diff --git a/advisories/github-reviewed/2022/02/GHSA-75jp-87w2-c6x2/GHSA-75jp-87w2-c6x2.json b/advisories/github-reviewed/2022/02/GHSA-75jp-87w2-c6x2/GHSA-75jp-87w2-c6x2.json index 5d0fb001960..f3a5eecdd64 100644 --- a/advisories/github-reviewed/2022/02/GHSA-75jp-87w2-c6x2/GHSA-75jp-87w2-c6x2.json +++ b/advisories/github-reviewed/2022/02/GHSA-75jp-87w2-c6x2/GHSA-75jp-87w2-c6x2.json @@ -50,9 +50,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-04-24T23:02:36Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-27v2-398x-f74x/GHSA-27v2-398x-f74x.json b/advisories/github-reviewed/2022/05/GHSA-27v2-398x-f74x/GHSA-27v2-398x-f74x.json index ed5e5085ce6..5ce6b4e1d7c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-27v2-398x-f74x/GHSA-27v2-398x-f74x.json +++ b/advisories/github-reviewed/2022/05/GHSA-27v2-398x-f74x/GHSA-27v2-398x-f74x.json @@ -8,9 +8,7 @@ ], "summary": "MAGMI cross-site scripting (XSS)", "details": "Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-2pmx-6mm6-6v72/GHSA-2pmx-6mm6-6v72.json b/advisories/github-reviewed/2022/05/GHSA-2pmx-6mm6-6v72/GHSA-2pmx-6mm6-6v72.json index df025b3bb05..d439572cfa6 100644 --- a/advisories/github-reviewed/2022/05/GHSA-2pmx-6mm6-6v72/GHSA-2pmx-6mm6-6v72.json +++ b/advisories/github-reviewed/2022/05/GHSA-2pmx-6mm6-6v72/GHSA-2pmx-6mm6-6v72.json @@ -8,9 +8,7 @@ ], "summary": "Smarty arbitrary PHP code execution", "details": "Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by \"{literal}<{/literal}script language=php>\" in a template.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-426q-975p-w5cr/GHSA-426q-975p-w5cr.json b/advisories/github-reviewed/2022/05/GHSA-426q-975p-w5cr/GHSA-426q-975p-w5cr.json index 3488b996390..88c7b72ea7c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-426q-975p-w5cr/GHSA-426q-975p-w5cr.json +++ b/advisories/github-reviewed/2022/05/GHSA-426q-975p-w5cr/GHSA-426q-975p-w5cr.json @@ -100,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-04-24T18:11:11Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-428j-q447-47rw/GHSA-428j-q447-47rw.json b/advisories/github-reviewed/2022/05/GHSA-428j-q447-47rw/GHSA-428j-q447-47rw.json index 13dbda68629..5f989ef633c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-428j-q447-47rw/GHSA-428j-q447-47rw.json +++ b/advisories/github-reviewed/2022/05/GHSA-428j-q447-47rw/GHSA-428j-q447-47rw.json @@ -8,9 +8,7 @@ ], "summary": "Apache Rave information disclosure vulnerability", "details": "The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-mhxj-6vf8-mwv3/GHSA-mhxj-6vf8-mwv3.json b/advisories/github-reviewed/2022/05/GHSA-mhxj-6vf8-mwv3/GHSA-mhxj-6vf8-mwv3.json index ddb61245709..f8c0c6605aa 100644 --- a/advisories/github-reviewed/2022/05/GHSA-mhxj-6vf8-mwv3/GHSA-mhxj-6vf8-mwv3.json +++ b/advisories/github-reviewed/2022/05/GHSA-mhxj-6vf8-mwv3/GHSA-mhxj-6vf8-mwv3.json @@ -100,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-04-24T18:10:51Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json b/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json index d24a2041a21..d2f903d51fa 100644 --- a/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json +++ b/advisories/github-reviewed/2022/05/GHSA-phhm-63xx-v9rr/GHSA-phhm-63xx-v9rr.json @@ -100,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-04-24T17:19:11Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-r326-mp8g-6xfc/GHSA-r326-mp8g-6xfc.json b/advisories/github-reviewed/2022/05/GHSA-r326-mp8g-6xfc/GHSA-r326-mp8g-6xfc.json index abeed606feb..4d6bde59649 100644 --- a/advisories/github-reviewed/2022/05/GHSA-r326-mp8g-6xfc/GHSA-r326-mp8g-6xfc.json +++ b/advisories/github-reviewed/2022/05/GHSA-r326-mp8g-6xfc/GHSA-r326-mp8g-6xfc.json @@ -100,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-04-24T17:18:03Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-rpj9-r897-wc6q/GHSA-rpj9-r897-wc6q.json b/advisories/github-reviewed/2022/05/GHSA-rpj9-r897-wc6q/GHSA-rpj9-r897-wc6q.json index 4527a42ad88..3880b172139 100644 --- a/advisories/github-reviewed/2022/05/GHSA-rpj9-r897-wc6q/GHSA-rpj9-r897-wc6q.json +++ b/advisories/github-reviewed/2022/05/GHSA-rpj9-r897-wc6q/GHSA-rpj9-r897-wc6q.json @@ -8,9 +8,7 @@ ], "summary": "Open redirect in Apache Struts", "details": "The Struts 2 DefaultActionMapper used to support a method for short-circuit navigation state changes by prefixing parameters with \"redirect:\" or \"redirectAction:\", followed by a desired redirect target expression. This mechanism was intended to help with attaching navigational information to buttons within forms. Attackers could use this to redirect to arbitrary web sites and conduct phishing attacks.\n\nIn Struts 2 before 2.3.15.1 the information following \"redirect:\" or \"redirectAction:\" can easily be manipulated to redirect to an arbitrary location.", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2022/05/GHSA-rv6m-chvv-wmxg/GHSA-rv6m-chvv-wmxg.json b/advisories/github-reviewed/2022/05/GHSA-rv6m-chvv-wmxg/GHSA-rv6m-chvv-wmxg.json index 62812f38d10..26a840fdce6 100644 --- a/advisories/github-reviewed/2022/05/GHSA-rv6m-chvv-wmxg/GHSA-rv6m-chvv-wmxg.json +++ b/advisories/github-reviewed/2022/05/GHSA-rv6m-chvv-wmxg/GHSA-rv6m-chvv-wmxg.json @@ -100,9 +100,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-04-24T18:12:25Z", diff --git a/advisories/github-reviewed/2023/10/GHSA-jq35-85cj-fj4p/GHSA-jq35-85cj-fj4p.json b/advisories/github-reviewed/2023/10/GHSA-jq35-85cj-fj4p/GHSA-jq35-85cj-fj4p.json index 261a46be524..a68c171606a 100644 --- a/advisories/github-reviewed/2023/10/GHSA-jq35-85cj-fj4p/GHSA-jq35-85cj-fj4p.json +++ b/advisories/github-reviewed/2023/10/GHSA-jq35-85cj-fj4p/GHSA-jq35-85cj-fj4p.json @@ -3,14 +3,10 @@ "id": "GHSA-jq35-85cj-fj4p", "modified": "2023-10-30T15:25:44Z", "published": "2023-10-30T15:25:44Z", - "aliases": [ - - ], + "aliases": [], "summary": "/sys/devices/virtual/powercap accessible by default to containers", "details": "Intel's RAPL (Running Average Power Limit) feature, introduced by the Sandy Bridge microarchitecture, provides software insights into hardware energy consumption. To facilitate this, Intel introduced the powercap framework in Linux kernel 3.13, which reads values via relevant MSRs (model specific registers) and provides unprivileged userspace access via `sysfs`. As RAPL is an interface to access a hardware feature, it is only available when running on bare metal with the module compiled into the kernel.\n\nBy 2019, it was realized that in some cases unprivileged access to RAPL readings could be exploited as a power-based side-channel against security features including AES-NI (potentially inside a SGX enclave) and KASLR (kernel address space layout randomization). Also known as the [PLATYPUS attack](https://platypusattack.com/), Intel assigned [CVE-2020-8694](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8694) and [CVE-2020-8695](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8695), and AMD assigned [CVE-2020-12912](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12912).\n\nSeveral mitigations were applied; Intel reduced the sampling resolution via a microcode update, and the Linux kernel [prevents access by non-root users](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=949dd0104c496fa7c14991a23c03c62e44637e71) since 5.10. However, this kernel-based mitigation does not apply to many container-based scenarios:\n* Unless using user namespaces, root inside a container has the same level of privilege as root outside the container, but with a slightly more narrow view of the system\n* `sysfs` is mounted inside containers read-only; however only read access is needed to carry out this attack on an unpatched CPU\n\nWhile this is not a direct vulnerability in container runtimes, defense in depth and safe defaults are valuable and preferred, especially as this poses a risk to multi-tenant container environments running directly on affected hardware. This is provided by masking `/sys/devices/virtual/powercap` in the default mount configuration, and adding an additional set of rules to deny it in the default AppArmor profile.\n\nWhile `sysfs` is not the only way to read from the RAPL subsystem, other ways of accessing it require additional capabilities such as `CAP_SYS_RAWIO` which is not available to containers by default, or `perf` paranoia level less than 1, which is a non-default kernel tunable.\n\n## References\n\n* https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8694\n* https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8695\n* https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12912\n* https://platypusattack.com/\n* https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=949dd0104c496fa7c14991a23c03c62e44637e71\n* https://web.eece.maine.edu/~vweaver/projects/rapl/", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -105,9 +101,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-10-30T15:25:44Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-5x4g-q5rc-36jp/GHSA-5x4g-q5rc-36jp.json b/advisories/github-reviewed/2024/02/GHSA-5x4g-q5rc-36jp/GHSA-5x4g-q5rc-36jp.json index 0041cb65b80..fefb671d7bc 100644 --- a/advisories/github-reviewed/2024/02/GHSA-5x4g-q5rc-36jp/GHSA-5x4g-q5rc-36jp.json +++ b/advisories/github-reviewed/2024/02/GHSA-5x4g-q5rc-36jp/GHSA-5x4g-q5rc-36jp.json @@ -3,14 +3,10 @@ "id": "GHSA-5x4g-q5rc-36jp", "modified": "2024-07-08T20:01:39Z", "published": "2024-02-03T00:02:58Z", - "aliases": [ - - ], + "aliases": [], "summary": "Etcd pkg Insecure ciphers are allowed by default", "details": "### Vulnerability type\nCryptography\n\n### Detail\nThe TLS ciphers list supported by etcd contains insecure cipher suites. Users can configure the desired ciphers using the “--cipher-suites” flag, and a default list of secure cipher suites is used if empty.\n\n### Workarounds\nBy default, no action is required. If users want to specify cipher suites using the '--cipher-suites' flag, they should try not to specify insecure cipher suites. Please refer to the [security documentation](https://etcd.io/docs/v3.4/op-guide/security/).\n\n### References\nFind out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/main/security/SECURITY_AUDIT.pdf)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/main/security/security-release-process.md#product-security-committee-psc)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -65,9 +61,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-02-03T00:02:58Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-j86v-2vjr-fg8f/GHSA-j86v-2vjr-fg8f.json b/advisories/github-reviewed/2024/02/GHSA-j86v-2vjr-fg8f/GHSA-j86v-2vjr-fg8f.json index a6971a8e23e..235aa5717d3 100644 --- a/advisories/github-reviewed/2024/02/GHSA-j86v-2vjr-fg8f/GHSA-j86v-2vjr-fg8f.json +++ b/advisories/github-reviewed/2024/02/GHSA-j86v-2vjr-fg8f/GHSA-j86v-2vjr-fg8f.json @@ -3,14 +3,10 @@ "id": "GHSA-j86v-2vjr-fg8f", "modified": "2024-07-08T20:02:03Z", "published": "2024-02-03T00:03:04Z", - "aliases": [ - - ], + "aliases": [], "summary": "Etcd Gateway TLS endpoint validation only confirms TCP reachability", "details": "### Vulnerability type\nCryptography\n\n### Workarounds\nRefer to the [gateway documentation](https://github.com/etcd-io/etcd/blob/master/Documentation/op-guide/gateway.md). The vulnerability was spotted due to unclear documentation of how the gateway handles endpoints validation. \n\n### Detail\nSecure endpoint validation is performed by the etcd gateway start command when the --discovery-srv flag is enabled. However, as currently implemented, it only validates TCP reachability, effectively allowing connections to an endpoint that doesn't accept TLS connections through the HTTPS URL. The auditors has noted that appropriate documentation of this validation functionality plus deprecation of this misleading functionality is an acceptable path forward.\n\n### References\nFind out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/master/security/security-release-process.md#product-security-committee-psc)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -61,9 +57,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-02-03T00:03:04Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-pm3m-32r3-7mfh/GHSA-pm3m-32r3-7mfh.json b/advisories/github-reviewed/2024/02/GHSA-pm3m-32r3-7mfh/GHSA-pm3m-32r3-7mfh.json index 73e683a99eb..6f098cf94ed 100644 --- a/advisories/github-reviewed/2024/02/GHSA-pm3m-32r3-7mfh/GHSA-pm3m-32r3-7mfh.json +++ b/advisories/github-reviewed/2024/02/GHSA-pm3m-32r3-7mfh/GHSA-pm3m-32r3-7mfh.json @@ -3,14 +3,10 @@ "id": "GHSA-pm3m-32r3-7mfh", "modified": "2024-07-08T20:02:40Z", "published": "2024-02-03T00:03:07Z", - "aliases": [ - - ], + "aliases": [], "summary": "Etcd embed auto compaction retention negative value causing a compaction loop or a crash", "details": "### Impact\nData Validation\n\n### Detail\nThe parseCompactionRetention function in embed/etcd.go allows the retention variable value to be negative and causes the node to execute the history compaction in a loop, taking more CPU than usual and spamming logs.\n\n### References\nFind out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/master/security/security-release-process.md#product-security-committee-psc)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -65,9 +61,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-02-03T00:03:07Z", diff --git a/advisories/github-reviewed/2024/02/GHSA-vjg6-93fv-qv64/GHSA-vjg6-93fv-qv64.json b/advisories/github-reviewed/2024/02/GHSA-vjg6-93fv-qv64/GHSA-vjg6-93fv-qv64.json index a28d8176753..6392d51bbea 100644 --- a/advisories/github-reviewed/2024/02/GHSA-vjg6-93fv-qv64/GHSA-vjg6-93fv-qv64.json +++ b/advisories/github-reviewed/2024/02/GHSA-vjg6-93fv-qv64/GHSA-vjg6-93fv-qv64.json @@ -3,14 +3,10 @@ "id": "GHSA-vjg6-93fv-qv64", "modified": "2024-07-08T20:02:46Z", "published": "2024-02-03T00:03:09Z", - "aliases": [ - - ], + "aliases": [], "summary": "Etcd auth Inaccurate logging of authentication attempts for users with CN-based auth only", "details": "### Vulnerability type\nLogging\n\n### Detail\netcd users who have no password can authenticate only through a client certificate. When such users try to authenticate into etcd using the Authenticate endpoint, errors are logged with insufficient information regarding why the authentication failed, and may be misleading when auditing etcd logs.\n\n### References\nFind out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/master/security/security-release-process.md#product-security-committee-psc)", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -65,9 +61,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-02-03T00:03:09Z", diff --git a/advisories/github-reviewed/2024/05/GHSA-c9cp-9c75-9v8c/GHSA-c9cp-9c75-9v8c.json b/advisories/github-reviewed/2024/05/GHSA-c9cp-9c75-9v8c/GHSA-c9cp-9c75-9v8c.json index 5eaee129aaf..7749996209a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-c9cp-9c75-9v8c/GHSA-c9cp-9c75-9v8c.json +++ b/advisories/github-reviewed/2024/05/GHSA-c9cp-9c75-9v8c/GHSA-c9cp-9c75-9v8c.json @@ -3,14 +3,10 @@ "id": "GHSA-c9cp-9c75-9v8c", "modified": "2024-07-08T12:58:29Z", "published": "2024-05-14T22:04:56Z", - "aliases": [ - - ], + "aliases": [], "summary": "containerd started with non-empty inheritable Linux process capabilities", "details": "### Impact\n\nA bug was found in containerd where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during `execve(2)`. Normally, when executable programs have specified permitted file capabilities, otherwise unprivileged users and processes can execute those programs and gain the specified file capabilities up to the bounding set. Due to this bug, containers which included executable programs with inheritable file capabilities allowed otherwise unprivileged users and processes to additionally gain these inheritable file capabilities up to the container's bounding set. Containers which use Linux users and groups to perform privilege separation inside the container are most directly impacted.\n\nThis bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set.\n\n\n### Patches\n\nThis bug has been fixed in containerd 1.5.11 and 1.6.2. Users should update to these versions as soon as possible. Running containers should be stopped, deleted, and recreated for the inheritable capabilities to be reset.\n\nThis fix changes containerd behavior such that containers are started with a more typical Linux environment. Refer to `capabilities(7)` for a description of how capabilities work. Note that permitted file capabilities continue to allow for privileges to be raised up to the container's bounding set and that processes may add capabilities to their own inheritable set up to the container's bounding set per the rules described in the manual page. In all cases the container's bounding set provides an upper bound on the capabilities that can be assumed and provides for the container security sandbox.\n\n### Workarounds\n\nThe entrypoint of a container can be modified to use a utility like `capsh(1)` to drop inheritable capabilities prior to the primary process starting.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* [Open an issue](https://github.com/containerd/containerd/issues/new)\n* Email us at [security@containerd.io](mailto:security@containerd.io) if you think you’ve found a security bug", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -66,9 +62,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-05-14T22:04:56Z", diff --git a/advisories/unreviewed/2022/01/GHSA-82rp-xg3c-hxpx/GHSA-82rp-xg3c-hxpx.json b/advisories/unreviewed/2022/01/GHSA-82rp-xg3c-hxpx/GHSA-82rp-xg3c-hxpx.json index 276821c715c..d629ae1355c 100644 --- a/advisories/unreviewed/2022/01/GHSA-82rp-xg3c-hxpx/GHSA-82rp-xg3c-hxpx.json +++ b/advisories/unreviewed/2022/01/GHSA-82rp-xg3c-hxpx/GHSA-82rp-xg3c-hxpx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-4rw9-jwmq-4v5r/GHSA-4rw9-jwmq-4v5r.json b/advisories/unreviewed/2022/02/GHSA-4rw9-jwmq-4v5r/GHSA-4rw9-jwmq-4v5r.json index fc774adf72b..77e99d07ed6 100644 --- a/advisories/unreviewed/2022/02/GHSA-4rw9-jwmq-4v5r/GHSA-4rw9-jwmq-4v5r.json +++ b/advisories/unreviewed/2022/02/GHSA-4rw9-jwmq-4v5r/GHSA-4rw9-jwmq-4v5r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/02/GHSA-9588-jwm4-r4w8/GHSA-9588-jwm4-r4w8.json b/advisories/unreviewed/2022/02/GHSA-9588-jwm4-r4w8/GHSA-9588-jwm4-r4w8.json index d82f741cd96..df9ac512caf 100644 --- a/advisories/unreviewed/2022/02/GHSA-9588-jwm4-r4w8/GHSA-9588-jwm4-r4w8.json +++ b/advisories/unreviewed/2022/02/GHSA-9588-jwm4-r4w8/GHSA-9588-jwm4-r4w8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/03/GHSA-4x8v-rchj-qvpf/GHSA-4x8v-rchj-qvpf.json b/advisories/unreviewed/2022/03/GHSA-4x8v-rchj-qvpf/GHSA-4x8v-rchj-qvpf.json index c0bfc166a11..10452d0e81e 100644 --- a/advisories/unreviewed/2022/03/GHSA-4x8v-rchj-qvpf/GHSA-4x8v-rchj-qvpf.json +++ b/advisories/unreviewed/2022/03/GHSA-4x8v-rchj-qvpf/GHSA-4x8v-rchj-qvpf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-4r7g-fj95-jwpc/GHSA-4r7g-fj95-jwpc.json b/advisories/unreviewed/2022/04/GHSA-4r7g-fj95-jwpc/GHSA-4r7g-fj95-jwpc.json index 3c826b255eb..47fc803fff7 100644 --- a/advisories/unreviewed/2022/04/GHSA-4r7g-fj95-jwpc/GHSA-4r7g-fj95-jwpc.json +++ b/advisories/unreviewed/2022/04/GHSA-4r7g-fj95-jwpc/GHSA-4r7g-fj95-jwpc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-rmwm-c9cm-59pw/GHSA-rmwm-c9cm-59pw.json b/advisories/unreviewed/2022/04/GHSA-rmwm-c9cm-59pw/GHSA-rmwm-c9cm-59pw.json index 29ccb0fd7f2..f84a19366cb 100644 --- a/advisories/unreviewed/2022/04/GHSA-rmwm-c9cm-59pw/GHSA-rmwm-c9cm-59pw.json +++ b/advisories/unreviewed/2022/04/GHSA-rmwm-c9cm-59pw/GHSA-rmwm-c9cm-59pw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/04/GHSA-v3g6-gh83-x752/GHSA-v3g6-gh83-x752.json b/advisories/unreviewed/2022/04/GHSA-v3g6-gh83-x752/GHSA-v3g6-gh83-x752.json index 034c212fed4..7285df03a51 100644 --- a/advisories/unreviewed/2022/04/GHSA-v3g6-gh83-x752/GHSA-v3g6-gh83-x752.json +++ b/advisories/unreviewed/2022/04/GHSA-v3g6-gh83-x752/GHSA-v3g6-gh83-x752.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2252-2x7m-w7r8/GHSA-2252-2x7m-w7r8.json b/advisories/unreviewed/2022/05/GHSA-2252-2x7m-w7r8/GHSA-2252-2x7m-w7r8.json index 22f68ba46e2..14b2d6c205b 100644 --- a/advisories/unreviewed/2022/05/GHSA-2252-2x7m-w7r8/GHSA-2252-2x7m-w7r8.json +++ b/advisories/unreviewed/2022/05/GHSA-2252-2x7m-w7r8/GHSA-2252-2x7m-w7r8.json @@ -7,12 +7,8 @@ "CVE-2013-6836" ], "details": "Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-228w-77f7-j98f/GHSA-228w-77f7-j98f.json b/advisories/unreviewed/2022/05/GHSA-228w-77f7-j98f/GHSA-228w-77f7-j98f.json index 67a2c58cfca..e04ba1a2258 100644 --- a/advisories/unreviewed/2022/05/GHSA-228w-77f7-j98f/GHSA-228w-77f7-j98f.json +++ b/advisories/unreviewed/2022/05/GHSA-228w-77f7-j98f/GHSA-228w-77f7-j98f.json @@ -7,12 +7,8 @@ "CVE-2015-3664" ], "details": "QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3665 and CVE-2015-3669.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2426-hmrr-whfq/GHSA-2426-hmrr-whfq.json b/advisories/unreviewed/2022/05/GHSA-2426-hmrr-whfq/GHSA-2426-hmrr-whfq.json index e6be9e8240d..f4faff036ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-2426-hmrr-whfq/GHSA-2426-hmrr-whfq.json +++ b/advisories/unreviewed/2022/05/GHSA-2426-hmrr-whfq/GHSA-2426-hmrr-whfq.json @@ -7,12 +7,8 @@ "CVE-2015-4240" ], "details": "Cisco IP Communicator 8.6(4) allows remote attackers to cause a denial of service (service outage) via an unspecified URL in a GET request, aka Bug ID CSCuu37656.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-24vq-hqp2-48h9/GHSA-24vq-hqp2-48h9.json b/advisories/unreviewed/2022/05/GHSA-24vq-hqp2-48h9/GHSA-24vq-hqp2-48h9.json index b95419b9f9b..410efad2553 100644 --- a/advisories/unreviewed/2022/05/GHSA-24vq-hqp2-48h9/GHSA-24vq-hqp2-48h9.json +++ b/advisories/unreviewed/2022/05/GHSA-24vq-hqp2-48h9/GHSA-24vq-hqp2-48h9.json @@ -7,12 +7,8 @@ "CVE-2015-2572" ], "details": "Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and earlier, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25j4-vg62-44m4/GHSA-25j4-vg62-44m4.json b/advisories/unreviewed/2022/05/GHSA-25j4-vg62-44m4/GHSA-25j4-vg62-44m4.json index 894c5d103b7..615eb5de14a 100644 --- a/advisories/unreviewed/2022/05/GHSA-25j4-vg62-44m4/GHSA-25j4-vg62-44m4.json +++ b/advisories/unreviewed/2022/05/GHSA-25j4-vg62-44m4/GHSA-25j4-vg62-44m4.json @@ -7,12 +7,8 @@ "CVE-2015-7863" ], "details": "The default configuration of Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 enables a remote Notify capability without the Extended Notify Security features, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-25jr-qm4x-mvhx/GHSA-25jr-qm4x-mvhx.json b/advisories/unreviewed/2022/05/GHSA-25jr-qm4x-mvhx/GHSA-25jr-qm4x-mvhx.json index acc4a4a4fca..7a1f4d784f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-25jr-qm4x-mvhx/GHSA-25jr-qm4x-mvhx.json +++ b/advisories/unreviewed/2022/05/GHSA-25jr-qm4x-mvhx/GHSA-25jr-qm4x-mvhx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26q8-whgc-65w9/GHSA-26q8-whgc-65w9.json b/advisories/unreviewed/2022/05/GHSA-26q8-whgc-65w9/GHSA-26q8-whgc-65w9.json index d96c2e4c894..af65063b829 100644 --- a/advisories/unreviewed/2022/05/GHSA-26q8-whgc-65w9/GHSA-26q8-whgc-65w9.json +++ b/advisories/unreviewed/2022/05/GHSA-26q8-whgc-65w9/GHSA-26q8-whgc-65w9.json @@ -7,12 +7,8 @@ "CVE-2015-1240" ], "details": "gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-26wc-fvf8-2rgq/GHSA-26wc-fvf8-2rgq.json b/advisories/unreviewed/2022/05/GHSA-26wc-fvf8-2rgq/GHSA-26wc-fvf8-2rgq.json index 198e31df151..cf60f9644e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-26wc-fvf8-2rgq/GHSA-26wc-fvf8-2rgq.json +++ b/advisories/unreviewed/2022/05/GHSA-26wc-fvf8-2rgq/GHSA-26wc-fvf8-2rgq.json @@ -7,12 +7,8 @@ "CVE-2008-3527" ], "details": "arch/i386/kernel/sysenter.c in the Virtual Dynamic Shared Objects (vDSO) implementation in the Linux kernel before 2.6.21 does not properly check boundaries, which allows local users to gain privileges or cause a denial of service via unspecified vectors, related to the install_special_mapping, syscall, and syscall32_nopage functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-27r8-6jpp-p76v/GHSA-27r8-6jpp-p76v.json b/advisories/unreviewed/2022/05/GHSA-27r8-6jpp-p76v/GHSA-27r8-6jpp-p76v.json index 97a30b8d9a1..52a44a08bf7 100644 --- a/advisories/unreviewed/2022/05/GHSA-27r8-6jpp-p76v/GHSA-27r8-6jpp-p76v.json +++ b/advisories/unreviewed/2022/05/GHSA-27r8-6jpp-p76v/GHSA-27r8-6jpp-p76v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-289g-9r5p-5m9c/GHSA-289g-9r5p-5m9c.json b/advisories/unreviewed/2022/05/GHSA-289g-9r5p-5m9c/GHSA-289g-9r5p-5m9c.json index b828088f8bc..8e5230b8f0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-289g-9r5p-5m9c/GHSA-289g-9r5p-5m9c.json +++ b/advisories/unreviewed/2022/05/GHSA-289g-9r5p-5m9c/GHSA-289g-9r5p-5m9c.json @@ -7,12 +7,8 @@ "CVE-2015-7030" ], "details": "The Swift implementation in Apple Xcode before 7.1 mishandles type conversion, which has unspecified impact and attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28h9-5x3g-w7q9/GHSA-28h9-5x3g-w7q9.json b/advisories/unreviewed/2022/05/GHSA-28h9-5x3g-w7q9/GHSA-28h9-5x3g-w7q9.json index 7a6c0eb479a..fd3fb0f248f 100644 --- a/advisories/unreviewed/2022/05/GHSA-28h9-5x3g-w7q9/GHSA-28h9-5x3g-w7q9.json +++ b/advisories/unreviewed/2022/05/GHSA-28h9-5x3g-w7q9/GHSA-28h9-5x3g-w7q9.json @@ -7,12 +7,8 @@ "CVE-2005-3356" ], "details": "The mq_open system call in Linux kernel 2.6.9, in certain situations, can decrement a counter twice (\"double decrement\") as a result of multiple calls to the mntput function when the dentry_open function call fails, which allows local users to cause a denial of service (panic) via unspecified attack vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-28x7-5mgh-vp76/GHSA-28x7-5mgh-vp76.json b/advisories/unreviewed/2022/05/GHSA-28x7-5mgh-vp76/GHSA-28x7-5mgh-vp76.json index a956051a7a4..ae56c5678d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-28x7-5mgh-vp76/GHSA-28x7-5mgh-vp76.json +++ b/advisories/unreviewed/2022/05/GHSA-28x7-5mgh-vp76/GHSA-28x7-5mgh-vp76.json @@ -7,12 +7,8 @@ "CVE-2015-4205" ], "details": "Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x flow-control PAUSE frames on the local network, aka Bug ID CSCut19959.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2948-rrxj-6qwq/GHSA-2948-rrxj-6qwq.json b/advisories/unreviewed/2022/05/GHSA-2948-rrxj-6qwq/GHSA-2948-rrxj-6qwq.json index 1d314128a32..ae9543c3041 100644 --- a/advisories/unreviewed/2022/05/GHSA-2948-rrxj-6qwq/GHSA-2948-rrxj-6qwq.json +++ b/advisories/unreviewed/2022/05/GHSA-2948-rrxj-6qwq/GHSA-2948-rrxj-6qwq.json @@ -7,12 +7,8 @@ "CVE-2015-6288" ], "details": "Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote attackers to cause a denial of service (rapid log-file rollover and application fault) via crafted HTTP requests, aka Bug ID CSCuw09620.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-29m8-82c7-qqgx/GHSA-29m8-82c7-qqgx.json b/advisories/unreviewed/2022/05/GHSA-29m8-82c7-qqgx/GHSA-29m8-82c7-qqgx.json index 09fbe21b6f9..ad082efae7a 100644 --- a/advisories/unreviewed/2022/05/GHSA-29m8-82c7-qqgx/GHSA-29m8-82c7-qqgx.json +++ b/advisories/unreviewed/2022/05/GHSA-29m8-82c7-qqgx/GHSA-29m8-82c7-qqgx.json @@ -7,12 +7,8 @@ "CVE-2013-7175" ], "details": "Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-29wc-g5r8-4r3v/GHSA-29wc-g5r8-4r3v.json b/advisories/unreviewed/2022/05/GHSA-29wc-g5r8-4r3v/GHSA-29wc-g5r8-4r3v.json index 1d822751c03..5e5423914be 100644 --- a/advisories/unreviewed/2022/05/GHSA-29wc-g5r8-4r3v/GHSA-29wc-g5r8-4r3v.json +++ b/advisories/unreviewed/2022/05/GHSA-29wc-g5r8-4r3v/GHSA-29wc-g5r8-4r3v.json @@ -7,12 +7,8 @@ "CVE-2015-5924" ], "details": "The OpenGL implementation in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2f8w-w2fc-fv9w/GHSA-2f8w-w2fc-fv9w.json b/advisories/unreviewed/2022/05/GHSA-2f8w-w2fc-fv9w/GHSA-2f8w-w2fc-fv9w.json index ef939d5cb3b..b8286b7b309 100644 --- a/advisories/unreviewed/2022/05/GHSA-2f8w-w2fc-fv9w/GHSA-2f8w-w2fc-fv9w.json +++ b/advisories/unreviewed/2022/05/GHSA-2f8w-w2fc-fv9w/GHSA-2f8w-w2fc-fv9w.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fg2-cvw6-w6w2/GHSA-2fg2-cvw6-w6w2.json b/advisories/unreviewed/2022/05/GHSA-2fg2-cvw6-w6w2/GHSA-2fg2-cvw6-w6w2.json index a68fef4b78a..64a55e2d58c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fg2-cvw6-w6w2/GHSA-2fg2-cvw6-w6w2.json +++ b/advisories/unreviewed/2022/05/GHSA-2fg2-cvw6-w6w2/GHSA-2fg2-cvw6-w6w2.json @@ -7,12 +7,8 @@ "CVE-2015-3293" ], "details": "FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the \"diag debug application httpd\" command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fg8-h8hj-9h3c/GHSA-2fg8-h8hj-9h3c.json b/advisories/unreviewed/2022/05/GHSA-2fg8-h8hj-9h3c/GHSA-2fg8-h8hj-9h3c.json index a68cd6aaeb2..083763caa0f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fg8-h8hj-9h3c/GHSA-2fg8-h8hj-9h3c.json +++ b/advisories/unreviewed/2022/05/GHSA-2fg8-h8hj-9h3c/GHSA-2fg8-h8hj-9h3c.json @@ -7,12 +7,8 @@ "CVE-2015-4233" ], "details": "SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu54037.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2fw2-hj8q-m4ff/GHSA-2fw2-hj8q-m4ff.json b/advisories/unreviewed/2022/05/GHSA-2fw2-hj8q-m4ff/GHSA-2fw2-hj8q-m4ff.json index 03cd8364cff..910716ae9c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-2fw2-hj8q-m4ff/GHSA-2fw2-hj8q-m4ff.json +++ b/advisories/unreviewed/2022/05/GHSA-2fw2-hj8q-m4ff/GHSA-2fw2-hj8q-m4ff.json @@ -7,12 +7,8 @@ "CVE-2015-4298" ], "details": "Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2g6h-x254-rxr5/GHSA-2g6h-x254-rxr5.json b/advisories/unreviewed/2022/05/GHSA-2g6h-x254-rxr5/GHSA-2g6h-x254-rxr5.json index 15eda16ffb2..1a395eb9085 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g6h-x254-rxr5/GHSA-2g6h-x254-rxr5.json +++ b/advisories/unreviewed/2022/05/GHSA-2g6h-x254-rxr5/GHSA-2g6h-x254-rxr5.json @@ -7,12 +7,8 @@ "CVE-2015-4197" ], "details": "Cisco NX-OS 5.2(5) on Nexus 7000 devices allows remote attackers to cause a denial of service (device crash) by sending a malformed LLDP packet on the local network, aka Bug ID CSCud89415.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2gx2-9hj7-p6pc/GHSA-2gx2-9hj7-p6pc.json b/advisories/unreviewed/2022/05/GHSA-2gx2-9hj7-p6pc/GHSA-2gx2-9hj7-p6pc.json index 15b7666e15d..5fbd7b0bfa7 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gx2-9hj7-p6pc/GHSA-2gx2-9hj7-p6pc.json +++ b/advisories/unreviewed/2022/05/GHSA-2gx2-9hj7-p6pc/GHSA-2gx2-9hj7-p6pc.json @@ -7,12 +7,8 @@ "CVE-2014-9200" ], "details": "Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB TCP/SL), Advantys DTM for OTB, Advantys DTM for STB, KINOS DTM, SOLO DTM, and Xantrex DTMs allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2h8j-xgvj-94wp/GHSA-2h8j-xgvj-94wp.json b/advisories/unreviewed/2022/05/GHSA-2h8j-xgvj-94wp/GHSA-2h8j-xgvj-94wp.json index babb5fecb32..82991c61ec7 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h8j-xgvj-94wp/GHSA-2h8j-xgvj-94wp.json +++ b/advisories/unreviewed/2022/05/GHSA-2h8j-xgvj-94wp/GHSA-2h8j-xgvj-94wp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2hc3-38qf-h9pv/GHSA-2hc3-38qf-h9pv.json b/advisories/unreviewed/2022/05/GHSA-2hc3-38qf-h9pv/GHSA-2hc3-38qf-h9pv.json index 6921a7f2af8..6d287f9fe31 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hc3-38qf-h9pv/GHSA-2hc3-38qf-h9pv.json +++ b/advisories/unreviewed/2022/05/GHSA-2hc3-38qf-h9pv/GHSA-2hc3-38qf-h9pv.json @@ -7,12 +7,8 @@ "CVE-2015-0426" ], "details": "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.3 and 12.1.0.4 allows remote attackers to affect confidentiality via unknown vectors related to UI Framework.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2j38-xhmg-c3g9/GHSA-2j38-xhmg-c3g9.json b/advisories/unreviewed/2022/05/GHSA-2j38-xhmg-c3g9/GHSA-2j38-xhmg-c3g9.json index 408b1616590..e100ca7fd1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-2j38-xhmg-c3g9/GHSA-2j38-xhmg-c3g9.json +++ b/advisories/unreviewed/2022/05/GHSA-2j38-xhmg-c3g9/GHSA-2j38-xhmg-c3g9.json @@ -7,12 +7,8 @@ "CVE-2013-6475" ], "details": "Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2jrv-628r-r64r/GHSA-2jrv-628r-r64r.json b/advisories/unreviewed/2022/05/GHSA-2jrv-628r-r64r/GHSA-2jrv-628r-r64r.json index 964a3449ae4..49067ef50d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-2jrv-628r-r64r/GHSA-2jrv-628r-r64r.json +++ b/advisories/unreviewed/2022/05/GHSA-2jrv-628r-r64r/GHSA-2jrv-628r-r64r.json @@ -7,12 +7,8 @@ "CVE-2015-2829" ], "details": "Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2mm4-937r-5vgh/GHSA-2mm4-937r-5vgh.json b/advisories/unreviewed/2022/05/GHSA-2mm4-937r-5vgh/GHSA-2mm4-937r-5vgh.json index 9bf20e8316c..ebf2381dd40 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mm4-937r-5vgh/GHSA-2mm4-937r-5vgh.json +++ b/advisories/unreviewed/2022/05/GHSA-2mm4-937r-5vgh/GHSA-2mm4-937r-5vgh.json @@ -7,12 +7,8 @@ "CVE-2015-4241" ], "details": "Cisco Adaptive Security Appliance (ASA) Software 9.3(2) allows remote attackers to cause a denial of service (system reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCut52679.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2qqr-78hq-cvh8/GHSA-2qqr-78hq-cvh8.json b/advisories/unreviewed/2022/05/GHSA-2qqr-78hq-cvh8/GHSA-2qqr-78hq-cvh8.json index d014cb1d947..5321b729b98 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qqr-78hq-cvh8/GHSA-2qqr-78hq-cvh8.json +++ b/advisories/unreviewed/2022/05/GHSA-2qqr-78hq-cvh8/GHSA-2qqr-78hq-cvh8.json @@ -7,12 +7,8 @@ "CVE-2013-4234" ], "details": "Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted ABC.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2qxm-84pw-9jpr/GHSA-2qxm-84pw-9jpr.json b/advisories/unreviewed/2022/05/GHSA-2qxm-84pw-9jpr/GHSA-2qxm-84pw-9jpr.json index 92ca52fb808..0c710b95a9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2qxm-84pw-9jpr/GHSA-2qxm-84pw-9jpr.json +++ b/advisories/unreviewed/2022/05/GHSA-2qxm-84pw-9jpr/GHSA-2qxm-84pw-9jpr.json @@ -7,12 +7,8 @@ "CVE-2015-0487" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2015-0472.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2rjf-grmv-wrvv/GHSA-2rjf-grmv-wrvv.json b/advisories/unreviewed/2022/05/GHSA-2rjf-grmv-wrvv/GHSA-2rjf-grmv-wrvv.json index f17371f69ce..5359680c711 100644 --- a/advisories/unreviewed/2022/05/GHSA-2rjf-grmv-wrvv/GHSA-2rjf-grmv-wrvv.json +++ b/advisories/unreviewed/2022/05/GHSA-2rjf-grmv-wrvv/GHSA-2rjf-grmv-wrvv.json @@ -7,12 +7,8 @@ "CVE-2015-4255" ], "details": "Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP Gateway devices with software 2.0(3.34) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90734.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2v77-g7rx-9jjr/GHSA-2v77-g7rx-9jjr.json b/advisories/unreviewed/2022/05/GHSA-2v77-g7rx-9jjr/GHSA-2v77-g7rx-9jjr.json index 47c24531802..6e67a9932a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-2v77-g7rx-9jjr/GHSA-2v77-g7rx-9jjr.json +++ b/advisories/unreviewed/2022/05/GHSA-2v77-g7rx-9jjr/GHSA-2v77-g7rx-9jjr.json @@ -7,12 +7,8 @@ "CVE-2015-0399" ], "details": "Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 10.1.3.4.2 and 11.1.1.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Analytics Web General.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2w2h-3v4h-88j6/GHSA-2w2h-3v4h-88j6.json b/advisories/unreviewed/2022/05/GHSA-2w2h-3v4h-88j6/GHSA-2w2h-3v4h-88j6.json index 70fe7a2fd0c..f327f02252f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2w2h-3v4h-88j6/GHSA-2w2h-3v4h-88j6.json +++ b/advisories/unreviewed/2022/05/GHSA-2w2h-3v4h-88j6/GHSA-2w2h-3v4h-88j6.json @@ -7,12 +7,8 @@ "CVE-2015-4222" ], "details": "SQL injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq46325.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2wpc-7vw8-rm2x/GHSA-2wpc-7vw8-rm2x.json b/advisories/unreviewed/2022/05/GHSA-2wpc-7vw8-rm2x/GHSA-2wpc-7vw8-rm2x.json index 1bb3f9f7af2..099222e397a 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wpc-7vw8-rm2x/GHSA-2wpc-7vw8-rm2x.json +++ b/advisories/unreviewed/2022/05/GHSA-2wpc-7vw8-rm2x/GHSA-2wpc-7vw8-rm2x.json @@ -7,12 +7,8 @@ "CVE-2015-2733" ], "details": "Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2x32-fffh-53mr/GHSA-2x32-fffh-53mr.json b/advisories/unreviewed/2022/05/GHSA-2x32-fffh-53mr/GHSA-2x32-fffh-53mr.json index cc5378460b2..49cf8e2111c 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x32-fffh-53mr/GHSA-2x32-fffh-53mr.json +++ b/advisories/unreviewed/2022/05/GHSA-2x32-fffh-53mr/GHSA-2x32-fffh-53mr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2x97-vvh4-m4q4/GHSA-2x97-vvh4-m4q4.json b/advisories/unreviewed/2022/05/GHSA-2x97-vvh4-m4q4/GHSA-2x97-vvh4-m4q4.json index 6f334dedc8a..e40edf5dece 100644 --- a/advisories/unreviewed/2022/05/GHSA-2x97-vvh4-m4q4/GHSA-2x97-vvh4-m4q4.json +++ b/advisories/unreviewed/2022/05/GHSA-2x97-vvh4-m4q4/GHSA-2x97-vvh4-m4q4.json @@ -7,12 +7,8 @@ "CVE-2014-8090" ], "details": "The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2xj4-744c-pqqp/GHSA-2xj4-744c-pqqp.json b/advisories/unreviewed/2022/05/GHSA-2xj4-744c-pqqp/GHSA-2xj4-744c-pqqp.json index 2a00f490906..f0ba8742406 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xj4-744c-pqqp/GHSA-2xj4-744c-pqqp.json +++ b/advisories/unreviewed/2022/05/GHSA-2xj4-744c-pqqp/GHSA-2xj4-744c-pqqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-2xpv-7mpx-xj47/GHSA-2xpv-7mpx-xj47.json b/advisories/unreviewed/2022/05/GHSA-2xpv-7mpx-xj47/GHSA-2xpv-7mpx-xj47.json index 1f66e802907..06134c693f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-2xpv-7mpx-xj47/GHSA-2xpv-7mpx-xj47.json +++ b/advisories/unreviewed/2022/05/GHSA-2xpv-7mpx-xj47/GHSA-2xpv-7mpx-xj47.json @@ -7,12 +7,8 @@ "CVE-2015-7018" ], "details": "FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7010.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-32wf-3wxg-68pf/GHSA-32wf-3wxg-68pf.json b/advisories/unreviewed/2022/05/GHSA-32wf-3wxg-68pf/GHSA-32wf-3wxg-68pf.json index 0ac47661c10..8d94f89c051 100644 --- a/advisories/unreviewed/2022/05/GHSA-32wf-3wxg-68pf/GHSA-32wf-3wxg-68pf.json +++ b/advisories/unreviewed/2022/05/GHSA-32wf-3wxg-68pf/GHSA-32wf-3wxg-68pf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-334x-r396-c494/GHSA-334x-r396-c494.json b/advisories/unreviewed/2022/05/GHSA-334x-r396-c494/GHSA-334x-r396-c494.json index af89717a35e..a20aaa2abf8 100644 --- a/advisories/unreviewed/2022/05/GHSA-334x-r396-c494/GHSA-334x-r396-c494.json +++ b/advisories/unreviewed/2022/05/GHSA-334x-r396-c494/GHSA-334x-r396-c494.json @@ -7,12 +7,8 @@ "CVE-2015-1087" ], "details": "Directory traversal vulnerability in Backup in Apple iOS before 8.3 allows attackers to read arbitrary files via a crafted relative path.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3385-jf4c-9xpg/GHSA-3385-jf4c-9xpg.json b/advisories/unreviewed/2022/05/GHSA-3385-jf4c-9xpg/GHSA-3385-jf4c-9xpg.json index 4736f4874ec..f79c71f9cd8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3385-jf4c-9xpg/GHSA-3385-jf4c-9xpg.json +++ b/advisories/unreviewed/2022/05/GHSA-3385-jf4c-9xpg/GHSA-3385-jf4c-9xpg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33c3-x8f5-62m8/GHSA-33c3-x8f5-62m8.json b/advisories/unreviewed/2022/05/GHSA-33c3-x8f5-62m8/GHSA-33c3-x8f5-62m8.json index 37142f9449b..54ea7466d84 100644 --- a/advisories/unreviewed/2022/05/GHSA-33c3-x8f5-62m8/GHSA-33c3-x8f5-62m8.json +++ b/advisories/unreviewed/2022/05/GHSA-33c3-x8f5-62m8/GHSA-33c3-x8f5-62m8.json @@ -7,12 +7,8 @@ "CVE-2014-9388" ], "details": "bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33cg-4pq4-gv4q/GHSA-33cg-4pq4-gv4q.json b/advisories/unreviewed/2022/05/GHSA-33cg-4pq4-gv4q/GHSA-33cg-4pq4-gv4q.json index 6fc1e6f1ae8..3c4c1ad72d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-33cg-4pq4-gv4q/GHSA-33cg-4pq4-gv4q.json +++ b/advisories/unreviewed/2022/05/GHSA-33cg-4pq4-gv4q/GHSA-33cg-4pq4-gv4q.json @@ -7,12 +7,8 @@ "CVE-2015-1884" ], "details": "Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via a crafted internationalization-file URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33jh-9x8q-p7j7/GHSA-33jh-9x8q-p7j7.json b/advisories/unreviewed/2022/05/GHSA-33jh-9x8q-p7j7/GHSA-33jh-9x8q-p7j7.json index c1f863031ba..e80ec01ed66 100644 --- a/advisories/unreviewed/2022/05/GHSA-33jh-9x8q-p7j7/GHSA-33jh-9x8q-p7j7.json +++ b/advisories/unreviewed/2022/05/GHSA-33jh-9x8q-p7j7/GHSA-33jh-9x8q-p7j7.json @@ -7,12 +7,8 @@ "CVE-2015-4263" ], "details": "The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-33mf-x5r5-qqmj/GHSA-33mf-x5r5-qqmj.json b/advisories/unreviewed/2022/05/GHSA-33mf-x5r5-qqmj/GHSA-33mf-x5r5-qqmj.json index 8ba4c93031f..143e224bd55 100644 --- a/advisories/unreviewed/2022/05/GHSA-33mf-x5r5-qqmj/GHSA-33mf-x5r5-qqmj.json +++ b/advisories/unreviewed/2022/05/GHSA-33mf-x5r5-qqmj/GHSA-33mf-x5r5-qqmj.json @@ -7,12 +7,8 @@ "CVE-2015-2338" ], "details": "TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2339.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3422-45qx-4m3x/GHSA-3422-45qx-4m3x.json b/advisories/unreviewed/2022/05/GHSA-3422-45qx-4m3x/GHSA-3422-45qx-4m3x.json index f32fce6874f..8cbcb3ab66f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3422-45qx-4m3x/GHSA-3422-45qx-4m3x.json +++ b/advisories/unreviewed/2022/05/GHSA-3422-45qx-4m3x/GHSA-3422-45qx-4m3x.json @@ -7,12 +7,8 @@ "CVE-2015-4199" ], "details": "Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity with many IPv6 CPE devices, aka Bug ID CSCug47366.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3464-vj4m-jgvg/GHSA-3464-vj4m-jgvg.json b/advisories/unreviewed/2022/05/GHSA-3464-vj4m-jgvg/GHSA-3464-vj4m-jgvg.json index 315106afbaf..1b2049834d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-3464-vj4m-jgvg/GHSA-3464-vj4m-jgvg.json +++ b/advisories/unreviewed/2022/05/GHSA-3464-vj4m-jgvg/GHSA-3464-vj4m-jgvg.json @@ -7,12 +7,8 @@ "CVE-2015-3910" ], "details": "Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before 43.0.2357.65, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-358j-r7c8-3h2p/GHSA-358j-r7c8-3h2p.json b/advisories/unreviewed/2022/05/GHSA-358j-r7c8-3h2p/GHSA-358j-r7c8-3h2p.json index 616e326b34a..36713fa418b 100644 --- a/advisories/unreviewed/2022/05/GHSA-358j-r7c8-3h2p/GHSA-358j-r7c8-3h2p.json +++ b/advisories/unreviewed/2022/05/GHSA-358j-r7c8-3h2p/GHSA-358j-r7c8-3h2p.json @@ -7,12 +7,8 @@ "CVE-2015-5937" ], "details": "ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5936, and CVE-2015-5939.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3598-jrjv-4569/GHSA-3598-jrjv-4569.json b/advisories/unreviewed/2022/05/GHSA-3598-jrjv-4569/GHSA-3598-jrjv-4569.json index 0992df03e3a..5cb66dcbba1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3598-jrjv-4569/GHSA-3598-jrjv-4569.json +++ b/advisories/unreviewed/2022/05/GHSA-3598-jrjv-4569/GHSA-3598-jrjv-4569.json @@ -7,12 +7,8 @@ "CVE-2015-0496" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect confidentiality via vectors related to PIA Search Functionality.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3767-mgp7-mj5m/GHSA-3767-mgp7-mj5m.json b/advisories/unreviewed/2022/05/GHSA-3767-mgp7-mj5m/GHSA-3767-mgp7-mj5m.json index 13de32e492e..ced5b8af953 100644 --- a/advisories/unreviewed/2022/05/GHSA-3767-mgp7-mj5m/GHSA-3767-mgp7-mj5m.json +++ b/advisories/unreviewed/2022/05/GHSA-3767-mgp7-mj5m/GHSA-3767-mgp7-mj5m.json @@ -7,12 +7,8 @@ "CVE-2015-0420" ], "details": "Unspecified vulnerability in the Oracle Forms component in Oracle Fusion Middleware 11.1.1.7 and 11.1.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Forms Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-377x-m9rv-682v/GHSA-377x-m9rv-682v.json b/advisories/unreviewed/2022/05/GHSA-377x-m9rv-682v/GHSA-377x-m9rv-682v.json index 1a82359a8cc..269d7a848b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-377x-m9rv-682v/GHSA-377x-m9rv-682v.json +++ b/advisories/unreviewed/2022/05/GHSA-377x-m9rv-682v/GHSA-377x-m9rv-682v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37r6-5w46-7pp7/GHSA-37r6-5w46-7pp7.json b/advisories/unreviewed/2022/05/GHSA-37r6-5w46-7pp7/GHSA-37r6-5w46-7pp7.json index f092dae4563..11334515498 100644 --- a/advisories/unreviewed/2022/05/GHSA-37r6-5w46-7pp7/GHSA-37r6-5w46-7pp7.json +++ b/advisories/unreviewed/2022/05/GHSA-37r6-5w46-7pp7/GHSA-37r6-5w46-7pp7.json @@ -7,12 +7,8 @@ "CVE-2015-2337" ], "details": "TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-37rg-pmjm-jjg7/GHSA-37rg-pmjm-jjg7.json b/advisories/unreviewed/2022/05/GHSA-37rg-pmjm-jjg7/GHSA-37rg-pmjm-jjg7.json index cbb16e3823a..de0dec34c4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-37rg-pmjm-jjg7/GHSA-37rg-pmjm-jjg7.json +++ b/advisories/unreviewed/2022/05/GHSA-37rg-pmjm-jjg7/GHSA-37rg-pmjm-jjg7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-37rg-q6m8-6h7g/GHSA-37rg-q6m8-6h7g.json b/advisories/unreviewed/2022/05/GHSA-37rg-q6m8-6h7g/GHSA-37rg-q6m8-6h7g.json index 78d16d95cdc..391f64d943e 100644 --- a/advisories/unreviewed/2022/05/GHSA-37rg-q6m8-6h7g/GHSA-37rg-q6m8-6h7g.json +++ b/advisories/unreviewed/2022/05/GHSA-37rg-q6m8-6h7g/GHSA-37rg-q6m8-6h7g.json @@ -7,12 +7,8 @@ "CVE-2015-4225" ], "details": "Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-383x-88fc-ggcf/GHSA-383x-88fc-ggcf.json b/advisories/unreviewed/2022/05/GHSA-383x-88fc-ggcf/GHSA-383x-88fc-ggcf.json index 84a353b9163..3988876c832 100644 --- a/advisories/unreviewed/2022/05/GHSA-383x-88fc-ggcf/GHSA-383x-88fc-ggcf.json +++ b/advisories/unreviewed/2022/05/GHSA-383x-88fc-ggcf/GHSA-383x-88fc-ggcf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3874-c4vv-qxvf/GHSA-3874-c4vv-qxvf.json b/advisories/unreviewed/2022/05/GHSA-3874-c4vv-qxvf/GHSA-3874-c4vv-qxvf.json index f947166f592..5b823880224 100644 --- a/advisories/unreviewed/2022/05/GHSA-3874-c4vv-qxvf/GHSA-3874-c4vv-qxvf.json +++ b/advisories/unreviewed/2022/05/GHSA-3874-c4vv-qxvf/GHSA-3874-c4vv-qxvf.json @@ -7,12 +7,8 @@ "CVE-2015-3660" ], "details": "Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-38jx-wppr-r4q4/GHSA-38jx-wppr-r4q4.json b/advisories/unreviewed/2022/05/GHSA-38jx-wppr-r4q4/GHSA-38jx-wppr-r4q4.json index 9470eff55ec..56355b295c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-38jx-wppr-r4q4/GHSA-38jx-wppr-r4q4.json +++ b/advisories/unreviewed/2022/05/GHSA-38jx-wppr-r4q4/GHSA-38jx-wppr-r4q4.json @@ -7,12 +7,8 @@ "CVE-2014-6489" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect integrity and availability via vectors related to SERVER:SP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3c9q-w3p6-49h3/GHSA-3c9q-w3p6-49h3.json b/advisories/unreviewed/2022/05/GHSA-3c9q-w3p6-49h3/GHSA-3c9q-w3p6-49h3.json index 2aa11707ecd..2a7edae5c21 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c9q-w3p6-49h3/GHSA-3c9q-w3p6-49h3.json +++ b/advisories/unreviewed/2022/05/GHSA-3c9q-w3p6-49h3/GHSA-3c9q-w3p6-49h3.json @@ -7,12 +7,8 @@ "CVE-2015-0509" ], "details": "Unspecified vulnerability in the Oracle Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to Reporting and Analysis.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3cv5-693m-8vg4/GHSA-3cv5-693m-8vg4.json b/advisories/unreviewed/2022/05/GHSA-3cv5-693m-8vg4/GHSA-3cv5-693m-8vg4.json index 82c27e9e4fc..f3b004999b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cv5-693m-8vg4/GHSA-3cv5-693m-8vg4.json +++ b/advisories/unreviewed/2022/05/GHSA-3cv5-693m-8vg4/GHSA-3cv5-693m-8vg4.json @@ -7,12 +7,8 @@ "CVE-2015-4195" ], "details": "Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3f5r-8cpv-jgc3/GHSA-3f5r-8cpv-jgc3.json b/advisories/unreviewed/2022/05/GHSA-3f5r-8cpv-jgc3/GHSA-3f5r-8cpv-jgc3.json index fafd0b88be5..94a5d570937 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f5r-8cpv-jgc3/GHSA-3f5r-8cpv-jgc3.json +++ b/advisories/unreviewed/2022/05/GHSA-3f5r-8cpv-jgc3/GHSA-3f5r-8cpv-jgc3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3f74-7777-69pq/GHSA-3f74-7777-69pq.json b/advisories/unreviewed/2022/05/GHSA-3f74-7777-69pq/GHSA-3f74-7777-69pq.json index 173d51f5074..e02b002bf23 100644 --- a/advisories/unreviewed/2022/05/GHSA-3f74-7777-69pq/GHSA-3f74-7777-69pq.json +++ b/advisories/unreviewed/2022/05/GHSA-3f74-7777-69pq/GHSA-3f74-7777-69pq.json @@ -7,12 +7,8 @@ "CVE-2015-3085" ], "details": "Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow remote attackers to bypass intended restrictions on filesystem write operations via unspecified vectors, a different vulnerability than CVE-2015-3082 and CVE-2015-3083.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3ffw-g42j-mp5v/GHSA-3ffw-g42j-mp5v.json b/advisories/unreviewed/2022/05/GHSA-3ffw-g42j-mp5v/GHSA-3ffw-g42j-mp5v.json index a9100e0bee3..8f13f78dcd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3ffw-g42j-mp5v/GHSA-3ffw-g42j-mp5v.json +++ b/advisories/unreviewed/2022/05/GHSA-3ffw-g42j-mp5v/GHSA-3ffw-g42j-mp5v.json @@ -7,12 +7,8 @@ "CVE-2015-6757" ], "details": "Use-after-free vulnerability in content/browser/service_worker/embedded_worker_instance.cc in the ServiceWorker implementation in Google Chrome before 46.0.2490.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging object destruction in a callback.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3g2r-q9r9-rjh5/GHSA-3g2r-q9r9-rjh5.json b/advisories/unreviewed/2022/05/GHSA-3g2r-q9r9-rjh5/GHSA-3g2r-q9r9-rjh5.json index f9ed5cb11fd..a7dc2814137 100644 --- a/advisories/unreviewed/2022/05/GHSA-3g2r-q9r9-rjh5/GHSA-3g2r-q9r9-rjh5.json +++ b/advisories/unreviewed/2022/05/GHSA-3g2r-q9r9-rjh5/GHSA-3g2r-q9r9-rjh5.json @@ -7,12 +7,8 @@ "CVE-2009-3556" ], "details": "A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3gg4-3mqm-xx5v/GHSA-3gg4-3mqm-xx5v.json b/advisories/unreviewed/2022/05/GHSA-3gg4-3mqm-xx5v/GHSA-3gg4-3mqm-xx5v.json index 42ed09a613e..345b90a25dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3gg4-3mqm-xx5v/GHSA-3gg4-3mqm-xx5v.json +++ b/advisories/unreviewed/2022/05/GHSA-3gg4-3mqm-xx5v/GHSA-3gg4-3mqm-xx5v.json @@ -7,12 +7,8 @@ "CVE-2015-7017" ], "details": "CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-6992.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hpf-fhp5-r44c/GHSA-3hpf-fhp5-r44c.json b/advisories/unreviewed/2022/05/GHSA-3hpf-fhp5-r44c/GHSA-3hpf-fhp5-r44c.json index 1e81427c3f5..ab0d1bbb2c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hpf-fhp5-r44c/GHSA-3hpf-fhp5-r44c.json +++ b/advisories/unreviewed/2022/05/GHSA-3hpf-fhp5-r44c/GHSA-3hpf-fhp5-r44c.json @@ -7,12 +7,8 @@ "CVE-2013-6343" ], "details": "Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3hq6-jjwr-fjv7/GHSA-3hq6-jjwr-fjv7.json b/advisories/unreviewed/2022/05/GHSA-3hq6-jjwr-fjv7/GHSA-3hq6-jjwr-fjv7.json index 2255494e4c4..3cb351d335a 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hq6-jjwr-fjv7/GHSA-3hq6-jjwr-fjv7.json +++ b/advisories/unreviewed/2022/05/GHSA-3hq6-jjwr-fjv7/GHSA-3hq6-jjwr-fjv7.json @@ -7,12 +7,8 @@ "CVE-2015-4232" ], "details": "Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3jpv-v5qf-r957/GHSA-3jpv-v5qf-r957.json b/advisories/unreviewed/2022/05/GHSA-3jpv-v5qf-r957/GHSA-3jpv-v5qf-r957.json index e5978920181..117d87e05e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jpv-v5qf-r957/GHSA-3jpv-v5qf-r957.json +++ b/advisories/unreviewed/2022/05/GHSA-3jpv-v5qf-r957/GHSA-3jpv-v5qf-r957.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3mw8-88mv-4wcm/GHSA-3mw8-88mv-4wcm.json b/advisories/unreviewed/2022/05/GHSA-3mw8-88mv-4wcm/GHSA-3mw8-88mv-4wcm.json index d2d24e0c0b9..bc4bd8eb5ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-3mw8-88mv-4wcm/GHSA-3mw8-88mv-4wcm.json +++ b/advisories/unreviewed/2022/05/GHSA-3mw8-88mv-4wcm/GHSA-3mw8-88mv-4wcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pg8-5qjj-jmqc/GHSA-3pg8-5qjj-jmqc.json b/advisories/unreviewed/2022/05/GHSA-3pg8-5qjj-jmqc/GHSA-3pg8-5qjj-jmqc.json index daf2b49a927..3609ee8a6d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pg8-5qjj-jmqc/GHSA-3pg8-5qjj-jmqc.json +++ b/advisories/unreviewed/2022/05/GHSA-3pg8-5qjj-jmqc/GHSA-3pg8-5qjj-jmqc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3pg9-3f6q-hjf5/GHSA-3pg9-3f6q-hjf5.json b/advisories/unreviewed/2022/05/GHSA-3pg9-3f6q-hjf5/GHSA-3pg9-3f6q-hjf5.json index 6f428cf6f93..59ce7c05e3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3pg9-3f6q-hjf5/GHSA-3pg9-3f6q-hjf5.json +++ b/advisories/unreviewed/2022/05/GHSA-3pg9-3f6q-hjf5/GHSA-3pg9-3f6q-hjf5.json @@ -7,12 +7,8 @@ "CVE-2015-1267" ], "details": "Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink public API, related to WebArrayBufferConverter.cpp, WebBlob.cpp, WebDOMError.cpp, and WebDOMFileSystem.cpp.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3qp4-8w7m-xx2g/GHSA-3qp4-8w7m-xx2g.json b/advisories/unreviewed/2022/05/GHSA-3qp4-8w7m-xx2g/GHSA-3qp4-8w7m-xx2g.json index dbdb352fd63..9d7c52a73d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qp4-8w7m-xx2g/GHSA-3qp4-8w7m-xx2g.json +++ b/advisories/unreviewed/2022/05/GHSA-3qp4-8w7m-xx2g/GHSA-3qp4-8w7m-xx2g.json @@ -7,12 +7,8 @@ "CVE-2008-1374" ], "details": "Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3r3c-9579-33c4/GHSA-3r3c-9579-33c4.json b/advisories/unreviewed/2022/05/GHSA-3r3c-9579-33c4/GHSA-3r3c-9579-33c4.json index 1d108607ce4..a122f5500ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r3c-9579-33c4/GHSA-3r3c-9579-33c4.json +++ b/advisories/unreviewed/2022/05/GHSA-3r3c-9579-33c4/GHSA-3r3c-9579-33c4.json @@ -7,12 +7,8 @@ "CVE-2015-6304" ], "details": "Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Server software 3.0(2.24) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCut63718, CSCut63724, and CSCut63760.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3rx9-3f42-rqvh/GHSA-3rx9-3f42-rqvh.json b/advisories/unreviewed/2022/05/GHSA-3rx9-3f42-rqvh/GHSA-3rx9-3f42-rqvh.json index c64f65c7ebe..6dfeda9d8aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-3rx9-3f42-rqvh/GHSA-3rx9-3f42-rqvh.json +++ b/advisories/unreviewed/2022/05/GHSA-3rx9-3f42-rqvh/GHSA-3rx9-3f42-rqvh.json @@ -7,12 +7,8 @@ "CVE-2014-7929" ], "details": "Use-after-free vulnerability in the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving movement of a SCRIPT element across documents.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-3vf2-rf9c-6455/GHSA-3vf2-rf9c-6455.json b/advisories/unreviewed/2022/05/GHSA-3vf2-rf9c-6455/GHSA-3vf2-rf9c-6455.json index 42e4e4197b4..a2f64a1f3c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vf2-rf9c-6455/GHSA-3vf2-rf9c-6455.json +++ b/advisories/unreviewed/2022/05/GHSA-3vf2-rf9c-6455/GHSA-3vf2-rf9c-6455.json @@ -7,12 +7,8 @@ "CVE-2014-8619" ], "details": "Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5.1.2 through 5.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3vgj-8j9j-hppx/GHSA-3vgj-8j9j-hppx.json b/advisories/unreviewed/2022/05/GHSA-3vgj-8j9j-hppx/GHSA-3vgj-8j9j-hppx.json index c988c392e5d..4a12278cd2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vgj-8j9j-hppx/GHSA-3vgj-8j9j-hppx.json +++ b/advisories/unreviewed/2022/05/GHSA-3vgj-8j9j-hppx/GHSA-3vgj-8j9j-hppx.json @@ -7,12 +7,8 @@ "CVE-2013-7368" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the gnew_template parameter to (1) users/profile.php, (2) articles/index.php, or (3) admin/polls.php; (4) category_id parameter to news/submit.php; news_id parameter to (5) news/send.php or (6) comments/add.php; or (7) post_subject or (8) thread_id parameter to posts/edit.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3w38-w685-6793/GHSA-3w38-w685-6793.json b/advisories/unreviewed/2022/05/GHSA-3w38-w685-6793/GHSA-3w38-w685-6793.json index 26e4076fba3..41d7b3229a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3w38-w685-6793/GHSA-3w38-w685-6793.json +++ b/advisories/unreviewed/2022/05/GHSA-3w38-w685-6793/GHSA-3w38-w685-6793.json @@ -7,12 +7,8 @@ "CVE-2015-3644" ], "details": "Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wfg-xv96-62cq/GHSA-3wfg-xv96-62cq.json b/advisories/unreviewed/2022/05/GHSA-3wfg-xv96-62cq/GHSA-3wfg-xv96-62cq.json index 1b90b0e619c..5584f72718f 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wfg-xv96-62cq/GHSA-3wfg-xv96-62cq.json +++ b/advisories/unreviewed/2022/05/GHSA-3wfg-xv96-62cq/GHSA-3wfg-xv96-62cq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3wmg-58pp-mmfc/GHSA-3wmg-58pp-mmfc.json b/advisories/unreviewed/2022/05/GHSA-3wmg-58pp-mmfc/GHSA-3wmg-58pp-mmfc.json index 3c8f401ef0b..a2d2cadd259 100644 --- a/advisories/unreviewed/2022/05/GHSA-3wmg-58pp-mmfc/GHSA-3wmg-58pp-mmfc.json +++ b/advisories/unreviewed/2022/05/GHSA-3wmg-58pp-mmfc/GHSA-3wmg-58pp-mmfc.json @@ -7,12 +7,8 @@ "CVE-2015-5936" ], "details": "ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5937, and CVE-2015-5939.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-3x54-79xc-w2f4/GHSA-3x54-79xc-w2f4.json b/advisories/unreviewed/2022/05/GHSA-3x54-79xc-w2f4/GHSA-3x54-79xc-w2f4.json index 44a710ba058..73e4e2c5960 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x54-79xc-w2f4/GHSA-3x54-79xc-w2f4.json +++ b/advisories/unreviewed/2022/05/GHSA-3x54-79xc-w2f4/GHSA-3x54-79xc-w2f4.json @@ -7,12 +7,8 @@ "CVE-2015-2042" ], "details": "net/rds/sysctl.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-439q-mv65-mm66/GHSA-439q-mv65-mm66.json b/advisories/unreviewed/2022/05/GHSA-439q-mv65-mm66/GHSA-439q-mv65-mm66.json index 78f1d45a6e1..b24cc2891f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-439q-mv65-mm66/GHSA-439q-mv65-mm66.json +++ b/advisories/unreviewed/2022/05/GHSA-439q-mv65-mm66/GHSA-439q-mv65-mm66.json @@ -7,12 +7,8 @@ "CVE-2014-8024" ], "details": "The API in the Guest Server in Cisco Jabber, when the HTML5 CORS feature is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST request, aka Bug ID CSCus19789.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-43h7-vvrf-6gmp/GHSA-43h7-vvrf-6gmp.json b/advisories/unreviewed/2022/05/GHSA-43h7-vvrf-6gmp/GHSA-43h7-vvrf-6gmp.json index 2c7321b1790..6332de2301b 100644 --- a/advisories/unreviewed/2022/05/GHSA-43h7-vvrf-6gmp/GHSA-43h7-vvrf-6gmp.json +++ b/advisories/unreviewed/2022/05/GHSA-43h7-vvrf-6gmp/GHSA-43h7-vvrf-6gmp.json @@ -7,12 +7,8 @@ "CVE-2013-7251" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in ProjectForge before 5.3 allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) web/admin/, (2) web/core/, (3) web/dialog/, (4) web/fibu/, (5) web/mobile/, (6) web/task/, or (7) web/wicket/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-442r-3r9f-48cm/GHSA-442r-3r9f-48cm.json b/advisories/unreviewed/2022/05/GHSA-442r-3r9f-48cm/GHSA-442r-3r9f-48cm.json index b0c00231239..45d9daf3012 100644 --- a/advisories/unreviewed/2022/05/GHSA-442r-3r9f-48cm/GHSA-442r-3r9f-48cm.json +++ b/advisories/unreviewed/2022/05/GHSA-442r-3r9f-48cm/GHSA-442r-3r9f-48cm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4458-ww2x-8wwm/GHSA-4458-ww2x-8wwm.json b/advisories/unreviewed/2022/05/GHSA-4458-ww2x-8wwm/GHSA-4458-ww2x-8wwm.json index daaaa6d0ae2..09925d2e608 100644 --- a/advisories/unreviewed/2022/05/GHSA-4458-ww2x-8wwm/GHSA-4458-ww2x-8wwm.json +++ b/advisories/unreviewed/2022/05/GHSA-4458-ww2x-8wwm/GHSA-4458-ww2x-8wwm.json @@ -7,12 +7,8 @@ "CVE-2015-3902" ], "details": "Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-44w2-xrgw-gqvj/GHSA-44w2-xrgw-gqvj.json b/advisories/unreviewed/2022/05/GHSA-44w2-xrgw-gqvj/GHSA-44w2-xrgw-gqvj.json index d91535d241f..0be43e0eef3 100644 --- a/advisories/unreviewed/2022/05/GHSA-44w2-xrgw-gqvj/GHSA-44w2-xrgw-gqvj.json +++ b/advisories/unreviewed/2022/05/GHSA-44w2-xrgw-gqvj/GHSA-44w2-xrgw-gqvj.json @@ -7,12 +7,8 @@ "CVE-2014-8012" ], "details": "Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-466g-x545-3vxm/GHSA-466g-x545-3vxm.json b/advisories/unreviewed/2022/05/GHSA-466g-x545-3vxm/GHSA-466g-x545-3vxm.json index 46538e00715..f74dd489dac 100644 --- a/advisories/unreviewed/2022/05/GHSA-466g-x545-3vxm/GHSA-466g-x545-3vxm.json +++ b/advisories/unreviewed/2022/05/GHSA-466g-x545-3vxm/GHSA-466g-x545-3vxm.json @@ -7,12 +7,8 @@ "CVE-2015-7031" ], "details": "The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-46gh-7h39-67p2/GHSA-46gh-7h39-67p2.json b/advisories/unreviewed/2022/05/GHSA-46gh-7h39-67p2/GHSA-46gh-7h39-67p2.json index 051bcc9006a..4cb8904a695 100644 --- a/advisories/unreviewed/2022/05/GHSA-46gh-7h39-67p2/GHSA-46gh-7h39-67p2.json +++ b/advisories/unreviewed/2022/05/GHSA-46gh-7h39-67p2/GHSA-46gh-7h39-67p2.json @@ -7,12 +7,8 @@ "CVE-2013-7241" ], "details": "Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows remote attackers to inject arbitrary web script or HTML via the URI.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-46r4-fm53-62xh/GHSA-46r4-fm53-62xh.json b/advisories/unreviewed/2022/05/GHSA-46r4-fm53-62xh/GHSA-46r4-fm53-62xh.json index 089382250e8..3967c7b3be8 100644 --- a/advisories/unreviewed/2022/05/GHSA-46r4-fm53-62xh/GHSA-46r4-fm53-62xh.json +++ b/advisories/unreviewed/2022/05/GHSA-46r4-fm53-62xh/GHSA-46r4-fm53-62xh.json @@ -7,12 +7,8 @@ "CVE-2013-7250" ], "details": "Cross-site scripting (XSS) vulnerability in the JsonBuilder implementation in ProjectForge before 5.3 allows remote authenticated users to inject arbitrary web script or HTML via an autocompletion string, related to web/core/JsonBuilder.java and web/wicket/autocompletion/PFAutoCompleteBehavior.java.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-474h-vp2m-gmq9/GHSA-474h-vp2m-gmq9.json b/advisories/unreviewed/2022/05/GHSA-474h-vp2m-gmq9/GHSA-474h-vp2m-gmq9.json index 0730d2ee574..8c5c9ae4986 100644 --- a/advisories/unreviewed/2022/05/GHSA-474h-vp2m-gmq9/GHSA-474h-vp2m-gmq9.json +++ b/advisories/unreviewed/2022/05/GHSA-474h-vp2m-gmq9/GHSA-474h-vp2m-gmq9.json @@ -7,12 +7,8 @@ "CVE-2015-0448" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via vectors related to ZFS File system.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-47j7-228r-59cw/GHSA-47j7-228r-59cw.json b/advisories/unreviewed/2022/05/GHSA-47j7-228r-59cw/GHSA-47j7-228r-59cw.json index a7360ee0a50..a86ea1767fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-47j7-228r-59cw/GHSA-47j7-228r-59cw.json +++ b/advisories/unreviewed/2022/05/GHSA-47j7-228r-59cw/GHSA-47j7-228r-59cw.json @@ -7,12 +7,8 @@ "CVE-2013-2031" ], "details": "MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in a SVG file, which is then incorrectly interpreted as UTF-8 by Chrome and Firefox.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-488v-xjjh-292p/GHSA-488v-xjjh-292p.json b/advisories/unreviewed/2022/05/GHSA-488v-xjjh-292p/GHSA-488v-xjjh-292p.json index b5ba9052b6d..39417abc1c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-488v-xjjh-292p/GHSA-488v-xjjh-292p.json +++ b/advisories/unreviewed/2022/05/GHSA-488v-xjjh-292p/GHSA-488v-xjjh-292p.json @@ -7,12 +7,8 @@ "CVE-2015-4208" ], "details": "Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4c6v-4fgp-f659/GHSA-4c6v-4fgp-f659.json b/advisories/unreviewed/2022/05/GHSA-4c6v-4fgp-f659/GHSA-4c6v-4fgp-f659.json index c86f8d6b45e..b0c49eba8a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4c6v-4fgp-f659/GHSA-4c6v-4fgp-f659.json +++ b/advisories/unreviewed/2022/05/GHSA-4c6v-4fgp-f659/GHSA-4c6v-4fgp-f659.json @@ -7,12 +7,8 @@ "CVE-2015-0197" ], "details": "IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges for program execution via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4cvr-5qqp-vwp5/GHSA-4cvr-5qqp-vwp5.json b/advisories/unreviewed/2022/05/GHSA-4cvr-5qqp-vwp5/GHSA-4cvr-5qqp-vwp5.json index 73320d4ebd4..7e23ff68b13 100644 --- a/advisories/unreviewed/2022/05/GHSA-4cvr-5qqp-vwp5/GHSA-4cvr-5qqp-vwp5.json +++ b/advisories/unreviewed/2022/05/GHSA-4cvr-5qqp-vwp5/GHSA-4cvr-5qqp-vwp5.json @@ -7,12 +7,8 @@ "CVE-2015-6762" ], "details": "The CSSFontFaceSrcValue::fetch function in core/css/CSSFontFaceSrcValue.cpp in the Cascading Style Sheets (CSS) implementation in Blink, as used in Google Chrome before 46.0.2490.71, does not use the CORS cross-origin request algorithm when a font's URL appears to be a same-origin URL, which allows remote web servers to bypass the Same Origin Policy via a redirect.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4f5g-64px-29pq/GHSA-4f5g-64px-29pq.json b/advisories/unreviewed/2022/05/GHSA-4f5g-64px-29pq/GHSA-4f5g-64px-29pq.json index fcae1307da4..8c1d8ad770a 100644 --- a/advisories/unreviewed/2022/05/GHSA-4f5g-64px-29pq/GHSA-4f5g-64px-29pq.json +++ b/advisories/unreviewed/2022/05/GHSA-4f5g-64px-29pq/GHSA-4f5g-64px-29pq.json @@ -7,12 +7,8 @@ "CVE-2015-2265" ], "details": "The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4g6q-mf75-jfx7/GHSA-4g6q-mf75-jfx7.json b/advisories/unreviewed/2022/05/GHSA-4g6q-mf75-jfx7/GHSA-4g6q-mf75-jfx7.json index 43a4d0bc092..e9a721a7750 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g6q-mf75-jfx7/GHSA-4g6q-mf75-jfx7.json +++ b/advisories/unreviewed/2022/05/GHSA-4g6q-mf75-jfx7/GHSA-4g6q-mf75-jfx7.json @@ -7,12 +7,8 @@ "CVE-2015-5749" ], "details": "The Sandbox_profiles component in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gf4-55f6-hq4x/GHSA-4gf4-55f6-hq4x.json b/advisories/unreviewed/2022/05/GHSA-4gf4-55f6-hq4x/GHSA-4gf4-55f6-hq4x.json index 6420c3b6552..23a3f7cc82d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gf4-55f6-hq4x/GHSA-4gf4-55f6-hq4x.json +++ b/advisories/unreviewed/2022/05/GHSA-4gf4-55f6-hq4x/GHSA-4gf4-55f6-hq4x.json @@ -7,12 +7,8 @@ "CVE-2015-6299" ], "details": "SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4ghc-9j93-h7xg/GHSA-4ghc-9j93-h7xg.json b/advisories/unreviewed/2022/05/GHSA-4ghc-9j93-h7xg/GHSA-4ghc-9j93-h7xg.json index ba24e9a8855..8902949df02 100644 --- a/advisories/unreviewed/2022/05/GHSA-4ghc-9j93-h7xg/GHSA-4ghc-9j93-h7xg.json +++ b/advisories/unreviewed/2022/05/GHSA-4ghc-9j93-h7xg/GHSA-4ghc-9j93-h7xg.json @@ -7,12 +7,8 @@ "CVE-2015-1967" ], "details": "MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4gp2-86m5-2qx6/GHSA-4gp2-86m5-2qx6.json b/advisories/unreviewed/2022/05/GHSA-4gp2-86m5-2qx6/GHSA-4gp2-86m5-2qx6.json index a2b5646d4b2..e6ecf3127a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gp2-86m5-2qx6/GHSA-4gp2-86m5-2qx6.json +++ b/advisories/unreviewed/2022/05/GHSA-4gp2-86m5-2qx6/GHSA-4gp2-86m5-2qx6.json @@ -7,12 +7,8 @@ "CVE-2015-1608" ], "details": "Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection strings, which allows attackers to read the cleartext version of sensitive credential and e-mail address information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4gwv-cfrq-qfh7/GHSA-4gwv-cfrq-qfh7.json b/advisories/unreviewed/2022/05/GHSA-4gwv-cfrq-qfh7/GHSA-4gwv-cfrq-qfh7.json index 9cb3e57d162..779448a904d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4gwv-cfrq-qfh7/GHSA-4gwv-cfrq-qfh7.json +++ b/advisories/unreviewed/2022/05/GHSA-4gwv-cfrq-qfh7/GHSA-4gwv-cfrq-qfh7.json @@ -7,12 +7,8 @@ "CVE-2015-0503" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hfg-9c96-mf76/GHSA-4hfg-9c96-mf76.json b/advisories/unreviewed/2022/05/GHSA-4hfg-9c96-mf76/GHSA-4hfg-9c96-mf76.json index 664cd840550..922433ca901 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hfg-9c96-mf76/GHSA-4hfg-9c96-mf76.json +++ b/advisories/unreviewed/2022/05/GHSA-4hfg-9c96-mf76/GHSA-4hfg-9c96-mf76.json @@ -7,12 +7,8 @@ "CVE-2015-3728" ], "details": "The WiFi Connectivity feature in Apple iOS before 8.4 allows remote Wi-Fi access points to trigger an automatic association, with an arbitrary security type, by operating with a recognized ESSID within an 802.11 network's coverage area.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4hmw-6qpr-wq88/GHSA-4hmw-6qpr-wq88.json b/advisories/unreviewed/2022/05/GHSA-4hmw-6qpr-wq88/GHSA-4hmw-6qpr-wq88.json index ff85b4a0f13..0c40aa6d7ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-4hmw-6qpr-wq88/GHSA-4hmw-6qpr-wq88.json +++ b/advisories/unreviewed/2022/05/GHSA-4hmw-6qpr-wq88/GHSA-4hmw-6qpr-wq88.json @@ -7,12 +7,8 @@ "CVE-2015-2663" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, and 6.3.0 through 6.3.7 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Business Process Automation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4j9x-vhq3-45pr/GHSA-4j9x-vhq3-45pr.json b/advisories/unreviewed/2022/05/GHSA-4j9x-vhq3-45pr/GHSA-4j9x-vhq3-45pr.json index dedce874870..e6ab552b464 100644 --- a/advisories/unreviewed/2022/05/GHSA-4j9x-vhq3-45pr/GHSA-4j9x-vhq3-45pr.json +++ b/advisories/unreviewed/2022/05/GHSA-4j9x-vhq3-45pr/GHSA-4j9x-vhq3-45pr.json @@ -7,12 +7,8 @@ "CVE-2015-1254" ], "details": "core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4jc7-gpxx-gg52/GHSA-4jc7-gpxx-gg52.json b/advisories/unreviewed/2022/05/GHSA-4jc7-gpxx-gg52/GHSA-4jc7-gpxx-gg52.json index fdcc5497817..b4ce48af7ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jc7-gpxx-gg52/GHSA-4jc7-gpxx-gg52.json +++ b/advisories/unreviewed/2022/05/GHSA-4jc7-gpxx-gg52/GHSA-4jc7-gpxx-gg52.json @@ -7,12 +7,8 @@ "CVE-2011-4304" ], "details": "The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4mf4-pwvw-5252/GHSA-4mf4-pwvw-5252.json b/advisories/unreviewed/2022/05/GHSA-4mf4-pwvw-5252/GHSA-4mf4-pwvw-5252.json index 076489d83f9..495a4be1219 100644 --- a/advisories/unreviewed/2022/05/GHSA-4mf4-pwvw-5252/GHSA-4mf4-pwvw-5252.json +++ b/advisories/unreviewed/2022/05/GHSA-4mf4-pwvw-5252/GHSA-4mf4-pwvw-5252.json @@ -7,12 +7,8 @@ "CVE-2015-4202" ], "details": "Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service, which allows remote attackers to obtain potentially sensitive MAC address and network-utilization information via crafted IPDR packets, aka Bug ID CSCua39203.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4p26-xwh2-224v/GHSA-4p26-xwh2-224v.json b/advisories/unreviewed/2022/05/GHSA-4p26-xwh2-224v/GHSA-4p26-xwh2-224v.json index 6fe6b2f213b..71774e4627f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p26-xwh2-224v/GHSA-4p26-xwh2-224v.json +++ b/advisories/unreviewed/2022/05/GHSA-4p26-xwh2-224v/GHSA-4p26-xwh2-224v.json @@ -7,12 +7,8 @@ "CVE-2015-2623" ], "details": "Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2, and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0, allows remote attackers to affect integrity via unknown vectors related to Java Server Faces.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4p7c-p2rw-3pw7/GHSA-4p7c-p2rw-3pw7.json b/advisories/unreviewed/2022/05/GHSA-4p7c-p2rw-3pw7/GHSA-4p7c-p2rw-3pw7.json index e4c68717491..9556a1fb67b 100644 --- a/advisories/unreviewed/2022/05/GHSA-4p7c-p2rw-3pw7/GHSA-4p7c-p2rw-3pw7.json +++ b/advisories/unreviewed/2022/05/GHSA-4p7c-p2rw-3pw7/GHSA-4p7c-p2rw-3pw7.json @@ -7,12 +7,8 @@ "CVE-2015-2120" ], "details": "Unspecified vulnerability in HP SiteScope 11.1x before 11.13, 11.2x before 11.24.391, and 11.3x before 11.30.521 allows remote authenticated users to gain privileges via unknown vectors, aka ZDI-CAN-2567.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4phh-wxc8-pcp3/GHSA-4phh-wxc8-pcp3.json b/advisories/unreviewed/2022/05/GHSA-4phh-wxc8-pcp3/GHSA-4phh-wxc8-pcp3.json index cd8218e7a06..cc2bc385c76 100644 --- a/advisories/unreviewed/2022/05/GHSA-4phh-wxc8-pcp3/GHSA-4phh-wxc8-pcp3.json +++ b/advisories/unreviewed/2022/05/GHSA-4phh-wxc8-pcp3/GHSA-4phh-wxc8-pcp3.json @@ -7,12 +7,8 @@ "CVE-2013-4996" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the navigation panel, (4) a crafted entry in a certain proxy list, or (5) crafted content in a version.json file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pv9-h9jj-rpcp/GHSA-4pv9-h9jj-rpcp.json b/advisories/unreviewed/2022/05/GHSA-4pv9-h9jj-rpcp/GHSA-4pv9-h9jj-rpcp.json index ef42762e572..329844e67a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pv9-h9jj-rpcp/GHSA-4pv9-h9jj-rpcp.json +++ b/advisories/unreviewed/2022/05/GHSA-4pv9-h9jj-rpcp/GHSA-4pv9-h9jj-rpcp.json @@ -7,12 +7,8 @@ "CVE-2015-4221" ], "details": "Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and consequently execute arbitrary commands, by visiting an unspecified web page and then conducting a decryption attack, aka Bug ID CSCuq46194.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4pw2-x5qf-3fx4/GHSA-4pw2-x5qf-3fx4.json b/advisories/unreviewed/2022/05/GHSA-4pw2-x5qf-3fx4/GHSA-4pw2-x5qf-3fx4.json index 93a0500e852..b17b0680413 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pw2-x5qf-3fx4/GHSA-4pw2-x5qf-3fx4.json +++ b/advisories/unreviewed/2022/05/GHSA-4pw2-x5qf-3fx4/GHSA-4pw2-x5qf-3fx4.json @@ -7,12 +7,8 @@ "CVE-2015-0198" ], "details": "IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4pwg-9hxp-h37h/GHSA-4pwg-9hxp-h37h.json b/advisories/unreviewed/2022/05/GHSA-4pwg-9hxp-h37h/GHSA-4pwg-9hxp-h37h.json index 68ea309e4eb..3799c4e6bc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pwg-9hxp-h37h/GHSA-4pwg-9hxp-h37h.json +++ b/advisories/unreviewed/2022/05/GHSA-4pwg-9hxp-h37h/GHSA-4pwg-9hxp-h37h.json @@ -7,12 +7,8 @@ "CVE-2015-1964" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4qw4-mgvm-hr9r/GHSA-4qw4-mgvm-hr9r.json b/advisories/unreviewed/2022/05/GHSA-4qw4-mgvm-hr9r/GHSA-4qw4-mgvm-hr9r.json index f7bf8de68df..c321813ad7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4qw4-mgvm-hr9r/GHSA-4qw4-mgvm-hr9r.json +++ b/advisories/unreviewed/2022/05/GHSA-4qw4-mgvm-hr9r/GHSA-4qw4-mgvm-hr9r.json @@ -7,12 +7,8 @@ "CVE-2015-6758" ], "details": "The CPDF_Document::GetPage function in fpdfapi/fpdf_parser/fpdf_parser_document.cpp in PDFium, as used in Google Chrome before 46.0.2490.71, does not properly perform a cast of a dictionary object, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4rw7-7wpq-7g64/GHSA-4rw7-7wpq-7g64.json b/advisories/unreviewed/2022/05/GHSA-4rw7-7wpq-7g64/GHSA-4rw7-7wpq-7g64.json index 12827d7270d..d50c9b2022e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4rw7-7wpq-7g64/GHSA-4rw7-7wpq-7g64.json +++ b/advisories/unreviewed/2022/05/GHSA-4rw7-7wpq-7g64/GHSA-4rw7-7wpq-7g64.json @@ -7,12 +7,8 @@ "CVE-2015-0817" ], "details": "The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 does not properly determine the cases in which bounds checking may be safely skipped during JIT compilation and heap access, which allows remote attackers to read or write to unintended memory locations, and consequently execute arbitrary code, via crafted JavaScript.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4v4c-9v2r-r2qg/GHSA-4v4c-9v2r-r2qg.json b/advisories/unreviewed/2022/05/GHSA-4v4c-9v2r-r2qg/GHSA-4v4c-9v2r-r2qg.json index b30a33b78e5..477da18feea 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v4c-9v2r-r2qg/GHSA-4v4c-9v2r-r2qg.json +++ b/advisories/unreviewed/2022/05/GHSA-4v4c-9v2r-r2qg/GHSA-4v4c-9v2r-r2qg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vf8-6hqf-prv9/GHSA-4vf8-6hqf-prv9.json b/advisories/unreviewed/2022/05/GHSA-4vf8-6hqf-prv9/GHSA-4vf8-6hqf-prv9.json index 89c04ccba37..d73af749021 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vf8-6hqf-prv9/GHSA-4vf8-6hqf-prv9.json +++ b/advisories/unreviewed/2022/05/GHSA-4vf8-6hqf-prv9/GHSA-4vf8-6hqf-prv9.json @@ -7,12 +7,8 @@ "CVE-2015-1249" ], "details": "Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -152,9 +148,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vgq-r9w4-vhv4/GHSA-4vgq-r9w4-vhv4.json b/advisories/unreviewed/2022/05/GHSA-4vgq-r9w4-vhv4/GHSA-4vgq-r9w4-vhv4.json index 004fc7721d5..2461766a28d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vgq-r9w4-vhv4/GHSA-4vgq-r9w4-vhv4.json +++ b/advisories/unreviewed/2022/05/GHSA-4vgq-r9w4-vhv4/GHSA-4vgq-r9w4-vhv4.json @@ -7,12 +7,8 @@ "CVE-2015-3099" ], "details": "Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-3098 and CVE-2015-3102.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vp9-q3c6-pqwg/GHSA-4vp9-q3c6-pqwg.json b/advisories/unreviewed/2022/05/GHSA-4vp9-q3c6-pqwg/GHSA-4vp9-q3c6-pqwg.json index 46502b60fce..04d746cab12 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vp9-q3c6-pqwg/GHSA-4vp9-q3c6-pqwg.json +++ b/advisories/unreviewed/2022/05/GHSA-4vp9-q3c6-pqwg/GHSA-4vp9-q3c6-pqwg.json @@ -7,12 +7,8 @@ "CVE-2015-7861" ], "details": "Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending unspecified commands in an environment that lacks relationship-based firewalling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4vph-7h2p-5498/GHSA-4vph-7h2p-5498.json b/advisories/unreviewed/2022/05/GHSA-4vph-7h2p-5498/GHSA-4vph-7h2p-5498.json index 4e86fd1b5c6..453b3c9b7cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vph-7h2p-5498/GHSA-4vph-7h2p-5498.json +++ b/advisories/unreviewed/2022/05/GHSA-4vph-7h2p-5498/GHSA-4vph-7h2p-5498.json @@ -7,12 +7,8 @@ "CVE-2013-2205" ], "details": "The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4vqp-m886-hqhq/GHSA-4vqp-m886-hqhq.json b/advisories/unreviewed/2022/05/GHSA-4vqp-m886-hqhq/GHSA-4vqp-m886-hqhq.json index 5c32b43bb9c..f87714b4890 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vqp-m886-hqhq/GHSA-4vqp-m886-hqhq.json +++ b/advisories/unreviewed/2022/05/GHSA-4vqp-m886-hqhq/GHSA-4vqp-m886-hqhq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w94-4xq8-3wqx/GHSA-4w94-4xq8-3wqx.json b/advisories/unreviewed/2022/05/GHSA-4w94-4xq8-3wqx/GHSA-4w94-4xq8-3wqx.json index b6de49620d3..35c6bb6232f 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w94-4xq8-3wqx/GHSA-4w94-4xq8-3wqx.json +++ b/advisories/unreviewed/2022/05/GHSA-4w94-4xq8-3wqx/GHSA-4w94-4xq8-3wqx.json @@ -7,12 +7,8 @@ "CVE-2015-5773" ], "details": "QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted office document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4w9r-63g7-xmfj/GHSA-4w9r-63g7-xmfj.json b/advisories/unreviewed/2022/05/GHSA-4w9r-63g7-xmfj/GHSA-4w9r-63g7-xmfj.json index 802dc0528f1..f37538f37a9 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w9r-63g7-xmfj/GHSA-4w9r-63g7-xmfj.json +++ b/advisories/unreviewed/2022/05/GHSA-4w9r-63g7-xmfj/GHSA-4w9r-63g7-xmfj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-4x2j-vmv4-3qc3/GHSA-4x2j-vmv4-3qc3.json b/advisories/unreviewed/2022/05/GHSA-4x2j-vmv4-3qc3/GHSA-4x2j-vmv4-3qc3.json index 3db0bb98470..802b859d7ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x2j-vmv4-3qc3/GHSA-4x2j-vmv4-3qc3.json +++ b/advisories/unreviewed/2022/05/GHSA-4x2j-vmv4-3qc3/GHSA-4x2j-vmv4-3qc3.json @@ -7,12 +7,8 @@ "CVE-2015-6297" ], "details": "The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4x7w-xmf9-qx55/GHSA-4x7w-xmf9-qx55.json b/advisories/unreviewed/2022/05/GHSA-4x7w-xmf9-qx55/GHSA-4x7w-xmf9-qx55.json index 6ed48891618..ac4da4fa8f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x7w-xmf9-qx55/GHSA-4x7w-xmf9-qx55.json +++ b/advisories/unreviewed/2022/05/GHSA-4x7w-xmf9-qx55/GHSA-4x7w-xmf9-qx55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -63,9 +61,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5277-qw9c-vxf6/GHSA-5277-qw9c-vxf6.json b/advisories/unreviewed/2022/05/GHSA-5277-qw9c-vxf6/GHSA-5277-qw9c-vxf6.json index c4d73a1d1ec..4fcaf1d50af 100644 --- a/advisories/unreviewed/2022/05/GHSA-5277-qw9c-vxf6/GHSA-5277-qw9c-vxf6.json +++ b/advisories/unreviewed/2022/05/GHSA-5277-qw9c-vxf6/GHSA-5277-qw9c-vxf6.json @@ -7,12 +7,8 @@ "CVE-2015-0548" ], "details": "The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52fg-2cvq-2h45/GHSA-52fg-2cvq-2h45.json b/advisories/unreviewed/2022/05/GHSA-52fg-2cvq-2h45/GHSA-52fg-2cvq-2h45.json index e97857c0881..f4cb7f080e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-52fg-2cvq-2h45/GHSA-52fg-2cvq-2h45.json +++ b/advisories/unreviewed/2022/05/GHSA-52fg-2cvq-2h45/GHSA-52fg-2cvq-2h45.json @@ -7,12 +7,8 @@ "CVE-2013-6017" ], "details": "Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML via the body of an e-mail message, as demonstrated by the SRC attribute of an IFRAME element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52mr-hjvg-fpjv/GHSA-52mr-hjvg-fpjv.json b/advisories/unreviewed/2022/05/GHSA-52mr-hjvg-fpjv/GHSA-52mr-hjvg-fpjv.json index 9c269020c7f..733d09d99fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-52mr-hjvg-fpjv/GHSA-52mr-hjvg-fpjv.json +++ b/advisories/unreviewed/2022/05/GHSA-52mr-hjvg-fpjv/GHSA-52mr-hjvg-fpjv.json @@ -7,12 +7,8 @@ "CVE-2015-7022" ], "details": "The Telephony subsystem in Apple iOS before 9.1 allows attackers to obtain sensitive call-status information via a crafted app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-52r5-7r4h-6hpf/GHSA-52r5-7r4h-6hpf.json b/advisories/unreviewed/2022/05/GHSA-52r5-7r4h-6hpf/GHSA-52r5-7r4h-6hpf.json index f744388b9a2..c6ade30b6b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-52r5-7r4h-6hpf/GHSA-52r5-7r4h-6hpf.json +++ b/advisories/unreviewed/2022/05/GHSA-52r5-7r4h-6hpf/GHSA-52r5-7r4h-6hpf.json @@ -7,12 +7,8 @@ "CVE-2015-2660" ], "details": "Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to Oracle Agile PLM Framework.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-52r6-fgpp-m7pq/GHSA-52r6-fgpp-m7pq.json b/advisories/unreviewed/2022/05/GHSA-52r6-fgpp-m7pq/GHSA-52r6-fgpp-m7pq.json index 80ad6c4da73..1e4924b7f1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-52r6-fgpp-m7pq/GHSA-52r6-fgpp-m7pq.json +++ b/advisories/unreviewed/2022/05/GHSA-52r6-fgpp-m7pq/GHSA-52r6-fgpp-m7pq.json @@ -7,12 +7,8 @@ "CVE-2014-7938" ], "details": "The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-535h-r53g-x9v4/GHSA-535h-r53g-x9v4.json b/advisories/unreviewed/2022/05/GHSA-535h-r53g-x9v4/GHSA-535h-r53g-x9v4.json index 8a29211dc21..93debcafe9a 100644 --- a/advisories/unreviewed/2022/05/GHSA-535h-r53g-x9v4/GHSA-535h-r53g-x9v4.json +++ b/advisories/unreviewed/2022/05/GHSA-535h-r53g-x9v4/GHSA-535h-r53g-x9v4.json @@ -7,12 +7,8 @@ "CVE-2015-3662" ], "details": "QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3663, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5394-7mcx-63pv/GHSA-5394-7mcx-63pv.json b/advisories/unreviewed/2022/05/GHSA-5394-7mcx-63pv/GHSA-5394-7mcx-63pv.json index 66e60917315..9f9fb04fa25 100644 --- a/advisories/unreviewed/2022/05/GHSA-5394-7mcx-63pv/GHSA-5394-7mcx-63pv.json +++ b/advisories/unreviewed/2022/05/GHSA-5394-7mcx-63pv/GHSA-5394-7mcx-63pv.json @@ -7,12 +7,8 @@ "CVE-2015-0231" ], "details": "Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -112,9 +108,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-53fv-rqv7-v4xm/GHSA-53fv-rqv7-v4xm.json b/advisories/unreviewed/2022/05/GHSA-53fv-rqv7-v4xm/GHSA-53fv-rqv7-v4xm.json index 5cf6af7c3e3..622ca2fca90 100644 --- a/advisories/unreviewed/2022/05/GHSA-53fv-rqv7-v4xm/GHSA-53fv-rqv7-v4xm.json +++ b/advisories/unreviewed/2022/05/GHSA-53fv-rqv7-v4xm/GHSA-53fv-rqv7-v4xm.json @@ -7,12 +7,8 @@ "CVE-2015-4526" ], "details": "EMC RecoverPoint for Virtual Machines (VMs) 4.2 allows local users to obtain root-shell access by bypassing the Installation Manager Boxmgmt CLI interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-53w7-2xj6-8f7m/GHSA-53w7-2xj6-8f7m.json b/advisories/unreviewed/2022/05/GHSA-53w7-2xj6-8f7m/GHSA-53w7-2xj6-8f7m.json index ec554fdf91d..e3fc4aa396a 100644 --- a/advisories/unreviewed/2022/05/GHSA-53w7-2xj6-8f7m/GHSA-53w7-2xj6-8f7m.json +++ b/advisories/unreviewed/2022/05/GHSA-53w7-2xj6-8f7m/GHSA-53w7-2xj6-8f7m.json @@ -7,12 +7,8 @@ "CVE-2015-4269" ], "details": "The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users to cause a denial of service (management outage) by sending many requests, aka Bug ID CSCuu99709.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-54xj-7cwx-cc55/GHSA-54xj-7cwx-cc55.json b/advisories/unreviewed/2022/05/GHSA-54xj-7cwx-cc55/GHSA-54xj-7cwx-cc55.json index 45dc635bc2b..f0904c7f7a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-54xj-7cwx-cc55/GHSA-54xj-7cwx-cc55.json +++ b/advisories/unreviewed/2022/05/GHSA-54xj-7cwx-cc55/GHSA-54xj-7cwx-cc55.json @@ -7,12 +7,8 @@ "CVE-2015-4214" ], "details": "Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading HTML source code, aka Bug ID CSCuu33050.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-55pr-qg64-v8m8/GHSA-55pr-qg64-v8m8.json b/advisories/unreviewed/2022/05/GHSA-55pr-qg64-v8m8/GHSA-55pr-qg64-v8m8.json index 4e3f32adb93..8ba16fffd8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-55pr-qg64-v8m8/GHSA-55pr-qg64-v8m8.json +++ b/advisories/unreviewed/2022/05/GHSA-55pr-qg64-v8m8/GHSA-55pr-qg64-v8m8.json @@ -7,12 +7,8 @@ "CVE-2014-0045" ], "details": "The needSamples method in AudioOutputSpeech.cpp in the client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots, Mumble for iOS 1.1 through 1.2.2, and MumbleKit before commit fd190328a9b24d37382b269a5674b0c0c7a7e36d does not check the return value of the opus_decode_float function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Opus voice packet, which triggers an error in opus_decode_float, a conversion of a negative integer to an unsigned integer, and a heap-based buffer over-read and over-write.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-567q-q8ff-85jf/GHSA-567q-q8ff-85jf.json b/advisories/unreviewed/2022/05/GHSA-567q-q8ff-85jf/GHSA-567q-q8ff-85jf.json index 61ad98d2e3a..2a126787f64 100644 --- a/advisories/unreviewed/2022/05/GHSA-567q-q8ff-85jf/GHSA-567q-q8ff-85jf.json +++ b/advisories/unreviewed/2022/05/GHSA-567q-q8ff-85jf/GHSA-567q-q8ff-85jf.json @@ -7,12 +7,8 @@ "CVE-2015-4227" ], "details": "Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91838.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-572m-8fgx-rjq3/GHSA-572m-8fgx-rjq3.json b/advisories/unreviewed/2022/05/GHSA-572m-8fgx-rjq3/GHSA-572m-8fgx-rjq3.json index 2e5d00edb1b..5cabe3aa51f 100644 --- a/advisories/unreviewed/2022/05/GHSA-572m-8fgx-rjq3/GHSA-572m-8fgx-rjq3.json +++ b/advisories/unreviewed/2022/05/GHSA-572m-8fgx-rjq3/GHSA-572m-8fgx-rjq3.json @@ -7,12 +7,8 @@ "CVE-2015-2126" ], "details": "Unspecified vulnerability in pppoec in HP HP-UX 11iv2 and 11iv3 allows local users to gain privileges by leveraging setuid permissions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-574v-ffv3-5fcx/GHSA-574v-ffv3-5fcx.json b/advisories/unreviewed/2022/05/GHSA-574v-ffv3-5fcx/GHSA-574v-ffv3-5fcx.json index ac8cf098132..f240006f10a 100644 --- a/advisories/unreviewed/2022/05/GHSA-574v-ffv3-5fcx/GHSA-574v-ffv3-5fcx.json +++ b/advisories/unreviewed/2022/05/GHSA-574v-ffv3-5fcx/GHSA-574v-ffv3-5fcx.json @@ -7,12 +7,8 @@ "CVE-2015-4191" ], "details": "Cisco IOS XR 5.2.1 allows remote attackers to cause a denial of service (ipv6_io service reload) via a malformed IPv6 packet, aka Bug ID CSCuq95565.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5758-xf62-wqrv/GHSA-5758-xf62-wqrv.json b/advisories/unreviewed/2022/05/GHSA-5758-xf62-wqrv/GHSA-5758-xf62-wqrv.json index 59531a0129a..34dec98c8b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-5758-xf62-wqrv/GHSA-5758-xf62-wqrv.json +++ b/advisories/unreviewed/2022/05/GHSA-5758-xf62-wqrv/GHSA-5758-xf62-wqrv.json @@ -7,12 +7,8 @@ "CVE-2015-5778" ], "details": "CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-5777.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5778-f7p4-mgrg/GHSA-5778-f7p4-mgrg.json b/advisories/unreviewed/2022/05/GHSA-5778-f7p4-mgrg/GHSA-5778-f7p4-mgrg.json index 98975486076..c0774a0e434 100644 --- a/advisories/unreviewed/2022/05/GHSA-5778-f7p4-mgrg/GHSA-5778-f7p4-mgrg.json +++ b/advisories/unreviewed/2022/05/GHSA-5778-f7p4-mgrg/GHSA-5778-f7p4-mgrg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-58wr-p3w5-wm2j/GHSA-58wr-p3w5-wm2j.json b/advisories/unreviewed/2022/05/GHSA-58wr-p3w5-wm2j/GHSA-58wr-p3w5-wm2j.json index b56ae663c25..9c15e1f818f 100644 --- a/advisories/unreviewed/2022/05/GHSA-58wr-p3w5-wm2j/GHSA-58wr-p3w5-wm2j.json +++ b/advisories/unreviewed/2022/05/GHSA-58wr-p3w5-wm2j/GHSA-58wr-p3w5-wm2j.json @@ -7,12 +7,8 @@ "CVE-2015-3667" ], "details": "QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, and CVE-2015-3668.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-59r3-hh3x-g9v9/GHSA-59r3-hh3x-g9v9.json b/advisories/unreviewed/2022/05/GHSA-59r3-hh3x-g9v9/GHSA-59r3-hh3x-g9v9.json index 79306338ebc..2ce491f9e08 100644 --- a/advisories/unreviewed/2022/05/GHSA-59r3-hh3x-g9v9/GHSA-59r3-hh3x-g9v9.json +++ b/advisories/unreviewed/2022/05/GHSA-59r3-hh3x-g9v9/GHSA-59r3-hh3x-g9v9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -191,9 +189,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cgv-pmc9-c3v3/GHSA-5cgv-pmc9-c3v3.json b/advisories/unreviewed/2022/05/GHSA-5cgv-pmc9-c3v3/GHSA-5cgv-pmc9-c3v3.json index 750691472a7..da8dd44b7b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cgv-pmc9-c3v3/GHSA-5cgv-pmc9-c3v3.json +++ b/advisories/unreviewed/2022/05/GHSA-5cgv-pmc9-c3v3/GHSA-5cgv-pmc9-c3v3.json @@ -7,12 +7,8 @@ "CVE-2008-3525" ], "details": "The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability before processing a (1) SIOCDEVRESINSTATS, (2) SIOCDEVSHWSTATE, (3) SIOCDEVENSLAVE, or (4) SIOCDEVEMANSIPATE ioctl request, which allows local users to bypass intended capability restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -156,9 +152,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5cx9-pqmm-54rv/GHSA-5cx9-pqmm-54rv.json b/advisories/unreviewed/2022/05/GHSA-5cx9-pqmm-54rv/GHSA-5cx9-pqmm-54rv.json index 5a082df5a9a..f92a678ee31 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cx9-pqmm-54rv/GHSA-5cx9-pqmm-54rv.json +++ b/advisories/unreviewed/2022/05/GHSA-5cx9-pqmm-54rv/GHSA-5cx9-pqmm-54rv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jfx-3759-24jc/GHSA-5jfx-3759-24jc.json b/advisories/unreviewed/2022/05/GHSA-5jfx-3759-24jc/GHSA-5jfx-3759-24jc.json index 5fe22d98865..75d0bb76b2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jfx-3759-24jc/GHSA-5jfx-3759-24jc.json +++ b/advisories/unreviewed/2022/05/GHSA-5jfx-3759-24jc/GHSA-5jfx-3759-24jc.json @@ -7,12 +7,8 @@ "CVE-2015-1113" ], "details": "The Sandbox Profiles component in Apple iOS before 8.3 allows attackers to read the (1) telephone number or (2) e-mail address of a recent contact via a crafted app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5jw5-27jq-vhq7/GHSA-5jw5-27jq-vhq7.json b/advisories/unreviewed/2022/05/GHSA-5jw5-27jq-vhq7/GHSA-5jw5-27jq-vhq7.json index 9bb2859223a..7293aaa0e95 100644 --- a/advisories/unreviewed/2022/05/GHSA-5jw5-27jq-vhq7/GHSA-5jw5-27jq-vhq7.json +++ b/advisories/unreviewed/2022/05/GHSA-5jw5-27jq-vhq7/GHSA-5jw5-27jq-vhq7.json @@ -7,12 +7,8 @@ "CVE-2015-0504" ], "details": "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Error Messages.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5r6c-r963-4qqw/GHSA-5r6c-r963-4qqw.json b/advisories/unreviewed/2022/05/GHSA-5r6c-r963-4qqw/GHSA-5r6c-r963-4qqw.json index c9ac5648090..1b005a250d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r6c-r963-4qqw/GHSA-5r6c-r963-4qqw.json +++ b/advisories/unreviewed/2022/05/GHSA-5r6c-r963-4qqw/GHSA-5r6c-r963-4qqw.json @@ -7,12 +7,8 @@ "CVE-2015-4200" ], "details": "Memory leak in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (memory consumption) by triggering an error during CPE negotiation, aka Bug ID CSCug00885.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vfg-767g-fxph/GHSA-5vfg-767g-fxph.json b/advisories/unreviewed/2022/05/GHSA-5vfg-767g-fxph/GHSA-5vfg-767g-fxph.json index f46e8548efa..4e645d01064 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vfg-767g-fxph/GHSA-5vfg-767g-fxph.json +++ b/advisories/unreviewed/2022/05/GHSA-5vfg-767g-fxph/GHSA-5vfg-767g-fxph.json @@ -7,12 +7,8 @@ "CVE-2015-0489" ], "details": "Unspecified vulnerability in the Application Management Pack for Oracle E-Business Suite component in Oracle E-Business Suite AMP 121030 and 121020 allows local users to affect confidentiality via vectors related to EBS Plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5vv3-jf75-3fr5/GHSA-5vv3-jf75-3fr5.json b/advisories/unreviewed/2022/05/GHSA-5vv3-jf75-3fr5/GHSA-5vv3-jf75-3fr5.json index 7f35794ccec..0e5a40b7356 100644 --- a/advisories/unreviewed/2022/05/GHSA-5vv3-jf75-3fr5/GHSA-5vv3-jf75-3fr5.json +++ b/advisories/unreviewed/2022/05/GHSA-5vv3-jf75-3fr5/GHSA-5vv3-jf75-3fr5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -171,9 +169,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5w35-f3pj-g29q/GHSA-5w35-f3pj-g29q.json b/advisories/unreviewed/2022/05/GHSA-5w35-f3pj-g29q/GHSA-5w35-f3pj-g29q.json index 96ee94c6f3c..b899e1abcea 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w35-f3pj-g29q/GHSA-5w35-f3pj-g29q.json +++ b/advisories/unreviewed/2022/05/GHSA-5w35-f3pj-g29q/GHSA-5w35-f3pj-g29q.json @@ -7,12 +7,8 @@ "CVE-2014-8007" ], "details": "Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML source code of the Quick Discovery options page, aka Bug ID CSCum00019.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5w4h-6c82-38w8/GHSA-5w4h-6c82-38w8.json b/advisories/unreviewed/2022/05/GHSA-5w4h-6c82-38w8/GHSA-5w4h-6c82-38w8.json index 72b773ceeca..28da4dd3e45 100644 --- a/advisories/unreviewed/2022/05/GHSA-5w4h-6c82-38w8/GHSA-5w4h-6c82-38w8.json +++ b/advisories/unreviewed/2022/05/GHSA-5w4h-6c82-38w8/GHSA-5w4h-6c82-38w8.json @@ -7,12 +7,8 @@ "CVE-2015-1938" ], "details": "The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1986.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wmx-f8h4-x4h7/GHSA-5wmx-f8h4-x4h7.json b/advisories/unreviewed/2022/05/GHSA-5wmx-f8h4-x4h7/GHSA-5wmx-f8h4-x4h7.json index 915c1535295..bc74b1dbf39 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wmx-f8h4-x4h7/GHSA-5wmx-f8h4-x4h7.json +++ b/advisories/unreviewed/2022/05/GHSA-5wmx-f8h4-x4h7/GHSA-5wmx-f8h4-x4h7.json @@ -7,12 +7,8 @@ "CVE-2014-8026" ], "details": "Cross-site scripting (XSS) vulnerability in the Guest Server in Cisco Jabber allows remote attackers to inject arbitrary web script or HTML via a (1) GET or (2) POST parameter, aka Bug ID CSCus08074.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5wx4-mvjj-533c/GHSA-5wx4-mvjj-533c.json b/advisories/unreviewed/2022/05/GHSA-5wx4-mvjj-533c/GHSA-5wx4-mvjj-533c.json index dbd0968df37..80e539b7c8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wx4-mvjj-533c/GHSA-5wx4-mvjj-533c.json +++ b/advisories/unreviewed/2022/05/GHSA-5wx4-mvjj-533c/GHSA-5wx4-mvjj-533c.json @@ -7,12 +7,8 @@ "CVE-2005-1767" ], "details": "traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-5x5v-qpmc-45vj/GHSA-5x5v-qpmc-45vj.json b/advisories/unreviewed/2022/05/GHSA-5x5v-qpmc-45vj/GHSA-5x5v-qpmc-45vj.json index 216e9990976..4f43bd9e5ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-5x5v-qpmc-45vj/GHSA-5x5v-qpmc-45vj.json +++ b/advisories/unreviewed/2022/05/GHSA-5x5v-qpmc-45vj/GHSA-5x5v-qpmc-45vj.json @@ -7,12 +7,8 @@ "CVE-2014-4776" ], "details": "IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xmg-w578-gq5j/GHSA-5xmg-w578-gq5j.json b/advisories/unreviewed/2022/05/GHSA-5xmg-w578-gq5j/GHSA-5xmg-w578-gq5j.json index bb3913d4a44..b58f579ca0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xmg-w578-gq5j/GHSA-5xmg-w578-gq5j.json +++ b/advisories/unreviewed/2022/05/GHSA-5xmg-w578-gq5j/GHSA-5xmg-w578-gq5j.json @@ -7,12 +7,8 @@ "CVE-2013-5583" ], "details": "Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-5xv5-5wfh-2gqv/GHSA-5xv5-5wfh-2gqv.json b/advisories/unreviewed/2022/05/GHSA-5xv5-5wfh-2gqv/GHSA-5xv5-5wfh-2gqv.json index d6e13dd4e71..152ad5f0d63 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xv5-5wfh-2gqv/GHSA-5xv5-5wfh-2gqv.json +++ b/advisories/unreviewed/2022/05/GHSA-5xv5-5wfh-2gqv/GHSA-5xv5-5wfh-2gqv.json @@ -7,12 +7,8 @@ "CVE-2015-4768" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, and 6.3.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Diagnostics.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6244-q3jq-rx84/GHSA-6244-q3jq-rx84.json b/advisories/unreviewed/2022/05/GHSA-6244-q3jq-rx84/GHSA-6244-q3jq-rx84.json index 8cf99e298b9..398c1500f46 100644 --- a/advisories/unreviewed/2022/05/GHSA-6244-q3jq-rx84/GHSA-6244-q3jq-rx84.json +++ b/advisories/unreviewed/2022/05/GHSA-6244-q3jq-rx84/GHSA-6244-q3jq-rx84.json @@ -7,12 +7,8 @@ "CVE-2015-1972" ], "details": "IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to obtain sensitive error-log information via a crafted POST request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-638g-4fq4-ffcc/GHSA-638g-4fq4-ffcc.json b/advisories/unreviewed/2022/05/GHSA-638g-4fq4-ffcc/GHSA-638g-4fq4-ffcc.json index 68146745701..1caf76a5a00 100644 --- a/advisories/unreviewed/2022/05/GHSA-638g-4fq4-ffcc/GHSA-638g-4fq4-ffcc.json +++ b/advisories/unreviewed/2022/05/GHSA-638g-4fq4-ffcc/GHSA-638g-4fq4-ffcc.json @@ -7,12 +7,8 @@ "CVE-2015-1091" ], "details": "The CFNetwork Session component in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle request headers during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6393-w7fp-pc5g/GHSA-6393-w7fp-pc5g.json b/advisories/unreviewed/2022/05/GHSA-6393-w7fp-pc5g/GHSA-6393-w7fp-pc5g.json index 3295cde895e..da9d894676c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6393-w7fp-pc5g/GHSA-6393-w7fp-pc5g.json +++ b/advisories/unreviewed/2022/05/GHSA-6393-w7fp-pc5g/GHSA-6393-w7fp-pc5g.json @@ -7,12 +7,8 @@ "CVE-2015-4135" ], "details": "Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-63p6-5792-gpfq/GHSA-63p6-5792-gpfq.json b/advisories/unreviewed/2022/05/GHSA-63p6-5792-gpfq/GHSA-63p6-5792-gpfq.json index 4894815bb58..fd5c4589e0c 100644 --- a/advisories/unreviewed/2022/05/GHSA-63p6-5792-gpfq/GHSA-63p6-5792-gpfq.json +++ b/advisories/unreviewed/2022/05/GHSA-63p6-5792-gpfq/GHSA-63p6-5792-gpfq.json @@ -7,12 +7,8 @@ "CVE-2015-6251" ], "details": "Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6434-hff7-vgp8/GHSA-6434-hff7-vgp8.json b/advisories/unreviewed/2022/05/GHSA-6434-hff7-vgp8/GHSA-6434-hff7-vgp8.json index ed3df67bd95..d5d8af96816 100644 --- a/advisories/unreviewed/2022/05/GHSA-6434-hff7-vgp8/GHSA-6434-hff7-vgp8.json +++ b/advisories/unreviewed/2022/05/GHSA-6434-hff7-vgp8/GHSA-6434-hff7-vgp8.json @@ -7,12 +7,8 @@ "CVE-2008-1676" ], "details": "Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and conduct man-in-the-middle attacks by submitting a certificate signing request (CSR) and using the resulting certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-64q2-rq62-qq2m/GHSA-64q2-rq62-qq2m.json b/advisories/unreviewed/2022/05/GHSA-64q2-rq62-qq2m/GHSA-64q2-rq62-qq2m.json index 887b6642a77..24c37cf2ce5 100644 --- a/advisories/unreviewed/2022/05/GHSA-64q2-rq62-qq2m/GHSA-64q2-rq62-qq2m.json +++ b/advisories/unreviewed/2022/05/GHSA-64q2-rq62-qq2m/GHSA-64q2-rq62-qq2m.json @@ -7,12 +7,8 @@ "CVE-2015-3060" ], "details": "Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, CVE-2015-3073, and CVE-2015-3074.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6522-r5wp-vr5j/GHSA-6522-r5wp-vr5j.json b/advisories/unreviewed/2022/05/GHSA-6522-r5wp-vr5j/GHSA-6522-r5wp-vr5j.json index baac52a99d7..e566b459771 100644 --- a/advisories/unreviewed/2022/05/GHSA-6522-r5wp-vr5j/GHSA-6522-r5wp-vr5j.json +++ b/advisories/unreviewed/2022/05/GHSA-6522-r5wp-vr5j/GHSA-6522-r5wp-vr5j.json @@ -7,12 +7,8 @@ "CVE-2015-6997" ], "details": "The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-65r9-74hc-qwqr/GHSA-65r9-74hc-qwqr.json b/advisories/unreviewed/2022/05/GHSA-65r9-74hc-qwqr/GHSA-65r9-74hc-qwqr.json index 351d81622d5..bed611f2e47 100644 --- a/advisories/unreviewed/2022/05/GHSA-65r9-74hc-qwqr/GHSA-65r9-74hc-qwqr.json +++ b/advisories/unreviewed/2022/05/GHSA-65r9-74hc-qwqr/GHSA-65r9-74hc-qwqr.json @@ -7,12 +7,8 @@ "CVE-2015-1253" ], "details": "core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that appends a child to a SCRIPT element, related to the insert and executeReparentTask functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-65xw-3h2x-5pw4/GHSA-65xw-3h2x-5pw4.json b/advisories/unreviewed/2022/05/GHSA-65xw-3h2x-5pw4/GHSA-65xw-3h2x-5pw4.json index 869ded7bf9d..9fc454ed245 100644 --- a/advisories/unreviewed/2022/05/GHSA-65xw-3h2x-5pw4/GHSA-65xw-3h2x-5pw4.json +++ b/advisories/unreviewed/2022/05/GHSA-65xw-3h2x-5pw4/GHSA-65xw-3h2x-5pw4.json @@ -7,12 +7,8 @@ "CVE-2013-7354" ], "details": "Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png_set_sPLT or (2) png_set_text_2 function, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-66f8-xmpj-j79x/GHSA-66f8-xmpj-j79x.json b/advisories/unreviewed/2022/05/GHSA-66f8-xmpj-j79x/GHSA-66f8-xmpj-j79x.json index 7d9d4048cc4..1c66b9f8e29 100644 --- a/advisories/unreviewed/2022/05/GHSA-66f8-xmpj-j79x/GHSA-66f8-xmpj-j79x.json +++ b/advisories/unreviewed/2022/05/GHSA-66f8-xmpj-j79x/GHSA-66f8-xmpj-j79x.json @@ -7,12 +7,8 @@ "CVE-2015-7023" ], "details": "CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-67f8-82xm-cq7m/GHSA-67f8-82xm-cq7m.json b/advisories/unreviewed/2022/05/GHSA-67f8-82xm-cq7m/GHSA-67f8-82xm-cq7m.json index daca65d737f..6c628003e7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-67f8-82xm-cq7m/GHSA-67f8-82xm-cq7m.json +++ b/advisories/unreviewed/2022/05/GHSA-67f8-82xm-cq7m/GHSA-67f8-82xm-cq7m.json @@ -7,12 +7,8 @@ "CVE-2015-2221" ], "details": "ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-67j3-xx8m-3q6v/GHSA-67j3-xx8m-3q6v.json b/advisories/unreviewed/2022/05/GHSA-67j3-xx8m-3q6v/GHSA-67j3-xx8m-3q6v.json index 827b67bcd6a..968df6880c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-67j3-xx8m-3q6v/GHSA-67j3-xx8m-3q6v.json +++ b/advisories/unreviewed/2022/05/GHSA-67j3-xx8m-3q6v/GHSA-67j3-xx8m-3q6v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-67jj-2hgw-486p/GHSA-67jj-2hgw-486p.json b/advisories/unreviewed/2022/05/GHSA-67jj-2hgw-486p/GHSA-67jj-2hgw-486p.json index b634e19e38f..fa4a72c42d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-67jj-2hgw-486p/GHSA-67jj-2hgw-486p.json +++ b/advisories/unreviewed/2022/05/GHSA-67jj-2hgw-486p/GHSA-67jj-2hgw-486p.json @@ -7,12 +7,8 @@ "CVE-2007-5962" ], "details": "Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -100,9 +96,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fj3-qfgx-97c3/GHSA-6fj3-qfgx-97c3.json b/advisories/unreviewed/2022/05/GHSA-6fj3-qfgx-97c3/GHSA-6fj3-qfgx-97c3.json index cab987f1aeb..0d13ea74d9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fj3-qfgx-97c3/GHSA-6fj3-qfgx-97c3.json +++ b/advisories/unreviewed/2022/05/GHSA-6fj3-qfgx-97c3/GHSA-6fj3-qfgx-97c3.json @@ -7,12 +7,8 @@ "CVE-2005-3053" ], "details": "The sys_set_mempolicy function in mempolicy.c in Linux kernel 2.6.x allows local users to cause a denial of service (kernel BUG()) via a negative first argument.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6h5v-qgqr-fmq8/GHSA-6h5v-qgqr-fmq8.json b/advisories/unreviewed/2022/05/GHSA-6h5v-qgqr-fmq8/GHSA-6h5v-qgqr-fmq8.json index 4898ed5dbc6..1515cca036e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6h5v-qgqr-fmq8/GHSA-6h5v-qgqr-fmq8.json +++ b/advisories/unreviewed/2022/05/GHSA-6h5v-qgqr-fmq8/GHSA-6h5v-qgqr-fmq8.json @@ -7,12 +7,8 @@ "CVE-2005-2700" ], "details": "ssl_engine_kernel.c in mod_ssl before 2.8.24, when using \"SSLVerifyClient optional\" in the global virtual host configuration, does not properly enforce \"SSLVerifyClient require\" in a per-location context, which allows remote attackers to bypass intended access restrictions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -332,9 +328,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6hg3-w88w-4r8v/GHSA-6hg3-w88w-4r8v.json b/advisories/unreviewed/2022/05/GHSA-6hg3-w88w-4r8v/GHSA-6hg3-w88w-4r8v.json index 99669d2e226..34c704b3ac0 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hg3-w88w-4r8v/GHSA-6hg3-w88w-4r8v.json +++ b/advisories/unreviewed/2022/05/GHSA-6hg3-w88w-4r8v/GHSA-6hg3-w88w-4r8v.json @@ -7,12 +7,8 @@ "CVE-2015-5121" ], "details": "Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5120.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6hhj-4h22-mrmm/GHSA-6hhj-4h22-mrmm.json b/advisories/unreviewed/2022/05/GHSA-6hhj-4h22-mrmm/GHSA-6hhj-4h22-mrmm.json index dcc66c46a9c..4abde696725 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hhj-4h22-mrmm/GHSA-6hhj-4h22-mrmm.json +++ b/advisories/unreviewed/2022/05/GHSA-6hhj-4h22-mrmm/GHSA-6hhj-4h22-mrmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6jp9-5rjr-5x66/GHSA-6jp9-5rjr-5x66.json b/advisories/unreviewed/2022/05/GHSA-6jp9-5rjr-5x66/GHSA-6jp9-5rjr-5x66.json index d92f41fc1e5..de9f2226a0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jp9-5rjr-5x66/GHSA-6jp9-5rjr-5x66.json +++ b/advisories/unreviewed/2022/05/GHSA-6jp9-5rjr-5x66/GHSA-6jp9-5rjr-5x66.json @@ -7,12 +7,8 @@ "CVE-2014-7924" ], "details": "Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering duplicate BLOB references, related to content/browser/indexed_db/indexed_db_callbacks.cc and content/browser/indexed_db/indexed_db_dispatcher_host.cc.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6qp9-77cv-mjx6/GHSA-6qp9-77cv-mjx6.json b/advisories/unreviewed/2022/05/GHSA-6qp9-77cv-mjx6/GHSA-6qp9-77cv-mjx6.json index d63c996577f..7bbe57fcde2 100644 --- a/advisories/unreviewed/2022/05/GHSA-6qp9-77cv-mjx6/GHSA-6qp9-77cv-mjx6.json +++ b/advisories/unreviewed/2022/05/GHSA-6qp9-77cv-mjx6/GHSA-6qp9-77cv-mjx6.json @@ -7,12 +7,8 @@ "CVE-2015-0455" ], "details": "Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6r4r-2j3q-9qvm/GHSA-6r4r-2j3q-9qvm.json b/advisories/unreviewed/2022/05/GHSA-6r4r-2j3q-9qvm/GHSA-6r4r-2j3q-9qvm.json index 1d07a08acda..53f906a4e12 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r4r-2j3q-9qvm/GHSA-6r4r-2j3q-9qvm.json +++ b/advisories/unreviewed/2022/05/GHSA-6r4r-2j3q-9qvm/GHSA-6r4r-2j3q-9qvm.json @@ -7,12 +7,8 @@ "CVE-2015-1880" ], "details": "Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6r89-gjq3-65ww/GHSA-6r89-gjq3-65ww.json b/advisories/unreviewed/2022/05/GHSA-6r89-gjq3-65ww/GHSA-6r89-gjq3-65ww.json index 2bb4769bb03..b782bb3f2b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6r89-gjq3-65ww/GHSA-6r89-gjq3-65ww.json +++ b/advisories/unreviewed/2022/05/GHSA-6r89-gjq3-65ww/GHSA-6r89-gjq3-65ww.json @@ -7,12 +7,8 @@ "CVE-2015-4271" ], "details": "Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request parameters, aka Bug ID CSCuv00604.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6rw5-p447-f2w5/GHSA-6rw5-p447-f2w5.json b/advisories/unreviewed/2022/05/GHSA-6rw5-p447-f2w5/GHSA-6rw5-p447-f2w5.json index 73ac5af85f1..9ae193d564c 100644 --- a/advisories/unreviewed/2022/05/GHSA-6rw5-p447-f2w5/GHSA-6rw5-p447-f2w5.json +++ b/advisories/unreviewed/2022/05/GHSA-6rw5-p447-f2w5/GHSA-6rw5-p447-f2w5.json @@ -7,12 +7,8 @@ "CVE-2015-0545" ], "details": "EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6v5w-2xvc-ghhh/GHSA-6v5w-2xvc-ghhh.json b/advisories/unreviewed/2022/05/GHSA-6v5w-2xvc-ghhh/GHSA-6v5w-2xvc-ghhh.json index 75baae99c19..6779ad90d87 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v5w-2xvc-ghhh/GHSA-6v5w-2xvc-ghhh.json +++ b/advisories/unreviewed/2022/05/GHSA-6v5w-2xvc-ghhh/GHSA-6v5w-2xvc-ghhh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6v7j-g6x9-qr7q/GHSA-6v7j-g6x9-qr7q.json b/advisories/unreviewed/2022/05/GHSA-6v7j-g6x9-qr7q/GHSA-6v7j-g6x9-qr7q.json index 72443d3732e..750ba092a23 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v7j-g6x9-qr7q/GHSA-6v7j-g6x9-qr7q.json +++ b/advisories/unreviewed/2022/05/GHSA-6v7j-g6x9-qr7q/GHSA-6v7j-g6x9-qr7q.json @@ -7,12 +7,8 @@ "CVE-2015-1264" ], "details": "Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted data that is improperly handled by the Bookmarks feature.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6w8p-2vvx-465g/GHSA-6w8p-2vvx-465g.json b/advisories/unreviewed/2022/05/GHSA-6w8p-2vvx-465g/GHSA-6w8p-2vvx-465g.json index 8cb467c22ee..439bab68e0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6w8p-2vvx-465g/GHSA-6w8p-2vvx-465g.json +++ b/advisories/unreviewed/2022/05/GHSA-6w8p-2vvx-465g/GHSA-6w8p-2vvx-465g.json @@ -7,12 +7,8 @@ "CVE-2015-5931" ], "details": "WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6wg2-x2g7-grw8/GHSA-6wg2-x2g7-grw8.json b/advisories/unreviewed/2022/05/GHSA-6wg2-x2g7-grw8/GHSA-6wg2-x2g7-grw8.json index f588aaad562..f9070f03d17 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wg2-x2g7-grw8/GHSA-6wg2-x2g7-grw8.json +++ b/advisories/unreviewed/2022/05/GHSA-6wg2-x2g7-grw8/GHSA-6wg2-x2g7-grw8.json @@ -7,12 +7,8 @@ "CVE-2015-0463" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, and 6.3.6 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6wq9-m5r8-4gq4/GHSA-6wq9-m5r8-4gq4.json b/advisories/unreviewed/2022/05/GHSA-6wq9-m5r8-4gq4/GHSA-6wq9-m5r8-4gq4.json index 39aaa840c4c..9ba20223137 100644 --- a/advisories/unreviewed/2022/05/GHSA-6wq9-m5r8-4gq4/GHSA-6wq9-m5r8-4gq4.json +++ b/advisories/unreviewed/2022/05/GHSA-6wq9-m5r8-4gq4/GHSA-6wq9-m5r8-4gq4.json @@ -7,12 +7,8 @@ "CVE-2011-4305" ], "details": "message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6x2f-ww2h-jg5g/GHSA-6x2f-ww2h-jg5g.json b/advisories/unreviewed/2022/05/GHSA-6x2f-ww2h-jg5g/GHSA-6x2f-ww2h-jg5g.json index b1fd6d3ab13..d109c52c684 100644 --- a/advisories/unreviewed/2022/05/GHSA-6x2f-ww2h-jg5g/GHSA-6x2f-ww2h-jg5g.json +++ b/advisories/unreviewed/2022/05/GHSA-6x2f-ww2h-jg5g/GHSA-6x2f-ww2h-jg5g.json @@ -7,12 +7,8 @@ "CVE-2013-5951" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-6xxp-p3pp-qrxg/GHSA-6xxp-p3pp-qrxg.json b/advisories/unreviewed/2022/05/GHSA-6xxp-p3pp-qrxg/GHSA-6xxp-p3pp-qrxg.json index ffd669f84d1..7e65604ee22 100644 --- a/advisories/unreviewed/2022/05/GHSA-6xxp-p3pp-qrxg/GHSA-6xxp-p3pp-qrxg.json +++ b/advisories/unreviewed/2022/05/GHSA-6xxp-p3pp-qrxg/GHSA-6xxp-p3pp-qrxg.json @@ -7,12 +7,8 @@ "CVE-2013-7293" ], "details": "The ASUS WL-330NUL router has a configuration process that relies on accessing the 192.168.1.1 IP address, but the documentation advises users to instead access a DNS hostname that does not always resolve to 192.168.1.1, which makes it easier for remote attackers to hijack the configuration traffic by controlling the server associated with that hostname.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72qj-6vqg-mprg/GHSA-72qj-6vqg-mprg.json b/advisories/unreviewed/2022/05/GHSA-72qj-6vqg-mprg/GHSA-72qj-6vqg-mprg.json index bda39b9faf1..81ae672fd5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-72qj-6vqg-mprg/GHSA-72qj-6vqg-mprg.json +++ b/advisories/unreviewed/2022/05/GHSA-72qj-6vqg-mprg/GHSA-72qj-6vqg-mprg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7352-jw4q-788p/GHSA-7352-jw4q-788p.json b/advisories/unreviewed/2022/05/GHSA-7352-jw4q-788p/GHSA-7352-jw4q-788p.json index a22d8c605e4..e7f27088cb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7352-jw4q-788p/GHSA-7352-jw4q-788p.json +++ b/advisories/unreviewed/2022/05/GHSA-7352-jw4q-788p/GHSA-7352-jw4q-788p.json @@ -7,12 +7,8 @@ "CVE-2015-1205" ], "details": "Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -188,9 +184,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-73pg-2qfc-2cfm/GHSA-73pg-2qfc-2cfm.json b/advisories/unreviewed/2022/05/GHSA-73pg-2qfc-2cfm/GHSA-73pg-2qfc-2cfm.json index 1b9c3e6603e..88173367e8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-73pg-2qfc-2cfm/GHSA-73pg-2qfc-2cfm.json +++ b/advisories/unreviewed/2022/05/GHSA-73pg-2qfc-2cfm/GHSA-73pg-2qfc-2cfm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-74cg-22qc-9jv5/GHSA-74cg-22qc-9jv5.json b/advisories/unreviewed/2022/05/GHSA-74cg-22qc-9jv5/GHSA-74cg-22qc-9jv5.json index 7573b30907a..31093b82319 100644 --- a/advisories/unreviewed/2022/05/GHSA-74cg-22qc-9jv5/GHSA-74cg-22qc-9jv5.json +++ b/advisories/unreviewed/2022/05/GHSA-74cg-22qc-9jv5/GHSA-74cg-22qc-9jv5.json @@ -7,12 +7,8 @@ "CVE-2015-3078" ], "details": "Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3089, CVE-2015-3090, and CVE-2015-3093.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-75mc-jhf7-g4w6/GHSA-75mc-jhf7-g4w6.json b/advisories/unreviewed/2022/05/GHSA-75mc-jhf7-g4w6/GHSA-75mc-jhf7-g4w6.json index 18edb0147df..6aa7079fb02 100644 --- a/advisories/unreviewed/2022/05/GHSA-75mc-jhf7-g4w6/GHSA-75mc-jhf7-g4w6.json +++ b/advisories/unreviewed/2022/05/GHSA-75mc-jhf7-g4w6/GHSA-75mc-jhf7-g4w6.json @@ -7,12 +7,8 @@ "CVE-2015-5775" ], "details": "FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and CVE-2015-5756.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-76h4-r3r3-f9xr/GHSA-76h4-r3r3-f9xr.json b/advisories/unreviewed/2022/05/GHSA-76h4-r3r3-f9xr/GHSA-76h4-r3r3-f9xr.json index 7b33772a043..de98577bd26 100644 --- a/advisories/unreviewed/2022/05/GHSA-76h4-r3r3-f9xr/GHSA-76h4-r3r3-f9xr.json +++ b/advisories/unreviewed/2022/05/GHSA-76h4-r3r3-f9xr/GHSA-76h4-r3r3-f9xr.json @@ -7,12 +7,8 @@ "CVE-2015-0456" ], "details": "Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to Portlet Services.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-76jw-wfj8-85m2/GHSA-76jw-wfj8-85m2.json b/advisories/unreviewed/2022/05/GHSA-76jw-wfj8-85m2/GHSA-76jw-wfj8-85m2.json index 7b4162ddd91..87a3f9c647e 100644 --- a/advisories/unreviewed/2022/05/GHSA-76jw-wfj8-85m2/GHSA-76jw-wfj8-85m2.json +++ b/advisories/unreviewed/2022/05/GHSA-76jw-wfj8-85m2/GHSA-76jw-wfj8-85m2.json @@ -7,12 +7,8 @@ "CVE-2015-3108" ], "details": "Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-775r-5j4x-p42j/GHSA-775r-5j4x-p42j.json b/advisories/unreviewed/2022/05/GHSA-775r-5j4x-p42j/GHSA-775r-5j4x-p42j.json index 5f00eef8f55..f991ada46a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-775r-5j4x-p42j/GHSA-775r-5j4x-p42j.json +++ b/advisories/unreviewed/2022/05/GHSA-775r-5j4x-p42j/GHSA-775r-5j4x-p42j.json @@ -7,12 +7,8 @@ "CVE-2015-4216" ], "details": "The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH root authorized key across different customers' installations, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of a private key from another installation, aka Bug IDs CSCuu95988, CSCuu95994, and CSCuu96630.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-776w-xwhq-5f9f/GHSA-776w-xwhq-5f9f.json b/advisories/unreviewed/2022/05/GHSA-776w-xwhq-5f9f/GHSA-776w-xwhq-5f9f.json index 11bfbb07fd4..fe0b968c24d 100644 --- a/advisories/unreviewed/2022/05/GHSA-776w-xwhq-5f9f/GHSA-776w-xwhq-5f9f.json +++ b/advisories/unreviewed/2022/05/GHSA-776w-xwhq-5f9f/GHSA-776w-xwhq-5f9f.json @@ -7,12 +7,8 @@ "CVE-2015-1108" ], "details": "The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77j3-h7w3-qqv7/GHSA-77j3-h7w3-qqv7.json b/advisories/unreviewed/2022/05/GHSA-77j3-h7w3-qqv7/GHSA-77j3-h7w3-qqv7.json index 4c79a25be8a..e084d40fea8 100644 --- a/advisories/unreviewed/2022/05/GHSA-77j3-h7w3-qqv7/GHSA-77j3-h7w3-qqv7.json +++ b/advisories/unreviewed/2022/05/GHSA-77j3-h7w3-qqv7/GHSA-77j3-h7w3-qqv7.json @@ -7,12 +7,8 @@ "CVE-2015-3921" ], "details": "Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-77vm-c9cv-mmrv/GHSA-77vm-c9cv-mmrv.json b/advisories/unreviewed/2022/05/GHSA-77vm-c9cv-mmrv/GHSA-77vm-c9cv-mmrv.json index 23e2e3d47a9..02f8cf42b03 100644 --- a/advisories/unreviewed/2022/05/GHSA-77vm-c9cv-mmrv/GHSA-77vm-c9cv-mmrv.json +++ b/advisories/unreviewed/2022/05/GHSA-77vm-c9cv-mmrv/GHSA-77vm-c9cv-mmrv.json @@ -7,12 +7,8 @@ "CVE-2015-7010" ], "details": "FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-788g-cj2v-3f95/GHSA-788g-cj2v-3f95.json b/advisories/unreviewed/2022/05/GHSA-788g-cj2v-3f95/GHSA-788g-cj2v-3f95.json index 861a2320ae3..4a4bacfdcbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-788g-cj2v-3f95/GHSA-788g-cj2v-3f95.json +++ b/advisories/unreviewed/2022/05/GHSA-788g-cj2v-3f95/GHSA-788g-cj2v-3f95.json @@ -7,12 +7,8 @@ "CVE-2015-0343" ], "details": "Cross-site scripting (XSS) vulnerability in admin/home/homepage/search in the web app in Adobe Connect before 9.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-78h8-qhmw-gr92/GHSA-78h8-qhmw-gr92.json b/advisories/unreviewed/2022/05/GHSA-78h8-qhmw-gr92/GHSA-78h8-qhmw-gr92.json index 0dde3853e0e..fc531155fc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-78h8-qhmw-gr92/GHSA-78h8-qhmw-gr92.json +++ b/advisories/unreviewed/2022/05/GHSA-78h8-qhmw-gr92/GHSA-78h8-qhmw-gr92.json @@ -7,12 +7,8 @@ "CVE-2015-1263" ], "details": "The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78q2-gpgm-j9wf/GHSA-78q2-gpgm-j9wf.json b/advisories/unreviewed/2022/05/GHSA-78q2-gpgm-j9wf/GHSA-78q2-gpgm-j9wf.json index be97b968904..1ff0bae9749 100644 --- a/advisories/unreviewed/2022/05/GHSA-78q2-gpgm-j9wf/GHSA-78q2-gpgm-j9wf.json +++ b/advisories/unreviewed/2022/05/GHSA-78q2-gpgm-j9wf/GHSA-78q2-gpgm-j9wf.json @@ -7,12 +7,8 @@ "CVE-2015-1804" ], "details": "The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via a crafted BDF font file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-78qg-q6hh-66c3/GHSA-78qg-q6hh-66c3.json b/advisories/unreviewed/2022/05/GHSA-78qg-q6hh-66c3/GHSA-78qg-q6hh-66c3.json index 7be7de38fc8..c59bdd0373f 100644 --- a/advisories/unreviewed/2022/05/GHSA-78qg-q6hh-66c3/GHSA-78qg-q6hh-66c3.json +++ b/advisories/unreviewed/2022/05/GHSA-78qg-q6hh-66c3/GHSA-78qg-q6hh-66c3.json @@ -7,12 +7,8 @@ "CVE-2015-5752" ], "details": "Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-79m3-pjgp-p5fq/GHSA-79m3-pjgp-p5fq.json b/advisories/unreviewed/2022/05/GHSA-79m3-pjgp-p5fq/GHSA-79m3-pjgp-p5fq.json index 612a11be5e8..62d26714121 100644 --- a/advisories/unreviewed/2022/05/GHSA-79m3-pjgp-p5fq/GHSA-79m3-pjgp-p5fq.json +++ b/advisories/unreviewed/2022/05/GHSA-79m3-pjgp-p5fq/GHSA-79m3-pjgp-p5fq.json @@ -7,12 +7,8 @@ "CVE-2015-1237" ], "details": "Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger renderer IPC messages during a detach operation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7c78-wvwc-9rw6/GHSA-7c78-wvwc-9rw6.json b/advisories/unreviewed/2022/05/GHSA-7c78-wvwc-9rw6/GHSA-7c78-wvwc-9rw6.json index c08c5349a06..e30cef38813 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c78-wvwc-9rw6/GHSA-7c78-wvwc-9rw6.json +++ b/advisories/unreviewed/2022/05/GHSA-7c78-wvwc-9rw6/GHSA-7c78-wvwc-9rw6.json @@ -7,12 +7,8 @@ "CVE-2015-4218" ], "details": "The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f26-wwp8-67rw/GHSA-7f26-wwp8-67rw.json b/advisories/unreviewed/2022/05/GHSA-7f26-wwp8-67rw/GHSA-7f26-wwp8-67rw.json index 415dd8d370f..2af3dbf5fc2 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f26-wwp8-67rw/GHSA-7f26-wwp8-67rw.json +++ b/advisories/unreviewed/2022/05/GHSA-7f26-wwp8-67rw/GHSA-7f26-wwp8-67rw.json @@ -7,12 +7,8 @@ "CVE-2015-3727" ], "details": "WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web site's database via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7f56-hqg2-6pm8/GHSA-7f56-hqg2-6pm8.json b/advisories/unreviewed/2022/05/GHSA-7f56-hqg2-6pm8/GHSA-7f56-hqg2-6pm8.json index d2e946fed11..d8868951b40 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f56-hqg2-6pm8/GHSA-7f56-hqg2-6pm8.json +++ b/advisories/unreviewed/2022/05/GHSA-7f56-hqg2-6pm8/GHSA-7f56-hqg2-6pm8.json @@ -7,12 +7,8 @@ "CVE-2015-0401" ], "details": "Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusion Middleware 7.0 and 11.1.1.7 allows remote authenticated users to affect integrity via unknown vectors related to Admin Console.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7f5w-fj39-gxxh/GHSA-7f5w-fj39-gxxh.json b/advisories/unreviewed/2022/05/GHSA-7f5w-fj39-gxxh/GHSA-7f5w-fj39-gxxh.json index 106d8b0aa5f..154174b7e8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f5w-fj39-gxxh/GHSA-7f5w-fj39-gxxh.json +++ b/advisories/unreviewed/2022/05/GHSA-7f5w-fj39-gxxh/GHSA-7f5w-fj39-gxxh.json @@ -7,12 +7,8 @@ "CVE-2015-1484" ], "details": "Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7f6f-5883-mmhm/GHSA-7f6f-5883-mmhm.json b/advisories/unreviewed/2022/05/GHSA-7f6f-5883-mmhm/GHSA-7f6f-5883-mmhm.json index cf0cfd201d8..39a6f00fb73 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f6f-5883-mmhm/GHSA-7f6f-5883-mmhm.json +++ b/advisories/unreviewed/2022/05/GHSA-7f6f-5883-mmhm/GHSA-7f6f-5883-mmhm.json @@ -7,12 +7,8 @@ "CVE-2013-4474" ], "details": "Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7f78-v2g2-6j4v/GHSA-7f78-v2g2-6j4v.json b/advisories/unreviewed/2022/05/GHSA-7f78-v2g2-6j4v/GHSA-7f78-v2g2-6j4v.json index dfc56d12a37..7daed0278a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7f78-v2g2-6j4v/GHSA-7f78-v2g2-6j4v.json +++ b/advisories/unreviewed/2022/05/GHSA-7f78-v2g2-6j4v/GHSA-7f78-v2g2-6j4v.json @@ -7,12 +7,8 @@ "CVE-2015-1963" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1964, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7g2f-f5p3-7xg4/GHSA-7g2f-f5p3-7xg4.json b/advisories/unreviewed/2022/05/GHSA-7g2f-f5p3-7xg4/GHSA-7g2f-f5p3-7xg4.json index 70f0412c06f..51937a53812 100644 --- a/advisories/unreviewed/2022/05/GHSA-7g2f-f5p3-7xg4/GHSA-7g2f-f5p3-7xg4.json +++ b/advisories/unreviewed/2022/05/GHSA-7g2f-f5p3-7xg4/GHSA-7g2f-f5p3-7xg4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7j5x-jvxx-9cf2/GHSA-7j5x-jvxx-9cf2.json b/advisories/unreviewed/2022/05/GHSA-7j5x-jvxx-9cf2/GHSA-7j5x-jvxx-9cf2.json index f655d2a0396..a7c1c2ef470 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j5x-jvxx-9cf2/GHSA-7j5x-jvxx-9cf2.json +++ b/advisories/unreviewed/2022/05/GHSA-7j5x-jvxx-9cf2/GHSA-7j5x-jvxx-9cf2.json @@ -7,12 +7,8 @@ "CVE-2015-3923" ], "details": "Coppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j76-ppf8-pw3x/GHSA-7j76-ppf8-pw3x.json b/advisories/unreviewed/2022/05/GHSA-7j76-ppf8-pw3x/GHSA-7j76-ppf8-pw3x.json index 7161c086434..a5a5218d778 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j76-ppf8-pw3x/GHSA-7j76-ppf8-pw3x.json +++ b/advisories/unreviewed/2022/05/GHSA-7j76-ppf8-pw3x/GHSA-7j76-ppf8-pw3x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7j82-f7g7-28w2/GHSA-7j82-f7g7-28w2.json b/advisories/unreviewed/2022/05/GHSA-7j82-f7g7-28w2/GHSA-7j82-f7g7-28w2.json index 2ecc9ca3656..f12c069c99e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7j82-f7g7-28w2/GHSA-7j82-f7g7-28w2.json +++ b/advisories/unreviewed/2022/05/GHSA-7j82-f7g7-28w2/GHSA-7j82-f7g7-28w2.json @@ -7,12 +7,8 @@ "CVE-2015-3345" ], "details": "SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the \"phpList database.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7jwx-cjhh-mfjj/GHSA-7jwx-cjhh-mfjj.json b/advisories/unreviewed/2022/05/GHSA-7jwx-cjhh-mfjj/GHSA-7jwx-cjhh-mfjj.json index 28d0f5f2132..4e93ae2e2c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7jwx-cjhh-mfjj/GHSA-7jwx-cjhh-mfjj.json +++ b/advisories/unreviewed/2022/05/GHSA-7jwx-cjhh-mfjj/GHSA-7jwx-cjhh-mfjj.json @@ -7,12 +7,8 @@ "CVE-2014-8025" ], "details": "The API in the Guest Server in Cisco Jabber, when HTML5 is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST response, aka Bug ID CSCus19801.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7m2w-hp2f-cmqp/GHSA-7m2w-hp2f-cmqp.json b/advisories/unreviewed/2022/05/GHSA-7m2w-hp2f-cmqp/GHSA-7m2w-hp2f-cmqp.json index d48119b6763..e2f69d73384 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m2w-hp2f-cmqp/GHSA-7m2w-hp2f-cmqp.json +++ b/advisories/unreviewed/2022/05/GHSA-7m2w-hp2f-cmqp/GHSA-7m2w-hp2f-cmqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -79,9 +77,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7m5g-q9fx-rh4c/GHSA-7m5g-q9fx-rh4c.json b/advisories/unreviewed/2022/05/GHSA-7m5g-q9fx-rh4c/GHSA-7m5g-q9fx-rh4c.json index ded5129af60..c382a053205 100644 --- a/advisories/unreviewed/2022/05/GHSA-7m5g-q9fx-rh4c/GHSA-7m5g-q9fx-rh4c.json +++ b/advisories/unreviewed/2022/05/GHSA-7m5g-q9fx-rh4c/GHSA-7m5g-q9fx-rh4c.json @@ -7,12 +7,8 @@ "CVE-2015-5889" ], "details": "rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7mgv-2hpg-78mr/GHSA-7mgv-2hpg-78mr.json b/advisories/unreviewed/2022/05/GHSA-7mgv-2hpg-78mr/GHSA-7mgv-2hpg-78mr.json index c149c33fa48..44f03dfd998 100644 --- a/advisories/unreviewed/2022/05/GHSA-7mgv-2hpg-78mr/GHSA-7mgv-2hpg-78mr.json +++ b/advisories/unreviewed/2022/05/GHSA-7mgv-2hpg-78mr/GHSA-7mgv-2hpg-78mr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7ppr-679p-72mg/GHSA-7ppr-679p-72mg.json b/advisories/unreviewed/2022/05/GHSA-7ppr-679p-72mg/GHSA-7ppr-679p-72mg.json index 19d405f72ac..3fd94ec81b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7ppr-679p-72mg/GHSA-7ppr-679p-72mg.json +++ b/advisories/unreviewed/2022/05/GHSA-7ppr-679p-72mg/GHSA-7ppr-679p-72mg.json @@ -7,12 +7,8 @@ "CVE-2015-5769" ], "details": "The MSVDX driver in Apple iOS before 8.4.1 allows remote attackers to cause a denial of service (device crash) via a crafted video.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7q52-2r47-35qw/GHSA-7q52-2r47-35qw.json b/advisories/unreviewed/2022/05/GHSA-7q52-2r47-35qw/GHSA-7q52-2r47-35qw.json index 23415abb1b7..6afdc51635c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q52-2r47-35qw/GHSA-7q52-2r47-35qw.json +++ b/advisories/unreviewed/2022/05/GHSA-7q52-2r47-35qw/GHSA-7q52-2r47-35qw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7q7r-w4pq-v5q2/GHSA-7q7r-w4pq-v5q2.json b/advisories/unreviewed/2022/05/GHSA-7q7r-w4pq-v5q2/GHSA-7q7r-w4pq-v5q2.json index aaa19af1593..6f590ed4361 100644 --- a/advisories/unreviewed/2022/05/GHSA-7q7r-w4pq-v5q2/GHSA-7q7r-w4pq-v5q2.json +++ b/advisories/unreviewed/2022/05/GHSA-7q7r-w4pq-v5q2/GHSA-7q7r-w4pq-v5q2.json @@ -7,12 +7,8 @@ "CVE-2015-1261" ], "details": "android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7r9p-c88x-w357/GHSA-7r9p-c88x-w357.json b/advisories/unreviewed/2022/05/GHSA-7r9p-c88x-w357/GHSA-7r9p-c88x-w357.json index 22afe28baa8..08f13d37740 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r9p-c88x-w357/GHSA-7r9p-c88x-w357.json +++ b/advisories/unreviewed/2022/05/GHSA-7r9p-c88x-w357/GHSA-7r9p-c88x-w357.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7v79-m7r5-h737/GHSA-7v79-m7r5-h737.json b/advisories/unreviewed/2022/05/GHSA-7v79-m7r5-h737/GHSA-7v79-m7r5-h737.json index fbccbc4b084..18baa6e20e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-7v79-m7r5-h737/GHSA-7v79-m7r5-h737.json +++ b/advisories/unreviewed/2022/05/GHSA-7v79-m7r5-h737/GHSA-7v79-m7r5-h737.json @@ -7,12 +7,8 @@ "CVE-2014-7948" ], "details": "The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows man-in-the-middle attackers to spoof HTML5 application content via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7vpp-g24v-jrr2/GHSA-7vpp-g24v-jrr2.json b/advisories/unreviewed/2022/05/GHSA-7vpp-g24v-jrr2/GHSA-7vpp-g24v-jrr2.json index 146b9ac9d1f..125ee24e21a 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vpp-g24v-jrr2/GHSA-7vpp-g24v-jrr2.json +++ b/advisories/unreviewed/2022/05/GHSA-7vpp-g24v-jrr2/GHSA-7vpp-g24v-jrr2.json @@ -7,12 +7,8 @@ "CVE-2015-5928" ], "details": "WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-7vwv-c4f9-4xwx/GHSA-7vwv-c4f9-4xwx.json b/advisories/unreviewed/2022/05/GHSA-7vwv-c4f9-4xwx/GHSA-7vwv-c4f9-4xwx.json index 431d2885db2..5cfb3d46029 100644 --- a/advisories/unreviewed/2022/05/GHSA-7vwv-c4f9-4xwx/GHSA-7vwv-c4f9-4xwx.json +++ b/advisories/unreviewed/2022/05/GHSA-7vwv-c4f9-4xwx/GHSA-7vwv-c4f9-4xwx.json @@ -7,12 +7,8 @@ "CVE-2015-1803" ], "details": "The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7w75-mgjq-f5m7/GHSA-7w75-mgjq-f5m7.json b/advisories/unreviewed/2022/05/GHSA-7w75-mgjq-f5m7/GHSA-7w75-mgjq-f5m7.json index 25abe0f6ef4..118c018a4dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w75-mgjq-f5m7/GHSA-7w75-mgjq-f5m7.json +++ b/advisories/unreviewed/2022/05/GHSA-7w75-mgjq-f5m7/GHSA-7w75-mgjq-f5m7.json @@ -7,12 +7,8 @@ "CVE-2015-3658" ], "details": "The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, which makes it easier for remote attackers to bypass CSRF protection mechanisms via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7wmj-q9mp-9x7x/GHSA-7wmj-q9mp-9x7x.json b/advisories/unreviewed/2022/05/GHSA-7wmj-q9mp-9x7x/GHSA-7wmj-q9mp-9x7x.json index 797f8dfc77f..6d0bac83cb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wmj-q9mp-9x7x/GHSA-7wmj-q9mp-9x7x.json +++ b/advisories/unreviewed/2022/05/GHSA-7wmj-q9mp-9x7x/GHSA-7wmj-q9mp-9x7x.json @@ -7,12 +7,8 @@ "CVE-2015-2741" ], "details": "Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7wx4-2c6r-76ww/GHSA-7wx4-2c6r-76ww.json b/advisories/unreviewed/2022/05/GHSA-7wx4-2c6r-76ww/GHSA-7wx4-2c6r-76ww.json index 184c23c84ab..f742009af52 100644 --- a/advisories/unreviewed/2022/05/GHSA-7wx4-2c6r-76ww/GHSA-7wx4-2c6r-76ww.json +++ b/advisories/unreviewed/2022/05/GHSA-7wx4-2c6r-76ww/GHSA-7wx4-2c6r-76ww.json @@ -7,12 +7,8 @@ "CVE-2015-2959" ], "details": "Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or remove accounts by leveraging the guest role.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-828x-j4vq-7vw7/GHSA-828x-j4vq-7vw7.json b/advisories/unreviewed/2022/05/GHSA-828x-j4vq-7vw7/GHSA-828x-j4vq-7vw7.json index f20915c09d6..1fbbeead128 100644 --- a/advisories/unreviewed/2022/05/GHSA-828x-j4vq-7vw7/GHSA-828x-j4vq-7vw7.json +++ b/advisories/unreviewed/2022/05/GHSA-828x-j4vq-7vw7/GHSA-828x-j4vq-7vw7.json @@ -7,12 +7,8 @@ "CVE-2015-4127" ], "details": "Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-82xj-jvx7-6989/GHSA-82xj-jvx7-6989.json b/advisories/unreviewed/2022/05/GHSA-82xj-jvx7-6989/GHSA-82xj-jvx7-6989.json index 9df590ffa85..73edd213d98 100644 --- a/advisories/unreviewed/2022/05/GHSA-82xj-jvx7-6989/GHSA-82xj-jvx7-6989.json +++ b/advisories/unreviewed/2022/05/GHSA-82xj-jvx7-6989/GHSA-82xj-jvx7-6989.json @@ -7,12 +7,8 @@ "CVE-2015-2576" ], "details": "Unspecified vulnerability in the MySQL Utilities component in Oracle MySQL 1.5.1 and earlier, when running on Windows, allows local users to affect integrity via unknown vectors related to Installation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-82xm-9qhp-mf4g/GHSA-82xm-9qhp-mf4g.json b/advisories/unreviewed/2022/05/GHSA-82xm-9qhp-mf4g/GHSA-82xm-9qhp-mf4g.json index ca1858ab3a1..376de3f74cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-82xm-9qhp-mf4g/GHSA-82xm-9qhp-mf4g.json +++ b/advisories/unreviewed/2022/05/GHSA-82xm-9qhp-mf4g/GHSA-82xm-9qhp-mf4g.json @@ -7,12 +7,8 @@ "CVE-2015-4219" ], "details": "Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug IDs CSCue00833 and CSCub40331.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8338-6xqh-crw7/GHSA-8338-6xqh-crw7.json b/advisories/unreviewed/2022/05/GHSA-8338-6xqh-crw7/GHSA-8338-6xqh-crw7.json index 2eba70b4aac..fb2655a2d50 100644 --- a/advisories/unreviewed/2022/05/GHSA-8338-6xqh-crw7/GHSA-8338-6xqh-crw7.json +++ b/advisories/unreviewed/2022/05/GHSA-8338-6xqh-crw7/GHSA-8338-6xqh-crw7.json @@ -7,12 +7,8 @@ "CVE-2013-6029" ], "details": "Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code via a malformed .SVT file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-833g-vcgj-6xrj/GHSA-833g-vcgj-6xrj.json b/advisories/unreviewed/2022/05/GHSA-833g-vcgj-6xrj/GHSA-833g-vcgj-6xrj.json index cf384880ee1..b8f8213f72c 100644 --- a/advisories/unreviewed/2022/05/GHSA-833g-vcgj-6xrj/GHSA-833g-vcgj-6xrj.json +++ b/advisories/unreviewed/2022/05/GHSA-833g-vcgj-6xrj/GHSA-833g-vcgj-6xrj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-84mh-26r2-jcpf/GHSA-84mh-26r2-jcpf.json b/advisories/unreviewed/2022/05/GHSA-84mh-26r2-jcpf/GHSA-84mh-26r2-jcpf.json index b5e611a872c..0d1506dbb11 100644 --- a/advisories/unreviewed/2022/05/GHSA-84mh-26r2-jcpf/GHSA-84mh-26r2-jcpf.json +++ b/advisories/unreviewed/2022/05/GHSA-84mh-26r2-jcpf/GHSA-84mh-26r2-jcpf.json @@ -7,12 +7,8 @@ "CVE-2014-6564" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:INNODB FULLTEXT SEARCH DML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-85p6-fxpj-g69h/GHSA-85p6-fxpj-g69h.json b/advisories/unreviewed/2022/05/GHSA-85p6-fxpj-g69h/GHSA-85p6-fxpj-g69h.json index 584889f482b..d6a920bb52a 100644 --- a/advisories/unreviewed/2022/05/GHSA-85p6-fxpj-g69h/GHSA-85p6-fxpj-g69h.json +++ b/advisories/unreviewed/2022/05/GHSA-85p6-fxpj-g69h/GHSA-85p6-fxpj-g69h.json @@ -7,12 +7,8 @@ "CVE-2012-1143" ], "details": "FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -120,9 +116,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-865v-63mv-86hf/GHSA-865v-63mv-86hf.json b/advisories/unreviewed/2022/05/GHSA-865v-63mv-86hf/GHSA-865v-63mv-86hf.json index dba5900d08c..9e47c5336f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-865v-63mv-86hf/GHSA-865v-63mv-86hf.json +++ b/advisories/unreviewed/2022/05/GHSA-865v-63mv-86hf/GHSA-865v-63mv-86hf.json @@ -7,12 +7,8 @@ "CVE-2015-0464" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, and 6.3.6 allows remote attackers to affect confidentiality via unknown vectors related to Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8699-7c7g-2p7j/GHSA-8699-7c7g-2p7j.json b/advisories/unreviewed/2022/05/GHSA-8699-7c7g-2p7j/GHSA-8699-7c7g-2p7j.json index eef691803aa..d200fe4f473 100644 --- a/advisories/unreviewed/2022/05/GHSA-8699-7c7g-2p7j/GHSA-8699-7c7g-2p7j.json +++ b/advisories/unreviewed/2022/05/GHSA-8699-7c7g-2p7j/GHSA-8699-7c7g-2p7j.json @@ -7,12 +7,8 @@ "CVE-2015-0485" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise SCM Strategic Sourcing component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86g9-4xm6-2vw3/GHSA-86g9-4xm6-2vw3.json b/advisories/unreviewed/2022/05/GHSA-86g9-4xm6-2vw3/GHSA-86g9-4xm6-2vw3.json index 35d2d023708..d3cc8c85e47 100644 --- a/advisories/unreviewed/2022/05/GHSA-86g9-4xm6-2vw3/GHSA-86g9-4xm6-2vw3.json +++ b/advisories/unreviewed/2022/05/GHSA-86g9-4xm6-2vw3/GHSA-86g9-4xm6-2vw3.json @@ -7,12 +7,8 @@ "CVE-2014-8989" ], "details": "The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a \"negative groups\" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-87f9-qh2w-ghc4/GHSA-87f9-qh2w-ghc4.json b/advisories/unreviewed/2022/05/GHSA-87f9-qh2w-ghc4/GHSA-87f9-qh2w-ghc4.json index ba2892e5c11..b6ef6d52930 100644 --- a/advisories/unreviewed/2022/05/GHSA-87f9-qh2w-ghc4/GHSA-87f9-qh2w-ghc4.json +++ b/advisories/unreviewed/2022/05/GHSA-87f9-qh2w-ghc4/GHSA-87f9-qh2w-ghc4.json @@ -7,12 +7,8 @@ "CVE-2014-9326" ], "details": "The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM 10.0.0 through 11.6.0 and PEM 11.3.0 through 11.6.0 does not properly validate server SSL certificates, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88j7-h683-wr6x/GHSA-88j7-h683-wr6x.json b/advisories/unreviewed/2022/05/GHSA-88j7-h683-wr6x/GHSA-88j7-h683-wr6x.json index c313362cc1a..dcb9c0d0edd 100644 --- a/advisories/unreviewed/2022/05/GHSA-88j7-h683-wr6x/GHSA-88j7-h683-wr6x.json +++ b/advisories/unreviewed/2022/05/GHSA-88j7-h683-wr6x/GHSA-88j7-h683-wr6x.json @@ -7,12 +7,8 @@ "CVE-2015-3722" ], "details": "Application Store in Apple iOS before 8.4 does not ensure the uniqueness of bundle IDs, which allows attackers to cause a denial of service (ID collision and launch outage) via a crafted universal provisioning profile app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-88mg-hqxv-95h4/GHSA-88mg-hqxv-95h4.json b/advisories/unreviewed/2022/05/GHSA-88mg-hqxv-95h4/GHSA-88mg-hqxv-95h4.json index 5dbe5eb3a71..896724bb8ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-88mg-hqxv-95h4/GHSA-88mg-hqxv-95h4.json +++ b/advisories/unreviewed/2022/05/GHSA-88mg-hqxv-95h4/GHSA-88mg-hqxv-95h4.json @@ -7,12 +7,8 @@ "CVE-2015-1420" ], "details": "Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-88xq-2hcg-rf4f/GHSA-88xq-2hcg-rf4f.json b/advisories/unreviewed/2022/05/GHSA-88xq-2hcg-rf4f/GHSA-88xq-2hcg-rf4f.json index 118a7a7d6fe..a398353666b 100644 --- a/advisories/unreviewed/2022/05/GHSA-88xq-2hcg-rf4f/GHSA-88xq-2hcg-rf4f.json +++ b/advisories/unreviewed/2022/05/GHSA-88xq-2hcg-rf4f/GHSA-88xq-2hcg-rf4f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8947-25cx-hm93/GHSA-8947-25cx-hm93.json b/advisories/unreviewed/2022/05/GHSA-8947-25cx-hm93/GHSA-8947-25cx-hm93.json index 18156dfd5da..a543f44823f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8947-25cx-hm93/GHSA-8947-25cx-hm93.json +++ b/advisories/unreviewed/2022/05/GHSA-8947-25cx-hm93/GHSA-8947-25cx-hm93.json @@ -7,12 +7,8 @@ "CVE-2015-2644" ], "details": "Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3 allows remote attackers to affect confidentiality via unknown vectors related to Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89c9-qj32-x5pr/GHSA-89c9-qj32-x5pr.json b/advisories/unreviewed/2022/05/GHSA-89c9-qj32-x5pr/GHSA-89c9-qj32-x5pr.json index a456b1d8d12..7c3fe983aff 100644 --- a/advisories/unreviewed/2022/05/GHSA-89c9-qj32-x5pr/GHSA-89c9-qj32-x5pr.json +++ b/advisories/unreviewed/2022/05/GHSA-89c9-qj32-x5pr/GHSA-89c9-qj32-x5pr.json @@ -7,12 +7,8 @@ "CVE-2015-7007" ], "details": "Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-89r9-97qh-2hq4/GHSA-89r9-97qh-2hq4.json b/advisories/unreviewed/2022/05/GHSA-89r9-97qh-2hq4/GHSA-89r9-97qh-2hq4.json index 23e620d28f6..b7dce6d04ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-89r9-97qh-2hq4/GHSA-89r9-97qh-2hq4.json +++ b/advisories/unreviewed/2022/05/GHSA-89r9-97qh-2hq4/GHSA-89r9-97qh-2hq4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-89vq-xp4x-vhgg/GHSA-89vq-xp4x-vhgg.json b/advisories/unreviewed/2022/05/GHSA-89vq-xp4x-vhgg/GHSA-89vq-xp4x-vhgg.json index 8812bf9fc70..79e2f6b197f 100644 --- a/advisories/unreviewed/2022/05/GHSA-89vq-xp4x-vhgg/GHSA-89vq-xp4x-vhgg.json +++ b/advisories/unreviewed/2022/05/GHSA-89vq-xp4x-vhgg/GHSA-89vq-xp4x-vhgg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8cp4-frg2-4854/GHSA-8cp4-frg2-4854.json b/advisories/unreviewed/2022/05/GHSA-8cp4-frg2-4854/GHSA-8cp4-frg2-4854.json index 4fb8aa7dcb3..d62519ec939 100644 --- a/advisories/unreviewed/2022/05/GHSA-8cp4-frg2-4854/GHSA-8cp4-frg2-4854.json +++ b/advisories/unreviewed/2022/05/GHSA-8cp4-frg2-4854/GHSA-8cp4-frg2-4854.json @@ -7,12 +7,8 @@ "CVE-2015-7013" ], "details": "WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8frw-6498-cgq3/GHSA-8frw-6498-cgq3.json b/advisories/unreviewed/2022/05/GHSA-8frw-6498-cgq3/GHSA-8frw-6498-cgq3.json index 5bdc164b375..d5e4aee928c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8frw-6498-cgq3/GHSA-8frw-6498-cgq3.json +++ b/advisories/unreviewed/2022/05/GHSA-8frw-6498-cgq3/GHSA-8frw-6498-cgq3.json @@ -7,12 +7,8 @@ "CVE-2015-2234" ], "details": "Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8g5w-5wrq-jqg3/GHSA-8g5w-5wrq-jqg3.json b/advisories/unreviewed/2022/05/GHSA-8g5w-5wrq-jqg3/GHSA-8g5w-5wrq-jqg3.json index 860776756c0..ce254a7c698 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g5w-5wrq-jqg3/GHSA-8g5w-5wrq-jqg3.json +++ b/advisories/unreviewed/2022/05/GHSA-8g5w-5wrq-jqg3/GHSA-8g5w-5wrq-jqg3.json @@ -7,12 +7,8 @@ "CVE-2015-0544" ], "details": "EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8gv8-v2jg-r2xw/GHSA-8gv8-v2jg-r2xw.json b/advisories/unreviewed/2022/05/GHSA-8gv8-v2jg-r2xw/GHSA-8gv8-v2jg-r2xw.json index 19440740bda..c303ca7886f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gv8-v2jg-r2xw/GHSA-8gv8-v2jg-r2xw.json +++ b/advisories/unreviewed/2022/05/GHSA-8gv8-v2jg-r2xw/GHSA-8gv8-v2jg-r2xw.json @@ -7,12 +7,8 @@ "CVE-2013-6473" ], "details": "Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gw4-r28f-7g55/GHSA-8gw4-r28f-7g55.json b/advisories/unreviewed/2022/05/GHSA-8gw4-r28f-7g55/GHSA-8gw4-r28f-7g55.json index aee01fd1667..02ec7aeac0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gw4-r28f-7g55/GHSA-8gw4-r28f-7g55.json +++ b/advisories/unreviewed/2022/05/GHSA-8gw4-r28f-7g55/GHSA-8gw4-r28f-7g55.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8gwf-4fhm-grr4/GHSA-8gwf-4fhm-grr4.json b/advisories/unreviewed/2022/05/GHSA-8gwf-4fhm-grr4/GHSA-8gwf-4fhm-grr4.json index 52c9aedcd28..2dfe52d89e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gwf-4fhm-grr4/GHSA-8gwf-4fhm-grr4.json +++ b/advisories/unreviewed/2022/05/GHSA-8gwf-4fhm-grr4/GHSA-8gwf-4fhm-grr4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8h55-h9jf-42p4/GHSA-8h55-h9jf-42p4.json b/advisories/unreviewed/2022/05/GHSA-8h55-h9jf-42p4/GHSA-8h55-h9jf-42p4.json index 0706b85cac5..38cd990aa7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h55-h9jf-42p4/GHSA-8h55-h9jf-42p4.json +++ b/advisories/unreviewed/2022/05/GHSA-8h55-h9jf-42p4/GHSA-8h55-h9jf-42p4.json @@ -7,12 +7,8 @@ "CVE-2015-3905" ], "details": "Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8j7j-8w2r-72pq/GHSA-8j7j-8w2r-72pq.json b/advisories/unreviewed/2022/05/GHSA-8j7j-8w2r-72pq/GHSA-8j7j-8w2r-72pq.json index 0e57253e432..c83efba625d 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j7j-8w2r-72pq/GHSA-8j7j-8w2r-72pq.json +++ b/advisories/unreviewed/2022/05/GHSA-8j7j-8w2r-72pq/GHSA-8j7j-8w2r-72pq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p3f-5g82-5m35/GHSA-8p3f-5g82-5m35.json b/advisories/unreviewed/2022/05/GHSA-8p3f-5g82-5m35/GHSA-8p3f-5g82-5m35.json index 579dfa500c9..03dd3dd91dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p3f-5g82-5m35/GHSA-8p3f-5g82-5m35.json +++ b/advisories/unreviewed/2022/05/GHSA-8p3f-5g82-5m35/GHSA-8p3f-5g82-5m35.json @@ -7,12 +7,8 @@ "CVE-2015-2336" ], "details": "TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the host OS via unspecified vectors, a different vulnerability than CVE-2012-0897.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8p4q-g3f4-h2jg/GHSA-8p4q-g3f4-h2jg.json b/advisories/unreviewed/2022/05/GHSA-8p4q-g3f4-h2jg/GHSA-8p4q-g3f4-h2jg.json index 3c9925de51a..7c8cab80856 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p4q-g3f4-h2jg/GHSA-8p4q-g3f4-h2jg.json +++ b/advisories/unreviewed/2022/05/GHSA-8p4q-g3f4-h2jg/GHSA-8p4q-g3f4-h2jg.json @@ -7,12 +7,8 @@ "CVE-2015-4260" ], "details": "Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8p96-4fvh-xrwg/GHSA-8p96-4fvh-xrwg.json b/advisories/unreviewed/2022/05/GHSA-8p96-4fvh-xrwg/GHSA-8p96-4fvh-xrwg.json index 390fc190786..c10094132d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p96-4fvh-xrwg/GHSA-8p96-4fvh-xrwg.json +++ b/advisories/unreviewed/2022/05/GHSA-8p96-4fvh-xrwg/GHSA-8p96-4fvh-xrwg.json @@ -7,12 +7,8 @@ "CVE-2005-1761" ], "details": "Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qjx-584q-xfgh/GHSA-8qjx-584q-xfgh.json b/advisories/unreviewed/2022/05/GHSA-8qjx-584q-xfgh/GHSA-8qjx-584q-xfgh.json index 32b375c575c..1e7aaa6d937 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qjx-584q-xfgh/GHSA-8qjx-584q-xfgh.json +++ b/advisories/unreviewed/2022/05/GHSA-8qjx-584q-xfgh/GHSA-8qjx-584q-xfgh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8qmf-pwhh-phx8/GHSA-8qmf-pwhh-phx8.json b/advisories/unreviewed/2022/05/GHSA-8qmf-pwhh-phx8/GHSA-8qmf-pwhh-phx8.json index 01994a91a3e..2bdbb02ef99 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qmf-pwhh-phx8/GHSA-8qmf-pwhh-phx8.json +++ b/advisories/unreviewed/2022/05/GHSA-8qmf-pwhh-phx8/GHSA-8qmf-pwhh-phx8.json @@ -7,12 +7,8 @@ "CVE-2015-3096" ], "details": "Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow remote attackers to bypass a CVE-2014-5333 protection mechanism via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8r9q-9pvc-52xq/GHSA-8r9q-9pvc-52xq.json b/advisories/unreviewed/2022/05/GHSA-8r9q-9pvc-52xq/GHSA-8r9q-9pvc-52xq.json index aff26aec7fe..598293f1184 100644 --- a/advisories/unreviewed/2022/05/GHSA-8r9q-9pvc-52xq/GHSA-8r9q-9pvc-52xq.json +++ b/advisories/unreviewed/2022/05/GHSA-8r9q-9pvc-52xq/GHSA-8r9q-9pvc-52xq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rjh-6ccf-h49m/GHSA-8rjh-6ccf-h49m.json b/advisories/unreviewed/2022/05/GHSA-8rjh-6ccf-h49m/GHSA-8rjh-6ccf-h49m.json index 78602589ef3..4ff376a15ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rjh-6ccf-h49m/GHSA-8rjh-6ccf-h49m.json +++ b/advisories/unreviewed/2022/05/GHSA-8rjh-6ccf-h49m/GHSA-8rjh-6ccf-h49m.json @@ -7,12 +7,8 @@ "CVE-2015-7009" ], "details": "FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7010, and CVE-2015-7018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8rvq-97mp-58qq/GHSA-8rvq-97mp-58qq.json b/advisories/unreviewed/2022/05/GHSA-8rvq-97mp-58qq/GHSA-8rvq-97mp-58qq.json index a5b712bd09c..c746a2e3b05 100644 --- a/advisories/unreviewed/2022/05/GHSA-8rvq-97mp-58qq/GHSA-8rvq-97mp-58qq.json +++ b/advisories/unreviewed/2022/05/GHSA-8rvq-97mp-58qq/GHSA-8rvq-97mp-58qq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8w42-q98x-hwrx/GHSA-8w42-q98x-hwrx.json b/advisories/unreviewed/2022/05/GHSA-8w42-q98x-hwrx/GHSA-8w42-q98x-hwrx.json index 85d70c0181e..01fbdda9958 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w42-q98x-hwrx/GHSA-8w42-q98x-hwrx.json +++ b/advisories/unreviewed/2022/05/GHSA-8w42-q98x-hwrx/GHSA-8w42-q98x-hwrx.json @@ -7,12 +7,8 @@ "CVE-2015-5929" ], "details": "WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8x6w-vmh7-xc9h/GHSA-8x6w-vmh7-xc9h.json b/advisories/unreviewed/2022/05/GHSA-8x6w-vmh7-xc9h/GHSA-8x6w-vmh7-xc9h.json index abeb30a9473..3990235bfdd 100644 --- a/advisories/unreviewed/2022/05/GHSA-8x6w-vmh7-xc9h/GHSA-8x6w-vmh7-xc9h.json +++ b/advisories/unreviewed/2022/05/GHSA-8x6w-vmh7-xc9h/GHSA-8x6w-vmh7-xc9h.json @@ -7,12 +7,8 @@ "CVE-2015-3339" ], "details": "Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xjh-f37p-57cj/GHSA-8xjh-f37p-57cj.json b/advisories/unreviewed/2022/05/GHSA-8xjh-f37p-57cj/GHSA-8xjh-f37p-57cj.json index db4edf760d5..24776e2834f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xjh-f37p-57cj/GHSA-8xjh-f37p-57cj.json +++ b/advisories/unreviewed/2022/05/GHSA-8xjh-f37p-57cj/GHSA-8xjh-f37p-57cj.json @@ -7,12 +7,8 @@ "CVE-2014-3684" ], "details": "The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted session id, which allows remote authenticated users to kill arbitrary processes via a crafted executable.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8xjw-hj33-qvm7/GHSA-8xjw-hj33-qvm7.json b/advisories/unreviewed/2022/05/GHSA-8xjw-hj33-qvm7/GHSA-8xjw-hj33-qvm7.json index c88503001ab..8b855b59348 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xjw-hj33-qvm7/GHSA-8xjw-hj33-qvm7.json +++ b/advisories/unreviewed/2022/05/GHSA-8xjw-hj33-qvm7/GHSA-8xjw-hj33-qvm7.json @@ -7,12 +7,8 @@ "CVE-2015-5939" ], "details": "ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5935, CVE-2015-5936, and CVE-2015-5937.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xmq-qp2g-jjf3/GHSA-8xmq-qp2g-jjf3.json b/advisories/unreviewed/2022/05/GHSA-8xmq-qp2g-jjf3/GHSA-8xmq-qp2g-jjf3.json index a9d16101e10..ac7999fc1ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xmq-qp2g-jjf3/GHSA-8xmq-qp2g-jjf3.json +++ b/advisories/unreviewed/2022/05/GHSA-8xmq-qp2g-jjf3/GHSA-8xmq-qp2g-jjf3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-8xv2-6qw9-7w72/GHSA-8xv2-6qw9-7w72.json b/advisories/unreviewed/2022/05/GHSA-8xv2-6qw9-7w72/GHSA-8xv2-6qw9-7w72.json index 1dbc4d6f9c0..6dec0ef99bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xv2-6qw9-7w72/GHSA-8xv2-6qw9-7w72.json +++ b/advisories/unreviewed/2022/05/GHSA-8xv2-6qw9-7w72/GHSA-8xv2-6qw9-7w72.json @@ -7,12 +7,8 @@ "CVE-2013-7174" ], "details": "Absolute path traversal vulnerability in cgi-bin/jc.cgi in QNAP QTS before 4.1.0 allows remote attackers to read arbitrary files via a full pathname in the f parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-92m2-qw95-6frf/GHSA-92m2-qw95-6frf.json b/advisories/unreviewed/2022/05/GHSA-92m2-qw95-6frf/GHSA-92m2-qw95-6frf.json index 2fe01f32b4b..8898b593364 100644 --- a/advisories/unreviewed/2022/05/GHSA-92m2-qw95-6frf/GHSA-92m2-qw95-6frf.json +++ b/advisories/unreviewed/2022/05/GHSA-92m2-qw95-6frf/GHSA-92m2-qw95-6frf.json @@ -7,12 +7,8 @@ "CVE-2015-6241" ], "details": "The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-934m-45xh-8j2f/GHSA-934m-45xh-8j2f.json b/advisories/unreviewed/2022/05/GHSA-934m-45xh-8j2f/GHSA-934m-45xh-8j2f.json index 69e90317777..4041926712f 100644 --- a/advisories/unreviewed/2022/05/GHSA-934m-45xh-8j2f/GHSA-934m-45xh-8j2f.json +++ b/advisories/unreviewed/2022/05/GHSA-934m-45xh-8j2f/GHSA-934m-45xh-8j2f.json @@ -7,12 +7,8 @@ "CVE-2015-2170" ], "details": "The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9359-5m76-c22m/GHSA-9359-5m76-c22m.json b/advisories/unreviewed/2022/05/GHSA-9359-5m76-c22m/GHSA-9359-5m76-c22m.json index 371f649deb5..2f40fd32f2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9359-5m76-c22m/GHSA-9359-5m76-c22m.json +++ b/advisories/unreviewed/2022/05/GHSA-9359-5m76-c22m/GHSA-9359-5m76-c22m.json @@ -7,12 +7,8 @@ "CVE-2015-1090" ], "details": "CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-93v5-5c97-fgrr/GHSA-93v5-5c97-fgrr.json b/advisories/unreviewed/2022/05/GHSA-93v5-5c97-fgrr/GHSA-93v5-5c97-fgrr.json index 4ffb931efeb..b019394f53d 100644 --- a/advisories/unreviewed/2022/05/GHSA-93v5-5c97-fgrr/GHSA-93v5-5c97-fgrr.json +++ b/advisories/unreviewed/2022/05/GHSA-93v5-5c97-fgrr/GHSA-93v5-5c97-fgrr.json @@ -7,12 +7,8 @@ "CVE-2015-3090" ], "details": "Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3078, CVE-2015-3089, and CVE-2015-3093.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-94fm-w27w-jfr2/GHSA-94fm-w27w-jfr2.json b/advisories/unreviewed/2022/05/GHSA-94fm-w27w-jfr2/GHSA-94fm-w27w-jfr2.json index 079ca8f395d..77b15acce9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-94fm-w27w-jfr2/GHSA-94fm-w27w-jfr2.json +++ b/advisories/unreviewed/2022/05/GHSA-94fm-w27w-jfr2/GHSA-94fm-w27w-jfr2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-959p-539g-8wj3/GHSA-959p-539g-8wj3.json b/advisories/unreviewed/2022/05/GHSA-959p-539g-8wj3/GHSA-959p-539g-8wj3.json index 452cb882f75..ca0f4e968e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-959p-539g-8wj3/GHSA-959p-539g-8wj3.json +++ b/advisories/unreviewed/2022/05/GHSA-959p-539g-8wj3/GHSA-959p-539g-8wj3.json @@ -7,12 +7,8 @@ "CVE-2015-4252" ], "details": "Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence ISDN Gateway devices with software 2.2(1.106) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90724.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-95xm-34f4-5j7v/GHSA-95xm-34f4-5j7v.json b/advisories/unreviewed/2022/05/GHSA-95xm-34f4-5j7v/GHSA-95xm-34f4-5j7v.json index 40462124a8e..b0f5542a583 100644 --- a/advisories/unreviewed/2022/05/GHSA-95xm-34f4-5j7v/GHSA-95xm-34f4-5j7v.json +++ b/advisories/unreviewed/2022/05/GHSA-95xm-34f4-5j7v/GHSA-95xm-34f4-5j7v.json @@ -7,12 +7,8 @@ "CVE-2015-7834" ], "details": "Multiple unspecified vulnerabilities in Google V8 before 4.6.85.23, as used in Google Chrome before 46.0.2490.71, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-965c-2h5q-fhff/GHSA-965c-2h5q-fhff.json b/advisories/unreviewed/2022/05/GHSA-965c-2h5q-fhff/GHSA-965c-2h5q-fhff.json index d9c55b62920..31fd597e9d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-965c-2h5q-fhff/GHSA-965c-2h5q-fhff.json +++ b/advisories/unreviewed/2022/05/GHSA-965c-2h5q-fhff/GHSA-965c-2h5q-fhff.json @@ -7,12 +7,8 @@ "CVE-2014-7931" ], "details": "factory.cc in Google V8, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers improper maintenance of backing-store pointers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9679-qhxv-w52c/GHSA-9679-qhxv-w52c.json b/advisories/unreviewed/2022/05/GHSA-9679-qhxv-w52c/GHSA-9679-qhxv-w52c.json index f46c9d0f111..3a0f0cb3617 100644 --- a/advisories/unreviewed/2022/05/GHSA-9679-qhxv-w52c/GHSA-9679-qhxv-w52c.json +++ b/advisories/unreviewed/2022/05/GHSA-9679-qhxv-w52c/GHSA-9679-qhxv-w52c.json @@ -7,12 +7,8 @@ "CVE-2015-1925" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9898-gf72-6p88/GHSA-9898-gf72-6p88.json b/advisories/unreviewed/2022/05/GHSA-9898-gf72-6p88/GHSA-9898-gf72-6p88.json index 2f8447e92d3..95dff70528e 100644 --- a/advisories/unreviewed/2022/05/GHSA-9898-gf72-6p88/GHSA-9898-gf72-6p88.json +++ b/advisories/unreviewed/2022/05/GHSA-9898-gf72-6p88/GHSA-9898-gf72-6p88.json @@ -7,12 +7,8 @@ "CVE-2015-4210" ], "details": "Cross-site scripting (XSS) vulnerability in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur03806.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-98p8-6886-r2jj/GHSA-98p8-6886-r2jj.json b/advisories/unreviewed/2022/05/GHSA-98p8-6886-r2jj/GHSA-98p8-6886-r2jj.json index 2a602d74bbf..a4b394d3947 100644 --- a/advisories/unreviewed/2022/05/GHSA-98p8-6886-r2jj/GHSA-98p8-6886-r2jj.json +++ b/advisories/unreviewed/2022/05/GHSA-98p8-6886-r2jj/GHSA-98p8-6886-r2jj.json @@ -7,12 +7,8 @@ "CVE-2014-7927" ], "details": "The SimplifiedLowering::DoLoadBuffer function in compiler/simplified-lowering.cc in Google V8, as used in Google Chrome before 40.0.2214.91, does not properly choose an integer data type, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-99pq-r374-7jh3/GHSA-99pq-r374-7jh3.json b/advisories/unreviewed/2022/05/GHSA-99pq-r374-7jh3/GHSA-99pq-r374-7jh3.json index 8c19368b38c..67fdd110169 100644 --- a/advisories/unreviewed/2022/05/GHSA-99pq-r374-7jh3/GHSA-99pq-r374-7jh3.json +++ b/advisories/unreviewed/2022/05/GHSA-99pq-r374-7jh3/GHSA-99pq-r374-7jh3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9f67-89h4-wvpf/GHSA-9f67-89h4-wvpf.json b/advisories/unreviewed/2022/05/GHSA-9f67-89h4-wvpf/GHSA-9f67-89h4-wvpf.json index 47b3cb54ed3..17a11695e40 100644 --- a/advisories/unreviewed/2022/05/GHSA-9f67-89h4-wvpf/GHSA-9f67-89h4-wvpf.json +++ b/advisories/unreviewed/2022/05/GHSA-9f67-89h4-wvpf/GHSA-9f67-89h4-wvpf.json @@ -7,12 +7,8 @@ "CVE-2015-6995" ], "details": "The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9gcw-rj26-vmwh/GHSA-9gcw-rj26-vmwh.json b/advisories/unreviewed/2022/05/GHSA-9gcw-rj26-vmwh/GHSA-9gcw-rj26-vmwh.json index 22f07250cba..5d5d84e4e51 100644 --- a/advisories/unreviewed/2022/05/GHSA-9gcw-rj26-vmwh/GHSA-9gcw-rj26-vmwh.json +++ b/advisories/unreviewed/2022/05/GHSA-9gcw-rj26-vmwh/GHSA-9gcw-rj26-vmwh.json @@ -7,12 +7,8 @@ "CVE-2015-4750" ], "details": "Unspecified vulnerability in the Oracle VM Server for SPARC component in Oracle Sun Systems Products Suite 3.2 allows remote attackers to affect availability via vectors related to LDOM Manager.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9h4w-j8f9-g7pr/GHSA-9h4w-j8f9-g7pr.json b/advisories/unreviewed/2022/05/GHSA-9h4w-j8f9-g7pr/GHSA-9h4w-j8f9-g7pr.json index 8738d9afc08..65e76f8bf90 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h4w-j8f9-g7pr/GHSA-9h4w-j8f9-g7pr.json +++ b/advisories/unreviewed/2022/05/GHSA-9h4w-j8f9-g7pr/GHSA-9h4w-j8f9-g7pr.json @@ -7,12 +7,8 @@ "CVE-2015-1268" ], "details": "bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creation context for a return value's DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code, as demonstrated by use of a data: URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9h8r-w7wj-gx59/GHSA-9h8r-w7wj-gx59.json b/advisories/unreviewed/2022/05/GHSA-9h8r-w7wj-gx59/GHSA-9h8r-w7wj-gx59.json index 7ff10030d6f..d52471437c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9h8r-w7wj-gx59/GHSA-9h8r-w7wj-gx59.json +++ b/advisories/unreviewed/2022/05/GHSA-9h8r-w7wj-gx59/GHSA-9h8r-w7wj-gx59.json @@ -7,12 +7,8 @@ "CVE-2014-8514" ], "details": "Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9hwj-6qf4-7f63/GHSA-9hwj-6qf4-7f63.json b/advisories/unreviewed/2022/05/GHSA-9hwj-6qf4-7f63/GHSA-9hwj-6qf4-7f63.json index e65283d4ed9..e273866081a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9hwj-6qf4-7f63/GHSA-9hwj-6qf4-7f63.json +++ b/advisories/unreviewed/2022/05/GHSA-9hwj-6qf4-7f63/GHSA-9hwj-6qf4-7f63.json @@ -7,12 +7,8 @@ "CVE-2015-4230" ], "details": "Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91854.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9j6v-gvm6-rm3f/GHSA-9j6v-gvm6-rm3f.json b/advisories/unreviewed/2022/05/GHSA-9j6v-gvm6-rm3f/GHSA-9j6v-gvm6-rm3f.json index 5bc33159e39..96ab012b61a 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j6v-gvm6-rm3f/GHSA-9j6v-gvm6-rm3f.json +++ b/advisories/unreviewed/2022/05/GHSA-9j6v-gvm6-rm3f/GHSA-9j6v-gvm6-rm3f.json @@ -7,12 +7,8 @@ "CVE-2015-3104" ], "details": "Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9j96-pxxw-qjr9/GHSA-9j96-pxxw-qjr9.json b/advisories/unreviewed/2022/05/GHSA-9j96-pxxw-qjr9/GHSA-9j96-pxxw-qjr9.json index 9593a6f8f65..a47b6ef56af 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j96-pxxw-qjr9/GHSA-9j96-pxxw-qjr9.json +++ b/advisories/unreviewed/2022/05/GHSA-9j96-pxxw-qjr9/GHSA-9j96-pxxw-qjr9.json @@ -7,12 +7,8 @@ "CVE-2013-6037" ], "details": "Cross-site scripting (XSS) vulnerability in index.php in Aker Secure Mail Gateway 2.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg_id parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9j9q-rr6w-2j7g/GHSA-9j9q-rr6w-2j7g.json b/advisories/unreviewed/2022/05/GHSA-9j9q-rr6w-2j7g/GHSA-9j9q-rr6w-2j7g.json index a73098915cf..96261ed67af 100644 --- a/advisories/unreviewed/2022/05/GHSA-9j9q-rr6w-2j7g/GHSA-9j9q-rr6w-2j7g.json +++ b/advisories/unreviewed/2022/05/GHSA-9j9q-rr6w-2j7g/GHSA-9j9q-rr6w-2j7g.json @@ -7,12 +7,8 @@ "CVE-2013-6369" ], "details": "Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted image file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9mvv-4q4j-q2j8/GHSA-9mvv-4q4j-q2j8.json b/advisories/unreviewed/2022/05/GHSA-9mvv-4q4j-q2j8/GHSA-9mvv-4q4j-q2j8.json index e50ea23387f..b473eca3564 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mvv-4q4j-q2j8/GHSA-9mvv-4q4j-q2j8.json +++ b/advisories/unreviewed/2022/05/GHSA-9mvv-4q4j-q2j8/GHSA-9mvv-4q4j-q2j8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p2m-7x3f-fh47/GHSA-9p2m-7x3f-fh47.json b/advisories/unreviewed/2022/05/GHSA-9p2m-7x3f-fh47/GHSA-9p2m-7x3f-fh47.json index a793d06d259..323840fd5b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p2m-7x3f-fh47/GHSA-9p2m-7x3f-fh47.json +++ b/advisories/unreviewed/2022/05/GHSA-9p2m-7x3f-fh47/GHSA-9p2m-7x3f-fh47.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9p3q-mjhj-h3m4/GHSA-9p3q-mjhj-h3m4.json b/advisories/unreviewed/2022/05/GHSA-9p3q-mjhj-h3m4/GHSA-9p3q-mjhj-h3m4.json index 0ef654eb5cd..133a6d47169 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p3q-mjhj-h3m4/GHSA-9p3q-mjhj-h3m4.json +++ b/advisories/unreviewed/2022/05/GHSA-9p3q-mjhj-h3m4/GHSA-9p3q-mjhj-h3m4.json @@ -7,12 +7,8 @@ "CVE-2014-9160" ], "details": "Multiple heap-based buffer overflows in Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9pg8-rfm3-8657/GHSA-9pg8-rfm3-8657.json b/advisories/unreviewed/2022/05/GHSA-9pg8-rfm3-8657/GHSA-9pg8-rfm3-8657.json index 689601e54e0..7d6f35909dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pg8-rfm3-8657/GHSA-9pg8-rfm3-8657.json +++ b/advisories/unreviewed/2022/05/GHSA-9pg8-rfm3-8657/GHSA-9pg8-rfm3-8657.json @@ -7,12 +7,8 @@ "CVE-2015-1966" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to the (1) ERROR_DESCRIPTION and (2) TOKEN:RelayState macros.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9qfw-82fr-g926/GHSA-9qfw-82fr-g926.json b/advisories/unreviewed/2022/05/GHSA-9qfw-82fr-g926/GHSA-9qfw-82fr-g926.json index a32ee957034..2ffd34a7767 100644 --- a/advisories/unreviewed/2022/05/GHSA-9qfw-82fr-g926/GHSA-9qfw-82fr-g926.json +++ b/advisories/unreviewed/2022/05/GHSA-9qfw-82fr-g926/GHSA-9qfw-82fr-g926.json @@ -7,12 +7,8 @@ "CVE-2015-1252" ], "details": "common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger a write operation with a large amount of data, related to the PartialCircularBuffer::Write and PartialCircularBuffer::DoWrite functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9r4f-v5jq-fc8w/GHSA-9r4f-v5jq-fc8w.json b/advisories/unreviewed/2022/05/GHSA-9r4f-v5jq-fc8w/GHSA-9r4f-v5jq-fc8w.json index cd11b6d3836..284ac37af16 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r4f-v5jq-fc8w/GHSA-9r4f-v5jq-fc8w.json +++ b/advisories/unreviewed/2022/05/GHSA-9r4f-v5jq-fc8w/GHSA-9r4f-v5jq-fc8w.json @@ -7,12 +7,8 @@ "CVE-2015-2340" ], "details": "TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r6c-6xf4-89m9/GHSA-9r6c-6xf4-89m9.json b/advisories/unreviewed/2022/05/GHSA-9r6c-6xf4-89m9/GHSA-9r6c-6xf4-89m9.json index 2bf2ed0d7e2..461413305b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r6c-6xf4-89m9/GHSA-9r6c-6xf4-89m9.json +++ b/advisories/unreviewed/2022/05/GHSA-9r6c-6xf4-89m9/GHSA-9r6c-6xf4-89m9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9r88-88v4-3j6c/GHSA-9r88-88v4-3j6c.json b/advisories/unreviewed/2022/05/GHSA-9r88-88v4-3j6c/GHSA-9r88-88v4-3j6c.json index 5340638d929..4b308bbf8dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-9r88-88v4-3j6c/GHSA-9r88-88v4-3j6c.json +++ b/advisories/unreviewed/2022/05/GHSA-9r88-88v4-3j6c/GHSA-9r88-88v4-3j6c.json @@ -7,12 +7,8 @@ "CVE-2015-1868" ], "details": "The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rm7-7m57-m6gm/GHSA-9rm7-7m57-m6gm.json b/advisories/unreviewed/2022/05/GHSA-9rm7-7m57-m6gm/GHSA-9rm7-7m57-m6gm.json index fef811fd7b0..8eef61af753 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rm7-7m57-m6gm/GHSA-9rm7-7m57-m6gm.json +++ b/advisories/unreviewed/2022/05/GHSA-9rm7-7m57-m6gm/GHSA-9rm7-7m57-m6gm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v48-qqhw-8p75/GHSA-9v48-qqhw-8p75.json b/advisories/unreviewed/2022/05/GHSA-9v48-qqhw-8p75/GHSA-9v48-qqhw-8p75.json index 3068acf25b9..eb03913a318 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v48-qqhw-8p75/GHSA-9v48-qqhw-8p75.json +++ b/advisories/unreviewed/2022/05/GHSA-9v48-qqhw-8p75/GHSA-9v48-qqhw-8p75.json @@ -7,12 +7,8 @@ "CVE-2015-5935" ], "details": "ImageIO in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted metadata in an image, a different vulnerability than CVE-2015-5936, CVE-2015-5937, and CVE-2015-5939.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9v74-8vgh-49gq/GHSA-9v74-8vgh-49gq.json b/advisories/unreviewed/2022/05/GHSA-9v74-8vgh-49gq/GHSA-9v74-8vgh-49gq.json index 6f455de6e56..66c1ec1a43d 100644 --- a/advisories/unreviewed/2022/05/GHSA-9v74-8vgh-49gq/GHSA-9v74-8vgh-49gq.json +++ b/advisories/unreviewed/2022/05/GHSA-9v74-8vgh-49gq/GHSA-9v74-8vgh-49gq.json @@ -7,12 +7,8 @@ "CVE-2015-0513" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging privileged access to set crafted values of unspecified fields.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vgm-8x7f-4gp3/GHSA-9vgm-8x7f-4gp3.json b/advisories/unreviewed/2022/05/GHSA-9vgm-8x7f-4gp3/GHSA-9vgm-8x7f-4gp3.json index 5ca476a9733..0ebc723cfbb 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vgm-8x7f-4gp3/GHSA-9vgm-8x7f-4gp3.json +++ b/advisories/unreviewed/2022/05/GHSA-9vgm-8x7f-4gp3/GHSA-9vgm-8x7f-4gp3.json @@ -7,12 +7,8 @@ "CVE-2015-1924" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-9vp4-3p6r-f9c3/GHSA-9vp4-3p6r-f9c3.json b/advisories/unreviewed/2022/05/GHSA-9vp4-3p6r-f9c3/GHSA-9vp4-3p6r-f9c3.json index 31046f127ad..84e509c21c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9vp4-3p6r-f9c3/GHSA-9vp4-3p6r-f9c3.json +++ b/advisories/unreviewed/2022/05/GHSA-9vp4-3p6r-f9c3/GHSA-9vp4-3p6r-f9c3.json @@ -7,12 +7,8 @@ "CVE-2015-0472" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2015-0487.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3fp-4gq7-m24g/GHSA-c3fp-4gq7-m24g.json b/advisories/unreviewed/2022/05/GHSA-c3fp-4gq7-m24g/GHSA-c3fp-4gq7-m24g.json index 8d74da3dfec..a3fc4016174 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3fp-4gq7-m24g/GHSA-c3fp-4gq7-m24g.json +++ b/advisories/unreviewed/2022/05/GHSA-c3fp-4gq7-m24g/GHSA-c3fp-4gq7-m24g.json @@ -7,12 +7,8 @@ "CVE-2015-3650" ], "details": "vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privileges by injecting a thread.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3mp-xm82-4vr9/GHSA-c3mp-xm82-4vr9.json b/advisories/unreviewed/2022/05/GHSA-c3mp-xm82-4vr9/GHSA-c3mp-xm82-4vr9.json index 59202f703aa..d25474055c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3mp-xm82-4vr9/GHSA-c3mp-xm82-4vr9.json +++ b/advisories/unreviewed/2022/05/GHSA-c3mp-xm82-4vr9/GHSA-c3mp-xm82-4vr9.json @@ -7,12 +7,8 @@ "CVE-2015-4735" ], "details": "Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1, and EM DB Control 11.2.0.3 and 11.2.0.4, allows remote attackers to affect confidentiality via vectors related to RAC Management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c3q8-35qx-5r8j/GHSA-c3q8-35qx-5r8j.json b/advisories/unreviewed/2022/05/GHSA-c3q8-35qx-5r8j/GHSA-c3q8-35qx-5r8j.json index 8b3851f13dc..22b9523b832 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3q8-35qx-5r8j/GHSA-c3q8-35qx-5r8j.json +++ b/advisories/unreviewed/2022/05/GHSA-c3q8-35qx-5r8j/GHSA-c3q8-35qx-5r8j.json @@ -7,12 +7,8 @@ "CVE-2014-7880" ], "details": "Multiple unspecified vulnerabilities in the POP implementation in HP OpenVMS TCP/IP 5.7 before ECO5 allow remote attackers to cause a denial of service via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c3qw-8xrq-mhcj/GHSA-c3qw-8xrq-mhcj.json b/advisories/unreviewed/2022/05/GHSA-c3qw-8xrq-mhcj/GHSA-c3qw-8xrq-mhcj.json index cd83f3d611e..70cf4904b6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c3qw-8xrq-mhcj/GHSA-c3qw-8xrq-mhcj.json +++ b/advisories/unreviewed/2022/05/GHSA-c3qw-8xrq-mhcj/GHSA-c3qw-8xrq-mhcj.json @@ -7,12 +7,8 @@ "CVE-2014-8010" ], "details": "The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c422-m9j6-9g96/GHSA-c422-m9j6-9g96.json b/advisories/unreviewed/2022/05/GHSA-c422-m9j6-9g96/GHSA-c422-m9j6-9g96.json index 540790e05b3..9221edd57aa 100644 --- a/advisories/unreviewed/2022/05/GHSA-c422-m9j6-9g96/GHSA-c422-m9j6-9g96.json +++ b/advisories/unreviewed/2022/05/GHSA-c422-m9j6-9g96/GHSA-c422-m9j6-9g96.json @@ -7,12 +7,8 @@ "CVE-2015-3091" ], "details": "Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-3092.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c5h4-r9pm-rvhr/GHSA-c5h4-r9pm-rvhr.json b/advisories/unreviewed/2022/05/GHSA-c5h4-r9pm-rvhr/GHSA-c5h4-r9pm-rvhr.json index 3d6cccc1850..e4d9129b81b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c5h4-r9pm-rvhr/GHSA-c5h4-r9pm-rvhr.json +++ b/advisories/unreviewed/2022/05/GHSA-c5h4-r9pm-rvhr/GHSA-c5h4-r9pm-rvhr.json @@ -7,12 +7,8 @@ "CVE-2015-3665" ], "details": "QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3664 and CVE-2015-3669.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c65m-5vxj-2r25/GHSA-c65m-5vxj-2r25.json b/advisories/unreviewed/2022/05/GHSA-c65m-5vxj-2r25/GHSA-c65m-5vxj-2r25.json index febb5331a99..313fc90b8a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-c65m-5vxj-2r25/GHSA-c65m-5vxj-2r25.json +++ b/advisories/unreviewed/2022/05/GHSA-c65m-5vxj-2r25/GHSA-c65m-5vxj-2r25.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c77c-xc78-vg5v/GHSA-c77c-xc78-vg5v.json b/advisories/unreviewed/2022/05/GHSA-c77c-xc78-vg5v/GHSA-c77c-xc78-vg5v.json index 10e4a6e35f5..e9778780953 100644 --- a/advisories/unreviewed/2022/05/GHSA-c77c-xc78-vg5v/GHSA-c77c-xc78-vg5v.json +++ b/advisories/unreviewed/2022/05/GHSA-c77c-xc78-vg5v/GHSA-c77c-xc78-vg5v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c7jw-qwf7-gqxx/GHSA-c7jw-qwf7-gqxx.json b/advisories/unreviewed/2022/05/GHSA-c7jw-qwf7-gqxx/GHSA-c7jw-qwf7-gqxx.json index ee94f743532..26760c6db08 100644 --- a/advisories/unreviewed/2022/05/GHSA-c7jw-qwf7-gqxx/GHSA-c7jw-qwf7-gqxx.json +++ b/advisories/unreviewed/2022/05/GHSA-c7jw-qwf7-gqxx/GHSA-c7jw-qwf7-gqxx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8cp-4m25-xvcm/GHSA-c8cp-4m25-xvcm.json b/advisories/unreviewed/2022/05/GHSA-c8cp-4m25-xvcm/GHSA-c8cp-4m25-xvcm.json index 2f36d2d613e..7b188354cd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8cp-4m25-xvcm/GHSA-c8cp-4m25-xvcm.json +++ b/advisories/unreviewed/2022/05/GHSA-c8cp-4m25-xvcm/GHSA-c8cp-4m25-xvcm.json @@ -7,12 +7,8 @@ "CVE-2014-9328" ], "details": "ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a \"heap out of bounds condition.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c8fh-xhvf-2gp8/GHSA-c8fh-xhvf-2gp8.json b/advisories/unreviewed/2022/05/GHSA-c8fh-xhvf-2gp8/GHSA-c8fh-xhvf-2gp8.json index 8626bc6f976..c9b812ba6dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8fh-xhvf-2gp8/GHSA-c8fh-xhvf-2gp8.json +++ b/advisories/unreviewed/2022/05/GHSA-c8fh-xhvf-2gp8/GHSA-c8fh-xhvf-2gp8.json @@ -7,12 +7,8 @@ "CVE-2015-1986" ], "details": "The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1938.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c997-r668-9ffx/GHSA-c997-r668-9ffx.json b/advisories/unreviewed/2022/05/GHSA-c997-r668-9ffx/GHSA-c997-r668-9ffx.json index f0606f50f36..7f4e0bcf05a 100644 --- a/advisories/unreviewed/2022/05/GHSA-c997-r668-9ffx/GHSA-c997-r668-9ffx.json +++ b/advisories/unreviewed/2022/05/GHSA-c997-r668-9ffx/GHSA-c997-r668-9ffx.json @@ -7,12 +7,8 @@ "CVE-2015-7649" ], "details": "Adobe Shockwave Player before 12.2.1.171 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c999-q72h-34xc/GHSA-c999-q72h-34xc.json b/advisories/unreviewed/2022/05/GHSA-c999-q72h-34xc/GHSA-c999-q72h-34xc.json index db2af98ad31..27590599afe 100644 --- a/advisories/unreviewed/2022/05/GHSA-c999-q72h-34xc/GHSA-c999-q72h-34xc.json +++ b/advisories/unreviewed/2022/05/GHSA-c999-q72h-34xc/GHSA-c999-q72h-34xc.json @@ -7,12 +7,8 @@ "CVE-2015-3333" ], "details": "Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c9f4-c4vv-377j/GHSA-c9f4-c4vv-377j.json b/advisories/unreviewed/2022/05/GHSA-c9f4-c4vv-377j/GHSA-c9f4-c4vv-377j.json index b5ecb0a6075..7cf6828bee5 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9f4-c4vv-377j/GHSA-c9f4-c4vv-377j.json +++ b/advisories/unreviewed/2022/05/GHSA-c9f4-c4vv-377j/GHSA-c9f4-c4vv-377j.json @@ -7,12 +7,8 @@ "CVE-2015-1247" ], "details": "The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML document, which might allow remote attackers to obtain sensitive information from local files via a crafted (1) http or (2) https web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-c9v6-jmq4-q762/GHSA-c9v6-jmq4-q762.json b/advisories/unreviewed/2022/05/GHSA-c9v6-jmq4-q762/GHSA-c9v6-jmq4-q762.json index eb383455219..2e0838dd5dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-c9v6-jmq4-q762/GHSA-c9v6-jmq4-q762.json +++ b/advisories/unreviewed/2022/05/GHSA-c9v6-jmq4-q762/GHSA-c9v6-jmq4-q762.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc55-ww9c-8rc9/GHSA-cc55-ww9c-8rc9.json b/advisories/unreviewed/2022/05/GHSA-cc55-ww9c-8rc9/GHSA-cc55-ww9c-8rc9.json index 4706123228d..31a928493bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc55-ww9c-8rc9/GHSA-cc55-ww9c-8rc9.json +++ b/advisories/unreviewed/2022/05/GHSA-cc55-ww9c-8rc9/GHSA-cc55-ww9c-8rc9.json @@ -7,12 +7,8 @@ "CVE-2015-4212" ], "details": "Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credentials, aka Bug ID CSCut17466.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc65-crhv-33g3/GHSA-cc65-crhv-33g3.json b/advisories/unreviewed/2022/05/GHSA-cc65-crhv-33g3/GHSA-cc65-crhv-33g3.json index 24e0f81486e..3bb0ee10e38 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc65-crhv-33g3/GHSA-cc65-crhv-33g3.json +++ b/advisories/unreviewed/2022/05/GHSA-cc65-crhv-33g3/GHSA-cc65-crhv-33g3.json @@ -7,12 +7,8 @@ "CVE-2015-0498" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Replication.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cc8j-46rm-jw6f/GHSA-cc8j-46rm-jw6f.json b/advisories/unreviewed/2022/05/GHSA-cc8j-46rm-jw6f/GHSA-cc8j-46rm-jw6f.json index 2cb204b071f..58c3a13a877 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc8j-46rm-jw6f/GHSA-cc8j-46rm-jw6f.json +++ b/advisories/unreviewed/2022/05/GHSA-cc8j-46rm-jw6f/GHSA-cc8j-46rm-jw6f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cc93-84wc-xxg5/GHSA-cc93-84wc-xxg5.json b/advisories/unreviewed/2022/05/GHSA-cc93-84wc-xxg5/GHSA-cc93-84wc-xxg5.json index f92e45e890e..004dd33eec1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc93-84wc-xxg5/GHSA-cc93-84wc-xxg5.json +++ b/advisories/unreviewed/2022/05/GHSA-cc93-84wc-xxg5/GHSA-cc93-84wc-xxg5.json @@ -7,12 +7,8 @@ "CVE-2015-5757" ], "details": "libpthread in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via an app that uses a crafted syscall to interfere with locking.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccfq-m9xh-mhqj/GHSA-ccfq-m9xh-mhqj.json b/advisories/unreviewed/2022/05/GHSA-ccfq-m9xh-mhqj/GHSA-ccfq-m9xh-mhqj.json index e756aa7a52c..f763a068c8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccfq-m9xh-mhqj/GHSA-ccfq-m9xh-mhqj.json +++ b/advisories/unreviewed/2022/05/GHSA-ccfq-m9xh-mhqj/GHSA-ccfq-m9xh-mhqj.json @@ -7,12 +7,8 @@ "CVE-2013-6030" ], "details": "Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch with firmware 1.9.16473 allows remote attackers to read arbitrary files via unspecified vectors, as demonstrated by reading the /etc/passwd file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccw8-8wj9-vq37/GHSA-ccw8-8wj9-vq37.json b/advisories/unreviewed/2022/05/GHSA-ccw8-8wj9-vq37/GHSA-ccw8-8wj9-vq37.json index c4d950b8df5..30abb06dd86 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccw8-8wj9-vq37/GHSA-ccw8-8wj9-vq37.json +++ b/advisories/unreviewed/2022/05/GHSA-ccw8-8wj9-vq37/GHSA-ccw8-8wj9-vq37.json @@ -7,12 +7,8 @@ "CVE-2015-2960" ], "details": "Cross-site scripting (XSS) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ccxh-j5wp-7pr6/GHSA-ccxh-j5wp-7pr6.json b/advisories/unreviewed/2022/05/GHSA-ccxh-j5wp-7pr6/GHSA-ccxh-j5wp-7pr6.json index 2a52fd8e66c..b7186e72bbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccxh-j5wp-7pr6/GHSA-ccxh-j5wp-7pr6.json +++ b/advisories/unreviewed/2022/05/GHSA-ccxh-j5wp-7pr6/GHSA-ccxh-j5wp-7pr6.json @@ -7,12 +7,8 @@ "CVE-2013-4359" ], "details": "Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ccxh-r3rj-ffjf/GHSA-ccxh-r3rj-ffjf.json b/advisories/unreviewed/2022/05/GHSA-ccxh-r3rj-ffjf/GHSA-ccxh-r3rj-ffjf.json index 14516f94044..eb575322dec 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccxh-r3rj-ffjf/GHSA-ccxh-r3rj-ffjf.json +++ b/advisories/unreviewed/2022/05/GHSA-ccxh-r3rj-ffjf/GHSA-ccxh-r3rj-ffjf.json @@ -7,12 +7,8 @@ "CVE-2015-1930" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cf7f-fcvj-qqfj/GHSA-cf7f-fcvj-qqfj.json b/advisories/unreviewed/2022/05/GHSA-cf7f-fcvj-qqfj/GHSA-cf7f-fcvj-qqfj.json index edd37137b80..5127b221643 100644 --- a/advisories/unreviewed/2022/05/GHSA-cf7f-fcvj-qqfj/GHSA-cf7f-fcvj-qqfj.json +++ b/advisories/unreviewed/2022/05/GHSA-cf7f-fcvj-qqfj/GHSA-cf7f-fcvj-qqfj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ch7x-55jf-9fgx/GHSA-ch7x-55jf-9fgx.json b/advisories/unreviewed/2022/05/GHSA-ch7x-55jf-9fgx/GHSA-ch7x-55jf-9fgx.json index ce7ed1b9623..acea75a9de3 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch7x-55jf-9fgx/GHSA-ch7x-55jf-9fgx.json +++ b/advisories/unreviewed/2022/05/GHSA-ch7x-55jf-9fgx/GHSA-ch7x-55jf-9fgx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-chmv-r89p-xxr4/GHSA-chmv-r89p-xxr4.json b/advisories/unreviewed/2022/05/GHSA-chmv-r89p-xxr4/GHSA-chmv-r89p-xxr4.json index 9d94e3d17c9..eda1c87df72 100644 --- a/advisories/unreviewed/2022/05/GHSA-chmv-r89p-xxr4/GHSA-chmv-r89p-xxr4.json +++ b/advisories/unreviewed/2022/05/GHSA-chmv-r89p-xxr4/GHSA-chmv-r89p-xxr4.json @@ -7,12 +7,8 @@ "CVE-2015-4301" ], "details": "Cisco NX-OS on Nexus 9000 devices 11.1(1c) allows remote authenticated users to cause a denial of service (device hang) via large files that are copied to a device's filesystem, aka Bug ID CSCuu77225.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cj69-qv22-52jw/GHSA-cj69-qv22-52jw.json b/advisories/unreviewed/2022/05/GHSA-cj69-qv22-52jw/GHSA-cj69-qv22-52jw.json index f908b6f7402..8b1490ea771 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj69-qv22-52jw/GHSA-cj69-qv22-52jw.json +++ b/advisories/unreviewed/2022/05/GHSA-cj69-qv22-52jw/GHSA-cj69-qv22-52jw.json @@ -7,12 +7,8 @@ "CVE-2015-1246" ], "details": "Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cj9f-hg66-h4qv/GHSA-cj9f-hg66-h4qv.json b/advisories/unreviewed/2022/05/GHSA-cj9f-hg66-h4qv/GHSA-cj9f-hg66-h4qv.json index db65b36b6a5..cb886b3d994 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj9f-hg66-h4qv/GHSA-cj9f-hg66-h4qv.json +++ b/advisories/unreviewed/2022/05/GHSA-cj9f-hg66-h4qv/GHSA-cj9f-hg66-h4qv.json @@ -7,12 +7,8 @@ "CVE-2015-0439" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cjfg-wq59-q7v2/GHSA-cjfg-wq59-q7v2.json b/advisories/unreviewed/2022/05/GHSA-cjfg-wq59-q7v2/GHSA-cjfg-wq59-q7v2.json index cf4feadd51f..f00cc20bf60 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjfg-wq59-q7v2/GHSA-cjfg-wq59-q7v2.json +++ b/advisories/unreviewed/2022/05/GHSA-cjfg-wq59-q7v2/GHSA-cjfg-wq59-q7v2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cm42-9fc9-hr86/GHSA-cm42-9fc9-hr86.json b/advisories/unreviewed/2022/05/GHSA-cm42-9fc9-hr86/GHSA-cm42-9fc9-hr86.json index fa601825abe..6077df6a475 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm42-9fc9-hr86/GHSA-cm42-9fc9-hr86.json +++ b/advisories/unreviewed/2022/05/GHSA-cm42-9fc9-hr86/GHSA-cm42-9fc9-hr86.json @@ -7,12 +7,8 @@ "CVE-2015-2578" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 11.2 allows remote attackers to affect availability via vectors related to Kernel IDMap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cmm7-9576-wh39/GHSA-cmm7-9576-wh39.json b/advisories/unreviewed/2022/05/GHSA-cmm7-9576-wh39/GHSA-cmm7-9576-wh39.json index 0bb5e71a61b..e95640f35df 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmm7-9576-wh39/GHSA-cmm7-9576-wh39.json +++ b/advisories/unreviewed/2022/05/GHSA-cmm7-9576-wh39/GHSA-cmm7-9576-wh39.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpj3-4vwc-2h5c/GHSA-cpj3-4vwc-2h5c.json b/advisories/unreviewed/2022/05/GHSA-cpj3-4vwc-2h5c/GHSA-cpj3-4vwc-2h5c.json index 81f5fbf8aea..58a6092707e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpj3-4vwc-2h5c/GHSA-cpj3-4vwc-2h5c.json +++ b/advisories/unreviewed/2022/05/GHSA-cpj3-4vwc-2h5c/GHSA-cpj3-4vwc-2h5c.json @@ -7,12 +7,8 @@ "CVE-2015-6247" ], "details": "The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x before 1.12.7 does not validate a certain offset value, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cpxr-x8w8-p34j/GHSA-cpxr-x8w8-p34j.json b/advisories/unreviewed/2022/05/GHSA-cpxr-x8w8-p34j/GHSA-cpxr-x8w8-p34j.json index 5eb4ad35901..145171d4066 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpxr-x8w8-p34j/GHSA-cpxr-x8w8-p34j.json +++ b/advisories/unreviewed/2022/05/GHSA-cpxr-x8w8-p34j/GHSA-cpxr-x8w8-p34j.json @@ -7,12 +7,8 @@ "CVE-2015-2052" ], "details": "Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary code via a long string in a GetDeviceSettings action to the HNAP interface.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq25-j7mv-44h4/GHSA-cq25-j7mv-44h4.json b/advisories/unreviewed/2022/05/GHSA-cq25-j7mv-44h4/GHSA-cq25-j7mv-44h4.json index 0bbf704798e..6ad40a23d8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq25-j7mv-44h4/GHSA-cq25-j7mv-44h4.json +++ b/advisories/unreviewed/2022/05/GHSA-cq25-j7mv-44h4/GHSA-cq25-j7mv-44h4.json @@ -7,12 +7,8 @@ "CVE-2014-7852" ], "details": "Cross-site scripting (XSS) vulnerability in JBoss RichFaces, as used in JBoss Portal 6.1.1, allows remote attackers to inject arbitrary web script or HTML via crafted URL, which is not properly handled in a CSS file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cq2w-9r84-5hfm/GHSA-cq2w-9r84-5hfm.json b/advisories/unreviewed/2022/05/GHSA-cq2w-9r84-5hfm/GHSA-cq2w-9r84-5hfm.json index be95282555b..d06199aeeb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-cq2w-9r84-5hfm/GHSA-cq2w-9r84-5hfm.json +++ b/advisories/unreviewed/2022/05/GHSA-cq2w-9r84-5hfm/GHSA-cq2w-9r84-5hfm.json @@ -7,12 +7,8 @@ "CVE-2015-4259" ], "details": "The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka Bug IDs CSCum56133 and CSCum56177.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqx8-x2xg-ch4g/GHSA-cqx8-x2xg-ch4g.json b/advisories/unreviewed/2022/05/GHSA-cqx8-x2xg-ch4g/GHSA-cqx8-x2xg-ch4g.json index 9717090f2aa..88f291477fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqx8-x2xg-ch4g/GHSA-cqx8-x2xg-ch4g.json +++ b/advisories/unreviewed/2022/05/GHSA-cqx8-x2xg-ch4g/GHSA-cqx8-x2xg-ch4g.json @@ -7,12 +7,8 @@ "CVE-2015-5759" ], "details": "WebKit in Apple iOS before 8.4.1 allows remote attackers to spoof clicks via a crafted web site that leverages tap events.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cr45-v5gw-mw3r/GHSA-cr45-v5gw-mw3r.json b/advisories/unreviewed/2022/05/GHSA-cr45-v5gw-mw3r/GHSA-cr45-v5gw-mw3r.json index 73472f03b45..5297a6936c7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr45-v5gw-mw3r/GHSA-cr45-v5gw-mw3r.json +++ b/advisories/unreviewed/2022/05/GHSA-cr45-v5gw-mw3r/GHSA-cr45-v5gw-mw3r.json @@ -7,12 +7,8 @@ "CVE-2015-4134" ], "details": "Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-crfj-g9h4-8jc8/GHSA-crfj-g9h4-8jc8.json b/advisories/unreviewed/2022/05/GHSA-crfj-g9h4-8jc8/GHSA-crfj-g9h4-8jc8.json index 29cdb8ea9dc..f64f9ff5a1e 100644 --- a/advisories/unreviewed/2022/05/GHSA-crfj-g9h4-8jc8/GHSA-crfj-g9h4-8jc8.json +++ b/advisories/unreviewed/2022/05/GHSA-crfj-g9h4-8jc8/GHSA-crfj-g9h4-8jc8.json @@ -7,12 +7,8 @@ "CVE-2013-6474" ], "details": "Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crhx-xmfj-53jv/GHSA-crhx-xmfj-53jv.json b/advisories/unreviewed/2022/05/GHSA-crhx-xmfj-53jv/GHSA-crhx-xmfj-53jv.json index f4ceecd7d6b..117ca230e4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-crhx-xmfj-53jv/GHSA-crhx-xmfj-53jv.json +++ b/advisories/unreviewed/2022/05/GHSA-crhx-xmfj-53jv/GHSA-crhx-xmfj-53jv.json @@ -7,12 +7,8 @@ "CVE-2015-2206" ], "details": "libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-crq8-23gq-h59r/GHSA-crq8-23gq-h59r.json b/advisories/unreviewed/2022/05/GHSA-crq8-23gq-h59r/GHSA-crq8-23gq-h59r.json index f88ec1198bc..e82c0d4b788 100644 --- a/advisories/unreviewed/2022/05/GHSA-crq8-23gq-h59r/GHSA-crq8-23gq-h59r.json +++ b/advisories/unreviewed/2022/05/GHSA-crq8-23gq-h59r/GHSA-crq8-23gq-h59r.json @@ -7,12 +7,8 @@ "CVE-2015-4258" ], "details": "Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MSE 8000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90444.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cv6w-px65-v3wf/GHSA-cv6w-px65-v3wf.json b/advisories/unreviewed/2022/05/GHSA-cv6w-px65-v3wf/GHSA-cv6w-px65-v3wf.json index bafd2499f91..6b545ddfdc0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv6w-px65-v3wf/GHSA-cv6w-px65-v3wf.json +++ b/advisories/unreviewed/2022/05/GHSA-cv6w-px65-v3wf/GHSA-cv6w-px65-v3wf.json @@ -7,12 +7,8 @@ "CVE-2015-3326" ], "details": "Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote attackers to bypass authentication via a brute force attack.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cvx4-vgw7-p9gv/GHSA-cvx4-vgw7-p9gv.json b/advisories/unreviewed/2022/05/GHSA-cvx4-vgw7-p9gv/GHSA-cvx4-vgw7-p9gv.json index 6774bc94f07..d6c2a4a2e66 100644 --- a/advisories/unreviewed/2022/05/GHSA-cvx4-vgw7-p9gv/GHSA-cvx4-vgw7-p9gv.json +++ b/advisories/unreviewed/2022/05/GHSA-cvx4-vgw7-p9gv/GHSA-cvx4-vgw7-p9gv.json @@ -7,12 +7,8 @@ "CVE-2015-1262" ], "details": "platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, does not initialize a certain width field, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Unicode text.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cw72-8fv8-g25v/GHSA-cw72-8fv8-g25v.json b/advisories/unreviewed/2022/05/GHSA-cw72-8fv8-g25v/GHSA-cw72-8fv8-g25v.json index d249ec6ba7c..5b1a1bc7cab 100644 --- a/advisories/unreviewed/2022/05/GHSA-cw72-8fv8-g25v/GHSA-cw72-8fv8-g25v.json +++ b/advisories/unreviewed/2022/05/GHSA-cw72-8fv8-g25v/GHSA-cw72-8fv8-g25v.json @@ -7,12 +7,8 @@ "CVE-2015-5761" ], "details": "CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5755.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cwv7-pxrq-5hf8/GHSA-cwv7-pxrq-5hf8.json b/advisories/unreviewed/2022/05/GHSA-cwv7-pxrq-5hf8/GHSA-cwv7-pxrq-5hf8.json index ae72788b02a..6a9df96e2c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwv7-pxrq-5hf8/GHSA-cwv7-pxrq-5hf8.json +++ b/advisories/unreviewed/2022/05/GHSA-cwv7-pxrq-5hf8/GHSA-cwv7-pxrq-5hf8.json @@ -7,12 +7,8 @@ "CVE-2015-1236" ], "details": "The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cwww-4cwr-37ph/GHSA-cwww-4cwr-37ph.json b/advisories/unreviewed/2022/05/GHSA-cwww-4cwr-37ph/GHSA-cwww-4cwr-37ph.json index cacca5cd117..6fd0b2603bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwww-4cwr-37ph/GHSA-cwww-4cwr-37ph.json +++ b/advisories/unreviewed/2022/05/GHSA-cwww-4cwr-37ph/GHSA-cwww-4cwr-37ph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cx82-pq93-6p39/GHSA-cx82-pq93-6p39.json b/advisories/unreviewed/2022/05/GHSA-cx82-pq93-6p39/GHSA-cx82-pq93-6p39.json index 7997b7421bf..a520f583a01 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx82-pq93-6p39/GHSA-cx82-pq93-6p39.json +++ b/advisories/unreviewed/2022/05/GHSA-cx82-pq93-6p39/GHSA-cx82-pq93-6p39.json @@ -7,12 +7,8 @@ "CVE-2014-9721" ], "details": "libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxpv-4qr3-6ggq/GHSA-cxpv-4qr3-6ggq.json b/advisories/unreviewed/2022/05/GHSA-cxpv-4qr3-6ggq/GHSA-cxpv-4qr3-6ggq.json index fea87ac9548..311a39ca368 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxpv-4qr3-6ggq/GHSA-cxpv-4qr3-6ggq.json +++ b/advisories/unreviewed/2022/05/GHSA-cxpv-4qr3-6ggq/GHSA-cxpv-4qr3-6ggq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxr5-cqh9-cwrf/GHSA-cxr5-cqh9-cwrf.json b/advisories/unreviewed/2022/05/GHSA-cxr5-cqh9-cwrf/GHSA-cxr5-cqh9-cwrf.json index 46854a2ec01..1dcf8663a55 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxr5-cqh9-cwrf/GHSA-cxr5-cqh9-cwrf.json +++ b/advisories/unreviewed/2022/05/GHSA-cxr5-cqh9-cwrf/GHSA-cxr5-cqh9-cwrf.json @@ -7,12 +7,8 @@ "CVE-2015-6242" ], "details": "The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark 1.12.x before 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a memory chunk to its original size, which allows remote attackers to cause a denial of service (incorrect free operation and application crash) via a crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-cxw8-xrj2-2xqm/GHSA-cxw8-xrj2-2xqm.json b/advisories/unreviewed/2022/05/GHSA-cxw8-xrj2-2xqm/GHSA-cxw8-xrj2-2xqm.json index 15d077476e8..c824e8524b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-cxw8-xrj2-2xqm/GHSA-cxw8-xrj2-2xqm.json +++ b/advisories/unreviewed/2022/05/GHSA-cxw8-xrj2-2xqm/GHSA-cxw8-xrj2-2xqm.json @@ -7,12 +7,8 @@ "CVE-2015-1242" ], "details": "The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages \"type confusion\" in the check-elimination optimization.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f249-2fcr-8866/GHSA-f249-2fcr-8866.json b/advisories/unreviewed/2022/05/GHSA-f249-2fcr-8866/GHSA-f249-2fcr-8866.json index 89b13b54427..31b6aac4c1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-f249-2fcr-8866/GHSA-f249-2fcr-8866.json +++ b/advisories/unreviewed/2022/05/GHSA-f249-2fcr-8866/GHSA-f249-2fcr-8866.json @@ -7,12 +7,8 @@ "CVE-2013-7375" ], "details": "SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitrary SQL commands via the user ID in a user cookie, a different vulnerability than CVE-2013-1803.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f3p2-j336-wh42/GHSA-f3p2-j336-wh42.json b/advisories/unreviewed/2022/05/GHSA-f3p2-j336-wh42/GHSA-f3p2-j336-wh42.json index 59fff1fd6e4..a5d1754d44e 100644 --- a/advisories/unreviewed/2022/05/GHSA-f3p2-j336-wh42/GHSA-f3p2-j336-wh42.json +++ b/advisories/unreviewed/2022/05/GHSA-f3p2-j336-wh42/GHSA-f3p2-j336-wh42.json @@ -7,12 +7,8 @@ "CVE-2015-1974" ], "details": "The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote authenticated users to bypass intended command restrictions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f55c-cff2-h6j3/GHSA-f55c-cff2-h6j3.json b/advisories/unreviewed/2022/05/GHSA-f55c-cff2-h6j3/GHSA-f55c-cff2-h6j3.json index 18272d5d845..d37c53001ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-f55c-cff2-h6j3/GHSA-f55c-cff2-h6j3.json +++ b/advisories/unreviewed/2022/05/GHSA-f55c-cff2-h6j3/GHSA-f55c-cff2-h6j3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f58f-gpmv-fc35/GHSA-f58f-gpmv-fc35.json b/advisories/unreviewed/2022/05/GHSA-f58f-gpmv-fc35/GHSA-f58f-gpmv-fc35.json index d8093e97d30..4a310b597ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-f58f-gpmv-fc35/GHSA-f58f-gpmv-fc35.json +++ b/advisories/unreviewed/2022/05/GHSA-f58f-gpmv-fc35/GHSA-f58f-gpmv-fc35.json @@ -7,12 +7,8 @@ "CVE-2015-5756" ], "details": "FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and CVE-2015-5775.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f64w-hg82-2rqv/GHSA-f64w-hg82-2rqv.json b/advisories/unreviewed/2022/05/GHSA-f64w-hg82-2rqv/GHSA-f64w-hg82-2rqv.json index b854f49e856..e1f5c47997c 100644 --- a/advisories/unreviewed/2022/05/GHSA-f64w-hg82-2rqv/GHSA-f64w-hg82-2rqv.json +++ b/advisories/unreviewed/2022/05/GHSA-f64w-hg82-2rqv/GHSA-f64w-hg82-2rqv.json @@ -7,12 +7,8 @@ "CVE-2015-4051" ], "details": "Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as demonstrated by a beckhoff.com:service:cxconfig:1#Write SOAP action to /upnpisapi.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-f6vv-86p4-jjqr/GHSA-f6vv-86p4-jjqr.json b/advisories/unreviewed/2022/05/GHSA-f6vv-86p4-jjqr/GHSA-f6vv-86p4-jjqr.json index 3d77d2a384f..404af45ba29 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6vv-86p4-jjqr/GHSA-f6vv-86p4-jjqr.json +++ b/advisories/unreviewed/2022/05/GHSA-f6vv-86p4-jjqr/GHSA-f6vv-86p4-jjqr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fcg8-gw57-7w3c/GHSA-fcg8-gw57-7w3c.json b/advisories/unreviewed/2022/05/GHSA-fcg8-gw57-7w3c/GHSA-fcg8-gw57-7w3c.json index 8a5646f972a..3355d1763ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-fcg8-gw57-7w3c/GHSA-fcg8-gw57-7w3c.json +++ b/advisories/unreviewed/2022/05/GHSA-fcg8-gw57-7w3c/GHSA-fcg8-gw57-7w3c.json @@ -7,12 +7,8 @@ "CVE-2014-9161" ], "details": "CoolType.dll in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows, and 10.x through 10.1.13 and 11.x through 11.0.10 on OS X, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted PDF document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff32-6745-wcvq/GHSA-ff32-6745-wcvq.json b/advisories/unreviewed/2022/05/GHSA-ff32-6745-wcvq/GHSA-ff32-6745-wcvq.json index 9b5d6452488..27d2a623a97 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff32-6745-wcvq/GHSA-ff32-6745-wcvq.json +++ b/advisories/unreviewed/2022/05/GHSA-ff32-6745-wcvq/GHSA-ff32-6745-wcvq.json @@ -7,12 +7,8 @@ "CVE-2015-3725" ], "details": "MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ff38-j34r-r7q3/GHSA-ff38-j34r-r7q3.json b/advisories/unreviewed/2022/05/GHSA-ff38-j34r-r7q3/GHSA-ff38-j34r-r7q3.json index 4194a0924bc..e14f666abd9 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff38-j34r-r7q3/GHSA-ff38-j34r-r7q3.json +++ b/advisories/unreviewed/2022/05/GHSA-ff38-j34r-r7q3/GHSA-ff38-j34r-r7q3.json @@ -7,12 +7,8 @@ "CVE-2013-7349" ], "details": "Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter to news/send.php, (2) thread_id parameter to posts/edit.php, or (3) user_email parameter to users/password.php or (4) users/register.php. NOTE: these issues were SPLIT from CVE-2013-5640 due to differences in researchers and disclosure dates.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ff56-mpjv-8r2j/GHSA-ff56-mpjv-8r2j.json b/advisories/unreviewed/2022/05/GHSA-ff56-mpjv-8r2j/GHSA-ff56-mpjv-8r2j.json index 4bbd44639af..649c49b5983 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff56-mpjv-8r2j/GHSA-ff56-mpjv-8r2j.json +++ b/advisories/unreviewed/2022/05/GHSA-ff56-mpjv-8r2j/GHSA-ff56-mpjv-8r2j.json @@ -7,12 +7,8 @@ "CVE-2014-9715" ], "details": "include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insufficiently large data type for certain extension data, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via outbound network traffic that triggers extension loading, as demonstrated by configuring a PPTP tunnel in a NAT environment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ff9j-2g3f-hmwq/GHSA-ff9j-2g3f-hmwq.json b/advisories/unreviewed/2022/05/GHSA-ff9j-2g3f-hmwq/GHSA-ff9j-2g3f-hmwq.json index b398ca0a033..e0a0f108197 100644 --- a/advisories/unreviewed/2022/05/GHSA-ff9j-2g3f-hmwq/GHSA-ff9j-2g3f-hmwq.json +++ b/advisories/unreviewed/2022/05/GHSA-ff9j-2g3f-hmwq/GHSA-ff9j-2g3f-hmwq.json @@ -7,12 +7,8 @@ "CVE-2015-0189" ], "details": "The cluster repository manager in IBM WebSphere MQ 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allows remote authenticated administrators to cause a denial of service (memory overwrite and daemon outage) by triggering multiple transmit-queue records.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ffp2-64hp-w22f/GHSA-ffp2-64hp-w22f.json b/advisories/unreviewed/2022/05/GHSA-ffp2-64hp-w22f/GHSA-ffp2-64hp-w22f.json index 7778fa960c9..a71148da34b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffp2-64hp-w22f/GHSA-ffp2-64hp-w22f.json +++ b/advisories/unreviewed/2022/05/GHSA-ffp2-64hp-w22f/GHSA-ffp2-64hp-w22f.json @@ -7,12 +7,8 @@ "CVE-2015-0506" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2015-0508.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fg3v-pvcm-8hvr/GHSA-fg3v-pvcm-8hvr.json b/advisories/unreviewed/2022/05/GHSA-fg3v-pvcm-8hvr/GHSA-fg3v-pvcm-8hvr.json index 457f6ab6a53..2bb48ed69c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg3v-pvcm-8hvr/GHSA-fg3v-pvcm-8hvr.json +++ b/advisories/unreviewed/2022/05/GHSA-fg3v-pvcm-8hvr/GHSA-fg3v-pvcm-8hvr.json @@ -7,12 +7,8 @@ "CVE-2015-1953" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fgjp-x7x2-6wf6/GHSA-fgjp-x7x2-6wf6.json b/advisories/unreviewed/2022/05/GHSA-fgjp-x7x2-6wf6/GHSA-fgjp-x7x2-6wf6.json index 3d408dba758..c0132c14e30 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgjp-x7x2-6wf6/GHSA-fgjp-x7x2-6wf6.json +++ b/advisories/unreviewed/2022/05/GHSA-fgjp-x7x2-6wf6/GHSA-fgjp-x7x2-6wf6.json @@ -7,12 +7,8 @@ "CVE-2015-4253" ], "details": "Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Serial Gateway devices with software 1.0(1.42) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90728.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fh6g-xj4c-5fmv/GHSA-fh6g-xj4c-5fmv.json b/advisories/unreviewed/2022/05/GHSA-fh6g-xj4c-5fmv/GHSA-fh6g-xj4c-5fmv.json index 4c5540a4d29..a834433c2fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-fh6g-xj4c-5fmv/GHSA-fh6g-xj4c-5fmv.json +++ b/advisories/unreviewed/2022/05/GHSA-fh6g-xj4c-5fmv/GHSA-fh6g-xj4c-5fmv.json @@ -7,12 +7,8 @@ "CVE-2015-4267" ], "details": "Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(0.793), 1.3(0.876), 1.4(0.109), 2.0(0.147), and 2.0(0.169) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus09940.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fhv9-q298-644g/GHSA-fhv9-q298-644g.json b/advisories/unreviewed/2022/05/GHSA-fhv9-q298-644g/GHSA-fhv9-q298-644g.json index 79d8661fe5c..ae8b70b2b23 100644 --- a/advisories/unreviewed/2022/05/GHSA-fhv9-q298-644g/GHSA-fhv9-q298-644g.json +++ b/advisories/unreviewed/2022/05/GHSA-fhv9-q298-644g/GHSA-fhv9-q298-644g.json @@ -7,12 +7,8 @@ "CVE-2014-7944" ], "details": "The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.91, does not properly handle odd values of image width, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fj54-786p-rwg3/GHSA-fj54-786p-rwg3.json b/advisories/unreviewed/2022/05/GHSA-fj54-786p-rwg3/GHSA-fj54-786p-rwg3.json index a2a7b33f838..b810801a156 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj54-786p-rwg3/GHSA-fj54-786p-rwg3.json +++ b/advisories/unreviewed/2022/05/GHSA-fj54-786p-rwg3/GHSA-fj54-786p-rwg3.json @@ -7,12 +7,8 @@ "CVE-2013-5005" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in ajaxRequest/methodCall.do in Tripwire Enterprise 8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) m_target_class_name, (2) m_target_method_name, or (3) m_request_context_params parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fjxr-28c8-xp4f/GHSA-fjxr-28c8-xp4f.json b/advisories/unreviewed/2022/05/GHSA-fjxr-28c8-xp4f/GHSA-fjxr-28c8-xp4f.json index 4dc67c73472..36d2baa9b27 100644 --- a/advisories/unreviewed/2022/05/GHSA-fjxr-28c8-xp4f/GHSA-fjxr-28c8-xp4f.json +++ b/advisories/unreviewed/2022/05/GHSA-fjxr-28c8-xp4f/GHSA-fjxr-28c8-xp4f.json @@ -7,12 +7,8 @@ "CVE-2015-1941" ], "details": "The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an unspecified port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fm68-9vx2-78fv/GHSA-fm68-9vx2-78fv.json b/advisories/unreviewed/2022/05/GHSA-fm68-9vx2-78fv/GHSA-fm68-9vx2-78fv.json index 4997336a6bb..22d428d817a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fm68-9vx2-78fv/GHSA-fm68-9vx2-78fv.json +++ b/advisories/unreviewed/2022/05/GHSA-fm68-9vx2-78fv/GHSA-fm68-9vx2-78fv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fmjc-gqw6-mrv8/GHSA-fmjc-gqw6-mrv8.json b/advisories/unreviewed/2022/05/GHSA-fmjc-gqw6-mrv8/GHSA-fmjc-gqw6-mrv8.json index 1cb78460860..30806285e7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmjc-gqw6-mrv8/GHSA-fmjc-gqw6-mrv8.json +++ b/advisories/unreviewed/2022/05/GHSA-fmjc-gqw6-mrv8/GHSA-fmjc-gqw6-mrv8.json @@ -7,12 +7,8 @@ "CVE-2015-4272" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page in Cisco Unified Communications Manager (formerly CallManager) 10.5(2.10000.5) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCut19580.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fpqv-m26w-pgqx/GHSA-fpqv-m26w-pgqx.json b/advisories/unreviewed/2022/05/GHSA-fpqv-m26w-pgqx/GHSA-fpqv-m26w-pgqx.json index 90745e2debe..93185ad4d6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fpqv-m26w-pgqx/GHSA-fpqv-m26w-pgqx.json +++ b/advisories/unreviewed/2022/05/GHSA-fpqv-m26w-pgqx/GHSA-fpqv-m26w-pgqx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fq5f-mc35-vh53/GHSA-fq5f-mc35-vh53.json b/advisories/unreviewed/2022/05/GHSA-fq5f-mc35-vh53/GHSA-fq5f-mc35-vh53.json index e9dee65fe8f..9320f770e50 100644 --- a/advisories/unreviewed/2022/05/GHSA-fq5f-mc35-vh53/GHSA-fq5f-mc35-vh53.json +++ b/advisories/unreviewed/2022/05/GHSA-fq5f-mc35-vh53/GHSA-fq5f-mc35-vh53.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fqgm-98vq-7hgr/GHSA-fqgm-98vq-7hgr.json b/advisories/unreviewed/2022/05/GHSA-fqgm-98vq-7hgr/GHSA-fqgm-98vq-7hgr.json index 558597deabd..6e7bd8d1087 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqgm-98vq-7hgr/GHSA-fqgm-98vq-7hgr.json +++ b/advisories/unreviewed/2022/05/GHSA-fqgm-98vq-7hgr/GHSA-fqgm-98vq-7hgr.json @@ -7,12 +7,8 @@ "CVE-2013-2072" ], "details": "Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fqwq-wr4g-qffh/GHSA-fqwq-wr4g-qffh.json b/advisories/unreviewed/2022/05/GHSA-fqwq-wr4g-qffh/GHSA-fqwq-wr4g-qffh.json index 3f06ab1f494..3ac5a6d6bfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-fqwq-wr4g-qffh/GHSA-fqwq-wr4g-qffh.json +++ b/advisories/unreviewed/2022/05/GHSA-fqwq-wr4g-qffh/GHSA-fqwq-wr4g-qffh.json @@ -7,12 +7,8 @@ "CVE-2015-0490" ], "details": "Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to BAS - Base Component.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fr49-w774-hwch/GHSA-fr49-w774-hwch.json b/advisories/unreviewed/2022/05/GHSA-fr49-w774-hwch/GHSA-fr49-w774-hwch.json index 7273a4f9c83..302e6a28a6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr49-w774-hwch/GHSA-fr49-w774-hwch.json +++ b/advisories/unreviewed/2022/05/GHSA-fr49-w774-hwch/GHSA-fr49-w774-hwch.json @@ -7,12 +7,8 @@ "CVE-2014-8730" ], "details": "The SSL profiles component in F5 BIG-IP LTM, APM, and ASM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, AAM 11.4.0 through 11.5.1, AFM 11.3.0 through 11.5.1, Analytics 11.0.0 through 11.5.1, Edge Gateway, WebAccelerator, and WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, PEM 11.3.0 through 11.6.0, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.4.1 and BIG-IQ Cloud and Security 4.0.0 through 4.4.0 and Device 4.2.0 through 4.4.0, when using TLS 1.x before TLS 1.2, does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE). NOTE: the scope of this identifier is limited to the F5 implementation only. Other vulnerable implementations should receive their own CVE ID, since this is not a vulnerability within the design of TLS 1.x itself.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fvg9-44pc-6w5x/GHSA-fvg9-44pc-6w5x.json b/advisories/unreviewed/2022/05/GHSA-fvg9-44pc-6w5x/GHSA-fvg9-44pc-6w5x.json index eecb55bd58e..feb20a4692f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvg9-44pc-6w5x/GHSA-fvg9-44pc-6w5x.json +++ b/advisories/unreviewed/2022/05/GHSA-fvg9-44pc-6w5x/GHSA-fvg9-44pc-6w5x.json @@ -7,12 +7,8 @@ "CVE-2015-1257" ], "details": "platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handle an insufficient number of values in an feColorMatrix filter, which allows remote attackers to cause a denial of service (container overflow) or possibly have unspecified other impact via a crafted document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fvm9-qc7j-544c/GHSA-fvm9-qc7j-544c.json b/advisories/unreviewed/2022/05/GHSA-fvm9-qc7j-544c/GHSA-fvm9-qc7j-544c.json index 89dc7e11bff..098c52b66e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvm9-qc7j-544c/GHSA-fvm9-qc7j-544c.json +++ b/advisories/unreviewed/2022/05/GHSA-fvm9-qc7j-544c/GHSA-fvm9-qc7j-544c.json @@ -7,12 +7,8 @@ "CVE-2015-6665" ], "details": "Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the \"a\" tag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fw8r-j75g-9f4r/GHSA-fw8r-j75g-9f4r.json b/advisories/unreviewed/2022/05/GHSA-fw8r-j75g-9f4r/GHSA-fw8r-j75g-9f4r.json index 23ddf0c2e43..247b2ca5d83 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw8r-j75g-9f4r/GHSA-fw8r-j75g-9f4r.json +++ b/advisories/unreviewed/2022/05/GHSA-fw8r-j75g-9f4r/GHSA-fw8r-j75g-9f4r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fwqh-hp5q-r4gh/GHSA-fwqh-hp5q-r4gh.json b/advisories/unreviewed/2022/05/GHSA-fwqh-hp5q-r4gh/GHSA-fwqh-hp5q-r4gh.json index 4e857e850d0..6eb22dbf6fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwqh-hp5q-r4gh/GHSA-fwqh-hp5q-r4gh.json +++ b/advisories/unreviewed/2022/05/GHSA-fwqh-hp5q-r4gh/GHSA-fwqh-hp5q-r4gh.json @@ -7,12 +7,8 @@ "CVE-2015-4224" ], "details": "Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug ID CSCuj39474.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-fxj6-f74w-fmhr/GHSA-fxj6-f74w-fmhr.json b/advisories/unreviewed/2022/05/GHSA-fxj6-f74w-fmhr/GHSA-fxj6-f74w-fmhr.json index acde30d1c54..9a749252017 100644 --- a/advisories/unreviewed/2022/05/GHSA-fxj6-f74w-fmhr/GHSA-fxj6-f74w-fmhr.json +++ b/advisories/unreviewed/2022/05/GHSA-fxj6-f74w-fmhr/GHSA-fxj6-f74w-fmhr.json @@ -7,12 +7,8 @@ "CVE-2014-7936" ], "details": "Use-after-free vulnerability in the ZoomBubbleView::Close function in browser/ui/views/location_bar/zoom_bubble_view.cc in the Views implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that triggers improper maintenance of a zoom bubble.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g22f-672c-27cg/GHSA-g22f-672c-27cg.json b/advisories/unreviewed/2022/05/GHSA-g22f-672c-27cg/GHSA-g22f-672c-27cg.json index 46c7491a5ca..831145d1c3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-g22f-672c-27cg/GHSA-g22f-672c-27cg.json +++ b/advisories/unreviewed/2022/05/GHSA-g22f-672c-27cg/GHSA-g22f-672c-27cg.json @@ -7,12 +7,8 @@ "CVE-2014-7947" ], "details": "OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g27v-jcrx-f673/GHSA-g27v-jcrx-f673.json b/advisories/unreviewed/2022/05/GHSA-g27v-jcrx-f673/GHSA-g27v-jcrx-f673.json index cd145d1774a..89f1d0c4ca4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g27v-jcrx-f673/GHSA-g27v-jcrx-f673.json +++ b/advisories/unreviewed/2022/05/GHSA-g27v-jcrx-f673/GHSA-g27v-jcrx-f673.json @@ -7,12 +7,8 @@ "CVE-2015-3723" ], "details": "CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3724.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g2r3-r98c-7g53/GHSA-g2r3-r98c-7g53.json b/advisories/unreviewed/2022/05/GHSA-g2r3-r98c-7g53/GHSA-g2r3-r98c-7g53.json index e15438ba5e9..ebc2b6b2234 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2r3-r98c-7g53/GHSA-g2r3-r98c-7g53.json +++ b/advisories/unreviewed/2022/05/GHSA-g2r3-r98c-7g53/GHSA-g2r3-r98c-7g53.json @@ -7,12 +7,8 @@ "CVE-2015-2714" ], "details": "Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g2r6-v9mj-qx9w/GHSA-g2r6-v9mj-qx9w.json b/advisories/unreviewed/2022/05/GHSA-g2r6-v9mj-qx9w/GHSA-g2r6-v9mj-qx9w.json index d7a7f719ebb..ae19e645cc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2r6-v9mj-qx9w/GHSA-g2r6-v9mj-qx9w.json +++ b/advisories/unreviewed/2022/05/GHSA-g2r6-v9mj-qx9w/GHSA-g2r6-v9mj-qx9w.json @@ -7,12 +7,8 @@ "CVE-2007-3106" ], "details": "lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via invalid (1) blocksize_0 and (2) blocksize_1 values, which trigger a \"heap overwrite\" in the _01inverse function in res0.c. NOTE: this issue has been RECAST so that CVE-2007-4029 handles additional vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5cf-7wmc-6v8q/GHSA-g5cf-7wmc-6v8q.json b/advisories/unreviewed/2022/05/GHSA-g5cf-7wmc-6v8q/GHSA-g5cf-7wmc-6v8q.json index 39bab877f64..74f3127fcd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5cf-7wmc-6v8q/GHSA-g5cf-7wmc-6v8q.json +++ b/advisories/unreviewed/2022/05/GHSA-g5cf-7wmc-6v8q/GHSA-g5cf-7wmc-6v8q.json @@ -7,12 +7,8 @@ "CVE-2015-4746" ], "details": "Unspecified vulnerability in the Oracle Agile Product Lifecycle Management for Process component in Oracle Supply Chain Products Suite 6.0.0.7, 6.1.0.3, 6.1.1.5, and 6.2.0.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Global Spec Management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g5hr-gmvw-m425/GHSA-g5hr-gmvw-m425.json b/advisories/unreviewed/2022/05/GHSA-g5hr-gmvw-m425/GHSA-g5hr-gmvw-m425.json index b546177f699..b26fc1efaed 100644 --- a/advisories/unreviewed/2022/05/GHSA-g5hr-gmvw-m425/GHSA-g5hr-gmvw-m425.json +++ b/advisories/unreviewed/2022/05/GHSA-g5hr-gmvw-m425/GHSA-g5hr-gmvw-m425.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g7rp-q2cv-gcmf/GHSA-g7rp-q2cv-gcmf.json b/advisories/unreviewed/2022/05/GHSA-g7rp-q2cv-gcmf/GHSA-g7rp-q2cv-gcmf.json index ee28ce50907..cd8a4ee5d76 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7rp-q2cv-gcmf/GHSA-g7rp-q2cv-gcmf.json +++ b/advisories/unreviewed/2022/05/GHSA-g7rp-q2cv-gcmf/GHSA-g7rp-q2cv-gcmf.json @@ -7,12 +7,8 @@ "CVE-2015-1260" ], "details": "Multiple use-after-free vulnerabilities in content/renderer/media/user_media_client_impl.cc in the WebRTC implementation in Google Chrome before 43.0.2357.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that executes upon completion of a getUserMedia request.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-g86g-ggjj-ppxm/GHSA-g86g-ggjj-ppxm.json b/advisories/unreviewed/2022/05/GHSA-g86g-ggjj-ppxm/GHSA-g86g-ggjj-ppxm.json index 46d941815fd..37aae727d57 100644 --- a/advisories/unreviewed/2022/05/GHSA-g86g-ggjj-ppxm/GHSA-g86g-ggjj-ppxm.json +++ b/advisories/unreviewed/2022/05/GHSA-g86g-ggjj-ppxm/GHSA-g86g-ggjj-ppxm.json @@ -7,12 +7,8 @@ "CVE-2015-1244" ], "details": "The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g8jj-53w4-q584/GHSA-g8jj-53w4-q584.json b/advisories/unreviewed/2022/05/GHSA-g8jj-53w4-q584/GHSA-g8jj-53w4-q584.json index 0e87f8d4922..180ed6ced16 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8jj-53w4-q584/GHSA-g8jj-53w4-q584.json +++ b/advisories/unreviewed/2022/05/GHSA-g8jj-53w4-q584/GHSA-g8jj-53w4-q584.json @@ -7,12 +7,8 @@ "CVE-2015-0344" ], "details": "Cross-site scripting (XSS) vulnerability in the web app in Adobe Connect before 9.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g93q-f2ww-cqcx/GHSA-g93q-f2ww-cqcx.json b/advisories/unreviewed/2022/05/GHSA-g93q-f2ww-cqcx/GHSA-g93q-f2ww-cqcx.json index 3743a2ccabf..9e72e1e4341 100644 --- a/advisories/unreviewed/2022/05/GHSA-g93q-f2ww-cqcx/GHSA-g93q-f2ww-cqcx.json +++ b/advisories/unreviewed/2022/05/GHSA-g93q-f2ww-cqcx/GHSA-g93q-f2ww-cqcx.json @@ -7,12 +7,8 @@ "CVE-2015-1962" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9cj-g4rw-3p5m/GHSA-g9cj-g4rw-3p5m.json b/advisories/unreviewed/2022/05/GHSA-g9cj-g4rw-3p5m/GHSA-g9cj-g4rw-3p5m.json index 8cffb359037..f5eed0324be 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9cj-g4rw-3p5m/GHSA-g9cj-g4rw-3p5m.json +++ b/advisories/unreviewed/2022/05/GHSA-g9cj-g4rw-3p5m/GHSA-g9cj-g4rw-3p5m.json @@ -7,12 +7,8 @@ "CVE-2015-4201" ], "details": "The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header, aka Bug ID CSCut68058.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-g9ff-c72j-2fjq/GHSA-g9ff-c72j-2fjq.json b/advisories/unreviewed/2022/05/GHSA-g9ff-c72j-2fjq/GHSA-g9ff-c72j-2fjq.json index b0fad969917..6aad59b4c46 100644 --- a/advisories/unreviewed/2022/05/GHSA-g9ff-c72j-2fjq/GHSA-g9ff-c72j-2fjq.json +++ b/advisories/unreviewed/2022/05/GHSA-g9ff-c72j-2fjq/GHSA-g9ff-c72j-2fjq.json @@ -7,12 +7,8 @@ "CVE-2015-2339" ], "details": "TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2338.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gc82-5wf6-rgrq/GHSA-gc82-5wf6-rgrq.json b/advisories/unreviewed/2022/05/GHSA-gc82-5wf6-rgrq/GHSA-gc82-5wf6-rgrq.json index 1dd405e9b6f..00f4c621de0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc82-5wf6-rgrq/GHSA-gc82-5wf6-rgrq.json +++ b/advisories/unreviewed/2022/05/GHSA-gc82-5wf6-rgrq/GHSA-gc82-5wf6-rgrq.json @@ -7,12 +7,8 @@ "CVE-2015-2566" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via vectors related to DML.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gcw4-w87m-5fhj/GHSA-gcw4-w87m-5fhj.json b/advisories/unreviewed/2022/05/GHSA-gcw4-w87m-5fhj/GHSA-gcw4-w87m-5fhj.json index c3965f58f33..efc094c7398 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcw4-w87m-5fhj/GHSA-gcw4-w87m-5fhj.json +++ b/advisories/unreviewed/2022/05/GHSA-gcw4-w87m-5fhj/GHSA-gcw4-w87m-5fhj.json @@ -7,12 +7,8 @@ "CVE-2015-1942" ], "details": "The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to write to arbitrary files, and subsequently execute these files, via a crafted TCP packet to an unspecified port.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gf65-6jjm-7xgc/GHSA-gf65-6jjm-7xgc.json b/advisories/unreviewed/2022/05/GHSA-gf65-6jjm-7xgc/GHSA-gf65-6jjm-7xgc.json index b326d814393..31dc089324e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf65-6jjm-7xgc/GHSA-gf65-6jjm-7xgc.json +++ b/advisories/unreviewed/2022/05/GHSA-gf65-6jjm-7xgc/GHSA-gf65-6jjm-7xgc.json @@ -7,12 +7,8 @@ "CVE-2015-3659" ], "details": "The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gg4m-mr27-r5f8/GHSA-gg4m-mr27-r5f8.json b/advisories/unreviewed/2022/05/GHSA-gg4m-mr27-r5f8/GHSA-gg4m-mr27-r5f8.json index 963764a310e..c7279bd01d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gg4m-mr27-r5f8/GHSA-gg4m-mr27-r5f8.json +++ b/advisories/unreviewed/2022/05/GHSA-gg4m-mr27-r5f8/GHSA-gg4m-mr27-r5f8.json @@ -7,12 +7,8 @@ "CVE-2014-8635" ], "details": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ggv6-xx7h-v52r/GHSA-ggv6-xx7h-v52r.json b/advisories/unreviewed/2022/05/GHSA-ggv6-xx7h-v52r/GHSA-ggv6-xx7h-v52r.json index 6f4b75c542f..de26c38c73e 100644 --- a/advisories/unreviewed/2022/05/GHSA-ggv6-xx7h-v52r/GHSA-ggv6-xx7h-v52r.json +++ b/advisories/unreviewed/2022/05/GHSA-ggv6-xx7h-v52r/GHSA-ggv6-xx7h-v52r.json @@ -7,12 +7,8 @@ "CVE-2015-1929" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ghjp-8c78-gf93/GHSA-ghjp-8c78-gf93.json b/advisories/unreviewed/2022/05/GHSA-ghjp-8c78-gf93/GHSA-ghjp-8c78-gf93.json index eb3653c8377..dbaeb810e28 100644 --- a/advisories/unreviewed/2022/05/GHSA-ghjp-8c78-gf93/GHSA-ghjp-8c78-gf93.json +++ b/advisories/unreviewed/2022/05/GHSA-ghjp-8c78-gf93/GHSA-ghjp-8c78-gf93.json @@ -7,12 +7,8 @@ "CVE-2015-1111" ], "details": "Safari in Apple iOS before 8.3 does not delete Recently Closed Tabs data in response to a history-clearing action, which allows attackers to obtain sensitive information by reading a history file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjgq-j5px-2wv8/GHSA-gjgq-j5px-2wv8.json b/advisories/unreviewed/2022/05/GHSA-gjgq-j5px-2wv8/GHSA-gjgq-j5px-2wv8.json index 37014f31936..b43eb20dd15 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjgq-j5px-2wv8/GHSA-gjgq-j5px-2wv8.json +++ b/advisories/unreviewed/2022/05/GHSA-gjgq-j5px-2wv8/GHSA-gjgq-j5px-2wv8.json @@ -7,12 +7,8 @@ "CVE-2015-5785" ], "details": "Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-5786.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gjjm-x2xg-8xgc/GHSA-gjjm-x2xg-8xgc.json b/advisories/unreviewed/2022/05/GHSA-gjjm-x2xg-8xgc/GHSA-gjjm-x2xg-8xgc.json index ced23eaa9e3..51bea5729c8 100644 --- a/advisories/unreviewed/2022/05/GHSA-gjjm-x2xg-8xgc/GHSA-gjjm-x2xg-8xgc.json +++ b/advisories/unreviewed/2022/05/GHSA-gjjm-x2xg-8xgc/GHSA-gjjm-x2xg-8xgc.json @@ -7,12 +7,8 @@ "CVE-2015-6259" ], "details": "The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gm84-c739-5hpp/GHSA-gm84-c739-5hpp.json b/advisories/unreviewed/2022/05/GHSA-gm84-c739-5hpp/GHSA-gm84-c739-5hpp.json index fe0162326df..18f3d8a0802 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm84-c739-5hpp/GHSA-gm84-c739-5hpp.json +++ b/advisories/unreviewed/2022/05/GHSA-gm84-c739-5hpp/GHSA-gm84-c739-5hpp.json @@ -7,12 +7,8 @@ "CVE-2014-7930" ], "details": "Use-after-free vulnerability in core/events/TreeScopeEventContext.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper maintenance of TreeScope data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gm89-5jj3-5f7f/GHSA-gm89-5jj3-5f7f.json b/advisories/unreviewed/2022/05/GHSA-gm89-5jj3-5f7f/GHSA-gm89-5jj3-5f7f.json index 4a855db91de..03edc6f237e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm89-5jj3-5f7f/GHSA-gm89-5jj3-5f7f.json +++ b/advisories/unreviewed/2022/05/GHSA-gm89-5jj3-5f7f/GHSA-gm89-5jj3-5f7f.json @@ -7,12 +7,8 @@ "CVE-2015-7000" ], "details": "Notification Center in Apple iOS before 9.1 mishandles changes to \"Show on Lock Screen\" settings, which allows physically proximate attackers to obtain sensitive information by looking for a (1) Phone or (2) Messages notification on the lock screen soon after a setting was disabled.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmh5-5f53-3929/GHSA-gmh5-5f53-3929.json b/advisories/unreviewed/2022/05/GHSA-gmh5-5f53-3929/GHSA-gmh5-5f53-3929.json index 931b0a0f20a..f76306945e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmh5-5f53-3929/GHSA-gmh5-5f53-3929.json +++ b/advisories/unreviewed/2022/05/GHSA-gmh5-5f53-3929/GHSA-gmh5-5f53-3929.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gmh7-v95w-mh6p/GHSA-gmh7-v95w-mh6p.json b/advisories/unreviewed/2022/05/GHSA-gmh7-v95w-mh6p/GHSA-gmh7-v95w-mh6p.json index 925976795d4..a440c4101f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-gmh7-v95w-mh6p/GHSA-gmh7-v95w-mh6p.json +++ b/advisories/unreviewed/2022/05/GHSA-gmh7-v95w-mh6p/GHSA-gmh7-v95w-mh6p.json @@ -7,12 +7,8 @@ "CVE-2015-6300" ], "details": "Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gp5c-v4fj-c3g3/GHSA-gp5c-v4fj-c3g3.json b/advisories/unreviewed/2022/05/GHSA-gp5c-v4fj-c3g3/GHSA-gp5c-v4fj-c3g3.json index 8e85750e7ee..d2868101b21 100644 --- a/advisories/unreviewed/2022/05/GHSA-gp5c-v4fj-c3g3/GHSA-gp5c-v4fj-c3g3.json +++ b/advisories/unreviewed/2022/05/GHSA-gp5c-v4fj-c3g3/GHSA-gp5c-v4fj-c3g3.json @@ -7,12 +7,8 @@ "CVE-2015-0462" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, and 6.3.6 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gqgc-5x67-vjjh/GHSA-gqgc-5x67-vjjh.json b/advisories/unreviewed/2022/05/GHSA-gqgc-5x67-vjjh/GHSA-gqgc-5x67-vjjh.json index 250cca22681..39922295959 100644 --- a/advisories/unreviewed/2022/05/GHSA-gqgc-5x67-vjjh/GHSA-gqgc-5x67-vjjh.json +++ b/advisories/unreviewed/2022/05/GHSA-gqgc-5x67-vjjh/GHSA-gqgc-5x67-vjjh.json @@ -7,12 +7,8 @@ "CVE-2015-0507" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gr2m-6qq8-c2w2/GHSA-gr2m-6qq8-c2w2.json b/advisories/unreviewed/2022/05/GHSA-gr2m-6qq8-c2w2/GHSA-gr2m-6qq8-c2w2.json index 546778dc15e..4245f7f9a3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-gr2m-6qq8-c2w2/GHSA-gr2m-6qq8-c2w2.json +++ b/advisories/unreviewed/2022/05/GHSA-gr2m-6qq8-c2w2/GHSA-gr2m-6qq8-c2w2.json @@ -7,12 +7,8 @@ "CVE-2015-3632" ], "details": "Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-grrh-62pc-382r/GHSA-grrh-62pc-382r.json b/advisories/unreviewed/2022/05/GHSA-grrh-62pc-382r/GHSA-grrh-62pc-382r.json index 10105f9c992..b5c432f193a 100644 --- a/advisories/unreviewed/2022/05/GHSA-grrh-62pc-382r/GHSA-grrh-62pc-382r.json +++ b/advisories/unreviewed/2022/05/GHSA-grrh-62pc-382r/GHSA-grrh-62pc-382r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gx65-cr9q-7fgc/GHSA-gx65-cr9q-7fgc.json b/advisories/unreviewed/2022/05/GHSA-gx65-cr9q-7fgc/GHSA-gx65-cr9q-7fgc.json index 79f1a699eaa..ddeb0f81ba3 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx65-cr9q-7fgc/GHSA-gx65-cr9q-7fgc.json +++ b/advisories/unreviewed/2022/05/GHSA-gx65-cr9q-7fgc/GHSA-gx65-cr9q-7fgc.json @@ -7,12 +7,8 @@ "CVE-2013-4568" ], "details": "Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain non-ASCII characters in CSS, as demonstrated using variations of \"expression\" containing (1) full width characters or (2) IPA extensions, which are converted and rendered by Internet Explorer.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gx95-jx2h-w327/GHSA-gx95-jx2h-w327.json b/advisories/unreviewed/2022/05/GHSA-gx95-jx2h-w327/GHSA-gx95-jx2h-w327.json index 2d5a80a12c3..0c0eaf1d224 100644 --- a/advisories/unreviewed/2022/05/GHSA-gx95-jx2h-w327/GHSA-gx95-jx2h-w327.json +++ b/advisories/unreviewed/2022/05/GHSA-gx95-jx2h-w327/GHSA-gx95-jx2h-w327.json @@ -7,12 +7,8 @@ "CVE-2013-4730" ], "details": "Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-gxcr-f6wv-xrc7/GHSA-gxcr-f6wv-xrc7.json b/advisories/unreviewed/2022/05/GHSA-gxcr-f6wv-xrc7/GHSA-gxcr-f6wv-xrc7.json index 9ae84e8f6d2..5a48b6c6080 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxcr-f6wv-xrc7/GHSA-gxcr-f6wv-xrc7.json +++ b/advisories/unreviewed/2022/05/GHSA-gxcr-f6wv-xrc7/GHSA-gxcr-f6wv-xrc7.json @@ -7,12 +7,8 @@ "CVE-2015-4763" ], "details": "Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h28w-hpqp-8qrm/GHSA-h28w-hpqp-8qrm.json b/advisories/unreviewed/2022/05/GHSA-h28w-hpqp-8qrm/GHSA-h28w-hpqp-8qrm.json index abf05612353..87ddcbe3842 100644 --- a/advisories/unreviewed/2022/05/GHSA-h28w-hpqp-8qrm/GHSA-h28w-hpqp-8qrm.json +++ b/advisories/unreviewed/2022/05/GHSA-h28w-hpqp-8qrm/GHSA-h28w-hpqp-8qrm.json @@ -7,12 +7,8 @@ "CVE-2015-4234" ], "details": "Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h2cj-472m-p2pg/GHSA-h2cj-472m-p2pg.json b/advisories/unreviewed/2022/05/GHSA-h2cj-472m-p2pg/GHSA-h2cj-472m-p2pg.json index a1922de8c9c..c685b4cc756 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2cj-472m-p2pg/GHSA-h2cj-472m-p2pg.json +++ b/advisories/unreviewed/2022/05/GHSA-h2cj-472m-p2pg/GHSA-h2cj-472m-p2pg.json @@ -7,12 +7,8 @@ "CVE-2015-2341" ], "details": "VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.6, and VMware Fusion 6.x before 6.0.6 and 7.x before 7.0.1 allow attackers to cause a denial of service against a 32-bit guest OS or 64-bit host OS via a crafted RPC command.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h2jh-2gpr-chh9/GHSA-h2jh-2gpr-chh9.json b/advisories/unreviewed/2022/05/GHSA-h2jh-2gpr-chh9/GHSA-h2jh-2gpr-chh9.json index 6996fec6e68..ab26424726b 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2jh-2gpr-chh9/GHSA-h2jh-2gpr-chh9.json +++ b/advisories/unreviewed/2022/05/GHSA-h2jh-2gpr-chh9/GHSA-h2jh-2gpr-chh9.json @@ -7,12 +7,8 @@ "CVE-2015-7860" ], "details": "Stack-based buffer overflow in the agent in Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending a large amount of data in an environment that lacks relationship-based firewalling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h37v-7fp2-rqjj/GHSA-h37v-7fp2-rqjj.json b/advisories/unreviewed/2022/05/GHSA-h37v-7fp2-rqjj/GHSA-h37v-7fp2-rqjj.json index 6a454b1a730..1fda3d3925c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h37v-7fp2-rqjj/GHSA-h37v-7fp2-rqjj.json +++ b/advisories/unreviewed/2022/05/GHSA-h37v-7fp2-rqjj/GHSA-h37v-7fp2-rqjj.json @@ -7,12 +7,8 @@ "CVE-2013-7409" ], "details": "Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .m3u (playlist) file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h4mf-xgwj-q6f7/GHSA-h4mf-xgwj-q6f7.json b/advisories/unreviewed/2022/05/GHSA-h4mf-xgwj-q6f7/GHSA-h4mf-xgwj-q6f7.json index 2da2a254273..52043b89ce1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h4mf-xgwj-q6f7/GHSA-h4mf-xgwj-q6f7.json +++ b/advisories/unreviewed/2022/05/GHSA-h4mf-xgwj-q6f7/GHSA-h4mf-xgwj-q6f7.json @@ -7,12 +7,8 @@ "CVE-2014-3669" ], "details": "Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -124,9 +120,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5jj-v3w6-pmjq/GHSA-h5jj-v3w6-pmjq.json b/advisories/unreviewed/2022/05/GHSA-h5jj-v3w6-pmjq/GHSA-h5jj-v3w6-pmjq.json index ec0335b249f..7b693059f8a 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5jj-v3w6-pmjq/GHSA-h5jj-v3w6-pmjq.json +++ b/advisories/unreviewed/2022/05/GHSA-h5jj-v3w6-pmjq/GHSA-h5jj-v3w6-pmjq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h5pf-q287-qfw2/GHSA-h5pf-q287-qfw2.json b/advisories/unreviewed/2022/05/GHSA-h5pf-q287-qfw2/GHSA-h5pf-q287-qfw2.json index d110a69f5df..9dd0c3556f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5pf-q287-qfw2/GHSA-h5pf-q287-qfw2.json +++ b/advisories/unreviewed/2022/05/GHSA-h5pf-q287-qfw2/GHSA-h5pf-q287-qfw2.json @@ -7,12 +7,8 @@ "CVE-2014-7934" ], "details": "Use-after-free vulnerability in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unexpected absence of document data structures.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h5q8-x55p-gmfg/GHSA-h5q8-x55p-gmfg.json b/advisories/unreviewed/2022/05/GHSA-h5q8-x55p-gmfg/GHSA-h5q8-x55p-gmfg.json index 8d4dfc6aad0..cbf85b66105 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5q8-x55p-gmfg/GHSA-h5q8-x55p-gmfg.json +++ b/advisories/unreviewed/2022/05/GHSA-h5q8-x55p-gmfg/GHSA-h5q8-x55p-gmfg.json @@ -7,12 +7,8 @@ "CVE-2015-3980" ], "details": "SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h659-mqwh-q9g3/GHSA-h659-mqwh-q9g3.json b/advisories/unreviewed/2022/05/GHSA-h659-mqwh-q9g3/GHSA-h659-mqwh-q9g3.json index fad8afde5dc..8abe95f9fd7 100644 --- a/advisories/unreviewed/2022/05/GHSA-h659-mqwh-q9g3/GHSA-h659-mqwh-q9g3.json +++ b/advisories/unreviewed/2022/05/GHSA-h659-mqwh-q9g3/GHSA-h659-mqwh-q9g3.json @@ -7,12 +7,8 @@ "CVE-2015-3109" ], "details": "Adobe Photoshop CC before 16.0 (aka 2015.0.0) allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h6pq-4fqr-9hfg/GHSA-h6pq-4fqr-9hfg.json b/advisories/unreviewed/2022/05/GHSA-h6pq-4fqr-9hfg/GHSA-h6pq-4fqr-9hfg.json index 0a025026fa8..0d3431d80d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6pq-4fqr-9hfg/GHSA-h6pq-4fqr-9hfg.json +++ b/advisories/unreviewed/2022/05/GHSA-h6pq-4fqr-9hfg/GHSA-h6pq-4fqr-9hfg.json @@ -7,12 +7,8 @@ "CVE-2015-1109" ], "details": "NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h779-883h-mr35/GHSA-h779-883h-mr35.json b/advisories/unreviewed/2022/05/GHSA-h779-883h-mr35/GHSA-h779-883h-mr35.json index 095289b3410..60938e2b667 100644 --- a/advisories/unreviewed/2022/05/GHSA-h779-883h-mr35/GHSA-h779-883h-mr35.json +++ b/advisories/unreviewed/2022/05/GHSA-h779-883h-mr35/GHSA-h779-883h-mr35.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h77x-2hj5-ggjw/GHSA-h77x-2hj5-ggjw.json b/advisories/unreviewed/2022/05/GHSA-h77x-2hj5-ggjw/GHSA-h77x-2hj5-ggjw.json index 63dad2469e7..37145c452e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-h77x-2hj5-ggjw/GHSA-h77x-2hj5-ggjw.json +++ b/advisories/unreviewed/2022/05/GHSA-h77x-2hj5-ggjw/GHSA-h77x-2hj5-ggjw.json @@ -7,12 +7,8 @@ "CVE-2015-0807" ], "details": "The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7q3-3hf3-hv3q/GHSA-h7q3-3hf3-hv3q.json b/advisories/unreviewed/2022/05/GHSA-h7q3-3hf3-hv3q/GHSA-h7q3-3hf3-hv3q.json index 61f7eb0194b..1bd52ba4961 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7q3-3hf3-hv3q/GHSA-h7q3-3hf3-hv3q.json +++ b/advisories/unreviewed/2022/05/GHSA-h7q3-3hf3-hv3q/GHSA-h7q3-3hf3-hv3q.json @@ -7,12 +7,8 @@ "CVE-2015-8382" ], "details": "The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (partially initialized memory and application crash) via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, aka ZDI-CAN-2547.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7qw-5c46-g9j3/GHSA-h7qw-5c46-g9j3.json b/advisories/unreviewed/2022/05/GHSA-h7qw-5c46-g9j3/GHSA-h7qw-5c46-g9j3.json index a0405119ead..c6a9ea39634 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7qw-5c46-g9j3/GHSA-h7qw-5c46-g9j3.json +++ b/advisories/unreviewed/2022/05/GHSA-h7qw-5c46-g9j3/GHSA-h7qw-5c46-g9j3.json @@ -7,12 +7,8 @@ "CVE-2015-6290" ], "details": "Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-h7qx-h373-6ccg/GHSA-h7qx-h373-6ccg.json b/advisories/unreviewed/2022/05/GHSA-h7qx-h373-6ccg/GHSA-h7qx-h373-6ccg.json index b24eb22368a..aa86188f101 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7qx-h373-6ccg/GHSA-h7qx-h373-6ccg.json +++ b/advisories/unreviewed/2022/05/GHSA-h7qx-h373-6ccg/GHSA-h7qx-h373-6ccg.json @@ -7,12 +7,8 @@ "CVE-2015-3378" ], "details": "Open redirect vulnerability in the Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal, when the Views UI submodule is enabled, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to the break lock page for edited views.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h847-jmmj-x7rc/GHSA-h847-jmmj-x7rc.json b/advisories/unreviewed/2022/05/GHSA-h847-jmmj-x7rc/GHSA-h847-jmmj-x7rc.json index c1a8f869fbd..b48cccb7e1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-h847-jmmj-x7rc/GHSA-h847-jmmj-x7rc.json +++ b/advisories/unreviewed/2022/05/GHSA-h847-jmmj-x7rc/GHSA-h847-jmmj-x7rc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hc4c-r8xq-xm9f/GHSA-hc4c-r8xq-xm9f.json b/advisories/unreviewed/2022/05/GHSA-hc4c-r8xq-xm9f/GHSA-hc4c-r8xq-xm9f.json index a0425fcbcd6..00e26a5fb0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hc4c-r8xq-xm9f/GHSA-hc4c-r8xq-xm9f.json +++ b/advisories/unreviewed/2022/05/GHSA-hc4c-r8xq-xm9f/GHSA-hc4c-r8xq-xm9f.json @@ -7,12 +7,8 @@ "CVE-2015-3100" ], "details": "Stack-based buffer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hcq6-qrq8-g2hg/GHSA-hcq6-qrq8-g2hg.json b/advisories/unreviewed/2022/05/GHSA-hcq6-qrq8-g2hg/GHSA-hcq6-qrq8-g2hg.json index 3abc55d77fd..f3200215152 100644 --- a/advisories/unreviewed/2022/05/GHSA-hcq6-qrq8-g2hg/GHSA-hcq6-qrq8-g2hg.json +++ b/advisories/unreviewed/2022/05/GHSA-hcq6-qrq8-g2hg/GHSA-hcq6-qrq8-g2hg.json @@ -7,12 +7,8 @@ "CVE-2015-2668" ], "details": "ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hfpr-gm4w-ghgf/GHSA-hfpr-gm4w-ghgf.json b/advisories/unreviewed/2022/05/GHSA-hfpr-gm4w-ghgf/GHSA-hfpr-gm4w-ghgf.json index 54edb44ca6f..304e33d3ee6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfpr-gm4w-ghgf/GHSA-hfpr-gm4w-ghgf.json +++ b/advisories/unreviewed/2022/05/GHSA-hfpr-gm4w-ghgf/GHSA-hfpr-gm4w-ghgf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg2x-9c6v-36xp/GHSA-hg2x-9c6v-36xp.json b/advisories/unreviewed/2022/05/GHSA-hg2x-9c6v-36xp/GHSA-hg2x-9c6v-36xp.json index 76628de15d7..7a13418f747 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg2x-9c6v-36xp/GHSA-hg2x-9c6v-36xp.json +++ b/advisories/unreviewed/2022/05/GHSA-hg2x-9c6v-36xp/GHSA-hg2x-9c6v-36xp.json @@ -7,12 +7,8 @@ "CVE-2015-0471" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to libelfsign.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hg76-79w5-rcwg/GHSA-hg76-79w5-rcwg.json b/advisories/unreviewed/2022/05/GHSA-hg76-79w5-rcwg/GHSA-hg76-79w5-rcwg.json index 2df2c9bfb26..83ed1fdc6d6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg76-79w5-rcwg/GHSA-hg76-79w5-rcwg.json +++ b/advisories/unreviewed/2022/05/GHSA-hg76-79w5-rcwg/GHSA-hg76-79w5-rcwg.json @@ -7,12 +7,8 @@ "CVE-2015-4244" ], "details": "The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hg92-xfw5-qgvm/GHSA-hg92-xfw5-qgvm.json b/advisories/unreviewed/2022/05/GHSA-hg92-xfw5-qgvm/GHSA-hg92-xfw5-qgvm.json index da20ad4a536..3c909f8730d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg92-xfw5-qgvm/GHSA-hg92-xfw5-qgvm.json +++ b/advisories/unreviewed/2022/05/GHSA-hg92-xfw5-qgvm/GHSA-hg92-xfw5-qgvm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hh57-f8fv-p2qw/GHSA-hh57-f8fv-p2qw.json b/advisories/unreviewed/2022/05/GHSA-hh57-f8fv-p2qw/GHSA-hh57-f8fv-p2qw.json index 1bacb7247d7..7ebfd215808 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh57-f8fv-p2qw/GHSA-hh57-f8fv-p2qw.json +++ b/advisories/unreviewed/2022/05/GHSA-hh57-f8fv-p2qw/GHSA-hh57-f8fv-p2qw.json @@ -7,12 +7,8 @@ "CVE-2015-3713" ], "details": "QuickTime in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted movie file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hh5c-mmwf-hc79/GHSA-hh5c-mmwf-hc79.json b/advisories/unreviewed/2022/05/GHSA-hh5c-mmwf-hc79/GHSA-hh5c-mmwf-hc79.json index cd36c7494ed..560ca78be35 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh5c-mmwf-hc79/GHSA-hh5c-mmwf-hc79.json +++ b/advisories/unreviewed/2022/05/GHSA-hh5c-mmwf-hc79/GHSA-hh5c-mmwf-hc79.json @@ -7,12 +7,8 @@ "CVE-2015-1250" ], "details": "Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hh5q-529x-q322/GHSA-hh5q-529x-q322.json b/advisories/unreviewed/2022/05/GHSA-hh5q-529x-q322/GHSA-hh5q-529x-q322.json index d05f9dd5fa3..d7487dfa553 100644 --- a/advisories/unreviewed/2022/05/GHSA-hh5q-529x-q322/GHSA-hh5q-529x-q322.json +++ b/advisories/unreviewed/2022/05/GHSA-hh5q-529x-q322/GHSA-hh5q-529x-q322.json @@ -7,12 +7,8 @@ "CVE-2006-0456" ], "details": "The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hhp4-hvm2-m2w3/GHSA-hhp4-hvm2-m2w3.json b/advisories/unreviewed/2022/05/GHSA-hhp4-hvm2-m2w3/GHSA-hhp4-hvm2-m2w3.json index eb89362c729..ecf1ad8e0c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-hhp4-hvm2-m2w3/GHSA-hhp4-hvm2-m2w3.json +++ b/advisories/unreviewed/2022/05/GHSA-hhp4-hvm2-m2w3/GHSA-hhp4-hvm2-m2w3.json @@ -7,12 +7,8 @@ "CVE-2015-4418" ], "details": "Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hjqr-g8j9-j3vw/GHSA-hjqr-g8j9-j3vw.json b/advisories/unreviewed/2022/05/GHSA-hjqr-g8j9-j3vw/GHSA-hjqr-g8j9-j3vw.json index dfb018d8a9b..996a149e205 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjqr-g8j9-j3vw/GHSA-hjqr-g8j9-j3vw.json +++ b/advisories/unreviewed/2022/05/GHSA-hjqr-g8j9-j3vw/GHSA-hjqr-g8j9-j3vw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hm36-8847-6hhf/GHSA-hm36-8847-6hhf.json b/advisories/unreviewed/2022/05/GHSA-hm36-8847-6hhf/GHSA-hm36-8847-6hhf.json index 859141b3b24..e007a143eb1 100644 --- a/advisories/unreviewed/2022/05/GHSA-hm36-8847-6hhf/GHSA-hm36-8847-6hhf.json +++ b/advisories/unreviewed/2022/05/GHSA-hm36-8847-6hhf/GHSA-hm36-8847-6hhf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hmf5-7f3h-jqqr/GHSA-hmf5-7f3h-jqqr.json b/advisories/unreviewed/2022/05/GHSA-hmf5-7f3h-jqqr/GHSA-hmf5-7f3h-jqqr.json index 101814c764e..2b625e2bbe6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmf5-7f3h-jqqr/GHSA-hmf5-7f3h-jqqr.json +++ b/advisories/unreviewed/2022/05/GHSA-hmf5-7f3h-jqqr/GHSA-hmf5-7f3h-jqqr.json @@ -7,12 +7,8 @@ "CVE-2015-2657" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, and 6.3.0 through 6.3.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Business Process Automation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hp57-8q89-468c/GHSA-hp57-8q89-468c.json b/advisories/unreviewed/2022/05/GHSA-hp57-8q89-468c/GHSA-hp57-8q89-468c.json index 5f3f1e88b4e..80e1041eb6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-hp57-8q89-468c/GHSA-hp57-8q89-468c.json +++ b/advisories/unreviewed/2022/05/GHSA-hp57-8q89-468c/GHSA-hp57-8q89-468c.json @@ -7,12 +7,8 @@ "CVE-2015-4242" ], "details": "Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 5.4.1.2 and 6.0.0 in FireSIGHT Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu94721.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hprr-8f78-r2q7/GHSA-hprr-8f78-r2q7.json b/advisories/unreviewed/2022/05/GHSA-hprr-8f78-r2q7/GHSA-hprr-8f78-r2q7.json index d9b8eb4b3c8..a5d0ff5648f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hprr-8f78-r2q7/GHSA-hprr-8f78-r2q7.json +++ b/advisories/unreviewed/2022/05/GHSA-hprr-8f78-r2q7/GHSA-hprr-8f78-r2q7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -171,9 +169,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hqvx-xg7f-6mmm/GHSA-hqvx-xg7f-6mmm.json b/advisories/unreviewed/2022/05/GHSA-hqvx-xg7f-6mmm/GHSA-hqvx-xg7f-6mmm.json index 5c7e9517a2e..df00854eec6 100644 --- a/advisories/unreviewed/2022/05/GHSA-hqvx-xg7f-6mmm/GHSA-hqvx-xg7f-6mmm.json +++ b/advisories/unreviewed/2022/05/GHSA-hqvx-xg7f-6mmm/GHSA-hqvx-xg7f-6mmm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hr5g-ggm4-mgqr/GHSA-hr5g-ggm4-mgqr.json b/advisories/unreviewed/2022/05/GHSA-hr5g-ggm4-mgqr/GHSA-hr5g-ggm4-mgqr.json index 104a7d6c20e..71cf4c9cd4a 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr5g-ggm4-mgqr/GHSA-hr5g-ggm4-mgqr.json +++ b/advisories/unreviewed/2022/05/GHSA-hr5g-ggm4-mgqr/GHSA-hr5g-ggm4-mgqr.json @@ -7,12 +7,8 @@ "CVE-2013-7353" ], "details": "Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a crafted image, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hr69-qwr2-87px/GHSA-hr69-qwr2-87px.json b/advisories/unreviewed/2022/05/GHSA-hr69-qwr2-87px/GHSA-hr69-qwr2-87px.json index ad9071b8f19..0ab35823c5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hr69-qwr2-87px/GHSA-hr69-qwr2-87px.json +++ b/advisories/unreviewed/2022/05/GHSA-hr69-qwr2-87px/GHSA-hr69-qwr2-87px.json @@ -7,12 +7,8 @@ "CVE-2015-0451" ], "details": "Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 3.0-04 allows remote authenticated users to affect confidentiality via vectors related to OpenSSO Web Agents.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hrhc-gjjr-rfhr/GHSA-hrhc-gjjr-rfhr.json b/advisories/unreviewed/2022/05/GHSA-hrhc-gjjr-rfhr/GHSA-hrhc-gjjr-rfhr.json index 62cc601eb7e..488108b66fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrhc-gjjr-rfhr/GHSA-hrhc-gjjr-rfhr.json +++ b/advisories/unreviewed/2022/05/GHSA-hrhc-gjjr-rfhr/GHSA-hrhc-gjjr-rfhr.json @@ -7,12 +7,8 @@ "CVE-2015-4744" ], "details": "Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect integrity via unknown vectors related to Java Server Faces.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hvrm-q5xx-h2xh/GHSA-hvrm-q5xx-h2xh.json b/advisories/unreviewed/2022/05/GHSA-hvrm-q5xx-h2xh/GHSA-hvrm-q5xx-h2xh.json index 4a7aa3808ce..d76f9671abd 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvrm-q5xx-h2xh/GHSA-hvrm-q5xx-h2xh.json +++ b/advisories/unreviewed/2022/05/GHSA-hvrm-q5xx-h2xh/GHSA-hvrm-q5xx-h2xh.json @@ -7,12 +7,8 @@ "CVE-2014-9569" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver Business Client (NWBC) for HTML 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) roundtrips parameter, aka SAP Security Note 2051285.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwjw-h532-j9qq/GHSA-hwjw-h532-j9qq.json b/advisories/unreviewed/2022/05/GHSA-hwjw-h532-j9qq/GHSA-hwjw-h532-j9qq.json index 3b1337a2d51..cb33474f543 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwjw-h532-j9qq/GHSA-hwjw-h532-j9qq.json +++ b/advisories/unreviewed/2022/05/GHSA-hwjw-h532-j9qq/GHSA-hwjw-h532-j9qq.json @@ -7,12 +7,8 @@ "CVE-2014-8630" ], "details": "Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hwm7-7gx2-6gr2/GHSA-hwm7-7gx2-6gr2.json b/advisories/unreviewed/2022/05/GHSA-hwm7-7gx2-6gr2/GHSA-hwm7-7gx2-6gr2.json index 4c4ad8899ce..4bbf9722b5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwm7-7gx2-6gr2/GHSA-hwm7-7gx2-6gr2.json +++ b/advisories/unreviewed/2022/05/GHSA-hwm7-7gx2-6gr2/GHSA-hwm7-7gx2-6gr2.json @@ -7,12 +7,8 @@ "CVE-2015-1115" ], "details": "The Telephony component in Apple iOS before 8.3 allows attackers to bypass a sandbox protection mechanism and access unintended telephone capabilities via a crafted app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-hx6q-2wx5-337x/GHSA-hx6q-2wx5-337x.json b/advisories/unreviewed/2022/05/GHSA-hx6q-2wx5-337x/GHSA-hx6q-2wx5-337x.json index 54aeb85547f..3ebbd76a642 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx6q-2wx5-337x/GHSA-hx6q-2wx5-337x.json +++ b/advisories/unreviewed/2022/05/GHSA-hx6q-2wx5-337x/GHSA-hx6q-2wx5-337x.json @@ -7,12 +7,8 @@ "CVE-2015-2961" ], "details": "Cross-site request forgery (CSRF) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to hijack the authentication of administrators.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j2v3-wwrj-4h89/GHSA-j2v3-wwrj-4h89.json b/advisories/unreviewed/2022/05/GHSA-j2v3-wwrj-4h89/GHSA-j2v3-wwrj-4h89.json index 7bb7e891758..7c76095121b 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2v3-wwrj-4h89/GHSA-j2v3-wwrj-4h89.json +++ b/advisories/unreviewed/2022/05/GHSA-j2v3-wwrj-4h89/GHSA-j2v3-wwrj-4h89.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -43,9 +41,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5gh-c7wf-rgw9/GHSA-j5gh-c7wf-rgw9.json b/advisories/unreviewed/2022/05/GHSA-j5gh-c7wf-rgw9/GHSA-j5gh-c7wf-rgw9.json index d43a53f48c2..ad6451fbda3 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5gh-c7wf-rgw9/GHSA-j5gh-c7wf-rgw9.json +++ b/advisories/unreviewed/2022/05/GHSA-j5gh-c7wf-rgw9/GHSA-j5gh-c7wf-rgw9.json @@ -7,12 +7,8 @@ "CVE-2015-0494" ], "details": "Unspecified vulnerability in the Oracle Retail Central Office component in Oracle Retail Applications 13.1, 13.2, 13.3, 13.4, 14.0, and 14.1 allows remote attackers to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j5hc-3w8h-5fpp/GHSA-j5hc-3w8h-5fpp.json b/advisories/unreviewed/2022/05/GHSA-j5hc-3w8h-5fpp/GHSA-j5hc-3w8h-5fpp.json index 4d089edc764..ef0c8dfa883 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5hc-3w8h-5fpp/GHSA-j5hc-3w8h-5fpp.json +++ b/advisories/unreviewed/2022/05/GHSA-j5hc-3w8h-5fpp/GHSA-j5hc-3w8h-5fpp.json @@ -7,12 +7,8 @@ "CVE-2005-3359" ], "details": "The atm module in Linux kernel 2.6 before 2.6.14 allows local users to cause a denial of service (panic) via certain socket calls that produce inconsistent reference counts for loadable protocol modules.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-j654-9mpv-92vg/GHSA-j654-9mpv-92vg.json b/advisories/unreviewed/2022/05/GHSA-j654-9mpv-92vg/GHSA-j654-9mpv-92vg.json index 98223fecfb1..3047106751a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j654-9mpv-92vg/GHSA-j654-9mpv-92vg.json +++ b/advisories/unreviewed/2022/05/GHSA-j654-9mpv-92vg/GHSA-j654-9mpv-92vg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j678-p965-44g9/GHSA-j678-p965-44g9.json b/advisories/unreviewed/2022/05/GHSA-j678-p965-44g9/GHSA-j678-p965-44g9.json index cf77deab7db..503f2252f38 100644 --- a/advisories/unreviewed/2022/05/GHSA-j678-p965-44g9/GHSA-j678-p965-44g9.json +++ b/advisories/unreviewed/2022/05/GHSA-j678-p965-44g9/GHSA-j678-p965-44g9.json @@ -7,12 +7,8 @@ "CVE-2015-1923" ], "details": "Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j6wm-fvj7-4v8m/GHSA-j6wm-fvj7-4v8m.json b/advisories/unreviewed/2022/05/GHSA-j6wm-fvj7-4v8m/GHSA-j6wm-fvj7-4v8m.json index 02e36b3413b..bea98dbb461 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6wm-fvj7-4v8m/GHSA-j6wm-fvj7-4v8m.json +++ b/advisories/unreviewed/2022/05/GHSA-j6wm-fvj7-4v8m/GHSA-j6wm-fvj7-4v8m.json @@ -7,12 +7,8 @@ "CVE-2015-4308" ], "details": "The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuu43968.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j89r-hqh8-62x2/GHSA-j89r-hqh8-62x2.json b/advisories/unreviewed/2022/05/GHSA-j89r-hqh8-62x2/GHSA-j89r-hqh8-62x2.json index 58a101dc00d..a88a166f369 100644 --- a/advisories/unreviewed/2022/05/GHSA-j89r-hqh8-62x2/GHSA-j89r-hqh8-62x2.json +++ b/advisories/unreviewed/2022/05/GHSA-j89r-hqh8-62x2/GHSA-j89r-hqh8-62x2.json @@ -7,12 +7,8 @@ "CVE-2015-1920" ], "details": "IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j8g5-3786-r7g7/GHSA-j8g5-3786-r7g7.json b/advisories/unreviewed/2022/05/GHSA-j8g5-3786-r7g7/GHSA-j8g5-3786-r7g7.json index 81e895588fb..7c5e42f1c08 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8g5-3786-r7g7/GHSA-j8g5-3786-r7g7.json +++ b/advisories/unreviewed/2022/05/GHSA-j8g5-3786-r7g7/GHSA-j8g5-3786-r7g7.json @@ -7,12 +7,8 @@ "CVE-2013-4995" ], "details": "Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row information.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9pq-x44j-6p86/GHSA-j9pq-x44j-6p86.json b/advisories/unreviewed/2022/05/GHSA-j9pq-x44j-6p86/GHSA-j9pq-x44j-6p86.json index 1d0e7c4dfb1..618fd230793 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9pq-x44j-6p86/GHSA-j9pq-x44j-6p86.json +++ b/advisories/unreviewed/2022/05/GHSA-j9pq-x44j-6p86/GHSA-j9pq-x44j-6p86.json @@ -7,12 +7,8 @@ "CVE-2015-6658" ], "details": "Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9qf-q9qf-j8gv/GHSA-j9qf-q9qf-j8gv.json b/advisories/unreviewed/2022/05/GHSA-j9qf-q9qf-j8gv/GHSA-j9qf-q9qf-j8gv.json index 912af443170..caab9d66d07 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9qf-q9qf-j8gv/GHSA-j9qf-q9qf-j8gv.json +++ b/advisories/unreviewed/2022/05/GHSA-j9qf-q9qf-j8gv/GHSA-j9qf-q9qf-j8gv.json @@ -7,12 +7,8 @@ "CVE-2015-5746" ], "details": "AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9r6-j2mr-f6mm/GHSA-j9r6-j2mr-f6mm.json b/advisories/unreviewed/2022/05/GHSA-j9r6-j2mr-f6mm/GHSA-j9r6-j2mr-f6mm.json index 0b2515d02df..f3dd85acff2 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9r6-j2mr-f6mm/GHSA-j9r6-j2mr-f6mm.json +++ b/advisories/unreviewed/2022/05/GHSA-j9r6-j2mr-f6mm/GHSA-j9r6-j2mr-f6mm.json @@ -7,12 +7,8 @@ "CVE-2014-9089" ], "details": "Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_set.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-j9wg-qqgj-ph9r/GHSA-j9wg-qqgj-ph9r.json b/advisories/unreviewed/2022/05/GHSA-j9wg-qqgj-ph9r/GHSA-j9wg-qqgj-ph9r.json index 770b5111c85..ee28da3b15a 100644 --- a/advisories/unreviewed/2022/05/GHSA-j9wg-qqgj-ph9r/GHSA-j9wg-qqgj-ph9r.json +++ b/advisories/unreviewed/2022/05/GHSA-j9wg-qqgj-ph9r/GHSA-j9wg-qqgj-ph9r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -143,9 +141,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jcf7-3f5g-p5qv/GHSA-jcf7-3f5g-p5qv.json b/advisories/unreviewed/2022/05/GHSA-jcf7-3f5g-p5qv/GHSA-jcf7-3f5g-p5qv.json index 79e20429d06..f1187d92694 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcf7-3f5g-p5qv/GHSA-jcf7-3f5g-p5qv.json +++ b/advisories/unreviewed/2022/05/GHSA-jcf7-3f5g-p5qv/GHSA-jcf7-3f5g-p5qv.json @@ -7,12 +7,8 @@ "CVE-2015-6284" ], "details": "Buffer overflow in the Conference Control Protocol API implementation in Cisco TelePresence Server software before 4.1(2.33) on 7010, MSE 8710, Multiparty Media 310 and 320, and Virtual Machine devices allows remote attackers to cause a denial of service (device crash) via a crafted URL, aka Bug ID CSCuu28277.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf5m-m48c-5w2g/GHSA-jf5m-m48c-5w2g.json b/advisories/unreviewed/2022/05/GHSA-jf5m-m48c-5w2g/GHSA-jf5m-m48c-5w2g.json index 0105a3b685c..2db1d73f121 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf5m-m48c-5w2g/GHSA-jf5m-m48c-5w2g.json +++ b/advisories/unreviewed/2022/05/GHSA-jf5m-m48c-5w2g/GHSA-jf5m-m48c-5w2g.json @@ -7,12 +7,8 @@ "CVE-2015-5776" ], "details": "Libinfo in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by leveraging use of an AF_INET6 socket.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jf6q-q38p-f3q8/GHSA-jf6q-q38p-f3q8.json b/advisories/unreviewed/2022/05/GHSA-jf6q-q38p-f3q8/GHSA-jf6q-q38p-f3q8.json index 71349d71964..73e1b278af2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jf6q-q38p-f3q8/GHSA-jf6q-q38p-f3q8.json +++ b/advisories/unreviewed/2022/05/GHSA-jf6q-q38p-f3q8/GHSA-jf6q-q38p-f3q8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jgqm-rhq8-wrjr/GHSA-jgqm-rhq8-wrjr.json b/advisories/unreviewed/2022/05/GHSA-jgqm-rhq8-wrjr/GHSA-jgqm-rhq8-wrjr.json index b77b28822dd..78cbd392e02 100644 --- a/advisories/unreviewed/2022/05/GHSA-jgqm-rhq8-wrjr/GHSA-jgqm-rhq8-wrjr.json +++ b/advisories/unreviewed/2022/05/GHSA-jgqm-rhq8-wrjr/GHSA-jgqm-rhq8-wrjr.json @@ -7,12 +7,8 @@ "CVE-2012-2359" ], "details": "admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jjqw-3jh9-43m5/GHSA-jjqw-3jh9-43m5.json b/advisories/unreviewed/2022/05/GHSA-jjqw-3jh9-43m5/GHSA-jjqw-3jh9-43m5.json index 57b97e003ec..ff185a9a2fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjqw-3jh9-43m5/GHSA-jjqw-3jh9-43m5.json +++ b/advisories/unreviewed/2022/05/GHSA-jjqw-3jh9-43m5/GHSA-jjqw-3jh9-43m5.json @@ -7,12 +7,8 @@ "CVE-2015-3079" ], "details": "Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jp2q-xrh4-4hph/GHSA-jp2q-xrh4-4hph.json b/advisories/unreviewed/2022/05/GHSA-jp2q-xrh4-4hph/GHSA-jp2q-xrh4-4hph.json index 4fab65b15aa..d841ed8ce43 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp2q-xrh4-4hph/GHSA-jp2q-xrh4-4hph.json +++ b/advisories/unreviewed/2022/05/GHSA-jp2q-xrh4-4hph/GHSA-jp2q-xrh4-4hph.json @@ -7,12 +7,8 @@ "CVE-2015-6659" ], "details": "SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jp68-rg97-wr3j/GHSA-jp68-rg97-wr3j.json b/advisories/unreviewed/2022/05/GHSA-jp68-rg97-wr3j/GHSA-jp68-rg97-wr3j.json index 39ea96af387..33f029cce4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jp68-rg97-wr3j/GHSA-jp68-rg97-wr3j.json +++ b/advisories/unreviewed/2022/05/GHSA-jp68-rg97-wr3j/GHSA-jp68-rg97-wr3j.json @@ -7,12 +7,8 @@ "CVE-2015-3922" ], "details": "Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jpfm-328g-jccg/GHSA-jpfm-328g-jccg.json b/advisories/unreviewed/2022/05/GHSA-jpfm-328g-jccg/GHSA-jpfm-328g-jccg.json index 1ab29cef35b..bc896bbf7dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-jpfm-328g-jccg/GHSA-jpfm-328g-jccg.json +++ b/advisories/unreviewed/2022/05/GHSA-jpfm-328g-jccg/GHSA-jpfm-328g-jccg.json @@ -7,12 +7,8 @@ "CVE-2015-2565" ], "details": "Unspecified vulnerability in the Oracle Installed Base component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Create Item Instance.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jqmf-8rw2-2qx7/GHSA-jqmf-8rw2-2qx7.json b/advisories/unreviewed/2022/05/GHSA-jqmf-8rw2-2qx7/GHSA-jqmf-8rw2-2qx7.json index ad8d3276aa7..9657329c81e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqmf-8rw2-2qx7/GHSA-jqmf-8rw2-2qx7.json +++ b/advisories/unreviewed/2022/05/GHSA-jqmf-8rw2-2qx7/GHSA-jqmf-8rw2-2qx7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jqxg-2f63-33rf/GHSA-jqxg-2f63-33rf.json b/advisories/unreviewed/2022/05/GHSA-jqxg-2f63-33rf/GHSA-jqxg-2f63-33rf.json index 2ceef39c671..9ff82d86af5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqxg-2f63-33rf/GHSA-jqxg-2f63-33rf.json +++ b/advisories/unreviewed/2022/05/GHSA-jqxg-2f63-33rf/GHSA-jqxg-2f63-33rf.json @@ -7,12 +7,8 @@ "CVE-2014-8014" ], "details": "Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCub63710.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrcw-x2cf-77fv/GHSA-jrcw-x2cf-77fv.json b/advisories/unreviewed/2022/05/GHSA-jrcw-x2cf-77fv/GHSA-jrcw-x2cf-77fv.json index e84383a518e..8981b5d6a84 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrcw-x2cf-77fv/GHSA-jrcw-x2cf-77fv.json +++ b/advisories/unreviewed/2022/05/GHSA-jrcw-x2cf-77fv/GHSA-jrcw-x2cf-77fv.json @@ -7,12 +7,8 @@ "CVE-2015-3726" ], "details": "The Telephony subsystem in Apple iOS before 8.4 allows physically proximate attackers to execute arbitrary code via a crafted (1) SIM or (2) UIM card.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jrr7-3c28-9wx3/GHSA-jrr7-3c28-9wx3.json b/advisories/unreviewed/2022/05/GHSA-jrr7-3c28-9wx3/GHSA-jrr7-3c28-9wx3.json index 4968312f15f..59e952984ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrr7-3c28-9wx3/GHSA-jrr7-3c28-9wx3.json +++ b/advisories/unreviewed/2022/05/GHSA-jrr7-3c28-9wx3/GHSA-jrr7-3c28-9wx3.json @@ -7,12 +7,8 @@ "CVE-2013-7441" ], "details": "The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-jrrc-8w3m-x99x/GHSA-jrrc-8w3m-x99x.json b/advisories/unreviewed/2022/05/GHSA-jrrc-8w3m-x99x/GHSA-jrrc-8w3m-x99x.json index 85fb95d1563..bb2b2062108 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrrc-8w3m-x99x/GHSA-jrrc-8w3m-x99x.json +++ b/advisories/unreviewed/2022/05/GHSA-jrrc-8w3m-x99x/GHSA-jrrc-8w3m-x99x.json @@ -7,12 +7,8 @@ "CVE-2014-7285" ], "details": "The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jv95-xwvp-r9rg/GHSA-jv95-xwvp-r9rg.json b/advisories/unreviewed/2022/05/GHSA-jv95-xwvp-r9rg/GHSA-jv95-xwvp-r9rg.json index 61121d558f9..3978ce4cfeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv95-xwvp-r9rg/GHSA-jv95-xwvp-r9rg.json +++ b/advisories/unreviewed/2022/05/GHSA-jv95-xwvp-r9rg/GHSA-jv95-xwvp-r9rg.json @@ -7,12 +7,8 @@ "CVE-2015-0551" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5 SP7 before P25; and Documentum Task Space 6.7SP1 before P31 and 6.7SP2 before P23 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jv9r-h7r8-3459/GHSA-jv9r-h7r8-3459.json b/advisories/unreviewed/2022/05/GHSA-jv9r-h7r8-3459/GHSA-jv9r-h7r8-3459.json index bdabe1d9849..70dcf09449a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jv9r-h7r8-3459/GHSA-jv9r-h7r8-3459.json +++ b/advisories/unreviewed/2022/05/GHSA-jv9r-h7r8-3459/GHSA-jv9r-h7r8-3459.json @@ -7,12 +7,8 @@ "CVE-2014-9427" ], "details": "sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid file that begins with a # character and lacks a newline character, which causes an out-of-bounds read and might (1) allow remote attackers to obtain sensitive information from php-cgi process memory by leveraging the ability to upload a .php file or (2) trigger unexpected code execution if a valid PHP script is present in memory locations adjacent to the mapping.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jw9m-973w-g927/GHSA-jw9m-973w-g927.json b/advisories/unreviewed/2022/05/GHSA-jw9m-973w-g927/GHSA-jw9m-973w-g927.json index 378faeee176..704e5aca9c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-jw9m-973w-g927/GHSA-jw9m-973w-g927.json +++ b/advisories/unreviewed/2022/05/GHSA-jw9m-973w-g927/GHSA-jw9m-973w-g927.json @@ -7,12 +7,8 @@ "CVE-2015-5942" ], "details": "FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5927.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwq9-7674-wmgg/GHSA-jwq9-7674-wmgg.json b/advisories/unreviewed/2022/05/GHSA-jwq9-7674-wmgg/GHSA-jwq9-7674-wmgg.json index 75ee46ad075..4981f689fab 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwq9-7674-wmgg/GHSA-jwq9-7674-wmgg.json +++ b/advisories/unreviewed/2022/05/GHSA-jwq9-7674-wmgg/GHSA-jwq9-7674-wmgg.json @@ -7,12 +7,8 @@ "CVE-2015-1116" ], "details": "The UIKit View component in Apple iOS before 8.3 displays unblurred application snapshots in the Task Switcher, which makes it easier for physically proximate attackers to obtain sensitive information by reading the device screen.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-jwxc-p8cx-qc8x/GHSA-jwxc-p8cx-qc8x.json b/advisories/unreviewed/2022/05/GHSA-jwxc-p8cx-qc8x/GHSA-jwxc-p8cx-qc8x.json index 353d4713c82..0d8c267eb38 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwxc-p8cx-qc8x/GHSA-jwxc-p8cx-qc8x.json +++ b/advisories/unreviewed/2022/05/GHSA-jwxc-p8cx-qc8x/GHSA-jwxc-p8cx-qc8x.json @@ -7,12 +7,8 @@ "CVE-2015-4207" ], "details": "Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive information and bypass intended attendance restrictions by visiting a meeting-registration page, aka Bug ID CSCus62147.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m2cm-xr3w-89p5/GHSA-m2cm-xr3w-89p5.json b/advisories/unreviewed/2022/05/GHSA-m2cm-xr3w-89p5/GHSA-m2cm-xr3w-89p5.json index fe6602395ac..55de37b0724 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2cm-xr3w-89p5/GHSA-m2cm-xr3w-89p5.json +++ b/advisories/unreviewed/2022/05/GHSA-m2cm-xr3w-89p5/GHSA-m2cm-xr3w-89p5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -39,9 +37,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m2xq-3pf4-x65f/GHSA-m2xq-3pf4-x65f.json b/advisories/unreviewed/2022/05/GHSA-m2xq-3pf4-x65f/GHSA-m2xq-3pf4-x65f.json index f76d6cafb9b..965a41bb87f 100644 --- a/advisories/unreviewed/2022/05/GHSA-m2xq-3pf4-x65f/GHSA-m2xq-3pf4-x65f.json +++ b/advisories/unreviewed/2022/05/GHSA-m2xq-3pf4-x65f/GHSA-m2xq-3pf4-x65f.json @@ -7,12 +7,8 @@ "CVE-2015-1965" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, and CVE-2015-1964.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m3wx-v4j7-r6fr/GHSA-m3wx-v4j7-r6fr.json b/advisories/unreviewed/2022/05/GHSA-m3wx-v4j7-r6fr/GHSA-m3wx-v4j7-r6fr.json index 1c15d83741d..172bbe00e10 100644 --- a/advisories/unreviewed/2022/05/GHSA-m3wx-v4j7-r6fr/GHSA-m3wx-v4j7-r6fr.json +++ b/advisories/unreviewed/2022/05/GHSA-m3wx-v4j7-r6fr/GHSA-m3wx-v4j7-r6fr.json @@ -7,12 +7,8 @@ "CVE-2015-2077" ], "details": "The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other products, uses the same X.509 certificate private key for a root CA certificate across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging knowledge of this key, as originally reported for Superfish VisualDiscovery on certain Lenovo Notebook laptop products.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m44q-pcg2-44fv/GHSA-m44q-pcg2-44fv.json b/advisories/unreviewed/2022/05/GHSA-m44q-pcg2-44fv/GHSA-m44q-pcg2-44fv.json index 9b86cc3dfa2..76480e1faac 100644 --- a/advisories/unreviewed/2022/05/GHSA-m44q-pcg2-44fv/GHSA-m44q-pcg2-44fv.json +++ b/advisories/unreviewed/2022/05/GHSA-m44q-pcg2-44fv/GHSA-m44q-pcg2-44fv.json @@ -7,12 +7,8 @@ "CVE-2015-7862" ], "details": "Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 improperly implements the Role Based Access Control feature, which might allow remote attackers to modify an account's role assignments via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m52w-9gvm-79q5/GHSA-m52w-9gvm-79q5.json b/advisories/unreviewed/2022/05/GHSA-m52w-9gvm-79q5/GHSA-m52w-9gvm-79q5.json index a70a2a8b3fd..81cb3e97bbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-m52w-9gvm-79q5/GHSA-m52w-9gvm-79q5.json +++ b/advisories/unreviewed/2022/05/GHSA-m52w-9gvm-79q5/GHSA-m52w-9gvm-79q5.json @@ -7,12 +7,8 @@ "CVE-2014-7933" ], "details": "Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m55j-9h2h-mhvh/GHSA-m55j-9h2h-mhvh.json b/advisories/unreviewed/2022/05/GHSA-m55j-9h2h-mhvh/GHSA-m55j-9h2h-mhvh.json index 3b768b2e1b5..85ff5bca0b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-m55j-9h2h-mhvh/GHSA-m55j-9h2h-mhvh.json +++ b/advisories/unreviewed/2022/05/GHSA-m55j-9h2h-mhvh/GHSA-m55j-9h2h-mhvh.json @@ -7,12 +7,8 @@ "CVE-2014-6474" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:MEMCACHED.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m5pc-rc38-gc82/GHSA-m5pc-rc38-gc82.json b/advisories/unreviewed/2022/05/GHSA-m5pc-rc38-gc82/GHSA-m5pc-rc38-gc82.json index fe8ece27ca4..25aa6b4306a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5pc-rc38-gc82/GHSA-m5pc-rc38-gc82.json +++ b/advisories/unreviewed/2022/05/GHSA-m5pc-rc38-gc82/GHSA-m5pc-rc38-gc82.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m5xf-8w89-qqxm/GHSA-m5xf-8w89-qqxm.json b/advisories/unreviewed/2022/05/GHSA-m5xf-8w89-qqxm/GHSA-m5xf-8w89-qqxm.json index 380323fb3dc..e27775f6f86 100644 --- a/advisories/unreviewed/2022/05/GHSA-m5xf-8w89-qqxm/GHSA-m5xf-8w89-qqxm.json +++ b/advisories/unreviewed/2022/05/GHSA-m5xf-8w89-qqxm/GHSA-m5xf-8w89-qqxm.json @@ -7,12 +7,8 @@ "CVE-2005-4872" ], "details": "Perl-Compatible Regular Expression (PCRE) library before 6.2 does not properly count the number of named capturing subpatterns, which allows context-dependent attackers to cause a denial of service (crash) via a regular expression with a large number of named subpatterns, which triggers a buffer overflow. NOTE: this issue was originally subsumed by CVE-2006-7224, but that CVE has been REJECTED and split.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-m74q-p473-55fr/GHSA-m74q-p473-55fr.json b/advisories/unreviewed/2022/05/GHSA-m74q-p473-55fr/GHSA-m74q-p473-55fr.json index e54e9995458..bcaea7ed5c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-m74q-p473-55fr/GHSA-m74q-p473-55fr.json +++ b/advisories/unreviewed/2022/05/GHSA-m74q-p473-55fr/GHSA-m74q-p473-55fr.json @@ -7,12 +7,8 @@ "CVE-2014-7925" ], "details": "Use-after-free vulnerability in the WebAudio implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an audio-rendering thread in which AudioNode data is improperly maintained.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m79m-w7q9-8mx9/GHSA-m79m-w7q9-8mx9.json b/advisories/unreviewed/2022/05/GHSA-m79m-w7q9-8mx9/GHSA-m79m-w7q9-8mx9.json index 232f219146f..b1a5df82631 100644 --- a/advisories/unreviewed/2022/05/GHSA-m79m-w7q9-8mx9/GHSA-m79m-w7q9-8mx9.json +++ b/advisories/unreviewed/2022/05/GHSA-m79m-w7q9-8mx9/GHSA-m79m-w7q9-8mx9.json @@ -7,12 +7,8 @@ "CVE-2015-0847" ], "details": "nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m849-v2w8-6c9x/GHSA-m849-v2w8-6c9x.json b/advisories/unreviewed/2022/05/GHSA-m849-v2w8-6c9x/GHSA-m849-v2w8-6c9x.json index 1ed88da9a1d..79edd46c020 100644 --- a/advisories/unreviewed/2022/05/GHSA-m849-v2w8-6c9x/GHSA-m849-v2w8-6c9x.json +++ b/advisories/unreviewed/2022/05/GHSA-m849-v2w8-6c9x/GHSA-m849-v2w8-6c9x.json @@ -7,12 +7,8 @@ "CVE-2015-3279" ], "details": "Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m86v-3qv8-q72m/GHSA-m86v-3qv8-q72m.json b/advisories/unreviewed/2022/05/GHSA-m86v-3qv8-q72m/GHSA-m86v-3qv8-q72m.json index 795169eff28..20e6c0dd203 100644 --- a/advisories/unreviewed/2022/05/GHSA-m86v-3qv8-q72m/GHSA-m86v-3qv8-q72m.json +++ b/advisories/unreviewed/2022/05/GHSA-m86v-3qv8-q72m/GHSA-m86v-3qv8-q72m.json @@ -7,12 +7,8 @@ "CVE-2015-3101" ], "details": "The Flash broker in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, when Internet Explorer is used, allows attackers to perform a transition from Low Integrity to Medium Integrity via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8c9-qwx9-gjr5/GHSA-m8c9-qwx9-gjr5.json b/advisories/unreviewed/2022/05/GHSA-m8c9-qwx9-gjr5/GHSA-m8c9-qwx9-gjr5.json index 7550008cb21..da6759ea008 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8c9-qwx9-gjr5/GHSA-m8c9-qwx9-gjr5.json +++ b/advisories/unreviewed/2022/05/GHSA-m8c9-qwx9-gjr5/GHSA-m8c9-qwx9-gjr5.json @@ -7,12 +7,8 @@ "CVE-2015-6294" ], "details": "Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (functionality loss) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuu25770.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8cq-r758-gmp2/GHSA-m8cq-r758-gmp2.json b/advisories/unreviewed/2022/05/GHSA-m8cq-r758-gmp2/GHSA-m8cq-r758-gmp2.json index 8b7f9ade119..0ff3e208642 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8cq-r758-gmp2/GHSA-m8cq-r758-gmp2.json +++ b/advisories/unreviewed/2022/05/GHSA-m8cq-r758-gmp2/GHSA-m8cq-r758-gmp2.json @@ -7,12 +7,8 @@ "CVE-2015-5770" ], "details": "MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisioning profile bundle IDs, which allows attackers to replace arbitrary extensions via a crafted enterprise app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-m8f3-577q-266f/GHSA-m8f3-577q-266f.json b/advisories/unreviewed/2022/05/GHSA-m8f3-577q-266f/GHSA-m8f3-577q-266f.json index 5fe9278db07..bfabf140352 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8f3-577q-266f/GHSA-m8f3-577q-266f.json +++ b/advisories/unreviewed/2022/05/GHSA-m8f3-577q-266f/GHSA-m8f3-577q-266f.json @@ -7,12 +7,8 @@ "CVE-2015-0461" ], "details": "Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5 and 11.1.1.7 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Authentication Engine.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mch4-462r-25hp/GHSA-mch4-462r-25hp.json b/advisories/unreviewed/2022/05/GHSA-mch4-462r-25hp/GHSA-mch4-462r-25hp.json index a524544ecd8..f3f57c0ed54 100644 --- a/advisories/unreviewed/2022/05/GHSA-mch4-462r-25hp/GHSA-mch4-462r-25hp.json +++ b/advisories/unreviewed/2022/05/GHSA-mch4-462r-25hp/GHSA-mch4-462r-25hp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mcrg-9w29-v64p/GHSA-mcrg-9w29-v64p.json b/advisories/unreviewed/2022/05/GHSA-mcrg-9w29-v64p/GHSA-mcrg-9w29-v64p.json index 9da01b6f884..7f3bb2cbe11 100644 --- a/advisories/unreviewed/2022/05/GHSA-mcrg-9w29-v64p/GHSA-mcrg-9w29-v64p.json +++ b/advisories/unreviewed/2022/05/GHSA-mcrg-9w29-v64p/GHSA-mcrg-9w29-v64p.json @@ -7,12 +7,8 @@ "CVE-2014-8017" ], "details": "The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfgx-5384-69g8/GHSA-mfgx-5384-69g8.json b/advisories/unreviewed/2022/05/GHSA-mfgx-5384-69g8/GHSA-mfgx-5384-69g8.json index 304a44d455a..6208dbd1a32 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfgx-5384-69g8/GHSA-mfgx-5384-69g8.json +++ b/advisories/unreviewed/2022/05/GHSA-mfgx-5384-69g8/GHSA-mfgx-5384-69g8.json @@ -7,12 +7,8 @@ "CVE-2015-4203" ], "details": "Race condition in Cisco IOS 12.2SCH in the Performance Routing Engine (PRE) module on uBR10000 devices, when NetFlow and an MPLS IPv6 VPN are configured, allows remote attackers to cause a denial of service (PXF process crash) by sending malformed MPLS 6VPE packets quickly, aka Bug ID CSCud83396.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mfhq-m29x-g5ww/GHSA-mfhq-m29x-g5ww.json b/advisories/unreviewed/2022/05/GHSA-mfhq-m29x-g5ww/GHSA-mfhq-m29x-g5ww.json index d8acd69e423..551c2b334a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfhq-m29x-g5ww/GHSA-mfhq-m29x-g5ww.json +++ b/advisories/unreviewed/2022/05/GHSA-mfhq-m29x-g5ww/GHSA-mfhq-m29x-g5ww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -99,9 +97,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mgcw-x9qc-5hhf/GHSA-mgcw-x9qc-5hhf.json b/advisories/unreviewed/2022/05/GHSA-mgcw-x9qc-5hhf/GHSA-mgcw-x9qc-5hhf.json index 6551eda31ba..18c11888303 100644 --- a/advisories/unreviewed/2022/05/GHSA-mgcw-x9qc-5hhf/GHSA-mgcw-x9qc-5hhf.json +++ b/advisories/unreviewed/2022/05/GHSA-mgcw-x9qc-5hhf/GHSA-mgcw-x9qc-5hhf.json @@ -7,12 +7,8 @@ "CVE-2015-1107" ], "details": "The Lock Screen component in Apple iOS before 8.3 does not properly implement the erasure feature for incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mhvg-9xgm-2g74/GHSA-mhvg-9xgm-2g74.json b/advisories/unreviewed/2022/05/GHSA-mhvg-9xgm-2g74/GHSA-mhvg-9xgm-2g74.json index a01dcc4b965..1589ee7f3ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhvg-9xgm-2g74/GHSA-mhvg-9xgm-2g74.json +++ b/advisories/unreviewed/2022/05/GHSA-mhvg-9xgm-2g74/GHSA-mhvg-9xgm-2g74.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mhvj-23qg-xqx6/GHSA-mhvj-23qg-xqx6.json b/advisories/unreviewed/2022/05/GHSA-mhvj-23qg-xqx6/GHSA-mhvj-23qg-xqx6.json index bc65977e193..d890201ece1 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhvj-23qg-xqx6/GHSA-mhvj-23qg-xqx6.json +++ b/advisories/unreviewed/2022/05/GHSA-mhvj-23qg-xqx6/GHSA-mhvj-23qg-xqx6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mj34-7h26-pj8g/GHSA-mj34-7h26-pj8g.json b/advisories/unreviewed/2022/05/GHSA-mj34-7h26-pj8g/GHSA-mj34-7h26-pj8g.json index 5cc98e626d3..83b0712ac60 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj34-7h26-pj8g/GHSA-mj34-7h26-pj8g.json +++ b/advisories/unreviewed/2022/05/GHSA-mj34-7h26-pj8g/GHSA-mj34-7h26-pj8g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mj5c-m7rm-67v6/GHSA-mj5c-m7rm-67v6.json b/advisories/unreviewed/2022/05/GHSA-mj5c-m7rm-67v6/GHSA-mj5c-m7rm-67v6.json index 8910e3ae70e..85362a69bc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj5c-m7rm-67v6/GHSA-mj5c-m7rm-67v6.json +++ b/advisories/unreviewed/2022/05/GHSA-mj5c-m7rm-67v6/GHSA-mj5c-m7rm-67v6.json @@ -7,12 +7,8 @@ "CVE-2015-1235" ], "details": "The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjp9-4wjh-f55v/GHSA-mjp9-4wjh-f55v.json b/advisories/unreviewed/2022/05/GHSA-mjp9-4wjh-f55v/GHSA-mjp9-4wjh-f55v.json index d605a93c2d8..49d8abe4d5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjp9-4wjh-f55v/GHSA-mjp9-4wjh-f55v.json +++ b/advisories/unreviewed/2022/05/GHSA-mjp9-4wjh-f55v/GHSA-mjp9-4wjh-f55v.json @@ -7,12 +7,8 @@ "CVE-2015-6301" ], "details": "The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun72171.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mjpg-hh65-wgff/GHSA-mjpg-hh65-wgff.json b/advisories/unreviewed/2022/05/GHSA-mjpg-hh65-wgff/GHSA-mjpg-hh65-wgff.json index 9a67a9009e9..04e4faab0a6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjpg-hh65-wgff/GHSA-mjpg-hh65-wgff.json +++ b/advisories/unreviewed/2022/05/GHSA-mjpg-hh65-wgff/GHSA-mjpg-hh65-wgff.json @@ -7,12 +7,8 @@ "CVE-2015-3633" ], "details": "Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via vectors related to digital signatures.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjqw-qqhj-w4r3/GHSA-mjqw-qqhj-w4r3.json b/advisories/unreviewed/2022/05/GHSA-mjqw-qqhj-w4r3/GHSA-mjqw-qqhj-w4r3.json index e36e8663f81..116e2f71d3d 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjqw-qqhj-w4r3/GHSA-mjqw-qqhj-w4r3.json +++ b/advisories/unreviewed/2022/05/GHSA-mjqw-qqhj-w4r3/GHSA-mjqw-qqhj-w4r3.json @@ -7,12 +7,8 @@ "CVE-2015-7011" ], "details": "WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mjvf-7w28-c7vv/GHSA-mjvf-7w28-c7vv.json b/advisories/unreviewed/2022/05/GHSA-mjvf-7w28-c7vv/GHSA-mjvf-7w28-c7vv.json index cd64bda2bc2..a8519dd60ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjvf-7w28-c7vv/GHSA-mjvf-7w28-c7vv.json +++ b/advisories/unreviewed/2022/05/GHSA-mjvf-7w28-c7vv/GHSA-mjvf-7w28-c7vv.json @@ -7,12 +7,8 @@ "CVE-2015-3092" ], "details": "Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-3091.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mmqm-9qw8-9hc9/GHSA-mmqm-9qw8-9hc9.json b/advisories/unreviewed/2022/05/GHSA-mmqm-9qw8-9hc9/GHSA-mmqm-9qw8-9hc9.json index ceb5272050d..2b7d51106e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmqm-9qw8-9hc9/GHSA-mmqm-9qw8-9hc9.json +++ b/advisories/unreviewed/2022/05/GHSA-mmqm-9qw8-9hc9/GHSA-mmqm-9qw8-9hc9.json @@ -7,12 +7,8 @@ "CVE-2015-2720" ], "details": "The update implementation in Mozilla Firefox before 38.0 on Windows does not ensure that the pathname for updater.exe corresponds to the application directory, which might allow local users to gain privileges via a Trojan horse file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mp9j-249w-q6hq/GHSA-mp9j-249w-q6hq.json b/advisories/unreviewed/2022/05/GHSA-mp9j-249w-q6hq/GHSA-mp9j-249w-q6hq.json index 4efc3b49d3d..0abe6a6a1b4 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp9j-249w-q6hq/GHSA-mp9j-249w-q6hq.json +++ b/advisories/unreviewed/2022/05/GHSA-mp9j-249w-q6hq/GHSA-mp9j-249w-q6hq.json @@ -7,12 +7,8 @@ "CVE-2015-2222" ], "details": "ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mq4c-rqf5-rww5/GHSA-mq4c-rqf5-rww5.json b/advisories/unreviewed/2022/05/GHSA-mq4c-rqf5-rww5/GHSA-mq4c-rqf5-rww5.json index 8835b4d372c..08c8a6c1ced 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq4c-rqf5-rww5/GHSA-mq4c-rqf5-rww5.json +++ b/advisories/unreviewed/2022/05/GHSA-mq4c-rqf5-rww5/GHSA-mq4c-rqf5-rww5.json @@ -7,12 +7,8 @@ "CVE-2015-0511" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : SP.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mq7m-72cj-7m7m/GHSA-mq7m-72cj-7m7m.json b/advisories/unreviewed/2022/05/GHSA-mq7m-72cj-7m7m/GHSA-mq7m-72cj-7m7m.json index 0bbd450e8f2..1671af5b942 100644 --- a/advisories/unreviewed/2022/05/GHSA-mq7m-72cj-7m7m/GHSA-mq7m-72cj-7m7m.json +++ b/advisories/unreviewed/2022/05/GHSA-mq7m-72cj-7m7m/GHSA-mq7m-72cj-7m7m.json @@ -7,12 +7,8 @@ "CVE-2014-8142" ], "details": "Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys within the serialized properties of an object, a different vulnerability than CVE-2004-1019.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mrx8-xmg2-v94q/GHSA-mrx8-xmg2-v94q.json b/advisories/unreviewed/2022/05/GHSA-mrx8-xmg2-v94q/GHSA-mrx8-xmg2-v94q.json index 883a9d906b0..cd4224295e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrx8-xmg2-v94q/GHSA-mrx8-xmg2-v94q.json +++ b/advisories/unreviewed/2022/05/GHSA-mrx8-xmg2-v94q/GHSA-mrx8-xmg2-v94q.json @@ -7,12 +7,8 @@ "CVE-2015-0840" ], "details": "The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mv47-v724-6j22/GHSA-mv47-v724-6j22.json b/advisories/unreviewed/2022/05/GHSA-mv47-v724-6j22/GHSA-mv47-v724-6j22.json index ee21437d3e1..ab29d13ba98 100644 --- a/advisories/unreviewed/2022/05/GHSA-mv47-v724-6j22/GHSA-mv47-v724-6j22.json +++ b/advisories/unreviewed/2022/05/GHSA-mv47-v724-6j22/GHSA-mv47-v724-6j22.json @@ -7,12 +7,8 @@ "CVE-2014-8008" ], "details": "Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-mwxh-q8vv-r69f/GHSA-mwxh-q8vv-r69f.json b/advisories/unreviewed/2022/05/GHSA-mwxh-q8vv-r69f/GHSA-mwxh-q8vv-r69f.json index 264b035d2a6..3e118dc1bb6 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwxh-q8vv-r69f/GHSA-mwxh-q8vv-r69f.json +++ b/advisories/unreviewed/2022/05/GHSA-mwxh-q8vv-r69f/GHSA-mwxh-q8vv-r69f.json @@ -7,12 +7,8 @@ "CVE-2015-1258" ], "details": "Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mx7m-rr36-mf2q/GHSA-mx7m-rr36-mf2q.json b/advisories/unreviewed/2022/05/GHSA-mx7m-rr36-mf2q/GHSA-mx7m-rr36-mf2q.json index e65dded3ced..c3863a699b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-mx7m-rr36-mf2q/GHSA-mx7m-rr36-mf2q.json +++ b/advisories/unreviewed/2022/05/GHSA-mx7m-rr36-mf2q/GHSA-mx7m-rr36-mf2q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mxgq-v86p-xg2p/GHSA-mxgq-v86p-xg2p.json b/advisories/unreviewed/2022/05/GHSA-mxgq-v86p-xg2p/GHSA-mxgq-v86p-xg2p.json index 1b5f86577e3..41378296363 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxgq-v86p-xg2p/GHSA-mxgq-v86p-xg2p.json +++ b/advisories/unreviewed/2022/05/GHSA-mxgq-v86p-xg2p/GHSA-mxgq-v86p-xg2p.json @@ -7,12 +7,8 @@ "CVE-2015-0199" ], "details": "The mmfslinux kernel module in IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to cause a denial of service (memory corruption) via unspecified character-device ioctl calls.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-mxpg-59pv-9mhw/GHSA-mxpg-59pv-9mhw.json b/advisories/unreviewed/2022/05/GHSA-mxpg-59pv-9mhw/GHSA-mxpg-59pv-9mhw.json index 5806ee169f9..4b6405e2523 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxpg-59pv-9mhw/GHSA-mxpg-59pv-9mhw.json +++ b/advisories/unreviewed/2022/05/GHSA-mxpg-59pv-9mhw/GHSA-mxpg-59pv-9mhw.json @@ -7,12 +7,8 @@ "CVE-2013-7365" ], "details": "Cross-site scripting (XSS) vulnerability in SAP Enterprise Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p33f-5f4f-x3rj/GHSA-p33f-5f4f-x3rj.json b/advisories/unreviewed/2022/05/GHSA-p33f-5f4f-x3rj/GHSA-p33f-5f4f-x3rj.json index 6a9500b23b2..939ee6d1b11 100644 --- a/advisories/unreviewed/2022/05/GHSA-p33f-5f4f-x3rj/GHSA-p33f-5f4f-x3rj.json +++ b/advisories/unreviewed/2022/05/GHSA-p33f-5f4f-x3rj/GHSA-p33f-5f4f-x3rj.json @@ -7,12 +7,8 @@ "CVE-2015-4268" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCus16052.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3h2-r83w-vg3r/GHSA-p3h2-r83w-vg3r.json b/advisories/unreviewed/2022/05/GHSA-p3h2-r83w-vg3r/GHSA-p3h2-r83w-vg3r.json index 2421f59bc19..9136789e5a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3h2-r83w-vg3r/GHSA-p3h2-r83w-vg3r.json +++ b/advisories/unreviewed/2022/05/GHSA-p3h2-r83w-vg3r/GHSA-p3h2-r83w-vg3r.json @@ -7,12 +7,8 @@ "CVE-2014-9324" ], "details": "The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before 3.3.11, and 4.0.x before 4.0.3 allows remote authenticated users to access and modify arbitrary tickets via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p3v9-93rx-rg76/GHSA-p3v9-93rx-rg76.json b/advisories/unreviewed/2022/05/GHSA-p3v9-93rx-rg76/GHSA-p3v9-93rx-rg76.json index 689f5c8bb52..ee267392a82 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3v9-93rx-rg76/GHSA-p3v9-93rx-rg76.json +++ b/advisories/unreviewed/2022/05/GHSA-p3v9-93rx-rg76/GHSA-p3v9-93rx-rg76.json @@ -7,12 +7,8 @@ "CVE-2015-2729" ], "details": "The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before 38.1 does not properly calculate an oscillator rendering range, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p3xr-h9wq-j6wv/GHSA-p3xr-h9wq-j6wv.json b/advisories/unreviewed/2022/05/GHSA-p3xr-h9wq-j6wv/GHSA-p3xr-h9wq-j6wv.json index a0e2e93c85c..048332a8268 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3xr-h9wq-j6wv/GHSA-p3xr-h9wq-j6wv.json +++ b/advisories/unreviewed/2022/05/GHSA-p3xr-h9wq-j6wv/GHSA-p3xr-h9wq-j6wv.json @@ -7,12 +7,8 @@ "CVE-2013-7277" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to saa.php, (2) username parameter to login.php, or (3) keyword_list parameter to keysearch.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p4cg-q598-w59r/GHSA-p4cg-q598-w59r.json b/advisories/unreviewed/2022/05/GHSA-p4cg-q598-w59r/GHSA-p4cg-q598-w59r.json index 9efd780c63f..2a7a55c9816 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4cg-q598-w59r/GHSA-p4cg-q598-w59r.json +++ b/advisories/unreviewed/2022/05/GHSA-p4cg-q598-w59r/GHSA-p4cg-q598-w59r.json @@ -7,12 +7,8 @@ "CVE-2015-3086" ], "details": "Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code by leveraging an unspecified \"type confusion,\" a different vulnerability than CVE-2015-3077 and CVE-2015-3084.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p4ff-c7wr-66j3/GHSA-p4ff-c7wr-66j3.json b/advisories/unreviewed/2022/05/GHSA-p4ff-c7wr-66j3/GHSA-p4ff-c7wr-66j3.json index 423dbb0fb1c..010dfa53477 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4ff-c7wr-66j3/GHSA-p4ff-c7wr-66j3.json +++ b/advisories/unreviewed/2022/05/GHSA-p4ff-c7wr-66j3/GHSA-p4ff-c7wr-66j3.json @@ -7,12 +7,8 @@ "CVE-2015-1255" ], "details": "Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging improper handling of a stop action for an audio track.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p4jq-wxrf-c5vq/GHSA-p4jq-wxrf-c5vq.json b/advisories/unreviewed/2022/05/GHSA-p4jq-wxrf-c5vq/GHSA-p4jq-wxrf-c5vq.json index 6b3ef5d6ada..f544334c26f 100644 --- a/advisories/unreviewed/2022/05/GHSA-p4jq-wxrf-c5vq/GHSA-p4jq-wxrf-c5vq.json +++ b/advisories/unreviewed/2022/05/GHSA-p4jq-wxrf-c5vq/GHSA-p4jq-wxrf-c5vq.json @@ -7,12 +7,8 @@ "CVE-2015-5940" ], "details": "The Accelerate Framework component in Apple iOS before 9.1 and OS X before 10.11.1, when multi-threading is enabled, omits certain validation and locking steps, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p5g7-mvx2-57vw/GHSA-p5g7-mvx2-57vw.json b/advisories/unreviewed/2022/05/GHSA-p5g7-mvx2-57vw/GHSA-p5g7-mvx2-57vw.json index 8dedb7366da..3b25c4e3456 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5g7-mvx2-57vw/GHSA-p5g7-mvx2-57vw.json +++ b/advisories/unreviewed/2022/05/GHSA-p5g7-mvx2-57vw/GHSA-p5g7-mvx2-57vw.json @@ -7,12 +7,8 @@ "CVE-2015-5755" ], "details": "CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5761.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p769-cjvp-8m5m/GHSA-p769-cjvp-8m5m.json b/advisories/unreviewed/2022/05/GHSA-p769-cjvp-8m5m/GHSA-p769-cjvp-8m5m.json index 63036aedf03..9c6f019a9e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-p769-cjvp-8m5m/GHSA-p769-cjvp-8m5m.json +++ b/advisories/unreviewed/2022/05/GHSA-p769-cjvp-8m5m/GHSA-p769-cjvp-8m5m.json @@ -7,12 +7,8 @@ "CVE-2005-2553" ], "details": "The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -80,9 +76,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p7q6-69w3-ppv9/GHSA-p7q6-69w3-ppv9.json b/advisories/unreviewed/2022/05/GHSA-p7q6-69w3-ppv9/GHSA-p7q6-69w3-ppv9.json index f1a5a02a819..7223086b0d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7q6-69w3-ppv9/GHSA-p7q6-69w3-ppv9.json +++ b/advisories/unreviewed/2022/05/GHSA-p7q6-69w3-ppv9/GHSA-p7q6-69w3-ppv9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-p7qf-fqjr-3jrq/GHSA-p7qf-fqjr-3jrq.json b/advisories/unreviewed/2022/05/GHSA-p7qf-fqjr-3jrq/GHSA-p7qf-fqjr-3jrq.json index d57a635f801..f26d1e8af5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p7qf-fqjr-3jrq/GHSA-p7qf-fqjr-3jrq.json +++ b/advisories/unreviewed/2022/05/GHSA-p7qf-fqjr-3jrq/GHSA-p7qf-fqjr-3jrq.json @@ -7,12 +7,8 @@ "CVE-2015-4237" ], "details": "The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p88r-4rfm-cpwf/GHSA-p88r-4rfm-cpwf.json b/advisories/unreviewed/2022/05/GHSA-p88r-4rfm-cpwf/GHSA-p88r-4rfm-cpwf.json index 8023eb940d1..516e17afcd2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p88r-4rfm-cpwf/GHSA-p88r-4rfm-cpwf.json +++ b/advisories/unreviewed/2022/05/GHSA-p88r-4rfm-cpwf/GHSA-p88r-4rfm-cpwf.json @@ -7,12 +7,8 @@ "CVE-2015-1269" ], "details": "The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to bypass intended access restrictions via a string that (1) ends in a . (dot) character or (2) is not entirely lowercase.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p89g-cq9h-86g3/GHSA-p89g-cq9h-86g3.json b/advisories/unreviewed/2022/05/GHSA-p89g-cq9h-86g3/GHSA-p89g-cq9h-86g3.json index 686960dac19..085901cee71 100644 --- a/advisories/unreviewed/2022/05/GHSA-p89g-cq9h-86g3/GHSA-p89g-cq9h-86g3.json +++ b/advisories/unreviewed/2022/05/GHSA-p89g-cq9h-86g3/GHSA-p89g-cq9h-86g3.json @@ -7,12 +7,8 @@ "CVE-2015-1256" ], "details": "Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that leverages improper handling of a shadow tree for a use element.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-p8wp-fqcr-gwq9/GHSA-p8wp-fqcr-gwq9.json b/advisories/unreviewed/2022/05/GHSA-p8wp-fqcr-gwq9/GHSA-p8wp-fqcr-gwq9.json index cc24b12396a..e6e7443de0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8wp-fqcr-gwq9/GHSA-p8wp-fqcr-gwq9.json +++ b/advisories/unreviewed/2022/05/GHSA-p8wp-fqcr-gwq9/GHSA-p8wp-fqcr-gwq9.json @@ -7,12 +7,8 @@ "CVE-2015-5930" ], "details": "WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pc4j-hm8h-32rp/GHSA-pc4j-hm8h-32rp.json b/advisories/unreviewed/2022/05/GHSA-pc4j-hm8h-32rp/GHSA-pc4j-hm8h-32rp.json index bce4db68e9c..f234af8545c 100644 --- a/advisories/unreviewed/2022/05/GHSA-pc4j-hm8h-32rp/GHSA-pc4j-hm8h-32rp.json +++ b/advisories/unreviewed/2022/05/GHSA-pc4j-hm8h-32rp/GHSA-pc4j-hm8h-32rp.json @@ -7,12 +7,8 @@ "CVE-2015-7006" ], "details": "Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code via a crafted CPIO archive.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pf54-f5v5-r8hp/GHSA-pf54-f5v5-r8hp.json b/advisories/unreviewed/2022/05/GHSA-pf54-f5v5-r8hp/GHSA-pf54-f5v5-r8hp.json index 4b50b21c00f..65fa83d6675 100644 --- a/advisories/unreviewed/2022/05/GHSA-pf54-f5v5-r8hp/GHSA-pf54-f5v5-r8hp.json +++ b/advisories/unreviewed/2022/05/GHSA-pf54-f5v5-r8hp/GHSA-pf54-f5v5-r8hp.json @@ -7,12 +7,8 @@ "CVE-2015-0530" ], "details": "Buffer overflow in an unspecified function in nsr_render_log in EMC NetWorker before 8.0.4.3, 8.1.x before 8.1.2.6, and 8.2.x before 8.2.1.2 allows local users to gain privileges via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pg6v-35j6-x9ww/GHSA-pg6v-35j6-x9ww.json b/advisories/unreviewed/2022/05/GHSA-pg6v-35j6-x9ww/GHSA-pg6v-35j6-x9ww.json index 3dc5b9902d4..993a2ad3b66 100644 --- a/advisories/unreviewed/2022/05/GHSA-pg6v-35j6-x9ww/GHSA-pg6v-35j6-x9ww.json +++ b/advisories/unreviewed/2022/05/GHSA-pg6v-35j6-x9ww/GHSA-pg6v-35j6-x9ww.json @@ -7,12 +7,8 @@ "CVE-2013-3706" ], "details": "Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pgp2-pr57-6j62/GHSA-pgp2-pr57-6j62.json b/advisories/unreviewed/2022/05/GHSA-pgp2-pr57-6j62/GHSA-pgp2-pr57-6j62.json index ef5e1aca7dd..2b8192b5eaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgp2-pr57-6j62/GHSA-pgp2-pr57-6j62.json +++ b/advisories/unreviewed/2022/05/GHSA-pgp2-pr57-6j62/GHSA-pgp2-pr57-6j62.json @@ -7,12 +7,8 @@ "CVE-2015-2570" ], "details": "Unspecified vulnerability in the Oracle Demand Planning component in Oracle Supply Chain Products Suite 11.5.10, 12.0, 12.1, and 12.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-pgp5-wmq5-xx4p/GHSA-pgp5-wmq5-xx4p.json b/advisories/unreviewed/2022/05/GHSA-pgp5-wmq5-xx4p/GHSA-pgp5-wmq5-xx4p.json index 3e8548f932b..dabc503a85a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgp5-wmq5-xx4p/GHSA-pgp5-wmq5-xx4p.json +++ b/advisories/unreviewed/2022/05/GHSA-pgp5-wmq5-xx4p/GHSA-pgp5-wmq5-xx4p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ph3r-pgq5-jxx4/GHSA-ph3r-pgq5-jxx4.json b/advisories/unreviewed/2022/05/GHSA-ph3r-pgq5-jxx4/GHSA-ph3r-pgq5-jxx4.json index 79d998eba9b..eb1760afa2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph3r-pgq5-jxx4/GHSA-ph3r-pgq5-jxx4.json +++ b/advisories/unreviewed/2022/05/GHSA-ph3r-pgq5-jxx4/GHSA-ph3r-pgq5-jxx4.json @@ -7,12 +7,8 @@ "CVE-2015-0508" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-0506.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ph8h-6p6x-772p/GHSA-ph8h-6p6x-772p.json b/advisories/unreviewed/2022/05/GHSA-ph8h-6p6x-772p/GHSA-ph8h-6p6x-772p.json index 227bae1f02d..123015a0753 100644 --- a/advisories/unreviewed/2022/05/GHSA-ph8h-6p6x-772p/GHSA-ph8h-6p6x-772p.json +++ b/advisories/unreviewed/2022/05/GHSA-ph8h-6p6x-772p/GHSA-ph8h-6p6x-772p.json @@ -7,12 +7,8 @@ "CVE-2014-8616" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) user group or (2) vpn template menus.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-phvx-v9j2-6wfr/GHSA-phvx-v9j2-6wfr.json b/advisories/unreviewed/2022/05/GHSA-phvx-v9j2-6wfr/GHSA-phvx-v9j2-6wfr.json index b8f7a9a3b2b..c9c04e0dda1 100644 --- a/advisories/unreviewed/2022/05/GHSA-phvx-v9j2-6wfr/GHSA-phvx-v9j2-6wfr.json +++ b/advisories/unreviewed/2022/05/GHSA-phvx-v9j2-6wfr/GHSA-phvx-v9j2-6wfr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm5w-373f-pqmv/GHSA-pm5w-373f-pqmv.json b/advisories/unreviewed/2022/05/GHSA-pm5w-373f-pqmv/GHSA-pm5w-373f-pqmv.json index fb998eef7a5..c70c342d099 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm5w-373f-pqmv/GHSA-pm5w-373f-pqmv.json +++ b/advisories/unreviewed/2022/05/GHSA-pm5w-373f-pqmv/GHSA-pm5w-373f-pqmv.json @@ -7,12 +7,8 @@ "CVE-2015-5766" ], "details": "Directory traversal vulnerability in Air Traffic in Apple iOS before 8.4.1 allows attackers to access arbitrary filesystem locations via vectors related to asset handling.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pm9c-c59m-r383/GHSA-pm9c-c59m-r383.json b/advisories/unreviewed/2022/05/GHSA-pm9c-c59m-r383/GHSA-pm9c-c59m-r383.json index 268c7bbd6db..3ac601f2cc4 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm9c-c59m-r383/GHSA-pm9c-c59m-r383.json +++ b/advisories/unreviewed/2022/05/GHSA-pm9c-c59m-r383/GHSA-pm9c-c59m-r383.json @@ -7,12 +7,8 @@ "CVE-2013-7280" ], "details": "Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of service (crash) via a long string in a .m3u file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pmh9-frrx-c2qm/GHSA-pmh9-frrx-c2qm.json b/advisories/unreviewed/2022/05/GHSA-pmh9-frrx-c2qm/GHSA-pmh9-frrx-c2qm.json index f6acaf01768..48e6ebdb52e 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmh9-frrx-c2qm/GHSA-pmh9-frrx-c2qm.json +++ b/advisories/unreviewed/2022/05/GHSA-pmh9-frrx-c2qm/GHSA-pmh9-frrx-c2qm.json @@ -7,12 +7,8 @@ "CVE-2015-4231" ], "details": "The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ppq4-pxjf-2xx4/GHSA-ppq4-pxjf-2xx4.json b/advisories/unreviewed/2022/05/GHSA-ppq4-pxjf-2xx4/GHSA-ppq4-pxjf-2xx4.json index 132cb242569..58244e3af0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-ppq4-pxjf-2xx4/GHSA-ppq4-pxjf-2xx4.json +++ b/advisories/unreviewed/2022/05/GHSA-ppq4-pxjf-2xx4/GHSA-ppq4-pxjf-2xx4.json @@ -7,12 +7,8 @@ "CVE-2013-2110" ], "details": "Heap-based buffer overflow in the php_quot_print_encode function in ext/standard/quot_print.c in PHP before 5.3.26 and 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted argument to the quoted_printable_encode function.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prgf-q87j-gvg5/GHSA-prgf-q87j-gvg5.json b/advisories/unreviewed/2022/05/GHSA-prgf-q87j-gvg5/GHSA-prgf-q87j-gvg5.json index d32bb24e747..ed6887991df 100644 --- a/advisories/unreviewed/2022/05/GHSA-prgf-q87j-gvg5/GHSA-prgf-q87j-gvg5.json +++ b/advisories/unreviewed/2022/05/GHSA-prgf-q87j-gvg5/GHSA-prgf-q87j-gvg5.json @@ -7,12 +7,8 @@ "CVE-2014-7937" ], "details": "Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Vorbis I data.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-prgf-rqp7-pmqx/GHSA-prgf-rqp7-pmqx.json b/advisories/unreviewed/2022/05/GHSA-prgf-rqp7-pmqx/GHSA-prgf-rqp7-pmqx.json index 80563a98abb..daf8d804f1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-prgf-rqp7-pmqx/GHSA-prgf-rqp7-pmqx.json +++ b/advisories/unreviewed/2022/05/GHSA-prgf-rqp7-pmqx/GHSA-prgf-rqp7-pmqx.json @@ -7,12 +7,8 @@ "CVE-2015-1248" ], "details": "The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:http: URL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-prjq-57v9-5pcf/GHSA-prjq-57v9-5pcf.json b/advisories/unreviewed/2022/05/GHSA-prjq-57v9-5pcf/GHSA-prjq-57v9-5pcf.json index f4947e4e737..7c9fd9e517e 100644 --- a/advisories/unreviewed/2022/05/GHSA-prjq-57v9-5pcf/GHSA-prjq-57v9-5pcf.json +++ b/advisories/unreviewed/2022/05/GHSA-prjq-57v9-5pcf/GHSA-prjq-57v9-5pcf.json @@ -7,12 +7,8 @@ "CVE-2015-5774" ], "details": "Buffer overflow in IOHIDFamily in Apple iOS before 8.4.1 and OS X before 10.10.5 allows local users to gain privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvg3-5pq8-4hwq/GHSA-pvg3-5pq8-4hwq.json b/advisories/unreviewed/2022/05/GHSA-pvg3-5pq8-4hwq/GHSA-pvg3-5pq8-4hwq.json index 3938228e3a6..a45cefc6a12 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvg3-5pq8-4hwq/GHSA-pvg3-5pq8-4hwq.json +++ b/advisories/unreviewed/2022/05/GHSA-pvg3-5pq8-4hwq/GHSA-pvg3-5pq8-4hwq.json @@ -7,12 +7,8 @@ "CVE-2014-9506" ], "details": "MantisBT before 1.2.18 does not properly check permissions when sending an email that indicates when a monitored issue is related to another issue, which allows remote authenticated users to obtain sensitive information about restricted issues.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pvwc-h4wp-xc77/GHSA-pvwc-h4wp-xc77.json b/advisories/unreviewed/2022/05/GHSA-pvwc-h4wp-xc77/GHSA-pvwc-h4wp-xc77.json index 19f07e72ea2..1c27d4eb4b5 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvwc-h4wp-xc77/GHSA-pvwc-h4wp-xc77.json +++ b/advisories/unreviewed/2022/05/GHSA-pvwc-h4wp-xc77/GHSA-pvwc-h4wp-xc77.json @@ -7,12 +7,8 @@ "CVE-2015-4273" ], "details": "The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15.0(912), 15.0(935), and 15.0(938) allows remote attackers to cause a denial of service (Session Manager outage) via malformed fields in an IP packet, aka Bug ID CSCut38476.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw5j-466g-x8qc/GHSA-pw5j-466g-x8qc.json b/advisories/unreviewed/2022/05/GHSA-pw5j-466g-x8qc/GHSA-pw5j-466g-x8qc.json index 9c5eb95d5d0..fc7184cb799 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw5j-466g-x8qc/GHSA-pw5j-466g-x8qc.json +++ b/advisories/unreviewed/2022/05/GHSA-pw5j-466g-x8qc/GHSA-pw5j-466g-x8qc.json @@ -7,12 +7,8 @@ "CVE-2014-7945" ], "details": "OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, and t2.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pw5v-j24x-gvj8/GHSA-pw5v-j24x-gvj8.json b/advisories/unreviewed/2022/05/GHSA-pw5v-j24x-gvj8/GHSA-pw5v-j24x-gvj8.json index 8eda7e0e2c7..088731a395d 100644 --- a/advisories/unreviewed/2022/05/GHSA-pw5v-j24x-gvj8/GHSA-pw5v-j24x-gvj8.json +++ b/advisories/unreviewed/2022/05/GHSA-pw5v-j24x-gvj8/GHSA-pw5v-j24x-gvj8.json @@ -7,12 +7,8 @@ "CVE-2014-8019" ], "details": "Directory traversal vulnerability in Cisco Enterprise Content Delivery System (ECDS) allows remote attackers to read arbitrary files via a crafted URL, aka Bug ID CSCuo90148.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-pxmf-hfjp-6v79/GHSA-pxmf-hfjp-6v79.json b/advisories/unreviewed/2022/05/GHSA-pxmf-hfjp-6v79/GHSA-pxmf-hfjp-6v79.json index 16bfeee585d..40011923473 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxmf-hfjp-6v79/GHSA-pxmf-hfjp-6v79.json +++ b/advisories/unreviewed/2022/05/GHSA-pxmf-hfjp-6v79/GHSA-pxmf-hfjp-6v79.json @@ -7,12 +7,8 @@ "CVE-2015-3102" ], "details": "Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-3098 and CVE-2015-3099.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q246-hj54-m729/GHSA-q246-hj54-m729.json b/advisories/unreviewed/2022/05/GHSA-q246-hj54-m729/GHSA-q246-hj54-m729.json index 7320c78d489..e373da4212a 100644 --- a/advisories/unreviewed/2022/05/GHSA-q246-hj54-m729/GHSA-q246-hj54-m729.json +++ b/advisories/unreviewed/2022/05/GHSA-q246-hj54-m729/GHSA-q246-hj54-m729.json @@ -7,12 +7,8 @@ "CVE-2015-2066" ], "details": "SQL injection vulnerability in DLGuard 4.5 allows remote attackers to execute arbitrary SQL commands via the c parameter to index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q299-h828-h44m/GHSA-q299-h828-h44m.json b/advisories/unreviewed/2022/05/GHSA-q299-h828-h44m/GHSA-q299-h828-h44m.json index 52929e5d901..e7fcade9cda 100644 --- a/advisories/unreviewed/2022/05/GHSA-q299-h828-h44m/GHSA-q299-h828-h44m.json +++ b/advisories/unreviewed/2022/05/GHSA-q299-h828-h44m/GHSA-q299-h828-h44m.json @@ -7,12 +7,8 @@ "CVE-2015-4209" ], "details": "Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive information by obtaining a list of all meetings and then sending a calendar request for each one, aka Bug ID CSCur23913.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q2xm-j8qr-28r7/GHSA-q2xm-j8qr-28r7.json b/advisories/unreviewed/2022/05/GHSA-q2xm-j8qr-28r7/GHSA-q2xm-j8qr-28r7.json index f51aa95b22c..9c0038d0fee 100644 --- a/advisories/unreviewed/2022/05/GHSA-q2xm-j8qr-28r7/GHSA-q2xm-j8qr-28r7.json +++ b/advisories/unreviewed/2022/05/GHSA-q2xm-j8qr-28r7/GHSA-q2xm-j8qr-28r7.json @@ -7,12 +7,8 @@ "CVE-2015-2567" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4fr-6j5h-39h7/GHSA-q4fr-6j5h-39h7.json b/advisories/unreviewed/2022/05/GHSA-q4fr-6j5h-39h7/GHSA-q4fr-6j5h-39h7.json index 14908230245..74e08f12e08 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4fr-6j5h-39h7/GHSA-q4fr-6j5h-39h7.json +++ b/advisories/unreviewed/2022/05/GHSA-q4fr-6j5h-39h7/GHSA-q4fr-6j5h-39h7.json @@ -7,12 +7,8 @@ "CVE-2015-5722" ], "details": "buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q4j2-qr5x-493m/GHSA-q4j2-qr5x-493m.json b/advisories/unreviewed/2022/05/GHSA-q4j2-qr5x-493m/GHSA-q4j2-qr5x-493m.json index a3eb42a1efe..a6c77af2869 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4j2-qr5x-493m/GHSA-q4j2-qr5x-493m.json +++ b/advisories/unreviewed/2022/05/GHSA-q4j2-qr5x-493m/GHSA-q4j2-qr5x-493m.json @@ -7,12 +7,8 @@ "CVE-2015-0801" ], "details": "Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q676-ggwg-j7vx/GHSA-q676-ggwg-j7vx.json b/advisories/unreviewed/2022/05/GHSA-q676-ggwg-j7vx/GHSA-q676-ggwg-j7vx.json index b1660d0512c..dfe9afd1f33 100644 --- a/advisories/unreviewed/2022/05/GHSA-q676-ggwg-j7vx/GHSA-q676-ggwg-j7vx.json +++ b/advisories/unreviewed/2022/05/GHSA-q676-ggwg-j7vx/GHSA-q676-ggwg-j7vx.json @@ -7,12 +7,8 @@ "CVE-2015-5986" ], "details": "openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q6g8-hgfg-fchf/GHSA-q6g8-hgfg-fchf.json b/advisories/unreviewed/2022/05/GHSA-q6g8-hgfg-fchf/GHSA-q6g8-hgfg-fchf.json index 4f8932fa369..0f7a10ac1b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6g8-hgfg-fchf/GHSA-q6g8-hgfg-fchf.json +++ b/advisories/unreviewed/2022/05/GHSA-q6g8-hgfg-fchf/GHSA-q6g8-hgfg-fchf.json @@ -7,12 +7,8 @@ "CVE-2015-4239" ], "details": "Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q75g-mf48-c9pw/GHSA-q75g-mf48-c9pw.json b/advisories/unreviewed/2022/05/GHSA-q75g-mf48-c9pw/GHSA-q75g-mf48-c9pw.json index 9ce2dd6cf9a..20a4d306009 100644 --- a/advisories/unreviewed/2022/05/GHSA-q75g-mf48-c9pw/GHSA-q75g-mf48-c9pw.json +++ b/advisories/unreviewed/2022/05/GHSA-q75g-mf48-c9pw/GHSA-q75g-mf48-c9pw.json @@ -7,12 +7,8 @@ "CVE-2013-6382" ], "details": "Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_ATTRLIST_BY_HANDLE or (2) XFS_IOC_ATTRLIST_BY_HANDLE_32 ioctl call with a crafted length value, related to the xfs_attrlist_by_handle function in fs/xfs/xfs_ioctl.c and the xfs_compat_attrlist_by_handle function in fs/xfs/xfs_ioctl32.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q75q-75h3-mpqm/GHSA-q75q-75h3-mpqm.json b/advisories/unreviewed/2022/05/GHSA-q75q-75h3-mpqm/GHSA-q75q-75h3-mpqm.json index f7907815546..e301e614e68 100644 --- a/advisories/unreviewed/2022/05/GHSA-q75q-75h3-mpqm/GHSA-q75q-75h3-mpqm.json +++ b/advisories/unreviewed/2022/05/GHSA-q75q-75h3-mpqm/GHSA-q75q-75h3-mpqm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q8gh-4j4r-hp3v/GHSA-q8gh-4j4r-hp3v.json b/advisories/unreviewed/2022/05/GHSA-q8gh-4j4r-hp3v/GHSA-q8gh-4j4r-hp3v.json index f6eccf23b4b..768b9c22839 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8gh-4j4r-hp3v/GHSA-q8gh-4j4r-hp3v.json +++ b/advisories/unreviewed/2022/05/GHSA-q8gh-4j4r-hp3v/GHSA-q8gh-4j4r-hp3v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q8rp-9m58-mhxh/GHSA-q8rp-9m58-mhxh.json b/advisories/unreviewed/2022/05/GHSA-q8rp-9m58-mhxh/GHSA-q8rp-9m58-mhxh.json index b53a424a4e0..0b7a9793faa 100644 --- a/advisories/unreviewed/2022/05/GHSA-q8rp-9m58-mhxh/GHSA-q8rp-9m58-mhxh.json +++ b/advisories/unreviewed/2022/05/GHSA-q8rp-9m58-mhxh/GHSA-q8rp-9m58-mhxh.json @@ -7,12 +7,8 @@ "CVE-2015-5120" ], "details": "Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5121.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-q9m9-w447-73m9/GHSA-q9m9-w447-73m9.json b/advisories/unreviewed/2022/05/GHSA-q9m9-w447-73m9/GHSA-q9m9-w447-73m9.json index 8557b6815b5..ad49e33e0bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-q9m9-w447-73m9/GHSA-q9m9-w447-73m9.json +++ b/advisories/unreviewed/2022/05/GHSA-q9m9-w447-73m9/GHSA-q9m9-w447-73m9.json @@ -7,12 +7,8 @@ "CVE-2015-0357" ], "details": "Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-3040.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qcf5-882h-xj7h/GHSA-qcf5-882h-xj7h.json b/advisories/unreviewed/2022/05/GHSA-qcf5-882h-xj7h/GHSA-qcf5-882h-xj7h.json index f6e4c5b6926..4ffd3edd04f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcf5-882h-xj7h/GHSA-qcf5-882h-xj7h.json +++ b/advisories/unreviewed/2022/05/GHSA-qcf5-882h-xj7h/GHSA-qcf5-882h-xj7h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qcv9-4m2r-585w/GHSA-qcv9-4m2r-585w.json b/advisories/unreviewed/2022/05/GHSA-qcv9-4m2r-585w/GHSA-qcv9-4m2r-585w.json index d58e3b05799..d4adee3654d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcv9-4m2r-585w/GHSA-qcv9-4m2r-585w.json +++ b/advisories/unreviewed/2022/05/GHSA-qcv9-4m2r-585w/GHSA-qcv9-4m2r-585w.json @@ -7,12 +7,8 @@ "CVE-2014-8500" ], "details": "ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -128,9 +124,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qf23-rh7h-w8wf/GHSA-qf23-rh7h-w8wf.json b/advisories/unreviewed/2022/05/GHSA-qf23-rh7h-w8wf/GHSA-qf23-rh7h-w8wf.json index ec5d0be29cc..6c133911cef 100644 --- a/advisories/unreviewed/2022/05/GHSA-qf23-rh7h-w8wf/GHSA-qf23-rh7h-w8wf.json +++ b/advisories/unreviewed/2022/05/GHSA-qf23-rh7h-w8wf/GHSA-qf23-rh7h-w8wf.json @@ -7,12 +7,8 @@ "CVE-2015-4002" ], "details": "drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 does not ensure that certain length values are sufficiently large, which allows remote attackers to cause a denial of service (system crash or large loop) or possibly execute arbitrary code via a crafted packet, related to the (1) oz_usb_rx and (2) oz_usb_handle_ep_data functions.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qfw7-427c-w3rp/GHSA-qfw7-427c-w3rp.json b/advisories/unreviewed/2022/05/GHSA-qfw7-427c-w3rp/GHSA-qfw7-427c-w3rp.json index d8f586f8894..238233d6d09 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfw7-427c-w3rp/GHSA-qfw7-427c-w3rp.json +++ b/advisories/unreviewed/2022/05/GHSA-qfw7-427c-w3rp/GHSA-qfw7-427c-w3rp.json @@ -7,12 +7,8 @@ "CVE-2015-3979" ], "details": "Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qg5v-7xq3-qwf4/GHSA-qg5v-7xq3-qwf4.json b/advisories/unreviewed/2022/05/GHSA-qg5v-7xq3-qwf4/GHSA-qg5v-7xq3-qwf4.json index 1f9056b0e41..0ad8aee8716 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg5v-7xq3-qwf4/GHSA-qg5v-7xq3-qwf4.json +++ b/advisories/unreviewed/2022/05/GHSA-qg5v-7xq3-qwf4/GHSA-qg5v-7xq3-qwf4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -123,9 +121,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qg6c-wpgx-vgfv/GHSA-qg6c-wpgx-vgfv.json b/advisories/unreviewed/2022/05/GHSA-qg6c-wpgx-vgfv/GHSA-qg6c-wpgx-vgfv.json index 34955560656..29e613a3c1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qg6c-wpgx-vgfv/GHSA-qg6c-wpgx-vgfv.json +++ b/advisories/unreviewed/2022/05/GHSA-qg6c-wpgx-vgfv/GHSA-qg6c-wpgx-vgfv.json @@ -7,12 +7,8 @@ "CVE-2015-7015" ], "details": "Heap-based buffer overflow in the DNS client library in configd in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code via a crafted app that sends a spoofed configd response to a client.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qgj6-v74v-wpqp/GHSA-qgj6-v74v-wpqp.json b/advisories/unreviewed/2022/05/GHSA-qgj6-v74v-wpqp/GHSA-qgj6-v74v-wpqp.json index 7fd67fbb8b1..33b15856d78 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgj6-v74v-wpqp/GHSA-qgj6-v74v-wpqp.json +++ b/advisories/unreviewed/2022/05/GHSA-qgj6-v74v-wpqp/GHSA-qgj6-v74v-wpqp.json @@ -7,12 +7,8 @@ "CVE-2015-6755" ], "details": "The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a DOM tree insertion in certain cases where a parent node no longer contains a child node, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qh2p-g6jp-838m/GHSA-qh2p-g6jp-838m.json b/advisories/unreviewed/2022/05/GHSA-qh2p-g6jp-838m/GHSA-qh2p-g6jp-838m.json index b8df1735ccf..c0bd9072bb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh2p-g6jp-838m/GHSA-qh2p-g6jp-838m.json +++ b/advisories/unreviewed/2022/05/GHSA-qh2p-g6jp-838m/GHSA-qh2p-g6jp-838m.json @@ -7,12 +7,8 @@ "CVE-2015-6276" ], "details": "Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which allows remote attackers to obtain cleartext versions of HTTPS traffic or spoof devices via a direct request to the certificate directory, aka Bug ID CSCuu63501.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qjm4-qw2v-5phj/GHSA-qjm4-qw2v-5phj.json b/advisories/unreviewed/2022/05/GHSA-qjm4-qw2v-5phj/GHSA-qjm4-qw2v-5phj.json index 44fb72c7cf8..9c647fcb89c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjm4-qw2v-5phj/GHSA-qjm4-qw2v-5phj.json +++ b/advisories/unreviewed/2022/05/GHSA-qjm4-qw2v-5phj/GHSA-qjm4-qw2v-5phj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qm5g-rprh-qhg3/GHSA-qm5g-rprh-qhg3.json b/advisories/unreviewed/2022/05/GHSA-qm5g-rprh-qhg3/GHSA-qm5g-rprh-qhg3.json index 1062900a574..6ab74ffd57f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm5g-rprh-qhg3/GHSA-qm5g-rprh-qhg3.json +++ b/advisories/unreviewed/2022/05/GHSA-qm5g-rprh-qhg3/GHSA-qm5g-rprh-qhg3.json @@ -7,12 +7,8 @@ "CVE-2015-0502" ], "details": "Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1 and 8.2 allows remote attackers to affect integrity via unknown vectors related to Portal Framework.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qm6h-hvwq-4xp6/GHSA-qm6h-hvwq-4xp6.json b/advisories/unreviewed/2022/05/GHSA-qm6h-hvwq-4xp6/GHSA-qm6h-hvwq-4xp6.json index 3cf40c23c42..b3db20f5a38 100644 --- a/advisories/unreviewed/2022/05/GHSA-qm6h-hvwq-4xp6/GHSA-qm6h-hvwq-4xp6.json +++ b/advisories/unreviewed/2022/05/GHSA-qm6h-hvwq-4xp6/GHSA-qm6h-hvwq-4xp6.json @@ -7,12 +7,8 @@ "CVE-2012-2362" ], "details": "Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qp55-3wrf-jx7r/GHSA-qp55-3wrf-jx7r.json b/advisories/unreviewed/2022/05/GHSA-qp55-3wrf-jx7r/GHSA-qp55-3wrf-jx7r.json index e99d4ef392e..a7d2e5af919 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp55-3wrf-jx7r/GHSA-qp55-3wrf-jx7r.json +++ b/advisories/unreviewed/2022/05/GHSA-qp55-3wrf-jx7r/GHSA-qp55-3wrf-jx7r.json @@ -7,12 +7,8 @@ "CVE-2015-5925" ], "details": "The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5926.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qqmj-3x2j-j469/GHSA-qqmj-3x2j-j469.json b/advisories/unreviewed/2022/05/GHSA-qqmj-3x2j-j469/GHSA-qqmj-3x2j-j469.json index 1fa17eb80c4..d0c92bf130a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqmj-3x2j-j469/GHSA-qqmj-3x2j-j469.json +++ b/advisories/unreviewed/2022/05/GHSA-qqmj-3x2j-j469/GHSA-qqmj-3x2j-j469.json @@ -7,12 +7,8 @@ "CVE-2015-1389" ], "details": "Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary web script or HTML via the username parameter to tips/tipsLoginSubmit.action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qr46-rwcx-5cjc/GHSA-qr46-rwcx-5cjc.json b/advisories/unreviewed/2022/05/GHSA-qr46-rwcx-5cjc/GHSA-qr46-rwcx-5cjc.json index 3549c2c9bfa..29010c4edeb 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr46-rwcx-5cjc/GHSA-qr46-rwcx-5cjc.json +++ b/advisories/unreviewed/2022/05/GHSA-qr46-rwcx-5cjc/GHSA-qr46-rwcx-5cjc.json @@ -7,12 +7,8 @@ "CVE-2015-0473" ], "details": "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control MOS 12.1.0.5 and 12.1.0.6 allows remote attackers to affect integrity via unknown vectors related to My Oracle Support Plugin.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qr93-pmmq-gcpm/GHSA-qr93-pmmq-gcpm.json b/advisories/unreviewed/2022/05/GHSA-qr93-pmmq-gcpm/GHSA-qr93-pmmq-gcpm.json index 963660419bb..d098ea169ba 100644 --- a/advisories/unreviewed/2022/05/GHSA-qr93-pmmq-gcpm/GHSA-qr93-pmmq-gcpm.json +++ b/advisories/unreviewed/2022/05/GHSA-qr93-pmmq-gcpm/GHSA-qr93-pmmq-gcpm.json @@ -7,12 +7,8 @@ "CVE-2015-0482" ], "details": "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.2.0 and 12.1.3.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to WLS-WebServices.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qrm5-m79m-cj3j/GHSA-qrm5-m79m-cj3j.json b/advisories/unreviewed/2022/05/GHSA-qrm5-m79m-cj3j/GHSA-qrm5-m79m-cj3j.json index c41449c81e0..ab4e53c83f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrm5-m79m-cj3j/GHSA-qrm5-m79m-cj3j.json +++ b/advisories/unreviewed/2022/05/GHSA-qrm5-m79m-cj3j/GHSA-qrm5-m79m-cj3j.json @@ -7,12 +7,8 @@ "CVE-2015-4194" ], "details": "The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether the username exists or corresponds to a privileged account, which allows remote attackers to enumerate account names and obtain sensitive information via a series of requests, aka Bug ID CSCuf28861.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrq4-w8rp-x888/GHSA-qrq4-w8rp-x888.json b/advisories/unreviewed/2022/05/GHSA-qrq4-w8rp-x888/GHSA-qrq4-w8rp-x888.json index 6478952cedc..e89c784e2e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrq4-w8rp-x888/GHSA-qrq4-w8rp-x888.json +++ b/advisories/unreviewed/2022/05/GHSA-qrq4-w8rp-x888/GHSA-qrq4-w8rp-x888.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qrwf-2h39-fm5c/GHSA-qrwf-2h39-fm5c.json b/advisories/unreviewed/2022/05/GHSA-qrwf-2h39-fm5c/GHSA-qrwf-2h39-fm5c.json index 3ecd7cee5ad..a52d5ad5d52 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrwf-2h39-fm5c/GHSA-qrwf-2h39-fm5c.json +++ b/advisories/unreviewed/2022/05/GHSA-qrwf-2h39-fm5c/GHSA-qrwf-2h39-fm5c.json @@ -7,12 +7,8 @@ "CVE-2015-7035" ], "details": "Apple Mac EFI before 2015-002, as used in OS X before 10.11.1 and other products, mishandles arguments, which allows attackers to reach \"unused\" functions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw2v-r7p6-9wjv/GHSA-qw2v-r7p6-9wjv.json b/advisories/unreviewed/2022/05/GHSA-qw2v-r7p6-9wjv/GHSA-qw2v-r7p6-9wjv.json index 1e859471746..158c29402d9 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw2v-r7p6-9wjv/GHSA-qw2v-r7p6-9wjv.json +++ b/advisories/unreviewed/2022/05/GHSA-qw2v-r7p6-9wjv/GHSA-qw2v-r7p6-9wjv.json @@ -7,12 +7,8 @@ "CVE-2013-5094" ], "details": "Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HTML via the cert_cn cookie parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qw4x-7w7g-p36r/GHSA-qw4x-7w7g-p36r.json b/advisories/unreviewed/2022/05/GHSA-qw4x-7w7g-p36r/GHSA-qw4x-7w7g-p36r.json index bc99b788e84..a64dd9a4ae6 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw4x-7w7g-p36r/GHSA-qw4x-7w7g-p36r.json +++ b/advisories/unreviewed/2022/05/GHSA-qw4x-7w7g-p36r/GHSA-qw4x-7w7g-p36r.json @@ -7,12 +7,8 @@ "CVE-2015-5782" ], "details": "ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecified data structure, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwm3-j3m5-fj24/GHSA-qwm3-j3m5-fj24.json b/advisories/unreviewed/2022/05/GHSA-qwm3-j3m5-fj24/GHSA-qwm3-j3m5-fj24.json index 8bcc578629f..5d78dac3156 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwm3-j3m5-fj24/GHSA-qwm3-j3m5-fj24.json +++ b/advisories/unreviewed/2022/05/GHSA-qwm3-j3m5-fj24/GHSA-qwm3-j3m5-fj24.json @@ -7,12 +7,8 @@ "CVE-2015-1238" ], "details": "Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-qwq3-64hp-77x6/GHSA-qwq3-64hp-77x6.json b/advisories/unreviewed/2022/05/GHSA-qwq3-64hp-77x6/GHSA-qwq3-64hp-77x6.json index 1db64b61808..ae49a02cec3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qwq3-64hp-77x6/GHSA-qwq3-64hp-77x6.json +++ b/advisories/unreviewed/2022/05/GHSA-qwq3-64hp-77x6/GHSA-qwq3-64hp-77x6.json @@ -7,12 +7,8 @@ "CVE-2014-8015" ], "details": "The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qxj4-ch7h-mvj4/GHSA-qxj4-ch7h-mvj4.json b/advisories/unreviewed/2022/05/GHSA-qxj4-ch7h-mvj4/GHSA-qxj4-ch7h-mvj4.json index 84154d030cf..de4c0c9d43d 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxj4-ch7h-mvj4/GHSA-qxj4-ch7h-mvj4.json +++ b/advisories/unreviewed/2022/05/GHSA-qxj4-ch7h-mvj4/GHSA-qxj4-ch7h-mvj4.json @@ -7,12 +7,8 @@ "CVE-2015-5927" ], "details": "FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5942.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r224-hwf4-6cww/GHSA-r224-hwf4-6cww.json b/advisories/unreviewed/2022/05/GHSA-r224-hwf4-6cww/GHSA-r224-hwf4-6cww.json index 4fb8a2e2bd4..74bbc39cc8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-r224-hwf4-6cww/GHSA-r224-hwf4-6cww.json +++ b/advisories/unreviewed/2022/05/GHSA-r224-hwf4-6cww/GHSA-r224-hwf4-6cww.json @@ -7,12 +7,8 @@ "CVE-2015-6287" ], "details": "Cisco Web Security Appliance (WSA) 8.0.6-078 and 8.0.6-115 allows remote attackers to cause a denial of service (service outage) via a flood of TCP traffic that leads to DNS resolution delays, aka Bug IDs CSCur32005 and CSCur07907.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r2jc-v6rc-4m52/GHSA-r2jc-v6rc-4m52.json b/advisories/unreviewed/2022/05/GHSA-r2jc-v6rc-4m52/GHSA-r2jc-v6rc-4m52.json index 6dbd7cbb3f6..9a1e0461ba2 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2jc-v6rc-4m52/GHSA-r2jc-v6rc-4m52.json +++ b/advisories/unreviewed/2022/05/GHSA-r2jc-v6rc-4m52/GHSA-r2jc-v6rc-4m52.json @@ -7,12 +7,8 @@ "CVE-2015-1978" ], "details": "Cross-site scripting (XSS) vulnerability in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r2xf-97vr-8x63/GHSA-r2xf-97vr-8x63.json b/advisories/unreviewed/2022/05/GHSA-r2xf-97vr-8x63/GHSA-r2xf-97vr-8x63.json index bc2d7c61d5c..f371dd83721 100644 --- a/advisories/unreviewed/2022/05/GHSA-r2xf-97vr-8x63/GHSA-r2xf-97vr-8x63.json +++ b/advisories/unreviewed/2022/05/GHSA-r2xf-97vr-8x63/GHSA-r2xf-97vr-8x63.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r328-753q-m689/GHSA-r328-753q-m689.json b/advisories/unreviewed/2022/05/GHSA-r328-753q-m689/GHSA-r328-753q-m689.json index ed48d7004d7..d5958cb9f39 100644 --- a/advisories/unreviewed/2022/05/GHSA-r328-753q-m689/GHSA-r328-753q-m689.json +++ b/advisories/unreviewed/2022/05/GHSA-r328-753q-m689/GHSA-r328-753q-m689.json @@ -7,12 +7,8 @@ "CVE-2013-4567" ], "details": "Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a \\b (backspace) character in CSS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r47q-gp6w-mwhx/GHSA-r47q-gp6w-mwhx.json b/advisories/unreviewed/2022/05/GHSA-r47q-gp6w-mwhx/GHSA-r47q-gp6w-mwhx.json index bc58aff36ab..e13be9a2ab8 100644 --- a/advisories/unreviewed/2022/05/GHSA-r47q-gp6w-mwhx/GHSA-r47q-gp6w-mwhx.json +++ b/advisories/unreviewed/2022/05/GHSA-r47q-gp6w-mwhx/GHSA-r47q-gp6w-mwhx.json @@ -7,12 +7,8 @@ "CVE-2015-1266" ], "details": "content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass intended access restrictions via a similar URL, as demonstrated by use of http://gpu when there is a WebUI class for handling chrome://gpu requests.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -64,9 +60,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r55g-hwj5-8wmc/GHSA-r55g-hwj5-8wmc.json b/advisories/unreviewed/2022/05/GHSA-r55g-hwj5-8wmc/GHSA-r55g-hwj5-8wmc.json index bee2e4f0a67..dceeae4800f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r55g-hwj5-8wmc/GHSA-r55g-hwj5-8wmc.json +++ b/advisories/unreviewed/2022/05/GHSA-r55g-hwj5-8wmc/GHSA-r55g-hwj5-8wmc.json @@ -7,12 +7,8 @@ "CVE-2015-0500" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -44,9 +40,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r5pq-r3w3-76q7/GHSA-r5pq-r3w3-76q7.json b/advisories/unreviewed/2022/05/GHSA-r5pq-r3w3-76q7/GHSA-r5pq-r3w3-76q7.json index 18c56b17c09..dbe3d79b952 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5pq-r3w3-76q7/GHSA-r5pq-r3w3-76q7.json +++ b/advisories/unreviewed/2022/05/GHSA-r5pq-r3w3-76q7/GHSA-r5pq-r3w3-76q7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r5xx-rrgx-p246/GHSA-r5xx-rrgx-p246.json b/advisories/unreviewed/2022/05/GHSA-r5xx-rrgx-p246/GHSA-r5xx-rrgx-p246.json index d11b520576d..0d153c1e2a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r5xx-rrgx-p246/GHSA-r5xx-rrgx-p246.json +++ b/advisories/unreviewed/2022/05/GHSA-r5xx-rrgx-p246/GHSA-r5xx-rrgx-p246.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r738-34gj-r3hp/GHSA-r738-34gj-r3hp.json b/advisories/unreviewed/2022/05/GHSA-r738-34gj-r3hp/GHSA-r738-34gj-r3hp.json index 9ea19a991af..143a84d3ff5 100644 --- a/advisories/unreviewed/2022/05/GHSA-r738-34gj-r3hp/GHSA-r738-34gj-r3hp.json +++ b/advisories/unreviewed/2022/05/GHSA-r738-34gj-r3hp/GHSA-r738-34gj-r3hp.json @@ -7,12 +7,8 @@ "CVE-2015-2064" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in DLGuard 5, 4.6, and 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) c, or (3) redirect parameter to index.php or (4) search field (searchTerm parameter) in the main page.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r7qm-f8h2-jq46/GHSA-r7qm-f8h2-jq46.json b/advisories/unreviewed/2022/05/GHSA-r7qm-f8h2-jq46/GHSA-r7qm-f8h2-jq46.json index d4394afbed6..3e3c3c2a9fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7qm-f8h2-jq46/GHSA-r7qm-f8h2-jq46.json +++ b/advisories/unreviewed/2022/05/GHSA-r7qm-f8h2-jq46/GHSA-r7qm-f8h2-jq46.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r7wf-7qgj-jjhc/GHSA-r7wf-7qgj-jjhc.json b/advisories/unreviewed/2022/05/GHSA-r7wf-7qgj-jjhc/GHSA-r7wf-7qgj-jjhc.json index 887046859aa..1845cc96470 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7wf-7qgj-jjhc/GHSA-r7wf-7qgj-jjhc.json +++ b/advisories/unreviewed/2022/05/GHSA-r7wf-7qgj-jjhc/GHSA-r7wf-7qgj-jjhc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8g9-x5r3-7rc6/GHSA-r8g9-x5r3-7rc6.json b/advisories/unreviewed/2022/05/GHSA-r8g9-x5r3-7rc6/GHSA-r8g9-x5r3-7rc6.json index 7d776db85d2..0e2cb6ddb28 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8g9-x5r3-7rc6/GHSA-r8g9-x5r3-7rc6.json +++ b/advisories/unreviewed/2022/05/GHSA-r8g9-x5r3-7rc6/GHSA-r8g9-x5r3-7rc6.json @@ -7,12 +7,8 @@ "CVE-2015-2728" ], "details": "The IndexedDatabaseManager class in the IndexedDB implementation in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 misinterprets an unspecified IDBDatabase field as a pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors, related to a \"type confusion\" issue.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -84,9 +80,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r8m3-47wj-g6r4/GHSA-r8m3-47wj-g6r4.json b/advisories/unreviewed/2022/05/GHSA-r8m3-47wj-g6r4/GHSA-r8m3-47wj-g6r4.json index a3319722b40..0923fbe260f 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8m3-47wj-g6r4/GHSA-r8m3-47wj-g6r4.json +++ b/advisories/unreviewed/2022/05/GHSA-r8m3-47wj-g6r4/GHSA-r8m3-47wj-g6r4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r8vw-rp4x-jw2v/GHSA-r8vw-rp4x-jw2v.json b/advisories/unreviewed/2022/05/GHSA-r8vw-rp4x-jw2v/GHSA-r8vw-rp4x-jw2v.json index 9d46bddde8f..52aa9f69da4 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8vw-rp4x-jw2v/GHSA-r8vw-rp4x-jw2v.json +++ b/advisories/unreviewed/2022/05/GHSA-r8vw-rp4x-jw2v/GHSA-r8vw-rp4x-jw2v.json @@ -7,12 +7,8 @@ "CVE-2015-0479" ], "details": "Unspecified vulnerability in the XDK and XDB - XML Database component in Oracle Database Server 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect availability via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r9jq-vwjm-mmc4/GHSA-r9jq-vwjm-mmc4.json b/advisories/unreviewed/2022/05/GHSA-r9jq-vwjm-mmc4/GHSA-r9jq-vwjm-mmc4.json index 109bc8e6e29..6d3323ddeab 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9jq-vwjm-mmc4/GHSA-r9jq-vwjm-mmc4.json +++ b/advisories/unreviewed/2022/05/GHSA-r9jq-vwjm-mmc4/GHSA-r9jq-vwjm-mmc4.json @@ -7,12 +7,8 @@ "CVE-2015-4302" ], "details": "The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CSCuu25390.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-r9pf-j5rf-wr57/GHSA-r9pf-j5rf-wr57.json b/advisories/unreviewed/2022/05/GHSA-r9pf-j5rf-wr57/GHSA-r9pf-j5rf-wr57.json index 3a80651bf6c..6edbd4d539b 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9pf-j5rf-wr57/GHSA-r9pf-j5rf-wr57.json +++ b/advisories/unreviewed/2022/05/GHSA-r9pf-j5rf-wr57/GHSA-r9pf-j5rf-wr57.json @@ -7,12 +7,8 @@ "CVE-2015-0356" ], "details": "Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code by leveraging an unspecified \"type confusion.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rc98-9q2q-438r/GHSA-rc98-9q2q-438r.json b/advisories/unreviewed/2022/05/GHSA-rc98-9q2q-438r/GHSA-rc98-9q2q-438r.json index 4011855c506..008773407d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc98-9q2q-438r/GHSA-rc98-9q2q-438r.json +++ b/advisories/unreviewed/2022/05/GHSA-rc98-9q2q-438r/GHSA-rc98-9q2q-438r.json @@ -7,12 +7,8 @@ "CVE-2015-3661" ], "details": "QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rcgv-75hg-vhm9/GHSA-rcgv-75hg-vhm9.json b/advisories/unreviewed/2022/05/GHSA-rcgv-75hg-vhm9/GHSA-rcgv-75hg-vhm9.json index 908c617c3dc..8b78a90282b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rcgv-75hg-vhm9/GHSA-rcgv-75hg-vhm9.json +++ b/advisories/unreviewed/2022/05/GHSA-rcgv-75hg-vhm9/GHSA-rcgv-75hg-vhm9.json @@ -7,12 +7,8 @@ "CVE-2013-6877" ], "details": "Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to execute arbitrary code via a long string in the TRACKID element of an RMP file, a different vulnerability than CVE-2013-7260.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rf43-wp3r-hwg3/GHSA-rf43-wp3r-hwg3.json b/advisories/unreviewed/2022/05/GHSA-rf43-wp3r-hwg3/GHSA-rf43-wp3r-hwg3.json index 128fe589a7b..b465b470569 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf43-wp3r-hwg3/GHSA-rf43-wp3r-hwg3.json +++ b/advisories/unreviewed/2022/05/GHSA-rf43-wp3r-hwg3/GHSA-rf43-wp3r-hwg3.json @@ -7,12 +7,8 @@ "CVE-2013-7242" ], "details": "SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rgqp-m6m6-56w9/GHSA-rgqp-m6m6-56w9.json b/advisories/unreviewed/2022/05/GHSA-rgqp-m6m6-56w9/GHSA-rgqp-m6m6-56w9.json index 2b5523f7db9..5e5996eb7a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgqp-m6m6-56w9/GHSA-rgqp-m6m6-56w9.json +++ b/advisories/unreviewed/2022/05/GHSA-rgqp-m6m6-56w9/GHSA-rgqp-m6m6-56w9.json @@ -7,12 +7,8 @@ "CVE-2015-2658" ], "details": "Unspecified vulnerability in the Web Cache component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality via vectors related to SSL/TLS Support.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rgvc-cf9g-ch6w/GHSA-rgvc-cf9g-ch6w.json b/advisories/unreviewed/2022/05/GHSA-rgvc-cf9g-ch6w/GHSA-rgvc-cf9g-ch6w.json index 1771d06ffa1..2edaf40252f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rgvc-cf9g-ch6w/GHSA-rgvc-cf9g-ch6w.json +++ b/advisories/unreviewed/2022/05/GHSA-rgvc-cf9g-ch6w/GHSA-rgvc-cf9g-ch6w.json @@ -7,12 +7,8 @@ "CVE-2015-2646" ], "details": "Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform: 11.1.0.1; EM Plugin for DB: 12.1.0.5, 12.1.0.6, 12.1.0.7; EM DB Control: 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote attackers to affect integrity via unknown vectors related to Content Management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rhfx-7hwf-9qxj/GHSA-rhfx-7hwf-9qxj.json b/advisories/unreviewed/2022/05/GHSA-rhfx-7hwf-9qxj/GHSA-rhfx-7hwf-9qxj.json index 2966a1c9e4e..8892ee5b3ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-rhfx-7hwf-9qxj/GHSA-rhfx-7hwf-9qxj.json +++ b/advisories/unreviewed/2022/05/GHSA-rhfx-7hwf-9qxj/GHSA-rhfx-7hwf-9qxj.json @@ -7,12 +7,8 @@ "CVE-2015-5965" ], "details": "The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rj2h-jjjq-4f7r/GHSA-rj2h-jjjq-4f7r.json b/advisories/unreviewed/2022/05/GHSA-rj2h-jjjq-4f7r/GHSA-rj2h-jjjq-4f7r.json index 70dd4ad15b2..a0320e6fe50 100644 --- a/advisories/unreviewed/2022/05/GHSA-rj2h-jjjq-4f7r/GHSA-rj2h-jjjq-4f7r.json +++ b/advisories/unreviewed/2022/05/GHSA-rj2h-jjjq-4f7r/GHSA-rj2h-jjjq-4f7r.json @@ -7,12 +7,8 @@ "CVE-2014-7935" ], "details": "Use-after-free vulnerability in browser/speech/tts_message_filter.cc in the Speech implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving utterances from a closed tab.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rp24-47cm-wf2p/GHSA-rp24-47cm-wf2p.json b/advisories/unreviewed/2022/05/GHSA-rp24-47cm-wf2p/GHSA-rp24-47cm-wf2p.json index e801915c1a2..477c2bd7c23 100644 --- a/advisories/unreviewed/2022/05/GHSA-rp24-47cm-wf2p/GHSA-rp24-47cm-wf2p.json +++ b/advisories/unreviewed/2022/05/GHSA-rp24-47cm-wf2p/GHSA-rp24-47cm-wf2p.json @@ -7,12 +7,8 @@ "CVE-2015-6999" ], "details": "The OCSP client in Apple iOS before 9.1 does not check for certificate expiry, which allows remote attackers to spoof a valid certificate by leveraging access to a revoked certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rq65-g62r-7h5f/GHSA-rq65-g62r-7h5f.json b/advisories/unreviewed/2022/05/GHSA-rq65-g62r-7h5f/GHSA-rq65-g62r-7h5f.json index a00c7079d74..26caaca0896 100644 --- a/advisories/unreviewed/2022/05/GHSA-rq65-g62r-7h5f/GHSA-rq65-g62r-7h5f.json +++ b/advisories/unreviewed/2022/05/GHSA-rq65-g62r-7h5f/GHSA-rq65-g62r-7h5f.json @@ -7,12 +7,8 @@ "CVE-2015-7008" ], "details": "FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rr27-273m-v696/GHSA-rr27-273m-v696.json b/advisories/unreviewed/2022/05/GHSA-rr27-273m-v696/GHSA-rr27-273m-v696.json index 80fc0e48d0f..1374718d73b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr27-273m-v696/GHSA-rr27-273m-v696.json +++ b/advisories/unreviewed/2022/05/GHSA-rr27-273m-v696/GHSA-rr27-273m-v696.json @@ -7,12 +7,8 @@ "CVE-2015-0331" ], "details": "Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrp5-xgfv-3935/GHSA-rrp5-xgfv-3935.json b/advisories/unreviewed/2022/05/GHSA-rrp5-xgfv-3935/GHSA-rrp5-xgfv-3935.json index 86041d58138..a96a67f2a62 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrp5-xgfv-3935/GHSA-rrp5-xgfv-3935.json +++ b/advisories/unreviewed/2022/05/GHSA-rrp5-xgfv-3935/GHSA-rrp5-xgfv-3935.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rrxx-c69g-x9hr/GHSA-rrxx-c69g-x9hr.json b/advisories/unreviewed/2022/05/GHSA-rrxx-c69g-x9hr/GHSA-rrxx-c69g-x9hr.json index 1f02e54bfd1..977c603c3c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-rrxx-c69g-x9hr/GHSA-rrxx-c69g-x9hr.json +++ b/advisories/unreviewed/2022/05/GHSA-rrxx-c69g-x9hr/GHSA-rrxx-c69g-x9hr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rvc8-rj9h-p9gx/GHSA-rvc8-rj9h-p9gx.json b/advisories/unreviewed/2022/05/GHSA-rvc8-rj9h-p9gx/GHSA-rvc8-rj9h-p9gx.json index a24c5f0372e..7486e171fb7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvc8-rj9h-p9gx/GHSA-rvc8-rj9h-p9gx.json +++ b/advisories/unreviewed/2022/05/GHSA-rvc8-rj9h-p9gx/GHSA-rvc8-rj9h-p9gx.json @@ -7,12 +7,8 @@ "CVE-2015-3112" ], "details": "Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rvwq-c757-x9gx/GHSA-rvwq-c757-x9gx.json b/advisories/unreviewed/2022/05/GHSA-rvwq-c757-x9gx/GHSA-rvwq-c757-x9gx.json index b17415a6929..f78c2fa85f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rvwq-c757-x9gx/GHSA-rvwq-c757-x9gx.json +++ b/advisories/unreviewed/2022/05/GHSA-rvwq-c757-x9gx/GHSA-rvwq-c757-x9gx.json @@ -7,12 +7,8 @@ "CVE-2015-3105" ], "details": "Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rw9x-rggx-hc52/GHSA-rw9x-rggx-hc52.json b/advisories/unreviewed/2022/05/GHSA-rw9x-rggx-hc52/GHSA-rw9x-rggx-hc52.json index 22b60812b24..4ac1aa5d1ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw9x-rggx-hc52/GHSA-rw9x-rggx-hc52.json +++ b/advisories/unreviewed/2022/05/GHSA-rw9x-rggx-hc52/GHSA-rw9x-rggx-hc52.json @@ -7,12 +7,8 @@ "CVE-2015-5758" ], "details": "ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-rwpv-8h6r-wrrr/GHSA-rwpv-8h6r-wrrr.json b/advisories/unreviewed/2022/05/GHSA-rwpv-8h6r-wrrr/GHSA-rwpv-8h6r-wrrr.json index 4e84a01acbc..e749aa93c3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rwpv-8h6r-wrrr/GHSA-rwpv-8h6r-wrrr.json +++ b/advisories/unreviewed/2022/05/GHSA-rwpv-8h6r-wrrr/GHSA-rwpv-8h6r-wrrr.json @@ -7,12 +7,8 @@ "CVE-2015-4217" ], "details": "The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH host keys across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a private key from another installation, aka Bug IDs CSCus29681, CSCuu95676, and CSCuu96601.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rx99-8mc5-222v/GHSA-rx99-8mc5-222v.json b/advisories/unreviewed/2022/05/GHSA-rx99-8mc5-222v/GHSA-rx99-8mc5-222v.json index 6a00d7356a0..fa75b582f0d 100644 --- a/advisories/unreviewed/2022/05/GHSA-rx99-8mc5-222v/GHSA-rx99-8mc5-222v.json +++ b/advisories/unreviewed/2022/05/GHSA-rx99-8mc5-222v/GHSA-rx99-8mc5-222v.json @@ -7,12 +7,8 @@ "CVE-2015-1259" ], "details": "PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v2p7-mrrm-w56p/GHSA-v2p7-mrrm-w56p.json b/advisories/unreviewed/2022/05/GHSA-v2p7-mrrm-w56p/GHSA-v2p7-mrrm-w56p.json index 1e7b2acb13f..4f512cb8e81 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2p7-mrrm-w56p/GHSA-v2p7-mrrm-w56p.json +++ b/advisories/unreviewed/2022/05/GHSA-v2p7-mrrm-w56p/GHSA-v2p7-mrrm-w56p.json @@ -7,12 +7,8 @@ "CVE-2013-4258" ], "details": "Format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to syslog.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v2x4-6r33-27c2/GHSA-v2x4-6r33-27c2.json b/advisories/unreviewed/2022/05/GHSA-v2x4-6r33-27c2/GHSA-v2x4-6r33-27c2.json index 8a0b5d709d5..4a96dcc2684 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2x4-6r33-27c2/GHSA-v2x4-6r33-27c2.json +++ b/advisories/unreviewed/2022/05/GHSA-v2x4-6r33-27c2/GHSA-v2x4-6r33-27c2.json @@ -7,12 +7,8 @@ "CVE-2014-7823" ], "details": "The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v3gx-624q-2q65/GHSA-v3gx-624q-2q65.json b/advisories/unreviewed/2022/05/GHSA-v3gx-624q-2q65/GHSA-v3gx-624q-2q65.json index 0876adc0820..663f00eca19 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3gx-624q-2q65/GHSA-v3gx-624q-2q65.json +++ b/advisories/unreviewed/2022/05/GHSA-v3gx-624q-2q65/GHSA-v3gx-624q-2q65.json @@ -7,12 +7,8 @@ "CVE-2015-3103" ], "details": "Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3106 and CVE-2015-3107.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v3q7-q964-x82m/GHSA-v3q7-q964-x82m.json b/advisories/unreviewed/2022/05/GHSA-v3q7-q964-x82m/GHSA-v3q7-q964-x82m.json index 64720433fd6..402abbd037f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v3q7-q964-x82m/GHSA-v3q7-q964-x82m.json +++ b/advisories/unreviewed/2022/05/GHSA-v3q7-q964-x82m/GHSA-v3q7-q964-x82m.json @@ -7,12 +7,8 @@ "CVE-2015-4003" ], "details": "The oz_usb_handle_ep_data function in drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via a crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v4px-7mr8-mhr3/GHSA-v4px-7mr8-mhr3.json b/advisories/unreviewed/2022/05/GHSA-v4px-7mr8-mhr3/GHSA-v4px-7mr8-mhr3.json index 0b6abaefced..385b487445b 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4px-7mr8-mhr3/GHSA-v4px-7mr8-mhr3.json +++ b/advisories/unreviewed/2022/05/GHSA-v4px-7mr8-mhr3/GHSA-v4px-7mr8-mhr3.json @@ -7,12 +7,8 @@ "CVE-2015-0453" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote attackers to affect confidentiality via vectors related to PORTAL.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5jw-2c5m-f8hv/GHSA-v5jw-2c5m-f8hv.json b/advisories/unreviewed/2022/05/GHSA-v5jw-2c5m-f8hv/GHSA-v5jw-2c5m-f8hv.json index f8e449a470a..d80d7d0d7b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5jw-2c5m-f8hv/GHSA-v5jw-2c5m-f8hv.json +++ b/advisories/unreviewed/2022/05/GHSA-v5jw-2c5m-f8hv/GHSA-v5jw-2c5m-f8hv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -87,9 +85,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5mp-695q-547x/GHSA-v5mp-695q-547x.json b/advisories/unreviewed/2022/05/GHSA-v5mp-695q-547x/GHSA-v5mp-695q-547x.json index 3859e8b78e2..05db692545a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5mp-695q-547x/GHSA-v5mp-695q-547x.json +++ b/advisories/unreviewed/2022/05/GHSA-v5mp-695q-547x/GHSA-v5mp-695q-547x.json @@ -7,12 +7,8 @@ "CVE-2015-0483" ], "details": "Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect integrity via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v5x3-2xr4-f8xj/GHSA-v5x3-2xr4-f8xj.json b/advisories/unreviewed/2022/05/GHSA-v5x3-2xr4-f8xj/GHSA-v5x3-2xr4-f8xj.json index 4032d23ec4d..52bc416deb0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5x3-2xr4-f8xj/GHSA-v5x3-2xr4-f8xj.json +++ b/advisories/unreviewed/2022/05/GHSA-v5x3-2xr4-f8xj/GHSA-v5x3-2xr4-f8xj.json @@ -7,12 +7,8 @@ "CVE-2015-4198" ], "details": "Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified HTTP header, aka Bug ID CSCuu24409.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v62p-hc6h-7mcr/GHSA-v62p-hc6h-7mcr.json b/advisories/unreviewed/2022/05/GHSA-v62p-hc6h-7mcr/GHSA-v62p-hc6h-7mcr.json index ee6a945502c..dd94ab75da7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v62p-hc6h-7mcr/GHSA-v62p-hc6h-7mcr.json +++ b/advisories/unreviewed/2022/05/GHSA-v62p-hc6h-7mcr/GHSA-v62p-hc6h-7mcr.json @@ -7,12 +7,8 @@ "CVE-2014-0558" ], "details": "Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0564.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v69f-xfrj-cq2p/GHSA-v69f-xfrj-cq2p.json b/advisories/unreviewed/2022/05/GHSA-v69f-xfrj-cq2p/GHSA-v69f-xfrj-cq2p.json index 8d1bef024d9..3211e013fb9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v69f-xfrj-cq2p/GHSA-v69f-xfrj-cq2p.json +++ b/advisories/unreviewed/2022/05/GHSA-v69f-xfrj-cq2p/GHSA-v69f-xfrj-cq2p.json @@ -7,12 +7,8 @@ "CVE-2015-6295" ], "details": "Cisco NX-OS 6.1(2)I3(4) and 7.0(3)I1(1) on Nexus 9000 (N9K) devices allows remote attackers to cause a denial of service (CPU consumption or control-plane instability) or trigger unintended traffic forwarding via a Layer 2 packet with a reserved VLAN number, aka Bug ID CSCuw13560.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6wq-m5xf-2r3c/GHSA-v6wq-m5xf-2r3c.json b/advisories/unreviewed/2022/05/GHSA-v6wq-m5xf-2r3c/GHSA-v6wq-m5xf-2r3c.json index 932142027c2..cff4d92a3ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6wq-m5xf-2r3c/GHSA-v6wq-m5xf-2r3c.json +++ b/advisories/unreviewed/2022/05/GHSA-v6wq-m5xf-2r3c/GHSA-v6wq-m5xf-2r3c.json @@ -7,12 +7,8 @@ "CVE-2014-7928" ], "details": "hydrogen.cc in Google V8, as used Google Chrome before 40.0.2214.91, does not properly handle arrays with holes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers an array copy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v79w-qm6g-qq2g/GHSA-v79w-qm6g-qq2g.json b/advisories/unreviewed/2022/05/GHSA-v79w-qm6g-qq2g/GHSA-v79w-qm6g-qq2g.json index f5033838aa5..b27075a58de 100644 --- a/advisories/unreviewed/2022/05/GHSA-v79w-qm6g-qq2g/GHSA-v79w-qm6g-qq2g.json +++ b/advisories/unreviewed/2022/05/GHSA-v79w-qm6g-qq2g/GHSA-v79w-qm6g-qq2g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8c7-r83c-4vvm/GHSA-v8c7-r83c-4vvm.json b/advisories/unreviewed/2022/05/GHSA-v8c7-r83c-4vvm/GHSA-v8c7-r83c-4vvm.json index 6e3a9d5958a..901e69a55ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8c7-r83c-4vvm/GHSA-v8c7-r83c-4vvm.json +++ b/advisories/unreviewed/2022/05/GHSA-v8c7-r83c-4vvm/GHSA-v8c7-r83c-4vvm.json @@ -7,12 +7,8 @@ "CVE-2015-1089" ], "details": "CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-v8hr-9qpr-jrwc/GHSA-v8hr-9qpr-jrwc.json b/advisories/unreviewed/2022/05/GHSA-v8hr-9qpr-jrwc/GHSA-v8hr-9qpr-jrwc.json index 31f30f3f888..12172a2cdd0 100644 --- a/advisories/unreviewed/2022/05/GHSA-v8hr-9qpr-jrwc/GHSA-v8hr-9qpr-jrwc.json +++ b/advisories/unreviewed/2022/05/GHSA-v8hr-9qpr-jrwc/GHSA-v8hr-9qpr-jrwc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -119,9 +117,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v9hg-mw5q-29q6/GHSA-v9hg-mw5q-29q6.json b/advisories/unreviewed/2022/05/GHSA-v9hg-mw5q-29q6/GHSA-v9hg-mw5q-29q6.json index 697887dec4c..9e5d58835f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9hg-mw5q-29q6/GHSA-v9hg-mw5q-29q6.json +++ b/advisories/unreviewed/2022/05/GHSA-v9hg-mw5q-29q6/GHSA-v9hg-mw5q-29q6.json @@ -7,12 +7,8 @@ "CVE-2015-5777" ], "details": "CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-5778.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vcfj-wrxg-9cqm/GHSA-vcfj-wrxg-9cqm.json b/advisories/unreviewed/2022/05/GHSA-vcfj-wrxg-9cqm/GHSA-vcfj-wrxg-9cqm.json index b12ac9ff78c..e03044adc83 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcfj-wrxg-9cqm/GHSA-vcfj-wrxg-9cqm.json +++ b/advisories/unreviewed/2022/05/GHSA-vcfj-wrxg-9cqm/GHSA-vcfj-wrxg-9cqm.json @@ -7,12 +7,8 @@ "CVE-2015-4299" ], "details": "Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default messaging-queue system folders via unspecified vectors, aka Bug ID CSCuo89046.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vf9x-fp9j-gp8c/GHSA-vf9x-fp9j-gp8c.json b/advisories/unreviewed/2022/05/GHSA-vf9x-fp9j-gp8c/GHSA-vf9x-fp9j-gp8c.json index b53cd9fa82a..629568540f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf9x-fp9j-gp8c/GHSA-vf9x-fp9j-gp8c.json +++ b/advisories/unreviewed/2022/05/GHSA-vf9x-fp9j-gp8c/GHSA-vf9x-fp9j-gp8c.json @@ -7,12 +7,8 @@ "CVE-2013-5003" ], "details": "Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfh6-43qg-hmc4/GHSA-vfh6-43qg-hmc4.json b/advisories/unreviewed/2022/05/GHSA-vfh6-43qg-hmc4/GHSA-vfh6-43qg-hmc4.json index ae35d25ccbb..c8bf67ec9f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfh6-43qg-hmc4/GHSA-vfh6-43qg-hmc4.json +++ b/advisories/unreviewed/2022/05/GHSA-vfh6-43qg-hmc4/GHSA-vfh6-43qg-hmc4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vfv2-4jmx-x9vh/GHSA-vfv2-4jmx-x9vh.json b/advisories/unreviewed/2022/05/GHSA-vfv2-4jmx-x9vh/GHSA-vfv2-4jmx-x9vh.json index bb9b8aa6f8e..b8a2338de5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfv2-4jmx-x9vh/GHSA-vfv2-4jmx-x9vh.json +++ b/advisories/unreviewed/2022/05/GHSA-vfv2-4jmx-x9vh/GHSA-vfv2-4jmx-x9vh.json @@ -7,12 +7,8 @@ "CVE-2015-6756" ], "details": "Use-after-free vulnerability in the CPDFSDK_PageView implementation in fpdfsdk/src/fsdk_mgr.cpp in PDFium, as used in Google Chrome before 46.0.2490.71, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging mishandling of a focused annotation in a PDF document.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vfw4-2ffw-69gw/GHSA-vfw4-2ffw-69gw.json b/advisories/unreviewed/2022/05/GHSA-vfw4-2ffw-69gw/GHSA-vfw4-2ffw-69gw.json index 9963f3b9a65..fbc162779bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfw4-2ffw-69gw/GHSA-vfw4-2ffw-69gw.json +++ b/advisories/unreviewed/2022/05/GHSA-vfw4-2ffw-69gw/GHSA-vfw4-2ffw-69gw.json @@ -7,12 +7,8 @@ "CVE-2015-6660" ], "details": "The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to \"file upload value callbacks.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vgh3-qfvh-cw6q/GHSA-vgh3-qfvh-cw6q.json b/advisories/unreviewed/2022/05/GHSA-vgh3-qfvh-cw6q/GHSA-vgh3-qfvh-cw6q.json index 97409186c0e..109dfeb589b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgh3-qfvh-cw6q/GHSA-vgh3-qfvh-cw6q.json +++ b/advisories/unreviewed/2022/05/GHSA-vgh3-qfvh-cw6q/GHSA-vgh3-qfvh-cw6q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vgr2-h473-jfqv/GHSA-vgr2-h473-jfqv.json b/advisories/unreviewed/2022/05/GHSA-vgr2-h473-jfqv/GHSA-vgr2-h473-jfqv.json index 7dbe8776f5e..83f5a8e9284 100644 --- a/advisories/unreviewed/2022/05/GHSA-vgr2-h473-jfqv/GHSA-vgr2-h473-jfqv.json +++ b/advisories/unreviewed/2022/05/GHSA-vgr2-h473-jfqv/GHSA-vgr2-h473-jfqv.json @@ -7,12 +7,8 @@ "CVE-2014-7946" ], "details": "The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips captions during table layout in certain situations, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors related to the Fonts implementation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhr4-982g-h2pj/GHSA-vhr4-982g-h2pj.json b/advisories/unreviewed/2022/05/GHSA-vhr4-982g-h2pj/GHSA-vhr4-982g-h2pj.json index eec04c8a05d..ac5e586dd97 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhr4-982g-h2pj/GHSA-vhr4-982g-h2pj.json +++ b/advisories/unreviewed/2022/05/GHSA-vhr4-982g-h2pj/GHSA-vhr4-982g-h2pj.json @@ -7,12 +7,8 @@ "CVE-2015-1949" ], "details": "The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands with SYSTEM privileges via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vhwf-3cfr-2p4m/GHSA-vhwf-3cfr-2p4m.json b/advisories/unreviewed/2022/05/GHSA-vhwf-3cfr-2p4m/GHSA-vhwf-3cfr-2p4m.json index 1a93817b9fc..d5be034718e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vhwf-3cfr-2p4m/GHSA-vhwf-3cfr-2p4m.json +++ b/advisories/unreviewed/2022/05/GHSA-vhwf-3cfr-2p4m/GHSA-vhwf-3cfr-2p4m.json @@ -7,12 +7,8 @@ "CVE-2014-4287" ], "details": "Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:CHARACTER SETS.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vj5g-jj63-gm6r/GHSA-vj5g-jj63-gm6r.json b/advisories/unreviewed/2022/05/GHSA-vj5g-jj63-gm6r/GHSA-vj5g-jj63-gm6r.json index 6ad8031541a..968948d438e 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj5g-jj63-gm6r/GHSA-vj5g-jj63-gm6r.json +++ b/advisories/unreviewed/2022/05/GHSA-vj5g-jj63-gm6r/GHSA-vj5g-jj63-gm6r.json @@ -7,12 +7,8 @@ "CVE-2015-4204" ], "details": "Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authenticated users to cause a denial of service (memory consumption or PXF process crash) by sending docsIfMCmtsMib SNMP requests quickly, aka Bug ID CSCue65051.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjfm-2p57-mvrc/GHSA-vjfm-2p57-mvrc.json b/advisories/unreviewed/2022/05/GHSA-vjfm-2p57-mvrc/GHSA-vjfm-2p57-mvrc.json index 32fbc7e5a0f..45d698e4887 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjfm-2p57-mvrc/GHSA-vjfm-2p57-mvrc.json +++ b/advisories/unreviewed/2022/05/GHSA-vjfm-2p57-mvrc/GHSA-vjfm-2p57-mvrc.json @@ -7,12 +7,8 @@ "CVE-2015-0813" ], "details": "Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -88,9 +84,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjq4-3f6q-h4fx/GHSA-vjq4-3f6q-h4fx.json b/advisories/unreviewed/2022/05/GHSA-vjq4-3f6q-h4fx/GHSA-vjq4-3f6q-h4fx.json index 78e677222fd..43f8cf18aa3 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjq4-3f6q-h4fx/GHSA-vjq4-3f6q-h4fx.json +++ b/advisories/unreviewed/2022/05/GHSA-vjq4-3f6q-h4fx/GHSA-vjq4-3f6q-h4fx.json @@ -7,12 +7,8 @@ "CVE-2015-0465" ], "details": "Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, and 6.3.6 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Infrastructure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vjvj-gr2r-88wq/GHSA-vjvj-gr2r-88wq.json b/advisories/unreviewed/2022/05/GHSA-vjvj-gr2r-88wq/GHSA-vjvj-gr2r-88wq.json index cfb451d460a..32e646f5b3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-vjvj-gr2r-88wq/GHSA-vjvj-gr2r-88wq.json +++ b/advisories/unreviewed/2022/05/GHSA-vjvj-gr2r-88wq/GHSA-vjvj-gr2r-88wq.json @@ -7,12 +7,8 @@ "CVE-2015-4211" ], "details": "Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCus65862.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vm8p-8844-p4rj/GHSA-vm8p-8844-p4rj.json b/advisories/unreviewed/2022/05/GHSA-vm8p-8844-p4rj/GHSA-vm8p-8844-p4rj.json index 92c21c02ed8..74ee5e3f7a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vm8p-8844-p4rj/GHSA-vm8p-8844-p4rj.json +++ b/advisories/unreviewed/2022/05/GHSA-vm8p-8844-p4rj/GHSA-vm8p-8844-p4rj.json @@ -7,12 +7,8 @@ "CVE-2015-0815" ], "details": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmq4-xhg5-xqj3/GHSA-vmq4-xhg5-xqj3.json b/advisories/unreviewed/2022/05/GHSA-vmq4-xhg5-xqj3/GHSA-vmq4-xhg5-xqj3.json index 11a0e231b46..1854acde824 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmq4-xhg5-xqj3/GHSA-vmq4-xhg5-xqj3.json +++ b/advisories/unreviewed/2022/05/GHSA-vmq4-xhg5-xqj3/GHSA-vmq4-xhg5-xqj3.json @@ -7,12 +7,8 @@ "CVE-2015-3724" ], "details": "CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vmr9-22rc-7435/GHSA-vmr9-22rc-7435.json b/advisories/unreviewed/2022/05/GHSA-vmr9-22rc-7435/GHSA-vmr9-22rc-7435.json index a3c3edca8e1..dfcf9c653fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmr9-22rc-7435/GHSA-vmr9-22rc-7435.json +++ b/advisories/unreviewed/2022/05/GHSA-vmr9-22rc-7435/GHSA-vmr9-22rc-7435.json @@ -7,12 +7,8 @@ "CVE-2015-4524" ], "details": "Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5 SP7 before P25; and Documentum Task Space 6.7SP1 before P31 and 6.7SP2 before P23 allows remote authenticated users to execute arbitrary code by uploading a file to the backend Content Server.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vp3g-8qhm-pw5j/GHSA-vp3g-8qhm-pw5j.json b/advisories/unreviewed/2022/05/GHSA-vp3g-8qhm-pw5j/GHSA-vp3g-8qhm-pw5j.json index f010138f4b5..31ac5f36a82 100644 --- a/advisories/unreviewed/2022/05/GHSA-vp3g-8qhm-pw5j/GHSA-vp3g-8qhm-pw5j.json +++ b/advisories/unreviewed/2022/05/GHSA-vp3g-8qhm-pw5j/GHSA-vp3g-8qhm-pw5j.json @@ -7,12 +7,8 @@ "CVE-2015-3983" ], "details": "The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpjp-446f-8x98/GHSA-vpjp-446f-8x98.json b/advisories/unreviewed/2022/05/GHSA-vpjp-446f-8x98/GHSA-vpjp-446f-8x98.json index 3a2e6a244f1..0b2b6d4d203 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpjp-446f-8x98/GHSA-vpjp-446f-8x98.json +++ b/advisories/unreviewed/2022/05/GHSA-vpjp-446f-8x98/GHSA-vpjp-446f-8x98.json @@ -7,12 +7,8 @@ "CVE-2015-3084" ], "details": "Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code by leveraging an unspecified \"type confusion,\" a different vulnerability than CVE-2015-3077 and CVE-2015-3086.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vpwc-qjh8-q22p/GHSA-vpwc-qjh8-q22p.json b/advisories/unreviewed/2022/05/GHSA-vpwc-qjh8-q22p/GHSA-vpwc-qjh8-q22p.json index 8e33c0edcac..5fc5170c03a 100644 --- a/advisories/unreviewed/2022/05/GHSA-vpwc-qjh8-q22p/GHSA-vpwc-qjh8-q22p.json +++ b/advisories/unreviewed/2022/05/GHSA-vpwc-qjh8-q22p/GHSA-vpwc-qjh8-q22p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vr44-r2gc-qh8c/GHSA-vr44-r2gc-qh8c.json b/advisories/unreviewed/2022/05/GHSA-vr44-r2gc-qh8c/GHSA-vr44-r2gc-qh8c.json index 69783891a7d..9dd656cf1fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-vr44-r2gc-qh8c/GHSA-vr44-r2gc-qh8c.json +++ b/advisories/unreviewed/2022/05/GHSA-vr44-r2gc-qh8c/GHSA-vr44-r2gc-qh8c.json @@ -7,12 +7,8 @@ "CVE-2015-0474" ], "details": "Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-0493.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vv8w-vhh3-w2fc/GHSA-vv8w-vhh3-w2fc.json b/advisories/unreviewed/2022/05/GHSA-vv8w-vhh3-w2fc/GHSA-vv8w-vhh3-w2fc.json index 5c134843054..8c5f6f54d7c 100644 --- a/advisories/unreviewed/2022/05/GHSA-vv8w-vhh3-w2fc/GHSA-vv8w-vhh3-w2fc.json +++ b/advisories/unreviewed/2022/05/GHSA-vv8w-vhh3-w2fc/GHSA-vv8w-vhh3-w2fc.json @@ -7,12 +7,8 @@ "CVE-2015-4270" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.5 and 6.0.0 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuv22557, CSCuv22583, CSCuv22632, CSCuv22641, CSCuv22650, CSCuv22662, CSCuv22697, and CSCuv22702.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vvvg-9wmm-566v/GHSA-vvvg-9wmm-566v.json b/advisories/unreviewed/2022/05/GHSA-vvvg-9wmm-566v/GHSA-vvvg-9wmm-566v.json index 54872f27025..d599ffd8d64 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvvg-9wmm-566v/GHSA-vvvg-9wmm-566v.json +++ b/advisories/unreviewed/2022/05/GHSA-vvvg-9wmm-566v/GHSA-vvvg-9wmm-566v.json @@ -7,12 +7,8 @@ "CVE-2015-7002" ], "details": "WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-vw28-xrgp-7gqj/GHSA-vw28-xrgp-7gqj.json b/advisories/unreviewed/2022/05/GHSA-vw28-xrgp-7gqj/GHSA-vw28-xrgp-7gqj.json index 6d783c69488..355976f2014 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw28-xrgp-7gqj/GHSA-vw28-xrgp-7gqj.json +++ b/advisories/unreviewed/2022/05/GHSA-vw28-xrgp-7gqj/GHSA-vw28-xrgp-7gqj.json @@ -7,12 +7,8 @@ "CVE-2014-8108" ], "details": "The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vw2j-w6mh-x39g/GHSA-vw2j-w6mh-x39g.json b/advisories/unreviewed/2022/05/GHSA-vw2j-w6mh-x39g/GHSA-vw2j-w6mh-x39g.json index 6aaccad9db9..81b86d495a4 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw2j-w6mh-x39g/GHSA-vw2j-w6mh-x39g.json +++ b/advisories/unreviewed/2022/05/GHSA-vw2j-w6mh-x39g/GHSA-vw2j-w6mh-x39g.json @@ -7,12 +7,8 @@ "CVE-2015-1085" ], "details": "AppleKeyStore in Apple iOS before 8.3 does not properly restrict a certain passcode-confirmation interface, which makes it easier for attackers to verify correct passcode guesses via a crafted app.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,9 +32,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwmq-8w98-3hr8/GHSA-vwmq-8w98-3hr8.json b/advisories/unreviewed/2022/05/GHSA-vwmq-8w98-3hr8/GHSA-vwmq-8w98-3hr8.json index 3c75d2949b9..ddf43bb3e0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwmq-8w98-3hr8/GHSA-vwmq-8w98-3hr8.json +++ b/advisories/unreviewed/2022/05/GHSA-vwmq-8w98-3hr8/GHSA-vwmq-8w98-3hr8.json @@ -7,12 +7,8 @@ "CVE-2015-1245" ], "details": "Use-after-free vulnerability in the OpenPDFInReaderView::Update function in browser/ui/views/location_bar/open_pdf_in_reader_view.cc in Google Chrome before 41.0.2272.76 might allow user-assisted remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by triggering interaction with a PDFium \"Open PDF in Reader\" button that has an invalid tab association.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vwrp-9627-m33j/GHSA-vwrp-9627-m33j.json b/advisories/unreviewed/2022/05/GHSA-vwrp-9627-m33j/GHSA-vwrp-9627-m33j.json index 83c8d9ea61b..4543b54cb1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwrp-9627-m33j/GHSA-vwrp-9627-m33j.json +++ b/advisories/unreviewed/2022/05/GHSA-vwrp-9627-m33j/GHSA-vwrp-9627-m33j.json @@ -7,12 +7,8 @@ "CVE-2015-4257" ], "details": "Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MCU 4500 devices with software 4.5(1.55) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90710.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w3hc-jprx-2f55/GHSA-w3hc-jprx-2f55.json b/advisories/unreviewed/2022/05/GHSA-w3hc-jprx-2f55/GHSA-w3hc-jprx-2f55.json index ad703343798..84f03455342 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3hc-jprx-2f55/GHSA-w3hc-jprx-2f55.json +++ b/advisories/unreviewed/2022/05/GHSA-w3hc-jprx-2f55/GHSA-w3hc-jprx-2f55.json @@ -7,12 +7,8 @@ "CVE-2015-3110" ], "details": "Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -40,9 +36,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w45p-69w3-w59q/GHSA-w45p-69w3-w59q.json b/advisories/unreviewed/2022/05/GHSA-w45p-69w3-w59q/GHSA-w45p-69w3-w59q.json index a365d7922bc..71ab4dc6517 100644 --- a/advisories/unreviewed/2022/05/GHSA-w45p-69w3-w59q/GHSA-w45p-69w3-w59q.json +++ b/advisories/unreviewed/2022/05/GHSA-w45p-69w3-w59q/GHSA-w45p-69w3-w59q.json @@ -7,12 +7,8 @@ "CVE-2015-3077" ], "details": "Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code by leveraging an unspecified \"type confusion,\" a different vulnerability than CVE-2015-3084 and CVE-2015-3086.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -52,9 +48,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w4gf-42f5-463m/GHSA-w4gf-42f5-463m.json b/advisories/unreviewed/2022/05/GHSA-w4gf-42f5-463m/GHSA-w4gf-42f5-463m.json index 3718e54f991..4a407f87213 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4gf-42f5-463m/GHSA-w4gf-42f5-463m.json +++ b/advisories/unreviewed/2022/05/GHSA-w4gf-42f5-463m/GHSA-w4gf-42f5-463m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4j3-crqw-q988/GHSA-w4j3-crqw-q988.json b/advisories/unreviewed/2022/05/GHSA-w4j3-crqw-q988/GHSA-w4j3-crqw-q988.json index 520c5efaff0..4941953d508 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4j3-crqw-q988/GHSA-w4j3-crqw-q988.json +++ b/advisories/unreviewed/2022/05/GHSA-w4j3-crqw-q988/GHSA-w4j3-crqw-q988.json @@ -7,12 +7,8 @@ "CVE-2013-7258" ], "details": "Cross-site scripting (XSS) vulnerability in web2ldap 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to \"displaying group DN and entry data in group administration UI.\"", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w4wg-4jcp-7wx8/GHSA-w4wg-4jcp-7wx8.json b/advisories/unreviewed/2022/05/GHSA-w4wg-4jcp-7wx8/GHSA-w4wg-4jcp-7wx8.json index c3fdc53aa19..e4dd275423c 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4wg-4jcp-7wx8/GHSA-w4wg-4jcp-7wx8.json +++ b/advisories/unreviewed/2022/05/GHSA-w4wg-4jcp-7wx8/GHSA-w4wg-4jcp-7wx8.json @@ -7,12 +7,8 @@ "CVE-2015-0543" ], "details": "EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w5hx-7gwg-x79g/GHSA-w5hx-7gwg-x79g.json b/advisories/unreviewed/2022/05/GHSA-w5hx-7gwg-x79g/GHSA-w5hx-7gwg-x79g.json index b2b42338650..bd401617b05 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5hx-7gwg-x79g/GHSA-w5hx-7gwg-x79g.json +++ b/advisories/unreviewed/2022/05/GHSA-w5hx-7gwg-x79g/GHSA-w5hx-7gwg-x79g.json @@ -7,12 +7,8 @@ "CVE-2015-0497" ], "details": "Unspecified vulnerability in the PeopleSoft Enterprise Portal Interaction Hub component in Oracle PeopleSoft Products 9.1.00 allows remote attackers to affect integrity via unknown vectors related to Enterprise Portal.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w72g-vxpg-rx3f/GHSA-w72g-vxpg-rx3f.json b/advisories/unreviewed/2022/05/GHSA-w72g-vxpg-rx3f/GHSA-w72g-vxpg-rx3f.json index c4eca1fa192..2b9be7a53f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-w72g-vxpg-rx3f/GHSA-w72g-vxpg-rx3f.json +++ b/advisories/unreviewed/2022/05/GHSA-w72g-vxpg-rx3f/GHSA-w72g-vxpg-rx3f.json @@ -7,12 +7,8 @@ "CVE-2015-0457" ], "details": "Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-2629.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8mr-3p5f-7x8h/GHSA-w8mr-3p5f-7x8h.json b/advisories/unreviewed/2022/05/GHSA-w8mr-3p5f-7x8h/GHSA-w8mr-3p5f-7x8h.json index 9efcf8f188e..8f75a2c1346 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8mr-3p5f-7x8h/GHSA-w8mr-3p5f-7x8h.json +++ b/advisories/unreviewed/2022/05/GHSA-w8mr-3p5f-7x8h/GHSA-w8mr-3p5f-7x8h.json @@ -7,12 +7,8 @@ "CVE-2015-4223" ], "details": "Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w8v6-4g87-w2vv/GHSA-w8v6-4g87-w2vv.json b/advisories/unreviewed/2022/05/GHSA-w8v6-4g87-w2vv/GHSA-w8v6-4g87-w2vv.json index fc5adff47bb..f72973d5bb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w8v6-4g87-w2vv/GHSA-w8v6-4g87-w2vv.json +++ b/advisories/unreviewed/2022/05/GHSA-w8v6-4g87-w2vv/GHSA-w8v6-4g87-w2vv.json @@ -7,12 +7,8 @@ "CVE-2015-7014" ], "details": "WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-w95m-h8v2-p6gj/GHSA-w95m-h8v2-p6gj.json b/advisories/unreviewed/2022/05/GHSA-w95m-h8v2-p6gj/GHSA-w95m-h8v2-p6gj.json index 6b1f0a2db34..45d0b9aa085 100644 --- a/advisories/unreviewed/2022/05/GHSA-w95m-h8v2-p6gj/GHSA-w95m-h8v2-p6gj.json +++ b/advisories/unreviewed/2022/05/GHSA-w95m-h8v2-p6gj/GHSA-w95m-h8v2-p6gj.json @@ -7,12 +7,8 @@ "CVE-2015-2577" ], "details": "Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Accounting commands.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wcwq-7gxw-3qwf/GHSA-wcwq-7gxw-3qwf.json b/advisories/unreviewed/2022/05/GHSA-wcwq-7gxw-3qwf/GHSA-wcwq-7gxw-3qwf.json index e1d0aa37920..b260dc948c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcwq-7gxw-3qwf/GHSA-wcwq-7gxw-3qwf.json +++ b/advisories/unreviewed/2022/05/GHSA-wcwq-7gxw-3qwf/GHSA-wcwq-7gxw-3qwf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wff6-5qmg-74j3/GHSA-wff6-5qmg-74j3.json b/advisories/unreviewed/2022/05/GHSA-wff6-5qmg-74j3/GHSA-wff6-5qmg-74j3.json index f1ec74acc69..28476dae9e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wff6-5qmg-74j3/GHSA-wff6-5qmg-74j3.json +++ b/advisories/unreviewed/2022/05/GHSA-wff6-5qmg-74j3/GHSA-wff6-5qmg-74j3.json @@ -7,12 +7,8 @@ "CVE-2015-0138" ], "details": "GSKit in IBM Tivoli Directory Server (ITDS) 6.0 before 6.0.0.73-ISS-ITDS-IF0073, 6.1 before 6.1.0.66-ISS-ITDS-IF0066, 6.2 before 6.2.0.42-ISS-ITDS-IF0042, and 6.3 before 6.3.0.35-ISS-ITDS-IF0035 and IBM Security Directory Server (ISDS) 6.3.1 before 6.3.1.9-ISS-ISDS-IF0009 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the \"FREAK\" issue, a different vulnerability than CVE-2015-0204.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -72,9 +68,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfg4-xgj4-pp73/GHSA-wfg4-xgj4-pp73.json b/advisories/unreviewed/2022/05/GHSA-wfg4-xgj4-pp73/GHSA-wfg4-xgj4-pp73.json index 186e188961e..75b4220a061 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfg4-xgj4-pp73/GHSA-wfg4-xgj4-pp73.json +++ b/advisories/unreviewed/2022/05/GHSA-wfg4-xgj4-pp73/GHSA-wfg4-xgj4-pp73.json @@ -7,12 +7,8 @@ "CVE-2015-1916" ], "details": "Unspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of service via unknown vectors related to SSL/TLS and the Secure Socket Extension provider.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wfqh-gccr-77jr/GHSA-wfqh-gccr-77jr.json b/advisories/unreviewed/2022/05/GHSA-wfqh-gccr-77jr/GHSA-wfqh-gccr-77jr.json index b6bf1bd08f4..fd10bb9a5ec 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfqh-gccr-77jr/GHSA-wfqh-gccr-77jr.json +++ b/advisories/unreviewed/2022/05/GHSA-wfqh-gccr-77jr/GHSA-wfqh-gccr-77jr.json @@ -7,12 +7,8 @@ "CVE-2015-3663" ], "details": "QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wfr4-5jwr-wxhg/GHSA-wfr4-5jwr-wxhg.json b/advisories/unreviewed/2022/05/GHSA-wfr4-5jwr-wxhg/GHSA-wfr4-5jwr-wxhg.json index 64da79ca507..b2c877df1af 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfr4-5jwr-wxhg/GHSA-wfr4-5jwr-wxhg.json +++ b/advisories/unreviewed/2022/05/GHSA-wfr4-5jwr-wxhg/GHSA-wfr4-5jwr-wxhg.json @@ -7,12 +7,8 @@ "CVE-2015-4161" ], "details": "SAP Afaria does not properly restrict access to unspecified functionality, which allows remote attackers to obtain sensitive information, gain privileges, or have other unspecified impact via unknown vectors, SAP Security Note 2155690.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wgpj-2628-3c8v/GHSA-wgpj-2628-3c8v.json b/advisories/unreviewed/2022/05/GHSA-wgpj-2628-3c8v/GHSA-wgpj-2628-3c8v.json index d861429a4bf..a61c96fda21 100644 --- a/advisories/unreviewed/2022/05/GHSA-wgpj-2628-3c8v/GHSA-wgpj-2628-3c8v.json +++ b/advisories/unreviewed/2022/05/GHSA-wgpj-2628-3c8v/GHSA-wgpj-2628-3c8v.json @@ -7,12 +7,8 @@ "CVE-2015-6661" ], "details": "Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to obtain sensitive node titles by reading the menu.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wh6f-4x45-xjrj/GHSA-wh6f-4x45-xjrj.json b/advisories/unreviewed/2022/05/GHSA-wh6f-4x45-xjrj/GHSA-wh6f-4x45-xjrj.json index edc7ce93f1e..ff8cadf2554 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh6f-4x45-xjrj/GHSA-wh6f-4x45-xjrj.json +++ b/advisories/unreviewed/2022/05/GHSA-wh6f-4x45-xjrj/GHSA-wh6f-4x45-xjrj.json @@ -7,12 +7,8 @@ "CVE-2005-3358" ], "details": "Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bitmask, which causes a panic when a page fault occurs.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -96,9 +92,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wh82-w6g6-vr7h/GHSA-wh82-w6g6-vr7h.json b/advisories/unreviewed/2022/05/GHSA-wh82-w6g6-vr7h/GHSA-wh82-w6g6-vr7h.json index ed3b311a65b..7329e841653 100644 --- a/advisories/unreviewed/2022/05/GHSA-wh82-w6g6-vr7h/GHSA-wh82-w6g6-vr7h.json +++ b/advisories/unreviewed/2022/05/GHSA-wh82-w6g6-vr7h/GHSA-wh82-w6g6-vr7h.json @@ -7,12 +7,8 @@ "CVE-2015-4001" ], "details": "Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,9 +44,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-whq2-g3c2-x5j3/GHSA-whq2-g3c2-x5j3.json b/advisories/unreviewed/2022/05/GHSA-whq2-g3c2-x5j3/GHSA-whq2-g3c2-x5j3.json index fe76f53f215..5c6f890d70c 100644 --- a/advisories/unreviewed/2022/05/GHSA-whq2-g3c2-x5j3/GHSA-whq2-g3c2-x5j3.json +++ b/advisories/unreviewed/2022/05/GHSA-whq2-g3c2-x5j3/GHSA-whq2-g3c2-x5j3.json @@ -7,12 +7,8 @@ "CVE-2013-4256" ], "details": "Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a denial of service (crash) or possibly execute arbitrary code via the (1) display command argument to the ProcessCommandLine function in server/os/utils.c; (2) ResetHosts function in server/os/access.c; (3) open_unix_socket, (4) open_isc_local, (5) open_xsight_local, (6) open_att_local, or (7) open_att_svr4_local function in server/os/connection.c; the (8) AUDIOHOST environment variable to the CreateWellKnownSockets or (9) AmoebaTCPConnectorThread function in server/os/connection.c; or (10) unspecified vectors related to logging in the osLogMsg function in server/os/aulog.c.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wj63-277w-g862/GHSA-wj63-277w-g862.json b/advisories/unreviewed/2022/05/GHSA-wj63-277w-g862/GHSA-wj63-277w-g862.json index bbb6b13a5f3..86403623e3e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj63-277w-g862/GHSA-wj63-277w-g862.json +++ b/advisories/unreviewed/2022/05/GHSA-wj63-277w-g862/GHSA-wj63-277w-g862.json @@ -7,12 +7,8 @@ "CVE-2014-7932" ], "details": "Use-after-free vulnerability in the Element::detach function in core/dom/Element.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving pending updates of detached elements.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -68,9 +64,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wjcc-qpfr-87ww/GHSA-wjcc-qpfr-87ww.json b/advisories/unreviewed/2022/05/GHSA-wjcc-qpfr-87ww/GHSA-wjcc-qpfr-87ww.json index 1e89ac80663..b4e721fbe0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjcc-qpfr-87ww/GHSA-wjcc-qpfr-87ww.json +++ b/advisories/unreviewed/2022/05/GHSA-wjcc-qpfr-87ww/GHSA-wjcc-qpfr-87ww.json @@ -7,12 +7,8 @@ "CVE-2015-0547" ], "details": "The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjjr-v27g-wfvj/GHSA-wjjr-v27g-wfvj.json b/advisories/unreviewed/2022/05/GHSA-wjjr-v27g-wfvj/GHSA-wjjr-v27g-wfvj.json index 0d0a774222a..3c1878fd9e6 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjjr-v27g-wfvj/GHSA-wjjr-v27g-wfvj.json +++ b/advisories/unreviewed/2022/05/GHSA-wjjr-v27g-wfvj/GHSA-wjjr-v27g-wfvj.json @@ -7,12 +7,8 @@ "CVE-2015-7012" ], "details": "WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjp7-mwhc-8ppq/GHSA-wjp7-mwhc-8ppq.json b/advisories/unreviewed/2022/05/GHSA-wjp7-mwhc-8ppq/GHSA-wjp7-mwhc-8ppq.json index 7b5b76b9638..4161a40d534 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjp7-mwhc-8ppq/GHSA-wjp7-mwhc-8ppq.json +++ b/advisories/unreviewed/2022/05/GHSA-wjp7-mwhc-8ppq/GHSA-wjp7-mwhc-8ppq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wjw2-9cj6-hcph/GHSA-wjw2-9cj6-hcph.json b/advisories/unreviewed/2022/05/GHSA-wjw2-9cj6-hcph/GHSA-wjw2-9cj6-hcph.json index 329aafd624f..d4db5c06055 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjw2-9cj6-hcph/GHSA-wjw2-9cj6-hcph.json +++ b/advisories/unreviewed/2022/05/GHSA-wjw2-9cj6-hcph/GHSA-wjw2-9cj6-hcph.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wmx9-mx7h-wm59/GHSA-wmx9-mx7h-wm59.json b/advisories/unreviewed/2022/05/GHSA-wmx9-mx7h-wm59/GHSA-wmx9-mx7h-wm59.json index a7397617643..ca404fe04f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-wmx9-mx7h-wm59/GHSA-wmx9-mx7h-wm59.json +++ b/advisories/unreviewed/2022/05/GHSA-wmx9-mx7h-wm59/GHSA-wmx9-mx7h-wm59.json @@ -7,12 +7,8 @@ "CVE-2015-1948" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1953, CVE-2015-1954, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wqgc-ghqv-pj27/GHSA-wqgc-ghqv-pj27.json b/advisories/unreviewed/2022/05/GHSA-wqgc-ghqv-pj27/GHSA-wqgc-ghqv-pj27.json index eef988a0280..cedcbdbd896 100644 --- a/advisories/unreviewed/2022/05/GHSA-wqgc-ghqv-pj27/GHSA-wqgc-ghqv-pj27.json +++ b/advisories/unreviewed/2022/05/GHSA-wqgc-ghqv-pj27/GHSA-wqgc-ghqv-pj27.json @@ -7,12 +7,8 @@ "CVE-2005-0529" ], "details": "Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -56,9 +52,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrvc-r7xq-7462/GHSA-wrvc-r7xq-7462.json b/advisories/unreviewed/2022/05/GHSA-wrvc-r7xq-7462/GHSA-wrvc-r7xq-7462.json index 96da45da7d3..67e2c36c169 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrvc-r7xq-7462/GHSA-wrvc-r7xq-7462.json +++ b/advisories/unreviewed/2022/05/GHSA-wrvc-r7xq-7462/GHSA-wrvc-r7xq-7462.json @@ -7,12 +7,8 @@ "CVE-2015-1088" ], "details": "CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which allows remote attackers to execute arbitrary code via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wv4v-cwg3-f8c9/GHSA-wv4v-cwg3-f8c9.json b/advisories/unreviewed/2022/05/GHSA-wv4v-cwg3-f8c9/GHSA-wv4v-cwg3-f8c9.json index 3dee4a56073..6df05b17b6d 100644 --- a/advisories/unreviewed/2022/05/GHSA-wv4v-cwg3-f8c9/GHSA-wv4v-cwg3-f8c9.json +++ b/advisories/unreviewed/2022/05/GHSA-wv4v-cwg3-f8c9/GHSA-wv4v-cwg3-f8c9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -55,9 +53,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ww3r-g52r-m6j3/GHSA-ww3r-g52r-m6j3.json b/advisories/unreviewed/2022/05/GHSA-ww3r-g52r-m6j3/GHSA-ww3r-g52r-m6j3.json index 548eca7ed2b..0cadff0f092 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww3r-g52r-m6j3/GHSA-ww3r-g52r-m6j3.json +++ b/advisories/unreviewed/2022/05/GHSA-ww3r-g52r-m6j3/GHSA-ww3r-g52r-m6j3.json @@ -7,12 +7,8 @@ "CVE-2015-2019" ], "details": "IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not prevent caching of documents retrieved in SSL sessions, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-ww56-rf55-229p/GHSA-ww56-rf55-229p.json b/advisories/unreviewed/2022/05/GHSA-ww56-rf55-229p/GHSA-ww56-rf55-229p.json index d3b9cf90659..f906031903a 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww56-rf55-229p/GHSA-ww56-rf55-229p.json +++ b/advisories/unreviewed/2022/05/GHSA-ww56-rf55-229p/GHSA-ww56-rf55-229p.json @@ -7,12 +7,8 @@ "CVE-2014-8618" ], "details": "Cross-site scripting (XSS) vulnerability in the theme login page in Fortinet FortiADC D models before 4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-ww7r-m379-j2pg/GHSA-ww7r-m379-j2pg.json b/advisories/unreviewed/2022/05/GHSA-ww7r-m379-j2pg/GHSA-ww7r-m379-j2pg.json index c85af05edb5..d62fb05fd27 100644 --- a/advisories/unreviewed/2022/05/GHSA-ww7r-m379-j2pg/GHSA-ww7r-m379-j2pg.json +++ b/advisories/unreviewed/2022/05/GHSA-ww7r-m379-j2pg/GHSA-ww7r-m379-j2pg.json @@ -7,12 +7,8 @@ "CVE-2015-7005" ], "details": "WebKit, as used in Apple iOS before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wwqg-4jcm-c5j4/GHSA-wwqg-4jcm-c5j4.json b/advisories/unreviewed/2022/05/GHSA-wwqg-4jcm-c5j4/GHSA-wwqg-4jcm-c5j4.json index fb749be0f87..d210f725aed 100644 --- a/advisories/unreviewed/2022/05/GHSA-wwqg-4jcm-c5j4/GHSA-wwqg-4jcm-c5j4.json +++ b/advisories/unreviewed/2022/05/GHSA-wwqg-4jcm-c5j4/GHSA-wwqg-4jcm-c5j4.json @@ -7,12 +7,8 @@ "CVE-2015-5786" ], "details": "Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-5785.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-wx88-xjww-5rhv/GHSA-wx88-xjww-5rhv.json b/advisories/unreviewed/2022/05/GHSA-wx88-xjww-5rhv/GHSA-wx88-xjww-5rhv.json index 7fdef997554..5fff715c2ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx88-xjww-5rhv/GHSA-wx88-xjww-5rhv.json +++ b/advisories/unreviewed/2022/05/GHSA-wx88-xjww-5rhv/GHSA-wx88-xjww-5rhv.json @@ -7,12 +7,8 @@ "CVE-2015-1959" ], "details": "IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly restrict encrypted files, which allows local users to obtain sensitive information or possibly have unspecified other impact via a (1) download or (2) upload action.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x3h6-r5xc-mc8q/GHSA-x3h6-r5xc-mc8q.json b/advisories/unreviewed/2022/05/GHSA-x3h6-r5xc-mc8q/GHSA-x3h6-r5xc-mc8q.json index 08946e11a34..057360d34b6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3h6-r5xc-mc8q/GHSA-x3h6-r5xc-mc8q.json +++ b/advisories/unreviewed/2022/05/GHSA-x3h6-r5xc-mc8q/GHSA-x3h6-r5xc-mc8q.json @@ -7,12 +7,8 @@ "CVE-2014-8986" ], "details": "Cross-site scripting (XSS) vulnerability in the selection list in the filters in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via a crafted config option, a different vulnerability than CVE-2014-8987.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x46f-47h6-v9jx/GHSA-x46f-47h6-v9jx.json b/advisories/unreviewed/2022/05/GHSA-x46f-47h6-v9jx/GHSA-x46f-47h6-v9jx.json index 5ff76be7c9a..4b12ddf4a46 100644 --- a/advisories/unreviewed/2022/05/GHSA-x46f-47h6-v9jx/GHSA-x46f-47h6-v9jx.json +++ b/advisories/unreviewed/2022/05/GHSA-x46f-47h6-v9jx/GHSA-x46f-47h6-v9jx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x4fr-qpcc-rhww/GHSA-x4fr-qpcc-rhww.json b/advisories/unreviewed/2022/05/GHSA-x4fr-qpcc-rhww/GHSA-x4fr-qpcc-rhww.json index 845747a266d..a110ec6a0a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x4fr-qpcc-rhww/GHSA-x4fr-qpcc-rhww.json +++ b/advisories/unreviewed/2022/05/GHSA-x4fr-qpcc-rhww/GHSA-x4fr-qpcc-rhww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5r4-6m79-9q47/GHSA-x5r4-6m79-9q47.json b/advisories/unreviewed/2022/05/GHSA-x5r4-6m79-9q47/GHSA-x5r4-6m79-9q47.json index c2e90d7c028..97c734356c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5r4-6m79-9q47/GHSA-x5r4-6m79-9q47.json +++ b/advisories/unreviewed/2022/05/GHSA-x5r4-6m79-9q47/GHSA-x5r4-6m79-9q47.json @@ -7,12 +7,8 @@ "CVE-2015-2731" ], "details": "Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allows remote attackers to execute arbitrary code by leveraging client-side JavaScript that triggers removal of a DOM object on the basis of a Content Policy.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -76,9 +72,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5w7-v6pc-m6c4/GHSA-x5w7-v6pc-m6c4.json b/advisories/unreviewed/2022/05/GHSA-x5w7-v6pc-m6c4/GHSA-x5w7-v6pc-m6c4.json index 756200ecc74..d3a43c4f668 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5w7-v6pc-m6c4/GHSA-x5w7-v6pc-m6c4.json +++ b/advisories/unreviewed/2022/05/GHSA-x5w7-v6pc-m6c4/GHSA-x5w7-v6pc-m6c4.json @@ -7,12 +7,8 @@ "CVE-2015-3668" ], "details": "QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, and CVE-2015-3667.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x5x5-qg9q-2423/GHSA-x5x5-qg9q-2423.json b/advisories/unreviewed/2022/05/GHSA-x5x5-qg9q-2423/GHSA-x5x5-qg9q-2423.json index 6aaa9ab8c0f..3e14cb98003 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5x5-qg9q-2423/GHSA-x5x5-qg9q-2423.json +++ b/advisories/unreviewed/2022/05/GHSA-x5x5-qg9q-2423/GHSA-x5x5-qg9q-2423.json @@ -7,12 +7,8 @@ "CVE-2015-3669" ], "details": "QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3664 and CVE-2015-3665.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x65g-mfcj-xhc5/GHSA-x65g-mfcj-xhc5.json b/advisories/unreviewed/2022/05/GHSA-x65g-mfcj-xhc5/GHSA-x65g-mfcj-xhc5.json index 9e8d4bc67e7..9f3309e9cf1 100644 --- a/advisories/unreviewed/2022/05/GHSA-x65g-mfcj-xhc5/GHSA-x65g-mfcj-xhc5.json +++ b/advisories/unreviewed/2022/05/GHSA-x65g-mfcj-xhc5/GHSA-x65g-mfcj-xhc5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -187,9 +185,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x698-8p98-2886/GHSA-x698-8p98-2886.json b/advisories/unreviewed/2022/05/GHSA-x698-8p98-2886/GHSA-x698-8p98-2886.json index 5a8d10aab0c..7789fceaab9 100644 --- a/advisories/unreviewed/2022/05/GHSA-x698-8p98-2886/GHSA-x698-8p98-2886.json +++ b/advisories/unreviewed/2022/05/GHSA-x698-8p98-2886/GHSA-x698-8p98-2886.json @@ -7,12 +7,8 @@ "CVE-2015-1243" ], "details": "Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an attempt to unregister a MutationObserver object that is not currently registered.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -60,9 +56,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x6gj-r267-c9vw/GHSA-x6gj-r267-c9vw.json b/advisories/unreviewed/2022/05/GHSA-x6gj-r267-c9vw/GHSA-x6gj-r267-c9vw.json index 93cba0a1fab..7e59526030e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6gj-r267-c9vw/GHSA-x6gj-r267-c9vw.json +++ b/advisories/unreviewed/2022/05/GHSA-x6gj-r267-c9vw/GHSA-x6gj-r267-c9vw.json @@ -7,12 +7,8 @@ "CVE-2014-4668" ], "details": "The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x6jx-g3r4-5xmh/GHSA-x6jx-g3r4-5xmh.json b/advisories/unreviewed/2022/05/GHSA-x6jx-g3r4-5xmh/GHSA-x6jx-g3r4-5xmh.json index 72cd66bf73b..4b23ccf2001 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6jx-g3r4-5xmh/GHSA-x6jx-g3r4-5xmh.json +++ b/advisories/unreviewed/2022/05/GHSA-x6jx-g3r4-5xmh/GHSA-x6jx-g3r4-5xmh.json @@ -7,12 +7,8 @@ "CVE-2013-5640" ], "details": "Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) answer_id or (2) question_id parameter to polls/vote.php, (3) story_id parameter to comments/add.php or (4) comments/edit.php, or (5) thread_id parameter to posts/add.php. NOTE: this issue was SPLIT due to differences in researchers and disclosure dates. CVE-2013-7349 already covers the news_id parameter to news/send.php, user_email parameter to users/register.php, and thread_id to posts/edit.php vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x733-qw5x-37j6/GHSA-x733-qw5x-37j6.json b/advisories/unreviewed/2022/05/GHSA-x733-qw5x-37j6/GHSA-x733-qw5x-37j6.json index a9cfed74de3..2f4e9554ebb 100644 --- a/advisories/unreviewed/2022/05/GHSA-x733-qw5x-37j6/GHSA-x733-qw5x-37j6.json +++ b/advisories/unreviewed/2022/05/GHSA-x733-qw5x-37j6/GHSA-x733-qw5x-37j6.json @@ -7,12 +7,8 @@ "CVE-2015-4196" ], "details": "Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH session, aka Bug ID CSCuq45546.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x82x-cpw5-ffgg/GHSA-x82x-cpw5-ffgg.json b/advisories/unreviewed/2022/05/GHSA-x82x-cpw5-ffgg/GHSA-x82x-cpw5-ffgg.json index 1777b9ca5af..62667a4fe25 100644 --- a/advisories/unreviewed/2022/05/GHSA-x82x-cpw5-ffgg/GHSA-x82x-cpw5-ffgg.json +++ b/advisories/unreviewed/2022/05/GHSA-x82x-cpw5-ffgg/GHSA-x82x-cpw5-ffgg.json @@ -7,12 +7,8 @@ "CVE-2015-4256" ], "details": "Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP VCR devices with software 3.0(1.27) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90736.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x872-hfmg-7gqf/GHSA-x872-hfmg-7gqf.json b/advisories/unreviewed/2022/05/GHSA-x872-hfmg-7gqf/GHSA-x872-hfmg-7gqf.json index a01096b002e..c9c51bc05fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-x872-hfmg-7gqf/GHSA-x872-hfmg-7gqf.json +++ b/advisories/unreviewed/2022/05/GHSA-x872-hfmg-7gqf/GHSA-x872-hfmg-7gqf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x8j6-6jmc-fw5c/GHSA-x8j6-6jmc-fw5c.json b/advisories/unreviewed/2022/05/GHSA-x8j6-6jmc-fw5c/GHSA-x8j6-6jmc-fw5c.json index 8f1ca880cc2..05efd156a5f 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8j6-6jmc-fw5c/GHSA-x8j6-6jmc-fw5c.json +++ b/advisories/unreviewed/2022/05/GHSA-x8j6-6jmc-fw5c/GHSA-x8j6-6jmc-fw5c.json @@ -7,12 +7,8 @@ "CVE-2015-5781" ], "details": "ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an unspecified data structure, which allows remote attackers to obtain sensitive information from process memory via a crafted PNG image.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-x9f3-r8x7-5xm5/GHSA-x9f3-r8x7-5xm5.json b/advisories/unreviewed/2022/05/GHSA-x9f3-r8x7-5xm5/GHSA-x9f3-r8x7-5xm5.json index 0ba76640468..759ae0ec63e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9f3-r8x7-5xm5/GHSA-x9f3-r8x7-5xm5.json +++ b/advisories/unreviewed/2022/05/GHSA-x9f3-r8x7-5xm5/GHSA-x9f3-r8x7-5xm5.json @@ -7,12 +7,8 @@ "CVE-2015-0450" ], "details": "Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to WebCenter Spaces Application.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xc49-qj7m-vpp4/GHSA-xc49-qj7m-vpp4.json b/advisories/unreviewed/2022/05/GHSA-xc49-qj7m-vpp4/GHSA-xc49-qj7m-vpp4.json index 201e94ab23f..c01440dbbb4 100644 --- a/advisories/unreviewed/2022/05/GHSA-xc49-qj7m-vpp4/GHSA-xc49-qj7m-vpp4.json +++ b/advisories/unreviewed/2022/05/GHSA-xc49-qj7m-vpp4/GHSA-xc49-qj7m-vpp4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf49-x3pq-cfv4/GHSA-xf49-x3pq-cfv4.json b/advisories/unreviewed/2022/05/GHSA-xf49-x3pq-cfv4/GHSA-xf49-x3pq-cfv4.json index 0cadd46b289..523ebdbfc3b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf49-x3pq-cfv4/GHSA-xf49-x3pq-cfv4.json +++ b/advisories/unreviewed/2022/05/GHSA-xf49-x3pq-cfv4/GHSA-xf49-x3pq-cfv4.json @@ -7,12 +7,8 @@ "CVE-2015-0475" ], "details": "Unspecified vulnerability in the JD Edwards EnterpriseOne Technology component in Oracle JD Edwards Products 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web Runtime Security.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xf8x-2jhx-xp6x/GHSA-xf8x-2jhx-xp6x.json b/advisories/unreviewed/2022/05/GHSA-xf8x-2jhx-xp6x/GHSA-xf8x-2jhx-xp6x.json index 7da59645c8d..21d1e21de86 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf8x-2jhx-xp6x/GHSA-xf8x-2jhx-xp6x.json +++ b/advisories/unreviewed/2022/05/GHSA-xf8x-2jhx-xp6x/GHSA-xf8x-2jhx-xp6x.json @@ -7,12 +7,8 @@ "CVE-2012-0792" ], "details": "mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xf9w-8ghj-9mwp/GHSA-xf9w-8ghj-9mwp.json b/advisories/unreviewed/2022/05/GHSA-xf9w-8ghj-9mwp/GHSA-xf9w-8ghj-9mwp.json index ab0f5fa3338..ad1d7efff13 100644 --- a/advisories/unreviewed/2022/05/GHSA-xf9w-8ghj-9mwp/GHSA-xf9w-8ghj-9mwp.json +++ b/advisories/unreviewed/2022/05/GHSA-xf9w-8ghj-9mwp/GHSA-xf9w-8ghj-9mwp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xfmg-9xv8-p5p4/GHSA-xfmg-9xv8-p5p4.json b/advisories/unreviewed/2022/05/GHSA-xfmg-9xv8-p5p4/GHSA-xfmg-9xv8-p5p4.json index 95f35965e25..f9a0754e6f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-xfmg-9xv8-p5p4/GHSA-xfmg-9xv8-p5p4.json +++ b/advisories/unreviewed/2022/05/GHSA-xfmg-9xv8-p5p4/GHSA-xfmg-9xv8-p5p4.json @@ -7,12 +7,8 @@ "CVE-2014-8018" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCur19651, CSCur18555, CSCur19630, and CSCur19661.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgfq-5hc7-wrmc/GHSA-xgfq-5hc7-wrmc.json b/advisories/unreviewed/2022/05/GHSA-xgfq-5hc7-wrmc/GHSA-xgfq-5hc7-wrmc.json index 709307ee2fa..4d45dc7d051 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgfq-5hc7-wrmc/GHSA-xgfq-5hc7-wrmc.json +++ b/advisories/unreviewed/2022/05/GHSA-xgfq-5hc7-wrmc/GHSA-xgfq-5hc7-wrmc.json @@ -7,12 +7,8 @@ "CVE-2015-3666" ], "details": "QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3667, and CVE-2015-3668.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xgvx-jq9r-m7mm/GHSA-xgvx-jq9r-m7mm.json b/advisories/unreviewed/2022/05/GHSA-xgvx-jq9r-m7mm/GHSA-xgvx-jq9r-m7mm.json index 9f741c274b0..98be5cde3c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgvx-jq9r-m7mm/GHSA-xgvx-jq9r-m7mm.json +++ b/advisories/unreviewed/2022/05/GHSA-xgvx-jq9r-m7mm/GHSA-xgvx-jq9r-m7mm.json @@ -7,12 +7,8 @@ "CVE-2015-4220" ], "details": "Cross-site scripting (XSS) vulnerability in Cisco Unified Presence Server 9.1(1) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuq03773.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhc2-42cx-x3vm/GHSA-xhc2-42cx-x3vm.json b/advisories/unreviewed/2022/05/GHSA-xhc2-42cx-x3vm/GHSA-xhc2-42cx-x3vm.json index 5151b71367c..cf8a0dee075 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhc2-42cx-x3vm/GHSA-xhc2-42cx-x3vm.json +++ b/advisories/unreviewed/2022/05/GHSA-xhc2-42cx-x3vm/GHSA-xhc2-42cx-x3vm.json @@ -7,12 +7,8 @@ "CVE-2015-1954" ], "details": "Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xhv3-q5hx-88ww/GHSA-xhv3-q5hx-88ww.json b/advisories/unreviewed/2022/05/GHSA-xhv3-q5hx-88ww/GHSA-xhv3-q5hx-88ww.json index d942c23cf2d..dca9ec4d174 100644 --- a/advisories/unreviewed/2022/05/GHSA-xhv3-q5hx-88ww/GHSA-xhv3-q5hx-88ww.json +++ b/advisories/unreviewed/2022/05/GHSA-xhv3-q5hx-88ww/GHSA-xhv3-q5hx-88ww.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj5m-432r-gpqm/GHSA-xj5m-432r-gpqm.json b/advisories/unreviewed/2022/05/GHSA-xj5m-432r-gpqm/GHSA-xj5m-432r-gpqm.json index 932274ec26b..dfda9e9d282 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj5m-432r-gpqm/GHSA-xj5m-432r-gpqm.json +++ b/advisories/unreviewed/2022/05/GHSA-xj5m-432r-gpqm/GHSA-xj5m-432r-gpqm.json @@ -7,12 +7,8 @@ "CVE-2015-7184" ], "details": "The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xj7r-q24h-7jww/GHSA-xj7r-q24h-7jww.json b/advisories/unreviewed/2022/05/GHSA-xj7r-q24h-7jww/GHSA-xj7r-q24h-7jww.json index d62ea4898ed..b78e26e1d47 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj7r-q24h-7jww/GHSA-xj7r-q24h-7jww.json +++ b/advisories/unreviewed/2022/05/GHSA-xj7r-q24h-7jww/GHSA-xj7r-q24h-7jww.json @@ -7,12 +7,8 @@ "CVE-2015-4213" ], "details": "Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmc4-rjq5-7xw2/GHSA-xmc4-rjq5-7xw2.json b/advisories/unreviewed/2022/05/GHSA-xmc4-rjq5-7xw2/GHSA-xmc4-rjq5-7xw2.json index e1028ab0661..9faa80749a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmc4-rjq5-7xw2/GHSA-xmc4-rjq5-7xw2.json +++ b/advisories/unreviewed/2022/05/GHSA-xmc4-rjq5-7xw2/GHSA-xmc4-rjq5-7xw2.json @@ -7,12 +7,8 @@ "CVE-2015-5926" ], "details": "The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xmx7-4wwc-55h4/GHSA-xmx7-4wwc-55h4.json b/advisories/unreviewed/2022/05/GHSA-xmx7-4wwc-55h4/GHSA-xmx7-4wwc-55h4.json index 3e33e29c31e..f71fd0b6221 100644 --- a/advisories/unreviewed/2022/05/GHSA-xmx7-4wwc-55h4/GHSA-xmx7-4wwc-55h4.json +++ b/advisories/unreviewed/2022/05/GHSA-xmx7-4wwc-55h4/GHSA-xmx7-4wwc-55h4.json @@ -7,12 +7,8 @@ "CVE-2015-4243" ], "details": "The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty94202.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xphm-84c2-8fw4/GHSA-xphm-84c2-8fw4.json b/advisories/unreviewed/2022/05/GHSA-xphm-84c2-8fw4/GHSA-xphm-84c2-8fw4.json index 7df620d52b0..2099430ed3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xphm-84c2-8fw4/GHSA-xphm-84c2-8fw4.json +++ b/advisories/unreviewed/2022/05/GHSA-xphm-84c2-8fw4/GHSA-xphm-84c2-8fw4.json @@ -7,12 +7,8 @@ "CVE-2015-0515" ], "details": "Unrestricted file upload vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to execute arbitrary code by uploading and then accessing an executable file.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xpm4-fqq7-59gc/GHSA-xpm4-fqq7-59gc.json b/advisories/unreviewed/2022/05/GHSA-xpm4-fqq7-59gc/GHSA-xpm4-fqq7-59gc.json index a192c4e16e8..73351889ce8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpm4-fqq7-59gc/GHSA-xpm4-fqq7-59gc.json +++ b/advisories/unreviewed/2022/05/GHSA-xpm4-fqq7-59gc/GHSA-xpm4-fqq7-59gc.json @@ -7,12 +7,8 @@ "CVE-2015-6296" ], "details": "Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obtain root access by leveraging knowledge of the credentials, aka Bug ID CSCuw21825.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,9 +24,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xq4h-hmq6-ghrv/GHSA-xq4h-hmq6-ghrv.json b/advisories/unreviewed/2022/05/GHSA-xq4h-hmq6-ghrv/GHSA-xq4h-hmq6-ghrv.json index ff79d00789a..a75963abf79 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq4h-hmq6-ghrv/GHSA-xq4h-hmq6-ghrv.json +++ b/advisories/unreviewed/2022/05/GHSA-xq4h-hmq6-ghrv/GHSA-xq4h-hmq6-ghrv.json @@ -7,12 +7,8 @@ "CVE-2015-2727" ], "details": "Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xqfv-5ghm-86xf/GHSA-xqfv-5ghm-86xf.json b/advisories/unreviewed/2022/05/GHSA-xqfv-5ghm-86xf/GHSA-xqfv-5ghm-86xf.json index 7f5bc71e7d1..dc10370c366 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqfv-5ghm-86xf/GHSA-xqfv-5ghm-86xf.json +++ b/advisories/unreviewed/2022/05/GHSA-xqfv-5ghm-86xf/GHSA-xqfv-5ghm-86xf.json @@ -7,12 +7,8 @@ "CVE-2015-3098" ], "details": "Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-3099 and CVE-2015-3102.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr47-4wf6-2gmw/GHSA-xr47-4wf6-2gmw.json b/advisories/unreviewed/2022/05/GHSA-xr47-4wf6-2gmw/GHSA-xr47-4wf6-2gmw.json index 37d4dc2480d..720c9547c37 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr47-4wf6-2gmw/GHSA-xr47-4wf6-2gmw.json +++ b/advisories/unreviewed/2022/05/GHSA-xr47-4wf6-2gmw/GHSA-xr47-4wf6-2gmw.json @@ -7,12 +7,8 @@ "CVE-2015-3111" ], "details": "Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xr4q-6qfj-q54q/GHSA-xr4q-6qfj-q54q.json b/advisories/unreviewed/2022/05/GHSA-xr4q-6qfj-q54q/GHSA-xr4q-6qfj-q54q.json index bd62099157f..c11666fdaec 100644 --- a/advisories/unreviewed/2022/05/GHSA-xr4q-6qfj-q54q/GHSA-xr4q-6qfj-q54q.json +++ b/advisories/unreviewed/2022/05/GHSA-xr4q-6qfj-q54q/GHSA-xr4q-6qfj-q54q.json @@ -7,12 +7,8 @@ "CVE-2015-1889" ], "details": "The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvc4-7g96-6592/GHSA-xvc4-7g96-6592.json b/advisories/unreviewed/2022/05/GHSA-xvc4-7g96-6592/GHSA-xvc4-7g96-6592.json index b2593c06bae..a50d7cfe472 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvc4-7g96-6592/GHSA-xvc4-7g96-6592.json +++ b/advisories/unreviewed/2022/05/GHSA-xvc4-7g96-6592/GHSA-xvc4-7g96-6592.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xvjw-g673-q26h/GHSA-xvjw-g673-q26h.json b/advisories/unreviewed/2022/05/GHSA-xvjw-g673-q26h/GHSA-xvjw-g673-q26h.json index e11dc3bdaa0..dbc4fb1208a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvjw-g673-q26h/GHSA-xvjw-g673-q26h.json +++ b/advisories/unreviewed/2022/05/GHSA-xvjw-g673-q26h/GHSA-xvjw-g673-q26h.json @@ -7,12 +7,8 @@ "CVE-2015-1106" ], "details": "The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwjf-v823-v896/GHSA-xwjf-v823-v896.json b/advisories/unreviewed/2022/05/GHSA-xwjf-v823-v896/GHSA-xwjf-v823-v896.json index a324eedf0a8..d267bd23fa2 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwjf-v823-v896/GHSA-xwjf-v823-v896.json +++ b/advisories/unreviewed/2022/05/GHSA-xwjf-v823-v896/GHSA-xwjf-v823-v896.json @@ -7,12 +7,8 @@ "CVE-2013-2892" ], "details": "drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xwxw-ph5c-h3rg/GHSA-xwxw-ph5c-h3rg.json b/advisories/unreviewed/2022/05/GHSA-xwxw-ph5c-h3rg/GHSA-xwxw-ph5c-h3rg.json index 070210d37de..378096b8a4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwxw-ph5c-h3rg/GHSA-xwxw-ph5c-h3rg.json +++ b/advisories/unreviewed/2022/05/GHSA-xwxw-ph5c-h3rg/GHSA-xwxw-ph5c-h3rg.json @@ -7,12 +7,8 @@ "CVE-2015-2647" ], "details": "Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1; EM Plugin for DB 12.1.0.5, 12.1.0.6, 12.1.0.7; and EM DB Control 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Management.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,9 +28,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xx9w-q44v-r2wh/GHSA-xx9w-q44v-r2wh.json b/advisories/unreviewed/2022/05/GHSA-xx9w-q44v-r2wh/GHSA-xx9w-q44v-r2wh.json index 8f9f6f39600..34dd14943a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-xx9w-q44v-r2wh/GHSA-xx9w-q44v-r2wh.json +++ b/advisories/unreviewed/2022/05/GHSA-xx9w-q44v-r2wh/GHSA-xx9w-q44v-r2wh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxmg-3gv9-85h2/GHSA-xxmg-3gv9-85h2.json b/advisories/unreviewed/2022/05/GHSA-xxmg-3gv9-85h2/GHSA-xxmg-3gv9-85h2.json index 8d1ee20a213..2e64f37a3f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxmg-3gv9-85h2/GHSA-xxmg-3gv9-85h2.json +++ b/advisories/unreviewed/2022/05/GHSA-xxmg-3gv9-85h2/GHSA-xxmg-3gv9-85h2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxpp-89v4-96px/GHSA-xxpp-89v4-96px.json b/advisories/unreviewed/2022/05/GHSA-xxpp-89v4-96px/GHSA-xxpp-89v4-96px.json index 22f28b869a7..304c60fc036 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxpp-89v4-96px/GHSA-xxpp-89v4-96px.json +++ b/advisories/unreviewed/2022/05/GHSA-xxpp-89v4-96px/GHSA-xxpp-89v4-96px.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/05/GHSA-xxwc-8p4f-87mq/GHSA-xxwc-8p4f-87mq.json b/advisories/unreviewed/2022/05/GHSA-xxwc-8p4f-87mq/GHSA-xxwc-8p4f-87mq.json index d2b89027950..5da21fd9438 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxwc-8p4f-87mq/GHSA-xxwc-8p4f-87mq.json +++ b/advisories/unreviewed/2022/05/GHSA-xxwc-8p4f-87mq/GHSA-xxwc-8p4f-87mq.json @@ -7,12 +7,8 @@ "CVE-2015-6249" ], "details": "The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/06/GHSA-xjxr-x4h8-946x/GHSA-xjxr-x4h8-946x.json b/advisories/unreviewed/2022/06/GHSA-xjxr-x4h8-946x/GHSA-xjxr-x4h8-946x.json index ccc7e386539..7e22daa6efb 100644 --- a/advisories/unreviewed/2022/06/GHSA-xjxr-x4h8-946x/GHSA-xjxr-x4h8-946x.json +++ b/advisories/unreviewed/2022/06/GHSA-xjxr-x4h8-946x/GHSA-xjxr-x4h8-946x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/07/GHSA-39rf-5f5g-vgx4/GHSA-39rf-5f5g-vgx4.json b/advisories/unreviewed/2022/07/GHSA-39rf-5f5g-vgx4/GHSA-39rf-5f5g-vgx4.json index 9708711e024..02d5ee3e083 100644 --- a/advisories/unreviewed/2022/07/GHSA-39rf-5f5g-vgx4/GHSA-39rf-5f5g-vgx4.json +++ b/advisories/unreviewed/2022/07/GHSA-39rf-5f5g-vgx4/GHSA-39rf-5f5g-vgx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/08/GHSA-rpf2-3hpw-c9qh/GHSA-rpf2-3hpw-c9qh.json b/advisories/unreviewed/2022/08/GHSA-rpf2-3hpw-c9qh/GHSA-rpf2-3hpw-c9qh.json index 02c6a93bdcc..41870eb994c 100644 --- a/advisories/unreviewed/2022/08/GHSA-rpf2-3hpw-c9qh/GHSA-rpf2-3hpw-c9qh.json +++ b/advisories/unreviewed/2022/08/GHSA-rpf2-3hpw-c9qh/GHSA-rpf2-3hpw-c9qh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-93gw-qjv3-mc4m/GHSA-93gw-qjv3-mc4m.json b/advisories/unreviewed/2022/09/GHSA-93gw-qjv3-mc4m/GHSA-93gw-qjv3-mc4m.json index 4d5e600ad9b..95e892b9f98 100644 --- a/advisories/unreviewed/2022/09/GHSA-93gw-qjv3-mc4m/GHSA-93gw-qjv3-mc4m.json +++ b/advisories/unreviewed/2022/09/GHSA-93gw-qjv3-mc4m/GHSA-93gw-qjv3-mc4m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-9qww-9g4v-vq9h/GHSA-9qww-9g4v-vq9h.json b/advisories/unreviewed/2022/09/GHSA-9qww-9g4v-vq9h/GHSA-9qww-9g4v-vq9h.json index fd885315eac..e7acb65b6fc 100644 --- a/advisories/unreviewed/2022/09/GHSA-9qww-9g4v-vq9h/GHSA-9qww-9g4v-vq9h.json +++ b/advisories/unreviewed/2022/09/GHSA-9qww-9g4v-vq9h/GHSA-9qww-9g4v-vq9h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-f93p-vc52-m3wg/GHSA-f93p-vc52-m3wg.json b/advisories/unreviewed/2022/09/GHSA-f93p-vc52-m3wg/GHSA-f93p-vc52-m3wg.json index b5b4c52eec9..421033b534d 100644 --- a/advisories/unreviewed/2022/09/GHSA-f93p-vc52-m3wg/GHSA-f93p-vc52-m3wg.json +++ b/advisories/unreviewed/2022/09/GHSA-f93p-vc52-m3wg/GHSA-f93p-vc52-m3wg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -51,9 +49,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/09/GHSA-g7gc-274p-xj2q/GHSA-g7gc-274p-xj2q.json b/advisories/unreviewed/2022/09/GHSA-g7gc-274p-xj2q/GHSA-g7gc-274p-xj2q.json index aca445025e6..9506411a034 100644 --- a/advisories/unreviewed/2022/09/GHSA-g7gc-274p-xj2q/GHSA-g7gc-274p-xj2q.json +++ b/advisories/unreviewed/2022/09/GHSA-g7gc-274p-xj2q/GHSA-g7gc-274p-xj2q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-gcgj-p97f-wp62/GHSA-gcgj-p97f-wp62.json b/advisories/unreviewed/2022/09/GHSA-gcgj-p97f-wp62/GHSA-gcgj-p97f-wp62.json index e85649861b1..190d1a3fa68 100644 --- a/advisories/unreviewed/2022/09/GHSA-gcgj-p97f-wp62/GHSA-gcgj-p97f-wp62.json +++ b/advisories/unreviewed/2022/09/GHSA-gcgj-p97f-wp62/GHSA-gcgj-p97f-wp62.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2022/09/GHSA-xm6c-5wr3-4phj/GHSA-xm6c-5wr3-4phj.json b/advisories/unreviewed/2022/09/GHSA-xm6c-5wr3-4phj/GHSA-xm6c-5wr3-4phj.json index 1663266df03..a20912176f3 100644 --- a/advisories/unreviewed/2022/09/GHSA-xm6c-5wr3-4phj/GHSA-xm6c-5wr3-4phj.json +++ b/advisories/unreviewed/2022/09/GHSA-xm6c-5wr3-4phj/GHSA-xm6c-5wr3-4phj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-29vv-f3x5-f29x/GHSA-29vv-f3x5-f29x.json b/advisories/unreviewed/2023/04/GHSA-29vv-f3x5-f29x/GHSA-29vv-f3x5-f29x.json index bba90120ab8..bc964aee9d7 100644 --- a/advisories/unreviewed/2023/04/GHSA-29vv-f3x5-f29x/GHSA-29vv-f3x5-f29x.json +++ b/advisories/unreviewed/2023/04/GHSA-29vv-f3x5-f29x/GHSA-29vv-f3x5-f29x.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-3957-4rpg-54f9/GHSA-3957-4rpg-54f9.json b/advisories/unreviewed/2023/04/GHSA-3957-4rpg-54f9/GHSA-3957-4rpg-54f9.json index a14d625268b..6785dfe6c2b 100644 --- a/advisories/unreviewed/2023/04/GHSA-3957-4rpg-54f9/GHSA-3957-4rpg-54f9.json +++ b/advisories/unreviewed/2023/04/GHSA-3957-4rpg-54f9/GHSA-3957-4rpg-54f9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-429r-6xc2-p825/GHSA-429r-6xc2-p825.json b/advisories/unreviewed/2023/04/GHSA-429r-6xc2-p825/GHSA-429r-6xc2-p825.json index a36ed6e00ba..670a85987cc 100644 --- a/advisories/unreviewed/2023/04/GHSA-429r-6xc2-p825/GHSA-429r-6xc2-p825.json +++ b/advisories/unreviewed/2023/04/GHSA-429r-6xc2-p825/GHSA-429r-6xc2-p825.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-445c-hfjr-5j56/GHSA-445c-hfjr-5j56.json b/advisories/unreviewed/2023/04/GHSA-445c-hfjr-5j56/GHSA-445c-hfjr-5j56.json index 5e29d52e2b6..3e33a1455c6 100644 --- a/advisories/unreviewed/2023/04/GHSA-445c-hfjr-5j56/GHSA-445c-hfjr-5j56.json +++ b/advisories/unreviewed/2023/04/GHSA-445c-hfjr-5j56/GHSA-445c-hfjr-5j56.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-47pw-3g2g-9xj2/GHSA-47pw-3g2g-9xj2.json b/advisories/unreviewed/2023/04/GHSA-47pw-3g2g-9xj2/GHSA-47pw-3g2g-9xj2.json index 981b12c911e..f4c2b1ddf31 100644 --- a/advisories/unreviewed/2023/04/GHSA-47pw-3g2g-9xj2/GHSA-47pw-3g2g-9xj2.json +++ b/advisories/unreviewed/2023/04/GHSA-47pw-3g2g-9xj2/GHSA-47pw-3g2g-9xj2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-54hc-hc4h-876h/GHSA-54hc-hc4h-876h.json b/advisories/unreviewed/2023/04/GHSA-54hc-hc4h-876h/GHSA-54hc-hc4h-876h.json index 3bd361f08fd..5bd872ce671 100644 --- a/advisories/unreviewed/2023/04/GHSA-54hc-hc4h-876h/GHSA-54hc-hc4h-876h.json +++ b/advisories/unreviewed/2023/04/GHSA-54hc-hc4h-876h/GHSA-54hc-hc4h-876h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-597p-6h73-4vqj/GHSA-597p-6h73-4vqj.json b/advisories/unreviewed/2023/04/GHSA-597p-6h73-4vqj/GHSA-597p-6h73-4vqj.json index d0bd507589e..c843fe876e0 100644 --- a/advisories/unreviewed/2023/04/GHSA-597p-6h73-4vqj/GHSA-597p-6h73-4vqj.json +++ b/advisories/unreviewed/2023/04/GHSA-597p-6h73-4vqj/GHSA-597p-6h73-4vqj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-64x6-jjx3-6ggh/GHSA-64x6-jjx3-6ggh.json b/advisories/unreviewed/2023/04/GHSA-64x6-jjx3-6ggh/GHSA-64x6-jjx3-6ggh.json index 60b9d5dd596..3ac634b3630 100644 --- a/advisories/unreviewed/2023/04/GHSA-64x6-jjx3-6ggh/GHSA-64x6-jjx3-6ggh.json +++ b/advisories/unreviewed/2023/04/GHSA-64x6-jjx3-6ggh/GHSA-64x6-jjx3-6ggh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-67rc-9g3p-jjqp/GHSA-67rc-9g3p-jjqp.json b/advisories/unreviewed/2023/04/GHSA-67rc-9g3p-jjqp/GHSA-67rc-9g3p-jjqp.json index fe8d920b9a4..781e8785eb3 100644 --- a/advisories/unreviewed/2023/04/GHSA-67rc-9g3p-jjqp/GHSA-67rc-9g3p-jjqp.json +++ b/advisories/unreviewed/2023/04/GHSA-67rc-9g3p-jjqp/GHSA-67rc-9g3p-jjqp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-68pg-g9hg-f6c6/GHSA-68pg-g9hg-f6c6.json b/advisories/unreviewed/2023/04/GHSA-68pg-g9hg-f6c6/GHSA-68pg-g9hg-f6c6.json index 40d9db0d8e7..b1cd12ae7ec 100644 --- a/advisories/unreviewed/2023/04/GHSA-68pg-g9hg-f6c6/GHSA-68pg-g9hg-f6c6.json +++ b/advisories/unreviewed/2023/04/GHSA-68pg-g9hg-f6c6/GHSA-68pg-g9hg-f6c6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-6cv9-9p4c-38fq/GHSA-6cv9-9p4c-38fq.json b/advisories/unreviewed/2023/04/GHSA-6cv9-9p4c-38fq/GHSA-6cv9-9p4c-38fq.json index d93aef1cf69..be72193af08 100644 --- a/advisories/unreviewed/2023/04/GHSA-6cv9-9p4c-38fq/GHSA-6cv9-9p4c-38fq.json +++ b/advisories/unreviewed/2023/04/GHSA-6cv9-9p4c-38fq/GHSA-6cv9-9p4c-38fq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-7v8p-3ffx-7rjc/GHSA-7v8p-3ffx-7rjc.json b/advisories/unreviewed/2023/04/GHSA-7v8p-3ffx-7rjc/GHSA-7v8p-3ffx-7rjc.json index 48264c58855..3fb8393c3c1 100644 --- a/advisories/unreviewed/2023/04/GHSA-7v8p-3ffx-7rjc/GHSA-7v8p-3ffx-7rjc.json +++ b/advisories/unreviewed/2023/04/GHSA-7v8p-3ffx-7rjc/GHSA-7v8p-3ffx-7rjc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-8c29-7v4v-jmh4/GHSA-8c29-7v4v-jmh4.json b/advisories/unreviewed/2023/04/GHSA-8c29-7v4v-jmh4/GHSA-8c29-7v4v-jmh4.json index 0cc79945109..b338b158b27 100644 --- a/advisories/unreviewed/2023/04/GHSA-8c29-7v4v-jmh4/GHSA-8c29-7v4v-jmh4.json +++ b/advisories/unreviewed/2023/04/GHSA-8c29-7v4v-jmh4/GHSA-8c29-7v4v-jmh4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-8pwp-f58v-6mvg/GHSA-8pwp-f58v-6mvg.json b/advisories/unreviewed/2023/04/GHSA-8pwp-f58v-6mvg/GHSA-8pwp-f58v-6mvg.json index 42e8bee7ce6..e6c83109726 100644 --- a/advisories/unreviewed/2023/04/GHSA-8pwp-f58v-6mvg/GHSA-8pwp-f58v-6mvg.json +++ b/advisories/unreviewed/2023/04/GHSA-8pwp-f58v-6mvg/GHSA-8pwp-f58v-6mvg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-8v94-jg2x-f3vr/GHSA-8v94-jg2x-f3vr.json b/advisories/unreviewed/2023/04/GHSA-8v94-jg2x-f3vr/GHSA-8v94-jg2x-f3vr.json index 04b6c3e18f3..7066f952ecd 100644 --- a/advisories/unreviewed/2023/04/GHSA-8v94-jg2x-f3vr/GHSA-8v94-jg2x-f3vr.json +++ b/advisories/unreviewed/2023/04/GHSA-8v94-jg2x-f3vr/GHSA-8v94-jg2x-f3vr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-946v-x5hx-9p7j/GHSA-946v-x5hx-9p7j.json b/advisories/unreviewed/2023/04/GHSA-946v-x5hx-9p7j/GHSA-946v-x5hx-9p7j.json index 3e39804ab65..23a707c4768 100644 --- a/advisories/unreviewed/2023/04/GHSA-946v-x5hx-9p7j/GHSA-946v-x5hx-9p7j.json +++ b/advisories/unreviewed/2023/04/GHSA-946v-x5hx-9p7j/GHSA-946v-x5hx-9p7j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-94g5-g8cc-mwfw/GHSA-94g5-g8cc-mwfw.json b/advisories/unreviewed/2023/04/GHSA-94g5-g8cc-mwfw/GHSA-94g5-g8cc-mwfw.json index 6191abfeb19..e5c8163c5cf 100644 --- a/advisories/unreviewed/2023/04/GHSA-94g5-g8cc-mwfw/GHSA-94g5-g8cc-mwfw.json +++ b/advisories/unreviewed/2023/04/GHSA-94g5-g8cc-mwfw/GHSA-94g5-g8cc-mwfw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-9mrh-vv7h-7mx2/GHSA-9mrh-vv7h-7mx2.json b/advisories/unreviewed/2023/04/GHSA-9mrh-vv7h-7mx2/GHSA-9mrh-vv7h-7mx2.json index 290d8ee714d..e522270f012 100644 --- a/advisories/unreviewed/2023/04/GHSA-9mrh-vv7h-7mx2/GHSA-9mrh-vv7h-7mx2.json +++ b/advisories/unreviewed/2023/04/GHSA-9mrh-vv7h-7mx2/GHSA-9mrh-vv7h-7mx2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-c2c7-r6r9-3c2v/GHSA-c2c7-r6r9-3c2v.json b/advisories/unreviewed/2023/04/GHSA-c2c7-r6r9-3c2v/GHSA-c2c7-r6r9-3c2v.json index 61e8e3e16f5..20ff5008146 100644 --- a/advisories/unreviewed/2023/04/GHSA-c2c7-r6r9-3c2v/GHSA-c2c7-r6r9-3c2v.json +++ b/advisories/unreviewed/2023/04/GHSA-c2c7-r6r9-3c2v/GHSA-c2c7-r6r9-3c2v.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-cwg8-hmx3-cww9/GHSA-cwg8-hmx3-cww9.json b/advisories/unreviewed/2023/04/GHSA-cwg8-hmx3-cww9/GHSA-cwg8-hmx3-cww9.json index 83c82608a95..87b1f08909d 100644 --- a/advisories/unreviewed/2023/04/GHSA-cwg8-hmx3-cww9/GHSA-cwg8-hmx3-cww9.json +++ b/advisories/unreviewed/2023/04/GHSA-cwg8-hmx3-cww9/GHSA-cwg8-hmx3-cww9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-fv28-mxf3-88gf/GHSA-fv28-mxf3-88gf.json b/advisories/unreviewed/2023/04/GHSA-fv28-mxf3-88gf/GHSA-fv28-mxf3-88gf.json index fbbd33d7692..c3dab9cd29b 100644 --- a/advisories/unreviewed/2023/04/GHSA-fv28-mxf3-88gf/GHSA-fv28-mxf3-88gf.json +++ b/advisories/unreviewed/2023/04/GHSA-fv28-mxf3-88gf/GHSA-fv28-mxf3-88gf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-g9wq-m3qj-wcj5/GHSA-g9wq-m3qj-wcj5.json b/advisories/unreviewed/2023/04/GHSA-g9wq-m3qj-wcj5/GHSA-g9wq-m3qj-wcj5.json index e7029420105..81f8bbb5ec3 100644 --- a/advisories/unreviewed/2023/04/GHSA-g9wq-m3qj-wcj5/GHSA-g9wq-m3qj-wcj5.json +++ b/advisories/unreviewed/2023/04/GHSA-g9wq-m3qj-wcj5/GHSA-g9wq-m3qj-wcj5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-h6x9-x85v-xv6m/GHSA-h6x9-x85v-xv6m.json b/advisories/unreviewed/2023/04/GHSA-h6x9-x85v-xv6m/GHSA-h6x9-x85v-xv6m.json index 3b30cdfd9fa..b5f60f850a7 100644 --- a/advisories/unreviewed/2023/04/GHSA-h6x9-x85v-xv6m/GHSA-h6x9-x85v-xv6m.json +++ b/advisories/unreviewed/2023/04/GHSA-h6x9-x85v-xv6m/GHSA-h6x9-x85v-xv6m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-h7xj-xr99-gpjr/GHSA-h7xj-xr99-gpjr.json b/advisories/unreviewed/2023/04/GHSA-h7xj-xr99-gpjr/GHSA-h7xj-xr99-gpjr.json index f44aa19c138..9ad7ffc7e92 100644 --- a/advisories/unreviewed/2023/04/GHSA-h7xj-xr99-gpjr/GHSA-h7xj-xr99-gpjr.json +++ b/advisories/unreviewed/2023/04/GHSA-h7xj-xr99-gpjr/GHSA-h7xj-xr99-gpjr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-hp9c-cr2q-p6fp/GHSA-hp9c-cr2q-p6fp.json b/advisories/unreviewed/2023/04/GHSA-hp9c-cr2q-p6fp/GHSA-hp9c-cr2q-p6fp.json index a4dbd1ddf60..5abe49ccc82 100644 --- a/advisories/unreviewed/2023/04/GHSA-hp9c-cr2q-p6fp/GHSA-hp9c-cr2q-p6fp.json +++ b/advisories/unreviewed/2023/04/GHSA-hp9c-cr2q-p6fp/GHSA-hp9c-cr2q-p6fp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-hpxw-6636-5h87/GHSA-hpxw-6636-5h87.json b/advisories/unreviewed/2023/04/GHSA-hpxw-6636-5h87/GHSA-hpxw-6636-5h87.json index c90eaf6165f..f89f0506255 100644 --- a/advisories/unreviewed/2023/04/GHSA-hpxw-6636-5h87/GHSA-hpxw-6636-5h87.json +++ b/advisories/unreviewed/2023/04/GHSA-hpxw-6636-5h87/GHSA-hpxw-6636-5h87.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-j62f-cmvp-vxcm/GHSA-j62f-cmvp-vxcm.json b/advisories/unreviewed/2023/04/GHSA-j62f-cmvp-vxcm/GHSA-j62f-cmvp-vxcm.json index 0a3bc42c57b..d4689eb5a76 100644 --- a/advisories/unreviewed/2023/04/GHSA-j62f-cmvp-vxcm/GHSA-j62f-cmvp-vxcm.json +++ b/advisories/unreviewed/2023/04/GHSA-j62f-cmvp-vxcm/GHSA-j62f-cmvp-vxcm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-jc3m-fp5q-7qx9/GHSA-jc3m-fp5q-7qx9.json b/advisories/unreviewed/2023/04/GHSA-jc3m-fp5q-7qx9/GHSA-jc3m-fp5q-7qx9.json index ec84b511e30..f86b9eedc95 100644 --- a/advisories/unreviewed/2023/04/GHSA-jc3m-fp5q-7qx9/GHSA-jc3m-fp5q-7qx9.json +++ b/advisories/unreviewed/2023/04/GHSA-jc3m-fp5q-7qx9/GHSA-jc3m-fp5q-7qx9.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-jr76-9m4q-w677/GHSA-jr76-9m4q-w677.json b/advisories/unreviewed/2023/04/GHSA-jr76-9m4q-w677/GHSA-jr76-9m4q-w677.json index b5d34e8328b..4c99b5029c1 100644 --- a/advisories/unreviewed/2023/04/GHSA-jr76-9m4q-w677/GHSA-jr76-9m4q-w677.json +++ b/advisories/unreviewed/2023/04/GHSA-jr76-9m4q-w677/GHSA-jr76-9m4q-w677.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-jw8g-rg5r-2x5j/GHSA-jw8g-rg5r-2x5j.json b/advisories/unreviewed/2023/04/GHSA-jw8g-rg5r-2x5j/GHSA-jw8g-rg5r-2x5j.json index 9457e4dd415..961248e9b33 100644 --- a/advisories/unreviewed/2023/04/GHSA-jw8g-rg5r-2x5j/GHSA-jw8g-rg5r-2x5j.json +++ b/advisories/unreviewed/2023/04/GHSA-jw8g-rg5r-2x5j/GHSA-jw8g-rg5r-2x5j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-jwh5-m9vf-pgw4/GHSA-jwh5-m9vf-pgw4.json b/advisories/unreviewed/2023/04/GHSA-jwh5-m9vf-pgw4/GHSA-jwh5-m9vf-pgw4.json index 686c4ea9d59..83e48aa85e4 100644 --- a/advisories/unreviewed/2023/04/GHSA-jwh5-m9vf-pgw4/GHSA-jwh5-m9vf-pgw4.json +++ b/advisories/unreviewed/2023/04/GHSA-jwh5-m9vf-pgw4/GHSA-jwh5-m9vf-pgw4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-mw45-5c3j-pmqf/GHSA-mw45-5c3j-pmqf.json b/advisories/unreviewed/2023/04/GHSA-mw45-5c3j-pmqf/GHSA-mw45-5c3j-pmqf.json index 069377f646d..a1af5f2f354 100644 --- a/advisories/unreviewed/2023/04/GHSA-mw45-5c3j-pmqf/GHSA-mw45-5c3j-pmqf.json +++ b/advisories/unreviewed/2023/04/GHSA-mw45-5c3j-pmqf/GHSA-mw45-5c3j-pmqf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-pxh4-4g7r-4w5h/GHSA-pxh4-4g7r-4w5h.json b/advisories/unreviewed/2023/04/GHSA-pxh4-4g7r-4w5h/GHSA-pxh4-4g7r-4w5h.json index 7b5fd2a096b..4512e2d5e53 100644 --- a/advisories/unreviewed/2023/04/GHSA-pxh4-4g7r-4w5h/GHSA-pxh4-4g7r-4w5h.json +++ b/advisories/unreviewed/2023/04/GHSA-pxh4-4g7r-4w5h/GHSA-pxh4-4g7r-4w5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-q772-4845-474h/GHSA-q772-4845-474h.json b/advisories/unreviewed/2023/04/GHSA-q772-4845-474h/GHSA-q772-4845-474h.json index aebf463c1f5..90aa7df3f01 100644 --- a/advisories/unreviewed/2023/04/GHSA-q772-4845-474h/GHSA-q772-4845-474h.json +++ b/advisories/unreviewed/2023/04/GHSA-q772-4845-474h/GHSA-q772-4845-474h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-qc2w-qcmx-m375/GHSA-qc2w-qcmx-m375.json b/advisories/unreviewed/2023/04/GHSA-qc2w-qcmx-m375/GHSA-qc2w-qcmx-m375.json index 7eb4dca1685..b245478cb99 100644 --- a/advisories/unreviewed/2023/04/GHSA-qc2w-qcmx-m375/GHSA-qc2w-qcmx-m375.json +++ b/advisories/unreviewed/2023/04/GHSA-qc2w-qcmx-m375/GHSA-qc2w-qcmx-m375.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-qw5x-g9qx-73xw/GHSA-qw5x-g9qx-73xw.json b/advisories/unreviewed/2023/04/GHSA-qw5x-g9qx-73xw/GHSA-qw5x-g9qx-73xw.json index d449f4e410e..2c9bb53bde3 100644 --- a/advisories/unreviewed/2023/04/GHSA-qw5x-g9qx-73xw/GHSA-qw5x-g9qx-73xw.json +++ b/advisories/unreviewed/2023/04/GHSA-qw5x-g9qx-73xw/GHSA-qw5x-g9qx-73xw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-r3h7-cpq4-j5rr/GHSA-r3h7-cpq4-j5rr.json b/advisories/unreviewed/2023/04/GHSA-r3h7-cpq4-j5rr/GHSA-r3h7-cpq4-j5rr.json index 4342f5d300f..c9ddbfb3b5b 100644 --- a/advisories/unreviewed/2023/04/GHSA-r3h7-cpq4-j5rr/GHSA-r3h7-cpq4-j5rr.json +++ b/advisories/unreviewed/2023/04/GHSA-r3h7-cpq4-j5rr/GHSA-r3h7-cpq4-j5rr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-vg73-w7ww-xm56/GHSA-vg73-w7ww-xm56.json b/advisories/unreviewed/2023/04/GHSA-vg73-w7ww-xm56/GHSA-vg73-w7ww-xm56.json index d3d837365f3..144c4c54bb0 100644 --- a/advisories/unreviewed/2023/04/GHSA-vg73-w7ww-xm56/GHSA-vg73-w7ww-xm56.json +++ b/advisories/unreviewed/2023/04/GHSA-vg73-w7ww-xm56/GHSA-vg73-w7ww-xm56.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-vg7q-437w-gm7q/GHSA-vg7q-437w-gm7q.json b/advisories/unreviewed/2023/04/GHSA-vg7q-437w-gm7q/GHSA-vg7q-437w-gm7q.json index f371757b288..ee84144aded 100644 --- a/advisories/unreviewed/2023/04/GHSA-vg7q-437w-gm7q/GHSA-vg7q-437w-gm7q.json +++ b/advisories/unreviewed/2023/04/GHSA-vg7q-437w-gm7q/GHSA-vg7q-437w-gm7q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-w45c-77r5-cpwj/GHSA-w45c-77r5-cpwj.json b/advisories/unreviewed/2023/04/GHSA-w45c-77r5-cpwj/GHSA-w45c-77r5-cpwj.json index f88478afbb0..5aaf7e541ff 100644 --- a/advisories/unreviewed/2023/04/GHSA-w45c-77r5-cpwj/GHSA-w45c-77r5-cpwj.json +++ b/advisories/unreviewed/2023/04/GHSA-w45c-77r5-cpwj/GHSA-w45c-77r5-cpwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-w4rg-r8xp-8849/GHSA-w4rg-r8xp-8849.json b/advisories/unreviewed/2023/04/GHSA-w4rg-r8xp-8849/GHSA-w4rg-r8xp-8849.json index 96730a7a5fe..f31276e2638 100644 --- a/advisories/unreviewed/2023/04/GHSA-w4rg-r8xp-8849/GHSA-w4rg-r8xp-8849.json +++ b/advisories/unreviewed/2023/04/GHSA-w4rg-r8xp-8849/GHSA-w4rg-r8xp-8849.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-w9gc-4j8x-xhjc/GHSA-w9gc-4j8x-xhjc.json b/advisories/unreviewed/2023/04/GHSA-w9gc-4j8x-xhjc/GHSA-w9gc-4j8x-xhjc.json index 5ed32cb263b..1232cdbfe4f 100644 --- a/advisories/unreviewed/2023/04/GHSA-w9gc-4j8x-xhjc/GHSA-w9gc-4j8x-xhjc.json +++ b/advisories/unreviewed/2023/04/GHSA-w9gc-4j8x-xhjc/GHSA-w9gc-4j8x-xhjc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-wr65-8g2h-54pr/GHSA-wr65-8g2h-54pr.json b/advisories/unreviewed/2023/04/GHSA-wr65-8g2h-54pr/GHSA-wr65-8g2h-54pr.json index fd17433dac0..addab145a3d 100644 --- a/advisories/unreviewed/2023/04/GHSA-wr65-8g2h-54pr/GHSA-wr65-8g2h-54pr.json +++ b/advisories/unreviewed/2023/04/GHSA-wr65-8g2h-54pr/GHSA-wr65-8g2h-54pr.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-x625-jv3w-7fff/GHSA-x625-jv3w-7fff.json b/advisories/unreviewed/2023/04/GHSA-x625-jv3w-7fff/GHSA-x625-jv3w-7fff.json index 7bd1fa2ad6e..3dc701c9b32 100644 --- a/advisories/unreviewed/2023/04/GHSA-x625-jv3w-7fff/GHSA-x625-jv3w-7fff.json +++ b/advisories/unreviewed/2023/04/GHSA-x625-jv3w-7fff/GHSA-x625-jv3w-7fff.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/04/GHSA-x7hv-6w9v-fmv8/GHSA-x7hv-6w9v-fmv8.json b/advisories/unreviewed/2023/04/GHSA-x7hv-6w9v-fmv8/GHSA-x7hv-6w9v-fmv8.json index cc0e52cac80..f1d6f443ea2 100644 --- a/advisories/unreviewed/2023/04/GHSA-x7hv-6w9v-fmv8/GHSA-x7hv-6w9v-fmv8.json +++ b/advisories/unreviewed/2023/04/GHSA-x7hv-6w9v-fmv8/GHSA-x7hv-6w9v-fmv8.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-54v8-3w5h-ggf6/GHSA-54v8-3w5h-ggf6.json b/advisories/unreviewed/2023/11/GHSA-54v8-3w5h-ggf6/GHSA-54v8-3w5h-ggf6.json index add1d0207fa..9eac144bcf2 100644 --- a/advisories/unreviewed/2023/11/GHSA-54v8-3w5h-ggf6/GHSA-54v8-3w5h-ggf6.json +++ b/advisories/unreviewed/2023/11/GHSA-54v8-3w5h-ggf6/GHSA-54v8-3w5h-ggf6.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-j5rw-m6xg-866q/GHSA-j5rw-m6xg-866q.json b/advisories/unreviewed/2023/11/GHSA-j5rw-m6xg-866q/GHSA-j5rw-m6xg-866q.json index d791d29f7d3..90e12651500 100644 --- a/advisories/unreviewed/2023/11/GHSA-j5rw-m6xg-866q/GHSA-j5rw-m6xg-866q.json +++ b/advisories/unreviewed/2023/11/GHSA-j5rw-m6xg-866q/GHSA-j5rw-m6xg-866q.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/11/GHSA-w3gp-79x2-f8rp/GHSA-w3gp-79x2-f8rp.json b/advisories/unreviewed/2023/11/GHSA-w3gp-79x2-f8rp/GHSA-w3gp-79x2-f8rp.json index 702261466eb..5d5876b05dd 100644 --- a/advisories/unreviewed/2023/11/GHSA-w3gp-79x2-f8rp/GHSA-w3gp-79x2-f8rp.json +++ b/advisories/unreviewed/2023/11/GHSA-w3gp-79x2-f8rp/GHSA-w3gp-79x2-f8rp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2023/12/GHSA-m5fp-jhxc-8cvh/GHSA-m5fp-jhxc-8cvh.json b/advisories/unreviewed/2023/12/GHSA-m5fp-jhxc-8cvh/GHSA-m5fp-jhxc-8cvh.json index 1bb3256f490..c187052bf77 100644 --- a/advisories/unreviewed/2023/12/GHSA-m5fp-jhxc-8cvh/GHSA-m5fp-jhxc-8cvh.json +++ b/advisories/unreviewed/2023/12/GHSA-m5fp-jhxc-8cvh/GHSA-m5fp-jhxc-8cvh.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-5cm2-xfwq-cj8j/GHSA-5cm2-xfwq-cj8j.json b/advisories/unreviewed/2024/02/GHSA-5cm2-xfwq-cj8j/GHSA-5cm2-xfwq-cj8j.json index 283f4c63f79..666dd4ff4bb 100644 --- a/advisories/unreviewed/2024/02/GHSA-5cm2-xfwq-cj8j/GHSA-5cm2-xfwq-cj8j.json +++ b/advisories/unreviewed/2024/02/GHSA-5cm2-xfwq-cj8j/GHSA-5cm2-xfwq-cj8j.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-6xjf-hqcm-9g3f/GHSA-6xjf-hqcm-9g3f.json b/advisories/unreviewed/2024/02/GHSA-6xjf-hqcm-9g3f/GHSA-6xjf-hqcm-9g3f.json index 95492954dd8..df7e079df13 100644 --- a/advisories/unreviewed/2024/02/GHSA-6xjf-hqcm-9g3f/GHSA-6xjf-hqcm-9g3f.json +++ b/advisories/unreviewed/2024/02/GHSA-6xjf-hqcm-9g3f/GHSA-6xjf-hqcm-9g3f.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-fjh2-g557-4jxp/GHSA-fjh2-g557-4jxp.json b/advisories/unreviewed/2024/03/GHSA-fjh2-g557-4jxp/GHSA-fjh2-g557-4jxp.json index ca6197eb6fd..a9ed12b2006 100644 --- a/advisories/unreviewed/2024/03/GHSA-fjh2-g557-4jxp/GHSA-fjh2-g557-4jxp.json +++ b/advisories/unreviewed/2024/03/GHSA-fjh2-g557-4jxp/GHSA-fjh2-g557-4jxp.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json b/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json index ba2effee45b..3003f78ba1f 100644 --- a/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json +++ b/advisories/unreviewed/2024/04/GHSA-27hf-w6wm-652c/GHSA-27hf-w6wm-652c.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2rfp-5w3v-6w75/GHSA-2rfp-5w3v-6w75.json b/advisories/unreviewed/2024/04/GHSA-2rfp-5w3v-6w75/GHSA-2rfp-5w3v-6w75.json index d7094695189..becb251daa4 100644 --- a/advisories/unreviewed/2024/04/GHSA-2rfp-5w3v-6w75/GHSA-2rfp-5w3v-6w75.json +++ b/advisories/unreviewed/2024/04/GHSA-2rfp-5w3v-6w75/GHSA-2rfp-5w3v-6w75.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-2w4r-8725-xcxv/GHSA-2w4r-8725-xcxv.json b/advisories/unreviewed/2024/04/GHSA-2w4r-8725-xcxv/GHSA-2w4r-8725-xcxv.json index 97878f718cf..8941bcefca8 100644 --- a/advisories/unreviewed/2024/04/GHSA-2w4r-8725-xcxv/GHSA-2w4r-8725-xcxv.json +++ b/advisories/unreviewed/2024/04/GHSA-2w4r-8725-xcxv/GHSA-2w4r-8725-xcxv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-3wqg-6hfx-9w42/GHSA-3wqg-6hfx-9w42.json b/advisories/unreviewed/2024/04/GHSA-3wqg-6hfx-9w42/GHSA-3wqg-6hfx-9w42.json index 9933f46a5dc..e7a421cb3d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-3wqg-6hfx-9w42/GHSA-3wqg-6hfx-9w42.json +++ b/advisories/unreviewed/2024/04/GHSA-3wqg-6hfx-9w42/GHSA-3wqg-6hfx-9w42.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-42g9-27rx-76cj/GHSA-42g9-27rx-76cj.json b/advisories/unreviewed/2024/04/GHSA-42g9-27rx-76cj/GHSA-42g9-27rx-76cj.json index 1ba6ee52253..f5f0909a526 100644 --- a/advisories/unreviewed/2024/04/GHSA-42g9-27rx-76cj/GHSA-42g9-27rx-76cj.json +++ b/advisories/unreviewed/2024/04/GHSA-42g9-27rx-76cj/GHSA-42g9-27rx-76cj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4cvp-jw4q-vr74/GHSA-4cvp-jw4q-vr74.json b/advisories/unreviewed/2024/04/GHSA-4cvp-jw4q-vr74/GHSA-4cvp-jw4q-vr74.json index 83fb2886894..52eef2609c1 100644 --- a/advisories/unreviewed/2024/04/GHSA-4cvp-jw4q-vr74/GHSA-4cvp-jw4q-vr74.json +++ b/advisories/unreviewed/2024/04/GHSA-4cvp-jw4q-vr74/GHSA-4cvp-jw4q-vr74.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-4fv8-fm6j-xc9r/GHSA-4fv8-fm6j-xc9r.json b/advisories/unreviewed/2024/04/GHSA-4fv8-fm6j-xc9r/GHSA-4fv8-fm6j-xc9r.json index eaa83c37730..4e7f8f1ff2c 100644 --- a/advisories/unreviewed/2024/04/GHSA-4fv8-fm6j-xc9r/GHSA-4fv8-fm6j-xc9r.json +++ b/advisories/unreviewed/2024/04/GHSA-4fv8-fm6j-xc9r/GHSA-4fv8-fm6j-xc9r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5m68-rc9v-rxh2/GHSA-5m68-rc9v-rxh2.json b/advisories/unreviewed/2024/04/GHSA-5m68-rc9v-rxh2/GHSA-5m68-rc9v-rxh2.json index 48a0ae418c6..d2f67281d6d 100644 --- a/advisories/unreviewed/2024/04/GHSA-5m68-rc9v-rxh2/GHSA-5m68-rc9v-rxh2.json +++ b/advisories/unreviewed/2024/04/GHSA-5m68-rc9v-rxh2/GHSA-5m68-rc9v-rxh2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-5v78-8gv6-c945/GHSA-5v78-8gv6-c945.json b/advisories/unreviewed/2024/04/GHSA-5v78-8gv6-c945/GHSA-5v78-8gv6-c945.json index 975921d8152..4e347996da1 100644 --- a/advisories/unreviewed/2024/04/GHSA-5v78-8gv6-c945/GHSA-5v78-8gv6-c945.json +++ b/advisories/unreviewed/2024/04/GHSA-5v78-8gv6-c945/GHSA-5v78-8gv6-c945.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -31,9 +29,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-684w-rg22-c86m/GHSA-684w-rg22-c86m.json b/advisories/unreviewed/2024/04/GHSA-684w-rg22-c86m/GHSA-684w-rg22-c86m.json index f1aeca9d9b3..3a0eef5f4d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-684w-rg22-c86m/GHSA-684w-rg22-c86m.json +++ b/advisories/unreviewed/2024/04/GHSA-684w-rg22-c86m/GHSA-684w-rg22-c86m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-72c6-gcpg-6rw3/GHSA-72c6-gcpg-6rw3.json b/advisories/unreviewed/2024/04/GHSA-72c6-gcpg-6rw3/GHSA-72c6-gcpg-6rw3.json index 557b781092e..a15abfbf9c6 100644 --- a/advisories/unreviewed/2024/04/GHSA-72c6-gcpg-6rw3/GHSA-72c6-gcpg-6rw3.json +++ b/advisories/unreviewed/2024/04/GHSA-72c6-gcpg-6rw3/GHSA-72c6-gcpg-6rw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-79c8-vq74-47fc/GHSA-79c8-vq74-47fc.json b/advisories/unreviewed/2024/04/GHSA-79c8-vq74-47fc/GHSA-79c8-vq74-47fc.json index 06fafd6a238..09ddd316c1b 100644 --- a/advisories/unreviewed/2024/04/GHSA-79c8-vq74-47fc/GHSA-79c8-vq74-47fc.json +++ b/advisories/unreviewed/2024/04/GHSA-79c8-vq74-47fc/GHSA-79c8-vq74-47fc.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8f6g-63pm-5fmx/GHSA-8f6g-63pm-5fmx.json b/advisories/unreviewed/2024/04/GHSA-8f6g-63pm-5fmx/GHSA-8f6g-63pm-5fmx.json index dd2d2f1e5eb..2de88a803aa 100644 --- a/advisories/unreviewed/2024/04/GHSA-8f6g-63pm-5fmx/GHSA-8f6g-63pm-5fmx.json +++ b/advisories/unreviewed/2024/04/GHSA-8f6g-63pm-5fmx/GHSA-8f6g-63pm-5fmx.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8vcp-v22r-9p96/GHSA-8vcp-v22r-9p96.json b/advisories/unreviewed/2024/04/GHSA-8vcp-v22r-9p96/GHSA-8vcp-v22r-9p96.json index 7ee568a5f30..99eb1a56c56 100644 --- a/advisories/unreviewed/2024/04/GHSA-8vcp-v22r-9p96/GHSA-8vcp-v22r-9p96.json +++ b/advisories/unreviewed/2024/04/GHSA-8vcp-v22r-9p96/GHSA-8vcp-v22r-9p96.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-8wm5-mx8v-3jpf/GHSA-8wm5-mx8v-3jpf.json b/advisories/unreviewed/2024/04/GHSA-8wm5-mx8v-3jpf/GHSA-8wm5-mx8v-3jpf.json index 13740c6f684..8b06bf6c270 100644 --- a/advisories/unreviewed/2024/04/GHSA-8wm5-mx8v-3jpf/GHSA-8wm5-mx8v-3jpf.json +++ b/advisories/unreviewed/2024/04/GHSA-8wm5-mx8v-3jpf/GHSA-8wm5-mx8v-3jpf.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-c43g-9f5q-rqx4/GHSA-c43g-9f5q-rqx4.json b/advisories/unreviewed/2024/04/GHSA-c43g-9f5q-rqx4/GHSA-c43g-9f5q-rqx4.json index 68f448b4a31..2f50c8abb64 100644 --- a/advisories/unreviewed/2024/04/GHSA-c43g-9f5q-rqx4/GHSA-c43g-9f5q-rqx4.json +++ b/advisories/unreviewed/2024/04/GHSA-c43g-9f5q-rqx4/GHSA-c43g-9f5q-rqx4.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-f53j-pgm5-c4r3/GHSA-f53j-pgm5-c4r3.json b/advisories/unreviewed/2024/04/GHSA-f53j-pgm5-c4r3/GHSA-f53j-pgm5-c4r3.json index 5cae4daa1b7..f9abf65b86e 100644 --- a/advisories/unreviewed/2024/04/GHSA-f53j-pgm5-c4r3/GHSA-f53j-pgm5-c4r3.json +++ b/advisories/unreviewed/2024/04/GHSA-f53j-pgm5-c4r3/GHSA-f53j-pgm5-c4r3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-fm53-2cx3-crw3/GHSA-fm53-2cx3-crw3.json b/advisories/unreviewed/2024/04/GHSA-fm53-2cx3-crw3/GHSA-fm53-2cx3-crw3.json index 57de6e9740e..57d8dc298bb 100644 --- a/advisories/unreviewed/2024/04/GHSA-fm53-2cx3-crw3/GHSA-fm53-2cx3-crw3.json +++ b/advisories/unreviewed/2024/04/GHSA-fm53-2cx3-crw3/GHSA-fm53-2cx3-crw3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-grqr-vjxq-x7g2/GHSA-grqr-vjxq-x7g2.json b/advisories/unreviewed/2024/04/GHSA-grqr-vjxq-x7g2/GHSA-grqr-vjxq-x7g2.json index d08729b1b0b..ef8ca1a86f4 100644 --- a/advisories/unreviewed/2024/04/GHSA-grqr-vjxq-x7g2/GHSA-grqr-vjxq-x7g2.json +++ b/advisories/unreviewed/2024/04/GHSA-grqr-vjxq-x7g2/GHSA-grqr-vjxq-x7g2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hjcw-3hhf-5gfv/GHSA-hjcw-3hhf-5gfv.json b/advisories/unreviewed/2024/04/GHSA-hjcw-3hhf-5gfv/GHSA-hjcw-3hhf-5gfv.json index 05f28b708e2..47f5438731f 100644 --- a/advisories/unreviewed/2024/04/GHSA-hjcw-3hhf-5gfv/GHSA-hjcw-3hhf-5gfv.json +++ b/advisories/unreviewed/2024/04/GHSA-hjcw-3hhf-5gfv/GHSA-hjcw-3hhf-5gfv.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-hr6p-pchq-hc5h/GHSA-hr6p-pchq-hc5h.json b/advisories/unreviewed/2024/04/GHSA-hr6p-pchq-hc5h/GHSA-hr6p-pchq-hc5h.json index 584745be986..a3025b6eba9 100644 --- a/advisories/unreviewed/2024/04/GHSA-hr6p-pchq-hc5h/GHSA-hr6p-pchq-hc5h.json +++ b/advisories/unreviewed/2024/04/GHSA-hr6p-pchq-hc5h/GHSA-hr6p-pchq-hc5h.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json b/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json index c2a5337a0ab..27d872e32d0 100644 --- a/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json +++ b/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json b/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json index 2f86436a3dd..a4d5d637b31 100644 --- a/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json +++ b/advisories/unreviewed/2024/04/GHSA-v859-v234-c2mg/GHSA-v859-v234-c2mg.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,9 +25,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vfmv-3fmr-wr8p/GHSA-vfmv-3fmr-wr8p.json b/advisories/unreviewed/2024/04/GHSA-vfmv-3fmr-wr8p/GHSA-vfmv-3fmr-wr8p.json index 9c09d0f0fcd..f417ad6379b 100644 --- a/advisories/unreviewed/2024/04/GHSA-vfmv-3fmr-wr8p/GHSA-vfmv-3fmr-wr8p.json +++ b/advisories/unreviewed/2024/04/GHSA-vfmv-3fmr-wr8p/GHSA-vfmv-3fmr-wr8p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-vx2h-v5x8-fp94/GHSA-vx2h-v5x8-fp94.json b/advisories/unreviewed/2024/04/GHSA-vx2h-v5x8-fp94/GHSA-vx2h-v5x8-fp94.json index 4fcfb2ccc26..a54c60c49c4 100644 --- a/advisories/unreviewed/2024/04/GHSA-vx2h-v5x8-fp94/GHSA-vx2h-v5x8-fp94.json +++ b/advisories/unreviewed/2024/04/GHSA-vx2h-v5x8-fp94/GHSA-vx2h-v5x8-fp94.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-w5hw-wf94-wxwj/GHSA-w5hw-wf94-wxwj.json b/advisories/unreviewed/2024/04/GHSA-w5hw-wf94-wxwj/GHSA-w5hw-wf94-wxwj.json index fc90cb1feb3..86bc9453b14 100644 --- a/advisories/unreviewed/2024/04/GHSA-w5hw-wf94-wxwj/GHSA-w5hw-wf94-wxwj.json +++ b/advisories/unreviewed/2024/04/GHSA-w5hw-wf94-wxwj/GHSA-w5hw-wf94-wxwj.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wjmr-c4qh-w89r/GHSA-wjmr-c4qh-w89r.json b/advisories/unreviewed/2024/04/GHSA-wjmr-c4qh-w89r/GHSA-wjmr-c4qh-w89r.json index a6aba0994a7..b3e9971709e 100644 --- a/advisories/unreviewed/2024/04/GHSA-wjmr-c4qh-w89r/GHSA-wjmr-c4qh-w89r.json +++ b/advisories/unreviewed/2024/04/GHSA-wjmr-c4qh-w89r/GHSA-wjmr-c4qh-w89r.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/04/GHSA-wrj7-28f3-vc97/GHSA-wrj7-28f3-vc97.json b/advisories/unreviewed/2024/04/GHSA-wrj7-28f3-vc97/GHSA-wrj7-28f3-vc97.json index d7badc73323..98b6ed81d8b 100644 --- a/advisories/unreviewed/2024/04/GHSA-wrj7-28f3-vc97/GHSA-wrj7-28f3-vc97.json +++ b/advisories/unreviewed/2024/04/GHSA-wrj7-28f3-vc97/GHSA-wrj7-28f3-vc97.json @@ -7,12 +7,8 @@ "CVE-2024-27462" ], "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", - "severity": [ - - ], - "affected": [ - - ], + "severity": [], + "affected": [], "references": [ { "type": "ADVISORY", @@ -20,9 +16,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json b/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json index 08555cbdb93..454937be445 100644 --- a/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json +++ b/advisories/unreviewed/2024/05/GHSA-59j5-r3pj-3q9p/GHSA-59j5-r3pj-3q9p.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY",