diff --git a/advisories/github-reviewed/2022/03/GHSA-49fj-qp6p-q544/GHSA-49fj-qp6p-q544.json b/advisories/github-reviewed/2022/03/GHSA-49fj-qp6p-q544/GHSA-49fj-qp6p-q544.json index aeb8559b74f..a30fb36fcc9 100644 --- a/advisories/github-reviewed/2022/03/GHSA-49fj-qp6p-q544/GHSA-49fj-qp6p-q544.json +++ b/advisories/github-reviewed/2022/03/GHSA-49fj-qp6p-q544/GHSA-49fj-qp6p-q544.json @@ -62,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-05-15T21:04:17Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-32hg-73hp-vwc8/GHSA-32hg-73hp-vwc8.json b/advisories/github-reviewed/2022/05/GHSA-32hg-73hp-vwc8/GHSA-32hg-73hp-vwc8.json index c250b4bc91a..1e91be04ce4 100644 --- a/advisories/github-reviewed/2022/05/GHSA-32hg-73hp-vwc8/GHSA-32hg-73hp-vwc8.json +++ b/advisories/github-reviewed/2022/05/GHSA-32hg-73hp-vwc8/GHSA-32hg-73hp-vwc8.json @@ -128,9 +128,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-26T20:14:34Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-8mvw-22r7-w6fq/GHSA-8mvw-22r7-w6fq.json b/advisories/github-reviewed/2022/05/GHSA-8mvw-22r7-w6fq/GHSA-8mvw-22r7-w6fq.json index 560ca6fb7c7..bc764ea02ca 100644 --- a/advisories/github-reviewed/2022/05/GHSA-8mvw-22r7-w6fq/GHSA-8mvw-22r7-w6fq.json +++ b/advisories/github-reviewed/2022/05/GHSA-8mvw-22r7-w6fq/GHSA-8mvw-22r7-w6fq.json @@ -8,9 +8,7 @@ ], "summary": "ruby_parser allows local users to overwrite arbitrary files via symlink attack on temporary file with predictable name", "details": "The `diff_pp` function in `lib/gauntlet_rubyparser.rb` in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in `/tmp`.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-9qvm-2vhf-q649/GHSA-9qvm-2vhf-q649.json b/advisories/github-reviewed/2022/05/GHSA-9qvm-2vhf-q649/GHSA-9qvm-2vhf-q649.json index db45aa2fab3..66d0100f5c8 100644 --- a/advisories/github-reviewed/2022/05/GHSA-9qvm-2vhf-q649/GHSA-9qvm-2vhf-q649.json +++ b/advisories/github-reviewed/2022/05/GHSA-9qvm-2vhf-q649/GHSA-9qvm-2vhf-q649.json @@ -8,9 +8,7 @@ ], "summary": "RubyGems Regular Expression Denial of Service", "details": "Algorithmic complexity vulnerability in `Gem::Version::ANCHORED_VERSION_PATTERN` in `lib/rubygems/version.rb` in RubyGems before 1.8.23.2, 1.8.24 through 1.8.26, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression. NOTE: this issue is due to an incomplete fix for CVE-2013-4287.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -124,9 +122,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-03-08T19:54:54Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-w9ph-q4h9-rwq6/GHSA-w9ph-q4h9-rwq6.json b/advisories/github-reviewed/2022/05/GHSA-w9ph-q4h9-rwq6/GHSA-w9ph-q4h9-rwq6.json index 97e052a8e43..80588413bd5 100644 --- a/advisories/github-reviewed/2022/05/GHSA-w9ph-q4h9-rwq6/GHSA-w9ph-q4h9-rwq6.json +++ b/advisories/github-reviewed/2022/05/GHSA-w9ph-q4h9-rwq6/GHSA-w9ph-q4h9-rwq6.json @@ -85,9 +85,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-08-16T23:04:17Z", diff --git a/advisories/github-reviewed/2023/06/GHSA-jx7q-xxmw-44vf/GHSA-jx7q-xxmw-44vf.json b/advisories/github-reviewed/2023/06/GHSA-jx7q-xxmw-44vf/GHSA-jx7q-xxmw-44vf.json index 451608ec0d2..d7af06c5566 100644 --- a/advisories/github-reviewed/2023/06/GHSA-jx7q-xxmw-44vf/GHSA-jx7q-xxmw-44vf.json +++ b/advisories/github-reviewed/2023/06/GHSA-jx7q-xxmw-44vf/GHSA-jx7q-xxmw-44vf.json @@ -567,9 +567,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-06-14T17:04:29Z", diff --git a/advisories/github-reviewed/2023/08/GHSA-jxcx-3h54-qqxx/GHSA-jxcx-3h54-qqxx.json b/advisories/github-reviewed/2023/08/GHSA-jxcx-3h54-qqxx/GHSA-jxcx-3h54-qqxx.json index 06e45778e0a..06ab0355ce6 100644 --- a/advisories/github-reviewed/2023/08/GHSA-jxcx-3h54-qqxx/GHSA-jxcx-3h54-qqxx.json +++ b/advisories/github-reviewed/2023/08/GHSA-jxcx-3h54-qqxx/GHSA-jxcx-3h54-qqxx.json @@ -3,14 +3,10 @@ "id": "GHSA-jxcx-3h54-qqxx", "modified": "2023-08-23T19:43:56Z", "published": "2023-08-23T19:43:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "SilverStripe CMS Cross-site Scripting vulnerabilities inherited from TinyMCE", "details": "TinyMCE 4.x is vulnerable to several XSS vectors, which had been patched in later versions. Two of these have been identified as affecting silverstripe/admin.\n\nOnly Silverstripe CMS 4 is affected by these vulnerabilities. It's not possible to upgrade Silverstripe CMS 4 to use a more recent release of TinyMCE without introducing breaking changes. Instead, the security patches that shipped in later releases of TinyMCE have been backported to the TinyMCE version bundled in silverstripe/admin.\n\nSilverstripe CMS 5 is not affected by these vulnerabilities because it uses TinyMCE 6.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2023/12/GHSA-r24f-hg58-vfrw/GHSA-r24f-hg58-vfrw.json b/advisories/github-reviewed/2023/12/GHSA-r24f-hg58-vfrw/GHSA-r24f-hg58-vfrw.json index e06734f2c7e..cc012c025e0 100644 --- a/advisories/github-reviewed/2023/12/GHSA-r24f-hg58-vfrw/GHSA-r24f-hg58-vfrw.json +++ b/advisories/github-reviewed/2023/12/GHSA-r24f-hg58-vfrw/GHSA-r24f-hg58-vfrw.json @@ -3,14 +3,10 @@ "id": "GHSA-r24f-hg58-vfrw", "modified": "2023-12-21T18:14:34Z", "published": "2023-12-21T18:14:34Z", - "aliases": [ - - ], + "aliases": [], "summary": "unsafe-libyaml unaligned write of u64 on 32-bit and 16-bit platforms", "details": "Affected versions allocate memory using the alignment of `usize` and write data to it of type `u64`, without using `core::ptr::write_unaligned`. In platforms with sub-64bit alignment for `usize` (including wasm32 and x86) these writes are insufficiently aligned some of the time.\n\nIf using an ordinary optimized standard library, the bug exhibits Undefined Behavior so may or may not behave in any sensible way, depending on optimization settings and hardware and other things. If using a Rust standard library built with debug assertions enabled, the bug manifests deterministically in a crash (non-unwinding panic) saying _\"ptr::write requires that the pointer argument is aligned and non-null\"_.\n\nNo 64-bit platform is impacted by the bug.\n\nThe flaw was corrected by allocating with adequately high alignment on all\nplatforms.\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -51,9 +47,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-12-21T18:14:34Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-38m8-5gfc-663g/GHSA-38m8-5gfc-663g.json b/advisories/github-reviewed/2024/02/GHSA-38m8-5gfc-663g/GHSA-38m8-5gfc-663g.json index bbe605982c6..241890793d0 100644 --- a/advisories/github-reviewed/2024/02/GHSA-38m8-5gfc-663g/GHSA-38m8-5gfc-663g.json +++ b/advisories/github-reviewed/2024/02/GHSA-38m8-5gfc-663g/GHSA-38m8-5gfc-663g.json @@ -8,9 +8,7 @@ ], "summary": "Enhavo Cross-site Scripting vulnerability", "details": "A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Create Tag text field.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/02/GHSA-4j93-fm92-rp4m/GHSA-4j93-fm92-rp4m.json b/advisories/github-reviewed/2024/02/GHSA-4j93-fm92-rp4m/GHSA-4j93-fm92-rp4m.json index e7c7c5d809e..92b59527e48 100644 --- a/advisories/github-reviewed/2024/02/GHSA-4j93-fm92-rp4m/GHSA-4j93-fm92-rp4m.json +++ b/advisories/github-reviewed/2024/02/GHSA-4j93-fm92-rp4m/GHSA-4j93-fm92-rp4m.json @@ -3,9 +3,7 @@ "id": "GHSA-4j93-fm92-rp4m", "modified": "2024-07-02T02:36:00Z", "published": "2024-02-21T00:12:51Z", - "aliases": [ - - ], + "aliases": [], "summary": "ASA-2024-003: Missing `BlockedAddressed` Validation in Vesting Module", "details": "## ASA-2024-003: Missing `BlockedAddressed` Validation in Vesting Module\n\n**Component**: Cosmos SDK\n**Criticality**: Low\n**Affected Versions**: Cosmos SDK versions <= 0.50.3; <= 0.47.8\n**Affected Users**: Chain developers, Validator and Node operators\n**Impact**: Denial of Service\n\n## Description\n\nA vulnerability was identified in the `x/auth/vesting` module, which can allow a user to create a periodic vesting account on a blocked address, for example a non-initialized module account. Additional validation was added to prevent creation of a periodic vesting account in this scenario.\n\nIf this case is triggered, there is the potential for a chain halt if the uninitialized account in question is called by `GetModuleAccount` in `Begin`/`EndBlock` of a module. This combination of an uninitialized blocked module account is not common. \n\n## Next Steps for Impacted Parties\n\nIf your chain has uninitialized blocked module accounts, it is recommended to proactively initialize them, as they are often initialized during a chain migration or during init genesis.\n\nIf you are a chain developer on an affected version of the Cosmos SDK, it is advised to update to the latest available version of the Cosmos SDK for your project. Once a patched version is available, it is recommended that network operators upgrade.\n\nA Github Security Advisory for this issue is available in the Cosmos-SDK [repository](https://github.com/cosmos/cosmos-sdk/security/advisories). For more information about Cosmos SDK, see https://docs.cosmos.network/.\n\nThis issue was found by [Dongsam](https://github.com/dongsam) who reported it to the Cosmos Bug Bounty Program on HackerOne on January 30, 2024. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos.\n\n## Addendum\n\nA variant trigger of this issue via the `x/authz` and `x/feegrant` modules was discovered by [Richie](https://github.com/sushiwushi) who reported it to the Cosmos Bug Bounty Program on HackerOne on April 6th, 2024, and was subsequently fixed by the Cosmos SDK team on April 21st, 2024. The guidance for mitigating this additional variant is the same as the parent advisory, so it is suggested that all chains proactively initialize module accounts if they have not already done so.", "severity": [ diff --git a/advisories/github-reviewed/2024/02/GHSA-8pf2-qj4v-fj64/GHSA-8pf2-qj4v-fj64.json b/advisories/github-reviewed/2024/02/GHSA-8pf2-qj4v-fj64/GHSA-8pf2-qj4v-fj64.json index 7845baefd06..8ed928ed604 100644 --- a/advisories/github-reviewed/2024/02/GHSA-8pf2-qj4v-fj64/GHSA-8pf2-qj4v-fj64.json +++ b/advisories/github-reviewed/2024/02/GHSA-8pf2-qj4v-fj64/GHSA-8pf2-qj4v-fj64.json @@ -8,9 +8,7 @@ ], "summary": "Apache Answer Cross-site Scripting vulnerability", "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer. This issue affects Apache Answer through 1.2.1.\n\nXSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack.\n\nUsers are recommended to upgrade to version 1.2.5, which fixes the issue.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/02/GHSA-9q24-hwmc-797x/GHSA-9q24-hwmc-797x.json b/advisories/github-reviewed/2024/02/GHSA-9q24-hwmc-797x/GHSA-9q24-hwmc-797x.json index 7fdaa53868c..8ceea6ee9dd 100644 --- a/advisories/github-reviewed/2024/02/GHSA-9q24-hwmc-797x/GHSA-9q24-hwmc-797x.json +++ b/advisories/github-reviewed/2024/02/GHSA-9q24-hwmc-797x/GHSA-9q24-hwmc-797x.json @@ -8,9 +8,7 @@ ], "summary": "Apache Answer Race Condition vulnerability", "details": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer through 1.2.1.\n\nRepeated submission during registration resulted in the registration of the same user. When users register, if they rapidly submit multiple registrations using scripts, it can result in the creation of multiple user accounts simultaneously with the same name.\n\nUsers are recommended to upgrade to version 1.2.5, which fixes the issue.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/02/GHSA-fvv5-h29g-f6w5/GHSA-fvv5-h29g-f6w5.json b/advisories/github-reviewed/2024/02/GHSA-fvv5-h29g-f6w5/GHSA-fvv5-h29g-f6w5.json index b2db20fda2f..7c0ba16229c 100644 --- a/advisories/github-reviewed/2024/02/GHSA-fvv5-h29g-f6w5/GHSA-fvv5-h29g-f6w5.json +++ b/advisories/github-reviewed/2024/02/GHSA-fvv5-h29g-f6w5/GHSA-fvv5-h29g-f6w5.json @@ -3,9 +3,7 @@ "id": "GHSA-fvv5-h29g-f6w5", "modified": "2024-02-22T21:36:04Z", "published": "2024-02-22T21:36:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository", "details": "### Impact\n\nA bug in permissions validation allows a user with the `ci:ReadAction` permission to skip read checks when copying an object. If they additionally have read and write permission to path in the repository, they can copy an otherwise unreadable object and read it.\n\nIn order to be affected and exploitable, the following conditions must ALL occur on the same user:\n1. `ci:ReadAction` enabled for the repository. Predefined policies RepoManagementRead and RepoManagementFullAccess allow this action.\n2. `fs:ReadObject` and `fs:WriteObject` enabled for some path.\n3. `fs:ReadObject` _not_ available for some path\n\nSuch a user can use (1) to copy the unreadable object (3) to a path that they can read and write (2). At that point they can read the object copy.\n\n### Patches\n\nReleases >= 1.12.1 fix this issue in lakeFS.\n\n### Workarounds\n\nAs a workaround, use RBAC to deny `ci:*` permissions to all users, or to all users who have limited read access.\n\nMany installations are unaffected:\n\n* **Installations using ACLs are _not_ affected.** This includes all OSS installations that have not implemented an external authorization server. We do not know of any OSS installations that have implemented such a server. ACLs that allow ci:ReadAction also allow reading repositories, so no capabilities are granted.\n* **Installations using RBAC that use only predefined policies with \"all\" ARNs (\"*\") are _not_ affected.** This includes **all installations that have not defined any new groups in RBAC.**\n\nIn order to be affected, **installations using RBAC** must define users and simultaneous allow `ci:ReadAction` and disallow `fs:ReadObject` for some path. `ci:ReadAction` is available in policies RepoManagementReadAll and RepoManagementFullAccess. By default these actions are configured for groups Developers and above, for all repositories and paths.\n\n\n### References\n\n* [lakeFS RBAC](https://docs.lakefs.io/reference/security/rbac.html)\n\n", "severity": [ @@ -53,9 +51,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-22T21:36:04Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-gj48-w74w-8gvm/GHSA-gj48-w74w-8gvm.json b/advisories/github-reviewed/2024/02/GHSA-gj48-w74w-8gvm/GHSA-gj48-w74w-8gvm.json index af5fa1ec1dc..9715d6d18db 100644 --- a/advisories/github-reviewed/2024/02/GHSA-gj48-w74w-8gvm/GHSA-gj48-w74w-8gvm.json +++ b/advisories/github-reviewed/2024/02/GHSA-gj48-w74w-8gvm/GHSA-gj48-w74w-8gvm.json @@ -3,14 +3,10 @@ "id": "GHSA-gj48-w74w-8gvm", "modified": "2024-02-22T10:51:10Z", "published": "2024-02-22T10:51:10Z", - "aliases": [ - - ], + "aliases": [], "summary": "Path Traversal in TYPO3 Core", "details": "Due to a too loose type check in an API method, attackers could bypass the directory traversal check by providing an invalid UTF-8 encoding sequence.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -81,9 +77,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-22T10:51:10Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-m43p-55rf-8c2j/GHSA-m43p-55rf-8c2j.json b/advisories/github-reviewed/2024/02/GHSA-m43p-55rf-8c2j/GHSA-m43p-55rf-8c2j.json index 806a3fe5d60..0666f0e3836 100644 --- a/advisories/github-reviewed/2024/02/GHSA-m43p-55rf-8c2j/GHSA-m43p-55rf-8c2j.json +++ b/advisories/github-reviewed/2024/02/GHSA-m43p-55rf-8c2j/GHSA-m43p-55rf-8c2j.json @@ -8,9 +8,7 @@ ], "summary": "Deserialization of Untrusted Data in Apache Camel CassandraQL", "details": "Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0.\n\nUsers are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/unreviewed/2022/02/GHSA-332r-78jx-2j2m/GHSA-332r-78jx-2j2m.json b/advisories/unreviewed/2022/02/GHSA-332r-78jx-2j2m/GHSA-332r-78jx-2j2m.json index 168927e10b3..229b246e7da 100644 --- a/advisories/unreviewed/2022/02/GHSA-332r-78jx-2j2m/GHSA-332r-78jx-2j2m.json +++ b/advisories/unreviewed/2022/02/GHSA-332r-78jx-2j2m/GHSA-332r-78jx-2j2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-3fcg-56fr-gpww/GHSA-3fcg-56fr-gpww.json b/advisories/unreviewed/2022/02/GHSA-3fcg-56fr-gpww/GHSA-3fcg-56fr-gpww.json index 6191654b216..cd3a942ed16 100644 --- a/advisories/unreviewed/2022/02/GHSA-3fcg-56fr-gpww/GHSA-3fcg-56fr-gpww.json +++ b/advisories/unreviewed/2022/02/GHSA-3fcg-56fr-gpww/GHSA-3fcg-56fr-gpww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-3gf2-723m-w3fv/GHSA-3gf2-723m-w3fv.json b/advisories/unreviewed/2022/02/GHSA-3gf2-723m-w3fv/GHSA-3gf2-723m-w3fv.json index 6b3af36d027..4d8cedb4117 100644 --- a/advisories/unreviewed/2022/02/GHSA-3gf2-723m-w3fv/GHSA-3gf2-723m-w3fv.json +++ b/advisories/unreviewed/2022/02/GHSA-3gf2-723m-w3fv/GHSA-3gf2-723m-w3fv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-3hmg-j35p-w2ww/GHSA-3hmg-j35p-w2ww.json b/advisories/unreviewed/2022/02/GHSA-3hmg-j35p-w2ww/GHSA-3hmg-j35p-w2ww.json index 3d22c0e522f..7caa7fa1f34 100644 --- a/advisories/unreviewed/2022/02/GHSA-3hmg-j35p-w2ww/GHSA-3hmg-j35p-w2ww.json +++ b/advisories/unreviewed/2022/02/GHSA-3hmg-j35p-w2ww/GHSA-3hmg-j35p-w2ww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-3jv4-4ccq-7qx5/GHSA-3jv4-4ccq-7qx5.json b/advisories/unreviewed/2022/02/GHSA-3jv4-4ccq-7qx5/GHSA-3jv4-4ccq-7qx5.json index 89ae62f8419..10cea9d707e 100644 --- a/advisories/unreviewed/2022/02/GHSA-3jv4-4ccq-7qx5/GHSA-3jv4-4ccq-7qx5.json +++ b/advisories/unreviewed/2022/02/GHSA-3jv4-4ccq-7qx5/GHSA-3jv4-4ccq-7qx5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-3pmw-f2r9-3rwg/GHSA-3pmw-f2r9-3rwg.json b/advisories/unreviewed/2022/02/GHSA-3pmw-f2r9-3rwg/GHSA-3pmw-f2r9-3rwg.json index 8b634810269..d72fd93589a 100644 --- a/advisories/unreviewed/2022/02/GHSA-3pmw-f2r9-3rwg/GHSA-3pmw-f2r9-3rwg.json +++ b/advisories/unreviewed/2022/02/GHSA-3pmw-f2r9-3rwg/GHSA-3pmw-f2r9-3rwg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-3q9w-xvhm-rg6c/GHSA-3q9w-xvhm-rg6c.json b/advisories/unreviewed/2022/02/GHSA-3q9w-xvhm-rg6c/GHSA-3q9w-xvhm-rg6c.json index bbe85ed5873..fb3ab158fa3 100644 --- a/advisories/unreviewed/2022/02/GHSA-3q9w-xvhm-rg6c/GHSA-3q9w-xvhm-rg6c.json +++ b/advisories/unreviewed/2022/02/GHSA-3q9w-xvhm-rg6c/GHSA-3q9w-xvhm-rg6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-458p-jh3w-vf34/GHSA-458p-jh3w-vf34.json b/advisories/unreviewed/2022/02/GHSA-458p-jh3w-vf34/GHSA-458p-jh3w-vf34.json index 77b10f3afca..547930379df 100644 --- a/advisories/unreviewed/2022/02/GHSA-458p-jh3w-vf34/GHSA-458p-jh3w-vf34.json +++ b/advisories/unreviewed/2022/02/GHSA-458p-jh3w-vf34/GHSA-458p-jh3w-vf34.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-48qq-gvpc-rg7v/GHSA-48qq-gvpc-rg7v.json b/advisories/unreviewed/2022/02/GHSA-48qq-gvpc-rg7v/GHSA-48qq-gvpc-rg7v.json index 8bbf321fc6b..dbad2480146 100644 --- a/advisories/unreviewed/2022/02/GHSA-48qq-gvpc-rg7v/GHSA-48qq-gvpc-rg7v.json +++ b/advisories/unreviewed/2022/02/GHSA-48qq-gvpc-rg7v/GHSA-48qq-gvpc-rg7v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-4g9f-cj32-8jmq/GHSA-4g9f-cj32-8jmq.json b/advisories/unreviewed/2022/02/GHSA-4g9f-cj32-8jmq/GHSA-4g9f-cj32-8jmq.json index d332e6a69ec..c9b3d8d0dd5 100644 --- a/advisories/unreviewed/2022/02/GHSA-4g9f-cj32-8jmq/GHSA-4g9f-cj32-8jmq.json +++ b/advisories/unreviewed/2022/02/GHSA-4g9f-cj32-8jmq/GHSA-4g9f-cj32-8jmq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-4vjv-fmc3-6724/GHSA-4vjv-fmc3-6724.json b/advisories/unreviewed/2022/02/GHSA-4vjv-fmc3-6724/GHSA-4vjv-fmc3-6724.json index 121bc6d816e..4f315505060 100644 --- a/advisories/unreviewed/2022/02/GHSA-4vjv-fmc3-6724/GHSA-4vjv-fmc3-6724.json +++ b/advisories/unreviewed/2022/02/GHSA-4vjv-fmc3-6724/GHSA-4vjv-fmc3-6724.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-56mw-g4x8-4wwm/GHSA-56mw-g4x8-4wwm.json b/advisories/unreviewed/2022/02/GHSA-56mw-g4x8-4wwm/GHSA-56mw-g4x8-4wwm.json index 006741860fc..ba74cb79b12 100644 --- a/advisories/unreviewed/2022/02/GHSA-56mw-g4x8-4wwm/GHSA-56mw-g4x8-4wwm.json +++ b/advisories/unreviewed/2022/02/GHSA-56mw-g4x8-4wwm/GHSA-56mw-g4x8-4wwm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-5wgx-qvpv-2353/GHSA-5wgx-qvpv-2353.json b/advisories/unreviewed/2022/02/GHSA-5wgx-qvpv-2353/GHSA-5wgx-qvpv-2353.json index 94d24db5e7d..999ce9d0867 100644 --- a/advisories/unreviewed/2022/02/GHSA-5wgx-qvpv-2353/GHSA-5wgx-qvpv-2353.json +++ b/advisories/unreviewed/2022/02/GHSA-5wgx-qvpv-2353/GHSA-5wgx-qvpv-2353.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-5xwv-qfcf-c76h/GHSA-5xwv-qfcf-c76h.json b/advisories/unreviewed/2022/02/GHSA-5xwv-qfcf-c76h/GHSA-5xwv-qfcf-c76h.json index 01007d365a2..1754a8e5fb9 100644 --- a/advisories/unreviewed/2022/02/GHSA-5xwv-qfcf-c76h/GHSA-5xwv-qfcf-c76h.json +++ b/advisories/unreviewed/2022/02/GHSA-5xwv-qfcf-c76h/GHSA-5xwv-qfcf-c76h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-66jq-wfrj-9h9w/GHSA-66jq-wfrj-9h9w.json b/advisories/unreviewed/2022/02/GHSA-66jq-wfrj-9h9w/GHSA-66jq-wfrj-9h9w.json index 0417e8c9726..f6dfd4bcca9 100644 --- a/advisories/unreviewed/2022/02/GHSA-66jq-wfrj-9h9w/GHSA-66jq-wfrj-9h9w.json +++ b/advisories/unreviewed/2022/02/GHSA-66jq-wfrj-9h9w/GHSA-66jq-wfrj-9h9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-6mwh-463x-c3v4/GHSA-6mwh-463x-c3v4.json b/advisories/unreviewed/2022/02/GHSA-6mwh-463x-c3v4/GHSA-6mwh-463x-c3v4.json index 0c3bed11558..cdf7b4f86e0 100644 --- a/advisories/unreviewed/2022/02/GHSA-6mwh-463x-c3v4/GHSA-6mwh-463x-c3v4.json +++ b/advisories/unreviewed/2022/02/GHSA-6mwh-463x-c3v4/GHSA-6mwh-463x-c3v4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-77jc-q8hg-fhfv/GHSA-77jc-q8hg-fhfv.json b/advisories/unreviewed/2022/02/GHSA-77jc-q8hg-fhfv/GHSA-77jc-q8hg-fhfv.json index 434e5ef5678..ae4445c48dd 100644 --- a/advisories/unreviewed/2022/02/GHSA-77jc-q8hg-fhfv/GHSA-77jc-q8hg-fhfv.json +++ b/advisories/unreviewed/2022/02/GHSA-77jc-q8hg-fhfv/GHSA-77jc-q8hg-fhfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-7c5g-cjm9-2jm4/GHSA-7c5g-cjm9-2jm4.json b/advisories/unreviewed/2022/02/GHSA-7c5g-cjm9-2jm4/GHSA-7c5g-cjm9-2jm4.json index 72f8ae250c4..96a0a7576b1 100644 --- a/advisories/unreviewed/2022/02/GHSA-7c5g-cjm9-2jm4/GHSA-7c5g-cjm9-2jm4.json +++ b/advisories/unreviewed/2022/02/GHSA-7c5g-cjm9-2jm4/GHSA-7c5g-cjm9-2jm4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-7j34-7774-6g84/GHSA-7j34-7774-6g84.json b/advisories/unreviewed/2022/02/GHSA-7j34-7774-6g84/GHSA-7j34-7774-6g84.json index 65616ca8a10..6e6b3c4e0d8 100644 --- a/advisories/unreviewed/2022/02/GHSA-7j34-7774-6g84/GHSA-7j34-7774-6g84.json +++ b/advisories/unreviewed/2022/02/GHSA-7j34-7774-6g84/GHSA-7j34-7774-6g84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-9864-67c6-52h4/GHSA-9864-67c6-52h4.json b/advisories/unreviewed/2022/02/GHSA-9864-67c6-52h4/GHSA-9864-67c6-52h4.json index 87f9c86d8d3..d7759ac1a64 100644 --- a/advisories/unreviewed/2022/02/GHSA-9864-67c6-52h4/GHSA-9864-67c6-52h4.json +++ b/advisories/unreviewed/2022/02/GHSA-9864-67c6-52h4/GHSA-9864-67c6-52h4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-c79c-2jrq-4m25/GHSA-c79c-2jrq-4m25.json b/advisories/unreviewed/2022/02/GHSA-c79c-2jrq-4m25/GHSA-c79c-2jrq-4m25.json index 1237eac889e..ef239378856 100644 --- a/advisories/unreviewed/2022/02/GHSA-c79c-2jrq-4m25/GHSA-c79c-2jrq-4m25.json +++ b/advisories/unreviewed/2022/02/GHSA-c79c-2jrq-4m25/GHSA-c79c-2jrq-4m25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-cwqx-fr79-h3cp/GHSA-cwqx-fr79-h3cp.json b/advisories/unreviewed/2022/02/GHSA-cwqx-fr79-h3cp/GHSA-cwqx-fr79-h3cp.json index 3d20d9bdf88..53044699548 100644 --- a/advisories/unreviewed/2022/02/GHSA-cwqx-fr79-h3cp/GHSA-cwqx-fr79-h3cp.json +++ b/advisories/unreviewed/2022/02/GHSA-cwqx-fr79-h3cp/GHSA-cwqx-fr79-h3cp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-f8cv-4vrc-c4q2/GHSA-f8cv-4vrc-c4q2.json b/advisories/unreviewed/2022/02/GHSA-f8cv-4vrc-c4q2/GHSA-f8cv-4vrc-c4q2.json index c5c0d567df4..0efcef7816b 100644 --- a/advisories/unreviewed/2022/02/GHSA-f8cv-4vrc-c4q2/GHSA-f8cv-4vrc-c4q2.json +++ b/advisories/unreviewed/2022/02/GHSA-f8cv-4vrc-c4q2/GHSA-f8cv-4vrc-c4q2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/02/GHSA-gff3-6394-p6p3/GHSA-gff3-6394-p6p3.json b/advisories/unreviewed/2022/02/GHSA-gff3-6394-p6p3/GHSA-gff3-6394-p6p3.json index 64fe4aeff67..4b33e25c535 100644 --- a/advisories/unreviewed/2022/02/GHSA-gff3-6394-p6p3/GHSA-gff3-6394-p6p3.json +++ b/advisories/unreviewed/2022/02/GHSA-gff3-6394-p6p3/GHSA-gff3-6394-p6p3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-gpqq-6qqr-w84g/GHSA-gpqq-6qqr-w84g.json b/advisories/unreviewed/2022/02/GHSA-gpqq-6qqr-w84g/GHSA-gpqq-6qqr-w84g.json index e579e342794..8db1d43f132 100644 --- a/advisories/unreviewed/2022/02/GHSA-gpqq-6qqr-w84g/GHSA-gpqq-6qqr-w84g.json +++ b/advisories/unreviewed/2022/02/GHSA-gpqq-6qqr-w84g/GHSA-gpqq-6qqr-w84g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-hwv5-9763-pqc4/GHSA-hwv5-9763-pqc4.json b/advisories/unreviewed/2022/02/GHSA-hwv5-9763-pqc4/GHSA-hwv5-9763-pqc4.json index b58520849d5..1fbc3472560 100644 --- a/advisories/unreviewed/2022/02/GHSA-hwv5-9763-pqc4/GHSA-hwv5-9763-pqc4.json +++ b/advisories/unreviewed/2022/02/GHSA-hwv5-9763-pqc4/GHSA-hwv5-9763-pqc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-j8m3-w6cg-p954/GHSA-j8m3-w6cg-p954.json b/advisories/unreviewed/2022/02/GHSA-j8m3-w6cg-p954/GHSA-j8m3-w6cg-p954.json index 33e46eac5b7..28820dbcf41 100644 --- a/advisories/unreviewed/2022/02/GHSA-j8m3-w6cg-p954/GHSA-j8m3-w6cg-p954.json +++ b/advisories/unreviewed/2022/02/GHSA-j8m3-w6cg-p954/GHSA-j8m3-w6cg-p954.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-mw25-45p2-8556/GHSA-mw25-45p2-8556.json b/advisories/unreviewed/2022/02/GHSA-mw25-45p2-8556/GHSA-mw25-45p2-8556.json index 3980df7ccba..6f57d2b6748 100644 --- a/advisories/unreviewed/2022/02/GHSA-mw25-45p2-8556/GHSA-mw25-45p2-8556.json +++ b/advisories/unreviewed/2022/02/GHSA-mw25-45p2-8556/GHSA-mw25-45p2-8556.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-p4gv-mjgc-3g68/GHSA-p4gv-mjgc-3g68.json b/advisories/unreviewed/2022/02/GHSA-p4gv-mjgc-3g68/GHSA-p4gv-mjgc-3g68.json index c6f8f1ea70a..a61b3d7bfcb 100644 --- a/advisories/unreviewed/2022/02/GHSA-p4gv-mjgc-3g68/GHSA-p4gv-mjgc-3g68.json +++ b/advisories/unreviewed/2022/02/GHSA-p4gv-mjgc-3g68/GHSA-p4gv-mjgc-3g68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-pp6c-vpf6-h727/GHSA-pp6c-vpf6-h727.json b/advisories/unreviewed/2022/02/GHSA-pp6c-vpf6-h727/GHSA-pp6c-vpf6-h727.json index 6f7c61cdb83..3d9f2a0a90e 100644 --- a/advisories/unreviewed/2022/02/GHSA-pp6c-vpf6-h727/GHSA-pp6c-vpf6-h727.json +++ b/advisories/unreviewed/2022/02/GHSA-pp6c-vpf6-h727/GHSA-pp6c-vpf6-h727.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-q27g-667c-gwvg/GHSA-q27g-667c-gwvg.json b/advisories/unreviewed/2022/02/GHSA-q27g-667c-gwvg/GHSA-q27g-667c-gwvg.json index f7a6ae28c95..e8a3edda5da 100644 --- a/advisories/unreviewed/2022/02/GHSA-q27g-667c-gwvg/GHSA-q27g-667c-gwvg.json +++ b/advisories/unreviewed/2022/02/GHSA-q27g-667c-gwvg/GHSA-q27g-667c-gwvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-q29x-769x-935v/GHSA-q29x-769x-935v.json b/advisories/unreviewed/2022/02/GHSA-q29x-769x-935v/GHSA-q29x-769x-935v.json index 226ec96542c..c5b7c7e598b 100644 --- a/advisories/unreviewed/2022/02/GHSA-q29x-769x-935v/GHSA-q29x-769x-935v.json +++ b/advisories/unreviewed/2022/02/GHSA-q29x-769x-935v/GHSA-q29x-769x-935v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-qq2w-vpgq-jp7x/GHSA-qq2w-vpgq-jp7x.json b/advisories/unreviewed/2022/02/GHSA-qq2w-vpgq-jp7x/GHSA-qq2w-vpgq-jp7x.json index 38af1745a88..723d8f59887 100644 --- a/advisories/unreviewed/2022/02/GHSA-qq2w-vpgq-jp7x/GHSA-qq2w-vpgq-jp7x.json +++ b/advisories/unreviewed/2022/02/GHSA-qq2w-vpgq-jp7x/GHSA-qq2w-vpgq-jp7x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-rcvm-rqrr-gf3r/GHSA-rcvm-rqrr-gf3r.json b/advisories/unreviewed/2022/02/GHSA-rcvm-rqrr-gf3r/GHSA-rcvm-rqrr-gf3r.json index ee5e3d02f93..70d0cc0b530 100644 --- a/advisories/unreviewed/2022/02/GHSA-rcvm-rqrr-gf3r/GHSA-rcvm-rqrr-gf3r.json +++ b/advisories/unreviewed/2022/02/GHSA-rcvm-rqrr-gf3r/GHSA-rcvm-rqrr-gf3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-rg7g-mrvx-gg82/GHSA-rg7g-mrvx-gg82.json b/advisories/unreviewed/2022/02/GHSA-rg7g-mrvx-gg82/GHSA-rg7g-mrvx-gg82.json index 21c310cb016..0b1e358ea5e 100644 --- a/advisories/unreviewed/2022/02/GHSA-rg7g-mrvx-gg82/GHSA-rg7g-mrvx-gg82.json +++ b/advisories/unreviewed/2022/02/GHSA-rg7g-mrvx-gg82/GHSA-rg7g-mrvx-gg82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-rj4c-hx63-x3x2/GHSA-rj4c-hx63-x3x2.json b/advisories/unreviewed/2022/02/GHSA-rj4c-hx63-x3x2/GHSA-rj4c-hx63-x3x2.json index dd118c1bf75..1a8154047de 100644 --- a/advisories/unreviewed/2022/02/GHSA-rj4c-hx63-x3x2/GHSA-rj4c-hx63-x3x2.json +++ b/advisories/unreviewed/2022/02/GHSA-rj4c-hx63-x3x2/GHSA-rj4c-hx63-x3x2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-rmqv-xpvq-7fm9/GHSA-rmqv-xpvq-7fm9.json b/advisories/unreviewed/2022/02/GHSA-rmqv-xpvq-7fm9/GHSA-rmqv-xpvq-7fm9.json index 15f98bb59e9..6fa44787bbe 100644 --- a/advisories/unreviewed/2022/02/GHSA-rmqv-xpvq-7fm9/GHSA-rmqv-xpvq-7fm9.json +++ b/advisories/unreviewed/2022/02/GHSA-rmqv-xpvq-7fm9/GHSA-rmqv-xpvq-7fm9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-v4mx-vj69-j98g/GHSA-v4mx-vj69-j98g.json b/advisories/unreviewed/2022/02/GHSA-v4mx-vj69-j98g/GHSA-v4mx-vj69-j98g.json index 9792dba82d1..dbbd8cd8910 100644 --- a/advisories/unreviewed/2022/02/GHSA-v4mx-vj69-j98g/GHSA-v4mx-vj69-j98g.json +++ b/advisories/unreviewed/2022/02/GHSA-v4mx-vj69-j98g/GHSA-v4mx-vj69-j98g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-vp3c-gmr6-8g2m/GHSA-vp3c-gmr6-8g2m.json b/advisories/unreviewed/2022/02/GHSA-vp3c-gmr6-8g2m/GHSA-vp3c-gmr6-8g2m.json index b42b40862e0..a087709cbc3 100644 --- a/advisories/unreviewed/2022/02/GHSA-vp3c-gmr6-8g2m/GHSA-vp3c-gmr6-8g2m.json +++ b/advisories/unreviewed/2022/02/GHSA-vp3c-gmr6-8g2m/GHSA-vp3c-gmr6-8g2m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-vq67-xx7v-6qmg/GHSA-vq67-xx7v-6qmg.json b/advisories/unreviewed/2022/02/GHSA-vq67-xx7v-6qmg/GHSA-vq67-xx7v-6qmg.json index eebac441d14..86b32aa3e19 100644 --- a/advisories/unreviewed/2022/02/GHSA-vq67-xx7v-6qmg/GHSA-vq67-xx7v-6qmg.json +++ b/advisories/unreviewed/2022/02/GHSA-vq67-xx7v-6qmg/GHSA-vq67-xx7v-6qmg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-w28w-pr47-399w/GHSA-w28w-pr47-399w.json b/advisories/unreviewed/2022/02/GHSA-w28w-pr47-399w/GHSA-w28w-pr47-399w.json index cbb4ac10a59..f93d4fd7293 100644 --- a/advisories/unreviewed/2022/02/GHSA-w28w-pr47-399w/GHSA-w28w-pr47-399w.json +++ b/advisories/unreviewed/2022/02/GHSA-w28w-pr47-399w/GHSA-w28w-pr47-399w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-ww8j-72j4-5x79/GHSA-ww8j-72j4-5x79.json b/advisories/unreviewed/2022/02/GHSA-ww8j-72j4-5x79/GHSA-ww8j-72j4-5x79.json index e9ac419c8f4..1bf895adb72 100644 --- a/advisories/unreviewed/2022/02/GHSA-ww8j-72j4-5x79/GHSA-ww8j-72j4-5x79.json +++ b/advisories/unreviewed/2022/02/GHSA-ww8j-72j4-5x79/GHSA-ww8j-72j4-5x79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-wx9x-cpp6-2q3w/GHSA-wx9x-cpp6-2q3w.json b/advisories/unreviewed/2022/02/GHSA-wx9x-cpp6-2q3w/GHSA-wx9x-cpp6-2q3w.json index 6322ac39a60..5f99b61a36e 100644 --- a/advisories/unreviewed/2022/02/GHSA-wx9x-cpp6-2q3w/GHSA-wx9x-cpp6-2q3w.json +++ b/advisories/unreviewed/2022/02/GHSA-wx9x-cpp6-2q3w/GHSA-wx9x-cpp6-2q3w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-xm82-54qx-4cvr/GHSA-xm82-54qx-4cvr.json b/advisories/unreviewed/2022/02/GHSA-xm82-54qx-4cvr/GHSA-xm82-54qx-4cvr.json index 566da7bb238..66f13d1e35f 100644 --- a/advisories/unreviewed/2022/02/GHSA-xm82-54qx-4cvr/GHSA-xm82-54qx-4cvr.json +++ b/advisories/unreviewed/2022/02/GHSA-xm82-54qx-4cvr/GHSA-xm82-54qx-4cvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-xxx5-wj7r-x3hv/GHSA-xxx5-wj7r-x3hv.json b/advisories/unreviewed/2022/02/GHSA-xxx5-wj7r-x3hv/GHSA-xxx5-wj7r-x3hv.json index 5cb8bea4d69..e4545943bf1 100644 --- a/advisories/unreviewed/2022/02/GHSA-xxx5-wj7r-x3hv/GHSA-xxx5-wj7r-x3hv.json +++ b/advisories/unreviewed/2022/02/GHSA-xxx5-wj7r-x3hv/GHSA-xxx5-wj7r-x3hv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-69m8-6m2p-9wrw/GHSA-69m8-6m2p-9wrw.json b/advisories/unreviewed/2022/03/GHSA-69m8-6m2p-9wrw/GHSA-69m8-6m2p-9wrw.json index 0bae661f178..b4151440168 100644 --- a/advisories/unreviewed/2022/03/GHSA-69m8-6m2p-9wrw/GHSA-69m8-6m2p-9wrw.json +++ b/advisories/unreviewed/2022/03/GHSA-69m8-6m2p-9wrw/GHSA-69m8-6m2p-9wrw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-f7p7-g8cw-67h3/GHSA-f7p7-g8cw-67h3.json b/advisories/unreviewed/2022/03/GHSA-f7p7-g8cw-67h3/GHSA-f7p7-g8cw-67h3.json index b9abe5b550d..6640138766d 100644 --- a/advisories/unreviewed/2022/03/GHSA-f7p7-g8cw-67h3/GHSA-f7p7-g8cw-67h3.json +++ b/advisories/unreviewed/2022/03/GHSA-f7p7-g8cw-67h3/GHSA-f7p7-g8cw-67h3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-fjww-grc5-6wh6/GHSA-fjww-grc5-6wh6.json b/advisories/unreviewed/2022/03/GHSA-fjww-grc5-6wh6/GHSA-fjww-grc5-6wh6.json index 0dbda745c67..01702d5d9a8 100644 --- a/advisories/unreviewed/2022/03/GHSA-fjww-grc5-6wh6/GHSA-fjww-grc5-6wh6.json +++ b/advisories/unreviewed/2022/03/GHSA-fjww-grc5-6wh6/GHSA-fjww-grc5-6wh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-fq7v-xj92-r9mr/GHSA-fq7v-xj92-r9mr.json b/advisories/unreviewed/2022/03/GHSA-fq7v-xj92-r9mr/GHSA-fq7v-xj92-r9mr.json index 0c29d6b587c..a433e68cd91 100644 --- a/advisories/unreviewed/2022/03/GHSA-fq7v-xj92-r9mr/GHSA-fq7v-xj92-r9mr.json +++ b/advisories/unreviewed/2022/03/GHSA-fq7v-xj92-r9mr/GHSA-fq7v-xj92-r9mr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-hh28-49mm-87qv/GHSA-hh28-49mm-87qv.json b/advisories/unreviewed/2022/03/GHSA-hh28-49mm-87qv/GHSA-hh28-49mm-87qv.json index 7838e768de6..b01f006cc5e 100644 --- a/advisories/unreviewed/2022/03/GHSA-hh28-49mm-87qv/GHSA-hh28-49mm-87qv.json +++ b/advisories/unreviewed/2022/03/GHSA-hh28-49mm-87qv/GHSA-hh28-49mm-87qv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-j372-v4w2-c5fm/GHSA-j372-v4w2-c5fm.json b/advisories/unreviewed/2022/03/GHSA-j372-v4w2-c5fm/GHSA-j372-v4w2-c5fm.json index 9abda8c3d03..b647cac2855 100644 --- a/advisories/unreviewed/2022/03/GHSA-j372-v4w2-c5fm/GHSA-j372-v4w2-c5fm.json +++ b/advisories/unreviewed/2022/03/GHSA-j372-v4w2-c5fm/GHSA-j372-v4w2-c5fm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-pw2w-8885-2537/GHSA-pw2w-8885-2537.json b/advisories/unreviewed/2022/03/GHSA-pw2w-8885-2537/GHSA-pw2w-8885-2537.json index b3c2dbca336..fad4a356c16 100644 --- a/advisories/unreviewed/2022/03/GHSA-pw2w-8885-2537/GHSA-pw2w-8885-2537.json +++ b/advisories/unreviewed/2022/03/GHSA-pw2w-8885-2537/GHSA-pw2w-8885-2537.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-qgrj-xj47-pjqm/GHSA-qgrj-xj47-pjqm.json b/advisories/unreviewed/2022/03/GHSA-qgrj-xj47-pjqm/GHSA-qgrj-xj47-pjqm.json index c152b7ab7af..dd3569bc882 100644 --- a/advisories/unreviewed/2022/03/GHSA-qgrj-xj47-pjqm/GHSA-qgrj-xj47-pjqm.json +++ b/advisories/unreviewed/2022/03/GHSA-qgrj-xj47-pjqm/GHSA-qgrj-xj47-pjqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-r3q4-4jhx-x4c9/GHSA-r3q4-4jhx-x4c9.json b/advisories/unreviewed/2022/03/GHSA-r3q4-4jhx-x4c9/GHSA-r3q4-4jhx-x4c9.json index aa5561b9f5d..6f32d3075ba 100644 --- a/advisories/unreviewed/2022/03/GHSA-r3q4-4jhx-x4c9/GHSA-r3q4-4jhx-x4c9.json +++ b/advisories/unreviewed/2022/03/GHSA-r3q4-4jhx-x4c9/GHSA-r3q4-4jhx-x4c9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-vh93-7ch4-7jjr/GHSA-vh93-7ch4-7jjr.json b/advisories/unreviewed/2022/03/GHSA-vh93-7ch4-7jjr/GHSA-vh93-7ch4-7jjr.json index 0267ad51df7..4e03fc373fa 100644 --- a/advisories/unreviewed/2022/03/GHSA-vh93-7ch4-7jjr/GHSA-vh93-7ch4-7jjr.json +++ b/advisories/unreviewed/2022/03/GHSA-vh93-7ch4-7jjr/GHSA-vh93-7ch4-7jjr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-vvw7-v96v-gmxr/GHSA-vvw7-v96v-gmxr.json b/advisories/unreviewed/2022/03/GHSA-vvw7-v96v-gmxr/GHSA-vvw7-v96v-gmxr.json index 77ce993ce70..1b115767f32 100644 --- a/advisories/unreviewed/2022/03/GHSA-vvw7-v96v-gmxr/GHSA-vvw7-v96v-gmxr.json +++ b/advisories/unreviewed/2022/03/GHSA-vvw7-v96v-gmxr/GHSA-vvw7-v96v-gmxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/03/GHSA-w864-mmhj-98gv/GHSA-w864-mmhj-98gv.json b/advisories/unreviewed/2022/03/GHSA-w864-mmhj-98gv/GHSA-w864-mmhj-98gv.json index 6c4ab3a1ca8..02249ac1ff6 100644 --- a/advisories/unreviewed/2022/03/GHSA-w864-mmhj-98gv/GHSA-w864-mmhj-98gv.json +++ b/advisories/unreviewed/2022/03/GHSA-w864-mmhj-98gv/GHSA-w864-mmhj-98gv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-wgcc-3vw8-rp8c/GHSA-wgcc-3vw8-rp8c.json b/advisories/unreviewed/2022/03/GHSA-wgcc-3vw8-rp8c/GHSA-wgcc-3vw8-rp8c.json index 427a5a229b5..6ddeda2a421 100644 --- a/advisories/unreviewed/2022/03/GHSA-wgcc-3vw8-rp8c/GHSA-wgcc-3vw8-rp8c.json +++ b/advisories/unreviewed/2022/03/GHSA-wgcc-3vw8-rp8c/GHSA-wgcc-3vw8-rp8c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-xh7f-2c8g-37p4/GHSA-xh7f-2c8g-37p4.json b/advisories/unreviewed/2022/03/GHSA-xh7f-2c8g-37p4/GHSA-xh7f-2c8g-37p4.json index 63a9d57fe27..b4516b08bd9 100644 --- a/advisories/unreviewed/2022/03/GHSA-xh7f-2c8g-37p4/GHSA-xh7f-2c8g-37p4.json +++ b/advisories/unreviewed/2022/03/GHSA-xh7f-2c8g-37p4/GHSA-xh7f-2c8g-37p4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-22f6-99mv-7p4v/GHSA-22f6-99mv-7p4v.json b/advisories/unreviewed/2022/04/GHSA-22f6-99mv-7p4v/GHSA-22f6-99mv-7p4v.json index 4d66571dce8..a4b79af6d87 100644 --- a/advisories/unreviewed/2022/04/GHSA-22f6-99mv-7p4v/GHSA-22f6-99mv-7p4v.json +++ b/advisories/unreviewed/2022/04/GHSA-22f6-99mv-7p4v/GHSA-22f6-99mv-7p4v.json @@ -7,12 +7,8 @@ "CVE-1999-0324" ], "details": "ppl program in HP-UX allows local users to create root files through symlinks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2752-8gwx-98x4/GHSA-2752-8gwx-98x4.json b/advisories/unreviewed/2022/04/GHSA-2752-8gwx-98x4/GHSA-2752-8gwx-98x4.json index 80a1a3b44ab..a6dae37a6cb 100644 --- a/advisories/unreviewed/2022/04/GHSA-2752-8gwx-98x4/GHSA-2752-8gwx-98x4.json +++ b/advisories/unreviewed/2022/04/GHSA-2752-8gwx-98x4/GHSA-2752-8gwx-98x4.json @@ -7,12 +7,8 @@ "CVE-1999-0233" ], "details": "IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-29f6-fjcr-g3qx/GHSA-29f6-fjcr-g3qx.json b/advisories/unreviewed/2022/04/GHSA-29f6-fjcr-g3qx/GHSA-29f6-fjcr-g3qx.json index 5022807d8f4..6cd56b859a8 100644 --- a/advisories/unreviewed/2022/04/GHSA-29f6-fjcr-g3qx/GHSA-29f6-fjcr-g3qx.json +++ b/advisories/unreviewed/2022/04/GHSA-29f6-fjcr-g3qx/GHSA-29f6-fjcr-g3qx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-29jf-w9mr-r2xp/GHSA-29jf-w9mr-r2xp.json b/advisories/unreviewed/2022/04/GHSA-29jf-w9mr-r2xp/GHSA-29jf-w9mr-r2xp.json index 144a3b8f477..af19d1e55b7 100644 --- a/advisories/unreviewed/2022/04/GHSA-29jf-w9mr-r2xp/GHSA-29jf-w9mr-r2xp.json +++ b/advisories/unreviewed/2022/04/GHSA-29jf-w9mr-r2xp/GHSA-29jf-w9mr-r2xp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-29pf-5g7p-h6r2/GHSA-29pf-5g7p-h6r2.json b/advisories/unreviewed/2022/04/GHSA-29pf-5g7p-h6r2/GHSA-29pf-5g7p-h6r2.json index 6c3cdd49717..b9287eb2aac 100644 --- a/advisories/unreviewed/2022/04/GHSA-29pf-5g7p-h6r2/GHSA-29pf-5g7p-h6r2.json +++ b/advisories/unreviewed/2022/04/GHSA-29pf-5g7p-h6r2/GHSA-29pf-5g7p-h6r2.json @@ -7,12 +7,8 @@ "CVE-1999-0053" ], "details": "TCP RST denial of service in FreeBSD.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-29qr-jmq6-gcm6/GHSA-29qr-jmq6-gcm6.json b/advisories/unreviewed/2022/04/GHSA-29qr-jmq6-gcm6/GHSA-29qr-jmq6-gcm6.json index ea3de5e2178..282d217988e 100644 --- a/advisories/unreviewed/2022/04/GHSA-29qr-jmq6-gcm6/GHSA-29qr-jmq6-gcm6.json +++ b/advisories/unreviewed/2022/04/GHSA-29qr-jmq6-gcm6/GHSA-29qr-jmq6-gcm6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2cv7-m7r7-5xxj/GHSA-2cv7-m7r7-5xxj.json b/advisories/unreviewed/2022/04/GHSA-2cv7-m7r7-5xxj/GHSA-2cv7-m7r7-5xxj.json index 43685997adf..c56e6785450 100644 --- a/advisories/unreviewed/2022/04/GHSA-2cv7-m7r7-5xxj/GHSA-2cv7-m7r7-5xxj.json +++ b/advisories/unreviewed/2022/04/GHSA-2cv7-m7r7-5xxj/GHSA-2cv7-m7r7-5xxj.json @@ -7,12 +7,8 @@ "CVE-1999-0353" ], "details": "rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2f2f-rjcq-rw8r/GHSA-2f2f-rjcq-rw8r.json b/advisories/unreviewed/2022/04/GHSA-2f2f-rjcq-rw8r/GHSA-2f2f-rjcq-rw8r.json index af446b37634..17a73e9a65d 100644 --- a/advisories/unreviewed/2022/04/GHSA-2f2f-rjcq-rw8r/GHSA-2f2f-rjcq-rw8r.json +++ b/advisories/unreviewed/2022/04/GHSA-2f2f-rjcq-rw8r/GHSA-2f2f-rjcq-rw8r.json @@ -7,12 +7,8 @@ "CVE-1999-0299" ], "details": "Buffer overflow in FreeBSD lpd through long DNS hostnames.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2fh5-2q69-8g9v/GHSA-2fh5-2q69-8g9v.json b/advisories/unreviewed/2022/04/GHSA-2fh5-2q69-8g9v/GHSA-2fh5-2q69-8g9v.json index 79d3c95129a..a3f2eebfd97 100644 --- a/advisories/unreviewed/2022/04/GHSA-2fh5-2q69-8g9v/GHSA-2fh5-2q69-8g9v.json +++ b/advisories/unreviewed/2022/04/GHSA-2fh5-2q69-8g9v/GHSA-2fh5-2q69-8g9v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2fxx-275j-35vm/GHSA-2fxx-275j-35vm.json b/advisories/unreviewed/2022/04/GHSA-2fxx-275j-35vm/GHSA-2fxx-275j-35vm.json index 64fc51e77fb..c1528f62a0f 100644 --- a/advisories/unreviewed/2022/04/GHSA-2fxx-275j-35vm/GHSA-2fxx-275j-35vm.json +++ b/advisories/unreviewed/2022/04/GHSA-2fxx-275j-35vm/GHSA-2fxx-275j-35vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-2gmm-8x35-3cmg/GHSA-2gmm-8x35-3cmg.json b/advisories/unreviewed/2022/04/GHSA-2gmm-8x35-3cmg/GHSA-2gmm-8x35-3cmg.json index 5d5a0db3731..6c54f3ade9c 100644 --- a/advisories/unreviewed/2022/04/GHSA-2gmm-8x35-3cmg/GHSA-2gmm-8x35-3cmg.json +++ b/advisories/unreviewed/2022/04/GHSA-2gmm-8x35-3cmg/GHSA-2gmm-8x35-3cmg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2gr4-wr48-7775/GHSA-2gr4-wr48-7775.json b/advisories/unreviewed/2022/04/GHSA-2gr4-wr48-7775/GHSA-2gr4-wr48-7775.json index a87835d67fa..ffa0a08bdd2 100644 --- a/advisories/unreviewed/2022/04/GHSA-2gr4-wr48-7775/GHSA-2gr4-wr48-7775.json +++ b/advisories/unreviewed/2022/04/GHSA-2gr4-wr48-7775/GHSA-2gr4-wr48-7775.json @@ -7,12 +7,8 @@ "CVE-1999-0262" ], "details": "Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2p8f-w9gg-hwrc/GHSA-2p8f-w9gg-hwrc.json b/advisories/unreviewed/2022/04/GHSA-2p8f-w9gg-hwrc/GHSA-2p8f-w9gg-hwrc.json index 472cc2ccff9..d74b65b4583 100644 --- a/advisories/unreviewed/2022/04/GHSA-2p8f-w9gg-hwrc/GHSA-2p8f-w9gg-hwrc.json +++ b/advisories/unreviewed/2022/04/GHSA-2p8f-w9gg-hwrc/GHSA-2p8f-w9gg-hwrc.json @@ -7,12 +7,8 @@ "CVE-1999-0018" ], "details": "Buffer overflow in statd allows root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2q9f-93v8-w2pf/GHSA-2q9f-93v8-w2pf.json b/advisories/unreviewed/2022/04/GHSA-2q9f-93v8-w2pf/GHSA-2q9f-93v8-w2pf.json index 7bfe20174b4..6ffefc11d07 100644 --- a/advisories/unreviewed/2022/04/GHSA-2q9f-93v8-w2pf/GHSA-2q9f-93v8-w2pf.json +++ b/advisories/unreviewed/2022/04/GHSA-2q9f-93v8-w2pf/GHSA-2q9f-93v8-w2pf.json @@ -7,12 +7,8 @@ "CVE-1999-0101" ], "details": "Buffer overflow in AIX and Solaris \"gethostbyname\" library call allows root access through corrupt DNS host names.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-2vq9-x634-p9m5/GHSA-2vq9-x634-p9m5.json b/advisories/unreviewed/2022/04/GHSA-2vq9-x634-p9m5/GHSA-2vq9-x634-p9m5.json index 9ceec1fa7e3..7bca3edbed1 100644 --- a/advisories/unreviewed/2022/04/GHSA-2vq9-x634-p9m5/GHSA-2vq9-x634-p9m5.json +++ b/advisories/unreviewed/2022/04/GHSA-2vq9-x634-p9m5/GHSA-2vq9-x634-p9m5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-339v-jgw2-82mh/GHSA-339v-jgw2-82mh.json b/advisories/unreviewed/2022/04/GHSA-339v-jgw2-82mh/GHSA-339v-jgw2-82mh.json index 92145c465e0..7f40b9fc841 100644 --- a/advisories/unreviewed/2022/04/GHSA-339v-jgw2-82mh/GHSA-339v-jgw2-82mh.json +++ b/advisories/unreviewed/2022/04/GHSA-339v-jgw2-82mh/GHSA-339v-jgw2-82mh.json @@ -7,12 +7,8 @@ "CVE-1999-0178" ], "details": "Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-35f8-88f3-66mw/GHSA-35f8-88f3-66mw.json b/advisories/unreviewed/2022/04/GHSA-35f8-88f3-66mw/GHSA-35f8-88f3-66mw.json index cda733ab745..aa3fe508c8a 100644 --- a/advisories/unreviewed/2022/04/GHSA-35f8-88f3-66mw/GHSA-35f8-88f3-66mw.json +++ b/advisories/unreviewed/2022/04/GHSA-35f8-88f3-66mw/GHSA-35f8-88f3-66mw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-35m5-388q-jrx8/GHSA-35m5-388q-jrx8.json b/advisories/unreviewed/2022/04/GHSA-35m5-388q-jrx8/GHSA-35m5-388q-jrx8.json index 784a2e5a730..e32d3473290 100644 --- a/advisories/unreviewed/2022/04/GHSA-35m5-388q-jrx8/GHSA-35m5-388q-jrx8.json +++ b/advisories/unreviewed/2022/04/GHSA-35m5-388q-jrx8/GHSA-35m5-388q-jrx8.json @@ -7,12 +7,8 @@ "CVE-1999-0196" ], "details": "websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-36qh-3xp5-xv7p/GHSA-36qh-3xp5-xv7p.json b/advisories/unreviewed/2022/04/GHSA-36qh-3xp5-xv7p/GHSA-36qh-3xp5-xv7p.json index e96c537a4e1..8a76882f2d7 100644 --- a/advisories/unreviewed/2022/04/GHSA-36qh-3xp5-xv7p/GHSA-36qh-3xp5-xv7p.json +++ b/advisories/unreviewed/2022/04/GHSA-36qh-3xp5-xv7p/GHSA-36qh-3xp5-xv7p.json @@ -7,12 +7,8 @@ "CVE-1999-0104" ], "details": "A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3mhg-8478-5f87/GHSA-3mhg-8478-5f87.json b/advisories/unreviewed/2022/04/GHSA-3mhg-8478-5f87/GHSA-3mhg-8478-5f87.json index 4d414f66b62..529c6bab76a 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mhg-8478-5f87/GHSA-3mhg-8478-5f87.json +++ b/advisories/unreviewed/2022/04/GHSA-3mhg-8478-5f87/GHSA-3mhg-8478-5f87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-3mvr-qcj7-4jj5/GHSA-3mvr-qcj7-4jj5.json b/advisories/unreviewed/2022/04/GHSA-3mvr-qcj7-4jj5/GHSA-3mvr-qcj7-4jj5.json index 66e0831987b..ae6b72342d1 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mvr-qcj7-4jj5/GHSA-3mvr-qcj7-4jj5.json +++ b/advisories/unreviewed/2022/04/GHSA-3mvr-qcj7-4jj5/GHSA-3mvr-qcj7-4jj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-3q9w-98w3-7hrf/GHSA-3q9w-98w3-7hrf.json b/advisories/unreviewed/2022/04/GHSA-3q9w-98w3-7hrf/GHSA-3q9w-98w3-7hrf.json index 147e309f4b8..e87fab69cd5 100644 --- a/advisories/unreviewed/2022/04/GHSA-3q9w-98w3-7hrf/GHSA-3q9w-98w3-7hrf.json +++ b/advisories/unreviewed/2022/04/GHSA-3q9w-98w3-7hrf/GHSA-3q9w-98w3-7hrf.json @@ -7,12 +7,8 @@ "CVE-1999-0157" ], "details": "Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3vxm-4f9v-fq2c/GHSA-3vxm-4f9v-fq2c.json b/advisories/unreviewed/2022/04/GHSA-3vxm-4f9v-fq2c/GHSA-3vxm-4f9v-fq2c.json index b3eabc552cf..febd43a56e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-3vxm-4f9v-fq2c/GHSA-3vxm-4f9v-fq2c.json +++ b/advisories/unreviewed/2022/04/GHSA-3vxm-4f9v-fq2c/GHSA-3vxm-4f9v-fq2c.json @@ -7,12 +7,8 @@ "CVE-2010-0128" ], "details": "Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-3x35-fvpx-4r5q/GHSA-3x35-fvpx-4r5q.json b/advisories/unreviewed/2022/04/GHSA-3x35-fvpx-4r5q/GHSA-3x35-fvpx-4r5q.json index 49f9a736596..e6e8e25cec0 100644 --- a/advisories/unreviewed/2022/04/GHSA-3x35-fvpx-4r5q/GHSA-3x35-fvpx-4r5q.json +++ b/advisories/unreviewed/2022/04/GHSA-3x35-fvpx-4r5q/GHSA-3x35-fvpx-4r5q.json @@ -7,12 +7,8 @@ "CVE-1999-0132" ], "details": "Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-3xqj-xx96-hm93/GHSA-3xqj-xx96-hm93.json b/advisories/unreviewed/2022/04/GHSA-3xqj-xx96-hm93/GHSA-3xqj-xx96-hm93.json index dbbd67dc2c5..622a3b900fe 100644 --- a/advisories/unreviewed/2022/04/GHSA-3xqj-xx96-hm93/GHSA-3xqj-xx96-hm93.json +++ b/advisories/unreviewed/2022/04/GHSA-3xqj-xx96-hm93/GHSA-3xqj-xx96-hm93.json @@ -7,12 +7,8 @@ "CVE-1999-0112" ], "details": "Buffer overflow in AIX dtterm program for the CDE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-46xg-4hcp-2ppj/GHSA-46xg-4hcp-2ppj.json b/advisories/unreviewed/2022/04/GHSA-46xg-4hcp-2ppj/GHSA-46xg-4hcp-2ppj.json index 233c2a2c581..9bd57c90676 100644 --- a/advisories/unreviewed/2022/04/GHSA-46xg-4hcp-2ppj/GHSA-46xg-4hcp-2ppj.json +++ b/advisories/unreviewed/2022/04/GHSA-46xg-4hcp-2ppj/GHSA-46xg-4hcp-2ppj.json @@ -7,12 +7,8 @@ "CVE-1999-0103" ], "details": "Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-49gg-qhgf-7m27/GHSA-49gg-qhgf-7m27.json b/advisories/unreviewed/2022/04/GHSA-49gg-qhgf-7m27/GHSA-49gg-qhgf-7m27.json index 3a5c9b44f2e..301e0c7bf7c 100644 --- a/advisories/unreviewed/2022/04/GHSA-49gg-qhgf-7m27/GHSA-49gg-qhgf-7m27.json +++ b/advisories/unreviewed/2022/04/GHSA-49gg-qhgf-7m27/GHSA-49gg-qhgf-7m27.json @@ -7,12 +7,8 @@ "CVE-1999-0158" ], "details": "Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-4h5h-gj9f-wqw6/GHSA-4h5h-gj9f-wqw6.json b/advisories/unreviewed/2022/04/GHSA-4h5h-gj9f-wqw6/GHSA-4h5h-gj9f-wqw6.json index 632a21316f1..959c6aca620 100644 --- a/advisories/unreviewed/2022/04/GHSA-4h5h-gj9f-wqw6/GHSA-4h5h-gj9f-wqw6.json +++ b/advisories/unreviewed/2022/04/GHSA-4h5h-gj9f-wqw6/GHSA-4h5h-gj9f-wqw6.json @@ -7,12 +7,8 @@ "CVE-1999-0057" ], "details": "Vacation program allows command execution by remote users through a sendmail command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-524v-mfqh-4rrh/GHSA-524v-mfqh-4rrh.json b/advisories/unreviewed/2022/04/GHSA-524v-mfqh-4rrh/GHSA-524v-mfqh-4rrh.json index aa6b45c4def..98cff58cd6d 100644 --- a/advisories/unreviewed/2022/04/GHSA-524v-mfqh-4rrh/GHSA-524v-mfqh-4rrh.json +++ b/advisories/unreviewed/2022/04/GHSA-524v-mfqh-4rrh/GHSA-524v-mfqh-4rrh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5283-mj4f-qf94/GHSA-5283-mj4f-qf94.json b/advisories/unreviewed/2022/04/GHSA-5283-mj4f-qf94/GHSA-5283-mj4f-qf94.json index 0758d77ed00..73ff547bfa8 100644 --- a/advisories/unreviewed/2022/04/GHSA-5283-mj4f-qf94/GHSA-5283-mj4f-qf94.json +++ b/advisories/unreviewed/2022/04/GHSA-5283-mj4f-qf94/GHSA-5283-mj4f-qf94.json @@ -7,12 +7,8 @@ "CVE-1999-0301" ], "details": "Buffer overflow in SunOS/Solaris ps command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-52pp-8p9h-45f8/GHSA-52pp-8p9h-45f8.json b/advisories/unreviewed/2022/04/GHSA-52pp-8p9h-45f8/GHSA-52pp-8p9h-45f8.json index 43caa602336..a46674cc8ad 100644 --- a/advisories/unreviewed/2022/04/GHSA-52pp-8p9h-45f8/GHSA-52pp-8p9h-45f8.json +++ b/advisories/unreviewed/2022/04/GHSA-52pp-8p9h-45f8/GHSA-52pp-8p9h-45f8.json @@ -7,12 +7,8 @@ "CVE-1999-0007" ], "details": "Information from SSL-encrypted sessions via PKCS #1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-5495-52g6-8q95/GHSA-5495-52g6-8q95.json b/advisories/unreviewed/2022/04/GHSA-5495-52g6-8q95/GHSA-5495-52g6-8q95.json index 11af40a3590..5c7844068b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-5495-52g6-8q95/GHSA-5495-52g6-8q95.json +++ b/advisories/unreviewed/2022/04/GHSA-5495-52g6-8q95/GHSA-5495-52g6-8q95.json @@ -7,12 +7,8 @@ "CVE-1999-0219" ], "details": "Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-56vx-g63m-22w4/GHSA-56vx-g63m-22w4.json b/advisories/unreviewed/2022/04/GHSA-56vx-g63m-22w4/GHSA-56vx-g63m-22w4.json index 34a76a0adc8..5753b201ea4 100644 --- a/advisories/unreviewed/2022/04/GHSA-56vx-g63m-22w4/GHSA-56vx-g63m-22w4.json +++ b/advisories/unreviewed/2022/04/GHSA-56vx-g63m-22w4/GHSA-56vx-g63m-22w4.json @@ -7,12 +7,8 @@ "CVE-1999-0367" ], "details": "NetBSD netstat command allows local users to access kernel memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5f3f-gp5f-2x6p/GHSA-5f3f-gp5f-2x6p.json b/advisories/unreviewed/2022/04/GHSA-5f3f-gp5f-2x6p/GHSA-5f3f-gp5f-2x6p.json index f42fc90e70b..c61fddfe49f 100644 --- a/advisories/unreviewed/2022/04/GHSA-5f3f-gp5f-2x6p/GHSA-5f3f-gp5f-2x6p.json +++ b/advisories/unreviewed/2022/04/GHSA-5f3f-gp5f-2x6p/GHSA-5f3f-gp5f-2x6p.json @@ -7,12 +7,8 @@ "CVE-1999-0322" ], "details": "The open() function in FreeBSD allows local attackers to write to arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5h6p-59g5-m8g3/GHSA-5h6p-59g5-m8g3.json b/advisories/unreviewed/2022/04/GHSA-5h6p-59g5-m8g3/GHSA-5h6p-59g5-m8g3.json index 2fefd495c0b..deb137db057 100644 --- a/advisories/unreviewed/2022/04/GHSA-5h6p-59g5-m8g3/GHSA-5h6p-59g5-m8g3.json +++ b/advisories/unreviewed/2022/04/GHSA-5h6p-59g5-m8g3/GHSA-5h6p-59g5-m8g3.json @@ -7,12 +7,8 @@ "CVE-1999-0325" ], "details": "vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5j6c-65fm-f6cr/GHSA-5j6c-65fm-f6cr.json b/advisories/unreviewed/2022/04/GHSA-5j6c-65fm-f6cr/GHSA-5j6c-65fm-f6cr.json index a081f9b6b26..4f7ba009ce1 100644 --- a/advisories/unreviewed/2022/04/GHSA-5j6c-65fm-f6cr/GHSA-5j6c-65fm-f6cr.json +++ b/advisories/unreviewed/2022/04/GHSA-5j6c-65fm-f6cr/GHSA-5j6c-65fm-f6cr.json @@ -7,12 +7,8 @@ "CVE-1999-0266" ], "details": "The info2www CGI script allows remote file access or remote command execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5jj5-vh28-7x64/GHSA-5jj5-vh28-7x64.json b/advisories/unreviewed/2022/04/GHSA-5jj5-vh28-7x64/GHSA-5jj5-vh28-7x64.json index 82308256367..e3156256a16 100644 --- a/advisories/unreviewed/2022/04/GHSA-5jj5-vh28-7x64/GHSA-5jj5-vh28-7x64.json +++ b/advisories/unreviewed/2022/04/GHSA-5jj5-vh28-7x64/GHSA-5jj5-vh28-7x64.json @@ -7,12 +7,8 @@ "CVE-1999-0335" ], "details": "DEPRECATED. This entry has been deprecated. It is a duplicate of CVE-1999-0032.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5m4c-63c4-rv6x/GHSA-5m4c-63c4-rv6x.json b/advisories/unreviewed/2022/04/GHSA-5m4c-63c4-rv6x/GHSA-5m4c-63c4-rv6x.json index 47265c6951a..ae4cd473b6d 100644 --- a/advisories/unreviewed/2022/04/GHSA-5m4c-63c4-rv6x/GHSA-5m4c-63c4-rv6x.json +++ b/advisories/unreviewed/2022/04/GHSA-5m4c-63c4-rv6x/GHSA-5m4c-63c4-rv6x.json @@ -7,12 +7,8 @@ "CVE-1999-0302" ], "details": "SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5mw4-cxpf-cxvj/GHSA-5mw4-cxpf-cxvj.json b/advisories/unreviewed/2022/04/GHSA-5mw4-cxpf-cxvj/GHSA-5mw4-cxpf-cxvj.json index 7562ee151a7..3c6772f836c 100644 --- a/advisories/unreviewed/2022/04/GHSA-5mw4-cxpf-cxvj/GHSA-5mw4-cxpf-cxvj.json +++ b/advisories/unreviewed/2022/04/GHSA-5mw4-cxpf-cxvj/GHSA-5mw4-cxpf-cxvj.json @@ -7,12 +7,8 @@ "CVE-1999-0016" ], "details": "Land IP denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-5wr5-299q-993r/GHSA-5wr5-299q-993r.json b/advisories/unreviewed/2022/04/GHSA-5wr5-299q-993r/GHSA-5wr5-299q-993r.json index b4b9f8b513e..ddaa8f3adf0 100644 --- a/advisories/unreviewed/2022/04/GHSA-5wr5-299q-993r/GHSA-5wr5-299q-993r.json +++ b/advisories/unreviewed/2022/04/GHSA-5wr5-299q-993r/GHSA-5wr5-299q-993r.json @@ -7,12 +7,8 @@ "CVE-1999-0025" ], "details": "root privileges via buffer overflow in df command on SGI IRIX systems.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-62vf-wrg7-5x68/GHSA-62vf-wrg7-5x68.json b/advisories/unreviewed/2022/04/GHSA-62vf-wrg7-5x68/GHSA-62vf-wrg7-5x68.json index 7885b045e0b..4c2c4c92005 100644 --- a/advisories/unreviewed/2022/04/GHSA-62vf-wrg7-5x68/GHSA-62vf-wrg7-5x68.json +++ b/advisories/unreviewed/2022/04/GHSA-62vf-wrg7-5x68/GHSA-62vf-wrg7-5x68.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-63gj-m3j5-p47q/GHSA-63gj-m3j5-p47q.json b/advisories/unreviewed/2022/04/GHSA-63gj-m3j5-p47q/GHSA-63gj-m3j5-p47q.json index 60601645e63..fab95213441 100644 --- a/advisories/unreviewed/2022/04/GHSA-63gj-m3j5-p47q/GHSA-63gj-m3j5-p47q.json +++ b/advisories/unreviewed/2022/04/GHSA-63gj-m3j5-p47q/GHSA-63gj-m3j5-p47q.json @@ -7,12 +7,8 @@ "CVE-1999-0210" ], "details": "Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-657c-jj8v-wh33/GHSA-657c-jj8v-wh33.json b/advisories/unreviewed/2022/04/GHSA-657c-jj8v-wh33/GHSA-657c-jj8v-wh33.json index 0137a104504..c87fc36732b 100644 --- a/advisories/unreviewed/2022/04/GHSA-657c-jj8v-wh33/GHSA-657c-jj8v-wh33.json +++ b/advisories/unreviewed/2022/04/GHSA-657c-jj8v-wh33/GHSA-657c-jj8v-wh33.json @@ -7,12 +7,8 @@ "CVE-1999-0296" ], "details": "Solaris volrmmount program allows attackers to read any file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-69m7-6fwc-hxpx/GHSA-69m7-6fwc-hxpx.json b/advisories/unreviewed/2022/04/GHSA-69m7-6fwc-hxpx/GHSA-69m7-6fwc-hxpx.json index eae232d0ca3..8ff58158eb4 100644 --- a/advisories/unreviewed/2022/04/GHSA-69m7-6fwc-hxpx/GHSA-69m7-6fwc-hxpx.json +++ b/advisories/unreviewed/2022/04/GHSA-69m7-6fwc-hxpx/GHSA-69m7-6fwc-hxpx.json @@ -7,12 +7,8 @@ "CVE-1999-0247" ], "details": "Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6f9m-5fvq-hr25/GHSA-6f9m-5fvq-hr25.json b/advisories/unreviewed/2022/04/GHSA-6f9m-5fvq-hr25/GHSA-6f9m-5fvq-hr25.json index 3d5de699ed7..155017ba0e5 100644 --- a/advisories/unreviewed/2022/04/GHSA-6f9m-5fvq-hr25/GHSA-6f9m-5fvq-hr25.json +++ b/advisories/unreviewed/2022/04/GHSA-6f9m-5fvq-hr25/GHSA-6f9m-5fvq-hr25.json @@ -7,12 +7,8 @@ "CVE-1999-0308" ], "details": "HP-UX gwind program allows users to modify arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6px6-48hw-rr4x/GHSA-6px6-48hw-rr4x.json b/advisories/unreviewed/2022/04/GHSA-6px6-48hw-rr4x/GHSA-6px6-48hw-rr4x.json index ab4f632f554..8c7e524f70f 100644 --- a/advisories/unreviewed/2022/04/GHSA-6px6-48hw-rr4x/GHSA-6px6-48hw-rr4x.json +++ b/advisories/unreviewed/2022/04/GHSA-6px6-48hw-rr4x/GHSA-6px6-48hw-rr4x.json @@ -7,12 +7,8 @@ "CVE-1999-0120" ], "details": "Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-6rch-6m73-jc8v/GHSA-6rch-6m73-jc8v.json b/advisories/unreviewed/2022/04/GHSA-6rch-6m73-jc8v/GHSA-6rch-6m73-jc8v.json index 8e54f2a570e..acf92d0de5a 100644 --- a/advisories/unreviewed/2022/04/GHSA-6rch-6m73-jc8v/GHSA-6rch-6m73-jc8v.json +++ b/advisories/unreviewed/2022/04/GHSA-6rch-6m73-jc8v/GHSA-6rch-6m73-jc8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-6w47-3vvr-m9hm/GHSA-6w47-3vvr-m9hm.json b/advisories/unreviewed/2022/04/GHSA-6w47-3vvr-m9hm/GHSA-6w47-3vvr-m9hm.json index b83c3efa5c7..735745d18a6 100644 --- a/advisories/unreviewed/2022/04/GHSA-6w47-3vvr-m9hm/GHSA-6w47-3vvr-m9hm.json +++ b/advisories/unreviewed/2022/04/GHSA-6w47-3vvr-m9hm/GHSA-6w47-3vvr-m9hm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-78g5-jc8q-wgq5/GHSA-78g5-jc8q-wgq5.json b/advisories/unreviewed/2022/04/GHSA-78g5-jc8q-wgq5/GHSA-78g5-jc8q-wgq5.json index f823c0e2de4..bf2f5b96373 100644 --- a/advisories/unreviewed/2022/04/GHSA-78g5-jc8q-wgq5/GHSA-78g5-jc8q-wgq5.json +++ b/advisories/unreviewed/2022/04/GHSA-78g5-jc8q-wgq5/GHSA-78g5-jc8q-wgq5.json @@ -7,12 +7,8 @@ "CVE-1999-0144" ], "details": "Denial of service in Qmail by specifying a large number of recipients with the RCPT command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-798m-fchr-585w/GHSA-798m-fchr-585w.json b/advisories/unreviewed/2022/04/GHSA-798m-fchr-585w/GHSA-798m-fchr-585w.json index fe258684984..a719ecae9a9 100644 --- a/advisories/unreviewed/2022/04/GHSA-798m-fchr-585w/GHSA-798m-fchr-585w.json +++ b/advisories/unreviewed/2022/04/GHSA-798m-fchr-585w/GHSA-798m-fchr-585w.json @@ -7,12 +7,8 @@ "CVE-1999-0055" ], "details": "Buffer overflows in Sun libnsl allow root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-79mx-82jw-xwqh/GHSA-79mx-82jw-xwqh.json b/advisories/unreviewed/2022/04/GHSA-79mx-82jw-xwqh/GHSA-79mx-82jw-xwqh.json index 1f210a76341..9786950a789 100644 --- a/advisories/unreviewed/2022/04/GHSA-79mx-82jw-xwqh/GHSA-79mx-82jw-xwqh.json +++ b/advisories/unreviewed/2022/04/GHSA-79mx-82jw-xwqh/GHSA-79mx-82jw-xwqh.json @@ -7,12 +7,8 @@ "CVE-1999-0363" ], "details": "SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7c4c-w2g7-wxj4/GHSA-7c4c-w2g7-wxj4.json b/advisories/unreviewed/2022/04/GHSA-7c4c-w2g7-wxj4/GHSA-7c4c-w2g7-wxj4.json index 858a0301079..d3b88e44771 100644 --- a/advisories/unreviewed/2022/04/GHSA-7c4c-w2g7-wxj4/GHSA-7c4c-w2g7-wxj4.json +++ b/advisories/unreviewed/2022/04/GHSA-7c4c-w2g7-wxj4/GHSA-7c4c-w2g7-wxj4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7g62-22rj-6jh7/GHSA-7g62-22rj-6jh7.json b/advisories/unreviewed/2022/04/GHSA-7g62-22rj-6jh7/GHSA-7g62-22rj-6jh7.json index 85baf98e768..f15b192e9b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-7g62-22rj-6jh7/GHSA-7g62-22rj-6jh7.json +++ b/advisories/unreviewed/2022/04/GHSA-7g62-22rj-6jh7/GHSA-7g62-22rj-6jh7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7h39-q4rx-36jm/GHSA-7h39-q4rx-36jm.json b/advisories/unreviewed/2022/04/GHSA-7h39-q4rx-36jm/GHSA-7h39-q4rx-36jm.json index 5b6b9f2b2ad..08c1ca2f9f2 100644 --- a/advisories/unreviewed/2022/04/GHSA-7h39-q4rx-36jm/GHSA-7h39-q4rx-36jm.json +++ b/advisories/unreviewed/2022/04/GHSA-7h39-q4rx-36jm/GHSA-7h39-q4rx-36jm.json @@ -7,12 +7,8 @@ "CVE-1999-0344" ], "details": "NT users can gain debug-level access on a system process using the Sechole exploit.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7hpc-4h5x-v8cw/GHSA-7hpc-4h5x-v8cw.json b/advisories/unreviewed/2022/04/GHSA-7hpc-4h5x-v8cw/GHSA-7hpc-4h5x-v8cw.json index c6830729747..d2c5a2171d3 100644 --- a/advisories/unreviewed/2022/04/GHSA-7hpc-4h5x-v8cw/GHSA-7hpc-4h5x-v8cw.json +++ b/advisories/unreviewed/2022/04/GHSA-7hpc-4h5x-v8cw/GHSA-7hpc-4h5x-v8cw.json @@ -7,12 +7,8 @@ "CVE-1999-0228" ], "details": "Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-7mr6-hmwx-3gvw/GHSA-7mr6-hmwx-3gvw.json b/advisories/unreviewed/2022/04/GHSA-7mr6-hmwx-3gvw/GHSA-7mr6-hmwx-3gvw.json index 919dfc8d1fd..7d0b742f7d4 100644 --- a/advisories/unreviewed/2022/04/GHSA-7mr6-hmwx-3gvw/GHSA-7mr6-hmwx-3gvw.json +++ b/advisories/unreviewed/2022/04/GHSA-7mr6-hmwx-3gvw/GHSA-7mr6-hmwx-3gvw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7mxv-pr28-272f/GHSA-7mxv-pr28-272f.json b/advisories/unreviewed/2022/04/GHSA-7mxv-pr28-272f/GHSA-7mxv-pr28-272f.json index 89025bfd41b..eb99707359e 100644 --- a/advisories/unreviewed/2022/04/GHSA-7mxv-pr28-272f/GHSA-7mxv-pr28-272f.json +++ b/advisories/unreviewed/2022/04/GHSA-7mxv-pr28-272f/GHSA-7mxv-pr28-272f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-7pq8-h83c-wwjc/GHSA-7pq8-h83c-wwjc.json b/advisories/unreviewed/2022/04/GHSA-7pq8-h83c-wwjc/GHSA-7pq8-h83c-wwjc.json index d2992e80ff2..da9a21848e2 100644 --- a/advisories/unreviewed/2022/04/GHSA-7pq8-h83c-wwjc/GHSA-7pq8-h83c-wwjc.json +++ b/advisories/unreviewed/2022/04/GHSA-7pq8-h83c-wwjc/GHSA-7pq8-h83c-wwjc.json @@ -7,12 +7,8 @@ "CVE-1999-0118" ], "details": "AIX infod allows local users to gain root access through an X display.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-836r-gprf-7h7h/GHSA-836r-gprf-7h7h.json b/advisories/unreviewed/2022/04/GHSA-836r-gprf-7h7h/GHSA-836r-gprf-7h7h.json index 76faa16f97c..06324aff3ff 100644 --- a/advisories/unreviewed/2022/04/GHSA-836r-gprf-7h7h/GHSA-836r-gprf-7h7h.json +++ b/advisories/unreviewed/2022/04/GHSA-836r-gprf-7h7h/GHSA-836r-gprf-7h7h.json @@ -7,12 +7,8 @@ "CVE-1999-0256" ], "details": "Buffer overflow in War FTP allows remote execution of commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-88cj-3gp2-w5gw/GHSA-88cj-3gp2-w5gw.json b/advisories/unreviewed/2022/04/GHSA-88cj-3gp2-w5gw/GHSA-88cj-3gp2-w5gw.json index d90cd658d4b..12168448b7e 100644 --- a/advisories/unreviewed/2022/04/GHSA-88cj-3gp2-w5gw/GHSA-88cj-3gp2-w5gw.json +++ b/advisories/unreviewed/2022/04/GHSA-88cj-3gp2-w5gw/GHSA-88cj-3gp2-w5gw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-895h-cx82-hrf4/GHSA-895h-cx82-hrf4.json b/advisories/unreviewed/2022/04/GHSA-895h-cx82-hrf4/GHSA-895h-cx82-hrf4.json index d7b855a3036..43a630aabe6 100644 --- a/advisories/unreviewed/2022/04/GHSA-895h-cx82-hrf4/GHSA-895h-cx82-hrf4.json +++ b/advisories/unreviewed/2022/04/GHSA-895h-cx82-hrf4/GHSA-895h-cx82-hrf4.json @@ -7,12 +7,8 @@ "CVE-1999-0320" ], "details": "SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8cwc-f864-wx68/GHSA-8cwc-f864-wx68.json b/advisories/unreviewed/2022/04/GHSA-8cwc-f864-wx68/GHSA-8cwc-f864-wx68.json index ae7e8ca9e1d..2dc5d1dc769 100644 --- a/advisories/unreviewed/2022/04/GHSA-8cwc-f864-wx68/GHSA-8cwc-f864-wx68.json +++ b/advisories/unreviewed/2022/04/GHSA-8cwc-f864-wx68/GHSA-8cwc-f864-wx68.json @@ -7,12 +7,8 @@ "CVE-1999-0212" ], "details": "Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8fmv-4jcp-rv3m/GHSA-8fmv-4jcp-rv3m.json b/advisories/unreviewed/2022/04/GHSA-8fmv-4jcp-rv3m/GHSA-8fmv-4jcp-rv3m.json index bc3d9497a74..7b2b7d4796f 100644 --- a/advisories/unreviewed/2022/04/GHSA-8fmv-4jcp-rv3m/GHSA-8fmv-4jcp-rv3m.json +++ b/advisories/unreviewed/2022/04/GHSA-8fmv-4jcp-rv3m/GHSA-8fmv-4jcp-rv3m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-8frp-93rf-q4mf/GHSA-8frp-93rf-q4mf.json b/advisories/unreviewed/2022/04/GHSA-8frp-93rf-q4mf/GHSA-8frp-93rf-q4mf.json index 80971e0747b..2ad965b2820 100644 --- a/advisories/unreviewed/2022/04/GHSA-8frp-93rf-q4mf/GHSA-8frp-93rf-q4mf.json +++ b/advisories/unreviewed/2022/04/GHSA-8frp-93rf-q4mf/GHSA-8frp-93rf-q4mf.json @@ -7,12 +7,8 @@ "CVE-1999-0362" ], "details": "WS_FTP server remote denial of service through cwd command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8q69-243x-44f9/GHSA-8q69-243x-44f9.json b/advisories/unreviewed/2022/04/GHSA-8q69-243x-44f9/GHSA-8q69-243x-44f9.json index 19bfd444602..9fc13b1119e 100644 --- a/advisories/unreviewed/2022/04/GHSA-8q69-243x-44f9/GHSA-8q69-243x-44f9.json +++ b/advisories/unreviewed/2022/04/GHSA-8q69-243x-44f9/GHSA-8q69-243x-44f9.json @@ -7,12 +7,8 @@ "CVE-1999-0283" ], "details": "The Java Web Server would allow remote users to obtain the source code for CGI programs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-8xwf-5pv7-g2w4/GHSA-8xwf-5pv7-g2w4.json b/advisories/unreviewed/2022/04/GHSA-8xwf-5pv7-g2w4/GHSA-8xwf-5pv7-g2w4.json index eb4ce20e3f2..07a79d434fa 100644 --- a/advisories/unreviewed/2022/04/GHSA-8xwf-5pv7-g2w4/GHSA-8xwf-5pv7-g2w4.json +++ b/advisories/unreviewed/2022/04/GHSA-8xwf-5pv7-g2w4/GHSA-8xwf-5pv7-g2w4.json @@ -7,12 +7,8 @@ "CVE-1999-0351" ], "details": "FTP PASV \"Pizza Thief\" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-92cr-5v4q-xgj9/GHSA-92cr-5v4q-xgj9.json b/advisories/unreviewed/2022/04/GHSA-92cr-5v4q-xgj9/GHSA-92cr-5v4q-xgj9.json index cecdc9a27bc..9a986e2e613 100644 --- a/advisories/unreviewed/2022/04/GHSA-92cr-5v4q-xgj9/GHSA-92cr-5v4q-xgj9.json +++ b/advisories/unreviewed/2022/04/GHSA-92cr-5v4q-xgj9/GHSA-92cr-5v4q-xgj9.json @@ -7,12 +7,8 @@ "CVE-1999-0186" ], "details": "In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-933w-hvw9-gc93/GHSA-933w-hvw9-gc93.json b/advisories/unreviewed/2022/04/GHSA-933w-hvw9-gc93/GHSA-933w-hvw9-gc93.json index 2a26c6f3d38..895d7dbe6e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-933w-hvw9-gc93/GHSA-933w-hvw9-gc93.json +++ b/advisories/unreviewed/2022/04/GHSA-933w-hvw9-gc93/GHSA-933w-hvw9-gc93.json @@ -7,12 +7,8 @@ "CVE-1999-0161" ], "details": "In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-93fg-xppj-x2xf/GHSA-93fg-xppj-x2xf.json b/advisories/unreviewed/2022/04/GHSA-93fg-xppj-x2xf/GHSA-93fg-xppj-x2xf.json index 34d62be0c43..c24c37e8682 100644 --- a/advisories/unreviewed/2022/04/GHSA-93fg-xppj-x2xf/GHSA-93fg-xppj-x2xf.json +++ b/advisories/unreviewed/2022/04/GHSA-93fg-xppj-x2xf/GHSA-93fg-xppj-x2xf.json @@ -7,12 +7,8 @@ "CVE-1999-0070" ], "details": "test-cgi program allows an attacker to list files on the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9693-h7pg-637x/GHSA-9693-h7pg-637x.json b/advisories/unreviewed/2022/04/GHSA-9693-h7pg-637x/GHSA-9693-h7pg-637x.json index 5ec520ade05..0aca9dd7c5d 100644 --- a/advisories/unreviewed/2022/04/GHSA-9693-h7pg-637x/GHSA-9693-h7pg-637x.json +++ b/advisories/unreviewed/2022/04/GHSA-9693-h7pg-637x/GHSA-9693-h7pg-637x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-988q-hp2f-8wq8/GHSA-988q-hp2f-8wq8.json b/advisories/unreviewed/2022/04/GHSA-988q-hp2f-8wq8/GHSA-988q-hp2f-8wq8.json index 8b76d9bfa81..b34eb3426c9 100644 --- a/advisories/unreviewed/2022/04/GHSA-988q-hp2f-8wq8/GHSA-988q-hp2f-8wq8.json +++ b/advisories/unreviewed/2022/04/GHSA-988q-hp2f-8wq8/GHSA-988q-hp2f-8wq8.json @@ -7,12 +7,8 @@ "CVE-1999-0315" ], "details": "Buffer overflow in Solaris fdformat command gives root access to local users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-98p6-p98w-j8w8/GHSA-98p6-p98w-j8w8.json b/advisories/unreviewed/2022/04/GHSA-98p6-p98w-j8w8/GHSA-98p6-p98w-j8w8.json index fe74eb61e13..9e00a0e126f 100644 --- a/advisories/unreviewed/2022/04/GHSA-98p6-p98w-j8w8/GHSA-98p6-p98w-j8w8.json +++ b/advisories/unreviewed/2022/04/GHSA-98p6-p98w-j8w8/GHSA-98p6-p98w-j8w8.json @@ -7,12 +7,8 @@ "CVE-1999-0295" ], "details": "Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-98r4-cjrq-q7qh/GHSA-98r4-cjrq-q7qh.json b/advisories/unreviewed/2022/04/GHSA-98r4-cjrq-q7qh/GHSA-98r4-cjrq-q7qh.json index 222d05a546b..d50b6212a8e 100644 --- a/advisories/unreviewed/2022/04/GHSA-98r4-cjrq-q7qh/GHSA-98r4-cjrq-q7qh.json +++ b/advisories/unreviewed/2022/04/GHSA-98r4-cjrq-q7qh/GHSA-98r4-cjrq-q7qh.json @@ -7,12 +7,8 @@ "CVE-2010-1981" ], "details": "Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-9cq6-7hj7-4449/GHSA-9cq6-7hj7-4449.json b/advisories/unreviewed/2022/04/GHSA-9cq6-7hj7-4449/GHSA-9cq6-7hj7-4449.json index 3f0cb38633e..dfece369b6f 100644 --- a/advisories/unreviewed/2022/04/GHSA-9cq6-7hj7-4449/GHSA-9cq6-7hj7-4449.json +++ b/advisories/unreviewed/2022/04/GHSA-9cq6-7hj7-4449/GHSA-9cq6-7hj7-4449.json @@ -7,12 +7,8 @@ "CVE-1999-0021" ], "details": "Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9fhg-rgm9-gqph/GHSA-9fhg-rgm9-gqph.json b/advisories/unreviewed/2022/04/GHSA-9fhg-rgm9-gqph/GHSA-9fhg-rgm9-gqph.json index 2ea7c4cad31..4c1133e004a 100644 --- a/advisories/unreviewed/2022/04/GHSA-9fhg-rgm9-gqph/GHSA-9fhg-rgm9-gqph.json +++ b/advisories/unreviewed/2022/04/GHSA-9fhg-rgm9-gqph/GHSA-9fhg-rgm9-gqph.json @@ -7,12 +7,8 @@ "CVE-1999-0346" ], "details": "CGI PHP mlog script allows an attacker to read any file on the target server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9hfq-647w-q8vp/GHSA-9hfq-647w-q8vp.json b/advisories/unreviewed/2022/04/GHSA-9hfq-647w-q8vp/GHSA-9hfq-647w-q8vp.json index a3dfd82b7f0..6f15abc2c97 100644 --- a/advisories/unreviewed/2022/04/GHSA-9hfq-647w-q8vp/GHSA-9hfq-647w-q8vp.json +++ b/advisories/unreviewed/2022/04/GHSA-9hfq-647w-q8vp/GHSA-9hfq-647w-q8vp.json @@ -7,12 +7,8 @@ "CVE-1999-0278" ], "details": "In IIS, remote attackers can obtain source code for ASP files by appending \"::$DATA\" to the URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9hrh-6m37-36f5/GHSA-9hrh-6m37-36f5.json b/advisories/unreviewed/2022/04/GHSA-9hrh-6m37-36f5/GHSA-9hrh-6m37-36f5.json index 9259fde6bf7..f36dd67d8c9 100644 --- a/advisories/unreviewed/2022/04/GHSA-9hrh-6m37-36f5/GHSA-9hrh-6m37-36f5.json +++ b/advisories/unreviewed/2022/04/GHSA-9hrh-6m37-36f5/GHSA-9hrh-6m37-36f5.json @@ -7,12 +7,8 @@ "CVE-1999-0230" ], "details": "Buffer overflow in Cisco 7xx routers through the telnet service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9jjh-mmpf-2gc5/GHSA-9jjh-mmpf-2gc5.json b/advisories/unreviewed/2022/04/GHSA-9jjh-mmpf-2gc5/GHSA-9jjh-mmpf-2gc5.json index 57718600457..7234fc209fc 100644 --- a/advisories/unreviewed/2022/04/GHSA-9jjh-mmpf-2gc5/GHSA-9jjh-mmpf-2gc5.json +++ b/advisories/unreviewed/2022/04/GHSA-9jjh-mmpf-2gc5/GHSA-9jjh-mmpf-2gc5.json @@ -7,12 +7,8 @@ "CVE-1999-0265" ], "details": "ICMP redirect messages may crash or lock up a host.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-9pwr-594w-vfp8/GHSA-9pwr-594w-vfp8.json b/advisories/unreviewed/2022/04/GHSA-9pwr-594w-vfp8/GHSA-9pwr-594w-vfp8.json index a18450b520d..fe582f56abc 100644 --- a/advisories/unreviewed/2022/04/GHSA-9pwr-594w-vfp8/GHSA-9pwr-594w-vfp8.json +++ b/advisories/unreviewed/2022/04/GHSA-9pwr-594w-vfp8/GHSA-9pwr-594w-vfp8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-9v5m-hg7x-6gfx/GHSA-9v5m-hg7x-6gfx.json b/advisories/unreviewed/2022/04/GHSA-9v5m-hg7x-6gfx/GHSA-9v5m-hg7x-6gfx.json index f2c2c00be8a..7f8dd8ab1f4 100644 --- a/advisories/unreviewed/2022/04/GHSA-9v5m-hg7x-6gfx/GHSA-9v5m-hg7x-6gfx.json +++ b/advisories/unreviewed/2022/04/GHSA-9v5m-hg7x-6gfx/GHSA-9v5m-hg7x-6gfx.json @@ -7,12 +7,8 @@ "CVE-1999-0261" ], "details": "Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9w26-mqcm-f7p2/GHSA-9w26-mqcm-f7p2.json b/advisories/unreviewed/2022/04/GHSA-9w26-mqcm-f7p2/GHSA-9w26-mqcm-f7p2.json index 163e3fc95c2..0cd076df8e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-9w26-mqcm-f7p2/GHSA-9w26-mqcm-f7p2.json +++ b/advisories/unreviewed/2022/04/GHSA-9w26-mqcm-f7p2/GHSA-9w26-mqcm-f7p2.json @@ -7,12 +7,8 @@ "CVE-1999-0227" ], "details": "Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-9wr7-mfw6-pfpw/GHSA-9wr7-mfw6-pfpw.json b/advisories/unreviewed/2022/04/GHSA-9wr7-mfw6-pfpw/GHSA-9wr7-mfw6-pfpw.json index ca7e3f000f8..1d0e2dda14e 100644 --- a/advisories/unreviewed/2022/04/GHSA-9wr7-mfw6-pfpw/GHSA-9wr7-mfw6-pfpw.json +++ b/advisories/unreviewed/2022/04/GHSA-9wr7-mfw6-pfpw/GHSA-9wr7-mfw6-pfpw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-c22c-6v4p-99rm/GHSA-c22c-6v4p-99rm.json b/advisories/unreviewed/2022/04/GHSA-c22c-6v4p-99rm/GHSA-c22c-6v4p-99rm.json index 0469c91083e..21c6e5e9c64 100644 --- a/advisories/unreviewed/2022/04/GHSA-c22c-6v4p-99rm/GHSA-c22c-6v4p-99rm.json +++ b/advisories/unreviewed/2022/04/GHSA-c22c-6v4p-99rm/GHSA-c22c-6v4p-99rm.json @@ -7,12 +7,8 @@ "CVE-1999-0146" ], "details": "The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-c39g-wmc4-j8vm/GHSA-c39g-wmc4-j8vm.json b/advisories/unreviewed/2022/04/GHSA-c39g-wmc4-j8vm/GHSA-c39g-wmc4-j8vm.json index f5789cbfdae..5f60c6bd433 100644 --- a/advisories/unreviewed/2022/04/GHSA-c39g-wmc4-j8vm/GHSA-c39g-wmc4-j8vm.json +++ b/advisories/unreviewed/2022/04/GHSA-c39g-wmc4-j8vm/GHSA-c39g-wmc4-j8vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-c3jc-r4gm-x242/GHSA-c3jc-r4gm-x242.json b/advisories/unreviewed/2022/04/GHSA-c3jc-r4gm-x242/GHSA-c3jc-r4gm-x242.json index 3516852cbf3..3788cff426e 100644 --- a/advisories/unreviewed/2022/04/GHSA-c3jc-r4gm-x242/GHSA-c3jc-r4gm-x242.json +++ b/advisories/unreviewed/2022/04/GHSA-c3jc-r4gm-x242/GHSA-c3jc-r4gm-x242.json @@ -7,12 +7,8 @@ "CVE-1999-0311" ], "details": "fpkg2swpk in HP-UX allows local users to gain root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-cchj-wxvc-4fxf/GHSA-cchj-wxvc-4fxf.json b/advisories/unreviewed/2022/04/GHSA-cchj-wxvc-4fxf/GHSA-cchj-wxvc-4fxf.json index fdefcd71ee4..c90121e7d1f 100644 --- a/advisories/unreviewed/2022/04/GHSA-cchj-wxvc-4fxf/GHSA-cchj-wxvc-4fxf.json +++ b/advisories/unreviewed/2022/04/GHSA-cchj-wxvc-4fxf/GHSA-cchj-wxvc-4fxf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-cx8m-q3j5-7c8p/GHSA-cx8m-q3j5-7c8p.json b/advisories/unreviewed/2022/04/GHSA-cx8m-q3j5-7c8p/GHSA-cx8m-q3j5-7c8p.json index 5ed5bd81709..0ac0b797813 100644 --- a/advisories/unreviewed/2022/04/GHSA-cx8m-q3j5-7c8p/GHSA-cx8m-q3j5-7c8p.json +++ b/advisories/unreviewed/2022/04/GHSA-cx8m-q3j5-7c8p/GHSA-cx8m-q3j5-7c8p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f37w-7jp2-g9vf/GHSA-f37w-7jp2-g9vf.json b/advisories/unreviewed/2022/04/GHSA-f37w-7jp2-g9vf/GHSA-f37w-7jp2-g9vf.json index ab0c224deeb..d8571662d61 100644 --- a/advisories/unreviewed/2022/04/GHSA-f37w-7jp2-g9vf/GHSA-f37w-7jp2-g9vf.json +++ b/advisories/unreviewed/2022/04/GHSA-f37w-7jp2-g9vf/GHSA-f37w-7jp2-g9vf.json @@ -7,12 +7,8 @@ "CVE-1999-0056" ], "details": "Buffer overflow in Sun's ping program can give root access to local users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-f6fj-c8gc-64v6/GHSA-f6fj-c8gc-64v6.json b/advisories/unreviewed/2022/04/GHSA-f6fj-c8gc-64v6/GHSA-f6fj-c8gc-64v6.json index 208f0f4bb06..5982f134581 100644 --- a/advisories/unreviewed/2022/04/GHSA-f6fj-c8gc-64v6/GHSA-f6fj-c8gc-64v6.json +++ b/advisories/unreviewed/2022/04/GHSA-f6fj-c8gc-64v6/GHSA-f6fj-c8gc-64v6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-f9p2-88mm-74g3/GHSA-f9p2-88mm-74g3.json b/advisories/unreviewed/2022/04/GHSA-f9p2-88mm-74g3/GHSA-f9p2-88mm-74g3.json index 864b2f26f7c..c43be23fb7d 100644 --- a/advisories/unreviewed/2022/04/GHSA-f9p2-88mm-74g3/GHSA-f9p2-88mm-74g3.json +++ b/advisories/unreviewed/2022/04/GHSA-f9p2-88mm-74g3/GHSA-f9p2-88mm-74g3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-fcp8-jrh7-67m9/GHSA-fcp8-jrh7-67m9.json b/advisories/unreviewed/2022/04/GHSA-fcp8-jrh7-67m9/GHSA-fcp8-jrh7-67m9.json index 14d68a15b7d..2cc29e35c7b 100644 --- a/advisories/unreviewed/2022/04/GHSA-fcp8-jrh7-67m9/GHSA-fcp8-jrh7-67m9.json +++ b/advisories/unreviewed/2022/04/GHSA-fcp8-jrh7-67m9/GHSA-fcp8-jrh7-67m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-fjvr-5p42-92hg/GHSA-fjvr-5p42-92hg.json b/advisories/unreviewed/2022/04/GHSA-fjvr-5p42-92hg/GHSA-fjvr-5p42-92hg.json index 677bb8a67e7..e29be6a5d33 100644 --- a/advisories/unreviewed/2022/04/GHSA-fjvr-5p42-92hg/GHSA-fjvr-5p42-92hg.json +++ b/advisories/unreviewed/2022/04/GHSA-fjvr-5p42-92hg/GHSA-fjvr-5p42-92hg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-fwjc-rphw-659w/GHSA-fwjc-rphw-659w.json b/advisories/unreviewed/2022/04/GHSA-fwjc-rphw-659w/GHSA-fwjc-rphw-659w.json index 4c33167381c..4a49468289b 100644 --- a/advisories/unreviewed/2022/04/GHSA-fwjc-rphw-659w/GHSA-fwjc-rphw-659w.json +++ b/advisories/unreviewed/2022/04/GHSA-fwjc-rphw-659w/GHSA-fwjc-rphw-659w.json @@ -7,12 +7,8 @@ "CVE-1999-0004" ], "details": "MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g5mj-9qj7-8j9f/GHSA-g5mj-9qj7-8j9f.json b/advisories/unreviewed/2022/04/GHSA-g5mj-9qj7-8j9f/GHSA-g5mj-9qj7-8j9f.json index b7274680d5c..0ed624bc3ac 100644 --- a/advisories/unreviewed/2022/04/GHSA-g5mj-9qj7-8j9f/GHSA-g5mj-9qj7-8j9f.json +++ b/advisories/unreviewed/2022/04/GHSA-g5mj-9qj7-8j9f/GHSA-g5mj-9qj7-8j9f.json @@ -7,12 +7,8 @@ "CVE-1999-0309" ], "details": "HP-UX vgdisplay program gives root access to local users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g8h2-q2mr-m37j/GHSA-g8h2-q2mr-m37j.json b/advisories/unreviewed/2022/04/GHSA-g8h2-q2mr-m37j/GHSA-g8h2-q2mr-m37j.json index 22ce6622d1b..d692d77f62f 100644 --- a/advisories/unreviewed/2022/04/GHSA-g8h2-q2mr-m37j/GHSA-g8h2-q2mr-m37j.json +++ b/advisories/unreviewed/2022/04/GHSA-g8h2-q2mr-m37j/GHSA-g8h2-q2mr-m37j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-g8hc-v6fv-6qxq/GHSA-g8hc-v6fv-6qxq.json b/advisories/unreviewed/2022/04/GHSA-g8hc-v6fv-6qxq/GHSA-g8hc-v6fv-6qxq.json index 04e2f92981b..7edecf9f148 100644 --- a/advisories/unreviewed/2022/04/GHSA-g8hc-v6fv-6qxq/GHSA-g8hc-v6fv-6qxq.json +++ b/advisories/unreviewed/2022/04/GHSA-g8hc-v6fv-6qxq/GHSA-g8hc-v6fv-6qxq.json @@ -7,12 +7,8 @@ "CVE-1999-0358" ], "details": "Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g8pm-3rfw-27p7/GHSA-g8pm-3rfw-27p7.json b/advisories/unreviewed/2022/04/GHSA-g8pm-3rfw-27p7/GHSA-g8pm-3rfw-27p7.json index c061c8cfea8..4496ceff99c 100644 --- a/advisories/unreviewed/2022/04/GHSA-g8pm-3rfw-27p7/GHSA-g8pm-3rfw-27p7.json +++ b/advisories/unreviewed/2022/04/GHSA-g8pm-3rfw-27p7/GHSA-g8pm-3rfw-27p7.json @@ -7,12 +7,8 @@ "CVE-1999-0263" ], "details": "Solaris SUNWadmap can be exploited to obtain root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-g9jq-2w39-657g/GHSA-g9jq-2w39-657g.json b/advisories/unreviewed/2022/04/GHSA-g9jq-2w39-657g/GHSA-g9jq-2w39-657g.json index 97aae4024fa..9de87b4dcde 100644 --- a/advisories/unreviewed/2022/04/GHSA-g9jq-2w39-657g/GHSA-g9jq-2w39-657g.json +++ b/advisories/unreviewed/2022/04/GHSA-g9jq-2w39-657g/GHSA-g9jq-2w39-657g.json @@ -7,12 +7,8 @@ "CVE-1999-0153" ], "details": "Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gcg2-8wmh-x2h4/GHSA-gcg2-8wmh-x2h4.json b/advisories/unreviewed/2022/04/GHSA-gcg2-8wmh-x2h4/GHSA-gcg2-8wmh-x2h4.json index d63a3e66554..ccd109fbdb4 100644 --- a/advisories/unreviewed/2022/04/GHSA-gcg2-8wmh-x2h4/GHSA-gcg2-8wmh-x2h4.json +++ b/advisories/unreviewed/2022/04/GHSA-gcg2-8wmh-x2h4/GHSA-gcg2-8wmh-x2h4.json @@ -7,12 +7,8 @@ "CVE-1999-0185" ], "details": "In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gh4g-jjvx-97h2/GHSA-gh4g-jjvx-97h2.json b/advisories/unreviewed/2022/04/GHSA-gh4g-jjvx-97h2/GHSA-gh4g-jjvx-97h2.json index 0698c758bfb..0ae7776d8af 100644 --- a/advisories/unreviewed/2022/04/GHSA-gh4g-jjvx-97h2/GHSA-gh4g-jjvx-97h2.json +++ b/advisories/unreviewed/2022/04/GHSA-gh4g-jjvx-97h2/GHSA-gh4g-jjvx-97h2.json @@ -7,12 +7,8 @@ "CVE-1999-0065" ], "details": "Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gh7m-jrjh-pwvm/GHSA-gh7m-jrjh-pwvm.json b/advisories/unreviewed/2022/04/GHSA-gh7m-jrjh-pwvm/GHSA-gh7m-jrjh-pwvm.json index 43b29907b6f..7cee38ea841 100644 --- a/advisories/unreviewed/2022/04/GHSA-gh7m-jrjh-pwvm/GHSA-gh7m-jrjh-pwvm.json +++ b/advisories/unreviewed/2022/04/GHSA-gh7m-jrjh-pwvm/GHSA-gh7m-jrjh-pwvm.json @@ -7,12 +7,8 @@ "CVE-1999-0190" ], "details": "Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gpx4-x6pm-ch4q/GHSA-gpx4-x6pm-ch4q.json b/advisories/unreviewed/2022/04/GHSA-gpx4-x6pm-ch4q/GHSA-gpx4-x6pm-ch4q.json index fcecc35d643..296a3e9f4eb 100644 --- a/advisories/unreviewed/2022/04/GHSA-gpx4-x6pm-ch4q/GHSA-gpx4-x6pm-ch4q.json +++ b/advisories/unreviewed/2022/04/GHSA-gpx4-x6pm-ch4q/GHSA-gpx4-x6pm-ch4q.json @@ -7,12 +7,8 @@ "CVE-1999-0048" ], "details": "Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gwrm-3497-38vq/GHSA-gwrm-3497-38vq.json b/advisories/unreviewed/2022/04/GHSA-gwrm-3497-38vq/GHSA-gwrm-3497-38vq.json index eeb2467736f..a619042ebd5 100644 --- a/advisories/unreviewed/2022/04/GHSA-gwrm-3497-38vq/GHSA-gwrm-3497-38vq.json +++ b/advisories/unreviewed/2022/04/GHSA-gwrm-3497-38vq/GHSA-gwrm-3497-38vq.json @@ -7,12 +7,8 @@ "CVE-1999-0131" ], "details": "Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-gxph-3c78-xmc3/GHSA-gxph-3c78-xmc3.json b/advisories/unreviewed/2022/04/GHSA-gxph-3c78-xmc3/GHSA-gxph-3c78-xmc3.json index a3d15fe247c..5710eb90928 100644 --- a/advisories/unreviewed/2022/04/GHSA-gxph-3c78-xmc3/GHSA-gxph-3c78-xmc3.json +++ b/advisories/unreviewed/2022/04/GHSA-gxph-3c78-xmc3/GHSA-gxph-3c78-xmc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-h74g-q6cf-5qxm/GHSA-h74g-q6cf-5qxm.json b/advisories/unreviewed/2022/04/GHSA-h74g-q6cf-5qxm/GHSA-h74g-q6cf-5qxm.json index 34d7f7e64d3..418220d8b1b 100644 --- a/advisories/unreviewed/2022/04/GHSA-h74g-q6cf-5qxm/GHSA-h74g-q6cf-5qxm.json +++ b/advisories/unreviewed/2022/04/GHSA-h74g-q6cf-5qxm/GHSA-h74g-q6cf-5qxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-h9xj-4798-57hx/GHSA-h9xj-4798-57hx.json b/advisories/unreviewed/2022/04/GHSA-h9xj-4798-57hx/GHSA-h9xj-4798-57hx.json index 0a637d7a632..1a54bf19ea8 100644 --- a/advisories/unreviewed/2022/04/GHSA-h9xj-4798-57hx/GHSA-h9xj-4798-57hx.json +++ b/advisories/unreviewed/2022/04/GHSA-h9xj-4798-57hx/GHSA-h9xj-4798-57hx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hcx2-xwc8-g58x/GHSA-hcx2-xwc8-g58x.json b/advisories/unreviewed/2022/04/GHSA-hcx2-xwc8-g58x/GHSA-hcx2-xwc8-g58x.json index 994804db535..1b864025179 100644 --- a/advisories/unreviewed/2022/04/GHSA-hcx2-xwc8-g58x/GHSA-hcx2-xwc8-g58x.json +++ b/advisories/unreviewed/2022/04/GHSA-hcx2-xwc8-g58x/GHSA-hcx2-xwc8-g58x.json @@ -7,12 +7,8 @@ "CVE-1999-0305" ], "details": "The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hcx3-7fvg-jr7j/GHSA-hcx3-7fvg-jr7j.json b/advisories/unreviewed/2022/04/GHSA-hcx3-7fvg-jr7j/GHSA-hcx3-7fvg-jr7j.json index 3abda5f3e6d..9e33de7a7c0 100644 --- a/advisories/unreviewed/2022/04/GHSA-hcx3-7fvg-jr7j/GHSA-hcx3-7fvg-jr7j.json +++ b/advisories/unreviewed/2022/04/GHSA-hcx3-7fvg-jr7j/GHSA-hcx3-7fvg-jr7j.json @@ -7,12 +7,8 @@ "CVE-1999-0349" ], "details": "A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hh43-c3j2-vcx4/GHSA-hh43-c3j2-vcx4.json b/advisories/unreviewed/2022/04/GHSA-hh43-c3j2-vcx4/GHSA-hh43-c3j2-vcx4.json index 7830ec50d33..7602331ac0d 100644 --- a/advisories/unreviewed/2022/04/GHSA-hh43-c3j2-vcx4/GHSA-hh43-c3j2-vcx4.json +++ b/advisories/unreviewed/2022/04/GHSA-hh43-c3j2-vcx4/GHSA-hh43-c3j2-vcx4.json @@ -7,12 +7,8 @@ "CVE-1999-0179" ], "details": "Windows NT crashes or locks up when a Samba client executes a \"cd ..\" command on a file share.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hh7x-vrmv-hcpw/GHSA-hh7x-vrmv-hcpw.json b/advisories/unreviewed/2022/04/GHSA-hh7x-vrmv-hcpw/GHSA-hh7x-vrmv-hcpw.json index 08ff13c2769..b927251814a 100644 --- a/advisories/unreviewed/2022/04/GHSA-hh7x-vrmv-hcpw/GHSA-hh7x-vrmv-hcpw.json +++ b/advisories/unreviewed/2022/04/GHSA-hh7x-vrmv-hcpw/GHSA-hh7x-vrmv-hcpw.json @@ -7,12 +7,8 @@ "CVE-1999-0225" ], "details": "Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hp2v-j3h7-3x3r/GHSA-hp2v-j3h7-3x3r.json b/advisories/unreviewed/2022/04/GHSA-hp2v-j3h7-3x3r/GHSA-hp2v-j3h7-3x3r.json index 121a17ce6dd..0d189ca462b 100644 --- a/advisories/unreviewed/2022/04/GHSA-hp2v-j3h7-3x3r/GHSA-hp2v-j3h7-3x3r.json +++ b/advisories/unreviewed/2022/04/GHSA-hp2v-j3h7-3x3r/GHSA-hp2v-j3h7-3x3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-hqvv-gg34-388m/GHSA-hqvv-gg34-388m.json b/advisories/unreviewed/2022/04/GHSA-hqvv-gg34-388m/GHSA-hqvv-gg34-388m.json index cd9b5294cd6..b8677220c4a 100644 --- a/advisories/unreviewed/2022/04/GHSA-hqvv-gg34-388m/GHSA-hqvv-gg34-388m.json +++ b/advisories/unreviewed/2022/04/GHSA-hqvv-gg34-388m/GHSA-hqvv-gg34-388m.json @@ -7,12 +7,8 @@ "CVE-1999-0108" ], "details": "The printers program in IRIX has a buffer overflow that gives root access to local users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hr69-c7w4-vwmp/GHSA-hr69-c7w4-vwmp.json b/advisories/unreviewed/2022/04/GHSA-hr69-c7w4-vwmp/GHSA-hr69-c7w4-vwmp.json index 7589ef93423..197dbc2a779 100644 --- a/advisories/unreviewed/2022/04/GHSA-hr69-c7w4-vwmp/GHSA-hr69-c7w4-vwmp.json +++ b/advisories/unreviewed/2022/04/GHSA-hr69-c7w4-vwmp/GHSA-hr69-c7w4-vwmp.json @@ -7,12 +7,8 @@ "CVE-1999-0126" ], "details": "SGI IRIX buffer overflow in xterm and Xaw allows root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-hvp5-q7xm-fj7p/GHSA-hvp5-q7xm-fj7p.json b/advisories/unreviewed/2022/04/GHSA-hvp5-q7xm-fj7p/GHSA-hvp5-q7xm-fj7p.json index 495c4234050..725b85b01ed 100644 --- a/advisories/unreviewed/2022/04/GHSA-hvp5-q7xm-fj7p/GHSA-hvp5-q7xm-fj7p.json +++ b/advisories/unreviewed/2022/04/GHSA-hvp5-q7xm-fj7p/GHSA-hvp5-q7xm-fj7p.json @@ -7,12 +7,8 @@ "CVE-1999-0364" ], "details": "Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j253-q87v-j6h6/GHSA-j253-q87v-j6h6.json b/advisories/unreviewed/2022/04/GHSA-j253-q87v-j6h6/GHSA-j253-q87v-j6h6.json index 25b2d2622fa..6760451f097 100644 --- a/advisories/unreviewed/2022/04/GHSA-j253-q87v-j6h6/GHSA-j253-q87v-j6h6.json +++ b/advisories/unreviewed/2022/04/GHSA-j253-q87v-j6h6/GHSA-j253-q87v-j6h6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-j2h3-fmf6-5vc4/GHSA-j2h3-fmf6-5vc4.json b/advisories/unreviewed/2022/04/GHSA-j2h3-fmf6-5vc4/GHSA-j2h3-fmf6-5vc4.json index 0a8b2fcb39d..8f5164fbc1e 100644 --- a/advisories/unreviewed/2022/04/GHSA-j2h3-fmf6-5vc4/GHSA-j2h3-fmf6-5vc4.json +++ b/advisories/unreviewed/2022/04/GHSA-j2h3-fmf6-5vc4/GHSA-j2h3-fmf6-5vc4.json @@ -7,12 +7,8 @@ "CVE-1999-0068" ], "details": "CGI PHP mylog script allows an attacker to read any file on the target server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j2jv-rjg6-95m2/GHSA-j2jv-rjg6-95m2.json b/advisories/unreviewed/2022/04/GHSA-j2jv-rjg6-95m2/GHSA-j2jv-rjg6-95m2.json index bf36b05b26f..f63447030e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-j2jv-rjg6-95m2/GHSA-j2jv-rjg6-95m2.json +++ b/advisories/unreviewed/2022/04/GHSA-j2jv-rjg6-95m2/GHSA-j2jv-rjg6-95m2.json @@ -7,12 +7,8 @@ "CVE-1999-0077" ], "details": "Predictable TCP sequence numbers allow spoofing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-j3c3-76w9-jg8q/GHSA-j3c3-76w9-jg8q.json b/advisories/unreviewed/2022/04/GHSA-j3c3-76w9-jg8q/GHSA-j3c3-76w9-jg8q.json index e15d3c9372c..748bbff7f12 100644 --- a/advisories/unreviewed/2022/04/GHSA-j3c3-76w9-jg8q/GHSA-j3c3-76w9-jg8q.json +++ b/advisories/unreviewed/2022/04/GHSA-j3c3-76w9-jg8q/GHSA-j3c3-76w9-jg8q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-j8r4-w4xh-mcv3/GHSA-j8r4-w4xh-mcv3.json b/advisories/unreviewed/2022/04/GHSA-j8r4-w4xh-mcv3/GHSA-j8r4-w4xh-mcv3.json index 27a9dbed90a..6505c3fef00 100644 --- a/advisories/unreviewed/2022/04/GHSA-j8r4-w4xh-mcv3/GHSA-j8r4-w4xh-mcv3.json +++ b/advisories/unreviewed/2022/04/GHSA-j8r4-w4xh-mcv3/GHSA-j8r4-w4xh-mcv3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-j989-83h4-x7f9/GHSA-j989-83h4-x7f9.json b/advisories/unreviewed/2022/04/GHSA-j989-83h4-x7f9/GHSA-j989-83h4-x7f9.json index 7d0cebfde35..6687f6094a2 100644 --- a/advisories/unreviewed/2022/04/GHSA-j989-83h4-x7f9/GHSA-j989-83h4-x7f9.json +++ b/advisories/unreviewed/2022/04/GHSA-j989-83h4-x7f9/GHSA-j989-83h4-x7f9.json @@ -7,12 +7,8 @@ "CVE-1999-0288" ], "details": "The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jfmp-2xvc-mh4c/GHSA-jfmp-2xvc-mh4c.json b/advisories/unreviewed/2022/04/GHSA-jfmp-2xvc-mh4c/GHSA-jfmp-2xvc-mh4c.json index 6dca7187587..ecbe02df094 100644 --- a/advisories/unreviewed/2022/04/GHSA-jfmp-2xvc-mh4c/GHSA-jfmp-2xvc-mh4c.json +++ b/advisories/unreviewed/2022/04/GHSA-jfmp-2xvc-mh4c/GHSA-jfmp-2xvc-mh4c.json @@ -7,12 +7,8 @@ "CVE-1999-0085" ], "details": "Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jg89-g7f6-c75m/GHSA-jg89-g7f6-c75m.json b/advisories/unreviewed/2022/04/GHSA-jg89-g7f6-c75m/GHSA-jg89-g7f6-c75m.json index b42842c7a08..f3925f2caa0 100644 --- a/advisories/unreviewed/2022/04/GHSA-jg89-g7f6-c75m/GHSA-jg89-g7f6-c75m.json +++ b/advisories/unreviewed/2022/04/GHSA-jg89-g7f6-c75m/GHSA-jg89-g7f6-c75m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-jh68-jmm9-8mjv/GHSA-jh68-jmm9-8mjv.json b/advisories/unreviewed/2022/04/GHSA-jh68-jmm9-8mjv/GHSA-jh68-jmm9-8mjv.json index fbd09073b7e..62053a0418c 100644 --- a/advisories/unreviewed/2022/04/GHSA-jh68-jmm9-8mjv/GHSA-jh68-jmm9-8mjv.json +++ b/advisories/unreviewed/2022/04/GHSA-jh68-jmm9-8mjv/GHSA-jh68-jmm9-8mjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-jhpj-x68v-g2h8/GHSA-jhpj-x68v-g2h8.json b/advisories/unreviewed/2022/04/GHSA-jhpj-x68v-g2h8/GHSA-jhpj-x68v-g2h8.json index d97e70e3f0d..ff834a438e6 100644 --- a/advisories/unreviewed/2022/04/GHSA-jhpj-x68v-g2h8/GHSA-jhpj-x68v-g2h8.json +++ b/advisories/unreviewed/2022/04/GHSA-jhpj-x68v-g2h8/GHSA-jhpj-x68v-g2h8.json @@ -7,12 +7,8 @@ "CVE-1999-0088" ], "details": "IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-jpfh-48x5-93p3/GHSA-jpfh-48x5-93p3.json b/advisories/unreviewed/2022/04/GHSA-jpfh-48x5-93p3/GHSA-jpfh-48x5-93p3.json index 90b5127ca8d..aae7234c125 100644 --- a/advisories/unreviewed/2022/04/GHSA-jpfh-48x5-93p3/GHSA-jpfh-48x5-93p3.json +++ b/advisories/unreviewed/2022/04/GHSA-jpfh-48x5-93p3/GHSA-jpfh-48x5-93p3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-jvxp-2488-w24g/GHSA-jvxp-2488-w24g.json b/advisories/unreviewed/2022/04/GHSA-jvxp-2488-w24g/GHSA-jvxp-2488-w24g.json index 51381f68cdc..0ae17665580 100644 --- a/advisories/unreviewed/2022/04/GHSA-jvxp-2488-w24g/GHSA-jvxp-2488-w24g.json +++ b/advisories/unreviewed/2022/04/GHSA-jvxp-2488-w24g/GHSA-jvxp-2488-w24g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-m29h-r53r-8j77/GHSA-m29h-r53r-8j77.json b/advisories/unreviewed/2022/04/GHSA-m29h-r53r-8j77/GHSA-m29h-r53r-8j77.json index 196e3776f7b..e7e7fd77bd2 100644 --- a/advisories/unreviewed/2022/04/GHSA-m29h-r53r-8j77/GHSA-m29h-r53r-8j77.json +++ b/advisories/unreviewed/2022/04/GHSA-m29h-r53r-8j77/GHSA-m29h-r53r-8j77.json @@ -7,12 +7,8 @@ "CVE-1999-0019" ], "details": "Delete or create a file via rpc.statd, due to invalid information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m4p5-87mw-mjv4/GHSA-m4p5-87mw-mjv4.json b/advisories/unreviewed/2022/04/GHSA-m4p5-87mw-mjv4/GHSA-m4p5-87mw-mjv4.json index 635d1cecd3b..19dbbf1f82c 100644 --- a/advisories/unreviewed/2022/04/GHSA-m4p5-87mw-mjv4/GHSA-m4p5-87mw-mjv4.json +++ b/advisories/unreviewed/2022/04/GHSA-m4p5-87mw-mjv4/GHSA-m4p5-87mw-mjv4.json @@ -7,12 +7,8 @@ "CVE-1999-0300" ], "details": "nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m4px-ph3f-7964/GHSA-m4px-ph3f-7964.json b/advisories/unreviewed/2022/04/GHSA-m4px-ph3f-7964/GHSA-m4px-ph3f-7964.json index 9fe738f5268..afe5cfe31af 100644 --- a/advisories/unreviewed/2022/04/GHSA-m4px-ph3f-7964/GHSA-m4px-ph3f-7964.json +++ b/advisories/unreviewed/2022/04/GHSA-m4px-ph3f-7964/GHSA-m4px-ph3f-7964.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-m7xv-wfqv-x2wf/GHSA-m7xv-wfqv-x2wf.json b/advisories/unreviewed/2022/04/GHSA-m7xv-wfqv-x2wf/GHSA-m7xv-wfqv-x2wf.json index f65639c8049..e717c331561 100644 --- a/advisories/unreviewed/2022/04/GHSA-m7xv-wfqv-x2wf/GHSA-m7xv-wfqv-x2wf.json +++ b/advisories/unreviewed/2022/04/GHSA-m7xv-wfqv-x2wf/GHSA-m7xv-wfqv-x2wf.json @@ -7,12 +7,8 @@ "CVE-1999-0109" ], "details": "Buffer overflow in ffbconfig in Solaris 2.5.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m95x-799j-2j8h/GHSA-m95x-799j-2j8h.json b/advisories/unreviewed/2022/04/GHSA-m95x-799j-2j8h/GHSA-m95x-799j-2j8h.json index a2ee743c02c..94588e2fb4c 100644 --- a/advisories/unreviewed/2022/04/GHSA-m95x-799j-2j8h/GHSA-m95x-799j-2j8h.json +++ b/advisories/unreviewed/2022/04/GHSA-m95x-799j-2j8h/GHSA-m95x-799j-2j8h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-m96g-x499-p5f9/GHSA-m96g-x499-p5f9.json b/advisories/unreviewed/2022/04/GHSA-m96g-x499-p5f9/GHSA-m96g-x499-p5f9.json index 496524de83e..c3aaddad558 100644 --- a/advisories/unreviewed/2022/04/GHSA-m96g-x499-p5f9/GHSA-m96g-x499-p5f9.json +++ b/advisories/unreviewed/2022/04/GHSA-m96g-x499-p5f9/GHSA-m96g-x499-p5f9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-m9mc-xf9x-5qg2/GHSA-m9mc-xf9x-5qg2.json b/advisories/unreviewed/2022/04/GHSA-m9mc-xf9x-5qg2/GHSA-m9mc-xf9x-5qg2.json index 3d57a1fa6c0..69b06844910 100644 --- a/advisories/unreviewed/2022/04/GHSA-m9mc-xf9x-5qg2/GHSA-m9mc-xf9x-5qg2.json +++ b/advisories/unreviewed/2022/04/GHSA-m9mc-xf9x-5qg2/GHSA-m9mc-xf9x-5qg2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mcc7-rcr3-2rgr/GHSA-mcc7-rcr3-2rgr.json b/advisories/unreviewed/2022/04/GHSA-mcc7-rcr3-2rgr/GHSA-mcc7-rcr3-2rgr.json index 5bfe40d09af..1eb844eb1b6 100644 --- a/advisories/unreviewed/2022/04/GHSA-mcc7-rcr3-2rgr/GHSA-mcc7-rcr3-2rgr.json +++ b/advisories/unreviewed/2022/04/GHSA-mcc7-rcr3-2rgr/GHSA-mcc7-rcr3-2rgr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mh8f-866p-w345/GHSA-mh8f-866p-w345.json b/advisories/unreviewed/2022/04/GHSA-mh8f-866p-w345/GHSA-mh8f-866p-w345.json index 3bb20f37de7..13764b6774d 100644 --- a/advisories/unreviewed/2022/04/GHSA-mh8f-866p-w345/GHSA-mh8f-866p-w345.json +++ b/advisories/unreviewed/2022/04/GHSA-mh8f-866p-w345/GHSA-mh8f-866p-w345.json @@ -7,12 +7,8 @@ "CVE-1999-0075" ], "details": "PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mhmm-r9x5-v638/GHSA-mhmm-r9x5-v638.json b/advisories/unreviewed/2022/04/GHSA-mhmm-r9x5-v638/GHSA-mhmm-r9x5-v638.json index dba925eb6dd..9b8a83c5247 100644 --- a/advisories/unreviewed/2022/04/GHSA-mhmm-r9x5-v638/GHSA-mhmm-r9x5-v638.json +++ b/advisories/unreviewed/2022/04/GHSA-mhmm-r9x5-v638/GHSA-mhmm-r9x5-v638.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-mpm3-7hwj-p7fp/GHSA-mpm3-7hwj-p7fp.json b/advisories/unreviewed/2022/04/GHSA-mpm3-7hwj-p7fp/GHSA-mpm3-7hwj-p7fp.json index e3cf2b4e257..d8b238eca4b 100644 --- a/advisories/unreviewed/2022/04/GHSA-mpm3-7hwj-p7fp/GHSA-mpm3-7hwj-p7fp.json +++ b/advisories/unreviewed/2022/04/GHSA-mpm3-7hwj-p7fp/GHSA-mpm3-7hwj-p7fp.json @@ -7,12 +7,8 @@ "CVE-1999-0209" ], "details": "The SunView (SunTools) selection_svc facility allows remote users to read files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mpqm-r86r-845w/GHSA-mpqm-r86r-845w.json b/advisories/unreviewed/2022/04/GHSA-mpqm-r86r-845w/GHSA-mpqm-r86r-845w.json index 7d73fd2cc62..846e894de8e 100644 --- a/advisories/unreviewed/2022/04/GHSA-mpqm-r86r-845w/GHSA-mpqm-r86r-845w.json +++ b/advisories/unreviewed/2022/04/GHSA-mpqm-r86r-845w/GHSA-mpqm-r86r-845w.json @@ -7,12 +7,8 @@ "CVE-1999-0347" ], "details": "Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a \"%01\" character in an \"about:\" Javascript URL, which causes Internet Explorer to use the domain specified after the character.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mrrg-f2wm-6g83/GHSA-mrrg-f2wm-6g83.json b/advisories/unreviewed/2022/04/GHSA-mrrg-f2wm-6g83/GHSA-mrrg-f2wm-6g83.json index 5c32475505b..a2d09df31d0 100644 --- a/advisories/unreviewed/2022/04/GHSA-mrrg-f2wm-6g83/GHSA-mrrg-f2wm-6g83.json +++ b/advisories/unreviewed/2022/04/GHSA-mrrg-f2wm-6g83/GHSA-mrrg-f2wm-6g83.json @@ -7,12 +7,8 @@ "CVE-1999-0139" ], "details": "Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-mxj7-853v-cxhh/GHSA-mxj7-853v-cxhh.json b/advisories/unreviewed/2022/04/GHSA-mxj7-853v-cxhh/GHSA-mxj7-853v-cxhh.json index ed1898ea389..c7fdf9e62b4 100644 --- a/advisories/unreviewed/2022/04/GHSA-mxj7-853v-cxhh/GHSA-mxj7-853v-cxhh.json +++ b/advisories/unreviewed/2022/04/GHSA-mxj7-853v-cxhh/GHSA-mxj7-853v-cxhh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-p4qf-98m6-vm84/GHSA-p4qf-98m6-vm84.json b/advisories/unreviewed/2022/04/GHSA-p4qf-98m6-vm84/GHSA-p4qf-98m6-vm84.json index 372f68bbb3a..2a65e7b2717 100644 --- a/advisories/unreviewed/2022/04/GHSA-p4qf-98m6-vm84/GHSA-p4qf-98m6-vm84.json +++ b/advisories/unreviewed/2022/04/GHSA-p4qf-98m6-vm84/GHSA-p4qf-98m6-vm84.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-p6cp-hx87-7342/GHSA-p6cp-hx87-7342.json b/advisories/unreviewed/2022/04/GHSA-p6cp-hx87-7342/GHSA-p6cp-hx87-7342.json index d5911b50f9a..7eac43afc79 100644 --- a/advisories/unreviewed/2022/04/GHSA-p6cp-hx87-7342/GHSA-p6cp-hx87-7342.json +++ b/advisories/unreviewed/2022/04/GHSA-p6cp-hx87-7342/GHSA-p6cp-hx87-7342.json @@ -7,12 +7,8 @@ "CVE-1999-0191" ], "details": "IIS newdsn.exe CGI script allows remote users to overwrite files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-p847-qhmr-433r/GHSA-p847-qhmr-433r.json b/advisories/unreviewed/2022/04/GHSA-p847-qhmr-433r/GHSA-p847-qhmr-433r.json index 28060773f8f..73f37d32ee6 100644 --- a/advisories/unreviewed/2022/04/GHSA-p847-qhmr-433r/GHSA-p847-qhmr-433r.json +++ b/advisories/unreviewed/2022/04/GHSA-p847-qhmr-433r/GHSA-p847-qhmr-433r.json @@ -7,12 +7,8 @@ "CVE-1999-0189" ], "details": "Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pc5g-vf3f-w3r7/GHSA-pc5g-vf3f-w3r7.json b/advisories/unreviewed/2022/04/GHSA-pc5g-vf3f-w3r7/GHSA-pc5g-vf3f-w3r7.json index 5b2f79c3be4..7924b398b2b 100644 --- a/advisories/unreviewed/2022/04/GHSA-pc5g-vf3f-w3r7/GHSA-pc5g-vf3f-w3r7.json +++ b/advisories/unreviewed/2022/04/GHSA-pc5g-vf3f-w3r7/GHSA-pc5g-vf3f-w3r7.json @@ -7,12 +7,8 @@ "CVE-1999-0058" ], "details": "Buffer overflow in PHP cgi program, php.cgi allows shell access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pf77-c4gh-6m4v/GHSA-pf77-c4gh-6m4v.json b/advisories/unreviewed/2022/04/GHSA-pf77-c4gh-6m4v/GHSA-pf77-c4gh-6m4v.json index aa9f304185b..83609e810bb 100644 --- a/advisories/unreviewed/2022/04/GHSA-pf77-c4gh-6m4v/GHSA-pf77-c4gh-6m4v.json +++ b/advisories/unreviewed/2022/04/GHSA-pf77-c4gh-6m4v/GHSA-pf77-c4gh-6m4v.json @@ -7,12 +7,8 @@ "CVE-1999-0115" ], "details": "AIX bugfiler program allows local users to gain root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pf77-xv47-9wfc/GHSA-pf77-xv47-9wfc.json b/advisories/unreviewed/2022/04/GHSA-pf77-xv47-9wfc/GHSA-pf77-xv47-9wfc.json index f024ab82a2c..50f0e1625e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-pf77-xv47-9wfc/GHSA-pf77-xv47-9wfc.json +++ b/advisories/unreviewed/2022/04/GHSA-pf77-xv47-9wfc/GHSA-pf77-xv47-9wfc.json @@ -7,12 +7,8 @@ "CVE-1999-0095" ], "details": "The debug command in Sendmail is enabled, allowing attackers to execute commands as root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pg9f-vmhv-m524/GHSA-pg9f-vmhv-m524.json b/advisories/unreviewed/2022/04/GHSA-pg9f-vmhv-m524/GHSA-pg9f-vmhv-m524.json index 1077cb8ac15..c088ebec444 100644 --- a/advisories/unreviewed/2022/04/GHSA-pg9f-vmhv-m524/GHSA-pg9f-vmhv-m524.json +++ b/advisories/unreviewed/2022/04/GHSA-pg9f-vmhv-m524/GHSA-pg9f-vmhv-m524.json @@ -7,12 +7,8 @@ "CVE-1999-0087" ], "details": "Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pmvg-g2g6-mpp9/GHSA-pmvg-g2g6-mpp9.json b/advisories/unreviewed/2022/04/GHSA-pmvg-g2g6-mpp9/GHSA-pmvg-g2g6-mpp9.json index 9391ff1abd8..eadd9e46462 100644 --- a/advisories/unreviewed/2022/04/GHSA-pmvg-g2g6-mpp9/GHSA-pmvg-g2g6-mpp9.json +++ b/advisories/unreviewed/2022/04/GHSA-pmvg-g2g6-mpp9/GHSA-pmvg-g2g6-mpp9.json @@ -7,12 +7,8 @@ "CVE-1999-0268" ], "details": "MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-pq3w-wpr9-q68m/GHSA-pq3w-wpr9-q68m.json b/advisories/unreviewed/2022/04/GHSA-pq3w-wpr9-q68m/GHSA-pq3w-wpr9-q68m.json index dcc072508a3..8966734f18b 100644 --- a/advisories/unreviewed/2022/04/GHSA-pq3w-wpr9-q68m/GHSA-pq3w-wpr9-q68m.json +++ b/advisories/unreviewed/2022/04/GHSA-pq3w-wpr9-q68m/GHSA-pq3w-wpr9-q68m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-pqg2-q88q-5h4p/GHSA-pqg2-q88q-5h4p.json b/advisories/unreviewed/2022/04/GHSA-pqg2-q88q-5h4p/GHSA-pqg2-q88q-5h4p.json index 9dae8dfc470..fa660888408 100644 --- a/advisories/unreviewed/2022/04/GHSA-pqg2-q88q-5h4p/GHSA-pqg2-q88q-5h4p.json +++ b/advisories/unreviewed/2022/04/GHSA-pqg2-q88q-5h4p/GHSA-pqg2-q88q-5h4p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-pwgq-fv9q-ff77/GHSA-pwgq-fv9q-ff77.json b/advisories/unreviewed/2022/04/GHSA-pwgq-fv9q-ff77/GHSA-pwgq-fv9q-ff77.json index cf4ebd6e27a..a35af66e032 100644 --- a/advisories/unreviewed/2022/04/GHSA-pwgq-fv9q-ff77/GHSA-pwgq-fv9q-ff77.json +++ b/advisories/unreviewed/2022/04/GHSA-pwgq-fv9q-ff77/GHSA-pwgq-fv9q-ff77.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-q289-h6gw-f7rp/GHSA-q289-h6gw-f7rp.json b/advisories/unreviewed/2022/04/GHSA-q289-h6gw-f7rp/GHSA-q289-h6gw-f7rp.json index 52c7ef0b499..1f7b02c56b0 100644 --- a/advisories/unreviewed/2022/04/GHSA-q289-h6gw-f7rp/GHSA-q289-h6gw-f7rp.json +++ b/advisories/unreviewed/2022/04/GHSA-q289-h6gw-f7rp/GHSA-q289-h6gw-f7rp.json @@ -7,12 +7,8 @@ "CVE-1999-0223" ], "details": "Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-q295-vmhf-gfx2/GHSA-q295-vmhf-gfx2.json b/advisories/unreviewed/2022/04/GHSA-q295-vmhf-gfx2/GHSA-q295-vmhf-gfx2.json index e104b816ce8..9b5d1c12cfa 100644 --- a/advisories/unreviewed/2022/04/GHSA-q295-vmhf-gfx2/GHSA-q295-vmhf-gfx2.json +++ b/advisories/unreviewed/2022/04/GHSA-q295-vmhf-gfx2/GHSA-q295-vmhf-gfx2.json @@ -7,12 +7,8 @@ "CVE-1999-0001" ], "details": "ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-q3xm-785w-f7gp/GHSA-q3xm-785w-f7gp.json b/advisories/unreviewed/2022/04/GHSA-q3xm-785w-f7gp/GHSA-q3xm-785w-f7gp.json index 728206e69f4..cef5aa00add 100644 --- a/advisories/unreviewed/2022/04/GHSA-q3xm-785w-f7gp/GHSA-q3xm-785w-f7gp.json +++ b/advisories/unreviewed/2022/04/GHSA-q3xm-785w-f7gp/GHSA-q3xm-785w-f7gp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-q6hg-qxrw-r3f8/GHSA-q6hg-qxrw-r3f8.json b/advisories/unreviewed/2022/04/GHSA-q6hg-qxrw-r3f8/GHSA-q6hg-qxrw-r3f8.json index 6a7a9e6d87f..3b0fedd189c 100644 --- a/advisories/unreviewed/2022/04/GHSA-q6hg-qxrw-r3f8/GHSA-q6hg-qxrw-r3f8.json +++ b/advisories/unreviewed/2022/04/GHSA-q6hg-qxrw-r3f8/GHSA-q6hg-qxrw-r3f8.json @@ -7,12 +7,8 @@ "CVE-1999-0348" ], "details": "IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qc45-j6qw-gcwq/GHSA-qc45-j6qw-gcwq.json b/advisories/unreviewed/2022/04/GHSA-qc45-j6qw-gcwq/GHSA-qc45-j6qw-gcwq.json index 13a2e74345c..2f9d54a875e 100644 --- a/advisories/unreviewed/2022/04/GHSA-qc45-j6qw-gcwq/GHSA-qc45-j6qw-gcwq.json +++ b/advisories/unreviewed/2022/04/GHSA-qc45-j6qw-gcwq/GHSA-qc45-j6qw-gcwq.json @@ -7,12 +7,8 @@ "CVE-1999-0354" ], "details": "Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-qj23-j7r8-wv79/GHSA-qj23-j7r8-wv79.json b/advisories/unreviewed/2022/04/GHSA-qj23-j7r8-wv79/GHSA-qj23-j7r8-wv79.json index 179fb42bcb3..bdd4442ab0b 100644 --- a/advisories/unreviewed/2022/04/GHSA-qj23-j7r8-wv79/GHSA-qj23-j7r8-wv79.json +++ b/advisories/unreviewed/2022/04/GHSA-qj23-j7r8-wv79/GHSA-qj23-j7r8-wv79.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-qmpj-76fg-rqm3/GHSA-qmpj-76fg-rqm3.json b/advisories/unreviewed/2022/04/GHSA-qmpj-76fg-rqm3/GHSA-qmpj-76fg-rqm3.json index ba6ee1a0426..4ded2bc1935 100644 --- a/advisories/unreviewed/2022/04/GHSA-qmpj-76fg-rqm3/GHSA-qmpj-76fg-rqm3.json +++ b/advisories/unreviewed/2022/04/GHSA-qmpj-76fg-rqm3/GHSA-qmpj-76fg-rqm3.json @@ -7,12 +7,8 @@ "CVE-1999-0298" ], "details": "ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r346-6vhr-2jfx/GHSA-r346-6vhr-2jfx.json b/advisories/unreviewed/2022/04/GHSA-r346-6vhr-2jfx/GHSA-r346-6vhr-2jfx.json index f19e0f49eb0..9cfbf52f86c 100644 --- a/advisories/unreviewed/2022/04/GHSA-r346-6vhr-2jfx/GHSA-r346-6vhr-2jfx.json +++ b/advisories/unreviewed/2022/04/GHSA-r346-6vhr-2jfx/GHSA-r346-6vhr-2jfx.json @@ -7,12 +7,8 @@ "CVE-1999-0031" ], "details": "JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r4w7-99qp-4gfx/GHSA-r4w7-99qp-4gfx.json b/advisories/unreviewed/2022/04/GHSA-r4w7-99qp-4gfx/GHSA-r4w7-99qp-4gfx.json index 46aff6ccbed..4b1869fc620 100644 --- a/advisories/unreviewed/2022/04/GHSA-r4w7-99qp-4gfx/GHSA-r4w7-99qp-4gfx.json +++ b/advisories/unreviewed/2022/04/GHSA-r4w7-99qp-4gfx/GHSA-r4w7-99qp-4gfx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-r5x4-9c2q-479j/GHSA-r5x4-9c2q-479j.json b/advisories/unreviewed/2022/04/GHSA-r5x4-9c2q-479j/GHSA-r5x4-9c2q-479j.json index 4470a263576..1f1744832db 100644 --- a/advisories/unreviewed/2022/04/GHSA-r5x4-9c2q-479j/GHSA-r5x4-9c2q-479j.json +++ b/advisories/unreviewed/2022/04/GHSA-r5x4-9c2q-479j/GHSA-r5x4-9c2q-479j.json @@ -7,12 +7,8 @@ "CVE-1999-0141" ], "details": "Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-r6f2-q5m9-c9hv/GHSA-r6f2-q5m9-c9hv.json b/advisories/unreviewed/2022/04/GHSA-r6f2-q5m9-c9hv/GHSA-r6f2-q5m9-c9hv.json index 856b07355d2..6d3d8562bd9 100644 --- a/advisories/unreviewed/2022/04/GHSA-r6f2-q5m9-c9hv/GHSA-r6f2-q5m9-c9hv.json +++ b/advisories/unreviewed/2022/04/GHSA-r6f2-q5m9-c9hv/GHSA-r6f2-q5m9-c9hv.json @@ -7,12 +7,8 @@ "CVE-1999-0145" ], "details": "Sendmail WIZ command enabled, allowing root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rcxw-5j32-vq8v/GHSA-rcxw-5j32-vq8v.json b/advisories/unreviewed/2022/04/GHSA-rcxw-5j32-vq8v/GHSA-rcxw-5j32-vq8v.json index 9d3ed0c3a59..40ca1e38742 100644 --- a/advisories/unreviewed/2022/04/GHSA-rcxw-5j32-vq8v/GHSA-rcxw-5j32-vq8v.json +++ b/advisories/unreviewed/2022/04/GHSA-rcxw-5j32-vq8v/GHSA-rcxw-5j32-vq8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rhcm-mpjw-m6hf/GHSA-rhcm-mpjw-m6hf.json b/advisories/unreviewed/2022/04/GHSA-rhcm-mpjw-m6hf/GHSA-rhcm-mpjw-m6hf.json index 8f7bcf24807..366c942bde0 100644 --- a/advisories/unreviewed/2022/04/GHSA-rhcm-mpjw-m6hf/GHSA-rhcm-mpjw-m6hf.json +++ b/advisories/unreviewed/2022/04/GHSA-rhcm-mpjw-m6hf/GHSA-rhcm-mpjw-m6hf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rrfw-jfjv-g7mx/GHSA-rrfw-jfjv-g7mx.json b/advisories/unreviewed/2022/04/GHSA-rrfw-jfjv-g7mx/GHSA-rrfw-jfjv-g7mx.json index d505f56d52f..6a639394288 100644 --- a/advisories/unreviewed/2022/04/GHSA-rrfw-jfjv-g7mx/GHSA-rrfw-jfjv-g7mx.json +++ b/advisories/unreviewed/2022/04/GHSA-rrfw-jfjv-g7mx/GHSA-rrfw-jfjv-g7mx.json @@ -7,12 +7,8 @@ "CVE-1999-0164" ], "details": "A race condition in the Solaris ps command allows an attacker to overwrite critical files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rx39-mff5-f3vv/GHSA-rx39-mff5-f3vv.json b/advisories/unreviewed/2022/04/GHSA-rx39-mff5-f3vv/GHSA-rx39-mff5-f3vv.json index badaf9415f5..cc1eeb985e7 100644 --- a/advisories/unreviewed/2022/04/GHSA-rx39-mff5-f3vv/GHSA-rx39-mff5-f3vv.json +++ b/advisories/unreviewed/2022/04/GHSA-rx39-mff5-f3vv/GHSA-rx39-mff5-f3vv.json @@ -7,12 +7,8 @@ "CVE-1999-0160" ], "details": "Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-rxx7-9cxm-4hfx/GHSA-rxx7-9cxm-4hfx.json b/advisories/unreviewed/2022/04/GHSA-rxx7-9cxm-4hfx/GHSA-rxx7-9cxm-4hfx.json index 06cb313e5fc..c93767e38b7 100644 --- a/advisories/unreviewed/2022/04/GHSA-rxx7-9cxm-4hfx/GHSA-rxx7-9cxm-4hfx.json +++ b/advisories/unreviewed/2022/04/GHSA-rxx7-9cxm-4hfx/GHSA-rxx7-9cxm-4hfx.json @@ -7,12 +7,8 @@ "CVE-1999-0130" ], "details": "Local users can start Sendmail in daemon mode and gain root privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v5qh-v63r-wvqx/GHSA-v5qh-v63r-wvqx.json b/advisories/unreviewed/2022/04/GHSA-v5qh-v63r-wvqx/GHSA-v5qh-v63r-wvqx.json index 073ccd5b527..c1cb7141cb0 100644 --- a/advisories/unreviewed/2022/04/GHSA-v5qh-v63r-wvqx/GHSA-v5qh-v63r-wvqx.json +++ b/advisories/unreviewed/2022/04/GHSA-v5qh-v63r-wvqx/GHSA-v5qh-v63r-wvqx.json @@ -7,12 +7,8 @@ "CVE-1999-0082" ], "details": "CWD ~root command in ftpd allows root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v6xx-2vrx-5x2g/GHSA-v6xx-2vrx-5x2g.json b/advisories/unreviewed/2022/04/GHSA-v6xx-2vrx-5x2g/GHSA-v6xx-2vrx-5x2g.json index 098542fdb4a..b49a8488d13 100644 --- a/advisories/unreviewed/2022/04/GHSA-v6xx-2vrx-5x2g/GHSA-v6xx-2vrx-5x2g.json +++ b/advisories/unreviewed/2022/04/GHSA-v6xx-2vrx-5x2g/GHSA-v6xx-2vrx-5x2g.json @@ -7,12 +7,8 @@ "CVE-1999-0062" ], "details": "The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-v76w-cp5w-h37c/GHSA-v76w-cp5w-h37c.json b/advisories/unreviewed/2022/04/GHSA-v76w-cp5w-h37c/GHSA-v76w-cp5w-h37c.json index f442bd5019d..4697077326b 100644 --- a/advisories/unreviewed/2022/04/GHSA-v76w-cp5w-h37c/GHSA-v76w-cp5w-h37c.json +++ b/advisories/unreviewed/2022/04/GHSA-v76w-cp5w-h37c/GHSA-v76w-cp5w-h37c.json @@ -7,12 +7,8 @@ "CVE-1999-0332" ], "details": "Buffer overflow in NetMeeting allows denial of service and remote command execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-v93g-8xmc-xvqm/GHSA-v93g-8xmc-xvqm.json b/advisories/unreviewed/2022/04/GHSA-v93g-8xmc-xvqm/GHSA-v93g-8xmc-xvqm.json index 3f0878c3035..702588d2bf4 100644 --- a/advisories/unreviewed/2022/04/GHSA-v93g-8xmc-xvqm/GHSA-v93g-8xmc-xvqm.json +++ b/advisories/unreviewed/2022/04/GHSA-v93g-8xmc-xvqm/GHSA-v93g-8xmc-xvqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-v9jq-22v9-c89h/GHSA-v9jq-22v9-c89h.json b/advisories/unreviewed/2022/04/GHSA-v9jq-22v9-c89h/GHSA-v9jq-22v9-c89h.json index db0df4b2983..78a26e2cb4d 100644 --- a/advisories/unreviewed/2022/04/GHSA-v9jq-22v9-c89h/GHSA-v9jq-22v9-c89h.json +++ b/advisories/unreviewed/2022/04/GHSA-v9jq-22v9-c89h/GHSA-v9jq-22v9-c89h.json @@ -7,12 +7,8 @@ "CVE-1999-0134" ], "details": "vold in Solaris 2.x allows local users to gain root access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vc5j-x9w7-frw6/GHSA-vc5j-x9w7-frw6.json b/advisories/unreviewed/2022/04/GHSA-vc5j-x9w7-frw6/GHSA-vc5j-x9w7-frw6.json index 91b10391275..2b69577af9f 100644 --- a/advisories/unreviewed/2022/04/GHSA-vc5j-x9w7-frw6/GHSA-vc5j-x9w7-frw6.json +++ b/advisories/unreviewed/2022/04/GHSA-vc5j-x9w7-frw6/GHSA-vc5j-x9w7-frw6.json @@ -7,12 +7,8 @@ "CVE-1999-0182" ], "details": "Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vhcr-j22h-735c/GHSA-vhcr-j22h-735c.json b/advisories/unreviewed/2022/04/GHSA-vhcr-j22h-735c/GHSA-vhcr-j22h-735c.json index 8ff4c92fb4a..d43edb5f71a 100644 --- a/advisories/unreviewed/2022/04/GHSA-vhcr-j22h-735c/GHSA-vhcr-j22h-735c.json +++ b/advisories/unreviewed/2022/04/GHSA-vhcr-j22h-735c/GHSA-vhcr-j22h-735c.json @@ -7,12 +7,8 @@ "CVE-1999-0248" ], "details": "A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-vmff-jqvr-5fqj/GHSA-vmff-jqvr-5fqj.json b/advisories/unreviewed/2022/04/GHSA-vmff-jqvr-5fqj/GHSA-vmff-jqvr-5fqj.json index 5b2062462b7..2b5929858b7 100644 --- a/advisories/unreviewed/2022/04/GHSA-vmff-jqvr-5fqj/GHSA-vmff-jqvr-5fqj.json +++ b/advisories/unreviewed/2022/04/GHSA-vmff-jqvr-5fqj/GHSA-vmff-jqvr-5fqj.json @@ -7,12 +7,8 @@ "CVE-1999-0047" ], "details": "MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-w9v4-2rg2-7r9v/GHSA-w9v4-2rg2-7r9v.json b/advisories/unreviewed/2022/04/GHSA-w9v4-2rg2-7r9v/GHSA-w9v4-2rg2-7r9v.json index 37a7af68aaa..3ff7f34e7b7 100644 --- a/advisories/unreviewed/2022/04/GHSA-w9v4-2rg2-7r9v/GHSA-w9v4-2rg2-7r9v.json +++ b/advisories/unreviewed/2022/04/GHSA-w9v4-2rg2-7r9v/GHSA-w9v4-2rg2-7r9v.json @@ -7,12 +7,8 @@ "CVE-1999-0054" ], "details": "Sun's ftpd daemon can be subjected to a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wc9v-xvxc-2x5v/GHSA-wc9v-xvxc-2x5v.json b/advisories/unreviewed/2022/04/GHSA-wc9v-xvxc-2x5v/GHSA-wc9v-xvxc-2x5v.json index 6c46460179b..4bd621b2f42 100644 --- a/advisories/unreviewed/2022/04/GHSA-wc9v-xvxc-2x5v/GHSA-wc9v-xvxc-2x5v.json +++ b/advisories/unreviewed/2022/04/GHSA-wc9v-xvxc-2x5v/GHSA-wc9v-xvxc-2x5v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wgf5-r6hp-p33g/GHSA-wgf5-r6hp-p33g.json b/advisories/unreviewed/2022/04/GHSA-wgf5-r6hp-p33g/GHSA-wgf5-r6hp-p33g.json index fdabdbd647e..f3737b8d296 100644 --- a/advisories/unreviewed/2022/04/GHSA-wgf5-r6hp-p33g/GHSA-wgf5-r6hp-p33g.json +++ b/advisories/unreviewed/2022/04/GHSA-wgf5-r6hp-p33g/GHSA-wgf5-r6hp-p33g.json @@ -7,12 +7,8 @@ "CVE-1999-0014" ], "details": "Unauthorized privileged access or denial of service via dtappgather program in CDE.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wghv-q62f-f457/GHSA-wghv-q62f-f457.json b/advisories/unreviewed/2022/04/GHSA-wghv-q62f-f457/GHSA-wghv-q62f-f457.json index 24d62c51196..d030d913660 100644 --- a/advisories/unreviewed/2022/04/GHSA-wghv-q62f-f457/GHSA-wghv-q62f-f457.json +++ b/advisories/unreviewed/2022/04/GHSA-wghv-q62f-f457/GHSA-wghv-q62f-f457.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wmqx-7q2f-fcf6/GHSA-wmqx-7q2f-fcf6.json b/advisories/unreviewed/2022/04/GHSA-wmqx-7q2f-fcf6/GHSA-wmqx-7q2f-fcf6.json index dd1ef19738b..28ae09158f4 100644 --- a/advisories/unreviewed/2022/04/GHSA-wmqx-7q2f-fcf6/GHSA-wmqx-7q2f-fcf6.json +++ b/advisories/unreviewed/2022/04/GHSA-wmqx-7q2f-fcf6/GHSA-wmqx-7q2f-fcf6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-wq5m-pq24-j5cv/GHSA-wq5m-pq24-j5cv.json b/advisories/unreviewed/2022/04/GHSA-wq5m-pq24-j5cv/GHSA-wq5m-pq24-j5cv.json index a1c664f926c..e8abef2f9f9 100644 --- a/advisories/unreviewed/2022/04/GHSA-wq5m-pq24-j5cv/GHSA-wq5m-pq24-j5cv.json +++ b/advisories/unreviewed/2022/04/GHSA-wq5m-pq24-j5cv/GHSA-wq5m-pq24-j5cv.json @@ -7,12 +7,8 @@ "CVE-1999-0250" ], "details": "Denial of service in Qmail through long SMTP commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-wvm5-6hrh-5wf3/GHSA-wvm5-6hrh-5wf3.json b/advisories/unreviewed/2022/04/GHSA-wvm5-6hrh-5wf3/GHSA-wvm5-6hrh-5wf3.json index 68993e35637..a90477e97d7 100644 --- a/advisories/unreviewed/2022/04/GHSA-wvm5-6hrh-5wf3/GHSA-wvm5-6hrh-5wf3.json +++ b/advisories/unreviewed/2022/04/GHSA-wvm5-6hrh-5wf3/GHSA-wvm5-6hrh-5wf3.json @@ -7,12 +7,8 @@ "CVE-1999-0005" ], "details": "Arbitrary command execution via IMAP buffer overflow in authenticate command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x3w7-5p4x-x8g9/GHSA-x3w7-5p4x-x8g9.json b/advisories/unreviewed/2022/04/GHSA-x3w7-5p4x-x8g9/GHSA-x3w7-5p4x-x8g9.json index 3aa1bf906e7..5cf5d94798a 100644 --- a/advisories/unreviewed/2022/04/GHSA-x3w7-5p4x-x8g9/GHSA-x3w7-5p4x-x8g9.json +++ b/advisories/unreviewed/2022/04/GHSA-x3w7-5p4x-x8g9/GHSA-x3w7-5p4x-x8g9.json @@ -7,12 +7,8 @@ "CVE-1999-0096" ], "details": "Sendmail decode alias can be used to overwrite sensitive files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x7qv-mjw2-5rwx/GHSA-x7qv-mjw2-5rwx.json b/advisories/unreviewed/2022/04/GHSA-x7qv-mjw2-5rwx/GHSA-x7qv-mjw2-5rwx.json index b7d1d1b0b18..f6376a9ff7b 100644 --- a/advisories/unreviewed/2022/04/GHSA-x7qv-mjw2-5rwx/GHSA-x7qv-mjw2-5rwx.json +++ b/advisories/unreviewed/2022/04/GHSA-x7qv-mjw2-5rwx/GHSA-x7qv-mjw2-5rwx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-x86v-j2gh-g3w6/GHSA-x86v-j2gh-g3w6.json b/advisories/unreviewed/2022/04/GHSA-x86v-j2gh-g3w6/GHSA-x86v-j2gh-g3w6.json index 966a7c691e3..a3d5d196510 100644 --- a/advisories/unreviewed/2022/04/GHSA-x86v-j2gh-g3w6/GHSA-x86v-j2gh-g3w6.json +++ b/advisories/unreviewed/2022/04/GHSA-x86v-j2gh-g3w6/GHSA-x86v-j2gh-g3w6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-x945-cxjq-chq5/GHSA-x945-cxjq-chq5.json b/advisories/unreviewed/2022/04/GHSA-x945-cxjq-chq5/GHSA-x945-cxjq-chq5.json index 3669a55b77b..e09ce85c935 100644 --- a/advisories/unreviewed/2022/04/GHSA-x945-cxjq-chq5/GHSA-x945-cxjq-chq5.json +++ b/advisories/unreviewed/2022/04/GHSA-x945-cxjq-chq5/GHSA-x945-cxjq-chq5.json @@ -7,12 +7,8 @@ "CVE-1999-0326" ], "details": "Vulnerability in HP-UX mediainit program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-x9m7-4vf7-7448/GHSA-x9m7-4vf7-7448.json b/advisories/unreviewed/2022/04/GHSA-x9m7-4vf7-7448/GHSA-x9m7-4vf7-7448.json index 22e6c184c2b..479e3bd9e8f 100644 --- a/advisories/unreviewed/2022/04/GHSA-x9m7-4vf7-7448/GHSA-x9m7-4vf7-7448.json +++ b/advisories/unreviewed/2022/04/GHSA-x9m7-4vf7-7448/GHSA-x9m7-4vf7-7448.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-xc68-xqhg-hr75/GHSA-xc68-xqhg-hr75.json b/advisories/unreviewed/2022/04/GHSA-xc68-xqhg-hr75/GHSA-xc68-xqhg-hr75.json index cd10990e2e8..322b0f1d159 100644 --- a/advisories/unreviewed/2022/04/GHSA-xc68-xqhg-hr75/GHSA-xc68-xqhg-hr75.json +++ b/advisories/unreviewed/2022/04/GHSA-xc68-xqhg-hr75/GHSA-xc68-xqhg-hr75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-xcgj-hpmh-8rc2/GHSA-xcgj-hpmh-8rc2.json b/advisories/unreviewed/2022/04/GHSA-xcgj-hpmh-8rc2/GHSA-xcgj-hpmh-8rc2.json index 84dbb738671..0104b16e028 100644 --- a/advisories/unreviewed/2022/04/GHSA-xcgj-hpmh-8rc2/GHSA-xcgj-hpmh-8rc2.json +++ b/advisories/unreviewed/2022/04/GHSA-xcgj-hpmh-8rc2/GHSA-xcgj-hpmh-8rc2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-xj3h-gcxj-7pw6/GHSA-xj3h-gcxj-7pw6.json b/advisories/unreviewed/2022/04/GHSA-xj3h-gcxj-7pw6/GHSA-xj3h-gcxj-7pw6.json index a3cb3e6e33a..c92c5acbec3 100644 --- a/advisories/unreviewed/2022/04/GHSA-xj3h-gcxj-7pw6/GHSA-xj3h-gcxj-7pw6.json +++ b/advisories/unreviewed/2022/04/GHSA-xj3h-gcxj-7pw6/GHSA-xj3h-gcxj-7pw6.json @@ -7,12 +7,8 @@ "CVE-1999-0015" ], "details": "Teardrop IP denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xjw4-7jv6-2hqx/GHSA-xjw4-7jv6-2hqx.json b/advisories/unreviewed/2022/04/GHSA-xjw4-7jv6-2hqx/GHSA-xjw4-7jv6-2hqx.json index 7ab92fbdddc..9bec13dcad3 100644 --- a/advisories/unreviewed/2022/04/GHSA-xjw4-7jv6-2hqx/GHSA-xjw4-7jv6-2hqx.json +++ b/advisories/unreviewed/2022/04/GHSA-xjw4-7jv6-2hqx/GHSA-xjw4-7jv6-2hqx.json @@ -7,12 +7,8 @@ "CVE-1999-0188" ], "details": "The passwd command in Solaris can be subjected to a denial of service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xr2c-mwcx-4xmj/GHSA-xr2c-mwcx-4xmj.json b/advisories/unreviewed/2022/04/GHSA-xr2c-mwcx-4xmj/GHSA-xr2c-mwcx-4xmj.json index 16a3b747c5a..a95102bd601 100644 --- a/advisories/unreviewed/2022/04/GHSA-xr2c-mwcx-4xmj/GHSA-xr2c-mwcx-4xmj.json +++ b/advisories/unreviewed/2022/04/GHSA-xr2c-mwcx-4xmj/GHSA-xr2c-mwcx-4xmj.json @@ -7,12 +7,8 @@ "CVE-1999-0008" ], "details": "Buffer overflow in NIS+, in Sun's rpc.nisd program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xrxr-vcvh-gm7h/GHSA-xrxr-vcvh-gm7h.json b/advisories/unreviewed/2022/04/GHSA-xrxr-vcvh-gm7h/GHSA-xrxr-vcvh-gm7h.json index 86d8fa83868..e2f47d17a95 100644 --- a/advisories/unreviewed/2022/04/GHSA-xrxr-vcvh-gm7h/GHSA-xrxr-vcvh-gm7h.json +++ b/advisories/unreviewed/2022/04/GHSA-xrxr-vcvh-gm7h/GHSA-xrxr-vcvh-gm7h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -47,9 +45,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/04/GHSA-xxhw-w5qp-5pvr/GHSA-xxhw-w5qp-5pvr.json b/advisories/unreviewed/2022/04/GHSA-xxhw-w5qp-5pvr/GHSA-xxhw-w5qp-5pvr.json index 3c38d7f3659..40da430bf0e 100644 --- a/advisories/unreviewed/2022/04/GHSA-xxhw-w5qp-5pvr/GHSA-xxhw-w5qp-5pvr.json +++ b/advisories/unreviewed/2022/04/GHSA-xxhw-w5qp-5pvr/GHSA-xxhw-w5qp-5pvr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-227g-5725-2cf3/GHSA-227g-5725-2cf3.json b/advisories/unreviewed/2022/05/GHSA-227g-5725-2cf3/GHSA-227g-5725-2cf3.json index c22ef61e6ca..e88aa8f9932 100644 --- a/advisories/unreviewed/2022/05/GHSA-227g-5725-2cf3/GHSA-227g-5725-2cf3.json +++ b/advisories/unreviewed/2022/05/GHSA-227g-5725-2cf3/GHSA-227g-5725-2cf3.json @@ -7,12 +7,8 @@ "CVE-2020-24045" ], "details": "A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebsd-tools/vmware-tools-distrib/vmware-install.pl path. The fake ISO image will be mounted and the script wmware-install.pl will be executed with super-user privileges as soon as the hidden option to install VMware Tools is selected in the main menu of the restricted shell (option number 5). The contents of the script can be whatever the attacker wants, including a backdoor or similar.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-22f7-crxf-6p65/GHSA-22f7-crxf-6p65.json b/advisories/unreviewed/2022/05/GHSA-22f7-crxf-6p65/GHSA-22f7-crxf-6p65.json index 734d7b4e446..4b38d9513e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-22f7-crxf-6p65/GHSA-22f7-crxf-6p65.json +++ b/advisories/unreviewed/2022/05/GHSA-22f7-crxf-6p65/GHSA-22f7-crxf-6p65.json @@ -7,12 +7,8 @@ "CVE-2020-11804" ], "details": "An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2347-fp75-m9xc/GHSA-2347-fp75-m9xc.json b/advisories/unreviewed/2022/05/GHSA-2347-fp75-m9xc/GHSA-2347-fp75-m9xc.json index e698268717a..4241353e23a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2347-fp75-m9xc/GHSA-2347-fp75-m9xc.json +++ b/advisories/unreviewed/2022/05/GHSA-2347-fp75-m9xc/GHSA-2347-fp75-m9xc.json @@ -7,12 +7,8 @@ "CVE-2020-16171" ], "details": "An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate web request issued by the application itself. This can be abused to conduct SSRF attacks against otherwise unreachable Acronis services that are bound to localhost such as the NotificationService on 127.0.0.1:30572.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-23px-c43v-54wp/GHSA-23px-c43v-54wp.json b/advisories/unreviewed/2022/05/GHSA-23px-c43v-54wp/GHSA-23px-c43v-54wp.json index 7dea35b0c6c..35c05589542 100644 --- a/advisories/unreviewed/2022/05/GHSA-23px-c43v-54wp/GHSA-23px-c43v-54wp.json +++ b/advisories/unreviewed/2022/05/GHSA-23px-c43v-54wp/GHSA-23px-c43v-54wp.json @@ -7,12 +7,8 @@ "CVE-2018-10585" ], "details": "Pexip Infinity before 18 allows remote Denial of Service (XML parsing).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25wr-cfxr-69vm/GHSA-25wr-cfxr-69vm.json b/advisories/unreviewed/2022/05/GHSA-25wr-cfxr-69vm/GHSA-25wr-cfxr-69vm.json index 6437eabfa6b..97b63bbc2db 100644 --- a/advisories/unreviewed/2022/05/GHSA-25wr-cfxr-69vm/GHSA-25wr-cfxr-69vm.json +++ b/advisories/unreviewed/2022/05/GHSA-25wr-cfxr-69vm/GHSA-25wr-cfxr-69vm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-262h-gvvr-qmcc/GHSA-262h-gvvr-qmcc.json b/advisories/unreviewed/2022/05/GHSA-262h-gvvr-qmcc/GHSA-262h-gvvr-qmcc.json index e7209bb79ac..97dc0c0ccc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-262h-gvvr-qmcc/GHSA-262h-gvvr-qmcc.json +++ b/advisories/unreviewed/2022/05/GHSA-262h-gvvr-qmcc/GHSA-262h-gvvr-qmcc.json @@ -7,12 +7,8 @@ "CVE-2020-0335" ], "details": "In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-122361504", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26jg-48xv-2wqr/GHSA-26jg-48xv-2wqr.json b/advisories/unreviewed/2022/05/GHSA-26jg-48xv-2wqr/GHSA-26jg-48xv-2wqr.json index ac39c530fe5..7cff7742752 100644 --- a/advisories/unreviewed/2022/05/GHSA-26jg-48xv-2wqr/GHSA-26jg-48xv-2wqr.json +++ b/advisories/unreviewed/2022/05/GHSA-26jg-48xv-2wqr/GHSA-26jg-48xv-2wqr.json @@ -7,12 +7,8 @@ "CVE-2020-13337" ], "details": "An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-26rv-4r9g-579p/GHSA-26rv-4r9g-579p.json b/advisories/unreviewed/2022/05/GHSA-26rv-4r9g-579p/GHSA-26rv-4r9g-579p.json index 200f6235a5e..3a9723d56fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-26rv-4r9g-579p/GHSA-26rv-4r9g-579p.json +++ b/advisories/unreviewed/2022/05/GHSA-26rv-4r9g-579p/GHSA-26rv-4r9g-579p.json @@ -7,12 +7,8 @@ "CVE-2020-0337" ], "details": "In MediaProvider, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124329382", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2764-7h3r-8xg3/GHSA-2764-7h3r-8xg3.json b/advisories/unreviewed/2022/05/GHSA-2764-7h3r-8xg3/GHSA-2764-7h3r-8xg3.json index e189821a176..a88bcac7c5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2764-7h3r-8xg3/GHSA-2764-7h3r-8xg3.json +++ b/advisories/unreviewed/2022/05/GHSA-2764-7h3r-8xg3/GHSA-2764-7h3r-8xg3.json @@ -7,12 +7,8 @@ "CVE-2019-16212" ], "details": "A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authentication process.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-27c2-9cc9-22v7/GHSA-27c2-9cc9-22v7.json b/advisories/unreviewed/2022/05/GHSA-27c2-9cc9-22v7/GHSA-27c2-9cc9-22v7.json index 11b8d54f0d2..e8bb94b8e5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-27c2-9cc9-22v7/GHSA-27c2-9cc9-22v7.json +++ b/advisories/unreviewed/2022/05/GHSA-27c2-9cc9-22v7/GHSA-27c2-9cc9-22v7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-282c-c2hf-44pq/GHSA-282c-c2hf-44pq.json b/advisories/unreviewed/2022/05/GHSA-282c-c2hf-44pq/GHSA-282c-c2hf-44pq.json index 5657a49b4e5..b48d53e9ad1 100644 --- a/advisories/unreviewed/2022/05/GHSA-282c-c2hf-44pq/GHSA-282c-c2hf-44pq.json +++ b/advisories/unreviewed/2022/05/GHSA-282c-c2hf-44pq/GHSA-282c-c2hf-44pq.json @@ -7,12 +7,8 @@ "CVE-2020-9739" ], "details": "Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28f5-7mw6-mfmc/GHSA-28f5-7mw6-mfmc.json b/advisories/unreviewed/2022/05/GHSA-28f5-7mw6-mfmc/GHSA-28f5-7mw6-mfmc.json index 9c4f57b54c1..e01f791a02a 100644 --- a/advisories/unreviewed/2022/05/GHSA-28f5-7mw6-mfmc/GHSA-28f5-7mw6-mfmc.json +++ b/advisories/unreviewed/2022/05/GHSA-28f5-7mw6-mfmc/GHSA-28f5-7mw6-mfmc.json @@ -7,12 +7,8 @@ "CVE-2020-0338" ], "details": "In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2955-cp7r-7qw6/GHSA-2955-cp7r-7qw6.json b/advisories/unreviewed/2022/05/GHSA-2955-cp7r-7qw6/GHSA-2955-cp7r-7qw6.json index 825fc76a868..6cefab115a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2955-cp7r-7qw6/GHSA-2955-cp7r-7qw6.json +++ b/advisories/unreviewed/2022/05/GHSA-2955-cp7r-7qw6/GHSA-2955-cp7r-7qw6.json @@ -7,12 +7,8 @@ "CVE-2020-14506" ], "details": "Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2c29-84m2-9q27/GHSA-2c29-84m2-9q27.json b/advisories/unreviewed/2022/05/GHSA-2c29-84m2-9q27/GHSA-2c29-84m2-9q27.json index 52112887aa0..8733e5b10dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c29-84m2-9q27/GHSA-2c29-84m2-9q27.json +++ b/advisories/unreviewed/2022/05/GHSA-2c29-84m2-9q27/GHSA-2c29-84m2-9q27.json @@ -7,12 +7,8 @@ "CVE-2020-4531" ], "details": "IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182715.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2c3m-f6hh-4v8q/GHSA-2c3m-f6hh-4v8q.json b/advisories/unreviewed/2022/05/GHSA-2c3m-f6hh-4v8q/GHSA-2c3m-f6hh-4v8q.json index a229e7bc8a8..c5a7072f4c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c3m-f6hh-4v8q/GHSA-2c3m-f6hh-4v8q.json +++ b/advisories/unreviewed/2022/05/GHSA-2c3m-f6hh-4v8q/GHSA-2c3m-f6hh-4v8q.json @@ -7,12 +7,8 @@ "CVE-2019-16009" ], "details": "A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user. If the user has administrative privileges, the attacker could alter the configuration, execute commands, or reload an affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2f4q-74mc-vp6m/GHSA-2f4q-74mc-vp6m.json b/advisories/unreviewed/2022/05/GHSA-2f4q-74mc-vp6m/GHSA-2f4q-74mc-vp6m.json index 240e75d4d1c..5ebaae3d0f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f4q-74mc-vp6m/GHSA-2f4q-74mc-vp6m.json +++ b/advisories/unreviewed/2022/05/GHSA-2f4q-74mc-vp6m/GHSA-2f4q-74mc-vp6m.json @@ -7,12 +7,8 @@ "CVE-2020-12870" ], "details": "RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2fch-4j3w-44mf/GHSA-2fch-4j3w-44mf.json b/advisories/unreviewed/2022/05/GHSA-2fch-4j3w-44mf/GHSA-2fch-4j3w-44mf.json index a685ec82281..3ea958d9bfd 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fch-4j3w-44mf/GHSA-2fch-4j3w-44mf.json +++ b/advisories/unreviewed/2022/05/GHSA-2fch-4j3w-44mf/GHSA-2fch-4j3w-44mf.json @@ -7,12 +7,8 @@ "CVE-2020-26107" ], "details": "cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hgq-mm33-36mf/GHSA-2hgq-mm33-36mf.json b/advisories/unreviewed/2022/05/GHSA-2hgq-mm33-36mf/GHSA-2hgq-mm33-36mf.json index 434205c54e0..0afdf9a3c70 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hgq-mm33-36mf/GHSA-2hgq-mm33-36mf.json +++ b/advisories/unreviewed/2022/05/GHSA-2hgq-mm33-36mf/GHSA-2hgq-mm33-36mf.json @@ -7,12 +7,8 @@ "CVE-2020-0343" ], "details": "In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119672472", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2jp9-cpg6-cxq3/GHSA-2jp9-cpg6-cxq3.json b/advisories/unreviewed/2022/05/GHSA-2jp9-cpg6-cxq3/GHSA-2jp9-cpg6-cxq3.json index 1497a15094f..a34cfcad830 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jp9-cpg6-cxq3/GHSA-2jp9-cpg6-cxq3.json +++ b/advisories/unreviewed/2022/05/GHSA-2jp9-cpg6-cxq3/GHSA-2jp9-cpg6-cxq3.json @@ -7,12 +7,8 @@ "CVE-2020-0322" ], "details": "In apexd, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147002540", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jqh-5pvj-7mrg/GHSA-2jqh-5pvj-7mrg.json b/advisories/unreviewed/2022/05/GHSA-2jqh-5pvj-7mrg/GHSA-2jqh-5pvj-7mrg.json index 5ef9fb0d4d5..a03a7f48fb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jqh-5pvj-7mrg/GHSA-2jqh-5pvj-7mrg.json +++ b/advisories/unreviewed/2022/05/GHSA-2jqh-5pvj-7mrg/GHSA-2jqh-5pvj-7mrg.json @@ -7,12 +7,8 @@ "CVE-2019-16211" ], "details": "Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mx8-3jpw-29fq/GHSA-2mx8-3jpw-29fq.json b/advisories/unreviewed/2022/05/GHSA-2mx8-3jpw-29fq/GHSA-2mx8-3jpw-29fq.json index 82a01a91961..071df6ab394 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mx8-3jpw-29fq/GHSA-2mx8-3jpw-29fq.json +++ b/advisories/unreviewed/2022/05/GHSA-2mx8-3jpw-29fq/GHSA-2mx8-3jpw-29fq.json @@ -7,12 +7,8 @@ "CVE-2020-14180" ], "details": "Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are before version 4.12.0.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2pxh-883j-pqvh/GHSA-2pxh-883j-pqvh.json b/advisories/unreviewed/2022/05/GHSA-2pxh-883j-pqvh/GHSA-2pxh-883j-pqvh.json index decebdff21c..804e767f5e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pxh-883j-pqvh/GHSA-2pxh-883j-pqvh.json +++ b/advisories/unreviewed/2022/05/GHSA-2pxh-883j-pqvh/GHSA-2pxh-883j-pqvh.json @@ -7,12 +7,8 @@ "CVE-2020-26121" ], "details": "An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against \"page creation\" and the attacker should not be able to create it. This occurs because of a mishandled distinction between an upload restriction and a create restriction. An attacker cannot leverage this to overwrite anything, but can leverage this to force a wiki to have a page with a disallowed title.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qx5-mv7p-q62v/GHSA-2qx5-mv7p-q62v.json b/advisories/unreviewed/2022/05/GHSA-2qx5-mv7p-q62v/GHSA-2qx5-mv7p-q62v.json index 5f54fbc0de5..71e6526b596 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qx5-mv7p-q62v/GHSA-2qx5-mv7p-q62v.json +++ b/advisories/unreviewed/2022/05/GHSA-2qx5-mv7p-q62v/GHSA-2qx5-mv7p-q62v.json @@ -7,12 +7,8 @@ "CVE-2020-13338" ], "details": "An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2v24-jcvm-2w9j/GHSA-2v24-jcvm-2w9j.json b/advisories/unreviewed/2022/05/GHSA-2v24-jcvm-2w9j/GHSA-2v24-jcvm-2w9j.json index f534e08a6e5..540050db37c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v24-jcvm-2w9j/GHSA-2v24-jcvm-2w9j.json +++ b/advisories/unreviewed/2022/05/GHSA-2v24-jcvm-2w9j/GHSA-2v24-jcvm-2w9j.json @@ -7,12 +7,8 @@ "CVE-2020-0306" ], "details": "In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139666480", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v79-q5m2-86r3/GHSA-2v79-q5m2-86r3.json b/advisories/unreviewed/2022/05/GHSA-2v79-q5m2-86r3/GHSA-2v79-q5m2-86r3.json index 53c68fc2c9a..8b29c6c74ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v79-q5m2-86r3/GHSA-2v79-q5m2-86r3.json +++ b/advisories/unreviewed/2022/05/GHSA-2v79-q5m2-86r3/GHSA-2v79-q5m2-86r3.json @@ -7,12 +7,8 @@ "CVE-2020-0406" ], "details": "In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if another exploit allowed this to be triggered with different parameters, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137794014", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2vg7-q8hg-5f79/GHSA-2vg7-q8hg-5f79.json b/advisories/unreviewed/2022/05/GHSA-2vg7-q8hg-5f79/GHSA-2vg7-q8hg-5f79.json index 95c98a07316..719d8a15765 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vg7-q8hg-5f79/GHSA-2vg7-q8hg-5f79.json +++ b/advisories/unreviewed/2022/05/GHSA-2vg7-q8hg-5f79/GHSA-2vg7-q8hg-5f79.json @@ -7,12 +7,8 @@ "CVE-2020-8333" ], "details": "A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2wmr-35cq-3r7p/GHSA-2wmr-35cq-3r7p.json b/advisories/unreviewed/2022/05/GHSA-2wmr-35cq-3r7p/GHSA-2wmr-35cq-3r7p.json index cd67b7fd525..fec19303737 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wmr-35cq-3r7p/GHSA-2wmr-35cq-3r7p.json +++ b/advisories/unreviewed/2022/05/GHSA-2wmr-35cq-3r7p/GHSA-2wmr-35cq-3r7p.json @@ -7,12 +7,8 @@ "CVE-2020-15849" ], "details": "Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A malicious actor with access to an administrative account could abuse this vulnerability to recover sensitive data from the application's database, allowing for authorization bypass and taking over additional accounts by means of modifying password-reset tokens stored in the database. Remote command execution is also possible by leveraging this to abuse the Yii framework's bizRule functionality, allowing for arbitrary PHP code to be executed by the application. Remote command execution is also possible by using this together with a separate insecure file upload vulnerability (CVE-2020-15488).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2x28-2cqf-228j/GHSA-2x28-2cqf-228j.json b/advisories/unreviewed/2022/05/GHSA-2x28-2cqf-228j/GHSA-2x28-2cqf-228j.json index 9e6f4e5cca7..ed76a969767 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x28-2cqf-228j/GHSA-2x28-2cqf-228j.json +++ b/advisories/unreviewed/2022/05/GHSA-2x28-2cqf-228j/GHSA-2x28-2cqf-228j.json @@ -7,12 +7,8 @@ "CVE-2020-6562" ], "details": "Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32q2-gv5x-j2pp/GHSA-32q2-gv5x-j2pp.json b/advisories/unreviewed/2022/05/GHSA-32q2-gv5x-j2pp/GHSA-32q2-gv5x-j2pp.json index 1dcc3988fbe..39a7128e91b 100644 --- a/advisories/unreviewed/2022/05/GHSA-32q2-gv5x-j2pp/GHSA-32q2-gv5x-j2pp.json +++ b/advisories/unreviewed/2022/05/GHSA-32q2-gv5x-j2pp/GHSA-32q2-gv5x-j2pp.json @@ -7,12 +7,8 @@ "CVE-2020-13169" ], "details": "Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-35vv-8xvm-74jp/GHSA-35vv-8xvm-74jp.json b/advisories/unreviewed/2022/05/GHSA-35vv-8xvm-74jp/GHSA-35vv-8xvm-74jp.json index 67d446d149b..8d7ee3f733d 100644 --- a/advisories/unreviewed/2022/05/GHSA-35vv-8xvm-74jp/GHSA-35vv-8xvm-74jp.json +++ b/advisories/unreviewed/2022/05/GHSA-35vv-8xvm-74jp/GHSA-35vv-8xvm-74jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-378c-mgfx-9vr9/GHSA-378c-mgfx-9vr9.json b/advisories/unreviewed/2022/05/GHSA-378c-mgfx-9vr9/GHSA-378c-mgfx-9vr9.json index fc37d1b00ba..19d1aa148ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-378c-mgfx-9vr9/GHSA-378c-mgfx-9vr9.json +++ b/advisories/unreviewed/2022/05/GHSA-378c-mgfx-9vr9/GHSA-378c-mgfx-9vr9.json @@ -7,12 +7,8 @@ "CVE-2020-4611" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 184922.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37rp-8p2j-8qqr/GHSA-37rp-8p2j-8qqr.json b/advisories/unreviewed/2022/05/GHSA-37rp-8p2j-8qqr/GHSA-37rp-8p2j-8qqr.json index 664af2d9d1f..7c1b4f19321 100644 --- a/advisories/unreviewed/2022/05/GHSA-37rp-8p2j-8qqr/GHSA-37rp-8p2j-8qqr.json +++ b/advisories/unreviewed/2022/05/GHSA-37rp-8p2j-8qqr/GHSA-37rp-8p2j-8qqr.json @@ -7,12 +7,8 @@ "CVE-2020-6573" ], "details": "Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3876-gmcv-479m/GHSA-3876-gmcv-479m.json b/advisories/unreviewed/2022/05/GHSA-3876-gmcv-479m/GHSA-3876-gmcv-479m.json index ec8a75ac6d9..567e6f88765 100644 --- a/advisories/unreviewed/2022/05/GHSA-3876-gmcv-479m/GHSA-3876-gmcv-479m.json +++ b/advisories/unreviewed/2022/05/GHSA-3876-gmcv-479m/GHSA-3876-gmcv-479m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3c6h-653r-qh3f/GHSA-3c6h-653r-qh3f.json b/advisories/unreviewed/2022/05/GHSA-3c6h-653r-qh3f/GHSA-3c6h-653r-qh3f.json index 1fe458a58d3..d30ee7adefc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c6h-653r-qh3f/GHSA-3c6h-653r-qh3f.json +++ b/advisories/unreviewed/2022/05/GHSA-3c6h-653r-qh3f/GHSA-3c6h-653r-qh3f.json @@ -7,12 +7,8 @@ "CVE-2020-4622" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 184983.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3c96-8q7p-6jr2/GHSA-3c96-8q7p-6jr2.json b/advisories/unreviewed/2022/05/GHSA-3c96-8q7p-6jr2/GHSA-3c96-8q7p-6jr2.json index 0549db18600..8ef3a210953 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c96-8q7p-6jr2/GHSA-3c96-8q7p-6jr2.json +++ b/advisories/unreviewed/2022/05/GHSA-3c96-8q7p-6jr2/GHSA-3c96-8q7p-6jr2.json @@ -7,12 +7,8 @@ "CVE-2020-4619" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cc3-r774-p8q6/GHSA-3cc3-r774-p8q6.json b/advisories/unreviewed/2022/05/GHSA-3cc3-r774-p8q6/GHSA-3cc3-r774-p8q6.json index b7087f14c8e..0a62e927674 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cc3-r774-p8q6/GHSA-3cc3-r774-p8q6.json +++ b/advisories/unreviewed/2022/05/GHSA-3cc3-r774-p8q6/GHSA-3cc3-r774-p8q6.json @@ -7,12 +7,8 @@ "CVE-2020-25147" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. This can occur via username[0] to the default URI, because of includes/authenticate.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3fgp-p3x8-6r59/GHSA-3fgp-p3x8-6r59.json b/advisories/unreviewed/2022/05/GHSA-3fgp-p3x8-6r59/GHSA-3fgp-p3x8-6r59.json index 679037d26cb..2e91c266d72 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fgp-p3x8-6r59/GHSA-3fgp-p3x8-6r59.json +++ b/advisories/unreviewed/2022/05/GHSA-3fgp-p3x8-6r59/GHSA-3fgp-p3x8-6r59.json @@ -7,12 +7,8 @@ "CVE-2020-8247" ], "details": "Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to escalation of privileges on the management interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3g45-cx6m-2pfc/GHSA-3g45-cx6m-2pfc.json b/advisories/unreviewed/2022/05/GHSA-3g45-cx6m-2pfc/GHSA-3g45-cx6m-2pfc.json index 7a4481eed6e..38db9193423 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g45-cx6m-2pfc/GHSA-3g45-cx6m-2pfc.json +++ b/advisories/unreviewed/2022/05/GHSA-3g45-cx6m-2pfc/GHSA-3g45-cx6m-2pfc.json @@ -7,12 +7,8 @@ "CVE-2020-25203" ], "details": "The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent with the action set to android.intent.action.VIEW, any other application is able to load any website/web content into the application's context, which is shown as a full-screen overlay to the user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3j3w-w8v5-3rch/GHSA-3j3w-w8v5-3rch.json b/advisories/unreviewed/2022/05/GHSA-3j3w-w8v5-3rch/GHSA-3j3w-w8v5-3rch.json index 2b6e51d41b5..bb25c085a07 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j3w-w8v5-3rch/GHSA-3j3w-w8v5-3rch.json +++ b/advisories/unreviewed/2022/05/GHSA-3j3w-w8v5-3rch/GHSA-3j3w-w8v5-3rch.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3jq7-m4v4-gfrf/GHSA-3jq7-m4v4-gfrf.json b/advisories/unreviewed/2022/05/GHSA-3jq7-m4v4-gfrf/GHSA-3jq7-m4v4-gfrf.json index de6feba17cc..1f4633bd787 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jq7-m4v4-gfrf/GHSA-3jq7-m4v4-gfrf.json +++ b/advisories/unreviewed/2022/05/GHSA-3jq7-m4v4-gfrf/GHSA-3jq7-m4v4-gfrf.json @@ -7,12 +7,8 @@ "CVE-2020-0304" ], "details": "In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645695", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mxc-8p66-5xwj/GHSA-3mxc-8p66-5xwj.json b/advisories/unreviewed/2022/05/GHSA-3mxc-8p66-5xwj/GHSA-3mxc-8p66-5xwj.json index 4e5b16f4d28..bf6253c6143 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mxc-8p66-5xwj/GHSA-3mxc-8p66-5xwj.json +++ b/advisories/unreviewed/2022/05/GHSA-3mxc-8p66-5xwj/GHSA-3mxc-8p66-5xwj.json @@ -7,12 +7,8 @@ "CVE-2020-0287" ], "details": "In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-141860394", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3p6f-5r42-cg3p/GHSA-3p6f-5r42-cg3p.json b/advisories/unreviewed/2022/05/GHSA-3p6f-5r42-cg3p/GHSA-3p6f-5r42-cg3p.json index 4eccf4e8d2c..3c7965bb050 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p6f-5r42-cg3p/GHSA-3p6f-5r42-cg3p.json +++ b/advisories/unreviewed/2022/05/GHSA-3p6f-5r42-cg3p/GHSA-3p6f-5r42-cg3p.json @@ -7,12 +7,8 @@ "CVE-2020-14031" ], "details": "An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be used to delete all/most files in a folder. Because the product usually runs as NT AUTHORITY\\SYSTEM, the only files that will not be deleted are those currently being run by the system and/or files that have special security attributes (e.g., Windows Defender files).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3pm8-h8w8-chv6/GHSA-3pm8-h8w8-chv6.json b/advisories/unreviewed/2022/05/GHSA-3pm8-h8w8-chv6/GHSA-3pm8-h8w8-chv6.json index deb72b38d09..5d3b2a46e81 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pm8-h8w8-chv6/GHSA-3pm8-h8w8-chv6.json +++ b/advisories/unreviewed/2022/05/GHSA-3pm8-h8w8-chv6/GHSA-3pm8-h8w8-chv6.json @@ -7,12 +7,8 @@ "CVE-2020-5628" ], "details": "UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, if the access destination is a malicious website, the user may fall victim to the social engineering attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3rpp-4v39-5h22/GHSA-3rpp-4v39-5h22.json b/advisories/unreviewed/2022/05/GHSA-3rpp-4v39-5h22/GHSA-3rpp-4v39-5h22.json index 10a71503242..9fa6076f4f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rpp-4v39-5h22/GHSA-3rpp-4v39-5h22.json +++ b/advisories/unreviewed/2022/05/GHSA-3rpp-4v39-5h22/GHSA-3rpp-4v39-5h22.json @@ -7,12 +7,8 @@ "CVE-2020-6552" ], "details": "Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rxc-xqq7-hm3h/GHSA-3rxc-xqq7-hm3h.json b/advisories/unreviewed/2022/05/GHSA-3rxc-xqq7-hm3h/GHSA-3rxc-xqq7-hm3h.json index 69fafc3c4a9..f1c2a55dd74 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rxc-xqq7-hm3h/GHSA-3rxc-xqq7-hm3h.json +++ b/advisories/unreviewed/2022/05/GHSA-3rxc-xqq7-hm3h/GHSA-3rxc-xqq7-hm3h.json @@ -7,12 +7,8 @@ "CVE-2020-3130" ], "details": "A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web management interface. A successful exploit could allow the attacker to overwrite files on the underlying filesystem of an affected system. Valid administrator credentials are required to access the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vm4-w5qq-w432/GHSA-3vm4-w5qq-w432.json b/advisories/unreviewed/2022/05/GHSA-3vm4-w5qq-w432/GHSA-3vm4-w5qq-w432.json index f8108342205..306d91a1901 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vm4-w5qq-w432/GHSA-3vm4-w5qq-w432.json +++ b/advisories/unreviewed/2022/05/GHSA-3vm4-w5qq-w432/GHSA-3vm4-w5qq-w432.json @@ -7,12 +7,8 @@ "CVE-2020-26110" ], "details": "cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3wr3-v78q-x45g/GHSA-3wr3-v78q-x45g.json b/advisories/unreviewed/2022/05/GHSA-3wr3-v78q-x45g/GHSA-3wr3-v78q-x45g.json index 79dd85a69e4..864161430d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wr3-v78q-x45g/GHSA-3wr3-v78q-x45g.json +++ b/advisories/unreviewed/2022/05/GHSA-3wr3-v78q-x45g/GHSA-3wr3-v78q-x45g.json @@ -7,12 +7,8 @@ "CVE-2019-18990" ], "details": "A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wwc-8979-r93x/GHSA-3wwc-8979-r93x.json b/advisories/unreviewed/2022/05/GHSA-3wwc-8979-r93x/GHSA-3wwc-8979-r93x.json index a23a23ddfc8..f66c92bf863 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wwc-8979-r93x/GHSA-3wwc-8979-r93x.json +++ b/advisories/unreviewed/2022/05/GHSA-3wwc-8979-r93x/GHSA-3wwc-8979-r93x.json @@ -7,12 +7,8 @@ "CVE-2020-22842" ], "details": "CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3xwq-264p-f7jp/GHSA-3xwq-264p-f7jp.json b/advisories/unreviewed/2022/05/GHSA-3xwq-264p-f7jp/GHSA-3xwq-264p-f7jp.json index 094106c70d6..df8350baa33 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xwq-264p-f7jp/GHSA-3xwq-264p-f7jp.json +++ b/advisories/unreviewed/2022/05/GHSA-3xwq-264p-f7jp/GHSA-3xwq-264p-f7jp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4239-cmjf-x875/GHSA-4239-cmjf-x875.json b/advisories/unreviewed/2022/05/GHSA-4239-cmjf-x875/GHSA-4239-cmjf-x875.json index 223ae4ef989..09593e8d968 100644 --- a/advisories/unreviewed/2022/05/GHSA-4239-cmjf-x875/GHSA-4239-cmjf-x875.json +++ b/advisories/unreviewed/2022/05/GHSA-4239-cmjf-x875/GHSA-4239-cmjf-x875.json @@ -7,12 +7,8 @@ "CVE-2020-25490" ], "details": "Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-443c-w3hv-6grh/GHSA-443c-w3hv-6grh.json b/advisories/unreviewed/2022/05/GHSA-443c-w3hv-6grh/GHSA-443c-w3hv-6grh.json index a5125fcfbd3..bc9656abf6e 100644 --- a/advisories/unreviewed/2022/05/GHSA-443c-w3hv-6grh/GHSA-443c-w3hv-6grh.json +++ b/advisories/unreviewed/2022/05/GHSA-443c-w3hv-6grh/GHSA-443c-w3hv-6grh.json @@ -7,12 +7,8 @@ "CVE-2020-26099" ], "details": "cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-44fm-5g3x-mp3f/GHSA-44fm-5g3x-mp3f.json b/advisories/unreviewed/2022/05/GHSA-44fm-5g3x-mp3f/GHSA-44fm-5g3x-mp3f.json index aadacc645ab..79a4d3c28e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-44fm-5g3x-mp3f/GHSA-44fm-5g3x-mp3f.json +++ b/advisories/unreviewed/2022/05/GHSA-44fm-5g3x-mp3f/GHSA-44fm-5g3x-mp3f.json @@ -7,12 +7,8 @@ "CVE-2020-21526" ], "details": "An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-462g-gcmx-hmf4/GHSA-462g-gcmx-hmf4.json b/advisories/unreviewed/2022/05/GHSA-462g-gcmx-hmf4/GHSA-462g-gcmx-hmf4.json index 9037a200475..33605c22e5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-462g-gcmx-hmf4/GHSA-462g-gcmx-hmf4.json +++ b/advisories/unreviewed/2022/05/GHSA-462g-gcmx-hmf4/GHSA-462g-gcmx-hmf4.json @@ -7,12 +7,8 @@ "CVE-2020-0365" ], "details": "In netd, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137346580", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46jg-5jjh-crxw/GHSA-46jg-5jjh-crxw.json b/advisories/unreviewed/2022/05/GHSA-46jg-5jjh-crxw/GHSA-46jg-5jjh-crxw.json index 795bea49296..45c6c8d3d7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-46jg-5jjh-crxw/GHSA-46jg-5jjh-crxw.json +++ b/advisories/unreviewed/2022/05/GHSA-46jg-5jjh-crxw/GHSA-46jg-5jjh-crxw.json @@ -7,12 +7,8 @@ "CVE-2020-0389" ], "details": "In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-156959408", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-485q-327p-g6wf/GHSA-485q-327p-g6wf.json b/advisories/unreviewed/2022/05/GHSA-485q-327p-g6wf/GHSA-485q-327p-g6wf.json index 7533fc3f240..607f55b1cdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-485q-327p-g6wf/GHSA-485q-327p-g6wf.json +++ b/advisories/unreviewed/2022/05/GHSA-485q-327p-g6wf/GHSA-485q-327p-g6wf.json @@ -7,12 +7,8 @@ "CVE-2020-26109" ], "details": "cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-49wh-pf3r-rqvx/GHSA-49wh-pf3r-rqvx.json b/advisories/unreviewed/2022/05/GHSA-49wh-pf3r-rqvx/GHSA-49wh-pf3r-rqvx.json index 7eb30d713b3..1ed3c9dcc0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-49wh-pf3r-rqvx/GHSA-49wh-pf3r-rqvx.json +++ b/advisories/unreviewed/2022/05/GHSA-49wh-pf3r-rqvx/GHSA-49wh-pf3r-rqvx.json @@ -7,12 +7,8 @@ "CVE-2020-5786" ], "details": "Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4c4x-3mvr-64jv/GHSA-4c4x-3mvr-64jv.json b/advisories/unreviewed/2022/05/GHSA-4c4x-3mvr-64jv/GHSA-4c4x-3mvr-64jv.json index f253f243081..ff4ebf39c46 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c4x-3mvr-64jv/GHSA-4c4x-3mvr-64jv.json +++ b/advisories/unreviewed/2022/05/GHSA-4c4x-3mvr-64jv/GHSA-4c4x-3mvr-64jv.json @@ -7,12 +7,8 @@ "CVE-2018-5354" ], "details": "The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gh4-x27r-cgrr/GHSA-4gh4-x27r-cgrr.json b/advisories/unreviewed/2022/05/GHSA-4gh4-x27r-cgrr/GHSA-4gh4-x27r-cgrr.json index 3be43cb0d01..14690f6165c 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gh4-x27r-cgrr/GHSA-4gh4-x27r-cgrr.json +++ b/advisories/unreviewed/2022/05/GHSA-4gh4-x27r-cgrr/GHSA-4gh4-x27r-cgrr.json @@ -7,12 +7,8 @@ "CVE-2020-0334" ], "details": "In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147995915", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jqm-rrqp-wmfr/GHSA-4jqm-rrqp-wmfr.json b/advisories/unreviewed/2022/05/GHSA-4jqm-rrqp-wmfr/GHSA-4jqm-rrqp-wmfr.json index d468c1458ea..5f8e16b93b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jqm-rrqp-wmfr/GHSA-4jqm-rrqp-wmfr.json +++ b/advisories/unreviewed/2022/05/GHSA-4jqm-rrqp-wmfr/GHSA-4jqm-rrqp-wmfr.json @@ -7,12 +7,8 @@ "CVE-2020-0330" ], "details": "In iorap, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege and code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150331085", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4p3x-6hj6-j849/GHSA-4p3x-6hj6-j849.json b/advisories/unreviewed/2022/05/GHSA-4p3x-6hj6-j849/GHSA-4p3x-6hj6-j849.json index 774cce6299a..706f3317a54 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p3x-6hj6-j849/GHSA-4p3x-6hj6-j849.json +++ b/advisories/unreviewed/2022/05/GHSA-4p3x-6hj6-j849/GHSA-4p3x-6hj6-j849.json @@ -7,12 +7,8 @@ "CVE-2020-5632" ], "details": "InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1, Host type SiteShell for Apache Windows V1.4, V1.5, and V1.6, and Host type SiteShell for Apache Windows prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1) allow authenticated attackers to bypass access restriction and to execute arbitrary code with an elevated privilege via a specially crafted executable files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p7h-q24r-h439/GHSA-4p7h-q24r-h439.json b/advisories/unreviewed/2022/05/GHSA-4p7h-q24r-h439/GHSA-4p7h-q24r-h439.json index d4dd0c05d80..569232ec3db 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p7h-q24r-h439/GHSA-4p7h-q24r-h439.json +++ b/advisories/unreviewed/2022/05/GHSA-4p7h-q24r-h439/GHSA-4p7h-q24r-h439.json @@ -7,12 +7,8 @@ "CVE-2019-18989" ], "details": "A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pqr-cgc7-84h8/GHSA-4pqr-cgc7-84h8.json b/advisories/unreviewed/2022/05/GHSA-4pqr-cgc7-84h8/GHSA-4pqr-cgc7-84h8.json index 08229ad60ce..83aaa0c19ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pqr-cgc7-84h8/GHSA-4pqr-cgc7-84h8.json +++ b/advisories/unreviewed/2022/05/GHSA-4pqr-cgc7-84h8/GHSA-4pqr-cgc7-84h8.json @@ -7,12 +7,8 @@ "CVE-2020-8348" ], "details": "A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's current browser session if a crafted url is visited, possibly through phishing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4pxr-jf5c-q3x5/GHSA-4pxr-jf5c-q3x5.json b/advisories/unreviewed/2022/05/GHSA-4pxr-jf5c-q3x5/GHSA-4pxr-jf5c-q3x5.json index 2633873e8e2..5d11da42a59 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pxr-jf5c-q3x5/GHSA-4pxr-jf5c-q3x5.json +++ b/advisories/unreviewed/2022/05/GHSA-4pxr-jf5c-q3x5/GHSA-4pxr-jf5c-q3x5.json @@ -7,12 +7,8 @@ "CVE-2020-0310" ], "details": "In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153356468", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vm4-96f5-cw5w/GHSA-4vm4-96f5-cw5w.json b/advisories/unreviewed/2022/05/GHSA-4vm4-96f5-cw5w/GHSA-4vm4-96f5-cw5w.json index da6ae4df2ef..fb9ffc713a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vm4-96f5-cw5w/GHSA-4vm4-96f5-cw5w.json +++ b/advisories/unreviewed/2022/05/GHSA-4vm4-96f5-cw5w/GHSA-4vm4-96f5-cw5w.json @@ -7,12 +7,8 @@ "CVE-2020-4616" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 could disclose sensitive username information to an attacker using a specially crafted HTTP request. IBM X-Force ID: 184929.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4wjm-q2fq-94vj/GHSA-4wjm-q2fq-94vj.json b/advisories/unreviewed/2022/05/GHSA-4wjm-q2fq-94vj/GHSA-4wjm-q2fq-94vj.json index 7739d291f98..d09f29e3384 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wjm-q2fq-94vj/GHSA-4wjm-q2fq-94vj.json +++ b/advisories/unreviewed/2022/05/GHSA-4wjm-q2fq-94vj/GHSA-4wjm-q2fq-94vj.json @@ -7,12 +7,8 @@ "CVE-2019-16000" ], "details": "A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerability is due to insufficient verification of the Windows Installer. An attacker could exploit this vulnerability by placing a file in a specific location in the Windows file system. A successful exploit could allow the attacker to bypass configured policy and install unapproved applications.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x9v-x49p-h42h/GHSA-4x9v-x49p-h42h.json b/advisories/unreviewed/2022/05/GHSA-4x9v-x49p-h42h/GHSA-4x9v-x49p-h42h.json index d239e408cb8..a2479a8443f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x9v-x49p-h42h/GHSA-4x9v-x49p-h42h.json +++ b/advisories/unreviewed/2022/05/GHSA-4x9v-x49p-h42h/GHSA-4x9v-x49p-h42h.json @@ -7,12 +7,8 @@ "CVE-2020-25727" ], "details": "The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4xrr-ph69-m596/GHSA-4xrr-ph69-m596.json b/advisories/unreviewed/2022/05/GHSA-4xrr-ph69-m596/GHSA-4xrr-ph69-m596.json index 55c29b51206..7865043dd05 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xrr-ph69-m596/GHSA-4xrr-ph69-m596.json +++ b/advisories/unreviewed/2022/05/GHSA-4xrr-ph69-m596/GHSA-4xrr-ph69-m596.json @@ -7,12 +7,8 @@ "CVE-2019-19393" ], "details": "The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts) as the content is always displayed after and before login. Persistent XSS allows an attacker to modify displayed content or to change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or a hijacked session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4xx4-xqw7-4f8r/GHSA-4xx4-xqw7-4f8r.json b/advisories/unreviewed/2022/05/GHSA-4xx4-xqw7-4f8r/GHSA-4xx4-xqw7-4f8r.json index 14527e5db20..664c8a0a0eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xx4-xqw7-4f8r/GHSA-4xx4-xqw7-4f8r.json +++ b/advisories/unreviewed/2022/05/GHSA-4xx4-xqw7-4f8r/GHSA-4xx4-xqw7-4f8r.json @@ -7,12 +7,8 @@ "CVE-2020-6545" ], "details": "Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-529g-gxp3-7xg6/GHSA-529g-gxp3-7xg6.json b/advisories/unreviewed/2022/05/GHSA-529g-gxp3-7xg6/GHSA-529g-gxp3-7xg6.json index df9e0ad1393..5019e75b196 100644 --- a/advisories/unreviewed/2022/05/GHSA-529g-gxp3-7xg6/GHSA-529g-gxp3-7xg6.json +++ b/advisories/unreviewed/2022/05/GHSA-529g-gxp3-7xg6/GHSA-529g-gxp3-7xg6.json @@ -7,12 +7,8 @@ "CVE-2020-23837" ], "details": "A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5355-m3jh-2v57/GHSA-5355-m3jh-2v57.json b/advisories/unreviewed/2022/05/GHSA-5355-m3jh-2v57/GHSA-5355-m3jh-2v57.json index 491986e7eea..f126adb566a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5355-m3jh-2v57/GHSA-5355-m3jh-2v57.json +++ b/advisories/unreviewed/2022/05/GHSA-5355-m3jh-2v57/GHSA-5355-m3jh-2v57.json @@ -7,12 +7,8 @@ "CVE-2020-22453" ], "details": "Untis WebUntis before 2020.9.6 allows XSS in multiple functions that store information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53ph-mcf9-r8mc/GHSA-53ph-mcf9-r8mc.json b/advisories/unreviewed/2022/05/GHSA-53ph-mcf9-r8mc/GHSA-53ph-mcf9-r8mc.json index e3e213ea696..ac0e2781ca1 100644 --- a/advisories/unreviewed/2022/05/GHSA-53ph-mcf9-r8mc/GHSA-53ph-mcf9-r8mc.json +++ b/advisories/unreviewed/2022/05/GHSA-53ph-mcf9-r8mc/GHSA-53ph-mcf9-r8mc.json @@ -7,12 +7,8 @@ "CVE-2020-14027" ], "details": "An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The database connection strings accept custom unsafe arguments, such as ENABLE_LOCAL_INFILE, that can be leveraged by attackers to enable MySQL Load Data Local (rogue MySQL server) attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53wh-qw7f-vmq3/GHSA-53wh-qw7f-vmq3.json b/advisories/unreviewed/2022/05/GHSA-53wh-qw7f-vmq3/GHSA-53wh-qw7f-vmq3.json index d2a7e16f98e..5403fbdebc7 100644 --- a/advisories/unreviewed/2022/05/GHSA-53wh-qw7f-vmq3/GHSA-53wh-qw7f-vmq3.json +++ b/advisories/unreviewed/2022/05/GHSA-53wh-qw7f-vmq3/GHSA-53wh-qw7f-vmq3.json @@ -7,12 +7,8 @@ "CVE-2020-17365" ], "details": "Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-55qc-4wg3-f2p8/GHSA-55qc-4wg3-f2p8.json b/advisories/unreviewed/2022/05/GHSA-55qc-4wg3-f2p8/GHSA-55qc-4wg3-f2p8.json index 2eccf21b46c..32769516217 100644 --- a/advisories/unreviewed/2022/05/GHSA-55qc-4wg3-f2p8/GHSA-55qc-4wg3-f2p8.json +++ b/advisories/unreviewed/2022/05/GHSA-55qc-4wg3-f2p8/GHSA-55qc-4wg3-f2p8.json @@ -7,12 +7,8 @@ "CVE-2020-14025" ], "details": "Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as installing new modules or changing a password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-564r-7p67-986w/GHSA-564r-7p67-986w.json b/advisories/unreviewed/2022/05/GHSA-564r-7p67-986w/GHSA-564r-7p67-986w.json index 6f457f43fc1..5f1b461bb73 100644 --- a/advisories/unreviewed/2022/05/GHSA-564r-7p67-986w/GHSA-564r-7p67-986w.json +++ b/advisories/unreviewed/2022/05/GHSA-564r-7p67-986w/GHSA-564r-7p67-986w.json @@ -7,12 +7,8 @@ "CVE-2020-3977" ], "details": "VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-565v-439w-r6r9/GHSA-565v-439w-r6r9.json b/advisories/unreviewed/2022/05/GHSA-565v-439w-r6r9/GHSA-565v-439w-r6r9.json index 5975ed323ab..fccbed05250 100644 --- a/advisories/unreviewed/2022/05/GHSA-565v-439w-r6r9/GHSA-565v-439w-r6r9.json +++ b/advisories/unreviewed/2022/05/GHSA-565v-439w-r6r9/GHSA-565v-439w-r6r9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-569r-pvqr-c78j/GHSA-569r-pvqr-c78j.json b/advisories/unreviewed/2022/05/GHSA-569r-pvqr-c78j/GHSA-569r-pvqr-c78j.json index 905262c9084..46c72b324e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-569r-pvqr-c78j/GHSA-569r-pvqr-c78j.json +++ b/advisories/unreviewed/2022/05/GHSA-569r-pvqr-c78j/GHSA-569r-pvqr-c78j.json @@ -7,12 +7,8 @@ "CVE-2020-25735" ], "details": "webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-56rg-qq2g-389g/GHSA-56rg-qq2g-389g.json b/advisories/unreviewed/2022/05/GHSA-56rg-qq2g-389g/GHSA-56rg-qq2g-389g.json index 2f0bd0b0fcb..2878146094a 100644 --- a/advisories/unreviewed/2022/05/GHSA-56rg-qq2g-389g/GHSA-56rg-qq2g-389g.json +++ b/advisories/unreviewed/2022/05/GHSA-56rg-qq2g-389g/GHSA-56rg-qq2g-389g.json @@ -7,12 +7,8 @@ "CVE-2020-0430" ], "details": "In skb_headlen of /include/linux/skbuff.h, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-153881554", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-57m9-xcr9-qv37/GHSA-57m9-xcr9-qv37.json b/advisories/unreviewed/2022/05/GHSA-57m9-xcr9-qv37/GHSA-57m9-xcr9-qv37.json index cd2f251fbde..74863d553bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-57m9-xcr9-qv37/GHSA-57m9-xcr9-qv37.json +++ b/advisories/unreviewed/2022/05/GHSA-57m9-xcr9-qv37/GHSA-57m9-xcr9-qv37.json @@ -7,12 +7,8 @@ "CVE-2019-1947" ], "details": "A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of email messages that contain large attachments. An attacker could exploit this vulnerability by sending a malicious email message through the targeted device. A successful exploit could allow the attacker to cause a permanent DoS condition due to high CPU utilization. This vulnerability may require manual intervention to recover the ESA.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5883-cq6h-c598/GHSA-5883-cq6h-c598.json b/advisories/unreviewed/2022/05/GHSA-5883-cq6h-c598/GHSA-5883-cq6h-c598.json index 23bd949b338..e1e342eebd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5883-cq6h-c598/GHSA-5883-cq6h-c598.json +++ b/advisories/unreviewed/2022/05/GHSA-5883-cq6h-c598/GHSA-5883-cq6h-c598.json @@ -7,12 +7,8 @@ "CVE-2020-15965" ], "details": "Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58h4-fw5x-m6gj/GHSA-58h4-fw5x-m6gj.json b/advisories/unreviewed/2022/05/GHSA-58h4-fw5x-m6gj/GHSA-58h4-fw5x-m6gj.json index ba0f19f5860..14c04ccf930 100644 --- a/advisories/unreviewed/2022/05/GHSA-58h4-fw5x-m6gj/GHSA-58h4-fw5x-m6gj.json +++ b/advisories/unreviewed/2022/05/GHSA-58h4-fw5x-m6gj/GHSA-58h4-fw5x-m6gj.json @@ -7,12 +7,8 @@ "CVE-2018-6449" ], "details": "Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58jg-c8v2-jcpf/GHSA-58jg-c8v2-jcpf.json b/advisories/unreviewed/2022/05/GHSA-58jg-c8v2-jcpf/GHSA-58jg-c8v2-jcpf.json index 9c470e856c4..386794b41d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-58jg-c8v2-jcpf/GHSA-58jg-c8v2-jcpf.json +++ b/advisories/unreviewed/2022/05/GHSA-58jg-c8v2-jcpf/GHSA-58jg-c8v2-jcpf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59cc-3745-q8c3/GHSA-59cc-3745-q8c3.json b/advisories/unreviewed/2022/05/GHSA-59cc-3745-q8c3/GHSA-59cc-3745-q8c3.json index b7fb9784f0f..f95451b0765 100644 --- a/advisories/unreviewed/2022/05/GHSA-59cc-3745-q8c3/GHSA-59cc-3745-q8c3.json +++ b/advisories/unreviewed/2022/05/GHSA-59cc-3745-q8c3/GHSA-59cc-3745-q8c3.json @@ -7,12 +7,8 @@ "CVE-2020-3513" ], "details": "Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed could allow an authenticated, local attacker with high privileges to execute persistent code at bootup and break the chain of trust. These vulnerabilities are due to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set. An attacker could exploit these vulnerabilities by copying a specific file to the local file system of an affected device and defining specific ROMMON variables. A successful exploit could allow the attacker to run arbitrary code on the underlying operating system (OS) with root privileges. To exploit these vulnerabilities, an attacker would need to have access to the root shell on the device or have physical access to the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-59g5-964j-wr4j/GHSA-59g5-964j-wr4j.json b/advisories/unreviewed/2022/05/GHSA-59g5-964j-wr4j/GHSA-59g5-964j-wr4j.json index 331678d4838..643b8e66043 100644 --- a/advisories/unreviewed/2022/05/GHSA-59g5-964j-wr4j/GHSA-59g5-964j-wr4j.json +++ b/advisories/unreviewed/2022/05/GHSA-59g5-964j-wr4j/GHSA-59g5-964j-wr4j.json @@ -7,12 +7,8 @@ "CVE-2020-26105" ], "details": "In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5c5v-3qwm-2cr8/GHSA-5c5v-3qwm-2cr8.json b/advisories/unreviewed/2022/05/GHSA-5c5v-3qwm-2cr8/GHSA-5c5v-3qwm-2cr8.json index 90e032d9cbb..059ae1a6893 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c5v-3qwm-2cr8/GHSA-5c5v-3qwm-2cr8.json +++ b/advisories/unreviewed/2022/05/GHSA-5c5v-3qwm-2cr8/GHSA-5c5v-3qwm-2cr8.json @@ -7,12 +7,8 @@ "CVE-2020-12840" ], "details": "ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fc5-pc3j-x9pm/GHSA-5fc5-pc3j-x9pm.json b/advisories/unreviewed/2022/05/GHSA-5fc5-pc3j-x9pm/GHSA-5fc5-pc3j-x9pm.json index 6b542abca5e..64b2199df42 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fc5-pc3j-x9pm/GHSA-5fc5-pc3j-x9pm.json +++ b/advisories/unreviewed/2022/05/GHSA-5fc5-pc3j-x9pm/GHSA-5fc5-pc3j-x9pm.json @@ -7,12 +7,8 @@ "CVE-2020-25140" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur in pages/contacts.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5fpr-fwpx-j26r/GHSA-5fpr-fwpx-j26r.json b/advisories/unreviewed/2022/05/GHSA-5fpr-fwpx-j26r/GHSA-5fpr-fwpx-j26r.json index ba40ef3cfaf..784c18da514 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fpr-fwpx-j26r/GHSA-5fpr-fwpx-j26r.json +++ b/advisories/unreviewed/2022/05/GHSA-5fpr-fwpx-j26r/GHSA-5fpr-fwpx-j26r.json @@ -7,12 +7,8 @@ "CVE-2020-12127" ], "details": "An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5fwv-f3m5-wrpg/GHSA-5fwv-f3m5-wrpg.json b/advisories/unreviewed/2022/05/GHSA-5fwv-f3m5-wrpg/GHSA-5fwv-f3m5-wrpg.json index e89b742d970..370f45818bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-5fwv-f3m5-wrpg/GHSA-5fwv-f3m5-wrpg.json +++ b/advisories/unreviewed/2022/05/GHSA-5fwv-f3m5-wrpg/GHSA-5fwv-f3m5-wrpg.json @@ -7,12 +7,8 @@ "CVE-2020-12125" ], "details": "A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary machine instructions as root without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5gc2-xc6c-wh7r/GHSA-5gc2-xc6c-wh7r.json b/advisories/unreviewed/2022/05/GHSA-5gc2-xc6c-wh7r/GHSA-5gc2-xc6c-wh7r.json index 7e1f86ce6ca..26a5bc02374 100644 --- a/advisories/unreviewed/2022/05/GHSA-5gc2-xc6c-wh7r/GHSA-5gc2-xc6c-wh7r.json +++ b/advisories/unreviewed/2022/05/GHSA-5gc2-xc6c-wh7r/GHSA-5gc2-xc6c-wh7r.json @@ -7,12 +7,8 @@ "CVE-2020-24560" ], "details": "An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper server certificate verification in the communication with the update server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5jc7-qjrp-83hw/GHSA-5jc7-qjrp-83hw.json b/advisories/unreviewed/2022/05/GHSA-5jc7-qjrp-83hw/GHSA-5jc7-qjrp-83hw.json index ae2c55f3f51..f9c82ca3691 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jc7-qjrp-83hw/GHSA-5jc7-qjrp-83hw.json +++ b/advisories/unreviewed/2022/05/GHSA-5jc7-qjrp-83hw/GHSA-5jc7-qjrp-83hw.json @@ -7,12 +7,8 @@ "CVE-2020-23446" ], "details": "Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5jp3-j2j9-56cp/GHSA-5jp3-j2j9-56cp.json b/advisories/unreviewed/2022/05/GHSA-5jp3-j2j9-56cp/GHSA-5jp3-j2j9-56cp.json index caddfc14aea..b455e093236 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jp3-j2j9-56cp/GHSA-5jp3-j2j9-56cp.json +++ b/advisories/unreviewed/2022/05/GHSA-5jp3-j2j9-56cp/GHSA-5jp3-j2j9-56cp.json @@ -7,12 +7,8 @@ "CVE-2020-26100" ], "details": "chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vrj-pf9q-p8m9/GHSA-5vrj-pf9q-p8m9.json b/advisories/unreviewed/2022/05/GHSA-5vrj-pf9q-p8m9/GHSA-5vrj-pf9q-p8m9.json index edba01ac979..a33c18d4638 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vrj-pf9q-p8m9/GHSA-5vrj-pf9q-p8m9.json +++ b/advisories/unreviewed/2022/05/GHSA-5vrj-pf9q-p8m9/GHSA-5vrj-pf9q-p8m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5w6v-hvf4-9m3p/GHSA-5w6v-hvf4-9m3p.json b/advisories/unreviewed/2022/05/GHSA-5w6v-hvf4-9m3p/GHSA-5w6v-hvf4-9m3p.json index c220306d4ca..166bafe7bd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w6v-hvf4-9m3p/GHSA-5w6v-hvf4-9m3p.json +++ b/advisories/unreviewed/2022/05/GHSA-5w6v-hvf4-9m3p/GHSA-5w6v-hvf4-9m3p.json @@ -7,12 +7,8 @@ "CVE-2020-25734" ], "details": "webTareas through 2.1 allows files/Default/ Directory Listing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5wcx-gjhc-645f/GHSA-5wcx-gjhc-645f.json b/advisories/unreviewed/2022/05/GHSA-5wcx-gjhc-645f/GHSA-5wcx-gjhc-645f.json index 81a71a91029..ba2a32a2d83 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wcx-gjhc-645f/GHSA-5wcx-gjhc-645f.json +++ b/advisories/unreviewed/2022/05/GHSA-5wcx-gjhc-645f/GHSA-5wcx-gjhc-645f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wpp-rjjg-p4xh/GHSA-5wpp-rjjg-p4xh.json b/advisories/unreviewed/2022/05/GHSA-5wpp-rjjg-p4xh/GHSA-5wpp-rjjg-p4xh.json index c4c3d1f07bf..1ef1fc61ac4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wpp-rjjg-p4xh/GHSA-5wpp-rjjg-p4xh.json +++ b/advisories/unreviewed/2022/05/GHSA-5wpp-rjjg-p4xh/GHSA-5wpp-rjjg-p4xh.json @@ -7,12 +7,8 @@ "CVE-2020-8246" ], "details": "Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to a denial of service attack originating from the management network.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5xph-x349-j5rr/GHSA-5xph-x349-j5rr.json b/advisories/unreviewed/2022/05/GHSA-5xph-x349-j5rr/GHSA-5xph-x349-j5rr.json index 6b91330543d..dfe62d0f1bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xph-x349-j5rr/GHSA-5xph-x349-j5rr.json +++ b/advisories/unreviewed/2022/05/GHSA-5xph-x349-j5rr/GHSA-5xph-x349-j5rr.json @@ -7,12 +7,8 @@ "CVE-2020-0381" ], "details": "In Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure in a highly constrained process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150159669", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-62vx-hh36-4mpq/GHSA-62vx-hh36-4mpq.json b/advisories/unreviewed/2022/05/GHSA-62vx-hh36-4mpq/GHSA-62vx-hh36-4mpq.json index a9a314cb1c6..07da3ef7a69 100644 --- a/advisories/unreviewed/2022/05/GHSA-62vx-hh36-4mpq/GHSA-62vx-hh36-4mpq.json +++ b/advisories/unreviewed/2022/05/GHSA-62vx-hh36-4mpq/GHSA-62vx-hh36-4mpq.json @@ -7,12 +7,8 @@ "CVE-2020-8245" ], "details": "Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b leads to an HTML Injection attack against the SSL VPN web portal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-62wm-r2r8-6qqw/GHSA-62wm-r2r8-6qqw.json b/advisories/unreviewed/2022/05/GHSA-62wm-r2r8-6qqw/GHSA-62wm-r2r8-6qqw.json index cbfff9ab46a..e0268e1da3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-62wm-r2r8-6qqw/GHSA-62wm-r2r8-6qqw.json +++ b/advisories/unreviewed/2022/05/GHSA-62wm-r2r8-6qqw/GHSA-62wm-r2r8-6qqw.json @@ -7,12 +7,8 @@ "CVE-2020-0399" ], "details": "In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-153993591", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63f3-68q8-wr22/GHSA-63f3-68q8-wr22.json b/advisories/unreviewed/2022/05/GHSA-63f3-68q8-wr22/GHSA-63f3-68q8-wr22.json index 4469dba546e..3c9873817d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-63f3-68q8-wr22/GHSA-63f3-68q8-wr22.json +++ b/advisories/unreviewed/2022/05/GHSA-63f3-68q8-wr22/GHSA-63f3-68q8-wr22.json @@ -7,12 +7,8 @@ "CVE-2020-25789" ], "details": "An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6495-758p-crj2/GHSA-6495-758p-crj2.json b/advisories/unreviewed/2022/05/GHSA-6495-758p-crj2/GHSA-6495-758p-crj2.json index c681c0fa29f..97afd8c49d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6495-758p-crj2/GHSA-6495-758p-crj2.json +++ b/advisories/unreviewed/2022/05/GHSA-6495-758p-crj2/GHSA-6495-758p-crj2.json @@ -7,12 +7,8 @@ "CVE-2020-3979" ], "details": "InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initialization time, writable by non-admin users. While those plugins are not required, they are loaded if present, which could allow an attacker to plant a malicious library which could result in code execution with the security scope of the installer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6588-mxrx-xcrg/GHSA-6588-mxrx-xcrg.json b/advisories/unreviewed/2022/05/GHSA-6588-mxrx-xcrg/GHSA-6588-mxrx-xcrg.json index 41ebb69110e..3c3512c33df 100644 --- a/advisories/unreviewed/2022/05/GHSA-6588-mxrx-xcrg/GHSA-6588-mxrx-xcrg.json +++ b/advisories/unreviewed/2022/05/GHSA-6588-mxrx-xcrg/GHSA-6588-mxrx-xcrg.json @@ -7,12 +7,8 @@ "CVE-2020-26114" ], "details": "cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-659w-726c-x8rx/GHSA-659w-726c-x8rx.json b/advisories/unreviewed/2022/05/GHSA-659w-726c-x8rx/GHSA-659w-726c-x8rx.json index ebc0214dcde..7cae1ed7d10 100644 --- a/advisories/unreviewed/2022/05/GHSA-659w-726c-x8rx/GHSA-659w-726c-x8rx.json +++ b/advisories/unreviewed/2022/05/GHSA-659w-726c-x8rx/GHSA-659w-726c-x8rx.json @@ -7,12 +7,8 @@ "CVE-2020-22481" ], "details": "An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered when the administrator views the information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65w4-p422-2r48/GHSA-65w4-p422-2r48.json b/advisories/unreviewed/2022/05/GHSA-65w4-p422-2r48/GHSA-65w4-p422-2r48.json index c45652d825c..044a3540682 100644 --- a/advisories/unreviewed/2022/05/GHSA-65w4-p422-2r48/GHSA-65w4-p422-2r48.json +++ b/advisories/unreviewed/2022/05/GHSA-65w4-p422-2r48/GHSA-65w4-p422-2r48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-662r-59mf-5fxr/GHSA-662r-59mf-5fxr.json b/advisories/unreviewed/2022/05/GHSA-662r-59mf-5fxr/GHSA-662r-59mf-5fxr.json index 4373bcd3259..5a98578491f 100644 --- a/advisories/unreviewed/2022/05/GHSA-662r-59mf-5fxr/GHSA-662r-59mf-5fxr.json +++ b/advisories/unreviewed/2022/05/GHSA-662r-59mf-5fxr/GHSA-662r-59mf-5fxr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6636-7w3v-fv4q/GHSA-6636-7w3v-fv4q.json b/advisories/unreviewed/2022/05/GHSA-6636-7w3v-fv4q/GHSA-6636-7w3v-fv4q.json index cb3e7b6a489..9e28b0a07b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-6636-7w3v-fv4q/GHSA-6636-7w3v-fv4q.json +++ b/advisories/unreviewed/2022/05/GHSA-6636-7w3v-fv4q/GHSA-6636-7w3v-fv4q.json @@ -7,12 +7,8 @@ "CVE-2020-3489" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit these vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-66q8-xjv5-xwwp/GHSA-66q8-xjv5-xwwp.json b/advisories/unreviewed/2022/05/GHSA-66q8-xjv5-xwwp/GHSA-66q8-xjv5-xwwp.json index 58eabe265f5..28503ca7090 100644 --- a/advisories/unreviewed/2022/05/GHSA-66q8-xjv5-xwwp/GHSA-66q8-xjv5-xwwp.json +++ b/advisories/unreviewed/2022/05/GHSA-66q8-xjv5-xwwp/GHSA-66q8-xjv5-xwwp.json @@ -7,12 +7,8 @@ "CVE-2020-25773" ], "details": "A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products.\n\nUser interaction is required to exploit this vulnerability in that the target must import a corrupted configuration file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-67pm-3c62-w89c/GHSA-67pm-3c62-w89c.json b/advisories/unreviewed/2022/05/GHSA-67pm-3c62-w89c/GHSA-67pm-3c62-w89c.json index fbb0a3c7a04..cdd00ecceaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-67pm-3c62-w89c/GHSA-67pm-3c62-w89c.json +++ b/advisories/unreviewed/2022/05/GHSA-67pm-3c62-w89c/GHSA-67pm-3c62-w89c.json @@ -7,12 +7,8 @@ "CVE-2020-14024" ], "details": "Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) Receiver or Recipient field in the Mailbox feature, (2) OZFORM_GROUPNAME field in the Group configuration of addresses, (3) listname field in the Defining address lists configuration, or (4) any GET Parameter in the /default URL of the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-68pq-529c-5jqg/GHSA-68pq-529c-5jqg.json b/advisories/unreviewed/2022/05/GHSA-68pq-529c-5jqg/GHSA-68pq-529c-5jqg.json index 3900c5b6bd1..219f4a858c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-68pq-529c-5jqg/GHSA-68pq-529c-5jqg.json +++ b/advisories/unreviewed/2022/05/GHSA-68pq-529c-5jqg/GHSA-68pq-529c-5jqg.json @@ -7,12 +7,8 @@ "CVE-2020-0393" ], "details": "In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-154123412", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-68rx-wxhw-923j/GHSA-68rx-wxhw-923j.json b/advisories/unreviewed/2022/05/GHSA-68rx-wxhw-923j/GHSA-68rx-wxhw-923j.json index e2161860812..c499d15977c 100644 --- a/advisories/unreviewed/2022/05/GHSA-68rx-wxhw-923j/GHSA-68rx-wxhw-923j.json +++ b/advisories/unreviewed/2022/05/GHSA-68rx-wxhw-923j/GHSA-68rx-wxhw-923j.json @@ -7,12 +7,8 @@ "CVE-2020-25139" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via la_id to the /syslog_rules URI for delete_syslog_rule, because of syslog_rules.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-699r-272q-qvfp/GHSA-699r-272q-qvfp.json b/advisories/unreviewed/2022/05/GHSA-699r-272q-qvfp/GHSA-699r-272q-qvfp.json index 5da4eea03dc..25c672fd8ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-699r-272q-qvfp/GHSA-699r-272q-qvfp.json +++ b/advisories/unreviewed/2022/05/GHSA-699r-272q-qvfp/GHSA-699r-272q-qvfp.json @@ -7,12 +7,8 @@ "CVE-2020-26103" ], "details": "In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6c3c-w7cf-ccf5/GHSA-6c3c-w7cf-ccf5.json b/advisories/unreviewed/2022/05/GHSA-6c3c-w7cf-ccf5/GHSA-6c3c-w7cf-ccf5.json index e093885ab16..cc84936d4e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c3c-w7cf-ccf5/GHSA-6c3c-w7cf-ccf5.json +++ b/advisories/unreviewed/2022/05/GHSA-6c3c-w7cf-ccf5/GHSA-6c3c-w7cf-ccf5.json @@ -7,12 +7,8 @@ "CVE-2020-12842" ], "details": "ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6fhv-wpvj-mgr8/GHSA-6fhv-wpvj-mgr8.json b/advisories/unreviewed/2022/05/GHSA-6fhv-wpvj-mgr8/GHSA-6fhv-wpvj-mgr8.json index f6aad51537f..9b8cfe000e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fhv-wpvj-mgr8/GHSA-6fhv-wpvj-mgr8.json +++ b/advisories/unreviewed/2022/05/GHSA-6fhv-wpvj-mgr8/GHSA-6fhv-wpvj-mgr8.json @@ -7,12 +7,8 @@ "CVE-2019-15959" ], "details": "A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by accessing the physical interface of a device and inserting a USB storage device. A successful exploit could allow the attacker to execute scripts on the device in an elevated security context.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6g59-7wc2-6wq7/GHSA-6g59-7wc2-6wq7.json b/advisories/unreviewed/2022/05/GHSA-6g59-7wc2-6wq7/GHSA-6g59-7wc2-6wq7.json index 8470fb7ba08..5e2a5e0f3d7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6g59-7wc2-6wq7/GHSA-6g59-7wc2-6wq7.json +++ b/advisories/unreviewed/2022/05/GHSA-6g59-7wc2-6wq7/GHSA-6g59-7wc2-6wq7.json @@ -7,12 +7,8 @@ "CVE-2020-24692" ], "details": "The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6j7f-h4xq-x8r7/GHSA-6j7f-h4xq-x8r7.json b/advisories/unreviewed/2022/05/GHSA-6j7f-h4xq-x8r7/GHSA-6j7f-h4xq-x8r7.json index fb31b82da96..d6bf8e045c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j7f-h4xq-x8r7/GHSA-6j7f-h4xq-x8r7.json +++ b/advisories/unreviewed/2022/05/GHSA-6j7f-h4xq-x8r7/GHSA-6j7f-h4xq-x8r7.json @@ -7,12 +7,8 @@ "CVE-2020-4620" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 184979.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6m48-4c69-4g6c/GHSA-6m48-4c69-4g6c.json b/advisories/unreviewed/2022/05/GHSA-6m48-4c69-4g6c/GHSA-6m48-4c69-4g6c.json index 80ecef62054..0499c50e6d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m48-4c69-4g6c/GHSA-6m48-4c69-4g6c.json +++ b/advisories/unreviewed/2022/05/GHSA-6m48-4c69-4g6c/GHSA-6m48-4c69-4g6c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6mq7-8xgf-69c7/GHSA-6mq7-8xgf-69c7.json b/advisories/unreviewed/2022/05/GHSA-6mq7-8xgf-69c7/GHSA-6mq7-8xgf-69c7.json index 8992671a23f..d51e813e1aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mq7-8xgf-69c7/GHSA-6mq7-8xgf-69c7.json +++ b/advisories/unreviewed/2022/05/GHSA-6mq7-8xgf-69c7/GHSA-6mq7-8xgf-69c7.json @@ -7,12 +7,8 @@ "CVE-2020-15521" ], "details": "Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6v2p-8q89-f8p6/GHSA-6v2p-8q89-f8p6.json b/advisories/unreviewed/2022/05/GHSA-6v2p-8q89-f8p6/GHSA-6v2p-8q89-f8p6.json index 1fcb266e5b6..fb9df72711c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v2p-8q89-f8p6/GHSA-6v2p-8q89-f8p6.json +++ b/advisories/unreviewed/2022/05/GHSA-6v2p-8q89-f8p6/GHSA-6v2p-8q89-f8p6.json @@ -7,12 +7,8 @@ "CVE-2020-0327" ], "details": "In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-129151407", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v8x-547f-7r6f/GHSA-6v8x-547f-7r6f.json b/advisories/unreviewed/2022/05/GHSA-6v8x-547f-7r6f/GHSA-6v8x-547f-7r6f.json index cea4825c1e7..f9278db3fc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v8x-547f-7r6f/GHSA-6v8x-547f-7r6f.json +++ b/advisories/unreviewed/2022/05/GHSA-6v8x-547f-7r6f/GHSA-6v8x-547f-7r6f.json @@ -7,12 +7,8 @@ "CVE-2020-3416" ], "details": "Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed could allow an authenticated, local attacker with high privileges to execute persistent code at bootup and break the chain of trust. These vulnerabilities are due to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set. An attacker could exploit these vulnerabilities by copying a specific file to the local file system of an affected device and defining specific ROMMON variables. A successful exploit could allow the attacker to run arbitrary code on the underlying operating system (OS) with root privileges. To exploit these vulnerabilities, an attacker would need to have access to the root shell on the device or have physical access to the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w33-qwcq-2qr3/GHSA-6w33-qwcq-2qr3.json b/advisories/unreviewed/2022/05/GHSA-6w33-qwcq-2qr3/GHSA-6w33-qwcq-2qr3.json index 5d58a901d27..aaf23f949b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w33-qwcq-2qr3/GHSA-6w33-qwcq-2qr3.json +++ b/advisories/unreviewed/2022/05/GHSA-6w33-qwcq-2qr3/GHSA-6w33-qwcq-2qr3.json @@ -7,12 +7,8 @@ "CVE-2020-0297" ], "details": "In devicepolicy service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155183624", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6w3q-44cj-75vr/GHSA-6w3q-44cj-75vr.json b/advisories/unreviewed/2022/05/GHSA-6w3q-44cj-75vr/GHSA-6w3q-44cj-75vr.json index 60f5b382936..a85abaf5852 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w3q-44cj-75vr/GHSA-6w3q-44cj-75vr.json +++ b/advisories/unreviewed/2022/05/GHSA-6w3q-44cj-75vr/GHSA-6w3q-44cj-75vr.json @@ -7,12 +7,8 @@ "CVE-2020-0396" ], "details": "In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-155094269", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6w47-7mpv-4v7c/GHSA-6w47-7mpv-4v7c.json b/advisories/unreviewed/2022/05/GHSA-6w47-7mpv-4v7c/GHSA-6w47-7mpv-4v7c.json index 0d551d9430d..6f56725b865 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w47-7mpv-4v7c/GHSA-6w47-7mpv-4v7c.json +++ b/advisories/unreviewed/2022/05/GHSA-6w47-7mpv-4v7c/GHSA-6w47-7mpv-4v7c.json @@ -7,12 +7,8 @@ "CVE-2020-4581" ], "details": "IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request. IBM X-Force ID: 184441.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6w6q-2f3j-fg92/GHSA-6w6q-2f3j-fg92.json b/advisories/unreviewed/2022/05/GHSA-6w6q-2f3j-fg92/GHSA-6w6q-2f3j-fg92.json index 0fa05367ba6..12309885591 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w6q-2f3j-fg92/GHSA-6w6q-2f3j-fg92.json +++ b/advisories/unreviewed/2022/05/GHSA-6w6q-2f3j-fg92/GHSA-6w6q-2f3j-fg92.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6wmx-p4xj-5jr6/GHSA-6wmx-p4xj-5jr6.json b/advisories/unreviewed/2022/05/GHSA-6wmx-p4xj-5jr6/GHSA-6wmx-p4xj-5jr6.json index 25e5d719036..b6f5bd4c287 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wmx-p4xj-5jr6/GHSA-6wmx-p4xj-5jr6.json +++ b/advisories/unreviewed/2022/05/GHSA-6wmx-p4xj-5jr6/GHSA-6wmx-p4xj-5jr6.json @@ -7,12 +7,8 @@ "CVE-2020-11700" ], "details": "An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6x3m-8754-ggf4/GHSA-6x3m-8754-ggf4.json b/advisories/unreviewed/2022/05/GHSA-6x3m-8754-ggf4/GHSA-6x3m-8754-ggf4.json index f88de37de7d..91079e5983c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x3m-8754-ggf4/GHSA-6x3m-8754-ggf4.json +++ b/advisories/unreviewed/2022/05/GHSA-6x3m-8754-ggf4/GHSA-6x3m-8754-ggf4.json @@ -7,12 +7,8 @@ "CVE-2020-5629" ], "details": "UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website via a malicious App created by the third party. As a result, if the access destination is a malicious website, the user may fall victim to the social engineering attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x3q-xm78-qvgq/GHSA-6x3q-xm78-qvgq.json b/advisories/unreviewed/2022/05/GHSA-6x3q-xm78-qvgq/GHSA-6x3q-xm78-qvgq.json index e763fc46f7b..75c425b170d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x3q-xm78-qvgq/GHSA-6x3q-xm78-qvgq.json +++ b/advisories/unreviewed/2022/05/GHSA-6x3q-xm78-qvgq/GHSA-6x3q-xm78-qvgq.json @@ -7,12 +7,8 @@ "CVE-2020-9745" ], "details": "Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6xgq-qqh9-3v8g/GHSA-6xgq-qqh9-3v8g.json b/advisories/unreviewed/2022/05/GHSA-6xgq-qqh9-3v8g/GHSA-6xgq-qqh9-3v8g.json index 9d53bfc9d78..885a272f037 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xgq-qqh9-3v8g/GHSA-6xgq-qqh9-3v8g.json +++ b/advisories/unreviewed/2022/05/GHSA-6xgq-qqh9-3v8g/GHSA-6xgq-qqh9-3v8g.json @@ -7,12 +7,8 @@ "CVE-2020-6554" ], "details": "Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-72f8-gmgh-g95g/GHSA-72f8-gmgh-g95g.json b/advisories/unreviewed/2022/05/GHSA-72f8-gmgh-g95g/GHSA-72f8-gmgh-g95g.json index df2932509bc..eb2f8c3a4c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-72f8-gmgh-g95g/GHSA-72f8-gmgh-g95g.json +++ b/advisories/unreviewed/2022/05/GHSA-72f8-gmgh-g95g/GHSA-72f8-gmgh-g95g.json @@ -7,12 +7,8 @@ "CVE-2020-12824" ], "details": "Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7369-45qw-88c2/GHSA-7369-45qw-88c2.json b/advisories/unreviewed/2022/05/GHSA-7369-45qw-88c2/GHSA-7369-45qw-88c2.json index 1db19650441..0c0e38669a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7369-45qw-88c2/GHSA-7369-45qw-88c2.json +++ b/advisories/unreviewed/2022/05/GHSA-7369-45qw-88c2/GHSA-7369-45qw-88c2.json @@ -7,12 +7,8 @@ "CVE-2020-25869" ], "details": "An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-73xv-fw87-7x76/GHSA-73xv-fw87-7x76.json b/advisories/unreviewed/2022/05/GHSA-73xv-fw87-7x76/GHSA-73xv-fw87-7x76.json index 4891f398354..865894e963d 100644 --- a/advisories/unreviewed/2022/05/GHSA-73xv-fw87-7x76/GHSA-73xv-fw87-7x76.json +++ b/advisories/unreviewed/2022/05/GHSA-73xv-fw87-7x76/GHSA-73xv-fw87-7x76.json @@ -7,12 +7,8 @@ "CVE-2019-16023" ], "details": "Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit these vulnerabilities, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7455-9qj9-w6rp/GHSA-7455-9qj9-w6rp.json b/advisories/unreviewed/2022/05/GHSA-7455-9qj9-w6rp/GHSA-7455-9qj9-w6rp.json index 0443732f63c..8eb22b177c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-7455-9qj9-w6rp/GHSA-7455-9qj9-w6rp.json +++ b/advisories/unreviewed/2022/05/GHSA-7455-9qj9-w6rp/GHSA-7455-9qj9-w6rp.json @@ -7,12 +7,8 @@ "CVE-2020-19451" ], "details": "SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-74vv-q3rm-9hv6/GHSA-74vv-q3rm-9hv6.json b/advisories/unreviewed/2022/05/GHSA-74vv-q3rm-9hv6/GHSA-74vv-q3rm-9hv6.json index a9ed520d0c1..f39a7c9be6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-74vv-q3rm-9hv6/GHSA-74vv-q3rm-9hv6.json +++ b/advisories/unreviewed/2022/05/GHSA-74vv-q3rm-9hv6/GHSA-74vv-q3rm-9hv6.json @@ -7,12 +7,8 @@ "CVE-2020-24562" ], "details": "A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution.\n\nAn attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis CVE is similar, but not identical to CVE-2020-24556.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-779w-7mcf-pvxf/GHSA-779w-7mcf-pvxf.json b/advisories/unreviewed/2022/05/GHSA-779w-7mcf-pvxf/GHSA-779w-7mcf-pvxf.json index 224527d6887..a30e0b13206 100644 --- a/advisories/unreviewed/2022/05/GHSA-779w-7mcf-pvxf/GHSA-779w-7mcf-pvxf.json +++ b/advisories/unreviewed/2022/05/GHSA-779w-7mcf-pvxf/GHSA-779w-7mcf-pvxf.json @@ -7,12 +7,8 @@ "CVE-2020-14525" ], "details": "Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-77g8-pq4g-f4jv/GHSA-77g8-pq4g-f4jv.json b/advisories/unreviewed/2022/05/GHSA-77g8-pq4g-f4jv/GHSA-77g8-pq4g-f4jv.json index 8c8832842a9..a15e084d7a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-77g8-pq4g-f4jv/GHSA-77g8-pq4g-f4jv.json +++ b/advisories/unreviewed/2022/05/GHSA-77g8-pq4g-f4jv/GHSA-77g8-pq4g-f4jv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77hg-8gw6-8f33/GHSA-77hg-8gw6-8f33.json b/advisories/unreviewed/2022/05/GHSA-77hg-8gw6-8f33/GHSA-77hg-8gw6-8f33.json index a05ea4a343b..c6ccbd6d7db 100644 --- a/advisories/unreviewed/2022/05/GHSA-77hg-8gw6-8f33/GHSA-77hg-8gw6-8f33.json +++ b/advisories/unreviewed/2022/05/GHSA-77hg-8gw6-8f33/GHSA-77hg-8gw6-8f33.json @@ -7,12 +7,8 @@ "CVE-2020-15370" ], "details": "Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorrectly logging the user password in log files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7945-j4f2-7xcp/GHSA-7945-j4f2-7xcp.json b/advisories/unreviewed/2022/05/GHSA-7945-j4f2-7xcp/GHSA-7945-j4f2-7xcp.json index bc2e23c7809..2d34c747a04 100644 --- a/advisories/unreviewed/2022/05/GHSA-7945-j4f2-7xcp/GHSA-7945-j4f2-7xcp.json +++ b/advisories/unreviewed/2022/05/GHSA-7945-j4f2-7xcp/GHSA-7945-j4f2-7xcp.json @@ -7,12 +7,8 @@ "CVE-2020-12282" ], "details": "iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible via /index.php. (This can be combined with reflected XSS.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7cxh-q528-m72h/GHSA-7cxh-q528-m72h.json b/advisories/unreviewed/2022/05/GHSA-7cxh-q528-m72h/GHSA-7cxh-q528-m72h.json index 83dcf8bd5cd..7f4cf0ce296 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cxh-q528-m72h/GHSA-7cxh-q528-m72h.json +++ b/advisories/unreviewed/2022/05/GHSA-7cxh-q528-m72h/GHSA-7cxh-q528-m72h.json @@ -7,12 +7,8 @@ "CVE-2020-11861" ], "details": "Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior to versions 12.11. The vulnerability could be exploited to escalate the local privileges and gain root access on the system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g9j-7jq7-5chw/GHSA-7g9j-7jq7-5chw.json b/advisories/unreviewed/2022/05/GHSA-7g9j-7jq7-5chw/GHSA-7g9j-7jq7-5chw.json index 3696a286b0e..018d47be738 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g9j-7jq7-5chw/GHSA-7g9j-7jq7-5chw.json +++ b/advisories/unreviewed/2022/05/GHSA-7g9j-7jq7-5chw/GHSA-7g9j-7jq7-5chw.json @@ -7,12 +7,8 @@ "CVE-2020-4324" ], "details": "IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID: 177515.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7h49-6h73-grw2/GHSA-7h49-6h73-grw2.json b/advisories/unreviewed/2022/05/GHSA-7h49-6h73-grw2/GHSA-7h49-6h73-grw2.json index 699b5ee9b72..234183ed1fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7h49-6h73-grw2/GHSA-7h49-6h73-grw2.json +++ b/advisories/unreviewed/2022/05/GHSA-7h49-6h73-grw2/GHSA-7h49-6h73-grw2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7hv9-2rpw-xx8j/GHSA-7hv9-2rpw-xx8j.json b/advisories/unreviewed/2022/05/GHSA-7hv9-2rpw-xx8j/GHSA-7hv9-2rpw-xx8j.json index e91815a4116..fa430d1a460 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hv9-2rpw-xx8j/GHSA-7hv9-2rpw-xx8j.json +++ b/advisories/unreviewed/2022/05/GHSA-7hv9-2rpw-xx8j/GHSA-7hv9-2rpw-xx8j.json @@ -7,12 +7,8 @@ "CVE-2020-25145" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /device/device=345/?tab=ports&view=../ URIs because of device/port.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7jfj-2652-mwfw/GHSA-7jfj-2652-mwfw.json b/advisories/unreviewed/2022/05/GHSA-7jfj-2652-mwfw/GHSA-7jfj-2652-mwfw.json index 69c1b1c5e04..67c3725454b 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jfj-2652-mwfw/GHSA-7jfj-2652-mwfw.json +++ b/advisories/unreviewed/2022/05/GHSA-7jfj-2652-mwfw/GHSA-7jfj-2652-mwfw.json @@ -7,12 +7,8 @@ "CVE-2020-15959" ], "details": "Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7m8h-2ghm-554f/GHSA-7m8h-2ghm-554f.json b/advisories/unreviewed/2022/05/GHSA-7m8h-2ghm-554f/GHSA-7m8h-2ghm-554f.json index 229848bbe27..cf4aadbf62a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m8h-2ghm-554f/GHSA-7m8h-2ghm-554f.json +++ b/advisories/unreviewed/2022/05/GHSA-7m8h-2ghm-554f/GHSA-7m8h-2ghm-554f.json @@ -7,12 +7,8 @@ "CVE-2020-24619" ], "details": "In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m9j-x85g-gf4r/GHSA-7m9j-x85g-gf4r.json b/advisories/unreviewed/2022/05/GHSA-7m9j-x85g-gf4r/GHSA-7m9j-x85g-gf4r.json index c3d54ca6a3b..a9c4d66a2d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m9j-x85g-gf4r/GHSA-7m9j-x85g-gf4r.json +++ b/advisories/unreviewed/2022/05/GHSA-7m9j-x85g-gf4r/GHSA-7m9j-x85g-gf4r.json @@ -7,12 +7,8 @@ "CVE-2019-7178" ], "details": "Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7mcp-gwc2-4c6m/GHSA-7mcp-gwc2-4c6m.json b/advisories/unreviewed/2022/05/GHSA-7mcp-gwc2-4c6m/GHSA-7mcp-gwc2-4c6m.json index 0f764b8276e..407569274ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mcp-gwc2-4c6m/GHSA-7mcp-gwc2-4c6m.json +++ b/advisories/unreviewed/2022/05/GHSA-7mcp-gwc2-4c6m/GHSA-7mcp-gwc2-4c6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7pqq-rhf6-g42w/GHSA-7pqq-rhf6-g42w.json b/advisories/unreviewed/2022/05/GHSA-7pqq-rhf6-g42w/GHSA-7pqq-rhf6-g42w.json index 8fd7dd1ea83..0c6d37a5ed3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pqq-rhf6-g42w/GHSA-7pqq-rhf6-g42w.json +++ b/advisories/unreviewed/2022/05/GHSA-7pqq-rhf6-g42w/GHSA-7pqq-rhf6-g42w.json @@ -7,12 +7,8 @@ "CVE-2020-0357" ], "details": "In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150225569", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7qq7-447v-42jx/GHSA-7qq7-447v-42jx.json b/advisories/unreviewed/2022/05/GHSA-7qq7-447v-42jx/GHSA-7qq7-447v-42jx.json index f0d7f5e4a7a..02a52f325cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-7qq7-447v-42jx/GHSA-7qq7-447v-42jx.json +++ b/advisories/unreviewed/2022/05/GHSA-7qq7-447v-42jx/GHSA-7qq7-447v-42jx.json @@ -7,12 +7,8 @@ "CVE-2020-13508" ], "details": "An SQL injection vulnerability exists in the Alias.asmx Web Service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Parameter AliasName in Alias.asmx is vulnerable to unauthenticated SQL injection attacks. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7rh9-qc99-8xg9/GHSA-7rh9-qc99-8xg9.json b/advisories/unreviewed/2022/05/GHSA-7rh9-qc99-8xg9/GHSA-7rh9-qc99-8xg9.json index 141c9491d63..d400b3356df 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rh9-qc99-8xg9/GHSA-7rh9-qc99-8xg9.json +++ b/advisories/unreviewed/2022/05/GHSA-7rh9-qc99-8xg9/GHSA-7rh9-qc99-8xg9.json @@ -7,12 +7,8 @@ "CVE-2020-17382" ], "details": "The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v3j-q8g3-xrh3/GHSA-7v3j-q8g3-xrh3.json b/advisories/unreviewed/2022/05/GHSA-7v3j-q8g3-xrh3/GHSA-7v3j-q8g3-xrh3.json index 1a753951a00..7928263a2ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v3j-q8g3-xrh3/GHSA-7v3j-q8g3-xrh3.json +++ b/advisories/unreviewed/2022/05/GHSA-7v3j-q8g3-xrh3/GHSA-7v3j-q8g3-xrh3.json @@ -7,12 +7,8 @@ "CVE-2020-4590" ], "details": "IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7v6g-m3gq-vpm5/GHSA-7v6g-m3gq-vpm5.json b/advisories/unreviewed/2022/05/GHSA-7v6g-m3gq-vpm5/GHSA-7v6g-m3gq-vpm5.json index 175d77c5d78..6fa1f332cda 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v6g-m3gq-vpm5/GHSA-7v6g-m3gq-vpm5.json +++ b/advisories/unreviewed/2022/05/GHSA-7v6g-m3gq-vpm5/GHSA-7v6g-m3gq-vpm5.json @@ -7,12 +7,8 @@ "CVE-2020-25138" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via /alert_check/action=delete_alert_checker/alert_test_id= because of pages/alert_check.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7wm3-575h-7pxh/GHSA-7wm3-575h-7pxh.json b/advisories/unreviewed/2022/05/GHSA-7wm3-575h-7pxh/GHSA-7wm3-575h-7pxh.json index e6aa6b1da1d..1513e18a45d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wm3-575h-7pxh/GHSA-7wm3-575h-7pxh.json +++ b/advisories/unreviewed/2022/05/GHSA-7wm3-575h-7pxh/GHSA-7wm3-575h-7pxh.json @@ -7,12 +7,8 @@ "CVE-2020-0318" ], "details": "In the System UI, there is a possible system crash due to an uncaught exception. This could lead to local permanent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-33646131", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7xcg-cx52-vr25/GHSA-7xcg-cx52-vr25.json b/advisories/unreviewed/2022/05/GHSA-7xcg-cx52-vr25/GHSA-7xcg-cx52-vr25.json index 183e3935f2a..f52e993a4bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-7xcg-cx52-vr25/GHSA-7xcg-cx52-vr25.json +++ b/advisories/unreviewed/2022/05/GHSA-7xcg-cx52-vr25/GHSA-7xcg-cx52-vr25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-836m-jqpq-6x9g/GHSA-836m-jqpq-6x9g.json b/advisories/unreviewed/2022/05/GHSA-836m-jqpq-6x9g/GHSA-836m-jqpq-6x9g.json index 4ce5c54e5f7..5330ee6ae90 100644 --- a/advisories/unreviewed/2022/05/GHSA-836m-jqpq-6x9g/GHSA-836m-jqpq-6x9g.json +++ b/advisories/unreviewed/2022/05/GHSA-836m-jqpq-6x9g/GHSA-836m-jqpq-6x9g.json @@ -7,12 +7,8 @@ "CVE-2020-0375" ], "details": "In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setting of supported EUICC countries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253476", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-83wr-vr8p-fw3c/GHSA-83wr-vr8p-fw3c.json b/advisories/unreviewed/2022/05/GHSA-83wr-vr8p-fw3c/GHSA-83wr-vr8p-fw3c.json index 249d2fb8b50..487bc0baff4 100644 --- a/advisories/unreviewed/2022/05/GHSA-83wr-vr8p-fw3c/GHSA-83wr-vr8p-fw3c.json +++ b/advisories/unreviewed/2022/05/GHSA-83wr-vr8p-fw3c/GHSA-83wr-vr8p-fw3c.json @@ -7,12 +7,8 @@ "CVE-2020-15371" ], "details": "Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86c7-v7v4-whcp/GHSA-86c7-v7v4-whcp.json b/advisories/unreviewed/2022/05/GHSA-86c7-v7v4-whcp/GHSA-86c7-v7v4-whcp.json index 5086d4a0db0..19a8eb7dbbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-86c7-v7v4-whcp/GHSA-86c7-v7v4-whcp.json +++ b/advisories/unreviewed/2022/05/GHSA-86c7-v7v4-whcp/GHSA-86c7-v7v4-whcp.json @@ -7,12 +7,8 @@ "CVE-2020-3116" ], "details": "A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit would cause the application to quit unexpectedly.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-86hj-9869-w59w/GHSA-86hj-9869-w59w.json b/advisories/unreviewed/2022/05/GHSA-86hj-9869-w59w/GHSA-86hj-9869-w59w.json index 53e76b68ecb..a12a6745747 100644 --- a/advisories/unreviewed/2022/05/GHSA-86hj-9869-w59w/GHSA-86hj-9869-w59w.json +++ b/advisories/unreviewed/2022/05/GHSA-86hj-9869-w59w/GHSA-86hj-9869-w59w.json @@ -7,12 +7,8 @@ "CVE-2020-25749" ], "details": "The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87hm-pwgx-2356/GHSA-87hm-pwgx-2356.json b/advisories/unreviewed/2022/05/GHSA-87hm-pwgx-2356/GHSA-87hm-pwgx-2356.json index ab0a1d0dff0..99495e5e212 100644 --- a/advisories/unreviewed/2022/05/GHSA-87hm-pwgx-2356/GHSA-87hm-pwgx-2356.json +++ b/advisories/unreviewed/2022/05/GHSA-87hm-pwgx-2356/GHSA-87hm-pwgx-2356.json @@ -7,12 +7,8 @@ "CVE-2020-13521" ], "details": "Parameter psAttribute in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks.Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8966-pp95-9j6j/GHSA-8966-pp95-9j6j.json b/advisories/unreviewed/2022/05/GHSA-8966-pp95-9j6j/GHSA-8966-pp95-9j6j.json index a07708d2235..334ef39c019 100644 --- a/advisories/unreviewed/2022/05/GHSA-8966-pp95-9j6j/GHSA-8966-pp95-9j6j.json +++ b/advisories/unreviewed/2022/05/GHSA-8966-pp95-9j6j/GHSA-8966-pp95-9j6j.json @@ -7,12 +7,8 @@ "CVE-2020-25787" ], "details": "An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8c2w-ph9m-jcmf/GHSA-8c2w-ph9m-jcmf.json b/advisories/unreviewed/2022/05/GHSA-8c2w-ph9m-jcmf/GHSA-8c2w-ph9m-jcmf.json index 1306bf8c0a8..6349b2b96bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-8c2w-ph9m-jcmf/GHSA-8c2w-ph9m-jcmf.json +++ b/advisories/unreviewed/2022/05/GHSA-8c2w-ph9m-jcmf/GHSA-8c2w-ph9m-jcmf.json @@ -7,12 +7,8 @@ "CVE-2020-12506" ], "details": "Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362 version FW03 and prior versions. WAGO 750-363 version FW03 and prior versions. WAGO 750-823 version FW03 and prior versions. WAGO 750-832/xxx-xxx version FW03 and prior versions. WAGO 750-862 version FW03 and prior versions. WAGO 750-891 version FW03 and prior versions. WAGO 750-890/xxx-xxx version FW03 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cpj-pr98-pf24/GHSA-8cpj-pr98-pf24.json b/advisories/unreviewed/2022/05/GHSA-8cpj-pr98-pf24/GHSA-8cpj-pr98-pf24.json index 11a4bac5504..4dde1211a69 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cpj-pr98-pf24/GHSA-8cpj-pr98-pf24.json +++ b/advisories/unreviewed/2022/05/GHSA-8cpj-pr98-pf24/GHSA-8cpj-pr98-pf24.json @@ -7,12 +7,8 @@ "CVE-2020-25515" ], "details": "Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http:///lms/index.php?page=books.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8grp-f8hg-jmhh/GHSA-8grp-f8hg-jmhh.json b/advisories/unreviewed/2022/05/GHSA-8grp-f8hg-jmhh/GHSA-8grp-f8hg-jmhh.json index 417135a2f5c..f1e280f29f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-8grp-f8hg-jmhh/GHSA-8grp-f8hg-jmhh.json +++ b/advisories/unreviewed/2022/05/GHSA-8grp-f8hg-jmhh/GHSA-8grp-f8hg-jmhh.json @@ -7,12 +7,8 @@ "CVE-2020-3560" ], "details": "A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of crafted UDP packets to a specific port on an affected device. A successful exploit could either allow the attacker to tear down the connection between the AP and the wireless LAN controller, resulting in the affected device not being able to process client traffic, or cause the vulnerable device to reload, triggering a DoS condition. After the attack, the affected device should automatically recover its normal functions without manual intervention.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8gxm-3m69-cf56/GHSA-8gxm-3m69-cf56.json b/advisories/unreviewed/2022/05/GHSA-8gxm-3m69-cf56/GHSA-8gxm-3m69-cf56.json index 89c07e4fedf..994b413ef9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gxm-3m69-cf56/GHSA-8gxm-3m69-cf56.json +++ b/advisories/unreviewed/2022/05/GHSA-8gxm-3m69-cf56/GHSA-8gxm-3m69-cf56.json @@ -7,12 +7,8 @@ "CVE-2020-26104" ], "details": "In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8h32-fwqj-xv4x/GHSA-8h32-fwqj-xv4x.json b/advisories/unreviewed/2022/05/GHSA-8h32-fwqj-xv4x/GHSA-8h32-fwqj-xv4x.json index 728510f454a..f9370766731 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h32-fwqj-xv4x/GHSA-8h32-fwqj-xv4x.json +++ b/advisories/unreviewed/2022/05/GHSA-8h32-fwqj-xv4x/GHSA-8h32-fwqj-xv4x.json @@ -7,12 +7,8 @@ "CVE-2020-0395" ], "details": "In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-154124307", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h46-8647-82rm/GHSA-8h46-8647-82rm.json b/advisories/unreviewed/2022/05/GHSA-8h46-8647-82rm/GHSA-8h46-8647-82rm.json index 58c4ef4a5d5..d5c7dcdd4a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h46-8647-82rm/GHSA-8h46-8647-82rm.json +++ b/advisories/unreviewed/2022/05/GHSA-8h46-8647-82rm/GHSA-8h46-8647-82rm.json @@ -7,12 +7,8 @@ "CVE-2020-0315" ], "details": "In Zen Mode, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155642026", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8h7h-w6qm-c2v7/GHSA-8h7h-w6qm-c2v7.json b/advisories/unreviewed/2022/05/GHSA-8h7h-w6qm-c2v7/GHSA-8h7h-w6qm-c2v7.json index 5ef8c14f892..746f7e34df7 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h7h-w6qm-c2v7/GHSA-8h7h-w6qm-c2v7.json +++ b/advisories/unreviewed/2022/05/GHSA-8h7h-w6qm-c2v7/GHSA-8h7h-w6qm-c2v7.json @@ -7,12 +7,8 @@ "CVE-2020-25146" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via la_id to the /syslog_rules URI for edit_syslog_rule.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8hf9-ggcp-8c36/GHSA-8hf9-ggcp-8c36.json b/advisories/unreviewed/2022/05/GHSA-8hf9-ggcp-8c36/GHSA-8hf9-ggcp-8c36.json index e3b551362c4..308d72f5cbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-8hf9-ggcp-8c36/GHSA-8hf9-ggcp-8c36.json +++ b/advisories/unreviewed/2022/05/GHSA-8hf9-ggcp-8c36/GHSA-8hf9-ggcp-8c36.json @@ -7,12 +7,8 @@ "CVE-2020-6537" ], "details": "Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8jfh-qgm5-rg54/GHSA-8jfh-qgm5-rg54.json b/advisories/unreviewed/2022/05/GHSA-8jfh-qgm5-rg54/GHSA-8jfh-qgm5-rg54.json index bc2c0fef2e7..34b676ca447 100644 --- a/advisories/unreviewed/2022/05/GHSA-8jfh-qgm5-rg54/GHSA-8jfh-qgm5-rg54.json +++ b/advisories/unreviewed/2022/05/GHSA-8jfh-qgm5-rg54/GHSA-8jfh-qgm5-rg54.json @@ -7,12 +7,8 @@ "CVE-2020-0394" ], "details": "In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-155648639", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mgm-98f6-65gc/GHSA-8mgm-98f6-65gc.json b/advisories/unreviewed/2022/05/GHSA-8mgm-98f6-65gc/GHSA-8mgm-98f6-65gc.json index 300a44c9992..de7b356f42a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mgm-98f6-65gc/GHSA-8mgm-98f6-65gc.json +++ b/advisories/unreviewed/2022/05/GHSA-8mgm-98f6-65gc/GHSA-8mgm-98f6-65gc.json @@ -7,12 +7,8 @@ "CVE-2020-3497" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit these vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8mp9-h8pq-r56x/GHSA-8mp9-h8pq-r56x.json b/advisories/unreviewed/2022/05/GHSA-8mp9-h8pq-r56x/GHSA-8mp9-h8pq-r56x.json index 838ee2c24f3..19f70b5dea5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mp9-h8pq-r56x/GHSA-8mp9-h8pq-r56x.json +++ b/advisories/unreviewed/2022/05/GHSA-8mp9-h8pq-r56x/GHSA-8mp9-h8pq-r56x.json @@ -7,12 +7,8 @@ "CVE-2020-0355" ], "details": "In libFraunhoferAAC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-141883493", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8mvc-hjhh-g99j/GHSA-8mvc-hjhh-g99j.json b/advisories/unreviewed/2022/05/GHSA-8mvc-hjhh-g99j/GHSA-8mvc-hjhh-g99j.json index b8d5c2e54c5..8210655133c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mvc-hjhh-g99j/GHSA-8mvc-hjhh-g99j.json +++ b/advisories/unreviewed/2022/05/GHSA-8mvc-hjhh-g99j/GHSA-8mvc-hjhh-g99j.json @@ -7,12 +7,8 @@ "CVE-2020-0341" ], "details": "In DisplayManager, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144920149", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8p74-f253-3hw4/GHSA-8p74-f253-3hw4.json b/advisories/unreviewed/2022/05/GHSA-8p74-f253-3hw4/GHSA-8p74-f253-3hw4.json index 5cbc5d1306b..680e1636bae 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p74-f253-3hw4/GHSA-8p74-f253-3hw4.json +++ b/advisories/unreviewed/2022/05/GHSA-8p74-f253-3hw4/GHSA-8p74-f253-3hw4.json @@ -7,12 +7,8 @@ "CVE-2020-13320" ], "details": "An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8q2m-xg6f-pf6x/GHSA-8q2m-xg6f-pf6x.json b/advisories/unreviewed/2022/05/GHSA-8q2m-xg6f-pf6x/GHSA-8q2m-xg6f-pf6x.json index 22443f26622..3412180c594 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q2m-xg6f-pf6x/GHSA-8q2m-xg6f-pf6x.json +++ b/advisories/unreviewed/2022/05/GHSA-8q2m-xg6f-pf6x/GHSA-8q2m-xg6f-pf6x.json @@ -7,12 +7,8 @@ "CVE-2020-13324" ], "details": "A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8q7q-4mc2-v628/GHSA-8q7q-4mc2-v628.json b/advisories/unreviewed/2022/05/GHSA-8q7q-4mc2-v628/GHSA-8q7q-4mc2-v628.json index 93d89d9c614..5f703310fdc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q7q-4mc2-v628/GHSA-8q7q-4mc2-v628.json +++ b/advisories/unreviewed/2022/05/GHSA-8q7q-4mc2-v628/GHSA-8q7q-4mc2-v628.json @@ -7,12 +7,8 @@ "CVE-2020-3135" ], "details": "A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8vqh-gxqj-vj4q/GHSA-8vqh-gxqj-vj4q.json b/advisories/unreviewed/2022/05/GHSA-8vqh-gxqj-vj4q/GHSA-8vqh-gxqj-vj4q.json index ce3f20166ff..515341cf60a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vqh-gxqj-vj4q/GHSA-8vqh-gxqj-vj4q.json +++ b/advisories/unreviewed/2022/05/GHSA-8vqh-gxqj-vj4q/GHSA-8vqh-gxqj-vj4q.json @@ -7,12 +7,8 @@ "CVE-2020-15669" ], "details": "When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8vvq-v9pr-9fqv/GHSA-8vvq-v9pr-9fqv.json b/advisories/unreviewed/2022/05/GHSA-8vvq-v9pr-9fqv/GHSA-8vvq-v9pr-9fqv.json index e92f96bce81..6b78136cd05 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vvq-v9pr-9fqv/GHSA-8vvq-v9pr-9fqv.json +++ b/advisories/unreviewed/2022/05/GHSA-8vvq-v9pr-9fqv/GHSA-8vvq-v9pr-9fqv.json @@ -7,12 +7,8 @@ "CVE-2020-11805" ], "details": "Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8wf3-m6g4-jx6p/GHSA-8wf3-m6g4-jx6p.json b/advisories/unreviewed/2022/05/GHSA-8wf3-m6g4-jx6p/GHSA-8wf3-m6g4-jx6p.json index 4be770e1e5c..0db9a68e988 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wf3-m6g4-jx6p/GHSA-8wf3-m6g4-jx6p.json +++ b/advisories/unreviewed/2022/05/GHSA-8wf3-m6g4-jx6p/GHSA-8wf3-m6g4-jx6p.json @@ -7,12 +7,8 @@ "CVE-2020-12505" ], "details": "Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852 version FW07 and prior versions. WAGO 750-880/xxx-xxx version FW07 and prior versions. WAGO 750-881 version FW07 and prior versions. WAGO 750-831/xxx-xxx version FW07 and prior versions. WAGO 750-882 version FW07 and prior versions. WAGO 750-885/xxx-xxx version FW07 and prior versions. WAGO 750-889 version FW07 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8whc-c8rj-g4hf/GHSA-8whc-c8rj-g4hf.json b/advisories/unreviewed/2022/05/GHSA-8whc-c8rj-g4hf/GHSA-8whc-c8rj-g4hf.json index b35078b80be..2f7c9b2c173 100644 --- a/advisories/unreviewed/2022/05/GHSA-8whc-c8rj-g4hf/GHSA-8whc-c8rj-g4hf.json +++ b/advisories/unreviewed/2022/05/GHSA-8whc-c8rj-g4hf/GHSA-8whc-c8rj-g4hf.json @@ -7,12 +7,8 @@ "CVE-2020-6569" ], "details": "Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8wp6-6wh9-vfqp/GHSA-8wp6-6wh9-vfqp.json b/advisories/unreviewed/2022/05/GHSA-8wp6-6wh9-vfqp/GHSA-8wp6-6wh9-vfqp.json index f3a3a0af272..c4921630a31 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wp6-6wh9-vfqp/GHSA-8wp6-6wh9-vfqp.json +++ b/advisories/unreviewed/2022/05/GHSA-8wp6-6wh9-vfqp/GHSA-8wp6-6wh9-vfqp.json @@ -7,12 +7,8 @@ "CVE-2020-6532" ], "details": "Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8x34-hcfv-c7qh/GHSA-8x34-hcfv-c7qh.json b/advisories/unreviewed/2022/05/GHSA-8x34-hcfv-c7qh/GHSA-8x34-hcfv-c7qh.json index ea44121cc26..f4247797073 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x34-hcfv-c7qh/GHSA-8x34-hcfv-c7qh.json +++ b/advisories/unreviewed/2022/05/GHSA-8x34-hcfv-c7qh/GHSA-8x34-hcfv-c7qh.json @@ -7,12 +7,8 @@ "CVE-2020-21564" ], "details": "An issue was discovered in Pluck CMS v4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-936f-xp4r-7g6w/GHSA-936f-xp4r-7g6w.json b/advisories/unreviewed/2022/05/GHSA-936f-xp4r-7g6w/GHSA-936f-xp4r-7g6w.json index a9f382dd0ff..316d0b8bbaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-936f-xp4r-7g6w/GHSA-936f-xp4r-7g6w.json +++ b/advisories/unreviewed/2022/05/GHSA-936f-xp4r-7g6w/GHSA-936f-xp4r-7g6w.json @@ -7,12 +7,8 @@ "CVE-2020-25733" ], "details": "webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-93m2-m6gp-jwhm/GHSA-93m2-m6gp-jwhm.json b/advisories/unreviewed/2022/05/GHSA-93m2-m6gp-jwhm/GHSA-93m2-m6gp-jwhm.json index d2c33a48d8c..a8f947282fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-93m2-m6gp-jwhm/GHSA-93m2-m6gp-jwhm.json +++ b/advisories/unreviewed/2022/05/GHSA-93m2-m6gp-jwhm/GHSA-93m2-m6gp-jwhm.json @@ -7,12 +7,8 @@ "CVE-2020-3429" ], "details": "A vulnerability in the WPA2 and WPA3 security implementation of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect packet processing during the WPA2 and WPA3 authentication handshake when configured for dot1x or pre-shared key (PSK) authentication key management (AKM) with 802.11r BSS Fast Transition (FT) enabled. An attacker could exploit this vulnerability by sending a crafted authentication packet to an affected device. A successful exploit could cause an affected device to reload, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93x8-xp39-6r6f/GHSA-93x8-xp39-6r6f.json b/advisories/unreviewed/2022/05/GHSA-93x8-xp39-6r6f/GHSA-93x8-xp39-6r6f.json index 914eab6e6cc..383e9aa7c7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-93x8-xp39-6r6f/GHSA-93x8-xp39-6r6f.json +++ b/advisories/unreviewed/2022/05/GHSA-93x8-xp39-6r6f/GHSA-93x8-xp39-6r6f.json @@ -7,12 +7,8 @@ "CVE-2019-1888" ], "details": "A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to upload arbitrary files and execute commands on the underlying operating system. To exploit this vulnerability, an attacker needs valid Administrator credentials. The vulnerability is due to insufficient restrictions for the content uploaded to an affected system. An attacker could exploit this vulnerability by uploading arbitrary files containing operating system commands that will be executed by an affected system. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the web interface and then elevate their privileges to root.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-956m-435w-x6jc/GHSA-956m-435w-x6jc.json b/advisories/unreviewed/2022/05/GHSA-956m-435w-x6jc/GHSA-956m-435w-x6jc.json index f021241702c..57f3ec23547 100644 --- a/advisories/unreviewed/2022/05/GHSA-956m-435w-x6jc/GHSA-956m-435w-x6jc.json +++ b/advisories/unreviewed/2022/05/GHSA-956m-435w-x6jc/GHSA-956m-435w-x6jc.json @@ -7,12 +7,8 @@ "CVE-2020-12811" ], "details": "An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-959v-9vmf-r6r9/GHSA-959v-9vmf-r6r9.json b/advisories/unreviewed/2022/05/GHSA-959v-9vmf-r6r9/GHSA-959v-9vmf-r6r9.json index d7657a1808c..268a6770348 100644 --- a/advisories/unreviewed/2022/05/GHSA-959v-9vmf-r6r9/GHSA-959v-9vmf-r6r9.json +++ b/advisories/unreviewed/2022/05/GHSA-959v-9vmf-r6r9/GHSA-959v-9vmf-r6r9.json @@ -7,12 +7,8 @@ "CVE-2020-3488" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit these vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95gm-vqqp-xfhw/GHSA-95gm-vqqp-xfhw.json b/advisories/unreviewed/2022/05/GHSA-95gm-vqqp-xfhw/GHSA-95gm-vqqp-xfhw.json index 924b18fcb83..6358e7f3803 100644 --- a/advisories/unreviewed/2022/05/GHSA-95gm-vqqp-xfhw/GHSA-95gm-vqqp-xfhw.json +++ b/advisories/unreviewed/2022/05/GHSA-95gm-vqqp-xfhw/GHSA-95gm-vqqp-xfhw.json @@ -7,12 +7,8 @@ "CVE-2020-19670" ], "details": "In Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-97jp-gj5w-5gwc/GHSA-97jp-gj5w-5gwc.json b/advisories/unreviewed/2022/05/GHSA-97jp-gj5w-5gwc/GHSA-97jp-gj5w-5gwc.json index 848873b69b2..97f68d024c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-97jp-gj5w-5gwc/GHSA-97jp-gj5w-5gwc.json +++ b/advisories/unreviewed/2022/05/GHSA-97jp-gj5w-5gwc/GHSA-97jp-gj5w-5gwc.json @@ -7,12 +7,8 @@ "CVE-2020-4618" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 could allow a privileged user to cause a denial of service due to improper input validation. IBM X-Force ID: 184937.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-97q5-v434-9c8f/GHSA-97q5-v434-9c8f.json b/advisories/unreviewed/2022/05/GHSA-97q5-v434-9c8f/GHSA-97q5-v434-9c8f.json index cf143ade885..016cf925ed4 100644 --- a/advisories/unreviewed/2022/05/GHSA-97q5-v434-9c8f/GHSA-97q5-v434-9c8f.json +++ b/advisories/unreviewed/2022/05/GHSA-97q5-v434-9c8f/GHSA-97q5-v434-9c8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-985f-4rhp-8wqw/GHSA-985f-4rhp-8wqw.json b/advisories/unreviewed/2022/05/GHSA-985f-4rhp-8wqw/GHSA-985f-4rhp-8wqw.json index aaf23982f9c..989dc0ab507 100644 --- a/advisories/unreviewed/2022/05/GHSA-985f-4rhp-8wqw/GHSA-985f-4rhp-8wqw.json +++ b/advisories/unreviewed/2022/05/GHSA-985f-4rhp-8wqw/GHSA-985f-4rhp-8wqw.json @@ -7,12 +7,8 @@ "CVE-2020-25134" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /settings/?format=../ URIs to pages/settings.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99cq-xr7g-h22w/GHSA-99cq-xr7g-h22w.json b/advisories/unreviewed/2022/05/GHSA-99cq-xr7g-h22w/GHSA-99cq-xr7g-h22w.json index ca16b821544..d7515700b01 100644 --- a/advisories/unreviewed/2022/05/GHSA-99cq-xr7g-h22w/GHSA-99cq-xr7g-h22w.json +++ b/advisories/unreviewed/2022/05/GHSA-99cq-xr7g-h22w/GHSA-99cq-xr7g-h22w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9cwr-72m4-73jq/GHSA-9cwr-72m4-73jq.json b/advisories/unreviewed/2022/05/GHSA-9cwr-72m4-73jq/GHSA-9cwr-72m4-73jq.json index 3a4c4e38f61..e2104f96bda 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cwr-72m4-73jq/GHSA-9cwr-72m4-73jq.json +++ b/advisories/unreviewed/2022/05/GHSA-9cwr-72m4-73jq/GHSA-9cwr-72m4-73jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f77-7fxg-mppm/GHSA-9f77-7fxg-mppm.json b/advisories/unreviewed/2022/05/GHSA-9f77-7fxg-mppm/GHSA-9f77-7fxg-mppm.json index f2758988627..db34f037f4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f77-7fxg-mppm/GHSA-9f77-7fxg-mppm.json +++ b/advisories/unreviewed/2022/05/GHSA-9f77-7fxg-mppm/GHSA-9f77-7fxg-mppm.json @@ -7,12 +7,8 @@ "CVE-2020-3510" ], "details": "A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to trigger a reload, resulting in a denial of service condition on an affected device. The vulnerability is due to insufficient error handling when parsing DNS requests. An attacker could exploit this vulnerability by sending a series of malicious DNS requests to an Umbrella Connector client interface of an affected device. A successful exploit could allow the attacker to cause a crash of the iosd process, which triggers a reload of the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9fc4-hf3h-f527/GHSA-9fc4-hf3h-f527.json b/advisories/unreviewed/2022/05/GHSA-9fc4-hf3h-f527/GHSA-9fc4-hf3h-f527.json index 5b8f2d7099b..7cbbb5c3e3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fc4-hf3h-f527/GHSA-9fc4-hf3h-f527.json +++ b/advisories/unreviewed/2022/05/GHSA-9fc4-hf3h-f527/GHSA-9fc4-hf3h-f527.json @@ -7,12 +7,8 @@ "CVE-2020-14023" ], "details": "Ozeki NG SMS Gateway through 4.17.6 allows SSRF via SMS WCF or RSS To SMS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9g2r-34xj-79x9/GHSA-9g2r-34xj-79x9.json b/advisories/unreviewed/2022/05/GHSA-9g2r-34xj-79x9/GHSA-9g2r-34xj-79x9.json index e105fc47600..5d9e9c78bda 100644 --- a/advisories/unreviewed/2022/05/GHSA-9g2r-34xj-79x9/GHSA-9g2r-34xj-79x9.json +++ b/advisories/unreviewed/2022/05/GHSA-9g2r-34xj-79x9/GHSA-9g2r-34xj-79x9.json @@ -7,12 +7,8 @@ "CVE-2020-3418" ], "details": "A vulnerability in Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9800 Series Routers could allow an unauthenticated, adjacent attacker to send ICMPv6 traffic prior to the client being placed into RUN state. The vulnerability is due to an incomplete access control list (ACL) being applied prior to RUN state. An attacker could exploit this vulnerability by connecting to the associated service set identifier (SSID) and sending ICMPv6 traffic. A successful exploit could allow the attacker to send ICMPv6 traffic prior to RUN state.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gfh-jm3x-h97m/GHSA-9gfh-jm3x-h97m.json b/advisories/unreviewed/2022/05/GHSA-9gfh-jm3x-h97m/GHSA-9gfh-jm3x-h97m.json index d2c80e72acf..8f2ab482b8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gfh-jm3x-h97m/GHSA-9gfh-jm3x-h97m.json +++ b/advisories/unreviewed/2022/05/GHSA-9gfh-jm3x-h97m/GHSA-9gfh-jm3x-h97m.json @@ -7,12 +7,8 @@ "CVE-2020-0370" ], "details": "In libAACdec, there is a possible out of bounds read due to missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-112051700", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9mg5-2pf2-x28v/GHSA-9mg5-2pf2-x28v.json b/advisories/unreviewed/2022/05/GHSA-9mg5-2pf2-x28v/GHSA-9mg5-2pf2-x28v.json index 1c8026006c9..5ca84abaa07 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mg5-2pf2-x28v/GHSA-9mg5-2pf2-x28v.json +++ b/advisories/unreviewed/2022/05/GHSA-9mg5-2pf2-x28v/GHSA-9mg5-2pf2-x28v.json @@ -7,12 +7,8 @@ "CVE-2020-6549" ], "details": "Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pg8-pw4x-p8jx/GHSA-9pg8-pw4x-p8jx.json b/advisories/unreviewed/2022/05/GHSA-9pg8-pw4x-p8jx/GHSA-9pg8-pw4x-p8jx.json index 4b5a4675530..ab102eb7a80 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pg8-pw4x-p8jx/GHSA-9pg8-pw4x-p8jx.json +++ b/advisories/unreviewed/2022/05/GHSA-9pg8-pw4x-p8jx/GHSA-9pg8-pw4x-p8jx.json @@ -7,12 +7,8 @@ "CVE-2020-3486" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit these vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pjj-6grx-8qjx/GHSA-9pjj-6grx-8qjx.json b/advisories/unreviewed/2022/05/GHSA-9pjj-6grx-8qjx/GHSA-9pjj-6grx-8qjx.json index 65ec49e4ac8..7eec53504d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pjj-6grx-8qjx/GHSA-9pjj-6grx-8qjx.json +++ b/advisories/unreviewed/2022/05/GHSA-9pjj-6grx-8qjx/GHSA-9pjj-6grx-8qjx.json @@ -7,12 +7,8 @@ "CVE-2020-24721" ], "details": "An issue was discovered in the GAEN (aka Google Apple Encounter Notification) protocol through 2020-08-27, as used in Corona applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or dis-proving an encounter notification.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9q2c-4gv2-vv76/GHSA-9q2c-4gv2-vv76.json b/advisories/unreviewed/2022/05/GHSA-9q2c-4gv2-vv76/GHSA-9q2c-4gv2-vv76.json index 9ab9cdd56e4..d747d5cd776 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q2c-4gv2-vv76/GHSA-9q2c-4gv2-vv76.json +++ b/advisories/unreviewed/2022/05/GHSA-9q2c-4gv2-vv76/GHSA-9q2c-4gv2-vv76.json @@ -7,12 +7,8 @@ "CVE-2020-13319" ], "details": "An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9q88-264f-9cgp/GHSA-9q88-264f-9cgp.json b/advisories/unreviewed/2022/05/GHSA-9q88-264f-9cgp/GHSA-9q88-264f-9cgp.json index aa1d5875427..4d578350da9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q88-264f-9cgp/GHSA-9q88-264f-9cgp.json +++ b/advisories/unreviewed/2022/05/GHSA-9q88-264f-9cgp/GHSA-9q88-264f-9cgp.json @@ -7,12 +7,8 @@ "CVE-2020-14022" ], "details": "Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts (\"Import Contacts\" functionality) from a file. It is possible to upload an executable or .bat file that can be executed with the help of a functionality (E.g. the \"Application Starter\" module) within the application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qpq-wq75-qh2w/GHSA-9qpq-wq75-qh2w.json b/advisories/unreviewed/2022/05/GHSA-9qpq-wq75-qh2w/GHSA-9qpq-wq75-qh2w.json index 112df94644d..26acb4430d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qpq-wq75-qh2w/GHSA-9qpq-wq75-qh2w.json +++ b/advisories/unreviewed/2022/05/GHSA-9qpq-wq75-qh2w/GHSA-9qpq-wq75-qh2w.json @@ -7,12 +7,8 @@ "CVE-2020-8347" ], "details": "A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's browser if a crafted url is visited, possibly through phishing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9qqq-hp54-hq2g/GHSA-9qqq-hp54-hq2g.json b/advisories/unreviewed/2022/05/GHSA-9qqq-hp54-hq2g/GHSA-9qqq-hp54-hq2g.json index ebf4a9e54ca..b63a383c5e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qqq-hp54-hq2g/GHSA-9qqq-hp54-hq2g.json +++ b/advisories/unreviewed/2022/05/GHSA-9qqq-hp54-hq2g/GHSA-9qqq-hp54-hq2g.json @@ -7,12 +7,8 @@ "CVE-2020-12841" ], "details": "ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rcr-qh8q-m9m6/GHSA-9rcr-qh8q-m9m6.json b/advisories/unreviewed/2022/05/GHSA-9rcr-qh8q-m9m6/GHSA-9rcr-qh8q-m9m6.json index e41bdb1c374..5afe51c6b73 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rcr-qh8q-m9m6/GHSA-9rcr-qh8q-m9m6.json +++ b/advisories/unreviewed/2022/05/GHSA-9rcr-qh8q-m9m6/GHSA-9rcr-qh8q-m9m6.json @@ -7,12 +7,8 @@ "CVE-2020-14026" ], "details": "CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rmc-v2wh-vw8c/GHSA-9rmc-v2wh-vw8c.json b/advisories/unreviewed/2022/05/GHSA-9rmc-v2wh-vw8c/GHSA-9rmc-v2wh-vw8c.json index 1666b8397c7..10f4df6a144 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rmc-v2wh-vw8c/GHSA-9rmc-v2wh-vw8c.json +++ b/advisories/unreviewed/2022/05/GHSA-9rmc-v2wh-vw8c/GHSA-9rmc-v2wh-vw8c.json @@ -7,12 +7,8 @@ "CVE-2019-15957" ], "details": "A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system. When processed, the commands will be executed with root privileges. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by providing malicious input to a specific field in the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system as the root user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9rw7-4q6q-6gch/GHSA-9rw7-4q6q-6gch.json b/advisories/unreviewed/2022/05/GHSA-9rw7-4q6q-6gch/GHSA-9rw7-4q6q-6gch.json index fbfdb4fdf81..bd0a5d5c5ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rw7-4q6q-6gch/GHSA-9rw7-4q6q-6gch.json +++ b/advisories/unreviewed/2022/05/GHSA-9rw7-4q6q-6gch/GHSA-9rw7-4q6q-6gch.json @@ -7,12 +7,8 @@ "CVE-2015-4719" ], "details": "The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9w53-qgf5-qxx6/GHSA-9w53-qgf5-qxx6.json b/advisories/unreviewed/2022/05/GHSA-9w53-qgf5-qxx6/GHSA-9w53-qgf5-qxx6.json index 43da7089962..0e88798d838 100644 --- a/advisories/unreviewed/2022/05/GHSA-9w53-qgf5-qxx6/GHSA-9w53-qgf5-qxx6.json +++ b/advisories/unreviewed/2022/05/GHSA-9w53-qgf5-qxx6/GHSA-9w53-qgf5-qxx6.json @@ -7,12 +7,8 @@ "CVE-2020-4727" ], "details": "IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9wp3-7mqv-3f2q/GHSA-9wp3-7mqv-3f2q.json b/advisories/unreviewed/2022/05/GHSA-9wp3-7mqv-3f2q/GHSA-9wp3-7mqv-3f2q.json index 72efde256c6..07f878dfecd 100644 --- a/advisories/unreviewed/2022/05/GHSA-9wp3-7mqv-3f2q/GHSA-9wp3-7mqv-3f2q.json +++ b/advisories/unreviewed/2022/05/GHSA-9wp3-7mqv-3f2q/GHSA-9wp3-7mqv-3f2q.json @@ -7,12 +7,8 @@ "CVE-2020-15962" ], "details": "Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9x7f-9g6j-gf94/GHSA-9x7f-9g6j-gf94.json b/advisories/unreviewed/2022/05/GHSA-9x7f-9g6j-gf94/GHSA-9x7f-9g6j-gf94.json index da361d0e724..1a91bb5c575 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x7f-9g6j-gf94/GHSA-9x7f-9g6j-gf94.json +++ b/advisories/unreviewed/2022/05/GHSA-9x7f-9g6j-gf94/GHSA-9x7f-9g6j-gf94.json @@ -7,12 +7,8 @@ "CVE-2020-5975" ], "details": "NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application software that includes sensitive information as part of a URL, which may lead to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9xj7-8ggj-44p4/GHSA-9xj7-8ggj-44p4.json b/advisories/unreviewed/2022/05/GHSA-9xj7-8ggj-44p4/GHSA-9xj7-8ggj-44p4.json index 8264f42ae01..0100eb8a0ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xj7-8ggj-44p4/GHSA-9xj7-8ggj-44p4.json +++ b/advisories/unreviewed/2022/05/GHSA-9xj7-8ggj-44p4/GHSA-9xj7-8ggj-44p4.json @@ -7,12 +7,8 @@ "CVE-2020-25131" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via the role_name or role_descr parameter to the roles/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xvv-5c4q-3hj4/GHSA-9xvv-5c4q-3hj4.json b/advisories/unreviewed/2022/05/GHSA-9xvv-5c4q-3hj4/GHSA-9xvv-5c4q-3hj4.json index a33e0139a3a..4930b79cee2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xvv-5c4q-3hj4/GHSA-9xvv-5c4q-3hj4.json +++ b/advisories/unreviewed/2022/05/GHSA-9xvv-5c4q-3hj4/GHSA-9xvv-5c4q-3hj4.json @@ -7,12 +7,8 @@ "CVE-2020-25135" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via the graph_title parameter to the graphs/ URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9xw8-fchc-9cwh/GHSA-9xw8-fchc-9cwh.json b/advisories/unreviewed/2022/05/GHSA-9xw8-fchc-9cwh/GHSA-9xw8-fchc-9cwh.json index 8f73f979317..740a8b2dfe1 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xw8-fchc-9cwh/GHSA-9xw8-fchc-9cwh.json +++ b/advisories/unreviewed/2022/05/GHSA-9xw8-fchc-9cwh/GHSA-9xw8-fchc-9cwh.json @@ -7,12 +7,8 @@ "CVE-2020-5789" ], "details": "Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c38h-42jg-3h9q/GHSA-c38h-42jg-3h9q.json b/advisories/unreviewed/2022/05/GHSA-c38h-42jg-3h9q/GHSA-c38h-42jg-3h9q.json index f2e8bba47e0..4c341954287 100644 --- a/advisories/unreviewed/2022/05/GHSA-c38h-42jg-3h9q/GHSA-c38h-42jg-3h9q.json +++ b/advisories/unreviewed/2022/05/GHSA-c38h-42jg-3h9q/GHSA-c38h-42jg-3h9q.json @@ -7,12 +7,8 @@ "CVE-2020-3516" ], "details": "A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device. The vulnerability is due to insufficient input validation during authentication. An attacker could exploit this vulnerability by entering unexpected characters during a valid authentication. A successful exploit could allow the attacker to crash the web server on the device, which must be manually recovered by disabling and re-enabling the web server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c438-hq8x-xh4m/GHSA-c438-hq8x-xh4m.json b/advisories/unreviewed/2022/05/GHSA-c438-hq8x-xh4m/GHSA-c438-hq8x-xh4m.json index 0f9d066ae9f..b1181ad8c32 100644 --- a/advisories/unreviewed/2022/05/GHSA-c438-hq8x-xh4m/GHSA-c438-hq8x-xh4m.json +++ b/advisories/unreviewed/2022/05/GHSA-c438-hq8x-xh4m/GHSA-c438-hq8x-xh4m.json @@ -7,12 +7,8 @@ "CVE-2020-12123" ], "details": "CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, because these endpoints do not contain CSRF tokens. If a user is authenticated in the router portal, then this attack will work.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4hj-3xv9-xxxq/GHSA-c4hj-3xv9-xxxq.json b/advisories/unreviewed/2022/05/GHSA-c4hj-3xv9-xxxq/GHSA-c4hj-3xv9-xxxq.json index 6df75b80c9e..55da5438591 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4hj-3xv9-xxxq/GHSA-c4hj-3xv9-xxxq.json +++ b/advisories/unreviewed/2022/05/GHSA-c4hj-3xv9-xxxq/GHSA-c4hj-3xv9-xxxq.json @@ -7,12 +7,8 @@ "CVE-2020-5930" ], "details": "In BIG-IP 15.0.0-15.1.0.4, 14.1.0-14.1.2.7, 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 and BIG-IQ 5.2.0-7.1.0, unauthenticated attackers can cause disruption of service via undisclosed methods.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c4rh-w37f-6w32/GHSA-c4rh-w37f-6w32.json b/advisories/unreviewed/2022/05/GHSA-c4rh-w37f-6w32/GHSA-c4rh-w37f-6w32.json index 5e38938c6dc..6ad19501cf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4rh-w37f-6w32/GHSA-c4rh-w37f-6w32.json +++ b/advisories/unreviewed/2022/05/GHSA-c4rh-w37f-6w32/GHSA-c4rh-w37f-6w32.json @@ -7,12 +7,8 @@ "CVE-2006-6994" ], "details": "Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers to upload and execute arbitrary ASP files by removing the client-side security checks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5g2-96g6-95vx/GHSA-c5g2-96g6-95vx.json b/advisories/unreviewed/2022/05/GHSA-c5g2-96g6-95vx/GHSA-c5g2-96g6-95vx.json index 9896461549d..612c8224350 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5g2-96g6-95vx/GHSA-c5g2-96g6-95vx.json +++ b/advisories/unreviewed/2022/05/GHSA-c5g2-96g6-95vx/GHSA-c5g2-96g6-95vx.json @@ -7,12 +7,8 @@ "CVE-2020-24625" ], "details": "Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c5r6-cm8r-wgh9/GHSA-c5r6-cm8r-wgh9.json b/advisories/unreviewed/2022/05/GHSA-c5r6-cm8r-wgh9/GHSA-c5r6-cm8r-wgh9.json index e02355dd3fd..decc2a7a508 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5r6-cm8r-wgh9/GHSA-c5r6-cm8r-wgh9.json +++ b/advisories/unreviewed/2022/05/GHSA-c5r6-cm8r-wgh9/GHSA-c5r6-cm8r-wgh9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c62x-66fc-368q/GHSA-c62x-66fc-368q.json b/advisories/unreviewed/2022/05/GHSA-c62x-66fc-368q/GHSA-c62x-66fc-368q.json index b91bdc52589..c6f64da8b41 100644 --- a/advisories/unreviewed/2022/05/GHSA-c62x-66fc-368q/GHSA-c62x-66fc-368q.json +++ b/advisories/unreviewed/2022/05/GHSA-c62x-66fc-368q/GHSA-c62x-66fc-368q.json @@ -7,12 +7,8 @@ "CVE-2020-4315" ], "details": "IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 177234.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c6p9-pfxr-3qp5/GHSA-c6p9-pfxr-3qp5.json b/advisories/unreviewed/2022/05/GHSA-c6p9-pfxr-3qp5/GHSA-c6p9-pfxr-3qp5.json index f9432e97c53..0545549d949 100644 --- a/advisories/unreviewed/2022/05/GHSA-c6p9-pfxr-3qp5/GHSA-c6p9-pfxr-3qp5.json +++ b/advisories/unreviewed/2022/05/GHSA-c6p9-pfxr-3qp5/GHSA-c6p9-pfxr-3qp5.json @@ -7,12 +7,8 @@ "CVE-2020-0390" ], "details": "In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-157598026", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c75r-fv95-pffp/GHSA-c75r-fv95-pffp.json b/advisories/unreviewed/2022/05/GHSA-c75r-fv95-pffp/GHSA-c75r-fv95-pffp.json index f4f13ba886d..254dc30d3fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-c75r-fv95-pffp/GHSA-c75r-fv95-pffp.json +++ b/advisories/unreviewed/2022/05/GHSA-c75r-fv95-pffp/GHSA-c75r-fv95-pffp.json @@ -7,12 +7,8 @@ "CVE-2019-17098" ], "details": "Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This issue affects: August Connect Wi-Fi Bridge App version v10.11.0 and prior versions on Android. August Connect Firmware version 2.2.12 and prior versions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9pq-99jp-354g/GHSA-c9pq-99jp-354g.json b/advisories/unreviewed/2022/05/GHSA-c9pq-99jp-354g/GHSA-c9pq-99jp-354g.json index 4a2b2576c86..83dbe77c8e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9pq-99jp-354g/GHSA-c9pq-99jp-354g.json +++ b/advisories/unreviewed/2022/05/GHSA-c9pq-99jp-354g/GHSA-c9pq-99jp-354g.json @@ -7,12 +7,8 @@ "CVE-2020-25788" ], "details": "An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST[\"url\"] in an error message.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9qg-vw6g-5g8v/GHSA-c9qg-vw6g-5g8v.json b/advisories/unreviewed/2022/05/GHSA-c9qg-vw6g-5g8v/GHSA-c9qg-vw6g-5g8v.json index 411f3d507d6..6774c13a2bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9qg-vw6g-5g8v/GHSA-c9qg-vw6g-5g8v.json +++ b/advisories/unreviewed/2022/05/GHSA-c9qg-vw6g-5g8v/GHSA-c9qg-vw6g-5g8v.json @@ -7,12 +7,8 @@ "CVE-2020-26102" ], "details": "In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg2x-f9qq-r586/GHSA-cg2x-f9qq-r586.json b/advisories/unreviewed/2022/05/GHSA-cg2x-f9qq-r586/GHSA-cg2x-f9qq-r586.json index 9517d97cb99..d347a430b14 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg2x-f9qq-r586/GHSA-cg2x-f9qq-r586.json +++ b/advisories/unreviewed/2022/05/GHSA-cg2x-f9qq-r586/GHSA-cg2x-f9qq-r586.json @@ -7,12 +7,8 @@ "CVE-2020-6576" ], "details": "Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cg6f-88f9-rp7x/GHSA-cg6f-88f9-rp7x.json b/advisories/unreviewed/2022/05/GHSA-cg6f-88f9-rp7x/GHSA-cg6f-88f9-rp7x.json index bb0f31ce5e3..18343bf2fc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg6f-88f9-rp7x/GHSA-cg6f-88f9-rp7x.json +++ b/advisories/unreviewed/2022/05/GHSA-cg6f-88f9-rp7x/GHSA-cg6f-88f9-rp7x.json @@ -7,12 +7,8 @@ "CVE-2020-26108" ], "details": "cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cgr8-5587-cqhj/GHSA-cgr8-5587-cqhj.json b/advisories/unreviewed/2022/05/GHSA-cgr8-5587-cqhj/GHSA-cgr8-5587-cqhj.json index eeb9450e2de..85ae869edee 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgr8-5587-cqhj/GHSA-cgr8-5587-cqhj.json +++ b/advisories/unreviewed/2022/05/GHSA-cgr8-5587-cqhj/GHSA-cgr8-5587-cqhj.json @@ -7,12 +7,8 @@ "CVE-2020-0403" ], "details": "In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-131252923", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ch7q-2q5r-pf55/GHSA-ch7q-2q5r-pf55.json b/advisories/unreviewed/2022/05/GHSA-ch7q-2q5r-pf55/GHSA-ch7q-2q5r-pf55.json index d93f97d1a94..fa842dfd72a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch7q-2q5r-pf55/GHSA-ch7q-2q5r-pf55.json +++ b/advisories/unreviewed/2022/05/GHSA-ch7q-2q5r-pf55/GHSA-ch7q-2q5r-pf55.json @@ -7,12 +7,8 @@ "CVE-2020-5605" ], "details": "Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive information such as setting values via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmqx-vr89-j979/GHSA-cmqx-vr89-j979.json b/advisories/unreviewed/2022/05/GHSA-cmqx-vr89-j979/GHSA-cmqx-vr89-j979.json index fff2853e440..3d042bf0e50 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmqx-vr89-j979/GHSA-cmqx-vr89-j979.json +++ b/advisories/unreviewed/2022/05/GHSA-cmqx-vr89-j979/GHSA-cmqx-vr89-j979.json @@ -7,12 +7,8 @@ "CVE-2020-15773" ], "details": "An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previously explicitly authenticating with the API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmw7-gvx2-669j/GHSA-cmw7-gvx2-669j.json b/advisories/unreviewed/2022/05/GHSA-cmw7-gvx2-669j/GHSA-cmw7-gvx2-669j.json index 9f8348e2f25..b100ea191b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmw7-gvx2-669j/GHSA-cmw7-gvx2-669j.json +++ b/advisories/unreviewed/2022/05/GHSA-cmw7-gvx2-669j/GHSA-cmw7-gvx2-669j.json @@ -7,12 +7,8 @@ "CVE-2019-15287" ], "details": "Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cpwr-wq7c-j52h/GHSA-cpwr-wq7c-j52h.json b/advisories/unreviewed/2022/05/GHSA-cpwr-wq7c-j52h/GHSA-cpwr-wq7c-j52h.json index 4cc6c8d19b5..ec7e949c6f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpwr-wq7c-j52h/GHSA-cpwr-wq7c-j52h.json +++ b/advisories/unreviewed/2022/05/GHSA-cpwr-wq7c-j52h/GHSA-cpwr-wq7c-j52h.json @@ -7,12 +7,8 @@ "CVE-2020-24564" ], "details": "An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product.\n\nAn attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities.\n\nThe subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24565 and CVE-2020-25770. ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqf5-qhc8-4rwc/GHSA-cqf5-qhc8-4rwc.json b/advisories/unreviewed/2022/05/GHSA-cqf5-qhc8-4rwc/GHSA-cqf5-qhc8-4rwc.json index 6be55495959..4b683472937 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqf5-qhc8-4rwc/GHSA-cqf5-qhc8-4rwc.json +++ b/advisories/unreviewed/2022/05/GHSA-cqf5-qhc8-4rwc/GHSA-cqf5-qhc8-4rwc.json @@ -7,12 +7,8 @@ "CVE-2020-26115" ], "details": "cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqfw-4m38-g25j/GHSA-cqfw-4m38-g25j.json b/advisories/unreviewed/2022/05/GHSA-cqfw-4m38-g25j/GHSA-cqfw-4m38-g25j.json index e834bac5444..bba9412f629 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqfw-4m38-g25j/GHSA-cqfw-4m38-g25j.json +++ b/advisories/unreviewed/2022/05/GHSA-cqfw-4m38-g25j/GHSA-cqfw-4m38-g25j.json @@ -7,12 +7,8 @@ "CVE-2020-25141" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via a /device/device=140/tab=wifi/view= URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqhq-p5mr-mqvp/GHSA-cqhq-p5mr-mqvp.json b/advisories/unreviewed/2022/05/GHSA-cqhq-p5mr-mqvp/GHSA-cqhq-p5mr-mqvp.json index 91a13297786..a9d1b75d642 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqhq-p5mr-mqvp/GHSA-cqhq-p5mr-mqvp.json +++ b/advisories/unreviewed/2022/05/GHSA-cqhq-p5mr-mqvp/GHSA-cqhq-p5mr-mqvp.json @@ -7,12 +7,8 @@ "CVE-2020-15394" ], "details": "The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cw67-prcg-9fwq/GHSA-cw67-prcg-9fwq.json b/advisories/unreviewed/2022/05/GHSA-cw67-prcg-9fwq/GHSA-cw67-prcg-9fwq.json index cd00ae79d5a..46eeb43e97d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw67-prcg-9fwq/GHSA-cw67-prcg-9fwq.json +++ b/advisories/unreviewed/2022/05/GHSA-cw67-prcg-9fwq/GHSA-cw67-prcg-9fwq.json @@ -7,12 +7,8 @@ "CVE-2020-12869" ], "details": "RainbowFish PacsOne Server 6.8.4 allows XSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cxjq-pgg3-g955/GHSA-cxjq-pgg3-g955.json b/advisories/unreviewed/2022/05/GHSA-cxjq-pgg3-g955/GHSA-cxjq-pgg3-g955.json index fce8df9aef2..708cf232c73 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxjq-pgg3-g955/GHSA-cxjq-pgg3-g955.json +++ b/advisories/unreviewed/2022/05/GHSA-cxjq-pgg3-g955/GHSA-cxjq-pgg3-g955.json @@ -7,12 +7,8 @@ "CVE-2020-5976" ], "details": "NVIDIA GeForce NOW, versions prior to 2.0.23 (Windows, macOS) and versions prior to 5.31 (Android, Shield TV), contains a vulnerability in the application software where the network test component transmits sensitive information insecurely, which may lead to information disclosure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxw8-vqfr-fp3q/GHSA-cxw8-vqfr-fp3q.json b/advisories/unreviewed/2022/05/GHSA-cxw8-vqfr-fp3q/GHSA-cxw8-vqfr-fp3q.json index 86d7c51da2b..b366e7c9e7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxw8-vqfr-fp3q/GHSA-cxw8-vqfr-fp3q.json +++ b/advisories/unreviewed/2022/05/GHSA-cxw8-vqfr-fp3q/GHSA-cxw8-vqfr-fp3q.json @@ -7,12 +7,8 @@ "CVE-2020-26098" ], "details": "cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f2w3-rc23-j83q/GHSA-f2w3-rc23-j83q.json b/advisories/unreviewed/2022/05/GHSA-f2w3-rc23-j83q/GHSA-f2w3-rc23-j83q.json index daab9dc08c9..1d1131226a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2w3-rc23-j83q/GHSA-f2w3-rc23-j83q.json +++ b/advisories/unreviewed/2022/05/GHSA-f2w3-rc23-j83q/GHSA-f2w3-rc23-j83q.json @@ -7,12 +7,8 @@ "CVE-2020-11857" ], "details": "An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f384-j97r-h7rp/GHSA-f384-j97r-h7rp.json b/advisories/unreviewed/2022/05/GHSA-f384-j97r-h7rp/GHSA-f384-j97r-h7rp.json index 989b4b0dab2..60de5b3635c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f384-j97r-h7rp/GHSA-f384-j97r-h7rp.json +++ b/advisories/unreviewed/2022/05/GHSA-f384-j97r-h7rp/GHSA-f384-j97r-h7rp.json @@ -7,12 +7,8 @@ "CVE-2020-6542" ], "details": "Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f659-48hf-f7xc/GHSA-f659-48hf-f7xc.json b/advisories/unreviewed/2022/05/GHSA-f659-48hf-f7xc/GHSA-f659-48hf-f7xc.json index 7bdd8e7b7ff..c49da83620b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f659-48hf-f7xc/GHSA-f659-48hf-f7xc.json +++ b/advisories/unreviewed/2022/05/GHSA-f659-48hf-f7xc/GHSA-f659-48hf-f7xc.json @@ -7,12 +7,8 @@ "CVE-2020-25751" ], "details": "The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7qj-p2x6-5jf3/GHSA-f7qj-p2x6-5jf3.json b/advisories/unreviewed/2022/05/GHSA-f7qj-p2x6-5jf3/GHSA-f7qj-p2x6-5jf3.json index 18ff931a3e0..3ae3b27c7ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7qj-p2x6-5jf3/GHSA-f7qj-p2x6-5jf3.json +++ b/advisories/unreviewed/2022/05/GHSA-f7qj-p2x6-5jf3/GHSA-f7qj-p2x6-5jf3.json @@ -7,12 +7,8 @@ "CVE-2020-13322" ], "details": "A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f82x-wp92-p4mp/GHSA-f82x-wp92-p4mp.json b/advisories/unreviewed/2022/05/GHSA-f82x-wp92-p4mp/GHSA-f82x-wp92-p4mp.json index 81577800b16..da630d80c4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f82x-wp92-p4mp/GHSA-f82x-wp92-p4mp.json +++ b/advisories/unreviewed/2022/05/GHSA-f82x-wp92-p4mp/GHSA-f82x-wp92-p4mp.json @@ -7,12 +7,8 @@ "CVE-2020-24594" ], "details": "Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f98v-r833-rqxp/GHSA-f98v-r833-rqxp.json b/advisories/unreviewed/2022/05/GHSA-f98v-r833-rqxp/GHSA-f98v-r833-rqxp.json index fb2a78f795d..d25c1b385d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-f98v-r833-rqxp/GHSA-f98v-r833-rqxp.json +++ b/advisories/unreviewed/2022/05/GHSA-f98v-r833-rqxp/GHSA-f98v-r833-rqxp.json @@ -7,12 +7,8 @@ "CVE-2020-5606" ], "details": "Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary script via a specially crafted page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f98x-c9gw-37gm/GHSA-f98x-c9gw-37gm.json b/advisories/unreviewed/2022/05/GHSA-f98x-c9gw-37gm/GHSA-f98x-c9gw-37gm.json index e07af197317..db2237650c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-f98x-c9gw-37gm/GHSA-f98x-c9gw-37gm.json +++ b/advisories/unreviewed/2022/05/GHSA-f98x-c9gw-37gm/GHSA-f98x-c9gw-37gm.json @@ -7,12 +7,8 @@ "CVE-2020-4607" ], "details": "IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fc8c-p326-r92q/GHSA-fc8c-p326-r92q.json b/advisories/unreviewed/2022/05/GHSA-fc8c-p326-r92q/GHSA-fc8c-p326-r92q.json index d5a81917d54..ddaf886b2ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc8c-p326-r92q/GHSA-fc8c-p326-r92q.json +++ b/advisories/unreviewed/2022/05/GHSA-fc8c-p326-r92q/GHSA-fc8c-p326-r92q.json @@ -7,12 +7,8 @@ "CVE-2020-25826" ], "details": "PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fch3-5vmv-jh77/GHSA-fch3-5vmv-jh77.json b/advisories/unreviewed/2022/05/GHSA-fch3-5vmv-jh77/GHSA-fch3-5vmv-jh77.json index e81950384b0..3ac91cdde22 100644 --- a/advisories/unreviewed/2022/05/GHSA-fch3-5vmv-jh77/GHSA-fch3-5vmv-jh77.json +++ b/advisories/unreviewed/2022/05/GHSA-fch3-5vmv-jh77/GHSA-fch3-5vmv-jh77.json @@ -7,12 +7,8 @@ "CVE-2020-6561" ], "details": "Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ff9r-638x-qg3h/GHSA-ff9r-638x-qg3h.json b/advisories/unreviewed/2022/05/GHSA-ff9r-638x-qg3h/GHSA-ff9r-638x-qg3h.json index 6d5de7ae1f7..bc16b4d9a0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff9r-638x-qg3h/GHSA-ff9r-638x-qg3h.json +++ b/advisories/unreviewed/2022/05/GHSA-ff9r-638x-qg3h/GHSA-ff9r-638x-qg3h.json @@ -7,12 +7,8 @@ "CVE-2020-24565" ], "details": "An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product.\n\nAn attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities.\n\nThe subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25770. ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ffvc-r4fg-pj7f/GHSA-ffvc-r4fg-pj7f.json b/advisories/unreviewed/2022/05/GHSA-ffvc-r4fg-pj7f/GHSA-ffvc-r4fg-pj7f.json index 18e79fae84b..9d15faa9ac1 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffvc-r4fg-pj7f/GHSA-ffvc-r4fg-pj7f.json +++ b/advisories/unreviewed/2022/05/GHSA-ffvc-r4fg-pj7f/GHSA-ffvc-r4fg-pj7f.json @@ -7,12 +7,8 @@ "CVE-2019-15969" ], "details": "A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script or HTML code in the context of the interface, which could allow the attacker to gain access to sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fgh5-3w2j-x3v9/GHSA-fgh5-3w2j-x3v9.json b/advisories/unreviewed/2022/05/GHSA-fgh5-3w2j-x3v9/GHSA-fgh5-3w2j-x3v9.json index 1ad9ee843e2..fac07abf7a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgh5-3w2j-x3v9/GHSA-fgh5-3w2j-x3v9.json +++ b/advisories/unreviewed/2022/05/GHSA-fgh5-3w2j-x3v9/GHSA-fgh5-3w2j-x3v9.json @@ -7,12 +7,8 @@ "CVE-2020-12281" ], "details": "iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fhj6-r884-6jpv/GHSA-fhj6-r884-6jpv.json b/advisories/unreviewed/2022/05/GHSA-fhj6-r884-6jpv/GHSA-fhj6-r884-6jpv.json index 4b0861d9d03..7c93cd45398 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhj6-r884-6jpv/GHSA-fhj6-r884-6jpv.json +++ b/advisories/unreviewed/2022/05/GHSA-fhj6-r884-6jpv/GHSA-fhj6-r884-6jpv.json @@ -7,12 +7,8 @@ "CVE-2020-15675" ], "details": "When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 81.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fhwv-46g6-2r65/GHSA-fhwv-46g6-2r65.json b/advisories/unreviewed/2022/05/GHSA-fhwv-46g6-2r65/GHSA-fhwv-46g6-2r65.json index a384a7998b7..8535f3ae894 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhwv-46g6-2r65/GHSA-fhwv-46g6-2r65.json +++ b/advisories/unreviewed/2022/05/GHSA-fhwv-46g6-2r65/GHSA-fhwv-46g6-2r65.json @@ -7,12 +7,8 @@ "CVE-2020-0380" ], "details": "In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-146398979", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fm58-pfxp-rgh5/GHSA-fm58-pfxp-rgh5.json b/advisories/unreviewed/2022/05/GHSA-fm58-pfxp-rgh5/GHSA-fm58-pfxp-rgh5.json index 3845efe7ad0..2f5eaa183ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm58-pfxp-rgh5/GHSA-fm58-pfxp-rgh5.json +++ b/advisories/unreviewed/2022/05/GHSA-fm58-pfxp-rgh5/GHSA-fm58-pfxp-rgh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm6v-5q4c-8xxp/GHSA-fm6v-5q4c-8xxp.json b/advisories/unreviewed/2022/05/GHSA-fm6v-5q4c-8xxp/GHSA-fm6v-5q4c-8xxp.json index dfb46b291af..1ba96d5957d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm6v-5q4c-8xxp/GHSA-fm6v-5q4c-8xxp.json +++ b/advisories/unreviewed/2022/05/GHSA-fm6v-5q4c-8xxp/GHSA-fm6v-5q4c-8xxp.json @@ -7,12 +7,8 @@ "CVE-2020-25132" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. Sending the improper variable type Array allows a bypass of core SQL Injection sanitization. Users are able to inject malicious statements in multiple functions. This vulnerability leads to full authentication bypass: any unauthorized user with access to the application is able to exploit this vulnerability. This can occur via the Cookie header to the default URI, within includes/authenticate.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fm8v-3mq9-h889/GHSA-fm8v-3mq9-h889.json b/advisories/unreviewed/2022/05/GHSA-fm8v-3mq9-h889/GHSA-fm8v-3mq9-h889.json index 80751a33d3e..00e9a987ff0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm8v-3mq9-h889/GHSA-fm8v-3mq9-h889.json +++ b/advisories/unreviewed/2022/05/GHSA-fm8v-3mq9-h889/GHSA-fm8v-3mq9-h889.json @@ -7,12 +7,8 @@ "CVE-2020-13296" ], "details": "An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fmjp-4h8h-4q4c/GHSA-fmjp-4h8h-4q4c.json b/advisories/unreviewed/2022/05/GHSA-fmjp-4h8h-4q4c/GHSA-fmjp-4h8h-4q4c.json index b9ff430cd60..914c752e56d 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmjp-4h8h-4q4c/GHSA-fmjp-4h8h-4q4c.json +++ b/advisories/unreviewed/2022/05/GHSA-fmjp-4h8h-4q4c/GHSA-fmjp-4h8h-4q4c.json @@ -7,12 +7,8 @@ "CVE-2020-14293" ], "details": "conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fpcq-7xx3-h92j/GHSA-fpcq-7xx3-h92j.json b/advisories/unreviewed/2022/05/GHSA-fpcq-7xx3-h92j/GHSA-fpcq-7xx3-h92j.json index 7b8f9e971fa..435c9b1c3e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpcq-7xx3-h92j/GHSA-fpcq-7xx3-h92j.json +++ b/advisories/unreviewed/2022/05/GHSA-fpcq-7xx3-h92j/GHSA-fpcq-7xx3-h92j.json @@ -7,12 +7,8 @@ "CVE-2020-6540" ], "details": "Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fr6q-7f5x-r9m2/GHSA-fr6q-7f5x-r9m2.json b/advisories/unreviewed/2022/05/GHSA-fr6q-7f5x-r9m2/GHSA-fr6q-7f5x-r9m2.json index 3c0bb530f33..43434c14626 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr6q-7f5x-r9m2/GHSA-fr6q-7f5x-r9m2.json +++ b/advisories/unreviewed/2022/05/GHSA-fr6q-7f5x-r9m2/GHSA-fr6q-7f5x-r9m2.json @@ -7,12 +7,8 @@ "CVE-2020-25774" ], "details": "A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account.\n\nUser interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fv47-8pvw-qc6p/GHSA-fv47-8pvw-qc6p.json b/advisories/unreviewed/2022/05/GHSA-fv47-8pvw-qc6p/GHSA-fv47-8pvw-qc6p.json index f57e7b1292a..a2677f598db 100644 --- a/advisories/unreviewed/2022/05/GHSA-fv47-8pvw-qc6p/GHSA-fv47-8pvw-qc6p.json +++ b/advisories/unreviewed/2022/05/GHSA-fv47-8pvw-qc6p/GHSA-fv47-8pvw-qc6p.json @@ -7,12 +7,8 @@ "CVE-2020-12817" ], "details": "An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvcc-fp3f-7c6c/GHSA-fvcc-fp3f-7c6c.json b/advisories/unreviewed/2022/05/GHSA-fvcc-fp3f-7c6c/GHSA-fvcc-fp3f-7c6c.json index e363c204dd8..31ef58a9834 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvcc-fp3f-7c6c/GHSA-fvcc-fp3f-7c6c.json +++ b/advisories/unreviewed/2022/05/GHSA-fvcc-fp3f-7c6c/GHSA-fvcc-fp3f-7c6c.json @@ -7,12 +7,8 @@ "CVE-2020-13119" ], "details": "ismartgate PRO 1.5.9 is vulnerable to clickjacking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvm3-gwpp-ccgq/GHSA-fvm3-gwpp-ccgq.json b/advisories/unreviewed/2022/05/GHSA-fvm3-gwpp-ccgq/GHSA-fvm3-gwpp-ccgq.json index d5245c53d58..e9134077d99 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvm3-gwpp-ccgq/GHSA-fvm3-gwpp-ccgq.json +++ b/advisories/unreviewed/2022/05/GHSA-fvm3-gwpp-ccgq/GHSA-fvm3-gwpp-ccgq.json @@ -7,12 +7,8 @@ "CVE-2020-15958" ], "details": "An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvqv-8686-3678/GHSA-fvqv-8686-3678.json b/advisories/unreviewed/2022/05/GHSA-fvqv-8686-3678/GHSA-fvqv-8686-3678.json index 68528637081..2d913f821d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvqv-8686-3678/GHSA-fvqv-8686-3678.json +++ b/advisories/unreviewed/2022/05/GHSA-fvqv-8686-3678/GHSA-fvqv-8686-3678.json @@ -7,12 +7,8 @@ "CVE-2020-15960" ], "details": "Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw54-qvjj-883j/GHSA-fw54-qvjj-883j.json b/advisories/unreviewed/2022/05/GHSA-fw54-qvjj-883j/GHSA-fw54-qvjj-883j.json index e1842d7cc46..33fd5d980db 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw54-qvjj-883j/GHSA-fw54-qvjj-883j.json +++ b/advisories/unreviewed/2022/05/GHSA-fw54-qvjj-883j/GHSA-fw54-qvjj-883j.json @@ -7,12 +7,8 @@ "CVE-2020-4731" ], "details": "IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188055.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwcm-6pr4-2759/GHSA-fwcm-6pr4-2759.json b/advisories/unreviewed/2022/05/GHSA-fwcm-6pr4-2759/GHSA-fwcm-6pr4-2759.json index e7d6416b186..20a366aa01f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwcm-6pr4-2759/GHSA-fwcm-6pr4-2759.json +++ b/advisories/unreviewed/2022/05/GHSA-fwcm-6pr4-2759/GHSA-fwcm-6pr4-2759.json @@ -7,12 +7,8 @@ "CVE-2020-0311" ], "details": "In InputManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153878642", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g479-6ppw-v22h/GHSA-g479-6ppw-v22h.json b/advisories/unreviewed/2022/05/GHSA-g479-6ppw-v22h/GHSA-g479-6ppw-v22h.json index 323da3437ac..36817570be2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g479-6ppw-v22h/GHSA-g479-6ppw-v22h.json +++ b/advisories/unreviewed/2022/05/GHSA-g479-6ppw-v22h/GHSA-g479-6ppw-v22h.json @@ -7,12 +7,8 @@ "CVE-2020-3133" ], "details": "A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper validation of incoming emails. An attacker could exploit this vulnerability by sending a crafted email message to a recipient protected by the ESA. A successful exploit could allow the attacker to bypass the configured content filters, which could allow malicious content to pass through the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g5hg-2j49-6fg6/GHSA-g5hg-2j49-6fg6.json b/advisories/unreviewed/2022/05/GHSA-g5hg-2j49-6fg6/GHSA-g5hg-2j49-6fg6.json index a44b0280e22..bc21c1d11d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5hg-2j49-6fg6/GHSA-g5hg-2j49-6fg6.json +++ b/advisories/unreviewed/2022/05/GHSA-g5hg-2j49-6fg6/GHSA-g5hg-2j49-6fg6.json @@ -7,12 +7,8 @@ "CVE-2020-3487" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit these vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5x2-f83w-r4hx/GHSA-g5x2-f83w-r4hx.json b/advisories/unreviewed/2022/05/GHSA-g5x2-f83w-r4hx/GHSA-g5x2-f83w-r4hx.json index 377b0cd0910..89b7a61eb13 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5x2-f83w-r4hx/GHSA-g5x2-f83w-r4hx.json +++ b/advisories/unreviewed/2022/05/GHSA-g5x2-f83w-r4hx/GHSA-g5x2-f83w-r4hx.json @@ -7,12 +7,8 @@ "CVE-2020-6543" ], "details": "Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g6j5-56jr-gpvw/GHSA-g6j5-56jr-gpvw.json b/advisories/unreviewed/2022/05/GHSA-g6j5-56jr-gpvw/GHSA-g6j5-56jr-gpvw.json index 973edfc805b..c503d1326a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6j5-56jr-gpvw/GHSA-g6j5-56jr-gpvw.json +++ b/advisories/unreviewed/2022/05/GHSA-g6j5-56jr-gpvw/GHSA-g6j5-56jr-gpvw.json @@ -7,12 +7,8 @@ "CVE-2020-25772" ], "details": "An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product.\n\nAn attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities.\n\nThe subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25771. ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g73j-h828-gg82/GHSA-g73j-h828-gg82.json b/advisories/unreviewed/2022/05/GHSA-g73j-h828-gg82/GHSA-g73j-h828-gg82.json index 17361d01997..7284c156794 100644 --- a/advisories/unreviewed/2022/05/GHSA-g73j-h828-gg82/GHSA-g73j-h828-gg82.json +++ b/advisories/unreviewed/2022/05/GHSA-g73j-h828-gg82/GHSA-g73j-h828-gg82.json @@ -7,12 +7,8 @@ "CVE-2020-24718" ], "details": "bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g87g-jrfr-qxmg/GHSA-g87g-jrfr-qxmg.json b/advisories/unreviewed/2022/05/GHSA-g87g-jrfr-qxmg/GHSA-g87g-jrfr-qxmg.json index 76eb1cf0b8d..897ab5da1ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-g87g-jrfr-qxmg/GHSA-g87g-jrfr-qxmg.json +++ b/advisories/unreviewed/2022/05/GHSA-g87g-jrfr-qxmg/GHSA-g87g-jrfr-qxmg.json @@ -7,12 +7,8 @@ "CVE-2020-0301" ], "details": "In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124940460", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g8jr-fhmg-4fr5/GHSA-g8jr-fhmg-4fr5.json b/advisories/unreviewed/2022/05/GHSA-g8jr-fhmg-4fr5/GHSA-g8jr-fhmg-4fr5.json index 696ca861bf2..1c0d21ef97c 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8jr-fhmg-4fr5/GHSA-g8jr-fhmg-4fr5.json +++ b/advisories/unreviewed/2022/05/GHSA-g8jr-fhmg-4fr5/GHSA-g8jr-fhmg-4fr5.json @@ -7,12 +7,8 @@ "CVE-2020-0340" ], "details": "In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144901522", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g97r-rvqc-x2fm/GHSA-g97r-rvqc-x2fm.json b/advisories/unreviewed/2022/05/GHSA-g97r-rvqc-x2fm/GHSA-g97r-rvqc-x2fm.json index 7346a760bec..588ffe97d35 100644 --- a/advisories/unreviewed/2022/05/GHSA-g97r-rvqc-x2fm/GHSA-g97r-rvqc-x2fm.json +++ b/advisories/unreviewed/2022/05/GHSA-g97r-rvqc-x2fm/GHSA-g97r-rvqc-x2fm.json @@ -7,12 +7,8 @@ "CVE-2020-3426" ], "details": "A vulnerability in the implementation of the Low Power, Wide Area (LPWA) subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data or cause a denial of service (DoS) condition. The vulnerability is due to a lack of input and validation checking mechanisms for virtual-LPWA (VLPWA) protocol modem messages. An attacker could exploit this vulnerability by supplying crafted packets to an affected device. A successful exploit could allow the attacker to gain unauthorized read access to sensitive data or cause the VLPWA interface of the affected device to shut down, resulting in DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gcjv-q27m-w6qm/GHSA-gcjv-q27m-w6qm.json b/advisories/unreviewed/2022/05/GHSA-gcjv-q27m-w6qm/GHSA-gcjv-q27m-w6qm.json index 52188c66f89..34a9d835981 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcjv-q27m-w6qm/GHSA-gcjv-q27m-w6qm.json +++ b/advisories/unreviewed/2022/05/GHSA-gcjv-q27m-w6qm/GHSA-gcjv-q27m-w6qm.json @@ -7,12 +7,8 @@ "CVE-2020-13168" ], "details": "SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gff7-q4h3-6x9j/GHSA-gff7-q4h3-6x9j.json b/advisories/unreviewed/2022/05/GHSA-gff7-q4h3-6x9j/GHSA-gff7-q4h3-6x9j.json index f36982ecea4..24f42d88371 100644 --- a/advisories/unreviewed/2022/05/GHSA-gff7-q4h3-6x9j/GHSA-gff7-q4h3-6x9j.json +++ b/advisories/unreviewed/2022/05/GHSA-gff7-q4h3-6x9j/GHSA-gff7-q4h3-6x9j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gfhr-vq5v-8r6m/GHSA-gfhr-vq5v-8r6m.json b/advisories/unreviewed/2022/05/GHSA-gfhr-vq5v-8r6m/GHSA-gfhr-vq5v-8r6m.json index d072e2a4d60..57634f4cdfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-gfhr-vq5v-8r6m/GHSA-gfhr-vq5v-8r6m.json +++ b/advisories/unreviewed/2022/05/GHSA-gfhr-vq5v-8r6m/GHSA-gfhr-vq5v-8r6m.json @@ -7,12 +7,8 @@ "CVE-2020-25771" ], "details": "An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product.\n\nAn attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities.\n\nThe subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25770. ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ggrp-mmv9-mmpc/GHSA-ggrp-mmv9-mmpc.json b/advisories/unreviewed/2022/05/GHSA-ggrp-mmv9-mmpc/GHSA-ggrp-mmv9-mmpc.json index c84ec1545e4..814c9aa3a58 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggrp-mmv9-mmpc/GHSA-ggrp-mmv9-mmpc.json +++ b/advisories/unreviewed/2022/05/GHSA-ggrp-mmv9-mmpc/GHSA-ggrp-mmv9-mmpc.json @@ -7,12 +7,8 @@ "CVE-2020-25761" ], "details": "Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive information etc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ghcw-jqxh-fxcc/GHSA-ghcw-jqxh-fxcc.json b/advisories/unreviewed/2022/05/GHSA-ghcw-jqxh-fxcc/GHSA-ghcw-jqxh-fxcc.json index 8306f58beb3..14067acfc6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghcw-jqxh-fxcc/GHSA-ghcw-jqxh-fxcc.json +++ b/advisories/unreviewed/2022/05/GHSA-ghcw-jqxh-fxcc/GHSA-ghcw-jqxh-fxcc.json @@ -7,12 +7,8 @@ "CVE-2020-15731" ], "details": "An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefender Engines versions prior to 7.85448.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ghg2-6xj5-w4cg/GHSA-ghg2-6xj5-w4cg.json b/advisories/unreviewed/2022/05/GHSA-ghg2-6xj5-w4cg/GHSA-ghg2-6xj5-w4cg.json index d50ad34e5c5..be1cc611d20 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghg2-6xj5-w4cg/GHSA-ghg2-6xj5-w4cg.json +++ b/advisories/unreviewed/2022/05/GHSA-ghg2-6xj5-w4cg/GHSA-ghg2-6xj5-w4cg.json @@ -7,12 +7,8 @@ "CVE-2020-0359" ], "details": "In GLESRenderEngine, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150303018", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gjg4-p49j-8pwc/GHSA-gjg4-p49j-8pwc.json b/advisories/unreviewed/2022/05/GHSA-gjg4-p49j-8pwc/GHSA-gjg4-p49j-8pwc.json index 0f041918a4b..67503fb6a80 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjg4-p49j-8pwc/GHSA-gjg4-p49j-8pwc.json +++ b/advisories/unreviewed/2022/05/GHSA-gjg4-p49j-8pwc/GHSA-gjg4-p49j-8pwc.json @@ -7,12 +7,8 @@ "CVE-2020-15373" ], "details": "Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c could allow remote unauthenticated attackers to perform various attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjmc-f7wf-pjp6/GHSA-gjmc-f7wf-pjp6.json b/advisories/unreviewed/2022/05/GHSA-gjmc-f7wf-pjp6/GHSA-gjmc-f7wf-pjp6.json index dda96b443fb..91a4ea539e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjmc-f7wf-pjp6/GHSA-gjmc-f7wf-pjp6.json +++ b/advisories/unreviewed/2022/05/GHSA-gjmc-f7wf-pjp6/GHSA-gjmc-f7wf-pjp6.json @@ -7,12 +7,8 @@ "CVE-2019-19199" ], "details": "REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gmmw-m27p-f77m/GHSA-gmmw-m27p-f77m.json b/advisories/unreviewed/2022/05/GHSA-gmmw-m27p-f77m/GHSA-gmmw-m27p-f77m.json index 5483ad742a1..d50f5b4e669 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmmw-m27p-f77m/GHSA-gmmw-m27p-f77m.json +++ b/advisories/unreviewed/2022/05/GHSA-gmmw-m27p-f77m/GHSA-gmmw-m27p-f77m.json @@ -7,12 +7,8 @@ "CVE-2020-25729" ], "details": "ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gpc6-hwvp-975x/GHSA-gpc6-hwvp-975x.json b/advisories/unreviewed/2022/05/GHSA-gpc6-hwvp-975x/GHSA-gpc6-hwvp-975x.json index 72ce789a856..33de495b46d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gpc6-hwvp-975x/GHSA-gpc6-hwvp-975x.json +++ b/advisories/unreviewed/2022/05/GHSA-gpc6-hwvp-975x/GHSA-gpc6-hwvp-975x.json @@ -7,12 +7,8 @@ "CVE-2020-25747" ], "details": "The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightness, clarity, time), restart the camera, or reset it to factory settings.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gq2x-qfg4-6326/GHSA-gq2x-qfg4-6326.json b/advisories/unreviewed/2022/05/GHSA-gq2x-qfg4-6326/GHSA-gq2x-qfg4-6326.json index 53f3a04192f..cecce3dc9a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-gq2x-qfg4-6326/GHSA-gq2x-qfg4-6326.json +++ b/advisories/unreviewed/2022/05/GHSA-gq2x-qfg4-6326/GHSA-gq2x-qfg4-6326.json @@ -7,12 +7,8 @@ "CVE-2020-25148" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. this can occur via /iftype/type= because of pages/iftype.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr9p-7jvx-9fcg/GHSA-gr9p-7jvx-9fcg.json b/advisories/unreviewed/2022/05/GHSA-gr9p-7jvx-9fcg/GHSA-gr9p-7jvx-9fcg.json index 284189dcf00..afc214f328d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr9p-7jvx-9fcg/GHSA-gr9p-7jvx-9fcg.json +++ b/advisories/unreviewed/2022/05/GHSA-gr9p-7jvx-9fcg/GHSA-gr9p-7jvx-9fcg.json @@ -7,12 +7,8 @@ "CVE-2020-0397" ], "details": "In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-155092443", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grfw-w735-79q7/GHSA-grfw-w735-79q7.json b/advisories/unreviewed/2022/05/GHSA-grfw-w735-79q7/GHSA-grfw-w735-79q7.json index 3cb2b3c1a49..fd69c0af1dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-grfw-w735-79q7/GHSA-grfw-w735-79q7.json +++ b/advisories/unreviewed/2022/05/GHSA-grfw-w735-79q7/GHSA-grfw-w735-79q7.json @@ -7,12 +7,8 @@ "CVE-2020-0363" ], "details": "In libmedia, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-132274514", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-grm4-j278-7rj2/GHSA-grm4-j278-7rj2.json b/advisories/unreviewed/2022/05/GHSA-grm4-j278-7rj2/GHSA-grm4-j278-7rj2.json index cae13b5aa95..4be970cc3f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-grm4-j278-7rj2/GHSA-grm4-j278-7rj2.json +++ b/advisories/unreviewed/2022/05/GHSA-grm4-j278-7rj2/GHSA-grm4-j278-7rj2.json @@ -7,12 +7,8 @@ "CVE-2020-4621" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization checks. IBM X-Force ID: 184981.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gw48-m95c-mfcg/GHSA-gw48-m95c-mfcg.json b/advisories/unreviewed/2022/05/GHSA-gw48-m95c-mfcg/GHSA-gw48-m95c-mfcg.json index 48d50dcd02b..9e7e2b61e4c 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw48-m95c-mfcg/GHSA-gw48-m95c-mfcg.json +++ b/advisories/unreviewed/2022/05/GHSA-gw48-m95c-mfcg/GHSA-gw48-m95c-mfcg.json @@ -7,12 +7,8 @@ "CVE-2020-0295" ], "details": "In Telecom, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155650969", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxcr-5j23-36ww/GHSA-gxcr-5j23-36ww.json b/advisories/unreviewed/2022/05/GHSA-gxcr-5j23-36ww/GHSA-gxcr-5j23-36ww.json index 0fd5fa39a7d..c677a3bdeca 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxcr-5j23-36ww/GHSA-gxcr-5j23-36ww.json +++ b/advisories/unreviewed/2022/05/GHSA-gxcr-5j23-36ww/GHSA-gxcr-5j23-36ww.json @@ -7,12 +7,8 @@ "CVE-2019-15283" ], "details": "Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gxh6-66gr-m9jm/GHSA-gxh6-66gr-m9jm.json b/advisories/unreviewed/2022/05/GHSA-gxh6-66gr-m9jm/GHSA-gxh6-66gr-m9jm.json index c22b9ca7c73..64f4910158f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxh6-66gr-m9jm/GHSA-gxh6-66gr-m9jm.json +++ b/advisories/unreviewed/2022/05/GHSA-gxh6-66gr-m9jm/GHSA-gxh6-66gr-m9jm.json @@ -7,12 +7,8 @@ "CVE-2020-5783" ], "details": "In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2mq-xrr7-hwv8/GHSA-h2mq-xrr7-hwv8.json b/advisories/unreviewed/2022/05/GHSA-h2mq-xrr7-hwv8/GHSA-h2mq-xrr7-hwv8.json index e3c04f58e5a..b1bf0bfc912 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2mq-xrr7-hwv8/GHSA-h2mq-xrr7-hwv8.json +++ b/advisories/unreviewed/2022/05/GHSA-h2mq-xrr7-hwv8/GHSA-h2mq-xrr7-hwv8.json @@ -7,12 +7,8 @@ "CVE-2020-26120" ], "details": "XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from PageGateway. Using crafted HTML, an attacker can elicit an XSS attack via jQuery's parseHTML method, which can cause image callbacks to fire even without the element being appended to the DOM.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h52m-3w75-qf28/GHSA-h52m-3w75-qf28.json b/advisories/unreviewed/2022/05/GHSA-h52m-3w75-qf28/GHSA-h52m-3w75-qf28.json index 59fcf673177..8f32b505e37 100644 --- a/advisories/unreviewed/2022/05/GHSA-h52m-3w75-qf28/GHSA-h52m-3w75-qf28.json +++ b/advisories/unreviewed/2022/05/GHSA-h52m-3w75-qf28/GHSA-h52m-3w75-qf28.json @@ -7,12 +7,8 @@ "CVE-2019-16025" ], "details": "A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of some parameters that are passed to the web server of the affected software. An attacker could exploit this vulnerability by persuading a user to access a malicious link or by intercepting a user request for the affected web interface and injecting malicious code into that request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web-based management interface or access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5q7-898h-rfv7/GHSA-h5q7-898h-rfv7.json b/advisories/unreviewed/2022/05/GHSA-h5q7-898h-rfv7/GHSA-h5q7-898h-rfv7.json index 16f7e204969..624cbd528d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5q7-898h-rfv7/GHSA-h5q7-898h-rfv7.json +++ b/advisories/unreviewed/2022/05/GHSA-h5q7-898h-rfv7/GHSA-h5q7-898h-rfv7.json @@ -7,12 +7,8 @@ "CVE-2020-0433" ], "details": "In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-151939299", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h623-hg85-6ph3/GHSA-h623-hg85-6ph3.json b/advisories/unreviewed/2022/05/GHSA-h623-hg85-6ph3/GHSA-h623-hg85-6ph3.json index c41c7f0d041..65001ebfcc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h623-hg85-6ph3/GHSA-h623-hg85-6ph3.json +++ b/advisories/unreviewed/2022/05/GHSA-h623-hg85-6ph3/GHSA-h623-hg85-6ph3.json @@ -7,12 +7,8 @@ "CVE-2020-15374" ], "details": "Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instances of reflected input.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h64v-cgrg-w33r/GHSA-h64v-cgrg-w33r.json b/advisories/unreviewed/2022/05/GHSA-h64v-cgrg-w33r/GHSA-h64v-cgrg-w33r.json index a2fc422a78b..4257a5cce29 100644 --- a/advisories/unreviewed/2022/05/GHSA-h64v-cgrg-w33r/GHSA-h64v-cgrg-w33r.json +++ b/advisories/unreviewed/2022/05/GHSA-h64v-cgrg-w33r/GHSA-h64v-cgrg-w33r.json @@ -7,12 +7,8 @@ "CVE-2020-0317" ], "details": "In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119671929", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h64x-c3g5-hw7j/GHSA-h64x-c3g5-hw7j.json b/advisories/unreviewed/2022/05/GHSA-h64x-c3g5-hw7j/GHSA-h64x-c3g5-hw7j.json index 4b4f7faf9b3..aacba5104c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-h64x-c3g5-hw7j/GHSA-h64x-c3g5-hw7j.json +++ b/advisories/unreviewed/2022/05/GHSA-h64x-c3g5-hw7j/GHSA-h64x-c3g5-hw7j.json @@ -7,12 +7,8 @@ "CVE-2020-3494" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit these vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6wp-6m5m-gc8m/GHSA-h6wp-6m5m-gc8m.json b/advisories/unreviewed/2022/05/GHSA-h6wp-6m5m-gc8m/GHSA-h6wp-6m5m-gc8m.json index 4ce4856a323..aa003cab2e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6wp-6m5m-gc8m/GHSA-h6wp-6m5m-gc8m.json +++ b/advisories/unreviewed/2022/05/GHSA-h6wp-6m5m-gc8m/GHSA-h6wp-6m5m-gc8m.json @@ -7,12 +7,8 @@ "CVE-2020-15604" ], "details": "An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-494: Update files are not properly verified.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7cc-v8qr-8733/GHSA-h7cc-v8qr-8733.json b/advisories/unreviewed/2022/05/GHSA-h7cc-v8qr-8733/GHSA-h7cc-v8qr-8733.json index c18355282cd..8da812f079c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7cc-v8qr-8733/GHSA-h7cc-v8qr-8733.json +++ b/advisories/unreviewed/2022/05/GHSA-h7cc-v8qr-8733/GHSA-h7cc-v8qr-8733.json @@ -7,12 +7,8 @@ "CVE-2020-6571" ], "details": "Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7j2-q7w6-j3r4/GHSA-h7j2-q7w6-j3r4.json b/advisories/unreviewed/2022/05/GHSA-h7j2-q7w6-j3r4/GHSA-h7j2-q7w6-j3r4.json index 8ad0491841b..07a952cb856 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7j2-q7w6-j3r4/GHSA-h7j2-q7w6-j3r4.json +++ b/advisories/unreviewed/2022/05/GHSA-h7j2-q7w6-j3r4/GHSA-h7j2-q7w6-j3r4.json @@ -7,12 +7,8 @@ "CVE-2020-24595" ], "details": "Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7mg-9xr4-w524/GHSA-h7mg-9xr4-w524.json b/advisories/unreviewed/2022/05/GHSA-h7mg-9xr4-w524/GHSA-h7mg-9xr4-w524.json index 26bb1f1ad2e..1b2a9aff33f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7mg-9xr4-w524/GHSA-h7mg-9xr4-w524.json +++ b/advisories/unreviewed/2022/05/GHSA-h7mg-9xr4-w524/GHSA-h7mg-9xr4-w524.json @@ -7,12 +7,8 @@ "CVE-2020-12843" ], "details": "ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h8fx-4qrr-fwv4/GHSA-h8fx-4qrr-fwv4.json b/advisories/unreviewed/2022/05/GHSA-h8fx-4qrr-fwv4/GHSA-h8fx-4qrr-fwv4.json index 62f9f29d4d5..1554bda827b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8fx-4qrr-fwv4/GHSA-h8fx-4qrr-fwv4.json +++ b/advisories/unreviewed/2022/05/GHSA-h8fx-4qrr-fwv4/GHSA-h8fx-4qrr-fwv4.json @@ -7,12 +7,8 @@ "CVE-2020-12839" ], "details": "ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8pg-xg8h-5pgp/GHSA-h8pg-xg8h-5pgp.json b/advisories/unreviewed/2022/05/GHSA-h8pg-xg8h-5pgp/GHSA-h8pg-xg8h-5pgp.json index b812b525c7f..3e5d84f6ef4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8pg-xg8h-5pgp/GHSA-h8pg-xg8h-5pgp.json +++ b/advisories/unreviewed/2022/05/GHSA-h8pg-xg8h-5pgp/GHSA-h8pg-xg8h-5pgp.json @@ -7,12 +7,8 @@ "CVE-2020-14390" ], "details": "A flaw was found in the Linux kernel in versions from 2.2.3 through 5.9.rc5. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. This highest threat from this vulnerability is to system availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h8qw-537m-557p/GHSA-h8qw-537m-557p.json b/advisories/unreviewed/2022/05/GHSA-h8qw-537m-557p/GHSA-h8qw-537m-557p.json index 5632d80d506..322072c9fee 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8qw-537m-557p/GHSA-h8qw-537m-557p.json +++ b/advisories/unreviewed/2022/05/GHSA-h8qw-537m-557p/GHSA-h8qw-537m-557p.json @@ -7,12 +7,8 @@ "CVE-2020-19455" ], "details": "SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h946-qqgh-qhrr/GHSA-h946-qqgh-qhrr.json b/advisories/unreviewed/2022/05/GHSA-h946-qqgh-qhrr/GHSA-h946-qqgh-qhrr.json index 483870b56b1..e2039ae22e5 100644 --- a/advisories/unreviewed/2022/05/GHSA-h946-qqgh-qhrr/GHSA-h946-qqgh-qhrr.json +++ b/advisories/unreviewed/2022/05/GHSA-h946-qqgh-qhrr/GHSA-h946-qqgh-qhrr.json @@ -7,12 +7,8 @@ "CVE-2020-12818" ], "details": "An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hc9r-cpm8-5cfw/GHSA-hc9r-cpm8-5cfw.json b/advisories/unreviewed/2022/05/GHSA-hc9r-cpm8-5cfw/GHSA-hc9r-cpm8-5cfw.json index fb568b6ac20..f71b869bb20 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc9r-cpm8-5cfw/GHSA-hc9r-cpm8-5cfw.json +++ b/advisories/unreviewed/2022/05/GHSA-hc9r-cpm8-5cfw/GHSA-hc9r-cpm8-5cfw.json @@ -7,12 +7,8 @@ "CVE-2020-0312" ], "details": "In Battery Saver, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153879099", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg22-m783-x52v/GHSA-hg22-m783-x52v.json b/advisories/unreviewed/2022/05/GHSA-hg22-m783-x52v/GHSA-hg22-m783-x52v.json index 121fc1e01ac..741fa32e519 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg22-m783-x52v/GHSA-hg22-m783-x52v.json +++ b/advisories/unreviewed/2022/05/GHSA-hg22-m783-x52v/GHSA-hg22-m783-x52v.json @@ -7,12 +7,8 @@ "CVE-2020-25762" ], "details": "An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hgrr-pqhr-c6c6/GHSA-hgrr-pqhr-c6c6.json b/advisories/unreviewed/2022/05/GHSA-hgrr-pqhr-c6c6/GHSA-hgrr-pqhr-c6c6.json index 93778fcde74..e4111eb2aaf 100644 --- a/advisories/unreviewed/2022/05/GHSA-hgrr-pqhr-c6c6/GHSA-hgrr-pqhr-c6c6.json +++ b/advisories/unreviewed/2022/05/GHSA-hgrr-pqhr-c6c6/GHSA-hgrr-pqhr-c6c6.json @@ -7,12 +7,8 @@ "CVE-2020-13260" ], "details": "A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in Configuration-Services-Security-OpenVPN-Config or as the static key file in Configuration-Services-Security-OpenVPN-Static Keys. This payload will execute each time a user opens an affected web page. This could be exploited in conjunction with CVE-2020-13259.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjjw-r3wm-fv67/GHSA-hjjw-r3wm-fv67.json b/advisories/unreviewed/2022/05/GHSA-hjjw-r3wm-fv67/GHSA-hjjw-r3wm-fv67.json index 5462398bc41..290ea90403e 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjjw-r3wm-fv67/GHSA-hjjw-r3wm-fv67.json +++ b/advisories/unreviewed/2022/05/GHSA-hjjw-r3wm-fv67/GHSA-hjjw-r3wm-fv67.json @@ -7,12 +7,8 @@ "CVE-2020-24397" ], "details": "An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hmpx-xg9m-66vp/GHSA-hmpx-xg9m-66vp.json b/advisories/unreviewed/2022/05/GHSA-hmpx-xg9m-66vp/GHSA-hmpx-xg9m-66vp.json index e12574249a9..7e8024c6b4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmpx-xg9m-66vp/GHSA-hmpx-xg9m-66vp.json +++ b/advisories/unreviewed/2022/05/GHSA-hmpx-xg9m-66vp/GHSA-hmpx-xg9m-66vp.json @@ -7,12 +7,8 @@ "CVE-2020-0288" ], "details": "In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153995991", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hpxx-cq4g-w5wr/GHSA-hpxx-cq4g-w5wr.json b/advisories/unreviewed/2022/05/GHSA-hpxx-cq4g-w5wr/GHSA-hpxx-cq4g-w5wr.json index ecd21449603..3ec0cf03331 100644 --- a/advisories/unreviewed/2022/05/GHSA-hpxx-cq4g-w5wr/GHSA-hpxx-cq4g-w5wr.json +++ b/advisories/unreviewed/2022/05/GHSA-hpxx-cq4g-w5wr/GHSA-hpxx-cq4g-w5wr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hr8v-c379-cg85/GHSA-hr8v-c379-cg85.json b/advisories/unreviewed/2022/05/GHSA-hr8v-c379-cg85/GHSA-hr8v-c379-cg85.json index d8a4baa0fab..b8a345c66f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr8v-c379-cg85/GHSA-hr8v-c379-cg85.json +++ b/advisories/unreviewed/2022/05/GHSA-hr8v-c379-cg85/GHSA-hr8v-c379-cg85.json @@ -7,12 +7,8 @@ "CVE-2020-6550" ], "details": "Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hr95-cqm5-95mg/GHSA-hr95-cqm5-95mg.json b/advisories/unreviewed/2022/05/GHSA-hr95-cqm5-95mg/GHSA-hr95-cqm5-95mg.json index befdb071af5..6df617ad84c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr95-cqm5-95mg/GHSA-hr95-cqm5-95mg.json +++ b/advisories/unreviewed/2022/05/GHSA-hr95-cqm5-95mg/GHSA-hr95-cqm5-95mg.json @@ -7,12 +7,8 @@ "CVE-2020-3552" ], "details": "A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting as a wired client to the Ethernet interface of an affected device and sending a series of specific packets within a short time frame. A successful exploit could allow the attacker to cause a NULL pointer access that results in a reload of the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrgj-3q96-r6rq/GHSA-hrgj-3q96-r6rq.json b/advisories/unreviewed/2022/05/GHSA-hrgj-3q96-r6rq/GHSA-hrgj-3q96-r6rq.json index b687a2c9ad7..056188595c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrgj-3q96-r6rq/GHSA-hrgj-3q96-r6rq.json +++ b/advisories/unreviewed/2022/05/GHSA-hrgj-3q96-r6rq/GHSA-hrgj-3q96-r6rq.json @@ -7,12 +7,8 @@ "CVE-2020-26150" ], "details": "info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hw8h-69vc-mwx3/GHSA-hw8h-69vc-mwx3.json b/advisories/unreviewed/2022/05/GHSA-hw8h-69vc-mwx3/GHSA-hw8h-69vc-mwx3.json index d86db271db1..0f16e95b78f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hw8h-69vc-mwx3/GHSA-hw8h-69vc-mwx3.json +++ b/advisories/unreviewed/2022/05/GHSA-hw8h-69vc-mwx3/GHSA-hw8h-69vc-mwx3.json @@ -7,12 +7,8 @@ "CVE-2020-3493" ], "details": "Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit these vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwj3-4q8p-jhpm/GHSA-hwj3-4q8p-jhpm.json b/advisories/unreviewed/2022/05/GHSA-hwj3-4q8p-jhpm/GHSA-hwj3-4q8p-jhpm.json index c9479cda76b..f1cb525d627 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwj3-4q8p-jhpm/GHSA-hwj3-4q8p-jhpm.json +++ b/advisories/unreviewed/2022/05/GHSA-hwj3-4q8p-jhpm/GHSA-hwj3-4q8p-jhpm.json @@ -7,12 +7,8 @@ "CVE-2020-25766" ], "details": "An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwvf-grj2-9364/GHSA-hwvf-grj2-9364.json b/advisories/unreviewed/2022/05/GHSA-hwvf-grj2-9364/GHSA-hwvf-grj2-9364.json index 22ccdc1362e..4bc6269699f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwvf-grj2-9364/GHSA-hwvf-grj2-9364.json +++ b/advisories/unreviewed/2022/05/GHSA-hwvf-grj2-9364/GHSA-hwvf-grj2-9364.json @@ -7,12 +7,8 @@ "CVE-2020-3390" ], "details": "A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to the lack of input validation of the information used to generate an SNMP trap in relation to a wireless client connection. An attacker could exploit this vulnerability by sending an 802.1x packet with crafted parameters during the wireless authentication setup phase of a connection. A successful exploit could allow the attacker to cause the device to reload, causing a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx2m-2hr2-8gjh/GHSA-hx2m-2hr2-8gjh.json b/advisories/unreviewed/2022/05/GHSA-hx2m-2hr2-8gjh/GHSA-hx2m-2hr2-8gjh.json index 5e3146d0267..119efa1cbc3 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx2m-2hr2-8gjh/GHSA-hx2m-2hr2-8gjh.json +++ b/advisories/unreviewed/2022/05/GHSA-hx2m-2hr2-8gjh/GHSA-hx2m-2hr2-8gjh.json @@ -7,12 +7,8 @@ "CVE-2019-15963" ], "details": "A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management interface of the affected software. The vulnerability is due to insufficient protection of user-supplied input by the web-based management interface of the affected service. An attacker could exploit this vulnerability by accessing the interface and viewing restricted portions of the software configuration. A successful exploit could allow the attacker to gain access to sensitive information or conduct further attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j2m6-qgr7-3354/GHSA-j2m6-qgr7-3354.json b/advisories/unreviewed/2022/05/GHSA-j2m6-qgr7-3354/GHSA-j2m6-qgr7-3354.json index afb20e7317c..aa5cbc2d553 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2m6-qgr7-3354/GHSA-j2m6-qgr7-3354.json +++ b/advisories/unreviewed/2022/05/GHSA-j2m6-qgr7-3354/GHSA-j2m6-qgr7-3354.json @@ -7,12 +7,8 @@ "CVE-2020-15966" ], "details": "Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j55q-wc55-chv4/GHSA-j55q-wc55-chv4.json b/advisories/unreviewed/2022/05/GHSA-j55q-wc55-chv4/GHSA-j55q-wc55-chv4.json index 3b7f9250a1e..6dc30ece06a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j55q-wc55-chv4/GHSA-j55q-wc55-chv4.json +++ b/advisories/unreviewed/2022/05/GHSA-j55q-wc55-chv4/GHSA-j55q-wc55-chv4.json @@ -7,12 +7,8 @@ "CVE-2020-3143" ], "details": "A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the xAPI of the affected software. An attacker could exploit this vulnerability by sending a crafted request to the xAPI. A successful exploit could allow the attacker to read and write arbitrary files in the system. To exploit this vulnerability, an attacker would need either an In-Room Control or administrator account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5pg-5f9j-cc85/GHSA-j5pg-5f9j-cc85.json b/advisories/unreviewed/2022/05/GHSA-j5pg-5f9j-cc85/GHSA-j5pg-5f9j-cc85.json index 851fc45b394..3c6219004e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5pg-5f9j-cc85/GHSA-j5pg-5f9j-cc85.json +++ b/advisories/unreviewed/2022/05/GHSA-j5pg-5f9j-cc85/GHSA-j5pg-5f9j-cc85.json @@ -7,12 +7,8 @@ "CVE-2020-9744" ], "details": "Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5rv-8887-pg3h/GHSA-j5rv-8887-pg3h.json b/advisories/unreviewed/2022/05/GHSA-j5rv-8887-pg3h/GHSA-j5rv-8887-pg3h.json index 8cb0b3631c1..820922085d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5rv-8887-pg3h/GHSA-j5rv-8887-pg3h.json +++ b/advisories/unreviewed/2022/05/GHSA-j5rv-8887-pg3h/GHSA-j5rv-8887-pg3h.json @@ -7,12 +7,8 @@ "CVE-2020-14029" ], "details": "An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the application to an XML External Entity attack that can be used to perform SSRF or read arbitrary local files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j62j-249h-8r55/GHSA-j62j-249h-8r55.json b/advisories/unreviewed/2022/05/GHSA-j62j-249h-8r55/GHSA-j62j-249h-8r55.json index 471a143eec9..3ccf22c8843 100644 --- a/advisories/unreviewed/2022/05/GHSA-j62j-249h-8r55/GHSA-j62j-249h-8r55.json +++ b/advisories/unreviewed/2022/05/GHSA-j62j-249h-8r55/GHSA-j62j-249h-8r55.json @@ -7,12 +7,8 @@ "CVE-2020-4643" ], "details": "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j965-j6r8-h8qr/GHSA-j965-j6r8-h8qr.json b/advisories/unreviewed/2022/05/GHSA-j965-j6r8-h8qr/GHSA-j965-j6r8-h8qr.json index 1c280b289fa..f7c1bf08f18 100644 --- a/advisories/unreviewed/2022/05/GHSA-j965-j6r8-h8qr/GHSA-j965-j6r8-h8qr.json +++ b/advisories/unreviewed/2022/05/GHSA-j965-j6r8-h8qr/GHSA-j965-j6r8-h8qr.json @@ -7,12 +7,8 @@ "CVE-2020-4579" ], "details": "IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j988-rgcc-gf47/GHSA-j988-rgcc-gf47.json b/advisories/unreviewed/2022/05/GHSA-j988-rgcc-gf47/GHSA-j988-rgcc-gf47.json index e5832067e5c..d305115f1c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-j988-rgcc-gf47/GHSA-j988-rgcc-gf47.json +++ b/advisories/unreviewed/2022/05/GHSA-j988-rgcc-gf47/GHSA-j988-rgcc-gf47.json @@ -7,12 +7,8 @@ "CVE-2020-4614" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 184927.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j9v4-qqch-4wvq/GHSA-j9v4-qqch-4wvq.json b/advisories/unreviewed/2022/05/GHSA-j9v4-qqch-4wvq/GHSA-j9v4-qqch-4wvq.json index 896ebcd9c61..029c16c6bbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9v4-qqch-4wvq/GHSA-j9v4-qqch-4wvq.json +++ b/advisories/unreviewed/2022/05/GHSA-j9v4-qqch-4wvq/GHSA-j9v4-qqch-4wvq.json @@ -7,12 +7,8 @@ "CVE-2020-0386" ], "details": "In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-155650356", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jc4p-c566-vgxg/GHSA-jc4p-c566-vgxg.json b/advisories/unreviewed/2022/05/GHSA-jc4p-c566-vgxg/GHSA-jc4p-c566-vgxg.json index 2d5d0550ddf..15debc2ee52 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc4p-c566-vgxg/GHSA-jc4p-c566-vgxg.json +++ b/advisories/unreviewed/2022/05/GHSA-jc4p-c566-vgxg/GHSA-jc4p-c566-vgxg.json @@ -7,12 +7,8 @@ "CVE-2020-25770" ], "details": "An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product.\n\nAn attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities.\n\nThe subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25771. ", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jfxf-h9g6-34fv/GHSA-jfxf-h9g6-34fv.json b/advisories/unreviewed/2022/05/GHSA-jfxf-h9g6-34fv/GHSA-jfxf-h9g6-34fv.json index 63027a169ef..8f4948c0644 100644 --- a/advisories/unreviewed/2022/05/GHSA-jfxf-h9g6-34fv/GHSA-jfxf-h9g6-34fv.json +++ b/advisories/unreviewed/2022/05/GHSA-jfxf-h9g6-34fv/GHSA-jfxf-h9g6-34fv.json @@ -7,12 +7,8 @@ "CVE-2020-6555" ], "details": "Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jg34-4xc3-m554/GHSA-jg34-4xc3-m554.json b/advisories/unreviewed/2022/05/GHSA-jg34-4xc3-m554/GHSA-jg34-4xc3-m554.json index c02aa9dfcc8..3578cdd5297 100644 --- a/advisories/unreviewed/2022/05/GHSA-jg34-4xc3-m554/GHSA-jg34-4xc3-m554.json +++ b/advisories/unreviewed/2022/05/GHSA-jg34-4xc3-m554/GHSA-jg34-4xc3-m554.json @@ -7,12 +7,8 @@ "CVE-2020-0362" ], "details": "In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123237930", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jj9r-6jpf-jj9q/GHSA-jj9r-6jpf-jj9q.json b/advisories/unreviewed/2022/05/GHSA-jj9r-6jpf-jj9q/GHSA-jj9r-6jpf-jj9q.json index d45a4211fd7..2bd272656ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj9r-6jpf-jj9q/GHSA-jj9r-6jpf-jj9q.json +++ b/advisories/unreviewed/2022/05/GHSA-jj9r-6jpf-jj9q/GHSA-jj9r-6jpf-jj9q.json @@ -7,12 +7,8 @@ "CVE-2020-0348" ], "details": "In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139188582", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjhp-q6qv-36g4/GHSA-jjhp-q6qv-36g4.json b/advisories/unreviewed/2022/05/GHSA-jjhp-q6qv-36g4/GHSA-jjhp-q6qv-36g4.json index 6882de3747e..e8620d272e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjhp-q6qv-36g4/GHSA-jjhp-q6qv-36g4.json +++ b/advisories/unreviewed/2022/05/GHSA-jjhp-q6qv-36g4/GHSA-jjhp-q6qv-36g4.json @@ -7,12 +7,8 @@ "CVE-2020-6548" ], "details": "Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jjwj-hr26-45r5/GHSA-jjwj-hr26-45r5.json b/advisories/unreviewed/2022/05/GHSA-jjwj-hr26-45r5/GHSA-jjwj-hr26-45r5.json index fe487bb8215..a7b20830bf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjwj-hr26-45r5/GHSA-jjwj-hr26-45r5.json +++ b/advisories/unreviewed/2022/05/GHSA-jjwj-hr26-45r5/GHSA-jjwj-hr26-45r5.json @@ -7,12 +7,8 @@ "CVE-2020-0361" ], "details": "In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151927433", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jm67-j8j6-p3h8/GHSA-jm67-j8j6-p3h8.json b/advisories/unreviewed/2022/05/GHSA-jm67-j8j6-p3h8/GHSA-jm67-j8j6-p3h8.json index bf2427daa38..543f64b055f 100644 --- a/advisories/unreviewed/2022/05/GHSA-jm67-j8j6-p3h8/GHSA-jm67-j8j6-p3h8.json +++ b/advisories/unreviewed/2022/05/GHSA-jm67-j8j6-p3h8/GHSA-jm67-j8j6-p3h8.json @@ -7,12 +7,8 @@ "CVE-2020-4617" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 184930.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqhh-x964-vqg4/GHSA-jqhh-x964-vqg4.json b/advisories/unreviewed/2022/05/GHSA-jqhh-x964-vqg4/GHSA-jqhh-x964-vqg4.json index 6327bfd61ad..fc053505839 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqhh-x964-vqg4/GHSA-jqhh-x964-vqg4.json +++ b/advisories/unreviewed/2022/05/GHSA-jqhh-x964-vqg4/GHSA-jqhh-x964-vqg4.json @@ -7,12 +7,8 @@ "CVE-2020-6544" ], "details": "Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrcw-gg4h-3f4v/GHSA-jrcw-gg4h-3f4v.json b/advisories/unreviewed/2022/05/GHSA-jrcw-gg4h-3f4v/GHSA-jrcw-gg4h-3f4v.json index 953628d4217..8ece6049368 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrcw-gg4h-3f4v/GHSA-jrcw-gg4h-3f4v.json +++ b/advisories/unreviewed/2022/05/GHSA-jrcw-gg4h-3f4v/GHSA-jrcw-gg4h-3f4v.json @@ -7,12 +7,8 @@ "CVE-2020-25744" ], "details": "SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\\SaferVPN\\Log is followed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jwvq-qvwv-pjcm/GHSA-jwvq-qvwv-pjcm.json b/advisories/unreviewed/2022/05/GHSA-jwvq-qvwv-pjcm/GHSA-jwvq-qvwv-pjcm.json index f1bf708dc39..b47815abdb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwvq-qvwv-pjcm/GHSA-jwvq-qvwv-pjcm.json +++ b/advisories/unreviewed/2022/05/GHSA-jwvq-qvwv-pjcm/GHSA-jwvq-qvwv-pjcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jx9f-93fm-j74w/GHSA-jx9f-93fm-j74w.json b/advisories/unreviewed/2022/05/GHSA-jx9f-93fm-j74w/GHSA-jx9f-93fm-j74w.json index 58237050107..1a608bb7467 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx9f-93fm-j74w/GHSA-jx9f-93fm-j74w.json +++ b/advisories/unreviewed/2022/05/GHSA-jx9f-93fm-j74w/GHSA-jx9f-93fm-j74w.json @@ -7,12 +7,8 @@ "CVE-2020-25143" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. This can occur via /ajax/device_entities.php?entity_type=netscalervsvr&device_id[]= because of /ajax/device_entities.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jxx2-55mc-35gm/GHSA-jxx2-55mc-35gm.json b/advisories/unreviewed/2022/05/GHSA-jxx2-55mc-35gm/GHSA-jxx2-55mc-35gm.json index f1f63a9a727..ed5568516c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxx2-55mc-35gm/GHSA-jxx2-55mc-35gm.json +++ b/advisories/unreviewed/2022/05/GHSA-jxx2-55mc-35gm/GHSA-jxx2-55mc-35gm.json @@ -7,12 +7,8 @@ "CVE-2020-3124" ], "details": "A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections by the affected software. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could change the password of a targeted user. An attacker could then take unauthorized actions on behalf of the targeted user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m223-8p4j-9j7p/GHSA-m223-8p4j-9j7p.json b/advisories/unreviewed/2022/05/GHSA-m223-8p4j-9j7p/GHSA-m223-8p4j-9j7p.json index a422929dfd0..4046113dc77 100644 --- a/advisories/unreviewed/2022/05/GHSA-m223-8p4j-9j7p/GHSA-m223-8p4j-9j7p.json +++ b/advisories/unreviewed/2022/05/GHSA-m223-8p4j-9j7p/GHSA-m223-8p4j-9j7p.json @@ -7,12 +7,8 @@ "CVE-2020-7945" ], "details": "Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2jc-6q57-p6jg/GHSA-m2jc-6q57-p6jg.json b/advisories/unreviewed/2022/05/GHSA-m2jc-6q57-p6jg/GHSA-m2jc-6q57-p6jg.json index e77d46908eb..31dbade88c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2jc-6q57-p6jg/GHSA-m2jc-6q57-p6jg.json +++ b/advisories/unreviewed/2022/05/GHSA-m2jc-6q57-p6jg/GHSA-m2jc-6q57-p6jg.json @@ -7,12 +7,8 @@ "CVE-2020-13387" ], "details": "Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2rx-pgqj-f3wf/GHSA-m2rx-pgqj-f3wf.json b/advisories/unreviewed/2022/05/GHSA-m2rx-pgqj-f3wf/GHSA-m2rx-pgqj-f3wf.json index 2a9dc45448f..5c73fc3c55d 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2rx-pgqj-f3wf/GHSA-m2rx-pgqj-f3wf.json +++ b/advisories/unreviewed/2022/05/GHSA-m2rx-pgqj-f3wf/GHSA-m2rx-pgqj-f3wf.json @@ -7,12 +7,8 @@ "CVE-2020-25726" ], "details": "A Directory Traversal issue was discovered on Hak5 WiFi Pineapple Mark VII 1.x before 1.0.1-beta.2020091914551 devices. An unauthenticated user can connect to the wireless management network, including the open wireless network, and access all files and subdirectories under /pineapple/ui, regardless of file permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m3wp-9jj9-qqp4/GHSA-m3wp-9jj9-qqp4.json b/advisories/unreviewed/2022/05/GHSA-m3wp-9jj9-qqp4/GHSA-m3wp-9jj9-qqp4.json index 3cd41e3d827..e9ae6d92501 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3wp-9jj9-qqp4/GHSA-m3wp-9jj9-qqp4.json +++ b/advisories/unreviewed/2022/05/GHSA-m3wp-9jj9-qqp4/GHSA-m3wp-9jj9-qqp4.json @@ -7,12 +7,8 @@ "CVE-2020-16230" ], "details": "All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5c8-vgg2-pch8/GHSA-m5c8-vgg2-pch8.json b/advisories/unreviewed/2022/05/GHSA-m5c8-vgg2-pch8/GHSA-m5c8-vgg2-pch8.json index 651ac61d403..c119f1922b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5c8-vgg2-pch8/GHSA-m5c8-vgg2-pch8.json +++ b/advisories/unreviewed/2022/05/GHSA-m5c8-vgg2-pch8/GHSA-m5c8-vgg2-pch8.json @@ -7,12 +7,8 @@ "CVE-2020-25137" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via the alert_name or alert_message parameter to the /alert_check URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m5r6-8jfm-hp4w/GHSA-m5r6-8jfm-hp4w.json b/advisories/unreviewed/2022/05/GHSA-m5r6-8jfm-hp4w/GHSA-m5r6-8jfm-hp4w.json index 8329d90a527..e37a0170ce4 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5r6-8jfm-hp4w/GHSA-m5r6-8jfm-hp4w.json +++ b/advisories/unreviewed/2022/05/GHSA-m5r6-8jfm-hp4w/GHSA-m5r6-8jfm-hp4w.json @@ -7,12 +7,8 @@ "CVE-2020-24046" ], "details": "A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. This restricted shell can be bypassed after changing the properties of the user admin in the operating system file /etc/passwd. This file cannot be accessed though the restricted shell, but it can be modified by abusing the Backup/Import Backup functionality of the web interface. An authenticated attacker would be able to obtain the file /var/tmp/admin.passwd after executing a Backup operation. This file can be manually modified to change the GUID of the user to 0 (root) and change the restricted shell to a normal shell /bin/sh. After the modification is done, the file can be recompressed to a .tar.bz file and imported again via the Import Backup functionality. The properties of the admin user will be overwritten and a root shell will be granted to the user upon the next successful login.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m986-vxw8-5993/GHSA-m986-vxw8-5993.json b/advisories/unreviewed/2022/05/GHSA-m986-vxw8-5993/GHSA-m986-vxw8-5993.json index 3b72eb552d7..1e07cb4feb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-m986-vxw8-5993/GHSA-m986-vxw8-5993.json +++ b/advisories/unreviewed/2022/05/GHSA-m986-vxw8-5993/GHSA-m986-vxw8-5993.json @@ -7,12 +7,8 @@ "CVE-2020-4580" ], "details": "IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON request with invalid characters. IBM X-Force ID: 184439.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mfgj-27xx-9qxp/GHSA-mfgj-27xx-9qxp.json b/advisories/unreviewed/2022/05/GHSA-mfgj-27xx-9qxp/GHSA-mfgj-27xx-9qxp.json index ca438e1af8d..cd5765fd84a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfgj-27xx-9qxp/GHSA-mfgj-27xx-9qxp.json +++ b/advisories/unreviewed/2022/05/GHSA-mfgj-27xx-9qxp/GHSA-mfgj-27xx-9qxp.json @@ -7,12 +7,8 @@ "CVE-2020-0308" ], "details": "In Window Manager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153654357", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg2f-7p87-hxwv/GHSA-mg2f-7p87-hxwv.json b/advisories/unreviewed/2022/05/GHSA-mg2f-7p87-hxwv/GHSA-mg2f-7p87-hxwv.json index 8c4cff630e5..1ed549195ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg2f-7p87-hxwv/GHSA-mg2f-7p87-hxwv.json +++ b/advisories/unreviewed/2022/05/GHSA-mg2f-7p87-hxwv/GHSA-mg2f-7p87-hxwv.json @@ -7,12 +7,8 @@ "CVE-2019-16004" ], "details": "A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to missing authentication on some of the API calls. An attacker could exploit this vulnerability by sending a request to one of the affected calls. A successful exploit could allow the attacker to interact with some parts of the API.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mg4x-vhcc-f5x7/GHSA-mg4x-vhcc-f5x7.json b/advisories/unreviewed/2022/05/GHSA-mg4x-vhcc-f5x7/GHSA-mg4x-vhcc-f5x7.json index 15138f8e68c..2d455d05f32 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg4x-vhcc-f5x7/GHSA-mg4x-vhcc-f5x7.json +++ b/advisories/unreviewed/2022/05/GHSA-mg4x-vhcc-f5x7/GHSA-mg4x-vhcc-f5x7.json @@ -7,12 +7,8 @@ "CVE-2020-4612" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to obtain sensitive information using a specially crafted HTTP request. IBM X-Force ID: 184924.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mg6c-ww2w-mv2h/GHSA-mg6c-ww2w-mv2h.json b/advisories/unreviewed/2022/05/GHSA-mg6c-ww2w-mv2h/GHSA-mg6c-ww2w-mv2h.json index 014257610c5..a7a415a8673 100644 --- a/advisories/unreviewed/2022/05/GHSA-mg6c-ww2w-mv2h/GHSA-mg6c-ww2w-mv2h.json +++ b/advisories/unreviewed/2022/05/GHSA-mg6c-ww2w-mv2h/GHSA-mg6c-ww2w-mv2h.json @@ -7,12 +7,8 @@ "CVE-2020-3117" ], "details": "A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user to access a crafted URL and receive a malicious HTTP response. A successful exploit could allow the attacker to inject arbitrary HTTP headers into valid HTTP responses sent to a user's browser.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgc3-c66w-fpmm/GHSA-mgc3-c66w-fpmm.json b/advisories/unreviewed/2022/05/GHSA-mgc3-c66w-fpmm/GHSA-mgc3-c66w-fpmm.json index a20e4674f99..8032b2f40f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgc3-c66w-fpmm/GHSA-mgc3-c66w-fpmm.json +++ b/advisories/unreviewed/2022/05/GHSA-mgc3-c66w-fpmm/GHSA-mgc3-c66w-fpmm.json @@ -7,12 +7,8 @@ "CVE-2020-25514" ], "details": "Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http:///lms/admin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mgp8-hj77-63qg/GHSA-mgp8-hj77-63qg.json b/advisories/unreviewed/2022/05/GHSA-mgp8-hj77-63qg/GHSA-mgp8-hj77-63qg.json index 991dd698bbc..1c549c592ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgp8-hj77-63qg/GHSA-mgp8-hj77-63qg.json +++ b/advisories/unreviewed/2022/05/GHSA-mgp8-hj77-63qg/GHSA-mgp8-hj77-63qg.json @@ -7,12 +7,8 @@ "CVE-2020-8253" ], "details": "Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mj5m-vqcr-c4pf/GHSA-mj5m-vqcr-c4pf.json b/advisories/unreviewed/2022/05/GHSA-mj5m-vqcr-c4pf/GHSA-mj5m-vqcr-c4pf.json index fb8b21f1997..d4765b26d5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj5m-vqcr-c4pf/GHSA-mj5m-vqcr-c4pf.json +++ b/advisories/unreviewed/2022/05/GHSA-mj5m-vqcr-c4pf/GHSA-mj5m-vqcr-c4pf.json @@ -7,12 +7,8 @@ "CVE-2020-6553" ], "details": "Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmvp-2hg2-g76c/GHSA-mmvp-2hg2-g76c.json b/advisories/unreviewed/2022/05/GHSA-mmvp-2hg2-g76c/GHSA-mmvp-2hg2-g76c.json index f8bb21ebdf6..56996a67efb 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmvp-2hg2-g76c/GHSA-mmvp-2hg2-g76c.json +++ b/advisories/unreviewed/2022/05/GHSA-mmvp-2hg2-g76c/GHSA-mmvp-2hg2-g76c.json @@ -7,12 +7,8 @@ "CVE-2020-3559" ], "details": "A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication requests from multiple clients to an affected device. A successful exploit could allow the attacker to cause the affected device to reload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mpqr-xh68-rm34/GHSA-mpqr-xh68-rm34.json b/advisories/unreviewed/2022/05/GHSA-mpqr-xh68-rm34/GHSA-mpqr-xh68-rm34.json index c4eda32d528..b6c155069f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpqr-xh68-rm34/GHSA-mpqr-xh68-rm34.json +++ b/advisories/unreviewed/2022/05/GHSA-mpqr-xh68-rm34/GHSA-mpqr-xh68-rm34.json @@ -7,12 +7,8 @@ "CVE-2020-13504" ], "details": "Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mr5m-8j6x-5qpr/GHSA-mr5m-8j6x-5qpr.json b/advisories/unreviewed/2022/05/GHSA-mr5m-8j6x-5qpr/GHSA-mr5m-8j6x-5qpr.json index 2682ed0c46e..31d1a459a97 100644 --- a/advisories/unreviewed/2022/05/GHSA-mr5m-8j6x-5qpr/GHSA-mr5m-8j6x-5qpr.json +++ b/advisories/unreviewed/2022/05/GHSA-mr5m-8j6x-5qpr/GHSA-mr5m-8j6x-5qpr.json @@ -7,12 +7,8 @@ "CVE-2020-21524" ], "details": "There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/wordpress) needs to parse the xml file, but it is not used for security defense, This vulnerability can detect the intranet, read files, enable ddos attacks, etc. exp:https://github.com/halo-dev/halo/issues/423", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mv4f-fvpr-9x8h/GHSA-mv4f-fvpr-9x8h.json b/advisories/unreviewed/2022/05/GHSA-mv4f-fvpr-9x8h/GHSA-mv4f-fvpr-9x8h.json index 36f9e01b470..b3f54182960 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv4f-fvpr-9x8h/GHSA-mv4f-fvpr-9x8h.json +++ b/advisories/unreviewed/2022/05/GHSA-mv4f-fvpr-9x8h/GHSA-mv4f-fvpr-9x8h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv8q-jr3c-hxp6/GHSA-mv8q-jr3c-hxp6.json b/advisories/unreviewed/2022/05/GHSA-mv8q-jr3c-hxp6/GHSA-mv8q-jr3c-hxp6.json index 5cd93607087..3b9690a034e 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv8q-jr3c-hxp6/GHSA-mv8q-jr3c-hxp6.json +++ b/advisories/unreviewed/2022/05/GHSA-mv8q-jr3c-hxp6/GHSA-mv8q-jr3c-hxp6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwcq-w75h-9p3w/GHSA-mwcq-w75h-9p3w.json b/advisories/unreviewed/2022/05/GHSA-mwcq-w75h-9p3w/GHSA-mwcq-w75h-9p3w.json index 792081ec1d8..ea53fb1ee27 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwcq-w75h-9p3w/GHSA-mwcq-w75h-9p3w.json +++ b/advisories/unreviewed/2022/05/GHSA-mwcq-w75h-9p3w/GHSA-mwcq-w75h-9p3w.json @@ -7,12 +7,8 @@ "CVE-2020-0358" ], "details": "In SurfaceFlinger, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150227563", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwjp-gcwv-rwcr/GHSA-mwjp-gcwv-rwcr.json b/advisories/unreviewed/2022/05/GHSA-mwjp-gcwv-rwcr/GHSA-mwjp-gcwv-rwcr.json index 35f373dcced..37f4a9188ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwjp-gcwv-rwcr/GHSA-mwjp-gcwv-rwcr.json +++ b/advisories/unreviewed/2022/05/GHSA-mwjp-gcwv-rwcr/GHSA-mwjp-gcwv-rwcr.json @@ -7,12 +7,8 @@ "CVE-2020-6551" ], "details": "Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mx65-vqhq-g7wg/GHSA-mx65-vqhq-g7wg.json b/advisories/unreviewed/2022/05/GHSA-mx65-vqhq-g7wg/GHSA-mx65-vqhq-g7wg.json index 1e934c3bff9..a7e8f90bcbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx65-vqhq-g7wg/GHSA-mx65-vqhq-g7wg.json +++ b/advisories/unreviewed/2022/05/GHSA-mx65-vqhq-g7wg/GHSA-mx65-vqhq-g7wg.json @@ -7,12 +7,8 @@ "CVE-2020-21523" ], "details": "A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign test=\"freemarker.template.utility.Execute\"?new()> ${test(\"touch /tmp/freemarkerPwned\")}", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2fw-42jv-4g2h/GHSA-p2fw-42jv-4g2h.json b/advisories/unreviewed/2022/05/GHSA-p2fw-42jv-4g2h/GHSA-p2fw-42jv-4g2h.json index 22264463b6b..f2342572fee 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2fw-42jv-4g2h/GHSA-p2fw-42jv-4g2h.json +++ b/advisories/unreviewed/2022/05/GHSA-p2fw-42jv-4g2h/GHSA-p2fw-42jv-4g2h.json @@ -7,12 +7,8 @@ "CVE-2020-26053" ], "details": "Cybereason Endpoint Solutions Cybereason Endpoint Protection Version 20.1.261.0 is affected by an infection using Powershell script calling Ransomware to encrypt the victim machine using a delay between server and sensor communication from Cybereason AV in Windows 10 Machines", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2g7-qwxm-9q47/GHSA-p2g7-qwxm-9q47.json b/advisories/unreviewed/2022/05/GHSA-p2g7-qwxm-9q47/GHSA-p2g7-qwxm-9q47.json index 6a303a44882..8cdf175ca63 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2g7-qwxm-9q47/GHSA-p2g7-qwxm-9q47.json +++ b/advisories/unreviewed/2022/05/GHSA-p2g7-qwxm-9q47/GHSA-p2g7-qwxm-9q47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p2v6-ppm3-3vj9/GHSA-p2v6-ppm3-3vj9.json b/advisories/unreviewed/2022/05/GHSA-p2v6-ppm3-3vj9/GHSA-p2v6-ppm3-3vj9.json index c1f42cd6772..b07782d24eb 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2v6-ppm3-3vj9/GHSA-p2v6-ppm3-3vj9.json +++ b/advisories/unreviewed/2022/05/GHSA-p2v6-ppm3-3vj9/GHSA-p2v6-ppm3-3vj9.json @@ -7,12 +7,8 @@ "CVE-2020-0374" ], "details": "In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156251602", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p48v-p5pg-6rp4/GHSA-p48v-p5pg-6rp4.json b/advisories/unreviewed/2022/05/GHSA-p48v-p5pg-6rp4/GHSA-p48v-p5pg-6rp4.json index aedb2aad42a..7f5e97dc166 100644 --- a/advisories/unreviewed/2022/05/GHSA-p48v-p5pg-6rp4/GHSA-p48v-p5pg-6rp4.json +++ b/advisories/unreviewed/2022/05/GHSA-p48v-p5pg-6rp4/GHSA-p48v-p5pg-6rp4.json @@ -7,12 +7,8 @@ "CVE-2020-7358" ], "details": "In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during an installation and any arbitrary code executable using the same file name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p53x-qr46-h26h/GHSA-p53x-qr46-h26h.json b/advisories/unreviewed/2022/05/GHSA-p53x-qr46-h26h/GHSA-p53x-qr46-h26h.json index 8124139cf37..9bd9bf168a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-p53x-qr46-h26h/GHSA-p53x-qr46-h26h.json +++ b/advisories/unreviewed/2022/05/GHSA-p53x-qr46-h26h/GHSA-p53x-qr46-h26h.json @@ -7,12 +7,8 @@ "CVE-2020-6538" ], "details": "Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p6fr-7234-rw5g/GHSA-p6fr-7234-rw5g.json b/advisories/unreviewed/2022/05/GHSA-p6fr-7234-rw5g/GHSA-p6fr-7234-rw5g.json index 0be02527c52..893818fb5ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6fr-7234-rw5g/GHSA-p6fr-7234-rw5g.json +++ b/advisories/unreviewed/2022/05/GHSA-p6fr-7234-rw5g/GHSA-p6fr-7234-rw5g.json @@ -7,12 +7,8 @@ "CVE-2020-24563" ], "details": "A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution.\n\nAn attacker must first obtain the ability to execute low-privileged code on the target in order to exploit this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p836-3j4x-6q4q/GHSA-p836-3j4x-6q4q.json b/advisories/unreviewed/2022/05/GHSA-p836-3j4x-6q4q/GHSA-p836-3j4x-6q4q.json index 67de74dbfef..a088c3be3be 100644 --- a/advisories/unreviewed/2022/05/GHSA-p836-3j4x-6q4q/GHSA-p836-3j4x-6q4q.json +++ b/advisories/unreviewed/2022/05/GHSA-p836-3j4x-6q4q/GHSA-p836-3j4x-6q4q.json @@ -7,12 +7,8 @@ "CVE-2020-18190" ], "details": "Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8cf-jjc3-phj5/GHSA-p8cf-jjc3-phj5.json b/advisories/unreviewed/2022/05/GHSA-p8cf-jjc3-phj5/GHSA-p8cf-jjc3-phj5.json index 8fd0977f4d6..f302a9018e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8cf-jjc3-phj5/GHSA-p8cf-jjc3-phj5.json +++ b/advisories/unreviewed/2022/05/GHSA-p8cf-jjc3-phj5/GHSA-p8cf-jjc3-phj5.json @@ -7,12 +7,8 @@ "CVE-2018-5353" ], "details": "The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pj9p-w8rm-cvj3/GHSA-pj9p-w8rm-cvj3.json b/advisories/unreviewed/2022/05/GHSA-pj9p-w8rm-cvj3/GHSA-pj9p-w8rm-cvj3.json index 0fcc589d932..9f44ed437cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj9p-w8rm-cvj3/GHSA-pj9p-w8rm-cvj3.json +++ b/advisories/unreviewed/2022/05/GHSA-pj9p-w8rm-cvj3/GHSA-pj9p-w8rm-cvj3.json @@ -7,12 +7,8 @@ "CVE-2020-12838" ], "details": "ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pmmp-f225-r347/GHSA-pmmp-f225-r347.json b/advisories/unreviewed/2022/05/GHSA-pmmp-f225-r347/GHSA-pmmp-f225-r347.json index 4e5c860975d..970416945e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmmp-f225-r347/GHSA-pmmp-f225-r347.json +++ b/advisories/unreviewed/2022/05/GHSA-pmmp-f225-r347/GHSA-pmmp-f225-r347.json @@ -7,12 +7,8 @@ "CVE-2020-8028" ], "details": "A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy 4.0, SUSE Manager Retail Branch Server 4.0, SUSE Manager Server 3.2, SUSE Manager Server 4.0 allows local users to escalate to root on every system managed by SUSE manager. On the managing node itself code can be executed as user salt, potentially allowing for escalation to root there. This issue affects: SUSE Linux Enterprise Module for SUSE Manager Server 4.1 google-gson versions prior to 2.8.5-3.4.3, httpcomponents-client-4.5.6-3.4.2, httpcomponents-. SUSE Manager Proxy 4.0 release-notes-susemanager-proxy versions prior to 4.0.9-0.16.38.1. SUSE Manager Retail Branch Server 4.0 release-notes-susemanager-proxy versions prior to 4.0.9-0.16.38.1. SUSE Manager Server 3.2 salt-netapi-client versions prior to 0.16.0-4.14.1, spacewalk-. SUSE Manager Server 4.0 release-notes-susemanager versions prior to 4.0.9-3.54.1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pmpm-gxwf-jp9j/GHSA-pmpm-gxwf-jp9j.json b/advisories/unreviewed/2022/05/GHSA-pmpm-gxwf-jp9j/GHSA-pmpm-gxwf-jp9j.json index 45f9f5abdb5..48d827a6f88 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmpm-gxwf-jp9j/GHSA-pmpm-gxwf-jp9j.json +++ b/advisories/unreviewed/2022/05/GHSA-pmpm-gxwf-jp9j/GHSA-pmpm-gxwf-jp9j.json @@ -7,12 +7,8 @@ "CVE-2020-16240" ], "details": "GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users who should not have access to such functionality. An attacker can download sensitive data related to user accounts without having the proper privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pp6v-prf5-pcw4/GHSA-pp6v-prf5-pcw4.json b/advisories/unreviewed/2022/05/GHSA-pp6v-prf5-pcw4/GHSA-pp6v-prf5-pcw4.json index 4ccc11249e6..865479989cd 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp6v-prf5-pcw4/GHSA-pp6v-prf5-pcw4.json +++ b/advisories/unreviewed/2022/05/GHSA-pp6v-prf5-pcw4/GHSA-pp6v-prf5-pcw4.json @@ -7,12 +7,8 @@ "CVE-2020-26112" ], "details": "The email quota cache in cPanel before 90.0.10 allows overwriting of files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pqx5-jwv2-ffhr/GHSA-pqx5-jwv2-ffhr.json b/advisories/unreviewed/2022/05/GHSA-pqx5-jwv2-ffhr/GHSA-pqx5-jwv2-ffhr.json index a77cedd4765..440265d9a99 100644 --- a/advisories/unreviewed/2022/05/GHSA-pqx5-jwv2-ffhr/GHSA-pqx5-jwv2-ffhr.json +++ b/advisories/unreviewed/2022/05/GHSA-pqx5-jwv2-ffhr/GHSA-pqx5-jwv2-ffhr.json @@ -7,12 +7,8 @@ "CVE-2020-15843" ], "details": "ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on %PROGRAMFILES%\\ActiveFax\\Client\\, %PROGRAMFILES%\\ActiveFax\\Install\\ and %PROGRAMFILES%\\ActiveFax\\Terminal\\. The folder permissions allow \"Full Control\" to \"Everyone\". An authenticated local attacker can exploit this to replace the TSClientB.exe binary in the Terminal directory, which is executed on logon for every user. Alternatively, the attacker can replace any of the binaries in the Client or Install directories. The latter requires additional user interaction, for example starting the client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prgx-65ww-w7j5/GHSA-prgx-65ww-w7j5.json b/advisories/unreviewed/2022/05/GHSA-prgx-65ww-w7j5/GHSA-prgx-65ww-w7j5.json index 70142f05df5..941cda1c744 100644 --- a/advisories/unreviewed/2022/05/GHSA-prgx-65ww-w7j5/GHSA-prgx-65ww-w7j5.json +++ b/advisories/unreviewed/2022/05/GHSA-prgx-65ww-w7j5/GHSA-prgx-65ww-w7j5.json @@ -7,12 +7,8 @@ "CVE-2019-16007" ], "details": "A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition. The vulnerability is due to the use of implicit service invocations. An attacker could exploit this vulnerability by persuading a user to install a malicious application. A successful exploit could allow the attacker to access confidential user information or cause a DoS condition on the AnyConnect application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pwj8-9qvg-5p8c/GHSA-pwj8-9qvg-5p8c.json b/advisories/unreviewed/2022/05/GHSA-pwj8-9qvg-5p8c/GHSA-pwj8-9qvg-5p8c.json index 7734cf73bc2..f315a408e43 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwj8-9qvg-5p8c/GHSA-pwj8-9qvg-5p8c.json +++ b/advisories/unreviewed/2022/05/GHSA-pwj8-9qvg-5p8c/GHSA-pwj8-9qvg-5p8c.json @@ -7,12 +7,8 @@ "CVE-2020-24623" ], "details": "A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware Esxi v2.5.2 and HPE Universal API Framework for Microsoft Hyper-V (VHD).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pwv5-j779-c4f3/GHSA-pwv5-j779-c4f3.json b/advisories/unreviewed/2022/05/GHSA-pwv5-j779-c4f3/GHSA-pwv5-j779-c4f3.json index 20405b32bd4..6da66674ec8 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwv5-j779-c4f3/GHSA-pwv5-j779-c4f3.json +++ b/advisories/unreviewed/2022/05/GHSA-pwv5-j779-c4f3/GHSA-pwv5-j779-c4f3.json @@ -7,12 +7,8 @@ "CVE-2020-6575" ], "details": "Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwvv-633w-65j9/GHSA-pwvv-633w-65j9.json b/advisories/unreviewed/2022/05/GHSA-pwvv-633w-65j9/GHSA-pwvv-633w-65j9.json index 4d80aa1b781..fbb53e91fff 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwvv-633w-65j9/GHSA-pwvv-633w-65j9.json +++ b/advisories/unreviewed/2022/05/GHSA-pwvv-633w-65j9/GHSA-pwvv-633w-65j9.json @@ -7,12 +7,8 @@ "CVE-2019-1736" ], "details": "A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. An attacker could exploit this vulnerability by installing a server firmware version that would allow the attacker to disable UEFI Secure Boot. A successful exploit could allow the attacker to bypass the signature validation checks that are done by UEFI Secure Boot technology and load a compromised software image on the affected device. A compromised software image is any software image that has not been digitally signed by Cisco.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pwwx-2gvr-j6qv/GHSA-pwwx-2gvr-j6qv.json b/advisories/unreviewed/2022/05/GHSA-pwwx-2gvr-j6qv/GHSA-pwwx-2gvr-j6qv.json index 6c063f9c3c8..251955f0adb 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwwx-2gvr-j6qv/GHSA-pwwx-2gvr-j6qv.json +++ b/advisories/unreviewed/2022/05/GHSA-pwwx-2gvr-j6qv/GHSA-pwwx-2gvr-j6qv.json @@ -7,12 +7,8 @@ "CVE-2020-16234" ], "details": "In PLC WinProladder Version 3.28 and prior, a stack-based buffer overflow vulnerability can be exploited when a valid user opens a specially crafted file, which may allow an attacker to remotely execute arbitrary code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxh5-999h-73g5/GHSA-pxh5-999h-73g5.json b/advisories/unreviewed/2022/05/GHSA-pxh5-999h-73g5/GHSA-pxh5-999h-73g5.json index 231b796c11a..f3dfe914c3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxh5-999h-73g5/GHSA-pxh5-999h-73g5.json +++ b/advisories/unreviewed/2022/05/GHSA-pxh5-999h-73g5/GHSA-pxh5-999h-73g5.json @@ -7,12 +7,8 @@ "CVE-2020-12280" ], "details": "iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /isg/opendoor.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q358-8xv4-rg52/GHSA-q358-8xv4-rg52.json b/advisories/unreviewed/2022/05/GHSA-q358-8xv4-rg52/GHSA-q358-8xv4-rg52.json index f95c51cb88e..67b6e790125 100644 --- a/advisories/unreviewed/2022/05/GHSA-q358-8xv4-rg52/GHSA-q358-8xv4-rg52.json +++ b/advisories/unreviewed/2022/05/GHSA-q358-8xv4-rg52/GHSA-q358-8xv4-rg52.json @@ -7,12 +7,8 @@ "CVE-2020-15372" ], "details": "A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k, v9.0.0, could allow a local authenticated attacker to modify shell variables, which may lead to an escalation of privileges or bypassing the logging.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q36v-x9xm-f2j9/GHSA-q36v-x9xm-f2j9.json b/advisories/unreviewed/2022/05/GHSA-q36v-x9xm-f2j9/GHSA-q36v-x9xm-f2j9.json index 3f36b661778..0a236fef1ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-q36v-x9xm-f2j9/GHSA-q36v-x9xm-f2j9.json +++ b/advisories/unreviewed/2022/05/GHSA-q36v-x9xm-f2j9/GHSA-q36v-x9xm-f2j9.json @@ -7,12 +7,8 @@ "CVE-2020-0431" ], "details": "In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-144161459", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q38m-p7rw-6h5p/GHSA-q38m-p7rw-6h5p.json b/advisories/unreviewed/2022/05/GHSA-q38m-p7rw-6h5p/GHSA-q38m-p7rw-6h5p.json index 84c3096f855..37224f01602 100644 --- a/advisories/unreviewed/2022/05/GHSA-q38m-p7rw-6h5p/GHSA-q38m-p7rw-6h5p.json +++ b/advisories/unreviewed/2022/05/GHSA-q38m-p7rw-6h5p/GHSA-q38m-p7rw-6h5p.json @@ -7,12 +7,8 @@ "CVE-2020-0344" ], "details": "In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-140729887", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q3pq-7jmm-xr4h/GHSA-q3pq-7jmm-xr4h.json b/advisories/unreviewed/2022/05/GHSA-q3pq-7jmm-xr4h/GHSA-q3pq-7jmm-xr4h.json index eda05adf1b1..365d236537f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3pq-7jmm-xr4h/GHSA-q3pq-7jmm-xr4h.json +++ b/advisories/unreviewed/2022/05/GHSA-q3pq-7jmm-xr4h/GHSA-q3pq-7jmm-xr4h.json @@ -7,12 +7,8 @@ "CVE-2020-3417" ], "details": "A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of trust. This vulnerability is due to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set. An attacker could exploit this vulnerability by installing code to a specific directory in the underlying operating system (OS) and setting a specific ROMMON variable. A successful exploit could allow the attacker to execute persistent code on the underlying OS. To exploit this vulnerability, the attacker would need access to the root shell on the device or have physical access to the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q5cw-4q48-3cxj/GHSA-q5cw-4q48-3cxj.json b/advisories/unreviewed/2022/05/GHSA-q5cw-4q48-3cxj/GHSA-q5cw-4q48-3cxj.json index a5703edb1f6..8b3917b1463 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5cw-4q48-3cxj/GHSA-q5cw-4q48-3cxj.json +++ b/advisories/unreviewed/2022/05/GHSA-q5cw-4q48-3cxj/GHSA-q5cw-4q48-3cxj.json @@ -7,12 +7,8 @@ "CVE-2020-15487" ], "details": "Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET parameter, it is possible to execute arbitrary SQL statements via a crafted URL. Unauthenticated remote command execution is possible by using this SQL injection to update certain database values, which are then executed by a bizRule eval() function in the yii/framework/web/auth/CAuthManager.php file. Resultant authorization bypass is also possible, by recovering or modifying password hashes and password reset tokens, allowing for administrative privileges to be obtained.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q674-xm8r-fx86/GHSA-q674-xm8r-fx86.json b/advisories/unreviewed/2022/05/GHSA-q674-xm8r-fx86/GHSA-q674-xm8r-fx86.json index 22817c7c551..9457ec236f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q674-xm8r-fx86/GHSA-q674-xm8r-fx86.json +++ b/advisories/unreviewed/2022/05/GHSA-q674-xm8r-fx86/GHSA-q674-xm8r-fx86.json @@ -7,12 +7,8 @@ "CVE-2018-6448" ], "details": "A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qc23-rcpx-gm4f/GHSA-qc23-rcpx-gm4f.json b/advisories/unreviewed/2022/05/GHSA-qc23-rcpx-gm4f/GHSA-qc23-rcpx-gm4f.json index cd07ada9de4..5f2e99454ee 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc23-rcpx-gm4f/GHSA-qc23-rcpx-gm4f.json +++ b/advisories/unreviewed/2022/05/GHSA-qc23-rcpx-gm4f/GHSA-qc23-rcpx-gm4f.json @@ -7,12 +7,8 @@ "CVE-2020-12815" ], "details": "An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qc8m-fmhj-x4j4/GHSA-qc8m-fmhj-x4j4.json b/advisories/unreviewed/2022/05/GHSA-qc8m-fmhj-x4j4/GHSA-qc8m-fmhj-x4j4.json index a8dbc1fc432..ad75016b2e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc8m-fmhj-x4j4/GHSA-qc8m-fmhj-x4j4.json +++ b/advisories/unreviewed/2022/05/GHSA-qc8m-fmhj-x4j4/GHSA-qc8m-fmhj-x4j4.json @@ -7,12 +7,8 @@ "CVE-2020-13991" ], "details": "vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qccw-5mh6-8cq6/GHSA-qccw-5mh6-8cq6.json b/advisories/unreviewed/2022/05/GHSA-qccw-5mh6-8cq6/GHSA-qccw-5mh6-8cq6.json index cdc5d4209ea..a161ec8e599 100644 --- a/advisories/unreviewed/2022/05/GHSA-qccw-5mh6-8cq6/GHSA-qccw-5mh6-8cq6.json +++ b/advisories/unreviewed/2022/05/GHSA-qccw-5mh6-8cq6/GHSA-qccw-5mh6-8cq6.json @@ -7,12 +7,8 @@ "CVE-2020-18184" ], "details": "In PluxXml V5.7,the theme edit function /PluXml/core/admin/parametres_edittpl.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qcwg-fv89-gmhm/GHSA-qcwg-fv89-gmhm.json b/advisories/unreviewed/2022/05/GHSA-qcwg-fv89-gmhm/GHSA-qcwg-fv89-gmhm.json index 9425131058b..75135cde01b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcwg-fv89-gmhm/GHSA-qcwg-fv89-gmhm.json +++ b/advisories/unreviewed/2022/05/GHSA-qcwg-fv89-gmhm/GHSA-qcwg-fv89-gmhm.json @@ -7,12 +7,8 @@ "CVE-2019-15974" ], "details": "A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. A successful exploit could allow the attacker to redirect a user to a malicious web page. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qf2q-g63v-vhh7/GHSA-qf2q-g63v-vhh7.json b/advisories/unreviewed/2022/05/GHSA-qf2q-g63v-vhh7/GHSA-qf2q-g63v-vhh7.json index a515e6c1df0..95bdb13a14f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf2q-g63v-vhh7/GHSA-qf2q-g63v-vhh7.json +++ b/advisories/unreviewed/2022/05/GHSA-qf2q-g63v-vhh7/GHSA-qf2q-g63v-vhh7.json @@ -7,12 +7,8 @@ "CVE-2020-11856" ], "details": "Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg2r-g932-mwff/GHSA-qg2r-g932-mwff.json b/advisories/unreviewed/2022/05/GHSA-qg2r-g932-mwff/GHSA-qg2r-g932-mwff.json index 652ad16566f..c75cceb34cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg2r-g932-mwff/GHSA-qg2r-g932-mwff.json +++ b/advisories/unreviewed/2022/05/GHSA-qg2r-g932-mwff/GHSA-qg2r-g932-mwff.json @@ -7,12 +7,8 @@ "CVE-2020-0350" ], "details": "In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139424089", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qg38-9f8p-h2hp/GHSA-qg38-9f8p-h2hp.json b/advisories/unreviewed/2022/05/GHSA-qg38-9f8p-h2hp/GHSA-qg38-9f8p-h2hp.json index 8d13795e848..324dc0f69e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg38-9f8p-h2hp/GHSA-qg38-9f8p-h2hp.json +++ b/advisories/unreviewed/2022/05/GHSA-qg38-9f8p-h2hp/GHSA-qg38-9f8p-h2hp.json @@ -7,12 +7,8 @@ "CVE-2020-0331" ], "details": "In Settings, there is a possible permissions bypass. This could lead to local information disclosure of the device's IMEI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147309310", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qg4c-f5h3-4h6q/GHSA-qg4c-f5h3-4h6q.json b/advisories/unreviewed/2022/05/GHSA-qg4c-f5h3-4h6q/GHSA-qg4c-f5h3-4h6q.json index 4ed2a7d2d42..8757dac28fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg4c-f5h3-4h6q/GHSA-qg4c-f5h3-4h6q.json +++ b/advisories/unreviewed/2022/05/GHSA-qg4c-f5h3-4h6q/GHSA-qg4c-f5h3-4h6q.json @@ -7,12 +7,8 @@ "CVE-2020-11855" ], "details": "An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow local attackers on the OBR host to execute code with escalated privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgrr-f26j-87vf/GHSA-qgrr-f26j-87vf.json b/advisories/unreviewed/2022/05/GHSA-qgrr-f26j-87vf/GHSA-qgrr-f26j-87vf.json index 96ad7f46064..4f3165258d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgrr-f26j-87vf/GHSA-qgrr-f26j-87vf.json +++ b/advisories/unreviewed/2022/05/GHSA-qgrr-f26j-87vf/GHSA-qgrr-f26j-87vf.json @@ -7,12 +7,8 @@ "CVE-2020-25288" ], "details": "An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular Expression property is used, improper escaping of the corresponding form input's pattern attribute allows HTML injection and, if CSP settings permit, execution of arbitrary JavaScript.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qh45-328h-49g4/GHSA-qh45-328h-49g4.json b/advisories/unreviewed/2022/05/GHSA-qh45-328h-49g4/GHSA-qh45-328h-49g4.json index 19169aa1570..4d99db38d53 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh45-328h-49g4/GHSA-qh45-328h-49g4.json +++ b/advisories/unreviewed/2022/05/GHSA-qh45-328h-49g4/GHSA-qh45-328h-49g4.json @@ -7,12 +7,8 @@ "CVE-2020-12676" ], "details": "FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a \"Signature exclusion attack\".", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjcv-q7cx-q8cc/GHSA-qjcv-q7cx-q8cc.json b/advisories/unreviewed/2022/05/GHSA-qjcv-q7cx-q8cc/GHSA-qjcv-q7cx-q8cc.json index 8a8650b9a4c..c2965eb92ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjcv-q7cx-q8cc/GHSA-qjcv-q7cx-q8cc.json +++ b/advisories/unreviewed/2022/05/GHSA-qjcv-q7cx-q8cc/GHSA-qjcv-q7cx-q8cc.json @@ -7,12 +7,8 @@ "CVE-2020-12124" ], "details": "A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qm32-jcf4-2654/GHSA-qm32-jcf4-2654.json b/advisories/unreviewed/2022/05/GHSA-qm32-jcf4-2654/GHSA-qm32-jcf4-2654.json index 8ab2e13a0d5..1696a2a61da 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm32-jcf4-2654/GHSA-qm32-jcf4-2654.json +++ b/advisories/unreviewed/2022/05/GHSA-qm32-jcf4-2654/GHSA-qm32-jcf4-2654.json @@ -7,12 +7,8 @@ "CVE-2019-18991" ], "details": "A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qm5j-wrx2-x8ww/GHSA-qm5j-wrx2-x8ww.json b/advisories/unreviewed/2022/05/GHSA-qm5j-wrx2-x8ww/GHSA-qm5j-wrx2-x8ww.json index 2e7dc26a515..8c1e323ab31 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm5j-wrx2-x8ww/GHSA-qm5j-wrx2-x8ww.json +++ b/advisories/unreviewed/2022/05/GHSA-qm5j-wrx2-x8ww/GHSA-qm5j-wrx2-x8ww.json @@ -7,12 +7,8 @@ "CVE-2020-0392" ], "details": "In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-150226608", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qm8x-mfrg-qj65/GHSA-qm8x-mfrg-qj65.json b/advisories/unreviewed/2022/05/GHSA-qm8x-mfrg-qj65/GHSA-qm8x-mfrg-qj65.json index aa37cf90fe2..dfb662edfba 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm8x-mfrg-qj65/GHSA-qm8x-mfrg-qj65.json +++ b/advisories/unreviewed/2022/05/GHSA-qm8x-mfrg-qj65/GHSA-qm8x-mfrg-qj65.json @@ -7,12 +7,8 @@ "CVE-2020-26101" ], "details": "In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp3x-rc72-hc9v/GHSA-qp3x-rc72-hc9v.json b/advisories/unreviewed/2022/05/GHSA-qp3x-rc72-hc9v/GHSA-qp3x-rc72-hc9v.json index c2d3db3e27f..bd42daa3249 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp3x-rc72-hc9v/GHSA-qp3x-rc72-hc9v.json +++ b/advisories/unreviewed/2022/05/GHSA-qp3x-rc72-hc9v/GHSA-qp3x-rc72-hc9v.json @@ -7,12 +7,8 @@ "CVE-2020-0379" ], "details": "In the Bluetooth service, there is a possible spoofing attack due to a logic error. This could lead to remote information disclosure of sensitive information with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150156492", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qprx-58vg-chx6/GHSA-qprx-58vg-chx6.json b/advisories/unreviewed/2022/05/GHSA-qprx-58vg-chx6/GHSA-qprx-58vg-chx6.json index 3fa17ab820d..bb8544a01e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qprx-58vg-chx6/GHSA-qprx-58vg-chx6.json +++ b/advisories/unreviewed/2022/05/GHSA-qprx-58vg-chx6/GHSA-qprx-58vg-chx6.json @@ -7,12 +7,8 @@ "CVE-2020-6547" ], "details": "Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qpvv-49xf-2gxx/GHSA-qpvv-49xf-2gxx.json b/advisories/unreviewed/2022/05/GHSA-qpvv-49xf-2gxx/GHSA-qpvv-49xf-2gxx.json index 06c7fb81b87..58029d21816 100644 --- a/advisories/unreviewed/2022/05/GHSA-qpvv-49xf-2gxx/GHSA-qpvv-49xf-2gxx.json +++ b/advisories/unreviewed/2022/05/GHSA-qpvv-49xf-2gxx/GHSA-qpvv-49xf-2gxx.json @@ -7,12 +7,8 @@ "CVE-2019-7177" ], "details": "Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qqrm-24j7-w67q/GHSA-qqrm-24j7-w67q.json b/advisories/unreviewed/2022/05/GHSA-qqrm-24j7-w67q/GHSA-qqrm-24j7-w67q.json index 65d42d59c23..0f044e9de16 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqrm-24j7-w67q/GHSA-qqrm-24j7-w67q.json +++ b/advisories/unreviewed/2022/05/GHSA-qqrm-24j7-w67q/GHSA-qqrm-24j7-w67q.json @@ -7,12 +7,8 @@ "CVE-2020-0342" ], "details": "There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812576", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qr39-8m4r-x8hp/GHSA-qr39-8m4r-x8hp.json b/advisories/unreviewed/2022/05/GHSA-qr39-8m4r-x8hp/GHSA-qr39-8m4r-x8hp.json index 8a33e0cede2..625db6807b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr39-8m4r-x8hp/GHSA-qr39-8m4r-x8hp.json +++ b/advisories/unreviewed/2022/05/GHSA-qr39-8m4r-x8hp/GHSA-qr39-8m4r-x8hp.json @@ -7,12 +7,8 @@ "CVE-2020-0366" ], "details": "In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-138443815", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qr73-pmfq-ggfg/GHSA-qr73-pmfq-ggfg.json b/advisories/unreviewed/2022/05/GHSA-qr73-pmfq-ggfg/GHSA-qr73-pmfq-ggfg.json index 2e5654760bd..bc1b35ccf1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr73-pmfq-ggfg/GHSA-qr73-pmfq-ggfg.json +++ b/advisories/unreviewed/2022/05/GHSA-qr73-pmfq-ggfg/GHSA-qr73-pmfq-ggfg.json @@ -7,12 +7,8 @@ "CVE-2020-25149" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /device/device=345/?tab=health&metric=../ because of device/health.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrq9-x625-6h7f/GHSA-qrq9-x625-6h7f.json b/advisories/unreviewed/2022/05/GHSA-qrq9-x625-6h7f/GHSA-qrq9-x625-6h7f.json index 79a4a58e360..d9555b1e2bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrq9-x625-6h7f/GHSA-qrq9-x625-6h7f.json +++ b/advisories/unreviewed/2022/05/GHSA-qrq9-x625-6h7f/GHSA-qrq9-x625-6h7f.json @@ -7,12 +7,8 @@ "CVE-2020-15769" ], "details": "An issue was discovered in Gradle Enterprise 2020.2 - 2020.2.4. An XSS issue exists via the request URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qv9c-5frx-mxp5/GHSA-qv9c-5frx-mxp5.json b/advisories/unreviewed/2022/05/GHSA-qv9c-5frx-mxp5/GHSA-qv9c-5frx-mxp5.json index 4f5e7d1dd8d..979afac38d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qv9c-5frx-mxp5/GHSA-qv9c-5frx-mxp5.json +++ b/advisories/unreviewed/2022/05/GHSA-qv9c-5frx-mxp5/GHSA-qv9c-5frx-mxp5.json @@ -7,12 +7,8 @@ "CVE-2020-6153" ], "details": "An exploitable SQL injection vulnerability exists in the FavoritesService.asmx Web Service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. A specially crafted SOAP web request can cause an SQL injection resulting in data compromise. An attacker can send an unauthenticated HTTP request to trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qwmx-g9mf-cw7w/GHSA-qwmx-g9mf-cw7w.json b/advisories/unreviewed/2022/05/GHSA-qwmx-g9mf-cw7w/GHSA-qwmx-g9mf-cw7w.json index 143875bae21..f31f2d0bacf 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwmx-g9mf-cw7w/GHSA-qwmx-g9mf-cw7w.json +++ b/advisories/unreviewed/2022/05/GHSA-qwmx-g9mf-cw7w/GHSA-qwmx-g9mf-cw7w.json @@ -7,12 +7,8 @@ "CVE-2020-25144" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /apps/?app=../ URIs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r22g-hfmg-72m8/GHSA-r22g-hfmg-72m8.json b/advisories/unreviewed/2022/05/GHSA-r22g-hfmg-72m8/GHSA-r22g-hfmg-72m8.json index f60c0f8af27..0a1bc188ee0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r22g-hfmg-72m8/GHSA-r22g-hfmg-72m8.json +++ b/advisories/unreviewed/2022/05/GHSA-r22g-hfmg-72m8/GHSA-r22g-hfmg-72m8.json @@ -7,12 +7,8 @@ "CVE-2020-24621" ], "details": "A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r4mh-c83r-pv4f/GHSA-r4mh-c83r-pv4f.json b/advisories/unreviewed/2022/05/GHSA-r4mh-c83r-pv4f/GHSA-r4mh-c83r-pv4f.json index 66d4ea42a66..29ac0eb3e69 100644 --- a/advisories/unreviewed/2022/05/GHSA-r4mh-c83r-pv4f/GHSA-r4mh-c83r-pv4f.json +++ b/advisories/unreviewed/2022/05/GHSA-r4mh-c83r-pv4f/GHSA-r4mh-c83r-pv4f.json @@ -7,12 +7,8 @@ "CVE-2020-16198" ], "details": "Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. When an attacker claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r536-4rjh-7q6r/GHSA-r536-4rjh-7q6r.json b/advisories/unreviewed/2022/05/GHSA-r536-4rjh-7q6r/GHSA-r536-4rjh-7q6r.json index 08c8b0ecc54..6d766a44bfe 100644 --- a/advisories/unreviewed/2022/05/GHSA-r536-4rjh-7q6r/GHSA-r536-4rjh-7q6r.json +++ b/advisories/unreviewed/2022/05/GHSA-r536-4rjh-7q6r/GHSA-r536-4rjh-7q6r.json @@ -7,12 +7,8 @@ "CVE-2020-5781" ], "details": "In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/config/luci) by the authenticator.htmlauth function. When modified with arbitrary javascript, this causes a denial-of-service condition for all other users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r6pf-3j3c-px2j/GHSA-r6pf-3j3c-px2j.json b/advisories/unreviewed/2022/05/GHSA-r6pf-3j3c-px2j/GHSA-r6pf-3j3c-px2j.json index 122ea0a4c64..20a6c04b664 100644 --- a/advisories/unreviewed/2022/05/GHSA-r6pf-3j3c-px2j/GHSA-r6pf-3j3c-px2j.json +++ b/advisories/unreviewed/2022/05/GHSA-r6pf-3j3c-px2j/GHSA-r6pf-3j3c-px2j.json @@ -7,12 +7,8 @@ "CVE-2020-0332" ], "details": "In libstagefright, there is a possible dead loop due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124783982", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r73h-rm5p-mq5f/GHSA-r73h-rm5p-mq5f.json b/advisories/unreviewed/2022/05/GHSA-r73h-rm5p-mq5f/GHSA-r73h-rm5p-mq5f.json index 053c16e4867..cc2664e538c 100644 --- a/advisories/unreviewed/2022/05/GHSA-r73h-rm5p-mq5f/GHSA-r73h-rm5p-mq5f.json +++ b/advisories/unreviewed/2022/05/GHSA-r73h-rm5p-mq5f/GHSA-r73h-rm5p-mq5f.json @@ -7,12 +7,8 @@ "CVE-2020-15963" ], "details": "Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rcww-hf7q-p3x9/GHSA-rcww-hf7q-p3x9.json b/advisories/unreviewed/2022/05/GHSA-rcww-hf7q-p3x9/GHSA-rcww-hf7q-p3x9.json index dd99b1d6d6e..c02d3ad7d94 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcww-hf7q-p3x9/GHSA-rcww-hf7q-p3x9.json +++ b/advisories/unreviewed/2022/05/GHSA-rcww-hf7q-p3x9/GHSA-rcww-hf7q-p3x9.json @@ -7,12 +7,8 @@ "CVE-2020-4340" ], "details": "IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate validation. IBM X-Force ID: 178180.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rf85-8538-r3fv/GHSA-rf85-8538-r3fv.json b/advisories/unreviewed/2022/05/GHSA-rf85-8538-r3fv/GHSA-rf85-8538-r3fv.json index dd0ad8f0f40..d2cb756da3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf85-8538-r3fv/GHSA-rf85-8538-r3fv.json +++ b/advisories/unreviewed/2022/05/GHSA-rf85-8538-r3fv/GHSA-rf85-8538-r3fv.json @@ -7,12 +7,8 @@ "CVE-2020-6570" ], "details": "Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rfmg-4pjp-2fr4/GHSA-rfmg-4pjp-2fr4.json b/advisories/unreviewed/2022/05/GHSA-rfmg-4pjp-2fr4/GHSA-rfmg-4pjp-2fr4.json index cb1a33836d8..9594078a979 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfmg-4pjp-2fr4/GHSA-rfmg-4pjp-2fr4.json +++ b/advisories/unreviewed/2022/05/GHSA-rfmg-4pjp-2fr4/GHSA-rfmg-4pjp-2fr4.json @@ -7,12 +7,8 @@ "CVE-2020-16202" ], "details": "WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rhfw-3659-4c6v/GHSA-rhfw-3659-4c6v.json b/advisories/unreviewed/2022/05/GHSA-rhfw-3659-4c6v/GHSA-rhfw-3659-4c6v.json index b96a16a4f92..ed868adc0c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhfw-3659-4c6v/GHSA-rhfw-3659-4c6v.json +++ b/advisories/unreviewed/2022/05/GHSA-rhfw-3659-4c6v/GHSA-rhfw-3659-4c6v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rhj2-pj5f-9276/GHSA-rhj2-pj5f-9276.json b/advisories/unreviewed/2022/05/GHSA-rhj2-pj5f-9276/GHSA-rhj2-pj5f-9276.json index 5f1d850264e..25144f14ade 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhj2-pj5f-9276/GHSA-rhj2-pj5f-9276.json +++ b/advisories/unreviewed/2022/05/GHSA-rhj2-pj5f-9276/GHSA-rhj2-pj5f-9276.json @@ -7,12 +7,8 @@ "CVE-2019-16019" ], "details": "Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit these vulnerabilities, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rhjr-m7qm-78wr/GHSA-rhjr-m7qm-78wr.json b/advisories/unreviewed/2022/05/GHSA-rhjr-m7qm-78wr/GHSA-rhjr-m7qm-78wr.json index c1b2169e3d8..508533f1266 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhjr-m7qm-78wr/GHSA-rhjr-m7qm-78wr.json +++ b/advisories/unreviewed/2022/05/GHSA-rhjr-m7qm-78wr/GHSA-rhjr-m7qm-78wr.json @@ -7,12 +7,8 @@ "CVE-2019-16017" ], "details": "A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to execute Insecure Direct Object Reference actions on specific pages within the OAMP application. The vulnerability is due to insufficient input validation on specific pages of the OAMP application. An attacker could exploit this vulnerability by authenticating to Cisco Unified CVP and sending crafted HTTP requests. A successful exploit could allow an attacker with administrator or read-only privileges to learn information outside of their expected scope. An attacker with administrator privileges could modify certain configuration details of resources outside of their defined scope, which could result in a denial of service (DoS) condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rjv3-2qfq-x6pf/GHSA-rjv3-2qfq-x6pf.json b/advisories/unreviewed/2022/05/GHSA-rjv3-2qfq-x6pf/GHSA-rjv3-2qfq-x6pf.json index bd945caa48b..766090fd26e 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjv3-2qfq-x6pf/GHSA-rjv3-2qfq-x6pf.json +++ b/advisories/unreviewed/2022/05/GHSA-rjv3-2qfq-x6pf/GHSA-rjv3-2qfq-x6pf.json @@ -7,12 +7,8 @@ "CVE-2020-0373" ], "details": "In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146894086", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rjvx-q2j5-w235/GHSA-rjvx-q2j5-w235.json b/advisories/unreviewed/2022/05/GHSA-rjvx-q2j5-w235/GHSA-rjvx-q2j5-w235.json index 5cb7d8e831b..a72d55881a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-rjvx-q2j5-w235/GHSA-rjvx-q2j5-w235.json +++ b/advisories/unreviewed/2022/05/GHSA-rjvx-q2j5-w235/GHSA-rjvx-q2j5-w235.json @@ -7,12 +7,8 @@ "CVE-2020-12816" ], "details": "An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin Users.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rm2c-w33r-fvgv/GHSA-rm2c-w33r-fvgv.json b/advisories/unreviewed/2022/05/GHSA-rm2c-w33r-fvgv/GHSA-rm2c-w33r-fvgv.json index 3a45fc6c259..e7beb24d3f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm2c-w33r-fvgv/GHSA-rm2c-w33r-fvgv.json +++ b/advisories/unreviewed/2022/05/GHSA-rm2c-w33r-fvgv/GHSA-rm2c-w33r-fvgv.json @@ -7,12 +7,8 @@ "CVE-2020-24592" ], "details": "Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rm8f-cg8j-qqw7/GHSA-rm8f-cg8j-qqw7.json b/advisories/unreviewed/2022/05/GHSA-rm8f-cg8j-qqw7/GHSA-rm8f-cg8j-qqw7.json index 72aef1a93b3..11796e3bf27 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm8f-cg8j-qqw7/GHSA-rm8f-cg8j-qqw7.json +++ b/advisories/unreviewed/2022/05/GHSA-rm8f-cg8j-qqw7/GHSA-rm8f-cg8j-qqw7.json @@ -7,12 +7,8 @@ "CVE-2020-3137" ], "details": "A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface of the affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or to access sensitive, browser-based information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rmvq-vf32-r4h4/GHSA-rmvq-vf32-r4h4.json b/advisories/unreviewed/2022/05/GHSA-rmvq-vf32-r4h4/GHSA-rmvq-vf32-r4h4.json index 971a3c27dc2..b27332897c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmvq-vf32-r4h4/GHSA-rmvq-vf32-r4h4.json +++ b/advisories/unreviewed/2022/05/GHSA-rmvq-vf32-r4h4/GHSA-rmvq-vf32-r4h4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rmx4-hffj-96cf/GHSA-rmx4-hffj-96cf.json b/advisories/unreviewed/2022/05/GHSA-rmx4-hffj-96cf/GHSA-rmx4-hffj-96cf.json index cc314b4d272..9ada08774c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmx4-hffj-96cf/GHSA-rmx4-hffj-96cf.json +++ b/advisories/unreviewed/2022/05/GHSA-rmx4-hffj-96cf/GHSA-rmx4-hffj-96cf.json @@ -7,12 +7,8 @@ "CVE-2020-14376" ], "details": "A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpc9-7g4h-432m/GHSA-rpc9-7g4h-432m.json b/advisories/unreviewed/2022/05/GHSA-rpc9-7g4h-432m/GHSA-rpc9-7g4h-432m.json index 4d609d08f2f..b75c99a834f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpc9-7g4h-432m/GHSA-rpc9-7g4h-432m.json +++ b/advisories/unreviewed/2022/05/GHSA-rpc9-7g4h-432m/GHSA-rpc9-7g4h-432m.json @@ -7,12 +7,8 @@ "CVE-2020-21244" ], "details": "An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rpm8-r8v3-f2rg/GHSA-rpm8-r8v3-f2rg.json b/advisories/unreviewed/2022/05/GHSA-rpm8-r8v3-f2rg/GHSA-rpm8-r8v3-f2rg.json index 9166390955d..36ce563423c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpm8-r8v3-f2rg/GHSA-rpm8-r8v3-f2rg.json +++ b/advisories/unreviewed/2022/05/GHSA-rpm8-r8v3-f2rg/GHSA-rpm8-r8v3-f2rg.json @@ -7,12 +7,8 @@ "CVE-2020-3492" ], "details": "A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers and Cisco AireOS Software for Cisco Wireless LAN Controllers (WLC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of certain parameters in a Flexible NetFlow Version 9 record. An attacker could exploit this vulnerability by spoofing the address of an existing Access Point on the network and sending a Control and Provisioning of Wireless Access Points (CAPWAP) packet that includes a crafted Flexible NetFlow Version 9 record to an affected device. A successful exploit could allow the attacker to cause a process crash that would lead to a reload of the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rpvq-7m68-cp2r/GHSA-rpvq-7m68-cp2r.json b/advisories/unreviewed/2022/05/GHSA-rpvq-7m68-cp2r/GHSA-rpvq-7m68-cp2r.json index 472444a3eb6..db841320565 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpvq-7m68-cp2r/GHSA-rpvq-7m68-cp2r.json +++ b/advisories/unreviewed/2022/05/GHSA-rpvq-7m68-cp2r/GHSA-rpvq-7m68-cp2r.json @@ -7,12 +7,8 @@ "CVE-2020-14028" ], "details": "An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Autoreply module's Script Name, an attacker may write to or overwrite arbitrary files, with arbitrary content, usually with NT AUTHORITY\\SYSTEM privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rq8v-cw5g-45r5/GHSA-rq8v-cw5g-45r5.json b/advisories/unreviewed/2022/05/GHSA-rq8v-cw5g-45r5/GHSA-rq8v-cw5g-45r5.json index 0aee9e7d50b..cc1ee37b605 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq8v-cw5g-45r5/GHSA-rq8v-cw5g-45r5.json +++ b/advisories/unreviewed/2022/05/GHSA-rq8v-cw5g-45r5/GHSA-rq8v-cw5g-45r5.json @@ -7,12 +7,8 @@ "CVE-2020-4615" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184928.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrg8-mgx4-vjw8/GHSA-rrg8-mgx4-vjw8.json b/advisories/unreviewed/2022/05/GHSA-rrg8-mgx4-vjw8/GHSA-rrg8-mgx4-vjw8.json index 4a0e7d5623a..78471319651 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrg8-mgx4-vjw8/GHSA-rrg8-mgx4-vjw8.json +++ b/advisories/unreviewed/2022/05/GHSA-rrg8-mgx4-vjw8/GHSA-rrg8-mgx4-vjw8.json @@ -7,12 +7,8 @@ "CVE-2020-14294" ], "details": "An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when reading transfer comments or the global notice board.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rv6j-7cg9-mxj7/GHSA-rv6j-7cg9-mxj7.json b/advisories/unreviewed/2022/05/GHSA-rv6j-7cg9-mxj7/GHSA-rv6j-7cg9-mxj7.json index 2e2081c5f33..1f917aaf37a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv6j-7cg9-mxj7/GHSA-rv6j-7cg9-mxj7.json +++ b/advisories/unreviewed/2022/05/GHSA-rv6j-7cg9-mxj7/GHSA-rv6j-7cg9-mxj7.json @@ -7,12 +7,8 @@ "CVE-2020-19447" ], "details": "SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwmh-92fw-c49r/GHSA-rwmh-92fw-c49r.json b/advisories/unreviewed/2022/05/GHSA-rwmh-92fw-c49r/GHSA-rwmh-92fw-c49r.json index c93e35513d0..24373a4c6ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwmh-92fw-c49r/GHSA-rwmh-92fw-c49r.json +++ b/advisories/unreviewed/2022/05/GHSA-rwmh-92fw-c49r/GHSA-rwmh-92fw-c49r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rwvv-h93r-mw45/GHSA-rwvv-h93r-mw45.json b/advisories/unreviewed/2022/05/GHSA-rwvv-h93r-mw45/GHSA-rwvv-h93r-mw45.json index 9737a3114a3..963845cd3dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwvv-h93r-mw45/GHSA-rwvv-h93r-mw45.json +++ b/advisories/unreviewed/2022/05/GHSA-rwvv-h93r-mw45/GHSA-rwvv-h93r-mw45.json @@ -7,12 +7,8 @@ "CVE-2020-17482" ], "details": "An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rx2w-m3fv-4jgc/GHSA-rx2w-m3fv-4jgc.json b/advisories/unreviewed/2022/05/GHSA-rx2w-m3fv-4jgc/GHSA-rx2w-m3fv-4jgc.json index 437d31edc59..06e07029388 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx2w-m3fv-4jgc/GHSA-rx2w-m3fv-4jgc.json +++ b/advisories/unreviewed/2022/05/GHSA-rx2w-m3fv-4jgc/GHSA-rx2w-m3fv-4jgc.json @@ -7,12 +7,8 @@ "CVE-2020-25763" ], "details": "Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rx66-wgx3-2ccf/GHSA-rx66-wgx3-2ccf.json b/advisories/unreviewed/2022/05/GHSA-rx66-wgx3-2ccf/GHSA-rx66-wgx3-2ccf.json index 629fa6434dd..344d3b62314 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx66-wgx3-2ccf/GHSA-rx66-wgx3-2ccf.json +++ b/advisories/unreviewed/2022/05/GHSA-rx66-wgx3-2ccf/GHSA-rx66-wgx3-2ccf.json @@ -7,12 +7,8 @@ "CVE-2020-5929" ], "details": "In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware acceleration cards, a Virtual Server configured with a Client SSL profile, and using Anonymous (ADH) or Ephemeral (DHE) Diffie-Hellman key exchange and Single DH use option not enabled in the options list may be vulnerable to crafted SSL/TLS Handshakes that may result with a PMS (Pre-Master Secret) that starts in a 0 byte and may lead to a recovery of plaintext messages as BIG-IP TLS/SSL ADH/DHE sends different error messages acting as an oracle. Similar error messages when PMS starts with 0 byte coupled with very precise timing measurement observation may also expose this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rxc8-7xh9-c8vm/GHSA-rxc8-7xh9-c8vm.json b/advisories/unreviewed/2022/05/GHSA-rxc8-7xh9-c8vm/GHSA-rxc8-7xh9-c8vm.json index f3b985916d6..623f58f9367 100644 --- a/advisories/unreviewed/2022/05/GHSA-rxc8-7xh9-c8vm/GHSA-rxc8-7xh9-c8vm.json +++ b/advisories/unreviewed/2022/05/GHSA-rxc8-7xh9-c8vm/GHSA-rxc8-7xh9-c8vm.json @@ -7,12 +7,8 @@ "CVE-2020-5784" ], "details": "Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v379-w98r-25cr/GHSA-v379-w98r-25cr.json b/advisories/unreviewed/2022/05/GHSA-v379-w98r-25cr/GHSA-v379-w98r-25cr.json index 7f2a52e8e85..a2c679654f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-v379-w98r-25cr/GHSA-v379-w98r-25cr.json +++ b/advisories/unreviewed/2022/05/GHSA-v379-w98r-25cr/GHSA-v379-w98r-25cr.json @@ -7,12 +7,8 @@ "CVE-2020-3399" ], "details": "A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insufficient input validation during CAPWAP packet processing. An attacker could exploit this vulnerability by sending a crafted CAPWAP packet to an affected device, resulting in a buffer over-read. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4cp-84g9-jwmp/GHSA-v4cp-84g9-jwmp.json b/advisories/unreviewed/2022/05/GHSA-v4cp-84g9-jwmp/GHSA-v4cp-84g9-jwmp.json index 7a23681d9c9..e656af2ea60 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4cp-84g9-jwmp/GHSA-v4cp-84g9-jwmp.json +++ b/advisories/unreviewed/2022/05/GHSA-v4cp-84g9-jwmp/GHSA-v4cp-84g9-jwmp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v575-q5p6-4v97/GHSA-v575-q5p6-4v97.json b/advisories/unreviewed/2022/05/GHSA-v575-q5p6-4v97/GHSA-v575-q5p6-4v97.json index ffe390402e8..a924cf370c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-v575-q5p6-4v97/GHSA-v575-q5p6-4v97.json +++ b/advisories/unreviewed/2022/05/GHSA-v575-q5p6-4v97/GHSA-v575-q5p6-4v97.json @@ -7,12 +7,8 @@ "CVE-2020-9084" ], "details": "Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5rw-6r3r-56jg/GHSA-v5rw-6r3r-56jg.json b/advisories/unreviewed/2022/05/GHSA-v5rw-6r3r-56jg/GHSA-v5rw-6r3r-56jg.json index 39536ed6df3..b9efd6e9b84 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5rw-6r3r-56jg/GHSA-v5rw-6r3r-56jg.json +++ b/advisories/unreviewed/2022/05/GHSA-v5rw-6r3r-56jg/GHSA-v5rw-6r3r-56jg.json @@ -7,12 +7,8 @@ "CVE-2020-0351" ], "details": "In libstagefright, there is possible CPU exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124777537", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6r4-c6r4-r649/GHSA-v6r4-c6r4-r649.json b/advisories/unreviewed/2022/05/GHSA-v6r4-c6r4-r649/GHSA-v6r4-c6r4-r649.json index 9231db2228a..4fbcc956b46 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6r4-c6r4-r649/GHSA-v6r4-c6r4-r649.json +++ b/advisories/unreviewed/2022/05/GHSA-v6r4-c6r4-r649/GHSA-v6r4-c6r4-r649.json @@ -7,12 +7,8 @@ "CVE-2019-1983" ], "details": "A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of email attachments. An attacker could exploit this vulnerability by sending an email message with a crafted attachment through an affected device. A successful exploit could allow the attacker to cause specific processes to crash repeatedly, resulting in the complete unavailability of both the Cisco Advanced Malware Protection (AMP) and message tracking features and in severe performance degradation while processing email. After the affected processes restart, the software resumes filtering for the same attachment, causing the affected processes to crash and restart again. A successful exploit could also allow the attacker to cause a repeated DoS condition. Manual intervention may be required to recover from this situation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v78j-8xxm-8wgf/GHSA-v78j-8xxm-8wgf.json b/advisories/unreviewed/2022/05/GHSA-v78j-8xxm-8wgf/GHSA-v78j-8xxm-8wgf.json index ec0d6071a95..92b6d690fd3 100644 --- a/advisories/unreviewed/2022/05/GHSA-v78j-8xxm-8wgf/GHSA-v78j-8xxm-8wgf.json +++ b/advisories/unreviewed/2022/05/GHSA-v78j-8xxm-8wgf/GHSA-v78j-8xxm-8wgf.json @@ -7,12 +7,8 @@ "CVE-2020-26158" ], "details": "Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vf6r-32rf-hv67/GHSA-vf6r-32rf-hv67.json b/advisories/unreviewed/2022/05/GHSA-vf6r-32rf-hv67/GHSA-vf6r-32rf-hv67.json index cfb42880904..e38e382a0ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf6r-32rf-hv67/GHSA-vf6r-32rf-hv67.json +++ b/advisories/unreviewed/2022/05/GHSA-vf6r-32rf-hv67/GHSA-vf6r-32rf-hv67.json @@ -7,12 +7,8 @@ "CVE-2020-24861" ], "details": "GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vfj5-r4fr-mp4h/GHSA-vfj5-r4fr-mp4h.json b/advisories/unreviewed/2022/05/GHSA-vfj5-r4fr-mp4h/GHSA-vfj5-r4fr-mp4h.json index 3557789de69..a2b907123ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfj5-r4fr-mp4h/GHSA-vfj5-r4fr-mp4h.json +++ b/advisories/unreviewed/2022/05/GHSA-vfj5-r4fr-mp4h/GHSA-vfj5-r4fr-mp4h.json @@ -7,12 +7,8 @@ "CVE-2020-6539" ], "details": "Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfmw-qwch-35g6/GHSA-vfmw-qwch-35g6.json b/advisories/unreviewed/2022/05/GHSA-vfmw-qwch-35g6/GHSA-vfmw-qwch-35g6.json index 1ac2aa841c5..45032ca25bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfmw-qwch-35g6/GHSA-vfmw-qwch-35g6.json +++ b/advisories/unreviewed/2022/05/GHSA-vfmw-qwch-35g6/GHSA-vfmw-qwch-35g6.json @@ -7,12 +7,8 @@ "CVE-2020-24615" ], "details": "Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjrm-wv6p-w4vm/GHSA-vjrm-wv6p-w4vm.json b/advisories/unreviewed/2022/05/GHSA-vjrm-wv6p-w4vm/GHSA-vjrm-wv6p-w4vm.json index 046cf9dab9e..86287771b7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjrm-wv6p-w4vm/GHSA-vjrm-wv6p-w4vm.json +++ b/advisories/unreviewed/2022/05/GHSA-vjrm-wv6p-w4vm/GHSA-vjrm-wv6p-w4vm.json @@ -7,12 +7,8 @@ "CVE-2020-0360" ], "details": "In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145129456", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vm7v-pxq2-f7qr/GHSA-vm7v-pxq2-f7qr.json b/advisories/unreviewed/2022/05/GHSA-vm7v-pxq2-f7qr/GHSA-vm7v-pxq2-f7qr.json index ab29cd0aa58..9f821425bbd 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm7v-pxq2-f7qr/GHSA-vm7v-pxq2-f7qr.json +++ b/advisories/unreviewed/2022/05/GHSA-vm7v-pxq2-f7qr/GHSA-vm7v-pxq2-f7qr.json @@ -7,12 +7,8 @@ "CVE-2020-12126" ], "details": "Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmh3-rhm9-223f/GHSA-vmh3-rhm9-223f.json b/advisories/unreviewed/2022/05/GHSA-vmh3-rhm9-223f/GHSA-vmh3-rhm9-223f.json index 994ea3d1dee..d58bfc47a01 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmh3-rhm9-223f/GHSA-vmh3-rhm9-223f.json +++ b/advisories/unreviewed/2022/05/GHSA-vmh3-rhm9-223f/GHSA-vmh3-rhm9-223f.json @@ -7,12 +7,8 @@ "CVE-2020-3359" ], "details": "A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of mDNS packets. An attacker could exploit this vulnerability by sending a crafted mDNS packet to an affected device. A successful exploit could cause a device to reload, resulting in a DoS condition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vpm9-g2jr-94gp/GHSA-vpm9-g2jr-94gp.json b/advisories/unreviewed/2022/05/GHSA-vpm9-g2jr-94gp/GHSA-vpm9-g2jr-94gp.json index 8a397ec0fc8..efa472cf769 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpm9-g2jr-94gp/GHSA-vpm9-g2jr-94gp.json +++ b/advisories/unreviewed/2022/05/GHSA-vpm9-g2jr-94gp/GHSA-vpm9-g2jr-94gp.json @@ -7,12 +7,8 @@ "CVE-2020-6541" ], "details": "Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vq4g-mcpm-2jhv/GHSA-vq4g-mcpm-2jhv.json b/advisories/unreviewed/2022/05/GHSA-vq4g-mcpm-2jhv/GHSA-vq4g-mcpm-2jhv.json index 0f1f89291e7..076dbd41a52 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq4g-mcpm-2jhv/GHSA-vq4g-mcpm-2jhv.json +++ b/advisories/unreviewed/2022/05/GHSA-vq4g-mcpm-2jhv/GHSA-vq4g-mcpm-2jhv.json @@ -7,12 +7,8 @@ "CVE-2020-26111" ], "details": "cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vq75-425f-vq6r/GHSA-vq75-425f-vq6r.json b/advisories/unreviewed/2022/05/GHSA-vq75-425f-vq6r/GHSA-vq75-425f-vq6r.json index 898972f81ad..3e978a92a9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vq75-425f-vq6r/GHSA-vq75-425f-vq6r.json +++ b/advisories/unreviewed/2022/05/GHSA-vq75-425f-vq6r/GHSA-vq75-425f-vq6r.json @@ -7,12 +7,8 @@ "CVE-2020-16200" ], "details": "Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vqf4-g492-5236/GHSA-vqf4-g492-5236.json b/advisories/unreviewed/2022/05/GHSA-vqf4-g492-5236/GHSA-vqf4-g492-5236.json index d0bc9d30743..5b36f7d8250 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqf4-g492-5236/GHSA-vqf4-g492-5236.json +++ b/advisories/unreviewed/2022/05/GHSA-vqf4-g492-5236/GHSA-vqf4-g492-5236.json @@ -7,12 +7,8 @@ "CVE-2020-12715" ], "details": "RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vrwx-q9pj-x488/GHSA-vrwx-q9pj-x488.json b/advisories/unreviewed/2022/05/GHSA-vrwx-q9pj-x488/GHSA-vrwx-q9pj-x488.json index c6b8e76205f..58e512cce38 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrwx-q9pj-x488/GHSA-vrwx-q9pj-x488.json +++ b/advisories/unreviewed/2022/05/GHSA-vrwx-q9pj-x488/GHSA-vrwx-q9pj-x488.json @@ -7,12 +7,8 @@ "CVE-2020-15840" ], "details": "In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vv6f-f322-w3fx/GHSA-vv6f-f322-w3fx.json b/advisories/unreviewed/2022/05/GHSA-vv6f-f322-w3fx/GHSA-vv6f-f322-w3fx.json index ad57152408e..1456583aea7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv6f-f322-w3fx/GHSA-vv6f-f322-w3fx.json +++ b/advisories/unreviewed/2022/05/GHSA-vv6f-f322-w3fx/GHSA-vv6f-f322-w3fx.json @@ -7,12 +7,8 @@ "CVE-2020-3477" ], "details": "A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem. The vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by using a specific command at the command line. A successful exploit could allow the attacker to obtain read-only access to files that are located on the flash: filesystem that otherwise might not have been accessible.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vwmh-rhvf-4w28/GHSA-vwmh-rhvf-4w28.json b/advisories/unreviewed/2022/05/GHSA-vwmh-rhvf-4w28/GHSA-vwmh-rhvf-4w28.json index 6275ae09ade..98e1fd77016 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwmh-rhvf-4w28/GHSA-vwmh-rhvf-4w28.json +++ b/advisories/unreviewed/2022/05/GHSA-vwmh-rhvf-4w28/GHSA-vwmh-rhvf-4w28.json @@ -7,12 +7,8 @@ "CVE-2020-0324" ], "details": "In libsonivox, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136660304", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vx94-9hx7-9hmw/GHSA-vx94-9hx7-9hmw.json b/advisories/unreviewed/2022/05/GHSA-vx94-9hx7-9hmw/GHSA-vx94-9hx7-9hmw.json index 7425dfe511e..c5eb3c1a9a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vx94-9hx7-9hmw/GHSA-vx94-9hx7-9hmw.json +++ b/advisories/unreviewed/2022/05/GHSA-vx94-9hx7-9hmw/GHSA-vx94-9hx7-9hmw.json @@ -7,12 +7,8 @@ "CVE-2020-15771" ], "details": "An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. CSRF mitigation can be bypassed because cross-site transmission of a cookie (containing a CSRF token) can occur.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vxv7-j638-5g5x/GHSA-vxv7-j638-5g5x.json b/advisories/unreviewed/2022/05/GHSA-vxv7-j638-5g5x/GHSA-vxv7-j638-5g5x.json index ba46682bcb3..7553026c140 100644 --- a/advisories/unreviewed/2022/05/GHSA-vxv7-j638-5g5x/GHSA-vxv7-j638-5g5x.json +++ b/advisories/unreviewed/2022/05/GHSA-vxv7-j638-5g5x/GHSA-vxv7-j638-5g5x.json @@ -7,12 +7,8 @@ "CVE-2020-25133" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /ports/?format=../ URIs to pages/ports.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w2c9-99w6-qcrh/GHSA-w2c9-99w6-qcrh.json b/advisories/unreviewed/2022/05/GHSA-w2c9-99w6-qcrh/GHSA-w2c9-99w6-qcrh.json index f0c045ee90a..bc5c57d9da6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2c9-99w6-qcrh/GHSA-w2c9-99w6-qcrh.json +++ b/advisories/unreviewed/2022/05/GHSA-w2c9-99w6-qcrh/GHSA-w2c9-99w6-qcrh.json @@ -7,12 +7,8 @@ "CVE-2020-15767" ], "details": "An issue was discovered in Gradle Enterprise before 2020.2.5. Lack of the secure attribute on the anti-CSRF cookie allows an attacker (with the ability to read HTTP traffic) to obtain a user's anti-CSRF token if the user initiates a cleartext HTTP request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w42q-r5v6-qw8j/GHSA-w42q-r5v6-qw8j.json b/advisories/unreviewed/2022/05/GHSA-w42q-r5v6-qw8j/GHSA-w42q-r5v6-qw8j.json index d3a6faadc6b..9a04e832e5e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w42q-r5v6-qw8j/GHSA-w42q-r5v6-qw8j.json +++ b/advisories/unreviewed/2022/05/GHSA-w42q-r5v6-qw8j/GHSA-w42q-r5v6-qw8j.json @@ -7,12 +7,8 @@ "CVE-2020-8200" ], "details": "Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w5h8-gj7c-wr5p/GHSA-w5h8-gj7c-wr5p.json b/advisories/unreviewed/2022/05/GHSA-w5h8-gj7c-wr5p/GHSA-w5h8-gj7c-wr5p.json index 230afa3d185..4a5344a4888 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5h8-gj7c-wr5p/GHSA-w5h8-gj7c-wr5p.json +++ b/advisories/unreviewed/2022/05/GHSA-w5h8-gj7c-wr5p/GHSA-w5h8-gj7c-wr5p.json @@ -7,12 +7,8 @@ "CVE-2020-0382" ], "details": "In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-152944488", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w626-fpjc-h33x/GHSA-w626-fpjc-h33x.json b/advisories/unreviewed/2022/05/GHSA-w626-fpjc-h33x/GHSA-w626-fpjc-h33x.json index 4452e909aee..c6e2aa26222 100644 --- a/advisories/unreviewed/2022/05/GHSA-w626-fpjc-h33x/GHSA-w626-fpjc-h33x.json +++ b/advisories/unreviewed/2022/05/GHSA-w626-fpjc-h33x/GHSA-w626-fpjc-h33x.json @@ -7,12 +7,8 @@ "CVE-2019-16021" ], "details": "Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic only from explicitly defined peers. To exploit these vulnerabilities, the malicious BGP update message would need to come from a configured, valid BGP peer, or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6g7-p99g-wfqw/GHSA-w6g7-p99g-wfqw.json b/advisories/unreviewed/2022/05/GHSA-w6g7-p99g-wfqw/GHSA-w6g7-p99g-wfqw.json index 93e387c4c41..e3ca7bab4fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6g7-p99g-wfqw/GHSA-w6g7-p99g-wfqw.json +++ b/advisories/unreviewed/2022/05/GHSA-w6g7-p99g-wfqw/GHSA-w6g7-p99g-wfqw.json @@ -7,12 +7,8 @@ "CVE-2020-25136" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /device/device=345/?tab=routing&proto=../ URIs to device/routing.inc.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w74p-9j5g-g6g8/GHSA-w74p-9j5g-g6g8.json b/advisories/unreviewed/2022/05/GHSA-w74p-9j5g-g6g8/GHSA-w74p-9j5g-g6g8.json index b4a2be304ab..27bc82dc6b8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w74p-9j5g-g6g8/GHSA-w74p-9j5g-g6g8.json +++ b/advisories/unreviewed/2022/05/GHSA-w74p-9j5g-g6g8/GHSA-w74p-9j5g-g6g8.json @@ -7,12 +7,8 @@ "CVE-2019-15289" ], "details": "Multiple vulnerabilities in the video service of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted traffic to the video service of an affected endpoint. A successful exploit could allow the attacker to cause the video service to crash, resulting in a DoS condition on an affected device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w7pp-8xw9-cmxg/GHSA-w7pp-8xw9-cmxg.json b/advisories/unreviewed/2022/05/GHSA-w7pp-8xw9-cmxg/GHSA-w7pp-8xw9-cmxg.json index 1aba25c8168..07e0ce649c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7pp-8xw9-cmxg/GHSA-w7pp-8xw9-cmxg.json +++ b/advisories/unreviewed/2022/05/GHSA-w7pp-8xw9-cmxg/GHSA-w7pp-8xw9-cmxg.json @@ -7,12 +7,8 @@ "CVE-2020-25130" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. Sending an improper variable type of Array allows a bypass of core SQL Injection sanitization. Authenticated users are able to inject malicious SQL queries. This vulnerability leads to full database leak including ckeys that can be used in the authentication process without knowing the username and cleartext password. This can occur via the ajax/actions.php group_id field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w944-cr63-4f5x/GHSA-w944-cr63-4f5x.json b/advisories/unreviewed/2022/05/GHSA-w944-cr63-4f5x/GHSA-w944-cr63-4f5x.json index e668c0c71e0..837b300f1c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w944-cr63-4f5x/GHSA-w944-cr63-4f5x.json +++ b/advisories/unreviewed/2022/05/GHSA-w944-cr63-4f5x/GHSA-w944-cr63-4f5x.json @@ -7,12 +7,8 @@ "CVE-2020-13505" ], "details": "Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w99f-f6h3-qccc/GHSA-w99f-f6h3-qccc.json b/advisories/unreviewed/2022/05/GHSA-w99f-f6h3-qccc/GHSA-w99f-f6h3-qccc.json index c44dc87cebb..cd870e6f694 100644 --- a/advisories/unreviewed/2022/05/GHSA-w99f-f6h3-qccc/GHSA-w99f-f6h3-qccc.json +++ b/advisories/unreviewed/2022/05/GHSA-w99f-f6h3-qccc/GHSA-w99f-f6h3-qccc.json @@ -7,12 +7,8 @@ "CVE-2020-3509" ], "details": "A vulnerability in the DHCP message handler of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the supervisor to crash, which could result in a denial of service (DoS) condition. The vulnerability is due to insufficient error handling when DHCP version 4 (DHCPv4) messages are parsed. An attacker could exploit this vulnerability by sending a malicious DHCPv4 message to or through a WAN interface of an affected device. A successful exploit could allow the attacker to cause a reload of the affected device. Note: On Cisco cBR-8 Converged Broadband Routers, all of the following are considered WAN interfaces: 10 Gbps Ethernet interfaces 100 Gbps Ethernet interfaces Port channel interfaces that include multiple 10 and/or 100 Gbps Ethernet interfaces", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcpp-58jv-4c64/GHSA-wcpp-58jv-4c64.json b/advisories/unreviewed/2022/05/GHSA-wcpp-58jv-4c64/GHSA-wcpp-58jv-4c64.json index 0ac5b5154fb..216d081b70d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcpp-58jv-4c64/GHSA-wcpp-58jv-4c64.json +++ b/advisories/unreviewed/2022/05/GHSA-wcpp-58jv-4c64/GHSA-wcpp-58jv-4c64.json @@ -7,12 +7,8 @@ "CVE-2020-12837" ], "details": "ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wh6w-5m55-xqm7/GHSA-wh6w-5m55-xqm7.json b/advisories/unreviewed/2022/05/GHSA-wh6w-5m55-xqm7/GHSA-wh6w-5m55-xqm7.json index 41d3d106155..879565db7ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh6w-5m55-xqm7/GHSA-wh6w-5m55-xqm7.json +++ b/advisories/unreviewed/2022/05/GHSA-wh6w-5m55-xqm7/GHSA-wh6w-5m55-xqm7.json @@ -7,12 +7,8 @@ "CVE-2020-25142" ], "details": "An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable if any links and forms lack an unpredictable CSRF token. Without such a token, attackers can forge malicious requests, such as for adding Device Settings via the /addsrv URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wh94-79gr-cv69/GHSA-wh94-79gr-cv69.json b/advisories/unreviewed/2022/05/GHSA-wh94-79gr-cv69/GHSA-wh94-79gr-cv69.json index 3ee0b1afe80..d9a2aa2a619 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh94-79gr-cv69/GHSA-wh94-79gr-cv69.json +++ b/advisories/unreviewed/2022/05/GHSA-wh94-79gr-cv69/GHSA-wh94-79gr-cv69.json @@ -7,12 +7,8 @@ "CVE-2020-13321" ], "details": "A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whq2-vjvp-xr63/GHSA-whq2-vjvp-xr63.json b/advisories/unreviewed/2022/05/GHSA-whq2-vjvp-xr63/GHSA-whq2-vjvp-xr63.json index f2b2cdb4475..ab05e77b235 100644 --- a/advisories/unreviewed/2022/05/GHSA-whq2-vjvp-xr63/GHSA-whq2-vjvp-xr63.json +++ b/advisories/unreviewed/2022/05/GHSA-whq2-vjvp-xr63/GHSA-whq2-vjvp-xr63.json @@ -7,12 +7,8 @@ "CVE-2020-0323" ], "details": "In libavb, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146516087", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wmcf-qhh4-xmvq/GHSA-wmcf-qhh4-xmvq.json b/advisories/unreviewed/2022/05/GHSA-wmcf-qhh4-xmvq/GHSA-wmcf-qhh4-xmvq.json index 073fd8e58a6..593c105a84e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmcf-qhh4-xmvq/GHSA-wmcf-qhh4-xmvq.json +++ b/advisories/unreviewed/2022/05/GHSA-wmcf-qhh4-xmvq/GHSA-wmcf-qhh4-xmvq.json @@ -7,12 +7,8 @@ "CVE-2020-0329" ], "details": "In the OMX encoder, there is a possible out of bounds read due to invalid input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-63522940", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wmhp-h895-68c5/GHSA-wmhp-h895-68c5.json b/advisories/unreviewed/2022/05/GHSA-wmhp-h895-68c5/GHSA-wmhp-h895-68c5.json index a3daa0b5443..8a7de516420 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmhp-h895-68c5/GHSA-wmhp-h895-68c5.json +++ b/advisories/unreviewed/2022/05/GHSA-wmhp-h895-68c5/GHSA-wmhp-h895-68c5.json @@ -7,12 +7,8 @@ "CVE-2018-10432" ], "details": "Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wmmw-33p5-2c6j/GHSA-wmmw-33p5-2c6j.json b/advisories/unreviewed/2022/05/GHSA-wmmw-33p5-2c6j/GHSA-wmmw-33p5-2c6j.json index 50eddc3a16b..778d27ee7aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmmw-33p5-2c6j/GHSA-wmmw-33p5-2c6j.json +++ b/advisories/unreviewed/2022/05/GHSA-wmmw-33p5-2c6j/GHSA-wmmw-33p5-2c6j.json @@ -7,12 +7,8 @@ "CVE-2020-3476" ], "details": "A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying host file system. The vulnerability is due to insufficient validation of the parameters of a specific CLI command. An attacker could exploit this vulnerability by issuing that command with specific parameters. A successful exploit could allow the attacker to overwrite the content of any arbitrary file that resides on the underlying host file system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wp5g-hhm3-443g/GHSA-wp5g-hhm3-443g.json b/advisories/unreviewed/2022/05/GHSA-wp5g-hhm3-443g/GHSA-wp5g-hhm3-443g.json index 6072bb48565..8dcc99a748b 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp5g-hhm3-443g/GHSA-wp5g-hhm3-443g.json +++ b/advisories/unreviewed/2022/05/GHSA-wp5g-hhm3-443g/GHSA-wp5g-hhm3-443g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wpmp-jhx9-xgq5/GHSA-wpmp-jhx9-xgq5.json b/advisories/unreviewed/2022/05/GHSA-wpmp-jhx9-xgq5/GHSA-wpmp-jhx9-xgq5.json index 4e53d3fc915..97f72d5ad6f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpmp-jhx9-xgq5/GHSA-wpmp-jhx9-xgq5.json +++ b/advisories/unreviewed/2022/05/GHSA-wpmp-jhx9-xgq5/GHSA-wpmp-jhx9-xgq5.json @@ -7,12 +7,8 @@ "CVE-2020-3400" ], "details": "A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize parts of the web UI for which they are not authorized.The vulnerability is due to insufficient authorization of web UI access requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web UI. A successful exploit could allow the attacker to utilize parts of the web UI for which they are not authorized. This could allow a Read-Only user to perform actions of an Admin user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wppm-6xvq-3hp8/GHSA-wppm-6xvq-3hp8.json b/advisories/unreviewed/2022/05/GHSA-wppm-6xvq-3hp8/GHSA-wppm-6xvq-3hp8.json index d9ad074c92c..f406e95847c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wppm-6xvq-3hp8/GHSA-wppm-6xvq-3hp8.json +++ b/advisories/unreviewed/2022/05/GHSA-wppm-6xvq-3hp8/GHSA-wppm-6xvq-3hp8.json @@ -7,12 +7,8 @@ "CVE-2020-13502" ], "details": "An exploitable SQL injection vulnerability exists in the DNAPoints.asmx web Service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. A specially crafted SOAP web request can cause an SQL injection resulting in data compromise. An attacker can send an unauthenticated HTTP request to trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wpq7-84wh-58gv/GHSA-wpq7-84wh-58gv.json b/advisories/unreviewed/2022/05/GHSA-wpq7-84wh-58gv/GHSA-wpq7-84wh-58gv.json index 8af0c23526a..00ddca84125 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpq7-84wh-58gv/GHSA-wpq7-84wh-58gv.json +++ b/advisories/unreviewed/2022/05/GHSA-wpq7-84wh-58gv/GHSA-wpq7-84wh-58gv.json @@ -7,12 +7,8 @@ "CVE-2020-3512" ], "details": "A vulnerability in the PROFINET handler for Link Layer Discovery Protocol (LLDP) messages of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a crash on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of LLDP messages in the PROFINET LLDP message handler. An attacker could exploit this vulnerability by sending a malicious LLDP message to an affected device. A successful exploit could allow the attacker to cause the affected device to reload.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wq7w-fc8m-6mr2/GHSA-wq7w-fc8m-6mr2.json b/advisories/unreviewed/2022/05/GHSA-wq7w-fc8m-6mr2/GHSA-wq7w-fc8m-6mr2.json index 091ffc454d3..93ad26aedf3 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq7w-fc8m-6mr2/GHSA-wq7w-fc8m-6mr2.json +++ b/advisories/unreviewed/2022/05/GHSA-wq7w-fc8m-6mr2/GHSA-wq7w-fc8m-6mr2.json @@ -7,12 +7,8 @@ "CVE-2020-3527" ], "details": "A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The vulnerability is due to insufficient packet size validation. An attacker could exploit this vulnerability by sending jumbo frames or frames larger than the configured MTU size to the management interface of this device. A successful exploit could allow the attacker to crash the device fully before an automatic recovery.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqfx-6jqw-39jh/GHSA-wqfx-6jqw-39jh.json b/advisories/unreviewed/2022/05/GHSA-wqfx-6jqw-39jh/GHSA-wqfx-6jqw-39jh.json index 22c1bd5fdff..d7eeb6621ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqfx-6jqw-39jh/GHSA-wqfx-6jqw-39jh.json +++ b/advisories/unreviewed/2022/05/GHSA-wqfx-6jqw-39jh/GHSA-wqfx-6jqw-39jh.json @@ -7,12 +7,8 @@ "CVE-2019-15285" ], "details": "Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wqqv-7cwj-pfwq/GHSA-wqqv-7cwj-pfwq.json b/advisories/unreviewed/2022/05/GHSA-wqqv-7cwj-pfwq/GHSA-wqqv-7cwj-pfwq.json index ed3ce84bc82..e75ad4a3992 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqqv-7cwj-pfwq/GHSA-wqqv-7cwj-pfwq.json +++ b/advisories/unreviewed/2022/05/GHSA-wqqv-7cwj-pfwq/GHSA-wqqv-7cwj-pfwq.json @@ -7,12 +7,8 @@ "CVE-2020-0388" ], "details": "In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-156123285", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrf8-p6r2-xw72/GHSA-wrf8-p6r2-xw72.json b/advisories/unreviewed/2022/05/GHSA-wrf8-p6r2-xw72/GHSA-wrf8-p6r2-xw72.json index 77d1fca47c0..787c15f8f95 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrf8-p6r2-xw72/GHSA-wrf8-p6r2-xw72.json +++ b/advisories/unreviewed/2022/05/GHSA-wrf8-p6r2-xw72/GHSA-wrf8-p6r2-xw72.json @@ -7,12 +7,8 @@ "CVE-2020-15594" ], "details": "An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wrrv-22mc-5gj3/GHSA-wrrv-22mc-5gj3.json b/advisories/unreviewed/2022/05/GHSA-wrrv-22mc-5gj3/GHSA-wrrv-22mc-5gj3.json index b5823fe5ac5..6eee10ad3fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrrv-22mc-5gj3/GHSA-wrrv-22mc-5gj3.json +++ b/advisories/unreviewed/2022/05/GHSA-wrrv-22mc-5gj3/GHSA-wrrv-22mc-5gj3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv2w-fw86-mw65/GHSA-wv2w-fw86-mw65.json b/advisories/unreviewed/2022/05/GHSA-wv2w-fw86-mw65/GHSA-wv2w-fw86-mw65.json index a96ab0140b6..f8f534e737a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv2w-fw86-mw65/GHSA-wv2w-fw86-mw65.json +++ b/advisories/unreviewed/2022/05/GHSA-wv2w-fw86-mw65/GHSA-wv2w-fw86-mw65.json @@ -7,12 +7,8 @@ "CVE-2020-13503" ], "details": "Parameter AttFilterName in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wxv6-x849-xqrm/GHSA-wxv6-x849-xqrm.json b/advisories/unreviewed/2022/05/GHSA-wxv6-x849-xqrm/GHSA-wxv6-x849-xqrm.json index e82223f70a5..97b8f8e2506 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxv6-x849-xqrm/GHSA-wxv6-x849-xqrm.json +++ b/advisories/unreviewed/2022/05/GHSA-wxv6-x849-xqrm/GHSA-wxv6-x849-xqrm.json @@ -7,12 +7,8 @@ "CVE-2020-26113" ], "details": "cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2cj-f63h-vgcc/GHSA-x2cj-f63h-vgcc.json b/advisories/unreviewed/2022/05/GHSA-x2cj-f63h-vgcc/GHSA-x2cj-f63h-vgcc.json index f1c74901027..34d6ed03f74 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2cj-f63h-vgcc/GHSA-x2cj-f63h-vgcc.json +++ b/advisories/unreviewed/2022/05/GHSA-x2cj-f63h-vgcc/GHSA-x2cj-f63h-vgcc.json @@ -7,12 +7,8 @@ "CVE-2020-24624" ], "details": "Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x2xp-v2cr-52r2/GHSA-x2xp-v2cr-52r2.json b/advisories/unreviewed/2022/05/GHSA-x2xp-v2cr-52r2/GHSA-x2xp-v2cr-52r2.json index 4f601384c26..8037587e772 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2xp-v2cr-52r2/GHSA-x2xp-v2cr-52r2.json +++ b/advisories/unreviewed/2022/05/GHSA-x2xp-v2cr-52r2/GHSA-x2xp-v2cr-52r2.json @@ -7,12 +7,8 @@ "CVE-2020-24213" ], "details": "An integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memory.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3q2-r9qw-8x9h/GHSA-x3q2-r9qw-8x9h.json b/advisories/unreviewed/2022/05/GHSA-x3q2-r9qw-8x9h/GHSA-x3q2-r9qw-8x9h.json index cbc53128b4f..3f928771751 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3q2-r9qw-8x9h/GHSA-x3q2-r9qw-8x9h.json +++ b/advisories/unreviewed/2022/05/GHSA-x3q2-r9qw-8x9h/GHSA-x3q2-r9qw-8x9h.json @@ -7,12 +7,8 @@ "CVE-2020-24626" ], "details": "Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3vc-q44q-vwcf/GHSA-x3vc-q44q-vwcf.json b/advisories/unreviewed/2022/05/GHSA-x3vc-q44q-vwcf/GHSA-x3vc-q44q-vwcf.json index d42daab3ab9..56a7463be4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3vc-q44q-vwcf/GHSA-x3vc-q44q-vwcf.json +++ b/advisories/unreviewed/2022/05/GHSA-x3vc-q44q-vwcf/GHSA-x3vc-q44q-vwcf.json @@ -7,12 +7,8 @@ "CVE-2020-0325" ], "details": "In NFC, there is a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145079309", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5q8-96h8-84w6/GHSA-x5q8-96h8-84w6.json b/advisories/unreviewed/2022/05/GHSA-x5q8-96h8-84w6/GHSA-x5q8-96h8-84w6.json index 05465e56345..419ac68978c 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5q8-96h8-84w6/GHSA-x5q8-96h8-84w6.json +++ b/advisories/unreviewed/2022/05/GHSA-x5q8-96h8-84w6/GHSA-x5q8-96h8-84w6.json @@ -7,12 +7,8 @@ "CVE-2020-16244" ], "details": "GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform at high risk because an authenticated user can retrieve all user account data and then retrieve the actual passwords.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6cp-vv2p-mcvh/GHSA-x6cp-vv2p-mcvh.json b/advisories/unreviewed/2022/05/GHSA-x6cp-vv2p-mcvh/GHSA-x6cp-vv2p-mcvh.json index 2d2901ac9eb..e88a78d83ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6cp-vv2p-mcvh/GHSA-x6cp-vv2p-mcvh.json +++ b/advisories/unreviewed/2022/05/GHSA-x6cp-vv2p-mcvh/GHSA-x6cp-vv2p-mcvh.json @@ -7,12 +7,8 @@ "CVE-2020-6559" ], "details": "Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6q7-hvcg-c4x6/GHSA-x6q7-hvcg-c4x6.json b/advisories/unreviewed/2022/05/GHSA-x6q7-hvcg-c4x6/GHSA-x6q7-hvcg-c4x6.json index d9075b59678..953394eaed6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6q7-hvcg-c4x6/GHSA-x6q7-hvcg-c4x6.json +++ b/advisories/unreviewed/2022/05/GHSA-x6q7-hvcg-c4x6/GHSA-x6q7-hvcg-c4x6.json @@ -7,12 +7,8 @@ "CVE-2020-19450" ], "details": "SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, getUserLimits function in the list parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6xf-x3wg-4j2w/GHSA-x6xf-x3wg-4j2w.json b/advisories/unreviewed/2022/05/GHSA-x6xf-x3wg-4j2w/GHSA-x6xf-x3wg-4j2w.json index dfccae6be65..2066dea0384 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6xf-x3wg-4j2w/GHSA-x6xf-x3wg-4j2w.json +++ b/advisories/unreviewed/2022/05/GHSA-x6xf-x3wg-4j2w/GHSA-x6xf-x3wg-4j2w.json @@ -7,12 +7,8 @@ "CVE-2020-4613" ], "details": "IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184925.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x7rq-h6hf-g9vh/GHSA-x7rq-h6hf-g9vh.json b/advisories/unreviewed/2022/05/GHSA-x7rq-h6hf-g9vh/GHSA-x7rq-h6hf-g9vh.json index a41a327e719..b953d40c2be 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7rq-h6hf-g9vh/GHSA-x7rq-h6hf-g9vh.json +++ b/advisories/unreviewed/2022/05/GHSA-x7rq-h6hf-g9vh/GHSA-x7rq-h6hf-g9vh.json @@ -7,12 +7,8 @@ "CVE-2020-24753" ], "details": "A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execute code via crafted Concise Binary Object Representation (CBOR) input to the cbor2json decoder. An uncaught error while decoding CBOR Major Type 3 text strings leads to the use of an attacker-controllable uninitialized stack value. This can be used to modify memory, causing a crash or potentially exploitable heap corruption.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9qm-p77w-2rhm/GHSA-x9qm-p77w-2rhm.json b/advisories/unreviewed/2022/05/GHSA-x9qm-p77w-2rhm/GHSA-x9qm-p77w-2rhm.json index 16eef31e3ae..3494e974e49 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9qm-p77w-2rhm/GHSA-x9qm-p77w-2rhm.json +++ b/advisories/unreviewed/2022/05/GHSA-x9qm-p77w-2rhm/GHSA-x9qm-p77w-2rhm.json @@ -7,12 +7,8 @@ "CVE-2020-26106" ], "details": "cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9r4-mp46-hrqx/GHSA-x9r4-mp46-hrqx.json b/advisories/unreviewed/2022/05/GHSA-x9r4-mp46-hrqx/GHSA-x9r4-mp46-hrqx.json index 24054204c0f..5719982dbf9 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9r4-mp46-hrqx/GHSA-x9r4-mp46-hrqx.json +++ b/advisories/unreviewed/2022/05/GHSA-x9r4-mp46-hrqx/GHSA-x9r4-mp46-hrqx.json @@ -7,12 +7,8 @@ "CVE-2020-3526" ], "details": "A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to crash a device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a malformed COPS message to the device. A successful exploit could allow the attacker to crash the device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xc77-54wc-w9q7/GHSA-xc77-54wc-w9q7.json b/advisories/unreviewed/2022/05/GHSA-xc77-54wc-w9q7/GHSA-xc77-54wc-w9q7.json index 08f87aa7286..51d9f146c76 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc77-54wc-w9q7/GHSA-xc77-54wc-w9q7.json +++ b/advisories/unreviewed/2022/05/GHSA-xc77-54wc-w9q7/GHSA-xc77-54wc-w9q7.json @@ -7,12 +7,8 @@ "CVE-2020-25748" ], "details": "A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencrypted form. One can also modify responses from NTP and RTSP servers and force the camera to use the changed values.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xcjr-v7v6-w2rw/GHSA-xcjr-v7v6-w2rw.json b/advisories/unreviewed/2022/05/GHSA-xcjr-v7v6-w2rw/GHSA-xcjr-v7v6-w2rw.json index 426d73b5e75..ce0a3cd910a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xcjr-v7v6-w2rw/GHSA-xcjr-v7v6-w2rw.json +++ b/advisories/unreviewed/2022/05/GHSA-xcjr-v7v6-w2rw/GHSA-xcjr-v7v6-w2rw.json @@ -7,12 +7,8 @@ "CVE-2020-0309" ], "details": "In the Bluetooth server, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147227320", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xg4x-xhfv-p56h/GHSA-xg4x-xhfv-p56h.json b/advisories/unreviewed/2022/05/GHSA-xg4x-xhfv-p56h/GHSA-xg4x-xhfv-p56h.json index 83f0a343bf0..a5ce02790d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg4x-xhfv-p56h/GHSA-xg4x-xhfv-p56h.json +++ b/advisories/unreviewed/2022/05/GHSA-xg4x-xhfv-p56h/GHSA-xg4x-xhfv-p56h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xghg-58h4-gjjw/GHSA-xghg-58h4-gjjw.json b/advisories/unreviewed/2022/05/GHSA-xghg-58h4-gjjw/GHSA-xghg-58h4-gjjw.json index 6755e59e420..bd19cc6c401 100644 --- a/advisories/unreviewed/2022/05/GHSA-xghg-58h4-gjjw/GHSA-xghg-58h4-gjjw.json +++ b/advisories/unreviewed/2022/05/GHSA-xghg-58h4-gjjw/GHSA-xghg-58h4-gjjw.json @@ -7,12 +7,8 @@ "CVE-2020-25728" ], "details": "The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjh9-2rw8-8486/GHSA-xjh9-2rw8-8486.json b/advisories/unreviewed/2022/05/GHSA-xjh9-2rw8-8486/GHSA-xjh9-2rw8-8486.json index 2b92cda3ece..4bcb9ec2d38 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjh9-2rw8-8486/GHSA-xjh9-2rw8-8486.json +++ b/advisories/unreviewed/2022/05/GHSA-xjh9-2rw8-8486/GHSA-xjh9-2rw8-8486.json @@ -7,12 +7,8 @@ "CVE-2017-17477" ], "details": "Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xjhx-fvc5-fv5p/GHSA-xjhx-fvc5-fv5p.json b/advisories/unreviewed/2022/05/GHSA-xjhx-fvc5-fv5p/GHSA-xjhx-fvc5-fv5p.json index cd14ccb68b6..716832c074c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjhx-fvc5-fv5p/GHSA-xjhx-fvc5-fv5p.json +++ b/advisories/unreviewed/2022/05/GHSA-xjhx-fvc5-fv5p/GHSA-xjhx-fvc5-fv5p.json @@ -7,12 +7,8 @@ "CVE-2020-6546" ], "details": "Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xjrh-8gjh-h7rm/GHSA-xjrh-8gjh-h7rm.json b/advisories/unreviewed/2022/05/GHSA-xjrh-8gjh-h7rm/GHSA-xjrh-8gjh-h7rm.json index 1b616f93b3f..c3c00641a4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjrh-8gjh-h7rm/GHSA-xjrh-8gjh-h7rm.json +++ b/advisories/unreviewed/2022/05/GHSA-xjrh-8gjh-h7rm/GHSA-xjrh-8gjh-h7rm.json @@ -7,12 +7,8 @@ "CVE-2020-15595" ], "details": "An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently obtain information about the cartography of the internal networks to which the product has access.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xp9h-4c3v-4fjv/GHSA-xp9h-4c3v-4fjv.json b/advisories/unreviewed/2022/05/GHSA-xp9h-4c3v-4fjv/GHSA-xp9h-4c3v-4fjv.json index e1323c66d1d..e1158e073ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp9h-4c3v-4fjv/GHSA-xp9h-4c3v-4fjv.json +++ b/advisories/unreviewed/2022/05/GHSA-xp9h-4c3v-4fjv/GHSA-xp9h-4c3v-4fjv.json @@ -7,12 +7,8 @@ "CVE-2020-0296" ], "details": "In ADB server and USB server, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153356209", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr3r-h3qr-pm77/GHSA-xr3r-h3qr-pm77.json b/advisories/unreviewed/2022/05/GHSA-xr3r-h3qr-pm77/GHSA-xr3r-h3qr-pm77.json index 4d755d512ee..9d5691b8c27 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr3r-h3qr-pm77/GHSA-xr3r-h3qr-pm77.json +++ b/advisories/unreviewed/2022/05/GHSA-xr3r-h3qr-pm77/GHSA-xr3r-h3qr-pm77.json @@ -7,12 +7,8 @@ "CVE-2020-13507" ], "details": "An SQL injection vulnerability exists in the Alias.asmx Web Service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Parameter OrigID in Alias.asmx is vulnerable to unauthenticated SQL injection attacks An attacker can send unauthenticated HTTP requests to trigger this vulnerability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xw9f-jjf6-qcrc/GHSA-xw9f-jjf6-qcrc.json b/advisories/unreviewed/2022/05/GHSA-xw9f-jjf6-qcrc/GHSA-xw9f-jjf6-qcrc.json index 558722490fb..0072f2b74cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw9f-jjf6-qcrc/GHSA-xw9f-jjf6-qcrc.json +++ b/advisories/unreviewed/2022/05/GHSA-xw9f-jjf6-qcrc/GHSA-xw9f-jjf6-qcrc.json @@ -7,12 +7,8 @@ "CVE-2020-24593" ], "details": "Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-3p6r-56fp-3cwc/GHSA-3p6r-56fp-3cwc.json b/advisories/unreviewed/2022/08/GHSA-3p6r-56fp-3cwc/GHSA-3p6r-56fp-3cwc.json index f0c9c703646..5dad2abd8f3 100644 --- a/advisories/unreviewed/2022/08/GHSA-3p6r-56fp-3cwc/GHSA-3p6r-56fp-3cwc.json +++ b/advisories/unreviewed/2022/08/GHSA-3p6r-56fp-3cwc/GHSA-3p6r-56fp-3cwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-3qq4-m2c2-vqxm/GHSA-3qq4-m2c2-vqxm.json b/advisories/unreviewed/2022/08/GHSA-3qq4-m2c2-vqxm/GHSA-3qq4-m2c2-vqxm.json index 5e28356f515..01948ee63cd 100644 --- a/advisories/unreviewed/2022/08/GHSA-3qq4-m2c2-vqxm/GHSA-3qq4-m2c2-vqxm.json +++ b/advisories/unreviewed/2022/08/GHSA-3qq4-m2c2-vqxm/GHSA-3qq4-m2c2-vqxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-578w-3cjw-832g/GHSA-578w-3cjw-832g.json b/advisories/unreviewed/2022/08/GHSA-578w-3cjw-832g/GHSA-578w-3cjw-832g.json index e559a528dad..5940d133725 100644 --- a/advisories/unreviewed/2022/08/GHSA-578w-3cjw-832g/GHSA-578w-3cjw-832g.json +++ b/advisories/unreviewed/2022/08/GHSA-578w-3cjw-832g/GHSA-578w-3cjw-832g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-5fwq-7x9f-h7rq/GHSA-5fwq-7x9f-h7rq.json b/advisories/unreviewed/2022/08/GHSA-5fwq-7x9f-h7rq/GHSA-5fwq-7x9f-h7rq.json index 8c9ed69e744..ad5afae2cdb 100644 --- a/advisories/unreviewed/2022/08/GHSA-5fwq-7x9f-h7rq/GHSA-5fwq-7x9f-h7rq.json +++ b/advisories/unreviewed/2022/08/GHSA-5fwq-7x9f-h7rq/GHSA-5fwq-7x9f-h7rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-768v-366j-4vqg/GHSA-768v-366j-4vqg.json b/advisories/unreviewed/2022/08/GHSA-768v-366j-4vqg/GHSA-768v-366j-4vqg.json index c786c8d2f5a..f19b455e04e 100644 --- a/advisories/unreviewed/2022/08/GHSA-768v-366j-4vqg/GHSA-768v-366j-4vqg.json +++ b/advisories/unreviewed/2022/08/GHSA-768v-366j-4vqg/GHSA-768v-366j-4vqg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-7m86-x2x7-3wq2/GHSA-7m86-x2x7-3wq2.json b/advisories/unreviewed/2022/08/GHSA-7m86-x2x7-3wq2/GHSA-7m86-x2x7-3wq2.json index 0ca1db64665..946b48a213c 100644 --- a/advisories/unreviewed/2022/08/GHSA-7m86-x2x7-3wq2/GHSA-7m86-x2x7-3wq2.json +++ b/advisories/unreviewed/2022/08/GHSA-7m86-x2x7-3wq2/GHSA-7m86-x2x7-3wq2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-84q6-9hr7-2jh7/GHSA-84q6-9hr7-2jh7.json b/advisories/unreviewed/2022/08/GHSA-84q6-9hr7-2jh7/GHSA-84q6-9hr7-2jh7.json index d3ee0cce105..6505006bd3c 100644 --- a/advisories/unreviewed/2022/08/GHSA-84q6-9hr7-2jh7/GHSA-84q6-9hr7-2jh7.json +++ b/advisories/unreviewed/2022/08/GHSA-84q6-9hr7-2jh7/GHSA-84q6-9hr7-2jh7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-95pg-qhjc-gcqg/GHSA-95pg-qhjc-gcqg.json b/advisories/unreviewed/2022/08/GHSA-95pg-qhjc-gcqg/GHSA-95pg-qhjc-gcqg.json index 8a6f988d542..32c5439cf49 100644 --- a/advisories/unreviewed/2022/08/GHSA-95pg-qhjc-gcqg/GHSA-95pg-qhjc-gcqg.json +++ b/advisories/unreviewed/2022/08/GHSA-95pg-qhjc-gcqg/GHSA-95pg-qhjc-gcqg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-9j8j-w6vx-vqfr/GHSA-9j8j-w6vx-vqfr.json b/advisories/unreviewed/2022/08/GHSA-9j8j-w6vx-vqfr/GHSA-9j8j-w6vx-vqfr.json index d1d6cff567a..f41583e8df2 100644 --- a/advisories/unreviewed/2022/08/GHSA-9j8j-w6vx-vqfr/GHSA-9j8j-w6vx-vqfr.json +++ b/advisories/unreviewed/2022/08/GHSA-9j8j-w6vx-vqfr/GHSA-9j8j-w6vx-vqfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-c83j-mhmm-58g7/GHSA-c83j-mhmm-58g7.json b/advisories/unreviewed/2022/08/GHSA-c83j-mhmm-58g7/GHSA-c83j-mhmm-58g7.json index cc97fe493aa..b21dbde4cd4 100644 --- a/advisories/unreviewed/2022/08/GHSA-c83j-mhmm-58g7/GHSA-c83j-mhmm-58g7.json +++ b/advisories/unreviewed/2022/08/GHSA-c83j-mhmm-58g7/GHSA-c83j-mhmm-58g7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-fpc9-36gg-rrq8/GHSA-fpc9-36gg-rrq8.json b/advisories/unreviewed/2022/08/GHSA-fpc9-36gg-rrq8/GHSA-fpc9-36gg-rrq8.json index c9050fe4d06..cf9361869d4 100644 --- a/advisories/unreviewed/2022/08/GHSA-fpc9-36gg-rrq8/GHSA-fpc9-36gg-rrq8.json +++ b/advisories/unreviewed/2022/08/GHSA-fpc9-36gg-rrq8/GHSA-fpc9-36gg-rrq8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-h4mx-hpfc-jg53/GHSA-h4mx-hpfc-jg53.json b/advisories/unreviewed/2022/08/GHSA-h4mx-hpfc-jg53/GHSA-h4mx-hpfc-jg53.json index 7c32dc455dc..ce525a62a0c 100644 --- a/advisories/unreviewed/2022/08/GHSA-h4mx-hpfc-jg53/GHSA-h4mx-hpfc-jg53.json +++ b/advisories/unreviewed/2022/08/GHSA-h4mx-hpfc-jg53/GHSA-h4mx-hpfc-jg53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-24jx-rfj6-x4mp/GHSA-24jx-rfj6-x4mp.json b/advisories/unreviewed/2022/09/GHSA-24jx-rfj6-x4mp/GHSA-24jx-rfj6-x4mp.json index d7fd9cb2910..988c25f4445 100644 --- a/advisories/unreviewed/2022/09/GHSA-24jx-rfj6-x4mp/GHSA-24jx-rfj6-x4mp.json +++ b/advisories/unreviewed/2022/09/GHSA-24jx-rfj6-x4mp/GHSA-24jx-rfj6-x4mp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-57g7-92mv-gwwp/GHSA-57g7-92mv-gwwp.json b/advisories/unreviewed/2022/11/GHSA-57g7-92mv-gwwp/GHSA-57g7-92mv-gwwp.json index dac3c0e9c2d..28edd72267b 100644 --- a/advisories/unreviewed/2022/11/GHSA-57g7-92mv-gwwp/GHSA-57g7-92mv-gwwp.json +++ b/advisories/unreviewed/2022/11/GHSA-57g7-92mv-gwwp/GHSA-57g7-92mv-gwwp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-g8jg-vfp7-h8mr/GHSA-g8jg-vfp7-h8mr.json b/advisories/unreviewed/2022/11/GHSA-g8jg-vfp7-h8mr/GHSA-g8jg-vfp7-h8mr.json index e7dbdca0dd7..774e4062544 100644 --- a/advisories/unreviewed/2022/11/GHSA-g8jg-vfp7-h8mr/GHSA-g8jg-vfp7-h8mr.json +++ b/advisories/unreviewed/2022/11/GHSA-g8jg-vfp7-h8mr/GHSA-g8jg-vfp7-h8mr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-hjxv-pvv5-vqv2/GHSA-hjxv-pvv5-vqv2.json b/advisories/unreviewed/2022/11/GHSA-hjxv-pvv5-vqv2/GHSA-hjxv-pvv5-vqv2.json index 565d19b9ec3..9cd16931ffb 100644 --- a/advisories/unreviewed/2022/11/GHSA-hjxv-pvv5-vqv2/GHSA-hjxv-pvv5-vqv2.json +++ b/advisories/unreviewed/2022/11/GHSA-hjxv-pvv5-vqv2/GHSA-hjxv-pvv5-vqv2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-m57w-hf24-4j3h/GHSA-m57w-hf24-4j3h.json b/advisories/unreviewed/2022/11/GHSA-m57w-hf24-4j3h/GHSA-m57w-hf24-4j3h.json index e0fb0ddc9ce..c8c002627ab 100644 --- a/advisories/unreviewed/2022/11/GHSA-m57w-hf24-4j3h/GHSA-m57w-hf24-4j3h.json +++ b/advisories/unreviewed/2022/11/GHSA-m57w-hf24-4j3h/GHSA-m57w-hf24-4j3h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/11/GHSA-qc8x-j8r7-6j42/GHSA-qc8x-j8r7-6j42.json b/advisories/unreviewed/2022/11/GHSA-qc8x-j8r7-6j42/GHSA-qc8x-j8r7-6j42.json index 1d0a367e201..babf5515f3a 100644 --- a/advisories/unreviewed/2022/11/GHSA-qc8x-j8r7-6j42/GHSA-qc8x-j8r7-6j42.json +++ b/advisories/unreviewed/2022/11/GHSA-qc8x-j8r7-6j42/GHSA-qc8x-j8r7-6j42.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-4mwx-89hh-m9vr/GHSA-4mwx-89hh-m9vr.json b/advisories/unreviewed/2023/01/GHSA-4mwx-89hh-m9vr/GHSA-4mwx-89hh-m9vr.json index 4fe6198b096..2528ec90ef6 100644 --- a/advisories/unreviewed/2023/01/GHSA-4mwx-89hh-m9vr/GHSA-4mwx-89hh-m9vr.json +++ b/advisories/unreviewed/2023/01/GHSA-4mwx-89hh-m9vr/GHSA-4mwx-89hh-m9vr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-57pm-mv49-wwr4/GHSA-57pm-mv49-wwr4.json b/advisories/unreviewed/2023/01/GHSA-57pm-mv49-wwr4/GHSA-57pm-mv49-wwr4.json index 5cdca8cdbc8..8aa88258175 100644 --- a/advisories/unreviewed/2023/01/GHSA-57pm-mv49-wwr4/GHSA-57pm-mv49-wwr4.json +++ b/advisories/unreviewed/2023/01/GHSA-57pm-mv49-wwr4/GHSA-57pm-mv49-wwr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-65gw-p9mc-q88m/GHSA-65gw-p9mc-q88m.json b/advisories/unreviewed/2023/01/GHSA-65gw-p9mc-q88m/GHSA-65gw-p9mc-q88m.json index 74eb480f333..92a447723a6 100644 --- a/advisories/unreviewed/2023/01/GHSA-65gw-p9mc-q88m/GHSA-65gw-p9mc-q88m.json +++ b/advisories/unreviewed/2023/01/GHSA-65gw-p9mc-q88m/GHSA-65gw-p9mc-q88m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-8hr2-28vp-mgr9/GHSA-8hr2-28vp-mgr9.json b/advisories/unreviewed/2023/01/GHSA-8hr2-28vp-mgr9/GHSA-8hr2-28vp-mgr9.json index 7f3392d0473..587c6bc254a 100644 --- a/advisories/unreviewed/2023/01/GHSA-8hr2-28vp-mgr9/GHSA-8hr2-28vp-mgr9.json +++ b/advisories/unreviewed/2023/01/GHSA-8hr2-28vp-mgr9/GHSA-8hr2-28vp-mgr9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-8rvm-9p93-p2qq/GHSA-8rvm-9p93-p2qq.json b/advisories/unreviewed/2023/01/GHSA-8rvm-9p93-p2qq/GHSA-8rvm-9p93-p2qq.json index 19d25d4f1f9..55d99aa51a3 100644 --- a/advisories/unreviewed/2023/01/GHSA-8rvm-9p93-p2qq/GHSA-8rvm-9p93-p2qq.json +++ b/advisories/unreviewed/2023/01/GHSA-8rvm-9p93-p2qq/GHSA-8rvm-9p93-p2qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-cvvh-7xcr-36pm/GHSA-cvvh-7xcr-36pm.json b/advisories/unreviewed/2023/01/GHSA-cvvh-7xcr-36pm/GHSA-cvvh-7xcr-36pm.json index 3a0a9d842d1..9c019885917 100644 --- a/advisories/unreviewed/2023/01/GHSA-cvvh-7xcr-36pm/GHSA-cvvh-7xcr-36pm.json +++ b/advisories/unreviewed/2023/01/GHSA-cvvh-7xcr-36pm/GHSA-cvvh-7xcr-36pm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-fc4f-qggq-6w34/GHSA-fc4f-qggq-6w34.json b/advisories/unreviewed/2023/01/GHSA-fc4f-qggq-6w34/GHSA-fc4f-qggq-6w34.json index 2dad35deda2..abd2dcf0e3a 100644 --- a/advisories/unreviewed/2023/01/GHSA-fc4f-qggq-6w34/GHSA-fc4f-qggq-6w34.json +++ b/advisories/unreviewed/2023/01/GHSA-fc4f-qggq-6w34/GHSA-fc4f-qggq-6w34.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-fh34-55jq-5v6v/GHSA-fh34-55jq-5v6v.json b/advisories/unreviewed/2023/01/GHSA-fh34-55jq-5v6v/GHSA-fh34-55jq-5v6v.json index 4407034ba25..456d062f320 100644 --- a/advisories/unreviewed/2023/01/GHSA-fh34-55jq-5v6v/GHSA-fh34-55jq-5v6v.json +++ b/advisories/unreviewed/2023/01/GHSA-fh34-55jq-5v6v/GHSA-fh34-55jq-5v6v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-hpp8-mh99-fxx9/GHSA-hpp8-mh99-fxx9.json b/advisories/unreviewed/2023/01/GHSA-hpp8-mh99-fxx9/GHSA-hpp8-mh99-fxx9.json index 62ca1ddd67e..6de6b40f079 100644 --- a/advisories/unreviewed/2023/01/GHSA-hpp8-mh99-fxx9/GHSA-hpp8-mh99-fxx9.json +++ b/advisories/unreviewed/2023/01/GHSA-hpp8-mh99-fxx9/GHSA-hpp8-mh99-fxx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-rcwq-9vjv-m77w/GHSA-rcwq-9vjv-m77w.json b/advisories/unreviewed/2023/01/GHSA-rcwq-9vjv-m77w/GHSA-rcwq-9vjv-m77w.json index 797b0213644..12ea81b3f0d 100644 --- a/advisories/unreviewed/2023/01/GHSA-rcwq-9vjv-m77w/GHSA-rcwq-9vjv-m77w.json +++ b/advisories/unreviewed/2023/01/GHSA-rcwq-9vjv-m77w/GHSA-rcwq-9vjv-m77w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/01/GHSA-x38j-4h5h-pvg6/GHSA-x38j-4h5h-pvg6.json b/advisories/unreviewed/2023/01/GHSA-x38j-4h5h-pvg6/GHSA-x38j-4h5h-pvg6.json index 4b30509ad21..d73d45908d5 100644 --- a/advisories/unreviewed/2023/01/GHSA-x38j-4h5h-pvg6/GHSA-x38j-4h5h-pvg6.json +++ b/advisories/unreviewed/2023/01/GHSA-x38j-4h5h-pvg6/GHSA-x38j-4h5h-pvg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-4vf7-8qf6-f3f9/GHSA-4vf7-8qf6-f3f9.json b/advisories/unreviewed/2023/02/GHSA-4vf7-8qf6-f3f9/GHSA-4vf7-8qf6-f3f9.json index 0ed7256df7d..694080be952 100644 --- a/advisories/unreviewed/2023/02/GHSA-4vf7-8qf6-f3f9/GHSA-4vf7-8qf6-f3f9.json +++ b/advisories/unreviewed/2023/02/GHSA-4vf7-8qf6-f3f9/GHSA-4vf7-8qf6-f3f9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/02/GHSA-f6p2-2572-4pjp/GHSA-f6p2-2572-4pjp.json b/advisories/unreviewed/2023/02/GHSA-f6p2-2572-4pjp/GHSA-f6p2-2572-4pjp.json index 7ebb1532ac8..f819db96889 100644 --- a/advisories/unreviewed/2023/02/GHSA-f6p2-2572-4pjp/GHSA-f6p2-2572-4pjp.json +++ b/advisories/unreviewed/2023/02/GHSA-f6p2-2572-4pjp/GHSA-f6p2-2572-4pjp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-3r5h-mjx6-6cjh/GHSA-3r5h-mjx6-6cjh.json b/advisories/unreviewed/2023/06/GHSA-3r5h-mjx6-6cjh/GHSA-3r5h-mjx6-6cjh.json index 67087796206..a87bd956e51 100644 --- a/advisories/unreviewed/2023/06/GHSA-3r5h-mjx6-6cjh/GHSA-3r5h-mjx6-6cjh.json +++ b/advisories/unreviewed/2023/06/GHSA-3r5h-mjx6-6cjh/GHSA-3r5h-mjx6-6cjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-4g7c-75vj-hqfj/GHSA-4g7c-75vj-hqfj.json b/advisories/unreviewed/2023/06/GHSA-4g7c-75vj-hqfj/GHSA-4g7c-75vj-hqfj.json index cc330af2311..32c4055b00f 100644 --- a/advisories/unreviewed/2023/06/GHSA-4g7c-75vj-hqfj/GHSA-4g7c-75vj-hqfj.json +++ b/advisories/unreviewed/2023/06/GHSA-4g7c-75vj-hqfj/GHSA-4g7c-75vj-hqfj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-6j86-v54w-73w8/GHSA-6j86-v54w-73w8.json b/advisories/unreviewed/2023/06/GHSA-6j86-v54w-73w8/GHSA-6j86-v54w-73w8.json index ed0af13955d..e24a53fe94f 100644 --- a/advisories/unreviewed/2023/06/GHSA-6j86-v54w-73w8/GHSA-6j86-v54w-73w8.json +++ b/advisories/unreviewed/2023/06/GHSA-6j86-v54w-73w8/GHSA-6j86-v54w-73w8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-qwvc-xxgc-r8jq/GHSA-qwvc-xxgc-r8jq.json b/advisories/unreviewed/2023/06/GHSA-qwvc-xxgc-r8jq/GHSA-qwvc-xxgc-r8jq.json index 66286bb223f..95f57eb9e7c 100644 --- a/advisories/unreviewed/2023/06/GHSA-qwvc-xxgc-r8jq/GHSA-qwvc-xxgc-r8jq.json +++ b/advisories/unreviewed/2023/06/GHSA-qwvc-xxgc-r8jq/GHSA-qwvc-xxgc-r8jq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/06/GHSA-r4jh-xqh3-r437/GHSA-r4jh-xqh3-r437.json b/advisories/unreviewed/2023/06/GHSA-r4jh-xqh3-r437/GHSA-r4jh-xqh3-r437.json index a80ca19dd9c..705177d32be 100644 --- a/advisories/unreviewed/2023/06/GHSA-r4jh-xqh3-r437/GHSA-r4jh-xqh3-r437.json +++ b/advisories/unreviewed/2023/06/GHSA-r4jh-xqh3-r437/GHSA-r4jh-xqh3-r437.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-2mhv-m6h4-3h94/GHSA-2mhv-m6h4-3h94.json b/advisories/unreviewed/2023/07/GHSA-2mhv-m6h4-3h94/GHSA-2mhv-m6h4-3h94.json index 8ffd60f13c7..88734ab5f36 100644 --- a/advisories/unreviewed/2023/07/GHSA-2mhv-m6h4-3h94/GHSA-2mhv-m6h4-3h94.json +++ b/advisories/unreviewed/2023/07/GHSA-2mhv-m6h4-3h94/GHSA-2mhv-m6h4-3h94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-37jr-8vrf-hwhp/GHSA-37jr-8vrf-hwhp.json b/advisories/unreviewed/2023/07/GHSA-37jr-8vrf-hwhp/GHSA-37jr-8vrf-hwhp.json index 3739a32b03d..b3c0b2c3f5c 100644 --- a/advisories/unreviewed/2023/07/GHSA-37jr-8vrf-hwhp/GHSA-37jr-8vrf-hwhp.json +++ b/advisories/unreviewed/2023/07/GHSA-37jr-8vrf-hwhp/GHSA-37jr-8vrf-hwhp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-qhgj-ghq2-5hjh/GHSA-qhgj-ghq2-5hjh.json b/advisories/unreviewed/2023/07/GHSA-qhgj-ghq2-5hjh/GHSA-qhgj-ghq2-5hjh.json index fb2a32cfab0..7ef3d1e9085 100644 --- a/advisories/unreviewed/2023/07/GHSA-qhgj-ghq2-5hjh/GHSA-qhgj-ghq2-5hjh.json +++ b/advisories/unreviewed/2023/07/GHSA-qhgj-ghq2-5hjh/GHSA-qhgj-ghq2-5hjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-rc83-8wmp-v9vx/GHSA-rc83-8wmp-v9vx.json b/advisories/unreviewed/2023/07/GHSA-rc83-8wmp-v9vx/GHSA-rc83-8wmp-v9vx.json index a597f304414..3c3ff486c23 100644 --- a/advisories/unreviewed/2023/07/GHSA-rc83-8wmp-v9vx/GHSA-rc83-8wmp-v9vx.json +++ b/advisories/unreviewed/2023/07/GHSA-rc83-8wmp-v9vx/GHSA-rc83-8wmp-v9vx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-rgjp-37vj-5h44/GHSA-rgjp-37vj-5h44.json b/advisories/unreviewed/2023/07/GHSA-rgjp-37vj-5h44/GHSA-rgjp-37vj-5h44.json index 8434fce54ae..883104169ba 100644 --- a/advisories/unreviewed/2023/07/GHSA-rgjp-37vj-5h44/GHSA-rgjp-37vj-5h44.json +++ b/advisories/unreviewed/2023/07/GHSA-rgjp-37vj-5h44/GHSA-rgjp-37vj-5h44.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-rhfh-gm98-5fx4/GHSA-rhfh-gm98-5fx4.json b/advisories/unreviewed/2023/07/GHSA-rhfh-gm98-5fx4/GHSA-rhfh-gm98-5fx4.json index e8f2676c922..58e0017e4f1 100644 --- a/advisories/unreviewed/2023/07/GHSA-rhfh-gm98-5fx4/GHSA-rhfh-gm98-5fx4.json +++ b/advisories/unreviewed/2023/07/GHSA-rhfh-gm98-5fx4/GHSA-rhfh-gm98-5fx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-w79p-2q4q-mwmw/GHSA-w79p-2q4q-mwmw.json b/advisories/unreviewed/2023/07/GHSA-w79p-2q4q-mwmw/GHSA-w79p-2q4q-mwmw.json index 1e026c00020..4f9821b182e 100644 --- a/advisories/unreviewed/2023/07/GHSA-w79p-2q4q-mwmw/GHSA-w79p-2q4q-mwmw.json +++ b/advisories/unreviewed/2023/07/GHSA-w79p-2q4q-mwmw/GHSA-w79p-2q4q-mwmw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/07/GHSA-xcpx-g9wm-frg6/GHSA-xcpx-g9wm-frg6.json b/advisories/unreviewed/2023/07/GHSA-xcpx-g9wm-frg6/GHSA-xcpx-g9wm-frg6.json index 06de9c55121..450094d5c52 100644 --- a/advisories/unreviewed/2023/07/GHSA-xcpx-g9wm-frg6/GHSA-xcpx-g9wm-frg6.json +++ b/advisories/unreviewed/2023/07/GHSA-xcpx-g9wm-frg6/GHSA-xcpx-g9wm-frg6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-6c8q-hm6g-chmq/GHSA-6c8q-hm6g-chmq.json b/advisories/unreviewed/2023/08/GHSA-6c8q-hm6g-chmq/GHSA-6c8q-hm6g-chmq.json index 917889152bd..bff094a4210 100644 --- a/advisories/unreviewed/2023/08/GHSA-6c8q-hm6g-chmq/GHSA-6c8q-hm6g-chmq.json +++ b/advisories/unreviewed/2023/08/GHSA-6c8q-hm6g-chmq/GHSA-6c8q-hm6g-chmq.json @@ -7,12 +7,8 @@ "CVE-2020-20145" ], "details": "An issue was discovered in /src/helper.c in Dnsmasq up to and including 2.80 allows attackers to cause a denial of service via function create_helper.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/08/GHSA-9rvg-h3ph-f3v3/GHSA-9rvg-h3ph-f3v3.json b/advisories/unreviewed/2023/08/GHSA-9rvg-h3ph-f3v3/GHSA-9rvg-h3ph-f3v3.json index 2a90c4b4f41..962084a04c0 100644 --- a/advisories/unreviewed/2023/08/GHSA-9rvg-h3ph-f3v3/GHSA-9rvg-h3ph-f3v3.json +++ b/advisories/unreviewed/2023/08/GHSA-9rvg-h3ph-f3v3/GHSA-9rvg-h3ph-f3v3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-9v86-j5rf-5xpx/GHSA-9v86-j5rf-5xpx.json b/advisories/unreviewed/2023/08/GHSA-9v86-j5rf-5xpx/GHSA-9v86-j5rf-5xpx.json index deed98f762d..cf1ebb7ccd5 100644 --- a/advisories/unreviewed/2023/08/GHSA-9v86-j5rf-5xpx/GHSA-9v86-j5rf-5xpx.json +++ b/advisories/unreviewed/2023/08/GHSA-9v86-j5rf-5xpx/GHSA-9v86-j5rf-5xpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json b/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json index d2007533e10..d080cc4ba4b 100644 --- a/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json +++ b/advisories/unreviewed/2023/08/GHSA-f5cr-mp3h-4jjj/GHSA-f5cr-mp3h-4jjj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-h44v-883g-x8c3/GHSA-h44v-883g-x8c3.json b/advisories/unreviewed/2023/08/GHSA-h44v-883g-x8c3/GHSA-h44v-883g-x8c3.json index b1d7a0f5f67..ade7fe4f8aa 100644 --- a/advisories/unreviewed/2023/08/GHSA-h44v-883g-x8c3/GHSA-h44v-883g-x8c3.json +++ b/advisories/unreviewed/2023/08/GHSA-h44v-883g-x8c3/GHSA-h44v-883g-x8c3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-ph8c-f4jv-6j8g/GHSA-ph8c-f4jv-6j8g.json b/advisories/unreviewed/2023/08/GHSA-ph8c-f4jv-6j8g/GHSA-ph8c-f4jv-6j8g.json index d967f8d5624..ea07580b6b5 100644 --- a/advisories/unreviewed/2023/08/GHSA-ph8c-f4jv-6j8g/GHSA-ph8c-f4jv-6j8g.json +++ b/advisories/unreviewed/2023/08/GHSA-ph8c-f4jv-6j8g/GHSA-ph8c-f4jv-6j8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/08/GHSA-rpj7-8p65-2w48/GHSA-rpj7-8p65-2w48.json b/advisories/unreviewed/2023/08/GHSA-rpj7-8p65-2w48/GHSA-rpj7-8p65-2w48.json index a55ba3b18f2..66ca7dcb724 100644 --- a/advisories/unreviewed/2023/08/GHSA-rpj7-8p65-2w48/GHSA-rpj7-8p65-2w48.json +++ b/advisories/unreviewed/2023/08/GHSA-rpj7-8p65-2w48/GHSA-rpj7-8p65-2w48.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-9p55-888j-qxrh/GHSA-9p55-888j-qxrh.json b/advisories/unreviewed/2023/09/GHSA-9p55-888j-qxrh/GHSA-9p55-888j-qxrh.json index 3646c81493e..54dfb33f03b 100644 --- a/advisories/unreviewed/2023/09/GHSA-9p55-888j-qxrh/GHSA-9p55-888j-qxrh.json +++ b/advisories/unreviewed/2023/09/GHSA-9p55-888j-qxrh/GHSA-9p55-888j-qxrh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/09/GHSA-g6hh-x63c-83gf/GHSA-g6hh-x63c-83gf.json b/advisories/unreviewed/2023/09/GHSA-g6hh-x63c-83gf/GHSA-g6hh-x63c-83gf.json index faa1d844ab2..bbf04e38a5b 100644 --- a/advisories/unreviewed/2023/09/GHSA-g6hh-x63c-83gf/GHSA-g6hh-x63c-83gf.json +++ b/advisories/unreviewed/2023/09/GHSA-g6hh-x63c-83gf/GHSA-g6hh-x63c-83gf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-q239-frwj-6m3v/GHSA-q239-frwj-6m3v.json b/advisories/unreviewed/2023/09/GHSA-q239-frwj-6m3v/GHSA-q239-frwj-6m3v.json index d5e668974c1..7f107418119 100644 --- a/advisories/unreviewed/2023/09/GHSA-q239-frwj-6m3v/GHSA-q239-frwj-6m3v.json +++ b/advisories/unreviewed/2023/09/GHSA-q239-frwj-6m3v/GHSA-q239-frwj-6m3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-qv4g-5q5g-2vc3/GHSA-qv4g-5q5g-2vc3.json b/advisories/unreviewed/2023/09/GHSA-qv4g-5q5g-2vc3/GHSA-qv4g-5q5g-2vc3.json index 299ac912bbe..ed6846b82b7 100644 --- a/advisories/unreviewed/2023/09/GHSA-qv4g-5q5g-2vc3/GHSA-qv4g-5q5g-2vc3.json +++ b/advisories/unreviewed/2023/09/GHSA-qv4g-5q5g-2vc3/GHSA-qv4g-5q5g-2vc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-vqqw-c55h-3h3r/GHSA-vqqw-c55h-3h3r.json b/advisories/unreviewed/2023/09/GHSA-vqqw-c55h-3h3r/GHSA-vqqw-c55h-3h3r.json index 563528d4eec..bcd10f8d61c 100644 --- a/advisories/unreviewed/2023/09/GHSA-vqqw-c55h-3h3r/GHSA-vqqw-c55h-3h3r.json +++ b/advisories/unreviewed/2023/09/GHSA-vqqw-c55h-3h3r/GHSA-vqqw-c55h-3h3r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/09/GHSA-wxxp-w379-49qj/GHSA-wxxp-w379-49qj.json b/advisories/unreviewed/2023/09/GHSA-wxxp-w379-49qj/GHSA-wxxp-w379-49qj.json index 832ab4d809a..12a55766cb1 100644 --- a/advisories/unreviewed/2023/09/GHSA-wxxp-w379-49qj/GHSA-wxxp-w379-49qj.json +++ b/advisories/unreviewed/2023/09/GHSA-wxxp-w379-49qj/GHSA-wxxp-w379-49qj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-2r79-m38c-p4mw/GHSA-2r79-m38c-p4mw.json b/advisories/unreviewed/2023/10/GHSA-2r79-m38c-p4mw/GHSA-2r79-m38c-p4mw.json index 188cb87f1a3..07e4b490948 100644 --- a/advisories/unreviewed/2023/10/GHSA-2r79-m38c-p4mw/GHSA-2r79-m38c-p4mw.json +++ b/advisories/unreviewed/2023/10/GHSA-2r79-m38c-p4mw/GHSA-2r79-m38c-p4mw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-663p-c8fh-73p2/GHSA-663p-c8fh-73p2.json b/advisories/unreviewed/2023/10/GHSA-663p-c8fh-73p2/GHSA-663p-c8fh-73p2.json index 7e4769cf5ff..ba47310ac68 100644 --- a/advisories/unreviewed/2023/10/GHSA-663p-c8fh-73p2/GHSA-663p-c8fh-73p2.json +++ b/advisories/unreviewed/2023/10/GHSA-663p-c8fh-73p2/GHSA-663p-c8fh-73p2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-67p8-6p5v-jxxj/GHSA-67p8-6p5v-jxxj.json b/advisories/unreviewed/2023/10/GHSA-67p8-6p5v-jxxj/GHSA-67p8-6p5v-jxxj.json index 7e6acde1ead..9b571485412 100644 --- a/advisories/unreviewed/2023/10/GHSA-67p8-6p5v-jxxj/GHSA-67p8-6p5v-jxxj.json +++ b/advisories/unreviewed/2023/10/GHSA-67p8-6p5v-jxxj/GHSA-67p8-6p5v-jxxj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-6gqg-m5mh-95hf/GHSA-6gqg-m5mh-95hf.json b/advisories/unreviewed/2023/10/GHSA-6gqg-m5mh-95hf/GHSA-6gqg-m5mh-95hf.json index ece122b1a33..0f6cba24011 100644 --- a/advisories/unreviewed/2023/10/GHSA-6gqg-m5mh-95hf/GHSA-6gqg-m5mh-95hf.json +++ b/advisories/unreviewed/2023/10/GHSA-6gqg-m5mh-95hf/GHSA-6gqg-m5mh-95hf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-72h3-f956-8mcr/GHSA-72h3-f956-8mcr.json b/advisories/unreviewed/2023/10/GHSA-72h3-f956-8mcr/GHSA-72h3-f956-8mcr.json index a7a6fa096ba..11a9cfbb2fa 100644 --- a/advisories/unreviewed/2023/10/GHSA-72h3-f956-8mcr/GHSA-72h3-f956-8mcr.json +++ b/advisories/unreviewed/2023/10/GHSA-72h3-f956-8mcr/GHSA-72h3-f956-8mcr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-77ph-2ww9-vq43/GHSA-77ph-2ww9-vq43.json b/advisories/unreviewed/2023/10/GHSA-77ph-2ww9-vq43/GHSA-77ph-2ww9-vq43.json index a9bb3eed6f7..a2bd58382f6 100644 --- a/advisories/unreviewed/2023/10/GHSA-77ph-2ww9-vq43/GHSA-77ph-2ww9-vq43.json +++ b/advisories/unreviewed/2023/10/GHSA-77ph-2ww9-vq43/GHSA-77ph-2ww9-vq43.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-784r-2wg6-39wc/GHSA-784r-2wg6-39wc.json b/advisories/unreviewed/2023/10/GHSA-784r-2wg6-39wc/GHSA-784r-2wg6-39wc.json index 8e9b1d1afc0..e66c321d488 100644 --- a/advisories/unreviewed/2023/10/GHSA-784r-2wg6-39wc/GHSA-784r-2wg6-39wc.json +++ b/advisories/unreviewed/2023/10/GHSA-784r-2wg6-39wc/GHSA-784r-2wg6-39wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-8jm8-53vg-f37j/GHSA-8jm8-53vg-f37j.json b/advisories/unreviewed/2023/10/GHSA-8jm8-53vg-f37j/GHSA-8jm8-53vg-f37j.json index db34a7dfe7f..3467d4a535d 100644 --- a/advisories/unreviewed/2023/10/GHSA-8jm8-53vg-f37j/GHSA-8jm8-53vg-f37j.json +++ b/advisories/unreviewed/2023/10/GHSA-8jm8-53vg-f37j/GHSA-8jm8-53vg-f37j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-9c3p-6729-gvhv/GHSA-9c3p-6729-gvhv.json b/advisories/unreviewed/2023/10/GHSA-9c3p-6729-gvhv/GHSA-9c3p-6729-gvhv.json index e9677e720fc..2600fb223be 100644 --- a/advisories/unreviewed/2023/10/GHSA-9c3p-6729-gvhv/GHSA-9c3p-6729-gvhv.json +++ b/advisories/unreviewed/2023/10/GHSA-9c3p-6729-gvhv/GHSA-9c3p-6729-gvhv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-9f65-22jw-cm3p/GHSA-9f65-22jw-cm3p.json b/advisories/unreviewed/2023/10/GHSA-9f65-22jw-cm3p/GHSA-9f65-22jw-cm3p.json index 3396dff8b8f..b79154b18f7 100644 --- a/advisories/unreviewed/2023/10/GHSA-9f65-22jw-cm3p/GHSA-9f65-22jw-cm3p.json +++ b/advisories/unreviewed/2023/10/GHSA-9f65-22jw-cm3p/GHSA-9f65-22jw-cm3p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-fjgx-2cvw-6h2f/GHSA-fjgx-2cvw-6h2f.json b/advisories/unreviewed/2023/10/GHSA-fjgx-2cvw-6h2f/GHSA-fjgx-2cvw-6h2f.json index 847f36508ef..b35be4a322d 100644 --- a/advisories/unreviewed/2023/10/GHSA-fjgx-2cvw-6h2f/GHSA-fjgx-2cvw-6h2f.json +++ b/advisories/unreviewed/2023/10/GHSA-fjgx-2cvw-6h2f/GHSA-fjgx-2cvw-6h2f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-gfh7-3mx2-9p35/GHSA-gfh7-3mx2-9p35.json b/advisories/unreviewed/2023/10/GHSA-gfh7-3mx2-9p35/GHSA-gfh7-3mx2-9p35.json index 1bdea7afc78..60ff415b39d 100644 --- a/advisories/unreviewed/2023/10/GHSA-gfh7-3mx2-9p35/GHSA-gfh7-3mx2-9p35.json +++ b/advisories/unreviewed/2023/10/GHSA-gfh7-3mx2-9p35/GHSA-gfh7-3mx2-9p35.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-h4x4-wpq5-72wc/GHSA-h4x4-wpq5-72wc.json b/advisories/unreviewed/2023/10/GHSA-h4x4-wpq5-72wc/GHSA-h4x4-wpq5-72wc.json index 359262da0ac..b0a4996debd 100644 --- a/advisories/unreviewed/2023/10/GHSA-h4x4-wpq5-72wc/GHSA-h4x4-wpq5-72wc.json +++ b/advisories/unreviewed/2023/10/GHSA-h4x4-wpq5-72wc/GHSA-h4x4-wpq5-72wc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-h9f2-f38p-v9fq/GHSA-h9f2-f38p-v9fq.json b/advisories/unreviewed/2023/10/GHSA-h9f2-f38p-v9fq/GHSA-h9f2-f38p-v9fq.json index 71219babcdd..4efc8108dd9 100644 --- a/advisories/unreviewed/2023/10/GHSA-h9f2-f38p-v9fq/GHSA-h9f2-f38p-v9fq.json +++ b/advisories/unreviewed/2023/10/GHSA-h9f2-f38p-v9fq/GHSA-h9f2-f38p-v9fq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-j97x-4gxg-7x49/GHSA-j97x-4gxg-7x49.json b/advisories/unreviewed/2023/10/GHSA-j97x-4gxg-7x49/GHSA-j97x-4gxg-7x49.json index 65d493a4b9d..aa4f63e24aa 100644 --- a/advisories/unreviewed/2023/10/GHSA-j97x-4gxg-7x49/GHSA-j97x-4gxg-7x49.json +++ b/advisories/unreviewed/2023/10/GHSA-j97x-4gxg-7x49/GHSA-j97x-4gxg-7x49.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-jrwj-fw3w-p28m/GHSA-jrwj-fw3w-p28m.json b/advisories/unreviewed/2023/10/GHSA-jrwj-fw3w-p28m/GHSA-jrwj-fw3w-p28m.json index dbb0c621166..6a7730b5fa4 100644 --- a/advisories/unreviewed/2023/10/GHSA-jrwj-fw3w-p28m/GHSA-jrwj-fw3w-p28m.json +++ b/advisories/unreviewed/2023/10/GHSA-jrwj-fw3w-p28m/GHSA-jrwj-fw3w-p28m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-pfw3-f5qp-9wf5/GHSA-pfw3-f5qp-9wf5.json b/advisories/unreviewed/2023/10/GHSA-pfw3-f5qp-9wf5/GHSA-pfw3-f5qp-9wf5.json index 8d889d04653..18f32af4409 100644 --- a/advisories/unreviewed/2023/10/GHSA-pfw3-f5qp-9wf5/GHSA-pfw3-f5qp-9wf5.json +++ b/advisories/unreviewed/2023/10/GHSA-pfw3-f5qp-9wf5/GHSA-pfw3-f5qp-9wf5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-pxm9-f4qv-v33j/GHSA-pxm9-f4qv-v33j.json b/advisories/unreviewed/2023/10/GHSA-pxm9-f4qv-v33j/GHSA-pxm9-f4qv-v33j.json index dd0ce7aa7f3..b6784e1271c 100644 --- a/advisories/unreviewed/2023/10/GHSA-pxm9-f4qv-v33j/GHSA-pxm9-f4qv-v33j.json +++ b/advisories/unreviewed/2023/10/GHSA-pxm9-f4qv-v33j/GHSA-pxm9-f4qv-v33j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-qhr5-m6x5-c253/GHSA-qhr5-m6x5-c253.json b/advisories/unreviewed/2023/10/GHSA-qhr5-m6x5-c253/GHSA-qhr5-m6x5-c253.json index c73d16da817..213280b54db 100644 --- a/advisories/unreviewed/2023/10/GHSA-qhr5-m6x5-c253/GHSA-qhr5-m6x5-c253.json +++ b/advisories/unreviewed/2023/10/GHSA-qhr5-m6x5-c253/GHSA-qhr5-m6x5-c253.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json b/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json index 49b9c498876..0c4ee0f942c 100644 --- a/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json +++ b/advisories/unreviewed/2023/10/GHSA-v994-7f87-hh83/GHSA-v994-7f87-hh83.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-vqpf-hpm5-9vf4/GHSA-vqpf-hpm5-9vf4.json b/advisories/unreviewed/2023/10/GHSA-vqpf-hpm5-9vf4/GHSA-vqpf-hpm5-9vf4.json index 7a6fa8c0f65..5cc659926d0 100644 --- a/advisories/unreviewed/2023/10/GHSA-vqpf-hpm5-9vf4/GHSA-vqpf-hpm5-9vf4.json +++ b/advisories/unreviewed/2023/10/GHSA-vqpf-hpm5-9vf4/GHSA-vqpf-hpm5-9vf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-vwch-x387-pmjh/GHSA-vwch-x387-pmjh.json b/advisories/unreviewed/2023/10/GHSA-vwch-x387-pmjh/GHSA-vwch-x387-pmjh.json index 09cb17a7f17..f284ebd9a1d 100644 --- a/advisories/unreviewed/2023/10/GHSA-vwch-x387-pmjh/GHSA-vwch-x387-pmjh.json +++ b/advisories/unreviewed/2023/10/GHSA-vwch-x387-pmjh/GHSA-vwch-x387-pmjh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-wprf-5vfh-42w4/GHSA-wprf-5vfh-42w4.json b/advisories/unreviewed/2023/10/GHSA-wprf-5vfh-42w4/GHSA-wprf-5vfh-42w4.json index 4b6a2d30d22..c08d30a1c9b 100644 --- a/advisories/unreviewed/2023/10/GHSA-wprf-5vfh-42w4/GHSA-wprf-5vfh-42w4.json +++ b/advisories/unreviewed/2023/10/GHSA-wprf-5vfh-42w4/GHSA-wprf-5vfh-42w4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/10/GHSA-wxwv-4j63-2fjm/GHSA-wxwv-4j63-2fjm.json b/advisories/unreviewed/2023/10/GHSA-wxwv-4j63-2fjm/GHSA-wxwv-4j63-2fjm.json index 76d30b3ec60..af1b0fbb433 100644 --- a/advisories/unreviewed/2023/10/GHSA-wxwv-4j63-2fjm/GHSA-wxwv-4j63-2fjm.json +++ b/advisories/unreviewed/2023/10/GHSA-wxwv-4j63-2fjm/GHSA-wxwv-4j63-2fjm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-4w34-678c-q5hp/GHSA-4w34-678c-q5hp.json b/advisories/unreviewed/2023/11/GHSA-4w34-678c-q5hp/GHSA-4w34-678c-q5hp.json index 1e623fee765..970de8c436e 100644 --- a/advisories/unreviewed/2023/11/GHSA-4w34-678c-q5hp/GHSA-4w34-678c-q5hp.json +++ b/advisories/unreviewed/2023/11/GHSA-4w34-678c-q5hp/GHSA-4w34-678c-q5hp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-7xq4-g7wr-q7cw/GHSA-7xq4-g7wr-q7cw.json b/advisories/unreviewed/2023/11/GHSA-7xq4-g7wr-q7cw/GHSA-7xq4-g7wr-q7cw.json index 68192e36366..f244cb5f6c4 100644 --- a/advisories/unreviewed/2023/11/GHSA-7xq4-g7wr-q7cw/GHSA-7xq4-g7wr-q7cw.json +++ b/advisories/unreviewed/2023/11/GHSA-7xq4-g7wr-q7cw/GHSA-7xq4-g7wr-q7cw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-cvww-5xmj-jrr4/GHSA-cvww-5xmj-jrr4.json b/advisories/unreviewed/2023/11/GHSA-cvww-5xmj-jrr4/GHSA-cvww-5xmj-jrr4.json index 7386d60c202..36573bf8f10 100644 --- a/advisories/unreviewed/2023/11/GHSA-cvww-5xmj-jrr4/GHSA-cvww-5xmj-jrr4.json +++ b/advisories/unreviewed/2023/11/GHSA-cvww-5xmj-jrr4/GHSA-cvww-5xmj-jrr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-cw6w-5w44-ccrq/GHSA-cw6w-5w44-ccrq.json b/advisories/unreviewed/2023/11/GHSA-cw6w-5w44-ccrq/GHSA-cw6w-5w44-ccrq.json index 00a04bdcac9..47d5d1e8e26 100644 --- a/advisories/unreviewed/2023/11/GHSA-cw6w-5w44-ccrq/GHSA-cw6w-5w44-ccrq.json +++ b/advisories/unreviewed/2023/11/GHSA-cw6w-5w44-ccrq/GHSA-cw6w-5w44-ccrq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-gp6r-24h3-qcjv/GHSA-gp6r-24h3-qcjv.json b/advisories/unreviewed/2023/11/GHSA-gp6r-24h3-qcjv/GHSA-gp6r-24h3-qcjv.json index cbaacad0195..50183fad838 100644 --- a/advisories/unreviewed/2023/11/GHSA-gp6r-24h3-qcjv/GHSA-gp6r-24h3-qcjv.json +++ b/advisories/unreviewed/2023/11/GHSA-gp6r-24h3-qcjv/GHSA-gp6r-24h3-qcjv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-gqm2-wv4v-659j/GHSA-gqm2-wv4v-659j.json b/advisories/unreviewed/2023/11/GHSA-gqm2-wv4v-659j/GHSA-gqm2-wv4v-659j.json index 7c92793db9d..9a4c4342f4f 100644 --- a/advisories/unreviewed/2023/11/GHSA-gqm2-wv4v-659j/GHSA-gqm2-wv4v-659j.json +++ b/advisories/unreviewed/2023/11/GHSA-gqm2-wv4v-659j/GHSA-gqm2-wv4v-659j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-jm3v-6m47-cv37/GHSA-jm3v-6m47-cv37.json b/advisories/unreviewed/2023/11/GHSA-jm3v-6m47-cv37/GHSA-jm3v-6m47-cv37.json index f2d70a51b4b..7118ba39df8 100644 --- a/advisories/unreviewed/2023/11/GHSA-jm3v-6m47-cv37/GHSA-jm3v-6m47-cv37.json +++ b/advisories/unreviewed/2023/11/GHSA-jm3v-6m47-cv37/GHSA-jm3v-6m47-cv37.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-pgg7-g5f4-6c8v/GHSA-pgg7-g5f4-6c8v.json b/advisories/unreviewed/2023/11/GHSA-pgg7-g5f4-6c8v/GHSA-pgg7-g5f4-6c8v.json index 9737a75bfcf..0b557ca0902 100644 --- a/advisories/unreviewed/2023/11/GHSA-pgg7-g5f4-6c8v/GHSA-pgg7-g5f4-6c8v.json +++ b/advisories/unreviewed/2023/11/GHSA-pgg7-g5f4-6c8v/GHSA-pgg7-g5f4-6c8v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json b/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json index dd57acb0be0..7611316b04a 100644 --- a/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json +++ b/advisories/unreviewed/2023/12/GHSA-3c85-mx4x-435c/GHSA-3c85-mx4x-435c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-46q9-5vx3-f5qh/GHSA-46q9-5vx3-f5qh.json b/advisories/unreviewed/2023/12/GHSA-46q9-5vx3-f5qh/GHSA-46q9-5vx3-f5qh.json index b35ea557c7d..85a1ec85f24 100644 --- a/advisories/unreviewed/2023/12/GHSA-46q9-5vx3-f5qh/GHSA-46q9-5vx3-f5qh.json +++ b/advisories/unreviewed/2023/12/GHSA-46q9-5vx3-f5qh/GHSA-46q9-5vx3-f5qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-9rmv-77v4-hrpv/GHSA-9rmv-77v4-hrpv.json b/advisories/unreviewed/2023/12/GHSA-9rmv-77v4-hrpv/GHSA-9rmv-77v4-hrpv.json index 103caafd477..7976095fc36 100644 --- a/advisories/unreviewed/2023/12/GHSA-9rmv-77v4-hrpv/GHSA-9rmv-77v4-hrpv.json +++ b/advisories/unreviewed/2023/12/GHSA-9rmv-77v4-hrpv/GHSA-9rmv-77v4-hrpv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-xh85-63vm-rw4g/GHSA-xh85-63vm-rw4g.json b/advisories/unreviewed/2023/12/GHSA-xh85-63vm-rw4g/GHSA-xh85-63vm-rw4g.json index f6376d03b33..f8a63f4f576 100644 --- a/advisories/unreviewed/2023/12/GHSA-xh85-63vm-rw4g/GHSA-xh85-63vm-rw4g.json +++ b/advisories/unreviewed/2023/12/GHSA-xh85-63vm-rw4g/GHSA-xh85-63vm-rw4g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-39g9-xc8h-ffgp/GHSA-39g9-xc8h-ffgp.json b/advisories/unreviewed/2024/01/GHSA-39g9-xc8h-ffgp/GHSA-39g9-xc8h-ffgp.json index 835467096fc..b448dc76243 100644 --- a/advisories/unreviewed/2024/01/GHSA-39g9-xc8h-ffgp/GHSA-39g9-xc8h-ffgp.json +++ b/advisories/unreviewed/2024/01/GHSA-39g9-xc8h-ffgp/GHSA-39g9-xc8h-ffgp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json b/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json index 702ed34bba0..4eb07ed5d75 100644 --- a/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json +++ b/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/01/GHSA-x2hg-844v-frvh/GHSA-x2hg-844v-frvh.json b/advisories/unreviewed/2024/01/GHSA-x2hg-844v-frvh/GHSA-x2hg-844v-frvh.json index 0daa378b71b..3f9452aada3 100644 --- a/advisories/unreviewed/2024/01/GHSA-x2hg-844v-frvh/GHSA-x2hg-844v-frvh.json +++ b/advisories/unreviewed/2024/01/GHSA-x2hg-844v-frvh/GHSA-x2hg-844v-frvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-38w2-rg56-gf7f/GHSA-38w2-rg56-gf7f.json b/advisories/unreviewed/2024/02/GHSA-38w2-rg56-gf7f/GHSA-38w2-rg56-gf7f.json index 231dcbb4124..eda1d95d8ce 100644 --- a/advisories/unreviewed/2024/02/GHSA-38w2-rg56-gf7f/GHSA-38w2-rg56-gf7f.json +++ b/advisories/unreviewed/2024/02/GHSA-38w2-rg56-gf7f/GHSA-38w2-rg56-gf7f.json @@ -7,12 +7,8 @@ "CVE-2024-26287" ], "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-3fhw-3rw6-474c/GHSA-3fhw-3rw6-474c.json b/advisories/unreviewed/2024/02/GHSA-3fhw-3rw6-474c/GHSA-3fhw-3rw6-474c.json index 3b111a9593b..8dd63815140 100644 --- a/advisories/unreviewed/2024/02/GHSA-3fhw-3rw6-474c/GHSA-3fhw-3rw6-474c.json +++ b/advisories/unreviewed/2024/02/GHSA-3fhw-3rw6-474c/GHSA-3fhw-3rw6-474c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-3jmf-c2v9-xc39/GHSA-3jmf-c2v9-xc39.json b/advisories/unreviewed/2024/02/GHSA-3jmf-c2v9-xc39/GHSA-3jmf-c2v9-xc39.json index 4afdfd87d0c..66c01c4d46f 100644 --- a/advisories/unreviewed/2024/02/GHSA-3jmf-c2v9-xc39/GHSA-3jmf-c2v9-xc39.json +++ b/advisories/unreviewed/2024/02/GHSA-3jmf-c2v9-xc39/GHSA-3jmf-c2v9-xc39.json @@ -7,12 +7,8 @@ "CVE-2023-20587" ], "details": "Improper\nAccess Control in System Management Mode (SMM) may allow an attacker access to\nthe SPI flash potentially leading to arbitrary code execution.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-3mjc-3jvj-6m9f/GHSA-3mjc-3jvj-6m9f.json b/advisories/unreviewed/2024/02/GHSA-3mjc-3jvj-6m9f/GHSA-3mjc-3jvj-6m9f.json index b644ac3e269..16e2d415bf3 100644 --- a/advisories/unreviewed/2024/02/GHSA-3mjc-3jvj-6m9f/GHSA-3mjc-3jvj-6m9f.json +++ b/advisories/unreviewed/2024/02/GHSA-3mjc-3jvj-6m9f/GHSA-3mjc-3jvj-6m9f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-3qgv-cmgx-82jm/GHSA-3qgv-cmgx-82jm.json b/advisories/unreviewed/2024/02/GHSA-3qgv-cmgx-82jm/GHSA-3qgv-cmgx-82jm.json index a252ffa2b56..7c9416ed5ab 100644 --- a/advisories/unreviewed/2024/02/GHSA-3qgv-cmgx-82jm/GHSA-3qgv-cmgx-82jm.json +++ b/advisories/unreviewed/2024/02/GHSA-3qgv-cmgx-82jm/GHSA-3qgv-cmgx-82jm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-42p9-m692-hxrc/GHSA-42p9-m692-hxrc.json b/advisories/unreviewed/2024/02/GHSA-42p9-m692-hxrc/GHSA-42p9-m692-hxrc.json index fe0de0c3ffb..7a594d0d779 100644 --- a/advisories/unreviewed/2024/02/GHSA-42p9-m692-hxrc/GHSA-42p9-m692-hxrc.json +++ b/advisories/unreviewed/2024/02/GHSA-42p9-m692-hxrc/GHSA-42p9-m692-hxrc.json @@ -7,12 +7,8 @@ "CVE-2023-52437" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d\"\n\nThis reverts commit 5e2cf333b7bd5d3e62595a44d598a254c697cd74.\n\nThat commit introduced the following race and can cause system hung.\n\n md_write_start: raid5d:\n // mddev->in_sync == 1\n set \"MD_SB_CHANGE_PENDING\"\n // running before md_write_start wakeup it\n waiting \"MD_SB_CHANGE_PENDING\" cleared\n >>>>>>>>> hung\n wakeup mddev->thread\n ...\n waiting \"MD_SB_CHANGE_PENDING\" cleared\n >>>> hung, raid5d should clear this flag\n but get hung by same flag.\n\nThe issue reverted commit fixing is fixed by last patch in a new way.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-4c39-5qhc-788c/GHSA-4c39-5qhc-788c.json b/advisories/unreviewed/2024/02/GHSA-4c39-5qhc-788c/GHSA-4c39-5qhc-788c.json index a10b5a04e00..448039da061 100644 --- a/advisories/unreviewed/2024/02/GHSA-4c39-5qhc-788c/GHSA-4c39-5qhc-788c.json +++ b/advisories/unreviewed/2024/02/GHSA-4c39-5qhc-788c/GHSA-4c39-5qhc-788c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json b/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json index 7cbe5cfabd3..b8218c89a43 100644 --- a/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json +++ b/advisories/unreviewed/2024/02/GHSA-4jff-4ww9-2jm5/GHSA-4jff-4ww9-2jm5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json b/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json index 8a848e21c32..62b94d09756 100644 --- a/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json +++ b/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-675c-mq76-7jv4/GHSA-675c-mq76-7jv4.json b/advisories/unreviewed/2024/02/GHSA-675c-mq76-7jv4/GHSA-675c-mq76-7jv4.json index 684bc5864b4..eb53bfaca30 100644 --- a/advisories/unreviewed/2024/02/GHSA-675c-mq76-7jv4/GHSA-675c-mq76-7jv4.json +++ b/advisories/unreviewed/2024/02/GHSA-675c-mq76-7jv4/GHSA-675c-mq76-7jv4.json @@ -7,12 +7,8 @@ "CVE-2024-26350" ], "details": "flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_contact_form_settings.php", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-6h5p-8mvr-f4fg/GHSA-6h5p-8mvr-f4fg.json b/advisories/unreviewed/2024/02/GHSA-6h5p-8mvr-f4fg/GHSA-6h5p-8mvr-f4fg.json index 48e98af7686..09a70c39276 100644 --- a/advisories/unreviewed/2024/02/GHSA-6h5p-8mvr-f4fg/GHSA-6h5p-8mvr-f4fg.json +++ b/advisories/unreviewed/2024/02/GHSA-6h5p-8mvr-f4fg/GHSA-6h5p-8mvr-f4fg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-783m-f4c2-pgqr/GHSA-783m-f4c2-pgqr.json b/advisories/unreviewed/2024/02/GHSA-783m-f4c2-pgqr/GHSA-783m-f4c2-pgqr.json index 949272dcd13..5ae83adf390 100644 --- a/advisories/unreviewed/2024/02/GHSA-783m-f4c2-pgqr/GHSA-783m-f4c2-pgqr.json +++ b/advisories/unreviewed/2024/02/GHSA-783m-f4c2-pgqr/GHSA-783m-f4c2-pgqr.json @@ -7,12 +7,8 @@ "CVE-2024-1563" ], "details": "An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json b/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json index 0b8a0a93033..c9341716707 100644 --- a/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json +++ b/advisories/unreviewed/2024/02/GHSA-7gfq-fv5r-j8r5/GHSA-7gfq-fv5r-j8r5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-7q9j-8gpw-vmc6/GHSA-7q9j-8gpw-vmc6.json b/advisories/unreviewed/2024/02/GHSA-7q9j-8gpw-vmc6/GHSA-7q9j-8gpw-vmc6.json index 692fe240906..01079783a5d 100644 --- a/advisories/unreviewed/2024/02/GHSA-7q9j-8gpw-vmc6/GHSA-7q9j-8gpw-vmc6.json +++ b/advisories/unreviewed/2024/02/GHSA-7q9j-8gpw-vmc6/GHSA-7q9j-8gpw-vmc6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-7r9f-99vw-hx7g/GHSA-7r9f-99vw-hx7g.json b/advisories/unreviewed/2024/02/GHSA-7r9f-99vw-hx7g/GHSA-7r9f-99vw-hx7g.json index f920a67d8ec..5601d04d7ee 100644 --- a/advisories/unreviewed/2024/02/GHSA-7r9f-99vw-hx7g/GHSA-7r9f-99vw-hx7g.json +++ b/advisories/unreviewed/2024/02/GHSA-7r9f-99vw-hx7g/GHSA-7r9f-99vw-hx7g.json @@ -7,12 +7,8 @@ "CVE-2024-25801" ], "details": "An arbitrary file upload vulnerability in the Add Media function of SKINsoft S-Museum v7.02.3 allows attackers to execute arbitrary code via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-9pr5-r4v8-xqjf/GHSA-9pr5-r4v8-xqjf.json b/advisories/unreviewed/2024/02/GHSA-9pr5-r4v8-xqjf/GHSA-9pr5-r4v8-xqjf.json index 868dde3aebd..8aaa492c122 100644 --- a/advisories/unreviewed/2024/02/GHSA-9pr5-r4v8-xqjf/GHSA-9pr5-r4v8-xqjf.json +++ b/advisories/unreviewed/2024/02/GHSA-9pr5-r4v8-xqjf/GHSA-9pr5-r4v8-xqjf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-9x8h-8xf2-qjcv/GHSA-9x8h-8xf2-qjcv.json b/advisories/unreviewed/2024/02/GHSA-9x8h-8xf2-qjcv/GHSA-9x8h-8xf2-qjcv.json index 2d75bb579e1..e75f0733ba1 100644 --- a/advisories/unreviewed/2024/02/GHSA-9x8h-8xf2-qjcv/GHSA-9x8h-8xf2-qjcv.json +++ b/advisories/unreviewed/2024/02/GHSA-9x8h-8xf2-qjcv/GHSA-9x8h-8xf2-qjcv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-c5fg-c732-px5h/GHSA-c5fg-c732-px5h.json b/advisories/unreviewed/2024/02/GHSA-c5fg-c732-px5h/GHSA-c5fg-c732-px5h.json index 4c0fda92c32..79613663b04 100644 --- a/advisories/unreviewed/2024/02/GHSA-c5fg-c732-px5h/GHSA-c5fg-c732-px5h.json +++ b/advisories/unreviewed/2024/02/GHSA-c5fg-c732-px5h/GHSA-c5fg-c732-px5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-fh4v-qfgj-jxxw/GHSA-fh4v-qfgj-jxxw.json b/advisories/unreviewed/2024/02/GHSA-fh4v-qfgj-jxxw/GHSA-fh4v-qfgj-jxxw.json index f78a3777255..ad2e5d3840f 100644 --- a/advisories/unreviewed/2024/02/GHSA-fh4v-qfgj-jxxw/GHSA-fh4v-qfgj-jxxw.json +++ b/advisories/unreviewed/2024/02/GHSA-fh4v-qfgj-jxxw/GHSA-fh4v-qfgj-jxxw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-h29x-7wp6-7rpx/GHSA-h29x-7wp6-7rpx.json b/advisories/unreviewed/2024/02/GHSA-h29x-7wp6-7rpx/GHSA-h29x-7wp6-7rpx.json index b8c35f98358..b1b7ba4b64d 100644 --- a/advisories/unreviewed/2024/02/GHSA-h29x-7wp6-7rpx/GHSA-h29x-7wp6-7rpx.json +++ b/advisories/unreviewed/2024/02/GHSA-h29x-7wp6-7rpx/GHSA-h29x-7wp6-7rpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-h49p-33vw-q6xw/GHSA-h49p-33vw-q6xw.json b/advisories/unreviewed/2024/02/GHSA-h49p-33vw-q6xw/GHSA-h49p-33vw-q6xw.json index 9510210238d..a9c51b1158a 100644 --- a/advisories/unreviewed/2024/02/GHSA-h49p-33vw-q6xw/GHSA-h49p-33vw-q6xw.json +++ b/advisories/unreviewed/2024/02/GHSA-h49p-33vw-q6xw/GHSA-h49p-33vw-q6xw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-h4jm-gjjm-3ffr/GHSA-h4jm-gjjm-3ffr.json b/advisories/unreviewed/2024/02/GHSA-h4jm-gjjm-3ffr/GHSA-h4jm-gjjm-3ffr.json index ea07b151694..6d24ae23d50 100644 --- a/advisories/unreviewed/2024/02/GHSA-h4jm-gjjm-3ffr/GHSA-h4jm-gjjm-3ffr.json +++ b/advisories/unreviewed/2024/02/GHSA-h4jm-gjjm-3ffr/GHSA-h4jm-gjjm-3ffr.json @@ -7,12 +7,8 @@ "CVE-2024-26489" ], "details": "A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Profile Name text field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-hvxm-wjcp-jrcc/GHSA-hvxm-wjcp-jrcc.json b/advisories/unreviewed/2024/02/GHSA-hvxm-wjcp-jrcc/GHSA-hvxm-wjcp-jrcc.json index 21798ac348d..3b8bd8c3f89 100644 --- a/advisories/unreviewed/2024/02/GHSA-hvxm-wjcp-jrcc/GHSA-hvxm-wjcp-jrcc.json +++ b/advisories/unreviewed/2024/02/GHSA-hvxm-wjcp-jrcc/GHSA-hvxm-wjcp-jrcc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-hwwp-7fmp-9cp2/GHSA-hwwp-7fmp-9cp2.json b/advisories/unreviewed/2024/02/GHSA-hwwp-7fmp-9cp2/GHSA-hwwp-7fmp-9cp2.json index 8b4cb8e3553..1559abd21f4 100644 --- a/advisories/unreviewed/2024/02/GHSA-hwwp-7fmp-9cp2/GHSA-hwwp-7fmp-9cp2.json +++ b/advisories/unreviewed/2024/02/GHSA-hwwp-7fmp-9cp2/GHSA-hwwp-7fmp-9cp2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-j26p-3qqc-p3hw/GHSA-j26p-3qqc-p3hw.json b/advisories/unreviewed/2024/02/GHSA-j26p-3qqc-p3hw/GHSA-j26p-3qqc-p3hw.json index 4d2ae06dc1a..bb7cf438ad6 100644 --- a/advisories/unreviewed/2024/02/GHSA-j26p-3qqc-p3hw/GHSA-j26p-3qqc-p3hw.json +++ b/advisories/unreviewed/2024/02/GHSA-j26p-3qqc-p3hw/GHSA-j26p-3qqc-p3hw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-j3c9-h64h-gwp9/GHSA-j3c9-h64h-gwp9.json b/advisories/unreviewed/2024/02/GHSA-j3c9-h64h-gwp9/GHSA-j3c9-h64h-gwp9.json index cd3ad327b2f..129ae834c29 100644 --- a/advisories/unreviewed/2024/02/GHSA-j3c9-h64h-gwp9/GHSA-j3c9-h64h-gwp9.json +++ b/advisories/unreviewed/2024/02/GHSA-j3c9-h64h-gwp9/GHSA-j3c9-h64h-gwp9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-j4h9-5vj5-4vff/GHSA-j4h9-5vj5-4vff.json b/advisories/unreviewed/2024/02/GHSA-j4h9-5vj5-4vff/GHSA-j4h9-5vj5-4vff.json index 43ef9eed640..a992fb13f97 100644 --- a/advisories/unreviewed/2024/02/GHSA-j4h9-5vj5-4vff/GHSA-j4h9-5vj5-4vff.json +++ b/advisories/unreviewed/2024/02/GHSA-j4h9-5vj5-4vff/GHSA-j4h9-5vj5-4vff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-jvwr-fmgq-5q3g/GHSA-jvwr-fmgq-5q3g.json b/advisories/unreviewed/2024/02/GHSA-jvwr-fmgq-5q3g/GHSA-jvwr-fmgq-5q3g.json index edf3f677d2a..1f9decd8143 100644 --- a/advisories/unreviewed/2024/02/GHSA-jvwr-fmgq-5q3g/GHSA-jvwr-fmgq-5q3g.json +++ b/advisories/unreviewed/2024/02/GHSA-jvwr-fmgq-5q3g/GHSA-jvwr-fmgq-5q3g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json b/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json index 8d1ceaafa6c..7160ec5ad75 100644 --- a/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json +++ b/advisories/unreviewed/2024/02/GHSA-mqv6-97c7-49r4/GHSA-mqv6-97c7-49r4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-pq7f-896m-7jg7/GHSA-pq7f-896m-7jg7.json b/advisories/unreviewed/2024/02/GHSA-pq7f-896m-7jg7/GHSA-pq7f-896m-7jg7.json index df49cf5a058..9846adee259 100644 --- a/advisories/unreviewed/2024/02/GHSA-pq7f-896m-7jg7/GHSA-pq7f-896m-7jg7.json +++ b/advisories/unreviewed/2024/02/GHSA-pq7f-896m-7jg7/GHSA-pq7f-896m-7jg7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-rvmf-9rf3-4vc3/GHSA-rvmf-9rf3-4vc3.json b/advisories/unreviewed/2024/02/GHSA-rvmf-9rf3-4vc3/GHSA-rvmf-9rf3-4vc3.json index 1af3e52feb5..b275ed7b96c 100644 --- a/advisories/unreviewed/2024/02/GHSA-rvmf-9rf3-4vc3/GHSA-rvmf-9rf3-4vc3.json +++ b/advisories/unreviewed/2024/02/GHSA-rvmf-9rf3-4vc3/GHSA-rvmf-9rf3-4vc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-w9jf-wgxm-ggqj/GHSA-w9jf-wgxm-ggqj.json b/advisories/unreviewed/2024/02/GHSA-w9jf-wgxm-ggqj/GHSA-w9jf-wgxm-ggqj.json index 814170abf32..2ec2a56fc20 100644 --- a/advisories/unreviewed/2024/02/GHSA-w9jf-wgxm-ggqj/GHSA-w9jf-wgxm-ggqj.json +++ b/advisories/unreviewed/2024/02/GHSA-w9jf-wgxm-ggqj/GHSA-w9jf-wgxm-ggqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-wcp3-6xhg-h726/GHSA-wcp3-6xhg-h726.json b/advisories/unreviewed/2024/02/GHSA-wcp3-6xhg-h726/GHSA-wcp3-6xhg-h726.json index 66c81dd5136..6ff2da6e070 100644 --- a/advisories/unreviewed/2024/02/GHSA-wcp3-6xhg-h726/GHSA-wcp3-6xhg-h726.json +++ b/advisories/unreviewed/2024/02/GHSA-wcp3-6xhg-h726/GHSA-wcp3-6xhg-h726.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-wq59-m22j-v4p5/GHSA-wq59-m22j-v4p5.json b/advisories/unreviewed/2024/02/GHSA-wq59-m22j-v4p5/GHSA-wq59-m22j-v4p5.json index de14105bec1..8eed63cf349 100644 --- a/advisories/unreviewed/2024/02/GHSA-wq59-m22j-v4p5/GHSA-wq59-m22j-v4p5.json +++ b/advisories/unreviewed/2024/02/GHSA-wq59-m22j-v4p5/GHSA-wq59-m22j-v4p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-wrvf-j637-77w5/GHSA-wrvf-j637-77w5.json b/advisories/unreviewed/2024/02/GHSA-wrvf-j637-77w5/GHSA-wrvf-j637-77w5.json index 8333e0319c2..20059222256 100644 --- a/advisories/unreviewed/2024/02/GHSA-wrvf-j637-77w5/GHSA-wrvf-j637-77w5.json +++ b/advisories/unreviewed/2024/02/GHSA-wrvf-j637-77w5/GHSA-wrvf-j637-77w5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-2292-859m-6prp/GHSA-2292-859m-6prp.json b/advisories/unreviewed/2024/03/GHSA-2292-859m-6prp/GHSA-2292-859m-6prp.json index 9ce382934ce..e4da651d667 100644 --- a/advisories/unreviewed/2024/03/GHSA-2292-859m-6prp/GHSA-2292-859m-6prp.json +++ b/advisories/unreviewed/2024/03/GHSA-2292-859m-6prp/GHSA-2292-859m-6prp.json @@ -7,12 +7,8 @@ "CVE-2023-52510" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: ca8210: Fix a potential UAF in ca8210_probe\n\nIf of_clk_add_provider() fails in ca8210_register_ext_clock(),\nit calls clk_unregister() to release priv->clk and returns an\nerror. However, the caller ca8210_probe() then calls ca8210_remove(),\nwhere priv->clk is freed again in ca8210_unregister_ext_clock(). In\nthis case, a use-after-free may happen in the second time we call\nclk_unregister().\n\nFix this by removing the first clk_unregister(). Also, priv->clk could\nbe an error code on failure of clk_register_fixed_rate(). Use\nIS_ERR_OR_NULL to catch this case in ca8210_unregister_ext_clock().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-2m3h-p692-qjp7/GHSA-2m3h-p692-qjp7.json b/advisories/unreviewed/2024/03/GHSA-2m3h-p692-qjp7/GHSA-2m3h-p692-qjp7.json index c000837dc69..b4307a45c94 100644 --- a/advisories/unreviewed/2024/03/GHSA-2m3h-p692-qjp7/GHSA-2m3h-p692-qjp7.json +++ b/advisories/unreviewed/2024/03/GHSA-2m3h-p692-qjp7/GHSA-2m3h-p692-qjp7.json @@ -7,12 +7,8 @@ "CVE-2023-52513" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Fix connection failure handling\n\nIn case immediate MPA request processing fails, the newly\ncreated endpoint unlinks the listening endpoint and is\nready to be dropped. This special case was not handled\ncorrectly by the code handling the later TCP socket close,\ncausing a NULL dereference crash in siw_cm_work_handler()\nwhen dereferencing a NULL listener. We now also cancel\nthe useless MPA timeout, if immediate MPA request\nprocessing fails.\n\nThis patch furthermore simplifies MPA processing in general:\nScheduling a useless TCP socket read in sk_data_ready() upcall\nis now surpressed, if the socket is already moved out of\nTCP_ESTABLISHED state.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-43w7-7gwv-35rc/GHSA-43w7-7gwv-35rc.json b/advisories/unreviewed/2024/03/GHSA-43w7-7gwv-35rc/GHSA-43w7-7gwv-35rc.json index b5bdc4c14db..619039b8acc 100644 --- a/advisories/unreviewed/2024/03/GHSA-43w7-7gwv-35rc/GHSA-43w7-7gwv-35rc.json +++ b/advisories/unreviewed/2024/03/GHSA-43w7-7gwv-35rc/GHSA-43w7-7gwv-35rc.json @@ -7,12 +7,8 @@ "CVE-2024-26620" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio-ap: always filter entire AP matrix\n\nThe vfio_ap_mdev_filter_matrix function is called whenever a new adapter or\ndomain is assigned to the mdev. The purpose of the function is to update\nthe guest's AP configuration by filtering the matrix of adapters and\ndomains assigned to the mdev. When an adapter or domain is assigned, only\nthe APQNs associated with the APID of the new adapter or APQI of the new\ndomain are inspected. If an APQN does not reference a queue device bound to\nthe vfio_ap device driver, then it's APID will be filtered from the mdev's\nmatrix when updating the guest's AP configuration.\n\nInspecting only the APID of the new adapter or APQI of the new domain will\nresult in passing AP queues through to a guest that are not bound to the\nvfio_ap device driver under certain circumstances. Consider the following:\n\nguest's AP configuration (all also assigned to the mdev's matrix):\n14.0004\n14.0005\n14.0006\n16.0004\n16.0005\n16.0006\n\nunassign domain 4\nunbind queue 16.0005\nassign domain 4\n\nWhen domain 4 is re-assigned, since only domain 4 will be inspected, the\nAPQNs that will be examined will be:\n14.0004\n16.0004\n\nSince both of those APQNs reference queue devices that are bound to the\nvfio_ap device driver, nothing will get filtered from the mdev's matrix\nwhen updating the guest's AP configuration. Consequently, queue 16.0005\nwill get passed through despite not being bound to the driver. This\nviolates the linux device model requirement that a guest shall only be\ngiven access to devices bound to the device driver facilitating their\npass-through.\n\nTo resolve this problem, every adapter and domain assigned to the mdev will\nbe inspected when filtering the mdev's matrix.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-448c-qhpp-cmmf/GHSA-448c-qhpp-cmmf.json b/advisories/unreviewed/2024/03/GHSA-448c-qhpp-cmmf/GHSA-448c-qhpp-cmmf.json index ff3eac33323..4cc8f3af7f6 100644 --- a/advisories/unreviewed/2024/03/GHSA-448c-qhpp-cmmf/GHSA-448c-qhpp-cmmf.json +++ b/advisories/unreviewed/2024/03/GHSA-448c-qhpp-cmmf/GHSA-448c-qhpp-cmmf.json @@ -7,12 +7,8 @@ "CVE-2024-26611" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: fix usage of multi-buffer BPF helpers for ZC XDP\n\nCurrently when packet is shrunk via bpf_xdp_adjust_tail() and memory\ntype is set to MEM_TYPE_XSK_BUFF_POOL, null ptr dereference happens:\n\n[1136314.192256] BUG: kernel NULL pointer dereference, address:\n0000000000000034\n[1136314.203943] #PF: supervisor read access in kernel mode\n[1136314.213768] #PF: error_code(0x0000) - not-present page\n[1136314.223550] PGD 0 P4D 0\n[1136314.230684] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[1136314.239621] CPU: 8 PID: 54203 Comm: xdpsock Not tainted 6.6.0+ #257\n[1136314.250469] Hardware name: Intel Corporation S2600WFT/S2600WFT,\nBIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019\n[1136314.265615] RIP: 0010:__xdp_return+0x6c/0x210\n[1136314.274653] Code: ad 00 48 8b 47 08 49 89 f8 a8 01 0f 85 9b 01 00 00 0f 1f 44 00 00 f0 41 ff 48 34 75 32 4c 89 c7 e9 79 cd 80 ff 83 fe 03 75 17 41 34 01 0f 85 02 01 00 00 48 89 cf e9 22 cc 1e 00 e9 3d d2 86\n[1136314.302907] RSP: 0018:ffffc900089f8db0 EFLAGS: 00010246\n[1136314.312967] RAX: ffffc9003168aed0 RBX: ffff8881c3300000 RCX:\n0000000000000000\n[1136314.324953] RDX: 0000000000000000 RSI: 0000000000000003 RDI:\nffffc9003168c000\n[1136314.336929] RBP: 0000000000000ae0 R08: 0000000000000002 R09:\n0000000000010000\n[1136314.348844] R10: ffffc9000e495000 R11: 0000000000000040 R12:\n0000000000000001\n[1136314.360706] R13: 0000000000000524 R14: ffffc9003168aec0 R15:\n0000000000000001\n[1136314.373298] FS: 00007f8df8bbcb80(0000) GS:ffff8897e0e00000(0000)\nknlGS:0000000000000000\n[1136314.386105] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[1136314.396532] CR2: 0000000000000034 CR3: 00000001aa912002 CR4:\n00000000007706f0\n[1136314.408377] DR0: 0000000000000000 DR1: 0000000000000000 DR2:\n0000000000000000\n[1136314.420173] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7:\n0000000000000400\n[1136314.431890] PKRU: 55555554\n[1136314.439143] Call Trace:\n[1136314.446058] \n[1136314.452465] ? __die+0x20/0x70\n[1136314.459881] ? page_fault_oops+0x15b/0x440\n[1136314.468305] ? exc_page_fault+0x6a/0x150\n[1136314.476491] ? asm_exc_page_fault+0x22/0x30\n[1136314.484927] ? __xdp_return+0x6c/0x210\n[1136314.492863] bpf_xdp_adjust_tail+0x155/0x1d0\n[1136314.501269] bpf_prog_ccc47ae29d3b6570_xdp_sock_prog+0x15/0x60\n[1136314.511263] ice_clean_rx_irq_zc+0x206/0xc60 [ice]\n[1136314.520222] ? ice_xmit_zc+0x6e/0x150 [ice]\n[1136314.528506] ice_napi_poll+0x467/0x670 [ice]\n[1136314.536858] ? ttwu_do_activate.constprop.0+0x8f/0x1a0\n[1136314.546010] __napi_poll+0x29/0x1b0\n[1136314.553462] net_rx_action+0x133/0x270\n[1136314.561619] __do_softirq+0xbe/0x28e\n[1136314.569303] do_softirq+0x3f/0x60\n\nThis comes from __xdp_return() call with xdp_buff argument passed as\nNULL which is supposed to be consumed by xsk_buff_free() call.\n\nTo address this properly, in ZC case, a node that represents the frag\nbeing removed has to be pulled out of xskb_list. Introduce\nappropriate xsk helpers to do such node operation and use them\naccordingly within bpf_xdp_adjust_tail().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-484w-f535-whcj/GHSA-484w-f535-whcj.json b/advisories/unreviewed/2024/03/GHSA-484w-f535-whcj/GHSA-484w-f535-whcj.json index 2ecde668cc7..202fb00d8fc 100644 --- a/advisories/unreviewed/2024/03/GHSA-484w-f535-whcj/GHSA-484w-f535-whcj.json +++ b/advisories/unreviewed/2024/03/GHSA-484w-f535-whcj/GHSA-484w-f535-whcj.json @@ -7,12 +7,8 @@ "CVE-2023-52569" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: remove BUG() after failure to insert delayed dir index item\n\nInstead of calling BUG() when we fail to insert a delayed dir index item\ninto the delayed node's tree, we can just release all the resources we\nhave allocated/acquired before and return the error to the caller. This is\nfine because all existing call chains undo anything they have done before\ncalling btrfs_insert_delayed_dir_index() or BUG_ON (when creating pending\nsnapshots in the transaction commit path).\n\nSo remove the BUG() call and do proper error handling.\n\nThis relates to a syzbot report linked below, but does not fix it because\nit only prevents hitting a BUG(), it does not fix the issue where somehow\nwe attempt to use twice the same index number for different index items.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4g8c-p257-92cq/GHSA-4g8c-p257-92cq.json b/advisories/unreviewed/2024/03/GHSA-4g8c-p257-92cq/GHSA-4g8c-p257-92cq.json index f6b9c72c6a0..ee83b58b4d2 100644 --- a/advisories/unreviewed/2024/03/GHSA-4g8c-p257-92cq/GHSA-4g8c-p257-92cq.json +++ b/advisories/unreviewed/2024/03/GHSA-4g8c-p257-92cq/GHSA-4g8c-p257-92cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4jr3-hwqp-2vq3/GHSA-4jr3-hwqp-2vq3.json b/advisories/unreviewed/2024/03/GHSA-4jr3-hwqp-2vq3/GHSA-4jr3-hwqp-2vq3.json index 3ebffd785e3..3bf4cd28778 100644 --- a/advisories/unreviewed/2024/03/GHSA-4jr3-hwqp-2vq3/GHSA-4jr3-hwqp-2vq3.json +++ b/advisories/unreviewed/2024/03/GHSA-4jr3-hwqp-2vq3/GHSA-4jr3-hwqp-2vq3.json @@ -7,12 +7,8 @@ "CVE-2023-52516" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-debug: don't call __dma_entry_alloc_check_leak() under free_entries_lock\n\n__dma_entry_alloc_check_leak() calls into printk -> serial console\noutput (qcom geni) and grabs port->lock under free_entries_lock\nspin lock, which is a reverse locking dependency chain as qcom_geni\nIRQ handler can call into dma-debug code and grab free_entries_lock\nunder port->lock.\n\nMove __dma_entry_alloc_check_leak() call out of free_entries_lock\nscope so that we don't acquire serial console's port->lock under it.\n\nTrimmed-down lockdep splat:\n\n The existing dependency chain (in reverse order) is:\n\n -> #2 (free_entries_lock){-.-.}-{2:2}:\n _raw_spin_lock_irqsave+0x60/0x80\n dma_entry_alloc+0x38/0x110\n debug_dma_map_page+0x60/0xf8\n dma_map_page_attrs+0x1e0/0x230\n dma_map_single_attrs.constprop.0+0x6c/0xc8\n geni_se_rx_dma_prep+0x40/0xcc\n qcom_geni_serial_isr+0x310/0x510\n __handle_irq_event_percpu+0x110/0x244\n handle_irq_event_percpu+0x20/0x54\n handle_irq_event+0x50/0x88\n handle_fasteoi_irq+0xa4/0xcc\n handle_irq_desc+0x28/0x40\n generic_handle_domain_irq+0x24/0x30\n gic_handle_irq+0xc4/0x148\n do_interrupt_handler+0xa4/0xb0\n el1_interrupt+0x34/0x64\n el1h_64_irq_handler+0x18/0x24\n el1h_64_irq+0x64/0x68\n arch_local_irq_enable+0x4/0x8\n ____do_softirq+0x18/0x24\n ...\n\n -> #1 (&port_lock_key){-.-.}-{2:2}:\n _raw_spin_lock_irqsave+0x60/0x80\n qcom_geni_serial_console_write+0x184/0x1dc\n console_flush_all+0x344/0x454\n console_unlock+0x94/0xf0\n vprintk_emit+0x238/0x24c\n vprintk_default+0x3c/0x48\n vprintk+0xb4/0xbc\n _printk+0x68/0x90\n register_console+0x230/0x38c\n uart_add_one_port+0x338/0x494\n qcom_geni_serial_probe+0x390/0x424\n platform_probe+0x70/0xc0\n really_probe+0x148/0x280\n __driver_probe_device+0xfc/0x114\n driver_probe_device+0x44/0x100\n __device_attach_driver+0x64/0xdc\n bus_for_each_drv+0xb0/0xd8\n __device_attach+0xe4/0x140\n device_initial_probe+0x1c/0x28\n bus_probe_device+0x44/0xb0\n device_add+0x538/0x668\n of_device_add+0x44/0x50\n of_platform_device_create_pdata+0x94/0xc8\n of_platform_bus_create+0x270/0x304\n of_platform_populate+0xac/0xc4\n devm_of_platform_populate+0x60/0xac\n geni_se_probe+0x154/0x160\n platform_probe+0x70/0xc0\n ...\n\n -> #0 (console_owner){-...}-{0:0}:\n __lock_acquire+0xdf8/0x109c\n lock_acquire+0x234/0x284\n console_flush_all+0x330/0x454\n console_unlock+0x94/0xf0\n vprintk_emit+0x238/0x24c\n vprintk_default+0x3c/0x48\n vprintk+0xb4/0xbc\n _printk+0x68/0x90\n dma_entry_alloc+0xb4/0x110\n debug_dma_map_sg+0xdc/0x2f8\n __dma_map_sg_attrs+0xac/0xe4\n dma_map_sgtable+0x30/0x4c\n get_pages+0x1d4/0x1e4 [msm]\n msm_gem_pin_pages_locked+0x38/0xac [msm]\n msm_gem_pin_vma_locked+0x58/0x88 [msm]\n msm_ioctl_gem_submit+0xde4/0x13ac [msm]\n drm_ioctl_kernel+0xe0/0x15c\n drm_ioctl+0x2e8/0x3f4\n vfs_ioctl+0x30/0x50\n ...\n\n Chain exists of:\n console_owner --> &port_lock_key --> free_entries_lock\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(free_entries_lock);\n lock(&port_lock_key);\n lock(free_entries_lock);\n lock(console_owner);\n\n *** DEADLOCK ***\n\n Call trace:\n dump_backtrace+0xb4/0xf0\n show_stack+0x20/0x30\n dump_stack_lvl+0x60/0x84\n dump_stack+0x18/0x24\n print_circular_bug+0x1cc/0x234\n check_noncircular+0x78/0xac\n __lock_acquire+0xdf8/0x109c\n lock_acquire+0x234/0x284\n console_flush_all+0x330/0x454\n consol\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4ph3-7qqh-5h7g/GHSA-4ph3-7qqh-5h7g.json b/advisories/unreviewed/2024/03/GHSA-4ph3-7qqh-5h7g/GHSA-4ph3-7qqh-5h7g.json index 1f9f86292d8..0c2f1d59724 100644 --- a/advisories/unreviewed/2024/03/GHSA-4ph3-7qqh-5h7g/GHSA-4ph3-7qqh-5h7g.json +++ b/advisories/unreviewed/2024/03/GHSA-4ph3-7qqh-5h7g/GHSA-4ph3-7qqh-5h7g.json @@ -7,12 +7,8 @@ "CVE-2024-27229" ], "details": "In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-59mx-6m8m-c99j/GHSA-59mx-6m8m-c99j.json b/advisories/unreviewed/2024/03/GHSA-59mx-6m8m-c99j/GHSA-59mx-6m8m-c99j.json index 062b51cee4a..24ef3e77b71 100644 --- a/advisories/unreviewed/2024/03/GHSA-59mx-6m8m-c99j/GHSA-59mx-6m8m-c99j.json +++ b/advisories/unreviewed/2024/03/GHSA-59mx-6m8m-c99j/GHSA-59mx-6m8m-c99j.json @@ -7,12 +7,8 @@ "CVE-2023-52504" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/alternatives: Disable KASAN in apply_alternatives()\n\nFei has reported that KASAN triggers during apply_alternatives() on\na 5-level paging machine:\n\n\tBUG: KASAN: out-of-bounds in rcu_is_watching()\n\tRead of size 4 at addr ff110003ee6419a0 by task swapper/0/0\n\t...\n\t__asan_load4()\n\trcu_is_watching()\n\ttrace_hardirqs_on()\n\ttext_poke_early()\n\tapply_alternatives()\n\t...\n\nOn machines with 5-level paging, cpu_feature_enabled(X86_FEATURE_LA57)\ngets patched. It includes KASAN code, where KASAN_SHADOW_START depends on\n__VIRTUAL_MASK_SHIFT, which is defined with cpu_feature_enabled().\n\nKASAN gets confused when apply_alternatives() patches the\nKASAN_SHADOW_START users. A test patch that makes KASAN_SHADOW_START\nstatic, by replacing __VIRTUAL_MASK_SHIFT with 56, works around the issue.\n\nFix it for real by disabling KASAN while the kernel is patching alternatives.\n\n[ mingo: updated the changelog ]", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5jhf-7c6v-c23x/GHSA-5jhf-7c6v-c23x.json b/advisories/unreviewed/2024/03/GHSA-5jhf-7c6v-c23x/GHSA-5jhf-7c6v-c23x.json index c47cf075d65..03fc3ae5ece 100644 --- a/advisories/unreviewed/2024/03/GHSA-5jhf-7c6v-c23x/GHSA-5jhf-7c6v-c23x.json +++ b/advisories/unreviewed/2024/03/GHSA-5jhf-7c6v-c23x/GHSA-5jhf-7c6v-c23x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json b/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json index 64a4cee7e83..9cd7e8ee521 100644 --- a/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json +++ b/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json @@ -7,12 +7,8 @@ "CVE-2024-1487" ], "details": "The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-64pw-78r7-788g/GHSA-64pw-78r7-788g.json b/advisories/unreviewed/2024/03/GHSA-64pw-78r7-788g/GHSA-64pw-78r7-788g.json index ed92d43669b..b19193bfc4c 100644 --- a/advisories/unreviewed/2024/03/GHSA-64pw-78r7-788g/GHSA-64pw-78r7-788g.json +++ b/advisories/unreviewed/2024/03/GHSA-64pw-78r7-788g/GHSA-64pw-78r7-788g.json @@ -7,12 +7,8 @@ "CVE-2024-22011" ], "details": "In ss_ProcessRejectComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-65mj-5f83-m897/GHSA-65mj-5f83-m897.json b/advisories/unreviewed/2024/03/GHSA-65mj-5f83-m897/GHSA-65mj-5f83-m897.json index 35d6ea153ed..1089a74ead5 100644 --- a/advisories/unreviewed/2024/03/GHSA-65mj-5f83-m897/GHSA-65mj-5f83-m897.json +++ b/advisories/unreviewed/2024/03/GHSA-65mj-5f83-m897/GHSA-65mj-5f83-m897.json @@ -7,12 +7,8 @@ "CVE-2023-52560" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions()\n\nWhen CONFIG_DAMON_VADDR_KUNIT_TEST=y and making CONFIG_DEBUG_KMEMLEAK=y\nand CONFIG_DEBUG_KMEMLEAK_AUTO_SCAN=y, the below memory leak is detected.\n\nSince commit 9f86d624292c (\"mm/damon/vaddr-test: remove unnecessary\nvariables\"), the damon_destroy_ctx() is removed, but still call\ndamon_new_target() and damon_new_region(), the damon_region which is\nallocated by kmem_cache_alloc() in damon_new_region() and the damon_target\nwhich is allocated by kmalloc in damon_new_target() are not freed. And\nthe damon_region which is allocated in damon_new_region() in\ndamon_set_regions() is also not freed.\n\nSo use damon_destroy_target to free all the damon_regions and damon_target.\n\n unreferenced object 0xffff888107c9a940 (size 64):\n comm \"kunit_try_catch\", pid 1069, jiffies 4294670592 (age 732.761s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 06 00 00 00 6b 6b 6b 6b ............kkkk\n 60 c7 9c 07 81 88 ff ff f8 cb 9c 07 81 88 ff ff `...............\n backtrace:\n [] kmalloc_trace+0x27/0xa0\n [] damon_new_target+0x3f/0x1b0\n [] damon_do_test_apply_three_regions.constprop.0+0x95/0x3e0\n [] damon_test_apply_three_regions1+0x21e/0x260\n [] kunit_generic_run_threadfn_adapter+0x4a/0x90\n [] kthread+0x2b6/0x380\n [] ret_from_fork+0x2d/0x70\n [] ret_from_fork_asm+0x11/0x20\n unreferenced object 0xffff8881079cc740 (size 56):\n comm \"kunit_try_catch\", pid 1069, jiffies 4294670592 (age 732.761s)\n hex dump (first 32 bytes):\n 05 00 00 00 00 00 00 00 14 00 00 00 00 00 00 00 ................\n 6b 6b 6b 6b 6b 6b 6b 6b 00 00 00 00 6b 6b 6b 6b kkkkkkkk....kkkk\n backtrace:\n [] damon_new_region+0x22/0x1c0\n [] damon_do_test_apply_three_regions.constprop.0+0xd1/0x3e0\n [] damon_test_apply_three_regions1+0x21e/0x260\n [] kunit_generic_run_threadfn_adapter+0x4a/0x90\n [] kthread+0x2b6/0x380\n [] ret_from_fork+0x2d/0x70\n [] ret_from_fork_asm+0x11/0x20\n unreferenced object 0xffff888107c9ac40 (size 64):\n comm \"kunit_try_catch\", pid 1071, jiffies 4294670595 (age 732.843s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 06 00 00 00 6b 6b 6b 6b ............kkkk\n a0 cc 9c 07 81 88 ff ff 78 a1 76 07 81 88 ff ff ........x.v.....\n backtrace:\n [] kmalloc_trace+0x27/0xa0\n [] damon_new_target+0x3f/0x1b0\n [] damon_do_test_apply_three_regions.constprop.0+0x95/0x3e0\n [] damon_test_apply_three_regions2+0x21e/0x260\n [] kunit_generic_run_threadfn_adapter+0x4a/0x90\n [] kthread+0x2b6/0x380\n [] ret_from_fork+0x2d/0x70\n [] ret_from_fork_asm+0x11/0x20\n unreferenced object 0xffff8881079ccc80 (size 56):\n comm \"kunit_try_catch\", pid 1071, jiffies 4294670595 (age 732.843s)\n hex dump (first 32 bytes):\n 05 00 00 00 00 00 00 00 14 00 00 00 00 00 00 00 ................\n 6b 6b 6b 6b 6b 6b 6b 6b 00 00 00 00 6b 6b 6b 6b kkkkkkkk....kkkk\n backtrace:\n [] damon_new_region+0x22/0x1c0\n [] damon_do_test_apply_three_regions.constprop.0+0xd1/0x3e0\n [] damon_test_apply_three_regions2+0x21e/0x260\n [] kunit_generic_run_threadfn_adapter+0x4a/0x90\n [] kthread+0x2b6/0x380\n [] ret_from_fork+0x2d/0x70\n [\ngeneric_shutdown_super+0x47/0x120\nkill_anon_super+0x14/0x30\nceph_kill_sb+0x36/0x90 [ceph]\ndeactivate_locked_super+0x29/0x60\ncleanup_mnt+0xb8/0x140\ntask_work_run+0x67/0xb0\nexit_to_user_mode_prepare+0x23d/0x240\nsyscall_exit_to_user_mode+0x25/0x60\ndo_syscall_64+0x40/0x80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\nRIP: 0033:0x7fd83dc39e9b\n\nLater the kernel will crash when iput() the inodes and dereferencing\nthe \"sb->s_master_keys\", which has been released by the\ngeneric_shutdown_super().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8pp8-jv8p-6mxh/GHSA-8pp8-jv8p-6mxh.json b/advisories/unreviewed/2024/03/GHSA-8pp8-jv8p-6mxh/GHSA-8pp8-jv8p-6mxh.json index 40987ac2724..cafd7a12a23 100644 --- a/advisories/unreviewed/2024/03/GHSA-8pp8-jv8p-6mxh/GHSA-8pp8-jv8p-6mxh.json +++ b/advisories/unreviewed/2024/03/GHSA-8pp8-jv8p-6mxh/GHSA-8pp8-jv8p-6mxh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8w3f-mchr-v6jh/GHSA-8w3f-mchr-v6jh.json b/advisories/unreviewed/2024/03/GHSA-8w3f-mchr-v6jh/GHSA-8w3f-mchr-v6jh.json index 292022106c2..1e7cd1a7dd4 100644 --- a/advisories/unreviewed/2024/03/GHSA-8w3f-mchr-v6jh/GHSA-8w3f-mchr-v6jh.json +++ b/advisories/unreviewed/2024/03/GHSA-8w3f-mchr-v6jh/GHSA-8w3f-mchr-v6jh.json @@ -7,12 +7,8 @@ "CVE-2023-52499" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/47x: Fix 47x syscall return crash\n\nEddie reported that newer kernels were crashing during boot on his 476\nFSP2 system:\n\n kernel tried to execute user page (b7ee2000) - exploit attempt? (uid: 0)\n BUG: Unable to handle kernel instruction fetch\n Faulting instruction address: 0xb7ee2000\n Oops: Kernel access of bad area, sig: 11 [#1]\n BE PAGE_SIZE=4K FSP-2\n Modules linked in:\n CPU: 0 PID: 61 Comm: mount Not tainted 6.1.55-d23900f.ppcnf-fsp2 #1\n Hardware name: ibm,fsp2 476fpe 0x7ff520c0 FSP-2\n NIP:  b7ee2000 LR: 8c008000 CTR: 00000000\n REGS: bffebd83 TRAP: 0400   Not tainted (6.1.55-d23900f.ppcnf-fs p2)\n MSR:  00000030   CR: 00001000  XER: 20000000\n GPR00: c00110ac bffebe63 bffebe7e bffebe88 8c008000 00001000 00000d12 b7ee2000\n GPR08: 00000033 00000000 00000000 c139df10 48224824 1016c314 10160000 00000000\n GPR16: 10160000 10160000 00000008 00000000 10160000 00000000 10160000 1017f5b0\n GPR24: 1017fa50 1017f4f0 1017fa50 1017f740 1017f630 00000000 00000000 1017f4f0\n NIP [b7ee2000] 0xb7ee2000\n LR [8c008000] 0x8c008000\n Call Trace:\n Instruction dump:\n XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX\n XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX\n ---[ end trace 0000000000000000 ]---\n\nThe problem is in ret_from_syscall where the check for\nicache_44x_need_flush is done. When the flush is needed the code jumps\nout-of-line to do the flush, and then intends to jump back to continue\nthe syscall return.\n\nHowever the branch back to label 1b doesn't return to the correct\nlocation, instead branching back just prior to the return to userspace,\ncausing bogus register values to be used by the rfi.\n\nThe breakage was introduced by commit 6f76a01173cc\n(\"powerpc/syscall: implement system call entry/exit logic in C for PPC32\") which\ninadvertently removed the \"1\" label and reused it elsewhere.\n\nFix it by adding named local labels in the correct locations. Note that\nthe return label needs to be outside the ifdef so that CONFIG_PPC_47x=n\ncompiles.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-94pf-4p5q-jc3r/GHSA-94pf-4p5q-jc3r.json b/advisories/unreviewed/2024/03/GHSA-94pf-4p5q-jc3r/GHSA-94pf-4p5q-jc3r.json index 06d996d0915..0d133e614fe 100644 --- a/advisories/unreviewed/2024/03/GHSA-94pf-4p5q-jc3r/GHSA-94pf-4p5q-jc3r.json +++ b/advisories/unreviewed/2024/03/GHSA-94pf-4p5q-jc3r/GHSA-94pf-4p5q-jc3r.json @@ -7,12 +7,8 @@ "CVE-2023-52559" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Avoid memory allocation in iommu_suspend()\n\nThe iommu_suspend() syscore suspend callback is invoked with IRQ disabled.\nAllocating memory with the GFP_KERNEL flag may re-enable IRQs during\nthe suspend callback, which can cause intermittent suspend/hibernation\nproblems with the following kernel traces:\n\nCalling iommu_suspend+0x0/0x1d0\n------------[ cut here ]------------\nWARNING: CPU: 0 PID: 15 at kernel/time/timekeeping.c:868 ktime_get+0x9b/0xb0\n...\nCPU: 0 PID: 15 Comm: rcu_preempt Tainted: G U E 6.3-intel #r1\nRIP: 0010:ktime_get+0x9b/0xb0\n...\nCall Trace:\n \n tick_sched_timer+0x22/0x90\n ? __pfx_tick_sched_timer+0x10/0x10\n __hrtimer_run_queues+0x111/0x2b0\n hrtimer_interrupt+0xfa/0x230\n __sysvec_apic_timer_interrupt+0x63/0x140\n sysvec_apic_timer_interrupt+0x7b/0xa0\n \n \n asm_sysvec_apic_timer_interrupt+0x1f/0x30\n...\n------------[ cut here ]------------\nInterrupts enabled after iommu_suspend+0x0/0x1d0\nWARNING: CPU: 0 PID: 27420 at drivers/base/syscore.c:68 syscore_suspend+0x147/0x270\nCPU: 0 PID: 27420 Comm: rtcwake Tainted: G U W E 6.3-intel #r1\nRIP: 0010:syscore_suspend+0x147/0x270\n...\nCall Trace:\n \n hibernation_snapshot+0x25b/0x670\n hibernate+0xcd/0x390\n state_store+0xcf/0xe0\n kobj_attr_store+0x13/0x30\n sysfs_kf_write+0x3f/0x50\n kernfs_fop_write_iter+0x128/0x200\n vfs_write+0x1fd/0x3c0\n ksys_write+0x6f/0xf0\n __x64_sys_write+0x1d/0x30\n do_syscall_64+0x3b/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\n\nGiven that only 4 words memory is needed, avoid the memory allocation in\niommu_suspend().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-98gp-w8mx-vgw9/GHSA-98gp-w8mx-vgw9.json b/advisories/unreviewed/2024/03/GHSA-98gp-w8mx-vgw9/GHSA-98gp-w8mx-vgw9.json index 978bfd1ba6e..cd447c8bb9b 100644 --- a/advisories/unreviewed/2024/03/GHSA-98gp-w8mx-vgw9/GHSA-98gp-w8mx-vgw9.json +++ b/advisories/unreviewed/2024/03/GHSA-98gp-w8mx-vgw9/GHSA-98gp-w8mx-vgw9.json @@ -7,12 +7,8 @@ "CVE-2023-52506" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Set all reserved memblocks on Node#0 at initialization\n\nAfter commit 61167ad5fecdea (\"mm: pass nid to reserve_bootmem_region()\")\nwe get a panic if DEFERRED_STRUCT_PAGE_INIT is enabled:\n\n[ 0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000000000002b82, era == 90000000040e3f28, ra == 90000000040e3f18\n[ 0.000000] Oops[#1]:\n[ 0.000000] CPU: 0 PID: 0 Comm: swapper Not tainted 6.5.0+ #733\n[ 0.000000] pc 90000000040e3f28 ra 90000000040e3f18 tp 90000000046f4000 sp 90000000046f7c90\n[ 0.000000] a0 0000000000000001 a1 0000000000200000 a2 0000000000000040 a3 90000000046f7ca0\n[ 0.000000] a4 90000000046f7ca4 a5 0000000000000000 a6 90000000046f7c38 a7 0000000000000000\n[ 0.000000] t0 0000000000000002 t1 9000000004b00ac8 t2 90000000040e3f18 t3 90000000040f0800\n[ 0.000000] t4 00000000000f0000 t5 80000000ffffe07e t6 0000000000000003 t7 900000047fff5e20\n[ 0.000000] t8 aaaaaaaaaaaaaaab u0 0000000000000018 s9 0000000000000000 s0 fffffefffe000000\n[ 0.000000] s1 0000000000000000 s2 0000000000000080 s3 0000000000000040 s4 0000000000000000\n[ 0.000000] s5 0000000000000000 s6 fffffefffe000000 s7 900000000470b740 s8 9000000004ad4000\n[ 0.000000] ra: 90000000040e3f18 reserve_bootmem_region+0xec/0x21c\n[ 0.000000] ERA: 90000000040e3f28 reserve_bootmem_region+0xfc/0x21c\n[ 0.000000] CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)\n[ 0.000000] PRMD: 00000000 (PPLV0 -PIE -PWE)\n[ 0.000000] EUEN: 00000000 (-FPE -SXE -ASXE -BTE)\n[ 0.000000] ECFG: 00070800 (LIE=11 VS=7)\n[ 0.000000] ESTAT: 00010800 [PIL] (IS=11 ECode=1 EsubCode=0)\n[ 0.000000] BADV: 0000000000002b82\n[ 0.000000] PRID: 0014d000 (Loongson-64bit, Loongson-3A6000)\n[ 0.000000] Modules linked in:\n[ 0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____))\n[ 0.000000] Stack : 0000000000000000 9000000002eb5430 0000003a00000020 90000000045ccd00\n[ 0.000000] 900000000470e000 90000000002c1918 0000000000000000 9000000004110780\n[ 0.000000] 00000000fe6c0000 0000000480000000 9000000004b4e368 9000000004110748\n[ 0.000000] 0000000000000000 900000000421ca84 9000000004620000 9000000004564970\n[ 0.000000] 90000000046f7d78 9000000002cc9f70 90000000002c1918 900000000470e000\n[ 0.000000] 9000000004564970 90000000040bc0e0 90000000046f7d78 0000000000000000\n[ 0.000000] 0000000000004000 90000000045ccd00 0000000000000000 90000000002c1918\n[ 0.000000] 90000000002c1900 900000000470b700 9000000004b4df78 9000000004620000\n[ 0.000000] 90000000046200a8 90000000046200a8 0000000000000000 9000000004218b2c\n[ 0.000000] 9000000004270008 0000000000000001 0000000000000000 90000000045ccd00\n[ 0.000000] ...\n[ 0.000000] Call Trace:\n[ 0.000000] [<90000000040e3f28>] reserve_bootmem_region+0xfc/0x21c\n[ 0.000000] [<900000000421ca84>] memblock_free_all+0x114/0x350\n[ 0.000000] [<9000000004218b2c>] mm_core_init+0x138/0x3cc\n[ 0.000000] [<9000000004200e38>] start_kernel+0x488/0x7a4\n[ 0.000000] [<90000000040df0d8>] kernel_entry+0xd8/0xdc\n[ 0.000000]\n[ 0.000000] Code: 02eb21ad 00410f4c 380c31ac <262b818d> 6800b70d 02c1c196 0015001c 57fe4bb1 260002cd\n\nThe reason is early memblock_reserve() in memblock_init() set node id to\nMAX_NUMNODES, making NODE_DATA(nid) a NULL dereference in the call chain\nreserve_bootmem_region() -> init_reserved_page(). After memblock_init(),\nthose late calls of memblock_reserve() operate on subregions of memblock\n.memory regions. As a result, these reserved regions will be set to the\ncorrect node at the first iteration of memmap_init_reserved_pages().\n\nSo set all reserved memblocks on Node#0 at initialization can avoid this\npanic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9mhh-v2w9-x3xj/GHSA-9mhh-v2w9-x3xj.json b/advisories/unreviewed/2024/03/GHSA-9mhh-v2w9-x3xj/GHSA-9mhh-v2w9-x3xj.json index 0c668cc275d..e809009ca34 100644 --- a/advisories/unreviewed/2024/03/GHSA-9mhh-v2w9-x3xj/GHSA-9mhh-v2w9-x3xj.json +++ b/advisories/unreviewed/2024/03/GHSA-9mhh-v2w9-x3xj/GHSA-9mhh-v2w9-x3xj.json @@ -7,12 +7,8 @@ "CVE-2023-52515" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srp: Do not call scsi_done() from srp_abort()\n\nAfter scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler\ncallback, it performs one of the following actions:\n* Call scsi_queue_insert().\n* Call scsi_finish_command().\n* Call scsi_eh_scmd_add().\nHence, SCSI abort handlers must not call scsi_done(). Otherwise all\nthe above actions would trigger a use-after-free. Hence remove the\nscsi_done() call from srp_abort(). Keep the srp_free_req() call\nbefore returning SUCCESS because we may not see the command again if\nSUCCESS is returned.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c5gm-r7c3-j9cp/GHSA-c5gm-r7c3-j9cp.json b/advisories/unreviewed/2024/03/GHSA-c5gm-r7c3-j9cp/GHSA-c5gm-r7c3-j9cp.json index cfac577ddc4..f9322d21ac5 100644 --- a/advisories/unreviewed/2024/03/GHSA-c5gm-r7c3-j9cp/GHSA-c5gm-r7c3-j9cp.json +++ b/advisories/unreviewed/2024/03/GHSA-c5gm-r7c3-j9cp/GHSA-c5gm-r7c3-j9cp.json @@ -7,12 +7,8 @@ "CVE-2023-52503" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntee: amdtee: fix use-after-free vulnerability in amdtee_close_session\n\nThere is a potential race condition in amdtee_close_session that may\ncause use-after-free in amdtee_open_session. For instance, if a session\nhas refcount == 1, and one thread tries to free this session via:\n\n kref_put(&sess->refcount, destroy_session);\n\nthe reference count will get decremented, and the next step would be to\ncall destroy_session(). However, if in another thread,\namdtee_open_session() is called before destroy_session() has completed\nexecution, alloc_session() may return 'sess' that will be freed up\nlater in destroy_session() leading to use-after-free in\namdtee_open_session.\n\nTo fix this issue, treat decrement of sess->refcount and removal of\n'sess' from session list in destroy_session() as a critical section, so\nthat it is executed atomically.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-cj2v-p5xc-w33f/GHSA-cj2v-p5xc-w33f.json b/advisories/unreviewed/2024/03/GHSA-cj2v-p5xc-w33f/GHSA-cj2v-p5xc-w33f.json index 4d876634ea8..9b4419e4921 100644 --- a/advisories/unreviewed/2024/03/GHSA-cj2v-p5xc-w33f/GHSA-cj2v-p5xc-w33f.json +++ b/advisories/unreviewed/2024/03/GHSA-cj2v-p5xc-w33f/GHSA-cj2v-p5xc-w33f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-cx4w-f43c-ww54/GHSA-cx4w-f43c-ww54.json b/advisories/unreviewed/2024/03/GHSA-cx4w-f43c-ww54/GHSA-cx4w-f43c-ww54.json index 3bea2adfea0..9f12c506e04 100644 --- a/advisories/unreviewed/2024/03/GHSA-cx4w-f43c-ww54/GHSA-cx4w-f43c-ww54.json +++ b/advisories/unreviewed/2024/03/GHSA-cx4w-f43c-ww54/GHSA-cx4w-f43c-ww54.json @@ -7,12 +7,8 @@ "CVE-2023-52500" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm80xx: Avoid leaking tags when processing OPC_INB_SET_CONTROLLER_CONFIG command\n\nTags allocated for OPC_INB_SET_CONTROLLER_CONFIG command need to be freed\nwhen we receive the response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-f5xj-5mm5-9v8f/GHSA-f5xj-5mm5-9v8f.json b/advisories/unreviewed/2024/03/GHSA-f5xj-5mm5-9v8f/GHSA-f5xj-5mm5-9v8f.json index c14192e82bf..30c02d14756 100644 --- a/advisories/unreviewed/2024/03/GHSA-f5xj-5mm5-9v8f/GHSA-f5xj-5mm5-9v8f.json +++ b/advisories/unreviewed/2024/03/GHSA-f5xj-5mm5-9v8f/GHSA-f5xj-5mm5-9v8f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-fh4f-4w54-vgrf/GHSA-fh4f-4w54-vgrf.json b/advisories/unreviewed/2024/03/GHSA-fh4f-4w54-vgrf/GHSA-fh4f-4w54-vgrf.json index 39c5566c6ac..361d34bd20e 100644 --- a/advisories/unreviewed/2024/03/GHSA-fh4f-4w54-vgrf/GHSA-fh4f-4w54-vgrf.json +++ b/advisories/unreviewed/2024/03/GHSA-fh4f-4w54-vgrf/GHSA-fh4f-4w54-vgrf.json @@ -7,12 +7,8 @@ "CVE-2023-52523" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Reject sk_msg egress redirects to non-TCP sockets\n\nWith a SOCKMAP/SOCKHASH map and an sk_msg program user can steer messages\nsent from one TCP socket (s1) to actually egress from another TCP\nsocket (s2):\n\ntcp_bpf_sendmsg(s1)\t\t// = sk_prot->sendmsg\n tcp_bpf_send_verdict(s1)\t// __SK_REDIRECT case\n tcp_bpf_sendmsg_redir(s2)\n tcp_bpf_push_locked(s2)\n\ttcp_bpf_push(s2)\n\t tcp_rate_check_app_limited(s2) // expects tcp_sock\n\t tcp_sendmsg_locked(s2)\t // ditto\n\nThere is a hard-coded assumption in the call-chain, that the egress\nsocket (s2) is a TCP socket.\n\nHowever in commit 122e6c79efe1 (\"sock_map: Update sock type checks for\nUDP\") we have enabled redirects to non-TCP sockets. This was done for the\nsake of BPF sk_skb programs. There was no indention to support sk_msg\nsend-to-egress use case.\n\nAs a result, attempts to send-to-egress through a non-TCP socket lead to a\ncrash due to invalid downcast from sock to tcp_sock:\n\n BUG: kernel NULL pointer dereference, address: 000000000000002f\n ...\n Call Trace:\n \n ? show_regs+0x60/0x70\n ? __die+0x1f/0x70\n ? page_fault_oops+0x80/0x160\n ? do_user_addr_fault+0x2d7/0x800\n ? rcu_is_watching+0x11/0x50\n ? exc_page_fault+0x70/0x1c0\n ? asm_exc_page_fault+0x27/0x30\n ? tcp_tso_segs+0x14/0xa0\n tcp_write_xmit+0x67/0xce0\n __tcp_push_pending_frames+0x32/0xf0\n tcp_push+0x107/0x140\n tcp_sendmsg_locked+0x99f/0xbb0\n tcp_bpf_push+0x19d/0x3a0\n tcp_bpf_sendmsg_redir+0x55/0xd0\n tcp_bpf_send_verdict+0x407/0x550\n tcp_bpf_sendmsg+0x1a1/0x390\n inet_sendmsg+0x6a/0x70\n sock_sendmsg+0x9d/0xc0\n ? sockfd_lookup_light+0x12/0x80\n __sys_sendto+0x10e/0x160\n ? syscall_enter_from_user_mode+0x20/0x60\n ? __this_cpu_preempt_check+0x13/0x20\n ? lockdep_hardirqs_on+0x82/0x110\n __x64_sys_sendto+0x1f/0x30\n do_syscall_64+0x38/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nReject selecting a non-TCP sockets as redirect target from a BPF sk_msg\nprogram to prevent the crash. When attempted, user will receive an EACCES\nerror from send/sendto/sendmsg() syscall.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-fqh8-982r-rggm/GHSA-fqh8-982r-rggm.json b/advisories/unreviewed/2024/03/GHSA-fqh8-982r-rggm/GHSA-fqh8-982r-rggm.json index 25a8ee10907..1ea752b4a22 100644 --- a/advisories/unreviewed/2024/03/GHSA-fqh8-982r-rggm/GHSA-fqh8-982r-rggm.json +++ b/advisories/unreviewed/2024/03/GHSA-fqh8-982r-rggm/GHSA-fqh8-982r-rggm.json @@ -7,12 +7,8 @@ "CVE-2024-27237" ], "details": "In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,9 +20,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gfh2-325r-ffgp/GHSA-gfh2-325r-ffgp.json b/advisories/unreviewed/2024/03/GHSA-gfh2-325r-ffgp/GHSA-gfh2-325r-ffgp.json index 648ae050c6e..8c72f30cc75 100644 --- a/advisories/unreviewed/2024/03/GHSA-gfh2-325r-ffgp/GHSA-gfh2-325r-ffgp.json +++ b/advisories/unreviewed/2024/03/GHSA-gfh2-325r-ffgp/GHSA-gfh2-325r-ffgp.json @@ -7,12 +7,8 @@ "CVE-2023-52570" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/mdev: Fix a null-ptr-deref bug for mdev_unregister_parent()\n\nInject fault while probing mdpy.ko, if kstrdup() of create_dir() fails in\nkobject_add_internal() in kobject_init_and_add() in mdev_type_add()\nin parent_create_sysfs_files(), it will return 0 and probe successfully.\nAnd when rmmod mdpy.ko, the mdpy_dev_exit() will call\nmdev_unregister_parent(), the mdev_type_remove() may traverse uninitialized\nparent->types[i] in parent_remove_sysfs_files(), and it will cause\nbelow null-ptr-deref.\n\nIf mdev_type_add() fails, return the error code and kset_unregister()\nto fix the issue.\n\n general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN\n KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n CPU: 2 PID: 10215 Comm: rmmod Tainted: G W N 6.6.0-rc2+ #20\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:__kobject_del+0x62/0x1c0\n Code: 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 51 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8b 6b 28 48 8d 7d 10 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 24 01 00 00 48 8b 75 10 48 89 df 48 8d 6b 3c e8\n RSP: 0018:ffff88810695fd30 EFLAGS: 00010202\n RAX: dffffc0000000000 RBX: ffffffffa0270268 RCX: 0000000000000000\n RDX: 0000000000000002 RSI: 0000000000000004 RDI: 0000000000000010\n RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed10233a4ef1\n R10: ffff888119d2778b R11: 0000000063666572 R12: 0000000000000000\n R13: fffffbfff404e2d4 R14: dffffc0000000000 R15: ffffffffa0271660\n FS: 00007fbc81981540(0000) GS:ffff888119d00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fc14a142dc0 CR3: 0000000110a62003 CR4: 0000000000770ee0\n DR0: ffffffff8fb0bce8 DR1: ffffffff8fb0bce9 DR2: ffffffff8fb0bcea\n DR3: ffffffff8fb0bceb DR6: 00000000fffe0ff0 DR7: 0000000000000600\n PKRU: 55555554\n Call Trace:\n \n ? die_addr+0x3d/0xa0\n ? exc_general_protection+0x144/0x220\n ? asm_exc_general_protection+0x22/0x30\n ? __kobject_del+0x62/0x1c0\n kobject_del+0x32/0x50\n parent_remove_sysfs_files+0xd6/0x170 [mdev]\n mdev_unregister_parent+0xfb/0x190 [mdev]\n ? mdev_register_parent+0x270/0x270 [mdev]\n ? find_module_all+0x9d/0xe0\n mdpy_dev_exit+0x17/0x63 [mdpy]\n __do_sys_delete_module.constprop.0+0x2fa/0x4b0\n ? module_flags+0x300/0x300\n ? __fput+0x4e7/0xa00\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n RIP: 0033:0x7fbc813221b7\n Code: 73 01 c3 48 8b 0d d1 8c 2c 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 b0 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d a1 8c 2c 00 f7 d8 64 89 01 48\n RSP: 002b:00007ffe780e0648 EFLAGS: 00000206 ORIG_RAX: 00000000000000b0\n RAX: ffffffffffffffda RBX: 00007ffe780e06a8 RCX: 00007fbc813221b7\n RDX: 000000000000000a RSI: 0000000000000800 RDI: 000055e214df9b58\n RBP: 000055e214df9af0 R08: 00007ffe780df5c1 R09: 0000000000000000\n R10: 00007fbc8139ecc0 R11: 0000000000000206 R12: 00007ffe780e0870\n R13: 00007ffe780e0ed0 R14: 000055e214df9260 R15: 000055e214df9af0\n \n Modules linked in: mdpy(-) mdev vfio_iommu_type1 vfio [last unloaded: mdpy]\n Dumping ftrace buffer:\n (ftrace buffer empty)\n ---[ end trace 0000000000000000 ]---\n RIP: 0010:__kobject_del+0x62/0x1c0\n Code: 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 51 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8b 6b 28 48 8d 7d 10 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 24 01 00 00 48 8b 75 10 48 89 df 48 8d 6b 3c e8\n RSP: 0018:ffff88810695fd30 EFLAGS: 00010202\n RAX: dffffc0000000000 RBX: ffffffffa0270268 RCX: 0000000000000000\n RDX: 0000000000000002 RSI: 0000000000000004 RDI: 0000000000000010\n RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed10233a4ef1\n R10: ffff888119d2778b R11: 0000000063666572 R12: 0000000000000000\n R13: fffffbfff404e2d4 R14: dffffc0000000000 R15: ffffffffa0271660\n FS: 00007fbc81981540(0000) GS:ffff888119d00000(000\n---truncated---", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gg3p-v52w-p6fr/GHSA-gg3p-v52w-p6fr.json b/advisories/unreviewed/2024/03/GHSA-gg3p-v52w-p6fr/GHSA-gg3p-v52w-p6fr.json index 23b8af92fb3..aaeb64a0797 100644 --- a/advisories/unreviewed/2024/03/GHSA-gg3p-v52w-p6fr/GHSA-gg3p-v52w-p6fr.json +++ b/advisories/unreviewed/2024/03/GHSA-gg3p-v52w-p6fr/GHSA-gg3p-v52w-p6fr.json @@ -7,12 +7,8 @@ "CVE-2023-52563" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/meson: fix memory leak on ->hpd_notify callback\n\nThe EDID returned by drm_bridge_get_edid() needs to be freed.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-ggvx-h8v5-pm3j/GHSA-ggvx-h8v5-pm3j.json b/advisories/unreviewed/2024/03/GHSA-ggvx-h8v5-pm3j/GHSA-ggvx-h8v5-pm3j.json index 26b987e14b4..0abbe3cfec0 100644 --- a/advisories/unreviewed/2024/03/GHSA-ggvx-h8v5-pm3j/GHSA-ggvx-h8v5-pm3j.json +++ b/advisories/unreviewed/2024/03/GHSA-ggvx-h8v5-pm3j/GHSA-ggvx-h8v5-pm3j.json @@ -7,12 +7,8 @@ "CVE-2023-52494" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: host: Add alignment check for event ring read pointer\n\nThough we do check the event ring read pointer by \"is_valid_ring_ptr\"\nto make sure it is in the buffer range, but there is another risk the\npointer may be not aligned. Since we are expecting event ring elements\nare 128 bits(struct mhi_ring_element) aligned, an unaligned read pointer\ncould lead to multiple issues like DoS or ring buffer memory corruption.\n\nSo add a alignment check for event ring read pointer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json b/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json index 11b41da07f8..d6022687c95 100644 --- a/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json +++ b/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json @@ -7,12 +7,8 @@ "CVE-2024-0559" ], "details": "The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-h234-f9wp-jpmr/GHSA-h234-f9wp-jpmr.json b/advisories/unreviewed/2024/03/GHSA-h234-f9wp-jpmr/GHSA-h234-f9wp-jpmr.json index 20546f4d75d..9f52fbe89a3 100644 --- a/advisories/unreviewed/2024/03/GHSA-h234-f9wp-jpmr/GHSA-h234-f9wp-jpmr.json +++ b/advisories/unreviewed/2024/03/GHSA-h234-f9wp-jpmr/GHSA-h234-f9wp-jpmr.json @@ -7,12 +7,8 @@ "CVE-2023-52528" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg\n\nsyzbot reported the following uninit-value access issue:\n\n=====================================================\nBUG: KMSAN: uninit-value in smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:975 [inline]\nBUG: KMSAN: uninit-value in smsc75xx_bind+0x5c9/0x11e0 drivers/net/usb/smsc75xx.c:1482\nCPU: 0 PID: 8696 Comm: kworker/0:3 Not tainted 5.8.0-rc5-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nWorkqueue: usb_hub_wq hub_event\nCall Trace:\n __dump_stack lib/dump_stack.c:77 [inline]\n dump_stack+0x21c/0x280 lib/dump_stack.c:118\n kmsan_report+0xf7/0x1e0 mm/kmsan/kmsan_report.c:121\n __msan_warning+0x58/0xa0 mm/kmsan/kmsan_instr.c:215\n smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:975 [inline]\n smsc75xx_bind+0x5c9/0x11e0 drivers/net/usb/smsc75xx.c:1482\n usbnet_probe+0x1152/0x3f90 drivers/net/usb/usbnet.c:1737\n usb_probe_interface+0xece/0x1550 drivers/usb/core/driver.c:374\n really_probe+0xf20/0x20b0 drivers/base/dd.c:529\n driver_probe_device+0x293/0x390 drivers/base/dd.c:701\n __device_attach_driver+0x63f/0x830 drivers/base/dd.c:807\n bus_for_each_drv+0x2ca/0x3f0 drivers/base/bus.c:431\n __device_attach+0x4e2/0x7f0 drivers/base/dd.c:873\n device_initial_probe+0x4a/0x60 drivers/base/dd.c:920\n bus_probe_device+0x177/0x3d0 drivers/base/bus.c:491\n device_add+0x3b0e/0x40d0 drivers/base/core.c:2680\n usb_set_configuration+0x380f/0x3f10 drivers/usb/core/message.c:2032\n usb_generic_driver_probe+0x138/0x300 drivers/usb/core/generic.c:241\n usb_probe_device+0x311/0x490 drivers/usb/core/driver.c:272\n really_probe+0xf20/0x20b0 drivers/base/dd.c:529\n driver_probe_device+0x293/0x390 drivers/base/dd.c:701\n __device_attach_driver+0x63f/0x830 drivers/base/dd.c:807\n bus_for_each_drv+0x2ca/0x3f0 drivers/base/bus.c:431\n __device_attach+0x4e2/0x7f0 drivers/base/dd.c:873\n device_initial_probe+0x4a/0x60 drivers/base/dd.c:920\n bus_probe_device+0x177/0x3d0 drivers/base/bus.c:491\n device_add+0x3b0e/0x40d0 drivers/base/core.c:2680\n usb_new_device+0x1bd4/0x2a30 drivers/usb/core/hub.c:2554\n hub_port_connect drivers/usb/core/hub.c:5208 [inline]\n hub_port_connect_change drivers/usb/core/hub.c:5348 [inline]\n port_event drivers/usb/core/hub.c:5494 [inline]\n hub_event+0x5e7b/0x8a70 drivers/usb/core/hub.c:5576\n process_one_work+0x1688/0x2140 kernel/workqueue.c:2269\n worker_thread+0x10bc/0x2730 kernel/workqueue.c:2415\n kthread+0x551/0x590 kernel/kthread.c:292\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:293\n\nLocal variable ----buf.i87@smsc75xx_bind created at:\n __smsc75xx_read_reg drivers/net/usb/smsc75xx.c:83 [inline]\n smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:968 [inline]\n smsc75xx_bind+0x485/0x11e0 drivers/net/usb/smsc75xx.c:1482\n __smsc75xx_read_reg drivers/net/usb/smsc75xx.c:83 [inline]\n smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:968 [inline]\n smsc75xx_bind+0x485/0x11e0 drivers/net/usb/smsc75xx.c:1482\n\nThis issue is caused because usbnet_read_cmd() reads less bytes than requested\n(zero byte in the reproducer). In this case, 'buf' is not properly filled.\n\nThis patch fixes the issue by returning -ENODATA if usbnet_read_cmd() reads\nless bytes than requested.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-h7jr-j6p8-85m6/GHSA-h7jr-j6p8-85m6.json b/advisories/unreviewed/2024/03/GHSA-h7jr-j6p8-85m6/GHSA-h7jr-j6p8-85m6.json index 82f5ff6802f..e7f1bdcfb51 100644 --- a/advisories/unreviewed/2024/03/GHSA-h7jr-j6p8-85m6/GHSA-h7jr-j6p8-85m6.json +++ b/advisories/unreviewed/2024/03/GHSA-h7jr-j6p8-85m6/GHSA-h7jr-j6p8-85m6.json @@ -7,12 +7,8 @@ "CVE-2023-52507" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: assert requested protocol is valid\n\nThe protocol is used in a bit mask to determine if the protocol is\nsupported. Assert the provided protocol is less than the maximum\ndefined so it doesn't potentially perform a shift-out-of-bounds and\nprovide a clearer error for undefined protocols vs unsupported ones.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-j56h-xwg2-4wc2/GHSA-j56h-xwg2-4wc2.json b/advisories/unreviewed/2024/03/GHSA-j56h-xwg2-4wc2/GHSA-j56h-xwg2-4wc2.json index 1d36211f54d..149f8204d34 100644 --- a/advisories/unreviewed/2024/03/GHSA-j56h-xwg2-4wc2/GHSA-j56h-xwg2-4wc2.json +++ b/advisories/unreviewed/2024/03/GHSA-j56h-xwg2-4wc2/GHSA-j56h-xwg2-4wc2.json @@ -7,12 +7,8 @@ "CVE-2023-52562" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab_common: fix slab_caches list corruption after kmem_cache_destroy()\n\nAfter the commit in Fixes:, if a module that created a slab cache does not\nrelease all of its allocated objects before destroying the cache (at rmmod\ntime), we might end up releasing the kmem_cache object without removing it\nfrom the slab_caches list thus corrupting the list as kmem_cache_destroy()\nignores the return value from shutdown_cache(), which in turn never removes\nthe kmem_cache object from slabs_list in case __kmem_cache_shutdown() fails\nto release all of the cache's slabs.\n\nThis is easily observable on a kernel built with CONFIG_DEBUG_LIST=y\nas after that ill release the system will immediately trip on list_add,\nor list_del, assertions similar to the one shown below as soon as another\nkmem_cache gets created, or destroyed:\n\n [ 1041.213632] list_del corruption. next->prev should be ffff89f596fb5768, but was 52f1e5016aeee75d. (next=ffff89f595a1b268)\n [ 1041.219165] ------------[ cut here ]------------\n [ 1041.221517] kernel BUG at lib/list_debug.c:62!\n [ 1041.223452] invalid opcode: 0000 [#1] PREEMPT SMP PTI\n [ 1041.225408] CPU: 2 PID: 1852 Comm: rmmod Kdump: loaded Tainted: G B W OE 6.5.0 #15\n [ 1041.228244] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20230524-3.fc37 05/24/2023\n [ 1041.231212] RIP: 0010:__list_del_entry_valid+0xae/0xb0\n\nAnother quick way to trigger this issue, in a kernel with CONFIG_SLUB=y,\nis to set slub_debug to poison the released objects and then just run\ncat /proc/slabinfo after removing the module that leaks slab objects,\nin which case the kernel will panic:\n\n [ 50.954843] general protection fault, probably for non-canonical address 0xa56b6b6b6b6b6b8b: 0000 [#1] PREEMPT SMP PTI\n [ 50.961545] CPU: 2 PID: 1495 Comm: cat Kdump: loaded Tainted: G B W OE 6.5.0 #15\n [ 50.966808] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20230524-3.fc37 05/24/2023\n [ 50.972663] RIP: 0010:get_slabinfo+0x42/0xf0\n\nThis patch fixes this issue by properly checking shutdown_cache()'s\nreturn value before taking the kmem_cache_release() branch.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-j6qg-38wf-82gm/GHSA-j6qg-38wf-82gm.json b/advisories/unreviewed/2024/03/GHSA-j6qg-38wf-82gm/GHSA-j6qg-38wf-82gm.json index b6b6472b9a6..1b34b3a39b9 100644 --- a/advisories/unreviewed/2024/03/GHSA-j6qg-38wf-82gm/GHSA-j6qg-38wf-82gm.json +++ b/advisories/unreviewed/2024/03/GHSA-j6qg-38wf-82gm/GHSA-j6qg-38wf-82gm.json @@ -7,12 +7,8 @@ "CVE-2023-52527" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4, ipv6: Fix handling of transhdrlen in __ip{,6}_append_data()\n\nIncluding the transhdrlen in length is a problem when the packet is\npartially filled (e.g. something like send(MSG_MORE) happened previously)\nwhen appending to an IPv4 or IPv6 packet as we don't want to repeat the\ntransport header or account for it twice. This can happen under some\ncircumstances, such as splicing into an L2TP socket.\n\nThe symptom observed is a warning in __ip6_append_data():\n\n WARNING: CPU: 1 PID: 5042 at net/ipv6/ip6_output.c:1800 __ip6_append_data.isra.0+0x1be8/0x47f0 net/ipv6/ip6_output.c:1800\n\nthat occurs when MSG_SPLICE_PAGES is used to append more data to an already\npartially occupied skbuff. The warning occurs when 'copy' is larger than\nthe amount of data in the message iterator. This is because the requested\nlength includes the transport header length when it shouldn't. This can be\ntriggered by, for example:\n\n sfd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_L2TP);\n bind(sfd, ...); // ::1\n connect(sfd, ...); // ::1 port 7\n send(sfd, buffer, 4100, MSG_MORE);\n sendfile(sfd, dfd, NULL, 1024);\n\nFix this by only adding transhdrlen into the length if the write queue is\nempty in l2tp_ip6_sendmsg(), analogously to how UDP does things.\n\nl2tp_ip_sendmsg() looks like it won't suffer from this problem as it builds\nthe UDP packet itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-jfc7-9f46-xvqw/GHSA-jfc7-9f46-xvqw.json b/advisories/unreviewed/2024/03/GHSA-jfc7-9f46-xvqw/GHSA-jfc7-9f46-xvqw.json index 17ae2e2836b..34f0ab05414 100644 --- a/advisories/unreviewed/2024/03/GHSA-jfc7-9f46-xvqw/GHSA-jfc7-9f46-xvqw.json +++ b/advisories/unreviewed/2024/03/GHSA-jfc7-9f46-xvqw/GHSA-jfc7-9f46-xvqw.json @@ -7,12 +7,8 @@ "CVE-2023-52501" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Do not attempt to read past \"commit\"\n\nWhen iterating over the ring buffer while the ring buffer is active, the\nwriter can corrupt the reader. There's barriers to help detect this and\nhandle it, but that code missed the case where the last event was at the\nvery end of the page and has only 4 bytes left.\n\nThe checks to detect the corruption by the writer to reads needs to see the\nlength of the event. If the length in the first 4 bytes is zero then the\nlength is stored in the second 4 bytes. But if the writer is in the process\nof updating that code, there's a small window where the length in the first\n4 bytes could be zero even though the length is only 4 bytes. That will\ncause rb_event_length() to read the next 4 bytes which could happen to be off the\nallocated page.\n\nTo protect against this, fail immediately if the next event pointer is\nless than 8 bytes from the end of the commit (last byte of data), as all\nevents must be a minimum of 8 bytes anyway.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-m7hf-5mp8-h9g2/GHSA-m7hf-5mp8-h9g2.json b/advisories/unreviewed/2024/03/GHSA-m7hf-5mp8-h9g2/GHSA-m7hf-5mp8-h9g2.json index a0e36e272b0..19bfd51416a 100644 --- a/advisories/unreviewed/2024/03/GHSA-m7hf-5mp8-h9g2/GHSA-m7hf-5mp8-h9g2.json +++ b/advisories/unreviewed/2024/03/GHSA-m7hf-5mp8-h9g2/GHSA-m7hf-5mp8-h9g2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mvcc-fjcm-33jm/GHSA-mvcc-fjcm-33jm.json b/advisories/unreviewed/2024/03/GHSA-mvcc-fjcm-33jm/GHSA-mvcc-fjcm-33jm.json index c16c32bf606..05a6c2016e7 100644 --- a/advisories/unreviewed/2024/03/GHSA-mvcc-fjcm-33jm/GHSA-mvcc-fjcm-33jm.json +++ b/advisories/unreviewed/2024/03/GHSA-mvcc-fjcm-33jm/GHSA-mvcc-fjcm-33jm.json @@ -7,12 +7,8 @@ "CVE-2023-52531" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: Fix a memory corruption issue\n\nA few lines above, space is kzalloc()'ed for:\n\tsizeof(struct iwl_nvm_data) +\n\tsizeof(struct ieee80211_channel) +\n\tsizeof(struct ieee80211_rate)\n\n'mvm->nvm_data' is a 'struct iwl_nvm_data', so it is fine.\n\nAt the end of this structure, there is the 'channels' flex array.\nEach element is of type 'struct ieee80211_channel'.\nSo only 1 element is allocated in this array.\n\nWhen doing:\n mvm->nvm_data->bands[0].channels = mvm->nvm_data->channels;\nWe point at the first element of the 'channels' flex array.\nSo this is fine.\n\nHowever, when doing:\n mvm->nvm_data->bands[0].bitrates =\n\t\t\t(void *)((u8 *)mvm->nvm_data->channels + 1);\nbecause of the \"(u8 *)\" cast, we add only 1 to the address of the beginning\nof the flex array.\n\nIt is likely that we want point at the 'struct ieee80211_rate' allocated\njust after.\n\nRemove the spurious casting so that the pointer arithmetic works as\nexpected.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mwpw-qjpv-xv3x/GHSA-mwpw-qjpv-xv3x.json b/advisories/unreviewed/2024/03/GHSA-mwpw-qjpv-xv3x/GHSA-mwpw-qjpv-xv3x.json index bf6d552be7e..76038d5cac0 100644 --- a/advisories/unreviewed/2024/03/GHSA-mwpw-qjpv-xv3x/GHSA-mwpw-qjpv-xv3x.json +++ b/advisories/unreviewed/2024/03/GHSA-mwpw-qjpv-xv3x/GHSA-mwpw-qjpv-xv3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mx24-9c8c-52xx/GHSA-mx24-9c8c-52xx.json b/advisories/unreviewed/2024/03/GHSA-mx24-9c8c-52xx/GHSA-mx24-9c8c-52xx.json index 733add25740..5ff9a796974 100644 --- a/advisories/unreviewed/2024/03/GHSA-mx24-9c8c-52xx/GHSA-mx24-9c8c-52xx.json +++ b/advisories/unreviewed/2024/03/GHSA-mx24-9c8c-52xx/GHSA-mx24-9c8c-52xx.json @@ -7,12 +7,8 @@ "CVE-2023-52505" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: lynx-28g: serialize concurrent phy_set_mode_ext() calls to shared registers\n\nThe protocol converter configuration registers PCC8, PCCC, PCCD\n(implemented by the driver), as well as others, control protocol\nconverters from multiple lanes (each represented as a different\nstruct phy). So, if there are simultaneous calls to phy_set_mode_ext()\nto lanes sharing the same PCC register (either for the \"old\" or for the\n\"new\" protocol), corruption of the values programmed to hardware is\npossible, because lynx_28g_rmw() has no locking.\n\nAdd a spinlock in the struct lynx_28g_priv shared by all lanes, and take\nthe global spinlock from the phy_ops :: set_mode() implementation. There\nare no other callers which modify PCC registers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pcxc-636v-74pc/GHSA-pcxc-636v-74pc.json b/advisories/unreviewed/2024/03/GHSA-pcxc-636v-74pc/GHSA-pcxc-636v-74pc.json index 784ad471ff0..41c438c0ca4 100644 --- a/advisories/unreviewed/2024/03/GHSA-pcxc-636v-74pc/GHSA-pcxc-636v-74pc.json +++ b/advisories/unreviewed/2024/03/GHSA-pcxc-636v-74pc/GHSA-pcxc-636v-74pc.json @@ -7,12 +7,8 @@ "CVE-2023-52565" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: uvcvideo: Fix OOB read\n\nIf the index provided by the user is bigger than the mask size, we might do\nan out of bound read.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pw43-2cfm-ff7r/GHSA-pw43-2cfm-ff7r.json b/advisories/unreviewed/2024/03/GHSA-pw43-2cfm-ff7r/GHSA-pw43-2cfm-ff7r.json index a9a3b1d70dd..cc6d3d5c5ba 100644 --- a/advisories/unreviewed/2024/03/GHSA-pw43-2cfm-ff7r/GHSA-pw43-2cfm-ff7r.json +++ b/advisories/unreviewed/2024/03/GHSA-pw43-2cfm-ff7r/GHSA-pw43-2cfm-ff7r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r7v7-m4x6-4rxm/GHSA-r7v7-m4x6-4rxm.json b/advisories/unreviewed/2024/03/GHSA-r7v7-m4x6-4rxm/GHSA-r7v7-m4x6-4rxm.json index 2758b9fb739..b17b6249acb 100644 --- a/advisories/unreviewed/2024/03/GHSA-r7v7-m4x6-4rxm/GHSA-r7v7-m4x6-4rxm.json +++ b/advisories/unreviewed/2024/03/GHSA-r7v7-m4x6-4rxm/GHSA-r7v7-m4x6-4rxm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-r867-j6v8-hv77/GHSA-r867-j6v8-hv77.json b/advisories/unreviewed/2024/03/GHSA-r867-j6v8-hv77/GHSA-r867-j6v8-hv77.json index 267043b342d..55787d007b8 100644 --- a/advisories/unreviewed/2024/03/GHSA-r867-j6v8-hv77/GHSA-r867-j6v8-hv77.json +++ b/advisories/unreviewed/2024/03/GHSA-r867-j6v8-hv77/GHSA-r867-j6v8-hv77.json @@ -7,12 +7,8 @@ "CVE-2023-52517" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: sun6i: fix race between DMA RX transfer completion and RX FIFO drain\n\nPreviously the transfer complete IRQ immediately drained to RX FIFO to\nread any data remaining in FIFO to the RX buffer. This behaviour is\ncorrect when dealing with SPI in interrupt mode. However in DMA mode the\ntransfer complete interrupt still fires as soon as all bytes to be\ntransferred have been stored in the FIFO. At that point data in the FIFO\nstill needs to be picked up by the DMA engine. Thus the drain procedure\nand DMA engine end up racing to read from RX FIFO, corrupting any data\nread. Additionally the RX buffer pointer is never adjusted according to\nDMA progress in DMA mode, thus calling the RX FIFO drain procedure in DMA\nmode is a bug.\nFix corruptions in DMA RX mode by draining RX FIFO only in interrupt mode.\nAlso wait for completion of RX DMA when in DMA mode before returning to\nensure all data has been copied to the supplied memory buffer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rh37-q3m6-762g/GHSA-rh37-q3m6-762g.json b/advisories/unreviewed/2024/03/GHSA-rh37-q3m6-762g/GHSA-rh37-q3m6-762g.json index e0e6d8746c3..d46c821a935 100644 --- a/advisories/unreviewed/2024/03/GHSA-rh37-q3m6-762g/GHSA-rh37-q3m6-762g.json +++ b/advisories/unreviewed/2024/03/GHSA-rh37-q3m6-762g/GHSA-rh37-q3m6-762g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-rj62-x3fp-f44h/GHSA-rj62-x3fp-f44h.json b/advisories/unreviewed/2024/03/GHSA-rj62-x3fp-f44h/GHSA-rj62-x3fp-f44h.json index 78c684b0c43..cdca2f3ac59 100644 --- a/advisories/unreviewed/2024/03/GHSA-rj62-x3fp-f44h/GHSA-rj62-x3fp-f44h.json +++ b/advisories/unreviewed/2024/03/GHSA-rj62-x3fp-f44h/GHSA-rj62-x3fp-f44h.json @@ -7,12 +7,8 @@ "CVE-2023-52572" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix UAF in cifs_demultiplex_thread()\n\nThere is a UAF when xfstests on cifs:\n\n BUG: KASAN: use-after-free in smb2_is_network_name_deleted+0x27/0x160\n Read of size 4 at addr ffff88810103fc08 by task cifsd/923\n\n CPU: 1 PID: 923 Comm: cifsd Not tainted 6.1.0-rc4+ #45\n ...\n Call Trace:\n \n dump_stack_lvl+0x34/0x44\n print_report+0x171/0x472\n kasan_report+0xad/0x130\n kasan_check_range+0x145/0x1a0\n smb2_is_network_name_deleted+0x27/0x160\n cifs_demultiplex_thread.cold+0x172/0x5a4\n kthread+0x165/0x1a0\n ret_from_fork+0x1f/0x30\n \n\n Allocated by task 923:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n __kasan_slab_alloc+0x54/0x60\n kmem_cache_alloc+0x147/0x320\n mempool_alloc+0xe1/0x260\n cifs_small_buf_get+0x24/0x60\n allocate_buffers+0xa1/0x1c0\n cifs_demultiplex_thread+0x199/0x10d0\n kthread+0x165/0x1a0\n ret_from_fork+0x1f/0x30\n\n Freed by task 921:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_save_free_info+0x2a/0x40\n ____kasan_slab_free+0x143/0x1b0\n kmem_cache_free+0xe3/0x4d0\n cifs_small_buf_release+0x29/0x90\n SMB2_negotiate+0x8b7/0x1c60\n smb2_negotiate+0x51/0x70\n cifs_negotiate_protocol+0xf0/0x160\n cifs_get_smb_ses+0x5fa/0x13c0\n mount_get_conns+0x7a/0x750\n cifs_mount+0x103/0xd00\n cifs_smb3_do_mount+0x1dd/0xcb0\n smb3_get_tree+0x1d5/0x300\n vfs_get_tree+0x41/0xf0\n path_mount+0x9b3/0xdd0\n __x64_sys_mount+0x190/0x1d0\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nThe UAF is because:\n\n mount(pid: 921) | cifsd(pid: 923)\n-------------------------------|-------------------------------\n | cifs_demultiplex_thread\nSMB2_negotiate |\n cifs_send_recv |\n compound_send_recv |\n smb_send_rqst |\n wait_for_response |\n wait_event_state [1] |\n | standard_receive3\n | cifs_handle_standard\n | handle_mid\n | mid->resp_buf = buf; [2]\n | dequeue_mid [3]\n KILL the process [4] |\n resp_iov[i].iov_base = buf |\n free_rsp_buf [5] |\n | is_network_name_deleted [6]\n | callback\n\n1. After send request to server, wait the response until\n mid->mid_state != SUBMITTED;\n2. Receive response from server, and set it to mid;\n3. Set the mid state to RECEIVED;\n4. Kill the process, the mid state already RECEIVED, get 0;\n5. Handle and release the negotiate response;\n6. UAF.\n\nIt can be easily reproduce with add some delay in [3] - [6].\n\nOnly sync call has the problem since async call's callback is\nexecuted in cifsd process.\n\nAdd an extra state to mark the mid state to READY before wakeup the\nwaitter, then it can get the resp safely.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-vhp7-fvvc-gp4m/GHSA-vhp7-fvvc-gp4m.json b/advisories/unreviewed/2024/03/GHSA-vhp7-fvvc-gp4m/GHSA-vhp7-fvvc-gp4m.json index 4480e7e923b..8b2a3eeaf07 100644 --- a/advisories/unreviewed/2024/03/GHSA-vhp7-fvvc-gp4m/GHSA-vhp7-fvvc-gp4m.json +++ b/advisories/unreviewed/2024/03/GHSA-vhp7-fvvc-gp4m/GHSA-vhp7-fvvc-gp4m.json @@ -7,12 +7,8 @@ "CVE-2023-52532" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix TX CQE error handling\n\nFor an unknown TX CQE error type (probably from a newer hardware),\nstill free the SKB, update the queue tail, etc., otherwise the\naccounting will be wrong.\n\nAlso, TX errors can be triggered by injecting corrupted packets, so\nreplace the WARN_ONCE to ratelimited error logging.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-vvwp-xfww-2qhh/GHSA-vvwp-xfww-2qhh.json b/advisories/unreviewed/2024/03/GHSA-vvwp-xfww-2qhh/GHSA-vvwp-xfww-2qhh.json index 34d99b452c4..5e031f77b27 100644 --- a/advisories/unreviewed/2024/03/GHSA-vvwp-xfww-2qhh/GHSA-vvwp-xfww-2qhh.json +++ b/advisories/unreviewed/2024/03/GHSA-vvwp-xfww-2qhh/GHSA-vvwp-xfww-2qhh.json @@ -7,12 +7,8 @@ "CVE-2023-52519" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: intel-ish-hid: ipc: Disable and reenable ACPI GPE bit\n\nThe EHL (Elkhart Lake) based platforms provide a OOB (Out of band)\nservice, which allows to wakup device when the system is in S5 (Soft-Off\nstate). This OOB service can be enabled/disabled from BIOS settings. When\nenabled, the ISH device gets PME wake capability. To enable PME wakeup,\ndriver also needs to enable ACPI GPE bit.\n\nOn resume, BIOS will clear the wakeup bit. So driver need to re-enable it\nin resume function to keep the next wakeup capability. But this BIOS\nclearing of wakeup bit doesn't decrement internal OS GPE reference count,\nso this reenabling on every resume will cause reference count to overflow.\n\nSo first disable and reenable ACPI GPE bit using acpi_disable_gpe().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-w2cg-jcf6-hrgr/GHSA-w2cg-jcf6-hrgr.json b/advisories/unreviewed/2024/03/GHSA-w2cg-jcf6-hrgr/GHSA-w2cg-jcf6-hrgr.json index 7704d55cd63..9b8818b3742 100644 --- a/advisories/unreviewed/2024/03/GHSA-w2cg-jcf6-hrgr/GHSA-w2cg-jcf6-hrgr.json +++ b/advisories/unreviewed/2024/03/GHSA-w2cg-jcf6-hrgr/GHSA-w2cg-jcf6-hrgr.json @@ -7,12 +7,8 @@ "CVE-2023-52520" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: think-lmi: Fix reference leak\n\nIf a duplicate attribute is found using kset_find_obj(), a reference\nto that attribute is returned which needs to be disposed accordingly\nusing kobject_put(). Move the setting name validation into a separate\nfunction to allow for this change without having to duplicate the\ncleanup code for this setting.\nAs a side note, a very similar bug was fixed in\ncommit 7295a996fdab (\"platform/x86: dell-sysman: Fix reference leak\"),\nso it seems that the bug was copied from that driver.\n\nCompile-tested only.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-wgvh-m7hp-9m4m/GHSA-wgvh-m7hp-9m4m.json b/advisories/unreviewed/2024/03/GHSA-wgvh-m7hp-9m4m/GHSA-wgvh-m7hp-9m4m.json index 0bff65a15fa..b554bfcfc9f 100644 --- a/advisories/unreviewed/2024/03/GHSA-wgvh-m7hp-9m4m/GHSA-wgvh-m7hp-9m4m.json +++ b/advisories/unreviewed/2024/03/GHSA-wgvh-m7hp-9m4m/GHSA-wgvh-m7hp-9m4m.json @@ -7,12 +7,8 @@ "CVE-2023-52509" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nravb: Fix use-after-free issue in ravb_tx_timeout_work()\n\nThe ravb_stop() should call cancel_work_sync(). Otherwise,\nravb_tx_timeout_work() is possible to use the freed priv after\nravb_remove() was called like below:\n\nCPU0\t\t\tCPU1\n\t\t\travb_tx_timeout()\nravb_remove()\nunregister_netdev()\nfree_netdev(ndev)\n// free priv\n\t\t\travb_tx_timeout_work()\n\t\t\t// use priv\n\nunregister_netdev() will call .ndo_stop() so that ravb_stop() is\ncalled. And, after phy_stop() is called, netif_carrier_off()\nis also called. So that .ndo_tx_timeout() will not be called\nafter phy_stop().", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-x9q8-72p3-mmvx/GHSA-x9q8-72p3-mmvx.json b/advisories/unreviewed/2024/03/GHSA-x9q8-72p3-mmvx/GHSA-x9q8-72p3-mmvx.json index 3836fff612f..1ef17f01a1d 100644 --- a/advisories/unreviewed/2024/03/GHSA-x9q8-72p3-mmvx/GHSA-x9q8-72p3-mmvx.json +++ b/advisories/unreviewed/2024/03/GHSA-x9q8-72p3-mmvx/GHSA-x9q8-72p3-mmvx.json @@ -7,12 +7,8 @@ "CVE-2023-52524" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nfc: llcp: Add lock when modifying device list\n\nThe device list needs its associated lock held when modifying it, or the\nlist could become corrupted, as syzbot discovered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xc3g-cm27-mcmg/GHSA-xc3g-cm27-mcmg.json b/advisories/unreviewed/2024/03/GHSA-xc3g-cm27-mcmg/GHSA-xc3g-cm27-mcmg.json index 82e3e55f866..a6efdd517e2 100644 --- a/advisories/unreviewed/2024/03/GHSA-xc3g-cm27-mcmg/GHSA-xc3g-cm27-mcmg.json +++ b/advisories/unreviewed/2024/03/GHSA-xc3g-cm27-mcmg/GHSA-xc3g-cm27-mcmg.json @@ -7,12 +7,8 @@ "CVE-2023-52526" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix memory leak of LZMA global compressed deduplication\n\nWhen stressing microLZMA EROFS images with the new global compressed\ndeduplication feature enabled (`-Ededupe`), I found some short-lived\ntemporary pages weren't properly released, which could slowly cause\nunexpected OOMs hours later.\n\nLet's fix it now (LZ4 and DEFLATE don't have this issue.)", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xxmf-2mw8-gvh6/GHSA-xxmf-2mw8-gvh6.json b/advisories/unreviewed/2024/03/GHSA-xxmf-2mw8-gvh6/GHSA-xxmf-2mw8-gvh6.json index 7a74add0e2a..90bf7597661 100644 --- a/advisories/unreviewed/2024/03/GHSA-xxmf-2mw8-gvh6/GHSA-xxmf-2mw8-gvh6.json +++ b/advisories/unreviewed/2024/03/GHSA-xxmf-2mw8-gvh6/GHSA-xxmf-2mw8-gvh6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-f982-vxqp-wp2r/GHSA-f982-vxqp-wp2r.json b/advisories/unreviewed/2024/04/GHSA-f982-vxqp-wp2r/GHSA-f982-vxqp-wp2r.json index a9b245ea433..fa1384b0866 100644 --- a/advisories/unreviewed/2024/04/GHSA-f982-vxqp-wp2r/GHSA-f982-vxqp-wp2r.json +++ b/advisories/unreviewed/2024/04/GHSA-f982-vxqp-wp2r/GHSA-f982-vxqp-wp2r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-2p8m-9j88-g5mf/GHSA-2p8m-9j88-g5mf.json b/advisories/unreviewed/2024/05/GHSA-2p8m-9j88-g5mf/GHSA-2p8m-9j88-g5mf.json index 9e3fa9727ac..da994eab1af 100644 --- a/advisories/unreviewed/2024/05/GHSA-2p8m-9j88-g5mf/GHSA-2p8m-9j88-g5mf.json +++ b/advisories/unreviewed/2024/05/GHSA-2p8m-9j88-g5mf/GHSA-2p8m-9j88-g5mf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3j75-rq9m-pxrv/GHSA-3j75-rq9m-pxrv.json b/advisories/unreviewed/2024/05/GHSA-3j75-rq9m-pxrv/GHSA-3j75-rq9m-pxrv.json index 6f2df8f78b4..8c224df8c91 100644 --- a/advisories/unreviewed/2024/05/GHSA-3j75-rq9m-pxrv/GHSA-3j75-rq9m-pxrv.json +++ b/advisories/unreviewed/2024/05/GHSA-3j75-rq9m-pxrv/GHSA-3j75-rq9m-pxrv.json @@ -7,12 +7,8 @@ "CVE-2024-20060" ], "details": "In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-3m75-gpxr-6926/GHSA-3m75-gpxr-6926.json b/advisories/unreviewed/2024/05/GHSA-3m75-gpxr-6926/GHSA-3m75-gpxr-6926.json index 82ab0b1df58..208b41dc410 100644 --- a/advisories/unreviewed/2024/05/GHSA-3m75-gpxr-6926/GHSA-3m75-gpxr-6926.json +++ b/advisories/unreviewed/2024/05/GHSA-3m75-gpxr-6926/GHSA-3m75-gpxr-6926.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-496x-pq3h-gfff/GHSA-496x-pq3h-gfff.json b/advisories/unreviewed/2024/05/GHSA-496x-pq3h-gfff/GHSA-496x-pq3h-gfff.json index 26c37b3accc..2bf0d8439ca 100644 --- a/advisories/unreviewed/2024/05/GHSA-496x-pq3h-gfff/GHSA-496x-pq3h-gfff.json +++ b/advisories/unreviewed/2024/05/GHSA-496x-pq3h-gfff/GHSA-496x-pq3h-gfff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-4q7g-933v-g3rq/GHSA-4q7g-933v-g3rq.json b/advisories/unreviewed/2024/05/GHSA-4q7g-933v-g3rq/GHSA-4q7g-933v-g3rq.json index 439f136121a..5654456600c 100644 --- a/advisories/unreviewed/2024/05/GHSA-4q7g-933v-g3rq/GHSA-4q7g-933v-g3rq.json +++ b/advisories/unreviewed/2024/05/GHSA-4q7g-933v-g3rq/GHSA-4q7g-933v-g3rq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-6v68-8fv3-wc3f/GHSA-6v68-8fv3-wc3f.json b/advisories/unreviewed/2024/05/GHSA-6v68-8fv3-wc3f/GHSA-6v68-8fv3-wc3f.json index 5de8ce30310..1e032f2b5d9 100644 --- a/advisories/unreviewed/2024/05/GHSA-6v68-8fv3-wc3f/GHSA-6v68-8fv3-wc3f.json +++ b/advisories/unreviewed/2024/05/GHSA-6v68-8fv3-wc3f/GHSA-6v68-8fv3-wc3f.json @@ -7,12 +7,8 @@ "CVE-2024-20064" ], "details": "In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08572601; Issue ID: MSV-1229.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-826p-p2mp-vgq9/GHSA-826p-p2mp-vgq9.json b/advisories/unreviewed/2024/05/GHSA-826p-p2mp-vgq9/GHSA-826p-p2mp-vgq9.json index af0c87deb2b..5b77a889f4f 100644 --- a/advisories/unreviewed/2024/05/GHSA-826p-p2mp-vgq9/GHSA-826p-p2mp-vgq9.json +++ b/advisories/unreviewed/2024/05/GHSA-826p-p2mp-vgq9/GHSA-826p-p2mp-vgq9.json @@ -7,12 +7,8 @@ "CVE-2024-20056" ], "details": "In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-8x9p-jch8-mr54/GHSA-8x9p-jch8-mr54.json b/advisories/unreviewed/2024/05/GHSA-8x9p-jch8-mr54/GHSA-8x9p-jch8-mr54.json index 7edf4cc6d7b..4930c7d2521 100644 --- a/advisories/unreviewed/2024/05/GHSA-8x9p-jch8-mr54/GHSA-8x9p-jch8-mr54.json +++ b/advisories/unreviewed/2024/05/GHSA-8x9p-jch8-mr54/GHSA-8x9p-jch8-mr54.json @@ -7,12 +7,8 @@ "CVE-2023-32873" ], "details": "In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08583919; Issue ID: ALPS08304227.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-mm6w-vpgv-7hxr/GHSA-mm6w-vpgv-7hxr.json b/advisories/unreviewed/2024/05/GHSA-mm6w-vpgv-7hxr/GHSA-mm6w-vpgv-7hxr.json index 2fefdde847e..b700e9a75ff 100644 --- a/advisories/unreviewed/2024/05/GHSA-mm6w-vpgv-7hxr/GHSA-mm6w-vpgv-7hxr.json +++ b/advisories/unreviewed/2024/05/GHSA-mm6w-vpgv-7hxr/GHSA-mm6w-vpgv-7hxr.json @@ -7,12 +7,8 @@ "CVE-2024-20059" ], "details": "In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541749.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json b/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json index a5656830ad9..09d809fbc94 100644 --- a/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json +++ b/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json @@ -7,12 +7,8 @@ "CVE-2023-32871" ], "details": "In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-qw4c-pw86-6rr6/GHSA-qw4c-pw86-6rr6.json b/advisories/unreviewed/2024/05/GHSA-qw4c-pw86-6rr6/GHSA-qw4c-pw86-6rr6.json index 395ba18e8aa..55331b656f8 100644 --- a/advisories/unreviewed/2024/05/GHSA-qw4c-pw86-6rr6/GHSA-qw4c-pw86-6rr6.json +++ b/advisories/unreviewed/2024/05/GHSA-qw4c-pw86-6rr6/GHSA-qw4c-pw86-6rr6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-vgpr-crmh-v58x/GHSA-vgpr-crmh-v58x.json b/advisories/unreviewed/2024/05/GHSA-vgpr-crmh-v58x/GHSA-vgpr-crmh-v58x.json index 7ce47318737..e9066c528d8 100644 --- a/advisories/unreviewed/2024/05/GHSA-vgpr-crmh-v58x/GHSA-vgpr-crmh-v58x.json +++ b/advisories/unreviewed/2024/05/GHSA-vgpr-crmh-v58x/GHSA-vgpr-crmh-v58x.json @@ -7,12 +7,8 @@ "CVE-2024-20057" ], "details": "In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-w2vp-gmjr-x26g/GHSA-w2vp-gmjr-x26g.json b/advisories/unreviewed/2024/05/GHSA-w2vp-gmjr-x26g/GHSA-w2vp-gmjr-x26g.json index 3760f13d1d2..7034ef23468 100644 --- a/advisories/unreviewed/2024/05/GHSA-w2vp-gmjr-x26g/GHSA-w2vp-gmjr-x26g.json +++ b/advisories/unreviewed/2024/05/GHSA-w2vp-gmjr-x26g/GHSA-w2vp-gmjr-x26g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",