHSA-gmrh-86v3-r98c.json +++ b/advisories/unreviewed/2022/05/GHSA-gmrh-86v3-r98c/GHSA-gmrh-86v3-r98c.json @@ -7,12 +7,8 @@ "CVE-2008-0921" ], "details": "SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gqc7-mq8q-h2vv/GHSA-gqc7-mq8q-h2vv.json b/advisories/unreviewed/2022/05/GHSA-gqc7-mq8q-h2vv/GHSA-gqc7-mq8q-h2vv.json index 2f1405fffc9..a0b1b79d28b 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqc7-mq8q-h2vv/GHSA-gqc7-mq8q-h2vv.json +++ b/advisories/unreviewed/2022/05/GHSA-gqc7-mq8q-h2vv/GHSA-gqc7-mq8q-h2vv.json @@ -7,12 +7,8 @@ "CVE-2008-0566" ], "details": "PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_public_program parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gr9c-j838-2fqj/GHSA-gr9c-j838-2fqj.json b/advisories/unreviewed/2022/05/GHSA-gr9c-j838-2fqj/GHSA-gr9c-j838-2fqj.json index a322f70c7d3..928ebbf47bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr9c-j838-2fqj/GHSA-gr9c-j838-2fqj.json +++ b/advisories/unreviewed/2022/05/GHSA-gr9c-j838-2fqj/GHSA-gr9c-j838-2fqj.json @@ -7,12 +7,8 @@ "CVE-2008-0606" ], "details": "SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grpg-6mx5-wwhv/GHSA-grpg-6mx5-wwhv.json b/advisories/unreviewed/2022/05/GHSA-grpg-6mx5-wwhv/GHSA-grpg-6mx5-wwhv.json index 483af9d18cc..33194bb6500 100644 --- a/advisories/unreviewed/2022/05/GHSA-grpg-6mx5-wwhv/GHSA-grpg-6mx5-wwhv.json +++ b/advisories/unreviewed/2022/05/GHSA-grpg-6mx5-wwhv/GHSA-grpg-6mx5-wwhv.json @@ -7,12 +7,8 @@ "CVE-2008-0591" ], "details": "Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the \"dialog refocus bug\" or \"ffclick2\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -264,9 +260,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gx26-p933-5c9f/GHSA-gx26-p933-5c9f.json b/advisories/unreviewed/2022/05/GHSA-gx26-p933-5c9f/GHSA-gx26-p933-5c9f.json index b4b03700b80..4cd3b474fbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx26-p933-5c9f/GHSA-gx26-p933-5c9f.json +++ b/advisories/unreviewed/2022/05/GHSA-gx26-p933-5c9f/GHSA-gx26-p933-5c9f.json @@ -7,12 +7,8 @@ "CVE-2008-0671" ], "details": "Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code via a long chat message, related to conversion from LF to CRLF.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxp4-wcxf-ffgg/GHSA-gxp4-wcxf-ffgg.json b/advisories/unreviewed/2022/05/GHSA-gxp4-wcxf-ffgg/GHSA-gxp4-wcxf-ffgg.json index 95d09881eec..2127d89a4ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxp4-wcxf-ffgg/GHSA-gxp4-wcxf-ffgg.json +++ b/advisories/unreviewed/2022/05/GHSA-gxp4-wcxf-ffgg/GHSA-gxp4-wcxf-ffgg.json @@ -7,12 +7,8 @@ "CVE-2008-0541" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxrw-8w52-4mmq/GHSA-gxrw-8w52-4mmq.json b/advisories/unreviewed/2022/05/GHSA-gxrw-8w52-4mmq/GHSA-gxrw-8w52-4mmq.json index 7745c4f4d02..fbfd7fd5d64 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxrw-8w52-4mmq/GHSA-gxrw-8w52-4mmq.json +++ b/advisories/unreviewed/2022/05/GHSA-gxrw-8w52-4mmq/GHSA-gxrw-8w52-4mmq.json @@ -7,12 +7,8 @@ "CVE-2008-0424" ], "details": "SQL injection vulnerability in blog.php in Mooseguy Blog System (MGBS) 1.0 allows remote attackers to execute arbitrary SQL commands via the month parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxxg-g22w-m8r2/GHSA-gxxg-g22w-m8r2.json b/advisories/unreviewed/2022/05/GHSA-gxxg-g22w-m8r2/GHSA-gxxg-g22w-m8r2.json index f28550062d4..101ccd3b4a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxxg-g22w-m8r2/GHSA-gxxg-g22w-m8r2.json +++ b/advisories/unreviewed/2022/05/GHSA-gxxg-g22w-m8r2/GHSA-gxxg-g22w-m8r2.json @@ -7,12 +7,8 @@ "CVE-2008-0879" ], "details": "SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h446-8cjw-27pj/GHSA-h446-8cjw-27pj.json b/advisories/unreviewed/2022/05/GHSA-h446-8cjw-27pj/GHSA-h446-8cjw-27pj.json index 87cc0ca19dc..04a74ab2a11 100644 --- a/advisories/unreviewed/2022/05/GHSA-h446-8cjw-27pj/GHSA-h446-8cjw-27pj.json +++ b/advisories/unreviewed/2022/05/GHSA-h446-8cjw-27pj/GHSA-h446-8cjw-27pj.json @@ -7,12 +7,8 @@ "CVE-2008-0521" ], "details": "Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a .. (dot dot) in the uri parameter to dispatcher.php in (1) examples/dispatcher/framework/, (2) examples/dispatcher/, (3) examples/wizard/, and (4) PHP/, different vectors than CVE-2008-0545.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h774-2wxq-fmf6/GHSA-h774-2wxq-fmf6.json b/advisories/unreviewed/2022/05/GHSA-h774-2wxq-fmf6/GHSA-h774-2wxq-fmf6.json index 929bc709b1b..2c07f05a067 100644 --- a/advisories/unreviewed/2022/05/GHSA-h774-2wxq-fmf6/GHSA-h774-2wxq-fmf6.json +++ b/advisories/unreviewed/2022/05/GHSA-h774-2wxq-fmf6/GHSA-h774-2wxq-fmf6.json @@ -7,12 +7,8 @@ "CVE-2008-0880" ], "details": "SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the page_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h78q-jxm5-wh6g/GHSA-h78q-jxm5-wh6g.json b/advisories/unreviewed/2022/05/GHSA-h78q-jxm5-wh6g/GHSA-h78q-jxm5-wh6g.json index fa4cca5d44c..b9d6c14451f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h78q-jxm5-wh6g/GHSA-h78q-jxm5-wh6g.json +++ b/advisories/unreviewed/2022/05/GHSA-h78q-jxm5-wh6g/GHSA-h78q-jxm5-wh6g.json @@ -7,12 +7,8 @@ "CVE-2008-0803" ], "details": "Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the sys_conf[path][real] parameter to (1) modules\\class\\Table.php; (2) db_admins.php, (3) db_alert.php, (4) db_double.php, (5) db_games.php, (6) db_matches.php, (7) db_match_teams.php, (8) db_news.php, (9) db_platform.php, (10) db_players.php, (11) db_server_group.php, (12) db_server_ip.php, (13) db_teams.php, (14) db_team_players.php, (15) db_tournaments.php, (16) db_tournament_teams.php, and (17) db_trees.php in modules\\class\\db\\; and (18) Match.php, (19) MatchTeam.php, (20) Rule.php, (21) RuleBuilder.php, (22) RulePool.php, (23) RuleSingle.php, (24) RuleTree.php, (25) Tournament.php, (26) TournamentTeam.php, (27) Tree.php, and (28) TreeSingle.php in modules\\class\\tournament\\. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7cp-5xgq-g2j7/GHSA-h7cp-5xgq-g2j7.json b/advisories/unreviewed/2022/05/GHSA-h7cp-5xgq-g2j7/GHSA-h7cp-5xgq-g2j7.json index dab1de63327..8f4b1a748c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7cp-5xgq-g2j7/GHSA-h7cp-5xgq-g2j7.json +++ b/advisories/unreviewed/2022/05/GHSA-h7cp-5xgq-g2j7/GHSA-h7cp-5xgq-g2j7.json @@ -7,12 +7,8 @@ "CVE-2019-2160" ], "details": "In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112715795", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h857-256j-hxp8/GHSA-h857-256j-hxp8.json b/advisories/unreviewed/2022/05/GHSA-h857-256j-hxp8/GHSA-h857-256j-hxp8.json index 7983a5e01c2..b1064a7fa92 100644 --- a/advisories/unreviewed/2022/05/GHSA-h857-256j-hxp8/GHSA-h857-256j-hxp8.json +++ b/advisories/unreviewed/2022/05/GHSA-h857-256j-hxp8/GHSA-h857-256j-hxp8.json @@ -7,12 +7,8 @@ "CVE-2008-0410" ], "details": "HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as %version% in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8fc-w45m-x9wj/GHSA-h8fc-w45m-x9wj.json b/advisories/unreviewed/2022/05/GHSA-h8fc-w45m-x9wj/GHSA-h8fc-w45m-x9wj.json index 47272815dfd..dc2667933b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8fc-w45m-x9wj/GHSA-h8fc-w45m-x9wj.json +++ b/advisories/unreviewed/2022/05/GHSA-h8fc-w45m-x9wj/GHSA-h8fc-w45m-x9wj.json @@ -7,12 +7,8 @@ "CVE-2008-0790" ], "details": "Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8h8-jvvh-7jjc/GHSA-h8h8-jvvh-7jjc.json b/advisories/unreviewed/2022/05/GHSA-h8h8-jvvh-7jjc/GHSA-h8h8-jvvh-7jjc.json index 9e10753fbd8..cf0b4a20f35 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8h8-jvvh-7jjc/GHSA-h8h8-jvvh-7jjc.json +++ b/advisories/unreviewed/2022/05/GHSA-h8h8-jvvh-7jjc/GHSA-h8h8-jvvh-7jjc.json @@ -7,12 +7,8 @@ "CVE-2008-0791" ], "details": "ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to cause a denial of service (CPU consumption) via short packets on TCP port 5001 with the 3, 5, 7, 13, 14, or 15 packet types.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8rx-2q5f-5vwg/GHSA-h8rx-2q5f-5vwg.json b/advisories/unreviewed/2022/05/GHSA-h8rx-2q5f-5vwg/GHSA-h8rx-2q5f-5vwg.json index b10bde880ad..bff6fe8db81 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8rx-2q5f-5vwg/GHSA-h8rx-2q5f-5vwg.json +++ b/advisories/unreviewed/2022/05/GHSA-h8rx-2q5f-5vwg/GHSA-h8rx-2q5f-5vwg.json @@ -7,12 +7,8 @@ "CVE-2008-0776" ], "details": "SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9g5-6mf3-h8qj/GHSA-h9g5-6mf3-h8qj.json b/advisories/unreviewed/2022/05/GHSA-h9g5-6mf3-h8qj/GHSA-h9g5-6mf3-h8qj.json index 56893b44115..c3ee16ddb7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9g5-6mf3-h8qj/GHSA-h9g5-6mf3-h8qj.json +++ b/advisories/unreviewed/2022/05/GHSA-h9g5-6mf3-h8qj/GHSA-h9g5-6mf3-h8qj.json @@ -7,12 +7,8 @@ "CVE-2008-0955" ], "details": "Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder property value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h9jh-74gh-hcpp/GHSA-h9jh-74gh-hcpp.json b/advisories/unreviewed/2022/05/GHSA-h9jh-74gh-hcpp/GHSA-h9jh-74gh-hcpp.json index 3c094e41642..fbc1883dbec 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9jh-74gh-hcpp/GHSA-h9jh-74gh-hcpp.json +++ b/advisories/unreviewed/2022/05/GHSA-h9jh-74gh-hcpp/GHSA-h9jh-74gh-hcpp.json @@ -7,12 +7,8 @@ "CVE-2008-0465" ], "details": "Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hgf8-pv4w-p39v/GHSA-hgf8-pv4w-p39v.json b/advisories/unreviewed/2022/05/GHSA-hgf8-pv4w-p39v/GHSA-hgf8-pv4w-p39v.json index 8ed807a15fa..61ffbd55e2c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgf8-pv4w-p39v/GHSA-hgf8-pv4w-p39v.json +++ b/advisories/unreviewed/2022/05/GHSA-hgf8-pv4w-p39v/GHSA-hgf8-pv4w-p39v.json @@ -7,12 +7,8 @@ "CVE-2008-0462" ], "details": "Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hgfm-c2w9-5xf5/GHSA-hgfm-c2w9-5xf5.json b/advisories/unreviewed/2022/05/GHSA-hgfm-c2w9-5xf5/GHSA-hgfm-c2w9-5xf5.json index c209f526f37..16577620eb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgfm-c2w9-5xf5/GHSA-hgfm-c2w9-5xf5.json +++ b/advisories/unreviewed/2022/05/GHSA-hgfm-c2w9-5xf5/GHSA-hgfm-c2w9-5xf5.json @@ -7,12 +7,8 @@ "CVE-2008-0407" ], "details": "HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hrxx-5fj9-6269/GHSA-hrxx-5fj9-6269.json b/advisories/unreviewed/2022/05/GHSA-hrxx-5fj9-6269/GHSA-hrxx-5fj9-6269.json index 7ebffa043d2..30f5f20437a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrxx-5fj9-6269/GHSA-hrxx-5fj9-6269.json +++ b/advisories/unreviewed/2022/05/GHSA-hrxx-5fj9-6269/GHSA-hrxx-5fj9-6269.json @@ -7,12 +7,8 @@ "CVE-2008-0816" ], "details": "SQL injection vulnerability in the com_sg component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the pid parameter in an order task.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwc8-3mcr-2wjf/GHSA-hwc8-3mcr-2wjf.json b/advisories/unreviewed/2022/05/GHSA-hwc8-3mcr-2wjf/GHSA-hwc8-3mcr-2wjf.json index 19afe86ddc3..ac8b8c45988 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwc8-3mcr-2wjf/GHSA-hwc8-3mcr-2wjf.json +++ b/advisories/unreviewed/2022/05/GHSA-hwc8-3mcr-2wjf/GHSA-hwc8-3mcr-2wjf.json @@ -7,12 +7,8 @@ "CVE-2008-0642" ], "details": "Cross-site scripting (XSS) vulnerability in files created by Adobe RoboHelp 6 and 7, possibly involving use of a (1) WebHelp5 (WebHelp5Ext) or (2) WildFire (WildFireExt) extension, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-1280.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwwx-2xrv-97gj/GHSA-hwwx-2xrv-97gj.json b/advisories/unreviewed/2022/05/GHSA-hwwx-2xrv-97gj/GHSA-hwwx-2xrv-97gj.json index 913fb82be35..e7060ed5b29 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwwx-2xrv-97gj/GHSA-hwwx-2xrv-97gj.json +++ b/advisories/unreviewed/2022/05/GHSA-hwwx-2xrv-97gj/GHSA-hwwx-2xrv-97gj.json @@ -7,12 +7,8 @@ "CVE-2008-0649" ], "details": "SQL injection vulnerability in detail.php in Astanda Directory Project (ADP) 1.2 and 1.3 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx37-57m6-7957/GHSA-hx37-57m6-7957.json b/advisories/unreviewed/2022/05/GHSA-hx37-57m6-7957/GHSA-hx37-57m6-7957.json index 26459d07a45..50b7f60643a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx37-57m6-7957/GHSA-hx37-57m6-7957.json +++ b/advisories/unreviewed/2022/05/GHSA-hx37-57m6-7957/GHSA-hx37-57m6-7957.json @@ -7,12 +7,8 @@ "CVE-2008-0448" ], "details": "PHP remote file inclusion vulnerability in utils/class_HTTPRetriever.php in phpSearch allows remote attackers to execute arbitrary PHP code via a URL in the libcurlemuinc parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j23m-2qch-pvvp/GHSA-j23m-2qch-pvvp.json b/advisories/unreviewed/2022/05/GHSA-j23m-2qch-pvvp/GHSA-j23m-2qch-pvvp.json index d0542c29289..73fe68ee7cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-j23m-2qch-pvvp/GHSA-j23m-2qch-pvvp.json +++ b/advisories/unreviewed/2022/05/GHSA-j23m-2qch-pvvp/GHSA-j23m-2qch-pvvp.json @@ -7,12 +7,8 @@ "CVE-2008-0971" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the Policy Name field in Search Based Retention Policy in Message Archiver; unspecified parameters in the (2) IP Configuration, (3) Administration, (4) Journal Accounts, (5) Retention Policy, and (6) GroupWise Sync components in Message Archiver; (7) input to search operations in Web Filter; and (8) input used in error messages and (9) hidden INPUT elements in (a) Spam Firewall, (b) IM Firewall, and (c) Web Filter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j24h-fjfc-58fr/GHSA-j24h-fjfc-58fr.json b/advisories/unreviewed/2022/05/GHSA-j24h-fjfc-58fr/GHSA-j24h-fjfc-58fr.json index 5feb6a1a339..8fdf987b203 100644 --- a/advisories/unreviewed/2022/05/GHSA-j24h-fjfc-58fr/GHSA-j24h-fjfc-58fr.json +++ b/advisories/unreviewed/2022/05/GHSA-j24h-fjfc-58fr/GHSA-j24h-fjfc-58fr.json @@ -7,12 +7,8 @@ "CVE-2019-1409" ], "details": "An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializes objects in memory, aka 'Windows Remote Procedure Call Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j26g-5fx3-gg9m/GHSA-j26g-5fx3-gg9m.json b/advisories/unreviewed/2022/05/GHSA-j26g-5fx3-gg9m/GHSA-j26g-5fx3-gg9m.json index f426fa5e39f..231b33ed36b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j26g-5fx3-gg9m/GHSA-j26g-5fx3-gg9m.json +++ b/advisories/unreviewed/2022/05/GHSA-j26g-5fx3-gg9m/GHSA-j26g-5fx3-gg9m.json @@ -7,12 +7,8 @@ "CVE-2008-0586" ], "details": "Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldeletepv, (3) putlvodm, (4) lvaryoffvg, and (5) lvgenminor programs in bos.rte.lvm; and the (6) tellclvmd program in bos.clvm.enh.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2vp-w8fr-w95m/GHSA-j2vp-w8fr-w95m.json b/advisories/unreviewed/2022/05/GHSA-j2vp-w8fr-w95m/GHSA-j2vp-w8fr-w95m.json index 367c739dc42..62799eb5233 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2vp-w8fr-w95m/GHSA-j2vp-w8fr-w95m.json +++ b/advisories/unreviewed/2022/05/GHSA-j2vp-w8fr-w95m/GHSA-j2vp-w8fr-w95m.json @@ -7,12 +7,8 @@ "CVE-2008-0704" ], "details": "Unspecified vulnerability in the SSH server in HP OpenVMS TCP/IP Services on OpenVMS on the Alpha platform with 5.4 before ECO 7, and on the Integrity and Alpha platforms with 5.5 before ECO 3 and 5.6 before ECO 2, allows remote attackers to obtain unspecified access via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j54p-j75c-v6pm/GHSA-j54p-j75c-v6pm.json b/advisories/unreviewed/2022/05/GHSA-j54p-j75c-v6pm/GHSA-j54p-j75c-v6pm.json index 9b38bf5a729..cbfa1a1699c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j54p-j75c-v6pm/GHSA-j54p-j75c-v6pm.json +++ b/advisories/unreviewed/2022/05/GHSA-j54p-j75c-v6pm/GHSA-j54p-j75c-v6pm.json @@ -7,12 +7,8 @@ "CVE-2008-0452" ], "details": "Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the cat parameter in a viewart action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j5q7-rgrp-pp6c/GHSA-j5q7-rgrp-pp6c.json b/advisories/unreviewed/2022/05/GHSA-j5q7-rgrp-pp6c/GHSA-j5q7-rgrp-pp6c.json index 03e9aa3d3ff..762c692c709 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5q7-rgrp-pp6c/GHSA-j5q7-rgrp-pp6c.json +++ b/advisories/unreviewed/2022/05/GHSA-j5q7-rgrp-pp6c/GHSA-j5q7-rgrp-pp6c.json @@ -7,12 +7,8 @@ "CVE-2008-0505" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j748-xg4f-5gvp/GHSA-j748-xg4f-5gvp.json b/advisories/unreviewed/2022/05/GHSA-j748-xg4f-5gvp/GHSA-j748-xg4f-5gvp.json index b32ed9360d5..ca8fad7a77d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j748-xg4f-5gvp/GHSA-j748-xg4f-5gvp.json +++ b/advisories/unreviewed/2022/05/GHSA-j748-xg4f-5gvp/GHSA-j748-xg4f-5gvp.json @@ -7,12 +7,8 @@ "CVE-2008-0700" ], "details": "Cross-site scripting (XSS) vulnerability in search.php in Crux Software CruxCMS 3.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j777-j44j-87h2/GHSA-j777-j44j-87h2.json b/advisories/unreviewed/2022/05/GHSA-j777-j44j-87h2/GHSA-j777-j44j-87h2.json index d4f32d6fec0..787e6f7e82a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j777-j44j-87h2/GHSA-j777-j44j-87h2.json +++ b/advisories/unreviewed/2022/05/GHSA-j777-j44j-87h2/GHSA-j777-j44j-87h2.json @@ -7,12 +7,8 @@ "CVE-2008-0878" ], "details": "SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j7vv-hfcm-2mq5/GHSA-j7vv-hfcm-2mq5.json b/advisories/unreviewed/2022/05/GHSA-j7vv-hfcm-2mq5/GHSA-j7vv-hfcm-2mq5.json index 433c90060a3..ddbaae377e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-j7vv-hfcm-2mq5/GHSA-j7vv-hfcm-2mq5.json +++ b/advisories/unreviewed/2022/05/GHSA-j7vv-hfcm-2mq5/GHSA-j7vv-hfcm-2mq5.json @@ -7,12 +7,8 @@ "CVE-2019-1419" ], "details": "A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1456.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j8pg-cxx4-5c4x/GHSA-j8pg-cxx4-5c4x.json b/advisories/unreviewed/2022/05/GHSA-j8pg-cxx4-5c4x/GHSA-j8pg-cxx4-5c4x.json index 251935576f6..5a18e1815ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8pg-cxx4-5c4x/GHSA-j8pg-cxx4-5c4x.json +++ b/advisories/unreviewed/2022/05/GHSA-j8pg-cxx4-5c4x/GHSA-j8pg-cxx4-5c4x.json @@ -7,12 +7,8 @@ "CVE-2008-0758" ], "details": "Multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allow remote attackers to read arbitrary (1) gif, (2) png, (3) jpg, (4) xml, (5) ico, (6) zip, and (7) html files via a \"..\\\" (dot dot backslash) sequence in the filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8v8-39p3-x83f/GHSA-j8v8-39p3-x83f.json b/advisories/unreviewed/2022/05/GHSA-j8v8-39p3-x83f/GHSA-j8v8-39p3-x83f.json index 08744026809..4308840f7e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8v8-39p3-x83f/GHSA-j8v8-39p3-x83f.json +++ b/advisories/unreviewed/2022/05/GHSA-j8v8-39p3-x83f/GHSA-j8v8-39p3-x83f.json @@ -7,12 +7,8 @@ "CVE-2019-1399" ], "details": "A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1310.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9g9-h6jh-x7f2/GHSA-j9g9-h6jh-x7f2.json b/advisories/unreviewed/2022/05/GHSA-j9g9-h6jh-x7f2/GHSA-j9g9-h6jh-x7f2.json index 8c2957b896d..8c7284a1e2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9g9-h6jh-x7f2/GHSA-j9g9-h6jh-x7f2.json +++ b/advisories/unreviewed/2022/05/GHSA-j9g9-h6jh-x7f2/GHSA-j9g9-h6jh-x7f2.json @@ -7,12 +7,8 @@ "CVE-2008-0934" ], "details": "SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_catg parameter in a ViewCatg action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc4m-r9c3-28j2/GHSA-jc4m-r9c3-28j2.json b/advisories/unreviewed/2022/05/GHSA-jc4m-r9c3-28j2/GHSA-jc4m-r9c3-28j2.json index 5ea1bbbecc5..b71232e6922 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc4m-r9c3-28j2/GHSA-jc4m-r9c3-28j2.json +++ b/advisories/unreviewed/2022/05/GHSA-jc4m-r9c3-28j2/GHSA-jc4m-r9c3-28j2.json @@ -7,12 +7,8 @@ "CVE-2008-0872" ], "details": "Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute of an element in the Subject field of an e-mail message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc8j-c4rx-788x/GHSA-jc8j-c4rx-788x.json b/advisories/unreviewed/2022/05/GHSA-jc8j-c4rx-788x/GHSA-jc8j-c4rx-788x.json index d18bd1d8b03..0aaad0de900 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc8j-c4rx-788x/GHSA-jc8j-c4rx-788x.json +++ b/advisories/unreviewed/2022/05/GHSA-jc8j-c4rx-788x/GHSA-jc8j-c4rx-788x.json @@ -7,12 +7,8 @@ "CVE-2008-0728" ], "details": "The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger \"heap corruption.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jcpw-wjxw-354f/GHSA-jcpw-wjxw-354f.json b/advisories/unreviewed/2022/05/GHSA-jcpw-wjxw-354f/GHSA-jcpw-wjxw-354f.json index e140dfd6acb..9a66b4199ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcpw-wjxw-354f/GHSA-jcpw-wjxw-354f.json +++ b/advisories/unreviewed/2022/05/GHSA-jcpw-wjxw-354f/GHSA-jcpw-wjxw-354f.json @@ -7,12 +7,8 @@ "CVE-2008-0707" ], "details": "HP StorageWorks Library and Tape Tools (LTT) before 4.5 SR1 on HP-UX B.11.11 and B.11.23 allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jgxf-w4hm-5gmh/GHSA-jgxf-w4hm-5gmh.json b/advisories/unreviewed/2022/05/GHSA-jgxf-w4hm-5gmh/GHSA-jgxf-w4hm-5gmh.json index 126b4142cbc..cd845a24e4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgxf-w4hm-5gmh/GHSA-jgxf-w4hm-5gmh.json +++ b/advisories/unreviewed/2022/05/GHSA-jgxf-w4hm-5gmh/GHSA-jgxf-w4hm-5gmh.json @@ -7,12 +7,8 @@ "CVE-2008-0522" ], "details": "Cross-site scripting (XSS) vulnerability in multiple Hal Networks shopping-cart products allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jjqg-vqjq-fcqh/GHSA-jjqg-vqjq-fcqh.json b/advisories/unreviewed/2022/05/GHSA-jjqg-vqjq-fcqh/GHSA-jjqg-vqjq-fcqh.json index 1038d438d9c..55622659110 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjqg-vqjq-fcqh/GHSA-jjqg-vqjq-fcqh.json +++ b/advisories/unreviewed/2022/05/GHSA-jjqg-vqjq-fcqh/GHSA-jjqg-vqjq-fcqh.json @@ -7,12 +7,8 @@ "CVE-2008-0426" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PacerCMS before 0.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) headline, or (3) text field in a message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jm47-5f5w-xv36/GHSA-jm47-5f5w-xv36.json b/advisories/unreviewed/2022/05/GHSA-jm47-5f5w-xv36/GHSA-jm47-5f5w-xv36.json index 9495ec414dd..50211e49b79 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm47-5f5w-xv36/GHSA-jm47-5f5w-xv36.json +++ b/advisories/unreviewed/2022/05/GHSA-jm47-5f5w-xv36/GHSA-jm47-5f5w-xv36.json @@ -7,12 +7,8 @@ "CVE-2008-0487" ], "details": "Multiple SQL injection vulnerabilities in login.asp in ASPired2Protect allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jph2-4993-v6wc/GHSA-jph2-4993-v6wc.json b/advisories/unreviewed/2022/05/GHSA-jph2-4993-v6wc/GHSA-jph2-4993-v6wc.json index cf6f4319f3a..4dfc1d0523e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jph2-4993-v6wc/GHSA-jph2-4993-v6wc.json +++ b/advisories/unreviewed/2022/05/GHSA-jph2-4993-v6wc/GHSA-jph2-4993-v6wc.json @@ -7,12 +7,8 @@ "CVE-2008-0923" ], "details": "Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a \"%c0%2e%c0%2e\" string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jq2h-57hv-fpf7/GHSA-jq2h-57hv-fpf7.json b/advisories/unreviewed/2022/05/GHSA-jq2h-57hv-fpf7/GHSA-jq2h-57hv-fpf7.json index ee96c0c07bd..b5da73ea7e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jq2h-57hv-fpf7/GHSA-jq2h-57hv-fpf7.json +++ b/advisories/unreviewed/2022/05/GHSA-jq2h-57hv-fpf7/GHSA-jq2h-57hv-fpf7.json @@ -7,12 +7,8 @@ "CVE-2008-0534" ], "details": "The SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device restart or daemon outage) via a high rate of login attempts, aka Bug ID CSCsi68582.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrwr-2x5x-8hqx/GHSA-jrwr-2x5x-8hqx.json b/advisories/unreviewed/2022/05/GHSA-jrwr-2x5x-8hqx/GHSA-jrwr-2x5x-8hqx.json index 05f29dbf76b..4ffa31a6688 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrwr-2x5x-8hqx/GHSA-jrwr-2x5x-8hqx.json +++ b/advisories/unreviewed/2022/05/GHSA-jrwr-2x5x-8hqx/GHSA-jrwr-2x5x-8hqx.json @@ -7,12 +7,8 @@ "CVE-2008-0747" ], "details": "Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute arbitrary code via a long URL in a .asx file, a different vulnerability than CVE-2007-5487.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jvxc-cf42-9cxc/GHSA-jvxc-cf42-9cxc.json b/advisories/unreviewed/2022/05/GHSA-jvxc-cf42-9cxc/GHSA-jvxc-cf42-9cxc.json index b2f32de4c4e..d81e0a5852b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jvxc-cf42-9cxc/GHSA-jvxc-cf42-9cxc.json +++ b/advisories/unreviewed/2022/05/GHSA-jvxc-cf42-9cxc/GHSA-jvxc-cf42-9cxc.json @@ -7,12 +7,8 @@ "CVE-2019-0712" ], "details": "A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309, CVE-2019-1310, CVE-2019-1399.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw24-p6mh-9cmh/GHSA-jw24-p6mh-9cmh.json b/advisories/unreviewed/2022/05/GHSA-jw24-p6mh-9cmh/GHSA-jw24-p6mh-9cmh.json index 854d4502974..d85571b661e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw24-p6mh-9cmh/GHSA-jw24-p6mh-9cmh.json +++ b/advisories/unreviewed/2022/05/GHSA-jw24-p6mh-9cmh/GHSA-jw24-p6mh-9cmh.json @@ -7,12 +7,8 @@ "CVE-2019-2154" ], "details": "In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117610057", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jw59-27mg-7cmg/GHSA-jw59-27mg-7cmg.json b/advisories/unreviewed/2022/05/GHSA-jw59-27mg-7cmg/GHSA-jw59-27mg-7cmg.json index 4eb5e4f6df6..aace81ee8f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw59-27mg-7cmg/GHSA-jw59-27mg-7cmg.json +++ b/advisories/unreviewed/2022/05/GHSA-jw59-27mg-7cmg/GHSA-jw59-27mg-7cmg.json @@ -7,12 +7,8 @@ "CVE-2008-0765" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in artmedic webdesign weblog allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to artmedic_print.php and the (2) jahrneu parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx5j-prpx-hpfh/GHSA-jx5j-prpx-hpfh.json b/advisories/unreviewed/2022/05/GHSA-jx5j-prpx-hpfh/GHSA-jx5j-prpx-hpfh.json index 69762f1ae16..b3e9d21cb62 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx5j-prpx-hpfh/GHSA-jx5j-prpx-hpfh.json +++ b/advisories/unreviewed/2022/05/GHSA-jx5j-prpx-hpfh/GHSA-jx5j-prpx-hpfh.json @@ -7,12 +7,8 @@ "CVE-2008-0690" ], "details": "SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewcat action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxr4-9m47-rq8f/GHSA-jxr4-9m47-rq8f.json b/advisories/unreviewed/2022/05/GHSA-jxr4-9m47-rq8f/GHSA-jxr4-9m47-rq8f.json index 30c9a8a70bf..d68d19c6dd4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxr4-9m47-rq8f/GHSA-jxr4-9m47-rq8f.json +++ b/advisories/unreviewed/2022/05/GHSA-jxr4-9m47-rq8f/GHSA-jxr4-9m47-rq8f.json @@ -7,12 +7,8 @@ "CVE-2008-0504" ], "details": "Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jxx6-3r86-qh2g/GHSA-jxx6-3r86-qh2g.json b/advisories/unreviewed/2022/05/GHSA-jxx6-3r86-qh2g/GHSA-jxx6-3r86-qh2g.json index 9221b682514..97c7f5c01d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxx6-3r86-qh2g/GHSA-jxx6-3r86-qh2g.json +++ b/advisories/unreviewed/2022/05/GHSA-jxx6-3r86-qh2g/GHSA-jxx6-3r86-qh2g.json @@ -7,12 +7,8 @@ "CVE-2008-0946" ], "details": "Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2pj-fhfv-4fq7/GHSA-m2pj-fhfv-4fq7.json b/advisories/unreviewed/2022/05/GHSA-m2pj-fhfv-4fq7/GHSA-m2pj-fhfv-4fq7.json index f998763e97e..40f37d092b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2pj-fhfv-4fq7/GHSA-m2pj-fhfv-4fq7.json +++ b/advisories/unreviewed/2022/05/GHSA-m2pj-fhfv-4fq7/GHSA-m2pj-fhfv-4fq7.json @@ -7,12 +7,8 @@ "CVE-2008-0927" ], "details": "dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values. NOTE: this might be similar to CVE-2008-1777.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m36h-rqxp-vqf7/GHSA-m36h-rqxp-vqf7.json b/advisories/unreviewed/2022/05/GHSA-m36h-rqxp-vqf7/GHSA-m36h-rqxp-vqf7.json index 5b3ddbaa78f..3395b9298d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-m36h-rqxp-vqf7/GHSA-m36h-rqxp-vqf7.json +++ b/advisories/unreviewed/2022/05/GHSA-m36h-rqxp-vqf7/GHSA-m36h-rqxp-vqf7.json @@ -7,12 +7,8 @@ "CVE-2008-0720" ], "details": "Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary web script or HTML via the search parameter to webmin_search.cgi (aka the search section), and possibly other components accessed through a \"search box\" or \"open file box.\" NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m434-vxwp-c3vg/GHSA-m434-vxwp-c3vg.json b/advisories/unreviewed/2022/05/GHSA-m434-vxwp-c3vg/GHSA-m434-vxwp-c3vg.json index 39abf92b71f..c21c8490118 100644 --- a/advisories/unreviewed/2022/05/GHSA-m434-vxwp-c3vg/GHSA-m434-vxwp-c3vg.json +++ b/advisories/unreviewed/2022/05/GHSA-m434-vxwp-c3vg/GHSA-m434-vxwp-c3vg.json @@ -7,12 +7,8 @@ "CVE-2008-0702" ], "details": "Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang) and possibly execute arbitrary code via a long argument to the (1) USER or (2) PASS command, different vectors than CVE-2004-1641.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m47r-rrx6-887p/GHSA-m47r-rrx6-887p.json b/advisories/unreviewed/2022/05/GHSA-m47r-rrx6-887p/GHSA-m47r-rrx6-887p.json index 03eaa8e7a95..23b11e7bf3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m47r-rrx6-887p/GHSA-m47r-rrx6-887p.json +++ b/advisories/unreviewed/2022/05/GHSA-m47r-rrx6-887p/GHSA-m47r-rrx6-887p.json @@ -7,12 +7,8 @@ "CVE-2008-0493" ], "details": "fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m4cq-28fp-6xmq/GHSA-m4cq-28fp-6xmq.json b/advisories/unreviewed/2022/05/GHSA-m4cq-28fp-6xmq/GHSA-m4cq-28fp-6xmq.json index 984e8d29e53..9488dd6ab5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4cq-28fp-6xmq/GHSA-m4cq-28fp-6xmq.json +++ b/advisories/unreviewed/2022/05/GHSA-m4cq-28fp-6xmq/GHSA-m4cq-28fp-6xmq.json @@ -7,12 +7,8 @@ "CVE-2008-0778" ], "details": "Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor, (2) SetHREF, (3) SetMovieName, (4) SetTarget, and (5) SetMatrix methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5jg-7x2h-hv4g/GHSA-m5jg-7x2h-hv4g.json b/advisories/unreviewed/2022/05/GHSA-m5jg-7x2h-hv4g/GHSA-m5jg-7x2h-hv4g.json index 9abce125bd6..0dc75286906 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5jg-7x2h-hv4g/GHSA-m5jg-7x2h-hv4g.json +++ b/advisories/unreviewed/2022/05/GHSA-m5jg-7x2h-hv4g/GHSA-m5jg-7x2h-hv4g.json @@ -7,12 +7,8 @@ "CVE-2008-0730" ], "details": "The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a) .iiim/le and (b) .Xlocale in home directories, which might allow local users to write to, or read from, the home directories of other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m5jv-88vc-r8cm/GHSA-m5jv-88vc-r8cm.json b/advisories/unreviewed/2022/05/GHSA-m5jv-88vc-r8cm/GHSA-m5jv-88vc-r8cm.json index ebd06febd25..9eb4c41c5f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5jv-88vc-r8cm/GHSA-m5jv-88vc-r8cm.json +++ b/advisories/unreviewed/2022/05/GHSA-m5jv-88vc-r8cm/GHSA-m5jv-88vc-r8cm.json @@ -7,12 +7,8 @@ "CVE-2008-0902" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. NOTE: this might be the same issue as CVE-2007-2694.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m66p-wxmq-pfc5/GHSA-m66p-wxmq-pfc5.json b/advisories/unreviewed/2022/05/GHSA-m66p-wxmq-pfc5/GHSA-m66p-wxmq-pfc5.json index a85de09723d..96dd3aa4d8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m66p-wxmq-pfc5/GHSA-m66p-wxmq-pfc5.json +++ b/advisories/unreviewed/2022/05/GHSA-m66p-wxmq-pfc5/GHSA-m66p-wxmq-pfc5.json @@ -7,12 +7,8 @@ "CVE-2008-0962" ], "details": "Stack-based buffer overflow in the File System Manager for EMC DiskXtender 6.20.060 allows remote authenticated users to execute arbitrary code via a crafted request to the RPC interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m73q-7r8g-9q4m/GHSA-m73q-7r8g-9q4m.json b/advisories/unreviewed/2022/05/GHSA-m73q-7r8g-9q4m/GHSA-m73q-7r8g-9q4m.json index edc4aee85af..221273e8669 100644 --- a/advisories/unreviewed/2022/05/GHSA-m73q-7r8g-9q4m/GHSA-m73q-7r8g-9q4m.json +++ b/advisories/unreviewed/2022/05/GHSA-m73q-7r8g-9q4m/GHSA-m73q-7r8g-9q4m.json @@ -7,12 +7,8 @@ "CVE-2008-0917" ], "details": "Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m7f6-rhxq-9pjx/GHSA-m7f6-rhxq-9pjx.json b/advisories/unreviewed/2022/05/GHSA-m7f6-rhxq-9pjx/GHSA-m7f6-rhxq-9pjx.json index 69aef9888da..00f4d43c850 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7f6-rhxq-9pjx/GHSA-m7f6-rhxq-9pjx.json +++ b/advisories/unreviewed/2022/05/GHSA-m7f6-rhxq-9pjx/GHSA-m7f6-rhxq-9pjx.json @@ -7,12 +7,8 @@ "CVE-2008-0459" ], "details": "Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the update parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m84x-fjr3-244q/GHSA-m84x-fjr3-244q.json b/advisories/unreviewed/2022/05/GHSA-m84x-fjr3-244q/GHSA-m84x-fjr3-244q.json index 7ec6c51a67b..f5d76f14029 100644 --- a/advisories/unreviewed/2022/05/GHSA-m84x-fjr3-244q/GHSA-m84x-fjr3-244q.json +++ b/advisories/unreviewed/2022/05/GHSA-m84x-fjr3-244q/GHSA-m84x-fjr3-244q.json @@ -7,12 +7,8 @@ "CVE-2008-0866" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Workshop allow remote attackers to inject arbitrary web script or HTML via an invalid action URI, which is not properly handled by NetUI page flows.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m89j-25jw-r9vq/GHSA-m89j-25jw-r9vq.json b/advisories/unreviewed/2022/05/GHSA-m89j-25jw-r9vq/GHSA-m89j-25jw-r9vq.json index e9dda474e67..3a22aeb2662 100644 --- a/advisories/unreviewed/2022/05/GHSA-m89j-25jw-r9vq/GHSA-m89j-25jw-r9vq.json +++ b/advisories/unreviewed/2022/05/GHSA-m89j-25jw-r9vq/GHSA-m89j-25jw-r9vq.json @@ -7,12 +7,8 @@ "CVE-2008-0734" ], "details": "SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the cuid cookie parameter to admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m8c8-vwp2-gj7m/GHSA-m8c8-vwp2-gj7m.json b/advisories/unreviewed/2022/05/GHSA-m8c8-vwp2-gj7m/GHSA-m8c8-vwp2-gj7m.json index a990b8b11ef..37c1918bc35 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8c8-vwp2-gj7m/GHSA-m8c8-vwp2-gj7m.json +++ b/advisories/unreviewed/2022/05/GHSA-m8c8-vwp2-gj7m/GHSA-m8c8-vwp2-gj7m.json @@ -7,12 +7,8 @@ "CVE-2008-0910" ], "details": "Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive. NOTE: this might be related to CVE-2008-0792.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m959-8wfp-9m54/GHSA-m959-8wfp-9m54.json b/advisories/unreviewed/2022/05/GHSA-m959-8wfp-9m54/GHSA-m959-8wfp-9m54.json index c5a49002b1b..76a1d6c9d03 100644 --- a/advisories/unreviewed/2022/05/GHSA-m959-8wfp-9m54/GHSA-m959-8wfp-9m54.json +++ b/advisories/unreviewed/2022/05/GHSA-m959-8wfp-9m54/GHSA-m959-8wfp-9m54.json @@ -7,12 +7,8 @@ "CVE-2008-0895" ], "details": "BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m96x-25r6-m4w8/GHSA-m96x-25r6-m4w8.json b/advisories/unreviewed/2022/05/GHSA-m96x-25r6-m4w8/GHSA-m96x-25r6-m4w8.json index b1c5c2012c1..335d3e02e7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m96x-25r6-m4w8/GHSA-m96x-25r6-m4w8.json +++ b/advisories/unreviewed/2022/05/GHSA-m96x-25r6-m4w8/GHSA-m96x-25r6-m4w8.json @@ -7,12 +7,8 @@ "CVE-2008-0779" ], "details": "The fortimon.sys device driver in Fortinet FortiClient Host Security 3.0 MR5 Patch 3 and earlier does not properly initialize its DeviceExtension, which allows local users to access kernel memory and execute arbitrary code via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mfcx-9c6j-j87r/GHSA-mfcx-9c6j-j87r.json b/advisories/unreviewed/2022/05/GHSA-mfcx-9c6j-j87r/GHSA-mfcx-9c6j-j87r.json index cbb0e313fee..90b98adbb11 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfcx-9c6j-j87r/GHSA-mfcx-9c6j-j87r.json +++ b/advisories/unreviewed/2022/05/GHSA-mfcx-9c6j-j87r/GHSA-mfcx-9c6j-j87r.json @@ -7,12 +7,8 @@ "CVE-2008-0873" ], "details": "SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in an Adsview action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg9c-8x79-2vxj/GHSA-mg9c-8x79-2vxj.json b/advisories/unreviewed/2022/05/GHSA-mg9c-8x79-2vxj/GHSA-mg9c-8x79-2vxj.json index 242d6114a4e..4253bfa2de8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg9c-8x79-2vxj/GHSA-mg9c-8x79-2vxj.json +++ b/advisories/unreviewed/2022/05/GHSA-mg9c-8x79-2vxj/GHSA-mg9c-8x79-2vxj.json @@ -7,12 +7,8 @@ "CVE-2008-0511" ], "details": "SQL injection vulnerability in index.php in the MaMML (com_mamml) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mh5w-r55j-6jjp/GHSA-mh5w-r55j-6jjp.json b/advisories/unreviewed/2022/05/GHSA-mh5w-r55j-6jjp/GHSA-mh5w-r55j-6jjp.json index 2f9063496e4..ec7fd89fbd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mh5w-r55j-6jjp/GHSA-mh5w-r55j-6jjp.json +++ b/advisories/unreviewed/2022/05/GHSA-mh5w-r55j-6jjp/GHSA-mh5w-r55j-6jjp.json @@ -7,12 +7,8 @@ "CVE-2008-0431" ], "details": "Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mp4r-cjg4-3v3m/GHSA-mp4r-cjg4-3v3m.json b/advisories/unreviewed/2022/05/GHSA-mp4r-cjg4-3v3m/GHSA-mp4r-cjg4-3v3m.json index 3e7c4bf14c8..ecad434cd9d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp4r-cjg4-3v3m/GHSA-mp4r-cjg4-3v3m.json +++ b/advisories/unreviewed/2022/05/GHSA-mp4r-cjg4-3v3m/GHSA-mp4r-cjg4-3v3m.json @@ -7,12 +7,8 @@ "CVE-2008-0767" ], "details": "ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain \"number of URLs\" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large integer in this field in a packet to the Service Location Protocol (SLP) service on UDP port 427, triggering an out-of-bounds read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mqjc-r7wr-hmvh/GHSA-mqjc-r7wr-hmvh.json b/advisories/unreviewed/2022/05/GHSA-mqjc-r7wr-hmvh/GHSA-mqjc-r7wr-hmvh.json index 94723759b32..b1df3df6449 100644 --- a/advisories/unreviewed/2022/05/GHSA-mqjc-r7wr-hmvh/GHSA-mqjc-r7wr-hmvh.json +++ b/advisories/unreviewed/2022/05/GHSA-mqjc-r7wr-hmvh/GHSA-mqjc-r7wr-hmvh.json @@ -7,12 +7,8 @@ "CVE-2008-0982" ], "details": "Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to obtain sensitive information via a direct request for spyce/examples/automaton.spy, which reveals the path in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrcv-rq92-q2cm/GHSA-mrcv-rq92-q2cm.json b/advisories/unreviewed/2022/05/GHSA-mrcv-rq92-q2cm/GHSA-mrcv-rq92-q2cm.json index 38402346dc0..90c65e089d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrcv-rq92-q2cm/GHSA-mrcv-rq92-q2cm.json +++ b/advisories/unreviewed/2022/05/GHSA-mrcv-rq92-q2cm/GHSA-mrcv-rq92-q2cm.json @@ -7,12 +7,8 @@ "CVE-2008-0489" ], "details": "Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mrwx-j9cq-447w/GHSA-mrwx-j9cq-447w.json b/advisories/unreviewed/2022/05/GHSA-mrwx-j9cq-447w/GHSA-mrwx-j9cq-447w.json index 6f329fb0212..64a2144f5d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrwx-j9cq-447w/GHSA-mrwx-j9cq-447w.json +++ b/advisories/unreviewed/2022/05/GHSA-mrwx-j9cq-447w/GHSA-mrwx-j9cq-447w.json @@ -7,12 +7,8 @@ "CVE-2008-0678" ], "details": "SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a page action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx7q-m4p3-672f/GHSA-mx7q-m4p3-672f.json b/advisories/unreviewed/2022/05/GHSA-mx7q-m4p3-672f/GHSA-mx7q-m4p3-672f.json index bdd9348f6d7..c5d06781786 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx7q-m4p3-672f/GHSA-mx7q-m4p3-672f.json +++ b/advisories/unreviewed/2022/05/GHSA-mx7q-m4p3-672f/GHSA-mx7q-m4p3-672f.json @@ -7,12 +7,8 @@ "CVE-2008-0413" ], "details": "The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via (1) a large switch statement, (2) certain uses of watch and eval, (3) certain uses of the mousedown event listener, and other vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -272,9 +268,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p33m-8v52-j9v7/GHSA-p33m-8v52-j9v7.json b/advisories/unreviewed/2022/05/GHSA-p33m-8v52-j9v7/GHSA-p33m-8v52-j9v7.json index a679b6087a9..c8a94ccd399 100644 --- a/advisories/unreviewed/2022/05/GHSA-p33m-8v52-j9v7/GHSA-p33m-8v52-j9v7.json +++ b/advisories/unreviewed/2022/05/GHSA-p33m-8v52-j9v7/GHSA-p33m-8v52-j9v7.json @@ -7,12 +7,8 @@ "CVE-2008-0912" ], "details": "Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long (1) username, (2) version, or (3) remote ID. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p383-332q-77v5/GHSA-p383-332q-77v5.json b/advisories/unreviewed/2022/05/GHSA-p383-332q-77v5/GHSA-p383-332q-77v5.json index 62779b53a2b..5b70b572366 100644 --- a/advisories/unreviewed/2022/05/GHSA-p383-332q-77v5/GHSA-p383-332q-77v5.json +++ b/advisories/unreviewed/2022/05/GHSA-p383-332q-77v5/GHSA-p383-332q-77v5.json @@ -7,12 +7,8 @@ "CVE-2008-0444" ], "details": "Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p548-ppqg-c57m/GHSA-p548-ppqg-c57m.json b/advisories/unreviewed/2022/05/GHSA-p548-ppqg-c57m/GHSA-p548-ppqg-c57m.json index 7a1b129292a..6ffe7aa01bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-p548-ppqg-c57m/GHSA-p548-ppqg-c57m.json +++ b/advisories/unreviewed/2022/05/GHSA-p548-ppqg-c57m/GHSA-p548-ppqg-c57m.json @@ -7,12 +7,8 @@ "CVE-2008-0958" ], "details": "Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioGrabber2 ActiveX control in NCTAudioGrabber2.dll allow remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p655-2748-w2pm/GHSA-p655-2748-w2pm.json b/advisories/unreviewed/2022/05/GHSA-p655-2748-w2pm/GHSA-p655-2748-w2pm.json index d0609e3a475..11b5c2c9664 100644 --- a/advisories/unreviewed/2022/05/GHSA-p655-2748-w2pm/GHSA-p655-2748-w2pm.json +++ b/advisories/unreviewed/2022/05/GHSA-p655-2748-w2pm/GHSA-p655-2748-w2pm.json @@ -7,12 +7,8 @@ "CVE-2008-0582" ], "details": "Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business item entry, accessible through (1) the SkypeFind dialog and (2) a skype:?skypefind URI for the skype: URI handler.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p67x-7ghg-3ccf/GHSA-p67x-7ghg-3ccf.json b/advisories/unreviewed/2022/05/GHSA-p67x-7ghg-3ccf/GHSA-p67x-7ghg-3ccf.json index 69732672b66..69aec549f82 100644 --- a/advisories/unreviewed/2022/05/GHSA-p67x-7ghg-3ccf/GHSA-p67x-7ghg-3ccf.json +++ b/advisories/unreviewed/2022/05/GHSA-p67x-7ghg-3ccf/GHSA-p67x-7ghg-3ccf.json @@ -7,12 +7,8 @@ "CVE-2008-0468" ], "details": "SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p6vv-g4h2-2ffv/GHSA-p6vv-g4h2-2ffv.json b/advisories/unreviewed/2022/05/GHSA-p6vv-g4h2-2ffv/GHSA-p6vv-g4h2-2ffv.json index a8e1b6cf44b..5d228546e5b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6vv-g4h2-2ffv/GHSA-p6vv-g4h2-2ffv.json +++ b/advisories/unreviewed/2022/05/GHSA-p6vv-g4h2-2ffv/GHSA-p6vv-g4h2-2ffv.json @@ -7,12 +7,8 @@ "CVE-2019-2164" ], "details": "In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113263695", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6w6-87q3-jc2h/GHSA-p6w6-87q3-jc2h.json b/advisories/unreviewed/2022/05/GHSA-p6w6-87q3-jc2h/GHSA-p6w6-87q3-jc2h.json index 8fc66dc023e..bce90d56f10 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6w6-87q3-jc2h/GHSA-p6w6-87q3-jc2h.json +++ b/advisories/unreviewed/2022/05/GHSA-p6w6-87q3-jc2h/GHSA-p6w6-87q3-jc2h.json @@ -7,12 +7,8 @@ "CVE-2008-0470" ], "details": "A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p783-rmxx-48w3/GHSA-p783-rmxx-48w3.json b/advisories/unreviewed/2022/05/GHSA-p783-rmxx-48w3/GHSA-p783-rmxx-48w3.json index af3e1d43699..87878c571f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p783-rmxx-48w3/GHSA-p783-rmxx-48w3.json +++ b/advisories/unreviewed/2022/05/GHSA-p783-rmxx-48w3/GHSA-p783-rmxx-48w3.json @@ -7,12 +7,8 @@ "CVE-2008-0806" ], "details": "wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7hr-mpcp-r568/GHSA-p7hr-mpcp-r568.json b/advisories/unreviewed/2022/05/GHSA-p7hr-mpcp-r568/GHSA-p7hr-mpcp-r568.json index 6eadc7e2ab8..139fd5b6797 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7hr-mpcp-r568/GHSA-p7hr-mpcp-r568.json +++ b/advisories/unreviewed/2022/05/GHSA-p7hr-mpcp-r568/GHSA-p7hr-mpcp-r568.json @@ -7,12 +7,8 @@ "CVE-2008-0812" ], "details": "Directory traversal vulnerability in DMS/index.php in BanPro DMS 1.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the action parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7q3-5c52-xg2j/GHSA-p7q3-5c52-xg2j.json b/advisories/unreviewed/2022/05/GHSA-p7q3-5c52-xg2j/GHSA-p7q3-5c52-xg2j.json index 2682a294c73..8ec0cbd3c41 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7q3-5c52-xg2j/GHSA-p7q3-5c52-xg2j.json +++ b/advisories/unreviewed/2022/05/GHSA-p7q3-5c52-xg2j/GHSA-p7q3-5c52-xg2j.json @@ -7,12 +7,8 @@ "CVE-2008-0539" ], "details": "Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script or HTML via the report_type parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7qf-46x2-8wwx/GHSA-p7qf-46x2-8wwx.json b/advisories/unreviewed/2022/05/GHSA-p7qf-46x2-8wwx/GHSA-p7qf-46x2-8wwx.json index c9380b3e3fe..de500db226c 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7qf-46x2-8wwx/GHSA-p7qf-46x2-8wwx.json +++ b/advisories/unreviewed/2022/05/GHSA-p7qf-46x2-8wwx/GHSA-p7qf-46x2-8wwx.json @@ -7,12 +7,8 @@ "CVE-2008-0620" ], "details": "SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LPD command, which causes the server to terminate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p9mv-qv93-c9ph/GHSA-p9mv-qv93-c9ph.json b/advisories/unreviewed/2022/05/GHSA-p9mv-qv93-c9ph/GHSA-p9mv-qv93-c9ph.json index 35865ad5e64..f69396e652a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9mv-qv93-c9ph/GHSA-p9mv-qv93-c9ph.json +++ b/advisories/unreviewed/2022/05/GHSA-p9mv-qv93-c9ph/GHSA-p9mv-qv93-c9ph.json @@ -7,12 +7,8 @@ "CVE-2008-0689" ], "details": "SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_category action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc3p-r5pr-cv9v/GHSA-pc3p-r5pr-cv9v.json b/advisories/unreviewed/2022/05/GHSA-pc3p-r5pr-cv9v/GHSA-pc3p-r5pr-cv9v.json index 030709d4bd2..e8286968d99 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc3p-r5pr-cv9v/GHSA-pc3p-r5pr-cv9v.json +++ b/advisories/unreviewed/2022/05/GHSA-pc3p-r5pr-cv9v/GHSA-pc3p-r5pr-cv9v.json @@ -7,12 +7,8 @@ "CVE-2008-0563" ], "details": "Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to perform unspecified actions as unspecified authenticated users via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pcwr-hp9j-hrg6/GHSA-pcwr-hp9j-hrg6.json b/advisories/unreviewed/2022/05/GHSA-pcwr-hp9j-hrg6/GHSA-pcwr-hp9j-hrg6.json index 6739040a1f5..eee4cde98eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pcwr-hp9j-hrg6/GHSA-pcwr-hp9j-hrg6.json +++ b/advisories/unreviewed/2022/05/GHSA-pcwr-hp9j-hrg6/GHSA-pcwr-hp9j-hrg6.json @@ -7,12 +7,8 @@ "CVE-2008-0488" ], "details": "Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the location parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pggf-4mfg-vr7g/GHSA-pggf-4mfg-vr7g.json b/advisories/unreviewed/2022/05/GHSA-pggf-4mfg-vr7g/GHSA-pggf-4mfg-vr7g.json index 7e3e1e4014c..fd746c6290e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pggf-4mfg-vr7g/GHSA-pggf-4mfg-vr7g.json +++ b/advisories/unreviewed/2022/05/GHSA-pggf-4mfg-vr7g/GHSA-pggf-4mfg-vr7g.json @@ -7,12 +7,8 @@ "CVE-2008-0408" ], "details": "HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgm5-2qgh-cvjr/GHSA-pgm5-2qgh-cvjr.json b/advisories/unreviewed/2022/05/GHSA-pgm5-2qgh-cvjr/GHSA-pgm5-2qgh-cvjr.json index 213c2d76109..9344256e7a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgm5-2qgh-cvjr/GHSA-pgm5-2qgh-cvjr.json +++ b/advisories/unreviewed/2022/05/GHSA-pgm5-2qgh-cvjr/GHSA-pgm5-2qgh-cvjr.json @@ -7,12 +7,8 @@ "CVE-2008-0924" ], "details": "Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a long Distinguished Name (DN) field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phfp-fpw5-wg8h/GHSA-phfp-fpw5-wg8h.json b/advisories/unreviewed/2022/05/GHSA-phfp-fpw5-wg8h/GHSA-phfp-fpw5-wg8h.json index a19cd236394..d098ffa10b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-phfp-fpw5-wg8h/GHSA-phfp-fpw5-wg8h.json +++ b/advisories/unreviewed/2022/05/GHSA-phfp-fpw5-wg8h/GHSA-phfp-fpw5-wg8h.json @@ -7,12 +7,8 @@ "CVE-2008-0751" ], "details": "Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj5v-m793-hc98/GHSA-pj5v-m793-hc98.json b/advisories/unreviewed/2022/05/GHSA-pj5v-m793-hc98/GHSA-pj5v-m793-hc98.json index d56e758cd4e..fd4c942b9bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj5v-m793-hc98/GHSA-pj5v-m793-hc98.json +++ b/advisories/unreviewed/2022/05/GHSA-pj5v-m793-hc98/GHSA-pj5v-m793-hc98.json @@ -7,12 +7,8 @@ "CVE-2008-0818" ], "details": "Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie to (1) comment.php, (2) index.php, and (3) show.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pj65-cvc7-46r9/GHSA-pj65-cvc7-46r9.json b/advisories/unreviewed/2022/05/GHSA-pj65-cvc7-46r9/GHSA-pj65-cvc7-46r9.json index 38ac1aeab48..97af54692e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj65-cvc7-46r9/GHSA-pj65-cvc7-46r9.json +++ b/advisories/unreviewed/2022/05/GHSA-pj65-cvc7-46r9/GHSA-pj65-cvc7-46r9.json @@ -7,12 +7,8 @@ "CVE-2008-0890" ], "details": "Red Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which allows local users to modify JAR files and execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pmw8-r2qf-v9wm/GHSA-pmw8-r2qf-v9wm.json b/advisories/unreviewed/2022/05/GHSA-pmw8-r2qf-v9wm/GHSA-pmw8-r2qf-v9wm.json index c5444e464bb..51603e5b068 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmw8-r2qf-v9wm/GHSA-pmw8-r2qf-v9wm.json +++ b/advisories/unreviewed/2022/05/GHSA-pmw8-r2qf-v9wm/GHSA-pmw8-r2qf-v9wm.json @@ -7,12 +7,8 @@ "CVE-2008-0859" ], "details": "Unspecified vulnerability in Kerio MailServer before 6.5.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to decoding of uuencoded input, which triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pp63-678x-h74w/GHSA-pp63-678x-h74w.json b/advisories/unreviewed/2022/05/GHSA-pp63-678x-h74w/GHSA-pp63-678x-h74w.json index fc92c779cd8..aaa8e3f449c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp63-678x-h74w/GHSA-pp63-678x-h74w.json +++ b/advisories/unreviewed/2022/05/GHSA-pp63-678x-h74w/GHSA-pp63-678x-h74w.json @@ -7,12 +7,8 @@ "CVE-2008-0863" ], "details": "BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain sensitive information and potentially launch further attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pp7w-4928-w3cj/GHSA-pp7w-4928-w3cj.json b/advisories/unreviewed/2022/05/GHSA-pp7w-4928-w3cj/GHSA-pp7w-4928-w3cj.json index 367e538fc9f..2bf5ac6bb20 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp7w-4928-w3cj/GHSA-pp7w-4928-w3cj.json +++ b/advisories/unreviewed/2022/05/GHSA-pp7w-4928-w3cj/GHSA-pp7w-4928-w3cj.json @@ -7,12 +7,8 @@ "CVE-2008-0451" ], "details": "Multiple SQL injection vulnerabilities in PacerCMS 0.6 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) siteadmin/article-edit.php; and unspecified parameters to (2) submitted-edit.php, (3) page-edit.php, (4) section-edit.php, (5) staff-edit.php, and (6) staff-access.php in siteadmin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pp96-r3vp-w36g/GHSA-pp96-r3vp-w36g.json b/advisories/unreviewed/2022/05/GHSA-pp96-r3vp-w36g/GHSA-pp96-r3vp-w36g.json index 66f8dda291c..f314279b067 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp96-r3vp-w36g/GHSA-pp96-r3vp-w36g.json +++ b/advisories/unreviewed/2022/05/GHSA-pp96-r3vp-w36g/GHSA-pp96-r3vp-w36g.json @@ -7,12 +7,8 @@ "CVE-2008-0507" ], "details": "SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pq3p-2788-w982/GHSA-pq3p-2788-w982.json b/advisories/unreviewed/2022/05/GHSA-pq3p-2788-w982/GHSA-pq3p-2788-w982.json index 8a0107b705f..9a34c7a732c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pq3p-2788-w982/GHSA-pq3p-2788-w982.json +++ b/advisories/unreviewed/2022/05/GHSA-pq3p-2788-w982/GHSA-pq3p-2788-w982.json @@ -7,12 +7,8 @@ "CVE-2008-0901" ], "details": "BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqfc-759q-j9jg/GHSA-pqfc-759q-j9jg.json b/advisories/unreviewed/2022/05/GHSA-pqfc-759q-j9jg/GHSA-pqfc-759q-j9jg.json index 23e99fbace4..d28dd95e631 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqfc-759q-j9jg/GHSA-pqfc-759q-j9jg.json +++ b/advisories/unreviewed/2022/05/GHSA-pqfc-759q-j9jg/GHSA-pqfc-759q-j9jg.json @@ -7,12 +7,8 @@ "CVE-2008-0390" ], "details": "stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat action to index.php, and execute online.db.txt via a certain request to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr4m-5jxx-mx4j/GHSA-pr4m-5jxx-mx4j.json b/advisories/unreviewed/2022/05/GHSA-pr4m-5jxx-mx4j/GHSA-pr4m-5jxx-mx4j.json index ad5acd58aa9..d9023c2446b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr4m-5jxx-mx4j/GHSA-pr4m-5jxx-mx4j.json +++ b/advisories/unreviewed/2022/05/GHSA-pr4m-5jxx-mx4j/GHSA-pr4m-5jxx-mx4j.json @@ -7,12 +7,8 @@ "CVE-2008-0398" ], "details": "Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pr6g-954v-x2pf/GHSA-pr6g-954v-x2pf.json b/advisories/unreviewed/2022/05/GHSA-pr6g-954v-x2pf/GHSA-pr6g-954v-x2pf.json index d7c0c078099..f3a8063eea5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pr6g-954v-x2pf/GHSA-pr6g-954v-x2pf.json +++ b/advisories/unreviewed/2022/05/GHSA-pr6g-954v-x2pf/GHSA-pr6g-954v-x2pf.json @@ -7,12 +7,8 @@ "CVE-2008-0592" ], "details": "Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a \"Content-Disposition: attachment\" and an invalid \"Content-Type: plain/text,\" which prevents Firefox from rendering future plain text files within the browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -196,9 +192,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prh3-4qp6-8m82/GHSA-prh3-4qp6-8m82.json b/advisories/unreviewed/2022/05/GHSA-prh3-4qp6-8m82/GHSA-prh3-4qp6-8m82.json index b70518249c1..ff1dc8b892e 100644 --- a/advisories/unreviewed/2022/05/GHSA-prh3-4qp6-8m82/GHSA-prh3-4qp6-8m82.json +++ b/advisories/unreviewed/2022/05/GHSA-prh3-4qp6-8m82/GHSA-prh3-4qp6-8m82.json @@ -7,12 +7,8 @@ "CVE-2019-1418" ], "details": "An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pvwj-ph3c-w4q5/GHSA-pvwj-ph3c-w4q5.json b/advisories/unreviewed/2022/05/GHSA-pvwj-ph3c-w4q5/GHSA-pvwj-ph3c-w4q5.json index 1b3222835e1..83a4ae31d36 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvwj-ph3c-w4q5/GHSA-pvwj-ph3c-w4q5.json +++ b/advisories/unreviewed/2022/05/GHSA-pvwj-ph3c-w4q5/GHSA-pvwj-ph3c-w4q5.json @@ -7,12 +7,8 @@ "CVE-2008-0509" ], "details": "Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c; or (2) piox25remote, related to piox25remote.sh.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxvv-6vfr-38vx/GHSA-pxvv-6vfr-38vx.json b/advisories/unreviewed/2022/05/GHSA-pxvv-6vfr-38vx/GHSA-pxvv-6vfr-38vx.json index 2e39ef82630..986e3cd2207 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxvv-6vfr-38vx/GHSA-pxvv-6vfr-38vx.json +++ b/advisories/unreviewed/2022/05/GHSA-pxvv-6vfr-38vx/GHSA-pxvv-6vfr-38vx.json @@ -7,12 +7,8 @@ "CVE-2008-0723" ], "details": "Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxw5-2h3g-44r8/GHSA-pxw5-2h3g-44r8.json b/advisories/unreviewed/2022/05/GHSA-pxw5-2h3g-44r8/GHSA-pxw5-2h3g-44r8.json index e77b0c0ab9d..dd2190318ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxw5-2h3g-44r8/GHSA-pxw5-2h3g-44r8.json +++ b/advisories/unreviewed/2022/05/GHSA-pxw5-2h3g-44r8/GHSA-pxw5-2h3g-44r8.json @@ -7,12 +7,8 @@ "CVE-2008-0743" ], "details": "PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the hlp parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q223-jqf3-hfg8/GHSA-q223-jqf3-hfg8.json b/advisories/unreviewed/2022/05/GHSA-q223-jqf3-hfg8/GHSA-q223-jqf3-hfg8.json index 77b714ce281..30d6d94c1ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-q223-jqf3-hfg8/GHSA-q223-jqf3-hfg8.json +++ b/advisories/unreviewed/2022/05/GHSA-q223-jqf3-hfg8/GHSA-q223-jqf3-hfg8.json @@ -7,12 +7,8 @@ "CVE-2008-0491" ], "details": "SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the album parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q23r-3633-4mr5/GHSA-q23r-3633-4mr5.json b/advisories/unreviewed/2022/05/GHSA-q23r-3633-4mr5/GHSA-q23r-3633-4mr5.json index 12042acdc49..35b81d0b2be 100644 --- a/advisories/unreviewed/2022/05/GHSA-q23r-3633-4mr5/GHSA-q23r-3633-4mr5.json +++ b/advisories/unreviewed/2022/05/GHSA-q23r-3633-4mr5/GHSA-q23r-3633-4mr5.json @@ -7,12 +7,8 @@ "CVE-2008-0906" ], "details": "SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q255-j47v-gc2r/GHSA-q255-j47v-gc2r.json b/advisories/unreviewed/2022/05/GHSA-q255-j47v-gc2r/GHSA-q255-j47v-gc2r.json index f52bd8c0ee8..c670c924105 100644 --- a/advisories/unreviewed/2022/05/GHSA-q255-j47v-gc2r/GHSA-q255-j47v-gc2r.json +++ b/advisories/unreviewed/2022/05/GHSA-q255-j47v-gc2r/GHSA-q255-j47v-gc2r.json @@ -7,12 +7,8 @@ "CVE-2008-0784" ], "details": "graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q27c-cfcq-96m5/GHSA-q27c-cfcq-96m5.json b/advisories/unreviewed/2022/05/GHSA-q27c-cfcq-96m5/GHSA-q27c-cfcq-96m5.json index 158a65af029..3a5ca8136c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-q27c-cfcq-96m5/GHSA-q27c-cfcq-96m5.json +++ b/advisories/unreviewed/2022/05/GHSA-q27c-cfcq-96m5/GHSA-q27c-cfcq-96m5.json @@ -7,12 +7,8 @@ "CVE-2008-0486" ], "details": "Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -152,9 +148,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q2wj-hqvv-9cm2/GHSA-q2wj-hqvv-9cm2.json b/advisories/unreviewed/2022/05/GHSA-q2wj-hqvv-9cm2/GHSA-q2wj-hqvv-9cm2.json index 1d8bfb7a53f..53e39f9b62d 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2wj-hqvv-9cm2/GHSA-q2wj-hqvv-9cm2.json +++ b/advisories/unreviewed/2022/05/GHSA-q2wj-hqvv-9cm2/GHSA-q2wj-hqvv-9cm2.json @@ -7,12 +7,8 @@ "CVE-2008-0760" ], "details": "Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\\ (dot dot backslash) in the URI. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q336-pvf2-2f5v/GHSA-q336-pvf2-2f5v.json b/advisories/unreviewed/2022/05/GHSA-q336-pvf2-2f5v/GHSA-q336-pvf2-2f5v.json index 27313f99f30..c07764addb5 100644 --- a/advisories/unreviewed/2022/05/GHSA-q336-pvf2-2f5v/GHSA-q336-pvf2-2f5v.json +++ b/advisories/unreviewed/2022/05/GHSA-q336-pvf2-2f5v/GHSA-q336-pvf2-2f5v.json @@ -7,12 +7,8 @@ "CVE-2008-0876" ], "details": "Unspecified vulnerability in the SEWB3 messaging service in Hitachi SEWB3/PLATFORM and SEWB3/MI-PLATFORM 01-00 through 02-14-/A allows remote attackers to cause a denial of service (service outage) via \"invalid data.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q38m-xc4p-rmp5/GHSA-q38m-xc4p-rmp5.json b/advisories/unreviewed/2022/05/GHSA-q38m-xc4p-rmp5/GHSA-q38m-xc4p-rmp5.json index 74200d4d79e..65f5695f1f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-q38m-xc4p-rmp5/GHSA-q38m-xc4p-rmp5.json +++ b/advisories/unreviewed/2022/05/GHSA-q38m-xc4p-rmp5/GHSA-q38m-xc4p-rmp5.json @@ -7,12 +7,8 @@ "CVE-2008-0942" ], "details": "SQL injection vulnerability in GradebookStuScores.asp in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote attackers to execute arbitrary SQL commands via the GrdBk parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3qj-hhm6-3g3m/GHSA-q3qj-hhm6-3g3m.json b/advisories/unreviewed/2022/05/GHSA-q3qj-hhm6-3g3m/GHSA-q3qj-hhm6-3g3m.json index f4cd35df51d..7c28db67d6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3qj-hhm6-3g3m/GHSA-q3qj-hhm6-3g3m.json +++ b/advisories/unreviewed/2022/05/GHSA-q3qj-hhm6-3g3m/GHSA-q3qj-hhm6-3g3m.json @@ -7,12 +7,8 @@ "CVE-2008-0554" ], "details": "Buffer overflow in the readImageData function in giftopnm.c in netpbm before 10.27 in netpbm before 10.27 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q3v9-vqch-gc4g/GHSA-q3v9-vqch-gc4g.json b/advisories/unreviewed/2022/05/GHSA-q3v9-vqch-gc4g/GHSA-q3v9-vqch-gc4g.json index 2dd5eec74b8..845079a679b 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3v9-vqch-gc4g/GHSA-q3v9-vqch-gc4g.json +++ b/advisories/unreviewed/2022/05/GHSA-q3v9-vqch-gc4g/GHSA-q3v9-vqch-gc4g.json @@ -7,12 +7,8 @@ "CVE-2008-0460" ], "details": "Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q65w-5wgj-fq9m/GHSA-q65w-5wgj-fq9m.json b/advisories/unreviewed/2022/05/GHSA-q65w-5wgj-fq9m/GHSA-q65w-5wgj-fq9m.json index 0f6e2a1d801..564546325ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-q65w-5wgj-fq9m/GHSA-q65w-5wgj-fq9m.json +++ b/advisories/unreviewed/2022/05/GHSA-q65w-5wgj-fq9m/GHSA-q65w-5wgj-fq9m.json @@ -7,12 +7,8 @@ "CVE-2008-0549" ], "details": "Integer overflow in the OggHeaderParse function in Steamcast 0.9.75 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via a long Ogg tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q669-qg45-xjm6/GHSA-q669-qg45-xjm6.json b/advisories/unreviewed/2022/05/GHSA-q669-qg45-xjm6/GHSA-q669-qg45-xjm6.json index b501f3cfc7d..3ebe72d3555 100644 --- a/advisories/unreviewed/2022/05/GHSA-q669-qg45-xjm6/GHSA-q669-qg45-xjm6.json +++ b/advisories/unreviewed/2022/05/GHSA-q669-qg45-xjm6/GHSA-q669-qg45-xjm6.json @@ -7,12 +7,8 @@ "CVE-2008-0686" ], "details": "SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7mg-4q42-3h7f/GHSA-q7mg-4q42-3h7f.json b/advisories/unreviewed/2022/05/GHSA-q7mg-4q42-3h7f/GHSA-q7mg-4q42-3h7f.json index 31ea58c2409..d8ec5c09bc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7mg-4q42-3h7f/GHSA-q7mg-4q42-3h7f.json +++ b/advisories/unreviewed/2022/05/GHSA-q7mg-4q42-3h7f/GHSA-q7mg-4q42-3h7f.json @@ -7,12 +7,8 @@ "CVE-2008-0501" ], "details": "Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7mr-xjvc-chw3/GHSA-q7mr-xjvc-chw3.json b/advisories/unreviewed/2022/05/GHSA-q7mr-xjvc-chw3/GHSA-q7mr-xjvc-chw3.json index 5c0c856a44b..54185561885 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7mr-xjvc-chw3/GHSA-q7mr-xjvc-chw3.json +++ b/advisories/unreviewed/2022/05/GHSA-q7mr-xjvc-chw3/GHSA-q7mr-xjvc-chw3.json @@ -7,12 +7,8 @@ "CVE-2008-0888" ], "details": "The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7p2-29gh-v5m8/GHSA-q7p2-29gh-v5m8.json b/advisories/unreviewed/2022/05/GHSA-q7p2-29gh-v5m8/GHSA-q7p2-29gh-v5m8.json index c75874969bd..e7f40fc6b38 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7p2-29gh-v5m8/GHSA-q7p2-29gh-v5m8.json +++ b/advisories/unreviewed/2022/05/GHSA-q7p2-29gh-v5m8/GHSA-q7p2-29gh-v5m8.json @@ -7,12 +7,8 @@ "CVE-2008-0735" ], "details": "SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q7pf-9472-q6v6/GHSA-q7pf-9472-q6v6.json b/advisories/unreviewed/2022/05/GHSA-q7pf-9472-q6v6/GHSA-q7pf-9472-q6v6.json index b1e8bb4f832..06f944728c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7pf-9472-q6v6/GHSA-q7pf-9472-q6v6.json +++ b/advisories/unreviewed/2022/05/GHSA-q7pf-9472-q6v6/GHSA-q7pf-9472-q6v6.json @@ -7,12 +7,8 @@ "CVE-2008-0435" ], "details": "Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the id parameter in a printpreview action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8j7-3mh3-6mh5/GHSA-q8j7-3mh3-6mh5.json b/advisories/unreviewed/2022/05/GHSA-q8j7-3mh3-6mh5/GHSA-q8j7-3mh3-6mh5.json index 0e4636868de..2d6a8f85da0 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8j7-3mh3-6mh5/GHSA-q8j7-3mh3-6mh5.json +++ b/advisories/unreviewed/2022/05/GHSA-q8j7-3mh3-6mh5/GHSA-q8j7-3mh3-6mh5.json @@ -7,12 +7,8 @@ "CVE-2019-9348" ], "details": "In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128431761", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qfc4-h5g7-5785/GHSA-qfc4-h5g7-5785.json b/advisories/unreviewed/2022/05/GHSA-qfc4-h5g7-5785/GHSA-qfc4-h5g7-5785.json index 946dc897a1e..058fb3b8662 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfc4-h5g7-5785/GHSA-qfc4-h5g7-5785.json +++ b/advisories/unreviewed/2022/05/GHSA-qfc4-h5g7-5785/GHSA-qfc4-h5g7-5785.json @@ -7,12 +7,8 @@ "CVE-2008-0752" ], "details": "SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfgr-q8f7-r48h/GHSA-qfgr-q8f7-r48h.json b/advisories/unreviewed/2022/05/GHSA-qfgr-q8f7-r48h/GHSA-qfgr-q8f7-r48h.json index e4c44ddebc1..162b768ae92 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfgr-q8f7-r48h/GHSA-qfgr-q8f7-r48h.json +++ b/advisories/unreviewed/2022/05/GHSA-qfgr-q8f7-r48h/GHSA-qfgr-q8f7-r48h.json @@ -7,12 +7,8 @@ "CVE-2008-0904" ], "details": "Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfpq-8mj8-93c3/GHSA-qfpq-8mj8-93c3.json b/advisories/unreviewed/2022/05/GHSA-qfpq-8mj8-93c3/GHSA-qfpq-8mj8-93c3.json index e97bc1d923a..c04cf4da4a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfpq-8mj8-93c3/GHSA-qfpq-8mj8-93c3.json +++ b/advisories/unreviewed/2022/05/GHSA-qfpq-8mj8-93c3/GHSA-qfpq-8mj8-93c3.json @@ -7,12 +7,8 @@ "CVE-2008-0746" ], "details": "SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfxw-x567-fwfc/GHSA-qfxw-x567-fwfc.json b/advisories/unreviewed/2022/05/GHSA-qfxw-x567-fwfc/GHSA-qfxw-x567-fwfc.json index f31cebf523d..3ec22b1ae2f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfxw-x567-fwfc/GHSA-qfxw-x567-fwfc.json +++ b/advisories/unreviewed/2022/05/GHSA-qfxw-x567-fwfc/GHSA-qfxw-x567-fwfc.json @@ -7,12 +7,8 @@ "CVE-2008-0640" ], "details": "Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg6p-6xqq-gh7c/GHSA-qg6p-6xqq-gh7c.json b/advisories/unreviewed/2022/05/GHSA-qg6p-6xqq-gh7c/GHSA-qg6p-6xqq-gh7c.json index 68016b802e5..8d2086786b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg6p-6xqq-gh7c/GHSA-qg6p-6xqq-gh7c.json +++ b/advisories/unreviewed/2022/05/GHSA-qg6p-6xqq-gh7c/GHSA-qg6p-6xqq-gh7c.json @@ -7,12 +7,8 @@ "CVE-2008-0387" ], "details": "Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qgfv-cgwg-p27q/GHSA-qgfv-cgwg-p27q.json b/advisories/unreviewed/2022/05/GHSA-qgfv-cgwg-p27q/GHSA-qgfv-cgwg-p27q.json index 2117124143b..8278782c0a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgfv-cgwg-p27q/GHSA-qgfv-cgwg-p27q.json +++ b/advisories/unreviewed/2022/05/GHSA-qgfv-cgwg-p27q/GHSA-qgfv-cgwg-p27q.json @@ -7,12 +7,8 @@ "CVE-2008-0709" ], "details": "Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to access other user accounts via unknown vectors, a different issue than CVE-2008-0214.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qgv2-86w3-h3p4/GHSA-qgv2-86w3-h3p4.json b/advisories/unreviewed/2022/05/GHSA-qgv2-86w3-h3p4/GHSA-qgv2-86w3-h3p4.json index 18a0849290d..7ec62e6c071 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgv2-86w3-h3p4/GHSA-qgv2-86w3-h3p4.json +++ b/advisories/unreviewed/2022/05/GHSA-qgv2-86w3-h3p4/GHSA-qgv2-86w3-h3p4.json @@ -7,12 +7,8 @@ "CVE-2008-0711" ], "details": "Unspecified vulnerability in the embedded management console in HP iLO-2 Management Processors (iLO-2 MP), as used in Integrity Servers rx2660, rx3600, and rx6600, and Integrity Blade Server model bl860c, allows remote attackers to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qj2j-r78w-5jg7/GHSA-qj2j-r78w-5jg7.json b/advisories/unreviewed/2022/05/GHSA-qj2j-r78w-5jg7/GHSA-qj2j-r78w-5jg7.json index 27f0cc795a0..a24786423d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qj2j-r78w-5jg7/GHSA-qj2j-r78w-5jg7.json +++ b/advisories/unreviewed/2022/05/GHSA-qj2j-r78w-5jg7/GHSA-qj2j-r78w-5jg7.json @@ -7,12 +7,8 @@ "CVE-2008-0937" ], "details": "SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a different vector than CVE-2007-1811.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjfc-qwh8-vh83/GHSA-qjfc-qwh8-vh83.json b/advisories/unreviewed/2022/05/GHSA-qjfc-qwh8-vh83/GHSA-qjfc-qwh8-vh83.json index 8ba853b3fb3..4c3dd5332d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjfc-qwh8-vh83/GHSA-qjfc-qwh8-vh83.json +++ b/advisories/unreviewed/2022/05/GHSA-qjfc-qwh8-vh83/GHSA-qjfc-qwh8-vh83.json @@ -7,12 +7,8 @@ "CVE-2008-0543" ], "details": "Multiple SQL injection vulnerabilities in Pre Dynamic Institution allow remote attackers to execute arbitrary SQL commands via the (1) sloginid and (2) spass parameters to (a) login.asp and (b) siteadmin/login.asp. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjhj-mx7w-2r2m/GHSA-qjhj-mx7w-2r2m.json b/advisories/unreviewed/2022/05/GHSA-qjhj-mx7w-2r2m/GHSA-qjhj-mx7w-2r2m.json index 05267483ea9..de0f442e6c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjhj-mx7w-2r2m/GHSA-qjhj-mx7w-2r2m.json +++ b/advisories/unreviewed/2022/05/GHSA-qjhj-mx7w-2r2m/GHSA-qjhj-mx7w-2r2m.json @@ -7,12 +7,8 @@ "CVE-2008-0401" ], "details": "Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qm2w-jjjx-8fp9/GHSA-qm2w-jjjx-8fp9.json b/advisories/unreviewed/2022/05/GHSA-qm2w-jjjx-8fp9/GHSA-qm2w-jjjx-8fp9.json index f4c7533b5f1..6fb42c0f26a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm2w-jjjx-8fp9/GHSA-qm2w-jjjx-8fp9.json +++ b/advisories/unreviewed/2022/05/GHSA-qm2w-jjjx-8fp9/GHSA-qm2w-jjjx-8fp9.json @@ -7,12 +7,8 @@ "CVE-2008-0736" ], "details": "admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpfx-f2pv-5c24/GHSA-qpfx-f2pv-5c24.json b/advisories/unreviewed/2022/05/GHSA-qpfx-f2pv-5c24/GHSA-qpfx-f2pv-5c24.json index d5248fee6e9..8f1fc17478f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpfx-f2pv-5c24/GHSA-qpfx-f2pv-5c24.json +++ b/advisories/unreviewed/2022/05/GHSA-qpfx-f2pv-5c24/GHSA-qpfx-f2pv-5c24.json @@ -7,12 +7,8 @@ "CVE-2008-0951" ], "details": "Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry value, which allows user-assisted remote attackers, and possibly physically proximate attackers, to execute arbitrary code by inserting a (1) CD-ROM device or (2) U3-enabled USB device containing a filesystem with an Autorun.inf file, and possibly other vectors related to (a) AutoRun and (b) AutoPlay actions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqc5-2p9g-3m85/GHSA-qqc5-2p9g-3m85.json b/advisories/unreviewed/2022/05/GHSA-qqc5-2p9g-3m85/GHSA-qqc5-2p9g-3m85.json index 5bd6c047acf..febf414e2b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqc5-2p9g-3m85/GHSA-qqc5-2p9g-3m85.json +++ b/advisories/unreviewed/2022/05/GHSA-qqc5-2p9g-3m85/GHSA-qqc5-2p9g-3m85.json @@ -7,12 +7,8 @@ "CVE-2008-0789" ], "details": "SQL injection vulnerability in countdown.php in LI-Scripts LI-Countdown allows remote attackers to execute arbitrary SQL commands via the years parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qr27-fv3r-7wf9/GHSA-qr27-fv3r-7wf9.json b/advisories/unreviewed/2022/05/GHSA-qr27-fv3r-7wf9/GHSA-qr27-fv3r-7wf9.json index c183abc6a5b..96c8481b366 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr27-fv3r-7wf9/GHSA-qr27-fv3r-7wf9.json +++ b/advisories/unreviewed/2022/05/GHSA-qr27-fv3r-7wf9/GHSA-qr27-fv3r-7wf9.json @@ -7,12 +7,8 @@ "CVE-2008-0611" ], "details": "SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrw2-cc7v-xx92/GHSA-qrw2-cc7v-xx92.json b/advisories/unreviewed/2022/05/GHSA-qrw2-cc7v-xx92/GHSA-qrw2-cc7v-xx92.json index 9017b662415..ce0f92e19ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrw2-cc7v-xx92/GHSA-qrw2-cc7v-xx92.json +++ b/advisories/unreviewed/2022/05/GHSA-qrw2-cc7v-xx92/GHSA-qrw2-cc7v-xx92.json @@ -7,12 +7,8 @@ "CVE-2008-0564" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's \"info attribute\" in the web administrator interface, a different vulnerability than CVE-2006-3636.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qv8r-3p22-q7wp/GHSA-qv8r-3p22-q7wp.json b/advisories/unreviewed/2022/05/GHSA-qv8r-3p22-q7wp/GHSA-qv8r-3p22-q7wp.json index e9f1f7e9d69..06c91479829 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv8r-3p22-q7wp/GHSA-qv8r-3p22-q7wp.json +++ b/advisories/unreviewed/2022/05/GHSA-qv8r-3p22-q7wp/GHSA-qv8r-3p22-q7wp.json @@ -7,12 +7,8 @@ "CVE-2008-0693" ], "details": "Stack-based buffer overflow in PQCore.exe in Print Manager Plus 2008 Client Billing and Authentication 7.0.127.16 allows remote attackers to cause a denial of service (service outage) via a series of long packets to TCP port 48101.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json b/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json index 05d532abcb2..823f0a45be1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json +++ b/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json @@ -7,12 +7,8 @@ "CVE-2008-0655" ], "details": "Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw7r-fgv9-5ggc/GHSA-qw7r-fgv9-5ggc.json b/advisories/unreviewed/2022/05/GHSA-qw7r-fgv9-5ggc/GHSA-qw7r-fgv9-5ggc.json index abb88e24d39..f946aae474e 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw7r-fgv9-5ggc/GHSA-qw7r-fgv9-5ggc.json +++ b/advisories/unreviewed/2022/05/GHSA-qw7r-fgv9-5ggc/GHSA-qw7r-fgv9-5ggc.json @@ -7,12 +7,8 @@ "CVE-2008-0703" ], "details": "Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or (2) section parameter to index.php, possibly involving includes/entries.inc.php and other files included by index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qxcp-87j8-2w2v/GHSA-qxcp-87j8-2w2v.json b/advisories/unreviewed/2022/05/GHSA-qxcp-87j8-2w2v/GHSA-qxcp-87j8-2w2v.json index 69ef9aa90d7..b7f54877b47 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxcp-87j8-2w2v/GHSA-qxcp-87j8-2w2v.json +++ b/advisories/unreviewed/2022/05/GHSA-qxcp-87j8-2w2v/GHSA-qxcp-87j8-2w2v.json @@ -7,12 +7,8 @@ "CVE-2008-0425" ], "details": "Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directories via a full pathname in the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxjq-q2r2-ccg4/GHSA-qxjq-q2r2-ccg4.json b/advisories/unreviewed/2022/05/GHSA-qxjq-q2r2-ccg4/GHSA-qxjq-q2r2-ccg4.json index 0f8a2a03371..5cfdcf637c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxjq-q2r2-ccg4/GHSA-qxjq-q2r2-ccg4.json +++ b/advisories/unreviewed/2022/05/GHSA-qxjq-q2r2-ccg4/GHSA-qxjq-q2r2-ccg4.json @@ -7,12 +7,8 @@ "CVE-2008-0466" ], "details": "Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r37c-fgx7-q833/GHSA-r37c-fgx7-q833.json b/advisories/unreviewed/2022/05/GHSA-r37c-fgx7-q833/GHSA-r37c-fgx7-q833.json index 02b63842096..8d69a8bbb16 100644 --- a/advisories/unreviewed/2022/05/GHSA-r37c-fgx7-q833/GHSA-r37c-fgx7-q833.json +++ b/advisories/unreviewed/2022/05/GHSA-r37c-fgx7-q833/GHSA-r37c-fgx7-q833.json @@ -7,12 +7,8 @@ "CVE-2008-0544" ], "details": "Heap-based buffer overflow in the IMG_LoadLBM_RW function in IMG_lbm.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted IFF ILBM file. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r3xp-mq32-wwmf/GHSA-r3xp-mq32-wwmf.json b/advisories/unreviewed/2022/05/GHSA-r3xp-mq32-wwmf/GHSA-r3xp-mq32-wwmf.json index c682d690270..d34faa7776d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3xp-mq32-wwmf/GHSA-r3xp-mq32-wwmf.json +++ b/advisories/unreviewed/2022/05/GHSA-r3xp-mq32-wwmf/GHSA-r3xp-mq32-wwmf.json @@ -7,12 +7,8 @@ "CVE-2008-0862" ], "details": "IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r58h-mh9m-crp8/GHSA-r58h-mh9m-crp8.json b/advisories/unreviewed/2022/05/GHSA-r58h-mh9m-crp8/GHSA-r58h-mh9m-crp8.json index 039dbc195d3..558d8840947 100644 --- a/advisories/unreviewed/2022/05/GHSA-r58h-mh9m-crp8/GHSA-r58h-mh9m-crp8.json +++ b/advisories/unreviewed/2022/05/GHSA-r58h-mh9m-crp8/GHSA-r58h-mh9m-crp8.json @@ -7,12 +7,8 @@ "CVE-2008-0646" ], "details": "The bdecode_recursive function in include/libtorrent/bencode.hpp in Rasterbar Software libtorrent before 0.12.1, as used in Deluge before 0.5.8.3 and other products, allows context-dependent attackers to cause a denial of service (stack exhaustion and crash) via a crafted bencoded message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5pf-wcfw-339x/GHSA-r5pf-wcfw-339x.json b/advisories/unreviewed/2022/05/GHSA-r5pf-wcfw-339x/GHSA-r5pf-wcfw-339x.json index 85085ca2721..c56da395950 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5pf-wcfw-339x/GHSA-r5pf-wcfw-339x.json +++ b/advisories/unreviewed/2022/05/GHSA-r5pf-wcfw-339x/GHSA-r5pf-wcfw-339x.json @@ -7,12 +7,8 @@ "CVE-2008-0667" ], "details": "The DOC.print function in the Adobe JavaScript API, as used by Adobe Acrobat and Reader before 8.1.2, allows remote attackers to configure silent non-interactive printing, and trigger the printing of an arbitrary number of copies of a document. NOTE: this issue might be subsumed by CVE-2008-0655.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -104,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5v5-xcxj-vxhm/GHSA-r5v5-xcxj-vxhm.json b/advisories/unreviewed/2022/05/GHSA-r5v5-xcxj-vxhm/GHSA-r5v5-xcxj-vxhm.json index 2d5a9322c6e..1634924b060 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5v5-xcxj-vxhm/GHSA-r5v5-xcxj-vxhm.json +++ b/advisories/unreviewed/2022/05/GHSA-r5v5-xcxj-vxhm/GHSA-r5v5-xcxj-vxhm.json @@ -7,12 +7,8 @@ "CVE-2008-0913" ], "details": "Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via crafted BBCodes in an unspecified context.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r63f-2f6c-mxvq/GHSA-r63f-2f6c-mxvq.json b/advisories/unreviewed/2022/05/GHSA-r63f-2f6c-mxvq/GHSA-r63f-2f6c-mxvq.json index b580fb2d15e..069b863b4d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-r63f-2f6c-mxvq/GHSA-r63f-2f6c-mxvq.json +++ b/advisories/unreviewed/2022/05/GHSA-r63f-2f6c-mxvq/GHSA-r63f-2f6c-mxvq.json @@ -7,12 +7,8 @@ "CVE-2008-0661" ], "details": "Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file with a long URI. NOTE: this might be the same issue as CVE-2004-1569.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r656-cf7f-6gq9/GHSA-r656-cf7f-6gq9.json b/advisories/unreviewed/2022/05/GHSA-r656-cf7f-6gq9/GHSA-r656-cf7f-6gq9.json index f7925ba8495..0fc69c99827 100644 --- a/advisories/unreviewed/2022/05/GHSA-r656-cf7f-6gq9/GHSA-r656-cf7f-6gq9.json +++ b/advisories/unreviewed/2022/05/GHSA-r656-cf7f-6gq9/GHSA-r656-cf7f-6gq9.json @@ -7,12 +7,8 @@ "CVE-2008-0769" ], "details": "Cross-site scripting (XSS) vulnerability in Livelink ECM 9.0.0 through 9.7.0 and possibly earlier does not set the charset, which allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r6gx-g2r9-8q8m/GHSA-r6gx-g2r9-8q8m.json b/advisories/unreviewed/2022/05/GHSA-r6gx-g2r9-8q8m/GHSA-r6gx-g2r9-8q8m.json index 2fa80ead711..f45a88545f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6gx-g2r9-8q8m/GHSA-r6gx-g2r9-8q8m.json +++ b/advisories/unreviewed/2022/05/GHSA-r6gx-g2r9-8q8m/GHSA-r6gx-g2r9-8q8m.json @@ -7,12 +7,8 @@ "CVE-2008-0931" ], "details": "w_export.c in XWine 1.0.1 on Debian GNU/Linux sets insecure permissions (0666) for /etc/wine/config, which might allow local users to execute arbitrary commands or cause a denial of service by modifying the file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6r7-cc63-q3qm/GHSA-r6r7-cc63-q3qm.json b/advisories/unreviewed/2022/05/GHSA-r6r7-cc63-q3qm/GHSA-r6r7-cc63-q3qm.json index cb5788af998..011bc295791 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6r7-cc63-q3qm/GHSA-r6r7-cc63-q3qm.json +++ b/advisories/unreviewed/2022/05/GHSA-r6r7-cc63-q3qm/GHSA-r6r7-cc63-q3qm.json @@ -7,12 +7,8 @@ "CVE-2008-0814" ], "details": "Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the upload_filename parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r7p6-qc6p-grmm/GHSA-r7p6-qc6p-grmm.json b/advisories/unreviewed/2022/05/GHSA-r7p6-qc6p-grmm/GHSA-r7p6-qc6p-grmm.json index 3aa560ab00a..d4cd6531a9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7p6-qc6p-grmm/GHSA-r7p6-qc6p-grmm.json +++ b/advisories/unreviewed/2022/05/GHSA-r7p6-qc6p-grmm/GHSA-r7p6-qc6p-grmm.json @@ -7,12 +7,8 @@ "CVE-2008-0517" ], "details": "SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r93m-826v-8qxq/GHSA-r93m-826v-8qxq.json b/advisories/unreviewed/2022/05/GHSA-r93m-826v-8qxq/GHSA-r93m-826v-8qxq.json index c14bc6fbc04..4edfb8a5db3 100644 --- a/advisories/unreviewed/2022/05/GHSA-r93m-826v-8qxq/GHSA-r93m-826v-8qxq.json +++ b/advisories/unreviewed/2022/05/GHSA-r93m-826v-8qxq/GHSA-r93m-826v-8qxq.json @@ -7,12 +7,8 @@ "CVE-2008-0477" ], "details": "Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary code via a long first argument to the Upgrade method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9mx-c64j-hf3f/GHSA-r9mx-c64j-hf3f.json b/advisories/unreviewed/2022/05/GHSA-r9mx-c64j-hf3f/GHSA-r9mx-c64j-hf3f.json index 0958ee3c8da..bed243ce34d 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9mx-c64j-hf3f/GHSA-r9mx-c64j-hf3f.json +++ b/advisories/unreviewed/2022/05/GHSA-r9mx-c64j-hf3f/GHSA-r9mx-c64j-hf3f.json @@ -7,12 +7,8 @@ "CVE-2019-5692" ], "details": "NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the product uses untrusted input when calculating or using an array index, which may lead to escalation of privileges or denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9v8-vjgf-82h8/GHSA-r9v8-vjgf-82h8.json b/advisories/unreviewed/2022/05/GHSA-r9v8-vjgf-82h8/GHSA-r9v8-vjgf-82h8.json index efc030eb9f7..2de3d4269df 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9v8-vjgf-82h8/GHSA-r9v8-vjgf-82h8.json +++ b/advisories/unreviewed/2022/05/GHSA-r9v8-vjgf-82h8/GHSA-r9v8-vjgf-82h8.json @@ -7,12 +7,8 @@ "CVE-2008-0633" ], "details": "Buffer overflow in Anon Proxy Server 0.102 and earlier, when user authentication is enabled, allows remote attackers to cause a denial of service (exception) via a user name with a large number of quotes, which triggers the overflow during escaping.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9x6-j8w2-r753/GHSA-r9x6-j8w2-r753.json b/advisories/unreviewed/2022/05/GHSA-r9x6-j8w2-r753/GHSA-r9x6-j8w2-r753.json index bc87feb6b9d..11897509a21 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9x6-j8w2-r753/GHSA-r9x6-j8w2-r753.json +++ b/advisories/unreviewed/2022/05/GHSA-r9x6-j8w2-r753/GHSA-r9x6-j8w2-r753.json @@ -7,12 +7,8 @@ "CVE-2008-0598" ], "details": "Unspecified vulnerability in the 32-bit and 64-bit emulation in the Linux kernel 2.6.9, 2.6.18, and probably other versions allows local users to read uninitialized memory via unknown vectors involving a crafted binary.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rc52-99jj-cxg6/GHSA-rc52-99jj-cxg6.json b/advisories/unreviewed/2022/05/GHSA-rc52-99jj-cxg6/GHSA-rc52-99jj-cxg6.json index 53d925cee2f..b86d8713da3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc52-99jj-cxg6/GHSA-rc52-99jj-cxg6.json +++ b/advisories/unreviewed/2022/05/GHSA-rc52-99jj-cxg6/GHSA-rc52-99jj-cxg6.json @@ -7,12 +7,8 @@ "CVE-2008-0809" ], "details": "Cross-site scripting (XSS) vulnerability in the htmlscrubber in Ikiwiki before 1.1.46 allows remote attackers to inject arbitrary web script or HTML via title contents.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rc66-4982-rv68/GHSA-rc66-4982-rv68.json b/advisories/unreviewed/2022/05/GHSA-rc66-4982-rv68/GHSA-rc66-4982-rv68.json index 371a6b40e9d..d86cf127cfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc66-4982-rv68/GHSA-rc66-4982-rv68.json +++ b/advisories/unreviewed/2022/05/GHSA-rc66-4982-rv68/GHSA-rc66-4982-rv68.json @@ -7,12 +7,8 @@ "CVE-2008-0755" ], "details": "Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; might allow remote attackers to execute arbitrary code via format string specifiers in the queue name in a request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rf6q-m37m-q323/GHSA-rf6q-m37m-q323.json b/advisories/unreviewed/2022/05/GHSA-rf6q-m37m-q323/GHSA-rf6q-m37m-q323.json index 816759943c8..c458cf568dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf6q-m37m-q323/GHSA-rf6q-m37m-q323.json +++ b/advisories/unreviewed/2022/05/GHSA-rf6q-m37m-q323/GHSA-rf6q-m37m-q323.json @@ -7,12 +7,8 @@ "CVE-2008-0918" ], "details": "SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rj64-3q6q-qjm9/GHSA-rj64-3q6q-qjm9.json b/advisories/unreviewed/2022/05/GHSA-rj64-3q6q-qjm9/GHSA-rj64-3q6q-qjm9.json index a4ff9d1ce18..2f40ff16282 100644 --- a/advisories/unreviewed/2022/05/GHSA-rj64-3q6q-qjm9/GHSA-rj64-3q6q-qjm9.json +++ b/advisories/unreviewed/2022/05/GHSA-rj64-3q6q-qjm9/GHSA-rj64-3q6q-qjm9.json @@ -7,12 +7,8 @@ "CVE-2008-0865" ], "details": "Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP6 allows remote attackers to bypass entitlements for instances of a floatable WLP portlet via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjvq-8jhg-x247/GHSA-rjvq-8jhg-x247.json b/advisories/unreviewed/2022/05/GHSA-rjvq-8jhg-x247/GHSA-rjvq-8jhg-x247.json index 03ad6621f78..1cd81f95acd 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjvq-8jhg-x247/GHSA-rjvq-8jhg-x247.json +++ b/advisories/unreviewed/2022/05/GHSA-rjvq-8jhg-x247/GHSA-rjvq-8jhg-x247.json @@ -7,12 +7,8 @@ "CVE-2019-1310" ], "details": "A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1399.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rpg2-6hr8-hcp4/GHSA-rpg2-6hr8-hcp4.json b/advisories/unreviewed/2022/05/GHSA-rpg2-6hr8-hcp4/GHSA-rpg2-6hr8-hcp4.json index ffc53d60985..ed27c589a67 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpg2-6hr8-hcp4/GHSA-rpg2-6hr8-hcp4.json +++ b/advisories/unreviewed/2022/05/GHSA-rpg2-6hr8-hcp4/GHSA-rpg2-6hr8-hcp4.json @@ -7,12 +7,8 @@ "CVE-2008-0909" ], "details": "Cross-site scripting (XSS) vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to inject arbitrary web script or HTML via the c parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpvq-484q-f5wg/GHSA-rpvq-484q-f5wg.json b/advisories/unreviewed/2022/05/GHSA-rpvq-484q-f5wg/GHSA-rpvq-484q-f5wg.json index 7d6f595af3e..9323b2e8e63 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpvq-484q-f5wg/GHSA-rpvq-484q-f5wg.json +++ b/advisories/unreviewed/2022/05/GHSA-rpvq-484q-f5wg/GHSA-rpvq-484q-f5wg.json @@ -7,12 +7,8 @@ "CVE-2008-0714" ], "details": "SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL commands via the username parameter in a lost_password_go action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rqg4-2qfx-wwqv/GHSA-rqg4-2qfx-wwqv.json b/advisories/unreviewed/2022/05/GHSA-rqg4-2qfx-wwqv/GHSA-rqg4-2qfx-wwqv.json index 59cf6584058..14a5d29b44a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqg4-2qfx-wwqv/GHSA-rqg4-2qfx-wwqv.json +++ b/advisories/unreviewed/2022/05/GHSA-rqg4-2qfx-wwqv/GHSA-rqg4-2qfx-wwqv.json @@ -7,12 +7,8 @@ "CVE-2008-0580" ], "details": "Geert Moernaut LSrunasE and Supercrypt use an encryption key composed of an SHA1 hash of a fixed string embedded in the executable file, which makes it easier for local users to obtain this key without reverse engineering.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrx7-386p-58w6/GHSA-rrx7-386p-58w6.json b/advisories/unreviewed/2022/05/GHSA-rrx7-386p-58w6/GHSA-rrx7-386p-58w6.json index 913b7df7a9d..61d4f265804 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrx7-386p-58w6/GHSA-rrx7-386p-58w6.json +++ b/advisories/unreviewed/2022/05/GHSA-rrx7-386p-58w6/GHSA-rrx7-386p-58w6.json @@ -7,12 +7,8 @@ "CVE-2008-0975" ], "details": "Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (CPU consumption) via a -1 value in the field that specifies the size of the vector value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rv8w-h7cq-9wg2/GHSA-rv8w-h7cq-9wg2.json b/advisories/unreviewed/2022/05/GHSA-rv8w-h7cq-9wg2/GHSA-rv8w-h7cq-9wg2.json index f9e63f72256..1c18af8973f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv8w-h7cq-9wg2/GHSA-rv8w-h7cq-9wg2.json +++ b/advisories/unreviewed/2022/05/GHSA-rv8w-h7cq-9wg2/GHSA-rv8w-h7cq-9wg2.json @@ -7,12 +7,8 @@ "CVE-2008-0588" ], "details": "Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvc4-4cr9-9c89/GHSA-rvc4-4cr9-9c89.json b/advisories/unreviewed/2022/05/GHSA-rvc4-4cr9-9c89/GHSA-rvc4-4cr9-9c89.json index 73407923bed..4b74fc4a8ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvc4-4cr9-9c89/GHSA-rvc4-4cr9-9c89.json +++ b/advisories/unreviewed/2022/05/GHSA-rvc4-4cr9-9c89/GHSA-rvc4-4cr9-9c89.json @@ -7,12 +7,8 @@ "CVE-2008-0718" ], "details": "Unspecified vulnerability in the USB Mouse STREAMS module (usbms) in Sun Solaris 9 and 10, when 64-bit mode is enabled, allows local users to cause a denial of service (panic) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvwg-7xj4-5x4j/GHSA-rvwg-7xj4-5x4j.json b/advisories/unreviewed/2022/05/GHSA-rvwg-7xj4-5x4j/GHSA-rvwg-7xj4-5x4j.json index a3910e1e870..b706d754c92 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvwg-7xj4-5x4j/GHSA-rvwg-7xj4-5x4j.json +++ b/advisories/unreviewed/2022/05/GHSA-rvwg-7xj4-5x4j/GHSA-rvwg-7xj4-5x4j.json @@ -7,12 +7,8 @@ "CVE-2008-0502" ], "details": "PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the template_path parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwf6-mxf8-5hcf/GHSA-rwf6-mxf8-5hcf.json b/advisories/unreviewed/2022/05/GHSA-rwf6-mxf8-5hcf/GHSA-rwf6-mxf8-5hcf.json index 7e71395842c..e2b2bb8f3f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwf6-mxf8-5hcf/GHSA-rwf6-mxf8-5hcf.json +++ b/advisories/unreviewed/2022/05/GHSA-rwf6-mxf8-5hcf/GHSA-rwf6-mxf8-5hcf.json @@ -7,12 +7,8 @@ "CVE-2008-0742" ], "details": "Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php, and (f) users.inc.php in pnadmin/; and (2) the page parameter to (g) pnadmin/index.php. NOTE: vector 2 is only exploitable by administrators.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rww3-9vvq-977p/GHSA-rww3-9vvq-977p.json b/advisories/unreviewed/2022/05/GHSA-rww3-9vvq-977p/GHSA-rww3-9vvq-977p.json index 5f65c44ce90..07993be443b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rww3-9vvq-977p/GHSA-rww3-9vvq-977p.json +++ b/advisories/unreviewed/2022/05/GHSA-rww3-9vvq-977p/GHSA-rww3-9vvq-977p.json @@ -7,12 +7,8 @@ "CVE-2019-18862" ], "details": "maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rx25-27q5-v53x/GHSA-rx25-27q5-v53x.json b/advisories/unreviewed/2022/05/GHSA-rx25-27q5-v53x/GHSA-rx25-27q5-v53x.json index 21f3cea579f..89afdb63052 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx25-27q5-v53x/GHSA-rx25-27q5-v53x.json +++ b/advisories/unreviewed/2022/05/GHSA-rx25-27q5-v53x/GHSA-rx25-27q5-v53x.json @@ -7,12 +7,8 @@ "CVE-2008-0558" ], "details": "Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified other components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx57-4mmf-7j34/GHSA-rx57-4mmf-7j34.json b/advisories/unreviewed/2022/05/GHSA-rx57-4mmf-7j34/GHSA-rx57-4mmf-7j34.json index d5fbb4f62d6..706f21756ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx57-4mmf-7j34/GHSA-rx57-4mmf-7j34.json +++ b/advisories/unreviewed/2022/05/GHSA-rx57-4mmf-7j34/GHSA-rx57-4mmf-7j34.json @@ -7,12 +7,8 @@ "CVE-2008-0605" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v24h-cghj-p7rq/GHSA-v24h-cghj-p7rq.json b/advisories/unreviewed/2022/05/GHSA-v24h-cghj-p7rq/GHSA-v24h-cghj-p7rq.json index 5a4e6600f74..024d9474252 100644 --- a/advisories/unreviewed/2022/05/GHSA-v24h-cghj-p7rq/GHSA-v24h-cghj-p7rq.json +++ b/advisories/unreviewed/2022/05/GHSA-v24h-cghj-p7rq/GHSA-v24h-cghj-p7rq.json @@ -7,12 +7,8 @@ "CVE-2008-0406" ], "details": "HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v4fw-xc8h-7p52/GHSA-v4fw-xc8h-7p52.json b/advisories/unreviewed/2022/05/GHSA-v4fw-xc8h-7p52/GHSA-v4fw-xc8h-7p52.json index d68989fdaf4..c5c786133cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4fw-xc8h-7p52/GHSA-v4fw-xc8h-7p52.json +++ b/advisories/unreviewed/2022/05/GHSA-v4fw-xc8h-7p52/GHSA-v4fw-xc8h-7p52.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4pj-7vpp-vw22/GHSA-v4pj-7vpp-vw22.json b/advisories/unreviewed/2022/05/GHSA-v4pj-7vpp-vw22/GHSA-v4pj-7vpp-vw22.json index 4036212a0eb..382257c7422 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4pj-7vpp-vw22/GHSA-v4pj-7vpp-vw22.json +++ b/advisories/unreviewed/2022/05/GHSA-v4pj-7vpp-vw22/GHSA-v4pj-7vpp-vw22.json @@ -7,12 +7,8 @@ "CVE-2008-0446" ], "details": "SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v52g-78c5-x43w/GHSA-v52g-78c5-x43w.json b/advisories/unreviewed/2022/05/GHSA-v52g-78c5-x43w/GHSA-v52g-78c5-x43w.json index 6a2cd6f03c3..6e12b23730e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v52g-78c5-x43w/GHSA-v52g-78c5-x43w.json +++ b/advisories/unreviewed/2022/05/GHSA-v52g-78c5-x43w/GHSA-v52g-78c5-x43w.json @@ -7,12 +7,8 @@ "CVE-2008-0587" ], "details": "Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v5pp-mxmw-5hvr/GHSA-v5pp-mxmw-5hvr.json b/advisories/unreviewed/2022/05/GHSA-v5pp-mxmw-5hvr/GHSA-v5pp-mxmw-5hvr.json index eb9208c97d5..cc6de1e827d 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5pp-mxmw-5hvr/GHSA-v5pp-mxmw-5hvr.json +++ b/advisories/unreviewed/2022/05/GHSA-v5pp-mxmw-5hvr/GHSA-v5pp-mxmw-5hvr.json @@ -7,12 +7,8 @@ "CVE-2008-0706" ], "details": "Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged access via unspecified vectors, possibly involving an authentication bypass of the power-on password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v684-4fqq-vwgc/GHSA-v684-4fqq-vwgc.json b/advisories/unreviewed/2022/05/GHSA-v684-4fqq-vwgc/GHSA-v684-4fqq-vwgc.json index e3f9e112167..4a6045a7c50 100644 --- a/advisories/unreviewed/2022/05/GHSA-v684-4fqq-vwgc/GHSA-v684-4fqq-vwgc.json +++ b/advisories/unreviewed/2022/05/GHSA-v684-4fqq-vwgc/GHSA-v684-4fqq-vwgc.json @@ -7,12 +7,8 @@ "CVE-2008-0467" ], "details": "Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v6cj-rg53-2x2x/GHSA-v6cj-rg53-2x2x.json b/advisories/unreviewed/2022/05/GHSA-v6cj-rg53-2x2x/GHSA-v6cj-rg53-2x2x.json index cc81c4cf272..f7429426c16 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6cj-rg53-2x2x/GHSA-v6cj-rg53-2x2x.json +++ b/advisories/unreviewed/2022/05/GHSA-v6cj-rg53-2x2x/GHSA-v6cj-rg53-2x2x.json @@ -7,12 +7,8 @@ "CVE-2008-0458" ], "details": "Directory traversal vulnerability in function/sources.php in SLAED CMS 2.5 Lite allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlang parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v7mq-3qjg-gc4w/GHSA-v7mq-3qjg-gc4w.json b/advisories/unreviewed/2022/05/GHSA-v7mq-3qjg-gc4w/GHSA-v7mq-3qjg-gc4w.json index 4707a14bfc9..39eec3fd02a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v7mq-3qjg-gc4w/GHSA-v7mq-3qjg-gc4w.json +++ b/advisories/unreviewed/2022/05/GHSA-v7mq-3qjg-gc4w/GHSA-v7mq-3qjg-gc4w.json @@ -7,12 +7,8 @@ "CVE-2008-0530" ], "details": "Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8mh-v2p3-87m5/GHSA-v8mh-v2p3-87m5.json b/advisories/unreviewed/2022/05/GHSA-v8mh-v2p3-87m5/GHSA-v8mh-v2p3-87m5.json index e8c5f6c5367..23ededf0b92 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8mh-v2p3-87m5/GHSA-v8mh-v2p3-87m5.json +++ b/advisories/unreviewed/2022/05/GHSA-v8mh-v2p3-87m5/GHSA-v8mh-v2p3-87m5.json @@ -7,12 +7,8 @@ "CVE-2008-0673" ], "details": "TinTin++ 1.97.9 and WinTin++ 1.97.9 open files on the basis of an inbound file-transfer request, before the user has an opportunity to decline the request, which allows remote attackers to truncate arbitrary files in the top level of a home directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9qm-hc37-6v36/GHSA-v9qm-hc37-6v36.json b/advisories/unreviewed/2022/05/GHSA-v9qm-hc37-6v36/GHSA-v9qm-hc37-6v36.json index 563b7320416..bb4f281548f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9qm-hc37-6v36/GHSA-v9qm-hc37-6v36.json +++ b/advisories/unreviewed/2022/05/GHSA-v9qm-hc37-6v36/GHSA-v9qm-hc37-6v36.json @@ -7,12 +7,8 @@ "CVE-2008-0868" ], "details": "Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote authenticated users to inject arbitrary web script or HTML via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vc3j-83qc-fgg9/GHSA-vc3j-83qc-fgg9.json b/advisories/unreviewed/2022/05/GHSA-vc3j-83qc-fgg9/GHSA-vc3j-83qc-fgg9.json index 54f0ecc5fc1..3530088284f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc3j-83qc-fgg9/GHSA-vc3j-83qc-fgg9.json +++ b/advisories/unreviewed/2022/05/GHSA-vc3j-83qc-fgg9/GHSA-vc3j-83qc-fgg9.json @@ -7,12 +7,8 @@ "CVE-2008-0788" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and (2) hijack the authentication of arbitrary users for requests that delete private messages (PM) via a delete action to private.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vc92-qxjw-hqcx/GHSA-vc92-qxjw-hqcx.json b/advisories/unreviewed/2022/05/GHSA-vc92-qxjw-hqcx/GHSA-vc92-qxjw-hqcx.json index 295440d8fbd..13ae7ebb6e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc92-qxjw-hqcx/GHSA-vc92-qxjw-hqcx.json +++ b/advisories/unreviewed/2022/05/GHSA-vc92-qxjw-hqcx/GHSA-vc92-qxjw-hqcx.json @@ -7,12 +7,8 @@ "CVE-2008-0932" ], "details": "diatheke.pl in The SWORD Project Diatheke 1.5.9 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the range parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vc9x-q8pm-49vv/GHSA-vc9x-q8pm-49vv.json b/advisories/unreviewed/2022/05/GHSA-vc9x-q8pm-49vv/GHSA-vc9x-q8pm-49vv.json index 9fd84b999be..d585b8dd932 100644 --- a/advisories/unreviewed/2022/05/GHSA-vc9x-q8pm-49vv/GHSA-vc9x-q8pm-49vv.json +++ b/advisories/unreviewed/2022/05/GHSA-vc9x-q8pm-49vv/GHSA-vc9x-q8pm-49vv.json @@ -7,12 +7,8 @@ "CVE-2008-0498" ], "details": "SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the pollid parameter in a results action to main_bigware_53.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcjx-xf8c-qxqm/GHSA-vcjx-xf8c-qxqm.json b/advisories/unreviewed/2022/05/GHSA-vcjx-xf8c-qxqm/GHSA-vcjx-xf8c-qxqm.json index b42db8082d5..fb3060bb7fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcjx-xf8c-qxqm/GHSA-vcjx-xf8c-qxqm.json +++ b/advisories/unreviewed/2022/05/GHSA-vcjx-xf8c-qxqm/GHSA-vcjx-xf8c-qxqm.json @@ -7,12 +7,8 @@ "CVE-2008-0882" ], "details": "Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vf4x-p8gp-539h/GHSA-vf4x-p8gp-539h.json b/advisories/unreviewed/2022/05/GHSA-vf4x-p8gp-539h/GHSA-vf4x-p8gp-539h.json index bcf73042ae7..790269fa317 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf4x-p8gp-539h/GHSA-vf4x-p8gp-539h.json +++ b/advisories/unreviewed/2022/05/GHSA-vf4x-p8gp-539h/GHSA-vf4x-p8gp-539h.json @@ -7,12 +7,8 @@ "CVE-2008-0666" ], "details": "Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by wml_contrib/wmg.cgi and (2) temporary files used by wml_backend/p3_eperl/eperl_sys.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhhc-w77j-mvf2/GHSA-vhhc-w77j-mvf2.json b/advisories/unreviewed/2022/05/GHSA-vhhc-w77j-mvf2/GHSA-vhhc-w77j-mvf2.json index 6cea4dc50c3..af1b33eaaac 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhhc-w77j-mvf2/GHSA-vhhc-w77j-mvf2.json +++ b/advisories/unreviewed/2022/05/GHSA-vhhc-w77j-mvf2/GHSA-vhhc-w77j-mvf2.json @@ -7,12 +7,8 @@ "CVE-2008-0813" ], "details": "Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm88-xwrf-p2q7/GHSA-vm88-xwrf-p2q7.json b/advisories/unreviewed/2022/05/GHSA-vm88-xwrf-p2q7/GHSA-vm88-xwrf-p2q7.json index c33586e5625..0ca245b32bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm88-xwrf-p2q7/GHSA-vm88-xwrf-p2q7.json +++ b/advisories/unreviewed/2022/05/GHSA-vm88-xwrf-p2q7/GHSA-vm88-xwrf-p2q7.json @@ -7,12 +7,8 @@ "CVE-2008-0610" ], "details": "Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a modified size value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmrm-3gr2-66vg/GHSA-vmrm-3gr2-66vg.json b/advisories/unreviewed/2022/05/GHSA-vmrm-3gr2-66vg/GHSA-vmrm-3gr2-66vg.json index 9919ea3a3c0..1304b4be4ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmrm-3gr2-66vg/GHSA-vmrm-3gr2-66vg.json +++ b/advisories/unreviewed/2022/05/GHSA-vmrm-3gr2-66vg/GHSA-vmrm-3gr2-66vg.json @@ -7,12 +7,8 @@ "CVE-2008-0520" ], "details": "Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq8g-f6qp-h94h/GHSA-vq8g-f6qp-h94h.json b/advisories/unreviewed/2022/05/GHSA-vq8g-f6qp-h94h/GHSA-vq8g-f6qp-h94h.json index 44eeeebdd70..4ca51a0b40d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq8g-f6qp-h94h/GHSA-vq8g-f6qp-h94h.json +++ b/advisories/unreviewed/2022/05/GHSA-vq8g-f6qp-h94h/GHSA-vq8g-f6qp-h94h.json @@ -7,12 +7,8 @@ "CVE-2008-0715" ], "details": "Buffer overflow in ACDSee Photo Manager 8.1, 9.0, and 10.0 allows user-assisted remote attackers to execute arbitrary code via a malformed XBM file. NOTE: this might be the same as CVE-2007-6009.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vqpj-w2mm-4vm8/GHSA-vqpj-w2mm-4vm8.json b/advisories/unreviewed/2022/05/GHSA-vqpj-w2mm-4vm8/GHSA-vqpj-w2mm-4vm8.json index 3b4a7119f90..67848da2c58 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqpj-w2mm-4vm8/GHSA-vqpj-w2mm-4vm8.json +++ b/advisories/unreviewed/2022/05/GHSA-vqpj-w2mm-4vm8/GHSA-vqpj-w2mm-4vm8.json @@ -7,12 +7,8 @@ "CVE-2008-0677" ], "details": "SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a news action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vr27-2rf5-6c74/GHSA-vr27-2rf5-6c74.json b/advisories/unreviewed/2022/05/GHSA-vr27-2rf5-6c74/GHSA-vr27-2rf5-6c74.json index 684f58d01f6..a349bdb1c10 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr27-2rf5-6c74/GHSA-vr27-2rf5-6c74.json +++ b/advisories/unreviewed/2022/05/GHSA-vr27-2rf5-6c74/GHSA-vr27-2rf5-6c74.json @@ -7,12 +7,8 @@ "CVE-2008-0492" ], "details": "Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUpload 3.0 allows remote attackers to execute arbitrary code via a long argument to the AddFile method. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vv7v-g229-vwgh/GHSA-vv7v-g229-vwgh.json b/advisories/unreviewed/2022/05/GHSA-vv7v-g229-vwgh/GHSA-vv7v-g229-vwgh.json index f8d1dd6cee9..a2d079b69f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv7v-g229-vwgh/GHSA-vv7v-g229-vwgh.json +++ b/advisories/unreviewed/2022/05/GHSA-vv7v-g229-vwgh/GHSA-vv7v-g229-vwgh.json @@ -7,12 +7,8 @@ "CVE-2008-0807" ], "details": "lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w2px-74cm-hrpr/GHSA-w2px-74cm-hrpr.json b/advisories/unreviewed/2022/05/GHSA-w2px-74cm-hrpr/GHSA-w2px-74cm-hrpr.json index d258552dee7..078ffca69ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2px-74cm-hrpr/GHSA-w2px-74cm-hrpr.json +++ b/advisories/unreviewed/2022/05/GHSA-w2px-74cm-hrpr/GHSA-w2px-74cm-hrpr.json @@ -7,12 +7,8 @@ "CVE-2008-0553" ], "details": "Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w49v-6qr7-cqmh/GHSA-w49v-6qr7-cqmh.json b/advisories/unreviewed/2022/05/GHSA-w49v-6qr7-cqmh/GHSA-w49v-6qr7-cqmh.json index 3b8204a12ad..3c220fda111 100644 --- a/advisories/unreviewed/2022/05/GHSA-w49v-6qr7-cqmh/GHSA-w49v-6qr7-cqmh.json +++ b/advisories/unreviewed/2022/05/GHSA-w49v-6qr7-cqmh/GHSA-w49v-6qr7-cqmh.json @@ -7,12 +7,8 @@ "CVE-2008-0388" ], "details": "SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4c2-qx4v-cx5j/GHSA-w4c2-qx4v-cx5j.json b/advisories/unreviewed/2022/05/GHSA-w4c2-qx4v-cx5j/GHSA-w4c2-qx4v-cx5j.json index 5b153c9513f..f8f4db37ffa 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4c2-qx4v-cx5j/GHSA-w4c2-qx4v-cx5j.json +++ b/advisories/unreviewed/2022/05/GHSA-w4c2-qx4v-cx5j/GHSA-w4c2-qx4v-cx5j.json @@ -7,12 +7,8 @@ "CVE-2008-0518" ], "details": "SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w569-jf9w-w6mg/GHSA-w569-jf9w-w6mg.json b/advisories/unreviewed/2022/05/GHSA-w569-jf9w-w6mg/GHSA-w569-jf9w-w6mg.json index 238af10edbd..a1623dda782 100644 --- a/advisories/unreviewed/2022/05/GHSA-w569-jf9w-w6mg/GHSA-w569-jf9w-w6mg.json +++ b/advisories/unreviewed/2022/05/GHSA-w569-jf9w-w6mg/GHSA-w569-jf9w-w6mg.json @@ -7,12 +7,8 @@ "CVE-2008-0552" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w62j-hhjm-mfjv/GHSA-w62j-hhjm-mfjv.json b/advisories/unreviewed/2022/05/GHSA-w62j-hhjm-mfjv/GHSA-w62j-hhjm-mfjv.json index c110661025c..3d09206644a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w62j-hhjm-mfjv/GHSA-w62j-hhjm-mfjv.json +++ b/advisories/unreviewed/2022/05/GHSA-w62j-hhjm-mfjv/GHSA-w62j-hhjm-mfjv.json @@ -7,12 +7,8 @@ "CVE-2008-0536" ], "details": "Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (management interface outage) via SSH traffic that occurs during management operations and triggers \"illegal I/O operations,\" aka Bug ID CSCsh49563.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6c3-65p5-g94h/GHSA-w6c3-65p5-g94h.json b/advisories/unreviewed/2022/05/GHSA-w6c3-65p5-g94h/GHSA-w6c3-65p5-g94h.json index 268d652c277..8b059aad7a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6c3-65p5-g94h/GHSA-w6c3-65p5-g94h.json +++ b/advisories/unreviewed/2022/05/GHSA-w6c3-65p5-g94h/GHSA-w6c3-65p5-g94h.json @@ -7,12 +7,8 @@ "CVE-2008-0437" ], "details": "Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of these details are obtained from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6cr-wr7p-2fjf/GHSA-w6cr-wr7p-2fjf.json b/advisories/unreviewed/2022/05/GHSA-w6cr-wr7p-2fjf/GHSA-w6cr-wr7p-2fjf.json index c0c8c6f89fb..c0aeaf48da8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6cr-wr7p-2fjf/GHSA-w6cr-wr7p-2fjf.json +++ b/advisories/unreviewed/2022/05/GHSA-w6cr-wr7p-2fjf/GHSA-w6cr-wr7p-2fjf.json @@ -7,12 +7,8 @@ "CVE-2008-0447" ], "details": "SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL commands via the story parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6mv-fhrx-pfw7/GHSA-w6mv-fhrx-pfw7.json b/advisories/unreviewed/2022/05/GHSA-w6mv-fhrx-pfw7/GHSA-w6mv-fhrx-pfw7.json index 733100de59f..302f101f4fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6mv-fhrx-pfw7/GHSA-w6mv-fhrx-pfw7.json +++ b/advisories/unreviewed/2022/05/GHSA-w6mv-fhrx-pfw7/GHSA-w6mv-fhrx-pfw7.json @@ -7,12 +7,8 @@ "CVE-2008-0481" ], "details": "Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\\\\ in the sub parameter in a save action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w6qq-43vp-x232/GHSA-w6qq-43vp-x232.json b/advisories/unreviewed/2022/05/GHSA-w6qq-43vp-x232/GHSA-w6qq-43vp-x232.json index 75d88fc37cb..02aad04de87 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6qq-43vp-x232/GHSA-w6qq-43vp-x232.json +++ b/advisories/unreviewed/2022/05/GHSA-w6qq-43vp-x232/GHSA-w6qq-43vp-x232.json @@ -7,12 +7,8 @@ "CVE-2008-0570" ], "details": "The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w74v-4922-34mq/GHSA-w74v-4922-34mq.json b/advisories/unreviewed/2022/05/GHSA-w74v-4922-34mq/GHSA-w74v-4922-34mq.json index f4fd625bd05..47f16da92fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-w74v-4922-34mq/GHSA-w74v-4922-34mq.json +++ b/advisories/unreviewed/2022/05/GHSA-w74v-4922-34mq/GHSA-w74v-4922-34mq.json @@ -7,12 +7,8 @@ "CVE-2008-0762" ], "details": "SQL injection vulnerability in index.php in the com_iomezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w7jw-whgf-5mgf/GHSA-w7jw-whgf-5mgf.json b/advisories/unreviewed/2022/05/GHSA-w7jw-whgf-5mgf/GHSA-w7jw-whgf-5mgf.json index d11c9b5a91a..d6009ba83d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7jw-whgf-5mgf/GHSA-w7jw-whgf-5mgf.json +++ b/advisories/unreviewed/2022/05/GHSA-w7jw-whgf-5mgf/GHSA-w7jw-whgf-5mgf.json @@ -7,12 +7,8 @@ "CVE-2008-0967" ], "details": "Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w826-7v7v-g233/GHSA-w826-7v7v-g233.json b/advisories/unreviewed/2022/05/GHSA-w826-7v7v-g233/GHSA-w826-7v7v-g233.json index 030410cdee9..a85b564cf2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-w826-7v7v-g233/GHSA-w826-7v7v-g233.json +++ b/advisories/unreviewed/2022/05/GHSA-w826-7v7v-g233/GHSA-w826-7v7v-g233.json @@ -7,12 +7,8 @@ "CVE-2008-0731" ], "details": "The Linux kernel before 2.6.18.8-0.8 in SUSE openSUSE 10.2 does not properly handle failure of an AppArmor change_hat system call, which might allow attackers to trigger the unconfining of an apparmored task.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w9c3-3cvm-x4wm/GHSA-w9c3-3cvm-x4wm.json b/advisories/unreviewed/2022/05/GHSA-w9c3-3cvm-x4wm/GHSA-w9c3-3cvm-x4wm.json index 22b68dcbc34..263ac4b91fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9c3-3cvm-x4wm/GHSA-w9c3-3cvm-x4wm.json +++ b/advisories/unreviewed/2022/05/GHSA-w9c3-3cvm-x4wm/GHSA-w9c3-3cvm-x4wm.json @@ -7,12 +7,8 @@ "CVE-2008-0947" ], "details": "Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file descriptors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfrp-xv66-pmxj/GHSA-wfrp-xv66-pmxj.json b/advisories/unreviewed/2022/05/GHSA-wfrp-xv66-pmxj/GHSA-wfrp-xv66-pmxj.json index 7c78d101aa8..e07d2c08df7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfrp-xv66-pmxj/GHSA-wfrp-xv66-pmxj.json +++ b/advisories/unreviewed/2022/05/GHSA-wfrp-xv66-pmxj/GHSA-wfrp-xv66-pmxj.json @@ -7,12 +7,8 @@ "CVE-2008-0727" ], "details": "Multiple buffer overflows in oninit.exe in IBM Informix Dynamic Server (IDS) 7.x through 11.x allow (1) remote attackers to execute arbitrary code via a long password and (2) remote authenticated users to execute arbitrary code via a long DBPATH value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wg37-27hc-9hm5/GHSA-wg37-27hc-9hm5.json b/advisories/unreviewed/2022/05/GHSA-wg37-27hc-9hm5/GHSA-wg37-27hc-9hm5.json index 4129fd8c998..01f9580464d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg37-27hc-9hm5/GHSA-wg37-27hc-9hm5.json +++ b/advisories/unreviewed/2022/05/GHSA-wg37-27hc-9hm5/GHSA-wg37-27hc-9hm5.json @@ -7,12 +7,8 @@ "CVE-2019-1407" ], "details": "An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1433, CVE-2019-1435, CVE-2019-1437, CVE-2019-1438.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wg47-xqc5-g367/GHSA-wg47-xqc5-g367.json b/advisories/unreviewed/2022/05/GHSA-wg47-xqc5-g367/GHSA-wg47-xqc5-g367.json index c9dc335cbb7..c0c61345974 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg47-xqc5-g367/GHSA-wg47-xqc5-g367.json +++ b/advisories/unreviewed/2022/05/GHSA-wg47-xqc5-g367/GHSA-wg47-xqc5-g367.json @@ -7,12 +7,8 @@ "CVE-2008-0681" ], "details": "SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via the product_id parameter, as demonstrated by a shop/flypage action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wgjq-j646-4ghv/GHSA-wgjq-j646-4ghv.json b/advisories/unreviewed/2022/05/GHSA-wgjq-j646-4ghv/GHSA-wgjq-j646-4ghv.json index b2c8e74cffc..2eb519b0939 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgjq-j646-4ghv/GHSA-wgjq-j646-4ghv.json +++ b/advisories/unreviewed/2022/05/GHSA-wgjq-j646-4ghv/GHSA-wgjq-j646-4ghv.json @@ -7,12 +7,8 @@ "CVE-2019-0721" ], "details": "A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0719.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wh57-998x-2qxh/GHSA-wh57-998x-2qxh.json b/advisories/unreviewed/2022/05/GHSA-wh57-998x-2qxh/GHSA-wh57-998x-2qxh.json index 8b47fe3dc35..964cb138f93 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh57-998x-2qxh/GHSA-wh57-998x-2qxh.json +++ b/advisories/unreviewed/2022/05/GHSA-wh57-998x-2qxh/GHSA-wh57-998x-2qxh.json @@ -7,12 +7,8 @@ "CVE-2008-0724" ], "details": "The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it easier for context-dependent attackers to obtain access to user accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whm3-pjww-fw7w/GHSA-whm3-pjww-fw7w.json b/advisories/unreviewed/2022/05/GHSA-whm3-pjww-fw7w/GHSA-whm3-pjww-fw7w.json index 6fb8349c715..66787903ab7 100644 --- a/advisories/unreviewed/2022/05/GHSA-whm3-pjww-fw7w/GHSA-whm3-pjww-fw7w.json +++ b/advisories/unreviewed/2022/05/GHSA-whm3-pjww-fw7w/GHSA-whm3-pjww-fw7w.json @@ -7,12 +7,8 @@ "CVE-2008-0883" ], "details": "acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmw4-483j-9m5r/GHSA-wmw4-483j-9m5r.json b/advisories/unreviewed/2022/05/GHSA-wmw4-483j-9m5r/GHSA-wmw4-483j-9m5r.json index f6a0bb507a4..f8f12bd96eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmw4-483j-9m5r/GHSA-wmw4-483j-9m5r.json +++ b/advisories/unreviewed/2022/05/GHSA-wmw4-483j-9m5r/GHSA-wmw4-483j-9m5r.json @@ -7,12 +7,8 @@ "CVE-2008-0516" ], "details": "PHP remote file inclusion vulnerability in spaw/dialogs/confirm.php in SQLiteManager 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmwx-j79h-c89r/GHSA-wmwx-j79h-c89r.json b/advisories/unreviewed/2022/05/GHSA-wmwx-j79h-c89r/GHSA-wmwx-j79h-c89r.json index 467c0e77a4d..f2fc9b79539 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmwx-j79h-c89r/GHSA-wmwx-j79h-c89r.json +++ b/advisories/unreviewed/2022/05/GHSA-wmwx-j79h-c89r/GHSA-wmwx-j79h-c89r.json @@ -7,12 +7,8 @@ "CVE-2008-0499" ], "details": "SQL injection vulnerability in Mambo LaiThai 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr3f-mxfc-4q69/GHSA-wr3f-mxfc-4q69.json b/advisories/unreviewed/2022/05/GHSA-wr3f-mxfc-4q69/GHSA-wr3f-mxfc-4q69.json index 0467a7b2a3e..d0f07354c29 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr3f-mxfc-4q69/GHSA-wr3f-mxfc-4q69.json +++ b/advisories/unreviewed/2022/05/GHSA-wr3f-mxfc-4q69/GHSA-wr3f-mxfc-4q69.json @@ -7,12 +7,8 @@ "CVE-2008-0450" ], "details": "Multiple PHP remote file inclusion vulnerabilities in BLOG:CMS 4.2.1.c allow remote attackers to execute arbitrary PHP code via a URL in the (1) DIR_PLUGINS parameter to (a) index.php, and the (2) DIR_LIBS parameter to (b) media.php and (c) xmlrpc/server.php in admin/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wr9w-gvmm-f764/GHSA-wr9w-gvmm-f764.json b/advisories/unreviewed/2022/05/GHSA-wr9w-gvmm-f764/GHSA-wr9w-gvmm-f764.json index d59177e6d8d..924c1adab55 100644 --- a/advisories/unreviewed/2022/05/GHSA-wr9w-gvmm-f764/GHSA-wr9w-gvmm-f764.json +++ b/advisories/unreviewed/2022/05/GHSA-wr9w-gvmm-f764/GHSA-wr9w-gvmm-f764.json @@ -7,12 +7,8 @@ "CVE-2008-0694" ], "details": "Cross-site scripting (XSS) vulnerability in the HTTP Server in IBM OS/400 V5R3M0 and V5R4M0 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrcf-h25j-7v55/GHSA-wrcf-h25j-7v55.json b/advisories/unreviewed/2022/05/GHSA-wrcf-h25j-7v55/GHSA-wrcf-h25j-7v55.json index 520ae88d3f4..e2bb9b24781 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrcf-h25j-7v55/GHSA-wrcf-h25j-7v55.json +++ b/advisories/unreviewed/2022/05/GHSA-wrcf-h25j-7v55/GHSA-wrcf-h25j-7v55.json @@ -7,12 +7,8 @@ "CVE-2008-0421" ], "details": "SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv8p-p965-2w2h/GHSA-wv8p-p965-2w2h.json b/advisories/unreviewed/2022/05/GHSA-wv8p-p965-2w2h/GHSA-wv8p-p965-2w2h.json index 2031a94efef..60d039c87fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv8p-p965-2w2h/GHSA-wv8p-p965-2w2h.json +++ b/advisories/unreviewed/2022/05/GHSA-wv8p-p965-2w2h/GHSA-wv8p-p965-2w2h.json @@ -7,12 +7,8 @@ "CVE-2008-0979" ], "details": "Stack consumption vulnerability in Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon crash) via a certain packet that triggers the recursive calling of a function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wvpm-5g4h-g8hp/GHSA-wvpm-5g4h-g8hp.json b/advisories/unreviewed/2022/05/GHSA-wvpm-5g4h-g8hp/GHSA-wvpm-5g4h-g8hp.json index 13fdfb172c1..c5f7795fd72 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvpm-5g4h-g8hp/GHSA-wvpm-5g4h-g8hp.json +++ b/advisories/unreviewed/2022/05/GHSA-wvpm-5g4h-g8hp/GHSA-wvpm-5g4h-g8hp.json @@ -7,12 +7,8 @@ "CVE-2008-0528" ], "details": "Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wvx9-gqx2-gw3m/GHSA-wvx9-gqx2-gw3m.json b/advisories/unreviewed/2022/05/GHSA-wvx9-gqx2-gw3m/GHSA-wvx9-gqx2-gw3m.json index aafa9c166db..c21ae79414b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvx9-gqx2-gw3m/GHSA-wvx9-gqx2-gw3m.json +++ b/advisories/unreviewed/2022/05/GHSA-wvx9-gqx2-gw3m/GHSA-wvx9-gqx2-gw3m.json @@ -7,12 +7,8 @@ "CVE-2008-0800" ], "details": "SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwx5-jh5w-7x6g/GHSA-wwx5-jh5w-7x6g.json b/advisories/unreviewed/2022/05/GHSA-wwx5-jh5w-7x6g/GHSA-wwx5-jh5w-7x6g.json index c13fd939ce9..f3f0d7d7d4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwx5-jh5w-7x6g/GHSA-wwx5-jh5w-7x6g.json +++ b/advisories/unreviewed/2022/05/GHSA-wwx5-jh5w-7x6g/GHSA-wwx5-jh5w-7x6g.json @@ -7,12 +7,8 @@ "CVE-2008-0584" ], "details": "Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) swap, (2) swapoff, and (3) swapon programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx4r-pwpq-mw5m/GHSA-wx4r-pwpq-mw5m.json b/advisories/unreviewed/2022/05/GHSA-wx4r-pwpq-mw5m/GHSA-wx4r-pwpq-mw5m.json index 05b7d7d07bf..64d27425fbc 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx4r-pwpq-mw5m/GHSA-wx4r-pwpq-mw5m.json +++ b/advisories/unreviewed/2022/05/GHSA-wx4r-pwpq-mw5m/GHSA-wx4r-pwpq-mw5m.json @@ -7,12 +7,8 @@ "CVE-2008-0526" ], "details": "Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a long ICMP echo request (ping) packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x376-5hfp-cxq9/GHSA-x376-5hfp-cxq9.json b/advisories/unreviewed/2022/05/GHSA-x376-5hfp-cxq9/GHSA-x376-5hfp-cxq9.json index ca6f8e3523a..1f871707cde 100644 --- a/advisories/unreviewed/2022/05/GHSA-x376-5hfp-cxq9/GHSA-x376-5hfp-cxq9.json +++ b/advisories/unreviewed/2022/05/GHSA-x376-5hfp-cxq9/GHSA-x376-5hfp-cxq9.json @@ -7,12 +7,8 @@ "CVE-2008-0601" ], "details": "SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3jq-r6gp-49qf/GHSA-x3jq-r6gp-49qf.json b/advisories/unreviewed/2022/05/GHSA-x3jq-r6gp-49qf/GHSA-x3jq-r6gp-49qf.json index ffcb5b1d65a..1c36ec519c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3jq-r6gp-49qf/GHSA-x3jq-r6gp-49qf.json +++ b/advisories/unreviewed/2022/05/GHSA-x3jq-r6gp-49qf/GHSA-x3jq-r6gp-49qf.json @@ -7,12 +7,8 @@ "CVE-2008-0887" ], "details": "gnome-screensaver before 2.22.1, when a remote authentication server is enabled, crashes upon an unlock attempt during a network outage, which allows physically proximate attackers to gain access to the locked session, a related issue to CVE-2007-1859.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x47m-3p5m-6489/GHSA-x47m-3p5m-6489.json b/advisories/unreviewed/2022/05/GHSA-x47m-3p5m-6489/GHSA-x47m-3p5m-6489.json index e453b66d908..91955e6c3f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-x47m-3p5m-6489/GHSA-x47m-3p5m-6489.json +++ b/advisories/unreviewed/2022/05/GHSA-x47m-3p5m-6489/GHSA-x47m-3p5m-6489.json @@ -7,12 +7,8 @@ "CVE-2008-0770" ], "details": "SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the g_display_order cookie parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4vj-cghm-76jq/GHSA-x4vj-cghm-76jq.json b/advisories/unreviewed/2022/05/GHSA-x4vj-cghm-76jq/GHSA-x4vj-cghm-76jq.json index f4ddfc26160..8b83bad5e72 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4vj-cghm-76jq/GHSA-x4vj-cghm-76jq.json +++ b/advisories/unreviewed/2022/05/GHSA-x4vj-cghm-76jq/GHSA-x4vj-cghm-76jq.json @@ -7,12 +7,8 @@ "CVE-2008-0400" ], "details": "Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x56q-c56w-9j5v/GHSA-x56q-c56w-9j5v.json b/advisories/unreviewed/2022/05/GHSA-x56q-c56w-9j5v/GHSA-x56q-c56w-9j5v.json index b750fdeac4f..3e040188009 100644 --- a/advisories/unreviewed/2022/05/GHSA-x56q-c56w-9j5v/GHSA-x56q-c56w-9j5v.json +++ b/advisories/unreviewed/2022/05/GHSA-x56q-c56w-9j5v/GHSA-x56q-c56w-9j5v.json @@ -7,12 +7,8 @@ "CVE-2008-0944" ], "details": "Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via a version field containing zero.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x599-j43r-893m/GHSA-x599-j43r-893m.json b/advisories/unreviewed/2022/05/GHSA-x599-j43r-893m/GHSA-x599-j43r-893m.json index 2a983cb9986..0d60bf9b37f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x599-j43r-893m/GHSA-x599-j43r-893m.json +++ b/advisories/unreviewed/2022/05/GHSA-x599-j43r-893m/GHSA-x599-j43r-893m.json @@ -7,12 +7,8 @@ "CVE-2008-0438" ], "details": "Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the txt parameter to a Flash (SWF) file, as demonstrated by fonts/FuturaLt.swf.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x59x-xr7f-524q/GHSA-x59x-xr7f-524q.json b/advisories/unreviewed/2022/05/GHSA-x59x-xr7f-524q/GHSA-x59x-xr7f-524q.json index 548c473056a..44743de8500 100644 --- a/advisories/unreviewed/2022/05/GHSA-x59x-xr7f-524q/GHSA-x59x-xr7f-524q.json +++ b/advisories/unreviewed/2022/05/GHSA-x59x-xr7f-524q/GHSA-x59x-xr7f-524q.json @@ -7,12 +7,8 @@ "CVE-2008-0688" ], "details": "Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5jq-v5pc-7p6h/GHSA-x5jq-v5pc-7p6h.json b/advisories/unreviewed/2022/05/GHSA-x5jq-v5pc-7p6h/GHSA-x5jq-v5pc-7p6h.json index 4d418c605e2..a6fd2a99e35 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5jq-v5pc-7p6h/GHSA-x5jq-v5pc-7p6h.json +++ b/advisories/unreviewed/2022/05/GHSA-x5jq-v5pc-7p6h/GHSA-x5jq-v5pc-7p6h.json @@ -7,12 +7,8 @@ "CVE-2008-0574" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via the sort parameter in a whoisonline action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5ph-343m-g2xh/GHSA-x5ph-343m-g2xh.json b/advisories/unreviewed/2022/05/GHSA-x5ph-343m-g2xh/GHSA-x5ph-343m-g2xh.json index 2ca1274579c..270dfbc5a96 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5ph-343m-g2xh/GHSA-x5ph-343m-g2xh.json +++ b/advisories/unreviewed/2022/05/GHSA-x5ph-343m-g2xh/GHSA-x5ph-343m-g2xh.json @@ -7,12 +7,8 @@ "CVE-2008-0417" ], "details": "CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x829-4ghm-j8mj/GHSA-x829-4ghm-j8mj.json b/advisories/unreviewed/2022/05/GHSA-x829-4ghm-j8mj/GHSA-x829-4ghm-j8mj.json index 0b1a171e6e8..6c9fe3c9c9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x829-4ghm-j8mj/GHSA-x829-4ghm-j8mj.json +++ b/advisories/unreviewed/2022/05/GHSA-x829-4ghm-j8mj/GHSA-x829-4ghm-j8mj.json @@ -7,12 +7,8 @@ "CVE-2008-0542" ], "details": "Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x927-rph6-c38j/GHSA-x927-rph6-c38j.json b/advisories/unreviewed/2022/05/GHSA-x927-rph6-c38j/GHSA-x927-rph6-c38j.json index e05a944c5ac..dacb473a90c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x927-rph6-c38j/GHSA-x927-rph6-c38j.json +++ b/advisories/unreviewed/2022/05/GHSA-x927-rph6-c38j/GHSA-x927-rph6-c38j.json @@ -7,12 +7,8 @@ "CVE-2008-0593" ], "details": "Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x995-j3jg-4xpc/GHSA-x995-j3jg-4xpc.json b/advisories/unreviewed/2022/05/GHSA-x995-j3jg-4xpc/GHSA-x995-j3jg-4xpc.json index a5f6177fd60..389a6aba8eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-x995-j3jg-4xpc/GHSA-x995-j3jg-4xpc.json +++ b/advisories/unreviewed/2022/05/GHSA-x995-j3jg-4xpc/GHSA-x995-j3jg-4xpc.json @@ -7,12 +7,8 @@ "CVE-2008-0804" ], "details": "PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a URL in the name parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9jf-g794-6pc5/GHSA-x9jf-g794-6pc5.json b/advisories/unreviewed/2022/05/GHSA-x9jf-g794-6pc5/GHSA-x9jf-g794-6pc5.json index e8e2cc50ebc..475ea0ab812 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9jf-g794-6pc5/GHSA-x9jf-g794-6pc5.json +++ b/advisories/unreviewed/2022/05/GHSA-x9jf-g794-6pc5/GHSA-x9jf-g794-6pc5.json @@ -7,12 +7,8 @@ "CVE-2008-0708" ], "details": "HP USB 2.0 Floppy Drive Key product options (1) 442084-B21 and (2) 442085-B21 for certain HP ProLiant servers contain the (a) W32.Fakerecy and (b) W32.SillyFDC worms, which might be launched if the server does not have up-to-date detection.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xchm-4wgc-jp23/GHSA-xchm-4wgc-jp23.json b/advisories/unreviewed/2022/05/GHSA-xchm-4wgc-jp23/GHSA-xchm-4wgc-jp23.json index ded69a8f84a..a4c4110017c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xchm-4wgc-jp23/GHSA-xchm-4wgc-jp23.json +++ b/advisories/unreviewed/2022/05/GHSA-xchm-4wgc-jp23/GHSA-xchm-4wgc-jp23.json @@ -7,12 +7,8 @@ "CVE-2008-0722" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Pagetool 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter in a pagetool_search action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xh4h-vjm3-wxmv/GHSA-xh4h-vjm3-wxmv.json b/advisories/unreviewed/2022/05/GHSA-xh4h-vjm3-wxmv/GHSA-xh4h-vjm3-wxmv.json index 6e8b288a013..4a98ed18d54 100644 --- a/advisories/unreviewed/2022/05/GHSA-xh4h-vjm3-wxmv/GHSA-xh4h-vjm3-wxmv.json +++ b/advisories/unreviewed/2022/05/GHSA-xh4h-vjm3-wxmv/GHSA-xh4h-vjm3-wxmv.json @@ -7,12 +7,8 @@ "CVE-2008-0870" ], "details": "BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj3v-mc9q-x9hh/GHSA-xj3v-mc9q-x9hh.json b/advisories/unreviewed/2022/05/GHSA-xj3v-mc9q-x9hh/GHSA-xj3v-mc9q-x9hh.json index a7012f88697..4777615588b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj3v-mc9q-x9hh/GHSA-xj3v-mc9q-x9hh.json +++ b/advisories/unreviewed/2022/05/GHSA-xj3v-mc9q-x9hh/GHSA-xj3v-mc9q-x9hh.json @@ -7,12 +7,8 @@ "CVE-2008-0385" ], "details": "SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjh9-37gr-4228/GHSA-xjh9-37gr-4228.json b/advisories/unreviewed/2022/05/GHSA-xjh9-37gr-4228/GHSA-xjh9-37gr-4228.json index cdcac2fbf92..4b7b0d80ddd 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjh9-37gr-4228/GHSA-xjh9-37gr-4228.json +++ b/advisories/unreviewed/2022/05/GHSA-xjh9-37gr-4228/GHSA-xjh9-37gr-4228.json @@ -7,12 +7,8 @@ "CVE-2008-0941" ], "details": "Cross-site scripting (XSS) vulnerability in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote authenticated users to inject arbitrary web script or HTML via an event.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xm9h-gvgh-crf7/GHSA-xm9h-gvgh-crf7.json b/advisories/unreviewed/2022/05/GHSA-xm9h-gvgh-crf7/GHSA-xm9h-gvgh-crf7.json index 3cb255c77da..65119b5aa1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm9h-gvgh-crf7/GHSA-xm9h-gvgh-crf7.json +++ b/advisories/unreviewed/2022/05/GHSA-xm9h-gvgh-crf7/GHSA-xm9h-gvgh-crf7.json @@ -7,12 +7,8 @@ "CVE-2008-0608" ], "details": "The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log commands from being recorded, a different vulnerability than CVE-2007-3823.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmp9-m365-hwwg/GHSA-xmp9-m365-hwwg.json b/advisories/unreviewed/2022/05/GHSA-xmp9-m365-hwwg/GHSA-xmp9-m365-hwwg.json index c758d38a06c..67ffb1e3eef 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmp9-m365-hwwg/GHSA-xmp9-m365-hwwg.json +++ b/advisories/unreviewed/2022/05/GHSA-xmp9-m365-hwwg/GHSA-xmp9-m365-hwwg.json @@ -7,12 +7,8 @@ "CVE-2008-0960" ], "details": "SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmrq-q3hv-6f55/GHSA-xmrq-q3hv-6f55.json b/advisories/unreviewed/2022/05/GHSA-xmrq-q3hv-6f55/GHSA-xmrq-q3hv-6f55.json index a4bd4980594..9e197ab4a4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmrq-q3hv-6f55/GHSA-xmrq-q3hv-6f55.json +++ b/advisories/unreviewed/2022/05/GHSA-xmrq-q3hv-6f55/GHSA-xmrq-q3hv-6f55.json @@ -7,12 +7,8 @@ "CVE-2019-9308" ], "details": "In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661742", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xppj-xjxm-v2wv/GHSA-xppj-xjxm-v2wv.json b/advisories/unreviewed/2022/05/GHSA-xppj-xjxm-v2wv/GHSA-xppj-xjxm-v2wv.json index 2991631223d..83b4cc4f01a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xppj-xjxm-v2wv/GHSA-xppj-xjxm-v2wv.json +++ b/advisories/unreviewed/2022/05/GHSA-xppj-xjxm-v2wv/GHSA-xppj-xjxm-v2wv.json @@ -7,12 +7,8 @@ "CVE-2008-0716" ], "details": "The agent in Symantec Altiris Notification Server before 6.0 SP3 R7 allows local users to gain privileges via a \"Shatter\" style attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xppv-jgh7-rvmh/GHSA-xppv-jgh7-rvmh.json b/advisories/unreviewed/2022/05/GHSA-xppv-jgh7-rvmh/GHSA-xppv-jgh7-rvmh.json index 778ecf115aa..3e43e0af82e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xppv-jgh7-rvmh/GHSA-xppv-jgh7-rvmh.json +++ b/advisories/unreviewed/2022/05/GHSA-xppv-jgh7-rvmh/GHSA-xppv-jgh7-rvmh.json @@ -7,12 +7,8 @@ "CVE-2008-0473" ], "details": "RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqc9-w6h7-577w/GHSA-xqc9-w6h7-577w.json b/advisories/unreviewed/2022/05/GHSA-xqc9-w6h7-577w/GHSA-xqc9-w6h7-577w.json index c2d39d93037..70582ef9012 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqc9-w6h7-577w/GHSA-xqc9-w6h7-577w.json +++ b/advisories/unreviewed/2022/05/GHSA-xqc9-w6h7-577w/GHSA-xqc9-w6h7-577w.json @@ -7,12 +7,8 @@ "CVE-2008-0619" ], "details": "Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (persistent crash) via a long URI in a .M3U file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqwr-9jf2-gqww/GHSA-xqwr-9jf2-gqww.json b/advisories/unreviewed/2022/05/GHSA-xqwr-9jf2-gqww/GHSA-xqwr-9jf2-gqww.json index 99ec97a893f..0354bb4b8c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqwr-9jf2-gqww/GHSA-xqwr-9jf2-gqww.json +++ b/advisories/unreviewed/2022/05/GHSA-xqwr-9jf2-gqww/GHSA-xqwr-9jf2-gqww.json @@ -7,12 +7,8 @@ "CVE-2008-0964" ], "details": "Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xv44-cpqx-3w77/GHSA-xv44-cpqx-3w77.json b/advisories/unreviewed/2022/05/GHSA-xv44-cpqx-3w77/GHSA-xv44-cpqx-3w77.json index 69133539ffe..ccc9d4852ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv44-cpqx-3w77/GHSA-xv44-cpqx-3w77.json +++ b/advisories/unreviewed/2022/05/GHSA-xv44-cpqx-3w77/GHSA-xv44-cpqx-3w77.json @@ -7,12 +7,8 @@ "CVE-2008-0440" ], "details": "AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw2j-g93q-hj2g/GHSA-xw2j-g93q-hj2g.json b/advisories/unreviewed/2022/05/GHSA-xw2j-g93q-hj2g/GHSA-xw2j-g93q-hj2g.json index 7f653754091..9ac9600b946 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw2j-g93q-hj2g/GHSA-xw2j-g93q-hj2g.json +++ b/advisories/unreviewed/2022/05/GHSA-xw2j-g93q-hj2g/GHSA-xw2j-g93q-hj2g.json @@ -7,12 +7,8 @@ "CVE-2008-0726" ], "details": "Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSepsWithParams, which triggers memory corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xxmr-5pw7-p42v/GHSA-xxmr-5pw7-p42v.json b/advisories/unreviewed/2022/05/GHSA-xxmr-5pw7-p42v/GHSA-xxmr-5pw7-p42v.json index a1ad581335a..3ec2218fccb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxmr-5pw7-p42v/GHSA-xxmr-5pw7-p42v.json +++ b/advisories/unreviewed/2022/05/GHSA-xxmr-5pw7-p42v/GHSA-xxmr-5pw7-p42v.json @@ -7,12 +7,8 @@ "CVE-2008-0402" ], "details": "Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-76qx-g957-hwpc/GHSA-76qx-g957-hwpc.json b/advisories/unreviewed/2022/08/GHSA-76qx-g957-hwpc/GHSA-76qx-g957-hwpc.json index 3e6ef626a70..bcccc20c8cf 100644 --- a/advisories/unreviewed/2022/08/GHSA-76qx-g957-hwpc/GHSA-76qx-g957-hwpc.json +++ b/advisories/unreviewed/2022/08/GHSA-76qx-g957-hwpc/GHSA-76qx-g957-hwpc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-c2v8-4gvf-47f7/GHSA-c2v8-4gvf-47f7.json b/advisories/unreviewed/2022/08/GHSA-c2v8-4gvf-47f7/GHSA-c2v8-4gvf-47f7.json index 486f58df81a..7ba7ecbc0ec 100644 --- a/advisories/unreviewed/2022/08/GHSA-c2v8-4gvf-47f7/GHSA-c2v8-4gvf-47f7.json +++ b/advisories/unreviewed/2022/08/GHSA-c2v8-4gvf-47f7/GHSA-c2v8-4gvf-47f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-g3r5-hp64-fq8f/GHSA-g3r5-hp64-fq8f.json b/advisories/unreviewed/2022/08/GHSA-g3r5-hp64-fq8f/GHSA-g3r5-hp64-fq8f.json index 623df6678ea..bab9592fc27 100644 --- a/advisories/unreviewed/2022/08/GHSA-g3r5-hp64-fq8f/GHSA-g3r5-hp64-fq8f.json +++ b/advisories/unreviewed/2022/08/GHSA-g3r5-hp64-fq8f/GHSA-g3r5-hp64-fq8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-j9g5-qh9r-498w/GHSA-j9g5-qh9r-498w.json b/advisories/unreviewed/2022/08/GHSA-j9g5-qh9r-498w/GHSA-j9g5-qh9r-498w.json index 01ad537bc47..6f51fe6419c 100644 --- a/advisories/unreviewed/2022/08/GHSA-j9g5-qh9r-498w/GHSA-j9g5-qh9r-498w.json +++ b/advisories/unreviewed/2022/08/GHSA-j9g5-qh9r-498w/GHSA-j9g5-qh9r-498w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-95pm-jjw7-hqh8/GHSA-95pm-jjw7-hqh8.json b/advisories/unreviewed/2022/09/GHSA-95pm-jjw7-hqh8/GHSA-95pm-jjw7-hqh8.json index a82fa6488af..98c458611a1 100644 --- a/advisories/unreviewed/2022/09/GHSA-95pm-jjw7-hqh8/GHSA-95pm-jjw7-hqh8.json +++ b/advisories/unreviewed/2022/09/GHSA-95pm-jjw7-hqh8/GHSA-95pm-jjw7-hqh8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-q32v-53r7-3hqv/GHSA-q32v-53r7-3hqv.json b/advisories/unreviewed/2022/09/GHSA-q32v-53r7-3hqv/GHSA-q32v-53r7-3hqv.json index e2fa0ae7ffd..22c20432231 100644 --- a/advisories/unreviewed/2022/09/GHSA-q32v-53r7-3hqv/GHSA-q32v-53r7-3hqv.json +++ b/advisories/unreviewed/2022/09/GHSA-q32v-53r7-3hqv/GHSA-q32v-53r7-3hqv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/12/GHSA-qwm8-3vw5-6956/GHSA-qwm8-3vw5-6956.json b/advisories/unreviewed/2022/12/GHSA-qwm8-3vw5-6956/GHSA-qwm8-3vw5-6956.json index 4bce3edbfd5..dfbd9b82552 100644 --- a/advisories/unreviewed/2022/12/GHSA-qwm8-3vw5-6956/GHSA-qwm8-3vw5-6956.json +++ b/advisories/unreviewed/2022/12/GHSA-qwm8-3vw5-6956/GHSA-qwm8-3vw5-6956.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-prxf-5xrr-96cp/GHSA-prxf-5xrr-96cp.json b/advisories/unreviewed/2023/04/GHSA-prxf-5xrr-96cp/GHSA-prxf-5xrr-96cp.json index 2bd91c7df61..3c9fc1877f7 100644 --- a/advisories/unreviewed/2023/04/GHSA-prxf-5xrr-96cp/GHSA-prxf-5xrr-96cp.json +++ b/advisories/unreviewed/2023/04/GHSA-prxf-5xrr-96cp/GHSA-prxf-5xrr-96cp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-crwp-wqxv-crr4/GHSA-crwp-wqxv-crr4.json b/advisories/unreviewed/2024/03/GHSA-crwp-wqxv-crr4/GHSA-crwp-wqxv-crr4.json index f2d20aa235e..72ca4d8190d 100644 --- a/advisories/unreviewed/2024/03/GHSA-crwp-wqxv-crr4/GHSA-crwp-wqxv-crr4.json +++ b/advisories/unreviewed/2024/03/GHSA-crwp-wqxv-crr4/GHSA-crwp-wqxv-crr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-mr2g-87r5-j9x5/GHSA-mr2g-87r5-j9x5.json b/advisories/unreviewed/2024/04/GHSA-mr2g-87r5-j9x5/GHSA-mr2g-87r5-j9x5.json index b07041cb282..99c5e7d2635 100644 --- a/advisories/unreviewed/2024/04/GHSA-mr2g-87r5-j9x5/GHSA-mr2g-87r5-j9x5.json +++ b/advisories/unreviewed/2024/04/GHSA-mr2g-87r5-j9x5/GHSA-mr2g-87r5-j9x5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-rc4x-jw53-834q/GHSA-rc4x-jw53-834q.json b/advisories/unreviewed/2024/04/GHSA-rc4x-jw53-834q/GHSA-rc4x-jw53-834q.json index 0b690ab865c..b90134e3f2f 100644 --- a/advisories/unreviewed/2024/04/GHSA-rc4x-jw53-834q/GHSA-rc4x-jw53-834q.json +++ b/advisories/unreviewed/2024/04/GHSA-rc4x-jw53-834q/GHSA-rc4x-jw53-834q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json index 6020a198bfa..a4f1d9a9b65 100644 --- a/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json +++ b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-3q86-v8qf-7gw8/GHSA-3q86-v8qf-7gw8.json b/advisories/unreviewed/2024/06/GHSA-3q86-v8qf-7gw8/GHSA-3q86-v8qf-7gw8.json index 49ca7a3e9a2..7397e6ff285 100644 --- a/advisories/unreviewed/2024/06/GHSA-3q86-v8qf-7gw8/GHSA-3q86-v8qf-7gw8.json +++ b/advisories/unreviewed/2024/06/GHSA-3q86-v8qf-7gw8/GHSA-3q86-v8qf-7gw8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-5jrp-h5qf-wgc4/GHSA-5jrp-h5qf-wgc4.json b/advisories/unreviewed/2024/06/GHSA-5jrp-h5qf-wgc4/GHSA-5jrp-h5qf-wgc4.json index b261b073e8a..9bf127f3ae9 100644 --- a/advisories/unreviewed/2024/06/GHSA-5jrp-h5qf-wgc4/GHSA-5jrp-h5qf-wgc4.json +++ b/advisories/unreviewed/2024/06/GHSA-5jrp-h5qf-wgc4/GHSA-5jrp-h5qf-wgc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-6w48-6mx5-8f6c/GHSA-6w48-6mx5-8f6c.json b/advisories/unreviewed/2024/06/GHSA-6w48-6mx5-8f6c/GHSA-6w48-6mx5-8f6c.json index 4bfe883061d..e5e5555a1a3 100644 --- a/advisories/unreviewed/2024/06/GHSA-6w48-6mx5-8f6c/GHSA-6w48-6mx5-8f6c.json +++ b/advisories/unreviewed/2024/06/GHSA-6w48-6mx5-8f6c/GHSA-6w48-6mx5-8f6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-726j-mj58-vjqp/GHSA-726j-mj58-vjqp.json b/advisories/unreviewed/2024/06/GHSA-726j-mj58-vjqp/GHSA-726j-mj58-vjqp.json index 4228d9db5c6..afb114d4101 100644 --- a/advisories/unreviewed/2024/06/GHSA-726j-mj58-vjqp/GHSA-726j-mj58-vjqp.json +++ b/advisories/unreviewed/2024/06/GHSA-726j-mj58-vjqp/GHSA-726j-mj58-vjqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-7jwq-45p5-2xh3/GHSA-7jwq-45p5-2xh3.json b/advisories/unreviewed/2024/06/GHSA-7jwq-45p5-2xh3/GHSA-7jwq-45p5-2xh3.json index 5136221e2d3..bce03785327 100644 --- a/advisories/unreviewed/2024/06/GHSA-7jwq-45p5-2xh3/GHSA-7jwq-45p5-2xh3.json +++ b/advisories/unreviewed/2024/06/GHSA-7jwq-45p5-2xh3/GHSA-7jwq-45p5-2xh3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-8jqr-962c-69rw/GHSA-8jqr-962c-69rw.json b/advisories/unreviewed/2024/06/GHSA-8jqr-962c-69rw/GHSA-8jqr-962c-69rw.json index 55334e4bb92..a605cbdf713 100644 --- a/advisories/unreviewed/2024/06/GHSA-8jqr-962c-69rw/GHSA-8jqr-962c-69rw.json +++ b/advisories/unreviewed/2024/06/GHSA-8jqr-962c-69rw/GHSA-8jqr-962c-69rw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-mj6c-grgr-xq75/GHSA-mj6c-grgr-xq75.json b/advisories/unreviewed/2024/06/GHSA-mj6c-grgr-xq75/GHSA-mj6c-grgr-xq75.json index fd469c004eb..7bc36b66988 100644 --- a/advisories/unreviewed/2024/06/GHSA-mj6c-grgr-xq75/GHSA-mj6c-grgr-xq75.json +++ b/advisories/unreviewed/2024/06/GHSA-mj6c-grgr-xq75/GHSA-mj6c-grgr-xq75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-pw5j-63j7-2mhr/GHSA-pw5j-63j7-2mhr.json b/advisories/unreviewed/2024/06/GHSA-pw5j-63j7-2mhr/GHSA-pw5j-63j7-2mhr.json index 400d967d98a..d262aa3675f 100644 --- a/advisories/unreviewed/2024/06/GHSA-pw5j-63j7-2mhr/GHSA-pw5j-63j7-2mhr.json +++ b/advisories/unreviewed/2024/06/GHSA-pw5j-63j7-2mhr/GHSA-pw5j-63j7-2mhr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-q726-xp8p-hc8g/GHSA-q726-xp8p-hc8g.json b/advisories/unreviewed/2024/06/GHSA-q726-xp8p-hc8g/GHSA-q726-xp8p-hc8g.json index 6540c1ed9ac..58742c2fdfa 100644 --- a/advisories/unreviewed/2024/06/GHSA-q726-xp8p-hc8g/GHSA-q726-xp8p-hc8g.json +++ b/advisories/unreviewed/2024/06/GHSA-q726-xp8p-hc8g/GHSA-q726-xp8p-hc8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-rx3m-g787-cp2f/GHSA-rx3m-g787-cp2f.json b/advisories/unreviewed/2024/06/GHSA-rx3m-g787-cp2f/GHSA-rx3m-g787-cp2f.json index 9db1d02980f..bf75a7b80ba 100644 --- a/advisories/unreviewed/2024/06/GHSA-rx3m-g787-cp2f/GHSA-rx3m-g787-cp2f.json +++ b/advisories/unreviewed/2024/06/GHSA-rx3m-g787-cp2f/GHSA-rx3m-g787-cp2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-v7pg-qx5m-v7x4/GHSA-v7pg-qx5m-v7x4.json b/advisories/unreviewed/2024/06/GHSA-v7pg-qx5m-v7x4/GHSA-v7pg-qx5m-v7x4.json index 880cdb3b35c..5b3ee7b82f7 100644 --- a/advisories/unreviewed/2024/06/GHSA-v7pg-qx5m-v7x4/GHSA-v7pg-qx5m-v7x4.json +++ b/advisories/unreviewed/2024/06/GHSA-v7pg-qx5m-v7x4/GHSA-v7pg-qx5m-v7x4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/06/GHSA-xmvf-wm3q-gh2f/GHSA-xmvf-wm3q-gh2f.json b/advisories/unreviewed/2024/06/GHSA-xmvf-wm3q-gh2f/GHSA-xmvf-wm3q-gh2f.json index 555db21de36..dd79adcb0d4 100644 --- a/advisories/unreviewed/2024/06/GHSA-xmvf-wm3q-gh2f/GHSA-xmvf-wm3q-gh2f.json +++ b/advisories/unreviewed/2024/06/GHSA-xmvf-wm3q-gh2f/GHSA-xmvf-wm3q-gh2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json b/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json index dd59e42fa07..d867a526993 100644 --- a/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json +++ b/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2hxw-2gfv-p3w2/GHSA-2hxw-2gfv-p3w2.json b/advisories/unreviewed/2024/07/GHSA-2hxw-2gfv-p3w2/GHSA-2hxw-2gfv-p3w2.json index 29c6f85d88b..1b5b32b95aa 100644 --- a/advisories/unreviewed/2024/07/GHSA-2hxw-2gfv-p3w2/GHSA-2hxw-2gfv-p3w2.json +++ b/advisories/unreviewed/2024/07/GHSA-2hxw-2gfv-p3w2/GHSA-2hxw-2gfv-p3w2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2m84-pxgc-c9vw/GHSA-2m84-pxgc-c9vw.json b/advisories/unreviewed/2024/07/GHSA-2m84-pxgc-c9vw/GHSA-2m84-pxgc-c9vw.json index aab31fe298f..c74b1f25e23 100644 --- a/advisories/unreviewed/2024/07/GHSA-2m84-pxgc-c9vw/GHSA-2m84-pxgc-c9vw.json +++ b/advisories/unreviewed/2024/07/GHSA-2m84-pxgc-c9vw/GHSA-2m84-pxgc-c9vw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-2xjw-j52v-f7gr/GHSA-2xjw-j52v-f7gr.json b/advisories/unreviewed/2024/07/GHSA-2xjw-j52v-f7gr/GHSA-2xjw-j52v-f7gr.json index 5bd882a3481..bf92c553540 100644 --- a/advisories/unreviewed/2024/07/GHSA-2xjw-j52v-f7gr/GHSA-2xjw-j52v-f7gr.json +++ b/advisories/unreviewed/2024/07/GHSA-2xjw-j52v-f7gr/GHSA-2xjw-j52v-f7gr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-32hm-m24x-pwrg/GHSA-32hm-m24x-pwrg.json b/advisories/unreviewed/2024/07/GHSA-32hm-m24x-pwrg/GHSA-32hm-m24x-pwrg.json index 0f4eaabef9e..2f5826b3c4b 100644 --- a/advisories/unreviewed/2024/07/GHSA-32hm-m24x-pwrg/GHSA-32hm-m24x-pwrg.json +++ b/advisories/unreviewed/2024/07/GHSA-32hm-m24x-pwrg/GHSA-32hm-m24x-pwrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-3vm9-v98f-4rrp/GHSA-3vm9-v98f-4rrp.json b/advisories/unreviewed/2024/07/GHSA-3vm9-v98f-4rrp/GHSA-3vm9-v98f-4rrp.json index ecf1d7c24b0..4feb2574e6c 100644 --- a/advisories/unreviewed/2024/07/GHSA-3vm9-v98f-4rrp/GHSA-3vm9-v98f-4rrp.json +++ b/advisories/unreviewed/2024/07/GHSA-3vm9-v98f-4rrp/GHSA-3vm9-v98f-4rrp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-489r-xxhh-492p/GHSA-489r-xxhh-492p.json b/advisories/unreviewed/2024/07/GHSA-489r-xxhh-492p/GHSA-489r-xxhh-492p.json index 75366c9b25b..a3644f60b06 100644 --- a/advisories/unreviewed/2024/07/GHSA-489r-xxhh-492p/GHSA-489r-xxhh-492p.json +++ b/advisories/unreviewed/2024/07/GHSA-489r-xxhh-492p/GHSA-489r-xxhh-492p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-536f-3wcm-q222/GHSA-536f-3wcm-q222.json b/advisories/unreviewed/2024/07/GHSA-536f-3wcm-q222/GHSA-536f-3wcm-q222.json index 25a6233bf1f..56cdf872ea6 100644 --- a/advisories/unreviewed/2024/07/GHSA-536f-3wcm-q222/GHSA-536f-3wcm-q222.json +++ b/advisories/unreviewed/2024/07/GHSA-536f-3wcm-q222/GHSA-536f-3wcm-q222.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-59gf-g6mr-cr4x/GHSA-59gf-g6mr-cr4x.json b/advisories/unreviewed/2024/07/GHSA-59gf-g6mr-cr4x/GHSA-59gf-g6mr-cr4x.json index 4f33ee0cfb3..d65b03ada8a 100644 --- a/advisories/unreviewed/2024/07/GHSA-59gf-g6mr-cr4x/GHSA-59gf-g6mr-cr4x.json +++ b/advisories/unreviewed/2024/07/GHSA-59gf-g6mr-cr4x/GHSA-59gf-g6mr-cr4x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-5h59-75vf-973c/GHSA-5h59-75vf-973c.json b/advisories/unreviewed/2024/07/GHSA-5h59-75vf-973c/GHSA-5h59-75vf-973c.json index 0b7bdc5b052..f0ca0613af6 100644 --- a/advisories/unreviewed/2024/07/GHSA-5h59-75vf-973c/GHSA-5h59-75vf-973c.json +++ b/advisories/unreviewed/2024/07/GHSA-5h59-75vf-973c/GHSA-5h59-75vf-973c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-789f-c4f8-rfp7/GHSA-789f-c4f8-rfp7.json b/advisories/unreviewed/2024/07/GHSA-789f-c4f8-rfp7/GHSA-789f-c4f8-rfp7.json index 2ad628b8729..ab5c9982d3a 100644 --- a/advisories/unreviewed/2024/07/GHSA-789f-c4f8-rfp7/GHSA-789f-c4f8-rfp7.json +++ b/advisories/unreviewed/2024/07/GHSA-789f-c4f8-rfp7/GHSA-789f-c4f8-rfp7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-7r4w-v667-c6cr/GHSA-7r4w-v667-c6cr.json b/advisories/unreviewed/2024/07/GHSA-7r4w-v667-c6cr/GHSA-7r4w-v667-c6cr.json index 454b476ba63..2e08acc4202 100644 --- a/advisories/unreviewed/2024/07/GHSA-7r4w-v667-c6cr/GHSA-7r4w-v667-c6cr.json +++ b/advisories/unreviewed/2024/07/GHSA-7r4w-v667-c6cr/GHSA-7r4w-v667-c6cr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-8fx4-qfq2-463h/GHSA-8fx4-qfq2-463h.json b/advisories/unreviewed/2024/07/GHSA-8fx4-qfq2-463h/GHSA-8fx4-qfq2-463h.json index b2417a63e29..330714452ac 100644 --- a/advisories/unreviewed/2024/07/GHSA-8fx4-qfq2-463h/GHSA-8fx4-qfq2-463h.json +++ b/advisories/unreviewed/2024/07/GHSA-8fx4-qfq2-463h/GHSA-8fx4-qfq2-463h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-8w32-6chg-qv5f/GHSA-8w32-6chg-qv5f.json b/advisories/unreviewed/2024/07/GHSA-8w32-6chg-qv5f/GHSA-8w32-6chg-qv5f.json index 46def0d8ca2..2429dd05633 100644 --- a/advisories/unreviewed/2024/07/GHSA-8w32-6chg-qv5f/GHSA-8w32-6chg-qv5f.json +++ b/advisories/unreviewed/2024/07/GHSA-8w32-6chg-qv5f/GHSA-8w32-6chg-qv5f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-9gvv-47x2-579h/GHSA-9gvv-47x2-579h.json b/advisories/unreviewed/2024/07/GHSA-9gvv-47x2-579h/GHSA-9gvv-47x2-579h.json index abc87990f30..1abb6f1812b 100644 --- a/advisories/unreviewed/2024/07/GHSA-9gvv-47x2-579h/GHSA-9gvv-47x2-579h.json +++ b/advisories/unreviewed/2024/07/GHSA-9gvv-47x2-579h/GHSA-9gvv-47x2-579h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-c2r9-6vp5-5wv7/GHSA-c2r9-6vp5-5wv7.json b/advisories/unreviewed/2024/07/GHSA-c2r9-6vp5-5wv7/GHSA-c2r9-6vp5-5wv7.json index f4750e0d102..639550e1ddd 100644 --- a/advisories/unreviewed/2024/07/GHSA-c2r9-6vp5-5wv7/GHSA-c2r9-6vp5-5wv7.json +++ b/advisories/unreviewed/2024/07/GHSA-c2r9-6vp5-5wv7/GHSA-c2r9-6vp5-5wv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-f8f7-g44v-jxm9/GHSA-f8f7-g44v-jxm9.json b/advisories/unreviewed/2024/07/GHSA-f8f7-g44v-jxm9/GHSA-f8f7-g44v-jxm9.json index 26d9d1809b8..9eda105a4ec 100644 --- a/advisories/unreviewed/2024/07/GHSA-f8f7-g44v-jxm9/GHSA-f8f7-g44v-jxm9.json +++ b/advisories/unreviewed/2024/07/GHSA-f8f7-g44v-jxm9/GHSA-f8f7-g44v-jxm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-g434-vgfp-rh6m/GHSA-g434-vgfp-rh6m.json b/advisories/unreviewed/2024/07/GHSA-g434-vgfp-rh6m/GHSA-g434-vgfp-rh6m.json index 16a66d0b6b6..5b10703c659 100644 --- a/advisories/unreviewed/2024/07/GHSA-g434-vgfp-rh6m/GHSA-g434-vgfp-rh6m.json +++ b/advisories/unreviewed/2024/07/GHSA-g434-vgfp-rh6m/GHSA-g434-vgfp-rh6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json b/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json index abd11008b07..85ffcaa1887 100644 --- a/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json +++ b/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-gm77-v33h-cghm/GHSA-gm77-v33h-cghm.json b/advisories/unreviewed/2024/07/GHSA-gm77-v33h-cghm/GHSA-gm77-v33h-cghm.json index c06a461ddb4..c0e1bbcee63 100644 --- a/advisories/unreviewed/2024/07/GHSA-gm77-v33h-cghm/GHSA-gm77-v33h-cghm.json +++ b/advisories/unreviewed/2024/07/GHSA-gm77-v33h-cghm/GHSA-gm77-v33h-cghm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-gw8p-7jqv-5v6x/GHSA-gw8p-7jqv-5v6x.json b/advisories/unreviewed/2024/07/GHSA-gw8p-7jqv-5v6x/GHSA-gw8p-7jqv-5v6x.json index 0bfe4c1c4e7..cd9772b350b 100644 --- a/advisories/unreviewed/2024/07/GHSA-gw8p-7jqv-5v6x/GHSA-gw8p-7jqv-5v6x.json +++ b/advisories/unreviewed/2024/07/GHSA-gw8p-7jqv-5v6x/GHSA-gw8p-7jqv-5v6x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json b/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json index a812522f97d..7edb013133a 100644 --- a/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json +++ b/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-j3c9-j8gj-cwrv/GHSA-j3c9-j8gj-cwrv.json b/advisories/unreviewed/2024/07/GHSA-j3c9-j8gj-cwrv/GHSA-j3c9-j8gj-cwrv.json index 787cf802eb5..9ccd276af6b 100644 --- a/advisories/unreviewed/2024/07/GHSA-j3c9-j8gj-cwrv/GHSA-j3c9-j8gj-cwrv.json +++ b/advisories/unreviewed/2024/07/GHSA-j3c9-j8gj-cwrv/GHSA-j3c9-j8gj-cwrv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-jgc6-c9v8-vfqw/GHSA-jgc6-c9v8-vfqw.json b/advisories/unreviewed/2024/07/GHSA-jgc6-c9v8-vfqw/GHSA-jgc6-c9v8-vfqw.json index 5a5587fa126..e1d1b3a9ec7 100644 --- a/advisories/unreviewed/2024/07/GHSA-jgc6-c9v8-vfqw/GHSA-jgc6-c9v8-vfqw.json +++ b/advisories/unreviewed/2024/07/GHSA-jgc6-c9v8-vfqw/GHSA-jgc6-c9v8-vfqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-m84w-3jq7-hjcm/GHSA-m84w-3jq7-hjcm.json b/advisories/unreviewed/2024/07/GHSA-m84w-3jq7-hjcm/GHSA-m84w-3jq7-hjcm.json index 24e9976d397..44903c3defe 100644 --- a/advisories/unreviewed/2024/07/GHSA-m84w-3jq7-hjcm/GHSA-m84w-3jq7-hjcm.json +++ b/advisories/unreviewed/2024/07/GHSA-m84w-3jq7-hjcm/GHSA-m84w-3jq7-hjcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-mgpw-5w39-9553/GHSA-mgpw-5w39-9553.json b/advisories/unreviewed/2024/07/GHSA-mgpw-5w39-9553/GHSA-mgpw-5w39-9553.json index 5c2c443ac27..9d6116081ae 100644 --- a/advisories/unreviewed/2024/07/GHSA-mgpw-5w39-9553/GHSA-mgpw-5w39-9553.json +++ b/advisories/unreviewed/2024/07/GHSA-mgpw-5w39-9553/GHSA-mgpw-5w39-9553.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-phwx-77rv-743g/GHSA-phwx-77rv-743g.json b/advisories/unreviewed/2024/07/GHSA-phwx-77rv-743g/GHSA-phwx-77rv-743g.json index 6765b0203b5..2ece6257579 100644 --- a/advisories/unreviewed/2024/07/GHSA-phwx-77rv-743g/GHSA-phwx-77rv-743g.json +++ b/advisories/unreviewed/2024/07/GHSA-phwx-77rv-743g/GHSA-phwx-77rv-743g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-ppc6-pqcq-584g/GHSA-ppc6-pqcq-584g.json b/advisories/unreviewed/2024/07/GHSA-ppc6-pqcq-584g/GHSA-ppc6-pqcq-584g.json index 310c1afc546..44bd2915d5a 100644 --- a/advisories/unreviewed/2024/07/GHSA-ppc6-pqcq-584g/GHSA-ppc6-pqcq-584g.json +++ b/advisories/unreviewed/2024/07/GHSA-ppc6-pqcq-584g/GHSA-ppc6-pqcq-584g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-rmpr-6w5x-hf6g/GHSA-rmpr-6w5x-hf6g.json b/advisories/unreviewed/2024/07/GHSA-rmpr-6w5x-hf6g/GHSA-rmpr-6w5x-hf6g.json index 48a7072d09a..b6e6d63a7b0 100644 --- a/advisories/unreviewed/2024/07/GHSA-rmpr-6w5x-hf6g/GHSA-rmpr-6w5x-hf6g.json +++ b/advisories/unreviewed/2024/07/GHSA-rmpr-6w5x-hf6g/GHSA-rmpr-6w5x-hf6g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-vf3w-mp85-cvwc/GHSA-vf3w-mp85-cvwc.json b/advisories/unreviewed/2024/07/GHSA-vf3w-mp85-cvwc/GHSA-vf3w-mp85-cvwc.json index dea49b5f73a..7ebec36bee1 100644 --- a/advisories/unreviewed/2024/07/GHSA-vf3w-mp85-cvwc/GHSA-vf3w-mp85-cvwc.json +++ b/advisories/unreviewed/2024/07/GHSA-vf3w-mp85-cvwc/GHSA-vf3w-mp85-cvwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-vjrw-gxxj-h5j4/GHSA-vjrw-gxxj-h5j4.json b/advisories/unreviewed/2024/07/GHSA-vjrw-gxxj-h5j4/GHSA-vjrw-gxxj-h5j4.json index 3fce2d5e1a9..dd3e0ab6add 100644 --- a/advisories/unreviewed/2024/07/GHSA-vjrw-gxxj-h5j4/GHSA-vjrw-gxxj-h5j4.json +++ b/advisories/unreviewed/2024/07/GHSA-vjrw-gxxj-h5j4/GHSA-vjrw-gxxj-h5j4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json b/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json index 6cc82a56fdd..d78fba7819a 100644 --- a/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json +++ b/advisories/unreviewed/2024/07/GHSA-vqfv-6vgr-3j88/GHSA-vqfv-6vgr-3j88.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json b/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json index 93a45b17d70..4e3864c9b3d 100644 --- a/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json +++ b/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-whqg-8c4f-4gwx/GHSA-whqg-8c4f-4gwx.json b/advisories/unreviewed/2024/07/GHSA-whqg-8c4f-4gwx/GHSA-whqg-8c4f-4gwx.json index a488894bb17..0fa69a56018 100644 --- a/advisories/unreviewed/2024/07/GHSA-whqg-8c4f-4gwx/GHSA-whqg-8c4f-4gwx.json +++ b/advisories/unreviewed/2024/07/GHSA-whqg-8c4f-4gwx/GHSA-whqg-8c4f-4gwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/07/GHSA-xgxh-897r-pw22/GHSA-xgxh-897r-pw22.json b/advisories/unreviewed/2024/07/GHSA-xgxh-897r-pw22/GHSA-xgxh-897r-pw22.json index df8c1016aa2..17d74d62319 100644 --- a/advisories/unreviewed/2024/07/GHSA-xgxh-897r-pw22/GHSA-xgxh-897r-pw22.json +++ b/advisories/unreviewed/2024/07/GHSA-xgxh-897r-pw22/GHSA-xgxh-897r-pw22.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-29j3-7mhp-wmwm/GHSA-29j3-7mhp-wmwm.json b/advisories/unreviewed/2024/08/GHSA-29j3-7mhp-wmwm/GHSA-29j3-7mhp-wmwm.json index 5e0c6e6380c..841301dbf9f 100644 --- a/advisories/unreviewed/2024/08/GHSA-29j3-7mhp-wmwm/GHSA-29j3-7mhp-wmwm.json +++ b/advisories/unreviewed/2024/08/GHSA-29j3-7mhp-wmwm/GHSA-29j3-7mhp-wmwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-2hfc-mfgr-3gpf/GHSA-2hfc-mfgr-3gpf.json b/advisories/unreviewed/2024/08/GHSA-2hfc-mfgr-3gpf/GHSA-2hfc-mfgr-3gpf.json index e2c9bbbc518..00f1a6c4769 100644 --- a/advisories/unreviewed/2024/08/GHSA-2hfc-mfgr-3gpf/GHSA-2hfc-mfgr-3gpf.json +++ b/advisories/unreviewed/2024/08/GHSA-2hfc-mfgr-3gpf/GHSA-2hfc-mfgr-3gpf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3fpr-5fgv-65vg/GHSA-3fpr-5fgv-65vg.json b/advisories/unreviewed/2024/08/GHSA-3fpr-5fgv-65vg/GHSA-3fpr-5fgv-65vg.json index baa98f5df7d..cfdf9339a95 100644 --- a/advisories/unreviewed/2024/08/GHSA-3fpr-5fgv-65vg/GHSA-3fpr-5fgv-65vg.json +++ b/advisories/unreviewed/2024/08/GHSA-3fpr-5fgv-65vg/GHSA-3fpr-5fgv-65vg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3qp2-9c8g-2g8x/GHSA-3qp2-9c8g-2g8x.json b/advisories/unreviewed/2024/08/GHSA-3qp2-9c8g-2g8x/GHSA-3qp2-9c8g-2g8x.json index 176d9ef4446..45ba8d95f41 100644 --- a/advisories/unreviewed/2024/08/GHSA-3qp2-9c8g-2g8x/GHSA-3qp2-9c8g-2g8x.json +++ b/advisories/unreviewed/2024/08/GHSA-3qp2-9c8g-2g8x/GHSA-3qp2-9c8g-2g8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-3rvv-226f-xrr5/GHSA-3rvv-226f-xrr5.json b/advisories/unreviewed/2024/08/GHSA-3rvv-226f-xrr5/GHSA-3rvv-226f-xrr5.json index 0bb16ce9147..e1f29dbf31a 100644 --- a/advisories/unreviewed/2024/08/GHSA-3rvv-226f-xrr5/GHSA-3rvv-226f-xrr5.json +++ b/advisories/unreviewed/2024/08/GHSA-3rvv-226f-xrr5/GHSA-3rvv-226f-xrr5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-4j2j-4gr5-gr6h/GHSA-4j2j-4gr5-gr6h.json b/advisories/unreviewed/2024/08/GHSA-4j2j-4gr5-gr6h/GHSA-4j2j-4gr5-gr6h.json index 5467ed94986..7f93e2328e5 100644 --- a/advisories/unreviewed/2024/08/GHSA-4j2j-4gr5-gr6h/GHSA-4j2j-4gr5-gr6h.json +++ b/advisories/unreviewed/2024/08/GHSA-4j2j-4gr5-gr6h/GHSA-4j2j-4gr5-gr6h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-8hj3-fhcj-rg42/GHSA-8hj3-fhcj-rg42.json b/advisories/unreviewed/2024/08/GHSA-8hj3-fhcj-rg42/GHSA-8hj3-fhcj-rg42.json index 76ce2b65bcd..b6f1fae8627 100644 --- a/advisories/unreviewed/2024/08/GHSA-8hj3-fhcj-rg42/GHSA-8hj3-fhcj-rg42.json +++ b/advisories/unreviewed/2024/08/GHSA-8hj3-fhcj-rg42/GHSA-8hj3-fhcj-rg42.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-9m45-g52w-xm9x/GHSA-9m45-g52w-xm9x.json b/advisories/unreviewed/2024/08/GHSA-9m45-g52w-xm9x/GHSA-9m45-g52w-xm9x.json index 7bf1e45ee3a..9d5f2b42456 100644 --- a/advisories/unreviewed/2024/08/GHSA-9m45-g52w-xm9x/GHSA-9m45-g52w-xm9x.json +++ b/advisories/unreviewed/2024/08/GHSA-9m45-g52w-xm9x/GHSA-9m45-g52w-xm9x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json b/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json index e13cd4e6126..504a123c28d 100644 --- a/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json +++ b/advisories/unreviewed/2024/08/GHSA-cmmr-cc39-65m3/GHSA-cmmr-cc39-65m3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-cqcg-4g39-cjvj/GHSA-cqcg-4g39-cjvj.json b/advisories/unreviewed/2024/08/GHSA-cqcg-4g39-cjvj/GHSA-cqcg-4g39-cjvj.json index 5089b10259b..6eb38f03d5e 100644 --- a/advisories/unreviewed/2024/08/GHSA-cqcg-4g39-cjvj/GHSA-cqcg-4g39-cjvj.json +++ b/advisories/unreviewed/2024/08/GHSA-cqcg-4g39-cjvj/GHSA-cqcg-4g39-cjvj.json @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-cqm6-fcfw-pfm3/GHSA-cqm6-fcfw-pfm3.json b/advisories/unreviewed/2024/08/GHSA-cqm6-fcfw-pfm3/GHSA-cqm6-fcfw-pfm3.json index a1901040f76..34563186ecc 100644 --- a/advisories/unreviewed/2024/08/GHSA-cqm6-fcfw-pfm3/GHSA-cqm6-fcfw-pfm3.json +++ b/advisories/unreviewed/2024/08/GHSA-cqm6-fcfw-pfm3/GHSA-cqm6-fcfw-pfm3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-cx25-3m56-wvfv/GHSA-cx25-3m56-wvfv.json b/advisories/unreviewed/2024/08/GHSA-cx25-3m56-wvfv/GHSA-cx25-3m56-wvfv.json index 893cb3f6654..cfd110ed049 100644 --- a/advisories/unreviewed/2024/08/GHSA-cx25-3m56-wvfv/GHSA-cx25-3m56-wvfv.json +++ b/advisories/unreviewed/2024/08/GHSA-cx25-3m56-wvfv/GHSA-cx25-3m56-wvfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-f6q3-hjwj-2j45/GHSA-f6q3-hjwj-2j45.json b/advisories/unreviewed/2024/08/GHSA-f6q3-hjwj-2j45/GHSA-f6q3-hjwj-2j45.json index 46d982830b6..f4413e2123f 100644 --- a/advisories/unreviewed/2024/08/GHSA-f6q3-hjwj-2j45/GHSA-f6q3-hjwj-2j45.json +++ b/advisories/unreviewed/2024/08/GHSA-f6q3-hjwj-2j45/GHSA-f6q3-hjwj-2j45.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json b/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json index bf852c713cd..747568c6e3e 100644 --- a/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json +++ b/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-mh6c-x63v-xvfr/GHSA-mh6c-x63v-xvfr.json b/advisories/unreviewed/2024/08/GHSA-mh6c-x63v-xvfr/GHSA-mh6c-x63v-xvfr.json index c8b668288a6..68aa1fef247 100644 --- a/advisories/unreviewed/2024/08/GHSA-mh6c-x63v-xvfr/GHSA-mh6c-x63v-xvfr.json +++ b/advisories/unreviewed/2024/08/GHSA-mh6c-x63v-xvfr/GHSA-mh6c-x63v-xvfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-p844-wjq6-m36r/GHSA-p844-wjq6-m36r.json b/advisories/unreviewed/2024/08/GHSA-p844-wjq6-m36r/GHSA-p844-wjq6-m36r.json index df1f501de5b..ec6a7501867 100644 --- a/advisories/unreviewed/2024/08/GHSA-p844-wjq6-m36r/GHSA-p844-wjq6-m36r.json +++ b/advisories/unreviewed/2024/08/GHSA-p844-wjq6-m36r/GHSA-p844-wjq6-m36r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-q46j-26g9-j9w4/GHSA-q46j-26g9-j9w4.json b/advisories/unreviewed/2024/08/GHSA-q46j-26g9-j9w4/GHSA-q46j-26g9-j9w4.json index 94ac33a247c..73eab3b9dab 100644 --- a/advisories/unreviewed/2024/08/GHSA-q46j-26g9-j9w4/GHSA-q46j-26g9-j9w4.json +++ b/advisories/unreviewed/2024/08/GHSA-q46j-26g9-j9w4/GHSA-q46j-26g9-j9w4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qv3m-79fc-wfwf/GHSA-qv3m-79fc-wfwf.json b/advisories/unreviewed/2024/08/GHSA-qv3m-79fc-wfwf/GHSA-qv3m-79fc-wfwf.json index 06587d6afc0..ec811528954 100644 --- a/advisories/unreviewed/2024/08/GHSA-qv3m-79fc-wfwf/GHSA-qv3m-79fc-wfwf.json +++ b/advisories/unreviewed/2024/08/GHSA-qv3m-79fc-wfwf/GHSA-qv3m-79fc-wfwf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-qx3j-rj87-66pj/GHSA-qx3j-rj87-66pj.json b/advisories/unreviewed/2024/08/GHSA-qx3j-rj87-66pj/GHSA-qx3j-rj87-66pj.json index 52f03b14907..ff6753496e3 100644 --- a/advisories/unreviewed/2024/08/GHSA-qx3j-rj87-66pj/GHSA-qx3j-rj87-66pj.json +++ b/advisories/unreviewed/2024/08/GHSA-qx3j-rj87-66pj/GHSA-qx3j-rj87-66pj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json b/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json index ce06a018bb4..b0ff716ef28 100644 --- a/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json +++ b/advisories/unreviewed/2024/08/GHSA-vh6j-6rmm-669j/GHSA-vh6j-6rmm-669j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-vjwj-m2x7-8w7q/GHSA-vjwj-m2x7-8w7q.json b/advisories/unreviewed/2024/08/GHSA-vjwj-m2x7-8w7q/GHSA-vjwj-m2x7-8w7q.json index 40fc591c4a5..02d73c80fe9 100644 --- a/advisories/unreviewed/2024/08/GHSA-vjwj-m2x7-8w7q/GHSA-vjwj-m2x7-8w7q.json +++ b/advisories/unreviewed/2024/08/GHSA-vjwj-m2x7-8w7q/GHSA-vjwj-m2x7-8w7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-whp4-jh65-8472/GHSA-whp4-jh65-8472.json b/advisories/unreviewed/2024/08/GHSA-whp4-jh65-8472/GHSA-whp4-jh65-8472.json index 3eb4c1d7af1..3dc9ecdcb35 100644 --- a/advisories/unreviewed/2024/08/GHSA-whp4-jh65-8472/GHSA-whp4-jh65-8472.json +++ b/advisories/unreviewed/2024/08/GHSA-whp4-jh65-8472/GHSA-whp4-jh65-8472.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-wxcq-86jx-7hv5/GHSA-wxcq-86jx-7hv5.json b/advisories/unreviewed/2024/08/GHSA-wxcq-86jx-7hv5/GHSA-wxcq-86jx-7hv5.json index 4448d358b4b..e09ccdeeaa3 100644 --- a/advisories/unreviewed/2024/08/GHSA-wxcq-86jx-7hv5/GHSA-wxcq-86jx-7hv5.json +++ b/advisories/unreviewed/2024/08/GHSA-wxcq-86jx-7hv5/GHSA-wxcq-86jx-7hv5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/08/GHSA-xpcc-5cmh-qxxp/GHSA-xpcc-5cmh-qxxp.json b/advisories/unreviewed/2024/08/GHSA-xpcc-5cmh-qxxp/GHSA-xpcc-5cmh-qxxp.json index caa41f01ccd..1a612a64b6e 100644 --- a/advisories/unreviewed/2024/08/GHSA-xpcc-5cmh-qxxp/GHSA-xpcc-5cmh-qxxp.json +++ b/advisories/unreviewed/2024/08/GHSA-xpcc-5cmh-qxxp/GHSA-xpcc-5cmh-qxxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-p7wm-h6q7-mx95/GHSA-p7wm-h6q7-mx95.json b/advisories/unreviewed/2024/09/GHSA-p7wm-h6q7-mx95/GHSA-p7wm-h6q7-mx95.json index 9251a4bc467..8e5afcabf87 100644 --- a/advisories/unreviewed/2024/09/GHSA-p7wm-h6q7-mx95/GHSA-p7wm-h6q7-mx95.json +++ b/advisories/unreviewed/2024/09/GHSA-p7wm-h6q7-mx95/GHSA-p7wm-h6q7-mx95.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/09/GHSA-rvhr-9pp2-823m/GHSA-rvhr-9pp2-823m.json b/advisories/unreviewed/2024/09/GHSA-rvhr-9pp2-823m/GHSA-rvhr-9pp2-823m.json index 2e90c422944..791af9dda70 100644 --- a/advisories/unreviewed/2024/09/GHSA-rvhr-9pp2-823m/GHSA-rvhr-9pp2-823m.json +++ b/advisories/unreviewed/2024/09/GHSA-rvhr-9pp2-823m/GHSA-rvhr-9pp2-823m.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-2252-mjp4-2v5j/GHSA-2252-mjp4-2v5j.json b/advisories/unreviewed/2024/10/GHSA-2252-mjp4-2v5j/GHSA-2252-mjp4-2v5j.json index 6b1a845faad..12b338df055 100644 --- a/advisories/unreviewed/2024/10/GHSA-2252-mjp4-2v5j/GHSA-2252-mjp4-2v5j.json +++ b/advisories/unreviewed/2024/10/GHSA-2252-mjp4-2v5j/GHSA-2252-mjp4-2v5j.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-23p5-23pm-xvp3/GHSA-23p5-23pm-xvp3.json b/advisories/unreviewed/2024/10/GHSA-23p5-23pm-xvp3/GHSA-23p5-23pm-xvp3.json index 071f920cc1d..792058eea1f 100644 --- a/advisories/unreviewed/2024/10/GHSA-23p5-23pm-xvp3/GHSA-23p5-23pm-xvp3.json +++ b/advisories/unreviewed/2024/10/GHSA-23p5-23pm-xvp3/GHSA-23p5-23pm-xvp3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-2xch-4r76-8cgw/GHSA-2xch-4r76-8cgw.json b/advisories/unreviewed/2024/10/GHSA-2xch-4r76-8cgw/GHSA-2xch-4r76-8cgw.json index 1bbe5b8ca05..681abae0de4 100644 --- a/advisories/unreviewed/2024/10/GHSA-2xch-4r76-8cgw/GHSA-2xch-4r76-8cgw.json +++ b/advisories/unreviewed/2024/10/GHSA-2xch-4r76-8cgw/GHSA-2xch-4r76-8cgw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-379f-cj7p-7fjj/GHSA-379f-cj7p-7fjj.json b/advisories/unreviewed/2024/10/GHSA-379f-cj7p-7fjj/GHSA-379f-cj7p-7fjj.json index eddfb748bc7..cae5f436bf0 100644 --- a/advisories/unreviewed/2024/10/GHSA-379f-cj7p-7fjj/GHSA-379f-cj7p-7fjj.json +++ b/advisories/unreviewed/2024/10/GHSA-379f-cj7p-7fjj/GHSA-379f-cj7p-7fjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-38wc-25cg-5x9w/GHSA-38wc-25cg-5x9w.json b/advisories/unreviewed/2024/10/GHSA-38wc-25cg-5x9w/GHSA-38wc-25cg-5x9w.json index cbbc3bdc328..c6f593bfa78 100644 --- a/advisories/unreviewed/2024/10/GHSA-38wc-25cg-5x9w/GHSA-38wc-25cg-5x9w.json +++ b/advisories/unreviewed/2024/10/GHSA-38wc-25cg-5x9w/GHSA-38wc-25cg-5x9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-3fv7-c5v3-xv9m/GHSA-3fv7-c5v3-xv9m.json b/advisories/unreviewed/2024/10/GHSA-3fv7-c5v3-xv9m/GHSA-3fv7-c5v3-xv9m.json index 2749f560090..8960f45ba47 100644 --- a/advisories/unreviewed/2024/10/GHSA-3fv7-c5v3-xv9m/GHSA-3fv7-c5v3-xv9m.json +++ b/advisories/unreviewed/2024/10/GHSA-3fv7-c5v3-xv9m/GHSA-3fv7-c5v3-xv9m.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-3j33-rhmh-72pg/GHSA-3j33-rhmh-72pg.json b/advisories/unreviewed/2024/10/GHSA-3j33-rhmh-72pg/GHSA-3j33-rhmh-72pg.json index bbbe0fd0e69..7caa221eaa9 100644 --- a/advisories/unreviewed/2024/10/GHSA-3j33-rhmh-72pg/GHSA-3j33-rhmh-72pg.json +++ b/advisories/unreviewed/2024/10/GHSA-3j33-rhmh-72pg/GHSA-3j33-rhmh-72pg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-3v49-pp4c-p3j5/GHSA-3v49-pp4c-p3j5.json b/advisories/unreviewed/2024/10/GHSA-3v49-pp4c-p3j5/GHSA-3v49-pp4c-p3j5.json index 3dce8452ce8..8d265303e2e 100644 --- a/advisories/unreviewed/2024/10/GHSA-3v49-pp4c-p3j5/GHSA-3v49-pp4c-p3j5.json +++ b/advisories/unreviewed/2024/10/GHSA-3v49-pp4c-p3j5/GHSA-3v49-pp4c-p3j5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-3x9w-fg96-5j98/GHSA-3x9w-fg96-5j98.json b/advisories/unreviewed/2024/10/GHSA-3x9w-fg96-5j98/GHSA-3x9w-fg96-5j98.json index d226177975a..b5740915724 100644 --- a/advisories/unreviewed/2024/10/GHSA-3x9w-fg96-5j98/GHSA-3x9w-fg96-5j98.json +++ b/advisories/unreviewed/2024/10/GHSA-3x9w-fg96-5j98/GHSA-3x9w-fg96-5j98.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-3xm8-g6r2-j83f/GHSA-3xm8-g6r2-j83f.json b/advisories/unreviewed/2024/10/GHSA-3xm8-g6r2-j83f/GHSA-3xm8-g6r2-j83f.json index a8f066845c0..9a7d9ebe499 100644 --- a/advisories/unreviewed/2024/10/GHSA-3xm8-g6r2-j83f/GHSA-3xm8-g6r2-j83f.json +++ b/advisories/unreviewed/2024/10/GHSA-3xm8-g6r2-j83f/GHSA-3xm8-g6r2-j83f.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-48m6-ppwj-w9gv/GHSA-48m6-ppwj-w9gv.json b/advisories/unreviewed/2024/10/GHSA-48m6-ppwj-w9gv/GHSA-48m6-ppwj-w9gv.json index 3136acfdb74..ee67fb62646 100644 --- a/advisories/unreviewed/2024/10/GHSA-48m6-ppwj-w9gv/GHSA-48m6-ppwj-w9gv.json +++ b/advisories/unreviewed/2024/10/GHSA-48m6-ppwj-w9gv/GHSA-48m6-ppwj-w9gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-5c3g-gw2g-j2h9/GHSA-5c3g-gw2g-j2h9.json b/advisories/unreviewed/2024/10/GHSA-5c3g-gw2g-j2h9/GHSA-5c3g-gw2g-j2h9.json index 694169d67c7..45cefd7b2bf 100644 --- a/advisories/unreviewed/2024/10/GHSA-5c3g-gw2g-j2h9/GHSA-5c3g-gw2g-j2h9.json +++ b/advisories/unreviewed/2024/10/GHSA-5c3g-gw2g-j2h9/GHSA-5c3g-gw2g-j2h9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-5h9r-8hc8-mvf6/GHSA-5h9r-8hc8-mvf6.json b/advisories/unreviewed/2024/10/GHSA-5h9r-8hc8-mvf6/GHSA-5h9r-8hc8-mvf6.json index 9dc92426ccb..68cd710823a 100644 --- a/advisories/unreviewed/2024/10/GHSA-5h9r-8hc8-mvf6/GHSA-5h9r-8hc8-mvf6.json +++ b/advisories/unreviewed/2024/10/GHSA-5h9r-8hc8-mvf6/GHSA-5h9r-8hc8-mvf6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-5jvv-5359-4v99/GHSA-5jvv-5359-4v99.json b/advisories/unreviewed/2024/10/GHSA-5jvv-5359-4v99/GHSA-5jvv-5359-4v99.json index dbd0d63ebb2..9fcdc073499 100644 --- a/advisories/unreviewed/2024/10/GHSA-5jvv-5359-4v99/GHSA-5jvv-5359-4v99.json +++ b/advisories/unreviewed/2024/10/GHSA-5jvv-5359-4v99/GHSA-5jvv-5359-4v99.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-5qw9-r654-q6hr/GHSA-5qw9-r654-q6hr.json b/advisories/unreviewed/2024/10/GHSA-5qw9-r654-q6hr/GHSA-5qw9-r654-q6hr.json index 3fe7d9c10e1..8ec6fa8eff1 100644 --- a/advisories/unreviewed/2024/10/GHSA-5qw9-r654-q6hr/GHSA-5qw9-r654-q6hr.json +++ b/advisories/unreviewed/2024/10/GHSA-5qw9-r654-q6hr/GHSA-5qw9-r654-q6hr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-5rpr-c4q4-7p3w/GHSA-5rpr-c4q4-7p3w.json b/advisories/unreviewed/2024/10/GHSA-5rpr-c4q4-7p3w/GHSA-5rpr-c4q4-7p3w.json index 6ba57702ddf..2758d5ef8cd 100644 --- a/advisories/unreviewed/2024/10/GHSA-5rpr-c4q4-7p3w/GHSA-5rpr-c4q4-7p3w.json +++ b/advisories/unreviewed/2024/10/GHSA-5rpr-c4q4-7p3w/GHSA-5rpr-c4q4-7p3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-5vpx-jjww-7m7g/GHSA-5vpx-jjww-7m7g.json b/advisories/unreviewed/2024/10/GHSA-5vpx-jjww-7m7g/GHSA-5vpx-jjww-7m7g.json index 4f2cedd1dd1..a72106db461 100644 --- a/advisories/unreviewed/2024/10/GHSA-5vpx-jjww-7m7g/GHSA-5vpx-jjww-7m7g.json +++ b/advisories/unreviewed/2024/10/GHSA-5vpx-jjww-7m7g/GHSA-5vpx-jjww-7m7g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-65j2-63g4-wq84/GHSA-65j2-63g4-wq84.json b/advisories/unreviewed/2024/10/GHSA-65j2-63g4-wq84/GHSA-65j2-63g4-wq84.json index 12079cd7523..8339f84a333 100644 --- a/advisories/unreviewed/2024/10/GHSA-65j2-63g4-wq84/GHSA-65j2-63g4-wq84.json +++ b/advisories/unreviewed/2024/10/GHSA-65j2-63g4-wq84/GHSA-65j2-63g4-wq84.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-698q-p785-rxxv/GHSA-698q-p785-rxxv.json b/advisories/unreviewed/2024/10/GHSA-698q-p785-rxxv/GHSA-698q-p785-rxxv.json index c100b88cda3..4d474a1f582 100644 --- a/advisories/unreviewed/2024/10/GHSA-698q-p785-rxxv/GHSA-698q-p785-rxxv.json +++ b/advisories/unreviewed/2024/10/GHSA-698q-p785-rxxv/GHSA-698q-p785-rxxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-6f2g-f8p6-xq23/GHSA-6f2g-f8p6-xq23.json b/advisories/unreviewed/2024/10/GHSA-6f2g-f8p6-xq23/GHSA-6f2g-f8p6-xq23.json index 340b1f96b9e..0f1fc9c6a74 100644 --- a/advisories/unreviewed/2024/10/GHSA-6f2g-f8p6-xq23/GHSA-6f2g-f8p6-xq23.json +++ b/advisories/unreviewed/2024/10/GHSA-6f2g-f8p6-xq23/GHSA-6f2g-f8p6-xq23.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-6qp8-6rcj-28rx/GHSA-6qp8-6rcj-28rx.json b/advisories/unreviewed/2024/10/GHSA-6qp8-6rcj-28rx/GHSA-6qp8-6rcj-28rx.json index 636ee79ca16..1f350eb07fb 100644 --- a/advisories/unreviewed/2024/10/GHSA-6qp8-6rcj-28rx/GHSA-6qp8-6rcj-28rx.json +++ b/advisories/unreviewed/2024/10/GHSA-6qp8-6rcj-28rx/GHSA-6qp8-6rcj-28rx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-6qpx-rmj4-mcj5/GHSA-6qpx-rmj4-mcj5.json b/advisories/unreviewed/2024/10/GHSA-6qpx-rmj4-mcj5/GHSA-6qpx-rmj4-mcj5.json index 501c3154882..0eae1202f2d 100644 --- a/advisories/unreviewed/2024/10/GHSA-6qpx-rmj4-mcj5/GHSA-6qpx-rmj4-mcj5.json +++ b/advisories/unreviewed/2024/10/GHSA-6qpx-rmj4-mcj5/GHSA-6qpx-rmj4-mcj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-76mc-phc3-p6jq/GHSA-76mc-phc3-p6jq.json b/advisories/unreviewed/2024/10/GHSA-76mc-phc3-p6jq/GHSA-76mc-phc3-p6jq.json index b0d30916728..6f560266e09 100644 --- a/advisories/unreviewed/2024/10/GHSA-76mc-phc3-p6jq/GHSA-76mc-phc3-p6jq.json +++ b/advisories/unreviewed/2024/10/GHSA-76mc-phc3-p6jq/GHSA-76mc-phc3-p6jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-7jh9-v3vw-v9px/GHSA-7jh9-v3vw-v9px.json b/advisories/unreviewed/2024/10/GHSA-7jh9-v3vw-v9px/GHSA-7jh9-v3vw-v9px.json index 42d0a4f2b95..417c5029c9b 100644 --- a/advisories/unreviewed/2024/10/GHSA-7jh9-v3vw-v9px/GHSA-7jh9-v3vw-v9px.json +++ b/advisories/unreviewed/2024/10/GHSA-7jh9-v3vw-v9px/GHSA-7jh9-v3vw-v9px.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-7pc6-64hm-2g2w/GHSA-7pc6-64hm-2g2w.json b/advisories/unreviewed/2024/10/GHSA-7pc6-64hm-2g2w/GHSA-7pc6-64hm-2g2w.json index 9ae7d43c995..eaaf8e8743a 100644 --- a/advisories/unreviewed/2024/10/GHSA-7pc6-64hm-2g2w/GHSA-7pc6-64hm-2g2w.json +++ b/advisories/unreviewed/2024/10/GHSA-7pc6-64hm-2g2w/GHSA-7pc6-64hm-2g2w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-7pfh-f4vj-ww8f/GHSA-7pfh-f4vj-ww8f.json b/advisories/unreviewed/2024/10/GHSA-7pfh-f4vj-ww8f/GHSA-7pfh-f4vj-ww8f.json index 7cfd2fbd77d..fc6ecea5466 100644 --- a/advisories/unreviewed/2024/10/GHSA-7pfh-f4vj-ww8f/GHSA-7pfh-f4vj-ww8f.json +++ b/advisories/unreviewed/2024/10/GHSA-7pfh-f4vj-ww8f/GHSA-7pfh-f4vj-ww8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-7q29-5pqw-mvcf/GHSA-7q29-5pqw-mvcf.json b/advisories/unreviewed/2024/10/GHSA-7q29-5pqw-mvcf/GHSA-7q29-5pqw-mvcf.json index a8bc578aef0..a7272a7f109 100644 --- a/advisories/unreviewed/2024/10/GHSA-7q29-5pqw-mvcf/GHSA-7q29-5pqw-mvcf.json +++ b/advisories/unreviewed/2024/10/GHSA-7q29-5pqw-mvcf/GHSA-7q29-5pqw-mvcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-7wg4-cjhf-qgvp/GHSA-7wg4-cjhf-qgvp.json b/advisories/unreviewed/2024/10/GHSA-7wg4-cjhf-qgvp/GHSA-7wg4-cjhf-qgvp.json index 9ab1e37ed61..e8953c28a87 100644 --- a/advisories/unreviewed/2024/10/GHSA-7wg4-cjhf-qgvp/GHSA-7wg4-cjhf-qgvp.json +++ b/advisories/unreviewed/2024/10/GHSA-7wg4-cjhf-qgvp/GHSA-7wg4-cjhf-qgvp.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-87jj-2mgc-93qw/GHSA-87jj-2mgc-93qw.json b/advisories/unreviewed/2024/10/GHSA-87jj-2mgc-93qw/GHSA-87jj-2mgc-93qw.json index 553ad45257a..108e95a66af 100644 --- a/advisories/unreviewed/2024/10/GHSA-87jj-2mgc-93qw/GHSA-87jj-2mgc-93qw.json +++ b/advisories/unreviewed/2024/10/GHSA-87jj-2mgc-93qw/GHSA-87jj-2mgc-93qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-88x9-v4vh-c4rx/GHSA-88x9-v4vh-c4rx.json b/advisories/unreviewed/2024/10/GHSA-88x9-v4vh-c4rx/GHSA-88x9-v4vh-c4rx.json index 671ad0c87a2..92c6c018e50 100644 --- a/advisories/unreviewed/2024/10/GHSA-88x9-v4vh-c4rx/GHSA-88x9-v4vh-c4rx.json +++ b/advisories/unreviewed/2024/10/GHSA-88x9-v4vh-c4rx/GHSA-88x9-v4vh-c4rx.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-897h-qq8f-vw6q/GHSA-897h-qq8f-vw6q.json b/advisories/unreviewed/2024/10/GHSA-897h-qq8f-vw6q/GHSA-897h-qq8f-vw6q.json index 0d742b2a61e..05684a44259 100644 --- a/advisories/unreviewed/2024/10/GHSA-897h-qq8f-vw6q/GHSA-897h-qq8f-vw6q.json +++ b/advisories/unreviewed/2024/10/GHSA-897h-qq8f-vw6q/GHSA-897h-qq8f-vw6q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-8h9p-x9cm-2cqx/GHSA-8h9p-x9cm-2cqx.json b/advisories/unreviewed/2024/10/GHSA-8h9p-x9cm-2cqx/GHSA-8h9p-x9cm-2cqx.json index 85e9f7b99da..a5143a7447c 100644 --- a/advisories/unreviewed/2024/10/GHSA-8h9p-x9cm-2cqx/GHSA-8h9p-x9cm-2cqx.json +++ b/advisories/unreviewed/2024/10/GHSA-8h9p-x9cm-2cqx/GHSA-8h9p-x9cm-2cqx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-96q8-ww86-7w7p/GHSA-96q8-ww86-7w7p.json b/advisories/unreviewed/2024/10/GHSA-96q8-ww86-7w7p/GHSA-96q8-ww86-7w7p.json index 1e949737281..56737e1314e 100644 --- a/advisories/unreviewed/2024/10/GHSA-96q8-ww86-7w7p/GHSA-96q8-ww86-7w7p.json +++ b/advisories/unreviewed/2024/10/GHSA-96q8-ww86-7w7p/GHSA-96q8-ww86-7w7p.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-98h2-2cpv-4fq9/GHSA-98h2-2cpv-4fq9.json b/advisories/unreviewed/2024/10/GHSA-98h2-2cpv-4fq9/GHSA-98h2-2cpv-4fq9.json index b793e399c5b..9c33a321dc4 100644 --- a/advisories/unreviewed/2024/10/GHSA-98h2-2cpv-4fq9/GHSA-98h2-2cpv-4fq9.json +++ b/advisories/unreviewed/2024/10/GHSA-98h2-2cpv-4fq9/GHSA-98h2-2cpv-4fq9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-9crx-q2j4-3x69/GHSA-9crx-q2j4-3x69.json b/advisories/unreviewed/2024/10/GHSA-9crx-q2j4-3x69/GHSA-9crx-q2j4-3x69.json index 74ee2eefad9..3b164bb0fea 100644 --- a/advisories/unreviewed/2024/10/GHSA-9crx-q2j4-3x69/GHSA-9crx-q2j4-3x69.json +++ b/advisories/unreviewed/2024/10/GHSA-9crx-q2j4-3x69/GHSA-9crx-q2j4-3x69.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-9f2q-rr78-p4xx/GHSA-9f2q-rr78-p4xx.json b/advisories/unreviewed/2024/10/GHSA-9f2q-rr78-p4xx/GHSA-9f2q-rr78-p4xx.json index 699544de27c..34d476a8e80 100644 --- a/advisories/unreviewed/2024/10/GHSA-9f2q-rr78-p4xx/GHSA-9f2q-rr78-p4xx.json +++ b/advisories/unreviewed/2024/10/GHSA-9f2q-rr78-p4xx/GHSA-9f2q-rr78-p4xx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-9g85-xp97-r463/GHSA-9g85-xp97-r463.json b/advisories/unreviewed/2024/10/GHSA-9g85-xp97-r463/GHSA-9g85-xp97-r463.json index 094872ae6d0..f76e57d6310 100644 --- a/advisories/unreviewed/2024/10/GHSA-9g85-xp97-r463/GHSA-9g85-xp97-r463.json +++ b/advisories/unreviewed/2024/10/GHSA-9g85-xp97-r463/GHSA-9g85-xp97-r463.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-9phr-pgh5-xh38/GHSA-9phr-pgh5-xh38.json b/advisories/unreviewed/2024/10/GHSA-9phr-pgh5-xh38/GHSA-9phr-pgh5-xh38.json index 1b6936a0a21..ceb22559891 100644 --- a/advisories/unreviewed/2024/10/GHSA-9phr-pgh5-xh38/GHSA-9phr-pgh5-xh38.json +++ b/advisories/unreviewed/2024/10/GHSA-9phr-pgh5-xh38/GHSA-9phr-pgh5-xh38.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-9r9p-h97h-c482/GHSA-9r9p-h97h-c482.json b/advisories/unreviewed/2024/10/GHSA-9r9p-h97h-c482/GHSA-9r9p-h97h-c482.json index 90136ed2fad..9ba36153148 100644 --- a/advisories/unreviewed/2024/10/GHSA-9r9p-h97h-c482/GHSA-9r9p-h97h-c482.json +++ b/advisories/unreviewed/2024/10/GHSA-9r9p-h97h-c482/GHSA-9r9p-h97h-c482.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-c5x7-8hmx-5g76/GHSA-c5x7-8hmx-5g76.json b/advisories/unreviewed/2024/10/GHSA-c5x7-8hmx-5g76/GHSA-c5x7-8hmx-5g76.json index 9637890c7a3..5d19a8dd29d 100644 --- a/advisories/unreviewed/2024/10/GHSA-c5x7-8hmx-5g76/GHSA-c5x7-8hmx-5g76.json +++ b/advisories/unreviewed/2024/10/GHSA-c5x7-8hmx-5g76/GHSA-c5x7-8hmx-5g76.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-c64m-qcp9-5qjc/GHSA-c64m-qcp9-5qjc.json b/advisories/unreviewed/2024/10/GHSA-c64m-qcp9-5qjc/GHSA-c64m-qcp9-5qjc.json index 099a9fbda6d..a2ee26d8396 100644 --- a/advisories/unreviewed/2024/10/GHSA-c64m-qcp9-5qjc/GHSA-c64m-qcp9-5qjc.json +++ b/advisories/unreviewed/2024/10/GHSA-c64m-qcp9-5qjc/GHSA-c64m-qcp9-5qjc.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-cfh3-3xc6-pccj/GHSA-cfh3-3xc6-pccj.json b/advisories/unreviewed/2024/10/GHSA-cfh3-3xc6-pccj/GHSA-cfh3-3xc6-pccj.json index f4d2f1585d0..d6ea888e691 100644 --- a/advisories/unreviewed/2024/10/GHSA-cfh3-3xc6-pccj/GHSA-cfh3-3xc6-pccj.json +++ b/advisories/unreviewed/2024/10/GHSA-cfh3-3xc6-pccj/GHSA-cfh3-3xc6-pccj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-cgj8-gpqh-35qr/GHSA-cgj8-gpqh-35qr.json b/advisories/unreviewed/2024/10/GHSA-cgj8-gpqh-35qr/GHSA-cgj8-gpqh-35qr.json index 712c20e006a..9f7b6571c84 100644 --- a/advisories/unreviewed/2024/10/GHSA-cgj8-gpqh-35qr/GHSA-cgj8-gpqh-35qr.json +++ b/advisories/unreviewed/2024/10/GHSA-cgj8-gpqh-35qr/GHSA-cgj8-gpqh-35qr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-cqpp-frwv-jr24/GHSA-cqpp-frwv-jr24.json b/advisories/unreviewed/2024/10/GHSA-cqpp-frwv-jr24/GHSA-cqpp-frwv-jr24.json index 28a7b2e6efa..fb756b9a141 100644 --- a/advisories/unreviewed/2024/10/GHSA-cqpp-frwv-jr24/GHSA-cqpp-frwv-jr24.json +++ b/advisories/unreviewed/2024/10/GHSA-cqpp-frwv-jr24/GHSA-cqpp-frwv-jr24.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-cqr9-wvm8-ffrj/GHSA-cqr9-wvm8-ffrj.json b/advisories/unreviewed/2024/10/GHSA-cqr9-wvm8-ffrj/GHSA-cqr9-wvm8-ffrj.json index 04e4b648952..ffaa571f6fc 100644 --- a/advisories/unreviewed/2024/10/GHSA-cqr9-wvm8-ffrj/GHSA-cqr9-wvm8-ffrj.json +++ b/advisories/unreviewed/2024/10/GHSA-cqr9-wvm8-ffrj/GHSA-cqr9-wvm8-ffrj.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-f3v3-rc63-5rrv/GHSA-f3v3-rc63-5rrv.json b/advisories/unreviewed/2024/10/GHSA-f3v3-rc63-5rrv/GHSA-f3v3-rc63-5rrv.json index 8213a3de297..b932ffe80fc 100644 --- a/advisories/unreviewed/2024/10/GHSA-f3v3-rc63-5rrv/GHSA-f3v3-rc63-5rrv.json +++ b/advisories/unreviewed/2024/10/GHSA-f3v3-rc63-5rrv/GHSA-f3v3-rc63-5rrv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-f5vf-w827-3pgv/GHSA-f5vf-w827-3pgv.json b/advisories/unreviewed/2024/10/GHSA-f5vf-w827-3pgv/GHSA-f5vf-w827-3pgv.json index 6dd57b00bd8..1ac33795597 100644 --- a/advisories/unreviewed/2024/10/GHSA-f5vf-w827-3pgv/GHSA-f5vf-w827-3pgv.json +++ b/advisories/unreviewed/2024/10/GHSA-f5vf-w827-3pgv/GHSA-f5vf-w827-3pgv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-fg94-xg7j-w3vf/GHSA-fg94-xg7j-w3vf.json b/advisories/unreviewed/2024/10/GHSA-fg94-xg7j-w3vf/GHSA-fg94-xg7j-w3vf.json index c4e48268a7e..61dbeed814a 100644 --- a/advisories/unreviewed/2024/10/GHSA-fg94-xg7j-w3vf/GHSA-fg94-xg7j-w3vf.json +++ b/advisories/unreviewed/2024/10/GHSA-fg94-xg7j-w3vf/GHSA-fg94-xg7j-w3vf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-fmc3-3jqc-79m4/GHSA-fmc3-3jqc-79m4.json b/advisories/unreviewed/2024/10/GHSA-fmc3-3jqc-79m4/GHSA-fmc3-3jqc-79m4.json index d578f9bcfbb..d4a3daa4654 100644 --- a/advisories/unreviewed/2024/10/GHSA-fmc3-3jqc-79m4/GHSA-fmc3-3jqc-79m4.json +++ b/advisories/unreviewed/2024/10/GHSA-fmc3-3jqc-79m4/GHSA-fmc3-3jqc-79m4.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-g375-p2h6-v8p8/GHSA-g375-p2h6-v8p8.json b/advisories/unreviewed/2024/10/GHSA-g375-p2h6-v8p8/GHSA-g375-p2h6-v8p8.json index cf960ad58f1..e46da579cec 100644 --- a/advisories/unreviewed/2024/10/GHSA-g375-p2h6-v8p8/GHSA-g375-p2h6-v8p8.json +++ b/advisories/unreviewed/2024/10/GHSA-g375-p2h6-v8p8/GHSA-g375-p2h6-v8p8.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-g3f3-622v-gg6f/GHSA-g3f3-622v-gg6f.json b/advisories/unreviewed/2024/10/GHSA-g3f3-622v-gg6f/GHSA-g3f3-622v-gg6f.json index 79c641966a8..5e33f7d75f6 100644 --- a/advisories/unreviewed/2024/10/GHSA-g3f3-622v-gg6f/GHSA-g3f3-622v-gg6f.json +++ b/advisories/unreviewed/2024/10/GHSA-g3f3-622v-gg6f/GHSA-g3f3-622v-gg6f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-g8f9-q4m9-5f38/GHSA-g8f9-q4m9-5f38.json b/advisories/unreviewed/2024/10/GHSA-g8f9-q4m9-5f38/GHSA-g8f9-q4m9-5f38.json index 09fc4d9b974..e43924222a4 100644 --- a/advisories/unreviewed/2024/10/GHSA-g8f9-q4m9-5f38/GHSA-g8f9-q4m9-5f38.json +++ b/advisories/unreviewed/2024/10/GHSA-g8f9-q4m9-5f38/GHSA-g8f9-q4m9-5f38.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-gc3w-pcvc-xwp8/GHSA-gc3w-pcvc-xwp8.json b/advisories/unreviewed/2024/10/GHSA-gc3w-pcvc-xwp8/GHSA-gc3w-pcvc-xwp8.json index bfad110da86..a45c460eb1f 100644 --- a/advisories/unreviewed/2024/10/GHSA-gc3w-pcvc-xwp8/GHSA-gc3w-pcvc-xwp8.json +++ b/advisories/unreviewed/2024/10/GHSA-gc3w-pcvc-xwp8/GHSA-gc3w-pcvc-xwp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-ggm3-qx64-63ch/GHSA-ggm3-qx64-63ch.json b/advisories/unreviewed/2024/10/GHSA-ggm3-qx64-63ch/GHSA-ggm3-qx64-63ch.json index 4e85b19c22a..c7419a076f8 100644 --- a/advisories/unreviewed/2024/10/GHSA-ggm3-qx64-63ch/GHSA-ggm3-qx64-63ch.json +++ b/advisories/unreviewed/2024/10/GHSA-ggm3-qx64-63ch/GHSA-ggm3-qx64-63ch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-gh27-x7g8-9fv7/GHSA-gh27-x7g8-9fv7.json b/advisories/unreviewed/2024/10/GHSA-gh27-x7g8-9fv7/GHSA-gh27-x7g8-9fv7.json index ff68d53cd56..c500b636190 100644 --- a/advisories/unreviewed/2024/10/GHSA-gh27-x7g8-9fv7/GHSA-gh27-x7g8-9fv7.json +++ b/advisories/unreviewed/2024/10/GHSA-gh27-x7g8-9fv7/GHSA-gh27-x7g8-9fv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-gpq3-2427-mrwr/GHSA-gpq3-2427-mrwr.json b/advisories/unreviewed/2024/10/GHSA-gpq3-2427-mrwr/GHSA-gpq3-2427-mrwr.json index 923ee49b5c5..b8048df40e5 100644 --- a/advisories/unreviewed/2024/10/GHSA-gpq3-2427-mrwr/GHSA-gpq3-2427-mrwr.json +++ b/advisories/unreviewed/2024/10/GHSA-gpq3-2427-mrwr/GHSA-gpq3-2427-mrwr.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-h64p-h4x7-h6r6/GHSA-h64p-h4x7-h6r6.json b/advisories/unreviewed/2024/10/GHSA-h64p-h4x7-h6r6/GHSA-h64p-h4x7-h6r6.json index c59576f2fc7..91961e8beb0 100644 --- a/advisories/unreviewed/2024/10/GHSA-h64p-h4x7-h6r6/GHSA-h64p-h4x7-h6r6.json +++ b/advisories/unreviewed/2024/10/GHSA-h64p-h4x7-h6r6/GHSA-h64p-h4x7-h6r6.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-hm9p-89r4-c9g7/GHSA-hm9p-89r4-c9g7.json b/advisories/unreviewed/2024/10/GHSA-hm9p-89r4-c9g7/GHSA-hm9p-89r4-c9g7.json index 62dedac19f5..562f19a3120 100644 --- a/advisories/unreviewed/2024/10/GHSA-hm9p-89r4-c9g7/GHSA-hm9p-89r4-c9g7.json +++ b/advisories/unreviewed/2024/10/GHSA-hm9p-89r4-c9g7/GHSA-hm9p-89r4-c9g7.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-hpxj-p7f4-g2gg/GHSA-hpxj-p7f4-g2gg.json b/advisories/unreviewed/2024/10/GHSA-hpxj-p7f4-g2gg/GHSA-hpxj-p7f4-g2gg.json index 64d01008cd9..79e2c2ed0b6 100644 --- a/advisories/unreviewed/2024/10/GHSA-hpxj-p7f4-g2gg/GHSA-hpxj-p7f4-g2gg.json +++ b/advisories/unreviewed/2024/10/GHSA-hpxj-p7f4-g2gg/GHSA-hpxj-p7f4-g2gg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-hr5m-r6hv-j389/GHSA-hr5m-r6hv-j389.json b/advisories/unreviewed/2024/10/GHSA-hr5m-r6hv-j389/GHSA-hr5m-r6hv-j389.json index 16d2828bf8f..a65ed703e2a 100644 --- a/advisories/unreviewed/2024/10/GHSA-hr5m-r6hv-j389/GHSA-hr5m-r6hv-j389.json +++ b/advisories/unreviewed/2024/10/GHSA-hr5m-r6hv-j389/GHSA-hr5m-r6hv-j389.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-hrh9-752p-34vj/GHSA-hrh9-752p-34vj.json b/advisories/unreviewed/2024/10/GHSA-hrh9-752p-34vj/GHSA-hrh9-752p-34vj.json index 680ae4499dc..64d2167e8c3 100644 --- a/advisories/unreviewed/2024/10/GHSA-hrh9-752p-34vj/GHSA-hrh9-752p-34vj.json +++ b/advisories/unreviewed/2024/10/GHSA-hrh9-752p-34vj/GHSA-hrh9-752p-34vj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-hrm8-rc8p-35fq/GHSA-hrm8-rc8p-35fq.json b/advisories/unreviewed/2024/10/GHSA-hrm8-rc8p-35fq/GHSA-hrm8-rc8p-35fq.json index c038fea79d9..5258959ea3a 100644 --- a/advisories/unreviewed/2024/10/GHSA-hrm8-rc8p-35fq/GHSA-hrm8-rc8p-35fq.json +++ b/advisories/unreviewed/2024/10/GHSA-hrm8-rc8p-35fq/GHSA-hrm8-rc8p-35fq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-j49p-mmfv-2jfj/GHSA-j49p-mmfv-2jfj.json b/advisories/unreviewed/2024/10/GHSA-j49p-mmfv-2jfj/GHSA-j49p-mmfv-2jfj.json index bb9f8097e94..51023c18d59 100644 --- a/advisories/unreviewed/2024/10/GHSA-j49p-mmfv-2jfj/GHSA-j49p-mmfv-2jfj.json +++ b/advisories/unreviewed/2024/10/GHSA-j49p-mmfv-2jfj/GHSA-j49p-mmfv-2jfj.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-j6x2-cm38-9jrr/GHSA-j6x2-cm38-9jrr.json b/advisories/unreviewed/2024/10/GHSA-j6x2-cm38-9jrr/GHSA-j6x2-cm38-9jrr.json index bfaf42d2ba1..7ffe9647e05 100644 --- a/advisories/unreviewed/2024/10/GHSA-j6x2-cm38-9jrr/GHSA-j6x2-cm38-9jrr.json +++ b/advisories/unreviewed/2024/10/GHSA-j6x2-cm38-9jrr/GHSA-j6x2-cm38-9jrr.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-j7g7-4mrc-2vvr/GHSA-j7g7-4mrc-2vvr.json b/advisories/unreviewed/2024/10/GHSA-j7g7-4mrc-2vvr/GHSA-j7g7-4mrc-2vvr.json index 70c90b15033..c037d7afebc 100644 --- a/advisories/unreviewed/2024/10/GHSA-j7g7-4mrc-2vvr/GHSA-j7g7-4mrc-2vvr.json +++ b/advisories/unreviewed/2024/10/GHSA-j7g7-4mrc-2vvr/GHSA-j7g7-4mrc-2vvr.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-jcvc-f8qv-gpjc/GHSA-jcvc-f8qv-gpjc.json b/advisories/unreviewed/2024/10/GHSA-jcvc-f8qv-gpjc/GHSA-jcvc-f8qv-gpjc.json index 6ef802604fd..75ecf8815d2 100644 --- a/advisories/unreviewed/2024/10/GHSA-jcvc-f8qv-gpjc/GHSA-jcvc-f8qv-gpjc.json +++ b/advisories/unreviewed/2024/10/GHSA-jcvc-f8qv-gpjc/GHSA-jcvc-f8qv-gpjc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-jf7j-fg7f-v385/GHSA-jf7j-fg7f-v385.json b/advisories/unreviewed/2024/10/GHSA-jf7j-fg7f-v385/GHSA-jf7j-fg7f-v385.json index ca0b77a8828..1367bb831ac 100644 --- a/advisories/unreviewed/2024/10/GHSA-jf7j-fg7f-v385/GHSA-jf7j-fg7f-v385.json +++ b/advisories/unreviewed/2024/10/GHSA-jf7j-fg7f-v385/GHSA-jf7j-fg7f-v385.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-jj92-x469-335w/GHSA-jj92-x469-335w.json b/advisories/unreviewed/2024/10/GHSA-jj92-x469-335w/GHSA-jj92-x469-335w.json index d387bf73c71..16f3397e455 100644 --- a/advisories/unreviewed/2024/10/GHSA-jj92-x469-335w/GHSA-jj92-x469-335w.json +++ b/advisories/unreviewed/2024/10/GHSA-jj92-x469-335w/GHSA-jj92-x469-335w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-jm9m-h6mg-fc5j/GHSA-jm9m-h6mg-fc5j.json b/advisories/unreviewed/2024/10/GHSA-jm9m-h6mg-fc5j/GHSA-jm9m-h6mg-fc5j.json index 3c0984401ad..51c986a98f6 100644 --- a/advisories/unreviewed/2024/10/GHSA-jm9m-h6mg-fc5j/GHSA-jm9m-h6mg-fc5j.json +++ b/advisories/unreviewed/2024/10/GHSA-jm9m-h6mg-fc5j/GHSA-jm9m-h6mg-fc5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-jx6p-33vm-7q3r/GHSA-jx6p-33vm-7q3r.json b/advisories/unreviewed/2024/10/GHSA-jx6p-33vm-7q3r/GHSA-jx6p-33vm-7q3r.json index 219363feefc..dca8026d62f 100644 --- a/advisories/unreviewed/2024/10/GHSA-jx6p-33vm-7q3r/GHSA-jx6p-33vm-7q3r.json +++ b/advisories/unreviewed/2024/10/GHSA-jx6p-33vm-7q3r/GHSA-jx6p-33vm-7q3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-m772-f9r2-vv89/GHSA-m772-f9r2-vv89.json b/advisories/unreviewed/2024/10/GHSA-m772-f9r2-vv89/GHSA-m772-f9r2-vv89.json index 43ac69a3517..0a5c7e2e516 100644 --- a/advisories/unreviewed/2024/10/GHSA-m772-f9r2-vv89/GHSA-m772-f9r2-vv89.json +++ b/advisories/unreviewed/2024/10/GHSA-m772-f9r2-vv89/GHSA-m772-f9r2-vv89.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-mp9x-ww6f-rq9q/GHSA-mp9x-ww6f-rq9q.json b/advisories/unreviewed/2024/10/GHSA-mp9x-ww6f-rq9q/GHSA-mp9x-ww6f-rq9q.json index aabf4da2287..bb7ed808858 100644 --- a/advisories/unreviewed/2024/10/GHSA-mp9x-ww6f-rq9q/GHSA-mp9x-ww6f-rq9q.json +++ b/advisories/unreviewed/2024/10/GHSA-mp9x-ww6f-rq9q/GHSA-mp9x-ww6f-rq9q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-mq8p-chwh-jrj5/GHSA-mq8p-chwh-jrj5.json b/advisories/unreviewed/2024/10/GHSA-mq8p-chwh-jrj5/GHSA-mq8p-chwh-jrj5.json index 27118b4523b..daf6ebfaf44 100644 --- a/advisories/unreviewed/2024/10/GHSA-mq8p-chwh-jrj5/GHSA-mq8p-chwh-jrj5.json +++ b/advisories/unreviewed/2024/10/GHSA-mq8p-chwh-jrj5/GHSA-mq8p-chwh-jrj5.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-p4jj-gp83-qc3g/GHSA-p4jj-gp83-qc3g.json b/advisories/unreviewed/2024/10/GHSA-p4jj-gp83-qc3g/GHSA-p4jj-gp83-qc3g.json index 5a6d119103e..0cb3c55dbcb 100644 --- a/advisories/unreviewed/2024/10/GHSA-p4jj-gp83-qc3g/GHSA-p4jj-gp83-qc3g.json +++ b/advisories/unreviewed/2024/10/GHSA-p4jj-gp83-qc3g/GHSA-p4jj-gp83-qc3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-p5f2-p286-m43f/GHSA-p5f2-p286-m43f.json b/advisories/unreviewed/2024/10/GHSA-p5f2-p286-m43f/GHSA-p5f2-p286-m43f.json index 070754b2f8a..728d9d732e7 100644 --- a/advisories/unreviewed/2024/10/GHSA-p5f2-p286-m43f/GHSA-p5f2-p286-m43f.json +++ b/advisories/unreviewed/2024/10/GHSA-p5f2-p286-m43f/GHSA-p5f2-p286-m43f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-p8mh-78pg-w6gc/GHSA-p8mh-78pg-w6gc.json b/advisories/unreviewed/2024/10/GHSA-p8mh-78pg-w6gc/GHSA-p8mh-78pg-w6gc.json index ebdfd0cfbd0..37f2e2e4f42 100644 --- a/advisories/unreviewed/2024/10/GHSA-p8mh-78pg-w6gc/GHSA-p8mh-78pg-w6gc.json +++ b/advisories/unreviewed/2024/10/GHSA-p8mh-78pg-w6gc/GHSA-p8mh-78pg-w6gc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-ph7w-3qv5-6r8m/GHSA-ph7w-3qv5-6r8m.json b/advisories/unreviewed/2024/10/GHSA-ph7w-3qv5-6r8m/GHSA-ph7w-3qv5-6r8m.json index b1ce4bc5596..031d1d27151 100644 --- a/advisories/unreviewed/2024/10/GHSA-ph7w-3qv5-6r8m/GHSA-ph7w-3qv5-6r8m.json +++ b/advisories/unreviewed/2024/10/GHSA-ph7w-3qv5-6r8m/GHSA-ph7w-3qv5-6r8m.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-pj59-59fw-j7px/GHSA-pj59-59fw-j7px.json b/advisories/unreviewed/2024/10/GHSA-pj59-59fw-j7px/GHSA-pj59-59fw-j7px.json index 78851f297a4..8ad96a257c8 100644 --- a/advisories/unreviewed/2024/10/GHSA-pj59-59fw-j7px/GHSA-pj59-59fw-j7px.json +++ b/advisories/unreviewed/2024/10/GHSA-pj59-59fw-j7px/GHSA-pj59-59fw-j7px.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-pj5g-5qxx-5hfp/GHSA-pj5g-5qxx-5hfp.json b/advisories/unreviewed/2024/10/GHSA-pj5g-5qxx-5hfp/GHSA-pj5g-5qxx-5hfp.json index 624d8b14105..4ada83c61ff 100644 --- a/advisories/unreviewed/2024/10/GHSA-pj5g-5qxx-5hfp/GHSA-pj5g-5qxx-5hfp.json +++ b/advisories/unreviewed/2024/10/GHSA-pj5g-5qxx-5hfp/GHSA-pj5g-5qxx-5hfp.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-q8jf-j34w-q74g/GHSA-q8jf-j34w-q74g.json b/advisories/unreviewed/2024/10/GHSA-q8jf-j34w-q74g/GHSA-q8jf-j34w-q74g.json index 956e677a6f4..2c8921663e4 100644 --- a/advisories/unreviewed/2024/10/GHSA-q8jf-j34w-q74g/GHSA-q8jf-j34w-q74g.json +++ b/advisories/unreviewed/2024/10/GHSA-q8jf-j34w-q74g/GHSA-q8jf-j34w-q74g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-qj8p-28gr-3h5v/GHSA-qj8p-28gr-3h5v.json b/advisories/unreviewed/2024/10/GHSA-qj8p-28gr-3h5v/GHSA-qj8p-28gr-3h5v.json index c8e20c63983..bee671bba12 100644 --- a/advisories/unreviewed/2024/10/GHSA-qj8p-28gr-3h5v/GHSA-qj8p-28gr-3h5v.json +++ b/advisories/unreviewed/2024/10/GHSA-qj8p-28gr-3h5v/GHSA-qj8p-28gr-3h5v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-qv3x-vgw2-qrfp/GHSA-qv3x-vgw2-qrfp.json b/advisories/unreviewed/2024/10/GHSA-qv3x-vgw2-qrfp/GHSA-qv3x-vgw2-qrfp.json index 7e37919c30b..27d5bfffacc 100644 --- a/advisories/unreviewed/2024/10/GHSA-qv3x-vgw2-qrfp/GHSA-qv3x-vgw2-qrfp.json +++ b/advisories/unreviewed/2024/10/GHSA-qv3x-vgw2-qrfp/GHSA-qv3x-vgw2-qrfp.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-qvf9-958h-6h8p/GHSA-qvf9-958h-6h8p.json b/advisories/unreviewed/2024/10/GHSA-qvf9-958h-6h8p/GHSA-qvf9-958h-6h8p.json index 6c287c3746b..8950d428491 100644 --- a/advisories/unreviewed/2024/10/GHSA-qvf9-958h-6h8p/GHSA-qvf9-958h-6h8p.json +++ b/advisories/unreviewed/2024/10/GHSA-qvf9-958h-6h8p/GHSA-qvf9-958h-6h8p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-qvh6-69xv-v77r/GHSA-qvh6-69xv-v77r.json b/advisories/unreviewed/2024/10/GHSA-qvh6-69xv-v77r/GHSA-qvh6-69xv-v77r.json index c4269dc2d5a..353f1ad8f23 100644 --- a/advisories/unreviewed/2024/10/GHSA-qvh6-69xv-v77r/GHSA-qvh6-69xv-v77r.json +++ b/advisories/unreviewed/2024/10/GHSA-qvh6-69xv-v77r/GHSA-qvh6-69xv-v77r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-qvrf-qm4g-4557/GHSA-qvrf-qm4g-4557.json b/advisories/unreviewed/2024/10/GHSA-qvrf-qm4g-4557/GHSA-qvrf-qm4g-4557.json index f38c4a86f7b..b770c0e5f2f 100644 --- a/advisories/unreviewed/2024/10/GHSA-qvrf-qm4g-4557/GHSA-qvrf-qm4g-4557.json +++ b/advisories/unreviewed/2024/10/GHSA-qvrf-qm4g-4557/GHSA-qvrf-qm4g-4557.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-r4rp-m7m9-jrfv/GHSA-r4rp-m7m9-jrfv.json b/advisories/unreviewed/2024/10/GHSA-r4rp-m7m9-jrfv/GHSA-r4rp-m7m9-jrfv.json index 1f2359edf96..3e6c079e5be 100644 --- a/advisories/unreviewed/2024/10/GHSA-r4rp-m7m9-jrfv/GHSA-r4rp-m7m9-jrfv.json +++ b/advisories/unreviewed/2024/10/GHSA-r4rp-m7m9-jrfv/GHSA-r4rp-m7m9-jrfv.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-r53c-qq92-w6x3/GHSA-r53c-qq92-w6x3.json b/advisories/unreviewed/2024/10/GHSA-r53c-qq92-w6x3/GHSA-r53c-qq92-w6x3.json index ec8d45313d7..2f7528922aa 100644 --- a/advisories/unreviewed/2024/10/GHSA-r53c-qq92-w6x3/GHSA-r53c-qq92-w6x3.json +++ b/advisories/unreviewed/2024/10/GHSA-r53c-qq92-w6x3/GHSA-r53c-qq92-w6x3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-rpxr-4v66-8vf4/GHSA-rpxr-4v66-8vf4.json b/advisories/unreviewed/2024/10/GHSA-rpxr-4v66-8vf4/GHSA-rpxr-4v66-8vf4.json index 9c8e4efa408..0e7022cddb2 100644 --- a/advisories/unreviewed/2024/10/GHSA-rpxr-4v66-8vf4/GHSA-rpxr-4v66-8vf4.json +++ b/advisories/unreviewed/2024/10/GHSA-rpxr-4v66-8vf4/GHSA-rpxr-4v66-8vf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-v69r-9546-4ccm/GHSA-v69r-9546-4ccm.json b/advisories/unreviewed/2024/10/GHSA-v69r-9546-4ccm/GHSA-v69r-9546-4ccm.json index 4220da01716..455ebcdaf22 100644 --- a/advisories/unreviewed/2024/10/GHSA-v69r-9546-4ccm/GHSA-v69r-9546-4ccm.json +++ b/advisories/unreviewed/2024/10/GHSA-v69r-9546-4ccm/GHSA-v69r-9546-4ccm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-v7vw-qwr3-vgr4/GHSA-v7vw-qwr3-vgr4.json b/advisories/unreviewed/2024/10/GHSA-v7vw-qwr3-vgr4/GHSA-v7vw-qwr3-vgr4.json index cc7f3a8ea2a..22a8175c7f3 100644 --- a/advisories/unreviewed/2024/10/GHSA-v7vw-qwr3-vgr4/GHSA-v7vw-qwr3-vgr4.json +++ b/advisories/unreviewed/2024/10/GHSA-v7vw-qwr3-vgr4/GHSA-v7vw-qwr3-vgr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-v8p3-f3p7-66xj/GHSA-v8p3-f3p7-66xj.json b/advisories/unreviewed/2024/10/GHSA-v8p3-f3p7-66xj/GHSA-v8p3-f3p7-66xj.json index 3d3bbf8745a..d99b2590a24 100644 --- a/advisories/unreviewed/2024/10/GHSA-v8p3-f3p7-66xj/GHSA-v8p3-f3p7-66xj.json +++ b/advisories/unreviewed/2024/10/GHSA-v8p3-f3p7-66xj/GHSA-v8p3-f3p7-66xj.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-vfh3-c3xr-qw22/GHSA-vfh3-c3xr-qw22.json b/advisories/unreviewed/2024/10/GHSA-vfh3-c3xr-qw22/GHSA-vfh3-c3xr-qw22.json index e08292a1c5d..9e7556d9300 100644 --- a/advisories/unreviewed/2024/10/GHSA-vfh3-c3xr-qw22/GHSA-vfh3-c3xr-qw22.json +++ b/advisories/unreviewed/2024/10/GHSA-vfh3-c3xr-qw22/GHSA-vfh3-c3xr-qw22.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-vg6p-xhm4-6r5f/GHSA-vg6p-xhm4-6r5f.json b/advisories/unreviewed/2024/10/GHSA-vg6p-xhm4-6r5f/GHSA-vg6p-xhm4-6r5f.json index 959fb4291ac..00bb3fc25af 100644 --- a/advisories/unreviewed/2024/10/GHSA-vg6p-xhm4-6r5f/GHSA-vg6p-xhm4-6r5f.json +++ b/advisories/unreviewed/2024/10/GHSA-vg6p-xhm4-6r5f/GHSA-vg6p-xhm4-6r5f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-vpc4-q7gx-ppmw/GHSA-vpc4-q7gx-ppmw.json b/advisories/unreviewed/2024/10/GHSA-vpc4-q7gx-ppmw/GHSA-vpc4-q7gx-ppmw.json index 48e1ab23676..7878ca4d6da 100644 --- a/advisories/unreviewed/2024/10/GHSA-vpc4-q7gx-ppmw/GHSA-vpc4-q7gx-ppmw.json +++ b/advisories/unreviewed/2024/10/GHSA-vpc4-q7gx-ppmw/GHSA-vpc4-q7gx-ppmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-vq2f-wpjw-qjm7/GHSA-vq2f-wpjw-qjm7.json b/advisories/unreviewed/2024/10/GHSA-vq2f-wpjw-qjm7/GHSA-vq2f-wpjw-qjm7.json index 130a0b7c1ef..a4b2c8c1707 100644 --- a/advisories/unreviewed/2024/10/GHSA-vq2f-wpjw-qjm7/GHSA-vq2f-wpjw-qjm7.json +++ b/advisories/unreviewed/2024/10/GHSA-vq2f-wpjw-qjm7/GHSA-vq2f-wpjw-qjm7.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-vrh2-53xm-76hq/GHSA-vrh2-53xm-76hq.json b/advisories/unreviewed/2024/10/GHSA-vrh2-53xm-76hq/GHSA-vrh2-53xm-76hq.json index 06c247bb4fc..46eea539fb3 100644 --- a/advisories/unreviewed/2024/10/GHSA-vrh2-53xm-76hq/GHSA-vrh2-53xm-76hq.json +++ b/advisories/unreviewed/2024/10/GHSA-vrh2-53xm-76hq/GHSA-vrh2-53xm-76hq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-vx9h-7frf-374v/GHSA-vx9h-7frf-374v.json b/advisories/unreviewed/2024/10/GHSA-vx9h-7frf-374v/GHSA-vx9h-7frf-374v.json index 4a6c3c118f8..24025369641 100644 --- a/advisories/unreviewed/2024/10/GHSA-vx9h-7frf-374v/GHSA-vx9h-7frf-374v.json +++ b/advisories/unreviewed/2024/10/GHSA-vx9h-7frf-374v/GHSA-vx9h-7frf-374v.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-vxgx-3742-3jj5/GHSA-vxgx-3742-3jj5.json b/advisories/unreviewed/2024/10/GHSA-vxgx-3742-3jj5/GHSA-vxgx-3742-3jj5.json index 5e33ca1a357..99f5653c804 100644 --- a/advisories/unreviewed/2024/10/GHSA-vxgx-3742-3jj5/GHSA-vxgx-3742-3jj5.json +++ b/advisories/unreviewed/2024/10/GHSA-vxgx-3742-3jj5/GHSA-vxgx-3742-3jj5.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-wphj-8vr3-fvfg/GHSA-wphj-8vr3-fvfg.json b/advisories/unreviewed/2024/10/GHSA-wphj-8vr3-fvfg/GHSA-wphj-8vr3-fvfg.json index f241f092f9f..d14c44648e5 100644 --- a/advisories/unreviewed/2024/10/GHSA-wphj-8vr3-fvfg/GHSA-wphj-8vr3-fvfg.json +++ b/advisories/unreviewed/2024/10/GHSA-wphj-8vr3-fvfg/GHSA-wphj-8vr3-fvfg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-wphm-3gx3-274q/GHSA-wphm-3gx3-274q.json b/advisories/unreviewed/2024/10/GHSA-wphm-3gx3-274q/GHSA-wphm-3gx3-274q.json index d2ef80e6530..88c39d2855c 100644 --- a/advisories/unreviewed/2024/10/GHSA-wphm-3gx3-274q/GHSA-wphm-3gx3-274q.json +++ b/advisories/unreviewed/2024/10/GHSA-wphm-3gx3-274q/GHSA-wphm-3gx3-274q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-wv3w-5m8g-gghx/GHSA-wv3w-5m8g-gghx.json b/advisories/unreviewed/2024/10/GHSA-wv3w-5m8g-gghx/GHSA-wv3w-5m8g-gghx.json index 9037ecbd52b..b5adc7a729c 100644 --- a/advisories/unreviewed/2024/10/GHSA-wv3w-5m8g-gghx/GHSA-wv3w-5m8g-gghx.json +++ b/advisories/unreviewed/2024/10/GHSA-wv3w-5m8g-gghx/GHSA-wv3w-5m8g-gghx.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-wwg3-85gh-r583/GHSA-wwg3-85gh-r583.json b/advisories/unreviewed/2024/10/GHSA-wwg3-85gh-r583/GHSA-wwg3-85gh-r583.json index 32226e36320..63a8c2a8fa8 100644 --- a/advisories/unreviewed/2024/10/GHSA-wwg3-85gh-r583/GHSA-wwg3-85gh-r583.json +++ b/advisories/unreviewed/2024/10/GHSA-wwg3-85gh-r583/GHSA-wwg3-85gh-r583.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-x6h6-973g-q656/GHSA-x6h6-973g-q656.json b/advisories/unreviewed/2024/10/GHSA-x6h6-973g-q656/GHSA-x6h6-973g-q656.json index f5f00513f4d..2f2483a7310 100644 --- a/advisories/unreviewed/2024/10/GHSA-x6h6-973g-q656/GHSA-x6h6-973g-q656.json +++ b/advisories/unreviewed/2024/10/GHSA-x6h6-973g-q656/GHSA-x6h6-973g-q656.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-x7j9-8hjg-7f8p/GHSA-x7j9-8hjg-7f8p.json b/advisories/unreviewed/2024/10/GHSA-x7j9-8hjg-7f8p/GHSA-x7j9-8hjg-7f8p.json index 7d6fa980b54..e96190bb971 100644 --- a/advisories/unreviewed/2024/10/GHSA-x7j9-8hjg-7f8p/GHSA-x7j9-8hjg-7f8p.json +++ b/advisories/unreviewed/2024/10/GHSA-x7j9-8hjg-7f8p/GHSA-x7j9-8hjg-7f8p.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-xw6g-7x68-mrj2/GHSA-xw6g-7x68-mrj2.json b/advisories/unreviewed/2024/10/GHSA-xw6g-7x68-mrj2/GHSA-xw6g-7x68-mrj2.json index 500269ece40..14471b3ee32 100644 --- a/advisories/unreviewed/2024/10/GHSA-xw6g-7x68-mrj2/GHSA-xw6g-7x68-mrj2.json +++ b/advisories/unreviewed/2024/10/GHSA-xw6g-7x68-mrj2/GHSA-xw6g-7x68-mrj2.json @@ -17,9 +17,7 @@ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-xwg4-3m43-wmp8/GHSA-xwg4-3m43-wmp8.json b/advisories/unreviewed/2024/10/GHSA-xwg4-3m43-wmp8/GHSA-xwg4-3m43-wmp8.json index 826d66c9089..a680a9bde55 100644 --- a/advisories/unreviewed/2024/10/GHSA-xwg4-3m43-wmp8/GHSA-xwg4-3m43-wmp8.json +++ b/advisories/unreviewed/2024/10/GHSA-xwg4-3m43-wmp8/GHSA-xwg4-3m43-wmp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-2v4f-h7wf-hprx/GHSA-2v4f-h7wf-hprx.json b/advisories/unreviewed/2024/11/GHSA-2v4f-h7wf-hprx/GHSA-2v4f-h7wf-hprx.json index e18a6788255..927270511ef 100644 --- a/advisories/unreviewed/2024/11/GHSA-2v4f-h7wf-hprx/GHSA-2v4f-h7wf-hprx.json +++ b/advisories/unreviewed/2024/11/GHSA-2v4f-h7wf-hprx/GHSA-2v4f-h7wf-hprx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-37jv-rq4h-f78r/GHSA-37jv-rq4h-f78r.json b/advisories/unreviewed/2024/11/GHSA-37jv-rq4h-f78r/GHSA-37jv-rq4h-f78r.json index 00cc617a239..fc594d4e907 100644 --- a/advisories/unreviewed/2024/11/GHSA-37jv-rq4h-f78r/GHSA-37jv-rq4h-f78r.json +++ b/advisories/unreviewed/2024/11/GHSA-37jv-rq4h-f78r/GHSA-37jv-rq4h-f78r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-3rfr-fgqp-grf8/GHSA-3rfr-fgqp-grf8.json b/advisories/unreviewed/2024/11/GHSA-3rfr-fgqp-grf8/GHSA-3rfr-fgqp-grf8.json index 3124abb6b3b..0e00bfe8c12 100644 --- a/advisories/unreviewed/2024/11/GHSA-3rfr-fgqp-grf8/GHSA-3rfr-fgqp-grf8.json +++ b/advisories/unreviewed/2024/11/GHSA-3rfr-fgqp-grf8/GHSA-3rfr-fgqp-grf8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-429p-cw2q-r86w/GHSA-429p-cw2q-r86w.json b/advisories/unreviewed/2024/11/GHSA-429p-cw2q-r86w/GHSA-429p-cw2q-r86w.json index f14f2caacb1..1d2df23993a 100644 --- a/advisories/unreviewed/2024/11/GHSA-429p-cw2q-r86w/GHSA-429p-cw2q-r86w.json +++ b/advisories/unreviewed/2024/11/GHSA-429p-cw2q-r86w/GHSA-429p-cw2q-r86w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-4cvp-44wg-9vjf/GHSA-4cvp-44wg-9vjf.json b/advisories/unreviewed/2024/11/GHSA-4cvp-44wg-9vjf/GHSA-4cvp-44wg-9vjf.json index 09d0b4d9164..3891139692e 100644 --- a/advisories/unreviewed/2024/11/GHSA-4cvp-44wg-9vjf/GHSA-4cvp-44wg-9vjf.json +++ b/advisories/unreviewed/2024/11/GHSA-4cvp-44wg-9vjf/GHSA-4cvp-44wg-9vjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-4ggp-78v2-3356/GHSA-4ggp-78v2-3356.json b/advisories/unreviewed/2024/11/GHSA-4ggp-78v2-3356/GHSA-4ggp-78v2-3356.json index 5e40e56b4e8..aee401e56dc 100644 --- a/advisories/unreviewed/2024/11/GHSA-4ggp-78v2-3356/GHSA-4ggp-78v2-3356.json +++ b/advisories/unreviewed/2024/11/GHSA-4ggp-78v2-3356/GHSA-4ggp-78v2-3356.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-6f6p-8qh5-2h9f/GHSA-6f6p-8qh5-2h9f.json b/advisories/unreviewed/2024/11/GHSA-6f6p-8qh5-2h9f/GHSA-6f6p-8qh5-2h9f.json index c7224ab7414..2af831882be 100644 --- a/advisories/unreviewed/2024/11/GHSA-6f6p-8qh5-2h9f/GHSA-6f6p-8qh5-2h9f.json +++ b/advisories/unreviewed/2024/11/GHSA-6f6p-8qh5-2h9f/GHSA-6f6p-8qh5-2h9f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-762q-x4w4-fx33/GHSA-762q-x4w4-fx33.json b/advisories/unreviewed/2024/11/GHSA-762q-x4w4-fx33/GHSA-762q-x4w4-fx33.json index 75806d21768..24f249cd49a 100644 --- a/advisories/unreviewed/2024/11/GHSA-762q-x4w4-fx33/GHSA-762q-x4w4-fx33.json +++ b/advisories/unreviewed/2024/11/GHSA-762q-x4w4-fx33/GHSA-762q-x4w4-fx33.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-7764-f533-ccmp/GHSA-7764-f533-ccmp.json b/advisories/unreviewed/2024/11/GHSA-7764-f533-ccmp/GHSA-7764-f533-ccmp.json index 34733766650..5789b48c320 100644 --- a/advisories/unreviewed/2024/11/GHSA-7764-f533-ccmp/GHSA-7764-f533-ccmp.json +++ b/advisories/unreviewed/2024/11/GHSA-7764-f533-ccmp/GHSA-7764-f533-ccmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-7v6m-5xcw-rjqw/GHSA-7v6m-5xcw-rjqw.json b/advisories/unreviewed/2024/11/GHSA-7v6m-5xcw-rjqw/GHSA-7v6m-5xcw-rjqw.json index 248c31c217b..32483717b91 100644 --- a/advisories/unreviewed/2024/11/GHSA-7v6m-5xcw-rjqw/GHSA-7v6m-5xcw-rjqw.json +++ b/advisories/unreviewed/2024/11/GHSA-7v6m-5xcw-rjqw/GHSA-7v6m-5xcw-rjqw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-8r46-93rm-2v8m/GHSA-8r46-93rm-2v8m.json b/advisories/unreviewed/2024/11/GHSA-8r46-93rm-2v8m/GHSA-8r46-93rm-2v8m.json index 0b6967cc7ba..16893e74294 100644 --- a/advisories/unreviewed/2024/11/GHSA-8r46-93rm-2v8m/GHSA-8r46-93rm-2v8m.json +++ b/advisories/unreviewed/2024/11/GHSA-8r46-93rm-2v8m/GHSA-8r46-93rm-2v8m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-95fx-xfpp-98x5/GHSA-95fx-xfpp-98x5.json b/advisories/unreviewed/2024/11/GHSA-95fx-xfpp-98x5/GHSA-95fx-xfpp-98x5.json index c377126e412..795564d6838 100644 --- a/advisories/unreviewed/2024/11/GHSA-95fx-xfpp-98x5/GHSA-95fx-xfpp-98x5.json +++ b/advisories/unreviewed/2024/11/GHSA-95fx-xfpp-98x5/GHSA-95fx-xfpp-98x5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-99cp-8r4m-63qq/GHSA-99cp-8r4m-63qq.json b/advisories/unreviewed/2024/11/GHSA-99cp-8r4m-63qq/GHSA-99cp-8r4m-63qq.json index 51ba185b5d0..105a2cc5a8b 100644 --- a/advisories/unreviewed/2024/11/GHSA-99cp-8r4m-63qq/GHSA-99cp-8r4m-63qq.json +++ b/advisories/unreviewed/2024/11/GHSA-99cp-8r4m-63qq/GHSA-99cp-8r4m-63qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-9jcw-gp33-g7j3/GHSA-9jcw-gp33-g7j3.json b/advisories/unreviewed/2024/11/GHSA-9jcw-gp33-g7j3/GHSA-9jcw-gp33-g7j3.json index 2c3350c815b..60695de6464 100644 --- a/advisories/unreviewed/2024/11/GHSA-9jcw-gp33-g7j3/GHSA-9jcw-gp33-g7j3.json +++ b/advisories/unreviewed/2024/11/GHSA-9jcw-gp33-g7j3/GHSA-9jcw-gp33-g7j3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-9mfg-cwh5-52p2/GHSA-9mfg-cwh5-52p2.json b/advisories/unreviewed/2024/11/GHSA-9mfg-cwh5-52p2/GHSA-9mfg-cwh5-52p2.json index 4ba499c93c8..7790aced762 100644 --- a/advisories/unreviewed/2024/11/GHSA-9mfg-cwh5-52p2/GHSA-9mfg-cwh5-52p2.json +++ b/advisories/unreviewed/2024/11/GHSA-9mfg-cwh5-52p2/GHSA-9mfg-cwh5-52p2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-c3jc-grcx-w43w/GHSA-c3jc-grcx-w43w.json b/advisories/unreviewed/2024/11/GHSA-c3jc-grcx-w43w/GHSA-c3jc-grcx-w43w.json index 853f17fcd1d..102d11a1bd5 100644 --- a/advisories/unreviewed/2024/11/GHSA-c3jc-grcx-w43w/GHSA-c3jc-grcx-w43w.json +++ b/advisories/unreviewed/2024/11/GHSA-c3jc-grcx-w43w/GHSA-c3jc-grcx-w43w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-cv4m-7ph2-f339/GHSA-cv4m-7ph2-f339.json b/advisories/unreviewed/2024/11/GHSA-cv4m-7ph2-f339/GHSA-cv4m-7ph2-f339.json index 264566b026b..c9af3a5403e 100644 --- a/advisories/unreviewed/2024/11/GHSA-cv4m-7ph2-f339/GHSA-cv4m-7ph2-f339.json +++ b/advisories/unreviewed/2024/11/GHSA-cv4m-7ph2-f339/GHSA-cv4m-7ph2-f339.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-cx35-jqf5-2rv6/GHSA-cx35-jqf5-2rv6.json b/advisories/unreviewed/2024/11/GHSA-cx35-jqf5-2rv6/GHSA-cx35-jqf5-2rv6.json index 88e965c46e9..f9f052e82b7 100644 --- a/advisories/unreviewed/2024/11/GHSA-cx35-jqf5-2rv6/GHSA-cx35-jqf5-2rv6.json +++ b/advisories/unreviewed/2024/11/GHSA-cx35-jqf5-2rv6/GHSA-cx35-jqf5-2rv6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-f57c-rm2w-7qmq/GHSA-f57c-rm2w-7qmq.json b/advisories/unreviewed/2024/11/GHSA-f57c-rm2w-7qmq/GHSA-f57c-rm2w-7qmq.json index 7ee6d4eae47..d459541c7a1 100644 --- a/advisories/unreviewed/2024/11/GHSA-f57c-rm2w-7qmq/GHSA-f57c-rm2w-7qmq.json +++ b/advisories/unreviewed/2024/11/GHSA-f57c-rm2w-7qmq/GHSA-f57c-rm2w-7qmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-f927-c8m5-jh63/GHSA-f927-c8m5-jh63.json b/advisories/unreviewed/2024/11/GHSA-f927-c8m5-jh63/GHSA-f927-c8m5-jh63.json index 720a48e2d23..87f2f096d38 100644 --- a/advisories/unreviewed/2024/11/GHSA-f927-c8m5-jh63/GHSA-f927-c8m5-jh63.json +++ b/advisories/unreviewed/2024/11/GHSA-f927-c8m5-jh63/GHSA-f927-c8m5-jh63.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-f974-j7q8-xmcc/GHSA-f974-j7q8-xmcc.json b/advisories/unreviewed/2024/11/GHSA-f974-j7q8-xmcc/GHSA-f974-j7q8-xmcc.json index 6252b9d4a87..ffe1afeaea3 100644 --- a/advisories/unreviewed/2024/11/GHSA-f974-j7q8-xmcc/GHSA-f974-j7q8-xmcc.json +++ b/advisories/unreviewed/2024/11/GHSA-f974-j7q8-xmcc/GHSA-f974-j7q8-xmcc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-fqxx-5f97-5vj8/GHSA-fqxx-5f97-5vj8.json b/advisories/unreviewed/2024/11/GHSA-fqxx-5f97-5vj8/GHSA-fqxx-5f97-5vj8.json index 230a285779f..7ac92ef4bee 100644 --- a/advisories/unreviewed/2024/11/GHSA-fqxx-5f97-5vj8/GHSA-fqxx-5f97-5vj8.json +++ b/advisories/unreviewed/2024/11/GHSA-fqxx-5f97-5vj8/GHSA-fqxx-5f97-5vj8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-g28c-hcr7-j2fw/GHSA-g28c-hcr7-j2fw.json b/advisories/unreviewed/2024/11/GHSA-g28c-hcr7-j2fw/GHSA-g28c-hcr7-j2fw.json index 2f50d3ad349..297030bddae 100644 --- a/advisories/unreviewed/2024/11/GHSA-g28c-hcr7-j2fw/GHSA-g28c-hcr7-j2fw.json +++ b/advisories/unreviewed/2024/11/GHSA-g28c-hcr7-j2fw/GHSA-g28c-hcr7-j2fw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-ghvj-wh2c-8cw6/GHSA-ghvj-wh2c-8cw6.json b/advisories/unreviewed/2024/11/GHSA-ghvj-wh2c-8cw6/GHSA-ghvj-wh2c-8cw6.json index f44cd4290d3..e5b2088c4e5 100644 --- a/advisories/unreviewed/2024/11/GHSA-ghvj-wh2c-8cw6/GHSA-ghvj-wh2c-8cw6.json +++ b/advisories/unreviewed/2024/11/GHSA-ghvj-wh2c-8cw6/GHSA-ghvj-wh2c-8cw6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-gm76-wjf8-pqmp/GHSA-gm76-wjf8-pqmp.json b/advisories/unreviewed/2024/11/GHSA-gm76-wjf8-pqmp/GHSA-gm76-wjf8-pqmp.json index a63183be9ab..ca0540aab24 100644 --- a/advisories/unreviewed/2024/11/GHSA-gm76-wjf8-pqmp/GHSA-gm76-wjf8-pqmp.json +++ b/advisories/unreviewed/2024/11/GHSA-gm76-wjf8-pqmp/GHSA-gm76-wjf8-pqmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-grx6-q36w-3gr9/GHSA-grx6-q36w-3gr9.json b/advisories/unreviewed/2024/11/GHSA-grx6-q36w-3gr9/GHSA-grx6-q36w-3gr9.json index 8eae84cd055..549c56e14a6 100644 --- a/advisories/unreviewed/2024/11/GHSA-grx6-q36w-3gr9/GHSA-grx6-q36w-3gr9.json +++ b/advisories/unreviewed/2024/11/GHSA-grx6-q36w-3gr9/GHSA-grx6-q36w-3gr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-h2qp-c6r3-cg2g/GHSA-h2qp-c6r3-cg2g.json b/advisories/unreviewed/2024/11/GHSA-h2qp-c6r3-cg2g/GHSA-h2qp-c6r3-cg2g.json index b92c3f1854b..059491f6953 100644 --- a/advisories/unreviewed/2024/11/GHSA-h2qp-c6r3-cg2g/GHSA-h2qp-c6r3-cg2g.json +++ b/advisories/unreviewed/2024/11/GHSA-h2qp-c6r3-cg2g/GHSA-h2qp-c6r3-cg2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-h8w4-623w-34f7/GHSA-h8w4-623w-34f7.json b/advisories/unreviewed/2024/11/GHSA-h8w4-623w-34f7/GHSA-h8w4-623w-34f7.json index e8408451a6d..7320d9aff51 100644 --- a/advisories/unreviewed/2024/11/GHSA-h8w4-623w-34f7/GHSA-h8w4-623w-34f7.json +++ b/advisories/unreviewed/2024/11/GHSA-h8w4-623w-34f7/GHSA-h8w4-623w-34f7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-hq9x-p5wc-jxf8/GHSA-hq9x-p5wc-jxf8.json b/advisories/unreviewed/2024/11/GHSA-hq9x-p5wc-jxf8/GHSA-hq9x-p5wc-jxf8.json index dc5f15b4ee5..2387b191aac 100644 --- a/advisories/unreviewed/2024/11/GHSA-hq9x-p5wc-jxf8/GHSA-hq9x-p5wc-jxf8.json +++ b/advisories/unreviewed/2024/11/GHSA-hq9x-p5wc-jxf8/GHSA-hq9x-p5wc-jxf8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-j6r2-9gj9-jmvp/GHSA-j6r2-9gj9-jmvp.json b/advisories/unreviewed/2024/11/GHSA-j6r2-9gj9-jmvp/GHSA-j6r2-9gj9-jmvp.json index e0ef0681813..010dd66c26a 100644 --- a/advisories/unreviewed/2024/11/GHSA-j6r2-9gj9-jmvp/GHSA-j6r2-9gj9-jmvp.json +++ b/advisories/unreviewed/2024/11/GHSA-j6r2-9gj9-jmvp/GHSA-j6r2-9gj9-jmvp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-mp4r-q64f-52vf/GHSA-mp4r-q64f-52vf.json b/advisories/unreviewed/2024/11/GHSA-mp4r-q64f-52vf/GHSA-mp4r-q64f-52vf.json index a93c040cfa7..d800b73ad16 100644 --- a/advisories/unreviewed/2024/11/GHSA-mp4r-q64f-52vf/GHSA-mp4r-q64f-52vf.json +++ b/advisories/unreviewed/2024/11/GHSA-mp4r-q64f-52vf/GHSA-mp4r-q64f-52vf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-p53m-6hr5-83pp/GHSA-p53m-6hr5-83pp.json b/advisories/unreviewed/2024/11/GHSA-p53m-6hr5-83pp/GHSA-p53m-6hr5-83pp.json index 43ab819d708..df3c689bd97 100644 --- a/advisories/unreviewed/2024/11/GHSA-p53m-6hr5-83pp/GHSA-p53m-6hr5-83pp.json +++ b/advisories/unreviewed/2024/11/GHSA-p53m-6hr5-83pp/GHSA-p53m-6hr5-83pp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-pmgm-5xgm-7h8f/GHSA-pmgm-5xgm-7h8f.json b/advisories/unreviewed/2024/11/GHSA-pmgm-5xgm-7h8f/GHSA-pmgm-5xgm-7h8f.json index af1f56f3b5e..413d42a0865 100644 --- a/advisories/unreviewed/2024/11/GHSA-pmgm-5xgm-7h8f/GHSA-pmgm-5xgm-7h8f.json +++ b/advisories/unreviewed/2024/11/GHSA-pmgm-5xgm-7h8f/GHSA-pmgm-5xgm-7h8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-qgjh-44qj-vgv5/GHSA-qgjh-44qj-vgv5.json b/advisories/unreviewed/2024/11/GHSA-qgjh-44qj-vgv5/GHSA-qgjh-44qj-vgv5.json index ac7055f7e3a..9b569b71f61 100644 --- a/advisories/unreviewed/2024/11/GHSA-qgjh-44qj-vgv5/GHSA-qgjh-44qj-vgv5.json +++ b/advisories/unreviewed/2024/11/GHSA-qgjh-44qj-vgv5/GHSA-qgjh-44qj-vgv5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-qmjq-qm3j-h6v3/GHSA-qmjq-qm3j-h6v3.json b/advisories/unreviewed/2024/11/GHSA-qmjq-qm3j-h6v3/GHSA-qmjq-qm3j-h6v3.json index 0d5075cc0ca..b973eefef00 100644 --- a/advisories/unreviewed/2024/11/GHSA-qmjq-qm3j-h6v3/GHSA-qmjq-qm3j-h6v3.json +++ b/advisories/unreviewed/2024/11/GHSA-qmjq-qm3j-h6v3/GHSA-qmjq-qm3j-h6v3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-rfpm-vfqf-wj57/GHSA-rfpm-vfqf-wj57.json b/advisories/unreviewed/2024/11/GHSA-rfpm-vfqf-wj57/GHSA-rfpm-vfqf-wj57.json index 596b8227917..b49f8d2acab 100644 --- a/advisories/unreviewed/2024/11/GHSA-rfpm-vfqf-wj57/GHSA-rfpm-vfqf-wj57.json +++ b/advisories/unreviewed/2024/11/GHSA-rfpm-vfqf-wj57/GHSA-rfpm-vfqf-wj57.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-rq38-6mrr-6jhw/GHSA-rq38-6mrr-6jhw.json b/advisories/unreviewed/2024/11/GHSA-rq38-6mrr-6jhw/GHSA-rq38-6mrr-6jhw.json index f0d56a6106f..142e6530694 100644 --- a/advisories/unreviewed/2024/11/GHSA-rq38-6mrr-6jhw/GHSA-rq38-6mrr-6jhw.json +++ b/advisories/unreviewed/2024/11/GHSA-rq38-6mrr-6jhw/GHSA-rq38-6mrr-6jhw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-rw84-778g-54fc/GHSA-rw84-778g-54fc.json b/advisories/unreviewed/2024/11/GHSA-rw84-778g-54fc/GHSA-rw84-778g-54fc.json index ba9680b2bf4..12b4c4f9c1d 100644 --- a/advisories/unreviewed/2024/11/GHSA-rw84-778g-54fc/GHSA-rw84-778g-54fc.json +++ b/advisories/unreviewed/2024/11/GHSA-rw84-778g-54fc/GHSA-rw84-778g-54fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-rwff-g3qh-f9xh/GHSA-rwff-g3qh-f9xh.json b/advisories/unreviewed/2024/11/GHSA-rwff-g3qh-f9xh/GHSA-rwff-g3qh-f9xh.json index a2cc82a20b0..c8037d002fa 100644 --- a/advisories/unreviewed/2024/11/GHSA-rwff-g3qh-f9xh/GHSA-rwff-g3qh-f9xh.json +++ b/advisories/unreviewed/2024/11/GHSA-rwff-g3qh-f9xh/GHSA-rwff-g3qh-f9xh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-v3xc-c94g-8jpm/GHSA-v3xc-c94g-8jpm.json b/advisories/unreviewed/2024/11/GHSA-v3xc-c94g-8jpm/GHSA-v3xc-c94g-8jpm.json index 03f2c8ee918..21dcb130bea 100644 --- a/advisories/unreviewed/2024/11/GHSA-v3xc-c94g-8jpm/GHSA-v3xc-c94g-8jpm.json +++ b/advisories/unreviewed/2024/11/GHSA-v3xc-c94g-8jpm/GHSA-v3xc-c94g-8jpm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-v68f-887p-phw7/GHSA-v68f-887p-phw7.json b/advisories/unreviewed/2024/11/GHSA-v68f-887p-phw7/GHSA-v68f-887p-phw7.json index 1c7e8ab7ee7..94a9659d80e 100644 --- a/advisories/unreviewed/2024/11/GHSA-v68f-887p-phw7/GHSA-v68f-887p-phw7.json +++ b/advisories/unreviewed/2024/11/GHSA-v68f-887p-phw7/GHSA-v68f-887p-phw7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-v98h-rr4x-822v/GHSA-v98h-rr4x-822v.json b/advisories/unreviewed/2024/11/GHSA-v98h-rr4x-822v/GHSA-v98h-rr4x-822v.json index 05f86085435..d7ec228b586 100644 --- a/advisories/unreviewed/2024/11/GHSA-v98h-rr4x-822v/GHSA-v98h-rr4x-822v.json +++ b/advisories/unreviewed/2024/11/GHSA-v98h-rr4x-822v/GHSA-v98h-rr4x-822v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-vv32-h72m-mqmf/GHSA-vv32-h72m-mqmf.json b/advisories/unreviewed/2024/11/GHSA-vv32-h72m-mqmf/GHSA-vv32-h72m-mqmf.json index d2621a20611..905be12fa71 100644 --- a/advisories/unreviewed/2024/11/GHSA-vv32-h72m-mqmf/GHSA-vv32-h72m-mqmf.json +++ b/advisories/unreviewed/2024/11/GHSA-vv32-h72m-mqmf/GHSA-vv32-h72m-mqmf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-ww63-p33h-p4hw/GHSA-ww63-p33h-p4hw.json b/advisories/unreviewed/2024/11/GHSA-ww63-p33h-p4hw/GHSA-ww63-p33h-p4hw.json index 8b672875811..aad6d07d6d8 100644 --- a/advisories/unreviewed/2024/11/GHSA-ww63-p33h-p4hw/GHSA-ww63-p33h-p4hw.json +++ b/advisories/unreviewed/2024/11/GHSA-ww63-p33h-p4hw/GHSA-ww63-p33h-p4hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-x6qj-888v-44p6/GHSA-x6qj-888v-44p6.json b/advisories/unreviewed/2024/11/GHSA-x6qj-888v-44p6/GHSA-x6qj-888v-44p6.json index 78bd1e94413..bd5fcec747a 100644 --- a/advisories/unreviewed/2024/11/GHSA-x6qj-888v-44p6/GHSA-x6qj-888v-44p6.json +++ b/advisories/unreviewed/2024/11/GHSA-x6qj-888v-44p6/GHSA-x6qj-888v-44p6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",